Re: About UDP Encapsulation of IPsec Packets

Ari Huttunen <Ari.Huttunen@f-secure.com> Tue, 23 April 2002 11:27 UTC

Received: from lists.tislabs.com (portal.gw.tislabs.com [192.94.214.101]) by above.proper.com (8.11.6/8.11.3) with ESMTP id g3NBRaa05436; Tue, 23 Apr 2002 04:27:36 -0700 (PDT)
Received: by lists.tislabs.com (8.9.1/8.9.1) id GAA13511 Tue, 23 Apr 2002 06:21:03 -0400 (EDT)
Message-ID: <3CC53899.E39D1F3A@F-Secure.com>
Date: Tue, 23 Apr 2002 13:34:01 +0300
From: Ari Huttunen <Ari.Huttunen@f-secure.com>
Organization: F-Secure Corporation
X-Mailer: Mozilla 4.79 [en] (Windows NT 5.0; U)
X-Accept-Language: en
MIME-Version: 1.0
To: Jerry Yao <jerryyao@mail.jl.cn>
CC: ipsec@lists.tislabs.com
Subject: Re: About UDP Encapsulation of IPsec Packets
References: <002401c1e9ce$61e46f60$04a7c6ca@server>
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
X-OriginalArrivalTime: 23 Apr 2002 10:34:05.0004 (UTC) FILETIME=[643F68C0:01C1EAB2]
Sender: owner-ipsec@lists.tislabs.com
Precedence: bulk

Jerry Yao wrote:
> 
> I read the IETF draft "UDP Encapsulation of IPsec Packets" and I have a question about it.
>     If I receive a packet from the communication peer who behind NAT, and the packet is Transport Mode ESP Encapsulation:
> 
>          -------------------------------------------------------------
>    IPv4  |orig IP hdr  | UDP | Non-| ESP |     |      |   ESP   | ESP|
>          |(any options)| Hdr | IKE | Hdr | TCP | Data | Trailer |Auth|
>          -------------------------------------------------------------
>                                          |<----- encrypted ---->|
>                                    |<------ authenticated ----->|
> 
>    Now I don't know the original IP address of the communication peer, How can I locate the corresponding sa to decrypt or authenticate the ESP packet?

RFC-2401:
> A security association is uniquely identified by a triple consisting
>    of a Security Parameter Index (SPI), an IP Destination Address, and a
>    security protocol (AH or ESP) identifier. 

Ari

-- 
"They that can give up essential liberty to obtain a little 
temporary safety deserve neither liberty nor safety." - Benjamin Franklin

Ari Huttunen                   phone: +358 9 2520 0700
Software Architect             fax  : +358 9 2520 5001

F-Secure Corporation       http://www.F-Secure.com 

F(ully)-Secure products: Securing the Mobile Enterprise