Skip to main content

Considerations for SRv6 across Untrusted Domain

Document Type Expired Internet-Draft (individual)
Expired & archived
Authors Changwang Lin , Ce Zhou , Mengxiao Chen
Last updated 2024-06-24 (Latest revision 2023-12-22)
RFC stream (None)
Intended RFC status (None)
Stream Stream state (No stream defined)
Consensus boilerplate Unknown
RFC Editor Note (None)
IESG IESG state Expired
Telechat date (None)
Responsible AD (None)
Send notices to (None)

This Internet-Draft is no longer active. A copy of the expired Internet-Draft is available in these formats:


Segment Routing operates within a trusted domain. There are some scenarios in which the whole SRv6 domain is separated by untrusted domain and SRv6 packets need to traverse it. This document describes some use cases of SRv6 across untrusted domain, and proposes a solution using IPSec technology.


Changwang Lin
Ce Zhou
Mengxiao Chen

(Note: The e-mail addresses provided for the authors of this Internet-Draft may no longer be valid.)