RFC 6311: Protocol Support for High Availability of IKEv2/IPsec
In plain English — editorial summary, not part of the RFC
The IPsec protocol suite is widely used for business-critical network traffic. In order to make IPsec deployments highly available, more scalable, and failure-resistant, they are often implemented as IPsec High Availability (HA) clusters. However, there are many issues in IPsec HA clustering, and in particular in Internet Key Exchange Protocol version 2 (IKEv2) clustering. An earlier document, "IPsec Cluster Problem Statement", enumerates the issues encountered in the IKEv2/IPsec HA cluster environment. This document resolves these issues with the least possible change to the protocol. This document defines an extension to the IKEv2 protocol to solve the main issues of "IPsec Cluster Problem Statement" in the commonly deployed hot standby cluster, and provides implementation advice for other issues. The main issues solved are the synchronization of IKEv2 Message ID counters, and of IPsec replay counters. [STANDARDS-TRACK]
Document record
- Document ID
- RFC6311
- Published
- July 2011
- Authors
- R. Singh; G. Kalyani; Y. Nir; Y. Sheffer; D. Zhang
- Status
- PROPOSED STANDARD
- Stream
- IETF
- Area
- sec
- Pages
- 26
- Also known as
- —
Topics
Related documents
Ranked automatically by shared keywords, IETF area and stream — not by editorial selection.
- RFC 7791Cloning the IKE Security Association in the Internet Key Exchange Protocol Version 2 (IKEv2)Current
March 2016
- RFC 6331Moving DIGEST-MD5 to HistoricCurrent
July 2011
- RFC 6290A Quick Crash Detection Method for the Internet Key Exchange Protocol (IKE)Current
June 2011
- RFC 6277Online Certificate Status Protocol Algorithm AgilityObsoleted
June 2011
- RFC 6347Datagram Transport Layer Security Version 1.2Obsoleted
January 2012
- RFC 6251Using Kerberos Version 5 over the Transport Layer Security (TLS) ProtocolCurrent
May 2011
- RFC 6394Use Cases and Requirements for DNS-Based Authentication of Named Entities (DANE)Current
October 2011
- RFC 6402Certificate Management over CMS (CMC) UpdatesObsoleted
November 2011
Also filed under
About this page
The document record above — title, authors, date, status, stream, area, relationships, DOI and errata — is imported verbatim from the public RFC Editor index. The “in plain English” section is editorial: written by The metasystema editorial team, not part of the RFC. Where the two differ, the RFC text governs.
Last checked against the RFC Editor index on . RFCs are never revised after publication; changes are issued as new documents.
Data sources · Editorial policy · Report a correction · What is an RFC?