[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: Increased sequence number in ESP/AH



At 4:02 PM -0500 1/23/01, Andrea Colegrove wrote:
>Steve,
>     How does this address freshness (anti-replay)?
>
>     Is this intended only as a useful feature for high-speed devices that may
>need additional SA lifetime?
>
>--- Andrea Colegrove

The extended sequence number is made part of the integrity check, 
e.g., by virtually appending it to the payload, so that anti-replay 
is still offered to an SA that makes use of the extended sequence 
numbers.

Steve



References: