作者投稿和查稿 主编审稿 专家审稿 编委审稿 远程编辑

计算机工程 ›› 2008, Vol. 34 ›› Issue (22): 148-149. doi: 10.3969/j.issn.1000-3428.2008.22.051

• 网络与通信 • 上一篇    下一篇

增强的NAT-PT和IPSec兼容解决方案

张志龙,杜学绘,钱雁斌   

  1. (解放军信息工程大学电子技术学院,郑州 450004)
  • 收稿日期:1900-01-01 修回日期:1900-01-01 出版日期:2008-11-20 发布日期:2008-11-20

Enhanced Compatibility Solution Between NAT-PT and IPSec

ZHANG Zhi-long, DU Xue-hui, QIAN Yan-bin   

  1. (Institute of Electronic Technology, PLA Information Engineering University, Zhengzhou 450004)
  • Received:1900-01-01 Revised:1900-01-01 Online:2008-11-20 Published:2008-11-20

摘要: 分析IPv4/IPv6过渡时期NAT-PT和IPSec协议的兼容性解决方案,并基于此提出一种增强的IPSec分段保护方案,通过对IKE协议的适当改进增加了发起方对NAT-PT转换网关的发现和自动处理机制,提高了NAT-PT转换网关的透明性。性能分析显示该方案具有较好的安全性和适应性,便于过渡网络安全策略的实施。

关键词: 协议转换, 分段协商, 转换网关

Abstract: This paper analyzes the solution about the compatibility between IPSec and Network Address Translation-Protocol Translation(NAT-PT) in IPv4/IPv6 interim, and puts forward an enhanced IPSec application solution in segments. It increases the discovery and automatic mechanism through the improvement to IKE protocol, and improves the transparence of the NAT-PT translation gateway. The performance analysis shows that it is more secure and flexible, and is convenient for the implement of security strategy in transition network.

Key words: Protocol Translation(PT), negotiation in segments, translation gateway

中图分类号: