Netgear fwag114 참조 매뉴얼

다운로드
페이지 192
Reference Manual for the ProSafe Dual Band Wireless VPN Firewall FWAG114
E-2
Virtual Private Networking
 
Intranets: Intranets connect an organization’s locations. These locations range from the 
headquarters offices, to branch offices, to a remote employee’s home. Often this connectivity 
is used for e-mail and for sharing applications and files. While Frame Relay, ATM, and MPLS 
accomplish these tasks, the shortcomings of each limits connectivity. The cost of connecting 
home users is also very expensive compared to Internet-access technologies, such as DSL or 
cable. Because of this, organizations are moving their networks to the Internet, which is 
inexpensive, and using IPSec to create these networks.
Remote Access: Remote access enables telecommuters and mobile workers to access e-mail 
and business applications. A dial-up connection to an organization’s modem pool is one 
method of access for remote workers, but is expensive because the organization must pay the 
associated long distance telephone and service costs. Remote access VPNs greatly reduce 
expenses by enabling mobile workers to dial a local Internet connection and then set up a 
secure IPSec-based VPN communications to their organization.
Extranets: Extranets are secure connections between two or more organizations. Common 
uses for extranets include supply-chain management, development partnerships, and 
subscription services. These undertakings can be difficult using legacy network technologies 
due to connection costs, time delays, and access availability. IPSec-based VPNs are ideal for 
extranet connections. IPSec-capable devices can be quickly and inexpensively installed on 
existing Internet connections.
What Is IPSec and How Does It Work?
IPSec is an Internet Engineering Task Force (IETF) standard suite of protocols that provides data 
authentication, integrity, and confidentiality as data is transferred between communication points 
across IP networks. IPSec provides data security at the IP packet level. A packet is a data bundle 
that is organized for transmission across a network, and includes a header and payload (the data in 
the packet). IPSec emerged as a viable network security standard because enterprises wanted to 
ensure that data could be securely transmitted over the Internet. IPSec protects against possible 
security exposures by protecting data while in while in transit.
IPSec Security Features
IPSec is the most secure method commercially available for connecting network sites. IPSec was 
designed to provide the following security features when transferring packets across networks:
Authentication: Verifies that the packet received is actually from the claimed sender.
Integrity: Ensures that the contents of the packet did not change in transit.