← Back to team overview

rohc team mailing list archive

Re: [Question #227455]: IPsec and ROHC

 

Question #227455 on rohc changed:
https://answers.launchpad.net/rohc/+question/227455

Didier Barvaux proposed the following answer:
Matthew,

> In case 1, in order for IP/ESP to be added to the encrypted data
> IPSec first needs to inspect the IP header of the data so it can
> pull out the original destination ip address, but in case 1 ROHC
> has removed that information prior to handing the data off to
> IPSec.

Yes, that's a problem if the IPsec tunneling packets use the same
destination IP address as the tunneled packets. However that's not
a problem if the tunnel uses another unrelated destination address.

Regards,
Didier

-- 
You received this question notification because you are a member of ROHC
Team, which is an answer contact for rohc.