FW: IPCOMP and IPSEC
Stephen Waters <Stephen.Waters@digital.com> Thu, 28 May 1998 17:44 UTC
Received: (from majordom@localhost) by portal.ex.tis.com (8.8.2/8.8.2) id NAA28993 for ipsec-outgoing; Thu, 28 May 1998 13:44:23 -0400 (EDT)
Message-ID: <250F9C8DEB9ED011A14D08002BE4F64C01959181@wade.reo.dec.com>
From: Stephen Waters <Stephen.Waters@digital.com>
To: Roy Pereira <rpereira@TimeStep.com>
Cc: ipsec@tis.com, ippcp@external.cisco.com
Subject: FW: IPCOMP and IPSEC
Date: Thu, 28 May 1998 18:55:40 +0100
MIME-Version: 1.0
X-Mailer: Internet Mail Service (5.5.1960.3)
Content-Type: text/plain
Sender: owner-ipsec@ex.tis.com
Precedence: bulk
Ah, so there is some confusion then. I think (thought) the right thing to do was put the IPCOMP header outside the original IP header though - that makes it obvious that the peer SG need to strip it off before forwarding the original packet. If the IPCOMP was inserted after IP1 by a SG, how would the receiving SG know whether to extract it again - it looks identical to a packet that has been compression by the original host. Steve. IPComp may be added by a security gateway just like IPSec ESP/AH is added. It would probably look like this though: [IP2] [ESP spi+replay+iv] [IP1] [IPCOMP] [TCP] [data] [ESP padding+next protocol+auth] > -----Original Message----- > From: Stephen Waters [mailto:Stephen.Waters@digital.com] <mailto:[mailto:Stephen.Waters@digital.com]> > Sent: Wednesday, May 27, 1998 6:19 PM > To: ippcp@external.cisco.com; <mailto:ippcp@external.cisco.com;> ipsec@tis.com <mailto:ipsec@tis.com> > Subject: IPCOMP and IPSEC > > > > Is IPCOMP restricted for use by Hosts (at packet origin), or can it be > appended by a Security Gateway as part of the process of > adding an IPSEC > tunnel header? > > e.g. > > Original host packet [IP1][TCP][data] > > After passing through a security gateway/IP tunnel: > > [IP2][ESP][IPCOMP][IP1][TCP][data][padding/next protocol][ESP auth] > > > If this is supported, is it detailed anywhere? For example, if an > Explicit IV is used, would it come after the ESP header or after the > IPCOMP header? > > > > > > Stephen Waters > DEVON, UK > > National: 01548 551012 / 550474 > International: 44 1548 551012 / 550474 > Stephen.Waters@Digital.com >
- IPCOMP and IPSEC Stephen Waters
- Re: IPCOMP and IPSEC Daniel Harkins
- Re: IPCOMP and IPSEC Vach Kompella
- Re: IPCOMP and IPSEC Naganand Doraswamy
- RE: IPCOMP and IPSEC Roy Pereira
- Re: IPCOMP and IPSEC Daniel Harkins
- FW: IPCOMP and IPSEC Stephen Waters
- RE: IPCOMP and IPSEC Roy Pereira
- Re: IPCOMP and IPSEC Daniel Harkins
- RE: IPCOMP and IPSEC Roy Pereira
- Re: IPCOMP and IPSEC Marc Hasson
- Re: IPCOMP and IPSEC Daniel Harkins
- Re: IPCOMP and IPSEC Marc Hasson
- Re: IPCOMP and IPSEC Saroop Mathur
- RE: IPCOMP and IPSEC Stephen Waters
- Re: IPCOMP and IPSEC Eric Dean
- RE: IPCOMP and IPSEC Avram Shacham
- RE: IPCOMP and IPSEC Avram Shacham
- RE: IPCOMP and IPSEC Eric Dean
- RE: IPCOMP and IPSEC Stephen Waters
- RE: IPCOMP and IPSEC Eric Dean
- RE: IPCOMP and IPSEC Eric Dean
- Re: IPCOMP and IPSEC Stephen Kent
- RE: IPCOMP and IPSEC Robert Moskowitz
- RE: IPCOMP and IPSEC Avram Shacham
- RE: IPCOMP and IPSEC Paul Koning