VMware NSX ืœืงื˜ื ื˜ื ื™ื. ื—ืœืง 6: ื”ื’ื“ืจืช VPN

VMware NSX ืœืงื˜ื ื˜ื ื™ื. ื—ืœืง 6: ื”ื’ื“ืจืช VPN

ื—ืœืง ืจืืฉื•ืŸ. ืึฒืงึธื“ึตืžึทืึดื™
ื—ืœืง ืฉื ื™. ื”ื’ื“ืจืช ื›ืœืœื™ ื—ื•ืžืช ืืฉ ื•ื›ืœืœื™ NAT
ื—ืœืง ืฉืœื™ืฉื™. ื”ื’ื“ืจืช DHCP
ื—ืœืง ืจื‘ื™ืขื™. ื”ื’ื“ืจืช ื ื™ืชื•ื‘
ื—ืœืง ื—ืžื™ืฉื™. ื”ืงืžืช ืžืื–ืŸ ืขื•ืžืกื™ื

ื”ื™ื•ื ืื ื—ื ื• ื”ื•ืœื›ื™ื ืœื”ืกืชื›ืœ ืขืœ ืืคืฉืจื•ื™ื•ืช ืชืฆื•ืจืช ื”-VPN ืฉ-NSX Edge ืžืฆื™ืขื” ืœื ื•.

ื‘ืื•ืคืŸ ื›ืœืœื™, ืื ื• ื™ื›ื•ืœื™ื ืœื—ืœืง ืืช ื˜ื›ื ื•ืœื•ื’ื™ื•ืช VPN ืœืฉื ื™ ืกื•ื’ื™ื ืžืจื›ื–ื™ื™ื:

  • VPN ืžืืชืจ ืœืืชืจ. ื”ืฉื™ืžื•ืฉ ื”ื ืคื•ืฅ ื‘ื™ื•ืชืจ ื‘-IPSec ื”ื•ื ื™ืฆื™ืจืช ืžื ื”ืจื” ืžืื•ื‘ื˜ื—ืช, ืœืžืฉืœ, ื‘ื™ืŸ ืจืฉืช ืžืฉืจื“ื™ืช ืจืืฉื™ืช ืœืจืฉืช ื‘ืืชืจ ืžืจื•ื—ืง ืื• ื‘ืขื ืŸ.
  • VPN ื’ื™ืฉื” ืžืจื—ื•ืง. ืžืฉืžืฉ ืœื—ื™ื‘ื•ืจ ืžืฉืชืžืฉื™ื ื‘ื•ื“ื“ื™ื ืœืจืฉืชื•ืช ืคืจื˜ื™ื•ืช ืืจื’ื•ื ื™ื•ืช ื‘ืืžืฆืขื•ืช ืชื•ื›ื ืช ืœืงื•ื— VPN.

NSX Edge ืžืืคืฉืจ ืœื ื• ืœื”ืฉืชืžืฉ ื‘ืฉืชื™ ื”ืืคืฉืจื•ื™ื•ืช.
ื ืขืจื•ืš ืชืฆื•ืจื” ื‘ืืžืฆืขื•ืช ืกืคืกืœ ื‘ื“ื™ืงื” ืขื ืฉื ื™ NSX Edge, ืฉืจืช ืœื™ื ื•ืงืก ืขื ื“ืžื•ืŸ ืžื•ืชืงืŸ ืจืงื˜ื•ืŸ ื•ืžื—ืฉื‘ ื ื™ื™ื“ ืฉืœ Windows ืœื‘ื“ื™ืงืช VPN ืฉืœ ื’ื™ืฉื” ืžืจื—ื•ืง.

IPsec

  1. ื‘ืžืžืฉืง vCloud Director, ืขื‘ื•ืจ ืœืงื˜ืข ื ื™ื”ื•ืœ ื•ื‘ื—ืจ ื‘-vDC. ื‘ืœืฉื•ื ื™ืช Edge Gateways, ื‘ื—ืจ ืืช ื”-Edge ืฉืื ื—ื ื• ืฆืจื™ื›ื™ื, ืœื—ืฅ ืœื—ื™ืฆื” ื™ืžื ื™ืช ื•ื‘ื—ืจ Edge Gateway Services.
    VMware NSX ืœืงื˜ื ื˜ื ื™ื. ื—ืœืง 6: ื”ื’ื“ืจืช VPN
  2. ื‘ืžืžืฉืง NSX Edge, ืขื‘ื•ืจ ืœืœืฉื•ื ื™ืช VPN-IPsec VPN, ื•ืœืื—ืจ ืžื›ืŸ ืœืงื˜ืข IPsec VPN Sites ื•ืœื—ืฅ ืขืœ + ื›ื“ื™ ืœื”ื•ืกื™ืฃ ืืชืจ ื—ื“ืฉ.

    VMware NSX ืœืงื˜ื ื˜ื ื™ื. ื—ืœืง 6: ื”ื’ื“ืจืช VPN

  3. ืžืœื ืืช ื”ืฉื“ื•ืช ื”ื ื“ืจืฉื™ื:
    • ืžื•ืคืขืœ โ€“ ืžืคืขื™ืœ ืืช ื”ืืชืจ ื”ืžืจื•ื—ืง.
    • PFS - ืžื‘ื˜ื™ื— ืฉื›ืœ ืžืคืชื— ืงืจื™ืคื˜ื•ื’ืจืคื™ ื—ื“ืฉ ืื™ื ื• ืžืฉื•ื™ืš ืœืžืคืชื— ืงื•ื“ื ื›ืœืฉื”ื•.
    • ืžื–ื”ื” ืžืงื•ืžื™ ื•ื ืงื•ื“ืช ืงืฆื” ืžืงื•ืžื™ืชt ื”ื™ื ื”ื›ืชื•ื‘ืช ื”ื—ื™ืฆื•ื ื™ืช ืฉืœ ื”-NSX Edge.
    • ืจืฉืช ืžืฉื ื” ืžืงื•ืžื™ืชs - ืจืฉืชื•ืช ืžืงื•ืžื™ื•ืช ืฉื™ืฉืชืžืฉื• ื‘-IPsec VPN.
    • ืžื–ื”ื” ืขืžื™ืช ื•ื ืงื•ื“ืช ืงืฆื” ืขืžื™ืช - ื›ืชื•ื‘ืช ื”ืืชืจ ื”ืžืจื•ื—ืง.
    • ืจืฉืชื•ืช ืžืฉื ื” ืฉืœ ืขืžื™ืชื™ื - ืจืฉืชื•ืช ืฉื™ืฉืชืžืฉื• ื‘-IPsec VPN ื‘ืฆื“ ื”ืžืจื•ื—ืง.
    • ืืœื’ื•ืจื™ืชื ื”ืฆืคื ื” - ืืœื’ื•ืจื™ืชื ื”ืฆืคื ืช ืžื ื”ืจื”.

    VMware NSX ืœืงื˜ื ื˜ื ื™ื. ื—ืœืง 6: ื”ื’ื“ืจืช VPN

    • ืื™ืžื•ืช - ื›ื™ืฆื“ ื ืืžืช ืืช ื”ืขืžื™ืช. ืืชื” ื™ื›ื•ืœ ืœื”ืฉืชืžืฉ ื‘ืžืคืชื— ืžืฉื•ืชืฃ ืžืจืืฉ ืื• ื‘ืชืขื•ื“ื”.
    • ืžืคืชื— ืžืฉื•ืชืฃ ืžืจืืฉ - ืฆื™ื™ืŸ ืืช ื”ืžืคืชื— ืฉื™ืฉืžืฉ ืœืื™ืžื•ืช ื•ื—ื™ื™ื‘ ืœื”ืชืื™ื ืžืฉื ื™ ื”ืฆื“ื“ื™ื.
    • ืงื‘ื•ืฆืช ื“ื™ืคื™ ื”ืœืžืŸ - ืืœื’ื•ืจื™ืชื ื”ื—ืœืคืช ืžืคืชื—ื•ืช.

    ืœืื—ืจ ืžื™ืœื•ื™ ื”ืฉื“ื•ืช ื”ื ื“ืจืฉื™ื, ืœื—ืฅ ืขืœ ืฉืžื•ืจ.

    VMware NSX ืœืงื˜ื ื˜ื ื™ื. ื—ืœืง 6: ื”ื’ื“ืจืช VPN

  4. ืกื™ื™ืžืชื™.

    VMware NSX ืœืงื˜ื ื˜ื ื™ื. ื—ืœืง 6: ื”ื’ื“ืจืช VPN

  5. ืœืื—ืจ ื”ื•ืกืคืช ื”ืืชืจ, ืขื‘ื•ืจ ืœืœืฉื•ื ื™ืช ืžืฆื‘ ื”ืคืขืœื” ื•ื”ืคืขืœ ืืช ืฉื™ืจื•ืช IPsec.

    VMware NSX ืœืงื˜ื ื˜ื ื™ื. ื—ืœืง 6: ื”ื’ื“ืจืช VPN

  6. ืœืื—ืจ ื”ื—ืœืช ื”ื”ื’ื“ืจื•ืช, ืขื‘ื•ืจ ืืœ ื”ื›ืจื˜ื™ืกื™ื™ื” ืกื˜ื˜ื™ืกื˜ื™ืงื” -> IPsec VPN ื•ื‘ื“ื•ืง ืืช ืžืฆื‘ ื”ืžื ื”ืจื”. ืื ื—ื ื• ืจื•ืื™ื ืฉื”ืžื ื”ืจื” ืขืœืชื”.

    VMware NSX ืœืงื˜ื ื˜ื ื™ื. ื—ืœืง 6: ื”ื’ื“ืจืช VPN

  7. ื‘ื“ื•ืง ืืช ืžืฆื‘ ื”ืžื ื”ืจื” ืžืžืกื•ืฃ ื”ืฉืขืจ ืฉืœ Edge:
    • show service ipsec - ื‘ื“ื•ืง ืืช ืžืฆื‘ ื”ืฉื™ืจื•ืช.

      VMware NSX ืœืงื˜ื ื˜ื ื™ื. ื—ืœืง 6: ื”ื’ื“ืจืช VPN

    • show service ipsec site - ืžื™ื“ืข ืขืœ ืžืฆื‘ ื”ืืชืจ ื•ืคืจืžื˜ืจื™ื ืฉืœ ืžืฉื ื•ืžืชืŸ.

      VMware NSX ืœืงื˜ื ื˜ื ื™ื. ื—ืœืง 6: ื”ื’ื“ืจืช VPN

    • ื”ืฆื’ ืฉื™ืจื•ืช ipsec sa - ื‘ื“ื•ืง ืืช ืกื˜ื˜ื•ืก ืื™ื’ื•ื“ ื”ืื‘ื˜ื—ื” (SA).

      VMware NSX ืœืงื˜ื ื˜ื ื™ื. ื—ืœืง 6: ื”ื’ื“ืจืช VPN

  8. ื‘ื“ื™ืงืช ืงื™ืฉื•ืจื™ื•ืช ืขื ืืชืจ ืžืจื•ื—ืง:
    root@racoon:~# ifconfig eth0:1 | grep inet
            inet 10.255.255.1  netmask 255.255.255.0  broadcast 0.0.0.0
    
    root@racoon:~# ping -c1 -I 10.255.255.1 192.168.0.10 
    PING 192.168.0.10 (192.168.0.10) from 10.255.255.1 : 56(84) bytes of data.
    64 bytes from 192.168.0.10: icmp_seq=1 ttl=63 time=59.9 ms
    
    --- 192.168.0.10 ping statistics ---
    1 packets transmitted, 1 received, 0% packet loss, time 0ms
    rtt min/avg/max/mdev = 59.941/59.941/59.941/0.000 ms
    

    ืงื‘ืฆื™ ืชืฆื•ืจื” ื•ืคืงื•ื“ื•ืช ื ื•ืกืคื•ืช ืœืื‘ื—ื•ืŸ ืžืฉืจืช ืœื™ื ื•ืงืก ืžืจื•ื—ืง:

    root@racoon:~# cat /etc/racoon/racoon.conf 
    
    log debug;
    path pre_shared_key "/etc/racoon/psk.txt";
    path certificate "/etc/racoon/certs";
    
    listen {
      isakmp 80.211.43.73 [500];
       strict_address;
    }
    
    remote 185.148.83.16 {
            exchange_mode main,aggressive;
            proposal {
                     encryption_algorithm aes256;
                     hash_algorithm sha1;
                     authentication_method pre_shared_key;
                     dh_group modp1536;
             }
             generate_policy on;
    }
     
    sainfo address 10.255.255.0/24 any address 192.168.0.0/24 any {
             encryption_algorithm aes256;
             authentication_algorithm hmac_sha1;
             compression_algorithm deflate;
    }
    
    ===
    
    root@racoon:~# cat /etc/racoon/psk.txt
    185.148.83.16 testkey
    
    ===
    
    root@racoon:~# cat /etc/ipsec-tools.conf 
    #!/usr/sbin/setkey -f
    
    flush;
    spdflush;
    
    spdadd 192.168.0.0/24 10.255.255.0/24 any -P in ipsec
          esp/tunnel/185.148.83.16-80.211.43.73/require;
    
    spdadd 10.255.255.0/24 192.168.0.0/24 any -P out ipsec
          esp/tunnel/80.211.43.73-185.148.83.16/require;
    
    ===
    
    
    root@racoon:~# racoonctl show-sa isakmp
    Destination            Cookies                           Created
    185.148.83.16.500      2088977aceb1b512:a4c470cb8f9d57e9 2019-05-22 13:46:13 
    
    ===
    
    root@racoon:~# racoonctl show-sa esp
    80.211.43.73 185.148.83.16 
            esp mode=tunnel spi=1646662778(0x6226147a) reqid=0(0x00000000)
            E: aes-cbc  00064df4 454d14bc 9444b428 00e2296e c7bb1e03 06937597 1e522ce0 641e704d
            A: hmac-sha1  aa9e7cd7 51653621 67b3b2e9 64818de5 df848792
            seq=0x00000000 replay=4 flags=0x00000000 state=mature 
            created: May 22 13:46:13 2019   current: May 22 14:07:43 2019
            diff: 1290(s)   hard: 3600(s)   soft: 2880(s)
            last: May 22 13:46:13 2019      hard: 0(s)      soft: 0(s)
            current: 72240(bytes)   hard: 0(bytes)  soft: 0(bytes)
            allocated: 860  hard: 0 soft: 0
            sadb_seq=1 pid=7739 refcnt=0
    185.148.83.16 80.211.43.73 
            esp mode=tunnel spi=88535449(0x0546f199) reqid=0(0x00000000)
            E: aes-cbc  c812505a 9c30515e 9edc8c4a b3393125 ade4c320 9bde04f0 94e7ba9d 28e61044
            A: hmac-sha1  cd9d6f6e 06dbcd6d da4d14f8 6d1a6239 38589878
            seq=0x00000000 replay=4 flags=0x00000000 state=mature 
            created: May 22 13:46:13 2019   current: May 22 14:07:43 2019
            diff: 1290(s)   hard: 3600(s)   soft: 2880(s)
            last: May 22 13:46:13 2019      hard: 0(s)      soft: 0(s)
            current: 72240(bytes)   hard: 0(bytes)  soft: 0(bytes)
            allocated: 860  hard: 0 soft: 0
            sadb_seq=0 pid=7739 refcnt=0

  9. ื”ื›ืœ ืžื•ื›ืŸ, IPsec VPN ืžืืชืจ ืœืืชืจ ืคื•ืขืœ.

    ื‘ื“ื•ื’ืžื” ื–ื•, ื”ืฉืชืžืฉื ื• ื‘-PSK ืขื‘ื•ืจ ืื™ืžื•ืช ืขืžื™ืชื™ื, ืืš ืื™ืžื•ืช ืชืขื•ื“ื” ืืคืฉืจื™ ื’ื. ืœืฉื ื›ืš, ืขื‘ื•ืจ ืœืœืฉื•ื ื™ืช Global Configuration, ื”ืคืขืœ ืื™ืžื•ืช ืื™ืฉื•ืจ ื•ื‘ื—ืจ ืืช ื”ืื™ืฉื•ืจ ืขืฆืžื•.

    ื‘ื ื•ืกืฃ, ื‘ื”ื’ื“ืจื•ืช ื”ืืชืจ ืชืฆื˜ืจืš ืœืฉื ื•ืช ืืช ืฉื™ื˜ืช ื”ืื™ืžื•ืช.

    VMware NSX ืœืงื˜ื ื˜ื ื™ื. ื—ืœืง 6: ื”ื’ื“ืจืช VPN

    VMware NSX ืœืงื˜ื ื˜ื ื™ื. ื—ืœืง 6: ื”ื’ื“ืจืช VPN

    ืื ื™ ืžืฆื™ื™ืŸ ืฉืžืกืคืจ ืžื ื”ืจื•ืช ื”-IPsec ืชืœื•ื™ ื‘ื’ื•ื“ืœ ื”-Edge Gateway ื”ืคืจื•ืก (ืงืจื ืขืœ ื›ืš ื‘- ืžืืžืจ ืจืืฉื•ืŸ).

    VMware NSX ืœืงื˜ื ื˜ื ื™ื. ื—ืœืง 6: ื”ื’ื“ืจืช VPN

SSL VPN

SSL VPN-Plus ื”ื™ื ืื—ืช ืžืืคืฉืจื•ื™ื•ืช ื”-VPN ืฉืœ ื’ื™ืฉื” ืžืจื—ื•ืง. ื–ื” ืžืืคืฉืจ ืœืžืฉืชืžืฉื™ื ืžืจื•ื—ืงื™ื ื‘ื•ื“ื“ื™ื ืœื”ืชื—ื‘ืจ ื‘ืฆื•ืจื” ืžืื•ื‘ื˜ื—ืช ืœืจืฉืชื•ืช ืคืจื˜ื™ื•ืช ืžืื—ื•ืจื™ NSX Edge Gateway. ืžื ื”ืจื” ืžื•ืฆืคื ืช ื‘ืžืงืจื” ืฉืœ SSL VPN-plus ื ื•ืฆืจืช ื‘ื™ืŸ ื”ืœืงื•ื— (Windows, Linux, Mac) ื•-NSX Edge.

  1. ื‘ื•ืื• ื ืชื—ื™ืœ ืœื”ื’ื“ื™ืจ. ื‘ืœื•ื— ื”ื‘ืงืจื” ืฉืœ ืฉื™ืจื•ืช Edge Gateway, ืขื‘ื•ืจ ืืœ ื”ื›ืจื˜ื™ืกื™ื™ื” SSL VPN-Plus ื•ืœืื—ืจ ืžื›ืŸ ืืœ ื”ื’ื“ืจื•ืช ืฉืจืช. ืื ื• ื‘ื•ื—ืจื™ื ืืช ื”ื›ืชื•ื‘ืช ื•ื”ื™ืฆื™ืื” ืฉื‘ื” ื”ืฉืจืช ื™ืงืฉื™ื‘ ืœื—ื™ื‘ื•ืจื™ื ื ื›ื ืกื™ื, ืžืืคืฉืจื™ื ืจื™ืฉื•ื ื•ื‘ื•ื—ืจื™ื ืืช ืืœื’ื•ืจื™ืชืžื™ ื”ื”ืฆืคื ื” ื”ื“ืจื•ืฉื™ื.

    VMware NSX ืœืงื˜ื ื˜ื ื™ื. ื—ืœืง 6: ื”ื’ื“ืจืช VPN

    ื›ืืŸ ืชื•ื›ืœ ื’ื ืœืฉื ื•ืช ืืช ื”ืื™ืฉื•ืจ ืฉื”ืฉืจืช ื™ืฉืชืžืฉ ื‘ื•.

    VMware NSX ืœืงื˜ื ื˜ื ื™ื. ื—ืœืง 6: ื”ื’ื“ืจืช VPN

  2. ืœืื—ืจ ืฉื”ื›ืœ ืžื•ื›ืŸ, ื”ืคืขืœ ืืช ื”ืฉืจืช ื•ืืœ ืชืฉื›ื— ืœืฉืžื•ืจ ืืช ื”ื”ื’ื“ืจื•ืช.

    VMware NSX ืœืงื˜ื ื˜ื ื™ื. ื—ืœืง 6: ื”ื’ื“ืจืช VPN

  3. ืœืื—ืจ ืžื›ืŸ, ืขืœื™ื ื• ืœื”ื’ื“ื™ืจ ืžืื’ืจ ื›ืชื•ื‘ื•ืช ืฉื ื ืคื™ืง ืœืœืงื•ื—ื•ืช ืขื ื”ื—ื™ื‘ื•ืจ. ืจืฉืช ื–ื• ื ืคืจื“ืช ืžื›ืœ ืชืช ืจืฉืช ืงื™ื™ืžืช ื‘ืกื‘ื™ื‘ืช ื”-NSX ืฉืœืš ื•ืื™ืŸ ืฆื•ืจืš ืœื”ื’ื“ื™ืจ ืื•ืชื” ื‘ืžื›ืฉื™ืจื™ื ืื—ืจื™ื ื‘ืจืฉืชื•ืช ื”ืคื™ื–ื™ื•ืช, ืœืžืขื˜ ื”ืžืกืœื•ืœื™ื ื”ืžืฆื‘ื™ืขื™ื ืขืœื™ื”.

    ืขื‘ื•ืจ ืœืœืฉื•ื ื™ืช IP Pools ื•ืœื—ืฅ ืขืœ +.

    VMware NSX ืœืงื˜ื ื˜ื ื™ื. ื—ืœืง 6: ื”ื’ื“ืจืช VPN

  4. ื‘ื—ืจ ื›ืชื•ื‘ื•ืช, ืžืกื›ืช ืจืฉืช ืžืฉื ื” ื•ืฉืขืจ. ื›ืืŸ ืชื•ื›ืœ ื’ื ืœืฉื ื•ืช ืืช ื”ื”ื’ื“ืจื•ืช ืขื‘ื•ืจ ืฉืจืชื™ DNS ื•-WINS.

    VMware NSX ืœืงื˜ื ื˜ื ื™ื. ื—ืœืง 6: ื”ื’ื“ืจืช VPN

  5. ื”ื‘ืจื™ื›ื” ืฉื ื•ืฆืจื”.

    VMware NSX ืœืงื˜ื ื˜ื ื™ื. ื—ืœืง 6: ื”ื’ื“ืจืช VPN

  6. ื›ืขืช ื ื•ืกื™ืฃ ืืช ื”ืจืฉืชื•ืช ืฉืืœื™ื”ืŸ ืชื”ื™ื” ื’ื™ืฉื” ืœืžืฉืชืžืฉื™ื ื”ืžืชื—ื‘ืจื™ื ืœ-VPN. ืขื‘ื•ืจ ืืœ ื”ื›ืจื˜ื™ืกื™ื™ื” ืจืฉืชื•ืช ืคืจื˜ื™ื•ืช ื•ืœื—ืฅ ืขืœ +.

    VMware NSX ืœืงื˜ื ื˜ื ื™ื. ื—ืœืง 6: ื”ื’ื“ืจืช VPN

  7. ืื ื• ืžืžืœืื™ื:
    • ืจืฉืช - ืจืฉืช ืžืงื•ืžื™ืช ืฉืืœื™ื” ืชื”ื™ื” ื’ื™ืฉื” ืœืžืฉืชืžืฉื™ื ืžืจื•ื—ืงื™ื.
    • ืฉืœื— ืชื ื•ืขื”, ื™ืฉ ืœื• ืฉืชื™ ืืคืฉืจื•ื™ื•ืช:
      - ืžืขืœ ื”ืžื ื”ืจื” - ืฉืœื— ืชืขื‘ื•ืจื” ืœืจืฉืช ื“ืจืš ื”ืžื ื”ืจื”,
      - ืขื•ืงืฃ ืžื ื”ืจื” - ืฉืœื— ืชื ื•ืขื” ืœืจืฉืช ื™ืฉื™ืจื•ืช ืขื•ืงืฃ ืืช ื”ืžื ื”ืจื”.
    • ื”ืคืขืœ ืื•ืคื˜ื™ืžื™ื–ืฆื™ื” ืฉืœ TCP - ื‘ื“ื•ืง ืื ื‘ื—ืจืช ื‘ืืคืฉืจื•ืช ืžืขื‘ืจ ืœืžื ื”ืจื”. ื›ืืฉืจ ืื•ืคื˜ื™ืžื™ื–ืฆื™ื” ืžื•ืคืขืœืช, ืืชื” ื™ื›ื•ืœ ืœืฆื™ื™ืŸ ืืช ืžืกืคืจื™ ื”ื™ืฆื™ืื” ืฉืขื‘ื•ืจื ื‘ืจืฆื•ื ืš ืœื™ื™ืขืœ ืืช ื”ืชืขื‘ื•ืจื”. ื”ืชื ื•ืขื” ืขื‘ื•ืจ ื”ื™ืฆื™ืื•ืช ื”ื ื•ืชืจื•ืช ื‘ืจืฉืช ื”ืžืกื•ื™ืžืช ืœื ืชืขื‘ื•ืจ ืื•ืคื˜ื™ืžื™ื–ืฆื™ื”. ืื ืœื ืฆื•ื™ื ื• ืžืกืคืจื™ ื™ืฆื™ืื•ืช, ื”ืชืขื‘ื•ืจื” ืขื‘ื•ืจ ื›ืœ ื”ื™ืฆื™ืื•ืช ืขื•ื‘ืจืช ืื•ืคื˜ื™ืžื™ื–ืฆื™ื”. ืงืจื ืขื•ื“ ืขืœ ืชื›ื•ื ื” ื–ื• ื›ืืŸ.

    VMware NSX ืœืงื˜ื ื˜ื ื™ื. ื—ืœืง 6: ื”ื’ื“ืจืช VPN

  8. ืœืื—ืจ ืžื›ืŸ, ืขื‘ื•ืจ ืœืœืฉื•ื ื™ืช ืื™ืžื•ืช ื•ืœื—ืฅ ืขืœ +. ืœืฆื•ืจืš ืื™ืžื•ืช, ื ืฉืชืžืฉ ื‘ืฉืจืช ืžืงื•ืžื™ ื‘-NSX Edge ืขืฆืžื•.

    VMware NSX ืœืงื˜ื ื˜ื ื™ื. ื—ืœืง 6: ื”ื’ื“ืจืช VPN

  9. ื›ืืŸ ื ื•ื›ืœ ืœื‘ื—ื•ืจ ืžื“ื™ื ื™ื•ืช ืœื™ืฆื™ืจืช ืกื™ืกืžืื•ืช ื—ื“ืฉื•ืช ื•ืœื”ื’ื“ื™ืจ ืืคืฉืจื•ื™ื•ืช ืœื—ืกื™ืžืช ื—ืฉื‘ื•ื ื•ืช ืžืฉืชืžืฉ (ืœื“ื•ื’ืžื”, ืžืกืคืจ ื”ื ื™ืกื™ื•ื ื•ืช ื”ื—ื•ื–ืจื™ื ืื ื”ืกื™ืกืžื” ื”ื•ื–ื ื” ื‘ืฆื•ืจื” ืฉื’ื•ื™ื”).

    VMware NSX ืœืงื˜ื ื˜ื ื™ื. ื—ืœืง 6: ื”ื’ื“ืจืช VPN

    VMware NSX ืœืงื˜ื ื˜ื ื™ื. ื—ืœืง 6: ื”ื’ื“ืจืช VPN

  10. ืžื›ื™ื•ื•ืŸ ืฉืื ื• ืžืฉืชืžืฉื™ื ื‘ืื™ืžื•ืช ืžืงื•ืžื™, ืขืœื™ื ื• ืœื™ืฆื•ืจ ืžืฉืชืžืฉื™ื.

    VMware NSX ืœืงื˜ื ื˜ื ื™ื. ื—ืœืง 6: ื”ื’ื“ืจืช VPN

  11. ื‘ื ื•ืกืฃ ืœื“ื‘ืจื™ื ื‘ืกื™ืกื™ื™ื ื›ืžื• ืฉื ื•ืกื™ืกืžื”, ื›ืืŸ ืืคืฉืจ ืœืžืฉืœ ืœืืกื•ืจ ืขืœ ื”ืžืฉืชืžืฉ ืœืฉื ื•ืช ืืช ื”ืกื™ืกืžื” ืื• ืœื”ื™ืคืš, ืœืืœืฅ ืื•ืชื• ืœื”ื—ืœื™ืฃ ืืช ื”ืกื™ืกืžื” ื‘ืคืขื ื”ื‘ืื” ืฉื”ื•ื ืžืชื—ื‘ืจ.

    VMware NSX ืœืงื˜ื ื˜ื ื™ื. ื—ืœืง 6: ื”ื’ื“ืจืช VPN

  12. ืœืื—ืจ ื”ื•ืกืคืช ื›ืœ ื”ืžืฉืชืžืฉื™ื ื”ื“ืจื•ืฉื™ื, ืขื‘ื•ืจ ืœืœืฉื•ื ื™ืช ื—ื‘ื™ืœื•ืช ื”ืชืงื ื”, ืœื—ืฅ ืขืœ + ื•ืฆื•ืจ ืืช ื”ืžืชืงื™ืŸ ืขืฆืžื•, ืื•ืชื• ื™ื•ืจื™ื“ ืขื•ื‘ื“ ืžืจื•ื—ืง ืœื”ืชืงื ื”.

    VMware NSX ืœืงื˜ื ื˜ื ื™ื. ื—ืœืง 6: ื”ื’ื“ืจืช VPN

  13. ื”ืงืฉ ืขืœ +. ื‘ื—ืจ ืืช ื”ื›ืชื•ื‘ืช ื•ื”ื™ืฆื™ืื” ืฉืœ ื”ืฉืจืช ืฉืืœื™ื• ื”ืœืงื•ื— ื™ืชื—ื‘ืจ, ื•ืืช ื”ืคืœื˜ืคื•ืจืžื•ืช ืฉืขื‘ื•ืจืŸ ื‘ืจืฆื•ื ืš ืœื”ืคื™ืง ืืช ื—ื‘ื™ืœืช ื”ื”ืชืงื ื”.

    VMware NSX ืœืงื˜ื ื˜ื ื™ื. ื—ืœืง 6: ื”ื’ื“ืจืช VPN

    ืœืžื˜ื” ื‘ื—ืœื•ืŸ ื–ื”, ืืชื” ื™ื›ื•ืœ ืœืฆื™ื™ืŸ ืืช ื”ื’ื“ืจื•ืช ื”ืœืงื•ื— ืขื‘ื•ืจ Windows. ื‘ื—ืจ:

    • ื”ืชื—ืœ ืœืงื•ื— ื‘ื›ื ื™ืกื” - ืœืงื•ื— ื”-VPN ื™ืชื•ื•ืกืฃ ืœืืชื—ื•ืœ ื‘ืžื—ืฉื‘ ื”ืžืจื•ื—ืง;
    • ื™ืฆื™ืจืช ืกืžืœ ืฉื•ืœื—ืŸ ื”ืขื‘ื•ื“ื” - ื™ืฆื•ืจ ืกืžืœ ืœืงื•ื— VPN ื‘ืฉื•ืœื—ืŸ ื”ืขื‘ื•ื“ื”;
    • ืื™ืžื•ืช ืื™ืฉื•ืจ ืฉืจืช ืื‘ื˜ื—ื” - ื™ืืžืช ืืช ืื™ืฉื•ืจ ื”ืฉืจืช ืขื ื”ื—ื™ื‘ื•ืจ.
      ื”ื’ื“ืจืช ื”ืฉืจืช ื”ื•ืฉืœืžื”.

    VMware NSX ืœืงื˜ื ื˜ื ื™ื. ื—ืœืง 6: ื”ื’ื“ืจืช VPN

  14. ื›ืขืช ื”ื‘ื” ื ื•ืจื™ื“ ืืช ื—ื‘ื™ืœืช ื”ื”ืชืงื ื” ืฉื™ืฆืจื ื• ื‘ืฉืœื‘ ื”ืื—ืจื•ืŸ ืœืžื—ืฉื‘ ืžืจื•ื—ืง. ื‘ืขืช ื”ื’ื“ืจืช ื”ืฉืจืช, ืฆื™ื™ื ื• ืืช ื”ื›ืชื•ื‘ืช ื”ื—ื™ืฆื•ื ื™ืช ืฉืœื• (185.148.83.16) ื•ื”ื™ืฆื™ืื” (445). ื‘ื›ืชื•ื‘ืช ื”ื–ื• ืื ื—ื ื• ืฆืจื™ื›ื™ื ืœื”ื™ื›ื ืก ืœื“ืคื“ืคืŸ ืื™ื ื˜ืจื ื˜. ื‘ืžืงืจื” ืฉืœื™ ื–ื” ื›ืŸ 185.148.83.16: 445.

    ื‘ื—ืœื•ืŸ ื”ื”ืจืฉืื”, ืขืœื™ืš ืœื”ื–ื™ืŸ ืืช ืื™ืฉื•ืจื™ ื”ืžืฉืชืžืฉ ืฉื™ืฆืจื ื• ืงื•ื“ื ืœื›ืŸ.

    VMware NSX ืœืงื˜ื ื˜ื ื™ื. ื—ืœืง 6: ื”ื’ื“ืจืช VPN

  15. ืœืื—ืจ ืื™ืฉื•ืจ, ืื ื• ืจื•ืื™ื ืจืฉื™ืžื” ืฉืœ ื—ื‘ื™ืœื•ืช ื”ืชืงื ื” ืฉื ื•ืฆืจื• ื”ื–ืžื™ื ื•ืช ืœื”ื•ืจื“ื”. ื™ืฆืจื ื• ืจืง ืื—ื“ - ื ื•ืจื™ื“ ืื•ืชื•.

    VMware NSX ืœืงื˜ื ื˜ื ื™ื. ื—ืœืง 6: ื”ื’ื“ืจืช VPN

  16. ืื ื• ืœื•ื—ืฆื™ื ืขืœ ื”ืงื™ืฉื•ืจ, ื”ื”ื•ืจื“ื” ืฉืœ ื”ืœืงื•ื— ืžืชื—ื™ืœื”.

    VMware NSX ืœืงื˜ื ื˜ื ื™ื. ื—ืœืง 6: ื”ื’ื“ืจืช VPN

  17. ืคืจืง ืืช ื”ืืจื›ื™ื•ืŸ ืฉื”ื•ืจื“ืช ื•ื”ืคืขืœ ืืช ืชื•ื›ื ื™ืช ื”ื”ืชืงื ื”.

    VMware NSX ืœืงื˜ื ื˜ื ื™ื. ื—ืœืง 6: ื”ื’ื“ืจืช VPN

  18. ืœืื—ืจ ื”ื”ืชืงื ื”, ื”ืคืขืœ ืืช ื”ืœืงื•ื—, ื‘ื—ืœื•ืŸ ื”ื”ืจืฉืื”, ืœื—ืฅ ืขืœ ื”ืชื—ื‘ืจื•ืช.

    VMware NSX ืœืงื˜ื ื˜ื ื™ื. ื—ืœืง 6: ื”ื’ื“ืจืช VPN

  19. ื‘ื—ืœื•ืŸ ืื™ืžื•ืช ื”ืื™ืฉื•ืจ, ื‘ื—ืจ ื›ืŸ.

    VMware NSX ืœืงื˜ื ื˜ื ื™ื. ื—ืœืง 6: ื”ื’ื“ืจืช VPN

  20. ืื ื• ืžื›ื ื™ืกื™ื ืืช ื”ืื™ืฉื•ืจื™ื ืฉืœ ื”ืžืฉืชืžืฉ ืฉื ื•ืฆืจ ื‘ืขื‘ืจ ื•ืจื•ืื™ื ืฉื”ื—ื™ื‘ื•ืจ ื”ื•ืฉืœื ื‘ื”ืฆืœื—ื”.

    VMware NSX ืœืงื˜ื ื˜ื ื™ื. ื—ืœืง 6: ื”ื’ื“ืจืช VPN

    VMware NSX ืœืงื˜ื ื˜ื ื™ื. ื—ืœืง 6: ื”ื’ื“ืจืช VPN

  21. ืื ื• ื‘ื•ื“ืงื™ื ืืช ื”ืกื˜ื˜ื™ืกื˜ื™ืงื” ืฉืœ ืœืงื•ื— ื”-VPN ื‘ืžื—ืฉื‘ ื”ืžืงื•ืžื™.

    VMware NSX ืœืงื˜ื ื˜ื ื™ื. ื—ืœืง 6: ื”ื’ื“ืจืช VPN

    VMware NSX ืœืงื˜ื ื˜ื ื™ื. ื—ืœืง 6: ื”ื’ื“ืจืช VPN

  22. ื‘ืฉื•ืจืช ื”ืคืงื•ื“ื” ืฉืœ Windows (ipconfig / all), ืื ื• ืจื•ืื™ื ืฉื”ื•ืคื™ืข ืžืชืื ื•ื™ืจื˜ื•ืืœื™ ื ื•ืกืฃ ื•ื™ืฉ ืงื™ืฉื•ืจื™ื•ืช ืœืจืฉืช ื”ืžืจื•ื—ืงืช, ื”ื›ืœ ืขื•ื‘ื“:

    VMware NSX ืœืงื˜ื ื˜ื ื™ื. ื—ืœืง 6: ื”ื’ื“ืจืช VPN

    VMware NSX ืœืงื˜ื ื˜ื ื™ื. ื—ืœืง 6: ื”ื’ื“ืจืช VPN

  23. ื•ืœื‘ืกื•ืฃ, ื‘ื“ื•ืง ืžืžืกื•ืฃ Edge Gateway.

    VMware NSX ืœืงื˜ื ื˜ื ื™ื. ื—ืœืง 6: ื”ื’ื“ืจืช VPN

L2 VPN

L2VPN ื™ื”ื™ื” ืฆื•ืจืš ื›ืืฉืจ ืืชื” ืฆืจื™ืš ืœืฉืœื‘ ื›ืžื” ื’ื™ืื•ื’ืจืคื™ืช
ืจืฉืชื•ืช ืžื‘ื•ื–ืจื•ืช ืœืชื—ื•ื ืฉื™ื“ื•ืจ ืื—ื“.

ื–ื” ื™ื›ื•ืœ ืœื”ื™ื•ืช ืฉื™ืžื•ืฉื™, ืœืžืฉืœ, ื‘ืขืช ื”ืขื‘ืจืช ืžื›ื•ื ื” ื•ื™ืจื˜ื•ืืœื™ืช: ื›ืืฉืจ VM ืขื•ื‘ืจ ืœืื–ื•ืจ ื’ื™ืื•ื’ืจืคื™ ืื—ืจ, ื”ืžื›ื•ื ื” ืชืฉืžื•ืจ ืขืœ ื”ื’ื“ืจื•ืช ื›ืชื•ื‘ืช ื”-IP ืฉืœื” ื•ืœื ืชืื‘ื“ ืืช ื”ืงื™ืฉื•ืจื™ื•ืช ืขื ืžื›ื•ื ื•ืช ืื—ืจื•ืช ื”ื ืžืฆืื•ืช ื‘ืื•ืชื• ืชื—ื•ื L2 ืื™ืชื”.

ื‘ืกื‘ื™ื‘ืช ื”ื‘ื“ื™ืงื” ืฉืœื ื•, ื ื—ื‘ืจ ืฉื ื™ ืืชืจื™ื ื–ื” ืœื–ื”, ื ืงืจื ืœื”ื A ื•-B ื‘ื”ืชืืžื”. ื™ืฉ ืœื ื• ืฉื ื™ NSXs ื•ืฉืชื™ ืจืฉืชื•ืช ืžื ื•ืชื‘ื•ืช ืฉื ื•ืฆืจื• ื‘ืื•ืคืŸ ื–ื”ื” ื”ืžื—ื•ื‘ืจื•ืช ืœ-Edges ืฉื•ื ื™ื. ืœืžื›ื•ื ื” A ื™ืฉ ืืช ื”ื›ืชื•ื‘ืช 10.10.10.250/24, ืœืžื›ื•ื ื” B ื™ืฉ ืืช ื”ื›ืชื•ื‘ืช 10.10.10.2/24.

  1. ื‘-vCloud Director, ืขื‘ื•ืจ ืœืœืฉื•ื ื™ืช Administration, ืขื‘ื•ืจ ืืœ ื”-VDC ืฉืื ื• ืฆืจื™ื›ื™ื, ืขื‘ื•ืจ ืœืœืฉื•ื ื™ืช Org VDC Networks ื•ื”ื•ืกืฃ ืฉืชื™ ืจืฉืชื•ืช ื—ื“ืฉื•ืช.

    VMware NSX ืœืงื˜ื ื˜ื ื™ื. ื—ืœืง 6: ื”ื’ื“ืจืช VPN

  2. ื‘ื—ืจ ืืช ืกื•ื’ ื”ืจืฉืช ื”ืžื ื•ืชื‘ืช ื•ืื’ื“ ืืช ื”ืจืฉืช ื”ื–ื• ืœ-NSX ืฉืœื ื•. ืฉืžื ื• ืืช ืชื™ื‘ืช ื”ืกื™ืžื•ืŸ ืฆื•ืจ ื›ืžืžืฉืง ืžืฉื ื”.

    VMware NSX ืœืงื˜ื ื˜ื ื™ื. ื—ืœืง 6: ื”ื’ื“ืจืช VPN

  3. ื›ืชื•ืฆืื” ืžื›ืš, ืขืœื™ื ื• ืœืงื‘ืœ ืฉืชื™ ืจืฉืชื•ืช. ื‘ื“ื•ื’ืžื” ืฉืœื ื•, ื”ื ื ืงืจืื™ื ืจืฉืช-a ื•ืจืฉืช-b ืขื ืื•ืชืŸ ื”ื’ื“ืจื•ืช ืฉืขืจ ื•ืื•ืชื” ืžืกื™ื›ื”.

    VMware NSX ืœืงื˜ื ื˜ื ื™ื. ื—ืœืง 6: ื”ื’ื“ืจืช VPN

    VMware NSX ืœืงื˜ื ื˜ื ื™ื. ื—ืœืง 6: ื”ื’ื“ืจืช VPN

  4. ื›ืขืช ื ืขื‘ื•ืจ ืœื”ื’ื“ืจื•ืช ืฉืœ ื”-NSX ื”ืจืืฉื•ืŸ. ื–ื” ื™ื”ื™ื” ื”-NSX ืืœื™ื• ืžื—ื•ื‘ืจืช ืจืฉืช A. ื”ื™ื ืชืคืขืœ ื›ืฉืจืช.

    ื ื—ื–ื•ืจ ืœืžืžืฉืง NSx Edge / ืขื‘ื•ืจ ืœืœืฉื•ื ื™ืช VPN -> L2VPN. ืื ื• ืžืคืขื™ืœื™ื ืืช L2VPN, ื‘ื•ื—ืจื™ื ืืช ืžืฆื‘ ื”ืคืขื•ืœื” ืฉืœ ื”ืฉืจืช, ื‘ื”ื’ื“ืจื•ืช ื”-Global Server ืื ื• ืžืฆื™ื™ื ื™ื ืืช ื›ืชื•ื‘ืช ื”-IP ื”ื—ื™ืฆื•ื ื™ืช ืฉืœ NSX ื‘ื” ืชืงืฉื™ื‘ ื”ื™ืฆื™ืื” ืœืžื ื”ืจื”. ื›ื‘ืจื™ืจืช ืžื—ื“ืœ, ื”ืฉืงืข ื™ื™ืคืชื— ื‘ื™ืฆื™ืื” 443, ืืš ื ื™ืชืŸ ืœืฉื ื•ืช ื–ืืช. ืืœ ืชืฉื›ื— ืœื‘ื—ื•ืจ ืืช ื”ื’ื“ืจื•ืช ื”ื”ืฆืคื ื” ืขื‘ื•ืจ ื”ืžื ื”ืจื” ื”ืขืชื™ื“ื™ืช.

    VMware NSX ืœืงื˜ื ื˜ื ื™ื. ื—ืœืง 6: ื”ื’ื“ืจืช VPN

  5. ืขื‘ื•ืจ ืœื›ืจื˜ื™ืกื™ื™ื” ืืชืจื™ ืฉืจืช ื•ื”ื•ืกืฃ ืขืžื™ืช.

    VMware NSX ืœืงื˜ื ื˜ื ื™ื. ื—ืœืง 6: ื”ื’ื“ืจืช VPN

  6. ืื ื• ืžืคืขื™ืœื™ื ืืช ื”ืขืžื™ืช, ืžื’ื“ื™ืจื™ื ืืช ื”ืฉื, ื”ืชื™ืื•ืจ, ื‘ืžื™ื“ืช ื”ืฆื•ืจืš, ืžื’ื“ื™ืจื™ื ืืช ืฉื ื”ืžืฉืชืžืฉ ื•ื”ืกื™ืกืžื”. ื ื–ื“ืงืง ืœื ืชื•ื ื™ื ืืœื• ืžืื•ื—ืจ ื™ื•ืชืจ ื‘ืขืช ื”ื’ื“ืจืช ืืชืจ ื”ืœืงื•ื—.

    ื‘-Egress Optimization Gateway Address ืื ื• ืžื’ื“ื™ืจื™ื ืืช ื›ืชื•ื‘ืช ื”ืฉืขืจ. ื–ื” ื”ื›ืจื—ื™ ื›ื“ื™ ืฉืœื ืชื”ื™ื” ื”ืชื ื’ืฉื•ืช ื‘ื™ืŸ ื›ืชื•ื‘ื•ืช IP, ืžื›ื™ื•ื•ืŸ ืฉืœืฉืขืจ ื”ืจืฉืชื•ืช ืฉืœื ื• ื™ืฉ ืื•ืชื” ื›ืชื•ื‘ืช. ืœืื—ืจ ืžื›ืŸ ืœื—ืฅ ืขืœ ื›ืคืชื•ืจ ื‘ื—ืจ ืžืžืฉืงื™ ืžืฉื ื”.

    VMware NSX ืœืงื˜ื ื˜ื ื™ื. ื—ืœืง 6: ื”ื’ื“ืจืช VPN

  7. ื›ืืŸ ื ื‘ื—ืจ ืืช ืžืžืฉืง ื”ืžืฉื ื” ื”ืจืฆื•ื™. ืื ื—ื ื• ืฉื•ืžืจื™ื ืืช ื”ื”ื’ื“ืจื•ืช.

    VMware NSX ืœืงื˜ื ื˜ื ื™ื. ื—ืœืง 6: ื”ื’ื“ืจืช VPN

  8. ืื ื• ืจื•ืื™ื ื›ื™ ืืชืจ ื”ืœืงื•ื— ื”ื—ื“ืฉ ืฉื ื•ืฆืจ ื”ื•ืคื™ืข ื‘ื”ื’ื“ืจื•ืช.

    VMware NSX ืœืงื˜ื ื˜ื ื™ื. ื—ืœืง 6: ื”ื’ื“ืจืช VPN

  9. ื›ืขืช ื ืขื‘ื•ืจ ืœื”ื’ื“ืจืช NSX ืžืฆื“ ื”ืœืงื•ื—.

    ืื ื—ื ื• ืขื•ื‘ืจื™ื ืœืฆื“ NSX B, ืขื•ื‘ืจื™ื ืœ-VPN -> L2VPN, ืžืคืขื™ืœื™ื L2VPN, ืžื’ื“ื™ืจื™ื ืืช ืžืฆื‘ L2VPN ืœืžืฆื‘ ืœืงื•ื—. ื‘ืœืฉื•ื ื™ืช Client Global, ื”ื’ื“ืจ ืืช ื”ื›ืชื•ื‘ืช ื•ื”ื™ืฆื™ืื” ืฉืœ NSX A, ืฉืฆื™ื™ื ื• ืงื•ื“ื ืœื›ืŸ ื‘ืชื•ืจ Listening IP ื•-Port ื‘ืฆื“ ื”ืฉืจืช. ื›ืžื• ื›ืŸ, ื™ืฉ ืฆื•ืจืš ืœื”ื’ื“ื™ืจ ืืช ืื•ืชืŸ ื”ื’ื“ืจื•ืช ื”ืฆืคื ื” ื›ืš ืฉื”ืŸ ื™ื”ื™ื• ืขืงื‘ื™ื•ืช ื›ืืฉืจ ื”ืžื ื”ืจื” ืžื•ืจืžืช.

    VMware NSX ืœืงื˜ื ื˜ื ื™ื. ื—ืœืง 6: ื”ื’ื“ืจืช VPN

    ืื ื• ื’ื•ืœืœื™ื ืœืžื˜ื”, ื‘ื•ื—ืจื™ื ืืช ืžืžืฉืง ื”ืžืฉื ื” ืฉื“ืจื›ื• ืชื™ื‘ื ื” ื”ืžื ื”ืจื” ืขื‘ื•ืจ L2VPN.
    ื‘-Egress Optimization Gateway Address ืื ื• ืžื’ื“ื™ืจื™ื ืืช ื›ืชื•ื‘ืช ื”ืฉืขืจ. ื”ื’ื“ืจ ืžื–ื”ื” ืžืฉืชืžืฉ ื•ืกื™ืกืžื”. ืื ื• ื‘ื•ื—ืจื™ื ืืช ืžืžืฉืง ื”ืžืฉื ื” ื•ืืœ ื ืฉื›ื— ืœืฉืžื•ืจ ืืช ื”ื”ื’ื“ืจื•ืช.

    VMware NSX ืœืงื˜ื ื˜ื ื™ื. ื—ืœืง 6: ื”ื’ื“ืจืช VPN

  10. ื‘ืขืฆื, ื–ื” ื”ื›ืœ. ื”ื”ื’ื“ืจื•ืช ืฉืœ ืฆื“ ื”ืœืงื•ื— ื•ื”ืฉืจืช ื›ืžืขื˜ ื–ื”ื•ืช, ืœืžืขื˜ ื›ืžื” ื ื™ื•ืื ืกื™ื.
  11. ื›ืขืช ืื ื• ื™ื›ื•ืœื™ื ืœืจืื•ืช ืฉื”ืžื ื”ืจื” ืฉืœื ื• ืขื‘ื“ื” ืขืœ ื™ื“ื™ ืžืขื‘ืจ ืืœ ืกื˜ื˜ื™ืกื˜ื™ืงื” -> L2VPN ื‘ื›ืœ NSX.

    VMware NSX ืœืงื˜ื ื˜ื ื™ื. ื—ืœืง 6: ื”ื’ื“ืจืช VPN

  12. ืื ื ืœืš ื›ืขืช ืœืงื•ื ืกื•ืœื” ืฉืœ Edge Gateway ื›ืœืฉื”ื•, โ€‹โ€‹ื ืจืื” ืขืœ ื›ืœ ืื—ื“ ืžื”ื ื‘ื˜ื‘ืœืช arp ืืช ื”ื›ืชื•ื‘ื•ืช ืฉืœ ืฉื ื™ ื”-VMs.

    VMware NSX ืœืงื˜ื ื˜ื ื™ื. ื—ืœืง 6: ื”ื’ื“ืจืช VPN

ื–ื” ื”ื›ืœ ืœื’ื‘ื™ VPN ื‘- NSX Edge. ืชืฉืืœ ืื ืžืฉื”ื• ืœื ื‘ืจื•ืจ. ื–ื”ื• ื’ื ื”ื—ืœืง ื”ืื—ืจื•ืŸ ื‘ืกื“ืจืช ืžืืžืจื™ื ืขืœ ืขื‘ื•ื“ื” ืขื NSX Edge. ืื ื• ืžืงื•ื•ื™ื ืฉื”ื ืขื–ืจื• ๐Ÿ™‚

ืžืงื•ืจ: www.habr.com

ื”ื•ืกืคืช ืชื’ื•ื‘ื”