[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: RFC 2401 section 5.2.1



> Obscured from whom? Don't transport mode and tunnel mode packets look
> identical to a passive evesdropper since the Next Header field is encrypted? 
> (Assuming you're not doing AH, or NULL ESP, which from your previous 
> statements seems plausible).

well, there's always traffic analysis on minimum packet lengths,
assuming that some minimum-length ack-only TCP segments will be in the
traffic mix, and ipcomp and/or more-than-minimal padding aren't in
use..

					- Bill


References: