簡易檢索 / 詳目顯示

研究生: 葉輝煌
Hui-Huang Yeh
論文名稱: 動態IP網路中實行IPSec VPN
Implementing the IPSec VPN in a dynamic IP network
指導教授: 洪西進
Shi-Jinn Horng
口試委員: 范欽雄
Chin-Shyurng Fahn
曾煜棋
Yu-Chee Tseng
張瑞雄
Ruay-Shiung Chang
蘇民揚
none
學位類別: 碩士
Master
系所名稱: 電資學院 - 資訊工程系
Department of Computer Science and Information Engineering
論文出版年: 2005
畢業學年度: 93
語文別: 中文
論文頁數: 83
中文關鍵詞: VPN、IPSec、DDNS、Firewall
外文關鍵詞: VPN、IPSec、DDNS、Firewall
相關次數: 點閱:602下載:3
分享至:
查詢本校圖書館目錄 查詢臺灣博碩士論文知識加值系統 勘誤回報

在以往的網路環境中,私有網路要完成相互連結的工作時,通常都是使用專線來完成,可是專線的費用非常昂貴,尤其遇到跨國連線時,費用更高。VPN是連接私有網路的技術,有別於傳統的專線,VPN提供更佳的彈性與更便宜的價格,IPSec是實行VPN的技術之一,IPSec主要架設在固定IP,若要架設於動態的IP環境則必須要付出較高的管理成本,目前Internet的環境下固定IP的取得成本較動態IP來的高,若能夠在動態IP下架設VPN將更為便利。
本論文提出使用DDNS來協助IPSec在動態IP中架設VPN,並加入Firewall來增加安全性。DDNS提供IP更新機制讓成員得知其他成員的IP位址來完成VPN的建立,在認證方面採用DNSSEC/TSIG,並搭配Firewall的狀態檢測技術來強化IPSec安全性,降低攻擊者的攻擊與入侵。
論文中針對所提方法的相關效能與資料流之間的安全性做評估與探討。效能評估方面分別在實驗室內區域網路以及Internet的環境作測試,根據測試所得到的結果證明所提的方法能夠適應於現實的網路環境。安全性方面則對所有資料流做探討,確保主機與主機之間的所有資料溝通安全性是無顧慮。在多項數據的評估下,證明本論文確實能使IPSec VPN更具彈性,使得IPSec VPN的應用更為廣泛。


About the network environment, we used to use the leased line for private network interconnection, but the expense of leased line is very expensive, the expense could be higher when the leased line is used for transnational interconnection. VPN(Virtua Private Network) is the technology for private network interconnection, being different from the traditional leased line, VPN offers more flexible and cheaper price. IPSec(IP Protocol Security) is one of the technologies for implementing VPN, it is implemented in a static IP network mainly. If we want to implement IPSec in a dynamic IP network, we have to demand higher management cost. The expense of static IP is higher than dynamic IP in the
Internet. It will be more convenient if VPN can implement in a dynamic IP network.
This thesis proposes using DDNS(Dynamic Domain Name System) to be assistance the IPSec for implementing VPN in a dynamic IP network; we could add Firewall to enhance the security. DDNS offers dynamic addition and deletion of DNS records to notice each member’s IP address for the VPN implementing, and adopts DNSSEC(DNS Security extension)/TSIG(Transaction Signature) for authentication. For reduce the assailants’ attack and invasions, we could strengthen the IPSec’s security level by using Firewall with its stateful-inspection technique.
This thesis focuses on evaluating the performances and discussing the security of data-flow between servers. Performance evaluations investigated into both LAN and Internet separately. Based on the result of investigations, it proves the proposition can adapt to the realistic network environment, it also discuss with the security of data commutations between the servers. According the investigations and evaluations, this thesis proves the applications of IPSec and VPN can be used more flexibility and more
extensive.

中文摘要……………………………………………………………………………………………I 英文摘要 …………………………………………………………………………………………II 誌謝………………………………………………………………………………………………III 目錄 ………………………………………………………………………………………………IV 圖索引 ……………………………………………………………………………………………VI 第一章 緒論 ………………………………………………………………………………………1 1.1 研究機動……………………………………………………………………………………1 1.2 研究目標……………………………………………………………………………………3 1.3 論文架構……………………………………………………………………………………4 第二章 VPN簡介……………………………………………………………………………………5 2.1 何謂VPN ……………………………………………………………………………………5 2.2 VPN架構 ……………………………………………………………………………………5 2.3 VPN協定 ……………………………………………………………………………………7 第三章 IPSec簡介…………………………………………………………………………………9 3.1 何謂IPSec …………………………………………………………………………………9 3.2 IPSec架構 …………………………………………………………………………………9 3.3 SA …………………………………………………………………………………………11 3.4 AH協定 ……………………………………………………………………………………14 3.5 ESP協定……………………………………………………………………………………16 3.6 IKE協定……………………………………………………………………………………18 第四章 DNS簡介 …………………………………………………………………………………42 4.1 何謂DNS……………………………………………………………………………………42 4.2 DNS架構與網域命名………………………………………………………………………42 4.3 DNS網域區域與伺服器類型………………………………………………………………43 4.4 DDNS ………………………………………………………………………………………44 4.5 DNSSEC ……………………………………………………………………………………44 第五章 Firewall簡介……………………………………………………………………………45 5.1 何謂Firewall ……………………………………………………………………………45 5.2 Firewall種類 ……………………………………………………………………………45 5.3 Firewall架構 ……………………………………………………………………………46 第六章 架構、測試與結果………………………………………………………………………48 6.1 系統架構 …………………………………………………………………………………48 6.2 IPSec效能評估……………………………………………………………………………51 6.3 可用率評估 ………………………………………………………………………………62 6.4 Internet環境測試 ………………………………………………………………………64 第七章 結論與未來展望…………………………………………………………………………70 7.1 結論 ………………………………………………………………………………………70 7.2 未來展望 …………………………………………………………………………………70 參考文獻 …………………………………………………………………………………………71 附錄 相關程式……………………………………………………………………………………73 作者簡介 …………………………………………………………………………………………83

【1】Charlie Scott, Paul Wolfe, Mike Erwin,“Virtual Private Network, Second
Edition”, O'Reilly, January 1999.
【2】翁木龍, “Linux環境下以AES及SHA-256強化VPN的設計與實現”, 高雄第一科技大學
碩士論文, July 2002.
【3】Point-to-Point Tunneling Protocol (PPTP), RFC 2637, July 1999.
【4】Generic Routing Encapsulation (GRE), RFC 1701, October 1994.
【5】Generic Routing Encapsulation over IPv4 networks, RFC 1702, October 1994.
【6】Layer Two Tunneling Protocol (L2TP), RFC 2661, August 1999.
【7】Security Architecture for the Internet Protocol, RFC 2401, November 1998.
【8】The TSL Protocol Version 1.0, RFC 2246, January 1999.
【9】Naganand Doraswamy, Dan Harkins, “IPSec: the new security standard for
the Internet, intranets, and virtual private networks, Second Edition” ,
Prentice-Hall, March 2003.
【10】Carlton R. Davis, “IPSec-VPN安全架構與實作”, 麥格羅.希爾國際出版社,
June 2002.
【11】Internet Protocol, Version 6 (IPv6) Specification, RFC 2460, December
1998.
【12】The Internet Key Exchange (IKE), RFC 2409, November 1998.
【13】Internet Security Association and Key Management Protocol (ISAKMP), RFC
2408, November 1998
【14】Albitz & Liu, “DNS and BIND, 4th Edition”, O’Reilly, April 2001.
【15】Dynamic Updates in the Domain Name System, RFC 2136, April 1997.
【16】Secret Key Transaction Authentication for DNS (TSIG), RFC 2845, May 2000.
【17】Robert Zalenski, “Firewall technologies”, IEEE POTENTIALS, 2002.
【18】The FreeBSD Project, http://www.freebsd.org
【19】Racoon project, http://www.kame.net/racoon/
【20】Sourceforge.net, http://ipsec-tools.sourceforge.net/
【21】Nagios home, http://www.nagios.org/

QR CODE