¹«º£²Ê´¬¡¤6600(ÖйúÓÎ)¹Ù·½ÍøÕ¾

µã»÷ÏÂÔØ¡¶ÍòÕ×Ô°ÇøÒÔÌ«²Ê¹âÑо¿±¨¸æ¡·£¬½âËøÍòÕ×Ô°ÇøÍøÂ罨ÉèÖ¸ÄÏ
Á¢¼´ÏÂÔØ
ÎÞ¸Ð×¼Èë ÈËÎïͳ¹Ü Ø­ RG-SAM+5.X ÐÂÒ»´ú¸ßУAIÈÏ֤ƽ̨·¢²¼
Ô¤Ô¼Ö±²¥
²úÆ·
< ·µ»ØÖ÷²Ëµ¥
²úÆ·ÖÐÐÄ
²úÆ·
ºÏ×÷»ï°é
·µ»ØÖ÷²Ëµ¥
Ñ¡ÔñÇøÓò/ÓïÑÔ

Õ¾µã¼äIPSec VPNÍøÂç¼¼ÊõÉî¶È½âÎö

¡¾IPSec VPN¡¿±¾ÎÄÊ×ÏÈͨ¹ýÊáÀíIPSec VPNÖи÷¼¼ÊõµÄÓÃ;¼°Ö®¼äµÄ¹ØÁª¹ØÏµ°ïÖú´ó¼ÒÀí½â¼¼ÊõÔ­Àí£¬Æä´ÎΪ´ó¼Ò½éÉÜIPSec VPNµÄһЩ¸ß¼¶¹¦ÄÜ£¬×îºóΪ´ó¼Ò·ÖÏíµäÐÍʵ¼ù³¡¾°ºÍ¹ÊÕÏÅŲ鷽·¨¡£

  • ·¢²¼Ê±¼ä£º2020-07-01

  • µã»÷Á¿£º

  • µãÔÞ£º

·ÖÏíÖÁ

ÎÒÏëÆÀÂÛ

±¾ÎÄ×÷ÕߣºÌï˼Ñî 

¹«º£²Ê´¬¡¤6600ÍøÂç¼¼Êõ·þÎñ²¿»¥ÁªÍø·þÎñÖÐÐÄ

ǰÑÔ

ÔÚÉÏһƪ¡¶VPN¼¼Êõdz̸֮ÈçºÎ²¿ÊðÔ¶³Ì°ì¹«ÍøÂç¡·ÖУ¬×÷ÕßΪ´ó¼Ò·ÖÏíÁ˶˵½Õ¾µãVPN¼¼Êõ£¬¸Ã¼¼ÊõÖ÷ҪʹÓÃÔÚÔ¶³Ì°ì¹«ÈËÔ±ºÍÆóÒµÍøÂ绥ͨ³¡¾°£¬¶øÕ¾µãµ½Õ¾µãVPN¼¼Êõ³£ÓÃÓÚ×ܲ¿Óë·ÖÖ§Ö®¼äµÄÍøÂ绥ͨ£¬Í¨¹ýÀûÓÃ×éÖ¯ÒÑÓеĻ¥ÁªÍø³ö¿Ú£¬Ê¹ÓÃVPN¼¼ÊõÐéÄâ³öÒ»Ìõ“רÏß”£¬½«ÆóÒµµÄ·ÖÖ§»ú¹¹ºÍ×ܲ¿Á¬½ÓÆðÀ´£¬×é³ÉÒ»¸ö´óµÄ¾ÖÓòÍø¡£Õ¾µãµ½Õ¾µãVPNÖ÷Òª°üÀ¨IPSec VPN¡¢L2TP VPN¡¢L2TP over IPSec VPN¡¢GRE VPN¡¢GRE over IPSec VPN¡¢SSL VPNµÈ¡£IPSec VPN¼¼ÊõÒòÆä¾ßÓа²È«ÐԸߡ¢³É±¾µÍ¡¢²¿ÊðÁé»î¡¢À©Õ¹ÐԺõÈÓŵ㣬ÒѳÉΪÆóÒµÕ¾µã¼äVPN²¿ÊðµÄµÚ Ò»¼¼ÊõÑ¡Ôñ¡£

IPSec VPN²»ÊÇÒ»¸öµ¥¶ÀµÄЭÒ飬¶øÊÇÓÉÒ»×éЭÒé×é³É£¬ÒòÆä°üº¬µÄ¼¼Êõ¶à¡¢¼¼Êõ¼ä¹ØÁª¹ØÏµ¶à£¬ºÜ¶àÅóÓÑÎÞ·¨°ÑIPSec VPN¼¼ÊõÀí½â͸¡£±¾ÎÄÊ×ÏÈͨ¹ýÊáÀíIPSec VPNÖи÷¼¼ÊõµÄÓÃ;¼°Ö®¼äµÄ¹ØÁª¹ØÏµ°ïÖú´ó¼ÒÀí½â¼¼ÊõÔ­Àí£¬Æä´ÎΪ´ó¼Ò½éÉÜIPSec VPNµÄһЩ¸ß¼¶¹¦ÄÜ£¬×îºóΪ´ó¼Ò·ÖÏíµäÐÍʵ¼ù³¡¾°ºÍ¹ÊÕÏÅŲ鷽·¨¡£Ï£Íû±¾ÎÄÄܹ»°ïÖú¸÷λ¶ÁÕß°ÑIPSec VPN¼¼Êõѧ͸¡¢ÓÃÃ÷°×£¬ÄÍÐĶÁÍêÕâÆªÎÄÕÂÏàÐÅÄã»áÓв»Ò»ÑùµÄÊÕ»ñ¡£

¹«º£²Ê´¬¡¤6600Ö§³ÖIPSec VPNµÄÉ豸ÓкܶàÖÖ£¬²»Í¬É豸¶Ô¸÷IPSec VPN¼¼ÊõµÄÖ§³ÖÇé¿öÂÔÓвîÒ죬±¾ÎÄÒÔ¹«º£²Ê´¬¡¤6600Íø¹ØÉ豸ΪÀý¸ø´ó¼Ò½²½â£¬Èç¶ÁÕßʹÓÃÆäËûÉ豸»¶Ó­ÁªÏµ¹«º£²Ê´¬¡¤6600¹¤³Ìʦ»òµ½¹«º£²Ê´¬¡¤6600¹ÙÍø²éѯ£¬¸Ðл¡£

 

ͼ1£º³£¼ûÆóÒµVPN½ÓÈëÍØÆËÄ£ÐÍ

IPSec VPN»ù´¡²ÎÊý

IPSecÖÐͨÐÅË«·½½¨Á¢µÄÁ¬½Ó½Ð×ö°²È«¹ØÁª£¨IPSec SA£©£¬Ë«·½Í¨¹ý²ÎÊýЭÉÌÍê³ÉIPSec SA½¨Á¢ºó£¬Í¨¹ýIPSec SA´«Êä¼ÓÃܵÄÊý¾Ý±¨ÎĽøÐÐͨÐÅ¡£ËùÒÔÁ½¸ö¶ÔµÈÌå¼äÒªÏëͨ¹ýIPSec VPNͨÐÅ£¬Ê×ÏÈÒª½¨Á¢IPSec SA¡£ÔÚ½øÐÐIPSec SA½¨Á¢Ê±¶ÔµÈÌå¼äÒª½øÐÐIPSec SA²ÎÊýЭÉÌ£¬Á½¶Ë²ÎÊýÏàͬʱ²Å»á½¨Á¢³É¹¦¡£

 

ͼ2£ºIPSec VPN»ù´¡²ÎÊý

IPSec SAÉú³É·½Ê½

ÊÖ¶¯Ö¸¶¨Éú³ÉIPSec SA

¶ÔµÈÌåͨ¹ýÊÖ¶¯Ö¸¶¨IPSec SAЭÉ̲ÎÊýÉú³ÉIPSec SA£¬IPSec SA½¨Á¢ºóûÓÐÉú´æÖÜÆÚÏÞÖÆ£¬ÓÀ²»¹ýÆÚ£¬³ý·ÇÊÖ¹¤É¾³ý£¬Òò´Ë´æÔÚ°²È«Òþ»¼¡£Ò»°ãÍÆ¼öÔÚ¶ÔµÈÌåÊýÁ¿½ÏÉÙÇÒÎÞ·¨Í¨¹ýIKEЭÉ̽¨Á¢IPSec SA³¡¾°ÏÂʹÓá£

IKEЭÉÌÉú³ÉIPSec SA

IKEÓÃÓÚ¶¯Ì¬½¨Á¢²¢ÊµÊ±Î¬»¤IPSec SA¡£IKEͨ¹ýÁ½¸ö½×¶ÎÀ´½¨Á¢IPSec SA£¬µÚÒ»½×¶ÎÊ×ÏÈҪЭÉ̽¨Á¢IKE SA£¬µÚ¶þ½×¶Îͨ¹ýIKE SAЭÉ̽¨Á¢IPSec SA¡£

IKEЭÉÌÉú³ÉIPSec SA±ÈÊÖ¶¯Ö¸¶¨Éú³ÉIPSec SA´æÔÚÒÔÏÂÓÅÊÆ£º

  1. ÊÊÓó¡¾°·á¸»£ºÊÖ¶¯Ö¸¶¨·½Ê½±ØÐë¶ÔµÈÌåÁ½¶Ë¶¼Óй̶¨µÄ¹«ÍøIPµØÖ·£¬ÈçÒ»¶Ë¶ÔµÈÌå¹«ÍøIPµØÖ·²»¹Ì¶¨±ØÐëʹÓÃIKEЭÉÌ·½Ê½£»
  2. ½µµÍÅäÖø´ÔÓ¶È£ºÊÖ¶¯Ö¸¶¨·½Ê½ÐèÒªÊÖ¶¯ÅäÖÃSPI¡¢ÃÜÔ¿µÈÐÅÏ¢£¬ÔÚ¶ÔµÈÌå½Ï¶àµÄ³¡¾°ÅäÖÃÁ¿½Ï´ó¶ø²»±ãÓÚά»¤£¬IKEЭÉÌ·½Ê½»áͨ¹ýIKE SAÀ´Éú³ÉºÍά»¤ÕâЩÐÅÏ¢£¬½µµÍÅäÖø´ÔӶȼ°Î¬»¤³É±¾£»
  3. Ìá¸ß°²È«ÐÔ£ºÊÖ¶¯Ö¸¶¨·½Ê½½¨Á¢µÄIPSec SAÃÜÔ¿ÊǾ²Ì¬µÄ£¬½¨Á¢ºóÓÀ²»¹ýÆÚ£¬IKEЭÉÌ·½Ê½»áͨ¹ýIKE SAÉú³ÉÃÜÔ¿£¬²¢ÇÒÉúÃüÖÜÆÚµ½ÆÚºó½øÐÐÀÏ»¯ÖØÐÂÉú³É£¬Ìá¸ßÁ˰²È«ÐÔ¡£

СÌáʾ£ºIKEЭÒéĿǰÓÐÁ½¸ö°æ±¾IKEv1ÓëIKEv2£¬IKEv1Ŀǰ½ÏΪ³£Óã¬IKEv2ÓëIKEv1ÅäÖÃ˼·Ïàͬ£¬µ«Ð­É̹ý³ÌÓëIKEv1ÓÐËùÇø±ð£¬±¾ÎIJ»½øÐн²½â£¬±¾ÎÄÖгöÏÖµÄIKEЭÒé¾ù´ú±íIKEv1¡£

IKE SAЭÉÌģʽ

ÔÚIKEµÚÒ»½×¶ÎÓÐÁ½ÖÖЭÉÌģʽ¿ÉЭÉ̽¨Á¢IKE SA£¬Ö÷ģʽ»òÕßÒ°Âùģʽ¡£Ö÷ģʽʹÓÃ6¸ö±¨ÎÄÍê³ÉIKE SA½¨Á¢£¬¶øÒ°ÂùģʽʹÓÃ3¸ö±¨ÎÄÍê³ÉIKE SA½¨Á¢£¬ÓëÖ÷ģʽÏà±ÈÒ°Âùģʽ¼õÉÙ½»»¥±¨ÎÄÊýÁ¿´Ó¶ø¼Ó¿ìÁËЭÉÌËÙ¶È£¬µ«Òò¶ÔÉí·ÝÐÅÏ¢ºÍÈÏÖ¤ÐÅÏ¢²ÉÓÃÃ÷ÎĽ»»¥£¬Ã»ÓмÓÃܱ£»¤£¬Òò´Ë²»°²È«£¬×÷Õß²»ÍƼöʹÓá£

Ò°ÂùģʽÔçÆÚÉè¼ÆÖ÷ҪΪ½â¾öÒ»¶Ë¶ÔµÈÌå¹«ÍøIPµØÖ·²»¹Ì¶¨»òûÓй«ÍøIPµØÖ·µÄ³¡¾°ÏÂÖ÷ģʽÎÞ·¨Ð­É̽¨Á¢µÄÎÊÌ⣬Ŀǰ¸ÃÎÊÌâ¿ÉÒÔͨ¹ý“¶¯Ì¬ËíµÀ”µÄ·½·¨¸üºÃµØ½â¾ö£¬ËùÒÔÍÆ¼öʹÓÃÖ÷ģʽ¡£Ò°Âùģʽ½öÔÚ¹«º£²Ê´¬¡¤6600É豸Óë·Ç¹«º£²Ê´¬¡¤6600É豸½¨Á¢IPSecʹÓÃÖ÷ģʽÎÞ·¨½¨Á¢³É¹¦ÏÂʹÓã¬ÆäËû³¡¾°Ï²»ÍƼöʹÓá£

СÌáʾ£ºÖ÷ģʽºÍÒ°Âùģʽ±¨ÎĽ»»¥ÏêϸÁ÷³Ì²Î¿¼±¾ÎÄ¡¶IKE±¨ÎĽ»»¥ÖªÊ¶µã»Ø¹Ë¡·Ð¡½Ú¡£

IKE SA¼ÓÃÜ·½Ê½

IKE SAʹÓöԳƼÓÃÜËã·¨¶ÔÊý¾Ý½øÐмÓÃܺͽâÃÜ£¬±£Ö¤Êý¾ÝµÄ°²È«ÐÔ¡£³£ÓõĶԳƼÓÃÜËã·¨ÓÐDES¡¢3DES¡¢AESµÈ£¬ÕâÈý¸ö¼ÓÃÜËã·¨µÄ°²È«ÐÔÓɸߵ½µÍÒÀ´ÎÊÇ£ºAES¡¢3DES¡¢DES£¬°²È«ÐԸߵļÓÃÜË㷨ʵÏÖ»úÖÆ¸´ÔÓ£¬ÔËËãËÙ¶ÈÂý¡£


ͼ3£ºIKE SA³£ÓõĶԳƼÓÃÜËã·¨

IKE SAÑéÖ¤·½Ê½

IKE SAʹÓÃÑéÖ¤Ëã·¨¶Ô±¨ÎÄÍêÕûÐÔ¼°À´Ô´ºÏ·¨ÐÔ½øÐÐÑéÖ¤£¬³£ÓõÄÑéÖ¤·½Ê½ÓÐMD5-HMAC¡¢SHA1-HMACµÈ£¬ÊÇHASHËã·¨ºÍHMACÁ½ÖÖ¼¼ÊõµÄ½áºÏ¡£

HASHË㷨ʵÏÖ¶Ô±¨ÎĽøÐÐÍêÕûÐÔУÑ飬³£¼ûµÄHASHËã·¨ÓÐMD5¡¢SHA1µÈ£¬MD5Ëã·¨µÄ¼ÆËãËٶȱÈSHA1Ëã·¨¿ì£¬¶øSHA1Ëã·¨µÄ°²È«Ç¿¶È±ÈMD5Ëã·¨¸ß¡£


ͼ4£ºIKE SA³£ÓõÄHASHËã·¨

 

HMAC(Hash-based Message Authentication Code)ÊÇÒ»ÖÖ»ùÓÚHASHËã·¨ºÍÃÜÔ¿½øÐÐÏûÏ¢ÈÏÖ¤µÄ·½·¨£¬ÊµÏÖ¶Ô±¨ÎÄÀ´Ô´µÄºÏ·¨ÐÔ½øÐÐÑéÖ¤£¬¿ÉÒÔÓëÈκÎHASHËã·¨À¦°óʹÓá£

IKE SAÃÜÔ¿Éú³É·½Ê½

DH£¨Diffie-Hellman£©ÊÇÒ»ÖַǶԳÆÃÜÔ¿Ëã·¨£¬Ë«·½¿Éͨ¹ý½ö½»»»Ò»Ð©Êý¾Ý£¬¼´¿É¼ÆËã³öË«·½µÄÃÜÔ¿£¬²¢ÇÒµÚÈý·½²¶»ñÁËÆäÖеÄÊý¾ÝÒ²ÎÞ·¨¼ÆËãµÃ³öÃÜÔ¿¡£DH²úÉúµÄÃÜÔ¿ÓÃÓÚÊý¾Ý±¨ÎļÓÃܼ°HMAC¼ÆËãÖС£¶ÔµÈÌåÁ½¶ËDH×鳤¶ÈÐèÖ¸¶¨ÎªÏàͬ£¬³£ÓõÄDH×鳤¶ÈÓÐ768bit£¨DH1£©¡¢1024bit£¨DH2£©¡¢1536bit£¨DH5£©¡£

IKE SAÈÏÖ¤·½Ê½

ÔÚIKE¶ÔµÈÌåÖ®¼äÔÚ½øÐÐÉí·ÝÈÏ֤ʱ֧³Öͨ¹ýÔ¤¹²ÏíÃÜÔ¿ÈÏÖ¤ºÍÊý×ÖÖ¤ÊéÈÏÖ¤Á½ÖÖ·½Ê½À´È·È϶Է½Éí·ÝµÄºÏ·¨ÐÔ¡£Ô¤¹²ÏíÃÜÔ¿ÈÏÖ¤ÅäÖñȽϼòµ¥£¬ÊÇĿǰ±È½Ï³£ÓõÄÈÏÖ¤·½Ê½¡£Êý×ÖÖ¤ÊéÈÏÖ¤Ïà¶Ô¸´ÔÓµ«°²È«ÐԽϸߣ¬¶Ô°²È«ÐÔÓнϸßÒªÇóµÄ³¡¾°½¨ÒéʹÓÃÊý×ÖÖ¤ÊéÈÏÖ¤¡£

IKE SAÉí·Ý±êʶ

ÔÚIKE SAЭÉÌÖжԵÈÌåË«·½ÐèҪʹÓÃÏàͬÀàÐ͵ÄÉí·Ý±êʶ£¬³£ÓõÄÉí·Ý±êʶÀàÐÍÓÐ4ÖÖ£¬IPµØÖ·¡¢FQDN¡¢USER-FQDN¡¢Ö¤ÊéDN¡£Êý×ÖÖ¤ÊéÈÏ֤ͨ³£²ÉÓÃÖ¤ÊéDN×÷Ϊ±¾µØÉí·Ý±êʶ¡£Ô¤¹²ÏíÃÜÔ¿ÈÏ֤ĬÈϲÉÓÃIPµØÖ·×÷Ϊ±¾µØÉí·Ý±êʶ£¬Í¨³£Ê¹ÓòÉÓÃIPµØÖ·×÷Ϊ±¾µØÉí·Ý±êʶ¼´¿É£¬ÈôÓöµ½ÒÔÏÂÁ½ÖÖ³¡¾°ÍƼöÊÖ¶¯ÐÞ¸ÄʹÓÃFQDN»òUSER-FQDN£º

  1. Èç¹û¶ÔµÈÌåµÄIPµØÖ·ÎªÓòÃûÐÎʽ£¬Ôò±ØÐëʹÓÃFQDN»òUSER-FQDN£»
  2. ¶ÔµÈÌå½Ï¶àµÄ³¡¾°Ï£¬½¨Òé²ÉÓÃFQDN»òUSER-FQDN£¬±ãÓÚÇø·Öÿ¸ö¶ÔµÈÌå¶ÔÓ¦ÊÇÄĸö·ÖÖ§¡£

СÌáʾ£ºÉí·Ý±êʶÀàÐÍÓëЭÉÌģʽÎ޹أ¬ÈκÎÉí·Ý±êʶÔÚÖ÷ģʽ»òÒ°ÂùģʽϾù¿ÉʹÓ㬱ÈÈçÖ÷ģʽʹÓÃFQDN×÷ΪÉí·Ý±êʶ»òÒ°ÂùģʽʹÓÃIP×÷ΪÉí·Ý±êʶ¶¼¿ÉÕý³£Íê³ÉIKE SAЭÉÌ£¬Ö»Òª¶ÔµÈÌåÁ½¶ËʹÓÃÏàͬÀàÐÍÉí·Ý±êʶ¼´¿É¡£

IKE SAÉúÃüÖÜÆÚ

ÓÉÓÚIPSec SAЭÉÌÊǽ¨Á¢ÔÚIKE SA»ù´¡ÉϵÄ£¬Òò´ËΪ½ÚʡЭÉÌIPSec SAµÄʱ¼ä£¬Ò»°ãIKE SAÉúÃüÖÜÆÚ£¨60Ãëµ½86400Ã룬ȱʡ86400Ã룩±ÈIPSec SAÉúÃüÖÜÆÚÉèÖõij¤¡£µ±ÔÚ½øÐÐIKE SAЭÉÌʱ£¬Á½¶Ë¶ÔµÈÌåÉèÖõÄIKE SAÉúÃüÖÜÆÚ²»Í¬²»»áÔì³ÉIKE SAЭÉÌʧ°Ü£¬¶øÊ¹Ó÷¢ËÍ·½ÉèÖõÄIKE SAÉúÃüÖÜÆÚ¡£

IPSec SA°²È«Ð­Òé

AHºÍESPÊÇIPSecµÄÁ½ÖÖ°²È«Ð­Ò飬ÓÃÓÚʵÏÖIPSecÔÚÉí·ÝÈÏÖ¤ºÍÊý¾Ý¼ÓÃܵݲȫ»úÖÆ¡£

  1. AHЭÒ飨Authentication Header£¬Ð­ÒéºÅ51£©£¬Ö÷ÒªÌṩÊý¾ÝÍêÕûÐÔÈ·ÈÏ¡¢Êý¾ÝÀ´Ô´È·ÈÏ¡¢·ÀÖØ·ÅµÈ°²È«ÌØÐÔ¡£AHͨ³£Ê¹ÓÃMD5-HMAC¡¢SHA-HMACµÈÑéÖ¤Ë㷨ʵÏÖÊý¾ÝÍêÕûÐÔ£»
  2. ESPЭÒ飨Encapsulating Security Payload£¬Ð­ÒéºÅ50£©£¬Ö÷ÒªÌṩÊý¾ÝÍêÕûÐÔÈ·ÈÏ¡¢Êý¾Ý¼ÓÃÜ¡¢Êý¾ÝÀ´Ô´È·ÈÏ¡¢·ÀÖØ·ÅµÈ°²È«ÌØÐÔ¡£ESPͨ³£Ê¹ÓÃDES¡¢3DES¡¢AESµÈ¼ÓÃÜË㷨ʵÏÖÊý¾Ý¼ÓÃÜ£¬Ê¹ÓÃMD5-HMAC¡¢SHA-HMACµÈÑéÖ¤Ë㷨ʵÏÖÊý¾ÝÍêÕûÐÔ¡£ESPЭÒéÏà±ÈAHЭÒé¶àÁËÖ§³ÖÊý¾Ý¼ÓÃÜ¡¢Ö§³ÖNAT´©Ô½£¨NAT-T£©ÕâÁ½´óÓÅÊÆ£¬ÊÇĿǰIPSec VPN½ÏΪ³£Óõİ²È«Ð­Òé¡£

IPSec SA·âװģʽ

·âװģʽÓÃÓÚÖ¸¶¨°²È«Ð­ÒéµÄ·âװλÖã¬Óд«ÊäģʽºÍËíµÀģʽÁ½ÖÖ£º

 

´«Ê䣨Transport£©Ä£Ê½Ï£¬AHÍ·»òESPÍ·²åÈëIPÍ·ºÍ´«Êä²ãЭÒéÖ®¼ä£¬²»¸Ä±äԭʼ±¨ÎÄÍ·£¬IPSecËíµÀµÄÔ´ºÍÄ¿µÄµØÖ·¾ÍÊÇ×îÖÕͨÐÅË«·½µÄÔ´ºÍÄ¿µÄµØÖ·£¬ËùÒÔÖ»Äܱ£»¤Á½¸öIPSec¶ÔµÈÌåÖ®¼äÏ໥ͨÐÅ¡£Ò»°ã³£ÓÃÔÚʹÓÃGRE over IPSec»òL2TP over IPSecЭÒéµÄ³¡¾°ÖУ¬Ê¹ÓÃIPSecËíµÀ±£»¤GRE»òL2TP¶ÔµÈÌ壻

ËíµÀ£¨Tunnel£©Ä£Ê½Ï£¬AHÍ·»òESPÍ·²åÔÚԭʼIPͷ֮ǰ£¬²¢ÇÒÐÂÉú³ÉÒ»¸öIPÍ··ÅÔÚESPÍ·»òAHͷ֮ǰ£¬ËùÒÔ¿ÉÒÔ±£»¤Á½¸öIPSec¶ÔµÈÌå±³ºóÁ½¸öÍøÂçÖ®¼ä½øÐÐͨÐÅ¡£Ò»°ã³£ÓÃÔÚÕ¾µã¼äÍøÂ绥ͨµÄ³¡¾°£¬Êǽϳ£Óõķâװģʽ¡£

 

ͼ5£ºAHЭÒéÁ½ÖÖ·âװģʽϱ¨ÎÄ·â×°

ͼ6£ºESPЭÒéÁ½ÖÖ·âװģʽϱ¨ÎÄ·â×°

IPSec SA¼ÓÃÜ·½Ê½

IPSec SAÖ§³ÖʹÓõļÓÃÜ·½Ê½ÓëIKE SAÏàͬ£¬²Î¿¼±¾ÎÄ¡¶IKE SA¼ÓÃÜ·½Ê½¡·Ð¡½Ú¡£

IPSec SAÑéÖ¤·½Ê½

IPSec SAÖ§³ÖʹÓõÄÑéÖ¤·½Ê½ÓëIKE SAÏàͬ£¬²Î¿¼±¾ÎÄ¡¶IKE SAÑéÖ¤·½Ê½¡·Ð¡½Ú¡£

IPSec SAÉúÃüÖÜÆÚ

ΪÁËÈ·±£°²È«£¬IPSec SA½«ÔÚ¾­¹ýÒ»¶¨Ê±¼ä£¨0»òÕß120Ãëµ½86400Ã룬ȱʡ3600Ã룩»ò´ïµ½Ò»¶¨Í¨ÐÅÁ¿£¨0»ò2560KBµ½536870912KB£¬È±Ê¡4608000KB£©Ö®ºó³¬Ê±£¬ÖØÐÂЭÉÌ£¬²¢Ê¹ÓÃеÄÃÜÔ¿¡£ÐÂIPSec SAÔÚÉúÃüÖÜÆÚ³¬Ê±Ç°30Ã룬»ò¾­ÓÉÕâÌõËíµÀµÄÊý¾ÝͨÐÅÁ¿¾àÉúÃüÖÜÆÚ»¹ÓÐ256KBʱ¿ªÊ¼½øÐÐЭÉÌ£¨¸ù¾ÝÄĸöÏÈ·¢Éú£©¡£

µ±ÔÚ½øÐÐIPSec SAЭÉÌʱ£¬Á½¶Ë¶ÔµÈÌåÉèÖõÄIPSec SAÉúÃüÖÜÆÚ²»Í¬²»»áÔì³ÉIPSec SAЭÉÌʧ°Ü£¬¶øÊ¹Ó÷¢Æð·½ÉèÖõÄIPSec SAÉúÃüÖÜÆÚ¡£

IPSec VPN¸ß¼¶¹¦ÄÜ

 

ͼ7£ºIPSec VPN¸ß¼¶¹¦ÄÜ

IPSecËíµÀ×Ô¶¯½¨Á¢£¨Set Autoup£©

ÔÚĬÈÏÇé¿öÏÂIPSec VPNÅäÖÃÍêºó£¬IPSecËíµÀÊÇÓÉÊý¾ÝÁ÷Á¿´¥·¢ºóÔÙЭÉ̽¨Á¢µÄ¡£ÅäÖÃIPSecËíµÀ×Ô¶¯½¨Á¢£¨Set Autoup£©¹¦Äܺ󣬲»¹ÜÊÇ·ñÓÐÊý¾ÝÁ÷Á¿´¥·¢£¬Ö»ÒªÍê³ÉIPSec VPNÅäÖúó£¬É豸»á×ÔÐд¥·¢IPSecËíµÀ½¨Á¢¡£

IPSecÁ´Â·Ì½²â£¨DPD/Track£©

DPD̽²â

ÔÚĬÈÏÇé¿öÏÂÁ½¶ËÉ豸½¨Á¢IPSecËíµÀºó£¬µ±Ò»¶ËÉ豸³öÏÖÎÊÌâºóÁíÒ»¶ËÊÇÎÞ¸ÐÖªµÄ£¬ÁíÒ»¶ËÉ豸»á¼ÌÐøÍ¨¹ýIPSecËíµÀ·¢ËÍÊý¾Ý¸ø¹ÊÕÏÉ豸µ¼ÖÂÊý¾ÝͨÐÅÖжϡ£´ËʱÐèÒªµÈ´ýIPSecËíµÀ³¬Ê±ºó¹ÊÕÏIPSecËíµÀ²Å»áÖжϣ¨IPSecËíµÀĬÈϳ¬Ê±Ê±¼äΪһСʱ£©¡£

DPD̽²âÊÇͨ¹ý·¢ËÍIKE±¨ÎÄÈ·È϶ԶËÉ豸IKE SA״̬ÊÇ·ñÕý³£µÄÒ»ÖÖ̽²â»úÖÆ£¬µ±Ì½²âµ½¶Ô¶ËIKE״̬Ò쳣ʱ£¬»áÇå³ý¶ÔÓ¦µÄIKE SAºÍIPSec SA¡£

DPD̽²âÓÐÁ½ÖÖ¹¤×÷ģʽ£º

  1. °´Ðè̽²âģʽ£¨On-demand£©£¬ÔÚ³¬¹ýÅäÖõÄ̽²âʱ¼äÇÒµ±ÓÐÊý¾Ý±¨ÎÄ·¢ËÍʱ£¬É豸»á·¢ËÍDPDÏûϢ̽²â¶Ô¶ËÉ豸ÊÇ·ñÕý³££¬µ±·¢ËÍ5´ÎDPDÐÅÏ¢¶¼Ã»ÓÐÊÕµ½¶Ô¶ËÉ豸»Ø°ü»áÈÏΪ¶Ô¶ËIKE SA״̬Òì³££»
  2. ÖÜÆÚ̽²âģʽ£¨Periodic£©£¬É豸»á¸ù¾ÝÅäÖõÄ̽²âʱ¼äÖÜÆÚÐÔÖ÷¶¯·¢ËÍ DPD ÏûϢ̽²â¶Ô¶ËÉ豸ÊÇ·ñÕý³££¬µ±·¢ËÍ5´ÎDPDÐÅÏ¢¶¼Ã»ÓÐÊÕµ½¶Ô¶ËÉ豸»Ø°ü»áÈÏΪ¶Ô¶ËIKE SA״̬Òì³£¡£

×ÛÉϰ´Ðè̽²âģʽ±ÈÖÜÆÚ̽²âģʽ»á·¢Ë͸üÉÙµÄDPDÐÅÏ¢Ö»ÔÚÊý¾Ý±¨ÎÄ·¢ËÍǰ¼ì²â£¬½ÚÔ¼É豸×ÊÔ´¼°ÍøÂç´ø¿í×ÊÔ´£¬µ«Ì½²âµ½¶Ô¶ËÉ豸¹ÊÕϵÄʱ¼ä»á±ÈÖÜÆÚ̽²âģʽ³¤£¬¶ÁÕ߸ù¾Ý×ÔÉíÒµÎñÐèÇóʹÓúÏÊÊģʽ½øÐÐDPD̽²â¼´¿É¡£

Track̽²â

DPD̽²âͨ¹ý½»»¥IKE±¨ÎÄ¿ÉÒÔ̽²âµ½¶Ô¶ËÉ豸IKE SA״̬ÊÇ·ñÕý³££¬¶ÔÓÚIKE SA״̬Õý³£¶øIPSec SAÒì³£µÄÇé¿öDPD̽²â¾ÍÎÞÄÜΪÁ¦ÁË£¬ÕâÖÖÇé¿öͬÑù»áµ¼ÖÂIPSecÒµÎñÖжÏ¡£Track̽²âͨ¹ý¶¨ÆÚ·¢ËÍICMP»òUDP±¨ÎÄ̽²âIPSecʵ¼ÊÒµÎñÊÇ·ñÕý³££¬µ±Track̽²âµ½IPSecÒµÎñ²»Í¨Ê±»áÇå³ý¶ÔÓ¦µÄIPSec SA½øÐÐÖØÐÂЭÉÌ¡£Ò»°ã½¨ÒéͬʱÅäÖÃDPD̽²âºÍTrack̽²â¡£

NAT´©Ô½£¨NAT-T£©

É豸ĬÈÏ¿ªÆôNAT´©Ô½£¨NAT-T£©¹¦ÄÜ£¬ÓÃÓÚ½â¾öµ±½¨Á¢IPSec VPNµÄÁ½Ì¨É豸¼ä´æÔÚNATÉ豸ESP±¨ÎÄÎÞ·¨Í¨¹ýµÄÎÊÌâ¡£ESP±¨Í··â×°ÔÚIP²ãÖ®ÉÏIPЭÒéºÅ50ËùÒÔÎÞ·¨Í¨¹ýNATÉ豸, NAT-Tͨ¹ýÔÚESP±¨ÎÄÖ®ÉÏ·â×°4500¶Ë¿ÚµÄUDP±¨Í·½â¾ö¸ÃÎÊÌâ¡£

 

ͼ8£ºNAT-TÔÚESP±¨ÎÄÖ®ÉÏ·â×°4500¶Ë¿ÚµÄUDP±¨Í·

 

ÔÚIKEЭÉ̵ĵÚÒ»½×¶Î£¨Ö÷ģʽµÚ1¡¢2¸ö±¨ÎÄ¡¢Ò°ÂùģʽµÚ1¸ö±¨ÎÄ£©Ö§³ÖNAT-TµÄÉ豸ÔÚ·¢ËÍIKE±¨ÎÄÖлáЯ´øÒ»¸ö¼ì²âNAT-TÄÜÁ¦µÄVendor IDµÄÔØºÉ£¬µ±Á½¶ËÉ豸¶¼Ð¯´øÕâ¸ö×Ö¶Î¾Í»á½øÐÐNAT-TЭÉÌ¡£µ±¼ì²âË«·½¶¼Ö§³ÖNAT-TËæºó£¨Ö÷ģʽµÚ3¡¢4¸ö±¨ÎÄ¡¢Ò°ÂùģʽµÚ2¸ö±¨ÎÄ£©»áЯ´øÒ»¸öNAT-DµÄÔØºÉ£¬NAT-DÔØºÉÖаüº¬×Ô¼ºIPµØÖ·ºÍ¶Ë¿ÚµÄHASHÖµ£¬¶Ô¶ËÉ豸ÊÕµ½Õâ¸öÖµºó»áÓëÊÕµ½µÄʵ¼ÊIPµØÖ·ºÍ¶Ë¿ÚµÄHashÖµ×ö¶Ô±È£¬Èç¹ûÏàͬ˵Ã÷Öмäδ¾­¹ýNATÉ豸£¬·ñÔò˵Ã÷Öм侭¹ýNATÉ豸¡£Èç¹ûNAT-T¼ì²âµ½Öм侭¹ýNATÉ豸£¬É豸»áÔÚÏÂÒ»¸ö±¨ÎÄ£¨Ö÷ģʽµÚ5¡¢6±¨ÎÄ¡¢Ò°ÂùģʽµÚ3¸ö±¨ÎÄ£©¿ªÊ¼²åÈëÒ»¸ö4500¶Ë¿ÚµÄUDP±¨Í·£¬ÖÁ´ËNAT-T¹¤×÷½áÊø¡£

 

¶¯Ì¬ËíµÀ£¨Crypto Dynamic-map£©

Ò»°ãÇé¿öÏ£¬Á½¶ËÉ豸¶¼Óй«ÍøIPµØÖ·£¬ÅäÖÃʱÁ½¶ËʹÓþ²Ì¬ËíµÀµÄ·½Ê½Ï໥ָ¶¨¶Ô¶Ë¹«ÍøIPµØÖ·½øÐÐIPSecËíµÀ½¨Á¢¡£Êµ¼ÊÖÐÒ²»áÓöµ½Ò»¶ËÓй«ÍøIPµØÖ·¶øÁíÒ»¶ËûÓй̶¨¹«ÍøIPµØÖ·»òÕßûÓй«ÍøIPµØÖ·µÄÇé¿ö£¬ÕâÖÖÇé¿öÁ½¶Ë¶¼Ê¹Óþ²Ì¬ËíµÀµÄ·½Ê½¾ÍÎÞ·¨½¨Á¢IPSecËíµÀ¡£Ê¹Óö¯Ì¬ËíµÀÅäÖÃʱÎÞÐèÖ¸¶¨¶Ô¶ËIPµØÖ·¡¢Éí·Ý¡¢¸ÐÐËȤÁ÷µÈ£¬Óй«ÍøIPµØÖ·µÄÒ»¶ËʹÓö¯Ì¬ËíµÀ¿É½â¾öÁíÒ»¶ËûÓй̶¨¹«ÍøIPµØÖ·»òÕßûÓй«ÍøIPµØÖ·µÄÎÊÌâ¡£´ËÍ⣬Èç¹û±¾¶ËÐèÒª½¨Á¢´óÁ¿IPSec VPNµÄ¶ÔµÈÌåÒ²¿ÉÒÔʹ¶¯Ì¬ËíµÀ£¬¼õÉÙÅäÖÃÁ¿¡£

·´Ïò·ÓÉ×¢È루RRI£©

ÔÚÍê³ÉIPSecÅäÖúóÎÒÃÇÒªÅäÖÃÈ¥Íù¶Ô¶ËÍø¶ÎµÄ¾²Ì¬Â·ÓÉ£¬Èç¹û¸ÐÐËȤÁ÷Íø¶Î½Ï¶àÈËΪÊÖ¶¯ÅäÖü°Î¬»¤ÕâЩ·ÓÉÓÐЩ²»±ã¡£¿ªÆô·´Ïò·ÓÉ×¢È빦ÄÜ£¬µ±IPSecËíµÀ½¨Á¢Íê³Éºó»á×Ô¶¯²úÉúÏàÓ¦µÄ¾²Ì¬Â·ÓÉ£¨Ä¿µÄµØÖ·ÊǶԶ˸ÐÐËȤÁ÷µØÖ·£¬ÏÂÒ»ÌøÊǶԶ˹«ÍøIPµØÖ·£©×¢È뵽·ÓɱíÖУ¬µ±IPSecËíµÀ¶Ï¿ªºó¶ÔÓ¦µÄ·ÓÉÒ²»áÏûʧ¡£·´Ïò·ÓÉ»á½áºÏIPSecËíµÀµÄ½¨Á¢ÐÅÏ¢×Ô¶¯Éú³É¶Ô¶ËÍø¶Î·ÓÉ£¬ÕâÑù±ãÄܶ¯Ì¬µØÍê³É·ÓɵÄÌí¼ÓÓëɾ³ý£¬±ÜÃâ´óÁ¿ÈËΪÅäÖᣴËÍ⣬ÔÚÉ豸´æÔÚ¶à³ö¿Ú³¡¾°£¬»¹¿ÉÒÔͨ¹ý·´Ïò·ÓÉ×¢Èë½øÐжà³ö¿ÚÉÏIPSecËíµÀµÄÇл»¡£

ʹÓö¯Ì¬Â·ÓÉЭÒ飨GRE over IPSec/L2TP over IPSec£©

ÔÚIPSecÍøÂçÖÐÖ»ÄÜͨ¹ý¾²Ì¬Â·ÓÉÅäÖõ½¶Ô¶ËÍø¶ÎµÄ·ÓÉ£¬IPSec¶ÔµÈÌåÖ®¼äÎÞ·¨Ê¹Óö¯Ì¬Â·ÓÉЭÒé½øÐзÓÉѧϰ£¬·´Ïò·ÓÉ×¢Èë¿ÉÒÔÒ»¶¨³Ì¶ÈÉϽâ¾ö¸ÐÐËȤÁ÷Íø¶Î½Ï¶à¡¢¾²Ì¬Â·ÓÉά»¤³É±¾¸ßµÄÎÊÌ⣬Èç¹ûÏ£ÍûʹÓö¯Ì¬Â·ÓÉЭÒé½øÒ»²½½µµÍ·ÓÉά»¤³É±¾£¬¿ÉÒÔʹÓÃGRE over IPSec VPN»òÕßL2TP over IPSec VPN£¬Ê¹ÓÃGRE»òÕßL2TP½¨Á¢VPNËíµÀ£¬È»ºóÔÙʹÓÃIPSecËíµÀ±£»¤Õâ¸öVPNËíµÀ£¬´Ëʱ¼È±£Ö¤ÁËÊý¾Ý°²È«ÓÖ¿ÉÔÚVPNËíµÀÁ½¶ËʹÓö¯Ì¬Â·ÓÉЭÒé¡£

IPSec VPNµäÐͳ¡¾°

µ¥×ܲ¿µ¥·ÖÖ§³¡¾°

³¡¾°¢ñ

 

ͼ9£ºIPSec VPNµäÐͳ¡¾°¢ñÅäÖñí

³¡¾°¢ò

 

ͼ10£ºIPSec VPNµäÐͳ¡¾°¢òÅäÖñí

 

³¡¾°¢ó

 

ͼ11£ºIPSec VPNµäÐͳ¡¾°¢óÅäÖñí

³¡¾°¢ô

 

ͼ12£ºIPSec VPNµäÐͳ¡¾°¢ôÅäÖñí

 

³¡¾°¢õ

 

ͼ13£ºIPSec VPNµäÐͳ¡¾°¢õÅäÖñí

³¡¾°¢ö

 

ͼ14£ºIPSec VPNµäÐͳ¡¾°¢öÅäÖñí

¶à×ܲ¿¶à·ÖÖ§³¡¾°

³¡¾°¢÷

 

ͼ15£ºIPSec VPNµäÐͳ¡¾°¢÷ÅäÖÃͼ

³¡¾°¢ø

 

ͼ16£ºIPSec VPNµäÐͳ¡¾°¢øÅäÖñí

 

ÔÚ¶à×ܲ¿¶à·ÖÖ§³¡¾°Ï£¬³ýÒÔÉÏÁ½ÖÖµ¥³ö¿ÚÇé¿öÍ⣬¶à³ö¿ÚµÄÇé¿öÒ²½ÏΪ³£¼û¡£²¿Êðʱ½«ÒÔÉÏÁ½ÖÖ¶à×ܲ¿¶à·ÖÖ§³¡¾°Óëµ¥×ܲ¿µ¥·ÖÖ§³¡¾°Ï¶à³ö¿ÚµÄÇé¿ö½áºÏʹÓü´¿É£¬±¾Õ²»ÔÚ׸Êö¡£

IPSec VPN¹ÊÕÏÅŲé

IPSec VPNʹÓÃʱÄÑÃâ»áÓöµ½ËíµÀ½¨Á¢Ê§°ÜµÄÇé¿ö¡£Ò»°ãIPSec VPN¹ÊÕϿɷÖΪÈýÀࣺIKE SA½¨Á¢Ê§°Ü£»IPSec SA½¨Á¢Ê§°Ü£»IPSec SA½¨Á¢³É¹¦µ«Êý¾Ý²»Í¨¡£ÔÚÓöµ½IPSec VPN¹ÊÕÏʱ¶ÁÕ߿ɲ鿴·¢Æð·½ºÍ½ÓÊÕ·½×´Ì¬²¢¶Ô±ÈÈçÏÂIPSec¶ÔµÈÌå״̬½âÎöͼȷÈÏÊôÓÚÄÄÀà¹ÊÕÏ£¬È»ºó¸ù¾ÝÿÀà¹ÊÕϳ£¼ûÔ­Òò½øÐÐÅŲé¡£

 

ͼ17£º²é¿´IPSec¶ÔµÈÌå״̬

18£ºIPSec¶ÔµÈÌå״̬½âÎö

IKE±¨ÎĽ»»¥ÖªÊ¶µã»Ø¹Ë

ÔÚ·ÖÎöÿÀà¹ÊÕϳ£¼û·¢ÉúÔ­Òòǰ£¬×÷ÕßÊ×ÏÈ´ø´ó¼Ò»Ø¹ËÏÂIKE±¨ÎĽ»»¥Çé¿ö£¬Ö»ÓÐÖªµÀÁËÿ¸ö±¨ÎÄÔÚ½»»¥Ê²Ã´ÄÚÈÝ£¬ÔÚÓöµ½IPSec½¨Á¢Í£ÁôÔÚijһ½×¶Îʱ£¬ÎÒÃDzÅÖªµÀÅŲéµÄ·½Ïò¡£IKEͨ¹ýÁ½¸ö½×¶ÎÀ´½¨Á¢IPSec SA£¬µÚÒ»½×¶Î²ÉÓÃÖ÷ģʽ»òÕßÒ°Âùģʽ½¨Á¢IKE SA£¬µÚ¶þ½×¶Î²ÉÓÿìËÙģʽ½¨Á¢IPSec SA¡£

IKEµÚÒ»½×¶Î£¨Ö÷ģʽ£©£º

  1. µÚ1-2¸ö±¨ÎÄЯ´øIKE²ßÂÔ£¬½øÐÐIKE²ßÂÔЭÉÌ£¬IKE²ßÂÔ°üº¬£º¼ÓÃÜËã·¨¡¢HASHËã·¨¡¢DH×é¡¢ÑéÖ¤·½Ê½¡¢IKE SAÉúÃüÖÜÆÚ£¬
  2. µÚ3-4¸ö±¨ÎÄЯ´øDHËã·¨ÐèÒªµÄ²ÄÁÏ£¬½øÐÐDHËã·¨¼ÆËãÉú³ÉÃÜÔ¿£¬
  3. µÚ5-6¸ö±¨ÎÄЯ´øÉí·ÝÐÅÏ¢¼°ÈÏÖ¤ÐÅÏ¢£¬½øÐжԵÈÌå¼äµÄÈÏÖ¤£¬Íê³ÉIKE SA½¨Á¢¡£ÐèҪעÒâµÄÊÇ´ÓµÚ5¸ö±¨ÎÄ¿ªÊ¼ÓÐÁ½´¦±ä»¯£¬µÚÒ»µãÊDZ¨ÎÄ¿ªÊ¼±»¼ÓÃܱ£»¤£¬µÚ¶þµãÊÇÈç¹û´æÔÚNAT´©Ô½µÄÇé¿öUDP¶Ë¿ÚºÅ½«´Ó500±äΪ4500

 

ͼ19£ºÖ÷ģʽ±¨ÎĽ»»¥Á÷³Ì¼°¶ÔµÈÌå״̬

 

IKEµÚÒ»½×¶Î£¨Ò°Âùģʽ£©£º

  1. µÚ1¸ö±¨ÎÄ·¢ËÍ·½·¢ËÍIKE²ßÂÔ¡¢DHËã·¨ÐèÒªµÄ²ÄÁÏ¡¢Éí·ÝÐÅÏ¢£¬IKE²ßÂÔ°üº¬£º¼ÓÃÜËã·¨¡¢HASHËã·¨¡¢DH×é¡¢ÑéÖ¤·½Ê½¡¢IKE SAÉúÃüÖÜÆÚ£»
  2. µÚ2¸ö±¨ÎĽÓÊÕ·½»ØÓ¦Æ¥ÅäµÄIKE²ßÂÔ£¬·¢ËÍDHËã·¨ÐèÒªµÄ²ÄÁÏ¡¢Éí·ÝÐÅÏ¢¡¢ÈÏÖ¤ÐÅÏ¢£»
  3. µÚ3¸ö±¨ÎÄ·¢ËÍ·½·¢ËÍÈÏÖ¤ÐÅÏ¢Íê³ÉÈÏÖ¤£¬Íê³ÉIKE SA½¨Á¢¡£Èç¹û´æÔÚNAT´©Ô½µÄÇé¿ö´Ó¸Ã±¨ÎÄ¿ªÊ¼UDP¶Ë¿ÚºÅ´Ó500±äΪ4500¡£

 

ͼ20£ºÒ°Âùģʽ±¨ÎĽ»»¥Á÷³Ì¼°¶ÔµÈÌå״̬

 

IKEµÚ¶þ½×¶Î£º

  1. µÚ1¸ö±¨ÎÄ·¢ËÍ·½·¢ËÍIPSecת»»¼¯¡¢¸ÐÐËȤÁ÷£¬½øÐÐIPSec²ÎÊýЭÉÌ£¬IPSecת»»¼¯°üº¬£º·âװģʽ¡¢°²È«Ð­Òé¡¢¼ÓÃÜËã·¨¡¢HASHËã·¨¡¢IPSec SAÉúÃüÖÜÆÚ¡£ÁíÍâÈç¹û¿ªÆôPFS»¹»áЯ´øDHËã·¨ÐèÒªµÄ²ÄÁÏ£¬½øÐÐDHËã·¨¼ÆËãÉú³ÉеÄÃÜÔ¿£»
  2. µÚ2¸ö±¨ÎĽÓÊÕ·½»ØÓ¦Æ¥ÅäµÄIPSec²ßÂÔ¡¢¸ÐÐËȤÁ÷¼°DHËã·¨ÐèÒªµÄ²ÄÁÏ(Èç¹û¿ªÆôPFS)£»
  3. µÚ3¸ö±¨ÎÄ·¢ËÍ·½½øÐнá¹ûÈ·ÈÏ£¬Ë«·½Íê³ÉIPSec SA½¨Á¢¡£

СÌáʾ£ºPFS£¨Perfect Forward Secrecy£©ÊÇÒ»ÖÖ°²È«»úÖÆ£¬Ä¬ÈÏÇé¿öÏÂIPSec SA»áÖ±½ÓʹÓÃIKE SAͨ¹ýDHËã·¨Éú³ÉµÄÃÜÔ¿£¬¿ªÆôPFS»úÖÆºó£¬IPSec SAÔÚЭÉÌʱ»áÔÚ¶îÍâ½øÐÐÒ»´ÎDHÃÜÔ¿½»»»Ëã·¨£¬Ê¹IPSec SAʹÓõÄÃÜÔ¿ÓëIKE SAʹÓõÄÃÜÔ¿²»Í¬£¬Ìá¸ß°²È«ÐÔ¡£

IKE SA½¨Á¢Ê§°Ü¹ÊÕÏÔ­Òò·ÖÎö

ͼ21£ºIKEµÚÒ»½×¶ÎIKE SA½¨Á¢Ê§°ÜÔ­Òò

 

IPSec SA½¨Á¢Ê§°Ü¹ÊÕÏÔ­Òò·ÖÎö

ͼ22£ºIKEµÚ¶þ½×¶ÎIPSec SA½¨Á¢Ê§°ÜÔ­Òò

 

IPSec SA½¨Á¢³É¹¦µ«Êý¾Ý²»Í¨¹ÊÕÏÔ­Òò·ÖÎö

ͼ23£ºIPSec SA½¨Á¢³É¹¦µ«Êý¾Ý²»Í¨Ô­Òò

 

дÔÚ×îºó

±¾ÎĽáºÏÀíÂÛÓëʵ¼ù¶ÔIPSec VPN¼¼ÊõµÄ»ù´¡²ÎÊý¡¢¸ß¼¶¹¦ÄÜ¡¢µäÐÍʵ¼ù³¡¾°¼°¹ÊÕÏÅŲ鷽·¨½øÐÐÁËÉîÈë½âÎö¡£³ýÁËIPSec VPN¼¼ÊõÍâL2TP over IPSec VPN¡¢GRE over IPSec VPNµÈVPN¼¼ÊõÒ²ÔÚһЩÆóÒµÕ¾µã¼äʹÓ㬶ÁÕ߿ɽáºÏ±¾ÎÄ˼·×ÔÐнøÐÐÑо¿¡£

Ïà¹ØÍÆ¼ö£º

¸ü¶à¼¼Êõ²©ÎÄ

ÈκÎÐèÒª£¬ÇëÁªÏµÎÒÃÇ

·µ»Ø¶¥²¿

ÊÕÆð
ÎĵµAIÖúÊÖ
ÎĵµÆÀ¼Û
¸Ã×ÊÁÏÊÇ·ñ½â¾öÁËÄúµÄÎÊÌ⣿
Äú¶Ôµ±Ç°Ò³ÃæµÄÂúÒâ¶ÈÈçºÎ£¿
²»Õ¦µÎ
·Ç³£ºÃ
ÄúÂúÒâµÄÔ­ÒòÊÇ£¨¶àÑ¡£©£¿
Äú¶ÔÎĵµÊÇ·ñ»¹ÓÐÆäËüµÄÎÊÌâ»ò½¨Ò飿
Ϊ¾¡¿ì½â¾öÎÊÌ⣬ÇëÄúÁôÏÂÁªÏµ·½Ê½Òﱋȯ¸´
ÓÊÏä
ÊÖ»úºÅ
¸ÐлÄúµÄ·´À¡£¡
ÇëÑ¡Ôñ·þÎñÏîÄ¿
¹Ø±Õ×Éѯҳ
ÊÛǰ×Éѯ ÊÛǰ×Éѯ
ÊÛǰ×Éѯ
ÊÛºó·þÎñ ÊÛºó·þÎñ
ÊÛºó·þÎñ
Òâ¼û·´À¡ Òâ¼û·´À¡
Òâ¼û·´À¡
¸ü¶àÁªÏµ·½Ê½
¡¾ÍøÕ¾µØÍ¼¡¿¡¾sitemap¡¿