[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: Increased sequence number in ESP/AH
At 4:02 PM -0500 1/23/01, Andrea Colegrove wrote:
>Steve,
> How does this address freshness (anti-replay)?
>
> Is this intended only as a useful feature for high-speed devices that may
>need additional SA lifetime?
>
>--- Andrea Colegrove
The extended sequence number is made part of the integrity check,
e.g., by virtually appending it to the payload, so that anti-replay
is still offered to an SA that makes use of the extended sequence
numbers.
Steve
References: