äœã®ããã«ïŒ
ç¬è£æ¿æš©ã«ããã€ã³ã¿ãŒãããã®æ€é²ã®å¢å ã«äŒŽãããŸããŸãå€ãã®æçšãªã€ã³ã¿ãŒããããªãœãŒã¹ãšãµã€ãããããã¯ãããŠããŸãã æè¡æ
å ±ãå«ãã
ãããã£ãŠãã€ã³ã¿ãŒããããå®å
šã«äœ¿çšããããšã¯äžå¯èœã«ãªãã äžç人暩宣èšã«DecãããŠããèšè«ã®èªç±ã«å¯Ÿããåºæ¬çãªæš©å©ã䟵害ãããŸãã
ã»ã¯ã·ã§ã³19
誰ããæèŠãšè¡šçŸã®èªç±ã«å¯Ÿããæš©å©ãæããŸãã ãã®æš©å©ã«ã¯ãèªåã®ä¿¡å¿µãèªç±ã«å®ãèªç±ãšãå·ã®åœå¢ã«é¢ä¿ãªããããããææ®µã§æ
å ±ãã¢ã€ãã¢ãæ±ããåãåããåºããèªç±ãå«ãŸããŸãã
ãã®ã¬ã€ãã§ã¯ã6ã¹ãããã§ãç¡æã®ã¢ã«ãŠã³ãïŒ12ãæéïŒã䜿çšããŠã Ubuntu Server 18.04ãå®è¡ããŠããã€ã³ã¹ã¿ã³ã¹ïŒä»®æ³ãã·ã³ïŒã§ã Amazon Web Services ïŒAWSïŒã¯ã©ãŠãã€ã³ãã©ã¹ãã©ã¯ãã£ã®Wireguardãã¯ãããžãŒã«åºã¥ãç¬èªã®ç¡æ* VPNãµãŒãã¹ãå±éããŸãLTS
ç§ã¯ããã®ãŠã©ãŒã¯ã¹ã«ãŒãITããé ãé¢ãã人ã
ã«å¯èœãªéãå奜çã«ããããšã詊ã¿ãŸããã å¯äžå¿
èŠãªããšã¯ã以äžã§èª¬æããæé ãç¹°ãè¿ãéã®å¿èã§ãã
ãæ³šæ
ã¹ããŒãž
- AWSç¡æã¢ã«ãŠã³ãç»é²
- AWSã€ã³ã¹ã¿ã³ã¹ãäœæãã
- AWSã€ã³ã¹ã¿ã³ã¹ã«æ¥ç¶ãã
- Wireguardã®æ§æ
- VPNã¯ã©ã€ã¢ã³ãã®æ§æ
- VPNã€ã³ã¹ããŒã«ã確èªãã
䟿å©ãªãªã³ã¯
1. AWSã¢ã«ãŠã³ãç»é²
ç¡æã®AWSã¢ã«ãŠã³ãã«ç»é²ããã«ã¯ãå®éã®é»è©±çªå·ã𿝿ãå¯èœãªVisaãŸãã¯Mastercardã¯ã¬ãžããã«ãŒããå¿
èŠã§ãã Yandex.MoneyãŸãã¯QiwiãŠã©ã¬ãããç¡æã§æäŸããä»®æ³ã«ãŒãã®äœ¿çšããå§ãããŸãã ã«ãŒãã®æå¹æ§ã確èªããããã«ãç»é²æã«1ãã«ãåŒãèœãšããããã®åŸè¿ãããŸãã
1.1ã AWSãããžã¡ã³ãã³ã³ãœãŒã«ãéã
ãã©ãŠã¶ãéããŠã https ïŒ //aws.amazon.com/en/ã«ã¢ã¯ã»ã¹ããå¿
èŠããããŸã
ãç»é²ããã¿ã³ãã¯ãªãã¯ããŸã

1.2ã å人ããŒã¿ã®å
¥å
ããŒã¿ãå
¥åãã[ç¶è¡]ãã¿ã³ãã¯ãªãã¯ããŸã

1.3ã é£çµ¡å
ã®è©³çްãèšå
¥ãã
é£çµ¡å
ã®è©³çްãå
¥åããŸãã

ã«ãŒãçªå·ãæå¹æéãã«ãŒãææè
ã®ååã

1.5ã ã¢ã«ãŠã³ã確èª
ãã®æ®µéã§ãé»è©±çªå·ã確èªããã1ãã«ãæ¯æã«ãŒãããçŽæ¥åŒãèœãšãããŸãã 4æ¡ã®ã³ãŒããã³ã³ãã¥ãŒã¿ãŒç»é¢ã«è¡šç€ºãããæå®ãããé»è©±ã§Amazonããé»è©±ãããããŸãã é話äžã«ãç»é¢ã«è¡šç€ºãããã³ãŒãããã€ã€ã«ããå¿
èŠããããŸãã

1.6ã æéãã©ã³ã®éžæã
éžæ-åºæ¬ãã©ã³ïŒç¡æïŒ

1.7ã 管çã³ã³ãœãŒã«ã«ãã°ã€ã³ãã

1.8ã ããŒã¿ã»ã³ã¿ãŒã®å Žæã®éžæ

1.8.1ã é床詊éš
ããŒã¿ã»ã³ã¿ãŒãéžæããåã«ãæå¯ãã®ããŒã¿ã»ã³ã¿ãŒãžã®ã¢ã¯ã»ã¹é床ãhttps://speedtest.netã§ãã¹ãããããšããå§ãããŸããç§ã®å Žæã§ã¯æ¬¡ã®çµæãåŸãããŸãã
- ã·ã³ã¬ããŒã«

- ããª

- ãã©ã³ã¯ãã«ã

- ã¹ããã¯ãã«ã

- ãã³ãã³

æé«é床ã®çµæã¯ããã³ãã³ã®ããŒã¿ã»ã³ã¿ãŒã«ç€ºãããŠããŸãã ãããã£ãŠãããã«ã«ã¹ã¿ãã€ãºããããã«éžæããŸããã
2. AWSã€ã³ã¹ã¿ã³ã¹ã®äœæ
2.1ä»®æ³ãã·ã³ïŒã€ã³ã¹ã¿ã³ã¹ïŒã®äœæ
2.1.0 ã€ã³ã¹ã¿ã³ã¹ã®äœæãŠã©ãŒã¯ã¹ã«ãŒã®èµ·å
2.1.0.1ã ã€ã³ã¹ã¿ã³ã¹èµ·åããŒãžã«ç§»å

2.1.0.2ã ã€ã³ã¹ã¿ã³ã¹ã®äœæãŠã©ãŒã¯ã¹ã«ãŒã®èµ·å

2.1.0.3ã ã€ã³ã¹ã¿ã³ã¹ã®ãªãã¬ãŒãã£ã³ã°ã·ã¹ãã ã¿ã€ãã®éžæ

2.1.1ã ã€ã³ã¹ã¿ã³ã¹ã¿ã€ããéžæ
ããã©ã«ãã§ã¯ãt2.microã€ã³ã¹ã¿ã³ã¹ãéžæãããŠããŸããå¿
èŠãªã®ã¯ã[ 次㞠]ãã¿ã³ãã¯ãªãã¯ããã ãã§ãïŒã€ã³ã¹ã¿ã³ã¹ã®èšå®

2.1.2ã ã€ã³ã¹ã¿ã³ã¹ãã©ã¡ãŒã¿ã®æ§æ
å°æ¥ãæ°žç¶çãªãããªãã¯IPãã€ã³ã¹ã¿ã³ã¹ã«æ¥ç¶ããããããã®æ®µéã§ãããªãã¯IPã®èªåå²ãåœãŠããªãã«ãã[ 次ãžïŒã¹ãã¬ãŒãžã®è¿œå ]ãã¯ãªãã¯ããŸã

2.1.3ã ã¹ãã¬ãŒãžæ¥ç¶
ãããŒããã£ã¹ã¯ãã®ãµã€ãºãæå®ããŸãã 16ã®ã¬ãã€ãã§ååãªã®ã§ã[ 次㞠]ãã¿ã³ãã¯ãªãã¯ããŠãã ããïŒã¿ã°ã远å

2.1.4ã ã¿ã°ã®ã«ã¹ã¿ãã€ãº
è€æ°ã®ã€ã³ã¹ã¿ã³ã¹ãäœæããå Žåãã¿ã°ã§ã°ã«ãŒãåããŠç®¡çã容æã«ããããšãã§ããŸãã ãã®å Žåããã®æ©èœã¯åé·ã§ããããã«[ 次㞠]ãã¿ã³ãã¯ãªãã¯ããŠãã ããã

2.1.5ã éæž¯
ãã®æç¹ã§ãå¿
èŠãªããŒããéããŠãã¡ã€ã¢ãŠã©ãŒã«ãæ§æããŸãã éããŠããããŒãã®ã»ããã¯ãã»ãã¥ãªãã£ã°ã«ãŒããšåŒã°ããŸãã æ°ããã»ãã¥ãªãã£ã°ã«ãŒããäœæããååãšèª¬æãä»ããUDPããŒãïŒã«ã¹ã¿ã UDPã«ãŒã«ïŒã远å ããŸããRortRangeãã£ãŒã«ãã§ã åçããŒãç¯å²49152ã65535ããããŒãçªå·ãå²ãåœãŠãå¿
èŠããããŸãã ãã®å ŽåãããŒãçªå·54321ãéžæããŸããã

å¿
èŠãªããŒã¿ãå
¥åãããã[ ã¬ãã¥ãŒããŠèµ·å ]ãã¿ã³ãã¯ãªãã¯ããŸã
2.1.6ã ãã¹ãŠã®ã€ã³ã¹ã¿ã³ã¹èšå®ã®æŠèŠ
ãã®ããŒãžã«ã¯ãã€ã³ã¹ã¿ã³ã¹ã®ãã¹ãŠã®èšå®ã®æŠèŠãããããã¹ãŠã®èšå®ãæ£ãããã©ããã確èªãã[ èµ·å ]ãã¿ã³ãã¯ãªãã¯ããŸã

2.1.7ã ãã¹ããŒãäœæãã
次ã«ãæ¢åã®SSHããŒãäœæãŸãã¯è¿œå ãããã€ã¢ãã°ããã¯ã¹ã衚瀺ãããŸããããã䜿çšããŠãåŸã§ã€ã³ã¹ã¿ã³ã¹ã«ãªã¢ãŒãæ¥ç¶ããŸãã [æ°ããããŒãã¢ãäœæãã]ãªãã·ã§ã³ãéžæããŠãæ°ããããŒãäœæããŸãã ååãèšå®ãã[ ããŒãã¢ã®ããŠã³ããŒã ]ãã¿ã³ãã¯ãªãã¯ããŠãäœæããããŒãããŠã³ããŒãããŸãã ããŒã«ã«ã³ã³ãã¥ãŒã¿ãŒã®ãã£ã¹ã¯äžã®å®å
šãªå Žæã«ä¿åããŸãã ããŠã³ããŒãããã-[ ã€ã³ã¹ã¿ã³ã¹ã®èµ·å ]ãã¿ã³ãã¯ãªãã¯ããŸã

2.1.7.1ã ãã¹ããŒãä¿åãã
åã®æé ã§äœæããããŒãä¿åããæé ã瀺ããŸãã [ ããŒãã¢ã®ããŠã³ããŒã ]ãã¿ã³ãã¯ãªãã¯ããåŸãããŒã¯æ¡åŒµåã.pemã®èšŒææžãã¡ã€ã«ãšããŠä¿åãããŸãã ãã®å Žåã wireguard-awskey.pemãšããååãä»ããŸããã

2.1.8ã ã€ã³ã¹ã¿ã³ã¹äœæçµæã®æŠèŠ
次ã«ãäœæããã€ã³ã¹ã¿ã³ã¹ã®æ£åžžãªèµ·åã«é¢ããã¡ãã»ãŒãžã衚瀺ãããŸãã [ã€ã³ã¹ã¿ã³ã¹ã®è¡šç€º]ãã¿ã³ãã¯ãªãã¯ããŠãã€ã³ã¹ã¿ã³ã¹ã®ãªã¹ãã«ç§»åã§ããŸãã

2.2ã å€éšIPã¢ãã¬ã¹ã®äœæ
2.2.1ã å€éšIPã®äœæãéå§
次ã«ãVPNãµãŒããŒã«æ¥ç¶ããããã®æ°žç¶çãªå€éšIPã¢ãã¬ã¹ãäœæããå¿
èŠããããŸãã ãããè¡ãã«ã¯ãç»é¢ã®å·ŠåŽã«ããããã²ãŒã·ã§ã³ããã«ã§ã[ ãããã¯ãŒã¯ãšã»ãã¥ãªã㣠] ã«ããŽãªãã[ Elastic IPs]ã¢ã€ãã ãéžæãã[ æ°ããã¢ãã¬ã¹ãå²ãåœãŠã ]ãã¿ã³ãã¯ãªãã¯ããŸã

2.2.2ã å€éšIPäœæãæ§æãã
次ã®ã¹ãããã§ã¯ã AmazonããŒã«ãªãã·ã§ã³ãæå¹ã«ããå¿
èŠãããïŒããã©ã«ãã§æå¹ïŒã å²ãåœãŠãã¿ã³ãã¯ãªãã¯ããŸã

2.2.3ã å€éšIPã¢ãã¬ã¹ãäœæããçµæã®æŠèŠ
次ã®ç»é¢ã«ã¯ãåãåã£ãå€éšIPã¢ãã¬ã¹ã衚瀺ãããŸãã èŠããŠããããšããå§ãããŸããæžãçããŠãããæ¹ãããã§ãããã ããã¯ãVPNãµãŒããŒãããã«ã»ããã¢ããããŠäœ¿çšããããã»ã¹ã§äœåºŠã圹ã«ç«ã¡ãŸãã ãã®ããã¥ã¢ã«ã§ã¯ãäŸãšããŠIPã¢ãã¬ã¹4.3.2.1ã䜿çšããŸãã ã¢ãã¬ã¹ã®æžãæ¹ã éãããã¿ã³ãã¯ãªãã¯ããŠãã ãã

2.2.4ã å€éšIPã¢ãã¬ã¹ã®ãªã¹ã
次ã«ãæ°žç¶çãªãããªãã¯IPã¢ãã¬ã¹ïŒãšã©ã¹ãã£ãã¯IPïŒã®ãªã¹ããéããŸãã

2.2.5ã å€éšIPã€ã³ã¹ã¿ã³ã¹ã®å²ãåœãŠ
ãã®ãªã¹ãã§ãåãåã£ãIPã¢ãã¬ã¹ãéžæããããŠã¹ã®å³ãã¿ã³ãæŒããŠããããããŠã³ã¡ãã¥ãŒã衚瀺ããŸãã ãã®äžã§ã[ ã¢ãã¬ã¹ã®é¢é£ä»ã]é
ç®ãéžæããŠã以åã«äœæããã€ã³ã¹ã¿ã³ã¹ã«å²ãåœãŠãŸãã

2.2.6ã å€éšIPå²ãåœãŠãæ§æãã
æ¬¡ã®æé ã§ã¯ãããããããŠã³ãªã¹ãããã€ã³ã¹ã¿ã³ã¹ãéžæãã[é¢é£ä»ã]ãã¿ã³ãã¯ãªãã¯ããŸã

2.2.7ã å€éšIPå²ãåœãŠçµæã®æŠèŠ
ãã®åŸãã€ã³ã¹ã¿ã³ã¹ãšãã®ãã©ã€ããŒãIPã¢ãã¬ã¹ãæ°žç¶çãªãããªãã¯IPã¢ãã¬ã¹ã«é¢é£ä»ããããŠããããšãããããŸãã

ããã§ãå€éšãããSSHãä»ããŠã³ã³ãã¥ãŒã¿ãŒããæ°ããäœæãããã€ã³ã¹ã¿ã³ã¹ã«æ¥ç¶ã§ããŸãã
3. AWSã€ã³ã¹ã¿ã³ã¹ã«æ¥ç¶ãã
SSHã¯ãã³ã³ãã¥ãŒã¿ãŒããã€ã¹ããªã¢ãŒãã§å¶åŸ¡ããããã®å®å
šãªãããã³ã«ã§ãã
3.1ã Windowsã³ã³ãã¥ãŒã¿ãŒããã®SSHæ¥ç¶
Windowsã³ã³ãã¥ãŒã¿ãŒã«æ¥ç¶ããã«ã¯ããŸãPuttyããã°ã©ã ãããŠã³ããŒãããŠã€ã³ã¹ããŒã«ããå¿
èŠããããŸãã
3.1.1ã Puttyã®ç§å¯ããŒãã€ã³ããŒããã
3.1.1.1ã Puttyãã€ã³ã¹ããŒã«ããããä»å±ã®PuTTYgenãŠãŒãã£ãªãã£ãå®è¡ããŠãPEM圢åŒã®èšŒææžããŒãPuttyã§ã®äœ¿çšã«é©ãã圢åŒã«ã€ã³ããŒãããå¿
èŠããããŸãã ãããè¡ãã«ã¯ããããã¡ãã¥ãŒã§[ 倿]-> [ããŒã®ã€ã³ããŒã ]ãéžæããŸãã

次ã«ãã¹ããã2.1.7.1ã§ä»¥åã«ä¿åããããŒãéžæããŸãããã®å Žåããã®ååã¯wireguard-awskey.pemã§ã

3.1.1.3ã ããŒã€ã³ããŒããªãã·ã§ã³ã®èšå®
ãã®ã¹ãããã§ã¯ããã®ããŒã®ã³ã¡ã³ãïŒèª¬æïŒãæå®ãããã¹ã¯ãŒããšã»ãã¥ãªãã£ã®ç¢ºèªãèšå®ããå¿
èŠããããŸãã æ¥ç¶ãããã³ã«èŠæ±ãããŸãã ãããã£ãŠãããŒããã¹ã¯ãŒãã§äžé©åãªäœ¿çšããä¿è·ããŸãã ãã¹ã¯ãŒããèšå®ããããšã¯ã§ããŸããããããŒãééã£ãæã«æž¡ããšå®å
šæ§ãäœäžããŸãã [ ç§å¯ããŒãä¿å ]ãã¿ã³ãã¯ãªãã¯ããåŸ

3.1.1.4ã ã€ã³ããŒãããããŒãä¿åãã
[ãã¡ã€ã«ã®ä¿å]ãã€ã¢ãã°ããã¯ã¹ãéãã Puttyã§ã®äœ¿çšã«é©ããæ¡åŒµåã.ppk
ãã¡ã€ã«ãšããŠç§å¯ããŒãä¿åããŸãã
ããŒã®ååïŒãã®å Žåã¯wireguard-awskey.ppk
ïŒãæå®ãã[ ä¿å ]ãã¿ã³ãã¯ãªãã¯ããŸã ã

3.1.2ã Puttyã§æ¥ç¶ãäœæããã³æ§æãã
3.1.2.1ã æ¥ç¶ãäœæãã
Puttyããã°ã©ã ãéãã ã»ãã·ã§ã³ã«ããŽãªãéžæãïŒããã©ã«ãã§éããŠããŸãïŒãã¹ããã2.2.3ã§åãåã£ã[ ãã¹ãå]ãã£ãŒã«ãã«ãµãŒããŒã®ãããªãã¯IPã¢ãã¬ã¹ãå
¥åããŸãã [ä¿åãããã»ãã·ã§ã³]ãã£ãŒã«ãã«ãæ¥ç¶ã®ä»»æã®ååïŒãã®å Žåã¯wireguard-aws-london ïŒãå
¥åãã[ ä¿å ]ãã¿ã³ãã¯ãªãã¯ããŠå€æŽãä¿åããŸãã

3.1.2.2ã ãŠãŒã¶ãŒã®èªåãã°ã€ã³èšå®
ããã«ã[ æ¥ç¶]ã«ããŽãªã§[ ããŒã¿]ãµãã«ããŽãªãéžæãã[ èªåãã°ã€ã³ãŠãŒã¶ãŒå]ãã£ãŒã«ãã«ubuntuãŠãŒã¶ãŒåãå
¥åããŸã-ããã¯Ubuntuã®æšæºAWSã€ã³ã¹ã¿ã³ã¹ãŠãŒã¶ãŒã§ãã

3.1.2.3ã SSHæ¥ç¶çšã®ç§å¯éµã®éžæ
次ã«ã[ æ¥ç¶ ]ã[ SSH ]ã[ èªèšŒ ]ãµãã«ããŽãªã«ç§»åãã[ èªèšŒçšã®ç§å¯ããŒãã¡ã€ã« ]ãã£ãŒã«ãã®æšªã«ãã[ åç
§... ]ãã¿ã³ãã¯ãªãã¯ããŠãããŒèšŒææžã®ãããã¡ã€ã«ãéžæããŸãã

3.1.2.4ã ã€ã³ããŒããããããŒãéã
åã«ã¹ããã3.1.1.4ã§ã€ã³ããŒãããããŒãæå®ããŸãããã®å Žåãããã¯ãã¡ã€ã«wireguard-awskey.ppkã§ã[ éã ]ãã¿ã³ãã¯ãªãã¯ããŸãã

3.1.2.5ã èšå®ãä¿åããŠæ¥ç¶ãéå§ãã
[ ã»ãã·ã§ã³ ]ã«ããŽãªããŒãžã«æ»ãã[ ä¿å ]ãã¿ã³ãããäžåºŠã¯ãªãã¯ããŠãåã®æé ïŒ3.1.2.2-3.1.2.4ïŒã§è¡ã£ã倿Žãä¿åããŸãã æ¬¡ã«ã [éã ]ãã¿ã³ãæŒããŠãäœæããã³æ§æãããªã¢ãŒãSSHæ¥ç¶ãéããŸãã

3.1.2.7ã ãã¹ãéã®ä¿¡é Œã®æ§æ
次ã®ã¹ãããã§ã¯ãåããŠæ¥ç¶ããããšãããšãèŠåã衚瀺ãããŸãã2å°ã®ã³ã³ãã¥ãŒã¿ãŒéã®ä¿¡é Œãæ§æããŠãããããªã¢ãŒãã³ã³ãã¥ãŒã¿ãŒãä¿¡é Œãããã©ãããå°ããŸãã [ ã¯ã ]ãã¯ãªãã¯ããŠãä¿¡é Œã§ãããã¹ãã®ãªã¹ãã«è¿œå ããŸãã

3.1.2.8ã ãã¹ã¯ãŒããå
¥åããŠããŒã«ã¢ã¯ã»ã¹ããŸã
ãã®åŸãã¹ããã3.1.1.3ã§ããŒãã€ã³ã¹ããŒã«ããå Žåã¯ãã¿ãŒããã«ãŠã£ã³ããŠãéããããŒã®ãã¹ã¯ãŒããèŠæ±ãããŸãã ãã¹ã¯ãŒããå
¥åãããšããç»é¢ã§ã®ã¢ã¯ã·ã§ã³ã¯çºçããŸããã ééããå Žåã¯ã BackspaceããŒã䜿çšã§ããŸãã

3.1.2.9ã æ¥ç¶æåã®ãŠã§ã«ã«ã ã¡ãã»ãŒãž
ãã¹ã¯ãŒããæ£åžžã«å
¥åãããšããªã¢ãŒãã·ã¹ãã ãã³ãã³ããå®è¡ããæºåãã§ããããšãç¥ããããŠã§ã«ã«ã ããã¹ãã端æ«ã«è¡šç€ºãããŸãã

4. WireguardãµãŒããŒã®æ§æ
以äžã§èª¬æããã¹ã¯ãªããã䜿çšããŠWireguardãã€ã³ã¹ããŒã«ããã³äœ¿çšããããã®ææ°ã®æé ã¯ããªããžããªã§èŠã€ããããšãã§ããŸãïŒ https : //github.com/isystem-io/wireguard-aws
4.1ã Wireguardãã€ã³ã¹ããŒã«ãã
ã¿ãŒããã«ã§ã次ã®ã³ãã³ããå
¥åããŸãïŒã¯ãªããããŒãã«ã³ããŒããå³ã¯ãªãã¯ããŠã¿ãŒããã«ã«è²Œãä»ããããšãã§ããŸãïŒã
4.1.1ã ãªããžããªã®ã¯ããŒãã³ã°
Wireguardã€ã³ã¹ããŒã«ã¹ã¯ãªããã䜿çšããŠãªããžããªãè€è£œããŸã
git clone https://github.com/pprometey/wireguard_aws.git wireguard_aws
4.1.2ã ã¹ã¯ãªãããã£ã¬ã¯ããªã«ç§»åãã
è€è£œããããªããžããªããããã£ã¬ã¯ããªã«ç§»åããŸã
cd wireguard_aws
4.1.3åæåã¹ã¯ãªããã®å®è¡
管çè
ïŒrootãŠãŒã¶ãŒïŒãšããŠWireguardã€ã³ã¹ããŒã«ã¹ã¯ãªãããå®è¡ããŸã
sudo ./initial.sh
ã€ã³ã¹ããŒã«äžã«ãWireguardã®æ§æã«å¿
èŠãªç¹å®ã®ããŒã¿ã®å
¥åãæ±ããããŸã
4.1.3.1ã æ¥ç¶ãã€ã³ããå
¥å
å€éšIPã¢ãã¬ã¹ãå
¥åããWireguardãµãŒããŒã®ããŒããéããŸãã ã¹ããã2.2.3ã§ãµãŒããŒã®å€éšIPã¢ãã¬ã¹ãååŸããã¹ããã2.1.5ã§ããŒããéããŸããã 4.3.2.1:54321
ããã«ã³ãã³ã§4.3.2.1:54321
ãŠäžç·ã«æå®ãããã®åŸEnterãæŒããŸã
åºåäŸïŒ
Enter the endpoint (external ip and port) in format [ipv4:port] (eg 4.3.2.1:54321): 4.3.2.1:54321
4.1.3.2ã å
éšIPã¢ãã¬ã¹ãå
¥åããŠãã ãã
ã»ãã¥ã¢VPNãµããããã®WireguardãµãŒããŒã®IPã¢ãã¬ã¹ãå
¥åããŸãããããäœãåãããªãå Žåã¯ãEnterãæŒããŠããã©ã«ãå€ïŒ 10.50.0.1
ïŒãèšå®ããŸã
åºåäŸïŒ
Enter the server address in the VPN subnet (CIDR format) ([ENTER] set to default: 10.50.0.1):
4.1.3.3ã DNSãµãŒããŒã®æå®
DNSãµãŒããŒã®IPã¢ãã¬ã¹ãå
¥åããããEnterããŒãæŒããŠããã©ã«ãå€ã1.1.1.1
ïŒCloudflareãããªãã¯DNSïŒã«èšå®ããŸã
åºåäŸïŒ
Enter the ip address of the server DNS (CIDR format) ([ENTER] set to default: 1.1.1.1):
4.1.3.4ã WANã€ã³ã¿ãŒãã§ã€ã¹ã®æå®
次ã«ãå
éšVPNãããã¯ãŒã¯ã€ã³ã¿ãŒãã§ã€ã¹ã§ãªãã¹ã³ããå€éšãããã¯ãŒã¯ã€ã³ã¿ãŒãã§ã€ã¹ã®ååãå
¥åããŸãã Enterãeth0
ãŠAWSã®ããã©ã«ãå€ïŒ eth0
ïŒãèšå®ããã ãã§ã
åºåäŸïŒ
Enter the name of the WAN network interface ([ENTER] set to default: eth0):
4.1.3.5ã 顧客å
VPNãŠãŒã¶ãŒã®ååãå
¥åããŸãã å®éãå°ãªããšã1ã€ã®ã¯ã©ã€ã¢ã³ãã远å ããããŸã§ãWireguard VPNãµãŒããŒã¯èµ·åã§ããŸããã ãã®å Žåã Alex@mobile
ãšããååãå
¥åããŸãã
åºåäŸïŒ
Enter VPN user name: Alex@mobile
ãã®åŸãQRã³ãŒããç»é¢ã«è¡šç€ºãããæ°ãã远å ãããã¯ã©ã€ã¢ã³ãã®æ§æã衚瀺ãããŸãããããæ§æããã«ã¯ãAndroidãŸãã¯iOSã®Wireguardã¢ãã€ã«ã¯ã©ã€ã¢ã³ãã䜿çšããŠèªã¿åãå¿
èŠããããŸãã ãŸããã¯ã©ã€ã¢ã³ããæåã§æ§æããå Žåã¯ãæ§æãã¡ã€ã«ã®ããã¹ããQRã³ãŒãã®äžã«è¡šç€ºãããŸãã ãããè¡ãæ¹æ³ã以äžã«èª¬æããŸãã

4.2ã æ°ããVPNãŠãŒã¶ãŒã远å ãã
æ°ãããŠãŒã¶ãŒã远å ããã«ã¯ãã¿ãŒããã«ã§add-client.sh
ã¹ã¯ãªãããå®è¡ããå¿
èŠããããŸã
sudo ./add-client.sh
ã¹ã¯ãªããã¯ãŠãŒã¶ãŒåãå°ããŸãïŒ
åºåäŸïŒ
Enter VPN user name:
ãŸãããŠãŒã¶ãŒåãã¹ã¯ãªãããã©ã¡ãŒã¿ãŒãšããŠæž¡ãããšãã§ããŸãïŒãã®å Žåã Alex@mobile
ïŒã
sudo ./add-client.sh Alex@mobile
ã¹ã¯ãªããå®è¡ã®çµæããã¹ã«æ²¿ã£ãã¯ã©ã€ã¢ã³ãã®ååãæã€ãã£ã¬ã¯ããªã§/etc/wireguard/clients/{}
ãã¯ã©ã€ã¢ã³ãæ§æ/etc/wireguard/clients/{}
CustomerNameâº.confã§ãã¡ã€ã«ãäœæããã端æ«ã衚瀺ãããŸãã¢ãã€ã«ã¯ã©ã€ã¢ã³ããšèšå®ãã¡ã€ã«ã®ã³ã³ãã³ããèšå®ããããã®QRã³ãŒãã
4.2.1ã ãŠãŒã¶ãŒæ§æãã¡ã€ã«
cat
ã䜿çšããŠãæåã§ã¯ã©ã€ã¢ã³ããæ§æããããã«ãç»é¢ã«.confãã¡ã€ã«ã®å
容ã衚瀺ã§ããŸã
sudo cat /etc/wireguard/clients/Alex@mobile/Alex@mobile.conf
å®è¡çµæïŒ
[Interface] PrivateKey = oDMWr0toPVCvgKt5oncLLRfHRit+jbzT5cshNUi8zlM= Address = 10.50.0.2/32 DNS = 1.1.1.1 [Peer] PublicKey = mLnd+mul15U0EP6jCH5MRhIAjsfKYuIU/j5ml8Z2SEk= PresharedKey = wjXdcf8CG29Scmnl5D97N46PhVn1jecioaXjdvrEkAc= AllowedIPs = 0.0.0.0/0, ::/0 Endpoint = 4.3.2.1:54321
ã¯ã©ã€ã¢ã³ãæ§æãã¡ã€ã«ã®èª¬æïŒ
[Interface] PrivateKey = Address = IP DNS = [Peer] PublicKey = PresharedKey = AllowedIPs = ( - 0.0.0.0/0, ::/0) Endpoint = IP
4.2.2ã QRã¯ã©ã€ã¢ã³ãæ§æã³ãŒã
qrencode -t ansiutf8
ã䜿çšããŠã端æ«ç»é¢ã«ä»¥åã«äœæãããã¯ã©ã€ã¢ã³ãã®æ§æã³ãŒãã®QRã³ãŒãã衚瀺ã§ããŸãïŒãã®äŸã§ã¯ãAlex @ mobileãšããååã®ã¯ã©ã€ã¢ã³ãã䜿çšãããŸãïŒã
sudo cat /etc/wireguard/clients/Alex@mobile/Alex@mobile.conf | qrencode -t ansiutf8
5. VPNã¯ã©ã€ã¢ã³ãã®æ§æ
5.1ã Androidã¢ãã€ã«ã¯ã©ã€ã¢ã³ãã®ã»ããã¢ãã
Androidã®å
¬åŒWireguardã¯ã©ã€ã¢ã³ãã¯ãå
¬åŒã®GooglePlayã¹ãã¢ããã€ã³ã¹ããŒã«ã§ããŸãã
ãã®åŸãã¯ã©ã€ã¢ã³ãæ§æã§QRã³ãŒããèªã¿åãïŒ4.2.2é
ãåç
§ïŒãååãä»ããŠæ§æãã€ã³ããŒãããå¿
èŠããããŸãã

æ§æãæ£åžžã«ã€ã³ããŒãããããVPNãã³ãã«ãæå¹ã«ã§ããŸãã æ¥ç¶ãæåãããšãAndroidã®ã·ã¹ãã ããã«ã«ããŒã®é ãå Žæã衚瀺ãããŸã

5.2ã Windowsã¯ã©ã€ã¢ã³ãã®ã»ããã¢ãã
æåã«ãããã°ã©ã TunSafe for WindowsãããŠã³ããŒãããŠã€ã³ã¹ããŒã«ããå¿
èŠããããŸã -ããã¯Windowsçšã®Wireguardã¯ã©ã€ã¢ã³ãã§ãã
5.2.1ã ã€ã³ããŒãçšã®æ§æãã¡ã€ã«ã®äœæ
å³ã¯ãªãã¯ããŠããã¹ã¯ãããã«ããã¹ããã¡ã€ã«ãäœæããŸãã

5.2.2ã ãµãŒããŒããæ§æãã¡ã€ã«ã®å
容ãã³ããŒãã
次ã«ãPuttyã¿ãŒããã«ã«æ»ããã¹ããã4.2.1ã§èª¬æããããã«ãç®çã®ãŠãŒã¶ãŒã®æ§æãã¡ã€ã«ã®å
容ã衚瀺ããŸãã
次ã«ãããŠã¹ã®å³ãã¿ã³ã§Puttyã¿ãŒããã«ã®æ§æããã¹ããéžæããŸã;éžæãå®äºãããšãèªåçã«ã¯ãªããããŒãã«ã³ããŒãããŸãã

5.2.3ã èšå®ãããŒã«ã«èšå®ãã¡ã€ã«ã«ã³ããŒ
ãã®ãã£ãŒã«ãã¯ããã¹ã¯ãããã§ä»¥åã«äœæããããã¹ããã¡ã€ã«ã«æ»ããã¯ãªããããŒãããèšå®ããã¹ãã貌ãä»ããŸãã

5.2.4ã ããŒã«ã«æ§æãã¡ã€ã«ã®ä¿å
ãã¡ã€ã«ãæ¡åŒµå.conf ïŒãã®å Žåã¯london.conf
ãšããååã§ïŒã§ä¿åããŸã

5.2.5ã ããŒã«ã«æ§æãã¡ã€ã«ãã€ã³ããŒããã
次ã«ãæ§æãã¡ã€ã«ãTunSafeããã°ã©ã ã«ã€ã³ããŒãããå¿
èŠããããŸãã

5.2.6ã VPNæ¥ç¶ã確ç«ãã
ãã®æ§æãã¡ã€ã«ãéžæãã[ æ¥ç¶ ]ãã¿ã³ãã¯ãªãã¯ããŠæ¥ç¶ããŸãã

6.æ¥ç¶ã®æåã確èªãã
VPNãã³ãã«ãä»ããæ¥ç¶ã®æåã確èªããã«ã¯ããã©ãŠã¶ãŒãéããŠãµã€ãhttps://2ip.ua/ru/ã«ã¢ã¯ã»ã¹ããå¿
èŠããããŸã

衚瀺ãããIPã¢ãã¬ã¹ã¯ãã¹ããã2.2.3ã§åãåã£ãIPã¢ãã¬ã¹ãšäžèŽããå¿
èŠããããŸãã
ãã®å ŽåãVPNãã³ãã«ã¯æ£åžžã«æ©èœããŠããŸãã
Linuxã®ã¿ãŒããã«ãããæ¬¡ã®ã³ãã³ããå
¥åããŠIPã¢ãã¬ã¹ã確èªã§ããŸãã
curl http://zx2c4.com/ip
ãŸãã¯ãã«ã¶ãã¹ã¿ã³ã«ããå Žåã¯ããã«ãããã«è¡ãããšãã§ããŸãã