ãã®èšäºã§ã¯ãDreamkasãã³ããŒã®ãã£ãã·ã¥ãã¹ã¯ãšpfSenseã«ãŒã¿ãŒãOpenVPNãä»ããŠ1CãµãŒããŒãšé£æºããå ¬éãã£ã³ãã«ãä»ããŠïŒTLS / SSLã䜿çšããŠïŒæå·åãããèšå®äŸãæ€èšããŸãã
ã¿ã¹ã¯ïŒå€ãã®åºèã«å€ãã®ãã£ãã·ã¥ãã¹ã¯ãããããªãã£ã¹ã«1CãµãŒããŒããããŸãã çžäºäœçšãæ§æããå¿ èŠããããŸãã 1Cã®ã»ããã¢ããã¯è¡ããŸããããpfSenseã«ãŒã¿ãŒã®OpenVPNãšãããã¯ãŒã¯ã®æ§ç¯ã«éç¹ã眮ããŠããŸãã ç§ã®èšäºã«ã¯ã¬ãžã®è©³çŽ°ãªèª¬æã¯ãããŸããã
é ç®1.ãœãããŠã§ã¢ãçŸåšã®ããŒãžã§ã³ã«æŽæ°ãã
pfSenseããŒãžã§ã³ã¯ã¡ã€ã³ããŒãžã§è¡šç€ºã§ããåãå Žæã§æåéã3ã¯ãªãã¯+ 1åã®åèµ·åã§æŽæ°ãããŸãã
ãã£ãã·ã£ãŒã®ããŒãžã§ã³ã¯ããã£ãã·ã£ãŒèªäœã®ãèšå®ãã¡ãã¥ãŒããèªåçã«æŽæ°ã§ããŸãã å€æ°ã®ã¢ããã°ã¬ãŒããªãã·ã§ã³ãããããããã¯è£œé å ã®Webãµã€ãã«ãªã¹ããããŠããŸãã
OpenVPNã®åé¡ãæå°éã«æããã«ã¯ãäž»ã«ãœãããŠã§ã¢ã®æŽæ°ãå¿ èŠã§ãã pfSenseã®ç°ãªãããŒãžã§ã³ã§openVPNãæäœããããã®ããã¥ã¢ã³ã¹ãããããŸããã äžèŠãªåé¡ãã身ãå®ããŸãã OpenVPNã¯æ¯èŒçæè¿ãèè¡åå ¥ã«ãç»å ŽããŸããã
ãã€ã³ã2. CA蚌ææžãæžãåºã
System-> Cert.Manager-> Caã«ç§»åããAddãã¿ã³ãã¯ãªãã¯ããŠãã£ãŒã«ãã«å ¥åããŸãã
ç§ã¯ãã£ãŒã«ãã«æ³šç®ããŸãïŒ
-蚌ââææžããŸã æºåããŠããªãå Žåã¯ã[ å éšãäœæ]ãéžæããŸã
- ã©ã€ãã¿ã€ã ïŒæ¥ïŒ -CA蚌ææžã®ã©ã€ãã¿ã€ã
- å ±éå -ããã¯ãèšå®ã§ããã«è¡šç€ºãããæ¹æ³ã§ãã
æå³çã«ããŒã¿ãå ¥åãããšãå€æŽããããšã¯ã§ããŸããã
ãã€ã³ã3.ãµãŒããŒèšŒææžãæžãåºã
[ã·ã¹ãã ]â[蚌ææžãããŒãžã£ãŒ]â[蚌ææž]ã«ç§»åãã[è¿œå ]ãã¯ãªãã¯ããŠãã£ãŒã«ãã«å ¥åããŸãã
次ã®ç¹ã«æ³šæãåŒããŸãã
-蚌ââææžã®æºåãã§ããŠããªãå Žåã¯å éšãäœæããŸã
- èªèšŒå± -ãã€ã³ã1ã§äœæãããCA蚌ææžãéžæããŸã
- 蚌ææžã¿ã€ãéžæãµãŒããŒ
- 寿åœïŒæ¥ïŒ -ãµãŒããŒèšŒææžã®å¯¿åœ
- å ±éå -ããã¯ãèšå®ã§ããã«è¡šç€ºãããæ¹æ³ã§ãã
ãã€ã³ã4.ã¯ã©ã€ã¢ã³ã蚌ææžãæžãåºã
éèŠïŒ ã¯ã©ã€ã¢ã³ãããšã«-åå¥ã®èšŒææžïŒ [ã·ã¹ãã ]â[蚌ææžãããŒãžã£ãŒ]â[蚌ææž]ã«ç§»åãã[è¿œå ]ãã¯ãªãã¯ããŠãã£ãŒã«ãã«å ¥åããŸãã ã¯ã©ã€ã¢ã³ããéžæãã蚌ææžã¿ã€ããé€ãããã¹ãŠãé ç®3ãšåæ§ã§ãã
次ã®ç¹ã«æ³šæãåŒããŸãã
- èªèšŒå± -ãã€ã³ã1ã§äœæãããCA蚌ææžãéžæããŸã
- 蚌ææžã¿ã€ã㯠ã¯ã©ã€ã¢ã³ããéžæããŸã
- 寿åœïŒæ¥ïŒ -ãµãŒããŒèšŒææžã®å¯¿åœ
- å ±éå -ããã¯ãèšå®ã§ããã«è¡šç€ºãããæ¹æ³ã§ãã
-[ 代æ¿å]ãã£ãŒã«ãã䜿çšã§ããŸããããããäœã§ãããããããªãå Žåã¯å¿ èŠãããŸããïŒç©ºçœã®ãŸãŸã«ããŸãïŒã äžè¬ã«ããã®ãã£ãŒã«ãã§ã¯ãopenVPNã¯ã©ã€ã¢ã³ãã®è¿œå ã®èšå®ãšãã€ã³ãã£ã³ã°ãæå®ã§ããŸãã
-
ç§ã®çµéšãå ±æããŸã-mag.address.kassanomerã®åœ¢åŒã§ã äžè¬åã§æ å ±ã«åºã¥ããååãä»ããŸã -ããã«ããã蚌ææžãäºãã«èŠèŠçã«åºå¥ãããŸãã
ãã€ã³ã5. OpenVPNãæ§æãã
ããã§ã¯ãã¹ãŠãç°¡åã§ãã pfSenseã®ãã¹ãŠã¯ããŠãŒã¶ãŒãã¬ã³ããªãŒãªã€ã³ã¿ãŒãã§ã€ã¹ãä»ããŠããŠã¹ã§æ§æãããŸãã éçºè ãšãã¹ãŠã®ã³ãã¥ããã£ã¡ã³ããŒã«æè¬ããŸãã
VPNâOpenVPNâãµãŒããŒã«ç§»åãããµãŒããŒãè¿œå ããŸãã
ã³ã¡ã³ããããŸãã
-ç§ã¯ã¿ãããã³ãã«ã§äœæ¥ããŸããç§ã«ãšã£ãŠã¯ãã䟿å©ã§ãL2ã¬ãã«ãæš¡å£ããŠããŸãã ããããçš®é¡ã®ãã«ããã£ã¹ãããããŒããã£ã¹ããªã©ã
-UDPã¯TCPãããé«éã§ãããåãæ¡ä»¶äžã§ã®ãã£ãã«å¹ ã¯å€§ãããªããŸãã ããã¯å€ä»£ã®OpenVPNã®åé¡ã§ãã
- ãµãŒããŒã¢ãŒã ã»ã¯ã·ã§ã³ã§RemoteAccess ã¢ãŒããéžæããŸãã
-ãªã¹ããã[ ãã¢èªèšŒå±]ã»ã¯ã·ã§ã³ã§CA蚌ææžãéžæããŸãã
-[ãµãŒããŒèšŒææž]ã»ã¯ã·ã§ã³ã§ãµãŒããŒèšŒææžãéžæããŸãã
-DHãã©ã¡ãŒã¿ã®é·ãïŒãããïŒã»ã¯ã·ã§ã³ã§ç®çã®é·ããéžæããŸãã
-[ 蚌ææžã®æ·±ã]ã»ã¯ã·ã§ã³ã§[1ïŒã¯ã©ã€ã¢ã³ã+ãµãŒããŒïŒ]ã¢ãŒããéžæããŸããããã¯ã仲ä»è ãèªèšŒããªãã¹ããŒã ã§ãã
-[ IPv4ãã³ãã«ãããã¯ãŒã¯]ã»ã¯ã·ã§ã³ã§ããã³ãã«ãããã¯ãŒã¯ãããšãã°192.168.202.0/24ãèŠå®ããŸãã
-IPv4ããŒã«ã«ãããã¯ãŒã¯ïŒsïŒã»ã¯ã·ã§ã³ã§ã¯ããã±ãããªãã£ã¹ãåãåãã¹ãã«ãŒãã£ã³ã°ããªãœãŒã¹ãèŠå®ããŠããŸãã ç§ã«ãšã£ãŠããã¯ãããšãã°192.168.100.2/32ã192.168.1.0/24ã§ãã
-æ®ãã¯è§Šããã«æ®ãããšããèªåã®å€æã§èšå ¥ããããšãã§ããŸãã OpenVPNãµãŒããŒããã³ã°ãããã¡ã€ã¢ãŠã©ãŒã«ããŒããéãããšãå¿ããªãã§ãã ããã
éèŠïŒ
ãã±ãããªãã£ã¹ã¯ãµãŒããŒã«ããã¿ã€ãã IPv4ãã³ãã«ãããã¯ãŒã¯ç¯å²ããã¢ãã¬ã¹ãåãåããŸããã¢ãã¬ã¹ã¯æ¥ç¶é ã«çºè¡ãããŸãã ãã ãã1CãµãŒããŒã¯ãããã®ãããªãã§ãã¯ã¢ãŠãããããã®ãããªç¹å®ã®ã¢ãã¬ã¹ãã«ããããšãåžžã«ç¥ã£ãŠããå¿ èŠããããŸãã ãããã£ãŠãããã«æ§æããŸãã
VPNâOpenVPNâã¯ã©ã€ã¢ã³ãåºæã®äžæžããè¿œå ãã¿ã³ã«ç§»åããŸãã ç¹å®ã®ã¯ã©ã€ã¢ã³ãã®èšå®ãäœæããå¿ èŠããããŸãã åã¯ã©ã€ã¢ã³ãã®IPã¢ãã¬ã¹ããã€ã³ãããŸã
ã¢ã«ãŽãªãºã ã¯æ¬¡ã®ãšããã§ãã
- ãµãŒããŒãªã¹ãã§ãµãŒããŒãéžæããŸã
- å ±éåã¯ã第4é ããã®ã¯ã©ã€ã¢ã³ã蚌ææžã®ååãç»é²ããŸã
-[ 詳现èšå®]ã»ã¯ã·ã§ã³ã§ãIPã¢ãã¬ã¹å²ãåœãŠã³ãã³ããèšè¿°ããŸã
ifconfig-push 192.168.202.12 255.255.255.0
ãã€ã³ã6. pfSense蚌ææžã§ã¢ããããŒããã
次ã®ãã¡ã€ã«ãã¢ã³ããŒãããå¿ èŠããããŸãã
1ïŒCA蚌ææž
2ïŒã¯ã©ã€ã¢ã³ã蚌ææž+ããŒ
3ïŒSSL / TLSãããå Žåã¯ãããŒãä¿åããŸã
4ïŒdhãã©ã¡ãŒã¿ãŒ
ã¢ã€ãã 1ïŒããã³2ïŒã¯ãWebã€ã³ã¿ãŒãã§ãŒã¹ãä»ããŠãšã¯ã¹ããŒããããŸãã
3ïŒã®ãã¡ã€ã«ã¯ãOpenVPNãµãŒããŒã®èšå®ãããšã¯ã¹ããŒããããŸãã ãã§ã«äœæããŠããå Žåã¯ãããŒãç»é²ããŠãã ããã ã³ããŒãããã¡ã€ã«ã«è²Œãä»ããŠãããšãã°client.tls-authãã¡ã€ã«ã«ä¿åããŸãã
DHãã©ã¡ãŒã¿ã¯æ¬¡ã®ã³ãã³ãã§ä¿åãããŸãã
/usr/bin/openssl dhparam 1024 > /etc/dh1024.pem /usr/bin/openssl dhparam 2048 > /etc/dh2048.pem /usr/bin/openssl dhparam 4096 > /etc/dh4096.pem
[蚺æ]-> [ãã¡ã€ã«ã®ç·šé]ã¡ãã¥ãŒã§ãå¿ èŠãªãã¡ã€ã«ïŒããšãã°dh1024.pem ïŒãéããŸããDHèšå®ã¯OpenVPNãµãŒããŒèšå®ã§æå®ãããŸãã
é ç®7.äžè¬çãªéçºçš
TLS / SSLãã»ããã¢ãããããšããã¯ã©ã€ã¢ã³ãã®èšå®ã«äœãæžãã°ããã®ãã»ãšãã©ããããŸããã§ãããOpenVPNã«ã€ããŠã®ç¥èã¯ã»ãšãã©ãããŸããã§ããã ãœãªã¥ãŒã·ã§ã³ãçæ£é¢ããè©ŠããŸãã-ã¯ã©ã€ã¢ã³ãæ¥ç¶ãå¥ã®pfSenseã¢ãŒãã§æ§æããã¯ã©ã€ã¢ã³ã蚌ææžãã¢ããããŒããããã®åäœã確èªããŸããã ã«ãŒã¿ãŒã¯Webã€ã³ã¿ãŒãã§ãŒã¹ãä»ããŠèšå®ãããæ¥ç¶ã¯é£ãããããŸããã§ããã
pfsense管çã³ã³ãœãŒã«ã®ãããã§ãOpenVPNã®èšå®ã/ var / etc / openvpnãã©ã«ããŒã«ããããšãããããŸãã ã ãã¡ã€ã«ã®ç·šéã䜿çšãããšãWebã€ã³ã¿ãŒãã§ãŒã¹ã®ãã§ãã¯ããŒã¯ãšãã©ã¡ãŒã¿ãŒã®ãªã³/ãªãããã¡ã€ã«ã«ã©ã®ããã«æžã蟌ãŸãããã確èªã§ããŸãã åæã«ãããŒãã®ããããšãã§ããŸãã
åãããšãè¡ãå Žåã¯ãOpenVPNã¯ã©ã€ã¢ã³ããšèšŒææžããã¹ããµãŒããŒããåé€ããããšãå¿ããªãã§ãã ããã
ã¢ã€ãã 8.ãã£ãã·ã¥ãã¹ã¯ã®ã»ããã¢ãã
ãã£ãã·ã¥ãã¹ã¯ã§ã¯ãããã©ã«ãã§ã\\ ipaddress \ exchangeãšããååã®smbãã©ã«ããŒãéããŠãããæžã蟌ã¿ã¢ã¯ã»ã¹æš©ããããŸãã ã¢ã€ãã 6ãã4ã€ã®ãã¡ã€ã«ãã¹ãŠãã¢ããããŒãããŸãã
SSHçµç±ã§ãã§ãã¯ã¢ãŠããæšæºã®ããã©ã«ãã«ãŒãã¢ã«ãŠã³ã/ 324012ã«æ¥ç¶ã ããã¡ã€ã«ã/ opt / networksã«è»¢éããŸãã ã¯ããããã€ãã®LinuxãæèŒãããŠããŸãã
ãµãŒããŒã«æ¥ç¶ããã«ã¯ã client.ovpnãã¡ã€ã«ãå¿ èŠã§ãã ã¹ããã 7ã§ç¢ºèªããããŒãºã«åãããŠç·šéã§ããŸãã åãå Žæã«çœ®ã-/ opt / networksã ç§ã¯ãã®ãããªãã®ãåŸãŸããïŒ
client dev tap proto udp remote server_ip server_port keepalive 10 60 ping-timer-rem persist-tun persist-key cipher AES-128-CBC auth SHA1 resolv-retry infinite nobind persist-key persist-tun ca "//opt//networks//CAforOpenVPN.crt" cert "//opt//networks//mag.magaddress.kassa1.crt" key "//opt//networks//mag.magaddress.kassa1.key" dh "//opt//networks//dh1024.pem" tls-client tls-auth "//opt//networks//client.tls-auth" 1 ns-cert-type server verb 3
ãã¡ã€ã«ãä¿åãããŸãã ãã§ãã¯ã¢ãŠãããªããŒããããšãããšãã°rebootã«ãã£ãŠãã¹ãŠãæ©èœããŸãã ãµããããã®pfSenseã§openVPNã€ã³ã¿ãŒãã§ã€ã¹ã«ã«ãŒã«ãèšå®ããããšãå¿ããªãã§ãã ããïŒ
ãã±ãããªãã£ã¹ãæ©èœããŠããããšãèŠèŠçã«ç¢ºèªããæ¹æ³ïŒæ¥ç¶ïŒ
ãªãã·ã§ã³1-pfSenseã¡ã€ã³ããŒãžã«OpenVPNãŠã£ãžã§ãããé 眮ãã
ãªãã·ã§ã³2-ã¡ãã¥ãŒã¹ããŒã¿ã¹-> OpenVPNãã
ãªãã·ã§ã³3-ãã£ãã·ã£ãŒãéããŠã sshãä»ããŠæ¥ç¶ãã次ã«æšæºã»ãã-ifconfigãpingãªã©ãæ¥ç¶ããŸã...
ã¢ã€ãã 9. 1Cã®äœ¿çšæ¹æ³
smb-folderã®ãã£ãã·ã¥ãã¹ã¯ã«ã¯ãäœæ¥ææãä¿ç®¡ãããŠããŸãã ãµãŒããŒ1Cã¯ããããèªã¿åããæžã蟌ã¿ãŸãã åºèãããã¯ãŒã¯ãèšèšãããšãã¯ãæ å ±ã»ãã¥ãªãã£ã®ãã®ç©Žã«çæããŠãã ããã
çµæãšããŠ
ãã®èšäºã§ã¯ãç¡æã®pfSenseã«ãŒã¿ãŒãšå€ãã®LinuxããŒã¹ã®ãã£ãã·ã¥ã¬ãžã¹ã¿ã䜿çšããŠãæ°åã¯ãªãã¯ããã ãã§èšå®ããããªã¢ãŒã1CãµãŒããŒãžã®é©åãªæå·åãã³ãã«ãäœæããæ¹æ³ã®äŸã説æããŸãã
説æããæ§æãªãã·ã§ã³ã§ã¯ãåãªã¢ãŒãããã€ã¹ã®å人蚌ææžãåãããã£ãã·ã¥ãã¹ã¯ã®éåžžã«ã¹ã±ãŒã©ãã«ãªæ¥ç¶ã¹ããŒã ãååŸããŸãã
ãã§ãã¯ã¢ãŠãæã«OpenVPNãçŽæ¥äœ¿çšãããšãããŒã¿è»¢éã«é¢é£ããæ å ±ã»ãã¥ãªãã£ãªã¹ã¯ãç¡é¢ä¿ã«ãªããŸãã
å°ããªã¢ãŠãã¬ãããããå Žåã¯ããããããããã¯ãŒã¯ãæ§ç¯ããå¿ èŠã¯ãããŸããã 3GããµããŒãããã«ãŒã¿ãŒãè³Œå ¥ããã€ã³ã¿ãŒããããéå§ããŸã-ãã±ãããªãã£ã¹ã¯ã±ãŒãã«ãŸãã¯Wi-Fiçµç±ã§ãããåä¿¡ãããµãŒããŒèªäœãããã¯ããŸãã ç§ã®èŠæš¡ã§ã¯ãããã¯ãããã¯ãŒã¯ã€ã³ãã©ã¹ãã©ã¯ãã£ã®å€§å¹ ãªç¯çŽã«ãªããŸãã
䟿å©ãªãªã³ã¯
pfSenseã«ã€ããŠ
OpenVPN PKIïŒãµã€ãéãã£ã¹ã«ãã·ã§ã³ã¬ã€ã
補é å ããã®æ瀺ãTLS / SSLããã³æå·åãªã
ã©ããããããšãã