6winit at IPv6 Concertation Meeting 14/10/02 1 Peter T. Kirstein University College London Dynamic VPN Needs for UCL-CS.

Slides:



Advertisements
Similar presentations
6WINIT Project Meeting, BASEL K. Egede Nielsen/TED Research 1 WP6 Progress Report 6WINIT Project Meeting Basel
Advertisements

Introducing Campus Networks
1 © 2005 Cisco Systems, Inc. All rights reserved. CONFIDENTIAL AND PROPRIETARY INFORMATION Cisco Wireless Strategy Extending and Securing the Network Bill.
L. Alchaal & al. Page Offering a Multicast Delivery Service in a Programmable Secure IP VPN Environment Lina ALCHAAL Netcelo S.A., Echirolles INRIA.
© 2014 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 1 High-performance Gigabit Ethernet ports rapidly transfer large files supporting.
LMF/TTR Raimo Vuopionperä 6WINIT: Ericsson (Research) Objectives (6WINIT Kick-Off, London) Raimo Vuopionperä (Ph. D.), NomadicLab (LMF/TTR)
Integration of PAP site 17 th July 10. Requirements of PAP SITE  Bandwidth drop  Router  RJ45 cables  Switch  Gateway  Nodes  Ups  9urack.
TANDBERG Video Communication Server March TANDBERG Video Communication Server Background  SIP is the future protocol of video communication and.
Defence R&D Canada R et D pour la défense Canada Dynamic VPN Controller Developed by NRNS Inc. July 2, 2003.
Guide to Network Defense and Countermeasures Second Edition
UCL VPN Update. 6NET “To look at the issues surrounding the provision of IPv6 dynamic VPN technology and deploy an IPv6- Enabled VPN Infrastructure”
Agenda Virtual Private Networks (VPNs) Motivation and Basics Deployment Topologies IPSEC (IP Security) Authentication Header (AH) Encapsulating Security.
IPv6 over xDSL: The DIODOS Proposal Athanassios Liakopoulos Greek Research & Technology Network International IPv6 Workshop, Kopaonik,
© 2006 Cisco Systems, Inc. All rights reserved.Cisco Public 1 Version 4.0 Prototyping the WAN Designing and Supporting Computer Networks – Chapter 8.
© 2008 Cisco Systems, Inc. All rights reserved.Cisco ConfidentialPresentation_ID 1 Chapter 9: Troubleshooting the Network Connecting Networks.
An Example of IPv6 Necessity in the Greek School Network Athanassios Liakopoulos Greek Research & Technology Network.
SDN and Openflow.
The UMU-PBNM Antonio F. Gomez Skarmeta Gregorio Martínez
UCL Overview of VPN Work. 10/11 July 2003VPN Workshop2 Current Work Projects Projects  Past  ANDROID  RADIOACTIVE  Present  6NET  ICB VPN Technologies.
1 In VINI Veritas: Realistic and Controlled Network Experimentation Jennifer Rexford with Andy Bavier, Nick Feamster, Mark Huang, and Larry Peterson
1 Version 3.0 Module 8 Virtual LANs. 2 Version 3.0.
1 Presentation_ID © 1999, Cisco Systems, Inc. Programmable Networks OPENSIG-99 Industry Panel John Hopprich.
This work is supported by the National Science Foundation under Grant Number DUE Any opinions, findings and conclusions or recommendations expressed.
Hands-On Microsoft Windows Server 2003 Networking Chapter 1 Windows Server 2003 Networking Overview.
NEtwork MObility By: Kristin Belanger. Contents Introduction Introduction Mobile Devices Mobile Devices Objectives Objectives Security Security Solution.
© 2006 Cisco Systems, Inc. All rights reserved. MPLS v2.2—4-1 MPLS VPN Technology Categorizing VPNs.
1 © 2001, Cisco Systems, Inc. All rights reserved. Session Number Presentation_ID Cisco Easy VPN Solutions Applications and Implementation with Cisco IOS.
Network-based IP VPNs using Virtual Routers Tim Hubbard.
Network based IP VPN Architecture using Virtual Routers Jessica Yu CoSine Communications, Inc. Feb. 19 th, 2001.
Week #10 Objectives: Remote Access and Mobile Computing Configure Mobile Computer and Device Settings Configure Remote Desktop and Remote Assistance for.
Course 201 – Administration, Content Inspection and SSL VPN
Clinic Security and Policy Enforcement in Windows Server 2008.
Chapter 1: Hierarchical Network Design
Networks Research Group Deployment of an IPv6-Enabled Dynamic VPN Infrastructure.
IPv6 activities in Greece Dimitrios Kalogeras, Ph.d.
CPMT 1451 IT Essentials: PC Hardware and Software ITCC 1301 Cisco Exploration 1: Network Fundamentals ITCC 1304 Cisco Exploration 2: Routing Protocols.
© 2006 Cisco Systems, Inc. All rights reserved. Optimizing Converged Cisco Networks (ONT) Module 4: Implement the DiffServ QoS Model.
Apricot2005, Feb Security Framework for the IPv6 Era SUZUKI, Shinsuke (Hitachi, Ltd. / KAME Project / WIDE Project Secure-6 WG)
Connecting to a Network Lesson 5. Objectives Understand the OSI Reference Model and its relationship to Windows 7 networking Install and configure networking.
Chapter 8: Virtual LAN (VLAN)
Cisco 3 - LAN Perrine. J Page 110/20/2015 Chapter 8 VLAN VLAN: is a logical grouping grouped by: function department application VLAN configuration is.
Management for IP-based Applications Mike Fisher BTexaCT Research
© 2002, Cisco Systems, Inc. All rights reserved..
Campus Network Development Network Architecture, Universal Access & Security.
1 © 2003, Cisco Systems, Inc. All rights reserved. CCNA 3 v3.0 Module 9 Virtual Trunking Protocol.
Cisco S3C3 Virtual LANS. Why VLANs? You can define groupings of workstations even if separated by switches and on different LAN segments –They are one.
© 2006 Cisco Systems, Inc. All rights reserved.Cisco PublicITE I Chapter 6 1 VLANs LAN Switching and Wireless – Chapter 3.
Look, Ma, No Hardware -Stephanie Schossow. Cisco & VMware  September 16, Industry leaders in virtualization Cisco and VMware® announced that they.
© 2006 Cisco Systems, Inc. All rights reserved.Cisco Public 1 Version 4.0 VLANs LAN Switching and Wireless – Chapter 3.
Defence R&D Canada R et D pour la défense Canada Dynamic VPN Controller Update Developed by NRNS Inc. November 12, 2003.
+ Routing Concepts 1 st semester Objectives  Describe the primary functions and features of a router.  Explain how routers use information.
© 2012 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 1.
1 Version 3.0 Module 8 Virtual LANs. 2 Version 3.0.
Draft-li-idr-cc-bgp-arch-00IETF 88 IDR1 An Architecture of Central Controlled Border Gateway Protocol (BGP) draft-li-idr-cc-bgp-arch-00 Zhenbin Li, Mach.
OpenFlow: Enabling Innovation in Campus Networks Yongli Chen.
© Copyright 2012 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice. Embrace the Future of.
© 2002, Cisco Systems, Inc. All rights reserved..
IPv6 Security Issues Georgios Koutepas, NTUA IPv6 Technology and Advanced Services Oct.19, 2004.
1 CONFIDENTIAL Maintainable Apps Apps are for business not for developers JANUARY 1, 2015.
© 2003, Cisco Systems, Inc. All rights reserved. 2-1 Campus Network Design.
© 2006 Cisco Systems, Inc. All rights reserved.Cisco Public 1 VLANs.
Hardware & Software Requirement Present by: Tan Ming Fatt Student ID: TP
أمن المعلومات لـ أ. عبدالرحمن محجوب حمد mtc.edu.sd أمن المعلومات Information Security أمن المعلومات Information Security  أ. عبدالرحمن محجوب  Lec (5)
SECURITY ZONES.
Introducing To Networking
Introducing Novell IPv6 Stack
Server-to-Client Remote Access and DirectAccess
Chapter 10: Advanced Cisco Adaptive Security Appliance
Presentation transcript:

6winit at IPv6 Concertation Meeting 14/10/02 1 Peter T. Kirstein University College London Dynamic VPN Needs for UCL-CS

6winit at IPv6 Concertation Meeting 14/10/02 2 Project Background Developed VPN technology in RADIOACTIVE and in ANDROID Both had IPv6 as primary goals Both wanted to provide dynamic VPNs Now have RADIOACTIVE and 6NET RADIOACTIVE still same goal –Also must work towards ICB VPN 6NET wants a deployable VPN –Deployable with real technology and apps

6winit at IPv6 Concertation Meeting 14/10/02 3 RADIOACTIVE RADIOACTIVE based first on Xbone –Porting to IPv6 done by UCL –Included Active Server (TAG) for edge devices with traffic limiting Abandoned after DANCE because no support for realistic topology Still require same applications –Would like to use same technology as 6NET

6winit at IPv6 Concertation Meeting 14/10/02 4 Advances in X-Bone Recent changes in X-Bone important –Now have static routing according to a particular topology –IPv6 support is close PERL support now exists –IPv6 version really works only with FreeBSD FreeS/WAN IPsec does not work with IPv6 –Some network management exists Should revisit suitability of X-Bone

6winit at IPv6 Concertation Meeting 14/10/02 5 ANDROID ANDROID now finished –Used proprietary management system from Netcelo –System still available if wanted, requires specific 6WIND PC router –Unnecessary parts of ANDROID software have been removed –ANDROID TAG is being consolidated

6winit at IPv6 Concertation Meeting 14/10/02 6 6NET Project Background UCL is responsible for deployable IPv6- enabled VPNs 6NET has many deployed applications –Even Grid applications under development Has access to latest IPv6 versions of Cisco, 6WIND and Kame routers Has UMU IPv6-enabled VPN manage- ment system and PKI from UMU

6winit at IPv6 Concertation Meeting 14/10/02 7 6NET VPN Requirements VPN Management Security Infrastructure VPN Dynamism Failure Tolerant Distributed Access Control Secure Routing Complete IPv6 Infrastructure

6winit at IPv6 Concertation Meeting 14/10/02 8 Current UCL VPN Status UCL ANDROID work with Netcelo VPN Manager and Active Networking – IPv6 VPN established between 2 UCL Nodes And 1 UMU Node – IPv6 UCL membership of 5-Node ICB Coalition – IPv4

6winit at IPv6 Concertation Meeting 14/10/02 9 UMU IPSec Policy-Based Network Management (UMU-PBNM) VPN Enforcement Tool (VPN ETool) Policy Management Tool (UMU-PMTv6) Completely IPv6 Focussed 6WIND Routers Only Future Cisco Support

6winit at IPv6 Concertation Meeting 14/10/02 10 DVC Coalition Based Solution Highly Distributed PC and Non-PC Based Enforcement Points Currently No IPv6 Support – Only IPv4 Currently No Security Enrolment / Management

6winit at IPv6 Concertation Meeting 14/10/02 11 Netcelo Separate Proprietary VPN Manager IPv6 Focussed 6WIND Routers Only Fully-Meshed

6winit at IPv6 Concertation Meeting 14/10/02 12 Comparison DVC Provides Widest Hardware Requirements Flexibility DVC Provides Distributed Management DVC Localised Interface Is Faster DVC Lacks IPv6 Support DVC Lacks Generic PKI Mechanisms DVC does not give Network Topology and Routability

6winit at IPv6 Concertation Meeting 14/10/02 13 What We Want IPv6-enabled VPN Infrastructure Dynamism and Security of DVC Distributed nature of DVC Wider Deployability of DVC Policy Management of UMU Security Management of UMU Non-Decrypted Routing Over VPN Collaboration with other ICB members

6winit at IPv6 Concertation Meeting 14/10/02 14 Maybe we finally have a joint project