@techreport{ietf-ipsecme-encrypted-esp-ping-03, number = {draft-ietf-ipsecme-encrypted-esp-ping-03}, type = {Internet-Draft}, institution = {Internet Engineering Task Force}, publisher = {Internet Engineering Task Force}, note = {Work in Progress}, url = {https://datatracker.ietf.org/doc/draft-ietf-ipsecme-encrypted-esp-ping/03/}, author = {Antony Antony and Steffen Klassert}, title = {{Encrypted ESP Echo Protocol}}, pagetotal = 11, year = 2026, month = may, day = 4, abstract = {This document defines the Encrypted ESP Echo Function, a mechanism to assess the reachability of IP Security (IPsec) network paths using Encapsulating Security Payload (ESP) packets. It detects end-to-end path status by exchanging only encrypted ESP packets between IPsec peers. The Encrypted Echo message can either use existing congestion control payloads from RFC9347 or a new message format defined here, with an option to specify a preferred return path when there is more than one pair of IPsec SAs between the same set of IPsec peers. A peer can announce support using a new IKEv2 Status Notification ENCRYPTED\_PING\_SUPPORTED.}, }