preview

IPSec and Network Security Essay

Decent Essays

IPSec is a framework which utilizes a set of IETF protocols to offer end-to-end IP security using strong encryption, public and private key pair cryptography. IPSec secures communication links that could experience network security issues like corruption, eavesdropping, misused data etc (Pezeshki et al 2007) when not secured. However, using IPSec tends to also have an adverse effect on router utilization and overall network performance. One of the major issues with IPSec is performance degradation and throughput (Berger, 2006) which goes back to the complex authentication and encapsulation techniques. Data protection tends to increase required bandwidth; security transformation reduces performance and delays data processing and …show more content…

Adding IPSec VPN technology appears to come with high data processing cost and additional complexity. IPSec is slow in establishing connection. This adds to delay in establishing authenticated connections degrading network service levels and user productivity (Pezeshki, et al.2007). Using IKE initially to negotiate security usually increases time of connection by one to three seconds depending on the network rounding time, policy design and required load on system to establish connection. IPSec protection tends to adds overheads to IP packets. The use of IKE, ESP, Cryptography and digital signature generation and Diffie-Hellman computations (Shue, et al 2007; Fujimoto and Takenaka, 2006) all cause overheads and this increases network utilization and reduces effective throughput especially when multiple clients connect to it simultaneously. The interaction of IPSec VPNs and firewalls in practice may cause problems (Berger, 2006; Adeyinka, 2008b). A strict firewall policy may prevent adoption of IPSec packets. This is because ESP and AH encapsulates IP payloads by adding security header to each packet making it difficult to interpret IPSec protected packets by existing network management. The presence of NAT could also lead to a wrong process of IP packets because NAT devices checks and modifies the packet port address which is encrypted by IPSec packet (Mei and Zhang, 2009). Interoperability is another issue with IPSec VPN

Get Access