@techreport{abad-sdnrg-sdn-ipsec-flow-protection-01, number = {draft-abad-sdnrg-sdn-ipsec-flow-protection-01}, type = {Internet-Draft}, institution = {Internet Engineering Task Force}, publisher = {Internet Engineering Task Force}, note = {Work in Progress}, url = {https://datatracker.ietf.org/doc/draft-abad-sdnrg-sdn-ipsec-flow-protection/01/}, author = {Alejandro Abad-Carrascosa and Rafael Marin-Lopez and Gabriel Lopez-Millan}, title = {{Software-Defined Networking (SDN)-based IPsec Flow Protection}}, pagetotal = 19, year = 2015, month = oct, day = 19, abstract = {This document describes the use case for providing IPsec flow protection by means of a Software-Defined Network (SDN) controller and raises the requirements to support this service. It considers two main scenarios: (i) gateway-to-gateway and (ii) host-to-gateway (Road Warrior). For the gateway-to-gateway scenario, this document describes a mechanism to support the bootstrapping of key material between network resources to protect data traffic with IPsec and IKE, both in intra and inter-SDN cases. The host-to-gateway case defines a mechanism to bootstrap key material to protect data with IPsec between an end user's device and a gateway.}, }