RSVP通过IPsec隧道方式使用rfc3175

T. Griem, A. Ayyagari, J. H. Kim
{"title":"RSVP通过IPsec隧道方式使用rfc3175","authors":"T. Griem, A. Ayyagari, J. H. Kim","doi":"10.1109/MILCOM.2005.1606156","DOIUrl":null,"url":null,"abstract":"Today, there is no effective solution for end-to-end (E2E) resource reservation protocol (RSVP) over Internet protocol security (IPsec) tunnel mode or virtual private network (VPN) environment. Currently, the interior routers supporting tunnels cannot respond to the encapsulated E2E RSVP messages and data. In this paper, we address the problem by providing a capability to support E2E RSVP over IPsec using the IETF RFC 3175 specifications. The RFC 3175-\"aggregation of RSVP for IPv4 and IPv6 reservations\", is an IETF proposal for improving the scalability of RSVP. however, it does not address its implementation over IPsec (or VPN) environments. We propose aggregate RSVP (A-RSVP) sessions between the routers to reserve the interior resources on behalf of the E2E RSVP sessions. The A-RSVP sessions are transmitted plain-text (PT) between enclaves and use the global DiffServ code point (DSCP) and tunnel exit point address as the RSVP session identifier. The encapsulated data is classified and scheduled by the interior network based on DiffServ's global DSCP marking and the corresponding per hop behaviors. The primary contribution of this design over RFC 3175 is to waive the requirement for protocol identifier modification (RSVP-E2E-IGNORE) and to identify a framework for implementing the capability over a tunnel-specific environment with multiple security enclaves. An alternative for multicast support is also proposed. The original proposal in RFC 3175 has the interior network depending on exterior multicast addresses to identify destination de-aggregators. We propose that portions of the multicast E2E path be aggregated together with unicast E2E RSVP sessions into the (unicast) A-RSVP sessions. The A-RSVP session will aggregate unicast and multicast RSVP sessions with similar service requirements.","PeriodicalId":223742,"journal":{"name":"MILCOM 2005 - 2005 IEEE Military Communications Conference","volume":"12 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2005-10-17","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"1","resultStr":"{\"title\":\"RSVP over IPsec tunnel mode using RFC 3175\",\"authors\":\"T. Griem, A. Ayyagari, J. H. Kim\",\"doi\":\"10.1109/MILCOM.2005.1606156\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"Today, there is no effective solution for end-to-end (E2E) resource reservation protocol (RSVP) over Internet protocol security (IPsec) tunnel mode or virtual private network (VPN) environment. Currently, the interior routers supporting tunnels cannot respond to the encapsulated E2E RSVP messages and data. In this paper, we address the problem by providing a capability to support E2E RSVP over IPsec using the IETF RFC 3175 specifications. The RFC 3175-\\\"aggregation of RSVP for IPv4 and IPv6 reservations\\\", is an IETF proposal for improving the scalability of RSVP. however, it does not address its implementation over IPsec (or VPN) environments. We propose aggregate RSVP (A-RSVP) sessions between the routers to reserve the interior resources on behalf of the E2E RSVP sessions. The A-RSVP sessions are transmitted plain-text (PT) between enclaves and use the global DiffServ code point (DSCP) and tunnel exit point address as the RSVP session identifier. The encapsulated data is classified and scheduled by the interior network based on DiffServ's global DSCP marking and the corresponding per hop behaviors. The primary contribution of this design over RFC 3175 is to waive the requirement for protocol identifier modification (RSVP-E2E-IGNORE) and to identify a framework for implementing the capability over a tunnel-specific environment with multiple security enclaves. An alternative for multicast support is also proposed. The original proposal in RFC 3175 has the interior network depending on exterior multicast addresses to identify destination de-aggregators. We propose that portions of the multicast E2E path be aggregated together with unicast E2E RSVP sessions into the (unicast) A-RSVP sessions. The A-RSVP session will aggregate unicast and multicast RSVP sessions with similar service requirements.\",\"PeriodicalId\":223742,\"journal\":{\"name\":\"MILCOM 2005 - 2005 IEEE Military Communications Conference\",\"volume\":\"12 1\",\"pages\":\"0\"},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2005-10-17\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"1\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"MILCOM 2005 - 2005 IEEE Military Communications Conference\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.1109/MILCOM.2005.1606156\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"MILCOM 2005 - 2005 IEEE Military Communications Conference","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/MILCOM.2005.1606156","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 1

摘要

目前,在IPsec (Internet protocol security)隧道模式或VPN (virtual private network)环境下,端到端(E2E)资源预留协议(RSVP)还没有有效的解决方案。目前,支持隧道的内部路由器无法响应封装后的端到端RSVP消息和数据。在本文中,我们通过提供使用IETF RFC 3175规范在IPsec上支持端到端RSVP的功能来解决这个问题。RFC 3175-“聚合IPv4和IPv6预留的RSVP”,是IETF为提高RSVP的可扩展性而提出的建议。但是,它没有解决其在IPsec(或VPN)环境上的实现。我们建议在路由器之间建立聚合RSVP (A-RSVP)会话,以代表端到端RSVP会话保留内部资源。A-RSVP会话以PT (plain-text)方式在enclave之间传输,使用全局DSCP (DiffServ code point)和隧道出口点地址作为RSVP会话标识符。内部网络根据DiffServ的全局DSCP标记和相应的每跳行为对封装后的数据进行分类和调度。这种设计在RFC 3175上的主要贡献是放弃了对协议标识符修改的需求(RSVP-E2E-IGNORE),并确定了一个框架,用于在具有多个安全飞地的特定于隧道的环境中实现该功能。另外还提出了一种支持组播的方案。RFC 3175中的原始提议是内部网络依赖于外部多播地址来识别目标去聚合器。我们建议将部分组播端到端路径与单播端到端RSVP会话聚合到(单播)A-RSVP会话中。A-RSVP会话将聚合具有类似业务需求的单播和多播RSVP会话。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
RSVP over IPsec tunnel mode using RFC 3175
Today, there is no effective solution for end-to-end (E2E) resource reservation protocol (RSVP) over Internet protocol security (IPsec) tunnel mode or virtual private network (VPN) environment. Currently, the interior routers supporting tunnels cannot respond to the encapsulated E2E RSVP messages and data. In this paper, we address the problem by providing a capability to support E2E RSVP over IPsec using the IETF RFC 3175 specifications. The RFC 3175-"aggregation of RSVP for IPv4 and IPv6 reservations", is an IETF proposal for improving the scalability of RSVP. however, it does not address its implementation over IPsec (or VPN) environments. We propose aggregate RSVP (A-RSVP) sessions between the routers to reserve the interior resources on behalf of the E2E RSVP sessions. The A-RSVP sessions are transmitted plain-text (PT) between enclaves and use the global DiffServ code point (DSCP) and tunnel exit point address as the RSVP session identifier. The encapsulated data is classified and scheduled by the interior network based on DiffServ's global DSCP marking and the corresponding per hop behaviors. The primary contribution of this design over RFC 3175 is to waive the requirement for protocol identifier modification (RSVP-E2E-IGNORE) and to identify a framework for implementing the capability over a tunnel-specific environment with multiple security enclaves. An alternative for multicast support is also proposed. The original proposal in RFC 3175 has the interior network depending on exterior multicast addresses to identify destination de-aggregators. We propose that portions of the multicast E2E path be aggregated together with unicast E2E RSVP sessions into the (unicast) A-RSVP sessions. The A-RSVP session will aggregate unicast and multicast RSVP sessions with similar service requirements.
求助全文
通过发布文献求助,成功后即可免费获取论文全文。 去求助
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术官方微信