• DocumentCode
    3392584
  • Title

    Experience with prefix discovery servers and IPSec VPN gateways

  • Author

    Sax, William ; Jillson, Carleton ; Wollman, William ; Jegers, Harry

  • Author_Institution
    MITRE Corp., McLean, VA
  • fYear
    2005
  • fDate
    17-20 Oct. 2005
  • Firstpage
    725
  • Abstract
    The use of IPSec encryption via virtual private network (VPN) gateways is expected to increase within tactical networks. Robust tactical networks that leverage VPN gateways require the ability to map remote IPSec protected plain text (PT) networks to their VPN gateway´s cipher text (CT) network address. Security associations between VPN gateways must allow for refresh and change based upon network connectivity and performance over time. A VPN-based prefix discovery server (PDS) can be implemented to help enable these network mappings and allow performance monitoring and network connection change. The discovery of new VPN gateways can be enabled through a registration process. Optional information for registration can include a VPN gateway´s ability to support different types of traffic or gateway preference. Following registration, the VPN gateway can be configured to distribute learned prefixes into the directly attached enclave´s interior routing protocol and provide updates to remote PDS(s) as network changes occur. To help analyze the challenges associated with the deployment of tactical network architectures that leverage a PDS, we have developed an open-source based VPN gateway and PDS. The purpose of this paper is to provide an overview of our PDS design, capabilities, lessons learned and recommendations for future architectures
  • Keywords
    IP networks; cryptography; internetworking; military communication; network servers; routing protocols; telecommunication security; virtual private networks; IPSec encryption; VPN gateways; cipher text network; interior routing protocol; plain text networks; prefix discovery servers; tactical networks; virtual private network; Cryptography; Data security; IP networks; Information security; Monitoring; Network servers; Robustness; Routing; Telecommunication traffic; Virtual private networks;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Military Communications Conference, 2005. MILCOM 2005. IEEE
  • Conference_Location
    Atlantic City, NJ
  • Print_ISBN
    0-7803-9393-7
  • Type

    conf

  • DOI
    10.1109/MILCOM.2005.1605768
  • Filename
    1605768