Re: Need some clarification on how to "locate the start of theFPDU unambiguously"
"Michael C. Cambria" <[email protected]> Tue, 30 Nov 2004 09:51:45 -0500
| Newsgroups | gmane.ietf.rddp |
|---|---|
| Message-ID | <[email protected]> |
Caitlin Bestler wrote: > Keep in mind that "CRC suppression" does not eliminate the field, > only generating it and checking it. > > So my reading has always been that when CRCs are "suppressed" > that the CRC field is always "valid". This has been my assumption as well. > Given the scenarios identified for suppressing CRCs, when there > is equivalent protection from IPSEC or something else, I think > it is also clear that this was the intent. Since I'm on the subject of making assumptions explicit... When IPsec is mentioned in this context, doesn't it specifically mean IPsec with Authentication (or Authentication & Encryption)? IPsec with Encryption alone isn't a substitute for CRC32c. This is also assuming that the IPsec SPD is setup to ensure that this policy will happen, e.g. there is no way for the remote peer to negotiate the security policy "down". Regards, MikeC