RFC 5879 on Heuristics for Detecting ESP-NULL Packets

rfc-editor@rfc-editor.org Thu, 27 May 2010 18:27 UTC

Return-Path: <wwwrun@rfc-editor.org>
X-Original-To: ietf-announce@core3.amsl.com
Delivered-To: ietf-announce@core3.amsl.com
Received: from localhost (localhost [127.0.0.1]) by core3.amsl.com (Postfix) with ESMTP id AD7433A6AFB; Thu, 27 May 2010 11:27:07 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.439
X-Spam-Level:
X-Spam-Status: No, score=-1.439 tagged_above=-999 required=5 tests=[AWL=1.161, BAYES_00=-2.599, NO_RELAYS=-0.001]
Received: from mail.ietf.org ([64.170.98.32]) by localhost (core3.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id hFhu3Lf385x4; Thu, 27 May 2010 11:27:06 -0700 (PDT)
Received: from rfc-editor.org (rfc-editor.org [IPv6:2001:1890:1112:1::2f]) by core3.amsl.com (Postfix) with ESMTP id CEE9D3A694E; Thu, 27 May 2010 11:27:06 -0700 (PDT)
Received: by rfc-editor.org (Postfix, from userid 30) id DBC5AE0697; Thu, 27 May 2010 11:26:57 -0700 (PDT)
To: ietf-announce@ietf.org, rfc-dist@rfc-editor.org
Subject: RFC 5879 on Heuristics for Detecting ESP-NULL Packets
From: rfc-editor@rfc-editor.org
Message-Id: <20100527182657.DBC5AE0697@rfc-editor.org>
Date: Thu, 27 May 2010 11:26:57 -0700
Cc: ipsec@ietf.org, rfc-editor@rfc-editor.org
X-BeenThere: ietf-announce@ietf.org
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: "IETF announcement list. No discussions." <ietf-announce.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/listinfo/ietf-announce>, <mailto:ietf-announce-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ietf-announce>
List-Post: <mailto:ietf-announce@ietf.org>
List-Help: <mailto:ietf-announce-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ietf-announce>, <mailto:ietf-announce-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 27 May 2010 18:27:07 -0000

A new Request for Comments is now available in online RFC libraries.

        
        RFC 5879

        Title:      Heuristics for Detecting ESP-NULL Packets 
        Author:     T. Kivinen, D. McDonald
        Status:     Informational
        Stream:     IETF
        Date:       May 2010
        Mailbox:    kivinen@iki.fi, 
                    danmcd@opensolaris.org
        Pages:      32
        Characters: 72917
        Updates/Obsoletes/SeeAlso:   None

        I-D Tag:    draft-ietf-ipsecme-esp-null-heuristics-07.txt

        URL:        http://www.rfc-editor.org/rfc/rfc5879.txt

This document describes a set of heuristics for distinguishing IPsec
ESP-NULL (Encapsulating Security Payload without encryption) packets
from encrypted ESP packets.  These heuristics can be used on
intermediate devices, like traffic analyzers, and deep-inspection
engines, to quickly decide whether or not a given packet flow is
encrypted, i.e., whether or not it can be inspected.  Use of these
heuristics does not require any changes made on existing IPsec hosts
that are compliant with RFC 4303.  This document is not an Internet 
Standards Track specification; it is published for informational 
purposes.

This document is a product of the IP Security Maintenance and Extensions Working Group of the IETF.


INFORMATIONAL: This memo provides information for the Internet community.
It does not specify an Internet standard of any kind. Distribution of
this memo is unlimited.

This announcement is sent to the IETF-Announce and rfc-dist lists.
To subscribe or unsubscribe, see
  http://www.ietf.org/mailman/listinfo/ietf-announce
  http://mailman.rfc-editor.org/mailman/listinfo/rfc-dist

For searching the RFC series, see http://www.rfc-editor.org/rfcsearch.html.
For downloading RFCs, see http://www.rfc-editor.org/rfc.html.

Requests for special distribution should be addressed to either the
author of the RFC in question, or to rfc-editor@rfc-editor.org.  Unless
specifically noted otherwise on the RFC itself, all RFCs are for
unlimited distribution.


The RFC Editor Team
Association Management Solutions, LLC