Mobile IPv6 - NSIS Interaction for Firewall traversal draft-thiruvengadam-nsis-mip6-fw-04 S. Thiruvengadam Hannes Tschofenig Franck Le Niklas Steinleitner.

Slides:



Advertisements
Similar presentations
Security Issues In Mobile IP
Advertisements

PMIPv6 Localized Routing Problem Statement draft-liebsch-netext-pmip6-ro-ps-01.txt Marco Liebsch, Sangjin Jeong, Qin Wu IETF75 - Stockholm NetExt WG, 30.
Applicability Statement of NSIS Protocols in Mobile Environments draft-ietf-nsis-applicability-mobility-signaling-12.txt Takako Sanda, Xiaoming Fu, Seong-Ho.
Secure Mobile IP Communication
Mobile IPv6: An Overview Dr Martin Dunmore, Lancaster University.
1 Introduction to Mobile IPv6 IIS5711: Mobile Computing Mobile Computing and Broadband Networking Laboratory CIS, NCTU.
Mobility Support in IPv6 Advanced Internet, 2004 Fall 8 November 2004 Sangheon Pack.
MIP Extensions: FMIP & HMIP
1Nokia Siemens Networks Presentation / Author / Date University of Twente On the Security of the Mobile IP Protocol Family Ulrike Meyer and Hannes Tschofenig.
1 Mobility Management for All-IP Mobile Networks: Mobile IPv6 vs. Proxy Mobile IPv6 Ki-Sik Kong; Wonjun Lee; Korea University Youn-Hee Han; Korea university.
Mobile IPv6 趨勢介紹 1. Mobile IP and its Variants Mobile IPv4 (MIPv4) – MIPv4 – Low-Latency Handover for MIPv4 (FMIPv4) – Regional Registration for MIPv4.
Dynamic Tunnel Management Protocol for IPv4 Traversal of IPv6 Mobile Network Jaehoon Jeong Protocol Engineering Center, ETRI
Inter-Subnet Mobile IP Handoffs in b Wireless LANs Albert Hasson.
Irish IPv6 Task Force - Irish IPv6 Task Force Mobility in IPv6 (MIPv6)
Spring 2004 Mobile IPv6 School of Electronics and Information Kyung Hee University Choong Seon HONG
1 Dual Stack Support in Mobile IPv6 for Hosts and Routers OR IPv4 traversal for Mobile IPv6 ! draft-ietf-mip6-nemo-v4traversal-00 H. Soliman, G. Tsirtsis,
1 © NOKIA NSIS MIPv6 FW/ November 8 th 2004 Mobile IPv6 - NSIS Interaction for Firewall traversal draft-thiruvengadam-nsis-mip6-fw-01 S. Thiruvengadam.
Mobile IP.
1 MIPv6 CN-Targeted Location Privacy and Optimized Routing draft-weniger-mobopts-mip6-cnlocpriv-01 IETF #68, Prague, March 2007.
1 Sideseadmed (IRT0040) loeng 5/2010 Avo
NSIS Path-coupled Signaling for NAT/Firewall Traversal Martin Stiemerling, Miquel Martin (NEC) Hannes Tschofenig (Siemens AG) Cedric Aoun (Nortel)
Draft-ietf-mobileip-vpn-problem-solution-02 Sami Vaarala Netseal.
IP Address Location Privacy and Mobile IPv6 draft-koodli-mip6-location-privacy-00.txt draft-koodli-mip6-location-privacy-solutions-00.txt.
0 NAT/Firewall NSLP Activities IETF 60th - August 2nd 2004 Cedric Aoun, Martin Stiemerling, Hannes Tschofenig.
1 RADIUS Mobile IPv6 Support draft-ietf-mip6-radius-01.txt Kuntal Chowdhury Avi Lior Hannes Tschofenig.
AAA and Mobile IPv6 Franck Le AAA WG - IETF55. Why Diameter support for Mobile IPv6? Mobile IPv6 is a routing protocol and does not deal with issues related.
Applicability Statement of NSIS Protocols in Mobile Environments (draft-ietf-nsis-applicability-mobility-signaling-00) Sung-Hyuck Lee, Seong-Ho Jeong,
Mobile IP Outline Intro to mobile IP Operation Problems with mobility.
1 Mobility Support in IPv6 (MIPv6) Chun-Chuan Yang Dept. Computer Science & Info. Eng. National Chi Nan University.
PMIPv6 Route Optimization Protocol draft-qin-mipshop-pmipro-00.txt Alice Qin Andy Huang Wenson Wu Behcet Sarikaya.
07/03/ nd IETF – Minneapolis Mobile IPv6 WG meeting PF_KEY Extension as an Interface between Mobile IPv6 and IPsec/IKE Shinta Sugimoto Francis Dupont.
Santhosh Rajathayalan ( ) Senthil Kumar Sevugan ( )
+ Solution Overview (LR procedure) The whole sequence for localized routing Local routing capability detection Local routing Initiation LR scope or LR.
Mobile IP 순천향대학교 정보기술공학부 이 상 정 VoIP 특론 순천향대학교 정보기술공학부 이 상 정 2 References  Tutorial: Mobile IP
Mobile IPv6 and Firewalls: Problem Statement Speaker: Jong-Ru Lin
Mobile IPv6 with IKEv2 and revised IPsec architecture IETF 61
Overview of draft–16 for MIPv6 MIPv6 Design Team March 19 th, 2002.
1 © NOKIA FILENAMs.PPT/ DATE / NN Requirements for Firewall Configuration Protocol March 10 th, 2005 Gabor Bajko Franck Le Michael Paddon Trevor Plestid.
NATFW NSLP Status draft-ietf-nsis-nslp-natfw-12.txt M. Stiemerling, H. Tschofenig, C. Aoun, and E. Davies NSIS Working Group,
Slide title In CAPITALS 50 pt Slide subtitle 32 pt Guidelines for Firewall Administrators Mobile IPv6 Suresh Krishnan, Niklas Steinleitner, Ying Qiu, Gabor.
MIPv6Security: Dimension Of Danger Unauthorized creation (or deletion) of the Binding Cache Entry (BCE).
Currently Open Issues in the MIPv6 Base RFC MIPv6 security design team.
1 Route Optimization and Location Privacy using Tunneling Agents (ROTA) draft-weniger-rota-01 Kilian Weniger, Takashi Aramaki IETF #64, Nov 2005.
IETF70 - Mobopts RG1 On Mobile IPv6 Optimization and Multihoming draft-ng-mobopts-multihoming-00.txt Chan-Wah Ng
Network Mobility (NEMO) Advanced Internet 2004 Fall
0 NAT/Firewall NSLP IETF 63th – August 2005 draft-ietf-nsis-nslp-natfw-07.txt Martin Stiemerling, Hannes Tschofenig, Cedric Aoun.
1 Mobility for IPv6 [MIP6] November 12 th, 2004 IETF61.
Slide title In CAPITALS 50 pt Slide subtitle 32 pt Guidelines for Firewall Vendors Mobile IPv6 Suresh Krishnan, Yaron Sheffer, Niklas Steinleitner, Gabor.
NSIS NAT/Firewall Signaling NSIS Interim Meeting Romsey/UK, June 2004 Martin Stiemerling, Hannes Tschofenig, Cedric Aoun.
Load Balance for Distributed Home Agents in Mobile IPv6 Authors: R. ZhangChina Telecom X.L. Huang UCLA K. Zhang Tsinghua Univ. H. DengHitachi (China) draft-deng-mip6-ha-loadbalance-01.txt.
Mobile IPv6 Location Privacy Solutions UPDATE draft-irtf-mobopts-location-privacy-solutions-04.txt Ying Qiu, Fan Zhao, Rajeev Koodli.
IP Address Location Privacy and Mobile IPv6: Problem Statement draft-irtf-mobopts-location-privacy-PS-00.txt Rajeev Koodli.
Paris, August 2005 IETF 63 rd – mip6 WG Mobile IPv6 bootstrapping in split scenario (draft-ietf-mip6-bootstrapping-split-00) mip6-boot-sol DT Gerardo Giaretta,
Applicability Statement of NSIS Protocols in Mobile Environments draft-ietf-nsis-applicability-mobility-signaling-06.txt Takako Sanda, Xiaoming Fu, Seong-Ho.
Service Flows Distribution and Handoff Technique based on MIPv6 draft-liu-dmm-flows-distribution-and-handoff-00
Slide title In CAPITALS 50 pt Slide subtitle 32 pt Flow Distribution Rule Language for Multi-Access Nodes draft-larsson-mext-flow-distribution-rules-01.
1 © NOKIA Presentation_Name.PPT / DD-MM-YYYY / Initials draft-bajko-nsis-fw-reqs-01 Gábor Bajkó IETF Interim May 2005.
Mobile IP THE 12 TH MEETING. Mobile IP  Incorporation of mobile users in the network.  Cellular system (e.g., GSM) started with mobility in mind. 
V4 traversal for IPv6 mobility protocols - Scenarios Mip6trans Design Team MIP6 and NEMO WGs, IETF 63.
RFC 3775 IPv6 Mobility Support
MOBILE IPv6 SECURITY ISSUES
Booting up on the Home Link
Mobility in a Dual Stack Internet
Monitoring MIPv6 Traffic with IPFIX
Support for Flow bindings in MIPv6 and NEMO
2002 IPv6 技術巡迴研討會 IPv6 Mobility
Mobile IP Presented by Team : Pegasus Kishore Reddy Yerramreddy Jagannatha Pochimireddy Sampath k Bavipati Spandana Nalluri Vandana Goyal.
Mobile IP Outline Homework #4 Solutions Intro to mobile IP Operation
Mobile IP Outline Intro to mobile IP Operation Problems with mobility.
Presentation transcript:

Mobile IPv6 - NSIS Interaction for Firewall traversal draft-thiruvengadam-nsis-mip6-fw-04 S. Thiruvengadam Hannes Tschofenig Franck Le Niklas Steinleitner Xiaoming Fu

Overview Problems of MIPv6 and Firewalls NSIS as Solution Draft Updates Open Issues Next Steps

Problem of MIPv6 and Firewalls Firewalls can cause several deployment problems –different based on FW placements Problem statement in RFC 4478 Additionally: draft-bajko-nsis-fw-reqs-04.txt

Overview of the Problems Binding Updates packets are IPsec protected Packets can be tunneled (or reverse tunneling) or not tunneled (route optimization) Several address are used Incoming packets does not match existing states in the FWs, because of different addresses (BU, CoTI, HoTI) Unsolved packets are dropped  Some packets might be dropped, preventing MIPv6 to perform well in presence of FWs

Why NSIS? Mobile IPv6 maintains entries for moving packets from a host to another host (in roaming scenarios) The endpoints are the only entities that –Have knowledge of the HoA, Home Agent address, CoA –Know the mode being used, and format of packets –Know the characteristics of the required pinholes The NAT/FW NSLP allow endpoints to configure FWs –Allow data receiver to initiate the signaling (REA) –Allow to create several states per request –Support the required filter parameter

NSIS as Solution The draft-thiruvengadam-nsis-mip6-fw-04 “Mobile IPv6 - NSIS Interaction for Firewall traversal” show how NSIS could solve the problems

Draft Updates Adapt draft to current version of NAT/FW NSLP draft and supported features Simplified protocol operation Reduce request latency

Necessity of detecting of the FW presence? Many states need to be created in the firewalls –Route Optimization –Reverse Tunneling –Home Test Init messages –Care of Test Init messages –Binding Updates –IPsec traffic between MN and HA Enabling a detection feature would –Allow several states to be created per request –Reduce the time delay: reduce MIP6/NSIS interaction –Reduce the overhead, especially for cellular networks

NATFW NSLP with MIP6 MN CN HA Example in a FW in MN’s access network (BT case): MN uses CREATE to allow: - binding update messages (src: CoA, dst: HA) {BU} - HoTI messages (src: CoA, dst: HA) {RO} - if uplink firewall, for data traffic from MN (src: MN, dst: *) MN uses REA to allow: - HoT messages (src: HA dst: CoA) {RO} - if CN is DS * for data traffic from HA to MN (src: HA, dst: CoA) {BT} * for data traffic from HA to MN (src: HA, dst: CoA) {TR} * for data traffic from CN to MN (src: CN, dst: CoA, SP: data application port, DP: data application port) {RO}

Open Issues Multiple rules for different patterns in single signaling messages possible? Detailed interaction with MIPv6 Authorization and authentication issues –May rely on an AAA infrastructure Triangle Routing case useful?

Next Steps Detailed interaction with MIPv6 operations Authorization using AAA Inputs, comments and suggestions appreciated!