Presentation is loading. Please wait.

Presentation is loading. Please wait.

Networks Research Group Deployment of an IPv6-Enabled Dynamic VPN Infrastructure.

Similar presentations


Presentation on theme: "Networks Research Group Deployment of an IPv6-Enabled Dynamic VPN Infrastructure."— Presentation transcript:

1 Networks Research Group Deployment of an IPv6-Enabled Dynamic VPN Infrastructure

2 3 September 2003Networks Research Group Seminar2 Current Work Projects Projects  Past  ANDROID  RADIOACTIVE  Present  6NET  ICB  Future  SEINIT VPN Technologies  Netcelo VPN Manager  ISI - X-Bone  DRDC - DVC  UMU - PBNM  Entrust VPN Connector

3 6NET VPN Infrastructure Deployment “To look at the issues surrounding the provision of IPv6 dynamic VPN technology and deploy an IPv6- Enabled VPN Infrastructure”

4 International Collaboration Board (ICB) “To carry out an experimental deployment of an IPv6-Enabled VPN Infrastructure upon which one can experiment on the sort of policies that coalition networks require”

5 3 September 2003Networks Research Group Seminar5 Netcelo VPN Management Deployed During ANDROID Deployed During ANDROID Single VPN Manager Single VPN Manager Full Mesh Topology Full Mesh Topology Tested with Multicast Conferencing Tested with Multicast Conferencing  Active Networking (Funnelweb)  Transcoding Active Gateway Proprietary System Proprietary System

6 3 September 2003Networks Research Group Seminar6 ISI X-Bone UCL extended X-Bone for IPv6 capability during RADIOACTIVE UCL extended X-Bone for IPv6 capability during RADIOACTIVE Overlay Managers & Resource Daemons Overlay Managers & Resource Daemons Invitation-Based Set-Up Invitation-Based Set-Up Choice Of Topology Choice Of Topology Recursive Overlays Recursive Overlays Demonstrated at DANCE - May 2002 Demonstrated at DANCE - May 2002  3 sites - Star Topology Possibility of sub-optimal topology Possibility of sub-optimal topology

7 3 September 2003Networks Research Group Seminar7 DRDC DVC “Provides secure/authenticated out-of-band channels to establish, monitor and dismantle VPNs” “Provides secure/authenticated out-of-band channels to establish, monitor and dismantle VPNs” Based On Ideas From X-Bone Based On Ideas From X-Bone Coalition-Based Coalition-Based Full Mesh Topology Full Mesh Topology Exchange of Security Policies Exchange of Security Policies

8 3 September 2003Networks Research Group Seminar8 UMU-PKIv6 UMU-PKIv6  CA Provides X.509 Certificate Enrollment And Lifecycle Management for IPv6  Supports LDAPv6, OCSP and SCEP UMU-PBNM UMU-PBNM  Policy Management Tool (PMT)  Policy Decision Point (PDP)  Policy Enforcement Point (PEP)  VPN Enforcement Tool (VPN ETool) UMU-PBNM COPS

9 3 September 2003Networks Research Group Seminar9 Issues No clear globally accepted VPN definition No clear globally accepted VPN definition Scope of a VPN Scope of a VPN Uncertainty in: Uncertainty in:  What is required  How to develop it  The Current status of each of the projects VPN Workshop – July 2003 VPN Workshop – July 2003  Aim to discuss and resolve issues of confusion  Aim to encourage collaboration

10 3 September 2003Networks Research Group Seminar10 Building An Ideal System Each system excels in its particular area of focus Each system excels in its particular area of focus  X-Bone – Overlay Hierarchy, Topology  DVC – Distributed, Localised Control  UMU-PBNM – Security Infrastructure Want the best of all worlds Want the best of all worlds

11 3 September 2003Networks Research Group Seminar11 Ideal System – Existing Features Localisation and Security of DVC Localisation and Security of DVC Distributed Nature of DVC Distributed Nature of DVC Platform Independence of DVC/X-Bone Platform Independence of DVC/X-Bone Hierarchic Nature of X-Bone Hierarchic Nature of X-Bone Topological Flexibility of X-Bone/UMU Topological Flexibility of X-Bone/UMU Policy Management of UMU Policy Management of UMU Security Management of UMU Security Management of UMU

12 3 September 2003Networks Research Group Seminar12 Ideal System – New Features Dynamic Topology Dynamic Topology (Secure?) Routing over VPN (Secure?) Routing over VPN Multicast Capability Multicast Capability QoS Provision QoS Provision

13 3 September 2003Networks Research Group Seminar13 VPN Workshop – Summary X-Bone X-Bone  Expected to be IPv6-Enabled October  Dynamic Overlay Routing  Node Re-visitation  Provides capability for topological definition  Does not allow addition/deletion of nodes to as existing overlay  Combination with other systems looks promising

14 3 September 2003Networks Research Group Seminar14 VPN Workshop – Summary cont. DVC DVC  Good model for flexible use of policies  Agreed to move to IPv6 – target date November  Currently moving toward XML based policy definition  Discussing combination with UMU

15 3 September 2003Networks Research Group Seminar15 VPN Workshop – Summary cont. UMU UMU  Security Management Infrastructure  Policy Management Infrastructure  VPN definition limited to 6WIND

16 3 September 2003Networks Research Group Seminar16 VPN Workshop – Summary cont. Cisco Cisco  Presented various approaches for large scale VPN deployment  Stated IPv6 IPSec solutions not planned before mid-2004

17 3 September 2003Networks Research Group Seminar17 VPN Workshop – Outcome Updated parties on status of projects Updated parties on status of projects Discussions conducted on problems and issues Discussions conducted on problems and issues Consensus reached over issues of confusion Consensus reached over issues of confusion All parties agreed on collaboration All parties agreed on collaboration Plans for hosting a further VPN Workshop during November Plans for hosting a further VPN Workshop during November

18 3 September 2003Networks Research Group Seminar18 Future Work Re-evaluate X-Bone With Enhancements Re-evaluate X-Bone With Enhancements Initial Deployment Potentially X-Bone Initial Deployment Potentially X-Bone VPN Management System VPN Management System  Dynamic Tunnel Establishment & Management  Dynamic Topology (Bootstrapping) Policy Definition Policy Definition  Types of policies

19 Networks Research Group Manish Lad m.lad@cs.ucl.ac.uk Department of Computer Science University College London


Download ppt "Networks Research Group Deployment of an IPv6-Enabled Dynamic VPN Infrastructure."

Similar presentations


Ads by Google