ããã¥ã¢ã«ãèŠã€ãããªãã£ãã®ã§ãèªåã§ãããææ¡ããWindows Server + OpenVPN + Android OpenVPN Clientã«åºã¥ããAmazon EC2ãäœæãããã£ãã®ã§ãã
è¡ããïŒ
ãã®èšäºã¯åå¿è åãã§ã¯ãªããããäžè¬çãªè³ªåãããã€ããããŸããã
Amazon AWSã§ã®ç»é²ããã»ã¹ã«ã€ããŠã¯èª¬æããŸãã-ç°¡åã§ãã ç§ã¯åã«ç»é²ããªãã£ãã®ã§ãé»è©±çªå·ã«ç¢ºèªãæ¥ãããšã«é©ããã å€åçªå·ãæžããŸãã ç»é²åŸã ããã·ã¥ããŒã https://console.aws.amazon.com/console/homeã«ã¢ã¯ã»ã¹ããŸã
ã¡ãã¥ãŒãµãŒãã¹ â èšç® â EC2 â ã€ã³ã¹ã¿ã³ã¹ãèžã¿ãŸãã [ Launch Instance]ãã¯ãªãã¯ããŠã ãŠã£ã¶ãŒããéããŸãã 䜿çšå¯èœãªAMIã®ãªã¹ãã§ã Microsoft Windows Server 2008 R2 Base-ami-59fc7439ãéžæããŸã
2çªç®ã®ã¹ãããã§ã¯ãå©çšå¯èœãªãªãã·ã§ã³t2.microïŒç¡æå©çšæ ïŒãéžæããŸã-ãã®æ©èœã¯ç§ãã¡ã«ãšã£ãŠåå以äžã®ãã®ã§ãã [ èµ·å ]ãã¯ãªãã¯ããã®ã¯æ¥ãã§ã¯ããŸããã[ 次ãžïŒã€ã³ã¹ã¿ã³ã¹ã®è©³çŽ°ãæ§æãã]ãã¯ãªãã¯ããŸãïŒããã©ã«ãã§VPCãæ§æããããã©ã«ãã®ãµããããããããKeyPairsãäœæãããŠãããšä»®å®ããŸã ãã¡ãªã¿ã«ãVPCããŒãããåæ§ç¯ãã1ã€ã®ãããã¯ãŒã¯ã®ã¿ãæ®ããŸãã10.100.11.0/24ïŒã
ããã©ã«ãã§ã¯èšå®ã¯ãã®ãŸãŸã§ããã[ ãããªãã¯IPã®èªåå²ãåœãŠ]ã[ æå¹]ã«èšå®ããŸãã 次ã«ã ãã¬ãã¥ãŒãšèµ·åãã¯ãªãã¯ããŸãã ã€ã³ã¹ã¿ã³ã¹ãäœæããããŸã§æ°ååŸ ã¡ãŸãã
å·ŠåŽã®ããã·ã¥ããŒãã§ã[ ãããã¯ãŒã¯ãšã»ãã¥ãªãã£] â[ ã»ãã¥ãªãã£ã°ã«ãŒã]ã»ã¯ã·ã§ã³ãéžæããŸãã ã€ã³ã¹ã¿ã³ã¹ã«é¢é£ä»ããããŠããã°ã«ãŒããéžæããŸãã 以äžã®[ åä¿¡]ã[éä¿¡]ã¿ãã§ã¯ ããã¹ãŠã®ãã©ãã£ãã¯ïŒalltraffïŒãééãããèš±å¯ãäžæçã«è¿œå ããŸãã
çŸåšãRDPã®ã¿ãèš±å¯ãããŠããŸãã æ¥ãã§ãã人ã¯ãäž¡æ¹ã®ã¿ãã§OpenVPNãšICMPã®ããŒã1194ãæå¹ã«ããããšãã§ããŸãã ã€ã³ã¹ã¿ã³ã¹ãäœæãããŠæ©èœããã®ã§ãæ¥ç¶ããå¿ èŠããããŸãã ã€ã³ã¹ã¿ã³ã¹ãéžæãã[ æ¥ç¶ ]ãã¯ãªãã¯ããŸã ã
.rdpãã¡ã€ã«ãããŠã³ããŒãããŠãã¹ã¯ãŒããååŸããããæ±ãããŠã£ã³ããŠã衚瀺ãããŸãã ããŠã³ããŒãã [ ãã¹ã¯ãŒããååŸ]ãã¯ãªãã¯ããŠãããŒãã¡ã€ã«ãæå®ãã埩å·åããŠããã¹ã¯ãŒããååŸããŸãã ã±ãŒã¹ã®ååãå®äºããŸããã RDPãéãããã¹ãã«æ¥ç¶ããŸãã
ç§ãã¡ã®åã«çŽç²ãªOSããããŸãã 次ã«äœãå¿ èŠã§ããïŒ
1. Google ChromeãããŠã³ããŒãããŠããã§ãã¯ãç°¡åã«ããŸãã
2. OpenVPNãããŠã³ããŒãããŸãã
3.ããã©ã«ãæ§æã§ãµãŒããŒãäžããŸãã
4. NATãäžããŸãã
IEçµç±ã§ããŠã³ããŒãããå¿ èŠãããå Žåãé€ããæåã®2ã€ã®ãã€ã³ãã«åé¡ã¯ãããŸããã å ¬åŒWebãµã€ãïŒMSIïŒããOpenVPNãããŠã³ããŒãããããã©ã«ãèšå®ã§èšå®ããŸããäœãå€æŽããªãã§ãã ããã
Chromeããipleak.netã«ã¢ã¯ã»ã¹ããŠãIPã確èªããŸãã 圌ã¯ç±³åœ/ãªã¬ãŽã³å·ã®ã©ããã«ããã§ãããã OpenVPNã®ãµãŒããŒèšŒææžãšã¯ã©ã€ã¢ã³ã蚌ææžã®äœææ¹æ³ã«ã€ããŠã¯èª¬æããŸããããã®ãããã¯ã«é¢ããè³æã¯ååã«ãããŸãã å¿ ãPAMãã¡ã€ã«ïŒDiffie-HellmanïŒãäœæããŠãã ãããäœæããªããšããµãŒããŒã¯èµ·åããŸããã
OKããã¹ãŠãããŠã³ããŒããããã€ã³ã¹ããŒã«ãããŸããã ãµãŒããŒã§ãµãŒããŒãããŒãžã£ãŒãéãã[ ãµãŒãã¹]ã»ã¯ã·ã§ã³ã«ç§»åããŸã ã OpenVPN Legacy ServiceãèŠã€ãããã®ããããã£ãéããŸã-Startup typeïŒ Automaticãæå®ããŠããµãŒãã¹ãéå§ããŸãã ããã¯ãã€ã³ã¹ã¿ã³ã¹ãåèµ·åããåŸã«OpenVPNãµãŒããŒãèªåçã«èµ·åããããã«å¿ èŠã§ãã
CïŒ\ Program Files \ OpenVPN \ configãéããŸã-CA.keyãserver.keyãta.keyãdh2048.pemã®ããŒãšãCAããã³ãµãŒããŒèšŒææžãããã«ããããããŸãã CïŒ\ Program Files \ OpenVPN \ sample-configãéããããããserver.ovpnãã¡ã€ã«ãCïŒ\ Program Files \ OpenVPN \ configã«ã³ããŒããŸãã
ãã®ãããªã³ã³ãã³ãã®æžãæãïŒ
ããŒã1194
ãããUDP
éçºè
ca ca.crt
cert server.crt
éµserver.key
dh dh2048.pem
ïŒVPNã®ä»®æ³ãããã¯ãŒã¯
ãµãŒããŒ172.10.10.0 255.255.255.0
ifconfig-pool-persist ipp.txt
ããŒãã¢ã©ã€ã10120
tls-auth ta.key 0ïŒãã®ãã¡ã€ã«ã¯ç§å¯ã§ã
æå·AES-256-CBC
æ倧ã¯ã©ã€ã¢ã³ãæ°100
æ°žç¶ããŒ
æç¶ãã
éçºããŒããHomeVPNã
#HomeVPNã¯ãOpenVPNã®ã€ã³ã¹ããŒã«ã«ãã£ãŠäœæãããTAPã§ãã 䟿å®äžååãå€æŽããŸãã
ïŒããã¯ããã¹ãŠã®ã¯ã©ã€ã¢ã³ããç¡çãªãã«ãŒãã£ã³ã°ã§ããããã«ããããã«å¿ èŠã§ãã
ãã«ãŒã0.0.0.0 0.0.0.0ããæŒããŸã
ïŒDNSãæå®ããŸãããããã¯å¿ é ã§ã¯ãããŸãã
push "dhcp-option DNS 8.8.8.8"
push "dhcp-option DNS 8.8.4.4"
åè©3
æ瀺ççµäºéç¥1
ä¿åããŸãã
ãµãŒããŒã®ã»ããã¢ãããå®äºããŸããã server.ovpnãéžæã ãã³ã³ããã¹ãã¡ãã¥ãŒãéãã ãã®èšå®ãã¡ã€ã«ã§[OpenVPNãéå§ ]ãéžæããŸã ã
ãã®åŸãã¿ãŒããã«ãéããããŠã³ããŒãããã»ã¹ãéå§ãããŸãã ãã¹ãŠãæ£ããè¡ããããšãæåŸã«åæåã·ãŒã±ã³ã¹å®äºã衚瀺ãããŸãã
ããã§ãã¯ã©ã€ã¢ã³ãæ¥ç¶ã«åé¡ããªãããã«ã1ã€ã®ããšãéžæããå¿ èŠããããŸããWindowsãã¡ã€ã¢ãŠã©ãŒã«ã§ãOpenVPNãã©ãã£ãã¯ãééãããŠããŒã1194ãèš±å¯ããã«ãŒã«ãäœæãããããã¡ã€ã¢ãŠã©ãŒã«ããªãã«ããã ãã§ãã ç§ã¯2çªç®ã®ã¢ã€ãã ãéžã³ãŸããã
ããã§ãã¯ã©ã€ã¢ã³ãæ§æãäœæããå¿ èŠããããŸãã ã¯ã©ã€ã¢ã³ãïŒAndroidïŒã«OpenVPN Clientãã€ã³ã¹ããŒã«ãããŠãããã¯ã©ã€ã¢ã³ããå«ããã¹ãŠã®å¿ èŠãªèšŒææžãšããŒãå©çšå¯èœã§ãããšæ³å®ãããŠããŸãã
ã¯ã©ã€ã¢ã³ãæ§æã¯æ¬¡ã®ãšããã§ãã
ã¯ã©ã€ã¢ã³ã
éçºè
ãããUDP
ãªã¢ãŒãxxx-xxx-xxx-xxx-xxx.us-west-2.compute.amazonaws.com 1194
ç¡éã®è§£æ±ºãšåè©Šè¡
ã«ãŒãã¡ãœããexe
ããã€ã³ã
æ°žç¶ããŒ
æç¶ãã
ca ca.crt
cert client.crt
ããŒclient.key
remote-cert-tlsãµãŒããŒ
tls-auth ta.key 1
æå·AES-256-CBC
auth SHA1
åè©3
ã«ãŒã0.0.0.0 0.0.0.0 vpn_gateway
AndroidåãOpenVPNã§ã¯ãèšå®ãã€ã³ããŒãããŸãã [ åºæ¬ ]ã¿ãã§ãèªèšŒã¿ã€ãã[ 蚌ææž ]ã«èšå®ããŸãã åºæ¬çã«ãã¹ã¯ãŒãã¯ãããŸããã [ ãµãŒããŒãªã¹ã ]ã¿ãã確èªããŸããAmazonãµãŒããŒãæå®ããå¿ èŠããããŸãïŒããŒã1194ãã¿ã€ãUDPïŒã [ IPã¢ãã¬ã¹ãšDNS ]ã¿ãã§ã[ èŠæ±ãã©ã¡ãŒã¿ãŒ ]ãªãã·ã§ã³ãèšå®ããå¿ èŠããããŸãã
IPv4ã® [ ã«ãŒãã£ã³ã° ]ã¿ã㧠ã[ ããã©ã«ãã«ãŒãã®äœ¿çš ]ãªãã·ã§ã³ãæå¹ã«ããå¿ èŠããããŸãã
èšå®ãä¿åããŸãã
ãµãŒããŒã«æ¥ç¶ããããšããŠããŸãã æ¥ç¶ã確ç«ãããŠããªãå Žåã¯ã ãããã¯ãŒã¯ãšã»ãã¥ãªã㣠â ã»ãã¥ãªãã£ã°ã«ãŒããšãã¡ã€ã¢ãŠã©ãŒã«ã確èªããŠãã ããã ãã¹ãŠãæ£åžžã§ããã°ã SUCCESSã衚瀺ãããIP VPNãããã¯ãŒã¯ã®ãããããåãåããŸãã ç§ã®å Žåãããã¯172.10.10.6/30ã§ãã
ã¯ã©ã€ã¢ã³ãäžã§ããã€ãã®ãµã€ããéãããšããŠããŸã...æ¥ç¶ãããããã§ããããµã€ãã¯éããŸããã
åé¡ã¯äœã§ããïŒ ãã€ã³ãã¯NATã§ãã
è¿œå ã®AMIãInternet GateãIP Elasticãããã³ãã®ä»ã®ã§ããããäœæããŠãAmazonã§NATãæ§æããæ¹æ³ã«é¢ãããããã¯ãŒã¯äžã®ããã¥ã¢ã«ããããŸãã ãããè¡ãå¿ èŠã¯ãããŸããã
ãã¹ãŠãã¯ããã«ç°¡åã§ãã
ãµãŒããŒã«æ»ãã ãããã¯ãŒã¯ããªã¹ãšã¢ã¯ã»ã¹ãµãŒãã¹ã®åœ¹å²ãäœæããŸã ã ããã«ã¯ã ã«ãŒãã£ã³ã°ãšãªã¢ãŒãã¢ã¯ã»ã¹ã®åœ¹å²ãå«ãŸããŸãã ã³ã³ããã¹ãã¡ãã¥ãŒãéãã[ æ§æãšæå¹å ]ãéžæããŸãã
æåŸã®é ç®ãéžæããŠãç¬èªã®æ§æãäœæããŸãã 次ã®ã¹ãããã§ãæåŸã®2ã€ã®é ç®ã NATããã³LANã«ãŒãã£ã³ã°ãéžæããŸã ã
ã«ãŒãã£ã³ã°ãšãªã¢ãŒãã¢ã¯ã»ã¹ â IPv4 â NATã®åœ¹å²ãæ¡åŒµããåŸã ã€ã³ã¿ãŒãã§ãŒã¹ãäœæããŸãïŒ LAN1-ã€ã³ã¿ãŒãããäžã§èŠãããã®ã ããããã£ã§ã ãããªãã¯ã€ã³ã¿ãŒãã§ã€ã¹ãèšå®ãããã®ã€ã³ã¿ãŒãã§ã€ã¹ã§NATãæå¹ã«ããŸã ã [ ã¢ãã¬ã¹ããŒã« ]ã¿ããéããŸãã è¿œå ãã¯ãªãã¯ããŸãã
ããã§ã¯ããããã¯ãŒã¯ã§ã¯ãªããã·ã³ã®IPã¢ãã¬ã¹ãã€ãŸããã·ã³ïŒipconfig / allïŒãè¿œå ããå¿ èŠããããŸã
ç§ã®ãããã¯ãŒã¯ã¯10.100.11.0/24ãVPNãããã¯ãŒã¯ã¯172.10.10.0/24 ããã·ã³ã®ã¢ãã¬ã¹ã¯10.100.11.20ã§ãã 10.100.11.20 ãæå®ããéå§ã¢ãã¬ã¹ãšãæå®ããçµäºã¢ãã¬ã¹ ã ãã¹ã¯255.255.255.0
ä¿åããŸãã
åãã¢ãŒãã§ã[ ã¢ãã¬ã¹ã®äºçŽ ]ãã¿ã³ãã¯ãªãã¯ããŸãã VPNã¯ã©ã€ã¢ã³ãã¢ãã¬ã¹ïŒæ¥ç¶æã¯172.10.10.6/30ã§ããïŒããã·ã³ã®ã¢ãã¬ã¹ãšãæ¥ç¶ãããå¿ èŠããããŸãã
è¿œå ãã¯ãªãã¯ããŸã
ãã®ãããªãã¯IPãäºçŽããŠ10.100.11.20ã«èšå®ããäžã®åã«172.10.10.6ãšèšè¿°ããŸã
[çä¿¡ãèš±å¯ãã]ãªãã·ã§ã³ã¯èšå®ããŸãã ã
ä¿åããŸãã
ããã§æåŸã®ã¹ããããæ®ããŸã-NATã«ãã1ã€ã®ã€ã³ã¿ãŒãã§ãŒã¹ãTAPãè¿œå ããŸãã ç§ã¯ãããHomeVPNãšåŒã³ãŸããã èšå®ã¯ãããŸããããã©ã€ããŒãã€ã³ã¿ãŒãã§ã€ã¹ã§ãã NATã¯èšå®ããŸããã
ãããã£ãŠã VPNããLANãžã® ã転éã ãååŸãããŸããïŒ172.10.10.6â10.100.11.20 ã
ã¯ã©ã€ã¢ã³ãã«åæ¥ç¶ããVPNãç«ã¡äžããã®ãåŸ ã£ãŠãipleak.netãéããŠç£èŠããŸãã
ã¯ã©ã€ã¢ã³ãã®IPã¢ãã¬ã¹ã¯ç±³åœ/ãªã¬ãŽã³å·ã«ãããWebRTCã®IPã¢ãã¬ã¹ã¯VPNãµãŒããŒã®IPã¢ãã¬ã¹ã衚瀺ããå¿ èŠããããŸãã 172.10.10.6 ã
ãããããªããããªãã¯æåããŸããã ããã§ãªãå Žåã¯ãããã€ãã®ã¹ãããã§ééããç¯ããããæ¥ãã§ããŸãã
çµè«ãšããŠã ããã·ã¥ããŒã â ãããã¯ãŒã¯ãšã»ãã¥ãªã㣠âã»ãã¥ãªãã£ã°ã«ãŒãã»ã¯ã·ã§ã³ã«é²ã¿ãŸã ã ã€ã³ã¹ã¿ã³ã¹ã«é¢é£ä»ããããŠããã°ã«ãŒããéžæããŸãã [ ã€ã³ããŠã³ã]ã[ã¢ãŠãããŠã³ã]ã¿ãã§ããã¹ãŠã®ãã©ãã£ãã¯ãééãããèš±å¯ãåé€ããŸãã RDPãå»ãã誰ããã£ãããšããªã人ã¯ãããŒã1194ã®ã«ãŒã«ãè¿œå ããICMPãæå¹ã«ããŸãã
ã·ã ã®å Žå-ããã ãã§ãã ããããšã
PS Windowsã¯ã©ã€ã¢ã³ãã§ã¯ãã¹ãããŠããŸãããããã¹ãŠã¯Androidäžãšåãã§ãããšæããŸãã