<?xml version="1.0" encoding="UTF-8"?>
<reference anchor="I-D.bhatia-ipsecme-esp-null" target="https://datatracker.ietf.org/doc/html/draft-bhatia-ipsecme-esp-null-00">
   <front>
      <title>Identifying ESP-NULL Packets</title>
      <author initials="M." surname="Bhatia" fullname="Manav Bhatia">
         <organization>Alcatel-Lucent</organization>
      </author>
      <date month="December" day="1" year="2008" />
      <abstract>
	 <t>Encapsulating Security Payload (ESP) [RFC4303] provides data 
   integrity protection, confidentiality and data origin authentication 
   for data transported in an IP packet.  
    
   There are various applications and protocols that do not require 
   confidentiality but only need data integrity assurance or data origin 
   authentication. Since ESP support is mandatory for IPSec, such 
   applications end up using ESP with NULL encryption. 
    
   However, because of the way ESP is defined, it is impossible for 
   firewalls and intermediate routers to differentiate between encrypted 
   ESP and ESP NULL packets by simply examining them. This poses 
   problems for the firewalls since such packets cannot be filtered and 
   identified. It poses a different set of problems for routers since 
   such packets cannot be properly filtered, classified and prioritized. 
    
   This document proposes an extension to ESP so that firewalls and 
   routers can disambiguate between ESP encrypted and ESP NULL encrypted 
   packets. 
	 </t>
      </abstract>
   </front>
   <seriesInfo name="Internet-Draft" value="draft-bhatia-ipsecme-esp-null-00" />
   
</reference>
