本文提出了基于IPSec VPN 技术的端到端虚拟组网思想,引入了虚拟工作组及组策 略的概念来实现不同VPN 通信实体的安全隔离。在现有安全策略管理方法的基础上,设计实现了一个基于工作组的安全策略系统,并讨论了该安全策略系统的功能模块及采用的关键 技术。关键词:安全策略系统;端到端;虚拟工作组 Abstract:This paper proposes a theory of end-to-end virtual network based on IPSec VPN technique. It introduces a concept of virtual workgroup and group policy to isolate different VPN communication entities safely. Based on the current IPSec security policy management method, a workgroup-based security policy system is designed and realized. The function modules and solution to key problems of the workgroup-based security policy system is also discussed. Key words: security policy system; end-to-end; virtual workgroup