摘要
IP安全协议(IPSec)业已成为当前构筑基于IP技术的虚拟专用网(VPN)的主流技术,然而已广泛使用的网络地址转换(NAT)技术正成为阻碍基于IPSec的VPN发展的主要障碍。该文对IPSec和NAT/NAPT之间的不兼容问题进行了详尽分析,介绍TRealm-Specific IP(RSIP)和UDP封装法两种解决方案,并对二者进行了比较,最后给出UDP封装法更利于解决该问题的结论。
IPSec has become a main tunneling technology in creating virtual private networks (VPN). However, it is shown that widespread network address translation (NAT) devices are becoming major barriers to the deployment of IPSec-based VPNs. In this paper, the incompatibility between IPSee and NAT/NAPT is clarified in detail, then two plausible solutions, RSFP and UDP encapsulation are introduced. After comparing these two proposals, a conclusion is drawn that the latter proposal will be a feasible and promising candidate to resolve the problem between IPSec and NAT.
出处
《计算机工程》
CAS
CSCD
北大核心
2003年第19期92-94,共3页
Computer Engineering
基金
国家"863"计划资助项目(2001AA112120)