You are on page 1of 15

Vpn

.


.
.
.
:

WAN )(Leased Line
. ( . ISDN 128
) ( OC3 Optical Carrier-3) ( 155 (
. WAN
. WAN


. .
"
."
) (
) VPN(Virtual Private Network .
VPN ) " (
.
: Leased
.

VPN
VPN :
(Remote-Access) . VPDN)Virtual
) private dial-up network . User-
) To-Lan ( .
) "
( .
" "
) ESP(Enterprise service provider . ESP
VPN ) NAS(Network access server
.
NAS
.
(Site-to-Site) .
. VPN
:
. ) (
VPN
.
.
VPN .
.
VPN :
WAN
...
. VPN :
.

LAN
.
.
. .
.
.
) (LAN .
.
) .
( .

.
.
.
).
( .
.

. Leased
. ) ( ) (
) ) LAN . )
( .
.
.
VPN VPN

VPN
. :
.
.

) ( .
.



. "
VPN .
) ( ) (LAN
. ) VPN (
.
VPN .
VPN
VPN ) (
:
. .

.
...
.
.
. .

.
:

" " ( Secret (



.
.
.
.
.
. ). A C
B D ) .

. ) ( .

.
.
" ) ( .

. )
)
. " " PGP(Pretty Good
)Privacy . .
IPSec
) Ipsec(Internet protocol security protocol
.
. :
Tunnel
Transport tunel Payload transport
" payload .
:
.1

.2
.3
.4
AAA
)( AAA : Authentication ,Authorization,Accounting
VPN " " .
AAA
:
(Authentication )
(Authorization )
(Accounting )
VPN
") VPN " " " (
:

" " VPN PIX
VPN Dial-up
NAS VPN
" " .
VPN
VPN
.
VPN . . .
100 10,000
.

VPN . . . VPN
.
PIX . ) PIX(Private Internet eXchange NAT ***** VPN
.
) Tunneling (
VPN
" " Tunneling .
. ) (
) ( . "
" . :
. .
. : IPSec,L2F,PPTP,L2TP,GRE
.
. IPX,IP,NetBeui
.
Tunneling ."
) (NetBeui
IP
IP ) (
IP .
VPN " "

GRE(generic routing

)encapsulation .
" " " " ) .
" IP ( .

. IPSec ) (tunnel
. IPSec ) VPN (
. Tunnel IPSec.
VPN " " Tunneling PPP
. PPP IP
.
PPP VPN
" " :
- L2F(Layer 2 Forwarding) . .
PPP .
PPTP(Point-to-Point Tunneling Protocol) .
. 40 128
PPP .
- L2TP(Layer 2 Tunneling Protocol) .
. PPTP L2F . L2TP
IPSec . :

NAS


Tunneling .
) ( ) (
) ( ) ( .
) ( ) (
) ( . ) (
) ( .



. .

.
) (
Virtual Private Network .
VPN
.
Leased .
VPN :
)(Remote-Access
) User-to-LAN (
.
) (
.
)(Site-to-Site

.
VPN :
WAN
.
VPN
VPN :


.
.

...
.


. .

.
IPSec
Internet Protocol Security
.
.
AAA
) (Authentication, Authorization, Accounting
VPN " " .
AAA
:
.1 (Authentication )
.2 (Authorization )
.3 (Accounting )
Vpn
.
.

VPN .
VPN

. Email
Mail .
FTP
.

RAS .
.

.
.
.
) VPN ( Virtual private Network
. VPN

. VPN
. Packet
sniffer .
VPN
VPN
.
. VPN
. VPN IP
.


VPN .
IP .
VPN
. Tunneling
. VPN

Point to point Tunneling protocol PPTP NetBEUI
IP .
Layer 2 Tunneling protocol L2TP IPX IP NetBEUI
Datagram ) ( Point to point
. Frame Relay X.25 IP ATM .
IP Security protocol Ipsec IP IP
.

Tunneling OSI . PPTP L2TP
2 Frame
)(PPP . PPP
) (DHCP .
VPN
. CHAP
. Call back .
.
. Packet IP
IP X NetBEUI Frame PPP . PPTP
Frame PPP IP
Packet IP . 1996
3 com Ascend Robotics US . PPTP
IP 1998 .L2TPFrame Relay X.25

ATM . L2TP PPTP


WAN .
- VPN-Ipsec
Ipsec PPTP L2TP .

IP Header .
IP Header
.Ipsec Tunneling .

.
.
. LAN VPN .
IP VPN .
(Service
) provider . ISP .
. ISP .
Ipsec
Ipsec ) Authentication Header ( AH Packet
) )
. AH (Seguence
) Number Replay . AH .
Encapsulation Security Header ESH .
VPN ESH .
ESH . AH
. IETF
Ipsec
. DES MD5 Secure Hash Algorithm .
Ipsec :
Diffie-Hellman .

Public Key
.
DES .
) ( Hash Packet.
.
- Ipsec
Ipsec
.
Tunneling IP packet
. Header
. ) ( Overhead
.
. OSI 3
Mail
.
Ipsec
Ipsec
.
.
.
DEC MD5 .
.
Ipsec ) Security Association (SA . SA
. SA
) SPI ( Security parameter Index . SPI
. SPI
:

A B B A .

. SPI Header Packet
.
Ipsec
Ipsec

Ipsec ) IKE ( Internet Key Exchange


) IKMP ( Key Management Protocol . SA
. :
Pre shared keys : IKE
Hash .
.
Public Key :
.
.
RSA .
: ) (
. RSA DSS ( Digital
) Singature Standard .
.
Diffie Hellman
.

.
.
VPN .

You might also like