RFC 5840: Wrapped Encapsulating Security Payload (ESP) for Traffic Visibility
In plain English — editorial summary, not part of the RFC
This document describes the Wrapped Encapsulating Security Payload (WESP) protocol, which builds on the Encapsulating Security Payload (ESP) RFC 4303 and is designed to allow intermediate devices to (1) ascertain if data confidentiality is being employed within ESP, and if not, (2) inspect the IPsec packets for network monitoring and access control functions. Currently, in the IPsec ESP standard, there is no deterministic way to differentiate between encrypted and unencrypted payloads by simply examining a packet. This poses certain challenges to the intermediate devices that need to deep inspect the packet before making a decision on what should be done with that packet (Inspect and/or Allow/Drop). The mechanism described in this document can be used to easily disambiguate integrity-only ESP from ESP-encrypted packets, without compromising on the security provided by ESP. [STANDARDS-TRACK]
Document record
- Document ID
- RFC5840
- Published
- April 2010
- Authors
- K. Grewal; G. Montenegro; M. Bhatia
- Status
- PROPOSED STANDARD
- Stream
- IETF
- Area
- sec
- Pages
- 15
- Also known as
- —
Topics
Related documents
Ranked automatically by shared keywords, IETF area and stream — not by editorial selection.
- RFC 5836Extensible Authentication Protocol (EAP) Early Authentication Problem StatementCurrent
April 2010
- RFC 5848Signed Syslog MessagesCurrent
May 2010
- RFC 5816ESSCertIDv2 Update for RFC 3161Current
April 2010
- RFC 5868Problem Statement on the Cross-Realm Operation of KerberosCurrent
May 2010
- RFC 5877The application/pkix-attr-cert Media Type for Attribute CertificatesCurrent
May 2010
- RFC 5802Salted Challenge Response Authentication Mechanism (SCRAM) SASL and GSS-API MechanismsUpdated
July 2010
- RFC 5801Using Generic Security Service Application Program Interface (GSS-API) Mechanisms in Simple Authentication and Security Layer (SASL): The GS2 Mechanism FamilyUpdated
July 2010
- RFC 5879Heuristics for Detecting ESP-NULL PacketsCurrent
May 2010
Also filed under
About this page
The document record above — title, authors, date, status, stream, area, relationships, DOI and errata — is imported verbatim from the public RFC Editor index. The “in plain English” section is editorial: written by The metasystema editorial team, not part of the RFC. Where the two differ, the RFC text governs.
Last checked against the RFC Editor index on . RFCs are never revised after publication; changes are issued as new documents.
Data sources · Editorial policy · Report a correction · What is an RFC?