Firewall traversal in mobile IPv6 networks

نویسنده

  • Niklas Steinleitner
چکیده

Middleboxes such as firewalls are an important aspect for a majority of IP networks today. Current IP networks are predominantly based on IPv4 technology, and hence various firewalls as well as Network Address Translators (NATs) have been originally designed for these networks. Deployment of IPv6 networks is currently work in progress. Given the fact that Mobile IPv6 is a recent standard, most firewalls available for IPv6 networks still do not support Mobile IPv6. Unless firewalls are aware of Mobile IPv6 protocol details, they will either block communication traffic under Mobile IPv6, or carefully deal with the traffic. This is a major impediment to the successful deployment of Mobile IPv6. This thesis describes the problems and impacts of having middleboxes in Mobile IPv6 environments. Therefore, it firstly explains which types of middleboxes are given, what exactly a middlebox is and how such a middlebox works and secondly identifies the problems and explains the impacts of having firewalls in Mobile IPv6 environments. Afterwards, it studies several state-of-the-art middlebox traversal solutions, which can be regarded as potential solutions to deal with the Mobile IPv6 firewall traversal problems. It explains in detail how these solutions work, and evaluates them in terms of their applicability for Mobile IPv6 firewall traversal. As the main contribution, this thesis proposes two solutions in detail, able to overcome the Mobile IPv6 firewall traversal problem. The first one, the NSIS based Mobile IPv6 firewall traversal, bases on the Next Steps in Signaling (NSIS) framework and the NAT/Firewall NSIS Signaling Layer Protocol (NAT/FW NSLP). Afterwards, it presents the second proposed solution, the Mobile IPv6 Application Layer Gateway. It explains in detail how these approaches are able to handle the problems and impacts of having firewalls in Mobile IPv6 environments. Additionally, this thesis presents how the NSIS based Mobile IPv6 firewall traversal and the Mobile IPv6 Application Layer Gateway proof-of-concept implementations, developed as part of this thesis, have been implemented. Finally, it evaluates and analyses the developed proof-of-concept implementations and the two proposed approaches in general.

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

Enabling Mobile Ipv6 in Operational Environments

Although Mobile IPv6 allows maintaining transport layer connections alive when an IPv6 node roams to different access networks, certain enabling mechanisms are needed for it to work in large scale network scenarios, including, most notably, issues with Mobile IPv6 bootstrapping and firewall traversal. This paper tries to address these problems by extending the IETF PANA and NSIS protocols to fo...

متن کامل

Secured Route Optimization and Micro-mobility with Enhanced Handover Scheme in Mobile IPv6 Networks

خسارات وارد شده به شبکه گاز شهری در یک زلزله می­تواند زیان­های زیادی از جمله خسارت ناشی از آتش­سوزی در شبکه زیر ساخت، و خسارت ناشی از قطع خدمات رسانی، تعمیر و تعویض اعضای شبکه، را در بر داشته باشد. در این مقاله یک مدل آتش­سوزی پیشنهاد شده است. مدل پیشنهادی در یک مدل نیمه احتمالاتی مرسوم برای برآورد خسارت­های مختلف ناشی از آسیب دیدن شبکه گاز شهری، به کار برده شده است. هدف از این کار توسعه یک ابز...

متن کامل

An IPv4/IPv6 Traversal Scheme with Seamless Mobility Support over Heterogeneous Wireless Networks

This paper proposes a new IPv4/IPv6 traversal scheme based on a scalable network-based IP mobility management system, called Access Independent Mobile Service (AIMS), which can provide MNs with high-quality mobility services over various wireless access networks. The proposed AIMS with IPv4/IPv6 Dual Stack Support (AIMS-DS) scheme can support an MN moving continuously across the IPv4/IPv6 coexi...

متن کامل

RFC 4487 MIPv

This memo provides information for the Internet community. It does not specify an Internet standard of any kind. Distribution of this memo is unlimited. Abstract This document captures the issues that may arise in the deployment of IPv6 networks when they support Mobile IPv6 and firewalls. The issues are not only applicable to firewalls protecting enterprise networks, but are also applicable in...

متن کامل

RFC 4487 MIPv 6 and

This memo provides information for the Internet community. It does not specify an Internet standard of any kind. Distribution of this memo is unlimited. Abstract This document captures the issues that may arise in the deployment of IPv6 networks when they support Mobile IPv6 and firewalls. The issues are not only applicable to firewalls protecting enterprise networks, but are also applicable in...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

عنوان ژورنال:

دوره   شماره 

صفحات  -

تاریخ انتشار 2008