Processing Inbound IPSec or non IPsec Trac From the lecture: 1. Determine if the packet contains an IPSec header. • If there is an IPSec header then extracts the SPI from the IPSec header, look up the SA in the SAD

and perform the appropriate AH/ESP processing.



.

If there is no SA referenced by the SPI, drop the packet

2. After the AH and/or ESP processing, determine if and how the packet should have been protected, this is again realized by performing a lookup in the SPD. • If the policy species "discard" then drop the packet. • If the protection of the packet did not match the policy, drop the packet.

3. If the packet had been properly secured, then deliver it. Now what about non-IPsec-protected incoming trac? In this case lookup diercly in the SPD to verify if there is a matching rule and if the packet is to be discarded or bypassed (the default), do so. Example 1:

In the example below when pinging from 192.0.0.3 to 192.0.0.12, the ICMP echo requests will go from 192.0.0.3 to 192.0.0.12 without IPSec protection as the SPD on 192.0.0.3 does not enforce this protection. On 192.0.0.12 using tcpdump we can see ICMP echo requests without IPSec protection. But we do not see any ICMP echo reply because the ICMP echo requests will be discarded before answering as they do not match the policy on 192.0.0.12.

Figure 1: On 192.0.0.3

Figure 2: On 192.0.0.12

1

2

Figure 3: ICMP echo requests on 192.0.0.12, without ICMP echo replies

Figure 4: Ping failure on 192.0.0.3

Example 2:

Now if we keep the same policy on 192.0.0.3 and change the policy on 192.0.0.12 to be:

Figure 5: On 192.0.0.12 The ping from 192.0.0.2 to 192.0.0.12 will be ok as illustrated the gure beside we can observe ICMP echo requests and ICMP echo responses on 192.0.0.12.

3

Figure 6: Ping from 192.0.0.3

Figure 7: Tcpdump on 192.0.0.12

If there is no SA referenced by the SPI, drop the packet ...

to 192.0.0.12 without IPSec protection as the SPD on 192.0.0.3 does not enforce this protection. On 192.0.0.12 using tcpdump we can see ICMP echo requests without IPSec protection. But we do not see any ICMP echo reply because the ICMP echo requests will be discarded before answering as they do not match the ...

269KB Sizes 0 Downloads 122 Views

Recommend Documents

pdf-1792\go-for-no-yes-is-the-destination-no-is-how-you-get-there ...
DOWNLOAD EBOOK : GO FOR NO! YES IS THE DESTINATION, NO IS HOW. YOU GET THERE BY RICHARD FENTON, ANDREA WALTZ PDF. Page 1 of 9 ...

There Is No Parkinson Disease
Movement Disorders Center, University of Maryland School of Medicine, Baltimore. (REPRINTED) ... “might call to question the definition given by Parkinson.

Where There Is No Doctor.pdf
... Karakalpak, Kazakh, Khmer, Kirundi, Korean,. Kwangali, Kyrgyz, Lao, Malayalam, Maranao, Marathi, Miskito, Mongolian, Mortlockese,. Nepali, Oriya, Oshivambo, Pashto, Pidgin, Portuguese, Quechua, Russian, Sepedi, Sebian,. Sgawkaren, Shan, Shuar, Si

PDF Download Porsche 70 Years: There Is No ...
... 227 o 46318 do 40723 Brasil 38043 da 37922 Da 35214 US 33367 Folha 29049 ... Porsche 70 Years: There Is No Substitute ,ebook reader software Porsche 70 ...... captures the full story of one of the world s leading automotive companies.

4 Why there almost certainly is no God
what can be called Einsteinian religion from supernatural religion. Einstein ...... in an old bearded man sitting on a cloud, so let's not waste any more time on that. ..... dered how the famous mathematician had managed to write his book without.

4 Why there almost certainly is no God
18 Poland Road, Glenfield, Auckland 10, New Zealand. RANDOM HOUSE SOUTH AFRICA (PTY) LTD. Isle of Houghton, Corner of Boundary Road &c Carse ...... in an old bearded man sitting on a cloud, so let's not waste any more time on that. I am not attacking