An Improved IPSec Protocol Scheme for the Problem of ICMP Packet Processing

胡少凤,李之棠
DOI: https://doi.org/10.3969/j.issn.1007-130x.2004.02.004
2004-01-01
Abstract:When IPSec is used in the tunneling mode, an additional external tunnel IP header to the initial IP packet is adjoined, in which the source and destination addresses are pointed to the original and final nodes that implement IPSec protocols respectively. This causes the router in packet transferring cannot forward correctly the ICMP error packets generated by its encapsulated IP data packets on the Internet. This is a hard nut to crack and there is now no mature and feasible scheme. The improved IPSec protocol scheme for this problem can give a satisfactory resolution without decreasing the efficiency of the current IPSec.
What problem does this paper attempt to address?