Current Issue


Table of contents

CD-ROM

Sys Admin and The Perl Journal CD-ROM version 12.0

Version 12.0 delivers every issue of Sys Admin from 1992 through 2006 and every
issue of The Perl Journal from 1996-2002 in one convenient CD-ROM!

Order now!

Sys Admin Magazine > Archives > 2001 > October 2001

Implementing IPSec in the SolarisTM 8 Environment

Kevin Wenchel

The Solaris 8 operating environment provides many new security features including native support for the IP Security Protocol (IPSec). IPSec, which was developed throughout the 1990s, defines cryptographic services at the IP layer that support data origin authentication, data integrity, and data confidentiality. The use of IPSec is transparent to users and network applications, making it an attractive way to improve the security of existing network services. In this article, I will provide a brief introduction to the architecture of the IPSec protocol, describe the tools used for managing IPSec on Solaris 8, and demonstrate a practical implementation of using IPSec to improve the security of the Network File System (NFS) protocol.

You do not have to look very hard to see that the Internet Protocol (IP) is inherently insecure. Noticeably absent from IP are any mechanisms to provide data origin authentication, data integrity, or data confidentiality. Simply put, when a host receives an IP datagram there is no guarantee that 1) the IP datagram originated from the source claimed in the IP header source address field; 2) the data content of an IP datagram has not been modified in transit; and 3) unauthorized persons have not inspected the data content of the IP datagram in transit. For these reasons, IP and its upper-level protocols are particularly susceptible to spoofing and session hijacking attacks. To understand how IPSec addresses these problems, it is important to understand three core IPSec components: the data protection mechanisms, the Security Association Database, and the Security Policy Database.




MarketPlace

FREE Trial Download Speeds Up Systems Now!
New Diskeeper 2008 Maximizes System Performance and Reliability�Automatically!

Villanova University Six Sigma & IT Certificate Programs
100% Online programs in Six Sigma, IS Security, CISSP Prep, Business Analysis, Proj. Mgmt. and more!

Automate Software Builds with Visual Build Pro
Easily create an automated, repeatable process for building and deploying software.

Discover WinDev 12 RAD
and develop 10 times faster ! ALM, IDE, .Net, PDF, 5GL, Database, 64-bit, etc. Free Express version

Wanna see your ad here?