ÏÂͼÊÇSSL VPNÊÊÓõÄ×éÍø½á¹¹
ArrayNetworks
ͬIPSec VPNÏà±È£¬SSL VPN¾ßÓÐÈçÏÂÓŵ㣺
? SSL VPNµÄ¿Í»§¶Ë³ÌÐò£¬ÈçMicrosoft Internet Explorer¡¢Netscape
Communicator¡¢MozillaµÈÒѾԤװÔÚÁËÖÕ¶ËÉ豸ÖУ¬Òò´Ë²»ÐèÒªÔٴΰ²×°£» ? SSL VPN¿ÉÔÚNAT´úÀí×°ÖÃÉÏÒÔ͸Ã÷ģʽ¹¤×÷£»
? SSL VPN²»»áÊܵ½°²×°ÔÚ¿Í»§¶ËÓë·þÎñÆ÷Ö®¼äµÄ·À»ðǽµÄÓ°Ïì¡£
? SSL VPN½«Ô¶³Ì°²È«½ÓÈëÑÓÉìµ½IPSec VPNÀ©Õ¹²»µ½µÄµØ·½£¬Ê¹¸ü¶àµÄÔ±¹¤£¬
ÔÚ¸ü¶àµÄµØ·½£¬Ê¹Óøü¶àµÄÉ豸£¬°²È«·ÃÎÊÆóÒµÍøÂç×ÊÔ´£¬Í¬Ê±½µµÍÁ˲¿ÊðºÍ
Company Confidential Page 9 of 28
ArrayNetworks
Ö§³Ö·ÑÓá£SSL VPNÕýÔÚ³ÉΪԶ³Ì½ÓÈëµÄÊÂʵ±ê×¼£¬ÏÂÃæÁоÙÁËÆäÖеÄһЩÀíÓÉ¡£
? SSL VPN¿ÉÒÔÔÚÈκεص㣬ÀûÓÃÈκÎÉ豸£¬Á¬½Óµ½ÏàÓ¦µÄÍøÂç×ÊÔ´ÉÏ¡£SSL VPN
ͨÐÅÔËÐÐÔÚTCP/ UDPÐÒéÉÏ£¬¾ßÓд©Ô½·À»ðǽµÄÄÜÁ¦¡£ÕâÖÖÄÜÁ¦Ê¹SSL VPNÄܹ»´ÓÒ»¼ÒÓû§ÍøÂçµÄ´úÀí·À»ðǽ±³ºó°²È«·ÃÎÊÁíÒ»¼ÒÓû§ÍøÂçÖеÄ×ÊÔ´¡£IPSec VPNͨ³£²»ÄÜÖ§³Ö¸´ÔÓµÄÍøÂ磬ÕâÊÇÒòΪËüÃÇÐèÒª¿Ë·þ´©Ô½·À»ðǽ¡¢IPµØÖ·³åÍ»µÈÀ§ÄÑ¡£¼øÓÚIPSec¿Í»§»ú´æÔÚµÄÎÊÌ⣬IPSec VPNʵ¼ÊÉÏÖ»ÊÊÓÃÓÚÒ×ÓÚ¹ÜÀíµÄ»òÕßλÖù̶¨µÄÉ豸¡£
? SSL VPNÊÇ»ùÓÚÓ¦ÓõÄVPN£¬»ùÓÚÓ¦ÓòãÉϵÄÁ¬½ÓÒâζ×Å£¨ºÍIPSec VPN ±È
½Ï£©£¬SSL VPN ¸üÈÝÒ×ÌṩϸÁ£¶ÈÔ¶³Ì·ÃÎÊ£¨¼´¿ÉÒÔ¶ÔÓû§µÄȨÏ޺ͿÉÒÔ·ÃÎʵÄ×ÊÔ´¡¢·þÎñ¡¢Îļþ½øÐиü¼ÓϸÖµĿØÖÆ£¬ÕâÊÇIPSec VPNÄÑÒÔ×öµ½µÄ£©¡£ IPsec VPNºÍSSL VPN ½«ÔÚÍøÂç×éÍøÖз¢»Ó¸÷×ÔµÄÓÅÊÆ£¬ÏÂͼÊÇÒ»¸öÔ¶³Ì°²È«Êг¡µÄÔ¶¾°·ÖÎö£º
WW VPN Equipment Spending by Product Category43$ Billion21020022004200520063.52.83.73.82.51.50.80.1IPSec VPN/FirewallSSL VPN Company Confidential Page 10 of 28
ArrayNetworks
2. Array Networks SSL VPN½â¾ö·½°¸
2.1 ArrayµÄSSL VPNµÄ¹¦ÄÜ
¶àÏîÒµÎñ¼¯³ÉÄÜ×î´óÏ޶ȵØÀûÓÃÒÑÓÐÁ´Â·£¬Ìá¸ßÍøÂç¾¼ÃÐÔ£¬µ«ÓÉ´Ë´øÀ´µÄ°²È«ÎÊÌâ²»ÈݺöÊÓ£¬ÀýÈ磺Զ³Ì´ó»§ºÍ¹«Ë¾ÓªÒµ²¿Ö°Ô±ËùÄÜ·ÃÎʵÄȨÏ޿϶¨ÊÇÓÐËù²»Í¬µÄ£¬ËüÃǵÄÊý¾ÝÓ¦Äܱ»Ê¶±ðºÍ¸ôÀ뿪À´·Ö±ð´¦Àí¡£²ÉÓÃArray¹«Ë¾¶Ëµ½¶ËµÄ°²È«½â¾ö·½°¸£¬¿ÉÒÔÌṩÒÔϰ²È«·À·¶ÊֶΣº
ʵʩ°²È«ÈÏÖ¤££°²È«ÈÏÖ¤Ö÷ÒªÊǶÔÓû§Éí·Ýʵʩ¼ìÑéºÍȨÏÞÉ趨£¬ÕâÑùµ±ÍⲿÓû§ÒÔÔ¶³Ì´ó»§Éí·ÝºÍÒÔÓªÒµ²¿Ö°Ô±Éí·ÝµÇ¼ʱ£¬ËûÃÇËùÄÜ·ÃÎʵÄÊý¾Ý¿ÉÒÔÊǽØÈ»²»Í¬µÄ¡£°²È«ÈÏÖ¤Ò»°ã²ÉÓü¯ÖйÜÀí·½Ê½£¬ÔÚÄÚ²¿ÍøÂçÖÐÉèÁ¢×¨ÃŵÄÈÏÖ¤·þÎñÆ÷£¬ÔÚÆäÉϽ¨Á¢Óû§Êý¾Ý¿â£¬ÕâÑù²»ÂÛÓû§´ÓºÎ´¦µÇ¼½øÀ´£¬¶¼ÐèÒª¾¹ý¸Ã·þÎñÆ÷µÄͳһ¼ìÑ飬ÊÚȨ²¢ÇÒÆäºóµÄËùÓзÃÎʹý³Ì¶¼¿É±»É󼯣¬¼ÇÈëÈÕÖ¾¡£
ÏÂͼΪArray SP²úÆ·ÔÚSSL VPNÓ¦ÓÃÖеÄÍøÂç½á¹¹¡£ Corporate NetworkSSLSSLSSLSSLArray SPProxySSLSSLSSLClientClientSSLInternet Page 11 of 28 Company Confidential https://intranet.arraynetworks.net
ArrayNetworks
ÉÏͼÊÇÒ»¸öµäÐ͵ÄSSL VPN×éÍøµÄÍØÆË½á¹¹Í¼£¬Ô²È¦ÖÐΪÆóÒµµÄºËÐÄÊý¾ÝÍøÂ磬Զ¶ËÓû§Í¨¹ýinternetÓëÆóÒµÊý¾ÝÖÐÐÄÏàÁ¬¡£´Ëʱ£¬ÔÚÆóÒµ±ßÔµ²¿ÊðSSL VPNÍø¹Ø£ArrayNetworks SP ( security proxy),SP¿ÉÒÔ·ÅÔÚ·ÓÉÆ÷ºÍ·À»ðǽµÄºóÃæ£¬ÌṩSSL VPNÃÅ»§Õ¾µã£¨ÈçÉÏͼ×óÉϽǵÄÒ³Ãæ£©¡£ËùÓÐÉÏÍøÓû§±ØÐëµÇ½´Ë SSL VPN ÃÅ»§Õ¾µã²ÅÄÜ·ÃÎÊSSL VPN£¬Í¬Ê±Ã¿¸öÓû§±ØÐëÓÐ×Ô¼ºµÄÕʺš¢¿ÚÁî²¢ÏíÓзÃÎÊSSL VPN¸÷ÖÖ×ÊÔ´µÄÏìӦȨÏÞ¡£SPÌṩµÄÃÅ»§Õ¾µãIPµØÖ·¿ÉÒÔÊǹ«ÍøµØÖ·£¬Ò²¿ÉÒÔÊÇ·À»ðǽµÈµØÖ·ÌṩµÄNATºóµÄ˽ÓеØÖ·¡£´Ëʱ£¬·À»ðǽ¿ÉÒÔÖ»¶ÔSP¿ª·ÅhttpsµÄ¶Ë¿ÚµØÖ·£¬È±Ê¡ÎªTCP 443¶Ë¿Ú¡£Óû§¶ËʹÓñê×¼µÄä¯ÀÀÆ÷£¬ÈçIE ºÍ Netscape£¬Óû§¿ÉÒÔÊÇNAT£¬»òÕßÊÇͨ¹ý´úÀí·½Ê½·ÃÎÊ£¬Ö»Ðè±£³ÖhttpsͨµÀÊdz©Í¨µÄ¼È¿É¡£
ArrayNetowrks SSL VPN½â¾ö·½°¸ÊÇGlobal Access·½°¸£¬²»Ö»Ö§³ÖRemote Access£¬¶ÔÓÚÆóÒµÄÚÍøÓû§Í¬Ñù¿ÉÒÔͨ¹ýSSL VPNÀ´½øÐÐÏìÓ¦µÄÈÏÖ¤¡¢¼ÓÃܺÍȨÏÞÏÞÖÆ£¬ÄÚ²¿·ÃÎʵݲȫÐÔ¡£ ÏÂͼÊÇArrayNetworks SPµäÐÍÓ¦ÓõÄÁ÷³Ìͼ£º
1. Initial HTTPS Request2. Request for Login/Password3. User Login/Password4 Request authentication (and authorization policies) from AAA server5. Portal Welcome Web Page6. Request Portal URL LinkAAA ServerArray SPClient7. Check if request is authorized8. Web Page Retrieved9. Secured, Rewritten Web PageWebServer Company Confidential
Page 12 of 28