2003
DOI: 10.17487/rfc3456
|View full text |Cite
|
Sign up to set email alerts
|

Dynamic Host Configuration Protocol (DHCPv4) Configuration of IPsec Tunnel Mode

Abstract: This memo explores the requirements for host configuration in IPsec tunnel mode, and describes how the Dynamic

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
1
1
1
1

Citation Types

0
5
0
1

Year Published

2004
2004
2010
2010

Publication Types

Select...
6

Relationship

2
4

Authors

Journals

citations
Cited by 7 publications
(6 citation statements)
references
References 25 publications
(36 reference statements)
0
5
0
1
Order By: Relevance
“…For completeness: a solution modeled after [RFC3456] would combine (1) the router aggregation link model, (2) prefix information distribution and unique address allocation with DHCPv6, and (3) access control enforced by IPsec SAD/SPD.…”
Section: A65 Sketch Based On Rfc 3456mentioning
confidence: 99%
“…For completeness: a solution modeled after [RFC3456] would combine (1) the router aggregation link model, (2) prefix information distribution and unique address allocation with DHCPv6, and (3) access control enforced by IPsec SAD/SPD.…”
Section: A65 Sketch Based On Rfc 3456mentioning
confidence: 99%
“…i-HA: Mobile IPv4 home agent residing in the internal network; typically has a private address [privaddr]. VPN-TIA: VPN tunnel inner address, the address(es) negotiated during IKE phase 2 (quick mode), assigned manually, using IPsec-DHCP [RFC3456], using the "de facto" standard Internet Security Association and Key Management Protocol (ISAKMP) configuration mode, or by some other means. Some VPN clients use their current care-of address as their Tunnel Inner Address (TIA) for architectural reasons.…”
Section: I-famentioning
confidence: 99%
“…Consequently, support for dynamic IP address assignment, as described in [RFC3456], will typically not be required, although it cannot be ruled out. Such facilities will also be relevant to iSCSI hosts whose addresses are dynamically assigned.…”
Section: Requirements Languagementioning
confidence: 99%
“…At present this is not a very common scenario; however, if address assignment is provided, then DHCP-based address assignment within IPsec tunnel mode [RFC3456] MUST be supported. Note that this mechanism is not yet widely deployed within IPsec security gateways; existing IPsec tunnel mode servers typically implement this functionality via proprietary extensions to IKE.…”
Section: Ipsec Tunnel Mode Addressing Considerationsmentioning
confidence: 99%