> >3.3 IPSEC > > ESP is purely optional and should be implemented as Protocol 50. SPI > works as port numbers for resource reservation (if any). AH is > forbidden because its functionality overridden by ESP and its SPI is > not located at port number part. If my understanding is correct, integrity check including IP header cannot be done with ESP. AH can do that. Hiroki Ishibashi