๐Ÿ“‚๋„คํŠธ์›Œํฌ&์„œ๋ฒ„/๐ŸŒ๋„คํŠธ์›Œํฌ

๐Ÿ’๋„คํŠธ์›Œํฌ 17์ผ์ฐจ(5.4) ๋ฐฉํ™”๋ฒฝ ์„ค์ •ํ•˜๊ธฐ, Access-list, BGP(Border Gateway Protocol) ์„ค์ •ํ•˜๊ธฐ

๐Ÿ‘ฉ‍๐ŸŽ“์ธํ…”๋ฆฌ๊ฐ์ž๐Ÿฅ” 2023. 5. 21. 16:59

์ง€๋‚œ ์‹œ๊ฐ„ ์š”์•ฝ

๋ผ์šฐํ„ฐ์—์„œ  ACL์€ ํŠน์ • ํ˜ธ์ŠคํŠธ๋‚˜ ๋„คํŠธ์›Œํฌ, ์„œ๋น„์Šค์— ๋Œ€ํ•œ ์ œํ•œ์„ ์„ค์ •ํ•˜๋Š” ๊ธฐ๋ฒ•
Wildmask๋Š” subnetmask ํ˜•์‹์œผ๋กœ ํ˜ธ์ŠคํŠธ๋ฅผ ํ‘œ์‹œํ•˜๋Š” ๊ธฐ๋ฒ•์œผ๋กœ NATACLOSPF์—์„œ ์‚ฌ์šฉ๋œ๋‹ค.


passive interface๋Š” ๋ผ์šฐํ„ฐ์˜ ํŠน์ • ์ธํ„ฐํŽ˜์ด์Šค์— ์„ค์ •ํ•ด์„œ ๋‚ด๋ถ€ ๋„คํŠธ์›Œํฌ์˜ ์ •๋ณด๊ฐ€ ์™ธ๋ถ€๋กœ ๋…ธ์ถœ๋˜์ง€ ์•Š๊ฒŒ ํ•œ๋‹ค.
=>์Šค์œ„์น˜์—์„œ VLAN์˜ VTP ์„ค์ •์—์„œ  Transparent mode ์„ค์ •๊ณผ ์œ ์‚ฌํ•˜๋‹ค.
    ์Šค์œ„์น˜์—์„œ๋Š” ํŠน์ • ํฌํŠธ๋กœ ์—ฐ๊ฒฐ๋˜๋Š” MAC ์ฃผ์†Œ๋ฅผ ์ง€์ •ํ•˜๋Š” port security ๊ธฐ๋ฒ•๋„ ์žˆ๋‹ค.


distribute list๋Š” ์˜์‹ฌ์Šค๋Ÿฌ์šด ๋„คํŠธ์›Œํฌ๊ฐ€ ๋ผ์šฐํ„ฐ๋กœ ๋“ค์–ด์˜ค์ง€ ๋ชปํ•˜๊ฒŒ ๋ง‰๋Š” ์„ค์ •์œผ๋กœ ACL๊ณผ ์—ฐ๊ณ„ํ•ด์„œ ์‚ฌ์šฉ๋œ๋‹ค.
=>์˜์‹ฌ์Šค๋Ÿฌ์šด ๋„คํŠธ์›Œํฌ๋ฅผ ๋ถˆ์‹ ํ•˜๋Š” ๋ง‰๋Š” ๋ฐฉ๋ฒ•์œผ๋กœ Distance Vector(RIP, RIPv2, IGRP)์—์„œ Administrative distance๋ฅผ 255๋กœ ์„ค์ •ํ•˜๊ฑฐ๋‚˜ Metric์„ ๋ฌดํ•œ๋Œ€(๋งค์šฐ ํฐ ์ˆ˜)๋กœ ์ง€์ •ํ•˜๋ฉด ๋œ๋‹ค. 


=>ํŠน์ • ์ธํ„ฐํŽ˜์ด์Šค๋กœ ์—ฐ๊ฒฐ๋˜๋Š” ๊ฒƒ์„ ๋ง‰๋Š” ๊ธฐ๋ฒ•์œผ๋กœ 
   no ssh input, no password input, set time 0  ..... ๋“ฑ์ด ์žˆ๋‹ค. 

 

  ๋ฐฉํ™”๋ฒฝ ์„ค์ •ํ•˜๊ธฐ

  ์ •์  ๋ผ์šฐํŒ… ์„ค์ •์€ ๋ฐฉํ™”๋ฒฝ์ด ์žˆ๋Š” ๋‚ด๋ถ€-์™ธ๋ถ€ ๋„คํŠธ์›Œํฌ ์„ค์ •์—์„œ๋„ ๋งค์šฐ ์š”๊ธดํ•˜๊ฒŒ ์‚ฌ์šฉ๋œ๋‹ค. ๋ฐฉํ™”๋ฒฝ์„ ์„ค์น˜ํ•˜๋ฉด FW ์žฅ๋น„๋ฅผ ์ค‘์‹ฌ์œผ๋กœ ๋‚ด๋ถ€์™€ ์™ธ๋ถ€๋ฅผ ๊ฐ๊ฐ VLAN 1(WAN)๊ณผ VLAN 2 (LAN)๋กœ ๋ถ„ํ• ํ•ด์„œ Inside์™€ Outside๋กœ ์„ค์ •ํ•˜๊ฒŒ ํ•œ๋‹ค. ๋ฐฉํ™”๋ฒฝ์—์„œ์˜ Security Level์€ 1~100๊นŒ์ง€ ์žˆ๋Š”๋ฐ ๋ณดํ†ต ๋‚ด๋ถ€ LAN์ด ์žˆ๋Š” Inside zone์€ 100์œผ๋กœ ํ•ด์„œ ์™ธ๋ถ€์—์„œ ๋šซ๊ณ  ๋“ค์–ด์˜ค๊ธฐ ์–ด๋ ต๊ฒŒ ํ•˜๊ณ , ์™ธ๋ถ€ WAN์ด ์žˆ๋Š” Outside zone์€ 0์œผ๋กœ ํ•ด์„œ ๋‚ด๋ถ€์—์„œ ์‰ฝ๊ฒŒ ์™ธ๋ถ€๋กœ ๋‚˜๊ฐ€๊ฒŒ ํ•œ๋‹ค. ์ด๋ ‡๊ธฐ ๋•Œ๋ฌธ์— ํ•ด์ปค๋Š” ์™ธ๋ถ€์—์„œ ๋ฐฉํ™”๋ฒฝ์„ ๋šซ๊ณ  ๋“ค์–ด์˜ค๋Š” ํ•ดํ‚น๋ณด๋‹ค ์†Œ์…œ ์—”์ง€๋‹ˆ์–ด๋ง ๋“ฑ์œผ๋กœ ๋‚ด๋ถ€์—์„œ ํ•ดํ‚นํ•˜๋Š” ๊ฒƒ์„ ์„ ํ˜ธํ•œ๋‹ค. ๋ผ์šฐํ„ฐ์™€ ๋ฐฉํ™”๋ฒฝ ์‚ฌ์ด์— Management zone์œผ๋กœ ๋งŒ๋“ค๊ณ  1-99 ์‚ฌ์ด์˜ ๋ณด์•ˆ ๋ ˆ๋ฒจ์„ ๋ณ„๋„๋กœ ์ง€์ •ํ•  ์ˆ˜๋„ ํ•œ๋‹ค. 

 

๋ฐฉํ™”๋ฒฝ ์‹ค์Šต

RT ์„ค์ •

๋”๋ณด๊ธฐ

Router>en

Router#conf t

Enter configuration commands, one per line. End with CNTL/Z.

Router(config)#host RT

RT(config)#int fa1/0

RT(config-if)#ip addr 201.1.1.1 255.255.255.252

RT(config-if)#no shut

 

RT(config-if)#

%LINK-5-CHANGED: Interface FastEthernet1/0, changed state to up

 

%LINEPROTO-5-UPDOWN: Line protocol on Interface FastEthernet1/0, changed state to up

int fa0/0

RT(config-if)#ip addr 8.8.8.5 255.255.255.252

RT(config-if)#no shut

 

RT(config-if)#

%LINK-5-CHANGED: Interface FastEthernet0/0, changed state to up

 

%LINEPROTO-5-UPDOWN: Line protocol on Interface FastEthernet0/0, changed state to up

int s2/0

RT(config-if)#ip addr 10.10.10.2 255.255.255.252

RT(config-if)#no shut

 

RT(config-if)#

%LINK-5-CHANGED: Interface Serial2/0, changed state to up

exit

RT(config)#router ospf 10

RT(config-router)#net 201.1.1.0 0.0.0.3 area 0

RT(config-router)#net 8.8.8.0 0.0.0.3 area 0

RT(config-router)#net 10.10.10.0 0.0.0.3 area 0

RT(config-router)#end

DNS ์„ค์ •๋„ ํ•ด์ค€๋‹ค. 

์ด์ œ FW1 ์„ค์ •ํ•ด์ฃผ๋Ÿฌ ๊ฐ„๋‹ค.

๋ณ€๊ฒฝ

int vlan 1

ip addr 192.168.1.1 255.255.255.0

nameif inside ๋„ค์ž„์ธํ„ฐํŽ˜์ด์Šค ์ธ์‚ฌ์ด

security-level 100(์™ธ๋ถ€์—์„œ ๋‚ด๋ถ€๋กœ ๋“ค์–ด์˜ฌ ๋•Œ ์–ด๋ ต๊ฒŒ ํ•ด๋ผ)

no shut

 

int e0/1

switchport access vlan 1 ์ด๋”๋„ท ์Šค์œ„์น˜ํฌํŠธ๋ฅผ vlan1์— ๊ฐ€์ž…์‹œํ‚ด 

 

vlan 2๋Š” outside๋กœ ๋‚˜๊ฐˆ ๋•Œ ์•„์ฃผ ์‰ฝ๊ฒŒ security level๋งŒ 0์œผ๋กœ ํ•ด์„œ ์„ค์ •!

 

dhcpd address 192.168.1.10-192.168.1.20 inside DHCP๊ฐ€ ์ฃผ์†Œ๋ฅผ ์ž„๋Œ€ํ•ด์ค€๋‹ค.
dhcpd dns 8.8.8.6 int inside

 

!!when dhcpd spread its information, they are host_ip_address, subnetmask, dns_server, and gateway_address, and administrator only assigns workgroup and host_name

 

DHCP๊ฐ€ ์ž๋™์œผ๋กœ ์ฃผ์†Œ๋ฅผ ๋ฐ›์•˜๊ณ  DNS ์„œ๋ฒ„๋„ 8.8.8.6์ด๋‹ค. stubํ•œ ๋„คํŠธ์›Œํฌ์˜ 0.0.0.0 ๋””ํดํŠธ ๊ฒŒ์ดํŠธ์›จ์ด ์ฃผ์†Œ๋‹ค.

์ฆ‰, ๋ผ์šฐํ„ฐ์—๋‹ค DHCP ์„œ๋ฒ„๋ฅผ ์„ค์ •ํ•ด์„œ ๋…ธ๋“œ๊ฐ€ ์ž๋™์œผ๋กœ ์ฃผ์†Œ๋ฅผ ๋ฐ›๊ฒŒ ํ•  ์ˆ˜ ์žˆ๋‹ค.

 

๋…ธ๋“œ๋ผ๋ฆฌ ์„œ๋กœ ํ•‘๋„ ๊ฐ„๋‹ค.

 

route outside 0.0.0.0 0.0.0.0 201.1.1.1

 

 

=>object network๋ฅผ inside์— ์ ์šฉํ•œ๋‹ค. object network๋Š” ํŠน์ • ๋Œ€์—ญํญ์ด๋‚˜ ์„œ๋น„์Šค๋ฅผ ๊ฐ์ฒด(object)๋กœ ๋งŒ๋“ค์–ด์„œ ๊ด€๋ฆฌํ•˜๋Š” ๊ธฐ๋ฒ•์œผ๋กœ์จ dhcp = network setting, ospf = network setting, ...์‹์œผ๋กœ ์„ค์ •ํ•œ ๋’ค ๊ฐ„๋‹จํžˆ dhcp, ospf๋กœ ์ ์šฉ์‹œํ‚ฌ ์ˆ˜ ์žˆ๋‹ค. ๋‹จ์ถ•ํ‚ค๋‚˜ ๊ฐ€์ƒ์˜ ๊ฐœ๋…์œผ๋กœ ACL์ด๋‚˜ VPN ๋“ฑ์—์„œ๋„ ์‚ฌ์šฉ๋œ๋‹ค. 

object network LAN

subnet 192.168.1.0 255.255.255.0

 

NAT ์„ค์ •

nat (inside,outside) dynamic int

 

 

access-list in2out extended permit tcp any any (์ผ๋ฐ˜ entry ์ง€์ •)

access-group in2out in int outside (in/out ์ง€์ •)

 

ACL์—์„œ access-list๋Š” Router(config)#์ธ ๊ธ€๋กœ๋ฒŒ ๋ชจ๋“œ์—์„œ ์„ค์ •ํ•ด์ค€๋‹ค. ์ผ๋ฐ˜ entry๋ฅผ ์ง€์ •
            access-group์€ Router(config-int)#์ธ ๋กœ์ปฌ ๋ชจ๋“œ์—์„œ ์„ค์ •ํ•ด์ค€๋‹ค. in/out์„ ์ง€์ •

 

access-list in2out extended permit icmp any any

!!!!! access-list in2out extended permit any any

 


  ์™ธ๋ถ€์—์„œ ์„ค์ •์„ ์œ„ํ•ด์„œ Telnet์œผ๋กœ ๋“ค์–ด์˜ค๋ ค๋ฉด 
1) password setting: enable password, enable secret๋Š” user mode์—์„œ privilege mode๋กœ ๋“ค์–ด๊ฐˆ ๋•Œ ์‚ฌ์šฉ 
2) virtual password setting: line vty 0 4(or vty 2), login local ํ•˜๋ฉด username & password setting OR login ํ•˜๋ฉด password setting๋งŒ ํ•˜๋ฉด ๋œ๋‹ค.


=>iptables, tcpwrapper, ACL ๋“ฑ ์„ค์ •์—์„œ๋Š” ์•”๋ฌต์ (implicity)์œผ๋กœ ๋งจ ์•„๋ž˜์— deny any any๊ฐ€ ๋“ค์–ด๊ฐ€ ์žˆ์–ด์„œ ์ด๋“ค์„ ์„ค์ •ํ•˜๊ณ  entry(๋ˆ„๊ตฐ ๋“ค์–ด์™€๋ผ, ๋ˆ„๊ตฐ ๋“ค์–ด์˜ค์ง€ ๋ง์•„๋ผ)๋ฅผ ์“ฐ์ง€ ์•Š์•„๋„ ๊ทœ์ œ๋œ๋‹ค!!!!
=>๋”ฐ๋ผ์„œ ์ด๋“ค์„ ์ƒ์„ฑํ•ด ๋‘์ง€ ์•Š์œผ๋ฉด ์ž๋™์œผ๋กœ ๋ชจ๋“  ํ”„๋ ˆ์ž„/ํŒจํ‚ท์€ ์ž์œ ๋กญ๊ฒŒ ํ†ต์‹ ํ•œ๋‹ค.

 

+

CHAP, PAP์œผ๋กœ Pivotting์„ ๋ง‰์„ ์ˆ˜ ์žˆ๋‹ค.

 

 

Q: ์ฒซ ๋ฒˆ์งธ entry์—์„œ tcp๋ฅผ ํ—ˆ์šฉํ•œ๋‹ค๋Š” ๋‚ด์šฉ์„ ์ž…๋ ฅํ•˜๊ณ  ์‹คํ–‰ํ•˜๋ฉด ping์ด ์ „๋‹ฌ๋˜์ง€ ์•Š๊ณ , ๋‘ ๋ฒˆ์งธ entry์— icmp๋ฅผ ํ—ˆ์šฉํ•œ๋‹ค๋Š” ๋‚ด์šฉ์„ ์ถ”๊ฐ€ํ•˜๊ณ  ์‹คํ–‰ํ•˜๋ฉด ping์ด ์ „๋‹ฌ๋˜๋Š” ๊ฒŒ ๋งž์•„?

A: ๋„ค, ๋งž์Šต๋‹ˆ๋‹ค. ์ฒซ ๋ฒˆ์งธ entry์—์„œ TCP๋ฅผ ํ—ˆ์šฉํ•˜๊ณ  ๋‘ ๋ฒˆ์งธ entry์—์„œ ICMP๋ฅผ ํ—ˆ์šฉํ•œ๋‹ค๋Š” ๊ฒฝ์šฐ, ping์ด ์ „๋‹ฌ๋˜์ง€ ์•Š๊ณ  ๊ทธ ํ›„์— ping์ด ์ „๋‹ฌ๋˜๋Š” ๊ฒƒ์ด ์˜ฌ๋ฐ”๋ฅธ ๋™์ž‘์ž…๋‹ˆ๋‹ค.

ACL์€ ์ˆœ์„œ๋Œ€๋กœ ํ‰๊ฐ€๋˜๊ธฐ ๋•Œ๋ฌธ์— ์ฒซ ๋ฒˆ์งธ entry๋ถ€ํ„ฐ ์ˆœ์„œ๋Œ€๋กœ ํ™•์ธ๋ฉ๋‹ˆ๋‹ค. ์ฒซ ๋ฒˆ์งธ entry์—์„œ๋Š” TCP๋ฅผ ํ—ˆ์šฉํ•˜๊ณ  ICMP๋ฅผ ๋ช…์‹œํ•˜์ง€ ์•Š์•˜์œผ๋ฏ€๋กœ, ICMP ํŒจํ‚ท์€ ์ฒซ ๋ฒˆ์งธ entry์— ์˜ํ•ด ๊ฑฐ๋ถ€๋ฉ๋‹ˆ๋‹ค. ๊ทธ๋Ÿฌ๋ฏ€๋กœ ping(ICMP)์€ ์ฒซ ๋ฒˆ์งธ entry์—์„œ ์ฐจ๋‹จ๋ฉ๋‹ˆ๋‹ค.

๊ทธ๋Ÿฌ๋‚˜ ๋‘ ๋ฒˆ์งธ entry์—์„œ ICMP๋ฅผ ํ—ˆ์šฉํ•˜๋Š” ๊ทœ์น™์„ ์ถ”๊ฐ€ํ•œ ๊ฒฝ์šฐ, ICMP ํŒจํ‚ท์€ ๋‘ ๋ฒˆ์งธ entry์—์„œ ํ—ˆ์šฉ๋˜๋ฏ€๋กœ ping์ด ์ „๋‹ฌ๋  ๊ฒƒ์ž…๋‹ˆ๋‹ค. ๋‘ ๋ฒˆ์งธ entry์—์„œ ICMP๋ฅผ ํ—ˆ์šฉํ•˜๋Š” ๊ทœ์น™์„ ์ถ”๊ฐ€ํ•˜๋ฉด ์ด์ „์— ์ฐจ๋‹จ๋œ ICMP ํŒจํ‚ท์ด ํ—ˆ์šฉ๋˜๊ฒŒ ๋ฉ๋‹ˆ๋‹ค.

๋”ฐ๋ผ์„œ, ์ฒซ ๋ฒˆ์งธ entry์—์„œ TCP๋ฅผ ํ—ˆ์šฉํ•˜๊ณ  ๋‘ ๋ฒˆ์งธ entry์—์„œ ICMP๋ฅผ ํ—ˆ์šฉํ•˜๋Š” ๊ฒฝ์šฐ, ์ฒซ ๋ฒˆ์งธ entry์—์„œ๋Š” ping(ICMP)์ด ์ฐจ๋‹จ๋˜๊ณ , ๋‘ ๋ฒˆ์งธ entry์—์„œ๋Š” ping(ICMP)์ด ํ—ˆ์šฉ๋˜์–ด ping์ด ์ „๋‹ฌ๋  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.



  BGP(Border Gateway Protocol) ์„ค์ •ํ•˜๊ธฐ

  BGP๋Š” WAN์—์„œ ์„œ๋กœ ๋‹ค๋ฅธ AS ์‚ฌ์ด์—์„œ ์‚ฌ์šฉ๋˜๋Š” EGP์˜ ํ”„๋กœํ† ์ฝœ๋กœ์จ ISP๋ฅผ ์—ฐ๊ฒฐํ•˜๊ฑฐ๋‚˜ ์ผ๋ฐ˜ ๋„คํŠธ์›Œํฌ๊ฐ€ ๋‘ ๊ฐœ ์ด์ƒ์˜ ISP์™€ ๋™์‹œ์— ์—ฐ๊ฒฐ๋˜์–ด ์žˆ์„ ๋•Œ ์‚ฌ์šฉ๋œ๋‹ค. ๋‚ด๋ถ€ LAN์˜ AS ๊ฐ„ ์—ฐ๊ฒฐ์— ์‚ฌ์šฉ๋˜๋Š” IGP๋Š” ๋ฉ€ํ‹ฐ์บ์ŠคํŠธ๋กœ ์šด์šฉ๋˜๋Š”๋ฐ ๋ฐ˜ํ•ด ์™ธ๋ถ€ WAN์˜ AS ๊ฐ„ ์—ฐ๊ฒฐ์— ์‚ฌ์šฉ๋˜๋Š” BGP๋Š” ์œ ๋‹ˆ์บ์ŠคํŠธ๋กœ ์šด์šฉ๋˜๋ฉฐ ๋ฒกํ„ฐ ๋ฉ”ํŠธ๋ฆญ์„ ์‚ฌ์šฉํ•œ๋‹ค. 
  ์˜ˆ๋ฅผ ๋“ค์–ด์„œ AS 100์— ์žˆ๋Š” ๋ผ์šฐํ„ฐ1์ด AS 400์— ์žˆ๋Š” ๋ผ์šฐํ„ฐ4์—๊ฒŒ ์ž์‹ ์˜ 192.168.1.2์˜ ์ •๋ณด๋ฅผ ๋ณด๋‚ด๋ฉด ์˜†์— ์žˆ๋Š” AS 200 ๋ผ์šฐํ„ฐ2๋Š” 100->200:192.168.1.2์œผ๋กœ ์ „๋‹ฌํ•˜๊ณ , ์˜†์˜ AS 300 ๋ผ์šฐํ„ฐ3์€ 100->200->300: 192.168.1.2์‹์œผ๋กœ ์ „๋‹ฌํ•ด์„œ 400์—๊ฒŒ ๋„์ฐฉํ•œ๋‹ค. ๋ผ์šฐํ„ฐ4๋Š” ์ง€๋‚˜์˜จ ๊ฒฝ๋กœ์—์„œ ์ž์‹ ์˜ AS 400์„ ๋นผ๊ณ  ๋‚˜๋จธ์ง€ 100 200 300 ๊ฒฝ๋กœ ์ค‘์—์„œ ์ตœ๋‹จ๊ฑฐ๋ฆฌ๋ฅผ ์„ ํƒํ•ด์„œ ๋ณด๋ƒ„์œผ๋กœ์จ ์Šคํ”Œ๋ฆฟ ํ˜ธ๋ผ์ด์ฆŒ์ด ์‹คํ–‰๋˜์–ด ๋ฃจํ•‘์ด ์ผ์–ด๋‚˜์ง€ ์•Š๋Š”๋‹ค. BGP์— ๋ฌธ์ œ๊ฐ€ ๋ฐœ์ƒํ•˜๋ฉด ์–ด๋Š ์ง€์—ญ ์ „์ฒด๋‚˜ ๊ตญ๊ฐ€๊นŒ์ง€ ๋„คํŠธ์›Œํฌ์— ๋ฌธ์ œ๊ฐ€ ์žˆ์„ ์ˆ˜ ์žˆ๋‹ค. 

  ์„œ๋กœ ๋‹ค๋ฅธ WAN์—์„œ BGP ์‚ฌ์ด์—๋Š” EBGP(External BGP)๋ฅผ ์‚ฌ์šฉํ•˜๊ณ  BGP ๋‚ด๋ถ€์—์„œ๋Š” IBGP(Internal BGP)๋ฅผ ์‚ฌ์šฉํ•œ๋‹ค. EBGP๋Š” TTL์ด 1์ด์–ด์„œ ์ง์ ‘ ์—ฐ๊ฒฐ๋œ ๋ผ์šฐํ„ฐ์—๊ฒŒ ์ •๋ณด๋ฅผ ์ „ํ•˜๊ณ  IBGP๋Š” TTL์ด 255๋ผ์„œ ์ด์›ƒํ•œ ๋ผ์šฐํ„ฐ๋ฅผ ์ฐพ์•„์„œ ์ •๋ณด๋ฅผ ์ „๋‹ฌํ•œ๋‹ค. ๋˜ BGP๋ผ๋ฆฌ๋Š” Open message, Update message, Keepalive message, ๊ทธ๋ฆฌ๊ณ  Notification message๋ฅผ ํ†ตํ•ด์„œ ์„œ๋กœ๋ฅผ ์ธ์‹ํ•˜๊ณ  ์—๋Ÿฌ๊ฐ€ ๋ฐœ์ƒํ•˜๋ฉด ์•Œ๋ ค์„œ ์ด๋ฅผ ์ˆ˜์ •ํ•œ๋‹ค. 

  ๊ฐ„๋‹จํžˆ ์ •๋ฆฌํ•˜๋ฉด 

โ–ช routing protocol : ๊ฒฝ๋กœ๋ฅผ ์ฐพ๋Š” ํ”„๋กœํ† ์ฝœ 
                   =>rip, ospf, eigrp 
โ–ช routed protocol : ์ฐพ์•„๋‚ธ ๊ฒฝ๋กœ๋กœ ์‹ค์ œ ๋ฐ์ดํ„ฐ๋ฅผ ์ „์†กํ•˜๋Š” ํ”„๋กœํ† ์ฝœ 
                  =>ip, ipx(Novell Netware), appletalk(Apple)
โ–ช IGP(Interior Gateway Protocol) : ๋‚ด๋ถ€ ๋ผ์šฐํ„ฐ(AS ๋ฒˆํ˜ธ๊ฐ€ ๋™์ผ) ์ธ์‹ ํ”„๋กœํ† ์ฝœ 
                                   =>ip, ipx(Novell Netwrare), appletalk(Apple)
โ–ช EGP(Exterio Gateway Protocol) : ๊ฐ ์™ธ๋ถ€ ๊ฒฝ๊ณ„ ๋ผ์šฐํ„ฐ(AS ๋ฒˆํ˜ธ๊ฐ€ ๋‹ค๋ฆ„) ์ธ์‹ ํ”„๋กœํ† ์ฝœ 
                                   =>BGP


  BGP ์„ค์ •์€ 
‘neighbor ์ƒ๋Œ€๋ฐฉ_๋ผ์šฐํ„ฐ์˜_์ž…๋ ฅ_ip remote-as ์ƒ๋Œ€๋ฐฉ_bgp_๋ฒˆํ˜ธ’ ํ•œ ๋’ค
‘network ์ƒ๋Œ€๋ฐฉ_๋„คํŠธ์›Œํฌ_์ฃผ์†Œ mask ์ƒ๋Œ€๋ฐฉ_์„œ๋ธŒ๋„ท๋งˆ์Šคํฌ’ ํ•ด์ฃผ๋ฉด ๋œ๋‹ค. 
  BGP ์„ค์ •์„ ํ•˜๋ฉด ๊ฐ ๊ฒฝ๊ณ„ ๋ผ์šฐํ„ฐ์—์„œ Serial ํšŒ์„ ๋งŒ ๋ณด์—ฌ์•ผ ํ•˜๊ณ  ์ž์‹ ์˜ ๋„คํŠธ์›Œํฌ๋Š” ๋ณด์ด์ง€๋งŒ ๋‹ค๋ฅธ ๋„คํŠธ์›Œํฌ์˜ ๋‚ด๋ถ€ ๋„คํŠธ์›Œํฌ๋Š” ๋ณด์ด์ง€ ์•Š์•„์•ผ ํ•œ๋‹ค!!!



'๐Ÿ“‚๋„คํŠธ์›Œํฌ&์„œ๋ฒ„ > ๐ŸŒ๋„คํŠธ์›Œํฌ' ์นดํ…Œ๊ณ ๋ฆฌ์˜ ๋‹ค๋ฅธ ๊ธ€

๐Ÿ‰๋„คํŠธ์›Œํฌ 19์ผ์ฐจ(5.9) ๋ผ์šฐํ„ฐ๋‚˜ ์Šค์œ„์น˜์˜ ํŒจ์Šค์›Œ๋“œ ๋ณ€๊ฒฝ ๋ฐ ์žฌ์„ค์ • HSRP(Hot Standby Response Protocol) VRRP(Virtual Router Redundancy Protocol) Apple ๋„คํŠธ์›Œํฌ  (0) 2023.05.21
๐Ÿฅ•๋„คํŠธ์›Œํฌ 18์ผ์ฐจ(5.8) ๋‚ด๋ถ€ ๋ผ์šฐํŒ… ํ”„๋กœํ† ์ฝœ(IGP)๊ณผ ์™ธ๋ถ€ ๋ผ์šฐํŒ… ํ”„๋กœํ† ์ฝœ(EGP) BGP(Border Gateway Protocol) ์„ค์ •ํ•˜๊ธฐ ๋ณ‘๋ ฌ๊ฒฝ๋กœ HSRP(Hot Standby Routing Protocol) VRRP(Vritual Router Redendancy Protocol)  (0) 2023.05.21
๐Ÿฅ๋„คํŠธ์›Œํฌ 16์ผ์ฐจ(5.3) ํŒจ์‹œ๋ธŒ ์ธํ„ฐํŽ˜์ด์Šค ๋ณ‘๋ ฌ ๊ฒฝ๋กœ ๋ฃจํ”„๋ฐฑ ์ธํ„ฐํŽ˜์ด์Šค(loopback interface) Distribute List(๋ถ„์‚ฐ ๋ฆฌ์ŠคํŠธ) vs Interface Restrict(์ธํ„ฐํŽ˜์ด์Šค ์ œํ•œ)  (0) 2023.05.20
๐Ÿ๋„คํŠธ์›Œํฌ 15์ผ์ฐจ(5.2) ๋ฌด์„  ๋„คํŠธ์›Œํฌ infrastructure mode ac-hoc mode ๋ฌด์„  ์ธ์ฆ ๊ธฐ๋ฒ• WEB ๋ฌด์„  ํ‘œ์ค€ Wi-fi PoE ๋ผ์šฐํ„ฐ ๋ถ€ํŒ… ๊ณผ์ • IOS ๋ฒ„์ „ ๋ผ์šฐํ„ฐ์˜ Looping  (2) 2023.05.06
๐ŸŠ๋„คํŠธ์›Œํฌ 14์ผ์ฐจ(4.28) ์„œ๋ธŒ๋„คํŒ… subnetting ์„œ๋ธŒ๋„คํŒ… ํ•˜๋Š” ์ด์œ  VLSM(Variable Length Subnet Mask) ๊ธฐ๋ฒ•  (0) 2023.05.02