Re: address inertia

Henry Spencer <[email protected]>
Newsgroups gmane.network.freeswan.devel
Message-ID <[email protected]>
On Mon, 17 Feb 2003, Jim Carter wrote:
> I thought that, when one side receives traffic on a connection which is
> defective, (i.e. it never made that connection because it was just
> rebooted), it will give an error reply to the other side, which will
> immediately tear up the defective connection and try to rekey.

In the wonderful world of IPsec, it's not that simple.  How can you send
an error reply which the other end can *trust*?  If error replies are not
authenticated, the potential for denial-of-service attacks is mind-boggling.
And authenticating them, at reasonable cost, is seriously hard.

                                                          Henry Spencer
                                                       [email protected]
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.