%% You should probably cite draft-ietf-ipsecme-multi-sa-performance instead of this I-D. @techreport{pwouters-ipsecme-multi-sa-performance-02, number = {draft-pwouters-ipsecme-multi-sa-performance-02}, type = {Internet-Draft}, institution = {Internet Engineering Task Force}, publisher = {Internet Engineering Task Force}, note = {Work in Progress}, url = {https://datatracker.ietf.org/doc/draft-pwouters-ipsecme-multi-sa-performance/02/}, author = {Antony Antony and Tobias Brunner and Steffen Klassert and Paul Wouters}, title = {{IKEv2 support for per-queue Child SAs}}, pagetotal = 13, year = 2021, month = oct, day = 14, abstract = {This document defines three Notify Message Type Payloads for the Internet Key Exchange Protocol Version 2 (IKEv2) indicating support for the negotiation of multiple identical Child SAs to optimize performance. The CPU\_QUEUES notification indicates support for multiple queues or CPUs. The CPU\_QUEUE\_INFO notification is used to confirm and optionally convey information about the specific queue. The TS\_MAX\_QUEUE notify conveys that the peer is unwilling to create more additional Child SAs for this particular Traffic Selector set. Using multiple identical Child SAs has the benefit that each stream has its own Sequence Number Counter, ensuring that CPUs don't have to synchronize their crypto state or disable their packet replay protection.}, }