DQ1
430 REPLIES 75-100 WORDS
A Joshua Skinner
The baseline reason for implementing IPsec is to facilitate security to IP's. While there are several distinct implementation architectures in RFC 2401 for IPsec it depends upon the factors like the version of IP utilized. Some of the implementations are as followed: End host implementation and router implementation. The DNSSEC is a method that is implemented to protect and validate the DNS record without requirement to understand what the query is for. Typically, when you enable this protocol it involves a multi-step process, which includes registrar of the domain, configuration of the nameserver, and the TLD extension. Some advantages of IPsec include but are not limited to network layered protection and confidentiality. Some disadvantages are wide access range, and compatibility problem. Some advantages of DNSSEC are that it helps to secure the part from when the user types the domain name and actually visits the desired or requested website. Some disadvantages include complexity issues and requiring some time if the user wants to disable or enable it again.
B Yamil Santana
Implementing IPsec by end host would provide all devices and workstations with the IPsec security. This can be important if as a company that is exactly what you want to do on your network. You can also do individual router installations for partial network protection on the devices that you choose you want the IPsec security on.
Disadvantages:
First, it relies on the security of your public keys. If you have poor key management or the integrity of your keys is compromised then you lose the security factor. The second disadvantage is performance.
C Olatunbosun Osifowode
Implementation of IPsec:
End-host implementation - By enabling Ipsec into all host devices facilitates security and flexibility. It allows the end-to-end protection among various devices on the network.
Router implementation - This implementation requires less operation as it signifies that the user requires making modification to only a few routers. It facilitates security only among pairs of routers that perform Ipsec, whereas is sufficient for applications like VPNs.
The given protocols require certain data to be correctly implemented. It becomes more easy and safe to utilize third party software in order to enable these protocols. For example, CloudFlare enables DNSSEC to be allowed via multiple clicks of the mouse for clients that use its services.
Disadvantages of IPsec:
1. The greatest drawback of IPsec is that in case access to an individual device in IPsec-based network, can provide access privileges for other devices.
2. Also, IPsec brings several compatibility problems, such as when the developer doesn't adhere to the IPsec's standards.