J4

• 计算机科学 • 上一篇    下一篇

IPSec的NAT兼容性改进

姚志林1, 刘淑芬1, 韩正服2   

  1. 1. 吉林大学计算机科学与技术学院, 长春 130012; 2. 吉林大学网络中心, 长春 130012, China
  • 收稿日期:2004-11-29 修回日期:1900-01-01 出版日期:2005-07-26
  • 通讯作者: 刘淑芬

Improvement of Compatibility of IPsec with NAT

YAO Zhi-lin1, LIU Shu-fen1, HAN Zheng-fu2   

  1. 1. College of Computer Science and Technology, Jilin University, Changchun 130012, China; 2. Centre of Network, Jilin University, Changchun 130012
  • Received:2004-11-29 Revised:1900-01-01 Online:2005-07-26
  • Contact: LIU Shu-fen

摘要: 通过分析Internet网络层安全协议(IPSec)工作机制提出 一种改进的隧道封装方法. 通过数据发送方在数据包中封装本主机的IP地址, 并在接收方对 其进行相应的处理, 在解决IPSec与网络地址翻译技术NAT兼容性问题的基础上, 使得通 信双方可以灵活决定对通信的保护方式. 与Internet工程任务组的解决方案相比, 在不损失 安全性及只增加很小开销的前提下, 保持了灵活设置安全策略的能力.

关键词: 网络安全技术, 网络层安全协议, 网络地址翻译, 用户数据报封装

Abstract: An improved tunnel encapsulation method was proposed ba sed on the analysis of the mechanism of Internet network layer security protocol IPSec. On the basis of encapsulating the original IP address of the host in the data packet and doing corresponding management of it at the opponent side and s olving the incompatibility problem between IPSec and NAT the two sides of t he communication can still configure their security policy flexibly. Compared wi th the solution method of Internet engineering task force, our method can keep t he flexibility of security policy configuration without the loss of security and with adding a little spending.

Key words: security of Network, IPSec, NAT, encapsulation of UDP

中图分类号: 

  • TP393