43
Linux Advanced Routing & Traffic Control HOWTO (1) 2006. 5.30 ์„ฑ ์„ฑ ์„ฑ iceboy98@hufs.ac.kr

Linux Advanced Routing & Traffic Control HOWTO (1)

  • Upload
    betsy

  • View
    130

  • Download
    0

Embed Size (px)

DESCRIPTION

Linux Advanced Routing & Traffic Control HOWTO (1). 2006. 5.30 ์„ฑ ๋ฐฑ ๋™ iceboy98 @hufs.ac.kr. Contents. Introduction Exploring your current configuration Rules-routing policy database GRE and other tunnels IPSEC : secure IP over the Internet Multicast routing. introduction. - PowerPoint PPT Presentation

Citation preview

Page 1: Linux Advanced Routing & Traffic  Control HOWTO (1)

Linux Advanced Routing & Traffic Control HOWTO (1)

2006. 5.30์„ฑ ๋ฐฑ ๋™

[email protected]

Page 2: Linux Advanced Routing & Traffic  Control HOWTO (1)

2

Contents

Introduction Exploring your current configuration Rules-routing policy database GRE and other tunnels IPSEC : secure IP over the Internet Multicast routing

Page 3: Linux Advanced Routing & Traffic  Control HOWTO (1)

3

introduction

๋ฆฌ๋ˆ…์Šค 2.2/2.4 ๊ธฐ๋ฐ˜ ๋ฆฌ๋ˆ…์Šค , ์œ ๋‹‰์Šค ์‹œ์Šคํ…œ์€ arp, ifconfig,route ๋ช…๋ น์–ด๋ฅผ

์‚ฌ์šฉ ์ปค๋„ 2.2 ์ดํ›„ ๋ฆฌ๋ˆ…์Šค์—์„œ๋Š” ์˜๋„ํ•˜์ง€ ์•Š์€ ๋™์ž‘์„ ๋ณด์ธ๋‹ค .

GRE ํ„ฐ๋„์€ ๋ผ์šฐํŒ…์„ ๊ตฌ์„ฑํ•˜๋Š” ํ•œ ๋ถ€๋ถ€์ด์ง€๋งŒ ์™„๋ฒฝํžˆ ๋‹ค๋ฅธ ๋„๊ตฌ๋ฅผ ํ•„์š”๋กœ ํ•œ๋‹ค .

Iproute2 ๋ฆฌ๋ˆ…์Šค๋Š” ํŠธ๋ž˜ํ”ฝ ์ œ์–ด๋ผ ๋ถ€๋ฅด๋Š” ๋งค์šฐ ์ •๊ตํ•œ ๋Œ€์—ญํญ ์‹œ์Šคํ…œ์„

๊ฐ€์ง ๋Œ€์—ญํญ ๋ถ„๋ฅ˜ , ์šฐ์„ ๊ถŒ ์ œ๊ณต , ๋ถ„๋ฐฐ , ํŠธ๋ž˜ํ”ฝ ์ œํ•œ์ด ๊ฐ€๋Šฅ

Page 4: Linux Advanced Routing & Traffic  Control HOWTO (1)

4

ํ…Œ์ŠคํŠธ ํ™˜๊ฒฝ

eth0192.168.4.3

eth0192.168.4.2

eth0192.168.4.1

eth1220.67.124.144 eth0

192.168.4.4

Page 5: Linux Advanced Routing & Traffic  Control HOWTO (1)

5

Exploring your current configuration

Ip shows us our links Link โ€“ network device

ip shows us our IP addresses

Page 6: Linux Advanced Routing & Traffic  Control HOWTO (1)

6

Exploring your current configuration

ip shows us our routes

Page 7: Linux Advanced Routing & Traffic  Control HOWTO (1)

7

Exploring your current configuration

ARP(Address Resolution Protocol) ์ฃผ์†Œ๊ฒฐ์ • ํ”„๋กœํ† ์ฝœ ๋„คํŠธ์›Œํฌ์— ์—ฐ๊ฒฐ๋œ ์ปดํ“จํ„ฐ๊ฐ€ ๊ฐ™์€ ์ง€์—ญ ๋„คํŠธ์›Œํฌ์— ์กด์žฌํ•˜๋Š”

๋‹ค๋ฅธ ์ปดํ“จํ„ฐ์˜ ํ•˜๋“œ์›จ์–ด ์œ„์น˜ / ์ฃผ์†Œ๋ฅผ ์•Œ์•„๋‚ด๋Š”๋ฐ ์‚ฌ์šฉ

ARP cache entry

Page 8: Linux Advanced Routing & Traffic  Control HOWTO (1)

8

Chap 4. Rules-routing policy database

IP RULE rule in routing policy database. Control the route selection algorithm. Classic rouing algorithm ์€ ํŒจํ‚ท ์˜ destination address ์„

๊ธฐ๋ฐ˜์œผ๋กœ ๋ผ์šฐํŒ…์„ ๊ฒฐ์ • . ๋‹ค์–‘ํ•œ ๋ฐฉ๋ฒ•์œผ๋กœ ๋ผ์šฐํŒ…์„ ๊ฒฐ์ •ํ•  ์ˆ˜ ์žˆ๋„๋ก ํ•˜๊ธฐ ์œ„ํ•ด์„œ

Policy routing rule ์€ selector ์™€ action predicate ๋กœ ๊ตฌ์„ฑ . ๊ฐ selector ๋Š” source address, destination address, incoming

interface, tos, fwmark ๋ฅผ ์ ์šฉํ•œ๋‹ค . Selector ์— ๋งž๋Š” ํŒจํ‚ท์ด ์žˆ๋‹ค๋ฉด ํ•ด๋‹นํ•˜๋Š” action ์„ ์ˆ˜ํ–‰ํ•œ๋‹ค .

Default rule

priority selector action

Lookup routing table local

reserved

The normal routing table containing all non-policy routes.

Page 9: Linux Advanced Routing & Traffic  Control HOWTO (1)

9

Simple source policy routing

local table

Main table

์ƒˆ๋กœ์šด Rule ์ƒ์„ฑ

Page 10: Linux Advanced Routing & Traffic  Control HOWTO (1)

10

Routing for multiple uplinks/providers

์ง€์—ญ ๋„คํŠธ์›Œํฌ๋ฅผ ์ธํ„ฐ๋„ท์— ์—ฐ๊ฒฐํ•˜๋Š”๋ฐ ์‚ฌ์—…์ž๊ฐ€ ๋‘๊ฐœ ์ผ ๋•Œ ์‚ฌ์šฉ๋˜๋Š” ์„ค์ • Split access Load balancing

Content Provider

Content Provider

์ง€์—ญ๋ง ์ธํ„ฐ๋„ท

Page 11: Linux Advanced Routing & Traffic  Control HOWTO (1)

11

Split Access

ํŠน์ • ์„œ๋น„์Šค ์ œ๊ณต์ž๋ฅผ ํ†ตํ•ด์„œ ํŒจํ‚ท์ด ์˜จ ๊ฒฝ์šฐ ๊ฐ™์€ ์„œ๋น„์Šค ์ œ๊ณต์ž๋ฅผ ํ†ตํ•ด ์‘๋‹ตํ•ด์•ผ ํ•œ๋‹ค .

๊ฒฝ๋กœ ์„ค์ • ์˜ˆ์ œ(IF โ€“ ์ธํ„ฐํŽ˜์ด์Šค , IP- IF ์— ํ• ๋‹น๋œ IP ์ฃผ์†Œ , P โ€“ Provider ์˜ gateway IP address , P-NET โ€“ P ์— ์žˆ๋Š” IP ๋„คํŠธ์›Œํฌ , T โ€“ routing table)

ip route add $P1_NET dev $IF1 src $IP1 table T1 ip route add default via $P1 table T1 ip route add $P2_NET dev $IF2 src $IP2 table T2 ip route add default via $P2 table T2

Gateway ๋กœ ๊ฐ€๋Š” ๊ฒฝ๋กœ๋ฅผ ํ•˜๋‚˜ ๋งŒ๋“ค๊ณ  gateway ๋ฅผ ํ†ตํ•ด ๊ธฐ๋ณธ ๊ฒฝ๋กœ๋ฅผ ์„ค์ •ํ•œ๋‹ค .

Page 12: Linux Advanced Routing & Traffic  Control HOWTO (1)

12

Split Access

Main routing table ์„ค์ • ์ธํ„ฐํŽ˜์ด์Šค์— ์—ฐ๊ฒฐ๋œ ์ด์›ƒ์—๊ฒŒ ์ง์ ‘ ๋ผ์šฐํŒ… โ€˜srcโ€™ ์ธ์ˆ˜ ์‚ฌ์šฉ ๋‚˜๊ฐ€๋Š” IP ์ฃผ์†Œ ์ง€์ •

ip route add $P1_NET dev $IF1 src $IP1 ip route add $P2_NET dev $IF2 src $IP2

๊ธฐ๋ณธ ๋ผ์šฐํŒ… ๊ฒฝ๋กœ ์„ค์ • Ip route add default via $P1

Routing rule ์„ค์ • ip rule add from $IP1 table T1 ip rule add from $IP2 table T2

Page 13: Linux Advanced Routing & Traffic  Control HOWTO (1)

13

Load balancing

๋‘ ์„œ๋น„์Šค ์ œ๊ณต์ž๋ฅผ ํ†ตํ•ด ๋‚˜๊ฐ€๋Š” ํ๋ฆ„์˜ ์–‘์„ ์กฐ์ ˆํ•˜๋Š” ๋ฐฉ๋ฒ• ํ•˜๋‚˜๋ฅผ ๊ธฐ๋ณธ ๊ฒฝ๋กœ๋กœ ์„ค์ •ํ•˜๋Š” ๋Œ€์‹  ๊ธฐ๋ณธ ๊ฒฝ๋กœ๋ฅผ ๋‹ค์ค‘ ๊ฒฝ๋กœ๋กœ

์ง€์ • Ip route add default scpe global nexthop via $P1 dev $IF1 weight

nexthop via $P2 dev $IF2 weight 1 Weight ์ธ์ˆ˜๋Š” ์„ ํ˜ธํ•˜๋Š” provider ๋กœ ์กฐ์ • ๊ฐ€๋Šฅ Load balancing ์€ route ๋ฅผ ๊ธฐ๋ฐ˜์œผ๋กœ ํ•˜๊ณ  route ๋“ค์ด ์บ์‹œ๋˜๊ธฐ

๋•Œ๋ฌธ์— ๋ถˆ์™„์ „ํ•˜๋‹ค . ๋งŒ์•ฝ ์ž์ฃผ ๋ฐฉ๋ฌธํ•˜๋Š” ์‚ฌ์ดํŠธ๋Š” ํ•ญ์ƒ ๊ฐ™์€ provider ๋ฅผ ํ†ตํ•ด์„œ๋งŒ ์—ฐ๊ฒฐ ๋  ์ˆ˜๋„ ์žˆ๋‹ค .

Page 14: Linux Advanced Routing & Traffic  Control HOWTO (1)

14

Chap 5. GRE and other tunnels

๋ฆฌ๋ˆ…์Šค ํ„ฐ๋„ IP in IP ํ„ฐ๋„๋ง GRE ํ„ฐ๋„๋ง ์ปค๋„ ์™ธ๋ถ€์˜ ํ„ฐ๋„ (PPTP[point-to-point tunneling protocol] ์™€ ์œ 

์‚ฌ )

ํ„ฐ๋„๋ง์˜ ํŠน์ง• ๊ฐ„์ ‘ ๋น„์šฉ ์ฆ๊ฐ€

IP ํ—ค๋”๊ฐ€ ์ถ”๊ฐ€ โ€“ ํŒจํ‚ท๋‹น 20 ๋ฐ”์ดํŠธ MTU ๊ฐ€ 1500 ๋ฐ”์ดํŠธ์ผ๋•Œ ํ„ฐ๋„์„ ํ†ต๊ณผํ•  ์ˆ˜ ์žˆ๋Š” ํŒจํ‚ท์€ 1480

๋ฐ”์ดํŠธ๊ฐ€ ํ•œ๊ณ„ ํ„ฐ๋„์„ ๋งŒ๋“œ๋Š”๋ฐ ๊ฐ€์žฅ ๋น ๋ฅธ ๋ฐฉ๋ฒ•์€ ์–‘์ชฝ์„ ํŒŒ๋ฉด ๋œ๋‹ค .

Page 15: Linux Advanced Routing & Traffic  Control HOWTO (1)

15

IP in IP tunneling

๋ฆฌ๋ˆ…์Šค์—์„œ ์˜ค๋ž˜์ „ ๋ถ€ํ„ฐ ์ง€์› ์ปค๋„ ๋ชจ๋“ˆ ํ•„์š”

Ipip.o, new_tunnel.o

IP-in-IP ํ„ฐ๋„์„ ํ†ตํ•ด์„œ IPv6 ๋‚˜ broadcast ํŠธ๋ž˜ํ”ฝ์„ ํฌ์›Œ๋”ฉํ•  ์ˆ˜ ์—†๋‹ค .

๋ฆฌ๋ˆ…์Šค์˜ IP-in-IP ํ„ฐ๋„๋ง์€ ๋‹ค๋ฅธ ์šด์˜์ฒด์ œ๋‚˜ ๋ผ์šฐํ„ฐ์™€ ๊ฐ™์ด ์‚ฌ์šฉํ•  ์ˆ˜ ์—†๋‹ค .

Page 16: Linux Advanced Routing & Traffic  Control HOWTO (1)

16

IP in IP tunneling

ํ…Œ์ŠคํŠธ ํ™˜๊ฒฝ

๋„คํŠธ์›Œํฌ C ์— ๋Œ€ํ•ด์„œ๋Š” ๋„คํŠธ์›Œํฌ A ์™€ B ์˜ ํŒจํ‚ท๋“ค์„ ์„œ๋กœ๊ฐ„์— ์ „๋‹ฌํ•ด์ค€๋‹ค .

๋„คํŠธ์›Œํฌ B

Network 10.0.1.0

Netmask 255.255.255.0

Router 10.0.1.1

Network 10.0.2.0

Netmask 255.255.255.0

Router 10.0.2.1172.16.17.18 172.19.20.21

๋„คํŠธ์›Œํฌ A ๋„คํŠธ์›Œํฌ C

10.0.1.1

10.0.2.1

Page 17: Linux Advanced Routing & Traffic  Control HOWTO (1)

17

IP in IP tunneling

๋ชจ๋“ˆ ์„ค์น˜Insmod ipip.o ipip.ko

Insmod new_tunnel.o ----- fedora4 ์—์„œ๋Š” ์—†๋Š” ๋ชจ๋“ˆ .

๋„คํŠธ์›Œํฌ A ์˜ ๋ผ์šฐํ„ฐIfconfig tun10 10.0.1.1 pointopoint 172.19.20.21

Route add โ€“net 10.0.2.0 netmask 255.255.255.0 dev tun10

๋„คํŠธ์›Œํฌ B ์˜ ๋ผ์šฐํ„ฐIfconfig tun10 10.0.2.1 pointopoint 172.16.17.18

Route add โ€“net 10.0.1.0 netmask 255.255.255.0 dev tun 10

ํ„ฐ๋„์„ ๋๋‚ด๋ ค๋ฉดIfconfig tun10 down

Page 18: Linux Advanced Routing & Traffic  Control HOWTO (1)

18

GRE tunneling

Cisco ์—์„œ ๊ฐœ๋ฐœํ•œ ํ„ฐ๋„๋ง ํ”„๋กœํ† ์ฝœ

๋ฉ€ํ‹ฐ์บ์ŠคํŠธ๋‚˜ IPv6 ์ฒ˜๋ฆฌ ๊ฐ€๋Šฅ ๋ชจ๋“ˆ ํ•„์š”

ip_gre.o IPv4 ํ„ฐ๋„๋ง

๋„คํŠธ์›Œํฌ B

Network 10.0.1.0

Netmask 255.255.255.0

Router 10.0.1.1

Network 10.0.2.0

Netmask 255.255.255.0

Router 10.0.2.1172.16.17.18 172.19.20.21

neta netb

๋„คํŠธ์›Œํฌ A ๋„คํŠธ์›Œํฌ C

10.0.1.1

10.0.2.1

Page 19: Linux Advanced Routing & Traffic  Control HOWTO (1)

19

IPv4 ํ„ฐ๋„๋ง

๋„คํŠธ์›Œํฌ A ์˜ ๋ผ์šฐํ„ฐ ์„ค์ •

Netb ๋ผ๋Š” ํ„ฐ๋„ ์žฅ์น˜ ์ถ”๊ฐ€ , GRE ํ”„๋กœํ† ์ฝœ์„ ์‚ฌ์šฉ , ์›๊ฒฉ์ง€ ์ฃผ์†Œ 172.19.20.21 , ํ„ฐ๋„์„ ์ง€๋‚˜๋Š” ํŒจํ‚ท์ด 172.16.17.18 ์—์„œ ์ถœ๋ฐœ

์žฅ์น˜ ํ™œ์„ฑํ™” ์ƒˆ๋กœ์šด netb ์— ์ฃผ์†Œ๋ฅผ 10.0.1.1 ๋กœ ์ง€์ •

ํ„ฐ๋„๋ง ์žฅ์น˜๋ฅผ ์œ„ํ•ด ๋‹ค๋ฅธ IP ๋Œ€์—ญ์„ ์‚ฌ์šฉํ•˜๋Š” ๊ฒƒ์„ ์ƒ๊ฐํ•ด ๋ณผ ์ˆ˜ ์žˆ๋‹ค .

๋„คํŠธ์›Œํฌ B ๋กœ ๊ฐ€๋Š” ๊ฒฝ๋กœ ์ง€์ •

Page 20: Linux Advanced Routing & Traffic  Control HOWTO (1)

20

IPv4 ํ„ฐ๋„๋ง

๋„คํŠธ์›Œํฌ B ์˜ ๋ผ์šฐํ„ฐ ์„ค์ •

๋ผ์šฐํ„ฐ A ์—์„œ ํ„ฐ๋„์„ ์—†์•จ ๋•Œ

Page 21: Linux Advanced Routing & Traffic  Control HOWTO (1)

21

IPv4 ํ„ฐ๋„๋ง

Page 22: Linux Advanced Routing & Traffic  Control HOWTO (1)

22

IPv6 Tunneling

๋‹ค์Œ๊ณผ ๊ฐ™์€ IPv6 newtork ์ด ์žˆ๊ณ  , 6bone ์— ์—ฐ๊ฒฐํ•˜๋ ค๋ฉด ??

๋„คํŠธ์›Œํฌ์˜ IPv4 ์ฃผ์†Œ๋Š” 172.16.17.18 ์ด๊ณ  , 6bone ๋ผ์šฐํ„ฐ์˜ IPv4 ์ฃผ์†Œ๋Š” 172.22.23.24

IPv4

IPv6

Page 23: Linux Advanced Routing & Traffic  Control HOWTO (1)

23

Chap 6. IPv4 tunneling with Cisco and/or 6bone

IPv6 Tunneling IPv6 address have Some rules

์ฒ˜์Œ์— ์˜ค๋Š” 0 ์„ ์“ฐ์ง€ ์•Š๋Š”๋‹ค . 16 ๋น„ํŠธ or ๋‘ ๋ฐ”์ดํŠธ๋ฅผ ๋‚˜์šฐ๊ธฐ ์œ„ํ•ด ์ฝœ๋ก  ์‚ฌ์šฉ ์—ฐ์†์ ์ธ 0 ์„ ๊ฐ€์ง€๋ฉด :: ์„ ์“ธ ์ˆ˜ ์žˆ๋‹ค . ์ฃผ์†Œ์—์„œ ์˜ค์ง ํ•œ๋ฒˆ๋งŒ ์“ฐ๊ณ  , ์ ์–ด๋„ 16 ๋น„ํŠธ ์ด์ƒ์ด ๋˜์–ด์•ผ ํ•œ๋‹ค .

2002:836b:9820:0000:0000:0000:836b:9886

2002:836b:9820::836b:9886

IPv6 ๋„คํŠธ์›Œํฌ์€ ์ด๋ฏธ ์žˆ๋Š” IPv4 ์ธํ”„๋ผ๋ฅผ ํ†ตํ•ด IPv6 ํ”„๋กœํ† ์ฝœ์„ IPv4 ํŒจํ‚ท์— ์‹ธ์„œ ๋ณด๋‚ด๋Š” ์‹์œผ๋กœ ์—ฐ๊ฒฐํ•œ๋‹ค .

Page 24: Linux Advanced Routing & Traffic  Control HOWTO (1)

24

IPv6 Tunneling

IPv4 address โ€“ 144.100.24.181 6bone ๋ผ์šฐํ„ฐ IPv4 address โ€“ 145.100.1.5

IP forwaring ์„ ์œ„ํ•ด์„œ

IPv6 ๋ฅผ ์œ„ํ•œ router advertisement daemon

Page 25: Linux Advanced Routing & Traffic  Control HOWTO (1)

25

IPSEC : secure IP over the Internet

IPSec(IP Security) IP ๋ ˆ์ด์–ด์—์„œ์˜ ํŒจํ‚ท ๊ตํ™˜์ด ์•ˆ์ „ํ•˜๊ฒŒ ์ด๋ฃจ์–ด ์งˆ ์ˆ˜ ์žˆ๋„๋ก

ํ•˜๊ธฐ ์œ„ํ•˜์—ฌ IETF ์—์„œ ๊ฐœ๋ฐœํ•œ ํ”„๋กœํ† ์ฝœ ๊ฐ€์ƒ์ ์ธ ์ „์šฉํšŒ์„ ์„ ๊ตฌ์ถ• ์‚ฌ์šฉ์ž ์ธก ๋‹จ๋ง๊ธฐ์— ํƒ‘์žฌ , ์ธํ„ฐ๋„ท์„ ๊ฑฐ์ณ ํŠน์ • ํด๋ผ์ด์–ธํŠธ์™€

์„œ๋ฒ„๋งŒ์ด IPSec ์œผ๋กœ ๋ฐ์ดํ„ฐ๋ฅผ ์ฃผ๊ณ  ๋ฐ›์„ ์ˆ˜ ์žˆ๋‹ค IPSec ์˜ ์ฃผ์š” ์žฅ์ 

Transparency IPSec ์€ network layer ์—์„œ ๋™์ž‘ํ•˜๋ฏ€๋กœ , application ๊ณผ๋Š” ๋ฌด๊ด€ํ•˜๊ฒŒ

๋™์ž‘ Network Topology ์˜์กด์„ฑ์ด ์—†๋‹ค

TCP/IP ํ”„๋กœํ† ์ฝœ์„ ์‚ฌ์šฉํ•˜๋ฏ€๋กœ Ethernet, TokenRing, PPP ๋“ฑ ๋ชจ๋“  network topology ์— ์‚ฌ์šฉ ๊ฐ€๋Šฅ .

ํ‘œ์ค€ํ™” ํ‘œ์ค€ํ™”๋œ tunneling, authentication, encryption ๋ฐฉ๋ฒ•์„ ์‚ฌ์šฉํ•œ๋‹ค .

Multiprotocol IPSec ์€ tunneling mode ๋ฅผ ์‚ฌ์šฉํ•  ๊ฒฝ์šฐ ์—ฌ๋Ÿฌ ํ”„๋กœํ† ์ฝœ๊ณผ๋„ ๋™์ž‘ํ•  ์ˆ˜

์žˆ๋‹ค .

Page 26: Linux Advanced Routing & Traffic  Control HOWTO (1)

26

IPSEC : secure IP over the Internet

IPSec operation mode ์ „์†ก๋ชจ๋“œ

IP payload ๋งŒ encrypt. IP Header ๋Š” ๋ณด์ „๋˜๋ฏ€๋กœ public network ์ƒ์˜ ๋ชจ๋“  ์žฅ๋น„๊ฐ€ ํ•ด๋‹น

ํŒจํ‚ท์˜ ์ตœ์ข… destination ์„ ์•Œ ์ˆ˜ ์žˆ๋‹ค . Clear ํ•œ ์ƒํƒœ์˜ IP Header ๋กœ ์ธํ•ด attacker ์˜ ํŠธ๋ž˜ํ”ฝ ๋ถ„์„ ๊ฐ€๋Šฅ ๊ฐ endpoint ๊ฐ€ IPSec ๋ฅผ ์ดํ•ด

ํ„ฐ๋„๋ชจ๋“œ ๋ชจ๋“  ์ดˆ๊ธฐ์˜ datagram ์ด encrypt, ์ƒˆ๋กœ์šด IP packet ์˜ header ๊ฐ€

๋งŒ๋“ค์–ด์ง ๋ผ์šฐํ„ฐ์™€ ๊ฐ™์€ ์žฅ๋น„๊ฐ€ IPSec Proxy ๋กœ ๋™์ž‘ ๊ฐ€๋Šฅ Source ์˜ ๋ผ์šฐํ„ฐ๊ฐ€ IPSec tunnel ์„ ํ†ตํ•ด์„œ ํŒจํ‚ท์„ encrypt ํ•˜์—ฌ

forward Destination ๋ผ์šฐํ„ฐ๋Š” ์ดˆ๊ธฐ IP ํŒจํ‚ท์„ decrypt ํ•ด์„œ ์ตœ์ข… ๋ชฉ์ ์ง€๋กœ

forward

์ „์ฒด ํŒจํ‚ท์„ encript. ์‹ค์งˆ์ ์ธ source ์™€ destination ์€ ๋…ธ์ถœ๋˜์ง€ ์•Š์Œ

Page 27: Linux Advanced Routing & Traffic  Control HOWTO (1)

27

IPSEC : secure IP over the Internet

IPSec components IPSec ์€ 2 ๊ฐœ์˜ protocol โ€“ AH, ESP ๋กœ ๊ตฌ์„ฑ

AH โ€“ authentication ๊ณผ data integrity ๋ฅผ ์œ„ํ•ด ๋™์ž‘ ESP โ€“ confidentiality ๋ฅผ ์œ„ํ•ด ์„œ๋น„์Šค

Database ์— ์ €์žฅ๋˜์–ด ์žˆ๋Š” policy โ€“ SPD(Security Policy Database)

System manager ์— ์˜ํ•ด ๋ณ€๊ฒฝ ๊ฐ€๋Šฅ IKE ํ”„๋กœํ† ์ฝœ์€ ์•”ํ˜ธํ™” ํ‚ค์˜ ๊ด€๋ฆฌ์— ์‚ฌ์šฉ

Page 28: Linux Advanced Routing & Traffic  Control HOWTO (1)

28

IPSec components

SAD(Security Association Database) SA ๋Š” IPSec ์„ ์‚ฌ์šฉํ•˜๋Š” ๋‘ peer ๊ฐ„์˜ ํ˜‘์•ฝ์„ ์˜๋ฏธ

Peer ๊ฐ„์— ์‚ฌ์šฉ๋˜๋Š” ์•”ํ˜ธํ™” ์•Œ๊ณ ๋ฆฌ์ฆ˜ ์‚ฌ์šฉ๋˜๋Š” key SA life time ์ตœ๋Œ€ ์ „์†ก byte ๋ฅผ ์ •์˜

์„ค์ • ๋ฐฉ๋ฒ•์€ manual ๊ณผ automatic

SPD(Security Policy Database) System manager ์— ์˜ํ•ด ์ •์˜ Traffic ์— ๋Œ€ํ•˜์—ฌ security ์„œ๋น„์Šค๊ฐ€ ์‚ฌ์šฉ๋˜์–ด์•ผ ํ•  ์ง€ ์ •์˜ .

Page 29: Linux Advanced Routing & Traffic  Control HOWTO (1)

29

IPSec components

AH(Authentication Header) IP extension Header ๋กœ์„œ IP packet ์— ๋Œ€ํ•œ ์ธ์ฆ ์—ฌ๋ถ€๋ฅผ ์ œ๊ณต ์ „์ฒด ํŒจํ‚ท์— ๋Œ€ํ•œ ์ธ์ฆ ์—ฌ๋ถ€๋ฅผ ๊ฒฐ์ • Transport mode ์˜ ๊ฒฝ์šฐ AH ๋Š” IP Header ์™€ Payload ์‚ฌ์ด์—

์œ„์น˜ํ•˜์—ฌ ์ „์ฒด IP Packet ์„ ์ธ์ฆ Tunnel mode ์˜ ๊ฒฝ์šฐ ์ƒˆ๋กœ์šด IP Header ์™€ AH ๊ฐ€ ์•ž ๋ถ€๋ถ„์—

์ฒจ๊ฐ€

Page 30: Linux Advanced Routing & Traffic  Control HOWTO (1)

30

IPSec components

ESP(Encapsulating Security Payload) ๋‹ค์ˆ˜์˜ security service ๋ฅผ ์ œ๊ณต

Confidentiality, origin authentication, data integrity ๋ฅผ ์ œ๊ณต Authentication ์—†์ด confidentaility ๋ฅผ ์ œ๊ณต ๊ฐ€๋Šฅ Transport mode ์˜ ๊ฒฝ์šฐ IP Header ๋’ค์— ๋‚˜ํƒ€๋‚˜๋ฉฐ , IP Payload ๋Š”

ESP Payload ์— ์˜ํ•ด encapsulate ๋œ๋‹ค . Tunnel mode ์ผ ๊ฒฝ์šฐ payload ๋Š” ์›๋ณธ IP ํŒจํ‚ท์ด ๋œ๋‹ค .

Page 31: Linux Advanced Routing & Traffic  Control HOWTO (1)

31

Chap 7. IPSEC : secure IP over the Internet ๋ฆฌ๋ˆ…์Šค์—์„œ๋Š” ๋‘ ๊ฐ€์ง€ ์ข…๋ฅ˜์˜ IPSEC ์„ ์‚ฌ์šฉํ•  ์ˆ˜ ์žˆ๋‹ค .

2.2 ๋ฐ 2.4 ์—๋Š” ์ตœ์ดˆ์˜ ๋ฉ”์ด์ € ๊ตฌํ˜„๋ฌผ์ธ FreeS/WAN ์ด ์žˆ๋‹ค . ๋ฆฌ๋ˆ…์Šค ์ปค๋„์— ์•„์ฃผ ์ž˜ ํ†ตํ•ฉ๋˜์ง€๋Š” ์•Š์œผ๋ฉฐ , ์‹ค์ œ merge ์˜

์ข‹์€ ํ›„๋ณด๊ฐ€ ๋˜์ง€ ๋ชปํ•จ ๋ฆฌ๋ˆ…์Šค 2.5.47 ์˜ ๊ฒฝ์šฐ ์ปค๋„ ๋‚ด์— ์ž์ฒด์ ์ธ IPSEC ๊ตฌํ˜„์ด

์žˆ๋‹ค . 2.5.49 ์˜ ๊ฒฝ์šฐ IPSEC ๋Š” ์ถ”๊ฐ€์ ์ธ ํŒจ์น˜ ์—†์ด๋„ ๋™์ž‘ํ•œ๋‹ค .

Page 32: Linux Advanced Routing & Traffic  Control HOWTO (1)

32

Intro with Manual Keying

Iptable ์—์„œ IPSEC ํŒจํ‚ท์„ ์ฐจ๋‹จ ์‹œํ‚ค๋ฏ€๋กœ ๋‹ค์Œ๊ณผ ๊ฐ™์€ ์„ค์ •์„ ํ•„์š” . iptable โ€“A xxx โ€“p 50 โ€“j ACCEPT iptable โ€“a xxx โ€“p 51 โ€“j ACCEPT

IPSEC ์€ Internet Protocol ์˜ ๋ณด์•ˆ ๋ฒ„์ „์„ ์ œ๊ณต ๋ณด์•ˆ - ์•”ํ˜ธํ™” (encryption) ๊ณผ ์ธ์ฆ (Authentication)

IPSEC ์€ ์•”ํ˜ธํ™”๋ฅผ ์œ„ํ•œ โ€œ ESPโ€ ์™€ โ€œ AHโ€ ๋ฅผ ์ง€์›ํ•œ๋‹ค . ESP ์™€ AH ๋Š” security association(SA) ์— ์˜์กดํ•œ๋‹ค . SA ๋Š” source ์™€ destination, instruction ์œผ๋กœ ๊ตฌ์„ฑ

๋Œ€์นญ์  ํ†ต์‹ ํ•˜๋Š” ์–‘์ชฝ์—์„œ ์ •ํ™•ํžˆ ๋™์ผํ•œ SA ๋ฅผ ๊ณต์œ  ์–‘๋ฐฉํ–ฅ ํŠธ๋ž˜ํ”ฝ์„ ์œ„ํ•ด์„œ๋Š” ๋‘ ๊ฐœ์˜ SA ๊ฐ€ ํ•„์š” .

SPI(Security Parameter Index) ID

Secret key

Page 33: Linux Advanced Routing & Traffic  Control HOWTO (1)

33

Intro with Manual Keying

์•”ํ˜ธํ™”๋ฅผ ์œ„ํ•œ Policy ์˜ ํ•„์š”์„ฑ ๊ฐ„๋‹จํ•œ Security Policy(SP)

Security Policy specifies WHAT we want; a Security Association describes HOW we want it.

๋‚˜๊ฐ€๋Š” ํŒจํ‚ท์—๋Š” SA SPI ๊ฐ€ ์žˆ์–ด์„œ ์ด๋ฅผ ํ†ตํ•ด ์›๊ฒฉ์ง€์— ๋Œ€์‘ํ•˜๋Š” verification ๊ณผ decryption instruction ์„ ์ฐพ์„ ์ˆ˜ ์žˆ๋‹ค .

10.0.0.216 ์—์„œ 10.0.0.11 ๋กœ ์•”ํ˜ธํ™” ๋ฐ ์ธ์ฆ์„ ํ†ตํ•ด ํ†ต์‹ ์„ ํ•˜๋Š” ๋‹จ์ˆœํ•œ ๊ตฌ์„ฑ

Page 34: Linux Advanced Routing & Traffic  Control HOWTO (1)

34

Intro with Manual Keying

/sbin/setkey โ€“f filename

Security Policy

Page 35: Linux Advanced Routing & Traffic  Control HOWTO (1)

35

Intro with Manual Keying

Page 36: Linux Advanced Routing & Traffic  Control HOWTO (1)

36

Automatic Keying

์•ˆ์ „ํ•œ ์ƒํƒœ ์œ ์ง€๋ฅผ ์œ„ํ•ด ์•”ํ˜ธํ™” ๊ตฌ์„ฑ์„ ์‹ ๋ขฐํ•  ์ˆ˜ ์žˆ๋Š” ๊ฒฝ๋กœ๋ฅผ ํ†ตํ•ด ์ „๋‹ฌํ•  ํ•„์š”๊ฐ€ ์žˆ๋‹ค .

๋น„๋ฐ€๊ฐ’์ด ๊ณต์œ ๋˜๊ธฐ์— ๋น„๋ฐ€์ด ์•„๋‹ˆ๋‹ค . ๋ชจ๋“  ์ƒ๋Œ€์™€์˜ ํ†ต์‹ ์—์„œ ์„œ๋กœ ๋‹ค๋ฅธ ๋น„๋ฐ€๊ฐ’์„ ์‚ฌ์šฉํ•˜๋„๋ก

ํ•ด์•ผํ•œ๋‹ค . Key rollover

์ผ์ •์‹œ๊ฐ„๋งˆ๋‹ค ์ƒˆ๋กœ์šด ํ‚ค๋กœ ์˜ฎ๊ฒจ์•ผ ํ•œ๋‹ค . ์ข€๋” ์ผ๋ฐ˜์ ์ธ ํ‚ค ์ •์ฑ…์„ ๊ธฐ์ˆ ํ•  ์ˆ˜ ์žˆ๊ฒŒ ๋˜์•ผ ํ•œ๋‹ค .

์ •ํ™•ํ•˜๊ฒŒ Internet Key Exchange ํ”„๋กœํ† ์ฝœ ์ œ๊ณต

๋‚œ์ˆ˜์ ์œผ๋กœ ์ƒ์„ฑ๋œ ํ‚ค๋ฅผ ์ž๋™์œผ๋กœ ๊ตํ™˜ ํ˜‘์ƒ๋œ ์•Œ๊ณ ๋ฆฌ์ฆ˜ ์„ธ๋ถ€ ์‚ฌํ•ญ์— ๋”ฐ๋ผ์„œ ๋น„๋Œ€์นญ ์•”ํ˜ธํ™” ๊ธฐ์ˆ ์„

์ด์šฉํ•ด ์ „์†ก IPSEC ๊ตฌํ˜„์€ KAME โ€˜racoonโ€™ IKE ๋ฐ๋ชฌ์œผ๋กœ ๋™์ž‘ํ•œ๋‹ค .

key manage protocol

Page 37: Linux Advanced Routing & Traffic  Control HOWTO (1)

37

Automatic Keying

Security Association ์„ ๋งŒ๋“ค์–ด ์ฃผ๊ณ  policy ๋Š” ์œ ์ €๊ฐ€ ์„ค์ • Racoon ์„ค์ • โ€“ racoon.conf & psk.txt

passwdOther host

Psk.txt ์˜ ํŒŒ์ผ์˜ ์†Œ์œ ์ž๋Š” root ๋ชจ๋“œ๋Š” 600 ์œผ๋กœ ์„ค์ •๋˜์–ด์•ผ ํ•œ๋‹ค .

Page 38: Linux Advanced Routing & Traffic  Control HOWTO (1)

38

Automatic Keying

Security policy

Page 39: Linux Advanced Routing & Traffic  Control HOWTO (1)

39

Automatic keying using X.509 certificates

๋น„ ๋Œ€์นญ ์•”ํ˜ธํ™” ๊ธฐ์ˆ  IPSEC ์ฐธ๊ฐ€์ž๊ฐ€ public key ์™€ private key ๋ฅผ ๋งŒ๋“ ๋‹ค . openssl ๋„๊ตฌ๋กœ ํ‚ค๋ฅผ ๋งŒ๋“ ๋‹ค .

Page 40: Linux Advanced Routing & Traffic  Control HOWTO (1)

40

IPSEC tunnels

Tunnel ๋ชจ๋“œ ๋ผ์šฐํ„ฐ๋งŒ IPSEC ์— ๋Œ€ํ•ด์„œ ์•Œ๊ณ  ๋‹ค๋ฅธ ํ˜ธ์ŠคํŠธ๋“ค์„ ๋Œ€์‹ ํ•ด์„œ

ํ•„์š”ํ•œ ์ž‘์—…๋“ค์„ ํ•œ๋‹ค . Proxy ESP ๋ผ๊ณ ๋„ ํ•จ .

Example 10.0.0.216 ์—์„œ 10.0.0.11 ์„ ๊ฑฐ์ณ 130.161.0.0/16 ์œผ๋กœ ๊ฐ€๋Š” ๋ชจ๋“  ํŠธ๋ž˜ํ”ฝ์ด ํ„ฐ๋„์„ ํ†ตํ•˜๊ธฐ ์œ„ํ•ด์„œ

10.0.0.216

10.0.0.11 130.161.0.0/16

Page 41: Linux Advanced Routing & Traffic  Control HOWTO (1)

41

IPSEC tunnels

10.0.0.216 ์—์„œ์˜ ์„ค์ •

10.0.0.11

ESP ์•”ํ˜ธํ™” SA ๋ฅผ ๊ตฌ์„ฑ

์‹ค์ œ ํ„ฐ๋„ ๊ตฌ์„ฑ

Page 42: Linux Advanced Routing & Traffic  Control HOWTO (1)

42

Chap 8. Multicast routing

๋ฉ€ํ‹ฐ์บ์ŠคํŠธ ๋ผ์šฐํŒ…์„ ์œ„ํ•ด์„œ๋Š” ์ž์‹ ์ด ์›ํ•˜๋Š” ์ข…๋ฅ˜๋ฅผ ์ง€์›ํ•˜๋„๋ก ๋ฆฌ๋ˆ…์Šค ์ปค๋„์„ ๊ตฌ์„ฑํ•ด์•ผ ํ•œ๋‹ค . DVMRP(RIP ์œ ๋‹ˆ์บ์ŠคํŠธ ํ”„๋กœํ† ์ฝœ์˜ ๋ฉ€ํ‹ฐ์บ์ŠคํŠธ ๋ฒ„์ „ ) ,

MOSPF(OSPF) , PIM-SM(Protocol Independent Multicast-Sparse Mode) , PIM-DM(Protocol Independent Multicast-Dense Mode)

๋ฉ€ํ‹ฐ์บ์ŠคํŠธ๋ฅผ ํ™œ์„ฑํ™” ์‹œํ‚จํ›„ ๋ผ์šฐํ„ฐ ํ…Œ์ด๋ธ”์— ๋ฉ€ํ‹ฐ์บ์ŠคํŠธ ๊ฐ€์ƒ ๋„คํŠธ์›Œํฌ๋ฅผ ์ถ”๊ฐ€

Page 43: Linux Advanced Routing & Traffic  Control HOWTO (1)

43

Multicast routing

๋ฆฌ๋ˆ…์Šค ํŒจํ‚ท ํฌ์›Œ๋”ฉ ์„ค์ •

Eth0 ์—์„œ ๋ฉ€ํ‹ฐ์บ์ŠคํŒ…์„ ํ•˜๊ณ  ์žˆ๋‹ค๊ณ  ๊ฐ€์ •