Netfilter nf_tables xfrm/IPSec security association matching

modulename: nft_xfrm.ko

configname: CONFIG_NFT_XFRM

Linux Kernel Configuration
└─>Networking support
└─>Networking options
└─>Network packet filtering framework (Netfilter)
└─>Core Netfilter Configuration
└─>Netfilter nf_tables xfrm/IPSec security association matching
In linux kernel since version 4.2 (release Date: 2015-08-30)  
This option adds an expression that you can use to extract properties
of a packets security association.

source code: