āĻ•āĻŋāĻ­āĻžāĻŦ⧇ āϘāϰ⧋āϝāĻŧāĻž IPsec VPN āĻāϰ āϏāĻŽāĻ¸ā§āϝāĻž āϏāĻŽāĻžāϧāĻžāύ āĻ•āϰāĻŦ⧇āύāĨ¤ āĻ…āĻ‚āĻļ 1

āĻ•āĻŋāĻ­āĻžāĻŦ⧇ āϘāϰ⧋āϝāĻŧāĻž IPsec VPN āĻāϰ āϏāĻŽāĻ¸ā§āϝāĻž āϏāĻŽāĻžāϧāĻžāύ āĻ•āϰāĻŦ⧇āύāĨ¤ āĻ…āĻ‚āĻļ 1

āĻĒāϰāĻŋāĻ¸ā§āĻĨāĻŋāϤāĻŋ

āϛ⧁āϟāĻŋ. āφāĻŽāĻŋ āĻ•āĻĢāĻŋ āĻĒāĻžāύ āĻ•āϰāĻŋ. āĻ›āĻžāĻ¤ā§āϰāϟāĻŋ āĻĻ⧁āϟāĻŋ āĻĒāϝāĻŧ⧇āĻ¨ā§āĻŸā§‡āϰ āĻŽāĻ§ā§āϝ⧇ āĻāĻ•āϟāĻŋ āĻ­āĻŋāĻĒāĻŋāĻāύ āϏāĻ‚āϝ⧋āĻ— āĻ¸ā§āĻĨāĻžāĻĒāύ āĻ•āϰ⧇ āĻ…āĻĻ⧃āĻļā§āϝ āĻšāϝāĻŧ⧇ āϗ⧇āϞāĨ¤ āφāĻŽāĻŋ āĻĒāϰ⧀āĻ•ā§āώāĻž āĻ•āϰ⧇ āĻĻ⧇āĻ–āϞāĻžāĻŽ: āϟāĻžāύ⧇āϞāϟāĻŋ āφāϏāϞ⧇āχ āφāϛ⧇, āĻ•āĻŋāĻ¨ā§āϤ⧁ āϟāĻžāύ⧇āϞ⧇ āϕ⧋āύ āĻŸā§āϰāĻžāĻĢāĻŋāĻ• āύ⧇āχāĨ¤ āĻ›āĻžāĻ¤ā§āϰ āĻ•āϞ⧇āϰ āωāĻ¤ā§āϤāϰ āĻĻ⧇āϝāĻŧ āύāĻžāĨ¤

āφāĻŽāĻŋ āϕ⧇āϟāϞāĻŋāϟāĻŋ āϚāĻžāϞ⧁ āĻ•āϰ⧇āĻ›āĻŋ āĻāĻŦāĻ‚ S-Terra āϗ⧇āϟāĻ“āϝāĻŧ⧇āϰ āϏāĻŽāĻ¸ā§āϝāĻž āϏāĻŽāĻžāϧāĻžāύ⧇ āĻĄā§āĻŦ āĻĻāĻŋāϝāĻŧ⧇āĻ›āĻŋāĨ¤ āφāĻŽāĻŋ āφāĻŽāĻžāϰ āĻ…āĻ­āĻŋāĻœā§āĻžāϤāĻž āĻāĻŦāĻ‚ āĻĒāĻĻā§āϧāϤāĻŋ āĻļ⧇āϝāĻŧāĻžāϰ āĻ•āϰāĻŋāĨ¤

āĻ•āĻžāρāϚāĻž āϤāĻĨā§āϝ

āĻĻ⧁āϟāĻŋ āϭ⧌āĻ—āϞāĻŋāĻ•āĻ­āĻžāĻŦ⧇ āĻĒ⧃āĻĨāĻ• āϏāĻžāχāϟ āĻāĻ•āϟāĻŋ GRE āϟāĻžāύ⧇āϞ āĻĻā§āĻŦāĻžāϰāĻž āϏāĻ‚āϝ⧁āĻ•ā§āϤ āĻ•āϰāĻž āĻšāϝāĻŧ. GRE āĻāύāĻ•ā§āϰāĻŋāĻĒā§āϟ āĻ•āϰāĻž āĻĒā§āϰāϝāĻŧā§‹āϜāύ:

āĻ•āĻŋāĻ­āĻžāĻŦ⧇ āϘāϰ⧋āϝāĻŧāĻž IPsec VPN āĻāϰ āϏāĻŽāĻ¸ā§āϝāĻž āϏāĻŽāĻžāϧāĻžāύ āĻ•āϰāĻŦ⧇āύāĨ¤ āĻ…āĻ‚āĻļ 1

āφāĻŽāĻŋ āϜāĻŋāφāϰāχ āϟāĻžāύ⧇āϞ⧇āϰ āĻ•āĻ°ā§āĻŽāĻ•ā§āώāĻŽāϤāĻž āĻĒāϰ⧀āĻ•ā§āώāĻž āĻ•āϰāĻŋāĨ¤ āĻāϟāĻŋ āĻ•āϰāĻžāϰ āϜāĻ¨ā§āϝ, āφāĻŽāĻŋ āĻĄāĻŋāĻ­āĻžāχāϏ R1 āĻĨ⧇āϕ⧇ āĻĄāĻŋāĻ­āĻžāχāϏ R2 āĻāϰ GRE āχāĻ¨ā§āϟāĻžāϰāĻĢ⧇āϏ⧇ āĻĒāĻŋāĻ‚ āĻ•āϰāĻž āĻļ⧁āϰ⧁ āĻ•āϰāĻŋāĨ¤ āĻāϟāĻŋ āĻāύāĻ•ā§āϰāĻŋāĻĒāĻļāύ⧇āϰ āϜāĻ¨ā§āϝ āϞāĻ•ā§āĻˇā§āϝāϝ⧁āĻ•ā§āϤ āĻŸā§āϰāĻžāĻĢāĻŋāĻ•āĨ¤ āωāĻ¤ā§āϤāϰ āύ⧇āχ:

root@R1:~# ping 1.1.1.2 -c 4
PING 1.1.1.2 (1.1.1.2) 56(84) bytes of data.

--- 1.1.1.2 ping statistics ---
4 packets transmitted, 0 received, 100% packet loss, time 3057ms

āφāĻŽāĻŋ āϗ⧇āϟ 1 āĻāĻŦāĻ‚ āϗ⧇āϟ 2 āĻāϰ āϞāĻ—āϗ⧁āϞāĻŋ āĻĻ⧇āĻ–āĻŋ⧎ āϞāĻ—āϟāĻŋ āφāύāĻ¨ā§āĻĻ⧇āϰ āϏāĻžāĻĨ⧇ āϰāĻŋāĻĒā§‹āĻ°ā§āϟ āĻ•āϰ⧇ āϝ⧇ IPsec āϟāĻžāύ⧇āϞ āϏāĻĢāϞāĻ­āĻžāĻŦ⧇ āωāϠ⧇ āĻāϏ⧇āϛ⧇, āϕ⧋āύ āϏāĻŽāĻ¸ā§āϝāĻž āύ⧇āχ:

root@Gate1:~# cat /var/log/cspvpngate.log
Aug  5 16:14:23 localhost  vpnsvc: 00100119 <4:1> IPSec connection 5 established, traffic selector 172.17.0.1->172.16.0.1, proto 47, peer 10.10.10.251, id "10.10.10.251", Filter 
IPsec:Protect:CMAP:1:LIST, IPsecAction IPsecAction:CMAP:1, IKERule IKERule:CMAP:1

Gate1 āĻ āϟāĻžāύ⧇āϞ⧇āϰ IPsec āĻĒāϰāĻŋāϏāĻ‚āĻ–ā§āϝāĻžāύ⧇, āφāĻŽāĻŋ āĻĻ⧇āĻ–āϤ⧇ āĻĒāĻžāĻšā§āĻ›āĻŋ āϝ⧇ āϟāĻžāύ⧇āϞāϟāĻŋ āϏāĻ¤ā§āϝāĻŋāχ āĻŦāĻŋāĻĻā§āϝāĻŽāĻžāύ, āĻ•āĻŋāĻ¨ā§āϤ⧁ Rcvd āĻ•āĻžāωāĻ¨ā§āϟāĻžāϰāϟāĻŋ āĻļā§‚āĻ¨ā§āϝ⧇ āϰāĻŋāϏ⧇āϟ āĻ•āϰāĻž āĻšāϝāĻŧ⧇āϛ⧇:

root@Gate1:~# sa_mgr show
ISAKMP sessions: 0 initiated, 0 responded

ISAKMP connections:
Num Conn-id (Local Addr,Port)-(Remote Addr,Port) State Sent Rcvd
1 3 (10.10.10.251,500)-(10.10.10.252,500) active 1070 1014

IPsec connections:
Num Conn-id (Local Addr,Port)-(Remote Addr,Port) Protocol Action Type Sent Rcvd
1 3 (172.16.0.1,*)-(172.17.0.1,*) 47 ESP tunn 480 0

āφāĻŽāĻŋ āĻāχāĻ­āĻžāĻŦ⧇ C-Terra āĻāϰ āϏāĻŽāĻ¸ā§āϝāĻžāϰ āϏāĻŽāĻžāϧāĻžāύ āĻ•āϰāĻŋ: R1 āĻĨ⧇āϕ⧇ R2 āϝāĻžāĻ“āϝāĻŧāĻžāϰ āĻĒāĻĨ⧇ āϞāĻ•ā§āĻˇā§āϝ āĻĒā§āϝāĻžāϕ⧇āϟāϗ⧁āϞāĻŋ āϕ⧋āĻĨāĻžāϝāĻŧ āĻšāĻžāϰāĻŋāϝāĻŧ⧇ āϗ⧇āϛ⧇ āϤāĻž āφāĻŽāĻŋ āϖ⧁āρāϜāĻ›āĻŋāĨ¤ āĻĒā§āϰāĻ•ā§āϰāĻŋāϝāĻŧāĻžāϝāĻŧ (āĻ¸ā§āĻĒāϝāĻŧāϞāĻžāϰ) āφāĻŽāĻŋ āĻāĻ•āϟāĻŋ āĻ¤ā§āϰ⧁āϟāĻŋ āϖ⧁āρāĻœā§‡ āĻĒāĻžāĻŦāĨ¤

āϏāĻŽāĻ¸ā§āϝāĻž āϏāĻŽāĻžāϧāĻžāύ

āϧāĻžāĻĒ 1: R1 āĻĨ⧇āϕ⧇ āϗ⧇āϟ1 āϕ⧀ āĻĒāĻžāϝāĻŧ

āφāĻŽāĻŋ āĻŦāĻŋāĻ˛ā§āϟ-āχāύ āĻĒā§āϝāĻžāϕ⧇āϟ āĻ¸ā§āύāĻŋāĻĢāĻžāϰ, tcpdump āĻŦā§āϝāĻŦāĻšāĻžāϰ āĻ•āϰāĻŋāĨ¤ āφāĻŽāĻŋ āĻ¸ā§āύāĻŋāĻĢāĻžāϰāϟāĻŋ āχāĻ¨ā§āϟāĻžāϰāύāĻžāϞ āύ⧇āϟāĻ“āϝāĻŧāĻžāĻ°ā§āϕ⧇ (āϏāĻŋāϏāϕ⧋āϰ āĻŽāϤ⧋ āύ⧋āĻŸā§‡āĻļāύ⧇ Gi0/1 āĻ…āĻĨāĻŦāĻž āĻ“āĻāϏ āύ⧋āĻŸā§‡āĻļāύ⧇ eth1) āϚāĻžāϞāĻžāχāĨ¤ Debian) āχāĻ¨ā§āϟāĻžāϰāĻĢ⧇āϏ:

root@Gate1:~# tcpdump -i eth1

tcpdump: verbose output suppressed, use -v or -vv for full protocol decode
listening on eth1, link-type EN10MB (Ethernet), capture size 262144 bytes
14:53:38.879525 IP 172.16.0.1 > 172.17.0.1: GREv0, key=0x1, length 92: IP 1.1.1.1 > 1.1.1.2: ICMP echo request, id 2083, seq 1, length 64
14:53:39.896869 IP 172.16.0.1 > 172.17.0.1: GREv0, key=0x1, length 92: IP 1.1.1.1 > 1.1.1.2: ICMP echo request, id 2083, seq 2, length 64
14:53:40.921121 IP 172.16.0.1 > 172.17.0.1: GREv0, key=0x1, length 92: IP 1.1.1.1 > 1.1.1.2: ICMP echo request, id 2083, seq 3, length 64
14:53:41.944958 IP 172.16.0.1 > 172.17.0.1: GREv0, key=0x1, length 92: IP 1.1.1.1 > 1.1.1.2: ICMP echo request, id 2083, seq 4, length 64

āφāĻŽāĻŋ āĻĻ⧇āĻ–āĻ›āĻŋ āϝ⧇ Gate1 R1 GRE āĻĨ⧇āϕ⧇ āĻĒā§āϝāĻžāϕ⧇āϟāϗ⧁āϞāĻŋ āĻ—ā§āϰāĻšāĻŖ āĻ•āϰ⧇āĨ¤ āφāĻŽāĻŋ āĻāĻ—āĻŋāϝāĻŧ⧇ āϝāĻžāχāĨ¤

āϧāĻžāĻĒ 2. GRE āĻĒā§āϝāĻžāϕ⧇āĻŸā§‡āϰ āϏāĻžāĻĨ⧇ Gate1 āĻ•āĻŋ āĻ•āϰ⧇

āφāĻŽāĻŋ klogview āχāωāϟāĻŋāϞāĻŋāϟāĻŋ āĻŦā§āϝāĻŦāĻšāĻžāϰ āĻ•āϰāĻŋ GRE āĻĒā§āϝāĻžāϕ⧇āĻŸā§‡āϰ āϭ⧇āϤāϰ⧇ āϕ⧀ āϘāϟāϛ⧇ āϤāĻž āĻĻ⧇āĻ–āĻžāϰ āϜāĻ¨ā§āϝāĨ¤ āĻ­āĻŋāĻĒāĻŋāĻāύ āĻāϏ-āĻŸā§‡āϰāĻž āĻĄā§āϰāĻžāχāĻ­āĻžāϰ:

root@Gate1:~# klogview -f 0xffffffff

filtration result for out packet 172.16.0.1->172.17.0.1, proto 47, len 112, if eth0: chain 4 "IPsecPolicy:CMAP", filter 8, event id IPsec:Protect:CMAP:1:LIST, status PASS
encapsulating with SA 31: 172.16.0.1->172.17.0.1, proto 47, len 112, if eth0
passed out packet 10.10.10.251->10.10.10.252, proto 50, len 160, if eth0: encapsulated

āφāĻŽāĻŋ āĻĻ⧇āĻ–āĻ›āĻŋ āϝ⧇ āϞāĻ•ā§āĻˇā§āϝ āϜāĻŋāφāϰāχ āĻŸā§āĻ°ā§āϝāĻžāĻĢāĻŋāĻ• (āĻĒā§āϰ⧋āĻŸā§‹ 47) 172.16.0.1 -> 172.17.0.1 CMAP āĻ•ā§āϰāĻŋāĻĒā§āĻŸā§‹āĻŽā§āϝāĻžāĻĒ⧇ āϤāĻžāϞāĻŋāĻ•āĻž āĻāύāĻ•ā§āϰāĻŋāĻĒāĻļāύ āύāĻŋāϝāĻŧāĻŽā§‡āϰ āĻ…āϧ⧀āύ⧇ āĻĒāĻĄāĻŧ⧇ (PASS) āĻāĻŦāĻ‚ āĻāύāĻ•ā§āϰāĻŋāĻĒā§āϟ āĻ•āϰāĻž āĻšāϝāĻŧ⧇āϛ⧇ (āĻāύāĻ•ā§āϝāĻžāĻĒāϏ⧁āϞ⧇āĻŸā§‡āĻĄ)āĨ¤ āĻāϰ āĻĒāϰ⧇, āĻĒā§āϝāĻžāϕ⧇āϟāϟāĻŋ āϰāĻžāωāϟ āĻ•āϰāĻž āĻšāϝāĻŧ⧇āĻ›āĻŋāϞ (āĻĒāĻžāϏ āφāωāϟ)āĨ¤ klogview āφāωāϟāĻĒ⧁āĻŸā§‡ āϕ⧋āύ āϰāĻŋāϟāĻžāĻ°ā§āύ āĻŸā§āϰāĻžāĻĢāĻŋāĻ• āύ⧇āχ.

Gate1 āĻĄāĻŋāĻ­āĻžāχāϏ⧇ āĻ…ā§āϝāĻžāĻ•ā§āϏ⧇āϏ āϤāĻžāϞāĻŋāĻ•āĻž āĻĒāϰ⧀āĻ•ā§āώāĻž āĻ•āϰāĻž āĻšāĻšā§āϛ⧇āĨ¤ āφāĻŽāĻŋ āĻāĻ•āϟāĻŋ LIST āĻ…ā§āϝāĻžāĻ•ā§āϏ⧇āϏ āϤāĻžāϞāĻŋāĻ•āĻž āĻĻ⧇āĻ–āϤ⧇ āĻĒāĻžāĻšā§āĻ›āĻŋ, āϝāĻž āĻāύāĻ•ā§āϰāĻŋāĻĒāĻļāύ⧇āϰ āϜāĻ¨ā§āϝ āϞāĻ•ā§āĻˇā§āϝ āĻŸā§āĻ°ā§āϝāĻžāĻĢāĻŋāĻ• āύāĻŋāĻ°ā§āϧāĻžāϰāĻŖ āĻ•āϰ⧇, āϝāĻžāϰ āĻ…āĻ°ā§āĻĨ āĻšāϞ ME āύāĻŋāϝāĻŧāĻŽāϗ⧁āϞāĻŋ āĻ•āύāĻĢāĻŋāĻ—āĻžāϰ āĻ•āϰāĻž āύ⧇āχ:

Gate1#show access-lists
Extended IP access list LIST
    10 permit gre host 172.16.0.1 host 172.17.0.1

āωāĻĒāϏāĻ‚āĻšāĻžāϰ: āϏāĻŽāĻ¸ā§āϝāĻžāϟāĻŋ Gate1 āĻĄāĻŋāĻ­āĻžāχāϏ⧇ āύāϝāĻŧāĨ¤

klogview āϏāĻŽā§āĻĒāĻ°ā§āϕ⧇ āφāϰ⧋

VPN āĻĄā§āϰāĻžāχāĻ­āĻžāϰ āϏāĻŽāĻ¸ā§āϤ āύ⧇āϟāĻ“āϝāĻŧāĻžāĻ°ā§āĻ• āĻŸā§āĻ°ā§āϝāĻžāĻĢāĻŋāĻ• āĻĒāϰāĻŋāϚāĻžāϞāύāĻž āĻ•āϰ⧇, āĻļ⧁āϧ⧁āĻŽāĻžāĻ¤ā§āϰ āϝ⧇āϗ⧁āϞāĻŋāϕ⧇ āĻāύāĻ•ā§āϰāĻŋāĻĒā§āϟ āĻ•āϰāĻž āĻĻāϰāĻ•āĻžāϰ āϤāĻž āύāϝāĻŧāĨ¤ āĻ­āĻŋāĻĒāĻŋāĻāύ āĻĄā§āϰāĻžāχāĻ­āĻžāϰ āϝāĻĻāĻŋ āύ⧇āϟāĻ“āϝāĻŧāĻžāĻ°ā§āĻ• āĻŸā§āĻ°ā§āϝāĻžāĻĢāĻŋāĻ• āĻĒā§āϰāĻ•ā§āϰāĻŋāϝāĻŧāĻž āĻ•āϰ⧇ āĻāĻŦāĻ‚ āĻĒā§āϞ⧇āχāύ āĻŸā§‡āĻ•ā§āϏāĻŸā§‡ āĻĒāĻžāĻ āĻžāϝāĻŧ āϤāĻžāĻšāϞ⧇ āĻ•ā§āϞ⧋āĻ—āĻ­āĻŋāωāϤ⧇ āĻĻ⧇āĻ–āĻž āĻŦāĻžāĻ°ā§āϤāĻžāϗ⧁āϞāĻŋ āĻāĻ–āĻžāύ⧇ āϰāϝāĻŧ⧇āϛ⧇:

root@R1:~# ping 172.17.0.1 -c 4

root@Gate1:~# klogview -f 0xffffffff

filtration result for out packet 172.16.0.1->172.17.0.1, proto 1, len 84, if eth0: chain 4 "IPsecPolicy:CMAP": no match
passed out packet 172.16.0.1->172.17.0.1, proto 1, len 84, if eth0: filtered

āφāĻŽāĻŋ āĻĻ⧇āĻ–āĻ›āĻŋ āϝ⧇ ICMP āĻŸā§āĻ°ā§āϝāĻžāĻĢāĻŋāĻ• (āĻĒā§āϰ⧋āĻŸā§‹ 1) 172.16.0.1->172.17.0.1 CMAP āĻ•ā§āϰāĻŋāĻĒā§āĻŸā§‹āĻŽā§āϝāĻžāĻĒ⧇āϰ āĻāύāĻ•ā§āϰāĻŋāĻĒāĻļāύ āύāĻŋāϝāĻŧāĻŽā§‡āϰ āĻŽāĻ§ā§āϝ⧇ āĻĒāĻĄāĻŧ⧇āύāĻŋ (āϕ⧋āύāĻ“ āĻŽāĻŋāϞ āύ⧇āχ)āĨ¤ āĻĒā§āϝāĻžāϕ⧇āϟāϟāĻŋ āĻĒāϰāĻŋāĻˇā§āĻ•āĻžāϰāĻ­āĻžāĻŦ⧇ āϰāĻžāωāϟ āĻ•āϰāĻž āĻšāϝāĻŧ⧇āĻ›āĻŋāϞ (āĻĒāĻžāϏ āφāωāϟ)āĨ¤

āϧāĻžāĻĒ 3. āϗ⧇āϟ2 āϗ⧇āϟ1 āĻĨ⧇āϕ⧇ āϕ⧀ āĻĒāĻžāϝāĻŧ

āφāĻŽāĻŋ WAN (eth0) āχāĻ¨ā§āϟāĻžāϰāĻĢ⧇āϏ Gate2 āĻ āĻ¸ā§āύāĻŋāĻĢāĻžāϰ āĻļ⧁āϰ⧁ āĻ•āϰāĻŋ:

root@Gate2:~# tcpdump -i eth0
tcpdump: verbose output suppressed, use -v or -vv for full protocol decode
listening on eth0, link-type EN10MB (Ethernet), capture size 262144 bytes
16:05:45.104195 IP 10.10.10.251 > 10.10.10.252: ESP(spi=0x30088112,seq=0x1), length 140
16:05:46.093918 IP 10.10.10.251 > 10.10.10.252: ESP(spi=0x30088112,seq=0x2), length 140
16:05:47.117078 IP 10.10.10.251 > 10.10.10.252: ESP(spi=0x30088112,seq=0x3), length 140
16:05:48.141785 IP 10.10.10.251 > 10.10.10.252: ESP(spi=0x30088112,seq=0x4), length 140

āφāĻŽāĻŋ āĻĻ⧇āĻ–āĻ›āĻŋ āϝ⧇ Gate2 Gate1 āĻĨ⧇āϕ⧇ ESP āĻĒā§āϝāĻžāϕ⧇āϟ āĻĒāĻžāĻšā§āϛ⧇āĨ¤

āϧāĻžāĻĒ 4. ESP āĻĒā§āϝāĻžāϕ⧇āĻŸā§‡āϰ āϏāĻžāĻĨ⧇ Gate2 āĻ•āĻŋ āĻ•āϰ⧇

āφāĻŽāĻŋ Gate2 āĻ klogview āχāωāϟāĻŋāϞāĻŋāϟāĻŋ āϚāĻžāϞāĻžāχ:

root@Gate2:~# klogview -f 0xffffffff
filtration result for in packet 10.10.10.251->10.10.10.252, proto 50, len 160, if eth0: chain 17 "FilterChain:L3VPN", filter 21, status DROP
dropped in packet 10.10.10.251->10.10.10.252, proto 50, len 160, if eth0: firewall

āφāĻŽāĻŋ āĻĻ⧇āĻ–āĻ›āĻŋ āϝ⧇ āĻĢāĻžāϝāĻŧāĻžāϰāĻ“āϝāĻŧāĻžāϞ (āĻĢāĻžāϝāĻŧāĻžāϰāĻ“āϝāĻŧāĻžāϞ) āĻāϰ āĻāĻ•āϟāĻŋ āύāĻŋāϝāĻŧāĻŽ (L50VPN) āĻĻā§āĻŦāĻžāϰāĻž ESP āĻĒā§āϝāĻžāϕ⧇āϟ (āĻĒā§āϰ⧋āĻŸā§‹ 3) āĻĄā§āϰāĻĒ (āĻĄā§āϰāĻĒ) āĻ•āϰāĻž āĻšāϝāĻŧ⧇āϛ⧇āĨ¤ āφāĻŽāĻŋ āύāĻŋāĻļā§āϚāĻŋāϤ āϝ⧇ Gi0 / 0 āϏāĻ¤ā§āϝāĻŋāχ L3VPN āĻ…ā§āϝāĻžāĻ•ā§āϏ⧇āϏ āϤāĻžāϞāĻŋāĻ•āĻžāϰ āϏāĻžāĻĨ⧇ āφāĻŦāĻĻā§āϧ:

Gate2#show ip interface gi0/0
GigabitEthernet0/0 is up, line protocol is up
  Internet address is 10.10.10.252/24
  MTU is 1500 bytes
  Outgoing access list is not set
  Inbound  access list is L3VPN

āϏāĻŽāĻ¸ā§āϝāĻž āϖ⧁āρāĻœā§‡ āĻĒ⧇āϝāĻŧ⧇āĻ›āĻŋāĨ¤

āϧāĻžāĻĒ 5: āĻ…ā§āϝāĻžāĻ•ā§āϏ⧇āϏ āϞāĻŋāĻ¸ā§āĻŸā§‡ āϕ⧀ āϏāĻŽāĻ¸ā§āϝāĻž āφāϛ⧇

L3VPN āĻ…ā§āϝāĻžāĻ•ā§āϏ⧇āϏ āϤāĻžāϞāĻŋāĻ•āĻžāϟāĻŋ āϕ⧀ āϤāĻž āφāĻŽāĻŋ āĻĻ⧇āĻ–āĻŋ:

Gate2#show access-list L3VPN
Extended IP access list L3VPN
    10 permit udp host 10.10.10.251 any eq isakmp
    20 permit udp host 10.10.10.251 any eq non500-isakmp
    30 permit icmp host 10.10.10.251 any

āφāĻŽāĻŋ āĻĻ⧇āĻ–āĻ›āĻŋ āϝ⧇ ISAKMP āĻĒā§āϝāĻžāϕ⧇āϟāϗ⧁āϞāĻŋ āĻ…āύ⧁āĻŽā§‹āĻĻāĻŋāϤ, āϤāĻžāχ āĻāĻ•āϟāĻŋ IPsec āϟāĻžāύ⧇āϞ āĻ¸ā§āĻĨāĻžāĻĒāύ āĻ•āϰāĻž āĻšāĻšā§āϛ⧇⧎ āĻ•āĻŋāĻ¨ā§āϤ⧁ ESP-āĻāϰ āϜāĻ¨ā§āϝ āϕ⧋āύ⧋ āĻ…āύ⧁āĻŽāϤāĻŋāĻŽā§‚āϞāĻ• āύāĻŋāϝāĻŧāĻŽ āύ⧇āχāĨ¤ āĻ¸ā§āĻĒāĻˇā§āϟāϤāχ, āĻ›āĻžāĻ¤ā§āϰāϟāĻŋ icmp āĻāĻŦāĻ‚ esp āϕ⧇ āĻŦāĻŋāĻ­ā§āϰāĻžāĻ¨ā§āϤ āĻ•āϰ⧇āϛ⧇āĨ¤

āĻ…ā§āϝāĻžāĻ•ā§āϏ⧇āϏ āϤāĻžāϞāĻŋāĻ•āĻž āϏāĻŽā§āĻĒāĻžāĻĻāύāĻž:

Gate2(config)#
ip access-list extended L3VPN
no 30
30 permit esp host 10.10.10.251 any

āϧāĻžāĻĒ 6. āφāĻŽāĻŋ āĻ•āĻ°ā§āĻŽāĻ•ā§āώāĻŽāϤāĻž āĻĒāϰ⧀āĻ•ā§āώāĻž

āĻĒā§āϰāĻĨāĻŽāϤ, āφāĻŽāĻŋ āύāĻŋāĻļā§āϚāĻŋāϤ āĻ•āϰāĻŋ āϝ⧇ L3VPN āĻ…ā§āϝāĻžāĻ•ā§āϏ⧇āϏ āϤāĻžāϞāĻŋāĻ•āĻž āϏāĻ āĻŋāĻ•:

Gate2#show access-list L3VPN
Extended IP access list L3VPN
    10 permit udp host 10.10.10.251 any eq isakmp
    20 permit udp host 10.10.10.251 any eq non500-isakmp
    30 permit esp host 10.10.10.251 any

āĻāĻ–āύ āφāĻŽāĻŋ R1 āĻĄāĻŋāĻ­āĻžāχāϏ āĻĨ⧇āϕ⧇ āϞāĻ•ā§āĻˇā§āϝāϝ⧁āĻ•ā§āϤ āĻŸā§āϰāĻžāĻĢāĻŋāĻ• āϚāĻžāϞ⧁ āĻ•āϰāĻŋ:

root@R1:~# ping 1.1.1.2 -c 4
PING 1.1.1.2 (1.1.1.2) 56(84) bytes of data.
64 bytes from 1.1.1.2: icmp_seq=1 ttl=64 time=35.3 ms
64 bytes from 1.1.1.2: icmp_seq=2 ttl=64 time=3.01 ms
64 bytes from 1.1.1.2: icmp_seq=3 ttl=64 time=2.65 ms
64 bytes from 1.1.1.2: icmp_seq=4 ttl=64 time=2.87 ms

--- 1.1.1.2 ping statistics ---
4 packets transmitted, 4 received, 0% packet loss, time 3006ms
rtt min/avg/max/mdev = 2.650/10.970/35.338/14.069 ms

āĻŦāĻŋāϜāϝāĻŧāĨ¤ GRE āϟāĻžāύ⧇āϞ āĻ¸ā§āĻĨāĻžāĻĒāύ āĻ•āϰāĻž āĻšāϝāĻŧ⧇āϛ⧇āĨ¤ IPsec āĻĒāϰāĻŋāϏāĻ‚āĻ–ā§āϝāĻžāύ⧇ āχāύāĻ•āĻžāĻŽāĻŋāĻ‚ āĻŸā§āϰāĻžāĻĢāĻŋāĻ• āĻ•āĻžāωāĻ¨ā§āϟāĻžāϰ āĻ…-āĻļā§‚āĻ¨ā§āϝ:

root@Gate1:~# sa_mgr show
ISAKMP sessions: 0 initiated, 0 responded

ISAKMP connections:
Num Conn-id (Local Addr,Port)-(Remote Addr,Port) State Sent Rcvd
1 3 (10.10.10.251,500)-(10.10.10.252,500) active 1474 1350

IPsec connections:
Num Conn-id (Local Addr,Port)-(Remote Addr,Port) Protocol Action Type Sent Rcvd
1 4 (172.16.0.1,*)-(172.17.0.1,*) 47 ESP tunn 1920 480

Gate2 āϗ⧇āϟāĻ“āϝāĻŧ⧇āϤ⧇, klogview āφāωāϟāĻĒ⧁āĻŸā§‡, āĻŦāĻžāĻ°ā§āϤāĻžāϗ⧁āϞāĻŋ āωāĻĒāĻ¸ā§āĻĨāĻŋāϤ āĻšāϝāĻŧ⧇āĻ›āĻŋāϞ āϝ⧇ āϞāĻ•ā§āĻˇā§āϝ āĻŸā§āϰāĻžāĻĢāĻŋāĻ• 172.16.0.1-> 172.17.0.1 āϏāĻĢāϞāĻ­āĻžāĻŦ⧇ (PASS) CMAP āĻ•ā§āϰāĻŋāĻĒā§āĻŸā§‹āĻŽā§āϝāĻžāĻĒ⧇ āϤāĻžāϞāĻŋāĻ•āĻž āύāĻŋāϝāĻŧāĻŽ āĻĻā§āĻŦāĻžāϰāĻž āĻĄāĻŋāĻ•ā§āϝāĻžāĻĒāϏ⧁āϞ⧇āϟ āĻ•āϰāĻž āĻšāϝāĻŧ⧇āϛ⧇:

root@Gate2:~# klogview -f 0xffffffff
filtration result for in packet 172.16.0.1->172.17.0.1, proto 47, len 112, if eth0: chain 18 "IPsecPolicy:CMAP", filter 25, event id IPsec:Protect:CMAP:1:LIST, status PASS
passed in packet 172.16.0.1->172.17.0.1, proto 47, len 112, if eth0: decapsulated

āĻĢāϞāĻžāĻĢāϞ

āϛ⧁āϟāĻŋāϰ āĻĻāĻŋāύāϟāĻž āύāĻˇā§āϟ āĻ•āϰ⧇ āĻĻāĻŋāϞ āĻ›āĻžāĻ¤ā§āϰāĨ¤
ME āĻāϰ āύāĻŋāϝāĻŧāĻŽā§‡āϰ āϏāĻžāĻĨ⧇ āϏāϤāĻ°ā§āĻ• āĻĨāĻžāϕ⧁āύāĨ¤

āĻŦ⧇āύāĻžāĻŽā§€ āĻĒā§āϰāĻ•ā§ŒāĻļāϞ⧀
t.me/anonymous_engineer


āωāĻ¤ā§āϏ: www.habr.com

DDoS āϏ⧁āϰāĻ•ā§āώāĻž, VPS VDS āϏāĻžāĻ°ā§āĻ­āĻžāϰ āϏāĻš āϏāĻžāχāϟāϗ⧁āϞāĻŋāϰ āϜāĻ¨ā§āϝ āύāĻŋāĻ°ā§āĻ­āϰāϝ⧋āĻ—ā§āϝ āĻšā§‹āĻ¸ā§āϟāĻŋāĻ‚ āĻ•āĻŋāύ⧁āύ đŸ”Ĩ DDoS āϏ⧁āϰāĻ•ā§āώāĻž āϏāĻš āύāĻŋāĻ°ā§āĻ­āϰāϝ⧋āĻ—ā§āϝ āĻ“āϝāĻŧ⧇āĻŦāϏāĻžāχāϟ āĻšā§‹āĻ¸ā§āϟāĻŋāĻ‚ āĻ•āĻŋāύ⧁āύ, VPS VDS āϏāĻžāĻ°ā§āĻ­āĻžāϰ | ProHoster