{"id":296287,"date":"2019-12-24T09:00:20","date_gmt":"2019-12-24T09:00:20","guid":{"rendered":"http:\/\/savepearlharbor.com\/?p=296287"},"modified":"-0001-11-30T00:00:00","modified_gmt":"-0001-11-29T21:00:00","slug":"","status":"publish","type":"post","link":"https:\/\/savepearlharbor.com\/?p=296287","title":{"rendered":"Juniper SRX \u0438 Cisco ASA: \u0441\u0435\u0440\u0438\u044f \u043e\u0447\u0435\u0440\u0435\u0434\u043d\u0430\u044f"},"content":{"rendered":"\n<div class=\"post__text post__text-html js-mediator-article\" id=\"post-content-body\" data-io-article-url=\"https:\/\/habr.com\/ru\/post\/481620\/\">\u041f\u0435\u0440\u0432\u044b\u0439 \u0440\u0430\u0437 \u0441\u0442\u0440\u043e\u0438\u0442\u044c IPSec \u043c\u0435\u0436\u0434\u0443 Juniper SRX \u0438 Cisco ASA \u043c\u043d\u0435 \u0434\u043e\u0432\u0435\u043b\u043e\u0441\u044c \u0435\u0449\u0451 \u0432 \u0434\u0430\u043b\u0451\u043a\u043e\u043c 2014 \u0433\u043e\u0434\u0443. \u0423\u0436\u0435 \u0442\u043e\u0433\u0434\u0430 \u044d\u0442\u043e \u0431\u044b\u043b\u043e \u0432\u0435\u0441\u044c\u043c\u0430 \u0431\u043e\u043b\u0435\u0437\u043d\u0435\u043d\u043d\u043e, \u043f\u043e\u0442\u043e\u043c\u0443 \u0447\u0442\u043e \u043f\u0440\u043e\u0431\u043b\u0435\u043c \u0431\u044b\u043b\u043e \u043c\u043d\u043e\u0433\u043e (\u043e\u0431\u044b\u0447\u043d\u043e \u2014 \u0440\u0430\u0437\u0432\u0430\u043b\u0438\u0432\u0430\u044e\u0449\u0438\u0439\u0441\u044f \u043f\u0440\u0438 \u0440\u0435\u0433\u0435\u043d\u0435\u0440\u0430\u0446\u0438\u0438 \u0442\u0443\u043d\u043d\u0435\u043b\u044c), \u0434\u0438\u0430\u0433\u043d\u043e\u0441\u0442\u0438\u0440\u043e\u0432\u0430\u0442\u044c \u0431\u044b\u043b\u043e \u0441\u043b\u043e\u0436\u043d\u043e (ASA \u0441\u0442\u043e\u044f\u043b\u0430 \u0443 \u043d\u0430\u0448\u0435\u0433\u043e \u0437\u0430\u043a\u0430\u0437\u0447\u0438\u043a\u0430, \u043f\u043e\u044d\u0442\u043e\u043c\u0443 \u0432\u043e\u0437\u043c\u043e\u0436\u043d\u043e\u0441\u0442\u0438 \u0434\u043b\u044f \u0434\u0435\u0431\u0430\u0433\u0430 \u0431\u044b\u043b\u0438 \u043e\u0433\u0440\u0430\u043d\u0438\u0447\u0435\u043d\u044b), \u043d\u043e \u043a\u0430\u043a-\u0442\u043e \u044d\u0442\u043e \u0440\u0430\u0431\u043e\u0442\u0430\u043b\u043e.<\/p>\n<p>  <img decoding=\"async\" src=\"https:\/\/habrastorage.org\/webt\/w2\/eb\/n_\/w2ebn_vjpuq9sfxp-vw8lhz090m.jpeg\" alt=\"image\"><\/p>\n<p>  \u0421 \u0442\u043e\u0439 \u043f\u043e\u0440\u044b \u0438 \u0440\u0435\u043a\u043e\u043c\u0435\u043d\u0434\u043e\u0432\u0430\u043d\u043d\u044b\u0439 JunOS \u0434\u043b\u044f SRX \u043e\u0431\u043d\u043e\u0432\u0438\u043b\u0441\u044f \u043d\u0430 15.1 (\u0434\u043b\u044f \u043b\u0438\u043d\u0435\u0439\u043a\u0438 SRX300, \u043f\u043e \u043a\u0440\u0430\u0439\u043d\u0435\u0439 \u043c\u0435\u0440\u0435), \u0438 ASA \u043d\u0430\u0443\u0447\u0438\u043b\u0430\u0441\u044c \u0432 route based IPSec (c \u0432\u0435\u0440\u0441\u0438\u0438 \u0441\u043e\u0444\u0442\u0430 9.8), \u0447\u0442\u043e \u043d\u0435\u0441\u043a\u043e\u043b\u044c\u043a\u043e \u0443\u043f\u0440\u043e\u0449\u0430\u0435\u0442 \u043d\u0430\u0441\u0442\u0440\u043e\u0439\u043a\u0443. \u0418 \u0432\u043e\u0442 \u043d\u0430 \u0442\u0435\u043a\u0443\u0449\u0435\u0439 \u0440\u0430\u0431\u043e\u0442\u0435 \u043d\u0435 \u0442\u0430\u043a \u0434\u0430\u0432\u043d\u043e \u043f\u0440\u0435\u0434\u0441\u0442\u0430\u0432\u0438\u043b\u0441\u044f \u0448\u0430\u043d\u0441 \u0441\u043d\u043e\u0432\u0430 \u0441\u043e\u0431\u0440\u0430\u0442\u044c \u0442\u0430\u043a\u0443\u044e \u0441\u0445\u0435\u043c\u0443. \u0418 \u0441\u043d\u043e\u0432\u0430 \u043d\u0435\u0443\u0434\u0430\u0447\u043d\u043e \u2014 \u043f\u0440\u0438 \u0440\u0435\u0433\u0435\u043d\u0435\u0440\u0430\u0446\u0438\u0438 \u0442\u0443\u043d\u043d\u0435\u043b\u044c \u0431\u043b\u0430\u0433\u043e\u043f\u043e\u043b\u0443\u0447\u043d\u043e \u043f\u0430\u0434\u0430\u043b (\u0438 \u043d\u0435 \u0432\u0441\u0435\u0433\u0434\u0430 \u043f\u043e\u0434\u043d\u0438\u043c\u0430\u043b\u0441\u044f \u0431\u0435\u0437 \u0440\u0443\u0447\u043d\u043e\u0433\u043e \u0440\u0435\u0441\u0442\u0430\u0440\u0442\u0430). \u0418 \u0441\u043d\u043e\u0432\u0430 \u0432 \u043b\u043e\u0433\u0430\u0445 \u0442\u0438\u0448\u0438\u043d\u0430 \u0438 \u043d\u0435\u043f\u043e\u043d\u044f\u0442\u043a\u0438, \u0430 \u0442.\u043a. ASA \u043d\u0430\u0445\u043e\u0434\u0438\u043b\u0430\u0441\u044c \u0443 \u043d\u0430\u0448\u0435\u0433\u043e \u043f\u0430\u0440\u0442\u043d\u0451\u0440\u0430, \u0442\u043e \u0438 \u0434\u0435\u0431\u0430\u0436\u0438\u0442\u044c, \u0441\u043e\u043e\u0442\u0432\u0435\u0442\u0441\u0442\u0432\u0435\u043d\u043d\u043e, \u043d\u0435 \u0431\u044b\u043b\u043e \u043d\u0438\u043a\u0430\u043a\u043e\u0439 \u0432\u043e\u0437\u043c\u043e\u0436\u043d\u043e\u0441\u0442\u0438.<br \/>  \u0418 \u0432\u043e\u0442 \u0442\u0435\u043f\u0435\u0440\u044c \u043f\u0440\u0435\u0434\u0441\u0442\u0430\u0432\u0438\u043b\u0441\u044f \u0441\u043b\u0443\u0447\u0430\u0439 \u0441\u043e\u0431\u0440\u0430\u0442\u044c \u0441\u0445\u0435\u043c\u0443, \u043f\u0440\u0438 \u043a\u043e\u0442\u043e\u0440\u043e\u0439 \u043e\u0431\u0435 \u0441\u0442\u043e\u0440\u043e\u043d\u044b (\u0438 SRX, \u0438 ASA) \u043d\u0430\u0445\u043e\u0434\u044f\u0442\u0441\u044f \u043f\u043e\u0434 \u043d\u0430\u0448\u0438\u043c \u0443\u043f\u0440\u0430\u0432\u043b\u0435\u043d\u0438\u0435\u043c, \u0441\u043e\u043e\u0442\u0432\u0435\u0442\u0441\u0442\u0432\u0435\u043d\u043d\u043e, \u043f\u043e\u0438\u0433\u0440\u0430\u0442\u044c\u0441\u044f \u043c\u043e\u0436\u043d\u043e \u043d\u0430 \u0441\u043b\u0430\u0432\u0443.<\/p>\n<p>  <a name=\"habracut\"><\/a><\/p>\n<h2>\u0414\u0438\u0441\u043f\u043e\u0437\u0438\u0446\u0438\u044f<\/h2>\n<p>  \u0418\u0442\u0430\u043a, \u0447\u0442\u043e \u0443 \u043d\u0430\u0441 \u0438\u043c\u0435\u0435\u0442\u0441\u044f:  <\/p>\n<ul>\n<li>Juniper SRX340 (JunOS 15.1X49D150.2)<\/li>\n<li>Cisco ASA 5506 (\u0441\u043e\u0444\u0442 9.8.4)<\/li>\n<li>route based IPSec \u043c\u0435\u0436\u0434\u0443 \u043d\u0438\u043c\u0438 (\u0440\u043e\u0443\u0442\u0438\u043d\u0433 \u0431\u0443\u0434\u0435\u0442 \u043e\u0431\u0435\u0441\u043f\u0435\u0447\u0438\u0432\u0430\u0442\u044c\u0441\u044f BGP, \u043e \u043d\u0451\u043c \u0442\u043e\u0436\u0435 \u0441\u043a\u0430\u0436\u0443 \u043f\u0430\u0440\u0443 \u0441\u043b\u043e\u0432)<\/li>\n<\/ul>\n<h2>\u0421\u0445\u0435\u043c\u0430<\/h2>\n<p>  <img decoding=\"async\" src=\"https:\/\/habrastorage.org\/webt\/sh\/my\/jo\/shmyjoejv-nyyjfd9xscuppkgqs.jpeg\"><\/p>\n<h2>\u041a\u043e\u043d\u0444\u0438\u0433\u0443\u0440\u0430\u0446\u0438\u044f<\/h2>\n<p>  <\/p>\n<h3>Juniper<\/h3>\n<p>  \u041d\u0430\u0447\u043d\u0451\u043c \u0441 \u043a\u043e\u043d\u0444\u0438\u0433\u0443\u0440\u0430\u0446\u0438\u0438 SRX. \u0423 \u043c\u0435\u043d\u044f \u0434\u043e\u0432\u043e\u043b\u044c\u043d\u043e \u043c\u043d\u043e\u0433\u043e \u0440\u0430\u0437\u043b\u0438\u0447\u043d\u044b\u0445 \u0442\u0443\u043d\u043d\u0435\u043b\u0435\u0439 \u0441\u0442\u0440\u043e\u0438\u0442\u0441\u044f \u0438\u043c\u0435\u043d\u043d\u043e \u043d\u0430 \u043d\u0451\u043c, \u0432 \u0438\u0442\u043e\u0433\u0435 \u044f \u043f\u0440\u0438\u0448\u0451\u043b \u043f\u0440\u0438\u043c\u0435\u0440\u043d\u043e \u043a \u0442\u0430\u043a\u043e\u0439 \u0441\u0445\u0435\u043c\u0435:<\/p>\n<pre><code class=\"plaintext\">set security ike policy IKE-ASA mode main set security ike policy IKE-ASA proposals SHA256-AES128-5-86400 set security ike policy IKE-ASA pre-shared-key ascii-text ...  set security ike gateway GW-ASA ike-policy IKE-ASA set security ike gateway GW-ASA address 192.0.2.2  set security ike gateway GW-ASA dead-peer-detection interval 10 set security ike gateway GW-ASA dead-peer-detection threshold 3 set security ike gateway GW-ASA local-identity inet 198.51.100.2 set security ike gateway GW-ASA external-interface ae0.4 set security ike gateway GW-ASA version v2-only  set security ipsec vpn VPN-ASA bind-interface st0.7 set security ipsec vpn VPN-ASA df-bit clear set security ipsec vpn VPN-ASA vpn-monitor source-interface st0.7 set security ipsec vpn VPN-ASA vpn-monitor destination-ip 169.254.100.2 set security ipsec vpn VPN-ASA ike gateway GW-ASA set security ipsec vpn VPN-ASA ike ipsec-policy SHA256-AES128-3600-14-policy set security ipsec vpn VPN-ASA establish-tunnels immediately  set interfaces st0 unit 7 description \"ASA AnyConnect router\" set interfaces st0 unit 7 family inet mtu 1436 set interfaces st0 unit 7 family inet address 169.254.100.1\/30  set routing-options static route 192.0.2.2\/32 next-hop 198.51.100.1  set security zones security-zone ZONE-VPN interfaces st0.7 host-inbound-traffic system-services ping set security zones security-zone ZONE-VPN interfaces st0.7 host-inbound-traffic system-services ike set security zones security-zone ZONE-VPN interfaces st0.7 host-inbound-traffic system-services traceroute set security zones security-zone ZONE-VPN interfaces st0.7 host-inbound-traffic protocols bgp <\/code><\/pre>\n<p>  \u0412\u0438\u0434\u043d\u043e, \u0447\u0442\u043e \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u0435\u0442\u0441\u044f IKEv2, \u0431\u0435\u0437 traffic-selectors (\u0443 \u043d\u0430\u0441 \u0432 \u0430\u0440\u0441\u0435\u043d\u0430\u043b\u0435 \u0438 \u0431\u0435\u0437 \u0442\u043e\u0433\u043e \u0434\u043e\u0441\u0442\u0430\u0442\u043e\u0447\u043d\u043e \u0441\u0440\u0435\u0434\u0441\u0442\u0432, \u0447\u0442\u043e\u0431\u044b \u043e\u0433\u0440\u0430\u043d\u0438\u0447\u0438\u0442\u044c \u0445\u043e\u0436\u0434\u0435\u043d\u0438\u0435 \u0442\u0440\u0430\u0444\u0438\u043a\u0430 \u2014 \u043e\u0442 \u043f\u0440\u0435\u0444\u0438\u043a\u0441-\u043b\u0438\u0441\u0442\u043e\u0432 BGP \u0434\u043e security policies). \u0414\u043e \u043a\u0443\u0447\u0438 \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u0435\u0442\u0441\u044f DPD (dead peer detection) \u0438 vpn-monitor (\u0443 \u043d\u0438\u0445 \u043d\u0435\u043c\u043d\u043e\u0433\u043e \u0440\u0430\u0437\u043d\u044b\u0439 \u0442\u0438\u043f \u043f\u0440\u043e\u0432\u0435\u0440\u043e\u043a, \u0434\u043b\u044f \u043d\u0430\u0434\u0451\u0436\u043d\u043e\u0441\u0442\u0438 \u044f \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u044e \u043e\u0431\u0430).<\/p>\n<h3>Cisco<\/h3>\n<p>  \u041a\u043e\u043d\u0444\u0438\u0433\u0443\u0440\u0430\u0446\u0438\u044f ASA:  <\/p>\n<pre><code class=\"plaintext\">crypto ipsec ikev2 ipsec-proposal SHA256-AES128  protocol esp encryption aes-256 aes-192 aes  protocol esp integrity sha-256  crypto ipsec profile IPSEC-PROFILE-AMS1-VPN2  set ikev2 ipsec-proposal SHA256-AES128  set pfs group14  set security-association lifetime kilobytes unlimited  set security-association lifetime seconds 3600  crypto ikev2 policy 1  encryption aes-256 aes-192 aes  integrity sha256  group 5  prf sha256  lifetime seconds 86400    tunnel-group 198.51.100.2 type ipsec-l2l tunnel-group 198.51.100.2 ipsec-attributes  isakmp keepalive threshold 30 retry 10  ikev2 remote-authentication pre-shared-key ...  ikev2 local-authentication pre-shared-key ...  crypto ikev2 enable outside  interface Tunnel7  nameif l2l-ams1-vpn2  ip address 169.254.100.2 255.255.255.252   tunnel source interface outside  tunnel destination 198.51.100.2  tunnel mode ipsec ipv4  tunnel protection ipsec profile IPSEC-PROFILE-AMS1-VPN2<\/code><\/pre>\n<p>  \u0421\u0442\u0440\u0443\u043a\u0442\u0443\u0440\u0430 \u043a\u043e\u043d\u0444\u0438\u0433\u043e\u0432 \u043f\u0440\u0438\u043c\u0435\u0440\u043d\u043e \u043e\u0434\u0438\u043d\u0430\u043a\u043e\u0432\u0430\u044f \u043d\u0430 \u043e\u0431\u043e\u0438\u0445 \u0440\u043e\u0443\u0442\u0435\u0440\u0430\u0445, \u043d\u043e, \u043a\u0430\u043a \u043e\u0431\u044b\u0447\u043d\u043e, \u043d\u0430\u0437\u0432\u0430\u043d\u0438\u0435 \u0441\u0435\u043a\u0446\u0438\u0439 \u043d\u0435 \u0441\u043e\u0432\u043f\u0430\u0434\u0430\u044e\u0442 \u0441\u043e\u0432\u0435\u0440\u0448\u0435\u043d\u043d\u043e.\u0414\u0430\u0432\u0430\u0439\u0442\u0435 \u043f\u0440\u043e\u0431\u0435\u0436\u0438\u043c\u0441\u044f, \u0447\u0442\u043e \u0447\u0435\u043c\u0443 \u0441\u043e\u043e\u0442\u0432\u0435\u0442\u0441\u0442\u0432\u0443\u0435\u0442.<\/p>\n<h3>\u0421\u0440\u0430\u0432\u043d\u0435\u043d\u0438\u0435 \u043a\u043e\u043d\u0444\u0438\u0433\u043e\u0432<\/h3>\n<h4>IKE policy \/ proposal<\/h4>\n<p>  <\/p>\n<pre><code class=\"plaintext\">crypto ikev2 policy 1  encryption aes-256 aes-192 aes  integrity sha256  group 5  prf sha256  lifetime seconds 86400<\/code><\/pre>\n<pre><code class=\"plaintext\">set security ike proposal SHA256-AES128-5-86400 description ike-phase1-proposal1 set security ike proposal SHA256-AES128-5-86400 authentication-method pre-shared-keys set security ike proposal SHA256-AES128-5-86400 dh-group group5 set security ike proposal SHA256-AES128-5-86400 authentication-algorithm sha-256 set security ike proposal SHA256-AES128-5-86400 encryption-algorithm aes-128-cbc set security ike proposal SHA256-AES128-5-86400 lifetime-seconds 86400  set security ike policy IKE-ASA mode main set security ike policy IKE-ASA proposals SHA256-AES128-5-86400 set security ike policy IKE-ASA pre-shared-key ascii-text ... <\/code><\/pre>\n<p>  \u0417\u0434\u0435\u0441\u044c \u043d\u0430\u0447\u0438\u043d\u0430\u0435\u0442\u0441\u044f \u043d\u0435\u043a\u043e\u0442\u043e\u0440\u0430\u044f \u043f\u0443\u0442\u0430\u043d\u0438\u0446\u0430 \u0432 \u0442\u0435\u0440\u043c\u0438\u043d\u043e\u043b\u043e\u0433\u0438\u0438. \u0422\u043e, \u0447\u0442\u043e \u0443 Cisco \u043d\u0430\u0437\u044b\u0432\u0430\u0435\u0442\u0441\u044f IKE policy, \u0443 Juniper \u2014 IKE Proposal. \u0410 IKE policy \u0443 Juniper \u043f\u043e\u0445\u043e\u0436\u0435 \u043d\u0430 tunnel group \u0443 ASA\u2026 \u041b\u0438\u0447\u043d\u043e \u043c\u043d\u0435 \u0431\u043e\u043b\u044c\u0448\u0435 \u043d\u0440\u0430\u0432\u0438\u0442\u0441\u044f \u043f\u043e\u0434\u0445\u043e\u0434 Juniper, \u043d\u043e \u0442\u0443\u0442, \u0431\u0435\u0437\u0443\u0441\u043b\u043e\u0432\u043d\u043e, \u0434\u0435\u043b\u043e \u043f\u0440\u0438\u0432\u044b\u0447\u043a\u0438. <br \/>  \u041d\u0430\u0434\u043e \u0441\u043a\u0430\u0437\u0430\u0442\u044c, \u043d\u0430\u0441\u0442\u0440\u043e\u0439\u043a\u0430 IKEv2 (\u0442\u0435\u043c \u0431\u043e\u043b\u0435\u0435 route based) \u043d\u0430 ASA \u0432\u044b\u0433\u043b\u044f\u0434\u0438\u0442 \u0432\u0441\u0451 \u0436\u0435 \u043a\u0443\u0434\u0430 \u043b\u043e\u0433\u0438\u0447\u043d\u0435\u0435, \u0447\u0435\u043c crypto maps \u0438 \u043f\u0440\u043e\u0447\u0435\u0435 \u0431\u0435\u0437\u043e\u0431\u0440\u0430\u0437\u0438\u0435, \u043a\u043e\u0442\u043e\u0440\u043e\u0435 \u0431\u044b\u043b\u043e \u0440\u0430\u043d\u044c\u0448\u0435. <\/p>\n<h4>IPSec policy\/proposal<\/h4>\n<p>  <\/p>\n<pre><code class=\"plaintext\">crypto ipsec ikev2 ipsec-proposal SHA256-AES128  protocol esp encryption aes-256 aes-192 aes  protocol esp integrity sha-256  crypto ipsec profile IPSEC-PROFILE-SHA256-AES128-3600-14  set ikev2 ipsec-proposal SHA256-AES128  set pfs group14  set security-association lifetime kilobytes unlimited  set security-association lifetime seconds 3600<\/code><\/pre>\n<pre><code class=\"plaintext\">set security ipsec proposal SHA256-AES128-3600 description ipsec-phase2-proposal set security ipsec proposal SHA256-AES128-3600 protocol esp set security ipsec proposal SHA256-AES128-3600 authentication-algorithm hmac-sha-256-128 set security ipsec proposal SHA256-AES128-3600 encryption-algorithm aes-128-cbc set security ipsec proposal SHA256-AES128-3600 lifetime-seconds 3600  set security ipsec policy SHA256-AES128-3600-14-policy description SHA256-AES128-3600-14-policy set security ipsec policy SHA256-AES128-3600-14-policy perfect-forward-secrecy keys group14 set security ipsec policy SHA256-AES128-3600-14-policy proposals SHA256-AES128-3600<\/code><\/pre>\n<p>  \u0417\u0434\u0435\u0441\u044c \u043e\u0431\u0430 \u0432\u0435\u043d\u0434\u043e\u0440\u0430 \u0434\u0435\u043b\u0430\u044e\u0442 \u043f\u043b\u044e\u0441-\u043c\u0438\u043d\u0443\u0441 \u043e\u0434\u0438\u043d\u0430\u043a\u043e\u0432\u043e \u2014 \u0441\u043d\u0430\u0447\u0430\u043b\u0430 \u0441\u043e\u0437\u0434\u0430\u0451\u043c proposal \u0441 \u043f\u0430\u0440\u0430\u043c\u0435\u0442\u0440\u0430\u043c\u0438 \u0448\u0438\u0444\u0440\u043e\u0432\u0430\u043d\u0438\u044f\/\u0430\u0443\u0442\u0435\u043d\u0442\u0438\u0444\u0438\u043a\u0430\u0446\u0438\u0438, \u0430 \u043f\u043e\u0442\u043e\u043c \u043d\u0430\u0432\u0435\u0448\u0438\u0432\u0430\u0435\u043c \u043d\u0430 \u043d\u0435\u0433\u043e lifetime \u0438 pfs.<\/p>\n<h4>Gateway<\/h4>\n<p>  <\/p>\n<pre><code class=\"plaintext\">tunnel-group 198.51.100.2 type ipsec-l2l tunnel-group 198.51.100.2 ipsec-attributes  isakmp keepalive threshold 30 retry 10  ikev2 remote-authentication pre-shared-key ...  ikev2 local-authentication pre-shared-key ...<\/code><\/pre>\n<pre><code class=\"plaintext\">set security ike gateway GW-ASA ike-policy IKE-ASA-LEGAL set security ike gateway GW-ASA address 192.0.2.2 set security ike gateway GW-ASA dead-peer-detection interval 10 set security ike gateway GW-ASA dead-peer-detection threshold 3 set security ike gateway GW-ASA local-identity inet 198.51.100.2 set security ike gateway GW-ASA external-interface ae0.4 set security ike gateway GW-ASA version v2-only<\/code><\/pre>\n<p>  \u0410 \u0437\u0434\u0435\u0441\u044c \u043e\u0442\u043b\u0438\u0447\u0438\u044f \u0443\u0436\u0435 \u0431\u043e\u043b\u0435\u0435 \u044f\u0432\u043d\u044b\u0435. \u041d\u0430 ASA PSK \u0443\u043a\u0430\u0437\u044b\u0432\u0430\u0435\u0442\u0441\u044f \u043d\u0435\u043f\u043e\u0441\u0440\u0435\u0434\u0441\u0442\u0432\u0435\u043d\u043d\u043e \u0432 \u043d\u0430\u0441\u0442\u0440\u043e\u0439\u043a\u0430\u0445 \u043f\u0438\u0440\u0430. Juniper \u0436\u0435 \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u0435\u0442 \u0437\u0434\u0435\u0441\u044c \u0437\u0430\u0434\u0430\u0442\u044c \u0438 \u0438\u0441\u0445\u043e\u0434\u044f\u0449\u0438\u0439 \u0438\u043d\u0442\u0435\u0440\u0444\u0435\u0439\u0441 \u0438 \u0434\u043e\u043f\u043e\u043b\u043d\u0438\u0442\u0435\u043b\u044c\u043d\u044b\u0435 \u043e\u043f\u0446\u0438\u0438 \u0442\u0438\u043f\u0430 local-identity, \u043f\u043b\u044e\u0441 \u0441\u0441\u044b\u043b\u0430\u0435\u0442\u0441\u044f \u043d\u0430 ike policy (\u0433\u0434\u0435 \u043c\u044b \u0443\u043a\u0430\u0437\u044b\u0432\u0430\u043b\u0438 PSK).<br \/>  \u041a\u0441\u0442\u0430\u0442\u0438, \u0435\u0441\u043b\u0438 \u0432\u044b \u0437\u0430\u0445\u043e\u0442\u0438\u0442\u0435 \u043f\u0435\u0440\u0435\u0434\u0435\u043b\u0430\u0442\u044c \u043d\u0430 ASA IKEv2 \u0432 IKEv1 (\u0438 \u043d\u0430\u043e\u0431\u043e\u0440\u043e\u0442), \u0442\u043e \u0443 Cisco \u043d\u0430\u0434\u043e \u0431\u0443\u0434\u0435\u0442 \u043f\u0435\u0440\u0435\u0441\u043e\u0437\u0434\u0430\u0432\u0430\u0442\u044c \u0432\u0441\u044e tunnel-group. \u0410 \u043d\u0430 SRX \u0432\u0441\u0435\u0433\u043e \u043b\u0438\u0448\u044c \u0441\u043c\u0435\u043d\u0438\u0442\u044c \u043e\u0434\u043d\u0443 \u043e\u043f\u0446\u0438\u044e. <i>(\u041f\u0440\u0430\u0432\u0434\u0430, \u0434\u0430\u043b\u0435\u0435 \u043f\u0440\u0438 commit \u043c\u043e\u0433\u0443\u0442 \u0432\u044b\u043b\u0435\u0437\u0442\u0438 \u043d\u0435\u0441\u043e\u0432\u043c\u0435\u0441\u0442\u0438\u043c\u044b\u0435 \u043e\u043f\u0446\u0438\u0438, \u043d\u043e \u044d\u0442\u043e \u0443\u0436\u0435 \u0434\u0435\u0442\u0430\u043b\u0438)<\/i><\/p>\n<h4>VPN \/ VTI<\/h4>\n<p>  <\/p>\n<pre><code class=\"plaintext\">interface Tunnel7  nameif l2l-ams1-vpn2  ip address 169.254.100.2 255.255.255.252   tunnel source interface outside  tunnel destination 198.51.100.2  tunnel mode ipsec ipv4  tunnel protection ipsec profile IPSEC-PROFILE-SHA256-AES128-3600-14<\/code><\/pre>\n<pre><code class=\"plaintext\">set security ipsec vpn VPN-ASA bind-interface st0.7 set security ipsec vpn VPN-ASA df-bit clear set security ipsec vpn VPN-ASA vpn-monitor source-interface st0.7 set security ipsec vpn VPN-ASA vpn-monitor destination-ip 169.254.100.2 set security ipsec vpn VPN-ASA ike gateway GW-ASA set security ipsec vpn VPN-ASA ike ipsec-policy SHA256-AES128-3600-14-policy set security ipsec vpn VPN-ASA establish-tunnels immediately  set interfaces st0 unit 7 description \"AnyConnect router\" set interfaces st0 unit 7 family inet mtu 1436 set interfaces st0 unit 7 family inet address 169.254.100.1\/30<\/code><\/pre>\n<p>  \u0418 \u0441\u043d\u043e\u0432\u0430 \u043a\u043e\u043d\u0444\u0438\u0433 Juniper \u043c\u043d\u0435 \u043a\u0430\u0436\u0435\u0442\u0441\u044f \u0431\u043e\u043b\u0435\u0435 \u043b\u043e\u0433\u0438\u0447\u043d\u044b\u043c. VPN \u043d\u0430\u0441\u0442\u0440\u0430\u0438\u0432\u0430\u0435\u0442\u0441\u044f \u043e\u0442\u0434\u0435\u043b\u044c\u043d\u043e (\u043e\u043d \u043c\u043e\u0436\u0435\u0442 \u0431\u044b\u0442\u044c \u0438 policy-based), \u0441\u0430\u043c security tunnel \u2014 \u043e\u0442\u0434\u0435\u043b\u044c\u043d\u043e. \u041e\u0442\u0434\u0435\u043b\u044c\u043d\u043e\u0435 \u0441\u043f\u0430\u0441\u0438\u0431\u043e \u0437\u0430 \u00abestablish-tunnels immediately\u00bb. \u041e\u0447\u0435\u043d\u044c \u043f\u043e\u043b\u0435\u0437\u043d\u0430\u044f \u043e\u043f\u0446\u0438\u044f \ud83d\ude09 (\u0446\u0438\u0441\u043a\u043e\u0432\u043e\u0434\u044b \u043f\u043e\u0439\u043c\u0443\u0442, \u043e \u0447\u0451\u043c \u044f). \u0415\u0449\u0451 \u043e\u0434\u0438\u043d \u00ab\u0431\u043e\u043d\u0443\u0441\u00bb SRX \u2014 \u043c\u043e\u0436\u043d\u043e \u0441\u0442\u0440\u043e\u0438\u0442\u044c \u043c\u043d\u043e\u0433\u043e\u0442\u043e\u0447\u0435\u0447\u043d\u044b\u0435 IPSec, \u043a\u0430\u043a \u0441 \u0430\u0432\u0442\u043e\u043e\u0431\u043d\u0430\u0440\u0443\u0436\u0435\u043d\u0438\u0435\u043c \u043f\u0438\u0440\u043e\u0432 (\u0440\u0430\u0431\u043e\u0442\u0430\u0435\u0442, \u043a \u0441\u043e\u0436\u0430\u043b\u0435\u043d\u0438\u044e, \u0442\u043e\u043b\u044c\u043a\u043e \u043c\u0435\u0436\u0434\u0443 SRX), \u0442\u0430\u043a \u0441 \u0440\u0443\u0447\u043d\u044b\u043c \u0440\u043e\u0443\u0442\u0438\u043d\u0433\u043e\u043c. \u042d\u0442\u043e, \u043a\u043e\u043d\u0435\u0447\u043d\u043e, \u043d\u0435 \u043f\u043e\u043b\u043d\u043e\u0446\u0435\u043d\u043d\u044b\u0439 DMVPN, \u043d\u043e \u0436\u0438\u0437\u043d\u044c \u0432 \u0441\u0435\u0442\u0430\u043f\u0430\u0445 \u0442\u0438\u043f\u0430 \u00ab\u043e\u0434\u0438\u043d \u0446\u0435\u043d\u0442\u0440 \u2014 \u043c\u043d\u043e\u0433\u043e \u0444\u0438\u043b\u0438\u0430\u043b\u043e\u0432\u00bb \u0437\u043d\u0430\u0447\u0438\u0442\u0435\u043b\u044c\u043d\u043e \u043e\u0431\u043b\u0435\u0433\u0447\u0430\u0435\u0442.<\/p>\n<h3>Interfaces<\/h3>\n<p>  \u041e\u0442\u0434\u0435\u043b\u044c\u043d\u043e \u043e\u0441\u0442\u0430\u043d\u043e\u0432\u043b\u044e\u0441\u044c \u043d\u0430 \u043d\u0430\u0441\u0442\u0440\u043e\u0439\u043a\u0435 \u0438\u043d\u0442\u0435\u0440\u0444\u0435\u0439\u0441\u043e\u0432, \u043d\u0430 \u043a\u043e\u0442\u043e\u0440\u044b\u0445 \u0441\u0442\u0440\u043e\u0438\u0442\u0441\u044f IPSec. \u0423 Juniper \u044d\u0442\u043e, \u0441\u043e\u043e\u0442\u0432\u0435\u0442\u0441\u0442\u0432\u0435\u043d\u043d\u043e, <b>ae0.4<\/b>, \u0443 ASA \u2014 <b>outside<\/b><\/p>\n<pre><code class=\"plaintext\">crypto ikev2 enable outside<\/code><\/pre>\n<pre><code class=\"plaintext\">set security zones security-zone ZONE-INTERNET interfaces ae0.4 host-inbound-traffic system-services ike set security zones security-zone ZONE-VPN interfaces st0.7 host-inbound-traffic system-services ping set security zones security-zone ZONE-VPN interfaces st0.7 host-inbound-traffic system-services traceroute set security zones security-zone ZONE-VPN interfaces st0.7 host-inbound-traffic protocols bgp<\/code><\/pre>\n<p>  \u041d\u0430 \u0438\u043d\u0442\u0435\u0440\u0444\u0435\u0439\u0441\u0430\u0445 \u043d\u0443\u0436\u043d\u043e \u0440\u0430\u0437\u0440\u0435\u0448\u0438\u0442\u044c ike, \u0438\u043d\u0430\u0447\u0435 \u0440\u0430\u0431\u043e\u0442\u0430\u0442\u044c \u043d\u0438\u0447\u0435\u0433\u043e \u043d\u0435 \u0431\u0443\u0434\u0435\u0442 \ud83d\ude42 \u0414\u043e\u043f\u043e\u043b\u043d\u0438\u0442\u0435\u043b\u044c\u043d\u043e, \u0443 SRX \u043d\u0443\u0436\u043d\u043e \u0434\u043b\u044f \u0442\u0443\u043d\u043d\u0435\u043b\u044c\u043d\u043e\u0433\u043e \u0438\u043d\u0442\u0435\u0440\u0444\u0435\u0439\u0441\u0430 \u0440\u0430\u0437\u0440\u0435\u0448\u0438\u0442\u044c bgp\/ospf\/whatever \u0434\u043b\u044f \u0432\u0445\u043e\u0434\u044f\u0449\u0438\u0445 \u043f\u043e\u0434\u043a\u043b\u044e\u0447\u0435\u043d\u0438\u0439 \u043d\u0430 st0.x \u0438\u043d\u0442\u0435\u0440\u0444\u0435\u0439\u0441\u0435<\/p>\n<h2>\u041d\u0430\u0441\u0442\u0440\u043e\u0439\u043a\u0430 BGP<\/h2>\n<p>  \u0422\u0443\u0442 \u0432\u0441\u0451 \u0434\u043e\u0432\u043e\u043b\u044c\u043d\u043e \u0431\u0430\u043d\u0430\u043b\u044c\u043d\u043e (\u0441 \u043e\u0434\u043d\u043e\u0439 \u0441\u0442\u043e\u0440\u043e\u043d\u044b)  <\/p>\n<pre><code class=\"plaintext\">set protocols bgp group ASA type external set protocols bgp group ASA description \"AnyConnect router\" set protocols bgp group ASA hold-time 30 set protocols bgp group ASA import IMPORT-EBGP-ASA set protocols bgp group ASA export EXPORT-EBGP-ASA set protocols bgp group ASA local-as 64666 set protocols bgp group ASA neighbor 169.254.100.2 peer-as 65001  set policy-options policy-statement EXPORT-EBGP-ASA term 0 from route-filter 10.0.0.0\/8 exact set policy-options policy-statement EXPORT-EBGP-ASA term 0 then accept set policy-options policy-statement EXPORT-EBGP-ASA term 1 then reject  set policy-options policy-statement IMPORT-EBGP-ASA term 1 then reject<\/code><\/pre>\n<p>  \u041d\u0430 ASA \u043e\u0442\u0434\u0430\u0451\u043c \u0430\u0433\u0440\u0435\u0433\u0438\u0440\u043e\u0432\u0430\u043d\u043d\u044b\u0439 \u043f\u0440\u0435\u0444\u0438\u043a\u0441 \u043d\u0430\u0448\u0435\u0439 \u043b\u043e\u043a\u0430\u043b\u043a\u0438 \u2014 \u0443 \u043c\u0435\u043d\u044f \u044d\u0442\u043e \u0431\u0443\u0434\u0435\u0442 10\/8. \u041e\u0442 ASA \u043d\u0438\u0447\u0435\u0433\u043e \u043d\u0435 \u043f\u0440\u0438\u043d\u0438\u043c\u0430\u0435\u043c, \u043f\u043e\u0442\u043e\u043c\u0443 \u0447\u0442\u043e \u0441 \u0432\u0435\u0440\u0441\u0438\u0438 \u0441\u043e\u0444\u0442\u0430 9.8.4 \u0432\u0441\u0451 \u0440\u0430\u0432\u043d\u043e \u043d\u0435\u043b\u044c\u0437\u044f \u0430\u043d\u043e\u043d\u0441\u0438\u0440\u043e\u0432\u0430\u0442\u044c \u043f\u043e BGP \u0430\u0434\u0440\u0435\u0441\u0430 management-\u0438\u043d\u0442\u0435\u0440\u0444\u0435\u0439\u0441\u043e\u0432 (\u0447\u0442\u043e \u043e\u0431\u044a\u044f\u0441\u043d\u0438\u043c\u043e) \u0438 BVI (\u0447\u0442\u043e \u0436\u0443\u0442\u043a\u043e \u043d\u0435\u0443\u0434\u043e\u0431\u043d\u043e). \u041d\u043e \u0435\u0441\u043b\u0438 \u0443 \u0432\u0430\u0441 \u0437\u0430 ASA \u0435\u0441\u0442\u044c \u0435\u0449\u0451 \u043a\u0430\u043a\u0438\u0435-\u0442\u043e \u0441\u0435\u0442\u0438, \u0438\u0445 \u043d\u0443\u0436\u043d\u043e \u0431\u0443\u0434\u0435\u0442 \u0434\u043e\u0431\u0430\u0432\u0438\u0442\u044c \u0432 policy, \u043a\u043e\u043d\u0435\u0447\u043d\u043e.<\/p>\n<pre><code class=\"plaintext\">asa(config-router-af)# network 10.255.32.252 mask 255.255.255.254 ERROR: BGP configuration not supported on management-only\/BVI interface<\/code><\/pre>\n<p>  \u0427\u0442\u043e\u0431\u044b \u00ab\u0443\u0432\u0438\u0434\u0435\u0442\u044c\u00bb inside \u0438\u043d\u0442\u0435\u0440\u0444\u0435\u0439\u0441, \u043d\u0443\u0436\u043d\u043e \u0431\u0443\u0434\u0435\u0442 \u043d\u0430 SRX \u043f\u0440\u043e\u043f\u0438\u0441\u0430\u0442\u044c static route \u0432 \u0441\u0442\u043e\u0440\u043e\u043d\u0443 ipsec:  <\/p>\n<pre><code class=\"plaintext\">set routing-options static route 10.255.32.252\/31 next-hop 169.254.100.2<\/code><\/pre>\n<p>  \u0412\u0434\u043e\u0431\u0430\u0432\u043e\u043a, ASA \u0434\u043e \u0441\u0438\u0445 \u043f\u043e\u0440 \u043d\u0435 \u0443\u043c\u0435\u0435\u0442 \u0432 loopback \u0438\u043d\u0442\u0435\u0440\u0444\u0435\u0439\u0441\u044b, \u043f\u043e\u044d\u0442\u043e\u043c\u0443 \u0432\u0441\u0435 \u043b\u043e\u0433\u0438\/netflow \u0438 \u043f\u0440\u043e\u0447\u0430\u044f \u043c\u044b \u0431\u0443\u0434\u0435\u043c \u043e\u0442\u043f\u0440\u0430\u0432\u043b\u044f\u0442\u044c \u0441 inside.<br \/>  \u0412 ASA5506 \u0435\u0441\u0442\u044c \u0432\u0441\u0442\u0440\u043e\u0435\u043d\u043d\u044b\u0439 \u0441\u0432\u0438\u0447, \u043f\u043e\u044d\u0442\u043e\u043c\u0443 \u043c\u043e\u0436\u043d\u043e \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u044c \u0432\u0438\u0440\u0442\u0443\u0430\u043b\u044c\u043d\u044b\u0439 BVI-\u0438\u043d\u0442\u0435\u0440\u0444\u0435\u0439\u0441 (\u043e\u0441\u043e\u0431\u0435\u043d\u043d\u043e \u043f\u043e\u043b\u0435\u0437\u043d\u043e, \u043a\u043e\u0433\u0434\u0430 \u0443 \u0432\u0430\u0441 \u0441\u0445\u0435\u043c\u0430 \u00ab\u0440\u043e\u0443\u0442\u0435\u0440-\u043d\u0430-\u043f\u0430\u043b\u043e\u0447\u043a\u0435\u00bb, \u0438 \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u0435\u0442\u0441\u044f \u0432\u0441\u0435\u0433\u043e \u043b\u0438\u0448\u044c \u043e\u0434\u0438\u043d \u0444\u0438\u0437\u0438\u0447\u0435\u0441\u043a\u0438\u0439 \u043f\u043e\u0440\u0442.  <\/p>\n<pre><code class=\"plaintext\">interface BVI1  nameif inside  security-level 100  ip address 10.255.32.253 255.255.255.254 management-access inside<\/code><\/pre>\n<p>  \u041f\u043e\u0441\u043b\u0435 \u044d\u0442\u043e\u0433\u043e \u0432 \u043d\u0443\u0436\u043d\u044b\u0445 \u043c\u0435\u0441\u0442\u0430\u0445 (logging, snmp, flow) \u0432 \u043a\u0430\u0447\u0435\u0441\u0442\u0432\u0435 \u0438\u043d\u0442\u0435\u0440\u0444\u0435\u0439\u0441\u0430-\u0438\u0441\u0442\u043e\u0447\u043d\u0438\u043a\u0430 \u043d\u0443\u0436\u043d\u043e \u0431\u0443\u0434\u0435\u0442 \u0443\u043a\u0430\u0437\u0430\u0442\u044c `inside`.<\/p>\n<h2>\u0415\u0441\u043b\u0438 \u0447\u0442\u043e-\u0442\u043e \u043f\u043e\u0448\u043b\u043e \u043d\u0435 \u0442\u0430\u043a a.k.a. troubleshooting<\/h2>\n<p>  <\/p>\n<h3>IKE\/IPSec<\/h3>\n<p>  \u041f\u0435\u0440\u0432\u043e\u0435 \u2014 \u0443 \u0432\u0430\u0441 \u0434\u043e\u043b\u0436\u043d\u044b \u0443\u0441\u0442\u0430\u043d\u043e\u0432\u0438\u0442\u044c\u0441\u044f \u043e\u0431\u0435 \u0444\u0430\u0437\u044b IPSec (\u0443 Juniper \u044d\u0442\u043e, \u0441\u043e\u0431\u0441\u0442\u0432\u0435\u043d\u043d\u043e, IKE\/IPSec). <br \/>  \u0421\u043c\u043e\u0442\u0440\u0438\u043c:  <\/p>\n<pre><code class=\"plaintext\">admin@srx&gt; show security ike security-associations  Index   State  Initiator cookie  Responder cookie  Mode           Remote Address    2128190 UP     ae7d7d447326218a  2be3b3004ae0e36a  IKEv2          192.0.2.2      admin@srx&gt; show security ipsec security-associations     Total active tunnels: 6   ID    Algorithm       SPI      Life:sec\/kb  Mon lsys Port  Gateway      &lt;131077 ESP:aes-cbc-128\/sha256 fec3c7d1 2867\/ unlim U root 500 192.0.2.2       &gt;131077 ESP:aes-cbc-128\/sha256 74d792ca 2867\/ unlim U root 500 192.0.2.2    <\/code><\/pre>\n<p>  \u041d\u0430 ASA:  <\/p>\n<pre><code class=\"plaintext\">asa# sho crypto ikev2 sa   IKEv2 SAs:  Session-id:5, Status:UP-ACTIVE, IKE count:1, CHILD count:1  Tunnel-id Local                                               Remote                                                  Status         Role 585564345 192.0.2.2\/500                                  198.51.100.2\/500                                        READY    RESPONDER       Encr: AES-CBC, keysize: 128, Hash: SHA256, DH Grp:5, Auth sign: PSK, Auth verify: PSK       Life\/Active Time: 86400\/47018 sec Child sa: local selector  0.0.0.0\/0 - 255.255.255.255\/65535           remote selector 0.0.0.0\/0 - 255.255.255.255\/65535           ESP spi in\/out: 0xc989d9ea\/0xcca8b6d5<\/code><\/pre>\n<p>  \u0423 Juniper \u0435\u0449\u0451 \u043c\u043e\u0436\u043d\u043e \u043f\u043e\u0441\u043c\u043e\u0442\u0440\u0435\u0442\u044c \u0441\u0442\u0430\u0442\u0438\u0441\u0442\u0438\u043a\u0443 \u043f\u043e ipsec-\u0442\u0443\u043d\u043d\u0435\u043b\u044e, \u0432\u043a\u043b\u044e\u0447\u0430\u044f \u043f\u0440\u0438\u0447\u0438\u043d\u044b \u043f\u0430\u0434\u0435\u043d\u0438\u044f:  <\/p>\n<pre><code class=\"plaintext\">admin@srx&gt; show security ipsec security-associations index 131078 detail   ID: 131078 Virtual-system: root, VPN Name: VPN-ASA-LEGAL-PL   Local Gateway: 198.51.100.2, Remote Gateway: 192.0.2.2   Local Identity: ipv4_subnet(any:0,[0..7]=0.0.0.0\/0)   Remote Identity: ipv4_subnet(any:0,[0..7]=0.0.0.0\/0)   Version: IKEv2   DF-bit: clear, Copy-Outer-DSCP Disabled, Bind-interface: st0.7   Port: 500, Nego#: 734, Fail#: 0, Def-Del#: 0 Flag: 0x600a29    Tunnel events:      Mon Dec 09 2019 13:40:35: IPSec SA rekey successfully completed (48 times)     Mon Dec 09 2019 00:30:47: IKE SA rekey successfully completed (10 times)     Fri Nov 29 2019 02:13:55: IPSec SA negotiation successfully completed (1 times)     Fri Nov 29 2019 02:13:55: IKE SA negotiation successfully completed (1 times)     Fri Nov 29 2019 02:13:55: No response from peer. Negotiation failed (7 times)     Fri Nov 29 2019 02:10:14: DPD detected peer as down. Existing IKE\/IPSec SAs cleared (1 times)     Fri Nov 29 2019 01:39:15: IPSec SA rekey successfully completed (1 times)     Fri Nov 29 2019 00:49:50: IPSec SA negotiation successfully completed (1 times)     Fri Nov 29 2019 00:49:50: IKE SA negotiation successfully completed (1 times)     Fri Nov 29 2019 00:49:30: No response from peer. Negotiation failed (23 times)     Fri Nov 29 2019 00:37:24: DPD detected peer as down. Existing IKE\/IPSec SAs cleared (1 times)     Fri Nov 29 2019 00:30:00: IPSec SA rekey successfully completed (77 times)     Thu Nov 28 2019 20:11:31: IKE SA rekey successfully completed (7 times)     Tue Nov 26 2019 08:51:44: IPSec SA negotiation successfully completed (1 times)     Thu Nov 21 2019 21:24:32: IKE SA negotiation successfully completed (1 times)     Thu Nov 21 2019 01:06:27: IKE SA rekey successfully completed (6 times)   Direction: inbound, SPI: 4bd2e2bd, AUX-SPI: 0                               , VPN Monitoring: UP     Hard lifetime: Expires in 3132 seconds     Lifesize Remaining:  Unlimited     Soft lifetime: Expires in 2495 seconds     Mode: Tunnel(10 10), Type: dynamic, State: installed     Protocol: ESP, Authentication: hmac-sha256-128, Encryption: aes-cbc (128 bits)     Anti-replay service: counter-based enabled, Replay window size: 64   Direction: outbound, SPI: 504f306e, AUX-SPI: 0                               , VPN Monitoring: UP     Hard lifetime: Expires in 3132 seconds     Lifesize Remaining:  Unlimited     Soft lifetime: Expires in 2495 seconds     Mode: Tunnel(10 10), Type: dynamic, State: installed     Protocol: ESP, Authentication: hmac-sha256-128, Encryption: aes-cbc (128 bits)     Anti-replay service: counter-based enabled, Replay window size: 64 <\/code><\/pre>\n<p>  \u0415\u0441\u043b\u0438 \u0441 IPSec \u0432\u0441\u0451 \u0432 \u043f\u043e\u0440\u044f\u0434\u043a\u0435, \u0442\u043e \u043d\u0443\u0436\u043d\u043e \u0441\u043c\u043e\u0442\u0440\u0435\u0442\u044c \u043d\u0430 ACL (security policies, host-inbound \u043f\u0440\u0430\u0432\u0438\u043b\u0430 \u0438 \u0442.\u0434.). \u041d\u0430 \u043a\u0440\u0430\u0439\u043d\u0435\u0439 \u0441\u043b\u0443\u0447\u0430\u0439, \u043c\u043e\u0436\u043d\u043e \u043f\u043e\u043f\u0440\u043e\u0431\u043e\u0432\u0430\u0442\u044c \u043f\u0435\u0440\u0435\u0437\u0430\u0433\u0440\u0443\u0437\u0438\u0442\u044c \u043a\u043e\u0440\u043e\u0431\u043a\u0443 (ASA) \u2014 \u043c\u043d\u0435, \u0431\u044b\u0432\u0430\u043b\u043e, \u043f\u043e\u043c\u043e\u0433\u0430\u0435\u0442.<\/p>\n<h3>BGP<\/h3>\n<p>  \u0417\u0434\u0435\u0441\u044c \u0432\u0441\u0451 \u0434\u043e\u0432\u043e\u043b\u044c\u043d\u043e \u0441\u0442\u0430\u043d\u0434\u0430\u0440\u0442\u043d\u043e \u2014 \u0435\u0441\u043b\u0438 \u0441\u0435\u0441\u0441\u0438\u044f \u043d\u0435 \u0443\u0441\u0442\u0430\u043d\u0430\u0432\u043b\u0438\u0432\u0430\u0435\u0442\u0441\u044f, \u043c\u043e\u0436\u043d\u043e \u043f\u043e\u0441\u043c\u043e\u0442\u0440\u0435\u0442\u044c \u0447\u0435\u0440\u0435\u0437 capture, \u043b\u0435\u0442\u044f\u0442 \u043b\u0438 BGP-hello \u0432 \u043e\u0431\u0435 \u0441\u0442\u043e\u0440\u043e\u043d\u044b.<\/p>\n<h3>\u0418\u0442\u043e\u0433\u043e<\/h3>\n<p>  \u041d\u0430 \u044d\u0442\u043e\u043c \u0432\u0441\u0451. \u041d\u0435 \u0437\u043d\u0430\u044e, \u0432\u0438\u043d\u043e\u0439 \u043b\u0438 \u0442\u043e\u043c\u0443 \u043d\u043e\u0432\u044b\u0439 \u0441\u043e\u0444\u0442, \u0438\u043b\u0438 \u0437\u0432\u0451\u0437\u0434\u044b \u0442\u0430\u043a \u0441\u043e\u0448\u043b\u0438\u0441\u044c \u2014 \u043d\u043e \u0442\u0443\u043d\u043d\u0435\u043b\u044c ASA&lt;&gt;SRX \u0434\u0435\u0440\u0436\u0438\u0442\u0441\u044f \u0441\u0442\u0430\u0431\u0438\u043b\u044c\u043d\u043e \u0438 \u043d\u0435 \u043f\u0430\u0434\u0430\u0435\u0442 \u0440\u0430\u0437 \u0432 \u0441\u0443\u0442\u043a\u0438, \u043a\u0430\u043a \u0431\u044b\u043b\u043e \u0440\u0430\u043d\u044c\u0448\u0435.<br \/>  \u041d\u0430\u0434\u0435\u044e\u0441\u044c, \u0443 \u0432\u0430\u0441 \u0442\u043e\u0436\u0435 \u0432\u0441\u0451 \u043f\u043e\u043b\u0443\u0447\u0438\u0442\u0441\u044f!<\/div>\n<p>               <script class=\"js-mediator-script\">!function(e){function t(t,n){if(!(n in e)){for(var r,a=e.document,i=a.scripts,o=i.length;o--;)if(-1!==i[o].src.indexOf(t)){r=i[o];break}if(!r){r=a.createElement(\"script\"),r.type=\"text\/javascript\",r.async=!0,r.defer=!0,r.src=t,r.charset=\"UTF-8\";var d=function(){var e=a.getElementsByTagName(\"script\")[0];e.parentNode.insertBefore(r,e)};\"[object Opera]\"==e.opera?a.addEventListener?a.addEventListener(\"DOMContentLoaded\",d,!1):e.attachEvent(\"onload\",d):d() } } }t(\"\/\/mediator.mail.ru\/script\/2820404\/\",\"_mediator\")}(window);<\/script>      <br \/> \u0441\u0441\u044b\u043b\u043a\u0430 \u043d\u0430 \u043e\u0440\u0438\u0433\u0438\u043d\u0430\u043b \u0441\u0442\u0430\u0442\u044c\u0438 <a href=\"https:\/\/habr.com\/ru\/post\/481620\/\"> https:\/\/habr.com\/ru\/post\/481620\/<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"\n<div class=\"post__text post__text-html js-mediator-article\" id=\"post-content-body\" data-io-article-url=\"https:\/\/habr.com\/ru\/post\/481620\/\">\u041f\u0435\u0440\u0432\u044b\u0439 \u0440\u0430\u0437 \u0441\u0442\u0440\u043e\u0438\u0442\u044c IPSec \u043c\u0435\u0436\u0434\u0443 Juniper SRX \u0438 Cisco ASA \u043c\u043d\u0435 \u0434\u043e\u0432\u0435\u043b\u043e\u0441\u044c \u0435\u0449\u0451 \u0432 \u0434\u0430\u043b\u0451\u043a\u043e\u043c 2014 \u0433\u043e\u0434\u0443. \u0423\u0436\u0435 \u0442\u043e\u0433\u0434\u0430 \u044d\u0442\u043e \u0431\u044b\u043b\u043e \u0432\u0435\u0441\u044c\u043c\u0430 \u0431\u043e\u043b\u0435\u0437\u043d\u0435\u043d\u043d\u043e, \u043f\u043e\u0442\u043e\u043c\u0443 \u0447\u0442\u043e \u043f\u0440\u043e\u0431\u043b\u0435\u043c \u0431\u044b\u043b\u043e \u043c\u043d\u043e\u0433\u043e (\u043e\u0431\u044b\u0447\u043d\u043e \u2014 \u0440\u0430\u0437\u0432\u0430\u043b\u0438\u0432\u0430\u044e\u0449\u0438\u0439\u0441\u044f \u043f\u0440\u0438 \u0440\u0435\u0433\u0435\u043d\u0435\u0440\u0430\u0446\u0438\u0438 \u0442\u0443\u043d\u043d\u0435\u043b\u044c), \u0434\u0438\u0430\u0433\u043d\u043e\u0441\u0442\u0438\u0440\u043e\u0432\u0430\u0442\u044c \u0431\u044b\u043b\u043e \u0441\u043b\u043e\u0436\u043d\u043e (ASA \u0441\u0442\u043e\u044f\u043b\u0430 \u0443 \u043d\u0430\u0448\u0435\u0433\u043e \u0437\u0430\u043a\u0430\u0437\u0447\u0438\u043a\u0430, \u043f\u043e\u044d\u0442\u043e\u043c\u0443 \u0432\u043e\u0437\u043c\u043e\u0436\u043d\u043e\u0441\u0442\u0438 \u0434\u043b\u044f \u0434\u0435\u0431\u0430\u0433\u0430 \u0431\u044b\u043b\u0438 \u043e\u0433\u0440\u0430\u043d\u0438\u0447\u0435\u043d\u044b), \u043d\u043e \u043a\u0430\u043a-\u0442\u043e \u044d\u0442\u043e \u0440\u0430\u0431\u043e\u0442\u0430\u043b\u043e.<\/p>\n<p>  <img decoding=\"async\" src=\"https:\/\/habrastorage.org\/webt\/w2\/eb\/n_\/w2ebn_vjpuq9sfxp-vw8lhz090m.jpeg\" alt=\"image\"><\/p>\n<p>  \u0421 \u0442\u043e\u0439 \u043f\u043e\u0440\u044b \u0438 \u0440\u0435\u043a\u043e\u043c\u0435\u043d\u0434\u043e\u0432\u0430\u043d\u043d\u044b\u0439 JunOS \u0434\u043b\u044f SRX \u043e\u0431\u043d\u043e\u0432\u0438\u043b\u0441\u044f \u043d\u0430 15.1 (\u0434\u043b\u044f \u043b\u0438\u043d\u0435\u0439\u043a\u0438 SRX300, \u043f\u043e \u043a\u0440\u0430\u0439\u043d\u0435\u0439 \u043c\u0435\u0440\u0435), \u0438 ASA \u043d\u0430\u0443\u0447\u0438\u043b\u0430\u0441\u044c \u0432 route based IPSec (c \u0432\u0435\u0440\u0441\u0438\u0438 \u0441\u043e\u0444\u0442\u0430 9.8), \u0447\u0442\u043e \u043d\u0435\u0441\u043a\u043e\u043b\u044c\u043a\u043e \u0443\u043f\u0440\u043e\u0449\u0430\u0435\u0442 \u043d\u0430\u0441\u0442\u0440\u043e\u0439\u043a\u0443. \u0418 \u0432\u043e\u0442 \u043d\u0430 \u0442\u0435\u043a\u0443\u0449\u0435\u0439 \u0440\u0430\u0431\u043e\u0442\u0435 \u043d\u0435 \u0442\u0430\u043a \u0434\u0430\u0432\u043d\u043e \u043f\u0440\u0435\u0434\u0441\u0442\u0430\u0432\u0438\u043b\u0441\u044f \u0448\u0430\u043d\u0441 \u0441\u043d\u043e\u0432\u0430 \u0441\u043e\u0431\u0440\u0430\u0442\u044c \u0442\u0430\u043a\u0443\u044e \u0441\u0445\u0435\u043c\u0443. \u0418 \u0441\u043d\u043e\u0432\u0430 \u043d\u0435\u0443\u0434\u0430\u0447\u043d\u043e \u2014 \u043f\u0440\u0438 \u0440\u0435\u0433\u0435\u043d\u0435\u0440\u0430\u0446\u0438\u0438 \u0442\u0443\u043d\u043d\u0435\u043b\u044c \u0431\u043b\u0430\u0433\u043e\u043f\u043e\u043b\u0443\u0447\u043d\u043e \u043f\u0430\u0434\u0430\u043b (\u0438 \u043d\u0435 \u0432\u0441\u0435\u0433\u0434\u0430 \u043f\u043e\u0434\u043d\u0438\u043c\u0430\u043b\u0441\u044f \u0431\u0435\u0437 \u0440\u0443\u0447\u043d\u043e\u0433\u043e \u0440\u0435\u0441\u0442\u0430\u0440\u0442\u0430). \u0418 \u0441\u043d\u043e\u0432\u0430 \u0432 \u043b\u043e\u0433\u0430\u0445 \u0442\u0438\u0448\u0438\u043d\u0430 \u0438 \u043d\u0435\u043f\u043e\u043d\u044f\u0442\u043a\u0438, \u0430 \u0442.\u043a. ASA \u043d\u0430\u0445\u043e\u0434\u0438\u043b\u0430\u0441\u044c \u0443 \u043d\u0430\u0448\u0435\u0433\u043e \u043f\u0430\u0440\u0442\u043d\u0451\u0440\u0430, \u0442\u043e \u0438 \u0434\u0435\u0431\u0430\u0436\u0438\u0442\u044c, \u0441\u043e\u043e\u0442\u0432\u0435\u0442\u0441\u0442\u0432\u0435\u043d\u043d\u043e, \u043d\u0435 \u0431\u044b\u043b\u043e \u043d\u0438\u043a\u0430\u043a\u043e\u0439 \u0432\u043e\u0437\u043c\u043e\u0436\u043d\u043e\u0441\u0442\u0438.<br \/>  \u0418 \u0432\u043e\u0442 \u0442\u0435\u043f\u0435\u0440\u044c \u043f\u0440\u0435\u0434\u0441\u0442\u0430\u0432\u0438\u043b\u0441\u044f \u0441\u043b\u0443\u0447\u0430\u0439 \u0441\u043e\u0431\u0440\u0430\u0442\u044c \u0441\u0445\u0435\u043c\u0443, \u043f\u0440\u0438 \u043a\u043e\u0442\u043e\u0440\u043e\u0439 \u043e\u0431\u0435 \u0441\u0442\u043e\u0440\u043e\u043d\u044b (\u0438 SRX, \u0438 ASA) \u043d\u0430\u0445\u043e\u0434\u044f\u0442\u0441\u044f \u043f\u043e\u0434 \u043d\u0430\u0448\u0438\u043c \u0443\u043f\u0440\u0430\u0432\u043b\u0435\u043d\u0438\u0435\u043c, \u0441\u043e\u043e\u0442\u0432\u0435\u0442\u0441\u0442\u0432\u0435\u043d\u043d\u043e, \u043f\u043e\u0438\u0433\u0440\u0430\u0442\u044c\u0441\u044f \u043c\u043e\u0436\u043d\u043e \u043d\u0430 \u0441\u043b\u0430\u0432\u0443.<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[],"tags":[],"class_list":["post-296287","post","type-post","status-publish","format-standard","hentry"],"_links":{"self":[{"href":"https:\/\/savepearlharbor.com\/index.php?rest_route=\/wp\/v2\/posts\/296287","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/savepearlharbor.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/savepearlharbor.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/savepearlharbor.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/savepearlharbor.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=296287"}],"version-history":[{"count":0,"href":"https:\/\/savepearlharbor.com\/index.php?rest_route=\/wp\/v2\/posts\/296287\/revisions"}],"wp:attachment":[{"href":"https:\/\/savepearlharbor.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=296287"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/savepearlharbor.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=296287"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/savepearlharbor.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=296287"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}