skip to content

AH vs ESP Headers

AH signs the packet including parts of the IP header but encrypts nothing; ESP encrypts its payload and can authenticate it too. Interviewers use the pair to see whether you know why NAT killed AH.

on this pageshow

questions

6

In IPsec, what does the Authentication Header (AH) protect, what does ESP protect, and why is ESP the one deployed?

level: juniorimportance: must knowfreq 45%

answer

  1. two protocols straight on IP
  2. one authenticates, one also encrypts
  3. immutable header fields in the ICV
  4. MUST versus MAY in RFC 4301

basics

~20 s

AH (IP protocol 51) authenticates the payload plus the IP header fields that do not change in transit, and encrypts nothing. ESP (protocol 50) encrypts and normally authenticates its own contents, not the outer header, and meets almost every need.

solid answer

~40 s

Both are IPsec security protocols carried directly over IP. `AH` (protocol 51, RFC 4302) gives integrity, data-origin authentication and optional anti-replay over the payload *and* the immutable fields of the IP header in front of it — version, lengths, protocol, source and destination address — while zeroing the fields routers change, such as TTL and the header checksum. It never encrypts. `ESP` (protocol 50, RFC 4303) offers the same services plus confidentiality, but its integrity check starts at its own SPI and does not reach back into the outer IP header. Because ESP with `ENCR_NULL` can provide integrity alone, RFC 4301 makes ESP a MUST and AH only a MAY — and AH's coverage of the addresses is exactly what a NAT breaks.

go deeper

for a junior

Recall the pair cleanly: AH is protocol 51 and authenticates without encrypting; ESP is protocol 50 and encrypts, normally with authentication too.

for a middle

Explain exactly which bytes each one covers: AH's ICV over immutable IP header fields with mutable ones zeroed, ESP's ICV from the SPI through the trailer and no further.

for a senior

Show why ESP displaced AH in practice: ESP with NULL encryption covers integrity-only needs, AH cannot cross a NAT, and RFC 4301 made AH optional.

for a principal

Be ready to argue when outer-header integrity is worth AH's cost, and why the specifications concluded it almost never is.

## Two security protocols directly on IP IPsec protects traffic at the network layer with two security protocols: the **Authentication Header** (`AH`, RFC 4302) and the **Encapsulating Security Payload** (`ESP`, RFC 4303), both framed by the architecture in RFC 4301. These three replaced RFC 2402, RFC 2406 and RFC 2401. Neither is natively carried inside TCP or UDP: the IP header in front of them names them directly, with protocol number **51** for AH and **50** for ESP. Both share two fields: - the **Security Parameters Index** (`SPI`, 32 bits), a label the receiver chose that tells it which security association — the negotiated keys and algorithms — applies; - a 32-bit **Sequence Number**, which a receiver may use to reject replayed packets. Everything else about them differs, and the difference is *which bytes each one protects, and how*. ## What AH protects AH computes an **Integrity Check Value** (`ICV`) — a keyed message authentication code — over three things: the IP header fields that are immutable in transit (or predictable at the receiver), the AH header itself with its ICV field zeroed, and everything after AH, which is assumed not to change. Fields that routers legitimately rewrite are set to zero before the computation, so ordinary forwarding does not break the check. RFC 4302 classifies the IPv4 base header like this: | Covered (immutable) | Zeroed for the ICV (mutable) | |---|---| | Version, Internet Header Length, Total Length | DSCP and ECN | | Identification, Protocol | Flags, Fragment Offset | | Source Address, Destination Address | TTL, Header Checksum | (A destination address rewritten by source routing is *mutable but predictable*: the sender puts the final value into the computation.) AH provides **integrity**, **data-origin authentication** and, at the receiver's discretion, **anti-replay**. It provides **no confidentiality**: every byte after the AH header crosses the network readable. ## What ESP protects ESP wraps the data it protects rather than standing beside it: 1. `SPI` (4 bytes) and `Sequence Number` (4 bytes), sent in the clear; 2. **Payload Data**, beginning with an initialisation vector when the cipher needs one; 3. the **ESP trailer** — `Padding` (0-255 bytes), `Pad Length` (1 byte) and `Next Header` (1 byte); 4. the `ICV`, when integrity is in use. The ciphertext covers the payload and the trailer. The integrity check covers the SPI, the sequence number, the payload and the trailer — and stops there. It does **not** reach back into the IP header in front of ESP. When ESP carries a whole inner IP packet, that inner header is part of the payload and is protected; the outer header never is. ## Side by side | | AH | ESP | |---|---|---| | IP protocol number | 51 | 50 | | Confidentiality | none | yes, unless NULL encryption is chosen | | Integrity and origin authentication | yes | yes, with an integrity algorithm or an AEAD cipher | | Covers the outer IP header | its immutable fields | no | | Anti-replay | optional, receiver's choice | optional, receiver's choice | | Status in RFC 4301 | implementations MAY support | implementations MUST support | ## Why ESP is the one you meet - **It does both jobs.** ESP gives confidentiality and integrity in one header. RFC 8221 calls an AEAD cipher such as `ENCR_AES_GCM_16` the fastest and most modern way to get both, with the cipher's tag serving as the ICV. - **It can do AH's job.** With `ENCR_NULL`, ESP authenticates without encrypting. RFC 4301 downgraded AH to MAY because "there are very few contexts in which ESP cannot provide the requisite security services". - **It survives address translation.** AH's ICV includes the addresses a NAT rewrites, so translated AH packets fail verification. ESP's ICV does not include them, and ESP can be carried inside UDP to cross a translator. - **Stacking them is discouraged.** RFC 8221 lists ESP for confidentiality plus AH for authentication as NOT RECOMMENDED: slower, more header bytes and a smaller effective MTU. ## Two traps in the short answer - **"AH encrypts the header."** It encrypts nothing; it authenticates part of the header. - **"ESP without integrity is fine."** RFC 4301 marks confidentiality without integrity NOT RECOMMENDED, and RFC 8221 says encryption without authentication MUST NOT be used. Integrity is what stops an attacker flipping bits in ciphertext they cannot read. The answer an interviewer wants in one breath: AH authenticates the payload and the unchanging parts of the IP header and encrypts nothing; ESP encrypts and authenticates its own contents but not the outer header; ESP is mandatory, AH optional, and NAT is why AH faded.

  • If ESP does not authenticate the outer IP header, what stops someone forging an ESP packet with a spoofed source address?
    The ICV. It is keyed with the security association's secret, so without the key an attacker cannot produce a packet that verifies; a forged packet is discarded whatever its source address says. Re-sending a captured valid packet is caught by the anti-replay window. What ESP does not prove is that the outer address is the one the peer used, which is why receivers also check the decrypted traffic against the association's policy.
  • Can AH and ESP be applied to the same packet, and should they be?
    RFC 4301 allows the two to be combined, and RFC 8221 lists ESP for confidentiality plus AH for authentication as one of three ways to get both properties. It marks that method NOT RECOMMENDED: it is the slowest, adds two headers and shrinks the effective MTU, and some configurations of ESP-without-authentication under AH have been shown insecure. ESP with an AEAD cipher such as `ENCR_AES_GCM_16` does both in one pass.

AH is a notary's stamp pressed across a postcard and its address label: anyone can read the card, and re-addressing it voids the stamp. ESP is a sealed, stamped envelope posted inside an outer envelope whose address the seal does not cover.

saying these in an interview costs you the question

  • AH encrypts the IP header while ESP encrypts the payload.
  • ESP's integrity check covers the outer IP source and destination addresses.
  • AH signs the TTL, so every router hop would break it.
  • Running ESP with encryption and no integrity algorithm is a normal choice.
  • IKE is the protocol that encrypts the data packets in an IPsec tunnel.
open as a page

Why does an IPsec AH packet fail its integrity check after crossing a NAT, when ESP traffic can be made to work?

level: middleimportance: must knowfreq 32%

basics

~20 s

AH's integrity check covers the IP source and destination addresses, which a NAT rewrites, so the receiver's recomputed ICV no longer matches and the packet is dropped. ESP's check excludes the outer header, so only ESP can be repaired.

open as a page

With IPsec ESP and AES-CBC, how much trailer padding does a 100-byte payload need, and what do Pad Length and Next Header record?

level: middleimportance: should knowfreq 18%

basics

~20 s

Ten bytes: AES-CBC needs payload, padding, Pad Length and Next Header to fill whole 16-byte blocks, so 100 + 2 rounds up to 112. Pad Length records 10; Next Header names the payload: 6 for TCP, 4 for IPv4.

open as a page

After QoS queuing was added after encryption on an IPsec gateway, the peer discards low-priority ESP packets as replays; what in ESP's anti-replay window explains it, and what fixes it?

level: seniorimportance: should knowfreq 22%

basics

~20 s

Sequence numbers are assigned at encryption; priority queuing then lets later numbers overtake. The receiver's window, 64 by default, moves past the delayed packets, which fall left of it and are dropped. Fix: one SA per traffic class, or a larger window.

open as a page

Why must an IPsec ESP SA be replaced before its 32-bit sequence number wraps, and how do extended sequence numbers avoid that?

level: middleimportance: nice to knowfreq 12%

basics

~20 s

With anti-replay on, an ESP sender MUST NOT let the sequence number cycle: an SA carries at most 2^32 − 1 packets, about 72 minutes at 1 Mpps. Extended sequence numbers count in 64 bits but send only the low 32.

open as a page

When traffic needs IPsec integrity without encryption, why do current specifications prefer ESP with NULL encryption over AH, and what does that give up?

level: seniorimportance: nice to knowfreq 10%

basics

~20 s

ESP with ENCR_NULL and an integrity transform authenticates the payload, crosses NAT and is mandatory to implement; AH is optional and fails behind NAT. The cost: no outer-header integrity, and nothing in the packet shows it is unencrypted.

open as a page