Security Portal: IPSec - We've Got a Ways to Go (Part I) | Linux Today

Security Portal: IPSec – We’ve Got a Ways to Go (Part I)

Written By
Web Webster
Web Webster
Jul 19, 2000

IPSec, supposedly the next great thing that will fix most
(if not all) our network security problems. No longer will
attackers be able to sniff network traffic, hijack connections or
spoof servers. Hijacking domain names will be impossible with
DNSSEC, and redirecting people to fake Websites will be a thing of
the past. Or will it?
There are currently a lot of problems
and shortcomings with IPSec that prevent the majority of network
traffic from being encrypted.”

“Right now IPSec is being deployed primarily in two
environments. The first is gateway to gateway, behind which are
normal IPv4 LANs moving unencrypted data around. In order to
connect them securely over the Internet, IPSec gateways are
deployed to encrypt traffic going through them. This is very useful
for connecting branch offices together, and in other similar
situations.”

“Alternatively, since LANs require a higher degree of security,
IPSec is deployed to all the desktops and servers in question,
resulting in all LAN traffic (interesting stuff like file and print
transfers, authentication sessions and so on) being strongly
encrypted. If an attacker breaks into this LAN they will not be
able to sniff for passwords or spoof machines, as all the IP
traffic is encrypted and authenticated.”

“Both of these methods are, generally speaking, very time- and
effort-intensive. You need to deploy IPSec software to the gateways
in question, and then do a lot of configuration, gateway to gateway
connection, subnet(s) to subnet(s) through the gateway connections,
and so on. If you have five sites with two subnets behind each
gateway, and you want a full mesh, you are going to need to
configure many IPSec tunnels (in some cases, almost 100
connections).”

Complete
Story

Web Webster

Web Webster

Web Webster has more than 20 years of writing and editorial experience in the tech sector. He’s written and edited news, demand generation, user-focused, and thought leadership content for business software solutions, consumer tech, and Linux Today, he edits and writes for a portfolio of tech industry news and analysis websites including webopedia.com, and DatabaseJournal.com.

Linux Today Logo

LinuxToday is a trusted, contributor-driven news resource supporting all types of Linux users. Our thriving international community engages with us through social media and frequent content contributions aimed at solving problems ranging from personal computing to enterprise-level IT operations. LinuxToday serves as a home for a community that struggles to find comparable information elsewhere on the web.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.