Search /
Docfinder:
Advanced search  |  Help  |  Site map
RESEARCH CENTERS
SITE RESOURCES
Click for Layer 8! No, really, click NOW!
Networking for Small Business
TODAY'S NEWS
Apple tops the $100B+ tech club
How to get the IRS' attention: Forge nearly $8 million in tax returns, steal identities
Microsoft details Windows 8 for ARM devices
Blogger exposes major Google Wallet security flaw
Web app lets enterprise set security, sharing for Google Apps users
Cloudscaling to offer OpenStack private cloud platform
Valentine's Day Patch Tuesday: Microsoft to issue 9 patches, 4 critical
Mobile World Congress sneak peek: Quad-core smartphones, Ice Cream Sandwich & more
Microsoft details 'Windows on ARM' program
March debut of 'iPad 3' a sure bet, says analyst
Resume Makeover: How an Information Security Professional Can Target CSO Jobs
FBI unbolts Steve Jobs 1991 investigation file
Cisco boosted profit, sales in Q2 while cutting costs
Macs take on the enterprise
/

IETF renews VPN protocol talks

Today's breaking news
Send to a friendFeedback


The Internet Engineering Task Force soon may sort out how to replace the standard protocol that manages encryption keys for IP Security VPNs with one that could lead to more secure VPNs and to equipment that is more interoperable and easier to configure.

Members of the group have been hashing out differences between two competing proposals to decide which will replace the current standard protocol, known as Internet Key Exchange (IKE).

Neither proposal drew major criticism during discussions on an IETF mailing list during the past week. Rather, discussion focused more on answering individual members' questions.

The alternative protocols, known as IKEv2 and just fast keying (JFK), were proposed last year, but a point-by-point comparison of the two recently posted to an IETF discussion group sparked renewed interest. Initially, IETF members thought they would pick one or the other proposal to go forward with in March, but no decision has been made yet.

Issues that have been raised include whether the proposed protocols are open to certain kinds of attacks and addressing how to make them work across wireless networks.

If no major flaws are found with either IKEv2 or JFK, the IETF IPSec Working Group could poll members to see which proposal they want to pursue.

IKE as it is used today as part of IPSec has been deemed too complicated, which is a barrier to interoperability and a potential security weakness. While no security flaw has been exploited, the complexity of the protocol lends itself to the possibility that a weakness could be found.

A simpler protocol also would mean fewer configuration parameters on VPN gear using it, making equipment setup easier.

RELATED LINKS

Contact Senior Editor Tim Greene

Other recent articles by Greene

IKEv2 overview
In PDF.

JFK draft


NWFusion offers more than 40 FREE technology-specific email newsletters in key network technology areas such as NSM, VPNs, Convergence, Security and more.
Click here to sign up!
New Event - WANs: Optimizing Your Network Now.
Hear from the experts about the innovations that are already starting to shake up the WAN world. Free Network World Technology Tour and Expo in Dallas, San Francisco, Washington DC, and New York.
Attend FREE
Your FREE Network World subscription will also include breaking news and information on wireless, storage, infrastructure, carriers and SPs, enterprise applications, videoconferencing, plus product reviews, technology insiders, management surveys and technology updates - GET IT NOW.