ืžื™ืงืจื•ื™ืง. IPSEC vpn ืžืื—ื•ืจื™ NAT โ€‹โ€‹ื›ืœืงื•ื—

ื™ื•ื ื˜ื•ื‘ ืœื›ื•ืœื!

ื–ื” ืงืจื” ืฉื‘ื—ื‘ืจื” ืฉืœื ื• ื‘ืžื”ืœืš ื”ืฉื ืชื™ื™ื ื”ืื—ืจื•ื ื•ืช ืขื‘ืจื ื• ืœืื˜ ืœืื˜ ืœืžื™ืงืจื•ื˜ื™ืงื”. ื”ืฆืžืชื™ื ื”ืจืืฉื™ื™ื ื‘ื ื•ื™ื™ื ืขืœ CCR1072, ื•ื ืงื•ื“ื•ืช ื—ื™ื‘ื•ืจ ืžืงื•ืžื™ื•ืช ืœืžื—ืฉื‘ื™ื ื‘ืžื›ืฉื™ืจื™ื ืคืฉื•ื˜ื•ืช ื™ื•ืชืจ. ื›ืžื•ื‘ืŸ ืฉื™ืฉ ื’ื ืฉื™ืœื•ื‘ ืฉืœ ืจืฉืชื•ืช ื“ืจืš ืžื ื”ืจืช IPSEC, ื‘ืžืงืจื” ื–ื” ื”ื”ื’ื“ืจื” ื“ื™ ืคืฉื•ื˜ื” ื•ืื™ื ื” ืžืขื•ืจืจืช ืงืฉื™ื™ื ืžืื—ืจ ื•ื™ืฉ ื”ืจื‘ื” ื—ื•ืžืจื™ื ื‘ืจืฉืช. ืื‘ืœ ื™ืฉ ืงืฉื™ื™ื ืžืกื•ื™ืžื™ื ืขื ื”ื—ื™ื‘ื•ืจ ื”ื ื™ื™ื“ ืฉืœ ืœืงื•ื—ื•ืช, ื”ื•ื•ื™ืงื™ ืฉืœ ื”ื™ืฆืจืŸ ืื•ืžืจ ืœืš ืื™ืš ืœื”ืฉืชืžืฉ ื‘ืœืงื•ื— ื”-VPN ื”ืจืš ืฉืœ Shrew (ื ืจืื” ืฉื”ื›ืœ ื‘ืจื•ืจ ืขื ื”ื”ื’ื“ืจื” ื”ื–ื•) ื•ื–ื” ื”ืœืงื•ื— ืฉืžืฉืžืฉ 99% ืžืžืฉืชืžืฉื™ ื”ื’ื™ืฉื” ืžืจื—ื•ืง , ื•-1% ื–ื” ืื ื™, ืคืฉื•ื˜ ื”ืชืขืฆืœืชื™ ืžื“ื™ ื›ืœ ืื—ื“ ืคืฉื•ื˜ ื”ื–ืŸ ืืช ื”ื›ื ื™ืกื” ื•ื”ืกื™ืกืžื” ื‘ืœืงื•ื— ื•ืจืฆื™ืชื™ ืžื™ืงื•ื ืขืฆืœืŸ ืขืœ ื”ืกืคื” ื•ื—ื™ื‘ื•ืจ ื ื•ื— ืœืจืฉืชื•ืช ื”ืขื‘ื•ื“ื”. ืœื ืžืฆืืชื™ ื”ื•ืจืื•ืช ืœื”ื’ื“ืจืช Mikrotik ืœืžืฆื‘ื™ื ืฉื‘ื”ื ื”ื•ื ืืคื™ืœื• ืœื ืžืื—ื•ืจื™ ื›ืชื•ื‘ืช ืืคื•ืจื”, ืืœื ืœื’ืžืจื™ ืžืื—ื•ืจื™ ื›ืชื•ื‘ืช ืฉื—ื•ืจื” ื•ืื•ืœื™ ืืคื™ืœื• ื›ืžื” NATs ื‘ืจืฉืช. ืœื›ืŸ, ื”ื™ื™ืชื™ ืฆืจื™ืš ืœืืœืชืจ, ื•ืœื›ืŸ ืื ื™ ืžืฆื™ืข ืœื”ืกืชื›ืœ ืขืœ ื”ืชื•ืฆืื”.

ื–ืžื™ืŸ:

  1. CCR1072 ื›ืžื›ืฉื™ืจ ืจืืฉื™. ื’ืจืกื” 6.44.1
  2. CAP ac ื›ื ืงื•ื“ืช ื—ื™ื‘ื•ืจ ื‘ื™ืชื™ืช. ื’ืจืกื” 6.44.1

ื”ืžืืคื™ื™ืŸ ื”ืขื™ืงืจื™ ืฉืœ ื”ื”ื’ื“ืจื” ื”ื•ื ืฉื”ืžื—ืฉื‘ ื”ืื™ืฉื™ ื•ื”ืžื™ืงืจื•ื˜ื™ืง ื—ื™ื™ื‘ื™ื ืœื”ื™ื•ืช ื‘ืื•ืชื” ืจืฉืช ืขื ืื•ืชื” ื›ืชื•ื‘ืช, ื”ืžื•ื ืคืงืช ืขืœ ื™ื“ื™ ื”-1072 ื”ืจืืฉื™.

ื ืขื‘ื•ืจ ืœื”ื’ื“ืจื•ืช:

1. ื›ืžื•ื‘ืŸ ืฉืื ื• ืžืคืขื™ืœื™ื ืืช Fasttrack, ืื‘ืœ ืžื›ื™ื•ื•ืŸ ืฉ-fasttrack ืื™ื ื• ืชื•ืื ืœ-vpn, ืขืœื™ื ื• ืœื—ืชื•ืš ืืช ื”ืชืขื‘ื•ืจื” ืฉืœื•.

/ip firewall mangle
add action=mark-connection chain=forward comment="ipsec in" ipsec-policy=
    in,ipsec new-connection-mark=ipsec passthrough=yes
add action=mark-connection chain=forward comment="ipsec out" ipsec-policy=
    out,ipsec new-connection-mark=ipsec passthrough=yes
/ip firewall filter add action=fasttrack-connection chain=forward connection-mark=!ipsec

2. ื”ื•ืกืคืช ื”ืขื‘ืจืช ืจืฉืช ืž/ืืœ ื”ื‘ื™ืช ื•ื”ืขื‘ื•ื“ื”

/ip firewall raw
add action=accept chain=prerouting dst-address=192.168.33.0/24 src-address=
    10.7.76.0/24
add action=accept chain=prerouting dst-address=192.168.33.0/24 src-address=
    10.7.98.0/24
add action=accept chain=prerouting disabled=yes dst-address=192.168.55.0/24 
    src-address=10.7.78.0/24
add action=accept chain=prerouting dst-address=10.7.76.0/24 src-address=
    192.168.33.0/24
add action=accept chain=prerouting dst-address=10.7.77.0/24 src-address=
    192.168.33.0/24
add action=accept chain=prerouting dst-address=10.7.98.0/24 src-address=
    192.168.33.0/24
add action=accept chain=prerouting disabled=yes dst-address=10.7.78.0/24 
    src-address=192.168.55.0/24
add action=accept chain=prerouting dst-address=192.168.33.0/24 src-address=
    10.7.77.0/24

3. ืฆื•ืจ ืชื™ืื•ืจ ื—ื™ื‘ื•ืจ ืžืฉืชืžืฉ

/ip ipsec identity
add auth-method=pre-shared-key-xauth notrack-chain=prerouting peer=CO secret=
    ะพะฑั‰ะธะน ะบะปัŽั‡ xauth-login=username xauth-password=password

4. ืฆื•ืจ ื”ืฆืขืช IPSEC

/ip ipsec proposal
add enc-algorithms=3des lifetime=5m name="prop1" pfs-group=none

5. ืฆื•ืจ ืžื“ื™ื ื™ื•ืช IPSEC

/ip ipsec policy
add dst-address=10.7.76.0/24 level=unique proposal="prop1" 
    sa-dst-address=<white IP 1072> sa-src-address=0.0.0.0 src-address=
    192.168.33.0/24 tunnel=yes
add dst-address=10.7.77.0/24 level=unique proposal="prop1" 
    sa-dst-address=<white IP 1072> sa-src-address=0.0.0.0 src-address=
    192.168.33.0/24 tunnel=yes

6. ืฆื•ืจ ืคืจื•ืคื™ืœ IPSEC

/ip ipsec profile
set [ find default=yes ] dpd-interval=disable-dpd enc-algorithm=
    aes-192,aes-128,3des nat-traversal=no
add dh-group=modp1024 enc-algorithm=aes-192,aes-128,3des name=profile_1
add name=profile_88
add dh-group=modp1024 lifetime=4h name=profile246

7. ืฆื•ืจ ืขืžื™ืช IPSEC

/ip ipsec peer
add address=<white IP 1072>/32 local-address=<ะฒะฐัˆ ะฐะดั€ะตั ั€ะพัƒั‚ะตั€ะฐ> name=CO profile=
    profile_88

ืขื›ืฉื™ื• ืœืงืฆืช ืงืกื ืคืฉื•ื˜. ืžื›ื™ื•ื•ืŸ ืฉืœื ืžืžืฉ ืจืฆื™ืชื™ ืœืฉื ื•ืช ืืช ื”ื”ื’ื“ืจื•ืช ื‘ื›ืœ ื”ืžื›ืฉื™ืจื™ื ื‘ืจืฉืช ื”ื‘ื™ืชื™ืช ืฉืœื™, ื ืืœืฆืชื™ ืื™ื›ืฉื”ื• ืœืชืœื•ืช DHCP ื‘ืื•ืชื” ืจืฉืช, ืื‘ืœ ื–ื” ืกื‘ื™ืจ ืฉืžื™ืงืจื•ื˜ื™ืง ืœื ืžืืคืฉืจืช ืœืชืœื•ืช ื™ื•ืชืจ ืžืžืื’ืจ ื›ืชื•ื‘ื•ืช ืื—ื“ ืขืœ ื’ืฉืจ ืื—ื“ , ืื– ืžืฆืืชื™ ื“ืจืš ืœืขืงื™ืคืช ื”ื‘ืขื™ื”, ื›ืœื•ืžืจ ืขื‘ื•ืจ ืžื—ืฉื‘ ื ื™ื™ื“, ืคืฉื•ื˜ ื™ืฆืจืชื™ DHCP Lease ืขื ืคืจืžื˜ืจื™ื ื™ื“ื ื™ื™ื, ื•ืžื›ื™ื•ื•ืŸ ืฉืœ Netmask, gateway ื•-dns ื™ืฉ ื’ื ืžืกืคืจื™ ืืคืฉืจื•ื™ื•ืช ื‘-DHCP, ืฆื™ื™ื ืชื™ ืื•ืชื ื‘ืื•ืคืŸ ื™ื“ื ื™.

1. ืืคืฉืจื•ื™ื•ืช DHCP

/ip dhcp-server option
add code=3 name=option3-gateway value="'192.168.33.1'"
add code=1 name=option1-netmask value="'255.255.255.0'"
add code=6 name=option6-dns value="'8.8.8.8'"

2.ื—ื›ื™ืจื” ืฉืœ DHCP

/ip dhcp-server lease
add address=192.168.33.4 dhcp-option=
    option1-netmask,option3-gateway,option6-dns mac-address=<MAC ะฐะดั€ะตั ะฝะพัƒั‚ะฑัƒะบะฐ>

ื™ื—ื“ ืขื ื–ืืช, ื”ื’ื“ืจืช 1072 ื”ื™ื ื‘ืกื™ืกื™ืช ืžืขืฉื™ืช, ืจืง ื›ืืฉืจ ืžื•ืฆื™ืื™ื ื›ืชื•ื‘ืช IP ืœืœืงื•ื— ื‘ื”ื’ื“ืจื•ืช ืžืฆื•ื™ื™ืŸ ื›ื™ ื™ืฉ ืœืžืกื•ืจ ืœื• ืืช ื›ืชื•ื‘ืช ื”-IP ืฉื”ื•ื–ื ื” ื™ื“ื ื™ืช, ื•ืœื ืžื”ืžืื’ืจ. ืขื‘ื•ืจ ืœืงื•ื—ื•ืช PC ืจื’ื™ืœื™ื, ืจืฉืช ื”ืžืฉื ื” ื–ื”ื” ืœืชืฆื•ืจืช Wiki 192.168.55.0/24.

ื”ื’ื“ืจื” ื›ื–ื• ืžืืคืฉืจืช ืœื ืœื”ืชื—ื‘ืจ ืœืžื—ืฉื‘ ื”ืื™ืฉื™ ื‘ืืžืฆืขื•ืช ืชื•ื›ื ืช ืฆื“ ืฉืœื™ืฉื™, ื•ื”ืžื ื”ืจื” ืขืฆืžื” ืžื•ื’ื‘ื”ืช ืขืœ ื™ื“ื™ ื”ื ืชื‘ ืœืคื™ ื”ืฆื•ืจืš. ื”ืขื•ืžืก ืฉืœ ื”ืœืงื•ื— CAP ac ื”ื•ื ื›ืžืขื˜ ืžื™ื ื™ืžืœื™, 8-11% ื‘ืžื”ื™ืจื•ืช ืฉืœ 9-10MB/s ื‘ืžื ื”ืจื”.

ื›ืœ ื”ื”ื’ื“ืจื•ืช ื‘ื•ืฆืขื• ื“ืจืš Winbox, ืื ื›ื™ ื‘ืื•ืชื” ื”ืฆืœื—ื” ื ื™ืชืŸ ืœืขืฉื•ืช ื–ืืช ื“ืจืš ื”ืงื•ื ืกื•ืœื”.

ืžืงื•ืจ: www.habr.com

ื”ื•ืกืคืช ืชื’ื•ื‘ื”