You are on page 1of 83

.

.
.
.
.


.
....
.
.
. .
.
.
.

. "
" . (network Local area(LAN
(network Wide area(WAN . LAN
. WAN
."
WAN
.
) (Leased . LAN WAN
. WAN
. LAN
.

" "Metcalfe
. .
.
.

.
.
.


) ( .
.
) (LAN .
. "
."
.

.
.
.
.

.

:

) Medium ( . .
) Segment ( . " " .
) Node ( . Segment " " .
) Frame( .

) ( ... .
" .
. )
( .
" .
. " ).
( .
.

.
." ) B
( C A D
.

) (.
Broadcast .
Broadcast
.
CSMA/CD
( detection carrier-sense multiple access with collision( CSMA/CD
.
.
:
. ) (
. ) access multiple ( :
) (
.). ( .


. carrier sense .


.
Carrier-sense multiple access
.
.

"
. ) (Collision
.
" .
.
!
.

. "

! .

) ( .

. .
.
.

.
CSMA/CD "

. ) (
.
.

.
.
)(Repeater
) Thicknet(
. .
. . .
.
.
.
) (
Bridges
) ( .
.


.
" .
.
. :
.
Bridges Bridge .
. . Bridge
Bridge
Bridge .
" Bridge .
) ( Bridge." ) .
Bridge Bridge (
"
). Bridge (.
.

Bridge .
A B Bridge
. Bridge
Bridge
.
. A B
. Bridge .
Bridge . C
D Broadcast Bridge
. Bridge
. Bridge
A B C
D . .
:
Bridge Bridge .

.
Bridge Broadcast
. .
Bridge Broadcast

.
.
.
.
.
.


. .
.

. .
) . Bridge
( .
.

. Bridge "
" .
.
Full-duplex Full-dulex .
.
) (half-duplex.
" .

..
.

.
: ) (DIX . IEEE
. IEEE
) . (
. .
IEEE x.x : X .
.
CSMA/CD ) . DIX Ethernet (

.

) ( IBM
ring Token . )(Gap
. Token ring
. .
" .
CSMA/CD passing Token .
) Token ( Token .
. Token
. "
) ( Token
. Token .
.
.

.
.


) ( ... )
( ) ( ) (
. .

. .
.
.
: ) (Servers ) (Clients .
.

.
Client-Server
.

Peer-To-Peer
.

LAN :
. . ) . Client-Server ( .
.
) (NIC . .
.
.
.
.
.
. "
.
.
. :
. LAN .
.

. .
. LAN .
. ). . ( ...
."
.
LAN :
BUS
STAR
RING
. BUS LAN .
)
( .

BUS
. .
.
. BUS . " .
. . Repeater .
BUS
. BUS .

.
. .
10

. .
. .
.
. STAR ""
. " " "
.

STAR
. STAR . .
. " . STAR .
.
. " .
. . .
STAR
. .
.
. .

.
- . ) (

11

.
. RING .
) (
. .
.
.
RING
. BUS . ) (
.

. .
. .
. .
" .
RING
. .
.
. . .
. .
. .
.

12

.
:
) ( LAN
MAN
WAN
. LAN
. :

. MAN
. :



. WAN
. :


LAN
LAN


.
. "
.
: .

.
(UTP( Unshielded Twisted pair .
.
.
) Shielded : ( ) Unshielded ( .
UTP STP .
13

UTP .
.
) ( .

UTP ) (Categories :

Type

Cat 1 ) (
Cat 2
Cat 3
Cat 4
Cat 5
:


.
:


.

.

UTP RJ-45 .
) (RJ-11 . .
)(Jack Registered:RJ

14

.
.

.
. .

.







"
.

(Neill - Concelman- Bayone(BNC .


.

15

.
.
. ) ( .
M1 M2 M2<M1 .
.
.
.

.
/ .
.
.
T .
Detector .
.
.
" .

16


Maximum length

Cable Type

Specification

100 meters

Unshielded Twisted Pair

10BaseT

185 meters

Thin Coaxial

10Base2

500 meters

Thick Coaxial

10Base5

2000 meters

Fiber Optic

10BaseF

100 meters

Unshielded Twisted Pair

100BaseT

220 meters

Unshielded Twisted Pair

100BaseTX

17

TCP/IP
TCP/IP .
:
.


TCP/IP .
IPX/SPX
.
TCP/IP ) ARPAnet ( .

. TCP/IP
.
TCP/IP
TCP/IP
. Transport Network
.
Network TCP/IP
(Protocol Transmission Control(TCP . " Connection-oriented .
.

. TCP
.
. "
.
. (User Datagram Protocol(UDP TCP " " UDP . TCP " " .
TCP .

.
. (Internet Protocol(IP .
.
Application TCP/IP
TCP/IP" UDP TCP IP Application
.
.
18

.
. (File Transfer Protocol(FTP .
FTP .
. (Simple Network Management Protocol(SNMP . SNMP
(MIB)Management Information Base MIB .
)."
(
. TelNet log on .
.
. (simple Mail Transfer Protocol(SMTP .
. (HyperText Transfer Protocol(HTTP .
) (... .

.
. (Network News Transfer Protocol(NNTP
.
NNTP
NewsReader
IP
TCP/IP
IP .
. ) IP (
) ( .
IP
IP TCP/IP .
IP
DHCP NAT
Subnetting
IP Subnetting .
) (Subnet
Subnet mask ) (ID .

19

IP
TCP/IP . IP
. IP :
216.27.61.137

IP ) (
. octet .
) ( . IP
:
11011000.00011011.00111101.10001001

IP .
) . ( "
) Broadcast ( . IP ) (Octet"
" " IP . Octet
: ) (Net ) . (Host octet
. octet

IP :
. Default Network IP . DHCP
.

. A . octet A . octet
. A
) .
( . A () . A octet
.
NET

)Host (Node

115.

24.53.107

20

). (
.
. B )." ( octet B . octet
. octet
( ) B .
) ( ( - ) .
B () B
octet .
NET

)Host (Node

145.24.

53.107

. C . octet C . octet
. octet
. ( ) C .
) ( ( - ) .
C ( ) . C
octet .
NET

)Host(Node

195.24.53.

107

. D multicasts . ) ( .
) ."
( " .
.
Multicast
. ( )
NET

)Host(Node

224.

24.53.107

. E . .
. Multicast
. ( )
NET

)Host(Node

240.

24.53.107

21

. BroadCast . :
255.255.255.255.

. IP ) ( :10.x.x.x
172.16.x.x - 172.31.x.x
192.168.x.x

IP . . : .
2b63:1478:1ac5:37ef:4e8c:75df:14cd:93f2

:
Class

1st Octet
Net ID

2nd Octet

3rd Octet
Host ID

4th Octet

A
Host ID

Net ID
B

Host ID

Net ID
C

Normal
Netmask
For very large networks
255.0.0.0
For medium size networks 255.255.0.0
For small networks
255.255.255.0
Used to support
multicasting

Network
Type
001.x.x.x to 126.x.x.x
Class A
128.1.x.x to 191.254.x.x
Class B
192.0.1.x to 223.255.254.x Class C
224.x.x.x to
Class D
239.255.255.255
240.x.x.x to
Class E
247.255.255.255

Comments

Address Range

22

OSI

. (Systems Interconnection OSI )Open
. ) ISO
( . .
.. OSI
.
. OSI .

.
) ( .
Application .
. ) (

.
) ( Application
.
.

23

OSI
OSI .
:
) . (Application . ."
....
) . (Presentation Application .
) . (Session .
) . (Transport .
stream
.
) . (Network . .
) .(Data . ) (Packet .

24

) . (Physical :
.
OSI
.


. TCP/IP
.
) . (Network Interface Physical Data .
) . (Internet Network OSI . ) (IP ) IP (
.
) . (Transport Transport OSI . TCP(Trnsport )control protocol
) . (Application Session,Presentation Application OSI . FTP SMTP .

25



.
.

" " .

.
"

laptop
Laptop .
: /
.
. /
" ) . ( .

. /
. Access point .
) (
.
) (

BlueTooth
IrDA
(SWAP(HomeRF
(Wi-Fi(WECA

Bluetooth
(Infrared Data Association(IrDA .
. )
( ) (
. IrDA .
SWAP Wi-Fi
. IEEE 802.11
IEEE .
. :
(spectrum Direct-sequence spread(DSSS
(spectrum Frequency-hopping spread(FHSS

26

(Frequency-shift keying(FSK .
Spread-spectrum / .
Spread Spectrum
.
DSSS
DSSS . ) "
( FHSS
) (hop .
FHSS Hop
) " (
FHSS ) ( . FHSS"
.
HomeRF SWAP
HomeRF (protocol Shared Wireless Access(SWAP
SWAP . DECT .
SWAP hop .
.
. SWAP :




Access point

.
.
.

SWAP :

) (
) / (
FHSS .
.
.

PCI , ISA PCMCIA) (


. Laptop PCMCIA
PCMCIA .
ISA HomeRF PCI PCMCIA .
" SWAP
. "

27

.
SWAP " " . "
Access point .
HomeRf .
WECA Wi-Fi
(Compatibility Alliance Wireless Ethernet(WECA HomeRF
Wi-Fi . IEEE
802.11 . FHSS DSSS ) .
( . b IEEE
. /
" .
.
Wi-Fi :

) (

) /
(
.
) DSSS 802.11 ( .

Wi-Fi :
.
.
.
Wi-Fi . Wi-
Fi " " " Wi-Fi Access Point
. Access point
. Wi-Fi PCMCIA .
PCI ISA .

28


.
) ( ) ( .
:

:
. .
. . ) (
.
) "
Cat5 ( .
) (
. :

.


.
. .
: Network
) Neighborhood ( .
: Properties . Network
Properties .
29

.
: Identification .
.
: .
" .
.
: .

.


.
.
.
File and Printer Sharing .
) Network Neighborhood (

30

. Properties . Network Properties


. Configuration Client for
Microsoft Networks . ) (Client
.

.
.

: Add Network Properties


: Client .
: Add
.
: Microsoft
.
: Microsoft Networks Client for OK
. )

31

CD (
.
) ( Network :
: sharing File and print .

: .
. .
: ) ( Checkmark
File and print sharing . OK Sharing-options
.
: Control Access Network .
Share-level Access Control
.
: OK Network .
.

. .
Sharing .
. Sharing Not Shared .
Shared As Share Name
. " .
" Access Control Share-level
) (Access Type .
Read-only "
.
. Full access
.
.

32


" File and
Printer Sharing .
.
: Start Setting Printers .
.
:
Sharing .
: Properties . Shared As
) ( .
.

33

: OK .
:
: Printer .
:) ( Printer Add a .
: Network Printer OK .
:
. Next .
) . CD
(

CE
(Internet Connection Sharing(ICS . ICS
: ISDN DSL

34

. CE
. ICS .
" .
) CE (
:
: Control Panel Add/Remove Programs .
: windows setup Internet Tools .
: Sharing Internet Connection . Next .
ICS ) ( ICS
.
: ICS
.
ICS
.
ICS XP
. Dial-up
Properties . Dial-up Connection properties
.

35

" "Sharing . " Enable internet


"this connection connection sharing for
.

36

37



" " " ."
" :
" . ) (ISP
ISP .
DSL

.
.



. .
.
) ( .
) T ( T3 .
.
FTP Telnet
.
.
" .
.
." :
FTP .
) Telnet FTP ( ...
. .

38

.
:
. .
.
. Proxy .
.

" .
:
. IP IP IP . ) . (Octet
IP )
(
.
) ( . " " . "
.
. . ." http Ftp
.
. :

(Internet Protocol(IP .
( Protocol Transport Control(TCP
.
. (Protocol Hyper Text Transfer(HTTP .
. (Protocol File Transfer(FTP .
. (Protocol User Datagram(UDP
) (
.(Protocol Internet control Message(ICMP
.
. (Protocol Simple Mail Transfer(SMTP e-mail
.
.(Protocol Simple Network Management(SNMP

39

. Telnet .
. ." Ftp
. .
. .
.
.
.
Gateway .
Gateway .
.

.
. Remote Login . .
. Application Backdoors . Backdoor
. .
. SMTP session hijacking SMTP e-mail . e-mail e-mail .
. Backdoors.
. E-mail e-mail . .
. .
" " .

.
. . .
.

40

Proxy
Proxy . Proxy
.
Proxy
. ) (
Proxy .
Proxy .
Proxy ) (Cache .
Proxy
) (

41


) ( ) (
. .
.
.
.
) " ( " .
..
LAN .
" .

r :

. ) (
.
. ). ( ...
. Bridge
.
. ."
."

.
. .
. .
) (
.
. MAC ) ( .

.
. Unicast .
. Multicast ) (
. .
. Broadcast .


. )
(... :
. Scalability . .

. .

42

. Latency . )
( .

.
.
. Network Failure .
) " (
Broadcast.
. Collisions CSMA/CD .
.
.
" .
) ( "
.
"
. .
.
.
." )
( ) ( ) .
( .
.
.
. ) (
.
.
. "
.
.
full-duplex .
half-duplex . .
" ) "
( .
.
.
.
.

43

.
" .
."

) ( .

.
" ) (Data layer OSI .
) MAC ( . ) (Network
OSI . IP IPX Appeltalk ) .
( .
.

Broadcast .
Broadcast .
.
broadcast
."
Broadcast .
. Broadcast

.

44

Broadcast
Broadcast . .
.
.
.
.
LAN packet-switching .
. ) (
) (MAC ) Lookup(
. LAN .
)(
.

.
Cut-Through
Store-and-forward
Fragment-free
Cut-through
MAC .
) .
( .
.
store-and-forward
) (CRC .
. .
MAC .
. cut-through
store-and-forward .
fragment-free .
cut-through .
LAN .
:
. Shared memory . ) (
. .
. Matrix ) ( .

45

MAC lookup .
.
. Bus Architecture ) ( ) (Bus TDMA .
.
Bridging Transparent
LAN transparent bridging
lookup .
. :

Learning
Flooding
Filtering
Forwarding
Aging

:
. - A ) (A ) (B

46

) (C .
A . MAC Lookup A . A
A .
Learning .
B ) A "
( .
Flooding .
B Acknowledgement A .
B . MAC B Lookup C . A
" . A B
.
Forwarding .
A B B " B .
C A . MAC C Lookup A A A C
. A C
.
. Filtering .
Learning Flooding MAC Lookup . Lookup .

. aging .
Entry Lookup
. .
Entry Lookup
. Entry
Entry .
A A D .
.
Filtering .

47

) (Star Bus Star


. :

A C
. ) (B
. C .
A C .


. " "
.
. "
.
Loop .

48

" B A B B
. A A
. A C
) B (C . B B Lookup .
) . (A C B C Lookup
. A
B A .
" ) .
A ( A "
. " " .
. Spanning
trees .
tress Spanning
" " Looping DEC
(Spanning-tree Protocol(STP . d
IEEE tree Spanning . (STA(Spanning-tree algoritm
.
.
STP :

49

) (ID . . (Bridge ID(BID


. MAC
. .
.
Path Cost . IEEE . ) (
.
Cost ) . (
Cost . STP Cost ) .
Path cost (
Bandwidth

STP Cost Value

4 Mbps

250

10 Mbps

100

16 Mbps

62

45 Mbps

39

100 Mbps

19

155 Mbps

14

622 Mbps

1 Gbps

10 Gbps

. Bridge (BPUD
(protocol data units . BPUD :
. Root BID BID Root Bridge .
. Path Cost to Bridge root bridge ."
Root bridge
cost ) (=++ . Root Bridge Cost
.
. Sender BID BID BPDU .
. Port ID BPDU .

BPDU . BPDU ) (
BPDU
) ( BPDU

50

.
Root bridge BPDU . Root . BPDU
BID Root BID . BPDU
BID BID Root .
BID Root "
. BID Root BPDU
BID Root BID . BPDU
Root Root BID
.
Root Bridge Root Bridge . Ports Root
.
designated . . "
Looping .
designated root bridge . Root bridge path cost
designated ) . ( Path
Cost . path cost
designated .
cost path BID .
designated port non -designated . designated
.
BPDU .
spanning tree roor bridge
. Root Ports root bridge
designated .

" OSI ). (Data Layer
" OSI
. (Layer Network) . .

. MAC
). (

51

.
. LAN " .
.
)
( . matching Pattern
caching .
.

.
Caching .
LAN .
.

52


.

.
.
.

.

.
E-mail

.
.
.

. .
.

. )
( .

.
.
. )
( .
.
.

.

.

.
.
" "
. :

53


.
.
:


.
.

. ).

( .
.
.
. .


.
.
.

. ..
.
) ( ... Packet -
switching network .
. :
.
Packet .
.
) ( switching Packet :
) (

.
" "
.
.
:

54

Internet connection sharing


. .
.
.
.
.
.
. .
) base-T
( .
) (ISP
. T1 .

ISP . Backup ) " ( T1
.
.

."
.
.
.
) (
.
. Subnet mask subnet . IP
.

."
.

.

.
.
.
: .

55


" : - - - "
.
.

. .
. .
.
."
) (NIC
. Media Access ( MAC
(Control .
. .
.
." ... .
.
.
.
TCP/IP .
NetBEUI .
.
.
.
) IPCONFIG (XP .

56

.
.
) .
( ...
. .
. .
.
" .
Packet .
Packet-Switched network .
.
.

) .
(

Traceroute
." www.microsoft.com
:
Tracert www.microsoft.com
:

.
.
) ( " .
. IP .
....
.


.
.
) . ( .
MHZ MIPS R5000 .
. .

.

57

.
.
) ( .
"
.
. " .
.
.
"
.

58

DNS
DNS ) (
Winsock . DNS
) ( NetBIOS .
NetBIOS
NetBIOS . IBM
. " " .
NetBIOS Session
NetBEUI .
NetBIOS . .
Broadcast Base . NetBIOS
Broadcast
.
. ds2000 Exeter .
Broadcast .
. Exeter MAC
ds2000 .

)
( "
Based Broadcast .
.

.
) NetBIOS (NetBEUI
NetBIOS .
NetBIOS ) Overlay
59

NetBIOS
NetBIOS .
BroadCast NetBIOS
" . .
) (Flat .
Flat NetBios NameSpace
NetBIOS
. " .
.
. "
.

" " "

" .

.

.
.
"
. .
.
NetBIOS
.
NetBIOS
) (
.
NetBIOS WinSock
DNS .
. DNS
" TCP/IP .

TCP/IP .
)(WinSock
NetBIOS
TCP/IP
. NetBIOS
" " NetBIOS"
session .

60

(TCP/IP )IP,TCP NetBIOS


.
) NetBIOS NetBIOS TCP/IP
( netBT NetBIOS over TCP/IP .
NetBIOS
Application NetBT . NetBIOS
IP . NetBIOS
TCP/IP .
.

Winsock
TCP/IP Winsock .
IP
.
) " ( IP .
."
. "
) (www.test.com
. IP
) ( . Winsock
Host Name
. ) (Name Resoulation Host .
NetBIOS WinSock
NetBIOS NetBIOS IP
). NetBIOS IP (. WinSock

61

) (Host name IP .
NetBIOS .
. NetBIOS
DNS .
DNS NameSpace
DNS .

.
NetBIOS .
.
DNS Root Domain .
. ) (Top Level
. Com , .net , .org , .edu. .
Top
Level . .
" com. edu. domain ...
. DNS .

."
com. net. Microsoft.com .
www
.
Top Level Second level DNS
.

62

.
(NSI)Network Solutions Intcorporated.
"
.
Host
DNS .
DNS FQDN .
(Qualified Domain Names FQDN)Fully
FQDN DNS . FQDN
FQDN .
) (Host ." TestCorp
) (TestCorp.com
TestCorp.com www www.testCorp.com
.
www FQDN " host
. FQDN :
: Label host .
: Dots .
lable . lable .
) ( lable .
DNS UTF-8 . "
. FQDN .

) ( DNS :
DNS ) ( ) ( /


.

.. .
) (Zone DNS
DNS . Zone
. Zone Zone
. " .


Mirror ." Test.com
) ( ) ( .

63


.
.
. www.test.com
.
. Mirror
zone DNS
. www.test.com
DNS zone .
www.test.com DNS
IP DNS .



.
. Zone
." Test.com
TestCorp.com .

64


.
Authority Zones of
DNS host
. DNS
DNS . Zone
database . DNS
. systemroot%\system32\dns% .
Zone .
Forward Lookup Zone
Reverse Lookup Zone
Zone .
Lookup Zone Forward
Zone host IP DNS
Zone .
. " " Resource Record .
Zone .
Domain Zone
Zone ) (Domain Zone
."
www.microsoft.com East , WestWest.microsoft.com , ) .
.( East.microsoft.com msn.com

65

mail.microsoft.com

.
) ( . Zone
Microsoft.com Msn.com Microsoft.com .
Zone Zone Zone .
.
TACteam . tacteam.net .
San Francisco, Dallas, and Boston . Dallas
. San Francisco
. Boston DNS .
Boston
. Dallas tacteam.net San
Francisco west.tacteam.net Boston east.tacteam.net
. " Zone . Zone
tacteam.net tacteam.net east.tacteam.net
Zone west.tacteam.net San Francisco
. Zone Zone
.
west.tacteam.net DNS ) DNS ( tacteam.net
tacteam.net" Zone .
) Delegation ( DNS west.tacteam.net
.
.

66

Reverse Lookup Zones


Zone Forward IP .. Reverse
Lookup :
IP ." IP
.
DNS Zone Zone . Forward
Zone ." Forward Lookup Zone
.

.
.
." .
IP in-addr.arpa
. ) (Network ID
.
DNS Zone ."
Zone :
1.168.192.in-addr.arpa.dns

67

NAT
. ) (
. " "
) (Host . Address Network
( NAT (Translation
IP IP . .
IP
. IP () ) .
( . ) ( .
multicasting .
) ( IP .
IP IP .
IP .
NAT . NAT .
. NAT ) (
) ( . " IP
) ( .

IP" NAT . NAT .


NAT
NAT .
.
" .
.
) ( . .
.
NAT ) ( NAT.
.
NAT . IP ) ( IP .) ( .
IP 192.168.32.10 IP .

68

NAT . IP IP . IP .

. OverLoading NAT . IP IP . (Port Address Translation(PAT .

. Overlapping IP NAT . IP NAT .


NAT .
) . NAT IP
. (

69

) ( " LAN . IP
.
. IP .
IP NAT
.
NAT . NAT
) IP ( ) ( IP
.
) ISP ( IP . . Inside global . IP
: NAT ) (Outside local address
) . (Inside local address Outside local
IP . outside global
) ( .

inside local . inside global .


inside local NAT .
NAT entry . NAT entry ) (ATT
. .

70

inside global . ) ( . outside global . inside global .


NAT .
NAT inside global inside local .
Overloading TCP/IP .
TCP UDP..
IP ) (Header :

. .
. TCP UDP .
: .
. TCP UDP
.


. ). )
( ( ." .
NAT Overloading
NAT :
) ( IP Internet Assigned Numbers(IANA (Authority ) . IP
( .
NAT . IP IANA .
) " ( . . IP . IP . ) ( IP
IP .
.

71

. ) (
. .
. .
Overloading :
) ( IP Internet Assigned Numbers (IANA (Authority .
.
NAT . IP IANA .
) " ( . . IP . IP .
.
.
. ) (
. .
. .
NAT ) ( . Timer
reset . ) Timer (
NAT ) ( .

NAT
Router's
NAT
Source
Source
Source
Assigned Router's Computer's Computer's
Computer
IP Address
Port
IP Address
Port
Number
A

192.168.32.10

400

215.37.32.203

192.168.32.13

50

215.37.32.203

192.168.32.15

3750

215.37.32.203

72

192.168.32.18

206

215.37.32.203

IP
IP NAT .
.
entry"
. .
IANA IP .
..
) ( . ) (Forward .
Range 1: Class A - 10.0.0.0
through 10.255.255.255
Range 2: Class B - 172.16.0.0 through 172.31.255.255
Range 3: Class C - 192.168.0.0 through 192.168.255.255

NAT NAT .
" .

) ( .
... IP NAT .

.
NAT .
.
.
NAT Proxy NAT . Proxy
NAT . Proxy .
.
Proxy ) ( .
Proxy Proxy . ) (Transport OSI
NAT ) (Network Proxy . NAT .

73


. :
.

.



. .
.

:
) . (Core .
) . (Cladding
.
) . (Buffer Coating

74

.

. Jacket .
:
) . (Single-Mode ) :
(
) . (Multi-Mode )
: (
) " (
) ( . ) " /
( LED .

.

.
) ( .

.
.
) ( )
( .
.
) (
) ) (Cladding ( ).
( .
.
.
) ."

(


.
"
. .
.
) ( .

75

. .
) " (
. ) (
.
:

. .
.
. .
. .

.
) (
.
. LED .
LED .
.
) (
" )
( ) (
. ) (
" " .
) (doping . .

.
). (

.
)
( ... . "" ""
.

:
. .

76

. .
. .
. .
.
.
.

.
. .
. .
. ) ( .
.
:
... .

.
.

77


.


.
.
.
:

WAN ) (Leased Line
. ) ISDN . (OC3 )
) (Optical Carrier-3 ( .
WAN .
WAN


. . "

." )
( Virtual (VPN
(Network Private .
VPN ) " (
.
: Leased
.
VPN
VPN :
) . (Remote-Access dial-up Virtual private(VPDN
(network . ) User-To-Lan
( .
) " (
. " "
(service provider Enterprise(ESP .
ESP VPN (Network access server(NAS
.
NAS
.
) . (Site-to-Site
. VPN
78

:
. ) (
VPN
.
.
VPN .
.
VPN :
WAN
... . VPN
: .
LAN
.
. .
.
.
. ) (LAN .

. ) .
( .

.
.
.
). ( .

.
.
Leased . ) (
) ( ) (LAN .
) ( .
.

.
VPN VPN

VPN .
:

79

.
) ( .
.


. " VPN .
)
( ) (LAN . ) VPN
(
. VPN .
VPN
VPN ) ( :
. .
.

... .
.
. .

. :


" " ) Secret (
.

.
. .
.
.
). A C B . ( D

. ) ( .

.
. "
) ( .
.

80

) (
. "
" (Pretty Good Privacy(PGP .
.
. IPSec (protocol Internet protocol security(IPsec
.
. . Transport Tunnel : tunel
Payload transport" payload .
:

. AAA ) Authentication : AAA


(Authorization,Accounting, VPN "
" . AAA
:
) ( Authentication
) ( Authorization
) ( Accounting
VPN
" ) VPN " " " (
:


" "VPN PIX
VPN Dial-up
NAS VPN "
" .
VPN

VPN
.
. VPN . .

.
- . VPN .

81

. VPN
.
. PIX (PIX(Private Internet eXchange NAT Proxy VPN .
)Tunneling (
VPN "
" Tunneling .
. ) ( )
( . " " .
:
. .
. IPSec,L2F,PPTP,L2TP,GRE : .
. IPX,IP,NetBeui
.
Tunneling ."
) (NetBeui IP
IP ) (
IP
.
VPN " " (encapsulation generic routing(GRE
. " "
" " ) . " IP ( .

. ) IPSec (tunnel
. IPSec ) VPN
( . Tunnel IPSec.
VPN " " Tunneling PPP PPP .
IP
.
PPP VPN "
" :
. (Layer 2 Forwarding(FL . PPP .
. (Tunneling Protocol Point-to-Point(PPTP
.

82

PPP .
. (Protocol Layer 2 Tunneling(L2TP . PPTP L2F . L2TP IPSec
. :

NAS

Tunneling .
) ( ) ( ) (
) ( . ) (
) ( ) ( . )
( ) ( .

83

You might also like