IETF86-KARP. Key Management and Adjacency Management for KARP-based Routing Systems

Size: px
Start display at page:

Download "IETF86-KARP. Key Management and Adjacency Management for KARP-based Routing Systems"

Transcription

1 IETF86-KARP Key Management and Adjacency Management for KARP-based Routing Systems

2 Overall Structure in akam-rp Layer 1: GCKS <-> each router Step 1: mutual authentication between an individual router and the GCKS Step 2: push key management configuration information to each individual router Layer 2: router to neighbors Step 3: mutual authentication between a router and its neighbors, possibly using information supplied by the GCKS Step 4: push or negotiate keys, etc IETF 86-KARP 2

3 -- The local routers retain key management information across re-boots, to avoid any possible issues with (apparent) DoS attacks on the GCKS when recovering from a general power failure (We put forth this architecture in Vancouver, based on a new protocol derived from IKE/gdoi) IETF 86-KARP 3

4 Scope of keys akam-rp More than one possible scope for keys: Entire administrative area Routers on a network segment This router plus its immediate neighbor routers This router plus its neighbor routers on an interface This router and a single peer router karp-ops-model More than one possible scope for keys Required scope may be fixed by the protocol spec Any AKM must enforce this IETF 86-KARP 4

5 Relationship of akam-rp to other karp drafts RKMP RKMP works out the details of key management for steps 3 and 4, for the case where the key scope is single peer MaRK (MRKMP) MaRK works out the details for steps 3 and 4, for the case where the key scope is neighbor routers on an interface IETF 86-KARP 5

6 Configuration management karp-ops-model There are many other things that may need to be considered/configured/controlled: Key table consistency Key update rules Key derivation rules Naming of peer groups Fault handling Upgrade rules Routing security may be considered to be just one more set of configuration parameters IETF 86-KARP 6

7 Framework relevance The framework proposed in akam-rp may be right, but The amount of information required to manage and configure keys is actually quite large Defining a new protocol (i.e., an extension of IKE/ gdoi) to transfer the key management information may not have been the best idea, in the sense that it would be good to have something that is itself extensible IETF 86-KARP 7

8 Structural questions What are we trying to achieve here? Movement of key-management information that is specific to the needs of secured routing How can we achieve this information movement? Modify/extend IKEv2 messages (or some similar security protocol) Done by rkmp, mrkmp, and akam-rp drafts Create a new information exchange protocol and transport it using a known, secure existing protocol (Which is my understanding of how SIDR works: move various messages on top of mutually-authenticated TCP-AO connections) IETF 86-KARP 8

9 Observations The need to mutually authenticate would argue for using something like TCP-AO for all the configuration-exchange steps The need to do general configuration would argue for something like NETCONF as a vehicle IETF 86-KARP 9

10 Questions Is it worth exploring such a general framework, i.e., one that is beyond the key management proposals? Does anyone favor TCP-AO? NETCONF? Why? IETF 86-KARP 10

11 Thank You! Questions? IETF 86-KARP 11

KARP KMP-Using IKEv2 with TCP-AO

KARP KMP-Using IKEv2 with TCP-AO 83 rd IETF @ Paris KARP KMP-Using IKEv2 with TCP-AO draft-chunduri-karp-using-ikev2-with-tcp-ao-01 Uma Chunduri, Albert Tian Ericsson Inc. Joe Touch USC/ISI IETF 83, Paris, France March 26-30,2011 1 Using

More information

Expires: January 16, 2014 Painless Security D. Zhang Huawei July 15, 2013

Expires: January 16, 2014 Painless Security D. Zhang Huawei July 15, 2013 KARP Internet-Draft Intended status: Standards Track Expires: January 16, 2014 W. Atwood R. Bangalore Somanatha Concordia University/CSE S. Hartman Painless Security D. Zhang Huawei July 15, 2013 Authentication,

More information

Intended status: Informational Expires: March 7, 2019 Huawei Technologies N. Leymann Deutsche Telekom G. Swallow Independent September 3, 2018

Intended status: Informational Expires: March 7, 2019 Huawei Technologies N. Leymann Deutsche Telekom G. Swallow Independent September 3, 2018 MPLS Working Group Internet-Draft Intended status: Informational Expires: March 7, 2019 L. Andersson Bronze Dragon Consulting S. Bryant A. Malis Huawei Technologies N. Leymann Deutsche Telekom G. Swallow

More information

RID IETF Draft Update

RID IETF Draft Update RID IETF Draft Update Kathleen M. Moriarty INCH Working Group 29 March 2005 This work was sponsored by the Air Force under Air Force Contract Number F19628-00-C-0002. "Opinions, interpretations, conclusions,

More information

An Autonomic Control Plane draft-ietf-anima-autonomic-control-plane- 05 (ietf98:06 - ietf99:08)

An Autonomic Control Plane draft-ietf-anima-autonomic-control-plane- 05 (ietf98:06 - ietf99:08) An Autonomic Control Plane draft-ietf-anima-autonomic-control-plane- 05 (ietf98:06 - ietf99:08) 99 th IETF, July 2017 Michael Behringer (editor), Toerless Eckert (editor), Steinthor Bjarnasson 1 06-07:

More information

Fear and Loathing at the IETF (Ten Years with No Pay)

Fear and Loathing at the IETF (Ten Years with No Pay) Fear and Loathing at the IETF (Ten Years with No Pay) Note: NEVER joke about your presentation title with the Panel Chairperson!! My apologies to HST Sepucha_Date_01 IETF Security Standards Challenges

More information

Programmatic Interface to Routing

Programmatic Interface to Routing Programmatic Interface to Routing NANOG 61 Draft version, slides will be updated before presentation Applications and Networks Routing system players: the Application and the Network. Different interdependent

More information

Configuring LDP with CLI

Configuring LDP with CLI Label Distribution Protocol Configuring LDP with CLI This section provides information to configure LDP using the command line interface. Topics in this section include: LDP Configuration Overview on page

More information

Keying & Authentication for Routing Protocols (KARP) draft-lebovitz-kmart-roadmap-03

Keying & Authentication for Routing Protocols (KARP) draft-lebovitz-kmart-roadmap-03 Keying & Authentication for Routing Protocols (KARP) KARP BoF IETF76, Hiroshima, Tue, 09 Nov, 2009 Gregory M. Lebovitz, Juniper gregory.ietf@gmail.com Intellectual Property When starting a presentation

More information

Category: Standards Track March Extensible Provisioning Protocol (EPP) Transport Over TCP

Category: Standards Track March Extensible Provisioning Protocol (EPP) Transport Over TCP Network Working Group S. Hollenbeck Request for Comments: 3734 VeriSign, Inc. Category: Standards Track March 2004 Extensible Provisioning Protocol (EPP) Transport Over TCP Status of this Memo This document

More information

Virtual Tunnel Interface

Virtual Tunnel Interface This chapter describes how to configure a VTI tunnel. About s, on page 1 Guidelines for s, on page 1 Create a VTI Tunnel, on page 2 About s The ASA supports a logical interface called (VTI). As an alternative

More information

CSCE 715: Network Systems Security

CSCE 715: Network Systems Security CSCE 715: Network Systems Security Chin-Tser Huang huangct@cse.sc.edu University of South Carolina Security in Network Layer Implementing security in application layer provides flexibility in security

More information

Internet Engineering Task Force (IETF) Category: Informational. June 2014

Internet Engineering Task Force (IETF) Category: Informational. June 2014 Internet Engineering Task Force (IETF) Request for Comments: 7211 Category: Informational ISSN: 2070-1721 S. Hartman Painless Security D. Zhang Huawei Technologies Co. Ltd. June 2014 Operations Model for

More information

Requirements for Subscription to YANG Datastores draft-ietf-i2rs-pub-sub-requirements-01

Requirements for Subscription to YANG Datastores draft-ietf-i2rs-pub-sub-requirements-01 Requirements for Subscription to YANG s draft-ietf-i2rs-pub-sub-requirements-01 NETCONF WG - IETF 92 Eric Voit, Alex Clemm, Alberto Gonzalez Prieto evoit@cisco.com, alex@cisco.com, albertgo@cisco.com March

More information

Operation Manual BFD-GR H3C S3610&S5510 Series Ethernet Switches. Table of Contents

Operation Manual BFD-GR H3C S3610&S5510 Series Ethernet Switches. Table of Contents Table of Contents Table of Contents... 1-1 1.1 Introduction to BFD... 1-1 1.1.1 How BFD Works... 1-1 1.1.2 BFD Packet Format... 1-3 1.1.3 Protocols and Standards... 1-5 1.2 BFD Configuration Task List...

More information

Configuring Transports

Configuring Transports This module provides information about Nonstop Routing (NSR), Transmission Control Protocol (TCP), and User Datagram Protocol (UDP) transports on Cisco ASR 9000 Series Aggregation Services Routers. If

More information

Key Management in IP Multicast

Key Management in IP Multicast Key Management in IP Multicast Petri Jokela Helsinki University of Technology petri.jokela@nomadiclab.com ABSTRACT The IP networking was originally designed to operate in point topoint way. However, when

More information

MULTICAST SECURITY. Piotr Wojciechowski (CCIE #25543)

MULTICAST SECURITY. Piotr Wojciechowski (CCIE #25543) MULTICAST SECURITY Piotr Wojciechowski (CCIE #25543) ABOUT ME Senior Network Engineer MSO at VeriFone Inc. Previously Network Solutions Architect at one of top polish IT integrators CCIE #25543 (Routing

More information

Security in inter-domain routing

Security in inter-domain routing DD2491 p2 2011 Security in inter-domain routing Olof Hagsand KTH CSC 1 Literature Practical BGP pages Chapter 9 See reading instructions Beware of BGP Attacks (Nordström, Dovrolis) Examples of attacks

More information

ONVIF Uplink Specification

ONVIF Uplink Specification ONVIF 1 Uplink Spec Ver. 18.12 ONVIF Uplink Specification Version 18.12 December, 2018 ONVIF 2 Uplink Spec Ver. 18.12 2008-2018 by ONVIF: Open Network Video Interface Forum Inc.. All rights reserved. Recipients

More information

IP Mobility vs. Session Mobility

IP Mobility vs. Session Mobility IP Mobility vs. Session Mobility Securing wireless communication is a formidable task, something that many companies are rapidly learning the hard way. IP level solutions become extremely cumbersome when

More information

The Internet community has developed application-specific security mechanisms in a number of application areas, including electronic mail (S/MIME,

The Internet community has developed application-specific security mechanisms in a number of application areas, including electronic mail (S/MIME, 1 The Internet community has developed application-specific security mechanisms in a number of application areas, including electronic mail (S/MIME, PGP), client/server (Kerberos), Web access (Secure Sockets

More information

Charles Perkins Nokia Research Center 2 July Mobility Support in IPv6 <draft-ietf-mobileip-ipv6-14.txt> Status of This Memo

Charles Perkins Nokia Research Center 2 July Mobility Support in IPv6 <draft-ietf-mobileip-ipv6-14.txt> Status of This Memo IETF Mobile IP Working Group INTERNET-DRAFT David B. Johnson Rice University Charles Perkins Nokia Research Center 2 July 2000 Mobility Support in IPv6 Status of This

More information

Cisco Exam Deploying Cisco Service Provider Network Routing (SPROUTE) Version: 7.0 [ Total Questions: 130 ]

Cisco Exam Deploying Cisco Service Provider Network Routing (SPROUTE) Version: 7.0 [ Total Questions: 130 ] s@lm@n Cisco Exam 642-883 Deploying Cisco Service Provider Network Routing (SPROUTE) Version: 7.0 [ Total Questions: 130 ] Question No : 1 When redistributing EIGRP routes into OSPF as type E2 external

More information

Internet Engineering Task Force Mark Baugher(Cisco) Expires: April, 2003 October, 2002

Internet Engineering Task Force Mark Baugher(Cisco) Expires: April, 2003 October, 2002 Internet Engineering Task Force Mark Baugher(Cisco) INTERNET-DRAFT Thomas Hardjono (Verisign) Category: Standards Track Hugh Harney (Sparta) Document: draft-ietf-msec-gdoi-06.txt Brian Weis (Cisco) Expires:

More information

Outline. CS5984 Mobile Computing. Dr. Ayman Abdel-Hamid, CS5984. Wireless Sensor Networks 1/2. Wireless Sensor Networks 2/2

Outline. CS5984 Mobile Computing. Dr. Ayman Abdel-Hamid, CS5984. Wireless Sensor Networks 1/2. Wireless Sensor Networks 2/2 CS5984 Mobile Computing Outline : a Survey Dr. Ayman Abdel-Hamid Computer Science Department Virginia Tech An Introduction to 1 2 1/2 Advances in micro-electro-mechanical systems technology, wireless communications,

More information

LAYER 3 FOR TSN LAYER 3 TSN DRAFT 3.1. Jouni Korhonen, Philippe Klein June 2014

LAYER 3 FOR TSN LAYER 3 TSN DRAFT 3.1. Jouni Korhonen, Philippe Klein June 2014 LAYER 3 FOR TSN LAYER 3 TSN DRAFT 3.1 Jouni Korhonen, Philippe Klein June 2014 1 REMEMBER THE HOMENET ARCHITECTURE? Media nw Common nw NAS TV etc e.g. TV feed ISP DHCPv6-PD -> CPE Public server HNET RTR

More information

PT Activity 5.6.1: Packet Tracer Skills Integration Challenge Topology Diagram

PT Activity 5.6.1: Packet Tracer Skills Integration Challenge Topology Diagram Topology Diagram All contents are Copyright 2008 Cisco Systems, Inc. All rights reserved. This document is Cisco Public Information. Page 1 of 6 Addressing Table Device Interface IP Address Subnet Mask

More information

RID IETF Draft Update

RID IETF Draft Update RID IETF Draft Update Kathleen M. Moriarty INCH Working Group 5 August 2004 This work was sponsored by the Air Force under Air Force Contract Number F19628-00-C-0002. "Opinions, interpretations, conclusions,

More information

Auxiliary Exchange in IKEv2 Protocol

Auxiliary Exchange in IKEv2 Protocol Auxiliary Exchange in IKEv2 Protocol draft-smyslov-ipsecme-ikev2-aux Valery Smyslov svan@elvis.ru IETF 101 Initial IKEv2 Exchanges Initiator Responder HDR(MID=0),SAi1,KEi,Ni HDR(MID=1),SK{IDi,AUTH,SAi2,TSi,TSr}

More information

IEEE Assisted Network Layer Mobility Support

IEEE Assisted Network Layer Mobility Support IEEE802.21 Assisted Network Layer Mobility Support Qazi Bouland Mussabbir *, Wenbing Yao ** and John Cosmas *** *School Of Engineering and Design, Brunel University Uxbridge, London, UB83PH, UK, qazi.mussabbir@brunel.ac.uk

More information

Configuring Passwords and Privileges

Configuring Passwords and Privileges Configuring Passwords and Privileges Using passwords and assigning privilege levels is a simple way of providing terminal access control in your network. This chapter describes the following topics and

More information

NFS Version 4 Security Update

NFS Version 4 Security Update NFS Version 4 Security Update Mike Eisler Sun Microsystems, Inc. mre@eng.sun.com 45th IETF Oslo July 11-16, 1999 NFS V4 Security 1 of 9 1999-07-08 Contents NFS V2/V3 security draft update Summary of issues

More information

Cryptography and Network Security. Sixth Edition by William Stallings

Cryptography and Network Security. Sixth Edition by William Stallings Cryptography and Network Security Sixth Edition by William Stallings Chapter 20 IP Security If a secret piece of news is divulged by a spy before the time is ripe, he must be put to death, together with

More information

Internet Engineering Task Force (IETF) Category: Informational. L. Zheng Huawei Technologies May 2013

Internet Engineering Task Force (IETF) Category: Informational. L. Zheng Huawei Technologies May 2013 Internet Engineering Task Force (IETF) Request for Comments: 6952 Category: Informational ISSN: 2070-1721 M. Jethanandani Ciena Corporation K. Patel Cisco Systems, Inc L. Zheng Huawei Technologies May

More information

Category: Experimental June 2006

Category: Experimental June 2006 Network Working Group K. Zeilenga Request for Comments: 4531 OpenLDAP Foundation Category: Experimental June 2006 Lightweight Directory Access Protocol (LDAP) Turn Operation Status of This Memo This memo

More information

Network Working Group Request for Comments: Nokia Research Center F. Dupont GET/ENST Bretagne June 2004

Network Working Group Request for Comments: Nokia Research Center F. Dupont GET/ENST Bretagne June 2004 Network Working Group Request for Comments: 3776 Category: Standards Track J. Arkko Ericsson V. Devarapalli Nokia Research Center F. Dupont GET/ENST Bretagne June 2004 Using IPsec to Protect Mobile IPv6

More information

Update on 5G Work & The IETF. Jari Arkko & Jeff Tantsura IAB Retreat, May 2017

Update on 5G Work & The IETF. Jari Arkko & Jeff Tantsura IAB Retreat, May 2017 Update on 5G Work & The IETF! Jari Arkko & Jeff Tantsura IAB Retreat, May 2017 Why discuss? Understand potential IETF work Major rush if anything new needed for 3GPP Release 15 as it is only 14 months

More information

IPv6 Changes in Mobile IPv6 from Connectathon

IPv6 Changes in Mobile IPv6 from Connectathon IPv6 Changes in Mobile IPv6 from Connectathon David B. Johnson The Monarch Project Carnegie Mellon University http://www.monarch.cs.cmu.edu/ dbj@cs.cmu.edu 47th IETF, Adelaide, Australia March 26 31, 2000

More information

The World Wide Web is widely used by businesses, government agencies, and many individuals. But the Internet and the Web are extremely vulnerable to

The World Wide Web is widely used by businesses, government agencies, and many individuals. But the Internet and the Web are extremely vulnerable to 1 The World Wide Web is widely used by businesses, government agencies, and many individuals. But the Internet and the Web are extremely vulnerable to compromises of various sorts, with a range of threats

More information

Request for Comments: 5573 Category: Experimental June Asynchronous Channels for the Blocks Extensible Exchange Protocol (BEEP)

Request for Comments: 5573 Category: Experimental June Asynchronous Channels for the Blocks Extensible Exchange Protocol (BEEP) Network Working Group M. Thomson Request for Comments: 5573 Andrew Category: Experimental June 2009 Asynchronous Channels for the Blocks Extensible Exchange Protocol (BEEP) Status of This Memo This memo

More information

Quick Note. Configure an IPSec VPN tunnel between a Digi TransPort LR router and a Digi Connect gateway. Digi Technical Support 20 September 2016

Quick Note. Configure an IPSec VPN tunnel between a Digi TransPort LR router and a Digi Connect gateway. Digi Technical Support 20 September 2016 Quick Note Configure an IPSec VPN between a Digi TransPort LR router and a Digi Connect gateway. Digi Technical Support 20 September 2016 Contents 1 Introduction... 3 1.1 Outline... 3 1.2 Assumptions...

More information

Virtual Private Networks

Virtual Private Networks EN-2000 Reference Manual Document 8 Virtual Private Networks O ne of the principal features of routers is their support of virtual private networks (VPNs). This document discusses transmission security,

More information

Other Developments: CIDR

Other Developments: CIDR Other Developments: CIDR CIDR (classless Inter domain routing) Too many small networks requiring multiple class C addresses Running out of class B addresses, not enough nets in class A Assign contiguous

More information

The IPsec protocols. Overview

The IPsec protocols. Overview The IPsec protocols -- components and services -- modes of operation -- Security Associations -- Authenticated Header (AH) -- Encapsulated Security Payload () (c) Levente Buttyán (buttyan@crysys.hu) Overview

More information

The Revolution Evolution of the IEEE 1588 Standard

The Revolution Evolution of the IEEE 1588 Standard Accurate time. Worldwide. The Revolution Evolution of the IEEE 1588 Standard Doug Arnold Meinberg USA Agenda Backward compatibility New Optional features Modular transparent clock Profile Isolation Interdomain

More information

Problem Statement and Considerations for ROA Mergence. 96 SIDR meeting

Problem Statement and Considerations for ROA Mergence. 96 SIDR meeting Problem Statement and Considerations for ROA Mergence draft-yan-sidr-roa-mergence-00 @IETF 96 SIDR meeting fuyu@cnnic.cn Background RFC 6482 1/19 ROA mergence What is the ROA mergence? is a common case

More information

Virtual Private Network

Virtual Private Network VPN and IPsec Virtual Private Network Creates a secure tunnel over a public network Client to firewall Router to router Firewall to firewall Uses the Internet as the public backbone to access a secure

More information

UMA and Dynamic Client Registration. Thomas Hardjono on behalf of the UMA Work Group

UMA and Dynamic Client Registration. Thomas Hardjono on behalf of the UMA Work Group UMA and Dynamic Client Registration Thomas Hardjono on behalf of the UMA Work Group 1 UMA is... A web protocol that lets you control authorization of data sharing and service access made on your behalf

More information

Security Baseline Data Model for Network Infrastructure Device draft-xia-sacm-nid-dp-security-baseline-00 draft-dong-sacm-nid-cp-security-baseline-00

Security Baseline Data Model for Network Infrastructure Device draft-xia-sacm-nid-dp-security-baseline-00 draft-dong-sacm-nid-cp-security-baseline-00 Security Baseline Data Model for Network Infrastructure Device draft-xia-sacm-nid-dp-security-baseline-00 draft-dong-sacm-nid-cp-security-baseline-00 Liang Xia Guangying Zheng Yue Dong Huawei Huawei Huawei

More information

Diameter Overload Control Application (DOCA) draft-korhonen-dime-ovl-00 Jouni Korhonen DIME WG IETF #85

Diameter Overload Control Application (DOCA) draft-korhonen-dime-ovl-00 Jouni Korhonen DIME WG IETF #85 Diameter Overload Control Application (DOCA) draft-korhonen-dime-ovl-00 Jouni Korhonen DIME WG IETF #85 What Diameter Overload Control Application is about? A simple/minimal (size wise) application for

More information

VPN World. MENOG 16 Istanbul-Turkey. By Ziad Zubidah Network Security Specialist

VPN World. MENOG 16 Istanbul-Turkey. By Ziad Zubidah Network Security Specialist VPN World MENOG 16 Istanbul-Turkey By Ziad Zubidah Network Security Specialist What is this Van used for?! Armed Van It used in secure transporting for valuable goods from one place to another. It is bullet

More information

MPLS LDP Graceful Restart

MPLS LDP Graceful Restart MPLS LDP Graceful Restart Last Updated: November 23, 2011 When a router is configured with Multiprotocol Label Switching (MPLS) Label Distribution Protocol (LDP) Graceful Restart (GR), it assists a neighboring

More information

Chapter 7 Forensic Duplication

Chapter 7 Forensic Duplication Chapter 7 Forensic Duplication Ed Crowley Spring 11 Topics Response Strategies Forensic Duplicates and Evidence Federal Rules of Evidence What is a Forensic Duplicate? Hard Drive Development Forensic Tool

More information

Implementing Network Configuration Protocol

Implementing Network Configuration Protocol This module provides details of the Network Configuration Protocol. For relevant commands, see Cisco ASR 9000 Series Aggregation Services Router System Security Command Reference. Release Modification

More information

Internet security and privacy

Internet security and privacy Internet security and privacy IPsec 1 Layer 3 App. TCP/UDP IP L2 L1 2 Operating system layers App. TCP/UDP IP L2 L1 User process Kernel process Interface specific Socket API Device driver 3 IPsec Create

More information

Department of Computer and IT Engineering University of Kurdistan. Computer Networks II Border Gateway protocol (BGP) By: Dr. Alireza Abdollahpouri

Department of Computer and IT Engineering University of Kurdistan. Computer Networks II Border Gateway protocol (BGP) By: Dr. Alireza Abdollahpouri Department of Computer and IT Engineering University of Kurdistan Computer Networks II Border Gateway protocol (BGP) By: Dr. Alireza Abdollahpouri Internet structure: network of networks local ISP Tier

More information

April 24, 1998 Expires in six months. SMTP Service Extension for Secure SMTP over TLS. Status of this memo

April 24, 1998 Expires in six months. SMTP Service Extension for Secure SMTP over TLS. Status of this memo HTTP/1.1 200 OK Date: Tue, 09 Apr 2002 00:24:41 GMT Server: Apache/1.3.20 (Unix) Last-Modified: Mon, 27 Apr 1998 14:31:00 GMT ETag: "2e9b64-31dd-354496a4" Accept-Ranges: bytes Content-Length: 12765 Connection:

More information

Protocols, Technologies and Standards Secure network protocols for the OSI stack P2.1 WLAN Security WPA, WPA2, IEEE i, IEEE 802.1X P2.

Protocols, Technologies and Standards Secure network protocols for the OSI stack P2.1 WLAN Security WPA, WPA2, IEEE i, IEEE 802.1X P2. P2 Protocols, Technologies and Standards Secure network protocols for the OSI stack P2.1 WLAN Security WPA, WPA2, IEEE 802.11i, IEEE 802.1X P2.2 IP Security IPsec transport mode (host-to-host), ESP and

More information

Cisco Nonstop Forwarding

Cisco Nonstop Forwarding Cisco Nonstop Forwarding Feature History Release Modification 12.0(22)S This feature was introduced. 12.0(23)S Support was added for 1xGE and 3xGE line cards on the 12.0(24)S Support was added for the

More information

Routing. Info 341 Networking and Distributed Applications. Addresses, fragmentation, reassembly. end-to-end communication UDP, TCP

Routing. Info 341 Networking and Distributed Applications. Addresses, fragmentation, reassembly. end-to-end communication UDP, TCP outing Info 341 Networking and Distributed Applications Context Layer 3 Addresses, fragmentation, reassembly Layer 4 end-to-end communication UDP, TCP outing At layer 3 Often relies on layer 4 Application

More information

IPV6 SIMPLE SECURITY CAPABILITIES.

IPV6 SIMPLE SECURITY CAPABILITIES. IPV6 SIMPLE SECURITY CAPABILITIES. 50 issues from RFC 6092 edited by J. Woodyatt, Apple Presentation by Olle E. Johansson, Edvina AB. ABSTRACT The RFC which this presentation is based upon is focused on

More information

Hillstone IPSec VPN Solution

Hillstone IPSec VPN Solution 1. Introduction With the explosion of Internet, more and more companies move their network infrastructure from private lease line to internet. Internet provides a significant cost advantage over private

More information

IPv6 Flow Label Specification

IPv6 Flow Label Specification IPv6 Flow Label Specification draft-ietf-ipv6-flow-label-02.txt Jarno Rajahalme Alex Conta Brian E. Carpenter Steve Deering IETF #54, Yokohama 1 7/18/2002 IPv6 Flow Label Specification Changes since -

More information

MLS BOF. Chair Slides: Nick & Sean IETF 101. Messaging Layer Security

MLS BOF. Chair Slides: Nick & Sean IETF 101. Messaging Layer Security MLS BOF Messaging Layer Security Chair Slides: Nick & Sean IETF 101 1 NOTE WELL This is a reminder of IETF policies in effect on various topics such as patents or code of conduct. It is only meant to point

More information

Configuration of Shrew VPN Client on RV042, RV042G and RV082 VPN Routers through Windows

Configuration of Shrew VPN Client on RV042, RV042G and RV082 VPN Routers through Windows Configuration of Shrew VPN Client on RV042, RV042G and RV082 VPN Routers through Windows Objective A Virtual Private Network (VPN) is a method for remote users to virtually connect to a private network

More information

October 4, 2000 Expires in six months. SMTP Service Extension for Secure SMTP over TLS. Status of this Memo

October 4, 2000 Expires in six months. SMTP Service Extension for Secure SMTP over TLS. Status of this Memo Internet Draft draft-hoffman-rfc2487bis-04.txt October 4, 2000 Expires in six months Paul Hoffman Internet Mail Consortium Status of this Memo SMTP Service Extension for Secure SMTP over TLS This document

More information

Scribe Notes -- October 31st, 2017

Scribe Notes -- October 31st, 2017 Scribe Notes -- October 31st, 2017 TCP/IP Protocol Suite Most popular protocol but was designed with fault tolerance in mind, not security. Consequences of this: People realized that errors in transmission

More information

Performance Study of COPS over TLS and IPsec Secure Session

Performance Study of COPS over TLS and IPsec Secure Session Performance Study of COPS over TLS and IPsec Secure Session Yijun Zeng and Omar Cherkaoui Université du Québec à Montréal CP. 8888 Suc. A, Montréal yj_zeng@hotmail.com, cherkaoui.omar@uqam.ca Abstract.

More information

The WAVE Communications Stack: IEEE p, and, September, 2007

The WAVE Communications Stack: IEEE p, and, September, 2007 The WAVE Communications Stack: IEEE 802.11p, 1609.4 and, 1609.3 September, 2007 WAVE System Components External Systems ROAD SIDE UNIT Covered by WAVE Standards ON-BOARD UNITS External Systems Host Host

More information

MPLS Label Distribution Protocol (LDP)

MPLS Label Distribution Protocol (LDP) MPLS Label Distribution Protocol (LDP) First Published: January 1, 1999 Last Updated: May 1, 2008 Multiprotocol Label Switching (MPLS) Label Distribution Protocol (LDP) enables peer label switch routers

More information

Fortinet NSE7 Exam. Volume: 30 Questions

Fortinet NSE7 Exam. Volume: 30 Questions Volume: 30 Questions Question No : 1 An administrator has configured a dial-up IPsec VPN with one phase 2, extended authentication (XAuth) and IKE mode configuration. The administrator has also enabled

More information

IETF RFCs Supported by Cisco NX-OS Unicast Features Release 6.x

IETF RFCs Supported by Cisco NX-OS Unicast Features Release 6.x IETF Supported by Cisco NX-OS Unicast Features Release 6.x BGP, page 1 First-Hop Redundancy Protocols, page 2 IP Services, page 3 IPv6, page 3 IS-IS, page 4 OSPF, page 5 RIP, page 5 BGP RFC 1997 BGP Communities

More information

This MOU sets the expectations for the activities and data that are appropriate on this network.

This MOU sets the expectations for the activities and data that are appropriate on this network. Research Network MOU Introduction Penn State s institutional data is a mission critical asset. Policies and protections on the network have been crafted to safeguard this data. As technology has evolved,

More information

Network Security: IPsec. Tuomas Aura

Network Security: IPsec. Tuomas Aura Network Security: IPsec Tuomas Aura 3 IPsec architecture and protocols Internet protocol security (IPsec) Network-layer security protocol Protects IP packets between two hosts or gateways Transparent to

More information

Configuring a Hub & Spoke VPN in AOS

Configuring a Hub & Spoke VPN in AOS June 2008 Quick Configuration Guide Configuring a Hub & Spoke VPN in AOS Configuring a Hub & Spoke VPN in AOS Introduction The traditional VPN connection is used to connect two private subnets using a

More information

Cisco Security Solutions for Systems Engineers (SSSE) Practice Test. Version

Cisco Security Solutions for Systems Engineers (SSSE) Practice Test. Version Cisco 642-566 642-566 Security Solutions for Systems Engineers (SSSE) Practice Test Version 3.10 QUESTION NO: 1 You are the network consultant from Your company. Please point out two requirements call

More information

Exam : Composite Exam. Title : Version : Demo

Exam : Composite Exam. Title : Version : Demo Exam : 642-892 Title : Composite Exam Version : Demo 1. If no metric is specified for the routes being redistributed into IS-IS, what metric value is assigned to the routes? A. 0 B. 1 C. 10 D. 20 Answer:A

More information

SIP INFO Event Framework (draft-kaplan-sip-info-events-00)

SIP INFO Event Framework (draft-kaplan-sip-info-events-00) SIP INFO Event Framework (draft-kaplan-sip-info-events-00) Hadriel Kaplan Christer Holmberg 70th IETF, Vancouver, Canada BACKGROUND The discussion on when to use INFO, how to use INFO, and whether to use

More information

How to Configure an IKEv1 IPsec VPN to an AWS VPN Gateway with BGP

How to Configure an IKEv1 IPsec VPN to an AWS VPN Gateway with BGP How to Configure an IKEv1 IPsec VPN to an AWS VPN Gateway with BGP If you are using the Amazon Virtual Private Cloud, you can transparently extend your local network to the cloud by connecting both networks

More information

Internet-Draft Intended status: Standards Track July 4, 2014 Expires: January 5, 2015

Internet-Draft Intended status: Standards Track July 4, 2014 Expires: January 5, 2015 Network Working Group M. Lepinski, Ed. Internet-Draft BBN Intended status: Standards Track July 4, 2014 Expires: January 5, 2015 Abstract BGPSEC Protocol Specification draft-ietf-sidr-bgpsec-protocol-09

More information

Techological Advantages of Mobile IPv6

Techological Advantages of Mobile IPv6 Techological Advantages of Mobile IPv6 Nokia Research Center Mountain View, CA USA Charles E. Perkins http://people.nokia.net/charliep charliep@iprg.nokia.com 1 NOKIA NERD2000.PPT/ 11/20/00 / HFl Outline

More information

CPSC 467b: Cryptography and Computer Security

CPSC 467b: Cryptography and Computer Security CPSC 467b: Cryptography and Computer Security Michael J. Fischer Lecture 24 April 16, 2012 CPSC 467b, Lecture 24 1/33 Kerberos Secure Shell (SSH) Transport Layer Security (TLS) Digital Rights Management

More information

SonicOS Enhanced Release Notes

SonicOS Enhanced Release Notes SonicOS Contents Platform Compatibility... 1 Known Issues... 2 Resolved Known Issues... 3 Upgrading SonicOS Enhanced Image Procedures... 4 Related Technical Documentation...7 Platform Compatibility The

More information

MPLS LDP MD5 Global Configuration

MPLS LDP MD5 Global Configuration MPLS LDP MD5 Global Configuration First Published: February 28, 2006 Last Updated: February 19, 2007 The MPLS LDP MD5 Global Configuration feature provides enhancements to the Label Distribution Protocol

More information

CNT Computer and Network Security: BGP Security

CNT Computer and Network Security: BGP Security CNT 5410 - Computer and Network Security: BGP Security Professor Kevin Butler Fall 2015 Internet inter-as routing: BGP BGP (Border Gateway Protocol): the de facto standard BGP provides each AS a means

More information

An Autonomic Control Plane

An Autonomic Control Plane An Autonomic Control Plane draft-ietf-anima-autonomic-control-plane update for ietf99:08 ietf100:12 100 th IETF, November 2017, Singapore Michael Behringer (editor), Toerless Eckert (editor), Steinthor

More information

Cisco Group Encrypted Transport VPN Configuration Guide, Cisco IOS Release 15M&T

Cisco Group Encrypted Transport VPN Configuration Guide, Cisco IOS Release 15M&T Cisco Group Encrypted Transport VPN Configuration Guide, Cisco IOS Release 15M&T Americas Headquarters Cisco Systems, Inc. 170 West Tasman Drive San Jose, CA 95134-1706 USA http://www.cisco.com Tel: 408

More information

How to Configure BGP over IKEv2 IPsec Site-to- Site VPN to an Google Cloud VPN Gateway

How to Configure BGP over IKEv2 IPsec Site-to- Site VPN to an Google Cloud VPN Gateway How to Configure BGP over IKEv2 IPsec Site-to- Site VPN to an Google Cloud VPN Gateway To connect to the Google Cloud VPN gateway, create an IPsec IKEv2 site-to-site VPN tunnel on your F-Series Firewall

More information

Supported Standards. Class of Service Tagging for Ethernet frames. Multiple Spanning Tree Protocol. Rapid Spanning Tree Protocol

Supported Standards. Class of Service Tagging for Ethernet frames. Multiple Spanning Tree Protocol. Rapid Spanning Tree Protocol , page 1 This table lists the IEEE compliance standards. Table 1: IEEE Compliance s 802.1D MAC Bridges 802.1p Class of Service Tagging for Ethernet frames 802.1Q VLAN Tagging 802.1s Multiple Spanning Tree

More information

BGP NSF Awareness. Finding Feature Information

BGP NSF Awareness. Finding Feature Information Nonstop Forwarding (NSF) awareness allows a device to assist NSF-capable neighbors to continue forwarding packets during a Stateful Switchover (SSO) operation. The feature allows an NSF-aware device that

More information

Lecture 9a: Secure Sockets Layer (SSL) March, 2004

Lecture 9a: Secure Sockets Layer (SSL) March, 2004 Internet and Intranet Protocols and Applications Lecture 9a: Secure Sockets Layer (SSL) March, 2004 Arthur Goldberg Computer Science Department New York University artg@cs.nyu.edu Security Achieved by

More information

Managing Site-to-Site VPNs: The Basics

Managing Site-to-Site VPNs: The Basics CHAPTER 23 A virtual private network (VPN) consists of multiple remote peers transmitting private data securely to one another over an unsecured network, such as the Internet. Site-to-site VPNs use tunnels

More information

Border Gateway Protocol (BGP-4)

Border Gateway Protocol (BGP-4) Vanguard Applications Ware IP and LAN Feature Protocols Border Gateway Protocol (BGP-4) Notice 2008 Vanguard Networks 25 Forbes Blvd Foxboro, MA 02035 Phone: (508) 964 6200 Fax: (508) 543 0237 All rights

More information

Workshop on Windows Server 2012

Workshop on Windows Server 2012 Workshop on Windows Server 2012 Topics covered on Workshop DHCP Scope Splitting. A Dynamic Host Configuration Protocol (DHCP) split-scope configuration using multiple DHCP servers allows for increased

More information

EMU BOF. EAP-TLS Experiment Report. RFC 2716 Bernard Aboba Microsoft Thursday, November 10, 2005 IETF 64, Vancouver, CA

EMU BOF. EAP-TLS Experiment Report. RFC 2716 Bernard Aboba Microsoft Thursday, November 10, 2005 IETF 64, Vancouver, CA EMU BOF EAP-TLS Experiment Report RFC 2716 Bernard Aboba Microsoft Thursday, November 10, 2005 IETF 64, Vancouver, CA History of RFC 2716 Goal: support for certificate-based mutual authentication within

More information

CTI-TC Working Session

CTI-TC Working Session CTI-TC Working Session Meeting Date: March 13, 2018 Time: 3:00 p.m. EDT Purpose: Weekly CTI-TC Weekly Working Call Attendees: Sarah Kelley Wunder Davidson Moderator ard Struse Piazza Thomson Drew Varner

More information

Network Encryption 3 4/20/17

Network Encryption 3 4/20/17 The Network Layer Network Encryption 3 CSC362, Information Security most of the security mechanisms we have surveyed were developed for application- specific needs electronic mail: PGP, S/MIME client/server

More information

Network Working Group. Category: Standards Track December 2005

Network Working Group. Category: Standards Track December 2005 Network Working Group J. Walker Request for Comments: 4261 A. Kulkarni, Ed. Updates: 2748 Intel Corp. Category: Standards Track December 2005 Status of This Memo Common Open Policy Service (COPS) Over

More information

An Operational Perspective on BGP Security. Geoff Huston February 2005

An Operational Perspective on BGP Security. Geoff Huston February 2005 An Operational Perspective on BGP Security Geoff Huston February 2005 Disclaimer This is not a description of the approach taken by any particular service provider in securing their network. It is intended

More information