ื”ื’ื“ืจืช IPSec ืืชืจ ืœืืชืจ VPN ื‘ืฆื™ื•ื“ Palo Alto Networks

ื”ื’ื“ืจืช IPSec ืืชืจ ืœืืชืจ VPN ื‘ืฆื™ื•ื“ Palo Alto Networks

ืžืืžืจ ื–ื” ื”ื•ื ื”ืžืฉืš ื—ื•ืžืจ ืงื•ื“ืืžื•ืงื“ืฉ ืœืคืจื˜ื™ื ืฉืœ ื”ื’ื“ืจืช ืฆื™ื•ื“ ืคืืœื• ืืœื˜ื• ื ื˜ื•ื•ืจืงืก . ื›ืืŸ ืื ื—ื ื• ืจื•ืฆื™ื ืœื“ื‘ืจ ืขืœ ื”ื”ื’ื“ืจื” IPSec VPN ืืชืจ ืœืืชืจ ืขืœ ืฆื™ื•ื“ ืคืืœื• ืืœื˜ื• ื ื˜ื•ื•ืจืงืก ื•ืœื’ื‘ื™ ืืคืฉืจื•ืช ืชืฆื•ืจื” ืืคืฉืจื™ืช ืœื—ื™ื‘ื•ืจ ืžืกืคืจ ืกืคืงื™ ืื™ื ื˜ืจื ื˜.

ืœืฆื•ืจืš ื”ื”ื“ื’ืžื” ืชืฉืžืฉ ืชื›ื ื™ืช ืกื˜ื ื“ืจื˜ื™ืช ืœื—ื™ื‘ื•ืจ ื”ืžืฉืจื“ ื”ืจืืฉื™ ืœืกื ื™ืฃ. ืขืœ ืžื ืช ืœืกืคืง ื—ื™ื‘ื•ืจ ืื™ื ื˜ืจื ื˜ ืขืžื™ื“ ืœืชืงืœื•ืช, ื”ืžืฉืจื“ ื”ืจืืฉื™ ืžืฉืชืžืฉ ื‘ื—ื™ื‘ื•ืจ ื‘ื•-ื–ืžื ื™ ืฉืœ ืฉื ื™ ืกืคืงื™ื: ISP-1 ื•-ISP-2. ืœืกื ื™ืฃ ื™ืฉ ื—ื™ื‘ื•ืจ ืœืกืคืง ืื—ื“ ื‘ืœื‘ื“, ISP-3. ืฉืชื™ ืžื ื”ืจื•ืช ื‘ื ื•ื™ื•ืช ื‘ื™ืŸ ื—ื•ืžื•ืช ื”ืืฉ PA-1 ื•-PA-2. ื”ืžื ื”ืจื•ืช ืคื•ืขืœื•ืช ื‘ืžืฆื‘ ืคืขื™ืœ-ื”ืžืชื ื”,ืžื ื”ืจื”-1 ืคืขื™ืœื”, ืžื ื”ืจื”-2 ืชืชื—ื™ืœ ืœืฉื“ืจ ืชืขื‘ื•ืจื” ื›ืืฉืจ ืžื ื”ืจื”-1 ืชื™ื›ืฉืœ. Tunnel-1 ืžืฉืชืžืฉ ื‘ื—ื™ื‘ื•ืจ ืœ-ISP-1, Tunnel-2 ืžืฉืชืžืฉ ื‘ื—ื™ื‘ื•ืจ ืœ-ISP-2. ื›ืœ ื›ืชื•ื‘ื•ืช ื”-IP ื ื•ืฆืจื•ืช ื‘ืื•ืคืŸ ืืงืจืื™ ืœืžื˜ืจื•ืช ื”ื“ื’ืžื” ื•ืื™ืŸ ืœื”ืŸ ืงืฉืจ ืœืžืฆื™ืื•ืช.

ื”ื’ื“ืจืช IPSec ืืชืจ ืœืืชืจ VPN ื‘ืฆื™ื•ื“ Palo Alto Networks

ื›ื“ื™ ืœื‘ื ื•ืช VPN ืืชืจ ืœืืชืจ ื™ื™ืขืฉื” ืฉื™ืžื•ืฉ IPSec - ืงื‘ื•ืฆื” ืฉืœ ืคืจื•ื˜ื•ืงื•ืœื™ื ื›ื“ื™ ืœื”ื‘ื˜ื™ื— ื”ื’ื ื” ืขืœ ื ืชื•ื ื™ื ื”ืžื•ืขื‘ืจื™ื ื‘ืืžืฆืขื•ืช IP. IPSec ื™ืขื‘ื•ื“ ื‘ืืžืฆืขื•ืช ืคืจื•ื˜ื•ืงื•ืœ ืื‘ื˜ื—ื” ESP (Encapsulating Security Payload), ืฉื™ื‘ื˜ื™ื— ื”ืฆืคื ื” ืฉืœ ื ืชื•ื ื™ื ืžื•ืขื‘ืจื™ื.

ะ’ IPSec ื ื›ื ืก IKE (Internet Key Exchange) ื”ื•ื ืคืจื•ื˜ื•ืงื•ืœ ื”ืื—ืจืื™ ืขืœ ืžืฉื ื•ืžืชืŸ ืขืœ SA (ืื’ื•ื“ื•ืช ืื‘ื˜ื—ื”), ืคืจืžื˜ืจื™ ืื‘ื˜ื—ื” ื”ืžืฉืžืฉื™ื ืœื”ื’ื ื” ืขืœ ื ืชื•ื ื™ื ืžื•ืขื‘ืจื™ื. ืชืžื™ื›ื” ื‘ื—ื•ืžืช ืืฉ PAN IKEv1 ะธ IKEv2.

ะ’ IKEv1 ื—ื™ื‘ื•ืจ VPN ื‘ื ื•ื™ ื‘ืฉื ื™ ืฉืœื‘ื™ื: IKEv1 ืฉืœื‘ 1 (ืžื ื”ืจืช IKE) ื• IKEv1 ืฉืœื‘ 2 (ืžื ื”ืจืช IPSec), ืœืคื™ื›ืš, ื ื•ืฆืจื•ืช ืฉืชื™ ืžื ื”ืจื•ืช, ืฉืื—ืช ืžื”ืŸ ืžืฉืžืฉืช ืœื”ื—ืœืคืช ืžื™ื“ืข ืฉื™ืจื•ืช ื‘ื™ืŸ ื—ื•ืžื•ืช ืืฉ, ื”ืฉื ื™ื™ื” ืœื”ืขื‘ืจืช ืชืขื‘ื•ืจื”. IN IKEv1 ืฉืœื‘ 1 ื™ืฉื ื ืฉื ื™ ืžืฆื‘ื™ ืคืขื•ืœื” - ืžืฆื‘ ืจืืฉื™ ื•ืžืฆื‘ ืื’ืจืกื™ื‘ื™. ืžืฆื‘ ืื’ืจืกื™ื‘ื™ ืžืฉืชืžืฉ ื‘ืคื—ื•ืช ื”ื•ื“ืขื•ืช ื•ืžื”ื™ืจ ื™ื•ืชืจ, ืืš ืื™ื ื• ืชื•ืžืš ื‘ื”ื’ื ื” ืขืœ ื–ื”ื•ืช ืขืžื™ืชื™ื.

IKEv2 ื”ื•ื—ืœืฃ IKEv1, ื•ื‘ื”ืฉื•ื•ืื” ืœ IKEv1 ื”ื™ืชืจื•ืŸ ื”ืขื™ืงืจื™ ืฉืœื• ื”ื•ื ื“ืจื™ืฉื•ืช ืจื•ื—ื‘ ืคืก ื ืžื•ื›ื•ืช ื™ื•ืชืจ ื•ืžืฉื ื•ืžืชืŸ ืžื”ื™ืจ ื™ื•ืชืจ ืฉืœ SA. IN IKEv2 ื ืขืฉื” ืฉื™ืžื•ืฉ ื‘ืคื—ื•ืช ื”ื•ื“ืขื•ืช ืฉื™ืจื•ืช (4 ื‘ืกืš ื”ื›ืœ), ืคืจื•ื˜ื•ืงื•ืœื™ EAP ื•-MOBIKE ื ืชืžื›ื™ื, ื•ื ื•ืกืฃ ืžื ื’ื ื•ืŸ ืœื‘ื“ื™ืงืช ื–ืžื™ื ื•ืช ื”ืขืžื™ืช ืฉืื™ืชื• ื ื•ืฆืจืช ื”ืžื ื”ืจื” - ื‘ื“ื™ืงืช ื—ื™ื™ื, ืžื—ืœื™ืฃ Dead Peer Detection ื‘-IKEv1. ืื ื”ื‘ื“ื™ืงื” ื ื›ืฉืœืช, ืื– IKEv2 ื™ื›ื•ืœ ืœืืคืก ืืช ื”ืžื ื”ืจื” ื•ืœืื—ืจ ืžื›ืŸ ืœืฉื—ื–ืจ ืื•ืชื” ืื•ื˜ื•ืžื˜ื™ืช ื‘ื”ื–ื“ืžื ื•ืช ื”ืจืืฉื•ื ื”. ืืชื” ื™ื›ื•ืœ ืœืœืžื•ื“ ืขื•ื“ ืขืœ ื”ื”ื‘ื“ืœื™ื ืงืจื ื›ืืŸ.

ืื ื ื‘ื ื™ืช ืžื ื”ืจื” ื‘ื™ืŸ ื—ื•ืžื•ืช ืืฉ ืžื™ืฆืจื ื™ื ืฉื•ื ื™ื, ืื– ื™ื™ืชื›ืŸ ืฉื™ืฉ ื‘ืื’ื™ื ื‘ื™ื™ืฉื•ื IKEv2, ื•ืœืฆื•ืจืš ืชืื™ืžื•ืช ืœืฆื™ื•ื“ ื›ื–ื” ื ื™ืชืŸ ืœื”ืฉืชืžืฉ IKEv1. ื‘ืžืงืจื™ื ืื—ืจื™ื ืขื“ื™ืฃ ืœื”ืฉืชืžืฉ IKEv2.

ืฉืœื‘ื™ ื”ื’ื“ืจื”:

โ€ข ื”ื’ื“ืจืช ืฉื ื™ ืกืคืงื™ ืื™ื ื˜ืจื ื˜ ื‘ืžืฆื‘ ActiveStandby

ื™ืฉื ืŸ ืžืกืคืจ ื“ืจื›ื™ื ืœื™ื™ืฉื ืคื•ื ืงืฆื™ื” ื–ื•. ืื—ื“ ืžื”ื ื”ื•ื ืœื”ืฉืชืžืฉ ื‘ืžื ื’ื ื•ืŸ ื ื™ื˜ื•ืจ ื ืชื™ื‘ื™ื, ืฉื”ืคืš ื–ืžื™ืŸ ื”ื—ืœ ืžื”ื’ืจืกื” PAN-OS 8.0.0. ื“ื•ื’ืžื” ื–ื• ืžืฉืชืžืฉืช ื‘ื’ืจืกื” 8.0.16. ืชื›ื•ื ื” ื–ื• ื“ื•ืžื” ืœ-IP SLA ื‘ื ืชื‘ื™ื ืฉืœ ืกื™ืกืงื•. ืคืจืžื˜ืจ ืžืกืœื•ืœ ื‘ืจื™ืจืช ื”ืžื—ื“ืœ ื”ืกื˜ื˜ื™ ืžื’ื“ื™ืจ ืฉืœื™ื—ืช ืžื ื•ืช ืคื™ื ื’ ืœื›ืชื•ื‘ืช IP ืกืคืฆื™ืคื™ืช ืžื›ืชื•ื‘ืช ืžืงื•ืจ ืกืคืฆื™ืคื™ืช. ื‘ืžืงืจื” ื–ื”, ืžืžืฉืง ethernet1/1 ืžืฆืœืฆืœ ืืช ืฉืขืจ ื‘ืจื™ืจืช ื”ืžื—ื“ืœ ืคืขื ื‘ืฉื ื™ื™ื”. ืื ืื™ืŸ ืชื’ื•ื‘ื” ืœืฉืœื•ืฉื” ืคื™ื ื’ื™ื ื‘ืจืฆืฃ, ื”ืžืกืœื•ืœ ื ื—ืฉื‘ ื›ืคื’ื•ื ื•ืžื•ืกืจ ืžื˜ื‘ืœืช ื”ื ื™ืชื•ื‘. ืื•ืชื• ืžืกืœื•ืœ ืžื•ื’ื“ืจ ื›ืœืคื™ ืกืคืง ื”ืื™ื ื˜ืจื ื˜ ื”ืฉื ื™, ืืš ืขื ืžื“ื“ ื’ื‘ื•ื” ื™ื•ืชืจ (ื–ื” ื’ื™ื‘ื•ื™). ืœืื—ืจ ื”ืกืจืช ื”ืžืกืœื•ืœ ื”ืจืืฉื•ืŸ ืžื”ื˜ื‘ืœื”, ื—ื•ืžืช ื”ืืฉ ืชืชื—ื™ืœ ืœืฉืœื•ื— ืชืขื‘ื•ืจื” ื“ืจืš ื”ืžืกืœื•ืœ ื”ืฉื ื™ - Fail-Over. ื›ืืฉืจ ื”ืกืคืง ื”ืจืืฉื•ืŸ ื™ืชื—ื™ืœ ืœื”ื’ื™ื‘ ืœืคื™ื ื’ื™ื, ื”ืžืกืœื•ืœ ืฉืœื• ื™ื—ื–ื•ืจ ืœื˜ื‘ืœื” ื•ื™ื—ืœื™ืฃ ืืช ื”ืฉื ื™ ื‘ื’ืœืœ ืžื“ื“ ื˜ื•ื‘ ื™ื•ืชืจ - ื›ืฉืœ-ื—ื–ืจื”. ืชื”ืœื™ืš Fail-Over ืœื•ืงื— ื›ืžื” ืฉื ื™ื•ืช, ืชืœื•ื™ ื‘ืžืจื•ื•ื—ื™ื ื”ืžื•ื’ื“ืจื™ื, ืื‘ืœ, ื‘ื›ืœ ืžืงืจื”, ื”ืชื”ืœื™ืš ืื™ื ื• ืžื™ื™ื“ื™, ื•ื‘ืžื”ืœืš ื–ืžืŸ ื–ื” ื”ืชื ื•ืขื” ืื•ื‘ื“ืช. ื›ืฉืœ-ื—ื–ืจื” ืขื•ื‘ืจ ืœืœื ืื•ื‘ื“ืŸ ืชื ื•ืขื”. ื™ืฉ ื”ื–ื“ืžื ื•ืช ืœืขืฉื•ืช Fail-Over ืžื”ื™ืจ ื™ื•ืชืจ, ืขื BFD, ืื ืกืคืง ื”ืื™ื ื˜ืจื ื˜ ืžืกืคืง ื”ื–ื“ืžื ื•ืช ื›ื–ื•. BFD ื ืชืžืš ื”ื—ืœ ืžื”ื“ื’ื ืกื“ืจืช PA-3000 ะธ VM-100. ืขื“ื™ืฃ ืœืฆื™ื™ืŸ ืœื ืืช ื”ืฉืขืจ ืฉืœ ื”ืกืคืง ื›ื›ืชื•ื‘ืช ื”ืคื™ื ื’, ืืœื ื›ืชื•ื‘ืช ืื™ื ื˜ืจื ื˜ ืฆื™ื‘ื•ืจื™ืช, ืชืžื™ื“ ื ื’ื™ืฉื”.

ื”ื’ื“ืจืช IPSec ืืชืจ ืœืืชืจ VPN ื‘ืฆื™ื•ื“ Palo Alto Networks

โ€ข ื™ืฆื™ืจืช ืžืžืฉืง ืžื ื”ืจื”

ื”ืชื ื•ืขื” ื‘ืชื•ืš ื”ืžื ื”ืจื” ืžื•ืขื‘ืจืช ื‘ืืžืฆืขื•ืช ืžืžืฉืงื™ื ื•ื™ืจื˜ื•ืืœื™ื™ื ืžื™ื•ื—ื“ื™ื. ื›ืœ ืื—ื“ ืžื”ื ื—ื™ื™ื‘ ืœื”ื™ื•ืช ืžื•ื’ื“ืจ ืขื ื›ืชื•ื‘ืช IP ืžืจืฉืช ื”ืชื—ื‘ื•ืจื”. ื‘ื“ื•ื’ืžื” ื–ื•, ืชื—ื ืช ื”ืžืฉื ื” 1/172.16.1.0 ืชืฉืžืฉ ืขื‘ื•ืจ ืžื ื”ืจื”-30, ื•ืชื—ื ืช ื”ืžืฉื ื” 2/172.16.2.0 ืชืฉืžืฉ ืขื‘ื•ืจ ืžื ื”ืจื”-30.
ืžืžืฉืง ื”ืžื ื”ืจื” ื ื•ืฆืจ ื‘ืงื˜ืข ืจืฉืช -> ืžืžืฉืงื™ื -> ืžื ื”ืจื”. ืขืœื™ืš ืœืฆื™ื™ืŸ ื ืชื‘ ื•ื™ืจื˜ื•ืืœื™ ื•ืื–ื•ืจ ืื‘ื˜ื—ื”, ื›ืžื• ื’ื ื›ืชื•ื‘ืช IP ืžืจืฉืช ื”ืชื—ื‘ื•ืจื” ื”ืžืชืื™ืžื”. ืžืกืคืจ ื”ืžืžืฉืง ื™ื›ื•ืœ ืœื”ื™ื•ืช ื›ืœ ื“ื‘ืจ.

ื”ื’ื“ืจืช IPSec ืืชืจ ืœืืชืจ VPN ื‘ืฆื™ื•ื“ Palo Alto Networks

ื”ื’ื“ืจืช IPSec ืืชืจ ืœืืชืจ VPN ื‘ืฆื™ื•ื“ Palo Alto Networks

ื‘ืกืขื™ืฃ ืžืชืงื“ื ื ื™ืชืŸ ืœืฆื™ื™ืŸ ืคืจื•ืคื™ืœ ื ื™ื”ื•ืœืืฉืจ ื™ืืคืฉืจ ping ื‘ืžืžืฉืง ื”ื ืชื•ืŸ, ื–ื” ืขืฉื•ื™ ืœื”ื™ื•ืช ืฉื™ืžื•ืฉื™ ืœื‘ื“ื™ืงื”.

ื”ื’ื“ืจืช IPSec ืืชืจ ืœืืชืจ VPN ื‘ืฆื™ื•ื“ Palo Alto Networks

โ€ข ื”ื’ื“ืจืช ืคืจื•ืคื™ืœ IKE

ืคืจื•ืคื™ืœ IKE ืื—ืจืื™ ืขืœ ื”ืฉืœื‘ ื”ืจืืฉื•ืŸ ืฉืœ ื™ืฆื™ืจืช ื—ื™ื‘ื•ืจ VPN; ืคืจืžื˜ืจื™ื ืฉืœ ื”ืžื ื”ืจื” ืžืคื•ืจื˜ื™ื ื›ืืŸ IKE ืฉืœื‘ 1. ื”ืคืจื•ืคื™ืœ ื ื•ืฆืจ ื‘ืžื“ื•ืจ ืจืฉืช -> ืคืจื•ืคื™ืœื™ ืจืฉืช -> IKE Crypto. ื™ืฉ ืฆื•ืจืš ืœืฆื™ื™ืŸ ืืช ืืœื’ื•ืจื™ืชื ื”ื”ืฆืคื ื”, ืืœื’ื•ืจื™ืชื ื”ื’ื™ื‘ื•ื‘, ืงื‘ื•ืฆืช ื“ื™ืคื™-ื”ืœืžืŸ ื•ืžืฉืš ื—ื™ื™ ื”ืžืคืชื—. ื‘ืื•ืคืŸ ื›ืœืœื™, ื›ื›ืœ ืฉื”ืืœื’ื•ืจื™ืชืžื™ื ืžื•ืจื›ื‘ื™ื ื™ื•ืชืจ, ื›ืš ื”ื‘ื™ืฆื•ืขื™ื ื’ืจื•ืขื™ื ื™ื•ืชืจ; ื™ืฉ ืœื‘ื—ื•ืจ ืื•ืชื ืขืœ ืกืžืš ื“ืจื™ืฉื•ืช ืื‘ื˜ื—ื” ืกืคืฆื™ืคื™ื•ืช. ืขื ื–ืืช, ื‘ื”ื—ืœื˜ ืœื ืžื•ืžืœืฅ ืœื”ืฉืชืžืฉ ื‘ืงื‘ื•ืฆืช ื“ื™ืคื™-ื”ืœืžืŸ ืžืชื—ืช ืœื’ื™ืœ 14 ื›ื“ื™ ืœื”ื’ืŸ ืขืœ ืžื™ื“ืข ืจื’ื™ืฉ. ื”ืกื™ื‘ื” ืœื›ืš ื”ื™ื ื”ืคื’ื™ืขื•ืช ืฉืœ ื”ืคืจื•ื˜ื•ืงื•ืœ, ืฉื ื™ืชืŸ ืœื”ืคื—ื™ืช ืจืง ืขืœ ื™ื“ื™ ืฉื™ืžื•ืฉ ื‘ื’ื“ืœื™ื ืฉืœ ืžื•ื“ื•ืœื™ื ืฉืœ 2048 ืกื™ื‘ื™ื•ืช ื•ืžืขืœื”, ืื• ื‘ืืœื’ื•ืจื™ืชืžื™ ืงืจื™ืคื˜ื•ื’ืจืคื™ื” ืืœื™ืคื˜ื™ื™ื, ื”ืžืฉืžืฉื™ื ื‘ืงื‘ื•ืฆื•ืช 19, 20, 21, 24. ืœืืœื’ื•ืจื™ืชืžื™ื ืืœื• ื™ืฉ ื‘ื™ืฆื•ืขื™ื ื’ื‘ื•ื”ื™ื ื™ื•ืชืจ ื‘ื”ืฉื•ื•ืื” ืœ- ืงืจื™ืคื˜ื•ื’ืจืคื™ื” ืžืกื•ืจืชื™ืช. ืงืจื ืขื•ื“ ื›ืืŸ. ื• ื›ืืŸ.

ื”ื’ื“ืจืช IPSec ืืชืจ ืœืืชืจ VPN ื‘ืฆื™ื•ื“ Palo Alto Networks

โ€ข ื”ื’ื“ืจืช ืคืจื•ืคื™ืœ IPSec

ื”ืฉืœื‘ ื”ืฉื ื™ ืฉืœ ื™ืฆื™ืจืช ื—ื™ื‘ื•ืจ VPN ื”ื•ื ืžื ื”ืจืช IPSec. ืคืจืžื˜ืจื™ SA ืขื‘ื•ืจื• ืžื•ื’ื“ืจื™ื ื‘ ืจืฉืช -> ืคืจื•ืคื™ืœื™ ืจืฉืช -> ืคืจื•ืคื™ืœ IPSec Crypto. ื›ืืŸ ืืชื” ืฆืจื™ืš ืœืฆื™ื™ืŸ ืืช ืคืจื•ื˜ื•ืงื•ืœ IPSec - AH ืื• ESP, ื›ืžื• ื’ื ืคืจืžื˜ืจื™ื SA - ืืœื’ื•ืจื™ืชืžื™ ื’ื™ื‘ื•ื‘, ื”ืฆืคื ื”, ืงื‘ื•ืฆื•ืช ื“ื™ืคื™-ื”ืœืžืŸ ื•ืžืฉืš ื—ื™ื™ ืžืคืชื—. ื™ื™ืชื›ืŸ ืฉื”ืคืจืžื˜ืจื™ื ืฉืœ SA ื‘ืคืจื•ืคื™ืœ IKE Crypto ื•ืคืจื•ืคื™ืœ IPSec Crypto ืื™ื ื ื–ื”ื™ื.

ื”ื’ื“ืจืช IPSec ืืชืจ ืœืืชืจ VPN ื‘ืฆื™ื•ื“ Palo Alto Networks

โ€ข ื”ื’ื“ืจืช ืฉืขืจ IKE

ืฉืขืจ IKE - ื–ื”ื• ืื•ื‘ื™ื™ืงื˜ ืฉืžื™ื™ืขื“ ื ืชื‘ ืื• ื—ื•ืžืช ืืฉ ืฉืื™ืชื ื ื‘ื ื™ืช ืžื ื”ืจืช VPN. ืขื‘ื•ืจ ื›ืœ ืžื ื”ืจื” ืืชื” ืฆืจื™ืš ืœื™ืฆื•ืจ ืžืฉืœืš ืฉืขืจ IKE. ื‘ืžืงืจื” ื–ื” ื ื•ืฆืจื•ืช ืฉืชื™ ืžื ื”ืจื•ืช, ืื—ืช ื“ืจืš ื›ืœ ืกืคืง ืื™ื ื˜ืจื ื˜. ื”ืžืžืฉืง ื”ื™ื•ืฆื ื”ืžืชืื™ื ื•ื›ืชื•ื‘ืช ื”-IP ืฉืœื•, ื›ืชื•ื‘ืช ื”-IP ืฉืœ ืขืžื™ืชื™ื ื•ื”ืžืคืชื— ื”ืžืฉื•ืชืฃ ืฉืœื• ืžืกื•ืžื ื™ื. ื ื™ืชืŸ ืœื”ืฉืชืžืฉ ื‘ืชืขื•ื“ื•ืช ื›ื—ืœื•ืคื” ืœืžืคืชื— ืžืฉื•ืชืฃ.

ื”ื’ื“ืจืช IPSec ืืชืจ ืœืืชืจ VPN ื‘ืฆื™ื•ื“ Palo Alto Networks

ื–ื” ืฉื ื•ืฆืจ ืงื•ื“ื ืœื›ืŸ ืžืฆื•ื™ืŸ ื›ืืŸ ืคืจื•ืคื™ืœ IKE Crypto. ืคืจืžื˜ืจื™ื ืฉืœ ื”ืื•ื‘ื™ื™ืงื˜ ื”ืฉื ื™ ืฉืขืจ IKE ื“ื•ืžื”, ืœืžืขื˜ ื›ืชื•ื‘ื•ืช IP. ืื ื—ื•ืžืช ื”ืืฉ ืฉืœ Palo Alto Networks ืžืžื•ืงืžืช ืžืื—ื•ืจื™ ื ืชื‘ NAT, ืขืœื™ืš ืœื”ืคืขื™ืœ ืืช ื”ืžื ื’ื ื•ืŸ ืžืขื‘ืจ NAT.

ื”ื’ื“ืจืช IPSec ืืชืจ ืœืืชืจ VPN ื‘ืฆื™ื•ื“ Palo Alto Networks

โ€ข ื”ื’ื“ืจืช IPSec Tunnel

ืžื ื”ืจืช IPSec ื”ื•ื ืื•ื‘ื™ื™ืงื˜ ื”ืžืฆื™ื™ืŸ ืืช ืคืจืžื˜ืจื™ ื”ืžื ื”ืจื” ืฉืœ IPSec, ื›ืคื™ ืฉื”ืฉื ืžืจืžื–. ื›ืืŸ ืืชื” ืฆืจื™ืš ืœืฆื™ื™ืŸ ืืช ืžืžืฉืง ื”ืžื ื”ืจื” ื•ืืช ื”ืื•ื‘ื™ื™ืงื˜ื™ื ืฉื ื•ืฆืจื• ื‘ืขื‘ืจ ืฉืขืจ IKE, ืคืจื•ืคื™ืœ IPSec Crypto. ื›ื“ื™ ืœื”ื‘ื˜ื™ื— ืžืขื‘ืจ ืื•ื˜ื•ืžื˜ื™ ืฉืœ ื ื™ืชื•ื‘ ืœืžื ื”ืจืช ื”ื’ื™ื‘ื•ื™, ืขืœื™ืš ืœื”ืคืขื™ืœ ืฆื’ ืžื ื”ืจื”. ื–ื”ื• ืžื ื’ื ื•ืŸ ืฉื‘ื•ื“ืง ืื ืขืžื™ืช ื—ื™ ื‘ืืžืฆืขื•ืช ืชืขื‘ื•ืจืช ICMP. ื›ื›ืชื•ื‘ืช ื”ื™ืขื“, ืขืœื™ืš ืœืฆื™ื™ืŸ ืืช ื›ืชื•ื‘ืช ื”-IP ืฉืœ ืžืžืฉืง ื”ืžื ื”ืจื” ืฉืœ ื”ืขืžื™ืช ืฉืื™ืชื• ื ื‘ื ื™ืช ื”ืžื ื”ืจื”. ื”ืคืจื•ืคื™ืœ ืžืฆื™ื™ืŸ ื˜ื™ื™ืžืจื™ื ื•ืžื” ืœืขืฉื•ืช ืื ื”ื—ื™ื‘ื•ืจ ืื‘ื“. ื”ืžืชืŸ ื”ืชืื•ืฉืฉื•ืช - ื”ืžืชืŸ ืขื“ ืฉื”ื—ื™ื‘ื•ืจ ื™ืฉื•ื—ื–ืจ, ื ื›ืฉืœ ื ื’ืžืจ - ืฉืœื— ืชื ื•ืขื” ืœืื•ืจืš ื ืชื™ื‘ ืื—ืจ, ืื ื–ืžื™ืŸ. ื”ื’ื“ืจืช ื”ืžื ื”ืจื” ื”ืฉื ื™ื™ื” ื“ื•ืžื” ืœื—ืœื•ื˜ื™ืŸ; ืžืžืฉืง ื”ืžื ื”ืจื” ื”ืฉื ื™ื™ื” ื•ืฉืขืจ IKE ืžืฆื•ื™ื ื™ื.

ื”ื’ื“ืจืช IPSec ืืชืจ ืœืืชืจ VPN ื‘ืฆื™ื•ื“ Palo Alto Networks

ื”ื’ื“ืจืช IPSec ืืชืจ ืœืืชืจ VPN ื‘ืฆื™ื•ื“ Palo Alto Networks

โ€ข ื”ื’ื“ืจืช ื ื™ืชื•ื‘

ื“ื•ื’ืžื” ื–ื• ืžืฉืชืžืฉืช ื‘ื ื™ืชื•ื‘ ืกื˜ื˜ื™. ื‘ื—ื•ืžืช ื”ืืฉ ืฉืœ PA-1, ื‘ื ื•ืกืฃ ืœืฉื ื™ ืžืกืœื•ืœื™ ื‘ืจื™ืจืช ื”ืžื—ื“ืœ, ืขืœื™ืš ืœืฆื™ื™ืŸ ืฉื ื™ ืžืกืœื•ืœื™ื ืœืจืฉืช ื”ืžืฉื ื” 10.10.10.0/24 ื‘ืกื ื™ืฃ. ืžืกืœื•ืœ ืื—ื“ ืžืฉืชืžืฉ ื‘ืžื ื”ืจื”-1, ื”ืฉื ื™ ื‘ืžื ื”ืจื”-2. ื”ืžืกืœื•ืœ ื“ืจืš ืžื ื”ืจื”-1 ื”ื•ื ื”ืขื™ืงืจื™ ืžื›ื™ื•ื•ืŸ ืฉื™ืฉ ืœื• ืžื“ื“ ื ืžื•ืš ื™ื•ืชืจ. ืžึทื ื’ึธื ื•ึนืŸ ื ื™ื˜ื•ืจ ื ืชื™ื‘ื™ื ืœื ืžืฉืžืฉ ืœืžืกืœื•ืœื™ื ืืœื”. ืื—ืจืื™ ืขืœ ื”ืžืขื‘ืจ ืฆื’ ืžื ื”ืจื”.

ื”ื’ื“ืจืช IPSec ืืชืจ ืœืืชืจ VPN ื‘ืฆื™ื•ื“ Palo Alto Networks

ื™ืฉ ืœื”ื’ื“ื™ืจ ืืช ืื•ืชื ืžืกืœื•ืœื™ื ืขื‘ื•ืจ ืจืฉืช ื”ืžืฉื ื” 192.168.30.0/24 ื‘-PA-2.

ื”ื’ื“ืจืช IPSec ืืชืจ ืœืืชืจ VPN ื‘ืฆื™ื•ื“ Palo Alto Networks

โ€ข ื”ื’ื“ืจืช ื—ื•ืงื™ ืจืฉืช

ื›ื“ื™ ืฉื”ืžื ื”ืจื” ืชืขื‘ื•ื“, ื™ืฉ ืฆื•ืจืš ื‘ืฉืœื•ืฉื” ื›ืœืœื™ื:

  1. ืœืขื‘ื•ื“ื” ืฆื’ ื ืชื™ื‘ ืืคืฉืจ ICMP ืขืœ ืžืžืฉืงื™ื ื—ื™ืฆื•ื ื™ื™ื.
  2. ืขื‘ื•ืจ IPSec ืœืืคืฉืจ ืืคืœื™ืงืฆื™ื•ืช ืื™ื™ืง ะธ ipsec ืขืœ ืžืžืฉืงื™ื ื—ื™ืฆื•ื ื™ื™ื.
  3. ืืคืฉืจ ืชืขื‘ื•ืจื” ื‘ื™ืŸ ืจืฉืชื•ืช ืžืฉื ื” ืคื ื™ืžื™ื•ืช ื•ืžืžืฉืงื™ ืžื ื”ืจื”.

ื”ื’ื“ืจืช IPSec ืืชืจ ืœืืชืจ VPN ื‘ืฆื™ื•ื“ Palo Alto Networks

ืžืกืงื ื”

ืžืืžืจ ื–ื” ื“ืŸ ื‘ืืคืฉืจื•ืช ืฉืœ ื”ื’ื“ืจืช ื—ื™ื‘ื•ืจ ืื™ื ื˜ืจื ื˜ ืกื•ื‘ืœื ื™ ืชืงืœื•ืช ื• ืืชืจ ืžืืชืจ ืœืืชืจ. ืื ื• ืžืงื•ื•ื™ื ืฉื”ืžื™ื“ืข ื”ื™ื” ืฉื™ืžื•ืฉื™ ื•ื”ืงื•ืจื ื”ืฉื™ื’ ืžื•ืฉื’ ืขืœ ื”ื˜ื›ื ื•ืœื•ื’ื™ื•ืช ื‘ื”ืŸ ื ืขืฉื” ืฉื™ืžื•ืฉ ืคืืœื• ืืœื˜ื• ื ื˜ื•ื•ืจืงืก. ืื ื™ืฉ ืœื›ื ืฉืืœื•ืช ืœื’ื‘ื™ ื”ื’ื“ืจื” ื•ื”ืฆืขื•ืช ื‘ื ื•ืฉืื™ื ืœืžืืžืจื™ื ืขืชื™ื“ื™ื™ื, ื›ืชื‘ื• ืื•ืชืŸ ื‘ืชื’ื•ื‘ื•ืช, ื ืฉืžื— ืœืขื ื•ืช.

ืžืงื•ืจ: www.habr.com

ื”ื•ืกืคืช ืชื’ื•ื‘ื”