Mikrotik RouterOS์˜ ๋ฉ€ํ‹ฐ๋ฐด ๋ฐ ๋ผ์šฐํŒ…

์†Œ๊ฐœ

ํ—ˆ์˜์‹ฌ ์™ธ์—๋„ ๊ธฐ์‚ฌ๋ฅผ ์ฑ„ํƒํ•˜๋Š” ๊ฒƒ์€ ๋Ÿฌ์‹œ์•„์–ด๋ฅผ ์‚ฌ์šฉํ•˜๋Š” ์ „๋ณด ์ปค๋ฎค๋‹ˆํ‹ฐ์˜ ํ”„๋กœํ•„ ๊ทธ๋ฃน์—์„œ์ด ์ฃผ์ œ์— ๋Œ€ํ•œ ์šฐ์šธํ•œ ์งˆ๋ฌธ ๋นˆ๋„๋กœ ์ธํ•ด ์ด‰๋ฐœ๋˜์—ˆ์Šต๋‹ˆ๋‹ค. ์ด ๊ธฐ์‚ฌ๋Š” ์ดˆ๋ณด์ž Mikrotik RouterOS(์ดํ•˜ ROS) ๊ด€๋ฆฌ์ž๋ฅผ ๋Œ€์ƒ์œผ๋กœ ํ•ฉ๋‹ˆ๋‹ค. ๋ผ์šฐํŒ…์— ์ค‘์ ์„ ๋‘” ๋ฉ€ํ‹ฐ๋ฐด๋งŒ ๋‹ค๋ฃน๋‹ˆ๋‹ค. ๋ณด๋„ˆ์Šค๋กœ ์•ˆ์ „ํ•˜๊ณ  ํŽธ๋ฆฌํ•œ ์ž‘๋™์„ ๋ณด์žฅํ•˜๋Š” ์ตœ์†Œํ•œ์˜ ์„ค์ •์ด ์žˆ์Šต๋‹ˆ๋‹ค. ๋Œ€๊ธฐ์—ด, ๋กœ๋“œ ๋ฐธ๋Ÿฐ์‹ฑ, VLAN, ๋ธŒ๋ฆฌ์ง€, ์ฑ„๋„ ์ƒํƒœ์— ๋Œ€ํ•œ ๋‹ค๋‹จ๊ณ„ ์‹ฌ์ธต ๋ถ„์„ ๋“ฑ์— ๋Œ€ํ•œ ์ฃผ์ œ ๊ณต๊ฐœ๋ฅผ ์›ํ•˜๋Š” ์‚ฌ๋žŒ๋“ค์€ ์‹œ๊ฐ„๊ณผ ๋…ธ๋ ฅ์„ ๋‚ญ๋น„ํ•˜์ง€ ์•Š์„ ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

์›์‹œ ๋ฐ์ดํ„ฐ

ํ…Œ์ŠคํŠธ ๋Œ€์ƒ์œผ๋กœ ROS ๋ฒ„์ „ 6.45.3์˜ 1ํฌํŠธ Mikrotik ๋ผ์šฐํ„ฐ๋ฅผ ์„ ํƒํ–ˆ์Šต๋‹ˆ๋‹ค. ๋‘ ๊ฐœ์˜ ๋กœ์ปฌ ๋„คํŠธ์›Œํฌ(LAN2 ๋ฐ LAN1)์™€ ์„ธ ๊ฐœ์˜ ๊ณต๊ธ‰์ž(ISP2, ISP3, ISP1) ๊ฐ„์— ํŠธ๋ž˜ํ”ฝ์„ ๋ผ์šฐํŒ…ํ•ฉ๋‹ˆ๋‹ค. ISP2์— ๋Œ€ํ•œ ์ฑ„๋„์—๋Š” ์ •์  "ํšŒ์ƒ‰" ์ฃผ์†Œ, ISP3 - "ํฐ์ƒ‰", DHCP๋ฅผ ํ†ตํ•ด ์–ป์€ ISPXNUMX - PPPoE ์ธ์ฆ์ด ์žˆ๋Š” "ํฐ์ƒ‰"์ด ์žˆ์Šต๋‹ˆ๋‹ค. ์—ฐ๊ฒฐ ๋‹ค์ด์–ด๊ทธ๋žจ์€ ๊ทธ๋ฆผ์— ๋‚˜์™€ ์žˆ์Šต๋‹ˆ๋‹ค.

Mikrotik RouterOS์˜ ๋ฉ€ํ‹ฐ๋ฐด ๋ฐ ๋ผ์šฐํŒ…

์ž‘์—…์€ ์ฒด๊ณ„๋ฅผ ๊ธฐ๋ฐ˜์œผ๋กœ MTK ๋ผ์šฐํ„ฐ๋ฅผ ๊ตฌ์„ฑํ•˜์—ฌ ๋‹ค์Œ์„ ์ˆ˜ํ–‰ํ•˜๋Š” ๊ฒƒ์ž…๋‹ˆ๋‹ค.

  1. ๋ฐฑ์—… ๊ณต๊ธ‰์ž์—๊ฒŒ ์ž๋™ ์ „ํ™˜์„ ์ œ๊ณตํ•ฉ๋‹ˆ๋‹ค. ์ฃผ์š” ๊ณต๊ธ‰์ž๋Š” ISP2์ด๊ณ  ์ฒซ ๋ฒˆ์งธ ์˜ˆ๋น„๋Š” ISP1์ด๊ณ  ๋‘ ๋ฒˆ์งธ ์˜ˆ๋น„๋Š” ISP3์ž…๋‹ˆ๋‹ค.
  2. ISP1์„ ํ†ตํ•ด์„œ๋งŒ ์ธํ„ฐ๋„ท์— LAN1 ๋„คํŠธ์›Œํฌ ์•ก์„ธ์Šค๋ฅผ ๊ตฌ์„ฑํ•ฉ๋‹ˆ๋‹ค.
  3. ์ฃผ์†Œ ๋ชฉ๋ก์„ ๊ธฐ๋ฐ˜์œผ๋กœ ์„ ํƒํ•œ ๊ณต๊ธ‰์ž๋ฅผ ํ†ตํ•ด ๋กœ์ปฌ ๋„คํŠธ์›Œํฌ์—์„œ ์ธํ„ฐ๋„ท์œผ๋กœ ํŠธ๋ž˜ํ”ฝ์„ ๋ผ์šฐํŒ…ํ•˜๋Š” ๊ธฐ๋Šฅ์„ ์ œ๊ณตํ•ฉ๋‹ˆ๋‹ค.
  4. ๋กœ์ปฌ ๋„คํŠธ์›Œํฌ์—์„œ ์ธํ„ฐ๋„ท์œผ๋กœ ์„œ๋น„์Šค ๊ฒŒ์‹œ ๊ฐ€๋Šฅ์„ฑ ์ œ๊ณต(DSTNAT)
  5. ์ธํ„ฐ๋„ท์—์„œ ์ตœ์†Œํ•œ์˜ ์ถฉ๋ถ„ํ•œ ๋ณด์•ˆ์„ ์ œ๊ณตํ•˜๋„๋ก ๋ฐฉํ™”๋ฒฝ ํ•„ํ„ฐ๋ฅผ ์„ค์ •ํ•˜์‹ญ์‹œ์˜ค.
  6. ๋ผ์šฐํ„ฐ๋Š” ์„ ํƒํ•œ ์†Œ์Šค ์ฃผ์†Œ์— ๋”ฐ๋ผ ์„ธ ๊ณต๊ธ‰์ž ์ค‘ ํ•˜๋‚˜๋ฅผ ํ†ตํ•ด ์ž์ฒด ํŠธ๋ž˜ํ”ฝ์„ ๋ฐœํ–‰ํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.
  7. ์‘๋‹ต ํŒจํ‚ท์ด ์˜จ ์ฑ„๋„(LAN ํฌํ•จ)๋กœ ๋ผ์šฐํŒ…๋˜๋Š”์ง€ ํ™•์ธํ•˜์‹ญ์‹œ์˜ค.

๋น„๊ณ  ๋ฒ„์ „์—์„œ ๋ฒ„์ „์œผ๋กœ ๋ณ€๊ฒฝ๋˜๋Š” "์ฆ‰์‹œ ์‚ฌ์šฉ ๊ฐ€๋Šฅํ•œ" ์‹œ์ž‘ ๊ตฌ์„ฑ์— ๋†€๋ผ์›€์ด ์—†๋„๋ก ๋ผ์šฐํ„ฐ๋ฅผ "์ฒ˜์Œ๋ถ€ํ„ฐ" ๊ตฌ์„ฑํ•ฉ๋‹ˆ๋‹ค. ๋ณ€๊ฒฝ ์‚ฌํ•ญ์ด ์‹œ๊ฐ์ ์œผ๋กœ ํ‘œ์‹œ๋˜๋Š” ๊ตฌ์„ฑ ๋„๊ตฌ๋กœ Winbox๊ฐ€ ์„ ํƒ๋˜์—ˆ์Šต๋‹ˆ๋‹ค. ์„ค์ • ์ž์ฒด๋Š” Winbox ํ„ฐ๋ฏธ๋„์˜ ๋ช…๋ น์œผ๋กœ ์„ค์ •๋ฉ๋‹ˆ๋‹ค. ๊ตฌ์„ฑ์„ ์œ„ํ•œ ๋ฌผ๋ฆฌ์  ์—ฐ๊ฒฐ์€ Ether5 ์ธํ„ฐํŽ˜์ด์Šค์— ๋Œ€ํ•œ ์ง์ ‘ ์—ฐ๊ฒฐ์„ ํ†ตํ•ด ์ด๋ฃจ์–ด์ง‘๋‹ˆ๋‹ค.

๋‹ค์ค‘ ๋ฐด์ด ๋ฌด์—‡์ธ์ง€์— ๋Œ€ํ•œ ์•ฝ๊ฐ„์˜ ์ถ”๋ก , ๊ทธ๊ฒƒ์ด ๋ฌธ์ œ์ž…๋‹ˆ๊นŒ ์•„๋‹ˆ๋ฉด ์Œ๋ชจ ๋„คํŠธ์›Œํฌ๋ฅผ ์งœ๋Š” ๋ฐ ๊ตํ™œํ•œ ๋˜‘๋˜‘ํ•œ ์‚ฌ๋žŒ๋“ค์ž…๋‹ˆ๊นŒ?

ํ˜ธ๊ธฐ์‹ฌ ๋งŽ๊ณ  ์„ธ์‹ฌํ•œ ๊ด€๋ฆฌ์ž๊ฐ€ ์Šค์Šค๋กœ ์ด์™€ ์œ ์‚ฌํ•œ ๊ณ„ํš์„ ์„ธ์šฐ๋‹ค๊ฐ€ ๊ฐ‘์ž๊ธฐ ์ด๋ฏธ ์ •์ƒ์ ์œผ๋กœ ์ž‘๋™ํ•˜๊ณ  ์žˆ์Œ์„ ๊นจ๋‹ซ์Šต๋‹ˆ๋‹ค. ์˜ˆ, ์˜ˆ, ์ด ์ฃผ์ œ์— ๋Œ€ํ•œ ๋Œ€๋ถ€๋ถ„์˜ ๊ธฐ์‚ฌ๊ฐ€ ๊ฐ€๋“ํ•œ ์‚ฌ์šฉ์ž ์ง€์ • ๋ผ์šฐํŒ… ํ…Œ์ด๋ธ” ๋ฐ ๊ธฐํƒ€ ๋ผ์šฐํŒ… ๊ทœ์น™์ด ์—†์Šต๋‹ˆ๋‹ค. ์ ๊ฒ€ ํ•ด๋ณด์ž?

์ธํ„ฐํŽ˜์ด์Šค ๋ฐ ๊ธฐ๋ณธ ๊ฒŒ์ดํŠธ์›จ์ด์—์„œ ์ฃผ์†Œ ์ง€์ •์„ ๊ตฌ์„ฑํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๊นŒ? ์˜ˆ:

ISP1์—์„œ ์ฃผ์†Œ์™€ ๊ฒŒ์ดํŠธ์›จ์ด๋Š” ๊ฑฐ๋ฆฌ=2 ะธ ์ฒดํฌ-๊ฒŒ์ดํŠธ์›จ์ด=ping.
ISP2์—์„œ ๊ธฐ๋ณธ dhcp ํด๋ผ์ด์–ธํŠธ ์„ค์ • - ๊ทธ์— ๋”ฐ๋ผ ๊ฑฐ๋ฆฌ๋Š” XNUMX๊ณผ ๊ฐ™์Šต๋‹ˆ๋‹ค.
pppoe ํด๋ผ์ด์–ธํŠธ ์„ค์ •์˜ ISP3์—์„œ ์ถ”๊ฐ€-๊ธฐ๋ณธ ๊ฒฝ๋กœ=์˜ˆ ๋†“๋‹ค ๊ธฐ๋ณธ ๊ฒฝ๋กœ ๊ฑฐ๋ฆฌ=3.

์ข…๋ฃŒ ์‹œ NAT๋ฅผ ๋“ฑ๋กํ•˜๋Š” ๊ฒƒ์„ ์žŠ์ง€ ๋งˆ์‹ญ์‹œ์˜ค.

/ip ๋ฐฉํ™”๋ฒฝ nat ์ถ”๊ฐ€ ์ž‘์—…=๋งค์Šค์ปค๋ ˆ์ด๋“œ ์ฒด์ธ=srcnat out-interface-list=WAN

๊ทธ ๊ฒฐ๊ณผ ๊ตญ๋‚ด ์‚ฌ์ดํŠธ ์ด์šฉ์ž๋“ค์€ ๋ฉ”์ธ ISP2 ์ œ๊ณต์ž๋ฅผ ํ†ตํ•ด ๊ณ ์–‘์ด๋ฅผ ๋‹ค์šด๋กœ๋“œํ•˜๋Š” ์žฌ๋ฏธ๋ฅผ ๋Š๋ผ๊ณ  ์žˆ์œผ๋ฉฐ, ๋ฉ”์ปค๋‹ˆ์ฆ˜์„ ์ด์šฉํ•œ ์ฑ„๋„ ์˜ˆ์•ฝ์ด ์žˆ๋‹ค. ๊ฒŒ์ดํŠธ์›จ์ด ํ™•์ธ ์ฐธ๊ณ  1 ์ฐธ์กฐ

์ž‘์—…์˜ ํฌ์ธํŠธ 1์ด ๊ตฌํ˜„๋ฉ๋‹ˆ๋‹ค. ๋งˆํฌ๊ฐ€ ์žˆ๋Š” ๋ฉ€ํ‹ฐ๋ฐด์€ ์–ด๋””์— ์žˆ์Šต๋‹ˆ๊นŒ? ์•„๋‹ˆ์š”โ€ฆ

๋” ๋‚˜์•„๊ฐ€. ISP1์„ ํ†ตํ•ด LAN์—์„œ ํŠน์ • ํด๋ผ์ด์–ธํŠธ๋ฅผ ํ•ด์ œํ•ด์•ผ ํ•ฉ๋‹ˆ๋‹ค.

/ip ๋ฐฉํ™”๋ฒฝ mangle add action=route chain=prerouting dst-address-list=!BOGONS
passthrough=์˜ˆ route-dst=100.66.66.1 src-address-list=Via_ISP1
/ip ๋ฐฉํ™”๋ฒฝ mangle add action=route chain=prerouting dst-address-list=!BOGONS
ํ†ต๊ณผ=๊ฒฝ๋กœ ์—†์Œ-dst=100.66.66.1 src-์ฃผ์†Œ=192.168.88.0/24

์ž‘์—…์˜ ํ•ญ๋ชฉ 2์™€ 3์ด ๊ตฌํ˜„๋˜์—ˆ์Šต๋‹ˆ๋‹ค. ๋ผ๋ฒจ, ์Šคํƒฌํ”„, ๊ฒฝ๋กœ ๊ทœ์น™, ์–ด๋””์— ์žˆ์Šต๋‹ˆ๊นŒ?!

์ธํ„ฐ๋„ท์—์„œ ํด๋ผ์ด์–ธํŠธ๋ฅผ ์œ„ํ•ด 172.17.17.17 ์ฃผ์†Œ๋กœ ์„ ํ˜ธํ•˜๋Š” OpenVPN ์„œ๋ฒ„์— ๋Œ€ํ•œ ์•ก์„ธ์Šค ๊ถŒํ•œ์„ ๋ถ€์—ฌํ•ด์•ผ ํ•ฉ๋‹ˆ๊นŒ? ์ œ๋ฐœ:

/ip ํด๋ผ์šฐ๋“œ ์„ธํŠธ ddns-enabled=yes

ํ”ผ์–ด๋กœ์„œ ์šฐ๋ฆฌ๋Š” ํด๋ผ์ด์–ธํŠธ์—๊ฒŒ ๋‹ค์Œ๊ณผ ๊ฐ™์€ ์ถœ๋ ฅ ๊ฒฐ๊ณผ๋ฅผ ์ œ๊ณตํ•ฉ๋‹ˆ๋‹ค.:put [IP ํด๋ผ์šฐ๋“œ DNS ์ด๋ฆ„ ๊ฐ€์ ธ์˜ค๊ธฐ]"

์ธํ„ฐ๋„ท์—์„œ ํฌํŠธ ํฌ์›Œ๋”ฉ์„ ๋“ฑ๋กํ•ฉ๋‹ˆ๋‹ค.

/ip ๋ฐฉํ™”๋ฒฝ nat ์ถ”๊ฐ€ ์ž‘์—…=dst-nat chain=dstnat dst-port=1194
์ธ-์ธํ„ฐํŽ˜์ด์Šค-๋ชฉ๋ก=WAN ํ”„๋กœํ† ์ฝœ=udp to-addresses=172.17.17.17

ํ•ญ๋ชฉ 4๊ฐ€ ์ค€๋น„๋˜์—ˆ์Šต๋‹ˆ๋‹ค.

์šฐ๋ฆฌ๋Š” ์ง€์  5์— ๋Œ€ํ•œ ๋ฐฉํ™”๋ฒฝ ๋ฐ ๊ธฐํƒ€ ๋ณด์•ˆ์„ ์„ค์ •ํ•˜๋Š” ๋™์‹œ์— ์‚ฌ์šฉ์ž๋ฅผ ์œ„ํ•ด ๋ชจ๋“  ๊ฒƒ์ด ์ด๋ฏธ ์ž‘๋™ํ•˜๊ณ  ์ข‹์•„ํ•˜๋Š” ์Œ๋ฃŒ๊ฐ€ ๋‹ด๊ธด ์šฉ๊ธฐ์— ๋„๋‹ฌํ•˜๋Š” ๊ฒƒ์„ ๊ธฐ์˜๊ฒŒ ์ƒ๊ฐํ•ฉ๋‹ˆ๋‹ค ...
ใ…! ํ„ฐ๋„์€ ์žŠํ˜€์กŒ์Šต๋‹ˆ๋‹ค.

Google ๊ธฐ์‚ฌ์—์„œ ๊ตฌ์„ฑํ•œ l2tp-client๊ฐ€ ๊ฐ€์žฅ ์ข‹์•„ํ•˜๋Š” ๋„ค๋œ๋ž€๋“œ VDS๋กœ ๋ถ€์ƒํ–ˆ์Šต๋‹ˆ๊นŒ? ์˜ˆ.
IPsec์„ ์‚ฌ์šฉํ•˜๋Š” l2tp-server๊ฐ€ ์ฆ๊ฐ€ํ•˜๊ณ  IP ํด๋ผ์šฐ๋“œ(์œ„ ์ฐธ์กฐ)์—์„œ DNS ์ด๋ฆ„์œผ๋กœ ํด๋ผ์ด์–ธํŠธ๊ฐ€ ๋‹ฌ๋ผ๋ถ™์Šต๋‹ˆ๊นŒ? ์˜ˆ.
์˜์ž์— ๋“ฑ์„ ๊ธฐ๋Œ€๊ณ  ์Œ๋ฃŒ์ˆ˜๋ฅผ ํ™€์ง์ด๋ฉฐ ๊ฒŒ์œผ๋ฅด๊ฒŒ ์ž‘์—…์˜ 6๋ฒˆ๊ณผ 7๋ฒˆ ํ•ญ๋ชฉ์„ ๊ณ ๋ คํ•ฉ๋‹ˆ๋‹ค. ์šฐ๋ฆฌ๋Š” ์ƒ๊ฐํ•ฉ๋‹ˆ๋‹ค-ํ•„์š”ํ•ฉ๋‹ˆ๊นŒ? ๋˜‘๊ฐ™์ด ์ž‘๋™ํ•ฉ๋‹ˆ๋‹ค (c) ... ๊ทธ๋ž˜์„œ ์—ฌ์ „ํžˆ ํ•„์š”ํ•˜์ง€ ์•Š๋‹ค๋ฉด ๊ทธ๊ฒŒ ๋‹ค์ž…๋‹ˆ๋‹ค. ๋ฉ€ํ‹ฐ๋ฐด ๊ตฌํ˜„.

๋ฉ€ํ‹ฐ๋ฐด์ด๋ž€? ์ด๊ฒƒ์€ ์—ฌ๋Ÿฌ ์ธํ„ฐ๋„ท ์ฑ„๋„์„ ํ•˜๋‚˜์˜ ๋ผ์šฐํ„ฐ์— ์—ฐ๊ฒฐํ•˜๋Š” ๊ฒƒ์ž…๋‹ˆ๋‹ค.

์˜์‹ฌ์Šค๋Ÿฌ์šด ์ ์šฉ ๊ฐ€๋Šฅ์„ฑ์„ ๊ณผ์‹œํ•˜๋Š” ๊ฒƒ ์™ธ์— ๋ฌด์—‡์ด ์žˆ์„ ์ˆ˜ ์žˆ๊ธฐ ๋•Œ๋ฌธ์— ๊ธฐ์‚ฌ๋ฅผ ๋” ์ฝ์„ ํ•„์š”๊ฐ€ ์—†์Šต๋‹ˆ๋‹ค.

๋‚จ์€ ์‚ฌ๋žŒ๋“ค, ์ž‘์—…์˜ 6๋ฒˆ๊ณผ 7๋ฒˆ ํ•ญ๋ชฉ์— ๊ด€์‹ฌ์ด ์žˆ๊ณ  ์™„๋ฒฝ์ฃผ์˜์˜ ๊ฐ„์ง€๋Ÿฌ์›€๋„ ๋Š๋ผ๋Š” ์‚ฌ๋žŒ๋“ค์„ ์œ„ํ•ด ์šฐ๋ฆฌ๋Š” ๋” ๊นŠ์ด ์ž ์ˆ˜ํ•ฉ๋‹ˆ๋‹ค.

๋ฉ€ํ‹ฐ๋ฐด ๊ตฌํ˜„์˜ ๊ฐ€์žฅ ์ค‘์š”ํ•œ ์ž‘์—…์€ ์˜ฌ๋ฐ”๋ฅธ ํŠธ๋ž˜ํ”ฝ ๋ผ์šฐํŒ…์ž…๋‹ˆ๋‹ค. ์ฆ‰ : ์–ด๋Š (๋˜๋Š” ์–ด๋Š) ์ฐธ์กฐ์— ๊ด€๊ณ„์—†์ด. ์ฐธ๊ณ  3 ISP์˜ ์ฑ„๋„์€ ๋ผ์šฐํ„ฐ์˜ ๊ธฐ๋ณธ ๊ฒฝ๋กœ๋ฅผ ์‚ดํŽด๋ณด๊ณ  ํŒจํ‚ท์ด ์˜จ ์ •ํ™•ํ•œ ์ฑ„๋„์— ๋Œ€ํ•œ ์‘๋‹ต์„ ๋ฐ˜ํ™˜ํ•ด์•ผ ํ•ฉ๋‹ˆ๋‹ค. ๊ณผ์ œ๋Š” ๋ถ„๋ช…ํ•ฉ๋‹ˆ๋‹ค. ๋ฌธ์ œ๋Š” ์–ด๋””์— ์žˆ์Šต๋‹ˆ๊นŒ? ์‹ค์ œ๋กœ ๊ฐ„๋‹จํ•œ ๋กœ์ปฌ ๋„คํŠธ์›Œํฌ์—์„œ ์ž‘์—…์€ ๋™์ผํ•˜์ง€๋งŒ ์•„๋ฌด๋„ ์ถ”๊ฐ€ ์„ค์ •์— ์‹ ๊ฒฝ ์“ฐ์ง€ ์•Š๊ณ  ๋ฌธ์ œ๋ฅผ ๋Š๋ผ์ง€ ์•Š์Šต๋‹ˆ๋‹ค. ์ฐจ์ด์ ์€ ์ธํ„ฐ๋„ท์˜ ๋ชจ๋“  ๋ผ์šฐํŒ… ๊ฐ€๋Šฅํ•œ ๋…ธ๋“œ๋Š” ๋‹จ์ˆœํ•œ LAN์—์„œ์™€ ๊ฐ™์ด ์—„๊ฒฉํ•˜๊ฒŒ ํŠน์ •ํ•œ ์ฑ„๋„์ด ์•„๋‹ˆ๋ผ ๊ฐ ์ฑ„๋„์„ ํ†ตํ•ด ์•ก์„ธ์Šคํ•  ์ˆ˜ ์žˆ๋‹ค๋Š” ๊ฒƒ์ž…๋‹ˆ๋‹ค. ๊ทธ๋ฆฌ๊ณ  "๋ฌธ์ œ"๋Š” ISP3์˜ IP ์ฃผ์†Œ์— ๋Œ€ํ•œ ์š”์ฒญ์ด ์šฐ๋ฆฌ์—๊ฒŒ ์˜จ ๊ฒฝ์šฐ ๊ธฐ๋ณธ ๊ฒŒ์ดํŠธ์›จ์ด๊ฐ€ ISP2 ์ฑ„๋„๋กœ ํ–ฅํ•˜๊ธฐ ๋•Œ๋ฌธ์— ์‘๋‹ต์ด ISPXNUMX ์ฑ„๋„์„ ํ†ตํ•ด ์ „๋‹ฌ๋œ๋‹ค๋Š” ๊ฒƒ์ž…๋‹ˆ๋‹ค. ๋ถ€์ •ํ™•ํ•œ ๊ฒƒ์œผ๋กœ ์ œ๊ณต์ž๊ฐ€ ๋– ๋‚˜๊ณ  ํ๊ธฐํ•ฉ๋‹ˆ๋‹ค. ๋ฌธ์ œ๊ฐ€ ํ™•์ธ๋˜์—ˆ์Šต๋‹ˆ๋‹ค. ๊ทธ๊ฒƒ์„ ํ•ด๊ฒฐํ•˜๋Š” ๋ฐฉ๋ฒ•?

์†”๋ฃจ์…˜์€ ์„ธ ๋‹จ๊ณ„๋กœ ๋‚˜๋‰ฉ๋‹ˆ๋‹ค.

  1. ์‚ฌ์ „ ์„ค์ •. ์ด ๋‹จ๊ณ„์—์„œ ๋กœ์ปฌ ๋„คํŠธ์›Œํฌ, ๋ฐฉํ™”๋ฒฝ, ์ฃผ์†Œ ๋ชฉ๋ก, ํ—ค์–ดํ•€ NAT ๋“ฑ ๋ผ์šฐํ„ฐ์˜ ๊ธฐ๋ณธ ์„ค์ •์ด ์„ค์ •๋ฉ๋‹ˆ๋‹ค.
  2. ๋ฉ€ํ‹ฐ๋ฐด. ์ด ๋‹จ๊ณ„์—์„œ ํ•„์š”ํ•œ ์—ฐ๊ฒฐ์ด ํ‘œ์‹œ๋˜๊ณ  ๋ผ์šฐํŒ… ํ…Œ์ด๋ธ”๋กœ ์ •๋ ฌ๋ฉ๋‹ˆ๋‹ค.
  3. ISP์— ์—ฐ๊ฒฐ ์ค‘์ž…๋‹ˆ๋‹ค. ์ด ๋‹จ๊ณ„์—์„œ ์ธํ„ฐ๋„ท ์—ฐ๊ฒฐ์„ ์ œ๊ณตํ•˜๋Š” ์ธํ„ฐํŽ˜์ด์Šค๊ฐ€ ๊ตฌ์„ฑ๋˜๊ณ  ๋ผ์šฐํŒ… ๋ฐ ์ธํ„ฐ๋„ท ์ฑ„๋„ ์˜ˆ์•ฝ ๋ฉ”์ปค๋‹ˆ์ฆ˜์ด ํ™œ์„ฑํ™”๋ฉ๋‹ˆ๋‹ค.

1. ์‚ฌ์ „ ์„ค์ •

1.1. ๋‹ค์Œ ๋ช…๋ น์„ ์‚ฌ์šฉํ•˜์—ฌ ๋ผ์šฐํ„ฐ ๊ตฌ์„ฑ์„ ์ง€์›๋‹ˆ๋‹ค.

/system reset-configuration skip-backup=yes no-defaults=yes

์— ๋™์˜ํ•ฉ๋‹ˆ๋‹ค "์œ„ํ—˜ํ•œ! ์žฌ์„ค์ •ํ•˜์‹œ๊ฒ ์Šต๋‹ˆ๊นŒ? [์˜ˆ/์•„๋‹ˆ์š”]:" ์žฌ๋ถ€ํŒ… ํ›„ MAC์„ ํ†ตํ•ด Winbox์— ์—ฐ๊ฒฐํ•ฉ๋‹ˆ๋‹ค. ์ด ๋‹จ๊ณ„์—์„œ ๊ตฌ์„ฑ ๋ฐ ์‚ฌ์šฉ์ž ๊ธฐ๋ฐ˜์ด ์ง€์›Œ์ง‘๋‹ˆ๋‹ค.

1.2. ์ƒˆ ์‚ฌ์šฉ์ž ๋งŒ๋“ค๊ธฐ:

/user add group=full name=knight password=ultrasecret comment=โ€Not horseโ€

๊ทธ ์•„๋ž˜์— ๋กœ๊ทธ์ธํ•˜๊ณ  ๊ธฐ๋ณธ ํ•ญ๋ชฉ์„ ์‚ญ์ œํ•˜์‹ญ์‹œ์˜ค.

/user remove admin

๋น„๊ณ  ์ €์ž๊ฐ€ ๋” ์•ˆ์ „ํ•˜๋‹ค๊ณ  ์ƒ๊ฐํ•˜๊ณ  ์‚ฌ์šฉ์„ ๊ถŒ์žฅํ•˜๋Š” ๊ฒƒ์€ ๊ธฐ๋ณธ ์‚ฌ์šฉ์ž๋ฅผ ์ œ๊ฑฐํ•˜๊ณ  ๋น„ํ™œ์„ฑํ™”ํ•˜์ง€ ์•Š๋Š” ๊ฒƒ์ž…๋‹ˆ๋‹ค.

1.3. ๋ฐฉํ™”๋ฒฝ, ๊ฒ€์ƒ‰ ์„ค์ • ๋ฐ ๊ธฐํƒ€ MAC ์„œ๋ฒ„์—์„œ ํŽธ๋ฆฌํ•˜๊ฒŒ ์ž‘๋™ํ•  ์ˆ˜ ์žˆ๋„๋ก ๊ธฐ๋ณธ ์ธํ„ฐํŽ˜์ด์Šค ๋ชฉ๋ก์„ ๋งŒ๋“ญ๋‹ˆ๋‹ค.

/interface list add name=WAN comment="For Internet"
/interface list add name=LAN comment="For Local Area"

์ฃผ์„์ด ์žˆ๋Š” ์„œ๋ช… ์ธํ„ฐํŽ˜์ด์Šค

/interface ethernet set ether1 comment="to ISP1"
/interface ethernet set ether2 comment="to ISP2"
/interface ethernet set ether3 comment="to ISP3"
/interface ethernet set ether4 comment="to LAN1"
/interface ethernet set ether5 comment="to LAN2"

์ธํ„ฐํŽ˜์ด์Šค ๋ชฉ๋ก์„ ์ฑ„์šฐ์‹ญ์‹œ์˜ค.

/interface list member add interface=ether1 list=WAN comment=ISP1
/interface list member add interface=ether2 list=WAN comment=ISP2 
/interface list member add interface=ether3 list=WAN comment="to ISP3"
/interface list member add interface=ether4 list=LAN  comment="LAN1"
/interface list member add interface=ether5 list=LAN  comment="LAN2"

๋น„๊ณ  ์ดํ•ดํ•  ์ˆ˜ ์žˆ๋Š” ์ฃผ์„์„ ์ž‘์„ฑํ•˜๋Š” ๊ฒƒ์€ ์—ฌ๊ธฐ์— ์‹œ๊ฐ„์„ ํˆฌ์žํ•  ๊ฐ€์น˜๊ฐ€ ์žˆ์œผ๋ฉฐ ๋ฌธ์ œ ํ•ด๊ฒฐ ๋ฐ ๊ตฌ์„ฑ ์ดํ•ด๋ฅผ ํฌ๊ฒŒ ์ด‰์ง„ํ•ฉ๋‹ˆ๋‹ค.

์ €์ž๋Š” ip ํ”„๋กœํ† ์ฝœ์ด ํ†ต๊ณผํ•˜์ง€ ์•Š๋Š”๋‹ค๋Š” ์‚ฌ์‹ค์—๋„ ๋ถˆ๊ตฌํ•˜๊ณ  ๋ณด์•ˆ์ƒ์˜ ์ด์œ ๋กœ "WAN" ์ธํ„ฐํŽ˜์ด์Šค ๋ชฉ๋ก์— ether3 ์ธํ„ฐํŽ˜์ด์Šค๋ฅผ ์ถ”๊ฐ€ํ•˜๋Š” ๊ฒƒ์ด ํ•„์š”ํ•˜๋‹ค๊ณ  ์ƒ๊ฐํ•ฉ๋‹ˆ๋‹ค.

PPP ์ธํ„ฐํŽ˜์ด์Šค๊ฐ€ ether3์—์„œ ์ƒ์„ฑ๋œ ํ›„ "WAN" ์ธํ„ฐํŽ˜์ด์Šค ๋ชฉ๋ก์—๋„ ์ถ”๊ฐ€ํ•ด์•ผ ํ•จ์„ ์žŠ์ง€ ๋งˆ์‹ญ์‹œ์˜ค.

1.4. ์šฐ๋ฆฌ๋Š” ๋ผ์šฐํ„ฐ๋ฅผ MAC์„ ํ†ตํ•ด ๊ณต๊ธ‰์ž ๋„คํŠธ์›Œํฌ์˜ ์ด์›ƒ ๊ฐ์ง€ ๋ฐ ์ œ์–ด๋กœ๋ถ€ํ„ฐ ์ˆจ๊น๋‹ˆ๋‹ค.

/ip neighbor discovery-settings set discover-interface-list=!WAN
/tool mac-server set allowed-interface-list=LAN
/tool mac-server mac-winbox set allowed-interface-list=LAN

1.5. ๋ผ์šฐํ„ฐ๋ฅผ ๋ณดํ˜ธํ•˜๊ธฐ ์œ„ํ•ด ์ตœ์†Œํ•œ์˜ ์ถฉ๋ถ„ํ•œ ๋ฐฉํ™”๋ฒฝ ํ•„ํ„ฐ ๊ทœ์น™ ์ง‘ํ•ฉ์„ ์ƒ์„ฑํ•ฉ๋‹ˆ๋‹ค.

/ip firewall filter add action=accept chain=input comment="Related Established Untracked Allow" 
connection-state=established,related,untracked

(์ด ๊ทœ์น™์€ ์—ฐ๊ฒฐ๋œ ๋„คํŠธ์›Œํฌ์™€ ๋ผ์šฐํ„ฐ ์ž์ฒด์—์„œ ์‹œ์ž‘๋˜๋Š” ์„ค์ • ๋ฐ ๊ด€๋ จ ์—ฐ๊ฒฐ์— ๋Œ€ํ•œ ๊ถŒํ•œ์„ ์ œ๊ณตํ•ฉ๋‹ˆ๋‹ค.)

/ip firewall filter add action=accept chain=input comment="ICMP from ALL" protocol=icmp

(ping๋ฟ๋งŒ ์•„๋‹ˆ๋ผ ping. ๋ชจ๋“  icmp๊ฐ€ ํ—ˆ์šฉ๋ฉ๋‹ˆ๋‹ค. MTU ๋ฌธ์ œ๋ฅผ ์ฐพ๋Š” ๋ฐ ๋งค์šฐ ์œ ์šฉํ•ฉ๋‹ˆ๋‹ค)

/ip firewall filter add action=drop chain=input comment="All other WAN Drop" in-interface-list=WAN

(์ž…๋ ฅ ์ฒด์ธ์„ ๋‹ซ๋Š” ๊ทœ์น™์€ ์ธํ„ฐ๋„ท์—์„œ ์˜ค๋Š” ๋ชจ๋“  ๊ฒƒ์„ ๊ธˆ์ง€ํ•ฉ๋‹ˆ๋‹ค)

/ip firewall filter add action=accept chain=forward 
comment="Established, Related, Untracked allow" 
connection-state=established,related,untracked

(๊ทœ์น™์€ ๋ผ์šฐํ„ฐ๋ฅผ ํ†ต๊ณผํ•˜๋Š” ํ™•๋ฆฝ๋œ ๊ด€๋ จ ์—ฐ๊ฒฐ์„ ํ—ˆ์šฉํ•จ)

/ip firewall filter add action=drop chain=forward comment="Invalid drop" connection-state=invalid

(๊ทœ์น™์€ ๋ผ์šฐํ„ฐ๋ฅผ ํ†ต๊ณผํ•˜๋Š” connection-state=invalid ํ†ต๊ณผ๋กœ ์—ฐ๊ฒฐ์„ ์žฌ์„ค์ •ํ•ฉ๋‹ˆ๋‹ค. Mikrotik์—์„œ ๊ฐ•๋ ฅํžˆ ๊ถŒ์žฅํ•˜์ง€๋งŒ ์ผ๋ถ€ ๋“œ๋ฌธ ๊ฒฝ์šฐ ์œ ์šฉํ•œ ํŠธ๋ž˜ํ”ฝ์„ ์ฐจ๋‹จํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.)

/ip firewall filter add action=drop chain=forward comment="Drop all from WAN not DSTNATed"  
connection-nat-state=!dstnat connection-state=new in-interface-list=WAN

(๊ทœ์น™์€ ์ธํ„ฐ๋„ท์—์„œ ์˜ค๋Š” ํŒจํ‚ท์ด dstnat ์ ˆ์ฐจ๋ฅผ ํ†ต๊ณผํ•˜์ง€ ์•Š๊ณ  ๋ผ์šฐํ„ฐ๋ฅผ ํ†ต๊ณผํ•˜๋Š” ๊ฒƒ์„ ๊ธˆ์ง€ํ•ฉ๋‹ˆ๋‹ค. ์ด๊ฒƒ์€ ์™ธ๋ถ€ ๋„คํŠธ์›Œํฌ์™€ ๋™์ผํ•œ ๋ธŒ๋กœ๋“œ์บ์ŠคํŠธ ๋„๋ฉ”์ธ์— ์žˆ๋Š” ์นจ์ž…์ž๋กœ๋ถ€ํ„ฐ ๋กœ์ปฌ ๋„คํŠธ์›Œํฌ๋ฅผ ๋ณดํ˜ธํ•˜๊ณ  ์™ธ๋ถ€ IP๋ฅผ ๋”ฐ๋ผ์„œ ๋กœ์ปฌ ๋„คํŠธ์›Œํฌ๋ฅผ "ํƒ์ƒ‰"ํ•˜๋ ค๊ณ  ํ•ฉ๋‹ˆ๋‹ค.)

๋น„๊ณ  ๋„คํŠธ์›Œํฌ LAN1๊ณผ LAN2๊ฐ€ ์‹ ๋ขฐ๋˜๊ณ  ์ด๋“ค ์‚ฌ์ด์˜ ํŠธ๋ž˜ํ”ฝ์ด ํ•„ํ„ฐ๋ง๋˜์ง€ ์•Š๋Š”๋‹ค๊ณ  ๊ฐ€์ •ํ•ฉ๋‹ˆ๋‹ค.

1.6. ๋ผ์šฐํŒ…ํ•  ์ˆ˜ ์—†๋Š” ๋„คํŠธ์›Œํฌ ๋ชฉ๋ก์œผ๋กœ ๋ชฉ๋ก์„ ๋งŒ๋“ญ๋‹ˆ๋‹ค.

/ip firewall address-list
add address=0.0.0.0/8 comment=""This" Network" list=BOGONS
add address=10.0.0.0/8 comment="Private-Use Networks" list=BOGONS
add address=100.64.0.0/10 comment="Shared Address Space. RFC 6598" list=BOGONS
add address=127.0.0.0/8 comment=Loopback list=BOGONS
add address=169.254.0.0/16 comment="Link Local" list=BOGONS
add address=172.16.0.0/12 comment="Private-Use Networks" list=BOGONS
add address=192.0.0.0/24 comment="IETF Protocol Assignments" list=BOGONS
add address=192.0.2.0/24 comment=TEST-NET-1 list=BOGONS
add address=192.168.0.0/16 comment="Private-Use Networks" list=BOGONS
add address=198.18.0.0/15 comment="Network Interconnect Device Benchmark Testing"
 list=BOGONS
add address=198.51.100.0/24 comment=TEST-NET-2 list=BOGONS
add address=203.0.113.0/24 comment=TEST-NET-3 list=BOGONS
add address=224.0.0.0/4 comment=Multicast list=BOGONS
add address=192.88.99.0/24 comment="6to4 Relay Anycast" list=BOGONS
add address=240.0.0.0/4 comment="Reserved for Future Use" list=BOGONS
add address=255.255.255.255 comment="Limited Broadcast" list=BOGONS

(์ด๋Š” ์ธํ„ฐ๋„ท์œผ๋กœ ๋ผ์šฐํŒ…ํ•  ์ˆ˜ ์—†๋Š” ์ฃผ์†Œ ๋ฐ ๋„คํŠธ์›Œํฌ ๋ชฉ๋ก์ด๋ฉฐ ๊ทธ์— ๋”ฐ๋ผ ๋”ฐ๋ฅผ ๊ฒƒ์ž…๋‹ˆ๋‹ค.)

๋น„๊ณ  ๋ชฉ๋ก์€ ๋ณ€๊ฒฝ๋  ์ˆ˜ ์žˆ์œผ๋ฏ€๋กœ ์ •๊ธฐ์ ์œผ๋กœ ๊ด€๋ จ์„ฑ์„ ํ™•์ธํ•˜๋Š” ๊ฒƒ์ด ์ข‹์Šต๋‹ˆ๋‹ค.

1.7. ๋ผ์šฐํ„ฐ ์ž์ฒด์— ๋Œ€ํ•œ DNS ์„ค์ •:

/ip dns set servers=1.1.1.1,8.8.8.8

๋น„๊ณ  ํ˜„์žฌ ๋ฒ„์ „์˜ ROS์—์„œ๋Š” ๋™์  ์„œ๋ฒ„๊ฐ€ ์ •์  ์„œ๋ฒ„๋ณด๋‹ค ์šฐ์„ ํ•ฉ๋‹ˆ๋‹ค. ์ด๋ฆ„ ํ™•์ธ ์š”์ฒญ์€ ๋ชฉ๋ก์— ์žˆ๋Š” ์ˆœ์„œ๋Œ€๋กœ ์ฒซ ๋ฒˆ์งธ ์„œ๋ฒ„๋กœ ์ „์†ก๋ฉ๋‹ˆ๋‹ค. ๋‹ค์Œ ์„œ๋ฒ„๋กœ์˜ ์ „ํ™˜์€ ํ˜„์žฌ ์„œ๋ฒ„๋ฅผ ์‚ฌ์šฉํ•  ์ˆ˜ ์—†์„ ๋•Œ ์ˆ˜ํ–‰๋ฉ๋‹ˆ๋‹ค. ์ œํ•œ ์‹œ๊ฐ„์ด 5์ดˆ ์ด์ƒ์ž…๋‹ˆ๋‹ค. "๋–จ์–ด์ง„ ์„œ๋ฒ„"๊ฐ€ ๋‹ค์‹œ ์‹œ์ž‘๋  ๋•Œ ๋‹ค์‹œ ๋Œ์•„๊ฐ€๋Š” ๊ฒƒ์€ ์ž๋™์œผ๋กœ ๋ฐœ์ƒํ•˜์ง€ ์•Š์Šต๋‹ˆ๋‹ค. ์ด ์•Œ๊ณ ๋ฆฌ์ฆ˜๊ณผ ๋ฉ€ํ‹ฐ๋ฐด์˜ ์กด์žฌ๋ฅผ ๊ณ ๋ คํ•  ๋•Œ ์ž‘์„ฑ์ž๋Š” ๊ณต๊ธ‰์ž๊ฐ€ ์ œ๊ณตํ•˜๋Š” ์„œ๋ฒ„๋ฅผ ์‚ฌ์šฉํ•˜์ง€ ์•Š์„ ๊ฒƒ์„ ๊ถŒ์žฅํ•ฉ๋‹ˆ๋‹ค.

1.8. ๋กœ์ปฌ ๋„คํŠธ์›Œํฌ๋ฅผ ์„ค์ •ํ•ฉ๋‹ˆ๋‹ค.
1.8.1. LAN ์ธํ„ฐํŽ˜์ด์Šค์—์„œ ๊ณ ์ • IP ์ฃผ์†Œ๋ฅผ ๊ตฌ์„ฑํ•ฉ๋‹ˆ๋‹ค.

/ip address add interface=ether4 address=192.168.88.254/24 comment="LAN1 IP"
/ip address add interface=ether5 address=172.16.1.0/23 comment="LAN2 IP"

1.8.2. ๊ธฐ๋ณธ ๋ผ์šฐํŒ… ํ…Œ์ด๋ธ”์„ ํ†ตํ•ด ๋กœ์ปฌ ๋„คํŠธ์›Œํฌ์— ๋Œ€ํ•œ ๊ฒฝ๋กœ ๊ทœ์น™์„ ์„ค์ •ํ•ฉ๋‹ˆ๋‹ค.

/ip route rule add dst-address=192.168.88.0/24 table=main comment=โ€to LAN1โ€
/ip route rule add dst-address=172.16.0.0/23 table=main comment="to LAN2"

๋น„๊ณ  ์ด๊ฒƒ์€ ๊ธฐ๋ณธ ๊ฒฝ๋กœ๋ฅผ ๊ฑฐ์น˜์ง€ ์•Š๋Š” ๋ผ์šฐํ„ฐ ์ธํ„ฐํŽ˜์ด์Šค์˜ ์™ธ๋ถ€ IP ์ฃผ์†Œ ์†Œ์Šค๋กœ LAN ์ฃผ์†Œ์— ์•ก์„ธ์Šคํ•˜๋Š” ๋น ๋ฅด๊ณ  ์‰ฌ์šด ๋ฐฉ๋ฒ• ์ค‘ ํ•˜๋‚˜์ž…๋‹ˆ๋‹ค.

1.8.3. LAN1 ๋ฐ LAN2์šฉ ํ—ค์–ดํ•€ NAT ํ™œ์„ฑํ™”:

/ip firewall nat add action=src-nat chain=srcnat comment="Hairpin to LAN1" 
out-interface=ether4 src-address=192.168.88.0/24 to-addresses=192.168.88.254
/ip firewall nat add action=src-nat chain=srcnat comment="Hairpin to LAN2" 
out-interface=ether5 src-address=172.16.0.0/23 to-addresses=172.16.1.0

๋น„๊ณ  ์ด๋ฅผ ํ†ตํ•ด ๋„คํŠธ์›Œํฌ ๋‚ด๋ถ€์— ์žˆ๋Š” ๋™์•ˆ ์™ธ๋ถ€ IP๋ฅผ ํ†ตํ•ด ๋ฆฌ์†Œ์Šค(dstnat)์— ์•ก์„ธ์Šคํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

2. ์‚ฌ์‹ค ์•„์ฃผ ์ •ํ™•ํ•œ ๋ฉ€ํ‹ฐ๋ฐด ๊ตฌํ˜„

"์š”์ฒญํ•œ ์œ„์น˜์— ์‘๋‹ต"ํ•˜๋Š” ๋ฌธ์ œ๋ฅผ ํ•ด๊ฒฐํ•˜๊ธฐ ์œ„ํ•ด ๋‘ ๊ฐ€์ง€ ROS ๋„๊ตฌ๋ฅผ ์‚ฌ์šฉํ•ฉ๋‹ˆ๋‹ค. ์—ฐ๊ฒฐ ๋งˆํฌ ะธ ๋ผ์šฐํŒ… ๋งˆํฌ. ์—ฐ๊ฒฐ ๋งˆํฌ ์›ํ•˜๋Š” ์—ฐ๊ฒฐ์„ ํ‘œ์‹œํ•œ ๋‹ค์Œ ์ด ๋ ˆ์ด๋ธ”์„ ์ ์šฉ ์กฐ๊ฑด์œผ๋กœ ์‚ฌ์šฉํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ๋ผ์šฐํŒ… ๋งˆํฌ. ๊ทธ๋ฆฌ๊ณ  ์ด๋ฏธ ๋ผ์šฐํŒ… ๋งˆํฌ ์—์„œ ๊ทผ๋ฌด ๊ฐ€๋Šฅ IP ๊ฒฝ๋กœ ะธ ๊ฒฝ๋กœ ๊ทœ์น™. ์šฐ๋ฆฌ๋Š” ๋„๊ตฌ๋ฅผ ์•Œ์•„๋ƒˆ์œผ๋ฏ€๋กœ ์ด์ œ ํ‘œ์‹œํ•  ์—ฐ๊ฒฐ์„ ๊ฒฐ์ •ํ•ด์•ผ ํ•ฉ๋‹ˆ๋‹ค. ํ•œ ๋ฒˆ, ์ •ํ™•ํžˆ ํ‘œ์‹œํ•  ์œ„์น˜๋Š” ๋‘ ๊ฐœ์ž…๋‹ˆ๋‹ค.

์ฒซ ๋ฒˆ์งธ๋Š” ๋ชจ๋“  ๊ฒƒ์ด ๊ฐ„๋‹จํ•ฉ๋‹ˆ๋‹ค. ์ ์ ˆํ•œ ์ฑ„๋„์„ ํ†ตํ•ด ์ธํ„ฐ๋„ท์—์„œ ๋ผ์šฐํ„ฐ๋กœ ์˜ค๋Š” ๋ชจ๋“  ์—ฐ๊ฒฐ์„ ํ‘œ์‹œํ•ด์•ผ ํ•ฉ๋‹ˆ๋‹ค. ์šฐ๋ฆฌ์˜ ๊ฒฝ์šฐ์—๋Š” "conn_isp1", "conn_isp2" ๋ฐ "conn_isp3"์˜ ์„ธ ๊ฐ€์ง€ ๋ ˆ์ด๋ธ”(์ฑ„๋„ ์ˆ˜ ๊ธฐ์ค€)์ด ๋ฉ๋‹ˆ๋‹ค.

๋‘ ๋ฒˆ์งธ์˜ ๋‰˜์•™์Šค๋Š” ๋“ค์–ด์˜ค๋Š” ์—ฐ๊ฒฐ์ด ํ†ต๊ณผ ๋ฐ ๋ผ์šฐํ„ฐ ์ž์ฒด๋ฅผ ์œ„ํ•œ ์—ฐ๊ฒฐ์˜ ๋‘ ๊ฐ€์ง€ ์œ ํ˜•์ด๋ผ๋Š” ๊ฒƒ์ž…๋‹ˆ๋‹ค. ์—ฐ๊ฒฐ ํ‘œ์‹œ ๋ฉ”์ปค๋‹ˆ์ฆ˜์€ ํ…Œ์ด๋ธ”์—์„œ ์ž‘๋™ํ•ฉ๋‹ˆ๋‹ค. ์••์ฐฉ ๋กค๋Ÿฌ. mikrotik-trainings.com ๋ฆฌ์†Œ์Šค(๊ด‘๊ณ  ์•„๋‹˜)์˜ ์ „๋ฌธ๊ฐ€๊ฐ€ ์นœ์ ˆํ•˜๊ฒŒ ํŽธ์ง‘ํ•œ ๋‹จ์ˆœํ™”๋œ ๋‹ค์ด์–ด๊ทธ๋žจ์—์„œ ํŒจํ‚ค์ง€์˜ ์›€์ง์ž„์„ ๊ณ ๋ คํ•˜์‹ญ์‹œ์˜ค.

Mikrotik RouterOS์˜ ๋ฉ€ํ‹ฐ๋ฐด ๋ฐ ๋ผ์šฐํŒ…

ํ™”์‚ดํ‘œ๋ฅผ ๋”ฐ๋ผ "์— ๋„์ฐฉํ•˜๋Š” ํŒจํ‚ท์„ ๋ณผ ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.์ž…๋ ฅ ์ธํ„ฐํŽ˜์ด์Šค", ์ฒด์ธ์„ ํ†ต๊ณผํ•ฉ๋‹ˆ๋‹ค. "์‚ฌ์ „ ๋ผ์šฐํŒ…โ€ ๊ทธ๋Ÿฐ ๋‹ค์Œ์—์•ผ ๋ธ”๋ก์—์„œ ๋Œ€์ค‘ ๊ตํ†ต๊ณผ ์ง€์—ญ์œผ๋กœ ๋‚˜๋‰ฉ๋‹ˆ๋‹ค.๋ผ์šฐํŒ… ๊ฒฐ์ •". ๋”ฐ๋ผ์„œ ํ•œ ๋Œ๋กœ ๋‘ ๋งˆ๋ฆฌ์˜ ์ƒˆ๋ฅผ ์ฃฝ์ด๋ ค๋ฉด ์—ฐ๊ฒฐ ๋งˆํฌ ํ…Œ์ด๋ธ”์— ๋งน๊ธ€ ํ”„๋ฆฌ๋ผ์šฐํŒ… ์‡ ์‚ฌ์Šฌ ์‚ฌ์ „ ๋ผ์šฐํŒ….

์ฐธ๊ณ  :. ROS์—์„œ "Routing mark" ๋ ˆ์ด๋ธ”์€ Ip/Routes/Rules ์„น์…˜์—์„œ "Table"๋กœ, ๋‹ค๋ฅธ ์„น์…˜์—์„œ๋Š” "Routing Mark"๋กœ ๋‚˜์—ด๋ฉ๋‹ˆ๋‹ค. ์ด๊ฒƒ์€ ์ดํ•ด์— ์•ฝ๊ฐ„์˜ ํ˜ผ๋ž€์„ ์•ผ๊ธฐํ•  ์ˆ˜ ์žˆ์ง€๋งŒ ์‚ฌ์‹ค ์ด๊ฒƒ์€ ๋™์ผํ•œ ๊ฒƒ์ด๋ฉฐ Linux์˜ iproute2์— ์žˆ๋Š” rt_tables์™€ ์œ ์‚ฌํ•ฉ๋‹ˆ๋‹ค.

2.1. ๊ฐ ๊ณต๊ธ‰์ž๋กœ๋ถ€ํ„ฐ ๋“ค์–ด์˜ค๋Š” ์—ฐ๊ฒฐ์„ ํ‘œ์‹œํ•ฉ๋‹ˆ๋‹ค.

/ip firewall mangle add action=mark-connection chain=prerouting 
comment="Connmark in from ISP1" connection-mark=no-mark in-interface=ether1  new-connection-mark=conn_isp1 passthrough=no

/ip firewall mangle add action=mark-connection chain=prerouting 
comment="Connmark in from ISP2" connection-mark=no-mark in-interface=ether2  new-connection-mark=conn_isp2 passthrough=no

/ip firewall mangle add action=mark-connection chain=prerouting 
comment="Connmark in from ISP3" connection-mark=no-mark in-interface=pppoe-isp3  new-connection-mark=conn_isp3 passthrough=no

๋น„๊ณ  ์ด๋ฏธ ํ‘œ์‹œ๋œ ์—ฐ๊ฒฐ์„ ํ‘œ์‹œํ•˜์ง€ ์•Š์œผ๋ ค๋ฉด connection-state=new ๋Œ€์‹  connection-mark=no-mark ์กฐ๊ฑด์„ ์‚ฌ์šฉํ•ฉ๋‹ˆ๋‹ค. ์ด๊ฒƒ์ด ๋” ์ •ํ™•ํ•˜๋‹ค๊ณ  ์ƒ๊ฐํ•˜๊ณ  ์ž…๋ ฅ ํ•„ํ„ฐ์—์„œ ์œ ํšจํ•˜์ง€ ์•Š์€ ์—ฐ๊ฒฐ ์‚ญ์ œ๋ฅผ ๊ฑฐ๋ถ€ํ•˜๊ธฐ ๋•Œ๋ฌธ์ž…๋‹ˆ๋‹ค.


passthrough=no - ์ด ๊ตฌํ˜„ ๋ฐฉ๋ฒ•์—์„œ๋Š” ์žฌํ‘œ์‹œ๊ฐ€ ์ œ์™ธ๋˜๊ณ  ์†๋„๋ฅผ ๋†’์ด๊ธฐ ์œ„ํ•ด ์ฒซ ๋ฒˆ์งธ ์ผ์น˜ ํ›„ ๊ทœ์น™ ์—ด๊ฑฐ๋ฅผ ์ค‘๋‹จํ•  ์ˆ˜ ์žˆ๊ธฐ ๋•Œ๋ฌธ์ž…๋‹ˆ๋‹ค.

์•„์ง ๋ผ์šฐํŒ…์„ ์–ด๋–ค ์‹์œผ๋กœ๋“  ๋ฐฉํ•ดํ•˜์ง€ ์•Š๋Š”๋‹ค๋Š” ์ ์„ ์—ผ๋‘์— ๋‘์–ด์•ผ ํ•ฉ๋‹ˆ๋‹ค. ์ด์ œ ์ค€๋น„ ๋‹จ๊ณ„๋งŒ ๋‚จ์•˜์Šต๋‹ˆ๋‹ค. ๊ตฌํ˜„์˜ ๋‹ค์Œ ๋‹จ๊ณ„๋Š” ๋กœ์ปฌ ๋„คํŠธ์›Œํฌ์˜ ๋Œ€์ƒ์—์„œ ์„ค์ •๋œ ์—ฐ๊ฒฐ์„ ํ†ตํ•ด ๋ฐ˜ํ™˜๋˜๋Š” ํ†ต๊ณผ ํŠธ๋ž˜ํ”ฝ์„ ์ฒ˜๋ฆฌํ•˜๋Š” ๊ฒƒ์ž…๋‹ˆ๋‹ค. ์ €๊ฒƒ๋“ค. ๊ฒฝ๋กœ๋ฅผ ๋”ฐ๋ผ ๋ผ์šฐํ„ฐ๋ฅผ ํ†ต๊ณผํ•œ ํŒจํ‚ท(๋‹ค์ด์–ด๊ทธ๋žจ ์ฐธ์กฐ):

โ€œ์ž…๋ ฅ ์ธํ„ฐํŽ˜์ด์Šคโ€=>โ€Preroutingโ€=>โ€Routing Decisionโ€=>โ€Forwardโ€=>โ€Post Routingโ€=>โ€์ถœ๋ ฅ ์ธํ„ฐํŽ˜์ด์Šคโ€ ๋กœ์ปฌ ๋„คํŠธ์›Œํฌ์˜ ์ˆ˜์ทจ์ธ์—๊ฒŒ ๋„์ฐฉํ–ˆ์Šต๋‹ˆ๋‹ค.

์ค‘์š”! ROS์—์„œ๋Š” ์™ธ๋ถ€ ์ธํ„ฐํŽ˜์ด์Šค์™€ ๋‚ด๋ถ€ ์ธํ„ฐํŽ˜์ด์Šค๋กœ์˜ ๋…ผ๋ฆฌ์  ๊ตฌ๋ถ„์ด ์—†์Šต๋‹ˆ๋‹ค. ์œ„์˜ ๋‹ค์ด์–ด๊ทธ๋žจ์— ๋”ฐ๋ผ ์‘๋‹ต ํŒจํ‚ท์˜ ๊ฒฝ๋กœ๋ฅผ ์ถ”์ ํ•˜๋ฉด ์š”์ฒญ๊ณผ ๋™์ผํ•œ ๋…ผ๋ฆฌ์  ๊ฒฝ๋กœ๋ฅผ ๋”ฐ๋ฆ…๋‹ˆ๋‹ค.

โ€œ์ž…๋ ฅ ์ธํ„ฐํŽ˜์ด์Šคโ€=>โ€Preroutingโ€=>โ€Routing Decisionโ€=>โ€Forwardโ€=>โ€Post Routingโ€=>โ€์ถœ๋ ฅ ์ธํ„ฐํŽ˜์ด์Šคโ€ ์š”์ฒญ์œผ๋กœ๋งŒ"์ž…๋ ฅ ์ธํ„ฐํŽ˜์ด์Šค"๋Š” ISP ์ธํ„ฐํŽ˜์ด์Šค์˜€์œผ๋ฉฐ ๋Œ€๋‹ต์€ LAN์ด์—ˆ์Šต๋‹ˆ๋‹ค.

2.2. ์‘๋‹ต ์ „์†ก ํŠธ๋ž˜ํ”ฝ์„ ํ•ด๋‹น ๋ผ์šฐํŒ… ํ…Œ์ด๋ธ”๋กœ ๋ณด๋ƒ…๋‹ˆ๋‹ค.

/ip firewall mangle add action=mark-routing chain=prerouting 
comment="Routemark transit out via ISP1" connection-mark=conn_isp1 
dst-address-type=!local in-interface-list=!WAN new-routing-mark=to_isp1 passthrough=no

/ip firewall mangle add action=mark-routing chain=prerouting 
comment="Routemark transit out via ISP2" connection-mark=conn_isp2 
dst-address-type=!local in-interface-list=!WAN new-routing-mark=to_isp2 passthrough=no

/ip firewall mangle add action=mark-routing chain=prerouting 
comment="Routemark transit out via ISP3" connection-mark=conn_isp3 
dst-address-type=!local in-interface-list=!WAN new-routing-mark=to_isp3 passthrough=no

๋…ผํ‰. in-interface-list=!WAN - ๋ผ์šฐํ„ฐ ์ž์ฒด์˜ ์ธํ„ฐํŽ˜์ด์Šค ์ฃผ์†Œ์˜ ๋Œ€์ƒ ์ฃผ์†Œ๊ฐ€ ์—†๋Š” ๋กœ์ปฌ ๋„คํŠธ์›Œํฌ ๋ฐ dst-address-type=!local์˜ ํŠธ๋ž˜ํ”ฝ์œผ๋กœ๋งŒ ์ž‘์—…ํ•ฉ๋‹ˆ๋‹ค.

๋„์ค‘์— ๋ผ์šฐํ„ฐ๋กœ ๋“ค์–ด์˜ค๋Š” ๋กœ์ปฌ ํŒจํ‚ท์— ๋Œ€ํ•ด์„œ๋„ ๋งˆ์ฐฌ๊ฐ€์ง€์ž…๋‹ˆ๋‹ค.

โ€œ์ž…๋ ฅ ์ธํ„ฐํŽ˜์ด์Šคโ€=>โ€ํ”„๋ฆฌ๋ผ์šฐํŒ…โ€=>โ€๋ผ์šฐํŒ… ๊ฒฐ์ •โ€=>โ€์ž…๋ ฅโ€=>โ€๋กœ์ปฌ ํ”„๋กœ์„ธ์Šคโ€

์ค‘์š”! ๋Œ€๋‹ต์€ ๋‹ค์Œ๊ณผ ๊ฐ™์ด ์ง„ํ–‰๋ฉ๋‹ˆ๋‹ค.

โ€๋กœ์ปฌ ํ”„๋กœ์„ธ์Šคโ€=>โ€๋ผ์šฐํŒ… ๊ฒฐ์ •โ€=>โ€์ถœ๋ ฅโ€=>โ€ํฌ์ŠคํŠธ ๋ผ์šฐํŒ…โ€=>โ€์ถœ๋ ฅ ์ธํ„ฐํŽ˜์ด์Šคโ€

2.3. ์‘๋‹ต ๋กœ์ปฌ ํŠธ๋ž˜ํ”ฝ์„ ํ•ด๋‹น ๋ผ์šฐํŒ… ํ…Œ์ด๋ธ”๋กœ ๋ณด๋ƒ…๋‹ˆ๋‹ค.

/ip firewall mangle add action=mark-routing chain=output 
comment="Routemark local out via ISP1" connection-mark=conn_isp1 dst-address-type=!local 
new-routing-mark=to_isp1 passthrough=no

/ip firewall mangle add action=mark-routing chain=output 
comment="Routemark local out via ISP2" connection-mark=conn_isp2 dst-address-type=!local 
new-routing-mark=to_isp2 passthrough=no

/ip firewall mangle add action=mark-routing chain=output 
comment="Routemark local out via ISP3" connection-mark=conn_isp3 dst-address-type=!local 
new-routing-mark=to_isp3 passthrough=no

์ด ๋‹จ๊ณ„์—์„œ ์š”์ฒญ์ด ์˜จ ์ธํ„ฐ๋„ท ์ฑ„๋„์— ์‘๋‹ต์„ ๋ณด๋‚ผ ์ค€๋น„ ์ž‘์—…์ด ํ•ด๊ฒฐ๋œ ๊ฒƒ์œผ๋กœ ๊ฐ„์ฃผํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ๋ชจ๋“  ๊ฒƒ์ด ํ‘œ์‹œ๋˜๊ณ  ๋ ˆ์ด๋ธ”์ด ์ง€์ •๋˜๋ฉฐ ๋ผ์šฐํŒ…ํ•  ์ค€๋น„๊ฐ€ ๋ฉ๋‹ˆ๋‹ค.
์ด ์„ค์ •์˜ ํƒ์›”ํ•œ "๋ถ€์ˆ˜" ํšจ๊ณผ๋Š” ๋‘ ๊ณต๊ธ‰์ž(ISP2, ISP3)์˜ DSNAT ํฌํŠธ ํฌ์›Œ๋”ฉ์„ ๋™์‹œ์— ์‚ฌ์šฉํ•  ์ˆ˜ ์žˆ๋‹ค๋Š” ๊ฒƒ์ž…๋‹ˆ๋‹ค. ์ „ํ˜€ ๊ทธ๋ ‡์ง€ ์•Š์Šต๋‹ˆ๋‹ค. ISP1์—๋Š” ๋ผ์šฐํŒ…ํ•  ์ˆ˜ ์—†๋Š” ์ฃผ์†Œ๊ฐ€ ์žˆ๊ธฐ ๋•Œ๋ฌธ์ž…๋‹ˆ๋‹ค. ์ด ํšจ๊ณผ๋Š” ์˜ˆ๋ฅผ ๋“ค์–ด ์„œ๋กœ ๋‹ค๋ฅธ ์ธํ„ฐ๋„ท ์ฑ„๋„์„ ๋ณด๋Š” ๋‘ ๊ฐœ์˜ MX๊ฐ€ ์žˆ๋Š” ๋ฉ”์ผ ์„œ๋ฒ„์— ์ค‘์š”ํ•ฉ๋‹ˆ๋‹ค.

์™ธ๋ถ€ IP ๋ผ์šฐํ„ฐ๋ฅผ ์‚ฌ์šฉํ•œ ๋กœ์ปฌ ๋„คํŠธ์›Œํฌ ์ž‘๋™์˜ ๋‰˜์•™์Šค๋ฅผ ์ œ๊ฑฐํ•˜๊ธฐ ์œ„ํ•ด ๋‹จ๋ฝ์˜ ์†”๋ฃจ์…˜์„ ์‚ฌ์šฉํ•ฉ๋‹ˆ๋‹ค. 1.8.2 ๋ฐ 3.1.2.6.

๋˜ํ•œ ํ‘œ์‹œ๊ฐ€ ์žˆ๋Š” ๋„๊ตฌ๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ ๋ฌธ์ œ์˜ ๋‹จ๋ฝ 3์„ ํ•ด๊ฒฐํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ๋‹ค์Œ๊ณผ ๊ฐ™์ด ๊ตฌํ˜„ํ•ฉ๋‹ˆ๋‹ค.

2.4. ๋ผ์šฐํŒ… ๋ชฉ๋ก์—์„œ ๋กœ์ปฌ ํด๋ผ์ด์–ธํŠธ์˜ ํŠธ๋ž˜ํ”ฝ์„ ์ ์ ˆํ•œ ํ…Œ์ด๋ธ”๋กœ ๋ณด๋ƒ…๋‹ˆ๋‹ค.

/ip firewall mangle add action=mark-routing chain=prerouting 
comment="Address List via ISP1" dst-address-list=!BOGONS new-routing-mark=to_isp1 
passthrough=no src-address-list=Via_ISP1

/ip firewall mangle add action=mark-routing chain=prerouting 
comment="Address List via ISP2" dst-address-list=!BOGONS new-routing-mark=to_isp2 
passthrough=no src-address-list=Via_ISP2

/ip firewall mangle add action=mark-routing chain=prerouting 
comment="Address List via ISP3" dst-address-list=!BOGONS new-routing-mark=to_isp3 
passthrough=no src-address-list=Via_ISP3

๊ฒฐ๊ณผ์ ์œผ๋กœ ๋‹ค์Œ๊ณผ ๊ฐ™์ด ๋ณด์ž…๋‹ˆ๋‹ค.

Mikrotik RouterOS์˜ ๋ฉ€ํ‹ฐ๋ฐด ๋ฐ ๋ผ์šฐํŒ…

3. ISP์— ๋Œ€ํ•œ ์—ฐ๊ฒฐ ์„ค์ • ๋ฐ ๋ธŒ๋žœ๋“œ ๋ผ์šฐํŒ… ํ™œ์„ฑํ™”

3.1. ISP1์— ๋Œ€ํ•œ ์—ฐ๊ฒฐ ์„ค์ •:
3.1.1. ๊ณ ์ • IP ์ฃผ์†Œ๋ฅผ ๊ตฌ์„ฑํ•ฉ๋‹ˆ๋‹ค.

/ip address add interface=ether1 address=100.66.66.2/30 comment="ISP1 IP"

3.1.2. ์ •์  ๋ผ์šฐํŒ… ์„ค์ •:
3.1.2.1. ๊ธฐ๋ณธ "๊ธด๊ธ‰" ๊ฒฝ๋กœ๋ฅผ ์ถ”๊ฐ€ํ•ฉ๋‹ˆ๋‹ค.

/ip route add comment="Emergency route" distance=254 type=blackhole

๋น„๊ณ  ์ด ๊ฒฝ๋กœ๋ฅผ ์‚ฌ์šฉํ•˜๋ฉด ๊ณต๊ธ‰์ž์˜ ๋งํฌ ์ƒํƒœ์— ๊ด€๊ณ„์—†์ด ๋กœ์ปฌ ํ”„๋กœ์„ธ์Šค์˜ ํŠธ๋ž˜ํ”ฝ์ด ๊ฒฝ๋กœ ๊ฒฐ์ • ๋‹จ๊ณ„๋ฅผ ํ†ต๊ณผํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ๋‚˜๊ฐ€๋Š” ๋กœ์ปฌ ํŠธ๋ž˜ํ”ฝ์˜ ๋ฏธ๋ฌ˜ํ•œ ์ฐจ์ด๋Š” ํŒจํ‚ท์ด ์ ์–ด๋„ ์–ด๋”˜๊ฐ€๋กœ ์ด๋™ํ•˜๊ธฐ ์œ„ํ•ด์„œ๋Š” ๊ธฐ๋ณธ ๋ผ์šฐํŒ… ํ…Œ์ด๋ธ”์— ๊ธฐ๋ณธ ๊ฒŒ์ดํŠธ์›จ์ด์— ๋Œ€ํ•œ ํ™œ์„ฑ ๊ฒฝ๋กœ๊ฐ€ ์žˆ์–ด์•ผ ํ•œ๋‹ค๋Š” ๊ฒƒ์ž…๋‹ˆ๋‹ค. ๊ทธ๋ ‡์ง€ ์•Š์€ ๊ฒฝ์šฐ ํŒจํ‚ค์ง€๋Š” ๋‹จ์ˆœํžˆ ํŒŒ๊ดด๋ฉ๋‹ˆ๋‹ค.

๋„๊ตฌ ํ™•์žฅ์œผ๋กœ ๊ฒŒ์ดํŠธ์›จ์ด ํ™•์ธ ์ฑ„๋„ ์ƒํƒœ์— ๋Œ€ํ•œ ๋” ๊นŠ์€ ๋ถ„์„์„ ์œ„ํ•ด ์žฌ๊ท€ ๊ฒฝ๋กœ ๋ฐฉ๋ฒ•์„ ์‚ฌ์šฉํ•˜๋Š” ๊ฒƒ์ด ์ข‹์Šต๋‹ˆ๋‹ค. ์ด ๋ฐฉ๋ฒ•์˜ ํ•ต์‹ฌ์€ ๋ผ์šฐํ„ฐ์—๊ฒŒ ๊ฒŒ์ดํŠธ์›จ์ด์— ๋Œ€ํ•œ ๊ฒฝ๋กœ๋ฅผ ์ง์ ‘ ์ฐพ์ง€ ์•Š๊ณ  ์ค‘๊ฐ„ ๊ฒŒ์ดํŠธ์›จ์ด๋ฅผ ํ†ตํ•ด ์ฐพ๋„๋ก ์ง€์‹œํ•˜๋Š” ๊ฒƒ์ž…๋‹ˆ๋‹ค. 4.2.2.1, 4.2.2.2 ๋ฐ 4.2.2.3์€ ๊ฐ๊ฐ ISP1, ISP2 ๋ฐ ISP3์— ๋Œ€ํ•œ "ํ…Œ์ŠคํŠธ" ๊ฒŒ์ดํŠธ์›จ์ด๋กœ ์„ ํƒ๋ฉ๋‹ˆ๋‹ค.

3.1.2.2. "ํ™•์ธ" ์ฃผ์†Œ๋กœ ๋ผ์šฐํŒ…:

/ip route add check-gateway=ping comment="For recursion via ISP1"  
distance=1 dst-address=4.2.2.1 gateway=100.66.66.1 scope=10

๋น„๊ณ  ํ–ฅํ›„ 4.2.2.1์„ ์žฌ๊ท€ ๊ฒŒ์ดํŠธ์›จ์ด๋กœ ์‚ฌ์šฉํ•˜๊ธฐ ์œ„ํ•ด ROS ๋Œ€์ƒ ๋ฒ”์œ„์—์„œ ๋ฒ”์œ„ ๊ฐ’์„ ๊ธฐ๋ณธ๊ฐ’์œผ๋กœ ๋‚ฎ์ถฅ๋‹ˆ๋‹ค. ์ €๋Š” ๊ฐ•์กฐํ•ฉ๋‹ˆ๋‹ค: "ํ…Œ์ŠคํŠธ" ์ฃผ์†Œ์— ๋Œ€ํ•œ ๊ฒฝ๋กœ์˜ ๋ฒ”์œ„๋Š” ํ…Œ์ŠคํŠธ ์ฃผ์†Œ๋ฅผ ์ฐธ์กฐํ•  ๊ฒฝ๋กœ์˜ ๋Œ€์ƒ ๋ฒ”์œ„๋ณด๋‹ค ์ž‘๊ฑฐ๋‚˜ ๊ฐ™์•„์•ผ ํ•ฉ๋‹ˆ๋‹ค.

3.1.2.3. ๋ผ์šฐํŒ… ํ‘œ์‹œ๊ฐ€ ์—†๋Š” ํŠธ๋ž˜ํ”ฝ์— ๋Œ€ํ•œ ์žฌ๊ท€์  ๊ธฐ๋ณธ ๊ฒฝ๋กœ:

/ip route add comment="Unmarked via ISP1" distance=2 gateway=4.2.2.1

๋น„๊ณ  ์ž‘์—… ์กฐ๊ฑด์— ๋”ฐ๋ผ ISP2์ด ์ฒซ ๋ฒˆ์งธ ๋ฐฑ์—…์œผ๋กœ ์„ ์–ธ๋˜์–ด ์žˆ๊ธฐ ๋•Œ๋ฌธ์— distance=1 ๊ฐ’์„ ์‚ฌ์šฉํ•ฉ๋‹ˆ๋‹ค.

3.1.2.4. ๋ผ์šฐํŒ… ํ‘œ์‹œ๊ฐ€ "to_isp1"์ธ ํŠธ๋ž˜ํ”ฝ์— ๋Œ€ํ•œ ์žฌ๊ท€์  ๊ธฐ๋ณธ ๊ฒฝ๋กœ:

/ip route add comment="Marked via ISP1 Main" distance=1 gateway=4.2.2.1 
routing-mark=to_isp1

๋น„๊ณ  ์‹ค์ œ๋กœ ์—ฌ๊ธฐ์—์„œ ์šฐ๋ฆฌ๋Š” 2ํ•ญ์—์„œ ์ˆ˜ํ–‰ํ•œ ์ค€๋น„ ์ž‘์—…์˜ ๊ฒฐ์‹ค์„ ๋งˆ์นจ๋‚ด ์ฆ๊ธฐ๊ธฐ ์‹œ์ž‘ํ–ˆ์Šต๋‹ˆ๋‹ค.


์ด ๊ฒฝ๋กœ์—์„œ ํ‘œ์‹œ ๊ฒฝ๋กœ "to_isp1"์ด ์žˆ๋Š” ๋ชจ๋“  ํŠธ๋ž˜ํ”ฝ์€ ํ˜„์žฌ ๊ธฐ๋ณธ ํ…Œ์ด๋ธ”์— ๋Œ€ํ•ด ํ™œ์„ฑํ™”๋œ ๊ธฐ๋ณธ ๊ฒŒ์ดํŠธ์›จ์ด์— ๊ด€๊ณ„์—†์ด ์ฒซ ๋ฒˆ์งธ ๊ณต๊ธ‰์ž์˜ ๊ฒŒ์ดํŠธ์›จ์ด๋กœ ์ „๋‹ฌ๋ฉ๋‹ˆ๋‹ค.

3.1.2.5. ISP2 ๋ฐ ISP3 ํƒœ๊ทธ๊ฐ€ ์ง€์ •๋œ ํŠธ๋ž˜ํ”ฝ์— ๋Œ€ํ•œ ์ฒซ ๋ฒˆ์งธ ํด๋ฐฑ ์žฌ๊ท€ ๊ธฐ๋ณธ ๊ฒฝ๋กœ:

/ip route add comment="Marked via ISP2 Backup1" distance=2 gateway=4.2.2.1 
routing-mark=to_isp2
/ip route add comment="Marked via ISP3 Backup1" distance=2 gateway=4.2.2.1 
routing-mark=to_isp3

๋น„๊ณ  ์ด๋Ÿฌํ•œ ๊ฒฝ๋กœ๋Š” ๋ฌด์—‡๋ณด๋‹ค๋„ "to_isp*" ์ฃผ์†Œ ๋ชฉ๋ก์˜ ๊ตฌ์„ฑ์›์ธ ๋กœ์ปฌ ๋„คํŠธ์›Œํฌ์˜ ํŠธ๋ž˜ํ”ฝ์„ ์˜ˆ์•ฝํ•˜๋Š” ๋ฐ ํ•„์š”ํ•ฉ๋‹ˆ๋‹ค.

3.1.2.6. ISP1์„ ํ†ตํ•ด ๋ผ์šฐํ„ฐ์˜ ๋กœ์ปฌ ํŠธ๋ž˜ํ”ฝ ๊ฒฝ๋กœ๋ฅผ ์ธํ„ฐ๋„ท์— ๋“ฑ๋กํ•ฉ๋‹ˆ๋‹ค.

/ip route rule add comment="From ISP1 IP to Inet" src-address=100.66.66.2 table=to_isp1

๋น„๊ณ  ๋‹จ๋ฝ 1.8.2์˜ ๊ทœ์น™๊ณผ ํ•จ๊ป˜ ์ฃผ์–ด์ง„ ์†Œ์Šค๋กœ ์›ํ•˜๋Š” ์ฑ„๋„์— ๋Œ€ํ•œ ์•ก์„ธ์Šค๋ฅผ ์ œ๊ณตํ•ฉ๋‹ˆ๋‹ค. ์ด๋Š” ๋กœ์ปฌ ์ธก IP ์ฃผ์†Œ(EoIP, IP-IP, GRE)๋ฅผ ์ง€์ •ํ•˜๋Š” ํ„ฐ๋„์„ ๊ตฌ์ถ•ํ•˜๋Š” ๋ฐ ์ค‘์š”ํ•ฉ๋‹ˆ๋‹ค. ip ๊ฒฝ๋กœ ๊ทœ์น™์˜ ๊ทœ์น™์€ ์กฐ๊ฑด์˜ ์ฒซ ๋ฒˆ์งธ ์ผ์น˜๊นŒ์ง€ ์œ„์—์„œ ์•„๋ž˜๋กœ ์‹คํ–‰๋˜๋ฏ€๋กœ ์ด ๊ทœ์น™์€ 1.8.2์ ˆ์˜ ๊ทœ์น™ ๋‹ค์Œ์— ์žˆ์–ด์•ผ ํ•ฉ๋‹ˆ๋‹ค.

3.1.3. ๋‚˜๊ฐ€๋Š” ํŠธ๋ž˜ํ”ฝ์— ๋Œ€ํ•ด NAT ๊ทœ์น™์„ ๋“ฑ๋กํ•ฉ๋‹ˆ๋‹ค.

/ip firewall nat add action=src-nat chain=srcnat comment="NAT via ISP1"  
ipsec-policy=out,none out-interface=ether1 to-addresses=100.66.66.2

๋น„๊ณ  NATim์€ IPsec ์ •์ฑ…์— ๋“ค์–ด์˜ค๋Š” ๊ฒƒ์„ ์ œ์™ธํ•˜๊ณ  ๋‚˜๊ฐ€๋Š” ๋ชจ๋“  ๊ฒƒ์ž…๋‹ˆ๋‹ค. ๊ผญ ํ•„์š”ํ•œ ๊ฒฝ์šฐ๊ฐ€ ์•„๋‹ˆ๋ฉด action=masquerade๋ฅผ ์‚ฌ์šฉํ•˜์ง€ ์•Š์œผ๋ ค๊ณ  ํ•ฉ๋‹ˆ๋‹ค. ๊ฐ๊ฐ์˜ ์ƒˆ ์—ฐ๊ฒฐ์— ๋Œ€ํ•œ NAT ์ฃผ์†Œ๋ฅผ ๊ณ„์‚ฐํ•˜๊ธฐ ๋•Œ๋ฌธ์— src-nat๋ณด๋‹ค ๋Š๋ฆฌ๊ณ  ๋ฆฌ์†Œ์Šค ์ง‘์•ฝ์ ์ž…๋‹ˆ๋‹ค.

3.1.4. ์šฐ๋ฆฌ๋Š” ๋‹ค๋ฅธ ๊ณต๊ธ‰์ž๋ฅผ ํ†ตํ•œ ์•ก์„ธ์Šค๊ฐ€ ๊ธˆ์ง€๋œ ๋ชฉ๋ก์˜ ํด๋ผ์ด์–ธํŠธ๋ฅผ ISP1 ๊ณต๊ธ‰์ž์˜ ๊ฒŒ์ดํŠธ์›จ์ด๋กœ ์ง์ ‘ ๋ณด๋ƒ…๋‹ˆ๋‹ค.

/ip firewall mangle add action=route chain=prerouting comment="Address List via ISP1 only" 
dst-address-list=!BOGONS passthrough=no route-dst=100.66.66.1 
src-address-list=Via_only_ISP1 place-before=0

๋น„๊ณ  action=route๋Š” ์šฐ์„  ์ˆœ์œ„๊ฐ€ ๋” ๋†’์œผ๋ฉฐ ๋‹ค๋ฅธ ๋ผ์šฐํŒ… ๊ทœ์น™๋ณด๋‹ค ๋จผ์ € ์ ์šฉ๋ฉ๋‹ˆ๋‹ค.


place-before=0 - ๋ชฉ๋ก์˜ ์ฒซ ๋ฒˆ์งธ ๊ทœ์น™์„ ๋ฐฐ์น˜ํ•ฉ๋‹ˆ๋‹ค.

3.2. ISP2์— ๋Œ€ํ•œ ์—ฐ๊ฒฐ์„ ์„ค์ •ํ•ฉ๋‹ˆ๋‹ค.

ISP2 ๊ณต๊ธ‰์ž๊ฐ€ DHCP๋ฅผ ํ†ตํ•ด ์„ค์ •์„ ์ œ๊ณตํ•˜๋ฏ€๋กœ DHCP ํด๋ผ์ด์–ธํŠธ๊ฐ€ ํŠธ๋ฆฌ๊ฑฐ๋  ๋•Œ ์‹œ์ž‘๋˜๋Š” ์Šคํฌ๋ฆฝํŠธ๋กœ ํ•„์š”ํ•œ ๋ณ€๊ฒฝ์„ ์ˆ˜ํ–‰ํ•˜๋Š” ๊ฒƒ์ด ํ•ฉ๋ฆฌ์ ์ž…๋‹ˆ๋‹ค.

/ip dhcp-client
add add-default-route=no disabled=no interface=ether2 script=":if ($bound=1) do={r
    n    /ip route add check-gateway=ping comment="For recursion via ISP2" distance=1 
           dst-address=4.2.2.2/32 gateway=$"gateway-address" scope=10r
    n    /ip route add comment="Unmarked via ISP2" distance=1 gateway=4.2.2.2;r
    n    /ip route add comment="Marked via ISP2 Main" distance=1 gateway=4.2.2.2 
           routing-mark=to_isp2;r
    n    /ip route add comment="Marked via ISP1 Backup1" distance=2 gateway=4.2.2.2 
           routing-mark=to_isp1;r
    n    /ip route add comment="Marked via ISP3 Backup2" distance=3 gateway=4.2.2.2 
           routing-mark=to_isp3;r
    n    /ip firewall nat add action=src-nat chain=srcnat ipsec-policy=out,none 
           out-interface=$"interface" to-addresses=$"lease-address" comment="NAT via ISP2" 
           place-before=1;r
    n    if ([/ip route rule find comment="From ISP2 IP to Inet"] ="") do={r
    n        /ip route rule add comment="From ISP2 IP to Inet" 
               src-address=$"lease-address" table=to_isp2 r
    n    } else={r
    n       /ip route rule set [find comment="From ISP2 IP to Inet"] disabled=no 
              src-address=$"lease-address"r
    n    }      r
    n} else={r
    n   /ip firewall nat remove  [find comment="NAT via ISP2"];r
    n   /ip route remove [find comment="For recursion via ISP2"];r
    n   /ip route remove [find comment="Unmarked via ISP2"];r
    n   /ip route remove [find comment="Marked via ISP2 Main"];r
    n   /ip route remove [find comment="Marked via ISP1 Backup1"];r
    n   /ip route remove [find comment="Marked via ISP3 Backup2"];r
    n   /ip route rule set [find comment="From ISP2 IP to Inet"] disabled=yesr
    n}r
    n" use-peer-dns=no use-peer-ntp=no

Winbox ์ฐฝ์˜ ์Šคํฌ๋ฆฝํŠธ ์ž์ฒด:

Mikrotik RouterOS์˜ ๋ฉ€ํ‹ฐ๋ฐด ๋ฐ ๋ผ์šฐํŒ…
๋น„๊ณ  ์ž„๋Œ€๊ฐ€ ์„ฑ๊ณต์ ์œผ๋กœ ํš๋“๋˜๋ฉด ์Šคํฌ๋ฆฝํŠธ์˜ ์ฒซ ๋ฒˆ์งธ ๋ถ€๋ถ„์ด ํŠธ๋ฆฌ๊ฑฐ๋˜๊ณ  ๋‘ ๋ฒˆ์งธ ๋ถ€๋ถ„์€ ์ž„๋Œ€๊ฐ€ ํ•ด์ œ๋œ ํ›„ ํŠธ๋ฆฌ๊ฑฐ๋ฉ๋‹ˆ๋‹ค.์ฐธ๊ณ  2 ์ฐธ์กฐ

3.3. ISP3 ๊ณต๊ธ‰์ž์— ๋Œ€ํ•œ ์—ฐ๊ฒฐ์„ ์„ค์ •ํ–ˆ์Šต๋‹ˆ๋‹ค.

์„ค์ • ์ œ๊ณต์ž๊ฐ€ ์šฐ๋ฆฌ์—๊ฒŒ ๋™์ ์ธ ๊ฒƒ์„ ์ œ๊ณตํ•˜๊ธฐ ๋•Œ๋ฌธ์—, ppp ์ธํ„ฐํŽ˜์ด์Šค๊ฐ€ ์˜ฌ๋ผ๊ฐ„ ํ›„์™€ ๋–จ์–ด์ง„ ํ›„์— ์‹œ์ž‘ํ•˜๋Š” ์Šคํฌ๋ฆฝํŠธ๋กœ ํ•„์š”ํ•œ ๋ณ€๊ฒฝ์„ ํ•˜๋Š” ๊ฒƒ์ด ํ•ฉ๋‹นํ•ฉ๋‹ˆ๋‹ค.

3.3.1. ๋จผ์ € ํ”„๋กœํ•„์„ ๊ตฌ์„ฑํ•ฉ๋‹ˆ๋‹ค.

/ppp profile
add comment="for PPPoE to ISP3" interface-list=WAN name=isp3_client 
on-down="/ip firewall nat remove  [find comment="NAT via ISP3"];r
    n/ip route remove [find comment="For recursion via ISP3"];r
    n/ip route remove [find comment="Unmarked via ISP3"];r
    n/ip route remove [find comment="Marked via ISP3 Main"];r
    n/ip route remove [find comment="Marked via ISP1 Backup2"];r
    n/ip route remove [find comment="Marked via ISP2 Backup2"];r
    n/ip route rule set [find comment="From ISP3 IP to Inet"] disabled=yes;" 
on-up="/ip route add check-gateway=ping comment="For recursion via ISP3" distance=1 
    dst-address=4.2.2.3/32 gateway=$"remote-address" scope=10r
    n/ip route add comment="Unmarked via ISP3" distance=3 gateway=4.2.2.3;r
    n/ip route add comment="Marked via ISP3 Main" distance=1 gateway=4.2.2.3 
    routing-mark=to_isp3;r
    n/ip route add comment="Marked via ISP1 Backup2" distance=3 gateway=4.2.2.3 
    routing-mark=to_isp1;r
    n/ip route add comment="Marked via ISP2 Backup2" distance=3 gateway=4.2.2.3 
    routing-mark=to_isp2;r
    n/ip firewall mangle set [find comment="Connmark in from ISP3"] 
    in-interface=$"interface";r
    n/ip firewall nat add action=src-nat chain=srcnat ipsec-policy=out,none 
    out-interface=$"interface" to-addresses=$"local-address" comment="NAT via ISP3" 
    place-before=1;r
    nif ([/ip route rule find comment="From ISP3 IP to Inet"] ="") do={r
    n   /ip route rule add comment="From ISP3 IP to Inet" src-address=$"local-address" 
    table=to_isp3 r
    n} else={r
    n   /ip route rule set [find comment="From ISP3 IP to Inet"] disabled=no 
    src-address=$"local-address"r
    n};r
    n"

Winbox ์ฐฝ์˜ ์Šคํฌ๋ฆฝํŠธ ์ž์ฒด:

Mikrotik RouterOS์˜ ๋ฉ€ํ‹ฐ๋ฐด ๋ฐ ๋ผ์šฐํŒ…
๋น„๊ณ  ์„ 
/ip firewall mangle set [find comment="Connmark in from ISP3"] in-interface=$"์ธํ„ฐํŽ˜์ด์Šค";
ํ‘œ์‹œ ์ด๋ฆ„์ด ์•„๋‹Œ ์ฝ”๋“œ์™€ ํ•จ๊ป˜ ์ž‘๋™ํ•˜๋ฏ€๋กœ ์ธํ„ฐํŽ˜์ด์Šค ์ด๋ฆ„ ๋ณ€๊ฒฝ์„ ์˜ฌ๋ฐ”๋ฅด๊ฒŒ ์ฒ˜๋ฆฌํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

3.3.2. ์ด์ œ ํ”„๋กœํ•„์„ ์‚ฌ์šฉํ•˜์—ฌ ppp ์—ฐ๊ฒฐ์„ ๋งŒ๋“ญ๋‹ˆ๋‹ค.

/interface pppoe-client add allow=mschap2 comment="to ISP3" disabled=no 
interface=ether3 name=pppoe-isp3 password=isp3_pass profile=isp3_client user=isp3_client

๋งˆ์ง€๋ง‰์œผ๋กœ ์‹œ๊ณ„๋ฅผ ์„ค์ •ํ•ด ๋ณด๊ฒ ์Šต๋‹ˆ๋‹ค.

/system ntp client set enabled=yes server-dns-names=0.pool.ntp.org,1.pool.ntp.org,2.pool.ntp.org

๋๊นŒ์ง€ ์ฝ์–ด์ฃผ์‹  ๋ถ„๋“ค์„ ์œ„ํ•ด

๋ฉ€ํ‹ฐ๋ฐด์„ ๊ตฌํ˜„ํ•˜๊ธฐ ์œ„ํ•ด ์ œ์•ˆ๋œ ๋ฐฉ๋ฒ•์€ ์ €์ž์˜ ๊ฐœ์ธ์  ์„ ํ˜ธ๋„์ด๋ฉฐ ๊ฐ€๋Šฅํ•œ ์œ ์ผํ•œ ๋ฐฉ๋ฒ•์€ ์•„๋‹™๋‹ˆ๋‹ค. ROS ํˆดํ‚ท์€ ๊ด‘๋ฒ”์œ„ํ•˜๊ณ  ์œ ์—ฐํ•˜์—ฌ ํ•œํŽธ์œผ๋กœ๋Š” ์ดˆ๋ณด์ž์—๊ฒŒ ์–ด๋ ค์›€์„ ์ดˆ๋ž˜ํ•˜๊ณ  ๋‹ค๋ฅธ ํ•œํŽธ์œผ๋กœ๋Š” ์ธ๊ธฐ์˜ ์ด์œ ์ž…๋‹ˆ๋‹ค. ์ƒˆ๋กœ์šด ๋„๊ตฌ์™€ ์†”๋ฃจ์…˜์„ ๋ฐฐ์šฐ๊ณ , ์‹œ๋„ํ•˜๊ณ , ๋ฐœ๊ฒฌํ•˜์‹ญ์‹œ์˜ค. ์˜ˆ๋ฅผ ๋“ค์–ด, ์Šต๋“ํ•œ ์ง€์‹์˜ ์‘์šฉ์œผ๋กœ ๋ฉ€ํ‹ฐ๋ฐด ๊ตฌํ˜„์—์„œ ๋„๊ตฌ๋ฅผ ๋Œ€์ฒดํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ์ฒดํฌ ๊ฒŒ์ดํŠธ์›จ์ด ์žฌ๊ท€ ๊ฒฝ๋กœ๋กœ ๋„ท์›Œ์น˜.

์ฐธ๊ณ  ์‚ฌํ•ญ

  1. ์ฒดํฌ ๊ฒŒ์ดํŠธ์›จ์ด - ๊ฒŒ์ดํŠธ์›จ์ด์˜ ๊ฐ€์šฉ์„ฑ ํ™•์ธ์— ๋‘ ๋ฒˆ ์—ฐ์† ์‹คํŒจํ•˜๋ฉด ๊ฒฝ๋กœ๋ฅผ ๋น„ํ™œ์„ฑํ™”ํ•  ์ˆ˜ ์žˆ๋Š” ๋ฉ”์ปค๋‹ˆ์ฆ˜์ž…๋‹ˆ๋‹ค. ํ™•์ธ์€ 10์ดˆ๋งˆ๋‹ค ํ•œ ๋ฒˆ์”ฉ ์ˆ˜ํ–‰๋˜๋ฉฐ ์‘๋‹ต ์‹œ๊ฐ„ ์ดˆ๊ณผ๋„ ํฌํ•จ๋ฉ๋‹ˆ๋‹ค. ์ „์ฒด์ ์œผ๋กœ ์‹ค์ œ ์Šค์œ„์นญ ํƒ€์ด๋ฐ์€ 20-30์ดˆ ๋ฒ”์œ„์— ์žˆ์Šต๋‹ˆ๋‹ค. ์ด๋Ÿฌํ•œ ์ „ํ™˜ ํƒ€์ด๋ฐ์ด ์ถฉ๋ถ„ํ•˜์ง€ ์•Š์€ ๊ฒฝ์šฐ ๋„๊ตฌ๋ฅผ ์‚ฌ์šฉํ•  ์ˆ˜ ์žˆ๋Š” ์˜ต์…˜์ด ์žˆ์Šต๋‹ˆ๋‹ค. ๋„ท์›Œ์น˜, ์—ฌ๊ธฐ์„œ ํ™•์ธ ํƒ€์ด๋จธ๋ฅผ ์ˆ˜๋™์œผ๋กœ ์„ค์ •ํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ์ฒดํฌ ๊ฒŒ์ดํŠธ์›จ์ด ๋งํฌ์—์„œ ๊ฐ„ํ—์ ์ธ ํŒจํ‚ท ์†์‹ค ์‹œ ์‹คํ–‰๋˜์ง€ ์•Š์Šต๋‹ˆ๋‹ค.

    ์ค‘์š”ํ•œ! ๊ธฐ๋ณธ ๊ฒฝ๋กœ๋ฅผ ๋น„ํ™œ์„ฑํ™”ํ•˜๋ฉด ์ด๋ฅผ ์ฐธ์กฐํ•˜๋Š” ๋‹ค๋ฅธ ๋ชจ๋“  ๊ฒฝ๋กœ๊ฐ€ ๋น„ํ™œ์„ฑํ™”๋ฉ๋‹ˆ๋‹ค. ๊ทธ๋Ÿฌ๋ฏ€๋กœ ๊ทธ๋“ค์ด ๋‚˜ํƒ€๋‚ด๊ธฐ ์œ„ํ•ด์„œ๋Š” ์ฒดํฌ-๊ฒŒ์ดํŠธ์›จ์ด=ping ํ•„์š”ํ•˜์ง€ ์•Š์Šต๋‹ˆ๋‹ค.

  2. ํด๋ผ์ด์–ธํŠธ๊ฐ€ ๊ฐฑ์‹  ์ƒํƒœ์— ์žˆ๋Š” ๊ฒƒ์ฒ˜๋Ÿผ ๋ณด์ด๋Š” DHCP ๋ฉ”์ปค๋‹ˆ์ฆ˜์—์„œ ์˜ค๋ฅ˜๊ฐ€ ๋ฐœ์ƒํ•ฉ๋‹ˆ๋‹ค. ์ด ๊ฒฝ์šฐ ์Šคํฌ๋ฆฝํŠธ์˜ ๋‘ ๋ฒˆ์งธ ๋ถ€๋ถ„์€ ์ž‘๋™ํ•˜์ง€ ์•Š์ง€๋งŒ ์ƒํƒœ๊ฐ€ ํ•ด๋‹น ์žฌ๊ท€ ๊ฒฝ๋กœ๋ฅผ ์ถ”์ ํ•˜๊ธฐ ๋•Œ๋ฌธ์— ํŠธ๋ž˜ํ”ฝ์ด ์˜ฌ๋ฐ”๋ฅด๊ฒŒ ๊ฑท๋Š” ๊ฒƒ์„ ๋ฐฉํ•ดํ•˜์ง€๋Š” ์•Š์Šต๋‹ˆ๋‹ค.
  3. ECMP(๋™์ผ ๋น„์šฉ ๋‹ค์ค‘ ๊ฒฝ๋กœ) - ROS์—์„œ๋Š” ์—ฌ๋Ÿฌ ๊ฒŒ์ดํŠธ์›จ์ด์™€ ๋™์ผํ•œ ๊ฑฐ๋ฆฌ๋กœ ๊ฒฝ๋กœ๋ฅผ ์„ค์ •ํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ์ด ๊ฒฝ์šฐ ์ง€์ •๋œ ๊ฒŒ์ดํŠธ์›จ์ด ์ˆ˜์— ๋น„๋ก€ํ•˜์—ฌ ๋ผ์šด๋“œ ๋กœ๋นˆ ์•Œ๊ณ ๋ฆฌ์ฆ˜์„ ์‚ฌ์šฉํ•˜์—ฌ ์ฑ„๋„ ๊ฐ„์— ์—ฐ๊ฒฐ์ด ๋ถ„์‚ฐ๋ฉ๋‹ˆ๋‹ค.

๊ธฐ์‚ฌ ์ž‘์„ฑ์— ๋Œ€ํ•œ ์ž๊ทน์„ ๋ฐ›์œผ๋ ค๋ฉด ๊ตฌ์กฐ ๋ฐ ์•…์„ผํŠธ ๋ฐฐ์น˜๋ฅผ ํ˜•์„ฑํ•˜๋Š” ๋ฐ ๋„์›€์„์ฃผ์‹ญ์‹œ์˜ค. Evgeny์— ๋Œ€ํ•œ ๊ฐœ์ธ์ ์ธ ๊ฐ์‚ฌ @jscar

์ถœ์ฒ˜ : habr.com