Router

Configurare ruta statica router Mikrotik

Avem un router Mikrotik cu sistem de operare RouterOS

Vrem sa configuram un vpn site to site si o ruta statica catre cealalta locatie.

Pentru exemplul nostru vom folosi clasa 192.168.0.0/24 pentru locatia curenta si 192.168.2.0/24 pentru locatia remote.

Ambele locatii au acces la internet direct de la provider. IP extern locatie curenta 10.0.0.1/24 cu gateway 10.0.0.254

IP extern locatie remote 10.0.2.1/24 cu gateway 10.0.2.254

In cazul nostru interfata lan va fi ether2 si interfata wan ether3

[mai mult...]

Cum se poate realiza un VPN folosind tunel ssh

In general VPN permite accesul securizat (criptat si cu parola) din internet in reteaua locala. Sau poate unii doua retele locale prin intermediul retelei publice de internet, cu criptarea transferului prin reteaua publica.

Incepand cu versiunea 4.3 de ssh acesta include optiunea de a crea “Virtual Private Networks” via interfata tun. Un bun tutorial este aici:

https://help.ubuntu.com/community/SSH_VPN

 

 

    +---------------+            OpenSSH 4.3           +---------------+
    |   Machine A   | tun0 -- Tunnel Interface -- tun0 |   Machine B   |
    |  Has a tunnel | <------------------------------->|  Has a tunnel |  
    |  and ethernet | 10.0.0.100            10.0.0.200 |  and ethernet |
    +-------+-------+     point to point connection    +-------+-------+
       eth0 |                 creates a bridge                 | eth0  
 10.0.0.100 |               that plugs machine B               | 192.168.0.100
   port 22  |                  into network A                  |          
  forwarded |                                                  |
    here    |                                                  |
    +-------+-------+          +-~-~-~-~-~-~-~-+       +-------+-------+ 
    |   Network A   |          |               |       |   Network B   |
    |  10.0.0.1/24  | 1.2.3.4  |  The Internet |       | 192.168.0.1/24|
    |  Has internet |<-------->|               |<----->|  Has internet |
    |  NAT gateway  | Routable |               |       |  NAT gateway  |
    +---------------+ Address  +-~-~-~-~-~-~-~-+       +---------------+

 

 

[mai mult...]