Skip to main content

IKEv2 Support for Anti-Replay Status Notification
draft-pan-ipsecme-anti-replay-notification-01

Document Type Expired Internet-Draft (individual)
Expired & archived
Authors Wei Pan , Qi He , Paul Wouters
Last updated 2025-04-24 (Latest revision 2024-10-21)
RFC stream (None)
Intended RFC status (None)
Formats
Stream Stream state (No stream defined)
Consensus boilerplate Unknown
RFC Editor Note (None)
IESG IESG state Expired
Telechat date (None)
Responsible AD (None)
Send notices to (None)

This Internet-Draft is no longer active. A copy of the expired Internet-Draft is available in these formats:

Abstract

Although RFC 4302 and RFC 4303 don't prohibit using Extended Sequence Number (ESN) when the anti-replay function is not enabled, many IPsec implementations require ESN to be used only with anti-replay. Therefore, failing to negotiate the use of ESN when the anti-replay is disabled will cause the sequence numbers to exhaust rapidly in high-traffic-volume scenarios, leading to the frequent rekey of Child SAs. This document defines the REPLAY_PROT_AND_ESN_STATUS Notify Message Status Type Payload in the Internet Key Exchange Protocol Version 2 (IKEv2) to inform the peer of its replay protection status and capability of using ESN without anti-replay when creating the Child SAs, to address the above problem.

Authors

Wei Pan
Qi He
Paul Wouters

(Note: The e-mail addresses provided for the authors of this Internet-Draft may no longer be valid.)