ãããã¯ãŒã¯äžã«ã¯ãAmazon AWSã¯ã©ãŠãã§VPNãµãŒããŒãäžããæ¹æ³ãå€æ°ãããŸãããUnixã®ãããªã·ã¹ãã åãã§ãããWindowsã§äžããæ¹æ³ã¯ãŸã£ããèæ
®ãããŠããŸããã
ããã¥ã¢ã«ãèŠã€ãããªãã£ãã®ã§ãèªåã§ãããææ¡ããWindows Server + OpenVPN + Android OpenVPN Clientã«åºã¥ããAmazon EC2ãäœæãããã£ãã®ã§ãã
è¡ããïŒ
ãã®èšäºã¯åå¿è
åãã§ã¯ãªããããäžè¬çãªè³ªåãããã€ããããŸããã
Amazon AWSã§ã®ç»é²ããã»ã¹ã«ã€ããŠã¯èª¬æããŸãã-ç°¡åã§ãã ç§ã¯åã«ç»é²ããªãã£ãã®ã§ãé»è©±çªå·ã«ç¢ºèªãæ¥ãããšã«é©ããã å€åçªå·ãæžããŸãã ç»é²åŸã
ããã·ã¥ããŒã https://console.aws.amazon.com/console/homeã«ã¢ã¯ã»ã¹ããŸãã¡ãã¥ãŒ
ãµãŒãã¹ â
èšç® â
EC2 â
ã€ã³ã¹ã¿ã³ã¹ãèžã¿ãŸãã [
Launch Instance]ãã¯ãªãã¯ããŠã
ãŠã£ã¶ãŒããéããŸãã 䜿çšå¯èœãªAMIã®ãªã¹ãã§ã
Microsoft Windows Server 2008 R2 Base-ami-59fc7439ãéžæã
ãŸã2çªç®ã®ã¹ãããã§ã¯ãå©çšå¯èœãªãªãã·ã§ã³
t2.microïŒç¡æå©çšæ ïŒãéžæããŸã-ãã®æ©èœã¯ç§ãã¡ã«ãšã£ãŠåå以äžã®ãã®ã§ãã [
èµ·å ]ãã¯ãªãã¯ããã®ã¯æ¥ãã§ã¯ããŸããã[
次ãžïŒã€ã³ã¹ã¿ã³ã¹ã®è©³çŽ°ãæ§æãã]ãã¯ãªãã¯ããŸãïŒããã©ã«ãã§VPCãæ§æããããã©ã«ãã®ãµããããããããKeyPairsãäœæãããŠãããšä»®å®ã
ãŸã ãã¡ãªã¿ã«ãVPCããŒãããåæ§ç¯ãã1ã€ã®ãããã¯ãŒã¯ã®ã¿ãæ®ããŸãã10.100.11.0/24ïŒã
ããã©ã«ãã§ã¯èšå®ã¯ãã®ãŸãŸã§ããã[
ãããªãã¯IPã®èªåå²ãåœãŠ]ã[ æå¹]ã«èšå®ããŸãã 次ã«ã
ãã¬ãã¥ãŒãšèµ·åãã¯ãªãã¯ããŸã
ã ã€ã³ã¹ã¿ã³ã¹ãäœæããããŸã§æ°ååŸ
ã¡ãŸãã
å·ŠåŽã®
ããã·ã¥ããŒãã§ã[
ãããã¯ãŒã¯ãšã»ãã¥ãªãã£] â[
ã»ãã¥ãªãã£ã°ã«ãŒã]ã»ã¯ã·ã§ã³ãéžæããŸãã ã€ã³ã¹ã¿ã³ã¹ã«é¢é£ä»ããããŠããã°ã«ãŒããéžæããŸãã 以äžã®[
åä¿¡]ã[éä¿¡]ã¿ãã§
㯠ããã¹ãŠã®ãã©ãã£ãã¯ïŒalltraffïŒãééãããèš±å¯ãäžæç
ã«è¿œå ããŸãã
çŸåšãRDPã®ã¿ãèš±å¯ãããŠããŸãã æ¥ãã§ãã人ã¯ãäž¡æ¹ã®ã¿ãã§OpenVPNãšICMPã®ããŒã1194ãæå¹ã«ããããšãã§ããŸãã ã€ã³ã¹ã¿ã³ã¹ãäœæãããŠæ©èœããã®ã§ãæ¥ç¶ããå¿
èŠããããŸãã ã€ã³ã¹ã¿ã³ã¹ãéžæãã[
æ¥ç¶ ]ãã¯ãªãã¯ã
ãŸã ã
.rdpãã¡ã€ã«ãããŠã³ããŒãããŠãã¹ã¯ãŒããååŸããããæ±ãããŠã£ã³ããŠã衚瀺ãããŸãã ããŠã³ããŒãã [
ãã¹ã¯ãŒããååŸ]ãã¯ãªãã¯ããŠãããŒãã¡ã€ã«ãæå®ãã埩å·åããŠããã¹ã¯ãŒããååŸããŸãã ã±ãŒã¹ã®ååãå®äºããŸããã RDPãéãããã¹ãã«æ¥ç¶ããŸãã
ç§ãã¡ã®åã«çŽç²ãªOSããããŸãã 次ã«äœãå¿
èŠã§ããïŒ
1. Google ChromeãããŠã³ããŒãããŠããã§ãã¯ãç°¡åã«ããŸãã
2. OpenVPNãããŠã³ããŒãããŸãã
3.ããã©ã«ãæ§æã§ãµãŒããŒãäžããŸãã
4. NATãäžããŸãã
IEçµç±ã§ããŠã³ããŒãããå¿
èŠãããå Žåãé€ããæåã®2ã€ã®ãã€ã³ãã«åé¡ã¯ãããŸããã å
¬åŒWebãµã€ãïŒMSIïŒããOpenVPNãããŠã³ããŒãããããã©ã«ãèšå®ã§èšå®ããŸããäœãå€æŽããªãã§ãã ããã
Chromeãã
ipleak.netã«ã¢ã¯ã»ã¹ããŠãIPã確èªããŸãã 圌ã¯ç±³åœ/ãªã¬ãŽã³å·ã®ã©ããã«ããã§ãããã OpenVPNã®ãµãŒããŒèšŒææžãšã¯ã©ã€ã¢ã³ã蚌ææžã®äœææ¹æ³ã«ã€ããŠã¯èª¬æããŸããããã®ãããã¯ã«é¢ããè³æã¯ååã«ãããŸãã å¿
ãPAMãã¡ã€ã«ïŒDiffie-HellmanïŒãäœæããŠãã ãããäœæããªããšããµãŒããŒã¯èµ·åããŸããã
OKããã¹ãŠãããŠã³ããŒããããã€ã³ã¹ããŒã«ãããŸããã ãµãŒããŒã§
ãµãŒããŒãããŒãžã£ãŒãéãã[
ãµãŒãã¹]ã»ã¯ã·ã§ã³ã«ç§»åã
ãŸã ã
OpenVPN Legacy ServiceãèŠã€ãããã®ããããã£ãéããŸã-Startup typeïŒ
Automaticãæå®ããŠããµãŒãã¹ãéå§ããŸãã ããã¯ãã€ã³ã¹ã¿ã³ã¹ãåèµ·åããåŸã«OpenVPNãµãŒããŒãèªåçã«èµ·åããããã«å¿
èŠã§ãã
CïŒ\ Program Files \ OpenVPN \ configãéããŸã-CA.keyãserver.keyãta.keyãdh2048.pemã®ããŒãšãCAããã³ãµãŒããŒèšŒææžãããã«ããããããŸãã
CïŒ\ Program Files \ OpenVPN \ sample-configãéããããããserver.ovpnãã¡ã€ã«ã
CïŒ\ Program Files \ OpenVPN \ configã«ã³ããŒããŸãã
ãã®ãããªã³ã³ãã³ãã®æžãæãïŒ
ããŒã1194
ãããUDP
éçºè
ca ca.crt
cert server.crt
éµserver.key
dh dh2048.pem
ïŒVPNã®ä»®æ³ãããã¯ãŒã¯
ãµãŒããŒ172.10.10.0 255.255.255.0
ifconfig-pool-persist ipp.txt
ããŒãã¢ã©ã€ã10120
tls-auth ta.key 0ïŒãã®ãã¡ã€ã«ã¯ç§å¯ã§ã
æå·AES-256-CBC
æ倧ã¯ã©ã€ã¢ã³ãæ°100
æ°žç¶ããŒ
æç¶ãã
éçºããŒããHomeVPNã
#HomeVPNã¯ãOpenVPNã®ã€ã³ã¹ããŒã«ã«ãã£ãŠäœæãããTAPã§ãã 䟿å®äžååãå€æŽããŸãã
ïŒããã¯ããã¹ãŠã®ã¯ã©ã€ã¢ã³ããç¡çãªãã«ãŒãã£ã³ã°ã§ããããã«ããããã«å¿
èŠã§ãã
ãã«ãŒã0.0.0.0 0.0.0.0ããæŒããŸã
ïŒDNSãæå®ããŸãããããã¯å¿
é ã§ã¯ãããŸãã
push "dhcp-option DNS 8.8.8.8"
push "dhcp-option DNS 8.8.4.4"
åè©3
æ瀺ççµäºéç¥1
ä¿åããŸãã
ãµãŒããŒã®ã»ããã¢ãããå®äºããŸããã
server.ovpnãéžæ
ã ãã³ã³ããã¹ãã¡ãã¥ãŒãéãã
ãã®èšå®ãã¡ã€ã«ã§[OpenVPNãéå§ ]ãéžæã
ãŸã ã
ãã®åŸãã¿ãŒããã«ãéããããŠã³ããŒãããã»ã¹ãéå§ãããŸãã ãã¹ãŠãæ£ããè¡ããããšãæåŸã«
åæåã·ãŒã±ã³ã¹å®äºã衚瀺ãããŸãã
ããã§ãã¯ã©ã€ã¢ã³ãæ¥ç¶ã«åé¡ããªãããã«ã1ã€ã®ããšãéžæããå¿
èŠããããŸããWindowsãã¡ã€ã¢ãŠã©ãŒã«ã§ãOpenVPNãã©ãã£ãã¯ãééãããŠããŒã1194ãèš±å¯ããã«ãŒã«ãäœæãããããã¡ã€ã¢ãŠã©ãŒã«ããªãã«ããã ãã§ãã ç§ã¯
2çªç®ã®ã¢ã€ãã ãéžã³ãŸããã
ããã§ãã¯ã©ã€ã¢ã³ãæ§æãäœæããå¿
èŠããããŸãã ã¯ã©ã€ã¢ã³ãïŒAndroidïŒã«OpenVPN Clientãã€ã³ã¹ããŒã«ãããŠãããã¯ã©ã€ã¢ã³ããå«ããã¹ãŠã®å¿
èŠãªèšŒææžãšããŒãå©çšå¯èœã§ãããšæ³å®ãããŠããŸãã
ã¯ã©ã€ã¢ã³ãæ§æã¯æ¬¡ã®ãšããã§ãã
ã¯ã©ã€ã¢ã³ã
éçºè
ãããUDP
ãªã¢ãŒãxxx-xxx-xxx-xxx-xxx.us-west-2.compute.amazonaws.com 1194
ç¡éã®è§£æ±ºãšåè©Šè¡
ã«ãŒãã¡ãœããexe
ããã€ã³ã
æ°žç¶ããŒ
æç¶ãã
ca ca.crt
cert client.crt
ããŒclient.key
remote-cert-tlsãµãŒããŒ
tls-auth ta.key 1
æå·AES-256-CBC
auth SHA1
åè©3
ã«ãŒã0.0.0.0 0.0.0.0 vpn_gateway
AndroidåãOpenVPNã§ã¯ãèšå®ãã€ã³ããŒãããŸãã [
åºæ¬ ]ã¿ãã§ãèªèšŒã¿ã€ãã[
蚌ææž ]ã«èšå®ããŸãã åºæ¬çã«ãã¹ã¯ãŒãã¯ãããŸããã [
ãµãŒããŒãªã¹ã ]ã¿ãã確èªããŸããAmazonãµãŒããŒãæå®ããå¿
èŠããããŸãïŒããŒã1194ãã¿ã€ãUDPïŒã [
IPã¢ãã¬ã¹ãšDNS ]ã¿ãã§ã[
èŠæ±ãã©ã¡ãŒã¿ãŒ ]ãªãã·ã§ã³ãèšå®ããå¿
èŠããããŸãã
IPv4ã® [
ã«ãŒãã£ã³ã° ]ã¿ã
㧠ã[
ããã©ã«ãã«ãŒãã®
äœ¿çš ]ãªãã·ã§ã³ãæå¹ã«ããå¿
èŠããããŸãã
èšå®ãä¿åããŸãã
ãµãŒããŒã«æ¥ç¶ããããšããŠããŸãã æ¥ç¶ã確ç«ãããŠããªãå Žåã¯ã
ãããã¯ãŒã¯ãšã»ãã¥ãªã㣠â
ã»ãã¥ãªãã£ã°ã«ãŒããšãã¡ã€ã¢ãŠã©ãŒã«ã確èªããŠãã ããã ãã¹ãŠãæ£åžžã§ããã°ã
SUCCESSã衚瀺ãããIP VPNãããã¯ãŒã¯ã®ãããããåãåããŸãã ç§ã®å Žåãããã¯172.10.10.6/30ã§ãã
ã¯ã©ã€ã¢ã³ãäžã§ããã€ãã®ãµã€ããéãããšããŠããŸã...æ¥ç¶ãããããã§ããããµã€ãã¯éããŸããã
åé¡ã¯äœã§ããïŒ ãã€ã³ãã¯NATã§ãã
è¿œå ã®AMIãInternet GateãIP Elasticãããã³ãã®ä»ã®ã§ããããäœæããŠãAmazonã§NATãæ§æããæ¹æ³ã«é¢ãããããã¯ãŒã¯äžã®ããã¥ã¢ã«ããããŸãã ãããè¡ãå¿
èŠã¯ãããŸããã
ãã¹ãŠãã¯ããã«ç°¡åã§ãã
ãµãŒããŒã«æ»ãã
ãããã¯ãŒã¯ããªã¹ãšã¢ã¯ã»ã¹ãµãŒãã¹ã®åœ¹å²ãäœæã
ãŸã ã ããã«ã¯ã
ã«ãŒãã£ã³ã°ãšãªã¢ãŒãã¢ã¯ã»ã¹ã®åœ¹å²ãå«ãŸããŸãã ã³ã³ããã¹ãã¡ãã¥ãŒãéãã[
æ§æãšæå¹å ]ãéžæããŸãã
æåŸã®é
ç®ãéžæããŠãç¬èªã®æ§æãäœæããŸãã 次ã®ã¹ãããã§ãæåŸã®2ã€ã®é
ç®ã
NATããã³
LANã«ãŒãã£ã³ã°ãéžæã
ãŸã ã
ã«ãŒãã£ã³ã°ãšãªã¢ãŒãã¢ã¯ã»ã¹ â
IPv4 â
NATã®åœ¹å²ãæ¡åŒµããåŸã ã€ã³ã¿ãŒãã§ãŒã¹ãäœæããŸãïŒ
LAN1-ã€ã³ã¿ãŒãããäžã§èŠãããã®ã ããããã£ã§ã
ãããªãã¯ã€ã³ã¿ãŒãã§ã€ã¹ãèšå®ã
ããã®ã€ã³ã¿ãŒãã§ã€ã¹ã§NATã
æå¹ã«ããŸã ã [
ã¢ãã¬ã¹ããŒã« ]ã¿ããéããŸãã
è¿œå ãã¯ãªãã¯ããŸãã
ããã§ã¯ããããã¯ãŒã¯ã§ã¯ãªããã·ã³ã®IPã¢ãã¬ã¹ãã€ãŸããã·ã³ïŒipconfig / allïŒãè¿œå ããå¿
èŠããããŸã
ç§ã®ãããã¯ãŒã¯ã¯
10.100.11.0/24ãVPNãããã¯ãŒã¯ã¯
172.10.10.0/24 ããã·ã³ã®ã¢ãã¬ã¹ã¯
10.100.11.20ã§ãã 10.100.11.20
ãæå®ãã
éå§ã¢ãã¬ã¹ãšãæå®ãã
çµäºã¢ãã¬ã¹ ã ãã¹ã¯255.255.255.0
ä¿åããŸãã
åãã¢ãŒãã§ã[
ã¢ãã¬ã¹ã®
äºçŽ ]ãã¿ã³ãã¯ãªãã¯ããŸãã VPNã¯ã©ã€ã¢ã³ãã¢ãã¬ã¹ïŒæ¥ç¶æã¯172.10.10.6/30ã§ããïŒããã·ã³ã®ã¢ãã¬ã¹ãšãæ¥ç¶ãããå¿
èŠããããŸãã
è¿œå ãã¯ãªãã¯ããŸã
ãã®ãããªãã¯IPãäºçŽããŠ
10.100.11.20ã«èšå®ããäžã®åã«
172.10.10.6ãšèšè¿°ã
ãŸã[çä¿¡ãèš±å¯ãã]ãªãã·ã§ã³
ã¯èšå®ããŸãã ã
ä¿åããŸãã
ããã§æåŸã®ã¹ããããæ®ããŸã-NATã«ãã1ã€ã®ã€ã³ã¿ãŒãã§ãŒã¹ãTAPãè¿œå ããŸãã ç§ã¯ãããHomeVPNãšåŒã³ãŸããã èšå®ã¯ãããŸããããã©ã€ããŒãã€ã³ã¿ãŒãã§ã€ã¹ã§ãã NATã¯èšå®ããŸããã
ãããã£ãŠã
VPNããLANãžã® ã転éã
ãååŸãããŸããïŒ172.10.10.6â10.100.11.20 ã
ã¯ã©ã€ã¢ã³ãã«åæ¥ç¶ããVPNãç«ã¡äžããã®ãåŸ
ã£ãŠãipleak.netãéããŠç£èŠããŸãã
ã¯ã©ã€ã¢ã³ãã®IPã¢ãã¬ã¹ã¯
ç±³åœ/ãªã¬ãŽã³å·ã«ãããWebRTCã®IPã¢ãã¬ã¹ã¯VPNãµãŒããŒã®IPã¢ãã¬ã¹ã衚瀺ããå¿
èŠããããŸãã
172.10.10.6 ã
ãããããªããããªãã¯æåããŸããã ããã§ãªãå Žåã¯ãããã€ãã®ã¹ãããã§ééããç¯ããããæ¥ãã§ããŸãã
çµè«ãšããŠã
ããã·ã¥ããŒã â
ãããã¯ãŒã¯ãšã»ãã¥ãªã㣠âã»ãã¥ãªãã£ã°ã«ãŒãã»ã¯ã·ã§ã³ã«é²ã¿
ãŸã ã ã€ã³ã¹ã¿ã³ã¹ã«é¢é£ä»ããããŠããã°ã«ãŒããéžæããŸãã [
ã€ã³ããŠã³ã]ã[ã¢ãŠãããŠã³ã]ã¿ãã§
ããã¹ãŠã®ãã©ãã£ãã¯ãééãããèš±å¯ãåé€ããŸãã RDPãå»ãã誰ããã£ãããšããªã人ã¯ãããŒã1194ã®ã«ãŒã«ãè¿œå ããICMPãæå¹ã«ããŸãã
ã·ã ã®å Žå-ããã ãã§ãã ããããšã
PS Windowsã¯ã©ã€ã¢ã³ãã§ã¯ãã¹ãããŠããŸãããããã¹ãŠã¯Androidäžãšåãã§ãããšæããŸãã