Page MenuHomeVyOS Platform

Add ESN support for IPSec
Open, Requires assessmentPublicFEATURE REQUEST

Description

Summary

It would be beneficial to add ESN support for IPSec connections that handle a lot of packets in short time.

Use case

More details here: https://docs.strongswan.org/docs/latest/config/proposals.html#_extended_sequence_numbers_esn

Additional information

Requirements:

  • update strongSwan to 6.0 (according to the changelog, it contains important fixes for ESN, also it is documented only in the docs for the 6.0 version), or backport necessary fixes.
  • add ESN in CLI for ESP profiles.

Details

Version
-
Is it a breaking change?
Perfectly compatible
Issue type
Feature (new functionality)