RFC 4891:Using IPsec to Secure IPv6-in-IPv4 Tunnel...
RFC-Ref

transport


Click on the red underlined text to get to the source

... IPsec can be used in two ways, in transport and tunnel mode; detailed discussion ...
... IPsec in Transport Mode ...
... In transport mode, the IPsec Encapsulating Security Payload (ESP) or ...
... This prevents threat (1) but not threat (2). IPsec in transport mode does not verify the contents of the payload itself where the IPv6 addresses ...
... IPv6 addresses are carried. That is, two nodes using IPsec transport mode to secure the tunnel can spoof the inner payload ...
... RFC3704]. In most implementations, a transport mode SA is applied to a normal IPv6-in-IPv4 ...
... the tunnel interface. (Transport mode is often also used in other kinds of tunnels such as Generic Routing Encapsulation ...
... As described in Section 5, using tunnel mode is more difficult than applying transport mode to a tunnel interface, and as a result this ...
... tunnel interface, and as a result this document recommends transport mode. Note that even though transport rather than tunnel mode ...
... interface, and as a result this document recommends transport mode. Note that even though transport rather than tunnel mode is recommended, an IPv6-in-IPv4 ...


... This section describes the SPD entries for setting up the IPsec transport mode SA to protect the IPv6 traffic ...
... The IPv6 traffic can be protected using transport or tunnel mode. There are many problems when using tunnel mode ...
... VLINK]. Because applying transport mode to protect a tunnel is a much simpler solution and also easily protects link-local ...
... IPsec Transport Mode ...
... Transport mode has typically been applied to L2TP, GRE, and other ...
... RFC3193], and [RFC4023] provide examples of applying transport mode to protect tunnel traffic that spans only a ...
... IPv4-TEP1 IPV4-TEP2 41 PROTECT(ESP,transport) Router2's SPD ...
... IPv4-TEP2 IPV4-TEP1 41 PROTECT(ESP,transport) In both SPD ...


... IPv6-in-IPv4 tunnel using either transport or tunnel mode. We observe that applying transport mode ...
... transport or tunnel mode. We observe that applying transport mode to a tunnel interface is the ...
... acceptable solution. Therefore, our primary recommendation is to use transport mode applied to a tunnel interface ...


... Touch, J., Eggert, L., and Y. Wang, "Use of IPsec Transport Mode for Dynamic Routing", RFC 3884, September 2004. ...


... tunnel interface) can be made to work, but it has reduced applicability, and the use of a transport mode tunnel is recommended instead. However, we will describe how the SSPD tunnel mode ...
... multicast, etc. will work through this tunnel. This mode is similar to transport mode. The SPDs must be interface ...
... IPsec processing when option (2) is chosen, whereas the operator has to enable it explicitly when transport mode or option (1) is chosen. In summary, there does not appear to be a standard solution in this ...
... limited set of features (e.g., no multicast) compared with a transport mode tunnel. ...
... fragment handling [RFC4301] may also be more difficult compared with transport mode and, depending on implementation, may need to be reflected in SPDs. ...



Google
Web
RFC-Ref