ç§ã®åã«ãã¯ã©ã€ã¢ã³ãèšŒææžãšããããåãæ¶ãæ©èœã䜿çšããŠãMikroTikãOVPNãµãŒããŒãšããŠæ§æããã¿ã¹ã¯ããããŸããã ãã®ããŒãã«é¢ããæç¢ºãªããŠããŒãã€ã³ã¿ãŒãããäžã§èŠã€ããããªãã£ãã®ã§ãèªåã®èªè»¢è»ãçºæããããšã«ããŸããã ãã®èšäºã§ã¯ããã®å¥è·¡ã®æ§æã¹ããŒã ã«ã€ããŠèª¬æããŸãã
PKI ROSã®äœ¿çš
PKIã«ã€ããŠã¯ã2ã€ã®ãªãã·ã§ã³ããããŸãã
1.çµã¿èŸŒã¿ã®PKI ROSã®äœ¿çšïŒ
- +èšŒææžãMikrotikã§çŽæ¥çºè¡ããŠå€±å¹ãããããšãã§ããŸããããã§ãªãå Žåã¯ã倱å¹ãããã³ã«æåã§crlãæŽæ°ããå¿
èŠããããŸã
- -蚌ââææžã®çœ²åãšåãæ¶ãã«äœ¿çšãããCAèšŒææžã®Mikrotikããã®èª€ã£ãåé€-èŽåœçãªã以åã«ã¢ããããŒããããèšŒææžãšCAããŒã®ã€ã³ããŒãã¯åœ¹ã«ç«ãããååãæ¶ãåŸã«opensslã䜿çšããŠæåã§crlãããŠã³ããŒãããããšã®ã¿ãå¯èœã§ãïŒãã¡ãããããããã¹ãŠã®å®éã®ããã¯ã¢ããããããŸãïŒ
- + Mikrotikæ§æå
šäœãããã¯ã¢ããããå ŽåãCAã¯ãããšãšãã«ããã¯ã¢ããããŸã
2.ãµãŒãããŒãã£ã®PKI-opensslããŸãã¯PKI WindowsãµãŒããŒã䜿çšããŸãïŒStartSSLãªã©ã®ä¿¡é Œã§ããCAã¯äœ¿çšããªãã§ãã ãããã¯ã©ã€ã¢ã³ãèšŒææžã¯ããªãã ãã«çºè¡ãããŸããïŒã
- +æåã®ãªãã·ã§ã³ã®æ¬ åŠããä¿è·
- -opensslã®å ŽåãåèšŒææžãåãæ¶ãããåŸãæåã§crlãMikrotikã«ã¢ããããŒãããå¿
èŠããããŸã
- + WindowsãµãŒããŒPKIã®å ŽåãSCEPã¡ã«ããºã ãä»ããŠèªèšŒãå®è£
ããããšã¯çè«çã«ã¯å¯èœã§ããããŸã æ€èšŒãããŠããŸãã
- -WindowsãµãŒããŒPKIã®å Žåããã¡ã€ã³ãå¿
èŠã§ããããããªããšããã®åãPKIã¯æ©èœããŸããã
第äžã«ãããã¯ç§ã«åã£ãŠããã®ã§ã第äºã«ãããã¯ããæè»ã§ãããããæåã®ãªãã·ã§ã³ã®ã¿ãæ€èšããŸãã ãŸããèšŒææžã®ãã©ã¡ãŒã¿ãŒãæšæºROSããŒã«ã®ä»ã®ããŸããŸãªãã©ã¡ãŒã¿ãŒã«ã€ããŠã¯èª¬æããŸããã å
æ¬çãªèª¬æã¯ãå
¬åŒã®
MikroTik Wikiã«ãããŸãã
ROSã§OVPNãµãŒããŒãæ§æãã
1. PKIã®æ§æ
1.1ã CAèšŒææžïŒ
/certificate add name=template-CA country="" state="" locality="" organization="" unit="" common-name="test-CA" key-size=4096 days-valid=3650 key-usage=crl-sign,key-cert-sign
/certificate sign template-CA ca-crl-host=127.0.0.1 name="test-CA"
泚ïŒca-crl-host =ã¯å¿
é ãã©ã¡ãŒã¿ãŒã§ãããã以å€ã®å Žåãã¬ãã¥ãŒãªã¹ãã¯äœæãããŸããã 倱å¹ãªã¹ããžã®å®å
šãªãã¹ã¯ãèšŒææžã®ãã©ã¡ãŒã¿ãŒã®åã[1]倱å¹ãªã¹ãã®é
åžãã€ã³ãïŒCRLïŒãã«ç€ºãããŸãã ååãšããŠãMikrotikã®IPã¢ãã¬ã¹ã®ãããããæå®ã§ããŸããããã¯ãæå®ãããã®ã§ãããèšŒææžã«ç»é²ãããŸãã æ®å¿µãªããããã¡ã€ã³åã¯ãã©ã¡ãŒã¿ãŒã§ãµããŒããããŠããŸããã
1.2ã ãµãŒããŒèšŒææžïŒ
/certificate add name=template-SRV country="" state="" locality="" organization="" unit="" common-name="test-srv-OVPN" key-size=4096 days-valid=1095 key-usage=digital-signature,key-encipherment,tls-server
/certificate sign template-SRV ca="test-CA" name="test-srv-OVPN"
泚ïŒéµäœ¿çšãµãŒããŒèšŒææžã®å Žåã
ããã§èª¬æãããŠ
ããçç±ã倿Žããªãããšããå§ãããŸãïŒå®éã«å€æŽãããå Žåã¯ãã¯ã©ã€ã¢ã³ãã®æ§æã«ç»é²ããå¿
èŠãããããšã瀺ããŸãïŒã
泚ïŒSSTPãšã¯ç°ãªããOVPNã¯ããµãŒããŒèšŒææžã®å
±éåããã®ãµãŒããŒã®fqdnãšäžèŽãããã©ããããã§ãã¯ããŸããã
1.3ã é¡§å®¢èšŒææžã®ãã³ãã¬ãŒãïŒ
/certificate add name=template-CL country="" state="" locality="" organization="" unit="" common-name="test-client-ovpn-template" key-size=4096 days-valid=365 key-usage=tls-client
1.3.1æåã®ã¯ã©ã€ã¢ã³ãã®èšŒææžïŒ
/certificate add name=template-CL-to-issue copy-from="template-CL" common-name="test-client-ovpn-1"
/certificate sign template-CL-to-issue ca="test-CA" name="test-client-ovpn-1"
1.3.2ã 2çªç®ä»¥éã®é¡§å®¢ã®èšŒææžïŒ
ã»ã¯ã·ã§ã³3.1ãåç
§ããŠãã ããããã ãããã©ã¡ãŒã¿ãŒã®å€ã倿ŽããŸãã
common-name="test-client-ovpn-1"
æåã®ã³ãã³ãã®å Žåããã®å€ã¯åãCAå
ã§äžæã§ãªããã°ãªããŸããã
name="test-client-ovpn-1"
2çªç®ã®ããŒã ã®å Žåããã®å€ã¯1ã€ã®ãã€ã¯ããã£ãã¯å
ã§äžæã§ãªããã°ãªããŸããã
1.4å°æ¥ãèšŒææžãåãæ¶ãã«ã¯ã次ã®ã³ãã³ãã䜿çšããŸãã
certificate issued-revoke %cert-name%
ããã§ãïŒ
cert-nameïŒ
ã¯ã眲åãããèšŒææžã®åå=ãã£ãŒã«ãã§ããã€ãŸããPKI mikrotikaã衚瀺ãããŸãã
2. OVPNãµãŒããŒãæ§æãã
泚ïŒtunã¢ãŒãïŒROSã®ãipãïŒã§æ§æããããtapã¢ãŒãïŒROSã®ãethernetãïŒã§æ§æã§ããŸãã Tunã¢ãŒãã¯éåžžã®ãã³ãã«ã§ãã ã¿ããã¢ãŒã-ãã«ã€ãŒãµãããã®ãšãã¥ã¬ãŒã·ã§ã³ãç¹ã«ã¿ããã¢ãŒãã§ã¯ãã¯ã©ã€ã¢ã³ããããªããžã¢ãŒãã«çµåã§ãããäºããå®å
šã«èªèããŸãã çè«çã«ã¯ãã¿ããã¢ãŒãã§DHCPãµãŒããŒãèµ·åã§ããŸãããããã¯ROSã®çŸåšã®ããŒãžã§ã³ã§ã¯å®è£
ãããŠããŸããã
2tunã 調æŽã¢ãŒã
2ãã³1ââã OVPNã¯ã©ã€ã¢ã³ãã®ã¢ãã¬ã¹ããŒã«ãèšå®ããŸãïŒPPPãããã¡ã€ã«ã§çŽæ¥èšå®ã§ããŸãïŒã
/ip pool add name=OVPN_srv_pool ranges=192.168.100.2-192.168.254
2ãã³2ã OVPNãµãŒããŒã®PPPãããã¡ã€ã«ãäœæããŸãã
/ppp profile add name=OVPN_server local-address=192.168.100.1 remote-address=OVPN_srv_pool
ãªãã·ã§ã³ïŒ æ®ãã®ãã©ã¡ãŒã¿ãŒã¯ãã客æ§ã®å¥œã¿ã«åãããŠãç®æšã«å¿ããŠæ±ºãŸããŸãã äŸïŒdns = 192.168.100.1 use-ipv6 = no
2tunã3ã ãŠãŒã¶ãŒèªèšŒã¢ãŒããæ§æããŸãã
/ppp aaa set accounting=yes
2ãã³4ã ãŠãŒã¶ãŒã远å ããŸãã
/ppp secret add name=test-user-1 password=P@ssword1 service=ovpn profile=OVPN_server
/ppp secret add name=test-user-2 password=P@ssword2 service=ovpn profile=OVPN_server
2ãã³5ã OVPNãµãŒããŒã®é»æºãå
¥ããŸãã
/interface ovpn-server server set auth=sha1 cipher=blowfish128 default-profile=OVPN_server mode=ip netmask=24 require-client-certificate=yes certificate=test-srv-OVPN enabled=yes
2ã¿ãã ã¿ããã¢ãŒã
2ã¿ãã1ã OVPNã¯ã©ã€ã¢ã³ãã®ã¢ãã¬ã¹ããŒã«ãèšå®ããŸãïŒPPPãããã¡ã€ã«ã§çŽæ¥èšå®ã§ããŸãïŒã
/ip pool add name=OVPN_srv_pool ranges=192.168.100.2-192.168.254
2tap.1 +ã OVPNæ¥ç¶çšã®ããªããžãäœæããŸãã
/interface bridge add name=OVPN_bridge arp=enabled
泚ïŒããªããžã®IPã¯å²ãåœãŠãå¿
èŠããããŸãããããã¯æ¢ã«PPPãããã¡ã€ã«ã«ãããŸãïŒããã«ãããªããžã®ã¢ãã¬ã¹ãæå®ããããPPPãããã¡ã€ã«ã§local-address =ãæå®ããªãå Žåãã¯ã©ã€ã¢ã³ãã¯æ¥ç¶ããŸããïŒã
泚ïŒarpãæå¹ã«ããå¿
èŠããããŸããæå¹ã«ããªããšãã¯ã©ã€ã¢ã³ãã¯ãäºããèŠãããšãã§ããŸããã
2ãã³2ã OVPNãµãŒããŒã®PPPãããã¡ã€ã«ãäœæããŸãã
/ppp profile add name=OVPN_server local-address=192.168.100.1 remote-address=OVPN_srv_pool bridge=OVPN_bridge
ãªãã·ã§ã³ïŒ æ®ãã®ãã©ã¡ãŒã¿ãŒã¯ãã客æ§ã®å¥œã¿ã«åãããŠãç®æšã«å¿ããŠæ±ºãŸããŸãã äŸïŒdns = 192.168.100.1 use-ipv6 = no
2ã¿ãã3ã ãŠãŒã¶ãŒèªèšŒã¢ãŒããæ§æããŸãã
/ppp aaa set accounting=yes
2ã¿ãã4ã ãŠãŒã¶ãŒã远å ããŸãã
/ppp secret add name=test-user-1 password=P@ssword1 service=ovpn profile=OVPN_server
/ppp secret add name=test-user-2 password=P@ssword2 service=ovpn profile=OVPN_server
2ã¿ãã5ã OVPNãµãŒããŒã®é»æºãå
¥ããŸãã
/interface ovpn-server server set auth=sha1 cipher=blowfish128 default-profile=OVPN_server mode=ethernet netmask=24 require-client-certificate=yes certificate=test-srv-OVPN enabled=yes
äž¡æ¹ã®ã¢ãŒãã«é¢ããæ³šæïŒ
1.èšŒææžã®æ¿èªã«ããããããããŠãŒã¶ãŒã®ååšã¯å¿
é ã§ãã ãã¹ãŠã®ã¯ã©ã€ã¢ã³ãã«å¯ŸããŠ1人ã®ãŠãŒã¶ãŒãäœæããã¯ã©ã€ã¢ã³ãæ§æã«åããŠãŒã¶ãŒå/ãã¹ã¯ãŒããç»é²ã§ããŸãããããã«ããç¹å®ã®ãŠãŒã¶ãŒã®æ¥ç¶ãšã¢ã¯ã·ã§ã³ã远跡ã§ããªããªããŸã-äžäŸ¿ã§ãããå®å
šã§ã¯ãããŸããã
2. RADIUSèªèšŒã«ã€ããŠã¯ããã¹ãããŠããªããšããçç±ã ãã§æ€èšããŠããŸããã ãŠãŒã¶ãŒå/ãã¹ã¯ãŒãã«å¯ŸããŠã®ã¿æ©èœãããšæ³å®ã§ããŸãããèšŒææžã¯åŒãç¶ãMikrotikã§ãã§ãã¯ãããŸãã
3.ã¢ãã¬ã¹ããŒã«ãOVPNãµãŒããŒèšå®ã§æå®ããããµãããããšäžèŽããããšã確èªããŸãã ããã«ãROS OVPNãµãŒããŒã¯ãããšãã°ããã¹ã¯29ã䜿çšããranges = 192.168.100.0 / 29ãããŒã«ãšããŠæå®ããå ŽåãããŒã«ã«ã¢ãã¬ã¹=ãµãŒããŒãšããŒã«ããå²ãåœãŠãããã¯ã©ã€ã¢ã³ãã¢ãã¬ã¹ãåããããã¯ãŒã¯ã«å±ããŠãããã©ããã倿ããŸããããããŒããã£ã¹ã192.168.100.7ã¯ãç§ãæã£ãŠããããã«ãã¯ã©ã€ã¢ã³ãã«ç°¡åã«å²ãåœãŠãããšãã§ããŸãã 瀺ãããããŒã«ããã¹ã¯ã瀺ãããã倧ããå ŽåããŸã£ããåãç¶æ³ãçºçããå¯èœæ§ããããŸããåé¡ã®ã¿ãããã«ã¯æããã«ãªãããå°ãåŸã§æããã«ãªããŸãã
3.èšŒææžããšã¯ã¹ããŒãããŠã¯ã©ã€ã¢ã³ããæ§æãã
3.1ã CAèšŒææžã®ãšã¯ã¹ããŒãïŒ
/certificate export-certificate test-CA export-passphrase=""
泚ïŒèšŒææžèªäœãå¿
èŠãªã ãã§ãç§å¯ããŒã¯å¿
èŠãªãããããã©ã¡ãŒã¿ãŒexport-passphrase = ""ã¯ç©ºã§ãªããã°ãªããŸããã
3.2ã é¡§å®¢èšŒææžã®ãšã¯ã¹ããŒãïŒ
/certificate export-certificate test-client-ovpn-1 export-passphrase=private-key-password1
/certificate export-certificate test-client-ovpn-2 export-passphrase=private-key-password2
泚ïŒexport-passphrase =-ç§å¯éµããšã¯ã¹ããŒãããããã®å¿
é ãã©ã¡ãŒã¿ãŒã åã¯ã©ã€ã¢ã³ãã«ãã¹ã¯ãŒãã䜿çšããŸãã 2.4é
ã§ãŠãŒã¶ãŒã«æå®ãããã®ãšåããã¹ã¯ãŒãã䜿çšããªãã§ãã ããïŒ
3.3ã åãåã£ãèšŒææžãšããŒãã¡ã€ã«ã䟿å©ãªæ¹æ³ã§MikrotikããæœåºããŸãïŒååãšããŠãwinboxããçŽæ¥ãã¡ã€ã«ãååŸã«ãã©ãã°ããŸãïŒã
Windowsã¯ã©ã€ã¢ã³ãã®ã»ããã¢ãã
1. openvpn.netãã
OVPNãã£ã¹ããªãã¥ãŒã·ã§ã³ã
ååŸããŸãã
2.æ§æã¢ãŒãã«å¿
èŠãªã¿ããã€ã³ã¿ãŒãã§ã€ã¹ãå«ãããã¹ãŠã®ãªãã·ã§ã³ãããã©ã«ãã§ã€ã³ã¹ããŒã«ããŸãã
3. OpenVPN \ configïŒããã©ã«ãã§ã¯CïŒ\ Program Files \ OpenVPN \ configïŒã«ç§»åããããã«client.ovpnãã¡ã€ã«ãäœæããŸãïŒãŸãã¯OpenVPN \ sample-configããã³ããŒããŸãïŒã
4.ã¯ã©ã€ã¢ã³ãæ§æãäœæããããsample-configã§å€æŽãå ããŸãã
client.ovpnã®å
容ãšå°ããªã³ã¡ã³ãïŒOVPNãµãŒãã¹ãæ©èœããã¢ãŒã
client
ïŒæ³šæïŒ 2ã€ã®ãã©ã¡ãŒã¿ãŒã1ã€ã ãæå®ããŸã
ïŒtupã¢ãŒãã®å Žåããã©ã¡ãŒã¿ãŒãæå®ããŸã
dev tun
ïŒã¿ããã¢ãŒãã®å Žåããã©ã¡ãŒã¿ãŒãæå®ããŸã
dev tap
ïŒãã®ãã©ã¡ãŒã¿ãŒã¯ãã¿ããã¢ãŒãã䜿çšãããå Žåã«ã®ã¿æå®ãããMyTapã®ä»£ããã«ãWindowsã®ã¿ããã€ã³ã¿ãŒãã§ã€ã¹åïŒipconfig / allããŸãã¯ã³ã³ãããŒã«ããã«ã®ãããã¯ãŒã¯æ¥ç¶ïŒã«çœ®ãæããããŸãã
dev-node MyTap
ïŒäœ¿çšããããããã³ã«ã ROS OVPNãµãŒããŒã¯TCPã¢ãŒãã§ã®ã¿åäœããŸã
proto tcp
ïŒæ¥ç¶ãããµãŒããŒã®ã¢ãã¬ã¹ãšããŒãã ovpn.my.domainã®ä»£ããã«-DNSåãŸãã¯IPã¢ãã¬ã¹ã è€æ°ã®ãµãŒããŒãæå®ã§ããŸãã
remote ovpn.my.domain 1194
;remote my-server-2 1194
ïŒãã®ãã©ã¡ãŒã¿ãŒã¯ãè€æ°ã®ãµãŒããŒã䜿çšãããŠããå Žåã«ã®ã¿å¿
èŠã§ãã æ¥ç¶äžã«ãã®ãã©ã¡ãŒã¿ãŒãæå®ãããšãã¯ã©ã€ã¢ã³ãã¯æå®ããããµãŒããŒã®1ã€ãã©ã³ãã ã«éžæããŸã
;remote-random
ïŒæå®ãããDNSãµãŒããŒåããIPã¢ãã¬ã¹ã決å®ãã詊è¡éã®ã¿ã€ã ã¢ãŠãïŒç§åäœïŒïŒãŸãã¯ç¡é-ç¡éïŒ
resolv-retry infinite
ïŒãã®ãã©ã¡ãŒã¿ãŒãæå®ãããŠããå Žåãã¯ã©ã€ã¢ã³ãã¯åçãªçºä¿¡ããŒãã䜿çšããŠæ¥ç¶ããŸã
nobind
ïŒã¯ã©ã€ã¢ã³ããåæ¥ç¶æã«ãã³ãã«èšå®ãä¿åã§ããããã«ãããšãšãã«ãããŒãã¡ã€ã«ãåèªã¿åãããªãããã«ãã
persist-key
persist-tun
ïŒãããã·èšå®
;http-proxy-retry # retry on connection failures
;http-proxy [proxy server] [proxy port #]
ïŒéè€ãã±ããã¡ãã»ãŒãžãç¡å¹ã«ããŸã
;mute-replay-warnings
ïŒèšŒææžãã¡ã€ã«ãžã®ãã¹
ïŒca-ã¯ã©ã€ã¢ã³ãèšŒææžãšãµãŒããŒèšŒææžãçºè¡ããCAèšŒææž
ïŒcert-ã¯ã©ã€ã¢ã³ãèšŒææž
ïŒkey-ã¯ã©ã€ã¢ã³ãèšŒææžã®ç§å¯éµ
ca cert_export_test-CA.crt
cert cert_export_test-client-ovpn-1.crt
key cert_export_test-client-ovpn-1.key
ïŒauth-user-passã¯ãã¯ã©ã€ã¢ã³ãã«èªèšŒã«ãŠãŒã¶ãŒåãšãã¹ã¯ãŒãã䜿çšããããã«æç€ºããŸãïŒãã ããèšŒææžã®ä»£ããã§ã¯ãªããèšŒææžã䜿çšããŸãïŒ
ïŒauth-user-passã¯ãOVPNã¯ã©ã€ã¢ã³ãã«ãŠãŒã¶ãŒåãšãã¹ã¯ãŒãã䜿çšããããã«æç€ºããŸãïŒãã ããèšŒææžã®ä»£ããã§ã¯ãªããèšŒææžã䜿çšããŸãïŒ
ïŒuser-pwd.txtã¯ããã°ã€ã³ãšãã¹ã¯ãŒããä¿åãããŠãããã¡ã€ã«ãæããŸãã ãã¡ã€ã«ã®æåã®è¡ã¯ãã°ã€ã³ã2çªç®ã®è¡ã¯ãã¹ã¯ãŒãã§ãã ãã®åŒæ°ããªãå Žåãæ¥ç¶ãããã³ã«ãŠãŒã¶ãŒåãšãã¹ã¯ãŒããèŠæ±ãããŸã
ïŒæ³šïŒæ¥ç¶ãããã³ã«ãã§ã«ããŒãå
¥åããå¿
èŠãããç§å¯ããŒãæã€èšŒææžã䜿çšããå ŽåããŠãŒã¶ãŒã«ãã¹ã¯ãŒãã«ãããã°ã€ã³ãèšæ¶ãããå¿
èŠã¯ãªããšèããŸã
--auth-user-pass user-pwd.txt
ïŒæ£ããããŒäœ¿çšæ³ã«ã€ããŠãµãŒããŒèšŒææžããã§ãã¯ããå¿
èŠãããããšãã¯ã©ã€ã¢ã³ãã«äŒããŸã
remote-cert-tls server
ïŒèªèšŒããã»ã¹ïŒãã³ãã·ã§ã€ã¯ïŒã®éå§ãæå·åããããŒã远å ã®ã»ãã¥ãªãã£å¯Ÿçã èšŒææžãªãã§ãã°ã€ã³/ãã¹ã¯ãŒãã®ã¿ã䜿çšããå Žåã«æå³ããããŸãã
;tls-auth ta.key 1
ïŒç¹å¥ãªæå·åæ¹åŒã®èšå®ãããã©ã«ãã§ã¯blowfish128ã䜿çšãããŸãã
;cipher x
ïŒlzoå§çž®ã䜿çšããŸãã ROSäžã®OVPNã¯ãµããŒããããŠããŸããã
;comp-lzo
ïŒãã°ã¬ãã«ã å€ã倧ããã»ã©è©³çްã«ãªããŸãã
verb 3
ïŒéè€ãããã°ã¡ãã»ãŒãžã®ãããã¯
;mute 20
ïŒäžèšã®ãã©ã¡ãŒã¿ãŒã«ã¯ãã¯ã©ã€ã¢ã³ãã®æ§æã®ããã€ãã£ããäŸã«ååšãããã©ã¡ãŒã¿ãŒ+ 1ãã©ã¡ãŒã¿ãŒãå¿
èŠã§ã
ïŒä»¥äžã«ãç§ã®æèŠã§ã¯ãããã«æçšãªãã©ã¡ãŒã¿ãŒã瀺ããŸãã
ïŒæ¥ç¶éå§æã«èšå®ãããã«ãŒã
ïŒã«ãŒãã¯ã²ãŒããŠã§ã€ã瀺ãã®ã§ã¯ãªããæ¥ç¶ãçŽæ¥ç€ºã
route 192.168.88.0 255.255.255.0
ïŒæ¥ç¶ã確ç«ããåŸãã«ãŒããèšå®ããåã«äžæåæ¢ããŸãïŒç§åäœïŒ
route-delay 5
ïŒOVPNæ¥ç¶ãã¡ã€ã³ã²ãŒããŠã§ã€ãšããŠèšå®ããå Žå
route-gateway 192.168.100.1
redirect-gateway def1 //
route-gateway 192.168.100.1
redirect-gateway def1 //
. , .
route-gateway 192.168.100.1
redirect-gateway def1 //
@bibliary . , .
route-gateway 192.168.100.1
redirect-gateway def1 //
. , .
. , .
æ³šïŒæ§æã§æå®ãããã«ãŒãã£ã³ã°ãã©ã¡ãŒã¿ãŒã䜿çšããã«ã¯ãOVPNãµãŒãã¹èªäœããŸãã¯OVPN GUIã管çè
æš©éã§éå§ããå¿
èŠããããŸãã
泚ïŒã»ãšãã©ã®ãã©ã¡ãŒã¿ãŒã®ãªã¹ãã¯
ããã«ãã
ãŸãããããæä»£é
ãã§ãã
MikroTikã¯ã©ã€ã¢ã³ããæ§æãã
1èšŒææžã®ã€ã³ããŒã
1.1 microtic CAèšŒææžãã¡ã€ã«ãšèšŒææžãã¡ã€ã«ãšã¯ã©ã€ã¢ã³ãããŒãã¡ã€ã«ã䟿å©ãªæ¹æ³ã§é
眮ããŸã
1.2 CAèšŒææžã®ã€ã³ããŒã
/certificate import file-name=cert_export_test-CA.crt passphrase=""
1.3èšŒææžãšã¯ã©ã€ã¢ã³ãããŒãã€ã³ããŒããã
/certificate import file-name=cert_export_test-client-ovpn-1.crt passphrase=""
/certificate import file-name=cert_export_test-client-ovpn-1.key passphrase=private-key-password1
2.ã¯ã©ã€ã¢ã³ããæ§æããŸã
/interface ovpn-client add name=OVPN_client connect-to={ovpn.my.domain|xxx.xxx.xxx.xxx} port=1194 mode={ip|ethernet} user=test-user-1 password=P@ssword1 profile=default certificate=cert_32 auth=sha1 cipher=blowfish128 add-default-route={no|yes} disabled=no
以åã®èšå®ãšããŒãºã«åŸã£ãŠã{}ã®å€ãæå®ããŸãã
å®éšã«ã¯ã次ã®ããŒããŠã§ã¢ãšãœãããŠã§ã¢ã䜿çšãããŸãããRouterOS 6.32.2ãæèŒããRouterBoard 2011UiAS-2HnD-2åã1ã€ã¯ãµãŒããŒãšããŠããã1ã€ã¯ã¯ã©ã€ã¢ã³ããšããŠã ã©ã¡ããå¢çã²ãŒããŠã§ã€ãšããŠæ©èœããŸã-èªå®
ã§ãè·å Žã§ãã
ãããã«Windows 10 Pro x64ãæèŒããã©ããããã-1å°ãã¯ã©ã€ã¢ã³ããšããŠã ä»äºãšç 究宀ãšããŠã®åœ¹å²ãæãããŸãã
次ã®ãªãœãŒã¹ãèªç¥ã«äœ¿çšãããŸããã ãæž
èŽããããšãããããŸããã