Cisco 1800¡B2800 ©M3800 ¶°¦¨¦h·~°È¸ô¥Ñ¾¹ªº¦w¥þ¯S©Ê
²£«~·§z
«ä¬ì¨t²Î¤½¥q±À¥X¤F¤@Ó¥þ·sªº¶°¦¨¦h·~°È¸ô¥Ñ¾¹¨t¦C¼Ò²Õ¤ÆCisco? 1800¡B2800©M 3800¶°¦¨¦h·~°È¸ô¥Ñ¾¹§@¬°«ä¬ì¦Û¨¾¿mºô¸ôªºÃöÁ䳡¥ó¡A«ä¬ì¶°¦¨¦h·~°È¸ô¥Ñ¾¹¨Ï«È¤á¹ê²{¤F¸ô¥Ñ©M¦w¥þµ¦²¤ªº¦P¨B¡A¨Ã°§C¤F¹BÀ禨¥»¡A´£°ª¤F¾ãÓºô¸ôªº¦w¥þ¤ô·Ç¡C¾ÌÂÇ°ò©óCisco IOS? ³nÅ骺VPN¡B¨¾¤õÀð©MIPS¡A¥H¤Î¥i¿ï¼W±jVPN¥[³t¡B¤J«IÀË´ú¨t²Î¡]IDS¡^©M¤º®e¤ÞÀººô¸ô¼Ò²Õ (Cisco 2800 ©M3800¨t¦C)¡A«ä¬ì¬°¤À¤ä¾÷·p¸ô¥Ñ¾¹´£¨Ñ¤F·~¬É³Ì±j¤j¡B¥i¾AÀ³ªº¦w¥þ¸Ñ¨M¤è®×¡C
³q¹L±N¦¨¼ôªºCisco IOS¥\¯à©M·~¬É»â¥ýªºLAN/WAN³s±µ»P¥@¬É¤@¬yªº¦w¥þ¯S©Ê¬Ûµ²¦X¡A¶°¦¨¤Æ¦w¥þ¸Ñ¨M¤è®×¬°«È¤á´£¨Ñ¤F¤U¦CÀu¶Õ¡G
· “§Q¥Î²{¦³³]¬I” -- §Q¥Î²{¦³ºô¸ô°ò¦³]¬I¡A¦b¸ô¥Ñ¾¹¤W³q¹LCisco IOS¤ä«ù¥þ·s¦w¥þ¯S©Ê¡AµL»Ý³¡¸pÃB¥~ªºµwÅé
· “¦b³Ì»Ýnªº¦a¤è³¡¸p¦w¥þ¯S©Ê” -- ¬°¦bºô¸ô¥ô·N¦aÂI±Ä¥Î¨¾¤õÀð¡BIPS©MVPNµ¥¦w¥þ¥\¯à´£¨Ñ¤FÆF¬¡©Ê, ±q¦Ó³Ì¤j«×¦aµo´§¤F¦w¥þÀu¶Õ
· “«OÅ@±zªº¹h¹D” -- ¦bºô¸ô©Ò¦³ªº¤JÂI³¡¸p³Ì¨Î¦w¥þ¥\¯à
· “¸`¬Ù®É¶¡©M¸êª÷” -- ´î¤Ö¤F³]³Æ¼Æ¶q¡A°§C¤F°ö°V©MºÞ²z¦¨¥»
· “«OÅ@±zªº°ò¦³]¬I” -- «OÅ@¤F¸ô¥Ñ¾¹¡A¥i¥H¨¾¿mª½±µ°w¹ïºô¸ô°ò¦³]¬Iªº§ðÀ»¡A¦pDDoS
«ä¬ì¦Û¨¾¿mºô¸ô
Cisco 1800¡B2800©M3800¸ô¥Ñ¾¹¤ä«ù§@¬°ÄÝ©ó«ä¬ì¦Û¨¾¿mºô¸ôªº¤º®e¼sªxªº¦w¥þ¯S©Ê¡A³oºØ¦w¥þµ¦²¤¨Ï¤½¥q¥iÃѧO¡B¨¾¤î©M¾AÀ³¦w¥þ«Â¯Ù¡C«ä¬ì¦Û¨¾¿mºô¸ô¾Ö¦³¥|Ãþ¾A¥Î¤_¸ô¥Ñ¾¹ªº«OÅ@±¹¬I¡G
· ¦w¥þ³s±µ -- ´£¨Ñ¤F¦w¥þ¡B¥iÂX®iªººô¸ô³s±µ¡A®e¯Ç¤F¦hºØ¬y¶qÃþ«¬¡A¦pVPN¡B °ÊºA¦hÂI VPN (DMVPN) ¡B¦hVRF©MMPLS ¦w¥þÀô¹Ò¡B ¸Üµ©MµøÀW«¬VPN (V3PN) ¡A¥H¤Î¦w¥þ¸Üµ¡C
· «Â¯Ù¨¾¿m -- §Q¥Îºô¸ôªA°È¥i¥H¹w¨¾©M¦^À³ºô¸ô§ðÀ»©M«Â¯Ù¡C¥]¬Aºô¸ô¤J«I¨¾¿m¨t²Î¡]IPS¡^©MCisco IOS¨¾¤õÀð ¡C
· «H¥ô©M¨¥÷ -- ¤¹³\ºô¸ô§Q¥Îºô¸ôã¤J±±¨î (NAC) ¡B¨¥÷ªA°È©MAAAµ¥§Þ³N´¼¼z¦a«OÅ@²×ºÝ¡C
· ºô¸ô°ò¦³]¬I«OÅ@ -- «OÅ@ºô¸ô§K¨ü§ðÀ»©Mº|¬}ªº¼vÅT¡A¤×¨ä¦bºô¸ô¯Å§O¡C¥]¬A±±¨î±ªOºÊºÞ¡B°ò©óºô¸ôªºÀ³¥ÎÃѧO¡]NBAR¡^ ©MAutoSecure¡C
¶°¦¨¦h·~°È¸ô¥Ñ¾¹¯S©Ê
¬°¦³§U©ó¹ê²{Cisco 1800¡B2800©M3800¨t¦C¤Wªº¦w¥þ¯S©Ê¡A°t³Æ¤F¤U¦CCisco IOS³nÅé¯S©Ê¶°¡G
· Advanced Enterprise Service (°ª¯Å¥ø·~ªA°È)
· Advanced IP Services (°ª¯ÅIPªA°È)
· Advanced Security (°ª¯Å¦w¥þ¯S©Ê)
¤º´OªA°ÈºÞ²z¡G«ä¬ì¸ô¥Ñ¾¹©M¦w¥þ³]³ÆºÞ²z¾¹(SDM)
«ä¬ì¸ô¥Ñ¾¹©M¦w¥þ³]³ÆºÞ²z¾¹(SDM)
¨C¥xCisco 1800¡B2800©M3800³£±a¦³¦b¤u¼t¤¤¦w¸Ëªº«ä¬ì¸ô¥Ñ¾¹©M¦w¥þ³]³ÆºÞ²z¾¹(SDM) ¡CCisco SDM¬O¤@ºØª½Æ[ªº¡B°ò©óWebªº³]³Æ ºÞ²z¾¹(GUI)¡A¥Î©ó«ä¬ì¸ô¥Ñ¾¹ªº³¡¸p©MºÞ²z¡]Cisco SDM 2.0±N¸ô¥Ñ©M¦w¥þªA°ÈºÞ²z»P¨Ï¥Î¤è«Kªº´¼¼zÂQ¾É©M²`¤J±Æ»Ù¥\¯à¬Ûµ²¦X¡A¬°±NªA°È¶°¦¨¨ì¸ô¥Ñ¾¹¤§¤W¡B¥H±q¤¤Àò¯q¦Ó´£¨Ñ¤F¤ä´©¤u¨ã¡C¥Ø«e¡A«È¤á¥i¥H¦b¾ãÓºô¸ô¤º±N¸ô¥Ñ©M¦w¥þµ¦²¤¦P¨B¤Æ¡A¾Ö¦³§ó¥þ±ªº¸ô¥Ñ¾¹ªA°Èª¬ºA¬yÄý¯à¤O¡A¨Ã°§C¤F¹BÀ禨¥»¡CCisco SDM 2.0ªº¥þ·sÃöÁä¯S©Ê¥]¬A¡G
· ´O¤JªºIPS¡A¥i§ó·s¯S¼x©M©w¨î¯S¼x
· °ò©ó¨¤¦âªº¸ô¥Ñ¾¹±µ¤J
· Easy VPN¦øªA¾¹©MAAA
· ¥Î©óIPSec VPNªº¼Æ¦ìÃÒ®Ñ
· VPN©MWAN³s±µ±Æ»Ù
· QoSµ¦²¤°t¸m©M°ò©óNBARªºÀ³¥Î¬y¶qºÊ±±
|
ªí1Cisco 1800¡B2800 ©M3800ªº¥Dn¦w¥þ¯S©Ê©MÀu¶Õ |
|
|
|
¯S©Ê |
Àu¶Õ |
¦w¥þ³s±µ |
¨CÓ¶°¦¨¦h·~°È¸ô¥Ñ¾¹ªº¤º¸mVPN¥[±K¥[³t¥\¯à |
„h ¸Ó¯S©Ê¤ä´©IPSec DES, 3DES©MAES 128, 192¤Î256¥[±K¡AµL»Ý¦û¥Î AIM´¡¼Ñ |
°ò©óAIMªº¦w¥þ¥[³t |
„h ¤ä´©¥i¿ï¡B±M¥Î¦w¥þAIM¡A¥i¥H´£¨Ñ§ó°ª©Ê¯à¡B¥iÂX®i©Ê©M²Ä¤T¼h IPPCPÀ£ÁY |
¦h¨ó©w¼ÐÅҥ洫(MPLS) VPN ¤ä«ù |
„h °w¹ï¤À¤ä¾÷·pÀu¤Æªº«È¤áÃä½t(CE)¥\¯à¡A¥H¤Î§Q¥Î¦hVRF·Pª¾¨¾¤õÀð©MIPSec±N«È¤áMPLS VPNºô¸ôÂX®i¦ÜCEªº¾÷¨î¡C |
¦hVRF©MMPLS¦w¥þÀô¹Ò |
„h ¦b¤À¤ä¾÷·p¤ä«ù¦hÓ¿W¥ßÀô¹Ò¡]½s§}¡B¸ô¥Ñ©M¤¶±¡^¡A¥H¹jÂ÷³¡ªù¡B¤l¤½¥q©Î«È¤á¡C |
Cisco Easy VPN »·ºÝ©M¦øªA¾¹¤ä´© |
„h ¸Ó¯S©Ê¥i±N¥þ·s¦w¥þµ¦²¤±q³æ¤@ÀYºÝ±À¼s¦Ü»·ºÝ¦aÂI¡A±q¦Ó²¤Æ¤FÂI¨ìÂIVPNºÞ²z¡C |
V3PN |
„h ¦bVPN¤W¥i¬°¥ô·N¦aÂI´£¨Ñ¸gÀÙ¦³®Äªº¶°¦¨¤Æ¸Üµ¡BµøÀW©M¸ê®Æ¥\¯à¡C |
DMVPN |
„h ´£¨Ñ¤F¤@ºØ¥iÂX®iªºÆF¬¡¤è¦¡¡A¨Ó«Ø¥ß¤À¤ä¾÷·p¶¡ªºµêÀÀ¥þºôª¬³s±µIPSecÀG¹D¡C²K¥[·s¤À¤ä®É¡A¤¤¤ß¦aÂIµL»Ý¶i¦æ°t¸m ¡C |
«Â¯Ù¨¾¿m |
Cisco IOS Firewall |
„h ¤@ºØ²z·Qªº³æ¾÷½c¦w¥þ©M¸ô¥Ñ¸Ñ¨M¤è®×¡A¥Î©ó«OÅ@ WANºô¸ô¤JÂI¡C¥Ø«e¡A°t³Æ¤FIPv6¤ä«ù¡C |
³z©ú¨¾¤õÀð |
„h ±N²{¦³ºô¸ô³¡¸p¹º¤À¦¨¦w¥þ«H¥ô°Ï¡AµL»Ý§ó§ï¦ì§}¡I ¤ä´©¤l¤¶±©MVLAN¤¤Ä~¡C¦P®É¤ä«ù³z©ú©ML3 FW¤ä«ù¡I |
¤J«I¨¾¿m |
„h ¤º´Oªº°ò©ó²`¼h¤À²ÕÀË´úªº¸Ñ¨M¤è®×¥i¥H»PCisco IOS ¦@¥Î¡A¥H«K¦³®Ä¦a½w¸Ñºô¸ô§ðÀ»¡C |
URL¹LÂo¡]¾÷½c¥~¡^ |
„h ®Ú¾Ú¦w¥þµ¦²¤¨¾¤î¥Î¤á±µ¤J¬Y¨ÇWeb¦aÂI¡C |
|
§Ú̯ണ¨Ñ¥H¤W²£«~¾ã¦X¡B¦w¸Ë©M¤ä´©ªA°È¡C
¦p¦³¥ô¦ó°ÝÃD©Î¬d¸ß¡AÅwªïP¹q 3422 8842¡A§Úַ̫ܼN¬°±z¸Ñµª°ÝÃD!
URL : www.ras.hk