VPN ±Ê¼Ç ÏÂÔØ±¾ÎÄ

¼ÓÃܺÍÈÏÖ¤·½°¸¡£IPSecÄÜΪIPv4/IPv6ÍøÂçÌṩÄܹ²Í¬²Ù×÷/ʹÓõġ¢¸ßÆ·Öʵġ¢»ùÓÚ¼ÓÃܵݲȫ»úÖÆ¡£

Ìṩ°üÀ¨´æÈ¡¿ØÖÆ¡¢ÎÞÁ¬½ÓÊý¾ÝµÄÍêÕûÐÔ¡¢Êý¾ÝÔ´ÈÏÖ¤¡¢·ÀÖ¹ÖØ·¢¹¥»÷¡¢»ùÓÚ¼ÓÃܵÄÊý¾Ý»úÃÜÐÔºÍÊÜÏÞÊý¾ÝÁ÷µÄ»úÃÜÐÔ·þÎñ¡£

2.SSLÓù«Ô¿¼ÓÃÜͨ¹ýSSLÁ¬½Ó´«ÊäµÄÊý¾ÝÀ´¹¤×÷¡£SSLÊÇÒ»Öָ߲㰲ȫЭÒ飬½¨Á¢ÔÚÓ¦ÓòãÉÏ¡£

SSL VPNʹÓÃSSLЭÒéºÍ´úÀíΪÖÕ¶ËÓû§ÌṩHrrP¡¢¿Í»§»ú/·þÎñÆ÷ºÍ¹²ÏíµÄÎļþ×ÊÔ´µÄ·ÃÎÊÈÏÖ¤ºÍ·ÃÎʰ²È«SSL VPN´«µÝÓû§²ãµÄÈÏÖ¤¡£È·±£Ö»ÓÐͨ¹ý°²È«²ßÂÔÈÏÖ¤µÄÓû§¿ÉÒÔ·ÃÎÊÖ¸¶¨µÄ×ÊÔ´¡£

3.MPLSÊÇÒ»¸ö¿ÉÒÔÔÚ¶àÖÖµÚ¶þ²ãýÖÊÉϽøÐбê¼Ç½»»»µÄÍøÂç¼¼Êõ¡£

²»ÂÛʲô¸ñʽµÄÊý¾Ý¾ù¿ÉÒÔµÚÈý²ãµÄ·ÓÉÔÚÍøÂçµÄ±ßԵʵʩ£¬¶øÔÚMPLSµÄÍøÂçºËÐIJÉÓõڶþ²ã½»»»£¬

Òò´Ë¿ÉÒÔÓÃÒ»¾ä»°¸ÅÀ¨MPLSµÄÌØµã£º¡°±ßԵ·ÓÉ£¬ºËÐĽ»»»¡±

IPsec»ù±¾¸ÅÄî Ô´ÓÚIPv6 ÍøÂç²ã¼ÓÃÜ

IPsec¿ò¼Ü

¼ÓÃÜ £ºDES¡¢3DES¡¢AES¡¢RSA

HASH £ºSHA-1¡¢md5 ·â×°·½Ê½£ºESP¡¢AH

ÈÏÖ¤·½Ê½£ºPre-key,Êý×ÖÖ¤Êé

| IP | IPSEC Header | TCP | FTP | Date | ----------------- | ¼ÓÃÜ Á½ÖÖÄ£ÐÍ

L2L/Remote Access Á½ÖÖģʽ

tunnel/Transport

Tunnel :ͨÐŵ㲻µÈÓÚ¼ÓÃܵã | NIP | ESP/AH | IP | DATA |

Transport :ͨÐŵã=¼ÓÃܵã | IP | ESP/AH | DATA |

L2L/Remote AccessÓÃTunnel·âװģʽ

Pc--PcºÍGRE over IPsecÓÃTransport·âװģʽ

SA£¨°²È«¹ØÁª£© ¹¹³ÉIPsecµÄ»ù´¡

SAÊÇÁ½¸öͨÐÅʵÌ徭ЭÉ̽¨Á¢ÆðÀ´µÄÒ»ÖÖЭ¶¨¡£ Ëü¾ö¶¨ÁËÓÃÀ´±£»¤Êý¾Ý°üµÄIPsec

ЭÒ飨ESP/AH£©¡¢×ªÂ뷽ʽ£¨¼ÓÃÜ/Hash£©¡¢ÃÜÔ¿¡¢ÃÜÔ¿ÓÐЧʱ¼ä

SADB£¨SAÊý¾Ý¿â£©

SAÊǵ¥ÏòµÄÓëЭÒéÏà¹ØµÄ

SPD£¨°²È«²ßÂÔÊý¾Ý¿â£© ¶ªÆú£¬Èƹý£¬Ó¦ÓÃ

IPsecµÄ×é³É²¿·Ö ESP£¨·â×°°²È«¸ºÔØ£© AH£¨ÈÏ֤ͷ²¿£© IKE£¨ÍøÂçÃÜÔ¿½»»»£© ESP

ЭÒéºÅ£º50

˽ÃÜÐÔ£¬Êý¾ÝÍêÕûÐÔ£¬Ô´ÈÏÖ¤£¬µÖÓùÖØ·Å¹¥»÷ | IP | ESP header | TCP | Data | ESP auth | ------------¼ÓÃÜ---- ---------ÑéÖ¤-------------

ESP°ü½á¹¹£¨tunnel mode£©

IP header

SPI--------------------------- sequence number | --IV | ¼Ó | IP header | ÈÏÖ¤ ÃÜ | TCP header | | Date | --Pad+pad length+next header---- Authentication data

Ã÷ÎÄ=SPI£¨ÔÚSADBÖÐÕÒµ½ÏàÓ¦²ßÂÔ£©+ÐòÁкţ¨·ÀÖØ·Å£© ESP auth=Hmac£¨96bit£©