ãããã¯habrahabr.ru/blogs/linux/67209ãèªãã§ãããã«ç§ã®èšäºãæçš¿ããããšã«ããŸãããããã¯ä»¥åã¯éå
¬éã®äŒæ¥Wikiã§ã®ã¿è¡šç€ºãããŠããŸãããéåžžãVPNã®äœææã«ã¯ãç¹å®ã®ãµããããããã³ãã«ã«å²ãåœãŠãããŠãããã€ã³ãããŒãã€ã³ãæ¥ç¶ããµãŒããŒã«äœ¿çšãããããã€ãŒãµããããã³ãã«ããµãŒããŒã«ã€ã³ã¹ããŒã«ãããŸãã VPNãµãŒããŒã¯åæã«ããã©ãã£ãã¯ãã«ãŒãã£ã³ã°ããã³ãã£ã«ã¿ãªã³ã°ããæ©èœãå®è¡ããŠãVPNãä»ããŠããŒã«ã«ãããã¯ãŒã¯ã«ã¢ã¯ã»ã¹ããŸãã
ãã®èšäºã§ã¯ããªã¢ãŒãã·ã¹ãã ãæ¢åã®ããŒã«ã«ãµããããã«å«ãŸããVPNãµãŒããŒãã€ãŒãµãããã²ãŒããŠã§ã€ãšããŠæ©èœãããä»®æ³ãããã¯ãŒã¯ãäœæããå¥ã®ã¢ãããŒããæ€èšããŸãã ãã®ã¢ãããŒãã䜿çšãããšãæ¥ç¶æ¹æ³ã«åºã¥ããŠãã©ãã£ãã¯ããã£ã«ã¿ãªã³ã°ããæ©èœããŸã ãããŸãïŒããšãã°ãããŒã«ã«ãããã¯ãŒã¯ãšãªã¢ãŒããŠãŒã¶ãŒã«ç°ãªããã£ã«ã¿ãŒã䜿çšããŸãïŒã远å èšå®ãªãã§ãããŒããã£ã¹ãã¡ãã»ãŒãžã䜿çšããŸãã ãã®VPNãä»ããŠãããŒã«ã«Windowsãããã¯ãŒã¯äžã®ãã¹ãŠã®ã³ã³ãã¥ãŒã¿ãŒãXDMCPãããŒããã£ã¹ãã䜿çšå¯èœãªãã¹ãŠã®XDMCPãµãŒããŒãªã©ã衚瀺ããŸãã
ãããã¯ãŒã¯æ§é ãšãµãŒããŒã®ã»ããã¢ãã
ããŒã«ã«ãããã¯ãŒã¯ã®ãããªãã£ã¹ããããšããŸããIPãµãããã
192.168.168.0/24ã䜿çšãããŸãã ãã®ããŒã«ã«ãããã¯ãŒã¯ã«ã¯ãããŒã ãŠãŒã¶ãŒãå«ãŸããŸããã€ãŸããåããµããããã®ã¢ãã¬ã¹ãæã¡ãŸãã èªå®
ã«ãã®ãµããããããªãããšãããã³ããŒã«ã«ãããã¯ãŒã¯äžã®ã·ã¹ãã ã«ãªã¢ãŒããŠãŒã¶ãŒã«å²ãåœãŠãç¯å²å
ã®ã¢ãã¬ã¹ããªãããšã確èªããå¿
èŠããããŸãã
ã³ã¢ããªããžã®ãµããŒã
ãã®ææ³ãæ©èœããã«ã¯ãããã€ãã®ã«ãŒãã«ãã©ã€ããŒãå¿
èŠã§ãã ããã¯ããŠãããŒãµã«
tunä»®æ³ãããã¯ãŒã¯ãã©ã€ããŒã§ãããã€ãŒãµãããããªããžãã©ã€ããŒã§ãã ããããã«ãŒãã«ã«å«ããããã¢ãžã¥ãŒã«ã§ã¢ã»ã³ãã«ã§ããŸãã
->ãããã¯ãŒãã³ã°
->ãããã¯ãŒãã³ã°ãµããŒãïŒNET [= y]ïŒ
->ãããã¯ãŒã¯ãªãã·ã§ã³
<*> 802.1d Ethenetããªããžã³ã°ïŒBRIDGE [= y]ïŒ
->ããã€ã¹ãã©ã€ããŒ
->ãããã¯ãŒã¯ããã€ã¹ã®ãµããŒãïŒNETDEVICES [= y]ïŒ
<*>ãŠãããŒãµã«TUN / TAPããã€ã¹ãã©ã€ããŒã®ãµããŒãïŒTUN [= y]ïŒ
ã¢ãžã¥ãŒã«ã«ãã£ãŠçµã¿ç«ãŠãããŠããå Žåãã«ãŒãã«ã§ã¢ãžã¥ãŒã«ã®èªåããŒããæå¹ã«ããããVPNæ¥ç¶ãã»ããã¢ããããåã«èªåã§ããŒãããå¿
èŠããããŸãã
ãœãããŠã§ã¢
ãµãŒããŒã¯ãããªããžã«ãµãŒãã¹ãæäŸããããã«OpenVPNãšãŠãŒãã£ãªãã£ãå¿
èŠãšããŸãã Gentooã§ã¯ã次ã®ããã«çµã¿ç«ãŠãããŸãã
emerge net-misc / bridge-utils net-misc / openvpn
> = sys-apps / baselayout-1.12.6ã䜿çšããå Žåã¯ããã§ååã§ããå€ãããŒãžã§ã³ã§ã¯ãtunããã€ã¹ãã¿ãããŸãã¯ã¿ããããããã«ç¹å¥ãªãŠãŒãã£ãªãã£ãå¿
èŠã§ãã
emerge sys-apps / usermode-utilities
ãããã¯ãŒã¯èšå®
eth2ãããŒã«ã«ãããã¯ãŒã¯ãæ¥ç¶ãããŠããã€ã³ã¿ãŒãã§ã€ã¹ã§ãããå²ãåœãŠãããã¢ãã¬ã¹192.168.168.254ã§ãããšããŸãã 圌ã®ã»ããã¢ããã¯æ¬¡ã®ããã«ãªããŸããã
config_eth2 =ïŒ "192.168.168.254/24"ïŒ
圌ã¯ããªããžã«åå ãããããã¢ãã¬ã¹ãå²ãåœãŠãå¿
èŠã¯ãããŸããã ãŸããæ°ããäœæãããä»®æ³ã€ã³ã¿ãŒãã§ã€ã¹tap0ã¯ããªããžã«é¢ä¿ããããªããžã«ãã¢ãã¬ã¹ãå²ãåœãŠãããŠããŸããã eth2ã䜿çšããã¢ãã¬ã¹ã¯ãbr0ããªããžã«å²ãåœãŠãããŠããŸãã
config_eth2 =ïŒ "null"ïŒ
tuntap_tap0 = "ã¿ãã"
config_tap0 =ïŒ "null"ïŒ
depend_br0ïŒïŒ{
net.tap0 net.eth2ãå¿
èŠã§ã
}
ïŒæ¢åã®ã€ã³ã¿ãŒãã§ãŒã¹ãæå®ããããããããªããžã«çµå
bridge_br0 = "eth2 tap0"
ïŒã©ã¡ãããããã«æ°ããçŸããã€ã³ã¿ãŒãã§ãŒã¹ãåçã«æ¥ç¶ã§ããŸã
ïŒbridge_add_eth2 = "br0"
config_br0 =ïŒ "192.168.168.254/24"ïŒ
ãŸããæå®ãããã€ã³ã¿ãŒãã§ã€ã¹ã®æ§æã¹ã¯ãªãããäœæããå¿
èŠããããŸãã
cd /etc/init.d
ln -s net.lo net.eth2
ln -s net.lo net.tap0
ln -s net.lo net.br0
br0ã€ã³ã¿ãŒãã§ãŒã¹ã®ã¿ãèªåçã«ããŒãããã ãã§ååã§ãã depend_br0ïŒïŒã¯ãåäœã«å¿
èŠãªä»ã®ãã¹ãŠãèªåçã«çºçãããŸãã
rc-update add net.br0 default
/etc/init.d/net.eth2 stop
/etc/init.d/net.br0 start
OpenVPNããŒã®äœæ
OpenSSLã®RSAããŒã䜿çšããŠã¯ã©ã€ã¢ã³ããæ¿èªããŸãã ããã»ã¹ãç°¡çŽ åããããã«ãããã€ãã®åæåã¹ã¯ãªãããçšæããŸããã
cd / usr / share / openvpn / easy-rsa /
äžè¬çãªå€ã远å ããvarsãã¡ã€ã«ããããŸãã
ããããŒ
ãã®ãã¡ã€ã«ã®æåŸã«ã倿°ãå
¥åããŸãã
ãšã¯ã¹ããŒãKEY_COUNTRY = "RU"
export KEY_PROVINCE = "Voronezh oblast"
ãšã¯ã¹ããŒãKEY_CITY = "Boguchar"
export KEY_ORG = "OrganiZationnAme"
export KEY_EMAIL = "root@oza.ru"
ãã®ãã¡ã€ã«ãã倿°ãããŒãããCAïŒèªèšŒå±ïŒãæ§ç¯ããŸãã
ãœãŒã¹./vars
./clean-all
./build-ca
ãµãŒããŒããŒ
officeãšããååã®ãµãŒããŒããŒãçæããã«ã¯ã次ã®ã³ãã³ãã䜿çšããŸãã
./build-key-server office
ãCommon Nameããšãã質åã«ã¯ããµãŒããŒåïŒãã®å Žåã¯officeïŒã§çããå¿
èŠããããŸãã ãèšŒææžã«çœ²åããŸããïŒãã®æåŸã®2ã€ã®è³ªå [y / n]ãããã³ã1ã€ã®èšŒææžèŠæ±ã®ãã¡1ã€ãèªèšŒãããã³ãããããŸããïŒ [y / n]ãçããŸããy "ã
å¿
èŠã«å¿ããŠã远å ã®ãµãŒããŒããŒãäœæã§ããŸãã ããšãã°ãã·ã¹ãã ã®ä¿¡é Œæ§ãé«ããããã¯ã¢ããã¢ã¯ã»ã¹ãµãŒããŒã«ããããšãã§ããŸãã ãããã¯ããœãŒã¹./varsãå®è¡ããå¿
èŠãããåã«ãåãã³ãã³ãã«ãã£ãŠäœæãããŸãã
Diffie Hellmanãã©ã¡ãŒã¿ãŒ
ããã§è¿œå ããããšã¯ãããŸããããåŸ
ã€å¿
èŠããããŸãã
./build-dh
ãã®ãã¡ã€ã«ã¯ãµãŒããŒäžã§ã®ã¿å¿
èŠã§ãã
顧客ããŒ
åã¯ã©ã€ã¢ã³ãã¯ãç¬èªã®ããŒãæäŸããå¿
èŠããããŸãã clientãšããååã®ã¯ã©ã€ã¢ã³ãã®å ŽåãããŒã¯ã³ãã³ãã«ãã£ãŠäœæãããŸã
./build-keyã¯ã©ã€ã¢ã³ã
ãCommon Nameããšãã質åã«ã¯ãã¯ã©ã€ã¢ã³ãïŒãã®å Žåã¯ã¯ã©ã€ã¢ã³ãïŒã®ååã§åçããŸãã æåŸã«ãåæããŠ2ã€ã®è³ªåã«çããŸãã
çæãããããŒãšèšŒææžãå®å
šãªãã£ãã«ãä»ããŠã¯ã©ã€ã¢ã³ãã«éä¿¡ããŸãã å¿
èŠã«å¿ããŠãåãã³ãã³ãã§ããã«ããŒãäœæã§ããŸãã éå§ããåã«ãç°å¢ãããŒãããå¿
èŠããããŸã-source ./varsãå®è¡ããŸãã
OpenVPNãµãŒãã¹ã®ã»ããã¢ãããšéå§
éå§ããã«ã¯ã次ã®ãµãŒããŒæ§æã䜿çšããŸãïŒãã¡ã€ã«/etc/openvpn/openvpn.confïŒïŒ
ïŒãã®ããŒãã¯ãOpenVPNçšã«IANAã«ãã£ãŠæšå¥šãããŠããŸãã å¥ã®ããŒãã«è»¢éã§ããŸãããæ©å¯æ§ã¯åäžããŸãããOpenPVNã§ããããšãæåã«èªèãããŸãã
ããŒã1194
ïŒOpenVPNã¯ãã©ã³ã¹ããŒããããã³ã«ãšããŠtcpãšudpã䜿çšã§ããŸãããudpãæãŸãã
ãããUDP
ïŒããªããžã«å«ããä»®æ³ã€ã³ã¿ãŒãã§ã€ã¹ã¯ã確ãã«ã¿ããã¿ã€ãã§ãïŒã€ãŒãµãããçµç±ã§ã€ãŒãµãããããšãã¥ã¬ãŒãããããšã¯ã§ããŸããïŒ
dev tap0
ïŒã«ãŒãèªå·±çœ²åCAèšŒææž
ca /etc/openvpn/keys/ca.crt
ïŒèšŒææžãšãµãŒããŒã®ç§å¯éµã crtã«ã¯ã¢ãŒã644ãããŒ-600ãå¿
èŠã§ã
cert /etc/openvpn/keys/office.crt
ããŒ/etc/openvpn/keys/office.key
ïŒDiffie-Hellmanãã©ã¡ãŒã¿ãå«ããã¡ã€ã«ã ããŒã®é·ããç°ãªãå Žåã¯ãååãä¿®æ£ããŠãã ãã:)
dh /etc/openvpn/keys/dh1024.pem
ïŒãã®ç¯å²å
ã®ãã®ãµããããå
ã®ã¢ãã¬ã¹ããªã¢ãŒãã¯ã©ã€ã¢ã³ãã«é
åžããŸãïŒæ³š-ãµããããã¯ãããã¯ãŒã¯ã«ãŒãæ§æã®ããã«EVERYTHINGã«èšå®ãããç¯å²ã¯ãµããããã®äžéšã§ãïŒ
server-bridge 192.168.168.254 255.255.255.0 192.168.168.128 192.168.168.159
ïŒã¯ã©ã€ã¢ã³ããçžäºã«å¯Ÿè©±ã§ããããã«ããŸãïŒããã§ãªãå Žåã¯ããµãŒããŒãšãããªããžã®èåŸãã®ãããã¯ãŒã¯ã»ã°ã¡ã³ããšã®ã¿å¯Ÿè©±ããŸãïŒ
ã¯ã©ã€ã¢ã³ãé
ïŒããã«ãããã¯ã©ã€ã¢ã³ãã¯ãããžãŒã§ãªãå Žåã以åã«äžããããã®ãšåãã¢ãã¬ã¹ãäžããããšãã§ããŸã
ifconfig-pool-persist /etc/openvpn/ipp.txt
ïŒDHCPãä»ããŠDNSãµãŒããŒã¢ãã¬ã¹ã転éããããªãå Žåã¯ã次ã®è¡ãåé€ã§ããŸãã
push "dhcp-option DNS 192.168.168.254"
ïŒå§çž®
comp-lzo
ïŒã¯ã©ã€ã¢ã³ãã®æå€§æ°-ãµãŒããŒããªããžç¯å²å
ã®ã¢ãã¬ã¹æ°ä»¥äžã«ããããšã¯çã«ããªã£ãŠããŸã
æå€§ã¯ã©ã€ã¢ã³ãæ°32
ïŒãããã®ããŒã®è©³çްã¯ãOpenVPNã®ããã¥ã¡ã³ãã«ãããŸã
ããŒãã¢ã©ã€ã10120
ïŒtunãååæåãããåæ¥ç¶æã«ããŒãåèªã¿åãããªãã§ãã ããã rootãšããŠã§ã¯ãªãã誰ãšããŠãåããŠããªãå Žåããããè¡ãããšã¯ã§ããŸããããããã£ãŠããããã®ãªãã·ã§ã³ã®ãã¹ãŠããŸãã¯ã©ãã
ãŠãŒã¶ãŒãªã
ã°ã«ãŒããªã
æ°žç¶ããŒ
æç¶ãã
ïŒOpenVPNã¯æ¯åããã§çŸåšã®ç¶æ
ïŒã¯ã©ã€ã¢ã³ããã«ãŒããªã©ã®ãªã¹ãïŒããªã»ããããŸã
ã¹ããŒã¿ã¹/tmp/openvpn-status.log
ïŒéåžžã«ãã€ãºã®å€ããã°ãéåžžã®æäœ-åè©2
åè©6
log-append /var/log/openvpn.log
ããŒ
office.keyã«ã¯ã¢ãŒã
600 ïŒææè
ã®ã¿ãžã®ã¢ã¯ã»ã¹ïŒãå¿
èŠã§ãã ãã¡ã€ã«
office.crtããã³
dh1024.pemã®ã¢ãŒãã¯
644ã§ãã
ãã£ã«ã¿ãŒèšå®
ããªããžã䜿çšããããããã±ãããã£ã«ã¿ãªã³ã°ãæŽçããããã®æ©èœãããã€ããããŸãã ããšãã°ããã¹ãŠã®ééãã±ãããIPv4ã§ãããšã¯éããŸããã ã«ãŒãã«ã§ããªããžã®åäœãæ§æããã«ã¯ãããã€ãã®ãã©ã¡ãŒã¿ãŒããããŸãã
ãã®ã°ã«ãŒãã®å€æ°ã¯ã/ proc / sys / net / bridge /ãã£ã¬ã¯ããªã®ãã¡ã€ã«ã«ä¿åãããŸãã ãŸãã/ etc / sysctl.confã§æ§æããããšãã§ããŸãããã®å Žåããã¹ãŠãnet.brigdeããšãããã¬ãã£ãã¯ã¹ãä»ããŸãã- bridge-nf-call-arptables
ããŒã«å€æ°bridge-nf-call-arptablesã¯ãarptablesãã±ãããã£ã«ã¿ãŒã®FORWARDãã§ãŒã³ãžã®ARPãã©ãã£ãã¯ã®è»¢éãå¶åŸ¡ããŸãã ããã©ã«ãå€ã®1ã¯ãã£ã«ã¿ãŒãžã®ãã±ããã®éä¿¡ãèš±å¯ãã0-çŠæ¢ããŸãã - bridge-nf-call-iptables
ããŒã«å€æ°bridge-nf-call-iptablesã¯ãããªããžãééããIPv4ãã©ãã£ãã¯ã®iptablesãã§ãŒã³ãžã®è»¢éãå¶åŸ¡ããŸãã ããã©ã«ãå€ã®1ã¯ãã£ã«ã¿ãªã³ã°ã®ããã®ãã±ããã®éä¿¡ãèš±å¯ãã0-çŠæ¢ããŸãã - bridge-nf-call-ip6tables
ã¢ã¯ã·ã§ã³ã¯åã®ã¢ã¯ã·ã§ã³ãšäŒŒãŠããŸãããip6tablesãã§ãŒã³ã§ã®ãã£ã«ã¿ãªã³ã°ã®ããã«IPv6ãã©ãã£ãã¯ã®éä¿¡ãæ§æããã ãã§ãã - bridge-nf-filter-vlan-tagged
ããŒã«å€æ°bridge-nf-filter-vlan-taggedã¯ãVLANã¿ã°ä»ãã®IP / ARPãã©ãã£ãã¯ããã±ãããã£ã«ã¿ãªã³ã°ããã°ã©ã ïŒarptables / iptablesïŒã«éä¿¡ãããã©ãããæ±ºå®ããŸãã å€1ïŒããã©ã«ãã§èšå®ïŒã¯ãVLANã¿ã°ä»ãã®ãã±ããã®ãã£ã«ã¿ãªã³ã°ããã°ã©ã ãžã®éä¿¡ãèš±å¯ããŸãã0-çŠæ¢ããŸãã
ããªããžãééãããã±ããããã£ã«ã¿ãªã³ã°ããããã«ãphysdevãããã³ã°ã䜿çšãããŸããããã¯ããã±ãããã©ã®ããŒããšã©ã®ããªããžãééããããåºå¥ããŸãã ã«ãŒãã«ã§æå¹ã«ããŸãïŒ
->ãããã¯ãŒãã³ã°
->ãããã¯ãŒãã³ã°ãµããŒãïŒNET [= y]ïŒ
->ãããã¯ãŒã¯ãªãã·ã§ã³
->ãããã¯ãŒã¯ãã±ãããã£ã«ã¿ãªã³ã°ãã¬ãŒã ã¯ãŒã¯ïŒNetfilterïŒïŒNETFILTER [= y]ïŒ
->ã³ã¢Netfilterèšå®
-> Netfilter XtablesãµããŒãïŒip_tablesã«å¿
èŠïŒïŒNETFILTER_XTABLES [= y]ïŒ
->ãphysdevãäžèŽãµããŒãïŒNETFILTER_XT_MATCH_PHYSDEV [= y]ïŒ
ããã«ãã«ãŒãã«æ§æã§ã¯ããã±ãããiptablesãã£ã«ã¿ãªã³ã°ã«è»¢éã§ããããã«ããå¿
èŠããããŸãã bridge-nf-call-iptables = 1ããã³bridge-nf-call-ip6tables = 1ïŒIPv6ã䜿çšããŠããå ŽåïŒã
ããšãã°ããã£ã«ã¿ãªã³ã°ã«æ¬¡ã®ã«ãŒã«ã䜿çšã§ããŸãã
iptables -A FORWARD -p tcp --dport 22 -m physdev --physdev-in eth1 --physdev-out eth0 -j ACCEPT
Linuxã§ããªããžãæ§ç¯ããã®èšäºã§æçš¿ããŒãéã®ãã£ã«ã¿ãªã³ã°ã®èšå®ã®è©³çްãèªãããšãã§ããŸãã
LANãŠãŒã¶ãŒãšããªããžVPNãŠãŒã¶ãŒãåºå¥ããããªãå Žåã¯ãã«ãŒãã«ã§ãããã®ãªãã·ã§ã³ããªãã«ããã ãã§æžã¿ãŸãïŒããã©ã«ãã§æå¹ã«ãªã£ãŠããŸãïŒã
echo "net.bridge.bridge-nf-call-iptables = 0" >> /etc/sysctl.conf echo "net.bridge.bridge-nf-call-ip6tables = 0" >> /etc/sysctl.conf
ã客ããŸ
ã¯ã©ã€ã¢ã³ãã§ã次ã®å
容ã®OpenVPNæ§æãã¡ã€ã«ãäœæããå¿
èŠããããŸãã
ã¯ã©ã€ã¢ã³ã
ããã€ã³ã
éçºè
ã¿ãã
ãããUDP
ïŒæ¥ç¶å
ã è€æ°ã®ãªã¢ãŒããªãã·ã§ã³ãæå®ã§ããŸã-æåã«äœ¿çšå¯èœãªãµãŒããŒã䜿çšãããŸãã server.example.netã®Aã¬ã³ãŒããè€æ°ããå Žåããããã®éžæã¯ã©ã³ãã ã§ãã
ãªã¢ãŒãserver.example.net 1194
ïŒæ±ºããŠããããããç¡éã«æ¥ç¶ããŠã¿ãŠãã ããã
ç¡éã®è§£æ±ºãšå詊è¡
ïŒãã¹ãŠã®ãªãã·ã§ã³ãäžç·ã«äœ¿çšããããã©ãã䜿çšããªã
æ°žç¶ããŒ
æç¶ãã
ãŠãŒã¶ãŒãªã
ã°ã«ãŒãnogroup
comp-lzo
ns-cert-typeãµãŒããŒ
ca ca.crt
cert client.crt
ããŒclient.key
ãµãŒããŒãè€æ°ã®ãããã€ããŒãä»ããŠæ¥ç¶ãããŠããå Žåãé害ã«å¯Ÿãããããã¯ãŒã¯ã®å埩åãé«ããããšãã§ããŸãã ãããè¡ãã«ã¯ãã¯ã©ã€ã¢ã³ãã¯è€æ°ã®ãªã¢ãŒããªãã·ã§ã³ããåªå
ããããé åºã§ãµãŒããŒããšã«1ã€ç»é²ããå¿
èŠããããŸãã
caãcertãããã³keyãã©ã¡ãŒã¿ãŒã§æå®ããããã¡ã€ã«åã¯ãå®å
šãªãã£ãã«ãä»ããŠè»¢éããããã¡ã€ã«ã§ãã ããŒãã¡ã€ã«ã®ã¢ã¯ã»ã¹èš±å¯ã¯600ã«èšå®ããå¿
èŠããããŸãã
Linux
ã«ãŒãã«ãŸãã¯ã¢ãžã¥ãŒã«ã§ã¯ããŠãããŒãµã«tun / tapãã©ã€ããŒãå¿
èŠã§ãããããŒããããŠããŸãã
ãžã§ã³ããŒ
net-misc / openvpnãã€ã³ã¹ããŒã«ãããšãã¹ã¯ãªãã/etc/init.d/openvpnãäœæãããŸãã ãã®ã¹ã¯ãªããã¯ãæ§æãã¡ã€ã«/etc/openvpn/openvpn.confã䜿çšããŠopenvpnãéå§ããŸãã ãã ãã/ etc / init.d / openvpn.network-name-> /etc/init.d/openvpnã®åœ¢åŒã®ã·ã³ããªãã¯ãªã³ã¯ãäœæããã°ãè€æ°ã®OpenVPNæ§æãåæã«ãµããŒãã§ããŸãããã®ãããªåã¹ã¯ãªããã¯ãæ§æãã¡ã€ã«/ etc / openvpnã§OpenVPNãèµ·åããŸã/network-name.confã
ãããã£ãŠãäžèšã®èšå®ãããã«é
眮ããã·ã³ããªãã¯ãªã³ã¯ãäœæããã¹ã¯ãªããã/ etc / openvpn /ã®ãµããã£ã¬ã¯ããªã«é
眮ããŸãã èšå®ã§ãããŒãšèšŒææžãžã®ãã«ãã¹ãç»é²ããŸãã äžå¿«ãªåœ±é¿ãé¿ããããã«ãæ§æå
ã®ãã¡ã€ã«åãéè€ããªãããã«ããŠãã ããïŒ
ãããã¯ãŒã¯ã®éå§ãšåæ¢ã¯ã/ etc / openvpn.network-nameãµãŒãã¹ã®ç®¡çãéããŠè¡ãããŸãã
çª
æ§æãã¡ã€ã«ã¯ããã£ã¬ã¯ããªãCïŒ\ Program Files \ OpenVPN \ config \ãã«ãoffice.ovpnããªã©ã®ååã§é
眮ãããæ®ãã®ãã¡ã€ã«-ããŒãšèšŒææžãããã«é
眮ãããŸãã ãããããµããã£ã¬ã¯ããªã«é
眮ããå ŽåïŒããšãã°ãè€æ°ã®ä»®æ³ãããã¯ãŒã¯ã䜿çšããããããã¹ãŠãåãååca.crtã®ãã¡ã€ã«ãæäŸããå ŽåïŒããã¡ã€ã«ãžã®ãã«ãã¹ã瀺ããŸãã
ãããã¯ãŒã¯ãéå§ããã«ã¯ãOpenVPNãµãŒãã¹ãéå§ãããïŒconfig \ã«ãããã¹ãŠã®* .ovpnæ§æãèµ·åãããŸãïŒãåå¥ã«-.ovpnãã¡ã€ã«ãå³ã¯ãªãã¯ããŠ[ãã®æ§æã§OpenVPNãå®è¡]ãéžæããŸãã
èããããåé¡
ãµãŒããŒãTCPã§å®è¡ãããŠããå Žåã¯ããµãŒããŒã®å¯çšæ§ã確èªããéåžžã®telnetã䜿çšã§ããŸãã
çª
ç¡æã®TAPä»®æ³ã¢ããã¿ãŒã¯ãããŸãã
2008幎12æ31æ¥10:43:51 2008 88.83.201.253:1194ã§TCPæ¥ç¶ã確ç«ãããŸãã
Wed Dec 31 10:43:51 2008 TCPv4_CLIENT link localïŒ[undef]
æ°Ž12æ31æ¥10:43:51 2008 TCPv4_CLIENTãªã³ã¯ãªã¢ãŒãïŒ88.83.201.253:1194
Wed Dec 31 10:44:51 2008 TLS ErrorïŒTLSããŒããŽã·ãšãŒã·ã§ã³ã¯60ç§ä»¥å
ã«çºçããŸããã§ããïŒãããã¯ãŒã¯æ¥ç¶ã確èªããŠãã ããïŒ
2008幎12æ31æ¥æ°Žææ¥10:44:51 TLSãšã©ãŒïŒTLSãã³ãã·ã§ã€ã¯ã«å€±æããŸãã
2008幎12æ31æ¥æ°Žææ¥10:44:51 2008èŽåœçãªTLSãšã©ãŒïŒcheck_tls_errors_coïŒãåèµ·åäž
2008幎12æ31æ¥æ°Žææ¥10:44:51 2008 SIGUSR1 [softãtls-error]ãåä¿¡ããããã»ã¹ãåèµ·åããŠããŸã
Wed Dec 31 10:44:56 2008éèŠïŒOpenVPNã®ããã©ã«ãã®ããŒãçªå·ã¯ãIANAã«ããå
¬åŒã®ããŒãçªå·å²ãåœãŠã«åºã¥ããŠ1194ã«ãªããŸããã OpenVPN 2.0-beta16以åã§ã¯ãããã©ã«ãããŒããšããŠ5000ã䜿çšãããŠããŸããã
Wed Dec 31 10:44:56 2008 SSL / TLSã³ã³ããã¹ãã®åå©çš
æ°Ž12æ31æ¥10:44:56 2008 LZOå§çž®ãåæåãããŸãã
Wed Dec 31 10:44:56 2008 88.83.201.253:1194ãšTCPæ¥ç¶ã確ç«ããããšããŠããŸã
æ°Ž12æ31æ¥10:44:56 2008 TCPæ¥ç¶ã¯88.83.201.253:1194ã§ç¢ºç«ãããŸãã
æ°Ž12æ31æ¥10:44:56 2008 TCPv4_CLIENTãªã³ã¯ããŒã«ã«ïŒ[undef]
Wed Dec 31 10:44:56 2008 TCPv4_CLIENT link remoteïŒ88.83.201.253:1194
æ°Ž12æ31æ¥10:45:11 2008 [ãªãã£ã¹] 88.83.201.253:1194ã§éå§ããããã¢æ¥ç¶
Wed Dec 31 10:45:13 2008ãã®ã·ã¹ãã äžã®ãã¹ãŠã®TAP-Win32ã¢ããã¿ãŒã¯çŸåšäœ¿çšäžã§ãã
2008幎12æ31æ¥æ°Žææ¥10:45:13 2008çµäº
ç¶è¡ããã«ã¯ä»»æã®ããŒãæŒããŠãã ãã...
OpenVPNãã°ã¯ãã¯ã©ã€ã¢ã³ãããµãŒããŒã«æ£åžžã«æ¥ç¶ãããã°ã€ã³ããããä»®æ³ãããã¯ãŒã¯ãä»®æ³ã¢ããã¿ãŒã«ãã€ã³ãã§ããªãã£ãããšã瀺ããŠããŸãã ãããããä»ã®ããã€ãã®ããã»ã¹ããã·ã¹ãã å
ã®ãã¹ãŠã®TAP-Win32ã¢ããã¿ãŒã«ãã§ã«åœ±é¿ãåãŒããŠããŸãã OpenVPNèªäœããã³ã°ããã¢ããã¿ãŒãæŸæ£ããªãå¯èœæ§ããããŸãã
åèµ·åããããããããã©ã®ãããªããã»ã¹ã§ããããèŠã€ããŠåŒ·å¶çã«çµäºããããšã§åŠçãããŸãã
åç
§è³æ
ãã®èšäºãæžããšããæ¬¡ã®ãœãŒã¹ã䜿çšãããŸããã
- Gentoo Linux Wiki-ãµãŒããŒèšŒææžã«ããEthenetããªããžã³ã°ã®ããã®HOWTO OpenVPNãµãŒã㌠ïŒãã®ããŒãžã®ã³ããŒã¯http://www.gentoo-wiki.info/HOWTO_OpenVPN_Server_for_Ethernet_Bridging_with_Server_Certificatesã«ãããŸã ããªã³ã¯ãããããšãããããŸã ïŒïŒ
- Gentoo Linux Wiki-HOWTO OpenVPN LinuxãµãŒããŒWindowsã¯ã©ã€ã¢ã³ã
- OpenVPNããã¥ã¡ã³ã-HOWTO
- ãããã¯ãŒã¯ãããã³ã«ãšã³ãµã€ã¯ãããã£ã¢-IPã¹ã¿ãã¯ã®sysctlãã©ã¡ãŒã¿ãŒ
- Linuxã§ããªããžãæ§ç¯ãã
PSäžéšã®ãœãŒã¹ã¯äŒã¿ãŸããã ãªã³ã¯ã¯åé€ããŸããããèŠããŠãã䟡å€ã¯ãããŸãã