[go: up one dir, main page]
More Web Proxy on the site http://driver.im/ skip to main content
10.1007/11556992_14guideproceedingsArticle/Chapter ViewAbstractPublication PagesConference Proceedingsacm-pubtype
Article

IPSec support in NAT-PT scenario for IPv6 transition

Published: 20 September 2005 Publication History

Abstract

Applying IPSec in NAT-PT environment for end-to-end security fails due to the problems caused by the IP header conversion in NAT-PT server. The IP header conversion causes the receiver to fail to verify the TCP/UDP checksum and the ICV value of the AH header. This study analyses potential problems in applying the IPSec between the IPv6-only node and an IPv4-only node, and proposes a solution to enable the receiver successfully ver-ify the IPSec packet. We also analyze that why the existing NAT-traversal so-lutions in IPv4 fails in NAT-PT environment.

References

[1]
G. Tsirtsis, P. Srisuresh.: Network Address Translation Protocol Translation (NAT-PT), RFC 2766. 2000. 2.
[2]
S. Satapati.: NAT-PT Applicability, draft-satapati-v6ops-natpt-applicability-00. October 2003.
[3]
Egevang, K. and P. Francis.: The IP Network Address Translator (NAT), RFC 1631. 1994. 5.
[4]
Kivinen, T.: Negotiation of NAT-Traversal in the IKE, draft-ietf-IPSec-nat-t-ike-08. February 2004.
[5]
Huttunen, A. et. al.: UDP Encapsulation of IPSec Packets, draft-ietf-IPSec-udp-encaps-6.txt. January 2003.
[6]
G. Montenegro, M. Borella.: RSIP Support for End-to-end IPSec, RFC 3104. October 2001.
[7]
E. Nordmark.: Stateless IP/ICMP Translation Algorithm (SIIT), RFC 2765. February 2000.
[8]
S. Kent, R. Atkinson.: Security Architecture for the Internet Protocol, RFC 2401. November 1998.
[9]
S. Kent, R. Atkinson.: IP Encapsulating Security Payload (ESP), RFC 2406. November 1998.
[10]
S. Kent, R. Atkinson.: IP Authentication Header, RFC 2402. November 1998.
[11]
D. Harkins, D. Carrel.: The Internet Key Exchange (IKE), RFC 2409. November 1998.
[12]
Aboba, B. et. Al.: IPSec-Network Address Translation (NAT) Compatibility Requirements, RFC 3715. March 2004.
  1. IPSec support in NAT-PT scenario for IPv6 transition

    Recommendations

    Comments

    Please enable JavaScript to view thecomments powered by Disqus.

    Information & Contributors

    Information

    Published In

    cover image Guide Proceedings
    ISC'05: Proceedings of the 8th international conference on Information Security
    September 2005
    516 pages
    ISBN:354029001X
    • Editors:
    • Jianying Zhou,
    • Javier Lopez,
    • Robert H. Deng,
    • Feng Bao

    Sponsors

    • Singapore Management University: Singapore Management University
    • Institute for Infocomm Research, A*STAR

    Publisher

    Springer-Verlag

    Berlin, Heidelberg

    Publication History

    Published: 20 September 2005

    Author Tags

    1. IKE
    2. IPSec
    3. IPv6 transition
    4. NAT-PT

    Qualifiers

    • Article

    Contributors

    Other Metrics

    Bibliometrics & Citations

    Bibliometrics

    Article Metrics

    • 0
      Total Citations
    • 0
      Total Downloads
    • Downloads (Last 12 months)0
    • Downloads (Last 6 weeks)0
    Reflects downloads up to 28 Dec 2024

    Other Metrics

    Citations

    View Options

    View options

    Media

    Figures

    Other

    Tables

    Share

    Share

    Share this Publication link

    Share on social media