RFC 9329 · PROPOSED STANDARD · 2022

TCP Encapsulation of Internet Key Exchange Protocol and IPsec Packets

Overview

RFC 9329, “TCP Encapsulation of Internet Key Exchange Protocol and IPsec Packets”, is a Proposed Standard document published in November 2022 by T. Pauly, V. Smyslov. It obsoletes RFC 8229. The canonical text is published by the RFC Editor.

Abstract

This document describes a method to transport Internet Key Exchange Protocol (IKE) and IPsec packets over a TCP connection for traversing network middleboxes that may block IKE negotiation over UDP. This method, referred to as "TCP encapsulation", involves sending both IKE packets for Security Association (SA) establishment and Encapsulating Security Payload (ESP) packets over a TCP connection. This method is intended to be used as a fallback option when IKE cannot be negotiated over UDP.

TCP encapsulation for IKE and IPsec was defined in RFC 8229. This document clarifies the specification for TCP encapsulation by including additional clarifications obtained during implementation and deployment of this method. This documents obsoletes RFC 8229.

Abstract as published in the RFC, via rfc-editor.org.

What “Proposed Standard” means

An entry-level standards-track specification: stable, peer-reviewed and a solid basis for implementation, though it may still evolve before becoming an Internet Standard.

Read this RFC

The canonical text of RFC 9329 is hosted at rfc-editor.org. Available in HTML,TXT,PDF,XML.

Relationships to other RFCs
This RFC obsoletes
RFC 8229
Other RFCs from 2022

Who Is Online

In total there are 72 users online: 0 registered, 67 guests and 5 bots.

Most users ever online was 1,226 on 13 Jun 2026, 3:56 am.

Bots: Applebot Other Bot Other Crawler SemrushBot YandexBot

Users active in the past 15 minutes. Total registered members: 354