"Magic Numbers" for ISAKMP Protocol

Last Updated
2023-04-25
Note
All registries listed below have been closed. See [RFC 9395]. 
  
Available Formats

XML

HTML

TXT

Registries Included Below

IPSEC Situation Definition

Registration Procedure(s)
Registry closed
Reference
[RFC 2407][RFC 9395]
Note
The Situation Definition is a 32-bit bitmask which represents the
environment under which the IPSEC SA proposal and negotiation is
carried out.  Requests for assignments of new situations must be
accompanied by an RFC which describes the interpretation for the
associated bit.

If the RFC is not on the standards-track (i.e., it is an informational
or experimental RFC), it must be explicitly reviewed and approved by
the IESG before the RFC is published and the transform identifier is
assigned.

The upper two bits are reserved for private use amongst cooperating
systems.
    
Available Formats

CSV
Value Situation References
0x01 SIT_IDENTITY_ONLY [RFC 2407]
0x02 SIT_SECRECY [RFC 2407]
0x04 SIT_INTEGRITY [RFC 2407]

IPSEC Security Protocol Identifiers

Registration Procedure(s)
Registry closed
Reference
[RFC 2407][RFC 9395]
Note
The Security Protocol Identifier is an 8-bit value which identifies a
security protocol suite being negotiated.  Requests for assignments of
new security protocol identifiers must be accompanied by an RFC which
describes the requested security protocol.  [AH] and [ESP] are
examples of security protocol documents.

If the RFC is not on the standards-track (i.e., it is an informational
or experimental RFC), it must be explicitly reviewed and approved by
the IESG before the RFC is published and the transform identifier is
assigned.
    
Available Formats

CSV
Value Protocol ID References
0 RESERVED [RFC 2407]
1 PROTO_ISAKMP [RFC 2407]
2 PROTO_IPSEC_AH [RFC 2407]
3 PROTO_IPSEC_ESP [RFC 2407]
4 PROTO_IPCOMP [RFC 2407]
5 PROTO_GIGABEAM_RADIO [RFC 4705]
6-248 Unassigned
249-255 Reserved for private use

IPSEC ISAKMP Transform Identifiers

Registration Procedure(s)
Registry closed
Reference
[RFC 2407][RFC 9395]
Note
The IPSEC ISAKMP Transform Identifier is an 8-bit value which
identifies a key exchange protocol to be used for the negotiation.
Requests for assignments of new ISAKMP transform identifiers must be
accompanied by an RFC which describes the requested key exchange
protocol.  [IKE] is an example of one such document.

If the RFC is not on the standards-track (i.e., it is an informational
or experimental RFC), it must be explicitly reviewed and approved by
the IESG before the RFC is published and the transform identifier is
assigned.
    
Available Formats

CSV
Value Transform References
0 RESERVED [RFC 2407]
1 KEY_IKE [RFC 2407]
2-248 Unassigned
249-255 Reserved for private use

IPSEC AH Transform Identifiers

Registration Procedure(s)
Registry closed
Reference
[RFC 2407][RFC 9395]
Note
The IPSEC AH Transform Identifier is an 8-bit value which identifies a
particular algorithm to be used to provide integrity protection for
AH.  Requests for assignments of new AH transform identifiers must be
accompanied by an RFC which describes how to use the algorithm within
the AH framework ([AH]).

If the RFC is not on the standards-track (i.e., it is an informational
or experimental RFC), it must be explicitly reviewed and approved by
the IESG before the RFC is published and the transform identifier is
assigned.
    
Available Formats

CSV
Value Transform ID References
0-1 RESERVED [RFC 2407]
2 AH_MD5 [RFC 2407]
3 AH_SHA [RFC 2407]
4 AH_DES [RFC 2407]
5 AH_SHA2-256 [RFC 4868]
6 AH_SHA2-384 [RFC 4868]
7 AH_SHA2-512 [RFC 4868]
8 AH_RIPEMD [RFC 2857]
9 AH_AES-XCBC-MAC [RFC 3566]
10 AH_RSA [RFC 4359]
11 AH_AES-128-GMAC [RFC 4543][RFC Errata 1821]
12 AH_AES-192-GMAC [RFC 4543][RFC Errata 1821]
13 AH_AES-256-GMAC [RFC 4543][RFC Errata 1821]
14-248 Unassigned
249-255 Reserved for private use

IPSEC ESP Transform Identifiers

Registration Procedure(s)
Registry closed
Reference
[RFC 2407][RFC 9395]
Note
The IPSEC ESP Transform Identifier is an 8-bit value which identifies
a particular algorithm to be used to provide secrecy protection for
ESP.  Requests for assignments of new ESP transform identifiers must
be accompanied by an RFC which describes how to use the algorithm
within the ESP framework ([ESP]).

If the RFC is not on the standards-track (i.e., it is an informational
or experimental RFC), it must be explicitly reviewed and approved by
the IESG before the RFC is published and the transform identifier is
assigned.
    
Available Formats

CSV
Value Transform ID References
0 RESERVED [RFC 2407]
1 ESP_DES_IV64 [RFC 2407]
2 ESP_DES [RFC 2407]
3 ESP_3DES [RFC 2407]
4 ESP_RC5 [RFC 2407]
5 ESP_IDEA [RFC 2407]
6 ESP_CAST [RFC 2407]
7 ESP_BLOWFISH [RFC 2407]
8 ESP_3IDEA [RFC 2407]
9 ESP_DES_IV32 [RFC 2407]
10 ESP_RC4 [RFC 2407]
11 ESP_NULL [RFC 2407]
12 ESP_AES-CBC [RFC 3602]
13 ESP_AES-CTR [RFC 3686]
14 ESP_AES-CCM_8 [RFC 4309][1]
15 ESP_AES-CCM_12 [RFC 4309][1]
16 ESP_AES-CCM_16 [RFC 4309][1]
17 Unassigned
18 ESP_AES-GCM_8 [RFC 4106][1]
19 ESP_AES-GCM_12 [RFC 4106][1]
20 ESP_AES-GCM_16 [RFC 4106][1]
21 ESP_SEED_CBC [RFC 4196]
22 ESP_CAMELLIA [RFC 4312]
23 ESP_NULL_AUTH_AES-GMAC [RFC 4543][RFC Errata 1821]
24-248 Unassigned
249-255 Reserved for private use

IPSEC IPCOMP Transform Identifiers

Registration Procedure(s)
Registry closed
Reference
[RFC 2407][RFC 9395]
Note
The IPSEC IPCOMP Transform Identifier is an 8-bit value which
identifier a particular algorithm to be used to provide IP-level
compression before ESP.  Requests for assignments of new IPCOMP
transform identifiers must be accompanied by an RFC which describes
how to use the algorithm within the IPCOMP framework ([IPCOMP]).  In
addition, the requested algorithm must be published and in the public
domain.

If the RFC is not on the standards-track (i.e., it is an informational
or experimental RFC), it must be explicitly reviewed and approved by
the IESG before the RFC is published and the transform identifier is
assigned.
    
Available Formats

CSV
Value Transform ID References
0 RESERVED [RFC 2407]
1 IPCOMP_OUI [RFC 2407]
2 IPCOMP_DEFLATE [RFC 2407]
3 IPCOMP_LZS [RFC 2407]
4 IPCOMP_LZJH [RFC 3051]
5-47 Reserved for approved algorithms
48-63 Reserved for private use
64-255 Unassigned

IPSEC Security Association Attributes

Registration Procedure(s)
Registry closed
Reference
[RFC 2407][RFC 9395]
Note
The IPSEC Security Association Attribute consists of a 16-bit type and
its associated value.  IPSEC SA attributes are used to pass
miscellaneous values between ISAKMP peers.  Requests for assignments
of new IPSEC SA attributes must be accompanied by an Internet Draft
which describes the attribute encoding (Basic/Variable-Length) and its
legal values.  Section 4.5 of this document provides an example of
such a description.
    
Available Formats

CSV
Value Type Class References
1 B SA Life Type [RFC 2407]
2 V SA Life Duration [RFC 2407]
3 B Group Description [RFC 2407]
4 B Encapsulation Mode [RFC 2407]
5 B Authentication Algorithm [RFC 2407]
6 B Key Length [RFC 2407]
7 B Key Rounds [RFC 2407]
8 B Compress Dictionary Size [RFC 2407]
9 V Compress Private Algorithm [RFC 2407]
10 B ECN Tunnel [RFC 3168]
11 B Extended (64-bit) Sequence Number [RFC 4304]
12 V Authentication Key Length [RFC 4359]
13 B Signature Encoding Algorithm [RFC 4359]
14 B Address Preservation [RFC 6407]
15 B SA Direction [RFC 6407]
16-32000 Unassigned
32001-32767 Reserved for private use

SA Life Type Values (Value 1)

Registration Procedure(s)
Registry closed
Reference
[RFC 2407][RFC 9395]
Available Formats

CSV
Value Name References
0 Reserved [RFC 2407]
1 seconds [RFC 2407]
2 kilobytes [RFC 2407]
3-61439 Unassigned
61440-65535 Reserved for private use

Group Description (Value 3)

Note
Please refer to the registry Group Description (Value 4) at [IANA registry ipsec-registry]

Encapsulation Mode (Value 4)

Registration Procedure(s)
Registry closed
Reference
[RFC 2407][RFC 9395]
Available Formats

CSV
Value Name References
0 Reserved [RFC 2407]
1 Tunnel [RFC 2407]
2 Transport [RFC 2407]
3 UDP-Encapsulated-Tunnel [RFC 3947]
4 UDP-Encapsulated-Transport [RFC 3947]
5-61439 Unassigned
61440-65535 Reserved for private use

Authentication Algorithm (Value 5)

Registration Procedure(s)
Registry closed
Reference
[RFC 2407][RFC 9395]
Available Formats

CSV
Value Name References
0 Reserved [RFC 2407]
1 HMAC-MD5 [RFC 2407]
2 HMAC-SHA [RFC 2407]
3 DES-MAC [RFC 2407]
4 KPDK [RFC 2407]
5 HMAC-SHA2-256 [Marcus_Leech][IPSEC]
6 HMAC-SHA2-384 [Marcus_Leech][IPSEC]
7 HMAC-SHA2-512 [Marcus_Leech][IPSEC]
8 HMAC-RIPEMD [RFC 2857]
9 AES-XCBC-MAC [RFC 3566]
10 SIG-RSA [RFC 4359]
11 AES-128-GMAC [RFC 4543][RFC Errata 1821]
12 AES-192-GMAC [RFC 4543][RFC Errata 1821]
13 AES-256-GMAC [RFC 4543][RFC Errata 1821]
14-61439 Unassigned
61440-65535 Reserved for private use

Compression Private Algorithm (Value 9)

Registration Procedure(s)
IANA does not assign
Reference
[RFC 2407]
Note
Specifies a private vendor compression algorithm.  The first
three (3) octets must be an IEEE assigned company_id (OUI).
The next octet may be a vendor specific compression subtype,
followed by zero or more octets of vendor data.
Registry is empty.

ECN Tunnel (Value 10)

Registration Procedure(s)
Registry closed
Reference
[RFC 3168][RFC 9395]
Note
If unspecified, the default shall be assumed to be Forbidden.
Available Formats

CSV
Value Name References
0 Reserved [RFC 3168]
1 Allowed [RFC 3168]
2 Forbidden [RFC 3168]
3-61439 Unassigned
61440-65535 Reserved for private use

Extended (64-bit) Sequence Number (Value 11)

Registration Procedure(s)
No additional class values will be assigned for this attribute.
Reference
[RFC 4304][RFC 9395]
Available Formats

CSV
Value Name References
0 RESERVED [RFC 4304]
1 64-bit Sequence Number [RFC 4304]

Signature Encoding Algorithm Values (Value 13)

Registration Procedure(s)
Registry closed
Reference
[RFC 4359][RFC 9395]
Available Formats

CSV
Value Name References
0 Reserved [RFC 4359]
1 RSASSA-PKCS1-v1_5 [RFC 4359]
2 RSASSA-PSS [RFC 4359]
3-61439 Unassigned
61440-65535 Reserved for private use

Address Preservation (Value 14)

Registration Procedure(s)
Registry closed
Reference
[RFC 6407][RFC 9395]
Available Formats

CSV
Value Name References
0 Reserved [RFC 6407]
1 None [RFC 6407]
2 Source-Only [RFC 6407]
3 Destination-Only [RFC 6407]
4 Source-and-Destination [RFC 6407]
5-61439 Unassigned
61440-65535 Private Use [RFC 6407]

SA Direction (Value 15)

Registration Procedure(s)
Registry closed
Reference
[RFC 6407][RFC 9395]
Available Formats

CSV
Value Name References
0 Reserved [RFC 6407]
1 Sender-Only [RFC 6407]
2 Receiver-Only [RFC 6407]
3 Symmetric [RFC 6407]
4-61439 Unassigned [RFC 6407]
61440-65535 Private Use [RFC 6407]

IPSEC Labeled Domain Identifiers

Registration Procedure(s)
Registry closed
Reference
[RFC 2407][RFC 9395]
Note
The IPSEC Labeled Domain Identifier is a 32-bit value which identifies
a namespace in which the Secrecy and Integrity levels and categories
values are said to exist.  Requests for assignments of new IPSEC
Labeled Domain Identifiers should be granted on demand.  No
accompanying documentation is required, though Internet Drafts are
encouraged when appropriate.
    
Available Formats

CSV
Value Domain References
0 Reserved [RFC 2407]
0x80000000-0xffffffff Reserved for private use

IPSEC Identification Type

Registration Procedure(s)
Registry closed
Reference
[RFC 2407][RFC 9395]
Note
The IPSEC Identification Type is an 8-bit value which is used as a
discriminant for interpretation of the variable-length Identification
Payload.  Requests for assignments of new IPSEC Identification Types
must be accompanied by an RFC which describes how to use the
identification type within IPSEC.

If the RFC is not on the standards track (i.e., it is an informational
or experimental RFC), it must be explicitly reviewed and approved by
the IESG before the RFC is published and the transform identifier is
assigned.
    
Available Formats

CSV
Value ID Type References
0 RESERVED [RFC 2407]
1 ID_IPV4_ADDR [RFC 2407]
2 ID_FQDN [RFC 2407]
3 ID_USER_FQDN [RFC 2407]
4 ID_IPV4_ADDR_SUBNET [RFC 2407]
5 ID_IPV6_ADDR [RFC 2407]
6 ID_IPV6_ADDR_SUBNET [RFC 2407]
7 ID_IPV4_ADDR_RANGE [RFC 2407]
8 ID_IPV6_ADDR_RANGE [RFC 2407]
9 ID_DER_ASN1_DN [RFC 2407]
10 ID_DER_ASN1_GN [RFC 2407]
11 ID_KEY_ID [RFC 2407]
12 ID_LIST [RFC 3554]
13-248 Unassigned
249-255 Reserved for private use

IPSEC Notify Message Types

Registration Procedure(s)
Registry closed
Reference
[RFC 2407][RFC 9395]
Note
The IPSEC Notify Message Type is a 16-bit value taken from the range
of values reserved by ISAKMP for each DOI.  There is one range for
error messages (8192-16383) and a different range for status messages
(24576-32767).  Requests for assignments of new Notify Message Types
must be accompanied by an Internet Draft which describes how to use
the identification type within IPSEC.
    

Notify Messages - Error Types (8192-16383)

Registration Procedure(s)
Registry closed
Reference
[RFC 9395]
Available Formats

CSV
Value Notify Messages - Error Types References
8192 Reserved [RFC 2407]
8193-16000 Unassigned
16001-16383 Reserved for private use

Notify Messages - Status Types (24576-32767)

Registration Procedure(s)
Registry closed
Reference
[RFC 9395]
Available Formats

CSV
Value Notify Messages - Status Types References
24576 RESPONDER-LIFETIME [RFC 2407]
24577 REPLAY-STATUS [RFC 2407]
24578 INITIAL-CONTACT [RFC 2407]
24579-32000 Unassigned
32001-32767 Reserved for private use

Contact Information

ID Name Contact URI Last Updated
[IPSEC] IETF IPSEC WG mailto:ipsec&ietf.org 2023-01-04
[Marcus_Leech] Marcus Leech mailto:mleech&nortelnetworks.com 2000-10

Footnote

[1]
This is combined mode cipher, but combined mode algorithms are not
a ature of IPsec-v2. Although some IKEv1/IPsec-v2 implementations 
inude this capability (see [RFC 6071] Section 5.4), it is not part of 
thprotocol.