[hipl-users] Re: ESP BEET mode vs ESP

  • From: "VÃisÃnen Teemu" <teemuuolevivaisanen@xxxxxxxxx>
  • To: hipl-users@xxxxxxxxxxxxx
  • Date: Tue, 23 May 2006 16:49:59 +0300

Hi.

I think I found reason that causes the difference:

With setkey -D I can see, that HIP ESP BEET has:
esp mode=transport spi=... reqid=...
       E: aes-cbc  ...
       A: hmac-sha1 ...

and IPsec ESP:
esp mode=transport spi=... reqid=...
       E: aes-cbc  ...

,so A: hmac-sha1 is missing.

I bet I'll get same packet sizes when hmac-sha1 is inserted in ESP.

-Teemu VÃisÃnen


2006/5/23, VÃisÃnen Teemu <teemuuolevivaisanen@xxxxxxxxx>:
Hi.

I use different machines in HIP ESP BEET mode and IPsec ESP transport
mode cases.

Actual data without any protection are same in both cases (UDP packets
with same, known sizes).

IPsec ESP transport mode SAs are set up with setkey.

I'm using HITs / IPv6 addresses.

Thank you for help.

-Teemu VÃisÃnen


---------- Forwarded message ---------- From: Diego Beltrami <Diego.Beltrami@xxxxxxx> Date: 23.5.2006 15:04 Subject: [hipl-users] Re: ESP BEET mode vs ESP To: hipl-users@xxxxxxxxxxxxx Cc: hipl-users@xxxxxxxxxxxxx


This is something to be analyzed in more details. As Miika mentioned, could you please elaborate more?

Basically the inner addresses shouldn't give this difference as I suppose you
are using IPv6 addresses in both cases.

Thank you,

--
Diego


> > Are you sending the same kind of data in both cases in exactly the same > way? > > > Clarification: > > > > I'm using HIPL with ESP BEET mode and IPsec ESP transport mode. > > > > -Teemu VÃisÃnen > > > > > > 2006/5/23, VÃisÃnen Teemu <teemuuolevivaisanen@xxxxxxxxx>: > >> Hi. > >> > >> When using HIPL with ESP BEET mode and IPsec ESP with same encryption > >> algorithms, ESP BEET packets are 12 bytes larger than in IPsec ESP. > >> > >> Is this result correct? Is this caused by inner addresses? > >> > >> -Teemu VÃisÃnen > >> > > > > -- > Miika Komu miika@xxxxxx http://www.iki.fi/miika/

Other related posts: