¡¾·±ÌåÖÐÎÄ¡¿
¡¾ÉèΪÊ×Ò³¡¿
¡¾¼ÓÈëÊղء¿
µ±Ç°Î»ÖãºASP¼¼ÊõÊ×Ò³ >> °²È«¼ÓÃÜ >> AspµÄ°²È«¹ÜÀí£¨12£©

AspµÄ°²È«¹ÜÀí£¨12£©

2004-10-01 08:26:10  ×÷Õߣº  À´Ô´£º»¥ÁªÍø  ä¯ÀÀ´ÎÊý£º13  ÎÄ×Ö´óС£º¡¾´ó¡¿¡¾ÖС¿¡¾Ð¡¡¿
¼ò½é£º¸½Â¼ C£ºÍøÂ簲ȫµÄ×î¼Ñ·½°¸ Steve Riley£¬Microsoft Communications Industry Solutions Group Consulting Practice 2000 Äê 8 Ô 7 ÈÕ ÕâÆª¶ÌÎÄÂÛÊöÁËÍøÂçÉè¼ÆºÍ°²È«µÄ×î¼Ñ·½°¸¡£¾¡¹ÜÍøÂçµÄÉè¼ÆºÍ°²È«±£»¤...
¹Ø¼ü×Ö£º°²È«¹ÜÀí Asp

¸½Â¼ C£ºÍøÂ簲ȫµÄ×î¼Ñ·½°¸

Steve Riley£¬Microsoft Communications Industry Solutions Group Consulting Practice

2000 Äê 8 ÔÂ 7 ÈÕ

ÕâÆª¶ÌÎÄÂÛÊöÁËÍøÂçÉè¼ÆºÍ°²È«µÄ×î¼Ñ·½°¸¡£¾¡¹ÜÍøÂçµÄÉè¼ÆºÍ°²È«±£»¤·½·¨ºÜ¶à£¬µ«Ö»ÓÐijЩ·½·¨ºÍ²½ÖèÉîÊÜÐí¶àÒµÄÚÈËÊ¿µÄϲ»¶¡£

ɸѡ·ÓÉÆ÷ ¡ª µÚÒ»µÀ·ÀÏß

Ó¦µ±Ê¹ÓÃɸѡ·ÓÉÆ÷À´±£»¤ÈκÎÃæÏò Internet µÄ·À»ðǽ¡£ÕâÖÖ·ÓÉÆ÷Ö»ÓÐÁ½¸ö½Ó¿Ú£ºÒ»¸öÓë Internet ÏàÁ¬¶øÁíÒ»¸öÓëÍⲿ·À»ðǽ£¨»ò±ØÒªÊ±Óë¸ºÔØÆ½ºâµÄ·À»ðǽȺ¼¯£©ÏàÁ¬¡£ËùÓй¥»÷ÖУ¬½«½ü 90% Éæ¼°µ½ IP µØÖ·Ê§ÇÔ£¬»ò¸Ä±äÔ´µØÖ·ÒÔʹÊý¾Ý°ü¿´ÆðÀ´ÈçͬÀ´×ÔÄÚ²¿ÍøÂç¡£´«ÈëÊý¾Ý°üûÓÐʲôÀíÓÉ¿ÉÒÔÀ´×ÔÄÚ²¿ÍøÂç¡£ÁíÍ⣬ÓÉÓÚÒ»¸öÍøÂçµÄ°²È«ÐÔͨ³£È¡¾öÓÚËùÁ¬½ÓÍøÂçµÄ°²È«ÐÔ£¬Òò´Ë×îºÃÄܱÜÃâÄúµÄÍøÂç±»ÓÃ×÷¼ÙÊý¾Ý°üµÄÀ´Ô´¡£É¸Ñ¡Â·ÓÉÆ÷ÊÇʵÏÖÕâЩĿµÄµÄÀíÏë·½·¨¡£

Ó¦µ±½«É¸Ñ¡Â·ÓÉÆ÷ÅäÖÃΪ¡°allow all except that which is specifically denied¡±£¨ÔÊÐíͨ¹ýÌØ±ð¾Ü¾øÒÔÍâµÄËùÓÐͨÐÅ£©×´Ì¬¡£ÕâÑù£¬ACL ¾ÍÖ´ÐÐÏÂÁвÙ×÷£º

¶¨ÒåÒ»¸ö½øÈëɸѡÆ÷£¬Ëü¾Ü¾øÈκÎÔ´µØÖ·ÎªÄÚ²¿ÍøÂçµØÖ·µÄ´«ÈëͨÐÅ¡£

¶¨ÒåÒ»¸öÍâ³öɸѡÆ÷£¬Ëü¾Ü¾øÔ´µØÖ··ÇÄÚ²¿ÍøÂçµÄ´«³öͨÐÅ¡£

¾Ü¾ø RFC 1918 ÖÐËùÈ·¶¨µÄÈκÎרÓõØÖ··¶Î§ÄÚÔ´µØÖ·»òÄ¿±êµØÖ·µÄËùÓд«Èë»ò´«³öͨÐÅ¡£

ÔÊÐíËùÓÐÆäËüµÄ´«ÈëºÍ´«³öͨÐÅ¡£

Õâ¿É×èÖ¹´ó¶àÊý¹¥»÷£¬ÒòΪÇÔÈ¡ÄÚ²¿µØÖ·¼¸ºõÊÇËùÓй¥»÷µÄ»ù±¾Ìõ¼þ¡£½«É¸Ñ¡Â·ÓÉÆ÷ºóÃæµÄ·À»ðǽÅäÖÃΪ¡°deny all except that which is specifically allowed¡±£¨¾Ü¾ø³ýÌØ±ðÔÊÐíÖ®ÍâµÄËùÓÐͨÐÅ£©×´Ì¬¡£

£¨Õⲿ·ÖÐÅÏ¢µÄÒÀ¾ÝΪ RFC 2267£¬¡°Network ingress filtering: Defeating denial of service attacks which employ IP source address spoofing¡±£¬1998 Äê 1 Ô¡££©

¶Ô¿ÉÓÃÐÔÒªÇó½Ï¸ßµÄ»·¾³£¬¿ÉʹÓÃÁ½¸öɸѡ·ÓÉÆ÷£¬²¢½«¶þÕßÁ¬½Óµ½Ò»¶Ô·À»ðǽ¸ºÔØÆ½ºâÉ豸ÉÏ¡£

·À»ðǽ ¡ª ·Ö²ã±£»¤

µäÐ͵ķǾüÊÂÇø (DMZ) ÓÐÁ½¸ö·À»ðǽ¡£Íⲿ·À»ðǽÅäÖÃΪֻÔÊÐí Internet ºÍ DMZ Ö®¼äÁ¬½ÓËùÐèµÄͨÐÅ¡£ÄÚ²¿·À»ðǽµÄÅäÖÃÒªÄܹ»±£»¤ÄÚ²¿ÍøÂç²»ÊÜ DMZ µÄÓ°Ïì ¡ª DMZ ÊÇ·ÇÐÅÈÎÍøÂ磬Òò´ËÓбØÒª¶ÔÄÚ²¿ÍøÂçʵʩ±£»¤¡£

ʲôÊÇ DMZ£¿¿´¿´ÊÀ½çÉϽöÓеÄÕþÖη½ÃæµÄ DMZ£ºÄϱ±³¯ÏÊÖ®¼äµÄÇøÓò¡£DMZ ÓÉÆä±£»¤±ß½çÈ·¶¨ ¡ª ÔÚÕâÖÖÇé¿öÏ£¬Á½¸öµØÀí±ß½ç£¬·Ö±ðÓɵ¥¶ÀµÄ±£»¤ÊµÌå½øÐмàÊӺͱ£»¤¡£ÍøÂçÖÐµÄ DMZ Óë´Ë·Ç³£ÀàËÆ£ºÄ³µ¥¶ÀµÄÍøÂ粿·Ö¾­¹ýµ¥¶ÀµÄÎïÀí·À»ðǽÓ루ͨ³££©Á½¸öÆäËüÍøÂçÏàÁ¬¡£

DMZ ÓëÆÁ±Î×ÓÍø¡£³£¼ûµÄ·½·¨ÊÇʹÓþßÓжà¸ö½Ó¿ÚµÄµ¥Ò»ÎïÀí·À»ðǽ¡£Ò»¸ö½Ó¿ÚÁ¬½Ó Internet£¬µÚ¶þ¸ö½Ó¿ÚÁ¬½Óµ½ÄÚ²¿ÍøÂ磬µÚÈý¸ö½Ó¿ÚÁ¬½Óµ½Í¨³£³ÆÎª DMZ µÄÇøÓò¡£ÕâÖÖÌåϵ½á¹¹²»ÊÇÕæÕýµÄ DMZ£¬ÒòΪµ¥¸öÉ豸¸ºÔð¶à¸ö±£»¤ÇøÓò¡£ÕâÖÖ·½°¸µÄÈ·ÇÐÃû³ÆÊÇÆÁ±Î×ÓÍø¡£ÆÁ±Î×ÓÍø¾ßÓÐÑÏÖØÈ±ÏÝ ¡ª µ¥¸ö¹¥»÷¾Í¿ÉÆÆ»µÕû¸öÍøÂ磬ÒòΪËùÓÐÍøÂç¶Î¶¼Óë¸Ã·À»ðǽÏàÁ¬¡£

DMZ µÄÓŵ㡣Ϊʲô²¿Êð DMZ£¿ÍøÂç¹¥»÷ÈÕÇ÷Ôö¼Ó ¡ª ÓÐЩֻÊdzöÓÚºÃÍæ¡¢ìÅÒ«×Ô¼ºµÄ¶ñ×÷¾çÄÜÁ¦£¬»¹Ò»Ð©ÊÇÑÏÖØµÄ¡¢ÓÐÄ¿µÄµÄ¹«Ë¾¼äµýºÍÆÆ»µ¡£ÓÐЧµÄ°²È«Ìåϵ½á¹¹Êǹ¥»÷µÄÒ»µÀÆÁÕÏ£¬Í¬Ê±¸Ã½á¹¹¾ßÓпɵ÷ÕûÄÜÁ¦¡£ÕæÕýµÄ DMZ ½á¹¹¾ßÓÐÏÂÁÐÓŵ㣺

¾ßÓÐÕë¶ÔÐԵݲȫ²ßÂÔ¡£Ã¿¸ö·À»ðǽʵʩÓë±£»¤¶ÔÏó¶ÔÓ¦µÄ²ßÂÔ¡£

ÉîÈë·ÀÓù¡£ÔÚ°²È«Ôâµ½ÆÆ»µÊ±£¬É豸µÄ¶à¸öÎïÀí¹¹¼þΪ°²È«¹ÜÀíÔ±Ìṩ¸ü¶àʱ¼äÀ´×ö³ö·´Ó¦¡£ÕâÊÇΪʲôҪ²¿ÊðÕæÕýµÄ DMZ ¶ø²»ÊÇÆÁ±Î×ÓÍøµÄΨһ¡¢Ò²ÊÇ×îÖØÒªµÄÔ­Òò¡£

¸Ä½øÐÔÄÜ¡£Á½É豸¼äͨÐżì²éµÄÖ°Ôð·Ö¿ª£¬Ã¿¸öÌØ¶¨±£»¤ÇøÅäÖÃһ̨É豸¡£

¿ÉÀ©Õ¹ÐÔ¡£¿É¸ù¾ÝÐèÒªÀ©Õ¹·À»ðǽ ¡ª Íⲿ·À»ðǽ´¦ÀíµÄ¸ºÔØÍ¨³£±ØÐë±ÈÄÚ²¿·À»ðǽ¸ßºÜ¶à¡£Ïñ RadWare's FireProof ÕâÑùµÄ¼¼Êõ¿ÉÒÔ¿ç·À»ðǽũ³¡¶øÆ½ºâ¸ºÔØ¡£

Ïû³ý¹ÊÕϵ㡣ΪÁË»ñµÃ¸ß¿ÉÓÃÐÔ£¬Ó¦µ±ÖÁÉÙ²¿ÊðÓëÒ»¶Ô·À»ðǽÍêÈ«ÊÊÓõÄÒ»¶Ô·À»ðǽ¸ºÔØÆ½ºâÆ÷¡£ÕâÑù·À»ðǽ¼´¿ÉÓë DMZ ºËÐĽ»»»»úÍêȫƥÅä¡£

·À»ðǽÀàÐÍ

ĿǰÓÐÈýÖÖ·À»ðǽ£º

»ù±¾Êý¾Ý°üɸѡÆ÷¡£

״̬¼ì²âÊý¾Ý°üɸѡÆ÷¡£

Ó¦ÓóÌÐò´úÀí¡£

»ù±¾Êý¾Ý°üɸѡÆ÷¡£°Ñ¼òµ¥µÄÊý¾Ý°üɸѡ×÷ΪһÖÖ·À»ðǽÒѲ»³£¼û£¬ÒòΪ¼¸ºõËùÓеÄ·ÓÉÆ÷¶¼¿ÉÖ´Ðд˹¦ÄÜ¡£Êý¾Ý°üɸѡֻÊǼòµ¥µØ°´ÕÕÒ»×鹿Ôò±È½Ï´«³öºÍ´«ÈëÊý¾Ý°üµÄ¶Ë¿Ú¡¢Ð­ÒéºÍµØÖ·¡£²»·ûºÏ¹æÔòµÄÊý¾Ý°ü±»·À»ðǽÖÕÖ¹¡£»ù±¾µÄÊý¾Ý°üɸѡÌṩºÜÉٵݲȫÐÔ£¬ÒòΪºÜ¶àÖÖ¹¥»÷¿ÉÇáÒ×µØÈƹýËü¡£

״̬¼ì²âÊý¾Ý°üɸѡÆ÷¡£ÕâЩ·À»ðǽ³ý¼ì²éµ¥¶ÀµÄÊý¾Ý°üÍ⻹¶ÔÁ÷³Ì½øÐмì²é¡£×´Ì¬¼ì²éÒýÇæ¸ú×Ùÿ¸öÁ¬½ÓµÄÆô¶¯²¢È·±£Æô¶¯Óëij¸öÏÈǰµÇ¼µÄÁ¬½ÓÏàÓ¦µÄËùÓÐͨÐÅ¡£·ûºÏ·À»ðǽ¹æÔòµ«ÎÞ·¨Ó³Éäµ½ÈκÎÁ¬½ÓµÄδ¾­ÇëÇóÊý¾Ý°ü½«±»ÖÕÖ¹¡£×´Ì¬¼ì²é±È»ù±¾Êý¾Ý°üɸѡ¸üΪ°²È«£¬µ«»¹ÊÇ¿ÉÄÜÊܵ½Äܹ»Í¨¹ý·À»ðǽ¿ÉÓÃЭÒ飨Èç HTTP£©µÄÈëÇÖµÄÏ®»÷¡£Á½ÀàÊý¾Ý°üɸѡÆ÷¶¼ÎÞ·¨·ÖÎöÈκÎÊý¾Ý°üµÄÄÚÈÝ¡£ÁíÍ⣬Á½ÀàÊý¾Ý°üɸѡ·À»ðǽ¼¸ºõ¶¼ÎÞ·¨ÔÚ°´ÕÕ¹æÔò¼¯½øÐмÆËã֮ǰ½«Ë鯬Êý¾Ý°üÖØÐÂ×é×°ÆðÀ´¡£ÓÚÊÇ£¬Ä³Ð©ÀàÐ͵Ĺ¥»÷µÃÒÔÓø߳¬¼¼ÇÉÖÆ×÷µÄÊý¾Ý°üË鯬½øÐгɹ¦´«µÝ¡£

Ó¦ÓóÌÐò´úÀí¡£Ó¦ÓóÌÐò´úÀíÌṩ×î¸ßµÄ°²È«¼¶±ð¡£Á¬½Ó²»Í¨¹ý´úÀí£¬¶ø´«ÈëÁ¬½ÓÔÚ´úÀí´¦±»Öнأ¬²¢ÓÉ´úÀíʵÏÖÓëÄ¿±ê·þÎñÆ÷µÄÁ¬½Ó¡£Ó¦ÓóÌÐò´úÀí¼ì²éÓÐÐ§ÔØºÉ²¢¿ÉÈ·¶¨ËüÊÇ·ñ·ûºÏЭÒé¡£ÀýÈ磬Õý³£µÄ HTTP ÇëÇóÓÐÈ·¶¨µÄÌØÕ÷¡£Í¨¹ý HTTP ´«µÝµÄ¹¥»÷½«ÓëÕâÐ©ÌØÕ÷ÓÐËù³öÈ루×îÏÔÖøµÄÊÇͨ¹ý HTTP ÇëÇ󴫵ݵÄͨОßÓйý¶à´«ÈëÐÅÏ¢Á¿£©£¬²¢½«±»ÖÕÖ¹¡£Ó¦ÓóÌÐò´úÀí»¹²»Ò×Êܵ½Ë鯬µÄ¹¥»÷¡£ÓÉÓÚΪӦÓóÌÐò´úÀíÊ©¼ÓÁ˸ºÔØ£¬Òò´ËËüÔÚÈýÀà·À»ðǽ¼¼ÊõÖÐËÙ¶È×îÂý¡£

Èç´Ë˵À´£¬ÄÄÖÖ¼¼Êõ×îºÃÄØ£¿´ð°¸È¡¾öÓÚÄúËùÐèµÄ°²È«¼¶±ð¡£Ò»Ð©×´Ì¬¼ì²é·À»ðǽ¿ªÊ¼¼ÓÈëÓ¦ÓóÌÐò´úÀí¹¦ÄÜ£»Checkpoint µÄ Firewall-1 ¾ÍÊÇÕâÑùµÄʵÀý¡£

»ùÓÚÖ÷»úµÄ·À»ðǽ±£»¤¡£³¹µ×·ÀÓùÓ¦µ±ÊÇÈκΰ²È«·½°¸µÄÉè¼ÆÄ¿±ê¡£É¸Ñ¡Â·ÓÉÆ÷ºÍ´«Í³µÄ DMZ ÌṩÈý²ã±£»¤£¬ËüÃÇͨ³£×ãÒÔ±£»¤´ó¶àÊýÍøÂç·þÎñ¡£¶ÔÓڸ߶Ȱ²È«µÄ»·¾³£¬»ùÓÚÖ÷»úµÄ·À»ðǽ»¹¿ÉÌṩÁíÒ»²ãµÄ±£»¤¡£»ùÓÚÖ÷»úµÄ·À»ðǽÔÊÐí°²È«¹ÜÀíԱȷ¶¨ÏêϸÖÜÈ«µÄ°²È«²ßÂÔ£¬ÒÔʹ·þÎñÆ÷µÄ IP Õ»Ö»¶Ô¸Ã·þÎñÆ÷ÉÏÓ¦ÓóÌÐòËùÒªÇóµÄ¶Ë¿ÚºÍЭÒ鿪·Å¡£Ò»Ð©»ùÓÚÖ÷»úµÄ·À»ðǽ»¹ÊµÊ©´«³ö±£»¤£¬ÒÔ°ïÖúÈ·±£Ä³Ì¨Ôâµ½ÆÆ»µµÄ»úÆ÷²»»áÓ°ÏìÍ¬Ò»ÍøÂçÉÏµÄÆäËü»úÆ÷¡£µ±È»£¬»ùÓÚÖ÷»úµÄ·À»ðǽȷʵÔö¼ÓÁËÆÕͨϵͳ¹ÜÀíµÄ¸ºµ£¡£Ó¦¿¼Âǽö¶ÔÄÇЩ°üº¬ÖÁ¹ØÖØÒªÊý¾ÝµÄ·þÎñÆ÷Ôö¼Ó»ùÓÚÖ÷»úµÄ±£»¤¡£

DMZ Ìåϵ½á¹¹ ¡ª °²È«ºÍÐÔÄÜ

ÁíÒ»Àà³£¼ûµÄ¹¥»÷ÊÇ´ÓÏß·ÉÏ¿ú̽Êý¾Ý°ü¡£¾¡¹ÜÓÐ×î½ü³öÏֵķÀ¿ú̽¹¤¾ß£¨¿ÉÄܾ­³£²»¿É¿¿£©£¬µ«Óüòµ¥¼¯Ï߯÷¹¹½¨µÄÍøÂ绹ÊǺÜÈÝÒ×Êܵ½ÕâÖÖ¹¥»÷¡££¨²¢ÇÒ·´·À¿ú̽¹¤¾ßÒ²¿ÉÄÜʹËü³ÉΪһÏîÖØÒªÒéÌâ¡££© ʹÓý»»»»úÌæ´ú¼¯Ï߯÷¿ÉÏû³ý´ËÈõµã¡£ÔÚ¹²Ïí½éÖÊÍøÂ磨¼´Óü¯Ï߯÷¹¹½¨µÄÍøÂ磩ÖУ¬ËùÓеÄÉ豸¿É¿´¼ûËùÓеÄͨÐÅ¡£Í¨³£ÍøÂç½Ó¿Ú¶Ô·Ç·¢¸øËüµÄÊý¾ÝÖ¡²»½øÐд¦Àí¡£»ìÔÓģʽµÄ½Ó¿Ú½«°Ñÿһ֡µÄÄÚÈÝÏòÉÏ´«µ½¼ÆËã»úµÄЭÒéÕ»¡£¸ÃÐÅÏ¢¶ÔÓÚÓÐЭÒé·ÖÎöÆ÷µÄ¹¥»÷Õß¿ÉÄܷdz£ÓмÛÖµ¡£

½»»»ÍøÂç¿ÉÒÔʵ¼Ê¶Å¾øÕâÖÖÇé¿öµÄ·¢Éú¡£½»»»ÍøÂçÖÐÈκλúÆ÷µÄÍøÂç½Ó¿Ú½«Ö»ÄÜ¿´µ½Ìر𷢸ø¸Ã½Ó¿ÚµÄÄÇЩ֡¡£ÔÚÕâÀï»ìÔÓģʽûÓÐʲô²»Í¬£¬ÒòΪ NIC ²»Ê¶±ðÆäËüÈκÎÍøÂçͨÐÅ¡£¹¥»÷Õß¿ú̽½»»»ÍøÂçµÄΨһÒÑÖª·½·¨ÊÇ£º¹¥»÷ÕßÆÆ»µ½»»»»ú±¾Éí²¢¸ü¸ÄÆä²Ù×÷£¬ÕâÑù½»»»»úÖÁÉÙÔÚÒ»¸ö¶Ë¿Ú³ä³âÁËËùÓÐͨÐÅ¡£ÆÆ»µ½»»»»úºÜÄÑ£¬²¢ÇҺܿì»á±»ÍøÂç¹ÜÀíÔ±·¢ÏÖ¡£

½»»»ÍøÂ绹ÃâÈ¥ÁËʹÓÃË«Ö÷»ú DMZ ·þÎñÆ÷µÄ±ØÒª¡£Ë«Ö÷»úÌṩ²»Á˸ü¶àµÄ¸½¼Ó±£»¤£»¸½¼ÓµÄ NIC ²»ÄÜ·ÀÖ¹À´×ÔÒÑÆÆ»µ¼ÆËã»úµÄ¹¥»÷¡£µ«ÊÇÔÚÐèÒª¸ß¿ÉÓÃÐÔ»ò¸ßÐÔÄÜÇé¿öÏ£¬Ê¹ÓÃÁ½¸ö NIC ¿ÉÄܸü¼ÓÊʺϡ£

Ïû³ý¹ÊÕϵ㡣ÔÚÐèÒª¸ß¿ÉÓÃÐԵĻ·¾³ÖÐÓбØÒªÊ¹ÓÃÁ½¸ö NIC¡£Ò»ÖÖÇÐʵ¿ÉÐеÄÉè¼Æ·½°¸ÊÇÔÚºËÐIJ¿·Ö°üÀ¨Á½Ì¨½»»»»ú£¬²¢ÔÚÿ̨·þÎñÆ÷ÖаüÀ¨Á½¸ö NIC¡£Ò»¸ö NIC Á¬½Óµ½Ò»Ì¨½»»»»ú£¬ÁíÒ»¸ö NIC Á¬½Óµ½Áíһ̨½»»»»ú¡£

ÄÚ²¿ÍøÂçµÄÇé¿öÈçºÎ£¿³öÓÚͬÑùµÄÔ­Òò£¬ÄÚ²¿ÍøÂçÒ²Ó¦µ±Óý»»»»úÀ´¹¹½¨¡£Èç¹ûÐèÒª¸ß¿ÉÓÃÐÔ£¬Çë×ñÕÕ DMZ ÖÐͬÑùµÄÔ­Ôò¡£

Ⱥ¼¯»¥Á¬¡£ÎÞÂÛÔÚ DMZ »¹ÊÇÔÚÄÚ²¿ÍøÂçÖУ¬¶¼Ê¹Óü¯Ï߯÷Á¬½ÓËùÓÐȺ¼¯¡£Microsoft ²»½¨ÒéʹÓÿç½ÓµçÀ£¬ÒòΪËüÃDz»ÄÜÌṩȷ±£½éÖÊÃô¸ÐÐͲÙ×÷Õý³£¹¤×÷ËùÐèµÄµç×ÓÐźš£

IPSec ¡ª ÐÅÈÎ DMZ µÄÒ»ÖÖ¸ü°²È«µÄÑ¡Ôñ

Èç¹ûËùÓеķþÎñÆ÷¶¼ÔÚÔËÐÐ Windows 2000£¬ÔòÓ¦µ±Ê¹Óà Internet ЭÒ鰲ȫ (IPSec) À´±£»¤ DMZ ºÍÄÚ²¿ÍøÂçÖ®¼äËùÓÐͨѶµÄ°²È«¡£IPSec ÌṩÏÂÁй¦ÄÜ£º

Éí·ÝÑéÖ¤¡£ ¿ÉÒÔÈ·¶¨ÕâÑùµÄ²ßÂÔ£¬Ê¹µÃÖ»ÓÐÄÇЩÐèÒª±Ë´ËͨѶµÄ¼ÆËã»ú²Å¿ÉÒÔ»¥ÏàͨѶ¡£

¼ÓÃÜ¡£ ÒѾ­ÇÖÈëµ½ DMZ µÄÈëÇÖÕßÎÞ·¨½«Í¨ÐŽâÊͽø»ò½âÊͳöÄÚ²¿ÍøÂç¡£

±£»¤¡£ IPSec ±£»¤ÍøÂç±ÜÃâÖØ·Å¹¥»÷¡¢ÈËΪ¸ÉÔ¤¹¥»÷ÒÔ¼°Í¨¹ý±ê׼ЭÒ飨Èç ICMP »ò HTTP£©½øÐеĹ¥»÷£¨ÕâЩ¹¥»÷¿Éͨ¹ý»ù±¾·À»ðǽºÍ״̬¼ì²éÊý¾Ý°üɸѡÆ÷·À»ðǽ£©¡£

ÆôÓà IPSec ºó£¬ÄÚ²¿·À»ðǽ±ØÐëÖ»ÔÊÐí IPSec¡¢IKE¡¢Kerberos ÒÔ¼° DNS ͨÐÅ£¬ÕâÑù½øÒ»²½¼ÓÇ¿ÁËÄÚ²¿ÍøÂçµÄ°²È«ÐÔ¡£ÄÚ²¿·À»ðǽÖв»»áÓÐÆäËü©¶´¡£¶ÔÓÚ¸÷ÖÖÓ¦ÓóÌÐòÓЩ¶´µÄ±ê×¼·À»ðǽ¹æÔò£¬ÈëÇÖÕß¿ÉÒÔͨ¹ý Firewalk ÕâÑùµÄ¹¤¾ßÈ·¶¨·À»ðǽµÄ²ßÂÔ£»¶ø½«ËùÓÐͨÐÅ·â×°ÔÚ IPSec Öв¢Ö»ÐíʹÓøÃЭÒ飬¿ÉÒþ²Ø¶Ô¹¥»÷Õß¿ÉÄÜÓÐÓõÄʵʩϸ½Ú£¨µ«ÊÇ»¹Ó¦²Î¼ûÏÂÃæµÄ¡°¿ÉÄܵݲȫº¬Ò⡱£©¡£Ï±íÁгöÁËÓ¦µ±ÔÚ·À»ðǽÖпªÆôµÄ·þÎñ£º ·þÎñ

λÖÃ

˵Ã÷

Domain

¶Ë¿Ú 53/tcp ºÍ 53/udp

ÓòÃû·þÎñ

kerberos

¶Ë¿Ú 88/tcp ºÍ 88/udp

Kerberos v.5 Éí·ÝÑéÖ¤

isakmp

¶Ë¿Ú 500/udp

Internet ÃÜÔ¿½»»»

esp

ЭÒé 50

IPSec ·â×°µÄ°²È«ÓÐÐ§ÔØºÉ

ah

ЭÒé 51

IPSec ÑéÖ¤µÄ±êÍ·

Çë×¢Òâ²»ÐèÒªÖ¤ÊéÊÚȨ£»IPSec ²ßÂÔ½«Óà Kerberos £¨±¾»úµÄ Windows 2000 Éí·ÝÑéÖ¤»úÖÆ£©×÷Ϊ½¨Á¢ IKE Ö÷ģʽ°²È«¹ØÁªµÄ»ù´¡¡£

¿ÉÄܵݲȫº¬Òâ¡£ÈçǰËùÊö£¬¶Ô DMZ ºÍÄÚ²¿ÍøÂçÖ®¼äµÄͨÐżÓÃܺ󲻿ÉÄÜÔÙ¼ì²éÄÚ²¿·À»ðǽÖеÄͨÐÅ¡£²¢·ÇËùÓеÄÍøÂç»ò°²È«¹ÜÀíÔ±¶¼¶Ô´Ë·½·¨ÂúÒâ¡£ESP µÄ¼ÓÃÜÌṩÁ˽øÈëÄÚ²¿ÍøÂçµÄ·âװ·¾¶£¬Ò»µ©Ä³Ì¨ DMZ »úÆ÷±»ÆÆ»µ£¬Ëü¾Í¿ÉÄܱ»ÀûÓá£Ê¹Óà IPSec AH Ìæ´ú ESP ½«Ê¹½ÏΪ¼òµ¥µÄ·À»ðǽÅäÖÃÏÔʾÆäÓÅÊÆ£¬Í¬Ê±ÓÉÓÚ AH Êý¾Ý°üÓÐÐ§ÔØºÉδ¾­¼ÓÃÜ£¬»¹¿É½øÐÐͨÐżì²é¡£

ÈëÇÖ¼ì²â ¡ª ÔçÆÚµÄ¾¯¸æÏµÍ³

ÈëÇÖ¼ì²âϵͳÕýÔÚ³ÉΪÓë Internet Á¬½ÓµÄÈκÎÍøÂçµÄ±ØÒª×é¼þ¡£¾¡¹ÜËü²»ÄÜÌæ´ú·À»ðǽÏêϸ²»¼ä¶ÏµÄ¼ì²éºÍ·þÎñÆ÷ÈÕÖ¾£¬µ«ÊÇÈëÇÖ¼ì²âϵͳÄܹ»ÌáÔçʶ±ðDZÔÚÈëÇÖ£¬ÎªÄúÌṩ¸ü¶àµÄʱ¼äÒÔ¶ÔʹʲÉÈ¡ÏàÓ¦´ëÊ©¡£ÇëÔÚ DMZ Öа²×°ÈëÇÖ¼ì²âϵͳ¡£

ÈëÇÖ¼ì²âϵͳºÍ·À²¡¶¾ÊµÓóÌÐòÏàËÆ£¬ËüÃǶ¼ÊÇÔÚ¼ì²âµ½ËüÃÇʶ±ðµÄ¶«Î÷ʱÏò¹ÜÀíÔ±·¢³ö¾¯±¨¡£ÈëÇÖ¼ì²âϵͳ°üº¬Ò»¸ö¹¥»÷ÌØÕ÷Êý¾Ý¿â£¬µ«ÊDz¢·ÇËùÓеÄÈëÇÖ¼ì²âϵͳ¶¼Í¬Ñù¿ÉÒÔʶ±ð²»Í¬ÀàÐ͵Ĺ¥»÷»ò±£³Ö×îÐÂ״̬£¨¸÷¸ö IDS ³§É̶¼½«ËûÃǵÄÌØÕ÷Êý¾Ý¿âºÍ¸üлúÖÆµ±×÷ÉÌÒµ»úÃÜ£©¡£Ä¿Ç°ÓÐÁ½ÖÖÖµµÃ¹Ø×¢µÄ¼ì²âϵͳ£¬ËüÃÇÊÇ£ºRealSecure by Internet Security Systems (http://www.iss.net) ºÍ Network Flight Recorder ( http://www.nfr.net )¡£

»ùÓÚÖ÷»úµÄÈëÇÖ¼ì²â¡£´ó¶àÊýÈëÇÖ¼ì²âϵͳÔÚÍøÂç¼¶±ð¹¤×÷£¬ÔÚÍøÂç±»ÆÆ»µºóÏò¹ÜÀíÔ±·¢³ö¾¯±¨¡£×î½ü³öÏÖÁËÒ»ÖÖеÄÈëÇÖ¼ì²âϵͳÀàÐÍ£º»ùÓÚÖ÷»úµÄÈëÇÖ¼ì²âϵͳ¡£ÕâЩ¹¤¾ß±¾ÉíÔÚ·þÎñÆ÷ÉÏÔËÐУ¬²¢ÔÚÌØ¶¨¼ÆËã»úÔâµ½ÆÆ»µÊ±Ïò¹ÜÀíÔ±·¢³ö¾¯±¨¡£ÕâÖÖ¾¯±¨»úÖÆ¶ÔÓÚ°üº¬ÓÐÖØÒª²Ù×÷Êý¾ÝµÄ¼ÆËã»ú£¨Èçºó¶ËÊý¾Ý¿â·þÎñÆ÷£©ÓÈÎªÖØÒª¡£

½«»ùÓÚÍøÂçµÄÈëÇÖ¼ì²âϵͳºÍ»ùÓÚÖ÷»úµÄÈëÇÖ¼ì²âϵͳ½áºÏÆðÀ´£¬²¢ÇÒÈÃѵÁ·ÓÐËØµÄ°²È«×¨¼Ò¶¨ÆÚ¼ì²éϵͳÈÕÖ¾ÊDZ£»¤ÍøÂç¡¢ÊÕ¼¯Ö¤¾ÝºÍ´¦Àí°²È«Ê¹ʵÄ×îÓÐЧ·½·¨¡£

DNS ¡ª È·±£¿Í»§µ½´ïÕýÈ·µÄµØ·½

³£¼ûµÄ DNS ʵʩ£¨°üÀ¨ÈçͼËùʾµÄʵʩ£©³ÆÎª²ð·Ö DNS ʵʩ¡£Íⲿ·þÎñÆ÷ÓÃÀ´½â¾ö Internet ¶Ô DMZ ÖмÆËã»úµÄ²éѯ£¬²¢½â¾ö DMZ ¼ÆËã»ú¶ÔÆäËü DMZ ¼ÆËã»úµÄ²éѯ¡£ÄÚ²¿·þÎñÆ÷ÓÃÀ´½â¾öÄÚ²¿ÍøÂç¶ÔÄÚ²¿¼ÆËã»úµÄ²éѯ£¬¶Ô DMZ Öлò Internet ÉϼÆËã»úµÄ²éѯ½«±»×ª·¢µ½Íⲿ·þÎñÆ÷¡£µ«ÊDzð·Ö DNS ²»Äܱ£»¤ DNS ¸ßËÙ»º´æÃâÊܹ¥»÷¡£

ÔÚ DNS ¸ßËÙ»º´æµÄÇÖº¦ÖУ¬¹¥»÷Õß»áÆÆ»µÁíÒ»ÍøÂçµÄ DNS ¸ßËÙ»º´æ¡£µ±Êܺ¦ÕßÊÔͼÔÚÆÆ»µµÄÍøÂçÖÐÈ·¶¨µØÖ·Ê±£¬¸Ã¸ßËÙ»º´æ·µ»Ø¹¥»÷ÕßÔÚ¸ßËÙ»º´æÖзÅÈëµÄÎÞЧÐÅÏ¢¡£Í¨³£¹¥»÷ÕßÕâÑù×öÊÇΪÁ˰ÑÊܺ¦ÕßÖØÐ¶¨Ïòµ½¹¥»÷ÕߵļÆËã»ú¡£

×ȫµÄ DNS ʵʩ³ÆÎª ²ð·Ö ¡ª ²ð·Ö DNS ʵʩ¡£ÔÚ DMZ ÖÐÓÐÁ½Ì¨ DNS ·þÎñÆ÷¡£Ò»Ì¨·þÎñÆ÷£¨ÀýÈç DMZDNS-IN£©Ö»½ÓÊÜ¶Ô DMZ ÖмÆËã»úµÄ´«Èë²éѯ ¡ª ²¢Ö»½ÓÊÜ Internet ÉϼÆËã»úµÄ²éѯ¡£Áíһ̨·þÎñÆ÷£¨Èç DMZDNS-OUT£©Ö»ÔÊÐí½â¾ö¶Ô Internet µÄ´«³ö²éѯ£¬ÒÔ¼° DMZ ¼ÆËã»ú¶ÔÆäËü DMZ ¼ÆËã»úµÄ²éѯ¡£DMZDNS-IN ÊÇ DMZ µÄ DNS ÇøÓòµÄÖ÷ DNS ·þÎñÆ÷£¬DMZDNS-OUT ÊǸ¨Öú DNS ·þÎñÆ÷£¬Ê¹Óà IPSec ½øÐÐÇøÓò´«Êä¡£ÄÚ²¿ÍøÂçÖÐµÄ DNS ·þÎñÆ÷½öÊÇÄÚ²¿ÍøÂçµÄÖ÷ DNS ·þÎñÆ÷£¬²¢ÇÒ½«¶Ô DMZ »ò Internet µÄÇëÇóת·¢µ½ DMZDNS-OUT¡£ÕâÏû³ýÁËÊ¹ÍøÂçÒ×ÓÚÊܵ½Òѱ»Ï®»÷µÄ DNS ¸ßËÙ»º´æ¹¥»÷µÄÌõ¼þ¡£

À´×Ô Internet µÄ DNS ²éѯ²»¿ÉÄÜͨ¹ý DMZ ½øÈëÄÚ²¿ÍøÂçÀ´»ñÈ¡´ð°¸¡£Ò»Ð©½üÆÚµÄ¹¥»÷ʹÓà DNS À´´«µÝÆäÓÐÐ§ÔØºÉ¡£Internet ÉϵÄÓû§Ã»ÓбØÒª¶ÔÄÚ²¿ÍøÂçÉϵķþÎñÆ÷½øÐвéѯ¡£

Ïû³ý¹ÊÕϵ㡣Ôڸ߿ÉÓÃÐÔ»·¾³ÖУ¬Ö»Ðè¼òµ¥±¶Ôö DNS ·þÎñÆ÷µÄÊýÁ¿¼´¿É¡£

Ó²¼þ¸ºÔØÆ½ºâ ¡ª ±£³Ö·þÎñÆ÷µÄ×î¼ÑÐÔÄÜ

Windows 2000 Advanced Server °üÀ¨Ò»ÖÖ³ÆÎª¡°ÍøÂç¸ºÔØÆ½ºâ·þÎñ¡±»ò NLBS µÄ¹¦ÄÜ¡£NLBS Ϊ Web Õ¾µã¹ÜÀíÔ±ÌṩÁËÔÚÏàͬÅäÖõķþÎñÆ÷Å©³¡ÖнøÐзþÎñÆ÷¸ºÔØ·ÖÅäµÄ·½·¨¡£NLBS ¶Ô²»ÐèÒª¸´ÔÓ״̬ά»¤»òÐÔÄܼàÊÓµÄÓ¦ÓóÌÐòÀ´Ëµ·Ç³£ÊÊÓᣵ«¶ÔÓÚÐèÒªÕâЩ¹¤×÷µÄÓ¦ÓóÌÐòÀ´Ëµ£¬ÔòӦѡÔñÓ²¼þ¸ºÔØÆ½ºâ¡£ÕâЩÉ豸ÓÐʱ³ÆÎªµÚ 7 ²ã½»»»»ú¡£

Ïñ F5 ÍøÂçµÄ BigIP Content Switch£¨·Ç¹Ù·½ÈϿɣ¬Ö»ÊÇÐÐÒµÖÐÈÏͬËüÊÇ×îºÃ²úÆ·Ö®Ò»£©ÕâÑùµÄÉ豸ÔÚ OSI Ä£ÐÍµÄµÚ 2 µ½µÚ 7 ²ã¹¤×÷¡£BigIP Content Switch ¼ì²âÓ¦ÓóÌÐòµÄ״̬ºÍÔËÐÐÇé¿ö£¬ÔÚ Web ·þÎñÆ÷Ö®¼äÌṩ¸ºÔØÆ½ºâºÍÕæÊµÈÝ´í¡£ÈôÒªÏû³ýÈκε¥Ò»µÄ¹ÊÕϵ㣬ÐèʹÓÃÁ½¸öÓëËùÓÐ Web ·þÎñÆ÷ÍêÈ«Ïà·ûµÄ¸ºÔØÆ½ºâÉ豸¡£F5 »¹ÌṩÁËÖ§³Ö¼ÓÃÜÌ×½Ó×ÖЭÒé²ã (SSL) µÄ BigIP Content Switch °æ±¾¡£SSL »á»°ÔÚ BigIP SSL AcceleratorÖÐÖÕÖ¹£¬È»ºóÈ·¶¨ÓÉÄĄ̈ Web ·þÎñÆ÷Ö´Ðиù¤×÷¡£BigIP Accelerator ½øÐÐÏÂÁвÙ×÷£º

Ð¶ÔØ Web ·þÎñÆ÷µÄ SSL ´¦Àí£¬Ìá¸ßÆäÐÔÄÜ¡£

¼¯ÖйÜÀíÖ¤Êé¡£½«Ö¤Êé°²×°ÔÚ SSL ¼ÓËÙÆ÷ÉÏ£¬¶ø²»ÊÇÿһ̨ Web ·þÎñÆ÷ÉÏ¡£Ëü»¹¿Éʹ¶à¸ö BigIP ¿ØÖÆÆ÷Ö®¼äµÄÖ¤Êéͬ²½¡£

ÆôÓà HTTP Ö÷»ú±êÍ·¡£

½â¾ö AOL ¿Í»§¶Ë IP µØÖ·¹²ÏíÎÊÌâ¡£

Ïû³ý¹ÊÕϵ㡣Èç¹ûÄ¿±ê½ö½öÊÇÆ½ºâ·þÎñÆ÷µÄ¸ºÔØ£¬Ò»Ì¨¸ºÔØÆ½ºâÉ豸×ãÒÓ¡£µ«ÊÇÈôÒªÌá¹©ÕæÊµÈÝ´í¹¦ÄÜ£¬ÔòÐè¶ą̀ÅäÖÃÍêȫƥÅäµÄÉ豸¡£

´æ´¢ÇøÓòÍøÂç ¡ª ¶ÔÄÚ²¿ÍøÂçµÄ¼¯Öд洢

´æ´¢ÇøÓòÍøÂç¼¼ÊõÒѷdz£³ÉÊ죬ֻҪÊÇÅ䱸ÓÐ´ó´æ´¢ÈÝÁ¿µÄµØ·½¶¼¿ÉʹÓá£SAN ½«´æ´¢¹¦ÄÜ´ÓͨÓ÷þÎñÆ÷ÒÆµ½Îª´«Êä´óÁ¿Êý¾Ý¶øÌرðÉè¼ÆµÄ¸ßËÙÍøÂçÉÏ¡£ÕâÓÐÖúÓÚ£º

ͨ¹ý½«´ÅÅÌÕóÁÐÒÆ³ö»ú¹ñÀ´ÓÅ»¯·þÎñÆ÷»ú¹ñ¿Õ¼ä¡£

ͨ¹ý½«Êý¾Ý´æ´¢ÔÚµ¥¶ÀµÄ¡¢²»Ò×ÔâÊÜĿǰËùÖªÀàÐ͹¥»÷µÄÍøÂçÖУ¬Ôö¼ÓÊý¾ÝµÄ°²È«ÐÔ¡£

ͨ¹ýÔÚÊý¾ÝÍøÂçÖ®Íâ±£ÁôͨÐű¸·Ý£¬Ìṩ²»ÊÜ LAN Ô¼ÊøµÄ±¸·Ý¡£

×î³õ£¬Ê¹ÓùâÏËͨµÀÖٲû· (FC-AL) À´½¨Á¢ SAN¡£½ÏеĹâÏËͨµÀ½»»»»úÌṩ¸ü¸ßˮƽµÄÍÌÍÂÁ¿£¬²¢Ê¹¹ÜÀíÔ±¿ÉÒÔÉè¼ÆÃ»Óе¥Ò»¹ÊÕϵãµÄ SAN¡£

½»»»¹âÏËͨµÀ SAN ÖÁÉÙ°üÀ¨£º

Á½Ì¨Î»ÓÚºËÐÄÏ໥Á¬½ÓµÄ FC ½»»»»ú¡£

¼¸Ì¨Î»ÓÚÍâΧµÄ½»»»»ú ¡ª ÿ¸ö LAN ÓÐһ̨Óë SAN Á¬½ÓµÄ½»»»»ú¡£Ã¿Ì¨ÍâΧ½»»»»ú¶¼ÓëÁ½Ì¨ºËÐĽ»»»»úÁ¬½Ó¡£

ÿ̨·þÎñÆ÷ÖÐµÄ FC ½Ó¿ÚÓëÆä±¾µØµÄ SAN ½»»»»úÏàÁ¬¡£

SAN ´ÅÅÌȺ¼¯ÓÐһ̨½»»»»úÓëÁ½Ì¨ºËÐĽ»»»»úÁ¬½Ó¡£

SAN ±¸·ÝÉ豸µÄһ̨½»»»»ú£¬ÓëÁ½Ì¨ºËÐĽ»»»»úÁ¬½Ó¡£

Ïû³ý¹ÊÕϵ㡣±¶ÔöºËÐÄÒÔÍâµÄËùÓÐÉ豸£ºÔÚÿ̨·þÎñÆ÷ÖÐʹÓÃÁ½¸ö¹âÏËͨµÀÊÊÅäÆ÷¡¢Ã¿¸ö LAN ÖÐʹÓÃÁ½Ì¨ÍâΧ½»»»»ú¡¢¶Ô SAN ´ÅÅÌȺ¼¯Ê¹ÓÃÁ½Ì¨ÍâΧ½»»»»ú£¬ÒÔ¼°¶Ô SAN ±¸·ÝÉ豸ʹÓÃÁ½Ì¨ÍâΧ½»»»»ú¡£Ê¼ÖÕ½«Á½Ì¨ÍâΧ½»»»»úÓëÁ½Ì¨ºËÐĽ»»»»úÏàÁ¬¡£

ÍøÂ總¼Ó´æ´¢µÄÓйØÇé¿ö£¿Microsoft ²»Ö§³Ö NAS ´æ´¢ Exchange Îļþ¡£Exchange ÒªÇóËùÓеÄÎļþ¶¼±£´æ±¾µØÉ豸ÉÏ¡£Exchange ÔÚ¹âÏËÁ¬½ÓµÄ SAN É豸ÉÏÔËÐÐÁ¼ºÃ£¬ÕâЩÉ豸¶Ô Windows 2000 ±íÏÖΪ±¾µØÉ豸¡£

© 2000 Microsoft Corporation¡£°æÈ¨ËùÓС£

±¾ÎĵµËù°üº¬µÄÐÅÏ¢´ú±íÁËÔÚ·¢²¼Ö®ÈÕ£¬Microsoft Corporation ¶ÔËùÌÖÂÛÎÊÌâµÄµ±Ç°¿´·¨¡£ÒòΪ Microsoft ±ØÐë˳Ӧ²»¶Ï±ä»¯µÄÊг¡Ìõ¼þ£¬¹Ê¸ÃÎĵµ²»Ó¦Àí½âΪ Microsoft Ò»·½µÄ³Ðŵ£¬Microsoft ²»±£Ö¤Ëù¸øÐÅÏ¢ÔÚ·¢²¼Ö®ÈÕÒÔºóµÄ׼ȷÐÔ¡£

±¾Îĵµ½ö¹©²Î¿¼¡£ÔÚ±¾ÎĵµÖУ¬MICROSOFT ²»×öÈκÎÃ÷ʾµÄ»òĬʾµÄ±£Ö¤¡£

Microsoft¡¢BackOffice¡¢MS-DOS¡¢Outlook¡¢PivotTable¡¢PowerPoint¡¢Microsoft Press¡¢Visual Basic¡¢Windows¡¢Windows NT ºÍ Office »Õ±êÊÇ Microsoft ÔÚÃÀ¹úºÍ/»òÆäËü¹ú¼Ò£¨»òµØÇø£©µÄ×¢²áÉ̱ê»òÉ̱ꡣ

ÔðÈα༭£ºadmin
±¾ÎÄÒýÓõØÖ·£º http://www.3pcode.com/asp/2004/10/2165.htm
Ïà¹ØÎÄÕÂ