5.3 IPSECµÄ°²È«ÐÔ
ÔÚÄúµÄ×éÖ¯Öв¿Êð IPSec ֮ǰ£¬Ç뿼ÂÇÏÂÁа²È«ÎÊÌ⣺
l 3DES ºÍÔËÐÐ Microsoft® Windows® 2000 µÄ¼ÆËã»ú
l Éí·ÝÑéÖ¤·½·¨
l ·À»ðǽÊý¾Ý°üɸѡ
l Êܱ£»¤µÄͨÐÅ
l Diffie-Hellman С×é
l IPSECµÄ¹¤×÷ģʽ
5.3.1 3DESºÍÔËÐÐWindows 2000¼ÆËã»ú
IPSec ²ßÂÔÔÊÐíÑ¡ÔñÇ¿¼ÓÃÜËã·¨ 3DES£¬¸ÃËã·¨ÌṩµÄ¼ÓÃÜÐÔÄÜÇ¿ÓÚ DES£¬¾ßÓнϸߵݲȫÐÔ¡£ÔËÐÐ Windows 2000 µÄ¼ÆËã»ú±ØÐë°²×°¡°¸ß¼¶¼ÓÃÜÊý¾Ý°ü¡±»ò¡°Service Pack 2¡±£¨»ò¸ü¸ß°æ±¾£©²ÅÄÜÖ´ÐÐ 3DES Ëã·¨¡£Èç¹ûÔËÐÐ Windows 2000 µÄ¼ÆËã»ú½ÓÊÕ 3DES ÉèÖ㬵«ÉÐδ°²×°¡°¸ß¶È¼ÓÃܰü¡±»ò¡°Service Pack 2¡±£¨»ò¸ü¸ß°æ±¾£©£¬Ôò 3DES ÉèÖý«±»ÉèÖÃΪ°²È«ÐÔ½ÏµÍµÄ DES ÒÔÌṩһ¶¨³Ì¶ÈµÄͨÐű£ÃÜ£¬¶ø²¢·Ç×èÖ¹Õû¸öͨÐÅ¡£µ«ÊÇ£¬Èç¹ûÄúµÄ»·¾³ÖеļÆËã»ú²¢²»¶¼Ö§³ÖʹÓà 3DES£¬×÷ΪÕÛÖÔÑ¡Ôñ£¬ÄúÓ¦¸Ã½öʹÓà DES¡£ÔËÐÐ Windows XP ºÍ Windows Server 2003 ¼Ò×åµÄ¼ÆËã»úÖ§³Ö 3DES ÇÒ²»ÐèÒª°²×°¡°¸ß¼¶¼ÓÃÜÊý¾Ý°ü¡±¡£
5.3.2 Éí·ÝÑéÖ¤·½·¨
Èç¹ûÆóÒµÖеļÆËã»úÊÇ Active Directory® ÓòÖеÄÒ»²¿·Ö£¬Ôò IPSec Ö÷ģʽÉí·ÝÑéÖ¤¿ÉÒÔʹÓÃĬÈϵÄÉí·ÝÑéÖ¤·½·¨ (Kerberos V5) Íê³É¡£²»±ØÎª Intranet ͨÐŲ¿Êð¹«Ô¿Ö¤Ê顣Ȼ¶ø£¬ÔËÐÐ Windows XP Home Edition µÄ¼ÆËã»ú²»Ö§³Ö Kerberos V5 Éí·ÝÑéÖ¤·½·¨¡£´ËÍ⣬Èç¹ûÄúÓÐÁ¬½Óµ½ Internet µÄ¼ÆËã»ú£¬½¨Ò鲻ҪʹÓà Kerberos V5 ×÷ΪÉí·ÝÑéÖ¤·½·¨¡£ÔÚʹÓà Kerberos ½øÐÐÉí·ÝÑé֤ʱ£¬ÔÚÖ÷ģʽÐÉÌÆÚ¼ä£¬Ã¿¸ö IPSec ¶ÔµÈ¶Ë¶¼ÒԷǼÓÃܵĸñʽ½«Æä¼ÆËã»ú±êʶ·¢Ë͵½ÁíÍâһ̨¶ÔµÈ¶Ë¡£ÔÚÖ÷ģʽÐÉ̵ÄÉí·ÝÑéÖ¤½×¶Î£¬Ö±ÖÁ¶ÔÕû¸ö±êʶ¸ºÔؼÓÃÜÖ®ºó£¬¼ÆËã»ú±êʶ²Å»á±»¼ÓÃÜ¡£¹¥»÷Õ߿ɷ¢ËÍÒ»¸ö¡°Internet ÃÜÔ¿½»»» (IKE)¡±Êý¾Ý°ü£¬¸ÃÊý¾Ý°ü»áµ¼ÖÂÏìÓ¦µÄ IPSec ¶ÔµÈ¶Ë±©Â¶Æä¼ÆËã»ú±êʶºÍÓò³ÉÔ±¡£Òò´Ë£¬Îª±£»¤Á¬½Óµ½ Internet µÄ¼ÆËã»ú£¬½¨ÒéʹÓõڶþÖÖÉí·ÝÑéÖ¤·½·¨¡ªÖ¤ÊéÉí·ÝÑéÖ¤¡£
Ò²¿ÉÒÔͨ¹ýÒ»¸öÔ¤¹²ÏíÃÜÔ¿À´ÌṩµÚÈýÖÖÉí·ÝÑéÖ¤·½·¨¡£µ«Òª»ñµÃÔöÇ¿µÄ°²È«ÐÔ£¬²»ÍƼöʹÓÃÔ¤¹²ÏíÃÜÔ¿Éí·ÝÑéÖ¤£¬Ïà¶ÔÀ´ËµËüÊÇÒ»ÖֱȽÏÈõµÄÉí·ÝÑéÖ¤·½·¨¡£´ËÍ⣬Ԥ¹²ÏíÃÜÔ¿ÒÔÃ÷ÎÄ·½Ê½´æ´¢¡£Ô¤¹²ÏíÃÜÔ¿µÄÉí·ÝÑéÖ¤·½·¨ÊdzöÓÚ»¥²Ù×÷ÐÔµÄÄ¿µÄ²¢×ñÑ IPSec ±ê×¼¡£½¨ÒéÖ»½«Ô¤¹²ÏíÃÜÔ¿ÓÃÓÚ²âÊÔ¡£
5.3.3 ·À»ðǽÊý¾Ý°üɸѡ
¶ÔÓÚ·À»ðǽ¡¢°²È«Íø¹Ø¡¢Â·ÓÉÆ÷»òÁ¬½Óµ½ Internet ²¢ÎªÍâÎ§ÍøÂ磨Ҳ½ÐÍøÂç¸ôÀëÇø»ò DMZ£©ÌṩÊý¾Ý°üɸѡÐÔÄܵÄÈÎºÎÆäËû·þÎñÆ÷»òÉ豸£¬±ØÐëÔڸüÆËã»úÉÏÆôÓÃÌØÊâɸѡÀ´È·±£ÔÊÐí½«Ê¹Óà IPSec ±£»¤µÄÊý¾Ý°üת·¢¸ø¸ÃÍâÎ§ÍøÂçÉϵļÆËã»ú¡£Í¨³££¬·À»ðǽ»òÆäËûÉ豸Ӧ¸ÃÔÊÐíÏÂÁÐͨÐÅÀàÐÍͨ¹ý£º
l ÓÃÓÚ IPSec ·âװʽ°²È«´ëÊ©¸ºÔØ (ESP) ͨÐÅµÄ IP ÐÒé ID 50 (0x32)¡£
l ÓÃÓÚ IPSec Éí·ÝÑéÖ¤±¨Í· (AH) ͨÐÅµÄ IP ÐÒé ID 51 (0x33)¡£
l ÓÃÓÚ¡°Internet ÃÜÔ¿½»»» (IKE)¡±ÐÉÌͨÐÅµÄ UDP ¶Ë¿Ú 500 (0x1F4)¡£
´ó²¿·ÖÊý¾Ý°üɸѡÈí¼þ¶¼ÔÊÐíͨ¹ý¸üÌØ¶¨µÄͨÐÅ¡£¿ÉΪÒÔÏÂÄÚÈÝ·Ö±ð¶¨Òåµ¥¶ÀµÄÊý¾Ý°üɸѡÆ÷£ºÈëվͨÐÅ£¨ÈëվɸѡÆ÷£©¡¢³öվͨÐÅ£¨³öվɸѡÆ÷£©ºÍÿ¸ö½Ó¿Ú¡£´ËÍ⣬»¹¿ÉΪÍâÎ§ÍøÂçÉ쵀 IPSec ¼ÆËã»úÖ¸¶¨ IP µØÖ·¡£
5.3.4 Êܱ£»¤µÄͨÐÅ
IPSECʹÓÃAHºÍESPÀ´±£Ö¤´«ÊäÊý¾ÝµÄ»úÃÜÐÔºÍÕæÊµ¿É¿¿¡£
l Éí·ÝÑéÖ¤±¨Í· (AH) ¿É¶ÔÕû¸öÊý¾Ý°ü£¨IP ±¨Í·ÓëÊý¾Ý°üÖеÄÊý¾Ý¸ºÔØ£©ÌṩÉí·ÝÑéÖ¤¡¢ÍêÕûÐÔÓë¿¹ÖØ²¥±£»¤¡£µ«ÊÇËü²»Ìṩ±£ÃÜÐÔ£¬¼´Ëü²»¶ÔÊý¾Ý½øÐмÓÃÜ¡£Êý¾Ý¿ÉÒÔ¶ÁÈ¡£¬µ«ÊǽûÖ¹Ð޸ġ£AH ʹÓüÓÃܹþÏ£Ë㷨ǩÃûÊý¾Ý°üÒÔÇóµÃÍêÕûÐÔ¡£
l ·âװʽ°²È«´ëÊ©¸ºÔØ (ESP) ²»½öΪ IP ¸ºÔØÌṩÉí·ÝÑéÖ¤¡¢ÍêÕûÐԺͿ¹Öز¥±£»¤£¬»¹Ìṩ»úÃÜÐÔ¡£´«ÊäģʽÖÐµÄ ESP ²»¶ÔÕû¸öÊý¾Ý°ü½øÐÐÇ©Ãû¡£Ö»¶Ô IP ¸ºÔØ£¨¶ø²»¶Ô IP ±¨Í·£©½øÐб£»¤¡£ESP ¿ÉÒÔ¶ÀÁ¢Ê¹Óã¬Ò²¿ÉÓë AH ×éºÏʹÓá£
Óë¶Ôÿ¸öÊý¾Ý°ü½øÐмÓÃÜÓë½âÃÜÏà±È£¬Ñé֤ÿ¸öÊý¾Ý°üµÄ¹þÏ£ËùÏûºÄµÄ CPU Ïà¶Ô½ÏÉÙ¡£Èç¹ûÐÔÄÜÎÊÌâÊÇÖ÷ÒªµÄ¿¼ÂÇÊÂÏÔò¿ÉʹÓà AH À´±£»¤´ó²¿·ÖͨÐÅ¡£ÐèÒª±£ÃÜʱ£¬¿ÉʹÓà ESP¡£ÀýÈ磬¿ÉʹÓà AH ±£»¤ Intranet ÉϵÄͨÐÅ£¬Ê¹Óà ESP ±£»¤Í¨¹ý Internet ·¢Ë͵ÄͨÐÅ¡£
5.3.5 Diffie-Hellman С×é
Diffie-Hellman £¨Ê¹Óà Diffie-Hellman С×é 1¡¢2 »ò 2048£©Ð¡×éÓÃÀ´È·¶¨ÃÜÔ¿½»»»¹ý³ÌÖÐʹÓõĻù±¾ËØÊýµÄ³¤¶È¡£×é 2048£¨¸ß£©±È×é 2£¨ÖУ©¸üÇ¿£¨¸ü°²È«£©£¬¶ø×é 2 Ç¿ÓÚ×é 1£¨µÍ£©¡£×é 1 Ìṩ 768 λµÄÃÜÔ¿Ç¿¶È£»×é 2 Ìṩ 1,024 λµÄÃÜÔ¿Ç¿¶È£»×é 2048 Ìṩ 2,048 λµÄÃÜÔ¿Ç¿¶È¡£
½«Ç¿ Diffie-Hellman С×éºÍ½Ï³¤µÄÃÜÔ¿³¤¶È½áºÏʹÓÿÉÒÔÌá¸ßÈ·¶¨ÃÜÔ¿µÄ¼ÆËãÄѶȡ£
ÒÔÏÂÊÇÔÚÔËÓÃDiffie-Hellman С×éʱµÄһЩעÒâÊÂÏ
l ΪÁË»ñµÃÔöÇ¿µÄ°²È«ÐÔ£¬Ç벻ҪʹÓà Diffie-Hellman С×é 1¡£Îª»ñµÃ×î¼Ñ°²È«ÐÔ£¬Ç뾡¿ÉÄÜʹÓÃ×é 2048¡£µ±ÐèÒª±£Ö¤Óë Windows 2000 ºÍ Windows XP µÄ»¥²Ù×÷ÐÔʱ£¬ÇëʹÓÃ×é 2¡£
l Diffie-Hellman С×é 2048 ½öËæ Windows Server 2003 ¼Ò×åÒ»ÆðÌṩ¡£
5.3.6 IPSECµÄ¹¤×÷ģʽ
IPSECʽµÄ¹¤×÷ģʽÓÐÁ½ÖÖ£º´«ÊäģʽºÍËíµÀģʽ¡£
´«ÊäģʽÊÇ IPSec µÄĬÈÏģʽ£¬ÓÃÓÚ½øÐж˶Զ˵ÄͨÐÅ£¨ÀýÈ磬ÓÃÓÚ¿Í»§¶ËºÍ·þÎñÆ÷Ö®¼äµÄͨÐÅ£©¡£µ±Ê¹Óô«Êäģʽʱ£¬IPSec Ö»¶Ô IP ¸ºÔؽøÐмÓÃÜ¡£´«Êäģʽͨ¹ý AH »ò ESP ±¨Í·¶Ô IP ¸ºÔØÌṩ±£»¤¡£µäÐ굀 IP ¸ºÔذüÀ¨ TCP ¶Î£¨°üº¬ TCP ±¨Í·Óë TCP ¶ÎÊý¾Ý£©¡¢Ò»Ìõ UDP ÏûÏ¢£¨°üº¬ UDP ±¨Í·Óë UDP ÏûÏ¢Êý¾Ý£©ÒÔ¼°Ò»Ìõ ICMP ÏûÏ¢£¨°üº¬ ICMP ±¨Í·Óë ICMP ÏûÏ¢Êý¾Ý£©¡£
ʹÓà IPSec ËíµÀģʽʱ£¬IPSec ¶Ô IP ±¨Í·ºÍ¸ºÔؽøÐмÓÃÜ£¬¶ø´«Êäģʽֻ¶Ô IP ¸ºÔؽøÐмÓÃÜ¡£Í¨¹ý½«Æäµ±×÷ AH »òÕß ESP ¸ºÔØ£¬ËíµÀģʽÌṩ¶ÔÕû¸ö IP Êý¾Ý°üµÄ±£»¤¡£Ê¹ÓÃËíµÀģʽʱ£¬»áͨ¹ý AH »ò ESP ±¨Í·ÓëÆäËû IP ±¨Í·À´·â×°Õû¸ö IP Êý¾Ý°ü¡£Íⲿ IP ±¨Í·µÄ IP µØÖ·ÊÇËíµÀÖÕ½áµã£¬·â×°µÄ IP ±¨Í·µÄ IP µØÖ·ÊÇ×îÖÕÔ´µØÖ·ÓëÄ¿±êµØÖ·¡£
IPSec ËíµÀģʽ¶ÔÓÚ±£»¤²»Í¬ÍøÂçÖ®¼äµÄͨÐÅ£¨µ±Í¨ÐűØÐë¾¹ýÖмäµÄ²»ÊÜÐÅÈεÄÍøÂçʱ£©Ê®·ÖÓÐÓá£ËíµÀģʽÖ÷ÒªÓÃÀ´Óë²»Ö§³Ö L2TP/IPSec »ò PPTP Á¬½ÓµÄÍø¹Ø»òÖÕ¶Ëϵͳ½øÐÐÏ໥²Ù×÷¡£¿ÉÒÔÔÚÏÂÁÐÅäÖÃÖÐʹÓÃËíµÀģʽ£º
l Íø¹Øµ½Íø¹Ø
l ·þÎñÆ÷µ½Íø¹Ø
l ·þÎñÆ÷µ½·þÎñÆ÷
5.4 IPSECµÄÅäÖÃ
5.4.1 ÆóÒµ±³¾°
ÄãµÄ¹«Ë¾ÕýÔÚÖÆ¶©Ò»Ïî°üÀ¨ÒµÎñ»ï°éÔÚÄڵĹ滮¡£ÓйØÕâÏî¹æ»®µÄ¹¤×÷ÒªÇ󼫯䱣ÃÜ¡£ÄãµÄÒµÎñ»ï°é½«ÀûÓÃInternet·ÃÎÊÄãµÄ·þÎñÆ÷ÉϵÄijЩÊý¾Ý¡£Äã±ØÐëÈ·±£Ä㹫˾µÄ¼ÆËã»úºÍÄãµÄÒµÎñ»ï°é¼ÆËã»úÖ®¼äµÄËùÓÐÍøÂçÊý¾ÝÁ÷ͨ¶¼¼ÓÃܽøÐС£
×÷Ϊ¹«Ë¾µÄÍøÂç¹ÜÀíÔ±£¬Ä㽫²ÉÓÃIPSECΪ¿çÔ½InternetµÄͨÐÅÌṩ°²È«µÄ±£»¤£¨ÔÚÕâÀïÎÒÃǽ«ÒªÍ¨ÐŵļÆËã»úÃû·Ö±ðÃüÃûΪHOSTAºÍHOSTB£©¡£
±¾´ÎÅäÖÃͨ¹ý±£»¤FTPͨÐŵݲȫΪÀý½²½âIPSecµÄʹÓ÷½·¨¡£
5.4.2 ÅäÖò½Öè
l ûÓÐIPSEC±£»¤ÏµÄFTPͨÐÅ
l ÔÚIPSEC±£»¤ÏµÄFTPͨÐÅ
5.4.2.1 ûÓÐIPSEC±£»¤ÏµÄFTPͨÐÅ
1¡¢¿Í»§¶ËÐèÒª´Ó·þÎñÆ÷ÉÏÏÂÔØÒ»Ð©ÓйØturboc2µÄ×ÊÔ´£¬ËùÒÔ¹ÜÀíÔ±Ê×ÏÈÔÚ·þÎñÆ÷ÉÏΪ֮´´½¨ÁËÒ»¸öFTPÕ¾µã¡£ÈçÏÂͼËùʾ£º
2¡¢¿Í»§¶Ëͨ¹ýÍøÂç·ÃÎÊ´´½¨µÄFTPÕ¾µã¡£ÈçÏÂͼËùʾ£º
3¡¢ÒÔÏÂÊÇͨ¹ýÍøÂç¼àÊÓÆ÷²¶×½µ½µÄÍøÂçÁ÷Á¿¡£
4¡¢Óɲ¶»ñµÄÁ÷Á¿ÖÐÎÒÃÇ¿ÉÒÔÇå³þµÄ¿´µ½FTPͨÐÅʱµÄÓû§ÃûºÍ¿ÚÁËùÒÔûÓÐIPSEC±£»¤ÏµÄFTPͨÐÅÊDz»°²È«µÄ¡£
5.4.2.2 ÔÚIPSEC±£»¤ÏµÄFTPͨÐÅ
1¡¢µÇ¼µ½HOSTA£¬µ¥»÷¡°¿ªÊ¼¡±£¬È»ºóµ¥»÷¡°ÔËÐС±°´Å¥£¬ÔÚÔËÐÐÖÐÊäÈë¡°MMC¡±£¬´ò¿ªÎ¢Èí¹ÜÀí¿ØÖÆÌ¨£¬×î´ó»¯¿ØÖÆÌ¨¸ù´°¿Ú¡£
2¡¢ÔÚ¿ØÖÆÌ¨1µÄµ¥ÖУ¬µ¥»÷¡°Ìí¼Ó/ɾ³ý²å¼þ¡±¡£

3¡¢ÔÚ¡°Ìí¼Ó/ɾ³ý²å¼þ¡±¶Ô»°¿òÖУ¬µ¥»÷¡°Ìí¼Ó¡±°´Å¥¡£
4¡¢ÔÚ¶Ô»°¿òÖУ¬È·ÈÏÑ¡Ôñ¡°IP°²È«²ßÂÔ¹ÜÀí¡±£¬µ¥»÷¡°Ìí¼Ó¡±²¢Ñ¡Ôñ¡°±¾µØ¼ÆËã»ú¡±°´Ä¬ÈÏÉèÖÃÍê³ÉIPSECµÄÌí¼Ó¡£
5¡¢IPSECÆô¶¯ºó£¬»á´ò¿ªÒ»¸ö¹ÜÀí¿ØÖÆÌ¨£¬ÀïÃæÓÐһЩԤ¶¨ÒåµÄ²ßÂÔ¡£
6¡¢ÓÒ»÷¡°IP°²È«²ßÂÔ¡±£¬Ñ¡Ôñ¡°¹ÜÀíIPɸѡÆ÷±íºÍɸѡÆ÷²Ù×÷¡±¡£
7¡¢ÔÚÕâÀïÎÒÃÇ´´½¨Ò»¸öеÄÕë¶ÔFTP·ÃÎʵÄIPɸѡÆ÷£¬ÆäÔ´µØÖ·Îª¡°ÈκεØÖ·¡±£¬Ä¿±êµØÖ·Îª¡°±¾µØIP¡±£¬¶Ë¿ÚºÅ·Ö±ðΪ20ºÍ21¡£ÈçÏÂͼËùʾ£º
8¡¢ÔÚ¿ØÖÆÌ¨Ê÷ÖУ¬ÓÒ¼üµ¥»÷¡°±¾µØ¼ÆËã»úÉϵݲȫÐÔ²ßÂÔ¡±£¬ÔÙµ¥»÷¡°´´½¨IP°²È«²ßÂÔ¡±£¬½øÈë¡°IP°²È«²ßÂÔÏòµ¼¡±¡£
9¡¢ÎÒÃÇ´´½¨Ò»¸öеÄIP°²È«²ßÂÔÈ¡ÃûΪ¡°°²È«FTPͨÐÅ¡±£¬ÈçÏÂͼËùʾ£º
10¡¢ÔÚ¡°°²È«FTPͨÐÅÊôÐÔ¡±Öеã»÷¡°Ìí¼Ó¡±£¬½øÈëIP°²È«¹æÔòÏòµ¼¡£
11¡¢ÔÚ¡°IPɸѡÆ÷ÁÐ±í¡±ÖÐÑ¡ÔñÎÒÃǸղŴ´½¨µÄɸѡÆ÷¡°°²È«FTP·ÃÎÊ¡±¡£
12¡¢È»ºóÔÚ¡°É¸Ñ¡Æ÷²Ù×÷¡±ÖÐÑ¡Ôñ¡°ÇëÇó°²È«£¨¿ÉÑ¡£©¡±£¬²¢±à¼Æä´ëʩΪ¡°ÐḚ́²È«¡±¡£ÔÚÉí·ÝÑéÖ¤·½·¨Ì¨Ñ¡Ôñ¡°Ô¤¹²ÏíÃÜÔ¿¡±£¬²¢ÉèÖÃÃÜԿΪ¡°123456¡±¡£½á¹ûÈçÏÂͼËùʾ£º
13¡¢Íê³É´´½¨ºó£¬»¹ÐèÖ¸ÅÉÕâ¸ö²ßÂÔ¡£ÈçÏÂͼËùʾ¡£
14¡¢Í¬ÑùµÄ·½·¨£¬ÔÚ¿Í»§¶ËÒ²Òª´´½¨Ò»¸öÓÃÓÚFTPͨÐŵIJßÂÔ£¬²¢Ö¸ÅÉ¡£ÏÂͼΪ¿Í»§¶Ë´´½¨µÄIP²ßÂÔÆ÷£¬Æä·½ÏòԴΪ¿Í»§¶ËºÍÄ¿±êΪFTP·þÎñÆ÷¡£
15¡¢Ë«·½Ö¸¶¨IPSEC²ßÂÔºóÔÙ½øÐÐFTPͨÐÅ¡£ÒÔÏÂÊÇͨ¹ýÍøÂç¼àÊÓÆ÷²¶»ñÁ¿Ë«·½Í¨ÐÅÁ÷Á¿£¬¿É¼û²»ÔÙ¿´µ½Í¨ÐŵÄÓû§ÃûºÍ¿ÚÁȫ²¿ÊÇESP¼ÓÃܵİü¡£¿É¼ûIPSEC¿ÉÒÔ±£»¤ÍøÂçͨÐŵݲȫ¡£