透過您的圖書館登入
IP:18.222.37.169
  • 學位論文

企業虛擬私有網路下安全連線機制之研究-以某油壓機械集團為例

Research of Secure Connection System under Enterprise Virtual Private Network – A Case Study of a Hydraulic Machinery Company Group

指導教授 : 簡宏宇
若您是本文的作者,可授權文章由華藝線上圖書館中協助推廣。

摘要


隨著企業全球化的運籌營運,以及科技的高速發展,企業與分公司間的通訊品質要求越來越高,於是尋求高品質的連線方式成了企業非常重要的一環。在傳統的連線方式通常都是採用ISP(Internet Service Provider)網路服務供應商所提供的私有網路服務,但是所付出的建構成本可是相當高的。 虛擬私有網路(IPSec VPN)技術的成熟,提供了企業有了更多的選擇,因虛擬私有網路使用加密通道(Tunneling)的連線技術,是透過公眾網際網路來虛擬出一條專屬於企業的虛擬私有網路。所以企業只需負擔上網的費用,即可節省向ISP業者另外承租專線的費用,而如何確保安全性,則是本研究的重點。 另外針對在外工作人員,也可有安全的作業連線環境,採用SSL-VPN加密機制建立Tunneling通道,與企業內部連線,使用起來與在內部網路相同。使在外工作人員也可存取內部網路資訊,對於在外工作人員資訊的即時取得有將會有相當大的幫助。 本研究將以個案企業,以目前連線架構分析,並在網路連線機制中,探討出符合企業的虛擬私有網路安全連線方式,在不影響公司整體運作及使用習慣下,以現有的網路設備,建構出符合企業與分公司間Site To Site架構的虛擬私有網路連線與End To Site的SSL-VPN連線。結合實際操作架設後,並以封包擷取軟體取回封包分析,驗證所建構的虛擬私有網路的安全性。

並列摘要


As corporate globalization logistics operations, as well as the rapid development of science and technology, business and the quality of communication between branch offices have become increasingly demanding, so to find high-quality connection methods has become a very important part of business. In the traditional approach is usually used to connect ISP (Internet Service Provider) provided by Internet service providers, private network services, but pay the cost of construction is very high. Virtual private network (IPSec VPN) technology to mature, providing enterprises have more choices because of the virtual private network using an encrypted channel (Tunneling) connection technology, is through the public Internet to a virtual out an exclusive enterprise virtual private network. Therefore, enterprises only need to pay the cost of Internet access could be saved in addition to the ISP industry the cost of leased line, but how to ensure security is the focus of this study. Also for the outside staff, but also a safe environment for operating connections using SSL-VPN encryption mechanism is established Tunneling channel, and internal connections with the internal network to use the same. So that staff can access outside the internal network information for the outside staff to obtain a real-time information will be of great help. This study will be cases of enterprises so as to connect the present framework of analysis and network connectivity mechanisms, explored in line with corporate virtual private network security connection manner, not affect the overall operation and the use of custom under the existing network equipment to construct a branch line between business and Site To Site architecture virtual private network connection with the Host To Site of the SSL-VPN connection. After erection with the actual operation and to recover the packets packet capture analysis software to verify the constructed virtual private network security.

參考文獻


[1]吳効憲(2007),各種系統環境下防火牆及IPSec機制研究與建置,碩士論文,朝陽科技大學。
[2]秦新發(2002),虛擬私有網路VPN之建置研究,碩士論文,國立中央大學資訊管理研究所。
[3] 王俊發(2008),以MPLS 技術完成企業網路(VPN)之整合電信服務,碩士論文,義守大學資訊工程研究所。
[4]葉輝煌(2005),動態IP網路中實行IPSec VPN,碩士論文,國立台灣科技大學資訊工程系。
[5]王百輝(2003),使用OpenSSL實現安全的FTP伺服器,碩士論文,國立高雄第一科技大學電腦與通訊工程系。

延伸閱讀