> - in the DOI document there is a reference to using ESP with a NULL He's right. If a policy calls for tunneling, the mechanisms should be IP-in-IP encapsulation, plain and simple. In other words, it's not that ESP should be used with no encryption; it's that ESP should not be used at all! /ji