Ntọhapụ nke OpenIKED 7.2, mmejuputa iwu nke IKEv2 maka IPsec

Ihe omume OpenBSD ekwuputala mwepụta nke OpenIKED 7.2, mmejuputa iwu IKEv2 nke OpenBSD Project mebere. Nke a bụ ntọhapụ nke anọ nke OpenIKED dị ka ọrụ dị iche - ihe ndị IKEv2 bụ akụkụ dị mkpa nke OpenBSD IPsec stack, mana e kewapụrụ ya na ngwugwu dị iche iche ma nwee ike iji ya na sistemụ arụmọrụ ndị ọzọ. A nwalere OpenIKED na FreeBSD, NetBSD, macOS na nkesa Linux dị iche iche gụnyere Arch, Debian, Fedora na Ubuntu. Edere koodu ahụ na C ma kesaa ya n'okpuru ikikere ISC.

OpenIKED na-enye gị ohere ibuga netwọk nzuzo mebere IPsec. Mpempe akwụkwọ IPsec nwere ụkpụrụ abụọ bụ isi: Key Exchange Protocol (IKE) na Protocol Transport Protocol (ESP). OpenIKED na-arụ ọrụ nke nyocha, nhazi, mgbanwe isi na mmezi amụma nchekwa, yana usoro kernel na-arụ ọrụ na-enyekarị protocol maka izochi okporo ụzọ ESP. Ụzọ nyocha na OpenIKED nwere ike iji igodo ekekọrịtaburu, EAP MSCHAPv2 nwere asambodo X.509, yana igodo ọha RSA na ECDSA.

Na ụdị ọhụrụ:

  • Ọnụgụ agbakwunyere nwere ọnụ ọgụgụ nke usoro ndabere iked, nke enwere ike ịlele site na iji iwu 'ikectl show stats'.
  • Enyerela ike izipu ụdọ asambodo n'ọtụtụ ụgwọ akwụ ụgwọ CERT.
  • Iji kwalite ndakọrịta na ụdị ochie, agbakwunyela ụgwọ ọrụ nwere NJ onye na-ere ahịa.
  • Ọchịchọ emelitere maka iwu na-eburu n'uche ihe onwunwe srcnat.
  • E hiwela ịrụ ọrụ na NAT-T na Linux.

isi: opennet.ru

Tinye a comment