Re: New issue 17: Full connectivity

Stephen Kent <[email protected]>
Newsgroups gmane.ietf.mobike
Message-ID <p06110402bd63953869a2@[128.89.89.75]>
At 12:27 PM -0700 9/6/04, Srinivasa Rao Addepalli wrote:
>Umm... I guess it depends on how IPSec is implemented.
>
>At the originitaing security gateway must know the remote peer IP 
>address and uses
>it as Destination IP address.

right.

>On the receiving end, some implementations would only check if the destination
>IP address of the received packet is its local IP address. If so, it 
>consumes the
>packet and if not, the packet is forwarded. Some implementation 
>might go beyond
>this and might even look for exact match.

If the destination is a security gateway, it must distinguish between 
IPsec traffic addressed to it and IPsec (or non-IPsec) traffic 
addressed to hosts behind it, and thus potentially bypassed. So, in 
that context, it is necessary to pay attention to the destination 
address!

Steve
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.