TCP Encapsulation of IKE and IPsec Packets
RFC 8229, “TCP Encapsulation of IKE and IPsec Packets”, is a Proposed Standard document published in August 2017 by T. Pauly, S. Touati, R. Mantha. It has been obsoleted by RFC 9329 — refer to the newer document for the authoritative version. The canonical text is published by the RFC Editor.
Abstract
This document describes a method to transport Internet Key Exchange Protocol (IKE) and IPsec packets over a TCP connection for traversing network middleboxes that may block IKE negotiation over UDP. This method, referred to as "TCP encapsulation", involves sending both IKE packets for Security Association establishment and Encapsulating Security Payload (ESP) packets over a TCP connection. This method is intended to be used as a fallback option when IKE cannot be negotiated over UDP.
What “Proposed Standard” means
An entry-level standards-track specification: stable, peer-reviewed and a solid basis for implementation, though it may still evolve before becoming an Internet Standard.
The canonical text of RFC 8229 is hosted at rfc-editor.org. Available in TXT,HTML.
- RFC 8228 Guidance on Designing Label Generation Rulesets Supporting Variant Labels
- RFC 8230 Using RSA Algorithms with CBOR Object Signing and Encryption Messages
- RFC 8227 MPLS-TP Shared-Ring Protection Mechanism for Ring Topology
- RFC 8231 Path Computation Element Communication Protocol Extensions for Stateful PCE
- RFC 8232 Optimizations of Label Switched Path State Synchronization Procedures for a Stateful PCE
- RFC 8233 Extensions to the Path Computation Element Communication Protocol to Compute Service-Aware Label Switched Paths
- RFC 8234 Updates to MPLS Transport Profile Linear Protection in Automatic Protection Switching Mode
- RFC 8223 Application-Aware Targeted LDP