[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: Simplifying IKE



On Wed, 8 Aug 2001, Francis Dupont wrote:
>    ...I believe the source route header is primarily used to see
>    what paths are broken in a network - using the process of elimination.

Actually, the source route header is increasingly frequently ignored (or
considered grounds for dropping the packet) by implementations, because of
its utility for various forms of attack. 

> PS: I am not in favor to reduce IPsec to VPNs, the thing which will happen
> if we remove AH then transport mode...

Can you explain that statement?  ESP tunnels can do everything AH or
transport mode can do, although sometimes at very slightly greater cost. 

                                                          Henry Spencer
                                                       henry@spsystems.net



Follow-Ups: References: