
虚拟专用网 (Virtual Private Network)

A Virtual Private Network or VPN is a private telecommunications network was established between subjects using a system of public broadcasting and shared such as the Internet. The purpose of VPN is to give companies the same opportunity to rent private lines at a lower cost by using shared public networks.

虚拟专用网络或VPN是使用公共广播和共享系统(例如Internet)在对象之间建立的专用电信网络。 VPN的目的是为公司提供通过共享公共网络以较低成本租用专线的相同机会。

VPN功能 (VPN Features)

The networks use VPN connections that require authentication to ensure that only authorized users can access, to ensure the security data sent across the Internet will not be intercepted or used by others not authorized, they use encryption.


VPNs secure protocols shall therefore ensure that encrypt the traffic transiting the VPN. In addition to encryption, a secure VPN to provide its protocols of the mechanisms that prevent security breaches such as identity theft or alteration of digital messages.

因此,VPN安全协议应确保对通过VPN的流量进行加密。 除加密外,安全VPN还提供其机制的协议,以防止安全漏洞,例如身份盗用或数字消息的更改。

The term VPN is a generic term and not a brand. In particular, there is no body that regulates the designation of a product as a VPN, so that individual producers can use at will.

术语VPN是通用术语,而不是品牌。 特别是,没有任何机构来规范将产品指定为VPN,以便各个生产者可以随意使用。

However, there are several independent bodies, widely recognized certifying interoperability and security of computer systems, such as ICSA Labs. A device or software, that includes the trademark of ICSA Labs IPSec VPN, has certainly undergone a series of objective tests and replicable, which ensures compatibility with all other implementations certified and an adequate level of security. It is now generally accepted that a properly designed VPN has a degree of security comparable to that of a dedicated network. Using a VPN, using an Internet connection, for example, is able to connect to the private network from outside your office.

但是,有几个独立的机构,例如ICSA Labs,被公认为计算机系统的互操作性和安全性。 带有ICSA Labs IPSec VPN商标的设备或软件当然已经经过一系列客观测试和可复制性,以确保与经认证的所有其他实现方式的兼容性以及足够的安全性。 现在,人们普遍认为,经过适当设计的VPN具有与专用网络相当的安全性。 使用VPN(例如,使用Internet连接)可以从办公室外部连接到专用网络。

Generally, a VPN consists of two parts: one inside the network, and therefore protected, which preserves the transmission, and a less reliable and secure which is outside the private network, such as via the Internet. The VPN is usually a firewall between the computer of the employee or a customer and the terminal or network server. The employee, for example, when establishing the connection with the firewall, it must authenticate the data that wants to transmit, via an authentication service inside.

通常,VPN由两部分组成:一部分在网络内部,因此受到保护(保留了传输),而可靠性和安全性较差(例如通过Internet)在专用网络外部,可靠性较低。 VPN通常是员工或客户的计算机与终端或网络服务器之间的防火墙。 例如,员工在与防火墙建立连接时,必须通过内部的身份验证服务对要传输的数据进行身份验证。

An authenticated user may be provided with special privileges to access resources that are generally not accessible to all users. Most programs require that all the client’s IP VPN traffic will pass through a “tunnel” between the virtual networks using the Internet as a means of connection. From the point of view this means that while the VPN connection is active, all access outside the secure network must pass through the same firewall as if the user were physically connected within the secure network. This reduces the risk that external users can access the private network of the company.

可以向已认证的用户提供特殊特权,以访问通常不是所有用户都可以访问的资源。 大多数程序都要求所有客户端的IP VPN通信都将使用Internet作为连接手段,通过虚拟网络之间的“隧道”。 从角度来看,这意味着在VPN连接处于活动状态时,安全网络外部的所有访问都必须通过相同的防火墙,就好像用户已物理连接到安全网络中一样。 这降低了外部用户可以访问公司专用网络的风险。

The security of the VPN connection is crucial, because the network on which the other computers are working may not be secure, or only partially. The VPN must guarantee a level of security that protects the computers of employees who are working simultaneously on the same network, among which one could be infected with a virus, worm or Trojan.

VPN连接的安全性至关重要,因为其他计算机正在使用的网络可能不安全,或仅部分安全。 VPN必须保证一定的安全级别,以保护在同一网络上同时工作的员工的计算机,其中可能感染了病毒,蠕虫或特洛伊木马。

VPN类型 (Types of VPN)


受信任的VPN (Trusted VPN)

Ensuring that the network is trusted VPN provides security that no unauthorized third party may use the circuit of the customer. This implies that the customer has its own IP address and its own security policy.

确保网络是受信任的VPN提供的安全性是未经授权的第三方不得使用客户的电路。 这意味着客户拥有自己的IP地址和自己的安全策略。

The circuit travels through one or more “switches” of communication that can be compromised by those who want to disrupt network traffic. The customer of a VPN is therefore expected that the provider (ISP) maintains the integrity of the VPN circuit to prevent intruders.

电路经过一个或多个通信“开关”,这些开关可能会受到那些希望破坏网络流量的人的破坏。 因此,VPN的客户应该期望提供商(ISP)保持VPN电路的完整性以防止入侵者。

Companies that use a Trusted VPN want to be sure that their data moves through a series of routes that have specific properties and which are controlled by an ISP (Internet Service Provider). The customer then has confidence that the paths through which these data are kept safe move according to the criteria of a previous agreement, although generally the customer does not know what are the paths used by the provider of Trusted VPN.

使用Trusted VPN的公司希望确保其数据通过一系列具有特定属性并由ISP(互联网服务提供商)控制的路由。 然后,客户有信心确保这些数据安全通过的路径根据先前协议的标准移动,尽管通常客户不知道Trusted VPN提供商使用的路径是什么。

可信VPN要求 (Trusted VPN Requirements)

No one outside of the provider of Trusted VPN can affect the creation or modification of the VPN route. No one outside of the trust can change any part of the VPN. No one outside of the provider of Trusted VPN can modify the data input or those removed from the path of the VPN.

Trusted VPN提供商之外的任何人都不会影响VPN路由的创建或修改。 信任之外的任何人都不能更改VPN的任何部分。 Trusted VPN提供商之外的任何人都不能修改数据输入或从VPN路径中删除的数据。

The data traveling in different pathways that are shared by multiple customers of the supplier, the path must be specified by the VPN and no one except the trusted provider can edit the various data. The location and the address used in a trusted VPN must be established before the VPN is created.

由供应商的多个客户共享的,以不同路径传播的数据,该路径必须由VPN指定,并且除了受信任的提供者之外,没有人可以编辑各种数据。 在创建VPN之前,必须先建立可信VPN中使用的位置和地址。

The customer must know what they expect from the supplier, so that both can plan and create the network for which they are collaborating.


Trusted VPN使用的技术 (Technologies used by the Trusted VPN)

The technologies used are divided into Layer 2 and Layer 3;


第2层 (Layer 2)

  • Circuits ATM (Asynchronous Transfer Mode)电路ATM(异步传输模式)
  • Transmission circuits传输电路
  • Layer 2 transport over MPLSMPLS上的第2层传输

第三层 (Layer 3)

  • MPLS with limited distribution information of the route through BGP (Border Gateway Protocol).具有通过BGP(边界网关协议)的路由的有限分发信息的MPLS。



翻译自: https://www.eukhost.com/blog/webhosting/virtual-private-network-part-1/


拨号和虚拟专用专用设置_虚拟专用网| 第1部分相关推荐

  1. 拨号和虚拟专用专用设置_虚拟专用网| 第三部分

    拨号和虚拟专用专用设置 安全VPN-协议 (Secure VPN  - The protocols) The Secure VPN tunnel using cryptographic protoco ...

  2. 防火墙下面的找不到专用网络设置,并且域网络、专用网络是灰的关不掉

    #问题描述 1.防火墙下面的专用网络设置未显示出来 2.域网络.专用网络是灰的关不掉 3.点击 使用推荐设置 或 高级设置 提示错误:防火墙无法更改某些设置,错误代码0x80074200 处理方法: ...

  3. 高科路由器有虚拟服务器设置吗,高科Q307R路由器安装(设置)_怎么设置高科路由器-168路由网...

    下面主要介绍高科(GAOKE)Q307R无线路由器的安装.上网设置.无线WiFi设置. 一台新购买回来(恢复出厂设置后)的高科Q307R路由器,要连接Internet上网,需要经过以下几个设置步骤: ...

  4. 华为虚拟home键关闭_华为手机音量忽大忽小,不妨打开这3个开关调整,音量变大变清晰...

    华为手机音量忽大忽小,不妨打开这3个开关调整,音量变大变清晰 手机现在已经不仅仅是一个通讯工具,日常生活听歌.看剧.打游戏来供人们娱乐,倘若手机音量忽大忽小,是非常影响我们娱乐的体验感,还有电话声忽大 ...

  5. windows防火墙设置_详解关闭Windows防火墙操作技巧,让你彻底断开与外网的连接...

    如果Windows防火墙干扰了网络连接,请按照以下步骤完全关闭或禁用Windows防火墙. 为了保护系统免受未经授权的传入和传出连接的侵害,Windows拥有内置的防火墙管理系统.使用Windows防 ...

  6. 磊科路由虚拟服务器设置,磊科路由器虚拟转发服务设置的方法

    磊科路由器虚拟转发服务设置的方法 磊科路由的虚拟 MAC 地址的分配功能实现了不同主机将流量发送给备份组中不同的路由器,但为了使备份组中的路由器能够转发主机发送的流量,还需要在路由器上创建虚拟转发器, ...

  7. 虚拟主机是设置在httpd-vhosts.conf还是vhosts.conf还是httpd.conf

    https://blog.csdn.net/weisubao/article/details/43536723 解决方案:虚拟主机是设置在httpd-vhosts.conf还是vhosts.conf还 ...

  8. linux设置默认终端模拟器,ubuntu终端默认设置_在Ubuntu Linux上设置默认终端模拟器...

    ubuntu终端默认设置_在Ubuntu Linux上设置默认终端模拟器 ubuntu终端默认设置_在Ubuntu Linux上设置默认终端模拟器 ubuntu终端默认设置 Ubuntu has a ...

  9. 虚拟服务器英文版设置,apache配置(linux及windows中的设置)以及虚拟主机的设置(国外英语资料).doc...

    apache配置(linux及windows中的设置)以及虚拟主机的设置(国外英语资料) apache配置(linux及windows中的设置)以及虚拟主机的设置 Syllabus Apache in ...


  1. 一文了解 lambda 用法与源码分析
  2. flutter打开第三方应用
  3. java中使用lua脚本
  4. mvc 怎么把后台拼接好的div写到前台_MVC 从后台页面 取前台页面传递过来的值的几种取法...
  5. 数电与模电的根本区别 转
  6. 操作系统 第一章 计算机系统概述
  7. 弃用 32 位!所有基于 IntelliJ 的 IDE 将不再支持 32 位操作系统
  8. Tomcat服务器搭建及测试教程(1),腾讯技术官发布的“神仙文档”火爆网络
  9. 关于vmvare网络连接方式的介绍与实践
  10. Nuxt.Js爬坑小记
  11. java 进制转换 栈 链表_c语言链表栈实现进制转换
  12. assert()理解
  13. Mac上的全局翻译利器 : Bob + PopClip
  14. 网吧网管新人对无盘技术不熟
  15. Android:一篇就够!全面详细解析APN(涉及内容:GGSN,authtype,MVNO,pdp,Apns-conf,supl,hipri,dun)
  16. 【Linux】一步一步学Linux——VMware Workstation 15 Pro安装图解教程(06)
  17. 台式计算机打印机共享,电脑不能共享打印机怎么办 电脑设置共享打印机详细教程...
  18. HTML如何实现多个空格
  19. jq 移动端网页分享功能_js实现QQ、微信、新浪微博分享功能
  20. 图片损坏修复软件,分享好用靠谱的软件


  1. 我从外包辞职了,10000小时后,走进字节跳动拿了offer
  2. 出招分析_饿狼传说9狼之印记
  3. 服务器如何做中转进行端口映射,使服务器之间通信,然后访问目标网站(baidu.com)
  4. 陕西省初级职称评审条件真的很简单
  5. Java之美[从菜鸟到高手演练]之Arrays类及其方法分析
  6. 未能添加对Windows.Devices.Bluetooth.dll的引用。请确保此文件可访问并且是一个有效的程序集或COM组件
  7. 90%的人都有的图表使用误区,赶紧看看自己是否中招
  8. 电脑计算机和算盘童话作文,网路_童话作文嫦娥玩电脑700字小学生作文
  9. service unavailable
  10. 我与python约个会:09.程序编程基础3~组合数据类型