Security Parameter Index
From Wikipedia, the free encyclopedia
The Security Parameter Index (SPI) is an identification tag added to the header while using IPSec for tunneling the IP traffic. It tells the kernel which encryption rule and algorithm has been used on the traffic tagged with that SPI.
The SPI (as per RFC 2401) is an essential part of an IPSec SA (Security Association) cause it enables the receiving system to select the SA under which a received packet will be processed. An SPI has only local significance, as is defined by the creator of the SA; so an SPI is generally viewed as an opaque bit string. However, the creator of an SA may interpret the bits in an SPI to facilitate local processing.