²úÆ··ÖÀà+
L2TP»ù±¾ÔÀí
L2TP VPN¼ò½é
L2TP»ù±¾¸ÅÄ
L2TP£¨Layer 2 Tunneling Protocol£© VPNÊÇÒ»ÖÖÓÃÓÚ³ÐÔØPPP±¨ÎĵÄËíµÀ¼¼Êõ£¬¸Ã¼¼ÊõÖ÷ÒªÓ¦ÓÃÔÚÔ¶³Ì°ì¹«³¡¾°ÖÐΪ³ö²îÔ±¹¤Ô¶³Ì·ÃÎÊÆóÒµÄÚÍø×ÊÔ´Ìṩ½ÓÈë·þÎñ¡£
Ä¿µÄ£º
L2TP VPN¼¼Êõ³öÏÖÒÔºó£¬Ê¹ÓÃL2TP VPNËíµÀ¡°³ÐÔØ¡±PPP±¨ÎÄÔÚInternetÉÏ´«Êä³ÉΪÁ˽â¾öÉÏÊöÎÊÌâµÄÒ»ÖÖ;¾¶¡£ÎÞÂÛ³ö²îÔ±¹¤ÊÇͨ¹ý´«Í³²¦ºÅ·½Ê½½ÓÈëInternet£¬»¹ÊÇͨ¹ýÒÔÌ«Íø·½Ê½½ÓÈëInternet£¬L2TP VPN¶¼¿ÉÒÔÏòÆäÌṩԶ³Ì½ÓÈë·þÎñ¡£
L2TP VPNµÄÓŵ㣺
Éí·ÝÑéÖ¤»úÖÆ
Ö§³Ö±¾µØÈÏÖ¤¡£
Ö§³ÖRadius·þÎñÆ÷µÈÈÏÖ¤·½Ê½
¶àÐÒé´«Êä
L2TP´«ÊäPPPÊý¾Ý°ü£¬PPP±¾Éí¿ÉÒÔ´«Êä¶àÐÒ飬¶ø²»½ö½öÊÇIP¿ÉÒÔÔÚPPPÊý¾Ý°üÄÚ·â×°¶àÖÖÐÒé
¼Æ·ÑÈÏÖ¤µØÖ··ÖÅä
¿ÉÔÚLACºÍLNSÁ½´¦Í¬Ê±¼Æ·Ñ£¬¼´ISP´¦£¨ÓÃÓÚ²úÉúÕ˵¥£©¼°ÆóÒµÍø¹Ø£¨ÓÃÓÚ¸¶·Ñ¼°É󼯣©¡£L2TPÄܹ»ÌṩÊý¾Ý´«ÊäµÄ³öÈë°üÊý¡¢×Ö½ÚÊýÒÔ¼°Á¬½ÓµÄÆðʼ¡¢½áÊøÊ±¼äµÈ¼Æ·ÑÊý¾Ý£¬¿É¸ù¾ÝÕâЩÊý¾Ý·½±ãµØ½øÐÐÍøÂç¼Æ·Ñ
LNS¿É·ÅÖÃÓÚÆóÒµÍøµÄUSGÖ®ºó£¬¶ÔÔ¶¶ËÓû§µØÖ·½øÐж¯Ì¬·ÖÅäºÍ¹ÜÀí£¬¿ÉÖ§³Ö˽ÓеØÖ·Ó¦ÓÃ
²»ÊÜNATÏÞÖÆ´©Ô½
Ö§³ÖÔ¶³Ì½ÓÈë
Áé»îµÄÉí·ÝÑéÖ¤¼°Ê±ÒÔ¼°¸ß¶ÈµÄ°²È«ÐÔ
L2TPÐÒé±¾Éí²¢²»ÌṩÁ¬½ÓµÄ°²È«ÐÔ£¬µ«Ëü¿ÉÒÔÒÀÀµÓÚPPPÌṩµÄÈÏÖ¤£¨CHAP¡¢PAPµÈ£©£¬Òò´Ë¾ßÓÐPPËù¾ßÓеÄËùÓа²È«ÌØÐÔ¡£
L2TPËíµÀ¿ÉÒÔÓëIPSec½áºÏ£¬Ê¹Í¨¹ýL2TPËù´«ÊäµÄÊý¾Ý¸üÄѱ»¹¥»÷¡£
¿É¸ù¾ÝÌØ¶¨µÄÍøÂ簲ȫҪÇó£¬ÔÚL2TPÖ®ÉϲÉÓÃͨµÀ¼ÓÃܼ¼Êõ¡¢¶Ë¶Ô¶ËÊý¾Ý¼ÓÃÜ»òÓ¦ÓòãÊý¾Ý¼ÓÃܵȷ½°¸À´Ìá¸ßÊý¾ÝµÄ°²È«ÐÔ¡£
¿É¿¿ÐÔ
L2TPÐÒéÖ§³Ö±¸·ÝLNS£¬µ±Ò»¸öÖ÷LNS²»¿É´ïÖ®ºó£¬LAC¿ÉÒÔÖØÐÂÓ뱸·ÝLNS½¨Á¢Á¬½Ó£¬Ôö¼ÓÁËVPN·þÎñµÄ¿É¿¿ÐÔºÍÈÝ´íÐÔ
L2TP VPNµÄÔÀí
L2TP VPNµÄÖ÷ÒªÓ¦Óó¡¾°£º
LACºÍLNS½éÉÜ£º
LACÊǸ½ÊôÔÚ½»»»ÍøÂçÉϵľßÓÐPPP¶ËϵͳºÍL2TPÐÒé´¦ÀíÄÜÁ¦µÄÉ豸£¬Ö÷ÒªÓÃÓÚΪPPPÀàÐ͵ÄÓû§Ìṩ½ÓÈë·þÎñ
LACλÓÚLNSºÍÓû§Ö®¼ä£¬ÓÃÓÚÔÚLNSºÍÓû§Ö®¼ä´«µÝÐÅÏ¢°ü£¬Ëü°ÑÓû§ÊÕµ½µÄÐÅÏ¢°ü°´ÕÕL2TPÐÒé½øÐзâ×°²¢ËÍÍùLNS£¬Í¬Ê±Ò²½«´ÓLNSÊÕµ½µÄÐÅÏ¢°ü½øÐнâ·â×°²¢ËÍÍùÓû§¡£LACÓëÓû§Ö®¼ä²ÉÓñ¾µØÁ¬½Ó»òPPPÁ´Â·£¬VPDNÓ¦ÓÃÖÐͨ³£ÎªPPPÁ´Â·¡£
LNS¼ÈÊÇPPP¶Ëϵͳ£¬ÓÖÊÇL2TPÐÒéµÄ·þÎñÆ÷¶Ë£¬Í¨³£×÷Ϊһ¸öÆóÒµÄÚ²¿ÍøµÄ±ßÔµÉ豸¡£
LNS×÷ΪL2TPËíµÀµÄÁíÒ»²à¶Ëµã£¬ÊÇLACµÄ¶Ô¶ËÉ豸 £¬ÊÇLAC½øÐÐËíµÀ´«ÊäµÄPPP»á»°µÄÂß¼ÖÕÖ¹¶Ëµã¡£Í¨¹ýÔÚ¹«ÍøÖн¨Á¢LACËíµÀ£¬½«Óû§µÄPPPÁ¬½ÓµÄÁíÒ»¶ËÓÉÔÀ´µÄLACÔÚÂß¼ÉÏÑÓÉìÁËÆóÒµÍøÄÚ²¿µÄLNS¡£
L2TP VPNÖ÷ÒªÓÐÈýÖÖÓ¦Óó¡¾°¡£·Ö±ðÊÇ£º
NAS-Initiated³¡¾°£¨²¦ºÅÓû§·ÃÎÊÆóÒµÄÚÍø£©
NAS£¨Network Access Server£©:ÊÇÔËÓªÉÌÓÃÀ´Ïò²¦ºÅÓû§ÌṩPPP/PPPoE½ÓÈë·þÎñµÄ·þÎñÆ÷£¬²¦ºÅÓû§Í¨¹ýNAS·ÃÎÊÍâ²¿ÍøÂç¡£
LNS£¨L2TP Network Server£©ÊÇÆóÒµ×ܲ¿µÄ³ö¿ÚÍø¹Ø¡£
Óû§Í¨¹ýPPPoE²¦ÈëLAC£¨L2TP Access Concentrator£©£¬´¥·¢LACºÍLNSÖ®¼ä½¨Á¢ËíµÀ¡£½ÓÈëÓû§µØÖ·ÓÉLNS·ÖÅ䣬¶Ô½ÓÈëÓû§µÄÈÏÖ¤¿ÉÓÉLAC²àµÄ´úÀíÍê³É£¬Ò²¿ÉÁ½²à¶¼¶Ô½ÓÈëÓû§×öÈÏÖ¤¡£µ±ËùÓÐL2TPÓû§¶¼ÏÂÏßʱ£¬ËíµÀ×Ô¶¯²ð³ýÒÔ½ÚÊ¡×ÊÔ´£¬Ö±ÖÁÔÙÓÐÓû§½ÓÈëʱ£¬ÖØÐ½¨Á¢ËíµÀ¡£
´Ë×éÍøÊÊÓÃÓÚ·ÖÖ§»ú¹¹Óû§Ïò×ܲ¿·¢ÆðÁ¬½Ó£¬ÇÒÒ»°ãÓÃÓÚ·ÖÖ§»ú¹¹µÄÓû§²»¾³£·ÃÎÊÆóÒµ×ܲ¿µÄÇé¿ö¡£
ͼ£ºNAS-Initiated VPNËíµÀ×éÍøÍ¼
LAC×Ô¶¯²¦ºÅ
LACÓëLNSÖ®¼ä½¨Á¢Ò»ÌõÓÀ¾ÃÐÔL2TP»á»°¡£¿Í»§¶Ë²»ÓÃPPP²¦ºÅ£¬¶øÍ¨¹ýIPÁ¬½Ó¼´¿ÉÔÚËíµÀÖд«ÊäÊý¾Ý¡£
Óû§Í¨¹ýÅäÖô¥·¢½¨Á¢LACÓëLNSÖ®¼äµÄÓÀ¾ÃÐÔL2TP»á»°¡£LACʹÓô洢ÔÚ±¾µØµÄÓû§ÃûºÍLNS½¨Á¢Ò»¸öÓÀ¾Ã´æÔÚµÄL2TPËíµÀ£¬´ËʱµÄL2TPËíµÀ¾ÍÏ൱ÓÚÒ»¸öÎïÀíÁ¬½Ó¡£Óû§ÓëLACÖ®¼äµÄÁ¬½Ó¾Í²»ÊÜÏÞÓÚPPPÁ¬½Ó£¬¶øÖ»ÐèIPÁ¬½Ó£¬LAC¼´¿É½«Óû§µÄIP±¨ÎÄת·¢µ½LNS¡£
ÕâÖÖ×éÍøÒ²ÊÊÓÃÓÚ·ÖÖ§»ú¹¹½ÓÈë×ܲ¿£¬ÓÃÓÚ·ÖÖ§»ú¹¹Ô±¹¤·ÃÎÊ×ܲ¿ÆµÂʽϸߵÄÇé¿ö¡£ÓëNAS-Initiated VPN³¡¾°Ïà±È£º
·ÖÖ§»ú¹¹Ô±¹¤¸ÐÖª²»µ½ËíµÀ´æÔÚ£¬²»ÐèҪʹÓÃÓû§Ãû½ÓÈë¡£LACΪ·ÖÖ§»ú¹¹µÄ¶à¸öÓû§ÌṩL2TP·þÎñ£¬ÃâÈ¥ÁËÿ¸öÓû§Ê¹ÓÃL2TP¶¼ÐèÒªÏȲ¦ºÅµÄÂé·³¡£
ÕâÖÖ×éÍøÏ£¬LNSÖ»¶ÔLAC½øÐÐÈÏÖ¤¡£ÆäȱµãΪ£º·ÖÖ§»ú¹¹Óû§Ö»ÒªÄܹ»Á¬½ÓLAC¼´¿ÉʹÓÃL2TPËíµÀ½ÓÈë×ܲ¿£¬¶ø²»Ðè±»ÈÏÖ¤¡£´æÔÚÒ»¶¨µÄ°²È«Òþ»¼¡£´ËʱÓû§½ÓÈë×ܲ¿ÒÔͨ¹ýÉ豸µÄÓû§ÈÏÖ¤¹¦ÄܶԽÓÈë×ܲ¿µÄÓû§½øÐÐÈÏÖ¤£¬´Ó¶øÌá¸ß°²È«ÐÔ¡£
ͼ£ºLAC×Ô¶¯²¦ºÅ×éÍøÊ¾Àý
Client-Initiated³¡¾°£¨Òƶ¯°ì¹«Óû§·ÃÎÊÆóÒµÄÚÍø£©
Ö±½ÓÓɽÓÈëÓû§£¨¿ÉΪ֧³ÖL2TPÐÒéµÄPC£©·¢ÆðÁ¬½Ó¡£´Ëʱ½ÓÈëÓû§¿ÉÖ±½ÓÏòLNS·¢ÆðËíµÀÁ¬½ÓÇëÇó£¬ÎÞÐèÔÙ¾¹ýÒ»¸öµ¥¶ÀµÄLACÉ豸¡£½ÓÈëÓû§µØÖ·µÄ·ÖÅäÓÉLNSÀ´Íê³É¡£
ÓÉÓÚLNS¶ËÐèҪΪÿ¸öÔ¶³ÌÓû§½¨Á¢Ò»ÌõËíµÀ£¬ÓëNAS-Initiated VPN³¡¾°Ïà±È£¬LNS¶ËÅäÖøü¸´ÔÓһЩ¡£ÓëÆäËûÁ½ÖÖ³¡¾°Ïà±È£¬ÆäÓŵãÔÚÓÚ½ÓÈëÓû§²»ÊܵØÓòÏÞÖÆ¡£
´Ë³¡¾°ÊÊÓÃÓÚ³ö²îÔ±¹¤Ê¹ÓÃPC¡¢ÊÖ»úµÈÒÆ¶¯É豸½ÓÈë×ܲ¿·þÎñÆ÷£¬ÊµÏÖÒÆ¶¯°ì¹«¡£
ͼ£ºClient-Initiated×éÍøÊ¾Òâͼ
ËíµÀºÍ»á»°½¨Á¢ÔÀí£º
ËíµÀºÍ»á»°µÄ¸ÅÄ
ÔÚLNSºÍLAC¶ÔÖ®¼ä´æÔÚ×ÅÁ½ÖÖÀàÐ͵ÄÁ¬½Ó¡£
ËíµÀ£¨Tunnel£©Á¬½Ó£ºËü¶¨ÒåÁË»¥ÏàͨÐŵÄÁ½¸öʵÌåLNSºÍLAC¡£
ÔÚÒ»¶ÔLACºÍLNSÖ®¼ä¿ÉÒÔ½¨Á¢¶àÌõËíµÀ¡£ËíµÀÓÉÒ»¸ö¿ØÖÆÁ¬½ÓºÍÖÁÉÙÒ»¸ö»á»°×é³É¡£
L2TPÊ×ÏÈÐèÒª½¨Á¢L2TPËíµÀ£¬È»ºóÔÚL2TPËíµÀÉϽ¨Á¢»á»°Á¬½Ó£¬×îºó½¨Á¢PPPÁ¬½Ó¡£ËùÓеÄL2TPÐèÒª³ÐÔØµÄÊý¾ÝÐÅÏ¢¶¼ÊÇÔÚPPPÁ¬½ÓÖнøÐд«µÝµÄ¡£
»á»°£¨Session£©Á¬½Ó£ºËü¸´ÓÃÔÚËíµÀÁ¬½ÓÖ®ÉÏ£¬ÓÃÓÚ±íʾ³ÐÔØËíµÀÁ¬½ÓÖеÄÿ¸öPPPÁ¬½Ó¹ý³Ì¡£
»á»°ÊÇÓз½ÏòµÄ£¬´ÓLACÏòLNS·¢ÆðµÄ»á»°½Ð×öIncoming»á»°£¬´ÓLNSÏòLAC·¢ÆðµÄ»á»°½Ð×öOutgoing»á»°¡£
ËíµÀºÍ»á»°µÄ¹ØÏµ£º
NAS-Initiated VPN³¡¾°ÖУ¬Ò»¶ÔLACºÍLNSµÄÁ´½Ó¿ÉÒÔ´æÔÚ¶àÌõËíµÀ£»Ò»ÌõËíµÀÖпɳÐÔØ¶àÌõ»á»°¡£¼´£º¶à¸öÓû§¿ÉÒÔ¹²ÓÃÒ»ÌõËíµÀ¡£
LAC×Ô¶¯²¦ºÅ³¡¾°ÖУ¬LACºÍLNS½¨Á¢ÓÀ¾ÃµÄËíµÀ¡£ÇÒ½ö³ÐÔØÒ»ÌõÓÀ¾ÃµÄL2TP»á»°ºÍPPPÁ¬½Ó¡£
Client-Initiated VPN³¡¾°ÖУ¬Ã¿¸ö½ÓÈëÓû§ºÍLNSÖ®¼ä¾ù½¨Á¢Ò»ÌõËíµÀ£»Ã¿ÌõËíµÀÖнö³ÐÔØÒ»Ì¨L2TP»á»°ºÍPPPÁ¬½Ó¡£
¿ØÖÆÏûÏ¢ºÍÊý¾ÝÏûÏ¢£º
**¿ØÖÆÏûÏ¢£º**¿ØÖÆÏûÏ¢ÓÃÓÚËíµÀºÍ»á»°Á¬½ÓµÄ½¨Á¢¡¢Î¬»¤ÒÔ¼°´«Êä¿ØÖÆ£»Î»ÓÚËíµÀºÍ»á»°½¨Á¢¹ý³ÌÖС£¿ØÖÆÏûÏ¢µÄ´«ÊäÊǿɿ¿´«Ê䣬²¢ÇÒÖ§³Ö¶Ô¿ØÖÆÏûÏ¢µÄÁ÷Á¿¿ØÖƺÍÓµÈû¿ØÖÆ£»Ö÷ÒªµÄ¿ØÖÆÏûÏ¢°üÀ¨¿ØÖƱ¨ÎÄ¡¢»á»°±¨Îĵȡ£
¿ØÖƱ¨ÎÄÓÃÓÚ½¨Á¢ºÍ²ð³ý¡¢Î¬³ÖËíµÀ£¬Ö÷Òª°üÀ¨£º
SCCRQ£¨Start-Control-Connection-Request£©£º¿ØÖÆÁ¬½Ó·¢ÆôÇëÇó¡£ÓÉLAC»òÕßLNSÏò¶Ô¶Ë·¢ËÍ£¬ÓÃÀ´³õʼ»¯LACºÍLNSÖ®¼äµÄËíµÀ£¬¿ªÊ¼ËíµÀµÄ½¨Á¢¹ý³Ì¡£NGFWµÄÓ¦Óó¡¾°ÖУ¬Ò»°ã¶¼ÊÇÓÉLACÏòLNS·¢ÆðÇëÇó¡£
SCCRP£¨Start-Control-Connection-Reply£©£º±íʾ½ÓÊÜÁ˶Զ˵ÄÁ¬½ÓÇëÇó£¬ËíµÀµÄ½¨Á¢¹ý³Ì¿ÉÒÔ¼ÌÐø¡£
SCCCN£¨Start-Control-Connection-Connected£©£º¶ÔSCCRPµÄ»ØÓ¦£¬Íê³ÉËíµÀµÄ½¨Á¢¡£
StopCCN£¨Stop-Control-Connection-Notification£©£ºÓÉLAC»òÕßLNS·¢³ö£¬Í¨Öª¶Ô¶ËËíµÀ½«ÒªÍ£Ö¹£¬¿ØÖÆÁ¬½Ó½«Òª¹Ø±Õ¡£ÁíÍ⣬ËùÓлµÄ»á»°¶¼»á±»Çå³ý¡£
HELLO£ºËíµÀ±£»î¿ØÖÆÏûÏ¢¡£L2TPʹÓÃHello±¨ÎÄÀ´¼ì²âËíµÀµÄÁ¬Í¨ÐÔ¡£LACºÍLNS¶¨Ê±Ïò¶Ô¶Ë·¢ËÍHello±¨ÎÄ£¬Èç¹ûÔÚÒ»¶Îʱ¼äÄÚδÊÕµ½Hello±¨ÎĵÄÓ¦´ð£¬ËíµÀ½«±»Çå³ý¡£
»á»°±¨ÎÄÓÃÓÚ½¨Á¢ºÍ²ð³ý»á»°£¬Ö÷Òª°üÀ¨£º
ICRQ£¨Incoming-Call-Request£©£ºµ±LAC¼ì²âµ½ÓÐÓû§²¦Èëµç»°µÄʱºò£¬ÏòLNS·¢ËÍICRQ£¬ÇëÇóÔÚÒѾ½¨Á¢µÄËíµÀÖн¨Á¢»á»°¡£
ICRP£¨Incoming-Call-Reply£©£ºÓÃÀ´»ØÓ¦ICRQ£¬±íʾICRQ³É¹¦£¬LNSÒ²»áÔÚICRPÖбêʶL2TP»á»°±ØÒªµÄ²ÎÊý¡£
ICCN£¨Incoming-Call-Connected£©£ºÓÃÀ´»ØÓ¦ICRP£¬L2TP»á»°½¨Á¢Íê³É¡£
CDN£¨Call-Disconnect-Notify£©£ºÓÉLAC»òÕßLNS·¢³ö£¬Í¨Öª¶Ô¶Ë»á»°½«ÒªÍ£Ö¹¡£
Êý¾ÝÏûÏ¢£ºÓÃÓÚ³ÐÔØÓû§µÄPPPÁ¬½ÓÊý¾Ý±¨ÎÄ£¬²¢ÔÚËíµÀÉϽøÐд«Êä¡£Êý¾ÝÏûÏ¢µÄ´«ÊäÊDz»¿É¿¿´«Ê䣬ÈôÊý¾Ý±¨ÎĶªÊ§£¬²»ÓèÖØ´«¡£²»Ö§³Ö¶ÔÊý¾ÝÏûÏ¢µÄÁ÷Á¿¿ØÖƺÍÓµÈû¿ØÖÆ¡£
NAS-Initiated VPNËíµÀºÍ»á»°½¨Á¢¹ý³Ì£º
ͼ£ºNAS-Initiated VPNËíµÀºÍ»á»°½¨Á¢¹ý³Ì
½¨Á¢PPPoEÁ¬½Ó
LAC¶ÔÓû§½øÐÐÈÏÖ¤¡£
½¨Á¢L2TPËíµÀ
L2TPÊý¾ÝÒÔUDP±¨ÎÄÐÎʽ·¢ËÍ¡£L2TP×¢²áÁËUDP¶Ë¿Ú1701£¬µ«ÊÇÕâ¸ö¶Ë¿Ú½öÓÃÓÚ³õʼµÄËíµÀ½¨Á¢¹ý³Ì¡£L2TPËíµÀ·¢Æð·½£¨LAC£©ÈÎѡһ¸ö¿ÕÏж˿ڣ¨Î´±ØÊÇ1701£©Ïò½ÓÊÕ·½£¨LNS£©µÄ1701¶Ë¿Ú·¢Ëͱ¨ÎÄ£»LNSÊÕµ½±¨Îĺó£¬Ê¹ÓÃ1701¶Ë¿Ú¸øLACµÄÖ¸¶¨¶Ë¿Ú»ØËͱ¨ÎÄ¡£ÖÁ´Ë£¬Ë«·½µÄ¶Ë¿ÚÑ¡¶¨£¬²¢ÔÚËíµÀ±£³ÖÁ¬Í¨µÄʱ¼ä¶ÎÄÚ²»Ôٸı䡣
LAC¼ì²éÓû§µÄLCPÐÉÌÖеÄÈÏÖ¤ÐÅÏ¢£¨Domain¡¢UsernameµÈ£©£¬²éÕÒÄܹ»Æ¥ÅäµÄL2TP×飬¸ù¾ÝL2TP×éµÄÅäÖöÔij¸öLNS½øÐÐL2TPºô½Ð½¨Á¢L2TPËíµÀ¡£Èç¹û´ËʱLAC·¢ÏÖL2TPËíµÀÒѾ½¨Á¢£¬ÔòLAC·¢Æð»á»°Á¬½Ó£¬·ñÔòÊ×ÏȽ¨Á¢L2TPËíµÀ¡£
LAC¶ËÏòÖ¸¶¨µÄLNS·¢ËÍCHAP challengeÐÅÏ¢£¬LNS»ØË͸ÃchallengeÏìÓ¦ÏûÏ¢CHAP response£¬²¢·¢ËÍLNS²àµÄCHAP challenge£¬LAC·µ»Ø¸ÃchallengeµÄÏìÓ¦ÏûÏ¢CHAP response¡£
LACºÍLNSÖ®¼äͨ¹ýSCCRQ¡¢SCCRPºÍSCCCNÏûÏ¢Íê³ÉL2TPËíµÀµÄ½¨Á¢£¬²¢ÇÒË«·½¶¼ÖªµÀ¶Ô·½µÄTunnel IDµÈÐÅÏ¢£¬ºóÐøµÄÊý¾Ý±¨Îͼ»áÌí¼ÓPeerµÄTunnel IDÐÅÏ¢£¬ÕâÑù½ÓÊÕÕ߾ͿÉÒÔÖªµÀÊÕµ½µÄL2TP±¨ÎÄÊôÓÚ±¾µØµÄÄĸöËíµÀ¡£
½¨Á¢L2TP»á»°
LACºÍLNSʹÓÃICRQ¡¢ICRPºÍICCNÏûÏ¢½¨Á¢L2TP»á»°£¬ÕâЩÏûÏ¢¶¼ÔÚÇ°Ãæ½¨Á¢µÄL2TPËíµÀÖд«µÝ£¬²¢ÇÒ¶¼»áÌí¼ÓËíµÀ¶Ô¶ËµÄTunnel IDÐÅÏ¢¡£
ÔÚICCNÏûÏ¢ÖУ¬LAC¶Ë½«Óû§CHAP response¡¢response identifierºÍPPPÐÉ̲ÎÊý´«Ë͸øLNS£¬ÒÔ±ãºóÐøLNSÓëÓû§½¨Á¢PPPÁ¬½Ó¡£
LNS¸ù¾ÝÓû§Ãû¡¢ÃÜÂëµÈÐÅÏ¢¶ÔÓû§½øÐÐÈÏÖ¤¡£
LNS¶ÔÓû§½øÐжþ´ÎÈÏÖ¤£¨¿ÉÑ¡£©
LNS¶ÔÓû§ÔÚ´ËÈÏÖ¤£¨¿ÉÑ¡£©
Óû§ÓëLNSÖ®¼ä½¨Á¢PPPÁ¬½Ó¡£
Íê³ÉÁËL2TP»á»°ÒÔºó£¬LAC»á½«ClientµÄÏà¹ØPPP²ÎÊýͨ¹ýL2TP»á»°×ª·¢¸øLNS£¬LNSºÍÓû§½øÐÐPPPµÄÈÏÖ¤¡£
LNSÏòÓû§·ÖÅäµØÖ·È»ºó½¨Á¢PPPÁ¬½Ó£¬×¢Òâ´ËʱµÄPPPÁ¬½ÓÔÚÓû§ºÍLNSÖ®¼ä½¨Á¢£¬²¢²»ÊÇÔÚLACºÍLNSÖ®¼ä¡£
´ËʱµÄLACÒ²±£³ÖןÍÓû§µÄPPPÁ¬½Ó£¬ÓÃÓÚ½«À´×ÔLNSµÄL2TPÊý¾Ý±¨ÎĽâ·â×°ÒÔºóͨ¹ýPPPÁ¬½Ó´«µÝ¸øClient¡£
Óû§·ÃÎÊÄÚÍø×ÊÔ´¡£
LAC×Ô¶¯²¦ºÅËíµÀºÍ»á»°µÄ½¨Á¢£º
Óë´¥·¢½¨Á¢ËíµÀµÄ·½Ê½²»Í¬£¬LAC×Ô¶¯²¦ºÅ³¡¾°ÊÇÎÞÐè´¥·¢µÄÓÀ¾ÃËíµÀ¡£Ò»µ©ÅäÖÃÍê±Ï£¬¼´¿É½¨Á¢ÓÀ¾ÃËíµÀ£¬²¢³ÐÔØÎ¨Ò»µÄÒ»ÌõÓÀ¾Ã»á»°¡£LACΪLNSµÄΨһµÄ¿Í»§¶Ë¡£
ͼ£ºLAC×Ô¶¯²¦ºÅµÄËíµÀºÍ»á»°½¨Á¢¹ý³Ì
Client-Initiated VPNËíµÀºÍ»á»°µÄ½¨Á¢£º
Client-Initiated VPN³¡¾°Ï£¬ËíµÀ½¨Á¢¹ý³ÌÓëNAS-Initiated VPNÏàËÆ¡£ÓëNAS-Initiated VPN³¡¾°Ïà±È£¬Client-Initiated VPN³¡¾°Ï൱ÓÚ½«ClientºÍLACºÏΪÁËÒ»¸öÕûÌå¡£
ͼ£ºClient-Initiated VPNËíµÀºÍ»á»°½¨Á¢¹ý³Ì
L2TP VPNµÄ±¨ÎÄ·â×°£º
NAS-Initiated VPN×éÍøÊý¾Ý·â×°¹ý³Ì£º
ͼ£ºNAS-Initiated VPN³¡¾°×éÍø±¨ÎÄ·â×°¹ý³Ì
NAS-Initiated VPN×éÍøÖУ¬½ÓÈëÓû§·ÃÎÊÄÚÍø·þÎñÆ÷ʱ£º
µ±ËíµÀºÍ»á»°¾ù½¨Á¢Íê³Éºó£¬½ÓÈëÓû§ÒÑ»ñÈ¡LNS·ÖÅäµÄµØÖ·£¬²¢Óô˵ØÖ·À´·ÃÎÊÄÚÍø·þÎñÆ÷¡£
½ÓÈëÓû§ÏòLAC·¢ÆðPPPoE²¦ºÅ£¬ÎªÊý¾ÝÌí¼Ó˽ÓÐIP¡¢PPP±¨ÎÄÍ·ºÍPPPoE±¨ÎÄÍ·£¬²¢Ìí¼ÓÌ«ÍøÍ·ºó£¬·¢Ë͸øLAC¡£
LACÊÕµ½±¨Îĺó£¬ÒÀ´Î°þÀëÒÔÌ«ÍøÍ·¡¢PPPoE±¨ÎÄÍ·£¬²¢¶Ô±¨ÎÄÒÀ´Î·â×°L2TP±¨ÎÄÍ·¡¢UDP±¨ÎÄÍ·£¬²¢Ìí¼Ó¹«ÍøIP£¬·¢Ë͸øLNS¡£
LNSÊÕµ½±¨Îĺó£¬Ê×ÏȶԱ¨ÎĽøÐÐL2TP½â·â×°£¬ÒÀ´Î°þÀë¹«ÍøIP¡¢UDP±¨ÎÄÍ·¡¢L2TP±¨ÎÄÍ·¡£Ö®ºó½øÐÐPPP½â·â×°£¬°þÀëPPP±¨ÎÄÍ·¡£×îºóÌí¼ÓÒÔÌ«ÍøÍ·£¬²¢¸ù¾Ý˽ÓÐIPµÄÄ¿µÄµØÖ·½«±¨ÎÄ·¢Ë͸øÄÚÍø·þÎñÆ÷¡£
·þÎñÆ÷½ÓÊÕ±¨Îĺ󣬻ñÈ¡±¨ÎÄÊý¾Ý£¬²¢½«ÏìÓ¦±¨ÎÄ·¢Ë͸øLNS¡£
LAC×Ô¶¯²¦ºÅ×éÍøÊý¾Ý·â×°¹ý³Ì£º
ͼ£ºLAC×Ô¶¯²¦ºÅ³¡¾°×éÍø±¨ÎÄ·â×°¹ý³Ì
LAC×Ô¶¯²¦ºÅ×éÍøÖУ¬PPP·â×°ºÍL2TP·â×°½öÏÞÓÚLACºÍLNSÖ®¼äµÄ±¨ÎĽ»»¥¡£
Client-Initiated VPN×éÍøÊý¾Ý·â×°¹ý³Ì£º
ͼ£ºClient-Initiated VPN³¡¾°×éÍø±¨ÎÄ·â×°¹ý³Ì
L2TP VPNµÄÈÏÖ¤£º
L2TPÖ§³ÖʹÓÃPAPºÍCHAPÁ½ÖÖ·½Ê½½øÐÐPPPÈÏÖ¤¡£
VT£¨Virtual-Template£©½Ó¿Ú£º
PPP¡¢Ethernet¶¼ÊǶþ²ãÐÒ飬ËüÃÇÖ®¼ä²»ÄÜÖ±½Ó»¥Ïà³ÐÔØ¡£µ±Óû§ÅäÖÃPPPoEµÈ¶þ²ãÐÒéʱ£¬ÕâЩ¶þ²ãÐÒéÖ®¼äÐèҪͨ¹ýÐéÄâ·ÃÎʽӿÚVA£¨Virtual-Access£©½øÐÐͨÐÅ¡£Ç°ÃæÒѾÌáµ½£¬L2TPÖлáʹÓÃPPPoEÐÒé¡£VT½Ó¿ÚÊÇÓÃÓÚÅäÖÃÐéÄâ·ÃÎʽӿڵÄÄ£°å¡£ÔÚL2TP»á»°Á¬½Ó½¨Á¢Ö®ºó£¬LAC¡¢LNS¾ùÐèÒª´´½¨ÐéÄâ·ÃÎʽӿÚÓÃÓںͶԶˣ¨¼´Óû§£©½»»»Êý¾Ý¡£´Ëʱ£¬ÏµÍ³½«°´ÕÕÓû§µÄÅäÖã¬Ñ¡ÔñVT½Ó¿Ú£¬¸ù¾Ý¸ÃÄ£°åµÄÅäÖòÎÊý£¨°üÀ¨½Ó¿ÚIPµØÖ·¡¢PPPÈÏÖ¤·½Ê½µÈ£©¶¯Ì¬µØ´´½¨ÐéÄâ·ÃÎʽӿڡ£
ÃüÁîÐÐÅäÖÃÖУ¬VT½Ó¿ÚÏ¿ÉÑ¡ÔñCHAP»òPAPÈÏÖ¤·½Ê½À´¶ÔÓû§½øÐÐPPPÈÏÖ¤¡£WebÅäÖÃÖв»Ö§³ÖÊÖ¹¤ÅäÖÃÈÏÖ¤·½Ê½£¬ÏµÍ³ÓÅÏÈÑ¡ÔñCHAP·½Ê½£¬Æä´ÎÑ¡ÔñPAP·½Ê½¡£
LAC×ÔÖ÷²¦ºÅ³¡¾°£º
LAC×ÔÖ÷²¦ºÅ³¡¾°ÖУ¬LAC²à²»¶ÔÓû§½øÐÐÈÏÖ¤£¬Ö»ÔÚLNS²à¶ÔLACÅäÖõÄÓû§½øÐÐPPPÈÏÖ¤£¨PAP»òCHAP£©¡£ÔÚÃüÁîÐÐÅäÖÃÖУ¬ÌåÏÖÔÚVT½Ó¿ÚÏÂÅäÖõÄPPPÈÏÖ¤·½Ê½¡£
Client-Initiated VPN³¡¾°£º
Client-Initiated VPN³¡¾°ÖУ¬ÔÚLNS²à¶ÔÓû§½øÐÐPPPÈÏÖ¤£¨PAP»òCHAP£©¡£ÔÚÃüÁîÐÐÅäÖÃÖУ¬ÌåÏÖÔÚVT½Ó¿ÚÏÂÅäÖõÄPPPÈÏÖ¤·½Ê½¡£
NAS-Initiated VPN³¡¾°£º
NAS-Initiated VPN³¡¾°ÖУ¬L2TP¿É¶ÔÓû§½øÐÐÁ½´ÎPPPÈÏÖ¤£ºµÚÒ»´Î·¢ÉúÔÚLAC²à£¬µÚ¶þ´Î·¢ÉúÔÚLNS²à¡£Ö»ÓÐÒ»ÖÖÇé¿öLNS²à²»¶Ô½ÓÈëÓû§½øÐжþ´ÎÈÏÖ¤£ºÆôÓÃLCPÖØÐÉ̺󣬲»ÔÚÏàÓ¦µÄVT½Ó¿ÚÉÏÅäÖÃÈÏÖ¤¡£Õâʱ£¬Óû§Ö»ÔÚLAC²à½ÓÊÜÒ»´ÎÈÏÖ¤¡£
ÁíÍ⣬²»ÂÛ¶ÔÓÚLAC»òLNS£¬Èç¹ûÆäÅäÖõÄÓû§ÈÏÖ¤·½Ê½Îª¡°²»ÈÏÖ¤¡±£¬Ôò²»ÂÛVT½Ó¿ÚÖÐʹÓúÎÖÖÈÏÖ¤·½Ê½£¬¶¼²»¶ÔÓû§½øÐÐÈÏÖ¤¡£
ÒÔ϶ÔÓÚÈÏÖ¤·½Ê½µÄÃèÊö¶¼ÊÇ»ùÓÚÅäÖõÄÓû§ÈÏÖ¤·½Ê½²»Îª¡°²»ÈÏÖ¤¡±µÄÇé¿ö¡£
LAC¶ËÈÏÖ¤·½Ê½
LAC¶Ë¿É¶ÔÓû§½øÐÐPAP»òCHAPÈÏÖ¤¡£ÔÚÃüÁîÐÐÅäÖÃÖУ¬Ê¹ÓÃVT½Ó¿ÚÏÂÅäÖõÄPPPÈÏÖ¤·½Ê½¡£
LNS¶ËÈÏÖ¤·½Ê½
LNS¶ÔÓû§µÄÈÏÖ¤·½Ê½³ýÓÉPPPÈÏÖ¤·½Ê½¾ö¶¨Í⣬»¹È¡¾öÓÚÅäÖõÄL2TPÈÏÖ¤·½Ê½¡£L2TPÈÏÖ¤·½Ê½ÓÐÈýÖÖ£º´úÀíÈÏÖ¤¡¢Ç¿ÖÆCHAPÈÏÖ¤ºÍLCPÖØÐÉÌ¡£ÆäÖУ¬LCPÖØÐÉ̵ÄÓÅÏȼ¶×î¸ß£¬´úÀíÈÏÖ¤ÓÅÏȼ¶×îµÍ¡£
LCPÖØÐÉÌ
Èç¹ûÐèÒªÔÚLNS²à½øÐбÈLAC²à¸üÑϸñµÄÈÏÖ¤£¬»òÕßLNS²àÐèÒªÖ±½Ó´ÓÓû§»ñȡijЩÐÅÏ¢£¨µ±LNSÓëLACÊDz»Í¬³§É̵ÄÉ豸ʱ¿ÉÄÜ·¢ÉúÕâÖÖÇé¿ö£©£¬Ôò¿ÉÒÔÅäÖÃLNSÓëÓû§¼ä½øÐÐLCPÖØÐÉÌ¡£LCPÖØÐÉÌʹÓÃÏàÓ¦VT½Ó¿ÚÅäÖõÄÈÏÖ¤·½Ê½¡£´Ëʱ½«ºöÂÔLAC²àµÄ´úÀíÈÏÖ¤ÐÅÏ¢¡£
Ç¿ÖÆCHAPÈÏÖ¤
Èç¹ûÖ»ÅäÖÃÇ¿ÖÆCHAPÈÏÖ¤£¬ÔòLNS¶ÔÓû§½øÐÐCHAPÈÏÖ¤£¬Èç¹ûÈÏÖ¤²»Í¨¹ý£¬»á»°¾Í²»Äܽ¨Á¢³É¹¦¡£
´úÀíÈÏÖ¤
´úÀíÈÏÖ¤¾ÍÊÇLAC½«Ëü´ÓÓû§µÃµ½µÄËùÓÐÈÏÖ¤ÐÅÏ¢¼°LACÅäÖõÄÈÏÖ¤·½Ê½´«¸øLNS£¬LNS»áÀûÓÃÕâЩÐÅÏ¢ºÍLAC¶Ë´«À´µÄÈÏÖ¤·½Ê½¶ÔÓû§½øÐÐÈÏÖ¤¡£
NAS-Initiated VPNÖУ¬ÔÚPPP»á»°¿ªÊ¼Ê±£¬Óû§ÏȺÍLAC½øÐÐPPPÐÉÌ¡£ÈôÐÉÌͨ¹ý£¬ÔòÓÉLAC³õʼ»¯L2TPËíµÀÁ¬½Ó£¬²¢½«Óû§ÐÅÏ¢¡¢ÈÏÖ¤ÐÅÏ¢µÈ´«µÝ¸øLNS£¬ÓÉLNS¸ù¾ÝÊÕµ½µÄ´úÀíÈÏÖ¤ÐÅÏ¢ÅжÏÓû§ÊÇ·ñºÏ·¨¡£
´úÀíÈÏÖ¤ÓëVT½Ó¿ÚµÄPPPÈÏÖ¤·½Ê½µÄ¹ØÏµ£º
LNSµÄPPPÈÏÖ¤·½Ê½²»ÄܱÈLAC¸´ÔÓ¡£ÀýÈ磬Èç¹ûLAC¶ËÅäÖõÄÈÏÖ¤·½Ê½ÎªPAP£¬¶øLNSÅäÖõÄPPPÈÏÖ¤·½Ê½ÎªCHAP£¬ÔòÓÉÓÚLNSÒªÇóµÄCHAPÈÏÖ¤¼¶±ð¸ßÓÚLACÄܹ»ÌṩµÄPAPÈÏÖ¤£¬ÈÏÖ¤½«ÎÞ·¨Í¨¹ý£¬»á»°Ò²¾Í²»ÄÜÕýÈ·½¨Á¢¡£
ÆäËûÇé¿öÏ£¬Èç¹ûLNSÓëLACµÄÈÏÖ¤·½Ê½²»Ò»Ö£¬LNS½«²ÉÓÃLAC·¢Ë͹ýÀ´µÄÈÏÖ¤·½Ê½½øÐÐÐÉÌ£¬ºöÂÔVT½Ó¿ÚÅäÖõÄÈÏÖ¤·½Ê½¡£
ÈýÖÖ×éÍøÄ£Ê½µÄ¶Ô±È
ÈýÖÖ×éÍø¶Ô±È£º
Client-Initiated VPN£ºÆäÓŵãÔÚÓÚ½ÓÈëÓû§²»ÊܵØÓòÏÞÖÆ¡£´Ë³¡¾°ÊÊÓÃÓÚÔ±¹¤Ê¹ÓÃPC¡¢ÊÖ»úµÈÒÆ¶¯É豸½ÓÈë×ܲ¿·þÎñÆ÷£¬ÊµÏÖÒÆ¶¯°ì¹«¡£
NAS-Initiated VPN£º½ÓÈëÓû§£¨PC£©Í¨¹ýPPPoE²¦ÈëLAC£¬ÓÉLACͨ¹ýInternetÏòLNS·¢Æð½¨Á¢ËíµÀÁ¬½ÓÇëÇó¡£½ÓÈëÓû§µØÖ·ÓÉLNS·ÖÅ䣬¶Ô½ÓÈëÓû§µÄÈÏÖ¤¿ÉÓÉLAC²à´úÀíÍê³É£¬Ò²¿ÉÁ½²à¶¼¶Ô½ÓÈëÓû§×öÈÏÖ¤¡£µ±ËùÓÐL2TPÓû§¶¼ÏÂÏßʱ£¬ËíµÀ×Ô¶¯²ð³ýÒÔ½ÚÊ¡×ÊÔ´£¬Ö±ÖÁÔÙÓÐÓû§½ÓÈëʱ£¬ÖØÐ½¨Á¢ËíµÀ¡£´Ë×éÍøÊÊÓÃÓÚ·ÖÖ§»ú¹¹Óû§Ïò×ܲ¿·¢ÆðÁ¬½Ó£¬ÇÒÒ»°ãÓÃÓÚ·ÖÖ§»ú¹¹µÄÓû§²»¾³£·ÃÎÊÆóÒµ×ܲ¿µÄÇé¿ö¡£
LAC-Auto£º·ÖÖ§»ú¹¹Ô±¹¤¸ÐÖª²»µ½ËíµÀ´æÔÚ£¬²»ÐèҪʹÓÃÓû§½ÓÈë¡£LACΪ·ÖÖ§»ú¹¹µÄ¶à¸öÓû§ÌṩL2TP·þÎñ£¬ÃâÈ¥ÁËÿ¸öÓû§Ê¹ÓÃL2TP¶¼ÐèÒªÏȰκŵÄÂé·³
ÕâÖÖ×éÍøÏ£¬LNSÖ»¶ÔLAC½øÐÐÈÏÖ¤¡£ÆäȱµãΪ£º·ÖÖ§»ú¹¹Óû§Ö»ÒªÄܹ»Á¬½ÓLAC¼´¿ÉʹÓÃL2TPËíµÀ½ÓÈë×ܲ¿£¬¶ø²»Ðè±»ÈÏÖ¤¡£´æÔÚÒ»¶¨µÄ°²È«Òþ»¼¡£´ËʱÓû§½ÓÈë×ܲ¿ÒÔͨ¹ýÉ豸µÄÓû§ÈÏÖ¤¹¦ÄܶԽÓÈë×ܲ¿µÄÓû§½øÐÐÈÏÖ¤£¬´Ó¶øÌá¸ß°²È«ÐÔ
L2TPºÍPPTPÇø±ð£º
L2TP£º¹«ÓÐÐÒé¡¢UDP1701¡¢Ö§³ÖËíµÀÑéÖ¤£¬Ö§³Ö¶à¸öÐÒ飬¶à¸öËíµÀ£¬Ñ¹Ëõ×Ö½Ú£¬Ö§³ÖÈýÖÖģʽ
PPTP£ºË½ÓÐÐÒé¡¢TCP1723¡¢²»Ö§³ÖËíµÀÑéÖ¤£¬Ö»Ö§³ÖIP¡¢Ö»Ö§³Öµãµ½µã
PPTP£º
µã¶ÔµãËíµÀÐÒ飨PPTP£©ÊÇÓɰüÀ¨MicrosoftºÍ3comµÈ¹«Ë¾×é³ÉµÄPPTPÂÛ̳¿ª·¢µÄ£¬Ò»ÖÖµã¶ÔµãËíµÀÐÒ飬»ùÓڰκÅʹÓõÄPPPÐÒéʹÓÃPAP»òCHAPÖ®ÀàµÄ¼ÓÃÜËã·¨£¬»òÕßʹÓÃMicrosoftµÄµã¶Ôµã¼ÓÃÜËã·¨MPPE¡£
L2TP£º
µÚ¶þ²ãËíµÀÐÒ飨L2TP£©ÊÇIETF»ùÓÚL2F£¨CiscoµÄ2²ãת·¢ÐÒ飩¿ª·¢µÄPPTPºóÐø°æ±¾£¬ÊÇÒ»ÖÖ¹¤Òµ±ê×¼InternetËíµÀÐÒé¡£
Á½ÕßµÄÖ÷񻂿±ðÖ÷ÒªÓÐÒÔϼ¸µã£º
PPTPÖ»ÄÜÔÚÁ½¶Ë¼ä½¨Á¢µ¥Ò»ËíµÀ£¬L2TPÖ§³ÖÔÚÁ½¶Ëµã¼äʹÓöàËíµÀ£¬ÕâÑù¿ÉÒÔÕë¶Ô²»Í¬µÄÓû§´´½¨²»Í¬µÄ·þÎñÖÊÁ¿
L2TP¿ÉÒÔÌṩËíµÀÑéÖ¤»úÖÆ£¬¶øPPTP²»ÄÜÌṩÕâÑùµÄ»úÖÆ£¬µ«µ±L2TP»òPPTPÓëIPSec¹²Í¬Ê¹ÓÃʱ£¬¿ÉÒÔÓÉIPSecÌṩËíµÀÑéÖ¤£¬²»ÐèÒªÔÚµÚ¶þ²ãÐÒéÉÏÌṩËíµÀÑéÖ¤»úÖÆ
PPTPÒªÇó»¥ÁªÍøÂçΪIPÍøÂ磬¶øL2TPÖ»ÒªÇóËíµÀý½éÌá¹©ÃæÏòÊý¾Ý°üµÄµã¶ÔµãÁ¬½Ó£¬L2TP¿ÉÒÔÔÚIP£¨Ê¹ÓÃUDP£©£¬FR£¬ATM£¬x.25ÍøÂçÉÏʹÓÃ
L2TP¿ÉÒÔÌṩ°üͷѹËõ¡£µ±Ñ¹Ëõ°üͷʱ£¬ÏµÍ³¿ªÏú£¨voerhead£©Õ¼ÓÃ4¸ö×Ö½Ú£¬¶øPPTPÐÒéÏÂÒªÕ¼ÓÃ6¸ö×Ö½Ú
L2TPʲôÇé¿öÏÂÐèÒªÇ¿ÖÆÈÏÖ¤£¿
ÔÚNASģʽÏ¡£ÇÒLNS²»ÐÅÈÎLAC£¬ÅäÖÃÁËÇ¿ÖÆÈÏÖ¤µÄÇé¿öÏÂ
L2TP,L2TP VPN,L2TP»ù±¾ÔÀí,L2TP,L2TP VPN,L2TP»ù±¾ÔÀí