ื‘ื™ื˜ื•ืœ ื—ืกื™ืžืช ื”ืื™ื ื˜ืจื ื˜ ื‘ืืžืฆืขื•ืช Mikrotik ื•-VPN: ื”ื“ืจื›ื” ืžืคื•ืจื˜ืช

ื‘ื™ื˜ื•ืœ ื—ืกื™ืžืช ื”ืื™ื ื˜ืจื ื˜ ื‘ืืžืฆืขื•ืช Mikrotik ื•-VPN: ื”ื“ืจื›ื” ืžืคื•ืจื˜ืช
ื‘ืžื“ืจื™ืš ืฉืœื‘ ืื—ืจ ืฉืœื‘ ื–ื”, ืืกืคืจ ืœื›ื ื›ื™ืฆื“ ืœื”ื’ื“ื™ืจ ืืช Mikrotik ื›ืš ืฉืืชืจื™ื ืืกื•ืจื™ื ื™ื™ืคืชื—ื• ืื•ื˜ื•ืžื˜ื™ืช ื“ืจืš ื”-VPN ื”ื–ื” ื•ืชื•ื›ืœื• ืœื”ื™ืžื ืข ืžืจื™ืงื•ื“ ืขื ื˜ืžื‘ื•ืจื™ื ื™ื: ื”ื’ื“ืจ ืืช ื–ื” ืคืขื ืื—ืช ื•ื”ื›ืœ ื™ืขื‘ื•ื“.

ื‘ื—ืจืชื™ ื‘-SoftEther ื›-VPN: ืงืœ ืœื”ื’ื“ื™ืจ ืื•ืชื• RRAS ื•ืžื”ืจ ื‘ืื•ืชื” ืžื™ื“ื”. ื‘ืฆื“ ืฉืจืช ื”-VPN, ื”ืคืขืœืชื™ ืืช Secure NAT; ืœื ื‘ื•ืฆืขื• ื”ื’ื“ืจื•ืช ืื—ืจื•ืช.

ืฉืงืœืชื™ ืืช RRAS ื›ืืœื˜ืจื ื˜ื™ื‘ื”, ืื‘ืœ ืžื™ืงืจื•ื˜ื™ืง ืœื ื™ื•ื“ืข ืื™ืš ืœืขื‘ื•ื“ ืื™ืชื”. ื”ื—ื™ื‘ื•ืจ ื ื•ืฆืจ, ื”-VPN ืขื•ื‘ื“, ืืš ืžื™ืงืจื•ื˜ื™ืง ืœื ืžืฆืœื™ื—ื” ืœืฉืžื•ืจ ืขืœ ื”ื—ื™ื‘ื•ืจ ืœืœื ื—ื™ื‘ื•ืจื™ื ืžืชืžื™ื“ื™ื ื•ืฉื’ื™ืื•ืช ื‘ื™ื•ืžืŸ.

ื”ื”ื’ื“ืจื” ื‘ื•ืฆืขื” ื‘ืืžืฆืขื•ืช ื”ื“ื•ื’ืžื” ืฉืœ RB3011UiAS-RM ื‘ื’ืจืกืช ืงื•ืฉื—ื” 6.46.11.
ืขื›ืฉื™ื•, ืœืคื™ ื”ืกื“ืจ, ืžื” ื•ืœืžื”.

1. ืฆื•ืจ ื—ื™ื‘ื•ืจ VPN

ื›ืžื•ื‘ืŸ, SoftEther, L2TP ืขื ืžืคืชื— ืžืฉื•ืชืฃ ืžืจืืฉ, ื ื‘ื—ืจ ื›ืคืชืจื•ืŸ VPN. ืจืžืช ื”ืื‘ื˜ื—ื” ื”ื–ื• ืžืกืคื™ืงื” ืœื›ืœ ืื—ื“, ื›ื™ ืจืง ื”ื ืชื‘ ื•ื‘ืขืœื™ื• ื™ื•ื“ืขื™ื ืืช ื”ืžืคืชื—.

ืขื‘ื•ืจ ืœืงื˜ืข ืžืžืฉืงื™ื. ืจืืฉื™ืช, ืื ื• ืžื•ืกื™ืคื™ื ืžืžืฉืง ื—ื“ืฉ, ื•ืœืื—ืจ ืžื›ืŸ ืžื›ื ื™ืกื™ื ืืช ื”-IP, ื”ื›ื ื™ืกื”, ื”ืกื™ืกืžื” ื•ื”ืžืคืชื— ื”ืžืฉื•ืชืฃ ืœืžืžืฉืง. ืœื—ืฅ ืขืœ ืื™ืฉื•ืจ.

ื‘ื™ื˜ื•ืœ ื—ืกื™ืžืช ื”ืื™ื ื˜ืจื ื˜ ื‘ืืžืฆืขื•ืช Mikrotik ื•-VPN: ื”ื“ืจื›ื” ืžืคื•ืจื˜ืช
ื‘ื™ื˜ื•ืœ ื—ืกื™ืžืช ื”ืื™ื ื˜ืจื ื˜ ื‘ืืžืฆืขื•ืช Mikrotik ื•-VPN: ื”ื“ืจื›ื” ืžืคื•ืจื˜ืช
ืื•ืชื” ืคืงื•ื“ื”:

/interface l2tp-client
name="LD8" connect-to=45.134.254.112 user="Administrator" password="PASSWORD" profile=default-encryption use-ipsec=yes ipsec-secret="vpn"

SoftEther ื™ืขื‘ื•ื“ ื‘ืœื™ ืœืฉื ื•ืช ืืช ื”ืฆืขื•ืช ipsec ื•ืคืจื•ืคื™ืœื™ ipsec, ืื ื—ื ื• ืœื ืฉื•ืงืœื™ื ืœื”ื’ื“ื™ืจ ืื•ืชื, ืื‘ืœ ื”ืžื—ื‘ืจ ื”ืฉืื™ืจ ืฆื™ืœื•ืžื™ ืžืกืš ืฉืœ ื”ืคืจื•ืคื™ืœื™ื ืฉืœื•, ืœื™ืชืจ ื‘ื™ื˜ื—ื•ืŸ.

ื‘ื™ื˜ื•ืœ ื—ืกื™ืžืช ื”ืื™ื ื˜ืจื ื˜ ื‘ืืžืฆืขื•ืช Mikrotik ื•-VPN: ื”ื“ืจื›ื” ืžืคื•ืจื˜ืช
ืขื‘ื•ืจ RRAS ื‘ื”ืฆืขื•ืช IPsec, ืคืฉื•ื˜ ืฉื ื” ืืช ืงื‘ื•ืฆืช PFS ืœืœื.

ื›ืขืช ืขืœื™ืš ืœืขืžื•ื“ ืžืื—ื•ืจื™ ื”-NAT ืฉืœ ืฉืจืช ื”-VPN ื”ื–ื”. ืœืฉื ื›ืš ืขืœื™ื ื• ืœืขื‘ื•ืจ ืืœ IP > ื—ื•ืžืช ืืฉ > NAT.

ื›ืืŸ ืื ื• ืžืืคืฉืจื™ื ืžืกื›ื•ืช ืขื‘ื•ืจ ืžืžืฉืงื™ PPP ืกืคืฆื™ืคื™ื™ื ืื• ื›ืœ. ื”ื ืชื‘ ืฉืœ ื”ืžื—ื‘ืจ ืžื—ื•ื‘ืจ ืœืฉืœื•ืฉื” VPN ื‘ื• ื–ืžื ื™ืช, ืื– ืขืฉื™ืชื™ ืืช ื–ื”:

ื‘ื™ื˜ื•ืœ ื—ืกื™ืžืช ื”ืื™ื ื˜ืจื ื˜ ื‘ืืžืฆืขื•ืช Mikrotik ื•-VPN: ื”ื“ืจื›ื” ืžืคื•ืจื˜ืช
ื‘ื™ื˜ื•ืœ ื—ืกื™ืžืช ื”ืื™ื ื˜ืจื ื˜ ื‘ืืžืฆืขื•ืช Mikrotik ื•-VPN: ื”ื“ืจื›ื” ืžืคื•ืจื˜ืช
ืื•ืชื” ืคืงื•ื“ื”:

/ip firewall nat
chain=srcnat action=masquerade out-interface=all-ppp

2. ื”ื•ืกืฃ ื›ืœืœื™ื ืœ-Mangle

ื”ื“ื‘ืจ ื”ืจืืฉื•ืŸ ืฉืื ื™ ืจื•ืฆื”, ื›ืžื•ื‘ืŸ, ื”ื•ื ืœื”ื’ืŸ ืขืœ ื›ืœ ืžื” ืฉื”ื›ื™ ื™ืงืจ ื•ื—ืกืจ ื”ื’ื ื”, ื›ืœื•ืžืจ ืชืขื‘ื•ืจืช DNS ื•-HTTP. ื ืชื—ื™ืœ ืขื HTTP.

ืขื‘ื•ืจ ืืœ IP โ†’ ื—ื•ืžืช ืืฉ โ†’ Mangle ื•ืฆื•ืจ ื›ืœืœ ื—ื“ืฉ.

ื‘ื›ืœืœ, ืฉืจืฉืจืช, ื‘ื—ืจ ื ื™ืชื•ื‘ ืžืจืืฉ.

ืื ื™ืฉ ืกืžืืจื˜ SFP ืื• ื ืชื‘ ืื—ืจ ืžื•ืœ ื”ื ืชื‘, ื•ื‘ืจืฆื•ื ื›ื ืœื”ืชื—ื‘ืจ ืืœื™ื• ื“ืจืš ืžืžืฉืง ื”ืื™ื ื˜ืจื ื˜, ื‘ืฉื“ื” Dst. ื›ืชื•ื‘ืช ืืชื” ืฆืจื™ืš ืœื”ื–ื™ืŸ ืืช ื›ืชื•ื‘ืช ื”-IP ืฉืœื” ืื• ืชืช ืจืฉืช ื•ืœืฉื™ื ืกื™ืžืŸ ืฉืœื™ืœื™ ื›ื“ื™ ืœื ืœื”ื—ื™ืœ Mangle ืขืœ ื”ื›ืชื•ื‘ืช ืื• ืขืœ ืชืช ืจืฉืช ื–ื•. ืœืžื—ื‘ืจ ื™ืฉ SFP GPON ONU ื‘ืžืฆื‘ ื’ืฉืจ, ื›ืš ืฉื”ืžื—ื‘ืจ ืฉืžืจ ืขืœ ื”ื™ื›ื•ืœืช ืœื”ืชื—ื‘ืจ ืœืžืžืฉืง ื”ืื™ื ื˜ืจื ื˜ ืฉืœื•.

ื›ื‘ืจื™ืจืช ืžื—ื“ืœ, Mangle ื™ื—ื™ืœ ืืช ื”ื›ืœืœ ืฉืœื• ืขืœ ื›ืœ ืžื“ื™ื ื•ืช ื”-NAT, ื–ื” ื™ื”ืคื•ืš ืืช ื”ืขื‘ืจืช ื”ืคื•ืจื˜ื™ื ื“ืจืš ื”-IP ื”ืœื‘ืŸ ืฉืœืš ืœื‘ืœืชื™ ืืคืฉืจื™, ืื– ื‘-Connection NAT State ืฉืžื ื• ืกื™ืžืŸ ื‘ื™ืงื•ืจืช ืขืœ dstnat ื•ืกื™ืžืŸ ืฉืœื™ืœื™. ื–ื” ื™ืืคืฉืจ ืœื ื• ืœืฉืœื•ื— ืชืขื‘ื•ืจื” ื™ื•ืฆืืช ื“ืจืš ื”ืจืฉืช ื“ืจืš ื”-VPN, ืื‘ืœ ืขื“ื™ื™ืŸ ืœื”ืขื‘ื™ืจ ื™ืฆื™ืื•ืช ื“ืจืš ื”-IP ื”ืœื‘ืŸ ืฉืœื ื•.

ื‘ื™ื˜ื•ืœ ื—ืกื™ืžืช ื”ืื™ื ื˜ืจื ื˜ ื‘ืืžืฆืขื•ืช Mikrotik ื•-VPN: ื”ื“ืจื›ื” ืžืคื•ืจื˜ืช
ืœืื—ืจ ืžื›ืŸ, ื‘ืœืฉื•ื ื™ืช Action ื‘ื—ืจื• ื‘-mark routing, ืงืจืื• ืœื–ื” New Routing Mark ื›ื“ื™ ืฉื–ื” ื™ื”ื™ื” ื‘ืจื•ืจ ืœื ื• ื‘ืขืชื™ื“ ื•ืชืžืฉื™ื›ื• ื”ืœืื”.

ื‘ื™ื˜ื•ืœ ื—ืกื™ืžืช ื”ืื™ื ื˜ืจื ื˜ ื‘ืืžืฆืขื•ืช Mikrotik ื•-VPN: ื”ื“ืจื›ื” ืžืคื•ืจื˜ืช
ืื•ืชื” ืคืงื•ื“ื”:

/ip firewall mangle
add chain=prerouting action=mark-routing new-routing-mark=HTTP passthrough=no connection-nat-state=!dstnat protocol=tcp dst-address=!192.168.1.1 dst-port=80

ื›ืขืช ื ืขื‘ื•ืจ ืœื”ื’ื ืช DNS. ื‘ืžืงืจื” ื–ื”, ืขืœื™ืš ืœื™ืฆื•ืจ ืฉื ื™ ื›ืœืœื™ื. ืื—ื“ ืœื ืชื‘, ื”ืฉื ื™ ืœืžื›ืฉื™ืจื™ื ื”ืžื—ื•ื‘ืจื™ื ืœื ืชื‘.

ืื ืืชื” ืžืฉืชืžืฉ ื‘-DNS ื”ืžื•ื‘ื ื” ื‘ื ืชื‘, ืžื” ืฉืขื•ืฉื” ื”ืžื—ื‘ืจ, ื”ื•ื ื’ื ืฆืจื™ืš ืœื”ื™ื•ืช ืžื•ื’ืŸ. ืœื›ืŸ, ืขื‘ื•ืจ ื”ื›ืœืœ ื”ืจืืฉื•ืŸ, ื›ืžื• ืœืขื™ืœ, ืื ื• ื‘ื•ื—ืจื™ื ื‘-prerouting ืฉืœ ืฉืจืฉืจืช, ืขื‘ื•ืจ ื”ืฉื ื™ ืื ื• ืฆืจื™ื›ื™ื ืœื‘ื—ื•ืจ ืคืœื˜.

ืคืœื˜ ื”ื•ื ื”ืžืขื’ืœ ืฉื‘ื• ืžืฉืชืžืฉ ื”ื ืชื‘ ืขืฆืžื• ื›ื“ื™ ืœื‘ืฆืข ื‘ืงืฉื•ืช ืชื•ืš ืฉื™ืžื•ืฉ ื‘ืคื•ื ืงืฆื™ื•ื ืœื™ื•ืช ืฉืœื•. ื”ื›ืœ ื›ืืŸ ื“ื•ืžื” ืœ-HTTP, ืคืจื•ื˜ื•ืงื•ืœ UDP, ื™ืฆื™ืื” 53.

ื‘ื™ื˜ื•ืœ ื—ืกื™ืžืช ื”ืื™ื ื˜ืจื ื˜ ื‘ืืžืฆืขื•ืช Mikrotik ื•-VPN: ื”ื“ืจื›ื” ืžืคื•ืจื˜ืช
ื‘ื™ื˜ื•ืœ ื—ืกื™ืžืช ื”ืื™ื ื˜ืจื ื˜ ื‘ืืžืฆืขื•ืช Mikrotik ื•-VPN: ื”ื“ืจื›ื” ืžืคื•ืจื˜ืช
ืื•ืชืŸ ืคืงื•ื“ื•ืช:

/ip firewall mangle
add chain=prerouting action=mark-routing new-routing-mark=DNS passthrough=no protocol=udp
add chain=output action=mark-routing new-routing-mark=DNS-Router passthrough=no protocol=udp dst-port=53

3. ื‘ื ื™ื™ืช ืžืกืœื•ืœ ื‘ืืžืฆืขื•ืช VPN

ืขื‘ื•ืจ ืืœ IP โ† ืžืกืœื•ืœื™ื ื•ืฆื•ืจ ืžืกืœื•ืœื™ื ื—ื“ืฉื™ื.

ืžืกืœื•ืœ ืœื ื™ืชื•ื‘ HTTP ื“ืจืš VPN. ืื ื• ืžืฆื™ื™ื ื™ื ืืช ื”ืฉื ืฉืœ ืžืžืฉืงื™ ื”-VPN ืฉืœื ื• ื•ื‘ื•ื—ืจื™ื ืกื™ืžื•ืŸ ื ื™ืชื•ื‘.

ื‘ื™ื˜ื•ืœ ื—ืกื™ืžืช ื”ืื™ื ื˜ืจื ื˜ ื‘ืืžืฆืขื•ืช Mikrotik ื•-VPN: ื”ื“ืจื›ื” ืžืคื•ืจื˜ืช

ื‘ืฉืœื‘ ื–ื” ื›ื‘ืจ ื”ืจื’ืฉืชื ืื™ืš ื”ืžืคืขื™ืœ ืฉืœื›ื ื ืขืฆืจ ืœื”ื˜ืžื™ืข ืคืจืกื•ื ื‘ืชืขื‘ื•ืจืช ื”-HTTP ืฉืœืš.

ืื•ืชื” ืคืงื•ื“ื”:

/ip route
add dst-address=0.0.0.0/0 gateway=LD8 routing-mark=HTTP distance=2 comment=HTTP

ื”ื›ืœืœื™ื ืœื”ื’ื ืช DNS ื™ื™ืจืื• ื‘ื“ื™ื•ืง ืื•ืชื• ื”ื“ื‘ืจ, ืคืฉื•ื˜ ื‘ื—ืจ ืืช ื”ืชื•ื•ื™ืช ื”ืจืฆื•ื™ื”:

ื‘ื™ื˜ื•ืœ ื—ืกื™ืžืช ื”ืื™ื ื˜ืจื ื˜ ื‘ืืžืฆืขื•ืช Mikrotik ื•-VPN: ื”ื“ืจื›ื” ืžืคื•ืจื˜ืช
ื•ืื– ื”ืจื’ืฉืช ืื™ืš ื‘ืงืฉื•ืช ื”-DNS ืฉืœืš ืžืคืกื™ืงื•ืช ืœื”ืื–ื™ืŸ. ืื•ืชืŸ ืคืงื•ื“ื•ืช:

/ip route
add dst-address=0.0.0.0/0 gateway=LD8 routing-mark=DNS distance=1 comment=DNS
add dst-address=0.0.0.0/0 gateway=LD8 routing-mark=DNS-Router distance=1 comment=DNS-Router

ื•ื‘ื›ืŸ, ื‘ืกื•ืคื• ืฉืœ ื“ื‘ืจ, ื‘ื•ืื• ื ื‘ื˜ืœ ืืช ื”ื—ืกื™ืžื” ืฉืœ Rutracker. ืจืฉืช ื”ืžืฉื ื” ื›ื•ืœื” ืฉื™ื™ื›ืช ืœื•, ื•ืœื›ืŸ ืจืฉืช ื”ืžืฉื ื” ืžืฆื•ื™ื ืช.

ื‘ื™ื˜ื•ืœ ื—ืกื™ืžืช ื”ืื™ื ื˜ืจื ื˜ ื‘ืืžืฆืขื•ืช Mikrotik ื•-VPN: ื”ื“ืจื›ื” ืžืคื•ืจื˜ืช
ืขื“ ื›ื“ื™ ื›ืš ืงืœ ื”ื™ื” ืœื”ื—ื–ื™ืจ ืืช ื”ืื™ื ื˜ืจื ื˜ ืฉืœืš. ืงึฐื‘ื•ึผืฆึธื”:

/ip route
add dst-address=195.82.146.0/24 gateway=LD8 distance=1 comment=Rutracker.Org

ื‘ื“ื™ื•ืง ื‘ืื•ืชื• ืื•ืคืŸ ื›ืžื• ืขื ืžืขืงื‘ ืฉื•ืจืฉ, ืืชื” ื™ื›ื•ืœ ืœื ืชื‘ ืžืฉืื‘ื™ื ืืจื’ื•ื ื™ื™ื ื•ืืชืจื™ื ื—ืกื•ืžื™ื ืื—ืจื™ื.

ื”ืžื—ื‘ืจ ืžืงื•ื•ื” ืฉืชืขืจื™ืš ืืช ื”ื ื•ื—ื•ืช ืฉืœ ื›ื ื™ืกื” ืœ-Root Tracker ื•ืœืคื•ืจื˜ืœ ื”ืืจื’ื•ื ื™ ื‘ื•-ื–ืžื ื™ืช ืžื‘ืœื™ ืœื”ื•ืจื™ื“ ืืช ื”ืกื•ื•ื“ืจ.

ื‘ื™ื˜ื•ืœ ื—ืกื™ืžืช ื”ืื™ื ื˜ืจื ื˜ ื‘ืืžืฆืขื•ืช Mikrotik ื•-VPN: ื”ื“ืจื›ื” ืžืคื•ืจื˜ืช

ืžืงื•ืจ: www.habr.com

ื”ื•ืกืคืช ืชื’ื•ื‘ื”