Hi All,

  I was going through the IPSec Pass-through section on the "Cisco
ASA:All-in-One Firewall,IPS,Anti-X and VPN Adaptive security appliance"
book.My understanding from that section is ,IPSec pass-through supports only
the ESP protocol;it does not support the Authentication Header(AH)
Protocol.On the ipsec pass-through inspect map section,it has 2 different
security levels(high and low) to choose from.Under the actions on each
security level we choose,it has check for Maximum AH flows per client and AH
idle timeout.

My question is,what it means,when IPSEC pass-through supports only ESP and
not AH ,even though it has checks for AH.

Kindly help me to clarify the same.

Thanks for the help

Regards
Anantha Subaramanian Natarajan
_______________________________________________
For more information regarding industry leading CCIE Lab training, please visit 
www.ipexpert.com

Reply via email to