...
首页> 外文期刊>IEEE Network >Policy-based IPsec management
【24h】

Policy-based IPsec management

机译:基于策略的IPsec管理

获取原文
获取原文并翻译 | 示例

摘要

Security is vital to the success of e-commerce and many new valued-added IP services. As a consequence, IPsec is an especially important security mechanism in that it provides cryptographic-based protection mechanisms for IP packets. Moreover, in order for IPsec to work properly, security policies that describe how different IP packets are protected must be provisioned on all network elements that offer IPsec protection. Since IPsec policies are quite complex, manually configuring them on individual network elements is inefficient and therefore infeasible for large-scale IPsec deployment. Policy-based IPsec management strives to solve this problem: Policy-based management employs a policy server to manage a network as a whole; it translates business goals or policies into network resource configurations and automates these configurations across multiple different network elements. Policy-based IPsec management significantly simplifies the task of defining, deploying, and maintaining security policies across a network, thereby significantly simplifying large-scale IPsec deployment. This article describes the motivations, key concepts, and recent IETF developments for policy-based IPsec management. It then applies the key concepts to an example a IPsec VPN service provisioning and further describes an example of an IPsec policy server as well as experience gained from implementing such a server. Challenges facing policy-based IPsec management are also discussed.
机译:安全性对于电子商务和许多新的增值IP服务的成功至关重要。结果,IPsec是一个特别重要的安全机制,因为它为IP数据包提供了基于密码的保护机制。此外,为了使IPsec正常工作,必须在提供IPsec保护的所有网络元素上提供描述如何保护不同IP数据包的安全策略。由于IPsec策略非常复杂,因此在单个网络元素上手动配置它们效率低下,因此对于大规模IPsec部署是不可行的。基于策略的IPsec管理致力于解决此问题:基于策略的管理使用策略服务器来管理整个网络;它将业务目标或策略转换为网络资源配置,并跨多个不同的网络元素自动执行这些配置。基于策略的IPsec管理显着简化了跨网络定义,部署和维护安全策略的任务,从而大大简化了大规模IPsec部署。本文介绍了基于策略的IPsec管理的动机,关键概念和IETF的最新发展。然后,它将关键概念应用于IPsec VPN服务供应的示例,并进一步描述IPsec策略服务器的示例以及从实现此类服务器获得的经验。还讨论了基于策略的IPsec管理面临的挑战。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号