|
What
is a VPN?
What is a VPN?
A VPN, or Virtual Private Network, is technology using hardware, software, or both to secure and privatize data across a network, usually the Internet, by building what techies call an “encrypted tunnel.” Data passes through this “tunnel,” protected from anyone who tries to intercept it. Even if the data is intercepted, it is hopelessly scrambled and useless to anyone without the key to decrypt it. Large businesses commonly use VPNs between offices to secure company data, and often provide individual “remote access” VPN solutions to home-based or traveling employees to protect data between them and the company’s network. You also use a VPN when you bank or shop online and see the https :// in your web browser. Unfortunately, the protection with an https:// session is temporary and limited to that specific website. With WiTopia’s VPN service, you initiate the secure encrypted tunnel from your side, so it is not dependent on the websites you visit. Your security and privacy is now maintained whether you see an https:// or not. It’s also important to note that your protection and privacy is not limited to just browsing. Our VPN service encrypts and anonymizes all your Internet data to and from our VPN gateways. This includes Skype, IM, streaming, e-mail, as well as browsing. Why do I need a “personal” VPN? Isn’t my
firewall and anti-virus enough?
A pc-based firewall only protects your data on your computer, and anti-virus software only protects you from, well, viruses. Neither protects your data as it flows over your local network, at a Wi-Fi Hotspot, or through your ISP. Without a VPN, your data is completely exposed and can easily be monitored and captured. As laptops, smartphones, and wireless networks have grown more popular, a great deal more data has become a great deal more mobile. Even with your home ISP or search engines, such as Google, privacy concerns abound. It is more crucial than ever to protect your data, as well as your identity and privacy, with a VPN. For a MUCH more complete answer, see the section, Why do I need a “personal” VPN? Why should I choose WiTopia for my VPN
service?
Glad you asked. Check out Why choose WiTopia for your VPN service? Is this a remote access VPN to reach my
company’s servers or my home computer?
We’re not a GotomyPC or Hamachi type service. We’re providing a secure and anonymous encryption service to the Internet. It has lots of benefits , but it is not a means to link to your home computer or company’s systems. Where and when should I use my VPN
service?
OpenVPN主流应用: 企业组网, 翻墙, WIFI热点加密, VoIP (Skype) 解锁,
Many of our customers located in countries that block VoIP or censor the Internet use it virtually all the time. Also, those who desire added privacy while online may use it a great deal. Others might only use it at wireless Hotspots or when traveling. Again, for a MUCH more complete answer, please visit, Why do I need a “personal” VPN? How does the VPN work?
When you activate your personalVPN, it instantaneously builds an encrypted tunnel through your Internet connection from wherever you are to one of our Secure Internet Gateways. All Internet data between you and WiTopia is now encrypted. Nobody can break the encryption, including your ISP. We also assign you a temporary and random WiTopia private IP address behind our gateway. Your “public” address will be that of whatever server of ours you are connected to for that session. This private IP cannot be traced by anyone through our server nor can anyone find your real IP address or location. You now cannot be sniffed, snooped, or spied on by anyone on your local network or across the Internet to our gateway. Once your data reaches our Secure Internet Gateway, we decrypt the data (we must so that your intended party can make sense of it), and send it to its destination. This last part is safe because it would be virtually impossible to “sniff” data between a secure data center over an actual Internet backbone link. It just doesn’t happen. “Sniffing” and “spying” occur over local networks because it is so very easy to do –much easier than trying to break into a guarded bunker-type data center with biometric scanners and such. When we receive the data from your destination server, we re-encrypt it and send it to you through the encrypted tunnel so no one can intercept it. Sound complicated? It only takes milliseconds. You shouldn’t even notice it’s happening. Will it work over any type of Internet
connection?
Yes. The VPN services should work over any Internet connection. Wired, Wi-Fi, and other wireless technologies should all support the VPN tunnel. We do recommend a broadband connection for best performance. Is the VPN easy to set up? Is it all done
online?
Yes. After purchase, you should be up and running within a few minutes. Although VPNs are complex applications, we’ve invested a great deal of time and money into developing a completely online setup process for our PPTP and openVPN-based VPN services. No additional software or hardware is required. And, if we may say so, this will be a far better experience than you’ll receive from other companies where you’ll often receive more of a “do it yourself” kit designed for computer experts. Do you share my information with any
other company?
No. Absolutely not. Why are your prices so low versus your
competition? Am I missing something?
核心竞争力: 启动期零利润, 规模效应(中国用户大于2万,@70USD/y), 积极早期推广,
No. There are no hidden fees or limits and we skimp on nothing. Although we can only theorize on the pricing strategy or cost structure of our competition, here are some thoughts.
What types of payment do you accept?
We use Authorize.Net and PayPal to process all major credit cards, checks, and, of course, PayPal itself. Do you offer a monthly plan?
唯一收费策略为年度收费 70, 60 40 USD/y
We don’t right now. We’re thinking about it, but we just went with the extremely low annual price with an unconditional 30 Day Money Back Guarantee. Do you serve ads or offer a free ad-based
version?
We do not allow ads on the service. That would put us in the advertising business, not the privacy and security business. In our opinion that would be a conflict of interest. The VPN services we know of that adopt an advertising-based model usually have data transfer limits and are likely more focused on selling ads than customers’ privacy and security. Be sure to check their policies concerning privacy and use of your information and we’re sure you’ll agree ad-based VPN services are not the bargain some might think. Do you offer trials?
30天试用期,无异议全额退款
We used to when we started out, but don’t anymore. And it’s not that we’ve grown cocky with success. Unfortunately, trials invite spammers and other assorted “bad guys” to dirty up the service. Trials sound like a good idea to inexperienced VPN companies, but we consider them gimmicky and they aren’t good for our existing customers or us. If you find that our VPN service doesn’t fit your needs for any reason, we will refund your money, in full, in the first 30 days after purchase. Do you have a Money Back Guarantee?
Yes! As mentioned, we’ll unconditionally refund 100% of your money within 30 days of purchase. We may ask you why so we ensure it is not some easily correctable configuration change or some misunderstanding, but we don’t require you to give us a reason. Does personalVPN work anywhere and
everywhere?
It should. We’ve had isolated cases where the PPTP VPN service has been blocked, but the openVPN-based SSL service (especially with the alternate port option locked and loaded) should get through most any force field. Why is a VPN better than a proxy?
强调OpenVPN相对于代理的功能优势
A VPN encrypts all data (Surfing, IM, FTP, etc.) to and from your computer where a proxy typically only encrypts http (WWW) traffic . VPNs also tend to be much faster and more reliable. To be fair, although limited in function, a commercial proxy, from a reputable company, may be fine for certain things. Unfortunately, many try the free anonymous web proxy route. These can be set up (and shared) by literally anyone. Yes, anyone — criminals, hackers, child pornographers, well-meaning geeks who are running it over their Grandma’s cable connection. You just don’t know. Utopian “fight the power” visions aside, using anonymous proxies means you may be pumping your passwords and personal data through a server setup by a couple enterprising 13-year-old hackers in Estonia. Which may work out fine for you…but it probably won’t. Why should I trust WiTopia?
核心竞争力: 私人运营, 求利为目的,专注单一产品, 自我期许, 竞争压力
Versus our imitators, we could brag about our team’s extensive experience with IP networking, data security, and managed services since 1995. Actually, some were in it long before that. Way before ISPs turned into “phone companies.” We could claim we’re smarter than most and have engineers so smart they’re rumored to speak Klingon in three dialects. That would all be true and it’s not just our mothers saying that. The bottom line is, compared to your Internet provider, a hotspot/network owner, or even a government, we have a vested interest in vigorously maintaining your data security and privacy . After all, that is what you pay us to do. Not to be too capitalistic or simplistic about it, but that really is quite an incentive. This is how we earn our livelihoods. We don’t sell ads. We don’t have side jobs. This is it . You pay us money and we do everything we can to provide you the best service and protection possible. If we don’t do it well, or somehow betrayed your trust, we’d guess you’d go elsewhere in an Internet minute. Knowing that, we will strive to earn your trust every single day and, hopefully, year after year. Do you keep logs of my activity? Can you
monitor my web surfing?
日志政策
We are not set up in any way to view an individual customer’s activity, nor do we monitor, capture, or store logs that are directly attributable to any individual customer. Some indirect data, and the other bits that are cached during the regular course of running an Internet business, are regularly destroyed, mostly during our weekly maintenance windows. In fact, we only keep this minimal and temporary “trailing log” of indirect data in case we learn a user is violating the terms of use, e.g. spamming, committing crimes using the service, etc. In that specific case, we will report this to our abuse team, determine the guilty party through a laborious matching process, terminate their service, and take further action, if necessary. What can I do and not do over the
service?
We’d say simply, please don’t commit any crimes or cause harm to anyone using the VPN , but the lawyer-approved version is here . Will my current e-mail work through the
VPN?
Yes. We offer a zero-configuration SMTP relay at no additional charge in case your current mail provider refuses to carry your e-mail while the VPN is connected. ISP-supplied DNS (Domain Name Service)
can cause privacy, performance, and blocking
issues. Does WiTopia offer DNS service for
complete security and privacy?
Yes. For best security and performance, especially in blocked countries, it is a good idea to use DNS servers that are not controlled by your ISP. Other available DNS servers may work fine, but we recommend that customers use ours. This will usually happen automatically when you connect or you can manually set them to make sure. Who owns WiTopia? Are you a front for the
government?
Sorry, but we’ve actually been asked that. I suppose it also begs the question “which government?” since we do business all over the world. All joking aside, WiTopia is completely privately owned by its founders and employees, none of whom work for, or are in collusion with, any government. I used another VPN service that had
repeated outages. What is your uptime?
Other than our scheduled one-hour maintenance window every Saturday at 6:00 PM ET (2200-2300 GMT), which usually lasts a few minutes in reality, we’ve had no more than 9 hours cumulative unplanned downtime since we brought systems online in early 2003. Do you have bandwidth limits, transfer
limits, or censor content?
价格政策不涉及流量
No. There are no bandwidth or transfer limits and we censor no content with the exception of sites that are repeatedly known for offering illegal content. We closely monitor and ensure we keep plenty of bandwidth and server capacity in reserve for peak load times. That being said, if we detect abusive usage patterns, e.g. you’re trying to run a phone company over the VPN, we reserve the right to be unpleasant about that. Still, in years of offering VPN services, we have never limited anyone. Will the VPN slow my Internet connection
down?
Any VPN or security application can slow performance, but it depends on a great many factors which can vary second to second and with each website you visit. Some users actually experience a speed increase when using the VPN service. Overall, due to the encryption and distance, you will likely see a slowdown in download speed, but it shouldn’t be too noticeable in any practical terms. And, due to how the VPN “optimizes” traffic you can usually rely on an increase in upload speed, which can improve the performance of applications such as VoIP. If you feel the VPN is slowing your connection abnormally, please consult Support immediately for troubleshooting. I have multiple computers and devices,
how many accounts do I need?
You’re welcome to load your VPN on other computers and devices that you own. We even allow two of those devices to be simultaneously connected as we realize you may need that sometimes. Still, it is a “personal” VPN so if you really need to simultaneously send/receive data over the VPN network from more than two computers/devices, contact sales@witopia.net and they’ll see if you qualify for special pricing. I have a Mac and a PC and wish to use
openVPN on both, but not simultaneously. Since
you have customized Window and Mac openVPN
installers, which openVPN service should I buy?
We recommend that you choose the product for the machine you use most to take advantage of our automated process and then follow instructions on the Support Wiki to set up openVPN on your computer with the different OS. Do you offer 256-bit encryption?
Yes. We offer true 256-bit encryption servers for our openVPN customers. Still, despite some speculation to the contrary, properly deployed 128-bit encryption cannot be broken with modern computing power. Mathematically, it would literally take thousands, if not millions, of years. Nevertheless, if you are being pursued by extraterrestrials, the NSA, or it just makes you feel better, we’re happy to provide it at no additional charge. Can I run personalVPN on a router?
To clear up any possible misunderstanding, you can, of course, run it *through* a router, but not *on* a router. personalVPN is priced and supported as an individual end-user service. Therefore, running the VPN account on a router, instead of a computer or other end-user device is prohibited. If you desire a pre-configured and fully-supported VPN router solution, take a look at our CloakBox in Products and Services . What kind of support do you offer?
客服平台: LiveChat (新加坡Zopim), 电邮,博客, 维基, 论坛
All customers enjoy unlimited online support 365 days a year. Any e-mail sent to support@witopia.net auto-generates a trouble ticket for tracking and is instantly assigned to a human support agent for resolution. We also have a comprehensive Support section complete with a gigantic Wiki filled with all sorts of solutions and tips for your VPN service. We understand that online chat or phone support would seem to be better, but our e-mail trouble ticketing system gives us the opportunity to capture, track, and resolve support issues more effectively and also keep our prices lower. We don’t believe you will be dissatisfied with the responsiveness. We take it very seriously. Lastly, we are continually investing in automation and our installers to ensure that support issues are minimized in the first place. That’s the real goal. Do you support torrents and P2P services?
P2P无需OpenVPN
We’re a data security and privacy (not piracy) company first and foremost and although torrent technology has many legitimate applications, it is often used in the trading and sharing of media files with 100,000 of your closest friends. It is a fact that P2P sites are often riddled with trojans, law enforcement honeypots, Identity thieves as well as, of course, copyrighted material. We also hear regularly from customers that when they subscribed to proxy services that cater to P2P activity they were sometimes attacked through these sites. Suffice it to say that, all arguments aside, we’d be remiss as a security company to encourage use of these sites so , like most every other VPN provider, we must say that if your goal is to download or upload pirated files, meaning they contain copyrighted content without the owner’s permission, please do not do so over our network. What Operating Systems do you support?
To make sure you purchase the correct VPN solution for your needs, be sure to consult Products and Services . Nevertheless, we typically support the following for VPN services:
I am in a country or location that
monitors, blocks, or censors the Internet. Will
your service work for me?
中国大陆用户近10万
Yes. Many of our customers are in countries or locations that block Internet services such as Skype or otherwise censor or monitor Internet activity or content. The VPN service should give you full and uncensored access to the Internet. Can I use VoIP over personalVPN?
Yes. Although we can’t vouch for every VoIP service out there, we have many thousands of customers using Skype, Vonage, and many other VoIP services over the VPN. If your VoIP service requires an ATA or other external hardware, you will likely need our CloakBox VPN router. This is most useful for those who don’t wish to use pc-based VoIP but want to use their regular phones or related peripherals. Will the VPN service unblock Skype,
Vonage, and other VoIP services if they are
blocked in the country in which I am located?
Yes. Again, although we cannot vouch for the performance of every VoIP service out there, we have thousands of customers in blocked countries that use Skype or other major VoIP services every day over the VPN. If your VoIP service requires external hardware, such as an ATA, we would recommend taking a look at our CloakBox VPN router. Will the VPN service work with my PS3,
Xbox, Apple TV, and programs like Boxee?
Yes. Now, if you need to plug in a device that does not have a VPN client, such as a PS3 or Xbox, you should look at our CloakBox VPN router. But AppleTV seems to have the ability to run the SSL VPN now so that should not require a CloakBox purchase. Contact sales@witopia.net if you have questions. Where are your VPN service gateways
located? Do you issue US and UK IP addresses?
Yes, and MANY more. WiTopia currently offers VPN service and IP addresses in: AMERICAS UNITED STATES
ARGENTINA
BRAZIL
CANADA
MEXICO
PANAMA
ASIA and AUSTRALIA AUSTRALIA
CHINA
INDIA
JAPAN
MALAYSIA
SINGAPORE
THAILAND
VIETNAM
EUROPE/MIDDLE EAST/AFRICA BELGIUM
CZECH REPUBLIC
EGYPT
FINLAND
FRANCE
GERMANY
IRELAND
ITALY
LATVIA
NETHERLANDS
POLAND
PORTUGAL
ROMANIA
RUSSIA
SPAIN
SWEDEN
TURKEY
UNITED KINGDOM
Do you offer alternate ports in case the
usual VPN ports are blocked?
Yes. It is very rare that the standard openVPN or PPTP ports are blocked, but it has happened. Our personalVPN-SSL (openVPN) customers have access to alternate ports which should get around almost any blocking by a local firewall. What if I try it and just don’t like it?
No problem. As mentioned, we’ll unconditionally refund 100% of your money within 30 days of purchase. We may ask you why so we ensure it is not some easily correctable configuration change or some misunderstanding, but we don’t require you to give us a reason. Just send your order information to sales@witopia.net and request a refund and we’ll process it right away. |
Showing posts with label OpenVPN. Show all posts
Showing posts with label OpenVPN. Show all posts
20110517
WiTopia FAQ
20100324
方滨兴:Father of GFW, Great Fire Wall of China
| GFW是中共历史上最肮脏的一页,等同于闭关锁国,愚弄人民; 庆幸的是,由于高等教育的过度行政化,党管教育,高教系统腐败横行,甘为党国鹰犬的知识分子一般技术水平都不高,封网一直都走在翻墙技术的后头; 高校计算机专业的老板无力在商业环境有所斩获,反倒热心承揽国防项目的主要原因在于此类项目技术水平幼稚,评估方式荒唐(暗箱操作,人情收受),成本较低,风险较小,利润较高. 方滨兴能够快速致富关键并不在于它具备基本的英文技术手册阅读能力(它主要看简体中文,英文由穷研究生查英汉字典翻译),而在于他以技术专业人员身份出镜,在肮脏的网络封锁的实质外裹了一张"信息安全技术"的中性包装,极大缓解了江胡政权实施此一基本国策时的内心负罪感.另外,GFW所用技术手段相对也比较低级,跟金盾所需技术不在一个层级上,实施成本较低,风险较小. |
GFW之父方滨兴的发家史 时间表 -1960年7月出生于黑龙江省哈尔滨市 -1989年在哈尔滨工业大学取得博士学位 -1998年9月22日,公安部部长办公会议通过研究,决定在全国公安机关开展全国公安工作信息化工程――”金盾工程”建设。 -1999年4月20日,公安部向国家计委送交金盾工程立项报告和金盾工程项目建议书。 -1999年6月,国家计算机网络与信息安全管理中心成立,局级事业单位。 -1999-2000年,在哈尔滨工业大学任教多年的方滨兴调任国家计算机网络与信息安全管理中心副总工程师。 -1999年12月23日,国务院发文成立国家信息化工作领导小组 ,国务院副总理吴邦国任组长。其第一下属机构计算机网络与信息安全管理工作办公室 设在已经成立的国家计算机网络与信息安全管理中心 ,取代计算机网络与信息安全管理部际协调小组,对”公安部、安全部、保密局、商用密码管理办公室以及信息产业部”等部门的网络安全管理进行组织协调。 -2000-2002年,方滨兴在国家计算机网络与信息安全管理中心任总工程师、副主任、教授级高级工程师 。 -2000年4月20日,公安部成立金盾工程领导小组 及办公室。 -2000年10月,信息产业部组建计算机网络应急处理协调中心 。 -2000年12月28日,第九届全国人民代表大会常务委员会第十九次会议通过《关于维护互联网安全的决定》 。 -2001年方滨兴”计算机病毒及其预防技术”获国防科学技术三等奖,排名第一。 -2001年方滨兴获国务院政府特殊津贴、信息产业部”在信息产业部重点工程中出突出贡献特等奖先进个人 ”称号,中组部、中宣部、中央政法委、公安部、民部、人事部等联合授予”先进个人”称号。 -2001年1月19日,国家计算机网络与信息安全管理中心上海分中心 成立,位于上海市黄浦区中山南路508号6楼。国家计算机网络应急技术处理协调中心上海分中心是工业和信息化部直属的中央财政全额拨款事业单位。 -2001年4月25日,”金盾工程 ”经国务院批准立项。 -2001年7月,计算机网络与信息安全管理工作办公室批准哈尔滨工业大学建立国家计算机信息内容安全重点实验室 ,胡铭曾、方滨兴牵头。 -2001年7月24日,国家计算机网络与信息安全管理中心广州分中心 成立,位于广州市越秀区建中路2、4号。 -2001年8月8日,国家计算机网络与信息安全管理中心组建国家计算机网络应急处理协调中心,缩写CNCERT/CC。 -2001年8月23日,国家信息化领导小组 重新组建,中央政治局常委、国务院总理朱镕基任组长。 -2001年11月28日,国家计算机网络与信息安全管理中心上海互联网交换中心成立。提供”互联网交换服务,互联网骨干网华东地区数据交换,数据流量监测与统计,网间通信质量监督,交换中心设备维护与运行,网间互联费用计算,网间互联争议协调”,位于上海市黄浦区中山南路508号。 -2001年11月28日,国家计算机网络与信息安全管理中心广州互联网交换中心成立,位于广州市越秀区建中路204号。 -2001年12月,在北京的国家计算机网络与信息安全管理中心 综合楼开始兴建。 -2001年12月17日,国家计算机网络与信息安全管理中心湖北分中心成立。 -2002年方滨兴任中国科学院计算技术研究所客座研究员、博士生导师、信息安全首席科学家。 -2002-2006年方滨兴在国家计算机网络与信息安全管理中心任主任、总工程师、教授级高级工程师,升迁后任其名誉主任。 -2002年1月25日报道称:”国家计算机网络与信息安全管理中心上海互联网交换中心 日前开通并投入试运行,中国电信、中国网通、中国联通、中国吉通 等4家国家级互联单位首批接入。中国移动互联网 的接入正在进行之中,近期可望成为第五家接入单位。” -2002年2月1日国家计算机网络与信息安全管理中心新疆分中心成立。 -2002年2月25日国家计算机网络与信息安全管理中心贵州分中心成立。 -2002年3月20日多个国家计算机网络与信息安全管理中心省级分中心同时成立。 -2002年9月3日Google.com被封锁,主要手段为DNS劫持 。 -2002年9月12日Google.com封锁解除,之后网页快照等功能被封锁,手段为TCP会话阻断 。 -2002年11月经费6600万 的国家信息安全重大项目”大范围宽带网络动态阻断系统 ”(大范围宽带网络动态处置系统)项目获国防科学技术二等奖。云晓春排名第一,方滨兴排名第二。哈尔滨工业大学计算机网络与信息内容安全重点实验室 李斌、清华大学计算机系网络技术研究所 、清华大学网格计算研究部杨广文有参与。 -2003-2007年方滨兴任信息产业部互联网应急处理协调办公室 主任。 -2003年1月31日经费4.9亿 的国家信息安全重大项目”国家信息安全管理系统”(005工程)获2002年度国家科技进步一等奖,方滨兴排名第一,胡铭曾排名第二,清华大学排名第三,哈尔滨工业大学排名第四,云晓春排名第四,北京大学排名第五,郑纬民排名第七,中国科学院计算技术研究所有参与。 -2003年2月在北京的国家计算机网络与信息安全管理中心综合楼工程竣工。 -2003年7月国家计算机网络应急处理协调中心更名为国家计算机网络应急技术处理协调中心。 -2003年9月2日全国”金盾工程”会议在北京召开,”金盾工程”全面启动。 -2004年国家信息安全重大项目”大规模网络特定信息获取系统 ”,经费7000万 ,获国家科技进步二等奖。 -2005年方滨兴任国防科学技术大学兼职教授、特聘教授、博士生导师。 -2005年方滨兴被遴选为中国工程院院士。 -2005年”该系统”已经在北京、上海、广州、长沙 建立了互相镜像的4套主系统,之间用万兆网互联。每套系统由8CPU的多节点集群构成,操作系统是红旗Linux,数据库用的是OracleRAC 。2005年国家计算机网络与信息安全管理中心(北京)就已经建立了一套384*16节点的集群用于网络内容过滤(005工程) 和短信过滤(016工程) 。该系统在广州、上海都有镜像,互相以十万兆网链接,可以协同工作,也可以独立接管工作。 -2006年方滨兴升迁,改任国家计算机网络与信息安全管理中心名誉主任 -2006年11月16日”金盾工程”一期在北京正式通过国家验收,其为”为中华人民共和国公安部设计,处理中国公安管理的业务,涉外饭店管理,出入境管理,治安管理等的工程”。 -2007年4月6日国家计算机网络与信息安全管理中心上海分中心机房楼 奠基,位于康桥镇杨高南路5788号,投资9047万元 ,”……是国家发改委批准实施的国家级重大项目,目前全国只有北京和上海建立了分中心,它是全国互联网信息海关 ,对保障国家信息安全担负着重要作用。” -2007年7月17日大量使用中国国内邮件服务商的用户与国外通信出现了退信、丢信等普遍现象。 -2007年12月方滨兴任北京邮电大学校长。 -2008年1月18日信息产业部决定免去方滨兴的国家计算机网络与信息安全管理中心名誉主任、信息产业部互联网应急处理协调办公室主任职务,”另有职用”。 -2008年2月29日方滨兴当选第十一届全国人民代表大会安徽省代表。 -2009年8月10日方滨兴在”第一届中国互联网治理与法律论坛”上大力鼓吹网络实名制 。 -2010年谷歌退出中国事件中,方滨兴多次出面为网络审查制度辩护 -2011年2月方滨兴在接受环球时报英文版采访时称在自己的家用电脑上有6个VPN用以测试GFW,实测证明VPN是目前GFW无法动态屏蔽(除事先知道静态IP地址,直接屏蔽服务器端IP地址方案外),希望国家进一步加大现金投入,尽快攻克此一技术难关. 机构关系 国家计算机网络与信息安全管理中心 (安管中心)是原信产部现工信部的直属部门。 安管中心与国家信息化工作领导小组计算机网络与信息安全管理工作办公室 与国家计算机网络应急技术处理协调中心 (CNCERT/CC,互联网应急中心)是一个机构几块牌子的关系。比如方滨兴简历中”1999-2000年在国家计算机网络应急技术处理协调中心任副总工”与”计算机网络应急处理协调中心”的成立时间两种说法就有着微妙的矛盾。实际上几个机构的人员基本一致。安管中心下属互联网交换中心与国家互联网络交换中心是不同的机构。各安管中心省级分中心一般挂靠当地的通信管理局。 安管中心的主要科研力量来自方滨兴当博导的哈工大 以及关系良好的中科院计算所 ,这两个机构是那三个国家信息安全重大项目的主要参与者,之后还在不断吸引人才并为安管中心输送人才和技术。在方滨兴空降北邮之后,往安管中心输血的成分中哈工大的逐渐减少,北邮的逐渐增多。 CNCERT/CC的国内”合作伙伴”有中国互联网协会主办北京光芒在线网络科技有限公司承办的中国互联网用户反垃圾邮件中心 ,是个没有实权的空壳;国家反计算机入侵及防病毒研究中心 、国家计算机病毒应急处理中心 ,是公安部、科技部麾下;违法和不良信息举报中心 是国新办势力范围;国家计算机网络入侵防范中心 是中科院研究生院的机构,同样直接支撑CNCERT/CC。 CNCERT/CC的应急支撑单位中民营企业最初领跑者是绿盟,后来绿盟因其台谍案被罢黜,启明星辰取而代之。而安管中心具有一些资质认证、准入审批的行政权力,这可能是民间安全企业趋之若骛的原因。不过,民营企业并未参与到国家信息安全的核心项目建设中,安管中心许多外围项目交给民企外企做,比如像隔离器之类的访问限制设备外包给启明星辰以作为辅助、备用,或者在与他们在网络安全监测上有所交流。 GFW与金盾没有关系 敏锐的读者从时间表应该已经看出这样的感觉了。实际上,GFW与金盾就是没有关系,两者泾渭分明 ,有很多区别。 公安系统搞网络监控的是公安部十一局 GFW是“国家信息关防工程 ”的一个子工程,直接上级是国家信息化工作领导小组和信息产业部是政治局亲自抓的国防工程 .这个工程主要监测发现有害网站和信息,IP地址定位,网上对抗信息的上报,跟踪有害短信息和及时进行封堵。江泽民,朱镕基,胡锦涛,李岚清,吴邦国 等多次视察该工程 “国家信息关防工程”包括“国家信息安全管理系统工程代号为005 。还有国家信息安全016工程 等等 GFW主要是舆情情报系统的工具,而金盾主要是公安系统的工具。GFW的总支持者是负责宣传工作的李长春,和张春江江绵恒最初的主要需求来自政治局政法委安全部610办;而金盾的总支持者是公安系统的高层人士,主要需求来自公安部门。GFW主外,作网络海关用;而金盾主内,作侦查取证用 。GFW建设时间短,花费少,成效好;而金盾建设时间长,花费巨大(GFW的十倍以上),成效不显著。 GFW依附于三个国家级国际出入口骨干网交换中心从CRSGSR流量分光镜像到自己的交换中心搞入侵检测,再扩散到一些放在ISP那里的路由封IP,位置集中,设备数量少 ;而金盾则是公安内部信息网络,无处不在,数量巨大。GFW的科研实力雄厚,国内研究信息安全的顶尖人才和实验室有不少在为其服务,比如哈工大信息安全重点实验室、中科院计算所软件所高能所国防科大总参三部安全部9局北邮西电、上海交大北方交大北京电子科技学院解放军信息工程学院解放军装甲兵工程学院信产部中电30所总参56所等等;另外几乎所有985211高校都参与此工程一些公司商业机构也参与某些外围工程项目如Websense packeteer Blue Coat华为北大方正港湾启明星辰神州数码也提供了一些辅助设备中搜奇虎北京大正雅虎等等参与了搜索引擎安全管理系统在某些省市级的网络机房里,接入监控的部门就五花八门了,有安全、公安、纪检、部队,等等部署的设备也是五花八门正规军杂牌军洋外援各自为战而金盾的科研实力较弱,公安系统的公安部第三研究所信息网络安全研发中心、国家反计算机入侵与防病毒研究中心都缺乏科研力量和科研成果,2008年8月成立信息网络安全公安部重点实验室想与哈工大的重点实验室抗衡,还特意邀请方滨兴来实验室学术委员会,不过这个实验室光是电子数据取证的研究方向就没什么前景,而且也没什么研究成果。GFW之父方滨兴没有参与金盾工程,而工程院里在支持金盾工程的是沈昌祥;实际上那个公安部重点实验室的学术委员会名单很是有趣,沈昌祥自然排第一,方滨兴因为最近声名太显赫也不好意思不邀请他,方滨兴可能也有屈尊与公安系统打好关系的用意。 GFW发展和状况 GFW主要使用的硬件来自曙光和华为,没有思科、Juniper,软件大部为自主开发。原因很简单,对国家信息安全基础设施建设,方滨兴在他最近的讲话《五个层面解读国家信息安全保障体系》 中也一直强调”信息安全应该以自主知识产权为主”。何况GFW属于保密的国防工程而且GFW没有闲钱去养洋老爷,肥水不流外人田。李国杰是工程院信息工程部主任、曙光公司董事长、中科院计算所所长,GFW的大量服务器设备订单都给了曙光 。方滨兴还将安管中心所需的大型机大订单给李国杰、国防科大卢锡城、总参56所陈左宁三位院士所在单位各一份。所以GFW为什么那么多曙光的设备,GFW为什么那么多中科院计算所的科研力量,为什么方滨兴成为中科院计算所和国防科大都有显赫的兼职,为什么方滨兴从老家哈尔滨出来打拼短短7年时间就入选工程院卢浮宫? 就是因为方滨兴头脑灵活,做事皆大欢喜 。 网上有人讽刺GFW夜郎自大,事实上这是盲目乐观,无知者无畏。GFW的技术是世界顶尖的,GFW集中了哈工大、中科院、北邮货真价实的顶尖人才,科研力量也是实打实地雄厚,什么动态SS LFreenet VPN SSH TOR GNUnetJAPI2PPsiphon什么Feed Over Email算什么葱。所有的翻墙方法,只要有人想得到,GFW都有研究并且有反制措施的实验室方案储备 。比如说:串接式封堵采用中间人攻击手段 来替换加密通信双方所用的没有经过可信赖CA签名保护的数字证书网关/代理间的证书协调,在出口网关上进行解密检测也就是所谓深度内容检测七层过滤HTTPS是需要认证的。客户端访问服务器时,服务器端提供CA证书,但有些实现也可以不提供CA证书那么对于不提供CA证书的服务器,防火墙处理很简单,一律屏蔽掉另外检测默认的CA发证机构 ,如果证书不是这些机构(Verisign、ThawteGeotrust)发的,杀无赦就是在客户端与服务器端进行https握手的阶段 ,过滤掉一切无CA证书或使用不合法CA证书的https请求 。这一步是广谱过滤,与服务器的IP地址无关。 GFW主要是入侵防御系统,检测-攻击两相模型。所有传输层明文的翻墙方案,检测然后立即进行攻击是很容易的事情 ;即使传输层用TLS之类的加密无法实时检测,那种方案面向最终用户肯定是透明的,谁也不能阻止GFW也作为最终用户来静态分析其网络层可检测特征。入侵检测然后TCP会话重置攻击算是干净利落的手段了,最不济也能通过人工的方式来查出翻墙方法的网络层特征(仅仅目标IP地址就已经足够 )然后进行定点清除 。如果是一两个国家的敌人,GFW也能找到集群来算密钥。GFW是难得能有中央财政喂奶的科研项目。那些在哈工大地下室、中科院破楼里的穷研究生即使没有钱也能搞出东西来,现在中央财政喂奶,更是干劲十足了。GFW什么都行,就是P2P没办法,因为匿名性太好了,既不能实时检测出来,也无法通过静态分析找到固定的、或者变化而可跟踪的网络层特征 。就这样也能建两个陷阱节点搞点小破坏,而且中科院的242项目”P2P协议分析与测量 ”一直都没停。什么时候国外开学术会议还是Defcon谁谁发一篇讲Tor安全性的paper,立即拿回来研究一番实现一下,已然紧跟学术技术最前沿了。不过实际上,即使GFW这样一个中国最顶尖的技术项目也摆脱不了山寨的本性,就是做一个东西出来很容易,但是要把东西做细致就不行了。 不过可能有人就疑问,为什么GFW什么都能封但又不真的封呢?我的这个翻墙方法一直还是好好的嘛。其实GFW有它自己的运作方式。GFW从性质上讲是纯粹的科研技术部门,对政治势力来说是一个完全没有主观能动性的工具 。GFW内部有很严格权限管理,技术与政治封装隔离得非常彻底。封什么还是解封什么,都是完全由上峰决定,党指挥枪,授权专门人员操作关键词列表,与技术实现者隔离得很彻底,互相都不知道在做什么。所以很多时候一些莫名其妙的封禁比如封freebsd.org封freepascal.org(可能都联想到freetibet.org),或者把跟轮子的GPass八杆子打不着的”package.debian.org/zh-cn/lenny/gpass”列为关键词,都是那些摆弄着IE6的官僚们的颐指气使,技术人员要是知道了都得气死 。方滨兴在他最近的讲话《五个层面解读国家信息安全保障体系》中讲一个立足国情的原则,说:”主要是强调综合平衡安全成本与风险,如果风险不大就没有必要花太大的安全成本来做。在这里面需要强调一点就是确保重点的,如等级保护就是根据信息系统的重要性来定级,从而施加适当强度的保护。 ”所以对于小众的翻墙方式,GFW按照它的职能发现了也就只能过一下目心里有个底,上峰根本都不知道有这么一种方式所以也根本不会去封、GFW自己也没权限封,或者知道了也懒得再花钱花精力去布置。枪打出头鸟,什么时候都是这样。目前的状况是对于敏感数据能通过封锁基本上就是安全的,否则就被过滤掉了,对于庞大的网络数据用人来分析是不可能的,敏感数据只能基于过滤技术根据数据流里面的一些特征来发现,目前的解密技术对于庞大数据流量和加密技术想使用解密的方法是不可能实现的,只要加密数据流没有可识别的特征,过滤技术就不会有任何记录和反映,因此过滤技术是无法真正实现网络封锁的,因此必需加入新的参数,它们选择了量,即保存你的一段时间的数据。现在的破网方法用的比较多得是动态网,无界,花园,等等,由于接点相对来说是有限的和可知的 ,因此保存一段时间的数据就有了意义,由于使用破网软件的人很多,不可能人人都抓,可以根据量来区分出重点,和经常使用破网软件的人,当然你可已通过代理来连接这些可知接点来解决这个问题,破网软件也提供了这样的方法,但是通过代理联接可知的接点的请求还是可能被截获的 方滨兴一个人把GFW崛起过程中的政治势能全部转化为他的动能之后就把GFW扔掉了 。现在GFW是平稳期,完全是清水衙门,既没有什么后台,也无法再有什么政治、资金上的利益可以攫取,也无法再搞什么新的大型项目,连IPv6对GFW来说都成了一件麻烦事情。方滨兴在他最近的讲话《五个层面解读国家信息安全保障体系》中也感慨道:”比如说Web2.0概念出现后,甚至包括病毒等等这些问题就比较容易扩散,再比如说IPv6出来之后,入侵检测就没有意义了,因为协议都看不懂还检测什么……”GFW一直就没有地位,一直就是一个没人管的萝莉,国新办、网监、广电、版权、通管局 之类的怪蜀黍都压在上面要做这做那。所以方滨兴在他最近的讲话《五个层面解读国家信息安全保障体系》中也首先强调一个机制,”需要宏观层面,包括主管部门予以支持。”所以,想解封网站,不要去找GFW本体,那没用,要去找GFW的上峰,随便哪个都行 。而ISP就根本跟GFW没关系了,都不知道GFW具体搞些什么,起诉ISP完全属于没找到脉门。 不过GFW现在还是运行得很好,工作能力还有很大潜力可挖,唯一害怕的就是DDoS死撞墙 。GFW的规模在前面的时间表里也有数字可以估计,而且GFW现在的网站封禁列表也有几十万条之多 。网络监控和对MSNYMSGICQ等IM短信监控也都尽善尽美。GFW在数据挖掘和协议分析上做的还比较成功多媒体数据如音频视频图形图像的智能识别分析自然语言语义判断识别模式匹配p2pVoIPIM流媒体加密内容识别过滤串接式封堵等等是将来的重点不过GFW也没有像机器学习之类的自组织反馈机制来自动生成关键词,因为它本身没有修改关键词的权限 ,所以这种技术也没必要,况且国内这种技术也是概念吹得多论文发得多实践不成熟。现在GFW和金盾最想要的就是能够从万草从中揪出一小撮毒草的数据挖掘之类的人工智能技术 。方滨兴在他最近的讲话《五个层面解读国家信息安全保障体系》中提到”舆情驾驭核心能力 ”,”首先要能够发现和获取,然后要有分析和引导的能力”。怎么发现?就靠中科院在研的973课题 ”文本识别及信息过滤 ”和863重点项目 ”大规模网络安全事件监控 ”这种项目。金盾工程花大钱搞出来,好评反而不如GFW,十一局的干警们脸上无光无法跟老一辈交代啊。公安系统的技术力量跟GFW没法比,不过公安系统有的是钱,先游山玩水吃喝一通,然后把剩下的税金像冲厕所一样随便买个几十万个摄像头几万台刀片几十PB硬盘接到省市级网络中心 ,把什么东西都记录下来。问题是记下来不能用,只能靠公安干警一页一页地翻Excel。所以说,虽然看起来GFW千疮百孔,金盾深不可测,只是因为公安部门比起GFW来比较有攻击性,看到毒草不是给你一个RST而是给你一张拘留证。反而是GFW大多数时候都把毒草给挡住了,而大多数毒草金盾都是没发现的。 国家信息安全话语范式 在轮子闹事被取缔之后,轮子组织仍然在从四面八方进行各种手段的宣传,而且逐渐依靠上了各种境外背景。境内的宣传活动很快就被公安和国安清理掉了,然而从境外网上而来的大量网络宣传让从未有过网络化经验的中央无所适从、毫无办法、十分着急 。这些东西对中央来说都是难以忍受的安全威胁,为这些威胁又发生在网上,自然国家网络安全就被提上了首要议程。适逢信息化大潮,电子政务概念兴起,中央下决心好好应对信息化的问题,于是就成立了国家信息化工作领导小组 。我们可以看到,首批组成名单中,安全部门和宣传部门占了大多数席位,而且其第一下属机构就是处理安全问题,第二下属才是处理信息化改革,安全需求之强烈,可见一斑。正是这个时候,一贯对信息安全充满独到见解的方滨兴被信产部的张春江调入了安管中心练级 。方滨兴对信息安全的见解与高层对网络安全的需求不谋而合。一个方滨兴见解的集大成概括,方滨兴在他最近的讲话《五个层面解读国家信息安全保障体系》中说:”一定要有一个信息安全法,有了这个核心法你才能做一系列的工作。”国家信息安全体系的首要核心就是以信息安全为纲的法律保障体系,通过国家意志――法律来定义何谓”信息安全”。信息安全本来是纯技术、完全中性的词语,通过国家意志的定义,将”煽动…煽动…煽动…煽动…捏造…宣扬…侮辱…损害…其他…”定义为所谓的网络攻击、网络垃圾、网络有害信息、网络安全威胁,却在实现层面完全技术性、中立性地看待安全,丝毫不考虑现实政治问题 。这样既在技术上实现完备的封装,也给了用户以高可扩展性的安全事件定义界面。对国家安全与技术安全实现充满隐喻的捆绑,对意识形态与信息科学进行牢不可破的焊接,这就是方滨兴带给高层的开拓性思维 ,这就是方滨兴提出的国家信息安全话语范式。 这个话语范式是如此自然、封装得如此彻底,以至于几乎所有人都没有意识到中国的网络化发展出现了怎样严重的问题。几乎所有网民都没有意识到,给他们带来巨大麻烦和沮丧的GFW竟然是本来应该为网民打黑除恶的国家互联网应急响应中心 ;几乎所有网民都没有意识到,自己在网上某处的一亩三分地修剪花草对于国家来说竟然是网络安全攻击事件 ;几乎所有决策者都没有意识到,那个看似立竿见影的防火墙实际上具有怎样强大的副作用、会给互联网发展带来怎样大的伤害;几乎所有决策者都没有意识到,使用GFW这样专业的安全工具来进行网络封锁意味着什么。意识形态面对网络化这样变幻莫测的景色无法忍受,就只能用眼罩封闭住眼睛 。在讨论网络化的中文理论文本中,摆到首要位置占据最多篇幅的便是网络安全和网络威胁。国家信息化工作领导小组第一下属机构便是处理安全问题。这样,在网络本身都没有发展起来的时候,就在理论上对网络进行种种限制和控制;在网络仍然自发地成长起来以后,便在文化上对网络进行系统性妖魔化,在地理上对网络中国进行闭关锁国 。更严重的是,在根本不了解技术本质和副作用的情况下使用国家信息安全工具,就像一个不懂事的小孩把玩枪械 。在维护安全的话语之下,决策者根本不知道使用GFW进行网络封锁就是在自己的网络国土上使用军队进行镇压 ,切断网线就是在自己的网络国土上种蘑菇。 更悲哀的是,GFW的建设者们大多都没有意识到他们在做的究竟是什么事情,在签订保密协议之后就无意识中投身党国事业滚滚长江东逝水 。像云晓春这种跟着方滨兴出来打江山的,方滨兴倒是高飞了,云晓春们就只能鞠躬尽瘁干死技术,在安管中心反而被王秀军、黄澄清之辈后来居上。而当初在哈工大跟着方滨兴的穷研究生们,最后也陆陆续续去了百度之类的公司。GFW面临与曼哈顿工程一样的伦理困局 。科学本是中立的,但科学家却被政治摆弄 。技术工作者们只关心也只被允许关心如何实现安全,并不能关心安全的定义到底如何。他们缺乏学术伦理精神,不能实践”对自己工作的一切可能后果进行检验和评估;一旦发现弊端或危险,应改变甚至中断自己的工作;如果不能独自做出抉择,应暂缓或中止相关研究,及时向社会报警 ”的准则。结果就算他们辛辛苦苦做研究却也不能造福民生,反而被扣上”扼杀中国人权”"纳粹帮凶”的帽子,不可谓不是历史的悲哀。这种话语范式浸透了社会的方方面面。在这种话语之下,中国有了世界上最强大的防火墙 ,但中国的网络建设却远远落后于世界先进水平;中国有了世界上最庞大的网瘾治疗产业链,但中国的网络产业却只会山寨技;中国有了世界上最多的网民,但在互联网上却听不见中国的声音 。GFW已经实现了人们的自我审查,让人们即使重获自由也无法飞翔,完成了其根本目的。现在即使对GFW的DDoS的技术已经成熟,然而推倒墙却也变得没有意义,只能让公安系统的金盾得势,更多的网民被捕,最终新墙竖起。这一切都出自意识形态化现代性与网络化后现代性之间巨大断裂,以及”国家信息安全话语”这种致命的讳疾忌医。 结语 一部GFW简史同时也是中国网络化简史 。网络化既是技术变革,也是文化变革。网络文化这种”有害成份”无法分而治之,因为网络化的技术变革与文化变革是一体的;后现代的网络文化也无法与现代的意识形态文化进行同化,因为两者分属不同的范式。网络的确是意识形态完全的敌人,因为网络多元化文化要求取消意识形态的中心地位;但意识形态不是网络的敌人,事实上网络没有敌人,因为网络只有解构对象 。因此对于执政者来说,意识形态的中心地位与网络化发展趋势两者只能选择其一 。实际情况是,执政者选择了前者,而把大刀挥向了Web2.0。于是网络用它一贯调侃的风格模仿意识形态话语进行了如下讽刺:”我们对你陈旧的政权概念和意识形态烂腌菜毫不感兴趣。你无法理解在人类网络化的历史潮流之前宏大叙事为何而消解,你也无法理解国家和民族概念为何将分崩离析,你无法改变你对互联网的无知。你的政权无法成为我们真正的敌人。”其实,《2009匿名网民宣言》 只是过早的预言,cyberpunk式的谜语。 然而,无论中国的互联网受到了怎样的限制和压迫,即便中国网民的眼界已经被成功禁锢,中国的网络还是以它自己的方式适应种种压力顽强地发展。无论有多么强大的GFW或者金盾,即使被关在果壳之中,网络仍然在以意识形态完全不能理解的方式走向后现代蓝海,自成为无限空间之王 |
| 来源:飞跃手册 |
20090504
方滨兴:互联网信息安全特指反共信息屏蔽,虚假舆情制造
| 互联网信息的自由传播是一场中国共产党根本无法打赢的攸关专制政权存废的新时代信息战争. 在中共中央的威权统治下,汉语的基本语义功能已经遭到全面性的腐蚀,曲解,朝廷当众撒谎成了常态; 在中共中央设计的语义环境里,所谓不安全信息并非指针对商业目的的技术层面的网络入侵,而是指在中国大陆互联网海关(光缆物理连接,国际出入口骨干网交换中心)以内的静态反专制网页内容,及全球范围内的反专制网页内容(以中文信息为主).信息安全一方面指的是在互联网海关以内消灭上述信息,通过在国际进出骨干网节点用中间人攻击,域名劫持,IP地址拦截,断开https连接,HTTP会话劫持等方法屏蔽反党信息入境,另外一个方面是用低技术方式雇佣大量五毛党发布拥共言论,人为制造虚假的中文网络舆情. 通过卫星传播的互联网流量中共中央无法用GFW技术阻截,只能用简单的信号干扰或者直接导弹摧毁的方式断网; 知名反共网站主动攻击是目前常态; 国际骨干网出口物理断网是随时可以执行的预案,但权限不在GFW,在党中央. |
| Wikipedia: 信息安全
信息安全,意为保护信息及信息系统免受未经授权的进入、使用、披露、破坏、修改、检视、记录及销毁 。 信息安全这一术语,与计算机安全和信息保障(information assurance)等术语经常被不正确地互相替换使用。这些领域经常相互关联,并且拥有一些共同的目标:保护信息的机密性、完整性、可用性;然而,它们之间仍然有一些微妙的区别。 区别主要存在于达到这些目标所使用的方法及策略,以及所关心的领域。信息安全主要涉及数据的机密性、完整性、可用性,而不管数据的存在形式是电子的、印刷的还是其它的形式。 计算机安全可以指关注计算机系统的可用性及正确的操作,而并不关心计算机内存储或产生的信息。 政府、军队、公司、金融机构、医院、私人企业积累了大量的有关他们的雇员、顾客、产品、研究、金融数据的机密信息。绝大多数此类的信息现在被收集、产生、存储在电子计算机内,并通过网络传送到别的计算机。 万一诸如一家企业的顾客、财政状况、新产品线的机密信息落入了其竞争对手的掌握,这种安全性的丧失可能会导致经济上的损失、法律诉讼甚至该企业的破产。保护机密的信息是商业上的需求,并且在许多情况中也是道德和法律上的需求。 对于个人来说,信息安全对于其个人隐私具有重大的影响,但这在不同的文化中的看法差异相当大。 信息安全的领域在最近这些年经历了巨大的成长和进化。有很多方式进入这一领域,并将之作为一项事业。它提供了许多专门的研究领域,包括:安全的网络和公共基础设施、安全的应用软件和数据库、安全测试、信息系统评估、企业安全规划以及数字取证技术等等。 |
| “作为国家信息安全保障体系来讲,其包括积极防御、综合防范等多个方面的多个原则。因此,要建立和完善信息安全等级保护制度就要加强和建设多个层面。”中国工程院院士方滨兴指出,当前国家信息安全的保障体系需要围绕以下细节全面建设,具体为:要加强密码技术的开发与应用、建设网络信息安全体系、加强网络信息安全风险评估工作、建设和完善信息安全监控体系、高度重视信息安全应急处置工作、重视灾难备份建设。 当然了,要增强国家信息安全保障能力,还必须要掌握核心安全技术 。此外还包括能力,如信息安全的法律保障能力、基础支撑能力等等。 简而言之,方院士称:“我们国家的信息安全保障体系可以从五个层面解读,又可以称之为‘一二三四五国家信息安全保障体系 ’”。 方院士的解读具体如下 : 一,即一个机制,就是要维护国家信息安全的长效机制。 二,是指两个原则:第一个原则是积极预防、综合防范;第二个原则是立足国情,优化配置。 三,是指三个要素:人、管理、技术。 四,是指四种能力:核心技术能力、法律保障能力、基础支撑能力、舆情宣传和驾驭能力 、国际信息安全的影响力。显然,在国际的信息安全斗争或对抗中,只有这几方面的能力具备了才能占有优势地位,当然这背后实际上需要做很多的工作。 五,是指五项主要的技术工作:风险评估与等级保护、监控系统、密码技术与网络信任体系、应急机制、灾备。 一、一个机制 所谓的一个机制,是说机制一定是一个完善长效的机制,一方面是在组织协调性上,另一方面是在支撑力度上。这需要宏观层面,包括主管部门予以支持。 二、两个原则 第一个原则是积极防御、综合防范。不难理解,综合是表现在整个产业的协调发展,也就是说网络信息安全与信息化的关系。在这个里面,积极当然有多种含义,虽然我们并不提倡主动攻击,但是掌握攻击技术是信息对抗所需要的 。但是值得注意的是,真正的积极是指一旦出现一个新的技术,我们就立即要想到研究这个新技术会带来什么安全性问题,以及这样的安全性问题该怎么办?比如说Web 2.0概念出现后,甚至包括病毒等等这些问题就比较容易扩散,再比如说Ipv6出来之后,入侵检测就没有意义了,因为协议都看不懂还检测什么……所以说这些信息化新技术的出现同时也都呼唤新的安全技术。 另外技术解决不了的还得靠管理,比如说等级保护,当然等级保护主要是面向政府部门的。那么反过来管理做不了的也得靠技术,你说有病毒,光嘴上说不行,还得有技术防范。再有就是强调了核心保障。 第二个原则是立足国情,这里面主要是强调综合平衡安全成本与风险,如果风险不大就没有必要花太大的安全成本来做。在这里面需要强调一点就是确保重点的,如等级保护就是根据信息系统的重要性来定级,从而施加适当强度的保护。此外,当你在发展的时候必须要考虑到涉及到安全问题的时候该怎么办,但你做安全也是为了促进发展,而不是说限制发展,所以尽管我们现在觉得需要物理隔离 的方式,但同时也在研究一系列的技术来替代这么一个简单的方式,这个就是国情的需要。 三、三个要素 三个要素包括人、管理、技术。 从人才角度来说强调了两个方面,一个方面是培养,培养你的人、才、水平,那么包括学历教育、研究、以及学科层面,无论是培养研究生还是其他研究人才,都和社会服务人才不一样。再有就是培训和网络教育。还有加强信息安全宣传工作和网络文明建设,也都需要相关的支持,基本上跟信息相关的底下都有这个。此外,就是论坛、媒体的努力。当然,吸引和用好高素质的信息安全管理和技术人才的机制也很有有用。 就管理这一点而言,其实互联网上的管理主要是靠四句话:法律保障、行政监管、行业自律、技术支撑。我们还可以把管理分为三级措施,那么从宏观的角度来说出现的是什么?方针,国家说积极预防、综合防范,这是一种方针,还有就是政策引导,我们现在制订这方面的政策等,再有就是具体的法规,就是要严格规章制度。此外还有标准,标准是从技术角度、管理角度引导你,你不会做按照这个做就行了。也就是说标准解决怎么做,法规解决做什么的问题。到微观方面就是说各个管理机构,要做好规章、制度、策略、措施。 需要说明的是,机制就是怎么管,我们现在是通过一些认证测评、市场准入来对安全做管理,这里面对产品服务做认真测评,包括政府采购也是受一定的限制。而措施则是,你到底管哪些事情,如等级保护这个是要管的,这个是没有问题的;再比如系统安全、产品的采购包括测评、密码技术等都在管理范畴。 第三个层面是信息安全技术,信息安全技术在这里面特别强调的是对引进的产品的安全问题,如它的安全可控必须要有人管。同时我们还要研究新技术、新业务,包括网络安全、内容安全、密码、安全隔离手续等。当然这其中也少不了需要政策导向和市场机制,当然最终的目标就是信息安全还应该以自主知识产权为主。 四、四个核心能力 四个核心能力,主要是信息安全的法律保障能力,信息安全的基础支撑能力,网络舆情宣传和驾驭的能力 。再有一个就是国际信息安全的影响力, 就法律保障能力而言,业内一致认为要以信息安全为纲,你一定要有一个信息安全法,有了这个核心法你才能做一系列的工作,包括制订相应的制度。 第二个能力叫做基础支撑能力,就是说国家要有一系列的相应的基础支撑,比如说数字证书、计算机网络应急响应体系、灾难恢复体系等等,再比如说密钥管理、授权管理等等,这些都是做得很成功的,而网络舆情掌控的体系,一些部门也都有,你它的运行效果还有很多需要改进的余地。 第三个能力是舆情驾驭能力,我们在网上可以看到这句话,要关注三个如何,如何引导网络舆论,如何对网上的热点话题做访问,如何提高处置网络的能力。这些实际上都是我们舆情驾驭能力的标志。舆情驾驭的具体目标是首先要能够发现和获取,然后要有分析和引导的能力,之后要有预警和处理的能力。 第四个是国际影响力。只有在信息安全较量中才能体现出一个国家的信息安全影响力。所以,这就需要发挥信息安全整体资源的优势,这其中包括对有害信息的应对能力、技术手段。用逆向思维的话,就是说假如出现最坏的情况网络被恶意中断,那么至少能保持一个封闭体系还能继续运转 ,这可能必须要有域名的解析,当然这个国内现在已经做到了。 五、五项工作 五项工作包括:加强风险评估工作,建立和完善等级保护制度;加强密码技术的开发利用 ,建设网络信任体系;建设和完善信息安全监控体系;高度重视信息安全应急处置工作;灾难备份等。 第一,风险评估和等级保护,两者相辅相成需要一体化考虑。因为风险评估是出发点,等级划分是判断点,安全控制是落脚点,所以风险评估和等级保护这两件事儿是不可分的,只有知道了系统的脆弱性有多大,等级保护才能跟上去。 第二,网络信任体系主要是靠密码技术,还要强调密钥体系。 第三,网络监控系统,强调国家对各个运营单位都要求有相应的信息监控系统,要有处理信息的能力,这样起码对一些网络攻击,防范失泄密可以提供支持。 第四,应急响应体系,国家在2003年SARS之后就开始建立应急响应体系,2008年的1月份出现了凝冻灾害天气,充分考验了这个体系。所以信息安全也有国家级的预案,或许将来会做更多的宣贯。 第四,灾难备份,这个里面最重要的目标是力保恢复,其次是及时发现,接下来才是快速响应。 |
| 原文:
大家好!今天我选择的题目是解读国家信息安全保障体系,本来这是一个三年前的话题,我为什么今天要讲呢?我们在这一段的回顾27号文发布5周年,作为国务院信息化专家委员会一直在回顾这一段的工作怎么样,这个时候我们突然发现大家不太知道国家有一个很公开的,很正式的文件告诉大家我们国家的信息安全保障体系是什么。这一点我也觉得比较诧异,所以我觉得我有责任把这件事再做一下宣传,这也是我今天选择这个题目的原因。 这个是中央的文件,文件注明是此件公开发布,在这个文件中强调印发了2006-2020国家信息化发展战略通知,在这个通知里面因为它是信息化发展战略,专门涵了一段就是信息安全战略。在这一块我们可以看出来有这么几个核心术语,因为比较繁杂,一般很难记住,我们就做一个解读。我们看一下这个已经定位为保障体系,在这个里面有两个要素,一个是积极防御,综合防范,一个是立足国情综合平衡安全成本,这是相当于指导思想。 再有就是要建立和完善信息安全等级保护制度,要加强密码技术的开发利用,要建设网络信用信息,要加强信息安全风险评估工作,要建设和完善信息安全监控体系,要高度重视信息安全应急处置工作,要重视灾难备份建设,这是一系列的具体工作。要掌握核心安全技术,要加快信息安全培养,最后又提出来了几个能力,要不断提高信息安全的法律保障能力,基础支撑能力,网络以及宣传的驾驭能力和我国在信息安全领域的影响力,最后要建立和完善维护国家信息安全的长效机制。 这么一个文你一看很难记住核心,所以我把这个核心总结一下,我把它叫做一、二、三、四、五国家信息安全保障体系。一是什么呢?就是机制,要维护国家信息安全的长效机制,这是一个机制。二就是两个原则,一个原则是积极预防综合防范,一个叫做立足国情优化配置,或者立足国情适度防范。三就是三个要素,人,管理和技术。四是四个核心能力,法律保障能力,国际影响力等,我们要想让国际认可我们肯定要在信息对抗方面做出相应的工作。五,五项主要技术工作,一个是评估与等保,一个是监控系统,一个是信任体系,一个是应对机制,一个是灾备。 我们说建立机制要有几个层面,组织层面、机制层面和资金层面,组织层面上现在应该说存在问题,本来是有一个国家信息化领导小组 ,我们有一个国家网络与信息安全小组 ,现在这个协调小组目前没有开展工作,也没有宣布撤销。整个协调小组的办公室是放在公信部,存在着运动员和裁判员合一,使得公信力出现了一定的问题。 再有是有一个机构,现在由于国信办合并到公信部,这些专家们曾经有一些糊涂,我们是公信部的专家还是国务院信息办的专家,前一段专门到国务院向德江副总理做了汇报,他们说你们还是国家信息化专家,但是希望同时也作为一个公信部的顾问来帮助他们工作,所以现在定位是这么定的。 机制上一直是齐抓共管,就是谁组建,谁负责,谁主管谁负责,管理机制现在明确了,比如说重要信息系统,你说海关、税务、广电、电信 是谁建的谁负责。其他的事情比如说打击犯罪,或者说网络的安全建设谁负责,这都是相对明确的。再有一个是资金,资金要求多渠道投入现在做的比较好,发改委十一五期间拿出两个数量级的资金来做信息安全方面的建设 ,包括信息安全专项,而且信息安全专项现在也在扩充。过去只是信息安全产品,我们在两年前成功的把服务放进来了,服务放进来以后现在认为还算是成功的,所以去年和今年都还在放。去年年底我们又把示范推了进来,去年已经有了立项,我们今年又把标准推进来,这次大概有13个企业都在报标准。这些都是发改委方面的。科技部有863计划,在信息安全这个专题里面已经投了将近3个亿 ,后面还有两年还会再投,在重点方面投的不是太多,也就在一个亿左右。重大的比较可惜,目前还没有。 专项基金不是特别分,所以几前做了一个网络与信息重大专项,说是重大,在5000多万,这个概念搞的混淆了,网络与信息安全被理解为网络一件事,信息安全是另外一件事,所以信息安全在这里面占的数量就很低,后来又推出来了可信软件,这个有一个多亿,算信息安全方面的一个延伸,但是像软件工程方面侧重的多一些。 两个原则,第一个原则是积极防御,综合防范,基本思想一个是强调协调发展,这个协调强调的是什么呢?就是这个表现在我们主动应对,当你出现了一个新的技术,我们一定要想这个技术会不会带来安全问题,比如说B2B出来,比如说WEB2.0出来,他带来的安全问题是什么,而且要提出来怎么应对,这是一个主动与发展相协调。再一个就是综合,技术管理并重,因为我们说技术解决不了的问题需要靠管理,但是管理可能做不到的还要技术支撑,他们俩谁也离不开谁。再一个就是核心保障,提出来8+2的概念,8就是我们海关、保险、银行、证券、税务、电力、民航 等。 第二个是强调立足国情,适度安全,我们的国情不是有很多钱,什么事都全力以赴往前冲的,首先是确保重点,把优化配置放在重点。然后对重点来说我们要增加投入,但是对于其他的我们要平衡安全和风险之间的平衡值,也许我这个系统风险小或者说就算出现问题损失不大,我的安全投入就会相对降低。再有一个我们要保驾护航,以安全保发展,在发展中促安全。最后就是强调国家、企业、个人的责任义务是什么,就是谁运营谁负责。 三,是三个基本要素,包含人、管理、技术。管理比较明确,我们在总理的报告中也强调对于互联网管理我们强调法律保障,行政监管,行业自律,当然了,还有一个是技术支撑,在这里面因为我们有技术,所以在这儿强调经济制约,在必要的时候要在经济上采取措施制约,不能这么做或者是那么做。表现在了法制、体制、机制几个方面,技术我们主要是靠前沿技术,科技部主要推进,装备设施这个发改委主要推进,安全服务这个是各个部门都在推进。自主产业这个是我们的企业都在推进。 需要的人才就是管理人才和技术人才,我们看人,人我们从两个方面,一个是学历教育,继续教育这个方面,学历教育我们知道国家自从在1999年以后设立了信息安全专业,大概现在有50多所院校有正式的信息安全专业,但是这是计划外的,而且可以理科也可以工科,情况不一样。去年北航设的就是理科专业,我们北邮就是工科专业。本科生是到社会上为社会服务的,研究生层面就是要搞研究的,但是研究生层面只是在二级学科,并没有像原来大家期望的能够上升到一级学科。信息安全作为一个计划外,所以各个单位可以随便放,有一些单位放到了通讯下面的二级学科,有的放在了数学下面,有的放在了计算机下面,各种情况都有。再有就是培训,再有就是网络教育。 还有一个是宣传,我们要对社会宣传,要强化宣传意识,这里面我们靠学会,这也是宣传的一种环境,还有论坛,还有媒体,我们这里有这么多的媒体都在参与。 最后一个就是提出来的要求,采取措施,吸引和用好高素质信息安全和基础人才,这句话我们也在想他落实从用好一点问题没有,现在缺人才,问题是管理和技术合在一起是不是真的有,现在并不是明确的。要不就是技术人才,要不就是管理人才,你培训就培训,双料不太容易,一般都是后面逐渐的演变。 第二个就是管理,管理我把它分解成三制一措施,我们知道我们搞预案都是要三制一案,就是法制、体制、机制和措施。法制就是解决谁来管的问题,我们行政部门领导层国务院有协调小组。我们有一个协调司,现在协调的力度不像过去那么大了,还有执行层,就是各个部委,谁分管的事谁在做,像文化就是文化部,新闻就是国务院新闻办。再有就是技术咨询体系,这个比较多,国家有一个专家咨询委,刚才说了专家咨询委经过德江副总理确认还要继续存在,这两个月就准备再换届,到今年已经是第三届了,马上要进入到第四届。 还有一个是法制,靠什么来管,宏观管理就是,政府法制就是指导思想,告诉大家怎么做,政策就是一种引导,你们要按照政策的思路走,法规就是一个约定,你必须要按照这个来做事情,标准就是大家完全按照确定的事情去做。到微观的就是各单位,单位自己需要有它的规章和制度,有它的安全策略和具体措施。涉及到机制,机制就是怎么管,目前对于信息安全主要是一个测评认证,市场准入,这方面是有。包括我们的产品,服务都在有一个侧面认证和市场准入,政府采购这方面也在做管理。最后就是措施,也就是管的是什么,过去管的比较简单,是密要啊,管的具体的人啊等等,现在就是按照标准在管了,比如说等级保护,系统安全,产品采购,测评,密码技术都是按照具体的标准在管的,这样的话就形成管理,我们说的三制一措施。 第三是技术,这个要加强对引进信息系统的安全可控,现在引进的产品安全不安全不了解,我们在关键部门不太敢用,而且要研究新技术,新任务带来的问题。在这里面国家专门提出来了比较具体的一些包括刚才我念到的文件里面也有,比如说广播电视我们知道我们经常被一些敌对分子把我们的卫星给黑了 ,导致我们的电视被插播,这个需要技术上解决问题。包括我们信息技术的产品漏洞和发现,你拿了产品用了之后发现里面有后门,这样带来的威胁就非常大。还有其他的常规技术像密码、安全审计,隔离防范等,测试与评估取证等等这些都是需要展开研究的。当然了,这里面还提出来了产业的问题,产业的问题就是一个政府导向和市场机制,信息安全政府的需求更大,所以政府往往起到了一种导向的作用,所以我们可以看到甲方大部分是政府,当然了政府的导向之后后面的企业、用户也都会跟进。 技术我们从863角度分成四个层面,物理安全是灾备,运行安全是包括分析、策略、防护等手段,检测包括主动式的和被动式的检测 ,包括应相应,包括系统恢复等,这些都是我们所关注的。数据安全是密码关注和认证关注。内容安全是内容过滤,舆情分析 等,还有数据保护,像刚才介绍的物理隔离都是一种手段。包括内容保护,比如说我们的水印和版权等等。 四是四个核心能力,一个是信心安全的法律保障能力,主要是建立信息安全的法律体系框架,一个是信息安全的基础支撑能力。网络与其宣传的驾驭能力,要分析网络舆情分析系统,国际信息安全影响力。 法律保障,国家一直在互换就是信息安全法,但是现在一个问题就是信息安全法有一点遥遥无期,所以现在主要是在起草信息安全条例,但是由于信息安全条例原来是国信办在做,现在交过来以后好像是断了,本来是去年列入了计划,今年据我所知还没有列入计划,部门的更替现在出现了一种缝隙,需要填补。一旦建好了以后我们的法律应该是以信息安全法律,有了上位法下面才有意义,现在是大量的下面先出来,刑法的285、286、287 都是关于信息安全的法条,行政法规有很多,像国务院的147号令有很多很多都是在做这方面的事情,部门规章在信息安全方面在所管辖的范围内都有相应的规章,再有就是标准,我们等级保护所依据的就是17859,这是最经典的一个标准。 第二个是基础支撑能力,比如说数字证书认证和基础设施体系,像计算机网络应急响应体系,灾难恢复基础设施,我认为基础设施做的不够理想化,还是简单的一对一的备份,需要多个系统备到一个系统中,现在是多个系统被分在一个基地里,这个不太理想。计算机网络应急响应、灾难恢复基础设施,病毒防治等等,这里面有的做的比较成功。 第三个是舆情驾驭能力,中央领导有一段话,这一点就是如何提高舆情的驾驭能力 。一个是舆情怎么发现和获取,怎么分析、领导和预警、处理。首先是两个方面,从疏导的方面要形成正面的舆论强势,要占领网络阵地 ,别人的网站那么吸引人,你的网站为什么不吸引人,这就要想如何迎合网民的喜好。再有就是要做综合治理,对一个有害的行为要有手段。还有就是快速反映机制,网上喊着大家去游行,你要立即发现,或者是喊出来抵制家乐福,我们觉得不好要有应对的措施。 第四个就是国际影响力。我不输于别人,我要不输于别人我就有影响,如果我根本没有过高的本事,我肯定没有任何的影响力。这里面首先要加强管理队伍和指导队伍的建设,再有就是对整体的优势要提出来,还有就是对国内突发事件和非常时期的安全保障条件要提出。 最后五项工作,一个是风险评估和建立完善等级保护制度。第二,加强密码开发利用。第三,完善信息安全监控体系。第四,重视信息安全处置工作。第五,重视灾难备份。在这里我简单说一下风险评估和等级保护之间的关系就是风险评估我们说是一个出发点,等级划分是一个判断点,安全控制是一个落脚点。网络体系主要是对密码进行开发利用,监控体系也是对网络监控,我们刚才说的 863就是很典型的网络监控。再有一个就是应急响应,最后一个是灾难备份,灾难备份也有一系列的规定。最后我们把这个框架拿出来看看,刚才我都说了一遍,整个的原文就是2006-2020年的国家信息化发展战略里面提到的,总结起来相当于两个基本的指导思想,一个是积极防御,综合防范,一个是立足国情科学化配置。在法律层要有一个信息保障体制,在组织成要有信息安全的组织管理体系,在具体措施要有信息安全的技术体系和信息安全的平台以及信息安全的基础设施。这样就形成了我们现在的国家信息安全保障体系,我就说这些,谢谢大家! |
| 来源:北京希艾欧管理技术有限公司 ciotimes.com |
Time:
22:07
Labels:
GFW,
Great Fire Wall,
OpenVPN,
大陆民主进程
20031017
张成良:中国骨干传送网的现状及发展
| 随着电信市场的开放,国家骨干传输网
出现了巨大的变化。从过去单一的中国电信
一家建设和拥有国家骨干网,到现在几家运营公司分别建设长途传输网,正在形成竞争局面。并且各运营公司在网络拓扑,技术选择上也有着不同的考虑和选择,出现了技术方案的多元化趋势。在组网技术上也出现了一些新特点,比如超长复用段MS- Spring保护环和VC-4级联技术。本文力图对各运营商采用的骨干网方案进行简单的介绍,从几方面探讨传送网技术的最新进展和存在的问题。 1 中国电信 的传送网经济基础 ——中国电信国内光缆干线网的大规模建设是从“八五”开始的,其中“八五”建设光缆省际干线22条 ,“九五”期间除新建光缆28条外,还对“八五”期间建造的光缆进行了扩容改造。目前,全国干线传送网光缆总长度达20万公里 ,省际干线光缆网的总长度达8万公里 。已基本形成贯穿南北,横跨东西的“八横八纵”光缆网格局。省际干线已经覆盖全国85%以上的地区城市。 ——从网上应用的系统看,“九五“期间的干线建设全部采用了SDH STM-16系统 ,1998、1999年建设的WDM系统承载的也全是SDH STM-16系统。这标志着SDH系统和承载SDH系统的WDM系统已成为省际干线传输的主力军。 1.1 SDH网络 ——中国电信是1994年 开始引入SDH系统的。第一条是南京-武汉 的 622Mbit/s SDH系统(ECI设备)。在以后的干线网建设中,由于实行了“超前,高起点,加速”的发展战略,所采用的系统从开始的 34Mbit/s、140Mbit/s的PDH系统迅速转移到高速率大容量的2.5 Gbit/s SDH系统,大大提高了系统容量。同时利用SDH丰富的开销和强大的网络管理功能,可进行同步信息传输、复用,分插,使传送网的整体水平上了一个台阶。并初步形成“八横八纵”的省际干线传输网。省际干线传输网光缆已连通包括拉萨在内的所有省会城市,网路结构由树形网向格形网(网孔网)为主的复合同结构演进基本完成。 ——从网络拓扑上看,由于中国地域广大,比照北美AT&T网络,当时的电信主管部门决定采用“Mesh”网状网+DXC的结构,准备在全国60多个城市设立DXC节点,各条干线在DXC节点处将需要转接的电路接入到DXC,由DXC完成电路的调度和保护恢复。但是由于当时DXC4/4技术不够成熟,后来又因为种种原因,DXC的引进工作一直没有展开。目前干线上基本是点到点 2.5 Gbit/s SDH系统,统一的传送网并没有形成。 由于建设周期短,而且大部分设备都是从国外引进的,局限于当时的技术和人们对问题的认识水平,中国电信的SDH传送网络存在着两个急待解决的问题:一是多厂家的上层网络管理问题,二是网络的保护和恢复问题 。 从SDH设备供应商看,中国电信设备主要来自Siemens、Lucent、Ericsson、NEC、Futijsu、Alcatel和Nortel等7个厂家 。多厂家虽然增加了设备选型的灵活性,但是也带来网络管理的复杂性。当前我国的SDH网络维护管理水平无法与世界第二的网络规模相适应,传输网维护管理仍处于较低水平,在网络维护体制、管理手段上存在许多问题,主要表现在:(1)网管系统的多厂商问题严重,网络管理仍停留在对单一厂家、单一干线网元设备的维护上,没有建成综合多厂家设备的网络管理系统。(2)网管系统的运行质量和稳定度不高。(3)没有统一的管理网,难以实现对整个省际干线网有效的管理,传送网使用效率低。在网络的安全性和保护恢复方面,由于DXC迟迟没有引入,严重影响了网络的灵活性和安全性。其主要缺陷表现在:(1)没有传送网自身的交换节点,不能支持交叉连接功能,无法实现灵活的端到端调度,及时满足各种业务网和租用专线的动态要求。不同干线之间不能通过网管系统进行调度,只能进行人工配线。在国家省际干线网地图上,我们看到的只是一条条不相关联的线和孤立的点,这些点是没有自动交换能力的死节点,必须采取人工的手段才能将一段段线路连通。(2)没有足够的空闲(备用)容量支持自愈功能,对断缆等全阻障碍没有恢复能力。业务没有足够的保护和恢复,基本上都是1+0的系统。 ——中国电信已经意识到目前网络存在的问题,已经着手解决网管和网络恢复保护这两大难题。在网络管理方面,已经决定在目前的网元管理系统之上先建立各主要供应商子网管理系统,力争将全国范围内的同一家产品管理起来,然后在于网管理系统之上再考虑建立网络级管理系统。具体是在北京建立Lucent、Siemens的子网管理系统,成都建立Nortel的子网管理中心,石家庄建立Futijsu子网管理系统,杭州建立Ericsson子网管理系统。另外,沉寂了几年的DXC引进也被摆上了议事日程,中国电信将在全国卫个重要节点城市建设DSC4/4恢复网络。 1.2 WDM网络 ——第一条WDM省际干线西安-武汉 工程是1997年引进的(8×2.5Gbit/s系统,Lucent设备),到目前为止,至少有16条干线已经采用了WDM系统。如京—九—广 、京—太—西 等。截至1999年底,WDM系统链路总长度超过25000km,大约占中国电信省际骨干网长度的40%。 ——近两年引进的WDM系统都是16×2.5GKbit/s系统,由于目前还没有那么大需求,系统多未配满。从承载的信号格式看,都是SDH STM-16信号。WDM系统可以承载多种格式信号的特点并没有得到发挥,主要原因在于目前的绝大部分业务仍是话音业务 。 ——1999年开始,中国电信的省际干线不再引进单波长的SDH系统,全面转向承载多个 SDH的开放式WDM系统。开放式WDM系统(带有波长转换单元OTU)由于其可以实现多厂商互连的优点,得到运营商和制造厂商的普遍欢迎,现在的多数产品都采用了开放方式,而且在发送端和接收端都采用了OTU波长变换器,从而更清楚地界定SDH和WDM的物理分界点。 ——从网络拓扑上看,当前建设的WDM全是点到点的线性系统,没有采用OADM(光分插复用设备)。在有业务上下的节点上,采用了复用器/解复用器的背对背方式。世界上大规模建设的WDM系统基本上都是这种系统,环型或其他结构的WDM网络在技术成熟后才会应用。 ——在WDM网管系统建设上,考虑到WDM网络是其他客户信号的传送平台(包括SDH信号),可以承载各种格式的信号,既可以承载标准的SDH信号,也可以承载其它任何不受限的数字信号或模拟信号。因而WDM的网络管理系统也应与其传送的信号的网管分离。对现在的干线工程来讲,就是独立于SDH的网管系统。WDM系统的网管系统只负责对光线路系统的管理,这包括波分复用器、光放大器等。SDH网管系统负责管理ADM、中继器等设备,而不涉及光传输系统。 ——目前引进的WDM系统中,只有4个设备供应商(即Lucent、NEC、Alcatel和Nortel ,其中Lucent的产品占绝大部分),比SDH供货商要少。相对于SDH系统,现在点到点WDM线路系统网管信息较少,基本上没有配置管理信息。在厂商不多,网管信息较少的情况下,比较容易建设WDM系统的网络层管理系统。目前我国采用的WDM系统只能实现告警管理和性能管理,只有“监视”功能,没有“控制”功能。中国电信已经委托国信朗讯公司在各厂家的网元管理系统(EM)层以上开发WDM网络层的网管系统,年内可以完成。 ——另外随着G.655光纤的建设和业务的强烈需求,中国电信传送网络已经开始从基于2.5 Gbit/s WDM系统向基于10 Gbit/s WDM系统过渡。 2 中国联通 的传送网 ——相对于中国电信,成立于1994年中国联通的网络建设较晚,目前中国联通光缆达到2.9万公里,其中干线光缆达到1.4万公里。从世界电信市场开放的形势看,第二运营商总是采用最先进的技术,以使自己处于有利的竞争地位。作为中国的主要电信运营商之一,中国联通在网络拓扑上与中国电信有着显著不同:中国电信采用的是网状网Mesh+DXC4/4恢复网,而联通采用的是自愈环+DXC4/1策略,即采用复用段保护环来组建全国性的骨干传输网。在欧洲和北美的网络中,尤其是新运营商也大多使用环网结构组建国家骨干网,如北美Qwest使用复用段保护环技术组建了覆盖美国的长途传输网。 ——联通的长途光缆网工程分为两个阶段,其中第一阶段采用的是2纤2.5Gbit/s 单向通道保护环(全部采用Lucent设备),已经在1999年12月开通。第二期工程总投资6000万美元左右,一共5个自愈环工程。2个环网采用常规 2.5 Gbit/s 2纤复用段保护环,2个环网采用2.5 Gbit/s SDH 2纤复用段保护环MS-Spring+16WDM系统,1个大环采用10Gbit/s SDH 4纤复用段保护环MS-Spring+16波WDM系统。网间相连的7个重要节点采用了等效256×256 155Mbit/s交叉能力的DXC4/4/1设备,以疏通环间的业务。 ——联通的一些环的长度超过了4000km,引起人们对保护时间的担心。ITU-T在 G.841确定50ms的保护时间时,假设的是1200km周长、16个节点的自愈环。因此超长复用段环网的保护时间会突破50 ms,这主要来自信号在环路上的传输时延。对于5000km的自愈环,仅信号的传输时延就达50ms,如果再加上传输节点对K字节的判断和贯通时间,一般保护倒换时间会增长到 100ms左右。过去国内MS-Spring主要在省网和长长中继网上应用,保护倒换时间矛盾不突出。现在几千公里的超长复用段保护环,引起人们对保护倒换时间的担心。根据国外相关论文和现场网络测试结果,周长为5800km超长SDH 10Gbit/s 4 纤复用段环,环上共有16个节点,实际测试平均保护倒换时间为100ms,最大不超过为110ms。中国联通的复用段虽然比较长,但因节点数较少,复用段环的保护倒换时间不会因环的周长增加而增加很多,主要增加的是传输时延,而节点数少也会相应地使保护倒换时间缩短,一般相信倒换时间会小于100ms,对业务不会造成很大影响。联通网络的另一个突出特点是10Gbit/s复用段保护环的应用。TDM 10 Gbit/s作为一种新技术在电信网上的应用是迟早的事情,中国电信在上海—南京 采用了点到点10Gbit/ s WDM的线性系统,但并没有环型网的应用。联通在华东业务量大的地区采用了10 Gbit/s 4纤超长复用段保护技术(环长度在3000km左右),这种技术选择有着较大的挑战性。 ——在供应商的选择上,联通吸取了中国电信传输网设备选型“七国八制”的教训。已经注意把供货商限制在二三家以内,既有利于开展竞争,不至于在设备价格上被供应商左右,另一方面也尽力保持设备的统一性,有利于建立统一的网络管理系统。 3 中国网通 的传送网 ——中国网络通信有限责任公司(CNC)是1999年8月才注册成立的一家新运营者,主要从事与IP相关的业务,例如IP电话、数据。中国网通将在明年中期建设完成一个全国性的高速宽带IP互联骨干网络,该网络将采用先进的 IP over DWDM 传输技术,建立全国规模的“IP over WDM”网络,一期工程涵盖15个主要城市,包括北京、上海、广州等,总长度达 7000km。传输上采用16 ×2.5Gbit/s WDM技术,物理上为2纤环,路由器直接与WDM设备相连。但在物理层并没有保护措施,所有的业务保护都在IP层实施。 ——在CNC的网络论证初期,对于“IP over WDM”技术进行长途传输时是采用 “IP/SDH/WDM”还是“Gbit/s Ethernet over WDM”进行了激烈的争论。开始人们认为吉比特以太网的价格低,其帧结构可以直接在计算机运载,不存在SDH或ATM那样的再映射协议,而且以太网是非同步的,对同步和时钟不敏感,能容忍各种时延和抖动问题。采用“Gbit/s Ethernet over WDM”可以进 行长途传输,但是实验室结果却证明了此方案的不可行。其原因主要如下:其一目前WDM厂家只开发了2.5Gbit/s的3R光转换单元OTU,对于吉比特以太网(GE)接口却只有2R中继,不能对信号的抖动进行有效抑制,从而系统的输出抖动超标造成传输距离受限;其二由于GE为异步信号,异步传输系统目前无法解决线路传输带来的抖动累积问题,无法实现长距离传输,两路由器采用不同的时钟时,如果路由器的缓存器(buffer)不是足够大,将会引起丢包;其三是因为GE信号在长途传输时,无法实现故障定位,对于信号劣化,也缺乏有效的监测手段,不能提供一定的OAM&P功能。 ——而反观采用SDH帧结构的POS信号效果则好得多。因为一方面IP信号借助于SDH的同步传输技术能充分保证网络的传输性能,且2.5Gbit/s 3R OTU器件技术非常成熟;另一方面IP业务层网管系统可利用SDH帧结构中提供的强大的开销和维护信号实现OAM&P功能,使传输网络具有较好的可靠性。 ——现在,中国网通公司(CNC)已经决定采用“IP/SDH/WDM”方式建设全国范围内“IP over WDM”传输网络。该WDM网络的客户信号虽然还是SDH帧格式,但帧结构为VC-4-16C,承载的是IP信号,而中国电信的 WDM网络上的SDH客户信号帧结构则不是W-4的级联,业务上基本上都是电话信号 。 ——网通公司在组建骨干网时,除了采取租赁光纤 方式外,还开始建设自己的光缆骨干网。值得一提的是目前开始建设的两条光缆干线:北京—武汉 和北京—济南 ,首次采用1800km的G.655光纤,这显示了新公司的不同凡响和技术选择的前瞻性。虽然G.655光纤国内专家已经论证多次,但国内应用进展缓慢。另外,考虑到光缆线路扩容的难度,网通公司也首先采用管道光缆技术,采用气吹缆技术,本次工程一次敷设8个管道,以方便将来的光缆扩容。 4 总 结 ——当前,传送网络正在发生深刻的变化,目前至少中国电信、中国联通、中国网通、广电总局 4个运营商都在建设自己的国内长途光缆干线网。各个运营公司采取了不同的网络拓扑或技术,出现了技术方案的多元化趋势。国家骨干传送网将出现激烈的竞争,各运营商纷纷投资长途网络的主要原因在于更容易、更快地收回投资。多运营者环境下网间互通也成了大家关心的一个问题,国家标准也变得更加重要。如何在新形势下建设国家骨干光缆传送网是值得每一个运营者和从事传输研究的人们深入研究的问题。 |
| 作者:张成良 (信息产业部电信传输研究所 北京100045) 来源: 光纤日报 |
20020410
OpenVPN How-to 1.0
| 重要历史文献 有空再翻译整理
|
||||||||||||
OpenVPN HOWTO 1.0
Introduction This HOWTO is mainly relevant for setting up single-client or static site-to-site VPNs and is oriented more towards OpenVPN 1.x than 2.0. To take advantage of the OpenVPN 2.0 client/server capability, see the OpenVPN 2.0 HOWTO . This document describes setting up OpenVPN in a typical Home to Office telecommuting configuration. While this HOWTO presents in-depth configuration examples, simpler examples are shown in the examples section of the man page. Additional Articles and Documentation Many excellent articles and HOWTOs exist for configuring OpenVPN in different environments. Basic Tunnel Types There are two basic types of tunnels that one can create with OpenVPN: * Routed IP tunnel s -- best used to route point-to-point IP traffic without broadcasts. Slightly more efficient than bridged ethernet tunnels and easier to configure. This HOWTO (below) covers routed IP tunnels. * Bridged Ethernet Tunnels -- can be used to tunnel both IP and non-IP protocols. This type of tunnel is appropriate for applications which communicate via broadcasts, such as Windows file and print sharing (without a WINS server) and LAN games. Slightly more complex to configure. A Mini-HOWTO for bridged ethernet tunnels. Routed IP tunnel HOWTO Given the interrelated issues involved in configuring firewalls, VPNs, and NAT, we will attempt to describe a complete system configuration rather than isolating the VPN component of the setup. In our example, both Home and Office private networks are linked to the internet via two gateway machines which each have a public IP address. Each gateway machine contains two NICs, one connected to the private network, the other connected to the internet. The gateway machines provide NAT, firewall, and VPN services for the machines on the private networks. The Home and Office sides of the configuration are roughly symmetrical except the Office gateway machine has a fixed IP address while the Home machine has a DHCP dynamic address. In the following examples, all configuration files shown are also available in the OpenVPN distribution. Home and Office IP Networking Parameters
Installing OpenVPN If your system doesn't have the OpenSSL Library , you should download and install it. If you want to take advantage of compression on the VPN link, or you want to install OpenVPN as an RPM package, install the LZO Library . If you are using Linux 2.2 or earlier, download the TUN/TAP driver . Users of Linux 2.4.7 or greater should find the TUN/TAP driver already bundled with their kernel. Users of Linux 2.4.0 -> 2.4.6 should note the caveat at the end of the INSTALL file. Now download the latest release of OpenVPN . Install from tarball Unzip the distribution: gzip -dc openvpn-1.6.0.tar.gz | tar xvf - Build OpenVPN: cd openvpn-1.6.0 ./configure make make install If you didn't download the LZO Library, add --disable-lzo to the configure command. Other options can be enabled such as pthread support (./configure --enable-pthread) to improve latency during SSL/TLS dynamic key exchanges. The command ./configure --help will show all configuration options. Install from RPM First build the RPM file. This will require that the OpenSSL, pthread, and LZO libraries are present. Normally only the LZO library requires an explicit download and install; the other libraries are present by default on most Linux distributions. rpmbuild -tb openvpn-1.6.0.tar.gz The RPM build process will generate a lot of output. If the build succeeds, there should be a note near the end of the output stating the name of the binary RPM file which was written. Install the binary RPM with the command: rpm -Uvh binary-RPM-file Configuring the TUN/TAP driver One-time Configuration Steps If you are using Linux 2.4.7 or higher, chances are good that the TUN/TAP driver is already bundled with your kernel. You can confirm this with the command locate if_tun.h which should show a file such as /usr/include/linux/if_tun.h. For Linux 2.4.7 or higher, if you installed from the tarball, enter the following command to configure the TUN/TAP device node (you can omit this step if you installed from RPM, as the RPM install will do it automatically for you): mknod /dev/net/tun c 10 200 If you are using Linux 2.2, you should obtain Version 1.1 of the TUN/TAP kernel module and follow the installation instructions. Once-per-reboot Configuration Steps On Linux, prior to using OpenVPN or any other program which uses TUN/TAP devices, you should load the TUN/TAP kernel module: modprobe tun and enable IP forwarding: echo 1 > /proc/sys/net/ipv4/ip_forward Configure Firewall and NAT This section assumes you are using Linux 2.4 with an iptables firewall . Here is a sample firewall configuration that provides NAT for machines on a private network to access the internet, stateful outgoing connection tracking, and OpenVPN support: sample-config-files/firewall.sh #!/bin/bash # A Sample OpenVPN-aware firewall. # eth0 is connected to the internet. # eth1 is connected to a private subnet. # Change this subnet to correspond to your private # ethernet subnet. Home will use 10.0.1.0/24 and # Office will use 10.0.0.0/24. PRIVATE=10.0.0.0/24 # Loopback address LOOP=127.0.0.1 # Delete old iptables rules # and temporarily block all traffic. iptables -P OUTPUT DROP iptables -P INPUT DROP iptables -P FORWARD DROP iptables -F # Set default policies iptables -P OUTPUT ACCEPT iptables -P INPUT DROP iptables -P FORWARD DROP # Prevent external packets from using loopback addr iptables -A INPUT -i eth0 -s $LOOP -j DROP iptables -A FORWARD -i eth0 -s $LOOP -j DROP iptables -A INPUT -i eth0 -d $LOOP -j DROP iptables -A FORWARD -i eth0 -d $LOOP -j DROP # Anything coming from the Internet should have a real Internet address iptables -A FORWARD -i eth0 -s 192.168.0.0/16 -j DROP iptables -A FORWARD -i eth0 -s 172.16.0.0/12 -j DROP iptables -A FORWARD -i eth0 -s 10.0.0.0/8 -j DROP iptables -A INPUT -i eth0 -s 192.168.0.0/16 -j DROP iptables -A INPUT -i eth0 -s 172.16.0.0/12 -j DROP iptables -A INPUT -i eth0 -s 10.0.0.0/8 -j DROP # Block outgoing NetBios (if you have windows machines running # on the private subnet). This will not affect any NetBios # traffic that flows over the VPN tunnel, but it will stop # local windows machines from broadcasting themselves to # the internet. iptables -A FORWARD -p tcp --sport 137:139 -o eth0 -j DROP iptables -A FORWARD -p udp --sport 137:139 -o eth0 -j DROP iptables -A OUTPUT -p tcp --sport 137:139 -o eth0 -j DROP iptables -A OUTPUT -p udp --sport 137:139 -o eth0 -j DROP # Check source address validity on packets going out to internet iptables -A FORWARD -s ! $PRIVATE -i eth1 -j DROP # Allow local loopback iptables -A INPUT -s $LOOP -j ACCEPT iptables -A INPUT -d $LOOP -j ACCEPT # Allow incoming pings (can be disabled) iptables -A INPUT -p icmp --icmp-type echo-request -j ACCEPT # Allow services such as www and ssh (can be disabled) iptables -A INPUT -p tcp --dport http -j ACCEPT iptables -A INPUT -p tcp --dport ssh -j ACCEPT # Allow incoming OpenVPN packets # Duplicate the line below for each # OpenVPN tunnel, changing --dport n # to match the OpenVPN UDP port. # # In OpenVPN, the port number is # controlled by the --port n option. # If you put this option in the config # file, you can remove the leading '--' # # If you taking the stateful firewall # approach (see the OpenVPN HOWTO), # then comment out the line below. iptables -A INPUT -p udp --dport 1194 -j ACCEPT # Allow packets from TUN/TAP devices. # When OpenVPN is run in a secure mode, # it will authenticate packets prior # to their arriving on a tun or tap # interface. Therefore, it is not # necessary to add any filters here, # unless you want to restrict the # type of packets which can flow over # the tunnel. iptables -A INPUT -i tun+ -j ACCEPT iptables -A FORWARD -i tun+ -j ACCEPT iptables -A INPUT -i tap+ -j ACCEPT iptables -A FORWARD -i tap+ -j ACCEPT # Allow packets from private subnets iptables -A INPUT -i eth1 -j ACCEPT iptables -A FORWARD -i eth1 -j ACCEPT # Keep state of connections from local machine and private subnets iptables -A OUTPUT -m state --state NEW -o eth0 -j ACCEPT iptables -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT iptables -A FORWARD -m state --state NEW -o eth0 -j ACCEPT iptables -A FORWARD -m state --state ESTABLISHED,RELATED -j ACCEPT # Masquerade local subnet iptables -t nat -A POSTROUTING -s $PRIVATE -o eth0 -j MASQUERADE OpenVPN offers a few additional options on firewall setup: * If both OpenVPN peers reference the other with an explicit --remote option, and stateful firewalls that provide UDP connection tracking (such as iptables) exist between the peers, it is possible to run OpenVPN without any explicit firewall rules, if both peers originate regular pings to each other to keep the connection alive. To do this, simply run OpenVPN with the --remote peer option, and specify --ping 15 to ensure that packets flow over the tunnel at least once every 15 seconds. * The above option is less convenient if one of the peers changes its IP address frequently such as a DHCP or a dial-in peer . For these cases, the sample firewall configuration above will allow incoming packets on UDP port 1194 (OpenVPN's default UDP port) from any IP address. This should be considered safe in any of OpenVPN's secure modes, since all incoming tunnel packets must pass an authentication test or they will be dropped. * If you choose to fully open OpenVPN's incoming UDP port as in the sample firewall configuration above, you might want to take advantage of the --tls-auth option to do double authentication on the TLS control channel, using both the RSA key and a pre-shared secret passphrase as a second line of defense against DoS or active attacks . For more information on --tls-auth, see the openvpn man page. Build RSA Certificates and Keys OpenVPN has two secure modes, one based on SSL/TLS security using RSA certificates and keys, the other using a pre-shared static key. While SSL/TLS + RSA keys is arguably the most secure option, static keys have the benefit of simplicity. If you want to use RSA keys, read on. For static keys, jump forward to the Build Pre-Shared Static Key section. We will build RSA certificates and keys using the openssl command , included in the OpenSSL library distribution. RSA certificates are public keys that also have other secure fields embedded in them such as the Common Name or email address of the certificate holder. OpenVPN provides the ability to write scripts to test these fields prior to authentication. For more information, see the --tls-verify option in the openvpn man page. In our example we will follow the apache convention of using the .crt file extension to denote certificate files and the .key file extension to denote private key files. Private key files must always be kept secure . Certificate files can be freely published or shared. Select one machine such as Office to be the key management machine . First edit the /usr/share/ssl/openssl.cnf file (this file may exist in a different place, so use locate openssl.cnf to find it). You may want to make some changes to this file: * Make a directory to serve as your key working area and change dir to point to it. * Consider increasing default_days so your VPN doesn't mysteriously stop working after exactly one year. * Set certificate and private_key to point to your master certificate authority certificate and private key files which we will presently generate. In the examples below, we will assume that your certificate authority certificate is named my-ca.crt and your certificate authority private key is named my-ca.key. * Note the files index.txt and serial. Initialize index.txt to be empty and serial to contain an initial serial number such as 01. * If you are paranoid about key sizes, increase default_bits to 2048. OpenVPN will have no problem handling a 2048 bit RSA key if you have built OpenVPN with pthread support, to enable background processing of RSA keys. You can still use large keys even without pthread support, but you will see some latency degradation on the tunnel during SSL/TLS key negotiations. For a good article on choosing an RSA key size, see the April 2002 issue of Bruce Schneier's Crypto-Gram Newsletter. After openssl.cnf has been edited, create your master certificate authority certificate/private-key pair: openssl req -nodes -new -x509 -keyout my-ca.key -out my-ca.crt -days 3650 This will create a master certificate authority certificate/private-key pair valid for 10 years. Now create certificate/private-key pairs for both Home and Office. When prompted for the common name, make sure to use a different name for Home and Office. openssl req -nodes -new -keyout office.key -out office.csr openssl ca -out office.crt -in office.csr openssl req -nodes -new -keyout home.key -out home.csr openssl ca -out home.crt -in home.csr Now copy home.crt, home.key, and my-ca.crt to Home over a secure channel, though actually only .key files should be considered non-public. Now create Diffie Hellman parameters on Office with the following command: openssl dhparam -out dh1024.pem 1024 Increase the bit size from 1024 to 2048 if you also increased it in openssl.cnf. For the paranoid, consider omitting the -nodes option on the openssl commands above. This will cause each private key to be encrypted with a password, making the keys secure even if someone broke onto your server and stole your private key files. The downside of this approach is that every time you run OpenVPN, you will need to type in the password. For more information see the --askpass option in the openvpn man page. If you find manual RSA key management confusing, note that OpenVPN will interoperate with any X509 certificate management tool or service including the commercial CAs such as Thawte or Verisign. Check out the OpenCA project for an example of what's being done with certificate/key management in the Open Source realm. In addition, the OpenVPN distribution contains a small set of scripts which can be used to simplify RSA certificate and key management. Important Note on the use of commercial certificate authorities (CAs) with OpenVPN It should be noted that OpenVPN's security model in SSL/TLS mode is oriented toward users who will generate their own root certificate, and hence be their own CA . In SSL/TLS mode, OpenVPN authenticates its peer by checking that the peer-supplied certificate was signed by the CA certificate specified in the --ca option. Like the SSL-based secure web, the security of OpenVPN's SSL/TLS mode rests on the infeasibility of forging a root certificate signature. This authentication procedure works perfectly well if you have generated your own root certificate, but presents a problem if you wish to use the root certificate of a commercial CA such as Thawte. If, for example, you specified Thawte's root certificate in the --ca option, any certificate signed by Thawte would now be able to authenticate with your OpenVPN peer -- certainly not what you would want. Luckily there is a solution to this problem in the --tls-verify option. This option will allow you to execute a command to check the contents of a certificate, to fine-tune the selection of which certificate is allowed, and which is not. See the script verify-cn in the sample-scripts subdirectory for an example of how to do this, and also see the man page for the --tls-verify option. Important Note on possible "Man-in-the-Middle" attack if clients do not verify the certificate of the server they are connecting to. See discussion here. http://openvpn.net/index.php/open-source/documentation/howto.html#mitm Configuration file using SSL/TLS mode and RSA certificates/keys In our example, we will use OpenVPN configuration files. OpenVPN allows options to be passed on either the command line or in one or more configuration files. Options in configuration files can omit the leading "--" that is required for command line options. Set up the following configuration files: sample-config-files/tls-office.conf # # Sample OpenVPN configuration file for # office using SSL/TLS mode and RSA certificates/keys. # # '#' or ';' may be used to delimit comments. # Use a dynamic tun device. # For Linux 2.2 or non-Linux OSes, # you may want to use an explicit # unit number such as "tun1". # OpenVPN also supports virtual # ethernet "tap" devices. dev tun # 10.1.0.1 is our local VPN endpoint (office). # 10.1.0.2 is our remote VPN endpoint (home). ifconfig 10.1.0.1 10.1.0.2 # Our up script will establish routes # once the VPN is alive. up ./office.up # In SSL/TLS key exchange, Office will # assume server role and Home # will assume client role. tls-server # Diffie-Hellman Parameters (tls-server only) dh dh1024.pem # Certificate Authority file ca my-ca.crt # Our certificate/public key cert office.crt # Our private key key office.key # OpenVPN 2.0 uses UDP port 1194 by default # (official port assignment by iana.org 11/04). # OpenVPN 1.x uses UDP port 5000 by default. # Each OpenVPN tunnel must use # a different port number. # lport or rport can be used # to denote different ports # for local and remote. ; port 1194 # Downgrade UID and GID to # "nobody" after initialization # for extra security. ; user nobody ; group nobody # If you built OpenVPN with # LZO compression, uncomment # out the following line. ; comp-lzo # Send a UDP ping to remote once # every 15 seconds to keep # stateful firewall connection # alive. Uncomment this # out if you are using a stateful # firewall. ; ping 15 # Uncomment this section for a more reliable detection when a system # loses its connection. For example, dial-ups or laptops that # travel to other locations. ; ping 15 ; ping-restart 45 ; ping-timer-rem ; persist-tun ; persist-key # Verbosity level. # 0 -- quiet except for fatal errors. # 1 -- mostly quiet, but display non-fatal network errors. # 3 -- medium output, good for normal operation. # 9 -- verbose, good for troubleshooting verb 3 sample-config-files/office.up #!/bin/sh route add -net 10.0.1.0 netmask 255.255.255.0 gw $5 sample-config-files/tls-home.conf # # Sample OpenVPN configuration file for # home using SSL/TLS mode and RSA certificates/keys. # # '#' or ';' may be used to delimit comments. # Use a dynamic tun device. # For Linux 2.2 or non-Linux OSes, # you may want to use an explicit # unit number such as "tun1". # OpenVPN also supports virtual # ethernet "tap" devices. dev tun # Our OpenVPN peer is the office gateway. remote 1.2.3.4 # 10.1.0.2 is our local VPN endpoint (home). # 10.1.0.1 is our remote VPN endpoint (office). ifconfig 10.1.0.2 10.1.0.1 # Our up script will establish routes # once the VPN is alive. up ./home.up # In SSL/TLS key exchange, Office will # assume server role and Home # will assume client role. tls-client # Certificate Authority file ca my-ca.crt # Our certificate/public key cert home.crt # Our private key key home.key # OpenVPN 2.0 uses UDP port 1194 by default # (official port assignment by iana.org 11/04). # OpenVPN 1.x uses UDP port 5000 by default. # Each OpenVPN tunnel must use # a different port number. # lport or rport can be used # to denote different ports # for local and remote. ; port 1194 # Downgrade UID and GID to # "nobody" after initialization # for extra security. ; user nobody ; group nobody # If you built OpenVPN with # LZO compression, uncomment # out the following line. ; comp-lzo # Send a UDP ping to remote once # every 15 seconds to keep # stateful firewall connection # alive. Uncomment this # out if you are using a stateful # firewall. ; ping 15 # Uncomment this section for a more reliable detection when a system # loses its connection. For example, dial-ups or laptops that # travel to other locations. ; ping 15 ; ping-restart 45 ; ping-timer-rem ; persist-tun ; persist-key # Verbosity level. # 0 -- quiet except for fatal errors. # 1 -- mostly quiet, but display non-fatal network errors. # 3 -- medium output, good for normal operation. # 9 -- verbose, good for troubleshooting verb 3 sample-config-files/home.up #!/bin/sh route add -net 10.0.0.0 netmask 255.255.255.0 gw $5 Build A Pre-Shared Static Key In contrast with RSA key management, using a pre-shared static key has the benefit of simplicity. The major downside of using static keys is that you give up the notion of perfect forward secrecy, meaning that if an attacker steals your static key, everything that was ever encrypted with it is compromised. Generate a static key with the following command: openvpn --genkey --secret static.key The static key file is formatted in ascii and looks like this: -----BEGIN OpenVPN Static key V1----- e5e4d6af39289d53 171ecc237a8f996a 97743d146661405e c724d5913c550a0c 30a48e52dfbeceb6 e2e7bd4a8357df78 4609fe35bbe99c32 bdf974952ade8fb9 71c204aaf4f256ba eeda7aed4822ff98 fd66da2efa9bf8c5 e70996353e0f96a9 c94c9f9afb17637b 283da25cc99b37bf 6f7e15b38aedc3e8 e6adb40fca5c5463 -----END OpenVPN Static key V1----- An OpenVPN static key file contains enough entropy to key both a 512 bit cipher key and a 512 bit HMAC key for authentication. Copy static.key to the other peer via a secure medium such as scp or copy-paste in ssh. Configuration File using a Pre-Shared Static Key In our example, we will use OpenVPN configuration files. OpenVPN allows options to be passed on either the command line or in one or more configuration files. Options in configuration files can omit the leading "--" that is required for command line options. Set up the following configuration files: sample-config-files/static-office.conf # # Sample OpenVPN configuration file for # office using a pre-shared static key. # # '#' or ';' may be used to delimit comments. # Use a dynamic tun device. # For Linux 2.2 or non-Linux OSes, # you may want to use an explicit # unit number such as "tun1". # OpenVPN also supports virtual # ethernet "tap" devices. dev tun # 10.1.0.1 is our local VPN endpoint (office). # 10.1.0.2 is our remote VPN endpoint (home). ifconfig 10.1.0.1 10.1.0.2 # Our up script will establish routes # once the VPN is alive. up ./office.up # Our pre-shared static key secret static.key # OpenVPN 2.0 uses UDP port 1194 by default # (official port assignment by iana.org 11/04). # OpenVPN 1.x uses UDP port 5000 by default. # Each OpenVPN tunnel must use # a different port number. # lport or rport can be used # to denote different ports # for local and remote. ; port 1194 # Downgrade UID and GID to # "nobody" after initialization # for extra security. ; user nobody ; group nobody # If you built OpenVPN with # LZO compression, uncomment # out the following line. ; comp-lzo # Send a UDP ping to remote once # every 15 seconds to keep # stateful firewall connection # alive. Uncomment this # out if you are using a stateful # firewall. ; ping 15 # Uncomment this section for a more reliable detection when a system # loses its connection. For example, dial-ups or laptops that # travel to other locations. ; ping 15 ; ping-restart 45 ; ping-timer-rem ; persist-tun ; persist-key # Verbosity level. # 0 -- quiet except for fatal errors. # 1 -- mostly quiet, but display non-fatal network errors. # 3 -- medium output, good for normal operation. # 9 -- verbose, good for troubleshooting verb 3 sample-config-files/office.up #!/bin/sh route add -net 10.0.1.0 netmask 255.255.255.0 gw $5 sample-config-files/static-home.conf # # Sample OpenVPN configuration file for # home using a pre-shared static key. # # '#' or ';' may be used to delimit comments. # Use a dynamic tun device. # For Linux 2.2 or non-Linux OSes, # you may want to use an explicit # unit number such as "tun1". # OpenVPN also supports virtual # ethernet "tap" devices. dev tun # Our OpenVPN peer is the office gateway. remote 1.2.3.4 # 10.1.0.2 is our local VPN endpoint (home). # 10.1.0.1 is our remote VPN endpoint (office). ifconfig 10.1.0.2 10.1.0.1 # Our up script will establish routes # once the VPN is alive. up ./home.up # Our pre-shared static key secret static.key # OpenVPN 2.0 uses UDP port 1194 by default # (official port assignment by iana.org 11/04). # OpenVPN 1.x uses UDP port 5000 by default. # Each OpenVPN tunnel must use # a different port number. # lport or rport can be used # to denote different ports # for local and remote. ; port 1194 # Downgrade UID and GID to # "nobody" after initialization # for extra security. ; user nobody ; group nobody # If you built OpenVPN with # LZO compression, uncomment # out the following line. ; comp-lzo # Send a UDP ping to remote once # every 15 seconds to keep # stateful firewall connection # alive. Uncomment this # out if you are using a stateful # firewall. ; ping 15 # Uncomment this section for a more reliable detection when a system # loses its connection. For example, dial-ups or laptops that # travel to other locations. ; ping 15 ; ping-restart 45 ; ping-timer-rem ; persist-tun ; persist-key # Verbosity level. # 0 -- quiet except for fatal errors. # 1 -- mostly quiet, but display non-fatal network errors. # 3 -- medium output, good for normal operation. # 9 -- verbose, good for troubleshooting verb 3 sample-config-files/home.up #!/bin/sh route add -net 10.0.0.0 netmask 255.255.255.0 gw $5 Starting the VPN in SSL/TLS mode On Home, start the VPN with the command: openvpn --config tls-home.conf On Office, start the VPN with the command: openvpn --config tls-office.conf Starting the VPN in Static Key mode On Home, start the VPN with the command: openvpn --config static-home.conf On Office, start the VPN with the command: openvpn --config static-office.conf Test the VPN On Home, test the VPN by pinging Office through the tunnel: ping 10.1.0.1 On Office, test the VPN by pinging Home through the tunnel: ping 10.1.0.2 If these tests silently fail, you may want to re-edit the configuration files and set the verbosity level to 8 which will produce much more detailed debugging output. Also consult the FAQ for more information on troubleshooting. If these tests succeed, now try pinging through the tunnel using machines on the private networks other than the OpenVPN gateway machines, to test the routing. Basically any machine on the 10.0.1.0/24 subnet should be able to access any machine on the 10.0.0.0/24 subnet and vice versa. If that works, congratulations! If not, you might want to check out the OpenVPN Mailing List archives to see if anyone else has had a similar problem. If you don't find a resolution to your problem there, consider posting to the openvpn-users list. Make the VPN DHCP-aware If you recall, in our example network configuration, Home has a dynamic IP address which could change without warning. If you are using dhcpcd as your client daemon, it is easy to construct a script which will be run anytime the client's IP address changes. This script will be named something like /etc/dhcpc/dhcpcd-eth0.exe. Basically, you should add a line to this script which will send a SIGUSR1 or SIGHUP signal to the OpenVPN daemon such as: killall -HUP openvpn When OpenVPN receives this signal it will close and reopen the network connection to its peer, using the new IP address assigned by DHCP. You should also use the --float option if you are connecting to a peer which may change its IP address due to a DHCP reset. It is also possible to handle DHCP resets with the SIGUSR1 signal which is like SIGHUP except it offers more fine-grained control over which OpenVPN subsystems are reset. A SIGUSR1 signal can also be generated internally based on --ping and --ping-restart. The --persist-tun option allows a reset without closing and reopening the TUN device (which allows seamless connectivity through the tunnel across DHCP resets). The --persist-remote-ip option allows for preservation of remote IP address across DHCP resets. This allows both OpenVPN peers to be DHCP clients. The --persist-key option doesn't re-read key files on restart (which allows an OpenVPN daemon to be restarted even if its privileges were downgraded with --user or --group). For more information on using OpenVPN in a dynamic IP address context, see the FAQ. OpenVPN can also be used in cases where both ends of the connection are dynamic. Start the VPN automatically on reboot First make a directory to store OpenVPN keys and configuration files such as /etc/openvpn. Decide whether you want to use TLS or Static Key mode and copy appropriate .conf, .up, .key, .pem, and .crt files to /etc/openvpn. Protect your .key files: chmod go-rwx /etc/openvpn/*.key If you are using Linux iptables, edit the firewall configuration file firewall.sh, making changes appropriate to your site and copy to /etc/openvpn. Make a startup script that looks something like this: sample-config-files/openvpn-startup.sh #!/bin/sh # A sample OpenVPN startup script # for Linux. # openvpn config file directory dir=/etc/openvpn # load the firewall $dir/firewall.sh # load TUN/TAP kernel module modprobe tun # enable IP forwarding echo 1 > /proc/sys/net/ipv4/ip_forward # Invoke openvpn for each VPN tunnel # in daemon mode. Alternatively, # you could remove "--daemon" from # the command line and add "daemon" # to the config file. # # Each tunnel should run on a separate # UDP port. Use the "port" option # to control this. Like all of # OpenVPN's options, you can # specify "--port 8000" on the command # line or "port 8000" in the config # file. openvpn --cd $dir --daemon --config vpn1.conf openvpn --cd $dir --daemon --config vpn2.conf openvpn --cd $dir --daemon --config vpn2.conf And make a shutdown script like this: sample-config-files/openvpn-shutdown.sh #!/bin/sh # stop all openvpn processes killall -TERM openvpn Finally, add calls to openvpn-startup.sh and openvpn-shutdown.sh to your system startup and shutdown scripts or to your /etc/init.d directory. Managing startup and shutdown of multiple OpenVPN tunnels Here is a sample /etc/init.d script which will automatically create an OpenVPN tunnel for each .conf file in /etc/openvpn. This script is installed by default if you install OpenVPN from an RPM package. sample-scripts/openvpn.init #!/bin/sh # # openvpn This shell script takes care of starting and stopping # openvpn on RedHat or other chkconfig-based system. # # chkconfig: 345 24 76 # # description: OpenVPN is a robust and highly flexible tunneling application that # uses all of the encryption, authentication, and certification features # of the OpenSSL library to securely tunnel IP networks over a single # UDP port. # # Contributed to the OpenVPN project by # Douglas Keller <doug@voidstar.dyndns.org> # 2002.05.15 # To install: # copy this file to /etc/rc.d/init.d/openvpn # shell> chkconfig --add openvpn # shell> mkdir /etc/openvpn # make .conf or .sh files in /etc/openvpn (see below) # To uninstall: # run: chkconfig --del openvpn # Author's Notes: # # I have created an /etc/init.d init script and enhanced openvpn.spec to # automatically register the init script. Once the RPM is installed you # can start and stop OpenVPN with "service openvpn start" and "service # openvpn stop". # # The init script does the following: # # - Starts an openvpn process for each .conf file it finds in # /etc/openvpn. # # - If /etc/openvpn/xxx.sh exists for a xxx.conf file then it executes # it before starting openvpn (useful for doing openvpn --mktun...). # # - In addition to start/stop you can do: # # service openvpn reload - SIGHUP # service openvpn reopen - SIGUSR1 # service openvpn status - SIGUSR2 # # Modifications: # # 2003.05.02 # * Changed == to = for sh compliance (Bishop Clark). # * If condrestart|reload|reopen|status, check that we were # actually started (James Yonan). # * Added lock, piddir, and work variables (James Yonan). # * If start is attempted twice, without an intervening stop, or # if start is attempted when previous start was not properly # shut down, then kill any previously started processes, before # commencing new start operation (James Yonan). # * Do a better job of flagging errors on start, and properly # returning success or failure status to caller (James Yonan). # # 2005.04.04 # * Added openvpn-startup and openvpn-shutdown script calls # (James Yonan). # # Location of openvpn binary openvpn="" openvpn_locations="/usr/sbin/openvpn /usr/local/sbin/openvpn" for location in $openvpn_locations do if [ -f "$location" ] then openvpn=$location fi done # Lockfile lock="/var/lock/subsys/openvpn" # PID directory piddir="/var/run/openvpn" # Our working directory work=/etc/openvpn # Source function library. . /etc/rc.d/init.d/functions # Source networking configuration. . /etc/sysconfig/network # Check that networking is up. if [ ${NETWORKING} = "no" ] then echo "Networking is down" exit 0 fi # Check that binary exists if ! [ -f $openvpn ] then echo "openvpn binary not found" exit 0 fi # See how we were called. case "$1" in start) echo -n $"Starting openvpn: " /sbin/modprobe tun >/dev/null 2>&1 # From a security perspective, I think it makes # sense to remove this, and have users who need # it explictly enable in their --up scripts or # firewall setups. #echo 1 > /proc/sys/net/ipv4/ip_forward # Run startup script, if defined if [ -f $work/openvpn-startup ]; then $work/openvpn-startup fi if [ ! -d $piddir ]; then mkdir $piddir fi if [ -f $lock ]; then # we were not shut down correctly for pidf in `/bin/ls $piddir/*.pid 2>/dev/null`; do if [ -s $pidf ]; then kill `cat $pidf` >/dev/null 2>&1 fi rm -f $pidf done rm -f $lock sleep 2 fi rm -f $piddir/*.pid cd $work # Start every .conf in $work and run .sh if exists errors=0 successes=0 for c in `/bin/ls *.conf 2>/dev/null`; do bn=${c%%.conf} if [ -f "$bn.sh" ]; then . $bn.sh fi rm -f $piddir/$bn.pid $openvpn --daemon --writepid $piddir/$bn.pid --config $c --cd $work if [ $? = 0 ]; then successes=1 else errors=1 fi done if [ $errors = 1 ]; then failure; echo else success; echo fi if [ $successes = 1 ]; then touch $lock fi ;; stop) echo -n $"Shutting down openvpn: " for pidf in `/bin/ls $piddir/*.pid 2>/dev/null`; do if [ -s $pidf ]; then kill `cat $pidf` >/dev/null 2>&1 fi rm -f $pidf done # Run shutdown script, if defined if [ -f $work/openvpn-shutdown ]; then $work/openvpn-shutdown fi success; echo rm -f $lock ;; restart) $0 stop sleep 2 $0 start ;; reload) if [ -f $lock ]; then for pidf in `/bin/ls $piddir/*.pid 2>/dev/null`; do if [ -s $pidf ]; then kill -HUP `cat $pidf` >/dev/null 2>&1 fi done else echo "openvpn: service not started" exit 1 fi ;; reopen) if [ -f $lock ]; then for pidf in `/bin/ls $piddir/*.pid 2>/dev/null`; do if [ -s $pidf ]; then kill -USR1 `cat $pidf` >/dev/null 2>&1 fi done else echo "openvpn: service not started" exit 1 fi ;; condrestart) if [ -f $lock ]; then $0 stop # avoid race sleep 2 $0 start fi ;; status) if [ -f $lock ]; then for pidf in `/bin/ls $piddir/*.pid 2>/dev/null`; do if [ -s $pidf ]; then kill -USR2 `cat $pidf` >/dev/null 2>&1 fi done echo "Status written to /var/log/messages" else echo "openvpn: service not started" exit 1 fi ;; *) echo "Usage: openvpn {start|stop|restart|condrestart|reload|reopen|status}" exit 1 ;; esac exit 0 Instantiate an OpenVPN daemon using inetd or xinetd The common xinetd service can be used to automatically instantiate an OpenVPN daemon upon receipt of an initial datagram from a remote peer. This xinetd configuration will cause xinetd to listen on UDP port 1194 for the first datagram of an incoming OpenVPN session (using a pre-shared key), at which time xinetd will automatically instantiate an OpenVPN daemon to handle the session. Note the use of the --inactive switch which will cause the OpenVPN daemon to time out and exit after 10 minutes of idle time. After the OpenVPN daemon exits for whatever reason, the xinetd service will resume listening on the port, and will again instantiate an OpenVPN daemon to handle additional incoming connections. Also note that xinetd will initially instantiate the OpenVPN daemon with root privileges, but OpenVPN will subsequently (after reading the protected key file) downgrade its privilege to nobody. The key file can be generated with the following command: openvpn --genkey --secret key Note that each OpenVPN tunnel needs to run on its own separate port number, and needs its own xinetd configuration file. This is because OpenVPN needs specific information on each potential incoming connection, including key files, TUN/TAP devices, tunnel endpoints, and routing configuration. At this point in OpenVPN's development, it is not capable of handling any sort of incoming connection template that would allow a single configuration file to describe a large class of potential connecting clients. Since OpenVPN is implemented as a UDP server, it cannot take advantage of the infrastructure available to forking TCP servers which listen on a fixed port number, then dynamically fork off a new handling daemon for each client session. Nonetheless, incoming connection templates are on the wish list and may be implemented if there is sufficient interest and support from the developer and user community. sample-config-files/xinetd-server-config # An xinetd configuration file for OpenVPN. # # This file should be renamed to openvpn or something suitably # descriptive and copied to the /etc/xinetd.d directory. # xinetd can then be made aware of this file by restarting # it or sending it a SIGHUP signal. # # For each potential incoming client, create a separate version # of this configuration file on a unique port number. Also note # that the key file and ifconfig endpoints should be unique for # each client. This configuration assumes that the OpenVPN # executable and key live in /root/openvpn. Change this to fit # your environment. service openvpn_1 { type = UNLISTED port = 1194 socket_type = dgram protocol = udp wait = yes user = root server = /root/openvpn/openvpn server_args = --inetd --dev tun --ifconfig 10.4.0.2 10.4.0.1 --secret /root/openvpn/key --inactive 600 --user nobody } sample-config-files/xinetd-client-config # This OpenVPN config file # is the client side counterpart # of xinetd-server-config dev tun ifconfig 10.4.0.1 10.4.0.2 remote my-server port 1194 user nobody secret /root/openvpn/key inactive 600 |
||||||||||||
| 来源: http://openvpn.net/index.php/open-source/documentation/miscellaneous/88-1xhowto.html |
Subscribe to:
Posts (Atom)