RFC 9061: A YANG Data Model for IPsec Flow Protection Based on Software-Defined Networking (SDN)
In plain English — editorial summary, not part of the RFC
This document describes how to provide IPsec-based flow protection (integrity and confidentiality) by means of an Interface to Network Security Function (I2NSF) Controller. It considers two main well-known scenarios in IPsec: gateway-to-gateway and host-to-host. The service described in this document allows the configuration and monitoring of IPsec Security Associations (IPsec SAs) from an I2NSF Controller to one or several flow-based Network Security Functions (NSFs) that rely on IPsec to protect data traffic. This document focuses on the I2NSF NSF-Facing Interface by providing YANG data models for configuring the IPsec databases, namely Security Policy Database (SPD), Security Association Database (SAD), Peer Authorization Database (PAD), and Internet Key Exchange Version 2 (IKEv2). This allows IPsec SA establishment with minimal intervention by the network administrator. This document defines three YANG modules, but it does not define any new protocol.
Document record
- Document ID
- RFC9061
- Published
- July 2021
- Authors
- R. Marin-Lopez; G. Lopez-Millan; F. Pereniguez-Garcia
- Status
- PROPOSED STANDARD
- Stream
- IETF
- Area
- sec
- Pages
- 90
- Also known as
- —
Topics
Related documents
Ranked automatically by shared keywords, IETF area and stream — not by editorial selection.
- RFC 7018Auto-Discovery VPN Problem Statement and RequirementsCurrent
September 2013
- RFC 4301Security Architecture for the Internet ProtocolUpdated
December 2005
- RFC 2401Security Architecture for the Internet ProtocolObsoleted
November 1998
- RFC 9329TCP Encapsulation of Internet Key Exchange Protocol (IKE) and IPsec PacketsCurrent
November 2022
- RFC 9349Definitions of Managed Objects for IP Traffic Flow SecurityCurrent
January 2023
- RFC 8750Implicit Initialization Vector (IV) for Counter-Based Ciphers in Encapsulating Security Payload (ESP)Current
March 2020
- RFC 9395Deprecation of the Internet Key Exchange Version 1 (IKEv1) Protocol and Obsoleted AlgorithmsCurrent
April 2023
- RFC 9611Internet Key Exchange Protocol Version 2 (IKEv2) Support for Per-Resource Child Security Associations (SAs)Current
July 2024
Also filed under
About this page
The document record above — title, authors, date, status, stream, area, relationships, DOI and errata — is imported verbatim from the public RFC Editor index. The “in plain English” section is editorial: written by The metasystema editorial team, not part of the RFC. Where the two differ, the RFC text governs.
Last checked against the RFC Editor index on . RFCs are never revised after publication; changes are issued as new documents.
Data sources · Editorial policy · Report a correction · What is an RFC?