ืžืขืœื“ื•ื ื’ ืคื•ืŸ OpenIKED 7.2, ืึท ืคึผืึธืจื˜ืึทื˜ื™ื•ื• ื™ืžืคึผืœืึทืžืขื ื˜ื™ื™ืฉืึทืŸ ืคื•ืŸ ื“ื™ IKEv2 ืคึผืจืึธื˜ืึธืงืึธืœ ืคึฟืึทืจ IPsec

ื“ื™ OpenBSD Project ื”ืื˜ ืึทื ืึทื•ื ืกื˜ ื“ื™ ืžืขืœื“ื•ื ื’ ืคื•ืŸ OpenIKED 7.2, ืึทืŸ ื™ืžืคึผืœืึทืžืขื ื˜ื™ื™ืฉืึทืŸ ืคื•ืŸ ื“ื™ IKEv2 ืคึผืจืึธื˜ืึธืงืึธืœ ื“ืขื•ื•ืขืœืึธืคึผืขื“ ื“ื•ืจืš ื“ื™ OpenBSD Project. ื“ืึธืก ืื™ื– ื“ืขืจ ืคืขืจื˜ ืžืขืœื“ื•ื ื’ ืคื•ืŸ OpenIKED ื•ื•ื™ ืึท ื‘ืึทื–ื•ื ื“ืขืจ ืคึผืจื•ื™ืขืงื˜ - ื“ื™ IKEv2 ืงืึทืžืคึผืึธื•ื ืึทื ืฅ ื–ืขื ืขืŸ ืขืจื™ื“ื–ืฉื ืึทืœื™ ืึท ื™ื ื˜ืึทื’ืจืึทืœ ื˜ื™ื™ืœ ืคื•ืŸ ื“ื™ OpenBSD IPsec ืึธื ืœื™ื™ื’ืŸ, ืึธื‘ืขืจ ื–ืขื ืขืŸ ื“ืขืžืึธืœื˜ ืืคื’ืขืฉื™ื™ื“ื˜ ืื™ืŸ ืึท ื‘ืึทื–ื•ื ื“ืขืจ ืคึผืึธืจื˜ืึทื˜ื™ื•ื• ืคึผืขืงืœ ืื•ืŸ ืงืขื ืขืŸ ืื™ืฆื˜ ื–ื™ื™ืŸ ื’ืขื•ื•ื™ื™ื ื˜ ืื•ื™ืฃ ืื ื“ืขืจืข ืึธืคึผืขืจื™ื™ื˜ื™ื ื’ ืกื™ืกื˜ืขืžืขืŸ. OpenIKED ืื™ื– ื˜ืขืกื˜ืขื“ ืื•ื™ืฃ FreeBSD, NetBSD, macOS ืื•ืŸ ืคืึทืจืฉื™ื“ืŸ ืœื™ื ื•ืงืก ื“ื™ืกื˜ืจื™ื‘ื™ื•ืฉืึทื ื– ืึทืจื™ื™ึทื ื’ืขืจืขื›ื ื˜ ืึทืจื˜ืฉ, ื“ืขื‘ื™ืึทืŸ, ืคืขื“ืึธืจืึท ืื•ืŸ ื•ื‘ื•ื ื˜ื•. ื“ืขืจ ืงืึธื“ ืื™ื– ื’ืขืฉืจื™ื‘ืŸ ืื™ืŸ C ืื•ืŸ ืื™ื– ืคื•ื ืื ื“ืขืจื’ืขื˜ื™ื™ืœื˜ ืื•ื ื˜ืขืจ ื“ื™ ISC ื“ืขืจืœื•ื™ื‘ืขื ื™ืฉ.

OpenIKED ืึทืœืึทื•ื– ืื™ืจ ืฆื• ืฆืขื•ื•ื™ืงืœืขืŸ IPsec-ื‘ืื–ื™ืจื˜ ื•ื•ื™ืจื˜ื•ืึทืœ ืคึผืจื™ื•ื•ืึทื˜ ื ืขื˜ื•ื•ืึธืจืงืก. ื“ื™ IPsec ืึธื ืœื™ื™ื’ืŸ ืื™ื– ืงืึทืžืคึผืจื™ื™ื–ื“ ืคื•ืŸ ืฆื•ื•ื™ื™ ื”ื•ื™ืคึผื˜ ืคึผืจืึธื˜ืึธืงืึธืœืก: ื“ื™ Key Exchange Protocol (IKE) ืื•ืŸ ื“ื™ Encrypted Transport Protocol (ESP). OpenIKED ื™ืžืคึผืœืึทืžืึทื ืฅ ืขืœืขืžืขื ื˜ืŸ ืคื•ืŸ ืึธื˜ืขื ื˜ืึทืงื™ื™ืฉืึทืŸ, ืงืึทื ืคื™ื’ื™ืขืจื™ื™ืฉืึทืŸ, ืฉืœื™ืกืœ ื•ื•ืขืงืกืœ ืื•ืŸ ื•ื™ืฉืึทืœื˜ ืคื•ืŸ ื–ื™ื›ืขืจื”ื™ื™ื˜ ืคึผืึธืœื™ื˜ื™ืง, ืื•ืŸ ื“ืขืจ ืคึผืจืึธื˜ืึธืงืึธืœ ืคึฟืึทืจ ืขื ืงืจื™ืคึผื˜ื™ื ื’ ESP ืคืึทืจืงืขืจ ืื™ื– ื˜ื™ืคึผื™ืงืœื™ ืฆื•ื’ืขืฉื˜ืขืœื˜ ื“ื•ืจืš ื“ื™ ืึธืคึผืขืจื™ื™ื˜ื™ื ื’ ืกื™ืกื˜ืขื ืงืขืจืŸ. ืึธื˜ืขื ื˜ืึทืงื™ื™ืฉืึทืŸ ืžืขื˜ื”ืึธื“ืก ืื™ืŸ OpenIKED ืงืขื ืขืŸ ื ื•ืฆืŸ ืคืึทืจ-ืฉืขืจื“ ืฉืœื™ืกืœืขืŸ, EAP MSCHAPv2 ืžื™ื˜ ืึทืŸ X.509 ื‘ืึทื•ื•ื™ื™ึทื–ืŸ, ืื•ืŸ RSA ืื•ืŸ ECDSA ืขืคื ื˜ืœืขืš ืฉืœื™ืกืœืขืŸ.

ืื™ืŸ ื“ื™ ื ื™ื™ึทืข ื•ื•ืขืจืกื™ืข:

  • ืฆื•ื’ืขืœื™ื™ื’ื˜ ืงืึธื•ื ื˜ืขืจืก ืžื™ื˜ ืกื˜ืึทื˜ื™ืกื˜ื™ืง ืคื•ืŸ ื“ื™ Iked ื”ื™ื ื˜ืขืจื’ืจื•ื ื˜ ืคึผืจืึธืฆืขืก, ื•ื•ืึธืก ืงืขื ืขืŸ ื–ื™ื™ืŸ ื•ื•ื™ื•ื“ ืžื™ื˜ ื“ื™ ื‘ืึทืคึฟืขืœ 'ikectl show stats'.
  • ื“ื™ ืคื™ื™ื™ืงื™ื™ื˜ ืฆื• ืฉื™ืงืŸ ื‘ืึทื•ื•ื™ื™ึทื–ืŸ ืงื™ื™ื˜ืŸ ืฆื• ืงื™ื™ืคืœ CERT ืคึผื™ื™ืœืึธื•ื“ื– ืื™ื– ืฆื•ื’ืขืฉื˜ืขืœื˜.
  • ืฆื• ืคึฟืึทืจื‘ืขืกืขืจืŸ ืงืึทืžืคึผืึทื˜ืึทื‘ื™ืœืึทื˜ื™ ืžื™ื˜ ืขืœื˜ืขืจืข ื•ื•ืขืจืกื™ืขืก, ืึท ืคึผื™ื™ืœืึธื•ื“ ืžื™ื˜ ืึท ืคืึทืจืงื•ื™ืคืขืจ ืฉื™ื™ึทืŸ ืื™ื– ืฆื•ื’ืขื’ืขื‘ืŸ.
  • ื™ืžืคึผืจื•ื•ื•ื“ ื–ื•ื›ืŸ ืคึฟืึทืจ ื›ึผืœืœื™ื ื’ืขื ื•ืžืขืŸ ืื™ืŸ ื—ืฉื‘ื•ืŸ ื“ื™ srcnat ืคืึทืจืžืึธื’.
  • ืึทืจื‘ืขื˜ ืžื™ื˜ NAT-T ืื™ืŸ ืœื™ื ื•ืงืก ืื™ื– ื’ืขื’ืจื™ื ื“ืขื˜.

ืžืงื•ืจ: opennet.ru

ืœื™ื™ื’ืŸ ืึท ื‘ืึทืžืขืจืงื•ื ื’