Network Extrusion

Network Extrusion

A network extrusion is a kind of VPN tunnel where a subnet (or host) is moved to another location, without any router advertisement changes. Such a subnet is routed to normally, but then send via a VPN tunnel to appear anywhere else on the internet. This type of VPN connection is often used for:

  • Adding IPv4 public address space to a location that has only 1 public IP address, such as a consumer internet connection
  • Assigning a static IP address to a roaming laptop to ensure it is always reachable on 1 static IP address. This is often done with IPsec and L2TP or XAUTH

In IPsec/Openswan IPv4 configuration, this corresponds to a policy on the client system like:

 conn mylaptop—extruded

When this IPsec connecion is active, the default IP address for outgoing connections is Since this is covered by the IPsec tunnel, the packet will be encrypted and send to the remote IPsec gateway at It will get decrypted and then sent to its original destination. Response packets follow a similar path in reverse.

When using leftsubnet=, one could even run a small network with the laptop as default gateway and provide public IP addresses to many computers, all appearing to live at the remote site.

Generally, IPsec VPNs are used in many cases to route private networks rather than public ones, so while this configuration is not implausible, it is unusual for VPN administrators.

Many remote access situations run as network extrusions so that a corporate firewall can inspect the traffic that travels to and from the laptop computer.

This technique can also be used to tunnel in IPv6 space into networks where only IPv4 space is available (or vice versa)

These tunnels are invisible to traceroute because the IPsec tunnel appears as a single additional hop, just like a subnet.\

Wikimedia Foundation. 2010.

Игры ⚽ Поможем написать курсовую

Look at other dictionaries:

  • Extrusion detection — or outbound intrusion detection is a branch of intrusion detection aimed at developing mechanisms to identify successful and unsuccessful attempts to use the resources of a computer system to compromise other systems. Extrusion detection… …   Wikipedia

  • New Technology Network — Création mars 1918 Action TSE  …   Wikipédia en Français

  • plastic — plastically, plasticly, adv. /plas tik/, n. 1. Often, plastics. any of a group of synthetic or natural organic materials that may be shaped when soft and then hardened, including many types of resins, resinoids, polymers, cellulose derivatives,… …   Universalium

  • Business and Industry Review — ▪ 1999 Introduction Overview        Annual Average Rates of Growth of Manufacturing Output, 1980 97, Table Pattern of Output, 1994 97, Table Index Numbers of Production, Employment, and Productivity in Manufacturing Industries, Table (For Annual… …   Universalium

  • Space Shuttle Challenger disaster — For more information about the final mission and crew of the Challenger, see STS 51 L. Space Shuttle Challenger s smoke plume after the in flight breakup that killed all seven crew members …   Wikipedia

  • industrial polymers, major — Introduction       chemical compounds used in the manufacture of synthetic industrial materials.       In the commercial production of plastics, elastomers, man made fibres, adhesives, and surface coatings, a tremendous variety of polymers are… …   Universalium

  • Tribostatik — Pulverbeschichteter Benzintank Pulverlacke sind organische, meist duroplastische Beschichtungspulver mit einem Festkörperanteil von 100 %. Das Beschichten mit Pulverlacken erfordert im Gegensatz zu allen anderen Beschichtungstechnologien keine… …   Deutsch Wikipedia

  • Pulverlack — Pulverbeschichteter Benzintank Pulverlacke sind organische, meist duroplastische Beschichtungspulver mit einem Festkörperanteil von 100 %. Das Beschichten mit Pulverlacken erfordert im Gegensatz zu allen anderen Beschichtungstechnologien… …   Deutsch Wikipedia

  • building construction — Techniques and industry involved in the assembly and erection of structures. Early humans built primarily for shelter, using simple methods. Building materials came from the land, and fabrication was dictated by the limits of the materials and… …   Universalium

  • metallurgy — metallurgic, metallurgical, adj. metallurgically, adv. metallurgist /met l err jist/ or, esp. Brit., /meuh tal euhr jist/, n. /met l err jee/ or, esp. Brit., /meuh tal euhr jee/, n. 1. the technique or science of working or heating metals so as… …   Universalium

Share the article and excerpts

Direct link
Do a right-click on the link above
and select “Copy Link”