In IPsec, what does the Authentication Header (AH) protect, what does ESP protect, and why is ESP the one deployed?
answer
- two protocols straight on IP
- one authenticates, one also encrypts
- immutable header fields in the ICV
- MUST versus MAY in RFC 4301
basics
~20 sAH (IP protocol 51) authenticates the payload plus the IP header fields that do not change in transit, and encrypts nothing. ESP (protocol 50) encrypts and normally authenticates its own contents, not the outer header, and meets almost every need.
solid answer
~40 sBoth are IPsec security protocols carried directly over IP. `AH` (protocol 51, RFC 4302) gives integrity, data-origin authentication and optional anti-replay over the payload *and* the immutable fields of the IP header in front of it — version, lengths, protocol, source and destination address — while zeroing the fields routers change, such as TTL and the header checksum. It never encrypts. `ESP` (protocol 50, RFC 4303) offers the same services plus confidentiality, but its integrity check starts at its own SPI and does not reach back into the outer IP header. Because ESP with `ENCR_NULL` can provide integrity alone, RFC 4301 makes ESP a MUST and AH only a MAY — and AH's coverage of the addresses is exactly what a NAT breaks.
go deeper
Recall the pair cleanly: AH is protocol 51 and authenticates without encrypting; ESP is protocol 50 and encrypts, normally with authentication too.
Explain exactly which bytes each one covers: AH's ICV over immutable IP header fields with mutable ones zeroed, ESP's ICV from the SPI through the trailer and no further.
Show why ESP displaced AH in practice: ESP with NULL encryption covers integrity-only needs, AH cannot cross a NAT, and RFC 4301 made AH optional.
Be ready to argue when outer-header integrity is worth AH's cost, and why the specifications concluded it almost never is.
## Two security protocols directly on IP IPsec protects traffic at the network layer with two security protocols: the **Authentication Header** (`AH`, RFC 4302) and the **Encapsulating Security Payload** (`ESP`, RFC 4303), both framed by the architecture in RFC 4301. These three replaced RFC 2402, RFC 2406 and RFC 2401. Neither is natively carried inside TCP or UDP: the IP header in front of them names them directly, with protocol number **51** for AH and **50** for ESP. Both share two fields: - the **Security Parameters Index** (`SPI`, 32 bits), a label the receiver chose that tells it which security association — the negotiated keys and algorithms — applies; - a 32-bit **Sequence Number**, which a receiver may use to reject replayed packets. Everything else about them differs, and the difference is *which bytes each one protects, and how*. ## What AH protects AH computes an **Integrity Check Value** (`ICV`) — a keyed message authentication code — over three things: the IP header fields that are immutable in transit (or predictable at the receiver), the AH header itself with its ICV field zeroed, and everything after AH, which is assumed not to change. Fields that routers legitimately rewrite are set to zero before the computation, so ordinary forwarding does not break the check. RFC 4302 classifies the IPv4 base header like this: | Covered (immutable) | Zeroed for the ICV (mutable) | |---|---| | Version, Internet Header Length, Total Length | DSCP and ECN | | Identification, Protocol | Flags, Fragment Offset | | Source Address, Destination Address | TTL, Header Checksum | (A destination address rewritten by source routing is *mutable but predictable*: the sender puts the final value into the computation.) AH provides **integrity**, **data-origin authentication** and, at the receiver's discretion, **anti-replay**. It provides **no confidentiality**: every byte after the AH header crosses the network readable. ## What ESP protects ESP wraps the data it protects rather than standing beside it: 1. `SPI` (4 bytes) and `Sequence Number` (4 bytes), sent in the clear; 2. **Payload Data**, beginning with an initialisation vector when the cipher needs one; 3. the **ESP trailer** — `Padding` (0-255 bytes), `Pad Length` (1 byte) and `Next Header` (1 byte); 4. the `ICV`, when integrity is in use. The ciphertext covers the payload and the trailer. The integrity check covers the SPI, the sequence number, the payload and the trailer — and stops there. It does **not** reach back into the IP header in front of ESP. When ESP carries a whole inner IP packet, that inner header is part of the payload and is protected; the outer header never is. ## Side by side | | AH | ESP | |---|---|---| | IP protocol number | 51 | 50 | | Confidentiality | none | yes, unless NULL encryption is chosen | | Integrity and origin authentication | yes | yes, with an integrity algorithm or an AEAD cipher | | Covers the outer IP header | its immutable fields | no | | Anti-replay | optional, receiver's choice | optional, receiver's choice | | Status in RFC 4301 | implementations MAY support | implementations MUST support | ## Why ESP is the one you meet - **It does both jobs.** ESP gives confidentiality and integrity in one header. RFC 8221 calls an AEAD cipher such as `ENCR_AES_GCM_16` the fastest and most modern way to get both, with the cipher's tag serving as the ICV. - **It can do AH's job.** With `ENCR_NULL`, ESP authenticates without encrypting. RFC 4301 downgraded AH to MAY because "there are very few contexts in which ESP cannot provide the requisite security services". - **It survives address translation.** AH's ICV includes the addresses a NAT rewrites, so translated AH packets fail verification. ESP's ICV does not include them, and ESP can be carried inside UDP to cross a translator. - **Stacking them is discouraged.** RFC 8221 lists ESP for confidentiality plus AH for authentication as NOT RECOMMENDED: slower, more header bytes and a smaller effective MTU. ## Two traps in the short answer - **"AH encrypts the header."** It encrypts nothing; it authenticates part of the header. - **"ESP without integrity is fine."** RFC 4301 marks confidentiality without integrity NOT RECOMMENDED, and RFC 8221 says encryption without authentication MUST NOT be used. Integrity is what stops an attacker flipping bits in ciphertext they cannot read. The answer an interviewer wants in one breath: AH authenticates the payload and the unchanging parts of the IP header and encrypts nothing; ESP encrypts and authenticates its own contents but not the outer header; ESP is mandatory, AH optional, and NAT is why AH faded.
- If ESP does not authenticate the outer IP header, what stops someone forging an ESP packet with a spoofed source address?The ICV. It is keyed with the security association's secret, so without the key an attacker cannot produce a packet that verifies; a forged packet is discarded whatever its source address says. Re-sending a captured valid packet is caught by the anti-replay window. What ESP does not prove is that the outer address is the one the peer used, which is why receivers also check the decrypted traffic against the association's policy.
- Can AH and ESP be applied to the same packet, and should they be?RFC 4301 allows the two to be combined, and RFC 8221 lists ESP for confidentiality plus AH for authentication as one of three ways to get both properties. It marks that method NOT RECOMMENDED: it is the slowest, adds two headers and shrinks the effective MTU, and some configurations of ESP-without-authentication under AH have been shown insecure. ESP with an AEAD cipher such as `ENCR_AES_GCM_16` does both in one pass.
AH is a notary's stamp pressed across a postcard and its address label: anyone can read the card, and re-addressing it voids the stamp. ESP is a sealed, stamped envelope posted inside an outer envelope whose address the seal does not cover.
saying these in an interview costs you the question
- AH encrypts the IP header while ESP encrypts the payload.
- ESP's integrity check covers the outer IP source and destination addresses.
- AH signs the TTL, so every router hop would break it.
- Running ESP with encryption and no integrity algorithm is a normal choice.
- IKE is the protocol that encrypts the data packets in an IPsec tunnel.