mikroik. ํด๋ผ์ด์–ธํŠธ๋กœ NAT ๋’ค์˜ IPSEC VPN

๋ชจ๋‘์—๊ฒŒ ์ข‹์€ ๋‚ !

์ง€๋‚œ 1072๋…„ ๋™์•ˆ ์šฐ๋ฆฌ ํšŒ์‚ฌ์—์„œ๋Š” ๋งˆ์ดํฌ๋กœํ‹ฑ์œผ๋กœ ์ฒœ์ฒœํžˆ ์ „ํ™˜ํ•ด ์™”์Šต๋‹ˆ๋‹ค. ๊ธฐ๋ณธ ๋…ธ๋“œ๋Š” CCR99์— ๊ตฌ์ถ•๋˜๋ฉฐ ์žฅ์น˜์˜ ์ปดํ“จํ„ฐ์— ๋Œ€ํ•œ ๋กœ์ปฌ ์—ฐ๊ฒฐ ์ง€์ ์ด ๋” ๊ฐ„๋‹จํ•ฉ๋‹ˆ๋‹ค. ๋ฌผ๋ก  IPSEC ํ„ฐ๋„์„ ํ†ตํ•œ ๋„คํŠธ์›Œํฌ ์กฐํ•ฉ๋„ ์žˆ์Šต๋‹ˆ๋‹ค. ์ด ๊ฒฝ์šฐ ๋„คํŠธ์›Œํฌ์— ๋งŽ์€ ์ž๋ฃŒ๊ฐ€ ์žˆ๊ธฐ ๋•Œ๋ฌธ์— ์„ค์ •์ด ๋งค์šฐ ๊ฐ„๋‹จํ•˜๊ณ  ๋ฌธ์ œ๊ฐ€ ๋ฐœ์ƒํ•˜์ง€ ์•Š์Šต๋‹ˆ๋‹ค. ๊ทธ๋Ÿฌ๋‚˜ ํด๋ผ์ด์–ธํŠธ์˜ ๋ชจ๋ฐ”์ผ ์—ฐ๊ฒฐ์—๋Š” ํŠน์ • ์–ด๋ ค์›€์ด ์žˆ์œผ๋ฉฐ ์ œ์กฐ์—…์ฒด์˜ ์œ„ํ‚ค๋Š” Shrew ์†Œํ”„ํŠธ VPN ํด๋ผ์ด์–ธํŠธ๋ฅผ ์‚ฌ์šฉํ•˜๋Š” ๋ฐฉ๋ฒ•์„ ์ œ์•ˆํ•˜๋ฉฐ(์ด ์„ค์ •์œผ๋กœ ๋ชจ๋“  ๊ฒƒ์ด ๋ช…ํ™•ํ•ด ๋ณด์ž…๋‹ˆ๋‹ค) ์›๊ฒฉ ์•ก์„ธ์Šค ์‚ฌ์šฉ์ž์˜ 1%๊ฐ€ ์‚ฌ์šฉํ•˜๋Š” ํด๋ผ์ด์–ธํŠธ์ž…๋‹ˆ๋‹ค. ๊ทธ๋ฆฌ๊ณ  XNUMX%๋Š” ์ €์ž…๋‹ˆ๋‹ค. ํด๋ผ์ด์–ธํŠธ์— ๋กœ๊ทธ์ธ๊ณผ ์•”ํ˜ธ๋ฅผ ์ž…๋ ฅํ•˜๊ธฐ๋งŒ ํ•˜๋ฉด ๋„ˆ๋ฌด ๊ฒŒ์„๋Ÿฌ์ง€๊ณ  ์†ŒํŒŒ์—์„œ ๊ฒŒ์œผ๋ฅธ ์œ„์น˜์™€ ์ž‘์—… ๋„คํŠธ์›Œํฌ์— ํŽธ๋ฆฌํ•œ ์—ฐ๊ฒฐ์„ ์›ํ–ˆ์Šต๋‹ˆ๋‹ค. ํšŒ์ƒ‰ ์ฃผ์†Œ ๋’ค์— ์žˆ์ง€ ์•Š๊ณ  ๊ฒ€์€์ƒ‰ ์ฃผ์†Œ ๋’ค์— ์™„์ „ํžˆ ์žˆ๊ณ  ๋„คํŠธ์›Œํฌ์˜ ์—ฌ๋Ÿฌ NAT ๋’ค์— ์žˆ๋Š” ์ƒํ™ฉ์— ๋Œ€ํ•ด Mikrotik์„ ๊ตฌ์„ฑํ•˜๋Š” ์ง€์นจ์„ ์ฐพ์ง€ ๋ชปํ–ˆ์Šต๋‹ˆ๋‹ค. ๋”ฐ๋ผ์„œ ์ฆ‰ํฅ์ ์œผ๋กœํ•ด์•ผํ–ˆ๊ธฐ ๋•Œ๋ฌธ์— ๊ฒฐ๊ณผ๋ฅผ ๋ณผ ๊ฒƒ์„ ์ œ์•ˆํ•ฉ๋‹ˆ๋‹ค.

์žˆ๋‹ค :

  1. ์ฃผ ์žฅ์น˜๋กœ CCR1072. ๋ฒ„์ „ 6.44.1
  2. ํ™ˆ ์—ฐ๊ฒฐ ์ง€์ ์œผ๋กœ CAP ac. ๋ฒ„์ „ 6.44.1

์„ค์ •์˜ ์ฃผ์š” ํŠน์ง•์€ PC์™€ Mikrotik์ด ๋ฉ”์ธ 1072์—์„œ ๋ฐœ๊ธ‰ํ•œ ๋™์ผํ•œ ์ฃผ์†Œ ์ง€์ •์œผ๋กœ ๋™์ผํ•œ ๋„คํŠธ์›Œํฌ์— ์žˆ์–ด์•ผ ํ•œ๋‹ค๋Š” ๊ฒƒ์ž…๋‹ˆ๋‹ค.

์„ค์ •์œผ๋กœ ์ด๋™ํ•ด ๋ณด๊ฒ ์Šต๋‹ˆ๋‹ค.

1. ๋ฌผ๋ก  Fasttrack์„ ์ผฐ์ง€๋งŒ fasttrack์€ vpn๊ณผ ํ˜ธํ™˜๋˜์ง€ ์•Š๊ธฐ ๋•Œ๋ฌธ์— ํŠธ๋ž˜ํ”ฝ์„ ์ค„์—ฌ์•ผ ํ•ฉ๋‹ˆ๋‹ค.

/ip firewall mangle
add action=mark-connection chain=forward comment="ipsec in" ipsec-policy=
    in,ipsec new-connection-mark=ipsec passthrough=yes
add action=mark-connection chain=forward comment="ipsec out" ipsec-policy=
    out,ipsec new-connection-mark=ipsec passthrough=yes
/ip firewall filter add action=fasttrack-connection chain=forward connection-mark=!ipsec

2. ์ง‘๊ณผ ์ง์žฅ์—์„œ ๋„คํŠธ์›Œํฌ ํฌ์›Œ๋”ฉ ์ถ”๊ฐ€

/ip firewall raw
add action=accept chain=prerouting dst-address=192.168.33.0/24 src-address=
    10.7.76.0/24
add action=accept chain=prerouting dst-address=192.168.33.0/24 src-address=
    10.7.98.0/24
add action=accept chain=prerouting disabled=yes dst-address=192.168.55.0/24 
    src-address=10.7.78.0/24
add action=accept chain=prerouting dst-address=10.7.76.0/24 src-address=
    192.168.33.0/24
add action=accept chain=prerouting dst-address=10.7.77.0/24 src-address=
    192.168.33.0/24
add action=accept chain=prerouting dst-address=10.7.98.0/24 src-address=
    192.168.33.0/24
add action=accept chain=prerouting disabled=yes dst-address=10.7.78.0/24 
    src-address=192.168.55.0/24
add action=accept chain=prerouting dst-address=192.168.33.0/24 src-address=
    10.7.77.0/24

3. ์‚ฌ์šฉ์ž ์—ฐ๊ฒฐ ์„ค๋ช… ๋งŒ๋“ค๊ธฐ

/ip ipsec identity
add auth-method=pre-shared-key-xauth notrack-chain=prerouting peer=CO secret=
    ะพะฑั‰ะธะน ะบะปัŽั‡ xauth-login=username xauth-password=password

4. IPSEC ์ œ์•ˆ์„œ ์ž‘์„ฑ

/ip ipsec proposal
add enc-algorithms=3des lifetime=5m name="prop1" pfs-group=none

5. IPSEC ์ •์ฑ… ๋งŒ๋“ค๊ธฐ

/ip ipsec policy
add dst-address=10.7.76.0/24 level=unique proposal="prop1" 
    sa-dst-address=<white IP 1072> sa-src-address=0.0.0.0 src-address=
    192.168.33.0/24 tunnel=yes
add dst-address=10.7.77.0/24 level=unique proposal="prop1" 
    sa-dst-address=<white IP 1072> sa-src-address=0.0.0.0 src-address=
    192.168.33.0/24 tunnel=yes

6. IPSEC ํ”„๋กœํ•„ ์ƒ์„ฑ

/ip ipsec profile
set [ find default=yes ] dpd-interval=disable-dpd enc-algorithm=
    aes-192,aes-128,3des nat-traversal=no
add dh-group=modp1024 enc-algorithm=aes-192,aes-128,3des name=profile_1
add name=profile_88
add dh-group=modp1024 lifetime=4h name=profile246

7. IPSEC ํ”ผ์–ด ์ƒ์„ฑ

/ip ipsec peer
add address=<white IP 1072>/32 local-address=<ะฒะฐัˆ ะฐะดั€ะตั ั€ะพัƒั‚ะตั€ะฐ> name=CO profile=
    profile_88

์ด์ œ ๊ฐ„๋‹จํ•œ ๋งˆ๋ฒ•์ด ํ•„์š”ํ•ฉ๋‹ˆ๋‹ค. ํ™ˆ ๋„คํŠธ์›Œํฌ์˜ ๋ชจ๋“  ์žฅ์น˜์— ๋Œ€ํ•œ ์„ค์ •์„ ๋ณ€๊ฒฝํ•˜๊ณ  ์‹ถ์ง€ ์•Š์•˜๊ธฐ ๋•Œ๋ฌธ์— ๊ฐ™์€ ๋„คํŠธ์›Œํฌ์—์„œ ์–ด๋–ป๊ฒŒ๋“  DHCP๋ฅผ ๊ฑธ์–ด์•ผ ํ–ˆ์ง€๋งŒ Mikrotik์ด ํ•˜๋‚˜์˜ ๋ธŒ๋ฆฌ์ง€์— ๋‘˜ ์ด์ƒ์˜ ์ฃผ์†Œ ํ’€์„ ๊ฑธ๋„๋ก ํ—ˆ์šฉํ•˜์ง€ ์•Š๋Š” ๊ฒƒ์ด ํ•ฉ๋ฆฌ์ ์ž…๋‹ˆ๋‹ค. ๊ทธ๋ž˜์„œ ํ•ด๊ฒฐ ๋ฐฉ๋ฒ•์„ ์ฐพ์•˜์Šต๋‹ˆ๋‹ค. ์ฆ‰, ๋žฉํ†ฑ์˜ ๊ฒฝ์šฐ ์ˆ˜๋™ ๋งค๊ฐœ ๋ณ€์ˆ˜๋กœ DHCP ์ž„๋Œ€๋ฅผ ๋ฐฉ๊ธˆ ๋งŒ๋“ค์—ˆ๊ณ  netmask, gateway ๋ฐ dns๋„ DHCP์— ์˜ต์…˜ ๋ฒˆํ˜ธ๊ฐ€ ์žˆ์œผ๋ฏ€๋กœ ์ˆ˜๋™์œผ๋กœ ์ง€์ •ํ–ˆ์Šต๋‹ˆ๋‹ค.

1.DHCP ์˜ต์…˜

/ip dhcp-server option
add code=3 name=option3-gateway value="'192.168.33.1'"
add code=1 name=option1-netmask value="'255.255.255.0'"
add code=6 name=option6-dns value="'8.8.8.8'"

2.DHCP ์ž„๋Œ€

/ip dhcp-server lease
add address=192.168.33.4 dhcp-option=
    option1-netmask,option3-gateway,option6-dns mac-address=<MAC ะฐะดั€ะตั ะฝะพัƒั‚ะฑัƒะบะฐ>

๋™์‹œ์— ์„ค์ • 1072๋Š” ์‚ฌ์‹ค์ƒ ๊ธฐ๋ณธ์ด๋ฉฐ ์„ค์ •์—์„œ ํด๋ผ์ด์–ธํŠธ์— IP ์ฃผ์†Œ๋ฅผ ๋ฐœ๊ธ‰ํ•  ๋•Œ๋งŒ ํ’€์—์„œ๊ฐ€ ์•„๋‹ˆ๋ผ ์ˆ˜๋™์œผ๋กœ ์ž…๋ ฅํ•œ IP ์ฃผ์†Œ๋ฅผ ๊ทธ์—๊ฒŒ ์ œ๊ณตํ•ด์•ผ ํ•จ์„ ๋‚˜ํƒ€๋ƒ…๋‹ˆ๋‹ค. ์ผ๋ฐ˜ PC ํด๋ผ์ด์–ธํŠธ์˜ ๊ฒฝ์šฐ ์„œ๋ธŒ๋„ท์€ Wiki ๊ตฌ์„ฑ 192.168.55.0/24์™€ ๋™์ผํ•ฉ๋‹ˆ๋‹ค.

์ด๋Ÿฌํ•œ ์„ค์ •์„ ์‚ฌ์šฉํ•˜๋ฉด ํƒ€์‚ฌ ์†Œํ”„ํŠธ์›จ์–ด๋ฅผ ํ†ตํ•ด PC์— ์—ฐ๊ฒฐํ•  ์ˆ˜ ์—†์œผ๋ฉฐ ํ•„์š”์— ๋”ฐ๋ผ ๋ผ์šฐํ„ฐ๊ฐ€ ํ„ฐ๋„ ์ž์ฒด๋ฅผ ์˜ฌ๋ฆฝ๋‹ˆ๋‹ค. ํด๋ผ์ด์–ธํŠธ CAP ac์˜ ๋ถ€ํ•˜๋Š” ํ„ฐ๋„์—์„œ 8-11MB/s์˜ ์†๋„๋กœ 9-10%๋กœ ๊ฑฐ์˜ ์ตœ์†Œ์ž…๋‹ˆ๋‹ค.

๋ชจ๋“  ์„ค์ •์€ Winbox๋ฅผ ํ†ตํ•ด ์ด๋ฃจ์–ด์กŒ์ง€๋งŒ ๋™์ผํ•œ ์„ฑ๊ณต์œผ๋กœ ์ฝ˜์†”์„ ํ†ตํ•ด ์ˆ˜ํ–‰ํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

์ถœ์ฒ˜ : habr.com

์ฝ”๋ฉ˜ํŠธ๋ฅผ ์ถ”๊ฐ€