论文部分内容阅读
IPSec和GRE均为构建虚拟专用网所采用的技术,其自身都有其局限性,IPSec不支持广播、组播和非IP数据流,而GRE不支持数据加密.分析了IPSec和GRE各自的优势,结合IPSec的安全性和GRE对广播、组播和非IP数据流支持的特点,提出了GRE over IPSec VPN结合NAT的构建方案,实现了两个局域网之间单播或组播数据的保密通讯,通过运行EIGRP协议交互内网路由信息,进而使用NAT技术实现局域网内部用户脱离VPN访问Internet.依据提出的构建方案,绘制了组网拓扑图,并基于GNS3进行了仿真实验,验证了方案的安全性和可实施性.该方案既满足了不同局域网之间安全通信的需要,也满足了局域网内部用户访问Internet的需求.
Both IPSec and GRE are technologies used to build a virtual private network, which has its own limitations. IPSec does not support broadcast, multicast, and non-IP data streams, and GRE does not support data encryption.Analysis of the respective advantages of IPSec and GRE , Combined with the security of IPSec and GRE support for broadcast, multicast and non-IP data streams, a construction scheme of GRE over IPSec VPN combined with NAT is proposed to realize the secure communication of unicast or multicast data between two local networks , Which interacts with the intranet routing information by running the EIGRP protocol, and then uses NAT technology to enable the intra-LAN users to access the Internet without the VPN.According to the proposed construction scheme, the topology of the network is drawn and simulated based on GNS3 to verify the security of the scheme The scheme not only meets the need of secure communication between different LANs, but also meets the needs of users accessing the Internet in the LAN.