How do you guys solve the security matters when opening XML-channels between to business systems ?

What do you guys normaly do ?

# 1 Send passwrods through the url-string ? (Doesn't seem safe to me)

# 2 Locking IP numbers, infosender and reciever has fixed IP-numbers and an .asp page is doing a check before to se who is asking for info ?

Please give me some comments on this

/Johan Johansson