IPsec VPN
Network

IPsec VPN

1. IPsec VPN

- Site to Site๋กœ ๋งบ๋Š” VPN์ž…๋‹ˆ๋‹ค.
- IETF์—์„œ ๊ถŒ๊ณ ํ•˜๋Š” IPsec ๊ธฐ์ˆ ์„ ์ค€์ˆ˜ํ•˜์—ฌ ๋งŒ๋“  VPN์ž…๋‹ˆ๋‹ค.
- ๊ฐ Site์˜ ๊ฒŒ์ดํŠธ์›จ์ด ์žฅ๋น„๋ผ๋ฆฌ ์–ด๋– ํ•œ ๋ฐฉ์‹์œผ๋กœ ์•”ํ˜ธํ™”๋ฅผ ํ• ์ง€ ๊ฒฐ์ •ํ•˜์—ฌ ๋™์ผํ•˜๊ฒŒ ์„ค์ •ํ•ด์•ผ ํ•ฉ๋‹ˆ๋‹ค.
- ๊ณต์ธ IP๊ฐ€ ์•„๋‹Œ ์‚ฌ์„ค IP๋กœ ํ†ต์‹  ๊ฐ€๋Šฅํ•ฉ๋‹ˆ๋‹ค.
- Site to Site๋กœ IPsec VPN์„ ๋งบ๊ธฐ ์œ„ํ•ด์„œ๋Š” Remote ๋‹ด๋‹น์ž์™€ ์•„๋ž˜ ์ •๋ณด(์ข…๋ฅ˜, ๋ชจ๋“œ, ์•Œ๊ณ ๋ฆฌ์ฆ˜ ๋“ฑ) ๊ฒฐ์ •์ด ํ•„์š”ํ•ฉ๋‹ˆ๋‹ค.

2. IPsec VPN ์ข…๋ฅ˜์™€ ๋ชจ๋“œ

์ข…๋ฅ˜
- AH(Authentication Header) : ๋ฌด๊ฒฐ์„ฑ, ์ธ์ฆ๋งŒ ๊ฒ€์ฆํ•ฉ๋‹ˆ๋‹ค. ๊ธฐ๋ฐ€์„ฑ์„ ์œ„ํ•œ ์•”ํ˜ธํ™”๊ฐ€ ์‚ฌ์šฉ๋˜์ง€ ์•Š์•„ ๊ฑฐ์˜ ์‚ฌ์šฉํ•˜์ง€ ์•Š์Šต๋‹ˆ๋‹ค.
- ESP(Encapsulation Security Payload) : AH + ๊ธฐ๋ฐ€์„ฑ์„ ์œ„ํ•œ ์•”ํ˜ธํ™”๊นŒ์ง€ ๊ฒ€์ฆํ•ฉ๋‹ˆ๋‹ค.

๋ชจ๋“œ
- ์ „์†ก ๋ชจ๋“œ(Transport Mode) : IP ํ—ค๋”๋ฅผ ์ œ์™ธํ•˜๊ณ  ์ƒ์œ„ ๊ณ„์ธต๋งŒ ์•”ํ˜ธํ™”ํ•ฉ๋‹ˆ๋‹ค. IP ํ—ค๋”๊ฐ€ ๋…ธ์ถœ๋˜๊ธฐ ๋•Œ๋ฌธ์— Source to Destination ์ •๋ณด๊ฐ€ ๋…ธ์ถœ๋œ๋‹ค. ๊ฐ„๋‹จํ•˜๊ฒŒ ์ •๋ฆฌํ•ด์„œ ์–ด๋–ค Source์—์„œ ์–ด๋–ค Destiantion์œผ๋กœ ๋ณด๋‚ด๋Š”์ง€ ์•Œ ์ˆ˜ ์žˆ๋‹ค!

- ํ„ฐ๋„ ๋ชจ๋“œ(Tunnel Mode) : IP ํ—ค๋”๋ฅผ ํฌํ•จํ•˜์—ฌ ๋ชจ๋‘ ์•”ํ˜ธํ™”ํ•ฉ๋‹ˆ๋‹ค. IP ํ—ค๋”๊ฐ€ ๋…ธ์ถœ๋˜์ง€ ์•Š๊ธฐ ๋•Œ๋ฌธ์— ์•„๋ฌด๊ฒƒ๋„ ๋…ธ์ถœ๋˜์ง€ ์•Š์Šต๋‹ˆ๋‹ค. ๋‹ค๋งŒ ํ†ต์‹ ์„ ์œ„ํ•˜์—ฌ ์‹ ๊ทœ IP ํ—ค๋”๊ฐ€ ๋ถ™๋Š”๋ฐ ํ•ด๋‹น ํ—ค๋”๋Š” Gateway to Gateway ์ •๋ณด๋ฅผ ๋‹ด๊ณ  ์žˆ์Šต๋‹ˆ๋‹ค. ๊ฐ„๋‹จํ•˜๊ฒŒ ์–ด๋–ค Gateway์—์„œ ์–ด๋–ค Gateway๋กœ ๊ฐ€๋Š”์ง€๋งŒ ์•Œ ์ˆ˜ ์žˆ๋‹ค! ์‹ค์ œ Source์™€ Destinatio์€ ์•”ํ˜ธํ™”๋˜์–ด ๋ณผ ์ˆ˜ ์—†๋‹ค!

3. IKE ํ”„๋กœํ† ์ฝœ

IKE(Internet Key Exchange) ํ”„๋กœํ† ์ฝœ
- IPsec VPN์„ ์œ„ํ•˜์—ฌ ๋ณด์•ˆ(SA : Security Association) ๊ด€๋ จ ์„ค์ •/์ƒ์„ฑ/ํ˜‘์ƒ/๊ด€๋ฆฌ

IKE ํ”„๋กœํ† ์ฝœ ๋ฒ„์ „
- ๋ฒ„์ „ 1(Phase 1 : Main/Aggressive Mode, Phase 2 : Quick Mode) : ํ‚ค ๊ตํ™˜ ๊ณผ์ •์€ ์ตœ์†Œ 6๋ฒˆ(Aggressive Mode/Quick Mode) ์ตœ๋Œ€ 9๋ฒˆ(Main Mode/Quick Mode) ํ•„์š”ํ•ฉ๋‹ˆ๋‹ค. Main ๋ชจ๋“œ๋Š” ์„ธ์…˜ ID๊ฐ€ ๋ณดํ˜ธ๋˜์ง€๋งŒ Aggressive ๋ชจ๋“œ์—์„œ๋Š” ๋ณดํ˜ธ๋˜์ง€ ์•Š์œผ๋ฉฐ ๊ตํ™˜ ๊ณผ์ •์ด ๋‹จ์ถ•๋˜์—ˆ์Šต๋‹ˆ๋‹ค.

Phase 1 : Main Mode
Phase 1 : Aggressive Mode
Phase 2 : Quick Mode

- ๋ฒ„์ „ 2(Mode X): ํ‚ค ๊ตํ™˜ ๊ณผ์ •์€ 4๋ฒˆ ํ•„์š”ํ•ฉ๋‹ˆ๋‹ค. ๋ฒ„์ „ 1๋ณด๋‹ค ๊ฐ€๋ณ๊ณ  DDoS ๊ณต๊ฒฉ ์ทจ์•ฝ์ ์ด ๊ฐœ์„ ๋˜์—ˆ์Šต๋‹ˆ๋‹ค.

- ๋‘ ๋ฒ„์ „์€ ํ˜ธํ™˜๋˜์ง€ ์•Š์Šต๋‹ˆ๋‹ค.

IKE ํ”„๋กœํ† ์ฝœ Phase 1
- ๋ณด์•ˆ ์„ค์ •์„ ์œ„ํ•˜์—ฌ ํ„ฐ๋„๋ง(IKE/SAKMP SA)์„ ์ƒ์„ฑํ•˜๊ธฐ ์œ„ํ•œ ์„ค์ •์ž…๋‹ˆ๋‹ค.
- ์ƒ์„ฑ๋œ ๋Œ€์นญํ‚ค(๋น„๊ณต๊ฐœํ‚ค)๋Š” Phase 2 ์•”ํ˜ธํ™”์— ์‚ฌ์šฉ๋ฉ๋‹ˆ๋‹ค.
- ํ‚ค ๊ตํ™˜/์•”ํ˜ธํ™”/ํ•ด์‰ฌ ์•Œ๊ณ ๋ฆฌ์ฆ˜๊ณผ Key Lifetime์„ ๊ฒฐ์ •์ด ํ•„์š”ํ•ฉ๋‹ˆ๋‹ค.

IKE ํ”„๋กœํ† ์ฝœ Phase 2
- ์‹ค์ œ ๋ฐ์ดํ„ฐ๋ฅผ ์•”ํ˜ธํ™”ํ•˜๊ธฐ ์œ„ํ•˜์—ฌ ํ„ฐ๋„๋ง(IPsec/Child SA)์„ ์ƒ์„ฑํ•˜๊ธฐ ์œ„ํ•œ ์„ค์ •์ž…๋‹ˆ๋‹ค.
- ์ƒ์„ฑ๋œ ๋Œ€์นญํ‚ค(๋น„๊ณต๊ฐœํ‚ค)๋Š” ์‹ค์ œ ๋ฐ์ดํ„ฐ ์•”ํ˜ธํ™”์— ์‚ฌ์šฉ๋ฉ๋‹ˆ๋‹ค.
- ํ‚ค ๊ตํ™˜/์•”ํ˜ธํ™”/ํ•ด์‰ฌ ์•Œ๊ณ ๋ฆฌ์ฆ˜๊ณผ Key Lifetime์„ ๊ฒฐ์ •์ด ํ•„์š”ํ•ฉ๋‹ˆ๋‹ค.

์ธ์ฆ ์•Œ๊ณ ๋ฆฌ์ฆ˜
- ์ธ์ฆ์„ ํ•˜๊ธฐ ์œ„ํ•œ ์•Œ๊ณ ๋ฆฌ์ฆ˜์ž…๋‹ˆ๋‹ค.
- Pre Shared Key, RSA Encryption, RSA Signature ๋“ฑ์ด ์žˆ์Šต๋‹ˆ๋‹ค.

ํ‚ค ๊ตํ™˜ ์•Œ๊ณ ๋ฆฌ์ฆ˜
- ์•”ํ˜ธํ™”์— ์‚ฌ์šฉํ•  ๋Œ€์นญํ‚ค๋ฅผ ๊ตํ™˜ํ•˜๊ธฐ ์œ„ํ•œ ์•Œ๊ณ ๋ฆฌ์ฆ˜์ž…๋‹ˆ๋‹ค.
- DH ๋“ฑ์ด ์žˆ์Šต๋‹ˆ๋‹ค.

์•”ํ˜ธํ™” ์•Œ๊ณ ๋ฆฌ์ฆ˜
- ๋ฐ์ดํ„ฐ ๊ธฐ๋ฐ€์„ฑ์„ ๊ฒ€์ฆํ•˜๊ธฐ ์œ„ํ•œ ์•Œ๊ณ ๋ฆฌ์ฆ˜์ž…๋‹ˆ๋‹ค.
- SEED, AES ๋“ฑ์ด ์žˆ์Šต๋‹ˆ๋‹ค

ํ•ด์‰ฌ ์•Œ๊ณ ๋ฆฌ์ฆ˜
- ๋ฐ์ดํ„ฐ ๋ฌด๊ฒฐ์„ฑ์„ ๊ฒ€์ฆํ•˜์—ฌ ์ธ์ฆํ•˜๊ธฐ ์œ„ํ•œ ์•Œ๊ณ ๋ฆฌ์ฆ˜์ž…๋‹ˆ๋‹ค.
- MD5, SHA 1, SHA 256 ๋“ฑ์ด ์žˆ์Šต๋‹ˆ๋‹ค.

Key Lifetime
- ํ•ด๋‹น ์‹œ๊ฐ„๋™์•ˆ ์•”ํ˜ธํ™” ๋ฐฉ์‹ ์ €์žฅํ•ฉ๋‹ˆ๋‹ค.

PFS(Perfect Forward Secrecy)
- DH ์•Œ๊ณ ๋ฆฌ์ฆ˜์„ ํ†ตํ•˜์—ฌ ํ‚ค๋ฅผ ๊ตํ™˜ํ•  ๊ฒฝ์šฐ ์‚ฌ์šฉํ•  ์ˆ˜ ์žˆ๋Š” ๊ธฐ๋Šฅ์œผ๋กœ ์„ธ์…˜ ํ‚ค๋ฅผ ์ง€์†์ ์œผ๋กœ ๋ณ€๊ฒฝํ•˜์—ฌ ๋Œ€์นญํ‚ค(๋น„๊ณต๊ฐœํ‚ค)๊ฐ€ ๋…ธ์ถœ๋˜๋”๋ผ๋„ ๊ณผ๊ฑฐ์˜ ๋ฐ์ดํ„ฐ๋Š” ๋ณตํ˜ธํ™”ํ•  ์ˆ˜ ์—†๋„๋ก ํ•˜์—ฌ ๋ณด์•ˆ์„ ๋†’์ž…๋‹ˆ๋‹ค.

MTU Size
- IPsec VPN ํŠธ๋ž˜ํ”ฝ์˜ MTU Size๋ฅผ ์„ค์ •ํ•ฉ๋‹ˆ๋‹ค. IPsec VPN์„ ๋งบ์„ ๊ฒฝ์šฐ ํ—ค๋”๊ฐ€ ๋Š˜์–ด๋‚˜ 1500๋ณด๋‹ค ๋‚ฎ๊ฒŒ MTU Size๋ฅผ ์„ค์ •ํ•ด์ค๋‹ˆ๋‹ค.
- AWS์™€ IPsec VPN์„ ๋งบ์„ ๊ฒฝ์šฐ MTU Size๋ฅผ 1399๋กœ ์„ค์ •ํ•ด์ค˜์•ผ ํ•ฉ๋‹ˆ๋‹ค.

NAT Traveral
- IKE ํ”„๋กœํ† ์ฝœ์€ UDP 500์„ ํ†ตํ•ด ํ†ต์‹ ํ•˜๊ณ  ์‹ค์ œ ๋ฐ์ดํ„ฐ์— ESP ํ”„๋กœํ† ์ฝœ์€ 50์„ ํ†ตํ•ด ํ†ต์‹ ํ•˜๊ฒŒ ๋˜๋Š”๋ฐ ESP์˜ ๊ฒฝ์šฐ IP ํ”„๋กœํ† ์ฝœ์ด๋ผ IP/Port NAT๋ฅผ ์ง€์›ํ•˜์ง€ ๋ชปํ•ด ์ƒ๊ธด ๊ธฐ๋Šฅ์ž…๋‹ˆ๋‹ค.
- ํ•ด๋‹น ๊ธฐ๋Šฅ์ด ์ผœ์ ธ์žˆ์œผ๋ฉด ์ตœ์ดˆ UDP 500์œผ๋กœ VPN ํ˜‘์ƒ์„ ์‹œ๋„ํ•˜๋‹ค๊ฐ€ ์ค‘๊ฐ„์— NAT ์žฅ๋น„๋ฅผ ๋ฐœ๊ฒฌํ•˜๊ฒŒ ๋˜๋ฉด์€ UDP 4500์œผ๋กœ VPN์„ ํ˜‘์ƒํ•ฉ๋‹ˆ๋‹ค. (ํ˜‘์ƒ ์™„๋ฃŒ ํ›„์—๋„ UDP 4500์„ ์‚ฌ์šฉํ•ฉ๋‹ˆ๋‹ค.)

์ฐธ๊ณ  :
https://liveyourit.tistory.com/4

[๋„คํŠธ์›Œํฌ] IPSecVPN์˜ ์ •์˜์™€ ๋‘๊ฐ€์ง€ ๋ชจ๋“œ(์ „์†ก๋ชจ๋“œ, ํ„ฐ๋„๋ชจ๋“œ)

์ง€๋‚œ ํฌ์ŠคํŒ…์—์„œ๋Š” VPN์ด๋ž€ ๋ฌด์—‡์ธ์ง€ ๊ฐ„๋‹จํžˆ ์•Œ์•„๋ณด์•˜๋‹ค. ์ด๋ฒˆ์—” VPN ์ค‘ ํ•˜๋‚˜๋กœ ๋ณดํŽธ์ ์œผ๋กœ ์‚ฌ์šฉ๋˜๋Š” IPSecVPN๊ณผ ๋‘๊ฐ€์ง€ ๋ชจ๋“œ์ธ ์ „์†ก๋ชจ๋“œ์™€ ํ„ฐ๋„๋ชจ๋“œ์— ๋Œ€ํ•ด ์•Œ์•„๋ณธ๋‹ค. ์–ด๋–ค ๋ชจ๋“œ์ธ์ง€๋ณด๋‹ค๋„ ๋” ์ค‘

liveyourit.tistory.com

https://www.omnisecu.com/tcpip/ikev2-phase-1-and-phase-2-message-exchanges.php

IKEv2 Phase 1 (IKE SA) and Phase 2 (Child SA) Message Exchanges

www.omnisecu.com

https://www.minzkn.com/moniwiki/wiki.php/VirtualPrivateNetwork#s-1.2.3.3

MINZKN

programming

www.minzkn.com

https://www.cisco.com/c/ko_kr/support/docs/security-vpn/ipsec-negotiation-ike-protocols/115936-understanding-ikev2-packet-exch-debug.html

IKEv2 ํŒจํ‚ท ๊ตํ™˜ ๋ฐ ํ”„๋กœํ† ์ฝœ ๋ ˆ๋ฒจ ๋””๋ฒ„๊น…

์ด ๋ฌธ์„œ์—์„œ๋Š” ์ตœ์‹  ๋ฒ„์ „์˜ IKE(Internet Key Exchange)์˜ ์žฅ์ ๊ณผ ๋ฒ„์ „ 1๊ณผ ๋ฒ„์ „ 2์˜ ์ฐจ์ด์ ์„ ์„ค๋ช…ํ•ฉ๋‹ˆ๋‹ค.

www.cisco.com