Title: IPSec??
1IPSec??
- ???
- shenguowei_at_hrbeu.edu.cn
2????
IPSec???????
IPSec?AH??
IPSec?ESP??
IPSec?IKE??
??IPSec?VPN??
3IPSec??
??
????????????,?????????????????????????
1
?????(Authentication Header, AH)
2
??????(Encapsulating Security Payload, ESP)
3
Internet????(Internet Key Exchange, IKE)
4IPSec???????
5IPSec?????
6IPSec????
????
????
7AH??
AH?? ?IP??????????????? ????????????
??????(????)????IP???(????)
AH???
8AH???
AH??????? ?????????
????
????
9ESP??
- ESP????
- ?IP???????????????????????????????
ESP???
10IKE??
IKE????ISAKMP?Oakley?SKEME,????????,?????ISAKMP??
??????,?????Oakley?SKEME???????
IKE?? ????
11IKE?????
- 1.Diffie-Hellman????
- 2.????
- 3.??????
- 4.??????
- 5.????
12IKE??????
IKEv2??? IPSec????2005?12????IKE2? IKERFC2409 IK
Ev2RFC4306
13??IPSec?VPN??
- VPN???
- RFC2746?IP VPN?????IP VPN?????IP??????????????,?
?ISP????NSP???????????,?????????????? - VPN?????
- 1.IPSec??
- 2.MPLS??
- 3.SSL??
14???IPSec VPN?????
15IKE??1
16IKE??2
17IPSec SA (Security Association)
?SPI (Security Parameter Index),?IKE???????????,?
?SPI???IPSec??????????,??SPI???SAD?SPD,??????????
????????hash???????SA????????,????IPSec??????IPSe
c SA?
18? ?!