Browse > Article

Configuration of an IPSec VPN Testbed and Development of an Encryption Verification Tool  

김윤희 (동의대학교 정보통신공학과)
이계상 (동의대학교 정보통신공학과)
Abstract
IPsec refers to a standardized set of security protocols and algorithms which can provide the integrity, the authentication and the confidentiality services for IP packets in the Internet. Between two security gateways, IPsec provides the access control, the connectionless Integrity, data origin authentication, the anti-replay, and the confidentiality services, not only to the IP layer but also to the upper layers. In this paper, we describe a VPN (Virtual Private Network) testbed configuration using the FreeS/WAN and analyze the ISAKMP messages exchanged between the linux security gateway during the IKE SA setup. Also, we describe our development of an IPSEC encryption verification tool which can be used conveniently by VPN administrators.
Keywords
Internet Security; IPSec; VPN; Frees/WAN; Testbed;
Citations & Related Records
연도 인용수 순위
  • Reference
1 /
[ freeswan ] / Linux FreeS/WAN is an implementation of IPSEC & IKE for Linux
2 The Internet IP Security Domain of Interpretation for ISAKMP /
[ D.piper ] / RFC2407
3 /
[ W. Richard Stevens ] / TCP/IP Illustrated
4 The Internet Key Exchange /
[ D.Harkins(et al.) ] / RFC2409
5 Internet Key Exchange(IKEv2) /
[ C.Kaufman ] / draft-ietf-ipsec-ikev2-08.txt
6 /
[ W.R.Stevens ] / UNIX Network Programming
7 IP Authentication Header /
[ S.Kent(et al.) ] / RFC2402
8 Security architecture for the Internet Protocol /
[ S.Kent(et. al.) ] / RFC 2401
9 SKEME: A versatile secuure key exchange mechanism for internet /
[ H.Krawczyk ] / IEEE Symposium on Network and Distributed Systems Security
10 The Oakley Key Determination Protocol /
[ H.Orman(et al.) ] / RFC2412
11 Internet Security Association and Key Management Protocol /
[ D.Maughan(et al.) ] / RFC2408
12 /
[] / IP Security Protocol (ipsec)
13 IP Authentication Header /
[ S.Kent(et al.) ] / RFC2406
14 /
[ Network Research Group at the Lawrence Berkeley National Laboratory ] / LIBPCAP 04: Packet Capture Library