RE: IPSEC over UDP or TCP

"shannong" <[email protected]>
Newsgroups gmane.comp.security.vpn
Message-ID <009601c39011$7fa48cc0$0101a8c0@ASTEROID>
 
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Note: NAT-T is a standard and specifies only UDP over port 4500. 
Some vendors provide a proprietary method (namely Cisco) for UDP
encapsulation over other defined ports and even with TCP.  Most
vendors' VPN clients do not allow the user to define the UDP port for
the connection as the standard says to use 4500.  However, some
vendors' VPN clients do allow the configuration of the TCP port. 
Additionally, some vendors' VPN terminators (read Cisco)can be
configured to listen on multiple TCP ports simultaneously.

Therefore, another functional advantage of using TCP encapsulation
instead of NAT-T (read UDP)is that the port for the IPSec connection
can be defined by the client provided the VPN terminating device has
been configured to listen on that TCP port.  I find this very useful
as I initiate VPN connections from varied and different networks as
part of my consulting work.  Many networks block all traffic except
for "normal" business needs.  Some networks allow only 80/443.  Some
networks allow 3389 for RDP, and others do not.  Therefore, I have a
lot more success with VPN tunnels by providing myself with 5 choices
of TCP ports.  I find that networks that are locked down and
providing HTTP access through proxies still frequently allow 443 out
without authentication or filtering due to the obvious added
complexity of handshaking the SSL connection on both sides to look at
the traffic and authenticate it.  Therefore, TCP/443 has shown to be
the most successful for me.  

I have also found that unrealiable connections like cable modems that
experience high packet loss cause my TCP-IPSec connections to provide
lower overall peformance due to the obvious problems of two entities
attempting reliable retransmission of lost data and invoking the TCP
slow-down algorithm.  This is a casual observance rather than
scientific measurement for which I have no corresponding data.



- -----Original Message-----
From: [email protected]
[mailto:[email protected]] On Behalf Of
Siddhartha Jain
Sent: Friday, October 10, 2003 12:54 PM
To: [email protected]
Subject: RE: [VPN] IPSEC over UDP or TCP


Thats interesting. I assumed a higher overhead for
obvious reasons. Can you point to any studies or white
papers proving that NAT-T doesn't affect performance??

Thanks,

Siddhartha



 --- Bill Yazji <[email protected]> wrote: > Quantify
your "con" - significant testing has shown
> this really isn't the
> case....
> 
> ~B
> 
> -----Original Message-----
> From: [email protected]
>
[mailto:[email protected]]On
> Behalf Of
> Siddhartha Jain
> Sent: Tuesday, October 07, 2003 11:45 AM
> To: [email protected]
> Subject: Re: [VPN] IPSEC over UDP or TCP
> 
> 
> Advantages: Beats ISP blocking of IPSec traffic and
> overcomes NAT difficulties.
> 
> Cons: Decreases throughput because you have higher
> overheads. Original packet inside IPSec inside
> TCP/UDP
> packet.
> 
> 
> 
>  --- "Shivdasani, Meenoo" <[email protected]>
> wrote:  
> > I'm interested in people's experiences with
> > > > implementing IPSEC over UDP
> > or TCP.
> >
> > Benefits?  Disadvantages?
> >
> > Thanks in advance,
> >
> > M
> > _______________________________________________
> > VPN mailing list
> > [email protected] http://lists.shmoo.com/mailman/listinfo/vpn
> 
>
______________________________________________________________________
__
> Want to chat instantly with your online friends?
> Get the FREE Yahoo!
> Messenger http://mail.messenger.yahoo.co.uk
> _______________________________________________
> VPN mailing list
> [email protected]
> http://lists.shmoo.com/mailman/listinfo/vpn
> 
> _______________________________________________
> VPN mailing list
> [email protected] http://lists.shmoo.com/mailman/listinfo/vpn

______________________________________________________________________
__
Want to chat instantly with your online friends?  Get the FREE Yahoo!
Messenger http://mail.messenger.yahoo.co.uk
_______________________________________________
VPN mailing list
[email protected]
http://lists.shmoo.com/mailman/listinfo/vpn


-----BEGIN PGP SIGNATURE-----
Version: PGP 8.0.2

iQA/AwUBP4gqRuzo5pjD9SKfEQJXCgCfVYLpdFLgfZaNn1crOiM6R+NzoOgAoJB1
2NZTZ9y5qodIVQnJfZPeUgPH
=chEs
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.