IPv6 ã®ç¥ã«äœãèšãããã®ã§ãããã?
ãããä»æ¥ã¯æå·ã®ç¥æ§ã«ãåãããšãèšã£ãŠã¿ããã
ããã§ã¯ãæå·åãããŠããªã IPv4 ãã³ãã«ã«ã€ããŠèª¬æããŸãããããŠã©ãŒã ã©ã³ãããã³ãã«ã§ã¯ãªããææ°ã®ãLEDããã³ãã«ã«ã€ããŠèª¬æããŸãã ãŸããããã§ã¯çã®ãœã±ããããã©ãã·ã¥ãããŠããããŠãŒã¶ãŒç©ºéã§ãã±ããã®äœæ¥ãé²è¡äžã§ãã
ãããã奜ã¿ãšè²ã«å¯Ÿã㊠N åã®ãã³ããªã³ã° ãããã³ã«ããããŸãã
- ã¹ã¿ã€ãªãã·ã¥ããã¡ãã·ã§ããã«ãè¥è
ã¯ã€ã€ã¬ãŒã - ã¹ã€ã¹ãã€ããOpenVPNãSSH ãªã©ã®å€æ©èœ
- å€ããŠæªããªãGRE
- æãã·ã³ãã«ãé«éãå®å šã«æå·åãããŠããªã IPIP
- ç©æ¥µçã«éçºäž
GENEVE - ä»ã®å€ãã
ãã ããç§ã¯ããã°ã©ããŒãªã®ã§ãN ãã»ãã®äžéšã ãå¢ãããå®éã®ãããã³ã«ã®éçºã¯ã³ã¡ã«ãµã³ãã®éçºè ã«ä»»ããŸãã
äžäººã®èå
ã®äžã§
ããŸããŸãªãã³ããªã³ã° ãããã³ã«ãç 究ããŠãããšãã«ãç§ã®å ãªãå®ç§äž»çŸ©è ã®æ³šæã¯ããªãŒããŒããããæå°éã«æããããŠãã IPIP ã«äœåºŠãåŒãå¯ããããŸããã ããããç§ã®ã¿ã¹ã¯ã«ã¯ XNUMX ã€ã®é倧ãªæ¬ ç¹ããããŸãã
- äž¡åŽã«ãããªã㯠IP ãå¿ èŠã§ãã
- ãããŠããªãã«å¯ŸããèªèšŒã¯ãããŸããã
ãããã£ãŠãå®ç§äž»çŸ©è ã¯é è骚ã®æãé ããŸãã¯ããã«åº§ã£ãŠããå Žæã®ã©ãã«ã§ãè¿œãããããŸããã
ãããŠããæ¥ã次ã®ãããªèšäºãèªãã§ãããšã
ããããç¹å¹è¬ã ïŒ ç§ã«ãšã£ãŠã¯åçŽãª IPIP ã§ååã§ããã -ç§ã¯æããŸããã
å®éã匟䞞ã¯å®å šã«éã§ã¯ãªãããšãå€æããã UDP ã§ã®ã«ãã»ã«åã«ãããæåã®åé¡ã解決ãããŸããäºåã«ç¢ºç«ãããæ¥ç¶ã䜿çšããŠãå€éšãã NAT ã®èåŸã«ããã¯ã©ã€ã¢ã³ãã«æ¥ç¶ã§ããŸãããããã§ãIPIP ã®æ¬¡ã®æ¬ ç¹ã®ååãæ°ããªå ãåœãŠãŸãããã©ã€ããŒã ãããã¯ãŒã¯ã®èª°ã§ããç®ã«èŠãããããã¯ãŒã¯ã®èåŸã«é ããããšãã§ããŸãããããªã㯠IP ãšã¯ã©ã€ã¢ã³ã ããŒã (çŽç²ãª IPIP ã§ã¯ãã®åé¡ã¯ååšããŸãã)ã
ãã® XNUMX ã€åã®åé¡ã解決ããããã«ããŠãŒãã£ãªãã£ãèªçããŸãã
ããªãã®ã¹ã¯ãªããã¯å¿ èŠãããŸãã!
ããããŸãããã¯ã©ã€ã¢ã³ãã®ãããªã㯠ããŒããš IP ãããã£ãŠããå Žå (ããšãã°ããã®èåŸã«ããå šå¡ã¯ã©ãã«ãè¡ãããNAT ã¯ããŒãã 1-in-1 ã«ãããããããšããŸã)ã次ã®ã³ãã³ãã䜿çšã㊠IPIP-over-FOU ãã³ãã«ãäœæã§ããŸããã¹ã¯ãªãããªãã§æ¬¡ã®ã³ãã³ããå®è¡ããŸãã
ãµãŒããŒäž:
# ÐПЎгÑÑзОÑÑ ÐŒÐŸÐŽÑÐ»Ñ ÑÐŽÑа FOU
modprobe fou
# СПзЎаÑÑ IPIP ÑÑÐœÐœÐµÐ»Ñ Ñ ÐžÐœÐºÐ°Ð¿ÑÑлÑÑОей в FOU.
# ÐПЎÑÐ»Ñ ipip пПЎгÑÑзОÑÑÑ Ð°Ð²ÑПЌаÑОÑеÑкО.
ip link add name ipipou0 type ipip
remote 198.51.100.2 local 203.0.113.1
encap fou encap-sport 10000 encap-dport 20001
mode ipip dev eth0
# ÐПбавОÑÑ Ð¿ÐŸÑÑ ÐœÐ° кПÑПÑПЌ бÑÐŽÐµÑ ÑлÑÑаÑÑ FOU ÐŽÐ»Ñ ÑÑПгП ÑÑММелÑ
ip fou add port 10000 ipproto 4 local 203.0.113.1 dev eth0
# ÐазМаÑОÑÑ IP аЎÑÐµÑ ÑÑММелÑ
ip address add 172.28.0.0 peer 172.28.0.1 dev ipipou0
# ÐПЎМÑÑÑ ÑÑММелÑ
ip link set ipipou0 up
ã¯ã©ã€ã¢ã³ãäž:
modprobe fou
ip link add name ipipou1 type ipip
remote 203.0.113.1 local 192.168.0.2
encap fou encap-sport 10001 encap-dport 10000 encap-csum
mode ipip dev eth0
# ÐпÑОО local, peer, peer_port, dev ЌПгÑÑ ÐœÐµ пПЎЎеÑжОваÑÑÑÑ ÑÑаÑÑЌО ÑÐŽÑаЌО, ЌПжМП ОÑ
ПпÑÑÑОÑÑ.
# peer О peer_port ОÑпПлÑзÑÑÑÑÑ ÐŽÐ»Ñ ÑÐŸÐ·ÐŽÐ°ÐœÐžÑ ÑÐŸÐµÐŽÐžÐœÐµÐœÐžÑ ÑÑÐ°Ð·Ñ Ð¿ÑО ÑПзЎаМОО FOU-listener-а.
ip fou add port 10001 ipproto 4 local 192.168.0.2 peer 203.0.113.1 peer_port 10000 dev eth0
ip address add 172.28.0.1 peer 172.28.0.0 dev ipipou1
ip link set ipipou1 up
ã©ã
ipipou*
â ããŒã«ã« ãã³ãã« ãããã¯ãŒã¯ ã€ã³ã¿ãŒãã§ã€ã¹ã®åå203.0.113.1
â ãããªãã¯IPãµãŒããŒ198.51.100.2
â ã¯ã©ã€ã¢ã³ãã®ãããªãã¯IP192.168.0.2
â ã€ã³ã¿ãŒãã§ã€ã¹ eth0 ã«å²ãåœãŠãããã¯ã©ã€ã¢ã³ã IP10001
â FOU ã®ããŒã«ã« ã¯ã©ã€ã¢ã³ã ããŒã20001
â FOU ã®ãããªã㯠ã¯ã©ã€ã¢ã³ã ããŒã10000
â FOU ã®ãããªãã¯ãµãŒããŒããŒãencap-csum
â ã«ãã»ã«åããã UDP ãã±ããã« UDP ãã§ãã¯ãµã ãè¿œå ãããªãã·ã§ã³ã ã§çœ®ãæããããšãã§ããŸãnoencap-csum
èšããŸã§ããªããæŽåæ§ã¯ïŒãã±ããããã³ãã«å ã«ããéïŒå€åŽã®ã«ãã»ã«åå±€ã«ãã£ãŠãã§ã«å¶åŸ¡ãããŠããŸããeth0
â ipip ãã³ãã«ããã€ã³ããããããŒã«ã« ã€ã³ã¿ãŒãã§ã€ã¹172.28.0.1
â ã¯ã©ã€ã¢ã³ã ãã³ãã« ã€ã³ã¿ãŒãã§ã€ã¹ã® IP (ãã©ã€ããŒã)172.28.0.0
â IP ãã³ãã« ãµãŒã㌠ã€ã³ã¿ãŒãã§ã€ã¹ (ãã©ã€ããŒã)
UDP æ¥ç¶ãçããŠããéãããã³ãã«ã¯æ£åžžã«æ©èœããŸãããåæãããå Žåã¯å¹žéã§ããã¯ã©ã€ã¢ã³ãã® IP: ããŒããåãã§ããã°åç¶ããŸãããå€æŽãããå Žåã¯åæãããŸãã
ãã¹ãŠãå
ã«æ»ãæãç°¡åãªæ¹æ³ã¯ãã«ãŒãã« ã¢ãžã¥ãŒã«ãã¢ã³ããŒãããããšã§ãã modprobe -r fou ipip
èªèšŒãå¿
èŠãªãå Žåã§ããã¯ã©ã€ã¢ã³ãã®ãããªã㯠IP ãšããŒãã¯åžžã«ç¥ãããŠããããã§ã¯ãªããå€ãã®å Žåã(NAT ã®çš®é¡ã«å¿ããŠ) äºæž¬äžå¯èœãŸãã¯å€åããŸãã çç¥ããå Žå encap-dport
ãµãŒããŒåŽã§ã¯ããã³ãã«ã¯æ©èœããããªã¢ãŒãæ¥ç¶ããŒããååŸããã»ã©è³¢ããããŸããã ãã®å Žåãipipu ã圹ç«ã¡ãŸãããŸãã¯ãWireGuard ããã®ä»ã®åæ§ã®ããŒã«ã圹ç«ã¡ãŸãã
ããã¯ã©ã®ããã«åäœããŸããïŒ
ã¯ã©ã€ã¢ã³ã (é垞㯠NAT ã®èåŸã«ãããŸã) ã¯ã(äžã®äŸã®ããã«) ãã³ãã«ãéãããµãŒããŒåŽã§ãã³ãã«ãæ§æããããã«èªèšŒãã±ããããµãŒããŒã«éä¿¡ããŸãã èšå®ã«å¿ããŠãããã¯ç©ºã®ãã±ãã (ãµãŒããŒããããªã㯠IP: æ¥ç¶ããŒããèªèã§ããããã«ãããã) ã§ããããšãããµãŒããŒãã¯ã©ã€ã¢ã³ããèå¥ã§ããããŒã¿ãå«ãããšãã§ããŸãã ããŒã¿ã¯ãã¯ãªã¢ ããã¹ãã®åçŽãªãã¹ãã¬ãŒãº (HTTP åºæ¬èªèšŒãšã®é¡äŒŒãæãæµ®ãã³ãŸã) ãŸãã¯ç§å¯ããŒã§çœ²åãããç¹å¥ã«èšèšãããããŒã¿ (HTTP ãã€ãžã§ã¹ãèªèšŒã«äŒŒãŠããŸããããã匷åã§ããã ãã§ããé¢æ°ãåç
§) ã«ããããšãã§ããŸãã client_auth
ã³ãŒãå
)ã
ãµãŒã㌠(ãããªã㯠IP ãæã€åŽ) ã§ã¯ãipipou ãéå§ããããšãnfqueue ãã¥ãŒ ãã³ãã©ãŒãäœæãããå¿ èŠãªãã±ãããéä¿¡ãããã¹ãå Žæã«éä¿¡ãããããã« netfilter ãèšå®ãããŸããnfqueue ãã¥ãŒãžã®æ¥ç¶ãåæåãããã±ãããããã³ [ã»ãŒ] æ®ãã¯ãã¹ãŠãªã¹ããŒã® FOU ã«çŽæ¥éä¿¡ãããŸãã
詳ãããªã人ã®ããã«èª¬æãããšãnfqueue (ãŸã㯠NetfilterQueue) ã¯ãã«ãŒãã« ã¢ãžã¥ãŒã«ã®éçºæ¹æ³ãç¥ããªãã¢ããã¥ã¢ã«ãšã£ãŠç¹å¥ãªãã®ã§ãããnetfilter (nftables/iptables) ã䜿çšãããšããããã¯ãŒã¯ ãã±ããããŠãŒã¶ãŒç©ºéã«ãªãã€ã¬ã¯ãããããã§æ¬¡ã®ã³ãã³ãã䜿çšããŠåŠçã§ããŸããããªããã£ããšã¯ãæå ã«ãããã®ãæå³ããŸã: å€æŽ (ãªãã·ã§ã³) ããŠã«ãŒãã«ã«æ»ãããç Žæ£ããŸãã
äžéšã®ããã°ã©ãã³ã°èšèªã§ã¯ãnfqueue ãæäœããããã®ãã€ã³ãã£ã³ã°ããããŸãããbash ã§ã¯ãã€ã³ãã£ã³ã°ããããŸããã§ãã (ãžãŒãé©ãã¹ãããšã§ã¯ãããŸãã)ãPython ã䜿çšããå¿
èŠããããŸããã
ããã©ãŒãã³ã¹ãéèŠã§ãªãå Žåã¯ãããã䜿çšãããšãããªãäœãã¬ãã«ã§ãã±ãããåŠçããããã®ç¬èªã®ããžãã¯ãæ¯èŒçè¿ éãã€ç°¡åã«äœæã§ããŸããããšãã°ãå®éšçãªããŒã¿è»¢éãããã³ã«ãäœæããããéæšæºã®åäœã§ããŒã«ã«ããã³ãªã¢ãŒãã®ãµãŒãã¹ãèããããããããšãã§ããŸãã
Raw ãœã±ãã㯠nfqueue ãšé£æºããŠåäœããŸããããšãã°ããã³ãã«ããã§ã«æ§æãããŠãããFOU ãç®çã®ããŒãã§ãªãã¹ã³ããŠããå Žåãéåžžã®æ¹æ³ã§ã¯åãããŒããããã±ãããéä¿¡ã§ããŸãããããžãŒç¶æ ã§ããã raw ãœã±ããã䜿çšããŠãã©ã³ãã ã«çæããããã±ãããåãåã£ãŠãããã¯ãŒã¯ ã€ã³ã¿ãŒãã§ã€ã¹ã«çŽæ¥éä¿¡ããããšãã§ããŸããããã®ãããªãã±ãããçæããã«ã¯ããå°ã工倫ãå¿ èŠã«ãªããŸãã ããã¯ãiipou ã§èªèšŒä»ãã®ãã±ãããäœæãããæ¹æ³ã§ãã
iipipou ã¯æ¥ç¶ããã®æåã®ãã±ãã (ããã³æ¥ç¶ã確ç«ãããåã«ãã¥ãŒã«æŒãããã±ãã) ã®ã¿ãåŠçãããããããã©ãŒãã³ã¹ã¯ã»ãšãã©äœäžããŸããã
ipipou ãµãŒããŒãèªèšŒããããã±ãããåä¿¡ãããšããã«ãã³ãã«ãäœæãããæ¥ç¶å ã®ãã¹ãŠã®åŸç¶ã®ãã±ãã㯠nfqueue ããã€ãã¹ããŠã«ãŒãã«ã«ãã£ãŠãã§ã«åŠçãããŠããŸãã æ¥ç¶ã倱æããå Žåãèšå®ã«å¿ããŠã次ã®ãã±ããã®æåã®ãã±ããã nfqueue ãã¥ãŒã«éä¿¡ãããŸããèªèšŒä»ãã®ãã±ããã§ã¯ãªããæåŸã«èšæ¶ããã IP ããã³ã¯ã©ã€ã¢ã³ã ããŒãããã®ãã®ã§ããã°ãéä¿¡ããããšãã§ããŸãããªã³ãŸãã¯ç Žæ£ãããŸãã èªèšŒããããã±ãããæ°ãã IP ããã³ããŒãããéä¿¡ãããå Žåããã³ãã«ã¯ãããã䜿çšããããã«åæ§æãããŸãã
éåžžã® IPIP-over-FOU ã«ã¯ãNAT ã䜿çšããå Žåã«ãã XNUMX ã€åé¡ããããŸããFOU ãš IPIP ã¢ãžã¥ãŒã«ã¯äºãã«å®å
šã«åé¢ãããŠãããããåã IP ãæ〠UDP ã«ã«ãã»ã«åããã XNUMX ã€ã® IPIP ãã³ãã«ãäœæããããšã¯äžå¯èœã§ãã ãããã®ã åããããªã㯠IP ã®èåŸã«ãã XNUMX çµã®ã¯ã©ã€ã¢ã³ãã¯ããã®æ¹æ³ã§åæã«åããµãŒããŒã«æ¥ç¶ã§ããŸããã å°æ¥ã¯ã
ãªããªãæ¥ç¶å ã®ãã¹ãŠã®ãã±ããã眲åãããŠããããã§ã¯ãªãããããã®åçŽãªä¿è·ã¯ MITM ã«å¯ŸããŠè匱ã§ãããããã¯ã©ã€ã¢ã³ããšãµãŒããŒã®éã®ãã¹ã«ãã©ãã£ãã¯ããªãã¹ã³ããŠæäœã§ããæªè ãæœãã§ããå Žåã圌ã¯èªèšŒããããã±ãããå¥ã®ã¢ãã¬ã¹ã䜿çšããŠãä¿¡é Œã§ããªããã¹ããããã³ãã«ãäœæããŸãã
ãã©ãã£ãã¯ã®å€§éšåãã³ã¢ã«æ®ãããŸãŸãââã®åé¡ã解決ããæ¹æ³ã«ã€ããŠã¢ã€ãã¢ããæã¡ã®æ¹ãããã£ããããŸããããé æ ®ãªã声ãäžããŠãã ããã
ãšããã§ãUDP ã§ã®ã«ãã»ã«åã¯éåžžã«ããŸã蚌æãããŠããŸãã IP äžã®ã«ãã»ã«åãšæ¯èŒãããšãUDP ããããŒã®è¿œå ãªãŒããŒãããã«ãããããããã¯ããã«å®å®ããŠãããå€ãã®å Žåé«éã§ãã ããã¯ãã€ã³ã¿ãŒãããäžã®ã»ãšãã©ã®ãã¹ãããTCPãUDPãICMP ãšãã XNUMX ã€ã®æãäžè¬çãªãããã³ã«ã§ã®ã¿æ£åžžã«åäœãããšããäºå®ã«ãããã®ã§ãã æ圢éšåã¯ãããã XNUMX ã€ã«å¯ŸããŠã®ã¿æé©åãããŠãããããä»ã®ãã¹ãŠãå®å šã«ç Žæ£ããããåŠçãé ããªããŸãã
ããšãã°ãHTTP/3 ã®ããŒã¹ãšãªã QUICK ã IP ã®äžã§ã¯ãªã UDP ã®äžã«äœæãããã®ã¯ãã®ããã§ãã
ããŠãèšèã¯ååã«ãããŸãããä»åºŠã¯ããããçŸå®ã®äžçãã§ã©ã®ããã«æ©èœããããèŠãŠã¿ãŸãããã
æŠã
çŸå®äžçããšãã¥ã¬ãŒãããããã«äœ¿çšãããŸã iperf3
ã çŸå®ãžã®è¿ããšããç¹ã§ã¯ãMinecraft ã§çŸå®äžçããšãã¥ã¬ãŒãããã®ãšã»ãŒåãã§ãããä»ã®ãšããã¯ããã§ååã§ãã
ã³ã³ãã¹ãã®åå è :
- ãªãã¡ã¬ã³ã¹ã¡ã€ã³ãã£ã³ãã«
- ãã®èšäºã®äž»äººå ¬ã¯ã€ãããŠã§ã
- OpenVPN èªèšŒãããæå·åãªã
- å æ¬çã¢ãŒãã® OpenVPN
- PresharedKey ãªãã® WireGuardãMTU=1440 (IPv4 ã®ã¿ã®ãã)
ããã¢åãã®æè¡ããŒã¿
ã¡ããªã¯ã¹ã¯æ¬¡ã®ã³ãã³ãã§ååŸãããŸãã
ã¯ã©ã€ã¢ã³ãäž:
UDP
CPULOG=NAME.udp.cpu.log; sar 10 6 >"$CPULOG" & iperf3 -c SERVER_IP -4 -t 60 -f m -i 10 -B LOCAL_IP -P 2 -u -b 12M; tail -1 "$CPULOG"
# ÐЎе "-b 12M" ÑÑП пÑПпÑÑÐºÐœÐ°Ñ ÑпПÑПбМПÑÑÑ ÐŸÑМПвМПгП каМала, ЎелÑÐœÐœÐ°Ñ ÐœÐ° ÑОÑлП пПÑПкПв "-P", ÑÑÐŸÐ±Ñ Ð»ÐžÑМОе пакеÑÑ ÐœÐµ плПЎОÑÑ Ðž Ме пПÑÑОÑÑ Ð¿ÑПОзвПЎОÑелÑМПÑÑÑ.
TCP
CPULOG=NAME.tcp.cpu.log; sar 10 6 >"$CPULOG" & iperf3 -c SERVER_IP -4 -t 60 -f m -i 10 -B LOCAL_IP -P 2; tail -1 "$CPULOG"
ICMP é 延
ping -c 10 SERVER_IP | tail -1
ãµãŒããŒäž (ã¯ã©ã€ã¢ã³ããšåæã«å®è¡):
UDP
CPULOG=NAME.udp.cpu.log; sar 10 6 >"$CPULOG" & iperf3 -s -i 10 -f m -1; tail -1 "$CPULOG"
TCP
CPULOG=NAME.tcp.cpu.log; sar 10 6 >"$CPULOG" & iperf3 -s -i 10 -f m -1; tail -1 "$CPULOG"
ãã³ãã«æ§æ
ã€ãããŠ
ãµãŒã
/etc/ipipou/server.conf
:
server
number 0
fou-dev eth0
fou-local-port 10000
tunl-ip 172.28.0.0
auth-remote-pubkey-b64 eQYNhD/Xwl6Zaq+z3QXDzNI77x8CEKqY1n5kt9bKeEI=
auth-secret topsecret
auth-lifetime 3600
reply-on-auth-ok
verb 3
systemctl start ipipou@server
顧客
/etc/ipipou/client.conf
:
client
number 0
fou-local @eth0
fou-remote SERVER_IP:10000
tunl-ip 172.28.0.1
# pubkey of auth-key-b64: eQYNhD/Xwl6Zaq+z3QXDzNI77x8CEKqY1n5kt9bKeEI=
auth-key-b64 RuBZkT23na2Q4QH1xfmZCfRgSgPt5s362UPAFbecTso=
auth-secret topsecret
keepalive 27
verb 3
systemctl start ipipou@client
openvpn (æå·åãªããèªèšŒãã)
ãµãŒã
openvpn --genkey --secret ovpn.key # ÐаÑеЌ МаЎП пеÑеЎаÑÑ ovpn.key клОеМÑÑ
openvpn --dev tun1 --local SERVER_IP --port 2000 --ifconfig 172.16.17.1 172.16.17.2 --cipher none --auth SHA1 --ncp-disable --secret ovpn.key
顧客
openvpn --dev tun1 --local LOCAL_IP --remote SERVER_IP --port 2000 --ifconfig 172.16.17.2 172.16.17.1 --cipher none --auth SHA1 --ncp-disable --secret ovpn.key
openvpn (æå·åãèªèšŒãUDP çµç±ããã¹ãŠæåŸ
ã©ãã)
ã䜿çšããŠæ§æãããŸã
ã¯ã€ã€ãŒã¬ãŒã
ãµãŒã
/etc/wireguard/server.conf
:
[Interface]
Address=172.31.192.1/18
ListenPort=51820
PrivateKey=aMAG31yjt85zsVC5hn5jMskuFdF8C/LFSRYnhRGSKUQ=
MTU=1440
[Peer]
PublicKey=LyhhEIjVQPVmr/sJNdSRqTjxibsfDZ15sDuhvAQ3hVM=
AllowedIPs=172.31.192.2/32
systemctl start wg-quick@server
顧客
/etc/wireguard/client.conf
:
[Interface]
Address=172.31.192.2/18
PrivateKey=uCluH7q2Hip5lLRSsVHc38nGKUGpZIUwGO/7k+6Ye3I=
MTU=1440
[Peer]
PublicKey=DjJRmGvhl6DWuSf1fldxNRBvqa701c0Sc7OpRr4gPXk=
AllowedIPs=172.31.192.1/32
Endpoint=SERVER_IP:51820
systemctl start wg-quick@client
çµæ
湿ã£ãéãçæ¿
ãµãŒããŒã® CPU è² è·ã¯ããŸãåèã«ãªããŸããããªããªã... ããã§ã¯ä»ã«ãå€ãã®ãµãŒãã¹ãå®è¡ãããŠãããå Žåã«ãã£ãŠã¯ãªãœãŒã¹ãæ¶è²»ããŸãã
proto bandwidth[Mbps] CPU_idle_client[%] CPU_idle_server[%]
# 20 Mbps каМал Ñ ÐŒÐžÐºÑПкПЌпÑÑÑеÑа (4 core) ЎП VPS (1 core) ÑеÑез ÐÑлаМÑОкÑ
# pure
UDP 20.4 99.80 93.34
TCP 19.2 99.67 96.68
ICMP latency min/avg/max/mdev = 198.838/198.997/199.360/0.372 ms
# ipipou
UDP 19.8 98.45 99.47
TCP 18.8 99.56 96.75
ICMP latency min/avg/max/mdev = 199.562/208.919/220.222/7.905 ms
# openvpn0 (auth only, no encryption)
UDP 19.3 99.89 72.90
TCP 16.1 95.95 88.46
ICMP latency min/avg/max/mdev = 191.631/193.538/198.724/2.520 ms
# openvpn (full encryption, auth, etc)
UDP 19.6 99.75 72.35
TCP 17.0 94.47 87.99
ICMP latency min/avg/max/mdev = 202.168/202.377/202.900/0.451 ms
# wireguard
UDP 19.3 91.60 94.78
TCP 17.2 96.76 92.87
ICMP latency min/avg/max/mdev = 217.925/223.601/230.696/3.266 ms
## ПкПлП-1Gbps каМал ÐŒÐµÐ¶ÐŽÑ VPS ÐвÑÐŸÐ¿Ñ Ðž СКР(1 core)
# pure
UDP 729 73.40 39.93
TCP 363 96.95 90.40
ICMP latency min/avg/max/mdev = 106.867/106.994/107.126/0.066 ms
# ipipou
UDP 714 63.10 23.53
TCP 431 95.65 64.56
ICMP latency min/avg/max/mdev = 107.444/107.523/107.648/0.058 ms
# openvpn0 (auth only, no encryption)
UDP 193 17.51 1.62
TCP 12 95.45 92.80
ICMP latency min/avg/max/mdev = 107.191/107.334/107.559/0.116 ms
# wireguard
UDP 629 22.26 2.62
TCP 198 77.40 55.98
ICMP latency min/avg/max/mdev = 107.616/107.788/108.038/0.128 ms
20Mbpsãã£ã³ãã«
1 楜芳ç Gbps ãããã®ãã£ãã«æ°
ãããã®å Žåããipipou ã®ããã©ãŒãã³ã¹ã¯ããŒã¹ ãã£ãã«ã«éåžžã«è¿ããããã¯çŽ æŽãããããšã§ãã
ã©ã¡ãã®å Žåã§ããæå·åãããŠããªã openvpn ãã³ãã«ã¯éåžžã«å¥åŠãªåäœãããŸããã
誰ããããããã¹ãããã€ãããªãããã£ãŒãããã¯ãèãã®ã¯èå³æ·±ãã§ãããã
IPv6 ãš NetPrickle ãç§ãã¡ãšãšãã«ãããŸãããã«!
åºæïŒ habr.com