softwire-4----Page:19
1  2  3  4  5  6  7  8  9  10  11  12  13  14  15  16  17  18  19  20  21 

Security?
Scope is Internet traffic, not VPN traffic
If confidentiality or integrity is required inside the tunnel, it’s also required outside the tunnel, so no new confidentiality requirement
Spoofed encapsulation header is possible
but without the tunnel, a spoofed payload packet would be possible, so no new authentication requirement

PPT Version