CHOICE OF REMOTE ACCESS TECHNOLOGY FOR EFFECTIVE ORGANIZATION OF PROTECTION OF NETWORK CONNECTIONS
DOI:
https://doi.org/10.28925/2663-4023.2023.19.3445Keywords:
Virtual Private Network, Internet Key Exchange, Virtual tunnel interfaces, Adaptive Security Appliance, Internet Security Association and Key Management Protocol. Interworking Operation SystemAbstract
Modern methods and means of building a service of virtual private networks are considered, the ways of their realization with the help of hardware and software on the example of a private virtual network based on CISCO FlexVPN are analyzed. To implement this task, the key exchange protocol was used to ensure the security of interaction in IKEv2 virtual networks. It is noteworthy that FlexVPN in IOS by default requires minimal action from the system administrator to quickly configure the VPN. The so-called smart-defaults are intended for this (standard ikev2 proposal / policy / profile, ipsec profile and others are configured in advance). In such a configuration, the following are configured by default: IKEv2 proposal, IKEv2 policy, IPSec transform-set, and IPSec profile. Moreover, they are configured so that the most serious algorithms have the highest priority, which, as a rule, suits the system administrator. Naturally, the greatest predictability of VPN operation will be provided by manual setting of all parameters. In view of the above, it can be stated that the FlexVPN technology is the most progressive for building VPN channels, as it has a wide scale, flexibility, does not impose any restrictions on the configuration, and also has a set of default commands called Smart-defaults, which can greatly facilitate the task regarding the configuration of the relevant communication equipment at certain stages. The main feature of this technology is the combination of two main types of construction of virtual private networks: Site-to-site and Client-to-site. The model, which is created on the basis of the GNS3 software, allows you to consider in more detail the main steps and the general principle of settings on the devices of the network being created. In general, the relevance of the technology used in the context of rapidly growing competition on the market and the need to provide remote users with secure access to remote corporate resources is demonstrated. As a result of the simulation, a virtual private network was created for the corporation, which provides both secure communication channels between departments, as well as organized remote access for employees using Cisco AnyConnect technology.
Downloads
References
Sannikova, O. (2018). New technologies for creating corporate virtual networks FlexVPN. VPN Expo
Andrew119 «IKEv2 и Flex VPN средствами Cisco IOS. Sintaksis i logika raboty» habr.com/ru/post/186126/
Nastrojka soedineniya cherez protokol IPSec mezhdu dvumya marshrutizatorami i Cisco VPN Client 4.x. www.cisco.com/
Rodrigues, A., Krupa, Jan. FlexVPN: AnyConnect IKEv2 Remote Access with Local User Database. www.cisco.com/
Skendzic, A., Kovacic, B. (2017). Open source system OpenVPN in a function of Virtual Private Network. IOP Conference Series: Materials Science and Engineering, 200, 012065. https://doi.org/10.1088/1757-899x/200/1/012065
FlexVPN and Internet Key Exchange Version 2 Configuration Guide, Cisco IOS XE Everest 16.6. www.cisco.com
Public Key Infrastructure Configuration Guide, Cisco IOS XE Release 3S - Configuring Certificate Enrollment for a PKI [Support]. Cisco. https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/sec_conn_pki/configuration/xe-3s/sec-pki-xe-3s-book/sec-cert-enroll-pki.html
Anwar, S. J., Ahmad, I. (2019). Design and Deployment of IPSec VPN Using CISCO Network Infrastructure. International Journal of Scientific Research in Computer Science, Engineering and Information Technology, 237–247. https://doi.org/10.32628/cseit195630
https://telecom-sales.ru/content/stati/tehnologii-cisco-vpn-vidy-i-tipy-udalennogo-dostupa/
FlexVPN and Internet Key Exchange Version 2 Configuration Guide, Cisco IOS XE Everest 16.6 - Configuring Internet Key Exchange Version 2 [Cisco ASR 1000 Series Aggregation Services Routers]. (б. д.). Cisco. https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/sec_conn_ike2vpn/configuration/xe-16-6/sec-flex-vpn-xe-16-6-book/sec-cfg-ikev2-flex.html#GUID-5C063DFB-B2F2-40C1-85F9-741C0035C979