çŸä»£ã®çµç¹ã®ããžãã¹ããã»ã¹ã®å®å®æ§ãšå¹çæ§ã¯ãITã€ã³ãã©ã¹ãã©ã¯ãã£ã®åæ»ãªæ©èœã«å€§ããäŸåããŠããŸãã ITã€ã³ãã©ã¹ãã©ã¯ãã£ã®ä¿å®ã¯ãç¹ã«äžå°äŒæ¥ã«ãšã£ãŠã¯ãå€ãã®å Žåé«äŸ¡ã§ãã
ã³ã¹ããæé©åããããã«ãä»æ¥å€ãã®çµç¹ã¯ITã¢ãŠããœãŒã·ã³ã°ã®å®è·µã«é Œã£ãŠããŸããæ©åšãè³Œå ¥ãã代ããã«ããµãŒãããŒãã£ã®ããŒã¿ã»ã³ã¿ãŒã§ã¬ã³ã¿ã«ããã¡ã³ããã³ã¹ã®ããã«ãµãŒãããŒãã£ã®å°é家ãéããŸãã
ãã®ãã©ã¯ãã£ã¹ãçµç¹çããã³è²¡åçãªèŠ³ç¹ããæçã§ããããã«ã¯ãåé¡ã®æè¡çãªåŽé¢ãæ éã«æ€èšããå¿ èŠããããŸãã
ITã€ã³ãã©ã¹ãã©ã¯ãã£ã®äžéšããµãŒãããŒãã£ã®ããŒã¿ã»ã³ã¿ãŒã«ç§»è¡ããããšãèšç»ããå Žåãçµç¹ã®ãã¹ãŠã®æ å ±ãªãœãŒã¹ãåäžãããã¯ãŒã¯ã«æ£ç¢ºã«çµ±åããæ¹æ³ã決å®ããå¿ èŠããããŸãã 倧æã¡ãŒã«ãŒïŒJuniperãCiscoãªã©ïŒã®ãœãªã¥ãŒã·ã§ã³ã¯ãå€ãã®å Žåé«äŸ¡ã§ãã äžå°äŒæ¥ã¯æé ãªäŸ¡æ Œã§ã¯ãªããããããŸããã ããã«é¢ããŠãç¡æã®ãªãŒãã³ãœãŒã¹è£œåãžã®é¢å¿ã®é«ãŸãã¯éåžžã«è«ççã§ç解ãããããã®ã§ããããã®å€ãã¯æ©èœãææã®ã¢ããã°ã«å£ãããæã«ã¯ããããäžåãããšãããããŸãã
äŒæ¥ãããã¯ãŒã¯ã®éèŠãªèŠçŽ ã¯ã«ãŒã¿ãŒã§ãã ã«ãŒã¿ãŒã¯ããããã¯ãŒã¯ã»ã°ã¡ã³ããçµåãããããã®éã§ãã±ããã転éããããã«èšèšãããå°çšãããã¯ãŒã¯ããã€ã¹ã§ãã ã«ãŒã¿ãŒã¯ããŒããŠã§ã¢ãšãœãããŠã§ã¢ã®äž¡æ¹ã§ãã æå°éã®ã³ã¹ãã§ITã€ã³ãã©ã¹ãã©ã¯ãã£ãæ§ç¯ããå¿ èŠãããå Žåã¯ããœãããŠã§ã¢ã«ãŒã¿ãŒã䜿çšããããšããå§ãããŸãã
ãã®èšäºã§ã¯ãç¡æã®ã©ã€ã»ã³ã¹ã§ç¡æã§é åžãããŠããèå³æ·±ãææãªè£œåã§ããVyOSã«ãŒã¿ãŒã«ã€ããŠèª¬æããå®éã®åé¡ã解決ããããã«ã©ã®ããã«äœ¿çšã§ãããã瀺ããŸãã
VyOSïŒäžè¬æ å ±
VyOSã¯ãââæåãªVyattaãããã¯ãŒã¯ãªãã¬ãŒãã£ã³ã°ã·ã¹ãã ã®ãã©ãŒã¯ã§ãã æåã®ãªãªãŒã¹ã§ãããã³ãŒãããŒã ã¯Hydrogenã§ã2013幎12æã«å°å ¥ãããŸããã
ãããŸã§ã®ææ°ãªãªãŒã¹ã§ããããªãŠã ã¯ã2014幎9æã«ãªãªãŒã¹ãããŸããã VyOSã®ã³ãã³ãã©ã€ã³ã€ã³ã¿ãŒãã§ã€ã¹ïŒCLIïŒã¯ããžã¥ãããŒãããã¯ãŒã¯ã¹ã®CLIããã€ã¹ã«äŒŒãŠããŸãã
VyOSã®æ©èœã¯éåžžã«å¹ åºãã§ãã å®å šãªãªã¹ãããã¯ã»ã©é ãã§ãã
- p2pãã©ãã£ãã¯ã®ãã£ã«ã¿ãªã³ã°ãå«ããIPv4ããã³IPv6ã®ãã¡ã€ã¢ãŠã©ãŒã«ã
ãããã¯ãŒã¯ã¢ãã¬ã¹å€æïŒNATïŒ; - IPv4ããã³IPv6çšã®DHCPãµãŒããŒã
- äŸµå ¥æ€ç¥ã·ã¹ãã ã
- è² è·åæ£ãšãã£ãã«ã®åé·æ§ã
- æ¥ç¶ç¶æ ããŒãã«ã®åæã䜿çšããã«ãŒã¿ãŒäºçŽ
- ä»®æ³ãã©ã€ããŒããããã¯ãŒã¯ïŒIPsecãL2TP / IPsecãPPTPãOpenVPNïŒ;
- ãã©ãã£ãã¯ã¢ã«ãŠã³ãã£ã³ã°ïŒNetflowããã³sFlowïŒ;
- Webãããã·ãšURLãã£ã«ã¿ãªã³ã°ã
Vyattaãšåæ§ã«ãVyOSã¯Debianã«åºã¥ããŠããŸãã ããã«ãããè¿œå ã®debããã±ãŒãžãã€ã³ã¹ããŒã«ããŠæ©èœãæ¡åŒµã§ããŸãã
èšçœ®
VyOSãã€ã³ã¹ããŒã«ããããã®è©³çŽ°ãªæé ã¯æäŸããŸããããããã¯å¿ èŠãããŸããããã¹ãŠãããã§è©³çŽ°ã«èª¬æãããŠããŸã ã VyOSã®ã€ã³ã¹ããŒã«ã«ã¯ãã·ã¹ãã ã®ã€ã³ã¹ããŒã«ãšã€ã¡ãŒãžã®ã€ã³ã¹ããŒã«ã®2çš®é¡ããããŸãã æåã®ã¿ã€ãïŒã€ã³ã¹ããŒã«ã·ã¹ãã ïŒã¯ããã£ã¹ã¯äžã®OSã®æšæºã€ã³ã¹ããŒã«ãæå³ããŸãã ã€ã³ã¹ããŒã«ã€ã¡ãŒãžã䜿çšããŠã€ã³ã¹ããŒã«ããå ŽåãVyOSã®åããŒãžã§ã³ã¯åå¥ã®ãã£ã¬ã¯ããªã«æ ŒçŽããããããåé¡ãçºçããå Žåã«ä»¥åã®ãªãªãŒã¹ã«ããŒã«ããã¯ã§ããŸãïŒæšå¥šã€ã³ã¹ããŒã«æ¹æ³ïŒã
ãã®ããããã£ã¹ã¯ããèµ·åããã·ã¹ãã ã«å ¥ãïŒãã°ã€ã³-vyosããã¹ã¯ãŒã-vyosïŒãinstall imageã³ãã³ããå®è¡ããŸãã ã€ã³ã¹ããŒã«ãéå§ãããŸãããã®éã«ãLinuxã€ã³ã¹ããŒã©ãŒã®æšæºçãªè³ªåã«çããå¿ èŠããããŸãã å®äºããããåèµ·åã³ãã³ããå®è¡ããŠã·ã¹ãã ã«å床ãã°ã€ã³ããã€ã³ã¹ããŒã«äžã«èšå®ãããŠãŒã¶ãŒåãšãã¹ã¯ãŒãã䜿çšããŠãã°ã€ã³ããŸãã
å®çšäŸ
ç¹å®ã®å®çšçãªäŸã§VyOSã®æ©èœãæ€èšããŠãã ããã ã¿ã¹ã¯æ¡ä»¶ïŒçµç¹ã¯ãå°ççã«é¢ãã3ã€ã®ãŠãããã§æ§æãããŠããŸãã1ã€ã¯ã¢ã¹ã¯ã¯ã2ã€ç®ã¯ãµã³ã¯ãããã«ãã«ã¯ã3ã€ç®ã¯ããããã¹ã¯ã§ãã ãµã³ã¯ãããã«ãã«ã¯ã§ã¯ãããŒã¿ã»ã³ã¿ãŒã«4ã€ã®ãµãŒããŒãã€ã³ã¹ããŒã«ãããŠããŸãã ãã®ãã¡ã®1ã€ã ããã€ã³ã¿ãŒãããã«çŽæ¥æ¥ç¶ããå¿ èŠãããããšã確èªããå¿ èŠããããŸãã æ®ãã¯ããŒã«ã«ãããã¯ãŒã¯ã«æ¥ç¶ããã«ãŒã¿ãŒãä»ããŠã€ã³ã¿ãŒãããã«ã¢ã¯ã»ã¹ããå¿ èŠããããŸãã ãã©ã³ãã«ã¯ããŸããŸãªã¿ã€ãã®æ¥ç¶ã䜿çšããŸã-L2TP / IPsecãPPTPãããã³OpenVPNã
ãããã¯ãŒã¯ã¯æ¬¡ã®ããã«ãªããŸãã
ã²ãŒããŠã§ã€æ§æ
ãããã¯ãŒã¯ãã€ã³ã¹ããŒã«ããåŸããŸã ãããã¯ãŒã¯ããªããããæåã«KVMã³ã³ãœãŒã«ããæ§æããŸãã
æåã«ãã¢ãã¬ã¹95.213.170.75ãæã€æåã®ãããã¯ãŒã¯ã€ã³ã¿ãŒãã§ã€ã¹ïŒå€éšïŒãæ§æããŸãã configureã³ãã³ãã§èšå®ã¢ãŒãã«å ¥ããŸã-ã¯ãããã¹ãŠããå€ããéã®å åŒã®ãããªãã®ã§ãã
set interfaces ethernet eth0 address 95.213.170.75/29 set interfaces ethernet eth0 description "WAN"
ãã®å ŽåãåŸã§æ··ä¹±ããªãããã«ãeth0ã€ã³ã¿ãŒãã§ã€ã¹ã«ã¢ãã¬ã¹ãå²ãåœãŠãããŒãã®èª¬æãæå®ããŸããã
ããã©ã«ãã²ãŒããŠã§ã€ã¢ãã¬ã¹ãšDNSãµãŒããŒãæå®ããŸãã
set system gateway-address 95.213.170.73 set system name-server 188.93.16.19
ããã§ã¯ããµã³ã¯ãããã«ãã«ã¯ã®DNSãµãŒããŒSelectelã䜿çšããŠããŸããããã¡ãããä»ã®ãã®ãæå®ã§ããŸãã
SSHãµãŒãã¹ãæ§æããŸããããã䜿çšããŠãã²ãŒããŠã§ã€ãããã«æ§æããŸãã
set service ssh port "22"
VyOSã®ããžãã¯ã¯ããžã¥ãããŒãããã¯ãŒã¯ã¹ã®ããã€ã¹ã®ããžãã¯ãšã»ãŒåãã§ãã å€æŽãé©çšããã«ã¯ãcommitã³ãã³ããå®è¡ããå¿ èŠããããŸãã åèµ·ååŸãå€æŽãæå¹ã«ããã«ã¯ãsaveã³ãã³ãã䜿çšããŠä¿åããå¿ èŠããããŸãã ãã®vyOSã³ãã³ãã®ããžãã¯ã¯JunOSãšç°ãªããŸãããžã¥ãããŒã®ãããã¯ãŒã¯ãªãã¬ãŒãã£ã³ã°ã·ã¹ãã ã§ã¯ãã³ãããåŸã«å€æŽãä¿åããå¿ èŠã¯ãããŸããã
SSHãä»ããŠã«ãŒã¿ãŒã«æ¥ç¶ããŸãã ã·ã¹ãã ã«å ¥ãã«ã¯ãã€ã³ã¹ããŒã«æã«æå®ãããã°ã€ã³ãšãã¹ã¯ãŒããå ¥åããŸãã 次ã«ãå éšãããã¯ãŒã¯ã€ã³ã¿ãŒãã§ã€ã¹eth1ãæ§æããŸãã ããã¯ãããŒã¿ã»ã³ã¿ãŒå ã®ãµãŒããŒãæ¥ç¶ãããããŒã«ã«ãããã¯ãŒã¯ã€ã³ã¿ãŒãã§ã€ã¹ã§ãã ãããã¯ãŒã¯ãã¹ã¯/ 24ã§ã¢ãã¬ã¹10.0.10.1ãå²ãåœãŠã説æãè¿œå ããŸãã
set interfaces ethernet eth1 address 10.0.10.1/24 set interfaces ethernet eth1 description "LAN"
ãã·ã³ããããã¯ãŒã¯ãªãœãŒã¹åãèªèããããã«ã¯ãDNSãæ§æããå¿ èŠããããŸãã DNSãã©ã¯ãŒããŒãæ§æããŠãæ§æã§æå®ããããµãŒããŒã«åå解決èŠæ±ããªãã€ã¬ã¯ãããŸãã ãã®ã³ã³ããŒãã³ãã®ã»ããã¢ããæé ã¯ç°¡åã§ãã
set service dns forwarding cache-size "0" set service dns forwarding listen-on "eth1" set service dns forwarding name-server "188.93.16.19" set service dns forwarding name-server "188.93.17.19"
æåã®ã³ãã³ãã¯ãDNSãã©ã¯ãŒããŒãã¬ã³ãŒãã®ä¿åã«äœ¿çšãããã£ãã·ã¥ã®ãµã€ãºã瀺ããŸãã ãã£ãã·ã¥ãµã€ãºããŒãã«èšå®ããŸãããã®å ŽåãDNSã¬ã³ãŒãã®ä¿åã¯ããŸãæå³ããªãããã§ãã 2çªç®ã®ã³ãã³ãã¯ãDNSãã©ã¯ãŒããŒããªãã¹ã³ããã€ã³ã¿ãŒãã§ã€ã¹ãèšå®ããŸãã DNSãã©ã¯ãŒããŒãã€ã³ã¿ãŒãããå šäœã§å©çšå¯èœã«ãªããªãããã«ãDNSãã©ã¯ãŒããŒãèŠæ±ãããªãã¹ã³ãããå éšã€ã³ã¿ãŒãã§ã€ã¹ã®ã¿ã䜿çšããŸãã 3çªç®ãš4çªç®ã®ã³ãã³ãã¯ãèŠæ±ã転éãããã¢ãã¬ã¹ã瀺ããŸãã ãã®äŸã§ã¯ãSelectel DNSãµãŒããŒã䜿çšãããŸããããã¡ãããããã®ä»£ããã«ãä»ã®ãµãŒããŒãæå®ã§ããŸãã
ããŒã«ã«ãããã¯ãŒã¯ã®æ©èœã«å¿ èŠãªãã¹ãŠã®ã³ã³ããŒãã³ãã¯ãããã«äœ¿çšã§ããŸãã ãã¡ã€ã¢ãŠã©ãŒã«ã®ã»ããã¢ããã«ç§»ããŸãããã
VyOSã§ã¯ããã¡ã€ã¢ãŠã©ãŒã«ïŒãã¡ã€ã¢ãŠã©ãŒã«ïŒã«ãŒã«ã»ããã䜿çšããŠãããããä»»æã®ååã§åŒã³åºãããšãã§ããŸãã ãã®äŸã§ã¯ãå€éšãããã¯ãŒã¯ã®å Žåãå éšã®ããããã«å¯ŸããŠãOUTSIDEãšããååã§äžé£ã®ã«ãŒã«ã䜿çšãããŸãã
å€éšã€ã³ã¿ãŒãã§ãŒã¹ã«ã€ããŠã¯ããã¹ãŠã®æ¥ç¶ããå åŽããããå éšã€ã³ã¿ãŒãã§ãŒã¹ã«ã€ããŠã¯ãã¹ãŠèš±å¯ããŸã-ãã¹ãŠãå åŽãããããã³SSHãžã®ã¢ã¯ã»ã¹ã
å€éšã€ã³ã¿ãŒãã§ã€ã¹ã®ã«ãŒã«ãäœæããŸãã
set firewall name OUTSIDE default-action "drop" set firewall name OUTSIDE rule 1 action "accept" set firewall name OUTSIDE rule 1 state established "enable" set firewall name OUTSIDE rule 1 state related "enable"
äžèšã®ã³ãã³ãã䜿çšãããšããã§ã«ç¢ºç«ïŒç¢ºç«ïŒããããããã«é¢é£ããæ¥ç¶ãèš±å¯ããŸãã
次ã«ããã¡ã€ã¢ãŠã©ãŒã«ã«ãŒã«ãèšå®ããŸãã
ã«ãŒã«ã衚瀺
set firewall name INSIDE default-action 'drop' set firewall name INSIDE rule 1 action 'accept' set firewall name INSIDE rule 1 state established 'enable' set firewall name INSIDE rule 1 state related 'enable' set firewall name INSIDE rule 2 action 'accept' set firewall name INSIDE rule 2 icmp type-name 'echo-request' set firewall name INSIDE rule 2 protocol 'icmp' set firewall name INSIDE rule 2 state new 'enable' set firewall name INSIDE rule 3 action 'drop' set firewall name INSIDE rule 3 destination port '22' set firewall name INSIDE rule 3 protocol 'tcp' set firewall name INSIDE rule 3 recent count '4' set firewall name INSIDE rule 3 recent time '60' set firewall name INSIDE rule 3 state new 'enable' set firewall name INSIDE rule 31 action 'accept' set firewall name INSIDE rule 31 destination port '22' set firewall name INSIDE rule 31 protocol 'tcp' set firewall name INSIDE rule 31 state new 'enable'
æåã®ã«ãŒã«ã§ã¯ãããã©ã«ãã®ã¢ã¯ã·ã§ã³ãèšå®ããŸãããã®å Žåãããããããã§ãïŒç¢ºç«ãããã«ãŒã«ã«è©²åœããªããã¹ãŠã®ãã±ããã¯ãã¡ã€ã¢ãŠã©ãŒã«ã«ãã£ãŠç Žæ£ãããŸãïŒã 2çªç®ã§ã¯ãICMPãã±ããã®ééãèš±å¯ããŸãã ãŸã第äžã«ãããã¯ãé害ãçºçããå Žåã«ã«ãŒã¿ãŒããpingãã§ããããã«ããããã«å¿ èŠã§ãã 3çªç®ã®ã«ãŒã«ã¯SSHæ¥ç¶ãæ åœããŸããããŒã22ã«çä¿¡ããTCPãã©ãã£ãã¯ãèš±å¯ããŸãã
äœæãããã«ãŒã«ã察å¿ããã€ã³ã¿ãŒãã§ã€ã¹ïŒå€éšããã³ããŒã«ã«ïŒã«é©çšããŸãã
set interfaces ethernet eth0 firewall in name 'OUTSIDE' set interfaces ethernet eth1 firewall out name 'INSIDE'
å ¥åããã³åºåãã©ã¡ãŒã¿ãŒã«æ³šæãã䟡å€ããããŸãããããã¯ãã«ãŒã¿ãŒã«é¢é£ããŠåºå ¥ããããã©ãã£ãã¯ã®ã¿ã€ããæå®ãããã¡ã€ã¢ãŠã©ãŒã«ã«ãŒã«ã»ããã®ååãšã¯é¢ä¿ãããŸããã
commitã³ãã³ããšsaveã³ãã³ãã䜿çšããŠãæ§æãé©çšããŠä¿åããããšãå¿ããªãã§ãã ããã
VPNã®ã»ããã¢ãã
åè¿°ã®ããã«ããã©ã³ãã§ã¯ããŸããŸãªã¿ã€ãã®VPNæ¥ç¶ã䜿çšããŸãã L2TP / IPSecã®ã»ããã¢ããããå§ããŸãããïŒè©³çŽ°ã¯ãã¡ããã芧ãã ããïŒïŒ
set vpn ipsec ipsec-interfaces interface eth0 set vpn ipsec nat-traversal enable set vpn ipsec nat-networks allowed-network 0.0.0.0/0 set vpn l2tp remote-access outside-address 95.213.170.75 set vpn l2tp remote-access client-ip-pool start 10.0.10.20 set vpn l2tp remote-access client-ip-pool stop 10.0.10.30 set vpn l2tp remote-access ipsec-settings authentication mode pre-shared-secret set vpn l2tp remote-access ipsec-settings authentication pre-shared-secret <> set vpn l2tp remote- access authentication mode local set vpn l2tp remote-access authentication local-users username <> password <_>
æåã®3ã€ã䜿çšããŠãIPSecãæ§æããŸãããã±ããã®éä¿¡å ã€ã³ã¿ãŒãã§ã€ã¹ãæå®ããNATãã©ããŒãµã«ãæå¹ã«ããŠããã¹ãŠã®ãããã¯ãŒã¯ã§NATãæå¹ã«ããŸãã 次ã¯ãL2TPãæ åœããããŒã ã§ãã äžè¬ã«ãã³ãã³ããæžããšããããããäœã«è²¬ä»»ãããã®ãââãæšæž¬ããããšã¯é£ãããããŸãã;ç§ãã¡ã¯ããã€ãã®ãã©ã¡ãŒã¿ã«ã®ã¿æ³šæãæããŸãã
- outside-address -VPNãµãŒããŒã®å€éšã¢ãã¬ã¹ã瀺ããŸãã
- pre-shared-secret <password> -æ¥ç¶ã®ãã¹ã¯ãŒããèšå®ããŸããããã¯ãå°æ¥ã¯ã©ã€ã¢ã³ãããã€ã¹ã§VPNãæ§æããããã«äœ¿çšãããŸãã
- èªèšŒã¢ãŒãããŒã«ã« -èªèšŒã¿ã€ããèšå®ããŸãã ãã®äŸã§ã¯ãããŒã«ã«ããŒã¿ããŒã¹ã§ã®èªèšŒã䜿çšãããŠããŸãããRADIUSãµãŒããŒã䜿çšããŠã¢ã«ãŠã³ããéäžç®¡çã§ããŸãã
æåŸã®è¡ã§ã¯ããŠãŒã¶ãŒãäœæãããã®ãŠãŒã¶ãŒã®ãã¹ã¯ãŒããèšå®ããŸãã
ãã®åŸããã¡ã€ã¢ãŠã©ãŒã«ã®ã«ãŒã«ã調æŽããL2TP / IPSecãã©ãã£ãã¯ãèš±å¯ããŸãã
ã«ãŒã«ã衚瀺
set firewall name INSIDE rule 4 action 'accept' set firewall name INSIDE rule 4 protocol 'esp' set firewall name INSIDE rule 41 action 'accept' set firewall name INSIDE rule 41 destination port '500' set firewall name INSIDE rule 41 protocol 'udp' set firewall name INSIDE rule 42 action 'accept' set firewall name INSIDE rule 42 destination port '4500' set firewall name INSIDE rule 42 protocol 'udp' set firewall name INSIDE rule 43 action 'accept' set firewall name INSIDE rule 43 destination port '1701' set firewall name INSIDE rule 43 ipsec 'match-ipsec' set firewall name INSIDE rule 43 protocol 'udp' commit save
ã«ãŒã«4ã¯ã確ç«ãããIPSECãã³ãã«ãå®è¡ãããESPãããã³ã«ãã©ãã£ãã¯ã42-NATãã©ããŒãµã«ã43-L2TPãå®è¡ãããããŒã1701ãèš±å¯ããŸãã
次ã«ã2çªç®ã®ã¿ã€ãã®VPNæ¥ç¶ã®ã»ããã¢ããã«é²ã¿ãOpenVPNãµãŒããŒããã¬ã€ãºãããŸãã
æåã«ãã·ã¹ãã ã®æŽæ°æã«ãã¡ã€ã«ã倱ãããªãããã«ãeasy-rsaãã¡ã€ã«ã/ config / easy-rsa2ãã£ã¬ã¯ããªã«ã³ããŒããŸãã
cp -rv /usr/share/doc/openvpn/examples/easy-rsa/2.0/ /config/easy-rsa2
å¿ èŠã«å¿ããŠã蚌ææžã§ããã©ã«ãã§æå®ãããŠããå€æ°ãå€æŽã§ããŸãã次ã«äŸã瀺ããŸãã
nano /config/easy-rsa2/vars export KEY_COUNTRY="RU" export KEY_CITY="Saint-Petersburg" export KEY_ORG="Selectel" export KEY_EMAIL="t-rex@selectel.ru"
ãã®ããŒã¿ã¯ãçæãã蚌ææžã®ãã£ãŒã«ãã«ç€ºãããŸãã / config / easy-rsa2 /ãã£ã¬ã¯ããªã«ç§»åããŠãå€æ°ãããŒãããŸãã
cd /config/easy-rsa2/ source ./vars
ãã¹ãŠã®ããŒãåé€ããŸãã
./clean-all
次ã«ãèªèšŒå±ãã¡ã€ã«ãçæããŸãã
./build-ca ./build-dh
ããã³ãµãŒããŒèšŒææžïŒ
./build-key-server t-rex-server
ãã®åŸãããŒãé©åãªãã£ã¬ã¯ããªã«ã³ããŒããŸãã
cp /config/easy-rsa2/keys/ca.crt /config/auth/ cp /config/easy-rsa2/keys/dh1024.pem /config/auth/ cp /config/easy-rsa2/keys/t-rex-server.key /config/auth/ cp /config/easy-rsa2/keys/t-rex-server.crt /config/auth/
次ã«ããµãŒããŒã«æ¥ç¶ããããã®ã¯ã©ã€ã¢ã³ããã¡ã€ã«ãæºåããŸãã
./build-key branch-msk
ããã«å¥ã®ãã©ã«ããŒã«ã³ããŒããŸãïŒ
cd /config/easy-rsa2/keys mkdir branch-msk cp branch-msk* branch-msk/ cp ca.crt branch-msk/
çæããããã¡ã€ã«ã¯ãã¯ã©ã€ã¢ã³ãããµãŒããŒã«æ¥ç¶ããããã«å¿ èŠã«ãªããããã¯ã©ã€ã¢ã³ãåŽã«è»¢éããå¿ èŠããããŸãã ããã¯ãWindowsçšã®WinSCPãŸãã¯Linuxçšã®æšæºscpã³ã³ãœãŒã«ã¯ã©ã€ã¢ã³ãã®SCPã¯ã©ã€ã¢ã³ãã䜿çšããŠå®è¡ã§ããŸãã
次ã«ããµãŒããŒã®ã»ããã¢ããã«ç§»åããŸãã
set interfaces openvpn vtun0 mode 'server' set interfaces openvpn vtun0 server name-server '10.0.10.1' set interfaces openvpn vtun0 server push-route '10.0.10.0/24' set interfaces openvpn vtun0 server subnet '10.1.10.0/24' set interfaces openvpn vtun0 tls ca-cert-file '/config/auth/ca.crt' set interfaces openvpn vtun0 tls cert-file '/config/auth/t-rex-server.crt' set interfaces openvpn vtun0 tls dh-file '/config/auth/dh1024.pem' set interfaces openvpn vtun0 tls key-file '/config/auth/t-rex-server.key' set service dns forwarding listen-on vtun0 commit save
æåŸã®ã³ãã³ãã«æ³šç®ããŸãããããã®ã³ãã³ãã§ã¯ãåå解決èŠæ±ã以åã«æ§æããDNSãã©ã¯ãŒããŒã«ãªãã€ã¬ã¯ãããŸãã ãŸããOpenVPNã®å Žåãæåã«åå¥ã®ãããã¯ãŒã¯ã䜿çšããŠãã³ãã«èªäœãæ§ç¯ãããããããµãŒããŒãé 眮ãããŠããããŒã«ã«ãããã¯ãŒã¯ã«ã«ãŒãã£ã³ã°ããããšã«ã泚æããŠãã ããã ããã¯ããããã³ã«æ©èœã«ãããã®ã§ãã ããã«ã€ããŠã¯ã次ã®åºçç©ã§è©³ãã説æããŸãã
PPTPãµãŒããŒã®ã»ããã¢ãã
VPNæ¥ç¶ã®æåŸã®ã¿ã€ã-PPTPãã»ããã¢ããããŸãã ãã¡ãããPPTPã¯ä¿è·ã匱ããããæ©å¯æ å ±ã®éä¿¡ã«ã¯ã»ãšãã©äœ¿çšã§ããŸãããããªã¢ãŒãã¢ã¯ã»ã¹ã®æäŸã«ã¯åºã䜿çšãããŠããŸãã PPTPã¯ã©ã€ã¢ã³ãã¯ããããã¯ãŒã¯æ¥ç¶ãæã€ã»ãšãã©ãã¹ãŠã®ããã€ã¹ã«ååšããŸãã
äžèšã®äŸãããPPTPãL2TPãšã»ãŒåãæ¹æ³ã§æ§æãããŠããããšãããããŸãã
set vpn pptp remote-access authentication mode local set vpn pptp remote-access authentication local-users username <_> password <> set vpn pptp remote-access client-ip-pool start 10.0.10.31 set vpn pptp remote-access client-ip-pool stop 10.0.10.40 set vpn pptp remote-access dns-server server-1 188.93.17.19 set vpn pptp remote-access outside-address 95.213.170.75
æåã®ã³ãã³ãã§ã¯ãããŒã«ã«ãŠãŒã¶ãŒèªèšŒã¢ãŒããèšå®ããŸãã RADIUSãµãŒããŒãããå ŽåãRADIUSèªèšŒã¢ãŒããéžæã§ããŸããRADIUSãµãŒããŒã䜿çšããŠãŠãŒã¶ãŒã¢ã«ãŠã³ãã管çããæ¹ãã¯ããã«äŸ¿å©ã§ãã
次ã«ãããŒã«ã«ãŠãŒã¶ãŒãäœæããã¯ã©ã€ã¢ã³ãã«çºè¡ãããDNSãµãŒããŒã®IPã¢ãã¬ã¹ãšããŒã¿ã®ç¯å²ãæå®ããŸãã æåŸã®ã³ãã³ãã¯ããµãŒããŒãããªãã¹ã³ãããã€ã³ã¿ãŒãã§ãŒã¹ã®ã¢ãã¬ã¹ãèšå®ããŸãã
èšå®ãé©çšããŠä¿åããŸãã
commit save
ãµãŒããŒã¯ã¯ã©ã€ã¢ã³ããæ¥ç¶ããæºåãã§ããŠããŸãã
ããŒã«ã«ãããã¯ãŒã¯ããå€éšãžã®ãã©ãã£ãã¯ã®ééãèš±å¯ããããã ãã«æ®ããŸãã ãããã£ãŠãããŒã«ã«ãããã¯ãŒã¯ã«æ¥ç¶ãããŠãããµãŒããŒãããã³ãã©ã³ãããã«ãŒã¿ãŒã«æ¥ç¶ããŠãããŠãŒã¶ãŒãžã®ã€ã³ã¿ãŒãããã¢ã¯ã»ã¹ãæäŸããŸãã
set nat source rule 1 outbound-interface 'eth0' set nat source rule 1 source address '10.0.10.0/24' set nat source rule 1 translation address masquerade
ãããã«
ããã§æºåã¯å®äºã§ããã¿ã¹ã¯ã®æ¡ä»¶ã«åŸã£ãŠãããã¯ãŒã¯ãæ§ç¯ããŸããã ãµãŒããŒã®1ã€ïŒãµã³ã¯ãããã«ãã«ã¯ã«ããïŒã¯ã«ãŒã¿ãŒãšããŠæ©èœããä»ã®3ã€ã®ãµãŒããŒã¯ããŒã«ã«ãããã¯ãŒã¯ãä»ããŠæ¥ç¶ãããŠããŸãã ãã©ã³ãã«ãŒã¿ãŒã¯ãå®å šãªVPNæ¥ç¶ãä»ããŠããŒã«ã«ãããã¯ãŒã¯ãªãœãŒã¹ã«ã¢ã¯ã»ã¹ã§ããŸãã
ãã®çãã¬ãã¥ãŒã§ã¯ãå°èŠæš¡ãªäŒæ¥ãããã¯ãŒã¯ã®æ§ç¯ã®åºæ¬ã®ã¿ã説æããŸããã 次ã®åºçç©ã§ã¯ãVyOSã®æ©èœã«ã€ããŠè©³ãã説æãããã¡ã€ã¢ãŠã©ãŒã«ã«ãŒã«ãããæè»ã«ç®¡çããããŒãã転éããäŒæ¥ãããã¯ãŒã¯ã§ãã䜿çšãããããŸããŸãªãããã³ã«ã®ãã©ãã£ãã¯ãèš±å¯ãã次ã®åé¡ã«ã€ããŠãæ€èšããŸãã
- GREãã³ãã«ã®ç·šæã
- L2TPv3ãããã³ã«ã§åäœããŸãã
- QoS;
- ãŸãŒã³ããŒã¹ã®ãã¡ã€ã¢ãŠã©ãŒã«ã
- ãããã¯ãŒã¯ã€ã³ã¿ãŒãã§ã€ã¹ã®ããã©ãŒãã³ã¹ãåäžãããŸãïŒããã©ãŒãã³ã¹ãã¥ãŒãã³ã°ïŒã
- VRRP