We use AH when we want to perform integrity checks on our peer and the data it is sending. AH does not use encryption. IPSec implements AH by creating a shim header between Layer 2 and Layer 3. So you might say IPSec works at Layer 2.5 in the Open Systems Interconnect (OSI) model. The Layer 2.5 header is identified as in use by Layer 2, identifying the next layer protocol as protocol number 51. The AH header has a next protocol field, which identifies the next Layer 4 transport protocol in use, usually TCP or UDP.
|