January 2008
Intermediate to advanced
624 pages
14h 16m
English
IPsec was designed to provide end-to-end security for two computers located in the same address domain. If two computers are located in different address domains, such as private IP addresses used on a home network and public IP addresses used on the Internet, then the addresses must be translated for communication to occur. The translation of addresses and TCP or UDP ports for network address translation to connect users to the Internet invalidates the security services of IPsec. Specifically, address and port translation causes the following problems for ESP-based IPsec traffic:
For ESP-protected packets, the TCP and UDP ports are encrypted and, therefore, cannot be translated.
ISAKMP messages calculate hashes and signatures ...