[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: Inbound processing of ESP packet
On Mon, 15 Jan 2001, Stephen Kent wrote:
> Steve Bellovin is right, Henry. A LAN interface may include padding
> after the end of the IP packet...
Please note what I said about the lower-level value possibly being
supplemented by information from the IP total length.
The IP total length field is authoritative, in a realistic sense, only if
the lower levels actually delivered at least that much data. Otherwise
the lower-level count *is* authoritative about how much data is present,
and the discrepancy between that and the IP length indicates a lower-level
transmission error.
The only statement of Steve B's that I actually disagree with is his
assertion that I am wrong. :-) We're saying the same thing in two
different ways.
Henry Spencer
henry@spsystems.net
References: