IPsec and SCTP
The Solaris 10 release supports the Streams Control Transmission Protocol (SCTP). The use
of the SCTP protocol and SCTP port number to specify IPsec policy is
supported, but is not robust. The IPsec extensions for SCTP as specified in
RFC 3554 are not yet implemented. These limitations can create complications in creating
IPsec policy for SCTP.
SCTP can make use of multiple source and destination addresses in the context
of a single SCTP association. When IPsec policy is applied to a
single source or a single destination address, communication can fail when SCTP switches the
source or the destination address of that association. IPsec policy only recognizes the
original address. For information about SCTP, read the RFCs and SCTP Protocol.