节点文献
IPsec加密数据流与防火墙过滤模式兼容问题
The solution of IPsec encrypted data stream and firewall filter mode compatibility
【摘要】 对适用于IPv6网络的包过滤防火墙的分组过滤模式与IPsec加密数据流之间的兼容性问题进行了分析 .针对网关防火墙不能对抗大量已取得了目标主机部分信任的“伪信任”主机所发出的具有攻击性的加密数据包 ,为IPv6逐跳选项扩展报头定义了一种新的选项———端口通告 ,有效地使网关防火墙能够对加密数据流进行分组过滤 ,并分析了亟待解决的问题
【Abstract】 This paper analyzes compatibility of the group filtering mode of firewall and IPsec encrypted datastream in the IPv6 network. Because the gateway firewall can′t deal with aggressive encrypted packets sent by half trust hosts, this paper defines a new option for the IPv6 hop-by-hop option--port announce, which can make gateway effectively filter the encrypted packets. Then some problems to be solved are studied.
【关键词】 IPsec协议;
包过滤防火墙;
伪信任主机;
端口通告选项;
【Key words】 IPsec; packet filter firewall; fake trust host; port announce option;
【Key words】 IPsec; packet filter firewall; fake trust host; port announce option;
【基金】 国家技术创新资助项目 (No0 2cj 12 0 3 5 1)
- 【文献出处】 华中科技大学学报(自然科学版) ,Journal of Huazhong University of Science and Technology , 编辑部邮箱 ,2003年S1期
- 【分类号】TP393.08
- 【被引频次】12
- 【下载频次】102