[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: RFC 2401 section 5.2.1





"Joseph D. Harwood" wrote:
> 
> >
> > What does tunnel mode give you that IPIP tunnels + IPsec transport mode
> > don't? Inbound processing for both should be identical, since you can't
> > tell the difference by looking at the packet.
> 
> Not quite identical.  After IPsec processing, the received packet's
> selectors are checked against the SPD to make sure all of the appropriate
> processing has been performed.  In Tunnel mode, these selectors are from the
> inner (encapsulated) header, in IPIP + IPsec transport these selectors are
> from the outer header.

Agreed. It's exactly that difference that allows IPIP+transport
to support dynamic routing over per-hop IPSEC'd tunnels.

Joe


References: