Re: Integrity protection in IPSec VPN GW

Siddhartha Jain <[email protected]> Sun, 26 Sep 2004 17:04:16 +0100 (BST)
Newsgroups gmane.comp.security.vpn
Message-ID <[email protected]>
 --- Son Phan <[email protected]> wrote: 
> I heard that IPSec VPN GW provides only
> confidentiality 
> service and doesn't  provide integrity protection.

Where did you hear that?

ESP and AH, both provide integrity by adding a hash of
the payload. 

RFC 2402, pages 2 and 3:

    The Authentication Header is used to provide
connectionless integrity and data origin
authentication for IP datagrams (hereafter referred to
as just "authentication"), and to provide protection
against replays. This latter, optional service may be
selected, by the receiver, when a Security Association
is established. (Although the default calls for the
sender to increment the Sequence Number used for
anti-replay, the service is effective only if the
receiver checks the Sequence Number.) AH provides
authentication for as much of the IP header as
possible, as well as for upper level protocol data.
However, some IP header fields may change in transit
and the value of these fields, when the packet arrives
at the receiver, may not be predictable by the sender.
The values of such fields cannot be protected by AH.
Thus the protection provided to the IP header by AH is
somewhat piecemeal.

    AH may be applied alone, in combination with the
Encapsulating Security Payload (ESP), or in a nested
fashion through the use of tunnel mode. Security
services can be provided between a pair of
communicating hosts, between a pair of communicating
security gateways, or between a security gateway and a
host. ESP may be used to provide the same security
services, and it also provides a confidentiality
(encryption) service. The primary difference between
the authentication provided by ESP and AH is the
extent of the coverage. Specifically, ESP does not
protect any IP header fields unless those fields are
encapsulated by ESP (tunnel mode).

RFC 2401, page 10:

    AH offers an anti-replay (partial sequence
integrity) service at the discretion of the receiver,
to help counter denial of service attacks. AH is an
appropriate protocol to employ when confidentiality is
not required (or is not permitted, e.g , due to
government restrictions on use of encryption). AH also
provides authentication for selected portions of the
IP header, which may be necessary in some contexts.
For example, if the integrity of an IPv4 option or
IPv6 extension header must be protected en route
between sender and receiver, AH can provide this
service (except for the non-predictable but mutable
parts of the IP header.)

Read the relevant RFCs for more info.

Hope this helps,

Siddhartha



	
	
		
___________________________________________________________ALL-NEW Yahoo! Messenger - all new features - even more fun!  http://uk.messenger.yahoo.com