A Simulation Study for Resolving Communication Failure in IPSec Tunnel Mode with Adaptive PMTU Discovery Mechanism

적응적 PMTU 발견 메커니즘을 통한 IPSec 터널 모드에서의 통신 불능 현상 해소에 관한 시뮬레이션 연구

  • 김은성 (KISTI 슈퍼컴퓨팅 센터) ;
  • 안성진 (성균관대학교 컴퓨터교육과) ;
  • 정진욱 (성균관대학교 정보통신공학부) ;
  • 이도훈 (ETRI 부설 국가보안기술연구소) ;
  • 윤재우 (ETRI 부설 국가보안기술연구소)
  • Published : 2002.03.01

Abstract

VPN which cuts down on expense and assures security and reliance, has increased its market shares quickly because the requirement of enterprise on security has increased. But Fragmentation may raise communication failure when VPN has been implemented using IPSec. In our paper, we have given careful consideration to various reasons Preventing us from communicating stable and have presented the existing solutions about them. Also we hate provided adaptive PMTU discovery mechanism to improve: the solutions. We have proven a prowess of this mechanism through simulation

Keywords

References

  1. IP Sec: The New Security Standard for the Internet, Intranets and Virtual Private Networks Dan Harkins;Naganand Doraswamy
  2. Network Security Chris Brenton
  3. Internet System Hand book Daniel Lynch;Marchall Rose
  4. Virtual Private Network Charlie Scott;Paul Wolfe;Mike Erwin
  5. Implementing Virtual Private Networks Steven Brown
  6. Fragmentation Considered Harmful C. Kent;J. Mogul
  7. Congestion Avoidance and Control Van Jacobson
  8. RFC 1191 Path MTU Discovery J. Mogul;S. Deering
  9. RFC 2401 Security Architecture for the Internet Protocol Stephen Kent;Randall Atkinson
  10. RFC 2402 IP Authentication Header Stephen Kent;Randall Atkinson
  11. RFC 2406 IP Encapsulating Security Payload (ESP) Stephen Kent;Randall Atkinson
  12. RFC 2407 The Internet IP Security Domain of Interpretation for ISAKMP Derrell Piper
  13. RFC 2408 Internet Security Association and Key Management Protocol (ISAKMP) Douglas Maughan;Mark Schneider(et.)
  14. RFC 2409 The Internet Key Exchange (IKE) D. Harkins;D.Carrel
  15. RFC 815 IP Datagram Reassembly Algorithms David D. Clark
  16. Proc. Sixth Usenix Security Symp. Problem Areas for the IP Security Protocols S. Bellovin
  17. RFC2003 IP Encapsulation within IP Perkins, C.
  18. Internet Draft Tunnel Establishment Protocol Calhoun, P.(et al.)