Skip to main content

Split-DNS Configuration for IKEv2
draft-pauly-ipsecme-split-dns-00

The information below is for an old version of the document.
Document Type
This is an older version of an Internet-Draft whose latest revision state is "Replaced".
Expired & archived
Authors Tommy Pauly , Paul Wouters
Last updated 2016-04-04 (Latest revision 2015-09-24)
Replaced by draft-ietf-ipsecme-split-dns, RFC 8598
RFC stream (None)
Formats
Additional resources
Stream Stream state (No stream defined)
Consensus boilerplate Unknown
RFC Editor Note (None)
IESG IESG state Expired
Telechat date (None)
Responsible AD (None)
Send notices to (None)

This Internet-Draft is no longer active. A copy of the expired Internet-Draft is available in these formats:

Abstract

This document defines two new Configuration Payload Attribute Types for the IKEv2 protocol that together define a set of private DNS domains which should be resolved by DNS servers reachable through an IPsec connection, while leaving all other DNS resolution unchanged. This allows for split-DNS views for multiple domains and includes support for private DNSSEC trust anchors. The information obtained via the new attribute types can be used to reconfigure a locally running DNS server with DNS forwarding for specific private domains.

Authors

Tommy Pauly
Paul Wouters

(Note: The e-mail addresses provided for the authors of this Internet-Draft may no longer be valid.)