. , , ,

,,,

VPN — ,

 

û


:

The removed access to a private network through the Internet

(Dubinin Igor)

__________________.

_____________________

___________________20__

________________________________

/ /


2003.

:

1.1 ..... 3

1.2 3

1.3 ? ... 4

1.4 VPN .... 6

1.5 VPN . 7

1.6 10

1.7 .. 11

1.8 ... 13

1.9 . 13

1.10 . 16

1.11 VPN ... 18

1.12 VPN . 19

1.13 VPN . 19

1.14 VPN Windows 2000 Server . 21

1.15 VPN Windows 2000 Server ... 24

1.16 ... 25

1.17 ... 26

1.1

, , . .

, , . , . . , .

VPN. .

VPN , , , . VPN IP . , IP , . , VPN .

1.2     

(VPN), , VPN, VPN, , , , VPN Windows 2000 Server VPN.

1.3 ?

VPN , , . . , . ⠠ .

蠠 :
- ;
- ;
- 頠 ;
- .
. , , . ( ), . ࠠ .
VPN . , PPP. PPP. , , .
, . , .
VPN , . . , PPP.
VPN (IP, IPX, AppleTalk . .) PPP . IP ( ) ATM Frame Relay. ,  .
(, VTP)  .
, , . , .
Simple Internet Transition (SIT), IPv6. (IETF) , (IPv4) (IPv6). ,   . IPv6 IPv4 .

1.4 VPN

VPN CENTREX . Centrex 60- PBX (Private Branch Exchange). , PBX, . Centrex , , , . Centrex , CUG (Closed Users Group) , PBX.
Centrex VPN - CUG, . VPN ( ) , Centrex CUG. PBX, VPN, .

1.5 VPN

VPN (Virtual Private Network ) . , , , VPN .

.2 VPN

VPN :

  • , , , VPN (VPN-). !
  • VPN- ( ). ( , ).

, , IP, VPN- .

IP- VPN- :

  • IP- , . , .
  • .
  • (, ).
  • , . . , , VPN-. - , VPN-. , IP-, .

IP- :

1.   VPN- . , . .

2.   , .

3.   , . , .

4.   , , .

. VPN VPN-, , , .

VPN- , , . , .

VPN- ( ) IP-. , VPN, Express VPN Intel, Triple DES.

, VPN- , . , ; .

.3   

, . , VPN- : .

, , VPN-. IP- , :

  • IP- ( - );
  • IP- ;
  • , (, TCP UDP);
  • , (, 1080).

1.6

, VPN, .

   Intrenet VPN, , . , -.

   Client/Server VPN, ( ) . , VPN , , , , . , , . , , , . VLAN, .

   Extranet VPN , , , .

   Remote Access VPN, ( ) , ( ) notebook ( ). , , , VPN, , , VPN. .

 

1.7

, . VPN , Isec. IPSec (Internet Protocol Security - , , IETF - Internet Engineering Task Force) - (IP), . Ipsec Ipsec . , , IP-.
, Ipsec, " " - Security Association (SA). , , Ipsec . : IP- , , , , , 젠 .
PPTP (Point to Point Tunneling Protocol), Microsoft, L2F (Layer 2 Forwarding), Cisco, - . Microsoft Cisco IETF, L2P2 (Layer 2 Tunneling Protocol) IPSec , .
, . , 100 , IP-. , , , . , , 򠠠 .
IT- . , , - . (56-) , - 168-.

1.8

, , VPN . , , . " " ( ), ( ) .. , , VPN . . -, VPN , , . (, Web-) VPN- . -, . , 80% , , , . , .

1.9

, , , . VPN, , , VPN-. , , :

   VPN-.

   , , , .

   , .

, VPN , VPN-. . VPN . , , 128 (Triple DES, 28147-89 ..). , DES, .

( 10 /). () , .

, VPN-. , . 25 . ( ) IP-. 50-100 . 64 /.

25 ( 16 , 8 , 1 ). IP- 24 ( IP-). Frame Relay LMI 10 FR-. 59 (472 ). , 750 10 (75 ) 75×472 = 34,5 /, 64 /. , VPN. SKIP.

59 112 ( 28148-89), 171 (1368 ). 75×1368 = 102,6 /, 60% .

IPSec 6% (67,8 /). , 28147-89 54 . , - -ʻ, , , 36 ( 26 ), (57 51 / ). , , , , .

1.10

VPN (Point-to-Point Tunnelling Protocol PPTP). 3Com Microsoft . PPTP TCP/IP . .
NT- - . , . ( ) Windows NT Server. , . NT, DHCP, WINS Network Neighborhood, .
, Windows, . , ISDN NT. , .
, (Layer 2 Tunneling Protocol L2TP). PPTP L2F (Layer 2 Forwarding ) . , VPN, , 頠 .

L2TP PPTP 젠 :
1. -. PPP, , .
2. . PPP- 頠 .
3. . PPP , . ( , .) , . .

1.11 VPN

VPN , , , . VPN 蠠 .
堠 VPN:
1. , 堠 ;
2. VPN , , - ;
3. , VPN 堠 ;
4. 頠 ;
5. -.

1.12   VPN

. Frame relay , 5-10, 20 . , VPN, , , , , . 95% , 젠 .
, VPN , , firewall, . . , , .
- VPN. , VPN. - Indus River Networks Inc., MCI WorldCom Novell. Forester Research, VPN , -, - .

1.13     VPN

VPN , , , IP. VPN , 蠠 .
, VPN , . , VPN. ,  VPN.
, IpV6, . VPN, , . IpV6- , , .
, , Cisco Systems, Cabletron Systems, 3Com, Bay Networks, HCL Comnet, VPN. , VPN.
VPN - . AT&T Level 3 Communications, MCI Worldcom Sprint IP- - , . VPN , , Unisource (AT&T, Telia, PTT Suisse PTT Netherlands), Concert (BT/MCI) Global One (Deutsche Telekom, France Telekom). VPN-, , , , .
, . , , , . VPN . , .

1.14 VPN Windows 2000 Server

VPN Windows 2000 Server . VPN . Routing and Remote Access (RRAS) , :

. , VPN . Server Status - Add Server. . This computer ( ) OK.

"Configure and Enable Routing and Remote Access" ( ).

"Configure and Enable Routing and Remote Access" ( ), RRAS.

, , , ( ).

:

Internet connection server

Remote access server

Virtual private network (VPN) server

Network router

Manually configured server

Virtual private network (VPN) server ( VPN).

VPN , , TCP/IP.

, . VPN, , , IP .

, , IP , IP , , IP VPN , IP 192.168.0.10 192.168.0.30.

, IP Next.

VPN , , , .

, , Manage(). Local Users and Groups( ).

, Users ; New User ( ). , User cannot change password( ), . VPN, test.

. "Member Of( )" "Add()".

. Users. , , Users.

"Dial-in( )" . "Remote Access Permission(Dial-in or VPN)( (VPN ))" "Allow access( )".

VPN , , IP , .

1.15 VPN Windows 2000 Server

VPN Windows98, WindowsMe,

Windows 2000 Windows 2000 Server , VPN Windows 2000 Server.

.

, , .

. .

.

IP- VPN 157.54.0.1 :

, , , VPN , , .
, .

( ) , , VPN.

VPN .

VPN .

, , ,

(CHAP) .

. : (TCP/IP) OK.

VPN, .

1.16

VPN.  VPN . VPN , , , . VPN , VPN . , , . VPN .

1.17

1. www.bugtraq.ru

2. . VPN. PCWEEK/RE, 2, 26 1999.
3. . VPN . LAN/ . 1998, 4, 10.
4. . . , 3 (25), 1998.

û : The removed access to a private network through the Inter

 

 

 

! , , , .
. , :