26.10.2012 Views

Internet Security - Dang Thanh Binh's Page

Internet Security - Dang Thanh Binh's Page

Internet Security - Dang Thanh Binh's Page

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

254 INTERNET SECURITY<br />

IPv4<br />

IPv4<br />

IPv6<br />

IPv6<br />

IPv4<br />

IPv6<br />

orig IP hdr<br />

(any options)<br />

Before applying AH<br />

orig IP hdr<br />

TCP Data<br />

Authenticated except for mutable fields<br />

orig IP hdr<br />

(any options)<br />

After applying AH<br />

(a) AH transport mode for an IPv4 packet<br />

ext hdrs<br />

(if any)<br />

Before applying AH<br />

After applying AH<br />

TCP Data<br />

Authenticated except for mutable fields<br />

(b) AH transport mode for an IPv6 packet<br />

Authenticated except for mutable fields in the new IP hdr<br />

Authenticated except for mutable fields in the new IP hdr and its extension headers<br />

new IP hdr<br />

AH<br />

ext<br />

hdrs<br />

TCP Data<br />

hop-by-hop, dest,<br />

orig IP hdr<br />

routing, fragment<br />

AH dest TCP Data<br />

new IP hdr AH orig IP hdr TCP Data<br />

AH<br />

orig IP<br />

header<br />

(c) AH tunnel mode for typical IPv4 and IPv6 packets<br />

ext<br />

headers<br />

Figure 7.5 Transport mode and tunnel mode for AH authentication.<br />

TCP Data<br />

is selected and the service is effective only if the receiver checks the sequence number.<br />

The current key management options required for both AH and ESP are manual keying<br />

and automated keying via IKE.<br />

7.3.1 ESP Packet Format<br />

Figure 7.6 shows the format of an ESP packet and the fields in the header format are<br />

defined in the following.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!