{"id":2567,"date":"2020-03-26T13:00:39","date_gmt":"2020-03-26T12:00:39","guid":{"rendered":"https:\/\/www.safekom.pl\/blog\/?p=2567"},"modified":"2020-03-26T13:00:39","modified_gmt":"2020-03-26T12:00:39","slug":"nsx-t-ipsec-route-base","status":"publish","type":"post","link":"https:\/\/www.safekom.pl\/blog\/vmware\/nsx\/nsx-t-ipsec-route-base\/","title":{"rendered":"NSX-t IPSec Route base"},"content":{"rendered":"\r\n<p class=\"wp-block-paragraph\">W dzisiejszym wpisie przedstawi\u0119 konfiguracj\u0119 NSX-t IPSec Route base, jest to\u00a0 opis krok po kroku jak skonfigurowa\u0107 IPseca po stronie NSX&#8217;a oraz Vyos kt\u00f3ry b\u0119dzie uczestnikiem IPseca.\u00a0<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\"><\/p>\r\n\r\n\r\n\r\n<h4 class=\"wp-block-heading\">Za\u0142o\u017cenia<\/h4>\r\n\r\n\r\n\r\n<ol class=\"wp-block-list\">\r\n<li>Poni\u017cej rysunek pogl\u0105dowy jak wygl\u0105da topologia po\u0142\u0105cze\u0144.<br \/>\r\n<figure><a href=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2020\/03\/lab_nsx-vpn-v1.png?ssl=1\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" data-attachment-id=\"2568\" data-permalink=\"https:\/\/www.safekom.pl\/blog\/vmware\/nsx\/nsx-t-ipsec-route-base\/attachment\/lab_nsx-vpn-v1\/\" data-orig-file=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2020\/03\/lab_nsx-vpn-v1.png?fit=864%2C142&amp;ssl=1\" data-orig-size=\"864,142\" data-comments-opened=\"0\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"lab_nsx-vpn-v1\" data-image-description=\"\" data-image-caption=\"\" data-large-file=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2020\/03\/lab_nsx-vpn-v1.png?fit=770%2C127&amp;ssl=1\" class=\"alignnone size-full wp-image-2568\" src=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2020\/03\/lab_nsx-vpn-v1.png?resize=770%2C127&#038;ssl=1\" alt=\"\" width=\"770\" height=\"127\" srcset=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2020\/03\/lab_nsx-vpn-v1.png?w=864&amp;ssl=1 864w, https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2020\/03\/lab_nsx-vpn-v1.png?resize=300%2C49&amp;ssl=1 300w, https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2020\/03\/lab_nsx-vpn-v1.png?resize=768%2C126&amp;ssl=1 768w\" sizes=\"auto, (max-width: 770px) 100vw, 770px\" \/><\/a><\/figure>\r\n<\/li>\r\n<li>Pomi\u0119dzy routerem T0 i chmurk\u0105 ju\u017c istnieje po\u0142\u0105czenie oraz jest zestawione s\u0105siedztwo BGP w celu dost\u0119pu do sieci &#8222;Internet&#8221; na powy\u017cszym rysunku chmurki<\/li>\r\n<li>Parametry po\u0142\u0105czenia:<\/li>\r\n<\/ol>\r\n\r\n\r\n\r\n<figure class=\"wp-block-table is-style-stripes\">\r\n<table class=\"has-fixed-layout\">\r\n<thead>\r\n<tr>\r\n<th><span style=\"color: #000000;\">IKE<\/span><\/th>\r\n<th>\u00a0<\/th>\r\n<\/tr>\r\n<\/thead>\r\n<tbody>\r\n<tr>\r\n<td><span style=\"color: #000000;\">IKE wersja<\/span><\/td>\r\n<td><span style=\"color: #000000;\">v2<\/span><\/td>\r\n<\/tr>\r\n<tr>\r\n<td><span style=\"color: #000000;\">Encryption Algorithm<\/span><\/td>\r\n<td><span class=\"label label-light-blue edd-tag\" style=\"color: #000000;\" title=\"AES 128\"><label>AES 256<\/label><\/span><\/td>\r\n<\/tr>\r\n<tr>\r\n<td><span style=\"color: #000000;\">Digest Algorithm<\/span><\/td>\r\n<td><span class=\"label label-light-blue edd-tag\" style=\"color: #000000;\" title=\"SHA2 256\"><label>SHA2 256<\/label><\/span><\/td>\r\n<\/tr>\r\n<tr>\r\n<td><span style=\"color: #000000;\">Diffie-Hellman<\/span><\/td>\r\n<td><span class=\"label label-light-blue edd-tag\" style=\"color: #000000;\" title=\"SHA2 256\"><label>Grupa 5<\/label><\/span><\/td>\r\n<\/tr>\r\n<tr>\r\n<td><span style=\"color: #000000;\"><label class=\"nsx-form-group-label ng-star-inserted\">SA Lifetime (sec)<\/label><\/span><\/td>\r\n<td><span style=\"color: #000000;\">86400<\/span><\/td>\r\n<\/tr>\r\n<\/tbody>\r\n<\/table>\r\n<\/figure>\r\n\r\n\r\n\r\n<figure class=\"wp-block-table is-style-stripes\">\r\n<table class=\"has-fixed-layout\">\r\n<thead>\r\n<tr>\r\n<th><span style=\"color: #000000;\">IPSec<\/span><\/th>\r\n<th>\u00a0<\/th>\r\n<\/tr>\r\n<\/thead>\r\n<tbody>\r\n<tr>\r\n<td><span style=\"color: #000000;\">Encryption Algorithm<\/span><\/td>\r\n<td><span class=\"label label-light-blue edd-tag\" style=\"color: #000000;\" title=\"AES 256\"><label>AES 256<\/label><\/span><\/td>\r\n<\/tr>\r\n<tr>\r\n<td><span style=\"color: #000000;\">Digest Algorithm<\/span><\/td>\r\n<td><span class=\"label label-light-blue edd-tag\" style=\"color: #000000;\" title=\"SHA2 256\"><label>SHA2 256<\/label><\/span><\/td>\r\n<\/tr>\r\n<tr>\r\n<td><span style=\"color: #000000;\">PFS Group<\/span><\/td>\r\n<td><span style=\"color: #000000;\">yes<\/span><\/td>\r\n<\/tr>\r\n<tr>\r\n<td><span style=\"color: #000000;\">Diffie-Hellman<\/span><\/td>\r\n<td><span class=\"label label-light-blue edd-tag\" style=\"color: #000000;\" title=\"SHA2 256\"><label>Grupa 5<\/label><\/span><\/td>\r\n<\/tr>\r\n<tr>\r\n<td><span style=\"color: #000000;\">SA Lifetime (sec)<\/span><\/td>\r\n<td><span class=\"label label-light-blue edd-tag\" style=\"color: #000000;\" title=\"SHA2 256\">3600<\/span><\/td>\r\n<\/tr>\r\n<\/tbody>\r\n<\/table>\r\n<\/figure>\r\n\r\n\r\n\r\n<h4 class=\"wp-block-heading\">Konfiguracja NSX-t<\/h4>\r\n\r\n\r\n\r\n<h5 class=\"wp-block-heading\">Konfiguracja po\u0142\u0105czenie IPSEC<\/h5>\r\n\r\n\r\n\r\n<ol class=\"wp-block-list\">\r\n<li>Logujemy si\u0119 do NSX Managera<br \/><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" data-attachment-id=\"2526\" data-permalink=\"https:\/\/www.safekom.pl\/blog\/vmware\/nsx-t-dhcp-relay\/attachment\/zrzut-ekranu-2020-03-13-o-21-28-33\/\" data-orig-file=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2020\/03\/Zrzut-ekranu-2020-03-13-o-21.28.33.png?fit=543%2C462&amp;ssl=1\" data-orig-size=\"543,462\" data-comments-opened=\"0\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"Zrzut ekranu 2020-03-13 o 21.28.33\" data-image-description=\"\" data-image-caption=\"\" data-large-file=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2020\/03\/Zrzut-ekranu-2020-03-13-o-21.28.33.png?fit=543%2C462&amp;ssl=1\" class=\"alignnone wp-image-2526\" style=\"width: 300px;\" src=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2020\/03\/Zrzut-ekranu-2020-03-13-o-21.28.33.png?resize=543%2C462&#038;ssl=1\" alt=\"nsx-t login page\" width=\"543\" height=\"462\" srcset=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2020\/03\/Zrzut-ekranu-2020-03-13-o-21.28.33.png?w=543&amp;ssl=1 543w, https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2020\/03\/Zrzut-ekranu-2020-03-13-o-21.28.33.png?resize=300%2C255&amp;ssl=1 300w\" sizes=\"auto, (max-width: 543px) 100vw, 543px\" \/><\/li>\r\n<li>Przechodzimy do Networking nast\u0119pnie VPN<br \/><a href=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2020\/03\/Zrzut-ekranu-2020-03-26-o-09.11.01.png?ssl=1\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" data-attachment-id=\"2592\" data-permalink=\"https:\/\/www.safekom.pl\/blog\/vmware\/nsx\/nsx-t-ipsec-route-base\/attachment\/zrzut-ekranu-2020-03-26-o-09-11-01\/\" data-orig-file=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2020\/03\/Zrzut-ekranu-2020-03-26-o-09.11.01.png?fit=560%2C834&amp;ssl=1\" data-orig-size=\"560,834\" data-comments-opened=\"0\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"Zrzut ekranu 2020-03-26 o 09.11.01\" data-image-description=\"\" data-image-caption=\"\" data-large-file=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2020\/03\/Zrzut-ekranu-2020-03-26-o-09.11.01.png?fit=560%2C834&amp;ssl=1\" class=\"alignnone  wp-image-2592\" src=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2020\/03\/Zrzut-ekranu-2020-03-26-o-09.11.01.png?resize=286%2C426&#038;ssl=1\" alt=\"NSX-t VPN\" width=\"286\" height=\"426\" srcset=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2020\/03\/Zrzut-ekranu-2020-03-26-o-09.11.01.png?w=560&amp;ssl=1 560w, https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2020\/03\/Zrzut-ekranu-2020-03-26-o-09.11.01.png?resize=201%2C300&amp;ssl=1 201w\" sizes=\"auto, (max-width: 286px) 100vw, 286px\" \/><\/a><\/li>\r\n<li>Skonfigurujemy profile dla IKE,IPSec przechodz\u0105c do Profiles\u00a0<br \/><a href=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2020\/03\/Zrzut-ekranu-2020-03-26-o-09.11.14.png?ssl=1\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" data-attachment-id=\"2594\" data-permalink=\"https:\/\/www.safekom.pl\/blog\/vmware\/nsx\/nsx-t-ipsec-route-base\/attachment\/zrzut-ekranu-2020-03-26-o-09-11-14\/\" data-orig-file=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2020\/03\/Zrzut-ekranu-2020-03-26-o-09.11.14.png?fit=2160%2C834&amp;ssl=1\" data-orig-size=\"2160,834\" data-comments-opened=\"0\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"Zrzut ekranu 2020-03-26 o 09.11.14\" data-image-description=\"\" data-image-caption=\"\" data-large-file=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2020\/03\/Zrzut-ekranu-2020-03-26-o-09.11.14.png?fit=770%2C297&amp;ssl=1\" class=\"alignnone size-full wp-image-2594\" src=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2020\/03\/Zrzut-ekranu-2020-03-26-o-09.11.14.png?resize=770%2C297&#038;ssl=1\" alt=\"nsx-t profiles\" width=\"770\" height=\"297\" srcset=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2020\/03\/Zrzut-ekranu-2020-03-26-o-09.11.14.png?w=2160&amp;ssl=1 2160w, https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2020\/03\/Zrzut-ekranu-2020-03-26-o-09.11.14.png?resize=300%2C116&amp;ssl=1 300w, https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2020\/03\/Zrzut-ekranu-2020-03-26-o-09.11.14.png?resize=1024%2C395&amp;ssl=1 1024w, https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2020\/03\/Zrzut-ekranu-2020-03-26-o-09.11.14.png?resize=768%2C297&amp;ssl=1 768w, https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2020\/03\/Zrzut-ekranu-2020-03-26-o-09.11.14.png?resize=1536%2C593&amp;ssl=1 1536w, https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2020\/03\/Zrzut-ekranu-2020-03-26-o-09.11.14.png?resize=2048%2C791&amp;ssl=1 2048w\" sizes=\"auto, (max-width: 770px) 100vw, 770px\" \/><\/a><\/li>\r\n<li>wybieramy IKE-Profiles nast\u0119pnie IKE ADD Profile, w nowym oknie podajemy parametry konfiguracyjne kt\u00f3re zosta\u0142y zebrane powy\u017cej w tabelce oraz podajemy nazw\u0119 dla profilu. Po zako\u0144czeniu wprowadzaniu zapisujemy profil.<br \/><a href=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2020\/03\/Zrzut-ekranu-2020-03-26-o-10.14.13.png?ssl=1\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" data-attachment-id=\"2595\" data-permalink=\"https:\/\/www.safekom.pl\/blog\/vmware\/nsx\/nsx-t-ipsec-route-base\/attachment\/zrzut-ekranu-2020-03-26-o-10-14-13\/\" data-orig-file=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2020\/03\/Zrzut-ekranu-2020-03-26-o-10.14.13.png?fit=2160%2C834&amp;ssl=1\" data-orig-size=\"2160,834\" data-comments-opened=\"0\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"Zrzut ekranu 2020-03-26 o 10.14.13\" data-image-description=\"\" data-image-caption=\"\" data-large-file=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2020\/03\/Zrzut-ekranu-2020-03-26-o-10.14.13.png?fit=770%2C297&amp;ssl=1\" class=\"alignnone size-full wp-image-2595\" src=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2020\/03\/Zrzut-ekranu-2020-03-26-o-10.14.13.png?resize=770%2C297&#038;ssl=1\" alt=\"NSXt ike profile \" width=\"770\" height=\"297\" srcset=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2020\/03\/Zrzut-ekranu-2020-03-26-o-10.14.13.png?w=2160&amp;ssl=1 2160w, https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2020\/03\/Zrzut-ekranu-2020-03-26-o-10.14.13.png?resize=300%2C116&amp;ssl=1 300w, https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2020\/03\/Zrzut-ekranu-2020-03-26-o-10.14.13.png?resize=1024%2C395&amp;ssl=1 1024w, https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2020\/03\/Zrzut-ekranu-2020-03-26-o-10.14.13.png?resize=768%2C297&amp;ssl=1 768w, https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2020\/03\/Zrzut-ekranu-2020-03-26-o-10.14.13.png?resize=1536%2C593&amp;ssl=1 1536w, https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2020\/03\/Zrzut-ekranu-2020-03-26-o-10.14.13.png?resize=2048%2C791&amp;ssl=1 2048w\" sizes=\"auto, (max-width: 770px) 100vw, 770px\" \/><\/a><\/li>\r\n<li>Kolejnym krokiem jest dodanie profilu dla IPSeca, Wybieramy IPSEC Profiles i nast\u0119pnie ADD IPSEC Profile w nowym oknie podajemy nazw\u0119 dla niego oraz parametry z tabelki powy\u017cej.<br \/><a href=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2020\/03\/Zrzut-ekranu-2020-03-26-o-10.16.26.png?ssl=1\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" data-attachment-id=\"2596\" data-permalink=\"https:\/\/www.safekom.pl\/blog\/vmware\/nsx\/nsx-t-ipsec-route-base\/attachment\/zrzut-ekranu-2020-03-26-o-10-16-26\/\" data-orig-file=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2020\/03\/Zrzut-ekranu-2020-03-26-o-10.16.26.png?fit=2160%2C834&amp;ssl=1\" data-orig-size=\"2160,834\" data-comments-opened=\"0\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"Zrzut ekranu 2020-03-26 o 10.16.26\" data-image-description=\"\" data-image-caption=\"\" data-large-file=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2020\/03\/Zrzut-ekranu-2020-03-26-o-10.16.26.png?fit=770%2C297&amp;ssl=1\" class=\"alignnone size-full wp-image-2596\" src=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2020\/03\/Zrzut-ekranu-2020-03-26-o-10.16.26.png?resize=770%2C297&#038;ssl=1\" alt=\"NSX-t ipsec profile\" width=\"770\" height=\"297\" srcset=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2020\/03\/Zrzut-ekranu-2020-03-26-o-10.16.26.png?w=2160&amp;ssl=1 2160w, https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2020\/03\/Zrzut-ekranu-2020-03-26-o-10.16.26.png?resize=300%2C116&amp;ssl=1 300w, https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2020\/03\/Zrzut-ekranu-2020-03-26-o-10.16.26.png?resize=1024%2C395&amp;ssl=1 1024w, https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2020\/03\/Zrzut-ekranu-2020-03-26-o-10.16.26.png?resize=768%2C297&amp;ssl=1 768w, https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2020\/03\/Zrzut-ekranu-2020-03-26-o-10.16.26.png?resize=1536%2C593&amp;ssl=1 1536w, https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2020\/03\/Zrzut-ekranu-2020-03-26-o-10.16.26.png?resize=2048%2C791&amp;ssl=1 2048w\" sizes=\"auto, (max-width: 770px) 100vw, 770px\" \/><\/a><\/li>\r\n<li>Ostatnim profilem do utworzenie jest profil DPD, wybieramy DPD Profiles i ADD DPD Profile, w nowym oknie podajemy nazw\u0119 oraz zostawiamy 60 secund.<br \/><a href=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2020\/03\/Zrzut-ekranu-2020-03-26-o-10.18.02.png?ssl=1\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" data-attachment-id=\"2597\" data-permalink=\"https:\/\/www.safekom.pl\/blog\/vmware\/nsx\/nsx-t-ipsec-route-base\/attachment\/zrzut-ekranu-2020-03-26-o-10-18-02\/\" data-orig-file=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2020\/03\/Zrzut-ekranu-2020-03-26-o-10.18.02.png?fit=2160%2C648&amp;ssl=1\" data-orig-size=\"2160,648\" data-comments-opened=\"0\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"Zrzut ekranu 2020-03-26 o 10.18.02\" data-image-description=\"\" data-image-caption=\"\" data-large-file=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2020\/03\/Zrzut-ekranu-2020-03-26-o-10.18.02.png?fit=770%2C231&amp;ssl=1\" class=\"alignnone size-full wp-image-2597\" src=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2020\/03\/Zrzut-ekranu-2020-03-26-o-10.18.02.png?resize=770%2C231&#038;ssl=1\" alt=\"NSX-t DPD profile\" width=\"770\" height=\"231\" srcset=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2020\/03\/Zrzut-ekranu-2020-03-26-o-10.18.02.png?w=2160&amp;ssl=1 2160w, https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2020\/03\/Zrzut-ekranu-2020-03-26-o-10.18.02.png?resize=300%2C90&amp;ssl=1 300w, https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2020\/03\/Zrzut-ekranu-2020-03-26-o-10.18.02.png?resize=1024%2C307&amp;ssl=1 1024w, https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2020\/03\/Zrzut-ekranu-2020-03-26-o-10.18.02.png?resize=768%2C230&amp;ssl=1 768w, https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2020\/03\/Zrzut-ekranu-2020-03-26-o-10.18.02.png?resize=1536%2C461&amp;ssl=1 1536w, https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2020\/03\/Zrzut-ekranu-2020-03-26-o-10.18.02.png?resize=2048%2C614&amp;ssl=1 2048w\" sizes=\"auto, (max-width: 770px) 100vw, 770px\" \/><\/a><\/li>\r\n<li>Po skonfigurowaniu profilu dla IKE i IPSec oraz DPD przechodzimy do konfiguracji VPN Service robimy to przechodz\u0105c do VPN Services gdzie klikamy na ADD Service i wybieramy IPSEC. W nowym oknie podajemy nazw\u0119 oraz wybieramy na kt\u00f3ry gateway ma zosta\u0107 uruchomiony serwis odpowiedzialny za IPSeca w naszym przypadku b\u0119dzie to T0.<br \/><a href=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2020\/03\/Zrzut-ekranu-2020-03-26-o-10.20.23.png?ssl=1\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" data-attachment-id=\"2598\" data-permalink=\"https:\/\/www.safekom.pl\/blog\/vmware\/nsx\/nsx-t-ipsec-route-base\/attachment\/zrzut-ekranu-2020-03-26-o-10-20-23\/\" data-orig-file=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2020\/03\/Zrzut-ekranu-2020-03-26-o-10.20.23.png?fit=2344%2C998&amp;ssl=1\" data-orig-size=\"2344,998\" data-comments-opened=\"0\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"Zrzut ekranu 2020-03-26 o 10.20.23\" data-image-description=\"\" data-image-caption=\"\" data-large-file=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2020\/03\/Zrzut-ekranu-2020-03-26-o-10.20.23.png?fit=770%2C328&amp;ssl=1\" class=\"alignnone size-full wp-image-2598\" src=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2020\/03\/Zrzut-ekranu-2020-03-26-o-10.20.23.png?resize=770%2C328&#038;ssl=1\" alt=\"NSX-T VPN Service\" width=\"770\" height=\"328\" srcset=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2020\/03\/Zrzut-ekranu-2020-03-26-o-10.20.23.png?w=2344&amp;ssl=1 2344w, https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2020\/03\/Zrzut-ekranu-2020-03-26-o-10.20.23.png?resize=300%2C128&amp;ssl=1 300w, https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2020\/03\/Zrzut-ekranu-2020-03-26-o-10.20.23.png?resize=1024%2C436&amp;ssl=1 1024w, https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2020\/03\/Zrzut-ekranu-2020-03-26-o-10.20.23.png?resize=768%2C327&amp;ssl=1 768w, https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2020\/03\/Zrzut-ekranu-2020-03-26-o-10.20.23.png?resize=1536%2C654&amp;ssl=1 1536w, https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2020\/03\/Zrzut-ekranu-2020-03-26-o-10.20.23.png?resize=2048%2C872&amp;ssl=1 2048w\" sizes=\"auto, (max-width: 770px) 100vw, 770px\" \/><\/a><\/li>\r\n<li>W tym kroku przechodzimy do konfiguracji LOCAL EDNPOINTS\u00a0 klikamy ADD LOCAL ENDPOINT w tym miejscu skonfigurujemy adres z kt\u00f3rego oraz do kt\u00f3rego b\u0119dziemy nawi\u0105zywa\u0107 sesj\u0119 IPSec.<br \/><a href=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2020\/03\/Zrzut-ekranu-2020-03-26-o-10.22.12.png?ssl=1\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" data-attachment-id=\"2599\" data-permalink=\"https:\/\/www.safekom.pl\/blog\/vmware\/nsx\/nsx-t-ipsec-route-base\/attachment\/zrzut-ekranu-2020-03-26-o-10-22-12\/\" data-orig-file=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2020\/03\/Zrzut-ekranu-2020-03-26-o-10.22.12.png?fit=2344%2C998&amp;ssl=1\" data-orig-size=\"2344,998\" data-comments-opened=\"0\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"Zrzut ekranu 2020-03-26 o 10.22.12\" data-image-description=\"\" data-image-caption=\"\" data-large-file=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2020\/03\/Zrzut-ekranu-2020-03-26-o-10.22.12.png?fit=770%2C328&amp;ssl=1\" class=\"alignnone size-full wp-image-2599\" src=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2020\/03\/Zrzut-ekranu-2020-03-26-o-10.22.12.png?resize=770%2C328&#038;ssl=1\" alt=\"NSXt vpn local endpoint\" width=\"770\" height=\"328\" srcset=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2020\/03\/Zrzut-ekranu-2020-03-26-o-10.22.12.png?w=2344&amp;ssl=1 2344w, https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2020\/03\/Zrzut-ekranu-2020-03-26-o-10.22.12.png?resize=300%2C128&amp;ssl=1 300w, https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2020\/03\/Zrzut-ekranu-2020-03-26-o-10.22.12.png?resize=1024%2C436&amp;ssl=1 1024w, https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2020\/03\/Zrzut-ekranu-2020-03-26-o-10.22.12.png?resize=768%2C327&amp;ssl=1 768w, https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2020\/03\/Zrzut-ekranu-2020-03-26-o-10.22.12.png?resize=1536%2C654&amp;ssl=1 1536w, https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2020\/03\/Zrzut-ekranu-2020-03-26-o-10.22.12.png?resize=2048%2C872&amp;ssl=1 2048w\" sizes=\"auto, (max-width: 770px) 100vw, 770px\" \/><\/a><\/li>\r\n<li>Przyszed\u0142 na ostatni krok konfiguracji IPSec przechodzimy do IPSEC SESION wybieramy Route Based.<br \/><a href=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2020\/03\/Zrzut-ekranu-2020-03-26-o-10.24.54.png?ssl=1\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" data-attachment-id=\"2600\" data-permalink=\"https:\/\/www.safekom.pl\/blog\/vmware\/nsx\/nsx-t-ipsec-route-base\/attachment\/zrzut-ekranu-2020-03-26-o-10-24-54\/\" data-orig-file=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2020\/03\/Zrzut-ekranu-2020-03-26-o-10.24.54.png?fit=706%2C426&amp;ssl=1\" data-orig-size=\"706,426\" data-comments-opened=\"0\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"Zrzut ekranu 2020-03-26 o 10.24.54\" data-image-description=\"\" data-image-caption=\"\" data-large-file=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2020\/03\/Zrzut-ekranu-2020-03-26-o-10.24.54.png?fit=706%2C426&amp;ssl=1\" class=\"alignnone  wp-image-2600\" src=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2020\/03\/Zrzut-ekranu-2020-03-26-o-10.24.54.png?resize=442%2C267&#038;ssl=1\" alt=\"nsx-t ipsec route based\" width=\"442\" height=\"267\" srcset=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2020\/03\/Zrzut-ekranu-2020-03-26-o-10.24.54.png?w=706&amp;ssl=1 706w, https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2020\/03\/Zrzut-ekranu-2020-03-26-o-10.24.54.png?resize=300%2C181&amp;ssl=1 300w\" sizes=\"auto, (max-width: 442px) 100vw, 442px\" \/><\/a><\/li>\r\n<li>W nowym okniekonfigurujemy nasz\u0105 sesj\u0119 IPSec podajemy dane:<br \/>Nazwa &#8211; dowolna nazwa dla sesji.<br \/>VPN Service &#8211; wybieramy wcze\u015bniej zdefiniowany profil.<br \/>Local Endpoint &#8211; podobnie wybieramy profil kt\u00f3ry wcze\u015bniej skonfigurowali\u015bmy.<br \/>Remote IP &#8211; podajemy adres IP partnera z kt\u00f3rym b\u0119dziemy nawi\u0105zywa\u0107 sesj\u0119 IPSec.<br \/>Authentication Mode &#8211; w naszym przypadku wybieramy PSK mo\u017ce kiedy\u015b zrobi\u0119 opis na certach :-).<br \/>Pre-shared Key &#8211; podajemy nasz klucz PSK\u00a0<br \/>Tunnel Interface &#8211; podajemy ip dla naszego interfejsu tunel w naszym przypadku jest to 100.100.10.1\/30 musi by\u0107 podana maska min 31.<br \/>Remote ID &#8211; podajemy zako\u0144czenie tunelu po drugiej stronie, zgodnie z za\u0142o\u017ceniami jest to 2.2.2.2<br \/>Do kolejnych ustawie\u0144 przechodzimy klikaj\u0105c<strong class=\"ng-tns-c93-140\">\u00a0 Advanced Properties<\/strong> gdzie dalej podajemy parametry naszego po\u0142\u0105czenia:<br \/>IKE Profiles &#8211; wybieramy utworzony przez nas profil IKE.<br \/>IPSec Profiles &#8211; wybieramy utworzony przez nas profil dla IPSec.<br \/>DPD Profiles &#8211; wybieramy utworzony profil dla DPD.<br \/>Connection Initiation &#8211; okre\u015blmy rol\u0119 w naszym przypadku zostawiamy bez zmiany.<br \/>Parametry nie wymienione zostawiamy bez zmian.<br \/><a href=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2020\/03\/Zrzut-ekranu-2020-03-26-o-10.29.51.png?ssl=1\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" data-attachment-id=\"2601\" data-permalink=\"https:\/\/www.safekom.pl\/blog\/vmware\/nsx\/nsx-t-ipsec-route-base\/attachment\/zrzut-ekranu-2020-03-26-o-10-29-51\/\" data-orig-file=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2020\/03\/Zrzut-ekranu-2020-03-26-o-10.29.51.png?fit=2344%2C1110&amp;ssl=1\" data-orig-size=\"2344,1110\" data-comments-opened=\"0\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"Zrzut ekranu 2020-03-26 o 10.29.51\" data-image-description=\"\" data-image-caption=\"\" data-large-file=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2020\/03\/Zrzut-ekranu-2020-03-26-o-10.29.51.png?fit=770%2C365&amp;ssl=1\" class=\"alignnone size-full wp-image-2601\" src=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2020\/03\/Zrzut-ekranu-2020-03-26-o-10.29.51.png?resize=770%2C365&#038;ssl=1\" alt=\"NSX-t vpn ipsec sesion\" width=\"770\" height=\"365\" srcset=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2020\/03\/Zrzut-ekranu-2020-03-26-o-10.29.51.png?w=2344&amp;ssl=1 2344w, https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2020\/03\/Zrzut-ekranu-2020-03-26-o-10.29.51.png?resize=300%2C142&amp;ssl=1 300w, https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2020\/03\/Zrzut-ekranu-2020-03-26-o-10.29.51.png?resize=1024%2C485&amp;ssl=1 1024w, https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2020\/03\/Zrzut-ekranu-2020-03-26-o-10.29.51.png?resize=768%2C364&amp;ssl=1 768w, https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2020\/03\/Zrzut-ekranu-2020-03-26-o-10.29.51.png?resize=1536%2C727&amp;ssl=1 1536w, https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2020\/03\/Zrzut-ekranu-2020-03-26-o-10.29.51.png?resize=2048%2C970&amp;ssl=1 2048w\" sizes=\"auto, (max-width: 770px) 100vw, 770px\" \/><\/a><\/li>\r\n<li>Po wy\u017cszych krokach mam skonfigurowane parametry dla IPSeca Rouet Base.<\/li>\r\n<\/ol>\r\n\r\n\r\n\r\n<h5 class=\"wp-block-heading\">Konfiguracja Routingu w NSX<\/h5>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">W tej sekcji dowiesz si\u0119 jak skonfigurowa\u0107 redystrybucj\u0119 adres Local Endpoint oraz jak zestawi\u0107 BGP.\u00a0<\/p>\r\n\r\n\r\n\r\n<h6 class=\"wp-block-heading\">Konfiguracja redystrybucji<\/h6>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">Aby poprawnie zestawi\u0107 po\u0142\u0105czenie IPSec przyda\u0142o by si\u0119 do naszej chmurki kt\u00f3ra jest pokazana na rysunku na pocz\u0105tku wpisu rozg\u0142osi\u0107 adres Local Endpoint a robimy to tak:<\/p>\r\n\r\n\r\n\r\n<ol class=\"wp-block-list\">\r\n<li>Przechodzimy do Networking nast\u0119pnie do Tier0 wybieramy nasz router T0 i przechodzimy do jego edycji.<br \/><a href=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2020\/03\/Zrzut-ekranu-2020-03-26-o-10.32.50.png?ssl=1\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" data-attachment-id=\"2603\" data-permalink=\"https:\/\/www.safekom.pl\/blog\/vmware\/nsx\/nsx-t-ipsec-route-base\/attachment\/zrzut-ekranu-2020-03-26-o-10-32-50\/\" data-orig-file=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2020\/03\/Zrzut-ekranu-2020-03-26-o-10.32.50.png?fit=1036%2C552&amp;ssl=1\" data-orig-size=\"1036,552\" data-comments-opened=\"0\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"Zrzut ekranu 2020-03-26 o 10.32.50\" data-image-description=\"\" data-image-caption=\"\" data-large-file=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2020\/03\/Zrzut-ekranu-2020-03-26-o-10.32.50.png?fit=770%2C411&amp;ssl=1\" class=\"alignnone  wp-image-2603\" src=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2020\/03\/Zrzut-ekranu-2020-03-26-o-10.32.50.png?resize=476%2C254&#038;ssl=1\" alt=\"EDIT T0 router\" width=\"476\" height=\"254\" srcset=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2020\/03\/Zrzut-ekranu-2020-03-26-o-10.32.50.png?w=1036&amp;ssl=1 1036w, https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2020\/03\/Zrzut-ekranu-2020-03-26-o-10.32.50.png?resize=300%2C160&amp;ssl=1 300w, https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2020\/03\/Zrzut-ekranu-2020-03-26-o-10.32.50.png?resize=1024%2C546&amp;ssl=1 1024w, https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2020\/03\/Zrzut-ekranu-2020-03-26-o-10.32.50.png?resize=768%2C409&amp;ssl=1 768w\" sizes=\"auto, (max-width: 476px) 100vw, 476px\" \/><\/a><\/li>\r\n<li>Przechodzimy do ROUTE RE-DISTRIBUTION klikamy na cyfr\u0119 w przy Route Re-Distribution.<br \/><a href=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2020\/03\/Zrzut-ekranu-2020-03-26-o-10.33.20.png?ssl=1\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" data-attachment-id=\"2604\" data-permalink=\"https:\/\/www.safekom.pl\/blog\/vmware\/nsx\/nsx-t-ipsec-route-base\/attachment\/zrzut-ekranu-2020-03-26-o-10-33-20\/\" data-orig-file=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2020\/03\/Zrzut-ekranu-2020-03-26-o-10.33.20.png?fit=2302%2C746&amp;ssl=1\" data-orig-size=\"2302,746\" data-comments-opened=\"0\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"Zrzut ekranu 2020-03-26 o 10.33.20\" data-image-description=\"\" data-image-caption=\"\" data-large-file=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2020\/03\/Zrzut-ekranu-2020-03-26-o-10.33.20.png?fit=770%2C250&amp;ssl=1\" class=\"alignnone size-full wp-image-2604\" src=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2020\/03\/Zrzut-ekranu-2020-03-26-o-10.33.20.png?resize=770%2C250&#038;ssl=1\" alt=\"t0\" width=\"770\" height=\"250\" srcset=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2020\/03\/Zrzut-ekranu-2020-03-26-o-10.33.20.png?w=2302&amp;ssl=1 2302w, https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2020\/03\/Zrzut-ekranu-2020-03-26-o-10.33.20.png?resize=300%2C97&amp;ssl=1 300w, https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2020\/03\/Zrzut-ekranu-2020-03-26-o-10.33.20.png?resize=1024%2C332&amp;ssl=1 1024w, https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2020\/03\/Zrzut-ekranu-2020-03-26-o-10.33.20.png?resize=768%2C249&amp;ssl=1 768w, https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2020\/03\/Zrzut-ekranu-2020-03-26-o-10.33.20.png?resize=1536%2C498&amp;ssl=1 1536w, https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2020\/03\/Zrzut-ekranu-2020-03-26-o-10.33.20.png?resize=2048%2C664&amp;ssl=1 2048w\" sizes=\"auto, (max-width: 770px) 100vw, 770px\" \/><\/a><\/li>\r\n<li>W nowym oknie zaznaczamy IPSec Local IP i klikamy Apply.<br \/><a href=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2020\/03\/Zrzut-ekranu-2020-03-26-o-10.33.33.png?ssl=1\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" data-attachment-id=\"2605\" data-permalink=\"https:\/\/www.safekom.pl\/blog\/vmware\/nsx\/nsx-t-ipsec-route-base\/attachment\/zrzut-ekranu-2020-03-26-o-10-33-33\/\" data-orig-file=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2020\/03\/Zrzut-ekranu-2020-03-26-o-10.33.33.png?fit=1592%2C1038&amp;ssl=1\" data-orig-size=\"1592,1038\" data-comments-opened=\"0\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"Zrzut ekranu 2020-03-26 o 10.33.33\" data-image-description=\"\" data-image-caption=\"\" data-large-file=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2020\/03\/Zrzut-ekranu-2020-03-26-o-10.33.33.png?fit=770%2C502&amp;ssl=1\" class=\"alignnone size-full wp-image-2605\" src=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2020\/03\/Zrzut-ekranu-2020-03-26-o-10.33.33.png?resize=770%2C502&#038;ssl=1\" alt=\"IPSec local IP\" width=\"770\" height=\"502\" srcset=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2020\/03\/Zrzut-ekranu-2020-03-26-o-10.33.33.png?w=1592&amp;ssl=1 1592w, https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2020\/03\/Zrzut-ekranu-2020-03-26-o-10.33.33.png?resize=300%2C196&amp;ssl=1 300w, https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2020\/03\/Zrzut-ekranu-2020-03-26-o-10.33.33.png?resize=1024%2C668&amp;ssl=1 1024w, https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2020\/03\/Zrzut-ekranu-2020-03-26-o-10.33.33.png?resize=768%2C501&amp;ssl=1 768w, https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2020\/03\/Zrzut-ekranu-2020-03-26-o-10.33.33.png?resize=1536%2C1001&amp;ssl=1 1536w\" sizes=\"auto, (max-width: 770px) 100vw, 770px\" \/><\/a><\/li>\r\n<li>Na koniec zapisujemy oraz klikamy close editing i temat ten mamy za sob\u0105.\u00a0<\/li>\r\n<\/ol>\r\n\r\n\r\n\r\n<h6 class=\"wp-block-heading\">Konfiguracja BGP pomi\u0119dzy NSX a Vyos<\/h6>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">W IPSec route base protok\u00f3\u0142 routingu jest odpowiedzialny za ustalenie pomi\u0119dzy jakimi sieciami ma nast\u0105pi\u0107 szyfrowanie w kanale IPSec. W NSX-t mamy do dyspozycji dwa protoko\u0142y routingu jest to statk oraz BGP w tym punkcie skupi\u0119 si\u0119 w\u0142a\u015bnie nad poczciwym BGP&#8217;em.\u00a0<\/p>\r\n\r\n\r\n\r\n<ol class=\"wp-block-list\">\r\n<li>Aby skonfigurowa\u0107 sesj\u0119 BGP przechodzimy do Networking nast\u0119pnie do Tier0 wybieramy nasz router T0 i przechodzimy do jego edycji<br \/><a href=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2020\/03\/Zrzut-ekranu-2020-03-26-o-10.32.50.png?ssl=1\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" data-attachment-id=\"2603\" data-permalink=\"https:\/\/www.safekom.pl\/blog\/vmware\/nsx\/nsx-t-ipsec-route-base\/attachment\/zrzut-ekranu-2020-03-26-o-10-32-50\/\" data-orig-file=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2020\/03\/Zrzut-ekranu-2020-03-26-o-10.32.50.png?fit=1036%2C552&amp;ssl=1\" data-orig-size=\"1036,552\" data-comments-opened=\"0\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"Zrzut ekranu 2020-03-26 o 10.32.50\" data-image-description=\"\" data-image-caption=\"\" data-large-file=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2020\/03\/Zrzut-ekranu-2020-03-26-o-10.32.50.png?fit=770%2C411&amp;ssl=1\" class=\"alignnone size-full wp-image-2603\" src=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2020\/03\/Zrzut-ekranu-2020-03-26-o-10.32.50.png?resize=770%2C410&#038;ssl=1\" alt=\"EDIT T0 router\" width=\"770\" height=\"410\" srcset=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2020\/03\/Zrzut-ekranu-2020-03-26-o-10.32.50.png?w=1036&amp;ssl=1 1036w, https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2020\/03\/Zrzut-ekranu-2020-03-26-o-10.32.50.png?resize=300%2C160&amp;ssl=1 300w, https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2020\/03\/Zrzut-ekranu-2020-03-26-o-10.32.50.png?resize=1024%2C546&amp;ssl=1 1024w, https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2020\/03\/Zrzut-ekranu-2020-03-26-o-10.32.50.png?resize=768%2C409&amp;ssl=1 768w\" sizes=\"auto, (max-width: 770px) 100vw, 770px\" \/><\/a><\/li>\r\n<li>Tam przechodzimy do sesji BGP, gdzie jest to pierwsza sesja BGP konfigurujemy:<br \/>Local AS &#8211; w labie oraz DC wybieramy co\u015b z puli privet AS\u00a0<br \/>reszt\u0119 parametr\u00f3w zostawiamy bez zmian w labie, w DC mo\u017cna podkr\u0119ci\u0107 czasy sesji BGP\u00a0<br \/>Tutaj ju\u017c mamy to skonfigurowane bo mamy sesj\u0119 do mojej chmurki\u00a0<br \/><a href=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2020\/03\/Zrzut-ekranu-2020-03-26-o-10.42.44.png?ssl=1\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" data-attachment-id=\"2606\" data-permalink=\"https:\/\/www.safekom.pl\/blog\/vmware\/nsx\/nsx-t-ipsec-route-base\/attachment\/zrzut-ekranu-2020-03-26-o-10-42-44\/\" data-orig-file=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2020\/03\/Zrzut-ekranu-2020-03-26-o-10.42.44.png?fit=2344%2C1110&amp;ssl=1\" data-orig-size=\"2344,1110\" data-comments-opened=\"0\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"Zrzut ekranu 2020-03-26 o 10.42.44\" data-image-description=\"\" data-image-caption=\"\" data-large-file=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2020\/03\/Zrzut-ekranu-2020-03-26-o-10.42.44.png?fit=770%2C365&amp;ssl=1\" class=\"alignnone size-full wp-image-2606\" src=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2020\/03\/Zrzut-ekranu-2020-03-26-o-10.42.44.png?resize=770%2C365&#038;ssl=1\" alt=\"nsx-t bgp\" width=\"770\" height=\"365\" srcset=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2020\/03\/Zrzut-ekranu-2020-03-26-o-10.42.44.png?w=2344&amp;ssl=1 2344w, https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2020\/03\/Zrzut-ekranu-2020-03-26-o-10.42.44.png?resize=300%2C142&amp;ssl=1 300w, https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2020\/03\/Zrzut-ekranu-2020-03-26-o-10.42.44.png?resize=1024%2C485&amp;ssl=1 1024w, https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2020\/03\/Zrzut-ekranu-2020-03-26-o-10.42.44.png?resize=768%2C364&amp;ssl=1 768w, https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2020\/03\/Zrzut-ekranu-2020-03-26-o-10.42.44.png?resize=1536%2C727&amp;ssl=1 1536w, https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2020\/03\/Zrzut-ekranu-2020-03-26-o-10.42.44.png?resize=2048%2C970&amp;ssl=1 2048w\" sizes=\"auto, (max-width: 770px) 100vw, 770px\" \/><\/a><\/li>\r\n<li>W kolejnym wa\u017cnym krokiem jest skonfigurowanie s\u0105siedztwa BGP aby to zrobi\u0107 przechodzimy do BGP Neighbors. W tym przypadku dodajemy kolejne s\u0105siedztwo.\u00a0<br \/><a href=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2020\/03\/Zrzut-ekranu-2020-03-26-o-10.44.23.png?ssl=1\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" data-attachment-id=\"2607\" data-permalink=\"https:\/\/www.safekom.pl\/blog\/vmware\/nsx\/nsx-t-ipsec-route-base\/attachment\/zrzut-ekranu-2020-03-26-o-10-44-23\/\" data-orig-file=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2020\/03\/Zrzut-ekranu-2020-03-26-o-10.44.23.png?fit=2098%2C1182&amp;ssl=1\" data-orig-size=\"2098,1182\" data-comments-opened=\"0\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"Zrzut ekranu 2020-03-26 o 10.44.23\" data-image-description=\"\" data-image-caption=\"\" data-large-file=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2020\/03\/Zrzut-ekranu-2020-03-26-o-10.44.23.png?fit=770%2C434&amp;ssl=1\" class=\"alignnone size-full wp-image-2607\" src=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2020\/03\/Zrzut-ekranu-2020-03-26-o-10.44.23.png?resize=770%2C434&#038;ssl=1\" alt=\"bgp sasiedzwto\" width=\"770\" height=\"434\" srcset=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2020\/03\/Zrzut-ekranu-2020-03-26-o-10.44.23.png?w=2098&amp;ssl=1 2098w, https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2020\/03\/Zrzut-ekranu-2020-03-26-o-10.44.23.png?resize=300%2C169&amp;ssl=1 300w, https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2020\/03\/Zrzut-ekranu-2020-03-26-o-10.44.23.png?resize=1024%2C577&amp;ssl=1 1024w, https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2020\/03\/Zrzut-ekranu-2020-03-26-o-10.44.23.png?resize=768%2C433&amp;ssl=1 768w, https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2020\/03\/Zrzut-ekranu-2020-03-26-o-10.44.23.png?resize=1536%2C865&amp;ssl=1 1536w, https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2020\/03\/Zrzut-ekranu-2020-03-26-o-10.44.23.png?resize=2048%2C1154&amp;ssl=1 2048w\" sizes=\"auto, (max-width: 770px) 100vw, 770px\" \/><\/a><\/li>\r\n<li>W nowym oknie dodajemy nowego s\u0105siada gdzie podajemy\u00a0parametry do skonfigurowania<br \/>IP Address &#8211; podajemy adres ip s\u0105siada w naszym przypadku jest to 100.100.10.2<br \/>Remote AS &#8211; Podajemy numer AS s\u0105siada w naszym przypadku jest to 65555<br \/>Source Addresses &#8211; podajemy nasz adres 100.100.10.1<br \/><label class=\"nsx-form-group-label ng-star-inserted\">IP Address Family &#8211; wybieramy IPv4<\/label>\r\n<div class=\"nsx-form-group-field\"><a href=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2020\/03\/Zrzut-ekranu-2020-03-26-o-10.47.20.png?ssl=1\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" data-attachment-id=\"2608\" data-permalink=\"https:\/\/www.safekom.pl\/blog\/vmware\/nsx\/nsx-t-ipsec-route-base\/attachment\/zrzut-ekranu-2020-03-26-o-10-47-20\/\" data-orig-file=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2020\/03\/Zrzut-ekranu-2020-03-26-o-10.47.20.png?fit=2344%2C1110&amp;ssl=1\" data-orig-size=\"2344,1110\" data-comments-opened=\"0\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"Zrzut ekranu 2020-03-26 o 10.47.20\" data-image-description=\"\" data-image-caption=\"\" data-large-file=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2020\/03\/Zrzut-ekranu-2020-03-26-o-10.47.20.png?fit=770%2C365&amp;ssl=1\" class=\"alignnone size-full wp-image-2608\" src=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2020\/03\/Zrzut-ekranu-2020-03-26-o-10.47.20.png?resize=770%2C365&#038;ssl=1\" alt=\"bgp add \" width=\"770\" height=\"365\" srcset=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2020\/03\/Zrzut-ekranu-2020-03-26-o-10.47.20.png?w=2344&amp;ssl=1 2344w, https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2020\/03\/Zrzut-ekranu-2020-03-26-o-10.47.20.png?resize=300%2C142&amp;ssl=1 300w, https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2020\/03\/Zrzut-ekranu-2020-03-26-o-10.47.20.png?resize=1024%2C485&amp;ssl=1 1024w, https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2020\/03\/Zrzut-ekranu-2020-03-26-o-10.47.20.png?resize=768%2C364&amp;ssl=1 768w, https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2020\/03\/Zrzut-ekranu-2020-03-26-o-10.47.20.png?resize=1536%2C727&amp;ssl=1 1536w, https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2020\/03\/Zrzut-ekranu-2020-03-26-o-10.47.20.png?resize=2048%2C970&amp;ssl=1 2048w\" sizes=\"auto, (max-width: 770px) 100vw, 770px\" \/><\/a><\/div>\r\n<\/li>\r\n<li>Klikamy Save i mamy skonfigurowane po stronie NSX&#8217;a BGP\u00a0<\/li>\r\n<\/ol>\r\n<p>Aby wszystko zadzia\u0142a\u0142o musimy skonfigurowa\u0107 naszego s\u0105siad czyli przechodzimy do konfiguracji Vyos,<\/p>\r\n\r\n\r\n\r\n<h4 class=\"wp-block-heading\">Konfiguracja Vyos<\/h4>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">Jak to by\u0142o w piosence &#8222;do tanga trzeba dwojga&#8221; w tym przypadku partnerem dla NSX b\u0119dzie Vyos na kt\u00f3rym poni\u017cej przedstawi\u0119 jak skonfigurowa\u0107 IPSec route Based oraz BGP.\u00a0 Nie b\u0119d\u0119 pokazywa\u0142 podstawowej konfiguracji tylko skupi\u0119 si\u0119 na omawianych zagadnieniach. Ca\u0142a konfiguracja jest wykonywana z poziomy SSH. W tym labie wykorzystuj\u0119 wersj\u0119 troch\u0119 star\u0105 bo jest to 1.3\u00a0<\/p>\r\n\r\n\r\n\r\n<h5 class=\"wp-block-heading\">Konfiguracja po\u0142\u0105czenie IPSEC w Vyos<\/h5>\r\n\r\n\r\n\r\n<ol class=\"wp-block-list\">\r\n<li>Logujemy si\u0119 do naszego Vyos po ssh<\/li>\r\n<li>Przechodzimy do konfiguracji i konfigurujemy nasz profil dla fazy 1 zgodnie z za\u0142o\u017ceniami<br \/>\r\n<pre class=\"lang:sh decode:true \">vyos@vyos01:~$ configure \r\n[edit]\r\nvyos@vyos01# set vpn ipsec esp-group NSX-T lifetime '3600'\r\n[edit]\r\nvyos@vyos01# set vpn ipsec esp-group NSX-T mode 'tunnel'\r\n[edit]\r\nvyos@vyos01# set vpn ipsec esp-group NSX-T pfs 'dh-group5'\r\n[edit]\r\nvyos@vyos01# set vpn ipsec esp-group NSX-T proposal 1 encryption 'aes256'  \r\n[edit]\r\nvyos@vyos01# set vpn ipsec esp-group NSX-T proposal 1 hash 'sha256'\r\n[edit]\r\nvyos@vyos01# <\/pre>\r\n<p>czysta konfiguracja same komendy<\/p>\r\n<pre class=\"lang:sh decode:true \">set vpn ipsec esp-group NSX-T lifetime '3600'\r\nset vpn ipsec esp-group NSX-T mode 'tunnel'\r\nset vpn ipsec esp-group NSX-T pfs 'dh-group5'\r\nset vpn ipsec esp-group NSX-T proposal 1 encryption 'aes256'\r\nset vpn ipsec esp-group NSX-T proposal 1 hash 'sha256'<\/pre>\r\n<\/li>\r\n<li>Nast\u0119pnie profil dla fazy 2\u00a0<br \/>\r\n<pre class=\"lang:sh decode:true \">[edit]\r\nvyos@vyos01# set vpn ipsec ike-group NSX-T ikev2-reauth 'yes'\r\n[edit]\r\nvyos@vyos01# set vpn ipsec ike-group NSX-T key-exchange 'ikev2'\r\n[edit]\r\nvyos@vyos01# set vpn ipsec ike-group NSX-T lifetime '86400'\r\n[edit]\r\nvyos@vyos01# set vpn ipsec ike-group NSX-T proposal 1 dh-group '5'\r\n[edit]\r\nvyos@vyos01# set vpn ipsec ike-group NSX-T proposal 1 encryption 'aes256'\r\n[edit]\r\nvyos@vyos01# set vpn ipsec ike-group NSX-T proposal 1 hash 'sha256'\r\n[edit]\r\nvyos@vyos01# <\/pre>\r\n<\/li>\r\n<li>Profil dla DPD<br \/>\r\n<pre class=\"lang:sh decode:true \">[edit]\r\nvyos@vyos01# set vpn ipsec ike-group NSX-T dead-peer-detection action 'restart'\r\n[edit]\r\nvyos@vyos01# set vpn ipsec ike-group NSX-T dead-peer-detection interval '15'\r\n[edit]\r\nvyos@vyos01# set vpn ipsec ike-group NSX-T dead-peer-detection timeout '60'\r\n<\/pre>\r\n<p>same komendy\u00a0<\/p>\r\n<pre class=\"lang:sh decode:true \">set vpn ipsec ike-group NSX-T dead-peer-detection action 'restart'\r\nset vpn ipsec ike-group NSX-T dead-peer-detection interval '15'\r\nset vpn ipsec ike-group NSX-T dead-peer-detection timeout '60'<\/pre>\r\n<\/li>\r\n<li>Tworzymy interfejs tunelowy oraz nadajemy jemu adres ip zgodnie z za\u0142o\u017ceniami<br \/>\r\n<pre class=\"lang:sh decode:true \">[edit]\r\nvyos@vyos01# set interfaces vti vti1 address '100.100.10.2\/30'<\/pre>\r\n<\/li>\r\n<li>Konfiguracja IPSeca<br \/>\r\n<pre class=\"lang:sh decode:true \">[edit]\r\nvyos@vyos01# set vpn ipsec site-to-site peer 1.1.1.1 authentication id '2.2.2.2'\r\n[edit]\r\nvyos@vyos01# set vpn ipsec site-to-site peer 1.1.1.1 authentication mode 'pre-shared-secret'\r\n[edit]\r\nvyos@vyos01# set vpn ipsec site-to-site peer 1.1.1.1 authentication pre-shared-secret 'de%b\/B\\7$*[rV*S%Pk(D'\r\n[edit]\r\nvyos@vyos01# set vpn ipsec site-to-site peer 1.1.1.1 ike-group 'NSX-T'\r\n[edit]\r\nvyos@vyos01# set vpn ipsec site-to-site peer 1.1.1.1 ikev2-reauth 'inherit'\r\n[edit]\r\nvyos@vyos01# set vpn ipsec site-to-site peer 1.1.1.1 local-address '2.2.2.2'\r\n[edit]\r\nvyos@vyos01# set vpn ipsec site-to-site peer 1.1.1.1 vti bind 'vti1'\r\n[edit]\r\nvyos@vyos01# set vpn ipsec site-to-site peer 1.1.1.1 vti esp-group 'NSX-T'\r\n[edit]\r\nvyos@vyos01# <\/pre>\r\nsame komendy kt\u00f3re zosta\u0142y u\u017cyte powy\u017cej\u00a0<br \/>\r\n<pre class=\"lang:sh decode:true\">set vpn ipsec site-to-site peer 1.1.1.1 authentication id '2.2.2.2'\r\nset vpn ipsec site-to-site peer 1.1.1.1 authentication mode 'pre-shared-secret'\r\nset vpn ipsec site-to-site peer 1.1.1.1 authentication pre-shared-secret 'de%b\/B\\7$*[rV*S%Pk(D'\r\nset vpn ipsec site-to-site peer 1.1.1.1 ike-group 'NSX-T'\r\nset vpn ipsec site-to-site peer 1.1.1.1 ikev2-reauth 'inherit'\r\nset vpn ipsec site-to-site peer 1.1.1.1 local-address '2.2.2.2'\r\nset vpn ipsec site-to-site peer 1.1.1.1 vti bind 'vti1'\r\nset vpn ipsec site-to-site peer 1.1.1.1 vti esp-group 'NSX-T'<\/pre>\r\n<\/li>\r\n<li>Na koniec wykonujemy commit<br \/>\r\n<pre class=\"lang:sh decode:true\">[edit]\r\nvyos@vyos01# commit\r\n[edit]\r\nvyos@vyos01# <\/pre>\r\n<p>&nbsp;<\/p>\r\n<\/li>\r\n<\/ol>\r\n\r\n\r\n\r\n<h5 class=\"wp-block-heading\">Konfiguracja BGP w Vyos<\/h5>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">Po skonfigurowaniu IPSeca przechodzimy do konfiguracji sesji BGP, poni\u017cej bardzo szybki config.<\/p>\r\n<pre class=\"lang:sh decode:true\">[edit]\r\nvyos@vyos01# set protocols bgp 65555 \r\n[edit]\r\nvyos@vyos01# set protocols bgp 65555 neighbor 100.100.10.1 remote-as 65502 \r\n[edit]\r\nvyos@vyos01# set protocols bgp 65555 neighbor 100.100.10.1 update-source 100.100.10.2 \r\n[edit]\r\nvyos@vyos01# set protocols bgp 65555 address-family ipv4-unicast redistribute connected\r\n[edit]\r\nvyos@vyos01# commit\r\n[edit]\r\nvyos@vyos01# <\/pre>\r\n<p>same komendy:<\/p>\r\n<pre class=\"lang:sh decode:true \">set protocols bgp 65555 address-family ipv4-unicast redistribute connected\r\nset protocols bgp 65555 neighbor 100.100.10.1 remote-as '65502'\r\nset protocols bgp 65555 neighbor 100.100.10.1 update-source '100.100.10.2'<\/pre>\r\n<p>&nbsp;<\/p>\r\n\r\n\r\n\r\n<h4 class=\"wp-block-heading\">Weryfikacja<\/h4>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">Po czasie konfiguracji NSXa i jak Vyos przyszed\u0142 czas na weryfikacj\u0119 naszej pracy.<\/p>\r\n\r\n\r\n\r\n<h5 class=\"wp-block-heading\">Sprawdzenie po stronie NSX\u00a0<br \/><br \/><\/h5>\r\n<h6>IPSEC<\/h6>\r\n\r\n\r\n\r\n<ol class=\"wp-block-list\">\r\n<li>logujemy si\u0119 po SSH do Edga na kt\u00f3rym jest nasze T0<\/li>\r\n<li>sprawdzamy sesj\u0119 ike wykonuj\u0105c komend\u0119 <strong><strong>get ipsecvpn ikesa active\u00a0<br \/><\/strong><\/strong>\r\n<pre class=\"lang:sh decode:true \">nsx-edge-01&gt; get ipsecvpn ikesa active \r\n    Total Number of Active IKE SAs: 1\r\n\r\n    IKE Version              : IKEv2\r\n    IKE Status               : Up\r\n    IKE Session ID           : 6\r\n    Session Name             : Tunnel-b522b518-59347c2-810b64c9-f60cccf2\r\n    Session Type             : Route Based\r\n    \r\n    IKE SPI Initiator        : 0x0e35db0e3da6b2d7\r\n    IKE SPI Responder        : 0x0402b472d9a26732\r\n    Role                     : Initiator\r\n    \r\n    Number of Child SA Pairs : 2\r\n    Created Timestamp        : 2020-03-26 11:12:09\r\n    IKE SA Uptime            : 425 sec\r\n    IKE SA Lifetime          : 86400 sec\r\n    DPD Probe Interval       : 60 sec\r\n    \r\n    IP Address:\r\n      Local                  : 1.1.1.1\r\n      Remote                 : 2.2.2.2\r\n    \r\n    Identity:\r\n      Local                  : 1.1.1.1 (ipv4)\r\n      Remote                 : 2.2.2.2 (ipv4)\r\n    \r\n    Algorithm:\r\n      Encryption             : aes256-cbc\r\n      Authentication         : hmac-sha256-128\r\n      PRF                    : hmac-sha256\r\n    DH Group                 : 5\r\n    \r\n    Authentication Method    : Pre-shared key\r\n    ----------------------------------------<\/pre>\r\n<p>&nbsp;<\/p>\r\n<\/li>\r\n<li>Weryfikujemy ca\u0142ego IPSeca wykonuj\u0105c komend\u0119<strong> get ipsecvpn session<\/strong><br \/>\r\n<pre class=\"lang:sh decode:true\">nsx-edge-01&gt; get ipsecvpn session \r\nTotal Number of Sessions: 1\r\n\r\nIKE Session ID   : 6\r\nUUID             : b522b518-0593-47c2-810b-64c9f60cccf2\r\nSR ID            : 74816ace-6bb1-4f82-b845-97a41c517c41\r\nType             : Route\r\nAuth Mode        : PSK\r\nCompliance Suite : NONE\r\n\r\nLocal IP         : 1.1.1.1            Peer IP          : 2.2.2.2\r\nLocal ID         : 1.1.1.1            Peer ID          : 2.2.2.2\r\nSession Status   : Up\r\n\r\nPolicy Rules\r\n    VTI UUID         : 9b519fea-7754-40e4-8a81-22e794d0b12a\r\n    ToRule ID        : 176235239          FromRule ID      : 2323718887\r\n    Local Subnet     : 0.0.0.0\/0          Peer Subnet      : 0.0.0.0\/0\r\n    Tunnel Status    : Up\r\n\r\n\r\n------------------------------------------------------------------------------------------\r\n<\/pre>\r\n<p>&nbsp;<\/p>\r\n<\/li>\r\n<li>Weryfikujemy jak wygl\u0105daj\u0105 statystyki czy zmieniaj\u0105 si\u0119 wykonuj\u0105c komend\u0119 <strong>get ipsecvpn tunnel stats\u00a0<\/strong><br \/>\r\n<pre class=\"lang:sh decode:true\">nsx-edge-01&gt; get ipsecvpn tunnel stats \r\nInterface UID                      : 324\r\nInterface UUID                     : 9b519fea-7754-40e4-8a81-22e794d0b12a\r\nVTI UUID                           : 9b519fea-7754-40e4-8a81-22e794d0b12a\r\n\r\nStats\r\n    Rx Pkts                            : 248           Tx Pkts                            : 399\r\n    Rx Bytes                           : 16153         Tx Bytes                           : 50820\r\n    Rx MSS Adjusted                    : 0             Tx MSS Adjusted                    : 0\r\n    Rx MSS Ignored                     : 0             Tx MSS Ignored                     : 0\r\n    Rx Drops                           : 1             Tx Drops                           : 0\r\n    Rx Drop Crypto Failure             : 0             Tx Drop Crypto Failure             : 0\r\n    Rx Drop State Mismatch             : 0             Tx Drop State Mismatch             : 0\r\n    Rx Drop Malformed                  : 0             Tx Drop Malformed                  : 0\r\n    Rx Drop Proto Not Supported        : 0             Tx Drop Proto Not Supported        : 0\r\n    Rx Drop Replay                     : 0             Tx Drop Seq Rollover               : 0\r\n    Rx Drop Inner Malformed            : 0             Tx Drop Fragmentation Needed       : 0\r\n    Rx Drop Policy Nomatch             : 0             Rekey Request Failure              : 0\r\n    Rx Drop Auth Failure               : 0<\/pre>\r\n<\/li>\r\n<\/ol>\r\n\r\n\r\n\r\n<h6 class=\"wp-block-heading\">BGP<\/h6>\r\n<p>Podobnie jak wy\u017cej wykorzystujemy po\u0142\u0105czenie ssh do EDGE<\/p>\r\n<ol>\r\n<li>sprawdzamy jaki id VRF ma nasz router T0 modu\u0142 serwisowy wykonuj\u0105c komend\u0119\u00a0<br \/>\r\n<pre class=\"lang:sh decode:true \">nsx-edge-01&gt; get logical-router\r\nLogical Router\r\nUUID                                   VRF    LR-ID  Name                              Type                        Ports  \r\n736a80e3-23f6-5a2d-81d6-bbefb2786666   0      0                                        TUNNEL                      4      \r\nf6badcc6-614e-4af3-bd27-50dc411e3a96   1      3      DR-t1                             DISTRIBUTED_ROUTER_TIER1    5      \r\n74816ace-6bb1-4f82-b845-97a41c517c41   2      2      SR-test                           SERVICE_ROUTER_TIER0        6      \r\na749186b-2250-486d-9cdc-00862a6b1a92   3      4      SR-t1                             SERVICE_ROUTER_TIER1        5      \r\n043a4cbd-97b9-4d48-ad0c-7f1c55c0065a   4      1      DR-test                           DISTRIBUTED_ROUTER_TIER0    4<\/pre>\r\n<\/li>\r\n<li>przechodzimy do vrfu 2\u00a0<br \/>\r\n<pre class=\"lang:sh decode:true \">nsx-edge-01&gt; vrf 2\r\nnsx-edge-01(tier0_sr)&gt; <\/pre>\r\n<\/li>\r\n<li>Sprawdzamy si\u0105sietzdwa BGP wykonuj\u0105c komend\u0119 <strong>get bgp neighbor summary<\/strong><br \/>\r\n<pre class=\"lang:sh decode:true\">nsx-edge-01(tier0_sr)&gt; get bgp neighbor summary \r\nBFD States: NC - Not configured, AC - Activating,DC - Disconnected\r\n            AD - Admin down, DW - Down, IN - Init,UP - Up\r\nBGP summary information for VRF default for address-family: ipv4Unicast\r\nRouter ID: 10.10.203.10  Local AS: 65502\r\n\r\nNeighbor                            AS          State Up\/DownTime  BFD InMsgs  OutMsgs InPfx  OutPfx\r\n\r\n10.10.203.1                         65500       Estab 01w4d23h     NC  17419   17412   19     25    \r\n100.100.10.2                        65555       Estab 00:17:13     NC  29      26      5      25 <\/pre>\r\n<\/li>\r\n<li>sprawdzamy tablic\u0119 routingu wykonuj\u0105c polecenie\u00a0<strong>get route bgp<\/strong><br \/>\r\n<pre class=\"lang:sh decode:true\">nsx-edge-01(tier0_sr)&gt; get route bgp\r\n\r\nFlags: t0c - Tier0-Connected, t0s - Tier0-Static, B - BGP,\r\nt0n - Tier0-NAT, t1s - Tier1-Static, t1c - Tier1-Connected,\r\nt1n: Tier1-NAT, t1l: Tier1-LB VIP, t1ls: Tier1-LB SNAT,\r\nt1d: Tier1-DNS FORWARDER, t1ipsec: Tier1-IPSec, \r\n&gt; - selected route, * - FIB route\r\n\r\nTotal number of routes: 20\r\n\r\nb  &gt; * 0.0.0.0\/0 [20\/0] via 10.10.203.1, uplink-280, 01w4d23h\r\nb  &gt; * 2.2.2.2\/32 [20\/0] via 10.10.203.1, uplink-280, 01:32:45\r\nb  &gt; * 10.1.1.0\/24 [20\/0] via 10.10.203.1, uplink-280, 01w4d23h\r\nb  &gt; * 10.2.2.0\/24 [20\/0] via 10.10.203.1, uplink-280, 01w4d23h\r\nb  &gt; * 10.2.3.0\/24 [20\/0] via 10.10.203.1, uplink-280, 01w4d23h\r\nb  &gt; * 10.2.4.0\/24 [20\/0] via 10.10.203.1, uplink-280, 01w4d23h\r\nb  &gt; * 10.10.0.0\/24 [20\/0] via 10.10.203.1, uplink-280, 01w4d23h\r\nb  &gt; * 10.10.11.0\/24 [20\/0] via 10.10.203.1, uplink-280, 01w4d23h\r\nb  &gt; * 10.10.201.0\/24 [20\/0] via 10.10.203.1, uplink-280, 01w4d23h\r\nb  &gt; * 10.10.202.0\/24 [20\/0] via 10.10.203.1, uplink-280, 01w4d23h\r\nb  &gt; * 10.100.1.0\/24 [20\/0] via 10.10.203.1, uplink-280, 03:58:22\r\nb  &gt; * 10.100.2.0\/24 [20\/0] via 10.10.203.1, uplink-280, 03:58:22\r\nb  &gt; * 10.100.3.0\/24 [20\/0] via 10.10.203.1, uplink-280, 03:58:22\r\nb  &gt; * 10.255.254.0\/24 [20\/0] via 10.10.203.1, uplink-280, 01w4d23h\r\nb  &gt; * 10.255.255.0\/24 [20\/0] via 10.10.203.1, uplink-280, 01w4d23h\r\nb  &gt; * 54.37.136.1\/32 [20\/0] via 10.10.203.1, uplink-280, 01w4d23h\r\nb  &gt; * 192.168.1.0\/24 [20\/0] via 10.10.203.1, uplink-280, 01w4d23h\r\nb  &gt; * 192.168.3.0\/24 [20\/0] via 10.10.203.1, uplink-280, 01w4d23h\r\nb  &gt; * 192.168.128.0\/24 [20\/0] via 100.100.10.2, vti-324, 00:18:17\r\nb  &gt; * 192.168.129.0\/24 [20\/0] via 100.100.10.2, vti-324, 00:18:17<\/pre>\r\n<\/li>\r\n<\/ol>\r\n<h5>Weryfikacja Vyos<\/h5>\r\n<p>Wszystkie sprawdzenie po stronie r\u00f3wnie\u017c wykonujemy z poziomu CLI poprzez SSH<\/p>\r\n\r\n\r\n\r\n<h6>Sprawdzenie IPSEC<\/h6>\r\n<ol class=\"wp-block-list\">\r\n<li>sprawdzamy sesj\u0119 IKE<br \/>\r\n<pre class=\"lang:sh decode:true\">vyos@vyos01:~$ show vpn ike sa \r\nPeer ID \/ IP                            Local ID \/ IP               \r\n------------                            -------------\r\n1.1.1.1                                 2.2.2.2                                \r\n\r\n    State  IKEVer  Encrypt  Hash    D-H Group      NAT-T  A-Time  L-Time\r\n    -----  ------  -------  ----    ---------      -----  ------  ------\r\n    up     IKEv2   aes256   sha256_128 5(MODP_1536)   no     3600    86400  \r\n<\/pre>\r\n<\/li>\r\n<li>Sprawdzamy sesj\u0119 IPSec<br \/>\r\n<pre class=\"lang:sh decode:true\">vyos@vyos01:~$ show vpn ipsec sa \r\nConnection               State    Uptime    Bytes In\/Out    Packets In\/Out    Remote address    Remote ID    Proposal\r\n-----------------------  -------  --------  --------------  ----------------  ----------------  -----------  ---------------------------------------\r\npeer-1.1.1.1-tunnel-vti  up       24m59s    0B\/60B          0\/1               1.1.1.1           N\/A          AES_CBC_256\/HMAC_SHA2_256_128\r\npeer-1.1.1.1-tunnel-vti  up       24m59s    3K\/4K           43\/67             1.1.1.1           N\/A          AES_CBC_256\/HMAC_SHA2_256_128\/MODP_1536<\/pre>\r\n<\/li>\r\n<\/ol>\r\n<h6>Weryfikacja BGP<\/h6>\r\n<ol>\r\n<li>weryfikacja statusu BGP<br \/>\r\n<pre class=\"lang:sh decode:true \">vyos@vyos01:~$ show ip bgp summary \r\n\r\nIPv4 Unicast Summary:\r\nBGP router identifier 2.2.2.2, local AS number 65555 vrf-id 0\r\nBGP table version 29\r\nRIB entries 47, using 8648 bytes of memory\r\nPeers 1, using 20 KiB of memory\r\n\r\nNeighbor        V         AS MsgRcvd MsgSent   TblVer  InQ OutQ  Up\/Down State\/PfxRcd\r\n100.100.10.1    4      65502      35      40        0    0    0 00:26:10           22<\/pre>\r\n<\/li>\r\n<li>Sprawdzenie tablicy routingu\u00a0<br \/>\r\n<pre class=\"lang:sh decode:true \">vyos@vyos01:~$ show ip route bgp \r\nCodes: K - kernel route, C - connected, S - static, R - RIP,\r\n       O - OSPF, I - IS-IS, B - BGP, E - EIGRP, N - NHRP,\r\n       T - Table, v - VNC, V - VNC-Direct, A - Babel, D - SHARP,\r\n       F - PBR, f - OpenFabric,\r\n       &gt; - selected route, * - FIB route, q - queued route, r - rejected route\r\n\r\n\r\nB&gt;* 10.1.1.0\/24 [20\/0] via 100.100.10.1, vti1, 00:26:46\r\nB&gt;* 10.2.2.0\/24 [20\/0] via 100.100.10.1, vti1, 00:26:46\r\nB&gt;* 10.2.3.0\/24 [20\/0] via 100.100.10.1, vti1, 00:26:46\r\nB&gt;* 10.2.4.0\/24 [20\/0] via 100.100.10.1, vti1, 00:26:46\r\nB&gt;* 10.10.0.0\/24 [20\/0] via 100.100.10.1, vti1, 00:26:46\r\nB&gt;* 10.10.11.0\/24 [20\/0] via 100.100.10.1, vti1, 00:26:46\r\nB&gt;* 10.10.201.0\/24 [20\/0] via 100.100.10.1, vti1, 00:26:46\r\nB&gt;* 10.10.202.0\/24 [20\/0] via 100.100.10.1, vti1, 00:26:46\r\nB&gt;* 10.10.203.0\/24 [20\/0] via 100.100.10.1, vti1, 00:26:46\r\nB&gt;* 10.11.1.0\/24 [20\/0] via 100.100.10.1, vti1, 00:26:46\r\nB&gt;* 10.12.1.0\/24 [20\/0] via 100.100.10.1, vti1, 00:26:46\r\nB&gt;* 10.100.1.0\/24 [20\/0] via 100.100.10.1, vti1, 00:26:46\r\nB&gt;* 10.100.2.0\/24 [20\/0] via 100.100.10.1, vti1, 00:26:46\r\nB&gt;* 10.100.3.0\/24 [20\/0] via 100.100.10.1, vti1, 00:26:46\r\nB&gt;* 10.255.254.0\/24 [20\/0] via 100.100.10.1, vti1, 00:26:46\r\nB&gt;* 10.255.255.0\/24 [20\/0] via 100.100.10.1, vti1, 00:26:46\r\nB&gt;* 54.37.136.1\/32 [20\/0] via 100.100.10.1, vti1, 00:26:46\r\nB&gt;* 192.168.3.0\/24 [20\/0] via 100.100.10.1, vti1, 00:26:46<\/pre>\r\n<p>&nbsp;<\/p>\r\n<\/li>\r\n<\/ol>\r\n<p>Na koniec test puszczenie ping z Vyosa to NSX&#8217;a dok\u0142adnie na ip 10.11.1.1 kt\u00f3ry potwierdzi nam dzia\u0142anie transmisji w IPSecu<\/p>\r\n<pre class=\"lang:sh decode:true \">vyos@vyos01:~$ ping 10.11.1.1\r\nPING 10.11.1.1 (10.11.1.1) 56(84) bytes of data.\r\n64 bytes from 10.11.1.1: icmp_seq=1 ttl=63 time=0.749 ms\r\n64 bytes from 10.11.1.1: icmp_seq=2 ttl=63 time=0.902 ms<\/pre>\r\n<p>&nbsp;<\/p>\r\n<p>Jak wida\u0107 proces weryfikacji wyszed\u0142 pozytywnie i mo\u017cemy cieszy\u0107 si\u0119 skonfigurowanym IPSeciem typu route base. Jak Macie pytania to zapraszam do kontaktu.\u00a0<\/p>\r\n\r\n\r\n","protected":false},"excerpt":{"rendered":"<p>W dzisiejszym wpisie przedstawi\u0119 konfiguracj\u0119 NSX-t IPSec Route base, jest to\u00a0 opis krok po kroku jak skonfigurowa\u0107 IPseca po stronie NSX&#8217;a oraz Vyos kt\u00f3ry b\u0119dzie uczestnikiem IPseca.\u00a0 Za\u0142o\u017cenia Poni\u017cej rysunek pogl\u0105dowy jak wygl\u0105da topologia po\u0142\u0105cze\u0144. Pomi\u0119dzy routerem T0 i chmurk\u0105 ju\u017c istnieje po\u0142\u0105czenie oraz jest zestawione s\u0105siedztwo BGP w celu dost\u0119pu do sieci &#8222;Internet&#8221; na [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":2166,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_publicize_message":"Opis jak skonfigurowa\u0107 IPSec typu route based pomi\u0119dzy NSX-t a Vyos. @VMware #NSXt @Vyos #Vyos #IPSec #BGP","jetpack_publicize_feature_enabled":true,"jetpack_social_post_already_shared":true,"jetpack_social_options":{"image_generator_settings":{"template":"highway","default_image_id":0,"font":"","enabled":false},"version":2},"jetpack_post_was_ever_published":false},"categories":[585,9,452],"tags":[218,606,604,605,125,77,353,533,603,602,16,254],"class_list":["post-2567","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-nsx","category-vmware","category-vyos","tag-bgp","tag-get-bgp-neighbor-summary","tag-get-ipsecvpn-ikesa-active","tag-get-ipsecvpn-session","tag-ike","tag-ipsec","tag-nsx","tag-nsx-t","tag-nsx-t-2-5","tag-nsx-t-ipsec-route-base","tag-vmware","tag-vyos"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.7 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>NSX-t IPSec Route base do Vyosa - SafeKom Blog<\/title>\n<meta name=\"description\" content=\"Opis jak skonfigurowa\u0107 krok po kroku NSX-t IPSec Route base. Partnerem sesji IPSec dla NSX-t jest Vyos. NSX-t IPSec Route base\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.safekom.pl\/blog\/vmware\/nsx\/nsx-t-ipsec-route-base\/\" \/>\n<meta property=\"og:locale\" content=\"pl_PL\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"NSX-t IPSec Route base do Vyosa - SafeKom Blog\" \/>\n<meta property=\"og:description\" content=\"Opis jak skonfigurowa\u0107 krok po kroku NSX-t IPSec Route base. Partnerem sesji IPSec dla NSX-t jest Vyos. NSX-t IPSec Route base\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.safekom.pl\/blog\/vmware\/nsx\/nsx-t-ipsec-route-base\/\" \/>\n<meta property=\"og:site_name\" content=\"SafeKom Blog\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/safekompl\" \/>\n<meta property=\"article:published_time\" content=\"2020-03-26T12:00:39+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2018\/01\/Autobot_symbol.png?fit=1012%2C946&ssl=1\" \/>\n\t<meta property=\"og:image:width\" content=\"1012\" \/>\n\t<meta property=\"og:image:height\" content=\"946\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"Micha\u0142 Iwa\u0144czuk\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@MIwaczuk\" \/>\n<meta name=\"twitter:site\" content=\"@MIwaczuk\" \/>\n<meta name=\"twitter:label1\" content=\"Napisane przez\" \/>\n\t<meta name=\"twitter:data1\" content=\"Micha\u0142 Iwa\u0144czuk\" \/>\n\t<meta name=\"twitter:label2\" content=\"Szacowany czas czytania\" \/>\n\t<meta name=\"twitter:data2\" content=\"13 minut\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.safekom.pl\\\/blog\\\/vmware\\\/nsx\\\/nsx-t-ipsec-route-base\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.safekom.pl\\\/blog\\\/vmware\\\/nsx\\\/nsx-t-ipsec-route-base\\\/\"},\"author\":{\"name\":\"Micha\u0142 Iwa\u0144czuk\",\"@id\":\"https:\\\/\\\/www.safekom.pl\\\/blog\\\/#\\\/schema\\\/person\\\/fd4cc931b624af4b7353d36d92ba7181\"},\"headline\":\"NSX-t IPSec Route base\",\"datePublished\":\"2020-03-26T12:00:39+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.safekom.pl\\\/blog\\\/vmware\\\/nsx\\\/nsx-t-ipsec-route-base\\\/\"},\"wordCount\":1173,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/www.safekom.pl\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.safekom.pl\\\/blog\\\/vmware\\\/nsx\\\/nsx-t-ipsec-route-base\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/i0.wp.com\\\/www.safekom.pl\\\/blog\\\/wp-content\\\/uploads\\\/2018\\\/01\\\/Autobot_symbol.png?fit=1012%2C946&ssl=1\",\"keywords\":[\"bgp\",\"get bgp neighbor summary\",\"get ipsecvpn ikesa active\",\"get ipsecvpn session\",\"ike\",\"ipsec\",\"NSX\",\"NSX-T\",\"nsx-t 2.5\",\"NSX-t IPSec Route base\",\"vmware\",\"vyos\"],\"articleSection\":[\"NSX\",\"Vmware\",\"Vyos\"],\"inLanguage\":\"pl-PL\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/www.safekom.pl\\\/blog\\\/vmware\\\/nsx\\\/nsx-t-ipsec-route-base\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.safekom.pl\\\/blog\\\/vmware\\\/nsx\\\/nsx-t-ipsec-route-base\\\/\",\"url\":\"https:\\\/\\\/www.safekom.pl\\\/blog\\\/vmware\\\/nsx\\\/nsx-t-ipsec-route-base\\\/\",\"name\":\"NSX-t IPSec Route base do Vyosa - SafeKom Blog\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.safekom.pl\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.safekom.pl\\\/blog\\\/vmware\\\/nsx\\\/nsx-t-ipsec-route-base\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.safekom.pl\\\/blog\\\/vmware\\\/nsx\\\/nsx-t-ipsec-route-base\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/i0.wp.com\\\/www.safekom.pl\\\/blog\\\/wp-content\\\/uploads\\\/2018\\\/01\\\/Autobot_symbol.png?fit=1012%2C946&ssl=1\",\"datePublished\":\"2020-03-26T12:00:39+00:00\",\"description\":\"Opis jak skonfigurowa\u0107 krok po kroku NSX-t IPSec Route base. Partnerem sesji IPSec dla NSX-t jest Vyos. NSX-t IPSec Route base\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.safekom.pl\\\/blog\\\/vmware\\\/nsx\\\/nsx-t-ipsec-route-base\\\/#breadcrumb\"},\"inLanguage\":\"pl-PL\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.safekom.pl\\\/blog\\\/vmware\\\/nsx\\\/nsx-t-ipsec-route-base\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"pl-PL\",\"@id\":\"https:\\\/\\\/www.safekom.pl\\\/blog\\\/vmware\\\/nsx\\\/nsx-t-ipsec-route-base\\\/#primaryimage\",\"url\":\"https:\\\/\\\/i0.wp.com\\\/www.safekom.pl\\\/blog\\\/wp-content\\\/uploads\\\/2018\\\/01\\\/Autobot_symbol.png?fit=1012%2C946&ssl=1\",\"contentUrl\":\"https:\\\/\\\/i0.wp.com\\\/www.safekom.pl\\\/blog\\\/wp-content\\\/uploads\\\/2018\\\/01\\\/Autobot_symbol.png?fit=1012%2C946&ssl=1\",\"width\":1012,\"height\":946},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.safekom.pl\\\/blog\\\/vmware\\\/nsx\\\/nsx-t-ipsec-route-base\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Strona g\u0142\u00f3wna\",\"item\":\"https:\\\/\\\/www.safekom.pl\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"NSX-t IPSec Route base\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.safekom.pl\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.safekom.pl\\\/blog\\\/\",\"name\":\"SafeKom Blog\",\"description\":\"Notatki Architekta i in\u017cyniera zwi\u0105zanego rozwi\u0105zaniami on-prem\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.safekom.pl\\\/blog\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.safekom.pl\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"pl-PL\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.safekom.pl\\\/blog\\\/#organization\",\"name\":\"SafeKom Blog\",\"url\":\"https:\\\/\\\/www.safekom.pl\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"pl-PL\",\"@id\":\"https:\\\/\\\/www.safekom.pl\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/i0.wp.com\\\/www.safekom.pl\\\/blog\\\/wp-content\\\/uploads\\\/2015\\\/05\\\/cropped-logo.png?fit=512%2C512&ssl=1\",\"contentUrl\":\"https:\\\/\\\/i0.wp.com\\\/www.safekom.pl\\\/blog\\\/wp-content\\\/uploads\\\/2015\\\/05\\\/cropped-logo.png?fit=512%2C512&ssl=1\",\"width\":512,\"height\":512,\"caption\":\"SafeKom Blog\"},\"image\":{\"@id\":\"https:\\\/\\\/www.safekom.pl\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/www.facebook.com\\\/safekompl\",\"https:\\\/\\\/x.com\\\/MIwaczuk\",\"https:\\\/\\\/www.linkedin.com\\\/in\\\/michaliwanczuk\\\/\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.safekom.pl\\\/blog\\\/#\\\/schema\\\/person\\\/fd4cc931b624af4b7353d36d92ba7181\",\"name\":\"Micha\u0142 Iwa\u0144czuk\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"pl-PL\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/cc6dda4ee8d21d1f254147e5ee6f5e38881b88a4a12a5774ca42380597e52014?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/cc6dda4ee8d21d1f254147e5ee6f5e38881b88a4a12a5774ca42380597e52014?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/cc6dda4ee8d21d1f254147e5ee6f5e38881b88a4a12a5774ca42380597e52014?s=96&d=mm&r=g\",\"caption\":\"Micha\u0142 Iwa\u0144czuk\"},\"description\":\"Pasjonat komputerowy od zawsze oraz maniak w zakresie sieci, wirtualizacji oraz bezpiecze\u0144stwa IT. Kompetentny in\u017cynier z du\u017cym do\u015bwiadczeniem w realizacji projekt\u00f3w informatycznych i telekomunikacyjnych. Wieloletni administrator IT, kt\u00f3ry utrzymuje systemy informatyczne dostosowuj\u0105c je do wymog\u00f3w biznesowych z zapewnieniem dost\u0119pno\u015bci 24\\\/7\\\/365.\",\"url\":\"https:\\\/\\\/www.safekom.pl\\\/blog\\\/author\\\/admin\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"NSX-t IPSec Route base do Vyosa - SafeKom Blog","description":"Opis jak skonfigurowa\u0107 krok po kroku NSX-t IPSec Route base. Partnerem sesji IPSec dla NSX-t jest Vyos. NSX-t IPSec Route base","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.safekom.pl\/blog\/vmware\/nsx\/nsx-t-ipsec-route-base\/","og_locale":"pl_PL","og_type":"article","og_title":"NSX-t IPSec Route base do Vyosa - SafeKom Blog","og_description":"Opis jak skonfigurowa\u0107 krok po kroku NSX-t IPSec Route base. Partnerem sesji IPSec dla NSX-t jest Vyos. NSX-t IPSec Route base","og_url":"https:\/\/www.safekom.pl\/blog\/vmware\/nsx\/nsx-t-ipsec-route-base\/","og_site_name":"SafeKom Blog","article_publisher":"https:\/\/www.facebook.com\/safekompl","article_published_time":"2020-03-26T12:00:39+00:00","og_image":[{"width":1012,"height":946,"url":"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2018\/01\/Autobot_symbol.png?fit=1012%2C946&ssl=1","type":"image\/png"}],"author":"Micha\u0142 Iwa\u0144czuk","twitter_card":"summary_large_image","twitter_creator":"@MIwaczuk","twitter_site":"@MIwaczuk","twitter_misc":{"Napisane przez":"Micha\u0142 Iwa\u0144czuk","Szacowany czas czytania":"13 minut"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.safekom.pl\/blog\/vmware\/nsx\/nsx-t-ipsec-route-base\/#article","isPartOf":{"@id":"https:\/\/www.safekom.pl\/blog\/vmware\/nsx\/nsx-t-ipsec-route-base\/"},"author":{"name":"Micha\u0142 Iwa\u0144czuk","@id":"https:\/\/www.safekom.pl\/blog\/#\/schema\/person\/fd4cc931b624af4b7353d36d92ba7181"},"headline":"NSX-t IPSec Route base","datePublished":"2020-03-26T12:00:39+00:00","mainEntityOfPage":{"@id":"https:\/\/www.safekom.pl\/blog\/vmware\/nsx\/nsx-t-ipsec-route-base\/"},"wordCount":1173,"commentCount":0,"publisher":{"@id":"https:\/\/www.safekom.pl\/blog\/#organization"},"image":{"@id":"https:\/\/www.safekom.pl\/blog\/vmware\/nsx\/nsx-t-ipsec-route-base\/#primaryimage"},"thumbnailUrl":"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2018\/01\/Autobot_symbol.png?fit=1012%2C946&ssl=1","keywords":["bgp","get bgp neighbor summary","get ipsecvpn ikesa active","get ipsecvpn session","ike","ipsec","NSX","NSX-T","nsx-t 2.5","NSX-t IPSec Route base","vmware","vyos"],"articleSection":["NSX","Vmware","Vyos"],"inLanguage":"pl-PL","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.safekom.pl\/blog\/vmware\/nsx\/nsx-t-ipsec-route-base\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.safekom.pl\/blog\/vmware\/nsx\/nsx-t-ipsec-route-base\/","url":"https:\/\/www.safekom.pl\/blog\/vmware\/nsx\/nsx-t-ipsec-route-base\/","name":"NSX-t IPSec Route base do Vyosa - SafeKom Blog","isPartOf":{"@id":"https:\/\/www.safekom.pl\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.safekom.pl\/blog\/vmware\/nsx\/nsx-t-ipsec-route-base\/#primaryimage"},"image":{"@id":"https:\/\/www.safekom.pl\/blog\/vmware\/nsx\/nsx-t-ipsec-route-base\/#primaryimage"},"thumbnailUrl":"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2018\/01\/Autobot_symbol.png?fit=1012%2C946&ssl=1","datePublished":"2020-03-26T12:00:39+00:00","description":"Opis jak skonfigurowa\u0107 krok po kroku NSX-t IPSec Route base. Partnerem sesji IPSec dla NSX-t jest Vyos. NSX-t IPSec Route base","breadcrumb":{"@id":"https:\/\/www.safekom.pl\/blog\/vmware\/nsx\/nsx-t-ipsec-route-base\/#breadcrumb"},"inLanguage":"pl-PL","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.safekom.pl\/blog\/vmware\/nsx\/nsx-t-ipsec-route-base\/"]}]},{"@type":"ImageObject","inLanguage":"pl-PL","@id":"https:\/\/www.safekom.pl\/blog\/vmware\/nsx\/nsx-t-ipsec-route-base\/#primaryimage","url":"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2018\/01\/Autobot_symbol.png?fit=1012%2C946&ssl=1","contentUrl":"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2018\/01\/Autobot_symbol.png?fit=1012%2C946&ssl=1","width":1012,"height":946},{"@type":"BreadcrumbList","@id":"https:\/\/www.safekom.pl\/blog\/vmware\/nsx\/nsx-t-ipsec-route-base\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Strona g\u0142\u00f3wna","item":"https:\/\/www.safekom.pl\/blog\/"},{"@type":"ListItem","position":2,"name":"NSX-t IPSec Route base"}]},{"@type":"WebSite","@id":"https:\/\/www.safekom.pl\/blog\/#website","url":"https:\/\/www.safekom.pl\/blog\/","name":"SafeKom Blog","description":"Notatki Architekta i in\u017cyniera zwi\u0105zanego rozwi\u0105zaniami on-prem","publisher":{"@id":"https:\/\/www.safekom.pl\/blog\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.safekom.pl\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"pl-PL"},{"@type":"Organization","@id":"https:\/\/www.safekom.pl\/blog\/#organization","name":"SafeKom Blog","url":"https:\/\/www.safekom.pl\/blog\/","logo":{"@type":"ImageObject","inLanguage":"pl-PL","@id":"https:\/\/www.safekom.pl\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2015\/05\/cropped-logo.png?fit=512%2C512&ssl=1","contentUrl":"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2015\/05\/cropped-logo.png?fit=512%2C512&ssl=1","width":512,"height":512,"caption":"SafeKom Blog"},"image":{"@id":"https:\/\/www.safekom.pl\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/safekompl","https:\/\/x.com\/MIwaczuk","https:\/\/www.linkedin.com\/in\/michaliwanczuk\/"]},{"@type":"Person","@id":"https:\/\/www.safekom.pl\/blog\/#\/schema\/person\/fd4cc931b624af4b7353d36d92ba7181","name":"Micha\u0142 Iwa\u0144czuk","image":{"@type":"ImageObject","inLanguage":"pl-PL","@id":"https:\/\/secure.gravatar.com\/avatar\/cc6dda4ee8d21d1f254147e5ee6f5e38881b88a4a12a5774ca42380597e52014?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/cc6dda4ee8d21d1f254147e5ee6f5e38881b88a4a12a5774ca42380597e52014?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/cc6dda4ee8d21d1f254147e5ee6f5e38881b88a4a12a5774ca42380597e52014?s=96&d=mm&r=g","caption":"Micha\u0142 Iwa\u0144czuk"},"description":"Pasjonat komputerowy od zawsze oraz maniak w zakresie sieci, wirtualizacji oraz bezpiecze\u0144stwa IT. Kompetentny in\u017cynier z du\u017cym do\u015bwiadczeniem w realizacji projekt\u00f3w informatycznych i telekomunikacyjnych. Wieloletni administrator IT, kt\u00f3ry utrzymuje systemy informatyczne dostosowuj\u0105c je do wymog\u00f3w biznesowych z zapewnieniem dost\u0119pno\u015bci 24\/7\/365.","url":"https:\/\/www.safekom.pl\/blog\/author\/admin\/"}]}},"jetpack_publicize_connections":[],"jetpack_featured_media_url":"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2018\/01\/Autobot_symbol.png?fit=1012%2C946&ssl=1","jetpack_shortlink":"https:\/\/wp.me\/p7i9ri-Fp","jetpack-related-posts":[{"id":2275,"url":"https:\/\/www.safekom.pl\/blog\/vmware\/nsx-t-routing\/","url_meta":{"origin":2567,"position":0},"title":"NSX-t Routing","author":"Micha\u0142 Iwa\u0144czuk","date":"05.03.2018","format":false,"excerpt":"W poprzednich wpisach pokaza\u0142em jak skonfigurowa\u0107 prawie ca\u0142ego NSX-t, dzi\u015b przyszed\u0142 czas na najciekawsze z perspektywy os\u00f3b zajmuj\u0105cych si\u0119 sieci\u0105 - b\u0119dziemy konfigurowa\u0107 NSX-t Routing. Poni\u017cej plan ca\u0142ej serii po\u015bwi\u0119cony NSX-t: Plan Dzia\u0142ania Poni\u017cej plan dzia\u0142ania oraz odno\u015bniki wcze\u015bniejszych wpis\u00f3w o NSX-T. Instalacja NSX Managera Instalacja NSX-t Controller pod\u0142\u0105czenie ich\u2026","rel":"","context":"W \u201eLab&quot;","block_context":{"text":"Lab","link":"https:\/\/www.safekom.pl\/blog\/en\/category\/lab\/"},"img":{"alt_text":"","src":"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2018\/01\/nsx-t-lab03.png?resize=350%2C200","width":350,"height":200,"srcset":"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2018\/01\/nsx-t-lab03.png?resize=350%2C200 1x, https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2018\/01\/nsx-t-lab03.png?resize=525%2C300 1.5x, https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2018\/01\/nsx-t-lab03.png?resize=700%2C400 2x"},"classes":[]},{"id":2332,"url":"https:\/\/www.safekom.pl\/blog\/vmware\/nsx-t-load-balancer\/","url_meta":{"origin":2567,"position":1},"title":"NSX-t Load Balancer","author":"Micha\u0142 Iwa\u0144czuk","date":"24.04.2018","format":false,"excerpt":"W poprzednich wpisach pokaza\u0142em jak skonfigurowa\u0107 prawie ca\u0142ego NSX-t, dzi\u015b przyszed\u0142 czas skonfigurownie NSX-t Load Balancer, kt\u00f3ry jest dost\u0119pny od wersji 2.0. Poni\u017cej plan ca\u0142ej serii po\u015bwi\u0119cony NSX-t: Plan Dzia\u0142ania Poni\u017cej plan dzia\u0142ania oraz odno\u015bniki wcze\u015bniejszych wpis\u00f3w o NSX-T. Instalacja NSX Managera Instalacja NSX-t Controller pod\u0142\u0105czenie ich do NSX Mangera\u2026","rel":"","context":"W \u201eLab&quot;","block_context":{"text":"Lab","link":"https:\/\/www.safekom.pl\/blog\/en\/category\/lab\/"},"img":{"alt_text":"","src":"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2018\/01\/Autobot_symbol.png?fit=1012%2C946&ssl=1&resize=350%2C200","width":350,"height":200,"srcset":"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2018\/01\/Autobot_symbol.png?fit=1012%2C946&ssl=1&resize=350%2C200 1x, https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2018\/01\/Autobot_symbol.png?fit=1012%2C946&ssl=1&resize=525%2C300 1.5x, https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2018\/01\/Autobot_symbol.png?fit=1012%2C946&ssl=1&resize=700%2C400 2x"},"classes":[]},{"id":2149,"url":"https:\/\/www.safekom.pl\/blog\/vmware\/nsx-t-czas-poznac-rywala\/","url_meta":{"origin":2567,"position":2},"title":"NSX-T czas pozna\u0107 rywala","author":"Micha\u0142 Iwa\u0144czuk","date":"22.01.2018","format":false,"excerpt":"Od d\u0142u\u017cszego czasu zajmuje si\u0119 NSX-v, ale stwierdzi\u0142em, \u017ce czas pozna\u0107 wersj\u0119 multi platform NSX-T. Gdy grudniu 2017 pojawi\u0142a si\u0119 wersja 2.1 mo\u017cna powiedzie\u0107, \u017ce wersja ju\u017c jest w miar\u0119 wygrzana. Poczu\u0142em, \u017ce przyszed\u0142 czas aby rozwi\u0105zanie to pojawi\u0142o si\u0119 w mym labie. Ten wpis otwiera seri\u0119 wpis\u00f3w na temat\u2026","rel":"","context":"W \u201eLab&quot;","block_context":{"text":"Lab","link":"https:\/\/www.safekom.pl\/blog\/en\/category\/lab\/"},"img":{"alt_text":"","src":"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2018\/01\/nsx-t-lab02.png?resize=350%2C200","width":350,"height":200,"srcset":"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2018\/01\/nsx-t-lab02.png?resize=350%2C200 1x, https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2018\/01\/nsx-t-lab02.png?resize=525%2C300 1.5x, https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2018\/01\/nsx-t-lab02.png?resize=700%2C400 2x, https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2018\/01\/nsx-t-lab02.png?resize=1050%2C600 3x, https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2018\/01\/nsx-t-lab02.png?resize=1400%2C800 4x"},"classes":[]},{"id":2191,"url":"https:\/\/www.safekom.pl\/blog\/vmware\/nsx-t-edge\/","url_meta":{"origin":2567,"position":3},"title":"NSX-t EDGE","author":"Micha\u0142 Iwa\u0144czuk","date":"30.01.2018","format":false,"excerpt":"W poprzednim wpisie pokaza\u0142em jak wygl\u0105da instalacja NSX-t Controler\u00f3w, dzi\u015b przyszed\u0142 czas aby zaj\u0105\u0107 si\u0119 NSX-t EDGE. NSX-t EDGE jest odpowiedzialny za routing w sieci nak\u0142adkowej oraz kontakt ze \u015bwiatem zewn\u0119trznym. Dzi\u015b skupimy si\u0119 na instalacji EDGE oraz pod\u0142\u0105czeniu do NSX Managera. Plan Dzia\u0142ania Poni\u017cej plan dzia\u0142ania oraz odno\u015bniki wcze\u015bniejszych\u2026","rel":"","context":"W \u201eLab&quot;","block_context":{"text":"Lab","link":"https:\/\/www.safekom.pl\/blog\/en\/category\/lab\/"},"img":{"alt_text":"","src":"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2018\/01\/Autobot_symbol.png?fit=1012%2C946&ssl=1&resize=350%2C200","width":350,"height":200,"srcset":"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2018\/01\/Autobot_symbol.png?fit=1012%2C946&ssl=1&resize=350%2C200 1x, https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2018\/01\/Autobot_symbol.png?fit=1012%2C946&ssl=1&resize=525%2C300 1.5x, https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2018\/01\/Autobot_symbol.png?fit=1012%2C946&ssl=1&resize=700%2C400 2x"},"classes":[]},{"id":2227,"url":"https:\/\/www.safekom.pl\/blog\/vmware\/nsx-t-transport-zone-node\/","url_meta":{"origin":2567,"position":4},"title":"NSX-t transport zone &#038; node","author":"Micha\u0142 Iwa\u0144czuk","date":"20.02.2018","format":false,"excerpt":"Mamy za sob\u0105 ju\u017c zainstalowane modu\u0142y wymagane do poprawnego dzia\u0142ania NSX-t na hostach z vSphere, Dzi\u015b przyszed\u0142 czas na konfiguracj\u0119 NSX-t transport zone i transport node i wszystko to co zwi\u0105zane aby uruchomi\u0107 sie\u0107 L2 w sieci nak\u0142adkowej w NSX-t. Plan Dzia\u0142ania Poni\u017cej plan dzia\u0142ania oraz odno\u015bniki wcze\u015bniejszych wpis\u00f3w o\u2026","rel":"","context":"W \u201eLab&quot;","block_context":{"text":"Lab","link":"https:\/\/www.safekom.pl\/blog\/en\/category\/lab\/"},"img":{"alt_text":"","src":"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2018\/01\/Autobot_symbol.png?fit=1012%2C946&ssl=1&resize=350%2C200","width":350,"height":200,"srcset":"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2018\/01\/Autobot_symbol.png?fit=1012%2C946&ssl=1&resize=350%2C200 1x, https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2018\/01\/Autobot_symbol.png?fit=1012%2C946&ssl=1&resize=525%2C300 1.5x, https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2018\/01\/Autobot_symbol.png?fit=1012%2C946&ssl=1&resize=700%2C400 2x"},"classes":[]},{"id":2383,"url":"https:\/\/www.safekom.pl\/blog\/vmware\/nsx-t-upgrade\/","url_meta":{"origin":2567,"position":5},"title":"NSX-t Upgrade","author":"Micha\u0142 Iwa\u0144czuk","date":"28.09.2018","format":false,"excerpt":"W poprzednich wpisach pokaza\u0142em jak skonfigurowa\u0107 NSX-t, dzi\u015b przyszed\u0142 podnie\u015b\u0107 wersj\u0119 do NSX-T 2.3. Poni\u017cej opis ca\u0142ego procesu aktualizacji. Dla przy pomnienia nasz schemat jak wygl\u0105da po\u0142\u0105czenie kart sieciowych Proces Upgrade Logujemy si\u0119 do konsoli NSX-t Managera przechodzimy do System--> Utilitles-->Uprgarde Gdzie klikamy Proceed to Upgrade wgrywamy plik \u015bci\u0105gni\u0119ty z\u2026","rel":"","context":"W \u201eVmware&quot;","block_context":{"text":"Vmware","link":"https:\/\/www.safekom.pl\/blog\/category\/vmware\/"},"img":{"alt_text":"","src":"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2018\/01\/Autobot_symbol.png?fit=1012%2C946&ssl=1&resize=350%2C200","width":350,"height":200,"srcset":"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2018\/01\/Autobot_symbol.png?fit=1012%2C946&ssl=1&resize=350%2C200 1x, https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2018\/01\/Autobot_symbol.png?fit=1012%2C946&ssl=1&resize=525%2C300 1.5x, https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2018\/01\/Autobot_symbol.png?fit=1012%2C946&ssl=1&resize=700%2C400 2x"},"classes":[]}],"jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/www.safekom.pl\/blog\/wp-json\/wp\/v2\/posts\/2567","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.safekom.pl\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.safekom.pl\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.safekom.pl\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.safekom.pl\/blog\/wp-json\/wp\/v2\/comments?post=2567"}],"version-history":[{"count":31,"href":"https:\/\/www.safekom.pl\/blog\/wp-json\/wp\/v2\/posts\/2567\/revisions"}],"predecessor-version":[{"id":2619,"href":"https:\/\/www.safekom.pl\/blog\/wp-json\/wp\/v2\/posts\/2567\/revisions\/2619"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.safekom.pl\/blog\/wp-json\/wp\/v2\/media\/2166"}],"wp:attachment":[{"href":"https:\/\/www.safekom.pl\/blog\/wp-json\/wp\/v2\/media?parent=2567"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.safekom.pl\/blog\/wp-json\/wp\/v2\/categories?post=2567"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.safekom.pl\/blog\/wp-json\/wp\/v2\/tags?post=2567"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}