论文部分内容阅读
针对目前企业远程办公存在的安全性问题,本文提出并设计了一种基于RSA双因素身份认证的SSL VPN远程访问控制方案。该方案将RSA与VPN网关进行联动,通过RSA的radius服务器对VPN用户进行身份认证与策略匹配,根据用户匹配的策略进行IP地址的指定,并结合VPN网关后端的防火墙最终实现远程办公用户对企业内部资源的访问控制。最后以cisco annyconnect客户端VPN软件为例验证了本文方案的有效性。
In view of the existing security problems in the enterprise remote office, this paper proposes and designs a SSL VPN remote access control scheme based on RSA two-factor authentication. The solution links the RSA with the VPN gateway and authenticates and matches VPN users through the radius server of the RSA. According to the policy matched by the users, the IP address is specified. Combined with the back-end firewall of the VPN gateway, the remote office user to the enterprise Internal resource access control. Finally, cisco annyconnect client VPN software as an example to verify the effectiveness of this program.