{"id":654,"date":"2016-09-14T15:19:58","date_gmt":"2016-09-14T06:19:58","guid":{"rendered":"http:\/\/www.uturtle.com\/blog\/?p=654"},"modified":"2016-09-14T15:38:53","modified_gmt":"2016-09-14T06:38:53","slug":"ios10-macos%ec%97%90%ec%84%9c-vpn-%ec%9d%b4%ec%9a%a9%ec%9d%84-%ec%9c%84%ed%95%98%ec%97%ac-%ec%9a%b0%eb%b6%84%ed%88%ac%ec%97%90%ec%84%9c-ikev2-%ec%84%9c%eb%b2%84-%ea%b5%ac%ec%b6%95-%eb%b0%a9%eb%b2%95","status":"publish","type":"post","link":"https:\/\/www.jinukbaek.com\/blog\/ko\/archives\/654","title":{"rendered":"iOS10, macOS\uc5d0\uc11c VPN \uc774\uc6a9\uc744 \uc704\ud558\uc5ec \uc6b0\ubd84\ud22c\uc5d0\uc11c IKEv2 \uc11c\ubc84 \uad6c\ucd95 \ubc29\ubc95"},"content":{"rendered":"<p>VPN\uc740 \uc678\ubd80\ub85c\ubd80\ud130 \uaca9\ub9ac\ub41c \uc778\ud2b8\ub77c\ub137\uc744 \uad6c\uc131\ud558\uba74 \uc678\ubd80\uc5d0\uc11c \uc811\uc18d\uc774 \ubd88\uac00\ub2a5\ud55c\ub370 \uc774\ub97c \uac00\ub2a5\ud558\uac8c \ud574\uc8fc\ub294 \uc11c\ube44\uc2a4\uc774\ub2e4. \ubb3c\ub9ac\uc801\uc73c\ub85c \uc11c\ub85c \ub5a8\uc5b4\uc838 \uc788\ub294 \ud68c\uc0ac \ub124\ud2b8\uc6cc\ud06c\ub97c \uc678\ubd80\uc5d0 \uacf5\uac1c\ud558\uc9c0 \uc54a\uc73c\uba74\uc11c \ud1b5\uc2e0\ud558\uae30 \uc704\ud574 \ub9cc\ub4e4\uc5b4 \uc84c\ub2e4. \ubb3c\ub860 \ud68c\uc0ac \ub124\ud2b8\uc6cc\ud06c\uc5d0\uc11c \uc0ac\uc6a9\ud558\uba74 \uc774\ub7f0\uc6a9\ub3c4\ub85c \uc0ac\uc6a9\ud558\uac8c \ub418\uaca0\uc9c0\ub9cc, \uc9d1\uc5d0\uc11c \uacf5\uc720\uae30 \ub4a4\uc5d0 NAS\ub97c \uc4f0\uac70\ub098, \uac1c\uc778 \uc11c\ubc84\ub97c \uc0ac\uc6a9\ud558\ub294 \uacbd\uc6b0\uc5d0\ub3c4 \ub3d9\uc77c\ud55c \ubc29\ubc95\uc73c\ub85c \ud65c\uc6a9\ud560 \uc218 \uc788\ub2e4. \ub9cc\uc57d NAS\ub098 \uac1c\uc778\uc11c\ubc84\ub97c SMB(\ub124\ud2b8\uc6cc\ud06c \uacf5\uc720 \uae30\ub2a5)\ud1b5\ud574 \uc0ac\uc6a9\ud558\uae30 \uc704\ud574\uc11c\ub294 \uac19\uc740 \ub124\ud2b8\uc6cc\ud06c\uc5d0 \uc788\uc5b4\uc57c \ud55c\ub2e4. \ud558\uc9c0\ub9cc \uc678\ubd80\uc5d0\uc11c\ub294 \uc774 \ubc29\ubc95\uc744 \uc0ac\uc6a9\ud560 \uc218 \uc5c6\ub294\ub370, \uc774\ub294 ISP(\ub124\ud2b8\uc6cc\ud06c \uc81c\uacf5\uc0ac)\uc758 \ubc29\ud654\ubcbd \ubb38\uc81c\uac00 \uc788\uae30 \ub54c\ubb38\uc774\uba70, \ub530\ub77c\uc11c WebDAV\ub4f1\uc744 \uc774\uc6a9\ud558\uc5ec \uad6c\ud604\ud558\ub294 \ubc29\ubc95\uc774 \uc77c\ubc18\uc801\uc774\ub2e4. \uc774 \uacbd\uc6b0\uc5d0 \uc678\ubd80\uc5d0\ub294 \ub0b4\ubd80 \uc11c\ubc84\ub97c \uacf5\uac1c\ud558\uc9c0 \uc54a\uc73c\uba74\uc11c \uc548\uc804(\uc554\ud638\ud654\ub41c)\ud558\uac8c \ub0b4\ubd80 \ub124\ud2b8\uc6cc\ud06c\uc5d0 \uc811\uc18d\ub41c \uac83\uacfc \uac19\uc740 \uc0c1\ud0dc\ub97c \ub9cc\ub4e4 \uc218 \uc788\ub294 \ubc29\ubc95\uc774 \ubc14\ub85c VPN\uc778 \uac83\uc774\ub2e4.<\/p>\n<p>\uc77c\ubc18\uc801\uc778 \uacf5\uc720\uae30\ub294 VPN \ud504\ub85c\ud1a0\ucf5c \uc911\uc5d0 \ud558\ub098\uc778 PPTP\ub97c \uc9c0\uc6d0\ud558\ub3c4\ub85d \uad6c\ud604\ub418\uc5b4 \uc788\ub2e4. \ud558\uc9c0\ub9cc PPTP\uc758 \ubb38\uc81c\ub294 \uc778\uc99d\uc2dc\uc2a4\ud15c\uc774\ub098 \uc554\ud638\ud654 \ubc29\uc2dd\uc774 \ub9e4\uc6b0 \uc624\ub798\ub418\uc5c8\uc73c\uba70 \ubcf4\uc548\uc5d0 \ucde8\uc57d\ud558\ub2e4\ub294 \uc810\uc774\ub2e4[1]. \uadf8\ub798\uc11c\uc778\uc9c0 \uc774\ubc88\uc5d0 \uc5c5\ub370\uc774\ud2b8 \ub418\ub294 iOS 10, macOS Sierra\ubd80\ud130\ub294 \ubcf4\uc548\uc0c1\uc758 \uc774\uc720\ub85c \ub354 \uc774\uc0c1 PPTP\ud504\ub85c\ud1a0\ucf5c \uae30\ubc18\uc758 VPN\uc11c\ube44\uc2a4\ub97c \uc774\uc6a9\ud560 \uc218 \uc5c6\uac8c \ub418\uc5c8\ub2e4[2]. \ud558\uc9c0\ub9cc \ud544\uc790\uac00 \uac00\uc9c0\uace0 \uc788\ub294 \uacf5\uc720\uae30\uc5d0\uc11c PPTP\ub97c \uc9c0\uc6d0\ud558\uc9c0 \uc54a\uae30 \ub54c\ubb38\uc5d0 \ub2e4\ub978 \ud504\ub85c\ud1a0\ucf5c\uc744 \uc0ac\uc6a9\ud558\ub294 VPN\uc774 \ud544\uc694\ud558\uac8c \ub418\uc5c8\ub2e4. \ud558\uc9c0\ub9cc \uad73\uc774 \uacf5\uc720\uae30\uc5d0\uc11c PPTP\uac00 \uc544\ub2cc \ub2e4\ub978 \ud504\ub85c\ud1a0\ucf5c\uc744 \uc9c0\uc6d0\ud558\uac8c \ud558\ub824\uba74 \uacf5\uc720\uae30\uc758 \ud38c\uc6e8\uc5b4\ub97c \ucee4\uc2a4\ud130\ub9c8\uc774\uc9d5\ud574\uc57c \ud55c\ub2e4\ub294 \uac83\uc778\ub370 \uadf8\uac74 \ub108\ubb34 \uc2dc\uac04\uc774 \ub9ce\uc774 \uac78\ub9ac\uba70 \uacf5\uc720\uae30 \uacf5\uae09\uc0ac\uc5d0\uc11c \uc18c\uc2a4\ucf54\ub4dc\ub97c \uacf5\uac1c\ud558\uc9c0 \uc54a\ub294\ub2e4\ub294 \uc810\uc5d0\uc11c \uc5b4\ub824\uc6c0\uc774 \uc788\ub2e4. \ub530\ub77c\uc11c VPN\uc11c\ubc84\ub97c \uacf5\uc720\uae30\uc5d0\uc11c \ub0b4\ubd80 \uc11c\ubc84\ub85c \ubcc0\uacbd\ud558\uba74 \uc5ec\ub7ec\uc885\ub958\uc758 VPN\ud504\ub85c\ud1a0\ucf5c\uc774 \uc0ac\uc6a9 \uac00\ub2a5\ud574 \uc9c0\uae30 \ub54c\ubb38\uc5d0 \ud648 \uc11c\ubc84\uc5d0 VPN\uc11c\ubc84\ub97c \uc124\uce58 \ud558\uac8c \ub418\uc5c8\ub2e4. \uc880 \ub354 \ud070 CPU\ud30c\uc6cc\ub97c \uc0ac\uc6a9\ud560 \uc218 \uc788\uac8c \ub428\uc73c\ub85c\uc368 \ucd5c\uc2e0 VPN \ud504\ub85c\ud1a0\ucf5c\uacfc \uace0\uae09 \uc554\ud638\ud654 \uae30\ub2a5\ub3c4 \uc0ac\uc6a9\ud560 \uc218 \uc788\uac8c \ub418\uc5c8\ub2e4.<\/p>\n<p>\uc790\ub8cc \uc870\uc0ac\ub97c \ud574\ubcf4\uba74\uc11c \uc5ec\ub7ec \uc885\ub958\uc758 VPN \ud504\ub85c\ud1a0\ucf5c\uc774 \uc874\uc7ac\ud568\uc744 \uc54c \uc218 \uc788\uc5c8\uc73c\uba70, VPN \ud504\ub85c\ud1a0\ucf5c\uc744 \uc120\ud0dd \uae30\uc900\uc774 \ud544\uc694\ud574 \uc84c\ub294\ub370 \ubaa8\ubc14\uc77c\uc774\ub098 OS\uc5d0\uc11c \ucd94\uac00\uc801\uc778 \ud504\ub85c\uadf8\ub7a8 \uc124\uce58 \uc5c6\uc774 \uc0ac\uc6a9\ud560 \uc218 \uc788\uc5b4\uc57c \ud55c\ub2e4\ub294 \uc870\uac74\uc744 \uac78\uc5c8\ub2e4. \uc774 \uc870\uac74\uc744 \ub9cc\uc871\ud558\uba74 \ubaa8\ubc14\uc77c\ub85c \uc678\ubd80\uc5d0\uc11c \uc9d1\uc5d0 \uc788\ub294 \uc11c\ubc84\uc5d0 \uc788\ub294 \ub3d9\uc601\uc0c1\uc744 \uc2a4\ud2b8\ub9ac\ubc0d\uc73c\ub85c \ubcfc \uc218 \uc788\uae30 \ub54c\ubb38\uc5d0\ub2e4. \uc774\uc5d0 \ucd94\uac00 \ud074\ub77c\uc774\uc5b8\ud2b8 \ud658\uacbd \uc124\uce58\uac00 \ud544\uc694\ud55c OpenVPN\uc740 \uc81c\uc678\ub418\uc5c8\ub2e4. \uadf8\ub807\uac8c \ub418\uba74 \uac00\ub2a5\ud55c \ud504\ub85c\ud1a0\ucf5c\uc774 L2TP\/IPSec, IPSec, IKEv2 \ub97c \uc0ac\uc6a9\ud560 \uc218 \uc788\uc74c\uc744 \ud655\uc778 \uac00\ub2a5\ud558\uc600\ub2e4. \ucd5c\ucd08\uc5d0\ub294 L2TP\/IPSec\uc744 \uc774\uc6a9\ud560 \uc608\uc815\uc774\uc600\uc73c\ub098, \ud544\uc790\uac00 \uc0ac\uc6a9\ud558\ub294 OS\uc5d0\uc11c\ub294 \uae30\ubcf8 \uc9c0\uc6d0\ud558\uba70, \uc18d\ub3c4\ub3c4 \ube60\ub974\uace0 \ub192\uc740 \ubcf4\uc548\uc744 \uc81c\uacf5\ud558\ub294 IKEv2 \ud504\ub85c\ud1a0\ucf5c\uc744 \uc774\uc6a9\ud558\uc5ec \uad6c\ud604\ud558\uae30\ub85c \ud558\uc600\ub2e4[3].<\/p>\n<p>IKEv2 \ud504\ub85c\ud1a0\ucf5c\uc744 \uc0ac\uc6a9\ud560 \ub54c\u00a0ESP\ub97c \ud1b5\ud558\uc5ec \uc554\ud638\ud654\ub41c \ud328\ud0b7\uc744 \uc804\uc1a1\ud55c\ub2e4. \uc6d0\ub798 ESP\ub294 IP\ud504\ub85c\ud1a0\ucf5c\uc5d0 \ubc14\ub85c \ub4e4\uc5b4\uac00\uae30 \ub54c\ubb38\uc5d0 \uacf5\uc720\uae30(NAT)\ub4a4\uc5d0 VPN\uc11c\ubc84\uac00 \uc788\ub294 \uacbd\uc6b0\uc5d0\ub294 DMZ\uc124\uc815 \uac19\uc740 \uac83\uc774 \ud544\uc694\ud558\uba70 \uacf5\uc720\uae30\uac00 \uc774 \uae30\ub2a5\uc744 \uc9c0\uc6d0\ud574\uc57c\ud560 \uc218\ub3c4 \uc788\ub2e4. DMZ\ub85c \uc124\uc815\ud558\uba74 VPN\uc11c\ubc84\uc758 \ubaa8\ub4e0 \ubd80\ubd84\uc774 \uc778\ud130\ub137\uc73c\ub85c \uacf5\uac1c\ub418\uae30 \ub54c\ubb38\uc5d0 \ub0b4\ubd80\ub97c \uc228\uae30\uaca0\ub2e4\ub294 \ubaa9\uc801\uc774 \ub2ec\uc131\ub418\uc9c0 \uc54a\ub294\ub2e4. \ud558\uc9c0\ub9cc \uc120\ubc30 \uac1c\ubc1c\uc790\ub4e4\uc740 \uc774\ub7f0 \ubb38\uc81c\ub97c \ud574\uacb0\ud558\uae30 \uc704\ud574 NAT Passthrough\ub77c\ub294 \uac83\uc744 \uc81c\uacf5\ud558\uba70 UDP\ud504\ub85c\ud1a0\ucf5c\uc5d0 ESP\ub97c \ub2f4\uc544\uc11c \ubcf4\ub0b4\ub3c4\ub85d \uad6c\ud604\uc774 \ub41c\ub2e4. \uc774 \ubb38\uc81c\ub294 \uc774\ub97c \uc124\uc815\ud568\uc73c\ub85c\uc368 \ud574\uacb0 \ub41c\ub2e4.<\/p>\n<p>\uc900\ube44\ubb3c\uc740 MITM(Man in the middle attack)\ubc29\uc9c0\ub97c \uc704\ud55c \uc11c\ubc84 \uc778\uc99d\uc744 \uc704\ud55c \uc778\uc99d\uc11c\uac00 \ud544\uc694\ud558\ub2e4. \uc774 \uae00\uc5d0\uc11c\ub294 self-signed \uc778\uc99d\uc11c\ub97c \uc0ac\uc6a9\ud558\uc5ec IKEv2\uc11c\ubc84 \uad6c\ucd95\ud558\ub294 \ubc29\ubc95\uc744 \uc54c\ub824\uc8fc\uc9c0 \uc54a\ub294\ub2e4. \ub9cc\uc57d self-signed \uc778\uc99d\uc11c\ub97c \uc0ac\uc6a9\ud558\uac8c \ub418\uba74 \ud074\ub77c\uc774\uc5b8\ud2b8\uc5d0\uc11c \ucd94\uac00\uc801\uc778 \uc124\uc815\uc774 \ud544\uc694\ud560 \uc218\ub3c4 \uc788\ub2e4.<\/p>\n<p>\uc774 \uae00\uc740 \uacf5\uc720\uae30\uc758 IP\uc8fc\uc18c\ub85c DNS\/DDNS \ub4f1\uc758 \ubc29\ubc95\uc73c\ub85c \ub3c4\uba54\uc778\uc774 \ud560\ub2f9\ub418\uc5b4 \uc788\uc73c\uba70, \uc774 \ub3c4\uba54\uc778\uc73c\ub85c \uc815\uc0c1\uc801\uc778 SSL \uc778\uc99d\uc11c\ub97c \ubc1c\uae09\ubc1b\uc558\ub2e4\ub294 \uc804\uc81c\ub85c \uc791\uc131\ub418\uc5b4 \uc788\ub2e4.<\/p>\n<p>SSL \uc778\uc99d\uc11c\ub294 \uc77c\ubc18\uc801\uc73c\ub85c \uc720\ub8cc\uc774\uc9c0\ub9cc <a href=\"http:\/\/www.startssl.com\">StartSSL<\/a>\uc774\ub098 <a href=\"http:\/\/www.letsencrypt.org\">Let&#8217;s Encrypt<\/a> \ub4f1\uc744 \ud1b5\ud558\uc5ec \ubb34\ub8cc\ub85c \ubc1c\uae09 \uac00\ub2a5\ud558\ub2e4.<\/p>\n<p>IKEv2\ub97c \ub3d9\uc791\uc2dc\ud0a4\uae30 \uc704\ud574\uc11c\ub294 UDP\/500\uacfc UDP\/4500\uc744 \uc5f4\uc5b4 \ub450\uc5b4\uc57c \ud55c\ub2e4. UDP\/500\uc740 IKE\ud504\ub85c\ud1a0\ucf5c\uc744 \uc704\ud574 \ud544\uc694\ud558\uba70, UDP\/4500\uc740 IPSec\uc744 \uc774\uc6a9\ud558\uae30\uc704\ud574 \ud544\uc694\ud558\ub2e4. \uc774 \ub450\uac00\uc9c0 \ud3ec\ud2b8\ub97c \uacf5\uc720\uae30\uc5d0\uc11c \ud3ec\ud2b8\ud3ec\uc6cc\ub529 \uc124\uc815\uc744 \ud574\ub450\uc5b4\uc57c \ud55c\ub2e4.<\/p>\n<p>IKEv2\ub97c \uc0ac\uc6a9\ud558\uae30 \uc704\ud574\uc11c\ub294 <code>strongswan<\/code>\uc774\ub77c\ub294 \ud328\ud0a4\uc9c0 \uc124\uce58\uc640 \uc554\ud638\ud654 \uae30\ub2a5 \ub4f1\uc758 \uae30\ub2a5\uc744 \uc0ac\uc6a9\ud558\uae30 \uc704\ud574\ub2e4.<\/p>\n<p>1. \ud328\ud0a4\uc9c0 \uc124\uce58<br \/>\n<code>apt-get install\u00a0strongswan libcharon-extra-plugins<\/code><\/p>\n<p>2. \uc778\uc99d\uc11c \uc124\uc815<\/p>\n<p>2.1. root \uc778\uc99d\uc11c \ubcf5\uc0ac<br \/>\n\ubc1c\uae09\ubc1b\uc740 \uc778\uc99d\uc11c\uc758 \ub8e8\ud2b8 \uc778\uc99d\uc11c \ubc0f \ucc44\uc778 \uc778\uc99d\uc11c \ubcf5\uc0ac<br \/>\n\ubcf5\uc0ac\uc2dc \ud55c \ud30c\uc77c\ub2f9 \ud558\ub098\uc758 \uc778\uc99d\uc11c\ub9cc \ud3ec\ud568 \uc2dc\ud0ac \uac83<br \/>\n<code>\/etc\/ipsec.d\/cacerts<\/code><\/p>\n<p>2.2. \uc778\uc99d\uc11c \ubcf5\uc0ac<br \/>\n\ubc1c\uae09\ubc1b\uc740 \uc778\uc99d\uc11c \ud30c\uc77c \ubcf5\uc0ac(pem)<br \/>\n<code>\/etc\/ipsec.d\/certs<\/code><\/p>\n<p>2.3 \uc778\uc99d\uc11c\uc758 \ube44\ubc00\ud0a4 \ubcf5\uc0ac<br \/>\n\ubc1c\uae09\ubc1b\uc744 \ub54c \uc0ac\uc6a9\ud55c \uc778\uc99d\uc11c \ube44\ubc00\ud0a4 \ubcf5\uc0ac (\ud0a4 \ud328\uc2a4\uc6cc\ub4dc \uc81c\uac70\ud560 \uac83)<br \/>\n<code>\/etc\/ipsec.d\/private<\/code><\/p>\n<p>2.4 \uad8c\ud55c \uc124\uc815<br \/>\n<code>chmod 740 \/etc\/ipsec.d\/cacerts<\/code><br \/>\n<code>chmod 740 \/etc\/ipsec.d\/certs<\/code><br \/>\n<code>chmod 700 \/etc\/ipsec.d\/private<\/code><\/p>\n<p>3. \/etc\/ipsec.conf \ud30c\uc77c \uc218\uc815<\/p>\n<pre class=\"lang:default decode:true\">config setup\r\n\u00a0 strictcrlpolicy=yes\r\n\u00a0 uniqueids = no\r\n\r\nconn roadwarrior\r\n\u00a0 auto=add\r\n\u00a0 compress=no\r\n\u00a0 type=tunnel \u00a0 \u00a0 # tunnel: network \uacc4\uce35(ip)\ubd80\ud130 \uc554\ud638\ud654, transport: \uc804\uc1a1 \uacc4\uce35(transport layer; TCP\/UDP)\ubd80\ud130 \uc554\ud638\ud654\r\n\u00a0 keyexchange=ikev2\r\n\u00a0 rekey=no\r\n\u00a0 reauth=no\r\n\u00a0 fragmentation=yes\r\n\u00a0 forceencaps=yes\r\n\u00a0 dpdaction=clear\r\n\u00a0 dpddelay=35s\r\n\u00a0 dpdtimeout=2000s\r\n\u00a0 left=%any\r\n\u00a0 leftid=@example.com \u00a0 # \uc544\ub798 ipsec.secrets\uc758 \uc774\ub984\uacfc \ud1b5\uc77c, \uc778\uc99d\uc11c\uc5d0 \ub3c4\uba54\uc778 \ud3ec\ud568\ub418\uc5b4 \uc788\uc744 \uac83\r\n\u00a0 leftcert=example_com.pem \u00a0 # \uc0c1\uae30 certs \ub514\ub809\ud1a0\ub9ac\uc5d0 \ubcf5\uc0ac\ud55c \uc778\uc99d\uc11c \ud30c\uc77c\uba85\uc73c\ub85c \ubcc0\uacbd\u00a0\r\n\u00a0 leftsendcert=always\r\n\u00a0 leftsubnet=0.0.0.0\/0\r\n\u00a0 leftauth=pubkey\r\n\u00a0 right=%any\r\n\u00a0 rightid=%any\r\n\u00a0 rightauth=eap-mschapv2\r\n\u00a0 eap_identity=%identity\r\n\u00a0 rightdns=192.168.1.1 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 #\u00a0\uc5ec\uae30\uc11c rightdns \uc758 \uc8fc\uc18c\ub97c VPN\uc0ac\uc6a9\uc2dc \uc4f8 DNS\uc11c\ubc84 \uc8fc\uc18c\ub85c \ubcc0\uacbd \ud544\uc694\ud558\ub2e4. (\uc608: 8.8.8.8)\r\n\u00a0 rightsourceip=10.8.10.0\/24\r\n\u00a0 rightsendcert=never<\/pre>\n<p>4. \/etc\/ipsec.secrets<\/p>\n<pre class=\"lang:default decode:true\"># \uc11c\ubc84 \ub3c4\uba54\uc778\uacfc \ud0a4 \uc124\uc815\r\n\r\n# \uc608\uc81c - \uc544\ub798 \ub3c4\uba54\uc778\uc740 \ud074\ub77c\uc774\uc5b8\ud2b8 \uc124\uc815\uc2dc \uc0ac\uc6a9, \uc778\uc99d\uc11c\uc5d0 \uc544\ub798 \ub3c4\uba54\uc778\uc774 \ud3ec\ud568\ub418\uc5b4 \uc788\uc5b4\uc57c \ud568, \uc0c1\uae30 \ubcf5\uc0ac\ud55c \ube44\ubc00\ud0a4 \ud30c\uc77c\uba85\uc744 \uc0ac\uc6a9\ud568\r\nexample.com : RSA \u201cexample_com.key\"\r\n\r\n{{VPN\uc811\uc18dID}} : EAP \u201c{{VPN\uc811\uc18dPASSWORD}}\"\r\n# \uc608\uc81c\r\nadmin : EAP \u201cpassword\"<\/pre>\n<p>5. \uc11c\ubc84 \uc7ac\uc2dc\uc791<br \/>\n<code>ipsec restart<\/code><\/p>\n<p>6. \uacf5\uc720\uae30(NAT) \ud3ec\ud2b8 \ud3ec\uc6cc\ub529<br \/>\nUDP 500 \uacfc UDP 4500\uc744 \ub0b4\ubd80\uc5d0 \uc124\uce58\ub41c VPN\uc11c\ubc84\ub85c \ud3ec\uc6cc\ub529<\/p>\n<p>7. \ud14c\uc2a4\ud2b8<br \/>\niOS\uae30\uae30\ub098 macOS\uc5d0\uc11c \uc544\ub798\uc758 \uc124\uc815\uc73c\ub85c \ub9cc\ub4e6<br \/>\n\ub0b4\ubd80\ub9dd\uacfc \uc678\ubd80\ub9dd\uc5d0\uc11c \uac01\uac01 \uc218\ud589\ud558\uc5ec \uc815\uc0c1\uc801\uc73c\ub85c \uc811\uc18d \ub418\ub294\uc9c0 \ud655\uc778\ud55c\ub2e4.<\/p>\n<ul>\n<li>VPN Type : IKEv2<\/li>\n<li>Server Address(\uc11c\ubc84 \uc8fc\uc18c) : VPN\uc758 \ub3c4\uba54\uc778 \uc8fc\uc18c (\uc608: example.com)<\/li>\n<li>Remote ID (\ub9ac\ubaa8\ud2b8 ID) : \uc0c1\uae30 \uc801\uc740 \ub3c4\uba54\uc778 \uc8fc\uc18c(\uc608: example.com)<\/li>\n<li>Local ID (\ub85c\uceec ID) : \ube44\uc6cc\ub458 \uac83<\/li>\n<li>Authentication Settings\u2026(\uc778\uc99d \uc124\uc815) : \uc0ac\uc6a9\uc790 \uc774\ub984<br \/>\n\uc0ac\uc6a9\uc790 \uc774\ub984 : ipsec.secrets \uc5d0 \uc124\uc815\ud55c \uc544\uc774\ub514<br \/>\n\ud328\uc2a4\uc6cc\ub4dc\u00a0: ipsec.secrets \uc5d0 \uc124\uc815\ud55c \ud328\uc2a4\uc6cc\ub4dc<\/li>\n<\/ul>\n<figure id=\"attachment_657\" aria-describedby=\"caption-attachment-657\" style=\"width: 150px\" class=\"wp-caption alignnone\"><a href=\"https:\/\/i0.wp.com\/www.jinukbaek.com\/blog\/wp-content\/uploads\/2016\/09\/IMG_7783.jpg?ssl=1\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" data-attachment-id=\"657\" data-permalink=\"https:\/\/www.jinukbaek.com\/blog\/ko\/archives\/654\/img_7783\" data-orig-file=\"https:\/\/i0.wp.com\/www.jinukbaek.com\/blog\/wp-content\/uploads\/2016\/09\/IMG_7783.jpg?fit=1242%2C2208&amp;ssl=1\" data-orig-size=\"1242,2208\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;1473865565&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;1&quot;}\" data-image-title=\"VPN setting example\" data-image-description=\"\" data-image-caption=\"&lt;p&gt;VPN \uc124\uc815 \uc608\uc2dc&lt;\/p&gt;\n\" data-large-file=\"https:\/\/i0.wp.com\/www.jinukbaek.com\/blog\/wp-content\/uploads\/2016\/09\/IMG_7783.jpg?fit=576%2C1024&amp;ssl=1\" class=\"wp-image-657 size-thumbnail\" src=\"https:\/\/i0.wp.com\/www.jinukbaek.com\/blog\/wp-content\/uploads\/2016\/09\/IMG_7783.jpg?resize=150%2C150&#038;ssl=1\" alt=\"VPN \uc124\uc815 \uc608\uc2dc\" width=\"150\" height=\"150\" srcset=\"https:\/\/i0.wp.com\/www.jinukbaek.com\/blog\/wp-content\/uploads\/2016\/09\/IMG_7783.jpg?resize=150%2C150&amp;ssl=1 150w, https:\/\/i0.wp.com\/www.jinukbaek.com\/blog\/wp-content\/uploads\/2016\/09\/IMG_7783.jpg?resize=144%2C144&amp;ssl=1 144w, https:\/\/i0.wp.com\/www.jinukbaek.com\/blog\/wp-content\/uploads\/2016\/09\/IMG_7783.jpg?resize=96%2C96&amp;ssl=1 96w, https:\/\/i0.wp.com\/www.jinukbaek.com\/blog\/wp-content\/uploads\/2016\/09\/IMG_7783.jpg?resize=24%2C24&amp;ssl=1 24w, https:\/\/i0.wp.com\/www.jinukbaek.com\/blog\/wp-content\/uploads\/2016\/09\/IMG_7783.jpg?resize=36%2C36&amp;ssl=1 36w, https:\/\/i0.wp.com\/www.jinukbaek.com\/blog\/wp-content\/uploads\/2016\/09\/IMG_7783.jpg?resize=48%2C48&amp;ssl=1 48w, https:\/\/i0.wp.com\/www.jinukbaek.com\/blog\/wp-content\/uploads\/2016\/09\/IMG_7783.jpg?resize=64%2C64&amp;ssl=1 64w, https:\/\/i0.wp.com\/www.jinukbaek.com\/blog\/wp-content\/uploads\/2016\/09\/IMG_7783.jpg?zoom=2&amp;resize=150%2C150&amp;ssl=1 300w, https:\/\/i0.wp.com\/www.jinukbaek.com\/blog\/wp-content\/uploads\/2016\/09\/IMG_7783.jpg?zoom=3&amp;resize=150%2C150&amp;ssl=1 450w\" sizes=\"auto, (max-width: 150px) 100vw, 150px\" \/><\/a><figcaption id=\"caption-attachment-657\" class=\"wp-caption-text\">VPN \uc124\uc815 \uc608\uc2dc<\/figcaption><\/figure>\n<p>&nbsp;<\/p>\n<figure id=\"attachment_656\" aria-describedby=\"caption-attachment-656\" style=\"width: 695px\" class=\"wp-caption alignnone\"><a href=\"https:\/\/i0.wp.com\/www.jinukbaek.com\/blog\/wp-content\/uploads\/2016\/09\/IMG_7753.png?ssl=1\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" data-attachment-id=\"656\" data-permalink=\"https:\/\/www.jinukbaek.com\/blog\/ko\/archives\/654\/img_7753\" data-orig-file=\"https:\/\/i0.wp.com\/www.jinukbaek.com\/blog\/wp-content\/uploads\/2016\/09\/IMG_7753.png?fit=1242%2C834&amp;ssl=1\" data-orig-size=\"1242,834\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"connected to VPN\" data-image-description=\"\" data-image-caption=\"\" data-large-file=\"https:\/\/i0.wp.com\/www.jinukbaek.com\/blog\/wp-content\/uploads\/2016\/09\/IMG_7753.png?fit=640%2C430&amp;ssl=1\" class=\"wp-image-656 size-large\" src=\"https:\/\/i0.wp.com\/www.jinukbaek.com\/blog\/wp-content\/uploads\/2016\/09\/IMG_7753.png?resize=640%2C430&#038;ssl=1\" alt=\"connected to VPN\" width=\"640\" height=\"430\" srcset=\"https:\/\/i0.wp.com\/www.jinukbaek.com\/blog\/wp-content\/uploads\/2016\/09\/IMG_7753.png?resize=1024%2C688&amp;ssl=1 1024w, https:\/\/i0.wp.com\/www.jinukbaek.com\/blog\/wp-content\/uploads\/2016\/09\/IMG_7753.png?resize=300%2C201&amp;ssl=1 300w, https:\/\/i0.wp.com\/www.jinukbaek.com\/blog\/wp-content\/uploads\/2016\/09\/IMG_7753.png?resize=768%2C516&amp;ssl=1 768w, https:\/\/i0.wp.com\/www.jinukbaek.com\/blog\/wp-content\/uploads\/2016\/09\/IMG_7753.png?w=1242&amp;ssl=1 1242w\" sizes=\"auto, (max-width: 640px) 100vw, 640px\" \/><\/a><figcaption id=\"caption-attachment-656\" class=\"wp-caption-text\">VPN \uc811\uc18d \uc131\uacf5<\/figcaption><\/figure>\n<p>8. \uad00\ub828 \uc811\uc18d \ub85c\uadf8 \ud655\uc778<br \/>\n<code>tail -f \/var\/log\/syslog<\/code><br \/>\n<code>tail -f \/var\/log\/auth.log<\/code><\/p>\n<p>\uc774 \uae00\uc744 \ud1b5\ud574 \uc6b0\ubd84\ud22c \uc11c\ubc84\uc5d0\uc11c IKEv2\ub97c \uc0ac\uc6a9\ud55c \uc11c\ubc84 \uad6c\ucd95\uc774 \uac00\ub2a5\ud558\uc600\uc73c\uba70 \uc774\ub97c \ud1b5\ud574 \uc5b4\ub514\uc5d0\uc11c\ub098 \ubaa8\ubc14\uc77c \ub514\ubc14\uc774\uc2a4, \ub370\uc2a4\ud06c\ud1b1\uc744 \ud1b5\ud558\uc5ec \ub0b4\ubd80 \ub124\ud2b8\uc6cc\ud06c\uc5d0 \uc811\uc18d\ud560 \uc218 \uc788\uac8c \ub418\uc5c8\uc73c\uba70, \uc554\ud638\ud654\uac00 \ub418\uc5b4 \uc548\uc804\ud55c \ud658\uacbd\uc5d0\uc11c \ub0b4\ubd80\uc11c\ubc84\uc758 \ub370\uc774\ud130\ub97c \uc0ac\uc6a9\ud560 \uc218 \uc788\uac8c \ub418\uc5c8\ub2e4.<\/p>\n<h4>\ucc38\uace0\ubb38\ud5cc<\/h4>\n<p>[1] B. Schneier, Mudge, \u201cCryptanalysis of Microsoft&#8217;s PPTP Authentication Extensions (MS-CHAPv2)\u201d,\u00a0CQRE &#8217;99, Springer-Verlag, 1999, pp. 192-203.<br \/>\n[2] &#8220;Prepare for removal of PPTP VPN before you upgrade to iOS 10 and macOS Sierra\u201d, Apple, <a href=\"https:\/\/support.apple.com\/en-us\/HT206844\" rev=\"en_rl_minimal\">https:\/\/support.apple.com\/en-us\/HT206844<\/a><br \/>\n[3] \u00a0<a href=\"https:\/\/hide.me\/en\/blog\/2015\/03\/whats-the-difference-considering-pptp-vs-l2tp-vs-sstp-vs-ikev2\/\" rev=\"en_rl_minimal\">https:\/\/hide.me\/en\/blog\/2015\/03\/whats-the-difference-considering-pptp-vs-l2tp-vs-sstp-vs-ikev2\/<\/a><br \/>\n[4] <a href=\"https:\/\/hub.zhovner.com\/geek\/universal-ikev2-server-configuration\/\" rev=\"en_rl_minimal\">https:\/\/hub.zhovner.com\/geek\/universal-ikev2-server-configuration\/<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>VPN\uc740 \uc678\ubd80\ub85c\ubd80\ud130 \uaca9\ub9ac\ub41c \uc778\ud2b8\ub77c\ub137\uc744 \uad6c\uc131\ud558\uba74 \uc678\ubd80\uc5d0\uc11c \uc811\uc18d\uc774 \ubd88\uac00\ub2a5\ud55c\ub370 \uc774\ub97c \uac00\ub2a5\ud558\uac8c \ud574\uc8fc\ub294 \uc11c\ube44\uc2a4\uc774\ub2e4. \ubb3c\ub9ac\uc801\uc73c\ub85c \uc11c\ub85c \ub5a8\uc5b4\uc838 \uc788\ub294 \ud68c\uc0ac \ub124\ud2b8\uc6cc\ud06c\ub97c<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"advanced_seo_description":"","jetpack_seo_html_title":"","jetpack_seo_noindex":false,"jetpack_post_was_ever_published":false,"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_publicize_message":"","jetpack_publicize_feature_enabled":true,"jetpack_social_post_already_shared":false,"jetpack_social_options":{"image_generator_settings":{"template":"highway","default_image_id":0,"font":"","enabled":false},"version":2}},"categories":[136,85],"tags":[343,345,353,347,349,351,331,341],"class_list":["post-654","post","type-post","status-publish","format-standard","hentry","category-osx","category-computer-linux","tag-ikev2","tag-ios10","tag-linux","tag-macos","tag-pptp","tag-strongswan","tag-ubuntu","tag-vpn"],"jetpack_publicize_connections":[],"jetpack_featured_media_url":"","jetpack_sharing_enabled":true,"jetpack_shortlink":"https:\/\/wp.me\/p8gT1J-ay","_links":{"self":[{"href":"https:\/\/www.jinukbaek.com\/blog\/wp-json\/wp\/v2\/posts\/654","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.jinukbaek.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.jinukbaek.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.jinukbaek.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.jinukbaek.com\/blog\/wp-json\/wp\/v2\/comments?post=654"}],"version-history":[{"count":8,"href":"https:\/\/www.jinukbaek.com\/blog\/wp-json\/wp\/v2\/posts\/654\/revisions"}],"predecessor-version":[{"id":664,"href":"https:\/\/www.jinukbaek.com\/blog\/wp-json\/wp\/v2\/posts\/654\/revisions\/664"}],"wp:attachment":[{"href":"https:\/\/www.jinukbaek.com\/blog\/wp-json\/wp\/v2\/media?parent=654"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.jinukbaek.com\/blog\/wp-json\/wp\/v2\/categories?post=654"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.jinukbaek.com\/blog\/wp-json\/wp\/v2\/tags?post=654"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}