I-VPN: IPSec no-SSL

Yiyiphi iThekhnoloji efanelekileyo kuwe?

Kwiminyaka edlulileyo ukuba iofisi ekude ifunekayo ukudibanisa nekhompyuter okanye inethiwekhi kwikomkhulu lekampani, kwakuthetha ukufaka imigca eqingqiweyo yokuqeshisa phakathi kweendawo. Le mizila eqeshwe ngokuqeshiswa yanikezela ngokunxibelelana ngokukhawuleza kunye nokukhuselekileyo phakathi kweziza, kodwa babebiza kakhulu.

Ukufumana iinkampani zabasebenzisi befowuni kuzakufuneka zifake ukudayela okuzinikezelweyo- kumaseva okufikelela okude (RAS). I-RAS ingaba ne-modem, okanye iimodem ezininzi, kunye nekhampani kuya kufuneka ibe nomgca wefowuni osebenza kwi modem nganye. Abasebenzisi abasebenzisa i-intanethi bangaxhumeka kwinethwekhi ngale ndlela, kodwa isantya sasicotha ngokukhawuleza kwaye yenza kube nzima ukwenza umsebenzi onobuchule obuninzi.

Ngokuza kwe-Intanethi ezininzi zazo zitshintshile. Ukuba i-web of server kunye nokunxibelelana kwenethiwekhi sele ikhona, ukuxhuma iikhomputha kwihlabathi jikelele, ngoko kutheni kufuneka inkampani ichithe imali kwaye idale intloko yezolawulo ngokusebenzisa imigca edibeneyo yokuqeshisa kunye neebhanki zeemodem. Kutheni ungasebenzisi nje intanethi?

Eyona nto, umngeni wokuqala kukuba kufuneka ukwazi ukukhetha ngubani na oya kubona ulwazi. Ukuba uvula i-intanethi yonke kwi-intanethi bekungeke kwenzeke ukuba kusebenze iindlela ezifanelekileyo zokugcina abasebenzisi abangagunyazisiweyo ukuba bangene kwi-intanethi yenkampani. Iinkampani zichitha iitoni zemali zokwakha umlilo kunye nezinye iindlela zokukhusela ukhuseleko lwenethiwekhi ezijoliswe ngokukodwa ekuqinisekiseni ukuba akukho mntu uvela kwi-intanethi angena kwinethiwekhi yangaphakathi.

Unxibelelana njani ufuna ukuvimba i-Intanethi yoluntu ukufikelela kwinethiwekhi yangaphakathi ngokufuna ukuba abasebenzisi bakho basemagqabini basebenzise i-intanethi njengendlela yokuxhuma kwinethiwekhi yangaphakathi? Uzalisekisa iNethiwekhi yangasese eyimfihlo (VPN ). I-VPN ikhiqiza "i-tunnel" eyiyo edibanisa ezi zimbini zokugqibela. I-trap ngaphakathi kwiphakheji yeVPN icacisiwe ukuze abanye abasebenzisi be-Intanethi bangaboni ngokukhawuleza ukubonisana nokuthintana.

Ngokufezekisa i-VPN, inkampani inokunika ukufikelela kumnatha wangasese wangasese kubaxhasi emhlabeni jikelele nakuphi na indawo kunye nokufikelela kwi-Intanethi. Iphelisa intloko yezolawulo kunye neyezimali ezihambelana nenethiwekhi yomhlaba oqeshwe ngokuqhelekileyo (WAN) kwaye ivumela abasebenzisi abakude nabaselula ukuba bavelise ngakumbi. Eyona nto ibaluleke kakhulu, ukuba iphunyezwe kakuhle, yenza njalo ngaphandle kokuchaphazela ukhuseleko kunye nenkolelo yeenkqubo zekhomputha kunye nedatha kwinkonzo yenkampani yabucala.

I-VPN yendabuko incike kwi-IPSec (iProtokholi ye-Intanethi ye-Intanethi) ukuya kumnatha phakathi kweempawu zokugqibela ezimbini. I-IPSec isebenza kwi-Network Layer ye-OSI Model-yokugcina yonke idatha ehamba phakathi kweziphelo ezimbini ngaphandle kokuhlanganisana nasiphi na isicelo esithile. Xa ixhunywe kwi-IPSec VPN ikhompyutha yomxhasi "cishe" ilungu elipheleleyo le-intanethi yenkampani yokubona kwaye inokufikelela kuyo yonke inethiwekhi.

Uninzi lwezisombululo ze-IPSec VPN zidinga i-hardware yeqela lesithathu kunye / okanye isofthiwe. Ukuze ufikelele kwi-IPSec VPN, isithuba somsebenzi okanye isixhobo esiphephayo kufuneka sibe ne-software ye-software ye-IPSec yomsebenzisi efakwe. Oku kokubili ip pro ne con.

Inkqubo kukuba unika ukhuseleko olongezelelweyo lokhuseleko ukuba umatshini wabaxumi afuneke ukuba asebenze i-software ye-VPN yesicelo somthengi ukuxhuma kwi-IPSec VPN yakho, kodwa kwakhona kufuneka ukuba ilungiselelwe kakuhle. Ezi ziyimingqinisiso eyongezelelweyo ukuba umsebenzisi ongekho mfuneko uza kufikelela ngaphaya kokufumana ukufikelela kwinethiwekhi yakho.

Ikhonkco kukuba ingaba ngumthwalo wemali ukugcina iisenisi zesofthiwe yomthengi kunye nezobungozi zokuxhasa inkxaso yezobuchwepheshe ukufakela nokuqwalasela isofthiwe somxhasi kuwo wonke omatshini obude-ngakumbi ukuba abanako ukufumana isayithi ngokwenyama ukulungiselela isofthiwe ngokwabo.

Yiyo le con edlalwa njengenye yeyona ndlela inkulu kakhulu ye-SSL (i- Secure Sockets Layer ) izisombululo ze-VPN. I-SSL iyi-protocol eqhelekileyo kwaye ezininzi iiphequluli zewebhu zinezakhono ze-SSL ezakhiwe kuyo. Ngoko ke phantse zonke iikhompyutha ehlabathini sele zixhotywe nge "software software" eziyimfuneko ukuxhuma kwi-SSL VPN.

Olunye uhlobo lwe-SSL VPN kukuba bavumela ukulawula okufikelelekileyo kokufikelela. Okokuqala kwabo bonke banikezela ngee-tunnels kwizicelo ezithile kunokuba bonke be-LAN beenkampani. Ngoko ke, abasebenzisi kwi-SSL VPN ukuxhumeka bangakwazi ukufikelela kuphela kwizicelo ezilungiselelwe ukufikelela kuzo kunethiwekhi yonke. Okwesibini, kulula ukubonelela ngamalungelo ahlukeneyo okufikelela kubasebenzisi abahlukeneyo kunye nokulawula okungaphezulu kwegranular phezu kokufikelela komsebenzisi.

Umgca we-SSL VPN nangona ufikelela kwisicelo (s) ngokusebenzisa isiphequluli sewebhu esithetha ukuba bayasebenza kuphela kwizicelo ezisekelwe kwiwebhu. Kunokwenzeka ukuba i-intanethi inike ezinye iifowuni ukwenzela ukuba bakwazi ukufikelela kwi-SSL VPN, nangona ukwenza oko kwongeza kwinkimbinkimbi yesisombululo kunye nokuphelisa ezinye iinkqubo.

Ukufikelela ngokukhawuleza kuphela kwizicelo ze-SSL ezinikezelwe ngewebhu kubonisa ukuba abasebenzisi abanakho ukufikelela kwizixhobo zonxibelelwano ezifana nabashicileli okanye ukugcinwa kwendawo kunye kwaye abakwazi ukusebenzisa i-VPN yokwabelana ngefayile okanye iifayile zokukhuphela.

I-SSL VPN iye yafumana ukuxhaphaka nokuthandwa; nangona kunjalo asiyisisombululo esifanelekileyo kwimeko nganye. Ngokufanayo, i-IPSec VPN ayifanelekanga kwimeko nganye. Abathengisi bayaqhubeka nokuphuhlisa iindlela zokwandisa ukusebenza kwe-SSL VPN kwaye iteknoloji ekufuneka uyibukele ngokukhawuleza xa usemakethikeni isisombululo esiphezulu sokunxibelelanisa inethiwekhi. Okwangoku, kubalulekile ukuqwalasela ngenyameko iimfuno zabasebenzisi bakho basemagqabini kwaye ulinganise ubuchule kunye neengxaki kwisisombululo ngasinye ukufumanisa oko kusebenza kakuhle kuwe.