• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

Why no ESP-NULL?

Scheduled Pinned Locked Moved IPsec
6 Posts 2 Posters 2.4k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • M
    mmcc
    last edited by Aug 26, 2011, 2:23 PM

    I've got an application in mind where authentication and data integrity is important, but confidentiality not so much. I'd like to do IPSec without encryption.

    I've tried setting up an AH tunnel, but without luck (subject of a different thread). The other option seems to be using the NULL encryption option:

    http://www.ietf.org/rfc/rfc2410.txt

    However, this isn't supported by pfSense.

    Is there any particular reason?

    1 Reply Last reply Reply Quote 0
    • J
      jimp Rebel Alliance Developer Netgate
      last edited by Aug 26, 2011, 3:05 PM

      If it's pfSense on both ends, we do support the null cipher in OpenVPN.

      Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

      Need help fast? Netgate Global Support!

      Do not Chat/PM for help!

      1 Reply Last reply Reply Quote 0
      • M
        mmcc
        last edited by Aug 26, 2011, 3:07 PM

        I did not know that. Unfortunately, it will not be pfSense on both ends, and on the non-pfSense end only IPSec will be possible.

        1 Reply Last reply Reply Quote 0
        • J
          jimp Rebel Alliance Developer Netgate
          last edited by Aug 26, 2011, 3:09 PM

          Then AH would be what you'd be after then. I've never tried AH so I'm not sure on the particulars, but in theory it should do the job.

          Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

          Need help fast? Netgate Global Support!

          Do not Chat/PM for help!

          1 Reply Last reply Reply Quote 0
          • M
            mmcc
            last edited by Aug 26, 2011, 3:11 PM

            I am indeed after AH. Unfortunately, that hasn't been going terribly well :) (see the next thread down).

            With respect to esp-null, I was just curious if there was a particular reason it hadn't been implemented, or if it just hadn't bubbled to the top.

            Thanks!

            1 Reply Last reply Reply Quote 0
            • J
              jimp Rebel Alliance Developer Netgate
              last edited by Aug 26, 2011, 3:13 PM

              Nobody has ever asked for esp-null to my knowledge, so it's probably lack of demand (and hence lack of funding or submitted code).

              The use cases for it are pretty rare as well.

              Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

              Need help fast? Netgate Global Support!

              Do not Chat/PM for help!

              1 Reply Last reply Reply Quote 0
              6 out of 6
              • First post
                6/6
                Last post
              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
                This community forum collects and processes your personal information.
                consent.not_received