VPN(IPsec VPN and SSL VPN)
Network

VPN(IPsec VPN and SSL VPN)

1. VPN(Virtual Private Network)

- VPN or ๊ฐ€์ƒ ๋„คํŠธ์›Œํฌ ์‚ฌ์„ค๋ง์œผ๋กœ ๋ถˆ๋ฆฌ๋ฉฐ VPN์œผ๋กœ ํ†ต์‹ ํ•  ๊ฒฝ์šฐ VPN Tuennling์„ ํ†ตํ•˜์—ฌ ์•”ํ˜ธํ™” ํ†ต์‹ ์„ ํ•˜๊ฒŒ ๋ฉ๋‹ˆ๋‹ค.

- ์•”ํ˜ธํ™” ํ†ต์‹ ์œผ๋กœ ๊ธฐ๋ฐ€์„ฑ(Confidentiality), ๋ฐ์ดํ„ฐ ๋ณ€์กฐ๋ฅผ ํ™•์ธํ•˜์—ฌ ๋ฌด๊ฒฐ์„ฑ(Integrity), ์ƒ๋Œ€๋ฐฉ ์ธ์ฆ(Authentication)์„ ํ†ตํ•œ ๋ณด์•ˆ์„ ์ œ๊ณตํ•ฉ๋‹ˆ๋‹ค.(CIA ๊ธฐ๋Šฅ)

 

2. IPsec VPN

- Site to Site๋กœ ๋งบ๋Š” VPN์ž…๋‹ˆ๋‹ค. 

- IETF์—์„œ ๊ถŒ๊ณ ํ•˜๋Š” IPsec ๊ธฐ์ˆ ์„ ์ค€์ˆ˜ํ•˜์—ฌ ๋งŒ๋“  VPN์ž…๋‹ˆ๋‹ค.

- ๊ฐ Site์˜ ๊ฒŒ์ดํŠธ์›จ์ด ์žฅ๋น„๋ผ๋ฆฌ ์–ด๋– ํ•œ ๋ฐฉ์‹์œผ๋กœ ์•”ํ˜ธํ™”๋ฅผ ํ• ์ง€ ๊ฒฐ์ •ํ•˜์—ฌ ๋™์ผํ•˜๊ฒŒ ์„ค์ •ํ•ด์•ผ ํ•ฉ๋‹ˆ๋‹ค.

- ๊ณต์ธ IP๊ฐ€ ์•„๋‹Œ ์‚ฌ์„ค IP๋กœ ํ†ต์‹  ๊ฐ€๋Šฅํ•ฉ๋‹ˆ๋‹ค.

- ์•„๋ž˜ ๋‘๊ฐ€์ง€ ๋ฐฉ์‹ ์ค‘ ํ•˜๋‚˜๋กœ ํŠธ๋ž˜ํ”ฝ์„ ๋ณดํ˜ธํ•ฉ๋‹ˆ๋‹ค.

- AH(Authentication Header) : ๋ฌด๊ฒฐ์„ฑ, ์ธ์ฆ๋งŒ ๊ฒ€์ฆํ•ฉ๋‹ˆ๋‹ค. ๊ธฐ๋ฐ€์„ฑ์„ ์œ„ํ•œ ์•”ํ˜ธํ™”๊ฐ€ ์‚ฌ์šฉ๋˜์ง€ ์•Š์•„ ๊ฑฐ์˜ ์‚ฌ์šฉํ•˜์ง€ ์•Š์Šต๋‹ˆ๋‹ค.

- ESP(Encapsulation Security Payload) : AH + ๊ธฐ๋ฐ€์„ฑ์„ ์œ„ํ•œ ์•”ํ˜ธํ™”๊นŒ์ง€ ๊ฒ€์ฆํ•ฉ๋‹ˆ๋‹ค.

 

3. SSL VPN

- Site to User๋กœ ๋งบ๋Š” VPN์ž…๋‹ˆ๋‹ค.

- 1994๋…„ ๋„ท์Šค์ผ€์ดํ”„์‚ฌ์—์„œ 1.0, 2.0 ๋ฒ„์ „์„ ํŒ”๋ตคํ•˜์˜€์œผ๋ฉฐ 1999๋…„ IETF์—์„œ ์ด๋ฅผ ํ‘œ์ค€ํ™”ํ•˜์—ฌ TLS(Transport Layer Security)๋ผ๊ณ  ๋ถ€๋ฆ…๋‹ˆ๋‹ค.

- HTTPS์˜ SSL์„ ์ด์šฉํ•˜์—ฌ HTTP ํŠธ๋ž˜ํ”ฝ์„ ๋ณดํ˜ธํ•˜๋Š” ๊ฒƒ๊ณผ ๋™์ผํ•œ ๊ธฐ์ˆ ์ž…๋‹ˆ๋‹ค.

- ํšŒ์‚ฌ ์ง์›์ด ๋ณธ์‚ฌ ์ธํŠธ๋ผ๋„ท์œผ๋กœ ์ ‘์†ํ•˜๊ธฐ ์œ„ํ•˜์—ฌ ๋ณ„๋„๋กœ ํšŒ์‚ฌ SSL VPN์„ ์ ‘์†ํ•˜์—ฌ ์ธํŠธ๋ผ๋„ท ์ ‘์† ํŠธ๋ž˜ํ”ฝ์„ ๋ณดํ˜ธํ•˜๊ธฐ๋„ ํ•ฉ๋‹ˆ๋‹ค.

- ํ˜„์žฌ TLS 1.2์™€ TLS 1.3์œผ๋กœ๋งŒ ์•”ํ˜ธํ™” ๊ฐ€๋Šฅํ•ฉ๋‹ˆ๋‹ค.

 

https://eunhyee.tistory.com/205

 

HTTPS ํŒจํ‚ท ๋ถ„์„(TLS 1.2์™€ TLS 1.3)

1. TLS 1.2 โ‘  DNS๋ฅผ ํ†ตํ•˜์—ฌ URL์œผ๋กœ IP ํ™•์ธ โ‘ก TCP Handshaking(1 Round Trip) - 3 Way Hanshaking https://eunhyee.tistory.com/96?category=937476 SYN_RCV ์ƒํƒœ ๋ณ€๊ฒฝ SYN+ACK - Sever๋Š” SYN์„ ํ™•์ธํ•˜๊ณ  Cl..

eunhyee.tistory.com

https://eunhyee.tistory.com/199

 

HTTP and TLS(SSL)

1. HTTP vs HTTPS - HTTP(Hypertext Transfer Protocol) : ์ „์†ก์ค‘ ์•”ํ˜ธํ™” X, 80 Port - HTTPS(HTTP Secure) : ์ „์†ก์ค‘ ์•”ํ˜ธํ™” O, 443 Port - ํ•ด์ปค๊ฐ€ HTTP ํŒจํ‚ท์„ ๊ฐˆ์ทจํ•˜๊ฒŒ ๋  ๊ฒฝ์šฐ ํ‰๋ฌธ์˜ ์ •๋ณด๋“ค์ด ๋ณด์ด์ง€๋งŒ HTTPS..

eunhyee.tistory.com