HP-UX IPSec Overview

Authentication Header (AH)

IPv6 In IPv6 AH transport mode, IPSec inserts the AH after the following headers and extensions:

the basic IPv6 header

hop-by-hop options

any destination options needed to interpret the AH header

routing extensions

fragment extensions

The items listed below follow the AH:

any destination options needed only for the “final” destination and not needed to interpret the AH header

the IP data or payload (e.g., TCP or UDP packet)

The entire packet is used to calculate the authentication value. Mutable and unpredictable fields and options, such as timestamp and traceroute options, are assigned a zero value before calculating the authentication value.

Figure 1-2

AH in Transport Mode

Chapter 1

31