[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: mech-v2: decapsulation check updates



Hi,

On Sat, Feb 07, 2004 at 07:12:35AM +0900, Jun-ichiro itojun Hagino wrote:
> > On Thu, Feb 05, 2004 at 03:22:57PM -0000, Tom Petch wrote:
> > > A thought.  The day before you sent this, I heard an interesting
> > > presentation at RIPE-47 on tunnel discovery which used  host to router
> > > tunnels to find out how many tunnels
[..]
> > I've been there as well, and spent some time discussing this with the
> > author.
> 
> 	do you know why the author recommeded GRE?  there's no real difference
> 	between RFC2893 tunnel and GRE with respect to address spoofs and stuff,
> 	as far as i understand.

If I understood him correctly, because GRE can do sequence numbering and
keying.  So you need more information to successfully spoof that.

Gert Doering
        -- NetMaster
-- 
Total number of prefixes smaller than registry allocations:  58081  (57882)

SpaceNet AG                 Mail: netmaster@Space.Net
Joseph-Dollinger-Bogen 14   Tel : +49-89-32356-0
80807 Muenchen              Fax : +49-89-32356-299