IPSec SA(2´Ü°è)
ÀÚµ¿ ŰÀÇ IPSec SA¸¦ ¼³Á¤ÇÕ´Ï´Ù. »õ·Î¿î IPSec SA¸¦ Ãß°¡Çϰųª ÀÌ¹Ì µî·ÏµÈ IPSec SA¸¦ È®ÀÎÇÏ°í ¼öÁ¤,
»èÁ¦ÇÒ ¼ö ÀÖ½À´Ï´Ù. ¼³Á¤ÇÑ IPSec SA´Â IPSec VPN ÅäÆú·ÎÁö¸¦ ±¸¼ºÇÒ¶§ »ç¿ëÇÕ´Ï´Ù.
Âü°í
ÀúÀåÇϱ⸦ ´©¸£¸é ÇöÀç ³»¿ëÀ» CSV ÆÄÀÏ·Î ÀúÀåÇÒ
¼ö ÀÖ½À´Ï´Ù.
IPSec SA Ãß°¡
IPSec SA¸¦ Ãß°¡ÇÏ´Â ¹æ¹ýÀº ´ÙÀ½°ú °°½À´Ï´Ù.
- ÇÁ·ÎÆÄÀÏ ¼³Á¤ ¿µ¿ªÀÇ VPN > IPSec VPN > IPSec VPN ¼³Á¤ > IPSec VPN
Ű ¼³Á¤ > IPSec SA(2´Ü°è)¸¦ ¼±ÅÃÇÕ´Ï´Ù. °ü¸®ÇÏ´Â ÀåºñÀÇ Á¾·ù°¡ µÎ °¡Áö ÀÌ»óÀÎ °æ¿ì AhnLab TrusGuard > VPN > IPSec VPN > IPSec
VPN ¼³Á¤ > IPSec VPN Ű ¼³Á¤ > IPSec SA(2´Ü°è)ÀÔ´Ï´Ù.
- ´ÙÀ½ Áß ÇÑ °¡Áö ¹æ¹ýÀ» ¼±ÅÃÇÏ¿© IPSec SA Ãß°¡ ȸéÀ» ½ÇÇàÇÕ´Ï´Ù.
- IPSec SA ¸ñ·Ï¿¡¼ Ãß°¡¸¦
´©¸¨´Ï´Ù.
- IPSec SA ¸ñ·Ï¿¡¼ ¸¶¿ì½º ¿À¸¥ÂÊ ¹öưÀ» ´©¸£¸é ³ªÅ¸³ª´Â ¸Þ´º¿¡¼ Ãß°¡¸¦ ´©¸¨´Ï´Ù.
- Ãß°¡ ȸ鿡¼ ÇÊ¿äÇÑ Ç׸ñÀ» ¼³Á¤ÇÕ´Ï´Ù.
- À̸§: IPSec SA¸¦ ±¸ºÐÇÒ ¼ö ÀÖ´Â À̸§À» ÀÔ·ÂÇÕ´Ï´Ù.
- IPSec ÇÁ·ÎÅäÄÝ: IPSec SA¿¡¼ »ç¿ëÇÒ ÇÁ·ÎÅäÄÝÀ» ¼±ÅÃÇÕ´Ï´Ù.
- ESP: ESP (Encapsulation Security Payload) ÇÁ·ÎÅäÄÝÀ»
IPSec SA¿¡ »ç¿ëÇÕ´Ï´Ù. ESP´Â IP ÆäÀ̷ε忡 ´ëÇØ¼¸¸ µ¥ÀÌÅÍ ¿øº» ÀÎÁõ, µ¥ÀÌÅÍ ¹«°á¼º, Àç»ý ¹æÁö º¸È£,
¹«°á¼º ¿É¼ÇÀ» Á¦°øÇÕ´Ï´Ù.
- AH: AH (Authentication Header) ÇÁ·ÎÅäÄÝÀ» IPSec
SA¿¡ »ç¿ëÇÕ´Ï´Ù. AH´Â º¯°æÀÌ Çã¿ëµÈ IP Çì´õÀÇ Çʵ带 Á¦¿ÜÇϰí Àüü ÆÐŶ(ÆÐŶÀÇ IP Çì´õ ¹× µ¥ÀÌÅÍ ÆäÀ̷εå)¿¡
´ëÇÑ µ¥ÀÌÅÍ ¿øº» ÀÎÁõ, µ¥ÀÌÅÍ ¹«°á¼º, Àç»ý ¹æÁö º¸È£¸¦ Á¦°øÇÕ´Ï´Ù.
- Ű Çù»ó ÁÖ±â: Ű Çù»ó Áֱ⸦ ¼³Á¤ÇÕ´Ï´Ù. Ű Çù»ó ÁÖ±â´Â ±âº»ÀûÀ¸·Î ½Ã°£À¸·Î
¼³Á¤ÇÒ ¼ö ÀÖÀ¸¸ç ÆÐŶ Å©±âÀÇ »ç¿ëÀ» ¼±ÅÃÇÏ¸é ÆÐŶ Å©±â·Îµµ ¼³Á¤ÇÒ
¼ö ÀÖ½À´Ï´Ù. Ű Çù»ó Áֱ⸶´Ù ¼¼¼Ç ۸¦ »õ·Î »ý¼ºÇÕ´Ï´Ù. ½Ã°£ÀÇ ±âº» °ªÀº 8½Ã°£À̸ç 1~24 »çÀÌÀÇ °ªÀ» ÀÔ·ÂÇÒ
¼ö ÀÖ½À´Ï´Ù. ÆÐŶ Å©±â´Â ±âº»ÀûÀ¸·Î »ç¿ëÇÏÁö ¾Êµµ·Ï ¼³Á¤µÇ¾î ÀÖ½À´Ï´Ù. ÆÐŶ Å©±âÀÇ ±âº» °ªÀº 10MBÀ̰í 1~4096
»çÀÌÀÇ °ªÀ» ÀÔ·ÂÇÒ ¼ö ÀÖ½À´Ï´Ù.
- PFS: PFS (Perfect Forward Secrecy)ÀÇ »ç¿ë ¿©ºÎ¸¦
¼±ÅÃÇÕ´Ï´Ù. PFS´Â ÇϳªÀÇ ¼¼¼Ç ۰¡ ³ëÃâµÇ¾îµµ ´Ù¸¥ ¼¼¼Ç ŰÀÇ ¾ÈÀüÀ» º¸ÀåÇÒ ¼ö ÀÖ´Â ±â´ÉÀÔ´Ï´Ù.
- DH ±×·ì: PFS¿¡ »ç¿ëÇÒ DH ±×·ì(Diffie-Hellman Group)À»
¼³Á¤ÇÕ´Ï´Ù. DH ±×·ìÀº 2, 5, 14, 16 °¡¿îµ¥¼ ¼±ÅÃÇÒ ¼ö ÀÖ½À´Ï´Ù.
- µ¥ÀÌÅÍ ¾ÐÃà: IPSec SA µ¥ÀÌÅ͸¦ ¾ÐÃàÇÕ´Ï´Ù.
- ¾Ë°í¸®Áò: IPSec SA¿¡ »ç¿ëÇÒ ¾Ë°í¸®ÁòÀ» ¼³Á¤ÇÕ´Ï´Ù.
- ¾ÏÈ£È ¾Ë°í¸®Áò: IPSec SA¿¡ »ç¿ëÇÒ ¾ÏÈ£È ¾Ë°í¸®ÁòÀ» ¼±ÅÃÇÕ´Ï´Ù. IPSec ÇÁ·ÎÅäÄÝÀ» ESP·Î
¼±ÅÃÇßÀ» ¶§¸¸ ³ªÅ¸³³´Ï´Ù. ÃÖ´ë 5°³±îÁö Ãß°¡ÇÒ ¼ö ÀÖ½À´Ï´Ù.
- 3DES: 3DES (Triple Data Encryption Standard)´Â
56ºñÆ®ÀÇ ÂªÀº Ű ±æÀ̸¦ °¡Áø DES (Data Encryption Standard)¸¦ º¸¿ÏÇÑ 168ºñÆ® ¾ÏÈ£È ¾Ë°í¸®ÁòÀÔ´Ï´Ù.
- AES-128: AES (Advanced Encryption Standard)´Â
3DES¸¦ ´ëüÇϱâ À§ÇØ °³¹ßµÈ ¾Ë°í¸®ÁòÀÔ´Ï´Ù. AES-128´Â 128ºñÆ® AES ¾Ë°í¸®ÁòÀÔ´Ï´Ù.
- AES-192: 192ºñÆ® AES ¾Ë°í¸®ÁòÀÔ´Ï´Ù.
- AES-256: 256ºñÆ® AES ¾Ë°í¸®ÁòÀÔ´Ï´Ù.
- SEED: ¹Î°£ ºÎ¹®¿¡¼ÀÇ Á¤º¸¸¦ º¸È£Çϱâ À§Çؼ Çѱ¹Á¤º¸º¸È£¼¾ÅÍ¿Í ETRI°¡
ÁÖµµÇÏ¿© °³¹ßÇÑ ´ëĪ Ű ¹æ½ÄÀÇ 128ºñÆ® ¾ÏÈ£È ¾Ë°í¸®ÁòÀÔ´Ï´Ù.
- Ãß°¡/»èÁ¦: ¼³Á¤ÇÑ ³»¿ëÀ» Ãß°¡Çϰųª »èÁ¦ÇÕ´Ï´Ù. Ãß°¡¸¦ ´©¸£¸é ¼³Á¤ÇÑ ³»¿ëÀ»
¸ñ·Ï¿¡ Ãß°¡ÇÕ´Ï´Ù. ¸¦ ´©¸£¸é ¼³Á¤ÇÑ ³»¿ëÀ» ¸ñ·Ï¿¡¼ »èÁ¦ÇÕ´Ï´Ù.
- ÇØ½Ã ¾Ë°í¸®Áò: IPSec SA¿¡ »ç¿ëÇÒ ÇØ½Ã ¾Ë°í¸®ÁòÀ» ¼±ÅÃÇÕ´Ï´Ù. ÃÖ´ë 5°³±îÁö
Ãß°¡ÇÒ ¼ö ÀÖ½À´Ï´Ù.
- SHA1: SHA1(Secure Hash Algorithm 1)˼ DSA (Digital
Signature Algorithm)¸¦ À§ÇØ °³¹ßµÈ ÇØ½Ã ¾Ë°í¸®ÁòÀÔ´Ï´Ù. MD5¿Í À¯»çÇÑ ±¸Á¶¸¦ °¡Áö°í ÀÖÀ¸³ª MD5º¸´Ù
¾ÈÀüÇÕ´Ï´Ù.
- SHA2-256: SHA2´Â SHA1º¸´Ù ³ôÀº ¼öÁØÀÇ ¾ÈÁ¤¼ºÀ» Á¦°øÇÏ´Â ÇØ½Ã
¾Ë°í¸®ÁòÀÔ´Ï´Ù. SHA2-256Àº 256ºñÆ®ÀÇ ÇØ½Ã Äڵ带 Ãâ·ÂÇÏ´Â SHA2 ¾Ë°í¸®ÁòÀÔ´Ï´Ù.
- SHA2-384: 384ºñÆ®ÀÇ ÇØ½Ã Äڵ带 Ãâ·ÂÇÏ´Â SHA2 ¾Ë°í¸®ÁòÀÔ´Ï´Ù.
- SHA2-512: 512ºñÆ®ÀÇ ÇØ½Ã Äڵ带 Ãâ·ÂÇÏ´Â SHA2 ¾Ë°í¸®ÁòÀÔ´Ï´Ù.
- HAS160: KCDSA (Korea Certification-based Digital
Signature Algorithm)¸¦ À§ÇØ °³¹ßµÈ ÇØ½Ã ¾Ë°í¸®ÁòÀÔ´Ï´Ù. 160ºñÆ®ÀÇ ÇØ½Ã Äڵ带 Ãâ·ÂÇÕ´Ï´Ù.
- Ãß°¡/»èÁ¦: ¼³Á¤ÇÑ ³»¿ëÀ» Ãß°¡Çϰųª »èÁ¦ÇÕ´Ï´Ù. Ãß°¡¸¦ ´©¸£¸é ¼³Á¤ÇÑ ³»¿ëÀ»
¸ñ·Ï¿¡ Ãß°¡ÇÕ´Ï´Ù. ¸¦ ´©¸£¸é ¼³Á¤ÇÑ ³»¿ëÀ» ¸ñ·Ï¿¡¼ »èÁ¦ÇÕ´Ï´Ù.
- ¼³¸í: IPSec SA¿¡ ´ëÇÑ ¼³¸íÀ» ÀÔ·ÂÇÕ´Ï´Ù. ¼³¸íÀº ¿µ¹®°ú ¼ýÀÚ¸¦ ±âÁØÀ¸·Î
127ÀÚ±îÁö ÀÔ·ÂÇÒ ¼ö ÀÖ½À´Ï´Ù. ÇѱÛÀ̳ª ÀϺ»¾î, Áß±¹¾î¿Í °°Àº 2¹ÙÀÌÆ® ¹®ÀÚ´Â ÇÑ ±ÛÀÚ°¡ 2ÀÚ·Î °è»êµË´Ï´Ù.
- È®ÀÎÀ» ´©¸¨´Ï´Ù.
IPSec SA ¼öÁ¤
IPSec SA¸¦ ¼öÁ¤ÇÏ´Â ¹æ¹ýÀº ´ÙÀ½°ú °°½À´Ï´Ù.
- ÇÁ·ÎÆÄÀÏ ¼³Á¤ ¿µ¿ªÀÇ VPN > IPSec VPN > IPSec VPN ¼³Á¤ > IPSec VPN
Ű ¼³Á¤ > IPSec SA(2´Ü°è)¸¦ ¼±ÅÃÇÕ´Ï´Ù. °ü¸®ÇÏ´Â ÀåºñÀÇ Á¾·ù°¡ µÎ °¡Áö ÀÌ»óÀÎ °æ¿ì AhnLab TrusGuard > VPN > IPSec VPN > IPSec
VPN ¼³Á¤ > IPSec VPN Ű ¼³Á¤ > IPSec SA(2´Ü°è)ÀÔ´Ï´Ù.
- ´ÙÀ½ Áß ÇÑ °¡Áö ¹æ¹ýÀ» ¼±ÅÃÇÏ¿© IPSec SA ¼öÁ¤ ȸéÀ» ½ÇÇàÇÕ´Ï´Ù.
- ¼öÁ¤ÇÒ Ç׸ñÀ» ¼±ÅÃÇÑ ´ÙÀ½ ¼öÁ¤À» ´©¸¨´Ï´Ù.
- ¼öÁ¤ÇÒ Ç׸ñÀ» ¸¶¿ì½º ¿À¸¥ÂÊ ¹öưÀ» ´©¸£¸é ³ªÅ¸³ª´Â ¸Þ´º¿¡¼ ¼öÁ¤À» ´©¸¨´Ï´Ù.
- IPSec SA¸¦ ¼öÁ¤ÇÑ ´ÙÀ½ È®ÀÎÀ»
´©¸¨´Ï´Ù.
- Àåºñ ¸ñ·Ï¿¡¼ Àåºñ¸¦ ¸¶¿ì½º
¿À¸¥ÂÊ ¹öưÀ¸·Î ´©¸¥ ´ÙÀ½ Àû¿ëÀ» ´·¯ º¯°æÇÑ Ç׸ñÀ» Àåºñ¿¡ Àû¿ëÇÕ´Ï´Ù.
IPSec SA »èÁ¦
IPSec SA¸¦ »èÁ¦ÇÏ´Â ¹æ¹ýÀº ´ÙÀ½°ú °°½À´Ï´Ù.
- ÇÁ·ÎÆÄÀÏ ¼³Á¤ ¿µ¿ªÀÇ VPN > IPSec VPN > IPSec VPN ¼³Á¤ > IPSec VPN
Ű ¼³Á¤ > IPSec SA(2´Ü°è)¸¦ ¼±ÅÃÇÕ´Ï´Ù. °ü¸®ÇÏ´Â ÀåºñÀÇ Á¾·ù°¡ µÎ °¡Áö ÀÌ»óÀÎ °æ¿ì AhnLab TrusGuard > VPN > IPSec VPN > IPSec
VPN ¼³Á¤ > IPSec VPN Ű ¼³Á¤ > IPSec SA(2´Ü°è)ÀÔ´Ï´Ù.
- »èÁ¦ÇÒ Ç׸ñÀ» ¼±ÅÃÇÑ ´ÙÀ½ »èÁ¦¸¦
´©¸¨´Ï´Ù.