{"id":53572,"date":"2019-12-05T00:00:00","date_gmt":"2019-12-04T21:00:00","guid":{"rendered":"https:\/\/prohoster.info\/blog\/blog_prohoster\/chto-proishodit-pri-soedineniyah-vnutri-i-vne-vpn-tunnelya"},"modified":"2020-02-18T14:01:29","modified_gmt":"2020-02-18T11:01:29","slug":"chto-proishodit-pri-soedineniyah-vnutri-i-vne-vpn-tunnelya","status":"publish","type":"post","link":"https:\/\/prohoster.info\/sq\/blog\/administrirovanie\/chto-proishodit-pri-soedineniyah-vnutri-i-vne-vpn-tunnelya","title":{"rendered":"\u00c7far\u00eb ndodh me lidhjet brenda dhe jasht\u00eb tunelit VPN","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>Nga letra n\u00eb sh\u00ebrbimin e mb\u00ebshtetjes teknike Tucha lindin artikuj t\u00eb v\u00ebrtet\u00eb. S\u00eb fundmi, na kontaktoi nj\u00eb klient me k\u00ebrkes\u00ebn p\u00ebr t\u00eb sqaruar se \u00e7far\u00eb ndodh gjat\u00eb lidhjeve brenda VPN-tunelit midis zyr\u00ebs s\u00eb p\u00ebrdoruesit dhe ambientit n\u00eb cloud, si dhe gjat\u00eb lidhjeve jasht\u00eb VPN-tunelit. Prandaj, i gjith\u00eb teksti i paraqitur m\u00eb posht\u00eb \u00ebsht\u00eb nj\u00eb let\u00ebr reale q\u00eb ne i d\u00ebrguam nj\u00ebrit prej klient\u00ebve tan\u00eb n\u00eb p\u00ebrgjigje t\u00eb pyetjes s\u00eb tij. Sigurisht, ne e ndryshuam adres\u00ebn IP p\u00ebr t\u00eb mos e deanonimizuar klientin. Por, po, sh\u00ebrbimi i mb\u00ebshtetjes teknike Tucha v\u00ebrtet njihet p\u00ebr p\u00ebrgjigjet e tij t\u00eb detajuara dhe letra informuese. \ud83d\ude42<\/p>\n<p>Sigurisht, ne kuptojm\u00eb se p\u00ebr shum\u00eb njer\u00ebz kjo artikull nuk do t\u00eb jet\u00eb nj\u00eb zbulim. Por, duke pasur parasysh se her\u00eb pas here n\u00eb Habr shfaqen artikuj p\u00ebr administrator\u00ebt e rinj, si dhe n\u00eb drit\u00ebn e faktit se ky artikull erdhi nga nj\u00eb let\u00ebr reale p\u00ebr nj\u00eb klient real, ne s\u00ebrish do ta ndajm\u00eb k\u00ebt\u00eb informacion edhe k\u00ebtu. Ka nj\u00eb mund\u00ebsi t\u00eb madhe q\u00eb dikujt do t'i jet\u00eb i dobish\u00ebm. <br \/>\nPrandaj e shpjegojm\u00eb n\u00eb detaje se \u00e7far\u00eb ndodh midis serverit n\u00eb cloud dhe zyr\u00ebs, n\u00ebse ato jan\u00eb t\u00eb lidhura me nj\u00eb rrjet site-to-site. Vlen t\u00eb p\u00ebrmendet se nj\u00eb pjes\u00eb e sh\u00ebrbimeve \u00ebsht\u00eb e disponueshme vet\u00ebm nga zyra, nd\u00ebrsa nj\u00eb pjes\u00eb \u2014 nga kudo n\u00eb internet.<\/p>\n<p>Menj\u00ebher\u00eb shpjegojm\u00eb se klienti yn\u00eb d\u00ebshiron q\u00eb n\u00eb serverin <b>192.168.A.1<\/b> t\u00eb mund t\u00eb hyj\u00eb nga kudo p\u00ebrmes RDP, duke u lidhur me <b>A.A.A.2:13389<\/b>, nd\u00ebrsa p\u00ebr sh\u00ebrbimet e tjera \u2014 vet\u00ebm nga zyrat <b>(192.168.B.0\/24)<\/b>, e cila \u00ebsht\u00eb e lidhur p\u00ebrmes <a class=\"wpil_keyword_link\" href=\"https:\/\/prohoster.info\/sq\/vpn\/\"   title=\"VPN\" data-wpil-keyword-link=\"linked\"  data-wpil-monitor-id=\"85\">VPN<\/a>. Po ashtu, klienti kishte fillimisht t\u00eb konfiguruar q\u00eb n\u00eb makin\u00ebn <b>192.168.B.2 <\/b>n\u00eb zyr\u00eb gjithashtu mund t\u00eb hyhej p\u00ebrmes RDP nga kudo, duke u lidhur me <b>B.B.B.1:11111<\/b>. Ne ndihmuam n\u00eb organizimin e lidhjeve IPSec midis cloud-it dhe zyr\u00ebs, dhe specialisti IT i klientit filloi t\u00eb b\u00ebj\u00eb pyetje n\u00eb lidhje me \u00e7far\u00eb do ndodhte n\u00eb raste t\u00eb caktuara. P\u00ebr t'iu p\u00ebrgjigjur t\u00eb gjitha k\u00ebtyre pyetjeve, ne, n\u00eb thelb, i shkruam atij gjith\u00e7ka q\u00eb mund t\u00eb lexoni m\u00eb posht\u00eb.<br \/>\n<noindex><a rel=\"nofollow\" name=\"habracut\"><\/a><\/noindex><br \/>\n<img decoding=\"async\" alt=\"\u00c7far\u00eb ndodh me lidhjet brenda dhe jasht\u00eb tunelit VPN\" src=\"\/wp-content\/uploads\/2019\/12\/7ee4e6c8fd9b122b092e7f8d99bb0235.jpg\" style=\"display:block;margin: 0 auto;\" \/><\/p>\n<p>Tani le t\u00eb shqyrtojm\u00eb k\u00ebto procese m\u00eb n\u00eb detaje.<\/p>\n<p><\/p>\n<h3>Pozita e par\u00eb<\/h3>\n<p>\nKur di\u00e7ka d\u00ebrgohet nga <b>192.168.B.0\/24<\/b> n\u00eb <b>192.168.A.0\/24<\/b> apo nga <b>192.168.A.0\/24<\/b> n\u00eb <b>192.168.B.0\/24<\/b>, ajo kalon n\u00eb VPN. Dometh\u00ebn\u00eb, ky paket\u00eb shtohet me enkriptim dhe d\u00ebrgohet midis <b>B.B.B.1<\/b> dhe <b>A.A.A.1<\/b>, por <b>192.168.A.1<\/b> sheh paket\u00ebn pik\u00ebrisht nga <b>192.168.B.1<\/b>. Ata mund t\u00eb komunikojn\u00eb me nj\u00ebri-tjetrin p\u00ebr \u00e7do protokoll. P\u00ebrgjigjet e kund\u00ebrta po ashtu kalohen p\u00ebrmes VPN, ku ajo paket\u00eb nga <b>192.168.A.1<\/b> p\u00ebr <b>192.168.B.1<\/b> do t\u00eb d\u00ebrgohet si nj\u00eb datagram ESP nga <b>A.A.A.1<\/b> n\u00eb <b>B.B.B.1<\/b>, which will be unpacked by the router on that side, retrieving the packet from it and delivering it to <b>192.168.B.1<\/b> as the packet from <b>192.168.A.1<\/b>.<\/p>\n<p>A specific example:<\/p>\n<p>1) <b>192.168.B.1<\/b> addresses <b>192.168.A.1<\/b>, wants to establish a TCP connection with <b>192.168.A.1:3389<\/b>;<\/p>\n<p>2) <b>192.168.B.1<\/b> sends a connection establishment request from <b>192.168.B.1:55555<\/b> (the port number for feedback is chosen by it, here and later we will use the number 55555 as an example of such a port number that the system selects when forming a TCP connection) to <b>192.168.A.1:3389<\/b>;<\/p>\n<p>3) the operating system running on the computer with the address <b>192.168.B.1<\/b>, decides to pass this packet to the router's gateway address (<b>192.168.B.254<\/b> in our case), because there are no other more specific routes for <b>192.168.A.1<\/b>, it therefore sends the packet via the default route (0.0.0.0\/0);<\/p>\n<p>4) to do this, it tries to find the MAC address for the IP address <b>192.168.B.254 <\/b>in the ARP protocol's cache table. If it is not found, it sends a <b>192.168.B.1<\/b> broadcast who-has request to the network <b>192.168.B.0\/24<\/b>. When <b>192.168.B.254<\/b> in response sends back its MAC address, the system transfers the Ethernet packet to it and adds this information to its cache table;<\/p>\n<p>5) the router receives this packet and decides where to send it: it has a policy indicating that it should forward all packets between <b>192.168.B.0\/24<\/b> dhe <b>192.168.A.0\/24<\/b> via the VPN connection between <b>B.B.B.1<\/b> dhe <b>A.A.A.1<\/b>;<\/p>\n<p>6) the router forms the ESP datagram from <b>B.B.B.1<\/b> n\u00eb <b>A.A.A.1<\/b>;<\/p>\n<p>7) the router determines to whom to send this packet, it sends it to, say, <b>B.B.B.254<\/b> (the internet provider's gateway), because it doesn't have more specific routes to <b>A.A.A.1<\/b>, than 0.0.0.0\/0;<\/p>\n<p>8) just as previously stated, it finds the MAC address for <b>B.B.B.254<\/b> and sends the packet to the internet provider's gateway;<\/p>\n<p>9) internet providers forward the ESP datagram through their networks from <b>B.B.B.1<\/b> n\u00eb <b>A.A.A.1<\/b>;<\/p>\n<p>10) the virtual router on <b>A.A.A.1<\/b> receives this datagram, decrypts it, and gets the packet from <b>192.168.B.1:55555<\/b> p\u00ebr <b>192.168.A.1:3389<\/b>;<\/p>\n<p>11) the virtual router checks who to send it to, finds the network in the routing table <b>192.168.A.0\/24<\/b> and sends it directly to <b>192.168.A.1<\/b>, since it has an interface <b>192.168.A.254\/24<\/b>;<\/p>\n<p>12) for this, the virtual router finds the MAC address for <b>192.168.A.1<\/b> and sends this packet to it over the virtual Ethernet network;<\/p>\n<p>13) <b>192.168.A.1<\/b> receives this packet on port 3389, agrees to establish a connection, and forms a response packet from <b>192.168.A.1:3389<\/b> n\u00eb <b>192.168.B.1:55555<\/b>;<\/p>\n<p>14) its system sends this packet to the gateway address of the virtual router (<b>192.168.A.254<\/b> in our case), because there are no other more specific routes for <b>192.168.B.1<\/b>, ajo nuk e ka, pra duhet t\u00eb d\u00ebrgoj\u00eb paket\u00ebn p\u00ebrmes ruterit t\u00eb parazgjedhur (0.0.0.0\/0);<\/p>\n<p>15) ashtu si n\u00eb rastet e m\u00ebparshme, sistemi q\u00eb punon n\u00eb serverin me adres\u00ebn <b>192.168.A.1<\/b>, gjen adres\u00ebn MAC <b>192.168.A.254<\/b>, p\u00ebr shkak se ndodhet n\u00eb t\u00eb nj\u00ebjtin rrjet me nd\u00ebrfaqen e saj <b>192.168.A.1\/24<\/b>;<\/p>\n<p>16) ruter virtual pranon k\u00ebt\u00eb paket\u00eb dhe vendos se ku ta d\u00ebrgoj\u00eb: ka nj\u00eb politik\u00eb q\u00eb e detyron t\u00eb d\u00ebrgoj\u00eb t\u00eb gjitha paketat midis <b>192.168.A.0\/24<\/b> dhe <b>192.168.B.0\/24<\/b> via the VPN connection between <b>A.A.A.1<\/b> dhe <b>B.B.B.1<\/b>;<\/p>\n<p>17) ruter virtuali formon nj\u00eb datagram ESP nga <b>A.A.A.1<\/b> p\u00ebr <b>B.B.B.1<\/b>;<\/p>\n<p>18) ruter virtuali vendos se kujt t'i d\u00ebrgoj\u00eb k\u00ebt\u00eb paket\u00eb, e d\u00ebrgon tek <b>A.A.A.254<\/b> (gateway i ofruesit t\u00eb sh\u00ebrbimit t\u00eb internetit, n\u00eb k\u00ebt\u00eb rast, \u00ebsht\u00eb gjithashtu ne), sepse nuk ka rute m\u00eb t\u00eb ve\u00e7anta p\u00ebr <b>B.B.B.1<\/b>, than 0.0.0.0\/0;<\/p>\n<p>19) ofruesit e sh\u00ebrbimit t\u00eb internetit d\u00ebrgojn\u00eb p\u00ebrmes rrjeteve t\u00eb tyre datagramin ESP <b>A.A.A.1<\/b> n\u00eb <b>B.B.B.1<\/b>;<\/p>\n<p>20) ruteri n\u00eb <b>B.B.B.1 <\/b>receives this datagram, decrypts it, and gets the packet from <b>192.168.A.1:3389<\/b> p\u00ebr <b>192.168.B.1:55555<\/b>;<\/p>\n<p>21) ku kupton se duhet ta d\u00ebrgoj\u00eb pik\u00ebrisht n\u00eb <b>192.168.B.1<\/b>, p\u00ebr shkak se ky \u00ebsht\u00eb n\u00eb t\u00eb nj\u00ebjtin rrjet me t\u00eb, ndihmon p\u00ebr t\u00eb d\u00ebrguar paketat p\u00ebr <b>192.168.B.0\/24<\/b> direkt;<\/p>\n<p>22) ruteri gjen adres\u00ebn MAC p\u00ebr <b>192.168.B.1<\/b> dhe i d\u00ebrgon k\u00ebsaj paket\u00eb;<\/p>\n<p>23) sistemi operativ n\u00eb kompjuterin me adres\u00ebn <b>192.168.B.1<\/b> pranon paket\u00ebn nga <b>192.168.A.1:3389<\/b> p\u00ebr <b>192.168.B.1:55555<\/b> dhe inicon hapat e m\u00ebposht\u00ebm p\u00ebr t\u00eb vendosur nj\u00eb lidhje TCP.<\/p>\n<p>N\u00eb k\u00ebt\u00eb shembull, \u00ebsht\u00eb p\u00ebrshkruar n\u00eb m\u00ebnyr\u00eb t\u00eb p\u00ebrmbledhur dhe t\u00eb thjesht\u00eb (dhe k\u00ebtu mund t\u00eb kujtojm\u00eb shum\u00eb detaje) se \u00e7far\u00eb ndodh n\u00eb nivelet 2-4. Nivelet 1, 5-7 nuk jan\u00eb shqyrtuar.<\/p>\n<h3>Pozita e dyt\u00eb<\/h3>\n<p>\nN\u00ebse nga <b>192.168.B.0\/24<\/b> di\u00e7ka d\u00ebrgohet pik\u00ebrisht n\u00eb <b>A.A.A.2<\/b>, ajo shkon jo n\u00eb VPN, por direkt. K\u00ebshtu, n\u00ebse p\u00ebrdoruesi me adres\u00eb <b>192.168.B.1<\/b> addresses <b>A.A.A.2:13389<\/b>, kjo paket\u00eb d\u00ebrgohet nga adresa <b>B.B.B.1<\/b>, kalon n\u00eb <b>A.A.A.2<\/b>, dhe atje ruteri e pranon dhe e d\u00ebrgon n\u00eb <b>192.168.A.1<\/b>. <b>192.168.A.1<\/b> nuk di asgj\u00eb p\u00ebr <b>192.168.B.1<\/b>, ai sheh paket\u00ebn nga<b> B.B.B.1<\/b>, sepse ajo ka ardhur prej saj. Prandaj, p\u00ebrgjigja p\u00ebr k\u00ebt\u00eb k\u00ebrkes\u00eb shkon p\u00ebrmes rrug\u00ebs s\u00eb zakonshme, e cila gjithashtu d\u00ebrgohet nga adresa <b>A.A.A.2 <\/b>dhe shkon n\u00eb <b>B.B.B.1<\/b>, dhe ai ruter e jep k\u00ebt\u00eb p\u00ebrgjigje n\u00eb <b>192.168.B.1<\/b>, ai sheh p\u00ebrgjigjen nga <b>A.A.A.2<\/b>, p\u00ebr t\u00eb cilin ai \u00ebsht\u00eb drejtuar.<\/p>\n<p>A specific example:<\/p>\n<p>1) <b>192.168.B.1<\/b> addresses <b>A.A.A.2<\/b>, wants to establish a TCP connection with <b>A.A.A.2:13389<\/b>;<\/p>\n<p>2) <b>192.168.B.1<\/b> sends a connection establishment request from <b>192.168.B.1:55555<\/b> (ky num\u00ebr, ashtu si\u00e7 \u00ebsht\u00eb n\u00eb shembullin e m\u00ebparsh\u00ebm, mund t\u00eb jet\u00eb tjet\u00ebr) n\u00eb <b>A.A.A.2:13389<\/b>;<\/p>\n<p>3) the operating system running on the computer with the address <b>192.168.B.1<\/b>, decides to pass this packet to the router's gateway address (<b>192.168.B.254<\/b> in our case), because there are no other more specific routes for <b>A.A.A.2<\/b>, ajo nuk e ka, dhe k\u00ebshtu, ajo d\u00ebrgon paket\u00ebn p\u00ebrmes ruterit t\u00eb parazgjedhur (0.0.0.0\/0);<\/p>\n<p>4) p\u00ebr k\u00ebt\u00eb, si\u00e7 e p\u00ebrmend\u00ebm n\u00eb shembullin e m\u00ebparsh\u00ebm, p\u00ebrpiqet t\u00eb gjej\u00eb adres\u00ebn MAC p\u00ebr adres\u00ebn IP <b>192.168.B.254<\/b> in the ARP protocol's cache table. If it is not found, it sends a <b>192.168.B.1<\/b> broadcast who-has request to the network <b>192.168.B.0\/24<\/b>. When <b>192.168.B.254<\/b> in response sends back its MAC address, the system transfers the Ethernet packet to it and adds this information to its cache table;<\/p>\n<p>5) ruteri pranon k\u00ebt\u00eb paket\u00eb dhe vendos se ku ta d\u00ebrgoj\u00eb: ka nj\u00eb politik\u00eb q\u00eb e detyron t\u00eb d\u00ebrgoj\u00eb (duke z\u00ebvend\u00ebsuar adres\u00ebn e rrethme) t\u00eb gjitha paketat nga <b>192.168.B.0\/24<\/b> tek nodet e tjera t\u00eb rrjetit t\u00eb internetit;<\/p>\n<p>6) pasi kjo politik\u00eb n\u00ebnkupton se adresa e kthimit duhet t\u00eb p\u00ebrputhet me adres\u00ebn m\u00eb t\u00eb ul\u00ebt n\u00eb nd\u00ebrfaqen, p\u00ebrmes s\u00eb cil\u00ebs do t\u00eb transmetohet ky paket\u00eb, rrug\u00ebzuesi fillimisht p\u00ebrcakton se kujt t'ia d\u00ebrgoj\u00eb k\u00ebt\u00eb paket\u00eb, dhe ai, ashtu si n\u00eb shembullin paraardh\u00ebs, duhet ta d\u00ebrgoj\u00eb n\u00eb <b>B.B.B.254<\/b> (the internet provider's gateway), because it doesn't have more specific routes to <b>A.A.A.2<\/b>, than 0.0.0.0\/0;<\/p>\n<p>7) p\u00ebr rrjedhoj\u00eb, rrug\u00ebzuesi nd\u00ebrron adres\u00ebn e kthimit t\u00eb paket\u00ebs, k\u00ebshtu q\u00eb tani paket\u00eb nga <b>B.B.B.1:44444<\/b> (numri i portit, natyrisht, mund t\u00eb jet\u00eb ndryshe) n\u00eb <b>A.A.A.2:13389<\/b>;<\/p>\n<p>8) rrug\u00ebzuesi mban mend se \u00e7far\u00eb ka b\u00ebr\u00eb, k\u00ebshtu q\u00eb, kur nga <b>A.A.A.2:13389<\/b> n\u00eb <b>B.B.B.1:44444<\/b> vjen nj\u00eb p\u00ebrgjigje, do t\u00eb di se \u00e7far\u00eb duhet t\u00eb ndryshoj\u00eb adres\u00ebn dhe portin e marr\u00ebsit n\u00eb <b>192.168.B.1:55555<\/b>.<\/p>\n<p>9) tani rrug\u00ebzuesi duhet ta d\u00ebrgoj\u00eb at\u00eb te rrjeti i ofruesit t\u00eb internetit p\u00ebrmes<b> B.B.B.254<\/b>, p\u00ebr rrjedhoj\u00eb, ashtu si\u00e7 p\u00ebrmend\u00ebm m\u00eb par\u00eb, ai gjen adres\u00ebn MAC p\u00ebr <b>B.B.B.254 <\/b>and sends the packet to the internet provider's gateway;<\/p>\n<p>10) ofruesit e internetit d\u00ebrgojn\u00eb p\u00ebrmes rrjeteve t\u00eb tyre paket\u00ebn nga <b>B.B.B.1<\/b> n\u00eb <b>A.A.A.2<\/b>;<\/p>\n<p>11) rrug\u00ebzuesi virtual n\u00eb <b>A.A.A.2<\/b> pranon k\u00ebt\u00eb paket\u00eb n\u00eb portin 13389;<\/p>\n<p>12) n\u00eb rrug\u00ebzuesin virtual ka nj\u00eb rregull, i cili parashikon se paketat q\u00eb vijn\u00eb nga \u00e7do d\u00ebrgues n\u00eb k\u00ebt\u00eb port, duhet t\u00eb d\u00ebrgohen n\u00eb <b>192.168.A.1:3389<\/b>;<\/p>\n<p>13) rrug\u00ebzuesi virtual gjen n\u00eb tabel\u00ebn e rrug\u00ebzimit rrjetin <b>192.168.A.0\/24<\/b> dhe e d\u00ebrgon direkt n\u00eb <b>192.168.A.<\/b>1, pasi ka nj\u00eb nd\u00ebrfaqe<b> 192.168.A.254\/24<\/b>;<\/p>\n<p>14) p\u00ebr k\u00ebt\u00eb, rrug\u00ebzuesi virtual gjen adres\u00ebn MAC p\u00ebr<b> 192.168.A.1<\/b> and sends this packet to it over the virtual Ethernet network;<\/p>\n<p>15) <b>192.168.A.1<\/b> receives this packet on port 3389, agrees to establish a connection, and forms a response packet from <b>192.168.A.1:3389<\/b> n\u00eb<b> B.B.B.1:44444<\/b>;<\/p>\n<p>16) sistemi i tij e d\u00ebrgon k\u00ebt\u00eb paket\u00eb n\u00eb adres\u00ebn e portit t\u00eb rrug\u00ebzuesit virtual (<b>192.168.A.254<\/b> in our case), because there are no other more specific routes for <b>B.B.B.1<\/b>, ajo nuk e ka, pra duhet t\u00eb d\u00ebrgoj\u00eb paket\u00ebn p\u00ebrmes ruterit t\u00eb parazgjedhur (0.0.0.0\/0);<\/p>\n<p>17) ashtu si n\u00eb rastet e m\u00ebparshme, sistemi q\u00eb funksionon n\u00eb serverin me adres\u00ebn <b>192.168.A.1<\/b>, gjen adres\u00ebn MAC <b>192.168.A.254<\/b>, p\u00ebr shkak se ndodhet n\u00eb t\u00eb nj\u00ebjtin rrjet me nd\u00ebrfaqen e saj <b>192.168.A.1\/24<\/b>;<\/p>\n<p>18) rrug\u00ebzuesi virtual e pranon k\u00ebt\u00eb paket\u00eb. Duhet theksuar, ai e mban mend se mori n\u00eb <b>A.A.A.2:13389<\/b> paket\u00ebn nga <b>B.B.B.1:44444<\/b> dhe e ndryshoi adres\u00ebn dhe portin e marr\u00ebsit n\u00eb <b>192.168.A.1:3389<\/b>, p\u00ebr rrjedhoj\u00eb, paket\u00ebs nga<b> 192.168.A.1:3389 <\/b>p\u00ebr <b>B.B.B.1:44444<\/b> ai e ndryshon adres\u00ebn e d\u00ebrguesit n\u00eb <b>A.A.A.2:13389<\/b>;<\/p>\n<p>19) rrug\u00ebzuesi virtual p\u00ebrcakton kujt t'ia d\u00ebrgoj\u00eb k\u00ebt\u00eb paket\u00eb, ai e d\u00ebrgon at\u00eb n\u00eb <b>A.A.A.254<\/b> (gateway i ofruesit t\u00eb sh\u00ebrbimit t\u00eb internetit, n\u00eb k\u00ebt\u00eb rast, \u00ebsht\u00eb gjithashtu ne), sepse nuk ka rute m\u00eb t\u00eb ve\u00e7anta p\u00ebr <b>B.B.B.1<\/b>, than 0.0.0.0\/0;<\/p>\n<p>20) ofruesit e internetit d\u00ebrgojn\u00eb p\u00ebrmes rrjeteve t\u00eb tyre paket\u00ebn me <b>A.A.A.2<\/b> n\u00eb <b>B.B.B.1<\/b>;<\/p>\n<p>21) rrug\u00ebzuesi n\u00eb <b>B.B.B.1<\/b> pranon k\u00ebt\u00eb paket\u00eb dhe kujton se, kur ai d\u00ebrgoi paket\u00ebn nga <b>192.168.B.1:55555<\/b> p\u00ebr <b>A.A.A.2:13389<\/b>, ai ndryshoi adres\u00ebn dhe portin e d\u00ebrguesit n\u00eb <b>B.B.B.1:44444<\/b>, k\u00ebshtu q\u00eb kjo \u00ebsht\u00eb p\u00ebrgjigje q\u00eb duhet ta d\u00ebrgoj\u00eb n\u00eb <b>192.168.B.1:55555<\/b> (n\u00eb t\u00eb v\u00ebrtet\u00eb, aty ekzistojn\u00eb edhe disa kontrolle t\u00eb tjera, por ne nuk e thellojm\u00eb n\u00eb k\u00ebt\u00eb);<\/p>\n<p>22) ai e kupton se duhet ta d\u00ebrgoj\u00eb drejtp\u00ebrdrejt n\u00eb <b>192.168.B.1<\/b>, pasi q\u00eb ai ndodhet me t\u00eb n\u00eb t\u00eb nj\u00ebjtin rrjet, p\u00ebr rrjedhoj\u00eb, ai ka nj\u00eb regjist\u00ebr p\u00ebrkat\u00ebs n\u00eb tabel\u00ebn e rrug\u00ebzimit e cila e detyron t\u00eb d\u00ebrgoj\u00eb paketat p\u00ebr t\u00eb gjitha <b>192.168.B.0\/24 <\/b>direkt;<\/p>\n<p>23) routeri gjenon adres\u00ebn MAC p\u00ebr <b>192.168.B.1<\/b> dhe i d\u00ebrgon k\u00ebsaj paket\u00eb;<\/p>\n<p>24) sistemi operativ n\u00eb kompjuterin me adres\u00eb <b>192.168.B.1<\/b> pranon paket\u00ebn nga <b>A.A.A.2:13389<\/b> p\u00ebr <b>192.168.B.1:55555<\/b> dhe inicon hapat e m\u00ebposht\u00ebm p\u00ebr t\u00eb vendosur nj\u00eb lidhje TCP.<\/p>\n<p>Duhet t\u00eb theksohet se n\u00eb k\u00ebt\u00eb rast kompjuteri me adres\u00ebn <b>192.168.B.1<\/b> nuk di asgj\u00eb p\u00ebr serverin me adres\u00ebn <b>192.168.A.1<\/b>, ai komunikon vet\u00ebm me <b>A.A.A.2<\/b>. Po ashtu serveri me adres\u00ebn <b>192.168.A.1<\/b> nuk di asgj\u00eb p\u00ebr kompjuterin me adres\u00ebn <b>192.168.B.1<\/b>. Ai mendon se iu lidha nga adresa <b>B.B.B.1<\/b>, dhe m\u00eb shum\u00eb nuk di asgj\u00eb, themi, nuk e di.<\/p>\n<p>Gjithashtu duhet t\u00eb theksohet se n\u00eb rastin kur ky kompjuter k\u00ebrkon lidhjen me <b>A.A.A.2:1540<\/b>, lidhja nuk do t\u00eb krijohet, sepse kalimi i lidhjeve n\u00eb portin 1540 nuk \u00ebsht\u00eb konfiguruar n\u00eb routerin virtual, edhe n\u00ebse ndonj\u00eb server n\u00eb rrjetin virtual <b>192.168.A.0\/24<\/b> (p.sh., n\u00eb serverin me adres\u00eb <b>192.168.A.1<\/b>) ka ndonj\u00eb sh\u00ebrbim q\u00eb pret lidhje n\u00eb k\u00ebt\u00eb port. N\u00ebse p\u00ebrdoruesit t\u00eb kompjuterit me adres\u00eb <b>192.168.B.1<\/b> i nevojitet me t\u00eb v\u00ebrtet\u00eb t\u00eb vendos\u00eb lidhjen me k\u00ebt\u00eb sh\u00ebrbim, ai duhet t\u00eb p\u00ebrdor\u00eb VPN, dmth. t\u00eb lidhet drejtp\u00ebrdrejt me <b>192.168.A.1:1540<\/b>.<\/p>\n<p>Duhet theksuar se \u00e7do p\u00ebrpjekje p\u00ebr t\u00eb krijuar lidhje me <b>A.A.A.1<\/b> sidoqoft\u00eb lidhjet IPSec nga <b>B.B.B.1<\/b> nuk do t\u00eb jet\u00eb e suksesshme. \u00c7do p\u00ebrpjekje p\u00ebr t\u00eb krijuar lidhje me <b>A.A.A.2<\/b>, p\u00ebrve\u00e7 lidhjeve n\u00eb portin 13389, gjithashtu nuk do t\u00eb jet\u00eb e suksesshme. <br \/>\nGjithashtu do t\u00eb theksojm\u00eb se n\u00ebse dikush tjet\u00ebr i drejtohet<b> A.A.A.2 <\/b>p.sh., C.C.C.C, gjith\u00e7ka q\u00eb \u00ebsht\u00eb p\u00ebrmendur n\u00eb pikat 10-20 do t\u00eb ket\u00eb t\u00eb b\u00ebj\u00eb edhe me t\u00eb. Ajo q\u00eb ndodh para k\u00ebsaj dhe pas k\u00ebsaj varet nga ajo q\u00eb ndodhet pas C.C.C.C. Ne nuk kemi informacion t\u00eb till\u00eb, prandaj k\u00ebshillojm\u00eb t\u00eb k\u00ebrkoni konsultime nga administrator\u00ebt e nod\u00ebs me adres\u00eb C.C.C.C.<\/p>\n<h3>Pozita e tret\u00eb<\/h3>\n<p>\nDhe, p\u00ebrkundrazi, n\u00ebse nga<b> 192.168.A.1 <\/b>d\u00ebrgohet ndonj\u00eb gj\u00eb n\u00eb nj\u00eb port q\u00eb \u00ebsht\u00eb konfiguruar p\u00ebr kalim brenda n\u00eb B.B.B.1 (p.sh., 11111), kjo gjithashtu nuk kalon n\u00eb VPN, por thjesht p\u00ebrfundon nga <b>A.A.A.1<\/b> dhe shkon n\u00eb <b>B.B.B.1<\/b>, dhe ai e d\u00ebrgon at\u00eb diku, t\u00eb themi, <b>192.168.B.2:3389<\/b>. Ai e sheh k\u00ebt\u00eb paket\u00eb jo nga <b>192.168.A.1<\/b>, por nga <b>A.A.A.1<\/b>. Dhe, kur <b>192.168.B.2<\/b> p\u00ebrgjigjet, paketa shkon nga <b>B.B.B.1<\/b> n\u00eb <b>A.A.A.1,<\/b> dhe m\u00eb von\u00eb arrin te iniciatori i lidhjes \u2014 <b>192.168.A.1<\/b>.<\/p>\n<p>A specific example:<\/p>\n<p>1) <b>192.168.A.1<\/b> addresses <b>B.B.B.1<\/b>, wants to establish a TCP connection with <b>B.B.B.1:11111<\/b>;<\/p>\n<p>2) <b>192.168.A.1<\/b> sends a connection establishment request from <b>192.168.A.1:55555<\/b> (ky num\u00ebr, ashtu si\u00e7 \u00ebsht\u00eb n\u00eb shembullin e m\u00ebparsh\u00ebm, mund t\u00eb jet\u00eb tjet\u00ebr) n\u00eb <b>B.B.B.1:11111<\/b>;<\/p>\n<p>3) sistemi operativ q\u00eb punon n\u00eb serverin me adres\u00eb <b>192.168.A.1<\/b>, decides to pass this packet to the router's gateway address (<b>192.168.A.254<\/b> in our case), because there are no other more specific routes for <b>B.B.B.1<\/b>, it therefore sends the packet via the default route (0.0.0.0\/0);<\/p>\n<p>4) p\u00ebr k\u00ebt\u00eb, si\u00e7 e p\u00ebrmend\u00ebm n\u00eb shembujt e m\u00ebparsh\u00ebm, ai p\u00ebrpiqet t\u00eb gjej\u00eb adres\u00ebn MAC p\u00ebr IP adres\u00ebn <b>192.168.A.254<\/b> in the ARP protocol's cache table. If it is not found, it sends a <b>192.168.A.1<\/b> broadcast who-has request to the network <b>192.168.A.0\/24<\/b>. When <b>192.168.A.254<\/b> p\u00ebrgjigjet i d\u00ebrgon adres\u00ebn e saj MAC, sistemi d\u00ebrgon paket\u00ebn Ethernet p\u00ebr t\u00eb dhe e ruan k\u00ebt\u00eb informacion n\u00eb tabel\u00ebn e saj t\u00eb p\u00ebrkohshme;<\/p>\n<p>5) router virtual pranon k\u00ebt\u00eb paket dhe vendos se ku ta d\u00ebrgoj\u00eb: ai ka nj\u00eb politik\u00eb t\u00eb shkruar, sipas s\u00eb cil\u00ebs duhet t\u00eb maskoj\u00eb (duke nd\u00ebrruar adres\u00ebn e prapme) t\u00eb gjitha paketat nga <b>192.168.A.0\/24<\/b> tek nodet e tjera t\u00eb rrjetit t\u00eb internetit;<\/p>\n<p>6) pasi kjo politik\u00eb parashikon se adresa e prapme duhet t\u00eb p\u00ebrputhet me adres\u00ebn m\u00eb t\u00eb ul\u00ebt n\u00eb nd\u00ebrfaqen, p\u00ebrmes t\u00eb cil\u00ebs do t\u00eb d\u00ebrgohet ky paket, router virtual fillimisht vendos se kujt t'ia d\u00ebrgoj\u00eb k\u00ebt\u00eb paket, dhe ai, si n\u00eb shembullin e m\u00ebparsh\u00ebm, duhet ta d\u00ebrgoj\u00eb n\u00eb <b>A.A.A.254<\/b> (gateway i ofruesit t\u00eb sh\u00ebrbimit t\u00eb internetit, n\u00eb k\u00ebt\u00eb rast, \u00ebsht\u00eb gjithashtu ne), sepse nuk ka rute m\u00eb t\u00eb ve\u00e7anta p\u00ebr <b>B.B.B.1<\/b>, than 0.0.0.0\/0;<\/p>\n<p>7) pra, routeri virtual nd\u00ebrron adres\u00ebn e prapme t\u00eb paket\u00ebs, tani kjo \u00ebsht\u00eb nj\u00eb paket\u00eb nga <b>A.A.A.1:44444<\/b> (numri i portit, natyrisht, mund t\u00eb jet\u00eb ndryshe) n\u00eb <b>B.B.B.1:11111<\/b>;<\/p>\n<p>8) routeri virtual e mban mend se \u00e7far\u00eb ka b\u00ebr\u00eb, k\u00ebshtu q\u00eb kur nga <b>B.B.B.1:11111<\/b> p\u00ebr <b>A.A.A.1:44444<\/b> vjen nj\u00eb p\u00ebrgjigje, do t\u00eb di se \u00e7far\u00eb duhet t\u00eb ndryshoj\u00eb adres\u00ebn dhe portin e marr\u00ebsit n\u00eb <b>192.168.A.1:55555<\/b>.<\/p>\n<p>9) tani routeri virtual duhet ta d\u00ebrgoj\u00eb n\u00eb rrjetin e ofruesit t\u00eb internetit p\u00ebrmes <b>A.A.A.254<\/b>, k\u00ebshtu q\u00eb, ashtu si\u00e7 e p\u00ebrmend\u00ebm m\u00eb par\u00eb, ai gjen adres\u00ebn MAC p\u00ebr <b>A.A.A.254 <\/b>and sends the packet to the internet provider's gateway;<\/p>\n<p>10) ofruesit e internetit d\u00ebrgojn\u00eb p\u00ebrmes rrjeteve t\u00eb tyre paket\u00ebn nga <b>A.A.A.1 n\u00eb B.B.B.1<\/b>;<\/p>\n<p>11) routeri n\u00eb <b>B.B.B.1<\/b> pranon k\u00ebt\u00eb paket n\u00eb portin 11111;<\/p>\n<p>12) n\u00eb routerin virtual ka nj\u00eb rregull q\u00eb parashikon se paketat q\u00eb vijn\u00eb nga nj\u00eb d\u00ebrgues n\u00eb k\u00ebt\u00eb port duhet t\u00eb d\u00ebrgohen n\u00eb <b>192.168.B.2:3389<\/b>;<\/p>\n<p>13) routeri gjen n\u00eb tabel\u00ebn e routing rrjetin <b>192.168.B.0\/24<\/b> and sends it directly to <b>192.168.B.2<\/b>, since it has an interface <b>192.168.B.254\/24<\/b>;<\/p>\n<p>14) p\u00ebr k\u00ebt\u00eb, rrug\u00ebzuesi virtual gjen adres\u00ebn MAC p\u00ebr <b>192.168.B.2<\/b> and sends this packet to it over the virtual Ethernet network;<\/p>\n<p>15) <b>192.168.B.2<\/b> receives this packet on port 3389, agrees to establish a connection, and forms a response packet from <b>192.168.B.2:3389<\/b> n\u00eb <b>A.A.A.1:44444<\/b>;<\/p>\n<p>16) sistemi i tij transmeton k\u00ebt\u00eb paket n\u00eb adres\u00ebn gateway t\u00eb routerit (<b>192.168.B.254<\/b> in our case), because there are no other more specific routes for <b>A.A.A.1<\/b>, ajo nuk e ka, pra duhet t\u00eb d\u00ebrgoj\u00eb paket\u00ebn p\u00ebrmes ruterit t\u00eb parazgjedhur (0.0.0.0\/0);<\/p>\n<p>17) po ashtu si n\u00eb rastet e m\u00ebparshme, sistemi q\u00eb punon n\u00eb kompjuterin me adres\u00ebn <b>192.168.B.2<\/b>, gjen adres\u00ebn MAC <b>192.168.B.254<\/b>, p\u00ebr shkak se ndodhet n\u00eb t\u00eb nj\u00ebjtin rrjet me nd\u00ebrfaqen e saj <b>192.168.B.2\/24<\/b>;<\/p>\n<p>18) routeri pranon k\u00ebt\u00eb paket. Duhet t\u00eb theksohet, ai e mban mend se mori n\u00eb <b>B.B.B.1:11111<\/b> paket\u00ebn nga <b>A.A.A.1 <\/b>dhe e ndryshoi adres\u00ebn dhe portin e marr\u00ebsit n\u00eb <b>192.168.B.2:3389<\/b>, p\u00ebr rrjedhoj\u00eb, paket\u00ebs nga <b>192.168.B.2:3389<\/b> p\u00ebr <b>A.A.A.1:44444<\/b> ai e ndryshon adres\u00ebn e d\u00ebrguesit n\u00eb <b>B.B.B.1:11111<\/b>;<\/p>\n<p>19) routeri vendos kujt t'ia d\u00ebrgoj\u00eb k\u00ebt\u00eb paket. Ai e d\u00ebrgon at\u00eb n\u00eb, le themi,<b> B.B.B.254 <\/b>(gateway t\u00eb ofruesit t\u00eb internetit, adres\u00ebn e sakt\u00eb t\u00eb s\u00eb cil\u00ebs nuk e dim\u00eb), sepse nuk ka rrug\u00eb m\u00eb t\u00eb sakta drejt <b>A.A.A.1<\/b>, than 0.0.0.0\/0;<\/p>\n<p>20) ofruesit e internetit d\u00ebrgojn\u00eb p\u00ebrmes rrjeteve t\u00eb tyre paket\u00ebn me <b>B.B.B.1<\/b> n\u00eb <b>A.A.A.1<\/b>;<\/p>\n<p>21) routeri virtual n\u00eb<b> A.A.A.1 <\/b>pranon k\u00ebt\u00eb paket\u00eb dhe kujton se, kur ai d\u00ebrgoi paket\u00ebn nga <b>192.168.A.1:55555<\/b> p\u00ebr <b>B.B.B.1:11111<\/b>, ai ndryshoi adres\u00ebn dhe portin e d\u00ebrguesit n\u00eb <b>A.A.A.1:44444<\/b>. K\u00ebshtu, kjo \u00ebsht\u00eb nj\u00eb p\u00ebrgjigje q\u00eb duhet t\u00eb d\u00ebrgohet n\u00eb <b>192.168.A.1:55555<\/b> (n\u00eb t\u00eb v\u00ebrtet\u00eb, si\u00e7 e p\u00ebrmend\u00ebm n\u00eb shembullin e m\u00ebparsh\u00ebm, ka edhe disa verifikime t\u00eb tjera, por k\u00ebt\u00eb her\u00eb ne nuk merremi me to);<\/p>\n<p>22) ai kupton se duhet ta d\u00ebrgoj\u00eb drejtp\u00ebrdrejt n\u00eb <b>192.168.A.1<\/b>, pasi ai ndodhet n\u00eb t\u00eb nj\u00ebjtin rrjet me t\u00eb, k\u00ebshtu q\u00eb ai ka nj\u00eb regjistrim p\u00ebrkat\u00ebs n\u00eb tabel\u00ebn e routing, q\u00eb e detyron ta d\u00ebrgoj\u00eb paketat p\u00ebr t\u00eb gjith\u00eb <b>192.168.A.0\/24<\/b> direkt;<\/p>\n<p>23) routeri gjenon adres\u00ebn MAC p\u00ebr <b>192.168.A.1<\/b> dhe i d\u00ebrgon k\u00ebsaj paket\u00eb;<\/p>\n<p>24) sistemi operativ n\u00eb serverin me adres\u00ebn <b>192.168.A.1<\/b> pranon paket\u00ebn nga <b>B.B.B.1:1111<\/b>1 p\u00ebr <b>192.168.A.1:55555 <\/b>dhe inicon hapat e m\u00ebposht\u00ebm p\u00ebr t\u00eb vendosur nj\u00eb lidhje TCP.<\/p>\n<p>Ashtu si n\u00eb rastin e m\u00ebparsh\u00ebm, n\u00eb k\u00ebt\u00eb rast serveri me adres\u00ebn <b>192.168.A.1<\/b> nuk di asgj\u00eb p\u00ebr kompjuterin me adres\u00ebn <b>192.168.B.1<\/b>, ai komunikon vet\u00ebm me <b>B.B.B.1<\/b>. Kompjuterin me adres\u00ebn <b>192.168.B.1<\/b> as nuk e di p\u00ebr serverin me adres\u00ebn <b>192.168.A.1<\/b>. Ai mendon se iu lidha nga adresa <b>A.A.A.1<\/b>, nd\u00ebrsa e gjith\u00eb pjesa tjet\u00ebr \u00ebsht\u00eb e fshehur prej tij.<\/p>\n<h3>P\u00ebrfundimi<\/h3>\n<p>\nK\u00ebshtu ndodhin t\u00eb gjitha lidhjet brenda tunelit VPN mes zyr\u00ebs s\u00eb klientit dhe mjedisit n\u00eb re, si dhe lidhjet jasht\u00eb tunelit VPN. N\u00ebse keni ndonj\u00eb pyetje ose keni nevoj\u00eb p\u00ebr ndihm\u00ebn ton\u00eb p\u00ebr zgjidhjen e problemeve n\u00eb re, <noindex><a rel=\"nofollow\" href=\"https:\/\/tucha.ua\/ru\/contacts\">mos hezitoni t\u00eb kontaktoni 24\/7.<\/a><\/noindex><br \/>\n<br \/>Burimi: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/post\/477854\/\">habr.com<\/a><\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0418\u0437 \u043f\u0438\u0441\u0435\u043c \u0432 \u0441\u043b\u0443\u0436\u0431\u0443 \u0442\u0435\u0445\u043f\u043e\u0434\u0434\u0435\u0440\u0436\u043a\u0438 Tucha \u0440\u043e\u0436\u0434\u0430\u044e\u0442\u0441\u044f \u043d\u0430\u0441\u0442\u043e\u044f\u0449\u0438\u0435 \u0441\u0442\u0430\u0442\u044c\u0438. \u0422\u0430\u043a, \u043d\u0435\u0434\u0430\u0432\u043d\u043e \u043a \u043d\u0430\u043c \u043e\u0431\u0440\u0430\u0442\u0438\u043b\u0441\u044f \u043a\u043b\u0438\u0435\u043d\u0442 \u0441 \u0437\u0430\u043f\u0440\u043e\u0441\u043e\u043c \u0440\u0430\u0437\u044a\u044f\u0441\u043d\u0438\u0442\u044c, \u0447\u0442\u043e \u043f\u0440\u043e\u0438\u0441\u0445\u043e\u0434\u0438\u0442 \u043f\u0440\u0438 \u0441\u043e\u0435\u0434\u0438\u043d\u0435\u043d\u0438\u044f\u0445 \u0432\u043d\u0443\u0442\u0440\u0438 VPN-\u0442\u0443\u043d\u043d\u0435\u043b\u044f \u043c\u0435\u0436\u0434\u0443 \u043e\u0444\u0438\u0441\u043e\u043c \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u044f \u0438 \u0441\u0440\u0435\u0434\u043e\u0439 \u0432 \u043e\u0431\u043b\u0430\u043a\u0435, \u0430 \u0442\u0430\u043a\u0436\u0435 \u043f\u0440\u0438 \u0441\u043e\u0435\u0434\u0438\u043d\u0435\u043d\u0438\u044f\u0445 \u0432\u043d\u0435 VPN-\u0442\u0443\u043d\u043d\u0435\u043b\u044f. \u041f\u043e\u044d\u0442\u043e\u043c\u0443 \u0432\u0435\u0441\u044c \u0442\u0435\u043a\u0441\u0442, \u043f\u0440\u0438\u0432\u0435\u0434\u0435\u043d\u043d\u044b\u0439 \u043d\u0438\u0436\u0435, \u2014 \u044d\u0442\u043e \u0440\u0435\u0430\u043b\u044c\u043d\u043e\u0435 \u043f\u0438\u0441\u044c\u043c\u043e, \u043a\u043e\u0442\u043e\u0440\u043e\u0435 \u043c\u044b \u043e\u0442\u043f\u0440\u0430\u0432\u0438\u043b\u0438 \u043e\u0434\u043d\u043e\u043c\u0443 \u0438\u0437 \u043a\u043b\u0438\u0435\u043d\u0442\u043e\u0432 \u0432 \u043e\u0442\u0432\u0435\u0442 \u043d\u0430 [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":53573,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[688],"tags":[],"class_list":["post-53572","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-administrirovanie"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0418\u0437 \u043f\u0438\u0441\u0435\u043c \u0432 \u0441\u043b\u0443\u0436\u0431\u0443 \u0442\u0435\u0445\u043f\u043e\u0434\u0434\u0435\u0440\u0436\u043a\u0438 Tucha \u0440\u043e\u0436\u0434\u0430\u044e\u0442\u0441\u044f \u043d\u0430\u0441\u0442\u043e\u044f\u0449\u0438\u0435 \u0441\u0442\u0430\u0442\u044c\u0438.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/sq\/blog\/administrirovanie\/chto-proishodit-pri-soedineniyah-vnutri-i-vne-vpn-tunnelya\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2\" \/>\n\t\t<meta property=\"og:locale\" content=\"sq_AL\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0427\u0442\u043e \u043f\u0440\u043e\u0438\u0441\u0445\u043e\u0434\u0438\u0442 \u043f\u0440\u0438 \u0441\u043e\u0435\u0434\u0438\u043d\u0435\u043d\u0438\u044f\u0445 \u0432\u043d\u0443\u0442\u0440\u0438 \u0438 \u0432\u043d\u0435 VPN-\u0442\u0443\u043d\u043d\u0435\u043b\u044f | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0418\u0437 \u043f\u0438\u0441\u0435\u043c \u0432 \u0441\u043b\u0443\u0436\u0431\u0443 \u0442\u0435\u0445\u043f\u043e\u0434\u0434\u0435\u0440\u0436\u043a\u0438 Tucha \u0440\u043e\u0436\u0434\u0430\u044e\u0442\u0441\u044f \u043d\u0430\u0441\u0442\u043e\u044f\u0449\u0438\u0435 \u0441\u0442\u0430\u0442\u044c\u0438.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/sq\/blog\/administrirovanie\/chto-proishodit-pri-soedineniyah-vnutri-i-vne-vpn-tunnelya\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2019-12-04T21:00:00+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2020-02-18T11:01:29+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47\u00c7far\u00eb ndodh gjat\u00eb lidhjeve brenda dhe jasht\u00eb tunelit VPN | ProHoster","description":"Nga email-et n\u00eb sh\u00ebrbimin e mb\u00ebshtetje teknike Tucha lindin artikuj t\u00eb v\u00ebrtet\u00eb.","canonical_url":"https:\/\/prohoster.info\/sq\/blog\/administrirovanie\/chto-proishodit-pri-soedineniyah-vnutri-i-vne-vpn-tunnelya","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"sq_AL","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0427\u0442\u043e \u043f\u0440\u043e\u0438\u0441\u0445\u043e\u0434\u0438\u0442 \u043f\u0440\u0438 \u0441\u043e\u0435\u0434\u0438\u043d\u0435\u043d\u0438\u044f\u0445 \u0432\u043d\u0443\u0442\u0440\u0438 \u0438 \u0432\u043d\u0435 VPN-\u0442\u0443\u043d\u043d\u0435\u043b\u044f | ProHoster","og:description":"\u0418\u0437 \u043f\u0438\u0441\u0435\u043c \u0432 \u0441\u043b\u0443\u0436\u0431\u0443 \u0442\u0435\u0445\u043f\u043e\u0434\u0434\u0435\u0440\u0436\u043a\u0438 Tucha \u0440\u043e\u0436\u0434\u0430\u044e\u0442\u0441\u044f \u043d\u0430\u0441\u0442\u043e\u044f\u0449\u0438\u0435 \u0441\u0442\u0430\u0442\u044c\u0438.","og:url":"https:\/\/prohoster.info\/sq\/blog\/administrirovanie\/chto-proishodit-pri-soedineniyah-vnutri-i-vne-vpn-tunnelya","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2019-12-04T21:00:00+00:00","article:modified_time":"2020-02-18T11:01:29+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"53572","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":"2026-02-04 15:17:19","breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-02-28 20:22:50","updated":"2026-02-04 15:17:19","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts\/53572","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/comments?post=53572"}],"version-history":[{"count":1,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts\/53572\/revisions"}],"predecessor-version":[{"id":156714,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts\/53572\/revisions\/156714"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/media\/53573"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/media?parent=53572"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/categories?post=53572"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/tags?post=53572"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}