Abstract
A virtual private network (VPN) is a kind of technology that takes the public telecommunication network to access the private network by using the tunneling and security protocol. Mobile IP allows the mobile node seamlessly roam to foreign networks without any session disconnection. However the combination of the VPN and Mobile IP results in some integration issues. Hence IETF proposed an solution, which could bring the mobility convenience for customers to keep up their connection seamlessly and confidentially. However, the mobile IP tunneling and security overhead could affect the realtime traffic severely, especially for the bandwidth consumption and end-to-end delay for VoIP service . This thesis presents an alternative SIP-Based Mobile VPN that comprises of SIP, SRTP, MIKEY, and Diameter to provide confidential realtime service with mobility. The proposed approach is implemented based on the MIDCOM architecture, which the SIP Proxy processes the signaling exchange and the Application Level Gateway (ALG) not only performs the firewall functionality but also acts as a middlebox for the SIP proxy to protect the realtime traffic between the mobile node and Intranet. The interaction of the SIP Proxy and the ALG is the core of our proposed solution. Finally, a testbed for our proposed solution has been implemented and have experiments of bandwidth consumption, end-to-end delay, and handoff delay for comparing with IETF Mobile VPN.