NSX Edge imatilola kugwiritsa ntchito njira zonse ziwiri.
Tidzakonza pogwiritsa ntchito benchi yoyesera yokhala ndi ma NSX Edge awiri, seva ya Linux yokhala ndi daemon yoyikidwa masewera ndi laputopu ya Windows kuyesa Remote Access VPN.
IPsec
Mu mawonekedwe a vCloud Director, pitani kugawo la Administration ndikusankha vDC. Pa tsamba la Edge Gateways, sankhani Edge yomwe tikufuna, dinani kumanja ndikusankha Edge Gateway Services.
Mu mawonekedwe a NSX Edge, pitani ku VPN-IPsec VPN tabu, ndiye ku IPsec VPN Sites gawo ndipo dinani + kuti muwonjezere tsamba latsopano.
Lembani magawo ofunikira:
Yathandiza - imatsegula tsamba lakutali.
Zolemba - amaonetsetsa kuti chinsinsi chilichonse chatsopano cha cryptographic sichikugwirizana ndi fungulo lapitalo.
Local ID ndi Local Endpointt ndi adilesi yakunja ya NSX Edge.
Chilichonse chakonzeka, IPsec VPN ya malo ndi malo ikugwira ntchito.
Mu chitsanzo ichi, tidagwiritsa ntchito PSK potsimikizira anzawo, koma kutsimikizika kwa satifiketi ndikothekanso. Kuti muchite izi, pitani ku Global Configuration tabu, yambitsani chitsimikiziro cha satifiketi ndikusankha satifiketi yokha.
Ndikuwona kuti kuchuluka kwa tunnel za IPsec kumadalira kukula kwa Edge Gateway yomwe yatumizidwa (werengani izi m'mabuku athu. nkhani yoyamba).
SSL VPN
SSL VPN-Plus ndi imodzi mwazosankha za Remote Access VPN. Imalola ogwiritsa ntchito akutali kuti alumikizane motetezeka ndi maukonde achinsinsi kuseri kwa NSX Edge Gateway. Msewu wobisika wa SSL VPN-plus imakhazikitsidwa pakati pa kasitomala (Windows, Linux, Mac) ndi NSX Edge.
Tiyeni tiyambe kukhazikitsa. Mugawo loyang'anira ntchito ya Edge Gateway, pitani ku tabu ya SSL VPN-Plus, kenako ku Zikhazikiko za Seva. Timasankha adilesi ndi doko pomwe seva imamvera zolumikizira zomwe zikubwera, yambitsani mitengo ndikusankha ma algorithms ofunikira.
Apa mutha kusinthanso satifiketi yomwe seva idzagwiritse ntchito.
Zonse zikakonzeka, yatsani seva ndipo musaiwale kusunga zoikamo.
Kenako, tiyenera kukhazikitsa dziwe la ma adilesi omwe tidzapereka kwa makasitomala akalumikizana. Netiweki iyi ndi yosiyana ndi subnet iliyonse yomwe ilipo mdera lanu la NSX ndipo sifunika kukonzedwa pazida zina pamanetiweki akuthupi, kupatula njira zomwe zimalozera.
Pitani ku tabu ya IP Pools ndikudina +.
Sankhani ma adilesi, subnet mask ndi zipata. Apa mutha kusinthanso makonda a seva za DNS ndi WINS.
Chifukwa dziwe.
Tsopano tiyeni tiwonjezere ma netiweki omwe ogwiritsa ntchito olumikizana ndi VPN azitha kuwapeza. Pitani ku tabu ya Private Networks ndikudina +.
Kuphatikiza pa zinthu zofunika monga dzina ndi mawu achinsinsi, apa mungathe, mwachitsanzo, kuletsa wogwiritsa ntchito kusintha mawu achinsinsi kapena, mosiyana, kumukakamiza kuti asinthe mawu achinsinsi akadzalowanso.
Ogwiritsa ntchito onse ofunikira atawonjezedwa, pitani ku tabu ya Instalation Packages, dinani + ndikupanga choyikiracho, chomwe chidzatsitsidwa ndi wogwira ntchito kutali kuti akhazikitse.
Dinani +. Sankhani adilesi ndi doko la seva yomwe kasitomala adzalumikiza, ndi nsanja zomwe mukufuna kupanga phukusi loyika.
Pansi pa zenera ili, mutha kufotokozera zokonda za kasitomala za Windows. Sankhani:
yambitsani kasitomala pa logon - kasitomala wa VPN adzawonjezedwa kuti ayambe pa makina akutali;
pangani chithunzi cha desktop - ipanga chizindikiro cha kasitomala wa VPN pa desktop;
chitsimikiziro cha satifiketi yachitetezo cha seva - chidzatsimikizira satifiketi ya seva ikalumikizidwa.
Kukhazikitsa kwa seva kwatha.
Tsopano tiyeni titsitse phukusi loyika lomwe tidapanga pomaliza ku PC yakutali. Pokhazikitsa seva, tidatchula adilesi yake yakunja (185.148.83.16) ndi doko (445). Ndi pa adilesi iyi yomwe tiyenera kupita mu msakatuli. Pankhani yanga ndi 185.148.83.16: 445.
Izi zitha kukhala zothandiza, mwachitsanzo, pakusamutsa makina owoneka bwino: VM ikasamukira kudera lina, makinawo amasunga maadiresi ake a IP ndipo sadzataya kulumikizana ndi makina ena omwe ali mugawo lomwelo la L2 nawo.
M'malo athu oyesera, tidzagwirizanitsa malo awiri kwa wina ndi mzake, tidzawatcha A ndi B, motero, Tili ndi ma NSX awiri ndi maukonde awiri opangidwa mofanana omwe amapangidwa ku Edges zosiyana. Makina A ali ndi adilesi 10.10.10.250/24, Makina B ali ndi adilesi 10.10.10.2/24.
Mu vCloud Director, pitani ku tabu ya Administration, pitani ku VDC yomwe tikufuna, pitani ku Org VDC Networks tabu ndikuwonjezera maukonde awiri atsopano.
Sankhani mtundu wa netiweki yoyendetsedwa ndikumanga netiweki iyi ku NSX yathu. Timayika checkbox Pangani ngati subinterface.
Zotsatira zake, tiyenera kupeza maukonde awiri. Muchitsanzo chathu, amatchedwa network-a ndi network-b yokhala ndi zoikamo zapakhomo ndi chigoba chomwecho.
Tsopano tiyeni tipitirire ku zoikamo za NSX yoyamba. Iyi ikhala NSX yomwe Network A imalumikizidwa nayo. Ikhala ngati seva.
Timabwerera ku mawonekedwe a NSx Edge / Pitani ku tabu ya VPN -> L2VPN. Timayatsa L2VPN, sankhani njira yogwiritsira ntchito Seva, m'makonzedwe a Server Global timatchula adilesi yakunja ya NSX IP yomwe doko la ngalandeyo lidzamvera. Mwachikhazikitso, socket idzatsegulidwa pa doko 443, koma izi zikhoza kusinthidwa. Musaiwale kusankha makonda achinsinsi amsewu wamtsogolo.
Mu Egress Optimization Gateway Address timayika adilesi yachipata. Izi ndizofunikira kuti pasakhale kutsutsana kwa ma adilesi a IP, chifukwa chipata cha maukonde athu chili ndi adilesi yomweyo. Kenako alemba pa sankhani SUB-INTERFACES batani.
Apa timasankha subinterface yomwe tikufuna. Timasunga zoikamo.
Tsopano tiyeni tipitirire kukonza NSX kuchokera kumbali ya kasitomala.
Timapita ku NSX mbali B, kupita ku VPN -> L2VPN, yambitsani L2VPN, ikani L2VPN mode kuti mukhale kasitomala. Pa Client Global tabu, ikani adilesi ndi doko la NSX A, zomwe tidazitchulapo kale kuti Kumvetsera IP ndi Port kumbali ya seva. Ndikofunikiranso kukhazikitsa zosintha zomwezo za encryption kuti zikhale zofananira pomwe ngalandeyo imakwezedwa.
Timapukuta pansipa, sankhani mawonekedwe amkati momwe msewu wa L2VPN udzapangidwira.
Mu Egress Optimization Gateway Address timayika adilesi yachipata. Khazikitsani id-user ndi password. Timasankha subinterface ndipo musaiwale kusunga zoikamo.
Kwenikweni, ndizo zonse. Zokonda pa kasitomala ndi mbali ya seva ndizofanana, kupatula ma nuances angapo.
Tsopano titha kuwona kuti ngalande yathu yagwira ntchito popita ku Statistics -> L2VPN pa NSX iliyonse.
Ngati tipita ku cholumikizira cha Edge Gateway iliyonse, tiwona pa chilichonse patebulo la arp ma adilesi a ma VM onse awiri.
Ndizo zonse za VPN pa NSX Edge. Funsani ngati chinachake sichikudziwika. Ilinso gawo lomaliza lazolemba zogwira ntchito ndi NSX Edge. Tikukhulupirira kuti anali othandiza π