1.5 шСми Π½Π° домашна IPsec VPN. Π”Π΅ΠΌΠΎ Π·Π° Ρ‚Π΅ΡΡ‚ΠΈΡ€Π°ΡšΠ΅

1.5 шСми Π½Π° домашна IPsec VPN. Π”Π΅ΠΌΠΎ Π·Π° Ρ‚Π΅ΡΡ‚ΠΈΡ€Π°ΡšΠ΅

Π‘ΠΈΡ‚ΡƒΠ°Ρ†ΠΈΡ˜Π°

Π”ΠΎΠ±ΠΈΠ² Π΄Π΅ΠΌΠΎ Π²Π΅Ρ€Π·ΠΈΡ˜Π° Π½Π° ΠΏΡ€ΠΎΠΈΠ·Π²ΠΎΠ΄ΠΈΡ‚Π΅ C-Terra VPN Π²Π΅Ρ€Π·ΠΈΡ˜Π° 4.3 Π·Π° Ρ‚Ρ€ΠΈ мСсСци. Π‘Π°ΠΊΠ°ΠΌ Π΄Π° Π΄ΠΎΠ·Π½Π°Π°ΠΌ Π΄Π°Π»ΠΈ ΠΌΠΎΡ˜ΠΎΡ‚ инТСнСрски ΠΆΠΈΠ²ΠΎΡ‚ ќС станС полСсСн ΠΎΡ‚ΠΊΠ°ΠΊΠΎ ќС сС ΠΏΡ€Π΅Ρ„Ρ€Π»Π°ΠΌ Π½Π° Π½ΠΎΠ²Π°Ρ‚Π° Π²Π΅Ρ€Π·ΠΈΡ˜Π°.

ДСнСска Π½Π΅ Π΅ Ρ‚Π΅ΡˆΠΊΠΎ, Π΄ΠΎΠ²ΠΎΠ»Π½ΠΎ Π΅ Π΅Π΄Π½Π° кСсичка инстант ΠΊΠ°Ρ„Π΅ 3 Π²ΠΎ 1. ЌС Π²ΠΈ ΠΊΠ°ΠΆΠ°ΠΌ ΠΊΠ°ΠΊΠΎ Π΄Π° Π΄ΠΎΠ±ΠΈΠ΅Ρ‚Π΅ Π΄Π΅ΠΌΠΎ. ЌС сС ΠΎΠ±ΠΈΠ΄Π°ΠΌ Π΄Π° Π³ΠΈ ΠΈΠ·Π³Ρ€Π°Π΄Π°ΠΌ ΡˆΠ΅ΠΌΠΈΡ‚Π΅ GRE-over-IPsec ΠΈ IPsec-over-GRE.

Како Π΄Π° Π΄ΠΎΠ±ΠΈΠ΅Ρ‚Π΅ Π΄Π΅ΠΌΠΎ

1.5 шСми Π½Π° домашна IPsec VPN. Π”Π΅ΠΌΠΎ Π·Π° Ρ‚Π΅ΡΡ‚ΠΈΡ€Π°ΡšΠ΅

Од сликата ΠΏΡ€ΠΎΠΈΠ·Π»Π΅Π³ΡƒΠ²Π° Π΄Π΅ΠΊΠ° Π·Π° Π΄Π° Π΄ΠΎΠ±ΠΈΠ΅Ρ‚Π΅ Π΄Π΅ΠΌΠΎ Ρ‚Ρ€Π΅Π±Π°:

  • ΠΠ°ΠΏΠΈΡˆΠ΅Ρ‚Π΅ писмо Π΄ΠΎ [Π·Π°ΡˆΡ‚ΠΈΡ‚Π΅Π½Π° ΠΏΠΎ Π΅-ΠΏΠΎΡˆΡ‚Π°] ΠΎΠ΄ ΠΊΠΎΡ€ΠΏΠΎΡ€Π°Ρ‚ΠΈΠ²Π½Π° адрСса;
  • Π’ΠΎ писмото, Π½Π°Π²Π΅Π΄Π΅Ρ‚Π΅ Π³ΠΎ TIN-ΠΎΡ‚ Π½Π° Π²Π°ΡˆΠ°Ρ‚Π° ΠΎΡ€Π³Π°Π½ΠΈΠ·Π°Ρ†ΠΈΡ˜Π°;
  • НавСдСтС Π³ΠΈ ΠΏΡ€ΠΎΠΈΠ·Π²ΠΎΠ΄ΠΈΡ‚Π΅ ΠΈ Π½ΠΈΠ²Π½Π°Ρ‚Π° ΠΊΠΎΠ»ΠΈΡ‡ΠΈΠ½Π°.

ДСмонстрациитС Π²Π°ΠΆΠ°Ρ‚ Ρ‚Ρ€ΠΈ мСсСци. ΠŸΡ€ΠΎΠ΄Π°Π²Π°Ρ‡ΠΎΡ‚ Π½Π΅ ја ΠΎΠ³Ρ€Π°Π½ΠΈΡ‡ΡƒΠ²Π° Π½ΠΈΠ²Π½Π°Ρ‚Π° функционалност.

ΠŸΡ€ΠΎΡˆΠΈΡ€ΡƒΠ²Π°ΡšΠ΅ Π½Π° сликата

Π”Π΅ΠΌΠΎΡ‚ΠΎ Π½Π° Security Gateway Π΅ слика Π½Π° Π²ΠΈΡ€Ρ‚ΡƒΠ΅Π»Π½Π° машина. Јас користам Ρ€Π°Π±ΠΎΡ‚Π½Π° станица VMWare. ΠšΠΎΠΌΠΏΠ»Π΅Ρ‚Π½Π° листа Π½Π° ΠΏΠΎΠ΄Π΄Ρ€ΠΆΠ°Π½ΠΈ Ρ…ΠΈΠΏΠ΅Ρ€Π²ΠΈΠ·ΠΎΡ€ΠΈ ΠΈ срСдини Π·Π° Π²ΠΈΡ€Ρ‚ΡƒΠ΅Π»ΠΈΠ·Π°Ρ†ΠΈΡ˜Π° Π΅ достапна Π½Π° Π²Π΅Π±-страницата Π½Π° ΠΏΡ€ΠΎΠ΄Π°Π²Π°Ρ‡ΠΎΡ‚.

ΠŸΡ€Π΅Π΄ Π΄Π° Π·Π°ΠΏΠΎΡ‡Π½Π΅Ρ‚Π΅, ΠΈΠΌΠ°Ρ˜Ρ‚Π΅ ΠΏΡ€Π΅Π΄Π²ΠΈΠ΄ Π΄Π΅ΠΊΠ° Π½Π΅ΠΌΠ° ΠΌΡ€Π΅ΠΆΠ½ΠΈ ΠΈΠ½Ρ‚Π΅Ρ€Ρ„Π΅Ρ˜ΡΠΈ Π²ΠΎ стандардната слика Π½Π° Π²ΠΈΡ€Ρ‚ΡƒΠ΅Π»Π½Π°Ρ‚Π° машина:

1.5 шСми Π½Π° домашна IPsec VPN. Π”Π΅ΠΌΠΎ Π·Π° Ρ‚Π΅ΡΡ‚ΠΈΡ€Π°ΡšΠ΅

Π›ΠΎΠ³ΠΈΠΊΠ°Ρ‚Π° Π΅ јасна, корисникот Ρ‚Ρ€Π΅Π±Π° Π΄Π° Π΄ΠΎΠ΄Π°Π΄Π΅ ΠΎΠ½ΠΎΠ»ΠΊΡƒ ΠΈΠ½Ρ‚Π΅Ρ€Ρ„Π΅Ρ˜ΡΠΈ ΠΊΠΎΠ»ΠΊΡƒ ΡˆΡ‚ΠΎ ΠΌΡƒ Ρ‚Ρ€Π΅Π±Π°. ЌС Π΄ΠΎΠ΄Π°Π΄Π°ΠΌ Ρ‡Π΅Ρ‚ΠΈΡ€ΠΈ одСднаш:

1.5 шСми Π½Π° домашна IPsec VPN. Π”Π΅ΠΌΠΎ Π·Π° Ρ‚Π΅ΡΡ‚ΠΈΡ€Π°ΡšΠ΅

Π‘Π΅Π³Π° ја стартувам Π²ΠΈΡ€Ρ‚ΡƒΠ΅Π»Π½Π°Ρ‚Π° машина. Π’Π΅Π΄Π½Π°Ρˆ ΠΏΠΎ ΡΡ‚Π°Ρ€Ρ‚ΡƒΠ²Π°ΡšΠ΅Ρ‚ΠΎ, ΠΏΠΎΡ€Ρ‚Π°Ρ‚Π° Π±Π°Ρ€Π° корисничко ΠΈΠΌΠ΅ ΠΈ Π»ΠΎΠ·ΠΈΠ½ΠΊΠ°.

ΠŸΠΎΡΡ‚ΠΎΡ˜Π°Ρ‚ Π½Π΅ΠΊΠΎΠ»ΠΊΡƒ ΠΊΠΎΠ½Π·ΠΎΠ»ΠΈ Π²ΠΎ S-Terra Gateway со Ρ€Π°Π·Π»ΠΈΡ‡Π½ΠΈ смСтки. Нивниот Π±Ρ€ΠΎΡ˜ ќС Π³ΠΎ ΠΈΠ·Π±Ρ€ΠΎΡ˜Π°ΠΌ Π²ΠΎ посСбна ΡΡ‚Π°Ρ‚ΠΈΡ˜Π°. Π—Π° сСга:
Login as: administrator
Password: s-terra

Ја ΠΈΠ½ΠΈΡ†ΠΈΡ˜Π°Π»ΠΈΠ·ΠΈΡ€Π°ΠΌ ΠΏΠΎΡ€Ρ‚Π°Ρ‚Π°. Π˜Π½ΠΈΡ†ΠΈΡ˜Π°Π»ΠΈΠ·Π°Ρ†ΠΈΡ˜Π°Ρ‚Π° Π΅ Π½ΠΈΠ·Π° Π΄Π΅Ρ˜ΡΡ‚Π²Π°: Π²Π½Π΅ΡΡƒΠ²Π°ΡšΠ΅ Π»ΠΈΡ†Π΅Π½Ρ†Π°, ΠΏΠΎΡΡ‚Π°Π²ΡƒΠ²Π°ΡšΠ΅ биолошки Π³Π΅Π½Π΅Ρ€Π°Ρ‚ΠΎΡ€ Π½Π° случаСн Π±Ρ€ΠΎΡ˜ (симулатор Π½Π° тастатура - ΠΌΠΎΡ˜ΠΎΡ‚ Ρ€Π΅ΠΊΠΎΡ€Π΄ Π΅ 27 сСкунди) ΠΈ ΠΊΡ€Π΅ΠΈΡ€Π°ΡšΠ΅ ΠΌΠ°ΠΏΠ° Π½Π° ΠΌΡ€Π΅ΠΆΠ΅Π½ ΠΈΠ½Ρ‚Π΅Ρ€Ρ„Π΅Ρ˜Ρ.

ΠšΠ°Ρ€Ρ‚Π° Π½Π° ΠΌΡ€Π΅ΠΆΠ½ΠΈ ΠΈΠ½Ρ‚Π΅Ρ€Ρ„Π΅Ρ˜ΡΠΈ. Π‘Ρ‚Π°Π½Π° полСсно

Π’Π΅Ρ€Π·ΠΈΡ˜Π°Ρ‚Π° 4.2 Π³ΠΎ ΠΏΠΎΠ·Π΄Ρ€Π°Π²ΠΈ Π°ΠΊΡ‚ΠΈΠ²Π½ΠΈΠΎΡ‚ корисник со ΠΏΠΎΡ€Π°ΠΊΠΈ:

Starting IPsec daemon….. failed
ERROR: Could not establish connection with daemon

АктивСн корисник (спорСд Π°Π½ΠΎΠ½ΠΈΠΌΠ΅Π½ ΠΈΠ½ΠΆΠ΅Π½Π΅Ρ€) Π΅ корисник кој ΠΌΠΎΠΆΠ΅ Π΄Π° постави сè Π±Ρ€Π·ΠΎ ΠΈ Π±Π΅Π· Π΄ΠΎΠΊΡƒΠΌΠ΅Π½Ρ‚Π°Ρ†ΠΈΡ˜Π°.

ΠΠ΅ΡˆΡ‚ΠΎ Ρ‚Ρ€Π³Π½Π° Π½Π°ΠΎΠΏΠ°ΠΊΡƒ ΠΏΡ€Π΅Π΄ Π΄Π° сС ΠΎΠ±ΠΈΠ΄Π΅ Π΄Π° поставитС IP адрСса Π½Π° ΠΈΠ½Ρ‚Π΅Ρ€Ρ„Π΅Ρ˜ΡΠΎΡ‚. Π‘Π΅ Ρ€Π°Π±ΠΎΡ‚ΠΈ Π·Π° ΠΌΠ°ΠΏΠ°Ρ‚Π° Π½Π° ΠΌΡ€Π΅ΠΆΠ½ΠΈΠΎΡ‚ ΠΈΠ½Ρ‚Π΅Ρ€Ρ„Π΅Ρ˜Ρ. Π‘Π΅ΡˆΠ΅ Π½Π΅ΠΎΠΏΡ…ΠΎΠ΄Π½ΠΎ Π΄Π° сС Π½Π°ΠΏΡ€Π°Π²ΠΈ:

/bin/netifcfg enum > /home/map
/bin/netifcfg map /home/map
service networking restart

Како Ρ€Π΅Π·ΡƒΠ»Ρ‚Π°Ρ‚ Π½Π° Ρ‚ΠΎΠ°, сС ΠΊΡ€Π΅ΠΈΡ€Π° ΠΌΠ°ΠΏΠ° Π½Π° ΠΌΡ€Π΅ΠΆΠ΅Π½ ΠΈΠ½Ρ‚Π΅Ρ€Ρ„Π΅Ρ˜Ρ ΡˆΡ‚ΠΎ содрТи ΠΌΠ°ΠΏΠΈΡ€Π°ΡšΠ΅ Π½Π° ΠΈΠΌΠΈΡšΠ°Ρ‚Π° Π½Π° Ρ„ΠΈΠ·ΠΈΡ‡ΠΊΠΈΡ‚Π΅ ΠΈΠ½Ρ‚Π΅Ρ€Ρ„Π΅Ρ˜ΡΠΈ (0000:02:03.0) ΠΈ Π½ΠΈΠ²Π½ΠΈΡ‚Π΅ Π»ΠΎΠ³ΠΈΡ‡ΠΊΠΈ ΠΎΠ·Π½Π°ΠΊΠΈ Π²ΠΎ ΠΎΠΏΠ΅Ρ€Π°Ρ‚ΠΈΠ²Π½ΠΈΠΎΡ‚ систСм (eth0) ΠΈ ΠΊΠΎΠ½Π·ΠΎΠ»Π°Ρ‚Π° слична Π½Π° Cisco (FastEthernet0/0):

#Unique ID iface type OS name Cisco-like name

0000:02:03.0 phye eth0 FastEthernet0/0

Π›ΠΎΠ³ΠΈΡ‡ΠΊΠΈΡ‚Π΅ ΠΎΠ·Π½Π°ΠΊΠΈ Π½Π° ΠΈΠ½Ρ‚Π΅Ρ€Ρ„Π΅Ρ˜ΡΠΈΡ‚Π΅ сС Π½Π°Ρ€Π΅ΠΊΡƒΠ²Π°Π°Ρ‚ псСвдоними. ΠΠ»ΠΈΡ˜Π°ΡΠΈΡ‚Π΅ сС Π·Π°Ρ‡ΡƒΠ²Π°Π½ΠΈ Π²ΠΎ Π΄Π°Ρ‚ΠΎΡ‚Π΅ΠΊΠ°Ρ‚Π° /etc/ifaliases.cf.
Π’ΠΎ Π²Π΅Ρ€Π·ΠΈΡ˜Π°Ρ‚Π° 4.3, ΠΊΠΎΠ³Π° Π²ΠΈΡ€Ρ‚ΡƒΠ΅Π»Π½Π°Ρ‚Π° машина Π·Π° ΠΏΡ€Π² ΠΏΠ°Ρ‚ сС стартува, автоматски сС ΠΊΡ€Π΅ΠΈΡ€Π° ΠΌΠ°ΠΏΠ° Π½Π° ΠΈΠ½Ρ‚Π΅Ρ€Ρ„Π΅Ρ˜Ρ. Ако Π³ΠΎ ΠΏΡ€ΠΎΠΌΠ΅Π½ΠΈΡ‚Π΅ Π±Ρ€ΠΎΡ˜ΠΎΡ‚ Π½Π° ΠΌΡ€Π΅ΠΆΠ½ΠΈ ΠΈΠ½Ρ‚Π΅Ρ€Ρ„Π΅Ρ˜ΡΠΈ Π²ΠΎ Π²ΠΈΡ€Ρ‚ΡƒΠ΅Π»Π½Π°Ρ‚Π° машина, Ρ‚ΠΎΠ³Π°Ρˆ ΠΏΠΎΠ²Ρ‚ΠΎΡ€Π½ΠΎ ΠΊΡ€Π΅ΠΈΡ€Π°Ρ˜Ρ‚Π΅ ја ΠΌΠ°ΠΏΠ°Ρ‚Π° Π½Π° ΠΈΠ½Ρ‚Π΅Ρ€Ρ„Π΅Ρ˜ΡΠΎΡ‚:

/bin/netifcfg enum > /home/map
/bin/netifcfg map /home/map
systemctl restart networking

Π¨Π΅ΠΌΠ° 1: GRE-over-IPsec

РаспорСдувам Π΄Π²Π΅ Π²ΠΈΡ€Ρ‚ΡƒΠ΅Π»Π½ΠΈ ΠΏΠΎΡ€Ρ‚ΠΈ, сС ΠΏΡ€Π΅Ρ„Ρ€Π»Π°ΠΌ ΠΊΠ°ΠΊΠΎ ΡˆΡ‚ΠΎ Π΅ ΠΏΡ€ΠΈΠΊΠ°ΠΆΠ°Π½ΠΎ Π½Π° сликата:

1.5 шСми Π½Π° домашна IPsec VPN. Π”Π΅ΠΌΠΎ Π·Π° Ρ‚Π΅ΡΡ‚ΠΈΡ€Π°ΡšΠ΅

Π§Π΅ΠΊΠΎΡ€ 1. ΠŸΠΎΡΡ‚Π°Π²Π΅Ρ‚Π΅ IP адрСси ΠΈ Ρ€ΡƒΡ‚ΠΈ

VG1(config) #
interface fa0/0
ip address 172.16.1.253 255.255.255.0
no shutdown
interface fa0/1
ip address 192.168.1.253 255.255.255.0
no shutdown
ip route 0.0.0.0 0.0.0.0 172.16.1.254

VG2(config) #
interface fa0/0
ip address 172.16.1.254 255.255.255.0
no shutdown
interface fa0/1
ip address 192.168.2.254 255.255.255.0
no shutdown
ip route 0.0.0.0 0.0.0.0 172.16.1.253

ΠŸΡ€ΠΎΠ²Π΅Ρ€ΠΊΠ° Π½Π° IP ΠΊΠΎΠ½Π΅ΠΊΡ†ΠΈΡ˜Π°:

root@VG1:~# ping 172.16.1.254 -c 4
PING 172.16.1.254 (172.16.1.254) 56(84) bytes of data.
64 bytes from 172.16.1.254: icmp_seq=1 ttl=64 time=0.545 ms
64 bytes from 172.16.1.254: icmp_seq=2 ttl=64 time=0.657 ms
64 bytes from 172.16.1.254: icmp_seq=3 ttl=64 time=0.687 ms
64 bytes from 172.16.1.254: icmp_seq=4 ttl=64 time=0.273 ms

--- 172.16.1.254 ping statistics ---
4 packets transmitted, 4 received, 0% packet loss, time 3005ms
rtt min/avg/max/mdev = 0.273/0.540/0.687/0.164 ms

Π§Π΅ΠΊΠΎΡ€ 2: ΠŸΠΎΡΡ‚Π°Π²Π΅Ρ‚Π΅ GRE

Π—Π΅ΠΌΠ°ΠΌ ΠΏΡ€ΠΈΠΌΠ΅Ρ€ Π·Π° ΠΏΠΎΡΡ‚Π°Π²ΡƒΠ²Π°ΡšΠ΅ GRE ΠΎΠ΄ ΠΎΡ„ΠΈΡ†ΠΈΡ˜Π°Π»Π½ΠΈ скрипти. Јас ΠΊΡ€Π΅ΠΈΡ€Π°ΠΌ Π΄Π°Ρ‚ΠΎΡ‚Π΅ΠΊΠ° gre1 Π²ΠΎ Π΄ΠΈΡ€Π΅ΠΊΡ‚ΠΎΡ€ΠΈΡƒΠΌΠΎΡ‚ /etc/network/interfaces.d со содрТината.

Π—Π° VG1:

auto gre1
iface gre1 inet static
address 1.1.1.1
netmask 255.255.255.252
pre-up ip tunnel add gre1 mode gre remote 172.16.1.254 local 172.16.1.253 key 1 ttl 64 tos inherit
pre-up ethtool -K gre1 tx off > /dev/null
pre-up ip link set gre1 mtu 1400
post-down ip link del gre1

Π—Π° VG2:

auto gre1
iface gre1 inet static
address 1.1.1.2
netmask 255.255.255.252
pre-up ip tunnel add gre1 mode gre remote 172.16.1.253 local 172.16.1.254 key 1 ttl 64 tos inherit
pre-up ethtool -K gre1 tx off > /dev/null
pre-up ip link set gre1 mtu 1400
post-down ip link del gre1

Π“ΠΎ ΠΏΠΎΠ΄ΠΈΠ³Π½ΡƒΠ²Π°ΠΌ ΠΈΠ½Ρ‚Π΅Ρ€Ρ„Π΅Ρ˜ΡΠΎΡ‚ Π²ΠΎ систСмот:

root@VG1:~# ifup gre1
root@VG2:~# ifup gre1

ΠŸΡ€ΠΎΠ²Π΅Ρ€ΠΊΠ°:

root@VG1:~# ip address show
8: gre1@NONE: <POINTOPOINT,NOARP,UP,LOWER_UP> mtu 1400 qdisc noqueue state UNKNOWN group default qlen 1
    link/gre 172.16.1.253 peer 172.16.1.254
    inet 1.1.1.1/30 brd 1.1.1.3 scope global gre1
       valid_lft forever preferred_lft forever

root@VG1:~# ip tunnel show
gre0: gre/ip remote any local any ttl inherit nopmtudisc
gre1: gre/ip remote 172.16.1.254 local 172.16.1.253 ttl 64 tos inherit key 1

C-Terra Gateway ΠΈΠΌΠ° Π²Π³Ρ€Π°Π΄Π΅Π½ Ρ‚Ρ€Π°Π³Π°Ρ‡ Π½Π° ΠΏΠ°ΠΊΠ΅Ρ‚ΠΈ - tcpdump. ЌС напишам ΡΠΎΠΎΠ±Ρ€Π°ΡœΠ°Ρ˜Π½Π° дСпонија Π²ΠΎ Π΄Π°Ρ‚ΠΎΡ‚Π΅ΠΊΠ° pcap:

root@VG2:~# tcpdump -i eth0 -w /home/dump.pcap

ΠŸΠΎΡ‡Π½ΡƒΠ²Π°ΠΌ Π΄Π° ΠΏΠΈΠ½Π³ΡƒΠ²Π°ΠΌ ΠΏΠΎΠΌΠ΅Ρ“Ρƒ ΠΈΠ½Ρ‚Π΅Ρ€Ρ„Π΅Ρ˜ΡΠΈΡ‚Π΅ GRE:

root@VG1:~# ping 1.1.1.2 -c 4
PING 1.1.1.2 (1.1.1.2) 56(84) bytes of data.
64 bytes from 1.1.1.2: icmp_seq=1 ttl=64 time=0.918 ms
64 bytes from 1.1.1.2: icmp_seq=2 ttl=64 time=0.850 ms
64 bytes from 1.1.1.2: icmp_seq=3 ttl=64 time=0.918 ms
64 bytes from 1.1.1.2: icmp_seq=4 ttl=64 time=0.974 ms

--- 1.1.1.2 ping statistics ---
4 packets transmitted, 4 received, 0% packet loss, time 3006ms
rtt min/avg/max/mdev = 0.850/0.915/0.974/0.043 ms

Π’ΡƒΠ½Π΅Π»ΠΎΡ‚ GRE Π΅ ΠΎΡ‚Π²ΠΎΡ€Π΅Π½ ΠΈ Ρ€Π°Π±ΠΎΡ‚ΠΈ:

1.5 шСми Π½Π° домашна IPsec VPN. Π”Π΅ΠΌΠΎ Π·Π° Ρ‚Π΅ΡΡ‚ΠΈΡ€Π°ΡšΠ΅

Π§Π΅ΠΊΠΎΡ€ 3. Π¨ΠΈΡ„Ρ€ΠΈΡ€Π°Ρ˜Ρ‚Π΅ со GOST GRE

Π“ΠΎ поставив Ρ‚ΠΈΠΏΠΎΡ‚ Π½Π° ΠΈΠ΄Π΅Π½Ρ‚ΠΈΡ„ΠΈΠΊΠ°Ρ†ΠΈΡ˜Π° - ΠΏΠΎ адрСса. ΠΠ²Ρ‚Π΅Π½Ρ‚ΠΈΠΊΠ°Ρ†ΠΈΡ˜Π° со ΠΏΡ€Π΅Ρ‚Ρ…ΠΎΠ΄Π½ΠΎ Π΄Π΅Ρ„ΠΈΠ½ΠΈΡ€Π°Π½ ΠΊΠ»ΡƒΡ‡ (спорСд УсловитС Π·Π° ΠΊΠΎΡ€ΠΈΡΡ‚Π΅ΡšΠ΅, ΠΌΠΎΡ€Π° Π΄Π° сС користат Π΄ΠΈΠ³ΠΈΡ‚Π°Π»Π½ΠΈ сСртификати):

VG1(config)#
crypto isakmp identity address
crypto isakmp key KEY address 172.16.1.254

Π“ΠΈ поставив ΠΏΠ°Ρ€Π°ΠΌΠ΅Ρ‚Ρ€ΠΈΡ‚Π΅ Π½Π° IPsec Ρ„Π°Π·Π° I:

VG1(config)#
crypto isakmp policy 1
encr gost
hash gost3411-256-tc26
auth pre-share
group vko2

Π“ΠΈ поставив ΠΏΠ°Ρ€Π°ΠΌΠ΅Ρ‚Ρ€ΠΈΡ‚Π΅ Π½Π° IPsec Π€Π°Π·Π° II:

VG1(config)#
crypto ipsec transform-set TSET esp-gost28147-4m-imit
mode tunnel

Јас ΠΊΡ€Π΅ΠΈΡ€Π°ΠΌ пристапна листа Π·Π° ΡˆΠΈΡ„Ρ€ΠΈΡ€Π°ΡšΠ΅. Π¦Π΅Π»Π΅Π½ ΡΠΎΠΎΠ±Ρ€Π°ΡœΠ°Ρ˜ - GRE:

VG1(config)#
ip access-list extended LIST
permit gre host 172.16.1.253 host 172.16.1.254

Јас создавам ΠΊΡ€ΠΈΠΏΡ‚ΠΎ-ΠΌΠ°ΠΏΠ° ΠΈ ја Π²Ρ€Π·ΡƒΠ²Π°ΠΌ Π·Π° WAN ΠΈΠ½Ρ‚Π΅Ρ€Ρ„Π΅Ρ˜ΡΠΎΡ‚:

VG1(config)#
crypto map CMAP 1 ipsec-isakmp
match address LIST
set transform-set TSET
set peer 172.16.1.253
interface fa0/0
  crypto map CMAP

Π—Π° VG2, ΠΊΠΎΠ½Ρ„ΠΈΠ³ΡƒΡ€Π°Ρ†ΠΈΡ˜Π°Ρ‚Π° Π΅ прСсликана, Ρ€Π°Π·Π»ΠΈΠΊΠΈΡ‚Π΅ сС:

VG2(config)#
crypto isakmp key KEY address 172.16.1.253
ip access-list extended LIST
permit gre host 172.16.1.254 host 172.16.1.253
crypto map CMAP 1 ipsec-isakmp
set peer 172.16.1.254

ΠŸΡ€ΠΎΠ²Π΅Ρ€ΠΊΠ°:

root@VG2:~# tcpdump -i eth0 -w /home/dump2.pcap
root@VG1:~# ping 1.1.1.2 -c 4
PING 1.1.1.2 (1.1.1.2) 56(84) bytes of data.
64 bytes from 1.1.1.2: icmp_seq=1 ttl=64 time=1128 ms
64 bytes from 1.1.1.2: icmp_seq=2 ttl=64 time=126 ms
64 bytes from 1.1.1.2: icmp_seq=3 ttl=64 time=1.07 ms
64 bytes from 1.1.1.2: icmp_seq=4 ttl=64 time=1.12 ms

--- 1.1.1.2 ping statistics ---
4 packets transmitted, 4 received, 0% packet loss, time 3006ms
rtt min/avg/max/mdev = 1.077/314.271/1128.419/472.826 ms, pipe 2

Бтатистика Π½Π° ISAKMP/IPsec:

root@VG1:~# sa_mgr show
ISAKMP sessions: 0 initiated, 0 responded

ISAKMP connections:
Num Conn-id (Local Addr,Port)-(Remote Addr,Port) State Sent Rcvd
1 1 (172.16.1.253,500)-(172.16.1.254,500) active 1086 1014

IPsec connections:
Num Conn-id (Local Addr,Port)-(Remote Addr,Port) Protocol Action Type Sent Rcvd
1 1 (172.16.1.253,*)-(172.16.1.254,*) 47 ESP tunn 480 480

НСма ΠΏΠ°ΠΊΠ΅Ρ‚ΠΈ Π²ΠΎ Π΄Π΅ΠΏΠΎΠ½ΠΈΡ˜Π°Ρ‚Π° Π·Π° ΡΠΎΠΎΠ±Ρ€Π°ΡœΠ°Ρ˜ GRE:

1.5 шСми Π½Π° домашна IPsec VPN. Π”Π΅ΠΌΠΎ Π·Π° Ρ‚Π΅ΡΡ‚ΠΈΡ€Π°ΡšΠ΅

Π—Π°ΠΊΠ»ΡƒΡ‡ΠΎΠΊ: ΡˆΠ΅ΠΌΠ°Ρ‚Π° GRE-over-IPsec Ρ€Π°Π±ΠΎΡ‚ΠΈ ΠΏΡ€Π°Π²ΠΈΠ»Π½ΠΎ.

Π‘Π»ΠΈΠΊΠ° 1.5: IPsec-over-GRE

НС ΠΏΠ»Π°Π½ΠΈΡ€Π°ΠΌ Π΄Π° користам IPsec-over-GRE Π½Π° ΠΌΡ€Π΅ΠΆΠ°Ρ‚Π°. Π‘ΠΎΠ±ΠΈΡ€Π°ΠΌ Π·Π°Ρ‚ΠΎΠ° ΡˆΡ‚ΠΎ сакам.

1.5 шСми Π½Π° домашна IPsec VPN. Π”Π΅ΠΌΠΎ Π·Π° Ρ‚Π΅ΡΡ‚ΠΈΡ€Π°ΡšΠ΅

Π—Π° Π΄Π° ја распорСдитС ΡˆΠ΅ΠΌΠ°Ρ‚Π° GRE-over-IPsec ΠΎΠ±Ρ€Π°Ρ‚Π½ΠΎ:

  • ΠŸΠΎΠΏΡ€Π°Π²Π΅Ρ‚Π΅ ја листата Π·Π° пристап Π·Π° ΡˆΠΈΡ„Ρ€ΠΈΡ€Π°ΡšΠ΅ - насочСн ΡΠΎΠΎΠ±Ρ€Π°ΡœΠ°Ρ˜ ΠΎΠ΄ LAN1 Π΄ΠΎ LAN2 ΠΈ ΠΎΠ±Ρ€Π°Ρ‚Π½ΠΎ;
  • ΠšΠΎΠ½Ρ„ΠΈΠ³ΡƒΡ€ΠΈΡ€Π°Ρ˜Ρ‚Π΅ Ρ€ΡƒΡ‚ΠΈΡ€Π°ΡšΠ΅ ΠΏΡ€Π΅ΠΊΡƒ GRE;
  • Π—Π°ΠΊΠ°Ρ‡Π΅Ρ‚Π΅ ΠΊΡ€ΠΈΠΏΡ‚ΠΎΠΌΠ°ΠΏΠ° Π½Π° ΠΈΠ½Ρ‚Π΅Ρ€Ρ„Π΅Ρ˜ΡΠΎΡ‚ GRE.

Π‘Ρ‚Π°Π½Π΄Π°Ρ€Π΄Π½ΠΎ, Π½Π΅ΠΌΠ° ΠΈΠ½Ρ‚Π΅Ρ€Ρ„Π΅Ρ˜Ρ GRE Π²ΠΎ ΠΊΠΎΠ½Π·ΠΎΠ»Π°Ρ‚Π° Π·Π° ΠΏΠΎΡ€Ρ‚Π°Ρ‚Π° слична Π½Π° Cisco. ΠŸΠΎΡΡ‚ΠΎΠΈ само Π²ΠΎ ΠΎΠΏΠ΅Ρ€Π°Ρ‚ΠΈΠ²Π½ΠΈΠΎΡ‚ систСм.

Π“ΠΎ Π΄ΠΎΠ΄Π°Π²Π°ΠΌ ΠΈΠ½Ρ‚Π΅Ρ€Ρ„Π΅Ρ˜ΡΠΎΡ‚ GRE Π½Π° ΠΊΠΎΠ½Π·ΠΎΠ»Π°Ρ‚Π° слична Π½Π° Cisco. Π—Π° Π΄Π° Π³ΠΎ Π½Π°ΠΏΡ€Π°Π²ΠΈΡ‚Π΅ ΠΎΠ²Π°, ја ΡƒΡ€Π΅Π΄ΡƒΠ²Π°ΠΌ Π΄Π°Ρ‚ΠΎΡ‚Π΅ΠΊΠ°Ρ‚Π° /etc/ifaliases.cf:

interface (name="FastEthernet0/0" pattern="eth0")
interface (name="FastEthernet0/1" pattern="eth1")
interface (name="FastEthernet0/2" pattern="eth2")
interface (name="FastEthernet0/3" pattern="eth3")
interface (name="Tunnel0" pattern="gre1")
interface (name="default" pattern="*")

ΠΊΠ°Π΄Π΅ ΡˆΡ‚ΠΎ gre1 Π΅ ΠΎΠ·Π½Π°ΠΊΠ°Ρ‚Π° Π½Π° ΠΈΠ½Ρ‚Π΅Ρ€Ρ„Π΅Ρ˜ΡΠΎΡ‚ Π²ΠΎ ΠΎΠΏΠ΅Ρ€Π°Ρ‚ΠΈΠ²Π½ΠΈΠΎΡ‚ систСм, Tunnel0 Π΅ ΠΎΠ·Π½Π°ΠΊΠ°Ρ‚Π° Π½Π° ΠΈΠ½Ρ‚Π΅Ρ€Ρ„Π΅Ρ˜ΡΠΎΡ‚ Π²ΠΎ ΠΊΠΎΠ½Π·ΠΎΠ»Π°Ρ‚Π° слична Π½Π° Cisco.

ΠŸΠΎΠ²Ρ‚ΠΎΡ€Π½ΠΎ Π³ΠΎ прСсмСтувам Ρ…Π°ΡˆΠΎΡ‚ Π½Π° Π΄Π°Ρ‚ΠΎΡ‚Π΅ΠΊΠ°Ρ‚Π°:

root@VG1:~# integr_mgr calc -f /etc/ifaliases.cf

SUCCESS:  Operation was successful.

Π‘Π΅Π³Π° ΠΈΠ½Ρ‚Π΅Ρ€Ρ„Π΅Ρ˜ΡΠΎΡ‚ Tunnel0 сС појави Π²ΠΎ ΠΊΠΎΠ½Π·ΠΎΠ»Π°Ρ‚Π° слична Π½Π° Cisco:

VG1# show run
interface Tunnel0
ip address 1.1.1.1 255.255.255.252
mtu 1400

ΠŸΠΎΠΏΡ€Π°Π²ΠΊΠ° Π½Π° списокот Π·Π° пристап Π·Π° ΡˆΠΈΡ„Ρ€ΠΈΡ€Π°ΡšΠ΅:

VG1(config)#
ip access-list extended LIST
permit ip 192.168.1.0 0.0.0.255 192.168.3.0 0.0.0.255

ΠšΠΎΠ½Ρ„ΠΈΠ³ΡƒΡ€ΠΈΡ€Π°ΠΌ Ρ€ΡƒΡ‚ΠΈΡ€Π°ΡšΠ΅ ΠΏΡ€Π΅ΠΊΡƒ GRE:

VG1(config)#
no ip route 0.0.0.0 0.0.0.0 172.16.1.254
ip route 192.168.3.0 255.255.255.0 1.1.1.2

Ја отстранувам ΠΊΡ€ΠΈΠΏΡ‚ΠΎΠΌΠ°ΠΏΠ°Ρ‚Π° ΠΎΠ΄ Fa0 / 0 ΠΈ ја Π²Ρ€Π·ΡƒΠ²Π°ΠΌ Π·Π° ΠΈΠ½Ρ‚Π΅Ρ€Ρ„Π΅Ρ˜ΡΠΎΡ‚ GRE:

VG1(config)#
interface Tunnel0
crypto map CMAP

Π—Π° VG2 Π΅ слично.

ΠŸΡ€ΠΎΠ²Π΅Ρ€ΠΊΠ°:

root@VG2:~# tcpdump -i eth0 -w /home/dump3.pcap

root@VG1:~# ping 192.168.2.254 -I 192.168.1.253 -c 4
PING 192.168.2.254 (192.168.2.254) from 192.168.1.253 : 56(84) bytes of data.
64 bytes from 192.168.2.254: icmp_seq=1 ttl=64 time=492 ms
64 bytes from 192.168.2.254: icmp_seq=2 ttl=64 time=1.08 ms
64 bytes from 192.168.2.254: icmp_seq=3 ttl=64 time=1.06 ms
64 bytes from 192.168.2.254: icmp_seq=4 ttl=64 time=1.07 ms

--- 192.168.2.254 ping statistics ---
4 packets transmitted, 4 received, 0% packet loss, time 3006ms
rtt min/avg/max/mdev = 1.064/124.048/492.972/212.998 ms

Бтатистика Π½Π° ISAKMP/IPsec:

root@VG1:~# sa_mgr show
ISAKMP sessions: 0 initiated, 0 responded

ISAKMP connections:
Num Conn-id (Local Addr,Port)-(Remote Addr,Port) State Sent Rcvd
1 2 (172.16.1.253,500)-(172.16.1.254,500) active 1094 1022

IPsec connections:
Num Conn-id (Local Addr,Port)-(Remote Addr,Port) Protocol Action Type Sent Rcvd
1 2 (192.168.1.0-192.168.1.255,*)-(192.168.2.0-192.168.2.255,*) * ESP tunn 352 352

Π’ΠΎ Π΄Π΅ΠΏΠΎΠ½ΠΈΡ˜Π°Ρ‚Π° Π·Π° ΡΠΎΠΎΠ±Ρ€Π°ΡœΠ°Ρ˜ ESP, ΠΏΠ°ΠΊΠ΅Ρ‚ΠΈΡ‚Π΅ сС инкапсулирани Π²ΠΎ GRE:

1.5 шСми Π½Π° домашна IPsec VPN. Π”Π΅ΠΌΠΎ Π·Π° Ρ‚Π΅ΡΡ‚ΠΈΡ€Π°ΡšΠ΅

Π—Π°ΠΊΠ»ΡƒΡ‡ΠΎΠΊ: IPsec-over-GRE Ρ€Π°Π±ΠΎΡ‚ΠΈ ΠΏΡ€Π°Π²ΠΈΠ»Π½ΠΎ.

Π Π΅Π·ΡƒΠ»Ρ‚Π°Ρ‚ΠΈΡ‚Π΅ ΠΎΠ΄

Π”ΠΎΠ²ΠΎΠ»Π½Π° бСшС Π΅Π΄Π½Π° шолја ΠΊΠ°Ρ„Π΅. Π‘ΠΊΠΈΡ†ΠΈΡ€Π°Π² инструкции Π·Π° добивањС Π΄Π΅ΠΌΠΎ Π²Π΅Ρ€Π·ΠΈΡ˜Π°. ΠšΠΎΠ½Ρ„ΠΈΠ³ΡƒΡ€ΠΈΡ€Π°Π½ GRE-over-IPsec ΠΈ распорСдСн ΠΎΠ±Ρ€Π°Ρ‚Π½ΠΎ.

ΠšΠ°Ρ€Ρ‚Π°Ρ‚Π° Π½Π° ΠΌΡ€Π΅ΠΆΠ½ΠΈΡ‚Π΅ ΠΈΠ½Ρ‚Π΅Ρ€Ρ„Π΅Ρ˜ΡΠΈ Π²ΠΎ Π²Π΅Ρ€Π·ΠΈΡ˜Π°Ρ‚Π° 4.3 Π΅ ​​автоматска! ВСстирам ΠΏΠΎΠ½Π°Ρ‚Π°ΠΌΡƒ.

АнонимСн ΠΈΠ½ΠΆΠ΅Π½Π΅Ρ€
t.me/anonymous_engineer


Π˜Π·Π²ΠΎΡ€: www.habr.com

Π”ΠΎΠ΄Π°Π΄Π΅Ρ‚Π΅ ΠΊΠΎΠΌΠ΅Π½Ρ‚Π°Ρ€