当前位置:网站首页>Network equipment hard core technology insider firewall and security gateway (11) secrets of zero contact office
Network equipment hard core technology insider firewall and security gateway (11) secrets of zero contact office
2022-07-28 00:40:00 【User 8289326】
Everything must be from that evil bat / Pangolin / Civet speaking ……
Talking on wheels , Cross out .
More than a decade ago , The concept of telecommuting has sprung up , And until recently , The public health crisis sweeping half the world has really made telecommuting popular .
Huashan sect expects that its internal disciples can also connect to the internal network when practicing at home , But the internal network and the disciples' home network are separated by the Internet , Two problems need to be solved to realize remote office :
- How to use the intranet address of the company , Cross the Internet and corporate networks ?
- How to ensure that the traffic in the middle is safe , Not monitored ?
When Yue buqun asked linghuchong these two questions , Lin Pingzhi on one side immediately interrupted :“ The master , I'll take care of it !”
Yue buqun didn't trust Lin Pingzhi , But Lin Pingzhi often praises the beauty of Shiniang , Shiniang spoke :“ This time, , Let Xiao Linzi have a try !”
Lin Pingzhi is trusted , Start to specify the plan ——
Because Huashan school has opened many branches all over the world , The export firewall of Huashan sect headquarters has long been equipped IPSec function , Communicate with the branch rudder through encrypted tunnel .
Lin Pingzhi thought , We regard each disciple's home as a branch , adopt IPSec The way to connect with the headquarters , No, that's fine ?
Laudeno, who made friends with Lin Pingzhi, was the first to laugh at Lin Pingzhi :
“ You need to know , Routers in disciples' homes are generally TP-Link Hundred yuan machine , How to support IPSec?”
Lin Pingzhi rolled his eyes , Avenue :
“ We Huashan sect can support IPSec Lend your equipment to disciples for remote use ……”
Laudeno stopped interrupting , Waiting to see Lin Pingzhi's joke .
Sure enough , Lin Pingzhi's plan can work normally in some disciples' homes , But other disciples are completely unable to establish IPSec Connect ……
This is because , Operators provide effective global unicast for enterprise users IP Address (Global Unicast Address), But for home broadband users , There is no obligation to provide a global unicast address . In practice , The operator will approve CGN (Carriger Grade NAT) The way , Provide users with 100.64.0.0-100.127.255.255 The network segment , after NAT Enter the public network after conversion .
good , Come here , We know why ——
IPSec Not based on UDP Of , It's not based on TCP Of , It needs to IP End to end connectivity , whatever NAT The existence of , Can lead to IPSec Unavailable , Or need to be in NAT Very special configuration on the device . obviously ,CGN The device cannot support IPSec through —— therefore ,IPSec The scheme is not feasible for telecommuting .
Let's sort out the above logic , We will find that ,IPSec The essential reason why it cannot be used for telecommuting is , Individual users cannot guarantee global unicast on the public network IP Address . that , What kind of communication mode can meet the following requirements :
- One end does not need to have global unicast IP Address ;
- Communication is secure , A certification / authentication / encryption ;
The answer is coming out —— Use SSL/HTTPS.
This is it. SSL VPN.
front , We have already mentioned ,LB Equipment has SSL Connection termination capability , in other words , It can achieve SSL/HTTPS Encryption and decryption of / authentication / authentication , that , Only need to LB Make some modifications to the equipment , Can create support SSL/HTTPS Of VPN equipment !
Late at the time , Fast then , Linghuchong has taken the transformed SSL VPN The equipment has been tested , The test networking is as follows :
Pictured , The address of the data center server is 10.100.100.10,SSL VPN After the user accesses the company network , The address assigned to is 10.100.200.100.
Users access the intranet VM The flow of :10.100.200.100:31233->10.100.100.10:443
It is encapsulated from users to VPN The gateway VPN Through the tunnel Internet.
From users to VPN Gateway tunnels pass through 2 Time NAT, The source of the tunnel IP And the source port are converted twice (192.168.1.101:13763 Convert to 100.64.123.213:12580; 100.64.123.213:12580 Convert to 123.118.108.217:51167), But because of NAT The mechanism of ensures based on HTTPS The tunnel can work normally .
such , No matter where the user accesses ,SSL VPN Can ensure remote security access !
but , Linghuchong didn't expect , More challenges lie ahead ……
边栏推荐
- Selection of FFT sampling frequency and sampling points
- MATLAB 文件夹前面的+和@是干啥的 命名空间与函数的重载
- [21 day learning challenge] classmate K invites you to participate in the in-depth learning seminar
- Strong collaboration and common development! Intel and Taiyi IOT held a seminar on AI computing box aggregation services
- 这种动态规划你见过吗——状态机动态规划之股票问题(中)
- The R language uses the hexsticker package to convert the visualized results of ggplot2 package into hexagonal diagrams (hexagonal stickers, hexagonal stickers, ggplot2 plot to hex stickers)
- A few lines of code can easily realize the real-time reasoning of paddleocr. Come and get!
- 592. 分数加减运算 : 表达式计算入门题
- [meetup preview] openmldb + ONEFLOW: link feature engineering to model training to accelerate machine learning model development
- The latest ijcai2022 tutorial of "figure neural network: foundation, frontier and application"
猜你喜欢

英特尔发布开源AI参考套件

Leetcode 415. string addition and 43. string multiplication

Matlab | matlab terrain generation: rectangular iteration method, inverse Fourier transform method, fractal Berlin noise method

What has the metauniverse of more than 30 years brought to us?

Introduction to thesis writing | how to write an academic research paper

MATLAB | 那些你不得不知道的MATLAB小技巧(四)

The second uncle cured my spiritual internal friction and made me angry out of station B

冲量在线出席2022数据要素安全流通论坛—政务领域专场,助力行业政务大数据建设创新发展
![[BRE]软件构建发布自动化](/img/c6/daead474a64a9a3c86dd140c097be0.jpg)
[BRE]软件构建发布自动化

The server is poisoned - the dish is the original sin
随机推荐
2022年中国网络视频市场年度综合分析
Is it amazing to extract text from pictures? Try three steps to realize OCR!
Overview of construction site selection of Yongzhou analytical laboratory
英特尔发布开源AI参考套件
Matlab | those matlab tips you have to know (2)
【Meetup预告】OpenMLDB+OneFlow:链接特征工程到模型训练,加速机器学习模型开发
MATLAB | 那些你不得不知道的MATLAB小技巧(三)
Microsoft Amazon layoffs, the economic crisis is getting closer...
How does matlab set the K-line diagram to classic red and green color matching?
Leetcode 452. minimum number of arrows to burst balloons (medium)
LeetCode 415. 字符串相加 和 43. 字符串相乘
The second uncle cured my spiritual internal friction and made me angry out of station B
leetcode 452. Minimum Number of Arrows to Burst Balloons 用最少数量的箭引爆气球(中等)
Smart convenience store takes you to unlock the future technology shopping experience
C event related exercise code.
有趣的哈夫曼树
Intel joins hands with hanshuo and Microsoft to release the "Ai + retail" trick!
Annual comprehensive analysis of China's online video market in 2022
Description and analysis of main parameters of R language r native plot function and lines function (type, PCH, CEX, lty, LWD, col, xlab, ylab)
网络设备硬核技术内幕 防火墙与安全网关篇 (小结)