{"id":435,"date":"2013-01-29T22:20:00","date_gmt":"2013-01-29T14:20:00","guid":{"rendered":"http:\/\/note.systw.net\/note\/?p=435"},"modified":"2023-11-01T22:21:47","modified_gmt":"2023-11-01T14:21:47","slug":"tunnel-vpn-in-layer2","status":"publish","type":"post","link":"https:\/\/systw.net\/note\/archives\/435","title":{"rendered":"Tunnel VPN in Layer2"},"content":{"rendered":"\n<p id=\"nv1c148\">PPTP(Point to Point Tunneling Protocol,\u9ede\u5c0d\u9ede\u901a\u9053\u901a\u8a0a\u5354\u5b9a)<strong>:<\/strong>\u5b9a\u7fa9\u4e3b\u5f9e\u5f0f\u7684\u67b6\u69cb<br>\u70bappp\u64f4\u5145\u904b\u7528,\u4e14pptp\u5c01\u88dd\u7684\u5c01\u5305\u591a\u5c6cppp\u8cc7\u6599\u5c01\u5305<br>\u56e0ppp\u652f\u63f4\u591a\u91cd\u5354\u5b9a,\u6240\u4ee5pptp\u4e5f\u53ef\u652f\u63f4\u591a\u91cd\u5354\u5b9a<br><br>\u5fae\u8edf\u7522\u54c1\u591a\u652f\u63f4pptp(1998)<br>\u56e0\u5bb9\u6613\u90e8\u7f72,\u5177\u5f48\u6027,\u4f46\u7de8\u78bc\u6280\u8853\u4e26\u975e\u5f88\u597d,\u8a8d\u8b49\u529f\u80fd\u4e5f\u4e0d\u4f73<br>pptp client\u6709win 95\/98\/nt\/2000<br>pptp server\u6709WinNT4\/2000<\/p>\n\n\n\n<p id=\"nv1c148\">\u904b\u4f5c\u65b9\u6cd5\u6709\uff1a<br>a.client pptp enable tunneling<br>\u7528\u64a5\u865f\u65b9\u5f0f\u63a5\u5165\u516c\u7528IP\u7db2,\u5148\u64a5\u5230ISP\u5efa\u7acbPPP\u9023\u7dda,\u5728\u9032\u884c\u4e8c\u6b21\u64a5\u865f\u5efa\u7acb\u5230PPTP\u4f3a\u670d\u5668\u7684\u9023\u63a5\uff0c\u8a72\u9023\u63a5\u7a31\u70baPPTP\u96a7\u9053<br>b.isp pptp enable tunneling<br>\u5ba2\u6236\u7aef\u64a5\u865f\u5230\u9060\u7aef\u5b58\u53d6\u8f49\u63a5\u5668\u5f8c,\u82e5isp\u5c0dpptp:<br>\u3000\u6709\u652f\u63f4\uff1a\u9023\u7dda\u5efa\u7acb\u5f8c\u9060\u7aef\u5b58\u53d6\u8f49\u63a5\u5668\u6703\u8207pptp\u4f3a\u670d\u7aef\u4e4b\u9593\u5efa\u7acbpptp session<br>\u3000\u7121\u652f\u63f4\uff1a\u5ba2\u6236\u7aef\u9700\u4e8b\u5b89\u88dd\u597dpptp,\u9023\u7dda\u5efa\u7acb\u5f8c\u5728\u64a5\u5165pptp\u4f3a\u670d\u7aef,\u6703\u5728\u5ba2\u6236\u7aef\u548c\u4f3a\u670d\u7aef\u4e4b\u9593\u5efa\u7acbpptp session<br>c.lan to lan tunneling<br>\u4e0d\u9700\u8981PPP\u7684\u64a5\u865f\u9023\u63a5,\u76f4\u63a5\u5728\u5169\u7aef\u7684PPTP\u4f3a\u670d\u5668\u5efa\u7acb\u865b\u64ec\u901a\u9053<\/p>\n\n\n\n<p id=\"nv1c162\">\u4e3b\u8981\u7531PNS(PPTP Network Server)\u548cPAC(PPTP Access Concentrator)\u7d44\u6210,\u4f7f\u7528\u8005\u64a5\u865f\u9023\u63a5\u7684\u7d42\u9ede\u662fPAC<br>\u5305\u542b\u5169\u5c64\u5b89\u5168\u7a0b\u5e8f<br>authentication(\u8eab\u4efd\u9a57\u8b49):\u53ef\u9078chap,mschap<br>encryption(\u52a0\u5bc6\u7de8\u78bc):\u52a0\u5bc6\u4f7f\u7528rc4,\u957740bit\u6216128bit\u7684session key(\u6bcf\u6b21\u5efa\u7acb\u65b0session\u6703\u7522\u751f\u4e00\u6b21key)<br>\u6839\u64daPPP(\u9ede\u5c0d\u9ede\u901a\u8a0a\u5354\u5b9a)\u6240\u5236\u8a02<br>\u3000PPTP\u6703\u5c07IP\u3001IPX\u6216NetBEUI\u901a\u8a0a\u5354\u5b9a\u5c01\u88dd\u5728IP\u5c01\u5305\u4e2d\uff0c\u7136\u5f8c\u5728\u5c01\u88dd\u9032ppp\u8a0a\u6846<br>\u3000\u5230\u9060\u7aef\u5b58\u53d6\u8f49\u63a5\u5668\u6642\u6703\u5c07PPP\u8a0a\u6846\u5167payload\u88dd\u9032grev2\u7684header,\u5728\u52a0\u4e0aip header,\u5728\u52a0\u4e0adelivery header<br>\u3000\u6700\u5f8c\u5728\u7528ip\u7db2\u8def\u4f86\u50b3\u9001\u8cc7\u6599,delivery header\u6703\u96a8\u8457\u5c01\u5305\u6240\u7d93\u50b3\u8f38\u5a92\u4ecb\u800c\u6539\u8b8a<br>\u3000\u5230\u9054pptp\u4f3a\u670d\u7aef\u5f8c\u5728\u4f9d\u5faa\u5c07\u62c6\u9664header,\u6700\u5f8c\u7559\u4e0bpayload<br>\u3000\u4f7f\u7528TCP port1723 \u65b9\u5f0f\u4f86\u4ea4\u63db\u52a0\u5bc6\u901a\u9053\u7684\u7dad\u8b77\u8a0a\u606f<br>remote access switch(\u9060\u7aef\u5b58\u53d6\u8f49\u63a5\u5668):\u53ef\u652f\u63f4pptp\u7684\u7522\u54c1<br>ex:remote access server(\u9060\u7aef\u5b58\u53d6\u4f3a\u670d\u5668),remote hub(\u9060\u7aef\u96c6\u7dda\u5668),terminal server(\u7d42\u7aef\u4f3a\u670d\u5668),remote access switch(\u9060\u7aef\u5b58\u53d6\u4ea4\u63db\u5668)<\/p>\n\n\n\n<p id=\"nv1c180\">&#8230;&#8230;.<\/p>\n\n\n\n<p id=\"x1i11\">L2TP(Layer 2 Tunneling Protocol,\u7b2c\u4e8c\u5c64\u901a\u9053\u901a\u8a0a\u5354\u5b9a)<br>\u7531Microsoft\u3001Cisco\u3001Ascend\u3001IBM\u53ca3Com\u5171\u540c\u958b\u767c\u7684\u4e00\u9805\u591a\u91cd\u901a\u8a0a\u5354\u5b9a\u901a\u9053\u6280\u8853<br>\u7d50\u5408L2F\u548cPPTP\u7279\u9ede\u7684\u8cc7\u6599\u9023\u7d50\u5c64\u7684\u52a0\u5bc6\u901a\u8a0a\u5354\u5b9a,\u5177\u6709\u5ee3\u6cdb\u5efa\u7f6e\u7684,\u6210\u719f\u7684IETF\u6a19\u6e96\u8ffd\u8e64\u901a\u8a0a\u5354\u5b9a<br>cisco router\u53ca\u6700\u65b0win 2000\u6709\u652f\u63f4<\/p>\n\n\n\n<p id=\"x1i11\">\u4e3b\u8981\u75312\u90e8\u4efd\u7d44\u6210\uff1a<br>LAC(L2TP Access Concentrator):<br>\u5be6\u9ad4\u4e0a\u7528\u65bc\u767c\u8d77\u547c\u53eb\u3001\u63a5\u6536\u547c\u53eb\u548c\u5efa\u7acb\u96a7\u9053\u6216\u53ef\u8aaa\u662f\u7bc0\u9ede\u7684\u88dd\u7f6e<br>\u4f7f\u7528\u65bcisp,\u4e3b\u8981\u63d0\u4f9b\u7d66\u4f7f\u7528\u8005\u64a5\u63a5\u5b58\u53d6<br>LNS(L2TP Network Server):<br>\u6240\u6709\u96a7\u9053\u7684\u7d42\u9ede,\u9ede\u5c0d\u9ede\u901a\u8a0a\u5354\u5b9a\u7684\u8a8d\u8b49\u88dd\u7f6e<br>\u4f7f\u7528\u65bc\u4f01\u696dlan\u4e2d\uff0c\u63d0\u4f9b\u7d66\u5167\u90e8\u4f7f\u7528\u8005\u4f7f\u7528l2tp\u5c01\u5305<\/p>\n\n\n\n<p id=\"x1i11\">\u53ef\u7528IPsec\u50b3\u8f38\u6a21\u5f0f,\u5177\u6709\u4ee5ppp\u70ba\u57fa\u790e\u4e4b\u901a\u9053\u512a\u9ede,\u53ef\u652f\u63f4tcp\/ip\u4ee5\u5916<br>\u9069\u5408\u7528\u6236\u7aef\u8207\u4f3a\u670d\u7aef\u9023\u7dda,\u56e0\u9023\u7dda\u53c3\u6578\u53ef\u61c9\u4ed8\u52d5\u614b\u8b8a\u5316\u4e4b\u7528\u6236\u7aef,\u4e5f\u53ef\u5f9e\u4f3a\u670d\u5668\u7aef\u767c\u8d77VPN\u9023\u63a5<br>\u9023\u63a5\u4e00\u500b\u7db2\u8def\u4ee5\u9ede\u5c0d\u9ede\u901a\u8a0a\u5354\u5b9aPPP\u70ba\u4e3b<br>L2TP\u53ef\u4ee5\u5efa\u7acb\u591a\u7a2e\u901a\u9053\uff0c\u6bcf\u4e00\u500b\u901a\u9053\u5404\u6709\u4e0d\u540c\u7684QoS<br>\u5c07IP\u3001IPX\u6216NetBEUI\u901a\u8a0a\u5354\u5b9a\u52a0\u5bc6\u4e26\u5c01\u88dd\u5728IP\u5c01\u5305\u4e2d,\u5728\u7528\u5728\u5404\u7a2e\u7db2\u8def\u50b3\u8f38\u8cc7\u6599\uff0c\u5305\u62ecIP\u3001X.25\u3001frame relay\u6216ATM<br>\u4f7f\u7528UDP\u4f86\u50b3\u9001L2TP\u5c01\u88dd\u7684PPP\u6846\u67b6\u6578\uff0c\u4f5c\u70ba\u900f\u904e\u901a\u9053\u50b3\u8f38\u7684\u300c\u8cc7\u6599\u300d<\/p>\n\n\n\n<p id=\"x1i11\">&#8230;&#8230;.<br><br>PPTP\u53caL2TP\u76f8\u540c\u8655<br>\u5747\u70ba\u7b2c\u4e8c\u5c64\u7684\u7a7f\u96a7\u6280\u8853\uff0c\u9069\u5408\u5177\u6709IP\/IPX\/AppleTalk\u7b49\u591a\u7a2e\u5354\u5b9a\u7684\u74b0\u5883\u3002<br>\u90fd\u662f\u5c07\u8cc7\u6599\u5c01\u88dd\u5728ppp(\u9ede\u5c0d\u9ede\u5354\u8b70)\u4e2d\u901a\u904e\u4e92\u806f\u7db2\u8def\u9001\u51fa<br>\u53ea\u80fd\u57f7\u884c\u9ede\u5c0d\u9edeVPN\u7684\u529f\u80fd\uff0c\u7121\u6cd5\u540c\u6642\u57f7\u884cInternet\u7684\u61c9\u7528\uff0c\u4f7f\u7528\u6642\u8f03\u4e0d\u65b9\u4fbf<br>\u53ef\u57f7\u884cpap,chap,mschap\u7b49\u9a57\u8b49\u5354\u5b9a<br>\u5c0d\u5c01\u5305\u7684Encapsulation(\u5c01\u88dd)\u505a\u52a0\u5bc6\u8655\u7406\uff0c\u4e26\u672a\u5c0d\u8cc7\u6599\uff0c\u5b89\u5168\u6027\u8f03\u4f4e<\/p>\n\n\n\n<p>PPTP\u548cL2TP\u4e0d\u540c\uff1a<br>1.PPTP\u8981\u6c42\u4e92\u806f\u7f51\u7d61\u70baIP\u7f51\u7d61,L2TP\u53ea\u8981\u6c42\u96a7\u9053\u5a92\u4ecb\u63d0\u4f9b\u9762\u5411\u6578\u636e\u5305\u7684\u9ede\u5c0d\u9ede\u7684\u9023\u63a5\u3002<br>2.PPTP\u53ea\u80fd\u5728\u5169\u7aef\u9ede\u9593\u5efa\u7acb\u55ae\u4e00\u96a7\u9053,L2TP\u652f\u6301\u5728\u5169\u7aef\u9ede\u9593\u4f7f\u7528\u591a\u96a7\u9053,\u6bcf\u4e00\u500b\u901a\u9053\u5404\u6709\u4e0d\u540c\u7684QoS<br>3.L2TP\u53ef\u4ee5\u63d0\u4f9b\u5305\u982d\u58d3\u7e2e,\u7576\u58d3\u7e2e\u5305\u982d\u6642,overhead(\u7cfb\u7d71\u958b\u92b7)\u5360\u75284\u500b\u5b57\u7bc0,\u800cPPTP\u5354\u8b70\u4e0b\u8981\u5360\u75286\u500b\u5b57\u7bc0\u3002<br>4.L2TP\u53ef\u4ee5\u63d0\u4f9b\u96a7\u9053\u9a57\u8a3c,\u800cPPTP\u5247\u4e0d\u652f\u6301\u96a7\u9053\u9a57\u8a3c,\u4f46\u662f\u7576L2TP\u6216PPTP\u4e0eIPSEC\u5171\u540c\u4f7f\u7528\u6642,\u53ef\u7531IPSEC\u63d0\u4f9b\u96a7\u9053\u9a57\u8a3c,\u4e0d\u9700\u8981\u5728\u7b2c2\u5c64\u5354\u8b70\u4e0a\u9a57\u8a3c\u96a7\u9053<br><br>&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;<\/p>\n\n\n\n<p id=\"nv1c183\">L2F(Layer 2 Forwarding,\u7b2c\u4e8c\u5c64\u8f49\u767c\u5354\u8b70)<br>\u601d\u79d1\u767c\u5c55\u7684TUNNELING\u901a\u8a0a\u5354\u5b9a,\u53ef\u7528\u4f86\u5728\u7db2\u969b\u7db2\u8def\u4e0a\u5efa\u7acbVPN,\u53ca\u5efa\u7acb\u7528\u6236\u8207\u4f01\u696d\u5ba2\u6236\u7db2\u8def\u9593\u7684\u865b\u64ec\u9ede\u5c0d\u9ede\u9023\u63a5<br>\u5141\u8a31\u93c8\u8def\u5c64\u5354\u8b70\u96a7\u9053\u6280\u8853\u3002\u4f7f\u7528\u9019\u6a23\u7684\u96a7\u9053\uff0c\u4f7f\u5f97\u5206\u96e2\u539f\u59cb\u64a5\u865f\u4f3a\u670d\u5668\u4f4d\u7f6e\u5373\u64a5\u865f\u5354\u8b70\u9023\u63a5\u7d42\u6b62\u7684\u4f4d\u7f6e\u8207\u63d0\u4f9b\u7684\u7db2\u8def\u8a2a\u554f\u7684\u4f4d\u7f6e\u6210\u70ba\u53ef\u80fd<br>\u5141\u8a31\u5728L2F\u4e2d\u5c01\u88ddPPP\/SLIP\u5305\u3002ISP NAS\u8207\u5bb6\u5ead\u901a\u8def\u90fd\u9700\u8981\u8acb\u6c42\u4e00\u7a2e\u5e38\u898f\u5c01\u88dd\u5354\u8b70\uff0c\u6240\u4ee5\u53ef\u4ee5\u6210\u529f\u5730\u50b3\u8f38\u6216\u63a5\u6536SLIP\/PPP\u5305<br>\u4f7f\u7528key\u957740bit\u621656bit\u7684des<\/p>\n","protected":false},"excerpt":{"rendered":"<p>PPTP(Point to Point Tunneling  &#8230;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"fifu_image_url":"","fifu_image_alt":"","_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_publicize_message":"","jetpack_publicize_feature_enabled":true,"jetpack_social_post_already_shared":false,"jetpack_social_options":{"image_generator_settings":{"template":"highway","default_image_id":0,"font":"","enabled":false},"version":2}},"categories":[10],"tags":[],"class_list":["post-435","post","type-post","status-publish","format-standard","hentry","category-securitysloution"],"jetpack_publicize_connections":[],"jetpack_featured_media_url":"","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/systw.net\/note\/wp-json\/wp\/v2\/posts\/435","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/systw.net\/note\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/systw.net\/note\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/systw.net\/note\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/systw.net\/note\/wp-json\/wp\/v2\/comments?post=435"}],"version-history":[{"count":0,"href":"https:\/\/systw.net\/note\/wp-json\/wp\/v2\/posts\/435\/revisions"}],"wp:attachment":[{"href":"https:\/\/systw.net\/note\/wp-json\/wp\/v2\/media?parent=435"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/systw.net\/note\/wp-json\/wp\/v2\/categories?post=435"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/systw.net\/note\/wp-json\/wp\/v2\/tags?post=435"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}