IETF RFC 9061 PDF

IETF RFC 9061 PDF

Name:
IETF RFC 9061 PDF

Published Date:
07/01/2021

Status:
[ Active ]

Description:

A YANG Data Model for IPsec Flow Protection Based on Software‑Defined Networking (SDN)

Publisher:
Internet Engineering Task Force

Document status:
Active

Format:
Electronic (PDF)

Delivery time:
10 minutes

Delivery time (for Russian version):
200 business days

SKU:

Choose Document Language:
$18.9
Need Help?

Abstract

This document describes how to provide IPsec-based flow protection (integrity and confidentiality) by means of an Interface to Network Security Function (I2NSF) Controller. It considers two main well-known scenarios in IPsec: gateway-to-gateway and host-to-host. The service described in this document allows the configuration and monitoring of IPsec Security Associations (IPsec SAs) from an I2NSF Controller to one or several flow-based Network Security Functions (NSFs) that rely on IPsec to protect data traffic.

This document focuses on the I2NSF NSF-Facing Interface by providing YANG data models for configuring the IPsec databases, namely Security Policy Database (SPD), Security Association Database (SAD), Peer Authorization Database (PAD), and Internet Key Exchange Version 2 (IKEv2). This allows IPsec SA establishment with minimal intervention by the network administrator. This document defines three YANG modules, but it does not define any new protocol.


Edition : 21
File Size : 1 file , 500 KB
Number of Pages : 90
Published : 07/01/2021

History


Related products

IETF RFC 9103
Published Date: 08/01/2021
DNS Zone Transfer over TLS
$12.9

Best-Selling Products