• DocumentCode
    3205570
  • Title

    Securing tunnel endpoints for IPv6 transition in enterprise networks

  • Author

    Taib, Abidah Mat ; Budiarto, Rahmat

  • Author_Institution
    Faculty of Computer and Mathematical Sciences, Universiti Teknologi MARA Perlis, Arau, Malaysia
  • fYear
    2010
  • fDate
    5-7 Dec. 2010
  • Firstpage
    1114
  • Lastpage
    1119
  • Abstract
    Tunneling IPv6-in-IPv4 has become common at the early stage of IPv6 deployment. Unfortunately, tunneling introduces security threats in which intruders may spoof the address of the packet origin, and potentially inject the packet at the tunnel endpoint. Additionally, during the coexistence of both IPv4 and IPv6 in the network, one of the protocols may escape from firewall by being encapsulated in the other protocol. Mitigating the issue is possible by utilizing IPsec to authenticate the incoming packet. Nevertheless, in order to thoroughly secure the tunnel endpoints, this paper puts forward the importance of having separate firewalls to filter IPv4 as well as IPv6 packet to ensure that none of the packets can escape the filtering process. Our preliminary result shows that applying separate firewalls at the tunnel endpoints does not really cause delay or give significant effect to the filtering time.
  • Keywords
    Delay; Filtering; Fires; IP networks; Protocols; Security; Tunneling; IPsec; IPv6 transition; ingress filtering; secure tunnel endpoints;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Science and Social Research (CSSR), 2010 International Conference on
  • Conference_Location
    Kuala Lumpur, Malaysia
  • Print_ISBN
    978-1-4244-8987-9
  • Type

    conf

  • DOI
    10.1109/CSSR.2010.5773699
  • Filename
    5773699