<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Why no ESP-NULL?]]></title><description><![CDATA[<p dir="auto">I've got an application in mind where authentication and data integrity is important, but confidentiality not so much. I'd like to do IPSec without encryption.</p>
<p dir="auto">I've tried setting up an AH tunnel, but without luck (subject of a different thread). The other option seems to be using the NULL encryption option:</p>
<p dir="auto">http://www.ietf.org/rfc/rfc2410.txt</p>
<p dir="auto">However, this isn't supported by pfSense.</p>
<p dir="auto">Is there any particular reason?</p>
]]></description><link>https://forum.netgate.com/topic/36704/why-no-esp-null</link><generator>RSS for Node</generator><lastBuildDate>Mon, 15 Jun 2026 11:26:46 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/36704.rss" rel="self" type="application/rss+xml"/><pubDate>Fri, 26 Aug 2011 14:23:16 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to Why no ESP-NULL? on Fri, 26 Aug 2011 15:13:30 GMT]]></title><description><![CDATA[<p dir="auto">Nobody has ever asked for esp-null to my knowledge, so it's probably lack of demand (and hence lack of funding or submitted code).</p>
<p dir="auto">The use cases for it are pretty rare as well.</p>
]]></description><link>https://forum.netgate.com/post/293350</link><guid isPermaLink="true">https://forum.netgate.com/post/293350</guid><dc:creator><![CDATA[jimp]]></dc:creator><pubDate>Fri, 26 Aug 2011 15:13:30 GMT</pubDate></item><item><title><![CDATA[Reply to Why no ESP-NULL? on Fri, 26 Aug 2011 15:11:56 GMT]]></title><description><![CDATA[<p dir="auto">I am indeed after AH. Unfortunately, that hasn't been going terribly well :) (see the next thread down).</p>
<p dir="auto">With respect to esp-null, I was just curious if there was a particular reason it hadn't been implemented, or if it just hadn't bubbled to the top.</p>
<p dir="auto">Thanks!</p>
]]></description><link>https://forum.netgate.com/post/293349</link><guid isPermaLink="true">https://forum.netgate.com/post/293349</guid><dc:creator><![CDATA[mmcc]]></dc:creator><pubDate>Fri, 26 Aug 2011 15:11:56 GMT</pubDate></item><item><title><![CDATA[Reply to Why no ESP-NULL? on Fri, 26 Aug 2011 15:09:26 GMT]]></title><description><![CDATA[<p dir="auto">Then AH would be what you'd be after then. I've never tried AH so I'm not sure on the particulars, but in theory it should do the job.</p>
]]></description><link>https://forum.netgate.com/post/293347</link><guid isPermaLink="true">https://forum.netgate.com/post/293347</guid><dc:creator><![CDATA[jimp]]></dc:creator><pubDate>Fri, 26 Aug 2011 15:09:26 GMT</pubDate></item><item><title><![CDATA[Reply to Why no ESP-NULL? on Fri, 26 Aug 2011 15:07:20 GMT]]></title><description><![CDATA[<p dir="auto">I did not know that. Unfortunately, it will not be pfSense on both ends, and on the non-pfSense end only IPSec will be possible.</p>
]]></description><link>https://forum.netgate.com/post/293345</link><guid isPermaLink="true">https://forum.netgate.com/post/293345</guid><dc:creator><![CDATA[mmcc]]></dc:creator><pubDate>Fri, 26 Aug 2011 15:07:20 GMT</pubDate></item><item><title><![CDATA[Reply to Why no ESP-NULL? on Fri, 26 Aug 2011 15:05:47 GMT]]></title><description><![CDATA[<p dir="auto">If it's pfSense on both ends, we do support the null cipher in OpenVPN.</p>
]]></description><link>https://forum.netgate.com/post/293344</link><guid isPermaLink="true">https://forum.netgate.com/post/293344</guid><dc:creator><![CDATA[jimp]]></dc:creator><pubDate>Fri, 26 Aug 2011 15:05:47 GMT</pubDate></item></channel></rss>