ืืืืข ืืึธื ืึทืืขืืขื!
ืขืก ืืจืขืคื ืืื ืื ืืื ืืื ืืืขืจ ืคืืจืืข, ืืืื ืืืจ ืืืกืืขืืืืืื ืืจืืืขืจืืขืืื ืืขื ืฆื ืืืงืจืืืืง ืืฉืืคืก ืืืืขืจ ืื ืืขืฆืืข ืฆืืืื ืืืจ. ืื ืืืืคื ื ืึธืืื ืืขื ืขื ืืขืืืื ืืืืฃ CCR1072, ืืฉืขืช ืืืงืืืข ืงืืืคืืืืขืจ ืงืื ืขืงืฉืื ืคืื ืงืื ืืขื ืขื ืืืืฃ ืคืฉืืืขืจืข ืืขืืืืืกืขืก. ื ืืืืจืืขื, ืืืจ ืคืึธืจืฉืืึธืื ืืืื ื ืขืฅ ืืื ืืขืืจืึทืฆืืข ืืืจื IPSEC ืืื ืขืื; ืืื ืืขื ืคืึทื, ืืื ืื ืกืขืืึทืคึผ ืืึทื ืฅ ืคึผืฉืื ืืื ืืืืื, ืืึทื ืง ืื ืืจืืืกืข ืฆืึธื ืจืขืกืืจืกื ืืืึธืก ืืขื ืขื ืคืึทืจืึทื ืึธื ืืืื. ืึธืืขืจ, ืืึธืืื ืงืืืขื ื ืงืื ืขืงืฉืื ืก ืฉืืขืื ืคืืจ ืืขืืืืกืข ืฉืืืขืจืืงืืืื; ืื ืืืืงื ืคืื ืขื ืคืึทืืจืืงืึทื ื ืืขืจืงืืขืจื ืืื ืฆื ื ืืฆื Shrew ืืืืืืืืืจื. ืืืคึผื ืงืืืขื ื (ืื ืกืขืืึทืคึผ ืืืื ื ืืื ืืขืืืกื-ืคืึทืจืฉืืขื ืืืขื), ืืื ืืึธืก ืืื ืืขืจ ืงืืืขื ื ืืืึธืก ืืืขืจื ืืขื ืืฆื ืืืจื 99% ืคืื ืืืืึทื ืึทืงืกืขืก ืืึทื ืืฆืขืจ, ืืื ืื ืืืืขืจืืงืข 1% ืืื ืืื. ืืื ืืึธื ืคืฉืื ื ืืฉื ืืขืืึทื ืงืืื ืืขืืืื ืฆื ืึทืจืืึทื ืฉืจืืึทืื ืืืื ืืึธืืื ืืื ืคึผืึทืจืึธื ืืขืืขืก ืืึธื, ืืื ืืื ืืึธื ืืขืืืึธืื ืึท ืืขืจ ืจืืืึทืงืกื, ืืขืจ ืืึทืงืืืขื ืงืึทืืืฉ ืคึผืึธืืขืืืึธ ืืขืจืคืึทืจืื ื ืืื ืืึทืงืืืขืืข ืงืึทื ืขืงืฉืึทื ื ืฆื ืึทืจืืขื ื ืขืืืืึธืจืงืก. ืืื ืงืขื ื ืืฉื ืืขืคึฟืื ืขื ืงืืื ืืื ืกืืจืืงืฆืืขืก ืคึฟืึทืจ ืงืึธื ืคืืืืจืืจื ืืืงืจืึธืืืง ืคึฟืึทืจ ืกืืืืึทืฆืืขืก ืืืึผ ืขืก ืืื ืืืื ื ืื ืึทืคึฟืืื ืืื ืืขืจ ืึท ืคึผืจืืืืึทื ืึทืืจืขืก, ืึธืืขืจ ืืื ืืขืจ ืึท ืืึธืจ ืฉืืืึทืจืฆืืืกืืขื ืืืื ืขืจ, ืืื ืืคึฟืฉืจ ืืคืืื ืืื ืงืืืคื NATs ืืืืฃ ืื ื ืขืืืืึธืจืง. ืึทืืื ืืื ืืึธื ืืขืืึทืจืคื ืืืคึผืจืึทืืืืืืจื, ืืื ืืื ืคึฟืึธืจืฉืืึธืื ืืืจ ื ืขืืขื ืึท ืงืืง ืืืืฃ ืื ืจืขืืืืืึทืื.
ืื ืืืฆื:
- CCR1072 ืืื ืืืืคึผื ืืืื. ืืืขืจืกืืข 6.44.1
- CAP ac ืืื ืืืื ืงืฉืจ ืคืื ื. ืืืขืจืกืืข 6.44.1
ืืขืจ ืืืืคึผื ืฉืืจืื ืคืื ืื ืืึทืฉืืขืืืงื ืืื ืึทื ืื ืคึผืืกื ืืื ืืืงืจืึธืืืง ืืืื ืืืื ืืืืฃ ืืขืจ ืืขืืืืงืขืจ ื ืขืฅ ืืื ืืขืจ ืืขืืืืงืขืจ ืึทืืจืขืกืื ื, ืืืึธืก ืืื ืืจืืืก ืืืจื ืื ืืืืคึผื 1072.
ืืึธืืืจ ืืืื ืฆื ืื ืกืขืืืื ืืก:
1. ืคืื ืงืืจืก, ืืืจ ืืืขื ืื ืืืืฃ ืคืึทืกืืืจืึทืงืง, ืึธืืขืจ ืืื ื ืคืึทืกืืืจืึทืงืง ืืื ื ืืฉื ืงืึทืืคึผืึทืืึทืืึทื ืืื ืืืคึผื, ืืืจ ืืึธืื ืฆื ืฉื ืืึทืื ืืืึทื ืคืึทืจืงืขืจ.
/ip firewall mangle
add action=mark-connection chain=forward comment="ipsec in" ipsec-policy=
in,ipsec new-connection-mark=ipsec passthrough=yes
add action=mark-connection chain=forward comment="ipsec out" ipsec-policy=
out,ipsec new-connection-mark=ipsec passthrough=yes
/ip firewall filter add action=fasttrack-connection chain=forward connection-mark=!ipsec
2. ืึทืืื ื ื ืขืฅ ืคืึธืจืืืขืจืืื ื ืคืื / ืฆื ืฉืืื ืืื ืึทืจืืขื
/ip firewall raw
add action=accept chain=prerouting dst-address=192.168.33.0/24 src-address=
10.7.76.0/24
add action=accept chain=prerouting dst-address=192.168.33.0/24 src-address=
10.7.98.0/24
add action=accept chain=prerouting disabled=yes dst-address=192.168.55.0/24
src-address=10.7.78.0/24
add action=accept chain=prerouting dst-address=10.7.76.0/24 src-address=
192.168.33.0/24
add action=accept chain=prerouting dst-address=10.7.77.0/24 src-address=
192.168.33.0/24
add action=accept chain=prerouting dst-address=10.7.98.0/24 src-address=
192.168.33.0/24
add action=accept chain=prerouting disabled=yes dst-address=10.7.78.0/24
src-address=192.168.55.0/24
add action=accept chain=prerouting dst-address=192.168.33.0/24 src-address=
10.7.77.0/24
3. ืฉืึทืคึฟื ืึท ืืึทื ืืฆืขืจ ืงืฉืจ ืืึทืฉืจืืึทืืื ื
/ip ipsec identity
add auth-method=pre-shared-key-xauth notrack-chain=prerouting peer=CO secret=
ะพะฑัะธะน ะบะปัั xauth-login=username xauth-password=password
4. ืฉืึทืคึฟื ืึทื IPSEC ืคืึธืจืฉืืึธื
/ip ipsec proposal
add enc-algorithms=3des lifetime=5m name="prop1" pfs-group=none
5. ืฉืึทืคึฟื ืึทื IPSEC ืคึผืึธืืืืืง
/ip ipsec policy
add dst-address=10.7.76.0/24 level=unique proposal="prop1"
sa-dst-address=<white IP 1072> sa-src-address=0.0.0.0 src-address=
192.168.33.0/24 tunnel=yes
add dst-address=10.7.77.0/24 level=unique proposal="prop1"
sa-dst-address=<white IP 1072> sa-src-address=0.0.0.0 src-address=
192.168.33.0/24 tunnel=yes
6. ืฉืึทืคึฟื ืึท IPSEC ืคึผืจืึธืคืื
/ip ipsec profile
set [ find default=yes ] dpd-interval=disable-dpd enc-algorithm=
aes-192,aes-128,3des nat-traversal=no
add dh-group=modp1024 enc-algorithm=aes-192,aes-128,3des name=profile_1
add name=profile_88
add dh-group=modp1024 lifetime=4h name=profile246
7. ืฉืึทืคึฟื ืึท IPSEC ืืึทื ืงืืงื
/ip ipsec peer
add address=<white IP 1072>/32 local-address=<ะฒะฐั ะฐะดัะตั ัะพััะตัะฐ> name=CO profile=
profile_88
ืืืฆื ืคึฟืึทืจ ืขืืืขืืข ืคึผืฉืื ืืึทืืืฉ. ืืื ื ืืื ืืื ื ืืฉื ืืึทืงืข ืืืืื ืฆื ืืืืฉื ืื ืกืขืืืื ืืก ืืืืฃ ืึทืืข ืืขืืืืกืขืก ืืืืฃ ืืืื ืืืื ื ืขืฅ, ืืื ืืขืืื ืฆื ืืขื ืืขื DHCP ืืืืฃ ืืขืจ ืืขืืืืงืขืจ ื ืขืฅ, ืึธืืขืจ ืขืก ืืื ืืืืึทื ืึทื ืืืงืจืึธืืืง ืงืขื ื ืืฉื ืืึธืื ืืืจ ืฆื ืืขื ืืขื ืืขืจ ืืื ืืืื ืึทืืจืขืก ืืขืงื ืืืืฃ ืืืื ืืจืืง, ืึทืืื ืืื ืืขืคึฟืื ืขื ืึท ืืืึธืจืงืึทืจืึธืื ื, ื ืืืืื ืคึฟืึทืจ ืึท ืืึทืคึผืืึทืคึผ, ืืื ื ืึธืจ ืืืฉืืคื DHCP ืืื ืืขื ืืื ืืึทื ืืึทื ืคึผืึทืจืึทืืขืืขืจืก, ืืื ืืื ื ื ืขืืืึทืกืง, ืืืืืืืื & dns ืืืื ืืึธืื ืึธืคึผืฆืืข ื ืืืขืจื ืืื DHCP, ืืื ืกืคึผืขืฆืืคืืฆืืจื ืืื ืืึทื ืืืึทืื.
1.DHCP ืึธืคึผืฆืืขืก
/ip dhcp-server option
add code=3 name=option3-gateway value="'192.168.33.1'"
add code=1 name=option1-netmask value="'255.255.255.0'"
add code=6 name=option6-dns value="'8.8.8.8'"
2.DHCP ืืื ืืขื
/ip dhcp-server lease
add address=192.168.33.4 dhcp-option=
option1-netmask,option3-gateway,option6-dns mac-address=<MAC ะฐะดัะตั ะฝะพััะฑัะบะฐ>
ืืื ืืขืจ ืืขืืืืงืขืจ ืฆืืื, ืืึทืฉืืขืืืงื 1072 ืืื ืคึผืจืึทืงืืึทืงืื ืืงืขืจืืืง, ื ืึธืจ ืืืขื ืืืจ ืึทืจืืืกืืขืื ืึทื IP ืึทืืจืขืก ืฆื ืึท ืงืืืขื ื ืืื ืื ืกืขืืืื ืืก, ืขืก ืืื ืื ืืขืืืืื ืึทื ืื IP ืึทืืจืขืก ืืจืืื ืืึทื ืืืึทืื ืืื ื ืืฉื ืคึฟืื ืื ืืขืงื ืืึธื ืืืื ืืขืืขืื ืฆื ืืื. ืคึฟืึทืจ ืจืขืืืืขืจ ืคึผืืกื ืงืืืืึทื ืฅ, ืื ืกืืื ืขื ืืื ืื ืืขืืืข ืืื ืื ืืืืงื ืงืึทื ืคืืืืขืจืืืฉืึทื 192.168.55.0/24.
ืึทืืึท ืึท ืืึทืฉืืขืืืงื ืึทืืึทืื ืืืจ ื ืืฉื ืฆื ืคืึทืจืืื ืื ืฆื ืื ืคึผืืกื ืืืจื ืืจืื-ืคึผืึทืจืืื ืืืืืืืืืจื, ืืื ืืขืจ ืืื ืขื ืืื ืืื ืืืืคืืขืฉืืื ืขื ืืืจื ืื ืจืึทืืืขืจ ืืื ืืืจืฃ. ืื ืืึทืกืข ืคืื โโืื ืงืืืขื ื CAP ac ืืื ืึผืืขื ืืื ืืืึทื, 8-11% ืืื ืึท ืืืืงืืึทื ืคืื 9-10 ืื / s ืืื ืืขื ืืื ืขื.
ืึทืืข ืกืขืืืื ืืก ืืขื ืขื ืืขืืืื ืืืจื Winbox, ืืึธืืฉ ืืื ืืขืจ ืืขืืืืงืขืจ ืืฆืืื ืขืก ืงืขื ืขื ืืืื ืืขืืื ืืืจื ืื ืงืึทื ืกืึธืื.
ืืงืืจ: www.habr.com
