GA»Æ½ð¼×

¡°¼«¼ò¡±»ÀР¡¤ È«ÓòÖÇÁª Ø­ GA»Æ½ð¼×м«¼òÁ캽ÏÂÒ»´úÐ£Ô°Íø½¨Éè×êÑлá
date
Ô¤Ô¼Ö±²¥
ÎÞ¸Ð×¼Èë ÈËÎïͳ¹Ü Ø­ RG-SAM+5.X ÐÂÒ»´ú¸ßУAIÈÏ֤ƽ̨°ä²¼
date
Ô¤Ô¼Ö±²¥
GA»Æ½ð¼×¡¤(Öйú¼¯ÍÅ)¹Ù·½ÍøÕ¾
²úÆ·
< ·µ»ØÖ÷²Ëµ¥
²úÆ·ÖÐÐÄ
²úÆ·
½â¾ö¹æ»®
< ·µ»ØÖ÷²Ëµ¥
½â¾ö¹æ»®ÖÐÐÄ
ÐÐÒµ
ºÏ×÷ͬ°é
·µ»ØÖ÷²Ëµ¥
Ñ¡ÔñÇøÓò/˵»°
GA»Æ½ð¼×¡¤(Öйú¼¯ÍÅ)¹Ù·½ÍøÕ¾
GA»Æ½ð¼×¡¤(Öйú¼¯ÍÅ)¹Ù·½ÍøÕ¾ GA»Æ½ð¼×¡¤(Öйú¼¯ÍÅ)¹Ù·½ÍøÕ¾

Õ¾µã¼äIPSec VPNÍøÂç¼¼ÊõÉî¶È½âÎö

¡¾IPSec VPN¡¿±¾ÎÄÊ×ÏÈͨ¹ýÊáÀíIPSec VPNÖи÷¼¼ÊõµÄÓô¦¼°Ö®¼äµÄ¹ØÁª¹ØÏµÔ®ÊÖ¸÷ÈËÀí½â¼¼ÊõµÀÀí £¬Æä´ÎΪ¸÷È˽éÉÜIPSec VPNµÄһЩ¸ß¼¶Ö°ÄÜ £¬×îºóΪ¸÷ÈË·ÖÏíµäÐÍʵ¼Ê³¡¾°ºÍ¹ÊÕÏÅŲ鲽Öè ¡£

  • GA»Æ½ð¼×¡¤(Öйú¼¯ÍÅ)¹Ù·½ÍøÕ¾

    °ä²¼¹¦·ò£º2020-07-01

  • GA»Æ½ð¼×¡¤(Öйú¼¯ÍÅ)¹Ù·½ÍøÕ¾

    µã»÷Á¿£º

  • GA»Æ½ð¼×¡¤(Öйú¼¯ÍÅ)¹Ù·½ÍøÕ¾

    µãÔÞ£º

·ÖÏíÖÁ

GA»Æ½ð¼×¡¤(Öйú¼¯ÍÅ)¹Ù·½ÍøÕ¾
GA»Æ½ð¼×¡¤(Öйú¼¯ÍÅ)¹Ù·½ÍøÕ¾
GA»Æ½ð¼×¡¤(Öйú¼¯ÍÅ)¹Ù·½ÍøÕ¾

ÎÒÏëÆÀÂÛ

±¾ÎÄ×÷ÕߣºÌï˼Ñî 

GA»Æ½ð¼×ÍøÂç¼¼Êõ·þÎñ²¿»¥ÁªÍø·þÎñÖÐÐÄ

ý½é

ÔÚÉÏһƪ¡¶VPN¼¼Êõdz̸֮ÈôºÎ²¿ÊðÔ¶³Ì°ì¹«ÍøÂç¡·ÖÐ £¬×÷ÕßΪ¸÷ÈË·ÖÏíÁ˶˵½Õ¾µãVPN¼¼Êõ £¬¸Ã¼¼ÊõÖØÒªÊ¹ÓÃÔÚÔ¶³Ì°ì¹«ÈËÔ±ºÍÆóÒµÍøÂ绥ͨ³¡¾° £¬¶øÕ¾µãµ½Õ¾µãVPN¼¼Êõ³£ÓÃÓÚ×ܲ¿Óë·ÖÖ§Ö®¼äµÄÍøÂ绥ͨ £¬Í¨¹ýÀûÓÃ×éÖ¯ÒÑÓеĻ¥ÁªÍø³ö¿Ú £¬Ê¹ÓÃVPN¼¼ÊõÐé¹¹³öÒ»Ìõ“רÏß” £¬½«ÆóÒµµÄ·ÖÖ§»ú¹¹ºÍ×ܲ¿ÏÎ½ÓÆðÀ´ £¬×é³ÉÒ»¸ö´óµÄ¾ÖÓòÍø ¡£Õ¾µãµ½Õ¾µãVPNÖØÒªÔ̺¬IPSec VPN¡¢L2TP VPN¡¢L2TP over IPSec VPN¡¢GRE VPN¡¢GRE over IPSec VPN¡¢SSL VPNµÈ ¡£IPSec VPN¼¼ÊõÒòÆäÓµÓа²È«ÐԸߡ¢³É±¾µÍ¡¢²¿Êð½Ã½Ý¡¢À©´óÐԺõÅ×ŵã £¬ÒѳÉΪÆóÒµÕ¾µã¼äVPN²¿ÊðµÄµÚ Ò»¼¼ÊõÑ¡Ôñ ¡£

IPSec VPN²»ÊÇÒ»¸öµ¥¶ÀµÄºÍ̸ £¬¶øÊÇÓÉÒ»×éºÍ̸×é³É £¬ÒòÆäÔ̺¬µÄ¼¼Êõ¶à¡¢¼¼Êõ¼ä¹ØÁª¹ØÏµ¶à £¬ºÃ¶à°éÂÂÎÞ·¨°ÑIPSec VPN¼¼ÊõÀí½â͸ ¡£±¾ÎÄÊ×ÏÈͨ¹ýÊáÀíIPSec VPNÖи÷¼¼ÊõµÄÓô¦¼°Ö®¼äµÄ¹ØÁª¹ØÏµÔ®ÊÖ¸÷ÈËÀí½â¼¼ÊõµÀÀí £¬Æä´ÎΪ¸÷È˽éÉÜIPSec VPNµÄһЩ¸ß¼¶Ö°ÄÜ £¬×îºóΪ¸÷ÈË·ÖÏíµäÐÍʵ¼Ê³¡¾°ºÍ¹ÊÕÏÅŲ鲽Öè ¡£µ«Ô¸±¾ÎÄ¿ÉÄÜÔ®ÊÖ¸÷λ¶ÁÕß°ÑIPSec VPN¼¼Êõѧ͸¡¢ÓÃÁìÂÔ £¬ÄÍÐĶÁÍêÕâÆªÎÄÕÂÏàÐÅÄã»áÓв»Ò»ÑùµÄÊÕ³É ¡£

GA»Æ½ð¼×Ö§³ÖIPSec VPNµÄÉ豸ÓкöàÖÖ £¬·ÖÆçÉ豸¶Ô¸÷IPSec VPN¼¼ÊõµÄÖ§³ÖÇé¿öÂÔÓвî¾à £¬±¾ÎÄÒÔGA»Æ½ð¼×Íø¹ØÉ豸ΪÀý¸ø¸÷È˽â˵ £¬Èç¶ÁÕßʹÓÃÆäËûÉ豸ӭ½ÓÁªÏµGA»Æ½ð¼×¹¤³Ìʦ»òµ½GA»Æ½ð¼×¹ÙÍø²éÎÊ £¬¸Ð¼¤ ¡£

 

GA»Æ½ð¼×¡¤(Öйú¼¯ÍÅ)¹Ù·½ÍøÕ¾

ͼ1£º³£¼ûÆóÒµVPN½ÓÈëÍØÆËÄ£ÐÍ

IPSec VPN»ù´¡²ÎÊý

IPSecÖÐͨѶ˫·½³ÉÁ¢µÄÏνӽÐ×ö°²È«¹ØÁª£¨IPSec SA£© £¬Ë«·½Í¨¹ý²ÎÊýЭÉÌʵÏÖIPSec SA³ÉÁ¢ºó £¬Í¨¹ýIPSec SA´«Êä¼ÓÃܵÄÊý¾Ý±¨ÎĽøÐÐͨѶ ¡£ËùÒÔÁ½¸ö¶ÔµÈÌå¼äÒªÏëͨ¹ýIPSec VPNͨѶ £¬Ê×ÏÈÒª³ÉÁ¢IPSec SA ¡£ÔÚ½øÐÐIPSec SA³ÉÁ¢Ê±¶ÔµÈÌå¼äÒª½øÐÐIPSec SA²ÎÊýЭÉÌ £¬Á½¶Ë²ÎÊýÒ»Ñùʱ²Å»á³ÉÁ¢³É¹¦ ¡£

 

GA»Æ½ð¼×¡¤(Öйú¼¯ÍÅ)¹Ù·½ÍøÕ¾

ͼ2£ºIPSec VPN»ù´¡²ÎÊý

IPSec SAÌìÉú·½Ê½

ÊÖ¶¯Ö¸¶¨ÌìÉúIPSec SA

¶ÔµÈÌåͨ¹ýÊÖ¶¯Ö¸¶¨IPSec SAЭÉ̲ÎÊýÌìÉúIPSec SA £¬IPSec SA³ÉÁ¢ºóûÓÐÉú¼ÆÖÜÆÚÏÞ¶È £¬ÓÀ²»Íâʱ £¬³ý·ÇÊÖ¹¤É¾³ý £¬Òò¶ø´æÔÚ°²È«Òþ»¼ ¡£Í¨³£ÍƼöÔÚ¶ÔµÈÌåÊýÁ¿½ÏÉÙÇÒÎÞ·¨Í¨¹ýIKEЭÉ̳ÉÁ¢IPSec SA³¡¾°ÏÂʹÓà ¡£

IKEЭÉÌÌìÉúIPSec SA

IKEÓÃÓÚ¶¯Ì¬³ÉÁ¢²¢ÊµÊ±ÊØ»¤IPSec SA ¡£IKEͨ¹ýÁ½¸ö½×¶ÎÀ´³ÉÁ¢IPSec SA £¬µÚÒ»½×¶ÎÊ×ÏÈҪЭÉ̳ÉÁ¢IKE SA £¬µÚ¶þ½×¶Îͨ¹ýIKE SAЭÉ̳ÉÁ¢IPSec SA ¡£

IKEЭÉÌÌìÉúIPSec SA±ÈÊÖ¶¯Ö¸¶¨ÌìÉúIPSec SA´æÔÚÒÔÏÂÓÅÊÆ£º

  1. ºÏÓó¡¾°·á˶£ºÊÖ¶¯Ö¸¶¨·½Ê½±ØÐë¶ÔµÈÌåÁ½¶Ë¶¼Óй̶¨µÄ¹«ÍøIPµØÖ· £¬ÈçÒ»¶Ë¶ÔµÈÌå¹«ÍøIPµØÖ·²»¹Ì¶¨±ØÐëʹÓÃIKEЭÉÌ·½Ê½£»
  2. ½µµÍÅäÖø´ÔÓ¶È£ºÊÖ¶¯Ö¸¶¨·½Ê½±ØÒªÊÖ¶¯ÅäÖÃSPI¡¢ÃÜÔ¿µÈÐÅÏ¢ £¬ÔÚ¶ÔµÈÌå½Ï¶àµÄ³¡¾°ÅäÖÃÁ¿½Ï´ó¶ø²»±ãÓÚÊØ»¤ £¬IKEЭÉÌ·½Ê½»áͨ¹ýIKE SAÀ´ÌìÉúºÍÊØ»¤ÕâЩÐÅÏ¢ £¬½µµÍÅäÖø´ÔӶȼ°ÊØ»¤³É±¾£»
  3. Ìá¸ß°²È«ÐÔ£ºÊÖ¶¯Ö¸¶¨·½Ê½³ÉÁ¢µÄIPSec SAÃÜÔ¿ÊǾ²Ì¬µÄ £¬³ÉÁ¢ºóÓÀ²»Íâʱ £¬IKEЭÉÌ·½Ê½»áͨ¹ýIKE SAÌìÉúÃÜÔ¿ £¬²¢ÇÒÐÔÃüÖÜÆÚµ½ÆÚºó½øÐÐÀÏ»¯³ÁÐÂÌìÉú £¬Ìá¸ßÁ˰²È«ÐÔ ¡£

Ó×ÌáÐÑ£ºIKEºÍ̸ĿǰÓÐÁ½¸ö°æ±¾IKEv1ÓëIKEv2 £¬IKEv1Ŀǰ½ÏΪ³£Óà £¬IKEv2ÓëIKEv1ÅäÖÃ˼·һÑù £¬µ«Ð­É̹ý³ÌÓëIKEv1ÓÐËùÇø±ð £¬±¾ÎIJ»½øÐнâ˵ £¬±¾ÎÄÖгöÏÖµÄIKEºÍ̸¾ù´ú±íIKEv1 ¡£

IKE SAЭÉÌģʽ

ÔÚIKEµÚÒ»½×¶ÎÓÐÁ½ÖÖЭÉÌģʽ¿ÉЭÉ̳ÉÁ¢IKE SA £¬Ö÷ģʽ»òÕßÒ°Âùģʽ ¡£Ö÷ģʽʹÓÃ6¸ö±¨ÎÄʵÏÖIKE SA³ÉÁ¢ £¬¶øÒ°ÂùģʽʹÓÃ3¸ö±¨ÎÄʵÏÖIKE SA³ÉÁ¢ £¬ÓëÖ÷ģʽÏà±ÈÒ°ÂùģʽÏ÷¼õ½»»¥±¨ÎÄÊýÁ¿´Ó¶ø¼Ó¿ìÁËЭÉÌ¿ìÂÊ £¬µ«Òò¶ÔÉí·ÝÐÅÏ¢ºÍÈÏÖ¤ÐÅϢѡȡÃ÷ÎĽ»»¥ £¬Ã»ÓмÓÃܱ£»¤ £¬Òò¶ø²»°²È« £¬×÷Õß²»ÍƼöʹÓà ¡£

Ò°ÂùģʽÔçÆÚÉè¼ÆÖØÒªÎª½â¾öÒ»¶Ë¶ÔµÈÌå¹«ÍøIPµØÖ·²»¹Ì¶¨»òûÓй«ÍøIPµØÖ·µÄ³¡¾°ÏÂÖ÷ģʽÎÞ·¨Ð­É̳ÉÁ¢µÄÎÊÌâ £¬Ä¿Ç°¸ÃÎÊÌâÄܹ»Í¨¹ý“¶¯Ì¬Ëí·”µÄ²½Öè¸üºÃµØ½â¾ö £¬ËùÒÔÍÆ¼öʹÓÃÖ÷ģʽ ¡£Ò°Âùģʽ½öÔÚGA»Æ½ð¼×É豸Óë·ÇGA»Æ½ð¼×É豸³ÉÁ¢IPSecʹÓÃÖ÷ģʽÎÞ·¨³ÉÁ¢³É¹¦ÏÂʹÓà £¬ÆäËû³¡¾°Ï²»ÍƼöʹÓà ¡£

Ó×ÌáÐÑ£ºÖ÷ģʽºÍÒ°Âùģʽ±¨ÎĽ»»¥¾ßÌåÁ÷³Ì²Î¿¼±¾ÎÄ¡¶IKE±¨ÎĽ»»¥ÖªÊ¶µã»ØÊס·Ó×½Ú ¡£

IKE SA¼ÓÃÜ·½Ê½

IKE SAʹÓöԳƼÓÃÜËã·¨¶ÔÊý¾Ý½øÐмÓÃܺͽâÃÜ £¬±£ÕÏÊý¾ÝµÄ°²È«ÐÔ ¡£³£ÓõĶԳƼÓÃÜËã·¨ÓÐDES¡¢3DES¡¢AESµÈ £¬ÕâÈý¸ö¼ÓÃÜËã·¨µÄ°²È«ÐÔÓɸߵ½µÍ˳´ÎÊÇ£ºAES¡¢3DES¡¢DES £¬°²È«ÐԸߵļÓÃÜË㷨ʵÏÖ»úÔ츴ÔÓ £¬ÔËËã¿ìÂÊÂý ¡£


GA»Æ½ð¼×¡¤(Öйú¼¯ÍÅ)¹Ù·½ÍøÕ¾

ͼ3£ºIKE SA³£ÓõĶԳƼÓÃÜËã·¨

IKE SAÑéÖ¤·½Ê½

IKE SAʹÓÃÑéÖ¤Ëã·¨¶Ô±¨ÎÄÆëÈ«ÐÔ¼°ÆðÔ´ºÏ·¨ÐÔ½øÐÐÑéÖ¤ £¬³£ÓõÄÑéÖ¤·½Ê½ÓÐMD5-HMAC¡¢SHA1-HMACµÈ £¬ÊÇHASHËã·¨ºÍHMACÁ½ÖÖ¼¼ÊõµÄ½áºÏ ¡£

HASHË㷨ʵÏÖ¶Ô±¨ÎĽøÐÐÆëÈ«ÐÔУÑé £¬³£¼ûµÄHASHËã·¨ÓÐMD5¡¢SHA1µÈ £¬MD5Ëã·¨µÄÍÆËã¿ìÂʱÈSHA1Ëã·¨¿ì £¬¶øSHA1Ëã·¨µÄ°²È«Ç¿¶È±ÈMD5Ëã·¨¸ß ¡£

GA»Æ½ð¼×¡¤(Öйú¼¯ÍÅ)¹Ù·½ÍøÕ¾
ͼ4£ºIKE SA³£ÓõÄHASHËã·¨

 

HMAC(Hash-based Message Authentication Code)ÊÇÒ»ÖÖ»ùÓÚHASHËã·¨ºÍÃÜÔ¿½øÐÐÐÂÎÅÈÏÖ¤µÄ²½Öè £¬ÊµÏÖ¶Ô±¨ÎÄÆðÔ´µÄºÏ·¨ÐÔ½øÐÐÑéÖ¤ £¬Äܹ»ÓëÈκÎHASHËã·¨°ó¸¿Ê¹Óà ¡£

IKE SAÃÜÔ¿ÌìÉú·½Ê½

DH£¨Diffie-Hellman£©ÊÇÒ»ÖַǶԳÆÃÜÔ¿Ëã·¨ £¬Ë«·½¿Éͨ¹ý½ö»¥»»Ò»Ð©Êý¾Ý £¬¼´¿ÉÍÆËã³öË«·½µÄÃÜÔ¿ £¬²¢ÇÒµÚÈý·½²¶»ñÁËÆäÖеÄÊý¾ÝÒ²ÎÞ·¨ÍÆËãµÃ³öÃÜÔ¿ ¡£DH²úÉúµÄÃÜÔ¿ÓÃÓÚÊý¾Ý±¨ÎļÓÃܼ°HMACÍÆËãÖÐ ¡£¶ÔµÈÌåÁ½¶ËDH×鳤¶ÈÐèÖ¸¶¨ÎªÒ»Ñù £¬³£ÓõÄDH×鳤¶Å×Ð768bit£¨DH1£©¡¢1024bit£¨DH2£©¡¢1536bit£¨DH5£© ¡£

IKE SAÈÏÖ¤·½Ê½

ÔÚIKE¶ÔµÈÌåÖ®¼äÔÚ½øÐÐÉí·ÝÈÏ֤ʱ֧³Öͨ¹ýÔ¤¹²ÏíÃÜÔ¿ÈÏÖ¤ºÍÊý×ÖÖ¤ÊéÈÏÖ¤Á½ÖÖ·½Ê½À´È·È϶Է½Éí·ÝµÄºÏ·¨ÐÔ ¡£Ô¤¹²ÏíÃÜÔ¿ÈÏÖ¤ÅäÖñÈÁ¦µ¥Ò» £¬ÊÇĿǰ±ÈÁ¦³£ÓõÄÈÏÖ¤·½Ê½ ¡£Êý×ÖÖ¤ÊéÈÏÖ¤Ïà¶Ô¸´ÔÓµ«°²È«ÐԽϸß £¬¶Ô°²È«ÐÔÓнϸßÒªÇóµÄ³¡¾°½¨ÒéʹÓÃÊý×ÖÖ¤ÊéÈÏÖ¤ ¡£

IKE SAÉí·Ý±êʶ

ÔÚIKE SAЭÉÌÖжԵÈÌåË«·½±ØÒªÊ¹ÓÃÒ»ÑùÀàÐ͵ÄÉí·Ý±êʶ £¬³£ÓõÄÉí·Ý±êʶÀàÐÍÓÐ4ÖÖ £¬IPµØÖ·¡¢FQDN¡¢USER-FQDN¡¢Ö¤ÊéDN ¡£Êý×ÖÖ¤ÊéÈÏ֤ͨ³£Ñ¡È¡Ö¤ÊéDN×÷Ϊ±¾µØÉí·Ý±êʶ ¡£Ô¤¹²ÏíÃÜÔ¿ÈÏ֤ĬÈÏѡȡIPµØÖ·×÷Ϊ±¾µØÉí·Ý±êʶ £¬Í¨³£Ê¹ÓÃѡȡIPµØÖ·×÷Ϊ±¾µØÉí·Ý±êʶ¼´¿É £¬ÈôÓöµ½ÒÔÏÂÁ½ÖÖ³¡¾°ÍƼöÊÖ¶¯Åú¸ÄʹÓÃFQDN»òUSER-FQDN£º

  1. ÈôÊǶԵÈÌåµÄIPµØÖ·ÎªÓòÃû´ó¾Ö £¬Ôò±ØÐëʹÓÃFQDN»òUSER-FQDN£»
  2. ¶ÔµÈÌå½Ï¶àµÄ³¡¾°Ï £¬½¨ÒéѡȡFQDN»òUSER-FQDN £¬±ãÓÚ·Ö±æÃ¿¸ö¶ÔµÈÌå¶ÔÓ¦ÊÇÄĸö·ÖÖ§ ¡£

Ó×ÌáÐÑ£ºÉí·Ý±êʶÀàÐÍÓëЭÉÌģʽÎÞ¹Ø £¬ÈκÎÉí·Ý±êʶÔÚÖ÷ģʽ»òÒ°ÂùģʽϾù¿ÉʹÓà £¬ºÃ±ÈÖ÷ģʽʹÓÃFQDN×÷ΪÉí·Ý±êʶ»òÒ°ÂùģʽʹÓÃIP×÷ΪÉí·Ý±êʶ¶¼¿ÉÕý³£ÊµÏÖIKE SAЭÉÌ £¬Ö»ÓжԵÈÌåÁ½¶ËʹÓÃÒ»ÑùÀàÐÍÉí·Ý±êʶ¼´¿É ¡£

IKE SAÐÔÃüÖÜÆÚ

ÓÉÓÚIPSec SAЭÉÌÊdzÉÁ¢ÔÚIKE SA»ù´¡ÉϵÄ £¬Òò¶øÎª½Ú¼óЭÉÌIPSec SAµÄ¹¦·ò £¬Í¨³£IKE SAÐÔÃüÖÜÆÚ£¨60Ãëµ½86400Ãë £¬È±Ê¡86400Ã룩±ÈIPSec SAÐÔÃüÖÜÆÚÉèÖõij¤ ¡£µ±ÔÚ½øÐÐIKE SAЭÉÌʱ £¬Á½¶Ë¶ÔµÈÌåÉèÖõÄIKE SAÐÔÃüÖÜÆÚ·ÖÆç²»»áÔì³ÉIKE SAЭÉÌʧ°Ü £¬¶øÊ¹Ó÷¢ËÍ·½ÉèÖõÄIKE SAÐÔÃüÖÜÆÚ ¡£

IPSec SA°²È«ºÍ̸

AHºÍESPÊÇIPSecµÄÁ½ÖÖ°²È«ºÍ̸ £¬ÓÃÓÚʵÏÖIPSecÔÚÉí·ÝÈÏÖ¤ºÍÊý¾Ý¼ÓÃܵݲȫ»úÔì ¡£

  1. AHºÍ̸£¨Authentication Header £¬ºÍ̸ºÅ51£© £¬ÖØÒªÌṩÊý¾ÝÆëÈ«ÐÔÈ·ÈÏ¡¢Êý¾ÝÆðÔ´È·ÈÏ¡¢·À³Á·ÅµÈ°²È«¸öÐÔ ¡£AHͨ³£Ê¹ÓÃMD5-HMAC¡¢SHA-HMACµÈÑéÖ¤Ë㷨ʵÏÖÊý¾ÝÆëÈ«ÐÔ£»
  2. ESPºÍ̸£¨Encapsulating Security Payload £¬ºÍ̸ºÅ50£© £¬ÖØÒªÌṩÊý¾ÝÆëÈ«ÐÔÈ·ÈÏ¡¢Êý¾Ý¼ÓÃÜ¡¢Êý¾ÝÆðÔ´È·ÈÏ¡¢·À³Á·ÅµÈ°²È«¸öÐÔ ¡£ESPͨ³£Ê¹ÓÃDES¡¢3DES¡¢AESµÈ¼ÓÃÜË㷨ʵÏÖÊý¾Ý¼ÓÃÜ £¬Ê¹ÓÃMD5-HMAC¡¢SHA-HMACµÈÑéÖ¤Ë㷨ʵÏÖÊý¾ÝÆëÈ«ÐÔ ¡£ESPºÍ̸Ïà±ÈAHºÍ̸¶àÁËÖ§³ÖÊý¾Ý¼ÓÃÜ¡¢Ö§³ÖNAT´©Ô½£¨NAT-T£©ÕâÁ½´óÓÅÊÆ £¬ÊÇĿǰIPSec VPN½ÏΪ³£ÓõݲȫºÍ̸ ¡£

IPSec SA·âװģʽ

·âװģʽÓÃÓÚÖ¸¶¨°²È«ºÍ̸µÄ·â×°µØÎ» £¬Óд«ÊäģʽºÍËí·ģʽÁ½ÖÖ£º

 

´«Ê䣨Transport£©Ä£Ê½Ï £¬AHÍ·»òESPÍ·²åÈëIPÍ·ºÍ´«Êä²ãºÍ̸֮¼ä £¬²»Å¤×ªÔ­Ê¼±¨ÎÄÍ· £¬IPSecËí·µÄÔ´ºÍÖ÷ÕŵØÖ·¾ÍÊÇ×îÖÕͨѶ˫·½µÄÔ´ºÍÖ÷ÕŵØÖ· £¬ËùÒÔÖ»Äܱ£»¤Á½¸öIPSec¶ÔµÈÌåÖ®¼äÏ໥ͨѶ ¡£Í¨¾­³£ÓÃÔÚʹÓÃGRE over IPSec»òL2TP over IPSecºÍ̸µÄ³¡¾°ÖÐ £¬Ê¹ÓÃIPSecËí·±£»¤GRE»òL2TP¶ÔµÈÌ壻

Ëí·£¨Tunnel£©Ä£Ê½Ï £¬AHÍ·»òESPÍ·²åÔÚԭʼIPͷ֮ǰ £¬²¢ÇÒÐÂÌìÉúÒ»¸öIPÍ··ÅÔÚESPÍ·»òAHͷ֮ǰ £¬ËùÒÔÄܹ»±£»¤Á½¸öIPSec¶ÔµÈÌå±³ºóÁ½¸öÍøÂçÖ®¼ä½øÐÐͨѶ ¡£Í¨¾­³£ÓÃÔÚÕ¾µã¼äÍøÂ绥ͨµÄ³¡¾° £¬Êǽϳ£Óõķâװģʽ ¡£

 

GA»Æ½ð¼×¡¤(Öйú¼¯ÍÅ)¹Ù·½ÍøÕ¾

ͼ5£ºAHºÍ̸Á½ÖÖ·âװģʽϱ¨ÎÄ·â×°

GA»Æ½ð¼×¡¤(Öйú¼¯ÍÅ)¹Ù·½ÍøÕ¾

ͼ6£ºESPºÍ̸Á½ÖÖ·âװģʽϱ¨ÎÄ·â×°

IPSec SA¼ÓÃÜ·½Ê½

IPSec SAÖ§³ÖʹÓõļÓÃÜ·½Ê½ÓëIKE SAÒ»Ñù £¬²Î¿¼±¾ÎÄ¡¶IKE SA¼ÓÃÜ·½Ê½¡·Ó×½Ú ¡£

IPSec SAÑéÖ¤·½Ê½

IPSec SAÖ§³ÖʹÓõÄÑéÖ¤·½Ê½ÓëIKE SAÒ»Ñù £¬²Î¿¼±¾ÎÄ¡¶IKE SAÑéÖ¤·½Ê½¡·Ó×½Ú ¡£

IPSec SAÐÔÃüÖÜÆÚ

ΪÁËÈ·±£°²È« £¬IPSec SA½«ÔÚ¾­¹ýÒ»°´¹¦·ò£¨0»òÕß120Ãëµ½86400Ãë £¬È±Ê¡3600Ã룩»ò´ïµ½¿Ï¶¨Í¨Ñ¶Á¿£¨0»ò2560KBµ½536870912KB £¬È±Ê¡4608000KB£©Ö®ºó³¬Ê± £¬³ÁÐÂЭÉÌ £¬²¢Ê¹ÓÃеÄÃÜÔ¿ ¡£ÐÂIPSec SAÔÚÐÔÃüÖÜÆÚ³¬Ê±Ç°30Ãë £¬»ò¾­ÓÉÕâÌõËí·µÄÊý¾ÝͨѶÁ¿¾àÐÔÃüÖÜÆÚ»¹ÓÐ256KBʱÆðÍ·½øÐÐЭÉÌ£¨Æ¾¾ÝÄĸöÏȲúÉú£© ¡£

µ±ÔÚ½øÐÐIPSec SAЭÉÌʱ £¬Á½¶Ë¶ÔµÈÌåÉèÖõÄIPSec SAÐÔÃüÖÜÆÚ·ÖÆç²»»áÔì³ÉIPSec SAЭÉÌʧ°Ü £¬¶øÊ¹ÓÃÌáÒé·½ÉèÖõÄIPSec SAÐÔÃüÖÜÆÚ ¡£

IPSec VPN¸ß¼¶Ö°ÄÜ

 

GA»Æ½ð¼×¡¤(Öйú¼¯ÍÅ)¹Ù·½ÍøÕ¾

ͼ7£ºIPSec VPN¸ß¼¶Ö°ÄÜ

IPSecËí·×Ô¶¯³ÉÁ¢£¨Set Autoup£©

ÔÚĬÈÏÇé¿öÏÂIPSec VPNÅäÖÃÍêºó £¬IPSecËí·ÊÇÓÉÊý¾ÝÁ÷Á¿´¥·¢ºóÔÙЭÉ̳ÉÁ¢µÄ ¡£ÅäÖÃIPSecËí·×Ô¶¯³ÉÁ¢£¨Set Autoup£©Ö°Äܺó £¬²»ÂÛÊÇ·ñº±¼û¾ÝÁ÷Á¿´¥·¢ £¬Ö»ÓÐʵÏÖIPSec VPNÅäÖúó £¬É豸»á×ÔÐд¥·¢IPSecËí·³ÉÁ¢ ¡£

IPSecÁ´Â·Ì½²â£¨DPD/Track£©

DPD̽²â

ÔÚĬÈÏÇé¿öÏÂÁ½¶ËÉ豸³ÉÁ¢IPSecËí·ºó £¬µ±Ò»¶ËÉ豸³öÏÖÎÊÌâºóÁíÒ»¶ËÊÇÎÞ¸ÐÖªµÄ £¬ÁíÒ»¶ËÉ豸»á³ÖÐøÍ¨¹ýIPSecËí··¢ËÍÊý¾Ý¸ø¹ÊÕÏÉ豸µ¼ÖÂÊý¾ÝͨѶÖжÏ ¡£´Ëʱ±ØÒªÆÚ´ýIPSecËí·³¬Ê±ºó¹ÊÕÏIPSecËí·²Å»áÖжϣ¨IPSecËí·ĬÈϳ¬²»¶Ï¼äΪһÓ×ʱ£© ¡£

DPD̽²âÊÇͨ¹ý·¢ËÍIKE±¨ÎÄÈ·È϶ԶËÉ豸IKE SA״̬ÊÇ·ñÕý³£µÄÒ»ÖÖ̽²â»úÔì £¬µ±Ì½²âµ½¶Ô¶ËIKE״̬Ò쳣ʱ £¬»á¶Ï¸ù¶ÔÓ¦µÄIKE SAºÍIPSec SA ¡£

DPD̽²âÓÐÁ½ÖÖ¹¤×÷ģʽ£º

  1. °´Ðè̽²âģʽ£¨On-demand£© £¬ÔÚ³¬¹ýÅäÖõÄ̽²â¹¦·òÇÒµ±º±¼û¾Ý±¨ÎÄ·¢ËÍʱ £¬É豸»á·¢ËÍDPDÐÂÎÅ̽²â¶Ô¶ËÉ豸ÊÇ·ñÕý³£ £¬µ±·¢ËÍ5´ÎDPDÐÅÏ¢¶¼Ã»ÓÐÊÕµ½¶Ô¶ËÉ豸»Ø°ü»áÒÔΪ¶Ô¶ËIKE SA״̬Òì³££»
  2. ÖÜÆÚ̽²âģʽ£¨Periodic£© £¬É豸»áƾ¾ÝÅäÖõÄ̽²â¹¦·òÖÜÆÚÐÔ×Ô¶¯·¢ËÍ DPD ÐÂÎÅ̽²â¶Ô¶ËÉ豸ÊÇ·ñÕý³£ £¬µ±·¢ËÍ5´ÎDPDÐÅÏ¢¶¼Ã»ÓÐÊÕµ½¶Ô¶ËÉ豸»Ø°ü»áÒÔΪ¶Ô¶ËIKE SA״̬Òì³£ ¡£

×ÛÉϰ´Ðè̽²âģʽ±ÈÖÜÆÚ̽²âģʽ»á·¢Ë͸üÉÙµÄDPDÐÅÏ¢Ö»ÔÚÊý¾Ý±¨ÎÄ·¢ËÍǰ¼ì²â £¬½ÚÔ¼É豸×ÊÔ´¼°ÍøÂç´ø¿í×ÊÔ´ £¬µ«Ì½²âµ½¶Ô¶ËÉ豸¹ÊÕϵŦ·ò»á±ÈÖÜÆÚ̽²âģʽ³¤ £¬¶ÁÕ߯¾¾Ý×ÔÉíÒµÎñÐèҪʹÓÃÏàÒËģʽ½øÐÐDPD̽²â¼´¿É ¡£

Track̽²â

DPD̽²âͨ¹ý½»»¥IKE±¨ÎÄÄܹ»Ì½²âµ½¶Ô¶ËÉ豸IKE SA״̬ÊÇ·ñÕý³£ £¬¶ÔÓÚIKE SA״̬Õý³£¶øIPSec SAÒì³£µÄÇé¿öDPD̽²â¾ÍÁ¦Ëù²»¼°ÁË £¬ÕâÖÖÇé¿öͬÑù»áµ¼ÖÂIPSecÒµÎñÖжÏ ¡£Track̽²âͨ¹ý¶¨ÆÚ·¢ËÍICMP»òUDP±¨ÎÄ̽²âIPSecÏÖʵҵÎñÊÇ·ñÕý³£ £¬µ±Track̽²âµ½IPSecÒµÎñ²»Í¨Ê±»á¶Ï¸ù¶ÔÓ¦µÄIPSec SA½øÐгÁÐÂЭÉÌ ¡£Í¨³£½¨ÒéͬʱÅäÖÃDPD̽²âºÍTrack̽²â ¡£

NAT´©Ô½£¨NAT-T£©

É豸ĬÈÏ¿ªÆôNAT´©Ô½£¨NAT-T£©Ö°ÄÜ £¬ÓÃÓÚ½â¾öµ±³ÉÁ¢IPSec VPNµÄÁ½Ì¨É豸¼ä´æÔÚNATÉ豸ESP±¨ÎÄÎÞ·¨Í¨¹ýµÄÎÊÌâ ¡£ESP±¨Í··â×°ÔÚIP²ãÖ®ÉÏIPºÍ̸ºÅ50ËùÒÔÎÞ·¨Í¨¹ýNATÉ豸, NAT-Tͨ¹ýÔÚESP±¨ÎÄÖ®ÉÏ·â×°4500¶Ë¿ÚµÄUDP±¨Í·½â¾ö¸ÃÎÊÌâ ¡£

 

GA»Æ½ð¼×¡¤(Öйú¼¯ÍÅ)¹Ù·½ÍøÕ¾

ͼ8£ºNAT-TÔÚESP±¨ÎÄÖ®ÉÏ·â×°4500¶Ë¿ÚµÄUDP±¨Í·

 

ÔÚIKEЭÉ̵ĵÚÒ»½×¶Î£¨Ö÷ģʽµÚ1¡¢2¸ö±¨ÎÄ¡¢Ò°ÂùģʽµÚ1¸ö±¨ÎÄ£©Ö§³ÖNAT-TµÄÉ豸ÔÚ·¢ËÍIKE±¨ÎÄÖлáЯ´øÒ»¸ö¼ì²âNAT-TÄÜÁ¦µÄVendor IDµÄÔØºÉ £¬µ±Á½¶ËÉ豸¶¼Ð¯´øÕâ¸ö×Ö¶Î¾Í»á½øÐÐNAT-TЭÉÌ ¡£µ±¼ì²âË«·½¶¼Ö§³ÖNAT-TËæºó£¨Ö÷ģʽµÚ3¡¢4¸ö±¨ÎÄ¡¢Ò°ÂùģʽµÚ2¸ö±¨ÎÄ£©»áЯ´øÒ»¸öNAT-DµÄÔØºÉ £¬NAT-DÔØºÉÖÐÔ̺¬×Ô¼ºIPµØÖ·ºÍ¶Ë¿ÚµÄHASHÖµ £¬¶Ô¶ËÉ豸ÊÕµ½Õâ¸öÖµºó»áÓëÊÕµ½µÄÏÖʵIPµØÖ·ºÍ¶Ë¿ÚµÄHashÖµ×ö¶Ô±È £¬ÈôÊÇÒ»Ñù×¢Ã÷ÖÐÑëδ¾­¹ýNATÉ豸 £¬²»È»×¢Ã÷ÖÐÑë¾­¹ýNATÉ豸 ¡£ÈôÊÇNAT-T¼ì²âµ½ÖÐÑë¾­¹ýNATÉ豸 £¬É豸»á±ÉÈËÒ»¸ö±¨ÎÄ£¨Ö÷ģʽµÚ5¡¢6±¨ÎÄ¡¢Ò°ÂùģʽµÚ3¸ö±¨ÎÄ£©ÆðÍ·²åÈëÒ»¸ö4500¶Ë¿ÚµÄUDP±¨Í· £¬ÖÁ´ËNAT-T¹¤×÷ʵÏÖ ¡£

 

¶¯Ì¬Ëí·£¨Crypto Dynamic-map£©

ͨ³£Çé¿öÏ £¬Á½¶ËÉ豸¶¼Óй«ÍøIPµØÖ· £¬ÅäÖÃʱÁ½¶ËʹÓþ²Ì¬Ëí·µÄ·½Ê½Ï໥ָ¶¨¶Ô¶Ë¹«ÍøIPµØÖ·½øÐÐIPSecËí·³ÉÁ¢ ¡£ÏÖʵÖÐÒ²»áÓöµ½Ò»¶ËÓй«ÍøIPµØÖ·¶øÁíÒ»¶ËûÓй̶¨¹«ÍøIPµØÖ·»òÕßûÓй«ÍøIPµØÖ·µÄÇé¿ö £¬ÕâÖÖÇé¿öÁ½¶Ë¶¼Ê¹Óþ²Ì¬Ëí·µÄ·½Ê½¾ÍÎÞ·¨³ÉÁ¢IPSecËí· ¡£Ê¹Óö¯Ì¬Ëí·ÅäÖÃʱÎÞÐèÖ¸¶¨¶Ô¶ËIPµØÖ·¡¢Éí·Ý¡¢¸ÐÐËÖÂÁ÷µÈ £¬Óй«ÍøIPµØÖ·µÄÒ»¶ËʹÓö¯Ì¬Ëí·¿É½â¾öÁíÒ»¶ËûÓй̶¨¹«ÍøIPµØÖ·»òÕßûÓй«ÍøIPµØÖ·µÄÎÊÌâ ¡£´Ë±í £¬ÈôÊDZ¾¶Ë±ØÒª³ÉÁ¢´óÁ¿IPSec VPNµÄ¶ÔµÈÌåÒ²Äܹ»Ê¹¶¯Ì¬Ëí· £¬Ï÷¼õÅäÖÃÁ¿ ¡£

·´Ïò·ÓÉ×¢È루RRI£©

ÔÚʵÏÖIPSecÅäÖúóÎÒÃÇÒªÅäÖÃÈ¥Íù¶Ô¶ËÍø¶ÎµÄ¾²Ì¬Â·ÓÉ £¬ÈôÊǸÐÐËÖÂÁ÷Íø¶Î½Ï¶à±¨´ðÊÖ¶¯ÅäÖü°ÊØ»¤ÕâЩ·ÓÉÓÐЩ²»±ã ¡£¿ªÆô·´Ïò·ÓÉ×¢ÈëÖ°ÄÜ £¬µ±IPSecËí·³ÉÁ¢ÊµÏÖºó»á×Ô¶¯²úÉúÏàÓ¦µÄ¾²Ì¬Â·ÓÉ£¨Ö÷ÕŵØÖ·ÊǶԶ˸ÐÐËÖÂÁ÷µØÖ· £¬ÏÂÒ»ÌøÊǶԶ˹«ÍøIPµØÖ·£©×¢È뵽·ÓɱíÖÐ £¬µ±IPSecËí·¶Ï¿ªºó¶ÔÓ¦µÄ·ÓÉÒ²»áÒþû ¡£·´Ïò·ÓÉ»á½áºÏIPSecËí·µÄ³ÉÁ¢ÐÅÏ¢×Ô¶¯ÌìÉú¶Ô¶ËÍø¶Î·ÓÉ £¬ÕâÑù±ãÄܶ¯Ì¬µØÊµÏÖ·ÓɵÄÔö³¤Óëɾ³ý £¬Ô¤·À´óÁ¿±¨´ðÅäÖà ¡£´Ë±í £¬ÔÚÉ豸´æÔÚ¶à³ö¿Ú³¡¾° £¬»¹Äܹ»Í¨¹ý·´Ïò·ÓÉ×¢Èë½øÐжà³ö¿ÚÉÏIPSecËí·µÄÇл» ¡£

ʹÓö¯Ì¬Â·ÓɺÍ̸£¨GRE over IPSec/L2TP over IPSec£©

ÔÚIPSecÍøÂçÖÐÖ»ÄÜͨ¹ý¾²Ì¬Â·ÓÉÅäÖõ½¶Ô¶ËÍø¶ÎµÄ·ÓÉ £¬IPSec¶ÔµÈÌåÖ®¼äÎÞ·¨Ê¹Óö¯Ì¬Â·ÓɺÍ̸½øÐзÓɽø½¨ £¬·´Ïò·ÓÉ×¢ÈëÄܹ»¿Ï¶¨Ë®Æ½ÉϽâ¾ö¸ÐÐËÖÂÁ÷Íø¶Î½Ï¶à¡¢¾²Ì¬Â·ÓÉÊØ»¤³É±¾¸ßµÄÎÊÌâ £¬ÈôÊǵ«Ô¸Ê¹Óö¯Ì¬Â·ÓɺÍ̸½øÒ»²½½µµÍ·ÓÉÊØ»¤³É±¾ £¬Äܹ»Ê¹ÓÃGRE over IPSec VPN»òÕßL2TP over IPSec VPN £¬Ê¹ÓÃGRE»òÕßL2TP³ÉÁ¢VPNËí· £¬¶øºóÔÙʹÓÃIPSecËí·±£»¤Õâ¸öVPNËí· £¬´Ëʱ¼È±£ÕÏÁËÊý¾Ý°²È«ÓÖ¿ÉÔÚVPNËí·Á½¶ËʹÓö¯Ì¬Â·ÓɺÍ̸ ¡£

IPSec VPNµäÐͳ¡¾°

µ¥×ܲ¿µ¥·ÖÖ§³¡¾°

³¡¾°¢ñ

GA»Æ½ð¼×¡¤(Öйú¼¯ÍÅ)¹Ù·½ÍøÕ¾

GA»Æ½ð¼×¡¤(Öйú¼¯ÍÅ)¹Ù·½ÍøÕ¾

 

GA»Æ½ð¼×¡¤(Öйú¼¯ÍÅ)¹Ù·½ÍøÕ¾

ͼ9£ºIPSec VPNµäÐͳ¡¾°¢ñÅäÖñí

³¡¾°¢ò

GA»Æ½ð¼×¡¤(Öйú¼¯ÍÅ)¹Ù·½ÍøÕ¾

GA»Æ½ð¼×¡¤(Öйú¼¯ÍÅ)¹Ù·½ÍøÕ¾

 

GA»Æ½ð¼×¡¤(Öйú¼¯ÍÅ)¹Ù·½ÍøÕ¾

ͼ10£ºIPSec VPNµäÐͳ¡¾°¢òÅäÖñí

 

³¡¾°¢ó

GA»Æ½ð¼×¡¤(Öйú¼¯ÍÅ)¹Ù·½ÍøÕ¾

GA»Æ½ð¼×¡¤(Öйú¼¯ÍÅ)¹Ù·½ÍøÕ¾

 

GA»Æ½ð¼×¡¤(Öйú¼¯ÍÅ)¹Ù·½ÍøÕ¾

ͼ11£ºIPSec VPNµäÐͳ¡¾°¢óÅäÖñí

³¡¾°¢ô

GA»Æ½ð¼×¡¤(Öйú¼¯ÍÅ)¹Ù·½ÍøÕ¾

GA»Æ½ð¼×¡¤(Öйú¼¯ÍÅ)¹Ù·½ÍøÕ¾

 

GA»Æ½ð¼×¡¤(Öйú¼¯ÍÅ)¹Ù·½ÍøÕ¾

ͼ12£ºIPSec VPNµäÐͳ¡¾°¢ôÅäÖñí

 

³¡¾°¢õ

GA»Æ½ð¼×¡¤(Öйú¼¯ÍÅ)¹Ù·½ÍøÕ¾

GA»Æ½ð¼×¡¤(Öйú¼¯ÍÅ)¹Ù·½ÍøÕ¾

 

GA»Æ½ð¼×¡¤(Öйú¼¯ÍÅ)¹Ù·½ÍøÕ¾

ͼ13£ºIPSec VPNµäÐͳ¡¾°¢õÅäÖñí

³¡¾°¢ö

GA»Æ½ð¼×¡¤(Öйú¼¯ÍÅ)¹Ù·½ÍøÕ¾

GA»Æ½ð¼×¡¤(Öйú¼¯ÍÅ)¹Ù·½ÍøÕ¾

 

GA»Æ½ð¼×¡¤(Öйú¼¯ÍÅ)¹Ù·½ÍøÕ¾

ͼ14£ºIPSec VPNµäÐͳ¡¾°¢öÅäÖñí

¶à×ܲ¿¶à·ÖÖ§³¡¾°

³¡¾°¢÷

GA»Æ½ð¼×¡¤(Öйú¼¯ÍÅ)¹Ù·½ÍøÕ¾

GA»Æ½ð¼×¡¤(Öйú¼¯ÍÅ)¹Ù·½ÍøÕ¾

 

GA»Æ½ð¼×¡¤(Öйú¼¯ÍÅ)¹Ù·½ÍøÕ¾

ͼ15£ºIPSec VPNµäÐͳ¡¾°¢÷ÅäÖÃͼ

³¡¾°¢ø

GA»Æ½ð¼×¡¤(Öйú¼¯ÍÅ)¹Ù·½ÍøÕ¾

GA»Æ½ð¼×¡¤(Öйú¼¯ÍÅ)¹Ù·½ÍøÕ¾

 

GA»Æ½ð¼×¡¤(Öйú¼¯ÍÅ)¹Ù·½ÍøÕ¾

ͼ16£ºIPSec VPNµäÐͳ¡¾°¢øÅäÖñí

 

ÔÚ¶à×ܲ¿¶à·ÖÖ§³¡¾°Ï £¬³ýÒÔÉÏÁ½ÖÖµ¥³ö¿ÚÇé¿ö±í £¬¶à³ö¿ÚµÄÇé¿öÒ²½ÏΪ³£¼û ¡£²¿Êðʱ½«ÒÔÉÏÁ½ÖÖ¶à×ܲ¿¶à·ÖÖ§³¡¾°Óëµ¥×ܲ¿µ¥·ÖÖ§³¡¾°Ï¶à³ö¿ÚµÄÇé¿ö½áºÏʹÓü´¿É £¬±¾Õ²»ÔÚ׸Êö ¡£

IPSec VPN¹ÊÕÏÅŲé

IPSec VPNʹÓÃʱδÃâ»áÓöµ½Ëí·³ÉÁ¢Ê§°ÜµÄÇé¿ö ¡£Í¨³£IPSec VPN¹ÊÕϿɷÖΪÈýÀࣺIKE SA³ÉÁ¢Ê§°Ü£»IPSec SA³ÉÁ¢Ê§°Ü£»IPSec SA³ÉÁ¢³É¹¦µ«Êý¾Ý²»Í¨ ¡£ÔÚÓöµ½IPSec VPN¹ÊÕÏʱ¶ÁÕ߿ɲ鿴ÌáÒé·½ºÍ½Ó¹Ü·½×´Ì¬²¢¶ÔºÃ±ÈÏÂIPSec¶ÔµÈÌå״̬½âÎöͼȷÈÏÊôÓÚÄÄÀà¹ÊÕÏ £¬¶øºóƾ¾ÝÿÀà¹ÊÕϳ£¼ûÔ­Òò½øÐÐÅŲé ¡£

 

GA»Æ½ð¼×¡¤(Öйú¼¯ÍÅ)¹Ù·½ÍøÕ¾

ͼ17£º²é¿´IPSec¶ÔµÈÌå״̬

GA»Æ½ð¼×¡¤(Öйú¼¯ÍÅ)¹Ù·½ÍøÕ¾

18£ºIPSec¶ÔµÈÌå״̬½âÎö

IKE±¨ÎĽ»»¥ÖªÊ¶µã»ØÊ×

ÔÚ·ÖÎöÿÀà¹ÊÕϳ£¼û²úÉúÔ­Òòǰ £¬×÷ÕßÊ×ÏÈ´ø¸÷ÈË»ØÊ×ÏÂIKE±¨ÎĽ»»¥Çé¿ö £¬Ö»ÓÐ֪·ÁËÿ¸ö±¨ÎÄÔÚ½»»¥Ê²Ã´ÄÚÈÝ £¬ÔÚÓöµ½IPSec³ÉÁ¢Í£¶ÙÔÚijһ½×¶Îʱ £¬ÎÒÃDzÅ֪·ÅŲéµÄ·½Ïò ¡£IKEͨ¹ýÁ½¸ö½×¶ÎÀ´³ÉÁ¢IPSec SA £¬µÚÒ»½×¶ÎѡȡÖ÷ģʽ»òÕßÒ°Âùģʽ³ÉÁ¢IKE SA £¬µÚ¶þ½×¶Îѡȡ¼±¾çģʽ³ÉÁ¢IPSec SA ¡£

IKEµÚÒ»½×¶Î£¨Ö÷ģʽ£©£º

  1. µÚ1-2¸ö±¨ÎÄЯ´øIKEÕ½Êõ £¬½øÐÐIKEÕ½ÊõЭÉÌ £¬IKEÕ½ÊõÔ̺¬£º¼ÓÃÜËã·¨¡¢HASHËã·¨¡¢DH×é¡¢ÑéÖ¤·½Ê½¡¢IKE SAÐÔÃüÖÜÆÚ £¬
  2. µÚ3-4¸ö±¨ÎÄЯ´øDHËã·¨±ØÒªµÄ×ÊÁÏ £¬½øÐÐDHËã·¨ÍÆËãÌìÉúÃÜÔ¿ £¬
  3. µÚ5-6¸ö±¨ÎÄЯ´øÉí·ÝÐÅÏ¢¼°ÈÏÖ¤ÐÅÏ¢ £¬½øÐжԵÈÌå¼äµÄÈÏÖ¤ £¬ÊµÏÖIKE SA³ÉÁ¢ ¡£±ØÒª°ÑÎȵÄÊÇ´ÓµÚ5¸ö±¨ÎÄÆðÍ·ÓÐÁ½´¦±ä¶¯ £¬µÚÒ»µãÊDZ¨ÎÄÆðÍ·±»¼ÓÃܱ£»¤ £¬µÚ¶þµãÊÇÈôÊÇ´æÔÚNAT´©Ô½µÄÇé¿öUDP¶Ë±êÓォ´Ó500±äΪ4500

 

GA»Æ½ð¼×¡¤(Öйú¼¯ÍÅ)¹Ù·½ÍøÕ¾

ͼ19£ºÖ÷ģʽ±¨ÎĽ»»¥Á÷³Ì¼°¶ÔµÈÌå״̬

 

IKEµÚÒ»½×¶Î£¨Ò°Âùģʽ£©£º

  1. µÚ1¸ö±¨ÎÄ·¢ËÍ·½·¢ËÍIKEÕ½Êõ¡¢DHËã·¨±ØÒªµÄ×ÊÁÏ¡¢Éí·ÝÐÅÏ¢ £¬IKEÕ½ÊõÔ̺¬£º¼ÓÃÜËã·¨¡¢HASHËã·¨¡¢DH×é¡¢ÑéÖ¤·½Ê½¡¢IKE SAÐÔÃüÖÜÆÚ£»
  2. µÚ2¸ö±¨ÎĽӹܷ½»ØÓ¦Æ¥ÅäµÄIKEÕ½Êõ £¬·¢ËÍDHËã·¨±ØÒªµÄ×ÊÁÏ¡¢Éí·ÝÐÅÏ¢¡¢ÈÏÖ¤ÐÅÏ¢£»
  3. µÚ3¸ö±¨ÎÄ·¢ËÍ·½·¢ËÍÈÏÖ¤ÐÅϢʵÏÖÈÏÖ¤ £¬ÊµÏÖIKE SA³ÉÁ¢ ¡£ÈôÊÇ´æÔÚNAT´©Ô½µÄÇé¿ö´Ó¸Ã±¨ÎÄÆðÍ·UDP¶Ë±êÓï´Ó500±äΪ4500 ¡£

 

GA»Æ½ð¼×¡¤(Öйú¼¯ÍÅ)¹Ù·½ÍøÕ¾

ͼ20£ºÒ°Âùģʽ±¨ÎĽ»»¥Á÷³Ì¼°¶ÔµÈÌå״̬

 

IKEµÚ¶þ½×¶Î£º

  1. µÚ1¸ö±¨ÎÄ·¢ËÍ·½·¢ËÍIPSecת»»¼¯¡¢¸ÐÐËÖÂÁ÷ £¬½øÐÐIPSec²ÎÊýЭÉÌ £¬IPSecת»»¼¯Ô̺¬£º·âװģʽ¡¢°²È«ºÍ̸¡¢¼ÓÃÜËã·¨¡¢HASHËã·¨¡¢IPSec SAÐÔÃüÖÜÆÚ ¡£Áí±íÈôÊÇ¿ªÆôPFS»¹»áЯ´øDHËã·¨±ØÒªµÄ×ÊÁÏ £¬½øÐÐDHËã·¨ÍÆËãÌìÉúеÄÃÜÔ¿£»
  2. µÚ2¸ö±¨ÎĽӹܷ½»ØÓ¦Æ¥ÅäµÄIPSecÕ½Êõ¡¢¸ÐÐËÖÂÁ÷¼°DHËã·¨±ØÒªµÄ×ÊÁÏ(ÈôÊÇ¿ªÆôPFS)£»
  3. µÚ3¸ö±¨ÎÄ·¢ËÍ·½½øÐÐÁ˾ÖÈ·ÈÏ £¬Ë«·½ÊµÏÖIPSec SA³ÉÁ¢ ¡£

Ó×ÌáÐÑ£ºPFS£¨Perfect Forward Secrecy£©ÊÇÒ»ÖÖ°²È«»úÔì £¬Ä¬ÈÏÇé¿öÏÂIPSec SA»áÖ±½ÓʹÓÃIKE SAͨ¹ýDHËã·¨ÌìÉúµÄÃÜÔ¿ £¬¿ªÆôPFS»úÔìºó £¬IPSec SAÔÚЭÉÌʱ»áÔÚ¶î±í½øÐÐÒ»´ÎDHÃÜÔ¿»¥»»Ëã·¨ £¬Ê¹IPSec SAʹÓõÄÃÜÔ¿ÓëIKE SAʹÓõÄÃÜÔ¿·ÖÆç £¬Ìá¸ß°²È«ÐÔ ¡£

IKE SA³ÉÁ¢Ê§°Ü¹ÊÕÏÔ­Òò·ÖÎö

GA»Æ½ð¼×¡¤(Öйú¼¯ÍÅ)¹Ù·½ÍøÕ¾

ͼ21£ºIKEµÚÒ»½×¶ÎIKE SA³ÉÁ¢Ê§°ÜÔ­Òò

 

IPSec SA³ÉÁ¢Ê§°Ü¹ÊÕÏÔ­Òò·ÖÎö

GA»Æ½ð¼×¡¤(Öйú¼¯ÍÅ)¹Ù·½ÍøÕ¾

ͼ22£ºIKEµÚ¶þ½×¶ÎIPSec SA³ÉÁ¢Ê§°ÜÔ­Òò

 

IPSec SA³ÉÁ¢³É¹¦µ«Êý¾Ý²»Í¨¹ÊÕÏÔ­Òò·ÖÎö

GA»Æ½ð¼×¡¤(Öйú¼¯ÍÅ)¹Ù·½ÍøÕ¾

ͼ23£ºIPSec SA³ÉÁ¢³É¹¦µ«Êý¾Ý²»Í¨Ô­Òò

 

дÔÚ×îºó

±¾ÎĽáºÏÀíÂÛÓëʵ¼Ê¶ÔIPSec VPN¼¼ÊõµÄ»ù´¡²ÎÊý¡¢¸ß¼¶Ö°ÄÜ¡¢µäÐÍʵ¼Ê³¡¾°¼°¹ÊÕÏÅŲ鲽Öè½øÐÐÁËÉî¿Ì½âÎö ¡£³ýÁËIPSec VPN¼¼Êõ±íL2TP over IPSec VPN¡¢GRE over IPSec VPNµÈVPN¼¼ÊõÒ²ÔÚһЩÆóÒµÕ¾µã¼äʹÓà £¬¶ÁÕ߿ɽáºÏ±¾ÎÄ˼·×Ôǰ½øÐÐ×êÑÐ ¡£

ÓйØÍƼö£º

¸ü¶à¼¼Êõ²©ÎÄ

ÈκαØÒª £¬ÇëÁªÏµGA»Æ½ð¼×

GA»Æ½ð¼×¡¤(Öйú¼¯ÍÅ)¹Ù·½ÍøÕ¾

·µ»Ø¶¥²¿

ÊÕÆð
GA»Æ½ð¼×¡¤(Öйú¼¯ÍÅ)¹Ù·½ÍøÕ¾ ÎĵµAI¸±ÊÖ
GA»Æ½ð¼×¡¤(Öйú¼¯ÍÅ)¹Ù·½ÍøÕ¾ ÎĵµÆÀ¼Û
ev-close
¸Ã×ÊÁÏÊÇ·ñ½â¾öÁËÄúµÄÎÊÌ⣿
ev-close
Äú¶Ôµ±Ç°Ò³ÃæµÄÖÐÒâ¶ÈÈôºÎ£¿
²»Õ¦µÎ
¼«¶ÈºÃ
dark-star dark-star dark-star dark-star dark-star
ev-close
ÄúÖÐÒâµÄÔ­ÒòÊÇ£¨¶àÑ ¡£©£¿
ev-close
Äú²»ÖÐÒâµÄÔ­ÒòÊÇ£¨¶àÑ ¡£©£¿
ev-close
ÄúÊÇ·ñ»¹ÓÐÆäËûÎÊÌâ»ò½¨Ò飿
ΪÁ˼±¾ç½â¾ö²¢»Ø¸´ÄúµÄÎÊÌâ £¬ÄúÄܹ»ÁôÏÂÁªÏµ·½Ê½
ÓÊÏä
ÊÖ»úºÅ
ev-bg
¸Ð¼¤ÄúµÄ·´À ¡£¡
GA»Æ½ð¼×¡¤(Öйú¼¯ÍÅ)¹Ù·½ÍøÕ¾
GA»Æ½ð¼×¡¤(Öйú¼¯ÍÅ)¹Ù·½ÍøÕ¾
GA»Æ½ð¼×¡¤(Öйú¼¯ÍÅ)¹Ù·½ÍøÕ¾
ÇëÑ¡Ôñ·þÎñÏîÄ¿
¹Ø¹ØÕ÷ѯҳ
ÊÛǰÕ÷ѯ ÊÛǰÕ÷ѯ
ÊÛǰÕ÷ѯ
ÊÛºó·þÎñ ÊÛºó·þÎñ
ÊÛºó·þÎñ
¶¨¼û·´À¡ ¶¨¼û·´À¡
¶¨¼û·´À¡
¸ü¶àÁªÏµ·½Ê½
¡¾ÍøÕ¾µØÍ¼¡¿