Changes in setup/configuration for VPN and IPSec??

Changes in setup/configuration for VPN and IPSec??

Secure Home | Search | About
 General Computer Security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
Changes in setup/configuration for VPN and IPSec?? qazmlp1209 04-26-2007
Posted by on April 26, 2007, 4:58 am
If you were  Registered and logged in, you could reply and use other advanced thread options
VPN network:
- The additional VPN related setup/configuration is required only at
the entry/exit point of the network i.e. routers. No changes are
necessary on other machines/systems in that network.

IPSec network:
- Each machine/system in the network will need to have the
additional
IPSec related setup/configuration.


Is that correct? Which one is preferred over the other, and in what
scenarios?


Posted by Walter Roberson on April 26, 2007, 10:51 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
>VPN network:
> - The additional VPN related setup/configuration is required only at
>the entry/exit point of the network i.e. routers. No changes are
>necessary on other machines/systems in that network.

>IPSec network:
> - Each machine/system in the network will need to have the
>additional
>IPSec related setup/configuration.

>Is that correct?

No. IPSec has two modes, point to point and network to network.
The (quite common) network to network mode is the same
as what you describe under "VPN Network".

"VPN" is a generic word to describe Virtual Private Networks
no matter how implemented. IPSec is one possible implementation.
Others include PPTP, GRE, and MLPS (amongst others.)

>Which one is preferred over the other, and in what
>scenarios?

Point to Point: the user can only reach the security endpoint
(e.g., a single server) unless that server allows the user's
traffic to be forwarded on. Good, for example, for allowing
vendors to check your currently open Request For Proposals
without allowing them to get at anything else.

Network to Network: it isn't uncommon for telecommuters to
require access to several internal machines

Similar ThreadsPosted
Can IPSec connect 2 VPN Clients or is ALWAYS an IPSec server needed ? July 25, 2005, 7:40 pm
IPsec on IPv6 (ipsec-tools on Linux) - does it work? July 27, 2007, 12:35 pm
IPSEC ESP questions May 10, 2005, 10:55 am
VxWorks & IPSec March 22, 2007, 8:26 am
IPSEC Question April 26, 2007, 6:42 pm
IPSec Question April 26, 2007, 6:45 pm
IS DoS security solution is IPSEC? May 1, 2005, 7:31 am
HPSBUX02076 SSRT5979 - HP-UX Running IPSec Remote Denial of Service (DoS) November 16, 2005, 7:24 pm
HPSBUX02082 SSRT051037 HP-UX Running IPSec Remote Unauthorized Access December 7, 2005, 2:50 pm
HPSBUX02079 SSRT5957 - HP-UX IPSec Encapsulating Security Payload (ESP) Tunnel Mode Remote Unauthorized Disclosure of Encrypted Data December 7, 2005, 2:48 pm

The site map in XML format XML site map

Contact Us | Privacy Policy