
YuChakTinMichael‘sGIACGCFWProjectAssignment
Page 120
VPNModel:
A routertorouterVPNmodelisnotdeployedprimarilybecausethevolumeofuse
betweenthepartneringorganizationsdoesnotjustifyarouterroutersetup. Instead,a
RemoteAccessbasedVPNsolutionisdeployedtoprovidemaximum flexibilityand
costeffectiveness.
TheparagraphbelowisextractedfromMicrosoft’sRemoteAccessVPNConnections
documenttoillustratethisparticulartypeof VPNscenario:
“FordialupVPNclientswhoconnecttotheInternetbeforecreatingaVPN
connectionwithaVPNserverontheInternet,twoIP addressesareallocated:
n WhencreatingthePPPconnection,IPCPnegotiationwiththeISPNASassignsa
publicIPaddress.
n WhencreatingtheVPNconnection,IPCPnegotiationwiththe VPNserver
assignsanintranetI Paddress.TheIPaddressallocated bytheVPNservercan
beapublicIPaddressorprivateIPaddress,dependingonwhetheryour
organizationisimplementingpublicorprivateaddressingonitsintranet.
Ineithercase,theIPaddressallocatedtotheVPNclientmustbereachablebyhosts
ontheintranet andviceversa.TheVPNservermusthaveappropriateentriesinits
routingtabletoreachallthehostsontheintranetandtheroutersoftheintranetmust
havetheappropriateentriesintheirroutingtablestoreachtheVPNclients.
ThetunneleddatasentthroughtheVPNisaddressedfromtheVPNclient'sVPN
serverallocatedaddresstoanintranetaddress.TheouterIPheaderisaddressed
betweentheISPallocatedIP addressoftheVPNclientandthepublicaddressofthe
VPNserver. BecausetheroutersontheInternetonlyprocesstheouterIPheader,the
InternetroutersforwardthetunneleddatatotheVPNserver'spublicIPaddress.”
24
24
http://www.microsoft.com/windows2000/techinfo/reskit/enus/default.asp?url=/WINDOWS2000/techi
nfo/reskit/enus/intwork/inbe_vpn_obwd.asp
Kommentare zu diesen Handbüchern