ãã®èšäºã§ã¯ãã¢ãã€ã«ããã€ã¹ãPCããŸãã¯ã©ããããããæ¥ç¶ã§ããTorãVPNãé£èªåãåããããŒã¿ãã«ãœãªã¥ãŒã·ã§ã³ãååŸããããã®ãªãã·ã§ã³ã®1ã€ã«ã€ããŠèª¬æããŸãã
åé¡ã¹ããŒãã¡ã³ã ïŒã©ããããã/ PC /ã¢ãã€ã«ããã€ã¹ã«æ¥ç¶ã§ããã·ã³ã°ã«ããŒãã³ã³ãã¥ãŒã¿ãŒãååŸããæåã«VPNã§ãã©ãã£ãã¯ãã©ãããã次ã«Torã§obfs-proxyã䜿çšããŠé£èªåãããªã¢ãŒãVPNãµãŒããŒã«éä¿¡ããŸãã
ãœãŒã¹ããŒã¿ïŒ1ïŒã·ã³ã°ã«ããŒãã³ã³ãã¥ãŒã¿ãŒã ç§ã®å Žåãããã¯Raspberry Piã¢ãã«B +ã§ãã
2ïŒRaspbian OSã ãã®èšäºã§ã¯ãRaspbian Jessieã䜿çšãã2016幎3æ18æ¥ãããã«ãããŸããã
3ïŒã¡ã¢ãªã«ãŒãïŒMicro SDïŒ;
4ïŒã«ãŒããªãŒããŒ;
5ïŒUSBã¢ããã¿ãŒãžã®ã¯ã€ã€ã¬ã¹ã¢ããã¿ãŒãŸãã¯ã€ãŒãµãããã
6ïŒãªã¢ãŒãOpenVPNãµãŒããŒã
é
ç·å³ïŒ1ïŒeth-eth
2ïŒwlan-eth
3ïŒwlan-wlan
4ïŒeth-wlan
æå®ïŒ1. SBC-ã·ã³ã°ã«ããŒãã³ã³ãã¥ãŒã¿ãŒã
2. CR-ã€ã³ã¿ãŒãããã¢ã¯ã»ã¹ãæäŸãããããã€ã¹ã ããã€ã¹ã¯å¿
ãããSBCããŒãã«çŽæ¥æ¥ç¶ããããšã¯éããŸããã
3. PC-SBCã«æ¥ç¶ãããŠããã³ã³ãã¥ãŒã¿ãŒïŒãŸãã¯ã¢ãã€ã«ããã€ã¹ïŒã
4. VPNãµãŒããŒ-ã¿ãŒã²ããVPNãµãŒããŒã
5.å
¥åã€ã³ã¿ãŒãã§ã€ã¹-ã¯ã©ã€ã¢ã³ããã©ãã£ãã¯ãå
¥ãç©çã€ã³ã¿ãŒãã§ã€ã¹ã
6.åºåã€ã³ã¿ãŒãã§ã€ã¹-ãã©ãã£ãã¯ãã€ã³ã¿ãŒãããã«éä¿¡ãããç©çã€ã³ã¿ãŒãã§ã€ã¹ã
ä»®å®ïŒãã®èšäºã§ã¯ãã€ã³ã¿ãŒããããžã®ãªã³ã¯ã®ãã©ã¡ãŒã¿ãŒãDHCPçµç±ã§éä¿¡ãããããéçã«èšå®ãããå Žåã«ã€ããŠèª¬æããŸãã L2TPãPPPoEããŸãã¯ãã®ä»ã®ç¶æ³ã§ãªã³ã¯ã®ãã©ã¡ãŒã¿ãŒãååŸããå Žåãèšå®ã¯ç°ãªããŸãã ãŸãã䟿å©ãªæäœã®ããã«ãVPNãµãŒããŒã¯DNSãªã¬ãŒãšããŠæ©èœãããšæ³å®ããŠããŸãã
ã·ã¹ãã ã®ã€ã³ã¹ããŒã«ãšæ¥ç¶
Rasbianã®å
¬åŒWeb
ãµã€ãã«ã¯ãLinuxãMac OSãããã³Windowsçšã®ã€ã¡ãŒãžãèšé²ããããã®éåžžã«è©³çŽ°ãªæé ãå«ãŸããŠãããããèšäºãç
©éã«ããªãããã«ãOSã€ã¡ãŒãžãã¡ã¢ãªã«ãŒãã«èšé²ããããã»ã¹ã«ã€ããŠã¯èª¬æããŸããã ç§ã®èŠ³å¯ãããå°æ¥ã®ã¡ã¢ãªäžè¶³ã®åé¡ãåé¿ããããã«ã16 GBã®ã«ãŒãã䜿çšããããšããå§ãããŸãã
ç»åãèšé²ããŠãªã³ã«ããåŸãããŒãã«æ¥ç¶ããåŸãããã€ãã®ãªãã·ã§ã³ããããŸãã
1ïŒhdmiããµããŒãããç¹å¥ãªç»é¢/ã¢ãã¿ãŒ/ãã¬ããããå Žåã¯ããããhdmiçµç±ã§æ¥ç¶ããŸãã
2ïŒç»é¢ã¯è¡šç€ºãããªããããã©ã¡ãŒã¿ãDHCPãä»ããŠç©çã€ã³ã¿ãŒãã§ã€ã¹ã«å±ãå Žåã¯ãå¥ã®ã³ã³ãã¥ãŒã¿ãŒããnmapãããã¯ãŒã¯ãã¹ãã£ã³ããŠãsshã§æ¥ç¶ã§ããŸãã ãŠãŒã¶ãŒpiããã¹ã¯ãŒãraspberryã
3ïŒDHCPããªãå Žåã¯ããã¡ã€ã«/ etc / network / interfacesãç·šéããŠãããã«ã¢ãã¬ã¹ãæåã§å
¥åã§ããŸãã
ãã©ãã£ãã¯è»¢é
ããã€ã³ã¿ãŒãã§ã€ã¹ããå¥ã®ã€ã³ã¿ãŒãã§ã€ã¹ã«ãã©ãã£ãã¯ã転éããã«ã¯ã察å¿ããLinuxã«ãŒãã«ãã©ã¡ãŒã¿ãŒãæå¹ã«ããå¿
èŠããããŸãã ããã¯ã次ã®ã³ãã³ãã䜿çšããŠå®è¡ã§ããŸãã
sysctl -w net.ipv4.ip_forward=1
ãŸãã¯
echo 1 > /proc/sys/net/ipv4/ip_forward
確èªããã«ã¯ã次ã®ã³ãã³ãã䜿çšã§ããŸãã
cat /proc/sys/net/ipv4/ip_forward
圌女ã¯ã1ããè¿ããªããã°ãªããŸããã
iptables
ãã©ãã£ãã¯ã®ã«ãŒãã£ã³ã°ãç°¡çŽ åããã«ã¯ãiptablesã䜿çšããŠãã³ãã«ã€ã³ã¿ãŒãã§ã€ã¹ã®ãã¹ãã³ã°ãæå¹ã«ããŸãã
iptables -t nat -A POSTROUTING -s 10.5.5.0/24 -o tun0 -j MASQUERADE
代ããã«ãã¯ã©ã€ã¢ã³ãã®éçã«ãŒããšéçã¢ãã¬ã¹ãäœæã§ããŸãã ãŸãã¯ãccdã䜿çšããŸãã
ããã±ãŒãžã®ã€ã³ã¹ããŒã«
ãªããžããªãæŽæ°ããŠæŽæ°ãååŸããŸãã
sudo apt-get update sudo apt-get upgrade
ãªããžããªããã®ã€ã³ã¹ããŒã«ïŒ
sudo apt-get install python2.7 python-pip python-dev build-essential tor openvpn obfs-proxy
ã¢ã¯ã»ã¹ãã€ã³ãã䜿çšããã¹ããŒã ãå¿
èŠãªå Žåã¯ãããã«hostapdãšDHCPãµãŒããŒãã€ã³ã¹ããŒã«ããŸãã
sudo apt-get install hostapd isc-dhcp-server
isc-dhcp-serverã®ä»£ããã«ãä»ã®ãã®ã䜿çšããããšãã§ããŸãã ãªããžããªã«ã¯ææ°ããŒãžã§ã³ãå«ãŸããŠããªãããšãå€ãããããœãŒã¹ããããã±ãŒãžãã³ã³ãã€ã«ã§ããŸãããè¿
éãªè§£æ±ºçãå¿
èŠãªå Žåã¯ããªããžããªããã®ã€ã³ã¹ããŒã«ãé©ããŠããŸãã
ãããã¯ãŒã¯æ¥ç¶ã®ã»ããã¢ãã
eth-ethãµãŒããããã®ãªãã·ã§ã³ã¯æãç°¡åã§ãã PCãæ¥ç¶ããRaspberry Piã®ç©çã€ã³ã¿ãŒãã§ã€ã¹ã§ã¯ãéçã¢ãã¬ã¹ãèšå®ããã ãã§ååã§ãã PCã§ãããã©ã¡ãŒã¿ãæåã§èšå®ããŸãã ãã©ã¡ãŒã¿ãè¿ãããã«isc-dhcp-serverãæ§æããããšãã§ããŸãã Linuxã®ã¯ã©ã€ã¢ã³ããã·ã³ã§ã¯ãåæèšå®ã®ããã«æ¬¡ã®ã³ãã³ããå®è¡ããã ãã§ååã§ãã
ip a add 10.5.5.2/24 dev <> ip route add default gw 10.5.5.1
ãŸãããã¡ã€ã«/etc/resolv.confã«ãšã³ããªãè¿œå ããŸãã
nameserver 10.8.0.1
Wlan-ethãµãŒããããã®ã¹ããŒã ã§ã¯ãå
¥åã€ã³ã¿ãŒãã§ã€ã¹ã¯ã¢ã¯ã»ã¹ãã€ã³ããšããŠåäœããã¯ã€ã€ã¬ã¹ã€ã³ã¿ãŒãã§ã€ã¹ã«ãªããŸãã å®å
šãªã¢ã¯ã»ã¹ãã€ã³ãã¢ãŒãã®ä»£ããã«ãã¢ãããã¯ã¢ãŒããèšå®ã§ããŸãã
DHCPã䜿çšããŠwi-fiã¢ã¯ã»ã¹ãã€ã³ããæŽçããã«ã¯ãhostapdãšisc-dhcp-serverã®æã䜿çšããŸãããããã®ç¹å®ã®æã䜿çšããå¿
èŠã¯ãããŸããã habrã«ã¯ãLinuxã®ããŸããŸãªãªãã·ã§ã³ã®ã»ããã¢ããã«é¢ããéåžžã«è©³çŽ°ãªèšäºããããŸãã ãœãŒã¹ã®ãªã³ã¯ãåŒçšããŸããã
ç§ã®èšå®ã®äŸãæããŸãïŒ
/etc/hostapd/hostapd.conf ãã©ã€ããŒãã¢ã¯ã»ã¹ãã€ã³ãã¢ãŒãã§ã®ã¯ã€ã€ã¬ã¹ã«ãŒãã®åäœã«åé¡ãããå¯èœæ§ãããããšãããã«èšåãã䟡å€ããããŸãã äºåã«ãã®ãããªããšã«ã€ããŠå°ããããšããå§ãããŸãã ãªããžããªããhostapdãæäœãããšããã«ãŒãã®1ã€ã§ãã®ãããªåé¡ãçºçããŸããã ãã®åé¡ã¯ãhostapdãããã«ãã£ãŠè§£æ±ºãããŸããã
WLAN-WLANã¹ããŒãå
¥åã€ã³ã¿ãŒãã§ã€ã¹ãæ§æããéšåã¯ã以åã®ã¹ããŒã ãšå€ãããŸããã åºåã€ã³ã¿ãŒãã§ã€ã¹ã¯ã¢ã¯ã»ã¹ãã€ã³ãã«æ¥ç¶ããå¿
èŠããããŸãã nmcliãŠãŒãã£ãªãã£ã䜿çšããæ¥ç¶äŸïŒ
nmcli d wifi connect <SSID > password <> iface <>
eth-wlanã¹ããŒãå
¥åã€ã³ã¿ãŒãã§ã€ã¹ã¯eth-ethã¹ããŒã ã®ããã«æ§æãããåºåã€ã³ã¿ãŒãã§ã€ã¹ã¯wlan-wlanã®ããã«æ§æãããŸãã
Tor + obfsproxy
Torãã©ãã£ãã¯ããã¹ã¯ããã«ã¯ã
obfsproxyã䜿çšã
ãŸã ã
Torã®ã»ããã¢ããã®äŸã次ã«ç€ºããŸãã
/ etc / tor / torrc SocksPort 9050 RunAsDaemon 1 VirtualAddrNetwork 172.16.0.0/12 DNSPort 53 DNSListenAddress 127.0.0.1 AutomapHostsOnResolve 1 BridgeRelay 1 Exitpolicy reject *:* ServerTransportPlugin obfs3 exec /usr/bin/obfsproxy managed obfs3 <1:1> <1> obfs3 <2:2> <2> obfs3 <3:3> <3>
obfsproxyãµãŒããŒã«æ¥ç¶ããããã®ããŒã¿ã¯ã
ããã«ãããŸã ã
Openvpn
VPNãç·šæããã«ã¯ãOpenVPN over TCPããã³L3ã¢ãŒãïŒã¿ããã€ã³ã¿ãŒãã§ã€ã¹ïŒã䜿çšããŸãã TorãTCPãã©ãã£ãã¯ã§ã®ã¿æ©èœãããããTCPã«ãã£ãŠäœ¿çšãããŸãã VPNãã³ãã«èªäœãžã®ãã©ãã£ãã¯ãèš±å¯ã§ããŸãã VPNãã©ãã£ãã¯ãTorã«è»¢éããããã«ãTorãä»ããŠãã¹ãŠã®VPNãã©ãã£ãã¯ãããããã·ãããŸãã OpenVPNã¯ãã®æ©èœããµããŒãããŠããŸãã
OpenVPNã®ã¯ã©ã€ã¢ã³ãåŽã®ã»ããã¢ããäŸãã詳现ãªã³ã¡ã³ããšãšãã«ç€ºããŸãã
ã€ã³ã¿ãŒãããã«ã¯ããµãŒããŒãã»ããã¢ããããããã®éåžžã«å€ãã®æ瀺ããããŸãã èšäºã®æåŸã«ããããœãŒã¹ãã®ãªã³ã¯ãåŒçšããŸããã æ§æã®éµã¯ããã©ã¡ãŒã¿ãŒã®äžèŽãšããµãŒããŒæ§æå
ã®ããã·ã¥ãredirect-gateway defãè¡ã®ååšã§ãã ã¯ã©ã€ã¢ã³ãã¯ãVPNãµãŒããŒãæããã©ãã£ãã¯ã®ããã©ã«ãã«ãŒãã確ç«ããå¿
èŠããããŸãã
ãã¹ãäž
æ£ããåäœããã¹ãããã«ã¯ãæ¥ç¶ãããPCããVPNãµãŒããŒã®tunã€ã³ã¿ãŒãã§ãŒã¹ã«pingããŸããtcpdumpã䜿çšããŠãã©ãã£ãã¯ãåé€ããããããããããããã«Wiresharkã§åæããŸãã
1ïŒICMPèŠæ±ãRaspberry Piå
¥åã€ã³ã¿ãŒãã§ã€ã¹ã«å°çããŸãã
èå¥åBEãLEãããã³ã¿ã€ã ã¹ã¿ã³ãã«æ³šæãã䟡å€ããããŸãã ããã«ããµãŒããŒåŽã®ICMPèŠæ±ãèå¥ããããã«å¿
èŠã«ãªããŸãã
2ïŒICMPãã±ããã¯OpenVPNã®åŠçæé ãçµãŠãããŒã9050ã«åããããTorããªãã¹ã³ããŸãã ã¹ãããã·ã§ãããã©ãã£ãã¯ã¯ãRaspberry Piã®ã«ãŒãããã¯ã€ã³ã¿ãŒãã§ã€ã¹ã§çºçããŸãã
3ïŒããã±ãŒãžã¯Raspberry Piãé¢ããobfsproxyãµãŒããŒéšåã䜿çšããŠTorãããã¯ãŒã¯ããŒãã®1ã€ã«éä¿¡ãããŸãã
4ïŒãããŠããã©ãã£ãã¯ã®ã¹ãããã·ã§ããã¯ãã§ã«VPNãµãŒããŒã®ãã³ãã«ã€ã³ã¿ãŒãã§ã€ã¹äžã«ãããŸãã ãµãŒããŒãå¿çãéä¿¡ããããšãããã«ããããŸãã
èå¥åBEãLEãããã³ã¿ã€ã ã¹ã¿ã³ãã¯ãéä¿¡ããããã±ããã®ãã®ãšåãã§ãã
5ïŒãã®ã¹ã¯ãªãŒã³ã·ã§ããã¯ãICMPå¿çãå«ãVPNãµãŒããŒããã®ãã±ããã瀺ããŠããŸãã
ãŸãããµãŒããŒãžã®TCPããã³UDPãã©ãã£ãã¯ã«iperfã䜿çšããŠããã®ãœãªã¥ãŒã·ã§ã³ã®åž¯åå¹
ããã¹ãããŸããã ãã¹ãã¯ãããŒã ãããã¯ãŒã¯äžã®Raspberry Piã¢ãã«B +ãšRaspbian OSã䜿çšããŠå®è¡ããããããç°ãªãOSãŸãã¯ç°ãªããããã¯ãŒã¯ç°å¢ãæã€ä»ã®ã·ã³ã°ã«ããŒãã³ã³ãã¥ãŒã¿ãŒã®æ°ã¯ç°ãªãå ŽåããããŸãã
çµæïŒ
-Tor + VPN + obfsproxyãã³ãã«
-VPNã®ã¿
-ããããªãã£ã³ãã«
ãããã«
æœåšçãªèœãšãç©ŽïŒ
1ïŒæéã®åæã torã¯ã¿ã€ã ã¹ã¿ã³ãããã§ãã¯ããŠæå·åæäœãå®è¡ãããããæå»ãåæããå¿
èŠããããŸãã æ®å¿µãªãããããŒãã®é»æºãåã£ãåŸã¯æ¯åæå»ãåæããå¿
èŠããããŸãã
2ïŒmtuãµã€ãºã éä¿¡ããããã±ããã®DFãããã«ããããã¹ã®ã©ããã§ãã±ããã®æçåãçŠæ¢ãããmtuå€ãèªåã®ãã®ãããå°ããå Žåããã©ãã£ãã¯ããã«ããããããããšããããŸãã
3ïŒVPN throught Torãšobfsproxyã®äœ¿çšã¯ããã¹ãŠã®äžèœè¬ã§ã¯ãããŸããã
ä»ã®åé¡ãèŠã€ããããŸãã¯æ¢ã«çºçããŠããå Žåã¯ãã³ã¡ã³ããèšå
¥ããŠãã ãã-èšäºã«è¿œå ããŸãã
ãœãŒã¹
1.
habrahabr.ru/post/89420ãhabrahabr.ru / post /
188274 -AP Linux
2.
habrahabr.ru/post/88281-Linuxã§ã®ã¢ãããã¯
3.
www.torproject.org -Torãããžã§ã¯ãã®å
¬åŒãµã€ãã
4.
openvpn.net/index.php/open-source/documentation/manuals.htmlãhelp.ubuntu.ru / wiki /
openvpn -OpenVPNã®ã»ããã¢ããã