RE: IPSEC over UDP or TCP
Jean-Francois Dive <[email protected]>
| Newsgroups | gmane.comp.security.vpn |
|---|---|
| Message-ID | <1066200618.1212.2.camel@gardafou> |
What you define here is a generic tunnel encapsulation which exist in multiple forms. As far as IPSec is concerned, it should not be affected by such environment. NAT-T is designed to cope with nat, punt. If you want to cross a restrictive network, ISP, firewall, then you should use whatever_you_name_it tunnel technology to carry ipsec traffic. On Sat, 2003-10-11 at 18:05, shannong wrote: > -----BEGIN PGP SIGNED MESSAGE----- > Hash: SHA1 > > Note: NAT-T is a standard and specifies only UDP over port 4500. > Some vendors provide a proprietary method (namely Cisco) for UDP > encapsulation over other defined ports and even with TCP. Most > vendors' VPN clients do not allow the user to define the UDP port for > the connection as the standard says to use 4500. However, some > vendors' VPN clients do allow the configuration of the TCP port. > Additionally, some vendors' VPN terminators (read Cisco)can be > configured to listen on multiple TCP ports simultaneously. > > Therefore, another functional advantage of using TCP encapsulation > instead of NAT-T (read UDP)is that the port for the IPSec connection > can be defined by the client provided the VPN terminating device has > been configured to listen on that TCP port. I find this very useful > as I initiate VPN connections from varied and different networks as > part of my consulting work. Many networks block all traffic except > for "normal" business needs. Some networks allow only 80/443. Some > networks allow 3389 for RDP, and others do not. Therefore, I have a > lot more success with VPN tunnels by providing myself with 5 choices > of TCP ports. I find that networks that are locked down and > providing HTTP access through proxies still frequently allow 443 out > without authentication or filtering due to the obvious added > complexity of handshaking the SSL connection on both sides to look at > the traffic and authenticate it. Therefore, TCP/443 has shown to be > the most successful for me. > > I have also found that unrealiable connections like cable modems that > experience high packet loss cause my TCP-IPSec connections to provide > lower overall peformance due to the obvious problems of two entities > attempting reliable retransmission of lost data and invoking the TCP > slow-down algorithm. This is a casual observance rather than > scientific measurement for which I have no corresponding data. > > > > - -----Original Message----- > From: [email protected] > [mailto:[email protected]] On Behalf Of > Siddhartha Jain > Sent: Friday, October 10, 2003 12:54 PM > To: [email protected] > Subject: RE: [VPN] IPSEC over UDP or TCP > > > Thats interesting. I assumed a higher overhead for > obvious reasons. Can you point to any studies or white > papers proving that NAT-T doesn't affect performance?? > > Thanks, > > Siddhartha > > > > --- Bill Yazji <[email protected]> wrote: > Quantify > your "con" - significant testing has shown > > this really isn't the > > case.... > > > > ~B > > > > -----Original Message----- > > From: [email protected] > > > [mailto:[email protected]]On > > Behalf Of > > Siddhartha Jain > > Sent: Tuesday, October 07, 2003 11:45 AM > > To: [email protected] > > Subject: Re: [VPN] IPSEC over UDP or TCP > > > > > > Advantages: Beats ISP blocking of IPSec traffic and > > overcomes NAT difficulties. > > > > Cons: Decreases throughput because you have higher > > overheads. Original packet inside IPSec inside > > TCP/UDP > > packet. > > > > > > > > --- "Shivdasani, Meenoo" <[email protected]> > > wrote: > > > I'm interested in people's experiences with > > > > > implementing IPSEC over UDP > > > or TCP. > > > > > > Benefits? Disadvantages? > > > > > > Thanks in advance, > > > > > > M > > > _______________________________________________ > > > VPN mailing list > > > [email protected] http://lists.shmoo.com/mailman/listinfo/vpn > > > > > ______________________________________________________________________ > __ > > Want to chat instantly with your online friends? > > Get the FREE Yahoo! > > Messenger http://mail.messenger.yahoo.co.uk > > _______________________________________________ > > VPN mailing list > > [email protected] > > http://lists.shmoo.com/mailman/listinfo/vpn > > > > _______________________________________________ > > VPN mailing list > > [email protected] http://lists.shmoo.com/mailman/listinfo/vpn > > ______________________________________________________________________ > __ > Want to chat instantly with your online friends? Get the FREE Yahoo! > Messenger http://mail.messenger.yahoo.co.uk > _______________________________________________ > VPN mailing list > [email protected] > http://lists.shmoo.com/mailman/listinfo/vpn > > > -----BEGIN PGP SIGNATURE----- > Version: PGP 8.0.2 > > iQA/AwUBP4gqRuzo5pjD9SKfEQJXCgCfVYLpdFLgfZaNn1crOiM6R+NzoOgAoJB1 > 2NZTZ9y5qodIVQnJfZPeUgPH > =chEs > -----END PGP SIGNATURE----- > > > _______________________________________________ > VPN mailing list > [email protected] > http://lists.shmoo.com/mailman/listinfo/vpn -- -> Jean-Francois Dive --> [email protected] I think that God in creating Man somewhat overestimated his ability. -- Oscar Wilde