[rfc-dist] RFC 5879 on Heuristics for Detecting ESP-NULL Packets

rfc-editor at rfc-editor.org rfc-editor at rfc-editor.org
Thu May 27 11:26:57 PDT 2010

A new Request for Comments is now available in online RFC libraries.

        RFC 5879

        Title:      Heuristics for Detecting ESP-NULL Packets 
        Author:     T. Kivinen, D. McDonald
        Status:     Informational
        Stream:     IETF
        Date:       May 2010
        Mailbox:    kivinen at iki.fi, 
                    danmcd at opensolaris.org
        Pages:      32
        Characters: 72917
        Updates/Obsoletes/SeeAlso:   None

        I-D Tag:    draft-ietf-ipsecme-esp-null-heuristics-07.txt

        URL:        http://www.rfc-editor.org/rfc/rfc5879.txt

This document describes a set of heuristics for distinguishing IPsec
ESP-NULL (Encapsulating Security Payload without encryption) packets
from encrypted ESP packets.  These heuristics can be used on
intermediate devices, like traffic analyzers, and deep-inspection
engines, to quickly decide whether or not a given packet flow is
encrypted, i.e., whether or not it can be inspected.  Use of these
heuristics does not require any changes made on existing IPsec hosts
that are compliant with RFC 4303.  This document is not an Internet 
Standards Track specification; it is published for informational 

This document is a product of the IP Security Maintenance and Extensions Working Group of the IETF.

INFORMATIONAL: This memo provides information for the Internet community.
It does not specify an Internet standard of any kind. Distribution of
this memo is unlimited.

This announcement is sent to the IETF-Announce and rfc-dist lists.
To subscribe or unsubscribe, see

For searching the RFC series, see http://www.rfc-editor.org/rfcsearch.html.
For downloading RFCs, see http://www.rfc-editor.org/rfc.html.

Requests for special distribution should be addressed to either the
author of the RFC in question, or to rfc-editor at rfc-editor.org.  Unless
specifically noted otherwise on the RFC itself, all RFCs are for
unlimited distribution.

The RFC Editor Team
Association Management Solutions, LLC

More information about the rfc-dist mailing list