mikroik. IPSEC vpn ื”ื™ื ื˜ืขืจ NAT ื•ื•ื™ ืงืœื™ืขื ื˜

ื’ื•ื˜ืข ื˜ืึธื’ ืึทืœืขืžืขืŸ!

ืขืก ืคึผื•ื ืงื˜ ืึทื–ื•ื™ ื’ืขื˜ืจืืคืŸ ืึทื– ืื™ืŸ ืื•ื ื“ื–ืขืจ ืคื™ืจืžืข ืื™ืŸ ื“ื™ ืœืขืฆื˜ืข ืฆื•ื•ื™ื™ ื™ืึธืจ ืžื™ืจ ื”ืึธื‘ืŸ ืกืœืึธื•ืœื™ ืกื•ื•ื™ื˜ืฉื™ื ื’ ืฆื• ืžื™ืงืจืึธื˜ื™ืงืก. ื“ื™ ื”ื•ื™ืคึผื˜ ื ืึธื•ื“ื– ื–ืขื ืขืŸ ื’ืขื‘ื•ื™ื˜ ืื•ื™ืฃ CCR1072, ืื•ืŸ ื”ื™ื’ืข ืงืึทื ืขืงืฉืึทื ื– ืคึฟืึทืจ ืงืึธืžืคึผื™ื•ื˜ืขืจืก ืื•ื™ืฃ ื“ืขื•ื•ื™ืกืขืก ื–ืขื ืขืŸ ืกื™ืžืคึผืœืขืจ. ืคื•ืŸ ืงื•ืจืก, ืขืก ืื™ื– ืื•ื™ืš ืึท ืงืึธืžื‘ื™ื ืึทืฆื™ืข ืคื•ืŸ โ€‹โ€‹ื ืขื˜ื•ื•ืึธืจืงืก ื“ื•ืจืš ื“ื™ IPSEC ื˜ื•ื ืขืœ, ืื™ืŸ ื“ืขื ืคืึทืœ, ื“ื™ ืกืขื˜ืึทืคึผ ืื™ื– ื’ืึทื ืฅ ืคึผืฉื•ื˜ ืื•ืŸ ื˜ื•ื˜ ื ื™ืฉื˜ ื’ืจื•ื ื˜ ืงื™ื™ืŸ ืฉื•ื•ืขืจื™ืงื™ื™ื˜ืŸ, ื•ื•ื™ื™ึทืœ ืขืก ื–ืขื ืขืŸ ืึท ืคึผืœืึทืฅ ืคื•ืŸ ืžืึทื˜ืขืจื™ืึทืœืก ืื•ื™ืฃ ื“ื™ ื ืขืฅ. ืื‘ืขืจ ืขืก ื–ืขื ืขืŸ ื–ื™ื›ืขืจ ืฉื•ื•ืขืจื™ืงื™ื™ื˜ืŸ ืžื™ื˜ ื“ื™ ืจื™ืจืขื•ื•ื“ื™ืง ืคึฟืึทืจื‘ื™ื ื“ื•ื ื’ ืคื•ืŸ ืงืœื™ื™ืึทื ืฅ, ื“ืขืจ ืคืึทื‘ืจื™ืงืึทื ื˜ ืก ื•ื•ื™ืงื™ ื“ืขืจืฆื™ื™ืœื˜ ืื™ืจ ื•ื•ื™ ืฆื• ื ื•ืฆืŸ ื“ื™ Shrew soft VPN ืงืœื™ืขื ื˜ (ืึทืœืฅ ืžื™ื™ื ื˜ ืฆื• ื–ื™ื™ืŸ ืงืœืึธืจ ืžื™ื˜ ื“ืขื ื‘ืึทืฉื˜ืขื˜ื™ืงืŸ) ืื•ืŸ ื“ืึธืก ืื™ื– ื“ืขืจ ืงืœื™ืขื ื˜ ื•ื•ืึธืก ืื™ื– ื’ืขื ื™ืฆื˜ ื“ื•ืจืš 99% ืคื•ืŸ ื•ื•ื™ื™ึทื˜ ืึทืงืกืขืก ื ื™ืฆืขืจืก , ืื•ืŸ 1% ืื™ื– ืžื™ืจ, ืื™ืš ืื™ื– ื’ืขื•ื•ืขืŸ ืคึผื•ื ืงื˜ ืฆื• ืคื•ื™ืœ ื™ืขื“ืขืจ ื ืึธืจ ืึทืจื™ื™ึทืŸ ื“ื™ ืœืึธื’ื™ืŸ ืื•ืŸ ืคึผืึทืจืึธืœ ืื™ืŸ ื“ืขื ืงืœื™ืขื ื˜ ืื•ืŸ ืื™ืš ื’ืขื•ื•ืืœื˜ ืึท ืคื•ื™ืœ ืึธืจื˜ ืื•ื™ืฃ ื“ืขืจ ืงืึทื ืึทืคึผืข ืื•ืŸ ื‘ืึทืงื•ื•ืขื ืงืฉืจ ืฆื• ืึทืจื‘ืขื˜ ื ืขื˜ื•ื•ืึธืจืงืก. ืื™ืš ื”ืึธื‘ ื ื™ื˜ ื’ืขืคึฟื•ื ืขืŸ ืื™ื ืกื˜ืจื•ืงืฆื™ืขืก ืคึฟืึทืจ ืงืึทื ืคื™ื’ื™ืขืจื™ื ื’ ืžื™ืงืจืึธื˜ื™ืง ืคึฟืึทืจ ืกื™ื˜ื•ืึทื˜ื™ืึธื ืก ื•ื•ืขืŸ ืขืก ืื™ื– ื ื™ืฉื˜ ืึทืคึฟื™ืœื• ื”ื™ื ื˜ืขืจ ืึท ื’ืจื•ื™ ืึทื“ืจืขืก, ืึธื‘ืขืจ ื’ืึธืจ ื”ื™ื ื˜ืขืจ ืึท ืฉื•ื•ืึทืจืฅ ืื•ืŸ ืืคึฟืฉืจ ืืคื™ืœื• ืขื˜ืœืขื›ืข NATs ืื•ื™ืฃ ื“ื™ ื ืขืฅ. ื“ืขืจืคืืจ ื”ืื‘ ืื™ืš ื’ืขืžื•ื–ื˜ ืื™ืžืคืจืื•ื•ื™ื–ื™ืจืŸ, ืื•ืŸ ื“ืขืจืคืืจ ืœื™ื™ื’ ืื™ืš ืคืืจ ืฆื• ืงื•ืงืŸ ืื•ื™ืคืŸ ืจืขื–ื•ืœื˜ืื˜.

ื‘ื ื™ืžืฆื:

  1. CCR1072 ื•ื•ื™ ื”ื•ื™ืคึผื˜ ืžื™ื˜ืœ. ื•ื•ืขืจืกื™ืข 6.44.1
  2. CAP ac ื•ื•ื™ ื”ื™ื™ื ืงืฉืจ ืคื•ื ื˜. ื•ื•ืขืจืกื™ืข 6.44.1

ื“ืขืจ ื”ื•ื™ืคึผื˜ ืฉื˜ืจื™ืš ืคื•ืŸ ื“ื™ ื‘ืึทืฉื˜ืขื˜ื™ืงืŸ ืื™ื– ืึทื– ื“ื™ ืคึผื™ืกื™ ืื•ืŸ ืžื™ืงืจืึธื˜ื™ืง ืžื•ื–ืŸ ื–ื™ื™ืŸ ืื•ื™ืฃ ื“ืขืจ ื–ืขืœื‘ื™ืงืขืจ ื ืขืฅ ืžื™ื˜ ื“ืขืจ ื–ืขืœื‘ื™ืงืขืจ ืึทื“ืจืขืกื™ื ื’, ื•ื•ืึธืก ืื™ื– ืืจื•ื™ืก ื“ื•ืจืš ื“ื™ ื”ื•ื™ืคึผื˜ 1072.

ืœืึธืžื™ืจ ื’ื™ื™ืŸ ืฆื• ื“ื™ ืกืขื˜ื˜ื™ื ื’ืก:

1. ืคื•ืŸ ืงื•ืจืก, ืžื™ืจ ื•ื•ืขื ื“ืŸ ืื•ื™ืฃ ืคืึทืกื˜ื˜ืจืึทืงืง, ืึธื‘ืขืจ ื–ื™ื ื˜ ืคืึทืกื˜ื˜ืจืึทืงืง ืื™ื– ื ื™ืฉื˜ ืงืึทืžืคึผืึทื˜ืึทื‘ืึทืœ ืžื™ื˜ ื•ื•ืคึผืŸ, ืžื™ืจ ื”ืึธื‘ืŸ ืฆื• ืฉื ื™ื™ึทื“ืŸ ื–ื™ื™ึทืŸ ืคืึทืจืงืขืจ.

/ip firewall mangle
add action=mark-connection chain=forward comment="ipsec in" ipsec-policy=
    in,ipsec new-connection-mark=ipsec passthrough=yes
add action=mark-connection chain=forward comment="ipsec out" ipsec-policy=
    out,ipsec new-connection-mark=ipsec passthrough=yes
/ip firewall filter add action=fasttrack-connection chain=forward connection-mark=!ipsec

2. ืึทื“ื™ื ื’ ื ืขืฅ ืคืึธืจื•ื•ืขืจื“ื™ื ื’ ืคื•ืŸ / ืฆื• ืฉื˜ื•ื‘ ืื•ืŸ ืึทืจื‘ืขื˜

/ip firewall raw
add action=accept chain=prerouting dst-address=192.168.33.0/24 src-address=
    10.7.76.0/24
add action=accept chain=prerouting dst-address=192.168.33.0/24 src-address=
    10.7.98.0/24
add action=accept chain=prerouting disabled=yes dst-address=192.168.55.0/24 
    src-address=10.7.78.0/24
add action=accept chain=prerouting dst-address=10.7.76.0/24 src-address=
    192.168.33.0/24
add action=accept chain=prerouting dst-address=10.7.77.0/24 src-address=
    192.168.33.0/24
add action=accept chain=prerouting dst-address=10.7.98.0/24 src-address=
    192.168.33.0/24
add action=accept chain=prerouting disabled=yes dst-address=10.7.78.0/24 
    src-address=192.168.55.0/24
add action=accept chain=prerouting dst-address=192.168.33.0/24 src-address=
    10.7.77.0/24

3. ืฉืึทืคึฟืŸ ืึท ื‘ืึทื ื™ืฆืขืจ ืงืฉืจ ื‘ืึทืฉืจื™ื™ึทื‘ื•ื ื’

/ip ipsec identity
add auth-method=pre-shared-key-xauth notrack-chain=prerouting peer=CO secret=
    ะพะฑั‰ะธะน ะบะปัŽั‡ xauth-login=username xauth-password=password

4. ืฉืึทืคึฟืŸ ืึทืŸ IPSEC ืคืึธืจืฉืœืึธื’

/ip ipsec proposal
add enc-algorithms=3des lifetime=5m name="prop1" pfs-group=none

5. ืฉืึทืคึฟืŸ ืึทืŸ IPSEC ืคึผืึธืœื™ื˜ื™ืง

/ip ipsec policy
add dst-address=10.7.76.0/24 level=unique proposal="prop1" 
    sa-dst-address=<white IP 1072> sa-src-address=0.0.0.0 src-address=
    192.168.33.0/24 tunnel=yes
add dst-address=10.7.77.0/24 level=unique proposal="prop1" 
    sa-dst-address=<white IP 1072> sa-src-address=0.0.0.0 src-address=
    192.168.33.0/24 tunnel=yes

6. ืฉืึทืคึฟืŸ ืึท IPSEC ืคึผืจืึธืคื™ืœ

/ip ipsec profile
set [ find default=yes ] dpd-interval=disable-dpd enc-algorithm=
    aes-192,aes-128,3des nat-traversal=no
add dh-group=modp1024 enc-algorithm=aes-192,aes-128,3des name=profile_1
add name=profile_88
add dh-group=modp1024 lifetime=4h name=profile246

7. ืฉืึทืคึฟืŸ ืึท IPSEC ื™ื™ึทื ืงื•ืงื 

/ip ipsec peer
add address=<white IP 1072>/32 local-address=<ะฒะฐัˆ ะฐะดั€ะตั ั€ะพัƒั‚ะตั€ะฐ> name=CO profile=
    profile_88

ืื™ืฆื˜ ืคึฟืึทืจ ืขื˜ืœืขื›ืข ืคึผืฉื•ื˜ ืžืึทื’ื™ืฉ. ื–ื™ื ื˜ ืื™ืš ื”ืื˜ ื ื™ืฉื˜ ื˜ืึทืงืข ื•ื•ื™ืœืŸ ืฆื• ื˜ื•ื™ืฉืŸ ื“ื™ ืกืขื˜ื˜ื™ื ื’ืก ืื•ื™ืฃ ืึทืœืข ื“ืขื•ื•ื™ืกืขืก ืื•ื™ืฃ ืžื™ื™ืŸ ื”ื™ื™ื ื ืขืฅ, ืื™ืš ื’ืขื”ืื˜ ืฆื• ื”ืขื ื’ืขืŸ DHCP ืื•ื™ืฃ ื“ืขืจ ื–ืขืœื‘ื™ืงืขืจ ื ืขืฅ, ืึธื‘ืขืจ ืขืก ืื™ื– ื’ืœื™ื™ึทืš ืึทื– ืžื™ืงืจืึธื˜ื™ืง ืงืขืŸ ื ื™ืฉื˜ ืœืึธื–ืŸ ืื™ืจ ืฆื• ื”ืขื ื’ืขืŸ ืžืขืจ ื•ื•ื™ ืื™ื™ืŸ ืึทื“ืจืขืก ื‘ืขืงืŸ ืื•ื™ืฃ ืื™ื™ืŸ ื‘ืจื™ืง, ืึทื–ื•ื™ ืื™ืš ื’ืขืคึฟื•ื ืขืŸ ืึท ื•ื•ืึธืจืงืึทืจืึธื•ื ื“, ื ื™ื™ืžืœื™ ืคึฟืึทืจ ืึท ืœืึทืคึผื˜ืึทืคึผ, ืื™ืš ื ืึธืจ ื‘ืืฉืืคืŸ DHCP ื“ื™ื ื’ืขืŸ ืžื™ื˜ ืžืึทื ื•ืึทืœ ืคึผืึทืจืึทืžืขื˜ืขืจืก, ืื•ืŸ ื–ื™ื ื˜ ื ืขื˜ืžืึทืกืง, ื’ื™ื™ื˜ื•ื•ื™ื™ & dns ืื•ื™ืš ื”ืึธื‘ืŸ ืึธืคึผืฆื™ืข ื ื•ืžืขืจืŸ ืื™ืŸ DHCP, ืื™ืš ืกืคึผืขืฆื™ืคื™ืฆื™ืจื˜ ื–ื™ื™ ืžืึทื ื™ื•ืึทืœื™.

1.DHCP ืึธืคึผืฆื™ืขืก

/ip dhcp-server option
add code=3 name=option3-gateway value="'192.168.33.1'"
add code=1 name=option1-netmask value="'255.255.255.0'"
add code=6 name=option6-dns value="'8.8.8.8'"

2.DHCP ื“ื™ื ื’ืขืŸ

/ip dhcp-server lease
add address=192.168.33.4 dhcp-option=
    option1-netmask,option3-gateway,option6-dns mac-address=<MAC ะฐะดั€ะตั ะฝะพัƒั‚ะฑัƒะบะฐ>

ืื™ืŸ ื“ืขืจ ื–ืขืœื‘ื™ืงืขืจ ืฆื™ื™ื˜, ื‘ืึทืฉื˜ืขื˜ื™ืงืŸ 1072 ืื™ื– ืคึผืจืึทืงื˜ืึทืงืœื™ ื™ืงืขืจื“ื™ืง, ื ืึธืจ ื•ื•ืขืŸ ืื™ืจ ืึทืจื•ื™ืกื’ืขื‘ืŸ ืึทืŸ IP ืึทื“ืจืขืก ืฆื• ืึท ืงืœื™ืขื ื˜ ืื™ืŸ ื“ื™ ืกืขื˜ื˜ื™ื ื’ืก, ืขืก ืื™ื– ืื ื’ืขื•ื•ื™ื–ืŸ ืึทื– ื“ื™ IP ืึทื“ืจืขืก ืืจื™ื™ืŸ ืžืึทื ื™ื•ืึทืœื™ ืื•ืŸ ื ื™ืฉื˜ ืคึฟื•ืŸ ื“ื™ ื‘ืขืงืŸ ื–ืึธืœ ื–ื™ื™ืŸ ื’ืขื’ืขื‘ืŸ ืฆื• ืื™ื. ืคึฟืึทืจ ืจืขื’ื•ืœืขืจ ืคึผื™ืกื™ ืงืœื™ื™ืึทื ืฅ, ื“ื™ ืกื•ื‘ื ืขื˜ ืื™ื– ื“ื™ ื–ืขืœื‘ืข ื•ื•ื™ ื“ื™ ื•ื•ื™ืงื™ ืงืึทื ืคื™ื’ื™ืขืจื™ื™ืฉืึทืŸ 192.168.55.0/24.

ืึทื–ืึท ืึท ื‘ืึทืฉื˜ืขื˜ื™ืงืŸ ืึทืœืึทื•ื– ืื™ืจ ื ื™ืฉื˜ ืฆื• ืคืึทืจื‘ื™ื ื“ืŸ ืฆื• ื“ื™ ืคึผื™ืกื™ ื“ื•ืจืš ื“ืจื™ื˜-ืคึผืึทืจื˜ื™ื™ ื•ื•ื™ื™ื›ื•ื•ืืจื’, ืื•ืŸ ื“ืขืจ ื˜ื•ื ืขืœ ื–ื™ืš ืื™ื– ืื•ื™ืคื’ืขืฉื˜ืื ืขืŸ ื“ื•ืจืš ื“ื™ ืจืึทื•ื˜ืขืจ ื•ื•ื™ ื“ืืจืฃ. ื“ื™ ืžืึทืกืข ืคื•ืŸ โ€‹โ€‹ื“ื™ ืงืœื™ืขื ื˜ CAP ac ืื™ื– ื›ึผืžืขื˜ ืžื™ื ื™ืžืึทืœ, 8-11% ืื™ืŸ ืึท ื’ื™ื›ืงื™ื™ึทื˜ ืคื•ืŸ 9-10 ืžื‘ / s ืื™ืŸ ื“ืขื ื˜ื•ื ืขืœ.

ืึทืœืข ืกืขื˜ื˜ื™ื ื’ืก ื–ืขื ืขืŸ ื’ืขืžืื›ื˜ ื“ื•ืจืš Winbox, ื›ืึธื˜ืฉ ืžื™ื˜ ื“ืขืจ ื–ืขืœื‘ื™ืงืขืจ ื”ืฆืœื—ื” ืขืก ืงืขื ืขืŸ ื–ื™ื™ืŸ ื’ืขื˜ืืŸ ื“ื•ืจืš ื“ื™ ืงืึทื ืกืึธื•ืœ.

ืžืงื•ืจ: www.habr.com

ืœื™ื™ื’ืŸ ืึท ื‘ืึทืžืขืจืงื•ื ื’