![Black Box LS1016A Скачать руководство пользователя страница 389](http://html.mh-extra.com/html/black-box/ls1016a/ls1016a_user-manual_2763435389.webp)
Appendix G - IPSEC
User Guide
389
Applications of IPsec
Because IPsec operates at the network layer, it is remarkably flexible and can be used to
secure nearly any type of Internet traffic. Two applications, however, are extremely wide-
spread:
•
A Virtual Private Network, or VPN, allows multiple sites to communicate with the Con-
sole Server securely over an insecure Internet by encrypting all communication between
the sites and the Console Server.
•
“Road Warriors” connect to the Console Server from home, or perhaps from a hotel
somewhere.
A somewhat more detailed description of each of these applications is below. Our Quick Start
section will show you how to build each of them.
Using secure tunnels to create a VPN
A VPN, or Virtual Private Network lets the Console Server and a whole network communicate
securely when the only connection between them is over a third network which is not trust-
able. The method is to put a security gateway machine in the network and create a security
tunnel between the Console Server and this gateway. The gateway machine and the Console
Server encrypt packets entering the untrusted net and decrypt packets leaving it, creating a
secure tunnel through it.
Road Warriors
The prototypical “Road Warrior” is a traveler connecting to the Console Server from a laptop
machine. For purposes of this document:
•
Anyone with a dynamic IP address is a “Road Warrior.”
•
Any machine doing IPsec processing is a “gateway.” Think of the single-user Road Warrior
machine as a gateway with a degenerate subnet (one machine: itself) behind it.
These require a somewhat different setup than VPN gateways with static addresses and with
client systems behind them, but are basically not problematic. There are some difficulties
which appear for some Road Warrior connections:
•
Road Warriors who get their addresses via DHCP may have a problem. FreeS/WAN can
quite happily build and use a tunnel to such an address, but when the DHCP lease
expires, FreeS/WAN does not know that. The tunnel fails, and the only recovery method
is to tear it down and rebuild it.
Содержание LS1016A
Страница 12: ...Table of Contents 12 BLACK BOX Advanced Console Server This page has been left intentionally blank ...
Страница 30: ...Introduction and Overview 30 BLACK BOX Advanced Console Server This page has been left intentionally blank ...
Страница 282: ...Time Zone 282 BLACK BOX Advanced Console Server This page has been left intentionally blank ...
Страница 406: ...Appendix H Web User Management 406 BLACK BOX Advanced Console Server Figure 43 Access Limit List default page ...
Страница 414: ...Appendix H Web User Management 414 BLACK BOX Advanced Console Server This page has been left intentionally blank ...
Страница 439: ...List of Figures User Guide 439 47 Terminal Server diagram 422 48 Ports configured for Dial in Access 424 ...
Страница 440: ...List of Figures 440 BLACK BOX Advanced Console Server This page has been left intentionally blank ...
Страница 449: ...This page has been left intentionally blank ...