1 ·À»ðǽ¸ÅÊö
ÔÚÏÈÈÝ·À»ðǽ¹¦Ð§Ö®Ç°£¬ÏȼòÆÓÏÈÈÝÏ·À»ðǽһ´ÊµÄËÞÊÀ½ñÉú¡£·À»ðǽһ´ÊÔ´ÓÚÒ»ÖֹŴúµÄÏû·ÀÐÞ½¨¡£ÔڹŴú£¬ÓÉÓÚºâÓîͨ³£ÊÇľÖʽṹ£¬Ò»µ©Ê§»ð¼«Ò×ÉìÕÅ£¬Ôì³É´ó×ÚÉúÃü¹¤ÒµËðʧ¡£ÎªÁËÔÚ»ðÔÖʱ×è¶ô»ðÊÆµÄÈö²¥£¬ÈËÃǰѽáʵµÄʯ¿éµþÆðÀ´£¬Î§ÈÆ×ÅÎÝ×ÓÖþÆðÁËÒ»¶Âǽ£¬ÒÔ´ËΪÆÁÕÏ£¬ÕâÖÖ·À»¤ÐÞ½¨Îï³ÆÎª·À»ðǽ¡£Ê±ÖÁ½ñÈÕ£¬·À»ðǽһ´Ê±»ÒýÈëͨѶÁìÓòÖС£ÓÉÓÚÔÚÍøÂ磨ÄÚ²¿ÍøÂ磩ÓëÍøÂ磨Íâ²¿ÍøÂ磩֮¼ä±£´æ×ÅÇå¾²ÈëÇÖºÍÍþв£¬ÒÔÊÇÈËÃÇÒ²ÐèÒªÔÚÍøÂçÖ®¼äÉèÖÃÒ»µÀ·À»ðǽ¡£
ÔÚÍøÂçÁìÓòÖУ¬·À»ðǽ¿ÉÒÔÊÇÓÉ×ÔÁ¦µÄÓ²¼þÓëÈí¼þ×éºÏ¶ø³ÉµÄÓ²¼þ·À»ðǽ£¬Ò²¿ÉÒÔÊÇǶÈëµ½ÆäËû×°±¸ÏµÍ³µÄÈí¼þ·À»ðǽ¡£ÆäʵÖÊÊǽ«ÄÚ²¿ÍøÂçÓëÍâ²¿ÍøÂç¸ôÍÑÀëÀ´µÄÒ»µÀ·ÀÓùϵͳ£¬Ëü»á¶ÔÁ÷¾·À»ðǽµÄÊý¾Ý¾ÙÐÐÇå¾²Éó²é£¬Ö»ÓоÓÉ·À»ðǽÊÚȨµÄÊý¾Ý²Å±»ÔÊÐí»á¼ûÄÚ²¿ÍøÂ磬´Ó¶ø±£»¤ÄÚ²¿ÍøÂçÃâÊܲ»·¨Óû§µÄ¹¥»÷ºÍÈëÇÖ¡£ÏÖÔÚ£¬·À»ðǽÒÑÈ»³ÉΪ±£»¤ÍøÂçÊý¾ÝÇå¾²²»¿É»òȱµÄÒ»ÖÖÊֶΡ£
ͼ1-1 ·À»ðǽÊý¾Ý»á¼ûʾÒâͼ
2 ·À»ðǽÖ÷Òª¹¦Ð§
ÆËÃæÁÙ´ó×ÚµÄÍøÂç¹¥»÷ʱ£¬·À»ðǽÄܹ»×÷ÎªÍøÂçÇå¾²·À»¤µÄµÚÒ»µÀÆÁÕÏ£¬²»±»²»·¨»ñÈ¡»òÆÆËð£¬ÒÀÀµµÄÊǸ»ºñµÄÇå¾²¹¦Ð§¡£ÓÉÓÚ²î±ðÇå¾²³§É̼äµÄ·À»ðǽ²úÆ·ÔÚÖ§³ÖµÄ¹¦Ð§ÉÏÓÐËù²î±ð£¬Òò´Ë£¬±¾ÎĽöÏÈÈÝһЩͨÓõķÀ»ðǽ¹¦Ð§£¬°üÀ¨»ù´¡µÄ·À»ðǽ¹¦Ð§ºÍ¸ß¼¶¹¦Ð§¡£
2.1 »ù´¡·À»ðǽ¹¦Ð§
±¾½Ú½«ÏÈÈÝÈçÏ»ù´¡·À»ðǽ¹¦Ð§£º
¡ñ»á¼û¿ØÖÆ
¡ñNAT
¡ñÈÕÖ¾¼Í¼Óë¼à¿Ø
2.1.1 »á¼û¿ØÖÆ
»á¼û¿ØÖÆÊÇ·À»ðǽ³£¼ûµÄ¹¦Ð§£¬ËüÖ÷Ҫͨ¹ý°ü¹ýÂËÀ´ÊµÏÖ¡£°ü¹ýÂ˽«¼ì²éת·¢±¨Îĵı¨ÎÄÍ·ÐÅÏ¢£¬°üÀ¨Ô´IPµØÖ·¡¢Ä¿µÄIPµØÖ·¡¢Ô´¶Ë¿ÚºÅ¡¢Ä¿µÄ¶Ë¿ÚºÅ¼°ÐÒéÀàÐÍ£¨¼´ÎåÔª×飩¡£µ±Óû§ÔÚ·À»ðǽÉèÖÃÁ˹ýÂ˹æÔòºó£¬»áÔÚ·À»ðǽÖÐÐγÉÒ»¸ö¹ýÂ˹æÔò±í£¬¹æÔòÆ¥ÅäµÄÐж¯ÊÇÔÊÐí£¨Permit£©»ò¾Ü¾ø£¨Deny£©¡£±¨ÎĽøÈë·À»ðǽʱ£¬·À»ðǽ»áƾ֤±¨ÎĵÄÍ·²¿ÐÅÏ¢Óë¹ýÂ˹æÔò±í¾ÙÐÐÖðÌõ±È¶Ô£¬Æ¾Ö¤±ÈÕÕµÄЧ¹ûÀ´¾öÒéÊÇ·ñÔÊÐíÊý¾Ý°üͨ¹ý¡£Í¼ÖÐIP±¨ÎÄ2δÄÜÆ¥Åä¹ýÂ˹æÔò2±»¾Ü¾øÍ¨¹ý£¬¶øIP±¨ÎÄ1ºÍ3ÇÐºÏÆ¥Å乿Ôò±»·ÅÐÐͨ¹ý¡£
ͼ2-1 °ü¹ýÂË»á¼û¿ØÖÆÊ¾Òâͼ
2.1.2 NAT
NAT£¨Network Address Translation£¬ÍøÂçµØÖ·×ª»»£©ÊÇÖ¸½«Ò»¸öIPµØÖ·×ª»»ÎªÁíÒ»¸öIPµØÖ·µÄÀú³Ì£¬Ö÷ÒªÓÃÓÚʵÏÖÄÚ²¿ÍøÂç»á¼ûÍâ²¿ÍøÂçµÄ¹¦Ð§¡£ÓÉÓÚ·À»ðǽ´ó¶à°²ÅÅÔÚÆóÒµÍøÂçµÄ½çÏß³ö¿Ú£¬ÓÃÓÚÓëÍⲿµÄInternetÍøÂç¸ôÀ룬ÄÚ²¿Óû§ÏëÒª»á¼û»¥ÁªÍøÍ¨³£ÐèÒª½èÖú·À»ðǽµÄNAT¹¦Ð§¡£²î±ðµÄNATÊÊÓÃÓÚ²î±ð³¡¾°£¬ÕâÀï½öÏÈÈÝ×î³£ÓõÄÔ´NATµØÖ·×ª»»¡£Ô´NATÖ÷ÒªÊǶÔIP±¨ÎĵÄÔ´µØÖ·¾ÙÐÐת»»£¬½«Óû§µÄË½ÍøIPµØÖ·×ª»»Îª¹«ÍøIPµØÖ·£¬ÕâÑùÄÜʹÖÚ¶àµÄË½ÍøÓû§Ê¹ÓÃÉÙÁ¿µÄ¹«ÍøµØÖ·¼´¿É»á¼ûInternet£¬ÓÐÖúÓÚ¼õ»º¿ÉÓÃIPµØÖ·¿Õ¼äµÄ¿Ý½ß¡£
ͼ2-2 Ô´NATת»»Ê¾Òâͼ
2.1.3 ÈÕÖ¾¼Í¼
µ±±¨Îĵִï·À»ðǽʱ£¬·À»ðǽ»áɨÃ豨ÎIJ¢Æ¾Ö¤ÉèÖõķÀ»ðǽսÂÔÖ´ÐÐÐж¯£¬ÕâЩÐж¯°üÀ¨ÔÊÐí»ò¾Ü¾ø±¨ÎÄͨ¹ý¡£·À»ðǽ´Ëʱ»á½«ÊÂÎñ¼Í¼ÔÚÈÕÖ¾µ±ÖУ¬ÕâЩÈÕÖ¾ÔÚ¼à¿ØÄÚ²¿ÍøÂçÓëInternetÖ®¼äµÄÁ÷Á¿ÐÅÏ¢¡¢Ê¶±ð²»·¨µÄ»á¼ûÅþÁ¬µÈÁ÷Á¿Éó¼ÆÔ˶¯ÖÐÄܹ»Ê©Õ¹Ö÷Òª×÷Ó᣷À»ðǽͨ³£Ö§³ÖÍâµØÉúÑÄÈÕÖ¾£¬»òÊǽ«ÈÕÖ¾ÉúÑÄÔÚÄÚÍø×¨ÃÅ´æ·ÅÈÕÖ¾µÄ·þÎñÆ÷Àï¡£
ͼ2-3 ·À»ðǽÈÕÖ¾¼Í¼ʾÒâͼ
2.2 ¸ß¼¶·À»ðǽ¹¦Ð§
±¾½Ú½«ÏÈÈÝÈçϸ߼¶·À»ðǽ¹¦Ð§£º
¡ñIPSec/SSL VPN
¡ñÇå¾²¹¥»÷Ìá·À
¡ñË«»úÈȱ¸¹¦Ð§
2.2.1 IPSec/SSL VPN
·À»ðǽ֧³Ö¶àÖÖVPN£¨Virtual Private Network£¬ÐéÄâרÓÃÍøÂ磩µÄ½ÓÈ룬²¢Ö§³ÖÓÃIPSec£¨IP Security£¬IPÇå¾²£©ºÍSSL£¨Secure Socket Layer£¬Çå¾²Ì׽Ӳ㣩À´¼ÓÃÜÊý¾Ý¡£IPSecͨ³£±»Ó¦ÓÃÔÚÕ¾µãµ½Õ¾µãÖ®¼äVPNÊý¾Ý¼ÓÃÜ£¬Èç×ܲ¿µÄÄÚ²¿Ö÷»úºÍºÍ·Ö¹«Ë¾Ö÷»ú±£´æÍ¨Ñ¶ÐèÇóʱ£¬´Ëʱ·Ö¹«Ë¾×°±¸¿ÉºÍ×ܲ¿µÄ·À»ðǽ½¨ÉèIPSec VPNÅþÁ¬ÒÔ½ÓÈë×ܲ¿ÄÚ²¿Ö÷»ú¡£¶øSSL VPN¸ü¶àµØÓ¦ÓÃÔÚÆóÒµÓû§µÄÒÆ¶¯Ô¶³Ì°ì¹«½ÓÈëÖУ¬Òƶ¯°ì¹«Ö°Ô±Í¨¹ýSSL VPNÅþÁ¬À´½ÓÈë×ܲ¿°ì¹«ÏµÍ³£¬ÓʼþϵͳµÈ¡£
ͼ2-4 ·À»ðǽIPSec VPN½ÓÈëʾÒâͼ
2.2.2 Çå¾²¹¥»÷Ìá·À
·À»ðǽµÄÇå¾²¹¥»÷Ìá·ÀÖ÷ÒªÊǶÔÓ¦ÓòãµÄӪҵʵÑé±£»¤£¬ÒÔ×èÖ¹±¨ÎÄÊܵ½Çå¾²Ë𺦡£Çå¾²¹¥»÷Ìá·ÀÖ÷Òª¿ÉÒÔ·ÖΪÈýÖÖÀàÐÍ£º
¡ñ²¡¶¾·À»¤£º·À»ðǽһÑùƽ³£ÓÐÄÚÖ÷À²¡¶¾¿â£¬¶ÔľÂí²¡¶¾¡¢È䳿²¡¶¾µÈ³£¼û²¡¶¾Îļþ¾ÙÐмì²â£¬Ê¹µÃЯ´ø²¡¶¾µÄ±¨ÎÄÎÞ·¨½ÓÈëÄÚ²¿ÍøÂç¡£
¡ñÈëÇÖ·ÀÓù£º·À»ðǽÈëÇÖ·ÀÓù¹¦Ð§Í¨¹ýÔ¤ÏȽç˵µÄ·ÀÓù¹æÔò£¬¶Ô½øÈë·À»ðǽµÄ±¨ÎÄ»áÓëÈëÇÖ·ÀÓùÌØÕ÷¿âÏàÆ¥Å䣬ÒÔ´ËÀ´µÖÓù³£¼ûµÄ¹¥»÷ÐÐΪ¡£
¡ñ¾Ü¾ø·þÎñ¹¥»÷£¨DoS£¬Denial of Service£©Í¨¹ýδÍê³ÉµÄTCP/IPÇëÇóÅþÁ¬´ó×ÚÕ¼ÓÃÖ÷»ú»á»°×ÊԴʹÖ÷»ú×îÖÕÍ߽⣬¶ø·À»ðǽ»áÕë¶ÔÕâЩ²»Õý³£µÄTCP/IPÅþÁ¬¾ÙÐÐ¼à¿Ø£¬²¢É趨ÅþÁ¬ÊýãÐÖµ£¬Ò»µ©½ÓÈëÅþÁ¬ÊýÁè¼Ý¸ÃãÐÖµ¾Í»á¹Ø±ÕËüÃÇ£¬´Ó¶øµÖÓùÍⲿDoSµÄ¹¥»÷¡£
2.2.3 Ë«»úÈȱ¸
ÓÉÓÚ·À»ðǽ¶à°²ÅÅÓÚÆóÒµÍøÂçµÄ³ö¿Ú£¬ÄÚÍâÍøÖ®¼äµÄÓªÒµ¶¼ÒªÍ¨¹ý·À»ðǽ¾ÙÐÐת·¢¡£Èô·À»ðǽ·ºÆðå´»ú½«Ôì³ÉÓªÒµÖÐÖ¹£¬Òò´Ë£¬·À»ðǽµÄ¿É¿¿ÐÔ¾ÍÏԵøñÍâÖ÷Òª¡£ÎªÁ˸üºÃµØÓ¦¶Ôµ¥»ú×°±¸ÔËÐеÄΣº¦£¬·À»ðǽͨ¹ýʹÓÃË«»úÈȱ¸ÊÖÒÕʵÏÖÈßÓ๦Ч£¬ÀàËÆÓÚÐéÄâ·ÓÉÈßÓàÐÒ飨VRRP£¬Virtual Router Redundancy Protocol£©£¬Õþ¸®ÓòÍøÄڼ縺·ÓÉת·¢¹¦Ð§µÄ×°±¸Ê§Ð§ºó£¬Áíһ̨½«×Ô¶¯½ÓÊÜ£¬´Ó¶øÊµÏÖIP·ÓɵÄÈȱ¸·ÝÓëÈÝ´í¡£Ë«»úÈȱ¸ÊÖÒÕ¿ÉÒÔ½«Ò»×é·À»ðǽÐéÄâ³Éһ̨·À»ðǽ¡£ÆäÖУ¬½öÓÐһ̨·À»ðǽ¿ÉÒÔ´¦ÓÚÔ˶¯£¬³ÆÎªÖ÷×°±¸£¨Active£©£¬ÆäÓà³ÆÎª±¸×°±¸£¨Backup£©¡£·À»ðǽ¿Éͨ¹ý´ËÊÖÒÕʵÏÖ½«ÉèÖúͻỰ±í£¨ÐÒéµÄÅþÁ¬×´Ì¬±í£©ÐÅÏ¢µÄͬ²½£¬ÈôÖ÷·À»ðǽ±¬·¢¹ÊÕÏ£¬±¸·À»ðǽ¿ÉÒÔÆ½»¬µÄ½ÓÌæ£¬°ü¹ÜÍøÂçµÄÎȹÌÔËÐС£
ͼ2-5 ·À»ðǽÖ÷±¸Çл»Ê¾Òâͼ
3 ×ܽá
ÔÚ»¥ÁªÍøÈÕÒæÉú³¤µÄ½ñÌ죬¿ª·ÅÊ½ÍøÂçÊܵ½µÄÇå¾²ÍþвÈÕÒæÔö¶à£¬ÎªÁËÌá¸ßÍøÂçµÄÇå¾²ÐÔ£¬Ô½À´Ô½¶àµÄÓû§Ñ¡ÔñÁ˰²ÅÅ·À»ðǽ¡£Í¨¹ý¶Ô·À»ðǽ¹¦Ð§µÄÎÞаÔËÓ㬿ÉÒÔÓÐÓõذü¹ÜÍøÂçÇå¾²ºÍÐÅÏ¢Çå¾²£¬°ü¹ÜÍøÂçÕý³£ÔËÐУ¬ÎªÈËÃÇÌṩÓÅÒìµÄÉÏÍøÇéÐΡ£