ip ipsec
play

IP IPSec ( ) 13 Network - PDF document

IP IPSec ( ) 13 Network Security, Principles and Practice,2nd Ed. : http://www.fata.ir


  1. IP ﻨﻣاﻴﺖ IPSec ( ) ﺮﺑ ﻲﻨﺘﺒﻣﻞﺼﻓ 13 بﺎﺘﻛ زا Network Security, Principles and Practice,2nd Ed. ﻂﺳﻮﺗ هﺪﺷ ﺶﻳاﺮﻳو : ﺎﺿر ﺪﻴﻤﺣيرﺎﻳﺮﻬﺷ http://www.fata.ir http://mehr.sharif.edu/~shahriari ���� ���� ����� ���� ١ ﺐﻟﺎﻄﻣ ﺖﺳﺮﻬﻓ � ﻪﻣﺪﻘﻣ IPSec � يرﺎﻤﻌﻣ IPSec � يﺎﻫ ﺲﻳوﺮﺳ SA � ﻨﻣا ﻊﻤﺠﻣﻴﺘﻲ ) ( � ﺖﻟﺎﺣ ﺎﻫيﻪﺘﺴﺑ لﺎﻘﺘﻧا ﺎﻫ AH � ESP � SA ﺎﻫ � ﺐﻴﻛﺮﺗ � ﺪﻴﻠﻛ ﺖﻳﺮﻳﺪﻣ ���� ���� ����� ���� ٢

  2. TCP/IP ﻪﻣﺪﻘﻣ - زاﻲﻟﺎﺜﻣ ���� ���� ����� ���� ٣ IPV4 ٤ Sharif Network Security Center

  3. ﻪﻣﺪﻘﻣ � دﺮﺑرﺎﻛ ﻪﺑ ﻪﺘﺴﺑاو ﻲﺘﻴﻨﻣا يﺎﻫ ﻞﺣ هار ) نﻮﻨﻛﺎﺗ ( PGP S/MIME � : ﻲﻜﻴﻧوﺮﺘﻜﻟا ﺖﺴﭘ ﺖﻴﻨﻣا و Kerberos � : ﺮﺑرﺎﻛ ﻦﻴﺑ ﺖﻴﻨﻣا - راﺰﮔرﺎﻛ ) زاﺮﺣاﺖﻳﻮﻫ ( SSL � : دﺎﺠﻳا ﻚﻳردﻦﻣا لﺎﻧﺎﻛ بو IP � ﺢﻄﺳ رد ﺖﻴﻨﻣا ﻪﺑ زﺎﻴﻧ IP � يﺎﻫ ﻪﺘﺴﺑ ياﻮﺘﺤﻣ ﻲﮕﻧﺎﻣﺮﺤﻣ � ﺎﻫ ﻪﺘﺴﺑ هﺪﻧﺮﻴﮔ وهﺪﻨﺘﺳﺮﻓ ﻲﺳﺎﻨﺷ ﺖﻳﻮﻫ ���� ���� ����� ���� ٥ ﻪﻣﺪﻘﻣ IPSec � زا يا ﻪﻋﻮﻤﺠﻣ ﻪﻜﻠﺑ ﺖﺴﻴﻧ ﺎﻬﻨﺗ ﻞﻜﺗوﺮﭘ ﻚﻳ يﺎﻬﻤﺘﻳرﻮﮕﻟا ﻚﻤﻛ ﻪﺑ ﻪﻛ ﺪﻨﻛ ﻲﻣ ﻢﻫاﺮﻓ ﻲﻠﻛ ﻲﺑﻮﭼرﺎﭼ وﻲﺘﻴﻨﻣا دﺮﻛ راﺮﻗﺮﺑ ﻲﻨﻣا طﺎﺒﺗرا نآ . IPSec � ﻂﺳﻮﺗ هﺪﺷ ﻢﻫاﺮﻓ ﻲﺘﻴﻨﻣا يﺎﻬﺴﻳوﺮﺳ � ﺳﺎﻨﺷ ﺖﻳﻮﻫﻲ ) ﺎﻫهداد ﺖﻴﻌﻣﺎﺟ لﺮﺘﻨﻛ هاﺮﻤﻫ ﻪﺑ ( � ﺎﻫ ﻪﺘﺴﺑ ﻲﮕﻧﺎﻣﺮﺤﻣ � ﺪﻴﻠﻛ ﺖﻳﺮﻳﺪﻣ ) ﺪﻴﻠﻛ ﻦﻣا لدﺎﺒﺗ ( ���� ���� ����� ���� ٦

  4. ﻪﻣﺪﻘﻣ IPSec � يﺎﻫدﺮﺑرﺎﻛ ﻪﻧﻮﻤﻧ VPN � دﺎﺠﻳا ياﺮﺑ يﺎﻫ ﻪﺒﻌﺷ ﺖﻧﺮﺘﻨﻳا ﻖﻳﺮﻃ زا نﺎﻣزﺎﺳ ﻚﻳ ﻒﻠﺘﺨﻣ � ﻖﻳﺮﻃ زا ﻪﻜﺒﺷ ﻊﺑﺎﻨﻣ ﻪﺑ ﺖﻛﺮﺷ ناﺪﻨﻣرﺎﻛ ﻦﻣا ﻲﺳﺮﺘﺳد ﺖﻧﺮﺘﻨﻳا � نﺎﻣزﺎﺳ ﺪﻨﭼ ﻦﻴﺑ ﻦﻣا طﺎﺒﺗرا نﺎﻜﻣا � ﺑﻪياﺮﺑ ﻲﺘﻴﻨﻣا تﺎﻣﺪﺧ ندروآ دﻮﺟو ﺎﻫدﺮﺑرﺎﻛ ﺮﮕﻳد ي ) ترﺎﺠﺗ ﻞﺜﻣ ﻚﻴﻧوﺮﺘﻜﻟا ( ���� ���� ����� ���� ٧ IPSec ٨ Sharif Network Security Center

  5. ﻪﻣﺪﻘﻣ IPSec � زا هدﺎﻔﺘﺳا يﺎﻳاﺰﻣ LAN � جرﺎﺧ وﻞﺧاد ﻦﻴﺑ يﻮﻗ ﺖﻴﻨﻣا ﻦﻴﻣﺎﺗ رد يﺮﻴﮔرﺎﻜﺑ ترﻮﺻ رد Firewall ﺎﻫ ( وﺎﻬﺑﺎﻴﻫار ظﺎﻔﺣ ﺎﻫ ) � ﻲﻳﺎﻬﺘﻧا طﺎﻘﻧ رد يرﺎﮕﻧﺰﻣر رﺎﺑﺮﺳ مﺪﻋ � ناﺮﺑرﺎﻛ ﺮﻈﻧ زا ﺖﻴﻓﺎﻔﺷ � ﺮﺗﻻﺎﺑ يﺎﻫ ﻪﻳﻻ يدﺮﺑرﺎﻛ يﺎﻫ ﻪﻣﺎﻧﺮﺑ ﺪﻳد زا ﺖﻴﻓﺎﻔﺷ � ﺧاد ﻪﺑ جرﺎﺧ زا نﺎﻣزﺎﺳ نﺎﻨﻛرﺎﻛ ﻦﻴﺑ ﻦﻣا طﺎﺒﺗرا دﺎﺠﻳا ﻞ ���� ���� ����� ���� ٩ رﺎﻤﻌﻣي :IPSec ﺎﻬﻴﮔﮋﻳو � ﺎﻬﻴﮔﮋﻳو � ﻞﻜﺸﻣ ﺎﺘﺒﺴﻧ ﻒﻴﺻﻮﺗ ياراد IPv4 IPv6 رد يرﺎﻴﺘﺧا و � رد ﻲﻣاﺰﻟا � ﺮﻳز دراﻮﻣ ﻦﺘﻓﺮﮔﺮﺑ رد : IP هدﺎﻴﭘ Header IPSec ﺪﻨﻳآﺮﺳ رد ) � ﻞﻜﺗوﺮﭘ ( ﻲﻠﺻا ﺪﻨﻳآﺮﺳ زا ﺪﻌﺑ وﻪﺘﻓﺎﻳ ﻪﻌﺳﻮﺗ يﺎﻫ دﻮﺷ ﻲﻣ يزﺎﺳ IPSec ﺖﺳا هﺪﺷ يﺪﻨﺑ ﻪﺘﺳد ﺮﻳز ترﻮﺻ ﻪﺑ وهدﻮﺑ ﻢﻴﺠﺣ رﺎﻴﺴﺑ : � تاﺪﺘﺴﻣ Architecture � (ESP) Encapsulating Security Payload : يرﺎﮕﻧﺰﻣر � ﺎﻫ ﻪﺘﺴﺑ ) يرﺎﻴﺘﺧا ترﻮﺻ ﻪﺑ ﺖﻳﻮﻫ زاﺮﺣا ( � (AH) Authentication Header : ﺎﻫﻪﺘﺴﺑ ﺖﻳﻮﻫ ﺺﻴﺨﺸﺗ � ﺪﻴﻠﻛ ﺖﻳﺮﻳﺪﻣ : ﺎﻫﺪﻴﻠﻛ ﻦﻣا لدﺎﺒﺗ � ﻢﺘﻳرﻮﮕﻟا ﺖﻳﻮﻫ ويرﺎﮕﻧﺰﻣر يﺎﻫ ﻲﺳﺎﻨﺷ ���� ���� ����� ���� ١٠

  6. رﺎﻤﻌﻣي :IPSec ﺎﻫﺲﻳوﺮﺳ IPSec � هﺪﺷ ﻪﺋارا يﺎﻫ ﺲﻳوﺮﺳ : ﻲﻣ ﺎﻬﻤﺘﺴﻴﺳ ﻪﺑ ار نﺎﻜﻣا ﻦﻳا ﺎﻬﻠﻜﺗوﺮﭘ ﺎﺗ ﺪﻫد،يﺎﻬﺴﻳوﺮﺳ ﻪﺋارا ياﺮﺑ مزﻻ يﺎﻫﺪﻴﻠﻛ وﺎﻬﻤﺘﻳرﻮﮕﻟا ﺪﻨﻨﻛ بﺎﺨﺘﻧا ار ﺮﻳز � ﻲﺳﺮﺘﺳد لﺮﺘﻨﻛ Connectionless � ﻤﻀﺗﻴﻦردﺎﻫ هداد ﺖﻴﻣﺎﻤﺗ طﺎﺒﺗرا Data Origin � ﺎﻫ هداد ﻊﺒﻨﻣ ﺖﻳﻮﻫ زاﺮﺣا ) ( Replay � ﺨﺸﺗﻴﺺهﺪﺷ لﺎﺳرا هرﺎﺑود يﺎﻫ ﻪﺘﺴﺑ ﺎﻬﻧآ در و ) Attack ( � ﻲﮕﻧﺎﻣﺮﺤﻣﻪﺘﺴﺑ ﺎﻫ � ﻚﻴﻓاﺮﺗ نﺎﻳﺮﺟ ﻲﮕﻧﺎﻣﺮﺤﻣ ���� ���� ����� ���� ١١ رﺎﻤﻌﻣي :IPSec ﺎﻫﺲﻳوﺮﺳ ١٢ Sharif Network Security Center

  7. رﺎﻤﻌﻣي :IPSec Association Security Security Association � ﻒﻳﺮﻌﺗ : ﻲﺘﻴﻨﻣا ﻊﻤﺠﻣ ) ( ﻚﻳمﻮﻬﻔﻣ IP ﻪﻄﺑار ﻚﻳ وهدﻮﺑ ياﺮﺑ ﻲﮕﻧﺎﻣﺮﺤﻣ وﺖﻳﻮﻫ زاﺮﺣا يﺎﻬﻣﺰﻴﻧﺎﻜﻣ رد يﺪﻴﻠﻛ ﻚﻳﻪﻓﺮﻃ ﺪﻨﻛ ﻲﻣ دﺎﺠﻳا ﻪﺘﺴﺑ هﺪﻧﺮﻴﮔ وهﺪﻨﺘﺳﺮﻓ ﻦﻴﺑ . TCP ﺖﺳا Connection IP لدﺎﻌﻣ ﻲﻋﻮﻧ ﻪﺑ SA � رد رد ���� ���� ����� ���� ١٣ رﺎﻤﻌﻣي :IPSec Association Security ﺎﻬﻴﮔﮋﻳو : SA ﺎﺑﺎﺘﻜﻳ ترﻮﺼﺑ 3 دﻮﺷ ﻲﻣ ﻦﻴﻴﻌﺗ ﺮﺘﻣارﺎﭘ : � ﻚﻳ SPI Security Parameters Index � : ﻲﺘﻴﺑ ﻪﺘﺷر ﻚﻳ ( ) SA ﻪﺑهﺪﺷ هداد ﺖﺒﺴﻧ SA IP Destination Address : ﻲﻳﺎﻬﻧ ﺪﺼﻘﻣ سردآ � AH ﺎﻳ SA ﻪﺑ Security Protocol Identifier � : ﻖﻠﻌﺗ ﺮﮕﻧﺎﻴﺑ ESP ���� ���� ����� ���� ١٤

  8. رﺎﻤﻌﻣي :IPSec Association Security SA � ���������� Sequence Number Counter � Sequence Counter Overflow � Anti Replay Windows � AH Information � ESP Information � SA Lifetime � IPSec Protocol Mode � Maximum Transmission Unit � ���� ���� ����� ���� ١٥ رﺎﻤﻌﻣي :IPSec ﺎﻬﺘﻟﺎﺣ يﻪﺘﺴﺑ لﺎﻘﺘﻧا ﺎﻫ ESP AH و � ﺮﻫ رديود دراد دﻮﺟو لﺎﻘﺘﻧا ﺖﻟﺎﺣ ود : � لﺎﻘﺘﻧا ﺖﻟﺎﺣ (Transport Mode) IP � دﺮﻴﮔ ﻲﻣ ترﻮﺻ ﻪﺘﺴﺑ ياﻮﺘﺤﻣ يور ﺎﻬﻨﺗ تاﺮﻴﻴﻐﺗ،ﺪﻨﻳآﺮﺳ ﺮﻴﻴﻐﺗ نوﺪﺑ � ﻞﻧﻮﺗ ﺖﻟﺎﺣ (Tunnel Mode) Payload IP ( وندﺎﺘﺳﺮﻓ ﻪﺑﻪﺠﻴﺘﻧ ) ﺪﻨﻳآﺮﺳ + � ﻪﺘﺴﺑ ﻞﻛ يور تاﺮﻴﻴﻐﺗ لﺎﻤﻋا ﺪﻳﺪﺟ ﻪﺘﺴﺑ ﻚﻳ ناﻮﻨﻋ ���� ���� ����� ���� ١٦

  9. رﺎﻤﻌﻣي :IPSec ﺎﻬﺘﻟﺎﺣ يﻪﺘﺴﺑ لﺎﻘﺘﻧا ﺎﻫ � لﺎﻘﺘﻧا ﺖﻟﺎﺣ end-to-end � يﺎﻫدﺮﺑرﺎﻛ رد ﺎﻬﺘﻧا ﻪﺑ ﺎﻬﺘﻧا ) ( راﺰﮔرﺎﻛ ﻞﺜﻣ / رﺎﻛ هدﺎﻔﺘﺳا ﺎﻣﺮﻓ ﻣﻲدﻮﺷ Payload ESP � : يرﺎﮕﻧﺰﻣر ) يروﺮﺿ ( ﻲﺳﺎﻨﺷ ﺖﻳﻮﻫ و ) ايرﺎﻴﺘﺧ ( ﻪﺘﺴﺑ Payload AH � ﺪﺷ بﺎﺨﺘﻧا يﺎﻬﺘﻤﺴﻗ وﻪﺘﺴﺑ هﺪﻨﻳآﺮﺳ : ﻲﺳﺎﻨﺷ ﺖﻳﻮﻫ ﻪﺘﺴﺑ ���� ���� ����� ���� ١٧ رﺎﻤﻌﻣي :IPSec ������ ������ � ������ � ﻞﻧﻮﺗ ﺖﻟﺎﺣ Gateway Gateway � رد هدﺎﻔﺘﺳا درﻮﻣ طﺎﺒﺗرا ﻪﺑ router � ﭻﻴﻫﺴﻣﻴﺮﻳبﺎ ) ( ﻲﻠﺧاد ﺪﻨﻳآﺮﺳ ﺺﻴﺨﺸﺗ ﻪﺑ ردﺎﻗ ﻲﻧﺎﻴﻣ ﺖﺴﻴﻧ ���� ���� ����� ���� ١٨

  10. Functionality of Modes ١٩ Sharif Network Security Center Authentication Header (AH) Authentication Header � IP � يﺎﻫ ﻪﺘﺴﺑ ﺖﻳﻮﻫ زاﺮﺣا وﺖﻴﻣﺎﻤﺗ ﻦﻴﻤﻀﺗ MAC � ﺖﻴﻣﺎﻤﺗ ﺲﻳوﺮﺳ ﻦﻴﻣﺎﺗ هداد ﺎﻫزاهدﺎﻔﺘﺳا ﺎﺑ HMAC-SHA-1-96 HMAC-MD5-96 ﺎﻳ � � ﻚﻳ يور ﻖﻓاﻮﺗ ﻪﺑ زﺎﻴﻧ ﻦﻴﻓﺮﻃ ﻠﻛﻴﺪكﺮﺘﺸﻣ نرﺎﻘﺘﻣ ﺪﻧراد ���� ���� ����� ���� ٢٠

Download Presentation
Download Policy: The content available on the website is offered to you 'AS IS' for your personal information and use only. It cannot be commercialized, licensed, or distributed on other websites without prior consent from the author. To download a presentation, simply click this link. If you encounter any difficulties during the download process, it's possible that the publisher has removed the file from their server.

Recommend


More recommend