๊ตญ๋‚ด IPsec VPN์˜ 1.5 ์ฒด๊ณ„. ํ…Œ์ŠคํŠธ ๋ฐ๋ชจ

๊ตญ๋‚ด IPsec VPN์˜ 1.5 ์ฒด๊ณ„. ํ…Œ์ŠคํŠธ ๋ฐ๋ชจ

์ƒํ™ฉ

C-Terra VPN ์ œํ’ˆ ๋ฒ„์ „ 4.3์˜ ๋ฐ๋ชจ ๋ฒ„์ „์„ XNUMX๊ฐœ์›” ๋™์•ˆ ๋ฐ›์•˜์Šต๋‹ˆ๋‹ค. ์ƒˆ ๋ฒ„์ „์œผ๋กœ ์ „ํ™˜ํ•œ ํ›„ ์—”์ง€๋‹ˆ์–ด๋ง ์ƒํ™œ์ด ๋” ์‰ฌ์›Œ์กŒ๋Š”์ง€ ์•Œ๊ณ  ์‹ถ์Šต๋‹ˆ๋‹ค.

์˜ค๋Š˜์€ ์–ด๋ ต์ง€ ์•Š์Šต๋‹ˆ๋‹ค. ์ธ์Šคํ„ดํŠธ ์ปคํ”ผ 3 in 1 ํ•œ ๋ด‰์ง€๋ฉด ์ถฉ๋ถ„ํ•ฉ๋‹ˆ๋‹ค. ๋ฐ๋ชจ๋ฅผ ๋ฐ›๋Š” ๋ฐฉ๋ฒ•์„ ์•Œ๋ ค๋“œ๋ฆฌ๊ฒ ์Šต๋‹ˆ๋‹ค. GRE-over-IPsec ๋ฐ IPsec-over-GRE ์ฒด๊ณ„๋ฅผ ๊ตฌ์ถ•ํ•˜๋ ค๊ณ  ํ•ฉ๋‹ˆ๋‹ค.

๋ฐ๋ชจ๋ฅผ ๋ฐ›๋Š” ๋ฐฉ๋ฒ•

๊ตญ๋‚ด IPsec VPN์˜ 1.5 ์ฒด๊ณ„. ํ…Œ์ŠคํŠธ ๋ฐ๋ชจ

๋ฐ๋ชจ๋ฅผ ๋ฐ›์œผ๋ ค๋ฉด ๋‹ค์Œ์„ ์ˆ˜ํ–‰ํ•ด์•ผ ํ•ฉ๋‹ˆ๋‹ค.

  • ํŽธ์ง€ ์“ฐ๊ธฐ [์ด๋ฉ”์ผ ๋ณดํ˜ธ] ํšŒ์‚ฌ ์ฃผ์†Œ์—์„œ;
  • ํŽธ์ง€์— ์กฐ์ง์˜ TIN์„ ํ‘œ์‹œํ•˜์‹ญ์‹œ์˜ค.
  • ์ œํ’ˆ๊ณผ ์ˆ˜๋Ÿ‰์„ ๋‚˜์—ดํ•˜์‹ญ์‹œ์˜ค.

๋ฐ๋ชจ๋Š” XNUMX๊ฐœ์›” ๋™์•ˆ ์œ ํšจํ•ฉ๋‹ˆ๋‹ค. ๋ฒค๋”๋Š” ๊ธฐ๋Šฅ์„ ์ œํ•œํ•˜์ง€ ์•Š์Šต๋‹ˆ๋‹ค.

์ด๋ฏธ์ง€ ํ™•์žฅ

Security Gateway ๋ฐ๋ชจ๋Š” ๊ฐ€์ƒ ๋จธ์‹  ์ด๋ฏธ์ง€์ž…๋‹ˆ๋‹ค. VM์›จ์–ด ์›Œํฌ์Šคํ…Œ์ด์…˜์„ ์‚ฌ์šฉํ•˜๊ณ  ์žˆ์Šต๋‹ˆ๋‹ค. ์ง€์›๋˜๋Š” ํ•˜์ดํผ๋ฐ”์ด์ € ๋ฐ ๊ฐ€์ƒํ™” ํ™˜๊ฒฝ์˜ ์ „์ฒด ๋ชฉ๋ก์€ ๊ณต๊ธ‰์—…์ฒด ์›น ์‚ฌ์ดํŠธ์—์„œ ํ™•์ธํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

์‹œ์ž‘ํ•˜๊ธฐ ์ „์— ๊ธฐ๋ณธ ๊ฐ€์ƒ ๋จธ์‹  ์ด๋ฏธ์ง€์— ๋„คํŠธ์›Œํฌ ์ธํ„ฐํŽ˜์ด์Šค๊ฐ€ ์—†๋‹ค๋Š” ์ ์— ์œ ์˜ํ•˜์‹ญ์‹œ์˜ค.

๊ตญ๋‚ด IPsec VPN์˜ 1.5 ์ฒด๊ณ„. ํ…Œ์ŠคํŠธ ๋ฐ๋ชจ

๋…ผ๋ฆฌ๋Š” ๋ช…ํ™•ํ•ฉ๋‹ˆ๋‹ค. ์‚ฌ์šฉ์ž๋Š” ํ•„์š”ํ•œ ๋งŒํผ ์ธํ„ฐํŽ˜์ด์Šค๋ฅผ ์ถ”๊ฐ€ํ•ด์•ผ ํ•ฉ๋‹ˆ๋‹ค. ํ•œ ๋ฒˆ์— XNUMX๊ฐœ๋ฅผ ์ถ”๊ฐ€ํ•˜๊ฒ ์Šต๋‹ˆ๋‹ค.

๊ตญ๋‚ด IPsec VPN์˜ 1.5 ์ฒด๊ณ„. ํ…Œ์ŠคํŠธ ๋ฐ๋ชจ

์ด์ œ ๊ฐ€์ƒ ๋จธ์‹ ์„ ์‹œ์ž‘ํ•ฉ๋‹ˆ๋‹ค. ์‹คํ–‰ ์งํ›„ ๊ฒŒ์ดํŠธ์›จ์ด์—๋Š” ์‚ฌ์šฉ์ž ์ด๋ฆ„๊ณผ ์•”ํ˜ธ๊ฐ€ ํ•„์š”ํ•ฉ๋‹ˆ๋‹ค.

S-Terra Gateway์—๋Š” ๊ณ„์ •์ด ๋‹ค๋ฅธ ์—ฌ๋Ÿฌ ์ฝ˜์†”์ด ์žˆ์Šต๋‹ˆ๋‹ค. ๋ณ„๋„์˜ ๊ธฐ์‚ฌ์—์„œ ๊ทธ ์ˆ˜๋ฅผ ์„ธ๊ฒ ์Šต๋‹ˆ๋‹ค. ์ง€๊ธˆ์€:
Login as: administrator
Password: s-terra

๊ฒŒ์ดํŠธ์›จ์ด๋ฅผ ์ดˆ๊ธฐํ™”ํ•˜๊ณ  ์žˆ์Šต๋‹ˆ๋‹ค. ์ดˆ๊ธฐํ™”๋Š” ๋ผ์ด์„ผ์Šค ์ž…๋ ฅ, ์ƒ๋ฌผํ•™์  ๋‚œ์ˆ˜ ์ƒ์„ฑ๊ธฐ ์„ค์ •(ํ‚ค๋ณด๋“œ ์‹œ๋ฎฌ๋ ˆ์ดํ„ฐ - ๋‚ด ๊ธฐ๋ก์€ 27์ดˆ) ๋ฐ ๋„คํŠธ์›Œํฌ ์ธํ„ฐํŽ˜์ด์Šค ๋งต ์ƒ์„ฑ๊ณผ ๊ฐ™์€ ์ผ๋ จ์˜ ์ž‘์—…์ž…๋‹ˆ๋‹ค.

๋„คํŠธ์›Œํฌ ์ธํ„ฐํŽ˜์ด์Šค์˜ ๋งต. ์‰ฌ์›Œ์กŒ๋‹ค

๋ฒ„์ „ 4.2๋Š” ํ™œ์„ฑ ์‚ฌ์šฉ์ž์—๊ฒŒ ๋‹ค์Œ๊ณผ ๊ฐ™์€ ๋ฉ”์‹œ์ง€๋ฅผ ํ‘œ์‹œํ–ˆ์Šต๋‹ˆ๋‹ค.

Starting IPsec daemonโ€ฆ.. failed
ERROR: Could not establish connection with daemon

ํ™œ์„ฑ ์‚ฌ์šฉ์ž(์ต๋ช…์˜ ์—”์ง€๋‹ˆ์–ด์— ๋”ฐ๋ฅด๋ฉด)๋Š” ๋ฌธ์„œ ์—†์ด ์‹ ์†ํ•˜๊ฒŒ ๋ฌด์—‡์ด๋“  ์„ค์ •ํ•  ์ˆ˜ ์žˆ๋Š” ์‚ฌ์šฉ์ž์ž…๋‹ˆ๋‹ค.

์ธํ„ฐํŽ˜์ด์Šค์—์„œ IP ์ฃผ์†Œ๋ฅผ ์„ค์ •ํ•˜๊ธฐ ์ „์— ๋ฌธ์ œ๊ฐ€ ๋ฐœ์ƒํ–ˆ์Šต๋‹ˆ๋‹ค. ๋„คํŠธ์›Œํฌ ์ธํ„ฐํŽ˜์ด์Šค ๋งต์— ๊ด€ํ•œ ๋ชจ๋“  ๊ฒƒ์ž…๋‹ˆ๋‹ค. ๋‹ค์Œ์„ ์ˆ˜ํ–‰ํ•ด์•ผ ํ–ˆ์Šต๋‹ˆ๋‹ค.

/bin/netifcfg enum > /home/map
/bin/netifcfg map /home/map
service networking restart

๊ฒฐ๊ณผ์ ์œผ๋กœ ๋ฌผ๋ฆฌ์  ์ธํ„ฐํŽ˜์ด์Šค ์ด๋ฆ„(0000:02:03.0)์˜ ๋งคํ•‘๊ณผ ์šด์˜ ์ฒด์ œ(eth0) ๋ฐ Cisco ์œ ์‚ฌ ์ฝ˜์†”(FastEthernet0/0)์˜ ๋…ผ๋ฆฌ์  ์ง€์ •์„ ํฌํ•จํ•˜๋Š” ๋„คํŠธ์›Œํฌ ์ธํ„ฐํŽ˜์ด์Šค ๋งต์ด ์ƒ์„ฑ๋ฉ๋‹ˆ๋‹ค.

#Unique ID iface type OS name Cisco-like name

0000:02:03.0 phye eth0 FastEthernet0/0

์ธํ„ฐํŽ˜์ด์Šค์˜ ๋…ผ๋ฆฌ์  ์ง€์ •์„ ๋ณ„์นญ์ด๋ผ๊ณ  ํ•ฉ๋‹ˆ๋‹ค. ๋ณ„์นญ์€ /etc/ifaliases.cf ํŒŒ์ผ์— ์ €์žฅ๋ฉ๋‹ˆ๋‹ค.
๋ฒ„์ „ 4.3์—์„œ๋Š” ๊ฐ€์ƒ ๋จธ์‹ ์ด ์ฒ˜์Œ ์‹œ์ž‘๋˜๋ฉด ์ธํ„ฐํŽ˜์ด์Šค ๋งต์ด ์ž๋™์œผ๋กœ ์ƒ์„ฑ๋ฉ๋‹ˆ๋‹ค. ๊ฐ€์ƒ ๋จธ์‹ ์—์„œ ๋„คํŠธ์›Œํฌ ์ธํ„ฐํŽ˜์ด์Šค ์ˆ˜๋ฅผ ๋ณ€๊ฒฝํ•˜๋Š” ๊ฒฝ์šฐ ์ธํ„ฐํŽ˜์ด์Šค ๋งต์„ ๋‹ค์‹œ ์ƒ์„ฑํ•˜์‹ญ์‹œ์˜ค.

/bin/netifcfg enum > /home/map
/bin/netifcfg map /home/map
systemctl restart networking

์ฒด๊ณ„ 1: GRE-over-IPsec

๋‘ ๊ฐœ์˜ ๊ฐ€์ƒ ๊ฒŒ์ดํŠธ์›จ์ด๋ฅผ ๋ฐฐํฌํ•˜๊ณ  ๊ทธ๋ฆผ๊ณผ ๊ฐ™์ด ์ „ํ™˜ํ•ฉ๋‹ˆ๋‹ค.

๊ตญ๋‚ด IPsec VPN์˜ 1.5 ์ฒด๊ณ„. ํ…Œ์ŠคํŠธ ๋ฐ๋ชจ

1๋‹จ๊ณ„. IP ์ฃผ์†Œ ๋ฐ ๊ฒฝ๋กœ ์„ค์ •

VG1(config) #
interface fa0/0
ip address 172.16.1.253 255.255.255.0
no shutdown
interface fa0/1
ip address 192.168.1.253 255.255.255.0
no shutdown
ip route 0.0.0.0 0.0.0.0 172.16.1.254

VG2(config) #
interface fa0/0
ip address 172.16.1.254 255.255.255.0
no shutdown
interface fa0/1
ip address 192.168.2.254 255.255.255.0
no shutdown
ip route 0.0.0.0 0.0.0.0 172.16.1.253

IP ์—ฐ๊ฒฐ ํ™•์ธ:

root@VG1:~# ping 172.16.1.254 -c 4
PING 172.16.1.254 (172.16.1.254) 56(84) bytes of data.
64 bytes from 172.16.1.254: icmp_seq=1 ttl=64 time=0.545 ms
64 bytes from 172.16.1.254: icmp_seq=2 ttl=64 time=0.657 ms
64 bytes from 172.16.1.254: icmp_seq=3 ttl=64 time=0.687 ms
64 bytes from 172.16.1.254: icmp_seq=4 ttl=64 time=0.273 ms

--- 172.16.1.254 ping statistics ---
4 packets transmitted, 4 received, 0% packet loss, time 3005ms
rtt min/avg/max/mdev = 0.273/0.540/0.687/0.164 ms

2๋‹จ๊ณ„: GRE ์„ค์ •

๊ณต์‹ ์Šคํฌ๋ฆฝํŠธ์—์„œ GRE๋ฅผ ์„ค์ •ํ•˜๋Š” ์˜ˆ๋ฅผ ๋“ค์—ˆ์Šต๋‹ˆ๋‹ค. ๋‚ด์šฉ์ด ์žˆ๋Š” /etc/network/interfaces.d ๋””๋ ‰ํ† ๋ฆฌ์— gre1 ํŒŒ์ผ์„ ๋งŒ๋“ญ๋‹ˆ๋‹ค.

VG1์˜ ๊ฒฝ์šฐ:

auto gre1
iface gre1 inet static
address 1.1.1.1
netmask 255.255.255.252
pre-up ip tunnel add gre1 mode gre remote 172.16.1.254 local 172.16.1.253 key 1 ttl 64 tos inherit
pre-up ethtool -K gre1 tx off > /dev/null
pre-up ip link set gre1 mtu 1400
post-down ip link del gre1

VG2์˜ ๊ฒฝ์šฐ:

auto gre1
iface gre1 inet static
address 1.1.1.2
netmask 255.255.255.252
pre-up ip tunnel add gre1 mode gre remote 172.16.1.253 local 172.16.1.254 key 1 ttl 64 tos inherit
pre-up ethtool -K gre1 tx off > /dev/null
pre-up ip link set gre1 mtu 1400
post-down ip link del gre1

์‹œ์Šคํ…œ์—์„œ ์ธํ„ฐํŽ˜์ด์Šค๋ฅผ ์˜ฌ๋ฆฝ๋‹ˆ๋‹ค.

root@VG1:~# ifup gre1
root@VG2:~# ifup gre1

ํ™•์ธ ์ค‘:

root@VG1:~# ip address show
8: gre1@NONE: <POINTOPOINT,NOARP,UP,LOWER_UP> mtu 1400 qdisc noqueue state UNKNOWN group default qlen 1
    link/gre 172.16.1.253 peer 172.16.1.254
    inet 1.1.1.1/30 brd 1.1.1.3 scope global gre1
       valid_lft forever preferred_lft forever

root@VG1:~# ip tunnel show
gre0: gre/ip remote any local any ttl inherit nopmtudisc
gre1: gre/ip remote 172.16.1.254 local 172.16.1.253 ttl 64 tos inherit key 1

C-Terra ๊ฒŒ์ดํŠธ์›จ์ด์—๋Š” ํŒจํ‚ท ์Šค๋‹ˆํผ(tcpdump)๊ฐ€ ๋‚ด์žฅ๋˜์–ด ์žˆ์Šต๋‹ˆ๋‹ค. pcap ํŒŒ์ผ์— ํŠธ๋ž˜ํ”ฝ ๋คํ”„๋ฅผ ์ž‘์„ฑํ•ฉ๋‹ˆ๋‹ค.

root@VG2:~# tcpdump -i eth0 -w /home/dump.pcap

GRE ์ธํ„ฐํŽ˜์ด์Šค ๊ฐ„์— ping์„ ์‹œ์ž‘ํ•ฉ๋‹ˆ๋‹ค.

root@VG1:~# ping 1.1.1.2 -c 4
PING 1.1.1.2 (1.1.1.2) 56(84) bytes of data.
64 bytes from 1.1.1.2: icmp_seq=1 ttl=64 time=0.918 ms
64 bytes from 1.1.1.2: icmp_seq=2 ttl=64 time=0.850 ms
64 bytes from 1.1.1.2: icmp_seq=3 ttl=64 time=0.918 ms
64 bytes from 1.1.1.2: icmp_seq=4 ttl=64 time=0.974 ms

--- 1.1.1.2 ping statistics ---
4 packets transmitted, 4 received, 0% packet loss, time 3006ms
rtt min/avg/max/mdev = 0.850/0.915/0.974/0.043 ms

GRE ํ„ฐ๋„์ด ์‹คํ–‰ ์ค‘์ž…๋‹ˆ๋‹ค.

๊ตญ๋‚ด IPsec VPN์˜ 1.5 ์ฒด๊ณ„. ํ…Œ์ŠคํŠธ ๋ฐ๋ชจ

3๋‹จ๊ณ„. GOST GRE๋กœ ์•”ํ˜ธํ™”

์‹๋ณ„ ์œ ํ˜•์„ ์ฃผ์†Œ๋กœ ์„ค์ •ํ–ˆ์Šต๋‹ˆ๋‹ค. ๋ฏธ๋ฆฌ ์ •์˜๋œ ํ‚ค๋กœ ์ธ์ฆ(์ด์šฉ ์•ฝ๊ด€์— ๋”ฐ๋ผ ๋””์ง€ํ„ธ ์ธ์ฆ์„œ๋ฅผ ์‚ฌ์šฉํ•ด์•ผ ํ•จ):

VG1(config)#
crypto isakmp identity address
crypto isakmp key KEY address 172.16.1.254

IPsec Phase I ๋งค๊ฐœ๋ณ€์ˆ˜๋ฅผ ์„ค์ •ํ•ฉ๋‹ˆ๋‹ค.

VG1(config)#
crypto isakmp policy 1
encr gost
hash gost3411-256-tc26
auth pre-share
group vko2

IPsec Phase II ๋งค๊ฐœ๋ณ€์ˆ˜๋ฅผ ์„ค์ •ํ–ˆ์Šต๋‹ˆ๋‹ค.

VG1(config)#
crypto ipsec transform-set TSET esp-gost28147-4m-imit
mode tunnel

์•”ํ˜ธํ™”๋ฅผ ์œ„ํ•œ ์•ก์„ธ์Šค ๋ชฉ๋ก์„ ๋งŒ๋“ญ๋‹ˆ๋‹ค. ํƒ€๊ฒŸ ํŠธ๋ž˜ํ”ฝ - GRE:

VG1(config)#
ip access-list extended LIST
permit gre host 172.16.1.253 host 172.16.1.254

์•”ํ˜ธํ™” ๋งต์„ ์ƒ์„ฑํ•˜๊ณ  WAN ์ธํ„ฐํŽ˜์ด์Šค์— ๋ฐ”์ธ๋”ฉํ•ฉ๋‹ˆ๋‹ค.

VG1(config)#
crypto map CMAP 1 ipsec-isakmp
match address LIST
set transform-set TSET
set peer 172.16.1.253
interface fa0/0
  crypto map CMAP

VG2์˜ ๊ฒฝ์šฐ ๊ตฌ์„ฑ์ด ๋ฏธ๋Ÿฌ๋ง๋˜๋ฉฐ ์ฐจ์ด์ ์€ ๋‹ค์Œ๊ณผ ๊ฐ™์Šต๋‹ˆ๋‹ค.

VG2(config)#
crypto isakmp key KEY address 172.16.1.253
ip access-list extended LIST
permit gre host 172.16.1.254 host 172.16.1.253
crypto map CMAP 1 ipsec-isakmp
set peer 172.16.1.254

ํ™•์ธ ์ค‘:

root@VG2:~# tcpdump -i eth0 -w /home/dump2.pcap
root@VG1:~# ping 1.1.1.2 -c 4
PING 1.1.1.2 (1.1.1.2) 56(84) bytes of data.
64 bytes from 1.1.1.2: icmp_seq=1 ttl=64 time=1128 ms
64 bytes from 1.1.1.2: icmp_seq=2 ttl=64 time=126 ms
64 bytes from 1.1.1.2: icmp_seq=3 ttl=64 time=1.07 ms
64 bytes from 1.1.1.2: icmp_seq=4 ttl=64 time=1.12 ms

--- 1.1.1.2 ping statistics ---
4 packets transmitted, 4 received, 0% packet loss, time 3006ms
rtt min/avg/max/mdev = 1.077/314.271/1128.419/472.826 ms, pipe 2

ISAKMP/IPsec ํ†ต๊ณ„:

root@VG1:~# sa_mgr show
ISAKMP sessions: 0 initiated, 0 responded

ISAKMP connections:
Num Conn-id (Local Addr,Port)-(Remote Addr,Port) State Sent Rcvd
1 1 (172.16.1.253,500)-(172.16.1.254,500) active 1086 1014

IPsec connections:
Num Conn-id (Local Addr,Port)-(Remote Addr,Port) Protocol Action Type Sent Rcvd
1 1 (172.16.1.253,*)-(172.16.1.254,*) 47 ESP tunn 480 480

GRE ํŠธ๋ž˜ํ”ฝ ๋คํ”„์— ํŒจํ‚ท์ด ์—†์Šต๋‹ˆ๋‹ค.

๊ตญ๋‚ด IPsec VPN์˜ 1.5 ์ฒด๊ณ„. ํ…Œ์ŠคํŠธ ๋ฐ๋ชจ

๊ฒฐ๋ก : GRE-over-IPsec ์ฒด๊ณ„๋Š” ์˜ฌ๋ฐ”๋ฅด๊ฒŒ ์ž‘๋™ํ•ฉ๋‹ˆ๋‹ค.

๊ทธ๋ฆผ 1.5: IPsec-over-GRE

๋„คํŠธ์›Œํฌ์—์„œ IPsec-over-GRE๋ฅผ ์‚ฌ์šฉํ•  ๊ณ„ํš์ด ์—†์Šต๋‹ˆ๋‹ค. ๋‚ด๊ฐ€ ์›ํ•˜๊ธฐ ๋•Œ๋ฌธ์— ์ˆ˜์ง‘ํ•ฉ๋‹ˆ๋‹ค.

๊ตญ๋‚ด IPsec VPN์˜ 1.5 ์ฒด๊ณ„. ํ…Œ์ŠคํŠธ ๋ฐ๋ชจ

GRE-over-IPsec ์ฒด๊ณ„๋ฅผ ๋ฐ˜๋Œ€๋กœ ๋ฐฐํฌํ•˜๋ ค๋ฉด ๋‹ค์Œ์„ ์ˆ˜ํ–‰ํ•˜์‹ญ์‹œ์˜ค.

  • ์•”ํ˜ธํ™” ์•ก์„ธ์Šค ๋ชฉ๋ก ์ˆ˜์ • - LAN1์—์„œ LAN2๋กœ ๋˜๋Š” ๊ทธ ๋ฐ˜๋Œ€๋กœ ๋Œ€์ƒ ํŠธ๋ž˜ํ”ฝ;
  • GRE๋ฅผ ํ†ตํ•œ ๋ผ์šฐํŒ… ๊ตฌ์„ฑ
  • GRE ์ธํ„ฐํŽ˜์ด์Šค์— cryptomap์„ ๊ฑธ์–ด๋‘ก๋‹ˆ๋‹ค.

๊ธฐ๋ณธ์ ์œผ๋กœ Cisco์™€ ์œ ์‚ฌํ•œ ๊ฒŒ์ดํŠธ์›จ์ด ์ฝ˜์†”์—๋Š” GRE ์ธํ„ฐํŽ˜์ด์Šค๊ฐ€ ์—†์Šต๋‹ˆ๋‹ค. ์šด์˜ ์ฒด์ œ์—๋งŒ ์กด์žฌํ•ฉ๋‹ˆ๋‹ค.

Cisco์™€ ๊ฐ™์€ ์ฝ˜์†”์— GRE ์ธํ„ฐํŽ˜์ด์Šค๋ฅผ ์ถ”๊ฐ€ํ•ฉ๋‹ˆ๋‹ค. ์ด๋ฅผ ์œ„ํ•ด /etc/ifaliases.cf ํŒŒ์ผ์„ ํŽธ์ง‘ํ•ฉ๋‹ˆ๋‹ค.

interface (name="FastEthernet0/0" pattern="eth0")
interface (name="FastEthernet0/1" pattern="eth1")
interface (name="FastEthernet0/2" pattern="eth2")
interface (name="FastEthernet0/3" pattern="eth3")
interface (name="Tunnel0" pattern="gre1")
interface (name="default" pattern="*")

์—ฌ๊ธฐ์„œ gre1์€ ์šด์˜ ์ฒด์ œ์˜ ์ธํ„ฐํŽ˜์ด์Šค ์ง€์ •์ด๊ณ  Tunnel0์€ Cisco์™€ ๊ฐ™์€ ์ฝ˜์†”์˜ ์ธํ„ฐํŽ˜์ด์Šค ์ง€์ •์ž…๋‹ˆ๋‹ค.

ํŒŒ์ผ์˜ ํ•ด์‹œ๋ฅผ ๋‹ค์‹œ ๊ณ„์‚ฐํ•ฉ๋‹ˆ๋‹ค.

root@VG1:~# integr_mgr calc -f /etc/ifaliases.cf

SUCCESS:  Operation was successful.

์ด์ œ Tunnel0 ์ธํ„ฐํŽ˜์ด์Šค๊ฐ€ Cisco์™€ ๊ฐ™์€ ์ฝ˜์†”์— ๋‚˜ํƒ€๋‚ฌ์Šต๋‹ˆ๋‹ค.

VG1# show run
interface Tunnel0
ip address 1.1.1.1 255.255.255.252
mtu 1400

์•”ํ˜ธํ™”๋ฅผ ์œ„ํ•œ ์•ก์„ธ์Šค ๋ชฉ๋ก ์ˆ˜์ •:

VG1(config)#
ip access-list extended LIST
permit ip 192.168.1.0 0.0.0.255 192.168.3.0 0.0.0.255

GRE๋ฅผ ํ†ตํ•ด ๋ผ์šฐํŒ…์„ ๊ตฌ์„ฑํ•ฉ๋‹ˆ๋‹ค.

VG1(config)#
no ip route 0.0.0.0 0.0.0.0 172.16.1.254
ip route 192.168.3.0 255.255.255.0 1.1.1.2

Fa0 / 0์—์„œ ์•”ํ˜ธ ๋งต์„ ์ œ๊ฑฐํ•˜๊ณ  GRE ์ธํ„ฐํŽ˜์ด์Šค์— ๋ฐ”์ธ๋”ฉํ•ฉ๋‹ˆ๋‹ค.

VG1(config)#
interface Tunnel0
crypto map CMAP

VG2์˜ ๊ฒฝ์šฐ ์œ ์‚ฌํ•ฉ๋‹ˆ๋‹ค.

ํ™•์ธ ์ค‘:

root@VG2:~# tcpdump -i eth0 -w /home/dump3.pcap

root@VG1:~# ping 192.168.2.254 -I 192.168.1.253 -c 4
PING 192.168.2.254 (192.168.2.254) from 192.168.1.253 : 56(84) bytes of data.
64 bytes from 192.168.2.254: icmp_seq=1 ttl=64 time=492 ms
64 bytes from 192.168.2.254: icmp_seq=2 ttl=64 time=1.08 ms
64 bytes from 192.168.2.254: icmp_seq=3 ttl=64 time=1.06 ms
64 bytes from 192.168.2.254: icmp_seq=4 ttl=64 time=1.07 ms

--- 192.168.2.254 ping statistics ---
4 packets transmitted, 4 received, 0% packet loss, time 3006ms
rtt min/avg/max/mdev = 1.064/124.048/492.972/212.998 ms

ISAKMP/IPsec ํ†ต๊ณ„:

root@VG1:~# sa_mgr show
ISAKMP sessions: 0 initiated, 0 responded

ISAKMP connections:
Num Conn-id (Local Addr,Port)-(Remote Addr,Port) State Sent Rcvd
1 2 (172.16.1.253,500)-(172.16.1.254,500) active 1094 1022

IPsec connections:
Num Conn-id (Local Addr,Port)-(Remote Addr,Port) Protocol Action Type Sent Rcvd
1 2 (192.168.1.0-192.168.1.255,*)-(192.168.2.0-192.168.2.255,*) * ESP tunn 352 352

ESP ํŠธ๋ž˜ํ”ฝ ๋คํ”„์—์„œ GRE๋กœ ์บก์Šํ™”๋œ ํŒจํ‚ท:

๊ตญ๋‚ด IPsec VPN์˜ 1.5 ์ฒด๊ณ„. ํ…Œ์ŠคํŠธ ๋ฐ๋ชจ

๊ฒฐ๋ก : IPsec-over-GRE๊ฐ€ ์˜ฌ๋ฐ”๋ฅด๊ฒŒ ์ž‘๋™ํ•ฉ๋‹ˆ๋‹ค.

๊ฒฐ๊ณผ

์ปคํ”ผ ํ•œ ์ž”์ด๋ฉด ์ถฉ๋ถ„ํ–ˆ๋‹ค. ๋ฐ๋ชจ ๋ฒ„์ „์„ ์–ป๊ธฐ ์œ„ํ•œ ์ง€์นจ์„ ์Šค์ผ€์น˜ํ–ˆ์Šต๋‹ˆ๋‹ค. GRE-over-IPsec์„ ๊ตฌ์„ฑํ•˜๊ณ  ๊ทธ ๋ฐ˜๋Œ€๋กœ ๋ฐฐํฌํ–ˆ์Šต๋‹ˆ๋‹ค.

๋ฒ„์ „ 4.3์˜ ๋„คํŠธ์›Œํฌ ์ธํ„ฐํŽ˜์ด์Šค ๋งต์€ ์ž๋™์ž…๋‹ˆ๋‹ค! ์ถ”๊ฐ€ ํ…Œ์ŠคํŠธ ์ค‘์ž…๋‹ˆ๋‹ค.

์ต๋ช…์˜ ์—”์ง€๋‹ˆ์–ด
t.me/anonymous_engineer


์ถœ์ฒ˜ : habr.com

์ฝ”๋ฉ˜ํŠธ๋ฅผ ์ถ”๊ฐ€