1. Trang chủ
  2. » Giáo Dục - Đào Tạo

26 introducing VPN solutions kho tài liệu bách khoa

17 57 0

Đang tải... (xem toàn văn)

Tài liệu hạn chế xem trước, để xem đầy đủ mời bạn chọn Tải xuống

THÔNG TIN TÀI LIỆU

Thông tin cơ bản

Định dạng
Số trang 17
Dung lượng 0,95 MB

Các công cụ chuyển đổi và chỉnh sửa cho tài liệu này

Nội dung

What Is a VPN?Virtual: Information within a private network is transported over a public network.. IPsec VPN Deployment• Site-to-site VPNs – Fully meshed static – Hub static and spoke dy

Trang 1

BSCI v3.0—2-1 Introducing VPN Solutions

Trang 2

VPN Taxonomy

Trang 3

VPN Models

VPN services can be offered based on two major

models:

Overlay VPNs , in which the service provider provides virtual point-to-point links between customer sites

Peer-to-peer VPNs , in which the service provider participates

in the customer routing

Trang 4

What Is a VPN?

Virtual: Information within a private network is transported over a public network.

Private: The traffic is encrypted to keep the data confidential.

Trang 5

Benefits of VPN

Cost

Security

Scalability

Trang 6

IPsec VPN Deployment

Site-to-site VPNs

Fully meshed (static)

Hub (static) and spoke (dynamic)

Fully meshed on demand (dynamic)

Cisco Easy VPN

WebVPN (Cisco IOS SSL VPN)

Trang 7

Site-to-Site VPNs

Site-to-site VPN: extension of classic WAN

Trang 8

Remote-Access VPNs

Remote-access VPN: evolution of dial-in networks and ISDN

Trang 9

Fully Meshed VPNs

IPsec Tunnel

Static IP Addresses

 There are static public

addresses between peers

 Local LAN addresses can

be private or public

Trang 10

Hub-and-Spoke VPNs

Static IP Addresses

IPsec Tunnel

Dynamic IP Addresses

 Static public address

needed at the hub only

 Spoke addresses can be

dynamically applied using

DHCP

Trang 11

Dynamic Multipoint VPNs

IPsec Tunnel

Static IP Addresses

Dynamic IP Addresses

Dynamic Spoke-to-Spoke IPsec Tunnels

 Local LAN addresses can be private

Trang 12

Easy VPN

Clients

Cisco Easy VPN

Workplace Resources

Internet

Cisco IOS Router and Easy VPN Server

 Cisco Unity is the common VPN language

between Cisco devices

Remote Office Home Office

Headquarters

Trang 13

Cisco IOS WebVPN

Workplace Resources

Internet

WebVPN

 Integrated security and routing

 Clientless and full network SSL VPN access

SSL VPN Tunnel

Headquarters

Trang 14

Generic Routing Encapsulation

OSI Layer 3 tunneling protocol:

Uses IP for transport

Uses an additional header to support any other OSI Layer 3 protocol as payload (e.g., IP, IPX, AppleTalk)

Trang 15

Default GRE Characteristics

Tunneling of arbitrary OSI Layer 3 payload is the primary goal

of GRE

Stateless (no flow control mechanisms)

No security (no confidentiality, data authentication, or

integrity assurance)

24-byte overhead by default (20-byte IP header and 4-byte

GRE header)

Trang 16

GRE Configuration Example

GRE tunnel is up and protocol up if:

Tunnel source and destination are configured

Tunnel destination is in routing table

GRE keepalives are received (if used)

GRE is the default tunnel mode.

Ngày đăng: 08/11/2019, 17:22

TỪ KHÓA LIÊN QUAN

w