Softethervpn: Softether VPNSERVER 99% CPU ์‚ฌ์šฉ๋Ÿ‰

์— ๋งŒ๋“  2020๋…„ 11์›” 12์ผ  ยท  13์ฝ”๋ฉ˜ํŠธ  ยท  ์ถœ์ฒ˜: SoftEtherVPN/SoftEtherVPN

์ „์ œ ์กฐ๊ฑด

  • [x] ์žฌํ˜„ํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๊นŒ?
  • [x] ์ตœ์‹  ๋ฒ„์ „์˜ SoftEtherVPN์„ ์‹คํ–‰ํ•˜๊ณ  ์žˆ์Šต๋‹ˆ๊นŒ?

SoftEther ๋ฒ„์ „:
๊ตฌ์„ฑ ์š”์†Œ: [์„œ๋ฒ„]
์šด์˜ ์ฒด์ œ: [๋ฆฌ๋ˆ…์Šค]
์•„ํ‚คํ…์ฒ˜: [64๋น„ํŠธ]

[๋ผ์ฆˆ๋ฒ ๋ฆฌํŒŒ์ด์™€ ๊ฐ™์ด ์•Œ๋ ค์ง„ ์‚ฌ์–‘์˜ ์ปดํ“จํ„ฐ์ธ ๊ฒฝ์šฐ ์„ธ๋ถ€์‚ฌํ•ญ์„ ์ƒ๋žตํ•˜์—ฌ ์ง€์ •ํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.]
ํ”„๋กœ์„ธ์„œ: [์ธํ…” ์ œ์˜จ ํ”„๋กœ์„ธ์„œ(Skylake, IBRS)]

์„ค๋ช…

[๋ฒ„๊ทธ ์„ค๋ช…]

๋‚ด kvm ์„œ๋ฒ„์—์„œ securenat์„ ์‚ฌ์šฉํ•  ๋•Œ๋งˆ๋‹ค CPU ์‚ฌ์šฉ๋Ÿ‰์ด 99%๊ฐ€ ๋ฉ๋‹ˆ๋‹ค. 0๋ช…์˜ ์‚ฌ์šฉ์ž๊ฐ€ ์—ฐ๊ฒฐ๋˜์–ด ์žˆ์–ด๋„ securenate๋ฅผ ํ™œ์„ฑํ™”ํ•  ๋•Œ๋งˆ๋‹ค vpnserver ์‚ฌ์šฉ๋Ÿ‰์ด 99%+-๋กœ ์ด๋™ํ•ฉ๋‹ˆ๋‹ค. ๊ทธ๋ฆฌ๊ณ  ๊ทธ๊ฒƒ์€ ์ธํ„ฐ๋„ท ์†๋„์— ๋ฌธ์ œ๋ฅผ ์ผ์œผํ‚ต๋‹ˆ๋‹ค.

์žฌํ˜„ ๋‹จ๊ณ„

  1. [์„œ๋ฒ„์—์„œ ๋ณด์•ˆ Nat ํ™œ์„ฑํ™”]
  2. [CPU ํ”„๋กœ์„ธ์Šค๋ฅผ ํ™•์ธํ•˜๊ณ  VPN ์„œ๋ฒ„๊ฐ€ 99%์— ๋„๋‹ฌํ–ˆ์Šต๋‹ˆ๋‹ค.]
  3. [๋ณด์•ˆ NAT๋ฅผ ๋น„ํ™œ์„ฑํ™”ํ•˜๋ฉด ๋ฌธ์ œ๊ฐ€ ํ•ด๊ฒฐ๋ฉ๋‹ˆ๋‹ค. ๋กœ์ปฌ ๋ธŒ๋ฆฌ์ง€๊ฐ€ ์ž‘๋™ํ•˜์ง€ ์•Š์Šต๋‹ˆ๋‹ค. IDK๊ฐ€ ๊ทธ ์ด์œ ์ž…๋‹ˆ๋‹ค.]

๋ชจ๋“  13 ๋Œ“๊ธ€

์„œ๋ฒ„ ๊ตฌ์„ฑ์—์„œ DisableIpRawModeSecureNAT ๋ฅผ ํ™œ์„ฑํ™”ํ•ด ์ฃผ์‹œ๊ฒ ์Šต๋‹ˆ๊นŒ?

@davidebeatrici ๋„ค. ์ด๋ฏธ ํ™œ์„ฑํ™”๋˜์–ด ์žˆ์Šต๋‹ˆ๋‹ค. ๊ทธ๋Ÿฌ๋‚˜ ์—ฌ์ „ํžˆ ์šด์ด ์—†์Šต๋‹ˆ๋‹ค. vpnserver๋Š” ํ•ญ์ƒ CPU ์‚ฌ์šฉ๋Ÿ‰์˜ ๋งจ ์œ„์— ๋ฉˆ์ท„์Šต๋‹ˆ๋‹ค.
image

์ •ํ™•ํžˆ ๋™์ผํ•œ ๋ฌธ์ œ๊ฐ€ ์žˆ์—ˆ๊ณ  ์ธํ„ฐํŽ˜์ด์Šค์—์„œ ๋ธŒ๋ฆฌ์ง€๋ฅผ ์‚ฌ์šฉํ•˜๋Š” ๋Œ€์‹  ํƒญ์„ ๊ตฌ์„ฑํ•˜์—ฌ ์ˆ˜์ •ํ–ˆ์Šต๋‹ˆ๋‹ค. ์ œ ๊ฒฝ์šฐ์—๋Š” KVM VM์ž…๋‹ˆ๋‹ค.

@DainBB ๊ฐ€์ด๋“œ๋ฅผ

์„œ๋ฒ„ ๊ด€๋ฆฌ์ž์—์„œ VPN ์„œ๋ฒ„์— ์—ฐ๊ฒฐ - ๋กœ์ปฌ ๋ธŒ๋ฆฌ์ง€ ์„ค์ • ํด๋ฆญ
ํ™”๋ฉด ์ƒ๋‹จ์˜ ๊ธฐ์กด ๋ธŒ๋ฆฌ์ง€ ์‚ญ์ œ

ํ™”๋ฉด ํ•˜๋‹จ์˜ ๋“œ๋กญ๋‹ค์šด ๋ชฉ๋ก์—์„œ Virtual Hub ์ด๋ฆ„์„ ์„ ํƒํ•œ ๋‹ค์Œ ๊ธฐ๋ณธ "Bridge with Physical Existing Network Adapter" ๋Œ€์‹  "Bridge with New Tap Device"๋ฅผ ์„ ํƒํ•ฉ๋‹ˆ๋‹ค.
ํƒญ์— "์ด๋ฆ„"์„ ์ง€์ •ํ•˜๋ฉด ํƒญ ์ธํ„ฐํŽ˜์ด์Šค๊ฐ€ tap_"name"์œผ๋กœ ์ƒ์„ฑ๋˜๊ณ  "๋กœ์ปฌ ๋ธŒ๋ฆฌ์ง€ ์ƒ์„ฑ"์„ ํด๋ฆญํ•ฉ๋‹ˆ๋‹ค.

๊ทธ๊ฒŒ ๋‹ค์•ผ, ๋‹น์‹ ์€ ์„œ๋ฒ„์˜ ifconfig -a ์ถœ๋ ฅ์— tap_"name"์ด ํ‘œ์‹œ๋˜์–ด์•ผ ํ•˜๊ณ  ๊ทธ ํ›„์— SecureNAT๋ฅผ ํ™œ์„ฑํ™”ํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ๋‚ด VM CPU ์‚ฌ์šฉ๋ฅ ์€ ์ด ์„ค์ •์œผ๋กœ ์ ˆ๋Œ€ 10%๋ฅผ ๋„˜์ง€ ์•Š์Šต๋‹ˆ๋‹ค. ํƒญ์„ ์ƒ์„ฑํ•˜๊ธฐ ์ „์—๋Š” ์œ ํœด ์ƒํƒœ์—์„œ 80%์˜€์Šต๋‹ˆ๋‹ค. .

@DainBB ์ •๋ง ๊ฐ์‚ฌํ•ฉ๋‹ˆ๋‹ค. ๊ทธ๋Ÿฐ๋ฐ ๊ธ‰ํ•œ๋ฐ SmartNAT ๋ถ€๋ถ„์— ๋Œ€ํ•ด ์„ค๋ช…ํ•ด ์ฃผ์‹œ๊ฒ ์Šต๋‹ˆ๊นŒ? ํฐ ๋„์›€์ด ๋  ๊ฒƒ์ž…๋‹ˆ๋‹ค.

SecureNAT์ž…๋‹ˆ๋‹ค. ์ฃ„์†กํ•ฉ๋‹ˆ๋‹ค. ํ™œ์„ฑํ™”ํ•˜๋Š” ๋ฐฉ๋ฒ•์„ ์•Œ๊ณ  ์žˆ์Šต๋‹ˆ๋‹ค.

@DainBB ์ƒˆ๋กœ์šด TAP ์ธํ„ฐํŽ˜์ด์Šค๋กœ SecureNAT ๊ตฌ์„ฑ์„ ๋ณ€๊ฒฝํ•˜์…จ์Šต๋‹ˆ๊นŒ?

๋ณ€๊ฒฝ ์‚ฌํ•ญ ์—†์Œ, ๋ชจ๋“  ๊ธฐ๋ณธ ์„ค์ •

@DainBB ๋‹ค์‹œ ํ•œ ๋ฒˆ ๊ฐ์‚ฌํ•ฉ๋‹ˆ๋‹ค ๋ฉ”์ดํŠธ! ๋‹น์‹ ์€ ๊ต‰์žฅํ•˜๋‹ค!

@AdroitAdorKhan ์•ˆ๋…•ํ•˜์„ธ์š”.
๋ช‡ ๋…„ ์ „์— CPU ์‚ฌ์šฉ๋Ÿ‰์ด ์ตœ๋Œ€ 100%๊นŒ์ง€ ์˜ฌ๋ผ๊ฐ€๊ณ  ์†๋„๊ฐ€ ๋Š๋ ค์ง€๋Š” ๊ฒƒ๊ณผ ๋™์ผํ•œ ๋ฌธ์ œ๊ฐ€ ๋ฐœ์ƒํ–ˆ์Šต๋‹ˆ๋‹ค.

๊ทธ ์‹œ๊ฐ„์— LOCAL BRIDGE์™€ SECURE-NAT๊ฐ€ ๋ชจ๋‘ ํ™œ์„ฑํ™”๋˜์–ด ๋ฐœ๊ฒฌ๋˜์—ˆ์Šต๋‹ˆ๋‹ค.
๊ทธ๋Ÿฐ ๋‹ค์Œ LOCAL BRIDGE๋ฅผ ๋น„ํ™œ์„ฑํ™”ํ•˜๊ณ  SECURE-NAT๋ฅผ ํ™œ์„ฑํ™”ํ•˜๋ฉด ๋ฌธ์ œ๊ฐ€ ํ•ด๊ฒฐ๋ฉ๋‹ˆ๋‹ค...

AdroitAdorKhan์˜ ๋ฌธ์ œ๋Š” ์ด๋ ‡๋‹ค?
(๋‚˜์˜ ์˜์–ด ์‹ค๋ ฅ์ด ์ข‹์ง€ ์•Š์•„ ์ฃ„์†กํ•ฉ๋‹ˆ๋‹ค!)

์•ˆ๋…•ํ•˜์„ธ์š” @libnumafly ์ €๋Š” ๋‹ค๋ฅธ ์ ‘๊ทผ ๋ฐฉ์‹์„ ์‚ฌ์šฉํ–ˆ์Šต๋‹ˆ๋‹ค. ๋‚˜๋Š” dnsmasq์™€ bridge๋ฅผ ์‚ฌ์šฉํ–ˆ๊ณ  ์ง€๊ธˆ์€ ์•„์ฃผ ์ž˜ ์ž‘๋™ํ•ฉ๋‹ˆ๋‹ค!

์•Œ๊ฒ ์Šต๋‹ˆ๋‹ค. @AdroitAdorKhan ๋‹ต๋ณ€ ๊ฐ์‚ฌํ•ฉ๋‹ˆ๋‹ค!

์ด ํŽ˜์ด์ง€๊ฐ€ ๋„์›€์ด ๋˜์—ˆ๋‚˜์š”?
0 / 5 - 0 ๋“ฑ๊ธ‰