NETGEAR VPN 产品配置手册 2004 目录一.NETGEAR VPN防火墙产品介绍.................................................................... 41. 1 常用的VPN技术..................................................................................................................41. 2 关于动态域名(Dynami c Domai n Name Ser vi ce)........................................................41. 3 Net gear VPN设备的应用...................................................................................................4二.Net gear VPN 设备配置指南....................................................................... 62.1 FVS318 to FVS318(网关到网关 IKE Main 模式) ............................................................72.1.1 配置网关 A 静态的 VPN(MAIN 模式) ......................................................................72.1.2 配置网关 B 静态的 VPN(MAIN 模式) ....................................................................112. 2 Remot e t o FVS318(客户端到网关 I KE Mai n / Aggr essi ve模式).........................152.2.1 用 Main 模式建立 Remot-to-LAN 的 VPN ...................................................................162. 2. 2 用Aggr essi ve 模式建立Remot e- t o- LAN 的VPN...................................................212. 3 Remot e t o FQDN FVS318 ( I KE Mai n模式网关为动态I P地址)...................................282.3.1 配置 FVS318 的动态 VPN(Main 模式)....................................................................282.3.2 配置远程客户端动态的 VPN(Main 模式)...............................................................322.4 FVL328 to FVL328(网关到网关 IKE Main 模式)..........................................................332.4.1 配置网关 A 固定 IP 地址的 VPN(MAIN 模式) ......................................................342.4.2 配置网关 B 固定 IP 的 VPN(Main 模式) .................................................................382. 5 Remot e t o FVL328(客户端到网关 Aggr essi ve模式)...............................................442.5.1 配置 FVL328 的远程接入 VPN(Aggressive 模式) ..................................................442. 5. 2 配置远程客户端的静态VPN(Aggr essi ve模式)。..............................................492. 6 Remot e t o FQDN FVL328( I KE Aggr ess模式网关为动态I P)........................................542.6.1 配置 FVL328 的动态的(Aggressive 模式)VPN。 ...................................................542.6.2 配置远程客户端的动态的 VPN(Aggressive 模式) .................................................572. 7 FVS318 t o FVL328(网关到网关 I KE Mai n模式).......................................................582.7.1 配置 FVS318 的静态 VPN(MAIN 模式).......................................................................582.7.2 配置 FVL328 固定 IP 的 VPN(Main 模式)。 ..........................................................622. 8 FQDN FVS318 t o FVL328(网关到网关 I KE Mai n/ Aggr essi ve模式).......................682. 8. 1 I KE Mai n模式网关到网关的VPN配置.....................................................................682.8.2 I KE Aggr essi ve模式网关到网关的VPN配置...........................................................74三.常用 VPN 专业述语............................................................................... 773.1 IPsec 简介 ..............................................................................................................................773.2 Internet 密钥交换协议(IKE) .................................................................................................773. 2. 1 I KE 协商......................................................................................................................773.2.2 IKE 协议 .........................................................................................................................783.2.3 IKE 阶段 1 - IKE 安全协商 ...........................................................................................783.2.4 IKE 阶段 2 - IPsec 安全协商 .........................................................................................783.2.4 IKE 参数 .........................................................................................................................793.3 IKE 认证方法(手工,PSK,证书) .................................................................................823.3.1 手工密钥 .........................................................................................................................823.3.2 Pre-Shared 密钥, PSK .....................................................................................................823.3.3 证书 .................................................................................................................................82 http://www.NETGEAR.com.cn - 2 -