DocumentCode
3392584
Title
Experience with prefix discovery servers and IPSec VPN gateways
Author
Sax, William ; Jillson, Carleton ; Wollman, William ; Jegers, Harry
Author_Institution
MITRE Corp., McLean, VA
fYear
2005
fDate
17-20 Oct. 2005
Firstpage
725
Abstract
The use of IPSec encryption via virtual private network (VPN) gateways is expected to increase within tactical networks. Robust tactical networks that leverage VPN gateways require the ability to map remote IPSec protected plain text (PT) networks to their VPN gateway´s cipher text (CT) network address. Security associations between VPN gateways must allow for refresh and change based upon network connectivity and performance over time. A VPN-based prefix discovery server (PDS) can be implemented to help enable these network mappings and allow performance monitoring and network connection change. The discovery of new VPN gateways can be enabled through a registration process. Optional information for registration can include a VPN gateway´s ability to support different types of traffic or gateway preference. Following registration, the VPN gateway can be configured to distribute learned prefixes into the directly attached enclave´s interior routing protocol and provide updates to remote PDS(s) as network changes occur. To help analyze the challenges associated with the deployment of tactical network architectures that leverage a PDS, we have developed an open-source based VPN gateway and PDS. The purpose of this paper is to provide an overview of our PDS design, capabilities, lessons learned and recommendations for future architectures
Keywords
IP networks; cryptography; internetworking; military communication; network servers; routing protocols; telecommunication security; virtual private networks; IPSec encryption; VPN gateways; cipher text network; interior routing protocol; plain text networks; prefix discovery servers; tactical networks; virtual private network; Cryptography; Data security; IP networks; Information security; Monitoring; Network servers; Robustness; Routing; Telecommunication traffic; Virtual private networks;
fLanguage
English
Publisher
ieee
Conference_Titel
Military Communications Conference, 2005. MILCOM 2005. IEEE
Conference_Location
Atlantic City, NJ
Print_ISBN
0-7803-9393-7
Type
conf
DOI
10.1109/MILCOM.2005.1605768
Filename
1605768
Link To Document