Editing a Source NAT Rule or Rule Set . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 534
Destination NAT Policy . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 535
Adding a Destination NAT Rulebase . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 536
Adding a Rule Set to a Destination NAT Rulebase . . . . . . . . . . . . . . . . . . . . 536
Adding a Rule to a Destination NAT Rule Set . . . . . . . . . . . . . . . . . . . . . . . . . 537
Editing a Destination NAT Rule or Rule Set . . . . . . . . . . . . . . . . . . . . . . . . . . 538
Static NAT Policy . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 539
Adding a Static NAT Rulebase . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 539
Adding a Rule Set to a Static NAT Rulebase . . . . . . . . . . . . . . . . . . . . . . . . . 539
Adding a Rule to a Static NAT Rule Set . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 540
Editing a Static NAT Rule/Rule Set . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 541
Chapter 12
Configuring VPNs . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 543
About VPNs . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 544
Creating System-Level VPNs with VPN Manager . . . . . . . . . . . . . . . . . . . . . 544
Creating Device-Level VPNs in Device Manager . . . . . . . . . . . . . . . . . . . . . . 545
Supported VPN Configurations . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 545
Planning for Your VPN . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 545
Determining Your VPN Members and Topology . . . . . . . . . . . . . . . . . . . . . . 546
Using Network Address Translation (NAT) . . . . . . . . . . . . . . . . . . . . . . 546
Site-to-Site . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 546
Hub and Spoke . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 547
Full Mesh . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 547
Creating Redundancy . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 547
Protecting Data in the VPN . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 548
Using IPSec . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 548
Using L2TP . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 550
Choosing a VPN Tunnel Type . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 550
About Policy-Based VPNs . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 550
About Route-Based VPNs . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 551
VPN Checklist . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 551
Define Members and Topology . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 551
Define VPN Type: Policy-Based, Route-Based, or Mixed-Mode . . . . . . 552
Define Security Protocol (Encryption and Authentication) . . . . . . . . . . 552
Define Method: VPN Manager or Device-Level? . . . . . . . . . . . . . . . . . . 552
Preparing VPN Components . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 554
Preparing Basic VPN Components . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 554
Preparing Required Policy-Based VPN Components . . . . . . . . . . . . . . . . . . 554
Configuring Address Objects . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 555
Configuring Protected Resources . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 555
Configuring Shared NAT Objects . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 555
Configuring Remote Access Service (RAS) Users . . . . . . . . . . . . . . . . . 556
Configuring Required Routing-Based VPN Components . . . . . . . . . . . . . . . 557
Configuring Tunnel Interfaces and Tunnel Zones . . . . . . . . . . . . . . . . . . 558
Configuring Static and Dynamic Routes . . . . . . . . . . . . . . . . . . . . . . . . . 558
Configuring Optional VPN Components . . . . . . . . . . . . . . . . . . . . . . . . . . . . 559
Creating Authentication Servers . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 559
Creating Certificate Objects . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 559
Creating PKI Defaults . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 560
Copyright © 2010, Juniper Networks, Inc.
xxvi
Network and Security Manager Administration Guide
Содержание NETWORK AND SECURITY MANAGER 2010.3
Страница 6: ...Copyright 2010 Juniper Networks Inc vi...
Страница 36: ...Copyright 2010 Juniper Networks Inc xxxvi Network and Security Manager Administration Guide...
Страница 52: ...Copyright 2010 Juniper Networks Inc 2 Network and Security Manager Administration Guide...
Страница 90: ...Copyright 2010 Juniper Networks Inc 40 Network and Security Manager Administration Guide...
Страница 144: ...Copyright 2010 Juniper Networks Inc 94 Network and Security Manager Administration Guide...
Страница 146: ...Copyright 2010 Juniper Networks Inc 96 Network and Security Manager Administration Guide...
Страница 234: ...Copyright 2010 Juniper Networks Inc 184 Network and Security Manager Administration Guide...
Страница 310: ...Copyright 2010 Juniper Networks Inc 260 Network and Security Manager Administration Guide...
Страница 364: ...Copyright 2010 Juniper Networks Inc 314 Network and Security Manager Administration Guide...
Страница 366: ...Copyright 2010 Juniper Networks Inc 316 Network and Security Manager Administration Guide...
Страница 478: ...Copyright 2010 Juniper Networks Inc 428 Network and Security Manager Administration Guide...
Страница 576: ...Copyright 2010 Juniper Networks Inc 526 Network and Security Manager Administration Guide...
Страница 580: ...Copyright 2010 Juniper Networks Inc 530 Network and Security Manager Administration Guide...
Страница 592: ...Copyright 2010 Juniper Networks Inc 542 Network and Security Manager Administration Guide...
Страница 684: ...Copyright 2010 Juniper Networks Inc 634 Network and Security Manager Administration Guide...
Страница 690: ...Copyright 2010 Juniper Networks Inc 640 Network and Security Manager Administration Guide...
Страница 696: ...Copyright 2010 Juniper Networks Inc 646 Network and Security Manager Administration Guide...
Страница 698: ...Copyright 2010 Juniper Networks Inc 648 Network and Security Manager Administration Guide...
Страница 748: ...Copyright 2010 Juniper Networks Inc 698 Network and Security Manager Administration Guide...
Страница 778: ...Copyright 2010 Juniper Networks Inc 728 Network and Security Manager Administration Guide...
Страница 870: ...Copyright 2010 Juniper Networks Inc 820 Network and Security Manager Administration Guide...
Страница 872: ...Copyright 2010 Juniper Networks Inc 822 Network and Security Manager Administration Guide...
Страница 898: ...Copyright 2010 Juniper Networks Inc 848 Network and Security Manager Administration Guide...
Страница 908: ...Copyright 2010 Juniper Networks Inc 858 Network and Security Manager Administration Guide...
Страница 910: ...Copyright 2010 Juniper Networks Inc 860 Network and Security Manager Administration Guide...
Страница 995: ...PART 6 Index Index on page 947 945 Copyright 2010 Juniper Networks Inc...
Страница 996: ...Copyright 2010 Juniper Networks Inc 946 Network and Security Manager Administration Guide...