寻英语高手翻译这篇文章(计算机网络方面文章)

Status of this Memo

This memo provides information for the Internet community. It does
not specify an Internet standard of any kind. Distribution of this
memo is unlimited.

Copyright Notice

Copyright (C) The Internet Society (1999). All Rights Reserved.

Abstract

There are a variety of NAT flavors, as described in [Ref 1]. Of the
domains supported by NATs, only Realm-Specific IP clients are able to
pursue end-to-end IPsec secure sessions. However, all flavors of NAT
are capable of offering tunnel-mode IPsec security to private domain
hosts peering with nodes in external realm. This document describes a
security model by which tunnel-mode IPsec security can be architected
on NAT devices. A section is devoted to describing how security
policies may be transparently communicated to IKE (for automated KEY
exchange) during Quick Mode. Also outlined are applications that can
benefit from the Security Model described.

1. Introduction and Overview

NAT devices provide transparent routing to end hosts trying to
communicate from disparate address realms, by modifying IP and
transport headers en-route. This solution works best when the end
user identifier (such as host name) is different from the address
used to locate end user.

End-to-end application level payload security can be provided for
applications that do not embed realm-specific information in payloads
that is meaningless to one of the end-users. Applications that do
embed realm-specific information in payload will require an
application level gateway (ALG) to make the payload meaningful in
both realms. However, applications that require assistance of an ALG
en-route cannot pursue end-to-end application level security.

第1个回答  2008-04-25
地位,这份备忘录

这份备忘录提供的资料,为互联网社区。但这
未指定Internet标准,任何形式的保证。分布,这
备忘录是无限的。

版权声明

版权所有( C )因特网社会( 1999年) 。保留所有权利。

摘要

有各种各样的NAT的口味,所描述的[参1 ] 。该
网域的支持,地址解析器,只有境界-特定的IP客户可以
追求端到端的IPSec安全会议。然而,所有口味的NAT
有能力提供隧道模式IPSec安全到私人领域
主机对等节点在外部的境界。本文件描述了
安全模型,其中隧道模式IPSec安全,可以设计
对NAT设备。一节是专门描述如何安全
政策可能会透明的传达给IKE协议(自动化的关键
交换)在快速模式。另外也扼要说明,可以申请
有利于从安全模型所描述的。

1 。介绍和概述

NAT设备提供透明路由结束东道主试图
沟通从不相干的地址境界,通过修改IP和
运输标题-路线。这个解决方案的最佳时,工程结束
用户识别码(如主机名称)是不同的从地址
用来找到最终用户。

端到端的应用水平,有效载荷安全可提供
申请不嵌入的境界,特定的信息在有效载荷
这是毫无意义的一个最终用户。应用程序做
嵌入的境界,特定的信息在有效载荷将需要1
应用级网关(算法) ,使有效载荷的意义
双方境界。然而,应用程序需要援助的一个算法
-路线不能追求端到端的应用级安全