ืื ื ืืื ืฆื ืฆืืฉืืขืื ืืืืึทื ืึทืงืกืขืก ืฆื ืึท ืคึฟืืจืืข ืกืืืืืืข ืืื ืืืขืจืืืฉืื ื ืืขืจ ืืื ืืขืจ ืึธืคื, ืงืืื ืขื ืื ืฆื ืขืก ืืขื ืขื ืืืื ืืืืขืจื ืึธืืขืจ ืคึผืึทืจืื ืขืจืก ืืืึธืก ืืึทืจืคึฟื ืึทืงืกืขืก ืฆื ืึท ืืึทืืื ืืขืจ ืกืขืจืืืขืจ ืืื ืืืื ืึธืจืืึทื ืืืึทืฆืืข.
ืคึฟืึทืจ ืื ืฆืืืขืงื, ืจืืึฟ ืงืึธืืคึผืึทื ืืขืก ื ืืฆื VPN ืืขืื ืึธืืึธืืืข, ืืืึธืก ืืื ืคึผืจืึธืืืขื ืืื ืฆื ืืืื ืึท ืจืืืืืึทืืื ืคึผืจืึธืืขืงืืขื ืืืขื ืฆื ืฆืืฉืืขืื ืึทืงืกืขืก ืฆื ืื ืืืืข ืจืขืกืืจืกื ืคืื ืืขืจ ืึธืจืืึทื ืืืึทืฆืืข.
ืืืึทื ืคืืจืืข ืืื ืืขืืืขื ืงืืื ืืืกื ืขื, ืืื ืืืจ, ืืื ืคืืืข ืื ืืขืจืข, ื ืืฆื ืืขื ืืขืื ืึธืืึธืืืข. ืืื, ืืื ืคืืืข ืื ืืขืจืข, ืืืจ ื ืืฆื Cisco ASA 55xx ืืื ืึท ืืืืึทื ืึทืงืกืขืก ืืืืืืืื.
ืืื ืื ื ืืืขืจ ืคืื ืืืืึทื ื ืืฆืขืจืก ืื ืงืจืืกืื, ืขืก ืืื ืึท ื ืืื ืฆื ืคืึทืจืคึผืึธืฉืขืืขืจื ืื ืคึผืจืึธืฆืขืืืจ ืคึฟืึทืจ ืืจืืืกืืขืื ืงืจืึทืืขื ืืฉืึทืื. ืืืขืจ ืืื ืืขืจ ืืขืืืืงืขืจ ืฆืืึทื, ืืึธืก ืืืื ืืืื ืืขืืื ืึธื ืงืึทืืคึผืจืึทืืืืืื ื ืืืืขืจืงืืึทื.
ืคึฟืึทืจ ืืื, ืืืจ ืืขืคึฟืื ืขื ืึท ืืืืืื ื ืืื ื ืืฆื ืฆืืืื-ืคืึทืงืืึธืจ ืึธืืขื ืืึทืงืืืฉืึทื ืคึฟืึทืจ ืงืึทื ืขืงืืื ื ืืืจื Cisco SSL VPN, ื ืืฆื ืืืื-ืฆืืึทื ืคึผืึทืกืืืขืจืื. ืืื ืื ืืืกืืึทืืข ืืืขื ืืึธืื ืืืจ ืืื ืฆื ืึธืจืืึทื ืืืืจื ืึทืืึท ืึท ืืืืืื ื ืืื ืืื ืืืึทื ืฆืืื ืืื ื ืื ืงืึธืก ืคึฟืึทืจ ืื ื ืืืืืง ืืืืืืืืืจื (ืฆืืืขืฉืืขืื ืึทื ืืืจ ืฉืืื ืืึธืื Cisco ASA ืืื ืืืื ืื ืคืจืึทืกืืจืึทืงืืฉืขืจ).
ืืขืจ ืืึทืจืง ืืื ืจืืคึผืืื ืืื ืืึธืงืกืขื ืกืึทืืืฉืึทื ื ืคึฟืึทืจ ืืืฉืขื ืขืจืืืืื ื ืืืื-ืฆืืึทื ืคึผืึทืกืืืขืจืื, ืืื ืึธืคืคืขืจืก ืึท ืคึผืืึทืฅ ืคืื ืึธืคึผืฆืืขืก ืฆื ืืึทืงืืืขื ืืื, ืืืื ืขืก ืฉืืงื ืื ืคึผืึทืจืึธื ืืืจื SMS ืึธืืขืจ ื ืืฆื ืืึธืงืขื ืก, ืืืืืข ืืึทืื ืืืึทืจื ืืื ืืืืืืืืืจื (ืืืฉื, ืืืืฃ ืึท ืจืืจืขืืืืืง ืืขืืขืคืึธื). ืึธืืขืจ ืืขืจ ืคืึทืจืืึทื ื ืฆื ืฉืคึผืึธืจื ืืขืื ืืื ืืขืจ ืคืึทืจืืึทื ื ืฆื ืฉืคึผืึธืจื ืืขืื ืคึฟืึทืจ ืืืื ืืึทืืขืืึธืก, ืืื ืืขื ืงืจืึทื ื ืงืจืืืืก, ืืขืฆืืืื ืืขื ืืืจ ืฆื ืืขืคึฟืื ืขื ืึท ืคืจืื ืืืขื ืฆื ืื ืกืืจืืืขื ื ืึท ืืื ืกื ืคึฟืึทืจ ืืืฉืขื ืขืจืืืืื ื ืืืื-ืฆืืึทื ืคึผืึทืกืืืขืจืื. ืืืึธืก, ืืึธืืฉ ืคืจืื, ืืื ื ืืฉื ืคืื ืขืจืืขืจ ืฆื ืืขืฉืขืคื ืกืึทืืืฉืึทื ื (ืืึธ ืืืจ ืืึธื ืืึทืื ืึท ืจืขืืขืจืืืึทืฆืืข, ืืืืขืจืงื ืึทื ืืขื ืคึผืจืึธืืืงื ืืืื ืืื ืึท ืืขืฉืขืคื ืืืขืจืกืืข, ืึธืืขืจ ืืืจ ืืกืืื ืึทื ืืื ืืืขืจ ืงืึธืก ืืื ืืขืื ืืืขื ืืืื ื ืื).
ืึทืืื, ืืืจ ืืืขืื ืืึทืจืคึฟื:
- ื ืืื ืืงืก ืืืื ืืื ืึท ืืขืืืื-ืืื ืืึทื ื ืคืื ืืืฉืืจืื - ืืืืืืึธืืคึผ, ืคืจืขืขืจืึทืืืืก ืืื ื ืืื ืงืก, ืคึฟืึทืจ ืึทืงืกืขืก ืื ืกืขืจืืืขืจ ืืืจื ืื ืืืขื (http://download.multiotp.net/ - ืืื ืืขืืืืื ื ืึท ืคืึทืจืืืง ืืืื ืคึฟืึทืจ VMware)
- ืึทืงืืืื Directory ืกืขืจืืืืจืขืจ
- Cisco ASA ืืื (ืคึฟืึทืจ ืงืึทื ืืืื ืืึทื ืก, ืืื ื ืืฆื ASDM)
- ืงืืื ืืืืืืืืืจื ืกืืืขื ืืืึธืก ืฉืืืฆื ืื TOTP ืืขืงืึทื ืืืึทื (ืืื, ืืืฉื, ื ืืฆื Google Authenticator, ืึธืืขืจ ืืขืจ ืืขืืืืงืขืจ FreeOTP ืืืขื ืืึธื)
ืืื ืืืขื ื ืืฉื ืืืื ืืื ืคืจืืื ืคืื ืืื ืื ืืืื ืึทื ืคืึธืืืื. ืืื ืึท ืจืขืืืืืึทื, ืืืจ ืืืขื ืืึทืงืืืขื ืืขืืืึทื ืืื ืืงืก ืืื MultiOTP ืืื FreeRADIUS ืฉืืื ืืื ืกืืึทืืืจื, ืงืึทื ืคืืืืขืจื ืฆื ืึทืจืืขืื ืฆืืืึทืืขื ืืื ืึท ืืืขื ืฆืืืื ื ืคึฟืึทืจ ืึธืืคึผ ืึทืืืื ืืกืืจืึทืฆืืข.
ืฉืจืื 1. ืืืจ ืึธื ืืืืื ืื ืกืืกืืขื ืืื ืงืึทื ืคืืืืขืจ ืขืก ืคึฟืึทืจ ืืืื ื ืขืฅ
ืืืจื ืคืขืืืงืืึทื, ืื ืกืืกืืขื ืงืืื ืืื ืืืึธืจืฆื ืืืึธืจืฆื ืงืจืึทืืขื ืืฉืึทืื. ืืื ืืจืึทืืื ืึทืืขืืขื ืืขืกื ืึทื ืขืก ืืืึธืื ืืืื ืึท ืืืืข ืืขืืึทื ืง ืฆื ืืืืฉื ืื ืืืึธืจืฆื ืืึทื ืืฆืขืจ ืคึผืึทืจืึธื ื ืึธื ืืขืจ ืขืจืฉืืขืจ ืืึธืืื. ืืืจ ืืืื ืืึทืจืคึฟื ืฆื ืืืืฉื ืื ื ืขืฅ ืกืขืืืื ืืก (ืืืจื ืคืขืืืงืืึทื ืขืก ืืื '192.168.1.44' ืืื ืื ืืืืืืืื '192.168.1.1'). ืืขืจื ืึธื ืืืจ ืงืขื ืขื ืจืืกืืึทืจื ืื ืกืืกืืขื.
ืืึธืืืจ ืฉืึทืคึฟื ืึท ืืึทื ืืฆืขืจ ืืื ืึทืงืืืื Directory ืึธืืคึผ, ืืื ืคึผืึทืจืึธื MySuperPassword.
ืฉืจืื 2. ืฉืืขืื ืึทืจืืืฃ ืื ืงืฉืจ ืืื ืึทืจืืึทื ืคืืจ ืึทืงืืืืืข Directory ื ืืฆืขืจืก
ืฆื ืืึธื ืืึธืก, ืืืจ ืืึทืจืคึฟื ืึทืงืกืขืก ืฆื ืื ืงืึทื ืกืึธืื ืืื ืืืืึทื ืฆื ืืขืจ ืืขืงืข multiotp.php, ื ืืฆื ืืืึธืก ืืืจ ืืืขืื ืงืึทื ืคืืืืขืจ ืงืฉืจ ืกืขืืืื ืืก ืฆื Active Directory.
ืืืื ืฆื ืืืขืืืืืึทืืขืจ /usr/local/bin/multiotp/ ืืื ืืืจืืคืืจื ืื ืคืืืืขื ืืข ืงืึทืืึทื ืื ืืื ืืจืืึท:
./multiotp.php -config default-request-prefix-pin=0
ืืึทืฉืืืืขื ืฆื ืึทื ื ืึธื (ืฉืืขื ืืืง) ืฉืืืคื ืืื ืคืืจืืื ืื ืืืขื ืึทืจืืึทื ืึท ืืืื-ืฆืืึทื ืฉืืืคื (0 ืึธืืขืจ 1)
./multiotp.php -config default-request-ldap-pwd=0
ืืืืขืจืืึทื ื ืฆื ืึท ืคืขืื ืคึผืึทืจืึธื ืืื ืคืืจืืื ืื ืืืขื ืึทืจืืึทื ืึท ืืืื-ืฆืืึทื ืฉืืืคื (0 ืึธืืขืจ 1)
./multiotp.php -config ldap-server-type=1
ืืขืจ ืืืคึผ ืคืื LDAP ืกืขืจืืืขืจ ืืื ืื ืืขืืืืื (0 = ืจืขืืืืขืจ LDAP ืกืขืจืืืขืจ, ืืื ืืื ืืืขืจ ืคืึทื 1 = ืึทืงืืืื Directory)
./multiotp.php -config ldap-cn-identifier="sAMAccountName"
ืกืคึผืขืฆืืคืืฆืืจื ืื ืคึฟืึธืจืืึทื ืืื ืืืึธืก ืฆื ืคืึธืจืฉืืขืื ืืขื ื ืืืขื (ืืขื ืืืขืจื ืืืขื ืืืืึทืื ืืืืื ืื ื ืึธืืขื, ืึธื ืื ืคืขืื)
./multiotp.php -config ldap-group-cn-identifier="sAMAccountName"
ืื ืืขืืืข ืืึทื, ื ืึธืจ ืคึฟืึทืจ ืึท ืืจืืคึผืข
./multiotp.php -config ldap-group-attribute="memberOf"
ืกืคึผืขืฆืืคืืฆืืจื ืึท ืืขืืึธื ืฆื ืืึทืฉืืืกื ืฆื ืึท ืืึทื ืืฆืขืจ ืืขืืขืจื ืฆื ืึท ืืจืืคึผืข
./multiotp.php -config ldap-ssl=1
ืืึธื ืืื ื ืืฆื ืึท ืืืืขืจ ืงืฉืจ ืฆื ืื LDAP ืกืขืจืืืขืจ (ืคืื ืงืืจืก - ืืึธ!)
./multiotp.php -config ldap-port=636
ืคึผืึธืจื ืคึฟืึทืจ ืงืึทื ืขืงืืื ื ืฆื ืื LDAP ืกืขืจืืืขืจ
./multiotp.php -config ldap-domain-controllers=adSRV.domain.local
ืืืื ืึทืงืืืืืข Directory ืกืขืจืืืขืจ ืึทืืจืขืก
./multiotp.php -config ldap-base-dn="CN=Users,DC=domain,DC=local"
ืืืจ ืึธื ืืืืึทืื ืืื ืฆื ืึธื ืืืืื ืืืื ืคึฟืึทืจ ื ืืฆืขืจืก ืืื ืื ืคืขืื
./multiotp.php -config ldap-bind-dn="[email protected]"
ืกืคึผืขืฆืืคืืฆืืจื ืึท ืืึทื ืืฆืขืจ ืืืืก ืืื ืืืื ืจืขืื ืืื ืึทืงืืืื Directory
./multiotp.php -config ldap-server-password="MySuperPassword"
ืกืคึผืขืฆืืคืืฆืืจื ืื ืืึทื ืืฆืขืจ ืคึผืึทืจืึธื ืฆื ืคืึทืจืืื ืื ืฆื Active Directory
./multiotp.php -config ldap-network-timeout=10
ืืึทืฉืืขืืืงื ืื ืืืืืึทืื ืคึฟืึทืจ ืงืึทื ืขืงืืื ื ืฆื Active Directory
./multiotp.php -config ldap-time-limit=30
ืืืจ ืฉืืขืื ืึท ืฆืืื ืืืืื ืคึฟืึทืจ ืื ืืึทื ืืฆืขืจ ืึทืจืืึทื ืคืืจ ืึธืคึผืขืจืึทืฆืืข
./multiotp.php -config ldap-activated=1
ืึทืงืืึทืืืืืืื ื ืื ืงืึทื ืคืืืืขืจืืืฉืึทื ืคืื Active Directory ืคึฟืึทืจืืื ืืื ื
./multiotp.php -debug -display-log -ldap-users-sync
ืืืจ ืึทืจืืึทื ืคืืจ ื ืืฆืขืจืก ืคืื ืึทืงืืืื Directory
ืฉืจืื 3. ืืืฉืขื ืขืจืืื ืึท QR ืงืึธื ืคึฟืึทืจ ืื ืกืืืขื
ืึทืืฅ ืืึธ ืืื ืืึธืจ ืคึผืฉืื. ืขืคึฟืขื ืขื ืื ืืืขื ืฆืืืื ื ืคืื ืื ืึธืืคึผ ืกืขืจืืืขืจ ืืื ืืขื ืืืขืืขืจืขืจ, โโืงืืึธืฅ ืืื (ืืึธื ื ืื ืคืึทืจืืขืกื ืฆื ืืืืฉื ืื ืคืขืืืงืืึทื ืคึผืึทืจืึธื ืคึฟืึทืจ ืื ืึทืืืื ืืกืืจืึทืืึธืจ!), ืืื ืืื ืื "ืืจืืง" ืงื ืขืคึผื:
ืืขืจ ืจืขืืืืืึทื ืคืื ืืขื ืงืึทืืฃ ืืืขื ืืืื ืึท ืืืึทื ืืืึธืก ืึผืืื ืฆืืืื QR ืงืึธืืื. ืืืจ ืืืืืง ืืืื ืึธืจืืจื ืืขืจ ืขืจืฉืืขืจ ืคืื ืืื (ืืจืึธืฅ ืื ืึทืืจืึทืงืืืื ืื ืกืงืจืืคึผืฉืึทื Google Authenticator / Authenticator / 2 Steps Authenticator), ืืื ืืืืืขืจ, ืืืจ ืืืืืง ืืืขืจืงืืงื ืื ืจืืข ืงืึธื ืืื ืึท ืืืืืืืืืจื ืกืืืขื ืืืืฃ ืื ืืขืืขืคืึธื:
(ืืึธ, ืืื ืืืืืืจืึทื ืงืึทืืืข ืื QR ืงืึธื ืฆื ืืึทืื ืขืก ืึทื ืจืืืึทืืึทื).
ื ืึธื ืงืึทืืคึผืืืืื ื ืื ืึทืงืฉืึทื ื, ืึท ืืขืงืก-ืฆืืคึฟืขืจ ืคึผืึทืจืึธื ืืืขื ืืืื ืืืฉืขื ืขืจืืืืึทื ืืื ืืืื ืึทืคึผืืึทืงืืืฉืึทื ืืขืืขืจ ืืจืืืกืืง ืกืขืงืื ืืขืก.
ืฆื ืืืื ืืืืขืจ, ืืืจ ืงืขื ืขื ืงืึธื ืืจืึธืืืจื ืขืก ืืื ืืขืจ ืืขืืืืงืขืจ ืฆืืืื ื:
ืืืจื ืึทืจืืึทื ืืืื ื ืืืขื ืืื ืืืื ืืึธื ืคึผืึทืจืึธื ืคึฟืื ืื ืึทืคึผืืึทืงืืืฉืึทื ืืืืฃ ืืืื ืืขืืขืคืึธื. ืืึธื ืืืจ ืืึทืงืืืขื ืึท positive ืขื ืืคืขืจ? ืึทืืื ืืืจ ืืึทื ืืืืฃ.
ืฉืจืื 4. ื ืึธื ืงืึทื ืคืืืืขืจืืืฉืึทื ืืื ืืขืกืืื ื ืคืื FreeRADIUS ืึธืคึผืขืจืึทืฆืืข
ืืื ืืื ืืขืจืืื ื ืืืืื, MultiOTP ืืื ืฉืืื ืงืึทื ืคืืืืขืจื ืฆื ืึทืจืืขืื ืืื FreeRADIUS, ืึทืืข ืืืึธืก ืืืืืื ืฆื ืืืืคื ืืขืกืฅ ืืื ืืืืื ืืื ืคึฟืึธืจืืึทืฆืืข ืืืขืื ืืื ืืืขืจ VPN ืืืืืืืื ืฆื ืื FreeRADIUS ืงืึทื ืคืืืืขืจืืืฉืึทื ืืขืงืข.
ืืืจ ืฆืืจืืงืงืืืขื ืฆื ืื ืกืขืจืืืขืจ ืงืึทื ืกืึธืื, ืฆื ืื ืืืขืืืืืึทืืขืจ /usr/local/bin/multiotp/, ืึทืจืืึทื:
./multiotp.php -config debug=1
./multiotp.php -config display-log=1
ืึทืจืืึทื ืืขืจืขืื ื ืืขืจ ืืืืืืื ืืึธืืื ื.
ืืื ืื FreeRADIUS ืงืืืืึทื ืฅ ืงืึทื ืคืืืืขืจืืืฉืึทื ืืขืงืข (/etc/freeradius/clinets.conf) ืืึทืืขืจืงื ืึทืืข ืฉืืจืืช ืฉืืึทืืืช ืฆื ืืึธืงืึทืืืึธืกื ืืื ืืืื ืฆืืืื ืืืื ืกื:
client localhost {
ipaddr = 127.0.0.1
secret = testing321
require_message_authenticator = no
}
- ืคึฟืึทืจ ืคึผืจืืืืจื
client 192.168.1.254/32 {
shortname = CiscoASA
secret = ConnectToRADIUSSecret
}
- ืคึฟืึทืจ ืืื ืืืขืจ VPN ืืืืืืืื.
ืจืืกืืึทืจื FreeRADIUS ืืื ืคึผืจืืืืจื ืฆื ืงืืึธืฅ ืืื:
radtest username 100110 localhost 1812 testing321
ืืื ื ืืืขื = ืืึทื ืืฆืขืจ ื ืึธืืขื, 100110 = ืคึผืึทืจืึธื ืืขืืขืื ืฆื ืืื ืื ืืืจื ืื ืึทืคึผืืึทืงืืืฉืึทื ืืืืฃ ืื ืืขืืขืคืึธื, ืืึธืงืึทืืืึธืกื = RADIUS ืกืขืจืืืขืจ ืึทืืจืขืก, 1812 - RADIUS ืกืขืจืืืขืจ ืคึผืึธืจื, testing321 - RADIUS ืกืขืจืืืขืจ ืงืืืขื ื ืคึผืึทืจืึธื (ืืืึธืก ืืืจ ืกืคึผืขืกืืคืืขื ืืื ืื ืงืึทื ืคืืืืขืจืืืฉืึทื).
ืืขืจ ืจืขืืืืืึทื ืคืื ืืขื ืืึทืคึฟืขื ืืืขื ืืืื ืจืขืืืืืึทื ืืขืขืจืขื ืืื ืืืื:
Sending Access-Request of id 44 to 127.0.0.1 port 1812
User-Name = "username"
User-Password = "100110"
NAS-IP-Address = 127.0.1.1
NAS-Port = 1812
Message-Authenticator = 0x00000000000000000000000000000000
rad_recv: Access-Accept packet from host 127.0.0.1 port 1812, id=44, length=20
ืืืฆื ืืืจ ืืึทืจืคึฟื ืฆื ืืึทืื ืืืืขืจ ืึทื ืืขืจ ืืึทื ืืฆืขืจ ืืื ืืฆืืื ืึธืืขื ืืึทืงืืืืึทื. ืฆื ืืึธื ืืึธืก, ืืืจ ืืืขืื ืงืืงื ืืื ืื ืืึธื ืคืื ืืืืืืึธืืคึผ ืืื:
tail /var/log/multiotp/multiotp.log
ืืื ืืืื ืื ืืขืฆืืข ืคึผืึธืืืฆืืข ืืื:
2016-09-01 08:58:17 notice username User OK: User username successfully logged in from 127.0.0.1
2016-09-01 08:58:17 debug Debug Debug: 0 OK: Token accepted from 127.0.0.1
ืืขืจื ืึธื ืึทืืฅ ืืื ืืื ืืื ืืืจ ืงืขื ืขื ืคืึทืจืขื ืืืงื
ืฉืจืื 5: ืงืึทื ืคืืืืขืจ Cisco ASA
ืืึธืืืจ ืฉืืืืขื ืึทื ืืืจ ืืึธืื ืฉืืื ืึท ืงืึทื ืคืืืืขืจื ืืจืืคึผืข ืืื ืคึผืึทืืึทืกืื ืคึฟืึทืจ ืึทืงืกืขืก ืืืจื SLL VPN, ืงืึทื ืคืืืืขืจื ืืื ืงืึทื ืืืฉืึทื ืืงืฉืึทื ืืื ืึทืงืืืื Directory, ืืื ืืืจ ืืึทืจืคึฟื ืฆื ืืืืื ืฆืืืื-ืคืึทืงืืึธืจ ืึธืืขื ืืึทืงืืืฉืึทื ืคึฟืึทืจ ืืขื ืคึผืจืึธืคืื.
1. ืืืื ืึท ื ืืึทืข AAA ืกืขืจืืืขืจ ืืจืืคึผืข:
2. ืืืื ืืื ืืืขืจ ืืืืืืึธืืคึผ ืกืขืจืืืขืจ ืฆื ืืขืจ ืืจืืคึผืข:
3. ืืืจ ืจืขืืึทืืืจื ืงืฉืจ ืคึผืจืึธืคืื, ืืึทืฉืืขืืืงื ืื ืึทืงืืืืืข Directory ืกืขืจืืืขืจ ืืจืืคึผืข ืืื ืื ืืืืคึผื ืึธืืขื ืืึทืงืืืฉืึทื ืกืขืจืืืขืจ:
4. ืืื ืื ืงืืืืื ืึทืืืึทื ืกืืจืืข -> ืึธืืขื ืืึทืงืืืฉืึทื ืืืจ ืืืื ืืืืกืงืืืึทืื ืื ืึทืงืืืืืข Directory ืกืขืจืืืขืจ ืืจืืคึผืข:
5. ืืื ืื ืงืืืืื ืึทืืืึทื ืกืืจืืข -> ืฆืืืืืืืง ืึธืืขื ืืึทืงืืืฉืึทื, ืืืืกืงืืืึทืื ืื ืืืฉืืคื ืกืขืจืืืขืจ ืืจืืคึผืข ืืื ืืืึธืก ืื ืืืืืืึธืืคึผ ืกืขืจืืืขืจ ืืื ืจืขืืืกืืจืืจื. ืืึทืืขืจืงืื ื ืึทื ืื ืกืขืกืืข ื ืืืขื ืืื ืื ืืขืจืึทืืื ืคืื ืื ืขืจืฉืืืง ืึทืึทืึท ืกืขืจืืืขืจ ืืจืืคึผืข:
ืฆืืืืืื ืื ืกืขืืืื ืืก ืืื
ืฉืจืื 6, ืืืื ืื ืืขืฆืืข
ืืึธืืืจ ืงืึธื ืืจืึธืืืจื ืืืื ืฆืืืื-ืคืึทืงืืึธืจ ืึธืืขื ืืึทืงืืืฉืึทื ืึทืจืืขื ืคึฟืึทืจ SLL VPN:
ืืืึธืืืึท! ืืืขื ืงืึทื ืขืงืืื ื ืืืจื Cisco AnyConnect VPN ืงืืืขื ื, ืืืจ ืืืขื ืืืื ืืืื ืืขืืขืื ืคึฟืึทืจ ืึท ืฆืืืืื ืืืื-ืฆืืึทื ืคึผืึทืจืึธื.
ืืื ืืึธืคึฟื ืึทื ืืขืจ ืึทืจืืืงื ืืืขื ืืขืืคึฟื ืขืืขืฆืขืจ, ืืื ืึทื ืขืก ืืืขื ืืขืื ืขืืขืฆืขืจ ืฆื ืืจืึทืืื ืืืขืื ืืื ืฆื ื ืืฆื ืืขื, ืคืจืื ืึธืืคึผ ืกืขืจืืืขืจ, ืคึฟืึทืจ ืื ืืขืจืข ืืึทืกืงืก. ืืึทื ืืืืื ืืื ืื ืืึทืืขืจืงืื ืืขื ืืืื ืืืจ ืืืืื.
ืืงืืจ: www.habr.com