๋„คํŠธ์›Œํฌ ๊ตฌ์„ฑ๊ธฐ NetworkManager 1.24.0 ์ถœ์‹œ

๊ฒŒ์‹œ ๋จ ๋„คํŠธ์›Œํฌ ๋งค๊ฐœ๋ณ€์ˆ˜ ์„ค์ •์„ ๋‹จ์ˆœํ™”ํ•˜๋Š” ์ƒˆ๋กœ์šด ์•ˆ์ •์ ์ธ ์ธํ„ฐํŽ˜์ด์Šค ๋ฆด๋ฆฌ์Šค - NetworkManager 1.24. ํ”Œ๋Ÿฌ๊ทธ์ธ VPN์„ ์ง€์›ํ•˜๊ธฐ ์œ„ํ•ด OpenConnect, PPTP, OpenVPN ๋ฐ OpenSWAN์ด ์ž์ฒด ๊ฐœ๋ฐœ ์ฃผ๊ธฐ๋ฅผ ํ†ตํ•ด ๊ฐœ๋ฐœ๋˜๊ณ  ์žˆ์Šต๋‹ˆ๋‹ค.

์ฃผ์š” ํ˜์‹  ๋„คํŠธ์›Œํฌ๋งค๋‹ˆ์ € 1.24:

  • ๊ฐ€์ƒ ๋ผ์šฐํŒ… ๋ฐ ์ „๋‹ฌ ๋„คํŠธ์›Œํฌ ์ธํ„ฐํŽ˜์ด์Šค(VRF, ๊ฐ€์ƒ ๋ผ์šฐํŒ… ๋ฐ ์ „๋‹ฌ)์— ๋Œ€ํ•œ ์ง€์›์ด ์ถ”๊ฐ€๋˜์—ˆ์Šต๋‹ˆ๋‹ค.
  • ๊ฐœ๋ฐฉํ˜• ๋ฌด์„  ๋„คํŠธ์›Œํฌ์—์„œ ์•”ํ˜ธํ™” ํ‚ค๋ฅผ ์ƒ์„ฑํ•˜๊ธฐ ์œ„ํ•œ OWE(Opportunistic Wireless Encryption, RFC 8110) ์—ฐ๊ฒฐ ํ˜‘์ƒ ๋ฐฉ๋ฒ•์— ๋Œ€ํ•œ ์ง€์›์ด ์ถ”๊ฐ€๋˜์—ˆ์Šต๋‹ˆ๋‹ค. OWE ํ™•์žฅ์€ WPA3 ํ‘œ์ค€์—์„œ ํด๋ผ์ด์–ธํŠธ์™€ ์ธ์ฆ์ด ํ•„์š”ํ•˜์ง€ ์•Š์€ ๊ณต์šฉ ๋ฌด์„  ๋„คํŠธ์›Œํฌ์˜ ์•ก์„ธ์Šค ํฌ์ธํŠธ ์‚ฌ์ด์˜ ๋ชจ๋“  ๋ฐ์ดํ„ฐ ํ๋ฆ„์„ ์•”ํ˜ธํ™”ํ•˜๋Š” ๋ฐ ์‚ฌ์šฉ๋ฉ๋‹ˆ๋‹ค.
  • IPv31 P31P ๋งํฌ์— ๋Œ€ํ•œ 2๋น„ํŠธ ์ ‘๋‘์‚ฌ(/4 ์„œ๋ธŒ๋„ท ๋งˆ์Šคํฌ)์— ๋Œ€ํ•œ ์ง€์›์ด ์ถ”๊ฐ€๋˜์—ˆ์Šต๋‹ˆ๋‹ค(RFC 3021);
  • libpolkit-agent-1 ๋ฐ libpolkit-gobject-1์ด ์ข…์†์„ฑ์—์„œ ์ œ๊ฑฐ๋˜์—ˆ์Šต๋‹ˆ๋‹ค.
  • ์ƒˆ๋กœ์šด ๋ช…๋ น์ธ "nmcli ์—ฐ๊ฒฐ ์ˆ˜์ • $CON_NAME ์ œ๊ฑฐ $์„ค์ •"์„ ์‚ฌ์šฉํ•˜์—ฌ ์„ค์ •์„ ์‚ญ์ œํ•˜๋Š” ๊ธฐ๋Šฅ์ด nmcli ์ธํ„ฐํŽ˜์ด์Šค์— ์ถ”๊ฐ€๋˜์—ˆ์Šต๋‹ˆ๋‹ค. "vpn.data", "vpn.secrets" ์„ค์ •์—์„œ,
    "bond.options" ๋ฐ "ethernet.s390-options"์—๋Š” ๋ฐฑ์Šฌ๋ž˜์‹œ ์ด์Šค์ผ€์ดํ”„ ์‹œํ€€์Šค์— ๋Œ€ํ•œ ์ง€์›์ด ์ถ”๊ฐ€๋˜์—ˆ์Šต๋‹ˆ๋‹ค.

  • ๋„คํŠธ์›Œํฌ ๋ธŒ๋ฆฌ์ง€์˜ ๊ฒฝ์šฐ "bridge.multicast-querier", "bridge.multicast-query-use-ifaddr" ์˜ต์…˜์ด ์ถ”๊ฐ€๋˜์—ˆ์Šต๋‹ˆ๋‹ค.
    "bridge.multicast-router", "bridge.vlan-stats-enabled", "bridge.vlan-protocol" ๋ฐ "bridge.group-address";

  • ์‹œ๊ฐ„ ์ œํ•œ "ipv6.ra-timeout" ๋ฐ "ipv6.dhcp-timeout"์„ ๊ตฌ์„ฑํ•˜๊ธฐ ์œ„ํ•ด IPv6 SLAAC ๋ฐ IPv6 DHCP์— ์˜ต์…˜์ด ์ถ”๊ฐ€๋˜์—ˆ์Šต๋‹ˆ๋‹ค.
  • WWAN์˜ ๊ฒฝ์šฐ PIN ์ฝ”๋“œ๋กœ ๋ณดํ˜ธ๋˜๋Š” ์ด๋ฏธ ์ž ๊ธˆ ํ•ด์ œ๋œ SIM ์นด๋“œ๋ฅผ ์‚ฌ์šฉํ•˜๋Š” ๊ฒฝ์šฐ USB ๋ชจ๋Ž€์„ ํ†ตํ•ด ์—ฐ๊ฒฐ์„ ์ž๋™์œผ๋กœ ํ™œ์„ฑํ™”ํ•˜๋Š” ๊ธฐ๋Šฅ์ด ๊ตฌํ˜„๋ฉ๋‹ˆ๋‹ค.
  • OVS ๋„คํŠธ์›Œํฌ ์ธํ„ฐํŽ˜์ด์Šค์— MTU๋ฅผ ๋ณ€๊ฒฝํ•˜๋Š” ๊ธฐ๋Šฅ์ด ์ถ”๊ฐ€๋˜์—ˆ์Šต๋‹ˆ๋‹ค.
  • VPN์€ ๋นˆ ๋ฐ์ดํ„ฐ ๊ฐ’๊ณผ ๋น„๋ฐ€ ์‹œํ€€์Šค๋ฅผ ํ—ˆ์šฉํ•ฉ๋‹ˆ๋‹ค.
  • ๋ชจ๋“  nm ์žฅ์น˜์˜ ๊ฒฝ์šฐ 'HwAddress' ์†์„ฑ์€ D-Bus๋ฅผ ํ†ตํ•ด ์ œ๊ณต๋ฉ๋‹ˆ๋‹ค.
  • ๋งˆ์Šคํ„ฐ ์žฅ์น˜๊ฐ€ ์—†๋Š” ๊ฒฝ์šฐ ์Šฌ๋ ˆ์ด๋ธŒ ์žฅ์น˜ ์ƒ์„ฑ ๋˜๋Š” ํ™œ์„ฑํ™”๊ฐ€ ์ค‘์ง€๋˜์—ˆ์Šต๋‹ˆ๋‹ค.
  • nmcli๋ฅผ ํ†ตํ•ด WireGuard ํ”„๋กœํ•„์„ ๊ฐ€์ ธ์˜ค๋Š” ๋ฌธ์ œ๊ฐ€ ํ•ด๊ฒฐ๋˜์—ˆ์œผ๋ฉฐ ๊ฒŒ์ดํŠธ์›จ์ด๋ฅผ ๋ช…์‹œ์ ์œผ๋กœ ์ง€์ •ํ•  ๋•Œ ip4-auto-default-route๋ฅผ ํฌํ•จํ•˜๋Š” ๊ตฌ์„ฑ ์ฒ˜๋ฆฌ๊ฐ€ ๊ฐœ์„ ๋˜์—ˆ์Šต๋‹ˆ๋‹ค.

์ถœ์ฒ˜ : opennet.ru

์ฝ”๋ฉ˜ํŠธ๋ฅผ ์ถ”๊ฐ€