ʽ£¬ ͨ¹ý·ÇÍøÂç´«ÊäµÄÆäËü°²È«Í¨ÐÅ·½Ê½Íê³ÉÃÜÔ¿ÔÚ¸÷°²È«Íø¹ØÖ®¼äµÄ´«ËÍ¡£¸÷°²È«Íø¹ØµÄÃÜÔ¿´æÖüÔÚÃÜÊý¾Ý¿âÖУ¬Ö§³ÖÒÔIPµØÖ·Îª¹Ø¼ü×ֵĿìËÙ²éѯ»ñÈ¡¡£
Éí·ÝÈÏ֤ģ¿é¶ÔIPÊý¾Ý°üÍê³ÉÊý×ÖÇ©ÃûµÄÔËËã¡£Õû¸öÊý×ÖÇ©ÃûµÄ¹ý³ÌÈçͼ5Ëùʾ£º
ͼ5 Êý×ÖÇ©Ãû
Ê×ÏÈ£¬·¢ËÍ·½¶ÔÊý¾Ý½øÐйþÏ£ÔËËãh£½H(m)£¬È»ºó ÓÃͨÐÅÃÜÔ¿k¶Ôh½øÐмÓÃܵõ½Ç©ÃûSignature£½{ h} key¡£·¢ËÍ·½½«Ç©Ãû¸½ÔÚÃ÷ÎÄÖ®ºó£¬Ò»Æð´«Ë͸ø½ÓÊÕ·½¡£ ½ÓÊÕ·½ÊÕµ½Êý¾Ýºó£¬Ê×ÏÈÓÃÃÜÔ¿k¶ÔÇ©Ãû½øÐнâÃܵõ½ h£¬²¢½«ÆäÓëH(m)½øÐбȽϣ¬Èç¹û¶þÕßÒ»Ö£¬Ôò±íÃ÷Êý¾ÝÊÇÍêÕûµÄ¡£Êý×ÖÇ©ÃûÔÚ±£Ö¤Êý¾ÝÍêÕûÐÔµÄͬʱ£¬Ò²Æðµ½ÁËÉí·ÝÈÏÖ¤µÄ×÷Óã¬ÒòΪֻÓÐÔÚÓÐÃÜÔ¿µÄÇé¿ö֮ϣ¬²ÅÄܶÔÊý¾Ý½øÐÐÕýÈ·µÄÇ©Ãû¡£
Êý¾Ý¼ÓÃÜ/½âÃÜÄ£¿éÍê³É¶ÔIPÊý¾Ý°üµÄ¼ÓÃܺͽâÃܲÙ×÷¡£¿ÉÑ¡µÄ¼ÓÃÜËã·¨ÓÐIDEAËã·¨ºÍDESËã·¨¡£Ç°ÕßÔÚÓÃÈí¼þ·½Ê½ÊµÏÖʱ¿ÉÒÔ»ñµÃ½Ï¿ìµÄ¼ÓÃÜËÙ¶È¡£ÎªÁË ½øÒ»²½Ìá¸ßϵͳЧÂÊ£¬¿ÉÒÔ²ÉÓÃרÓÃÓ²¼þµÄ·½Ê½ÊµÏÖÊý¾ÝµÄ¼ÓÃܺͽâÃÜ£¬Õâʱ²ÉÓÃDESËã·¨Äܵõ½½Ï¿ìµÄ¼ÓÃÜËÙ¶È¡£Ëæ×ŵ±Ç°¼ÆËã»úÔËËãÄÜÁ¦µÄÌá¸ß£¬DESËã·¨µÄ°² È«ÐÔ¿ªÊ¼Êܵ½ÌôÕ½£¬¶ÔÓÚ°²È«ÐÔÒªÇó¸ü¸ßµÄÍøÂçÊý¾Ý£¬Êý¾Ý¼ÓÃÜ/½âÃÜÄ£¿é¿ÉÒÔÌṩTriPle DES¼ÓÃÜ·þÎñ¡£
Êý¾Ý·Ö×éµÄ·â×°/·Ö½âÄ£¿éʵÏÖ¶ÔIPÊý¾Ý·Ö×é½øÐа²È«·â×°»ò·Ö½â¡£µ±´Ó°²È«Íø¹Ø·¢ËÍIPÊý¾Ý·Ö×éʱ£¬Êý¾Ý·Ö×é·â×°/·Ö½âÄ£¿éΪIPÊý¾Ý·Ö×鸽¼ÓÉÏÉí·ÝÈÏ
֤ͷAHºÍ°²È«Êý¾Ý·â×°Í·ESP¡£µ±°²È«Íø¹Ø½ÓÊÕµ½IP Êý¾Ý·Ö×éʱ£¬Êý¾Ý·Ö×é·â×°/·Ö½âÄ£¿é¶ÔAHºÍESP½øÐÐÐÒé·ÖÎö£¬²¢¸ù¾Ý°üÍ·ÐÅÏ¢½øÐÐÉí·ÝÑéÖ¤ºÍÊý¾Ý½âÃÜ¡£
¼ÓÃܺ¯Êý¿âΪÉÏÊöÄ£¿éÌṩͳһµÄ¼ÓÃÜ·þÎñ¡£¼ÓÃÜ º¯Êý¿âÉè¼ÆµÄÒ»Ìõ»ù±¾ÔÔòÊÇͨ¹ýÒ»¸öͳһµÄº¯Êý½Ó¿Ú½çÃæÓëÉÏÊöÄ£¿é½øÐÐͨÐÅ¡£ÕâÑù¿ÉÒÔ¸ù¾Ýʵ¼ÊµÄÐèÒª£¬ÔÚ¹Ò½Ó¼ÓÃÜËã·¨ºÍ¼ÓÃÜÇ¿¶È²»Í¬µÄº¯Êý¿âʱ£¬ÆäËüÄ£¿é²»Ðè×÷³ö¸Ä¶¯
4.»ùÓÚGREÐÒéµÄVPNÔÀí¼°ÊµÏÖ
1)GREÐÒé¼ò½é
GRE£¨Generic Routing Encapsulation£©¼´Í¨Ó÷ÓÉ·â×°ÐÒéÊǶÔÄ³Ð©ÍøÂç²ãÐÒ飨ÈçIPºÍIPX£©µÄÊý¾Ý±¨½øÐзâ×°£¬Ê¹ÕâЩ±»·â×°µÄÊý¾Ý±¨Äܹ»ÔÚÁíÒ»¸öÍøÂç²ãÐÒ飨ÈçIP£©Öд«Êä¡£GREÊÇVPN£¨Virtual Private Network £©µÄµÚÈý²ãËíµÀÐÒ飬¼´ÔÚÐÒé²ãÖ®¼ä²ÉÓÃÁËÒ»ÖÖ±»³ÆÖ®ÎªTunnel£¨ËíµÀ£©µÄ¼¼Êõ ¢Å GREµÄTunnel£¨ËíµÀ£©¹¤×÷ÔÀí
Ò»¸ö±¨ÎÄÒªÏëÔÚTunnelÖд«Ê䣬±ØÐëÒª¾¹ý¼Ó·â×°Óë½â·â×°Á½¸ö¹ý³Ì: a) ¼Ó·â×°¹ý³Ì
ÈçÏÂͼ£¬Á¬½ÓNovell group1µÄ½Ó¿ÚÊÕµ½IPXÊý¾Ý±¨ºóÊ×ÏȽ»ÓÉIPXÐÒé´¦Àí£¬IPXÐÒé¼ì²éIPX±¨Í·ÖеÄÄ¿µÄµØÖ·ÓòÀ´È·¶¨ÈçºÎ·Óɴ˰ü:
InternetIPXD-¨°¨¦Group1Router AtunnelRouter BIPXD-¨°¨¦Group2
GREµäÐÍ×éÍøÍ¼
b) ·â×°ºÃµÄ±¨ÎĵÄÐÎʽÈçÏÂͼËùʾ:
(Transport Protocol)GRE Header(Encapsulation Protocol)Payload Packet(Passenger Protocol)·â×°ºÃµÄTunnel±¨Îĸñʽ
c) ½â·â×°µÄ¹ý³Ì
½â·â×°¹ý³ÌºÍ¼Ó·â×°µÄ¹ý³ÌÏà·´¡£´ÓTunnel½Ó¿ÚÊÕµ½µÄIP±¨ÎÄ£¬Í¨¹ý¼ì²éÄ¿µÄµØÖ·£¬·¢ÏÖÄ¿µÄµØ¾ÍÊÇ´Ë·ÓÉÆ÷ʱ£¬°þµôIP±¨Í·£¬ÔÙ½»¸øGREÐÒé´¦Àíºó£¨½øÐмìÑéÃÜÔ¿¡¢¼ì²éУÑéºÍ»ò±¨ÎĵÄÐòÁкŵȣ©£¬°þµôGRE±¨Í·ºó£¬ÔÙ½»ÓÉIPXÐÒéÏó¶Ô´ýÒ»°ãÊý¾Ý±¨Ò»Ñù¶Ô´ËÊý¾Ý±¨½øÐд¦Àí¡£ÏµÍ³ÊÕµ½Ò»¸öÐèÒª·â×°ºÍ·ÓɵÄÊý¾Ý±¨£¬³ÆÖ®Îª¾»ºÉ(Payload)£¬Õâ¸ö¾»ºÉÊ×Ïȱ»¼ÓÉÏGRE·â×°£¬³ÉΪGRE±¨ÎÄ£»ÔÙ±»·â×°ÔÚIP±¨ÎÄÖУ¬ÕâÑù¾Í¿ÉÍêÈ«ÓÉIP²ã¸ºÔð´Ë±¨ÎĵÄÏòǰ´«Ê䣨Forwarded£©¡£Õâ¸ö¸ºÔðÏòǰ´«ÊäµÄIPÐÒé±»³ÆÎª´«µÝ£¨Delivery£©ÐÒé»ò´«Ê䣨Transport£©ÐÒé. ¢Æ GREÓ¦Ó÷¶Î§:
¢Ù ¶àÐÒé±¾µØÍøÍ¨¹ýµ¥Ò»ÐÒé¹Ç¸ÉÍø´«Êä
Novell IPX-¨°D¨¦Group1Novell IPX-¨°D¨¦Group2InternetInternettunnelIPD-¨°¨¦Term 1Router ARouter BIPD-¨°¨¦Term 2
¢Ú À©´ó°üº¬²½ÌøÊýÊÜÏÞÐÒ飨ÈçIPX£©µÄÍøÂçµÄ¹¤×÷·¶Î§
RoutertunnelRouterIP networkRouterPCrrIP networkIP networkRouterPC
¢Û ½«Ò»Ð©²»ÄÜÁ¬ÐøµÄ×ÓÍøÁ¬½ÓÆðÀ´£¬×齨VPN
Routernovellgroup 1IP networkVLANRouternovellgroup2tunnel
ÆäÖУ¬ÒÔµÚÒ»ÖÖÓ¦ÓÃΪÖ÷.
2»ùÓÚGRE£¬ÒÔIP·â×°IPXÔÀí¼°ÊµÏÖ ¢Å ÐÒé·â×°
Ò»¸ö·â×°ÔÚIP TunnelÖеÄIPX´«Ê䱨ÎĵĸñʽÈçÏ£º
IPGREIPX³Ë¿ÍÐÒé(Passager Protocol)ÔËÔØÐÒé»ò·â×°ÐÒé(Carrier Protocol)(Encapsulation Protocol)ÔËÊäÐÒé(Transport Protocol)
¢Æ IP³ÐÔØIPXµÄGREÓ¦ÓÃ×éÍøÍ¼
192.10.1.1202.18.3.2IPXD-¨°¨¦Group1tunnelIPXD-¨°¨¦Group21eRouter A1fInternet1fRouter B31
¢Ç GREÅäÖÃ
GREµÄ»ù±¾ÅäÖðüÀ¨ ´´½¨ÐéÄâTunnel½Ó¿Ú
ÅäÖÃTunnel½Ó¿ÚµÄÔ´¶ËµØÖ· ÅäÖÃTunnel½Ó¿ÚµÄÄ¿µÄµØÖ· ÅäÖÃTunnel½Ó¿ÚµÄÍøÂçµØÖ·