RE: IPSEC over UDP or TCP

Jean-Francois Dive <[email protected]>
Newsgroups gmane.comp.security.vpn
Message-ID <1066200618.1212.2.camel@gardafou>
What you define here is a generic tunnel encapsulation which exist in
multiple forms. As far as IPSec is concerned, it should not be affected
by such environment. NAT-T is designed to cope with nat, punt. If you
want to cross a restrictive network, ISP, firewall, then you should use
whatever_you_name_it tunnel technology to carry ipsec traffic.

On Sat, 2003-10-11 at 18:05, shannong wrote:
>  -----BEGIN PGP SIGNED MESSAGE-----
> Hash: SHA1
> 
> Note: NAT-T is a standard and specifies only UDP over port 4500. 
> Some vendors provide a proprietary method (namely Cisco) for UDP
> encapsulation over other defined ports and even with TCP.  Most
> vendors' VPN clients do not allow the user to define the UDP port for
> the connection as the standard says to use 4500.  However, some
> vendors' VPN clients do allow the configuration of the TCP port. 
> Additionally, some vendors' VPN terminators (read Cisco)can be
> configured to listen on multiple TCP ports simultaneously.
> 
> Therefore, another functional advantage of using TCP encapsulation
> instead of NAT-T (read UDP)is that the port for the IPSec connection
> can be defined by the client provided the VPN terminating device has
> been configured to listen on that TCP port.  I find this very useful
> as I initiate VPN connections from varied and different networks as
> part of my consulting work.  Many networks block all traffic except
> for "normal" business needs.  Some networks allow only 80/443.  Some
> networks allow 3389 for RDP, and others do not.  Therefore, I have a
> lot more success with VPN tunnels by providing myself with 5 choices
> of TCP ports.  I find that networks that are locked down and
> providing HTTP access through proxies still frequently allow 443 out
> without authentication or filtering due to the obvious added
> complexity of handshaking the SSL connection on both sides to look at
> the traffic and authenticate it.  Therefore, TCP/443 has shown to be
> the most successful for me.  
> 
> I have also found that unrealiable connections like cable modems that
> experience high packet loss cause my TCP-IPSec connections to provide
> lower overall peformance due to the obvious problems of two entities
> attempting reliable retransmission of lost data and invoking the TCP
> slow-down algorithm.  This is a casual observance rather than
> scientific measurement for which I have no corresponding data.
> 
> 
> 
> - -----Original Message-----
> From: [email protected]
> [mailto:[email protected]] On Behalf Of
> Siddhartha Jain
> Sent: Friday, October 10, 2003 12:54 PM
> To: [email protected]
> Subject: RE: [VPN] IPSEC over UDP or TCP
> 
> 
> Thats interesting. I assumed a higher overhead for
> obvious reasons. Can you point to any studies or white
> papers proving that NAT-T doesn't affect performance??
> 
> Thanks,
> 
> Siddhartha
> 
> 
> 
>  --- Bill Yazji <[email protected]> wrote: > Quantify
> your "con" - significant testing has shown
> > this really isn't the
> > case....
> > 
> > ~B
> > 
> > -----Original Message-----
> > From: [email protected]
> >
> [mailto:[email protected]]On
> > Behalf Of
> > Siddhartha Jain
> > Sent: Tuesday, October 07, 2003 11:45 AM
> > To: [email protected]
> > Subject: Re: [VPN] IPSEC over UDP or TCP
> > 
> > 
> > Advantages: Beats ISP blocking of IPSec traffic and
> > overcomes NAT difficulties.
> > 
> > Cons: Decreases throughput because you have higher
> > overheads. Original packet inside IPSec inside
> > TCP/UDP
> > packet.
> > 
> > 
> > 
> >  --- "Shivdasani, Meenoo" <[email protected]>
> > wrote:  
> > > I'm interested in people's experiences with
> > > > > implementing IPSEC over UDP
> > > or TCP.
> > >
> > > Benefits?  Disadvantages?
> > >
> > > Thanks in advance,
> > >
> > > M
> > > _______________________________________________
> > > VPN mailing list
> > > [email protected] http://lists.shmoo.com/mailman/listinfo/vpn
> > 
> >
> ______________________________________________________________________
> __
> > Want to chat instantly with your online friends?
> > Get the FREE Yahoo!
> > Messenger http://mail.messenger.yahoo.co.uk
> > _______________________________________________
> > VPN mailing list
> > [email protected]
> > http://lists.shmoo.com/mailman/listinfo/vpn
> > 
> > _______________________________________________
> > VPN mailing list
> > [email protected] http://lists.shmoo.com/mailman/listinfo/vpn
> 
> ______________________________________________________________________
> __
> Want to chat instantly with your online friends?  Get the FREE Yahoo!
> Messenger http://mail.messenger.yahoo.co.uk
> _______________________________________________
> VPN mailing list
> [email protected]
> http://lists.shmoo.com/mailman/listinfo/vpn
> 
> 
> -----BEGIN PGP SIGNATURE-----
> Version: PGP 8.0.2
> 
> iQA/AwUBP4gqRuzo5pjD9SKfEQJXCgCfVYLpdFLgfZaNn1crOiM6R+NzoOgAoJB1
> 2NZTZ9y5qodIVQnJfZPeUgPH
> =chEs
> -----END PGP SIGNATURE-----
> 
> 
> _______________________________________________
> VPN mailing list
> [email protected]
> http://lists.shmoo.com/mailman/listinfo/vpn
-- 

-> Jean-Francois Dive
--> [email protected]

I think that God in creating Man somewhat overestimated his ability.
-- Oscar Wilde
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.