ืชื•ื›ื ื™ื•ืช 1.5 ื‘-IPsec VPN ืžืงื•ืžื™. ื‘ื“ื™ืงื•ืช ื”ื“ื’ืžื•ืช

ืชื•ื›ื ื™ื•ืช 1.5 ื‘-IPsec VPN ืžืงื•ืžื™. ื‘ื“ื™ืงื•ืช ื”ื“ื’ืžื•ืช

ื”ืžืฆื‘

ืงื™ื‘ืœืชื™ ื’ืจืกืช ื”ื“ื’ืžื” ืฉืœ ืžื•ืฆืจื™ C-Terra VPN ื’ืจืกื” 4.3 ืœืžืฉืš ืฉืœื•ืฉื” ื—ื•ื“ืฉื™ื. ืื ื™ ืจื•ืฆื” ืœื‘ืจืจ ืื ื—ื™ื™ ื”ื”ื ื“ืกื” ืฉืœื™ ื™ื”ืคื›ื• ืœืงืœื™ื ื™ื•ืชืจ ืœืื—ืจ ื”ืžืขื‘ืจ ืœื’ืจืกื” ื”ื—ื“ืฉื”.

ื”ื™ื•ื ื–ื” ืœื ืงืฉื”, ืฉืงื™ืช ืื—ืช ืฉืœ ืงืคื” ื ืžืก 3 ื‘-1 ืืžื•ืจื” ืœื”ืกืคื™ืง. ืื ื™ ืื’ื™ื“ ืœืš ืื™ืš ืœื”ืฉื™ื’ ื”ื“ื’ืžื•ืช. ืื ื™ ืื ืกื” ืœื‘ื ื•ืช ืืช ืกื›ื™ืžื•ืช GRE-over-IPsec ื•-IPsec-over-GRE.

ืื™ืš ืœื”ืฉื™ื’ ื”ื“ื’ืžื”

ืชื•ื›ื ื™ื•ืช 1.5 ื‘-IPsec VPN ืžืงื•ืžื™. ื‘ื“ื™ืงื•ืช ื”ื“ื’ืžื•ืช

ืžื”ืื™ื•ืจ ืขื•ืœื” ืฉื›ื“ื™ ืœืงื‘ืœ ื”ื“ื’ืžื” ืืชื” ืฆืจื™ืš:

  • ื›ืชื•ื‘ ืžื›ืชื‘ ืœ [ืžื•ื’ืŸ ื‘ื“ื•ื"ืœ] ืžื›ืชื•ื‘ืช ืืจื’ื•ื ื™ืช;
  • ื‘ืžื›ืชื‘, ืฆื™ื™ืŸ ืืช ื”-TIN ืฉืœ ื”ืืจื’ื•ืŸ ืฉืœืš;
  • ืจืฉื•ื ืืช ื”ืžื•ืฆืจื™ื ื•ื›ืžื•ืชื.

ื”ื”ื“ื’ืžื•ืช ืชืงืคื•ืช ืœืฉืœื•ืฉื” ื—ื•ื“ืฉื™ื. ื”ืกืคืง ืื™ื ื• ืžื’ื‘ื™ืœ ืืช ื”ืคื•ื ืงืฆื™ื•ื ืœื™ื•ืช ืฉืœื”ื.

ื”ืจื—ื‘ืช ื”ืชืžื•ื ื”

ื”ื”ื“ื’ืžื” ืฉืœ ืฉืขืจ ื”ืื‘ื˜ื—ื” ื”ื™ื ืชืžื•ื ืช ืžื›ื•ื ื” ื•ื™ืจื˜ื•ืืœื™ืช. ืื ื™ ืžืฉืชืžืฉ ื‘-VMWare Workstation. ืจืฉื™ืžื” ืžืœืื” ืฉืœ ื”ื™ืคืจื•ื•ื™ื–ื•ืจื™ื ื•ืกื‘ื™ื‘ื•ืช ื•ื™ืจื˜ื•ืืœื™ื–ืฆื™ื” ื ืชืžื›ื•ืช ื–ืžื™ื ื” ื‘ืืชืจ ื”ืื™ื ื˜ืจื ื˜ ืฉืœ ื”ืกืคืง.

ืœืคื ื™ ืฉืชืชื—ื™ืœ, ืฉื™ื ืœื‘ ืฉืื™ืŸ ืžืžืฉืงื™ ืจืฉืช ื‘ืชืžื•ื ืช ื‘ืจื™ืจืช ื”ืžื—ื“ืœ ืฉืœ ื”ืžื—ืฉื‘ ื”ื•ื•ื™ืจื˜ื•ืืœื™:

ืชื•ื›ื ื™ื•ืช 1.5 ื‘-IPsec VPN ืžืงื•ืžื™. ื‘ื“ื™ืงื•ืช ื”ื“ื’ืžื•ืช

ื”ื”ื™ื’ื™ื•ืŸ ื‘ืจื•ืจ, ื”ืžืฉืชืžืฉ ืฆืจื™ืš ืœื”ื•ืกื™ืฃ ื›ืžื” ืžืžืฉืงื™ื ืฉื”ื•ื ืฆืจื™ืš. ืื ื™ ืื•ืกื™ืฃ ืืจื‘ืขื” ื‘ื‘ืช ืื—ืช:

ืชื•ื›ื ื™ื•ืช 1.5 ื‘-IPsec VPN ืžืงื•ืžื™. ื‘ื“ื™ืงื•ืช ื”ื“ื’ืžื•ืช

ืขื›ืฉื™ื• ืื ื™ ืžืคืขื™ืœ ืืช ื”ืžื›ื•ื ื” ื”ื•ื™ืจื˜ื•ืืœื™ืช. ืžื™ื“ ืœืื—ืจ ื”ื”ืฉืงื”, ื”ืฉืขืจ ื“ื•ืจืฉ ืฉื ืžืฉืชืžืฉ ื•ืกื™ืกืžื”.

ื™ืฉื ืŸ ืžืกืคืจ ืงื•ื ืกื•ืœื•ืช ื‘-S-Terra Gateway ืขื ื—ืฉื‘ื•ื ื•ืช ืฉื•ื ื™ื. ืื ื™ ืืกืคื•ืจ ืืช ืžืกืคืจื ื‘ืžืืžืจ ื ืคืจื“. ืœืขืช ืขืชื”:
Login as: administrator
Password: s-terra

ืื ื™ ืžืืชื—ืœ ืืช ื”ืฉืขืจ. ื”ืืชื—ื•ืœ ื”ื•ื ืจืฆืฃ ืฉืœ ืคืขื•ืœื•ืช: ื”ื–ื ืช ืจื™ืฉื™ื•ืŸ, ื”ืงืžืช ืžื—ื•ืœืœ ืžืกืคืจื™ื ืืงืจืื™ื™ื ื‘ื™ื•ืœื•ื’ื™ื™ื (ืกื™ืžื•ืœื˜ื•ืจ ืžืงืœื“ืช - ื”ืฉื™ื ืฉืœื™ ื”ื•ื 27 ืฉื ื™ื•ืช) ื•ื™ืฆื™ืจืช ืžืคืช ืžืžืฉืง ืจืฉืช.

ืžืคื” ืฉืœ ืžืžืฉืงื™ ืจืฉืช. ื–ื” ื ืขืฉื” ืงืœ ื™ื•ืชืจ

ื’ืจืกื” 4.2 ืงื™ื‘ืœื” ืืช ืคื ื™ ื”ืžืฉืชืžืฉ ื”ืคืขื™ืœ ื‘ื”ื•ื“ืขื•ืช:

Starting IPsec daemonโ€ฆ.. failed
ERROR: Could not establish connection with daemon

ืžืฉืชืžืฉ ืคืขื™ืœ (ืœืคื™ ืžื”ื ื“ืก ืื ื•ื ื™ืžื™) ื”ื•ื ืžืฉืชืžืฉ ืฉื™ื›ื•ืœ ืœื”ื’ื“ื™ืจ ื›ืœ ื“ื‘ืจ ื‘ืžื”ื™ืจื•ืช ื•ืœืœื ืชื™ืขื•ื“.

ืžืฉื”ื• ื”ืฉืชื‘ืฉ ืœืคื ื™ ืฉื ื™ืกื™ืช ืœื”ื’ื“ื™ืจ ื›ืชื•ื‘ืช IP ื‘ืžืžืฉืง. ื”ื›ืœ ืงืฉื•ืจ ืœืžืคืช ืžืžืฉืง ื”ืจืฉืช. ื”ื™ื” ืฆื•ืจืš ืœืขืฉื•ืช:

/bin/netifcfg enum > /home/map
/bin/netifcfg map /home/map
service networking restart

ื›ืชื•ืฆืื” ืžื›ืš, ื ื•ืฆืจืช ืžืคืช ืžืžืฉืง ืจืฉืช ื”ืžื›ื™ืœื” ืืช ื”ืžื™ืคื•ื™ ืฉืœ ืฉืžื•ืช ืžืžืฉืงื™ื ืคื™ื–ื™ื™ื (0000:02:03.0) ื•ื”ื™ื™ืขื•ื“ื™ื ื”ืœื•ื’ื™ื™ื ืฉืœื”ื ื‘ืžืขืจื›ืช ื”ื”ืคืขืœื” (eth0) ื•ื‘ืงื•ื ืกื•ืœื” ื“ืžื•ื™ืช ืกื™ืกืงื• (FastEthernet0/0):

#Unique ID iface type OS name Cisco-like name

0000:02:03.0 phye eth0 FastEthernet0/0

ื”ื™ื™ืขื•ื“ื™ื ื”ืœื•ื’ื™ื™ื ืฉืœ ืžืžืฉืงื™ื ื ืงืจืื™ื ื›ื™ื ื•ื™ื™ื. ื›ื™ื ื•ื™ื™ื ืžืื•ื—ืกื ื™ื ื‘ืงื•ื‘ืฅ /etc/ifaliases.cf.
ื‘ื’ืจืกื” 4.3, ื›ืืฉืจ ื”ืžื—ืฉื‘ ื”ื•ื™ืจื˜ื•ืืœื™ ืžื•ืคืขืœ ืœืจืืฉื•ื ื”, ื ื•ืฆืจืช ืื•ื˜ื•ืžื˜ื™ืช ืžืคืช ืžืžืฉืง. ืื ืชืฉื ื” ืืช ืžืกืคืจ ืžืžืฉืงื™ ื”ืจืฉืช ื‘ืžื›ื•ื ื” ื”ื•ื™ืจื˜ื•ืืœื™ืช, ืื ื ืฆื•ืจ ืžื—ื“ืฉ ืืช ืžืคืช ื”ืžืžืฉืง:

/bin/netifcfg enum > /home/map
/bin/netifcfg map /home/map
systemctl restart networking

ืชื›ื ื™ืช 1: GRE-over-IPsec

ืื ื™ ืคื•ืจืก ืฉื ื™ ืฉืขืจื™ื ื•ื™ืจื˜ื•ืืœื™ื™ื, ืื ื™ ืžื—ืœื™ืฃ ื›ืคื™ ืฉืžื•ืฆื’ ื‘ืื™ื•ืจ:

ืชื•ื›ื ื™ื•ืช 1.5 ื‘-IPsec VPN ืžืงื•ืžื™. ื‘ื“ื™ืงื•ืช ื”ื“ื’ืžื•ืช

ืฉืœื‘ 1. ื”ื’ื“ืจ ื›ืชื•ื‘ื•ืช IP ื•ืžืกืœื•ืœื™ื

VG1(config) #
interface fa0/0
ip address 172.16.1.253 255.255.255.0
no shutdown
interface fa0/1
ip address 192.168.1.253 255.255.255.0
no shutdown
ip route 0.0.0.0 0.0.0.0 172.16.1.254

VG2(config) #
interface fa0/0
ip address 172.16.1.254 255.255.255.0
no shutdown
interface fa0/1
ip address 192.168.2.254 255.255.255.0
no shutdown
ip route 0.0.0.0 0.0.0.0 172.16.1.253

ื‘ื“ื™ืงืช ืงื™ืฉื•ืจื™ื•ืช IP:

root@VG1:~# ping 172.16.1.254 -c 4
PING 172.16.1.254 (172.16.1.254) 56(84) bytes of data.
64 bytes from 172.16.1.254: icmp_seq=1 ttl=64 time=0.545 ms
64 bytes from 172.16.1.254: icmp_seq=2 ttl=64 time=0.657 ms
64 bytes from 172.16.1.254: icmp_seq=3 ttl=64 time=0.687 ms
64 bytes from 172.16.1.254: icmp_seq=4 ttl=64 time=0.273 ms

--- 172.16.1.254 ping statistics ---
4 packets transmitted, 4 received, 0% packet loss, time 3005ms
rtt min/avg/max/mdev = 0.273/0.540/0.687/0.164 ms

ืฉืœื‘ 2: ื”ื’ื“ืจ ืืช GRE

ืื ื™ ืœื•ืงื— ื“ื•ื’ืžื” ืฉืœ ื”ื’ื“ืจืช GRE ืžืชืกืจื™ื˜ื™ื ืจืฉืžื™ื™ื. ืื ื™ ื™ื•ืฆืจ ืงื•ื‘ืฅ gre1 ื‘ืกืคืจื™ื™ื” /etc/network/interfaces.d ืขื ื”ืชื•ื›ืŸ.

ืขื‘ื•ืจ VG1:

auto gre1
iface gre1 inet static
address 1.1.1.1
netmask 255.255.255.252
pre-up ip tunnel add gre1 mode gre remote 172.16.1.254 local 172.16.1.253 key 1 ttl 64 tos inherit
pre-up ethtool -K gre1 tx off > /dev/null
pre-up ip link set gre1 mtu 1400
post-down ip link del gre1

ืขื‘ื•ืจ VG2:

auto gre1
iface gre1 inet static
address 1.1.1.2
netmask 255.255.255.252
pre-up ip tunnel add gre1 mode gre remote 172.16.1.253 local 172.16.1.254 key 1 ttl 64 tos inherit
pre-up ethtool -K gre1 tx off > /dev/null
pre-up ip link set gre1 mtu 1400
post-down ip link del gre1

ืื ื™ ืžืขืœื” ืืช ื”ืžืžืฉืง ื‘ืžืขืจื›ืช:

root@VG1:~# ifup gre1
root@VG2:~# ifup gre1

ื‘ื•ื“ืง:

root@VG1:~# ip address show
8: gre1@NONE: <POINTOPOINT,NOARP,UP,LOWER_UP> mtu 1400 qdisc noqueue state UNKNOWN group default qlen 1
    link/gre 172.16.1.253 peer 172.16.1.254
    inet 1.1.1.1/30 brd 1.1.1.3 scope global gre1
       valid_lft forever preferred_lft forever

root@VG1:~# ip tunnel show
gre0: gre/ip remote any local any ttl inherit nopmtudisc
gre1: gre/ip remote 172.16.1.254 local 172.16.1.253 ttl 64 tos inherit key 1

ืœ-C-Terra Gateway ื™ืฉ ืจื—ืจื— ืžื ื•ืช ืžื•ื‘ื ื” - tcpdump. ืื ื™ ืื›ืชื•ื‘ dump ืชื ื•ืขื” ืœืงื•ื‘ืฅ pcap:

root@VG2:~# tcpdump -i eth0 -w /home/dump.pcap

ืื ื™ ืžืชื—ื™ืœ ืœืขืฉื•ืช ืคื™ื ื’ ื‘ื™ืŸ ืžืžืฉืงื™ GRE:

root@VG1:~# ping 1.1.1.2 -c 4
PING 1.1.1.2 (1.1.1.2) 56(84) bytes of data.
64 bytes from 1.1.1.2: icmp_seq=1 ttl=64 time=0.918 ms
64 bytes from 1.1.1.2: icmp_seq=2 ttl=64 time=0.850 ms
64 bytes from 1.1.1.2: icmp_seq=3 ttl=64 time=0.918 ms
64 bytes from 1.1.1.2: icmp_seq=4 ttl=64 time=0.974 ms

--- 1.1.1.2 ping statistics ---
4 packets transmitted, 4 received, 0% packet loss, time 3006ms
rtt min/avg/max/mdev = 0.850/0.915/0.974/0.043 ms

ืžื ื”ืจืช GRE ืคื•ืขืœืช:

ืชื•ื›ื ื™ื•ืช 1.5 ื‘-IPsec VPN ืžืงื•ืžื™. ื‘ื“ื™ืงื•ืช ื”ื“ื’ืžื•ืช

ืฉืœื‘ 3. ื”ืฆืคื™ืŸ ืขื GOST GRE

ืื ื™ ืงื•ื‘ืข ืืช ืกื•ื’ ื”ื–ื™ื”ื•ื™ - ืœืคื™ ื›ืชื•ื‘ืช. ืื™ืžื•ืช ืขื ืžืคืชื— ืžื•ื’ื“ืจ ืžืจืืฉ (ืขืœ ืคื™ ืชื ืื™ ื”ืฉื™ืžื•ืฉ, ื™ืฉ ืœื”ืฉืชืžืฉ ื‘ืชืขื•ื“ื•ืช ื“ื™ื’ื™ื˜ืœื™ื•ืช):

VG1(config)#
crypto isakmp identity address
crypto isakmp key KEY address 172.16.1.254

ื”ื’ื“ืจืชื™ ืืช ื”ืคืจืžื˜ืจื™ื ืฉืœ IPsec Phase I:

VG1(config)#
crypto isakmp policy 1
encr gost
hash gost3411-256-tc26
auth pre-share
group vko2

ื”ื’ื“ืจืชื™ ืืช ื”ืคืจืžื˜ืจื™ื ืฉืœ IPsec Phase II:

VG1(config)#
crypto ipsec transform-set TSET esp-gost28147-4m-imit
mode tunnel

ืื ื™ ื™ื•ืฆืจ ืจืฉื™ืžืช ื’ื™ืฉื” ืœื”ืฆืคื ื”. ืชื ื•ืขื” ืžืžื•ืงื“ืช - GRE:

VG1(config)#
ip access-list extended LIST
permit gre host 172.16.1.253 host 172.16.1.254

ืื ื™ ื™ื•ืฆืจ ืžืคืช ืงืจื™ืคื˜ื• ื•ืžืงืฉืจ ืื•ืชื” ืœืžืžืฉืง ื”-WAN:

VG1(config)#
crypto map CMAP 1 ipsec-isakmp
match address LIST
set transform-set TSET
set peer 172.16.1.253
interface fa0/0
  crypto map CMAP

ืขื‘ื•ืจ VG2, ื”ืชืฆื•ืจื” ื”ื™ื ืฉื™ืงื•ืฃ, ื”ื”ื‘ื“ืœื™ื ื”ื:

VG2(config)#
crypto isakmp key KEY address 172.16.1.253
ip access-list extended LIST
permit gre host 172.16.1.254 host 172.16.1.253
crypto map CMAP 1 ipsec-isakmp
set peer 172.16.1.254

ื‘ื•ื“ืง:

root@VG2:~# tcpdump -i eth0 -w /home/dump2.pcap
root@VG1:~# ping 1.1.1.2 -c 4
PING 1.1.1.2 (1.1.1.2) 56(84) bytes of data.
64 bytes from 1.1.1.2: icmp_seq=1 ttl=64 time=1128 ms
64 bytes from 1.1.1.2: icmp_seq=2 ttl=64 time=126 ms
64 bytes from 1.1.1.2: icmp_seq=3 ttl=64 time=1.07 ms
64 bytes from 1.1.1.2: icmp_seq=4 ttl=64 time=1.12 ms

--- 1.1.1.2 ping statistics ---
4 packets transmitted, 4 received, 0% packet loss, time 3006ms
rtt min/avg/max/mdev = 1.077/314.271/1128.419/472.826 ms, pipe 2

ืกื˜ื˜ื™ืกื˜ื™ืงื•ืช ISAKMP/IPsec:

root@VG1:~# sa_mgr show
ISAKMP sessions: 0 initiated, 0 responded

ISAKMP connections:
Num Conn-id (Local Addr,Port)-(Remote Addr,Port) State Sent Rcvd
1 1 (172.16.1.253,500)-(172.16.1.254,500) active 1086 1014

IPsec connections:
Num Conn-id (Local Addr,Port)-(Remote Addr,Port) Protocol Action Type Sent Rcvd
1 1 (172.16.1.253,*)-(172.16.1.254,*) 47 ESP tunn 480 480

ืื™ืŸ ืžื ื•ืช ื‘ืžื–ื‘ืœื” ืฉืœ ื”ืชืขื‘ื•ืจื” ืฉืœ GRE:

ืชื•ื›ื ื™ื•ืช 1.5 ื‘-IPsec VPN ืžืงื•ืžื™. ื‘ื“ื™ืงื•ืช ื”ื“ื’ืžื•ืช

ืžืกืงื ื”: ืขืจื›ืช GRE-over-IPsec ืคื•ืขืœืช ื›ื”ืœื›ื”.

ืื™ื•ืจ 1.5: IPsec-over-GRE

ืื ื™ ืœื ืžืชื›ื ืŸ ืœื”ืฉืชืžืฉ ื‘-IPsec-over-GRE ื‘ืจืฉืช. ืื ื™ ืื•ืกืฃ ื›ื™ ืื ื™ ืจื•ืฆื”.

ืชื•ื›ื ื™ื•ืช 1.5 ื‘-IPsec VPN ืžืงื•ืžื™. ื‘ื“ื™ืงื•ืช ื”ื“ื’ืžื•ืช

ื›ื“ื™ ืœืคืจื•ืก ืืช ืขืจื›ืช GRE-over-IPsec ืœื”ื™ืคืš:

  • ืชืงืŸ ืจืฉื™ืžืช ื’ื™ืฉื” ืœื”ืฆืคื ื” - ืชืขื‘ื•ืจื” ืžืžื•ืงื“ืช ืž-LAN1 ืœ-LAN2 ื•ืœื”ื™ืคืš;
  • ื”ื’ื“ืจ ื ื™ืชื•ื‘ ื“ืจืš GRE;
  • ืชืœื” ืžืคืช ืงืจื™ืคื˜ื• ื‘ืžืžืฉืง GRE.

ื›ื‘ืจื™ืจืช ืžื—ื“ืœ, ืื™ืŸ ืžืžืฉืง GRE ื‘ืงื•ื ืกื•ืœืช ื”ืฉืขืจ ื“ืžื•ื™ Cisco. ื–ื” ืงื™ื™ื ืจืง ื‘ืžืขืจื›ืช ื”ื”ืคืขืœื”.

ืื ื™ ืžื•ืกื™ืฃ ืืช ืžืžืฉืง GRE ืœืงื•ื ืกื•ืœื” ื“ืžื•ื™ื™ืช ืกื™ืกืงื•. ื›ื“ื™ ืœืขืฉื•ืช ื–ืืช, ืื ื™ ืขื•ืจืš ืืช ื”ืงื•ื‘ืฅ /etc/ifaliases.cf:

interface (name="FastEthernet0/0" pattern="eth0")
interface (name="FastEthernet0/1" pattern="eth1")
interface (name="FastEthernet0/2" pattern="eth2")
interface (name="FastEthernet0/3" pattern="eth3")
interface (name="Tunnel0" pattern="gre1")
interface (name="default" pattern="*")

ื›ืืฉืจ gre1 ื”ื•ื ื™ื™ืขื•ื“ ื”ืžืžืฉืง ื‘ืžืขืจื›ืช ื”ื”ืคืขืœื”, Tunnel0 ื”ื•ื ื™ื™ืขื•ื“ ื”ืžืžืฉืง ื‘ืงื•ื ืกื•ืœื” ื“ืžื•ื™ื™ืช ืกื™ืกืงื•.

ืื ื™ ืžื—ืฉื‘ ืžื—ื“ืฉ ืืช ื”-hash ืฉืœ ื”ืงื•ื‘ืฅ:

root@VG1:~# integr_mgr calc -f /etc/ifaliases.cf

SUCCESS:  Operation was successful.

ื›ืขืช ื”ืžืžืฉืง Tunnel0 ื”ื•ืคื™ืข ื‘ืงื•ื ืกื•ืœื” ื“ืžื•ื™ื™ืช ืกื™ืกืงื•:

VG1# show run
interface Tunnel0
ip address 1.1.1.1 255.255.255.252
mtu 1400

ืชื™ืงื•ืŸ ืจืฉื™ืžืช ื”ื’ื™ืฉื” ืœื”ืฆืคื ื”:

VG1(config)#
ip access-list extended LIST
permit ip 192.168.1.0 0.0.0.255 192.168.3.0 0.0.0.255

ืื ื™ ืžื’ื“ื™ืจ ื ื™ืชื•ื‘ ื“ืจืš GRE:

VG1(config)#
no ip route 0.0.0.0 0.0.0.0 172.16.1.254
ip route 192.168.3.0 255.255.255.0 1.1.1.2

ืื ื™ ืžืกื™ืจ ืืช ื”-cryptomap ืž-Fa0 / 0 ื•ืžืงืฉืจ ืื•ืชื• ืœืžืžืฉืง GRE:

VG1(config)#
interface Tunnel0
crypto map CMAP

ืขื‘ื•ืจ VG2 ื–ื” ื“ื•ืžื”.

ื‘ื•ื“ืง:

root@VG2:~# tcpdump -i eth0 -w /home/dump3.pcap

root@VG1:~# ping 192.168.2.254 -I 192.168.1.253 -c 4
PING 192.168.2.254 (192.168.2.254) from 192.168.1.253 : 56(84) bytes of data.
64 bytes from 192.168.2.254: icmp_seq=1 ttl=64 time=492 ms
64 bytes from 192.168.2.254: icmp_seq=2 ttl=64 time=1.08 ms
64 bytes from 192.168.2.254: icmp_seq=3 ttl=64 time=1.06 ms
64 bytes from 192.168.2.254: icmp_seq=4 ttl=64 time=1.07 ms

--- 192.168.2.254 ping statistics ---
4 packets transmitted, 4 received, 0% packet loss, time 3006ms
rtt min/avg/max/mdev = 1.064/124.048/492.972/212.998 ms

ืกื˜ื˜ื™ืกื˜ื™ืงื•ืช ISAKMP/IPsec:

root@VG1:~# sa_mgr show
ISAKMP sessions: 0 initiated, 0 responded

ISAKMP connections:
Num Conn-id (Local Addr,Port)-(Remote Addr,Port) State Sent Rcvd
1 2 (172.16.1.253,500)-(172.16.1.254,500) active 1094 1022

IPsec connections:
Num Conn-id (Local Addr,Port)-(Remote Addr,Port) Protocol Action Type Sent Rcvd
1 2 (192.168.1.0-192.168.1.255,*)-(192.168.2.0-192.168.2.255,*) * ESP tunn 352 352

ื‘ืžื–ื‘ืœื” ืฉืœ ืชืขื‘ื•ืจืช ESP, ื”ื—ื‘ื™ืœื•ืช ืžื•ื‘ืœืขื•ืช ื‘-GRE:

ืชื•ื›ื ื™ื•ืช 1.5 ื‘-IPsec VPN ืžืงื•ืžื™. ื‘ื“ื™ืงื•ืช ื”ื“ื’ืžื•ืช

ืžืกืงื ื”: IPsec-over-GRE ืคื•ืขืœ ื›ื”ืœื›ื”.

ืชื•ืฆืื•ืช ืฉืœ

ื›ื•ืก ืงืคื” ืื—ืช ื”ืกืคื™ืงื”. ืฉืจื˜ื˜ืชื™ ื”ื•ืจืื•ืช ืœื”ืฉื’ืช ื’ืจืกืช ื”ื“ื’ืžื”. ื”ื•ื’ื“ืจ GRE-over-IPsec ื•ืคืจื™ืกื” ืœื”ื™ืคืš.

ืžืคืช ืžืžืฉืงื™ ื”ืจืฉืช ื‘ื’ืจืกื” 4.3 ื”ื™ื ืื•ื˜ื•ืžื˜ื™ืช! ืื ื™ ื‘ื•ื“ืง ืขื•ื“.

ืžื”ื ื“ืก ืื ื•ื ื™ืžื™
t.me/anonymous_engineer


ืžืงื•ืจ: www.habr.com

ื”ื•ืกืคืช ืชื’ื•ื‘ื”