On Sun, Jun 14, 2026 at 10:50 AM Wang Xi <[email protected]>
wrote:

> Hi all,
>
> While reviewing draft-ietf-ipsecme-ikev2-reliable-transport, I was
> thinking about the broader transport design space for IKEv2.
>
> The current work extends IKEv2 over TCP to improve reliability for large
> exchanges (e.g., post-quantum key material), which is very useful and well
> aligned with current deployment constraints.
>
> As a potential direction for future work (not for this document), it may
> be worth considering whether QUIC could also serve as an alternative
> reliable transport for IKEv2.
>
> Compared to TCP, QUIC provides:
> - built-in stream multiplexing
> - avoidance of TCP head-of-line blocking
> - better behavior under NAT and loss-prone networks
> - integrated congestion control over UDP
>
> This is not a suggestion to change the current specification scope, but
> rather to highlight a possible future design option for discussion.
>
> Best regards,
>
> Wang Xi
>

IKEv2-o-QUIC seems like a "why not?" tool to have in the toolbox, but I
wonder whether at that point it might just be easier to use that
QUIC connection to setup MASQUE connectivity.  🤷
_______________________________________________
IPsec mailing list -- [email protected]
To unsubscribe send an email to [email protected]

Reply via email to