Opportunistic Encryption in MPLS Networks

The information below is for an old version of the document
Document Type Expired Internet-Draft (individual)
Last updated 2014-08-14 (latest revision 2014-02-10)
Replaced by draft-ietf-mpls-opportunistic-encrypt
Stream (None)
Intended RFC status (None)
Expired & archived
plain text pdf html bibtex
Stream Stream state (No stream defined)
Consensus Boilerplate Unknown
RFC Editor Note (None)
IESG IESG state Expired
Telechat date
Responsible AD (None)
Send notices to (None)

This Internet-Draft is no longer active. A copy of the expired Internet-Draft can be found at


This document describes a way to apply opportunistic encryption between adjacent nodes on an MPLS Label Switched Path (LSP) or between end points of an LSP. It explains how keys may be exchanged to enable the encryption, and indicates how key identifiers are exchanged in encrypted MPLS packets. Finally, this document describes the applicability of opportunistic encryption in MPLS networks with an indication of the level of improved security as well as the continued vulnerabilities. This document does not describe security for MPLS control plane protocols.


Adrian Farrel (adrian@olddog.co.uk)
Stephen Farrell (stephen.farrell@cs.tcd.ie)

(Note: The e-mail addresses provided for the authors of this Internet-Draft may no longer be valid.)