Sei sulla pagina 1di 7

2401bis: Revised Processing Model (v2)

Steve Kent BBN Technologies

Processing Model Highlights


SPDs no longer per interface; support as many as are needed in a specific context Forwarding decision separate from SPD selection decision
SPD may be selected via packet header and local metadata (e.g., inbound interface) Forwarding performed after traffic passes through IPsec

Nested SA support now optional, requires coordination between forwarding tables and SPD entries

IPsec Processing Model


BLACK

AH/ESP
IKE

IPsec boundary

RED

Next Layer of Model (Outbound)


Black Interface

Forwarding

SPD cache

AH/ESP

SPD Selection

Red Interface

Next Layer of Model (Inbound)


Black Interface

demux

Bypass/ discard

AH/ESP
IKE SAD check

Forwarding

Red Interface

IPsec Outbound Traffic Processing


discard

SPD Selection

Red interface

SPD outbound cache


miss
create SA

bypass Forwarding AH/ESP SAD SA creation (IKE) SPD-I cache


Black interface

create new cache entry

SPD lookup

This example assumes a decorrelated cache

IPsec Handling of Inbound Packet


discard

Red interface

SAD Selector check

IKE discard SPD outbound cache SPD

forwarding

AH/ESP

SAD lookup SPD-I

IPsec

IP proc
~IPsec

Black interface

Potrebbero piacerti anche