[IPsec] FW: New Version Notification for draft-ponchon-ipsecme-anti-replay-subspaces-00.txt

"Paul Ponchon (pponchon)" <pponchon@cisco.com> Mon, 24 October 2022 14:56 UTC

Return-Path: <pponchon@cisco.com>
X-Original-To: ipsec@ietfa.amsl.com
Delivered-To: ipsec@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 288D7C14CE3C for <ipsec@ietfa.amsl.com>; Mon, 24 Oct 2022 07:56:58 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -14.606
X-Spam-Level:
X-Spam-Status: No, score=-14.606 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_HI=-5, SPF_NONE=0.001, T_SCC_BODY_TEXT_LINE=-0.01, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001, USER_IN_DEF_DKIM_WL=-7.5] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=cisco.com header.b=F2Z1nFfR; dkim=pass (1024-bit key) header.d=cisco.onmicrosoft.com header.b=uLFZt+Ye
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 2Q6ISFyHgwMp for <ipsec@ietfa.amsl.com>; Mon, 24 Oct 2022 07:56:52 -0700 (PDT)
Received: from rcdn-iport-8.cisco.com (rcdn-iport-8.cisco.com [173.37.86.79]) (using TLSv1.2 with cipher DHE-RSA-SEED-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 1C708C14CE2B for <ipsec@ietf.org>; Mon, 24 Oct 2022 07:56:52 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=cisco.com; i=@cisco.com; l=13636; q=dns/txt; s=iport; t=1666623412; x=1667833012; h=from:to:subject:date:message-id:references:in-reply-to: mime-version; bh=jjDADtDVsjz1InKHM3gKOk5cX8mtFMh/4TXW1m3Sc88=; b=F2Z1nFfRyqRXOaa/PWbvd4ctXTMO4kKBc0PJ6QomKXTiVy4C/W1wY784 W5TknWEZIrc05wvM0fNzdB3JX4ZJgKJoez1vFm/g7ip1TTi6AuvwGMF0b Ha85pmXn9OMO1Pjm7GsEyfJ7uAo+4OsiS8YjKBbN2Hzl3f6zhUY/Z2Fvy M=;
IronPort-PHdr: A9a23:pJQxKhFkeUzNzrnA7/hhzJ1GfiYY04WdBeZdwpYkircbdKOl8tyiOUHE/vxigRfPWpmT8PNLjefa8sWCEWwN6JqMqjYOJZpLURJWhcAfhQd1BsmDBAXyJ+LraCpvGsNEWRdl8ni3PFITFtz5YgjZo2a56ngZHRCsXTc=
IronPort-Data: A9a23:qblhJq7muepylA20Fqls1wxRtCXFchMFZxGqfqrLsTDasY5as4F+vmofX2jXO/6Ia2rwKIgna96xoUhT7JGHnIRkT1A+/Hg0Zn8b8sCt6fZ1gavT04J+FiBIJa5ex512huLocYZlFxcwmj/3auK79SQli/nRLlbBILes1h5ZFFcMpBgJ0XqPq8Zh6mJZqYDR7zGl4LsekOWHULOR4AOYB0pPg061RLyDi9yp0N8QlgRWifmmJzYynVFNZH4UDfnZw3cV3uBp8uCGq+brlNlV/0vD9BsrT9iiiLu+LwsBQ6XZOk6FjX8+t6qK20cZ4HdtlPdgcqNBNy+7iB3R9zx14M1Vspq7SQAvFqbNg+8aFRJfFkmSOIUfoO6cfCfn6ZPNp6HBWz62qxl0N2k3JZYV8c52DH1As/sCJ1gwgrqr7w6t6KiwRu8pjcM5IYy2eogeoXpnizreCJ4brVn4a/2izbdlMP0Y26iixcrjWvc=
IronPort-HdrOrdr: A9a23:pregvq5sBOVnVHQpSQPXwU+BI+orL9Y04lQ7vn2ZFiY6TiXIra+TdaoguSMc0AxhJU3I6urwRJVoIEmsv6KdhLNxAV7MZniehILFFvAB0WKm+UybJ8SczJ8R6U4DSdkHNDSYNzET5qyWgHjaLz9j+qj9zEnCv5a7854Zd3ANV0gW1XYfNu/0KDwSeCB2Qb4CULaM7MtOoDStPV4NaN6gO3UDV+/f4/XWiZPPe3c9dlIawTjLqQntxK/xEhCe0BtbeShI260e/W/MlBG8zrm/ssu81gTX2wbonttrcZrau5V+7f63+4gowwbX+0WVjUNaKv+/VQUO0aCSAZAR4ZzxSlkbToBOAjjqDx6ISFPWqnfdOXAVmjjfIZvyuwq7nSQ/LwhKTfapzLgpAyfx+g4uuspx37lM2H/cv51LDQnYlCC4/NTQUQp2/3DE6EbKvNRj+EC3a7FuHoN5vMga5gdYAZ0AFCX15MQuF/RvFtjV4LJTfUmBZ37Us2FzyJj0N05DVSuuUwwHoIiYwjJWlHd2ww8Rw9EehG4J8NY4R4Nf7+rJP6x0nPVFT9MQb6h6GOAdKPHHQlDlUFbJKiafMF7nHKYINzbErIP2+qw84KWwdJkB3PIJ6eD8uZNjxBsPkm7VeL+zNcdwg2DwqU2GLEfQ9v0=
X-IronPort-Anti-Spam-Filtered: true
X-IronPort-Anti-Spam-Result: A0CcCwB2bIJi/5xdJa1aHQIsCQgFBSOBTwKBHzFSB3UCWDlDiBgCA4UxhQldgiUDliWFE4EsgSUDVAsBAQENAQESAiUJBAEBhQIChT4CJTQJDgECBAEBARIBAQUBAQECAQcEgQkThWgBDIZCAQEBAQMSLgEBNQMPAgEIEQMBAi8yGwEBBQMCBBMIEweCXIIMVwMxAQ6fZwGBPgKKH3iBM4EBgggBAQYEBIFNQYJ/GII4AwaBPAGDE4MFWEqDCIQdJxyBSUSBWIIwNz6CYgEBAgGBOCceDYNggi6VYQc6A1SBBRKBIXEBCAYGBwoFMgYCDBgUBAITElMeAhMMChwOVBkMDwMSAxEBBwILEggVCSMIAwIDCAMCAy4CAxgJBwoDHQgKHBIQFAIEEx8LCAMaHy0JAgQOA0MICwoDEQQDExgLFggQBAYDCS8NKAsDBQ8PAQYDBgIFBQEDIAMUAwUnBwMhBwsmDQ0EIx0DAwUmAwICGwcCAgMCBhcGAgJxCigNCAQIBBweJRMFAgcxBQQvAh4EBQYRCQIWAgYEBQIEBBYCAhIIAggnGwcWNhkBBV0GCwkjHBwBDwwFBQYWAyZSBQQfAZJZgx0IgQ0mgTAEUQIUBQkOHi0IAkBAODqfY0OgQAqDTIsalQwVqFeWZiCNB5RFF4R7AgQCBAUCDgEBBoFhPIFZcBUaIYJoURkPjleDO4UUhUp1AjkCBgsBAQMJkRoBAQ
X-IronPort-AV: E=Sophos;i="5.91,230,1647302400"; d="scan'208,217";a="1093570076"
Received: from rcdn-core-5.cisco.com ([173.37.93.156]) by rcdn-iport-8.cisco.com with ESMTP/TLS/DHE-RSA-SEED-SHA; 24 Oct 2022 14:56:50 +0000
Received: from mail.cisco.com (xfe-rcd-004.cisco.com [173.37.227.252]) by rcdn-core-5.cisco.com (8.15.2/8.15.2) with ESMTPS id 29OEunQD004487 (version=TLSv1.2 cipher=AES256-SHA bits=256 verify=OK) for <ipsec@ietf.org>; Mon, 24 Oct 2022 14:56:50 GMT
Received: from xfe-aln-004.cisco.com (173.37.135.124) by xfe-rcd-004.cisco.com (173.37.227.252) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.2.1118.9; Mon, 24 Oct 2022 09:56:49 -0500
Received: from NAM02-BN1-obe.outbound.protection.outlook.com (173.37.151.57) by xfe-aln-004.cisco.com (173.37.135.124) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.2.1118.15 via Frontend Transport; Mon, 24 Oct 2022 09:56:49 -0500
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=arr0VdOLb5r/j6UrxV7xUqenLiwjUQsKvtNdMGTsb+LbKOAxdRMLy3HQURjx8yD8HKKC8puo12JCvwmQM0e2R3x6reebJ+8Bg2/VjV9TsnkyrRgJYdZ47efCK/Dzc3IluSaiAYO+vt6EAzHMhCseSUeCHFMPNlOKhuZGCsmzaxbxvX3JWezap5Z2snlnqwhbb1/A/JYMEN2E9qKDsNdDS3lZR1BRik/PKNZwHXFUbWmHnxr8e+7E7LEOmRdMsj+hPy8tph+S+8/3e2iq7R+8EiS5zOz0z0eAwtMnnEQng2nceGfidpmu83ghyp1hj2I2ngu5CrZY0ghxB1t8O+lpoA==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=5cmB4XD46421YzVo/iftI6tYhWxrSovIoBorvvRRIHA=; b=Ez3nAAWISYA7uCGaN2f8MY2UPwbV6H0XZ7ufBQ7xrK54VzNGxWnRPhHN7MJymRcOVTGReJYtqXGlpZNHYMevThwLKmmtf90SeLHfOo5oi3Hh+xUJQQynLmRUQbsaqZ/mQSbZzRr1VGVsQlMdx54aNMu7J9azhj8mnGomMgLekI3MQdXcSmoGApP5bLMIGtIkDMllxWBjm6CuOKL11tfemUxQLOVVnTBVZV3xEyThO3/TFCScVNZa+ZvZJ52EH0YKeB3zZsxthMCfxzWwUvi9kqKiEkLwRtbKusxLvey6UHQNjK5zrGhgSKeIur0dAJ8Kw7sY2oQ56XGVcxFkm6K13Q==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=cisco.com; dmarc=pass action=none header.from=cisco.com; dkim=pass header.d=cisco.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=cisco.onmicrosoft.com; s=selector2-cisco-onmicrosoft-com; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=5cmB4XD46421YzVo/iftI6tYhWxrSovIoBorvvRRIHA=; b=uLFZt+Yege/Syaq5Aki5ClTo7vbIo7B6KsI6TnWD+B8F1hpdLlN1eX//IbAtcUb3oJEHiXGDUJUAb8ci9bjNFnKxw1i3HZyFWOUWrxcNCEEErgF9/nUtEEbxp48ZBt1HIadUHv2ml3qay8qSJJMaj20cn68WLvKa5j3bWnEnfdI=
Received: from DM6PR11MB4531.namprd11.prod.outlook.com (2603:10b6:5:2a5::19) by PH0PR11MB5048.namprd11.prod.outlook.com (2603:10b6:510:3d::14) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.5746.28; Mon, 24 Oct 2022 14:56:48 +0000
Received: from DM6PR11MB4531.namprd11.prod.outlook.com ([fe80::80c3:ee31:7f03:49e3]) by DM6PR11MB4531.namprd11.prod.outlook.com ([fe80::80c3:ee31:7f03:49e3%4]) with mapi id 15.20.5723.034; Mon, 24 Oct 2022 14:56:47 +0000
From: "Paul Ponchon (pponchon)" <pponchon@cisco.com>
To: "ipsec@ietf.org" <ipsec@ietf.org>
Thread-Topic: New Version Notification for draft-ponchon-ipsecme-anti-replay-subspaces-00.txt
Thread-Index: AQHY57gEo4sMkI8IJUeAHk+MiltMaK4dodf4
Date: Mon, 24 Oct 2022 14:56:47 +0000
Message-ID: <DM6PR11MB4531E91C45B7E44F212DF849CB2E9@DM6PR11MB4531.namprd11.prod.outlook.com>
References: <166662303140.2807.4357443238363299404@ietfa.amsl.com>
In-Reply-To: <166662303140.2807.4357443238363299404@ietfa.amsl.com>
Accept-Language: en-GB, en-US
Content-Language: en-GB
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
authentication-results: dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=cisco.com;
x-ms-publictraffictype: Email
x-ms-traffictypediagnostic: DM6PR11MB4531:EE_|PH0PR11MB5048:EE_
x-ms-office365-filtering-correlation-id: 8eff70c1-3e11-4ce7-8d5c-08dab5cff997
x-ms-exchange-senderadcheck: 1
x-ms-exchange-antispam-relay: 0
x-microsoft-antispam: BCL:0;
x-microsoft-antispam-message-info: UkmYYItjvd0T0qUEBdGJhlH2xjRTL511YI9bhMyWYZl6QapbMo/V5mx6k5DCsErWUkxez/rplKGbhU4cGnGmThfcqIIMgRwKuanggQMI6eEqiUjnWWs5RU9CVDMguQVV++70dhBtEFdQf5eIquS6lWbXdyQVHZwUBxz/t7iaqcXyl0AHF8TH2Vp9sle5UmW//wDDZG7ItEVU3H28bnq85lJR2nSoUXukhXXHEsZXSMLg+67GcdxD4WlD/v8j0JZdqt7M1KPaOqXZ43J6ZoGmA6oL0wfKvlijVW3Rdi8q7MtLn7HQrPbmFyQpuBQeqFVuip9Z9928MqrRli+EObEl7yIdWcz1O4yLlWHKojdOvfz/0lVDpbtIECn3kij+nhcfN7JBlnN2q2daCRhUhjXnxEF/6u9FY0WXlvybdN8+F8XIflGKYih3Z5N0L14tle39bT0eMh9cfdU7+iDWlTnudlqjFOsuL2V5DVQTJyTTCIH044CAKJ0QXm/PIKGp0h9NKf5/SjT6+hYg/oGCtvmisUZjYbJ2nIsFzn3x9SbtKTa+8H8kVjDUwgt/6bMGrbkSY7bYZjB3dORxX/TNylm3OMzRLyuT9qCQcZZ9WtbLsQoMrdcTvsaWlXFQOhj8Vh08yocPXV1+4qwbppi3OLnbAI1i9NeQoymS3wQhRcjO9BiS86wsGAxgLWnx+u35GCGVEkYTfN9HyrhcCjNdclqmjSnCnL2aTk6WC0p7kuoP/1MnHFbgBO7IsvlCfvNCfxTv+JNT5ByZS+wchJi6bDI6B+vigpUh/Rd+zy3+snyEHCfUo+c9ixFtKVzlS/rrEOpA
x-forefront-antispam-report: CIP:255.255.255.255; CTRY:; LANG:en; SCL:1; SRV:; IPV:NLI; SFV:NSPM; H:DM6PR11MB4531.namprd11.prod.outlook.com; PTR:; CAT:NONE; SFS:(13230022)(4636009)(136003)(39860400002)(366004)(396003)(346002)(376002)(451199015)(33656002)(38070700005)(4001150100001)(6916009)(2906002)(15650500001)(5660300002)(8936002)(66476007)(66446008)(64756008)(8676002)(41300700001)(66946007)(66556008)(86362001)(316002)(52536014)(6506007)(91956017)(9686003)(26005)(76116006)(53546011)(7696005)(83380400001)(66574015)(186003)(55016003)(38100700002)(71200400001)(966005)(166002)(122000001)(478600001); DIR:OUT; SFP:1101;
x-ms-exchange-antispam-messagedata-chunkcount: 1
x-ms-exchange-antispam-messagedata-0: PRZZSDq6O5u8z6sgmCI00Abn+s+WvFW9kGQcApPj9sdV9/KWheMkFLo4OucdmmWRs1CDAO3HajNBhmeCNvQTHNyFZPp7IwTTuNoySKEPO2JqmJa0++rd191QdNRM+APRpNod+VyWe3Tm6sbawUr9by+VVnNWyER54yfMorjeMXtiPA5JVK//jFo3HcKi9opDYT9DftaszM7duY8Bo77aMOj1dACPftNdMdoz7Pf/xBm/MfFbPGF/vtbf/AveqMQuasdSKW2ShkZxfDVBYnX7bJGwT40YhZ1nL5QgGQi8jv6nN7s3amM9/zyePTzThk5N+EFeE4xdsvHo7C6I4PgWdP1/OfDPcBRNL44jx31L7XzmFYkRJnreu0Vd/rQe8SL7o2zkAVgtV9PtnVymbTUantlp5d9gIWKZtLA1CrorCW+JZnjoRW8cWQXb1xCFHDJLvp9afxPPiLsEfOAmoriyDMO1rvnbiIpDZQctqowRGvrWYfPeIEPoJ8ihKdUOd/cYioG9B5eC9+9wXtVizezcE97iRLMuPs5sxZRkwE3WhNxgw0sG05H9KCDRVcES0joadxqIUle8ZtNAJyN51PMjF62sw3v7X0gEpsGLRZKWbIj5pLqhM8dbj401XNuUWXW1mobx9e2sj/AbI0yGEtw2PwLRwUQWGENTMoB5FN2GtZuIiCTVEz5rwuvtxljS4GIMAIQxY9hcstW2negeOMrKAqNLhTEraXBWHi6S1L7sGjMIVZBKvNJnA83pmHYfUW9uELPPXpYnNNIZTgK0S+OXvjHx0aPaieidHTiW6hzRbo1kP9qUWzAXdqKO7ENet92ZRBKbsGQ/J46Z0bTXKGk1L/5WVSxfAwLm+2rQVmaElKzuvMkGu+X/oqnwi1bPHNpxKDF9eLTF3T39LA8Q0IHpQduqh8PvAvgAlMt4tHEdHxG+SdPmsLuWwtMnpuHN7nbDQW9rVb2wgHJPe37YftSyI/A4qAXSxh2QxEfKtV9BvPAD92zkj0gWsNPtHn0thLo8CbQHmqhfr+fo1wWcjIFrpNbNnA4+WR5nIgPyd//a/lViNoRmpB/1BKL4okGxcpOR9DNkdKJLGHjam/v/VVo3IoEmCR1Dlp/w7KDbcniEQwRnar8IqHRKV/+3k5dxxuyDZ5vFw6CHJDirTMC50jQmsFolRfH2amUw1o4XE590hnUHgEHcoI163KTDYPmb15cfyFcut34FG/hbyIcIAiZVtg+/2mYw/msFUoZfDNifdh0YLWmJablwEw4zgHfJOlVp/t4SvP1MT1H93l+B4xquDYZq8trs0AYhxBqpHukvw7aEjYSUshhBG3aNtnbJeYn+5rzjskF1wyDvCS//qbVz2wzBjBl/nwzm/KRYJldDE45IN806/Gyfok6PCdUYM5oCuyzwBNYpN5EadSMcKcGpolfE0STtg3grtmPzTzZ6d8Og0NfP4V2fFhi0YRFP8sS949/zc1HFfu785CmRHqJ5fPogi7klFXmMUn+Jbs4sGS7pL9x4EQT+eNVm+lXmlqfeVbFbOuEGyCgeygUJyTfkWUjRpfWbsiVnPe+qr7bcr/dYhLyzT+iu8yP/U+EBycKzS91EmJqlIEWfRvSlF7IAng==
Content-Type: multipart/alternative; boundary="_000_DM6PR11MB4531E91C45B7E44F212DF849CB2E9DM6PR11MB4531namp_"
MIME-Version: 1.0
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-AuthSource: DM6PR11MB4531.namprd11.prod.outlook.com
X-MS-Exchange-CrossTenant-Network-Message-Id: 8eff70c1-3e11-4ce7-8d5c-08dab5cff997
X-MS-Exchange-CrossTenant-originalarrivaltime: 24 Oct 2022 14:56:47.6350 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 5ae1af62-9505-4097-a69a-c1553ef7840e
X-MS-Exchange-CrossTenant-mailboxtype: HOSTED
X-MS-Exchange-CrossTenant-userprincipalname: Bco/YbcDR7m3gFSJzgUcq/sfGbPd9MsWhdn75AEjvmTcXuxH3JeOtl96BPbLyewCusU2kLv7UN5JoIlUEp2mAw==
X-MS-Exchange-Transport-CrossTenantHeadersStamped: PH0PR11MB5048
X-OriginatorOrg: cisco.com
X-Outbound-SMTP-Client: 173.37.227.252, xfe-rcd-004.cisco.com
X-Outbound-Node: rcdn-core-5.cisco.com
Archived-At: <https://mailarchive.ietf.org/arch/msg/ipsec/ccgGEsIp3ByL8KU1HkIInnfL6og>
Subject: [IPsec] FW: New Version Notification for draft-ponchon-ipsecme-anti-replay-subspaces-00.txt
X-BeenThere: ipsec@ietf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: Discussion of IPsec protocols <ipsec.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ipsec>, <mailto:ipsec-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/ipsec/>
List-Post: <mailto:ipsec@ietf.org>
List-Help: <mailto:ipsec-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ipsec>, <mailto:ipsec-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 24 Oct 2022 14:58:30 -0000

Hello ipsecme,

We would like to notify the list that we just published a new draft (ieft-draft-pponchon-ipsecme-anti-replay-subspaces) and would kindly ask for the opportunity to present it in London in person.

We (the authors of this draft) are currently involved in the performance optimization of an IPsec stack deployed in some large SD-WAN networks. We have been observing performance and scalability challenges related to anti-replay, and believe the working group could propose a solution.

We recently became aware that the working group was investigating similar issues in the multi-sa draft (draft-pwouters-ipsecme-multi-sa-performance-04). We are very enthusiastic about that work, but believe that we have additional requirements, as well as operational experience, which might challenge the currently proposed solution. To summarize: We do need anti-replay to scale to multiple cores (as detailed in the multi-sa draft), but we also need packets to be sent across multiple paths and multiple QoS policies.

These problems add-up in showing anti-replay limitations. And using more Child SA comes with a significant performance degradation. We believe that the anti-replay mechanism itself could be improved to support all these use-cases. And that's what this draft is about.

We would appreciate any feedback and, again, would love to have the opportunity to present that work in London.

Thanks,

Paul, Mohsin, Pierre and Guillaume.

From: internet-drafts@ietf.org <internet-drafts@ietf.org>
Date: Monday, 24 October 2022 at 16:50
To: Guillaume Solignac (gsoligna) <gsoligna@cisco.com>, Mohsin Shaikh (mohsisha) <mohsisha@cisco.com>, Paul Ponchon (pponchon) <pponchon@cisco.com>, Pierre Pfister (ppfister) <ppfister@cisco.com>
Subject: New Version Notification for draft-ponchon-ipsecme-anti-replay-subspaces-00.txt

A new version of I-D, draft-ponchon-ipsecme-anti-replay-subspaces-00.txt
has been successfully submitted by Paul Ponchon and posted to the
IETF repository.

Name:           draft-ponchon-ipsecme-anti-replay-subspaces
Revision:       00
Title:          IPsec and IKE anti-replay sequence number subspaces for multi-path tunnels and multi-core processing
Document date:  2022-10-24
Group:          Individual Submission
Pages:          11
URL:            https://www.ietf.org/archive/id/draft-ponchon-ipsecme-anti-replay-subspaces-00.txt
Status:         https://datatracker.ietf.org/doc/draft-ponchon-ipsecme-anti-replay-subspaces/
Htmlized:       https://datatracker.ietf.org/doc/html/draft-ponchon-ipsecme-anti-replay-subspaces


Abstract:
   This document discusses the challenges of running IPsec with anti-
   replay in environments where packets may be re-ordered (e.g., when
   sent over multiple IP paths, traffic-engineered paths and/or using
   different QoS classes) as well as when processed on multiple cores.
   Different approaches to solving this problem are discussed, and a new
   solution based on splitting the anti-replay sequence number space
   into multiple different sequencing subspaces is proposed.  Since this
   solution requires support on both parties, an IKE extension is
   proposed in order to negotiate the use of the Anti-Replay sequence
   number subspaces.




The IETF Secretariat