RFC 8598

Split DNS Configuration for the Internet Key Exchange Protocol Version 2 (IKEv2), May 2019

Canonical URL:
https://www.rfc-editor.org/rfc/rfc8598.txt
File formats:
Plain TextPDF HTML
Status:
PROPOSED STANDARD
Authors:
T. Pauly
P. Wouters
Stream:
IETF
Source:
ipsecme (sec)

Cite this RFC: TXT  |  XML

DOI:  10.17487/RFC8598

Discuss this RFC: Send questions or comments to ipsec@ietf.org

Other actions: Submit Errata  |  Find IPR Disclosures from the IETF


Abstract

This document defines two Configuration Payload Attribute Types (INTERNAL_DNS_DOMAIN and INTERNAL_DNSSEC_TA) for the Internet Key Exchange Protocol version 2 (IKEv2). These payloads add support for private (internal-only) DNS domains. These domains are intended to be resolved using non-public DNS servers that are only reachable through the IPsec connection. DNS resolution for other domains remains unchanged. These Configuration Payloads only apply to split- tunnel configurations.


For the definition of Status, see RFC 2026.

For the definition of Stream, see RFC 4844.


Download PDF Reader