IPsec Was a Good Idea. It Is Time to Turn It Off.
IPsec was right in 1995: encrypt below the application, bind the security association to the IP address, let every protocol inherit it. Then NAT arrived, carrier-grade NAT finished the job, and the fix was to wrap the whole thing in UDP and keep a timer running so a translation table would not forget you. This post shows how it falls down, diagram by diagram β the security association that cannot survive a rewritten header, the two translators every CGNAT line now has, the NAT64 standard that names IPsec as out of scope, the tunnel that cannot use a second link because ESP has no ports, the MTU nobody owns, and L2TP and PPTP as the two protocols that were never fit to be here. It carries the vendor documentation from Cisco, Juniper and Microsoft that admits every one of those, the eighteen pieces that call themselves an IPsec VPN including the two that were never standards at all, why the Fisher-Price OS has never truly interoperated with an open stack, a working method for diagnosing IPsec while you still run it, and the case for retiring the lot with dates.