V2EX = way to explore
V2EX 是一个关于分享和探索的地方
Sign Up Now
For Existing Member  Sign In
kxmp
V2EX  ›  互联网

图解 L2TP 密码验证过程

  •  1
     
  •   kxmp · Jan 30, 2015 · 8266 views
    This topic created in 4105 days ago, the information mentioned may be changed or developed.

    https://i.imgur.com/BgezX8H.png
    连接的时候,客户端要发出去这个信息.当然是明文的...
    https://i.imgur.com/Anuiohs.png

    c是windows客户端
    s是服务端
    下面9行字对应第一张图从上到下9个包
    c:l2tp vpn!的干活
    s:密码.?

    c:咱们开始吧...(小声点,别让别人听到.) 其实已经被别人听到了
    s:嗯.... (前4个包不仅没加密而且还暴露了你试图使用l2tp over ipsec)
    c:我开始了.. (这时候才开始传送加密的密码数据,但是一开始已经暴露了你是要用l2tp)
    s:有感觉了...

    c:快速模式~你懂的 (快速模式过后,身份验证过程就彻底结束了.也就是数据全部都用esp封装.由ipsec隧道传送)
    s:你确认么?
    c:你快点行不行
    esp上了....

    7 replies    2015-02-01 20:41:29 +08:00
    kiritoalex
        1
    kiritoalex  
       Jan 30, 2015 via iPhone
    2333333333
    xenme
        2
    xenme  
       Jan 30, 2015
    L2TP Over IPSEC
    quericy
        3
    quericy  
       Jan 30, 2015
    噗噗噗噗噗噗
    ryd994
        4
    ryd994  
       Jan 31, 2015 via Android
    加force_encapsulate会怎么样?
    kxmp
        5
    kxmp  
    OP
       Jan 31, 2015
    @ryd994
    forceencaps = yes | no
    force UDP encapsulation for ESP packets even if no NAT situation
    is detected. This may help to surmount restrictive firewalls.
    In order to force the peer to encapsulate packets, NAT detection
    payloads are faked (IKEv2 only).
    ryd994
        6
    ryd994  
       Jan 31, 2015 via Android
    @kxmp 手册我有认真看啦
    我是好奇抓包会是什么样子
    kxmp
        7
    kxmp  
    OP
       Feb 1, 2015
    @ryd994 开那个没用啊l2tp又不是ikev2.
    About   ·   Help   ·   Advertise   ·   Blog   ·   API   ·   FAQ   ·   Solana   ·   4715 Online   Highest 6679   ·     Select Language
    创意工作者们的社区
    World is powered by solitude
    VERSION: 3.9.8.5 · 38ms · UTC 10:06 · PVG 18:06 · LAX 03:06 · JFK 06:06
    ♥ Do have faith in what you're doing.