> On second thought, an implementation obviously shouldn't be sending a
> decryption of a packet inside of an ICMP error message, so this case
> is moot.
Not at all. Either you send the ICMP error back down the same SA as
the offending packet or, if the selectors don't permit that, you
negotiate a new SA to send the error.
This has been thought of before, although 2401 could be a lot clearer.
Matt
--------------------------------------------------------------------
IETF IPng Working Group Mailing List
IPng Home Page: http://playground.sun.com/ipng
FTP archive: ftp://playground.sun.com/pub/ipng
Direct all administrative requests to [EMAIL PROTECTED]
--------------------------------------------------------------------
- ICMP and unknown extension headers? Markku Savela
- Re: ICMP and unknown extension headers... JINMEI Tatuya / $B?@L@C#:H(B
- Re: ICMP and unknown extension hea... Markku Savela
- Re: ICMP and unknown extension headers... Steve Deering
- Re: ICMP and unknown extension hea... Erik Nordmark
- Re: ICMP and unknown extension... Steve Deering
- Re: ICMP and unknown exten... Steve Deering
- Re: ICMP and unknown ... Matt Crawford
- Re: ICMP and unkn... Bill Sommerfeld
- Re: ICMP and ... Markku Savela
- Re: ICMP and ... JINMEI Tatuya / $B?@L@C#:H(B
- Re: ICMP and ... Markku Savela
- Re: ICMP and ... JINMEI Tatuya / $B?@L@C#:H(B
- Re: ICMP and unknown exten... Erik Nordmark
- Re: ICMP and unknown extension... Niels M�ller
- Re: ICMP and unknown exten... itojun
- Re: ICMP and unknown ... Niels M�ller
- Re: ICMP and unkn... Steve Deering
