ืื™ืš ืžื’ื™ืขื™ื ืœ-Beeline IPVPN ื“ืจืš IPSec. ื—ืœืง 1

ืฉืœื•ื! IN ืคื•ืกื˜ ืงื•ื“ื ืชื™ืืจืชื™ ืืช ื”ืขื‘ื•ื“ื” ืฉืœ ืฉื™ืจื•ืช ื”-MultiSIM ืฉืœื ื• ื‘ื—ืœืงื• ื”ืกืชื™ื™ื’ื•ื™ื•ืช ะธ ืžึฐืึทื–ึตืŸ ืขืจื•ืฆื™ื. ื›ืืžื•ืจ, ืื ื• ืžื—ื‘ืจื™ื ืœืงื•ื—ื•ืช ืœืจืฉืช ื‘ืืžืฆืขื•ืช VPN, ื•ื”ื™ื•ื ืืกืคืจ ืœื›ื ืงืฆืช ื™ื•ืชืจ ืขืœ VPN ื•ื”ื™ื›ื•ืœื•ืช ืฉืœื ื• ื‘ื—ืœืง ื–ื”.

ื›ื“ืื™ ืœื”ืชื—ื™ืœ ื‘ืขื•ื‘ื“ื” ืฉื™ืฉ ืœื ื•, ื›ืžืคืขื™ืœื™ ื˜ืœืงื•ื, ืจืฉืช MPLS ืขื ืงื™ืช ืžืฉืœื ื•, ืฉืขื‘ื•ืจ ืœืงื•ื—ื•ืช ืงื•ื•ื™ื™ื ืžื—ื•ืœืงืช ืœืฉื ื™ ืกื’ืžื ื˜ื™ื ืขื™ืงืจื™ื™ื - ื–ื” ืฉืžืฉืžืฉ ื™ืฉื™ืจื•ืช ืœื’ื™ืฉื” ืœืื™ื ื˜ืจื ื˜, ื•ื–ื” ืฉื”ื•ื ืžืฉืžืฉ ืœื™ืฆื™ืจืช ืจืฉืชื•ืช ืžื‘ื•ื“ื“ื•ืช - ื•ื‘ืืžืฆืขื•ืช ืžืงื˜ืข MPLS ื–ื” ืขื•ื‘ืจืช ืชืขื‘ื•ืจืช IPVPN (L3 OSI) ื•- VPLAN (L2 OSI) ืขื‘ื•ืจ ื”ืœืงื•ื—ื•ืช ื”ืืจื’ื•ื ื™ื™ื ืฉืœื ื•.

ืื™ืš ืžื’ื™ืขื™ื ืœ-Beeline IPVPN ื“ืจืš IPSec. ื—ืœืง 1
ื‘ื“ืจืš ื›ืœืœ, ื—ื™ื‘ื•ืจ ืœืงื•ื— ืžืชืจื—ืฉ ื‘ืื•ืคืŸ ื”ื‘ื.

ืงื• ื’ื™ืฉื” ืžื•ื ื— ืœืžืฉืจื“ ื”ืœืงื•ื— ืžื ืงื•ื“ืช ื”ื ื•ื›ื—ื•ืช ื”ืงืจื•ื‘ื” ื‘ื™ื•ืชืจ ืฉืœ ื”ืจืฉืช (ืฆื•ืžืช MEN, RRL, BSSS, FTTB ื•ื›ื•') ื•ื‘ื”ืžืฉืš, ื”ืขืจื•ืฅ ื ืจืฉื ื“ืจืš ืจืฉืช ื”ืชื—ื‘ื•ืจื” ืœ-PE-MPLS ื”ืžืงื‘ื™ืœ ื ืชื‘, ืขืœื™ื• ืื ื• ืžืคืœื˜ ืื•ืชื• ืœืœืงื•ื— ืฉื ื•ืฆืจ ื‘ืžื™ื•ื—ื“ ืขื‘ื•ืจ ืœืงื•ื— VRF, ืชื•ืš ื”ืชื—ืฉื‘ื•ืช ื‘ืคืจื•ืคื™ืœ ื”ืชืขื‘ื•ืจื” ืฉื”ืœืงื•ื— ืฆืจื™ืš (ืชื•ื•ื™ื•ืช ืคืจื•ืคื™ืœ ื ื‘ื—ืจื•ืช ืขื‘ื•ืจ ื›ืœ ื™ืฆื™ืืช ื’ื™ืฉื”, ื‘ื”ืชื‘ืกืก ืขืœ ืขืจื›ื™ ืงื“ื™ืžื•ืช ip 0,1,3,5, XNUMX).

ืื ืžืกื™ื‘ื” ื›ืœืฉื”ื™ ืื™ื ื ื• ื™ื›ื•ืœื™ื ืœืืจื’ืŸ ื‘ืื•ืคืŸ ืžืœื ืืช ื”ืžื™ื™ืœ ื”ืื—ืจื•ืŸ ืขื‘ื•ืจ ื”ืœืงื•ื—, ืœืžืฉืœ, ืžืฉืจื“ื• ืฉืœ ื”ืœืงื•ื— ืžืžื•ืงื ื‘ืžืจื›ื– ืขืกืงื™ื, ืฉื‘ื• ืกืคืง ืื—ืจ ื ืžืฆื ื‘ืจืืฉ ืกื“ืจ ื”ืขื“ื™ืคื•ื™ื•ืช, ืื• ืฉืคืฉื•ื˜ ืื™ืŸ ืœื ื• ืืช ื ืงื•ื“ืช ื”ื ื•ื›ื—ื•ืช ืฉืœื ื• ื‘ืงืจื‘ืช ืžืงื•ื, ืื– ื‘ืขื‘ืจ ืœืงื•ื—ื•ืช ื”ื™ื” ืฆืจื™ืš ืœื™ืฆื•ืจ ืžืกืคืจ ืจืฉืชื•ืช IPVPN ืืฆืœ ืกืคืงื™ื ืฉื•ื ื™ื (ืœื ื”ืืจื›ื™ื˜ืงื˜ื•ืจื” ื”ืžืฉืชืœืžืช ื‘ื™ื•ืชืจ) ืื• ืœืคืชื•ืจ ื‘ืื•ืคืŸ ืขืฆืžืื™ ื‘ืขื™ื•ืช ืขื ืืจื’ื•ืŸ ื”ื’ื™ืฉื” ืœ-VRF ืฉืœืš ื“ืจืš ื”ืื™ื ื˜ืจื ื˜.

ืจื‘ื™ื ืขืฉื• ื–ืืช ืขืœ ื™ื“ื™ ื”ืชืงื ืช ืฉืขืจ ืื™ื ื˜ืจื ื˜ IPVPN - ื”ื ื”ืชืงื™ื ื• ื ืชื‘ ื’ื‘ื•ืœ (ื—ื•ืžืจื” ืื• ืคืชืจื•ืŸ ืžื‘ื•ืกืก ืœื™ื ื•ืงืก ื›ืœืฉื”ื•), ื—ื™ื‘ืจื• ืืœื™ื• ืขืจื•ืฅ IPVPN ืขื ื™ืฆื™ืื” ืื—ืช ื•ืขืจื•ืฅ ืื™ื ื˜ืจื ื˜ ืขื ื”ืฉื ื™, ื”ืฉื™ืงื• ื‘ื• ืืช ืฉืจืช ื”-VPN ืฉืœื”ื ื•ื”ืชื—ื‘ืจื•. ืžืฉืชืžืฉื™ื ื“ืจืš ืฉืขืจ VPN ืžืฉืœื”ื. ืžื˜ื‘ืข ื”ื“ื‘ืจื™ื, ืชื›ื ื™ืช ื›ื–ื• ื’ื ื™ื•ืฆืจืช ืขื•ืžืกื™ื: ื™ืฉ ืœื‘ื ื•ืช ืชืฉืชื™ืช ื›ื–ื•, ื•ื‘ืื•ืคืŸ ืœื ื ื•ื— ื‘ื™ื•ืชืจ, ืœืชืคืขืœ ื•ืœืคืชื—.

ื›ื“ื™ ืœื”ืงืœ ืขืœ ื”ืœืงื•ื—ื•ืช ืฉืœื ื•, ื”ืชืงื ื• ืจื›ื–ืช VPN ืžืจื›ื–ื™ืช ื•ืืจื’ื ื• ืชืžื™ื›ื” ื‘ื—ื™ื‘ื•ืจื™ื ื“ืจืš ื”ืื™ื ื˜ืจื ื˜ ื‘ืืžืฆืขื•ืช IPSec, ื›ืœื•ืžืจ, ื›ืขืช ืœืงื•ื—ื•ืช ืฆืจื™ื›ื™ื ืจืง ืœื”ื’ื“ื™ืจ ืืช ื”ื ืชื‘ ืฉืœื”ื ื›ืš ืฉื™ืขื‘ื•ื“ ืขื ืจื›ื–ืช ื”-VPN ืฉืœื ื• ื“ืจืš ืžื ื”ืจืช IPSec ื‘ื›ืœ ืื™ื ื˜ืจื ื˜ ืฆื™ื‘ื•ืจื™. , ื•ื‘ื•ืื• ื ืฉื—ืจืจ ืืช ื”ืชืขื‘ื•ืจื” ืฉืœ ื”ืœืงื•ื— ื”ื–ื” ืœ-VRF ืฉืœื•.

ืžื™ ื™ืฆื˜ืจืš

  • ืœืžื™ ืฉื›ื‘ืจ ื™ืฉ ืœื• ืจืฉืช IPVPN ื’ื“ื•ืœื” ื•ืฆืจื™ืš ื—ื™ื‘ื•ืจื™ื ื—ื“ืฉื™ื ืชื•ืš ื–ืžืŸ ืงืฆืจ.
  • ื›ืœ ืžื™ ืฉืจื•ืฆื” ืžืกื™ื‘ื” ื›ืœืฉื”ื™ ืœื”ืขื‘ื™ืจ ื—ืœืง ืžื”ืชืขื‘ื•ืจื” ืžื”ืื™ื ื˜ืจื ื˜ ื”ืฆื™ื‘ื•ืจื™ ืœ-IPVPN, ืืš ื ืชืงืœ ื‘ืขื‘ืจ ื‘ืžื’ื‘ืœื•ืช ื˜ื›ื ื™ื•ืช ื”ืงืฉื•ืจื•ืช ืœืžืกืคืจ ืกืคืงื™ ืฉื™ืจื•ืช.
  • ืœืžื™ ืฉื™ืฉ ืœื”ื ื›ืจื’ืข ื›ืžื” ืจืฉืชื•ืช VPN ืฉื•ื ื•ืช ื‘ื™ืŸ ืžืคืขื™ืœื™ ื˜ืœืงื•ื ืฉื•ื ื™ื. ื™ืฉื ื ืœืงื•ื—ื•ืช ืฉืืจื’ื ื• ื‘ื”ืฆืœื—ื” IPVPN ืž-Beeline, Megafon, Rostelecom ื•ื›ื•'. ื›ื“ื™ ืœื”ืงืœ, ืืชื” ื™ื›ื•ืœ ืœื”ื™ืฉืืจ ืจืง ื‘-VPN ื”ื‘ื•ื“ื“ ืฉืœื ื•, ืœื”ืขื‘ื™ืจ ืืช ื›ืœ ืฉืืจ ื”ืขืจื•ืฆื™ื ืฉืœ ืžืคืขื™ืœื™ื ืื—ืจื™ื ืœืื™ื ื˜ืจื ื˜, ื•ืื– ืœื”ืชื—ื‘ืจ ืœ-Beeline IPVPN ื“ืจืš IPSec ื•ื”ืื™ื ื˜ืจื ื˜ ืžืžืคืขื™ืœื™ื ืืœื”.
  • ืœืžื™ ืฉื›ื‘ืจ ื™ืฉ ืœื• ืจืฉืช IPVPN ืขืœ ื’ื‘ื™ ื”ืื™ื ื˜ืจื ื˜.

ืื ืืชื” ืคื•ืจืก ื”ื›ืœ ืืฆืœื ื•, ื”ืœืงื•ื—ื•ืช ืžืงื‘ืœื™ื ืชืžื™ื›ืช VPN ืžืœืื”, ื™ืชื™ืจื•ืช ืจืฆื™ื ื™ืช ื‘ืชืฉืชื™ืช ื•ื”ื’ื“ืจื•ืช ืกื˜ื ื“ืจื˜ื™ื•ืช ืฉื™ืขื‘ื“ื• ืขืœ ื›ืœ ื ืชื‘ ืฉื”ื ืจื’ื™ืœื™ื ืืœื™ื• (ื‘ื™ืŸ ืื ื–ื” ืกื™ืกืงื•, ืืคื™ืœื• ืžื™ืงืจื•ื˜ื™ืง, ื”ืขื™ืงืจ ืฉื”ื•ื ื™ื›ื•ืœ ืœืชืžื•ืš ื›ืจืื•ื™ IPSec/IKEv2 ืขื ืฉื™ื˜ื•ืช ืื™ืžื•ืช ืกื˜ื ื“ืจื˜ื™ื•ืช). ืื’ื‘, ืœื’ื‘ื™ IPSec - ื›ืจื’ืข ืื ื—ื ื• ืจืง ืชื•ืžื›ื™ื ื‘ื–ื”, ืื‘ืœ ืื ื—ื ื• ืžืชื›ื ื ื™ื ืœื”ืฉื™ืง ื”ืคืขืœื” ืžืœืื” ืฉืœ OpenVPN ื•ืฉืœ Wireguard, ื›ืš ืฉืœืงื•ื—ื•ืช ืœื ื™ื•ื›ืœื• ืœืกืžื•ืš ืขืœ ื”ืคืจื•ื˜ื•ืงื•ืœ ื•ื–ื” ืืคื™ืœื• ื™ื•ืชืจ ืงืœ ืœืงื—ืช ื•ืœื”ืขื‘ื™ืจ ื”ื›ืœ ืืœื™ื ื•, ื•ืื ื—ื ื• ื’ื ืจื•ืฆื™ื ืœื”ืชื—ื™ืœ ืœื—ื‘ืจ ืœืงื•ื—ื•ืช ืžืžื—ืฉื‘ื™ื ื•ืžื›ืฉื™ืจื™ื ื ื™ื™ื“ื™ื (ืคืชืจื•ื ื•ืช ืžื•ื‘ื ื™ื ื‘ืžืขืจื›ืช ื”ื”ืคืขืœื”, Cisco AnyConnect ื•-strongSwan ื•ื›ื“ื•ืžื”). ืขื ื’ื™ืฉื” ื–ื•, ื ื™ืชืŸ ืœื”ืขื‘ื™ืจ ื‘ื‘ื˜ื—ื” ืืช ื‘ื ื™ื™ืช ื”ืชืฉืชื™ืช ื‘ืคื•ืขืœ ืœืžืคืขื™ืœ, ื•ืœื”ืฉืื™ืจ ืจืง ืืช ื”ืชืฆื•ืจื” ืฉืœ ื”-CPE ืื• ื”ืžืืจื—.

ื›ื™ืฆื“ ืขื•ื‘ื“ ืชื”ืœื™ืš ื”ื—ื™ื‘ื•ืจ ืขื‘ื•ืจ ืžืฆื‘ IPSec:

  1. ื”ืœืงื•ื— ืžืฉืื™ืจ ื‘ืงืฉื” ืœืžื ื”ืœ ืฉืœื• ื‘ื” ื”ื•ื ืžืฆื™ื™ืŸ ืืช ืžื”ื™ืจื•ืช ื”ื—ื™ื‘ื•ืจ ื”ื ื“ืจืฉืช, ืคืจื•ืคื™ืœ ื”ืชืขื‘ื•ืจื” ื•ืคืจืžื˜ืจื™ ื›ืชื•ื‘ืช ื”-IP ืขื‘ื•ืจ ื”ืžื ื”ืจื” (ื›ื‘ืจื™ืจืช ืžื—ื“ืœ, ืจืฉืช ืžืฉื ื” ืขื ืžืกื™ื›ืช /30) ื•ืืช ืกื•ื’ ื”ื ื™ืชื•ื‘ (ืกื˜ื˜ื™ ืื• BGP). ื›ื“ื™ ืœื”ืขื‘ื™ืจ ืžืกืœื•ืœื™ื ืœืจืฉืชื•ืช ื”ืžืงื•ืžื™ื•ืช ืฉืœ ื”ืœืงื•ื— ื‘ืžืฉืจื“ ื”ืžื—ื•ื‘ืจ, ื ืขืฉื” ืฉื™ืžื•ืฉ ื‘ืžื ื’ื ื•ื ื™ IKEv2 ืฉืœ ืฉืœื‘ ืคืจื•ื˜ื•ืงื•ืœ IPSec ืชื•ืš ืฉื™ืžื•ืฉ ื‘ื”ื’ื“ืจื•ืช ื”ืžืชืื™ืžื•ืช ื‘ื ืชื‘ ื”ืœืงื•ื—, ืื• ืฉื”ื ืžืคื•ืจืกืžื™ื ื‘ืืžืฆืขื•ืช BGP ื‘-MPLS ืžื”-BGP AS ื”ืคืจื˜ื™ ืฉืฆื•ื™ืŸ ื‘ืืคืœื™ืงืฆื™ื” ืฉืœ ื”ืœืงื•ื—. . ืœืคื™ื›ืš, ืžื™ื“ืข ืขืœ ื”ืžืกืœื•ืœื™ื ืฉืœ ืจืฉืชื•ืช ื”ืœืงื•ื— ื ืฉืœื˜ ืœื—ืœื•ื˜ื™ืŸ ืขืœ ื™ื“ื™ ื”ืœืงื•ื— ื‘ืืžืฆืขื•ืช ื”ื”ื’ื“ืจื•ืช ืฉืœ ื ืชื‘ ื”ืœืงื•ื—.
  2. ื‘ืชื’ื•ื‘ื” ืžื”ืžื ื”ืœ ืฉืœื•, ื”ืœืงื•ื— ืžืงื‘ืœ ื ืชื•ื ื™ื ื—ืฉื‘ื•ื ืื™ื™ื ืœื”ื›ืœืœื” ื‘-VRF ืฉืœื• ืฉืœ ื”ื˜ื•ืคืก:
    • ื›ืชื•ื‘ืช IP ืฉืœ VPN-HUB
    • ื›ื ื™ืกื”
    • ืกื™ืกืžืช ืื™ืžื•ืช
  3. ืžื’ื“ื™ืจ CPE, ืœื”ืœืŸ, ืœื“ื•ื’ืžื”, ืฉืชื™ ืืคืฉืจื•ื™ื•ืช ืชืฆื•ืจื” ื‘ืกื™ืกื™ื•ืช:

    ืืคืฉืจื•ืช ืขื‘ื•ืจ ืกื™ืกืงื•:
    ืžื—ื–ื™ืง ืžืคืชื—ื•ืช crypto ikev2 BeelineIPsec_keyring
    ืขืžื™ืช Beeline_VPNHub
    ื›ืชื•ื‘ืช 62.141.99.183 โ€“ ืจื›ื–ืช VPN Beeline
    ืžืคืชื— ืžืฉื•ืชืฃ ืžืจืืฉ <ืกื™ืกืžืช ืื™ืžื•ืช>
    !
    ืขื‘ื•ืจ ืืคืฉืจื•ืช ื”ื ื™ืชื•ื‘ ื”ืกื˜ื˜ื™, ื ื™ืชืŸ ืœืฆื™ื™ืŸ ืžืกืœื•ืœื™ื ืœืจืฉืชื•ืช ื”ื ื’ื™ืฉื•ืช ื“ืจืš ื”-Vpn-hub ื‘ืชืฆื•ืจืช IKEv2 ื•ื”ื ื™ื•ืคื™ืขื• ืื•ื˜ื•ืžื˜ื™ืช ื›ืžืกืœื•ืœื™ื ืกื˜ื˜ื™ื™ื ื‘ื˜ื‘ืœืช ื”ื ื™ืชื•ื‘ CE. ื ื™ืชืŸ ืœื‘ืฆืข ื”ื’ื“ืจื•ืช ืืœื• ื’ื ื‘ืืžืฆืขื•ืช ื”ืฉื™ื˜ื” ื”ืกื˜ื ื“ืจื˜ื™ืช ืฉืœ ื”ื’ื“ืจืช ืžืกืœื•ืœื™ื ืกื˜ื˜ื™ื™ื (ืจืื” ืœื”ืœืŸ).

    ืžื“ื™ื ื™ื•ืช ื”ืจืฉืื•ืช crypto ikev2 FlexClient-author

    ื ื™ืชื•ื‘ ืœืจืฉืชื•ืช ืžืื—ื•ืจื™ ื ืชื‘ CE โ€“ ื”ื’ื“ืจืช ื—ื•ื‘ื” ืœื ื™ืชื•ื‘ ืกื˜ื˜ื™ ื‘ื™ืŸ CE ืœ-PE. ื”ืขื‘ืจืช ื ืชื•ื ื™ ื”ืžืกืœื•ืœ ืœ-PE ืžืชื‘ืฆืขืช ื‘ืื•ืคืŸ ืื•ื˜ื•ืžื˜ื™ ื›ืืฉืจ ืžืขืœื™ื ืืช ื”ืžื ื”ืจื” ื‘ืืžืฆืขื•ืช ืื™ื ื˜ืจืืงืฆื™ื” IKEv2.

    ืขืจื›ืช ืžืกืœื•ืœ ืžืจื—ื•ืง ipv4 10.1.1.0 255.255.255.0 -ืจืฉืช ืžืงื•ืžื™ืช ืžืฉืจื“ื™ืช
    !
    ืงืจื™ืคื˜ื• ikev2 profile BeelineIPSec_profile
    ื–ื”ื•ืช ืžืงื•ืžื™ืช <login>
    ืฉื™ืชื•ืฃ ืžืงื•ืžื™ ืฉืœ ืื™ืžื•ืช ืžืงื•ืžื™
    ืฉื™ืชื•ืฃ ืžื•ืงื“ื ืฉืœ ืื™ืžื•ืช ืžืจื—ื•ืง
    ืžื—ื–ื™ืง ืžืคืชื—ื•ืช ืžืงื•ืžื™ BeelineIPsec_keyring
    aaa ืงื‘ื•ืฆืช ื”ืจืฉืื•ืช psk list group-author-list FlexClient-author
    !
    crypto ikev2 client flexvpn BeelineIPsec_flex
    peer 1 Beeline_VPNHub
    ื—ื™ื‘ื•ืจ ืœืงื•ื— Tunnel1
    !
    crypto ipsec transform-set TRANSFORM1 esp-aes 256 esp-sha256-hmac
    ืžื ื”ืจืช ืžืฆื‘
    !
    ื‘ืจื™ืจืช ื”ืžื—ื“ืœ ืฉืœ ืคืจื•ืคื™ืœ crypto ipsec
    set transform-set TRANSFORM1
    set ikev2-profile BeelineIPSec_profile
    !
    ืžืžืฉืง Tunnel1
    ื›ืชื•ื‘ืช ip 10.20.1.2 255.255.255.252 -ื›ืชื•ื‘ืช ื”ืžื ื”ืจื”
    ืžืงื•ืจ ื”ืžื ื”ืจื” GigabitEthernet0/2 -ืžืžืฉืง ื’ื™ืฉื” ืœืื™ื ื˜ืจื ื˜
    ืžืฆื‘ ืžื ื”ืจื” ipsec ipv4
    ื“ื™ื ืžื™ืงื” ืฉืœ ื™ืขื“ ื”ืžื ื”ืจื”
    ื”ื’ื ืช ืžื ื”ืจื” ื‘ืจื™ืจืช ื”ืžื—ื“ืœ ืฉืœ ืคืจื•ืคื™ืœ ipsec
    !
    ื ื™ืชืŸ ืœื”ื’ื“ื™ืจ ื‘ืื•ืคืŸ ืกื˜ื˜ื™ ืžืกืœื•ืœื™ื ืœืจืฉืชื•ืช ื”ืคืจื˜ื™ื•ืช ืฉืœ ื”ืœืงื•ื— ื”ื ื’ื™ืฉื•ืช ื“ืจืš ืจื›ื– ื”-VPN ืฉืœ Beeline.

    ืžืกืœื•ืœ ip 172.16.0.0 255.255.0.0 Tunnel1
    ืžืกืœื•ืœ ip 192.168.0.0 255.255.255.0 Tunnel1

    ืืคืฉืจื•ืช ืขื‘ื•ืจ Huawei (ar160/120):
    ike local-name <login>
    #
    ืฉื acl ipsec 3999
    ื›ืœืœ 1 ื”ื™ืชืจ ip ืžืงื•ืจ 10.1.1.0 0.0.0.255 -ืจืฉืช ืžืงื•ืžื™ืช ืžืฉืจื“ื™ืช
    #
    aaa
    ืชื•ื›ื ื™ืช ืฉื™ืจื•ืช IPSEC
    ืกื˜ ืžืกืœื•ืœ acl 3999
    #
    ื”ืฆืขืช ipsec ipsec
    esp ืื™ืžื•ืช-ืืœื’ื•ืจื™ืชื sha2-256
    ืืœื’ื•ืจื™ืชื ื”ืฆืคื ื” esp aes-256
    #
    ื‘ืจื™ืจืช ื”ืžื—ื“ืœ ืฉืœ ื”ืฆืขืช ike
    ืืœื’ื•ืจื™ืชื ื”ืฆืคื ื” aes-256
    ืงื‘ื•ืฆืช dh2
    ืืœื’ื•ืจื™ืชื ืื™ืžื•ืช sha2-256
    ืฉื™ืชื•ืฃ ืžืจืืฉ ื‘ืฉื™ื˜ืช ืื™ืžื•ืช
    ืฉืœืžื•ืช-ืืœื’ื•ืจื™ืชื hmac-sha2-256
    prf hmac-sha2-256
    #
    ike peer ipsec
    ืžืคืชื— ืžืฉื•ืชืฃ ืžืจืืฉ ืคืฉื•ื˜ <ืกื™ืกืžืช ืื™ืžื•ืช>
    fqdn ืžืกื•ื’ local-ID
    ip-ืžื–ื”ื” ืžืจื—ื•ืง
    ื›ืชื•ื‘ืช ืžืจื—ื•ืง 62.141.99.183 โ€“ ืจื›ื–ืช VPN Beeline
    ืชื•ื›ื ื™ืช ืฉื™ืจื•ืช IPSEC
    ื‘ืงืฉื” ืœ-config-exchange
    config-exchange set accept
    config-exchange set send
    #
    ืคืจื•ืคื™ืœ ipsec ipsecprof
    ike-peer ipsec
    ื”ืฆืขื” ipsec
    #
    ืžืžืฉืง Tunnel0/0/0
    ื›ืชื•ื‘ืช ip 10.20.1.2 255.255.255.252 -ื›ืชื•ื‘ืช ื”ืžื ื”ืจื”
    ืคืจื•ื˜ื•ืงื•ืœ ืžื ื”ืจื” ipsec
    ืžืงื•ืจ GigabitEthernet0/0/1 -ืžืžืฉืง ื’ื™ืฉื” ืœืื™ื ื˜ืจื ื˜
    ืคืจื•ืคื™ืœ ipsec ipsecprof
    #
    ื ื™ืชืŸ ืœื”ื’ื“ื™ืจ ื‘ืื•ืคืŸ ืกื˜ื˜ื™ ืžืกืœื•ืœื™ื ืœืจืฉืชื•ืช ื”ืคืจื˜ื™ื•ืช ืฉืœ ื”ืœืงื•ื— ื”ื ื’ื™ืฉื•ืช ื“ืจืš ืจื›ื– ื”-VPN ืฉืœ Beeline

    ip route-static 192.168.0.0 255.255.255.0 Tunnel0/0/0
    ip route-static 172.16.0.0 255.255.0.0 Tunnel0/0/0

ื“ื™ืื’ืจืžืช ื”ืชืงืฉื•ืจืช ืฉื”ืชืงื‘ืœื” ื ืจืื™ืช ื‘ืขืจืš ื›ืš:

ืื™ืš ืžื’ื™ืขื™ื ืœ-Beeline IPVPN ื“ืจืš IPSec. ื—ืœืง 1

ืื ืœืœืงื•ื— ืื™ืŸ ื›ืžื” ื“ื•ื’ืžืื•ืช ืœืชืฆื•ืจื” ื”ื‘ืกื™ืกื™ืช, ืื– ืื ื—ื ื• ื‘ื“ืจืš ื›ืœืœ ืขื•ื–ืจื™ื ื‘ื™ืฆื™ืจืชื ื•ืžืขืžื™ื“ื™ื ืื•ืชื ืœื–ืžื™ื ื™ื ืœื›ืœ ื”ืฉืืจ.

ื›ืœ ืžื” ืฉื ื•ืชืจ ื”ื•ื ืœื—ื‘ืจ ืืช ื”-CPE ืœืื™ื ื˜ืจื ื˜, ืคื™ื ื’ ืœื—ืœืง ื”ืชื’ื•ื‘ื” ืฉืœ ืžื ื”ืจืช ื”-VPN ื•ืœื›ืœ ืžืืจื— ื‘ืชื•ืš ื”-VPN, ื•ื–ื”ื•, ืื ื—ื ื• ื™ื›ื•ืœื™ื ืœื”ื ื™ื— ืฉื”ื—ื™ื‘ื•ืจ ื ืขืฉื”.

ื‘ืžืืžืจ ื”ื‘ื ื ืกืคืจ ืœื›ื ื›ื™ืฆื“ ืฉื™ืœื‘ื ื• ืืช ื”ืกื›ื™ืžื” ื”ื–ื• ืขื IPSec ื•-MultiSIM Redundancy ื‘ืืžืฆืขื•ืช Huawei CPE: ืื ื• ืžืชืงื™ื ื™ื ืืช ื”-Huawei CPE ืฉืœื ื• ืขื‘ื•ืจ ืœืงื•ื—ื•ืช, ืฉื™ื›ื•ืœื™ื ืœื”ืฉืชืžืฉ ืœื ืจืง ื‘ืขืจื•ืฅ ืื™ื ื˜ืจื ื˜ ืงื•ื•ื™, ืืœื ื’ื ื‘ืฉื ื™ ื›ืจื˜ื™ืกื™ SIM ืฉื•ื ื™ื, ื•ื‘-CPE ื‘ื•ื ื” ืžื—ื“ืฉ ืื•ื˜ื•ืžื˜ื™ืช ืืช ืžื ื”ืจืช IPSec ื‘ืืžืฆืขื•ืช WAN ืงื•ื•ื™ ืื• ื‘ืืžืฆืขื•ืช ืจื“ื™ื• (LTE#2/LTE#1), ืชื•ืš ืžื™ืžื•ืฉ ืกื•ื‘ืœื ื•ืช ืชืงืœื•ืช ื’ื‘ื•ื”ื” ืฉืœ ื”ืฉื™ืจื•ืช ื”ืžืชืงื‘ืœ.

ืชื•ื“ื” ืžื™ื•ื—ื“ืช ืœืขืžื™ืชื™ื ื• RnD ืขืœ ื”ื›ื ืช ืžืืžืจ ื–ื” (ื•ืœืžืขืฉื”, ืœืžื—ื‘ืจื™ ื”ืคืชืจื•ื ื•ืช ื”ื˜ื›ื ื™ื™ื ื”ืœืœื•)!

ืžืงื•ืจ: www.habr.com

ื”ื•ืกืคืช ืชื’ื•ื‘ื”