Desktop Nics with Cryptography offloading

From: Justin Funke (Jfunke@kortexcomputer.com)
Date: 07/19/01


Message-ID: <0FA4FC04D3B1D411B34F0090275BE0630126D38C@SM-MAIL>
From: Justin Funke <Jfunke@kortexcomputer.com>
To: SECURITY-BASICS@securityfocus.com
Subject: Desktop Nics with Cryptography offloading
Date: Thu, 19 Jul 2001 08:52:34 -0500


-=-
Sorry for the cross post but this list seems to be more active.
-=-

I have specifically asked Intel if the "S" series NICs would offload the
encryption/decryption for standard "public" VPN's vs "LAN" encrypted
communications.

They claim that it is not possible but I don't see how this is true. If it
is offloading all IPSEC traffic how does the nic know what is public vs.
private
traffic.

http://www.intel.com/network/connectivity/resources/doc_library/data_sheets/
pro100s.pdf

And if it does have a way of detecting it - couldn't the traffic be
encapsulated to trick the Nic into thinking it was a local connection.

Any ideas?

Thanks,

Justin

VPN is sponsored by SecurityFocus.com