Re: [Anima] RFC8994's IPsec tunnel description

2024-02-20 Thread Michael Richardson
{clearing out inbox} Toerless Eckert wrote: >> I know that we did many rounds to get this right, but I feel that >> maybe we did it wrong. >> >> The goal are packets that look like: >> >> (a) IPv6-LL ESP[nh=41] IPv6-ULA[1] ULP > What is "ULP" ? If I didn't answer

Re: [Anima] RFC8994's IPsec tunnel description

2023-12-18 Thread Toerless Eckert
Inline On Mon, Dec 11, 2023 at 10:48:57AM -0500, Michael Richardson wrote: > RFC8994 says: > > 6.8.3.1. Native IPsec > >An ACP node that is supporting native IPsec MUST use IPsec in tunnel >mode, negotiated via IKEv2, and with IPv6 payload (e.g., ESP Next >Header of 41). It MUST

[Anima] RFC8994's IPsec tunnel description

2023-12-11 Thread Michael Richardson
RFC8994 says: 6.8.3.1. Native IPsec An ACP node that is supporting native IPsec MUST use IPsec in tunnel mode, negotiated via IKEv2, and with IPv6 payload (e.g., ESP Next Header of 41). It MUST use local and peer link-local IPv6 addresses for encapsulation. Manual keying MUST NOT