Re: Can IPSec ESP be nested in another ESP?

Igor Pronin <[email protected]> Wed, 29 Sep 2004 10:10:14 +0300
Newsgroups gmane.comp.security.vpn
Organization Elma Oyj Electronic Trading
Message-ID <[email protected]>
Travis Watson wrote:
> Son,
> 
> I know that Checkpoint was talking about having an ability like that 
> with their client (encrypt/decrypt/then automatically re-encrypt by 
> policy), but I don't know if they have implemented it.
> 
> It seems like you could have people use their IPSec client through a b2b 
> tunnel easily enough though.  So:
> 
> 
> Users ------> firewall <--------IPSEC 
> tunnel------->firewall------>application server---------->target app
> 
> |---Site A------------| <--------  Internet ---------->| <-------  Site 
> B-----------------------------------|
> 
> Users w/IPSec client -----------------------------------------------| 
> terminate client tunnel --> hit target app
> 
> 
> The users would ride the b2b tunnel through to the application server.  
> It seems a little bit like overkill though.  I don't  know your specific 
> situation, but you could just as easily have a firewall rule allowing 
> IPSec clients in to your application server.
> 
> Good luck!
> 
> --Travis
> 
> 
> 
> Son Phan wrote:
> 
>> Hello,
>>
>> I understand that AH & ESP mode can be applied together for the same 
>> IP packet.
>>
>> However I don't know whether two ESP can be nested. The case is as below:
>>
>> PC-------------------------------VPN GW-------------Application Server 
>> (AS)
>> <<------ESP tunnel mode----->>
>> <<-------------ESP transport mode ------------------->>
>>
>> PC has remote access to some closed domain using via VPN GW. ESP 
>> tunnel mode is used here.
>> One of the application running on this PC want to use a service 
>> provided by an AS within this closed domain. However this service 
>> mandates the client to use ESP transmode mode to contact it.
>>
>> Can this scenario works?
>> Any extra requirement toward the IPSec implementation on PC?
>>
>> Thanks, Son

I tried to do something like that.

I.e. to tunnel IPSec through an IPSsec tunnel with Windows but did not 
succeed. I tried to use Nortel client (configured by my ISP) for the 
outer tunnel and Finnish made Secgo implementation (used by my employer)
http://www.secgo.com/
for the inside tunnel and the Windows native IPSec disabled. Did not 
work and I thaught that it may be too complicated or may be even impossible.

But luckily the IPSec tunnel of my ISP was dual functioning and 
understood PPTP, too.  So I configured the outside tunnel to use PPTP 
tunnel and IPSec runs within it. I have used it for about 2 years now 
and it works fine. Half a year ago I had to adjust Windows default MTU 
and Path MTU default values due to some mysterious change "somewhere" 
but after disabling in Windows Path MTU Discovery and fixing MTU down to 
1292 everything has run well now.

regards

Igor.Pronin at iki.fi