|
|
 |
µ¥ÀÌÅÍ ½ÃÆ®
Cisco Catalyst 6500 Series ¹× Cisco 7600 Series¿ë IPSEC VPN Services Module (VPNSM)
¾÷¹«¿¡ ÇʼöÀûÀÎ °í´ë¿ª ºñÁî´Ï½º ¾ÖÇø®ÄÉÀ̼ÇÀ¸·Î ÀÎÇØ ¾ðÁ¦ ¾îµð¼³ª ¾×¼¼½º°¡ °¡´ÉÇÑ À¯ºñÄõÅͽº ¿¬°á°ú Çâ»óµÈ ¼º´ÉÀÌ ÇÊ¿äÇÏ°Ô µÇ¾ú½À´Ï´Ù. ±â¾÷°ú ¼ºñ½º Á¦°ø¾÷ü¿¡¼´Â ³ôÀº ¼º´É°ú ¾ÈÀüÇÑ ¿¬°áÀÌ ÇÊ¿äÇÕ´Ï´Ù. »ó´ç¼ö ±â¾÷¿¡¼´Â ÀÌ·¯ÇÑ »õ·Î¿î ¿¬°á ¿ä±¸»çÇ×À» ÃæÁ·ÇÏ ±â À§ÇØ ±âÁ¸ WANÀ» »çÀÌÆ® °£ VPN ¹× ¿ø°Ý ¾×¼¼½º VPNÀ¸·Î È®ÀåÇϰųª ´ëüÇϰí ÀÖ½À´Ï´Ù. ¼ºñ½º Á¦°ø¾÷üµµ °¡»óÈµÈ ³×Æ®¿öÅ© ±â ¹Ý VPNÀ» ºñ·ÔÇÑ °ü¸®Çü VPN ¼ºñ½º¸¦ Á¦°øÇϰí ÀÖ½À´Ï´Ù.
±×¸² 1. Cisco Catalyst 6500 Series ¹× Cisco 7600 Series¿ë Cisco IPSec VPN

Services Module Cisco® IPSec VPN Services Module(VPNSM)Àº °æÁ¦ÀûÀÎ ºñ¿ëÀ¸·Î Cisco Catalyst® 6500 Series ½ºÀ§Ä¡¿Í Cisco 7600 Series ¶ó¿ìÅÍ¿¡ VPN ¼º´ÉÀ» Á¦°øÇÕ´Ï´Ù. Cisco IPSec VPNSM¿¡¼ Á¦°øÇÏ´Â ÁÖ¿ä VPN ±â´ÉÀº ´ÙÀ½°ú °°½À´Ï´Ù.
• ³×Æ®¿öÅ© ÀÎÇÁ¶ó¿¡ ÅëÇÕµÈ º¸¾È ±â´É- Cisco IPSec VPNSMÀº Cisco Catalyst 6500 Series ½ºÀ§Ä¡¿Í Cisco 7600 Series ¶ó¿ìÅ͸¦ Áö¿øÇÕ´Ï ´Ù. ÀÌ·¯ÇÑ ÀÎÇÁ¶ó Ç÷§Æû¿¡ VPNÀ» ÅëÇÕÇϸé, ¿À¹ö·¹ÀÌ ÀåÄ¡³ª ³×Æ®¿öÅ©¸¦ º°µµ·Î º¯°æÇÏÁö ¾Ê¾Æµµ ³×Æ®¿öÅ©¸¦ º¸È£ÇÒ ¼ö ÀÖ½À´Ï´Ù. ¶ÇÇÑ, ´Ù ¾çÇÑ Á¾·ùÀÇ LAN/WAN ÀÎÅÍÆäÀ̽º¿Í VPN, ¹æÈº®, ³×Æ®¿öÅ© ÀÌ»ó Çö»ó ŽÁö, ħÀÓ Å½Áö ¹× ¹æÁö, ÄÁÅÙÃ÷ ¼ºñ½º, SSL(Secure Sockets Layer), ¹«¼± LAN°ú °°Àº ¸ðµç º¸¾È ¼ºñ½º ¸ðµâÀ» µ¿ÀÏÇÑ Ç÷§Æû ³»¿¡¼ »ç¿ëÇÒ ¼ö ÀÖ½À´Ï´Ù.
• °í¼º´É- °¢ Cisco IPSec VPNSMÀº ÃֽоÏÈ£È Çϵå¿þ¾î °¡¼Ó ±â¼úÀ» »ç¿ëÇÏ¿© 500¹ÙÀÌÆ® ÀÌ»óÀÇ Å« ÆÐŶ¿¡¼ ÃÖ´ë 1.9 Gbps 3DES(Triple Data Encryption Standard) Æ®·¡ÇȰú IMIX(Internet Mix Traffic)¿¡¼ Á¤ÀÇÇÑ Æò±Õ ÆÐŶ Å©±â¿¡¼ ÃÖ´ë 1.6 GbpsÀÇ 3DES Æ® ·¡ÇÈÀ» Àü´ÞÇÒ ¼ö ÀÖ½À´Ï´Ù.
• È®À强- Cisco IPSec VPNSMÀº ÃÖ´ë 8000°³ÀÇ »çÀÌÆ® °£ IPSec ¶Ç´Â ¿ø°Ý ¾×¼¼½º IPSec ÅͳÎÀ» µ¿½Ã¿¡ Á¾·áÇÒ ¼ö ÀÖÀ¸¸ç ÃÊ ´ç ÃÖ´ë 65°³ ÀÇ ¼Óµµ·Î »õ·Î¿î ÅͳÎÀ» ±¸¼ºÇÒ ¼ö ÀÖ½À´Ï´Ù. ¶ÇÇÑ, DMVPN(Dynamic Multipoint VPN)À» »ç¿ëÇÏ¿© ºÎºÐ ¸Þ½¬ ¶Ç´Â Àüü ¸Þ½¬ IPSec VPNÀ» Çãºê-½ºÆ÷Å© ÅäÆú·ÎÁö»ó¿¡ µ¿ÀûÀ¸·Î ¹èÄ¡ÇÒ ¼ö ÀÖ½À´Ï´Ù.
• VPN º¹¿ø·Â ¹× °í°¡¿ë¼º- Cisco IPSec VPNSMÀº Çõ½ÅÀûÀÎ ±â´ÉÀ» »ç¿ëÇÏ¿© VPN º¹¿ø·Â°ú ³ôÀº °¡¿ë¼ºÀ» Á¦°øÇÕ´Ï´Ù. ÀÌ·¯ÇÑ ±â´É¿¡´Â IPSec ¹× GRE(Generic Routing Encapsulation)¸¦ À§ÇÑ »óÅ º¸Á¸Çü Àå¾Ö º¹±¸, HSRP+RRI(Hot Standby Router Protocol with Reverse Route Injection), DPD(Dead Peer Detection), »çÀÌÆ® °£ ÅͳÎÀ» ÅëÇÑ µ¿Àû ¶ó¿ìÆÃ ¾÷µ¥ÀÌÆ® Áö¿ø µîÀÌ ÀÖ½À´Ï´Ù.
• °í±Þ º¸¾È ¼ºñ½º Á¦°ø- °·ÂÇÑ ¾ÏÈ£È, ÀÎÁõ ¹× ³×Æ®¿öÅ©¿ÍÀÇ ÅëÇÕÀ» Cisco IPSec VPNSM¿¡ ½±°Ô Ãß°¡ÇÒ ¼ö ÀÖ½À´Ï´Ù. ÀÌÁ¦ ÅëÇÕÇü µ¥ÀÌÅÍ, À½¼º ¹× ºñµð¿À Áö¿ø VPN, SAN(Storage Area Networks), IPSec/MPLSÀÇ ÅëÇÕÀ» ºñ·ÔÇÑ Ä·ÆÛ½º ¹× ¼ºñ½º Á¦°ø¾÷üÀÇ ¾ÈÀüÇÑ ¿¡Áö VPN ¾ÖÇø®ÄÉÀ̼ÇÀ» ½±°Ô ¹èÄ¡ÇÒ ¼ö ÀÖ½À´Ï´Ù. Cisco IPSec VPNSMÀº LAN ¹× WAN ÀÎÅÍÆäÀ̽º¸¦ ÅëÇØ °í±Þ »çÀÌÆ® °£ IPSec ¹× ¿ø°Ý ¾×¼¼½º IPSec ¼ºñ½º¸¦ Á¦°øÇÕ´Ï´Ù. Cisco IPSEC VPNSM °³¿ä Cisco IPSec VPNSMÀº Cisco Catalyst 6500 Series ¹× Cisco 7600 Series ¼¨½Ã¿¡ ÀåÂøµÇ´Â Ç® ½½·Ô Ä«µåÀÔ´Ï´Ù. ÀÌ Ä«µå¿¡´Â ¹°¸®Àû WAN ¶Ç ´Â LAN ÀÎÅÍÆäÀ̽º°¡ ¾ø´Â ´ë½Å Ç÷§ÆûÀÇ LAN ¹× WANÀ» Ȱ¿ëÇÕ´Ï´Ù.
Ç¥ 1Àº Cisco IPSec VPNSM ±â´É¿¡ ´ëÇÑ ÀÚ¼¼ÇÑ ¼³¸íÀ̸ç, Ç¥ 2´Â ºÎ ǰ ¹øÈ£¸¦ ³ªÅ¸³À´Ï´Ù.
Ç¥ 1. Cisco IPSec VPNSM ±â´É
Ç¥ 2. ºÎǰ ¹øÈ£ ¹× ÁÖ¹® Á¤º¸
±â¼ú ¿ä¾à
VPN Åͳθµ
• IPSec(RFC 2401-2411, 2451)
¾ÏÈ£È
• ESP(Extended Services Processor), DES ¹× 3DES(RFC 2406, 2451)
ÀÎÁõ
• X.509 µðÁöÅÐ ÀÎÁõ¼(RSA ¼¸í)
• ¹Ì¸® °øÀ¯µÈ Ű
• SCEP(Simple Certificate Enrollment Protocol)
• RADIUS (RFC 2138)
• TACACS+
• CHAP(Challenge Handshake Authentication Protocol) ¹× PAP(Password Authentication Protocol) (RFC 1994)
¹«°á¼º
• HMAC-MD5(Hashed Message Authentication Code with Message Digest 5) ¹× HMAC-SHA-1(Hashed Message Authentication Code with Secure Hash Algorithm-1) (RFC 2403- 2404)
Ű °ü¸®
• Internet Key Exchange) (RFC 2407-2409)
• IKE-XAUTH
• IKE-CFG-MODE
CA/PKI Áö¿ø
• Entrust
• VeriSign
• Microsoft
• Netscape
• IPlanet
• Baltimore Technologies
°í°¡¿ë¼º
• HSRP+RRI(Reverse Route Injection)
• ¼¨½Ã ³»(ºí·¹À̵å-ºí·¹À̵å) Active/Active IPSec Stateful Failover
• ¼¨½Ã °£(¼¨½Ã-¼¨½Ã) Active/Standby IPSec PSec Stateful Failover
• DPD (Dead Peer Detection)
• IPSec¸¦ ÅëÇÑ µ¿Àû ¶ó¿ìÆÃ
°ü¸® ¿É¼Ç
• CiscoWorks VMS ¹× Router MC
• Cisco ISC
• SSH(Secure Shell) ¶Ç´Â Kerberized ÅÚ³ÝÀ» »ç¿ëÇÏ´Â ¾ÈÀüÇÑ Ä¿¸Çµå ¶óÀÎ ÀÎÅÍÆäÀ̽º(CLI)
¶ó¿ìÆÃ ÇÁ·ÎÅäÄÝ
• BGP(Border Gateway Protocol) Version 4
• RIP(Routing Initiation Protocol) ¹× RIP ¹öÀü 2(RIPv2)
• OSPF(Open Shortest Path First)
• EIGRP(Enhanced Interior Gateway Routing Protocol) ¹× IGRP
• IS-IS(Intermediate System-to-Intermediate System)
³»ÀåÇü ÀÎÅÍÆäÀ̽º
• ¾øÀ½
Áö¿øµÇ´Â ¼öÆÛ¹ÙÀÌÀú ¿£Áø
• Cisco Catalyst 6500 Series Supervisor Engine 2 - MSFC2(Multilayer Switch Feature Card 2) Æ÷ÇÔ
• Cisco Catalyst 6500 Series Supervisor Engine 720 - PFC(Policy Feature Card)-3A, PFC-3B ¶Ç´Â PFC-3BXL Æ÷ÇÔ
Áö¿øµÇ´Â ¸ðµâ ¹× ÀÎÅÍÆäÀ̽º
• LAN ÀÎÅÍÆäÀ̽º
- ¸ÖƼÆ÷Æ® °í¼Ó ÀÌ´õ³Ý
- ÀζóÀÎ Àü¿øÀÌ ÀÖ´Â ¸ÖƼÆ÷Æ® °í¼Ó ÀÌ´õ³Ý
- ¸ÖƼÆ÷Æ® ±â°¡ºñÆ® ÀÌ´õ³Ý
- 10 ±â°¡ºñÆ® ÀÌ´õ³Ý
• WAN ÀÎÅÍÆäÀ̽º
- FlexWAN ¹× °í±Þ FlexWAN
- OSM(Optical Services Module) ¹× °í±Þ OSM
- ±â°¡ºñÆ® ÀÌ´õ³Ý WAN(GE-WAN) ¹× °í±Þ GE
- WAN
- ´ÜÀÏ ¹× ÀÌÁß Æ÷Æ® T3/E3
- ´ÜÀÏ ¹× ÀÌÁß Æ÷Æ® HSSI(High-Speed Serial Interface)
- ¸ÖƼÆ÷Æ® T1/E1
- ¸ÖƼä³Î T1/T3/E3
- OC- 3 ATM ½Ì±Û¸ðµå ¹× ¸ÖƼ¸ðµå
- OC-3 POS(Packet Over SONET) ½Ì±Û¸ðµå ¹× ¸ÖƼ¸ðµå
- OC-12 ATM ½Ì±Û¸ðµå ¹× ¸ÖƼ¸ðµå
- OC-12 POS ½Ì±Û¸ðµå ¹× ¸ÖƼ¸ðµå
- OC-48 POS ½Ì±Û¸ðµå
- OC-48 POS-DPT(Dynamic Packet Transport) ´ÜÀÏ ¸ðµå
• µ¿ÀÏ ¼¨½Ã¿¡ ÀÖ´Â Ãß°¡ÀûÀÎ º¸¾È ¹× ³×Æ®¿öÅ© ¼ºñ½º ¸ðµâ
- Cisco Catalyst 6500 Series FWSM(Firewall Services Module)
- Cisco Catalyst 6500 Series IDSM-2(Intrusion Detection Services Module 2)
- Cisco Catalyst 6500 Series NAM(Network Analysis Module)-1 ¹× NAM-2
- Cisco Catalyst 6500 SSL Services Module
- Cisco Catalyst 6500 Series CSM(Content Switching Module)
- Cisco Catalyst 6500 Series MWAM(Multiprocessor WAN Application Module)
- Cisco Catalyst 6500 Series WLSM(Wireless LAN Services Module)
Cisco IOS Software Áö¿ø(°íÀ¯ Cisco IOS Software ¸ðµå)
• Cisco IOS Software Release 12.2(18)SXD1 (Cisco Catalyst 6500 Series Supervisor Engine 2 ¹× Supervisor Engine 720)
• Cisco IOS Software Release 12.2(18)SXD (Cisco Catalyst 6500 Series Supervisor Engine 2 ¹× Supervisor Engine 720)
• Cisco IOS Software Release 12.2(17d)SXB (Cisco Catalyst 6500 Series Supervisor Engine 2 ¹× Supervisor Engine 720)
• Cisco IOS Software Release 12.2(17b)SXA (Cisco Catalyst 6500 Series Supervisor Engine 720 Àü¿ë)
• Cisco IOS Software Release 12.2(14)SY (Cisco Catalyst 6500 Series Supervisor Engine 2 Àü¿ë)
<¾÷µ¥ÀÌÆ®: 2005³â 6¿ù 16ÀÏ>
|
|
Cisco¿¡ ¹®ÀÇÇϼ¼¿ä
- ÀϹݹ®ÀÇ 080-377-0880
Á¦Ç°/±¸¸Å 080-808-8082
|
|