当前位置:网站首页>Network equipment hard core technology insider firewall and security gateway (12) the mystery of zero contact office
Network equipment hard core technology insider firewall and security gateway (12) the mystery of zero contact office
2022-07-28 00:40:00 【User 8289326】
Huashan sect deployed SSL VPN, So that everyone can work remotely , It not only solves the problem of self use , It is also promoted to the whole society , During the critical period, it has won wide praise from the society .
however , Everyone generally reflects a problem :
Even on SSL VPN in the future , Why is the Internet slower ?
original , Here's the problem ——
so , Users are connecting SSL VPN in the future , Because all traffic is sent to the company's intranet , Including going to P The traffic of the station also needs to enter the company's intranet , Then bypass the company's Internet Export , The delay is seriously increased , Affects fluency .
Why is all traffic sent to the company's intranet ?
original ,SSL VPN The implementation of the , Rely on a little secret —— Routing table .
The routing table exists in every terminal that needs to connect to the network .
Take a chestnut :
some Linux The virtual machine has only one network card ,IP The address is 192.168.1.16, The mask is 255.255.255.0, The gateway is the default 192.168.1.1.
We knock down at the terminal route After the order , You can see , It has 3 Route table , among default Pointing to 192.168.1.1, in other words , Except for packets pointing to the same network segment , Any other next hop needs to point to this gateway .
And connected SSL VPN in the future , Things have changed ——
People often say ,SSL VPN It's a “ Tunnel ”. seeing the name of a thing one thinks of its function , Tunnels need to have entrances and exits .SSL VPN The entrance and exit of is here ——
To install H3C iNode SSL VPN Client's Windows Take computer as an example :
Let's open it Windows In the control panel " Network settings ", We found that , Installed on iNode after , One more network device ——
actually , Running iNode VPN And connect successfully , By default, all traffic will lead here . original ,SSL VPN The working process of seems simple , There are seven steps hidden inside ——
1. Administrator in SSL VPN Create on the gateway SSL VPN AC Interface , Configure and send to SSL VPN The routing table entry of the client ;
2. The user logs in at the client SSL VPN;
3. SSL VPN After the gateway passes the authentication and authorization , Assign the virtual network card of the client IP Address , And send the routing table entry to the client ;
4. The client is set for the virtual network card IP Address , And add routing table entries , The outgoing interface of the route is the virtual network card .
5. When users access the intranet server on the client , The access request message matches the added routing table entry , The message will be sent SSL encapsulation , And send it to SSL VPN The gateway SSL VPN AC Interface .
6. SSL VPN Gateway to SSL Unpack the message , And will IP The message is forwarded to the intranet server .
7. The intranet server sends the reply message to SSL VPN gateway , SSL VPN The gateway performs SSL After encapsulation , adopt SSL VPN AC Interface sends it to the client .
We found that , In the 4 Step , It determines that all users' traffic will enter iNode VPN The virtual network adapter , That is, the entrance of the tunnel . such , Even the traffic accessing the Internet , It will also bypass the company's intranet .
that , We just need to change in this place , We can realize that God belongs to God , Caesar's to Caesar ——
stay SSL VPN When the gateway issues a route , Only send routes to the enterprise intranet , Let the traffic to the intranet go VPN Tunnel , That's all right. .
We see , The traffic is separated when entering the Internet , therefore , such SSL VPN It's also called split tunnel ( Separation tunnel ) The way .
Use Split tunnel Is that , It makes the traffic to the Internet do not need to bypass the intranet , Greatly reduce the delay , It's also reduced SSL VPN The burden of the gateway . Of course , The disadvantage is that there may be some potential safety hazards .
therefore , For customers in special industries such as finance , Need special SSL VPN Deployment way ——
Pictured , Customers in the financial industry need heterogeneous firewall networking , Between the two firewalls SSL VPN gateway . such , Outer firewall check SSL VPN Outer flow , And the inner firewall is checked again from SSL VPN The legitimacy of gateway to virtual machine .
On the basis of SSL VPN Remote office program blessing of , We believe that , The Chinese people will surely overcome all difficulties !
边栏推荐
- require、loadfile、dofile、load、loadstring
- 永州清洁级动物实验室建设选址注意事项
- The latest notice of the Chinese Academy of Sciences: abandon the impact factor! The journal zoning table will be published for the "Journal surpassing index"
- 冲量在线出席2022数据要素安全流通论坛—政务领域专场,助力行业政务大数据建设创新发展
- Remote solution of Internet of things system in Mechanical Engineering
- LeetCode 415. 字符串相加 和 43. 字符串相乘
- [meetup preview] openmldb + ONEFLOW: link feature engineering to model training to accelerate machine learning model development
- Rational and perceptual activities and required skills in programmers' work
- leetcode 452. Minimum Number of Arrows to Burst Balloons 用最少数量的箭引爆气球(中等)
- BuildForge 资料
猜你喜欢

【Meetup预告】OpenMLDB+OneFlow:链接特征工程到模型训练,加速机器学习模型开发

Ali Er Mian: why do we need to separate databases and tables?

mysql数据库的基本操作(二)-——基于数据表

二舅治好我的精神内耗,也让我火出了B站

Rational and perceptual activities and required skills in programmers' work

The latest notice of the Chinese Academy of Sciences: abandon the impact factor! The journal zoning table will be published for the "Journal surpassing index"

Matlab | those matlab tips you have to know (I)

【Meetup预告】OpenMLDB+OneFlow:链接特征工程到模型训练,加速机器学习模型开发

Prepare for the interview and stick to the third sentence of the question - Branch sentences!

MATLAB | MATLAB地形生成:矩形迭代法 · 傅里叶逆变换法 · 分形柏林噪声法
随机推荐
Possible reasons why there is no voltage in the corresponding channel, but the ADC value is changing greatly and is not equal to 0
半导体测试设备市场现状:国产化率仍不足10%!
map集合
MATLAB | 那些你不得不知道的MATLAB小技巧(四)
冲量在线出席2022数据要素安全流通论坛—政务领域专场,助力行业政务大数据建设创新发展
Intel AI practice day issue 56 | explore new trends in industry development
threejs个人笔记
二舅治好我的精神内耗,也让我火出了B站
[21 day learning challenge] classmate K invites you to participate in the in-depth learning seminar
mysql数据库的基本操作(三)-——基于字段
Numpy has no unsqueeze function
Precautions for site selection of Yongzhou clean animal laboratory
See how well-known enterprises use Web3 to reshape their industries
Promoting cloud network integration and building a digital economy: Intel unveiled the 5th Digital China Construction Summit - cloud ecosystem Conference
Matlab | those matlab tips you have to know (4)
英特尔发布开源AI参考套件
View the construction details of Yongzhou dioxin Laboratory
基于Unittest的ddt+yaml实现数据驱动机制
永州植物细胞实验室建设布局方案
"Digital economy, science and technology for the good" talk about dry goods