[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: Inbound processing of ESP packet



On Mon, 15 Jan 2001, Stephen Kent wrote:
> Steve Bellovin is right, Henry. A LAN interface may include padding 
> after the end of the IP packet...

Please note what I said about the lower-level value possibly being
supplemented by information from the IP total length.

The IP total length field is authoritative, in a realistic sense, only if
the lower levels actually delivered at least that much data.  Otherwise
the lower-level count *is* authoritative about how much data is present,
and the discrepancy between that and the IP length indicates a lower-level
transmission error. 

The only statement of Steve B's that I actually disagree with is his
assertion that I am wrong. :-)  We're saying the same thing in two
different ways.

                                                          Henry Spencer
                                                       henry@spsystems.net



References: