分享
分销 收藏 举报 申诉 / 54
播放页_导航下方通栏广告

类型RAS远程访问和VPN服务器架构.ppt

  • 上传人:xrp****65
  • 文档编号:13186680
  • 上传时间:2026-02-01
  • 格式:PPT
  • 页数:54
  • 大小:3.90MB
  • 下载积分:10 金币
  • 播放页_非在线预览资源立即下载上方广告
    配套讲稿:

    如PPT文件的首页显示word图标,表示该PPT已包含配套word讲稿。双击word图标可打开word文档。

    特殊限制:

    部分文档作品中含有的国旗、国徽等图片,仅作为作品整体效果示例展示,禁止商用。设计者仅对作品中独创性部分享有著作权。

    关 键  词:
    RAS 远程 访问 VPN 服务器 架构
    资源描述:
    Slide Title,Body Text,Second level,Third level,Fourth level,Fifth level,配置远程访问,概述:,介绍远程访问的基础结构,配置,VPN,连接,配置拨号连接,配置无线连接,为,DHCP,集成配置路由和远程访问,利用远程访问策略控制用户的远程访问,介绍远程访问的基础结构,Network Access Server,IAS,Server,DHCP Server,Domain,Controller,Dial-up Client,Wireless Access Point,Wireless Client,VPN Client,建立远程访问连接(,1,),LAN Protocols,Remote Access Protocols,Local Area Network,LAN Protocols,Remote Access,Protocols,Internet,Remote Access Client,Remote Access Server,远程访问客户端,Type of Client,Description,VPN Client,Connects to a network across a shared or public network,Emulates a point-to-point link on a private network,Dial-up,Client,Connects to a network by using a communications network,Creates a physical connection to a port on a remote access server on a private network,Uses a modem or ISDN adapter to dial in to the remote access server,Wireless,Client,Connects to a network by infrared light and radio frequency technologies,Includes many different types of devices,身份验证,Authentication,Verifies a remote users identification to the network service that the remote user is attempting to access(interactive logon),Network Access,Server,Network Access,Client,Domain,Controller,1,2,1,Authorization,Verifies that the connection attempt is allowed;authorization occurs after a successful logon attempt,2,概述:,介绍远程访问的基础结构,配置,VPN,连接,配置拨号连接,配置无线连接,为,DHCP,集成配置路由和远程访问,利用远程访问策略控制用户的远程访问,4,配置,VPN,链接,标准架构模式,Server,版操作系统,两块网卡,客户端,另类架构模式,单网卡架构,VPN,服务器,单网卡单公网,IP,单网卡双,IP,(公,+,私),虚拟网卡架构,VPN,服务器,利用,MS LOOPBACK,虚拟网卡,配置方法如同标准架构模式,5 VPN,原理,在公共网络上通过建立起点到点链路从而在两台计算机之间发送加密数据。,数据封装的目的:建立点到点链路。,数据加密的目的:建立私有的链路。,5 VPN,原理,VPN,的优点,节约成本;移动通信费用的节省;专线费用得节省;设备投资的节省;支持费用的节省。,增强安全性:隧道技术,Tunneling,,加解密技术,Encryption&Decryption,,密钥管理技术,Key Management,,身份认证技术,Authentication,。,网络协议支持:,IP,,,IPX,,,NetBEUI,。,Appletalk,,,DECNet,,,SNA,等。,容易扩展。,可随意与合作伙伴联网。,更好控制主动权。,安全的,IP,地址。,支持新兴应用:,IP,语音,,IP,传输,,RSIP,,,IPv6,,,MPLS,,,SNMPv3,,以及支持,ADSL,、,Cable Modem,、光纤以太网、,WLAN,等网络链接技术。,Domain,Controller,VPN Client,VPN Server,VPN,连接,A,VPN,extends the capabilities of a private network to encompass links across shared or public networks,such as the Internet,in a manner that emulates a point-to-point link,3,VPN server authenticates,and authorizes the client,2,VPN server,answers the call,4,VPN server transfers,data,VPN client calls the,VPN server,1,VPN,连接结构,VPN Tunnel,Tunneling Protocols,Tunneled Data,VPN Client,VPN Server,Address and Name Server Allocation,DHCP,Server,Domain,Controller,Authentication,Transit Network,Remote User to Corp Net,Remote,Access Server,Branch Office to Branch Office,Remote,Access Server,VPN,连接协议,Examples of Remote Access Server Using L2TP/IPSec,Category,Description,PPTP,Employs user-level Point-to-Point Protocol(PPP)authentication methods and Microsoft Point-to-Point Encryption(MPPE)for data encryption,L2TP/IPSec,Employs user-level PPP authentication methods over a connection that is encrypted with IPSec,Recommended authentication method for VPN network access is L2TP/IPSec with certificates,配置虚拟专用网端口,路由和远程访问,操作,(A),查看,(V),路由和远程访问,服务器状态,SERVERX(,本地,),Ports,远程访问客户端,(0),IP,路由,远程访问策略,名称,设备,注释,状态,端口,WAN,微型端口,(PPTP)(VPN3-4)VPN,不活动,WAN,微型端口,(PPTP)(VPN3-3)VPN,不活动,WAN,微型端口,(PPTP)(VPN3-2)VPN Inactive,WAN,微型端口,(PPTP)(VPN3-1)VPN Inactive,WAN,微型端口,(PPTP)(VPN3-0)VPN,不活动,WAN,微型端口,(L2TP)(VPN2-4)VPN,不活动,WAN,微型端口,(L2TP)(VPN2-3)VPN Inactive,WAN,微型端口,(L2TP)(VPN2-2)VPN Inactive,WAN,微型端口,(L2TP)(VPN2-1)VPN,不活动,WAN,微型端口,(L2TP)(VPN2-0)VPN,不活动,Direct Parallel(LPT1)PARALLEL Inactive,Modem(COM 3)MODEM Inactive,PPTP,端口,L2TP,端口,调制解调器和电缆端口,7.2.2,配置虚拟专用网端口,配置用户拨入设置,权限,呼叫方,ID,回拨,IP,路由,7.2.4,配置用户拨入设置,验证服务器,概述:,介绍远程访问的基础结构,配置,VPN,连接,配置拨号连接,配置无线连接,为,DHCP,集成配置路由和远程访问,利用远程访问策略控制用户的远程访问,拨号连接,Domain,Controller,Dial-up,Client,Dial-up networking,is the process of a remote access client making a temporary dial-up connection to a physical port on a remote access server by using the service of a telecommunications provider,3,RA server authenticates,and authorizes the client,2,RA server,answers the call,4,RA server transfers,data,Dial-up client calls,the RA server,1,Remote Access Server,配置拨号链接和无线链接,Standard,Description,802.11,又称为,Wi-Fi,。由,IEEE,的一个工作组为,WLAN,开发的一组规范。定义了,OSI,中物理层和数据链路层中的媒体访问子层,MAC,部分内容。所有的,802.11,标准的,MAC,子层均相同,但它们的物理实现方式有所不同。,802.11b,两种速率:,5.5Mbps,和,11Mbps,,比,802.11,有更高的数据传输率,支持较大的工作距离,但易收到无线电信号干扰。适合于家庭和小型企业使用。,802.11a,传输速率高达,54Mbps,,工作距离小。使用,12,个互不重叠的信道,所以适合在高流量的场合中使用。由于使用的无线电频谱喻,802.11,、,802.11b,、,802.11g,不同,所以它们之间不能实现互操作。,802.11g,是,802.11b,的增强版本,二者兼容。只需升级一个固件即可。速度达到,54Mbps,,但工作距离比,802.11b,反而短,且更易收到无线电信号的干扰。,802.1x,是,802.11,的扩展。定义了在允许访问网络之前需要进行身份验证的方式。同时,也可适用于有线网络。可以使用,EAP-TLS,、,EAP-MS-CHAP v2,、,PEAP,的密码验证方式。,PEAP,可与,TLS,或,MS-CHAP v2,一起使用。,PEAP-TLS,是推荐验证方式,提供在严格的验证方式和确定密钥方式,拨号访问连接结构,Dial-up Client,Address and Name Server Allocation,DHCP,Server,Domain,Controller,Authentication,Remote Access,Server,WAN Options:,Telephone,ISDN,X.25,or ATM,LAN and Remote Access,Protocols,Network Access Server,IAS,Server,DHCP Server,Domain,Controller,Wireless Access Point,Wireless Client,无线网络访问,A,wireless network,uses technology that enables devices to communicate by using standard network protocols and electromagnetic wavesnot network cablingto carry signals over part or all of the network infrastructure,Standard,Description,Infrastructure WLAN,Clients connect to wireless access points,Peer-to-peer WLAN,Network wireless clients communicate directly with each other without the use of cables,无线连接的结构,DHCP,Server,Remote Access Server,Domain,Controller,Wireless Client,(Station),Wireless Access Point,Address and Name Server Allocation,Authentication,Ports,配置身份验证协议,标准的身份验证,可扩展的身份验证,Available Methods of Authentication,Remote and wireless authentication methods include:,CHAP,PAP,SPAP,MS-CHAP,MS-CHAP v2,EAP-TLS,PEAP,MD-5 Challenge,Recommended method for user,authentication is by using smart card certificates,身份验证协议,PAP(,密码身份验证协议,),使用简单文字组成的密码,它是最简单的身份验证协议,SPAP(shiva,密码身份验证协议,),一种简单的加密密码的身份验证协议,被,shive,远程访问服务器支持,CHAP(,质询握手身份验证协议,),被各种类型的远程访问服务器和客户端使用,Microsoft,路由和远程访问服务支持,CHAP,身份验证协议,MS-CHAP(microsoft,质询握手身份验证协议,),被,microsoft windows95,客户端使用,只支持,microsoft,客户端,MS-CHAP V2(Microsoft,质询握手身份验证协议,),执行交互的身份验证,作为,windows2000,和更新版本操作系统的默认远程访,问协议,EAP-TLS(,可扩展身份验证协议,-,传输层安全,),PEAP(,受保护的可扩展身份验证协议,),标准的身份验证,Protocol,Security,密码身分验,证协议,Low,Shiva,密码,身份验证,协议,Medium,High,Use when,客户机和服务器不能利用更安全的验证形式进行协商时。,连接到,Shiva LANRover,时,或者当,Shiva,客户机连接到基于,Windows 2000,的远程访问服务器时。,某些客户机运行的不是,Microsoft,操作系统时,盘问沟通,身份验,证协议,High,MS-CHAP,MS-CHAP,v2,High,你的客户机运行,Windows NT version 4.0 and later or,Microsoft Windows 95,或以后的版本,有些运行,Windows 2000,的拨号客户机,运行,Windows NT 4.0,或,Windows 98,的,VPN,客户机时,可扩展的身份验证,允许客户机和服务器协商他们将使用的身份验证方法,支持所使用的身份验证,1,、,MD5-CHAP,2,、传输层安全性,3,、附加的第三方的身份验证方法,确保支持通过,API,进行身份验证的方法,概述:,介绍远程访问的基础结构,配置,VPN,连接,配置拨号连接,配置无线连接,为,DHCP,集成配置路由和远程访问,利用远程访问策略控制用户的远程访问,利用,DHCP,将,IP,地址分配给远程访问客户机,如果,DHCP,服务器是有效的,远程服务器在最初从,DHCP,服务器获取,10,个,IP,地址,如果,DHCP,服务器是无效的,远程服务器使用“自动专用,IP,寻址”地址确保,DHCP,服务器总是可用,为使用,DHCP,而配置路由和远程访问,General,Security,IP,PPP,Event Logging,Enable IP routing,Allow IP-based remote access and demand-dial connections,IP address assignment,This server can assign IP addresses by using:,Dynamic Host Configuration Protocol(DHCP),Static address pool,From,To,Number,IP Add,Mask,A,dd,E,dit,R,emove,Use the following adapter to obtain DHCP,DNS,and WINS addresses for dial-up clients.,Ada,p,ter:,OK,Cancel,A,pply,LONDON(local)Properties,Corpnet:,概述:,介绍远程访问的基础结构,配置,VPN,连接,配置拨号连接,配置无线连接,为,DHCP,集成配置路由和远程访问,利用远程访问策略控制用户的远程访问,What Is a Remote Access Policy?,A,remote access policy,is a named rule that consists of the following elements:,Conditions,.,远程访问策略的条件是一系列参数,例如一天中的时间,用户组,主叫,ID,或者,ip,地址。这些参数与连接到服务器的客户机的参数项匹配。,Remote access permission.,对用户帐号的拨入属性和远程访问策略加以组合,在此基础上才允许远程访问连接。,Profile.,每个策略包括一个配置文件,里面有一些设置值(例如身份验证和加密协议),这个配置文件被应用于相应的连接。配子文件中的设置值立即应用于连接,并且可能会导致该连接拒绝,。,What Is a Remote Access Policy Profile?,Dial-in Constraints,IP Properties,IP Address Assignment,IP Filters,Multilink,Authentication,Encryption,Advanced Settings,Remote Access User,检测远程访问策略,A Remote Access Policy:,存储在本地,而不在活动目录,策略组件,条件,权限,配置,文件,检测远程访问策略评估,遵循策略评估的逻辑,检测默认策略和检测多个策略,遵循策略评估的逻辑,Connection,No,Deny,Allow,Profile Evaluation,Conditions,Permissions,Profile,Allow,Deny,Use Remote,Access Policy,Connection,Yes,No,Connection,No,Deny,Allow,Profile Evaluation,Connection,Conditions,Permissions,Profile,Yes,Allow,Deny,Use Remote,Access Policy,No,Yes,实验,7-1,如何架设,windows2003,远程访问服务器,远程访问的集中身份验证,IAS,概述,介绍,IAS(Internet Authentication Service),安装和配置,IAS,Introduction to IAS,Windows 2003,网络 中的,IAS and RADIUS,IAS,的用途和用法,RADIUS(Remote Authentication Dial-In User Service),How Centralized Authentication Works,RADIUS Server,RADIUS Client,Client,Dials in to a local RADIUS client to gain network connectivity,1,Forwards requests to a RADIUS server,2,Authenticates requests and stores accounting information,3,Domain Controller,Communicates to the RADIUS client to grant or deny access,4,Remote Access Server,Installing and Configuring IAS,安装,IAS Server,配置,IAS Server,为利用,RADIUS,的身份验证功能配置远程访问服务器,为利用,RADIUS,的记帐功能配置远程访问服务器,为记帐信息配置日志,Installing an IAS Server,Windows Components Wizard,Windows Components,You can add or remove components of Windows 2000.,To add or remove a component,click the check box.A shaded box means that only part of the component will be installed.To see whats included in a component,click Details.,Components:,Management and Monitoring Tools,Message Queuing Services,Other Network File and Print Services,Networking Services,3.5 MB,0.0 MB,5.0 MB,2.6 MB,Description:,Contains a variety of specialized,network-related services and protocols.,Total disk space required:,Space available on disk:,0.8 MB,5962.6 MB,Details,Cancel,Networking Services,To add or remove a component,click the check box.A shaded box means that only part of the component will be installed.To see whats included in a component,click Details.,Total disk space required:,Space available on disk:,0.8 MB,5962.6 MB,Details,Cancel,OK,Description:,Enables authentication,authorization and accounting of dial-up and PN users.IAS supports the RADIUS protocol,Subcomponents of Networking Services:,COM Internet Services Proxy,Domain Name System(DNS),Dynamic Host Configuration Protocol(DHCP),Internet Authentication Service,QoS Admission Control Service,Simple TCP/IP Services,0.0 MB,1.1 MB,0.0 MB,0.0 MB,0.0 MB,0.0 MB,Configuring an IAS Server,Add RADIUS Client,Client Information,Specify information regarding the client.,Client a,d,dress(IP or DNS):,192.168.1.200,C,l,ient-Vendor,Microsoft,C,lient must always send the signature attribute in the request,S,hared secret:,Con,f,irm shared secret:,B,ack,Finish,Cancel,V,erify,Use an IP address,if possible,Select Microsoft if using Routing and Remote Access,Configuring a Remote Access Server to Use RADIUS Authentication,PHOENIX(local)Properties,General,Security,IP,PPP,Event Logging,The authentication provider validate credentials for remote access clients and demand-dial routers.,Authentication provider:,RADIUS Authentication,Authentication Methods,Configure,Configure,Windows Accounting,Accounting provider:,The accounting provider maintains a log of connection requests and sessions.,OK,Cancel,Apply,Change to RADIUS Authentication,Add RADIUS Server,Server name:,Secret:,Time-out(seconds):,Port:,Always use digital signatures,Change,OK,Cancel,Initial score:,Radius Server,5,30,1812,Enter the Server Name,Configuring a Remote Access Server to Use RADIUS Accounting,PHOENIX(local)Properties,General,Security,IP,PPP,Event Logging,The authentication provider validate credentials for remote access clients and demand-dial routers.,Authentication provider:,RADIUS Authentication,Authentication Methods,Configure,Configure,RADIUS Accounting,Accounting provider:,The accounting provider maintains a log of connection requests and sessions.,OK,Cancel,Apply,Add RADIUS Server,Server name:,Secret:,Time-out(seconds):,Port:,Send RADIUS Accounting On and Accounting Off messages,Change,OK,Cancel,Initial score:,Radius Server,5,30,1812,Enter the Server Name,Change to RADIUS Accounting,Configuring Logs for Accounting Information,Configure Settings for Accounting Logs:,Select Events to Log,Log accounting requests,Log authentication requests,Log periodic status,Select Log File Format,Database-compatible format,IAS format,New Log Time Period,Log File Directory,总结,:,介绍,IAS(Internet Authentication Service),安装和配置,IAS,实验,7-2,配置,VPN,拨入控制及,IAS,
    展开阅读全文
    提示  咨信网温馨提示:
    1、咨信平台为文档C2C交易模式,即用户上传的文档直接被用户下载,收益归上传人(含作者)所有;本站仅是提供信息存储空间和展示预览,仅对用户上传内容的表现方式做保护处理,对上载内容不做任何修改或编辑。所展示的作品文档包括内容和图片全部来源于网络用户和作者上传投稿,我们不确定上传用户享有完全著作权,根据《信息网络传播权保护条例》,如果侵犯了您的版权、权益或隐私,请联系我们,核实后会尽快下架及时删除,并可随时和客服了解处理情况,尊重保护知识产权我们共同努力。
    2、文档的总页数、文档格式和文档大小以系统显示为准(内容中显示的页数不一定正确),网站客服只以系统显示的页数、文件格式、文档大小作为仲裁依据,个别因单元格分列造成显示页码不一将协商解决,平台无法对文档的真实性、完整性、权威性、准确性、专业性及其观点立场做任何保证或承诺,下载前须认真查看,确认无误后再购买,务必慎重购买;若有违法违纪将进行移交司法处理,若涉侵权平台将进行基本处罚并下架。
    3、本站所有内容均由用户上传,付费前请自行鉴别,如您付费,意味着您已接受本站规则且自行承担风险,本站不进行额外附加服务,虚拟产品一经售出概不退款(未进行购买下载可退充值款),文档一经付费(服务费)、不意味着购买了该文档的版权,仅供个人/单位学习、研究之用,不得用于商业用途,未经授权,严禁复制、发行、汇编、翻译或者网络传播等,侵权必究。
    4、如你看到网页展示的文档有www.zixin.com.cn水印,是因预览和防盗链等技术需要对页面进行转换压缩成图而已,我们并不对上传的文档进行任何编辑或修改,文档下载后都不会有水印标识(原文档上传前个别存留的除外),下载后原文更清晰;试题试卷类文档,如果标题没有明确说明有答案则都视为没有答案,请知晓;PPT和DOC文档可被视为“模板”,允许上传人保留章节、目录结构的情况下删减部份的内容;PDF文档不管是原文档转换或图片扫描而得,本站不作要求视为允许,下载前可先查看【教您几个在下载文档中可以更好的避免被坑】。
    5、本文档所展示的图片、画像、字体、音乐的版权可能需版权方额外授权,请谨慎使用;网站提供的党政主题相关内容(国旗、国徽、党徽--等)目的在于配合国家政策宣传,仅限个人学习分享使用,禁止用于任何广告和商用目的。
    6、文档遇到问题,请及时联系平台进行协调解决,联系【微信客服】、【QQ客服】,若有其他问题请点击或扫码反馈【服务填表】;文档侵犯商业秘密、侵犯著作权、侵犯人身权等,请点击“【版权申诉】”,意见反馈和侵权处理邮箱:1219186828@qq.com;也可以拔打客服电话:0574-28810668;投诉电话:18658249818。

    开通VIP折扣优惠下载文档

    自信AI创作助手
    关于本文
    本文标题:RAS远程访问和VPN服务器架构.ppt
    链接地址:https://www.zixin.com.cn/doc/13186680.html
    页脚通栏广告

    Copyright ©2010-2026   All Rights Reserved  宁波自信网络信息技术有限公司 版权所有   |  客服电话:0574-28810668    微信客服:咨信网客服    投诉电话:18658249818   

    违法和不良信息举报邮箱:help@zixin.com.cn    文档合作和网站合作邮箱:fuwu@zixin.com.cn    意见反馈和侵权处理邮箱:1219186828@qq.com   | 证照中心

    12321jubao.png12321网络举报中心 电话:010-12321  jubao.png中国互联网举报中心 电话:12377   gongan.png浙公网安备33021202000488号  icp.png浙ICP备2021020529号-1 浙B2-20240490   


    关注我们 :微信公众号  抖音  微博  LOFTER               

    自信网络  |  ZixinNetwork