Kabir, Kantola, and Llorente Santos
204
2) supports Realm Gateway (RGW) to handle inbound connections towards private
hosts from the legacy Internet. RGW offers a better‐than classical NAT traversal
solution that scales well to mobile devices.
3) can act as a cooperative firewall that negotiates the communication policies of its
host with the policies of the destination located in another CES network.
Both the NAT and RGW functions aim to provide the backwards compatibility and
interconnection of CES with the legacy Internet, whereas CES‐to‐CES connectivity
allows secure interconnection between two customer networks. We briefly present the
comparison of CES functionality with NATs in Figure 9.3.
In the context of security, CES can be seen as an extension of the traditional stateful
firewall functionality into a cooperative firewall. Compared to the classical stateful fire‑
walls, which either accept or drop an inbound packet, CES can issue additional queries
to the source (network) of the packet, for example, for the purpose of eliminating spoof‑
ing, authenticating the sender and establishing the base‐level policy compliance. The
queries can also be issued to other Internet entities, such as Certificate Authorities (CA).
This establishes the basic trust at the network level, and provides grounds for attributing
the evidence of misbehaviour to the source address (or to the source network). Thus, if
a traditional firewall mostly executes the destination network rules, a CES firewall also
provides efficient methods related to the source addresses. A CES node can also use the
black, grey and white lists maintained by its trust domain. The reaction to a particular
flow can be controlled by a policy at CES and host levels. The policies can be dynamic
and will react to the type and level of malicious activity.
The establishment of trust at the network‐level allows hosts in the respective net‑
works to communicate following a negotiation of policies. A CES node acts as a connec‑
tion broker for the hosts/applications that it serves and exchanges their policy offers
and requirements with the remote hosts using Customer Edge Traversal Protocol
(CETP). For two hosts connected to their respective CES node, the negotiation of CETP
policies must succeed prior to the relaying of user data between the hosts. The scope of
policy negotiation is limited to CES only and is a must to establish the data connection
between two hosts communicating across their respective CES nodes. Subsequently,
CES acts as NAT
Legacy IP
sender
Sender behind CES
in Private Network
Legacy IP
receiver
Receiver behind CES
in Private Network
Basic Internet
CES acts a Realm
Gateway
CES acts as a
cooperative
firewall
(CETP-based)
Figure 9.3 CES Functionality comparison with NAT.
Précédent

- 246/483

Suivant