March 12, 2002
Practical Aspects of Modern Cryptography
34
IPSEC ESP and NAT
n
Can change IP header in special cases only
n
Special TCP/UDP ignores pseudo header used in
checksum calculation
n
Port information encrypted!
n
Can’t change ESP header because integrity hash
coverage
Data
TCP Hdr
ESP Hdr
Orig IP Hdr
ESP Trailer
ESP Auth
encrypted
integrity hash coverage