University of Freiburg Computer Science Computer Networks and Telematics
- Prof. Christian Schindelhauer
Communication Systems
IPSec
Communication Systems IPSec University of Freiburg Computer - - PowerPoint PPT Presentation
Communication Systems IPSec University of Freiburg Computer Science Computer Networks and Telematics Prof. Christian Schindelhauer Organization I. Data and voice communication in IP networks II. Security issues in networking
University of Freiburg Computer Science Computer Networks and Telematics
IPSec
Communication Systems
Computer Networks and Telematics University of Freiburg
2
Communication Systems
Computer Networks and Telematics University of Freiburg
classical web security and application Layer (PGP, S/ MIME) in last practical
layer: IPsec as a general means to secure all higher level protocols between IP networked hosts
3
Communication Systems
Computer Networks and Telematics University of Freiburg
was put - No alteration to the IP was needed, simply the transportation protocol was interchanged (or and additional security header introduced)
and encryption services
sender and have not been altered in transit
contents
4
Communication Systems
Computer Networks and Telematics University of Freiburg
whole IP traffic that might occur
through untrusted networks
encrypted by the IPSEC gateway machine and decrypted by the gateway at the other end
Network (VPN)
5
Communication Systems
Computer Networks and Telematics University of Freiburg
IP version 6 (next generation Internet protocol, see earlier lecture)
standard, but in real only a few products really operate
implementations of IPSEC for the 2.6 kernel series available
daemon for key exchange
implementation is used (operable with Cisco VPN concentrator (only))
part)
6
Communication Systems
Computer Networks and Telematics University of Freiburg
required to protect traffic of LANs
various application servers, and on end-user desktop or laptop machines
authentication service
plus authentication
parameters, including keys, for the other two
7
Communication Systems
Computer Networks and Telematics University of Freiburg
header
the expected sender and has not been altered on route
needed – that means to establish a security association (SA)
8
Communication Systems
Computer Networks and Telematics University of Freiburg
from the IPv6 standard, refer to earlier lecture)
9
Communication Systems
Computer Networks and Telematics University of Freiburg
bits)
ESP: 50, AH: 51 -> see /etc/protocols) -> depends on IPSEC mode
node and firewall
10
Communication Systems
Computer Networks and Telematics University of Freiburg
(But: MTU size change – payload available to higher level protocols - results in shorter packets ...)
11
Communication Systems
Computer Networks and Telematics University of Freiburg
provides encryption
with null encryption (which should be used for testing and analysis only)
12
Communication Systems
Computer Networks and Telematics University of Freiburg
13
Communication Systems
Computer Networks and Telematics University of Freiburg
protected data
14
Communication Systems
Computer Networks and Telematics University of Freiburg
header are encrypted
ESP, or just use ESP
15
Communication Systems
Computer Networks and Telematics University of Freiburg
encryption of predefined connections by now
encryption” - check if IP sec is available and use secure channel then
insecure Internet
16
Communication Systems
Computer Networks and Telematics University of Freiburg
easy adaptation of IP sec to end user devices
servers and clients side
certificates – shared secret (“community string/password”)
recompilation of module wrapper
network device, support for unsupported (by Cisco) platforms
17
Communication Systems
Computer Networks and Telematics University of Freiburg
problems
practical part to follow)
package filters the upcoming lecture)
and security (strongSWAN, developed at some Swiss University)
18
Communication Systems
Computer Networks and Telematics University of Freiburg
Security Payload (ESP)”
Engineering Task Force (IETF)
19
University of Freiburg Computer Science Computer Networks and Telematics