基于IPSec 的VPN 模型采用传输加密报文的形式,实现了企业重要数据的安全共享。网络复杂性的增加以及一些高端的网络应用需求已迫使对VPN 的模型做优化改造,引入策略管理和策略授权协议,设计基于策略服务协议的隧道模式的 VPN 安全网关模型,成功的实现了高端网络对访问控制与审计、动态IP技术以及WLAN 的需求,提高了网络安全管理的效率。 关键词:策略协议;CA;VPN 网关;隧道 Abstract: In the form of encrypted messages, the VPN model based on IPSec realizes secure share of the primary data among enterprises. The increased complication of the network has entailed optimization and transformation of the traditional model of VPN. By introducing policy management and policy authorization protocols, and devising the secure gateway model based on the tunnel model which adopts policy service protocols, it has successfully fulfilled the demands of the advance network for access control, auditing, dynamic IP techniques and WLAN, and accordingly enhanced the efficiency of the network security management.