Professional Documents
Culture Documents
______________________________________________________________________
__
ti :
MC LC
I. Gii thiu v Cng ngh VPN.....................................................2
1.1 VPN l g................................................................................................................3
1.2 Li ch ca VPN em li.......................................................................................3
VPN lm gim chi ph thng xuyn:......................................................................4
Gim chi ph qun l v h tr.................................................................................4
VPN m bo an ton thng tin, tnh ton vn v xc thc4Error: Reference source not found
VPN d dng kt ni cc chi nhnh thnh mt mng cc b ..4
1.3 Cc thnh phn cn thit to kt ni VPN. 4
____________________________________________________________
__
Khoa in T Vin Thng i hc Khoa Hc T Nhin
2
V. Kt lun26
VI. Cch cu hnh m hnh VPN (Client to Site)..
VII.Ti liu tham kho.27
____________________________________________________________
__
Khoa in T Vin Thng i hc Khoa Hc T Nhin
3
VPN= ng h m + M ho
____________________________________________________________
__
Khoa in T Vin Thng i hc Khoa Hc T Nhin
4
1.2
Li ch ca VPN em li :
____________________________________________________________
__
Khoa in T Vin Thng i hc Khoa Hc T Nhin
5
____________________________________________________________
__
Khoa in T Vin Thng i hc Khoa Hc T Nhin
6
____________________________________________________________
__
Khoa in T Vin Thng i hc Khoa Hc T Nhin
8
3.2 ng hm
Hu ht cc VPN u da vo k thut gi l Tunneling to ra mt mng ring
trn nn Internet. V bn cht, y l qu trnh t ton b gi tin vo trong mt
____________________________________________________________
__
Khoa in T Vin Thng i hc Khoa Hc T Nhin
9
lp header (tiu ) cha thng tin nh tuyn c th truyn qua h thng mng
trung gian theo nhng "ng ng" ring (tunnel).
Khi gi tin c truyn n ch, chng c tch lp header v chuyn n cc
my trm cui cng cn nhn d liu. thit lp kt ni Tunnel, my khch v
my ch phi s dng chung mt giao thc (tunnel protocol).
Giao thc ca gi tin bc ngoi c c mng v hai im u cui nhn bit. Hai
im u cui ny c gi l giao din Tunnel (tunnel interface), ni gi tin i
vo v i ra trong mng.
K thut Tunneling yu cu 3 giao thc khc nhau:
- Giao thc truyn ti (Carrier Protocol) l giao thc c s dng bi mng c
thng tin ang i qua.
- Giao thc m ha d liu (Encapsulating Protocol) l giao thc (nh GRE, IPSec,
L2F, PPTP, L2TP) c bc quanh gi d liu gc.
- Giao thc gi tin (Passenger Protocol) l giao thc ca d liu gc c truyn i
(nh IPX, NetBeui, IP).
Ngi dng c th t mt gi tin s dng giao thc khng c h tr trn Internet (nh
NetBeui) bn trong mt gi IP v gi n an ton qua Internet. Hoc, h c th t mt gi tin dng
a ch IP ring (khng nh tuyn) bn trong mt gi khc dng a ch IP chung (nh tuyn)
m rng mt mng ring trn Internet.
____________________________________________________________
__
Khoa in T Vin Thng i hc Khoa Hc T Nhin
10
____________________________________________________________
__
Khoa in T Vin Thng i hc Khoa Hc T Nhin
11
L giao thc lp 2 c pht trin bi Cisco System. L2F c thit k cho php
to ng hm gia NAS v mt thit b VPN Getway truyn cc Frame, ngi
s dng t xa c th kt ni n NAS v truyn Frame PPP t remote user n
VPN Getway trong ng hm c to ra.
Giao thc PPTP(Point-to-Point Tunneling Protocol)
y l giao thc ng hm ph bin nht hin nay. Giao thc c pht trin bi
Microsoft.
PPTP cung cp mt phn ca dch v truy cp t xa RAS(Remote Access Service).
Nh L2F, PPTP cho php to ng hm t pha ngi dng(Mobile User) truy
cp vo VPN Getway/Concentrator
Giao thc L2TP
L chun giao thc do IETF xut, L2TP tch hp c hai im mnh l truy nhp
t xa ca L2F(Layer 2 Forwarding ca Cisco System) v tnh kt ni nhanh Point to Point ca PPTP(Point to Point Tunnling Protocol ca Microsoft). Trong mi
trng Remote Access L2TP cho php khi to ng hm cho cc frame v s
dng giao thc PPP truyn d liu trong ng hm.
Mt s u im ca L2TP
L2TP h tr a giao thc
Khng yu cu cc phn mm m rng hay s h tr ca HH. V vy
nhng ngi dng t xa cng nh trong mng Intranet khng cn ci thm
cc phn mm c bit.
L2TP cho php nhiu Mobile user truy cp vo Remote Network thng qua
h thng mng cng cng
L2TP khng c tnh bo mt cao tuy nhin L2TP c th kt hp vi c ch
bo mt IPSec bo v d liu.
____________________________________________________________
__
Khoa in T Vin Thng i hc Khoa Hc T Nhin
12
____________________________________________________________
__
Khoa in T Vin Thng i hc Khoa Hc T Nhin
13
Tn
IPSE
C
____________________________________________________________
__
Khoa in T Vin Thng i hc Khoa Hc T Nhin
14
PPTP
L2F
L2TP
+ p ng cc k
thut m ha
+ Chy trn nn
Win NT,98,95
+ nh ng hm
kt ni
+ Cung cp kh
nng a giao thc
+M ha RSA RC4
+ Cho php nh
ng hm a giao
thc
+ c cung cp
bi nhiu nh cung
cp
+ Kt hp PPTP v
L2F
+ Ch cn mt gi
chy trn X25 v
Frame relay
+ S dng IPSEC
cho vic m ha
nh sn xut
+ t h tr giao din
+ Khng cung cp m
ha d liu t nhng
my ch truy cp t
xa
+ Mang tnh c
quyn rng ln
+ Khng c m ha
+ Yu trong vic xc
thc ngi dng
+ Khng c iu
khinlung cho ng
hm
+ Cha c cung cp
nhiu trong sn phm
+ Khng bo mt
nhng on cui
+ c dng my
ch truy cp t xa
+ C th dng cho
my bn win9x
hay my trm dng
winNT
+ Dng cho truy cp
t xa
3.2 M ho
____________________________________________________________
__
Khoa in T Vin Thng i hc Khoa Hc T Nhin
15
____________________________________________________________
__
Khoa in T Vin Thng i hc Khoa Hc T Nhin
16
ng hm GRE
Generic routing encapsulation (GRE) c khi xng v pht trin bi Cisco v
sau c IETF xc nhn thnh chun RFC 1702. GRE c dng khi to
cc ng hm v c th vn chuyn nhiu loi giao thc nh IP, IPX, Apple Talk
v bt k cc gi d liu giao thc khc vo bn trong ng hm IP. GRE khng
c chc nng bo mt cp cao nhng c th c bo v bng cch s dng c ch
IPSec. Mt ng hm GRE gia 2 site, IP c th vn ti c c th c
m t nh l mt VPN bi v d liu ring gia 2 site c th c ng gi thnh
cc gi tin vi phn Header tun theo chun GRE.
____________________________________________________________
__
Khoa in T Vin Thng i hc Khoa Hc T Nhin
17
____________________________________________________________
__
Khoa in T Vin Thng i hc Khoa Hc T Nhin
18
i xng(Symmetric)
Bt i xng(Asymmetric)
Public Key thng c dng gii quyt vn phn phi Key ca thut ton
i xng. Public Key khng thay th Symmetric m chng tr gip ln nhau.
Digital Signatures
Mt ng dng khc ca thut ton m ho cng khai l ch k in t(Digital
Signature). Tr li bi ton Alice v Bob. Lc ny Bob mun chng thc l th
Alice gi cho mnh do chnh Alice gi ch khng phi l mt l th nc danh t
mt k thc 3 no . Do vy mt ch k in t c sinh ra v gn km vo tp
tin ca Alice, Bob s dng Public Key gii m v xc nhn y ng l ch k
ca Alice. C ch xc thc nh sau:
C ch xc thc ch k s
____________________________________________________________
__
Khoa in T Vin Thng i hc Khoa Hc T Nhin
22
Hnh: Hin th mt IP Packet c bo v bi IPSec trong
ch Transport Mode
____________________________________________________________
__
Khoa in T Vin Thng i hc Khoa Hc T Nhin
24
Gi d liu IP c bo v bi ESP
Gi IP c bo v bi AH
AH l mt giao thc IP, c xc nh bi gi tr 51 trong IP Header. Trong ch
Transport, g tr giao thc lp trn c bo v nh UPD, TCP..., trong ch
Tunnle, gi tr ny l 4. V tr ca AH trong ch Transport v Tunnle nh trong
hnh sau:
____________________________________________________________
__
Hnh: Gi IP c bo v bi AH trong ch
Khoa in T Vin Thng i hcTransport
Khoa Hc T Nhin
26
Gi IP bo v bi AH trong ch Tunnle
Trong ch Transport, AH l rt tt cho kt ni cc endpoint s dng IPSec,
trong ch Tunnle AH ng gi gi IP v thm IP Header vo pha trc Header.
Qua AH trong ch Tunnle c s dng cung cp kt ni VPN end-to-end
bo mt. Tuy nhin phn ni dung ca gi tin l khng c bo mt
Tin trnh chng thc bt tay 3 bc Three-Way CHAP Authentication Process
____________________________________________________________
__
Khoa in T Vin Thng i hc Khoa Hc T Nhin
27
____________________________________________________________
__
Khoa in T Vin Thng i hc Khoa Hc T Nhin
28
VI. Kt lun
Hin nay xu hng cc cng ty c nhiu chi nhnh l ph bin, do nhu cu trao i
thng tin gia cc chi nhnh l cn thit v cp bch. Do vy trong tng lai, nhu
cu trin khai h thng mng VPN gia cc chi nhnh trong mt cng ty l nhu cu
tt yu.
____________________________________________________________
__
Khoa in T Vin Thng i hc Khoa Hc T Nhin
29
Quy c:
card LAN: card mng dng ni gia 2 my vi nhau
card INTERNET: card mng ni n switch cc my u thy nhau v ni vo
Router
- M hnh bi Lab nh sau:
**Quy c:
card LAN: card mng dng ni gia 2 my vi nhau
card INTERNET: card mng ni n switch cc my u thy nhau
v ni vo Router
Client1 : s dng 1 card
Card LAN:
IP Address : 172.16.1.2
Subnet Mask : 255.255.0.0
Default Gateway : 172.16.1.1
Preferred DNS : trng
SERVER1
Card LAN:
IP Address : 172.16.1.1
Subnet Mask : 255.255.0.0
____________________________________________________________
__
Khoa in T Vin Thng i hc Khoa Hc T Nhin
30
Password: 123
-b du chn ti User must change password at next logon.
OK Cho php U1 c quyn Allow access
____________________________________________________________
__
Khoa in T Vin Thng i hc Khoa Hc T Nhin
32
____________________________________________________________
__
Khoa in T Vin Thng i hc Khoa Hc T Nhin
33
____________________________________________________________
__
Khoa in T Vin Thng i hc Khoa Hc T Nhin
34
____________________________________________________________
__
Khoa in T Vin Thng i hc Khoa Hc T Nhin
35
____________________________________________________________
__
Khoa in T Vin Thng i hc Khoa Hc T Nhin
36
____________________________________________________________
__
Khoa in T Vin Thng i hc Khoa Hc T Nhin
37
____________________________________________________________
__
Khoa in T Vin Thng i hc Khoa Hc T Nhin
39
____________________________________________________________
__
Khoa in T Vin Thng i hc Khoa Hc T Nhin
40
____________________________________________________________
__
Khoa in T Vin Thng i hc Khoa Hc T Nhin
41
____________________________________________________________
__
Khoa in T Vin Thng i hc Khoa Hc T Nhin
42
____________________________________________________________
__
Khoa in T Vin Thng i hc Khoa Hc T Nhin
43
1.
2.
3.
____________________________________________________________
__
Khoa in T Vin Thng i hc Khoa Hc T Nhin
44