Ubiquitous communication will be one of the paradigms for the next decades. The use of the Internet in such applications demands for a highly reliable and secure system, especially when used in non-academical environments like remote offices, e-commerce, or traffic telematics. Today’s Internet, even with the mobility extension Mobile IP, has not been designed with private addresses, firewalls, network address translation, quality of service etc. in mind. Several optimisations already exist—however, security is often neglected. This paper proposes the firewall-aware transparent internet mobility architecture FATIMA, which integrates security functionality but is transparent to existing Mobile IP implementations. All security critical functions are concentrated in a firewall, all control messages are authenticated, and micro-mobility is supported. Corporate networks with private addresses are supported seamlessly, and further extensions allow for the use of dynamic home address...