VPNs White Papers
IPsec/VPN Security Policy Engineering: Automatic Generation and Conflict Detection
Overview IPsec is a useful IP layer security protocol which can provide authentication and encryption for end-to-end traffic flow, but configuring IPsec VPN tunnels is notoriously complicated because it has so many options (key exchange, ciphers, authentication etc) to configure. Thus the ultimate solutions to the security requirements are often prone to errors, let alone that dynamic routing changes can also cause troubles when interacting with existing IPsec tunnels. One minor configuration mistake or one subtle change (e.g. in routing) can cause insecure message transmission or even packet looping. Therefore, in this dissertation, it first proposes a network framework, BANDS, to provide an infrastructure where each domain has a requirement server to correctly handle inter-domain security requirements and policies.
| Publisher | University of California | File Format | |
|---|---|---|---|
| Date Published | June 2006 | ||
| Format | White Papers | ||
| Topics | |||


