home
NEWS       BLOGS       FORUMS       NEWSLETTERS       RESEARCH       EVENTS       DIGITAL LIBRARY       CAREERS  
Network Computing Network Computing Powered by InformationWeek Business Technology Network

IMMERSE YOURSELF:

SOA

  |

Data Center

  |

802.11n

  |

Data Privacy

  |
APO  |

Virtualization

  |

NAC

  |

Security

  |

Network Mgmt

  |

Enterprise Apps

  |

Storage & Servers






Making IPSec Work for You

By Mike Fratto
our customizable newsletter, sends you security alerts, product updates and software patches on the products you use. Sign up now at www.networkcomputing.com /express/
 After years of discussions, bake-offs, and numerous drafts, all the hard work of dedicated developers has paid off: Interoperable IPSec (IP Security) products are a reality. No longer are you locked into a single-vendor solution. The promise of low-cost extranets across the Internet is here. As of this writing, the ICSA has certified seven IPSec-compatible products based on the current RFC using preshared secrets. (For a complete listing, go to www.ncsa.com/services/product_cert/ipsec.) But what does that really mean in terms of implementing an IPSec-based solution?

In one of our Real-World Labs® at Syracuse University, we set up IPSec tunnels based on preshared secrets, with Check Point Software Technologies' FireWall-1 4.0, Shiva Corp.'s LanRover VPN Gateway, TimeStep Corp.'s Permit 4520 and VPNet Technologies' VSU-1010 V2.0b25. While we were able to get all these products to communicate, doing so was neither simple nor robust. Numerous issues popped up along the way, including basic tunnel construction when tunneling across subnets. We also ran into configuration issues, largely specific to implementation, in determining particular control parameters of the IPSec protocol. While irrelevant in a single-vendor implementation, these issues matter in a multivendor setup, where tunnel establishment goes from asymmetric to utter failure.

Bear in mind there are proprietary features that you may give up in a multivendor environment. VPNet's VSU1010, for one, supports Stac compression, but only within VPNet's environment. And while unified management seems to be an issue, one goal of a VPN (virtual private network) is to connect separate organizations securely for extranet access across the Internet, so you would only manage one side of the VPN anyway.

You should also remember that IPSec is an evolving standard. Though interoperation is possible, it's not exactly an elegant configuration. In the coming months, the ICSA will begin certifying IPSec version 1.1, which adds support for advanced features such as certificate authorities and IPSec tunnels for variable subnets. It is possible to obtain non-ICSA-certified products to interoperate, though the vendors won't guarantee stable results. In our testing, Shiva's LanRover VPN Gateway (not ICSA-certified at the time of this writing) interoperated very well, though we did run into a few small anomalies.

In general, IPSec tunnels are configured on each IPSec gateway by defining the two endpoints (or subnets), the encryption and authentication algorithms used, and the preshared secret each IPSec gateway in the VPN is to use. This information must match exactly for the gateway to negotiate successfully. For single-host VPNs, the configuration is straightforward; it gets more complex for subnets.

Subnet-Specific Problems Tunneling subnets poses a particular problem because of the way IDs are handled during IPSec negotiation. All IP addresses for the protected networks must be formatted exactly or the Quick Mode negotiation fails because of an unknown ID (see "The Many Modes of IPSec With IKE," on page 112). When protecting a single host, such as 10.2.2.5, the configuration of the two gateways are fairly straightforward. During the IKE security association (SA) negotiation, the IPSec gateways pass their own IP addresses as IDs. But during Phase 2, the IP addresses of the device or devices being protected are used as the ID. For example, creating a VPN to pass traffic between 10.2.2.5 and 10.3.3.5 (see "VPN Network Map," at left), TimeStep's Permit was configured to secure traffic from 10.2.2.5. We configured Permit to send all traffic for 10.3.3.5 to the VSU1010. During Quick Mode, Permit sent 10.2.2.5 as the ID while VSU sent 10.3.3.5. To set up the entire subnet, both the subnet address and the subnet mask pairs on each VPN gateway must be precisely defined.


Related Links

IPSec For Communities Of Interest
April 1, 1998

IPSec-Compliant VPN Solutions: Virtualizing Your Network
August 1, 1998


Other Workshops

Developments in DNS: Investigating BIND 8
By Greg Shiply

Company Directory
to browse our data, starting with a particular company.

Network Computing Links
allows you to request additional product information from our advertisers.

Print This Page


e-mail E-mail this URL






Looking for a new job?

Function:

Keyword(s):

State:
SPONSOR
RECENT JOB POSTINGS
CAREER NEWS
The tumbling of IT jobs stopped in the second quarter, as the IT sector added about 44,000 jobs.

It's just a glimmer, but Oracle is starting to see a bit of light at the end of the recession tunnel.










2009 IT Salary Survey: Meager Raises, Solid Prospects
Though raises are notably smaller than a year ago, and job security’s shrinking, IT careers are looking safer than many others in this economic downturn. Get all the findings in InformationWeek's 2009 IT Salary Survey. Available FREE for a limited time.
 
ROLLING RIGHT ALONG
Follow key Network Computing Reviews from conception to completion. This Week: Holistic APM.



Network Computing Reports Emerging Enterprise Podcast Series: Secrets to Success








TechSearch


Microsite of the Week


Powerful Information at Your Fingertips



Techweb
Informationweek Business Technology Network
InformationweekInformationweek 500Informationweek 500 ConferenceInformationweek AnalyticsInformationweek Events
Informationweek MagazineGlobal CIOIWK Government ITbMightyByte and SwitchDark Reading
Digital LibraryIntelligent EnterpriseInternet EvolutionNetwork ComputingPlug Into The CloudDr. DobbsContentinople
space
TechWeb Events Network
InteropVoiceConWeb 2.0 ExpoWeb 2.0 SummitEnterprise 2.0Mobile Business ExpoNoJitter
Black HatGTECEnergy CampCloud ConnectGov 2.0 ExpoGov 2.0 Summit
space
Light Reading Communications Network
Light ReadingLight Reading AsiaUnstrungCable Digital NewsInternet EvolutionPyramid Research
Heavy ReadingLight Reading LiveLight Reading InsiderEthrnet ExpoTelco TVTower Technology Summit
space
Financial Technology Network
Advanced TradingBank Systems and TechnologyInsurance and TechnologyWall Street and TechnologyAccelerating WallstreetBST SummitBuyside Trading SummitIT Summit
space
Microsoft Technology Network
MSDNTechNetTotal IT ProTotal Dev ProNET Total Dev Pro CommunitySQL Total Dev Pro Community
space


App Infrastructure   |   Messaging & Collaboration   |   Network & Systems Mgmt   |   Network Infrastructure   |   Security  |   Storage & Servers   |   Wireless   |   Enterprise Apps
About Us  |  Contact Us  |  Site Map  |  Technology Marketing Solutions  |  Advertising Contacts  |   Briefing Centers
Copyright © 2009  United Business Media LLC  |  Privacy Statement  |  Terms of Service