DocumentCode
3205570
Title
Securing tunnel endpoints for IPv6 transition in enterprise networks
Author
Taib, Abidah Mat ; Budiarto, Rahmat
Author_Institution
Faculty of Computer and Mathematical Sciences, Universiti Teknologi MARA Perlis, Arau, Malaysia
fYear
2010
fDate
5-7 Dec. 2010
Firstpage
1114
Lastpage
1119
Abstract
Tunneling IPv6-in-IPv4 has become common at the early stage of IPv6 deployment. Unfortunately, tunneling introduces security threats in which intruders may spoof the address of the packet origin, and potentially inject the packet at the tunnel endpoint. Additionally, during the coexistence of both IPv4 and IPv6 in the network, one of the protocols may escape from firewall by being encapsulated in the other protocol. Mitigating the issue is possible by utilizing IPsec to authenticate the incoming packet. Nevertheless, in order to thoroughly secure the tunnel endpoints, this paper puts forward the importance of having separate firewalls to filter IPv4 as well as IPv6 packet to ensure that none of the packets can escape the filtering process. Our preliminary result shows that applying separate firewalls at the tunnel endpoints does not really cause delay or give significant effect to the filtering time.
Keywords
Delay; Filtering; Fires; IP networks; Protocols; Security; Tunneling; IPsec; IPv6 transition; ingress filtering; secure tunnel endpoints;
fLanguage
English
Publisher
ieee
Conference_Titel
Science and Social Research (CSSR), 2010 International Conference on
Conference_Location
Kuala Lumpur, Malaysia
Print_ISBN
978-1-4244-8987-9
Type
conf
DOI
10.1109/CSSR.2010.5773699
Filename
5773699
Link To Document