Split DNS Configuration for IKEv2

Document Type Replaced Internet-Draft (ipsecme WG)
Authors Tommy Pauly  , Paul Wouters 
Last updated 2017-03-13 (latest revision 2016-09-21)
Replaced by RFC 8598
Stream Internet Engineering Task Force (IETF)
Intended RFC status (None)
Expired & archived
plain text xml pdf htmlized bibtex
Stream WG state WG Document
Document shepherd No shepherd assigned
IESG IESG state Replaced by draft-ietf-ipsecme-split-dns
Consensus Boilerplate Unknown
Telechat date
Responsible AD (None)
Send notices to (None)

This Internet-Draft is no longer active. A copy of the expired Internet-Draft can be found at


This document defines two Configuration Payload Attribute Types for the IKEv2 protocol that add support for private DNS domains. These domains should be resolved using DNS servers reachable through an IPsec connection, while leaving all other DNS resolution unchanged. This approach of resolving a subset of domains using non-public DNS servers is referred to as "Split DNS".


Tommy Pauly (tpauly@apple.com)
Paul Wouters (pwouters@redhat.com)

(Note: The e-mail addresses provided for the authors of this Internet-Draft may no longer be valid.)