æè¿ WireGuard å€ãã®æ³šç®ãéããŠãããå®éãããã¯æ°ããªãã¹ã¿ãŒãã§ããã VPNããããèŠãç®ã»ã©è¯ããã®ãªã®ã§ããããïŒããã€ãæ°ã¥ããç¹ãè¿°ã¹ãå®è£ ã«ã€ããŠæ€èšŒããããšæããŸãã WireGuardIPsec ã«åã£ãŠä»£ãããœãªã¥ãŒã·ã§ã³ã§ã¯ãªãçç±ã説æããããã OpenVPN.
ãã®èšäºã§ã¯ãããã€ãã®ç¥è©±ãè§£ãæãããããšæããŸãã WireGuardã¯ããããªãé·ãèšäºãªã®ã§ããŸã ãè¶ãã³ãŒããŒãæ·¹ããŠããªãæ¹ã¯ãä»ããã®æã§ãããŸããç§ã®ãŸãšãŸãã®ãªãèããæ ¡æ£ããŠãããããŒã¿ãŒã«ãæè¬ããããšæããŸãã
éçºè ã®ä¿¡çšã倱å¢ãããããšãç§ã®ç®çã§ã¯ãããŸããã WireGuard圌ãã®åªåãã¢ã€ãã¢ã軜èŠããŠããã圌ãã®è£œåã¯æ©èœããŠããããå人çã«ã¯ãå®éãšã¯å šãç°ãªããã®ãšããŠæç€ºãããŠãããšæããIPsec ã®ä»£æ¿åãšããŠæç€ºãããŠãããã OpenVPNå®éãããã¯çŸåšã§ã¯ååšããªãã
è£è¶³ãšããŠããã®ãããªäœçœ®ä»ãã®è²¬ä»»ã¯ WireGuard å ±éããã¡ãã£ã¢ã«ãã£ãŠæ¡æ£ãããã®ã§ãã£ãŠããããžã§ã¯ãèªäœããã®å¶äœè ã«ãã£ãŠæ¡æ£ãããã®ã§ã¯ãªãã
æè¿ãã³ã¢ã®è©±é¡ã«ã€ã㊠Linux è¯ããã¥ãŒã¹ã¯ã»ãšãã©ãªãã£ãããœãããŠã§ã¢ã§è»œæžãããæãããããã»ããµã®è匱æ§ã«ã€ããŠèããããããéçºè ã®å®çšçãªèšèé£ãã§æžããããªãŒãã¹ã»ããŒãã«ãºã®èª¬æã¯ããŸãã«ãç²éã§éå±ã ã£ããã¹ã±ãžã¥ãŒã©ãã¬ãã«0ãããã¯ãŒã¯ã¹ã¿ãã¯ããå æ²¢ã®ããéèªã§åãäžããã«ã¯åããããã話é¡ãšã¯èšããªãããããŠãããã«çŸããã®ã WireGuard.
æºäžã§ã¯ããã¹ãŠãçŽ æŽãããèãããŸãããšããµã€ãã£ã³ã°ãªæ°ãã¯ãããžãŒã§ãã
ããããããå°ã詳ããèŠãŠã¿ãŸãããã
æè¡ææž WireGuard
ãã®èšäºã¯ä»¥äžã«åºã¥ããŠããŸã å ¬åŒããã¥ã¡ã³ã WireGuardãžã§ã€ãœã³ã»ããã³ãã§ã«ããå·çããèšäºã§ã圌ã¯ãã®æŠå¿µãç®çãæè¡çãªå®è£ ã«ã€ããŠèª¬æããŠããŸããWireGuard] ã³ã¢éšå Linux.
æåã®æã¯æ¬¡ã®ããã«ãªããŸãã
WireGuard [âŠ]ã¯ãã»ãšãã©ã®ãŠãŒã¹ã±ãŒã¹ã§IPsecã ãã§ãªããä»ã®äžè¬çãªãŠãŒã¶ãŒç©ºéããã³/ãŸãã¯TLSããŒã¹ã®ãœãªã¥ãŒã·ã§ã³ã眮ãæããããšãç®æããŠããŸãã OpenVPNããå®å šã§ãããçç£çã§ããã䜿ãããã[ããŒã«]ã§ãã
ãã¡ããããã¹ãŠã®æ°ãããã¯ãããžãŒã®äž»ãªå©ç¹ã¯ã åçŽã ãå 代ãšã®æ¯èŒãã ããããVPN ãåæ§ã§ããå¿ èŠããããŸãã å¹ççãã€å®å š.
ãããŠæ¬¡ã¯ïŒ
ãã㯠[VPN ã«] å¿ èŠãªãã®ã§ã¯ãªããšããå Žåã¯ãããã§èªã¿çµããŠãæ§ããŸããã ãã ãããã®ãããªã¿ã¹ã¯ã¯ä»ã®ãã³ããªã³ã°æè¡ã«ãèšå®ãããŠããããšã«æ³šæããŠãã ããã
äžèšã®åŒçšæã®äžã§æãè峿·±ãã®ã¯ããã»ãšãã©ã®å Žåããšããèšèã«ãããããã¡ãããã¹ã³ãã¯ç¡èŠããã ãããŠããã®èšäºã§ã¯ããã®é倱ã«ãã£ãŠåŒãèµ·ããããæ··ä¹±ã®ããã§ãç§ãã¡ã¯æçµçã«ãã®ãããªç¶æ³ã«é¥ã£ãŠããŸãã

ããã¯èµ·ããã§ããããïŒ WireGuard [IPsec]ãµã€ãéVPNã眮ãæããã¹ãã§ããããïŒ
ããããã·ã¹ã³ããžã¥ãããŒãªã©ã®å€§æãã³ããŒãèªç€Ÿè£œåã®ããã«ãããååŸããå¯èœæ§ã¯å šããããŸããã WireGuard圌ãã¯ãã»ã©ã®ç·æ¥äºæ ã§ããªãéãããéããããã®åè»ã«é£ã³ä¹ãããããªããšã¯ããŸãããåŸã»ã©ã圌ããèªç€Ÿè£œåãè»å ã«èšçœ®ã§ããªãã§ãããçç±ã«ã€ããŠããã€ã説æããŸãã WireGuardããšã圌ããããããããŠãã
ããã¯çãæ®ããã ãããïŒ WireGuard ç§ã®RoadWarriorã¯ãããŒãããœã³ã³ããããŒã¿ã»ã³ã¿ãŒãŸã§ç§»åããŸãã
ãããã WireGuard ãã®ãããªæ©èœãå®çŸããã«ã¯ãéåžžã«å€ãã®éèŠãªæ©èœãæ¬ ããŠããŸããäŸãã°ããã³ãã«ãµãŒããŒåŽã§åçIPã¢ãã¬ã¹ã䜿çšã§ããªããããããã ãã§ãã®è£œåã®å©çšç®çå šäœãæãªãããŠããŸããŸãã
IPFire ã¯ãDSL æ¥ç¶ãã±ãŒãã«æ¥ç¶ãªã©ã®å®äŸ¡ãªã€ã³ã¿ãŒããã ãªã³ã¯ã«ãã䜿çšãããŸãã ããã¯ãé«éãã¡ã€ããŒãå¿ èŠãšããªãäžå°äŒæ¥ã«ãšã£ãŠã¯çã«ããªã£ãŠããŸãã [翻蚳è ããã®æ³š: éä¿¡ã®ç¹ã§ã¯ããã·ã¢ãšäžéšã® CIS 諞åœã¯ãšãŒããããç±³åœãããã¯ããã«å ãè¡ã£ãŠããããšãå¿ããªãã§ãã ããããªããªããç§ãã¡ããããã¯ãŒã¯ãæ§ç¯ãå§ããã®ã¯ããªãåŸã«ãªã£ãŠããã§ãããã€ãŒãµããããšå ãã¡ã€ã㌠ãããã¯ãŒã¯ã®åºçŸã«ãããæšæºãªã®ã§ãåæ§ç¯ããã®ãç°¡åã§ããã EU ãç±³åœã®åãåœã ã§ã¯ã3 ïœ 5 Mbps ã®é床ã§ã® xDSL ãããŒããã³ã ã¢ã¯ã»ã¹ãäŸç¶ãšããŠäžè¬çã§ãããå ãã¡ã€ããŒæ¥ç¶ã«ã¯ãç§ãã¡ã®åºæºãããããšéçŸå®çãªéé¡ãããããŸãã ãããã£ãŠããã®èšäºã®èè ã¯ãDSL ãŸãã¯ã±ãŒãã«æ¥ç¶ãæã®ããšã§ã¯ãªããæšæºã§ãããšè¿°ã¹ãŠããŸãã] ãã ããDSLãã±ãŒãã«ãLTE (ããã³ãã®ä»ã®ã¯ã€ã€ã¬ã¹ ã¢ã¯ã»ã¹æ¹æ³) ã«ã¯åç IP ã¢ãã¬ã¹ããããŸãã ãã¡ãããé »ç¹ã«å€åããªãããšããããŸãããå€åããããšããããŸãã
ãšãããµããããžã§ã¯ãããããŸã ãwg-ãã€ãããã¯ãããã®æ¬ ç¹ãå æããããã«ãŠãŒã¶ãŒã¹ããŒã¹ ããŒã¢ã³ã远å ããŸãã äžã§èª¬æãããŠãŒã¶ãŒ ã·ããªãªã®å€§ããªåé¡ã¯ãåç IPv6 ã¢ãã¬ãã·ã³ã°ã®æªåã§ãã
ãã£ã¹ããªãã¥ãŒã¿ãŒã®èгç¹ãããããšããããããŸãè¯ãããšã§ã¯ãããŸããã èšèšç®æšã® XNUMX ã€ã¯ããããã³ã«ãã·ã³ãã«ãã€ã¯ãªãŒã³ã«ä¿ã€ããšã§ããã
æ®å¿µãªãããå®éã«ã¯ããããã¹ãŠãããŸãã«ãåçŽãã€åå§çãªãã®ã«ãªã£ãŠããããããã®èšèšå šäœãå®éã«äœ¿çšã§ããããã«ããã«ã¯ã远å ã®ãœãããŠã§ã¢ã䜿çšããå¿ èŠããããŸãã
WireGuard ãããªã«ç°¡åã«äœ¿ãããã§ããïŒ
ãŸã ã ãç§ã¯ããã¯èšã£ãŠããªãã WireGuard ããã¯2ç¹éããã³ãã«ã§çµã¶ããã®åªããä»£æ¿ææ®µã«ã¯æ±ºããŠãªããªãã ããããä»ã®ãšããã¯ãå°æ¥çã«ç®æãã¹ã補åã®ã¢ã«ãã¡çã«éããªãã
ããããããã§ã¯åœŒã¯å®éã«äœãããŠããã®ã§ããããïŒ IPsec ã®ä¿å®ã¯æ¬åœã«ããã»ã©é£ããã®ã§ãããã?
æããã«éããŸãã IPsec ãã³ããŒã¯ãããèæ ®ããIPFire ãªã©ã®ã€ã³ã¿ãŒãã§ã€ã¹ãåãã補åãåºè·ããŠããŸãã
IPsec çµç±ã§ VPN ãã³ãã«ãèšå®ããã«ã¯ãæ§æã«å ¥åããå¿ èŠããã XNUMX ã€ã®ããŒã¿ ã»ãããå¿ èŠã«ãªããŸããããã¯ãèªåã®ãããªã㯠IP ã¢ãã¬ã¹ãåä¿¡åŽã®ãããªã㯠IP ã¢ãã¬ã¹ããããªãã¯ã«ãããµããããã§ãããã® VPN æ¥ç¶ãšäºåå ±æããŒã ãããã£ãŠãVPN ã¯æ°å以å ã«ã»ããã¢ãããããã©ã®ãã³ããŒãšãäºææ§ããããŸãã
æ®å¿µãªããããã®è©±ã«ã¯ããã€ãã®äŸå€ããããŸãã IPsec çµç±ã§ OpenBSD ãã·ã³ã«ãã³ãã«ã詊ã¿ãããšããã人ãªããç§ãäœãèšã£ãŠããã®ããããã§ãããã ä»ã«ãããã€ãåä»ãªäŸããããŸãããå®éã«ã¯ãIPsec ã䜿çšããããã®åªããå®è·µæ¹æ³ãããã«ãããããããŸãã
ãããã³ã«ã®è€éãã«ã€ããŠ
ãšã³ããŠãŒã¶ãŒã¯ãããã³ã«ã®è€éããå¿é ããå¿ èŠã¯ãããŸããã
ããããŠãŒã¶ãŒã®çã®é¢å¿äºã§ããäžçã«ç§ãã¡ãäœãã§ãããªãã323 幎以äžåã«äœæããããNAT ã§ã¯ããŸãåäœããªã SIPãH.XNUMXãFTPããã®ä»ã®ãããã³ã«ã¯å»æ¢ãããŠããã§ãããã
IPsecãä»ã®æè¡ãããè€éãªçç±ã¯ããã€ããããŸãã WireGuard: ããã ãã§ã¯ãããŸãããäŸãã°ããã°ã€ã³IDãšãã¹ã¯ãŒãããŸãã¯EAP察å¿ã®SIMã«ãŒãã䜿çšããŠãŠãŒã¶ãŒèªèšŒãè¡ããŸããããã«ãæ°ãããŠãŒã¶ãŒã远å ããæ©èœãåããŠããŸãã æå·ããªããã£ã.
ãããŠã WireGuard ããã¯ååšããŸããã
ãããŠããã¯ã€ãŸã WireGuard ãããã¯ãæå·ããªããã£ãã®ããããã匱äœåããããå®å šã«äŸµå®³ããããããããããã®ã·ã¹ãã ã¯æ©èœããªããªãã ãããæè¡ææžã®èè ã¯æ¬¡ã®ããã«è¿°ã¹ãŠããã
ããã¯ãããšã¯æ³šç®ã«å€ããŸã WireGuard æå·æè¡ã«éä¿¡ããŠãããæå³çã«æå·æ¹åŒãšãããã³ã«ã«æè»æ§ãæãããŠããªããåºç€ãšãªãããªããã£ãã«æ·±å»ãªè匱æ§ãçºèŠãããå Žåããã¹ãŠã®ãšã³ããã€ã³ããæŽæ°ããå¿ èŠããããSSL/TLSã®è匱æ§ã次ã ãšçºèŠãããŠããããšããããããããã«ãæå·åã®æè»æ§ã¯åçã«åäžããŠããã
æåŸã®æã¯ãŸã£ããæ£ããã§ãã
ã©ã®æå·åã䜿çšãããã«ã€ããŠåæã«éãããšãIKE ã TLS ãªã©ã®ãããã³ã«ãäœæãããŸãã бПлее è€éã è€éãããïŒ ã¯ããTLS/SSL ã§ã¯è匱æ§ãéåžžã«äžè¬çã§ããããããã«ä»£ãããã®ã¯ãããŸããã
çŸå®ã®åé¡ãç¡èŠããããšã«ã€ããŠ
äžçåå°ã«200å°ã®ã¯ã©ã€ã¢ã³ããæã€VPNãµãŒããŒããããšæ³åããŠã¿ãŠãã ãããããã¯ããäžè¬çãªäœ¿çšäŸã§ããæå·åæ¹åŒã倿Žããå¿ èŠãããå Žåã¯ããã¹ãŠã®ã¯ã©ã€ã¢ã³ãã«ã¢ããããŒããé©çšããå¿ èŠããããŸãã WireGuard ãããã®ããŒãããœã³ã³ãã¹ããŒããã©ã³ãªã©ã§ã åæã« é éã ããã¯æåéãäžå¯èœã§ãã 管çè ããããå®è¡ããããšãããšãå¿ èŠãªæ§æãå±éããã®ã«äœãæãããããäžèŠæš¡ã®äŒæ¥ããã®ãããªã€ãã³ããå®è¡ããã«ã¯æåéãæ°å¹ŽããããŸãã
IPsecãš OpenVPN æå·æ¹åŒã®ããŽã·ãšãŒã·ã§ã³æ©èœãæäŸããŸãããã®ãããæ°ããæå·åæ¹åŒãæå¹ã«ããåŸãçæéã¯å€ãæå·åæ¹åŒãåŒãç¶ã䜿çšã§ããŸããããã«ãããæ¢åã®ã¯ã©ã€ã¢ã³ãã¯æ°ããããŒãžã§ã³ã«ã¢ããã°ã¬ãŒãã§ããŸããã¢ããããŒããå±éãããããèåŒ±ãªæå·åæ¹åŒãç¡å¹ã«ããã ãã§ããããã§å®äºã§ãïŒçŽ æŽãããïŒã¯ã©ã€ã¢ã³ãã¯äœãæ°ã¥ããªãã§ãããã
ããã¯å€§èŠæš¡ãªå±éã§ã¯å®éã«ããããã±ãŒã¹ã§ããã OpenVPN ãã®ç¹ã«é¢ããŠãããã€ãåé¡ãçããŠããŸããåŸæ¹äºææ§ã¯éèŠã§ãããããšãæå·åã匱ããªã£ããšããŠããå€ãã®äŒæ¥ã«ãšã£ãŠãããã¯äºæ¥ã忢ããçç±ã«ã¯ãªããŸããããªããªããäºæ¥åæ¢ã«ãã£ãŠäœçŸãã®é¡§å®¢ãæ¥åãéè¡ã§ããªããªãããã§ãã
ããŒã WireGuard ãããã³ã«ã¯ç°¡çŽ åããããã®ã®ããã³ãã«ã®äž¡ãã¢ãåžžã«å¶åŸ¡ã§ããªããŠãŒã¶ãŒã«ã¯å šãäžåãã§ãããç§ã®çµéšã§ã¯ããããæãäžè¬çãªã±ãŒã¹ã ã

æå·ïŒ
ããããçŸåšäœ¿çšãããŠãããã®è峿·±ãæ°ããæå·åæ¹åŒãšã¯äžäœäœãªã®ã§ããããïŒ WireGuard?
WireGuard éµäº€æã«ã¯Curve25519ãæå·åã«ã¯ChaCha20ãããŒã¿èªèšŒã«ã¯Poly1305ã䜿çšããŸãããŸããéµããã·ã¥ã«ã¯SipHashãããã·ã¥ã«ã¯BLAKE2ããµããŒãããŠããŸãã
ChaCha20-Poly1305ã¯IPsecçšã«æšæºåãããŠããã OpenVPN ïŒTLSçµç±ïŒ
ãããšã«ã»ããŒã³ã¹ã¿ã€ã³ã®éçºãéåžžã«é »ç¹ã«äœ¿çšãããŠããããšãããããŸãã BLAKE2 ã¯ãSHA-3 ãšã®é¡äŒŒæ§ã®ããã« SHA-2 ãã¡ã€ããªã¹ãã«éžã°ããªãã£ã BLAKE ã®åŸç¶ã§ãã SHA-2 ãç Žãããå ŽåãBLAKE ã䟵害ãããå¯èœæ§ãååã«ãããŸãã
IPsecãš OpenVPN SipHashã¯èšèšäžå¿ é ã§ã¯ãããŸããããã®ãããçŸæç¹ã§VPNãšäœµçšã§ããªãã®ã¯BLAKE2ã®ã¿ã§ããããããæšæºåããããŸã§ã®éã ãã§ããVPNã¯æŽåæ§ã®ããã«HMACã䜿çšããŠãããHMACã¯MD5ãšçµã¿åãããŠã匷åãªãœãªã¥ãŒã·ã§ã³ãšèããããŠãããããããã¯å€§ããªæ¬ ç¹ã§ã¯ãããŸããã
ããã§ç§ã¯ããã¹ãŠã®VPNã¯ã»ãŒåãæå·åããŒã«ã»ããã䜿çšããŠãããšããçµè«ã«è³ããŸããããããã£ãŠ WireGuard æå·åãéä¿¡ããŒã¿ã®å®å šæ§ã«é¢ããŠèšãã°ãä»ã®çŸè¡è£œåãšæ¯ã¹ãŠã»ãã¥ãªãã£é¢ã§åªããŠããããã§ãå£ã£ãŠããããã§ããªãã
ãããããããããæãéèŠãªããšã§ã¯ãããŸããããããžã§ã¯ãã®å ¬åŒããã¥ã¡ã³ãã«ãããšãããã¯æ³šæãæã䟡å€ããããŸãã çµå±ã®ãšãããéèŠãªã®ã¯ã¹ããŒãã§ãã
WireGuard ä»ã®VPNãœãªã¥ãŒã·ã§ã³ãããé«éã§ããïŒ
èŠããã«ãããããéãã¯ãããŸããã
ChaCha20 ã¯ããœãããŠã§ã¢ãžã®å®è£ ã容æãªã¹ããªãŒã æå·ã§ãã äžåºŠã« 128 ããããã€æå·åããŸãã AES ãªã©ã®ããã㯠ãããã³ã«ã¯ããããã¯ãäžåºŠã« XNUMX ãããæå·åããŸãã ããŒããŠã§ã¢ ãµããŒããå®è£ ããã«ã¯ããã«å€ãã®ãã©ã³ãžã¹ã¿ãå¿ èŠãšãªãããã倧åã®ããã»ããµã«ã¯ãæå·åããã»ã¹ã®ã¿ã¹ã¯ã®äžéšãå®è¡ããŠé«éåããåœä»€ã»ããæ¡åŒµæ©èœã§ãã AES-NI ãæèŒãããŠããŸãã
AES-NI ãã¹ããŒããã©ã³ã«æ¡çšãããããšã¯æ±ºããŠãªããšäºæ³ãããŠããŸããããå®éã«ã¯æ¡çšãããŸããã ãããã]ã ãã®ãããChaCha20 ã¯è»œéã§ããããªãŒç¯çŽã®ä»£æ¿åãšããŠéçºãããŸããã ãããã£ãŠãçŸåšè³Œå ¥ã§ãããã¹ãŠã®ã¹ããŒããã©ã³ã«ã¯äœããã® AES ã¢ã¯ã»ã©ã¬ãŒã·ã§ã³ãæèŒãããŠããããã®æå·åã䜿çšãããš ChaCha20 ãããé«éãã€äœæ¶è²»é»åã§åäœãããšãããã¥ãŒã¹ãå±ããããããŸããã
æããã«ãããæ°å¹Žã§è³Œå ¥ãããã»ãŒãã¹ãŠã®ãã¹ã¯ããã/ãµãŒã㌠ããã»ããµã«ã¯ AES-NI ãæèŒãããŠããŸãã
ãããã£ãŠãããããã·ããªãªã«ãããŠAESãChaCha20ãäžåããšäºæ³ãããŸããå ¬åŒããã¥ã¡ã³ãã§ã¯ WireGuard AVX512ã®ãããã§ChaCha20-Poly1305ã¯AES-NIãäžåãæ§èœãçºæ®ãããšãããŠããŸããããã®åœä»€ã»ããæ¡åŒµã¯å€§åããã»ããµã§ã®ã¿å©çšå¯èœã§ãããå°åã®ã¢ãã€ã«ããŒããŠã§ã¢ã§ã¯åœ¹ã«ç«ããããããã®ããŒããŠã§ã¢ã§ã¯åžžã«AES-NIã®æ¹ãé«éã«ãªããŸãã
éçºæ®µéã§ãããäºèŠã§ãããã©ããã¯åãããŸããã WireGuardããã仿¥ã§ã¯ãäžã€ã®æå·åæ¹åŒã«çžãããŠãããšããäºå®èªäœãæ¢ã«æ¬ ç¹ãšãªã£ãŠããããã®éçšã«ããŸãè¯ã圱é¿ãäžããªãå¯èœæ§ãããã
IPsec ã䜿çšãããšãã±ãŒã¹ã«æé©ãªæå·åãèªç±ã«éžæã§ããŸãã ãã¡ãããããã¯ãããšãã° VPN æ¥ç¶ãéã㊠10 GB 以äžã®ããŒã¿ã転éããå Žåã«å¿ èŠã§ãã
çµ±åã®åé¡ Linux
ããã WireGuard ç§ã¯ææ°ã®æå·åãããã³ã«ãéžæããŸãããããã§ã«å€ãã®åé¡ãåŒãèµ·ãããŠããŸãããã®ãããã«ãŒãã«ãæšæºã§ãµããŒãããŠãããã®ã䜿çšãã代ããã«ãçµ±å WireGuard ãããã®ããªããã£ããäžè¶³ããŠãããããäœå¹Žãå»¶æãããŸããã Linux.
ä»ã®ãªãã¬ãŒãã£ã³ã°ã·ã¹ãã ã§ã®ç¶æ³ã¯ããããããŸããããããããããã»ã©éãã¯ãªãã§ãããã Linux.
çŸå®ã¯ã©ã®ããã«èŠããŸããïŒ
æ®å¿µãªãããã¯ã©ã€ã¢ã³ããã VPN æ¥ç¶ã®ã»ããã¢ãããäŸé Œããããã³ã«ãå€ãèªèšŒæ å ±ãšæå·åã䜿çšãããŠãããšããåé¡ã«ééããŸãã 3DES ãš MD5 ãçµã¿åããã䜿çšã¯ãAES-256 ã SHA1 ãšåæ§ã«ãäŸç¶ãšããŠäžè¬çã«è¡ãããŠããŸãã åŸè ã®æ¹ãè¥å¹²åªããŠããŸããããã㯠2020 幎ã«äœ¿çšãã¹ããã®ã§ã¯ãããŸããã
éµäº€æã®å Žå åžžã« RSA ã䜿çšãããŸããããã¯é ãã§ããããªãå®å šãªããŒã«ã§ãã
ç§ã®ã¯ã©ã€ã¢ã³ãã¯ãçšé¢ããã®ä»ã®æ¿åºæ©é¢ãæ©é¢ãããã«ã¯äžçäžã§ååãç¥ãããŠããå€§äŒæ¥ãšé¢ä¿ããŠããŸãã ãããã¯ãã¹ãŠãæ°å幎åã«äœæããããªã¯ãšã¹ã ãã©ãŒã ã䜿çšããŠãããSHA-512 ã䜿çšããæ©èœã¯ãŸã£ãã远å ãããŠããŸããã§ããã ãããäœããã®åœ¢ã§æè¡ã®é²æ©ã«æããã«åœ±é¿ãäžããŠãããšã¯èšããŸããããæããã«äŒæ¥ããã»ã¹ãé ãããŸãã
IPsec 㯠2005 幎以æ¥ãæ¥åæ²ç·ãçŽæ¥ãµããŒãããŠããããããããèŠããšå¿ãçã¿ãŸããCurve25519 ãæ°ãããªãã䜿çšã§ããããã«ãªããŸãã Camellia ã ChaCha20 ãªã©ã® AES ã®ä»£æ¿ææ®µããããŸãããæããã«ããããã¹ãŠã Cisco ãªã©ã®äž»èŠãã³ããŒã«ãã£ãŠãµããŒããããŠããããã§ã¯ãããŸããã
ãããŠäººã ã¯ãããå©çšããŸãã Cisco ãããã¯æ°å€ããããCisco ãšé£æºããããã«èšèšãããããããæ°å€ããããŸãã 圌ãã¯ãã®åéã®åžå ŽãªãŒããŒã§ããããããªãçš®é¡ã®ã€ãããŒã·ã§ã³ã«ãããŸãèå³ããããŸããã
ã¯ããïŒäŒæ¥éšéã®ïŒç¶æ³ã¯ã²ã©ãã§ããã WireGuardã¡ãŒã«ãŒã¯ãçŸåšäœ¿çšããŠããããŒã«ãæå·åæ¹åŒã«ããã©ãŒãã³ã¹äžã®åé¡ãããããšã«æ°ã¥ãããšã¯ãŸããªããIKEv2ã«ãåé¡ãèŠåºãããšã¯ãªãã ããããã®ãããä»£æ¿æ¡ãæ¢ãããšããªãã
äžè¬çã«ãCisco ããããããšãèããããšã¯ãããŸãã?
ãã³ãããŒã¯
ããã§ã¯ãããã¥ã¡ã³ãã«èšèŒãããŠãããã³ãããŒã¯çµæãèŠãŠãããŸãããã WireGuardãã®ææžã¯ç§åŠè«æã§ã¯ãããŸããããéçºè ã«ã¯ãã£ãšç§åŠçãªã¢ãããŒããåããããããã¯ç§åŠçãªã¢ãããŒãããã³ãããŒã¯ãšããŠçšããããšãæåŸ ããŠããŸãããåçŸã§ããªããã³ãããŒã¯ã¯åœ¹ã«ç«ããããŸããŠãå®éšå®€ç°å¢ã§åŸããããã³ãããŒã¯ã¯ãªããã圹ã«ç«ã¡ãŸããã
ã¢ã»ã³ããªèšèª WireGuard ã®ããã« Linux GSOïŒæ±çšã»ã°ã¡ã³ããŒã·ã§ã³ãªãããŒãïŒãå©çšããããšã§ããã®æ¹åŒã¯åªäœæ§ãåŸãŸããã¯ã©ã€ã¢ã³ãã¯64ãããã€ããã®å·šå€§ãªãã±ãããäœæãããããäžåºŠã®åŠçã§æå·åïŒåŸ©å·åã§ããŸããããã«ãããæå·ååŠçãšéä¿¡ã«ãããã³ã¹ããåæžãããŸããVPNæ¥ç¶ã®ã¹ã«ãŒããããæå€§åãããå Žåã¯ããã®æ¹åŒãæå¹ã§ãã
ãããããã€ãã®ããã«ãçŸå®ã¯ããã»ã©åçŽã§ã¯ãããŸããã ãã®ãããªå€§ããªãã±ããããããã¯ãŒã¯ ã¢ããã¿ã«éä¿¡ããã«ã¯ããã±ããã倿°ã®å°ããªãã±ããã«åå²ããå¿ èŠããããŸãã éåžžã®éä¿¡ãµã€ãºã¯ 1500 ãã€ãã§ãã ã€ãŸãã64 ãããã€ãã®å·šå€§ãªãã±ãã㯠45 ã®ãã±ãã (1240 ãã€ãã®æ å ±ãš 20 ãã€ãã® IP ããããŒ) ã«åå²ãããŸãã ãã®åŸããããã¯äžç·ã«äžåºŠã«éä¿¡ããå¿ èŠãããããããã°ããã®éããããã¯ãŒã¯ ã¢ããã¿ãŒã®åäœãå®å šã«ãããã¯ãããŸãã ãã®çµæãåªå é äœãæ¥äžæããVoIP ãªã©ã®ãã±ããããã¥ãŒã«å ¥ããããããšã«ãªããŸãã
ãããã£ãŠã倧èã«äž»åŒµãããŠããé«ãã¹ã«ãŒããã WireGuardããã¯ãä»ã®ã¢ããªã±ãŒã·ã§ã³ã®ãããã¯ãŒã¯ããã©ãŒãã³ã¹ãäœäžãããããšã«ãã£ãŠå®çŸãããŸãããããŠããŒã 㯠WireGuard ãã§ã« ç¢ºèªæžã¿ ãããç§ã®çµè«ã§ãã
ããããå ã«é²ã¿ãŸãããã
æè¡ããã¥ã¡ã³ãã®ãã³ãããŒã¯ã«ãããšãæ¥ç¶ã®ã¹ã«ãŒããã㯠1011 Mbps ã§ãã
å°è±¡çã§ãã
ããã¯ç¹ã«å°è±¡çã§ãããªããªããåäžã®ã®ã¬ãããã€ãŒãµãããæ¥ç¶ã®çè«äžã®æå€§ã¹ã«ãŒãããã¯966Mbpsã§ããããã±ãããµã€ãºã¯1500ãã€ãããIPããããŒã®20ãã€ããUDPããããŒã®8ãã€ããããã³ããããŒèªäœã®16ãã€ããå·®ãåŒããå€ã ããã§ãã WireGuardã«ãã»ã«åããããã±ããã«ã¯å¥ã®IPããããŒããããTCPã«ã20ãã€ãã®IPããããŒãããäžã€ãããŸããã§ã¯ããã®äœåãªåž¯åå¹ ã¯ã©ãããæ¥ãã®ã§ããããïŒ
巚倧ãªãã¬ãŒã ãšäžã§èª¬æãã GSO ã®å©ç¹ãèæ ®ãããšããã¬ãŒã ãµã€ãº 9000 ãã€ãã®çè«äžã®æå€§å€ã¯ 1014 Mbps ã«ãªããŸãã éåžžããã®ãããªã¹ã«ãŒãããã¯å€§ããªå°é£ã䌎ããããçŸå®ã«ã¯éæã§ããŸããã ãããã£ãŠãçè«äžã®æå€§å€ã 64 Mbps ã§ãäžéšã®ãããã¯ãŒã¯ ã¢ããã¿ã§ã®ã¿ãµããŒããããã1023 ãããã€ãã®ããã«å€ªãç¹å€§ãã¬ãŒã ã䜿çšããŠãã¹ããå®è¡ããããšããèããããŸããã ããããããã¯å®éã®ç¶æ³ã§ã¯ãŸã£ããé©çšã§ãããçŽæ¥æ¥ç¶ããã XNUMX ã€ã®ã¹ããŒã·ã§ã³éã§ã®ã¿ããã¹ããã³ãå ã§ã®ã¿äœ¿çšã§ããŸãã
ãã ããVPN ãã³ãã«ã¯ãžã£ã³ã ãã¬ãŒã ããŸã£ãããµããŒãããªãã€ã³ã¿ãŒãããæ¥ç¶ã䜿çšã㊠XNUMX ã€ã®ãã¹ãéã§è»¢éãããããããã³ãã§åŸãããçµæããã³ãããŒã¯ãšããŠæ¡çšããããšã¯ã§ããŸããã ããã¯åã«å®éšå®€ã§ã®éçŸå®çãªææã§ãããå®éã®æŠéç¶æ³ã§ã¯äžå¯èœã§ãããé©çšã§ããŸããã
ããŒã¿ã»ã³ã¿ãŒã«åº§ã£ãŠããŠãã9000 ãã€ããè¶ ãããã¬ãŒã ã転éã§ããŸããã§ããã
å®ç掻ãžã®é©çšæ§ã®åºæºã¯å®å šã«éåãããŠãããç§ãæãã«ãå®è¡ããããæž¬å®ãã®äœæè ã¯ãæçœãªçç±ã§èªåèªèº«ã®ä¿¡çšãèããå·ã€ããŸããã

æåŸã®åžæã®å
ãµã€ã WireGuard ã³ã³ããã«ã€ããŠå€ãã®è°è«ã亀ããããããããå®éã«äœã®ããã«äœãããã®ããæããã«ãªã£ãŠããã
ã·ã³ãã«ã§é«é㪠VPN ã¯æ§æãå¿ èŠãšãããAmazon ãã¯ã©ãŠãã«åããŠãããããªå€§èŠæš¡ãªãªãŒã±ã¹ãã¬ãŒã·ã§ã³ ããŒã«ã䜿çšããŠå±éããã³æ§æã§ããŸãã å ·äœçã«ã¯ãAmazon ã¯ãAVX512 ãªã©ãåè¿°ããææ°ã®ããŒããŠã§ã¢æ©èœã䜿çšããŠããŸãã ããã¯ãx86 ããã®ä»ã®ã¢ãŒããã¯ãã£ã«çžããããäœæ¥ãé«éåããããã«è¡ãããŸãã
ãããã¯ã¹ã«ãŒããããš9000ãã€ããè¶ ãããã±ãããµã€ãºãæé©åããã³ã³ããéä¿¡ãããã¯ã¢ããæäœãã¹ãããã·ã§ããäœæãã³ã³ããå±éãªã©ã®ããã®å·šå€§ãªã«ãã»ã«åãã¬ãŒã ãçæããŸããåçIPã¢ãã¬ã¹ã䜿çšããŠãããã©ãŒãã³ã¹ã«åœ±é¿ã¯ãããŸããã WireGuard ç§ã説æããã·ããªãªã®å Žåã
ãããã£ãã åªããå®è£ ãšéåžžã«èããã»ãŒåç §ãããã³ã«ã
ããããå®å šã«å¶åŸ¡ã§ããããŒã¿ã»ã³ã¿ãŒä»¥å€ã®äžçã§ã¯ãããã¯åçŽã«é©ããŠããŸããããªã¹ã¯ãåããŠäœ¿çšãéå§ãããšã WireGuardæå·åãããã³ã«ãèšèšã»å®è£ ããéã«ã¯ãåžžã«äœããã®åŠ¥åã匷ããããããšã«ãªãã§ãããã
åºå
ç§ã«ãšã£ãŠçµè«ãåºãã®ã¯é£ãããªã WireGuard ãŸã æºåãã§ããŠããŸããã
ããã¯ãæ¢åã®ãœãªã¥ãŒã·ã§ã³ã®å€ãã®åé¡ã«å¯Ÿãã軜éãã€é«éãªãœãªã¥ãŒã·ã§ã³ãšããŠæå³ãããŠããŸãããæ®å¿µãªããããããã®ãœãªã¥ãŒã·ã§ã³ãå®çŸããããã«ãã»ãšãã©ã®ãŠãŒã¶ãŒã«ãšã£ãŠéèŠãªå€ãã®æ©èœãç ç²ã«ããŸããããã®ãããIPsecã OpenVPN.
ããããã«ã WireGuard ç«¶äºåãé«ããããã«ã¯ãå°ãªããšãIPã¢ãã¬ã¹èšå®ãã«ãŒãã£ã³ã°ãDNSèšå®æ©èœã远å ããå¿ èŠãããããã®ããã«ã¯ãæå·åããããã£ãã«ãäžå¯æ¬ ã§ããããšã¯èšããŸã§ããªãã
ã»ãã¥ãªãã£ã¯ç§ã®æåªå äºé ã§ãããçŸæç¹ã§ã¯ãIKE ãŸã㯠TLS ãäœããã®åœ¢ã§äŸµå®³ããããç ŽæãããããŠãããšä¿¡ããçç±ã¯ãããŸããã ã©ã¡ãã§ãææ°ã®æå·åããµããŒããããŠãããæ°å幎ã®éçšã«ãã£ãŠèšŒæãããŠããŸãã äœããæ°ãããããšãã£ãŠããããåªããŠãããšããããã§ã¯ãããŸããã
çžäºéçšæ§ã¯ãå¶åŸ¡ã§ããªã第äžè ã®ç«¯æ«ãšéä¿¡ããå Žåã«éåžžã«éèŠã§ããIPsec ã¯äºå®äžã®æšæºã§ãããã»ãŒãã¹ãŠã®å Žæã§ãµããŒããããŠããŸãããããŠãããã¯æ©èœããŸãããããŠãçè«çã«ã¯ã©ã®ãããªãã®ã§ãã£ãŠãã WireGuard å°æ¥çã«ã¯ãç°ãªãããŒãžã§ã³ã®èªåèªèº«ãšãäºææ§ããªããªãå¯èœæ§ãããã
æå·åä¿è·ã¯é ããæ©ããç Žãããããã亀æãŸãã¯æŽæ°ããå¿ èŠããããŸãã
ãããã®äºå®å šãŠãåŠå®ããç²ç®çã«å©çšããããšãã顿 WireGuard æ¥ç¶ããã«ã¯ iPhone èªå® ã«ã¯ãŒã¯ã¹ããŒã·ã§ã³ãèšçœ®ããããšã¯ãçŸå®ããç®ãèããããšã®æ¥µã¿ãšèšããã ããã
åºæïŒ habr.com
