¼ÓÃܺÍÈÏÖ¤·½°¸¡£IPSecÄÜΪIPv4/IPv6ÍøÂçÌṩÄܹ²Í¬²Ù×÷/ʹÓõġ¢¸ßÆ·Öʵġ¢»ùÓÚ¼ÓÃܵݲȫ»úÖÆ¡£
Ìṩ°üÀ¨´æÈ¡¿ØÖÆ¡¢ÎÞÁ¬½ÓÊý¾ÝµÄÍêÕûÐÔ¡¢Êý¾ÝÔ´ÈÏÖ¤¡¢·ÀÖ¹ÖØ·¢¹¥»÷¡¢»ùÓÚ¼ÓÃܵÄÊý¾Ý»úÃÜÐÔºÍÊÜÏÞÊý¾ÝÁ÷µÄ»úÃÜÐÔ·þÎñ¡£
2.SSLÓù«Ô¿¼ÓÃÜͨ¹ýSSLÁ¬½Ó´«ÊäµÄÊý¾ÝÀ´¹¤×÷¡£SSLÊÇÒ»Öָ߲㰲ȫÐÒ飬½¨Á¢ÔÚÓ¦ÓòãÉÏ¡£
SSL VPNʹÓÃSSLÐÒéºÍ´úÀíΪÖÕ¶ËÓû§ÌṩHrrP¡¢¿Í»§»ú/·þÎñÆ÷ºÍ¹²ÏíµÄÎļþ×ÊÔ´µÄ·ÃÎÊÈÏÖ¤ºÍ·ÃÎʰ²È«SSL VPN´«µÝÓû§²ãµÄÈÏÖ¤¡£È·±£Ö»ÓÐͨ¹ý°²È«²ßÂÔÈÏÖ¤µÄÓû§¿ÉÒÔ·ÃÎÊÖ¸¶¨µÄ×ÊÔ´¡£
3.MPLSÊÇÒ»¸ö¿ÉÒÔÔÚ¶àÖÖµÚ¶þ²ãýÖÊÉϽøÐбê¼Ç½»»»µÄÍøÂç¼¼Êõ¡£
²»ÂÛʲô¸ñʽµÄÊý¾Ý¾ù¿ÉÒÔµÚÈý²ãµÄ·ÓÉÔÚÍøÂçµÄ±ßԵʵʩ£¬¶øÔÚMPLSµÄÍøÂçºËÐIJÉÓõڶþ²ã½»»»£¬
Òò´Ë¿ÉÒÔÓÃÒ»¾ä»°¸ÅÀ¨MPLSµÄÌØµã£º¡°±ßԵ·ÓÉ£¬ºËÐĽ»»»¡±
IPsec»ù±¾¸ÅÄî Ô´ÓÚIPv6 ÍøÂç²ã¼ÓÃÜ
IPsec¿ò¼Ü
¼ÓÃÜ £ºDES¡¢3DES¡¢AES¡¢RSA
HASH £ºSHA-1¡¢md5 ·â×°·½Ê½£ºESP¡¢AH
ÈÏÖ¤·½Ê½£ºPre-key,Êý×ÖÖ¤Êé
| IP | IPSEC Header | TCP | FTP | Date | ----------------- | ¼ÓÃÜ Á½ÖÖÄ£ÐÍ
L2L/Remote Access Á½ÖÖģʽ
tunnel/Transport
Tunnel :ͨÐŵ㲻µÈÓÚ¼ÓÃܵã | NIP | ESP/AH | IP | DATA |
Transport :ͨÐŵã=¼ÓÃܵã | IP | ESP/AH | DATA |
L2L/Remote AccessÓÃTunnel·âװģʽ
Pc--PcºÍGRE over IPsecÓÃTransport·âװģʽ
SA£¨°²È«¹ØÁª£© ¹¹³ÉIPsecµÄ»ù´¡
SAÊÇÁ½¸öͨÐÅʵÌå¾ÐÉ̽¨Á¢ÆðÀ´µÄÒ»ÖÖж¨¡£ Ëü¾ö¶¨ÁËÓÃÀ´±£»¤Êý¾Ý°üµÄIPsec
ÐÒ飨ESP/AH£©¡¢×ªÂ뷽ʽ£¨¼ÓÃÜ/Hash£©¡¢ÃÜÔ¿¡¢ÃÜÔ¿ÓÐЧʱ¼ä
SADB£¨SAÊý¾Ý¿â£©
SAÊǵ¥ÏòµÄÓëÐÒéÏà¹ØµÄ
SPD£¨°²È«²ßÂÔÊý¾Ý¿â£© ¶ªÆú£¬Èƹý£¬Ó¦ÓÃ
IPsecµÄ×é³É²¿·Ö ESP£¨·â×°°²È«¸ºÔØ£© AH£¨ÈÏ֤ͷ²¿£© IKE£¨ÍøÂçÃÜÔ¿½»»»£© ESP
ÐÒéºÅ£º50
˽ÃÜÐÔ£¬Êý¾ÝÍêÕûÐÔ£¬Ô´ÈÏÖ¤£¬µÖÓùÖØ·Å¹¥»÷ | IP | ESP header | TCP | Data | ESP auth | ------------¼ÓÃÜ---- ---------ÑéÖ¤-------------
ESP°ü½á¹¹£¨tunnel mode£©
IP header
SPI--------------------------- sequence number | --IV | ¼Ó | IP header | ÈÏÖ¤ ÃÜ | TCP header | | Date | --Pad+pad length+next header---- Authentication data
Ã÷ÎÄ=SPI£¨ÔÚSADBÖÐÕÒµ½ÏàÓ¦²ßÂÔ£©+ÐòÁкţ¨·ÀÖØ·Å£© ESP auth=Hmac£¨96bit£©