In tunnel mode why options are not copied to outer IP header
Padma Goli <padma@trinc.com> Fri, 19 June 1998 04:13 UTC
Received: (from majordom@localhost) by portal.ex.tis.com (8.8.2/8.8.2) id AAA13469 for ipsec-outgoing; Fri, 19 Jun 1998 00:13:01 -0400 (EDT)
Message-Id: <3.0.1.32.19980619094828.006dbdd4@172.16.1.10>
X-Sender: padma@172.16.1.10
X-Mailer: Windows Eudora Light Version 3.0.1 (32)
Date: Fri, 19 Jun 1998 09:48:28 +0500
To: ipsec@ex.tis.com
From: Padma Goli <padma@trinc.com>
Subject: In tunnel mode why options are not copied to outer IP header
Cc: kseo@bnn.com
Mime-Version: 1.0
Content-Type: text/plain; charset="us-ascii"
Sender: owner-ipsec@ex.tis.com
Precedence: bulk
Hi Karen, I have a pending ( I wanted to ask this question long before) question ( rather a clarification ) in draft-ietf-ipsec-arch-sec-04.txt : In section 5.1.2 Header Construction for Tunnel Mode: 1) It is said that options are never copied to outer IP header from the inner IP header. Why is it so ? 2) According to that a user cannot have tunnel mode security between two endpoints along with strict routing( or any options ). Is it so. But having Strict routing along with security ( I am speaking in the context of tunnel mode ) provided, makes a lot of sense because we can avoid the datagram traversal along a previously known insecured route or a rival's router. 3) We are doing options processing after IpsecOutbound processing. In case of tunnel mode even though the hidden inner IP header had Options set as they are not visible from outer IP header, we are just processing as if no options was present in the inner IP header. Is this way correct. Even if option processing is done before Ipsecoutbound processing, options of the inner IP header will be processed before encapsulation by the IPSEC only at the sender, but the intermediate security gateways acting as just routers will not be doing any options processing at all. If this what is thought of? Hoping an immediate reply. Thanks, Padma Goli. *~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~| *~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~| *Padma Goli | *Rendzevous Onchip Pvt Ltd. | *Secunderbad | *Phone No : (040)7742606 | (040)7740406 | *email address : padma@trinc.com | *~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~|
- In tunnel mode why options are not copied to oute… Padma Goli
- Re: In tunnel mode why options are not copied to … Charles Lynn