%% You should probably cite draft-ietf-ipsecme-split-dns instead of this I-D. @techreport{pauly-ipsecme-split-dns-01, number = {draft-pauly-ipsecme-split-dns-01}, type = {Internet-Draft}, institution = {Internet Engineering Task Force}, publisher = {Internet Engineering Task Force}, note = {Work in Progress}, url = {https://datatracker.ietf.org/doc/draft-pauly-ipsecme-split-dns/01/}, author = {Tommy Pauly and Paul Wouters}, title = {{Split-DNS Configuration for IKEv2 }}, pagetotal = 10, year = 2016, month = may, day = 27, abstract = {This document defines two Configuration Payload Attribute Types for the IKEv2 protocol that define sets of private DNS domains which should be resolved by DNS servers reachable through an IPsec connection, while leaving all other DNS resolution unchanged. The options define the set of DNS domains, DNS nameserver IP addresses and DNSSEC trust anchors to use for these DNS domains. This approach of resolving a subset of domains using an IPSec connection is referred to as "split-DNS". The information obtained via these attribute types can be used to reconfigure the local DNS resolution to use DNS forwarding for specific private domains.}, }