²úÆ··ÖÀà+
GREÐÒé½éÉÜ
ÏîÄ¿±³¾°
IPv6µÄ²¿Êð´óÖÂÒª¾ÀúÒ»¸ö½¥½øµÄ¹ý³Ì£¬ÔÚ³õʼ½×¶Î£¬IPv4µÄÍøÂ纣ÑóÖлá³öÏÖÈô¸É¾Ö²¿ÁãÉ¢µÄIPv6¹Âµº£¬ÎªÁ˱£³ÖͨÐÅ£¬ÕâЩ¹ÂµºÍ¨¹ý¿çÔ½IPv4µÄËíµÀ±Ë´ËÁ¬½Ó£»Ëæ×ÅIPv6¹æÄ£µÄÓ¦Óã¬ÔÀ´µÄ¹ÂµºÖ𽥾ۺϳÉΪÁ˹ǸɵÄIPv6 InternetÍøÂ磬ÐγÉÓÚIPv4¹Ç¸ÉÍø²¢´æµÄ¾ÖÃæ£¬ÔÚIPv6¹Ç¸ÉÉÏ¿ÉÒÔÒýÈëÁË´óÁ¿µÄÐÂÒµÎñ£¬Í¬Ê±¿ÉÒÔ³ä·Ö·¢»ÓIPv6µÄÖî¶àÓÅÊÆ¡£ÎªÁËʵÏÖIPv6ºÍIPv4ÍøÂç×ÊÔ´µÄ»¥·Ã£¬»¹ÐèҪת»»·þÎñÆ÷ÒÔʵÏÖv6ºÍv4µÄ»¥Í¨£»×îºó£¬IPv4¹Ç¸ÉÍøÖð²½Î®Ëõ³É¾Ö²¿µÄ¹Âµº£¬Í¨¹ýËíµÀÁ¬½Ó£¬IPv6Õ¼¾ÝÁËÖ÷µ¼µØÎ»£¬¾ß±¸È«Çò·¶Î§µÄÁ¬Í¨ÐÔ¡£
IPv6ÌṩºÜ¶à¹ý¶É¼¼ÊõÀ´ÊµÏÖÉÏÊöÕâÑùÒ»¸öÑݽø¹ý³Ì¡£ÕâЩ¹ý¶É¼¼ÊõÎ§ÈÆÁ½ÀàÎÊÌâ½â¾ö£º
IPv6¹Âµº»¥Í¨¼¼Êõ£ºÊµÏÖIPv6ÍøÂçºÍIPv6ÍøÂçµÄ»¥Í¨
IPv6ºÍIPv4»¥Í¨¼¼Êõ£ºÊµÏÖÁ½¸ö²»Í¬ÍøÂçÖ®¼ä»¥Ïà·ÃÎÊ×ÊÔ´
Ŀǰ£¬½â¾öÉÏÊöÎÊÌâµÄ»ù±¾¹ý¶É¼¼ÊõÓÐÁ½ÖÖ£ºË«Õ»ºÍËíµÀ¡£
˫ջ£º¼´É豸Éý¼¶µ½IPv6µÄͬʱ±£ÁôIPv4Ö§³Ö£¬¿ÉÒÔͬʱ·ÃÎÊIPv6ºÍIPv4É豸£¬°üº¬Ë«ÐÒéÕ»Ö§³Ö£¬Ó¦ÓóÌÐòÒÀ¿¿DNSµØÖ·½âÎö·µ»ØµÄµØÖ·ÀàÐÍ£¬À´¾ö¶¨Ê¹ÓúÎÖÖÐÒéÕ»¡£
ËíµÀ£ºÍ¨¹ýÔÚÒ»ÖÖÐÒéÖгÐÔØÁíÒ»ÖÖÐÒ飬ʵÏÖ¿çÔ½²»Í¬ÓòµÄ»¥Í¨£¬¾ßÌå¿ÉÒÔÊÇIPv6-in-IPv4,IPv6-in-MPLS,IPv4-in-IPv6µÈËíµÀÀàÐÍ¡£
GREËíµÀ£¨VPN£©
GREÓëIP in IP¡¢IPX over IPµÈ·â×°ÐÎʽºÜÏàËÆ£¬µ«±ÈËûÃǸüͨÓá£ÔÚGREµÄ´¦ÀíÖУ¬ºÜ¶àÐÒéµÄϯλ²îÒì¶¼±»ºöÂÔ£¬ÕâʹµÃGRE²»ÏÞÓÚij¸öÌØ¶¨µÄ¡°X over Y¡±Ó¦Ó㬶øÊÇÒ»ÖÖ×î»ù±¾µÄ·â×°ÐÎʽ¡£
ÔÚ×î¼òµ¥µÄÇé¿öÏ£¬Â·ÓÉÆ÷½ÓÊÕµ½Ò»¸öÐèÒª·â×°ºÍ·ÓɵÄÔʼÊý¾Ý±¨ÎÄ£¨Payload£©£¬Õâ¸ö±¨ÎÄÊ×Ïȱ»GRE·â×°¶ø³ÉGRE±¨ÎÄ£¬½Ó×ű»·â×°ÔÚIPÐÒéÖУ¬È»ºóÍêÈ«ÓÉIP²ã¸ºÔð´Ë±¨ÎĵÄת·¢¡£Ôʼ±¨ÎĵÄÐÒé±»³ÆÖ®Îª³Ë¿ÍÐÒ飬GRE±»³ÆÖ®Îª·â×°ÐÒ飬¶ø¸ºÔðת·¢µÄIPÐÒé±»³ÆÖ®Îª´«µÝ£¨Delivery£©ÐÒé»ò´«Ê䣨Transport£©ÐÒé¡£×¢Òâµ½ÔÚÒÔÉϵÄÁ÷³ÌÖв»ÓùØÐij˿ÍÐÒéµÄ¾ßÌå¸ñʽ»òÄÚÈÝ£¬Õû¸ö±»·â×°µÄ±¨Îĸñʽ£º
-------------------------------
| Delivery Header |
| (Transport Protocol) |
-------------------------------
| GRE Header |
| (Encapsulation Protocol |
-------------------------------
| Payload Packet |
| (Passenger Protocol) |
-------------------------------
GRE±¨Í·µÄ¸ñʽÈçÏÂ:
0 1 2 3
0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2
+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+
|C|R|K|S|s|Recur| Flags | Ver | Protocol Type |
+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+
| Checksum (optional) | Offset (optional) |
+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+
| Key (optional) |
+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+
| Sequence Number (optional) |
+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+
| Routing (optional) |
+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+
GREËíµÀÔÀí£º
1¡¢·â×°
Ingress PE´ÓÁ¬½ÓXÐÒéµÄ½Ó¿Ú½ÓÊÕµ½XÐÒ鱨Îĺó£¬Ê×ÏȽ»ÓÉXÐÒé´¦Àí¡£
XÐÒé¸ù¾Ý±¨ÎÄÍ·ÖеÄÄ¿µÄµØÖ·ÔÚ·Óɱí»òת·¢±íÖвéÕÒ³ö½Ó¿Ú£¬È·¶¨ÈçºÎת·¢´Ë±¨ÎÄ¡£Èç¹û·¢ÏÖ³ö½Ó¿ÚÊÇGRE Tunnel½Ó¿Ú£¬Ôò¶Ô±¨ÎĽøÐÐGRE·â×°£¬¼´Ìí¼ÓGREÍ·¡£
¸ù¾Ý¹Ç¸ÉÍø´«ÊäÐÒéΪIP£¬¸ø±¨ÎļÓÉÏIPÍ·¡£IPÍ·µÄÔ´µØÖ·¾ÍÊÇËíµÀÔ´µØÖ·£¬Ä¿µÄµØÖ·¾ÍÊÇËíµÀÄ¿µÄµØÖ·¡£
¸ù¾Ý¸ÃIPÍ·µÄÄ¿µÄµØÖ·£¨¼´ËíµÀÄ¿µÄµØÖ·£©£¬ÔڹǸÉÍøÂ·ÓɱíÖвéÕÒÏàÓ¦µÄ³ö½Ó¿Ú²¢·¢Ëͱ¨ÎÄ¡£Ö®ºó£¬·â×°ºóµÄ±¨ÎĽ«ÔڸùǸÉÍøÖд«Êä¡£
2¡¢½â·â×°
½â·â×°¹ý³ÌºÍ·â×°¹ý³ÌÏà·´¡£
Egress PE´ÓGRE Tunnel½Ó¿ÚÊÕµ½¸Ã±¨ÎÄ£¬·ÖÎöIPÍ··¢ÏÖ±¨ÎĵÄÄ¿µÄµØÖ·Îª±¾É豸£¬ÔòEgress PEÈ¥µôIPÍ·ºó½»¸øGREÐÒé´¦Àí¡£GREÐÒé°þµôGRE±¨Í·£¬»ñÈ¡XÐÒ飬ÔÙ½»ÓÉXÐÒé¶Ô´ËÊý¾Ý±¨ÎĽøÐкóÐøµÄת·¢´¦Àí¡£
ÅäÖÃ
×ó±ßΪR3£¬ÓÒ±ßΪR4
R3£º
ÅäÖù«ÍøIP£º
interface GE0/3/4
ip address 34.0.0.3/24
no shutdown
!
ÅäÖÃË½ÍøIP£º
interface GE0/1/3
ip address 13.0.0.3/24
no shutdown
!
ÅäÖÃGRE Tunnel£º
interface tunnel100
tunnel mode gre
tunnel source 34.0.0.3
tunnel destination 34.0.0.4
ip address 192.168.100.3/24 //ºÍ¶Ô·½Tunnel IPÔÚÍ¬Ò»Íø¶Î
no shutdown
!
ÅäÖ÷ÓÉ£º
ip route 0.0.0.0/0 34.0.0.4 //µ½¹«ÍøÄ¬ÈÏ·ÓÉ
ip route 24.0.0.0/24 tunnel100 //µ½¶Ô·½Ë½ÍøÂ·ÓÉͨ¹ýTunnel 100·ÃÎÊ
!
R4£º
ÅäÖù«ÍøIP£º
interface GE0/3/4
ip address 34.0.0.4/24
no shutdown
!
ÅäÖÃË½ÍøIP£º
interface GE0/2/4
ip address 24.0.0.4/24
no shutdown
!
ÅäÖÃGRE Tunnel£º
interface tunnel100
tunnel mode gre
tunnel source 34.0.0.4
tunnel destination 34.0.0.3
ip address 192.168.100.4/24 //ºÍ¶Ô·½Tunnel IPÔÚÍ¬Ò»Íø¶Î
no shutdown
!
ÅäÖ÷ÓÉ£º
ip route 0.0.0.0/0 34.0.0.3 //µ½¹«ÍøÄ¬ÈÏ·ÓÉ
ip route 13.0.0.0/24 tunnel100 //µ½¶Ô·½Ë½ÍøÂ·ÓÉͨ¹ýTunnel 100·ÃÎÊ
!
ÔÚR4ÉÏping R3µÄË½ÍøµØÖ·13.0.0.3,×¥°üÈçÏ£º
GRE±¨ÎĽâÎö

GREÍ·¸÷×ֶνâÊÍ£º
C УÑéºÍÑé֤λ¡£1-GREÍ·²åÈëÁËУÑéºÍ£¨Checksum£©×ֶΡ£0-GREÍ·²»°üº¬Ð£ÑéºÍ×ֶΡ£
K ¹Ø¼ü×Öλ¡£1-GREÍ·²åÈëÁ˹ؼü×Ö£¨Key£©×ֶΡ£0-GREÍ·²»°üº¬¹Ø¼ü×Ö×ֶΡ£
Recursion GRE±¨Îı»·â×°µÄ²ãÊý¡£Ò»´ÎGRE·â×°ºó½«¸Ã×ֶμÓ1¡£Èç¹û·â×°²ãÊý´óÓÚ3£¬Ôò¶ªÆú¸Ã±¨ÎÄ¡£¸Ã×ֶεÄ×÷ÓÃÊÇ·ÀÖ¹±¨Îı»ÎÞÏ޴εķâ×°¡£RFC1701¹æ¶¨¸Ã×Ö¶ÎĬÈÏֵΪ0¡£RFC2784¹æ¶¨µ±·¢ËͺͽÓÊܶ˸Ã×ֶβ»Ò»ÖÂʱ²»»áÒýÆðÒì³££¬ÇÒ½ÓÊն˱ØÐëºöÂÔ¸Ã×ֶΡ£É豸ʵÏÖʱ¸Ã×ֶνöÔÚ¼Ó·â×°±¨ÎÄʱÓÃ×÷±ê¼ÇËíµÀǶÌײãÊý£¬GRE½â·â×°±¨ÎÄʱ²»¸ÐÖª¸Ã×ֶΣ¬²»»áÓ°Ï챨ÎĵĴ¦Àí¡£
Flags Ô¤Áô×ֶΡ£µ±Ç°±ØÐëÖÃΪ0¡£
Version °æ±¾×ֶΡ£±ØÐëÖÃΪ0¡£
Protocol ±êʶ³Ë¿ÍÐÒéµÄÐÒéÀàÐÍ¡£³£¼ûµÄ³Ë¿ÍÐÒéΪIPv4ÐÒ飬ÐÒé´úÂëΪ0800¡£
Checksum ¶ÔGREÍ·¼°Æä¸ºÔصÄУÑéºÍ×ֶΡ£
Key ¹Ø¼ü×Ö×ֶΣ¬ËíµÀ½ÓÊÕ¶ËÓÃÓÚ¶ÔÊÕµ½µÄ±¨ÎĽøÐÐÑéÖ¤¡£
ĿǰʵÏÖµÄGREÍ·²»°üº¬Ô´Â·ÓÉ×ֶΣ¬ËùÒÔBit 1¡¢Bit 3ºÍBit 4¶¼ÖÃΪ0¡£
GRE°²È«»úÖÆ
GRE±¾ÉíÌṩÁ½ÖÖ»ù±¾µÄ°²È«»úÖÆ£ºÐ£ÑéºÍÑéÖ¤£¬Ê¶±ð¹Ø¼ü×Ö¡£
1¡¢Ð£ÑéºÍÑéÖ¤
УÑéºÍÑéÖ¤ÊÇÖ¸¶Ô·â×°µÄ±¨ÎĽøÐж˵½¶ËУÑé¡£
ÈôGRE±¨ÎÄÍ·ÖеÄCλ±êʶλÖÃ1£¬ÔòУÑéºÍÓÐЧ¡£·¢ËÍ·½½«¸ù¾ÝGREÍ·¼°PayloadÐÅÏ¢¼ÆËãУÑéºÍ£¬²¢½«°üº¬Ð£ÑéºÍµÄ±¨ÎÄ·¢Ë͸ø¶Ô¶Ë¡£½ÓÊÕ·½¶Ô½ÓÊÕµ½µÄ±¨ÎļÆËãУÑéºÍ£¬²¢Ó뱨ÎÄÖеÄУÑéºÍ±È½Ï£¬Èç¹ûÒ»ÖÂÔò¶Ô±¨ÎĽøÒ»²½´¦Àí£¬·ñÔò¶ªÆú¡£
ËíµÀÁ½¶Ë¿ÉÒÔ¸ù¾Ýʵ¼ÊÓ¦ÓõÄÐèÒª¾ö¶¨ÅäÖÃУÑéºÍ»ò½ûֹУÑéºÍ¡£Èç¹û±¾¶ËÅäÖÃÁËУÑéºÍ¶ø¶Ô¶ËûÓÐÅäÖã¬Ôò±¾¶Ë½«²»»á¶Ô½ÓÊÕµ½µÄ±¨ÎĽøÐÐУÑéºÍ¼ì²é£¬µ«¶Ô·¢Ë͵ı¨ÎļÆËãУÑéºÍ£»Ïà·´£¬Èç¹û±¾¶ËûÓÐÅäÖÃУÑéºÍ¶ø¶Ô¶ËÒÑÅäÖã¬Ôò±¾¶Ë½«¶Ô´Ó¶Ô¶Ë·¢À´µÄ±¨ÎĽøÐÐУÑéºÍ¼ì²é£¬µ«¶Ô·¢Ë͵ı¨ÎIJ»¼ÆËãУÑéºÍ¡£
2¡¢Ê¶±ð¹Ø¼ü×Ö
ʶ±ð¹Ø¼ü×Ö£¨Key£©ÑéÖ¤ÊÇÖ¸¶ÔTunnel½Ó¿Ú½øÐÐУÑ顣ͨ¹ýÕâÖÖÈõ°²È«»úÖÆ£¬¿ÉÒÔ·ÀÖ¹´íÎóʶ±ð¡¢½ÓÊÕÆäËüµØ·½À´µÄ±¨ÎÄ¡£
RFC1701Öй涨£ºÈôGRE±¨ÎÄÍ·ÖеÄKλΪ1£¬ÔòÔÚGREÍ·ÖвåÈëÒ»¸öËÄ×Ö½Ú³¤¹Ø¼ü×Ö×ֶΣ¬ÊÕ·¢Ë«·½½«½øÐÐʶ±ð¹Ø¼ü×ÖµÄÑéÖ¤¡£
¹Ø¼ü×ÖµÄ×÷ÓÃÊDZêÖ¾ËíµÀÖеÄÁ÷Á¿£¬ÊôÓÚͬһÁ÷Á¿µÄ±¨ÎÄʹÓÃÏàͬµÄ¹Ø¼ü×Ö¡£ÔÚ±¨ÎĽâ·âװʱ£¬GRE½«»ùÓڹؼü×ÖÀ´Ê¶±ðÊôÓÚÏàͬÁ÷Á¿µÄÊý¾Ý±¨ÎÄ¡£Ö»ÓÐTunnelÁ½¶ËÉèÖõÄʶ±ð¹Ø¼ü×ÖÍêȫһÖÂʱ²ÅÄÜͨ¹ýÑéÖ¤£¬·ñÔò½«±¨ÎĶªÆú¡£ÕâÀïµÄ¡°ÍêȫһÖ¡±ÊÇÖ¸Á½¶Ë¶¼²»ÉèÖÃʶ±ð¹Ø¼ü×Ö£¬»òÕßÁ½¶Ë¶¼ÉèÖÃÏàͬµÄ¹Ø¼ü×Ö¡£
GREµÄKeepalive¼ì²â
ÓÉÓÚGREÐÒé²¢²»¾ß±¸¼ì²âÁ´Â·×´Ì¬µÄ¹¦ÄÜ£¬Èç¹û¶Ô¶Ë½Ó¿Ú²»¿É´ï£¬ËíµÀ²¢²»Äܼ°Ê±¹Ø±Õ¸ÃTunnelÁ¬½Ó£¬ÕâÑù»áÔì³ÉÔ´¶Ë»á²»¶ÏµÄÏò¶Ô¶Ëת·¢Êý¾Ý£¬¶ø¶Ô¶ËÈ´ÒòËíµÀ²»Í¨½ÓÊÕ²»µ½±¨ÎÄ£¬Óɴ˾ͻáÐγÉÊý¾Ý¿Õ¶´¡£
GREµÄKeepalive¼ì²â¹¦ÄÜ¿ÉÒÔ¼ì²âËíµÀ״̬£¬¼´¼ì²âËíµÀ¶Ô¶ËÊÇ·ñ¿É´ï¡£Èç¹û¶Ô¶Ë²»¿É´ï£¬ËíµÀÁ¬½Ó¾Í»á¼°Ê±¹Ø±Õ£¬±ÜÃâÒò¶Ô¶Ë²»¿É´ï¶øÔì³ÉµÄÊý¾Ý¶ªÊ§£¬ÓÐЧ·ÀÖ¹Êý¾Ý¿Õ¶´£¬±£Ö¤Êý¾Ý´«ÊäµÄ¿É¿¿ÐÔ¡£
Keepalive¼ì²â¹¦ÄܵÄʵÏÖ¹ý³ÌÈçÏ£º
µ±GREËíµÀµÄÔ´¶ËʹÄÜKeepalive¼ì²â¹¦Äܺ󣬾ʹ´½¨Ò»¸ö¶¨Ê±Æ÷£¬ÖÜÆÚµØ·¢ËÍKeepalive̽²â±¨ÎÄ£¬Í¬Ê±Í¨¹ý¼ÆÊýÆ÷½øÐв»¿É´ï¼ÆÊý¡£Ã¿·¢ËÍÒ»¸ö̽²â±¨ÎÄ£¬²»¿É´ï¼ÆÊý¼Ó1¡£
¶Ô¶ËÿÊÕµ½Ò»¸ö̽²â±¨ÎÄ£¬¾Í¸øÔ´¶Ë·¢ËÍÒ»¸ö»ØÓ¦±¨ÎÄ¡£
Èç¹ûÔ´¶ËµÄ¼ÆÊýÆ÷ֵδ´ïµ½Ô¤ÏÈÉèÖõÄÖµ¾ÍÊÕµ½»ØÓ¦±¨ÎÄ£¬¾Í±íÃ÷¶Ô¶Ë¿É´ï¡£Èç¹ûÔ´¶ËµÄ¼ÆÊýÆ÷Öµµ½´ïÔ¤ÏÈÉèÖõÄÖµ¡ª¡ªÖØÊÔ´ÎÊý£¨Retry Times£©Ê±£¬»¹Ã»ÊÕµ½»ØËͱ¨ÎÄ£¬¾ÍÈÏΪ¶Ô¶Ë²»¿É´ï¡£´Ëʱ£¬Ô´¶Ë½«¹Ø±ÕËíµÀÁ¬½Ó¡£µ«ÊÇÔ´¶Ë¿ÚÈÔ»á¼ÌÐø·¢ËÍKeepalive±¨ÎÄ£¬Èô¶Ô¶ËUp£¬ÔòÔ´¶Ë¿ÚÒ²»áUp£¬½¨Á¢ËíµÀÁ´½Ó¡£
¶ÔÓÚÉ豸ʵÏÖµÄGRE Keepalive¼ì²â¹¦ÄÜ£¬Ö»ÒªÔÚËíµÀÒ»¶ËÅäÖÃKeepalive£¬¸Ã¶Ë¾Í¾ß±¸Keepalive¹¦ÄÜ£¬¶ø²»ÒªÇóËíµÀ¶Ô¶ËÒ²¾ß±¸¸Ã¹¦ÄÜ¡£ËíµÀ¶Ô¶ËÊÕµ½±¨ÎÄ£¬Èç¹ûÊÇKeepalive̽²â±¨ÎÄ£¬ÎÞÂÛÊÇ·ñÅäÖÃKeepalive£¬¶¼»á¸øÔ´¶Ë·¢ËÍÒ»¸ö»ØÓ¦±¨ÎÄ¡£
GRE¾ßÓÐÈçϵÄÓŵ㣺
¶àÐÒéµÄ±¾µØÍø¿ÉÒÔͨ¹ýµ¥Ò»ÐÒéµÄ¹Ç¸ÉÍøÊµÏÖ´«Ê䣻
½«Ò»Ð©²»ÄÜÁ¬ÐøµÄ×ÓÍøÁ¬½ÓÆðÀ´£¬ÓÃÓÚ×齨VPN£»
À©´óÁËÍøÂçµÄ¹¤×÷·¶Î§£¬°üÀ¨ÄÇЩ·ÓÉÍø¹ÜÓÐÏÞµÄÐÒé¡£ÈçIPX°ü×î¶à¿ÉÒÔת·¢16´Î£¨¼´¾¹ý16¸ö·ÓÉÆ÷£©£¬¶øÔÚÒ»¸öTunnelÁ¬½ÓÖп´ÉÏÈ¥Ö»¾¹ýÒ»¸ö·ÓÉÆ÷¡£
ÓÉÓÚGREÊǽ«Ò»¸öÊý¾Ý°ü·â×°µ½ÁíÒ»¸öÊý¾Ý°üÖУ¬Òò´Ë¿ÉÄÜ»áÓöµ½GREµÄÊý¾Ý±¨´óÓÚÍøÂç½Ó¿ÚËùÉ趨µÄÊý¾Ý°ü×î´ó³ß´çµÄÇé¿ö¡£½â¾öÕâÖÖÎÊÌâµÄ·½·¨ÊÇÔÚËíµÀ½Ó¿ÚÉÏÅäÖÃip tcp adjust-mss 1436¡£ÁíÍ⣬ËäÈ»GRE²¢²»Ö§³Ö¼ÓÃÜ£¬µ«ÊÇ¿ÉÒÔͨ¹ýTunnel keyÃüÁîÔÚËíµÀµÄÁ½Í·¸÷ÉèÖÃÒ»¸öÃÜÔ¿¡£Õâ¸öÃÜÔ¿Æäʵ¾ÍÊÇÒ»¸öÃ÷ÎĵÄÃÜÂë¡£ÓÉÓÚGREËíµÀûÓÐ״̬¿ØÖÆ£¬¿ÉÄÜËíµÀµÄÒ»¶ËÒѾ¹Ø±Õ£¬¶øÁíÒ»¶ËÈÔÈ»¿ªÆô¡£ÕâÒ»ÎÊÌâµÄ½â¾ö·½°¸¾ÍÊÇÔÚËíµÀÁ½¶Ë¿ªÆôkeepaliveÊý¾Ý°ü£¬Ëü¿ÉÒÔÈÃËíµÀÒ»¶Ë¶¨Ê±ÏòÁíÒ»¶Ë·¢ËÍkeepaliveÊý¾Ý£¬È·È϶˿ڱ£³Ö¿ªÆô״̬¡£Èç¹ûËíµÀµÄijһ¶ËûÓа´Ê±ÊÕµ½keepaliveÊý¾Ý£¬ÄÇôÕâÒ»²àµÄËíµÀ¶Ë¿ÚÒ²»á¹Ø±Õ¡£
IPSec£¨VPN£©
IPSec£¨IP Security£©ÊÇÒ»×鿪·ÅÐÒéµÄ×ܳƣ¬Ìض¨µÄͨÐÅ·½Ö®¼äµÄIP²ãͨ¹ý¼ÓÃÜÓëÊý¾ÝÔ´ÑéÖ¤£¬ÒÔ±£Ö¤Êý¾Ý°üÔÚInternetÍøÉÏ´«ÊäʱµÄ˽ÓÐÐÔ¡¢ÍêÕûÐÔºÍÕæÊµÐÔ¡£IPSecͨ¹ýAH£¨Authentication Header£©ºÍESP£¨Encapsulating Security Payload£©ÕâÁ½¸ö°²È«ÐÒéÀ´ÊµÏÖ¡£
AHÔÚIP°üÖеÄλÖÃ(ËíµÀ·½Ê½):
------------------- ------------------------------
| IP | TCP | Data | ----------> | IP2 | AH | IP | TCP | Data |
------------------- ------------------------------
1
2
3
ESP½«ÐèÒª±£»¤µÄÓû§Êý¾Ý½øÐмÓÃܺóÔÙ·â×°µ½IP°üÖУ¬ESP¿ÉÒÔ±£Ö¤Êý¾ÝµÄÍêÕûÐÔ¡¢ÕæÊµÐÔºÍ˽ÓÐÐÔ¡£
ESPÍ·ÔÚIP°üÖеÄλÖÃ(ËíµÀ·½Ê½)£º
------------------- ------------------------------------------------
| IP | TCP | Data | ----------> | IP2 | ESP | IP | TCP | Data | Trailer | Auth |
------------------- ------------------------------------------------
###IPv6 over IPv4ËíµÀ
ÔÚIPv4ÍøÂçÏòIPv6ÍøÂç¹ý¶ÉµÄ³õÆÚ£¬IPv4ÍøÂçÒѱ»´óÁ¿²¿Ê𣬶øIPv6ÍøÂçÖ»ÊÇÉ¢²¼ÔÚÊÀ½ç¸÷µØµÄһЩ¹Âµº¡£ÀûÓÃËíµÀ¼¼Êõ¿ÉÒÔÔÚIPv4ÍøÂçÉÏ´´½¨ËíµÀ£¬´Ó¶øÊµÏÖIPv6¹ÂµºÖ®¼äµÄ»¥Á¬¡£ÔÚIPv4ÍøÂçÉÏÓÃÓÚÁ¬½ÓIPv6¹ÂµºµÄËíµÀ³ÉΪIPv6 over IPv4ËíµÀ¡£ÎªÁËʵÏÖIPv6 over IPv4ËíµÀ£¬ÐèÒªÔÚIPv4¹ÂµºµÄËíµÀ³ÆÎªIPv6 over IPv4ËíµÀ¡£ÎªÁËʵÏÖIPv6 over IPv4ËíµÀ£¬ÐèÒªÔÚIPv4ÍøÂçÓëIPv6ÍøÂç½»½çµÄ±ß½ç·ÓÉÉ豸ÉÌÆô¶¯IPv4/IPv6Ë«ÐÒéÕ»¡£
IPv6 over IPv4ËíµÀ¼¼ÊõµÄÔÀí:
±ß½ç·ÓÉÉ豸Æô¶¯IPv4/IPv6Ë«ÐÒéÕ»£¬²¢ÅäÖÃIPv6 over IPv4ËíµÀ¡£
±ß½ç·ÓÉÉ豸ÔÚÊÕµ½´ÓIPv6ÍøÂç²à·¢À´µÄ±¨Îĺó£¬Èç¹û±¨ÎĵÄÄ¿µÄµØÖ·²»ÊÇ×ÔÉíÇÒÏÂÒ»Ìø³ö½Ó¿ÚΪTunnel½Ó¿Ú£¬¾ÍÒª°ÑÊÕµ½µÄIPv6±¨ÎÄ×÷Ϊ¸ºÔØ£¬¼ÓÉÏIpv4±¨ÎÄÍ·£¬·â×°³ÉIPv4±¨ÎÄ¡£
ÔÚIPv4ÍøÂçÖУ¬·â×°ºóµÄ±¨Îı»´«µÝµ½¶Ô¶ËµÄ±ß½ç·ÓÉÉ豸¡£
¶Ô¶Ë±ß½ç·ÓÉÉ豸¶Ô±¨ÎĽâ·â×°£¬È¥µôIPv4±¨ÎÄÍ·£¬È»ºó½«·â×°ºóµÄIPv6±¨ÎÄ·¢Ë͵½¶Ô¶ËµÄIPv6ÍøÂçÖС£
ÆäËûËíµÀÔÀíÀàËÆ¡£
IPv4 over IPv6ËíµÀ
ÔÚIPv4 InternetÏòIPv6 Internet¹ý¶ÉºóÆÚ£¬IPv6ÍøÂç±»´óÁ¿²¿Êðºó£¬¶øIPv4ÍøÂçÖ»ÊÇÉ¢²¼ÔÚÊÀ½ç¸÷µØµÄһЩ¹Âµº¡£ÀûÓÃËíµÀ¼¼Êõ¿ÉÒÔÔÚIPv6ÍøÂçÉÏ´´½¨ËíµÀ£¬´Ó¶øÊµÏÖIPv4¹ÂµºµÄ»¥Áª£¬IPv4¹ÂµºÄÜͨ¹ýIPv6¹«Íø·ÃÎÊÆäËûIPv4ÍøÂç¡£