blog




  • Essay / IPSec and Network Security - 653

    IPSec is a framework that uses a set of IETF protocols to provide end-to-end IP security using strong encryption and public key pair cryptography and private. IPSec secures communication links that might encounter network security issues such as corruption, eavesdropping, misused data, etc. (Pezeshki et al 2007) when they are not secure. However, the use of IPSec also tends to have a negative effect on router utilization and overall network performance. One of the major problems with IPSec is performance and throughput degradation (Berger, 2006), which can be traced back to complex authentication and encapsulation techniques. Data protection tends to increase the bandwidth required; Security transformation reduces performance and delays data processing and transmission. Consider a scenario in which a packet must be transmitted from computer 1 to computer 2, each with customer-premises equipment (CPE). In an environment without IPSec VPN, the packet would go directly to CPE 2 from computer 1. This is not the case when IPSec VPN is deployed in this same environment. The packet would be moved from computer 1 to CPE 1 which performs various tasks on the packet before transmitting it to CPE 2. The packet is first encrypted which takes time resulting in delay in transmission of the pack. Filtering and encryption consume computing power. When there are more packets to transmit, the load on the processor and network increases. After encryption, the packet is encapsulated, thus causing additional delay. The packet is then sent to the service provider where another delay may occur due to fragmentation. This is when the new packet formed is larger than the maximum transmission unit (MTU) size of the links between the two CPEs. The new package would then...... middle of paper ......t_design.html [Accessed August 8, 2009].13) JAHA, A., BEN, SF and ASHINBAI, M., 2008. Proper Virtual network (VPN) solution. Proceedings of the Second International Conference on Next Generation Mobile Applications, Services and Technologies. September 16-19, 2008. Libya: Higher Institute of Industry, Misurata. pp. 309 - 304.14) JIANWU Wu., 2009. Implementation of a virtual private network based on the IPSec protocol. Proceedings of the International Conference on Future Computing and Communication. June 6-7, 2009. China: School of Politics, Law and Public Administration, Hubei University. pp 138-14115) JING-BO, X., MING-HUI. L. and LU-JUN, W., 2008. Research on MPLS VPN network application based on OPNET. Proceedings of the International Symposium on Information Science and Engineering. December 20-22, 2008. Télécommun. Eng. Inst., Eng. of the Air Force. University, Xian. pp 404-408 vol..(1)