ืœื™ื‘ืช NetBSD ืžื•ืกื™ืคื” ืชืžื™ื›ื” ืขื‘ื•ืจ VPN WireGuard

ืžืคืชื—ื™ ืคืจื•ื™ืงื˜ื™ื ืฉืœ NetBSD ัะพะพะฑั‰ะธะปะธ ืขืœ ื”ื›ืœืœืช ืžื ื”ืœ ื”ื”ืชืงืŸ wg ืขื ื™ื™ืฉื•ื ืคืจื•ื˜ื•ืงื•ืœ WireGuard ื‘ืœื™ื‘ืช NetBSD ื”ืจืืฉื™ืช. NetBSD ื”ืคื›ื” ืœืžืขืจื›ืช ื”ื”ืคืขืœื” ื”ืฉืœื™ืฉื™ืช ืื—ืจื™ ืœื™ื ื•ืงืก ื•-OpenBSD ืขื ืชืžื™ื›ื” ืžืฉื•ืœื‘ืช ื‘-WireGuard. ืคืงื•ื“ื•ืช ืงืฉื•ืจื•ืช ืœื”ื’ื“ืจืช VPN ืžื•ืฆืขื•ืช ื’ื - wg-keygen ื•-wgconfig. ื‘ืชืฆื•ืจืช ืœื™ื‘ืช ื‘ืจื™ืจืช ื”ืžื—ื“ืœ (GENERIC), ืžื ื”ืœ ื”ื”ืชืงืŸ ืขื“ื™ื™ืŸ ืœื ืžื•ืคืขืœ ื•ื“ื•ืจืฉ ื—ื™ื•ื•ื™ ืžืคื•ืจืฉ ืฉืœ "pseudo-device wg" ื‘ื”ื’ื“ืจื•ืช.

ื‘ื ื•ืกืฃ, ื ื™ืชืŸ ืœืฆื™ื™ืŸ ืคืจืกื•ื ืขื“ื›ื•ืŸ ืžืชืงืŸ ืœื—ื‘ื™ืœืช wireguard-tools 1.0.20200820, ื”ื›ื•ืœืœืช ื›ืœื™ ืขื–ืจ ืœืžืจื—ื‘ ืžืฉืชืžืฉ ื›ื’ื•ืŸ wg ื•-wg-quick. ื”ืžื”ื“ื•ืจื” ื”ื—ื“ืฉื” ืžื›ื™ื ื” ืืช IPC ืœืชืžื™ื›ืช WireGuard ื”ืงืจื•ื‘ื” ื‘ืžืขืจื›ืช ื”ื”ืคืขืœื” FreeBSD. ื”ืงื•ื“ ื”ืกืคืฆื™ืคื™ ืœืคืœื˜ืคื•ืจืžื•ืช ืฉื•ื ื•ืช ื—ื•ืœืง ืœืงื‘ืฆื™ื ืฉื•ื ื™ื. ืชืžื™ื›ื” ื‘ืคืงื•ื“ื” "ื˜ืขื™ื ื” ืžื—ื“ืฉ" ื ื•ืกืคื” ืœืงื•ื‘ืฅ ื™ื—ื™ื“ืช systemd, ื”ืžืืคืฉืจ ืœืš ืœื”ืจื™ืฅ ืžื‘ื ื™ื ื›ืžื• "systemctl reload wg-quick at wgnet0".

ื ื–ื›ื™ืจ ืœื›ื ืฉ-VPN WireGuard ืžื™ื•ืฉื ืขืœ ื‘ืกื™ืก ืฉื™ื˜ื•ืช ื”ืฆืคื ื” ืžื•ื“ืจื ื™ื•ืช, ืžืกืคืง ื‘ื™ืฆื•ืขื™ื ื’ื‘ื•ื”ื™ื ืžืื•ื“, ืงืœ ืœืฉื™ืžื•ืฉ, ืœืœื ืกื™ื‘ื•ื›ื™ื ื•ื”ื•ื›ื™ื— ืืช ืขืฆืžื• ื‘ืžืกืคืจ ืคืจื™ืกื•ืช ื’ื“ื•ืœื•ืช ื”ืžืขื‘ื“ื•ืช ื ืคื—ื™ ืชืขื‘ื•ืจื” ื’ื“ื•ืœื™ื. ื”ืคืจื•ื™ืงื˜ ืžืชืคืชื— ืžืฉื ืช 2015, ืขื‘ืจ ื‘ื™ืงื•ืจืช ื• ืื™ืžื•ืช ืคื•ืจืžืœื™ ืฉื™ื˜ื•ืช ื”ืฆืคื ื” ื‘ืฉื™ืžื•ืฉ. ืชืžื™ื›ืช WireGuard ื›ื‘ืจ ืžืฉื•ืœื‘ืช ื‘-NetworkManager ื•ื‘-systemd, ื•ืชื™ืงื•ื ื™ ืœื™ื‘ื” ื›ืœื•ืœื™ื ื‘ื”ืคืฆื•ืช ื”ื‘ืกื™ืกื™ื•ืช ื“ื‘ื™ืืŸ ืœื ื™ืฆื™ื‘, Mageia, Alpine, Arch, Gentoo, OpenWrt, NixOS, ืกื•ื‘ื’ืจืฃ ะธ ALT.

WireGuard ืžืฉืชืžืฉ ื‘ืงื•ื ืกืคื˜ ืฉืœ ื ื™ืชื•ื‘ ืžืคืชื—ื•ืช ื”ืฆืคื ื”, ื”ื›ื•ืœืœ ื”ืฆืžื“ืช ืžืคืชื— ืคืจื˜ื™ ืœื›ืœ ืžืžืฉืง ืจืฉืช ื•ืฉื™ืžื•ืฉ ื‘ื• ื›ื“ื™ ืœืื’ื“ ืืช ื”ืžืคืชื—ื•ืช ื”ืฆื™ื‘ื•ืจื™ื™ื. ืžืคืชื—ื•ืช ืฆื™ื‘ื•ืจื™ื™ื ืžื•ื—ืœืคื™ื ื›ื“ื™ ืœื™ืฆื•ืจ ื—ื™ื‘ื•ืจ ื‘ืฆื•ืจื” ื“ื•ืžื” ืœ-SSH. ื›ื“ื™ ืœื ื”ืœ ืžืฉื ื•ืžืชืŸ ืขืœ ืžืคืชื—ื•ืช ื•ืœื”ืชื—ื‘ืจ ืžื‘ืœื™ ืœื”ืคืขื™ืœ ื“ืžื•ืŸ ื ืคืจื“ ื‘ืžืจื—ื‘ ื”ืžืฉืชืžืฉ, ืžื ื’ื ื•ืŸ Noise_IK ืž ืžืกื’ืจืช ืคืจื•ื˜ื•ืงื•ืœ ืจืขืฉื‘ื“ื•ืžื” ืœืชื—ื–ื•ืงืช ื”ืžืคืชื—ื•ืช ื”ืžืื•ืฉืจื™ื ื‘-SSH. ื”ืขื‘ืจืช ื”ื ืชื•ื ื™ื ืžืชื‘ืฆืขืช ื‘ืืžืฆืขื•ืช ืื ืงืคืกื•ืœืฆื™ื” ื‘ืžื ื•ืช UDP. ื–ื” ืชื•ืžืš ื‘ืฉื™ื ื•ื™ ื›ืชื•ื‘ืช ื”-IP ืฉืœ ืฉืจืช ื”-VPN (ื ื“ื™ื“ื”) ืžื‘ืœื™ ืœื ืชืง ืืช ื”ื—ื™ื‘ื•ืจ ืขื ืงื•ื ืคื™ื’ื•ืจืฆื™ื” ืื•ื˜ื•ืžื˜ื™ืช ืฉืœ ื”ืœืงื•ื—.

ืœื”ืฆืคื ื” ืžืฉืžืฉ ืฆื•ืคืŸ ื–ืจื ChaCha20 ื•ืืœื’ื•ืจื™ืชื ืื™ืžื•ืช ื”ื•ื“ืขื•ืช (MAC) Poly1305, ื‘ืขื™ืฆื•ื‘ื• ืฉืœ ื“ื ื™ืืœ ื‘ืจื ืฉื˜ื™ื™ืŸ (ื“ื ื™ืืœ ื‘ืจื ืฉื˜ื™ื™ืŸ), ื˜ื ื™ื” ืœื ื’ื”
(ื˜ื ื—ื” ืœืื ื’) ื•ืคื™ื˜ืจ ืฉื•ื•ืื‘ื”. ChaCha20 ื•- Poly1305 ืžืžื•ืงืžื™ื ื›ืื ืœื•ื’ื™ื ืžื”ื™ืจื™ื ื•ื‘ื˜ื•ื—ื™ื ื™ื•ืชืจ ืฉืœ AES-256-CTR ื•-HMAC, ืฉื”ื˜ืžืขืช ื”ืชื•ื›ื ื” ืฉืœื”ื ืžืืคืฉืจืช ื”ืฉื’ืช ื–ืžืŸ ื‘ื™ืฆื•ืข ืงื‘ื•ืข ืœืœื ืฉื™ืžื•ืฉ ื‘ืชืžื™ื›ืช ื—ื•ืžืจื” ืžื™ื•ื—ื“ืช. ื›ื“ื™ ืœื™ืฆื•ืจ ืžืคืชื— ืกื•ื“ื™ ืžืฉื•ืชืฃ, ื ืขืฉื” ืฉื™ืžื•ืฉ ื‘ืคืจื•ื˜ื•ืงื•ืœ ื”ืขืงื•ืžื” ื”ืืœื™ืคื˜ื™ืช Diffie-Hellman ื‘ื™ื™ืฉื•ื CurveXNXX, ื’ื ื”ื•ืฆืข ืขืœ ื™ื“ื™ ื“ื ื™ืืœ ื‘ืจื ืฉื˜ื™ื™ืŸ. ื”ืืœื’ื•ืจื™ืชื ื”ืžืฉืžืฉ ืœื’ื™ื‘ื•ื‘ ื”ื•ื BLAKE2s (RFC7693).

ืžืงื•ืจ: OpenNet.ru

ื”ื•ืกืคืช ืชื’ื•ื‘ื”