
ãã®ããŒãã§ã¯ãPPTPãL2TPïŒIPsecã®æç¡ã«ãããããïŒãã¢ãã¬ã¹ããŒã«ãããŸããŸãªãŠãŒã¶ãŒã°ã«ãŒããLDAPããã³ããŒã«ã«ããŒã¿ããŒã¹ãããã°ã«ãŒããããã³WindowsãLinuxãOSXãIOSãAndroidã¯ã©ã€ã¢ã³ããããã³ããããã¹ãŠããªãŒãã³ãœãªã¥ãŒã·ã§ã³ã§ãµããŒãããåã
ã®ãŠãŒã¶ãŒã®äž¡æ¹ã®ã·ã§ãŒãã³ã°ã®ãªãã·ã§ã³æ§æã
PSãã®ããŒãã§ã¯ããããã¯ãŒã¯ã»ãã¥ãªãã£ã®åŽé¢ã¯åœ±é¿ãåããŸãããããã§ãªããã°ãå®è£
ã«åŸ®åŠãªãã¥ã¢ã³ã¹ã®ãã巚倧ãªããã¥ã¡ã³ãã«æé·ããŸããæ¬¡åãå¢çä¿è·ãšãããã¯ãŒã¯ã»ãã¥ãªãã£ã«ã€ããŠèª¬æããŸãã
èª°ãæ°ã«ããªããç«ãžããããã
ç®æ¬¡ïŒã¯ããã«ãµãŒããŒã§ã®æºåäœæ¥Accel-PPPïŒPPTPãL2TPïŒã¹ããã³ã°ã¹ã¯ã³ïŒIPsecïŒããªãŒååŸãµã³ã4ãã®çµæã次ã®ãããªãã®ãååŸããäºå®ã§ãã

ãããã¯ãŒã¯ã«ã¯ãã¢ãã€ã«ã¯ã©ã€ã¢ã³ãããªãã£ã¹ã¯ã©ã€ã¢ã³ããéèŠãªãµãŒãã¹ãåããå®å
šãªãããã¯ãŒã¯ããããVPNãä»ããŠã®ã¿ã¢ã¯ã»ã¹å¯èœã§ããå¿
èŠããããŸããäžæ¹ããªãã£ã¹ã¯ã©ã€ã¢ã³ããšã¢ãã€ã«ã¯ã©ã€ã¢ã³ãã¯ãVPNããç°ãªããµãããããåãåãããªãœãŒã¹ã«ã¢ã¯ã»ã¹ããããã®ç°ãªãæš©å©ãæã£ãŠããå¿
èŠããããŸãããããã«ããããªãã£ã¹ã®å€ããåããŠããäŒç€Ÿã®å
éšã€ã³ãã©ã¹ãã©ã¯ãã£ãžã®å®å
šãªã¢ã¯ã»ã¹æš©ãå¿
èŠãªç®¡çè
ããããã¯ãŒã¯äžã«ããŸãããã®ã¹ããŒã ã¯ããªãã£ã¹ã§äœ¿çšå¯èœãªãµãŒããŒãæã€å
éšãªãã£ã¹ãããã¯ãŒã¯ãã«ããŒããŸããã ããŒã«ã«ãããã³VPNçµç±ã®ã¢ãã€ã«ã¯ã©ã€ã¢ã³ãã
ãµãŒããŒã®ã»ããã¢ãããéå§ããŸãã
0ïŒæºåäœæ¥ã

VPNã®ã»ããã¢ããã«çŽæ¥é²ãåã«ãããã€ãã®æºåäœæ¥ãè¡ããŸãã
ãããŠãæå°éã®æ§æã§Debian 7ãã€ã³ã¹ããŒã«ããã°ããã®ãµãŒããŒããããŸãïŒåé¡ã§ã¯ãªããä»ã®Linuxã§ãåãããã«åäœããŸãïŒã sshãŸãã¯ããŒã«ã«ã³ã³ãœãŒã«ã§ãã°ã€ã³ããæ¬¡ã®æäœãè¡ããŸãã
æ£ããã¿ã€ã ãŸãŒã³ãèšå®ããŸãïŒãã®äŸã§ã¯MSKãé
眮ããŸãïŒ
mv /etc/localtime /etc/localtime_org && ln -s /usr/share/zoneinfo/"Europe/Moscow" /etc/localtime && date
ãã®ãµãŒããŒã§IPv6ã䜿çšããäºå®ããªãå Žåã¯ãIPv6ãç¡å¹ã«ããŸã
echo net.ipv6.conf.all.disable_ipv6=1 > /etc/sysctl.d/disableipv6.conf
ããã¯ããŒããã«ãã«æ¥ç¶ããŸãïŒå€ãã®åé¡ãæ±ããŠããå€ä»£ã®ãµã³ããšã¹ããã³ã°ã¹ã¯ã³ã眮ããªãããã«ïŒããã®ããã«
/etc/apt/sources.listã«æ¬¡ã®è¡ã远å ããŸãã
deb http://http.debian.net/debian wheezy-backports main contrib non-free deb http://mirror.yandex.ru/debian/ wheezy-backports main contrib non-free
ãã®æ®µéã§æäœéå¿
èŠãªããã±ãŒãžãã€ã³ã¹ããŒã«ãã
apt-get update apt-get install cmake make libssl-dev libpcre3-dev libnet-snmp-perl libtritonus-bin bzip2 checkinstall ntpdate
ãµãŒããŒã®æå»ãåæããŸãããã¡ã€ã³ã¯ããã¯ã䜿çšãããšããã«æ¹åãããŸããæãç°¡åãªãªãã·ã§ã³ã¯
ntpdate DC.DOMAIN.COM
/etc/resolv.confã§DNSãã¡ã€ã³ãµãŒããŒãæå®ããŸã
ãã¡ã€ã¢ãŠã©ãŒã«èšå®ã¯äŒç€Ÿåºæã®ãã®ã§ãããããã§ã¯å
¬éããŸããããããã«åºã¥ããŠãVPNã¯ã©ã€ã¢ã³ãã®ç°ãªããµãããããç°ãªãçŠæ¢ãšèš±å¯ã«ãã€ã³ãããŸãããããã
..1.99ã¯ããµãŒããŒã®å€éšIPã§ãã1ïŒAccel-PPP-L2TPããã³PPTPãæäœããããã®ã¡ã€ã³ãµãŒãã¹

ãããžã§ã¯ãã®ãŠã§ããµã€ãããã®èª¬æACCEL-PPPã¯ãLinuxçšã®é«æ§èœVPN / IPoEãµãŒããŒã§ãã
ä»ã®ãœãªã¥ãŒã·ã§ã³ã«å¯Ÿããå©ç¹ã¯ãäžè¬çãªããŸããŸãªVPNãã¯ãããžãŒãåäžã®ã¢ããªã±ãŒã·ã§ã³ã«çµã¿åãããŠããããšã§ãã
VPNãµãŒãã¹ãç·šæããããã®å€ãã®ãªãŒãã³ãœãªã¥ãŒã·ã§ã³ããããŸããããããã¯ãã¹ãŠ1çš®é¡ã®VPNã«çŠç¹ãåœãŠãŠããŸããPPTPã®ã¿ãPPPOEã®ã¿ãL2TPã®ã¿ã§ãã
ãã«ããµãŒãã¹VPNãµãŒããŒãèµ·åããå Žåã¯ãåã¢ããªã±ãŒã·ã§ã³ãåå¥ã«èª¿ã¹ãŠæ§æããå¿
èŠããããŸãã
ACCEL-PPPã䜿çšãããšãåäžã®æ§æãã¡ã€ã«ãçµ±åããã管çãšç£èŠã«ããããã¹ãŠããµããŒããã1ââã€ã®ã¢ããªã±ãŒã·ã§ã³ãååŸã§ããŸãã
...
ãããžã§ã¯ãã®è©³çްã«ã€ããŠã¯ã
ãã¡ããã芧ãã ãã ã
ãã®VPNã¯éåžžã«äžååã§ãããããã«ã€ããŠã®èšåã¯ãªããå€ããå°ãªããåãnagaãã©ã³ããäžå¿ã«è°è«ãããŠããŸããã䜿ãããããå®å®æ§ãæ©èœã®ç¹ã§ããäžè¬çãªãœãªã¥ãŒã·ã§ã³ããã€ãã¹ããŠããŸãããæè©ã§çµãããå§ããŸãããããµãŒããŒã«ããŠã³ããŒãããŠã¹ããŒããŸãã
http://downloads.sourceforge.net/project/accel-ppp/accel-ppp-1.9.0.tar.bz2
è§£åãã
tar -xjf accel-ppp-1.9.0.tar.bz2 mkdir accel-ppp-build cd accel-ppp-build
éãã
cmake -DBUILD_PPTP_DRIVER=FALSE -DLOG_PGSQL=FALSE -DNETSNMP=FALSE -DRADIUS=TRUE -DSHAPER=TRUE /root/accel-ppp-1.9.0/ make checkinstall -D
äŸããèªåå®è¡ã¹ã¯ãªãããäœæããŸãã
cd ../accel-ppp-1.9.0/contrib/debian cp accel-ppp-init /etc/init.d/accel-ppp
ããŒã¢ã³ã§ãã£ã¬ã¯ããªãå®çŸ©ãã
which accel-pppd
debã®å¯èœæ§ãæãé«ãã®ã¯ã
/ usr / local / sbin / accel-pppdã§ããéå§ãã¡ã€ã«ã§ããã¹ãäžèšã§ååŸãããã¹ã«å€æŽããŸãã
nano /etc/init.d/accel-ppp
èªåå®è¡ã«è¿œå
insserv -v accel-ppp
ãã°çšã®ãã£ã¬ã¯ããªãäœæãã
mkdir /var/log/accel-ppp/
æ¥ç¶ã確èªããããã®ã¢ã¯ã»ã¹
æš©ãæã€ãã¡ã€ã«ãäœæããŸãã
å°æ¥çã«ã¯ãRADIUSèªèšŒã«çœ®ãæããŸã touch /etc/ppp/chap-secrets
æžåŒïŒ
login * password ip _forçºè¡ïŒããŒã«ããååŸããå¿
èŠãããå Žåã¯ã*ã®ã¿ïŒ
æ§æãã¡ã€ã«
/etc/accel-ppp.confãäœæããŸã
å
容*ãã¹ãäžã«ãªãã·ã§ã³ã«ã€ããŠå¯èœãªéãã³ã¡ã³ãããããšããŸãã
ãchap-secretsã®ã³ã¡ã³ããå€ãã
ã¢ãžã¥ãŒã«ã»ã¯ã·ã§ã³ã®
ååŸãã³ã¡ã³ãã¢ãŠãããŸããã
[modules] path=/usr/local/lib64/accel-ppp
æã¡äžã
service accel-ppp start
äœãåé¡ãããå Žåã¯ãæ§æã®ãã°ã¬ãã«ãäžããŠãã°ã確èªããŸãã
è² è·ãããã£ãç¶æ
ã§äœæ¥ããã«ã¯ãå°ãã®ãã¥ãŒãã³ã°ãå¿
èŠã§ããVPNäžã«500æªæºã®åæã¯ã©ã€ã¢ã³ããããå Žåãã¢ã€ãã
net.ipv4.ip_forward = 1ãé€ãããããè¡ãããšãã§ããŸãã
/etc/sysctl.confã«è¿œå ããŸã###############################
net.ipv4.ip_forward = 1
net.ipv4.neigh.default.gc_thresh1 = 1024
net.ipv4.neigh.default.gc_thresh2 = 2048
net.ipv4.neigh.default.gc_thresh3 = 4096
net.ipv4.netfilter.ip_conntrack_max = 9548576
net.netfilter.nf_conntrack_max = 9548576
ïŒéžæçACKãšã¿ã€ã ã¹ã¿ã³ãããªãã«ãã
net.ipv4.tcp_sack = 0
net.ipv4.tcp_timestamps = 0
ïŒã¡ã¢ãªå²ãåœãŠæå°/å§å/æå€§
ïŒèªã¿åããããã¡ãæžã蟌ã¿ãããã¡ãããã³ãããã¡ã¹ããŒã¹
net.ipv4.tcp_rmem = 10,000,000 10,000,000 10,000,000
net.ipv4.tcp_wmem = 10,000,000 10,000,000 10,000,000
net.ipv4.tcp_mem = 10,000,000 10,000,000 10,000,000
net.core.rmem_max = 524287
net.core.wmem_max = 524287
net.core.rmem_default = 524287
net.core.wmem_default = 524287
net.core.optmem_max = 524287
net.core.netdev_max_backlog = 300000
net.core.netdev_tstamp_prequeue = 0
###############################
é©çšããŸãïŒ
sysctl -p
/ etc / ppp / chap-secretsã§æå®ããããŠãŒã¶ãŒåãšãã¹ã¯ãŒãã䜿çšããŠãIPsecãªãã§PPTPããã³L2TPã«æ¥ç¶ããããšããŸãã
ãµãŒããŒèªäœã§ã¯ãæ¥ç¶ãããŠããã¯ã©ã€ã¢ã³ãã®ãªã¹ããæ¬¡ã®ããã«è¡šç€ºã§ããŸãã
accel-cmd show session
accel-cmdã®ãã«ããèªãããšã匷ããå§ãããŸããããã«ã¯ãã»ãã·ã§ã³ãäžæããããšãªããŠãŒã¶ãŒèªèšŒæ¹æ³ããã®å Žã§å€æŽãããªã©ãå€ãã®æ©èœããããŸãã
ãã¹ãŠåé¡ãªããã°ã次ã®é
ç®ã«é²ã¿ãŸã
2ïŒIPsec

ãããäœã§ãããããªããããå¿
èŠãªã®ããç¥ãããã«ã
ããã«ç°¡å
ã«ã€ã³ã¹ããŒã«ãã
apt-get -t wheezy-backports install strongswan libcharon-extra-plugins
æ§æå¯èœ
nano /etc/ipsec.conf次ã«ãç§å¯éµãæå®ããŸã
nano /etc/ipsec.secrets: PSK "Sicret-Test-Key"
Freeradiusãšã®ãããªãçµ±åã®ããã«ãç·šéãè¡ããŸã
nano /etc/strongswan.d/charon/eap-radius.confeap-radius.conf eap-radius { accounting = yes load = yes nas_identifier = StrongSwan
æã¡äžã
service ipsec start
次ã®ãããªã¹ããŒã¿ã¹ã確èªã§ããŸãã
ipsec statusall
3ïŒFreeRadius
*ãããäœã§ããããç¥ããªã人ã®ããã«ãæšæºãšããŠã€ã³ã¹ããŒã«
apt-get install freeradius freeradius-ldap
FreeRadiusãŠãŒã¶ãŒã®èšå®ãå«ã
/etc/freeradius/clients.confãã¡ã€ã«ã
ä¿®æ£ããŸããããŒã«ã«Accel-PPPããã³StrongswanããŒã¢ã³ãããã以äžã®å
å®¹ã¯æå°éã§ãã
client localhost { ipaddr = 127.0.0.1 secret = Radius-Sicret nastype = cisco shortname = MY_TEST_VPN }
次ã«ãèµ·åçšã®ãããã¡ã€ã«ãæºåããŸããæšæºãããã¡ã€ã«ã¯ããã«ãããŸã
/ etc / freeradius /ãµã€ã察å¿/ããã©ã«ã
ãæ¬¡ã®åœ¢åŒã«ããå¿
èŠããããŸãã
/ etc / freeradius /ãµã€ã察å¿/ããã©ã«ã* LDAPãšã®çµ±åãèšå®ããããŸã§ãldapããã³ntlm_authã«é¢é£ãããã¹ãŠã®ãªãã·ã§ã³ãã³ã¡ã³ãåããŠããããããã®ãããããã³ã¡ã³ãè§£é€ããå¿
èŠããããŸãããäžåºŠã«äž¡æ¹ã§ã¯ãªããç«¶åããŸãããã®äŸã§ã¯ãäœæ¥èšå®ã«ã¯ãã§ã«ã°ã«ãŒããå«ãŸããŠããŸãã
authorize { preprocess chap mschap ldap
次ã«ãããŒã«ã«ãŠãŒã¶ãŒã®ãã¡ã€ã«ãšãLDAPããã®ããŸããŸãªã°ã«ãŒãã®èšå®ã®èª¬æãäœæããŸãã
/ etc / freeradius / users åèµ·åååŸ
service freeradius restart
*ãããã°ã®ããã«ã端æ«
freeradius -Xã§ãã°åºåã¢ãŒãã§å®è¡ã§ããŸã
ãã¹ãŠãæ£åžžã§ãèµ·åã«ãšã©ãŒããªãå Žåã¯ããã¹ããŠãŒã¶ãŒã確èªããŸãã
radtest testuser testpassword 127.0.0.1 0 Radius-Sicret
次ã®ãããªåçãåŸãããŸãã
Sending Access-Request of id 238 to 127.0.0.1 port 1812 User-Name = "testuser" User-Password = "testpassword" NAS-IP-Address = XX.YY.1.99 NAS-Port = 0 Message-Authenticator = 0x00000000000000000000000000000000 rad_recv: Access-Accept packet from host 127.0.0.1 port 1812, id=238, length=105 Service-Type = Framed-User Framed-Protocol = PPP Framed-IP-Address = 10.65.18.12 Framed-IP-Netmask = 255.255.255.255 Framed-Pool = "office" Filter-Id = "100000/100000" Reply-Message = "Accepted from local file"
åçã«
Access-Acceptãå«ãŸããŠããå Žåããã¹ãŠãæ£åžžã§ãããFreeradiusãšLDAPã®çµ±åã®æ§æã«é²ãããšãã§ããŸããäºåã«ãã®ã»ã¯ã·ã§ã³ã«æ§æãé
眮ããä¿®æ£ããå¿
èŠããããŸãã
nano / etc / freeradius / modules / ntlm_auth* KR.LOCã®ä»£ããã«ããã¡ã€ã³ã瀺ã
exec ntlm_auth { wait = yes program = "/usr/bin/ntlm_auth --request-nt-key --domain=KR.LOC --username=%{mschap:User-Name} --password=%{User-Password}" }
mschapãtkãä»ããŠå°ã調æŽããŸãã papã¯å®å
šã«äœ¿çšã§ããŸããã
nano / etc / freeradius / modules / mschap mschap {
ãããŠæãéèŠãªã®ã¯ãLDAPãšã®çŽæ¥çµ±å
nano / etc / freeradius / modules / ldapã«æžãã*ã¢ã¯ã»ã¹èšå®ãç¬èªã®ldapã«å€æŽããããšãå¿ããªãã§ãã ããããŠãŒã¶ãŒã¢ã«ãŠã³ãã«ã¯ããã¡ã€ã³å
ã®ãããã¡ã€ã«ãèªã¿åãæš©éãå¿
èŠã§ãã
ldap { server = "10.13.205.7"
å¥ã®éèŠãªç¹ã¯ãç¹å®ã®ãŠãŒã¶ãŒã®ååŸå±æ§ãldapãã¡ã€ã³å±æ§ããçŽæ¥ååŸããã«ã¯ãçžäºã®å¯Ÿå¿ãæ§æããå¿
èŠããããŸããããã¯
/etc/freeradius/ldap.attrmapãã¡ã€ã«ã§è¡ãããŸããç¬èªã®ããã€ãïŒ
replyItem Framed-IP-Address msRADIUSFramedIPAddress replyItem Framed-Pool msRADIUSFramedRoute
ãããã£ãŠããŠãŒã¶ãŒã®ãã¡ã€ã³ã§
msRADIUSFramedIPAddressåäººå±æ§ãæå®ãããšãååŸã転éããŠãããã
Framed-IP-Address屿§ã§ãããšèŠãªãã顿šã«ããããŒã«ã«ã€ããŠãVPNãä»ããŠãŠãŒã¶ãŒã«
æç€ºçã«çºè¡ããŸãã
ãã¡ã€ã³åŽããã¯ã次ã®ããã«ãªããŸãã

IPã¯
IPèšç®æ©ã§HEXã«å€æããå¿
èŠããããŸãããã¡ããã屿§ãšãã£ã¿ãŒã䜿çšããŠldapã®ä»»æã®å±æ§ãäœæã§ããŸããã説æãå éããããã«æšæºã®ãã®ã䜿çšããŸãã
*ãããã®ãªãã·ã§ã³ã¯samba4ã®èšå®åŸã«å©çšå¯èœã«ãªããŸãã/etc/freeradius/sites-enabled/defaultã®
ldapã»ã¯ã·ã§ã³ã®ã³ã¡ã³ããå¿ããªãã§ãã ããã
4ïŒSAMBA 4
*ã¯ã€ãã¯ãªãã¡ã¬ã³ã¹éå§ããã«ã¯ãå¿
èŠãªãã®ããã¹ãŠã€ã³ã¹ããŒã«ããŸãã
apt-get install krb5-user libpam-krb5 samba winbind libnss-winbind libpam-winbind -t wheezy-backports
Sambaã®èšå®ã¯/etc/samba/smb.confãã¡ã€ã«ã«ãããŸã
smb.conf*ãã¡ã€ã³åãèªåã®ãã®ã«å€æŽããããšãå¿ããªãã§ãã ããã
[global] obey pam restrictions = Yes log file = /var/log/samba/log.%m log level = 1 socket options = TCP_NODELAY SO_SNDBUF=8192 SO_RCVBUF=8192 encrypt passwords = yes idmap config * : range = 10000-20000 idmap config * : backend = tdb auth methods = winbind name resolve order = hosts bcast lmhosts case sensitive = no dns proxy = no netbios name = SAMBA server string = %v samba password server = DC02.KR.LOC
ããã§winbindãæ§æããŸãïŒSambaãADãŠãŒã¶ãŒãèªèããããŒã«ã«ãŠãŒã¶ãŒãšããŠéä¿¡ã§ããããã«ããŸãïŒã
ãã¡ã€ã«
/etc/nsswitch.confãç·šéããŠã远å ããå¿
èŠããããŸãã
passwd: compat winbind group: compat winbind shadow: compat winbind
Kerberosãæ§æããããã«æ®ããŸãïŒSambaãActive Directoryã«çµ±åããããã«äœ¿çšïŒ
ãã¡ã€ã«/etc/krb5.confããã©ãŒã ã«å
¥ããŸã
krb5.conf*ãã¡ã€ã³ãç¬èªã®ãã®ã«å€æŽããŸãã
[logging] default = FILE:/var/log/krb5.log kdc = FILE:/var/log/krb5kdc.log [libdefaults] default_realm = KR.LOC clockskew = 500 dns_lookup_realm = false dns_lookup_kdc = true ticket_lifetime = 324000 [realms] KR.LOC = { kdc = DC02.KR.LOC admin_server = DC02.KR.LOC default_domain = KR.LOC } [domain_realm] .kr.loc = KR.LOC [login] krb4_convert = true krb4_get_tickets = false
æ§æãä¿®æ£ããããµãŒãã¹ãåèµ·åã§ããŸãã
service samba restart service winbind restart
ãã¡ã€ã³ãŠãŒã¶ãŒã確èªããŸãã
kinit sf-test@KR.LOC
ãã¹ã¯ãŒãã®ãªã¯ãšã¹ããåãåããå
¥åããŸãã
Password for sf-test@KR.LOC:
ãã¹ãŠãåé¡ãªãå Žåãç»é¢ã«åºåã¯è¡šç€ºãããŸããããã¹ãŠã衚瀺ãããŠããå Žåã¯ãèšå®ã®ãšã©ãŒãæ³šææ·±ãèªãã§ä¿®æ£ããŠãã ããã
ç§ãã¡ã¯ãã¹ãŠãããªããšããŸããã£ãŠãããšä¿¡ããŠããã¡ã€ã³å
ã®ãµãŒããŒã«å
¥ããŸã
net join âU sf-test@KR.LOC
winbindã®åäœã確èªããŸãã
wbinfo -u wbinfo -g
åºåã«ã¯ããã¡ã€ã³ãŠãŒã¶ãŒãšã°ã«ãŒãã®ãªã¹ãã衚瀺ãããŸãã
ãã¡ã€ã³ãŠãŒã¶ãŒãããŒã«ã«ãšããŠèªèãããŠãããã©ããã確èªããã«ã¯ã次ã®ã³ãã³ãã䜿çšã§ããŸãã
id domain_user
èªèšŒã¢ãžã¥ãŒã«ã®åäœã確èªããŸãïŒãã°ã€ã³/ãã¹ã¯ãŒã/ãã¡ã€ã³-åœç¶ç§ãã¡ã®ãã®ïŒ
ntlm_auth --request-nt-key --domain=KR.LOC --username=sf-test --password=123456789
OKã«ãªã£ãã®ã§ãradius configã§ldapãŸãã¯ntlm_authã¢ãžã¥ãŒã«ã®ã³ã¡ã³ããè§£é€ãïŒãã¡ã€ã³ã°ã«ãŒããäžèŠãªå ŽåïŒãfreeradiusãåèµ·åãããã¡ã€ã³ã¢ã«ãŠã³ãã§VPNãµãŒããŒã®äœæ¥ã楜ããã§ãã ããã
radtest -t mschap sf-test 123456789 127.0.0.1 0 Radius-Sicret
ããã§ãèªå®
ã§VPNæ¥ç¶ãäœæããå
šäœã確èªã§ããŸãã
5ïŒããŒãã¹
ã¡ã¢ãã¹ã¯ããŒã«ããŠããããã¯ãŒã¯ãã€ã¢ã°ã©ã ãããäžåºŠèŠãŠãIPsecã®ãµã€ã鿥ç¶ãããããšãæãåºããŸãããVPNãŠãŒã¶ãŒãä»ã®ãããã¯ãŒã¯ã«ã¢ã¯ã»ã¹ããå¿
èŠãããå Žåã«ã䟿å©ã§ããããã¯ãã¹ãŠãã¡ã€ã¢ãŠã©ãŒã«ã«ãã£ãŠå®è£
ãããŸããããã®ããã®ã¹ããã³ã°ã¹ã¯ã³ã®èšå®äŸä»¥äžã«æ¥ç¶ã瀺ããŸãã
ipsec.conf/etc/ipsec.confã§ ãã»ã¯ã·ã§ã³ãæåŸã«è¿œå ããŸãã
conn juniper forceencaps=yes dpddelay=30
ãããã«
ãã¹ãŠãåããŠããŸããããããã§ãªããã°ããã«ããŸããã£ãããšãé¡ã£ãŠããŸã-ã³ã¡ã³ãã§è³ªåããŠãã ããã ééããã¿ã€ããã¹ããããŸããããŸãã¯ã¡ã¢ã®èªèã劚ããä»ã®ç¬éãèŠã€ããå Žåãèè
ã¯ç
çåŠçã«èªã¿æžããã§ããŸãããPMã§ãç¥ãããã ããã ãæéãããããšãããããŸããã