Research on Compatibility of IPSec and NAT
Fang Liu
Abstract
Fang Liu
Abstract
IPSec architecture is based on the concept of keeping data secure while it is being transported across a network. Therefore there are problems when packet headers change in transmission across the network, by virtue of NAT devices such as firewalls. This document discusses the incompatibilities between VPN and NAT,and the requirements for firewall traversal. Then a solution is proposed to make both initial IKE negotiations and subsequent authentication / encoded communications across IPSec AH / ESP SAs work.
A significance statement is not available in the OpenAlex record.
A contribution statement is not available in the OpenAlex record.
Method details are not available in the OpenAlex metadata.
Findings are not separately available in the OpenAlex metadata.
Limitations are not available in the OpenAlex metadata.
Application details are not available in the OpenAlex metadata.
IPSec architecture is based on the concept of keeping data secure while it is being transported across a network. Therefore there are problems when packet headers change in transmission across the network, by virtue of NAT devices such as firewalls. This document discusses the incompatibilities between VPN and NAT,and the requirements for firewall traversal. Then a solution is proposed to make both initial IKE negotiations and subsequent authentication / encoded communications across IPSec AH / ESP SAs work.
Key concepts: IPsec, NAT traversal, Computer network, Nat, Firewall (physics), Computer science, Network packet, IPv6