|
Answer» IPSEC uses two DIFFERENT protocols defined by IETF (Internet Engineering Task Force): AH (Authentication Header) and ESP (ENCAPSULATING Security Payload) | AH Protocol | ESP Protocol |
|---|
| As of now, the AH protocol only provides authentication (data origin authentication, replay protection, and data integrity). | With the ESP protocol, authentication (data origin authentication, replay protection, and data integrity) and data confidentiality (encryption) are all provided. You can use ESP with confidentiality only, with authentication only, or with both confidentiality and authentication. | | It authenticates the outer IP header as well as the IP packet as a whole. | Only the IP datagram portion of the IP packet is authenticated by ESP authentication. |
|