IPSec VPN Design (Paperback)
暫譯: IPSec VPN 設計 (平裝本)

Vijay Bollapragada, Mohamed Khalid, Scott Wainner

  • 出版商: Cisco Press
  • 出版日期: 2005-04-01
  • 售價: $2,630
  • 貴賓價: 9.5$2,499
  • 語言: 英文
  • 頁數: 384
  • 裝訂: Paperback
  • ISBN: 1587051117
  • ISBN-13: 9781587051111
  • 已絕版

買這商品的人也買了...

商品描述

Description:

 

The definitive design and deployment guide for secure virtual private networks

  • Learn about IPSec protocols and Cisco IOS IPSec packet processing
  • Understand the differences between IPSec tunnel mode and transport mode
  • Evaluate the IPSec features that improve VPN scalability and fault tolerance, such as dead peer detection and control plane keepalives
  • Overcome the challenges of working with NAT and PMTUD
  • Explore IPSec remote-access features, including extended authentication, mode-configuration, and digital certificates
  • Examine the pros and cons of various IPSec connection models such as native IPSec, GRE, and remote access
  • Apply fault tolerance methods to IPSec VPN designs
  • Employ mechanisms to alleviate the configuration complexity of a large- scale IPSec VPN, including Tunnel End-Point Discovery (TED) and Dynamic Multipoint VPNs (DMVPN)
  • Add services to IPSec VPNs, including voice and multicast
  • Understand how network-based VPNs operate and how to integrate IPSec VPNs with MPLS VPNs

Among the many functions that networking technologies permit is the ability for organizations to easily and securely communicate with branch offices, mobile users, telecommuters, and business partners. Such connectivity is now vital to maintaining a competitive level of business productivity. Although several technologies exist that can enable interconnectivity among business sites, Internet-based virtual private networks (VPNs) have evolved as the most effective means to link corporate network resources to remote employees, offices, and mobile workers. VPNs provide productivity enhancements, efficient and convenient remote access to network resources, site-to-site connectivity, a high level of security, and tremendous cost savings.

 

IPSec VPN Design is the first book to present a detailed examination of the design aspects of IPSec protocols that enable secure VPN communication. Divided into three parts, the book provides a solid understanding of design and architectural issues of large-scale, secure VPN solutions. Part I includes a comprehensive introduction to the general architecture of IPSec, including its protocols and Cisco IOS® IPSec implementation details. Part II examines IPSec VPN design principles covering hub-and-spoke, full-mesh, and fault-tolerant designs. This part of the book also covers dynamic configuration models used to simplify IPSec VPN designs. Part III addresses design issues in adding services to an IPSec VPN such as voice and multicast. This part of the book also shows you how to effectively integrate IPSec VPNs with MPLS VPNs.

 

IPSec VPN Design provides you with the field-tested design and configuration advice to help you deploy an effective and secure VPN solution in any environment.

 

This security book is part of the Cisco Press® Networking Technology Series. Security titles from Cisco Press help networking professionals secure critical data and resources, prevent and mitigate network attacks, and build end-to-end self-defending networks.

 

 

 

商品描述(中文翻譯)

**描述:**

這是一本關於安全虛擬私人網路的設計與部署指南。

- 了解 IPSec 協議和 Cisco IOS IPSec 封包處理
- 理解 IPSec 隧道模式和傳輸模式之間的差異
- 評估改善 VPN 可擴展性和容錯性的 IPSec 特性,例如死對等檢測和控制平面保持連接
- 克服與 NAT 和 PMTUD 相關的挑戰
- 探索 IPSec 遠端存取功能,包括擴展身份驗證、模式配置和數位證書
- 檢視各種 IPSec 連接模型的優缺點,例如原生 IPSec、GRE 和遠端存取
- 將容錯方法應用於 IPSec VPN 設計
- 採用機制來減輕大型 IPSec VPN 的配置複雜性,包括隧道端點發現 (TED) 和動態多點 VPN (DMVPN)
- 為 IPSec VPN 添加服務,包括語音和多播
- 理解基於網路的 VPN 如何運作,以及如何將 IPSec VPN 與 MPLS VPN 整合

在網路技術所允許的眾多功能中,組織能夠輕鬆且安全地與分支辦公室、行動用戶、遠端工作者和商業夥伴進行通信。這種連接對於維持競爭力的商業生產力至關重要。雖然存在幾種技術可以實現商業地點之間的互連,但基於互聯網的虛擬私人網路 (VPN) 已發展為將企業網路資源連接到遠端員工、辦公室和行動工作者的最有效手段。VPN 提供生產力提升、高效且方便的遠端存取網路資源、站點對站點的連接、高度的安全性以及巨大的成本節省。

《IPSec VPN 設計》是第一本詳細檢視 IPSec 協議設計方面的書籍,這些協議使安全的 VPN 通信成為可能。本書分為三個部分,提供對大型安全 VPN 解決方案的設計和架構問題的深入理解。第一部分包括對 IPSec 一般架構的全面介紹,包括其協議和 Cisco IOS® IPSec 實作細節。第二部分檢視 IPSec VPN 設計原則,涵蓋中心-輻射、全網狀和容錯設計。本書的這一部分還涵蓋了用於簡化 IPSec VPN 設計的動態配置模型。第三部分探討在 IPSec VPN 中添加服務(如語音和多播)的設計問題。這一部分還展示了如何有效地將 IPSec VPN 與 MPLS VPN 整合。

《IPSec VPN 設計》為您提供經過實地測試的設計和配置建議,幫助您在任何環境中部署有效且安全的 VPN 解決方案。

這本安全書籍是 Cisco Press® 網路技術系列的一部分。Cisco Press 的安全書籍幫助網路專業人員保護關鍵數據和資源,防止和減輕網路攻擊,並建立端到端的自我防禦網路。

最後瀏覽商品 (20)