[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: RFC 2401 section 5.2.1



(Note mobile-ip dropped from addressees list.)

On Tue, 28 Nov 2000, Shoichi 'Ne' Sakane wrote:
> > ...It would be better if they could also work with ESP.
> 
> ESP can not protect all part of a IP packet...

Correct.  Neither can AH, although it protects slightly more than ESP. 
The question is whether it is wise for protocol designers to rely on the
extra portions AH protects.  Where possible, they should avoid that. 

> I believe we need AH in spite of the IP version.

Perhaps.  But the existence of protocols which depend on it should not be
advanced as a reason, unless it is first demonstrated that those protocols
fundamentally need AH and could not work with ESP.

                                                          Henry Spencer
                                                       henry@spsystems.net



Follow-Ups: References: