Summary

  • RFC 2004 replaces the original Protocol and destination, conditionally replaces the source, and stores what the exit needs in an eight- or twelve-octet Minimal Forwarding Header instead of adding a full second IPv4 header.
  • The S bit omits the original source only when the tunnel entry is already the datagram’s source. That omission is a conformance-dependent compression rule, not authentication.
  • The forwarding-header checksum covers only the small inserted header. Reconstructing a valid IPv4 header proves that the restoration rules completed, not the original identity, tunnel authorization, path integrity or final delivery.

One card was edited, not placed in an envelope

RFC 2004 begins with a narrow economy. Conventional IP-in-IP adds another IPv4 header, normally at least twenty octets. Minimal encapsulation keeps the original payload where it is and modifies the original IP header itself. It then inserts a compact forwarding header between that modified header and the unchanged payload.

That makes this mechanism fundamentally different from the complete outer envelope examined in RFC 2003. The tunnel-visible header in RFC 2004 is not a separate copy with an independent life. It is the original header performing a temporary job. Its Protocol becomes 55. Its destination becomes the tunnel exit. If the entry is forwarding someone else’s datagram, its source becomes an address of that entry. Total Length grows by the size of the inserted slip, and the IP header checksum is recomputed.

The saving is easy to count. The short form adds eight octets, twelve fewer than a bare twenty-octet outer IPv4 header. The long form adds twelve, saving eight. But the comparison does not describe the whole bargain. A complete inner header is a retained record. RFC 2004 instead retains selected fields plus a reconstruction procedure.

The optional four bytes contain a claim about equality

The Minimal Forwarding Header always preserves the original Protocol and original destination. It preserves the original source only when the S bit is one. In that long form, the entry replaced the IP source with its own address and needs four more octets so the exit can recover the sender’s address.

When S is zero, the field is absent. The intended reason is precise: the encapsulator was already the original source, so the source still visible in the modified IP header is also the value needed after decapsulation. The protocol does not save a value it believes it already has.

This is efficient conditional encoding. It is not a credential. A conforming receiver may use S to parse eight or twelve octets and to decide whether it must restore a source field. The bit does not prove who configured the tunnel, whether the visible address was authorized, or whether the node that emitted the packet was entitled to speak for that source. Absence reduces bytes; it also removes an independent copy that could have been compared.

Two checksums answer two smaller questions

The inserted header carries a 16-bit one’s-complement checksum. Its scope is exactly the Minimal Forwarding Header with the checksum field treated as zero. The modified IPv4 header and the following payload are explicitly excluded. A valid value therefore supports a limited observation: the saved Protocol, S/reserved bits and saved address words are internally consistent under that checksum at this point.

The modified IPv4 header has its own checksum, updated for its current Protocol, addresses and Total Length. At the exit, restoration changes those fields again, removes eight or twelve octets, reduces Total Length and requires a new IP header checksum. These are separate integrity domains and separate processing events. Neither checksum is a signature; neither authorizes the tunnel; neither covers the application payload end to end.

Restoration does not rewind the journey

RFC 2004 says that the exit restores fields from the forwarding header and removes it. That does not mean the exit reproduces a byte-for-byte photograph of the ingress header. The old IP checksum was not preserved. A new checksum is calculated over the reconstructed current header. More importantly, the original TTL remains in the one modified header during the tunnel journey. Ordinary forwarding decrements it, so tunnel hops remain visible to tools such as traceroute. The exit does not restore the earlier TTL.

The reconstructed packet is semantically ready to continue under IPv4 rules. That is a useful and testable result. It is still bounded. A successful decapsulation does not establish which physical path was taken, whether every intermediate action was authorized, whether the source identity was genuine, whether the next hop accepted the packet, or whether an application received anything.

The shortest header refuses already fragmented input

Minimal encapsulation must not be used when the original datagram is already fragmented: the compact forwarding header has no place to save the existing fragmentation information. This is a precondition at entry, not a ban on all later fragmentation. After encapsulation, ordinary IPv4 options and fragmentation remain available unless DF is set, and RFC 1191 remains relevant to path-MTU behavior.

Routing-loop precautions and tunnel ICMP handling are not reinvented here. RFC 2004 points to RFC 2003, including tunnel soft state. Its security section is even more restrained: security is not addressed, beyond saying that the considerations are generally similar to RFC 2003. Protocol 55 and a valid reconstruction therefore cannot carry security claims that the document never assigned to them.

The document emerged beside RFC 2002 as an optional way to reduce Mobile IP carriage overhead, but registration and mobility binding are separate records. The RFC Editor and IETF Datatracker establish the document and its Proposed Standard status. They do not show a deployment. That distinction follows Lu Heng’s Running-Code Primacy: publication is a specification event, while operation must be shown by running evidence. His Minimum Initial Specification and Reality Layers sharpen the same discipline. A compact common format can make reconstruction deterministic without making every surrounding claim true.

Sources