ืคืจื™ืกืช ืืฉื›ื•ืœ ASA VPN ืœืื™ื–ื•ืŸ ืขื•ืžืกื™ื

ื‘ืžืืžืจ ื–ื”, ื‘ืจืฆื•ื ื™ ืœืกืคืง ื”ื•ืจืื•ืช ืฉืœื‘ ืื—ืจ ืฉืœื‘ ื›ื™ืฆื“ ื ื™ืชืŸ ืœืคืจื•ืก ื‘ืžื”ื™ืจื•ืช ืืช ื”ืกื›ื™ืžื” ื”ื ื™ืชื ืช ืœื”ืจื—ื‘ื” ื‘ื™ื•ืชืจ ื›ืจื’ืข. VPN ื’ื™ืฉื” ืžืจื—ื•ืง ืžื‘ื•ืกืก ื’ื™ืฉื” AnyConnect ื•-Cisco ASA - ืืฉื›ื•ืœ ืื™ื–ื•ืŸ ืขื•ืžืกื™ื ืฉืœ VPN.

ืžื‘ื•ื: ื—ื‘ืจื•ืช ืจื‘ื•ืช ื‘ืจื—ื‘ื™ ื”ืขื•ืœื, ืœืื•ืจ ื”ืžืฆื‘ ื”ื ื•ื›ื—ื™ ืขื COVID-19, ืขื•ืฉื•ืช ืžืืžืฆื™ื ืœื”ืขื‘ื™ืจ ืืช ืขื•ื‘ื“ื™ื”ืŸ ืœืขื‘ื•ื“ื” ืžืจื—ื•ืง. ืขืงื‘ ื”ืžืขื‘ืจ ื”ื”ืžื•ื ื™ ืœืขื‘ื•ื“ื” ืžืจื—ื•ืง, ื”ืขื•ืžืก ืขืœ ืฉืขืจื™ ื”-VPN ื”ืงื™ื™ืžื™ื ืฉืœ ื—ื‘ืจื•ืช ื’ื“ืœ ื‘ืื•ืคืŸ ืงืจื™ื˜ื™ ื•ื ื“ืจืฉืช ื™ื›ื•ืœืช ืžื”ื™ืจื” ืžืื•ื“ ืœื”ืจื—ื™ื‘ ืื•ืชื. ืžืฆื“ ืฉื ื™, ื—ื‘ืจื•ืช ืจื‘ื•ืช ื ืืœืฆื•ืช ืœืฉืœื•ื˜ ื‘ื—ื•ืคื–ื” ื‘ืงื•ื ืกืคื˜ ืฉืœ ืขื‘ื•ื“ื” ืžืจื—ื•ืง ืžืืคืก.

ื›ื“ื™ ืœืขื–ื•ืจ ืœืขืกืงื™ื ืœื”ืฉื™ื’ ื’ื™ืฉืช VPN ื ื•ื—ื”, ืžืื•ื‘ื˜ื—ืช ื•ื ื™ืชื ืช ืœื”ืจื—ื‘ื” ืœืขื•ื‘ื“ื™ื ื‘ื–ืžืŸ ื”ืงืฆืจ ื‘ื™ื•ืชืจ ื”ืืคืฉืจื™, ืกื™ืกืงื• ื ื•ืชื ืช ืจื™ืฉื™ื•ืŸ ืœืœืงื•ื— SSL-VPN ื”ืขืฉื™ืจ ื‘ืชื›ื•ื ื•ืช AnyConnect ืœืžืฉืš ืขื“ 13 ืฉื‘ื•ืขื•ืช. ืืชื” ื™ื›ื•ืœ ื’ื ืœืงื—ืช ืืช ASAv ืœื‘ื“ื™ืงื” (Virtual ASA ืขื‘ื•ืจ VMWare/Hyper-V/KVM hypervisors ื•-AWS/Azure Cloud Platforms) ืžืฉื•ืชืคื™ื ืžื•ืจืฉื™ื ืื• ืขืœ ื™ื“ื™ ืคื ื™ื™ื” ืœื ืฆื™ื’ื™ Cisco ื”ืขื•ื‘ื“ื™ื ืื™ืชืš.

ื”ื”ืœื™ืš ืœื”ื ืคืงืช ืจื™ืฉื™ื•ื ื•ืช AnyConnect COVID-19 ืžืชื•ืืจ ื›ืืŸ.

ื”ื›ื ืชื™ ืžื“ืจื™ืš ืฉืœื‘ ืื—ืจ ืฉืœื‘ ืœืคืจื™ืกื” ืคืฉื•ื˜ื” ืฉืœ โ€‹โ€‹VPN Load-Balancing Cluster ื›ื˜ื›ื ื•ืœื•ื’ื™ื™ืช ื”-VPN ื”ื ื™ืชื ืช ืœื”ืจื—ื‘ื” ื‘ื™ื•ืชืจ.

ื”ื“ื•ื’ืžื” ืœื”ืœืŸ ืชื”ื™ื” ืคืฉื•ื˜ื” ืœืžื“ื™ ืžื‘ื—ื™ื ืช ืืœื’ื•ืจื™ืชืžื™ ื”ืื™ืžื•ืช ื•ื”ื”ืจืฉืื” ื‘ืฉื™ืžื•ืฉ, ืืš ืชื”ื•ื•ื” ืื•ืคืฆื™ื” ื˜ื•ื‘ื” ืœื”ืชื—ืœื” ืžื”ื™ืจื” (ืฉื›ื™ื•ื ืœื ืžืกืคื™ืงื” ืœืจื‘ื™ื) ืขื ืืคืฉืจื•ืช ื”ืชืืžื” ืžืขืžื™ืงื” ืœืฆืจื›ื™ื ืฉืœื›ื ื‘ืžื”ืœืš ื”ืคืจื™ืกื” ืชื”ืœื™ืš.

ืžื™ื“ืข ืงืฆืจ: ื˜ื›ื ื•ืœื•ื’ื™ื™ืช VPN Load Balancing Cluster ื”ื™ื ืœื ืชืงืœื” ื•ืœื ืคื•ื ืงืฆื™ื™ืช ืืฉื›ื•ืœื•ืช ื‘ืžื•ื‘ืŸ ื”ืžืงื•ืจื™ ืฉืœื”, ื˜ื›ื ื•ืœื•ื’ื™ื” ื–ื• ื™ื›ื•ืœื” ืœืฉืœื‘ ื“ื’ืžื™ ASA ืฉื•ื ื™ื ืœื—ืœื•ื˜ื™ืŸ (ืขื ื”ื’ื‘ืœื•ืช ืžืกื•ื™ืžื•ืช) ืขืœ ืžื ืช ืœืื–ืŸ ืขื•ืžืก ื—ื™ื‘ื•ืจื™ VPN ืขื ื’ื™ืฉื” ืžืจื—ื•ืง. ืื™ืŸ ืกื ื›ืจื•ืŸ ืฉืœ ื”ืคืขืœื•ืช ื•ืชืฆื•ืจื•ืช ื‘ื™ืŸ ื”ืฆืžืชื™ื ืฉืœ ืืฉื›ื•ืœ ื›ื–ื”, ืืš ื ื™ืชืŸ ืœื˜ืขื•ืŸ ืื•ื˜ื•ืžื˜ื™ืช ื—ื™ื‘ื•ืจื™ VPN ื‘ืื™ื–ื•ืŸ ืขื•ืžืก ื•ืœื”ื‘ื˜ื™ื— ืกื•ื‘ืœื ื•ืช ืœืชืงืœื•ืช ืฉืœ ื—ื™ื‘ื•ืจื™ VPN ืขื“ ืฉื™ื™ืฉืืจ ืœืคื—ื•ืช ืฆื•ืžืช ืคืขื™ืœ ืื—ื“ ื‘ืืฉื›ื•ืœ. ื”ืขื•ืžืก ื‘ืืฉื›ื•ืœ ืžืื•ื–ืŸ ืื•ื˜ื•ืžื˜ื™ืช ื‘ื”ืชืื ืœืขื•ืžืก ื”ืขื‘ื•ื“ื” ืฉืœ ื”ืฆืžืชื™ื ืœืคื™ ืžืกืคืจ ื”ืคืขืœื•ืช VPN.

ืขื‘ื•ืจ ื›ืฉืœ ืฉืœ ืฆืžืชื™ื ืกืคืฆื™ืคื™ื™ื ืฉืœ ื”ืืฉื›ื•ืœ (ืื ื ื“ืจืฉ), ื ื™ืชืŸ ืœื”ืฉืชืžืฉ ื‘ืงื•ื‘ืฅ, ื›ืš ืฉื”ื—ื™ื‘ื•ืจ ื”ืคืขื™ืœ ื™ื˜ื•ืคืœ ืขืœ ื™ื“ื™ ื”ืฆื•ืžืช ื”ืจืืฉื™ ืฉืœ ื”ืงื•ื‘ืฅ. ื”-filover ืื™ื ื• ืชื ืื™ ื”ื›ืจื—ื™ ืœื”ื‘ื˜ื—ืช ืกื‘ื™ืœื•ืช ืชืงืœื•ืช ื‘ืชื•ืš ืืฉื›ื•ืœ ื”-Load-Balancing, ื”ืืฉื›ื•ืœ ืขืฆืžื•, ื‘ืžืงืจื” ืฉืœ ื›ืฉืœ ื‘ืฆื•ืžืช, ื™ืขื‘ื™ืจ ืืช ื”ืคืขืœืช ื”ืžืฉืชืžืฉ ืœืฆื•ืžืช ื—ื™ ืื—ืจ, ืืš ืœืœื ืฉืžื™ืจืช ืžืฆื‘ ื”ื—ื™ื‘ื•ืจ, ืฉื”ื•ื ื‘ื“ื™ื•ืง ืžืกื•ืคืง ืขืœ ื™ื“ื™ ื”ืžื’ื™ืฉ. ื‘ื”ืชืื ืœื›ืš, ื ื™ืชืŸ, ื‘ืžื™ื“ืช ื”ืฆื•ืจืš, ืœืฉืœื‘ ื‘ื™ืŸ ืฉืชื™ ื”ื˜ื›ื ื•ืœื•ื’ื™ื•ืช ื”ืœืœื•.

ืืฉื›ื•ืœ ืื™ื–ื•ืŸ ืขื•ืžืกื™ื ืฉืœ VPN ื™ื›ื•ืœ ืœื”ื›ื™ืœ ื™ื•ืชืจ ืžืฉื ื™ ืฆืžืชื™ื.

ืืฉื›ื•ืœ ืื™ื–ื•ืŸ ืขื•ืžืกื™ื ืฉืœ VPN ื ืชืžืš ื‘-ASA 5512-X ื•ืžืขืœื”.

ืžื›ื™ื•ื•ืŸ ืฉื›ืœ ASA ื‘ืชื•ืš ืืฉื›ื•ืœ ื”-VPN Load-Balancing ื”ื™ื ื™ื—ื™ื“ื” ืขืฆืžืื™ืช ืžื‘ื—ื™ื ืช ื”ื’ื“ืจื•ืช, ืื ื• ืžื‘ืฆืขื™ื ืืช ื›ืœ ืฉืœื‘ื™ ื”ืชืฆื•ืจื” ื‘ื ืคืจื“ ืขืœ ื›ืœ ืžื›ืฉื™ืจ ื‘ื ืคืจื“.

ืคืจื˜ื™ ื˜ื›ื ื•ืœื•ื’ื™ื” ื›ืืŸ

ื”ื˜ื•ืคื•ืœื•ื’ื™ื” ื”ืœื•ื’ื™ืช ืฉืœ ื”ื“ื•ื’ืžื” ื”ื ืชื•ื ื”:

ืคืจื™ืกืช ืืฉื›ื•ืœ ASA VPN ืœืื™ื–ื•ืŸ ืขื•ืžืกื™ื

ืคืจื™ืกื” ืจืืฉื™ืช:

  1. ืื ื• ืคื•ืจืกื™ื ืžื•ืคืขื™ ASAv ืฉืœ ื”ืชื‘ื ื™ื•ืช ืฉืื ื• ืฆืจื™ื›ื™ื (ASAv5/10/30/50) ืžื”ืชืžื•ื ื”.

  2. ืื ื• ืžืงืฆื™ื ืืช ืžืžืฉืงื™ INSIDE / OUTSIDE ืœืื•ืชื VLANs (Outside ื‘-VLAN ืžืฉืœื•, INSIDE ื‘ืคื ื™ ืขืฆืžื•, ืื‘ืœ ื‘ื“ืจืš ื›ืœืœ ื‘ืชื•ืš ื”ืืฉื›ื•ืœ, ืจืื” ืืช ื”ื˜ื•ืคื•ืœื•ื’ื™ื”), ื—ืฉื•ื‘ ืฉืžืžืฉืงื™ื ืžืื•ืชื• ืกื•ื’ ื™ื”ื™ื• ื‘ืื•ืชื• ืงื˜ืข L2.

  3. ืจื™ืฉื™ื•ื ื•ืช:

    • ื›ืจื’ืข ืœื”ืชืงื ืช ASAv ืœื ื™ื”ื™ื• ื›ืœ ืจื™ืฉื™ื•ื ื•ืช ื•ื”ื™ื ืชื”ื™ื” ืžื•ื’ื‘ืœืช ืœ-100kbps.
    • ื›ื“ื™ ืœื”ืชืงื™ืŸ ืจื™ืฉื™ื•ืŸ, ืขืœื™ืš ืœื™ืฆื•ืจ ืืกื™ืžื•ืŸ ื‘ื—ืฉื‘ื•ืŸ ื”ื—ื›ื ืฉืœืš: https://software.cisco.com/ -> ืจื™ืฉื•ื™ ืชื•ื›ื ื” ื—ื›ืžื”
    • ื‘ื—ืœื•ืŸ ืฉื ืคืชื—, ืœื—ืฅ ืขืœ ื”ื›ืคืชื•ืจ ืืกื™ืžื•ืŸ ื—ื“ืฉ

    ืคืจื™ืกืช ืืฉื›ื•ืœ ASA VPN ืœืื™ื–ื•ืŸ ืขื•ืžืกื™ื

    • ื™ืฉ ืœื•ื•ื“ื ืฉื‘ื—ืœื•ืŸ ืฉื ืคืชื— ื™ืฉ ืฉื“ื” ืคืขื™ืœ ื•ืžืกื•ืžืŸ ืกื™ืžื•ืŸ ืืคืฉืจ ืคื•ื ืงืฆื™ื•ื ืœื™ื•ืช ืžื‘ื•ืงืจืช ื™ื™ืฆื•ื... ืœืœื ืฉื“ื” ื–ื” ืคืขื™ืœ, ืœื ืชื•ื›ืœ ืœื”ืฉืชืžืฉ ื‘ืคื•ื ืงืฆื™ื•ืช ืฉืœ ื”ืฆืคื ื” ื—ื–ืงื” ื•ื‘ื”ืชืื, VPN. ืื ืฉื“ื” ื–ื” ืื™ื ื• ืคืขื™ืœ, ืื ื ืฆื•ืจ ืงืฉืจ ืขื ืฆื•ื•ืช ื”ื—ืฉื‘ื•ืŸ ืฉืœืš ืขื ื‘ืงืฉืช ื”ืคืขืœื”.

    ืคืจื™ืกืช ืืฉื›ื•ืœ ASA VPN ืœืื™ื–ื•ืŸ ืขื•ืžืกื™ื

    • ืœืื—ืจ ืœื—ื™ืฆื” ืขืœ ื”ื›ืคืชื•ืจ ืฆื•ืจ ืืกื™ืžื•ืŸ, ื™ื™ื•ื•ืฆืจ ืืกื™ืžื•ืŸ ืฉื‘ื• ื ืฉืชืžืฉ ื›ื“ื™ ืœืงื‘ืœ ืจื™ืฉื™ื•ืŸ ืขื‘ื•ืจ ASAv, ื”ืขืชืง ืื•ืชื•:

    ืคืจื™ืกืช ืืฉื›ื•ืœ ASA VPN ืœืื™ื–ื•ืŸ ืขื•ืžืกื™ื

    • ื—ื–ื•ืจ ืขืœ ืฉืœื‘ื™ื C,D,E ืขื‘ื•ืจ ื›ืœ ASAv ืฉื ืคืจืก.
    • ื›ื“ื™ ืœื”ืงืœ ืขืœ ื”ืขืชืงืช ื”ืืกื™ืžื•ืŸ, ื‘ื•ืื• ื ืืคืฉืจ ื–ืžื ื™ืช ืืช Telnet. ื‘ื•ืื• ื ื’ื“ื™ืจ ื›ืœ ASA (ื”ื“ื•ื’ืžื” ืœืžื˜ื” ืžืžื—ื™ืฉื” ืืช ื”ื”ื’ื“ืจื•ืช ื‘-ASA-1). telnet ืœื ืขื•ื‘ื“ ืขื ื—ื•ืฅ, ืื ืืชื” ื‘ืืžืช ืฆืจื™ืš ืืช ื–ื”, ืฉื ื” ืืช ืจืžืช ื”ืื‘ื˜ื—ื” ืœ-100 ืœื—ื•ืฅ, ื•ืื– ื”ื—ื–ืจ ืื•ืชื• ื‘ื—ื–ืจื”.

    !
    ciscoasa(config)# int gi0/0
    ciscoasa(config)# nameif outside
    ciscoasa(config)# ip address 192.168.31.30 255.255.255.0
    ciscoasa(config)# no shut
    !
    ciscoasa(config)# int gi0/1
    ciscoasa(config)# nameif inside
    ciscoasa(config)# ip address 192.168.255.2 255.255.255.0
    ciscoasa(config)# no shut
    !
    ciscoasa(config)# telnet 0 0 inside
    ciscoasa(config)# username admin password cisco priv 15
    ciscoasa(config)# ena password cisco
    ciscoasa(config)# aaa authentication telnet console LOCAL
    !
    ciscoasa(config)# route outside 0 0 192.168.31.1
    !
    ciscoasa(config)# wr
    !

    • ื›ื“ื™ ืœืจืฉื•ื ืืกื™ืžื•ืŸ ื‘ืขื ืŸ Smart-Account, ืขืœื™ืš ืœืกืคืง ื’ื™ืฉื” ืœืื™ื ื˜ืจื ื˜ ืขื‘ื•ืจ ASA, ืคืจื˜ื™ื ื›ืืŸ.

    ื‘ืงื™ืฆื•ืจ, ื™ืฉ ืฆื•ืจืš ื‘-ASA:

    • ื’ื™ืฉื” ื“ืจืš HTTPS ืœืื™ื ื˜ืจื ื˜;
    • ืกื ื›ืจื•ืŸ ื–ืžืŸ (ื ื›ื•ืŸ ื™ื•ืชืจ, ื‘ืืžืฆืขื•ืช NTP);
    • ืฉืจืช DNS ืจืฉื•ื;
      • ืื ื• ื˜ืœื ื˜ื™ื ืœ-ASA ืฉืœื ื• ื•ืžื‘ืฆืขื™ื ื”ื’ื“ืจื•ืช ืœื”ืคืขืœืช ื”ืจื™ืฉื™ื•ืŸ ื‘ืืžืฆืขื•ืช Smart-Account.

    !
    ciscoasa(config)# clock set 19:21:00 Mar 18 2020
    ciscoasa(config)# clock timezone MSK 3
    ciscoasa(config)# ntp server 192.168.99.136
    !
    ciscoasa(config)# dns domain-lookup outside
    ciscoasa(config)# DNS server-group DefaultDNS
    ciscoasa(config-dns-server-group)# name-server 192.168.99.132 
    !
    ! ะŸั€ะพะฒะตั€ะธะผ ั€ะฐะฑะพั‚ัƒ DNS:
    !
    ciscoasa(config-dns-server-group)# ping ya.ru
    Type escape sequence to abort.
    Sending 5, 100-byte ICMP Echos to 87.250.250.242, timeout is 2 seconds:
    !!!!!
    !
    ! ะŸั€ะพะฒะตั€ะธะผ ัะธะฝั…ั€ะพะฝะธะทะฐั†ะธัŽ NTP:
    !
    ciscoasa(config)# show ntp associations 
      address         ref clock     st  when  poll reach  delay  offset    disp
    *~192.168.99.136   91.189.94.4       3    63    64    1    36.7    1.85    17.5
    * master (synced), # master (unsynced), + selected, - candidate, ~ configured
    !
    ! ะฃัั‚ะฐะฝะพะฒะธะผ ะบะพะฝั„ะธะณัƒั€ะฐั†ะธัŽ ะฝะฐัˆะตะน ASAv ะดะปั Smart-Licensing (ะฒ ัะพะพั‚ะฒะตั‚ัั‚ะฒะธะธ ั ะ’ะฐัˆะธะผ ะฟั€ะพั„ะธะปะตะผ, ะฒ ะผะพะตะผ ัะปัƒั‡ะฐะต 100ะœ ะดะปั ะฟั€ะธะผะตั€ะฐ)
    !
    ciscoasa(config)# license smart
    ciscoasa(config-smart-lic)# feature tier standard
    ciscoasa(config-smart-lic)# throughput level 100M
    !
    ! ะ’ ัะปัƒั‡ะฐะต ะฝะตะพะฑั…ะพะดะธะผะพัั‚ะธ ะผะพะถะฝะพ ะฝะฐัั‚ั€ะพะธั‚ัŒ ะดะพัั‚ัƒะฟ ะฒ ะ˜ะฝั‚ะตั€ะฝะตั‚ ั‡ะตั€ะตะท ะฟั€ะพะบัะธ ะธัะฟะพะปัŒะทัƒะนั‚ะต ัะปะตะดัƒัŽั‰ะธะน ะฑะปะพะบ ะบะพะผะฐะฝะด:
    !call-home
    !  http-proxy ip_address port port
    !
    ! ะ”ะฐะปะตะต ะผั‹ ะฒัั‚ะฐะฒะปัะตะผ ัะบะพะฟะธั€ะพะฒะฐะฝะฝั‹ะน ะธะท ะฟะพั€ั‚ะฐะปะฐ Smart-Account ั‚ะพะบะตะฝ (<token>) ะธ ั€ะตะณะธัั‚ั€ะธั€ัƒะตะผ ะปะธั†ะตะฝะทะธัŽ
    !
    ciscoasa(config)# end
    ciscoasa# license smart register idtoken <token>

    • ืื ื• ื‘ื•ื“ืงื™ื ืฉื”ืžื›ืฉื™ืจ ืจืฉื ื‘ื”ืฆืœื—ื” ืจื™ืฉื™ื•ืŸ ื•ืืคืฉืจื•ื™ื•ืช ื”ืฆืคื ื” ื–ืžื™ื ื•ืช:

    ืคืจื™ืกืช ืืฉื›ื•ืœ ASA VPN ืœืื™ื–ื•ืŸ ืขื•ืžืกื™ื

    ืคืจื™ืกืช ืืฉื›ื•ืœ ASA VPN ืœืื™ื–ื•ืŸ ืขื•ืžืกื™ื

  4. ื”ื’ื“ืจ SSL-VPN ื‘ืกื™ืกื™ ื‘ื›ืœ ืฉืขืจ

    • ืœืื—ืจ ืžื›ืŸ, ื”ื’ื“ืจ ื’ื™ืฉื” ื‘ืืžืฆืขื•ืช SSH ื•-ASDM:

    ciscoasa(config)# ssh ver 2
    ciscoasa(config)# aaa authentication ssh console LOCAL
    ciscoasa(config)# aaa authentication http console LOCAL
    ciscoasa(config)# hostname vpn-demo-1
    vpn-demo-1(config)# domain-name ashes.cc
    vpn-demo-1(config)# cry key gen rsa general-keys modulus 4096 
    vpn-demo-1(config)# ssh 0 0 inside  
    vpn-demo-1(config)# http 0 0 inside
    !
    ! ะŸะพะดะฝะธะผะตะผ ัะตั€ะฒะตั€ HTTPS ะดะปั ASDM ะฝะฐ ะฟะพั€ั‚ัƒ 445 ั‡ั‚ะพะฑั‹ ะฝะต ะฟะตั€ะตัะตะบะฐั‚ัŒัั ั SSL-VPN ะฟะพั€ั‚ะฐะปะพะผ
    !
    vpn-demo-1(config)# http server enable 445 
    !

    • ื›ื“ื™ ืฉ-ASDM ื™ืขื‘ื•ื“, ืชื—ื™ืœื” ืขืœื™ืš ืœื”ื•ืจื™ื“ ืื•ืชื• ืžืืชืจ cisco.com, ื‘ืžืงืจื” ืฉืœื™ ื–ื” ื”ืงื•ื‘ืฅ ื”ื‘ื:

    ืคืจื™ืกืช ืืฉื›ื•ืœ ASA VPN ืœืื™ื–ื•ืŸ ืขื•ืžืกื™ื

    • ื›ื“ื™ ืฉืœืงื•ื— AnyConnect ื™ืขื‘ื•ื“, ืขืœื™ืš ืœื”ืขืœื•ืช ืชืžื•ื ื” ืœื›ืœ ASA ืขื‘ื•ืจ ื›ืœ ืžืขืจื›ืช ื”ืคืขืœื” ืฉื•ืœื—ื ื™ืช ืžืฉื•ืžืฉืช ืฉืœ ืœืงื•ื— (ืžืชื•ื›ื ื ืช ืœื”ืฉืชืžืฉ ื‘-Linux / Windows / MAC), ืชืฆื˜ืจืš ืงื•ื‘ืฅ ืขื ื—ื‘ื™ืœืช ืคืจื™ืกื” ืจืืฉื•ื ื™ืช ื‘ื›ื•ืชืจืช:

    ืคืจื™ืกืช ืืฉื›ื•ืœ ASA VPN ืœืื™ื–ื•ืŸ ืขื•ืžืกื™ื

    • ื ื™ืชืŸ ืœื”ืขืœื•ืช ืืช ื”ืงื‘ืฆื™ื ืฉื”ื•ืจื“ืช, ืœืžืฉืœ, ืœืฉืจืช FTP ื•ืœื”ืขืœื•ืช ืœื›ืœ ASA ื‘ื ืคืจื“:

    ืคืจื™ืกืช ืืฉื›ื•ืœ ASA VPN ืœืื™ื–ื•ืŸ ืขื•ืžืกื™ื

    • ืื ื• ืžื’ื“ื™ืจื™ื ืื™ืฉื•ืจ ASDM ื•-Self-Signed ืขื‘ื•ืจ SSL-VPN (ืžื•ืžืœืฅ ืœื”ืฉืชืžืฉ ื‘ืชืขื•ื“ื” ืžื”ื™ืžื ื” ื‘ื™ื™ืฆื•ืจ). ื”-FQDN ืฉื ืงื‘ืข ืฉืœ ื›ืชื•ื‘ืช ื”ืืฉื›ื•ืœ ื”ื•ื•ื™ืจื˜ื•ืืœื™ (vpn-demo.ashes.cc), ื›ืžื• ื’ื ื›ืœ FQDN ื”ืžืฉื•ื™ืš ืœื›ืชื•ื‘ืช ื”ื—ื™ืฆื•ื ื™ืช ืฉืœ ื›ืœ ืฆื•ืžืช ืืฉื›ื•ืœ, ื—ื™ื™ื‘ื™ื ืœื”ืชืื™ื ื‘ืื–ื•ืจ ื”-DNS ื”ื—ื™ืฆื•ื ื™ ืœื›ืชื•ื‘ืช ื”-IP ืฉืœ ืžืžืฉืง OUTSIDE (ืื• ืœื›ืชื•ื‘ืช ื”ืžืžื•ืคืช ืื ื ืขืฉื” ืฉื™ืžื•ืฉ ื‘ื”ืขื‘ืจืช ื™ืฆื™ืื•ืช udp/443 (DTLS) ื•-tcp/443(TLS)). ืžื™ื“ืข ืžืคื•ืจื˜ ืขืœ ื”ื“ืจื™ืฉื•ืช ืœืชืขื•ื“ื” ืžืคื•ืจื˜ ื‘ืกืขื™ืฃ ืื™ืžื•ืช ืชืขื•ื“ื” ืชื™ืขื•ื“.

    !
    vpn-demo-1(config)# crypto ca trustpoint SELF
    vpn-demo-1(config-ca-trustpoint)# enrollment self
    vpn-demo-1(config-ca-trustpoint)# fqdn vpn-demo.ashes.cc
    vpn-demo-1(config-ca-trustpoint)# subject-name cn=*.ashes.cc, ou=ashes-lab, o=ashes, c=ru
    vpn-demo-1(config-ca-trustpoint)# serial-number             
    vpn-demo-1(config-ca-trustpoint)# crl configure
    vpn-demo-1(config-ca-crl)# cry ca enroll SELF
    % The fully-qualified domain name in the certificate will be: vpn-demo.ashes.cc
    Generate Self-Signed Certificate? [yes/no]: yes
    vpn-demo-1(config)# 
    !
    vpn-demo-1(config)# sh cry ca certificates 
    Certificate
    Status: Available
    Certificate Serial Number: 4d43725e
    Certificate Usage: General Purpose
    Public Key Type: RSA (4096 bits)
    Signature Algorithm: SHA256 with RSA Encryption
    Issuer Name: 
    serialNumber=9A439T02F95
    hostname=vpn-demo.ashes.cc
    cn=*.ashes.cc
    ou=ashes-lab
    o=ashes
    c=ru
    Subject Name:
    serialNumber=9A439T02F95
    hostname=vpn-demo.ashes.cc
    cn=*.ashes.cc
    ou=ashes-lab
    o=ashes
    c=ru
    Validity Date: 
    start date: 00:16:17 MSK Mar 19 2020
    end   date: 00:16:17 MSK Mar 17 2030
    Storage: config
    Associated Trustpoints: SELF 
    
    CA Certificate
    Status: Available
    Certificate Serial Number: 0509
    Certificate Usage: General Purpose
    Public Key Type: RSA (4096 bits)
    Signature Algorithm: SHA1 with RSA Encryption
    Issuer Name: 
    cn=QuoVadis Root CA 2
    o=QuoVadis Limited
    c=BM
    Subject Name: 
    cn=QuoVadis Root CA 2
    o=QuoVadis Limited
    c=BM
    Validity Date: 
    start date: 21:27:00 MSK Nov 24 2006
    end   date: 21:23:33 MSK Nov 24 2031
    Storage: config
    Associated Trustpoints: _SmartCallHome_ServerCA               

    • ืืœ ืชืฉื›ื— ืœืฆื™ื™ืŸ ืืช ื”ื™ืฆื™ืื” ื›ื“ื™ ืœื‘ื“ื•ืง ืฉ-ASDM ืขื•ื‘ื“, ืœืžืฉืœ:

    ืคืจื™ืกืช ืืฉื›ื•ืœ ASA VPN ืœืื™ื–ื•ืŸ ืขื•ืžืกื™ื

    • ื‘ื•ืื• ื ื‘ืฆืข ืืช ื”ื”ื’ื“ืจื•ืช ื”ื‘ืกื™ืกื™ื•ืช ืฉืœ ื”ืžื ื”ืจื”:
    • ื‘ื•ืื• ื ื”ืคื•ืš ืืช ื”ืจืฉืช ื”ืืจื’ื•ื ื™ืช ืœื–ืžื™ื ื” ื“ืจืš ื”ืžื ื”ืจื”, ื•ื ืืคืฉืจ ืœืื™ื ื˜ืจื ื˜ ืœืขื‘ื•ืจ ื™ืฉื™ืจื•ืช (ืœื ื”ืฉื™ื˜ื” ื”ื‘ื˜ื•ื—ื” ื‘ื™ื•ืชืจ ืื ืื™ืŸ ื”ื’ื ื•ืช ืขืœ ื”ืžืืจื— ื”ืžื—ื‘ืจ, ืืคืฉืจ ืœื—ื“ื•ืจ ื“ืจืš ืžืืจื— ื ื’ื•ืข ื•ืœื”ืฆื™ื’ ื ืชื•ื ื™ื ืืจื’ื•ื ื™ื™ื, ืืคืฉืจื•ืช split-tunnel-policy tunnelall ื™ืืคืฉืจ ืœื›ืœ ื”ืชื ื•ืขื” ื”ืžืืจื— ืœื”ื™ื›ื ืก ืœืžื ื”ืจื”. ืขืœ ื›ืœ ืคื ื™ื ืžื ื”ืจื” ืžืคื•ืฆืœืช ืžืืคืฉืจ ืœื”ื•ืจื™ื“ ืืช ืฉืขืจ ื”-VPN ื•ืœื ืœืขื‘ื“ ืชืขื‘ื•ืจืช ืื™ื ื˜ืจื ื˜ ืžืืจื—)
    • ื‘ื•ืื• ื ื ืคื™ืง ื›ืชื•ื‘ื•ืช ืžืจืฉืช ื”ืžืฉื ื” 192.168.20.0/24 ืœืžืืจื—ื™ื ื‘ืžื ื”ืจื” (ืžืื’ืจ ืž-10 ืขื“ 30 ื›ืชื•ื‘ื•ืช (ืขื‘ื•ืจ ืฆื•ืžืช ืžืก' 1)). ืœื›ืœ ืฆื•ืžืช ื‘ืืฉื›ื•ืœ ื”-VPN ื—ื™ื™ื‘ ืœื”ื™ื•ืช ืžืื’ืจ ืžืฉืœื•.
    • ืื ื• ื ื‘ืฆืข ืื™ืžื•ืช ื‘ืกื™ืกื™ ืขื ืžืฉืชืžืฉ ืฉื ื•ืฆืจ ื‘ืื•ืคืŸ ืžืงื•ืžื™ ื‘-ASA (ื–ื” ืœื ืžื•ืžืœืฅ, ื–ื• ื”ืฉื™ื˜ื” ื”ืงืœื” ื‘ื™ื•ืชืจ), ืขื“ื™ืฃ ืœืขืฉื•ืช ืื™ืžื•ืช ื‘ืืžืฆืขื•ืช LDAP/RADIUS, ืื• ื™ื•ืชืจ ื˜ื•ื‘, ืขื ื™ื‘ื” ืื™ืžื•ืช ืจื‘ ื’ื•ืจืžื™ื (MFA)ืœื“ื•ื’ืžื” ืกื™ืกืงื• DUO.

    !
    vpn-demo-1(config)# ip local pool vpn-pool 192.168.20.10-192.168.20.30 mask 255.255.255.0
    !
    vpn-demo-1(config)# access-list split-tunnel standard permit 192.168.0.0 255.255.0.0
    !
    vpn-demo-1(config)# group-policy SSL-VPN-GROUP-POLICY internal
    vpn-demo-1(config)# group-policy SSL-VPN-GROUP-POLICY attributes
    vpn-demo-1(config-group-policy)# vpn-tunnel-protocol ssl-client 
    vpn-demo-1(config-group-policy)# split-tunnel-policy tunnelspecified
    vpn-demo-1(config-group-policy)# split-tunnel-network-list value split-tunnel
    vpn-demo-1(config-group-policy)# dns-server value 192.168.99.132
    vpn-demo-1(config-group-policy)# default-domain value ashes.cc
    vpn-demo-1(config)# tunnel-group DefaultWEBVPNGroup general-attributes
    vpn-demo-1(config-tunnel-general)#  default-group-policy SSL-VPN-GROUP-POLICY
    vpn-demo-1(config-tunnel-general)#  address-pool vpn-pool
    !
    vpn-demo-1(config)# username dkazakov password cisco
    vpn-demo-1(config)# username dkazakov attributes
    vpn-demo-1(config-username)# service-type remote-access
    !
    vpn-demo-1(config)# ssl trust-point SELF
    vpn-demo-1(config)# webvpn
    vpn-demo-1(config-webvpn)#  enable outside
    vpn-demo-1(config-webvpn)#  anyconnect image disk0:/anyconnect-win-4.8.03036-webdeploy-k9.pkg
    vpn-demo-1(config-webvpn)#  anyconnect enable
    !

    • (ืื•ืคืฆื™ื•ื ืืœื™): ื‘ื“ื•ื’ืžื” ืฉืœืžืขืœื”, ื”ืฉืชืžืฉื ื• ื‘ืžืฉืชืžืฉ ืžืงื•ืžื™ ื‘-ITU ื›ื“ื™ ืœืืžืช ืžืฉืชืžืฉื™ื ืžืจื•ื—ืงื™ื, ืžื” ืฉื›ืžื•ื‘ืŸ, ืœืžืขื˜ ื‘ืžืขื‘ื“ื”, ื™ืฉื™ื ื‘ืฆื•ืจื” ื’ืจื•ืขื”. ืืชืŸ ื“ื•ื’ืžื” ื›ื™ืฆื“ ืœื”ืชืื™ื ื‘ืžื”ื™ืจื•ืช ืืช ื”ื”ื’ื“ืจื” ืœืื™ืžื•ืช ืจึทื“ึดื™ื•ึผืก ืฉืจืช, ืœืžืฉืœ ื‘ืฉื™ืžื•ืฉ ืžื ื•ืข ืฉื™ืจื•ืชื™ ื–ื”ื•ืช ืฉืœ ืกื™ืกืงื•:

    vpn-demo-1(config-aaa-server-group)# dynamic-authorization
    vpn-demo-1(config-aaa-server-group)# interim-accounting-update
    vpn-demo-1(config-aaa-server-group)# aaa-server RADIUS (outside) host 192.168.99.134
    vpn-demo-1(config-aaa-server-host)# key cisco
    vpn-demo-1(config-aaa-server-host)# exit
    vpn-demo-1(config)# tunnel-group DefaultWEBVPNGroup general-attributes
    vpn-demo-1(config-tunnel-general)# authentication-server-group  RADIUS 
    !

    ืื™ื ื˜ื’ืจืฆื™ื” ื–ื• ืืคืฉืจื” ืœื ืจืง ืœืฉืœื‘ ื‘ืžื”ื™ืจื•ืช ืืช ื”ืœื™ืš ื”ืื™ืžื•ืช ืขื ืฉื™ืจื•ืช ื”ืกืคืจื™ื•ืช ืฉืœ AD, ืืœื ื’ื ืœื”ื‘ื—ื™ืŸ ืื ื”ืžื—ืฉื‘ ื”ืžื—ื•ื‘ืจ ืฉื™ื™ืš ืœ-AD, ืœื”ื‘ื™ืŸ ืื ื”ืชืงืŸ ื–ื” ื”ื•ื ืชืื’ื™ื“ื™ ืื• ืื™ืฉื™, ื•ืœื”ืขืจื™ืš ืืช ืžืฆื‘ ื”ืžื›ืฉื™ืจ ื”ืžื—ื•ื‘ืจ. .

    ืคืจื™ืกืช ืืฉื›ื•ืœ ASA VPN ืœืื™ื–ื•ืŸ ืขื•ืžืกื™ื

    ืคืจื™ืกืช ืืฉื›ื•ืœ ASA VPN ืœืื™ื–ื•ืŸ ืขื•ืžืกื™ื

    • ื‘ื•ืื• ื ื’ื“ื™ืจ NAT ืฉืงื•ืฃ ื›ืš ืฉื”ืชืขื‘ื•ืจื” ื‘ื™ืŸ ื”ืœืงื•ื— ืœืžืฉืื‘ื™ ืจืฉืช ื”ืจืฉืช ื”ืืจื’ื•ื ื™ืช ืœื ืชื”ื™ื” ืžืฉื•ืจื‘ื˜ืช:

    vpn-demo-1(config-network-object)#  subnet 192.168.20.0 255.255.255.0
    !
    vpn-demo-1(config)# nat (inside,outside) source static any any destination static vpn-users vpn-users no-proxy-arp

    • (ืื•ืคืฆื™ื•ื ืืœื™): ืœื—ืฉื•ืฃ ืืช ืœืงื•ื—ื•ืชื™ื ื• ืœืื™ื ื˜ืจื ื˜ ื“ืจืš ื”-ASA (ื‘ืขืช ืฉื™ืžื•ืฉ ื”ืžื ื”ืจื” ืืคืฉืจื•ื™ื•ืช) ื‘ืืžืฆืขื•ืช PAT, ื›ืžื• ื’ื ืœืฆืืช ื“ืจืš ืื•ืชื• ืžืžืฉืง OUTSIDE ืฉืžืžื ื• ื”ื ืžื—ื•ื‘ืจื™ื, ืขืœื™ืš ืœื‘ืฆืข ืืช ื”ื”ื’ื“ืจื•ืช ื”ื‘ืื•ืช

    vpn-demo-1(config-network-object)# nat (outside,outside) source dynamic vpn-users interface
    vpn-demo-1(config)# nat (inside,outside) source dynamic any interface
    vpn-demo-1(config)# same-security-traffic permit intra-interface 
    !

    • ื‘ืขืช ืฉื™ืžื•ืฉ ื‘ืืฉื›ื•ืœ, ื—ืฉื•ื‘ ื‘ื™ื•ืชืจ ืœืืคืฉืจ ืœืจืฉืช ื”ืคื ื™ืžื™ืช ืœื”ื‘ื™ืŸ ืื™ื–ื” ASA ืœื ืชื‘ ืชืขื‘ื•ืจืช ื—ื•ื–ืจืช ืœืžืฉืชืžืฉื™ื, ืœืฉื ื›ืš ื™ืฉ ืœื”ืคื™ืฅ ืžื—ื“ืฉ ืžืกืœื•ืœื™ื / 32 ื›ืชื•ื‘ื•ืช ืฉื”ื•ื ืคืงื• ืœืœืงื•ื—ื•ืช.
      ื›ืจื’ืข, ืขื“ื™ื™ืŸ ืœื ื”ื’ื“ืจื ื• ืืช ื”ืืฉื›ื•ืœ, ืื‘ืœ ื›ื‘ืจ ื™ืฉ ืœื ื• ืฉืขืจื™ VPN ืขื•ื‘ื“ื™ื ืฉื ื™ืชืŸ ืœื—ื‘ืจ ื‘ื ืคืจื“ ื“ืจืš FQDN ืื• IP.

    ืคืจื™ืกืช ืืฉื›ื•ืœ ASA VPN ืœืื™ื–ื•ืŸ ืขื•ืžืกื™ื

    ืื ื• ืจื•ืื™ื ืืช ื”ืœืงื•ื— ื”ืžื—ื•ื‘ืจ ื‘ื˜ื‘ืœืช ื”ื ื™ืชื•ื‘ ืฉืœ ื”-ASA ื”ืจืืฉื•ืŸ:

    ืคืจื™ืกืช ืืฉื›ื•ืœ ASA VPN ืœืื™ื–ื•ืŸ ืขื•ืžืกื™ื

    ื›ื“ื™ ืฉื›ืœ ืืฉื›ื•ืœ ื”-VPN ืฉืœื ื• ื•ื›ืœ ื”ืจืฉืช ื”ืืจื’ื•ื ื™ืช ื™ื“ืขื• ืืช ื”ืžืกืœื•ืœ ืœืœืงื•ื— ืฉืœื ื•, ื ืคื™ืฅ ืžื—ื“ืฉ ืืช ืงื™ื“ื•ืžืช ื”ืœืงื•ื— ืœืคืจื•ื˜ื•ืงื•ืœ ื ื™ืชื•ื‘ ื“ื™ื ืžื™, ืœืžืฉืœ OSPF:

    !
    vpn-demo-1(config)# route-map RMAP-VPN-REDISTRIBUTE permit 1
    vpn-demo-1(config-route-map)#  match ip address VPN-REDISTRIBUTE
    !
    vpn-demo-1(config)# router ospf 1
    vpn-demo-1(config-router)#  network 192.168.255.0 255.255.255.0 area 0
    vpn-demo-1(config-router)#  log-adj-changes
    vpn-demo-1(config-router)#  redistribute static metric 5000 subnets route-map RMAP-VPN-REDISTRIBUTE

    ื›ืขืช ื™ืฉ ืœื ื• ื ืชื™ื‘ ืœืœืงื•ื— ืžืฉืขืจ ื”-ASA-2 ื”ืฉื ื™ ื•ืžืฉืชืžืฉื™ื ื”ืžื—ื•ื‘ืจื™ื ืœืฉืขืจื™ VPN ืฉื•ื ื™ื ื‘ืชื•ืš ื”ืืฉื›ื•ืœ ื™ื›ื•ืœื™ื, ืœืžืฉืœ, ืœืชืงืฉืจ ื™ืฉื™ืจื•ืช ื“ืจืš softphone ืืจื’ื•ื ื™, ื›ืžื• ื’ื ืœื”ื—ื–ื™ืจ ืชืขื‘ื•ืจื” ืžื”ืžืฉืื‘ื™ื ื”ืžื‘ื•ืงืฉ ืขืœ ื™ื“ื™ ื”ืžืฉืชืžืฉ ืžื’ื™ืขื™ื ืœืฉืขืจ ื”-VPN ื”ืจืฆื•ื™:

    ืคืจื™ืกืช ืืฉื›ื•ืœ ASA VPN ืœืื™ื–ื•ืŸ ืขื•ืžืกื™ื

  5. ื‘ื•ืื• ื ืขื‘ื•ืจ ืœื”ื’ื“ืจืช ืืฉื›ื•ืœ ืื™ื–ื•ืŸ ื”ืขื•ืžืก.

    ื”ื›ืชื•ื‘ืช 192.168.31.40 ืชืฉืžืฉ ื›-IP ื•ื™ืจื˜ื•ืืœื™ (VIP - ื›ืœ ืœืงื•ื—ื•ืช ื”-VPN ื™ืชื—ื‘ืจื• ืืœื™ื” ื‘ืชื—ื™ืœื”), ืžื›ืชื•ื‘ืช ื–ื• ื”-Master cluster ื™ื‘ืฆืข REDIRECT ืœืฆื•ืžืช ืืฉื›ื•ืœ ืคื—ื•ืช ื˜ืขื•ืŸ. ืืœ ืชืฉื›ื— ืœื›ืชื•ื‘ ืจืฉื•ืžืช DNS ืงื“ื™ืžื” ื•ืื—ื•ืจื” ื”ืŸ ืขื‘ื•ืจ ื›ืœ ื›ืชื•ื‘ืช ื—ื™ืฆื•ื ื™ืช / FQDN ืฉืœ ื›ืœ ืฆื•ืžืช ืฉืœ ื”ืืฉื›ื•ืœ, ื•ื”ืŸ ืขื‘ื•ืจ VIP.

    vpn-demo-1(config)# vpn load-balancing
    vpn-demo-1(config-load-balancing)# interface lbpublic outside
    vpn-demo-1(config-load-balancing)# interface lbprivate inside
    vpn-demo-1(config-load-balancing)# priority 10
    vpn-demo-1(config-load-balancing)# cluster ip address 192.168.31.40
    vpn-demo-1(config-load-balancing)# cluster port 4000
    vpn-demo-1(config-load-balancing)# redirect-fqdn enable
    vpn-demo-1(config-load-balancing)# cluster key cisco
    vpn-demo-1(config-load-balancing)# cluster encryption
    vpn-demo-1(config-load-balancing)# cluster port 9023
    vpn-demo-1(config-load-balancing)# participate
    vpn-demo-1(config-load-balancing)#

    • ืื ื• ื‘ื•ื“ืงื™ื ืืช ืคืขื•ืœืช ื”ืืฉื›ื•ืœ ืขื ืฉื ื™ ืœืงื•ื—ื•ืช ืžื—ื•ื‘ืจื™ื:

    ืคืจื™ืกืช ืืฉื›ื•ืœ ASA VPN ืœืื™ื–ื•ืŸ ืขื•ืžืกื™ื

    • ื‘ื•ืื• ื ื”ืคื•ืš ืืช ื—ื•ื•ื™ืช ื”ืœืงื•ื— ืœื ื•ื—ื” ื™ื•ืชืจ ืขื ืคืจื•ืคื™ืœ AnyConnect ื”ื ื˜ืขืŸ ืื•ื˜ื•ืžื˜ื™ืช ื‘ืืžืฆืขื•ืช ASDM.

    ืคืจื™ืกืช ืืฉื›ื•ืœ ASA VPN ืœืื™ื–ื•ืŸ ืขื•ืžืกื™ื

    ืื ื• ืงื•ืจืื™ื ืœืคืจื•ืคื™ืœ ื‘ืฆื•ืจื” ื ื•ื—ื” ื•ืžืฉื™ื™ื›ื™ื ืืœื™ื• ืืช ื”ืžื“ื™ื ื™ื•ืช ื”ืงื‘ื•ืฆืชื™ืช ืฉืœื ื•:

    ืคืจื™ืกืช ืืฉื›ื•ืœ ASA VPN ืœืื™ื–ื•ืŸ ืขื•ืžืกื™ื

    ืœืื—ืจ ื”ื—ื™ื‘ื•ืจ ื”ื‘ื ืฉืœ ื”ืœืงื•ื—, ืคืจื•ืคื™ืœ ื–ื” ื™ื•ืจื™ื“ ื•ื™ื•ืชืงืŸ ื‘ืื•ืคืŸ ืื•ื˜ื•ืžื˜ื™ ื‘ืœืงื•ื— AnyConnect, ื›ืš ืฉืื ืืชื” ืฆืจื™ืš ืœื”ืชื—ื‘ืจ, ืคืฉื•ื˜ ื‘ื—ืจ ืื•ืชื• ืžื”ืจืฉื™ืžื”:

    ืคืจื™ืกืช ืืฉื›ื•ืœ ASA VPN ืœืื™ื–ื•ืŸ ืขื•ืžืกื™ื

    ืžื›ื™ื•ื•ืŸ ืฉื™ืฆืจื ื• ืคืจื•ืคื™ืœ ื–ื” ืจืง ื‘-ASA ืื—ื“ ื‘ืืžืฆืขื•ืช ASDM, ืืœ ืชืฉื›ื— ืœื—ื–ื•ืจ ืขืœ ื”ืฉืœื‘ื™ื ื‘ืฉืืจ ื”-ASAs ื‘ืืฉื›ื•ืœ.

ืžืกืงื ื”: ืœืคื™ื›ืš, ืคืจืกื ื• ื‘ืžื”ื™ืจื•ืช ืืฉื›ื•ืœ ืฉืœ ืžืกืคืจ ืฉืขืจื™ื ืฉืœ VPN ืขื ืื™ื–ื•ืŸ ืขื•ืžืกื™ื ืื•ื˜ื•ืžื˜ื™. ื”ื•ืกืคืช ืฆืžืชื™ื ื—ื“ืฉื™ื ืœืืฉื›ื•ืœ ื”ื™ื ืงืœื”, ืขื ืงื ื” ืžื™ื“ื” ืื•ืคืงื™ ืคืฉื•ื˜ ืขืœ ื™ื“ื™ ืคืจื™ืกืช ืžื›ื•ื ื•ืช ื•ื™ืจื˜ื•ืืœื™ื•ืช ื—ื“ืฉื•ืช ืฉืœ ASAv ืื• ืฉื™ืžื•ืฉ ื‘-ASA ื—ื•ืžืจื”. ืœืงื•ื— AnyConnect ืขืฉื™ืจ ื‘ืชื›ื•ื ื•ืช ื™ื›ื•ืœ ืœืฉืคืจ ืžืื•ื“ ืืช ื”ื—ื™ื‘ื•ืจ ื”ืžืื•ื‘ื˜ื— ืžืจื—ื•ืง ืขืœ ื™ื“ื™ ืฉื™ืžื•ืฉ ื‘ ื™ืฆื™ื‘ื” (ื”ืขืจื›ื•ืช ืžื“ื™ื ื”), ื‘ืฉื™ืžื•ืฉ ื”ื™ืขื™ืœ ื‘ื™ื•ืชืจ ื‘ืฉื™ืœื•ื‘ ืขื ืžืขืจื›ืช ื‘ืงืจื” ืžืจื›ื–ื™ืช ื•ื—ืฉื‘ื•ื ืื•ืช ื’ื™ืฉื” ืžื ื•ืข ืฉื™ืจื•ืชื™ ื–ื”ื•ืช.

ืžืงื•ืจ: www.habr.com

ื”ื•ืกืคืช ืชื’ื•ื‘ื”