{"id":89276,"date":"2020-07-21T13:42:28","date_gmt":"2020-07-21T11:42:28","guid":{"rendered":"https:\/\/prohoster.info\/blog\/administrirovanie\/kak-popast-v-ipvpn-bilajn-cherez-ipsec-chast-1"},"modified":"2026-07-05T10:59:44","modified_gmt":"2026-07-05T08:59:44","slug":"kak-popast-v-ipvpn-bilajn-cherez-ipsec-chast-1","status":"publish","type":"post","link":"https:\/\/prohoster.info\/en\/blog\/administrirovanie\/kak-popast-v-ipvpn-bilajn-cherez-ipsec-chast-1","title":{"rendered":"How to access Beeline IPVPN through IPSec. Part 1","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>Hello! In <a href=\"https:\/\/habr.com\/ru\/company\/beeline\/blog\/498450\/\" rel=\"nofollow\">the previous post<\/a> I described the operation of our MultiSIM service regarding <a href=\"https:\/\/moskva.beeline.ru\/business\/mobile-and-internet\/office-internet\/rezervirovanie-internet-soedineniia\/?utm_source=habr\" rel=\"nofollow\">reservation<\/a> and <a href=\"https:\/\/moskva.beeline.ru\/business\/mobile-and-internet\/office-internet\/obedinenie-mobilnih-setey\/?utm_source=habr\" rel=\"nofollow\">balancing<\/a> channels. As mentioned, we connect clients to the network via VPN, and today I'll share a bit more about VPN and our capabilities in this area.<\/p>\n<p>To begin with, as a telecommunications operator, we have our own extensive MPLS network, which is divided into two main segments for fixed-line clients \u2014 one used directly for Internet access, and the other used for creating isolated networks \u2014 with IPVPN (L3 OSI) and VPLAN (L2 OSI) traffic flowing through this MPLS segment for our corporate clients.<\/p>\n<p><a href=\"https:\/\/habr.com\/ru\/company\/beeline\/blog\/510154\/\" rel=\"nofollow\"><img decoding=\"async\" style=\"display: block; margin: 0 auto;\" src=\"\/wp-content\/uploads\/2020\/07\/b5b3d5c28266d1916b7ac93e94d2fe5b.jpg\" alt=\"How to access Beeline IPVPN through IPSec. Part 1\" \/><\/a><a rel=\"nofollow\" name=\"habracut\"><\/a><br \/>\nTypically, client connections occur as follows.<\/p>\n<p>An access line is laid to the client's office from the nearest Point of Presence (POP) of the network (MEN node, P2P link, BSSS, FTTB, etc.), and then, the channel is routed through the transport network to the corresponding PE-MPLS router, where it's assigned to a specifically created VRF for the client, taking into account their required traffic profile (profile tags are selected for each access port based on the values of IP precedence 0, 1, 3, 5).<\/p>\n<p>If, for any reason, we cannot fully organize the last mile for the client, for example, if the client's office is in a business center where another provider is prioritized, or if there is simply no point of presence near them, clients previously had to create multiple IPVPN networks with different providers (not the most cost-effective architecture) or solve access issues to their VRF over the Internet.<\/p>\n<p>Many did this by setting up an IPVPN Internet gateway \u2014 they installed a border router (hardware or some solution based on Linux), connected an IPVPN channel to one port and an Internet channel to another, launching their own <a href=\"https:\/\/prohoster.info\/en\/vpn\/\">VPN server<\/a> and connecting users through their own VPN gateway. Naturally, such a scheme brings its own challenges: this infrastructure needs to be built correctly and, what's most inconvenient \u2014 maintained and developed.<\/p>\n<p>To simplify life for our clients, we established a centralized VPN hub and organized support for connections over the internet using IPSec. Now, clients only need to configure their routers to work with our VPN hub via an IPSec tunnel through any public internet, and we will route that client's traffic into their VRF.<\/p>\n<h2>Who will benefit<\/h2>\n<p>&nbsp;<\/p>\n<ul>\n<li>Those with an existing large IPVPN network looking for new connections in a short time frame.<\/li>\n<li>Anyone who, for various reasons, wants to shift some traffic from the public internet to IPVPN but has previously faced technical limitations with multiple service providers.<\/li>\n<li>Those who currently have several disconnected VPN networks with different operators. There are clients who successfully organized IPVPN from Beeline, MegaFon, and Rostelecom, etc. To simplify things, they can only rely on our unified network, <a href=\"https:\/\/prohoster.info\/en\/vpn\/\">VPN<\/a>, switching all other channels from different operators to the internet, after which they can connect to Beeline's IPVPN via IPSec and these operators' internet.<\/li>\n<li>Those who already have an IPVPN network overlaying the internet.<\/li>\n<\/ul>\n<p>If everything is deployed with us, clients receive full support for VPN, serious infrastructure redundancy, and standard settings that will work on any router they are accustomed to (whether it\u2019s Cisco or Mikrotik, as long as it supports IPSec\/IKEv2 with standardized authentication methods). By the way, regarding IPSec \u2014 we currently support only it, but we plan to fully implement OpenVPN and WireGuard, so clients won\u2019t be dependent on the protocol and can more easily migrate everything to us. Additionally, we want to start connecting clients from computers and mobile devices (integrated OS solutions, Cisco AnyConnect, strongSwan, and similar). With this approach, de facto infrastructure construction can confidently be delegated to the operator, leaving only the configuration of CPE or host.<\/p>\n<p>How the connection process works for the IPSec mode:<\/p>\n<ol>\n<li>The client submits a request to their manager, specifying the required connection speed, traffic profile, and IP address parameters for the tunnel (by default a subnet with a mask of \/30) and the routing type (static or BGP). To transmit routes to the client's local networks in the connected office, IKEv2 phase mechanisms of the IPSec protocol are used with the appropriate settings on the client's router, or they are announced via BGP in MPLS from the private BGP AS specified by the client in the request. Thus, information about the routes of client networks is fully controlled by the client through the settings of the client router.<\/li>\n<li>In response from their manager, the client receives accounting data to include in their VRF, as follows:\n<ul>\n<li>IP address of the VPN-HUB<\/li>\n<li>Login<\/li>\n<li>Authentication password<\/li>\n<\/ul>\n<\/li>\n<li>Configure the CPE, below are two examples of basic configurations:<b class=\"spoiler_title\">Option for Cisco:<\/b><br \/>\ncrypto ikev2 keyring BeelineIPsec_keyring<br \/>\npeer Beeline_VPNHub<br \/>\naddress 62.141.99.183 <i> \u2013 VPN hub Beeline<\/i><br \/>\npre-shared-key<br \/>\n!<br \/>\n<i>For the option with static routing, the routes to the networks accessible via the VPN hub can be specified in the IKEv2 setup and will automatically appear as static routes in the CPE's routing table. These settings can also be configured using the standard method for specifying static routes (see below).<\/i><\/p>\n<p>crypto ikev2 authorization policy FlexClient-author<\/p>\n<p><i>The route to the networks behind the CPE router is a mandatory setting when using static routing between the CPE and PE. The transfer of routing data to the PE is performed automatically when the tunnel is established via IKEv2 interaction.<\/i><\/p>\n<p>route set remote ipv4 10.1.1.0 255.255.255.0 <i> \u2013 Local office network<\/i><br \/>\n!<br \/>\ncrypto ikev2 profile BeelineIPSec_profile<br \/>\nidentity local<br \/>\nauthentication local pre-share<br \/>\nauthentication remote pre-share<br \/>\nkeyring local BeelineIPsec_keyring<br \/>\naaa authorization group psk list group-author-list FlexClient-author<br \/>\n!<br \/>\ncrypto ikev2 client flexvpn BeelineIPsec_flex<br \/>\npeer 1 Beeline_VPNHub<br \/>\nclient connect Tunnel1<br \/>\n!<br \/>\ncrypto ipsec transform-set TRANSFORM1 esp-aes 256 esp-sha256-hmac<br \/>\nmode tunnel<br \/>\n!<br \/>\ncrypto ipsec profile default<br \/>\nset transform-set TRANSFORM1<br \/>\nset ikev2-profile BeelineIPSec_profile<br \/>\n!<br \/>\ninterface Tunnel1<br \/>\nip address 10.20.1.2 255.255.255.252 <i> \u2013 Tunnel address<\/i><br \/>\ntunnel source GigabitEthernet0\/2 <i> \u2013 Internet access interface<\/i><br \/>\ntunnel mode ipsec ipv4<br \/>\ntunnel destination dynamic<br \/>\ntunnel protection ipsec profile default<br \/>\n!<br \/>\n<i>Routes to the client's private networks accessible via the VPN hub Beeline can be specified statically.<\/i><\/p>\n<p>ip route 172.16.0.0 255.255.0.0 Tunnel1<br \/>\nip route 192.168.0.0 255.255.255.0 Tunnel1<\/p>\n<p><b class=\"spoiler_title\">Option for Huawei (ar160\/120):<\/b><br \/>\nike local-name<br \/>\n#<br \/>\nacl name ipsec 3999<br \/>\nrule 1 permit ip source 10.1.1.0 0.0.0.255 <i> \u2013 Local office network<\/i><br \/>\n#<br \/>\naaa<br \/>\nservice-scheme IPSEC<br \/>\nroute set acl 3999<br \/>\n#<br \/>\nipsec proposal ipsec<br \/>\nesp authentication-algorithm sha2-256<br \/>\nesp encryption-algorithm aes-256<br \/>\n#<br \/>\nike proposal default<br \/>\nencryption-algorithm aes-256<br \/>\ndh group2<br \/>\nauthentication-algorithm sha2-256<br \/>\nauthentication-method pre-share<br \/>\nintegrity-algorithm hmac-sha2-256<br \/>\nprf hmac-sha2-256<br \/>\n#<br \/>\nike peer ipsec<br \/>\npre-shared-key simple<br \/>\nlocal-id-type fqdn<br \/>\nremote-id-type ip<br \/>\nremote-address 62.141.99.183 <i> \u2013 VPN hub Beeline<\/i><br \/>\nservice-scheme IPSEC<br \/>\nconfig-exchange request<br \/>\nconfig-exchange set accept<br \/>\nconfig-exchange set send<br \/>\n#<br \/>\nipsec profile ipsecprof<br \/>\nike-peer ipsec<br \/>\nproposal ipsec<br \/>\n#<br \/>\ninterface Tunnel0\/0\/0<br \/>\nip address 10.20.1.2 255.255.255.252 <i> \u2013 Tunnel address<\/i><br \/>\ntunnel-protocol ipsec<br \/>\nsource GigabitEthernet0\/0\/1 <i> \u2013 Internet access interface<\/i><br \/>\nipsec profile ipsecprof<br \/>\n#<br \/>\n<i>Routes to the client's private networks available through the Beeline VPN gateway can be set statically<\/i><\/p>\n<p>ip route-static 192.168.0.0 255.255.255.0 Tunnel0\/0\/0<br \/>\nip route-static 172.16.0.0 255.255.0.0 Tunnel0\/0\/0<\/li>\n<\/ol>\n<p>The resulting communication scheme looks something like this:<\/p>\n<p><img decoding=\"async\" style=\"display: block; margin: 0 auto;\" src=\"\/wp-content\/uploads\/2020\/07\/8083e9190bdcdd816ac3014d7b7f5de4.jpg\" alt=\"How to access Beeline IPVPN through IPSec. Part 1\" \/><\/p>\n<p>If there are no examples of basic configurations from the client, we usually help in creating them and make them available to everyone else.<\/p>\n<p>Finally, connect the CPE to the Internet, ping the opposite side of the VPN tunnel and any host inside the VPN, and that's it, you can consider the connection established.<\/p>\n<p>In the next article, we will discuss how we combined this scheme with IPSec and MultiSIM Resilience using Huawei CPE: we install our Huawei CPE for clients, which can use not only a wired internet channel but also 2 different SIM cards, and the CPE automatically rebuilds the IPSec tunnel either through wired WAN or via radio (LTE#1\/LTE#2), achieving high service availability.<\/p>\n<p>Special thanks for preparing this article (and, actually, to the authors of these technical solutions) to our RnD colleagues!<\/p>\n<p>Source: <a rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/company\/beeline\/blog\/510154\/\">habr.com<\/a><\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u041f\u0440\u0438\u0432\u0435\u0442! \u0412 \u043f\u0440\u0435\u0434\u044b\u0434\u0443\u0449\u0435\u043c \u043f\u043e\u0441\u0442\u0435 \u044f \u043e\u043f\u0438\u0441\u0430\u043b \u0440\u0430\u0431\u043e\u0442\u0443 \u043d\u0430\u0448\u0435\u0433\u043e \u0441\u0435\u0440\u0432\u0438\u0441\u0430 MultiSIM \u0432 \u0447\u0430\u0441\u0442\u0438 \u0440\u0435\u0437\u0435\u0440\u0432\u0438\u0440\u043e\u0432\u0430\u043d\u0438\u044f \u0438 \u0431\u0430\u043b\u0430\u043d\u0441\u0438\u0440\u043e\u0432\u043a\u0438 \u043a\u0430\u043d\u0430\u043b\u043e\u0432. \u041a\u0430\u043a \u0431\u044b\u043b\u043e \u0443\u043f\u043e\u043c\u044f\u043d\u0443\u0442\u043e, \u043a\u043b\u0438\u0435\u043d\u0442\u043e\u0432 \u043a \u0441\u0435\u0442\u0438 \u043c\u044b \u043f\u043e\u0434\u043a\u043b\u044e\u0447\u0430\u0435\u043c \u0447\u0435\u0440\u0435\u0437 VPN, \u0438 \u0441\u0435\u0433\u043e\u0434\u043d\u044f \u044f \u0440\u0430\u0441\u0441\u043a\u0430\u0436\u0443 \u043d\u0435\u043c\u043d\u043e\u0433\u043e \u0431\u043e\u043b\u044c\u0448\u0435 \u043f\u0440\u043e VPN \u0438 \u043d\u0430\u0448\u0438 \u0432\u043e\u0437\u043c\u043e\u0436\u043d\u043e\u0441\u0442\u0438 \u0432 \u044d\u0442\u043e\u0439 \u0447\u0430\u0441\u0442\u0438. \u041d\u0430\u0447\u0430\u0442\u044c \u0441\u0442\u043e\u0438\u0442 \u0441 \u0442\u043e\u0433\u043e, \u0447\u0442\u043e \u0443 \u043d\u0430\u0441 \u043a\u0430\u043a \u0443 \u043e\u043f\u0435\u0440\u0430\u0442\u043e\u0440\u0430 \u0441\u0432\u044f\u0437\u0438 \u0435\u0441\u0442\u044c \u0441\u0432\u043e\u044f \u043e\u0433\u0440\u043e\u043c\u043d\u0430\u044f MPLS-\u0441\u0435\u0442\u044c, [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":89277,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[688],"tags":[],"class_list":["post-89276","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-administrirovanie"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u041f\u0440\u0438\u0432\u0435\u0442!\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/en\/blog\/administrirovanie\/kak-popast-v-ipvpn-bilajn-cherez-ipsec-chast-1\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2\" \/>\n\t\t<meta property=\"og:locale\" content=\"en_US\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u041a\u0430\u043a \u043f\u043e\u043f\u0430\u0441\u0442\u044c \u0432 IPVPN \u0411\u0438\u043b\u0430\u0439\u043d \u0447\u0435\u0440\u0435\u0437 IPSec. \u0427\u0430\u0441\u0442\u044c 1 | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u041f\u0440\u0438\u0432\u0435\u0442!\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/en\/blog\/administrirovanie\/kak-popast-v-ipvpn-bilajn-cherez-ipsec-chast-1\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2020-07-21T11:42:28+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2026-07-05T08:59:44+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47How to Access Beeline IPVPN via IPSec. Part 1 | ProHoster","description":"Hello!","canonical_url":"https:\/\/prohoster.info\/en\/blog\/administrirovanie\/kak-popast-v-ipvpn-bilajn-cherez-ipsec-chast-1","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"en_US","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u041a\u0430\u043a \u043f\u043e\u043f\u0430\u0441\u0442\u044c \u0432 IPVPN \u0411\u0438\u043b\u0430\u0439\u043d \u0447\u0435\u0440\u0435\u0437 IPSec. \u0427\u0430\u0441\u0442\u044c 1 | ProHoster","og:description":"\u041f\u0440\u0438\u0432\u0435\u0442!","og:url":"https:\/\/prohoster.info\/en\/blog\/administrirovanie\/kak-popast-v-ipvpn-bilajn-cherez-ipsec-chast-1","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2020-07-21T11:42:28+00:00","article:modified_time":"2026-07-05T08:59:44+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"89276","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":null,"breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-02-28 13:13:28","updated":"2022-09-30 17:39:06","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/89276","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/comments?post=89276"}],"version-history":[{"count":1,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/89276\/revisions"}],"predecessor-version":[{"id":182465,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/89276\/revisions\/182465"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/media\/89277"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/media?parent=89276"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/categories?post=89276"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/tags?post=89276"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}