ãã®èšäºã§ã¯ãå¿
èŠãªããã±ãŒãžãéžæããŠãç¬èªã®Openwrtãã¡ãŒã ãŠã§ã¢ãæ§ç¯ãããã£ãã«ã®å³æããŒããŒã·ã§ã³ãšãããã®åææäœã«ãããã©ãŒã«ããã¬ã©ã³ããªã€ã³ã¿ãŒãããã¢ã¯ã»ã¹ã®èšå®ããããã€ããŒã®é床ã®è¿œå ããããŠãã®çµæããã¹ãŠã®ãæ°ã«å
¥ãã®VLANã®èšå®ã®çµéšãå
±æããããšæããŸãã
éžæè¢ã¯ã«ãŒã¿ãŒTp-Link TL-WR741ND v.4.25ïŒäŸ¡æ Œ1150ã«ãŒãã«ïŒã«ããã次ã®ç¹æ§ã«åŸã£ãŠéžæããŸããã
1ïŒäœäŸ¡æ Œ
2ïŒæå®ãããèŠä»¶ã«ååãªéã®ã¡ã¢ãª
3ïŒUSBããã©ãã·ã¥ããæ©èœïŒçã®æ奜家ãéçãæãããïŒ
4ïŒOpenWrtããªã¢ãã¬ãŒã«ãŒã®ãµããŒã
5ïŒVLANãµããŒã
6ïŒé©ãã¹ãçåæ§ïŒäžæ£ãªãã¡ãŒã ãŠã§ã¢ã§ã¯ã«ãŒã¿ãŒã殺ãããšãã§ãããtftpdã«ãããã¡ãŒã ãŠã§ã¢å埩æ©èœã¯æèšã®ããã«æ©èœãã倱æããå®éšäžã«äœåºŠãå©ããŸããïŒã å埩æ¹æ³ã«ã€ããŠã¯ãèšäºã®æåŸã«æžããŸãã
OpenWrtã®ãã®ã«ãŒã¿ãŒã®æšæºãã¡ãŒã ãŠã§ã¢ã¯é©åããŸããã§ããã ãã®çç±ã¯ããã®èµ€ã¡ããã®è²Žéãªèšæ¶ã®å Žæãå ããäœåãªããã±ãŒãžã§ããã
ã«ããããããšã«æ±ºããŸããïŒpppãipv6ã®ãµããŒããopkgïŒä»ã®ãã®ã¯ã€ã³ã¹ããŒã«ããŸããïŒã
è¿œå ïŒopenvpn-polarsslïŒå¿
èŠãªã¹ããŒã¹ãå°ãªãïŒãluci-mwan3ïŒèŠèŠèšå®ãšãã£ã³ãã«ã®è¡šç€ºãæ¬åœã«æ°ã«å
¥ã£ãïŒ
ããã§ã¯ãå§ããŸãããïŒ
1ïŒããã€ã¹ã®æºå
éå§ããã«ã¯ãããã€ã¹ãæšæºã®tp-linkãã¡ãŒã ãŠã§ã¢ã®ææ°ããŒãžã§ã³ã«
æŽæ°ããŠãã ããã ãã®ã¢ã¯ã·ã§ã³ã詳现ã«èª¬æããããšã«ã¯æå³ããããŸããããã¹ãŠãéåžžã«æ確ã§ã·ã³ãã«ã§ãã
2ïŒãã¡ãŒã ãŠã§ã¢ã®åé
ãã¡ãŒã ãŠã§ã¢ãå¿«é©ã«äœæããã«ã¯ããã«ãã³ã¢ããã»ããµãå¿
èŠã«ãªããŸãïŒi7äžã«æ§ç¯ããŸããïŒã ãã ããåéããæéãé·ããªããªãéããCore2Duoã¯å®è¡ããŸãã OSã¯Ubuntu 15 x86_64ã«é©åããŸãã
å¿
èŠãªããã±ãŒãžã®ã€ã³ã¹ããŒã«ïŒ
sudo apt-get update && sudo apt-get upgrade -y sudo apt-get install subversion git g++ libncurses5-dev zlib1g-dev gawk -y
ãã以éã®ãã¹ãŠã®ãã«ãã³ãã³ãã¯ãã«ãŒãããã§ã¯ãªããå¹³åçãªãŠãŒã¶ãŒããäœæãããŸãïŒãœãŒã¹ã®ãã¹ãã¢ãã«ç§»åããŸãã OpenWrt Bariier Breakerãéžæããã®ã¯ãã»ããã¢ãããç°¡åã§ã以åã®ã«ãŒã¿ãŒïŒTP-LINK Archer C7ïŒã§ã®å®å®æ§ãåªããŠããããã§ãã
svn co svn://svn.openwrt.org/openwrt/branches/barrier_breaker wrt cd ~/wrt svn update
ããŒã ãã©ã«ããŒã«ã¯ããã«ãããwrtãã©ã«ããŒããããŸãã
è¿œå ããã±ãŒãžïŒLuciãªã©ïŒã®ãœãŒã¹ãããŠã³ããŒãããŸãã
./scripts/feeds update -a ./scripts/feeds install -a
ãã©ãããã©ãŒã ãèšå®ããŸããã
make menuconfig
ã¿ãŒã²ããã·ã¹ãã ããµãã¿ãŒã²ãããã¿ãŒã²ãããããã¡ã€ã«ã®é
ç®ã«é¢å¿ãããæ¬äŒŒã°ã©ãã£ãã¯ã¡ãã¥ãŒã衚瀺ãããŸãã

ãã¹ãŠã®ããã²ãŒã·ã§ã³ã§ãç®çã®ã¢ã€ãã ïŒç¢å°ïŒãéžæããEnterããŒãæŒããŸããã³ã³ããŒãã³ãéžæ-EnterããŒãã¡ãã¥ãŒãçµäº-å·Šç¢å°ããã³å³ç¢å°-Exitã æ§æãä¿åããããšãå¿ããªãã§ãã ããã
ãããã¡ã€ã«ã«æšæºãã©ã¡ãŒã¿ãŒãé©çšããŸãã
make defconfig
ããã±ãŒãžã®ã»ãããå€æŽããŸãã
make menuconfig
åé€æžã¿ïŒopkg fromïŒåºæ¬ã·ã¹ãã ïŒ
ipv6ããµããŒããããã«ããªãã·ã§ã³ãåé€ïŒã°ããŒãã«ãã«ãèšå®ïŒ
pppïŒãããã¯ãŒã¯ïŒã
è¿œå è
ïŒã«ã·
luci-app-mwan3ïŒLuci-ApplicationsïŒ
openvpn-polarsslïŒãããã¯ãŒã¯VPNïŒã
æ§æãä¿åããããšãå¿ããªãã§ãã ããïŒã¢ã»ã³ããªãéå§ããŸãã make -j5 V=s
-j5ãã©ã¡ãŒã¿ãŒã¯ãã³ã¢ã®æ°+è¿
éãªçµã¿ç«ãŠã®ããã®1ã¹ã¬ããã瀺ããV = sã¯è©³çŽ°ã®åºåã瀺ããŸãïŒãšã©ãŒãããå ŽåïŒã
ãã®ããã»ã¹ã¯ãi7ããã»ããµã§10ã15åãããããã®åŸãã«ãŒã¿ãŒã®ããŸããŸãªããŒãžã§ã³ã®ãã¡ãŒã ãŠã§ã¢ããã£ã¬ã¯ããª/ home / user / wrt / bin / ar71xxã«è¡šç€ºãããŸãã 衚瀺ãããŠããªãå Žåã¯ããã«ããã°ã確èªããŸãã確ãã«ããã¡ãŒã ãŠã§ã¢ã®ãµã€ãºãè¶
ããŠãããããããã¡ãŒã ãŠã§ã¢ã倧ããããŸãããšããè¡ã衚瀺ãããŸãã ã¯ãªãŒã³ã«ããdistcleanã«ããæåããããçŽãå¿
èŠããããŸãã ïŒã¹ããã./scripts/feeds update -aããïŒ
èå³ãããã®ã¯ïŒ
openwrt-ar71xx-generic-tl-wr741nd-v4-squashfs-factory.bin- ãå·¥å Žããã¡ãŒã ãŠã§ã¢ã
ã€ãŒãµãããçµç±ã§æ¥ç¶ãããã«ãŒã¿ãŒïŒããšãã°ãftpãwinscpïŒã䜿çšããŠã³ã³ãã¥ãŒã¿ãŒã«è»¢éããŸãã
ã¢ãã¬ã¹
192.168.0.1ã«ç§»åããæ°ããäœæããããã¡ãŒã ãŠã§ã¢ããã©ãã·ã¥ããåèµ·åãåŸ
æ©ããŠãããã¢ãã¬ã¹
192.168.1.1ã«ç§»åããŸãã
ãã¹ã¯ãŒããªãã®ã«ãŒãïŒæåã®ãã°ã€ã³æã«å²ãåœãŠãŸã-èŠåä»ãã®é»è²ã®ãããŒãšãã¹ã¯ãŒããå€æŽãããªã³ã¯ãäžéšã«ãã³ã°ããŸãïŒã
ããŠãæåŸã«ãæãé£ããéšåãèåŸã«ãããŸããçŸåšãææ°ã®ãã¡ãŒã ãŠã§ã¢ãšããã°ã©ã ã®ã»ããããããŸãã
3ïŒVLANã®æ§æïŒ
ã«ãŒã¿ãŒã¡ãã¥ãŒã§çºçããŸãïŒ
ãããã¯ãŒã¯-ã¹ã€ãã
ããã€ãã®èª€è§£ããããŸãã-ã«ãŒã¿ãŒãšVLANæ§æã®ããŒãçªå·ãäžèŽããŠããŸããã ã¹ã¯ãªãŒã³ã·ã§ããã§ã¯ãããããã©ã®ããã«å€æŽããããã説æããããšããŸããã ã«ãŒã¿ã®WANããŒãã¯vlanæ©èœã«é¢äžããŠããŸããã
ã¿ã°ä»ã -ã¿ã°ä»ããã©ãã£ãã¯ãåVLANïŒ101ã102ã103ïŒããã®ãã±ããã¯ããã§éä¿¡ãããã€ã³ã¿ãŒãã§ãŒã¹wanïŒãã©ã€ããªãããã€ããŒïŒãwan2ïŒããã¯ã¢ãããããã€ããŒïŒãeth0.103ïŒããŒã«ã«ãããã¯ãŒã¯ã®VLANïŒã§é
ä¿¡ãããŸãã
ã¿ã°ãªã-ã¿ã°ãªãããŒãã¢ãŒãïŒç®çã®ãããã€ããŒããã®ã€ãŒãµãããã±ãŒãã«ãšã³ããªãã€ã³ãïŒã ããã§ã¯ãé
ç·ãæ··åããªãããã«ããããšãéèŠã§ããäœãã©ãã«è¡ãã®ãã å°æ¥æ··ä¹±ããªãããã«ãã«ãŒã¿ãŒã®èé¢ã§å¿
èŠãªååã«çœ²åããŸããïŒãããã€ããŒçªå·101ããããã€ããŒçªå·102ãLAN 103ïŒã
ç°¡åã«èšãã°ã3ã€ã®ç°ãªããããã¯ãŒã¯ãä»ããŠ3ã€ã®ããŒããæ¥ç¶ããããã€ã¹å
ã®ã·ã§ã«ãã«é
åžããŸãã
å€æŽåŸããä¿åããã¯ãªãã¯ããŸããããé©çšãã¯ã¯ãªãã¯ããŸããïŒ ã»ããã¢ããäžã«ãããã¯ãŒã¯ãªãã§æŸçœ®ãããããªãã§ããïŒ
ããã§ã
ãããã¯ãŒã¯-ã€ã³ã¿ãŒãã§ãŒã¹ã§å¿
èŠãªã€ã³ã¿ãŒãã§ãŒã¹ãäœæããå¿
èŠããããŸãã

wan6ã€ã³ã¿ãŒãã§ãŒã¹ãåé€ããŸãïŒãã®å Žåãipv6ã¯äœ¿çšããŸããïŒã
æåã®ãããã€ããŒã®wanã€ã³ã¿ãŒãã§ã€ã¹ãå€æŽããæ¥ç¶ã«å¿
èŠãªããŒã¿ãæå®ãïŒããšãã°ããããã€ããŒãdhcpçµç±ã§ã€ã³ã¿ãŒããããæäŸããïŒããã®ã€ã³ã¿ãŒãã§ã€ã¹ã«äœ¿çšããVLANãæå®ããŸãã ããã¯VLANãããã³ã°ãè¡ããšããã§ãïŒã¯ã€ã€ãŒïŒã€ã³ã¿ãŒãã§ã€ã¹ã

2çªç®ã®ãããã€ããŒwan2ã«ã¯ãeth0.102ãæå®ããŸãã
Lanã®å Žåãããªããžeth0ããã³eth0.103ã§çµåããã€ã³ã¿ãŒãã§ã€ã¹ãæå®ããŸãã

wanããã³wan2ã€ã³ã¿ãŒãã§ãŒã¹ã®èšå®ã§ãããã€ã¹ã¡ããªãã¯ãæå®ããŸãïŒmwan3ãæ©èœããããã«å¿
èŠïŒïŒ

ããã§å®å
šã«
ãä¿åããŠé©çšããã¯ãªãã¯ããŠãå
¥åããèšå®ã確èªã§ããŸãã
4ïŒmwan3ãŸãã¯cool admin admin
ãã®ããã±ãŒãžãéå°è©äŸ¡ããããšã¯å°é£ã§ãããŠãŒã¶ãŒã¯2ã€ã®ã€ã³ã¿ãŒããããã£ãã«ã®é床ã®åèšãåãåãããšãã§ããã€ã³ã¿ãŒãããã¯åžžã«ãªãã£ã¹ã«ãããŸããäž¡æ¹ã®ãã£ãã«ãèœã¡ãå¯èœæ§ã¯äœãããã§ãã
管çè
ã«ãšã£ãŠãããããã®ãã£ãã«ãäžæçã«åæããã®ã¯é çã®çš®ã§ãããåãæ¿ãã®ããã«æŸèæã¹ã¯ãªãããäœæããå¿
èŠã¯ãããŸããã ã€ã³ã¿ãŒãããã®ãªãã£ã¹ã®åé¡ãå¿ããŠããŸã£ãã®ã§ããã®ãã¡ã®1ã€ãã¯ã©ãã·ã¥ãããšãã«å¿é
ããå¿
èŠã¯ãããŸããïŒãããã®ã€ãã³ãã®SMSãåãåããŸãïŒã
OpenVPNã30ç§ã§ããã¯ã¢ãããã£ãã«ã«åãæ¿ããããšã¯ç¢ºãã§ãïŒãã«ãããŒã ãã©ã¡ãŒã¿ãŒã®ãããã§ïŒãã¢ã¹ã¯ã¯ã®æ¬ç€Ÿãšã®éä¿¡ã埩å
ãããäžéšã®ãŠãŒã¶ãŒãšäžåžã¯ãã®ã€ã³ã·ãã³ãã«æ°ä»ããªãã§ãããã
ç¶è¡ïŒãããã¯ãŒã¯ã«è¡ããŸããã-è² è·åæ£-èšå®ïŒ

ãããŠwan2ãä»äºã«å€ããŸãïŒ

次ã«ããã£ãã«ã®ã«ãŒã«ãæ§æããŸãã
1ïŒãã©ã³ã¹-ãã£ã³ãã«ãè¿œå ãããé床ãäžããããã©ãŒã«ããã¬ã©ã³ã¹ããããŸãïŒåãæ¿ãïŒã ãå§ãã§ãã
2ïŒwan_only-ãããã€ããŒçªå·1ã®ã¿
3ïŒwan2_only-ãããã€ããŒçªå·2ã®ã¿
æ§æ-ã«ãŒã«

æ®ãã®ã«ãŒã«ã¯åé€ããããå¥ã®ã«ãŒã«ãæ®ãããšãã§ããŸãã
mwan3ã«ã€ããŠã¯è©³ãã説æããŸããããã®ãªãœãŒã¹ã«IPãã€ã³ãã£ã³ã°ãããå Žåããã£ãã«ã®1ã€ãä»ããŠç¹å®ã®ãªãœãŒã¹ã«ãã©ãã£ãã¯ãéä¿¡ããããšãå¯èœã ãšèšããŸãã
5ïŒãªãã£ã¹ã®åæ
ãŸãã¯openvpn
ããŠãã€ã³ã¿ãŒããããèšå®ããŸããã2ã€ã®ãªãã£ã¹ãæ¥ç¶ããå¿
èŠããããŸãã
éçããŒã§è¡ããŸãã ããŒã®çæã¯ãã¯ã©ã€ã¢ã³ãåŽã§å®è¡ã§ããŸãã
sudo openvpn --genkey --secret office2.key
ããŒã¯ã/ etc / openvpn / keys /ïŒãµãŒããŒãã¯ã©ã€ã¢ã³ãïŒã«é
眮ããå¿
èŠããããŸãã
OpenVPNã¯æ¢ã«ã«ãŒã¿ãŒã«ã€ã³ã¹ããŒã«ãããŠãããæ§æã®ç·šéãéå§ããŸãã ãããè¡ãã«ã¯ãsshçµç±ã§TP-Linkã«ã¢ã¯ã»ã¹ããŸãã
vi /etc/config/openvpn
configããããŒã§å€æŽããŸãïŒ
package openvpn
ä¿åããŠçµäºããŸãã ããã§ã¯ãã«ã¹ã¿ã æ§æã/etc/openvpn/openvpn.confã«å«ããŸãããç§ã«ãšã£ãŠã¯ãå人çã«ã¯å€å°éŠŽæã¿ããããŸãã
次ã«ãèšå®èªäœïŒ
mkdir /etc/openvpn mkdir /etc/openvpn/keys vi /etc/openvpn/openvpn.conf
ã«ãŒã¿ãŒã«ã¯ããµãŒããŒåŽã®openvpnããããŸãã æ§æã確èªããŸãïŒ
port 1194
ä¿åããŠããïŒ
/etc/init.d/openvpn restart
ã¯ã©ã€ã¢ã³ãïŒ
èšå®äŸã¯æ¬¡ã®ããã«ãªããŸãã
remote wan.office2.ru
èšå®ãä¿åããé©çšããŸãïŒ
/etc/init.d/openvpn restart
ifconfigããã°ãç£èŠããä¿¡é Œã§ãããã£ã³ãã«ã楜ããã§ããŸãã
çµè«ïŒ
ãã¡ããã倱æãããã¡ãŒã ãŠã§ã¢ã䜿çšããŠã«ãŒã¿ãŒãè€æ°å匷å¶çµäºããåºæ¬ã·ã¹ãã ã®å¿
èŠãªã³ã³ããŒãã³ããåé€ããæéããããŸãã
ãããã倧ããããšã¯ãããŸããïŒ
ã«ãŒã¿ãŒã埩å
ããæãç°¡åãªæ¹æ³ã¯ãopenwrtã§
å®å
šã«
倱æããããšã§ãã
1ïŒIPã¢ãã¬ã¹192.168.1.2ãã³ã³ãã¥ãŒã¿ãŒã®ãããã¯ãŒã¯ã¢ããã¿ãŒã«å²ãåœãŠãŸã
2ïŒãã¹ã¯255.255.255.0
3ïŒã€ãŒãµãããã±ãŒãã«-LAN1ããŒããž
4ïŒã«ãŒã¿ãŒã®é»æºãåã
5ïŒé»æºãå
¥ããæ¯è»ã®ã¢ã€ã³ã³ãç¹ç¯ãããŸã§åŸ
ã¡ãŸã
6ïŒQSSã«ãŒã¿ãŒãã¿ã³ã1ã2ç§éæŒãç¶ããŸã-ã®ã¢ãéåžžã«éãç¹æ»
ããŸã
7ïŒtelnetã¯ã©ã€ã¢ã³ããèµ·åããã¢ãã¬ã¹192.168.1.1ã«æ¥ç¶ããŸã
8ïŒããšãã°ãtinywebããWebãµãŒããŒãä»ããŠãã¢ãã«ã®ããã©ã«ãã®æå·åãtmpã«ãŒã¿ãŒã«æ³šããŸã
9ïŒå®è¡ïŒ
mtd -r write /tmp/.bin firmware
ã«ãŒã¿ãŒã¯ãã¡ãŒã ãŠã§ã¢ã䜿çšããŠãªããŒãããŸãã
ã·ã§ããããã¯ãã¹ãŠãªããªã£ãïŒã¯ããããã¯ç§ãã«ãŒã¿ãŒãããã«æ¿ãã殺ãããšãç§ãæã£ãŠãããã®ã§ãã ã®ã¢ã¯çãããã«ãŒã¿ãŒã¯åæ¢ããããšãªãåšæçã«åèµ·åããŸããã
tp-linkãã¡ãŒã ãŠã§ã¢ã§çŽ æŽãããæ©èœã䜿çšããŸã-tftpçµç±ã§ãã¡ãŒã ãŠã§ã¢ãããŠã³ããŒãããŸãïŒ
1ïŒIPã¢ãã¬ã¹192.168.0.66ãã³ã³ãã¥ãŒã¿ãŒã®ãããã¯ãŒã¯ã¢ããã¿ãŒã«å²ãåœãŠãŸã
2ïŒãã¹ã¯255.255.255.0
3ïŒã€ãŒãµãããã±ãŒãã«-LAN1ããŒããž
4ïŒãwr741ndv4_tp_recovery.binããšãããã©ã«ããŒå
ã®ããã©ã«ããã¡ãŒã ãŠã§ã¢ã§tftpãµãŒããŒãå®è¡ããŸãïŒãã¡ãŒã ãŠã§ã¢ãã¡ã€ã«ã®ååãå€æŽããå¿
èŠããããŸãïŒ
4ïŒã«ãŒã¿ãŒã®é»æºãåã
5ïŒéãèãç©äœïŒãã³ïŒãåããŸã
6ïŒã«ãŒã¿ãŒãæã«åããããŒãã®ããé¢ã«åããŠã空ããŠããæã§ãã³ãã«ãæã¡ãŸãã
7ïŒã«ãŒã¿ãŒã®é»æºãå
¥ããããã«çæ¹ã®æã§QSSãä¿æããããçæ¹ã®æã§ãã³ãã«ããªã»ããããŸãã ç·Žç¿ããã°ããŸããããŸãã
8ïŒtftpã¯ã©ã€ã¢ã³ãã§ã«ãŒã¿ãŒãžã®ãã¡ãŒã ãŠã§ã¢ã®ããŠã³ããŒããéå§ããããŸã§ãããã2ã€ã®ãã¿ã³ã4ã8ç§éæŒãç¶ããŸãã ãããŠåœŒå¥³ã¯è¡ããŸããå¿é
ããªãã§ãã ããã
ãã¡ãŒã ãŠã§ã¢ãããŒãããããïŒ2ã3ç§ïŒãã¿ã³ãæŸããŸãã æ¯ãåããã«ãŒã¿ãŒãä¿åãããŸãã
äžå€åïŒwiki.openwrt.org/en/doc/howto/buildopenvpn.net/index.php/open-source/documentation/miscellaneous/78-static-key-mini-howto.htmldenisyuriev.ru/linux/openwrt-linux/openwrt-sborka-iz-isxodnikovhabrahabr.ru/post/186760wiki.gentoo.org/wiki/OpenVPNwiki.openwrt.org/doc/howto/mwan3wiki.openwrt.org/en/doc/howto/generic.uninstall