[IPsec] Query about SEq Number

Manish Aggarwal <maaggarwal@gmail.com> Fri, 18 September 2009 15:34 UTC

Return-Path: <maaggarwal@gmail.com>
X-Original-To: ipsec@core3.amsl.com
Delivered-To: ipsec@core3.amsl.com
Received: from localhost (localhost [127.0.0.1]) by core3.amsl.com (Postfix) with ESMTP id 377EF3A691A for <ipsec@core3.amsl.com>; Fri, 18 Sep 2009 08:34:42 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.598
X-Spam-Level:
X-Spam-Status: No, score=-2.598 tagged_above=-999 required=5 tests=[BAYES_00=-2.599, HTML_MESSAGE=0.001]
Received: from mail.ietf.org ([64.170.98.32]) by localhost (core3.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id x-ZVh45P7kE4 for <ipsec@core3.amsl.com>; Fri, 18 Sep 2009 08:34:41 -0700 (PDT)
Received: from mail-yw0-f192.google.com (mail-yw0-f192.google.com [209.85.211.192]) by core3.amsl.com (Postfix) with ESMTP id 5C2103A68DA for <ipsec@ietf.org>; Fri, 18 Sep 2009 08:34:41 -0700 (PDT)
Received: by ywh30 with SMTP id 30so1425107ywh.31 for <ipsec@ietf.org>; Fri, 18 Sep 2009 08:35:33 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=gamma; h=domainkey-signature:mime-version:received:date:message-id:subject :from:to:content-type; bh=FPjNX4HlOlnmiFQ2FV7+Vzek0El7dA4gz0eCRi4ox1M=; b=Y5KrTWs4Ue0F/SIJzUXWFNSndCN6bXA5504GY6LmsaZIc1YHLXA97Ud787aK8KwMsy 9rxuaRRc/d3c5t+4J+jEDPk/jjRkAWC6HjjFu+c/ExfOh/1AjJAImAzRRTrsfk4F0Es8 xmMEW9qqVV7eq/WGz34X35LQuHclMYhP2bVnM=
DomainKey-Signature: a=rsa-sha1; c=nofws; d=gmail.com; s=gamma; h=mime-version:date:message-id:subject:from:to:content-type; b=gr48OHE0p9XGT6pl/Oi0CWVUy8SPg8xGYl2ybzCqrYhryM6dPYIAdD778HYl+yKju1 pAE0twqLOn6wzolPSglObDohTG+BJN83HiiTKdvAgs9Zlj2SHFSV2Y8lLLoxT4dx7o34 wBznsi8KakejA4tDSSqIO8n21oOlp9J+Pbzpg=
MIME-Version: 1.0
Received: by 10.150.55.31 with SMTP id d31mr3566829yba.147.1253288133006; Fri, 18 Sep 2009 08:35:33 -0700 (PDT)
Date: Fri, 18 Sep 2009 10:35:32 -0500
Message-ID: <329767350909180835q3b6c3690g40f2e77702e992e8@mail.gmail.com>
From: Manish Aggarwal <maaggarwal@gmail.com>
To: "ipsec@ietf.org" <ipsec@ietf.org>
Content-Type: multipart/alternative; boundary="000e0cd72266f8149c0473dbe171"
Subject: [IPsec] Query about SEq Number
X-BeenThere: ipsec@ietf.org
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Discussion of IPsec protocols <ipsec.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/listinfo/ipsec>, <mailto:ipsec-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ipsec>
List-Post: <mailto:ipsec@ietf.org>
List-Help: <mailto:ipsec-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ipsec>, <mailto:ipsec-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 18 Sep 2009 15:34:42 -0000

HI,
I have a query about the Sequence number in the ESP Header.
If for any packet, the receiver finds the seq number as ZERO, what is the
desired behavior..?

Should this result in the anti-replay check failure..?
Should this be treated as a corrupted packet..?

Appreciate your inputs.


Thanks
Manish