论文部分内容阅读
建立 VPN根据 TCP/IP 的协议模型,VPN 可以分别在链路层、网络层、传输层、应用层上实现。采用路由过滤技术建立 VPN通常情况下,各种公用网将为所有连接其上的子网完成路由的传输和处理,因此,一种最简便的方法是通过在网络层上实施路由控制来实现 VPN。具体地说,我们可以把通过公用网络连接起来的,属于某企业或机构的各子网抽象为一个网络集合,该集合中的所有路由器不对非本集合的子网传播路由信息;同时,任何非本集合的子网路由信息也不能到达该网络集合,这种技术被称为路由过滤(ROUT FILTERING)。路
Establishing a VPN According to the TCP / IP protocol model, VPNs can be implemented at the link layer, network layer, transport layer, and application layer respectively. Using Route Filtering to Establish VPNs Generally, various public networks will perform the routing and processing of all the subnets connected to them. Therefore, one of the easiest ways is to implement VPN by implementing route control at the network layer . Specifically, we can abstract subnets belonging to an enterprise or organization that are connected through a public network as a network set, and all the routers in the set do not propagate routing information to the subnets that are not the set. At the same time, any non- The set of subnet routing information can not reach the network set, this technology is called routing filtering (ROUT FILTERING). road