VPN sika: IPSec vs. SSL

Yikuphi Ubuchwepheshe Okulungile Kuwe?

Eminyakeni edlule uma ihhovisi elikude lidingekile ukuxhuma nekhompiyutha noma inethiwekhi enkampanini yenkampani, kwakusho ukusungula imigqa eqondile yokuqashisa phakathi kwezindawo. Le migqa eqondile yokuqashisa inikeza ukuxhumana okusheshayo nokuphephile phakathi kwalezi zingosi, kodwa kwakubiza kakhulu.

Ukwamukela izinkampani zabasebenzisi beselula kuzodingeka ukusetha ukudayela okuzinikele- kumasethingi okufinyelela okude (RAS). I-RAS ingaba ne-modem, noma imodemu eminingi, futhi inkampani kuzodingeka ibe nomugqa wefoni ogijima kumodemu ngayinye. Abasebenzisi abaselula bangakwazi ukuxhuma kunethiwekhi ngale ndlela, kodwa ijubane lancipha kancane futhi lenza kube nzima ukwenza umsebenzi ocebile kakhulu.

Ngokufika kwe-intanethi okuningi kwalokho kuye kwashintsha. Uma ngabe iwebhu yamaseva nokuxhumeka kwenethiwekhi kakade ikhona, ukuxhumeka kwamakhompiyutha emhlabeni jikelele, kungani kufanele inkampani isichithe imali futhi idale ukuphathwa kwekhanda ngokusebenzisa imigqa eqondile yokuqashiswa kanye namabhange we-modem wokungena. Kungani ungasebenzisi nje i-intanethi kuphela?

Yebo, inselelo yokuqala ukuthi udinga ukwazi ukukhetha ukuthi ubani ozobona ukuthi yiluphi ulwazi. Uma umane uvule inethiwekhi yonke kwi-intanethi cishe akunakwenzeka ukusebenzisa izindlela eziphumelelayo zokugcina abasebenzisi abangagunyaziwe ekufinyeleleni kwinethiwekhi yezinkampani. Izinkampani zichitha amathani emali ukwakha izibhamu kanye nezinye izinyathelo zokuphepha kwenethiwekhi ezihlose ngokucacile ukuqinisekisa ukuthi akekho umuntu ovela kuyi-intanethi ongangena kwinethiwekhi yangaphakathi.

Uvumelanisa kanjani ukufuna ukuvimbela i-Inthanethi yomphakathi ekufinyeleleni kwinethiwekhi yangaphakathi ngokufuna abasebenzisi bakho basemuva ukuba basebenzise i-intanethi njengendlela yokuxhuma kwinethiwekhi yangaphakathi? Usebenzisa i- Virtual Private Network (VPN ). I-VPN ikhiqiza "umhubhe" obonakalayo ohlanganisa iziphetho ezimbili. Umgwaqo ngaphakathi komhubhe we-VPN ubhalwe ngekhodi ukuze abanye abasebenzisi be-inthanethi yomphakathi bangaboni kalula ukuxhumana okutholiwe.

Ngokusebenzisa i-VPN, inkampani inganikeza ukufinyelela kwinethiwekhi yangasese yangasese kumaklayenti emhlabeni wonke kunoma iyiphi indawo ngokufinyelela ku-inthanethi yomphakathi. Iqeda ikhanda lokuphatha kanye nezimali elihlobene nenethiwekhi yendawo yendabuko ehlanganisiwe (WAN) futhi ivumela abasebenzisi bokude nabaselula ukuba bavelele ngokwengeziwe. Okuhle kakhulu, uma kusetshenziswe kahle, kuyakwenza ngaphandle kokuthinta ukuphepha nobuqotho bezinhlelo zekhompyutha nedatha kwinethiwekhi yenkampani yangasese.

I-VPN yendabuko incike ku-IPSec (i-Inthanethi Protocol Security) emhubheni phakathi kokuphela kokuphela kokubili. I-IPSec isebenza ku-Layer Network ye-OSI Model- yokuvikela yonke idatha ehamba phakathi kweziphetho ezimbili ngaphandle kokuhlangana kunoma yisiphi isicelo esithile. Uma uxhunywe kwi-IPSec VPN ikhompyutha yeklayenti "cishe" ilungu eliphelele lenethiwekhi yebhizinisi- elingazibona futhi elingafinyelela lonke inethiwekhi.

Iningi lezixazululo ze-IPSec VPN zidinga i-third party hardware kanye / noma isofthiwe. Ukuze ufinyelele i-IPSec VPN, isistimu yokusebenza noma idivaysi embukisweni kumele ibe ne-software ye-software ye-IPSec iklayenti efakwe. Lokhu kokubili ipro ne-con.

Ipro is ukuthi inikeza ungqimba owengeziwe wokuphepha uma umshini wamaklayenti udinga ukuba nje usebenze isofthiwe iklayenti ye-VPN efanele ukuxhuma ku-IPSec VPN yakho, kodwa futhi kufanele ilungiselelwe kahle. Lezi zingqinamba ezengeziwe ukuthi umsebenzisi ongagunyaziwe kuzodingeka awele ngaphambi kokuthola ukufinyelela kwinethiwekhi yakho.

I-con is ukuthi kungaba umthwalo wezezimali ukugcina amalayisensi we-software yeklayenti kanye nesibindi sokusekelwa kwe-tech ukufaka nokulungisa isofthiwe iklayenti kuzo zonke imishini esilawuliwe-ikakhulukazi uma bengakwazi ukubeka isayithi ngokomzimba ukuze bahlele isofthiwe ngokwabo.

Kuyinto le con ngokuvamile ebizwa njengenye yezinzuzo ezinkulu kunazo SSL mpikiswano ( Secure Sockets Layer ) izixazululo VPN. I-SSL iyi-protocol evamile futhi iziphequluli eziningi zewebhu zinamakhono we-SSL akhiwe kuwo. Ngakho-ke cishe yonke ikhompyutha emhlabeni isivele ifakwe "isofthiwe iklayenti" edingekayo ukuxhuma kwi-SSL VPN.

Enye inqubo ye-SSL VPN yukuthi ivumela ukulawula okufinyeleleka kokufinyelela okuqondile. Okokuqala bahlinzeka imigudu kwezinye izinhlelo zokusebenza kunokuba yonke i-LAN yenkampani. Ngakho-ke, abasebenzisi be-SSL VPN ukuxhumeka bangakwazi ukufinyelela kuphela izinhlelo zokusebenza ezilungiselelwe ukufinyelela kuzo kunethiwekhi yonke. Okwesibili, kulula ukuhlinzeka ngamalungelo okufinyelela ahlukene kubasebenzisi abahlukene futhi abe nokulawula okungaphezulu kwe-granular ngaphezu kokufinyelela komsebenzisi.

Isixazululo se-SSL VPN sika noma ngabe ufinyelela uhlelo lokusebenza (s) ngokusebenzisa isiphequluli sewebhu esho ukuthi ngempela isebenza kuphela ngezinhlelo zokusebenza ezisuselwa kuwebhu. Kungenzeka ukuthi i-web-inike amandla ezinye izinhlelo zokusebenza ukuze zifinyeleleke nge-SSL VPN, kodwa ukwenza kanjalo kufakazela ubunzima besisombululo futhi kuqede ezinye zezinzuzo.

Ukuba nokufinyelela okuqondile kuphela kwezicelo ze-SSL ezinikwe amandla kuwebhu kusho ukuthi abasebenzisi abanakho ukufinyelela ezinsizeni zenethiwekhi njengamaphrinta noma isitoreji esisodwa futhi abakwazi ukusebenzisa i-VPN yokwabelana ngefayela noma izipele zokufayela.

I-SSL VPN ibilokhu ithola ukusabalalisa nokuthandwa; Kodwa akuzona isisombululo esifanele kuzo zonke izimo. Ngokufanayo, i-IPSec VPN ayihambisani nanoma yiziphi izimo noma. Abathengisi bayaqhubeka nokuthuthukisa izindlela zokwandisa ukusebenza kwe-SSL VPN futhi ubuchwepheshe okufanele ubuke ngokucophelela uma usemakethe isisombululo sokuxhumana esiseduze esiphephile. Okwamanje, kubalulekile ukucabangela ngokucophelela izidingo zabasebenzisi bakho abakude futhi uhlole izinzuzo nezindleko zesisombululo ngasinye ukuthola ukuthi yini okusebenza kahle kuwe.