作者投稿和查稿 主编审稿 专家审稿 编委审稿 远程编辑

计算机工程 ›› 2009, Vol. 35 ›› Issue (4): 154-156. doi: 10.3969/j.issn.1000-3428.2009.04.054

• 安全技术 • 上一篇    下一篇

基于防火墙钩子的IPSec VPN研究与实现

张 明,陈性元,杜学绘,钱雁斌   

  1. (解放军信息工程大学电子技术学院,郑州 450004)
  • 收稿日期:1900-01-01 修回日期:1900-01-01 出版日期:2009-02-20 发布日期:2009-02-20

Research and Implementation of IPSec VPN Based on Firewall Hook

ZHANG Ming, CHEN Xing-yuan, DU Xue-hui, QIAN Yan-bin   

  1. (Institute of Electronic Technology, PLA Information Engineering University, Zhengzhou 450004)
  • Received:1900-01-01 Revised:1900-01-01 Online:2009-02-20 Published:2009-02-20

摘要: 针对采用网络驱动接口规范(NDIS)实现IPSec VPN系统过程中存在的问题,提出一种基于防火墙钩子的IPSec VPN系统,研究了Windows网络层防火墙钩子数据包过滤技术,将IPSec封包处理提升到网络层中加以实现。该系统能有效解决由NDIS实现方式引起的MTU处理、路由和数据包分片、重组等问题,提高了系统处理效率,且具有较好的应用特性。

关键词: IPSec VPN系统, 防火墙钩子, 网络驱动接口规范

Abstract: Aiming at the problems existed in the process of using Network Driver Interface Specification(NDIS) to implement IPSec VPN system, a new IPSec VPN system based on firewall hook is presented, and the data packet filtering technology for firewall hook at Windows network layer is researched, which upgrades the IPSec encapsulation processing to network layer and implements it. This system can effectively solve the problems caused by NDIS such as MTU, routing and reassembly. It promotes the processing efficiency and has better performance of application.

Key words: IPSec VPN system, firewall hook, Network Driven Interface Specification(NDIS)

中图分类号: