Re: [fw-wiz] IPv6 and IPSec

From: Devdas Bhagat (devdas_at_dvb.homelinux.org)
Date: 08/28/04

  • Next message: Kevin Sheldrake: "Re: [fw-wiz] Instance Messengers and Firewalls"
    To: firewall-wizards@honor.icsalabs.com
    Date: Sat, 28 Aug 2004 05:22:32 +0530
    
    

    On 26/08/04 13:47 -0700, suren wrote:
    > Hi,
    > IPSec based security is MUST for IPv6. Due to this, I would
    > assume that end systems would use IPSec to secure the traffic
    > going out.
    >
    > Quite a number of times, organizations would like to filter out
    > the connection(Firewall) run the data through centralized virus
    > scanning/spam scanning engines. This requires clear traffic.
    >
    > With respect to these, I have questions on how the deployments
    > going to be. One type of depolyments I can think of is:
    >
    > Central gateway implementing Firewall/Virus Scanning
    > engine and also terminting IPSec tunnels from local PCs and
    > creating tunnels from the gateway to ultimate destination.
    > By doing this, the gateway gets hold of clear packets, can
    > apply firewall rules, scan and any other operations.

    Too complex. IPSec will not be a tunnel in IPv6. What you have referred
    to above, is just an ALG. Just ask Marcus :)

    > What other types of deployments would be required/considered by
    > organizations having IPv6 networks?

    Broken ones? Where simple packet filtering will continue to be used, and
    then they will throw good money at IPS rather than using the firewall
    for what it was designed to do.

    Devdas Bhagat
    _______________________________________________
    firewall-wizards mailing list
    firewall-wizards@honor.icsalabs.com
    http://honor.icsalabs.com/mailman/listinfo/firewall-wizards


  • Next message: Kevin Sheldrake: "Re: [fw-wiz] Instance Messengers and Firewalls"

    Relevant Pages

    • Re: [fw-wiz] IPv6 and IPSec
      ... > require IPSec? ... And "support" can be a nebulus thing. ... all of IPv4 in toto. ... And something like 40 million IPv6 networks are routable in the ...
      (Firewall-Wizards)
    • Re: Ipv6 - performance results on red hat linux.
      ... similar things but IPsec happens at a different layer unless ... The processes then would tend to be CPU bound, not protocol stack bound so ... repeating the same tests with IPv6 should produce the same differences ... (also note - RedHat Linux or another brand of linux will produce extremely ...
      (RedHat)
    • [fw-wiz] IPv6 and IPSec
      ... IPSec based security is MUST for IPv6. ... assume that end systems would use IPSec to secure the traffic ... scanning/spam scanning engines. ...
      (Firewall-Wizards)
    • Re: [fw-wiz] IPv6 and IPSec
      ... > the security stuff is tightly marshalled over IPv6. ... Tunnels have always been an issue for protected networks. ... You don't have to support IPSec to be IPv4 compliant, ...
      (Firewall-Wizards)
    • Re: [fw-wiz] IPv6 and IPSec
      ... > IPSec based security is MUST for IPv6. ... Paul D. Robertson "My statements in this message are personal opinions ...
      (Firewall-Wizards)