97¹ú¼Ê

¹¤³§ÑÐѧ Ø­ 97¹ú¼ÊÍøÂçÊý×Ö»¯ÖÇÄܹ¤³§¡°ºÚ¿Æ¼¼¡±´ó½ÒÃØ
Ô¤Ô¼Ö±²¥
ÀÖÏíÓªÒµ°ü¹Ü·þÎñ Ø­ ÊØ»¤Ò½ÁÆÓªÒµÒ»Á¬ÎȹÌ
Ô¤Ô¼Ö±²¥
97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾
²úÆ·
< ·µ»ØÖ÷²Ëµ¥
²úÆ·ÖÐÐÄ
²úÆ·
½â¾ö¼Æ»®
< ·µ»ØÖ÷²Ëµ¥
½â¾ö¼Æ»®ÖÐÐÄ
ÐÐÒµ
ºÏ×÷»ï°é
·µ»ØÖ÷²Ëµ¥
Ñ¡ÔñÇøÓò/ÓïÑÔ
97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾
97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾ 97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾

Õ¾µã¼äIPSec VPNÍøÂçÊÖÒÕÉî¶ÈÆÊÎö

¡¾IPSec VPN¡¿±¾ÎÄÊ×ÏÈͨ¹ýÊáÀíIPSec VPNÖи÷ÊÖÒÕµÄÓÃ;¼°Ö®¼äµÄ¹ØÁª¹ØÏµ×ÊÖú¸÷ÈËÃ÷È·ÊÖÒÕÔ­Àí£¬Æä´ÎΪ¸÷ÈËÏÈÈÝIPSec VPNµÄһЩ¸ß¼¶¹¦Ð§£¬×îºóΪ¸÷ÈË·ÖÏíµä·¶Êµ¼ù³¡¾°ºÍ¹ÊÕÏÅŲéÒªÁì¡£

  • 97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾

    Ðû²¼Ê±¼ä£º2020-07-01

  • 97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾

    µã»÷Á¿£º

  • 97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾

    µãÔÞ£º

·ÖÏíÖÁ

97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾
97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾
97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾

ÎÒÏë̸ÂÛ

±¾ÎÄ×÷ÕߣºÌï˼Ñî 

97¹ú¼ÊÍøÂçÊÖÒÕ·þÎñ²¿»¥ÁªÍø·þÎñÖÐÐÄ

ǰÑÔ

ÔÚÉÏһƪ¡¶VPNÊÖÒÕdz̸֮ÔõÑù°²ÅÅÔ¶³Ì°ì¹«ÍøÂç¡·ÖУ¬×÷ÕßΪ¸÷ÈË·ÖÏíÁ˶˵½Õ¾µãVPNÊÖÒÕ£¬¸ÃÊÖÒÕÖ÷ҪʹÓÃÔÚÔ¶³Ì°ì¹«Ö°Ô±ºÍÆóÒµÍøÂ绥ͨ³¡¾°£¬¶øÕ¾µãµ½Õ¾µãVPNÊÖÒÕ³£ÓÃÓÚ×ܲ¿Óë·ÖÖ§Ö®¼äµÄÍøÂ绥ͨ£¬Í¨¹ýʹÓÃ×éÖ¯ÒÑÓеĻ¥ÁªÍø³ö¿Ú£¬Ê¹ÓÃVPNÊÖÒÕÐéÄâ³öÒ»Ìõ“רÏß”£¬½«ÆóÒµµÄ·ÖÖ§»ú¹¹ºÍ×ܲ¿ÅþÁ¬ÆðÀ´£¬×é³ÉÒ»¸ö´óµÄ¾ÖÓòÍø¡£Õ¾µãµ½Õ¾µãVPNÖ÷Òª°üÀ¨IPSec VPN¡¢L2TP VPN¡¢L2TP over IPSec VPN¡¢GRE VPN¡¢GRE over IPSec VPN¡¢SSL VPNµÈ¡£IPSec VPNÊÖÒÕÒòÆä¾ßÓÐÇå¾²ÐԸߡ¢±¾Ç®µÍ¡¢°²ÅÅÎÞа¡¢À©Õ¹ÐԺõÈÓŵ㣬ÒѳÉΪÆóÒµÕ¾µã¼äVPN°²ÅŵĵڠһÊÖÒÕÑ¡Ôñ¡£

IPSec VPN²»ÊÇÒ»¸öµ¥¶ÀµÄЭÒ飬¶øÊÇÓÉÒ»×éЭÒé×é³É£¬ÒòÆä°üÀ¨µÄÊÖÒÕ¶à¡¢ÊÖÒռ乨Áª¹ØÏµ¶à£¬Ðí¶àÅóÙ­ÎÞ·¨°ÑIPSec VPNÊÖÒÕÃ÷ȷ͸¡£±¾ÎÄÊ×ÏÈͨ¹ýÊáÀíIPSec VPNÖи÷ÊÖÒÕµÄÓÃ;¼°Ö®¼äµÄ¹ØÁª¹ØÏµ×ÊÖú¸÷ÈËÃ÷È·ÊÖÒÕÔ­Àí£¬Æä´ÎΪ¸÷ÈËÏÈÈÝIPSec VPNµÄһЩ¸ß¼¶¹¦Ð§£¬×îºóΪ¸÷ÈË·ÖÏíµä·¶Êµ¼ù³¡¾°ºÍ¹ÊÕÏÅŲéÒªÁ졣ϣÍû±¾ÎÄÄܹ»×ÊÖúÁÐλ¶ÁÕß°ÑIPSec VPNÊÖÒÕѧ͸¡¢ÓÃÃ÷È·£¬ÄÍÐĶÁÍêÕâÆªÎÄÕÂÏàÐÅÄã»áÓÐ·×ÆçÑùµÄÊÕ»ñ¡£

97¹ú¼ÊÖ§³ÖIPSec VPNµÄ×°±¸ÓÐÐí¶àÖÖ£¬²î±ð×°±¸¶Ô¸÷IPSec VPNÊÖÒÕµÄÖ§³ÖÇéÐÎÂÔÓвî±ð£¬±¾ÎÄÒÔ97¹ú¼ÊÍø¹Ø×°±¸ÎªÀý¸ø¸÷È˽â˵£¬Èç¶ÁÕßʹÓÃÆäËû×°±¸»¶Ó­ÁªÏµ97¹ú¼Ê¹¤³Ìʦ»òµ½97¹ú¼Ê¹ÙÍøÅÌÎÊ£¬Ð»Ð»¡£

 

97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾

ͼ1£º³£¼ûÆóÒµVPN½ÓÈëÍØÆËÄ£×Ó

IPSec VPN»ù´¡²ÎÊý

IPSecÖÐͨѶ˫·½½¨ÉèµÄÅþÁ¬½Ð×öÇå¾²¹ØÁª£¨IPSec SA£©£¬Ë«·½Í¨¹ý²ÎÊýЭÉÌÍê³ÉIPSec SA½¨Éèºó£¬Í¨¹ýIPSec SA´«Êä¼ÓÃܵÄÊý¾Ý±¨ÎľÙÐÐͨѶ¡£ÒÔÊÇÁ½¸ö¶ÔµÈÌå¼äÒªÏëͨ¹ýIPSec VPNͨѶ£¬Ê×ÏÈÒª½¨ÉèIPSec SA¡£ÔÚ¾ÙÐÐIPSec SA½¨Éèʱ¶ÔµÈÌå¼äÒª¾ÙÐÐIPSec SA²ÎÊýЭÉÌ£¬Á½Í·²ÎÊýÏàͬʱ²Å»á½¨ÉèÀֳɡ£

 

97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾

ͼ2£ºIPSec VPN»ù´¡²ÎÊý

IPSec SAÌìÉú·½·¨

ÊÖ¶¯Ö¸¶¨ÌìÉúIPSec SA

¶ÔµÈÌåͨ¹ýÊÖ¶¯Ö¸¶¨IPSec SAЭÉ̲ÎÊýÌìÉúIPSec SA£¬IPSec SA½¨ÉèºóûÓÐÉúÑÄÖÜÏÞÆÚÖÆ£¬ÓÀ²»¹ýÆÚ£¬³ý·ÇÊÖ¹¤É¾³ý£¬Òò´Ë±£´æÇå¾²Òþ»¼¡£Ò»Ñùƽ³£ÍƼöÔÚ¶ÔµÈÌåÊýÄ¿½ÏÉÙÇÒÎÞ·¨Í¨¹ýIKEЭÉ̽¨ÉèIPSec SA³¡¾°ÏÂʹÓá£

IKEЭÉÌÌìÉúIPSec SA

IKEÓÃÓÚ¶¯Ì¬½¨É貢ʵʱά»¤IPSec SA¡£IKEͨ¹ýÁ½¸ö½×¶ÎÀ´½¨ÉèIPSec SA£¬µÚÒ»½×¶ÎÊ×ÏÈҪЭÉ̽¨ÉèIKE SA£¬µÚ¶þ½×¶Îͨ¹ýIKE SAЭÉ̽¨ÉèIPSec SA¡£

IKEЭÉÌÌìÉúIPSec SA±ÈÊÖ¶¯Ö¸¶¨ÌìÉúIPSec SA±£´æÒÔÏÂÓÅÊÆ£º

  1. ÊÊÓó¡¾°¸»ºñ£ºÊÖ¶¯Ö¸¶¨·½·¨±ØÐè¶ÔµÈÌåÁ½Í·¶¼ÓÐÀο¿µÄ¹«ÍøIPµØÖ·£¬ÈçÒ»¶Ë¶ÔµÈÌå¹«ÍøIPµØÖ·²»Àο¿±ØÐèʹÓÃIKEЭÉÌ·½·¨£»
  2. ½µµÍÉèÖÃÖØÆ¯ºó£ºÊÖ¶¯Ö¸¶¨·½·¨ÐèÒªÊÖ¶¯ÉèÖÃSPI¡¢ÃÜÔ¿µÈÐÅÏ¢£¬ÔÚ¶ÔµÈÌå½Ï¶àµÄ³¡¾°ÉèÖÃÁ¿½Ï´ó¶øÎ´±ãÓÚά»¤£¬IKEЭÉÌ·½·¨»áͨ¹ýIKE SAÀ´ÌìÉúºÍά»¤ÕâЩÐÅÏ¢£¬½µµÍÉèÖÃÖØÆ¯ºó¼°Î¬»¤±¾Ç®£»
  3. Ìá¸ßÇå¾²ÐÔ£ºÊÖ¶¯Ö¸¶¨·½·¨½¨ÉèµÄIPSec SAÃÜÔ¿ÊǾ²Ì¬µÄ£¬½¨ÉèºóÓÀ²»¹ýÆÚ£¬IKEЭÉÌ·½·¨»áͨ¹ýIKE SAÌìÉúÃÜÔ¿£¬²¢ÇÒÉúÃüÖÜÆÚµ½ÆÚºó¾ÙÐÐÀÏ»¯ÖØÐÂÌìÉú£¬Ìá¸ßÁËÇå¾²ÐÔ¡£

СÌáÐÑ£ºIKEЭÒéÏÖÔÚÓÐÁ½¸ö°æ±¾IKEv1ÓëIKEv2£¬IKEv1ÏÖÔÚ½ÏΪ³£Óã¬IKEv2ÓëIKEv1ÉèÖÃ˼Ð÷Ïàͬ£¬µ«Ð­ÉÌÀú³ÌÓëIKEv1ÓÐËùÇø±ð£¬±¾ÎIJ»¾ÙÐнâ˵£¬±¾ÎÄÖзºÆðµÄIKEЭÒé¾ù´ú±íIKEv1¡£

IKE SAЭÉÌģʽ

ÔÚIKEµÚÒ»½×¶ÎÓÐÁ½ÖÖЭÉÌģʽ¿ÉЭÉ̽¨ÉèIKE SA£¬Ö÷ģʽ»òÕßÒ°Âùģʽ¡£Ö÷ģʽʹÓÃ6¸ö±¨ÎÄÍê³ÉIKE SA½¨É裬¶øÒ°ÂùģʽʹÓÃ3¸ö±¨ÎÄÍê³ÉIKE SA½¨É裬ÓëÖ÷ģʽÏà±ÈÒ°ÂùģʽïÔÌ­½»»¥±¨ÎÄÊýÄ¿´Ó¶ø¼ÓËÙÁËЭÉÌËÙÂÊ£¬µ«Òò¶ÔÉí·ÝÐÅÏ¢ºÍÈÏÖ¤ÐÅÏ¢½ÓÄÉÃ÷ÎĽ»»¥£¬Ã»ÓмÓÃܱ£»¤£¬Òò´Ë²»Çå¾²£¬×÷Õß²»ÍƼöʹÓá£

Ò°ÂùģʽÔçÆÚÉè¼ÆÖ÷ҪΪ½â¾öÒ»¶Ë¶ÔµÈÌå¹«ÍøIPµØÖ·²»Àο¿»òûÓй«ÍøIPµØÖ·µÄ³¡¾°ÏÂÖ÷ģʽÎÞ·¨Ð­É̽¨ÉèµÄÎÊÌ⣬ÏÖÔÚ¸ÃÎÊÌâ¿ÉÒÔͨ¹ý“¶¯Ì¬ËíµÀ”µÄÒªÁì¸üºÃµØ½â¾ö£¬ÒÔÊÇÍÆ¼öʹÓÃÖ÷ģʽ¡£Ò°Âùģʽ½öÔÚ97¹ú¼Ê×°±¸Óë·Ç97¹ú¼Ê×°±¸½¨ÉèIPSecʹÓÃÖ÷ģʽÎÞ·¨½¨ÉèÀÖ³ÉÏÂʹÓã¬ÆäËû³¡¾°Ï²»ÍƼöʹÓá£

СÌáÐÑ£ºÖ÷ģʽºÍÒ°Âùģʽ±¨ÎĽ»»¥ÏêϸÁ÷³Ì²Î¿¼±¾ÎÄ¡¶IKE±¨ÎĽ»»¥ÖªÊ¶µã»ØÊס·Ð¡½Ú¡£

IKE SA¼ÓÃÜ·½·¨

IKE SAʹÓöԳƼÓÃÜËã·¨¶ÔÊý¾Ý¾ÙÐмÓÃÜÏ¢ÕùÃÜ£¬°ü¹ÜÊý¾ÝµÄÇå¾²ÐÔ¡£³£ÓõĶԳƼÓÃÜËã·¨ÓÐDES¡¢3DES¡¢AESµÈ£¬ÕâÈý¸ö¼ÓÃÜËã·¨µÄÇå¾²ÐÔÓɸߵ½µÍÒÀ´ÎÊÇ£ºAES¡¢3DES¡¢DES£¬Çå¾²ÐԸߵļÓÃÜË㷨ʵÏÖ»úÖÆÖØ´ó£¬ÔËËãËÙÂÊÂý¡£


97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾

ͼ3£ºIKE SA³£ÓõĶԳƼÓÃÜËã·¨

IKE SAÑéÖ¤·½·¨

IKE SAʹÓÃÑéÖ¤Ëã·¨¶Ô±¨ÎÄÍêÕûÐÔ¼°ÈªÔ´Õýµ±ÐÔ¾ÙÐÐÑéÖ¤£¬³£ÓõÄÑéÖ¤·½·¨ÓÐMD5-HMAC¡¢SHA1-HMACµÈ£¬ÊÇHASHËã·¨ºÍHMACÁ½ÖÖÊÖÒÕµÄÍŽá¡£

HASHË㷨ʵÏÖ¶Ô±¨ÎľÙÐÐÍêÕûÐÔУÑ飬³£¼ûµÄHASHËã·¨ÓÐMD5¡¢SHA1µÈ£¬MD5Ëã·¨µÄÅÌËãËÙÂʱÈSHA1Ëã·¨¿ì£¬¶øSHA1Ëã·¨µÄÇ徲ǿ¶È±ÈMD5Ëã·¨¸ß¡£

97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾
ͼ4£ºIKE SA³£ÓõÄHASHËã·¨

 

HMAC(Hash-based Message Authentication Code)ÊÇÒ»ÖÖ»ùÓÚHASHËã·¨ºÍÃÜÔ¿¾ÙÐÐÐÂÎÅÈÏÖ¤µÄÒªÁ죬ʵÏÖ¶Ô±¨ÎÄȪԴµÄÕýµ±ÐÔ¾ÙÐÐÑéÖ¤£¬¿ÉÒÔÓëÈκÎHASHËã·¨À¦°óʹÓá£

IKE SAÃÜÔ¿ÌìÉú·½·¨

DH£¨Diffie-Hellman£©ÊÇÒ»ÖַǶԳÆÃÜÔ¿Ëã·¨£¬Ë«·½¿Éͨ¹ý½ö½»Á÷һЩÊý¾Ý£¬¼´¿ÉÅÌËã³öË«·½µÄÃÜÔ¿£¬²¢ÇÒµÚÈý·½²¶»ñÁËÆäÖеÄÊý¾ÝÒ²ÎÞ·¨ÅÌËãµÃ³öÃÜÔ¿¡£DH±¬·¢µÄÃÜÔ¿ÓÃÓÚÊý¾Ý±¨ÎļÓÃܼ°HMACÅÌËãÖС£¶ÔµÈÌåÁ½Í·DH×鳤¶ÈÐèÖ¸¶¨ÎªÏàͬ£¬³£ÓõÄDH×鳤¶ÈÓÐ768bit£¨DH1£©¡¢1024bit£¨DH2£©¡¢1536bit£¨DH5£©¡£

IKE SAÈÏÖ¤·½·¨

ÔÚIKE¶ÔµÈÌåÖ®¼äÔÚ¾ÙÐÐÉí·ÝÈÏ֤ʱ֧³Öͨ¹ýÔ¤¹²ÏíÃÜÔ¿ÈÏÖ¤ºÍÊý×ÖÖ¤ÊéÈÏÖ¤Á½ÖÖ·½·¨À´È·È϶Է½Éí·ÝµÄÕýµ±ÐÔ¡£Ô¤¹²ÏíÃÜÔ¿ÈÏÖ¤ÉèÖýÏÁ¿¼òÆÓ£¬ÊÇÏÖÔÚ½ÏÁ¿³£ÓõÄÈÏÖ¤·½·¨¡£Êý×ÖÖ¤ÊéÈÏÖ¤Ïà¶ÔÖØ´óµ«Çå¾²ÐԽϸߣ¬¶ÔÇå¾²ÐÔÓнϸßÒªÇóµÄ³¡¾°½¨ÒéʹÓÃÊý×ÖÖ¤ÊéÈÏÖ¤¡£

IKE SAÉí·Ý±êʶ

ÔÚIKE SAЭÉÌÖжԵÈÌåË«·½ÐèҪʹÓÃÏàͬÀàÐ͵ÄÉí·Ý±êʶ£¬³£ÓõÄÉí·Ý±êʶÀàÐÍÓÐ4ÖÖ£¬IPµØÖ·¡¢FQDN¡¢USER-FQDN¡¢Ö¤ÊéDN¡£Êý×ÖÖ¤ÊéÈÏ֤ͨ³£½ÓÄÉÖ¤ÊéDN×÷ΪÍâµØÉí·Ý±êʶ¡£Ô¤¹²ÏíÃÜÔ¿ÈÏ֤ĬÈϽÓÄÉIPµØÖ·×÷ΪÍâµØÉí·Ý±êʶ£¬Í¨³£Ê¹ÓýÓÄÉIPµØÖ·×÷ΪÍâµØÉí·Ý±êʶ¼´¿É£¬ÈôÓöµ½ÒÔÏÂÁ½ÖÖ³¡¾°ÍƼöÊÖ¶¯ÐÞ¸ÄʹÓÃFQDN»òUSER-FQDN£º

  1. ÈôÊǶԵÈÌåµÄIPµØÖ·ÎªÓòÃûÐÎʽ£¬Ôò±ØÐèʹÓÃFQDN»òUSER-FQDN£»
  2. ¶ÔµÈÌå½Ï¶àµÄ³¡¾°Ï£¬½¨Òé½ÓÄÉFQDN»òUSER-FQDN£¬±ãÓÚÇø·Öÿ¸ö¶ÔµÈÌå¶ÔÓ¦ÊÇÄĸö·ÖÖ§¡£

СÌáÐÑ£ºÉí·Ý±êʶÀàÐÍÓëЭÉÌģʽÎ޹أ¬ÈκÎÉí·Ý±êʶÔÚÖ÷ģʽ»òÒ°ÂùģʽϾù¿ÉʹÓ㬺ñÈÖ÷ģʽʹÓÃFQDN×÷ΪÉí·Ý±êʶ»òÒ°ÂùģʽʹÓÃIP×÷ΪÉí·Ý±êʶ¶¼¿ÉÕý³£Íê³ÉIKE SAЭÉÌ£¬Ö»Òª¶ÔµÈÌåÁ½Í·Ê¹ÓÃÏàͬÀàÐÍÉí·Ý±êʶ¼´¿É¡£

IKE SAÉúÃüÖÜÆÚ

ÓÉÓÚIPSec SAЭÉÌÊǽ¨ÉèÔÚIKE SA»ù´¡ÉϵÄ£¬Òò´ËΪ½ÚԼЭÉÌIPSec SAµÄʱ¼ä£¬Ò»Ñùƽ³£IKE SAÉúÃüÖÜÆÚ£¨60Ãëµ½86400Ã룬ȱʡ86400Ã룩±ÈIPSec SAÉúÃüÖÜÆÚÉèÖõij¤¡£µ±ÔÚ¾ÙÐÐIKE SAЭÉÌʱ£¬Á½Í·¶ÔµÈÌåÉèÖõÄIKE SAÉúÃüÖÜÆÚ²î±ð²»»áÔì³ÉIKE SAЭÉÌʧ°Ü£¬¶øÊ¹Ó÷¢ËÍ·½ÉèÖõÄIKE SAÉúÃüÖÜÆÚ¡£

IPSec SAÇ徲ЭÒé

AHºÍESPÊÇIPSecµÄÁ½ÖÖÇ徲ЭÒ飬ÓÃÓÚʵÏÖIPSecÔÚÉí·ÝÈÏÖ¤ºÍÊý¾Ý¼ÓÃܵÄÇå¾²»úÖÆ¡£

  1. AHЭÒ飨Authentication Header£¬Ð­ÒéºÅ51£©£¬Ö÷ÒªÌṩÊý¾ÝÍêÕûÐÔÈ·ÈÏ¡¢Êý¾ÝȪԴȷÈÏ¡¢·ÀÖØ·ÅµÈÇå¾²ÌØÕ÷¡£AHͨ³£Ê¹ÓÃMD5-HMAC¡¢SHA-HMACµÈÑéÖ¤Ë㷨ʵÏÖÊý¾ÝÍêÕûÐÔ£»
  2. ESPЭÒ飨Encapsulating Security Payload£¬Ð­ÒéºÅ50£©£¬Ö÷ÒªÌṩÊý¾ÝÍêÕûÐÔÈ·ÈÏ¡¢Êý¾Ý¼ÓÃÜ¡¢Êý¾ÝȪԴȷÈÏ¡¢·ÀÖØ·ÅµÈÇå¾²ÌØÕ÷¡£ESPͨ³£Ê¹ÓÃDES¡¢3DES¡¢AESµÈ¼ÓÃÜË㷨ʵÏÖÊý¾Ý¼ÓÃÜ£¬Ê¹ÓÃMD5-HMAC¡¢SHA-HMACµÈÑéÖ¤Ë㷨ʵÏÖÊý¾ÝÍêÕûÐÔ¡£ESPЭÒéÏà±ÈAHЭÒé¶àÁËÖ§³ÖÊý¾Ý¼ÓÃÜ¡¢Ö§³ÖNAT´©Ô½£¨NAT-T£©ÕâÁ½´óÓÅÊÆ£¬ÊÇÏÖÔÚIPSec VPN½ÏΪ³£ÓõÄÇ徲ЭÒé¡£

IPSec SA·âװģʽ

·âװģʽÓÃÓÚÖ¸¶¨Ç徲ЭÒéµÄ·âװλÖã¬Óд«ÊäģʽºÍËíµÀģʽÁ½ÖÖ£º

 

´«Ê䣨Transport£©Ä£Ê½Ï£¬AHÍ·»òESPÍ·²åÈëIPÍ·ºÍ´«Êä²ãЭÒéÖ®¼ä£¬²»¸Ä±äԭʼ±¨ÎÄÍ·£¬IPSecËíµÀµÄÔ´ºÍÄ¿µÄµØÖ·¾ÍÊÇ×îÖÕͨѶ˫·½µÄÔ´ºÍÄ¿µÄµØÖ·£¬ÒÔÊÇÖ»Äܱ£»¤Á½¸öIPSec¶ÔµÈÌåÖ®¼äÏ໥ͨѶ¡£Ò»Ñùƽ³£³£ÓÃÔÚʹÓÃGRE over IPSec»òL2TP over IPSecЭÒéµÄ³¡¾°ÖУ¬Ê¹ÓÃIPSecËíµÀ±£»¤GRE»òL2TP¶ÔµÈÌ壻

ËíµÀ£¨Tunnel£©Ä£Ê½Ï£¬AHÍ·»òESPÍ·²åÔÚԭʼIPͷ֮ǰ£¬²¢ÇÒÐÂÌìÉúÒ»¸öIPÍ··ÅÔÚESPÍ·»òAHͷ֮ǰ£¬ÒÔÊÇ¿ÉÒÔ±£»¤Á½¸öIPSec¶ÔµÈÌå±³ºóÁ½¸öÍøÂçÖ®¼ä¾ÙÐÐͨѶ¡£Ò»Ñùƽ³£³£ÓÃÔÚÕ¾µã¼äÍøÂ绥ͨµÄ³¡¾°£¬Êǽϳ£Óõķâװģʽ¡£

 

97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾

ͼ5£ºAHЭÒéÁ½ÖÖ·âװģʽϱ¨ÎÄ·â×°

97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾

ͼ6£ºESPЭÒéÁ½ÖÖ·âװģʽϱ¨ÎÄ·â×°

IPSec SA¼ÓÃÜ·½·¨

IPSec SAÖ§³ÖʹÓõļÓÃÜ·½·¨ÓëIKE SAÏàͬ£¬²Î¿¼±¾ÎÄ¡¶IKE SA¼ÓÃÜ·½·¨¡·Ð¡½Ú¡£

IPSec SAÑéÖ¤·½·¨

IPSec SAÖ§³ÖʹÓõÄÑéÖ¤·½·¨ÓëIKE SAÏàͬ£¬²Î¿¼±¾ÎÄ¡¶IKE SAÑéÖ¤·½·¨¡·Ð¡½Ú¡£

IPSec SAÉúÃüÖÜÆÚ

ΪÁËÈ·±£Çå¾²£¬IPSec SA½«ÔÚ¾­ÓÉһ׼ʱ¼ä£¨0»òÕß120Ãëµ½86400Ã룬ȱʡ3600Ã룩»òµÖ´ïÒ»¶¨Í¨Ñ¶Á¿£¨0»ò2560KBµ½536870912KB£¬È±Ê¡4608000KB£©Ö®ºó³¬Ê±£¬ÖØÐÂЭÉÌ£¬²¢Ê¹ÓÃеÄÃÜÔ¿¡£ÐÂIPSec SAÔÚÉúÃüÖÜÆÚ³¬Ê±Ç°30Ã룬»ò¾­ÓÉÕâÌõËíµÀµÄÊý¾ÝͨѶÁ¿¾àÉúÃüÖÜÆÚÉÐÓÐ256KBʱ×îÏȾÙÐÐЭÉÌ£¨Æ¾Ö¤ÄĸöÏȱ¬·¢£©¡£

µ±ÔÚ¾ÙÐÐIPSec SAЭÉÌʱ£¬Á½Í·¶ÔµÈÌåÉèÖõÄIPSec SAÉúÃüÖÜÆÚ²î±ð²»»áÔì³ÉIPSec SAЭÉÌʧ°Ü£¬¶øÊ¹ÓÃÌᳫ·½ÉèÖõÄIPSec SAÉúÃüÖÜÆÚ¡£

IPSec VPN¸ß¼¶¹¦Ð§

 

97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾

ͼ7£ºIPSec VPN¸ß¼¶¹¦Ð§

IPSecËíµÀ×Ô¶¯½¨É裨Set Autoup£©

ÔÚĬÈÏÇéÐÎÏÂIPSec VPNÉèÖÃÍêºó£¬IPSecËíµÀÊÇÓÉÊý¾ÝÁ÷Á¿´¥·¢ºóÔÙЭÉ̽¨ÉèµÄ¡£ÉèÖÃIPSecËíµÀ×Ô¶¯½¨É裨Set Autoup£©¹¦Ð§ºó£¬²»¹ÜÊÇ·ñÓÐÊý¾ÝÁ÷Á¿´¥·¢£¬Ö»ÒªÍê³ÉIPSec VPNÉèÖúó£¬×°±¸»á×ÔÐд¥·¢IPSecËíµÀ½¨Éè¡£

IPSecÁ´Â·Ì½²â£¨DPD/Track£©

DPD̽²â

ÔÚĬÈÏÇéÐÎÏÂÁ½Í·×°±¸½¨ÉèIPSecËíµÀºó£¬µ±Ò»¶Ë×°±¸·ºÆðÎÊÌâºóÁíÒ»¶ËÊÇÎÞ¸ÐÖªµÄ£¬ÁíÒ»¶Ë×°±¸»á¼ÌÐøÍ¨¹ýIPSecËíµÀ·¢ËÍÊý¾Ý¸ø¹ÊÕÏ×°±¸µ¼ÖÂÊý¾ÝͨѶÖÐÖ¹¡£´ËʱÐèÒªÆÚ´ýIPSecËíµÀ³¬Ê±ºó¹ÊÕÏIPSecËíµÀ²Å»áÖÐÖ¹£¨IPSecËíµÀĬÈϳ¬Ê±Ê±¼äΪһСʱ£©¡£

DPD̽²âÊÇͨ¹ý·¢ËÍIKE±¨ÎÄÈ·È϶ԶË×°±¸IKE SA״̬ÊÇ·ñÕý³£µÄÒ»ÖÖ̽²â»úÖÆ£¬µ±Ì½²âµ½¶Ô¶ËIKE״̬Ò쳣ʱ£¬»áɨ³ý¶ÔÓ¦µÄIKE SAºÍIPSec SA¡£

DPD̽²âÓÐÁ½ÖÖÊÂÇéģʽ£º

  1. °´Ðè̽²âģʽ£¨On-demand£©£¬ÔÚÁè¼ÝÉèÖõÄ̽²âʱ¼äÇÒµ±ÓÐÊý¾Ý±¨ÎÄ·¢ËÍʱ£¬×°±¸»á·¢ËÍDPDÐÂÎÅ̽²â¶Ô¶Ë×°±¸ÊÇ·ñÕý³££¬µ±·¢ËÍ5´ÎDPDÐÅÏ¢¶¼Ã»ÓÐÊÕµ½¶Ô¶Ë×°±¸»Ø°ü»áÒÔΪ¶Ô¶ËIKE SA״̬Òì³££»
  2. ÖÜÆÚ̽²âģʽ£¨Periodic£©£¬×°±¸»áƾ֤ÉèÖõÄ̽²âʱ¼äÖÜÆÚÐÔ×Ô¶¯·¢ËÍ DPD ÐÂÎÅ̽²â¶Ô¶Ë×°±¸ÊÇ·ñÕý³££¬µ±·¢ËÍ5´ÎDPDÐÅÏ¢¶¼Ã»ÓÐÊÕµ½¶Ô¶Ë×°±¸»Ø°ü»áÒÔΪ¶Ô¶ËIKE SA״̬Òì³£¡£

×ÛÉϰ´Ðè̽²âģʽ±ÈÖÜÆÚ̽²âģʽ»á·¢Ë͸üÉÙµÄDPDÐÅÏ¢Ö»ÔÚÊý¾Ý±¨ÎÄ·¢ËÍǰ¼ì²â£¬½ÚÔ¼×°±¸×ÊÔ´¼°ÍøÂç´ø¿í×ÊÔ´£¬µ«Ì½²âµ½¶Ô¶Ë×°±¸¹ÊÕϵÄʱ¼ä»á±ÈÖÜÆÚ̽²âģʽ³¤£¬¶ÁÕ߯¾Ö¤×ÔÉíÓªÒµÐèÇóʹÓúÏÊÊģʽ¾ÙÐÐDPD̽²â¼´¿É¡£

Track̽²â

DPD̽²âͨ¹ý½»»¥IKE±¨ÎÄ¿ÉÒÔ̽²âµ½¶Ô¶Ë×°±¸IKE SA״̬ÊÇ·ñÕý³££¬¹ØÓÚIKE SA״̬Õý³£¶øIPSec SAÒì³£µÄÇéÐÎDPD̽²â¾ÍÎÞÄÜΪÁ¦ÁË£¬ÕâÖÖÇéÐÎͬÑù»áµ¼ÖÂIPSecÓªÒµÖÐÖ¹¡£Track̽²âͨ¹ý°´ÆÚ·¢ËÍICMP»òUDP±¨ÎÄ̽²âIPSecÏÖʵӪҵÊÇ·ñÕý³££¬µ±Track̽²âµ½IPSecӪҵǷºàʱ»áɨ³ý¶ÔÓ¦µÄIPSec SA¾ÙÐÐÖØÐÂЭÉÌ¡£Ò»Ñùƽ³£½¨ÒéͬʱÉèÖÃDPD̽²âºÍTrack̽²â¡£

NAT´©Ô½£¨NAT-T£©

×°±¸Ä¬ÈÏ¿ªÆôNAT´©Ô½£¨NAT-T£©¹¦Ð§£¬ÓÃÓÚ½â¾öµ±½¨ÉèIPSec VPNµÄÁ½Ì¨×°±¸¼ä±£´æNAT×°±¸ESP±¨ÎÄÎÞ·¨Í¨¹ýµÄÎÊÌâ¡£ESP±¨Í··â×°ÔÚIP²ãÖ®ÉÏIPЭÒéºÅ50ÒÔÊÇÎÞ·¨Í¨¹ýNAT×°±¸, NAT-Tͨ¹ýÔÚESP±¨ÎÄÖ®ÉÏ·â×°4500¶Ë¿ÚµÄUDP±¨Í·½â¾ö¸ÃÎÊÌâ¡£

 

97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾

ͼ8£ºNAT-TÔÚESP±¨ÎÄÖ®ÉÏ·â×°4500¶Ë¿ÚµÄUDP±¨Í·

 

ÔÚIKEЭÉ̵ĵÚÒ»½×¶Î£¨Ö÷ģʽµÚ1¡¢2¸ö±¨ÎÄ¡¢Ò°ÂùģʽµÚ1¸ö±¨ÎÄ£©Ö§³ÖNAT-TµÄ×°±¸ÔÚ·¢ËÍIKE±¨ÎÄÖлáЯ´øÒ»¸ö¼ì²âNAT-TÄÜÁ¦µÄVendor IDµÄÔØºÉ£¬µ±Á½Í·×°±¸¶¼Ð¯´øÕâ¸ö×ֶξͻá¾ÙÐÐNAT-TЭÉÌ¡£µ±¼ì²âË«·½¶¼Ö§³ÖNAT-TËæºó£¨Ö÷ģʽµÚ3¡¢4¸ö±¨ÎÄ¡¢Ò°ÂùģʽµÚ2¸ö±¨ÎÄ£©»áЯ´øÒ»¸öNAT-DµÄÔØºÉ£¬NAT-DÔØºÉÖаüÀ¨×Ô¼ºIPµØÖ·ºÍ¶Ë¿ÚµÄHASHÖµ£¬¶Ô¶Ë×°±¸ÊÕµ½Õâ¸öÖµºó»áÓëÊÕµ½µÄÏÖʵIPµØÖ·ºÍ¶Ë¿ÚµÄHashÖµ×ö±ÈÕÕ£¬ÈôÊÇÏàͬ˵Ã÷ÖÐÐÄδ¾­ÓÉNAT×°±¸£¬²»È»ËµÃ÷ÖÐÐľ­ÓÉNAT×°±¸¡£ÈôÊÇNAT-T¼ì²âµ½ÖÐÐľ­ÓÉNAT×°±¸£¬×°±¸»áÔÚÏÂÒ»¸ö±¨ÎÄ£¨Ö÷ģʽµÚ5¡¢6±¨ÎÄ¡¢Ò°ÂùģʽµÚ3¸ö±¨ÎÄ£©×îÏȲåÈëÒ»¸ö4500¶Ë¿ÚµÄUDP±¨Í·£¬ÖÁ´ËNAT-TÊÂÇ鿢ʡ£

 

¶¯Ì¬ËíµÀ£¨Crypto Dynamic-map£©

Ò»Ñùƽ³£ÇéÐÎÏ£¬Á½Í·×°±¸¶¼Óй«ÍøIPµØÖ·£¬ÉèÖÃʱÁ½Í·Ê¹Óþ²Ì¬ËíµÀµÄ·½·¨Ï໥ָ¶¨¶Ô¶Ë¹«ÍøIPµØÖ·¾ÙÐÐIPSecËíµÀ½¨Éè¡£ÏÖʵÖÐÒ²»áÓöµ½Ò»¶ËÓй«ÍøIPµØÖ·¶øÁíÒ»¶ËûÓÐÀο¿¹«ÍøIPµØÖ·»òÕßûÓй«ÍøIPµØÖ·µÄÇéÐΣ¬ÕâÖÖÇéÐÎÁ½Í·¶¼Ê¹Óþ²Ì¬ËíµÀµÄ·½·¨¾ÍÎÞ·¨½¨ÉèIPSecËíµÀ¡£Ê¹Óö¯Ì¬ËíµÀÉèÖÃʱÎÞÐèÖ¸¶¨¶Ô¶ËIPµØÖ·¡¢Éí·Ý¡¢¸ÐÐËȤÁ÷µÈ£¬Óй«ÍøIPµØÖ·µÄÒ»¶ËʹÓö¯Ì¬ËíµÀ¿É½â¾öÁíÒ»¶ËûÓÐÀο¿¹«ÍøIPµØÖ·»òÕßûÓй«ÍøIPµØÖ·µÄÎÊÌâ¡£±ðµÄ£¬ÈôÊDZ¾¶ËÐèÒª½¨Éè´ó×ÚIPSec VPNµÄ¶ÔµÈÌåÒ²¿ÉÒÔʹ¶¯Ì¬ËíµÀ£¬ïÔÌ­ÉèÖÃÁ¿¡£

·´Ïò·ÓÉ×¢È루RRI£©

ÔÚÍê³ÉIPSecÉèÖúóÎÒÃÇÒªÉèÖÃÈ¥Íù¶Ô¶ËÍø¶ÎµÄ¾²Ì¬Â·ÓÉ£¬ÈôÊǸÐÐËȤÁ÷Íø¶Î½Ï¶àÈËΪÊÖ¶¯ÉèÖü°Î¬»¤ÕâЩ·ÓÉÓÐЩδ±ã¡£¿ªÆô·´Ïò·ÓÉ×¢È빦Ч£¬µ±IPSecËíµÀ½¨ÉèÍê³Éºó»á×Ô¶¯±¬·¢ÏìÓ¦µÄ¾²Ì¬Â·ÓÉ£¨Ä¿µÄµØÖ·ÊǶԶ˸ÐÐËȤÁ÷µØÖ·£¬ÏÂÒ»ÌøÊǶԶ˹«ÍøIPµØÖ·£©×¢È뵽·ÓɱíÖУ¬µ±IPSecËíµÀ¶Ï¿ªºó¶ÔÓ¦µÄ·ÓÉÒ²»áÏûÊÅ¡£·´Ïò·ÓÉ»áÍŽáIPSecËíµÀµÄ½¨ÉèÐÅÏ¢×Ô¶¯ÌìÉú¶Ô¶ËÍø¶Î·ÓÉ£¬ÕâÑù±ãÄܶ¯Ì¬µØÍê³É·ÓɵÄÌí¼ÓÓëɾ³ý£¬×èÖ¹´ó×ÚÈËΪÉèÖᣱðµÄ£¬ÔÚ×°±¸±£´æ¶à³ö¿Ú³¡¾°£¬»¹¿ÉÒÔͨ¹ý·´Ïò·ÓÉ×¢Èë¾ÙÐжà³ö¿ÚÉÏIPSecËíµÀµÄÇл»¡£

ʹÓö¯Ì¬Â·ÓÉЭÒ飨GRE over IPSec/L2TP over IPSec£©

ÔÚIPSecÍøÂçÖÐÖ»ÄÜͨ¹ý¾²Ì¬Â·ÓÉÉèÖõ½¶Ô¶ËÍø¶ÎµÄ·ÓÉ£¬IPSec¶ÔµÈÌåÖ®¼äÎÞ·¨Ê¹Óö¯Ì¬Â·ÓÉЭÒé¾ÙÐзÓÉѧϰ£¬·´Ïò·ÓÉ×¢Èë¿ÉÒÔÒ»¶¨Ë®Æ½ÉϽâ¾ö¸ÐÐËȤÁ÷Íø¶Î½Ï¶à¡¢¾²Ì¬Â·ÓÉά»¤±¾Ç®¸ßµÄÎÊÌ⣬ÈôÊÇÏ£ÍûʹÓö¯Ì¬Â·ÓÉЭÒé½øÒ»²½½µµÍ·ÓÉά»¤±¾Ç®£¬¿ÉÒÔʹÓÃGRE over IPSec VPN»òÕßL2TP over IPSec VPN£¬Ê¹ÓÃGRE»òÕßL2TP½¨ÉèVPNËíµÀ£¬È»ºóÔÙʹÓÃIPSecËíµÀ±£»¤Õâ¸öVPNËíµÀ£¬´Ëʱ¼È°ü¹ÜÁËÊý¾ÝÇå¾²ÓÖ¿ÉÔÚVPNËíµÀÁ½Í·Ê¹Óö¯Ì¬Â·ÓÉЭÒé¡£

IPSec VPNµä·¶³¡¾°

µ¥×ܲ¿µ¥·ÖÖ§³¡¾°

³¡¾°¢ñ

97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾

97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾

 

97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾

ͼ9£ºIPSec VPNµä·¶³¡¾°¢ñÉèÖñí

³¡¾°¢ò

97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾

97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾

 

97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾

ͼ10£ºIPSec VPNµä·¶³¡¾°¢òÉèÖñí

 

³¡¾°¢ó

97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾

97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾

 

97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾

ͼ11£ºIPSec VPNµä·¶³¡¾°¢óÉèÖñí

³¡¾°¢ô

97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾

97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾

 

97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾

ͼ12£ºIPSec VPNµä·¶³¡¾°¢ôÉèÖñí

 

³¡¾°¢õ

97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾

97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾

 

97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾

ͼ13£ºIPSec VPNµä·¶³¡¾°¢õÉèÖñí

³¡¾°¢ö

97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾

97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾

 

97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾

ͼ14£ºIPSec VPNµä·¶³¡¾°¢öÉèÖñí

¶à×ܲ¿¶à·ÖÖ§³¡¾°

³¡¾°¢÷

97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾

97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾

 

97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾

ͼ15£ºIPSec VPNµä·¶³¡¾°¢÷ÉèÖÃͼ

³¡¾°¢ø

97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾

97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾

 

97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾

ͼ16£ºIPSec VPNµä·¶³¡¾°¢øÉèÖñí

 

ÔÚ¶à×ܲ¿¶à·ÖÖ§³¡¾°Ï£¬³ýÒÔÉÏÁ½ÖÖµ¥³ö¿ÚÇéÐÎÍ⣬¶à³ö¿ÚµÄÇéÐÎÒ²½ÏΪ³£¼û¡£°²ÅÅʱ½«ÒÔÉÏÁ½ÖÖ¶à×ܲ¿¶à·ÖÖ§³¡¾°Óëµ¥×ܲ¿µ¥·ÖÖ§³¡¾°Ï¶à³ö¿ÚµÄÇéÐÎÍŽáʹÓü´¿É£¬±¾Õ²»ÔÚ׸Êö¡£

IPSec VPN¹ÊÕÏÅŲé

IPSec VPNʹÓÃʱÄÑÃâ»áÓöµ½ËíµÀ½¨Éèʧ°ÜµÄÇéÐΡ£Ò»Ñùƽ³£IPSec VPN¹ÊÕϿɷÖΪÈýÀࣺIKE SA½¨Éèʧ°Ü£»IPSec SA½¨Éèʧ°Ü£»IPSec SA½¨ÉèÀֳɵ«Êý¾ÝÇ·ºà¡£ÔÚÓöµ½IPSec VPN¹ÊÕÏʱ¶ÁÕß¿ÉÉó²éÌᳫ·½ºÍÎüÊÕ·½×´Ì¬²¢¶ÔºÃ±ÈÏÂIPSec¶ÔµÈÌå״̬ÆÊÎöͼȷÈÏÊôÓÚÄÄÀà¹ÊÕÏ£¬È»ºóƾ֤ÿÀà¹ÊÕϳ£¼ûÔµ¹ÊÔ­ÓɾÙÐÐÅŲé¡£

 

97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾

ͼ17£ºÉó²éIPSec¶ÔµÈÌå״̬

97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾

18£ºIPSec¶ÔµÈÌå״̬ÆÊÎö

IKE±¨ÎĽ»»¥ÖªÊ¶µã»ØÊ×

ÔÚÆÊÎöÿÀà¹ÊÕϳ£¼û±¬·¢Ôµ¹ÊÔ­ÓÉǰ£¬×÷ÕßÊ×ÏÈ´ø¸÷ÈË»ØÊ×ÏÂIKE±¨ÎĽ»»¥ÇéÐΣ¬Ö»ÓÐÖªµÀÁËÿ¸ö±¨ÎÄÔÚ½»»¥Ê²Ã´ÄÚÈÝ£¬ÔÚÓöµ½IPSec½¨ÉèÍ£ÁôÔÚijһ½×¶Îʱ£¬ÎÒÃDzÅÖªµÀÅŲéµÄÆ«Ïò¡£IKEͨ¹ýÁ½¸ö½×¶ÎÀ´½¨ÉèIPSec SA£¬µÚÒ»½×¶Î½ÓÄÉÖ÷ģʽ»òÕßÒ°Âùģʽ½¨ÉèIKE SA£¬µÚ¶þ½×¶Î½ÓÄÉ¿ìËÙģʽ½¨ÉèIPSec SA¡£

IKEµÚÒ»½×¶Î£¨Ö÷ģʽ£©£º

  1. µÚ1-2¸ö±¨ÎÄЯ´øIKEÕ½ÂÔ£¬¾ÙÐÐIKEÕ½ÂÔЭÉÌ£¬IKEÕ½ÂÔ°üÀ¨£º¼ÓÃÜËã·¨¡¢HASHËã·¨¡¢DH×é¡¢ÑéÖ¤·½·¨¡¢IKE SAÉúÃüÖÜÆÚ£¬
  2. µÚ3-4¸ö±¨ÎÄЯ´øDHËã·¨ÐèÒªµÄÖÊÁÏ£¬¾ÙÐÐDHËã·¨ÅÌËãÌìÉúÃÜÔ¿£¬
  3. µÚ5-6¸ö±¨ÎÄЯ´øÉí·ÝÐÅÏ¢¼°ÈÏÖ¤ÐÅÏ¢£¬¾ÙÐжԵÈÌå¼äµÄÈÏÖ¤£¬Íê³ÉIKE SA½¨Éè¡£ÐèÒª×¢ÖØµÄÊÇ´ÓµÚ5¸ö±¨ÎÄ×îÏÈÓÐÁ½´¦×ª±ä£¬µÚÒ»µãÊDZ¨ÎÄ×îÏȱ»¼ÓÃܱ£»¤£¬µÚ¶þµãÊÇÈôÊDZ£´æNAT´©Ô½µÄÇéÐÎUDP¶Ë¿ÚºÅ½«´Ó500±äΪ4500

 

97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾

ͼ19£ºÖ÷ģʽ±¨ÎĽ»»¥Á÷³Ì¼°¶ÔµÈÌå״̬

 

IKEµÚÒ»½×¶Î£¨Ò°Âùģʽ£©£º

  1. µÚ1¸ö±¨ÎÄ·¢ËÍ·½·¢ËÍIKEÕ½ÂÔ¡¢DHËã·¨ÐèÒªµÄÖÊÁÏ¡¢Éí·ÝÐÅÏ¢£¬IKEÕ½ÂÔ°üÀ¨£º¼ÓÃÜËã·¨¡¢HASHËã·¨¡¢DH×é¡¢ÑéÖ¤·½·¨¡¢IKE SAÉúÃüÖÜÆÚ£»
  2. µÚ2¸ö±¨ÎÄÎüÊÕ·½»ØÓ¦Æ¥ÅäµÄIKEÕ½ÂÔ£¬·¢ËÍDHËã·¨ÐèÒªµÄÖÊÁÏ¡¢Éí·ÝÐÅÏ¢¡¢ÈÏÖ¤ÐÅÏ¢£»
  3. µÚ3¸ö±¨ÎÄ·¢ËÍ·½·¢ËÍÈÏÖ¤ÐÅÏ¢Íê³ÉÈÏÖ¤£¬Íê³ÉIKE SA½¨Éè¡£ÈôÊDZ£´æNAT´©Ô½µÄÇéÐδӸñ¨ÎÄ×îÏÈUDP¶Ë¿ÚºÅ´Ó500±äΪ4500¡£

 

97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾

ͼ20£ºÒ°Âùģʽ±¨ÎĽ»»¥Á÷³Ì¼°¶ÔµÈÌå״̬

 

IKEµÚ¶þ½×¶Î£º

  1. µÚ1¸ö±¨ÎÄ·¢ËÍ·½·¢ËÍIPSecת»»¼¯¡¢¸ÐÐËȤÁ÷£¬¾ÙÐÐIPSec²ÎÊýЭÉÌ£¬IPSecת»»¼¯°üÀ¨£º·âװģʽ¡¢Ç徲ЭÒé¡¢¼ÓÃÜËã·¨¡¢HASHËã·¨¡¢IPSec SAÉúÃüÖÜÆÚ¡£ÁíÍâÈôÊÇ¿ªÆôPFS»¹»áЯ´øDHËã·¨ÐèÒªµÄÖÊÁÏ£¬¾ÙÐÐDHËã·¨ÅÌËãÌìÉúеÄÃÜÔ¿£»
  2. µÚ2¸ö±¨ÎÄÎüÊÕ·½»ØÓ¦Æ¥ÅäµÄIPSecÕ½ÂÔ¡¢¸ÐÐËȤÁ÷¼°DHËã·¨ÐèÒªµÄÖÊÁÏ(ÈôÊÇ¿ªÆôPFS)£»
  3. µÚ3¸ö±¨ÎÄ·¢ËÍ·½¾ÙÐÐЧ¹ûÈ·ÈÏ£¬Ë«·½Íê³ÉIPSec SA½¨Éè¡£

СÌáÐÑ£ºPFS£¨Perfect Forward Secrecy£©ÊÇÒ»ÖÖÇå¾²»úÖÆ£¬Ä¬ÈÏÇéÐÎÏÂIPSec SA»áÖ±½ÓʹÓÃIKE SAͨ¹ýDHËã·¨ÌìÉúµÄÃÜÔ¿£¬¿ªÆôPFS»úÖÆºó£¬IPSec SAÔÚЭÉÌʱ»áÔÚÌØÊâ¾ÙÐÐÒ»´ÎDHÃÜÔ¿½»Á÷Ëã·¨£¬Ê¹IPSec SAʹÓõÄÃÜÔ¿ÓëIKE SAʹÓõÄÃÜÔ¿²î±ð£¬Ìá¸ßÇå¾²ÐÔ¡£

IKE SA½¨Éèʧ°Ü¹ÊÕÏÔµ¹ÊÔ­ÓÉÆÊÎö

97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾

ͼ21£ºIKEµÚÒ»½×¶ÎIKE SA½¨Éèʧ°ÜÔµ¹ÊÔ­ÓÉ

 

IPSec SA½¨Éèʧ°Ü¹ÊÕÏÔµ¹ÊÔ­ÓÉÆÊÎö

97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾

ͼ22£ºIKEµÚ¶þ½×¶ÎIPSec SA½¨Éèʧ°ÜÔµ¹ÊÔ­ÓÉ

 

IPSec SA½¨ÉèÀֳɵ«Êý¾ÝÇ·ºà¹ÊÕÏÔµ¹ÊÔ­ÓÉÆÊÎö

97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾

ͼ23£ºIPSec SA½¨ÉèÀֳɵ«Êý¾ÝÇ·ºàÔµ¹ÊÔ­ÓÉ

 

дÔÚ×îºó

±¾ÎÄÍŽáÀíÂÛÓëʵ¼ù¶ÔIPSec VPNÊÖÒյĻù´¡²ÎÊý¡¢¸ß¼¶¹¦Ð§¡¢µä·¶Êµ¼ù³¡¾°¼°¹ÊÕÏÅŲéÒªÁì¾ÙÐÐÁËÉîÈëÆÊÎö¡£³ýÁËIPSec VPNÊÖÒÕÍâL2TP over IPSec VPN¡¢GRE over IPSec VPNµÈVPNÊÖÒÕÒ²ÔÚһЩÆóÒµÕ¾µã¼äʹÓ㬶ÁÕß¿ÉÍŽ᱾ÎÄ˼Ð÷×ÔÐоÙÐÐÑо¿¡£

Ïà¹ØÍÆ¼ö£º

¸ü¶àÊÖÒÕ²©ÎÄ

ÈκÎÐèÒª£¬ÇëÁªÏµ97¹ú¼Ê

97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾ 97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾
97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾

·µ»Ø¶¥²¿

ÊÕÆð
97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾
ÎĵµÆÀ¼Û
¸Ã×ÊÁÏÊÇ·ñ½â¾öÁËÄúµÄÎÊÌ⣿
Äú¶ÔÄ¿½ñÒ³ÃæµÄÖª×ã¶ÈÔõÑù£¿
²»Õ¦µÎ
ºÜÊǺÃ
ÄúÖª×ãµÄÔµ¹ÊÔ­ÓÉÊÇ£¨¶àÑ¡£©£¿
Äú²»Öª×ãµÄÔµ¹ÊÔ­ÓÉÊÇ£¨¶àÑ¡£©£¿
ÄúÊÇ·ñÉÐÓÐÆäËûÎÊÌâ»ò½¨Ò飿
ΪÁË¿ìËÙ½â¾ö²¢»Ø¸´ÄúµÄÎÊÌ⣬Äú¿ÉÒÔÁôÏÂÁªÏµ·½·¨
ÓÊÏä
ÊÖ»úºÅ
ллÄúµÄ·´À¡£¡
97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾
97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾
97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾
ÇëÑ¡Ôñ·þÎñÏîÄ¿
¹Ø±Õ×Éѯҳ
ÊÛǰ×Éѯ ÊÛǰ×Éѯ
ÊÛǰ×Éѯ
ÊÛºó·þÎñ ÊÛºó·þÎñ
ÊÛºó·þÎñ
Òâ¼û·´Ïì Òâ¼û·´Ïì
Òâ¼û·´Ïì
¸ü¶àÁªÏµ·½·¨
ÍøÕ¾µØÍ¼