tunnel mode
Click on the red underlined text to get to the source
... the requirements for host configuration in IPsec tunnel mode, and
describes how DHCPv4 may be leveraged for configuration.
...
... IPsec tunnel mode configuration requirements ...
... requirements of a host with
an IPsec tunnel mode interface include the need to obtain an IPv4
address and other configuration parameters ...
...
Leveraging DHCP for configuration of IPsec tunnel mode meets the
basic requirements described in [21 ...
... IPv4, leveraging DHCPv4 [3] for the configuration of IPsec
tunnel mode satisfies the basic requirements described in [21].
...
... authentication [5] is required, this can be
supported on an IPsec tunnel mode interface as it would be on
any other interface ...
... requirements, nor does it provide the additional capabilities. As a
result, DHCPv4 is the superior alternative for IPsec tunnel mode
configuration.
...
... security gateway,
using IPsec tunnel mode. This host is then configured in such a
manner so as to provide it with a virtual presence on the internal
...
... interfaces are used in the outer and inner headers of the
IPsec tunnel mode packet, respectively.
...
... The configuration of the intranet interface of the IPsec tunnel mode
host is accomplished in the following steps:
...
... remote host establishes a DHCP SA with the IPsec tunnel mode
server in a quick mode exchange. The DHCP ...
... quick mode exchange. The DHCP SA is an IPsec tunnel
mode SA established to protect initial DHCPv4 traffic ...
... tunnel is required, the remote host establishes a
tunnel mode SA to the security gateway in a quick mode exchange.
...
... htype 1 Hardware address type. Set to value 31.
signifying an IPsec tunnel mode virtual interface.
hlen 1 Hardware address ...
... DHCP message
The htype value is set to the value 31, signifying a virtual IPsec
tunnel mode interface, in order to enable the DHCP server to
...
... DHCPDISCOVER or DHCPREQUEST) is then tunneled to the security
gateway using the tunnel mode SA. Note that since the DHCPDISCOVER
packet has a broadcast ...
... the security gateway (acting as a DHCP Relay) using the IPsec tunnel
mode SA, including DHCPOFFER, DHCPACK ...
...
This document requires that an htype value be allocated for use with
IPsec tunnel mode, as described in section 4.1. Note that DHCP
relies on the arp-parameters registry ...
