1.5 ืกืงื™ืžื– ืื•ื™ืฃ ื“ื™ื ืขืจ IPsec VPN. ื˜ืขืกื˜ื™ื ื’ ื“ืขืžืึธืก

1.5 ืกืงื™ืžื– ืื•ื™ืฃ ื“ื™ื ืขืจ IPsec VPN. ื˜ืขืกื˜ื™ื ื’ ื“ืขืžืึธืก

ื“ื™ ืกื™ื˜ื•ืึทืฆื™ืข

ืื™ืš ื‘ืืงื•ืžืขืŸ ืึท ื“ืขืžืึธ ื•ื•ืขืจืกื™ืข ืคื•ืŸ โ€‹โ€‹S-Terra VPN ืคึผืจืึธื“ื•ืงื˜ืŸ ื•ื•ืขืจืกื™ืข 4.3 ืคึฟืึทืจ ื“ืจื™ื™ ื—ื“ืฉื™ื. ืื™ืš ื•ื•ื™ืœืŸ ืฆื• ืจืขื›ืขื ืขืŸ ืฆื™ ืžื™ื™ืŸ ื™ื ื–ืฉืขื ื™ืขืจื™ืข ืœืขื‘ืŸ ื•ื•ืขื˜ ื•ื•ืขืจืŸ ื’ืจื™ื ื’ืขืจ ื ืึธืš ืกื•ื•ื™ื˜ืฉื™ื ื’ ืฆื• ื“ื™ ื ื™ื™ึทืข ื•ื•ืขืจืกื™ืข.

ื”ื™ื™ึทื ื˜ ืขืก ืื™ื– ื ื™ืฉื˜ ืฉื•ื•ืขืจ, ืื™ื™ืŸ ื–ืขืงืœ ืคื•ืŸ 3 ืื™ืŸ 1 ืจืขื’ืข ืงืึทื•ื•ืข ื–ืึธืœ ื–ื™ื™ืŸ ื’ืขื ื•ื’. ืื™ืš ื•ื•ืขื˜ ื–ืึธื’ืŸ ืื™ืจ ื•ื•ื™ ืฆื• ื‘ืึทืงื•ืžืขืŸ ื“ืขืžืึธ ื•ื•ืขืจืกื™ืขืก. ืื™ืš ื•ื•ืขืœ ืคึผืจื•ื‘ื™ืจืŸ ืฆื• ืฉื˜ืขืœืŸ ืฆื•ื–ืึทืžืขืŸ ื“ื™ GRE-over-IPsec ืื•ืŸ IPsec-over-GRE ืกืงื™ืžื–.

ื•ื•ื™ ืฆื• ื‘ืึทืงื•ืžืขืŸ ืึท ื“ืขืžืึธ

1.5 ืกืงื™ืžื– ืื•ื™ืฃ ื“ื™ื ืขืจ IPsec VPN. ื˜ืขืกื˜ื™ื ื’ ื“ืขืžืึธืก

ืคื•ืŸ ื“ื™ ื‘ื™ืœื“ ืขืก ื’ื™ื™ื˜ ืึทื– ืฆื• ื‘ืึทืงื•ืžืขืŸ ื“ื™ ื“ืขืžืึธ ื•ื•ืขืจืกื™ืข ืื™ืจ ื“ืึทืจืคึฟืŸ:

  • ืฉืจื™ื™ื‘ื˜ ื ื‘ืจื™ื•ื• ืฆื• presale@s-terra.ru ืคื•ืŸ ืื™ื™ืขืจ ืงืืจืคืืจืื˜ ืื“ืจืขืก;
  • ืื™ืŸ ื“ืขื ื‘ืจื™ื•ื•, ืึธื ื•ื•ื™ื™ึทื–ืŸ ื“ื™ TIN ืคื•ืŸ ื“ื™ื™ืŸ ืึธืจื’ืึทื ื™ื–ืึทืฆื™ืข;
  • ืจืฉื™ืžื” ื“ื™ ืคึผืจืึธื“ื•ืงื˜ืŸ ืื•ืŸ ื–ื™ื™ืขืจ ืงื•ื•ืึทื ื˜ืึทื˜ื™ื–.

ื“ืขืžืึธ ื•ื•ืขืจืกื™ืขืก ื–ืขื ืขืŸ ื’ื™ืœื˜ื™ืง ืคึฟืึทืจ ื“ืจื™ื™ ื—ื“ืฉื™ื. ื“ืขืจ ืคืึทืจืงื•ื™ืคืขืจ ื˜ื•ื˜ ื ื™ืฉื˜ ื‘ืึทื’ืจืขื ืขืฆืŸ ื–ื™ื™ืขืจ ืคืึทื ื’ืงืฉืึทื ืึทืœื™ื˜ื™.

ืึทื ืคืึธื•ืœื“ื™ื ื’ ื“ื™ ื‘ื™ืœื“

ื“ื™ ื“ืขืžืึธ ื•ื•ืขืจืกื™ืข ืคื•ืŸ โ€‹โ€‹ื“ื™ ืกืขืงื•ืจื™ื˜ื™ ื’ืึทื˜ืขื•ื•ื™ื™ึท ืื™ื– ืึท ื‘ื™ืœื“ ืคื•ืŸ ืึท ื•ื•ื™ืจื˜ื•ืึทืœ ืžืึทืฉื™ืŸ. ืื™ืš ื ื•ืฆืŸ VMWare Workstation. ื ืคื•ืœืฉื˜ืขื ื“ื™ืง ืจืฉื™ืžื” ืคื•ืŸ ื’ืขืฉื˜ื™ืฆื˜ ื›ื™ื™ืคึผืขืจื•ื•ื™ื™ื–ืขืจื– ืื•ืŸ ื•ื•ื™ืจื˜ื•ืึทืœื™ื–ืึทื˜ื™ืึธืŸ ื™ื ื•ื•ื™ื™ืจืึทื ืžืึทื ืฅ ืื™ื– ื‘ื ื™ืžืฆื ืื•ื™ืฃ ื“ื™ ืคืึทืจืงื•ื™ืคืขืจ ืก ื•ื•ืขื‘ื–ื™ื™ื˜ืœ.

ืื™ื™ื“ืขืจ ืื™ืจ ืึธื ื”ื™ื™ื‘ืŸ, ื‘ื™ื˜ืข ื˜ืึธืŸ ืึทื– ื“ื™ ืคืขืœื™ืงื™ื™ึทื˜ ื•ื•ื™ืจื˜ื•ืึทืœ ืžืึทืฉื™ืŸ ื‘ื™ืœื“ ื”ืื˜ ื ื™ืฉื˜ ื ืขืฅ ื™ื ื˜ืขืจืคื™ื™ืกื™ื–:

1.5 ืกืงื™ืžื– ืื•ื™ืฃ ื“ื™ื ืขืจ IPsec VPN. ื˜ืขืกื˜ื™ื ื’ ื“ืขืžืึธืก

ื“ื™ ืœืึธื’ื™ืง ืื™ื– ืงืœืึธืจ, ื“ืขืจ ื‘ืึทื ื™ืฆืขืจ ืžื•ื–ืŸ ืœื™ื™ื’ืŸ ื•ื•ื™ ืคื™ืœืข ื™ื ื˜ืขืจืคื™ื™ืกื™ื– ื•ื•ื™ ืขืจ ื“ืึทืจืฃ. ืื™ืš ืฐืขืœ ืฆื•ืœืฒื’ืŸ ืคึฟื™ืจ ื’ืœืฒึทืš:

1.5 ืกืงื™ืžื– ืื•ื™ืฃ ื“ื™ื ืขืจ IPsec VPN. ื˜ืขืกื˜ื™ื ื’ ื“ืขืžืึธืก

ืื™ืฆื˜ ืื™ืš ืงืึทื˜ืขืจ ื“ื™ ื•ื•ื™ืจื˜ื•ืึทืœ ืžืึทืฉื™ืŸ. ื’ืœื™ื™ืš ื ืึธืš ืงืึทื˜ืขืจ, ื“ื™ ื’ื™ื™ื˜ื•ื•ื™ื™ ืจื™ืงื•ื•ื™ื™ืขืจื– ืึท ืœืึธื’ื™ืŸ ืื•ืŸ ืคึผืึทืจืึธืœ.

S-Terra Gateway ื”ืื˜ ืขื˜ืœืขื›ืข ืงืึทื ืกืึธื•ืœื– ืžื™ื˜ ืคืึทืจืฉื™ื“ืขื ืข ืึทืงืึทื•ื ืฅ. ืื™ืš ื•ื•ืขืœ ืฆื™ื™ืœืŸ ื–ื™ื™ืขืจ ื ื•ืžืขืจ ืื™ืŸ ืึท ื‘ืึทื–ื•ื ื“ืขืจ ืึทืจื˜ื™ืงืœ. ื‘ื™ื–ื“ืขืจื•ื•ื™ื™ืœ:
Login as: administrator
Password: s-terra

ืื™ืš ื‘ื™ืŸ ื™ื ื™ืฉืึทืœื™ื–ื™ื ื’ ื“ื™ ื˜ื•ื™ืขืจ. ื™ื ื™ื˜ื™ืึทืœื™ื–ืึทื˜ื™ืึธืŸ ืื™ื– ืึท ืกื™ืงื•ื•ืึทื ืก ืคื•ืŸ ืึทืงืฉืึทื ื–: ืึทืจื™ื™ึทืŸ ืึท ื“ืขืจืœื•ื™ื‘ืขื ื™ืฉ, ื‘ืึทืฉื˜ืขื˜ื™ืงืŸ ืึท ื‘ื™ื™ืึทืœืึทื“ื–ืฉื™ืงืึทืœ ื˜ืจืึทืค ื ื•ืžืขืจ ื’ืขื ืขืจืึทื˜ืึธืจ (ืงืœืึทื•ื•ื™ืึทื˜ื•ืจ ืกื™ืžื™ืึทืœื™ื™ื˜ืขืจ - ืžื™ื™ืŸ ืจืขืงืึธืจื“ ืื™ื– 27 ืกืขืงื•ื ื“ืขืก) ืื•ืŸ ืฉืึทืคึฟืŸ ืึท ื ืขืฅ ืฆื•ื‘ื™ื ื“ ืžืึทืคึผืข.

ื ืขืฅ ืฆื•ื‘ื™ื ื“ ืžืึทืคึผืข. ืขืก ืื™ื– ื’ืขื•ื•ืืจืŸ ื’ืจื™ื ื’ืขืจ

ื•ื•ืขืจืกื™ืข 4.2 ื‘ืึทื’ืจื™ืกืŸ ื“ื™ ืึทืงื˜ื™ื•ื• ื‘ืึทื ื™ืฆืขืจ ืžื™ื˜ ืึทืจื˜ื™ืงืœืขืŸ:

Starting IPsec daemonโ€ฆ.. failed
ERROR: Could not establish connection with daemon

ืึทืŸ ืึทืงื˜ื™ื•ื• ื‘ืึทื ื™ืฆืขืจ (ืœื•ื™ื˜ ืึทืŸ ืึทื ืึธื ื™ืžืข ื‘ืึทื ื•ืฆืขืจืก) ืื™ื– ืึท ื‘ืึทื ื™ืฆืขืจ ื•ื•ืึธืก ืงืขื ืขืŸ ืงืึทื ืคื™ื’ื™ืขืจ ืขืคึผืขืก ื’ืขืฉื•ื•ื™ื ื“ ืื•ืŸ ืึธืŸ ื“ืึทืงื™ื•ืžืขื ื˜ื™ื™ืฉืึทืŸ.

ืขืคึผืขืก ืื™ื– ื’ืขื•ื•ืขืŸ ืคืึทืœืฉ ืืคื™ืœื• ืื™ื™ื“ืขืจ ื˜ืจื™ื™ื ื’ ืฆื• ืงืึทื ืคื™ื’ื™ืขืจ ื“ื™ IP ืึทื“ืจืขืก ืื•ื™ืฃ ื“ื™ ืฆื•ื‘ื™ื ื“. ืขืก ืก ืึทืœืข ื•ื•ืขื’ืŸ ื“ื™ ื ืขืฅ ืฆื•ื‘ื™ื ื“ ืžืึทืคึผืข. ืขืก ืื™ื– ื ื™ื™ื˜ื™ืง ืฆื• ื˜ืึธืŸ:

/bin/netifcfg enum > /home/map
/bin/netifcfg map /home/map
service networking restart

ื•ื•ื™ ืึท ืจืขื–ื•ืœื˜ืึทื˜, ืึท ืžืึทืคึผืข ืคื•ืŸ โ€‹โ€‹ื ืขืฅ ื™ื ื˜ืขืจืคื™ื™ืกื™ื– ืื™ื– ื‘ืืฉืืคืŸ, ื•ื•ืึธืก ื›ึผื•ืœืœ ืึท ืžืึทืคึผื™ื ื’ ืคื•ืŸ ื“ื™ ื ืขืžืขืŸ ืคื•ืŸ ื’ืฉืžื™ื•ืช ื™ื ื˜ืขืจืคื™ื™ืกื™ื– (0000:02:03.0) ืื•ืŸ ื–ื™ื™ืขืจ ืœืึทื“ื–ืฉื™ืงืึทืœ ื“ืขื–ื™ื’ื ื™ื™ืฉืึทื ื– ืื™ืŸ ื“ื™ ืึธืคึผืขืจื™ื™ื˜ื™ื ื’ ืกื™ืกื˜ืขื (ืขื˜ื”0) ืื•ืŸ ืกื™ืกืงืึธ-ื•ื•ื™ ืงืึทื ืกืึธื•ืœ (FastEthernet0/0) :

#Unique ID iface type OS name Cisco-like name

0000:02:03.0 phye eth0 FastEthernet0/0

ืœืึทื“ื–ืฉื™ืงืึทืœ ืฆื•ื‘ื™ื ื“ ื“ืขื–ื™ื’ื ื™ื™ืฉืึทื ื– ื–ืขื ืขืŸ ื’ืขืจื•ืคืŸ ื™ื™ืœื™ืึทืกื™ื–. ืึทืœื™ืึทืกืขืก ื–ืขื ืขืŸ ืกื˜ืึธืจื“ ืื™ืŸ ื“ื™ /etc/ifaliases.cf ื˜ืขืงืข.
ืื™ืŸ ื•ื•ืขืจืกื™ืข 4.3, ื•ื•ืขืŸ ืื™ืจ ืขืจืฉื˜ืขืจ ืึธื ื”ื™ื™ื‘ ืึท ื•ื•ื™ืจื˜ื•ืึทืœ ืžืึทืฉื™ืŸ, ืึทืŸ ืฆื•ื‘ื™ื ื“ ืžืึทืคึผืข ืื™ื– ืื•ื™ื˜ืึธืžืึทื˜ื™ืฉ ื‘ืืฉืืคืŸ. ืื•ื™ื‘ ืื™ืจ ื˜ื•ื™ืฉืŸ ื“ื™ ื ื•ืžืขืจ ืคื•ืŸ ื ืขืฅ ื™ื ื˜ืขืจืคื™ื™ืกื™ื– ืื™ืŸ ื“ื™ ื•ื•ื™ืจื˜ื•ืึทืœ ืžืึทืฉื™ืŸ, ื‘ื™ื˜ืข ืžืึทื›ืŸ ื“ื™ ืฆื•ื‘ื™ื ื“ ืžืึทืคึผืข ื•ื•ื™ื“ืขืจ:

/bin/netifcfg enum > /home/map
/bin/netifcfg map /home/map
systemctl restart networking

ืกื›ืขืžืข 1: GRE-over-IPsec

ืื™ืš ืฆืขื•ื•ื™ืงืœืขืŸ ืฆื•ื•ื™ื™ ื•ื•ื™ืจื˜ื•ืึทืœ ื’ื™ื™ื˜ื•ื•ื™ื™ื– ืื•ืŸ ื‘ืึทืฉื˜ื™ืžืขืŸ ื•ื•ื™ ื’ืขื•ื•ื™ื–ืŸ ืื™ืŸ ื“ื™ ืคื™ื’ื•ืจ:

1.5 ืกืงื™ืžื– ืื•ื™ืฃ ื“ื™ื ืขืจ IPsec VPN. ื˜ืขืกื˜ื™ื ื’ ื“ืขืžืึธืก

ืฉืจื™ื˜ 1. ืงืึทื ืคื™ื’ื™ืขืจ ื™ืคึผ ื•ื•ืขื ื“ื˜ ืื•ืŸ ืจื•ืฅ

VG1(config) #
interface fa0/0
ip address 172.16.1.253 255.255.255.0
no shutdown
interface fa0/1
ip address 192.168.1.253 255.255.255.0
no shutdown
ip route 0.0.0.0 0.0.0.0 172.16.1.254

VG2(config) #
interface fa0/0
ip address 172.16.1.254 255.255.255.0
no shutdown
interface fa0/1
ip address 192.168.2.254 255.255.255.0
no shutdown
ip route 0.0.0.0 0.0.0.0 172.16.1.253

ืื™ืš ื˜ืฉืขืง IP ืงืึทื ืขืงื˜ื™ื•ื•ื™ื˜ื™:

root@VG1:~# ping 172.16.1.254 -c 4
PING 172.16.1.254 (172.16.1.254) 56(84) bytes of data.
64 bytes from 172.16.1.254: icmp_seq=1 ttl=64 time=0.545 ms
64 bytes from 172.16.1.254: icmp_seq=2 ttl=64 time=0.657 ms
64 bytes from 172.16.1.254: icmp_seq=3 ttl=64 time=0.687 ms
64 bytes from 172.16.1.254: icmp_seq=4 ttl=64 time=0.273 ms

--- 172.16.1.254 ping statistics ---
4 packets transmitted, 4 received, 0% packet loss, time 3005ms
rtt min/avg/max/mdev = 0.273/0.540/0.687/0.164 ms

ืฉืจื™ื˜ 2. ื‘ืึทืฉื˜ืขื˜ื™ืงืŸ GRE

ืื™ืš ื ืขืžืขืŸ ืึท ื‘ื™ื™ืฉืคึผื™ืœ ืคื•ืŸ ื‘ืึทืฉื˜ืขื˜ื™ืงืŸ GRE ืคึฟื•ืŸ ื“ื™ ื‘ืึทืึทืžื˜ืขืจ ืกืงืจื™ืคึผืก. ืื™ืš ืžืึทื›ืŸ ืึท ื˜ืขืงืข gre1 ืื™ืŸ ื“ื™ /etc/network/interfaces.d ื•ื•ืขื’ื•ื•ื™ื™ึทื–ืขืจ ืžื™ื˜ ื“ื™ ืื™ื ื”ืึทืœื˜.

ืคึฟืึทืจ VG1:

auto gre1
iface gre1 inet static
address 1.1.1.1
netmask 255.255.255.252
pre-up ip tunnel add gre1 mode gre remote 172.16.1.254 local 172.16.1.253 key 1 ttl 64 tos inherit
pre-up ethtool -K gre1 tx off > /dev/null
pre-up ip link set gre1 mtu 1400
post-down ip link del gre1

ืคึฟืึทืจ VG2:

auto gre1
iface gre1 inet static
address 1.1.1.2
netmask 255.255.255.252
pre-up ip tunnel add gre1 mode gre remote 172.16.1.253 local 172.16.1.254 key 1 ttl 64 tos inherit
pre-up ethtool -K gre1 tx off > /dev/null
pre-up ip link set gre1 mtu 1400
post-down ip link del gre1

ืื™ืš ื›ืึทืคึผืŸ ื“ื™ ืฆื•ื‘ื™ื ื“ ืื™ืŸ ื“ื™ ืกื™ืกื˜ืขื:

root@VG1:~# ifup gre1
root@VG2:~# ifup gre1

ืื™ืš ื˜ืฉืขืง:

root@VG1:~# ip address show
8: gre1@NONE: <POINTOPOINT,NOARP,UP,LOWER_UP> mtu 1400 qdisc noqueue state UNKNOWN group default qlen 1
    link/gre 172.16.1.253 peer 172.16.1.254
    inet 1.1.1.1/30 brd 1.1.1.3 scope global gre1
       valid_lft forever preferred_lft forever

root@VG1:~# ip tunnel show
gre0: gre/ip remote any local any ttl inherit nopmtudisc
gre1: gre/ip remote 172.16.1.254 local 172.16.1.253 ttl 64 tos inherit key 1

S-Terra Gateway ื”ืื˜ ืึท ื’ืขื‘ื•ื™ื˜-ืื™ืŸ ืคึผืึทืงืึทื˜ ืกื ื™ืคืขืจ - tcpdump. ืื™ืš ื•ื•ืขื˜ ืฉืจื™ื™ึทื‘ืŸ ืึท ืคืึทืจืงืขืจ ื“ืึทืžืคึผ ืฆื• ืึท ืคึผืงืึทืคึผ ื˜ืขืงืข:

root@VG2:~# tcpdump -i eth0 -w /home/dump.pcap

ืื™ืš ืœื•ื™ืคืŸ ืคึผื™ื ื’ ืฆื•ื•ื™ืฉืŸ GRE ื™ื ื˜ืขืจืคื™ื™ืกื™ื–:

root@VG1:~# ping 1.1.1.2 -c 4
PING 1.1.1.2 (1.1.1.2) 56(84) bytes of data.
64 bytes from 1.1.1.2: icmp_seq=1 ttl=64 time=0.918 ms
64 bytes from 1.1.1.2: icmp_seq=2 ttl=64 time=0.850 ms
64 bytes from 1.1.1.2: icmp_seq=3 ttl=64 time=0.918 ms
64 bytes from 1.1.1.2: icmp_seq=4 ttl=64 time=0.974 ms

--- 1.1.1.2 ping statistics ---
4 packets transmitted, 4 received, 0% packet loss, time 3006ms
rtt min/avg/max/mdev = 0.850/0.915/0.974/0.043 ms

GRE ื˜ื•ื ืขืœ ืื™ื– ืึทืงื˜ื™ื•ื• ืื•ืŸ ืคืœื™ืกื ื“ื™ืง:

1.5 ืกืงื™ืžื– ืื•ื™ืฃ ื“ื™ื ืขืจ IPsec VPN. ื˜ืขืกื˜ื™ื ื’ ื“ืขืžืึธืก

ืฉืจื™ื˜ 3. ืขื ืงืจื™ืคึผื˜ ืžื™ื˜ GOST GRE

ืื™ืš ืฉื˜ืขืœืŸ ื“ื™ ืœืขื’ื™ื˜ื™ืžืึทืฆื™ืข ื˜ื™ืคึผ - ื“ื•ืจืš ืึทื“ืจืขืก. ืึธื˜ืขื ื˜ืึทืงื™ื™ืฉืึทืŸ ื ื™ืฆืŸ ืึท ืคึผืจืขื“ืขืคื™ื ืขื“ ืฉืœื™ืกืœ (ืœื•ื™ื˜ ื“ื™ ืชึผื ืึธื™ื ืคื•ืŸ ื ื•ืฆืŸ, ื“ื™ื’ื™ื˜ืึทืœ ืกืขืจื˜ื™ืคื™ืงืึทืฅ ืžื•ื–ืŸ ื–ื™ื™ืŸ ื’ืขื•ื•ื™ื™ื ื˜):

VG1(config)#
crypto isakmp identity address
crypto isakmp key KEY address 172.16.1.254

ืื™ืš ืฉื˜ืขืœืŸ ื“ื™ IPsec ืคืึทืกืข ืื™ืš ืคึผืึทืจืึทืžืขื˜ืขืจืก:

VG1(config)#
crypto isakmp policy 1
encr gost
hash gost3411-256-tc26
auth pre-share
group vko2

ืื™ืš ืฉื˜ืขืœืŸ ื“ื™ IPsec ืคืึทืกืข ื•ื• ืคึผืึทืจืึทืžืขื˜ืขืจืก:

VG1(config)#
crypto ipsec transform-set TSET esp-gost28147-4m-imit
mode tunnel

ืื™ืš ืงืจื™ื™ื™ื˜ื™ื ื’ ืึท ืขื ืงืจื™ืคึผืฉืึทืŸ ืึทืงืกืขืก ืจืฉื™ืžื”. ืฆื™ืœ ืคืึทืจืงืขืจ - GRE:

VG1(config)#
ip access-list extended LIST
permit gre host 172.16.1.253 host 172.16.1.254

ืื™ืš ืžืึทื›ืŸ ืึท ืงืจื™ืคึผื˜ืึธ ืงืึธืจื˜ ืื•ืŸ ื‘ื™ื ื“ืŸ ืขืก ืฆื• ื“ื™ WAN ืฆื•ื‘ื™ื ื“:

VG1(config)#
crypto map CMAP 1 ipsec-isakmp
match address LIST
set transform-set TSET
set peer 172.16.1.253
interface fa0/0
  crypto map CMAP

ืคึฟืึทืจ VG2 ื“ื™ ืงืึทื ืคื™ื’ื™ืขืจื™ื™ืฉืึทืŸ ืื™ื– ืฉืคึผื™ื’ืœ, ื“ื™ืคืขืจืึทื ืกื™ื–:

VG2(config)#
crypto isakmp key KEY address 172.16.1.253
ip access-list extended LIST
permit gre host 172.16.1.254 host 172.16.1.253
crypto map CMAP 1 ipsec-isakmp
set peer 172.16.1.254

ืื™ืš ื˜ืฉืขืง:

root@VG2:~# tcpdump -i eth0 -w /home/dump2.pcap
root@VG1:~# ping 1.1.1.2 -c 4
PING 1.1.1.2 (1.1.1.2) 56(84) bytes of data.
64 bytes from 1.1.1.2: icmp_seq=1 ttl=64 time=1128 ms
64 bytes from 1.1.1.2: icmp_seq=2 ttl=64 time=126 ms
64 bytes from 1.1.1.2: icmp_seq=3 ttl=64 time=1.07 ms
64 bytes from 1.1.1.2: icmp_seq=4 ttl=64 time=1.12 ms

--- 1.1.1.2 ping statistics ---
4 packets transmitted, 4 received, 0% packet loss, time 3006ms
rtt min/avg/max/mdev = 1.077/314.271/1128.419/472.826 ms, pipe 2

ISAKMP/IPsec ืกื˜ืึทื˜ื™ืกื˜ื™ืง:

root@VG1:~# sa_mgr show
ISAKMP sessions: 0 initiated, 0 responded

ISAKMP connections:
Num Conn-id (Local Addr,Port)-(Remote Addr,Port) State Sent Rcvd
1 1 (172.16.1.253,500)-(172.16.1.254,500) active 1086 1014

IPsec connections:
Num Conn-id (Local Addr,Port)-(Remote Addr,Port) Protocol Action Type Sent Rcvd
1 1 (172.16.1.253,*)-(172.16.1.254,*) 47 ESP tunn 480 480

ืขืก ื–ืขื ืขืŸ ืงื™ื™ืŸ ืคึผืึทืงื™ืฅ ืื™ืŸ ื“ื™ GRE ืคืึทืจืงืขืจ ื“ืึทืžืคึผ:

1.5 ืกืงื™ืžื– ืื•ื™ืฃ ื“ื™ื ืขืจ IPsec VPN. ื˜ืขืกื˜ื™ื ื’ ื“ืขืžืึธืก

ืžืกืงื ื: ื“ื™ GRE-over-IPsec ืกื›ืขืžืข ืึทืจื‘ืขื˜ ืจื™ื›ื˜ื™ืง.

ืกื›ืขืžืข 1.5: IPsec-over-GRE

ืื™ืš ื˜ืึธืŸ ื ื™ื˜ ืคึผืœืึทืŸ ืฆื• ื ื•ืฆืŸ IPsec-over-GRE ืื•ื™ืฃ ื“ื™ ื ืขืฅ. ืื™ืš ืงืœื™ื™ึทื‘ืŸ ืขืก ื•ื•ื™ื™ึทืœ ืื™ืš ื•ื•ื™ืœืŸ ืฆื•.

1.5 ืกืงื™ืžื– ืื•ื™ืฃ ื“ื™ื ืขืจ IPsec VPN. ื˜ืขืกื˜ื™ื ื’ ื“ืขืžืึธืก

ืฆื• ืฆืขื•ื•ื™ืงืœืขืŸ ื“ื™ GRE-over-IPsec ืกื›ืขืžืข ืคืึทืจืงืขืจื˜, ืื™ืจ ื“ืึทืจืคึฟืŸ ืฆื•:

  • ืจื™ื›ื˜ื™ืง ื“ื™ ืึทืงืกืขืก ืจืฉื™ืžื” ืคึฟืึทืจ ืขื ืงืจื™ืคึผืฉืึทืŸ - ืฆื™ืœ ืคืึทืจืงืขืจ ืคื•ืŸ LAN1 ืฆื• LAN2 ืื•ืŸ ื•ื•ื™ืฆืข ื•ื•ืขืจืกืึท;
  • ืงืึทื ืคื™ื’ื™ืขืจ ืจื•ื˜ื™ื ื’ ื“ื•ืจืš GRE;
  • ื”ืขื ื’ืขืŸ ื“ื™ ืงืจื™ืคึผื˜ืึธ ืงืึธืจื˜ ืื•ื™ืฃ ื“ื™ GRE ืฆื•ื‘ื™ื ื“.

ื“ื•ืจืš ืคืขืœื™ืงื™ื™ึทื˜, ื“ื™ ืกื™ืกืงืึธ-ื•ื•ื™ ื’ื™ื™ื˜ื•ื•ื™ื™ ืงืึทื ืกืึธื•ืœ ื”ืื˜ ื ื™ืฉื˜ ืึท GRE ืฆื•ื‘ื™ื ื“. ืขืก ืื™ื– ื‘ืœื•ื™ื– ืื™ืŸ ื“ื™ ืึธืคึผืขืจื™ื™ื˜ื™ื ื’ ืกื™ืกื˜ืขื.

ืื™ืš ื‘ื™ืŸ ืึทื“ื™ื ื’ ืึท GRE ืฆื•ื‘ื™ื ื“ ืฆื• ืึท ืกื™ืกืงืึธ-ื•ื•ื™ ืงืึทื ืกืึธื•ืœ. ืฆื• ื˜ืึธืŸ ื“ืึธืก, ืื™ืš ืจืขื“ืึทื’ื™ืจืŸ ื“ื™ /etc/ifaliases.cf ื˜ืขืงืข:

interface (name="FastEthernet0/0" pattern="eth0")
interface (name="FastEthernet0/1" pattern="eth1")
interface (name="FastEthernet0/2" pattern="eth2")
interface (name="FastEthernet0/3" pattern="eth3")
interface (name="Tunnel0" pattern="gre1")
interface (name="default" pattern="*")

ื•ื•ื• gre1 ืื™ื– ื“ื™ ืฆื•ื‘ื™ื ื“ ื‘ืึทืฆื™ื™ื›ืขื ื•ื ื’ ืื™ืŸ ื“ื™ ืึธืคึผืขืจื™ื™ื˜ื™ื ื’ ืกื™ืกื˜ืขื, Tunnel0 ืื™ื– ื“ื™ ืฆื•ื‘ื™ื ื“ ื‘ืึทืฆื™ื™ื›ืขื ื•ื ื’ ืื™ืŸ ื“ื™ ืกื™ืกืงืึธ-ื•ื•ื™ ืงืึทื ืกืึธื•ืœ.

ืื™ืš ืจืขืงืึทืœืงื•ืœื™ืจืŸ ื“ื™ ื”ืึทืฉ ืคื•ืŸ ื“ืขืจ ื˜ืขืงืข:

root@VG1:~# integr_mgr calc -f /etc/ifaliases.cf

SUCCESS:  Operation was successful.

ืื™ืฆื˜ ื“ื™ Tunnel0 ืฆื•ื‘ื™ื ื“ ืื•ื™ืก ืื™ืŸ ื“ื™ ืกื™ืกืงืึธ-ื•ื•ื™ ืงืึทื ืกืึธื•ืœ:

VG1# show run
interface Tunnel0
ip address 1.1.1.1 255.255.255.252
mtu 1400

ืื™ืš ืึทื“ื–ืฉืึทืกื˜ื™ื“ ื“ื™ ืึทืงืกืขืก ืจืฉื™ืžื” ืคึฟืึทืจ ืขื ืงืจื™ืคึผืฉืึทืŸ:

VG1(config)#
ip access-list extended LIST
permit ip 192.168.1.0 0.0.0.255 192.168.3.0 0.0.0.255

ื‘ืึทืฉื˜ืขื˜ื™ืงืŸ ืจื•ื˜ื™ื ื’ ื“ื•ืจืš GRE:

VG1(config)#
no ip route 0.0.0.0 0.0.0.0 172.16.1.254
ip route 192.168.3.0 255.255.255.0 1.1.1.2

ืื™ืš ืึทืจืึธืคึผื ืขืžืขืŸ ื“ื™ ืงืจื™ืคึผื˜ืึธ ืงืึธืจื˜ ืคื•ืŸ Fa0/0 ืื•ืŸ ื‘ื™ื ื“ืŸ ืขืก ืฆื• ื“ื™ GRE ืฆื•ื‘ื™ื ื“:

VG1(config)#
interface Tunnel0
crypto map CMAP

ืคึฟืึทืจ VG2 ืขืก ืื™ื– ื“ื™ ื–ืขืœื‘ืข.

ืื™ืš ื˜ืฉืขืง:

root@VG2:~# tcpdump -i eth0 -w /home/dump3.pcap

root@VG1:~# ping 192.168.2.254 -I 192.168.1.253 -c 4
PING 192.168.2.254 (192.168.2.254) from 192.168.1.253 : 56(84) bytes of data.
64 bytes from 192.168.2.254: icmp_seq=1 ttl=64 time=492 ms
64 bytes from 192.168.2.254: icmp_seq=2 ttl=64 time=1.08 ms
64 bytes from 192.168.2.254: icmp_seq=3 ttl=64 time=1.06 ms
64 bytes from 192.168.2.254: icmp_seq=4 ttl=64 time=1.07 ms

--- 192.168.2.254 ping statistics ---
4 packets transmitted, 4 received, 0% packet loss, time 3006ms
rtt min/avg/max/mdev = 1.064/124.048/492.972/212.998 ms

ISAKMP/IPsec ืกื˜ืึทื˜ื™ืกื˜ื™ืง:

root@VG1:~# sa_mgr show
ISAKMP sessions: 0 initiated, 0 responded

ISAKMP connections:
Num Conn-id (Local Addr,Port)-(Remote Addr,Port) State Sent Rcvd
1 2 (172.16.1.253,500)-(172.16.1.254,500) active 1094 1022

IPsec connections:
Num Conn-id (Local Addr,Port)-(Remote Addr,Port) Protocol Action Type Sent Rcvd
1 2 (192.168.1.0-192.168.1.255,*)-(192.168.2.0-192.168.2.255,*) * ESP tunn 352 352

ืื™ืŸ ื“ื™ ESP ืคืึทืจืงืขืจ ื“ืึทืžืคึผ, ืคึผืึทืงื™ืฅ ืขื ืงืึทืคึผืกืึทืœื™ื™ื˜ื™ื“ ืื™ืŸ GRE:

1.5 ืกืงื™ืžื– ืื•ื™ืฃ ื“ื™ื ืขืจ IPsec VPN. ื˜ืขืกื˜ื™ื ื’ ื“ืขืžืึธืก

ืžืกืงื ื: IPsec-over-GRE ืึทืจื‘ืขื˜ ืจื™ื›ื˜ื™ืง.

ืจืขื–ื•ืœื˜ืึทื˜ืŸ ืคื•ืŸ

ืื™ื™ืŸ ื’ืœืขื–ืœ ืงืึทื•ื•ืข ืื™ื– ื’ืขื ื•ื’. ืื™ืš'ื•ื•ืข ื“ื–ืฉืึธื˜ื˜ืขื“ ืึทืจืึธืคึผ ื™ื ืกื˜ืจืึทืงืฉืึทื ื– ืคึฟืึทืจ ื‘ืึทืงื•ืžืขืŸ ืึท ื“ืขืžืึธ. ืงืึทื ืคื™ื’ื™ืขืจื“ GRE-over-IPsec ืื•ืŸ ื“ื™ืคึผืœื•ื™ื“ ืขืก ื“ื™ ืื ื“ืขืจืข ื•ื•ืขื’ ืึทืจื•ื.

ื“ื™ ื ืขืฅ ืฆื•ื‘ื™ื ื“ ืžืึทืคึผืข ืื™ืŸ ื•ื•ืขืจืกื™ืข 4.3 ืื™ื– ืึธื˜ืึทืžืึทื˜ื™ืง! ืื™ืš ืคึผืจื•ื‘ื™ืจืŸ ื•ื•ื™ื™ึทื˜ืขืจ.

ืึทื ืึธื ื™ืžืึธื•ืก ื™ื ื–ืฉืขื ื™ืจ
t.me/anonymous_engineer


ืžืงื•ืจ: www.habr.com