I think there is something else I am missing here.

How does the receiving system 'know' that the packet is a diet-esp packet?

Protocol ID is ESP.  That is all we have.  Right after the IPv6 or IPv4 header comes the ESP header, but is it a regular ESP header with a 4-byte SPI or is it a dist-esp header with some other SPI size?

How is this done?

Is the source IP the 'key' that it is a diet-esp, and look at all the SAs associated with that source IP and hopefully find one that maps to at least the 1st byte or full 4 bytes?

What is the logic trigger?

And if it is the source IP, how might gateways and such mess things up.

Or am I back to needing a SCHC protocol ID to put in the Next Header field rather than ESP?

Confused here...

Bob

_______________________________________________
IPsec mailing list
IPsec@ietf.org
https://www.ietf.org/mailman/listinfo/ipsec

Reply via email to