ื ื™ืชื•ื— ืฉืœ ื”-SD-WAN ื”ื“ืžื•ืงืจื˜ื™ ื‘ื™ื•ืชืจ: ืืจื›ื™ื˜ืงื˜ื•ืจื”, ืชืฆื•ืจื”, ื ื™ื”ื•ืœ ื•ืžืœื›ื•ื“ื•ืช

ืื ืœืฉืคื•ื˜ ืœืคื™ ืžืกืคืจ ื”ืฉืืœื•ืช ืฉื”ื—ืœื• ืœื”ื’ื™ืข ืืœื™ื ื• ื‘ืืžืฆืขื•ืช SD-WAN, ื”ื˜ื›ื ื•ืœื•ื’ื™ื” ื”ื—ืœื” ืœื”ืฉืชืจืฉ ื‘ื™ืกื•ื“ื™ื•ืช ื‘ืจื•ืกื™ื”. ืกืคืงื™ื, ื›ืžื•ื‘ืŸ, ืœื ื™ืฉื ื™ื ื•ืžืฆื™ืขื™ื ืืช ื”ืžื•ืฉื’ื™ื ืฉืœื”ื, ื•ื›ืžื” ื—ืœื•ืฆื™ื ืืžื™ืฆื™ื ื›ื‘ืจ ืžื™ื™ืฉืžื™ื ืื•ืชื ื‘ืจืฉืชื•ืช ืฉืœื”ื.

ืื ื• ืขื•ื‘ื“ื™ื ื›ืžืขื˜ ืขื ื›ืœ ื”ืกืคืงื™ื, ื•ืœืื•ืจืš ืžืกืคืจ ืฉื ื™ื ื‘ืžืขื‘ื“ื” ืฉืœื ื• ื”ืฆืœื—ืชื™ ืœื”ืชืขืžืง ื‘ืืจื›ื™ื˜ืงื˜ื•ืจื” ืฉืœ ื›ืœ ืžืคืชื— ื’ื“ื•ืœ ืฉืœ ืคืชืจื•ื ื•ืช ืžื•ื’ื“ืจื™ ืชื•ื›ื ื”. SD-WAN ืž-Fortinet ืขื•ืžื“ ื›ืืŸ ืงืฆืช ื‘ื ืคืจื“, ืฉืคืฉื•ื˜ ื‘ื ืชื” ืืช ื”ืคื•ื ืงืฆื™ื•ื ืœื™ื•ืช ืฉืœ ืื™ื–ื•ืŸ ืชืขื‘ื•ืจื” ื‘ื™ืŸ ืขืจื•ืฆื™ ืชืงืฉื•ืจืช ืœืชื•ืš ืชื•ื›ื ืช ื—ื•ืžืช ื”ืืฉ. ื”ืคืชืจื•ืŸ ื”ื•ื ื“ืžื•ืงืจื˜ื™ ืœืžื“ื™, ื•ืœื›ืŸ ื”ื•ื ื ื—ืฉื‘ ื‘ื“ืจืš ื›ืœืœ ืขืœ ื™ื“ื™ ื—ื‘ืจื•ืช ืฉืขื“ื™ื™ืŸ ืœื ืžื•ื›ื ื•ืช ืœืฉื™ื ื•ื™ื™ื ื’ืœื•ื‘ืœื™ื™ื, ืืš ืจื•ืฆื•ืช ืœื”ืฉืชืžืฉ ื‘ืขืจื•ืฆื™ ื”ืชืงืฉื•ืจืช ืฉืœื”ืŸ ื‘ืฆื•ืจื” ื™ืขื™ืœื” ื™ื•ืชืจ.

ื‘ืžืืžืจ ื–ื” ืื ื™ ืจื•ืฆื” ืœืกืคืจ ืœื›ื ื›ื™ืฆื“ ืœื”ื’ื“ื™ืจ ื•ืœืขื‘ื•ื“ ืขื SD-WAN ืž-Fortinet, ืœืžื™ ื”ืคืชืจื•ืŸ ื”ื–ื” ืžืชืื™ื ื•ื‘ืื™ืœื• ืžืœื›ื•ื“ื•ืช ืืชื ืขืœื•ืœื™ื ืœื”ื™ืชืงืœ ื›ืืŸ.

ื ื™ืชืŸ ืœืกื•ื•ื’ ืืช ื”ืฉื—ืงื ื™ื ื”ื‘ื•ืœื˜ื™ื ื‘ื™ื•ืชืจ ื‘ืฉื•ืง ื”-SD-WAN ืœืื—ื“ ืžืฉื ื™ ืกื•ื’ื™ื:

1. ืกื˜ืืจื˜ืืคื™ื ืฉื™ืฆืจื• ืคืชืจื•ื ื•ืช SD-WAN ืžืืคืก. ื”ืžืฆืœื™ื—ื™ื ืฉื‘ื”ื ืžืงื‘ืœื™ื ืชื ื•ืคื” ืขืฆื•ืžื” ืœืคื™ืชื•ื— ืœืื—ืจ ืฉื ืจื›ืฉื• ืขืœ ื™ื“ื™ ื—ื‘ืจื•ืช ื’ื“ื•ืœื•ืช - ื–ื” ื”ืกื™ืคื•ืจ ืฉืœ Cisco/Viptela, VMWare/VeloCloud, Nuage/Nokia

2. ืกืคืงื™ ืจืฉืช ื’ื“ื•ืœื™ื ืฉื™ืฆืจื• ืคืชืจื•ื ื•ืช SD-WAN, ืžืคืชื—ื™ื ืืช ื™ื›ื•ืœืช ื”ืชื›ื ื•ืช ื•ื”ื ื™ื”ื•ืœ ืฉืœ ื”ื ืชื‘ื™ื ื”ืžืกื•ืจืชื™ื™ื ืฉืœื”ื - ื–ื” ื”ืกื™ืคื•ืจ ืฉืœ Juniper, Huawei

ืคื•ืจื˜ื™ื ื˜ ื”ืฆืœื™ื—ื” ืœืžืฆื•ื ืืช ื“ืจื›ื”. ืœืชื•ื›ื ืช ื—ื•ืžืช ื”ืืฉ ื”ื™ื™ืชื” ืคื•ื ืงืฆื™ื•ื ืœื™ื•ืช ืžื•ื‘ื ื™ืช ืฉืืคืฉืจื” ืœืฉืœื‘ ืืช ื”ืžืžืฉืงื™ื ืฉืœื”ืŸ ืœืขืจื•ืฆื™ื ื•ื™ืจื˜ื•ืืœื™ื™ื ื•ืœืื–ืŸ ืืช ื”ืขื•ืžืก ื‘ื™ื ื™ื”ื ื‘ืืžืฆืขื•ืช ืืœื’ื•ืจื™ืชืžื™ื ืžื•ืจื›ื‘ื™ื ื‘ื”ืฉื•ื•ืื” ืœื ื™ืชื•ื‘ ืงื•ื ื‘ื ืฆื™ื•ื ืœื™. ืคื•ื ืงืฆื™ื•ื ืœื™ื•ืช ื–ื• ื ืงืจืื” SD-WAN. ื”ืื ืžื” ืคื•ืจื˜ื™ื ื˜ ื›ืŸ ื™ื›ื•ืœ ืœื”ื™ืงืจื SD-WAN? ื”ืฉื•ืง ืžื‘ื™ืŸ ื‘ื”ื“ืจื’ื” ืฉ-Software-Defined ืคื™ืจื•ืฉื” ื”ืคืจื“ื” ืฉืœ ืžื™ืฉื•ืจ ื”ื‘ืงืจื” ืžืžื™ืฉื•ืจ ื”ื ืชื•ื ื™ื, ื‘ืงืจื™ื ื™ื™ืขื•ื“ื™ื™ื ื•ืžืชื–ืžืจื™ื. ืœืคื•ืจื˜ื™ื ื˜ ืื™ืŸ ื“ื‘ืจ ื›ื–ื”. ื ื™ื”ื•ืœ ืžืจื›ื–ื™ ื”ื•ื ืื•ืคืฆื™ื•ื ืœื™ ื•ืžื•ืฆืข ื‘ืืžืฆืขื•ืช ื”ื›ืœื™ ื”ืžืกื•ืจืชื™ Fortimanager. ืื‘ืœ ืœื“ืขืชื™, ืืชื” ืœื ืฆืจื™ืš ืœื—ืคืฉ ืืžืช ืžื•ืคืฉื˜ืช ื•ืœื‘ื–ื‘ื– ื–ืžืŸ ื‘ื•ื•ื™ื›ื•ื—ื™ื ืขืœ ืžื•ื ื—ื™ื. ื‘ืขื•ืœื ื”ืืžื™ืชื™, ืœื›ืœ ื’ื™ืฉื” ื™ืฉ ืืช ื”ื™ืชืจื•ื ื•ืช ื•ื”ื—ืกืจื•ื ื•ืช ืฉืœื”. ื”ื“ืจืš ื”ื˜ื•ื‘ื” ื‘ื™ื•ืชืจ ืœืฆืืช ื”ื™ื ืœื”ื‘ื™ืŸ ืื•ืชื ื•ืœื”ื™ื•ืช ืžืกื•ื’ืœื™ื ืœื‘ื—ื•ืจ ืคืชืจื•ื ื•ืช ื”ืชื•ืืžื™ื ืืช ื”ืžืฉื™ืžื•ืช.

ืื ื™ ืื ืกื” ืœืกืคืจ ืœื›ื ืขื ืฆื™ืœื•ืžื™ ืžืกืš ื‘ื™ื“ ืื™ืš ื ืจืื” SD-WAN ืž-Fortinet ื•ืžื” ื”ื•ื ื™ื›ื•ืœ ืœืขืฉื•ืช.

ืื™ืš ื”ื›ืœ ืขื•ื‘ื“

ื ื ื™ื— ืฉื™ืฉ ืœืš ืฉื ื™ ืกื ื™ืคื™ื ื”ืžื—ื•ื‘ืจื™ื ืขืœ ื™ื“ื™ ืฉื ื™ ืขืจื•ืฆื™ ื ืชื•ื ื™ื. ืงื™ืฉื•ืจื™ ื ืชื•ื ื™ื ืืœื” ืžืฉื•ืœื‘ื™ื ืœืงื‘ื•ืฆื”, ื‘ื“ื•ืžื” ืœืื•ืคืŸ ืฉื‘ื• ืžืฉื•ืœื‘ื™ื ืžืžืฉืงื™ Ethernet ืจื’ื™ืœื™ื ืœืชื•ืš LACP-Port-Channel. ื”ื•ื•ืชื™ืงื™ื ื™ื–ื›ืจื• PPP Multilink - ื’ื ืื ืœื•ื’ื™ื” ืžืชืื™ืžื”. ืขืจื•ืฆื™ื ื™ื›ื•ืœื™ื ืœื”ื™ื•ืช ื™ืฆื™ืื•ืช ืคื™ื–ื™ื•ืช, VLAN SVI, ื›ืžื• ื’ื ืžื ื”ืจื•ืช VPN ืื• GRE.

VPN ืื• GRE ืžืฉืžืฉื™ื ื‘ื“ืจืš ื›ืœืœ ื‘ืขืช ื—ื™ื‘ื•ืจ ืจืฉืชื•ืช ืžืงื•ืžื™ื•ืช ืกื ื™ืคื™ื ื“ืจืš ื”ืื™ื ื˜ืจื ื˜. ื•ื™ืฆื™ืื•ืช ืคื™ื–ื™ื•ืช - ืื ื™ืฉ ื—ื™ื‘ื•ืจื™ L2 ื‘ื™ืŸ ืืชืจื™ื, ืื• ื‘ื—ื™ื‘ื•ืจ ื‘ืืžืฆืขื•ืช MPLS/VPN ื™ื™ืขื•ื“ื™, ืื ืื ื—ื ื• ืžืจื•ืฆื™ื ืžื”ื—ื™ื‘ื•ืจ ืœืœื Overlay ื•ื”ืฆืคื ื”. ืชืจื—ื™ืฉ ื ื•ืกืฃ ืฉื‘ื• ื ืขืฉื” ืฉื™ืžื•ืฉ ื‘ื™ืฆื™ืื•ืช ืคื™ื–ื™ื•ืช ื‘ืงื‘ื•ืฆืช SD-WAN ื”ื•ื ืื™ื–ื•ืŸ ื”ื’ื™ืฉื” ื”ืžืงื•ืžื™ืช ืฉืœ ืžืฉืชืžืฉื™ื ืœืื™ื ื˜ืจื ื˜.

ื‘ื“ื•ื›ืŸ ืฉืœื ื• ื™ืฉ ืืจื‘ืข ื—ื•ืžื•ืช ืืฉ ื•ืฉืชื™ ืžื ื”ืจื•ืช VPN ื”ืคื•ืขืœื•ืช ื‘ืืžืฆืขื•ืช ืฉื ื™ "ืžืคืขื™ืœื™ ืชืงืฉื•ืจืช". ื”ืชืจืฉื™ื ื ืจืื” ื›ืš:

ื ื™ืชื•ื— ืฉืœ ื”-SD-WAN ื”ื“ืžื•ืงืจื˜ื™ ื‘ื™ื•ืชืจ: ืืจื›ื™ื˜ืงื˜ื•ืจื”, ืชืฆื•ืจื”, ื ื™ื”ื•ืœ ื•ืžืœื›ื•ื“ื•ืช

ืžื ื”ืจื•ืช VPN ืžื•ื’ื“ืจื•ืช ื‘ืžืฆื‘ ืžืžืฉืง ื›ืš ืฉื”ืŸ ื“ื•ืžื•ืช ืœื—ื™ื‘ื•ืจื™ื ืžื ืงื•ื“ื” ืœื ืงื•ื“ื” ื‘ื™ืŸ ืžื›ืฉื™ืจื™ื ืขื ื›ืชื•ื‘ื•ืช IP ื‘ืžืžืฉืงื™ P2P, ืืฉืจ ื ื™ืชืŸ ืœื‘ืฆืข pinging ื›ื“ื™ ืœื”ื‘ื˜ื™ื— ืฉื”ืชืงืฉื•ืจืช ื“ืจืš ืžื ื”ืจื” ืžืกื•ื™ืžืช ืคื•ืขืœืช. ื›ื“ื™ ืฉื”ืชื ื•ืขื” ืชื”ื™ื” ืžื•ืฆืคื ืช ื•ืชืขื‘ื•ืจ ืœืฆื“ ื”ื ื’ื“ื™, ืžืกืคื™ืง ืœื ืชื‘ ืื•ืชื” ืœืชื•ืš ื”ืžื ื”ืจื”. ื”ืืœื˜ืจื ื˜ื™ื‘ื” ื”ื™ื ืœื‘ื—ื•ืจ ืชืขื‘ื•ืจื” ืœื”ืฆืคื ื” ื‘ืืžืฆืขื•ืช ืจืฉื™ืžื•ืช ืฉืœ ืจืฉืชื•ืช ืžืฉื ื”, ืžื” ืฉืžื‘ืœื‘ืœ ืžืื•ื“ ืืช ื”ืžื ื”ืœ ื›ื›ืœ ืฉื”ืงื•ื ืคื™ื’ื•ืจืฆื™ื” ื”ื•ืคื›ืช ืžื•ืจื›ื‘ืช ื™ื•ืชืจ. ื‘ืจืฉืช ื’ื“ื•ืœื”, ืืชื” ื™ื›ื•ืœ ืœื”ืฉืชืžืฉ ื‘ื˜ื›ื ื•ืœื•ื’ื™ื™ืช ADVPN ื›ื“ื™ ืœื‘ื ื•ืช VPN; ื–ื”ื• ืื ืœื•ื’ื™ ืฉืœ DMVPN ืž-Cisco ืื• DVPN ืž-Huawei, ืžื” ืฉืžืืคืฉืจ ื”ื’ื“ืจื” ืงืœื” ื™ื•ืชืจ.

ืชืฆื•ืจืช VPN ืžืืชืจ ืœืืชืจ ืขื‘ื•ืจ ืฉื ื™ ืžื›ืฉื™ืจื™ื ืขื ื ื™ืชื•ื‘ BGP ืžืฉื ื™ ื”ืฆื“ื“ื™ื

ยซะฆะžะ”ยป (DC)
ยซะคะธะปะธะฐะปยป (BRN)

config system interface
โ€ƒedit "WAN1"
โ€ƒโ€ƒset vdom "Internet"
โ€ƒโ€ƒset ip 1.1.1.1 255.255.255.252
โ€ƒโ€ƒset allowaccess ping
โ€ƒโ€ƒset role wan
โ€ƒโ€ƒset interface "DC-BRD"
โ€ƒโ€ƒset vlanid 111
โ€ƒnext
โ€ƒedit "WAN2"
โ€ƒโ€ƒset vdom "Internet"
โ€ƒโ€ƒset ip 3.3.3.1 255.255.255.252
โ€ƒโ€ƒset allowaccess ping
โ€ƒโ€ƒset role lan
โ€ƒโ€ƒset interface "DC-BRD"
โ€ƒโ€ƒset vlanid 112
โ€ƒnext
โ€ƒedit "BRN-Ph1-1"
โ€ƒโ€ƒset vdom "Internet"
โ€ƒโ€ƒset ip 192.168.254.1 255.255.255.255
โ€ƒโ€ƒset allowaccess ping
โ€ƒโ€ƒset type tunnel
โ€ƒโ€ƒset remote-ip 192.168.254.2 255.255.255.255
โ€ƒโ€ƒset interface "WAN1"
โ€ƒnext
โ€ƒedit "BRN-Ph1-2"
โ€ƒโ€ƒset vdom "Internet"
โ€ƒโ€ƒset ip 192.168.254.3 255.255.255.255
โ€ƒโ€ƒset allowaccess ping
โ€ƒโ€ƒset type tunnel
โ€ƒโ€ƒset remote-ip 192.168.254.4 255.255.255.255
โ€ƒโ€ƒset interface "WAN2"
โ€ƒnext
end

config vpn ipsec phase1-interface
โ€ƒedit "BRN-Ph1-1"
โ€ƒโ€ƒset interface "WAN1"
โ€ƒโ€ƒset local-gw 1.1.1.1
โ€ƒโ€ƒset peertype any
โ€ƒโ€ƒset net-device disable
โ€ƒโ€ƒset proposal aes128-sha1
โ€ƒโ€ƒset dhgrp 2
โ€ƒโ€ƒset remote-gw 2.2.2.1
โ€ƒโ€ƒset psksecret ***
โ€ƒnext
โ€ƒedit "BRN-Ph1-2"
โ€ƒโ€ƒset interface "WAN2"
โ€ƒโ€ƒset local-gw 3.3.3.1
โ€ƒโ€ƒset peertype any
โ€ƒโ€ƒset net-device disable
โ€ƒโ€ƒset proposal aes128-sha1
โ€ƒโ€ƒset dhgrp 2
โ€ƒโ€ƒset remote-gw 4.4.4.1
โ€ƒโ€ƒset psksecret ***
โ€ƒnext
end

config vpn ipsec phase2-interface
โ€ƒedit "BRN-Ph2-1"
โ€ƒโ€ƒset phase1name "BRN-Ph1-1"
โ€ƒโ€ƒset proposal aes256-sha256
โ€ƒโ€ƒset dhgrp 2
โ€ƒnext
โ€ƒedit "BRN-Ph2-2"
โ€ƒโ€ƒset phase1name "BRN-Ph1-2"
โ€ƒโ€ƒset proposal aes256-sha256
โ€ƒโ€ƒset dhgrp 2
โ€ƒnext
end

config router static
โ€ƒedit 1
โ€ƒโ€ƒset gateway 1.1.1.2
โ€ƒโ€ƒset device "WAN1"
โ€ƒnext
โ€ƒedit 3
โ€ƒโ€ƒset gateway 3.3.3.2
โ€ƒโ€ƒset device "WAN2"
โ€ƒnext
end

config router bgp
โ€ƒset as 65002
โ€ƒset router-id 10.1.7.1
โ€ƒset ebgp-multipath enable
โ€ƒconfig neighbor
โ€ƒโ€ƒedit "192.168.254.2"
โ€ƒโ€ƒโ€ƒset remote-as 65003
โ€ƒโ€ƒnext
โ€ƒโ€ƒedit "192.168.254.4"
โ€ƒโ€ƒโ€ƒset remote-as 65003
โ€ƒโ€ƒnext
โ€ƒend

โ€ƒconfig network
โ€ƒโ€ƒedit 1
โ€ƒโ€ƒโ€ƒset prefix 10.1.0.0 255.255.0.0
โ€ƒโ€ƒnext
end

config system interface
โ€ƒedit "WAN1"
โ€ƒโ€ƒset vdom "Internet"
โ€ƒโ€ƒset ip 2.2.2.1 255.255.255.252
โ€ƒโ€ƒset allowaccess ping
โ€ƒโ€ƒset role wan
โ€ƒโ€ƒset interface "BRN-BRD"
โ€ƒโ€ƒset vlanid 111
โ€ƒnext
โ€ƒedit "WAN2"
โ€ƒโ€ƒset vdom "Internet"
โ€ƒโ€ƒset ip 4.4.4.1 255.255.255.252
โ€ƒโ€ƒset allowaccess ping
โ€ƒโ€ƒset role wan
โ€ƒโ€ƒset interface "BRN-BRD"
โ€ƒโ€ƒset vlanid 114
โ€ƒnext
โ€ƒedit "DC-Ph1-1"
โ€ƒโ€ƒset vdom "Internet"
โ€ƒโ€ƒset ip 192.168.254.2 255.255.255.255
โ€ƒโ€ƒset allowaccess ping
โ€ƒโ€ƒset type tunnel
โ€ƒโ€ƒset remote-ip 192.168.254.1 255.255.255.255
โ€ƒโ€ƒset interface "WAN1"
โ€ƒnext
โ€ƒedit "DC-Ph1-2"
โ€ƒโ€ƒset vdom "Internet"
โ€ƒโ€ƒset ip 192.168.254.4 255.255.255.255
โ€ƒโ€ƒset allowaccess ping
โ€ƒโ€ƒset type tunnel
โ€ƒโ€ƒset remote-ip 192.168.254.3 255.255.255.255
โ€ƒโ€ƒset interface "WAN2"
โ€ƒnext
end

config vpn ipsec phase1-interface
โ€ƒ edit "DC-Ph1-1"
โ€ƒโ€ƒ set interface "WAN1"
โ€ƒโ€ƒ set local-gw 2.2.2.1
โ€ƒโ€ƒ set peertype any
โ€ƒโ€ƒ set net-device disable
โ€ƒโ€ƒ set proposal aes128-sha1
โ€ƒโ€ƒ set dhgrp 2
โ€ƒโ€ƒ set remote-gw 1.1.1.1
โ€ƒโ€ƒ set psksecret ***
โ€ƒ next
โ€ƒ edit "DC-Ph1-2"
โ€ƒโ€ƒ set interface "WAN2"
โ€ƒโ€ƒ set local-gw 4.4.4.1
โ€ƒโ€ƒ set peertype any
โ€ƒโ€ƒ set net-device disable
โ€ƒโ€ƒ set proposal aes128-sha1
โ€ƒโ€ƒ set dhgrp 2
โ€ƒโ€ƒ set remote-gw 3.3.3.1
โ€ƒโ€ƒ set psksecret ***
โ€ƒ next
end

config vpn ipsec phase2-interface
โ€ƒ edit "DC-Ph2-1"
โ€ƒโ€ƒ set phase1name "DC-Ph1-1"
โ€ƒโ€ƒ set proposal aes128-sha1
โ€ƒโ€ƒ set dhgrp 2
โ€ƒ next
โ€ƒ edit "DC2-Ph2-2"
โ€ƒโ€ƒ set phase1name "DC-Ph1-2"
โ€ƒโ€ƒ set proposal aes128-sha1
โ€ƒโ€ƒ set dhgrp 2
โ€ƒ next
end

config router static
โ€ƒedit 1
โ€ƒโ€ƒset gateway 2.2.2.2
โ€ƒโ€ƒet device "WAN1"
โ€ƒnext
โ€ƒedit 3
โ€ƒโ€ƒset gateway 4.4.4.2
โ€ƒโ€ƒset device "WAN2"
โ€ƒnext
end

config router bgp
โ€ƒ set as 65003
โ€ƒ set router-id 10.200.7.1
โ€ƒ set ebgp-multipath enable
โ€ƒ config neighbor
โ€ƒโ€ƒ edit "192.168.254.1"
โ€ƒโ€ƒโ€ƒ set remote-as 65002
โ€ƒโ€ƒ next
โ€ƒโ€ƒedit "192.168.254.3"
โ€ƒโ€ƒโ€ƒset remote-as 65002
โ€ƒโ€ƒ next
โ€ƒ end

โ€ƒ config network
โ€ƒโ€ƒ edit 1
โ€ƒโ€ƒโ€ƒ set prefix 10.200.0.0 255.255.0.0
โ€ƒ โ€ƒnext
end

ืื ื™ ืžืกืคืง ืืช ื”ืชืฆื•ืจื” ื‘ืฆื•ืจืช ื˜ืงืกื˜, ืžื›ื™ื•ื•ืŸ ืฉืœื“ืขืชื™ ื ื•ื— ื™ื•ืชืจ ืœื”ื’ื“ื™ืจ ืืช ื”-VPN ื‘ืฆื•ืจื” ื–ื•. ื›ืžืขื˜ ื›ืœ ื”ื”ื’ื“ืจื•ืช ื–ื”ื•ืช ืžืฉื ื™ ื”ืฆื“ื“ื™ื; ื‘ืฆื•ืจืช ื˜ืงืกื˜ ื ื™ืชืŸ ืœื‘ืฆืข ืื•ืชืŸ ื›ื”ืขืชืง-ื”ื“ื‘ืง. ืื ืืชื” ืขื•ืฉื” ืืช ืื•ืชื• ื”ื“ื‘ืจ ื‘ืžืžืฉืง ื”ืื™ื ื˜ืจื ื˜, ืงืœ ืœื˜ืขื•ืช - ืฉื›ื— ืื™ืคืฉื”ื• ืกื™ืžืŸ ื‘ื™ืงื•ืจืช, ื”ื–ืŸ ืืช ื”ืขืจืš ื”ืœื ื ื›ื•ืŸ.

ืœืื—ืจ ืฉื”ื•ืกืคื ื• ืืช ื”ืžืžืฉืงื™ื ืœื—ื‘ื™ืœื”

ื ื™ืชื•ื— ืฉืœ ื”-SD-WAN ื”ื“ืžื•ืงืจื˜ื™ ื‘ื™ื•ืชืจ: ืืจื›ื™ื˜ืงื˜ื•ืจื”, ืชืฆื•ืจื”, ื ื™ื”ื•ืœ ื•ืžืœื›ื•ื“ื•ืช

ื›ืœ ื”ืžืกืœื•ืœื™ื ื•ืžื“ื™ื ื™ื•ืช ื”ืื‘ื˜ื—ื” ื™ื›ื•ืœื™ื ืœื”ืชื™ื™ื—ืก ืืœื™ื•, ื•ืœื ืœืžืžืฉืงื™ื ื”ื›ืœื•ืœื™ื ื‘ื•. ืœื›ืœ ื”ืคื—ื•ืช, ืขืœื™ืš ืœืืคืฉืจ ืชืขื‘ื•ืจื” ืžืจืฉืชื•ืช ืคื ื™ืžื™ื•ืช ืœ-SD-WAN. ื›ืืฉืจ ืืชื” ื™ื•ืฆืจ ืขื‘ื•ืจื ื›ืœืœื™ื, ืืชื” ื™ื›ื•ืœ ืœื”ื—ื™ืœ ืืžืฆืขื™ ื”ื’ื ื” ื›ื’ื•ืŸ IPS, ืื ื˜ื™ ื•ื™ืจื•ืก ื•ื’ื™ืœื•ื™ HTTPS.

ื ื™ืชื•ื— ืฉืœ ื”-SD-WAN ื”ื“ืžื•ืงืจื˜ื™ ื‘ื™ื•ืชืจ: ืืจื›ื™ื˜ืงื˜ื•ืจื”, ืชืฆื•ืจื”, ื ื™ื”ื•ืœ ื•ืžืœื›ื•ื“ื•ืช

ื›ืœืœื™ SD-WAN ืžื•ื’ื“ืจื™ื ืขื‘ื•ืจ ื”ื—ื‘ื™ืœื”. ืืœื• ื›ืœืœื™ื ื”ืžื’ื“ื™ืจื™ื ืืช ืืœื’ื•ืจื™ืชื ื”ืื™ื–ื•ืŸ ืขื‘ื•ืจ ืชืขื‘ื•ืจื” ืกืคืฆื™ืคื™ืช. ื”ื ื“ื•ืžื™ื ืœืžื“ื™ื ื™ื•ืช ื ื™ืชื•ื‘ ื‘ื ื™ืชื•ื‘ ืžื‘ื•ืกืก-ืžื“ื™ื ื™ื•ืช, ืจืง ื›ืชื•ืฆืื” ืžืชืขื‘ื•ืจื” ืฉื ื•ืคืœืช ืชื—ืช ื”ืžื“ื™ื ื™ื•ืช, ืœื ืžื•ืชืงืŸ ื”-Next-Hop ืื• ื”ืžืžืฉืง ื”ื™ื•ืฆื ื”ืจื’ื™ืœ, ืืœื ื”ืžืžืฉืงื™ื ืฉื ื•ืกืคื• ืœื—ื‘ื™ืœืช SD-WAN plus ืืœื’ื•ืจื™ืชื ืื™ื–ื•ืŸ ืชืขื‘ื•ืจื” ื‘ื™ืŸ ื”ืžืžืฉืงื™ื ื”ืœืœื•.

ื ื™ืชืŸ ืœื”ืคืจื™ื“ ืืช ื”ืชื ื•ืขื” ืžื”ื–ืจื™ืžื” ื”ื›ืœืœื™ืช ืขืœ ื™ื“ื™ ืžื™ื“ืข L3-L4, ืขืœ ื™ื“ื™ ื™ื™ืฉื•ืžื™ื ืžื•ื›ืจื™ื, ืฉื™ืจื•ืชื™ ืื™ื ื˜ืจื ื˜ (URL ื•-IP), ื•ื›ืŸ ืขืœ ื™ื“ื™ ืžืฉืชืžืฉื™ื ืžื•ื›ืจื™ื ืฉืœ ืชื—ื ื•ืช ืขื‘ื•ื“ื” ื•ืžื—ืฉื‘ื™ื ื ื™ื™ื“ื™ื. ืœืื—ืจ ืžื›ืŸ, ื ื™ืชืŸ ืœื”ืงืฆื•ืช ืื—ื“ ืžืืœื’ื•ืจื™ืชืžื™ ื”ืื™ื–ื•ืŸ ื”ื‘ืื™ื ืœืชืขื‘ื•ืจื” ืฉื”ื•ืงืฆืชื”:

ื ื™ืชื•ื— ืฉืœ ื”-SD-WAN ื”ื“ืžื•ืงืจื˜ื™ ื‘ื™ื•ืชืจ: ืืจื›ื™ื˜ืงื˜ื•ืจื”, ืชืฆื•ืจื”, ื ื™ื”ื•ืœ ื•ืžืœื›ื•ื“ื•ืช

ื‘ืจืฉื™ืžื” ื”ืขื“ืคื•ืช ืžืžืฉืง, ื ื‘ื—ืจื™ื ืื•ืชื ืžืžืฉืงื™ื ืžืืœื” ืฉื›ื‘ืจ ื ื•ืกืคื• ืœื—ื‘ื™ืœื” ืฉื™ืฉืจืชื• ืกื•ื’ ื–ื” ืฉืœ ืชืขื‘ื•ืจื”. ืขืœ ื™ื“ื™ ื”ื•ืกืคืช ืœื ืืช ื›ืœ ื”ืžืžืฉืงื™ื, ืืชื” ื™ื›ื•ืœ ืœื”ื’ื‘ื™ืœ ื‘ื“ื™ื•ืง ื‘ืื™ืœื• ืขืจื•ืฆื™ื ืืชื” ืžืฉืชืžืฉ, ืœืžืฉืœ, ื‘ื“ื•ื"ืœ, ืื ืืชื” ืœื ืจื•ืฆื” ืœื”ืขืžื™ืก ืขืœ ืขืจื•ืฆื™ื ื™ืงืจื™ื ืขื SLA ื’ื‘ื•ื”. ื‘-FortiOS 6.4.1, ื”ืชืืคืฉืจ ืœืงื‘ืฅ ืžืžืฉืงื™ื ืฉื ื•ืกืคื• ืœื—ื‘ื™ืœืช ื”-SD-WAN ืœืื–ื•ืจื™ื, ื•ืœื™ืฆื•ืจ, ืœืžืฉืœ, ืื–ื•ืจ ืื—ื“ ืœืชืงืฉื•ืจืช ืขื ืืชืจื™ื ืžืจื•ื—ืงื™ื, ื•ืื—ืจ ืœื’ื™ืฉื” ืœืื™ื ื˜ืจื ื˜ ืžืงื•ืžื™ ื‘ืืžืฆืขื•ืช NAT. ื›ืŸ, ื›ืŸ, ื’ื ืชืขื‘ื•ืจื” ืฉืขื•ื‘ืจืช ืœืื™ื ื˜ืจื ื˜ ื”ืจื’ื™ืœ ื™ื›ื•ืœื” ืœื”ื™ื•ืช ืžืื•ื–ื ืช.

ืขืœ ืืœื’ื•ืจื™ืชืžื™ ืื™ื–ื•ืŸ

ืœื’ื‘ื™ ื”ืื•ืคืŸ ืฉื‘ื• Fortigate (ื—ื•ืžืช ืืฉ ืž-Fortinet) ื™ื›ื•ืœื” ืœืคืฆืœ ืชืขื‘ื•ืจื” ื‘ื™ืŸ ืขืจื•ืฆื™ื, ื™ืฉื ืŸ ืฉืชื™ ืืคืฉืจื•ื™ื•ืช ืžืขื ื™ื™ื ื•ืช ืฉืื™ื ืŸ ื ืคื•ืฆื•ืช ื‘ืžื™ื•ื—ื“ ื‘ืฉื•ืง:

ื”ืขืœื•ืช ื”ื ืžื•ื›ื” ื‘ื™ื•ืชืจ (SLA) โ€“ ืžื‘ื™ืŸ ื›ืœ ื”ืžืžืฉืงื™ื ื”ืขื•ื ื™ื ืขืœ ื”-SLA ื›ืจื’ืข, ื ื‘ื—ืจ ื–ื” ื‘ืขืœ ื”ืžืฉืงืœ ื”ื ืžื•ืš (ื”ืขืœื•ืช), ืฉื ืงื‘ืข ื™ื“ื ื™ืช ืขืœ ื™ื“ื™ ื”ืžื ื”ืœ; ืžืฆื‘ ื–ื” ืžืชืื™ื ืœืชืขื‘ื•ืจื” "ื‘ื›ืžื•ืช ื’ื“ื•ืœื”" ื›ื’ื•ืŸ ื’ื™ื‘ื•ื™ื™ื ื•ื”ืขื‘ืจืช ืงื‘ืฆื™ื.

ื”ืื™ื›ื•ืช ื”ื˜ื•ื‘ื” ื‘ื™ื•ืชืจ (SLA) - ืืœื’ื•ืจื™ืชื ื–ื”, ื‘ื ื•ืกืฃ ืœืขื™ื›ื•ื‘ ื”ืจื’ื™ืœ, ืจื™ืฆื•ื“ ื•ืื•ื‘ื“ืŸ ืฉืœ ืžื ื•ืช Fortigate, ื™ื›ื•ืœ ื’ื ืœื”ืฉืชืžืฉ ื‘ืขื•ืžืก ื”ืขืจื•ืฅ ื”ื ื•ื›ื—ื™ ื›ื“ื™ ืœื”ืขืจื™ืš ืืช ืื™ื›ื•ืช ื”ืขืจื•ืฆื™ื; ืžืฆื‘ ื–ื” ืžืชืื™ื ืœืชืขื‘ื•ืจื” ืจื’ื™ืฉื” ื›ื’ื•ืŸ VoIP ื•ืฉื™ื—ื•ืช ื•ืขื™ื“ื” ื‘ื•ื•ื™ื“ืื•.

ืืœื’ื•ืจื™ืชืžื™ื ืืœื• ื“ื•ืจืฉื™ื ื”ื’ื“ืจืช ืžื“ ื‘ื™ืฆื•ืขื™ื ืฉืœ ืขืจื•ืฅ ืชืงืฉื•ืจืช - Performance SLA. ืžื“ ื–ื” ืขื•ืงื‘ ืžืขืช ืœืขืช (ืžืจื•ื•ื— ื‘ื“ื™ืงื”) ืžื™ื“ืข ืขืœ ืขืžื™ื“ื” ื‘-SLA: ืื•ื‘ื“ืŸ ืžื ื•ืช, ืขื™ื›ื•ื‘ (ืฉื”ื™ื™ื”) ื•ืจื™ืฆื•ื“ (ืจื™ืฆื•ื“) ื‘ืขืจื•ืฅ ื”ืชืงืฉื•ืจืช, ื•ื™ื›ื•ืœ "ืœื“ื—ื•ืช" ืืช ืื•ืชื ืขืจื•ืฆื™ื ืฉื›ืจื’ืข ืื™ื ื ืขื•ืžื“ื™ื ื‘ืกืคื™ ื”ืื™ื›ื•ืช - ื”ื ืžืื‘ื“ื™ื ื™ื•ืชืจ ืžื“ื™ ืžื ื•ืช ืื• ื—ื•ื•ื™ืช ื–ืžืŸ ืื—ื–ื•ืจ ืจื‘ ืžื“ื™. ื‘ื ื•ืกืฃ, ื”ืžื“ ืขื•ืงื‘ ืื—ืจ ืžืฆื‘ ื”ืขืจื•ืฅ, ื•ื™ื›ื•ืœ ืœื”ืกื™ืจ ืื•ืชื• ื‘ืื•ืคืŸ ื–ืžื ื™ ืžื”ืฆืจื•ืจ ื‘ืžืงืจื” ืฉืœ ืื•ื‘ื“ืŸ ื—ื•ื–ืจ ืฉืœ ืชื’ื•ื‘ื•ืช (ื›ืฉืœื™ื ืœืคื ื™ ื—ื•ืกืจ ืคืขื™ืœื•ืช). ืœืื—ืจ ื”ืฉื—ื–ื•ืจ, ืœืื—ืจ ืžืกืคืจ ืชื’ื•ื‘ื•ืช ืจืฆื•ืคื•ืช (ืฉื—ื–ื•ืจ ืงื™ืฉื•ืจ ืœืื—ืจ), ื”ืžื“ ื™ื—ื–ื™ืจ ืื•ื˜ื•ืžื˜ื™ืช ืืช ื”ืขืจื•ืฅ ืœืฆืจื•ืจ, ื•ื”ื ืชื•ื ื™ื ื™ืชื—ื™ืœื• ืœื”ื™ื•ืช ืžืฉื•ื“ืจื™ื ื“ืจื›ื• ืฉื•ื‘.

ื›ืš ื ืจืื™ืช ื”ื’ื“ืจืช "ืžื˜ืจ":

ื ื™ืชื•ื— ืฉืœ ื”-SD-WAN ื”ื“ืžื•ืงืจื˜ื™ ื‘ื™ื•ืชืจ: ืืจื›ื™ื˜ืงื˜ื•ืจื”, ืชืฆื•ืจื”, ื ื™ื”ื•ืœ ื•ืžืœื›ื•ื“ื•ืช

ื‘ืžืžืฉืง ื”ืื™ื ื˜ืจื ื˜, ICMP-Echo-request, HTTP-GET ื•ื‘ืงืฉืช DNS ื–ืžื™ื ื™ื ื›ืคืจื•ื˜ื•ืงื•ืœื™ ื‘ื“ื™ืงื”. ื™ืฉ ืขื•ื“ ืงืฆืช ืืคืฉืจื•ื™ื•ืช ื‘ืฉื•ืจืช ื”ืคืงื•ื“ื”: ืืคืฉืจื•ื™ื•ืช TCP-echo ื•-UDP-echo ื–ืžื™ื ื•ืช, ื›ืžื• ื’ื ืคืจื•ื˜ื•ืงื•ืœ ืžื“ื™ื“ืช ืื™ื›ื•ืช ืžื™ื•ื—ื“ - TWAMP.

ื ื™ืชื•ื— ืฉืœ ื”-SD-WAN ื”ื“ืžื•ืงืจื˜ื™ ื‘ื™ื•ืชืจ: ืืจื›ื™ื˜ืงื˜ื•ืจื”, ืชืฆื•ืจื”, ื ื™ื”ื•ืœ ื•ืžืœื›ื•ื“ื•ืช

ืืช ืชื•ืฆืื•ืช ื”ืžื“ื™ื“ื” ื ื™ืชืŸ ืœืจืื•ืช ื’ื ื‘ืžืžืฉืง ื”ืื™ื ื˜ืจื ื˜:

ื ื™ืชื•ื— ืฉืœ ื”-SD-WAN ื”ื“ืžื•ืงืจื˜ื™ ื‘ื™ื•ืชืจ: ืืจื›ื™ื˜ืงื˜ื•ืจื”, ืชืฆื•ืจื”, ื ื™ื”ื•ืœ ื•ืžืœื›ื•ื“ื•ืช

ื•ื‘ืฉื•ืจืช ื”ืคืงื•ื“ื”:

ื ื™ืชื•ื— ืฉืœ ื”-SD-WAN ื”ื“ืžื•ืงืจื˜ื™ ื‘ื™ื•ืชืจ: ืืจื›ื™ื˜ืงื˜ื•ืจื”, ืชืฆื•ืจื”, ื ื™ื”ื•ืœ ื•ืžืœื›ื•ื“ื•ืช

ืคืชืจื•ืŸ ืชืงืœื•ืช

ืื ื™ืฆืจืช ื›ืœืœ, ืื‘ืœ ื”ื›ืœ ืœื ืขื•ื‘ื“ ื›ืžืฆื•ืคื”, ืขืœื™ืš ืœื”ืกืชื›ืœ ืขืœ ืขืจืš ืกืคื™ืจืช ื”ื”ื™ื˜ ื‘ืจืฉื™ืžืช ื›ืœืœื™ SD-WAN. ื–ื” ื™ืจืื” ืื โ€‹โ€‹ื”ืชื ื•ืขื” ื ื•ืคืœืช ื‘ื›ืœืœ ื–ื”:

ื ื™ืชื•ื— ืฉืœ ื”-SD-WAN ื”ื“ืžื•ืงืจื˜ื™ ื‘ื™ื•ืชืจ: ืืจื›ื™ื˜ืงื˜ื•ืจื”, ืชืฆื•ืจื”, ื ื™ื”ื•ืœ ื•ืžืœื›ื•ื“ื•ืช

ื‘ืขืžื•ื“ ื”ื”ื’ื“ืจื•ืช ืฉืœ ื”ืžื“ ืขืฆืžื•, ื ื™ืชืŸ ืœืจืื•ืช ืืช ื”ืฉื™ื ื•ื™ ื‘ืคืจืžื˜ืจื™ ื”ืขืจื•ืฅ ืœืื•ืจืš ื–ืžืŸ. ื”ืงื• ื”ืžืงื•ื•ืงื• ืžืฆื™ื™ืŸ ืืช ืขืจืš ื”ืกืฃ ืฉืœ ื”ืคืจืžื˜ืจ

ื ื™ืชื•ื— ืฉืœ ื”-SD-WAN ื”ื“ืžื•ืงืจื˜ื™ ื‘ื™ื•ืชืจ: ืืจื›ื™ื˜ืงื˜ื•ืจื”, ืชืฆื•ืจื”, ื ื™ื”ื•ืœ ื•ืžืœื›ื•ื“ื•ืช

ื‘ืžืžืฉืง ื”ืื™ื ื˜ืจื ื˜ ื ื™ืชืŸ ืœืจืื•ืช ื›ื™ืฆื“ ื”ืชืขื‘ื•ืจื” ืžืชืคื–ืจืช ืœืคื™ ื›ืžื•ืช ื”ื ืชื•ื ื™ื ื”ืžื•ืขื‘ืจื™ื/ืžืชืงื‘ืœื™ื ื•ืžืกืคืจ ื”ืคืขืœื•ืช:

ื ื™ืชื•ื— ืฉืœ ื”-SD-WAN ื”ื“ืžื•ืงืจื˜ื™ ื‘ื™ื•ืชืจ: ืืจื›ื™ื˜ืงื˜ื•ืจื”, ืชืฆื•ืจื”, ื ื™ื”ื•ืœ ื•ืžืœื›ื•ื“ื•ืช

ื‘ื ื•ืกืฃ ืœื›ืœ ื–ื”, ื™ืฉื ื” ื”ื–ื“ืžื ื•ืช ืžืฆื•ื™ื ืช ืœืขืงื•ื‘ ืื—ืจ ืžืขื‘ืจ ืžื ื•ืช ื‘ืคื™ืจื•ื˜ ืžื™ืจื‘ื™. ื›ืืฉืจ ืขื•ื‘ื“ื™ื ื‘ืจืฉืช ืืžื™ืชื™ืช, ืชืฆื•ืจืช ื”ืžื›ืฉื™ืจ ืฆื•ื‘ืจืช ืžื“ื™ื ื™ื•ืช ื ื™ืชื•ื‘, ื—ื•ืžืช ืืฉ ื•ื”ืคืฆืช ืชื ื•ืขื” ืขืœ ืคื ื™ ื™ืฆื™ืื•ืช SD-WAN ืจื‘ื•ืช. ื›ืœ ื–ื” ืžืงื™ื™ื ืื™ื ื˜ืจืืงืฆื™ื” ื–ื” ืขื ื–ื” ื‘ืฆื•ืจื” ืžื•ืจื›ื‘ืช, ื•ืœืžืจื•ืช ืฉื”ืกืคืง ืžืกืคืง ื“ื™ืื’ืจืžื•ืช ื‘ืœื•ืง ืžืคื•ืจื˜ื•ืช ืฉืœ ืืœื’ื•ืจื™ืชืžื™ ืขื™ื‘ื•ื“ ืžื ื•ืช, ื—ืฉื•ื‘ ืžืื•ื“ ืœื”ื™ื•ืช ืžืกื•ื’ืœื™ื ืœื ืœื‘ื ื•ืช ื•ืœื‘ื“ื•ืง ืชื™ืื•ืจื™ื•ืช, ืืœื ืœืจืื•ืช ืœืืŸ ื”ืชื ื•ืขื” ื‘ืืžืช ื”ื•ืœื›ืช.

ืœื“ื•ื’ืžื”, ืงื‘ื•ืฆืช ื”ืคืงื•ื“ื•ืช ื”ื‘ืื”

diagnose debug flow filter saddr 10.200.64.15
diagnose debug flow filter daddr 10.1.7.2
diagnose debug flow show function-name
diagnose debug enable
diagnose debug trace 2

ืžืืคืฉืจ ืœืš ืœืขืงื•ื‘ ืื—ืจ ืฉืชื™ ืžื ื•ืช ืขื ื›ืชื•ื‘ืช ืžืงื•ืจ ืฉืœ 10.200.64.15 ื•ื›ืชื•ื‘ืช ื™ืขื“ ืฉืœ 10.1.7.2.
ืื ื—ื ื• ืขื•ืฉื™ื ืคื™ื ื’ 10.7.1.2 ืžืชืืจื™ืš 10.200.64.15 ืคืขืžื™ื™ื ื•ืžืกืชื›ืœื™ื ืขืœ ื”ืคืœื˜ ื‘ืงื•ื ืกื•ืœื”.

ื—ื‘ื™ืœื” ืจืืฉื•ื ื”:

ื ื™ืชื•ื— ืฉืœ ื”-SD-WAN ื”ื“ืžื•ืงืจื˜ื™ ื‘ื™ื•ืชืจ: ืืจื›ื™ื˜ืงื˜ื•ืจื”, ืชืฆื•ืจื”, ื ื™ื”ื•ืœ ื•ืžืœื›ื•ื“ื•ืช

ื—ื‘ื™ืœื” ืฉื ื™ื™ื”:

ื ื™ืชื•ื— ืฉืœ ื”-SD-WAN ื”ื“ืžื•ืงืจื˜ื™ ื‘ื™ื•ืชืจ: ืืจื›ื™ื˜ืงื˜ื•ืจื”, ืชืฆื•ืจื”, ื ื™ื”ื•ืœ ื•ืžืœื›ื•ื“ื•ืช

ื”ื ื” ื”ื—ื‘ื™ืœื” ื”ืจืืฉื•ื ื” ืฉื”ืชืงื‘ืœื” ืขืœ ื™ื“ื™ ื—ื•ืžืช ื”ืืฉ:
id=20085 trace_id=475 func=print_pkt_detail line=5605 msg="vd-Internet:0 received a packet(proto=1, 10.200.64.15:42->10.1.7.2:2048) from DMZ-Office. type=8, code=0, id=42, seq=0."
VDOM โ€“ Internet, Proto=1 (ICMP), DMZ-Office โ€“ ะฝะฐะทะฒะฐะฝะธะต L3-ะธะฝั‚ะตั€ั„ะตะนัะฐ. Type=8 โ€“ Echo.

ืžืคื’ืฉ ื—ื“ืฉ ื ื•ืฆืจ ืขื‘ื•ืจื•:
msg="allocate a new session-0006a627"

ื•ื ืžืฆืื” ื”ืชืืžื” ื‘ื”ื’ื“ืจื•ืช ืžื“ื™ื ื™ื•ืช ื”ื ื™ืชื•ื‘
msg="Match policy routing id=2136539137: to 10.1.7.2 via ifindex-110"

ืžืกืชื‘ืจ ืฉืฆืจื™ืš ืœืฉืœื•ื— ืืช ื”ื—ื‘ื™ืœื” ืœืื—ืช ืžืžื ื”ืจื•ืช ื”-VPN:
"find a route: flag=04000000 gw-192.168.254.1 via DC-Ph1-1"

ื›ืœืœ ื”ื”ืจืฉืื” ื”ื‘ื ืžื–ื•ื”ื” ื‘ืžื“ื™ื ื™ื•ืช ื—ื•ืžืช ื”ืืฉ:
msg="Allowed by Policy-3:"

ื”ื—ื‘ื™ืœื” ืžื•ืฆืคื ืช ื•ื ืฉืœื—ืช ืœืžื ื”ืจืช ื”-VPN:
func=ipsecdev_hard_start_xmit line=789 msg="enter IPsec interface-DC-Ph1-1"
func=_ipsecdev_hard_start_xmit line=666 msg="IPsec tunnel-DC-Ph1-1"
func=esp_output4 line=905 msg="IPsec encrypt/auth"

ื”ื—ื‘ื™ืœื” ื”ืžื•ืฆืคื ืช ื ืฉืœื—ืช ืœื›ืชื•ื‘ืช ื”ืฉืขืจ ืขื‘ื•ืจ ืžืžืฉืง WAN ื–ื”:
msg="send to 2.2.2.2 via intf-WAN1"

ืขื‘ื•ืจ ื”ื—ื‘ื™ืœื” ื”ืฉื ื™ื™ื”, ื”ื›ืœ ืงื•ืจื” ื‘ืื•ืคืŸ ื“ื•ืžื”, ืื‘ืœ ื”ื™ื ื ืฉืœื—ืช ืœืžื ื”ืจืช VPN ืื—ืจืช ื•ื™ื•ืฆืืช ื“ืจืš ื™ืฆื™ืืช ื—ื•ืžืช ืืฉ ืื—ืจืช:
func=ipsecdev_hard_start_xmit line=789 msg="enter IPsec interface-DC-Ph1-2"
func=_ipsecdev_hard_start_xmit line=666 msg="IPsec tunnel-DC-Ph1-2"
func=esp_output4 line=905 msg="IPsec encrypt/auth"
func=ipsec_output_finish line=622 msg="send to 4.4.4.2 via intf-WAN2"

ื”ื™ืชืจื•ื ื•ืช ืฉืœ ื”ืคืชืจื•ืŸ

ืคื•ื ืงืฆื™ื•ื ืœื™ื•ืช ืืžื™ื ื” ื•ืžืžืฉืง ื™ื“ื™ื“ื•ืชื™ ืœืžืฉืชืžืฉ. ืžืขืจืš ื”ืชื›ื•ื ื•ืช ืฉื”ื™ื” ื–ืžื™ืŸ ื‘-FortiOS ืœืคื ื™ ื”ื•ืคืขืช ื”-SD-WAN ื ืฉืžืจ ื‘ืžืœื•ืื•. ื›ืœื•ืžืจ, ืื™ืŸ ืœื ื• ืชื•ื›ื ื” ื—ื“ืฉื” ืฉืคื•ืชื—ื”, ืืœื ืžืขืจื›ืช ื‘ื•ื’ืจืช ืฉืœ ืกืคืง ื—ื•ืžืช ืืฉ ืžื•ื›ื—. ืขื ืกื˜ ืžืกื•ืจืชื™ ืฉืœ ืคื•ื ืงืฆื™ื•ืช ืจืฉืช, ืžืžืฉืง ืื™ื ื˜ืจื ื˜ ื ื•ื— ื•ืงืœ ืœืœืžื™ื“ื”. ืœื›ืžื” ืกืคืงื™ SD-WAN ื™ืฉ, ืœืžืฉืœ, ืคื•ื ืงืฆื™ื•ื ืœื™ื•ืช VPN ืฉืœ ื’ื™ืฉื” ืžืจื—ื•ืง ื‘ืžื›ืฉื™ืจื™ ืงืฆื”?

ืจืžืช ืื‘ื˜ื—ื” 80. FortiGate ื”ื•ื ืื—ื“ ืžืคืชืจื•ื ื•ืช ื—ื•ืžืช ื”ืืฉ ื”ืžื•ื‘ื™ืœื™ื. ื™ืฉ ื”ืจื‘ื” ื—ื•ืžืจ ื‘ืื™ื ื˜ืจื ื˜ ืขืœ ื”ืงืžื” ื•ื ื™ื”ื•ืœ ืฉืœ ื—ื•ืžื•ืช ืืฉ, ื•ื‘ืฉื•ืง ื”ืขื‘ื•ื“ื” ื™ืฉ โ€‹โ€‹ื”ืจื‘ื” ืžื•ืžื—ื™ ืื‘ื˜ื—ื” ืฉื›ื‘ืจ ืฉื•ืœื˜ื™ื ื‘ืคืชืจื•ื ื•ืช ืฉืœ ื”ืกืคืง.

ืžื—ื™ืจ ืืคืก ืขื‘ื•ืจ ืคื•ื ืงืฆื™ื•ื ืœื™ื•ืช SD-WAN. ื‘ื ื™ื™ืช ืจืฉืช SD-WAN ื‘-FortiGate ืขื•ืœื” ื›ืžื• ื‘ื ื™ื™ืช ืจืฉืช WAN ืจื’ื™ืœื” ืขืœื™ื”, ืžื›ื™ื•ื•ืŸ ืฉืื™ืŸ ืฆื•ืจืš ื‘ืจื™ืฉื™ื•ื ื•ืช ื ื•ืกืคื™ื ื›ื“ื™ ืœื™ื™ืฉื ืคื•ื ืงืฆื™ื•ื ืœื™ื•ืช SD-WAN.

ืžื—ื™ืจ ื—ืกื ื›ื ื™ืกื” ื ืžื•ืš. ืœ-Fortigate ื™ืฉ ื”ื“ืจื’ื” ื˜ื•ื‘ื” ืฉืœ ืžื›ืฉื™ืจื™ื ืขื‘ื•ืจ ืจืžื•ืช ื‘ื™ืฆื•ืขื™ื ืฉื•ื ื•ืช. ื”ื“ื’ืžื™ื ื”ืฆืขื™ืจื™ื ื•ื”ื–ื•ืœื™ื ื‘ื™ื•ืชืจ ืžืชืื™ืžื™ื ืœืžื“ื™ ืœื”ืจื—ื‘ืช ืžืฉืจื“ ืื• ื ืงื•ื“ืช ืžื›ื™ืจื” ืขืœ ื™ื“ื™, ืœืžืฉืœ, 3-5 ืขื•ื‘ื“ื™ื. ืœืกืคืงื™ื ืจื‘ื™ื ืคืฉื•ื˜ ืื™ืŸ ื“ื’ืžื™ื ื‘ืขืœื™ ื‘ื™ืฆื•ืขื™ื ื ืžื•ื›ื™ื ื•ื‘ืžื—ื™ืจ ืกื‘ื™ืจ.

ื‘ื™ืฆื•ืขื™ื ื’ื‘ื•ื”ื™ื. ื”ืคื—ืชืช ืคื•ื ืงืฆื™ื•ื ืœื™ื•ืช SD-WAN ืœืื™ื–ื•ืŸ ืชืขื‘ื•ืจื” ืืคืฉืจื” ืœื—ื‘ืจื” ืœืฉื—ืจืจ SD-WAN ASIC ืžื™ื•ื—ื“, ืฉื‘ื–ื›ื•ืชื• ืคืขื•ืœืช SD-WAN ืื™ื ื” ืžืคื—ื™ืชื” ืืช ื‘ื™ืฆื•ืขื™ ื—ื•ืžืช ื”ืืฉ ื‘ื›ืœืœื•ืชื”.

ื”ื™ื›ื•ืœืช ืœื™ื™ืฉื ืžืฉืจื“ ืฉืœื ืขืœ ืฆื™ื•ื“ Fortinet. ืืœื• ื”ื ื–ื•ื’ ื—ื•ืžื•ืช ืืฉ, ืžืชื’ื™ื, ื ืงื•ื“ื•ืช ื’ื™ืฉื” ืœ-Wi-Fi. ืžืฉืจื“ ื›ื–ื” ืงืœ ื•ื ื•ื— ืœื ื™ื”ื•ืœ - ืžืชื’ื™ื ื•ื ืงื•ื“ื•ืช ื’ื™ืฉื” ื ืจืฉืžื™ื ืขืœ ื—ื•ืžื•ืช ืืฉ ื•ืžื ื•ื”ืœื™ื ืžื”ื. ืœื“ื•ื’ืžื”, ื›ืš ืขืฉื•ื™ื” ืœื”ื™ืจืื•ืช ื™ืฆื™ืืช ืžืชื’ ืžืžืžืฉืง ื—ื•ืžืช ื”ืืฉ ืฉืฉื•ืœื˜ ื‘ืžืชื’ ื–ื”:

ื ื™ืชื•ื— ืฉืœ ื”-SD-WAN ื”ื“ืžื•ืงืจื˜ื™ ื‘ื™ื•ืชืจ: ืืจื›ื™ื˜ืงื˜ื•ืจื”, ืชืฆื•ืจื”, ื ื™ื”ื•ืœ ื•ืžืœื›ื•ื“ื•ืช

ื—ื•ืกืจ ื‘ืงืจื™ื ื›ื ืงื•ื“ืช ื›ืฉืœ ืื—ืช. ื”ืกืคืง ืขืฆืžื• ืžืชืžืงื“ ื‘ื›ืš, ืื‘ืœ ื–ื” ื™ื›ื•ืœ ืœื”ื™ืงืจื ืจืง ื™ืชืจื•ืŸ ื—ืœืงื™, ื›ื™ ืขื‘ื•ืจ ืื•ืชื ืกืคืงื™ื ืฉื™ืฉ ืœื”ื ื‘ืงืจื™ื, ื”ื‘ื˜ื—ืช ืกื•ื‘ืœื ื•ืช ื”ืชืงืœื•ืช ืฉืœื”ื ื”ื™ื ื–ื•ืœื”, ืœืจื•ื‘ ื‘ืžื—ื™ืจ ืฉืœ ื›ืžื•ืช ืงื˜ื ื” ืฉืœ ืžืฉืื‘ื™ ืžื—ืฉื•ื‘ ื‘ืกื‘ื™ื‘ืช ื•ื™ืจื˜ื•ืืœื™ื–ืฆื™ื”.

ืžื” ืœื—ืคืฉ

ืื™ืŸ ื”ืคืจื“ื” ื‘ื™ืŸ ืžื™ืฉื•ืจ ื‘ืงืจื” ืœืžื™ืฉื•ืจ ื ืชื•ื ื™ื. ื”ืžืฉืžืขื•ืช ื”ื™ื ืฉื™ืฉ ืœื”ื’ื“ื™ืจ ืืช ื”ืจืฉืช ื‘ืื•ืคืŸ ื™ื“ื ื™ ืื• ื‘ืืžืฆืขื•ืช ื›ืœื™ ื”ื ื™ื”ื•ืœ ื”ืžืกื•ืจืชื™ื™ื ืฉื›ื‘ืจ ื–ืžื™ื ื™ื - FortiManager. ืขื‘ื•ืจ ืกืคืงื™ื ืฉื”ื˜ืžื™ืขื• ื”ืคืจื“ื” ื›ื–ื•, ื”ืจืฉืช ืžื•ืจื›ื‘ืช ื‘ืขืฆืžื”. ื™ื›ื•ืœ ืœื”ื™ื•ืช ืฉื”ืžื ื”ืœ ืฆืจื™ืš ืจืง ืœื”ืชืื™ื ืืช ื”ื˜ื•ืคื•ืœื•ื’ื™ื” ืฉืœื•, ืœืืกื•ืจ ืžืฉื”ื• ืื™ืคืฉื”ื•, ืœื ื™ื•ืชืจ. ืขื ื–ืืช, ื›ืจื˜ื™ืก ื”ืžื ืฆื— ืฉืœ FortiManager ื”ื•ื ืฉื”ื•ื ื™ื›ื•ืœ ืœื ื”ืœ ืœื ืจืง ื—ื•ืžื•ืช ืืฉ, ืืœื ื’ื ืžืชื’ื™ื ื•ื ืงื•ื“ื•ืช ื’ื™ืฉื” ืœ-Wi-Fi, ื›ืœื•ืžืจ ื›ืžืขื˜ ืืช ื›ืœ ื”ืจืฉืช.

ืขืœื™ื™ื” ืžื•ืชื ื™ืช ื‘ื™ื›ื•ืœืช ื”ืฉืœื™ื˜ื”. ื‘ืฉืœ ื”ืขื•ื‘ื“ื” ืฉื”ื›ืœื™ื ื”ืžืกื•ืจืชื™ื™ื ืžืฉืžืฉื™ื ืœืื•ื˜ื•ืžื˜ื™ื•ืช ืฉืœ ืชืฆื•ืจืช ืจืฉืช, ื™ื›ื•ืœืช ื”ื ื™ื”ื•ืœ ืฉืœ ื”ืจืฉืช ืขื ื”ื›ื ืกืช SD-WAN ืขื•ืœื” ืžืขื˜. ืžืฆื“ ืฉื ื™, ืคื•ื ืงืฆื™ื•ื ืœื™ื•ืช ื—ื“ืฉื” ื”ื•ืคื›ืช ืœื–ืžื™ื ื” ืžื”ืจ ื™ื•ืชืจ, ืฉื›ืŸ ื”ืกืคืง ืžืฉื—ืจืจ ืื•ืชื” ืชื—ื™ืœื” ืจืง ืขื‘ื•ืจ ืžืขืจื›ืช ื”ื”ืคืขืœื” ืฉืœ ื—ื•ืžืช ื”ืืฉ (ืžื” ืฉืžืืคืฉืจ ืœื”ืฉืชืžืฉ ื‘ื” ื‘ืื•ืคืŸ ืžื™ื™ื“ื™), ื•ืจืง ืœืื—ืจ ืžื›ืŸ ืžืฉืœื™ื ืืช ืžืขืจื›ืช ื”ื ื™ื”ื•ืœ ื‘ืžืžืฉืงื™ื ื”ื“ืจื•ืฉื™ื.

ืคื•ื ืงืฆื™ื•ื ืœื™ื•ืช ืžืกื•ื™ืžืช ืขืฉื•ื™ื” ืœื”ื™ื•ืช ื–ืžื™ื ื” ืžืฉื•ืจืช ื”ืคืงื•ื“ื”, ืืš ืื™ื ื” ื–ืžื™ื ื” ืžืžืžืฉืง ื”ืื™ื ื˜ืจื ื˜. ืœืคืขืžื™ื ื–ื” ืœื ื›ืœ ื›ืš ืžืคื—ื™ื“ ืœื”ื™ื›ื ืก ืœืฉื•ืจืช ื”ืคืงื•ื“ื” ื›ื“ื™ ืœื”ื’ื“ื™ืจ ืžืฉื”ื•, ืื‘ืœ ื–ื” ืžืคื—ื™ื“ ืœื ืœืจืื•ืช ื‘ืžืžืฉืง ื”ืื™ื ื˜ืจื ื˜ ืฉืžื™ืฉื”ื• ื›ื‘ืจ ื”ื’ื“ื™ืจ ืžืฉื”ื• ืžืฉื•ืจืช ื”ืคืงื•ื“ื”. ืื‘ืœ ื–ื” ื‘ื“ืจืš ื›ืœืœ ื—ืœ ืขืœ ื”ืชื›ื•ื ื•ืช ื”ื—ื“ืฉื•ืช ื‘ื™ื•ืชืจ ื•ื‘ื”ื“ืจื’ื”, ืขื ืขื“ื›ื•ื ื™ FortiOS, ื”ื™ื›ื•ืœื•ืช ืฉืœ ืžืžืฉืง ื”ืื™ื ื˜ืจื ื˜ ืžืฉืชืคืจื•ืช.

ื›ื“ื™ ืœื”ืชืื™ื

ืœืžื™ ืฉืื™ืŸ ืœื• ื”ืจื‘ื” ืกื ื™ืคื™ื. ื”ื˜ืžืขืช ืคืชืจื•ืŸ SD-WAN ืขื ืจื›ื™ื‘ื™ื ืžืจื›ื–ื™ื™ื ืžื•ืจื›ื‘ื™ื ื‘ืจืฉืช ืฉืœ 8-10 ืกื ื™ืคื™ื ืขืฉื•ื™ื” ืฉืœื ืœืขืœื•ืช ืขืœ ื”ื ืจ - ืชืฆื˜ืจื›ื• ืœื”ื•ืฆื™ื ื›ืกืฃ ืขืœ ืจื™ืฉื™ื•ื ื•ืช ืขื‘ื•ืจ ื”ืชืงื ื™ SD-WAN ื•ืžืฉืื‘ื™ ืžืขืจื›ืช ื•ื™ืจื˜ื•ืืœื™ื–ืฆื™ื” ื›ื“ื™ ืœืืจื— ืืช ื”ืจื›ื™ื‘ื™ื ื”ืžืจื›ื–ื™ื™ื. ืœื—ื‘ืจื” ืงื˜ื ื” ื™ืฉ ื‘ื“ืจืš ื›ืœืœ ืžืฉืื‘ื™ ืžื—ืฉื•ื‘ ื—ื•ืคืฉื™ื™ื ืžื•ื’ื‘ืœื™ื. ื‘ืžืงืจื” ืฉืœ Fortinet, ืžืกืคื™ืง ืคืฉื•ื˜ ืœืงื ื•ืช ื—ื•ืžื•ืช ืืฉ.

ืœืžื™ ืฉื™ืฉ ื”ืจื‘ื” ืกื ื™ืคื™ื ืงื˜ื ื™ื. ืขื‘ื•ืจ ืกืคืงื™ื ืจื‘ื™ื, ืžื—ื™ืจ ื”ืคืชืจื•ืŸ ื”ืžื™ื ื™ืžืœื™ ืœืกื ื™ืฃ ื”ื•ื ื“ื™ ื’ื‘ื•ื” ื•ืื•ืœื™ ืœื ืžืขื ื™ื™ืŸ ืžื ืงื•ื“ืช ื”ืžื‘ื˜ ืฉืœ ื”ืขืกืง ืฉืœ ื”ืœืงื•ื— ื”ืกื•ืคื™. ืคื•ืจื˜ื™ื ื˜ ืžืฆื™ืขื” ืžื›ืฉื™ืจื™ื ืงื˜ื ื™ื ื‘ืžื—ื™ืจื™ื ืื˜ืจืงื˜ื™ื‘ื™ื™ื ื‘ืžื™ื•ื—ื“.

ืœืžื™ ืฉืขื“ื™ื™ืŸ ืœื ืžื•ื›ืŸ ืœืฆืขื•ื“ ืจื—ื•ืง ืžื“ื™. ื”ื˜ืžืขืช SD-WAN ืขื ื‘ืงืจื™ื, ื ื™ืชื•ื‘ ืงื ื™ื™ื ื™ ื•ื’ื™ืฉื” ื—ื“ืฉื” ืœืชื›ื ื•ืŸ ื•ื ื™ื”ื•ืœ ืจืฉืช ืขืฉื•ื™ ืœื”ื™ื•ืช ืฆืขื“ ื’ื“ื•ืœ ืžื“ื™ ืขื‘ื•ืจ ื—ืœืง ืžื”ืœืงื•ื—ื•ืช. ื›ืŸ, ื™ื™ืฉื•ื ื›ื–ื” ื™ืขื–ื•ืจ ื‘ืกื•ืคื• ืฉืœ ื“ื‘ืจ ืœื™ื™ืขืœ ืืช ื”ืฉื™ืžื•ืฉ ื‘ืขืจื•ืฆื™ ื”ืชืงืฉื•ืจืช ื•ืืช ืขื‘ื•ื“ืชื ืฉืœ ื”ืžื ื”ืœื™ื, ืื‘ืœ ืงื•ื“ื ื›ืœ ืชืฆื˜ืจื›ื• ืœืœืžื•ื“ ื”ืจื‘ื” ื“ื‘ืจื™ื ื—ื“ืฉื™ื. ืœืžื™ ืฉืขื“ื™ื™ืŸ ืœื ืžื•ื›ืŸ ืœืฉื™ื ื•ื™ ืคืจื“ื™ื’ืžื”, ืื‘ืœ ืจื•ืฆื” ืœืกื—ื•ื˜ ื™ื•ืชืจ ืžืขืจื•ืฆื™ ื”ืชืงืฉื•ืจืช ืฉืœื•, ื”ืคืชืจื•ืŸ ืฉืœ Fortinet ื”ื•ื ื‘ื“ื™ื•ืง ืžืชืื™ื.

ืžืงื•ืจ: www.habr.com

ื”ื•ืกืคืช ืชื’ื•ื‘ื”