Dissertation > Excellent graduate degree dissertation topics show
The Study and Design of NAT Traversal Based on IPSec VPN
Author: DaiBin
Tutor: YuJianQiao
School: Southwestern University
Course: Agricultural Mechanization Engineering
Keywords: VPN NAT IPSec IKE UDP Encapsulation
CLC: TP393.03
Type: Master's thesis
Year: 2006
Downloads: 213
Quote: 1
Read: Download Dissertation
Abstract
|
VPN (Visual Private Network) based on IPSec and NAT (Network Address Translation) are excellent technologies that are widely used in network. VPN can establish private network in public network that allows data transmit safely through the encrypted tunnel. The clients only need to connect to the local public network, the data can be transmitted in the public network safely. NAT is an IETF (Internet Engineering Task Force) standard, allowing a whole organization appear on Internet by one public IP address. It is capable of translating the interior private network address to the legal network IP address. NAT not only improves efficiency of IP address utilization, saves much money the corporations spend in registering IP, but also enhances the system’s security because of another characteristic of NAT, namely, its capability to let many computers share one IP address, which allows NAT gateway covers up both the interior private network and the public network. Recently, NAT is often used in firewall, gateway or Router.At present, because VPN and NAT are incompatible, the two excellent technologies cannot co-exist in network at the same time. The reason is that NAT destroys the tunnel established by VPN. That is, while establishing communication tunnel, VPN does encrypting and decrypting to the data package address and check sum, which is changed by NAT; If this problem is solved, mass medium and small sized enterprises could exchange data safely at a lower cost. Consequently, it has a prosperous future of application.Based on the theories of IPSec and NAT, the reasons why they are incompatible are presented. Several feasible ways to deal with the incompatibility are analyzed and compared. At last, combining the least-cost principle with the practical needs of today’s medium and small sized enterprises, the method of using UDP encapsulation with certain modification and expansion of IKE protocol is fixed to complete the NAT traversal. In this way, the appended data process can be reduced to the least, and the present NAT equipment needs no reconfiguration. It is a good way to solve the problem before IPv6 is put into practice. From the user’s perspective, this solution costs less and permits VPN and NAT work together.According to the data processing in NAT traversal, the general structure of NAT traversal is made. The structure clearly describes how to modify and expand the functions under the present protocol in order to accomplish NAT traversal. Two key
|
Related Dissertations
- Study on Dose Verification of IMRT with Film Dosimetry,R815
- Research and Implementation on Authentication Encryption Process of TD-SCDMA Femto HNB,TN929.533
- Design and Implementation of Port Triggering Function on NAT Gateway,TP393.08
- The Study and Application of Interconnection between Digital Homes,TP393.03
- Design and Implementation of the synchronization system based on the P2P transfer of VOD material,TP393.02
- The Research and Implementation of P2P Instant Messaging System Based on XMPP,TN915.02
- Yunnan Lancang River Hydropower control center communications networking solutions,TV736
- Programming and Application of MPLS VPN Technology in Tianjin Power Integrated Services Digital Networks,TM769
- Network Safety Research and Realization Based on IPSec and SSL VPN,TP393.08
- Research on Security Scheme for the Integration of SAN and NAS,TP393.08
- The Design, Implementation and Performance Verification of Integrated VPN System Based on IPv6 Campus Network,TP393.08
- Design and Implementation of IPSec NAT Traversal,TP393.04
- Design and Implementation of Peer-to-Peer Multimedia Communication Module for Teleconsultation,TP311.52
- The Design and Implementation of Customer Service System,TP311.52
- Study of Rallway Special Data Networks,TN915.852
- The Design and Implementation of a NAT Traversal Solution on Session Border Controller,TN916.2
- Design and Implementation of Digital Video Monitoring System Based on MPLS-VPN Network,TP277
- Research on Remote Access Control Platform Based on SSL VPN,TP393.08
- MPLS-VPN at Network Video Frequency Application Within System,TP393.1
- The Research and Design of the Network and Network Trust System of the Private Office Network of Construction Bank System of Jilin Province,TP393.08
- Internet research ERP system security based on ECC encryption algorithm,F270.7
CLC: > Industrial Technology > Automation technology,computer technology > Computing technology,computer technology > Computer applications > Computer network > General issues > Network interconnect technology
© 2012 www.DissertationTopic.Net Mobile
|