Firewall traversal in mobile IPv6 networks
نویسنده
چکیده
Middleboxes such as firewalls are an important aspect for a majority of IP networks today. Current IP networks are predominantly based on IPv4 technology, and hence various firewalls as well as Network Address Translators (NATs) have been originally designed for these networks. Deployment of IPv6 networks is currently work in progress. Given the fact that Mobile IPv6 is a recent standard, most firewalls available for IPv6 networks still do not support Mobile IPv6. Unless firewalls are aware of Mobile IPv6 protocol details, they will either block communication traffic under Mobile IPv6, or carefully deal with the traffic. This is a major impediment to the successful deployment of Mobile IPv6. This thesis describes the problems and impacts of having middleboxes in Mobile IPv6 environments. Therefore, it firstly explains which types of middleboxes are given, what exactly a middlebox is and how such a middlebox works and secondly identifies the problems and explains the impacts of having firewalls in Mobile IPv6 environments. Afterwards, it studies several state-of-the-art middlebox traversal solutions, which can be regarded as potential solutions to deal with the Mobile IPv6 firewall traversal problems. It explains in detail how these solutions work, and evaluates them in terms of their applicability for Mobile IPv6 firewall traversal. As the main contribution, this thesis proposes two solutions in detail, able to overcome the Mobile IPv6 firewall traversal problem. The first one, the NSIS based Mobile IPv6 firewall traversal, bases on the Next Steps in Signaling (NSIS) framework and the NAT/Firewall NSIS Signaling Layer Protocol (NAT/FW NSLP). Afterwards, it presents the second proposed solution, the Mobile IPv6 Application Layer Gateway. It explains in detail how these approaches are able to handle the problems and impacts of having firewalls in Mobile IPv6 environments. Additionally, this thesis presents how the NSIS based Mobile IPv6 firewall traversal and the Mobile IPv6 Application Layer Gateway proof-of-concept implementations, developed as part of this thesis, have been implemented. Finally, it evaluates and analyses the developed proof-of-concept implementations and the two proposed approaches in general.
منابع مشابه
Enabling Mobile Ipv6 in Operational Environments
Although Mobile IPv6 allows maintaining transport layer connections alive when an IPv6 node roams to different access networks, certain enabling mechanisms are needed for it to work in large scale network scenarios, including, most notably, issues with Mobile IPv6 bootstrapping and firewall traversal. This paper tries to address these problems by extending the IETF PANA and NSIS protocols to fo...
متن کاملSecured Route Optimization and Micro-mobility with Enhanced Handover Scheme in Mobile IPv6 Networks
خسارات وارد شده به شبکه گاز شهری در یک زلزله میتواند زیانهای زیادی از جمله خسارت ناشی از آتشسوزی در شبکه زیر ساخت، و خسارت ناشی از قطع خدمات رسانی، تعمیر و تعویض اعضای شبکه، را در بر داشته باشد. در این مقاله یک مدل آتشسوزی پیشنهاد شده است. مدل پیشنهادی در یک مدل نیمه احتمالاتی مرسوم برای برآورد خسارتهای مختلف ناشی از آسیب دیدن شبکه گاز شهری، به کار برده شده است. هدف از این کار توسعه یک ابز...
متن کاملAn IPv4/IPv6 Traversal Scheme with Seamless Mobility Support over Heterogeneous Wireless Networks
This paper proposes a new IPv4/IPv6 traversal scheme based on a scalable network-based IP mobility management system, called Access Independent Mobile Service (AIMS), which can provide MNs with high-quality mobility services over various wireless access networks. The proposed AIMS with IPv4/IPv6 Dual Stack Support (AIMS-DS) scheme can support an MN moving continuously across the IPv4/IPv6 coexi...
متن کاملRFC 4487 MIPv
This memo provides information for the Internet community. It does not specify an Internet standard of any kind. Distribution of this memo is unlimited. Abstract This document captures the issues that may arise in the deployment of IPv6 networks when they support Mobile IPv6 and firewalls. The issues are not only applicable to firewalls protecting enterprise networks, but are also applicable in...
متن کاملRFC 4487 MIPv 6 and
This memo provides information for the Internet community. It does not specify an Internet standard of any kind. Distribution of this memo is unlimited. Abstract This document captures the issues that may arise in the deployment of IPv6 networks when they support Mobile IPv6 and firewalls. The issues are not only applicable to firewalls protecting enterprise networks, but are also applicable in...
متن کامل