Re: [fw-wiz] IPv6 and IPSec

From: Paul D. Robertson (paul_at_compuwar.net)
Date: 08/28/04

  • Next message: ROUMEGOUX Pierre: "RE: [fw-wiz] Netscreen compatibility"
    To: suren <suren@intotoinc.com>
    Date: Sat, 28 Aug 2004 09:43:33 -0400 (EDT)
    
    

    On Thu, 26 Aug 2004, suren wrote:

    > Hi,
    > IPSec based security is MUST for IPv6. Due to this, I would
    > assume that end systems would use IPSec to secure the traffic
    > going out.

    Why? It's not a must for IPv4, why would adding address space suddenly
    require IPSec? Heck, the cascading headers for V6 offer the chance for
    pseudo-out-of-band control and encapsulation, why again would you use
    IPSec?

    >
    > Quite a number of times, organizations would like to filter out
    > the connection(Firewall) run the data through centralized virus
    > scanning/spam scanning engines. This requires clear traffic.
    >

    Not quite, it requires the ability to inspect the traffic, which is a
    different thing entirely. There was, at one point, a major push to do
    alternate decryption keys for such purposes.

    > With respect to these, I have questions on how the deployments
    > going to be. One type of depolyments I can think of is:
    >
    > Central gateway implementing Firewall/Virus Scanning
    > engine and also terminting IPSec tunnels from local PCs and
    > creating tunnels from the gateway to ultimate destination.
    > By doing this, the gateway gets hold of clear packets, can
    > apply firewall rules, scan and any other operations.
    >
    > What other types of deployments would be required/considered by
    > organizations having IPv6 networks?

    The same as today- where we have those (application layer firewalls, for
    instance) as well as NAT and straight through and trust the host security
    and bunches of others. The only thing v6 brings that might be
    "interesting" from a security perspective[1] is encapsulated or cascading
    headers, that'll allow some socks-like stuff to happen if enough people
    get momentum (likely though it'll be QoS that first tries it.)

    Paul
    [1] Admittedly, I haven't looked at v6 in a good number of years, so
    something may have changed since I looked at the drafts way back when.
    -----------------------------------------------------------------------------
    Paul D. Robertson "My statements in this message are personal opinions
    paul@compuwar.net which may have no basis whatsoever in fact."
    probertson@trusecure.com Director of Risk Assessment TruSecure Corporation
    _______________________________________________
    firewall-wizards mailing list
    firewall-wizards@honor.icsalabs.com
    http://honor.icsalabs.com/mailman/listinfo/firewall-wizards


  • Next message: ROUMEGOUX Pierre: "RE: [fw-wiz] Netscreen compatibility"

    Relevant Pages

    • Re: Encryption for IPv6
      ... >>to the separate IPSec workgroup years ago, ... my understanding is that IPSec is mandatory in IPv6 ... Leaving security features out of application protocols was one of the ...
      (sci.crypt)
    • Re: [fw-wiz] IPv6 and IPSec
      ... > require IPSec? ... And "support" can be a nebulus thing. ... all of IPv4 in toto. ... And something like 40 million IPv6 networks are routable in the ...
      (Firewall-Wizards)
    • [NEWS] Cisco IPSec IKE Multiple DoS Vulnerabilities
      ... Get your security news from a reliable source. ... IP Security, or IPSec, is a set of protocols standardized by the IETF to ... Multiple Cisco products contain vulnerabilities in the processing of IPSec ... an IPSec connection between them for the purposes of connecting two remote ...
      (Securiteam)
    • [NEWS] Multiple Crafted IPv6 Packets Cause Reload
      ... Get your security news from a reliable source. ... Denial of Service attack from crafted IPv6 packets when the device ... Cisco has made free software available to address this vulnerability. ... Infrastructure Protection Access Control Lists", ...
      (Securiteam)
    • Re: Isolate systems
      ... You also may want to download the " Securing Windows 2000 Server Security ... to use ipsec "filtering" policies to secure domain controllers and other ... >> filtering policy on your computers which is a policy that uses rules with ...
      (microsoft.public.win2000.security)