%% You should probably cite draft-ietf-i2nsf-sdn-ipsec-flow-protection instead of this I-D. @techreport{abad-i2nsf-sdn-ipsec-flow-protection-01, number = {draft-abad-i2nsf-sdn-ipsec-flow-protection-01}, type = {Internet-Draft}, institution = {Internet Engineering Task Force}, publisher = {Internet Engineering Task Force}, note = {Work in Progress}, url = {https://datatracker.ietf.org/doc/draft-abad-i2nsf-sdn-ipsec-flow-protection/01/}, author = {Rafael Marin-Lopez and Gabriel Lopez-Millan and Sowmini Varadhan}, title = {{Software-Defined Networking (SDN)-based IPsec Flow Protection}}, pagetotal = 23, year = , month = , day = , abstract = {This document describes the use case of providing IPsec-based flow protection by means of a Software-Defined Network (SDN) controller and raises the requirements to support this service. It considers two main scenarios: (i) gateway-to-gateway and (ii) host-to-gateway (Road Warrior). For the gateway-to-gateway scenario, this document describes a mechanism to support the distribution of IPsec information to flow-based Network Security Functions (NSFs) that implements IPsec to protect data traffic. between network resources to protect data traffic with IPsec and IKE, in intra and inter-SDN cases. The host-to-gateway case defines a mechanism to distribute IPsec information to the NSF to protect data with IPsec between an end user's device (host) and a gateway.}, }