{"id":95220,"date":"2020-09-26T19:42:34","date_gmt":"2020-09-26T17:42:34","guid":{"rendered":"https:\/\/prohoster.info\/blog\/administrirovanie\/postroenie-setevoj-infrastruktury-na-baze-nebula-chast-1-zadachi-i-resheniya"},"modified":"2020-09-26T19:42:34","modified_gmt":"2020-09-26T17:42:34","slug":"postroenie-setevoj-infrastruktury-na-baze-nebula-chast-1-zadachi-i-resheniya","status":"publish","type":"post","link":"https:\/\/prohoster.info\/en\/blog\/administrirovanie\/postroenie-setevoj-infrastruktury-na-baze-nebula-chast-1-zadachi-i-resheniya","title":{"rendered":"Building a Network Infrastructure Based on Nebula. Part 1 - Challenges and Solutions","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p><img decoding=\"async\" alt=\"Building a Network Infrastructure Based on Nebula. Part 1 - Challenges and Solutions\" src=\"\/wp-content\/uploads\/2020\/09\/00918e3fa2c8734f30983f6591f4b84a.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<em>This article discusses the problems of organizing network infrastructure in the traditional way and the methods of solving these issues using cloud technologies.<\/em><\/p>\n<p><noindex><a rel=\"nofollow\" name=\"habracut\"><\/a><\/noindex><\/p>\n<p><strong>For your information.<\/strong> Nebula is a SaaS cloud environment for remote management of network infrastructure. All devices supporting Nebula are managed from the cloud through a secure connection. A large distributed network infrastructure can be managed from a single center without the effort required to establish one.<\/p>\n<p><\/p>\n<h2 id=\"dlya-chego-nuzhen-ocherednoy-oblachnyy-servis\">What is the purpose of another cloud service?<\/h2>\n<p><\/p>\n<p>The main problem when working with network infrastructure is not the design of the network or the purchase of equipment, nor even the mounting in a rack, but everything else that will need to be done with this network later.<\/p>\n<p><\/p>\n<h3 id=\"set-novaya--zaboty-starye\">A new network - old worries<\/h3>\n<p><\/p>\n<p>When putting a new network node into operation after installing and connecting the equipment, the initial configuration begins. From the perspective of the 'higher-ups' \u2014 it seems simple: 'Take the working documentation for the project and start configuring\u2026' It sounds great when all network elements are located in one data center. However, if they are scattered across branches, it becomes a headache to ensure remote access. It's a vicious cycle: to gain remote access over the network, network equipment needs to be configured, and for that, network access is required\u2026<\/p>\n<p><\/p>\n<p>Different schemes have to be devised to break out of the described deadlock. For example, a laptop with Internet access through a USB 4G modem is connected to the network being configured via a patch cord. A VPN client is launched on this laptop, and through it, the network administrator from headquarters tries to gain access to the branch network. The scheme is not the most transparent - even if you bring a laptop with a pre-configured VPN to the remote site and ask to turn it on, there is no guarantee everything will work on the first try. Especially if it's a different region with another provider.<\/p>\n<p><\/p>\n<p>Thus, the most reliable way is to have a good specialist \"on the other end of the line\" who can configure their part according to the project. If there is none in the branch, options remain: either outsourcing or a business trip.<\/p>\n<p><\/p>\n<p>A monitoring system is also needed. It requires installation, configuration, and maintenance (at least to keep track of disk space and regularly make backups). And it shouldn\u2019t know about our devices until we inform it. For this, settings for all equipment must be configured, and records should be regularly updated.<\/p>\n<p><\/p>\n<p>It's wonderful when there is a 'one-man band' on staff who, besides specific knowledge as a network administrator, knows how to work with Zabbix or another similar system. Otherwise, we need to hire another person or outsource it.<\/p>\n<p><\/p>\n<p><em><strong>Note.<\/strong> The most unfortunate mistakes begin with the words: 'What\u2019s so difficult about setting up Zabbix (Nagios, OpenView, etc.)? I\u2019ll just quickly get it up and running!'<\/em><\/p>\n<p><\/p>\n<h3 id=\"ot-vnedreniya-k-ekspluatacii\">From Implementation to Operation<\/h3>\n<p><\/p>\n<p>Let's consider a specific example.<\/p>\n<p><\/p>\n<p>An alarming message has been received indicating that a WiFi access point is unresponsive somewhere.<\/p>\n<p><\/p>\n<p>Where is it located?<\/p>\n<p><\/p>\n<p>Of course, a good network administrator has their personal directory where everything is noted. Questions arise when this information needs to be shared. For instance, if one urgently needs to send someone to sort things out on-site, they must provide something like: 'The access point is located in the business center at Stroitely Street, building 1, on the 3rd floor, office N 301 next to the entrance door under the ceiling.'<\/p>\n<p><\/p>\n<p>Let's say we are lucky, and the access point is powered via PoE, while the switch allows for remote rebooting. No need to go there, but remote access to the switch is required. We still need to configure port forwarding through PAT on the router, deal with VLAN for external connections, and so on. It\u2019s great if everything was set up in advance. The task may not be complicated, but it still needs to be done.<\/p>\n<p><\/p>\n<p>So, the access point has been rebooted for power. Didn't help?<\/p>\n<p><\/p>\n<p>Suppose something is wrong with the hardware. Now we need to look for information about the warranty, the start of operation, and other interesting details.<\/p>\n<p><\/p>\n<p>Speaking of WiFi, using a home version of WPA2-PSK, where one key is used for all devices, is not recommended in a corporate environment. Firstly, having a single key for everyone is simply insecure; secondly, when an employee leaves, you have to change this common key and reconfigure all devices for all users. To avoid such issues, there is WPA2-Enterprise with individual authentication for each user. However, this requires a RADIUS server\u2014another infrastructure component that needs to be monitored, backed up, and so on.<\/p>\n<p><\/p>\n<p>Note that at every stage, whether it's implementation or operation, we utilized auxiliary systems. This includes a laptop with an 'external' Internet connection, a monitoring system, a reference database for equipment, and RADIUS as an authentication system. Besides network devices, we also have to support third-party services.<\/p>\n<p><\/p>\n<p>In such cases, you might hear the advice: 'Put it in the cloud and don't worry about it.' Surely there is a cloud-based Zabbix, there may be a cloud-based RADIUS somewhere, and even a cloud database to maintain a list of devices. The problem is that these need to be integrated, not separate. And there are still questions about access organization, initial device setup, security, and many others.<\/p>\n<p><\/p>\n<h2 id=\"kak-eto-vyglyadit-pri-ispolzovanii-nebula\">How does it work with Nebula?<\/h2>\n<p><\/p>\n<p>Of course, initially the 'cloud' knows nothing about our plans or the equipment purchased.<\/p>\n<p><\/p>\n<p>First, an organization profile is created. This means that the entire infrastructure\u2014headquarters and branches\u2014is initially documented in the cloud. Credentials are specified, and accounts are created to delegate permissions.<\/p>\n<p><\/p>\n<p>You can register the used devices in the cloud in two ways: the old-fashioned way\u2014by simply entering the serial number when filling out a web form, or by scanning a QR code with a mobile phone. All that is needed for the second method is a smartphone with a camera and Internet access, including through a mobile provider.<\/p>\n<p><\/p>\n<p>Of course, Zyxel Nebula provides the necessary infrastructure for storing both account information and configurations.<\/p>\n<p><\/p>\n<p><img decoding=\"async\" alt=\"Building a Network Infrastructure Based on Nebula. Part 1 - Challenges and Solutions\" src=\"\/wp-content\/uploads\/2020\/09\/39014b58954c55ba55d24077f481a35c.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<em>Figure 1. Security report of the Nebula Control Center.<\/em><\/p>\n<p><\/p>\n<p>What about access settings? Opening ports, forwarding traffic through the incoming gateway, all that which security administrators affectionately refer to as 'poking holes'? Fortunately, none of this is necessary. Devices under the Nebula control initiate an outbound connection. The administrator connects to the cloud instead of to a separate device for configuration. Nebula acts as an intermediary between two connections: with the device and with the network administrator's computer. This means that the step involving the incoming admin can be minimized or even skipped entirely. And there are no additional 'holes' in the firewall.<\/p>\n<p><\/p>\n<p>What about the RADIUS server? A centralized authentication is necessary, right?<\/p>\n<p><\/p>\n<p>Nebula also takes care of this function. Authentication of accounts for access to equipment occurs through a secure database. This greatly simplifies delegating or revoking rights to manage the system. To transfer rights, we create a user and assign a role. To revoke rights, we perform the reverse actions.<\/p>\n<p><\/p>\n<p>It's worth mentioning WPA2-Enterprise, which requires a separate authentication service. Zyxel Nebula has its own equivalent \u2014 DPPSK, which allows using WPA2-PSK with an individual key for each user.<\/p>\n<p><\/p>\n<h2 id=\"neudobnye-voprosy\">\"Inconvenient\" questions<\/h2>\n<p><\/p>\n<p>Below, we will attempt to answer the most challenging questions that are often asked when entering the cloud service.<\/p>\n<p><\/p>\n<h3 id=\"a-eto-tochno-bezopasno\">Is it really safe?<\/h3>\n<p><\/p>\n<p>In any delegation of control and management, two factors play an important role in ensuring security: anonymization and encryption.<\/p>\n<p><\/p>\n<p>The use of encryption to protect traffic from prying eyes is somewhat familiar to readers.<\/p>\n<p><\/p>\n<p>Anonymization hides the owner's information and the source from the cloud provider's staff. Personal information is removed, and records are assigned a 'faceless' identifier. Neither the developer of the cloud software nor the administrator servicing the cloud system can know the owner of the requests. 'Where did this come from? Who could be interested in this?' \u2014 such questions will remain unanswered. The absence of data about the owner and source makes insider threats a meaningless waste of time.<\/p>\n<p><\/p>\n<p>When comparing this approach to the traditional practice of outsourcing or hiring a temporary admin, it is clear that cloud technologies are more secure. A temporary IT specialist knows quite a bit about the organization they are working with and can, either intentionally or unintentionally, cause significant security harm. Additionally, there is the issue of termination or contract completion. Sometimes, aside from blocking or deleting an account, it leads to a global password change for access to services, as well as an audit of all resources for 'forgotten' entry points and possible 'backdoors'.<\/p>\n<p><\/p>\n<h3 id=\"naskolko-nebula-dorozhe-ili-deshevle-prihodyaschego-admina\">How much more expensive or cheaper is Nebula compared to a temporary admin?<\/h3>\n<p><\/p>\n<p>Everything is understood in comparison. The basic features of Nebula are available for free. In fact, what could be cheaper?<\/p>\n<p><\/p>\n<p>Of course, it is impossible to completely do without a network administrator or someone to take their place. The issue lies in the number of people, their specialization, and distribution across sites.<\/p>\n<p><\/p>\n<p>As for the paid extended service, asking a direct question: is it more expensive or cheaper? This approach will always be inaccurate and one-sided. It is better to compare multiple factors, from the payment for the work of specific specialists to the costs involved in ensuring their interaction with a contractor or individual: quality control, documentation preparation, maintaining a level of security, and so on.<\/p>\n<p><\/p>\n<p>Speaking of whether it is beneficial or not to purchase the paid service package (Pro-Pack), the approximate answer may sound like this: if the organization is small, the basic version will suffice; if the organization is growing, it makes sense to consider the Pro-Pack. The differences between the Zyxel Nebula versions can be seen in Table 1.<\/p>\n<p><\/p>\n<p><em>Table 1. Differences between the basic version and the Pro-Pack version features for Nebula.<\/em><\/p>\n<p><\/p>\n<p><img decoding=\"async\" alt=\"Building a Network Infrastructure Based on Nebula. Part 1 - Challenges and Solutions\" src=\"\/wp-content\/uploads\/2020\/09\/0cf50e1b2dbd509c3a8f014ae37323cf.jpg\" style=\"display:block;margin: 0 auto;\" \/><\/p>\n<p><\/p>\n<p>This includes extended reporting, user auditing, configuration cloning, and much more.<\/p>\n<p><\/p>\n<h3 id=\"a-chto-s-zaschitoy-trafika\">What about traffic protection?<\/h3>\n<p><\/p>\n<p>Nebula uses the protocol <noindex><a rel=\"nofollow\" href=\"https:\/\/ru.wikipedia.org\/wiki\/NETCONF\">NETCONF<\/a><\/noindex> to ensure the security of network equipment operations.<\/p>\n<p><\/p>\n<p>NETCONF can operate over several transport protocols:<\/p>\n<p><\/p>\n<ul>\n<li><noindex><a rel=\"nofollow\" href=\"https:\/\/ru.wikipedia.org\/wiki\/Secure_Shell\">SSH<\/a><\/noindex> (<noindex><a rel=\"nofollow\" href=\"https:\/\/tools.ietf.org\/html\/rfc4742\">RFC 4742<\/a><\/noindex>);<\/li>\n<li><noindex><a rel=\"nofollow\" href=\"https:\/\/ru.wikipedia.org\/wiki\/SOAP\">SOAP<\/a><\/noindex> (<noindex><a rel=\"nofollow\" href=\"https:\/\/tools.ietf.org\/html\/rfc4743\">RFC 4743<\/a><\/noindex>);<\/li>\n<li><noindex><a rel=\"nofollow\" href=\"https:\/\/ru.wikipedia.org\/w\/index.php?title=BEEP&amp;action=edit&amp;redlink=1\">BEEP<\/a><\/noindex> (<noindex><a rel=\"nofollow\" href=\"https:\/\/tools.ietf.org\/html\/rfc4744\">RFC 4744<\/a><\/noindex>);<\/li>\n<li><noindex><a rel=\"nofollow\" href=\"https:\/\/ru.wikipedia.org\/wiki\/Transport_Layer_Security\">TLS<\/a><\/noindex> (<noindex><a rel=\"nofollow\" href=\"https:\/\/tools.ietf.org\/html\/rfc5539\">RFC 5539<\/a><\/noindex>).<\/li>\n<\/ul>\n<p><\/p>\n<p>When comparing NETCONF with other methods, such as management via SNMP, it should be noted that <strong>NETCONF<\/strong> supports outgoing TCP connections to overcome NAT barriers and is considered more reliable.<\/p>\n<p><\/p>\n<h3 id=\"chto-s-podderzhkoy-oborudovaniya\">What about hardware support?<\/h3>\n<p><\/p>\n<p>Of course, you shouldn't turn the server room into a zoo with representatives of rare and endangered species of equipment. It's highly desirable that the equipment managed by technology should cover all directions: from the central switch to access points. Zyxel engineers ensured this capability. A multitude of devices operate under Nebula:<\/p>\n<p><\/p>\n<ul>\n<li>10G central switches;<\/li>\n<li>access level switches;<\/li>\n<li>PoE switches;<\/li>\n<li>access points;<\/li>\n<li>network gateways.<\/li>\n<\/ul>\n<p><\/p>\n<p>By utilizing a wide range of supported devices, networks can be built for various types of tasks. This is especially relevant for companies that are expanding not vertically, but horizontally, constantly exploring new premises for business.<\/p>\n<p><\/p>\n<h2 id=\"postoyannoe-razvitie\">Continuous development<\/h2>\n<p><\/p>\n<p>Network devices with traditional management methods have only one path for improvement \u2014 modifying the device itself, be it a new firmware or additional modules. With Zyxel Nebula, there is an additional path for enhancements \u2014 through improvements to cloud infrastructure. For example, after the Nebula Control Center (NCC) was updated to version 10.1 on September 21, 2020, users gained new capabilities, here are a few of them:<\/p>\n<p><\/p>\n<ul>\n<li>the organization owner can now transfer all ownership rights to another administrator within the same organization;<\/li>\n<li>a new role called 'Owner's Representative', which has the same rights as the organization owner;<\/li>\n<li>a new feature for firmware updates across the organization (Pro-Pack feature);<\/li>\n<li>two new options added to the topology: device reboot and enabling\/disabling PoE port power (Pro-Pack feature);<\/li>\n<li>support for new access point models: WAC500, WAC500H, WAC5302D-Sv2, and NWA1123ACv3;<\/li>\n<li>support for voucher authentication with QR code printing (Pro-Pack feature).<\/li>\n<\/ul>\n<p><\/p>\n<h2 id=\"poleznye-ssylki\">Useful links<\/h2>\n<p><\/p>\n<ol>\n<li><noindex><a rel=\"nofollow\" href=\"https:\/\/t.me\/zyxelru\">Zyxel Telegram chat<\/a><\/noindex><\/li>\n<li><noindex><a rel=\"nofollow\" href=\"https:\/\/www.zyxel.com\/ru\/ru\/ci_general_20191031_520516.shtml\">Zyxel Equipment Forum<\/a><\/noindex><\/li>\n<li><noindex><a rel=\"nofollow\" href=\"https:\/\/www.youtube.com\/channel\/UCcNN2UCEz1e49PEaAisN5ow\">A lot of useful videos on the YouTube channel<\/a><\/noindex><\/li>\n<li><noindex><a rel=\"nofollow\" href=\"https:\/\/www.youtube.com\/channel\/UCcNN2UCEz1e49PEaAisN5ow\">Zyxel Nebula \u2014 management simplicity as a foundation for savings<\/a><\/noindex><\/li>\n<li><noindex><a rel=\"nofollow\" href=\"https:\/\/www.zyxel.com\/library\/assets\/solutions\/nebula\/pdf\/nebula-licensing-table.pdf\">Differences between Zyxel Nebula versions<\/a><\/noindex><\/li>\n<li><noindex><a rel=\"nofollow\" href=\"https:\/\/www.youtube.com\/channel\/UCcNN2UCEz1e49PEaAisN5ow\">Zyxel Nebula and company growth<\/a><\/noindex><\/li>\n<li><noindex><a rel=\"nofollow\" href=\"https:\/\/www.youtube.com\/channel\/UCcNN2UCEz1e49PEaAisN5ow\">The ultramodern Zyxel Nebula cloud \u2014 a cost-effective path to security?<\/a><\/noindex><\/li>\n<li><noindex><a rel=\"nofollow\" href=\"https:\/\/www.zyxel.com\/library\/assets\/solutions\/nebula\/pdf\/nebula-licensing-table.pdf\">Zyxel Nebula \u2014 Options for Your Business<\/a><\/noindex><\/li>\n<\/ol>\n<p>Source: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/company\/zyxel\/blog\/520462\/\">habr.com<\/a> <\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0412 \u0441\u0442\u0430\u0442\u044c\u0435 \u043f\u043e\u0439\u0434\u0435\u0442 \u0440\u0435\u0447\u044c \u043e \u043f\u0440\u043e\u0431\u043b\u0435\u043c\u0430\u0445 \u043e\u0440\u0433\u0430\u043d\u0438\u0437\u0430\u0446\u0438\u0438 \u0441\u0435\u0442\u0435\u0432\u043e\u0439 \u0438\u043d\u0444\u0440\u0430\u0441\u0442\u0440\u0443\u043a\u0442\u0443\u0440\u044b \u0442\u0440\u0430\u0434\u0438\u0446\u0438\u043e\u043d\u043d\u044b\u043c \u0441\u043f\u043e\u0441\u043e\u0431\u043e\u043c \u0438 \u043e \u043c\u0435\u0442\u043e\u0434\u0430\u0445 \u0440\u0435\u0448\u0435\u043d\u0438\u044f \u0442\u0435\u0445 \u0436\u0435 \u0441\u0430\u043c\u044b\u0445 \u0432\u043e\u043f\u0440\u043e\u0441\u043e\u0432 \u043f\u0440\u0438 \u043f\u043e\u043c\u043e\u0449\u0438 \u043e\u0431\u043b\u0430\u0447\u043d\u044b\u0445 \u0442\u0435\u0445\u043d\u043e\u043b\u043e\u0433\u0438\u0439. \u0414\u043b\u044f \u0441\u043f\u0440\u0430\u0432\u043a\u0438. Nebula \u2014 \u043e\u0431\u043b\u0430\u0447\u043d\u0430\u044f \u0441\u0440\u0435\u0434\u0430 SaaS \u0434\u043b\u044f \u0443\u0434\u0430\u043b\u0435\u043d\u043d\u043e\u0433\u043e \u043f\u043e\u0434\u0434\u0435\u0440\u0436\u0430\u043d\u0438\u044f \u0441\u0435\u0442\u0435\u0432\u043e\u0439 \u0438\u043d\u0444\u0440\u0430\u0441\u0442\u0440\u0443\u043a\u0442\u0443\u0440\u044b. \u0412\u0441\u0435 \u0443\u0441\u0442\u0440\u043e\u0439\u0441\u0442\u0432\u0430, \u043f\u043e\u0434\u0434\u0435\u0440\u0436\u0438\u0432\u0430\u044e\u0449\u0438\u0435 Nebula, \u0443\u043f\u0440\u0430\u0432\u043b\u044f\u044e\u0442\u0441\u044f \u0438\u0437 \u043e\u0431\u043b\u0430\u043a\u0430 \u0447\u0435\u0440\u0435\u0437 \u0431\u0435\u0437\u043e\u043f\u0430\u0441\u043d\u043e\u0435 \u0441\u043e\u0435\u0434\u0438\u043d\u0435\u043d\u0438\u0435. \u041c\u043e\u0436\u043d\u043e \u0443\u043f\u0440\u0430\u0432\u043b\u044f\u0442\u044c \u043a\u0440\u0443\u043f\u043d\u043e\u0439 \u0440\u0430\u0441\u043f\u0440\u0435\u0434\u0435\u043b\u0435\u043d\u043d\u043e\u0439 \u0441\u0435\u0442\u0435\u0432\u043e\u0439 \u0438\u043d\u0444\u0440\u0430\u0441\u0442\u0440\u0443\u043a\u0442\u0443\u0440\u043e\u0439 \u0438\u0437 \u0435\u0434\u0438\u043d\u043e\u0433\u043e \u0446\u0435\u043d\u0442\u0440\u0430, \u043d\u0435 [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":95221,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[688],"tags":[],"class_list":["post-95220","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-administrirovanie"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2 - aioseo.com -->\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/en\/blog\/administrirovanie\/postroenie-setevoj-infrastruktury-na-baze-nebula-chast-1-zadachi-i-resheniya\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2\" \/>\n\t\t<meta property=\"og:locale\" content=\"en_US\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u041f\u043e\u0441\u0442\u0440\u043e\u0435\u043d\u0438\u0435 \u0441\u0435\u0442\u0435\u0432\u043e\u0439 \u0438\u043d\u0444\u0440\u0430\u0441\u0442\u0440\u0443\u043a\u0442\u0443\u0440\u044b \u043d\u0430 \u0431\u0430\u0437\u0435 Nebula. \u0427\u0430\u0441\u0442\u044c 1 \u2014 \u0437\u0430\u0434\u0430\u0447\u0438 \u0438 \u0440\u0435\u0448\u0435\u043d\u0438\u044f | ProHoster\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/en\/blog\/administrirovanie\/postroenie-setevoj-infrastruktury-na-baze-nebula-chast-1-zadachi-i-resheniya\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2020-09-26T17:42:34+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2020-09-26T17:42:34+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Building a network infrastructure based on Nebula. Part 1 \u2014 tasks and solutions | ProHoster","description":"","canonical_url":"https:\/\/prohoster.info\/en\/blog\/administrirovanie\/postroenie-setevoj-infrastruktury-na-baze-nebula-chast-1-zadachi-i-resheniya","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"en_US","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u041f\u043e\u0441\u0442\u0440\u043e\u0435\u043d\u0438\u0435 \u0441\u0435\u0442\u0435\u0432\u043e\u0439 \u0438\u043d\u0444\u0440\u0430\u0441\u0442\u0440\u0443\u043a\u0442\u0443\u0440\u044b \u043d\u0430 \u0431\u0430\u0437\u0435 Nebula. \u0427\u0430\u0441\u0442\u044c 1 \u2014 \u0437\u0430\u0434\u0430\u0447\u0438 \u0438 \u0440\u0435\u0448\u0435\u043d\u0438\u044f | ProHoster","og:url":"https:\/\/prohoster.info\/en\/blog\/administrirovanie\/postroenie-setevoj-infrastruktury-na-baze-nebula-chast-1-zadachi-i-resheniya","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2020-09-26T17:42:34+00:00","article:modified_time":"2020-09-26T17:42:34+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"95220","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":null,"breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-02-28 11:10:35","updated":"2022-10-03 07:30:00","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/95220","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/comments?post=95220"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/95220\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/media\/95221"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/media?parent=95220"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/categories?post=95220"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/tags?post=95220"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}