1.5 αž‚αŸ’αžšαŸ„αž„αž€αžΆαžšαžŽαŸαž“αŸ…αž›αžΎ IPsec VPN αž€αŸ’αž“αž»αž„αžŸαŸ’αžšαž»αž€αŸ” αž€αžΆαžšαž’αŸ’αžœαžΎαžαŸαžŸαŸ’αžαžŸαžΆαž€αž›αŸ’αž”αž„

1.5 αž‚αŸ’αžšαŸ„αž„αž€αžΆαžšαžŽαŸαž“αŸ…αž›αžΎ IPsec VPN αž€αŸ’αž“αž»αž„αžŸαŸ’αžšαž»αž€αŸ” αž€αžΆαžšαž’αŸ’αžœαžΎαžαŸαžŸαŸ’αžαžŸαžΆαž€αž›αŸ’αž”αž„

αžŸαŸ’αžαžΆαž“αž—αžΆαž–

αžαŸ’αž‰αž»αŸ†αž”αžΆαž“αž‘αž‘αž½αž›αž€αŸ†αžŽαŸ‚αžŸαžΆαž€αž›αŸ’αž”αž„αž“αŸƒαž•αž›αž·αžαž•αž› C-Terra VPN αž€αŸ†αžŽαŸ‚ 4.3 αžŸαž˜αŸ’αžšαžΆαž”αŸ‹αžšαž™αŸˆαž–αŸαž›αž”αžΈαžαŸ‚αŸ” αžαŸ’αž‰αž»αŸ†αž…αž„αŸ‹αžŸαŸ’αžœαŸ‚αž„αž™αž›αŸ‹αžαžΆαžαžΎαž‡αžΈαžœαž·αžαžœαž·αžŸαŸ’αžœαž€αž˜αŸ’αž˜αžšαž”αžŸαŸ‹αžαŸ’αž‰αž»αŸ†αž“αžΉαž„αž€αžΆαž“αŸ‹αžαŸ‚αž„αžΆαž™αžŸαŸ’αžšαž½αž›αž”αž“αŸ’αž‘αžΆαž”αŸ‹αž–αžΈαž”αŸ’αžαžΌαžšαž‘αŸ…αž€αŸ†αžŽαŸ‚αžαŸ’αž˜αžΈαŸ”

αžαŸ’αž„αŸƒαž“αŸαŸ‡αž˜αž·αž“αž–αž·αž”αžΆαž€αž‘αŸ αž˜αž½αž™αž€αž‰αŸ’αž…αž”αŸ‹ αž€αžΆαž αŸ’αžœαŸ 3 in 1 αž‚αž½αžšαžαŸ‚αž‚αŸ’αžšαž”αŸ‹αž‚αŸ’αžšαžΆαž“αŸ‹αŸ” αžαŸ’αž‰αž»αŸ†αž“αžΉαž„αž”αŸ’αžšαžΆαž”αŸ‹αž’αŸ’αž“αž€αž–αžΈαžšαž”αŸ€αž”αžŠαžΎαž˜αŸ’αž”αžΈαž‘αž‘αž½αž›αž”αžΆαž“αž€αžΆαžšαž”αž„αŸ’αž αžΆαž‰αŸ” αžαŸ’αž‰αž»αŸ†αž“αžΉαž„αž–αŸ’αž™αžΆαž™αžΆαž˜αž”αž„αŸ’αž€αžΎαžαž‚αŸ’αžšαŸ„αž„αž€αžΆαžšαžŽαŸ GRE-over-IPsec αž“αž·αž„ IPsec-over-GRE αŸ”

αžšαž”αŸ€αž”αžŠαžΎαž˜αŸ’αž”αžΈαž‘αž‘αž½αž›αž”αžΆαž“αž€αžΆαžšαž”αž„αŸ’αž αžΆαž‰

1.5 αž‚αŸ’αžšαŸ„αž„αž€αžΆαžšαžŽαŸαž“αŸ…αž›αžΎ IPsec VPN αž€αŸ’αž“αž»αž„αžŸαŸ’αžšαž»αž€αŸ” αž€αžΆαžšαž’αŸ’αžœαžΎαžαŸαžŸαŸ’αžαžŸαžΆαž€αž›αŸ’αž”αž„

αžœαžΆαž’αŸ’αžœαžΎαžαžΆαž˜αž–αžΈαžαž½αžšαž›αŸαžαžŠαŸ‚αž›αžŠαžΎαž˜αŸ’αž”αžΈαž‘αž‘αž½αž›αž”αžΆαž“αž€αžΆαžšαž”αž„αŸ’αž αžΆαž‰ αž’αŸ’αž“αž€αžαŸ’αžšαžΌαžœαŸ–

  • αžŸαžšαžŸαŸαžšαžŸαŸ†αž”αž»αžαŸ’αžšαž‘αŸ… [αž’αŸŠαžΈαž˜αŸ‚αž›αž€αžΆαžšαž–αžΆαžš] αž–αžΈαž’αžΆαžŸαž™αžŠαŸ’αž‹αžΆαž“αžŸαžΆαž‡αžΈαžœαž€αž˜αŸ’αž˜;
  • αž“αŸ…αž€αŸ’αž“αž»αž„αž›αž·αžαž·αžαž“αŸ„αŸ‡ αž…αž„αŸ’αž’αž»αž›αž”αž„αŸ’αž αžΆαž‰ TIN αž“αŸƒαžŸαŸ’αžαžΆαž”αŸαž“αžšαž”αžŸαŸ‹αž’αŸ’αž“αž€
  • αžšαžΆαž™αž”αž‰αŸ’αž‡αžΈαž•αž›αž·αžαž•αž›αž“αž·αž„αž”αžšαž·αž˜αžΆαžŽαžšαž”αžŸαŸ‹αžœαžΆαŸ”

αž€αžΆαžšαž”αž„αŸ’αž αžΆαž‰αž˜αžΆαž“αžŸαž»αž–αž›αž—αžΆαž–αžšαž™αŸˆαž–αŸαž›αž”αžΈαžαŸ‚αŸ” αž’αŸ’αž“αž€αž›αž€αŸ‹αž˜αž·αž“αž€αŸ†αžŽαžαŸ‹αž˜αž»αžαž„αžΆαžšαžšαž”αžŸαŸ‹αž–αž½αž€αž‚αŸαž‘αŸαŸ”

αž€αžΆαžšαž–αž„αŸ’αžšαžΈαž€αžšαžΌαž”αž—αžΆαž–

αž€αžΆαžšαž”αž„αŸ’αž αžΆαž‰αž“αŸƒ Security Gateway αž‚αžΊαž‡αžΆαžšαžΌαž”αž—αžΆαž–αž˜αŸ‰αžΆαžŸαŸŠαžΈαž“αž“αž·αž˜αŸ’αž˜αž·αžαŸ” αžαŸ’αž‰αž»αŸ†αž€αŸ†αž–αž»αž„αž”αŸ’αžšαžΎ VMWare WorkstationαŸ” αž”αž‰αŸ’αž‡αžΈαž–αŸαž‰αž›αŸαž‰αž“αŸƒ hypervisors αžŠαŸ‚αž›αž‚αžΆαŸ†αž‘αŸ’αžš αž“αž·αž„αž”αžšαž·αžŸαŸ’αžαžΆαž“αž“αž·αž˜αŸ’αž˜αž·αžαž˜αžΆαž“αž“αŸ…αž›αžΎαž‚αŸαž αž‘αŸ†αž–αŸαžšαžšαž”αžŸαŸ‹αž’αŸ’αž“αž€αž›αž€αŸ‹αŸ”

αž˜αž»αž“αž–αŸαž›αž’αŸ’αž“αž€αž…αžΆαž”αŸ‹αž•αŸ’αžαžΎαž˜ αžŸαžΌαž˜αž…αŸ†αžŽαžΆαŸ†αžαžΆαž˜αž·αž“αž˜αžΆαž“αž…αŸ†αžŽαž»αž…αž”αŸ’αžšαž‘αžΆαž€αŸ‹αž”αžŽαŸ’αžαžΆαž‰αž“αŸ…αž€αŸ’αž“αž»αž„αžšαžΌαž”αž—αžΆαž–αž˜αŸ‰αžΆαžŸαŸŠαžΈαž“αž“αž·αž˜αŸ’αž˜αž·αžαž›αŸ†αž“αžΆαŸ†αžŠαžΎαž˜αž‘αŸαŸ–

1.5 αž‚αŸ’αžšαŸ„αž„αž€αžΆαžšαžŽαŸαž“αŸ…αž›αžΎ IPsec VPN αž€αŸ’αž“αž»αž„αžŸαŸ’αžšαž»αž€αŸ” αž€αžΆαžšαž’αŸ’αžœαžΎαžαŸαžŸαŸ’αžαžŸαžΆαž€αž›αŸ’αž”αž„

αžαž€αŸ’αž€αžœαž·αž‡αŸ’αž‡αžΆαž‚αžΊαž…αŸ’αž”αžΆαžŸαŸ‹αž›αžΆαžŸαŸ‹ αž’αŸ’αž“αž€αž”αŸ’αžšαžΎαž”αŸ’αžšαžΆαžŸαŸ‹αž‚αž½αžšαžαŸ‚αž”αž“αŸ’αžαŸ‚αž˜αž…αŸ†αžŽαž»αž…αž”αŸ’αžšαž‘αžΆαž€αŸ‹αž‡αžΆαž…αŸ’αžšαžΎαž“αžαžΆαž˜αžŠαŸ‚αž›αž‚αžΆαžαŸ‹αžαŸ’αžšαžΌαžœαž€αžΆαžšαŸ” αžαŸ’αž‰αž»αŸ†αž“αžΉαž„αž”αž“αŸ’αžαŸ‚αž˜αž”αž½αž“αž€αŸ’αž“αž»αž„αž–αŸαž›αžαŸ‚αž˜αž½αž™αŸ–

1.5 αž‚αŸ’αžšαŸ„αž„αž€αžΆαžšαžŽαŸαž“αŸ…αž›αžΎ IPsec VPN αž€αŸ’αž“αž»αž„αžŸαŸ’αžšαž»αž€αŸ” αž€αžΆαžšαž’αŸ’αžœαžΎαžαŸαžŸαŸ’αžαžŸαžΆαž€αž›αŸ’αž”αž„

αž₯αž‘αžΌαžœαž“αŸαŸ‡αžαŸ’αž‰αž»αŸ†αž…αžΆαž”αŸ‹αž•αŸ’αžαžΎαž˜αž˜αŸ‰αžΆαžŸαŸŠαžΈαž“αž“αž·αž˜αŸ’αž˜αž·αžαŸ” αž—αŸ’αž›αžΆαž˜αŸ—αž”αž“αŸ’αž‘αžΆαž”αŸ‹αž–αžΈαž€αžΆαžšαž”αžΎαž€αžŠαŸ†αžŽαžΎαžšαž€αžΆαžš αž…αŸ’αžšαž€αž‘αŸ’αžœαžΆαžšαžαž˜αŸ’αžšαžΌαžœαž±αŸ’αž™αž˜αžΆαž“αžˆαŸ’αž˜αŸ„αŸ‡αž’αŸ’αž“αž€αž”αŸ’αžšαžΎαž”αŸ’αžšαžΆαžŸαŸ‹ αž“αž·αž„αž–αžΆαž€αŸ’αž™αžŸαž˜αŸ’αž„αžΆαžαŸ‹αŸ”

αž˜αžΆαž“αž€αž»αž„αžŸαžΌαž›αž‡αžΆαž…αŸ’αžšαžΎαž“αž“αŸ…αž€αŸ’αž“αž»αž„ S-Terra Gateway αžŠαŸ‚αž›αž˜αžΆαž“αž‚αžŽαž“αžΈαž•αŸ’αžŸαŸαž„αŸ—αž‚αŸ’αž“αžΆαŸ” αžαŸ’αž‰αž»αŸ†αž“αžΉαž„αžšαžΆαž”αŸ‹αž›αŸαžαžšαž”αžŸαŸ‹αž–αž½αž€αž‚αŸαž“αŸ…αž€αŸ’αž“αž»αž„αž’αžαŸ’αžαž”αž‘αžŠαžΆαž…αŸ‹αžŠαŸ„αž™αž‘αŸ‚αž€αž˜αž½αž™αŸ” αž€αŸ’αž“αž»αž„β€‹αž–αŸαž›β€‹αž₯ទូវ:
Login as: administrator
Password: s-terra

αžαŸ’αž‰αž»αŸ†αž€αŸ†αž–αž»αž„αž…αžΆαž”αŸ‹αž•αŸ’αžαžΎαž˜αž…αŸ’αžšαž€αž•αŸ’αž›αžΌαžœαŸ” αž€αžΆαžšαž…αžΆαž”αŸ‹αž•αŸ’αžαžΎαž˜αž‚αžΊαž‡αžΆαžŸαž€αž˜αŸ’αž˜αž—αžΆαž–αžαžΆαž˜αž›αŸ†αžŠαžΆαž”αŸ‹αž›αŸ†αžŠαŸ„αž™αŸ– αž”αž‰αŸ’αž…αžΌαž›αž’αžΆαž‡αŸ’αž‰αžΆαž”αŸαžŽαŸ’αžŽ αž”αž„αŸ’αž€αžΎαžαž˜αŸ‰αžΆαžŸαŸŠαžΈαž“αž”αž„αŸ’αž€αžΎαžαž›αŸαžαž…αŸƒαžŠαž“αŸ’αž™αž‡αžΈαžœαžŸαžΆαžŸαŸ’αžαŸ’αžš (αž˜αŸ‰αžΆαžŸαŸŠαžΈαž“αž€αŸ’αž›αŸ‚αž„αž’αŸ’αžœαžΎαž€αŸ’αžαžΆαžšαž…αž»αž… - αž€αŸ†αžŽαžαŸ‹αžαŸ’αžšαžΆαžšαž”αžŸαŸ‹αžαŸ’αž‰αž»αŸ†αž‚αžΊ 27 αžœαž·αž“αžΆαž‘αžΈ) αž“αž·αž„αž”αž„αŸ’αž€αžΎαžαž•αŸ‚αž“αž‘αžΈαž…αŸ†αžŽαž»αž…αž”αŸ’αžšαž‘αžΆαž€αŸ‹αž”αžŽαŸ’αžαžΆαž‰αŸ”

αž•αŸ‚αž“αž‘αžΈαž“αŸƒαž…αŸ†αžŽαž»αž…αž”αŸ’αžšαž‘αžΆαž€αŸ‹αž”αžŽαŸ’αžαžΆαž‰αŸ” αžœαžΆαž€αžΆαž“αŸ‹αžαŸ‚αž„αžΆαž™αžŸαŸ’αžšαž½αž›

αž€αŸ†αžŽαŸ‚ 4.2 αž”αžΆαž“αžŸαŸ’αžœαžΆαž‚αž˜αž“αŸαž’αŸ’αž“αž€αž”αŸ’αžšαžΎαž”αŸ’αžšαžΆαžŸαŸ‹αžŸαž€αž˜αŸ’αž˜αž‡αžΆαž˜αž½αž™αž“αžΉαž„αžŸαžΆαžšαŸ–

Starting IPsec daemon….. failed
ERROR: Could not establish connection with daemon

αž’αŸ’αž“αž€αž”αŸ’αžšαžΎαž”αŸ’αžšαžΆαžŸαŸ‹αžŸαž€αž˜αŸ’αž˜ (αž™αŸ„αž„αž‘αŸ…αžαžΆαž˜αžœαž·αžŸαŸ’αžœαž€αžšαž’αž“αžΆαž˜αž·αž€) αž‚αžΊαž‡αžΆαž’αŸ’αž“αž€αž”αŸ’αžšαžΎαž”αŸ’αžšαžΆαžŸαŸ‹αžŠαŸ‚αž›αž’αžΆαž…αžŠαŸ†αž‘αžΎαž„αž’αŸ’αžœαžΈαŸ—αž”αžΆαž“αž™αŸ‰αžΆαž„αž†αžΆαž”αŸ‹αžšαž αŸαžŸ αž“αž·αž„αžŠαŸ„αž™αž‚αŸ’αž˜αžΆαž“αž―αž€αžŸαžΆαžšαŸ”

αž˜αžΆαž“αž’αŸ’αžœαžΈαž˜αž½αž™αžαž»αžŸαž”αŸ’αžšαž€αŸ’αžšαžαžΈ αž˜αž»αž“αž–αŸαž›αž–αŸ’αž™αžΆαž™αžΆαž˜αžŠαŸ†αž‘αžΎαž„αž’αžΆαžŸαž™αžŠαŸ’αž‹αžΆαž“ IP αž“αŸ…αž›αžΎαž…αŸ†αžŽαž»αž…αž”αŸ’αžšαž‘αžΆαž€αŸ‹αŸ” αžœαžΆαž‘αžΆαŸ†αž„αž’αžŸαŸ‹αž’αŸ†αž–αžΈαž•αŸ‚αž“αž‘αžΈαž…αŸ†αžŽαž»αž…αž”αŸ’αžšαž‘αžΆαž€αŸ‹αž”αžŽαŸ’αžαžΆαž‰αŸ” αžœαžΆαž…αžΆαŸ†αž”αžΆαž…αŸ‹αžŠαžΎαž˜αŸ’αž”αžΈαž’αŸ’αžœαžΎαŸ–

/bin/netifcfg enum > /home/map
/bin/netifcfg map /home/map
service networking restart

αž‡αžΆαž›αž‘αŸ’αž’αž•αž› αž•αŸ‚αž“αž‘αžΈαž…αŸ†αžŽαž»αž…αž”αŸ’αžšαž‘αžΆαž€αŸ‹αž”αžŽαŸ’αžαžΆαž‰αžαŸ’αžšαžΌαžœαž”αžΆαž“αž”αž„αŸ’αž€αžΎαžαž‘αžΎαž„αžŠαŸ‚αž›αž˜αžΆαž“αž€αžΆαžšαž‚αžΌαžŸαž•αŸ‚αž“αž‘αžΈαž“αŸƒαžˆαŸ’αž˜αŸ„αŸ‡αž…αŸ†αžŽαž»αž…αž”αŸ’αžšαž‘αžΆαž€αŸ‹αžšαžΌαž”αžœαž“αŸ’αž (0000:02:03.0) αž“αž·αž„αž€αžΆαžšαžšαž…αž“αžΆαž‘αžΌαž‡αžΈαžαž›αžšαž”αžŸαŸ‹αž–αž½αž€αž‚αŸαž“αŸ…αž€αŸ’αž“αž»αž„αž”αŸ’αžšαž–αŸαž“αŸ’αž’αž”αŸ’αžšαžαž·αž”αžαŸ’αžαž·αž€αžΆαžš (eth0) αž“αž·αž„αž€αž»αž„αžŸαžΌαž›αžŠαžΌαž…αžŸαŸŠαžΈαžŸαŸ’αž€αžΌ (FastEthernet0/0):

#Unique ID iface type OS name Cisco-like name

0000:02:03.0 phye eth0 FastEthernet0/0

αž€αžΆαžšαžšαž…αž“αžΆαž‘αžΌαž‡αžΈαžαž›αž“αŸƒαž…αŸ†αžŽαž»αž…αž”αŸ’αžšαž‘αžΆαž€αŸ‹αžαŸ’αžšαžΌαžœαž”αžΆαž“αž‚αŸαž αŸ…αžαžΆαžˆαŸ’αž˜αŸ„αŸ‡αž€αŸ’αž›αŸ‚αž„αž€αŸ’αž›αžΆαž™αŸ” αžˆαŸ’αž˜αŸ„αŸ‡αž€αŸ’αž›αŸ‚αž„αž€αŸ’αž›αžΆαž™αžαŸ’αžšαžΌαžœαž”αžΆαž“αžšαž€αŸ’αžŸαžΆαž‘αž»αž€αž€αŸ’αž“αž»αž„αž―αž€αžŸαžΆαžš /etc/ifaliases.cf αŸ”
αž“αŸ…αž€αŸ’αž“αž»αž„αž€αŸ†αžŽαŸ‚ 4.3 αž“αŸ…αž–αŸαž›αžŠαŸ‚αž›αž˜αŸ‰αžΆαžŸαŸŠαžΈαž“αž“αž·αž˜αŸ’αž˜αž·αžαžαŸ’αžšαžΌαžœαž”αžΆαž“αž…αžΆαž”αŸ‹αž•αŸ’αžαžΎαž˜αžŠαŸ†αž”αžΌαž„ αž•αŸ‚αž“αž‘αžΈαž…αŸ†αžŽαž»αž…αž”αŸ’αžšαž‘αžΆαž€αŸ‹αžαŸ’αžšαžΌαžœαž”αžΆαž“αž”αž„αŸ’αž€αžΎαžαžŠαŸ„αž™αžŸαŸ’αžœαŸαž™αž”αŸ’αžšαžœαžαŸ’αžαž·αŸ” αž”αŸ’αžšαžŸαž·αž“αž”αžΎαž’αŸ’αž“αž€αž•αŸ’αž›αžΆαžŸαŸ‹αž”αŸ’αžαžΌαžšαž…αŸ†αž“αž½αž“αž“αŸƒαž…αŸ†αžŽαž»αž…αž”αŸ’αžšαž‘αžΆαž€αŸ‹αž”αžŽαŸ’αžαžΆαž‰αž“αŸ…αž€αŸ’αž“αž»αž„αž˜αŸ‰αžΆαžŸαŸŠαžΈαž“αž“αž·αž˜αŸ’αž˜αž·αžαž“αŸ„αŸ‡ αžŸαžΌαž˜αž”αž„αŸ’αž€αžΎαžαž•αŸ‚αž“αž‘αžΈαž…αŸ†αžŽαž»αž…αž”αŸ’αžšαž‘αžΆαž€αŸ‹αž‘αžΎαž„αžœαž·αž‰αŸ–

/bin/netifcfg enum > /home/map
/bin/netifcfg map /home/map
systemctl restart networking

αž‚αŸ’αžšαŸ„αž„αž€αžΆαžšαžŽαŸαž‘αžΈ 1: GRE-over-IPsec

αžαŸ’αž‰αž»αŸ†β€‹αžŠαžΆαž€αŸ‹β€‹αž–αž„αŸ’αžšαžΆαž™β€‹αž…αŸ’αžšαž€β€‹αž“αž·αž˜αŸ’αž˜αž·αžβ€‹αž–αžΈαžš αžαŸ’αž‰αž»αŸ†β€‹αž”αŸ’αžαžΌαžšβ€‹αžŠαžΌαž…β€‹αž”αž„αŸ’αž αžΆαž‰β€‹αž€αŸ’αž“αž»αž„β€‹αžšαžΌαž”αŸ–

1.5 αž‚αŸ’αžšαŸ„αž„αž€αžΆαžšαžŽαŸαž“αŸ…αž›αžΎ IPsec VPN αž€αŸ’αž“αž»αž„αžŸαŸ’αžšαž»αž€αŸ” αž€αžΆαžšαž’αŸ’αžœαžΎαžαŸαžŸαŸ’αžαžŸαžΆαž€αž›αŸ’αž”αž„

αž‡αŸ†αž αžΆαž“αž‘αžΈ 1. αžšαŸ€αž”αž…αŸ†αž’αžΆαžŸαž™αžŠαŸ’αž‹αžΆαž“ IP αž“αž·αž„αž•αŸ’αž›αžΌαžœ

VG1(config) #
interface fa0/0
ip address 172.16.1.253 255.255.255.0
no shutdown
interface fa0/1
ip address 192.168.1.253 255.255.255.0
no shutdown
ip route 0.0.0.0 0.0.0.0 172.16.1.254

VG2(config) #
interface fa0/0
ip address 172.16.1.254 255.255.255.0
no shutdown
interface fa0/1
ip address 192.168.2.254 255.255.255.0
no shutdown
ip route 0.0.0.0 0.0.0.0 172.16.1.253

αž–αž·αž“αž·αžαŸ’αž™αž€αžΆαžšαž—αŸ’αž‡αžΆαž”αŸ‹ IPαŸ–

root@VG1:~# ping 172.16.1.254 -c 4
PING 172.16.1.254 (172.16.1.254) 56(84) bytes of data.
64 bytes from 172.16.1.254: icmp_seq=1 ttl=64 time=0.545 ms
64 bytes from 172.16.1.254: icmp_seq=2 ttl=64 time=0.657 ms
64 bytes from 172.16.1.254: icmp_seq=3 ttl=64 time=0.687 ms
64 bytes from 172.16.1.254: icmp_seq=4 ttl=64 time=0.273 ms

--- 172.16.1.254 ping statistics ---
4 packets transmitted, 4 received, 0% packet loss, time 3005ms
rtt min/avg/max/mdev = 0.273/0.540/0.687/0.164 ms

αž‡αŸ†αž αžΆαž“αž‘αžΈ 2: αžŠαŸ†αž‘αžΎαž„ GRE

αžαŸ’αž‰αž»αŸ†αž™αž€αž§αž‘αžΆαž αžšαžŽαŸαž“αŸƒαž€αžΆαžšαžŠαŸ†αž‘αžΎαž„ GRE αž–αžΈαžŸαŸ’αž‚αŸ’αžšαžΈαž”αž•αŸ’αž›αžΌαžœαž€αžΆαžšαŸ” αžαŸ’αž‰αž»αŸ†αž”αž„αŸ’αž€αžΎαžαž―αž€αžŸαžΆαžš gre1 αž“αŸ…αž€αŸ’αž“αž»αž„αžαž /etc/network/interfaces.d αž‡αžΆαž˜αž½αž™αž“αžΉαž„αž˜αžΆαžαž·αž€αžΆαŸ”

αžŸαž˜αŸ’αžšαžΆαž”αŸ‹ VG1αŸ–

auto gre1
iface gre1 inet static
address 1.1.1.1
netmask 255.255.255.252
pre-up ip tunnel add gre1 mode gre remote 172.16.1.254 local 172.16.1.253 key 1 ttl 64 tos inherit
pre-up ethtool -K gre1 tx off > /dev/null
pre-up ip link set gre1 mtu 1400
post-down ip link del gre1

αžŸαž˜αŸ’αžšαžΆαž”αŸ‹ VG2αŸ–

auto gre1
iface gre1 inet static
address 1.1.1.2
netmask 255.255.255.252
pre-up ip tunnel add gre1 mode gre remote 172.16.1.253 local 172.16.1.254 key 1 ttl 64 tos inherit
pre-up ethtool -K gre1 tx off > /dev/null
pre-up ip link set gre1 mtu 1400
post-down ip link del gre1

αžαŸ’αž‰αž»αŸ†αž›αžΎαž€αž…αŸ†αžŽαž»αž…αž”αŸ’αžšαž‘αžΆαž€αŸ‹αž“αŸ…αž€αŸ’αž“αž»αž„αž”αŸ’αžšαž–αŸαž“αŸ’αž’αŸ–

root@VG1:~# ifup gre1
root@VG2:~# ifup gre1

αž€αŸ†αž–αž»αž„αž–αž·αž“αž·αžαŸ’αž™αŸ–

root@VG1:~# ip address show
8: gre1@NONE: <POINTOPOINT,NOARP,UP,LOWER_UP> mtu 1400 qdisc noqueue state UNKNOWN group default qlen 1
    link/gre 172.16.1.253 peer 172.16.1.254
    inet 1.1.1.1/30 brd 1.1.1.3 scope global gre1
       valid_lft forever preferred_lft forever

root@VG1:~# ip tunnel show
gre0: gre/ip remote any local any ttl inherit nopmtudisc
gre1: gre/ip remote 172.16.1.254 local 172.16.1.253 ttl 64 tos inherit key 1

C-Terra Gateway αž˜αžΆαž“αž§αž”αž€αžšαžŽαŸ sniffer αž€αž‰αŸ’αž…αž”αŸ‹αžŠαŸ‚αž›αž—αŸ’αž‡αžΆαž”αŸ‹αž˜αž€αž‡αžΆαž˜αž½αž™ - tcpdump αŸ” αžαŸ’αž‰αž»αŸ†αž“αžΉαž„αžŸαžšαžŸαŸαžšαž€αžΆαžšαž”αŸ„αŸ‡αž…αŸ„αž›αž…αžšαžΆαž…αžšαžŽαŸαž‘αŸ…αž€αžΆαž“αŸ‹αž―αž€αžŸαžΆαžš pcapαŸ–

root@VG2:~# tcpdump -i eth0 -w /home/dump.pcap

αžαŸ’αž‰αž»αŸ†αž…αžΆαž”αŸ‹αž•αŸ’αžαžΎαž˜ ping αžšαžœαžΆαž„αž…αŸ†αžŽαž»αž…αž”αŸ’αžšαž‘αžΆαž€αŸ‹ GREαŸ–

root@VG1:~# ping 1.1.1.2 -c 4
PING 1.1.1.2 (1.1.1.2) 56(84) bytes of data.
64 bytes from 1.1.1.2: icmp_seq=1 ttl=64 time=0.918 ms
64 bytes from 1.1.1.2: icmp_seq=2 ttl=64 time=0.850 ms
64 bytes from 1.1.1.2: icmp_seq=3 ttl=64 time=0.918 ms
64 bytes from 1.1.1.2: icmp_seq=4 ttl=64 time=0.974 ms

--- 1.1.1.2 ping statistics ---
4 packets transmitted, 4 received, 0% packet loss, time 3006ms
rtt min/avg/max/mdev = 0.850/0.915/0.974/0.043 ms

αž•αŸ’αž›αžΌαžœαžšαžΌαž„αž€αŸ’αžšαŸ„αž˜αžŠαžΈ GRE αžŠαŸ†αžŽαžΎαžšαž€αžΆαžšαž αžΎαž™αŸ–

1.5 αž‚αŸ’αžšαŸ„αž„αž€αžΆαžšαžŽαŸαž“αŸ…αž›αžΎ IPsec VPN αž€αŸ’αž“αž»αž„αžŸαŸ’αžšαž»αž€αŸ” αž€αžΆαžšαž’αŸ’αžœαžΎαžαŸαžŸαŸ’αžαžŸαžΆαž€αž›αŸ’αž”αž„

αž‡αŸ†αž αžΆαž“αž‘αžΈ 3. αž’αŸŠαž·αž“αž‚αŸ’αžšαžΈαž”αž‡αžΆαž˜αž½αž™ GOST GRE

αžαŸ’αž‰αž»αŸ†αž”αžΆαž“αž€αŸ†αžŽαžαŸ‹αž”αŸ’αžšαž—αŸαž‘αž“αŸƒαž’αžαŸ’αžαžŸαž‰αŸ’αž‰αžΆαžŽ - αžαžΆαž˜αž’αžΆαžŸαž™αžŠαŸ’αž‹αžΆαž“αŸ” αž€αžΆαžšαž•αŸ’αž‘αŸ€αž„αž•αŸ’αž‘αžΆαžαŸ‹αž—αžΆαž–αžαŸ’αžšαžΉαž˜αžαŸ’αžšαžΌαžœαžŠαŸ„αž™αž”αŸ’αžšαžΎαžŸαŸ„αžŠαŸ‚αž›αž”αžΆαž“αž€αŸ†αžŽαžαŸ‹αž‡αžΆαž˜αž»αž“ (αž™αŸ„αž„αž‘αŸ…αžαžΆαž˜αž›αž€αŸ’αžαžαžŽαŸ’αžŒαž“αŸƒαž€αžΆαžšαž”αŸ’αžšαžΎαž”αŸ’αžšαžΆαžŸαŸ‹ αžœαž·αž‰αŸ’αž‰αžΆαž”αž“αž”αžαŸ’αžšαžŒαžΈαž‡αžΈαžαž›αžαŸ’αžšαžΌαžœαžαŸ‚αž”αŸ’αžšαžΎ)αŸ–

VG1(config)#
crypto isakmp identity address
crypto isakmp key KEY address 172.16.1.254

αžαŸ’αž‰αž»αŸ†αž€αŸ†αžŽαžαŸ‹αž”αŸ‰αžΆαžšαŸ‰αžΆαž˜αŸ‰αŸ‚αžαŸ’αžš IPsec Phase IαŸ–

VG1(config)#
crypto isakmp policy 1
encr gost
hash gost3411-256-tc26
auth pre-share
group vko2

αžαŸ’αž‰αž»αŸ†αž€αŸ†αžŽαžαŸ‹αž”αŸ‰αžΆαžšαŸ‰αžΆαž˜αŸ‰αŸ‚αžαŸ’αžš IPsec αžŠαŸ†αžŽαžΆαž€αŸ‹αž€αžΆαž›αž‘αžΈ IIαŸ–

VG1(config)#
crypto ipsec transform-set TSET esp-gost28147-4m-imit
mode tunnel

αžαŸ’αž‰αž»αŸ†αž”αž„αŸ’αž€αžΎαžαž”αž‰αŸ’αž‡αžΈαž…αžΌαž›αž”αŸ’αžšαžΎαžŸαž˜αŸ’αžšαžΆαž”αŸ‹αž€αžΆαžšαž’αŸŠαž·αž“αž‚αŸ’αžšαžΈαž”αŸ” αž…αžšαžΆαž…αžšαžŽαŸαž‚αŸ„αž›αžŠαŸ… - GREαŸ–

VG1(config)#
ip access-list extended LIST
permit gre host 172.16.1.253 host 172.16.1.254

αžαŸ’αž‰αž»αŸ†αž”αž„αŸ’αž€αžΎαžαž•αŸ‚αž“αž‘αžΈαž‚αŸ’αžšαžΈαž”αžαžΌ αž αžΎαž™αž—αŸ’αž‡αžΆαž”αŸ‹αžœαžΆαž‘αŸ…αž…αŸ†αžŽαž»αž…αž”αŸ’αžšαž‘αžΆαž€αŸ‹ WANαŸ–

VG1(config)#
crypto map CMAP 1 ipsec-isakmp
match address LIST
set transform-set TSET
set peer 172.16.1.253
interface fa0/0
  crypto map CMAP

αžŸαž˜αŸ’αžšαžΆαž”αŸ‹ VG2 αž€αžΆαžšαž€αŸ†αžŽαžαŸ‹αžšαž…αž“αžΆαžŸαž˜αŸ’αž–αŸαž“αŸ’αž’αžαŸ’αžšαžΌαžœαž”αžΆαž“αž†αŸ’αž›αž»αŸ‡αž”αž‰αŸ’αž…αžΆαŸ†αž„ αž—αžΆαž–αžαž»αžŸαž‚αŸ’αž“αžΆαž‚αžΊαŸ–

VG2(config)#
crypto isakmp key KEY address 172.16.1.253
ip access-list extended LIST
permit gre host 172.16.1.254 host 172.16.1.253
crypto map CMAP 1 ipsec-isakmp
set peer 172.16.1.254

αž€αŸ†αž–αž»αž„αž–αž·αž“αž·αžαŸ’αž™αŸ–

root@VG2:~# tcpdump -i eth0 -w /home/dump2.pcap
root@VG1:~# ping 1.1.1.2 -c 4
PING 1.1.1.2 (1.1.1.2) 56(84) bytes of data.
64 bytes from 1.1.1.2: icmp_seq=1 ttl=64 time=1128 ms
64 bytes from 1.1.1.2: icmp_seq=2 ttl=64 time=126 ms
64 bytes from 1.1.1.2: icmp_seq=3 ttl=64 time=1.07 ms
64 bytes from 1.1.1.2: icmp_seq=4 ttl=64 time=1.12 ms

--- 1.1.1.2 ping statistics ---
4 packets transmitted, 4 received, 0% packet loss, time 3006ms
rtt min/avg/max/mdev = 1.077/314.271/1128.419/472.826 ms, pipe 2

αžŸαŸ’αžαž·αžαž· ISAKMP/IPsecαŸ–

root@VG1:~# sa_mgr show
ISAKMP sessions: 0 initiated, 0 responded

ISAKMP connections:
Num Conn-id (Local Addr,Port)-(Remote Addr,Port) State Sent Rcvd
1 1 (172.16.1.253,500)-(172.16.1.254,500) active 1086 1014

IPsec connections:
Num Conn-id (Local Addr,Port)-(Remote Addr,Port) Protocol Action Type Sent Rcvd
1 1 (172.16.1.253,*)-(172.16.1.254,*) 47 ESP tunn 480 480

αž˜αž·αž“αž˜αžΆαž“αž€αž‰αŸ’αž…αž”αŸ‹αž“αŸ…αž€αŸ’αž“αž»αž„αž€αž“αŸ’αž›αŸ‚αž„αž…αžΆαž€αŸ‹αžŸαŸ†αžšαžΆαž˜ GRE αž‘αŸαŸ–

1.5 αž‚αŸ’αžšαŸ„αž„αž€αžΆαžšαžŽαŸαž“αŸ…αž›αžΎ IPsec VPN αž€αŸ’αž“αž»αž„αžŸαŸ’αžšαž»αž€αŸ” αž€αžΆαžšαž’αŸ’αžœαžΎαžαŸαžŸαŸ’αžαžŸαžΆαž€αž›αŸ’αž”αž„

αžŸαŸαž…αž€αŸ’αžαžΈαžŸαž“αŸ’αž“αž·αžŠαŸ’αž‹αžΆαž“αŸ– αž‚αŸ’αžšαŸ„αž„αž€αžΆαžšαžŽαŸ GRE-over-IPsec αžŠαŸ†αžŽαžΎαžšαž€αžΆαžšαž”αžΆαž“αžαŸ’αžšαžΉαž˜αžαŸ’αžšαžΌαžœαŸ”

αžšαžΌαž”αž—αžΆαž– 1.5: IPsec-over-GRE

αžαŸ’αž‰αž»αŸ†αž˜αž·αž“αž˜αžΆαž“αž‚αž˜αŸ’αžšαŸ„αž„αž”αŸ’αžšαžΎ IPsec-over-GRE αž“αŸ…αž›αžΎαž”αžŽαŸ’αžαžΆαž‰αž‘αŸαŸ” αžαŸ’αž‰αž»αŸ†αž”αŸ’αžšαž˜αžΌαž›αž–αŸ’αžšαŸ„αŸ‡αžαŸ’αž‰αž»αŸ†αž…αž„αŸ‹αŸ”

1.5 αž‚αŸ’αžšαŸ„αž„αž€αžΆαžšαžŽαŸαž“αŸ…αž›αžΎ IPsec VPN αž€αŸ’αž“αž»αž„αžŸαŸ’αžšαž»αž€αŸ” αž€αžΆαžšαž’αŸ’αžœαžΎαžαŸαžŸαŸ’αžαžŸαžΆαž€αž›αŸ’αž”αž„

αžŠαžΎαž˜αŸ’αž”αžΈαžŠαžΆαž€αŸ‹αž–αž„αŸ’αžšαžΆαž™αž‚αŸ’αžšαŸ„αž„αž€αžΆαžšαžŽαŸ GRE-over-IPsec αžαžΆαž˜αž˜αž’αŸ’αž™αŸ„αž”αžΆαž™αž•αŸ’αžŸαŸαž„αž‘αŸ€αžαŸ–

  • αž‡αž½αžŸαž‡αž»αž›αž”αž‰αŸ’αž‡αžΈαž€αžΆαžšαž…αžΌαž›αž”αŸ’αžšαžΎαž€αžΆαžšαž’αŸŠαž·αž“αž‚αŸ’αžšαžΈαž” - αž…αžšαžΆαž…αžšαžŽαŸαž‚αŸ„αž›αžŠαŸ…αž–αžΈ LAN1 αž‘αŸ… LAN2 αž“αž·αž„αž…αŸ’αžšαžΆαžŸαž˜αž€αžœαž·αž‰;
  • αž€αŸ†αžŽαžαŸ‹αžšαž…αž“αžΆαžŸαž˜αŸ’αž–αŸαž“αŸ’αž’αž•αŸ’αž›αžΌαžœαžαžΆαž˜αžšαž™αŸˆ GRE;
  • αž–αŸ’αž™αž½αžš cryptomap αž“αŸ…αž›αžΎαž…αŸ†αžŽαž»αž…αž”αŸ’αžšαž‘αžΆαž€αŸ‹ GRE αŸ”

αžαžΆαž˜αž›αŸ†αž“αžΆαŸ†αžŠαžΎαž˜ αž˜αž·αž“αž˜αžΆαž“αž…αŸ†αžŽαž»αž…αž”αŸ’αžšαž‘αžΆαž€αŸ‹ GRE αž“αŸ…αž€αŸ’αž“αž»αž„αž€αž»αž„αžŸαžΌαž›αž…αŸ’αžšαž€αž•αŸ’αž›αžΌαžœαžŠαžΌαž… Cisco αž‘αŸαŸ” αžœαžΆαž˜αžΆαž“αžαŸ‚αž“αŸ…αž€αŸ’αž“αž»αž„αž”αŸ’αžšαž–αŸαž“αŸ’αž’αž”αŸ’αžšαžαž·αž”αžαŸ’αžαž·αž€αžΆαžšαž”αŸ‰αž»αžŽαŸ’αžŽαŸ„αŸ‡αŸ”

αžαŸ’αž‰αž»αŸ†αž”αž“αŸ’αžαŸ‚αž˜αž…αŸ†αžŽαž»αž…αž”αŸ’αžšαž‘αžΆαž€αŸ‹ GRE αž‘αŸ…αž€αž»αž„αžŸαžΌαž›αžŠαžΌαž… Cisco αŸ” αžŠαžΎαž˜αŸ’αž”αžΈαž’αŸ’αžœαžΎαžŠαžΌαž…αž“αŸαŸ‡αžαŸ’αž‰αž»αŸ†αž€αŸ‚αžŸαž˜αŸ’αžšαž½αž›αž―αž€αžŸαžΆαžš /etc/ifaliases.cfαŸ–

interface (name="FastEthernet0/0" pattern="eth0")
interface (name="FastEthernet0/1" pattern="eth1")
interface (name="FastEthernet0/2" pattern="eth2")
interface (name="FastEthernet0/3" pattern="eth3")
interface (name="Tunnel0" pattern="gre1")
interface (name="default" pattern="*")

αžŠαŸ‚αž› gre1 αž‚αžΊαž‡αžΆαž€αžΆαžšαžšαž…αž“αžΆαž…αŸ†αžŽαž»αž…αž”αŸ’αžšαž‘αžΆαž€αŸ‹αž“αŸ…αž€αŸ’αž“αž»αž„αž”αŸ’αžšαž–αŸαž“αŸ’αž’αž”αŸ’αžšαžαž·αž”αžαŸ’αžαž·αž€αžΆαžš Tunnel0 αž‚αžΊαž‡αžΆαž€αžΆαžšαžšαž…αž“αžΆαž…αŸ†αžŽαž»αž…αž”αŸ’αžšαž‘αžΆαž€αŸ‹αž“αŸ…αž€αŸ’αž“αž»αž„αž€αž»αž„αžŸαžΌαž›αžŠαžΌαž… Cisco αŸ”

αžαŸ’αž‰αž»αŸ†αž‚αžŽαž“αžΆαž‘αžΎαž„αžœαž·αž‰αž“αžΌαžœ hash αž“αŸƒαž―αž€αžŸαžΆαžšαŸ–

root@VG1:~# integr_mgr calc -f /etc/ifaliases.cf

SUCCESS:  Operation was successful.

αž₯αž‘αžΌαžœαž“αŸαŸ‡αž…αŸ†αžŽαž»αž…αž”αŸ’αžšαž‘αžΆαž€αŸ‹ Tunnel0 αž”αžΆαž“αž”αž„αŸ’αž αžΆαž‰αžαŸ’αž›αž½αž“αž“αŸ…αž€αŸ’αž“αž»αž„αž€αž»αž„αžŸαžΌαž›αžŠαžΌαž… CiscoαŸ–

VG1# show run
interface Tunnel0
ip address 1.1.1.1 255.255.255.252
mtu 1400

αž€αžΆαžšαž€αŸ‚αžαž˜αŸ’αžšαžΌαžœαž”αž‰αŸ’αž‡αžΈαž…αžΌαž›αž”αŸ’αžšαžΎαžŸαž˜αŸ’αžšαžΆαž”αŸ‹αž€αžΆαžšαž’αŸŠαž·αž“αž‚αŸ’αžšαžΈαž”αŸ–

VG1(config)#
ip access-list extended LIST
permit ip 192.168.1.0 0.0.0.255 192.168.3.0 0.0.0.255

αžαŸ’αž‰αž»αŸ†αž€αŸ†αžŽαžαŸ‹αžšαž…αž“αžΆαžŸαž˜αŸ’αž–αŸαž“αŸ’αž’αž•αŸ’αž›αžΌαžœαžαžΆαž˜αžšαž™αŸˆ GREαŸ–

VG1(config)#
no ip route 0.0.0.0 0.0.0.0 172.16.1.254
ip route 192.168.3.0 255.255.255.0 1.1.1.2

αžαŸ’αž‰αž»αŸ†αžŠαž€ cryptomap αž…αŸαž‰αž–αžΈ Fa0/0 αž αžΎαž™αž…αž„αžœαžΆαž‘αŸ…αž…αŸ†αžŽαž»αž…αž”αŸ’αžšαž‘αžΆαž€αŸ‹ GREαŸ–

VG1(config)#
interface Tunnel0
crypto map CMAP

αžŸαž˜αŸ’αžšαžΆαž”αŸ‹ VG2 αžœαžΆαžŸαŸ’αžšαžŠαŸ€αž„αž‚αŸ’αž“αžΆαŸ”

αž€αŸ†αž–αž»αž„αž–αž·αž“αž·αžαŸ’αž™αŸ–

root@VG2:~# tcpdump -i eth0 -w /home/dump3.pcap

root@VG1:~# ping 192.168.2.254 -I 192.168.1.253 -c 4
PING 192.168.2.254 (192.168.2.254) from 192.168.1.253 : 56(84) bytes of data.
64 bytes from 192.168.2.254: icmp_seq=1 ttl=64 time=492 ms
64 bytes from 192.168.2.254: icmp_seq=2 ttl=64 time=1.08 ms
64 bytes from 192.168.2.254: icmp_seq=3 ttl=64 time=1.06 ms
64 bytes from 192.168.2.254: icmp_seq=4 ttl=64 time=1.07 ms

--- 192.168.2.254 ping statistics ---
4 packets transmitted, 4 received, 0% packet loss, time 3006ms
rtt min/avg/max/mdev = 1.064/124.048/492.972/212.998 ms

αžŸαŸ’αžαž·αžαž· ISAKMP/IPsecαŸ–

root@VG1:~# sa_mgr show
ISAKMP sessions: 0 initiated, 0 responded

ISAKMP connections:
Num Conn-id (Local Addr,Port)-(Remote Addr,Port) State Sent Rcvd
1 2 (172.16.1.253,500)-(172.16.1.254,500) active 1094 1022

IPsec connections:
Num Conn-id (Local Addr,Port)-(Remote Addr,Port) Protocol Action Type Sent Rcvd
1 2 (192.168.1.0-192.168.1.255,*)-(192.168.2.0-192.168.2.255,*) * ESP tunn 352 352

αž“αŸ…αž€αŸ’αž“αž»αž„αž€αžΆαžšαž”αŸ„αŸ‡αž…αŸ„αž›αž…αžšαžΆαž…αžšαžŽαŸ ESP αž€αž‰αŸ’αž…αž”αŸ‹αž–αŸαžαŸŒαž˜αžΆαž“αžŠαŸ‚αž›αžšαž»αŸ†αž–αŸαž‘αŸ’αž’αžŠαŸ„αž™ GREαŸ–

1.5 αž‚αŸ’αžšαŸ„αž„αž€αžΆαžšαžŽαŸαž“αŸ…αž›αžΎ IPsec VPN αž€αŸ’αž“αž»αž„αžŸαŸ’αžšαž»αž€αŸ” αž€αžΆαžšαž’αŸ’αžœαžΎαžαŸαžŸαŸ’αžαžŸαžΆαž€αž›αŸ’αž”αž„

αžŸαŸαž…αž€αŸ’αžαžΈαžŸαž“αŸ’αž“αž·αžŠαŸ’αž‹αžΆαž“αŸ– IPsec-over-GRE αžŠαŸ†αžŽαžΎαžšαž€αžΆαžšαž”αžΆαž“αžαŸ’αžšαžΉαž˜αžαŸ’αžšαžΌαžœαŸ”

αž›αž‘αŸ’αž’αž•αž›

αž€αžΆαž αŸ’αžœαŸαž˜αž½αž™αž–αŸ‚αž„αž‚αžΊαž‚αŸ’αžšαž”αŸ‹αž‚αŸ’αžšαžΆαž“αŸ‹αž αžΎαž™αŸ” αžαŸ’αž‰αž»αŸ†αž”αžΆαž“αž‚αžΌαžŸαžœαžΆαžŸαž€αžΆαžšαžŽαŸ‚αž“αžΆαŸ†αžŸαž˜αŸ’αžšαžΆαž”αŸ‹αž€αžΆαžšαž‘αž‘αž½αž›αž”αžΆαž“αž€αŸ†αžŽαŸ‚αžŸαžΆαž€αž›αŸ’αž”αž„αŸ” αž”αžΆαž“αž€αŸ†αžŽαžαŸ‹αžšαž…αž“αžΆαžŸαž˜αŸ’αž–αŸαž“αŸ’αž’ GRE-over-IPsec αž“αž·αž„αžŠαžΆαž€αŸ‹αž±αŸ’αž™αž”αŸ’αžšαžΎαž”αŸ’αžšαžΆαžŸαŸ‹αž•αŸ’αž‘αž»αž™αž˜αž€αžœαž·αž‰αŸ”

αž•αŸ‚αž“αž‘αžΈαž“αŸƒαž…αŸ†αžŽαž»αž…αž”αŸ’αžšαž‘αžΆαž€αŸ‹αž”αžŽαŸ’αžαžΆαž‰αž“αŸ…αž€αŸ’αž“αž»αž„αž€αŸ†αžŽαŸ‚ 4.3 αž‚αžΊαžŠαŸ„αž™αžŸαŸ’αžœαŸαž™αž”αŸ’αžšαžœαžαŸ’αžαž·! αžαŸ’αž‰αž»αŸ†αž€αŸ†αž–αž»αž„αž’αŸ’αžœαžΎαžαŸαžŸαŸ’αžαž”αž“αŸ’αžαŸ‚αž˜αž‘αŸ€αžαŸ”

αžœαž·αžŸαŸ’αžœαž€αžšαž’αž“αžΆαž˜αž·αž€
t.me/anonymous_engineer


αž”αŸ’αžšαž—αž–: www.habr.com

αž”αž“αŸ’αžαŸ‚αž˜αž˜αžαž·αž™αŸ„αž”αž›αŸ‹