* IPv6 could help remove one of the barriers to IPSec VPN adoption
One of the vexing things about IP Security (IPSec) VPNs is network address translation (NAT); that is, converting private IP addresses to public ones when traffic crosses a firewall so Internet routers can figure out where the traffic ought to go and where it comes from.
Standards and vendors have overcome this problem by encapsulating packets to hide their private headers, but setting up the NATting is still a chore. Getting rid of worries about NATting is one of the draws of Secure Sockets Layer (SSL) VPNs, and NATing is often cited as one of the drawbacks of IPSec VPNs.
Enter IPv6, which has enough unique IP addresses so there is no need for private IP addresses. Each device can have its own public address, making NAT unnecessary.
At a recent conference, a group of university IT professionals was delivering an update on the Internet 2 project that, among many other things, relies on IPv6. Internet 2 is primarily driven by universities, but businesses are also involved.
One of the speakers cited a case in which an auto manufacturer used Internet 2 to connect with a university using IPv6. The auto IT execs were delighted that they didn’t have to deal with firewall issues due to NAT. Their relief was so strong as to be notable by their university counterparts.
As IPv6 becomes more common, and it seems to be on a slow adoption curve, it will remove one of the barriers to people adopting IPSec VPNs, especially for remote access. It may make SSL VPNs less of the slam-dunk choice for secure remote access as many have characterized it.




