I think Network Address Translation (NAT), which translates private and public IP addresses, is unnecessary overhead...
that will go away with IPv6. The elimination of NAT with IPv6 will offer major technical benefits by restoring the end-to-end principal of the Internet. With IPv6, enterprises will also get closer to end-to-end protection since the IPsec tunnel can initiate and terminate on the respective communication nodes; no intermediate gateway termination must take place. Additionally, the Authentication Header (AH), a core component of the IPsec protocol, is now an integral part of the connection. AH, which cannot be used in NAT environments, provides source authentication and integrity protection.
Users should make sure that their VPN providers offer true dual-stack IPsec implementations, supporting both IPv4 and IPv6 at the same time. Transport Relay Translator (TRT) nodes, as described by RFC 3142, do not support IPsec across those protocol relays which can pose challenges to VPN network traffic.
Email your VPN-related questions to email@example.com.
Dig Deeper on Network Security
Related Q&A from Rainer Enders
Administrators don't have to worry about interoperability; integrated mobile application and device management is the best approach. Continue Reading
Ensuring that the client software itself is up to date is just one of many reasons why it's critical to oversee VPN clients. Continue Reading
To ensure mobile device security, VPN expert Rainer Enders explains that it is crucial to monitor changed states and block software modifications. Continue Reading