ipsecvpnÅäÖÃÃû´Ê½âÊÍ

ipsecvpnÅäÖÃÃû´Ê½âÊÍ

µÚÒ»½×¶Î IKE(Internet Key Exchange£¬ÒòÌØÍøÃÜÔ¿½»»»Ð­Òé)ÉèÖÃ

´ó¶àÊý²úÉ̶¼°ÑÕâ¸ö½Ð³ÉVPNs GatewayЭÉÌģʽ£º ¿ÉÒÔÑ¡ÔñÖ÷ģʽ(Main)»òÒ°Âùģʽ(Aggressive)¡£µ±Ñ¡ÔñÖ÷ģʽʱ£¬Ö»ÄÜʹÓÃipµØÖ·×÷ΪIDµÄÀàÐÍ¡£µ±Óû§¶ËÉ豸µÄIPµØÖ·Îª¶¯

̬»ñÈ¡µÄÇé¿öʱ£¬ÐèҪѡÔñÒ°Âùģʽ¡£IKEÒ°ÂùģʽÏà¶ÔÓÚÖ÷ģʽÀ´Ëµ¸ü¼ÓÁé»î£¬¿ÉÒÔÑ¡Ôñ¸ù¾ÝЭÉÌ·¢Æð¶ËµÄIPµØÖ·»òÕßIDÀ´²éÕÒ

¶ÔÓ¦µÄÉí·ÝÑéÖ¤×Ö£¬²¢×îÖÕÍê³ÉЭÉÌ¡£ÑéÖ¤·½·¨AH(Authentication Header)£º

Éí·ÝÑé֤ȷÈÏͨÐÅË«·½µÄÉí·Ý¡£Ä¿Ç°ÔÚIKEÌáÒéÖУ¬½ö¿ÉÓÃpre-shared-keyÉí·ÝÑéÖ¤·½·¨£¬Ê¹ÓøÃÑéÖ¤·½·¨Ê±±ØÐëÅäÖÃÉí·ÝÑéÖ¤

×Ö¡£¼ÓÃÜËã·¨£º

1£®°üÀ¨DESºÍ3DES¼ÓÃÜËã·¨£¬

2£®DESËã·¨²ÉÓÃ56 bitsµÄÃÜÔ¿½øÐмÓÃÜ£» 3£®3DESËã·¨²ÉÓÃ168bitsµÄÃÜÔ¿½øÐмÓÃÜ£»

4£®AES128(Advanced Encryption Standard£¬¼´¸ß¼¶¼ÓÃܱê×¼)²ÉÓÃRijndaelÖеÄ128bitsµÄÃÜÔ¿½øÐмÓÃÜ

5£®AES192(Advanced Encryption Standard£¬¼´¸ß¼¶¼ÓÃܱê×¼)²ÉÓÃRijndaelÖеÄ192bitsµÄÃÜÔ¿½øÐмÓÃÜ

6£® AES256(Advanced Encryption Standard£¬¼´¸ß¼¶¼ÓÃܱê×¼)²ÉÓÃRijndaelÖеÄ256bitsµÄÃÜÔ¿½øÐмÓÃÜ

Ò»°ãÀ´Ëµ£¬ÃÜÔ¿Ô½³¤µÄË㷨ǿ¶ÈÔ½¸ß£¬Êܱ£»¤Êý¾ÝÔ½Äѱ»ÆÆ½â£¬µ«ÏûºÄµÄ¼ÆËã×ÊÔ´»á¸ü¶à¡£Diffie-Hellman×é±êʶ(DH)£º Óû§¿ÉÒÔÑ¡ÔñGroup1¼´768bit»òGroup2¼´1024bit¡£ISAKMP-SAÉú´æÖÜÆÚ£º

IKEʹÓÃÁËÁ½¸ö½×¶ÎΪIPSEC½øÐÐÃÜԿЭÉ̲¢½¨Á¢°²È«ÁªÃË¡£µÚÒ»½×¶Î£¬Í¨ÐŸ÷·½±Ë´Ë¼ä½¨Á¢ÁËÒ»¸öÒÑͨ¹ýÉí·ÝÑéÖ¤ºÍ°²È«±£»¤µÄ

ͨµÀ£¬¼´ISAKMP°²È«ÁªÃË£¨ISAKMP SA£©£»µÚ¶þ½×¶Î£¬ÓÃÔÚµÚÒ»½×¶Î½¨Á¢µÄ°²È«Í¨µÀΪIPSECЭḚ́²È«·þÎñ£¬¼´ÎªIPSECЭÉ̾ß

ÌåµÄ°²È«ÁªÃË£¬½¨ Á¢IPSEC SA£¬IPSEC SAÓÃÓÚ×îÖÕµÄIPÊý¾Ý°²È«´«ËÍ¡£ISAKMP-SAÉú´æÖÜÆÚ¿ÉÒÔÉ趨Ϊ60µ½604800Ö®¼äµÄÒ»

¸öÕûÊý¡£¶¨Ê±·¢ËÍkeepAlive±¨ÎÄ£º

IKEͨ¹ýISAKMP SAÏò¶Ô¶Ë¶¨Ê±·¢ËÍKeepalive±¨ÎÄά»¤¸ÃÌõISAKMP SAµÄÁ´Â·×´Ì¬¡£µ±¶Ô¶ËÔÚÅäÖõij¬Ê±Ê±¼äÄÚδÊÕµ½´Ë

Keepalive±¨ÎÄʱ£¬ Èç¸ÃISAKMP SA´øÓÐTIMEOUT±ê¼Ç£¬

Ôòɾ³ý¸ÃISAKMP SA¼°ÓÉÆäЭÉ̵ÄIPSEC SA£»·ñÔò£¬½«Æä±ê¼ÇΪ

TIMEOUT¡£µÚ¶þ½×¶ÎIPSEC·âװģʽ£º

°üÀ¨´«Êäģʽ(Transport)ºÍËíµÀģʽ(Tunnel)¡£´Ó°²È«ÐÔÀ´½²£¬ËíµÀģʽÓÅÓÚ´«Êäģʽ¡£Ëü¿ÉÒÔÍêÈ«µØ¶ÔԭʼIPÊý¾Ý±¨½øÐÐÑéÖ¤ºÍ

¼ÓÃÜ£»´ËÍ⣬¿ÉÒÔʹÓÃIPSEC¶ÔµÈÌåµÄIPµØÖ·À´Òþ²Ø¿Í»§»úµÄIPµØÖ·¡£´ÓÐÔÄÜÀ´½²£¬ËíµÀģʽ±È´«ÊäģʽռÓøü¶à´ø¿í£¬ÒòΪËüÓÐ

Ò»¸ö¶îÍâµÄIPÍ·¡£Òò´Ë£¬µ½µ×ʹÓÃÄÄ ÖÖģʽÐèÒªÔÚ°²È«ÐÔºÍÐÔÄܼ佸ÐÐȨºâ¡£°²È«ÁªÃËÉú´æÖÜÆÚ£º

ËùÓÐÔÚ°²È«²ßÂÔÊÓͼÏÂûÓе¥¶ÀÅäÖÃÉú´æÖÜÆÚµÄ°²È«ÁªÃË£¬¶¼²ÉÓÃÈ«¾ÖÉú´æÖÜÆÚ¡£IKE£¨Internet Key Exchange£¬ÒòÌØÍøÃÜÔ¿½»»»

ЭÒ飩ΪIPSECЭÉ̽¨Á¢°²È«ÁªÃËʱ£¬²ÉÓñ¾µØÉèÖõĺͶԶËÌáÒéµÄÉú´æÖÜÆÚÖнÏСµÄÒ»¸ö¡£°²È«ÁªÃËÉú´æÖÜÆÚµÄÊäÈ뷶ΧΪ

30~604800µÄÕûÊý¡£²ÉÓõİ²È«Ð­Ò飺

°²È«ÌáÒéÖÐÐèҪѡÔñËù²ÉÓõİ²È«Ð­Ò顣Ŀǰ¿ÉÑ¡µÄ°²È«Ð­ÒéÓÐAHºÍESP£¬Ò²¿ÉÖ¸¶¨Í¬Ê±Ê¹ÓÃAHÓëESP¡£°²È«ËíµÀÁ½¶ËËùÑ¡ÔñµÄ

°²È«Ð­Ò鱨ÐëÒ»Ö¡£ESPЭÒé¼ÓÃÜËã·¨£º

ÁªÏµ¿Í·þ£º779662525#qq.com(#Ìæ»»Îª@) ËÕICP±¸20003344ºÅ-4