English  |  正體中文  |  简体中文  |  Items with full text/Total items : 62819/95882 (66%)
Visitors : 4010854      Online Users : 983
RC Version 7.0 © Powered By DSPACE, MIT. Enhanced by NTU Library & TKU Library IR team.
Scope Tips:
  • please add "double quotation mark" for query phrases to get precise results
  • please goto advance search for comprehansive author search
  • Adv. Search
    HomeLoginUploadHelpAboutAdminister Goto mobile version
    Please use this identifier to cite or link to this item: https://tkuir.lib.tku.edu.tw/dspace/handle/987654321/34196


    Title: IPsec效能分析及IPsec VPN架構設計之研究
    Other Titles: IPsec performance and IPsec VPN architecture study
    Authors: 呂佐鴻;Lu, Tso-hung
    Contributors: 淡江大學資訊管理學系碩士班
    李鴻璋;Lee, Hung-chang
    Keywords: IPsec;IPv6;認證標頭;加密安全承載資料;虛擬私有網路;IPsec;AH;ESP;VPN;IPv6
    Date: 2007
    Issue Date: 2010-01-11 05:01:15 (UTC+8)
    Abstract: 目前較熱門的虛擬私有網路技術有IPsec和SSL虛擬私有網路,雖然IPsec在IPv4網路環境與NAT有建置上的複雜度,但在未來的五年,隨著IPv4的位址用盡和IPsec已成為IPv6協定標準的一部分,使得IPsec在IPv6網路環境上的建置更顯的重要和簡單,所以本論文探討IPsec虛擬私有網路在不同網路環境下的策略研究,以顯示出在IPv6網路環境下的不同網路架構建置IPsec都簡單而且大同小異,不需繁雜的設定步驟。本研究實驗IPsec在IPv6網路環境上使用不同整數運算能力主機時TCP和UDP傳輸資料的輸出量(throughput),以探討使用不同整數運算能力主機對於IPsec套用認證標頭和加密安全承載資料時效能的差異性。
    本論文實驗結果顯示出,在TCP協定上使用IPsec的輸出量為未使用IPsec時的77.04%(較高運算能力主機)和75.46%(較低運算能力主機),而ARIGA只有未使用IPsec時的四分之ㄧ。同樣的,在UDP協定上,未使用IPsec的輸出量分別為80.31%和75.36%,ARIGA為未使用IPsec的九分之ㄧ。本文效能實驗結果希望能夠泯除在IPv6上使用IPsec導致效能嚴重下降的疑慮。
    IPsec VPN and SSL VPN are getting popular nowadays. It is complex when IPsec is established with NAT in the IPv4 network. Future five years, when the IPv4 address is used finished and IPsec have now become a part of IPv6 standard, the establishment which IPsec is in the IPv6 network will be more important and easier. This research is about the policy setting which IPsec VPN is in the different network architecture. There are similar settings even if the network architecture is different. This research also do some experiment to gain the throughput of TCP/UDP data transmission by using different ability host and IPsec is implemented in the IPv6 network. We also research the different of throughput which different host uses the authentication header (AH) and encapsulating security payload (ESP).
    With both the AH and the ESP by using TCP, the throughput degrades to about 77.04% (higher ability host) and 75.46% (lower ability host), but ARIGA’s result shows that the throughput degrades to 1/4. When it is by using UDP, the throughput degrades to about 80.31% and 75.36%, but ARIGA’s result shows that the throughput degrades to 1/9. We hope this research can reduce the misgivings which the throughput dropped seriously when IPsec is used in the IPv6 network.
    Appears in Collections:[Graduate Institute & Department of Information Management] Thesis

    Files in This Item:

    File SizeFormat
    0KbUnknown497View/Open

    All items in 機構典藏 are protected by copyright, with all rights reserved.


    DSpace Software Copyright © 2002-2004  MIT &  Hewlett-Packard  /   Enhanced by   NTU Library & TKU Library IR teams. Copyright ©   - Feedback