Skip to main content

Considerations for SRv6 across Untrusted Domain

The information below is for an old version of the document.
Document Type
This is an older version of an Internet-Draft whose latest revision state is "Active".
Expired & archived
Authors Changwang Lin , Mengxiao Chen
Last updated 2023-09-13 (Latest revision 2023-03-12)
RFC stream (None)
Stream Stream state (No stream defined)
Consensus boilerplate Unknown
RFC Editor Note (None)
IESG IESG state Expired
Telechat date (None)
Responsible AD (None)
Send notices to (None)

This Internet-Draft is no longer active. A copy of the expired Internet-Draft is available in these formats:


Segment Routing operates within a trusted domain. There are some scenarios in which the whole SRv6 domain is separated by untrusted domain and SRv6 packets need to traverse it. This document describes some use cases of SRv6 across untrusted domain, and proposes a solution using IPSec technology.


Changwang Lin
Mengxiao Chen

(Note: The e-mail addresses provided for the authors of this Internet-Draft may no longer be valid.)