<?xml version="1.0" encoding="UTF-8"?>
<reference anchor="I-D.ietf-ipsec-ecn" target="https://datatracker.ietf.org/doc/html/draft-ietf-ipsec-ecn-02">
   <front>
      <title>IPsec Interactions with ECN</title>
      <author initials="S." surname="Floyd" fullname="Sally Floyd">
         </author>
      <author initials="D. L." surname="Black" fullname="David L. Black">
         </author>
      <author initials="K. K." surname="Ramakrishnan" fullname="Dr. K. K. Ramakrishnan">
         </author>
      <date month="December" day="8" year="1999" />
      <abstract>
	 <t>IPsec supports secure communication over potentially insecure network
components such as intermediate routers.  IPsec protocols support two
operating modes, transport mode and tunnel mode.  Explicit Congestion
Notification (ECN) is an experimental addition to the IP architecture
that provides notification of onset of congestion to delay- or loss-
sensitive applications.  ECN provides congestion notifications to
enable adaptation to network conditions without the impact of dropped
packets [RFC 2481].  The use of two bits in the IPsec header for ECN
experimentation conflicts with header processing at IPsec tunnel
endpoints in a manner that makes ECN unusable in the presence of
IPsec tunnels.  This document considers issues related to this
conflict, describes two alternative solutions, and updates the IPsec
architecture [RFC 2401] to include these alternatives.  Support for
one or the other of these alternatives is REQUIRED to remove the
underlying conflict.
	 </t>
      </abstract>
   </front>
   <seriesInfo name="Internet-Draft" value="draft-ietf-ipsec-ecn-02" />
   
</reference>
