97¹ú¼Ê

Àë±ðÔËάÄÚÚ§ È«ÓòЭͬÌáЧ Ø­ 97¹ú¼ÊÍøÂçÔËά°ü¹ÜÂÄÀú·ÖÏí»á
Ô¤Ô¼Ö±²¥
ÎÞ¸Ð×¼Èë ÈËÎïͳ¹Ü Ø­ RG-SAM+5.X ÐÂÒ»´ú¸ßУAIÈÏ֤ƽ̨Ðû²¼
Ô¤Ô¼Ö±²¥
97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾
²úÆ·
< ·µ»ØÖ÷²Ëµ¥
²úÆ·ÖÐÐÄ
²úÆ·
½â¾ö¼Æ»®
< ·µ»ØÖ÷²Ëµ¥
½â¾ö¼Æ»®ÖÐÐÄ
ÐÐÒµ
ºÏ×÷»ï°é
·µ»ØÖ÷²Ëµ¥
Ñ¡ÔñÇøÓò/ÓïÑÔ
97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾
97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾ 97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾

Õ¾µã¼äIPSec VPNÍøÂçÊÖÒÕÉî¶ÈÆÊÎö

¡¾IPSec VPN¡¿±¾ÎÄÊ×ÏÈͨ¹ýÊáÀíIPSec VPNÖи÷ÊÖÒÕµÄÓÃ;¼°Ö®¼äµÄ¹ØÁª¹ØÏµ×ÊÖú¸÷ÈËÃ÷È·ÊÖÒÕÔ­Àí £¬Æä´ÎΪ¸÷ÈËÏÈÈÝIPSec VPNµÄһЩ¸ß¼¶¹¦Ð§ £¬×îºóΪ¸÷ÈË·ÖÏíµä·¶Êµ¼ù³¡¾°ºÍ¹ÊÕÏÅŲéÒªÁì¡£

  • 97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾

    Ðû²¼Ê±¼ä£º2020-07-01

  • 97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾

    µã»÷Á¿£º

  • 97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾

    µãÔÞ£º

·ÖÏíÖÁ

97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾
97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾
97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾

ÎÒÏë̸ÂÛ

±¾ÎÄ×÷ÕߣºÌï˼Ñî 

97¹ú¼ÊÍøÂçÊÖÒÕ·þÎñ²¿»¥ÁªÍø·þÎñÖÐÐÄ

ǰÑÔ

ÔÚÉÏһƪ¡¶VPNÊÖÒÕdz̸֮ÔõÑù°²ÅÅÔ¶³Ì°ì¹«ÍøÂç¡·ÖÐ £¬×÷ÕßΪ¸÷ÈË·ÖÏíÁ˶˵½Õ¾µãVPNÊÖÒÕ £¬¸ÃÊÖÒÕÖ÷ҪʹÓÃÔÚÔ¶³Ì°ì¹«Ö°Ô±ºÍÆóÒµÍøÂ绥ͨ³¡¾° £¬¶øÕ¾µãµ½Õ¾µãVPNÊÖÒÕ³£ÓÃÓÚ×ܲ¿Óë·ÖÖ§Ö®¼äµÄÍøÂ绥ͨ £¬Í¨¹ýʹÓÃ×éÖ¯ÒÑÓеĻ¥ÁªÍø³ö¿Ú £¬Ê¹ÓÃVPNÊÖÒÕÐéÄâ³öÒ»Ìõ“רÏß” £¬½«ÆóÒµµÄ·ÖÖ§»ú¹¹ºÍ×ܲ¿ÅþÁ¬ÆðÀ´ £¬×é³ÉÒ»¸ö´óµÄ¾ÖÓòÍø¡£Õ¾µãµ½Õ¾µãVPNÖ÷Òª°üÀ¨IPSec VPN¡¢L2TP VPN¡¢L2TP over IPSec VPN¡¢GRE VPN¡¢GRE over IPSec VPN¡¢SSL VPNµÈ¡£IPSec VPNÊÖÒÕÒòÆä¾ßÓÐÇå¾²ÐԸߡ¢±¾Ç®µÍ¡¢°²ÅÅÎÞа¡¢À©Õ¹ÐԺõÈÓŵã £¬ÒѳÉΪÆóÒµÕ¾µã¼äVPN°²ÅŵĵڠһÊÖÒÕÑ¡Ôñ¡£

IPSec VPN²»ÊÇÒ»¸öµ¥¶ÀµÄЭÒé £¬¶øÊÇÓÉÒ»×éЭÒé×é³É £¬ÒòÆä°üÀ¨µÄÊÖÒÕ¶à¡¢ÊÖÒռ乨Áª¹ØÏµ¶à £¬Ðí¶àÅóÙ­ÎÞ·¨°ÑIPSec VPNÊÖÒÕÃ÷ȷ͸¡£±¾ÎÄÊ×ÏÈͨ¹ýÊáÀíIPSec VPNÖи÷ÊÖÒÕµÄÓÃ;¼°Ö®¼äµÄ¹ØÁª¹ØÏµ×ÊÖú¸÷ÈËÃ÷È·ÊÖÒÕÔ­Àí £¬Æä´ÎΪ¸÷ÈËÏÈÈÝIPSec VPNµÄһЩ¸ß¼¶¹¦Ð§ £¬×îºóΪ¸÷ÈË·ÖÏíµä·¶Êµ¼ù³¡¾°ºÍ¹ÊÕÏÅŲéÒªÁ졣ϣÍû±¾ÎÄÄܹ»×ÊÖúÁÐλ¶ÁÕß°ÑIPSec VPNÊÖÒÕѧ͸¡¢ÓÃÃ÷È· £¬ÄÍÐĶÁÍêÕâÆªÎÄÕÂÏàÐÅÄã»áÓÐ·×ÆçÑùµÄÊÕ»ñ¡£

97¹ú¼ÊÖ§³ÖIPSec VPNµÄ×°±¸ÓÐÐí¶àÖÖ £¬²î±ð×°±¸¶Ô¸÷IPSec VPNÊÖÒÕµÄÖ§³ÖÇéÐÎÂÔÓвî±ð £¬±¾ÎÄÒÔ97¹ú¼ÊÍø¹Ø×°±¸ÎªÀý¸ø¸÷È˽â˵ £¬Èç¶ÁÕßʹÓÃÆäËû×°±¸»¶Ó­ÁªÏµ97¹ú¼Ê¹¤³Ìʦ»òµ½97¹ú¼Ê¹ÙÍøÅÌÎÊ £¬Ð»Ð»¡£

 

97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾

ͼ1£º³£¼ûÆóÒµVPN½ÓÈëÍØÆËÄ£×Ó

IPSec VPN»ù´¡²ÎÊý

IPSecÖÐͨѶ˫·½½¨ÉèµÄÅþÁ¬½Ð×öÇå¾²¹ØÁª£¨IPSec SA£© £¬Ë«·½Í¨¹ý²ÎÊýЭÉÌÍê³ÉIPSec SA½¨Éèºó £¬Í¨¹ýIPSec SA´«Êä¼ÓÃܵÄÊý¾Ý±¨ÎľÙÐÐͨѶ¡£ÒÔÊÇÁ½¸ö¶ÔµÈÌå¼äÒªÏëͨ¹ýIPSec VPNͨѶ £¬Ê×ÏÈÒª½¨ÉèIPSec SA¡£ÔÚ¾ÙÐÐIPSec SA½¨Éèʱ¶ÔµÈÌå¼äÒª¾ÙÐÐIPSec SA²ÎÊýЭÉÌ £¬Á½Í·²ÎÊýÏàͬʱ²Å»á½¨ÉèÀֳɡ£

 

97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾

ͼ2£ºIPSec VPN»ù´¡²ÎÊý

IPSec SAÌìÉú·½·¨

ÊÖ¶¯Ö¸¶¨ÌìÉúIPSec SA

¶ÔµÈÌåͨ¹ýÊÖ¶¯Ö¸¶¨IPSec SAЭÉ̲ÎÊýÌìÉúIPSec SA £¬IPSec SA½¨ÉèºóûÓÐÉúÑÄÖÜÏÞÆÚÖÆ £¬ÓÀ²»¹ýÆÚ £¬³ý·ÇÊÖ¹¤É¾³ý £¬Òò´Ë±£´æÇå¾²Òþ»¼¡£Ò»Ñùƽ³£ÍƼöÔÚ¶ÔµÈÌåÊýÄ¿½ÏÉÙÇÒÎÞ·¨Í¨¹ýIKEЭÉ̽¨ÉèIPSec SA³¡¾°ÏÂʹÓá£

IKEЭÉÌÌìÉúIPSec SA

IKEÓÃÓÚ¶¯Ì¬½¨É貢ʵʱά»¤IPSec SA¡£IKEͨ¹ýÁ½¸ö½×¶ÎÀ´½¨ÉèIPSec SA £¬µÚÒ»½×¶ÎÊ×ÏÈҪЭÉ̽¨ÉèIKE SA £¬µÚ¶þ½×¶Îͨ¹ýIKE SAЭÉ̽¨ÉèIPSec SA¡£

IKEЭÉÌÌìÉúIPSec SA±ÈÊÖ¶¯Ö¸¶¨ÌìÉúIPSec SA±£´æÒÔÏÂÓÅÊÆ£º

  1. ÊÊÓó¡¾°¸»ºñ£ºÊÖ¶¯Ö¸¶¨·½·¨±ØÐè¶ÔµÈÌåÁ½Í·¶¼ÓÐÀο¿µÄ¹«ÍøIPµØÖ· £¬ÈçÒ»¶Ë¶ÔµÈÌå¹«ÍøIPµØÖ·²»Àο¿±ØÐèʹÓÃIKEЭÉÌ·½·¨£»
  2. ½µµÍÉèÖÃÖØÆ¯ºó£ºÊÖ¶¯Ö¸¶¨·½·¨ÐèÒªÊÖ¶¯ÉèÖÃSPI¡¢ÃÜÔ¿µÈÐÅÏ¢ £¬ÔÚ¶ÔµÈÌå½Ï¶àµÄ³¡¾°ÉèÖÃÁ¿½Ï´ó¶øÎ´±ãÓÚά»¤ £¬IKEЭÉÌ·½·¨»áͨ¹ýIKE SAÀ´ÌìÉúºÍά»¤ÕâЩÐÅÏ¢ £¬½µµÍÉèÖÃÖØÆ¯ºó¼°Î¬»¤±¾Ç®£»
  3. Ìá¸ßÇå¾²ÐÔ£ºÊÖ¶¯Ö¸¶¨·½·¨½¨ÉèµÄIPSec SAÃÜÔ¿ÊǾ²Ì¬µÄ £¬½¨ÉèºóÓÀ²»¹ýÆÚ £¬IKEЭÉÌ·½·¨»áͨ¹ýIKE SAÌìÉúÃÜÔ¿ £¬²¢ÇÒÉúÃüÖÜÆÚµ½ÆÚºó¾ÙÐÐÀÏ»¯ÖØÐÂÌìÉú £¬Ìá¸ßÁËÇå¾²ÐÔ¡£

СÌáÐÑ£ºIKEЭÒéÏÖÔÚÓÐÁ½¸ö°æ±¾IKEv1ÓëIKEv2 £¬IKEv1ÏÖÔÚ½ÏΪ³£Óà £¬IKEv2ÓëIKEv1ÉèÖÃ˼Ð÷Ïàͬ £¬µ«Ð­ÉÌÀú³ÌÓëIKEv1ÓÐËùÇø±ð £¬±¾ÎIJ»¾ÙÐнâ˵ £¬±¾ÎÄÖзºÆðµÄIKEЭÒé¾ù´ú±íIKEv1¡£

IKE SAЭÉÌģʽ

ÔÚIKEµÚÒ»½×¶ÎÓÐÁ½ÖÖЭÉÌģʽ¿ÉЭÉ̽¨ÉèIKE SA £¬Ö÷ģʽ»òÕßÒ°Âùģʽ¡£Ö÷ģʽʹÓÃ6¸ö±¨ÎÄÍê³ÉIKE SA½¨Éè £¬¶øÒ°ÂùģʽʹÓÃ3¸ö±¨ÎÄÍê³ÉIKE SA½¨Éè £¬ÓëÖ÷ģʽÏà±ÈÒ°ÂùģʽïÔÌ­½»»¥±¨ÎÄÊýÄ¿´Ó¶ø¼ÓËÙÁËЭÉÌËÙÂÊ £¬µ«Òò¶ÔÉí·ÝÐÅÏ¢ºÍÈÏÖ¤ÐÅÏ¢½ÓÄÉÃ÷ÎĽ»»¥ £¬Ã»ÓмÓÃܱ£»¤ £¬Òò´Ë²»Çå¾² £¬×÷Õß²»ÍƼöʹÓá£

Ò°ÂùģʽÔçÆÚÉè¼ÆÖ÷ҪΪ½â¾öÒ»¶Ë¶ÔµÈÌå¹«ÍøIPµØÖ·²»Àο¿»òûÓй«ÍøIPµØÖ·µÄ³¡¾°ÏÂÖ÷ģʽÎÞ·¨Ð­É̽¨ÉèµÄÎÊÌâ £¬ÏÖÔÚ¸ÃÎÊÌâ¿ÉÒÔͨ¹ý“¶¯Ì¬ËíµÀ”µÄÒªÁì¸üºÃµØ½â¾ö £¬ÒÔÊÇÍÆ¼öʹÓÃÖ÷ģʽ¡£Ò°Âùģʽ½öÔÚ97¹ú¼Ê×°±¸Óë·Ç97¹ú¼Ê×°±¸½¨ÉèIPSecʹÓÃÖ÷ģʽÎÞ·¨½¨ÉèÀÖ³ÉÏÂʹÓà £¬ÆäËû³¡¾°Ï²»ÍƼöʹÓá£

СÌáÐÑ£ºÖ÷ģʽºÍÒ°Âùģʽ±¨ÎĽ»»¥ÏêϸÁ÷³Ì²Î¿¼±¾ÎÄ¡¶IKE±¨ÎĽ»»¥ÖªÊ¶µã»ØÊס·Ð¡½Ú¡£

IKE SA¼ÓÃÜ·½·¨

IKE SAʹÓöԳƼÓÃÜËã·¨¶ÔÊý¾Ý¾ÙÐмÓÃÜÏ¢ÕùÃÜ £¬°ü¹ÜÊý¾ÝµÄÇå¾²ÐÔ¡£³£ÓõĶԳƼÓÃÜËã·¨ÓÐDES¡¢3DES¡¢AESµÈ £¬ÕâÈý¸ö¼ÓÃÜËã·¨µÄÇå¾²ÐÔÓɸߵ½µÍÒÀ´ÎÊÇ£ºAES¡¢3DES¡¢DES £¬Çå¾²ÐԸߵļÓÃÜË㷨ʵÏÖ»úÖÆÖØ´ó £¬ÔËËãËÙÂÊÂý¡£


97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾

ͼ3£ºIKE SA³£ÓõĶԳƼÓÃÜËã·¨

IKE SAÑéÖ¤·½·¨

IKE SAʹÓÃÑéÖ¤Ëã·¨¶Ô±¨ÎÄÍêÕûÐÔ¼°ÈªÔ´Õýµ±ÐÔ¾ÙÐÐÑéÖ¤ £¬³£ÓõÄÑéÖ¤·½·¨ÓÐMD5-HMAC¡¢SHA1-HMACµÈ £¬ÊÇHASHËã·¨ºÍHMACÁ½ÖÖÊÖÒÕµÄÍŽá¡£

HASHË㷨ʵÏÖ¶Ô±¨ÎľÙÐÐÍêÕûÐÔУÑé £¬³£¼ûµÄHASHËã·¨ÓÐMD5¡¢SHA1µÈ £¬MD5Ëã·¨µÄÅÌËãËÙÂʱÈSHA1Ëã·¨¿ì £¬¶øSHA1Ëã·¨µÄÇ徲ǿ¶È±ÈMD5Ëã·¨¸ß¡£

97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾
ͼ4£ºIKE SA³£ÓõÄHASHËã·¨

 

HMAC(Hash-based Message Authentication Code)ÊÇÒ»ÖÖ»ùÓÚHASHËã·¨ºÍÃÜÔ¿¾ÙÐÐÐÂÎÅÈÏÖ¤µÄÒªÁì £¬ÊµÏÖ¶Ô±¨ÎÄȪԴµÄÕýµ±ÐÔ¾ÙÐÐÑéÖ¤ £¬¿ÉÒÔÓëÈκÎHASHËã·¨À¦°óʹÓá£

IKE SAÃÜÔ¿ÌìÉú·½·¨

DH£¨Diffie-Hellman£©ÊÇÒ»ÖַǶԳÆÃÜÔ¿Ëã·¨ £¬Ë«·½¿Éͨ¹ý½ö½»Á÷һЩÊý¾Ý £¬¼´¿ÉÅÌËã³öË«·½µÄÃÜÔ¿ £¬²¢ÇÒµÚÈý·½²¶»ñÁËÆäÖеÄÊý¾ÝÒ²ÎÞ·¨ÅÌËãµÃ³öÃÜÔ¿¡£DH±¬·¢µÄÃÜÔ¿ÓÃÓÚÊý¾Ý±¨ÎļÓÃܼ°HMACÅÌËãÖС£¶ÔµÈÌåÁ½Í·DH×鳤¶ÈÐèÖ¸¶¨ÎªÏàͬ £¬³£ÓõÄDH×鳤¶ÈÓÐ768bit£¨DH1£©¡¢1024bit£¨DH2£©¡¢1536bit£¨DH5£©¡£

IKE SAÈÏÖ¤·½·¨

ÔÚIKE¶ÔµÈÌåÖ®¼äÔÚ¾ÙÐÐÉí·ÝÈÏ֤ʱ֧³Öͨ¹ýÔ¤¹²ÏíÃÜÔ¿ÈÏÖ¤ºÍÊý×ÖÖ¤ÊéÈÏÖ¤Á½ÖÖ·½·¨À´È·È϶Է½Éí·ÝµÄÕýµ±ÐÔ¡£Ô¤¹²ÏíÃÜÔ¿ÈÏÖ¤ÉèÖýÏÁ¿¼òÆÓ £¬ÊÇÏÖÔÚ½ÏÁ¿³£ÓõÄÈÏÖ¤·½·¨¡£Êý×ÖÖ¤ÊéÈÏÖ¤Ïà¶ÔÖØ´óµ«Çå¾²ÐÔ½Ï¸ß £¬¶ÔÇå¾²ÐÔÓнϸßÒªÇóµÄ³¡¾°½¨ÒéʹÓÃÊý×ÖÖ¤ÊéÈÏÖ¤¡£

IKE SAÉí·Ý±êʶ

ÔÚIKE SAЭÉÌÖжԵÈÌåË«·½ÐèҪʹÓÃÏàͬÀàÐ͵ÄÉí·Ý±êʶ £¬³£ÓõÄÉí·Ý±êʶÀàÐÍÓÐ4ÖÖ £¬IPµØÖ·¡¢FQDN¡¢USER-FQDN¡¢Ö¤ÊéDN¡£Êý×ÖÖ¤ÊéÈÏ֤ͨ³£½ÓÄÉÖ¤ÊéDN×÷ΪÍâµØÉí·Ý±êʶ¡£Ô¤¹²ÏíÃÜÔ¿ÈÏ֤ĬÈϽÓÄÉIPµØÖ·×÷ΪÍâµØÉí·Ý±êʶ £¬Í¨³£Ê¹ÓýÓÄÉIPµØÖ·×÷ΪÍâµØÉí·Ý±êʶ¼´¿É £¬ÈôÓöµ½ÒÔÏÂÁ½ÖÖ³¡¾°ÍƼöÊÖ¶¯ÐÞ¸ÄʹÓÃFQDN»òUSER-FQDN£º

  1. ÈôÊǶԵÈÌåµÄIPµØÖ·ÎªÓòÃûÐÎʽ £¬Ôò±ØÐèʹÓÃFQDN»òUSER-FQDN£»
  2. ¶ÔµÈÌå½Ï¶àµÄ³¡¾°Ï £¬½¨Òé½ÓÄÉFQDN»òUSER-FQDN £¬±ãÓÚÇø·Öÿ¸ö¶ÔµÈÌå¶ÔÓ¦ÊÇÄĸö·ÖÖ§¡£

СÌáÐÑ£ºÉí·Ý±êʶÀàÐÍÓëЭÉÌģʽÎÞ¹Ø £¬ÈκÎÉí·Ý±êʶÔÚÖ÷ģʽ»òÒ°ÂùģʽϾù¿ÉʹÓà £¬ºÃ±ÈÖ÷ģʽʹÓÃFQDN×÷ΪÉí·Ý±êʶ»òÒ°ÂùģʽʹÓÃIP×÷ΪÉí·Ý±êʶ¶¼¿ÉÕý³£Íê³ÉIKE SAЭÉÌ £¬Ö»Òª¶ÔµÈÌåÁ½Í·Ê¹ÓÃÏàͬÀàÐÍÉí·Ý±êʶ¼´¿É¡£

IKE SAÉúÃüÖÜÆÚ

ÓÉÓÚIPSec SAЭÉÌÊǽ¨ÉèÔÚIKE SA»ù´¡É쵀 £¬Òò´ËΪ½ÚԼЭÉÌIPSec SAµÄʱ¼ä £¬Ò»Ñùƽ³£IKE SAÉúÃüÖÜÆÚ£¨60Ãëµ½86400Ãë £¬È±Ê¡86400Ã룩±ÈIPSec SAÉúÃüÖÜÆÚÉèÖõij¤¡£µ±ÔÚ¾ÙÐÐIKE SAЭÉÌʱ £¬Á½Í·¶ÔµÈÌåÉèÖõÄIKE SAÉúÃüÖÜÆÚ²î±ð²»»áÔì³ÉIKE SAЭÉÌʧ°Ü £¬¶øÊ¹Ó÷¢ËÍ·½ÉèÖõÄIKE SAÉúÃüÖÜÆÚ¡£

IPSec SAÇ徲ЭÒé

AHºÍESPÊÇIPSecµÄÁ½ÖÖÇ徲ЭÒé £¬ÓÃÓÚʵÏÖIPSecÔÚÉí·ÝÈÏÖ¤ºÍÊý¾Ý¼ÓÃܵÄÇå¾²»úÖÆ¡£

  1. AHЭÒ飨Authentication Header £¬Ð­ÒéºÅ51£© £¬Ö÷ÒªÌṩÊý¾ÝÍêÕûÐÔÈ·ÈÏ¡¢Êý¾ÝȪԴȷÈÏ¡¢·ÀÖØ·ÅµÈÇå¾²ÌØÕ÷¡£AHͨ³£Ê¹ÓÃMD5-HMAC¡¢SHA-HMACµÈÑéÖ¤Ë㷨ʵÏÖÊý¾ÝÍêÕûÐÔ£»
  2. ESPЭÒ飨Encapsulating Security Payload £¬Ð­ÒéºÅ50£© £¬Ö÷ÒªÌṩÊý¾ÝÍêÕûÐÔÈ·ÈÏ¡¢Êý¾Ý¼ÓÃÜ¡¢Êý¾ÝȪԴȷÈÏ¡¢·ÀÖØ·ÅµÈÇå¾²ÌØÕ÷¡£ESPͨ³£Ê¹ÓÃDES¡¢3DES¡¢AESµÈ¼ÓÃÜË㷨ʵÏÖÊý¾Ý¼ÓÃÜ £¬Ê¹ÓÃMD5-HMAC¡¢SHA-HMACµÈÑéÖ¤Ë㷨ʵÏÖÊý¾ÝÍêÕûÐÔ¡£ESPЭÒéÏà±ÈAHЭÒé¶àÁËÖ§³ÖÊý¾Ý¼ÓÃÜ¡¢Ö§³ÖNAT´©Ô½£¨NAT-T£©ÕâÁ½´óÓÅÊÆ £¬ÊÇÏÖÔÚIPSec VPN½ÏΪ³£ÓõÄÇ徲ЭÒé¡£

IPSec SA·âװģʽ

·âװģʽÓÃÓÚÖ¸¶¨Ç徲ЭÒéµÄ·âװλÖà £¬Óд«ÊäģʽºÍËíµÀģʽÁ½ÖÖ£º

 

´«Ê䣨Transport£©Ä£Ê½Ï £¬AHÍ·»òESPÍ·²åÈëIPÍ·ºÍ´«Êä²ãЭÒéÖ®¼ä £¬²»¸Ä±äԭʼ±¨ÎÄÍ· £¬IPSecËíµÀµÄÔ´ºÍÄ¿µÄµØÖ·¾ÍÊÇ×îÖÕͨѶ˫·½µÄÔ´ºÍÄ¿µÄµØÖ· £¬ÒÔÊÇÖ»Äܱ£»¤Á½¸öIPSec¶ÔµÈÌåÖ®¼äÏ໥ͨѶ¡£Ò»Ñùƽ³£³£ÓÃÔÚʹÓÃGRE over IPSec»òL2TP over IPSecЭÒéµÄ³¡¾°ÖÐ £¬Ê¹ÓÃIPSecËíµÀ±£»¤GRE»òL2TP¶ÔµÈÌ壻

ËíµÀ£¨Tunnel£©Ä£Ê½Ï £¬AHÍ·»òESPÍ·²åÔÚԭʼIPͷ֮ǰ £¬²¢ÇÒÐÂÌìÉúÒ»¸öIPÍ··ÅÔÚESPÍ·»òAHͷ֮ǰ £¬ÒÔÊÇ¿ÉÒÔ±£»¤Á½¸öIPSec¶ÔµÈÌå±³ºóÁ½¸öÍøÂçÖ®¼ä¾ÙÐÐͨѶ¡£Ò»Ñùƽ³£³£ÓÃÔÚÕ¾µã¼äÍøÂ绥ͨµÄ³¡¾° £¬Êǽϳ£Óõķâװģʽ¡£

 

97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾

ͼ5£ºAHЭÒéÁ½ÖÖ·âװģʽϱ¨ÎÄ·â×°

97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾

ͼ6£ºESPЭÒéÁ½ÖÖ·âװģʽϱ¨ÎÄ·â×°

IPSec SA¼ÓÃÜ·½·¨

IPSec SAÖ§³ÖʹÓõļÓÃÜ·½·¨ÓëIKE SAÏàͬ £¬²Î¿¼±¾ÎÄ¡¶IKE SA¼ÓÃÜ·½·¨¡·Ð¡½Ú¡£

IPSec SAÑéÖ¤·½·¨

IPSec SAÖ§³ÖʹÓõÄÑéÖ¤·½·¨ÓëIKE SAÏàͬ £¬²Î¿¼±¾ÎÄ¡¶IKE SAÑéÖ¤·½·¨¡·Ð¡½Ú¡£

IPSec SAÉúÃüÖÜÆÚ

ΪÁËÈ·±£Çå¾² £¬IPSec SA½«ÔÚ¾­ÓÉһ׼ʱ¼ä£¨0»òÕß120Ãëµ½86400Ãë £¬È±Ê¡3600Ã룩»òµÖ´ïÒ»¶¨Í¨Ñ¶Á¿£¨0»ò2560KBµ½536870912KB £¬È±Ê¡4608000KB£©Ö®ºó³¬Ê± £¬ÖØÐÂЭÉÌ £¬²¢Ê¹ÓÃеÄÃÜÔ¿¡£ÐÂIPSec SAÔÚÉúÃüÖÜÆÚ³¬Ê±Ç°30Ãë £¬»ò¾­ÓÉÕâÌõËíµÀµÄÊý¾ÝͨѶÁ¿¾àÉúÃüÖÜÆÚÉÐÓÐ256KBʱ×îÏȾÙÐÐЭÉÌ£¨Æ¾Ö¤ÄĸöÏȱ¬·¢£©¡£

µ±ÔÚ¾ÙÐÐIPSec SAЭÉÌʱ £¬Á½Í·¶ÔµÈÌåÉèÖõÄIPSec SAÉúÃüÖÜÆÚ²î±ð²»»áÔì³ÉIPSec SAЭÉÌʧ°Ü £¬¶øÊ¹ÓÃÌᳫ·½ÉèÖõÄIPSec SAÉúÃüÖÜÆÚ¡£

IPSec VPN¸ß¼¶¹¦Ð§

 

97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾

ͼ7£ºIPSec VPN¸ß¼¶¹¦Ð§

IPSecËíµÀ×Ô¶¯½¨É裨Set Autoup£©

ÔÚĬÈÏÇéÐÎÏÂIPSec VPNÉèÖÃÍêºó £¬IPSecËíµÀÊÇÓÉÊý¾ÝÁ÷Á¿´¥·¢ºóÔÙЭÉ̽¨ÉèµÄ¡£ÉèÖÃIPSecËíµÀ×Ô¶¯½¨É裨Set Autoup£©¹¦Ð§ºó £¬²»¹ÜÊÇ·ñÓÐÊý¾ÝÁ÷Á¿´¥·¢ £¬Ö»ÒªÍê³ÉIPSec VPNÉèÖúó £¬×°±¸»á×ÔÐд¥·¢IPSecËíµÀ½¨Éè¡£

IPSecÁ´Â·Ì½²â£¨DPD/Track£©

DPD̽²â

ÔÚĬÈÏÇéÐÎÏÂÁ½Í·×°±¸½¨ÉèIPSecËíµÀºó £¬µ±Ò»¶Ë×°±¸·ºÆðÎÊÌâºóÁíÒ»¶ËÊÇÎÞ¸ÐÖªµÄ £¬ÁíÒ»¶Ë×°±¸»á¼ÌÐøÍ¨¹ýIPSecËíµÀ·¢ËÍÊý¾Ý¸ø¹ÊÕÏ×°±¸µ¼ÖÂÊý¾ÝͨѶÖÐÖ¹¡£´ËʱÐèÒªÆÚ´ýIPSecËíµÀ³¬Ê±ºó¹ÊÕÏIPSecËíµÀ²Å»áÖÐÖ¹£¨IPSecËíµÀĬÈϳ¬Ê±Ê±¼äΪһСʱ£©¡£

DPD̽²âÊÇͨ¹ý·¢ËÍIKE±¨ÎÄÈ·È϶ԶË×°±¸IKE SA״̬ÊÇ·ñÕý³£µÄÒ»ÖÖ̽²â»úÖÆ £¬µ±Ì½²âµ½¶Ô¶ËIKE״̬Ò쳣ʱ £¬»áɨ³ý¶ÔÓ¦µÄIKE SAºÍIPSec SA¡£

DPD̽²âÓÐÁ½ÖÖÊÂÇéģʽ£º

  1. °´Ðè̽²âģʽ£¨On-demand£© £¬ÔÚÁè¼ÝÉèÖõÄ̽²âʱ¼äÇÒµ±ÓÐÊý¾Ý±¨ÎÄ·¢ËÍʱ £¬×°±¸»á·¢ËÍDPDÐÂÎÅ̽²â¶Ô¶Ë×°±¸ÊÇ·ñÕý³£ £¬µ±·¢ËÍ5´ÎDPDÐÅÏ¢¶¼Ã»ÓÐÊÕµ½¶Ô¶Ë×°±¸»Ø°ü»áÒÔΪ¶Ô¶ËIKE SA״̬Òì³££»
  2. ÖÜÆÚ̽²âģʽ£¨Periodic£© £¬×°±¸»áƾ֤ÉèÖõÄ̽²âʱ¼äÖÜÆÚÐÔ×Ô¶¯·¢ËÍ DPD ÐÂÎÅ̽²â¶Ô¶Ë×°±¸ÊÇ·ñÕý³£ £¬µ±·¢ËÍ5´ÎDPDÐÅÏ¢¶¼Ã»ÓÐÊÕµ½¶Ô¶Ë×°±¸»Ø°ü»áÒÔΪ¶Ô¶ËIKE SA״̬Òì³£¡£

×ÛÉϰ´Ðè̽²âģʽ±ÈÖÜÆÚ̽²âģʽ»á·¢Ë͸üÉÙµÄDPDÐÅÏ¢Ö»ÔÚÊý¾Ý±¨ÎÄ·¢ËÍǰ¼ì²â £¬½ÚÔ¼×°±¸×ÊÔ´¼°ÍøÂç´ø¿í×ÊÔ´ £¬µ«Ì½²âµ½¶Ô¶Ë×°±¸¹ÊÕϵÄʱ¼ä»á±ÈÖÜÆÚ̽²âģʽ³¤ £¬¶ÁÕ߯¾Ö¤×ÔÉíÓªÒµÐèÇóʹÓúÏÊÊģʽ¾ÙÐÐDPD̽²â¼´¿É¡£

Track̽²â

DPD̽²âͨ¹ý½»»¥IKE±¨ÎÄ¿ÉÒÔ̽²âµ½¶Ô¶Ë×°±¸IKE SA״̬ÊÇ·ñÕý³£ £¬¹ØÓÚIKE SA״̬Õý³£¶øIPSec SAÒì³£µÄÇéÐÎDPD̽²â¾ÍÎÞÄÜΪÁ¦ÁË £¬ÕâÖÖÇéÐÎͬÑù»áµ¼ÖÂIPSecÓªÒµÖÐÖ¹¡£Track̽²âͨ¹ý°´ÆÚ·¢ËÍICMP»òUDP±¨ÎÄ̽²âIPSecÏÖʵӪҵÊÇ·ñÕý³£ £¬µ±Track̽²âµ½IPSecӪҵǷºàʱ»áɨ³ý¶ÔÓ¦µÄIPSec SA¾ÙÐÐÖØÐÂЭÉÌ¡£Ò»Ñùƽ³£½¨ÒéͬʱÉèÖÃDPD̽²âºÍTrack̽²â¡£

NAT´©Ô½£¨NAT-T£©

×°±¸Ä¬ÈÏ¿ªÆôNAT´©Ô½£¨NAT-T£©¹¦Ð§ £¬ÓÃÓÚ½â¾öµ±½¨ÉèIPSec VPNµÄÁ½Ì¨×°±¸¼ä±£´æNAT×°±¸ESP±¨ÎÄÎÞ·¨Í¨¹ýµÄÎÊÌâ¡£ESP±¨Í··â×°ÔÚIP²ãÖ®ÉÏIPЭÒéºÅ50ÒÔÊÇÎÞ·¨Í¨¹ýNAT×°±¸, NAT-Tͨ¹ýÔÚESP±¨ÎÄÖ®ÉÏ·â×°4500¶Ë¿ÚµÄUDP±¨Í·½â¾ö¸ÃÎÊÌâ¡£

 

97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾

ͼ8£ºNAT-TÔÚESP±¨ÎÄÖ®ÉÏ·â×°4500¶Ë¿ÚµÄUDP±¨Í·

 

ÔÚIKEЭÉ̵ĵÚÒ»½×¶Î£¨Ö÷ģʽµÚ1¡¢2¸ö±¨ÎÄ¡¢Ò°ÂùģʽµÚ1¸ö±¨ÎÄ£©Ö§³ÖNAT-TµÄ×°±¸ÔÚ·¢ËÍIKE±¨ÎÄÖлáЯ´øÒ»¸ö¼ì²âNAT-TÄÜÁ¦µÄVendor IDµÄÔØºÉ £¬µ±Á½Í·×°±¸¶¼Ð¯´øÕâ¸ö×ֶξͻá¾ÙÐÐNAT-TЭÉÌ¡£µ±¼ì²âË«·½¶¼Ö§³ÖNAT-TËæºó£¨Ö÷ģʽµÚ3¡¢4¸ö±¨ÎÄ¡¢Ò°ÂùģʽµÚ2¸ö±¨ÎÄ£©»áЯ´øÒ»¸öNAT-DµÄÔØºÉ £¬NAT-DÔØºÉÖаüÀ¨×Ô¼ºIPµØÖ·ºÍ¶Ë¿ÚµÄHASHÖµ £¬¶Ô¶Ë×°±¸ÊÕµ½Õâ¸öÖµºó»áÓëÊÕµ½µÄÏÖʵIPµØÖ·ºÍ¶Ë¿ÚµÄHashÖµ×ö±ÈÕÕ £¬ÈôÊÇÏàͬ˵Ã÷ÖÐÐÄδ¾­ÓÉNAT×°±¸ £¬²»È»ËµÃ÷ÖÐÐľ­ÓÉNAT×°±¸¡£ÈôÊÇNAT-T¼ì²âµ½ÖÐÐľ­ÓÉNAT×°±¸ £¬×°±¸»áÔÚÏÂÒ»¸ö±¨ÎÄ£¨Ö÷ģʽµÚ5¡¢6±¨ÎÄ¡¢Ò°ÂùģʽµÚ3¸ö±¨ÎÄ£©×îÏȲåÈëÒ»¸ö4500¶Ë¿ÚµÄUDP±¨Í· £¬ÖÁ´ËNAT-TÊÂÇ鿢ʡ£

 

¶¯Ì¬ËíµÀ£¨Crypto Dynamic-map£©

Ò»Ñùƽ³£ÇéÐÎÏ £¬Á½Í·×°±¸¶¼Óй«ÍøIPµØÖ· £¬ÉèÖÃʱÁ½Í·Ê¹Óþ²Ì¬ËíµÀµÄ·½·¨Ï໥ָ¶¨¶Ô¶Ë¹«ÍøIPµØÖ·¾ÙÐÐIPSecËíµÀ½¨Éè¡£ÏÖʵÖÐÒ²»áÓöµ½Ò»¶ËÓй«ÍøIPµØÖ·¶øÁíÒ»¶ËûÓÐÀο¿¹«ÍøIPµØÖ·»òÕßûÓй«ÍøIPµØÖ·µÄÇéÐÎ £¬ÕâÖÖÇéÐÎÁ½Í·¶¼Ê¹Óþ²Ì¬ËíµÀµÄ·½·¨¾ÍÎÞ·¨½¨ÉèIPSecËíµÀ¡£Ê¹Óö¯Ì¬ËíµÀÉèÖÃʱÎÞÐèÖ¸¶¨¶Ô¶ËIPµØÖ·¡¢Éí·Ý¡¢¸ÐÐËȤÁ÷µÈ £¬Óй«ÍøIPµØÖ·µÄÒ»¶ËʹÓö¯Ì¬ËíµÀ¿É½â¾öÁíÒ»¶ËûÓÐÀο¿¹«ÍøIPµØÖ·»òÕßûÓй«ÍøIPµØÖ·µÄÎÊÌâ¡£±ðµÄ £¬ÈôÊDZ¾¶ËÐèÒª½¨Éè´ó×ÚIPSec VPNµÄ¶ÔµÈÌåÒ²¿ÉÒÔʹ¶¯Ì¬ËíµÀ £¬ïÔÌ­ÉèÖÃÁ¿¡£

·´Ïò·ÓÉ×¢È루RRI£©

ÔÚÍê³ÉIPSecÉèÖúóÎÒÃÇÒªÉèÖÃÈ¥Íù¶Ô¶ËÍø¶ÎµÄ¾²Ì¬Â·ÓÉ £¬ÈôÊǸÐÐËȤÁ÷Íø¶Î½Ï¶àÈËΪÊÖ¶¯ÉèÖü°Î¬»¤ÕâЩ·ÓÉÓÐЩδ±ã¡£¿ªÆô·´Ïò·ÓÉ×¢È빦Ч £¬µ±IPSecËíµÀ½¨ÉèÍê³Éºó»á×Ô¶¯±¬·¢ÏìÓ¦µÄ¾²Ì¬Â·ÓÉ£¨Ä¿µÄµØÖ·ÊǶԶ˸ÐÐËȤÁ÷µØÖ· £¬ÏÂÒ»ÌøÊǶԶ˹«ÍøIPµØÖ·£©×¢È뵽·ÓɱíÖÐ £¬µ±IPSecËíµÀ¶Ï¿ªºó¶ÔÓ¦µÄ·ÓÉÒ²»áÏûÊÅ¡£·´Ïò·ÓÉ»áÍŽáIPSecËíµÀµÄ½¨ÉèÐÅÏ¢×Ô¶¯ÌìÉú¶Ô¶ËÍø¶Î·ÓÉ £¬ÕâÑù±ãÄܶ¯Ì¬µØÍê³É·ÓɵÄÌí¼ÓÓëɾ³ý £¬×èÖ¹´ó×ÚÈËΪÉèÖᣱðµÄ £¬ÔÚ×°±¸±£´æ¶à³ö¿Ú³¡¾° £¬»¹¿ÉÒÔͨ¹ý·´Ïò·ÓÉ×¢Èë¾ÙÐжà³ö¿ÚÉÏIPSecËíµÀµÄÇл»¡£

ʹÓö¯Ì¬Â·ÓÉЭÒ飨GRE over IPSec/L2TP over IPSec£©

ÔÚIPSecÍøÂçÖÐÖ»ÄÜͨ¹ý¾²Ì¬Â·ÓÉÉèÖõ½¶Ô¶ËÍø¶ÎµÄ·ÓÉ £¬IPSec¶ÔµÈÌåÖ®¼äÎÞ·¨Ê¹Óö¯Ì¬Â·ÓÉЭÒé¾ÙÐзÓÉѧϰ £¬·´Ïò·ÓÉ×¢Èë¿ÉÒÔÒ»¶¨Ë®Æ½ÉϽâ¾ö¸ÐÐËȤÁ÷Íø¶Î½Ï¶à¡¢¾²Ì¬Â·ÓÉά»¤±¾Ç®¸ßµÄÎÊÌâ £¬ÈôÊÇÏ£ÍûʹÓö¯Ì¬Â·ÓÉЭÒé½øÒ»²½½µµÍ·ÓÉά»¤±¾Ç® £¬¿ÉÒÔʹÓÃGRE over IPSec VPN»òÕßL2TP over IPSec VPN £¬Ê¹ÓÃGRE»òÕßL2TP½¨ÉèVPNËíµÀ £¬È»ºóÔÙʹÓÃIPSecËíµÀ±£»¤Õâ¸öVPNËíµÀ £¬´Ëʱ¼È°ü¹ÜÁËÊý¾ÝÇå¾²ÓÖ¿ÉÔÚVPNËíµÀÁ½Í·Ê¹Óö¯Ì¬Â·ÓÉЭÒé¡£

IPSec VPNµä·¶³¡¾°

µ¥×ܲ¿µ¥·ÖÖ§³¡¾°

³¡¾°¢ñ

97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾

97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾

 

97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾

ͼ9£ºIPSec VPNµä·¶³¡¾°¢ñÉèÖñí

³¡¾°¢ò

97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾

97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾

 

97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾

ͼ10£ºIPSec VPNµä·¶³¡¾°¢òÉèÖñí

 

³¡¾°¢ó

97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾

97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾

 

97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾

ͼ11£ºIPSec VPNµä·¶³¡¾°¢óÉèÖñí

³¡¾°¢ô

97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾

97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾

 

97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾

ͼ12£ºIPSec VPNµä·¶³¡¾°¢ôÉèÖñí

 

³¡¾°¢õ

97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾

97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾

 

97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾

ͼ13£ºIPSec VPNµä·¶³¡¾°¢õÉèÖñí

³¡¾°¢ö

97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾

97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾

 

97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾

ͼ14£ºIPSec VPNµä·¶³¡¾°¢öÉèÖñí

¶à×ܲ¿¶à·ÖÖ§³¡¾°

³¡¾°¢÷

97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾

97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾

 

97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾

ͼ15£ºIPSec VPNµä·¶³¡¾°¢÷ÉèÖÃͼ

³¡¾°¢ø

97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾

97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾

 

97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾

ͼ16£ºIPSec VPNµä·¶³¡¾°¢øÉèÖñí

 

ÔÚ¶à×ܲ¿¶à·ÖÖ§³¡¾°Ï £¬³ýÒÔÉÏÁ½ÖÖµ¥³ö¿ÚÇéÐÎÍâ £¬¶à³ö¿ÚµÄÇéÐÎÒ²½ÏΪ³£¼û¡£°²ÅÅʱ½«ÒÔÉÏÁ½ÖÖ¶à×ܲ¿¶à·ÖÖ§³¡¾°Óëµ¥×ܲ¿µ¥·ÖÖ§³¡¾°Ï¶à³ö¿ÚµÄÇéÐÎÍŽáʹÓü´¿É £¬±¾Õ²»ÔÚ׸Êö¡£

IPSec VPN¹ÊÕÏÅŲé

IPSec VPNʹÓÃʱÄÑÃâ»áÓöµ½ËíµÀ½¨Éèʧ°ÜµÄÇéÐΡ£Ò»Ñùƽ³£IPSec VPN¹ÊÕϿɷÖΪÈýÀࣺIKE SA½¨Éèʧ°Ü£»IPSec SA½¨Éèʧ°Ü£»IPSec SA½¨ÉèÀֳɵ«Êý¾ÝÇ·ºà¡£ÔÚÓöµ½IPSec VPN¹ÊÕÏʱ¶ÁÕß¿ÉÉó²éÌᳫ·½ºÍÎüÊÕ·½×´Ì¬²¢¶ÔºÃ±ÈÏÂIPSec¶ÔµÈÌå״̬ÆÊÎöͼȷÈÏÊôÓÚÄÄÀà¹ÊÕÏ £¬È»ºóƾ֤ÿÀà¹ÊÕϳ£¼ûÔµ¹ÊÔ­ÓɾÙÐÐÅŲé¡£

 

97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾

ͼ17£ºÉó²éIPSec¶ÔµÈÌå״̬

97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾

18£ºIPSec¶ÔµÈÌå״̬ÆÊÎö

IKE±¨ÎĽ»»¥ÖªÊ¶µã»ØÊ×

ÔÚÆÊÎöÿÀà¹ÊÕϳ£¼û±¬·¢Ôµ¹ÊÔ­ÓÉǰ £¬×÷ÕßÊ×ÏÈ´ø¸÷ÈË»ØÊ×ÏÂIKE±¨ÎĽ»»¥ÇéÐÎ £¬Ö»ÓÐÖªµÀÁËÿ¸ö±¨ÎÄÔÚ½»»¥Ê²Ã´ÄÚÈÝ £¬ÔÚÓöµ½IPSec½¨ÉèÍ£ÁôÔÚijһ½×¶Îʱ £¬ÎÒÃDzÅÖªµÀÅŲéµÄÆ«Ïò¡£IKEͨ¹ýÁ½¸ö½×¶ÎÀ´½¨ÉèIPSec SA £¬µÚÒ»½×¶Î½ÓÄÉÖ÷ģʽ»òÕßÒ°Âùģʽ½¨ÉèIKE SA £¬µÚ¶þ½×¶Î½ÓÄÉ¿ìËÙģʽ½¨ÉèIPSec SA¡£

IKEµÚÒ»½×¶Î£¨Ö÷ģʽ£©£º

  1. µÚ1-2¸ö±¨ÎÄЯ´øIKEÕ½ÂÔ £¬¾ÙÐÐIKEÕ½ÂÔЭÉÌ £¬IKEÕ½ÂÔ°üÀ¨£º¼ÓÃÜËã·¨¡¢HASHËã·¨¡¢DH×é¡¢ÑéÖ¤·½·¨¡¢IKE SAÉúÃüÖÜÆÚ £¬
  2. µÚ3-4¸ö±¨ÎÄЯ´øDHËã·¨ÐèÒªµÄÖÊÁÏ £¬¾ÙÐÐDHËã·¨ÅÌËãÌìÉúÃÜÔ¿ £¬
  3. µÚ5-6¸ö±¨ÎÄЯ´øÉí·ÝÐÅÏ¢¼°ÈÏÖ¤ÐÅÏ¢ £¬¾ÙÐжԵÈÌå¼äµÄÈÏÖ¤ £¬Íê³ÉIKE SA½¨Éè¡£ÐèÒª×¢ÖØµÄÊÇ´ÓµÚ5¸ö±¨ÎÄ×îÏÈÓÐÁ½´¦×ª±ä £¬µÚÒ»µãÊDZ¨ÎÄ×îÏȱ»¼ÓÃܱ£»¤ £¬µÚ¶þµãÊÇÈôÊDZ£´æNAT´©Ô½µÄÇéÐÎUDP¶Ë¿ÚºÅ½«´Ó500±äΪ4500

 

97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾

ͼ19£ºÖ÷ģʽ±¨ÎĽ»»¥Á÷³Ì¼°¶ÔµÈÌå״̬

 

IKEµÚÒ»½×¶Î£¨Ò°Âùģʽ£©£º

  1. µÚ1¸ö±¨ÎÄ·¢ËÍ·½·¢ËÍIKEÕ½ÂÔ¡¢DHËã·¨ÐèÒªµÄÖÊÁÏ¡¢Éí·ÝÐÅÏ¢ £¬IKEÕ½ÂÔ°üÀ¨£º¼ÓÃÜËã·¨¡¢HASHËã·¨¡¢DH×é¡¢ÑéÖ¤·½·¨¡¢IKE SAÉúÃüÖÜÆÚ£»
  2. µÚ2¸ö±¨ÎÄÎüÊÕ·½»ØÓ¦Æ¥ÅäµÄIKEÕ½ÂÔ £¬·¢ËÍDHËã·¨ÐèÒªµÄÖÊÁÏ¡¢Éí·ÝÐÅÏ¢¡¢ÈÏÖ¤ÐÅÏ¢£»
  3. µÚ3¸ö±¨ÎÄ·¢ËÍ·½·¢ËÍÈÏÖ¤ÐÅÏ¢Íê³ÉÈÏÖ¤ £¬Íê³ÉIKE SA½¨Éè¡£ÈôÊDZ£´æNAT´©Ô½µÄÇéÐδӸñ¨ÎÄ×îÏÈUDP¶Ë¿ÚºÅ´Ó500±äΪ4500¡£

 

97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾

ͼ20£ºÒ°Âùģʽ±¨ÎĽ»»¥Á÷³Ì¼°¶ÔµÈÌå״̬

 

IKEµÚ¶þ½×¶Î£º

  1. µÚ1¸ö±¨ÎÄ·¢ËÍ·½·¢ËÍIPSecת»»¼¯¡¢¸ÐÐËȤÁ÷ £¬¾ÙÐÐIPSec²ÎÊýЭÉÌ £¬IPSecת»»¼¯°üÀ¨£º·âװģʽ¡¢Ç徲ЭÒé¡¢¼ÓÃÜËã·¨¡¢HASHËã·¨¡¢IPSec SAÉúÃüÖÜÆÚ¡£ÁíÍâÈôÊÇ¿ªÆôPFS»¹»áЯ´øDHËã·¨ÐèÒªµÄÖÊÁÏ £¬¾ÙÐÐDHËã·¨ÅÌËãÌìÉúеÄÃÜÔ¿£»
  2. µÚ2¸ö±¨ÎÄÎüÊÕ·½»ØÓ¦Æ¥ÅäµÄIPSecÕ½ÂÔ¡¢¸ÐÐËȤÁ÷¼°DHËã·¨ÐèÒªµÄÖÊÁÏ(ÈôÊÇ¿ªÆôPFS)£»
  3. µÚ3¸ö±¨ÎÄ·¢ËÍ·½¾ÙÐÐЧ¹ûÈ·ÈÏ £¬Ë«·½Íê³ÉIPSec SA½¨Éè¡£

СÌáÐÑ£ºPFS£¨Perfect Forward Secrecy£©ÊÇÒ»ÖÖÇå¾²»úÖÆ £¬Ä¬ÈÏÇéÐÎÏÂIPSec SA»áÖ±½ÓʹÓÃIKE SAͨ¹ýDHËã·¨ÌìÉúµÄÃÜÔ¿ £¬¿ªÆôPFS»úÖÆºó £¬IPSec SAÔÚЭÉÌʱ»áÔÚÌØÊâ¾ÙÐÐÒ»´ÎDHÃÜÔ¿½»Á÷Ëã·¨ £¬Ê¹IPSec SAʹÓõÄÃÜÔ¿ÓëIKE SAʹÓõÄÃÜÔ¿²î±ð £¬Ìá¸ßÇå¾²ÐÔ¡£

IKE SA½¨Éèʧ°Ü¹ÊÕÏÔµ¹ÊÔ­ÓÉÆÊÎö

97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾

ͼ21£ºIKEµÚÒ»½×¶ÎIKE SA½¨Éèʧ°ÜÔµ¹ÊÔ­ÓÉ

 

IPSec SA½¨Éèʧ°Ü¹ÊÕÏÔµ¹ÊÔ­ÓÉÆÊÎö

97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾

ͼ22£ºIKEµÚ¶þ½×¶ÎIPSec SA½¨Éèʧ°ÜÔµ¹ÊÔ­ÓÉ

 

IPSec SA½¨ÉèÀֳɵ«Êý¾ÝÇ·ºà¹ÊÕÏÔµ¹ÊÔ­ÓÉÆÊÎö

97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾

ͼ23£ºIPSec SA½¨ÉèÀֳɵ«Êý¾ÝÇ·ºàÔµ¹ÊÔ­ÓÉ

 

дÔÚ×îºó

±¾ÎÄÍŽáÀíÂÛÓëʵ¼ù¶ÔIPSec VPNÊÖÒյĻù´¡²ÎÊý¡¢¸ß¼¶¹¦Ð§¡¢µä·¶Êµ¼ù³¡¾°¼°¹ÊÕÏÅŲéÒªÁì¾ÙÐÐÁËÉîÈëÆÊÎö¡£³ýÁËIPSec VPNÊÖÒÕÍâL2TP over IPSec VPN¡¢GRE over IPSec VPNµÈVPNÊÖÒÕÒ²ÔÚһЩÆóÒµÕ¾µã¼äʹÓà £¬¶ÁÕß¿ÉÍŽ᱾ÎÄ˼Ð÷×ÔÐоÙÐÐÑо¿¡£

Ïà¹ØÍÆ¼ö£º

¸ü¶àÊÖÒÕ²©ÎÄ

ÈκÎÐèÒª £¬ÇëÁªÏµ97¹ú¼Ê

97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾

·µ»Ø¶¥²¿

ÊÕÆð
97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾ ÎĵµAIÖúÊÖ
97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾ ÎĵµÆÀ¼Û
¸Ã×ÊÁÏÊÇ·ñ½â¾öÁËÄúµÄÎÊÌ⣿
Äú¶ÔÄ¿½ñÒ³ÃæµÄÖª×ã¶ÈÔõÑù£¿
²»Õ¦µÎ
ºÜÊǺÃ
ÄúÖª×ãµÄÔµ¹ÊÔ­ÓÉÊÇ£¨¶àÑ¡£©£¿
Äú²»Öª×ãµÄÔµ¹ÊÔ­ÓÉÊÇ£¨¶àÑ¡£©£¿
ÄúÊÇ·ñÉÐÓÐÆäËûÎÊÌâ»ò½¨Ò飿
ΪÁË¿ìËÙ½â¾ö²¢»Ø¸´ÄúµÄÎÊÌâ £¬Äú¿ÉÒÔÁôÏÂÁªÏµ·½·¨
ÓÊÏä
ÊÖ»úºÅ
ллÄúµÄ·´À¡£¡
97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾
97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾
97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾
ÇëÑ¡Ôñ·þÎñÏîÄ¿
¹Ø±Õ×Éѯҳ
ÊÛǰ×Éѯ ÊÛǰ×Éѯ
ÊÛǰ×Éѯ
ÊÛºó·þÎñ ÊÛºó·þÎñ
ÊÛºó·þÎñ
Òâ¼û·´Ïì Òâ¼û·´Ïì
Òâ¼û·´Ïì
¸ü¶àÁªÏµ·½·¨
ÍøÕ¾µØÍ¼