Chapter 18 GRE Configuration
Confidential and Proprietary Information of ZTE CORPORATION
267
The encryption/decryption technology is a mature technology
in data communications. The VPN can directly use the
existing technology.
The key management technology is intended to guarantee
secure transfer of a key on a public data network so that the
key will not be stolen.
The existing key management technology is divided into two
types: SKIP and ISAKMP/OAKLEY.SKIP uses the calculation
rules of Diffie-Hellman to transfer keys on networks. In
ISAKMP, both parties have two keys used for public or
private applications
The most common identity authentication technologies are user
name, password and card authentication.
Some other latest technologies, such as MPLS VPN, need the
corresponding services of the ISP.
GRE Overview
General Route Encapsulation (GRE) means that an IP header is
added externally to an IP packet, that is to say, the private data
is processed in a disguise way and added with a "jacket" and
then is sent to other places.
Since IP addresses of a private enterprise network are normally
planned by the enterprise itself, so correct routing cannot be
completed between the enterprise network and the external
Internet. However, on the egress of the enterprise network,
normally there will be a unique IP address of the Internet. The
address can be identified uniquely on the Internet. GRE is used
to encapsulate packets with the destination and source IP
addresses being the internal addresses of the enterprise and add
an IP header. The destination address is the IP address of the
egress of the remote Internet, while the source address is the IP
address of the egress of the local Internet. Thus, the packets
can be transmitted correctly on the Internet. This technology is
the simplest VPN technology.
When a router sends or forwards an IP datagram, if the IP
datagram should be sent out a GRE tunnel interface after routing
process, GRE encapsulation is needed. Upon encapsulation, the
GRE header field is processed according to the option
configuration of the GRE tunnel interface, and finally a route is
found according to the encapsulated destination address and the
datagram is sent to the output network interface to implement
forwarding of the datagram.
If the length of the datagram to be sent is greater than the MTU
(Maximum Transmission Unit) of the interface, fragmentation
operation should be performed before GRE encapsulation and
sending, that is, fragmentation is performed before
encapsulation. If the DF bit of the IP data header is set to "1"
Definition
Simplest VPN
Technology
IP Datagram
MTU
Содержание ZXR10 GER
Страница 4: ...This page is intentionally blank ...
Страница 14: ...This page is intentionally blank ...
Страница 22: ......
Страница 24: ......
Страница 140: ......
Страница 206: ......
Страница 232: ......
Страница 248: ......
Страница 294: ......
Страница 326: ......
Страница 386: ......
Страница 407: ...Tables Confidential and Proprietary Information of ZTE CORPORATION 385 Table 426 Debug Ip Msdp Command 358 ...
Страница 408: ......