ASA VPN ๋กœ๋“œ ๋ฐธ๋Ÿฐ์‹ฑ ํด๋Ÿฌ์Šคํ„ฐ ๋ฐฐํฌ

์ด ๊ธฐ์‚ฌ์—์„œ๋Š” ํ˜„์žฌ ๊ฐ€์žฅ ํ™•์žฅ ๊ฐ€๋Šฅํ•œ ์ฒด๊ณ„๋ฅผ ์‹ ์†ํ•˜๊ฒŒ ๋ฐฐํฌํ•  ์ˆ˜ ์žˆ๋Š” ๋ฐฉ๋ฒ•์— ๋Œ€ํ•œ ๋‹จ๊ณ„๋ณ„ ์ง€์นจ์„ ์ œ๊ณตํ•˜๊ณ ์ž ํ•ฉ๋‹ˆ๋‹ค. ์›๊ฒฉ ์•ก์„ธ์Šค VPN ์•ก์„ธ์Šค ๊ธฐ๋ฐ˜ AnyConnect ๋ฐ Cisco ASA - VPN ๋ถ€ํ•˜ ๋ถ„์‚ฐ ํด๋Ÿฌ์Šคํ„ฐ.

๋™์˜์ƒ: ์ฝ”๋กœ๋‚˜19๋กœ ์ธํ•œ ํ˜„ ์ƒํ™ฉ์„ ๊ฐ์•ˆํ•˜์—ฌ ์ „ ์„ธ๊ณ„ ๋งŽ์€ ๊ธฐ์—…๋“ค์ด ์ง์›๋“ค์˜ ์›๊ฒฉ๊ทผ๋ฌด ์ „ํ™˜์„ ์œ„ํ•ด ๋…ธ๋ ฅํ•˜๊ณ  ์žˆ์Šต๋‹ˆ๋‹ค. ์›๊ฒฉ ์ž‘์—…์œผ๋กœ์˜ ๋Œ€๊ทœ๋ชจ ์ „ํ™˜์œผ๋กœ ์ธํ•ด ํšŒ์‚ฌ์˜ ๊ธฐ์กด VPN ๊ฒŒ์ดํŠธ์›จ์ด์— ๋Œ€ํ•œ ๋ถ€ํ•˜๊ฐ€ ํฌ๊ฒŒ ์ฆ๊ฐ€ํ•˜๊ณ  ์žˆ์œผ๋ฉฐ ์ด๋ฅผ ํ™•์žฅํ•  ์ˆ˜ ์žˆ๋Š” ๋งค์šฐ ๋น ๋ฅธ ๊ธฐ๋Šฅ์ด ํ•„์š”ํ•ฉ๋‹ˆ๋‹ค. ๋ฐ˜๋ฉด์— ๋งŽ์€ ํšŒ์‚ฌ๋Š” ์ฒ˜์Œ๋ถ€ํ„ฐ ์›๊ฒฉ ์ž‘์—…์˜ ๊ฐœ๋…์„ ์„œ๋‘˜๋Ÿฌ ๋งˆ์Šคํ„ฐํ•ด์•ผ ํ•ฉ๋‹ˆ๋‹ค.

๊ธฐ์—…์ด ๊ฐ€๋Šฅํ•œ ํ•œ ์ตœ๋‹จ ์‹œ๊ฐ„ ๋‚ด์— ์ง์›์„ ์œ„ํ•œ ํŽธ๋ฆฌํ•˜๊ณ  ์•ˆ์ „ํ•˜๋ฉฐ ํ™•์žฅ ๊ฐ€๋Šฅํ•œ VPN ์•ก์„ธ์Šค๋ฅผ ๋‹ฌ์„ฑํ•  ์ˆ˜ ์žˆ๋„๋ก Cisco๋Š” ์ตœ๋Œ€ 13์ฃผ ๋™์•ˆ ํ’๋ถ€ํ•œ ๊ธฐ๋Šฅ์˜ AnyConnect SSL VPN ํด๋ผ์ด์–ธํŠธ์— ๋ผ์ด์„ผ์Šค๋ฅผ ๋ถ€์—ฌํ•ฉ๋‹ˆ๋‹ค. ๊ณต์ธ ํŒŒํŠธ๋„ˆ ๋˜๋Š” ํ•จ๊ป˜ ์ผํ•˜๋Š” Cisco ๋‹ด๋‹น์ž์—๊ฒŒ ์—ฐ๋ฝํ•˜์—ฌ ASAv ํ…Œ์ŠคํŠธ(VMWare/Hyper-V/KVM ํ•˜์ดํผ๋ฐ”์ด์ € ๋ฐ AWS/Azure ํด๋ผ์šฐ๋“œ ํ”Œ๋žซํผ์šฉ ๊ฐ€์ƒ ASA)๋ฅผ ๋ฐ›์„ ์ˆ˜๋„ ์žˆ์Šต๋‹ˆ๋‹ค..

AnyConnect COVID-19 ๋ผ์ด์„ ์Šค ๋ฐœ๊ธ‰ ์ ˆ์ฐจ๋Š” ์—ฌ๊ธฐ์— ์„ค๋ช…๋˜์–ด ์žˆ์Šต๋‹ˆ๋‹ค..

๊ฐ€์žฅ ํ™•์žฅ์„ฑ์ด ๋›ฐ์–ด๋‚œ VPN ๊ธฐ์ˆ ์ธ VPN Load-Balancing Cluster์˜ ๊ฐ„๋‹จํ•œ ๋ฐฐํฌ๋ฅผ ์œ„ํ•œ ๋‹จ๊ณ„๋ณ„ ๊ฐ€์ด๋“œ๋ฅผ ์ค€๋น„ํ–ˆ์Šต๋‹ˆ๋‹ค.

์•„๋ž˜์˜ ์˜ˆ๋Š” ์‚ฌ์šฉ๋œ ์ธ์ฆ ๋ฐ ๊ถŒํ•œ ๋ถ€์—ฌ ์•Œ๊ณ ๋ฆฌ์ฆ˜ ์ธก๋ฉด์—์„œ ๋งค์šฐ ๊ฐ„๋‹จํ•˜์ง€๋งŒ ๋ฐฐํฌ ์ค‘ ์š”๊ตฌ ์‚ฌํ•ญ์— ๋Œ€ํ•œ ์‹ฌ์ธต ์ ์‘ ๊ฐ€๋Šฅ์„ฑ๊ณผ ํ•จ๊ป˜ ๋น ๋ฅธ ์‹œ์ž‘(ํ˜„์žฌ ๋งŽ์€ ๊ฒฝ์šฐ ์ถฉ๋ถ„ํ•˜์ง€ ์•Š์Œ)์„ ์œ„ํ•œ ์ข‹์€ ์˜ต์…˜์ด ๋  ๊ฒƒ์ž…๋‹ˆ๋‹ค. ํ”„๋กœ์„ธ์Šค.

๊ฐ„๋žตํ•œ ์ •๋ณด: VPN ๋กœ๋“œ ๋ฐธ๋Ÿฐ์‹ฑ ํด๋Ÿฌ์Šคํ„ฐ ๊ธฐ์ˆ ์€ ๊ธฐ๋ณธ ์˜๋ฏธ์—์„œ ์žฅ์•  ์กฐ์น˜๋‚˜ ํด๋Ÿฌ์Šคํ„ฐ๋ง ๊ธฐ๋Šฅ์ด ์•„๋‹™๋‹ˆ๋‹ค. ์ด ๊ธฐ์ˆ ์€ ์›๊ฒฉ ์•ก์„ธ์Šค VPN ์—ฐ๊ฒฐ์˜ ๋กœ๋“œ ๋ฐธ๋Ÿฐ์‹ฑ์„ ์œ„ํ•ด ์™„์ „ํžˆ ๋‹ค๋ฅธ ASA ๋ชจ๋ธ(ํŠน์ • ์ œํ•œ ์žˆ์Œ)์„ ๊ฒฐํ•ฉํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ์ด๋Ÿฌํ•œ ํด๋Ÿฌ์Šคํ„ฐ์˜ ๋…ธ๋“œ ๊ฐ„์—๋Š” ์„ธ์…˜ ๋ฐ ๊ตฌ์„ฑ์˜ ๋™๊ธฐํ™”๊ฐ€ ์—†์ง€๋งŒ ํด๋Ÿฌ์Šคํ„ฐ์— ์ตœ์†Œํ•œ ํ•˜๋‚˜์˜ ํ™œ์„ฑ ๋…ธ๋“œ๊ฐ€ ๋‚จ์„ ๋•Œ๊นŒ์ง€ ์ž๋™์œผ๋กœ VPN ์—ฐ๊ฒฐ์˜ ๋ถ€ํ•˜๋ฅผ ๋ถ„์‚ฐํ•˜๊ณ  VPN ์—ฐ๊ฒฐ์˜ ๋‚ด๊ฒฐํ•จ์„ฑ์„ ๋ณด์žฅํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ํด๋Ÿฌ์Šคํ„ฐ์˜ ๋กœ๋“œ๋Š” VPN ์„ธ์…˜ ์ˆ˜์— ๋”ฐ๋ผ ๋…ธ๋“œ์˜ ์›Œํฌ๋กœ๋“œ์— ๋”ฐ๋ผ ์ž๋™์œผ๋กœ ๊ท ํ˜•์„ ์ด๋ฃน๋‹ˆ๋‹ค.

ํด๋Ÿฌ์Šคํ„ฐ์˜ ํŠน์ • ๋…ธ๋“œ์— ๋Œ€ํ•œ ์žฅ์•  ์กฐ์น˜(ํ•„์š”ํ•œ ๊ฒฝ์šฐ)์˜ ๊ฒฝ์šฐ ํŒŒ์ผ๋Ÿฌ๋ฅผ ์‚ฌ์šฉํ•  ์ˆ˜ ์žˆ์œผ๋ฏ€๋กœ ํŒŒ์ผ๋Ÿฌ์˜ ๊ธฐ๋ณธ ๋…ธ๋“œ์—์„œ ํ™œ์„ฑ ์—ฐ๊ฒฐ์„ ์ฒ˜๋ฆฌํ•ฉ๋‹ˆ๋‹ค. ํŒŒ์ผ ์˜ค๋ฒ„๋Š” ๋กœ๋“œ ๋ฐธ๋Ÿฐ์‹ฑ ํด๋Ÿฌ์Šคํ„ฐ ๋‚ด ๋‚ด๊ฒฐํ•จ์„ฑ์„ ๋ณด์žฅํ•˜๊ธฐ ์œ„ํ•œ ํ•„์ˆ˜ ์กฐ๊ฑด์ด ์•„๋‹ˆ๋ฉฐ, ํด๋Ÿฌ์Šคํ„ฐ ์ž์ฒด๋Š” ๋…ธ๋“œ ์žฅ์• ๊ฐ€ ๋ฐœ์ƒํ•  ๊ฒฝ์šฐ ์‚ฌ์šฉ์ž ์„ธ์…˜์„ ๋‹ค๋ฅธ ๋ผ์ด๋ธŒ ๋…ธ๋“œ๋กœ ์ „์†กํ•˜์ง€๋งŒ ์—ฐ๊ฒฐ ์ƒํƒœ๋ฅผ ์ €์žฅํ•˜์ง€ ์•Š์Šต๋‹ˆ๋‹ค. ํŒŒ์ผ๋Ÿฌ ์ œ๊ณต. ๋”ฐ๋ผ์„œ ํ•„์š”์— ๋”ฐ๋ผ ์ด ๋‘ ๊ฐ€์ง€ ๊ธฐ์ˆ ์„ ๊ฒฐํ•ฉํ•˜๋Š” ๊ฒƒ๋„ ๊ฐ€๋Šฅํ•˜๋‹ค.

VPN ๋กœ๋“œ ๋ฐธ๋Ÿฐ์‹ฑ ํด๋Ÿฌ์Šคํ„ฐ๋Š” XNUMX๊ฐœ ์ด์ƒ์˜ ๋…ธ๋“œ๋ฅผ ํฌํ•จํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

VPN ๋ถ€ํ•˜ ๋ถ„์‚ฐ ํด๋Ÿฌ์Šคํ„ฐ๋Š” ASA 5512-X ์ด์ƒ์—์„œ ์ง€์›๋ฉ๋‹ˆ๋‹ค.

VPN ๋กœ๋“œ ๋ฐธ๋Ÿฐ์‹ฑ ํด๋Ÿฌ์Šคํ„ฐ ๋‚ด์˜ ๊ฐ ASA๋Š” ์„ค์ • ์ธก๋ฉด์—์„œ ๋…๋ฆฝ์ ์ธ ๋‹จ์œ„์ด๋ฏ€๋กœ ๊ฐ ๊ฐœ๋ณ„ ์žฅ์น˜์—์„œ ๋ชจ๋“  ๊ตฌ์„ฑ ๋‹จ๊ณ„๋ฅผ ๊ฐœ๋ณ„์ ์œผ๋กœ ์ˆ˜ํ–‰ํ•ฉ๋‹ˆ๋‹ค.

๊ธฐ์ˆ  ์„ธ๋ถ€ ์ •๋ณด๋Š” ์—ฌ๊ธฐ

์ฃผ์–ด์ง„ ์˜ˆ์˜ ๋…ผ๋ฆฌ์  ํ† ํด๋กœ์ง€:

ASA VPN ๋กœ๋“œ ๋ฐธ๋Ÿฐ์‹ฑ ํด๋Ÿฌ์Šคํ„ฐ ๋ฐฐํฌ

๊ธฐ๋ณธ ๋ฐฐํฌ:

  1. ์ด๋ฏธ์ง€์—์„œ ํ•„์š”ํ•œ ํ…œํ”Œ๋ฆฟ(ASAv5/10/30/50)์˜ ASAv ์ธ์Šคํ„ด์Šค๋ฅผ ๋ฐฐํฌํ•ฉ๋‹ˆ๋‹ค.

  2. ์šฐ๋ฆฌ๋Š” INSIDE / OUTSIDE ์ธํ„ฐํŽ˜์ด์Šค๋ฅผ ๋™์ผํ•œ VLAN์— ํ• ๋‹นํ•ฉ๋‹ˆ๋‹ค(์ž์ฒด VLAN์˜ ์™ธ๋ถ€, ์ž์ฒด์˜ INSIDE, ๊ทธ๋Ÿฌ๋‚˜ ์ผ๋ฐ˜์ ์œผ๋กœ ํด๋Ÿฌ์Šคํ„ฐ ๋‚ด, ํ† ํด๋กœ์ง€ ์ฐธ์กฐ). ๋™์ผํ•œ ์œ ํ˜•์˜ ์ธํ„ฐํŽ˜์ด์Šค๊ฐ€ ๋™์ผํ•œ L2 ์„ธ๊ทธ๋จผํŠธ์— ์žˆ๋Š” ๊ฒƒ์ด ์ค‘์š”ํ•ฉ๋‹ˆ๋‹ค.

  3. ๋ผ์ด์„ผ์Šค:

    • ํ˜„์žฌ ASAv ์„ค์น˜์—๋Š” ๋ผ์ด์„ผ์Šค๊ฐ€ ์—†์œผ๋ฉฐ 100kbps๋กœ ์ œํ•œ๋ฉ๋‹ˆ๋‹ค.
    • ๋ผ์ด์„ ์Šค๋ฅผ ์„ค์น˜ํ•˜๋ ค๋ฉด ์Šค๋งˆํŠธ ๊ณ„์ •์—์„œ ํ† ํฐ์„ ์ƒ์„ฑํ•ด์•ผ ํ•ฉ๋‹ˆ๋‹ค. https://software.cisco.com/ -> ์Šค๋งˆํŠธ ์†Œํ”„ํŠธ์›จ์–ด ๋ผ์ด์„ ์Šค
    • ์—ด๋ฆฌ๋Š” ์ฐฝ์—์„œ ๋ฒ„ํŠผ์„ ํด๋ฆญํ•˜์‹ญ์‹œ์˜ค. ์ƒˆ๋กœ์šด ํ† ํฐ

    ASA VPN ๋กœ๋“œ ๋ฐธ๋Ÿฐ์‹ฑ ํด๋Ÿฌ์Šคํ„ฐ ๋ฐฐํฌ

    • ์—ด๋ฆฌ๋Š” ์ฐฝ์— ํ™œ์„ฑ ํ•„๋“œ๊ฐ€ ์žˆ๊ณ  ํ™•์ธ ํ‘œ์‹œ๊ฐ€ ์„ ํƒ๋˜์–ด ์žˆ๋Š”์ง€ ํ™•์ธํ•˜์‹ญ์‹œ์˜ค. ์ˆ˜์ถœ ํ†ต์ œ ๊ธฐ๋Šฅ ํ—ˆ์šฉโ€ฆ ์ด ํ•„๋“œ๊ฐ€ ํ™œ์„ฑํ™”๋˜์–ด ์žˆ์ง€ ์•Š์œผ๋ฉด ๊ฐ•๋ ฅํ•œ ์•”ํ˜ธํ™” ๋ฐ ๊ทธ์— ๋”ฐ๋ฅธ VPN ๊ธฐ๋Šฅ์„ ์‚ฌ์šฉํ•  ์ˆ˜ ์—†์Šต๋‹ˆ๋‹ค. ์ด ํ•„๋“œ๊ฐ€ ํ™œ์„ฑํ™”๋˜์ง€ ์•Š์€ ๊ฒฝ์šฐ ํ™œ์„ฑํ™” ์š”์ฒญ๊ณผ ํ•จ๊ป˜ ๊ณ„์ • ํŒ€์— ๋ฌธ์˜ํ•˜์‹ญ์‹œ์˜ค.

    ASA VPN ๋กœ๋“œ ๋ฐธ๋Ÿฐ์‹ฑ ํด๋Ÿฌ์Šคํ„ฐ ๋ฐฐํฌ

    • ๋ฒ„ํŠผ์„ ๋ˆ„๋ฅธ ํ›„ ํ† ํฐ ์ƒ์„ฑ, ASAv์— ๋Œ€ํ•œ ๋ผ์ด์„ผ์Šค๋ฅผ ์–ป๋Š” ๋ฐ ์‚ฌ์šฉํ•  ํ† ํฐ์ด ์ƒ์„ฑ๋ฉ๋‹ˆ๋‹ค. ๋ณต์‚ฌํ•˜์‹ญ์‹œ์˜ค.

    ASA VPN ๋กœ๋“œ ๋ฐธ๋Ÿฐ์‹ฑ ํด๋Ÿฌ์Šคํ„ฐ ๋ฐฐํฌ

    • ๋ฐฐํฌ๋œ ๊ฐ ASAv์— ๋Œ€ํ•ด C, D, E ๋‹จ๊ณ„๋ฅผ ๋ฐ˜๋ณตํ•ฉ๋‹ˆ๋‹ค.
    • ํ† ํฐ์„ ๋” ์‰ฝ๊ฒŒ ๋ณต์‚ฌํ•  ์ˆ˜ ์žˆ๋„๋ก ์ž„์‹œ๋กœ telnet์„ ํ—ˆ์šฉํ•ด ๋ณด๊ฒ ์Šต๋‹ˆ๋‹ค. ๊ฐ ASA๋ฅผ ๊ตฌ์„ฑํ•ด ๋ณด๊ฒ ์Šต๋‹ˆ๋‹ค(์•„๋ž˜ ์˜ˆ๋Š” ASA-1์˜ ์„ค์ •์„ ๋ณด์—ฌ์ค๋‹ˆ๋‹ค). ํ…”๋„ท์€ ์™ธ๋ถ€์—์„œ ์ž‘๋™ํ•˜์ง€ ์•Š์Šต๋‹ˆ๋‹ค. ์ •๋ง ํ•„์š”ํ•˜๋‹ค๋ฉด ์™ธ๋ถ€์—์„œ ๋ณด์•ˆ ์ˆ˜์ค€์„ 100์œผ๋กœ ๋ณ€๊ฒฝํ•œ ๋‹ค์Œ ๋‹ค์‹œ ๋˜๋Œ๋ฆฌ์‹ญ์‹œ์˜ค.

    !
    ciscoasa(config)# int gi0/0
    ciscoasa(config)# nameif outside
    ciscoasa(config)# ip address 192.168.31.30 255.255.255.0
    ciscoasa(config)# no shut
    !
    ciscoasa(config)# int gi0/1
    ciscoasa(config)# nameif inside
    ciscoasa(config)# ip address 192.168.255.2 255.255.255.0
    ciscoasa(config)# no shut
    !
    ciscoasa(config)# telnet 0 0 inside
    ciscoasa(config)# username admin password cisco priv 15
    ciscoasa(config)# ena password cisco
    ciscoasa(config)# aaa authentication telnet console LOCAL
    !
    ciscoasa(config)# route outside 0 0 192.168.31.1
    !
    ciscoasa(config)# wr
    !

    • Smart-Account ํด๋ผ์šฐ๋“œ์— ํ† ํฐ์„ ๋“ฑ๋กํ•˜๋ ค๋ฉด ASA์— ๋Œ€ํ•œ ์ธํ„ฐ๋„ท ์•ก์„ธ์Šค๋ฅผ ์ œ๊ณตํ•ด์•ผ ํ•ฉ๋‹ˆ๋‹ค. ์ž์„ธํ•œ ๋‚ด์šฉ์€ ์—ฌ๊ธฐ.

    ์ฆ‰, ASA๊ฐ€ ํ•„์š”ํ•ฉ๋‹ˆ๋‹ค.

    • HTTPS๋ฅผ ํ†ตํ•œ ์ธํ„ฐ๋„ท ์•ก์„ธ์Šค
    • ์‹œ๊ฐ„ ๋™๊ธฐํ™”(๋ณด๋‹ค ์ •ํ™•ํ•˜๊ฒŒ๋Š” NTP๋ฅผ ํ†ตํ•ด)
    • ๋“ฑ๋ก๋œ DNS ์„œ๋ฒ„;
      • ASA์— ํ…”๋„ท์œผ๋กœ ์—ฐ๊ฒฐํ•˜๊ณ  Smart-Account๋ฅผ ํ†ตํ•ด ๋ผ์ด์„ ์Šค๋ฅผ ํ™œ์„ฑํ™”ํ•˜๋„๋ก ์„ค์ •ํ•ฉ๋‹ˆ๋‹ค.

    !
    ciscoasa(config)# clock set 19:21:00 Mar 18 2020
    ciscoasa(config)# clock timezone MSK 3
    ciscoasa(config)# ntp server 192.168.99.136
    !
    ciscoasa(config)# dns domain-lookup outside
    ciscoasa(config)# DNS server-group DefaultDNS
    ciscoasa(config-dns-server-group)# name-server 192.168.99.132 
    !
    ! ะŸั€ะพะฒะตั€ะธะผ ั€ะฐะฑะพั‚ัƒ DNS:
    !
    ciscoasa(config-dns-server-group)# ping ya.ru
    Type escape sequence to abort.
    Sending 5, 100-byte ICMP Echos to 87.250.250.242, timeout is 2 seconds:
    !!!!!
    !
    ! ะŸั€ะพะฒะตั€ะธะผ ัะธะฝั…ั€ะพะฝะธะทะฐั†ะธัŽ NTP:
    !
    ciscoasa(config)# show ntp associations 
      address         ref clock     st  when  poll reach  delay  offset    disp
    *~192.168.99.136   91.189.94.4       3    63    64    1    36.7    1.85    17.5
    * master (synced), # master (unsynced), + selected, - candidate, ~ configured
    !
    ! ะฃัั‚ะฐะฝะพะฒะธะผ ะบะพะฝั„ะธะณัƒั€ะฐั†ะธัŽ ะฝะฐัˆะตะน ASAv ะดะปั Smart-Licensing (ะฒ ัะพะพั‚ะฒะตั‚ัั‚ะฒะธะธ ั ะ’ะฐัˆะธะผ ะฟั€ะพั„ะธะปะตะผ, ะฒ ะผะพะตะผ ัะปัƒั‡ะฐะต 100ะœ ะดะปั ะฟั€ะธะผะตั€ะฐ)
    !
    ciscoasa(config)# license smart
    ciscoasa(config-smart-lic)# feature tier standard
    ciscoasa(config-smart-lic)# throughput level 100M
    !
    ! ะ’ ัะปัƒั‡ะฐะต ะฝะตะพะฑั…ะพะดะธะผะพัั‚ะธ ะผะพะถะฝะพ ะฝะฐัั‚ั€ะพะธั‚ัŒ ะดะพัั‚ัƒะฟ ะฒ ะ˜ะฝั‚ะตั€ะฝะตั‚ ั‡ะตั€ะตะท ะฟั€ะพะบัะธ ะธัะฟะพะปัŒะทัƒะนั‚ะต ัะปะตะดัƒัŽั‰ะธะน ะฑะปะพะบ ะบะพะผะฐะฝะด:
    !call-home
    !  http-proxy ip_address port port
    !
    ! ะ”ะฐะปะตะต ะผั‹ ะฒัั‚ะฐะฒะปัะตะผ ัะบะพะฟะธั€ะพะฒะฐะฝะฝั‹ะน ะธะท ะฟะพั€ั‚ะฐะปะฐ Smart-Account ั‚ะพะบะตะฝ (<token>) ะธ ั€ะตะณะธัั‚ั€ะธั€ัƒะตะผ ะปะธั†ะตะฝะทะธัŽ
    !
    ciscoasa(config)# end
    ciscoasa# license smart register idtoken <token>

    • ์žฅ์น˜๊ฐ€ ๋ผ์ด์„ ์Šค๋ฅผ ์„ฑ๊ณต์ ์œผ๋กœ ๋“ฑ๋กํ–ˆ๊ณ  ์•”ํ˜ธํ™” ์˜ต์…˜์„ ์‚ฌ์šฉํ•  ์ˆ˜ ์žˆ๋Š”์ง€ ํ™•์ธํ•ฉ๋‹ˆ๋‹ค.

    ASA VPN ๋กœ๋“œ ๋ฐธ๋Ÿฐ์‹ฑ ํด๋Ÿฌ์Šคํ„ฐ ๋ฐฐํฌ

    ASA VPN ๋กœ๋“œ ๋ฐธ๋Ÿฐ์‹ฑ ํด๋Ÿฌ์Šคํ„ฐ ๋ฐฐํฌ

  4. ๊ฐ ๊ฒŒ์ดํŠธ์›จ์ด์—์„œ ๊ธฐ๋ณธ SSL-VPN ์„ค์ •

    • ๊ทธ๋Ÿฐ ๋‹ค์Œ SSH ๋ฐ ASDM์„ ํ†ตํ•ด ์•ก์„ธ์Šค๋ฅผ ๊ตฌ์„ฑํ•ฉ๋‹ˆ๋‹ค.

    ciscoasa(config)# ssh ver 2
    ciscoasa(config)# aaa authentication ssh console LOCAL
    ciscoasa(config)# aaa authentication http console LOCAL
    ciscoasa(config)# hostname vpn-demo-1
    vpn-demo-1(config)# domain-name ashes.cc
    vpn-demo-1(config)# cry key gen rsa general-keys modulus 4096 
    vpn-demo-1(config)# ssh 0 0 inside  
    vpn-demo-1(config)# http 0 0 inside
    !
    ! ะŸะพะดะฝะธะผะตะผ ัะตั€ะฒะตั€ HTTPS ะดะปั ASDM ะฝะฐ ะฟะพั€ั‚ัƒ 445 ั‡ั‚ะพะฑั‹ ะฝะต ะฟะตั€ะตัะตะบะฐั‚ัŒัั ั SSL-VPN ะฟะพั€ั‚ะฐะปะพะผ
    !
    vpn-demo-1(config)# http server enable 445 
    !

    • ASDM์ด ์ž‘๋™ํ•˜๋ ค๋ฉด ๋จผ์ € cisco.com ์›น ์‚ฌ์ดํŠธ์—์„œ ๋‹ค์šด๋กœ๋“œํ•ด์•ผ ํ•ฉ๋‹ˆ๋‹ค. ์ œ ๊ฒฝ์šฐ์—๋Š” ๋‹ค์Œ ํŒŒ์ผ์ž…๋‹ˆ๋‹ค.

    ASA VPN ๋กœ๋“œ ๋ฐธ๋Ÿฐ์‹ฑ ํด๋Ÿฌ์Šคํ„ฐ ๋ฐฐํฌ

    • AnyConnect ํด๋ผ์ด์–ธํŠธ๊ฐ€ ์ž‘๋™ํ•˜๋ ค๋ฉด ์‚ฌ์šฉ๋œ ๊ฐ ํด๋ผ์ด์–ธํŠธ ๋ฐ์Šคํฌํ†ฑ OS(Linux/Windows/MAC ์‚ฌ์šฉ ๊ณ„ํš)์— ๋Œ€ํ•ด ๊ฐ ASA์— ์ด๋ฏธ์ง€๋ฅผ ์—…๋กœ๋“œํ•ด์•ผ ํ•ฉ๋‹ˆ๋‹ค. ํ—ค๋“œ์—”๋“œ ๋ฐฐํฌ ํŒจํ‚ค์ง€ ์ œ๋ชฉ์—์„œ:

    ASA VPN ๋กœ๋“œ ๋ฐธ๋Ÿฐ์‹ฑ ํด๋Ÿฌ์Šคํ„ฐ ๋ฐฐํฌ

    • ๋‹ค์šด๋กœ๋“œํ•œ ํŒŒ์ผ์€ ์˜ˆ๋ฅผ ๋“ค์–ด FTP ์„œ๋ฒ„์— ์—…๋กœ๋“œํ•˜๊ณ  ๊ฐ ๊ฐœ๋ณ„ ASA์— ์—…๋กœ๋“œํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

    ASA VPN ๋กœ๋“œ ๋ฐธ๋Ÿฐ์‹ฑ ํด๋Ÿฌ์Šคํ„ฐ ๋ฐฐํฌ

    • SSL-VPN์— ๋Œ€ํ•œ ASDM ๋ฐ ์ž์ฒด ์„œ๋ช… ์ธ์ฆ์„œ๋ฅผ ๊ตฌ์„ฑํ•ฉ๋‹ˆ๋‹ค(ํ”„๋กœ๋•์…˜์—์„œ ์‹ ๋ขฐํ•  ์ˆ˜ ์žˆ๋Š” ์ธ์ฆ์„œ ์‚ฌ์šฉ ๊ถŒ์žฅ). ๊ฐ€์ƒ ํด๋Ÿฌ์Šคํ„ฐ ์ฃผ์†Œ(vpn-demo.ashes.cc)์˜ ์„ค์ •๋œ FQDN๊ณผ ๊ฐ ํด๋Ÿฌ์Šคํ„ฐ ๋…ธ๋“œ์˜ ์™ธ๋ถ€ ์ฃผ์†Œ์™€ ์—ฐ๊ฒฐ๋œ ๊ฐ FQDN์€ ์™ธ๋ถ€ DNS ์˜์—ญ์—์„œ OUTSIDE ์ธํ„ฐํŽ˜์ด์Šค์˜ IP ์ฃผ์†Œ(๋˜๋Š” ํฌํŠธ ํฌ์›Œ๋”ฉ udp/443(DTLS) ๋ฐ tcp/443(TLS)์„ ์‚ฌ์šฉํ•˜๋Š” ๊ฒฝ์šฐ ๋งคํ•‘๋œ ์ฃผ์†Œ๋กœ). ์ธ์ฆ์„œ ์š”๊ตฌ ์‚ฌํ•ญ์— ๋Œ€ํ•œ ์ž์„ธํ•œ ์ •๋ณด๋Š” ์„น์…˜์— ์ง€์ •๋˜์–ด ์žˆ์Šต๋‹ˆ๋‹ค. ์ธ์ฆ์„œ ํ™•์ธ ์„ ์  ์„œ๋ฅ˜ ๋น„์น˜.

    !
    vpn-demo-1(config)# crypto ca trustpoint SELF
    vpn-demo-1(config-ca-trustpoint)# enrollment self
    vpn-demo-1(config-ca-trustpoint)# fqdn vpn-demo.ashes.cc
    vpn-demo-1(config-ca-trustpoint)# subject-name cn=*.ashes.cc, ou=ashes-lab, o=ashes, c=ru
    vpn-demo-1(config-ca-trustpoint)# serial-number             
    vpn-demo-1(config-ca-trustpoint)# crl configure
    vpn-demo-1(config-ca-crl)# cry ca enroll SELF
    % The fully-qualified domain name in the certificate will be: vpn-demo.ashes.cc
    Generate Self-Signed Certificate? [yes/no]: yes
    vpn-demo-1(config)# 
    !
    vpn-demo-1(config)# sh cry ca certificates 
    Certificate
    Status: Available
    Certificate Serial Number: 4d43725e
    Certificate Usage: General Purpose
    Public Key Type: RSA (4096 bits)
    Signature Algorithm: SHA256 with RSA Encryption
    Issuer Name: 
    serialNumber=9A439T02F95
    hostname=vpn-demo.ashes.cc
    cn=*.ashes.cc
    ou=ashes-lab
    o=ashes
    c=ru
    Subject Name:
    serialNumber=9A439T02F95
    hostname=vpn-demo.ashes.cc
    cn=*.ashes.cc
    ou=ashes-lab
    o=ashes
    c=ru
    Validity Date: 
    start date: 00:16:17 MSK Mar 19 2020
    end   date: 00:16:17 MSK Mar 17 2030
    Storage: config
    Associated Trustpoints: SELF 
    
    CA Certificate
    Status: Available
    Certificate Serial Number: 0509
    Certificate Usage: General Purpose
    Public Key Type: RSA (4096 bits)
    Signature Algorithm: SHA1 with RSA Encryption
    Issuer Name: 
    cn=QuoVadis Root CA 2
    o=QuoVadis Limited
    c=BM
    Subject Name: 
    cn=QuoVadis Root CA 2
    o=QuoVadis Limited
    c=BM
    Validity Date: 
    start date: 21:27:00 MSK Nov 24 2006
    end   date: 21:23:33 MSK Nov 24 2031
    Storage: config
    Associated Trustpoints: _SmartCallHome_ServerCA               

    • ASDM์ด ์ž‘๋™ํ•˜๋Š”์ง€ ํ™•์ธํ•˜๊ธฐ ์œ„ํ•ด ํฌํŠธ๋ฅผ ์ง€์ •ํ•˜๋Š” ๊ฒƒ์„ ์žŠ์ง€ ๋งˆ์‹ญ์‹œ์˜ค. ์˜ˆ๋ฅผ ๋“ค๋ฉด ๋‹ค์Œ๊ณผ ๊ฐ™์Šต๋‹ˆ๋‹ค.

    ASA VPN ๋กœ๋“œ ๋ฐธ๋Ÿฐ์‹ฑ ํด๋Ÿฌ์Šคํ„ฐ ๋ฐฐํฌ

    • ํ„ฐ๋„์˜ ๊ธฐ๋ณธ ์„ค์ •์„ ์ˆ˜ํ–‰ํ•ด ๋ณด๊ฒ ์Šต๋‹ˆ๋‹ค.
    • ํ„ฐ๋„์„ ํ†ตํ•ด ํšŒ์‚ฌ ๋„คํŠธ์›Œํฌ๋ฅผ ์‚ฌ์šฉํ•  ์ˆ˜ ์žˆ๊ฒŒ ํ•˜๊ณ , ์ธํ„ฐ๋„ท์ด ์ง์ ‘ ๊ฐ€๋„๋ก ํ•ฉ์‹œ๋‹ค(์—ฐ๊ฒฐํ•˜๋Š” ํ˜ธ์ŠคํŠธ์— ๋ณดํ˜ธ ์žฅ์น˜๊ฐ€ ์—†์œผ๋ฉด ๊ฐ€์žฅ ์•ˆ์ „ํ•œ ๋ฐฉ๋ฒ•์ด ์•„๋‹ˆ๋ฉฐ, ๊ฐ์—ผ๋œ ํ˜ธ์ŠคํŠธ๋ฅผ ํ†ตํ•ด ์นจํˆฌํ•˜์—ฌ ํšŒ์‚ฌ ๋ฐ์ดํ„ฐ๋ฅผ ํ‘œ์‹œํ•  ์ˆ˜ ์žˆ์Œ, ์˜ต์…˜ ๋ถ„ํ•  ํ„ฐ๋„ ์ •์ฑ… tunnelall ๋ชจ๋“  ํ˜ธ์ŠคํŠธ ํŠธ๋ž˜ํ”ฝ์„ ํ„ฐ๋„๋กœ ํ—ˆ์šฉํ•ฉ๋‹ˆ๋‹ค. ๊ทธ๋Ÿผ์—๋„ ๋ถˆ๊ตฌํ•˜๊ณ  ๋ถ„ํ•  ํ„ฐ๋„ VPN ๊ฒŒ์ดํŠธ์›จ์ด๋ฅผ ์˜คํ”„๋กœ๋“œํ•˜๊ณ  ํ˜ธ์ŠคํŠธ ์ธํ„ฐ๋„ท ํŠธ๋ž˜ํ”ฝ์„ ์ฒ˜๋ฆฌํ•˜์ง€ ์•Š๋„๋ก ํ•จ)
    • 192.168.20.0/24 ์„œ๋ธŒ๋„ท์—์„œ ํ„ฐ๋„์˜ ํ˜ธ์ŠคํŠธ๋กœ ์ฃผ์†Œ๋ฅผ ๋ฐœ๊ธ‰ํ•ด ๋ด…์‹œ๋‹ค(10~30๊ฐœ์˜ ์ฃผ์†Œ ํ’€๋ง(๋…ธ๋“œ #1์˜ ๊ฒฝ์šฐ)). VPN ํด๋Ÿฌ์Šคํ„ฐ์˜ ๊ฐ ๋…ธ๋“œ์—๋Š” ์ž์ฒด ํ’€์ด ์žˆ์–ด์•ผ ํ•ฉ๋‹ˆ๋‹ค.
    • ASA์—์„œ ๋กœ์ปฌ๋กœ ์ƒ์„ฑ๋œ ์‚ฌ์šฉ์ž๋กœ ๊ธฐ๋ณธ ์ธ์ฆ์„ ์ˆ˜ํ–‰ํ•ฉ๋‹ˆ๋‹ค(๊ถŒ์žฅํ•˜์ง€ ์•Š์Œ, ๊ฐ€์žฅ ์‰ฌ์šด ๋ฐฉ๋ฒ•). LDAP/๋ฐ˜๊ฒฝ, ๋˜๋Š” ๋” ๋‚˜์€ ์•„์ง, ๋„ฅํƒ€์ด ๋‹ค์ค‘ ์ธ์ฆ(MFA)์˜ˆ๋ฅผ ๋“ค์–ด ์‹œ์Šค์ฝ” ๋“€์˜ค.

    !
    vpn-demo-1(config)# ip local pool vpn-pool 192.168.20.10-192.168.20.30 mask 255.255.255.0
    !
    vpn-demo-1(config)# access-list split-tunnel standard permit 192.168.0.0 255.255.0.0
    !
    vpn-demo-1(config)# group-policy SSL-VPN-GROUP-POLICY internal
    vpn-demo-1(config)# group-policy SSL-VPN-GROUP-POLICY attributes
    vpn-demo-1(config-group-policy)# vpn-tunnel-protocol ssl-client 
    vpn-demo-1(config-group-policy)# split-tunnel-policy tunnelspecified
    vpn-demo-1(config-group-policy)# split-tunnel-network-list value split-tunnel
    vpn-demo-1(config-group-policy)# dns-server value 192.168.99.132
    vpn-demo-1(config-group-policy)# default-domain value ashes.cc
    vpn-demo-1(config)# tunnel-group DefaultWEBVPNGroup general-attributes
    vpn-demo-1(config-tunnel-general)#  default-group-policy SSL-VPN-GROUP-POLICY
    vpn-demo-1(config-tunnel-general)#  address-pool vpn-pool
    !
    vpn-demo-1(config)# username dkazakov password cisco
    vpn-demo-1(config)# username dkazakov attributes
    vpn-demo-1(config-username)# service-type remote-access
    !
    vpn-demo-1(config)# ssl trust-point SELF
    vpn-demo-1(config)# webvpn
    vpn-demo-1(config-webvpn)#  enable outside
    vpn-demo-1(config-webvpn)#  anyconnect image disk0:/anyconnect-win-4.8.03036-webdeploy-k9.pkg
    vpn-demo-1(config-webvpn)#  anyconnect enable
    !

    • (์„ ํƒ ๊ณผ๋ชฉ): ์œ„์˜ ์˜ˆ์—์„œ๋Š” ์›๊ฒฉ ์‚ฌ์šฉ์ž๋ฅผ ์ธ์ฆํ•˜๊ธฐ ์œ„ํ•ด ITU์˜ ๋กœ์ปฌ ์‚ฌ์šฉ์ž๋ฅผ ์‚ฌ์šฉํ–ˆ๋Š”๋ฐ, ๋ฌผ๋ก  ์‹คํ—˜์‹ค์„ ์ œ์™ธํ•˜๊ณ ๋Š” ์ ์šฉํ•˜๊ธฐ๊ฐ€ ์–ด๋ ต์Šต๋‹ˆ๋‹ค. ์ธ์ฆ์„ ์œ„ํ•œ ์„ค์ •์„ ๋ฐ˜์ง€๋ฆ„ ์˜ˆ๋ฅผ ๋“ค์–ด ์‚ฌ์šฉ๋˜๋Š” ์„œ๋ฒ„ Cisco ID ์„œ๋น„์Šค ์—”์ง„:

    vpn-demo-1(config-aaa-server-group)# dynamic-authorization
    vpn-demo-1(config-aaa-server-group)# interim-accounting-update
    vpn-demo-1(config-aaa-server-group)# aaa-server RADIUS (outside) host 192.168.99.134
    vpn-demo-1(config-aaa-server-host)# key cisco
    vpn-demo-1(config-aaa-server-host)# exit
    vpn-demo-1(config)# tunnel-group DefaultWEBVPNGroup general-attributes
    vpn-demo-1(config-tunnel-general)# authentication-server-group  RADIUS 
    !

    ์ด ํ†ตํ•ฉ์„ ํ†ตํ•ด ์ธ์ฆ ์ ˆ์ฐจ๋ฅผ AD ๋””๋ ‰ํ„ฐ๋ฆฌ ์„œ๋น„์Šค์™€ ๋น ๋ฅด๊ฒŒ ํ†ตํ•ฉํ•  ์ˆ˜ ์žˆ์„ ๋ฟ๋งŒ ์•„๋‹ˆ๋ผ ์—ฐ๊ฒฐ๋œ ์ปดํ“จํ„ฐ๊ฐ€ AD์— ์†ํ•˜๋Š”์ง€ ์—ฌ๋ถ€๋ฅผ ๊ตฌ๋ถ„ํ•˜๊ณ  ์ด ์žฅ์น˜๊ฐ€ ํšŒ์‚ฌ์ธ์ง€ ๊ฐœ์ธ์ธ์ง€ ์ดํ•ดํ•˜๊ณ  ์—ฐ๊ฒฐ๋œ ์žฅ์น˜์˜ ์ƒํƒœ๋ฅผ ํ‰๊ฐ€ํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. .

    ASA VPN ๋กœ๋“œ ๋ฐธ๋Ÿฐ์‹ฑ ํด๋Ÿฌ์Šคํ„ฐ ๋ฐฐํฌ

    ASA VPN ๋กœ๋“œ ๋ฐธ๋Ÿฐ์‹ฑ ํด๋Ÿฌ์Šคํ„ฐ ๋ฐฐํฌ

    • ํด๋ผ์ด์–ธํŠธ์™€ ํšŒ์‚ฌ ๋„คํŠธ์›Œํฌ ๋„คํŠธ์›Œํฌ์˜ ๋ฆฌ์†Œ์Šค ๊ฐ„์˜ ํŠธ๋ž˜ํ”ฝ์ด ๊ธฐ๋ก๋˜์ง€ ์•Š๋„๋ก ํˆฌ๋ช… NAT๋ฅผ ๊ตฌ์„ฑํ•ด ๋ณด๊ฒ ์Šต๋‹ˆ๋‹ค.

    vpn-demo-1(config-network-object)#  subnet 192.168.20.0 255.255.255.0
    !
    vpn-demo-1(config)# nat (inside,outside) source static any any destination static vpn-users vpn-users no-proxy-arp

    • (์„ ํƒ ๊ณผ๋ชฉ): ASA๋ฅผ ํ†ตํ•ด ํด๋ผ์ด์–ธํŠธ๋ฅผ ์ธํ„ฐ๋„ท์— ๋…ธ์ถœํ•˜๊ธฐ ์œ„ํ•ด(์‚ฌ์šฉ ์‹œ ํ„ฐ๋„ ์˜ต์…˜) PAT๋ฅผ ์‚ฌ์šฉํ•˜๊ณ  ์—ฐ๊ฒฐ๋œ ๋™์ผํ•œ OUTSIDE ์ธํ„ฐํŽ˜์ด์Šค๋ฅผ ํ†ตํ•ด ์ข…๋ฃŒํ•˜๋ ค๋ฉด ๋‹ค์Œ ์„ค์ •์„ ์ง€์ •ํ•ด์•ผ ํ•ฉ๋‹ˆ๋‹ค.

    vpn-demo-1(config-network-object)# nat (outside,outside) source dynamic vpn-users interface
    vpn-demo-1(config)# nat (inside,outside) source dynamic any interface
    vpn-demo-1(config)# same-security-traffic permit intra-interface 
    !

    • ํด๋Ÿฌ์Šคํ„ฐ๋ฅผ ์‚ฌ์šฉํ•  ๋•Œ ์–ด๋–ค ASA๊ฐ€ ์‚ฌ์šฉ์ž์—๊ฒŒ ๋ฐ˜ํ™˜ ํŠธ๋ž˜ํ”ฝ์„ ๋ผ์šฐํŒ…ํ• ์ง€ ์ดํ•ดํ•˜๋„๋ก ๋‚ด๋ถ€ ๋„คํŠธ์›Œํฌ๋ฅผ ํ™œ์„ฑํ™”ํ•˜๋Š” ๊ฒƒ์ด ๋งค์šฐ ์ค‘์š”ํ•ฉ๋‹ˆ๋‹ค. ์ด๋ฅผ ์œ„ํ•ด ํด๋ผ์ด์–ธํŠธ์— ๋ฐœ๊ธ‰๋œ ๊ฒฝ๋กœ/32 ์ฃผ์†Œ๋ฅผ ์žฌ๋ถ„๋ฐฐํ•ด์•ผ ํ•ฉ๋‹ˆ๋‹ค.
      ์ง€๊ธˆ์€ ์•„์ง ํด๋Ÿฌ์Šคํ„ฐ๋ฅผ ๊ตฌ์„ฑํ•˜์ง€ ์•Š์•˜์ง€๋งŒ FQDN ๋˜๋Š” IP๋ฅผ ํ†ตํ•ด ๊ฐœ๋ณ„์ ์œผ๋กœ ์—ฐ๊ฒฐํ•  ์ˆ˜ ์žˆ๋Š” ์ž‘๋™ ์ค‘์ธ VPN ๊ฒŒ์ดํŠธ์›จ์ด๊ฐ€ ์ด๋ฏธ ์žˆ์Šต๋‹ˆ๋‹ค.

    ASA VPN ๋กœ๋“œ ๋ฐธ๋Ÿฐ์‹ฑ ํด๋Ÿฌ์Šคํ„ฐ ๋ฐฐํฌ

    ์ฒซ ๋ฒˆ์งธ ASA์˜ ๋ผ์šฐํŒ… ํ…Œ์ด๋ธ”์—์„œ ์—ฐ๊ฒฐ๋œ ํด๋ผ์ด์–ธํŠธ๋ฅผ ๋ณผ ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

    ASA VPN ๋กœ๋“œ ๋ฐธ๋Ÿฐ์‹ฑ ํด๋Ÿฌ์Šคํ„ฐ ๋ฐฐํฌ

    ์ „์ฒด VPN ํด๋Ÿฌ์Šคํ„ฐ์™€ ์ „์ฒด ํšŒ์‚ฌ ๋„คํŠธ์›Œํฌ๊ฐ€ ํด๋ผ์ด์–ธํŠธ์— ๋Œ€ํ•œ ๊ฒฝ๋กœ๋ฅผ ์•Œ๊ธฐ ์œ„ํ•ด ํด๋ผ์ด์–ธํŠธ ์ ‘๋‘์‚ฌ๋ฅผ ๋™์  ๋ผ์šฐํŒ… ํ”„๋กœํ† ์ฝœ(์˜ˆ: OSPF)์— ์žฌ๋ฐฐํฌํ•ฉ๋‹ˆ๋‹ค.

    !
    vpn-demo-1(config)# route-map RMAP-VPN-REDISTRIBUTE permit 1
    vpn-demo-1(config-route-map)#  match ip address VPN-REDISTRIBUTE
    !
    vpn-demo-1(config)# router ospf 1
    vpn-demo-1(config-router)#  network 192.168.255.0 255.255.255.0 area 0
    vpn-demo-1(config-router)#  log-adj-changes
    vpn-demo-1(config-router)#  redistribute static metric 5000 subnets route-map RMAP-VPN-REDISTRIBUTE

    ์ด์ œ ๋‘ ๋ฒˆ์งธ ASA-2 ๊ฒŒ์ดํŠธ์›จ์ด์—์„œ ํด๋ผ์ด์–ธํŠธ๋กœ ๊ฐ€๋Š” ๊ฒฝ๋กœ๊ฐ€ ์ƒ๊ฒผ๊ณ  ํด๋Ÿฌ์Šคํ„ฐ ๋‚ด์˜ ๋‹ค๋ฅธ VPN ๊ฒŒ์ดํŠธ์›จ์ด์— ์—ฐ๊ฒฐ๋œ ์‚ฌ์šฉ์ž๋Š” ์˜ˆ๋ฅผ ๋“ค์–ด ํšŒ์‚ฌ ์†Œํ”„ํŠธํฐ์„ ํ†ตํ•ด ์ง์ ‘ ํ†ต์‹ ํ•  ์ˆ˜ ์žˆ์„ ๋ฟ๋งŒ ์•„๋‹ˆ๋ผ ์‚ฌ์šฉ์ž๊ฐ€ ์š”์ฒญํ•œ ๋ฆฌ์†Œ์Šค์—์„œ ํŠธ๋ž˜ํ”ฝ์„ ๋ฐ˜ํ™˜ํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ์›ํ•˜๋Š” VPN ๊ฒŒ์ดํŠธ์›จ์ด๋กœ ์ด๋™:

    ASA VPN ๋กœ๋“œ ๋ฐธ๋Ÿฐ์‹ฑ ํด๋Ÿฌ์Šคํ„ฐ ๋ฐฐํฌ

  5. ๋ถ€ํ•˜ ๋ถ„์‚ฐ ํด๋Ÿฌ์Šคํ„ฐ ๊ตฌ์„ฑ์œผ๋กœ ์ด๋™ํ•˜๊ฒ ์Šต๋‹ˆ๋‹ค.

    ์ฃผ์†Œ 192.168.31.40์€ ๊ฐ€์ƒ IP(VIP - ๋ชจ๋“  VPN ํด๋ผ์ด์–ธํŠธ๊ฐ€ ์ดˆ๊ธฐ์— ์—ฐ๊ฒฐ๋จ)๋กœ ์‚ฌ์šฉ๋˜๋ฉฐ, ์ด ์ฃผ์†Œ์—์„œ ๋งˆ์Šคํ„ฐ ํด๋Ÿฌ์Šคํ„ฐ๋Š” ๋ถ€ํ•˜๊ฐ€ ์ ์€ ํด๋Ÿฌ์Šคํ„ฐ ๋…ธ๋“œ๋กœ ๋ฆฌ๋””๋ ‰์…˜๋ฉ๋‹ˆ๋‹ค. ์ž‘์„ฑํ•˜๋Š” ๊ฒƒ์„ ์žŠ์ง€ ๋งˆ์„ธ์š” ์ˆœ๋ฐฉํ–ฅ ๋ฐ ์—ญ๋ฐฉํ–ฅ DNS ๋ ˆ์ฝ”๋“œ ํด๋Ÿฌ์Šคํ„ฐ์˜ ๊ฐ ๋…ธ๋“œ์˜ ๊ฐ ์™ธ๋ถ€ ์ฃผ์†Œ/FQDN๊ณผ VIP ๋ชจ๋‘์— ๋Œ€ํ•ด.

    vpn-demo-1(config)# vpn load-balancing
    vpn-demo-1(config-load-balancing)# interface lbpublic outside
    vpn-demo-1(config-load-balancing)# interface lbprivate inside
    vpn-demo-1(config-load-balancing)# priority 10
    vpn-demo-1(config-load-balancing)# cluster ip address 192.168.31.40
    vpn-demo-1(config-load-balancing)# cluster port 4000
    vpn-demo-1(config-load-balancing)# redirect-fqdn enable
    vpn-demo-1(config-load-balancing)# cluster key cisco
    vpn-demo-1(config-load-balancing)# cluster encryption
    vpn-demo-1(config-load-balancing)# cluster port 9023
    vpn-demo-1(config-load-balancing)# participate
    vpn-demo-1(config-load-balancing)#

    • ๋‘ ๊ฐœ์˜ ์—ฐ๊ฒฐ๋œ ํด๋ผ์ด์–ธํŠธ๋กœ ํด๋Ÿฌ์Šคํ„ฐ์˜ ์ž‘๋™์„ ํ™•์ธํ•ฉ๋‹ˆ๋‹ค.

    ASA VPN ๋กœ๋“œ ๋ฐธ๋Ÿฐ์‹ฑ ํด๋Ÿฌ์Šคํ„ฐ ๋ฐฐํฌ

    • ASDM์„ ํ†ตํ•ด ์ž๋™์œผ๋กœ ๋กœ๋“œ๋˜๋Š” AnyConnect ํ”„๋กœํŒŒ์ผ๋กœ ๊ณ ๊ฐ ๊ฒฝํ—˜์„ ๋”์šฑ ํŽธ๋ฆฌํ•˜๊ฒŒ ๋งŒ๋“ค์–ด ๋ณด์‹ญ์‹œ์˜ค.

    ASA VPN ๋กœ๋“œ ๋ฐธ๋Ÿฐ์‹ฑ ํด๋Ÿฌ์Šคํ„ฐ ๋ฐฐํฌ

    ํŽธ๋ฆฌํ•œ ๋ฐฉ์‹์œผ๋กœ ํ”„๋กœํ•„ ์ด๋ฆ„์„ ์ง€์ •ํ•˜๊ณ  ๊ทธ๋ฃน ์ •์ฑ…์„ ์—ฐ๊ฒฐํ•ฉ๋‹ˆ๋‹ค.

    ASA VPN ๋กœ๋“œ ๋ฐธ๋Ÿฐ์‹ฑ ํด๋Ÿฌ์Šคํ„ฐ ๋ฐฐํฌ

    ๋‹ค์Œ์— ํด๋ผ์ด์–ธํŠธ๋ฅผ ์—ฐ๊ฒฐํ•˜๋ฉด ์ด ํ”„๋กœํŒŒ์ผ์ด ์ž๋™์œผ๋กœ ๋‹ค์šด๋กœ๋“œ๋˜์–ด AnyConnect ํด๋ผ์ด์–ธํŠธ์— ์„ค์น˜๋˜๋ฏ€๋กœ ์—ฐ๊ฒฐํ•ด์•ผ ํ•˜๋Š” ๊ฒฝ์šฐ ๋ชฉ๋ก์—์„œ ์„ ํƒํ•˜๊ธฐ๋งŒ ํ•˜๋ฉด ๋ฉ๋‹ˆ๋‹ค.

    ASA VPN ๋กœ๋“œ ๋ฐธ๋Ÿฐ์‹ฑ ํด๋Ÿฌ์Šคํ„ฐ ๋ฐฐํฌ

    ASDM์„ ์‚ฌ์šฉํ•˜์—ฌ ํ•˜๋‚˜์˜ ASA์—์„œ๋งŒ ์ด ํ”„๋กœํŒŒ์ผ์„ ์ƒ์„ฑํ–ˆ์œผ๋ฏ€๋กœ ํด๋Ÿฌ์Šคํ„ฐ์˜ ๋‹ค๋ฅธ ASA์—์„œ ๋‹จ๊ณ„๋ฅผ ๋ฐ˜๋ณตํ•˜๋Š” ๊ฒƒ์„ ์žŠ์ง€ ๋งˆ์‹ญ์‹œ์˜ค.

๊ฒฐ๋ก  : ๋”ฐ๋ผ์„œ ์šฐ๋ฆฌ๋Š” ์ž๋™ ๋กœ๋“œ ๋ฐธ๋Ÿฐ์‹ฑ ๊ธฐ๋Šฅ์ด ์žˆ๋Š” ์—ฌ๋Ÿฌ VPN ๊ฒŒ์ดํŠธ์›จ์ด์˜ ํด๋Ÿฌ์Šคํ„ฐ๋ฅผ ์‹ ์†ํ•˜๊ฒŒ ๋ฐฐํฌํ–ˆ์Šต๋‹ˆ๋‹ค. ์ƒˆ๋กœ์šด ASAv ๊ฐ€์ƒ ๋จธ์‹ ์„ ๋ฐฐํฌํ•˜๊ฑฐ๋‚˜ ํ•˜๋“œ์›จ์–ด ASA๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ ๊ฐ„๋‹จํ•œ ์ˆ˜ํ‰ ํ™•์žฅ์„ ํ†ตํ•ด ํด๋Ÿฌ์Šคํ„ฐ์— ์ƒˆ ๋…ธ๋“œ๋ฅผ ์‰ฝ๊ฒŒ ์ถ”๊ฐ€ํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ๊ธฐ๋Šฅ์ด ํ’๋ถ€ํ•œ AnyConnect ํด๋ผ์ด์–ธํŠธ๋Š” ๋‹ค์Œ์„ ์‚ฌ์šฉํ•˜์—ฌ ๋ณด์•ˆ ์›๊ฒฉ ์—ฐ๊ฒฐ์„ ํฌ๊ฒŒ ํ–ฅ์ƒ์‹œํ‚ฌ ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ์ž์„ธ(์ƒํƒœ ์ถ”์ •์น˜), ์ค‘์•™ ์ง‘์ค‘์‹ ์ œ์–ด ๋ฐ ์•ก์„ธ์Šค ๊ณ„์ • ์‹œ์Šคํ…œ๊ณผ ํ•จ๊ป˜ ๊ฐ€์žฅ ํšจ๊ณผ์ ์œผ๋กœ ์‚ฌ์šฉ๋จ ID ์„œ๋น„์Šค ์—”์ง„.

์ถœ์ฒ˜ : habr.com

์ฝ”๋ฉ˜ํŠธ๋ฅผ ์ถ”๊ฐ€