I can understand why this should be revisited, but it also requires a revision of RFC 2003. RFC 2401 already specifies some incompatible rules (e.g. for DF flag processing) that are in conflict with IPIP encapsulation as standardized in RFC 2003. (See draft-touch-ipsec-vpn-03.txt.) It may be useful to update 2401 and 2003 together.
we already anticipate updating 2401 to describe appropriate ECN handling. I also anticipate closer alignment with 2003; there has been a view that tunnel mode was intentionally different from IP-in-IP tunneling. I don't hold that view is necessarily true in all respects; tunnel mode is different in terms of offering certain controls to a security administrator to manage covert channels (which would not normally be an issue) and in ensuring that the receiver examines the right portions of the received packet re access controls. to the extent that there are no adverse security implications, IP-in-IP processing should be applicable in IPsec.
Lars -- Lars Eggert <larse@xxxxxxx> Information Sciences Institute http://www.isi.edu/larse/ University of Southern California
Attachment:
smime.p7s
Description: S/MIME Cryptographic Signature