jdancer wrote: » I would consider ESP and AH a bad design and if I am not mistaken may slow things down. As to why it was configured that way, I can only think of one answer: the person who configured it probably doesn't know that ESP offers AH. So, chalk it up to lack of knowledge on how IPSec really works.
fuz1on wrote: » Tunnel...
creamy_stew wrote: » I always thought that ESP/AH was choose 1. Where everyone would choose ESP. Is it at all possible to do ESP and Ah in the same tunnel?
fuz1on wrote: » It is possible but unpractical (NAT traversal); I just alluding to the fact that a tunnel would be like the best of both worlds.
creamy_stew wrote: » So, it seems pretty clear that not only can you use AH+ESP together, but you can also use AH in tunnel mode. Weird. I've never seen this in the wild.