What does IPv6 mean for IPsec VPNs?
What does IPv6 mean for IPsec VPNs?

    Requires Free Membership to View

    SearchEnterpriseWAN.com members gain immediate and unlimited access to breaking industry news, best practices for designing and managing Wide Area Networks, WAN Security, and more -- all at no cost. Join me on SearchEnterpriseWAN.com today!

    Kate Gerwig, Editorial Director

    By submitting your registration information to SearchEnterpriseWAN.com you agree to receive email communications from TechTarget and TechTarget partners. We encourage you to read our Privacy Policy which contains important disclosures about how we collect and use your registration and other information. If you reside outside of the United States, by submitting this registration information you consent to having your personal data transferred to and processed in the United States. Your use of SearchEnterpriseWAN.com is governed by our Terms of Use. You may contact us at webmaster@TechTarget.com.

I think Network Address Translation (NAT), which translates private and public IP addresses, is unnecessary overhead that will go away with IPv6. The elimination of NAT with IPv6 will offer major technical benefits by restoring the end-to-end principal of the Internet. With IPv6, enterprises will also get closer to end-to-end protection since the IPsec tunnel can initiate and terminate on the respective communication nodes; no intermediate gateway termination must take place. Additionally, the Authentication Header (AH), a core component of the IPsec protocol, is now an integral part of the connection. AH, which cannot be used in NAT environments, provides source authentication and integrity protection.

Users should make sure that their VPN providers offer true dual-stack IPsec implementations, supporting both IPv4 and IPv6 at the same time. Transport Relay Translator (TRT) nodes, as described by RFC 3142, do not support IPsec across those protocol relays which can pose challenges to VPN network traffic.

Email your VPN-related questions to editor@searchenterprisewan.com.

 

This was first published in November 2011