{"id":32137,"date":"2019-10-31T21:45:21","date_gmt":"2019-10-31T18:45:21","guid":{"rendered":"https:\/\/prohoster.info\/blog\/nastrojka-ipsec-site-to-site-vpn-na-oborudovanii-palo-alto-networks\/"},"modified":"2019-10-31T21:45:21","modified_gmt":"2019-10-31T18:45:21","slug":"nastrojka-ipsec-site-to-site-vpn-na-oborudovanii-palo-alto-networks","status":"publish","type":"post","link":"https:\/\/prohoster.info\/sq\/blog\/administrirovanie\/nastrojka-ipsec-site-to-site-vpn-na-oborudovanii-palo-alto-networks","title":{"rendered":"Konfigurimi i IPSec Site-to-Site VPN n\u00eb pajisjet Palo Alto Networks","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p><img decoding=\"async\" alt=\"Konfigurimi i IPSec Site-to-Site VPN n\u00eb pajisjet Palo Alto Networks\" src=\"\/wp-content\/uploads\/2019\/04\/65e9f9ded1254535c40642a480432877.png\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\nKy kjo artikull \u00ebsht\u00eb vazhdimi <noindex><a rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/company\/crosstech\/blog\/443726\/\">i materialit t\u00eb m\u00ebparsh\u00ebm<\/a><\/noindex>, i dedikuar ve\u00e7orive t\u00eb konfigurimit t\u00eb pajisjeve <b>Palo Alto Networks <\/b>. K\u00ebtu d\u00ebshirojm\u00eb t\u00eb flasim p\u00ebr konfigurimin <b>IPSec Site-to-Site VPN<\/b> n\u00eb pajisjet <b>Palo Alto Networks<\/b> dhe p\u00ebr nj\u00eb mund\u00ebsi konfigurimi p\u00ebr lidhjen me disa ofrues interneti.<br \/>\n<noindex><a rel=\"nofollow\" name=\"habracut\"><\/a><\/noindex><br \/>\nP\u00ebr demonstrim do t\u00eb p\u00ebrdoret nj\u00eb skem\u00eb standarde lidhjeje midis zyr\u00ebs qendrore dhe deg\u00ebs. P\u00ebr t\u00eb siguruar nj\u00eb lidhje interneti t\u00eb q\u00ebndrueshme, zyrat qendrore p\u00ebrdorin lidhjen me dy ofrues: ISP-1 dhe ISP-2. Delega ka lidhje vet\u00ebm me nj\u00eb ofrues, ISP-3. Midis firewalleve PA-1 dhe PA-2 krijohen dy tunel\u00eb. Tunel\u00ebt punojn\u00eb n\u00eb mod\u00ebn <b>Active-Standby<\/b>, Tuneli-1 \u00ebsht\u00eb aktiv, Tuneli-2 do t\u00eb filloj\u00eb t\u00eb kaloj\u00eb trafik n\u00eb rast d\u00ebshtimi t\u00eb Tuneli-1. Tuneli-1 p\u00ebrdor lidhjen me ofruesin internet ISP-1, Tuneli-2 p\u00ebrdor lidhjen me ofruesin internet ISP-2. T\u00eb gjitha adresat IP jan\u00eb gjeneruar rast\u00ebsisht p\u00ebr q\u00ebllime demonstrative dhe nuk kan\u00eb lidhje me realitetin.<\/p>\n<p><img decoding=\"async\" alt=\"Konfigurimi i IPSec Site-to-Site VPN n\u00eb pajisjet Palo Alto Networks\" src=\"\/wp-content\/uploads\/2019\/04\/e1e9c97bdcea77c3c1adf44e48f1c275.png\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\nP\u00ebr t\u00eb nd\u00ebrtuar VPN Site-to-Site do t\u00eb p\u00ebrdoret <b>IPSec<\/b> \u2014 nj\u00eb grup protokollesh p\u00ebr t\u00eb siguruar mbrojtjen e t\u00eb dh\u00ebnave t\u00eb transmetuara p\u00ebrmes protokollit IP. <b>IPSec <\/b>do t\u00eb punoj\u00eb me p\u00ebrdorimin e protokollit t\u00eb siguris\u00eb <b>ESP <\/b>(Encapsulating Security Payload), i cili siguron enkriptimin e t\u00eb dh\u00ebnave t\u00eb transmetuara.<\/p>\n<p>N\u00eb <b>IPSec <\/b>\u00ebsht\u00eb <b>IKE <\/b>(Internet Key Exchange) \u2014 protokolli p\u00ebrgjegj\u00ebs p\u00ebr negociat\u00ebn e SA (associacionet e siguris\u00eb), parametrat e siguris\u00eb q\u00eb p\u00ebrdoren p\u00ebr t\u00eb mbrojtur t\u00eb dh\u00ebnat e transmetuara. Firewalle PAN mb\u00ebshtesin <b>IKEv1 <\/b>dhe <b>IKEv2<\/b>.<\/p>\n<p>N\u00eb <b>IKEv1 <\/b>VPN nd\u00ebrtimi b\u00ebhet n\u00eb dy faza: <b>IKEv1 Faza 1 <\/b>(tuneli IKE) dhe <b>IKEv1 Faza 2<\/b> (tuneli IPSec), k\u00ebshtu krijohen dy tunel\u00eb, nj\u00ebri nga t\u00eb cil\u00ebt sh\u00ebrben p\u00ebr shk\u00ebmbimin e informacionit administrativ midis firewalleve, tjetri \u2014 p\u00ebr transmetimin e trafikut. N\u00eb <b>IKEv1 Faza 1<\/b> ka dy m\u00ebnyra operative \u2014 m\u00ebnyra kryesore dhe m\u00ebnyra agresive. M\u00ebnyra agresive p\u00ebrdor m\u00eb pak mesazhe dhe punon m\u00eb shpejt, por nuk mb\u00ebshtet Mbrojtjen e Identitetit t\u00eb Pjes\u00ebmarr\u00ebsit.<\/p>\n<p><b>IKEv2 <\/b>z\u00ebvend\u00ebsoi <b>IKEv1<\/b>, dhe krahasuar me <b>IKEv1<\/b> avantazhi i tij kryesor \u00ebsht\u00eb se ka k\u00ebrkesa m\u00eb t\u00eb ul\u00ebta p\u00ebr band\u00eb dhe m\u00eb shpejt negocion SA. N\u00eb <b>IKEv2<\/b> p\u00ebrdoren m\u00eb pak mesazhe administrative (gjithsej 4), mb\u00ebshtetet protokolli EAP, MOBIKE dhe \u00ebsht\u00eb shtuar nj\u00eb mekaniz\u00ebm p\u00ebr kontrollin e disponueshm\u00ebris\u00eb s\u00eb pjes\u00ebmarr\u00ebsit, me t\u00eb cilin krijohet tuneli \u2014 <b>Kontrolli i Aktivitetit<\/b>, duke z\u00ebvend\u00ebsuar Kontrollin e Pjes\u00ebmarr\u00ebsit t\u00eb Vdekur n\u00eb IKEv1. N\u00ebse kontrolli d\u00ebshton, ai <b>IKEv2 <\/b>mund t\u00eb kthej\u00eb tunelin dhe m\u00eb pas ta rikthej\u00eb automatikisht sa m\u00eb shpejt t\u00eb jet\u00eb e mundur. P\u00ebr m\u00eb shum\u00eb detaje mbi dallimet, mund t\u00eb <noindex><a rel=\"nofollow\" href=\"https:\/\/docs.paloaltonetworks.com\/pan-os\/8-0\/pan-os-admin\/vpns\/site-to-site-vpn-concepts\/ikev2\">lexoni k\u00ebtu<\/a><\/noindex>.<\/p>\n<p>N\u00ebse tuneli krijohet midis firewalleve t\u00eb prodhuesve t\u00eb ndrysh\u00ebm, ka mund\u00ebsi q\u00eb t\u00eb ket\u00eb gabime n\u00eb implementim <b>IKEv2<\/b>, dhe p\u00ebr subjektivitetin me pajisje t\u00eb tilla, ka mund\u00ebsin\u00eb p\u00ebr t\u00eb p\u00ebrdorur <b>IKEv1<\/b>. N\u00eb rastet tjera, \u00ebsht\u00eb m\u00eb mir\u00eb t\u00eb p\u00ebrdoret <b>IKEv2<\/b>.<\/p>\n<p>Hapat e konfigurimit:<\/p>\n<p><b>\u2022 Konfigurimi i dy ofruesve t\u00eb internetit n\u00eb m\u00ebnyr\u00ebn Active-Standby<\/b><\/p>\n<p>Ka disa m\u00ebnyra p\u00ebr t\u00eb realizuar k\u00ebt\u00eb funksion. Nj\u00ebra prej tyre \u00ebsht\u00eb p\u00ebrdorimi i mekanizmit <b>Monitorimi i Rrug\u00ebve<\/b>, e cila \u00ebsht\u00eb b\u00ebr\u00eb e disponueshme duke filluar nga versioni <b>PAN-OS 8.0.0<\/b>. N\u00eb k\u00ebt\u00eb shembull p\u00ebrdoret versioni 8.0.16. Ky funksion \u00ebsht\u00eb i ngjash\u00ebm me IP SLA n\u00eb routerat Cisco. N\u00eb parametrin e rrug\u00ebs statike default, konfigurohet d\u00ebrgimi i paketave ping n\u00eb nj\u00eb adres\u00eb IP t\u00eb caktuar nga nj\u00eb adres\u00eb burimi e caktuar. N\u00eb k\u00ebt\u00eb rast, interfejsi ethernet1\/1 pingon portin e paracaktuar nj\u00eb her\u00eb n\u00eb sekond\u00eb. N\u00ebse nuk ka p\u00ebrgjigje p\u00ebr tre ping t\u00eb nj\u00ebpasnj\u00ebsh\u00ebm, rruga konsiderohet jo funksionale dhe hiqet nga tabela e routingut. Nj\u00eb rrug\u00eb e till\u00eb konfigurohet n\u00eb drejtimin e ofruesit t\u00eb dyt\u00eb t\u00eb internetit, por me metrik t\u00eb lart\u00eb (\u00ebsht\u00eb rezerv\u00eb). Pasi rruga e par\u00eb t\u00eb hiqet nga tabela, firewall-i do t\u00eb filloj\u00eb t\u00eb d\u00ebrgoj\u00eb trafik n\u00eb rrug\u00ebn e dyt\u00eb \u2014 <b>Shk\u00ebputja<\/b>. Kur ofruesi i par\u00eb fillon t\u00eb p\u00ebrgjigjet n\u00eb ping, rruga e tij do t\u00eb kthehet n\u00eb tabel\u00eb dhe do t\u00eb z\u00ebvend\u00ebsoj\u00eb t\u00eb dyt\u00ebn p\u00ebr shkak t\u00eb metrik\u00ebs m\u00eb t\u00eb mir\u00eb \u2014 <b>Rikthimi<\/b>. Procesi <b>Shk\u00ebputja<\/b> zgjat disa sekonda n\u00eb var\u00ebsi t\u00eb intervaleve t\u00eb konfiguruara, por n\u00eb \u00e7do rast, procesi nuk \u00ebsht\u00eb momental, dhe n\u00eb k\u00ebt\u00eb koh\u00eb, trafik humbet. <b>Rikthimi<\/b> kalon pa humbje trafiku. Ka mund\u00ebsi t\u00eb b\u00ebhet <b>Shk\u00ebputja<\/b> m\u00eb shpejt, me an\u00eb t\u00eb <b>BFD<\/b>, n\u00ebse ofruesi i internetit e siguron nj\u00eb mund\u00ebsi t\u00eb till\u00eb. <b>BFD <\/b>mb\u00ebshtetet duke filluar nga modelit <b>PA-3000 Series<\/b> dhe <b>VM-100<\/b>. Si adres\u00eb p\u00ebr ping, \u00ebsht\u00eb m\u00eb mir\u00eb t\u00eb specifikoni nj\u00eb adres\u00eb publike, gjithmon\u00eb t\u00eb aksesueshme n\u00eb internet.<\/p>\n<p><img decoding=\"async\" alt=\"Konfigurimi i IPSec Site-to-Site VPN n\u00eb pajisjet Palo Alto Networks\" src=\"\/wp-content\/uploads\/2019\/04\/91f85e24112d5c997dc17d6492be2621.png\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\n<b>\u2022 Krijimi i nj\u00eb interfejsi tuneli<\/b><\/p>\n<p>Trafiku brenda tunelit transmetohet p\u00ebrmes interfejsve virtual\u00eb t\u00eb specializuar. \u00c7do nj\u00eb prej tyre duhet t\u00eb konfigurohet me nj\u00eb adres\u00eb IP nga rrjeti tranzit. N\u00eb k\u00ebt\u00eb shembull, p\u00ebr Tuneli-1 do t\u00eb p\u00ebrdoret subneti 172.16.1.0\/30, nd\u00ebrsa p\u00ebr Tuneli-2 \u2014 subneti 172.16.2.0\/30.<br \/>\nInterfejsi tuneli krijohet n\u00eb seksionin <b>Network -&gt; Interfaces -&gt; Tunnel<\/b>. Duhet t\u00eb specifikoni nj\u00eb router virtual dhe nj\u00eb zon\u00eb sigurie, si dhe nj\u00eb adres\u00eb IP nga rrjeti p\u00ebrkat\u00ebs. Numri i nd\u00ebrfaqes mund t\u00eb jet\u00eb \u00e7far\u00ebdo.<\/p>\n<p><img decoding=\"async\" alt=\"Konfigurimi i IPSec Site-to-Site VPN n\u00eb pajisjet Palo Alto Networks\" src=\"\/wp-content\/uploads\/2019\/04\/4d6ae0695e80de2ab86e791d4a77fb1a.png\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\n<img decoding=\"async\" alt=\"Konfigurimi i IPSec Site-to-Site VPN n\u00eb pajisjet Palo Alto Networks\" src=\"\/wp-content\/uploads\/2019\/04\/cd80ff75d9b2855892cb22e2d8f9d8d0.png\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\nN\u00eb seksionin <b>Advanced <\/b>mund t\u00eb specifikohet <b>Profili i Menaxhimit<\/b>, e cila do t\u00eb lejoj\u00eb ping n\u00eb k\u00ebt\u00eb nd\u00ebrfaqe, kjo mund t\u00eb jet\u00eb e dobishme p\u00ebr testim.<\/p>\n<p><img decoding=\"async\" alt=\"Konfigurimi i IPSec Site-to-Site VPN n\u00eb pajisjet Palo Alto Networks\" src=\"\/wp-content\/uploads\/2019\/04\/8eb1b7a0d97e4b2528a0c1d98677ca1f.png\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\n<b>\u2022 Konfigurimi i Profilit IKE<\/b><\/p>\n<p><b>Profili IKE<\/b> \u00ebsht\u00eb p\u00ebrgjegj\u00ebs p\u00ebr faz\u00ebn e par\u00eb t\u00eb krijimit t\u00eb lidhjes VPN, ku specifikohen parametrat e tunelit <b>IKE Faz\u00eb 1<\/b>. Profili krijohet n\u00eb seksionin <b>Network -&gt; Network Profiles -&gt; IKE Crypto<\/b>. Duhet t\u00eb specifikoni algoritmin e enkriptimit, hash, grupin e Diffie-Hellman dhe koh\u00ebn e jet\u00ebs s\u00eb \u00e7el\u00ebsit. N\u00eb p\u00ebrgjith\u00ebsi, sa m\u00eb t\u00eb komplikuar t\u00eb jen\u00eb algoritmet, aq m\u00eb keq \u00ebsht\u00eb performanca; ata duhet t\u00eb zgjidhen sipas k\u00ebrkesave specifike t\u00eb siguris\u00eb. Megjithat\u00eb, nuk rekomandohet kategorikisht p\u00ebrdorimi i grupit t\u00eb Diffie-Hellman m\u00eb posht\u00eb 14 p\u00ebr t\u00eb mbrojtur informacionin e r\u00ebnd\u00ebsish\u00ebm. Kjo \u00ebsht\u00eb e lidhur me vunerabilitetin e protokollit, t\u00eb cilin mund ta neutralizosh vet\u00ebm duke p\u00ebrdorur madh\u00ebsi modulo 2048 bit dhe m\u00eb lart, ose algoritme t\u00eb kriptografis\u00eb eliptike, t\u00eb cilat p\u00ebrdoren n\u00eb grupet 19, 20, 21, 24. K\u00ebto algoritmo kan\u00eb performanc\u00eb m\u00eb t\u00eb lart\u00eb krahasuar me kriptografin\u00eb tradicionale. <noindex><a rel=\"nofollow\" href=\"https:\/\/arstechnica.com\/information-technology\/2016\/10\/how-the-nsa-could-put-undetectable-trapdoors-in-millions-of-crypto-keys\/\">M\u00eb shum\u00eb k\u00ebtu<\/a><\/noindex>. Dhe <noindex><a rel=\"nofollow\" href=\"https:\/\/www.cisco.com\/c\/en\/us\/about\/security-center\/next-generation-cryptography.html\">k\u00ebtu<\/a><\/noindex>.<\/p>\n<p><img decoding=\"async\" alt=\"Konfigurimi i IPSec Site-to-Site VPN n\u00eb pajisjet Palo Alto Networks\" src=\"\/wp-content\/uploads\/2019\/04\/0ae865d3175cda77e91ae0dc3a304dda.png\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\n<b>\u2022 Konfigurimi i Profilit IPSec<\/b><\/p>\n<p>Faza e dyt\u00eb e krijimit t\u00eb lidhjes VPN \u2014 tuneli IPSec. Parametrat SA p\u00ebr t\u00eb konfigurohen n\u00eb <b>Network -&gt; Network Profiles -&gt; IPSec Crypto Profile<\/b>. K\u00ebtu duhet t\u00eb specifikoni protokollin IPSec \u2014 <b>AH <\/b>apo <b>ESP<\/b>, si dhe parametrat <b>SA <\/b> \u2014 algoritmet e hash, enkriptimit, grupet e Diffie-Hellman dhe koh\u00ebn e jet\u00ebs s\u00eb \u00e7el\u00ebsit. Parametrat SA n\u00eb Profilin IKE Crypto dhe Profilin IPSec Crypto mund t\u00eb mos p\u00ebrputhen.<\/p>\n<p><img decoding=\"async\" alt=\"Konfigurimi i IPSec Site-to-Site VPN n\u00eb pajisjet Palo Alto Networks\" src=\"\/wp-content\/uploads\/2019\/04\/d375361041882306b916d46dcf18a38c.png\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\n<b>\u2022 Konfigurimi i IKE Gateway<\/b><\/p>\n<p><b>IKE Gateway<\/b> \u2014 \u00ebsht\u00eb nj\u00eb objekt q\u00eb p\u00ebrfaq\u00ebson nj\u00eb router ose nj\u00eb firewall, me t\u00eb cilin nd\u00ebrtohet tuneli VPN. P\u00ebr \u00e7do tunel duhet t\u00eb krijohet nj\u00eb <b>IKE Gateway<\/b>. N\u00eb k\u00ebt\u00eb rast, krijohen dy tunel\u00eb, nj\u00eb p\u00ebr \u00e7do ofrues t\u00eb internetit. Specifikohen nd\u00ebrfaqja e daljes p\u00ebrkat\u00ebse dhe adresa e saj IP, adresa IP e partneri dhe \u00e7el\u00ebsi i p\u00ebrbashk\u00ebt. Si nj\u00eb alternativ\u00eb p\u00ebr \u00e7el\u00ebsin e p\u00ebrbashk\u00ebt, mund t\u00eb p\u00ebrdoren certifikatat.<\/p>\n<p><img decoding=\"async\" alt=\"Konfigurimi i IPSec Site-to-Site VPN n\u00eb pajisjet Palo Alto Networks\" src=\"\/wp-content\/uploads\/2019\/04\/902d6950a3b4127183659aaca252669e.png\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\nK\u00ebtu specifikohet profili i krijuar m\u00eb par\u00eb <b>IKE Crypto Profile<\/b>. Parametrat e objektit t\u00eb dyt\u00eb <b>IKE Gateway<\/b> jan\u00eb t\u00eb ngjash\u00ebm, p\u00ebrve\u00e7 adresave IP. N\u00ebse firewall-i Palo Alto Networks \u00ebsht\u00eb vendosur pas nj\u00eb router-i NAT, at\u00ebher\u00eb duhet t\u00eb aktivizoni mekanizmin <b>Kalimi NAT<\/b>.<\/p>\n<p><img decoding=\"async\" alt=\"Konfigurimi i IPSec Site-to-Site VPN n\u00eb pajisjet Palo Alto Networks\" src=\"\/wp-content\/uploads\/2019\/04\/4fc32cafe491c86344aa9484a019bd1f.png\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\n<b>\u2022 Konfigurimi i Tunelit IPSec<\/b><\/p>\n<p><b>Tuneli IPSec<\/b> \u2014 \u00ebsht\u00eb nj\u00eb objekt ku specifikohen parametrat e tunelit IPSec, sipas emrit. K\u00ebtu duhet t\u00eb specifikoni nd\u00ebrfaqen e tunelit dhe objektet e krijuara m\u00eb par\u00eb <b>IKE Gateway<\/b>, <b>IPSec Crypto Profile<\/b>. P\u00ebr t\u00eb siguruar kalimin automatik t\u00eb rrug\u00ebzimit n\u00eb tunelin rezerv\u00eb, duhet t\u00eb aktivizoni <b>Tunnel Monitor<\/b>. Ky \u00ebsht\u00eb nj\u00eb mekaniz\u00ebm, i cili kontrollon n\u00ebse partneri \u00ebsht\u00eb aktiv, duke p\u00ebrdorur trafik ICMP. Si adres\u00eb cak duhet t\u00eb specifikohet adresa IP e nd\u00ebrfaqes s\u00eb tunelit t\u00eb partnerit, me t\u00eb cilin nd\u00ebrtohet tuneli. N\u00eb profil specifikohen timerat dhe veprimi n\u00eb rast humbjeje t\u00eb lidhjes. <b>Wait Recover<\/b> \u2013 prisni derisa lidhja t\u00eb rikthehet, <b>Fail Over<\/b> \u2014 d\u00ebrgoni trafik n\u00eb nj\u00eb rrug\u00eb tjet\u00ebr, n\u00ebse ka nj\u00eb t\u00eb till\u00eb. Konfigurimi i tunelit t\u00eb dyt\u00eb \u00ebsht\u00eb plot\u00ebsisht i ngjash\u00ebm, specifikohet nd\u00ebrfaqja e dyt\u00eb e tunelit dhe IKE Gateway.<\/p>\n<p><img decoding=\"async\" alt=\"Konfigurimi i IPSec Site-to-Site VPN n\u00eb pajisjet Palo Alto Networks\" src=\"\/wp-content\/uploads\/2019\/04\/e609b3916a3b2f58342c5a368b8e9ae0.png\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\n<img decoding=\"async\" alt=\"Konfigurimi i IPSec Site-to-Site VPN n\u00eb pajisjet Palo Alto Networks\" src=\"\/wp-content\/uploads\/2019\/04\/91d0da4549f2298588ab99f1cfd7194b.png\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\n<b>\u2022 Konfigurimi i Rrug\u00ebzimit<\/b><\/p>\n<p>N\u00eb k\u00ebt\u00eb shembull p\u00ebrdoret rrug\u00ebzimi statik. N\u00eb firewall-in PA-1, p\u00ebrve\u00e7 dy rrug\u00ebve t\u00eb zakonshme, duhet t\u00eb specifikoni dy rrug\u00eb p\u00ebr subnet-in 10.10.10.0\/24 n\u00eb filial. Nj\u00eb rrug\u00eb p\u00ebrdor Tunnel-1, tjetra Tunnel-2. Rruga p\u00ebrmes Tunnel-1 \u00ebsht\u00eb kryesorja, pasi ka nj\u00eb metrik\u00eb m\u00eb t\u00eb ul\u00ebt. Mekanizmi <b>Monitorimi i Rrug\u00ebve<\/b> nuk p\u00ebrdoret p\u00ebr k\u00ebto rrug\u00eb. Kalimi mbulohet nga <b>Tunnel Monitor<\/b>.<\/p>\n<p><img decoding=\"async\" alt=\"Konfigurimi i IPSec Site-to-Site VPN n\u00eb pajisjet Palo Alto Networks\" src=\"\/wp-content\/uploads\/2019\/04\/865492c962787216747f876ae8e45156.png\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\nK\u00ebto rrug\u00eb duhet t\u00eb konfigurohen n\u00eb PA-2 p\u00ebr subnet-in 192.168.30.0\/24.<\/p>\n<p><img decoding=\"async\" alt=\"Konfigurimi i IPSec Site-to-Site VPN n\u00eb pajisjet Palo Alto Networks\" src=\"\/wp-content\/uploads\/2019\/04\/6af420d6272d7cf38f44b0ded85cdfa6.png\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\n<b>\u2022 Konfigurimi i Rregullave t\u00eb Rrjetit<\/b><\/p>\n<p>P\u00ebr funksionimin e tunelit nevojiten tre rregulla:<\/p>\n<ol>\n<li>P\u00ebr funksionimin e <b>Path Monitor<\/b> lejo ICMP n\u00eb nd\u00ebrfaqet e jashtme.<\/li>\n<li>P\u00ebr <b>IPSec <\/b>lejo aplikacionet <b>ike <\/b>dhe <b>ipsec <\/b>n\u00eb nd\u00ebrfaqet e jashtme.<\/li>\n<li>Lejo trafikun nd\u00ebrmjet subnet-eve t\u00eb brendshme dhe nd\u00ebrfaqeve t\u00eb tunelit.<\/li>\n<\/ol>\n<p>\n<img decoding=\"async\" alt=\"Konfigurimi i IPSec Site-to-Site VPN n\u00eb pajisjet Palo Alto Networks\" src=\"\/wp-content\/uploads\/2019\/04\/90525c88fb133cf9aa1cacefb51c9c98.png\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\n<b>P\u00ebrfundimi<\/b><\/p>\n<p>N\u00eb k\u00ebt\u00eb artikull, ne shqyrtuam nj\u00eb variant t\u00eb konfigurimit t\u00eb nj\u00eb lidhjeje interneti t\u00eb besueshme dhe<b> Site-to-Site VPN<\/b>. Shpresojm\u00eb q\u00eb informacioni ishte i dobish\u00ebm dhe lexuesi fitoi nj\u00eb ide p\u00ebr teknologjit\u00eb e p\u00ebrdorura n\u00eb <b>Palo Alto Networks<\/b>. N\u00ebse keni pyetje n\u00eb lidhje me konfigurimin dhe sugjerime p\u00ebr tema t\u00eb artikujve t\u00eb ardhsh\u00ebm \u2014 shkruani ato n\u00eb komentet, do t\u00eb jemi t\u00eb lumtur t\u00eb p\u00ebrgjigjemi.<br \/>\n<br \/>Burimi: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/company\/crosstech\/blog\/448952\/\">habr.com<\/a><\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0414\u0430\u043d\u043d\u0430\u044f \u0441\u0442\u0430\u0442\u044c\u044f \u043f\u0440\u0435\u0434\u0441\u0442\u0430\u0432\u043b\u044f\u0435\u0442 \u0441\u043e\u0431\u043e\u0439 \u043f\u0440\u043e\u0434\u043e\u043b\u0436\u0435\u043d\u0438\u0435 \u043f\u0440\u0435\u0434\u044b\u0434\u0443\u0449\u0435\u0433\u043e \u043c\u0430\u0442\u0435\u0440\u0438\u0430\u043b\u0430, \u043f\u043e\u0441\u0432\u044f\u0449\u0435\u043d\u043d\u043e\u0433\u043e \u043e\u0441\u043e\u0431\u0435\u043d\u043d\u043e\u0441\u0442\u044f\u043c \u043d\u0430\u0441\u0442\u0440\u043e\u0439\u043a\u0438 \u043e\u0431\u043e\u0440\u0443\u0434\u043e\u0432\u0430\u043d\u0438\u044f Palo Alto Networks . \u0417\u0434\u0435\u0441\u044c \u043c\u044b \u0445\u043e\u0442\u0438\u043c \u0440\u0430\u0441\u0441\u043a\u0430\u0437\u0430\u0442\u044c \u043e \u043d\u0430\u0441\u0442\u0440\u043e\u0439\u043a\u0435 IPSec Site-to-Site VPN \u043d\u0430 \u043e\u0431\u043e\u0440\u0443\u0434\u043e\u0432\u0430\u043d\u0438\u0438 Palo Alto Networks \u0438 \u043e \u0432\u043e\u0437\u043c\u043e\u0436\u043d\u043e\u043c \u0432\u0430\u0440\u0438\u0430\u043d\u0442\u0435 \u043a\u043e\u043d\u0444\u0438\u0433\u0443\u0440\u0430\u0446\u0438\u0438 \u043f\u043e\u0434\u043a\u043b\u044e\u0447\u0435\u043d\u0438\u044f \u043d\u0435\u0441\u043a\u043e\u043b\u044c\u043a\u0438\u0445 \u0438\u043d\u0442\u0435\u0440\u043d\u0435\u0442-\u043f\u0440\u043e\u0432\u0430\u0439\u0434\u0435\u0440\u043e\u0432. \u0414\u043b\u044f \u0434\u0435\u043c\u043e\u043d\u0441\u0442\u0440\u0430\u0446\u0438\u0438 \u0431\u0443\u0434\u0435\u0442 \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u043d\u0430 \u0441\u0442\u0430\u043d\u0434\u0430\u0440\u0442\u043d\u0430\u044f \u0441\u0445\u0435\u043c\u0430 \u043f\u043e\u0434\u043a\u043b\u044e\u0447\u0435\u043d\u0438\u044f \u0433\u043e\u043b\u043e\u0432\u043d\u043e\u0433\u043e \u043e\u0444\u0438\u0441\u0430 \u043a \u0444\u0438\u043b\u0438\u0430\u043b\u0443. \u0414\u043b\u044f \u0442\u043e\u0433\u043e, \u0447\u0442\u043e\u0431\u044b \u043e\u0431\u0435\u0441\u043f\u0435\u0447\u0438\u0442\u044c \u043e\u0442\u043a\u0430\u0437\u043e\u0443\u0441\u0442\u043e\u0439\u0447\u0438\u0432\u043e\u0435 \u0438\u043d\u0442\u0435\u0440\u043d\u0435\u0442-\u0441\u043e\u0435\u0434\u0438\u043d\u0435\u043d\u0438\u0435, \u0432 [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":23973,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[688],"tags":[],"class_list":["post-32137","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-administrirovanie"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.0.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0414\u0430\u043d\u043d\u0430\u044f \u0441\u0442\u0430\u0442\u044c\u044f \u043f\u0440\u0435\u0434\u0441\u0442\u0430\u0432\u043b\u044f\u0435\u0442 \u0441\u043e\u0431\u043e\u0439 \u043f\u0440\u043e\u0434\u043e\u043b\u0436\u0435\u043d\u0438\u0435 \u043f\u0440\u0435\u0434\u044b\u0434\u0443\u0449\u0435\u0433\u043e \u043c\u0430\u0442\u0435\u0440\u0438\u0430\u043b\u0430, \u043f\u043e\u0441\u0432\u044f\u0449\u0435\u043d\u043d\u043e\u0433\u043e \u043e\u0441\u043e\u0431\u0435\u043d\u043d\u043e\u0441\u0442\u044f\u043c \u043d\u0430\u0441\u0442\u0440\u043e\u0439\u043a\u0438 \u043e\u0431\u043e\u0440\u0443\u0434\u043e\u0432\u0430\u043d\u0438\u044f Palo Alto Networks . \u0417\u0434\u0435\u0441\u044c \u043c\u044b \u0445\u043e\u0442\u0438\u043c \u0440\u0430\u0441\u0441\u043a\u0430\u0437\u0430\u0442\u044c \u043e \u043d\u0430\u0441\u0442\u0440\u043e\u0439\u043a\u0435 IPSec Site-to-Site VPN \u043d\u0430 \u043e\u0431\u043e\u0440\u0443\u0434\u043e\u0432\u0430\u043d\u0438\u0438 Palo Alto Networks \u0438 \u043e \u0432\u043e\u0437\u043c\u043e\u0436\u043d\u043e\u043c \u0432\u0430\u0440\u0438\u0430\u043d\u0442\u0435 \u043a\u043e\u043d\u0444\u0438\u0433\u0443\u0440\u0430\u0446\u0438\u0438 \u043f\u043e\u0434\u043a\u043b\u044e\u0447\u0435\u043d\u0438\u044f \u043d\u0435\u0441\u043a\u043e\u043b\u044c\u043a\u0438\u0445 \u0438\u043d\u0442\u0435\u0440\u043d\u0435\u0442-\u043f\u0440\u043e\u0432\u0430\u0439\u0434\u0435\u0440\u043e\u0432. \u0414\u043b\u044f \u0434\u0435\u043c\u043e\u043d\u0441\u0442\u0440\u0430\u0446\u0438\u0438 \u0431\u0443\u0434\u0435\u0442 \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u043d\u0430 \u0441\u0442\u0430\u043d\u0434\u0430\u0440\u0442\u043d\u0430\u044f \u0441\u0445\u0435\u043c\u0430 \u043f\u043e\u0434\u043a\u043b\u044e\u0447\u0435\u043d\u0438\u044f \u0433\u043e\u043b\u043e\u0432\u043d\u043e\u0433\u043e \u043e\u0444\u0438\u0441\u0430 \u043a \u0444\u0438\u043b\u0438\u0430\u043b\u0443. \u0414\u043b\u044f \u0442\u043e\u0433\u043e, \u0447\u0442\u043e\u0431\u044b \u043e\u0431\u0435\u0441\u043f\u0435\u0447\u0438\u0442\u044c \u043e\u0442\u043a\u0430\u0437\u043e\u0443\u0441\u0442\u043e\u0439\u0447\u0438\u0432\u043e\u0435 \u0438\u043d\u0442\u0435\u0440\u043d\u0435\u0442-\u0441\u043e\u0435\u0434\u0438\u043d\u0435\u043d\u0438\u0435, \u0432\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/sq\/blog\/administrirovanie\/nastrojka-ipsec-site-to-site-vpn-na-oborudovanii-palo-alto-networks\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.0.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"sq_AL\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u041d\u0430\u0441\u0442\u0440\u043e\u0439\u043a\u0430 IPSec Site-to-Site VPN \u043d\u0430 \u043e\u0431\u043e\u0440\u0443\u0434\u043e\u0432\u0430\u043d\u0438\u0438 Palo Alto Networks | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0414\u0430\u043d\u043d\u0430\u044f \u0441\u0442\u0430\u0442\u044c\u044f \u043f\u0440\u0435\u0434\u0441\u0442\u0430\u0432\u043b\u044f\u0435\u0442 \u0441\u043e\u0431\u043e\u0439 \u043f\u0440\u043e\u0434\u043e\u043b\u0436\u0435\u043d\u0438\u0435 \u043f\u0440\u0435\u0434\u044b\u0434\u0443\u0449\u0435\u0433\u043e \u043c\u0430\u0442\u0435\u0440\u0438\u0430\u043b\u0430, \u043f\u043e\u0441\u0432\u044f\u0449\u0435\u043d\u043d\u043e\u0433\u043e \u043e\u0441\u043e\u0431\u0435\u043d\u043d\u043e\u0441\u0442\u044f\u043c \u043d\u0430\u0441\u0442\u0440\u043e\u0439\u043a\u0438 \u043e\u0431\u043e\u0440\u0443\u0434\u043e\u0432\u0430\u043d\u0438\u044f Palo Alto Networks . \u0417\u0434\u0435\u0441\u044c \u043c\u044b \u0445\u043e\u0442\u0438\u043c \u0440\u0430\u0441\u0441\u043a\u0430\u0437\u0430\u0442\u044c \u043e \u043d\u0430\u0441\u0442\u0440\u043e\u0439\u043a\u0435 IPSec Site-to-Site VPN \u043d\u0430 \u043e\u0431\u043e\u0440\u0443\u0434\u043e\u0432\u0430\u043d\u0438\u0438 Palo Alto Networks \u0438 \u043e \u0432\u043e\u0437\u043c\u043e\u0436\u043d\u043e\u043c \u0432\u0430\u0440\u0438\u0430\u043d\u0442\u0435 \u043a\u043e\u043d\u0444\u0438\u0433\u0443\u0440\u0430\u0446\u0438\u0438 \u043f\u043e\u0434\u043a\u043b\u044e\u0447\u0435\u043d\u0438\u044f \u043d\u0435\u0441\u043a\u043e\u043b\u044c\u043a\u0438\u0445 \u0438\u043d\u0442\u0435\u0440\u043d\u0435\u0442-\u043f\u0440\u043e\u0432\u0430\u0439\u0434\u0435\u0440\u043e\u0432. \u0414\u043b\u044f \u0434\u0435\u043c\u043e\u043d\u0441\u0442\u0440\u0430\u0446\u0438\u0438 \u0431\u0443\u0434\u0435\u0442 \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u043d\u0430 \u0441\u0442\u0430\u043d\u0434\u0430\u0440\u0442\u043d\u0430\u044f \u0441\u0445\u0435\u043c\u0430 \u043f\u043e\u0434\u043a\u043b\u044e\u0447\u0435\u043d\u0438\u044f \u0433\u043e\u043b\u043e\u0432\u043d\u043e\u0433\u043e \u043e\u0444\u0438\u0441\u0430 \u043a \u0444\u0438\u043b\u0438\u0430\u043b\u0443. \u0414\u043b\u044f \u0442\u043e\u0433\u043e, \u0447\u0442\u043e\u0431\u044b \u043e\u0431\u0435\u0441\u043f\u0435\u0447\u0438\u0442\u044c \u043e\u0442\u043a\u0430\u0437\u043e\u0443\u0441\u0442\u043e\u0439\u0447\u0438\u0432\u043e\u0435 \u0438\u043d\u0442\u0435\u0440\u043d\u0435\u0442-\u0441\u043e\u0435\u0434\u0438\u043d\u0435\u043d\u0438\u0435, \u0432\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/sq\/blog\/administrirovanie\/nastrojka-ipsec-site-to-site-vpn-na-oborudovanii-palo-alto-networks\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2019-10-31T18:45:21+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2019-10-31T18:45:21+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Konfigurimi i IPSec Site-to-Site VPN n\u00eb pajisjet Palo Alto Networks | ProHoster","description":"Ky artikull \u00ebsht\u00eb nj\u00eb vazhdim i materialit t\u00eb m\u00ebparsh\u00ebm, i dedikuar ve\u00e7orive t\u00eb konfigurimit t\u00eb pajisjeve Palo Alto Networks. K\u00ebtu d\u00ebshirojm\u00eb t\u00eb flasim p\u00ebr konfigurimin e IPSec Site-to-Site VPN n\u00eb pajisjet Palo Alto Networks dhe p\u00ebr nj\u00eb mund\u00ebsim t\u00eb cil\u00ebsimit t\u00eb lidhjeve me disa ofrues interneti. P\u00ebr demonstrim do t\u00eb p\u00ebrdoret nj\u00eb skem\u00eb standarde e lidhjes s\u00eb zyr\u00ebs kryesore me filialin. P\u00ebr t\u00eb siguruar nj\u00eb lidhje interneti t\u00eb besueshme, n\u00eb","canonical_url":"https:\/\/prohoster.info\/sq\/blog\/administrirovanie\/nastrojka-ipsec-site-to-site-vpn-na-oborudovanii-palo-alto-networks","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"sq_AL","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u041d\u0430\u0441\u0442\u0440\u043e\u0439\u043a\u0430 IPSec Site-to-Site VPN \u043d\u0430 \u043e\u0431\u043e\u0440\u0443\u0434\u043e\u0432\u0430\u043d\u0438\u0438 Palo Alto Networks | ProHoster","og:description":"\u0414\u0430\u043d\u043d\u0430\u044f \u0441\u0442\u0430\u0442\u044c\u044f \u043f\u0440\u0435\u0434\u0441\u0442\u0430\u0432\u043b\u044f\u0435\u0442 \u0441\u043e\u0431\u043e\u0439 \u043f\u0440\u043e\u0434\u043e\u043b\u0436\u0435\u043d\u0438\u0435 \u043f\u0440\u0435\u0434\u044b\u0434\u0443\u0449\u0435\u0433\u043e \u043c\u0430\u0442\u0435\u0440\u0438\u0430\u043b\u0430, \u043f\u043e\u0441\u0432\u044f\u0449\u0435\u043d\u043d\u043e\u0433\u043e \u043e\u0441\u043e\u0431\u0435\u043d\u043d\u043e\u0441\u0442\u044f\u043c \u043d\u0430\u0441\u0442\u0440\u043e\u0439\u043a\u0438 \u043e\u0431\u043e\u0440\u0443\u0434\u043e\u0432\u0430\u043d\u0438\u044f Palo Alto Networks . \u0417\u0434\u0435\u0441\u044c \u043c\u044b \u0445\u043e\u0442\u0438\u043c \u0440\u0430\u0441\u0441\u043a\u0430\u0437\u0430\u0442\u044c \u043e \u043d\u0430\u0441\u0442\u0440\u043e\u0439\u043a\u0435 IPSec Site-to-Site VPN \u043d\u0430 \u043e\u0431\u043e\u0440\u0443\u0434\u043e\u0432\u0430\u043d\u0438\u0438 Palo Alto Networks \u0438 \u043e \u0432\u043e\u0437\u043c\u043e\u0436\u043d\u043e\u043c \u0432\u0430\u0440\u0438\u0430\u043d\u0442\u0435 \u043a\u043e\u043d\u0444\u0438\u0433\u0443\u0440\u0430\u0446\u0438\u0438 \u043f\u043e\u0434\u043a\u043b\u044e\u0447\u0435\u043d\u0438\u044f \u043d\u0435\u0441\u043a\u043e\u043b\u044c\u043a\u0438\u0445 \u0438\u043d\u0442\u0435\u0440\u043d\u0435\u0442-\u043f\u0440\u043e\u0432\u0430\u0439\u0434\u0435\u0440\u043e\u0432. \u0414\u043b\u044f \u0434\u0435\u043c\u043e\u043d\u0441\u0442\u0440\u0430\u0446\u0438\u0438 \u0431\u0443\u0434\u0435\u0442 \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u043d\u0430 \u0441\u0442\u0430\u043d\u0434\u0430\u0440\u0442\u043d\u0430\u044f \u0441\u0445\u0435\u043c\u0430 \u043f\u043e\u0434\u043a\u043b\u044e\u0447\u0435\u043d\u0438\u044f \u0433\u043e\u043b\u043e\u0432\u043d\u043e\u0433\u043e \u043e\u0444\u0438\u0441\u0430 \u043a \u0444\u0438\u043b\u0438\u0430\u043b\u0443. \u0414\u043b\u044f \u0442\u043e\u0433\u043e, \u0447\u0442\u043e\u0431\u044b \u043e\u0431\u0435\u0441\u043f\u0435\u0447\u0438\u0442\u044c \u043e\u0442\u043a\u0430\u0437\u043e\u0443\u0441\u0442\u043e\u0439\u0447\u0438\u0432\u043e\u0435 \u0438\u043d\u0442\u0435\u0440\u043d\u0435\u0442-\u0441\u043e\u0435\u0434\u0438\u043d\u0435\u043d\u0438\u0435, \u0432","og:url":"https:\/\/prohoster.info\/sq\/blog\/administrirovanie\/nastrojka-ipsec-site-to-site-vpn-na-oborudovanii-palo-alto-networks","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2019-10-31T18:45:21+00:00","article:modified_time":"2019-10-31T18:45:21+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"32137","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":"2026-01-21 09:27:20","breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-03-01 03:04:40","updated":"2026-01-21 09:27:20","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts\/32137","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/comments?post=32137"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts\/32137\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/media\/23973"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/media?parent=32137"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/categories?post=32137"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/tags?post=32137"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}