Re: ISPs can easily decrease net abuse

From: Walter Roberson (roberson_at_ibd.nrc-cnrc.gc.ca)
Date: 12/02/03

  • Next message: Walter Roberson: "Re: ISPs can easily decrease net abuse"
    Date: 2 Dec 2003 03:59:39 GMT
    
    

    In article <0TTyb.118354$Fv8.114900@twister01.bloor.is.net.cable.rogers.com>,
    booster <saltynuts2002@msn.com> wrote:
    :ipv6 isn't only about shortage.. it has better security and a host of
    :features too. For example you can't do ipsec over NAT. NAT is a hack and we
    :all know hacks will burn you sooner or later

    You *can* do IPSec over NAT.

    IPSec defines multiple layers: the payload itself (possibly
    encrypted), encryption headers (ESP), and authentication headers (AH).
    AH is optional, and if you don't have it turned on, then you can
    still use the authentication layer that ESP provides for the payload;
    AH adds authentication of the IP addresses themselves.

    It was not possible before to do AH over NAT, but there is now a
    draft IETF "UDP Encpasulation of IPSec Packets",
    http://www.ietf.org/html.charters/ipsec-charter.html
    This UDP encapsulation routine -automatically- detects whether
    one or both ends of the link are undergoing NAT, and does encapsulation
    via UDP 4500 only if necessary.

    -- 
       "There are three kinds of lies: lies, damn lies, and statistics."
       -- not Twain, perhaps Disraeli, first quoted by Leonard Courtney
    

  • Next message: Walter Roberson: "Re: ISPs can easily decrease net abuse"

    Relevant Pages

    • Re: VPN through NAT?
      ... IPSEC NAT traversal uses UDP 4500? ... I belive 4500 is Cisco's way of doing it, but not all IPSEC vpn clients are the same. ...
      (freebsd-isp)
    • Re: L2TP/IPSec Verbindung läuft mit XP SP2 nicht mehr
      ... In XPSP2 the IPsec driver needs a registry setting when either the ... server or workstation are behind a NAT gateway. ... 1- Client initiates to a server that is behind the NAT ... > Peer Private Addr ...
      (microsoft.public.de.german.windowsxp.networking)
    • Re: =?iso-8859-15?Q?Verst=E4ndnisfrage?= IPSec; NAT; NAT-T
      ... IPSec Passthrough ... Der Trick bei NAT Traversal scheint ja zu sein, ... Port 500 UDP auf diesen, ... Der eigentliche IPSEC tunnel wird dann nach Standard ueber UDP Port ...
      (de.comp.security.firewall)
    • Re: IPsec + NAT + mehrere Tunnelendpunkte
      ... Ist der VPN-Endpunkt ein Cisco Concentrator oder eine PIX? ... Und warum macht er dort ueberhaupt doppelt NAT? ... Session-Keys des IPSEC Tunnels verwendet. ...
      (de.comp.security.firewall)
    • Re: VPN From W2K/Pro to W2K Server Doesn;t Work Through Firewall
      ... My belief is that your NAT ... My understanding is that IPSec AH protocol does not work with NAT devices ... IPSec operates in either one of two modes - transport mode or tunnel mode. ... provide a VPN remote access solution. ...
      (microsoft.public.win2000.security)