éåžžãVPNã®äœææã«ã¯ãç¹å®ã®ãµããããããã³ãã«ã«å²ãåœãŠãããŠãããã€ã³ãããŒãã€ã³ãæ¥ç¶ããµãŒããŒã«äœ¿çšãããããã€ãŒãµããããã³ãã«ããµãŒããŒã«ã€ã³ã¹ããŒã«ãããŸãã VPNãµãŒããŒã¯åæã«ããã©ãã£ãã¯ãã«ãŒãã£ã³ã°ããã³ãã£ã«ã¿ãªã³ã°ããæ©èœãå®è¡ããŠãVPNãä»ããŠããŒã«ã«ãããã¯ãŒã¯ã«ã¢ã¯ã»ã¹ããŸãã
ãã®èšäºã§ã¯ããªã¢ãŒãã·ã¹ãã ãæ¢åã®ããŒã«ã«ãµããããã«å«ãŸããVPNãµãŒããŒãã€ãŒãµãããã²ãŒããŠã§ã€ãšããŠæ©èœãããä»®æ³ãããã¯ãŒã¯ãäœæããå¥ã®ã¢ãããŒããæ€èšããŸãã ãã®ã¢ãããŒãã䜿çšãããšãæ¥ç¶æ¹æ³ã«åºã¥ããŠãã©ãã£ãã¯ããã£ã«ã¿ãªã³ã°ããæ©èœããŸã ãããŸãïŒããšãã°ãããŒã«ã«ãããã¯ãŒã¯ãšãªã¢ãŒããŠãŒã¶ãŒã«ç°ãªããã£ã«ã¿ãŒã䜿çšããŸãïŒãè¿œå èšå®ãªãã§ãããŒããã£ã¹ãã¡ãã»ãŒãžã䜿çšããŸãã ãã®VPNãä»ããŠãããŒã«ã«Windowsãããã¯ãŒã¯äžã®ãã¹ãŠã®ã³ã³ãã¥ãŒã¿ãŒãXDMCPãããŒããã£ã¹ãã䜿çšå¯èœãªãã¹ãŠã®XDMCPãµãŒããŒãªã©ã衚瀺ããŸãã
ãããã¯ãŒã¯æ§é ãšãµãŒããŒã®ã»ããã¢ãã
ããŒã«ã«ãããã¯ãŒã¯ã®ãããªãã£ã¹ããããšããŸããIPãµãããã192.168.168.0/24ã䜿çšãããŸãã ãã®ããŒã«ã«ãããã¯ãŒã¯ã«ã¯ãããŒã ãŠãŒã¶ãŒãå«ãŸããŸããã€ãŸããåããµããããã®ã¢ãã¬ã¹ãæã¡ãŸãã èªå® ã«ãã®ãµããããããªãããšãããã³ããŒã«ã«ãããã¯ãŒã¯äžã®ã·ã¹ãã ã«ãªã¢ãŒããŠãŒã¶ãŒã«å²ãåœãŠãç¯å²å ã®ã¢ãã¬ã¹ããªãããšã確èªããå¿ èŠããããŸãã
ã³ã¢ããªããžã®ãµããŒã
ãã®ææ³ãæ©èœããã«ã¯ãããã€ãã®ã«ãŒãã«ãã©ã€ããŒãå¿ èŠã§ãã ããã¯ããŠãããŒãµã«tunä»®æ³ãããã¯ãŒã¯ãã©ã€ããŒã§ãããã€ãŒãµãããããªããžãã©ã€ããŒã§ãã ããããã«ãŒãã«ã«å«ããããã¢ãžã¥ãŒã«ã§ã¢ã»ã³ãã«ã§ããŸãã
->ãããã¯ãŒãã³ã° ->ãããã¯ãŒãã³ã°ãµããŒãïŒNET [= y]ïŒ ->ãããã¯ãŒã¯ãªãã·ã§ã³ <*> 802.1d Ethenetããªããžã³ã°ïŒBRIDGE [= y]ïŒ ->ããã€ã¹ãã©ã€ã㌠->ãããã¯ãŒã¯ããã€ã¹ã®ãµããŒãïŒNETDEVICES [= y]ïŒ <*>ãŠãããŒãµã«TUN / TAPããã€ã¹ãã©ã€ããŒã®ãµããŒãïŒTUN [= y]ïŒ
ã¢ãžã¥ãŒã«ã«ãã£ãŠçµã¿ç«ãŠãããŠããå Žåãã«ãŒãã«ã§ã¢ãžã¥ãŒã«ã®èªåããŒããæå¹ã«ããããVPNæ¥ç¶ãã»ããã¢ããããåã«èªåã§ããŒãããå¿ èŠããããŸãã
ãœãããŠã§ã¢
ãµãŒããŒã¯ãããªããžã«ãµãŒãã¹ãæäŸããããã«OpenVPNãšãŠãŒãã£ãªãã£ãå¿ èŠãšããŸãã Gentooã§ã¯ã次ã®ããã«çµã¿ç«ãŠãããŸãã
emerge net-misc / bridge-utils net-misc / openvpn
> = sys-apps / baselayout-1.12.6ã䜿çšããå Žåã¯ããã§ååã§ããå€ãããŒãžã§ã³ã§ã¯ãtunããã€ã¹ãã¿ãããŸãã¯ã¿ããããããã«ç¹å¥ãªãŠãŒãã£ãªãã£ãå¿ èŠã§ãã
emerge sys-apps / usermode-utilities
ãããã¯ãŒã¯èšå®
eth2ãããŒã«ã«ãããã¯ãŒã¯ãæ¥ç¶ãããŠããã€ã³ã¿ãŒãã§ã€ã¹ã§ãããå²ãåœãŠãããã¢ãã¬ã¹192.168.168.254ã§ãããšããŸãã 圌ã®ã»ããã¢ããã¯æ¬¡ã®ããã«ãªããŸããã
config_eth2 =ïŒ "192.168.168.254/24"ïŒ
圌ã¯ããªããžã«åå ãããããã¢ãã¬ã¹ãå²ãåœãŠãå¿ èŠã¯ãããŸããã ãŸããæ°ããäœæãããä»®æ³ã€ã³ã¿ãŒãã§ã€ã¹tap0ã¯ããªããžã«é¢ä¿ããããªããžã«ãã¢ãã¬ã¹ãå²ãåœãŠãããŠããŸããã eth2ã䜿çšããã¢ãã¬ã¹ã¯ãbr0ããªããžã«å²ãåœãŠãããŠããŸãã
config_eth2 =ïŒ "null"ïŒ tuntap_tap0 = "ã¿ãã" config_tap0 =ïŒ "null"ïŒ depend_br0ïŒïŒ{ net.tap0 net.eth2ãå¿ èŠã§ã } ïŒæ¢åã®ã€ã³ã¿ãŒãã§ãŒã¹ãæå®ããããããããªããžã«çµå bridge_br0 = "eth2 tap0" ïŒã©ã¡ãããããã«æ°ããçŸããã€ã³ã¿ãŒãã§ãŒã¹ãåçã«æ¥ç¶ã§ããŸã ïŒbridge_add_eth2 = "br0" config_br0 =ïŒ "192.168.168.254/24"ïŒ
ãŸããæå®ãããã€ã³ã¿ãŒãã§ã€ã¹ã®æ§æã¹ã¯ãªãããäœæããå¿ èŠããããŸãã
cd /etc/init.d ln -s net.lo net.eth2 ln -s net.lo net.tap0 ln -s net.lo net.br0
br0ã€ã³ã¿ãŒãã§ãŒã¹ã®ã¿ãèªåçã«ããŒãããã ãã§ååã§ãã depend_br0ïŒïŒã¯ãåäœã«å¿ èŠãªä»ã®ãã¹ãŠãèªåçã«çºçãããŸãã
rc-update add net.br0 default /etc/init.d/net.eth2 stop /etc/init.d/net.br0 start
OpenVPNããŒã®äœæ
OpenSSLã®RSAããŒã䜿çšããŠã¯ã©ã€ã¢ã³ããæ¿èªããŸãã ããã»ã¹ãç°¡çŽ åããããã«ãããã€ãã®åæåã¹ã¯ãªãããçšæããŸããã
cd / usr / share / openvpn / easy-rsa /
äžè¬çãªå€ãè¿œå ããvarsãã¡ã€ã«ããããŸãã
ããããŒ
ãã®ãã¡ã€ã«ã®æåŸã«ãå€æ°ãå ¥åããŸãã
ãšã¯ã¹ããŒãKEY_COUNTRY = "RU" export KEY_PROVINCE = "Voronezh oblast" ãšã¯ã¹ããŒãKEY_CITY = "Boguchar" export KEY_ORG = "OrganiZationnAme" export KEY_EMAIL = "root@oza.ru"
ãã®ãã¡ã€ã«ããå€æ°ãããŒãããCAïŒèªèšŒå±ïŒãæ§ç¯ããŸãã
ãœãŒã¹./vars ./clean-all ./build-ca
ãµãŒããŒããŒ
officeãšããååã®ãµãŒããŒããŒãçæããã«ã¯ã次ã®ã³ãã³ãã䜿çšããŸãã
./build-key-server office
ãCommon Nameããšãã質åã«ã¯ããµãŒããŒåïŒãã®å Žåã¯officeïŒã§çããå¿ èŠããããŸãã ã蚌ææžã«çœ²åããŸããïŒãã®æåŸã®2ã€ã®è³ªå [y / n]ãããã³ã1ã€ã®èšŒææžèŠæ±ã®ãã¡1ã€ãèªèšŒãããã³ãããããŸããïŒ [y / n]ãçããŸããy "ã
å¿ èŠã«å¿ããŠãè¿œå ã®ãµãŒããŒããŒãäœæã§ããŸãã ããšãã°ãã·ã¹ãã ã®ä¿¡é Œæ§ãé«ããããã¯ã¢ããã¢ã¯ã»ã¹ãµãŒããŒã«ããããšãã§ããŸãã ãããã¯ããœãŒã¹./varsãå®è¡ããå¿ èŠãããåã«ãåãã³ãã³ãã«ãã£ãŠäœæãããŸãã
Diffie Hellmanãã©ã¡ãŒã¿ãŒ
ããã§è¿œå ããããšã¯ãããŸããããåŸ ã€å¿ èŠããããŸãã
./build-dh
ãã®ãã¡ã€ã«ã¯ãµãŒããŒäžã§ã®ã¿å¿ èŠã§ãã
顧客ããŒ
åã¯ã©ã€ã¢ã³ãã¯ãç¬èªã®ããŒãæäŸããå¿ èŠããããŸãã clientãšããååã®ã¯ã©ã€ã¢ã³ãã®å ŽåãããŒã¯ã³ãã³ãã«ãã£ãŠäœæãããŸã
./build-keyã¯ã©ã€ã¢ã³ã
ãCommon Nameããšãã質åã«ã¯ãã¯ã©ã€ã¢ã³ãïŒãã®å Žåã¯ã¯ã©ã€ã¢ã³ãïŒã®ååã§åçããŸãã æåŸã«ãåæããŠ2ã€ã®è³ªåã«çããŸãã
çæãããããŒãšèšŒææžãå®å šãªãã£ãã«ãä»ããŠã¯ã©ã€ã¢ã³ãã«éä¿¡ããŸãã å¿ èŠã«å¿ããŠãåãã³ãã³ãã§ããã«ããŒãäœæã§ããŸãã éå§ããåã«ãç°å¢ãããŒãããå¿ èŠããããŸã-source ./varsãå®è¡ããŸãã
OpenVPNãµãŒãã¹ã®ã»ããã¢ãããšéå§
éå§ããã«ã¯ã次ã®ãµãŒããŒæ§æã䜿çšããŸãïŒãã¡ã€ã«/etc/openvpn/openvpn.confïŒïŒ
ïŒãã®ããŒãã¯ãOpenVPNçšã«IANAã«ãã£ãŠæšå¥šãããŠããŸãã å¥ã®ããŒãã«è»¢éã§ããŸãããæ©å¯æ§ã¯åäžããŸãããOpenPVNã§ããããšãæåã«èªèãããŸãã ããŒã1194 ïŒOpenVPNã¯ãã©ã³ã¹ããŒããããã³ã«ãšããŠtcpãšudpã䜿çšã§ããŸãããudpãæãŸãã ãããUDP ïŒããªããžã«å«ããä»®æ³ã€ã³ã¿ãŒãã§ã€ã¹ã¯ã確ãã«ã¿ããã¿ã€ãã§ãïŒã€ãŒãµãããçµç±ã§ã€ãŒãµãããããšãã¥ã¬ãŒãããããšã¯ã§ããŸããïŒ dev tap0 ïŒã«ãŒãèªå·±çœ²åCA蚌ææž ca /etc/openvpn/keys/ca.crt ïŒèšŒææžãšãµãŒããŒã®ç§å¯éµã crtã«ã¯ã¢ãŒã644ãããŒ-600ãå¿ èŠã§ã cert /etc/openvpn/keys/office.crt ããŒ/etc/openvpn/keys/office.key ïŒDiffie-Hellmanãã©ã¡ãŒã¿ãå«ããã¡ã€ã«ã ããŒã®é·ããç°ãªãå Žåã¯ãååãä¿®æ£ããŠãã ãã:) dh /etc/openvpn/keys/dh1024.pem ïŒãã®ç¯å²å ã®ãã®ãµããããå ã®ã¢ãã¬ã¹ããªã¢ãŒãã¯ã©ã€ã¢ã³ãã«é åžããŸãïŒæ³š-ãµããããã¯ãããã¯ãŒã¯ã«ãŒãæ§æã®ããã«EVERYTHINGã«èšå®ãããç¯å²ã¯ãµããããã®äžéšã§ãïŒ server-bridge 192.168.168.254 255.255.255.0 192.168.168.128 192.168.168.159 ïŒã¯ã©ã€ã¢ã³ããçžäºã«å¯Ÿè©±ã§ããããã«ããŸãïŒããã§ãªãå Žåã¯ããµãŒããŒãšãããªããžã®èåŸãã®ãããã¯ãŒã¯ã»ã°ã¡ã³ããšã®ã¿å¯Ÿè©±ããŸãïŒ ã¯ã©ã€ã¢ã³ãé ïŒããã«ãããã¯ã©ã€ã¢ã³ãã¯ãããžãŒã§ãªãå Žåã以åã«äžããããã®ãšåãã¢ãã¬ã¹ãäžããããšãã§ããŸã ifconfig-pool-persist /etc/openvpn/ipp.txt ïŒDHCPãä»ããŠDNSãµãŒããŒã¢ãã¬ã¹ã転éããããªãå Žåã¯ã次ã®è¡ãåé€ã§ããŸãã push "dhcp-option DNS 192.168.168.254" ïŒå§çž® comp-lzo ïŒã¯ã©ã€ã¢ã³ãã®æ倧æ°-ãµãŒããŒããªããžç¯å²å ã®ã¢ãã¬ã¹æ°ä»¥äžã«ããããšã¯çã«ããªã£ãŠããŸã æ倧ã¯ã©ã€ã¢ã³ãæ°32 ïŒãããã®ããŒã®è©³çŽ°ã¯ãOpenVPNã®ããã¥ã¡ã³ãã«ãããŸã ããŒãã¢ã©ã€ã10120 ïŒtunãååæåãããåæ¥ç¶æã«ããŒãåèªã¿åãããªãã§ãã ããã rootãšããŠã§ã¯ãªãã誰ãšããŠãåããŠããªãå Žåããããè¡ãããšã¯ã§ããŸããããããã£ãŠããããã®ãªãã·ã§ã³ã®ãã¹ãŠããŸãã¯ã©ãã ãŠãŒã¶ãŒãªã ã°ã«ãŒããªã æ°žç¶ã㌠æç¶ãã ïŒOpenVPNã¯æ¯åããã§çŸåšã®ç¶æ ïŒã¯ã©ã€ã¢ã³ããã«ãŒããªã©ã®ãªã¹ãïŒããªã»ããããŸã ã¹ããŒã¿ã¹/tmp/openvpn-status.log ïŒéåžžã«ãã€ãºã®å€ããã°ãéåžžã®æäœ-åè©2 åè©6 log-append /var/log/openvpn.log
ããŒoffice.keyã«ã¯ã¢ãŒã600 ïŒææè ã®ã¿ãžã®ã¢ã¯ã»ã¹ïŒãå¿ èŠã§ãã ãã¡ã€ã«office.crtããã³dh1024.pemã®ã¢ãŒãã¯644ã§ãã
ãã£ã«ã¿ãŒèšå®
ããªããžã䜿çšããããããã±ãããã£ã«ã¿ãªã³ã°ãæŽçããããã®æ©èœãããã€ããããŸãã ããšãã°ããã¹ãŠã®ééãã±ãããIPv4ã§ãããšã¯éããŸããã ã«ãŒãã«ã§ããªããžã®åäœãæ§æããã«ã¯ãããã€ãã®ãã©ã¡ãŒã¿ãŒããããŸãã
ãã®ã°ã«ãŒãã®å€æ°ã¯ã/ proc / sys / net / bridge /ãã£ã¬ã¯ããªã®ãã¡ã€ã«ã«ä¿åãããŸãã ãŸãã/ etc / sysctl.confã§æ§æããããšãã§ããŸãããã®å Žåããã¹ãŠãnet.brigdeããšãããã¬ãã£ãã¯ã¹ãä»ããŸãã
- bridge-nf-call-arptables
ããŒã«å€æ°bridge-nf-call-arptablesã¯ãarptablesãã±ãããã£ã«ã¿ãŒã®FORWARDãã§ãŒã³ãžã®ARPãã©ãã£ãã¯ã®è»¢éãå¶åŸ¡ããŸãã ããã©ã«ãå€ã®1ã¯ãã£ã«ã¿ãŒãžã®ãã±ããã®éä¿¡ãèš±å¯ãã0-çŠæ¢ããŸãã - bridge-nf-call-iptables
ããŒã«å€æ°bridge-nf-call-iptablesã¯ãããªããžãééããIPv4ãã©ãã£ãã¯ã®iptablesãã§ãŒã³ãžã®è»¢éãå¶åŸ¡ããŸãã ããã©ã«ãå€ã®1ã¯ãã£ã«ã¿ãªã³ã°ã®ããã®ãã±ããã®éä¿¡ãèš±å¯ãã0-çŠæ¢ããŸãã - bridge-nf-call-ip6tables
ã¢ã¯ã·ã§ã³ã¯åã®ã¢ã¯ã·ã§ã³ãšäŒŒãŠããŸãããip6tablesãã§ãŒã³ã§ã®ãã£ã«ã¿ãªã³ã°ã®ããã«IPv6ãã©ãã£ãã¯ã®éä¿¡ãæ§æããã ãã§ãã - bridge-nf-filter-vlan-tagged
ããŒã«å€æ°bridge-nf-filter-vlan-taggedã¯ãVLANã¿ã°ä»ãã®IP / ARPãã©ãã£ãã¯ããã±ãããã£ã«ã¿ãªã³ã°ããã°ã©ã ïŒarptables / iptablesïŒã«éä¿¡ãããã©ããã決å®ããŸãã å€1ïŒããã©ã«ãã§èšå®ïŒã¯ãVLANã¿ã°ä»ãã®ãã±ããã®ãã£ã«ã¿ãªã³ã°ããã°ã©ã ãžã®éä¿¡ãèš±å¯ããŸãã0-çŠæ¢ããŸãã
ããªããžãééãããã±ããããã£ã«ã¿ãªã³ã°ããããã«ãphysdevãããã³ã°ã䜿çšãããŸããããã¯ããã±ãããã©ã®ããŒããšã©ã®ããªããžãééããããåºå¥ããŸãã ã«ãŒãã«ã§æå¹ã«ããŸãïŒ
->ãããã¯ãŒãã³ã° ->ãããã¯ãŒãã³ã°ãµããŒãïŒNET [= y]ïŒ ->ãããã¯ãŒã¯ãªãã·ã§ã³ ->ãããã¯ãŒã¯ãã±ãããã£ã«ã¿ãªã³ã°ãã¬ãŒã ã¯ãŒã¯ïŒNetfilterïŒïŒNETFILTER [= y]ïŒ ->ã³ã¢Netfilterèšå® -> Netfilter XtablesãµããŒãïŒip_tablesã«å¿ èŠïŒïŒNETFILTER_XTABLES [= y]ïŒ ->ãphysdevãäžèŽãµããŒãïŒNETFILTER_XT_MATCH_PHYSDEV [= y]ïŒ
ããã«ãã«ãŒãã«æ§æã§ã¯ããã±ãããiptablesãã£ã«ã¿ãªã³ã°ã«è»¢éã§ããããã«ããå¿ èŠããããŸãã bridge-nf-call-iptables = 1ããã³bridge-nf-call-ip6tables = 1ïŒIPv6ã䜿çšããŠããå ŽåïŒã
ããšãã°ããã£ã«ã¿ãªã³ã°ã«æ¬¡ã®ã«ãŒã«ã䜿çšã§ããŸãã
iptables -A FORWARD -p tcp --dport 22 -m physdev --physdev-in eth1 --physdev-out eth0 -j ACCEPT
Linuxã§ããªããžãæ§ç¯ããã®èšäºã§æçš¿ããŒãéã®ãã£ã«ã¿ãªã³ã°ã®èšå®ã®è©³çŽ°ãèªãããšãã§ããŸãã
LANãŠãŒã¶ãŒãšããªããžVPNãŠãŒã¶ãŒãåºå¥ããããªãå Žåã¯ãã«ãŒãã«ã§ãããã®ãªãã·ã§ã³ããªãã«ããã ãã§æžã¿ãŸãïŒããã©ã«ãã§æå¹ã«ãªã£ãŠããŸãïŒã
echo "net.bridge.bridge-nf-call-iptables = 0" >> /etc/sysctl.conf echo "net.bridge.bridge-nf-call-ip6tables = 0" >> /etc/sysctl.conf
ã客ããŸ
ã¯ã©ã€ã¢ã³ãã§ã次ã®å 容ã®OpenVPNæ§æãã¡ã€ã«ãäœæããå¿ èŠããããŸãã
ã¯ã©ã€ã¢ã³ã ããã€ã³ã éçºè ã¿ãã ãããUDP ïŒæ¥ç¶å ã è€æ°ã®ãªã¢ãŒããªãã·ã§ã³ãæå®ã§ããŸã-æåã«äœ¿çšå¯èœãªãµãŒããŒã䜿çšãããŸãã server.example.netã®Aã¬ã³ãŒããè€æ°ããå Žåããããã®éžæã¯ã©ã³ãã ã§ãã ãªã¢ãŒãserver.example.net 1194 ïŒæ±ºããŠããããããç¡éã«æ¥ç¶ããŠã¿ãŠãã ããã ç¡éã®è§£æ±ºãšåè©Šè¡ ïŒãã¹ãŠã®ãªãã·ã§ã³ãäžç·ã«äœ¿çšããããã©ãã䜿çšããªã æ°žç¶ã㌠æç¶ãã ãŠãŒã¶ãŒãªã ã°ã«ãŒãnogroup comp-lzo ns-cert-typeãµãŒã㌠ca ca.crt cert client.crt ããŒclient.key
ãµãŒããŒãè€æ°ã®ãããã€ããŒãä»ããŠæ¥ç¶ãããŠããå Žåãé害ã«å¯Ÿãããããã¯ãŒã¯ã®å埩åãé«ããããšãã§ããŸãã ãããè¡ãã«ã¯ãã¯ã©ã€ã¢ã³ãã¯è€æ°ã®ãªã¢ãŒããªãã·ã§ã³ããåªå ããããé åºã§ãµãŒããŒããšã«1ã€ç»é²ããå¿ èŠããããŸãã
caãcertãããã³keyãã©ã¡ãŒã¿ãŒã§æå®ããããã¡ã€ã«åã¯ãå®å šãªãã£ãã«ãä»ããŠè»¢éããããã¡ã€ã«ã§ãã ããŒãã¡ã€ã«ã®ã¢ã¯ã»ã¹èš±å¯ã¯600ã«èšå®ããå¿ èŠããããŸãã
Linux
ã«ãŒãã«ãŸãã¯ã¢ãžã¥ãŒã«ã§ã¯ããŠãããŒãµã«tun / tapãã©ã€ããŒãå¿ èŠã§ãããããŒããããŠããŸãã
ãžã§ã³ããŒ
net-misc / openvpnãã€ã³ã¹ããŒã«ãããšãã¹ã¯ãªãã/etc/init.d/openvpnãäœæãããŸãã ãã®ã¹ã¯ãªããã¯ãæ§æãã¡ã€ã«/etc/openvpn/openvpn.confã䜿çšããŠopenvpnãéå§ããŸãã ãã ãã/ etc / init.d / openvpn.network-name-> /etc/init.d/openvpnã®åœ¢åŒã®ã·ã³ããªãã¯ãªã³ã¯ãäœæããã°ãè€æ°ã®OpenVPNæ§æãåæã«ãµããŒãã§ããŸãããã®ãããªåã¹ã¯ãªããã¯ãæ§æãã¡ã€ã«/ etc / openvpnã§OpenVPNãèµ·åããŸã/network-name.confã
ãããã£ãŠãäžèšã®èšå®ãããã«é 眮ããã·ã³ããªãã¯ãªã³ã¯ãäœæããã¹ã¯ãªããã/ etc / openvpn /ã®ãµããã£ã¬ã¯ããªã«é 眮ããŸãã èšå®ã§ãããŒãšèšŒææžãžã®ãã«ãã¹ãç»é²ããŸãã äžå¿«ãªåœ±é¿ãé¿ããããã«ãæ§æå ã®ãã¡ã€ã«åãéè€ããªãããã«ããŠãã ããïŒ
ãããã¯ãŒã¯ã®éå§ãšåæ¢ã¯ã/ etc / openvpn.network-nameãµãŒãã¹ã®ç®¡çãéããŠè¡ãããŸãã
çª
æ§æãã¡ã€ã«ã¯ããã£ã¬ã¯ããªãCïŒ\ Program Files \ OpenVPN \ config \ãã«ãoffice.ovpnããªã©ã®ååã§é 眮ãããæ®ãã®ãã¡ã€ã«-ããŒãšèšŒææžãããã«é 眮ãããŸãã ãããããµããã£ã¬ã¯ããªã«é 眮ããå ŽåïŒããšãã°ãè€æ°ã®ä»®æ³ãããã¯ãŒã¯ã䜿çšããããããã¹ãŠãåãååca.crtã®ãã¡ã€ã«ãæäŸããå ŽåïŒããã¡ã€ã«ãžã®ãã«ãã¹ã瀺ããŸãã
ãããã¯ãŒã¯ãéå§ããã«ã¯ãOpenVPNãµãŒãã¹ãéå§ãããïŒconfig \ã«ãããã¹ãŠã®* .ovpnæ§æãèµ·åãããŸãïŒãåå¥ã«-.ovpnãã¡ã€ã«ãå³ã¯ãªãã¯ããŠ[ãã®æ§æã§OpenVPNãå®è¡]ãéžæããŸãã
èããããåé¡
ãµãŒããŒãTCPã§å®è¡ãããŠããå Žåã¯ããµãŒããŒã®å¯çšæ§ã確èªããéåžžã®telnetã䜿çšã§ããŸãã
çª
ç¡æã®TAPä»®æ³ã¢ããã¿ãŒã¯ãããŸãã
2008幎12æ31æ¥10:43:51 2008 88.83.201.253:1194ã§TCPæ¥ç¶ã確ç«ãããŸãã Wed Dec 31 10:43:51 2008 TCPv4_CLIENT link localïŒ[undef] æ°Ž12æ31æ¥10:43:51 2008 TCPv4_CLIENTãªã³ã¯ãªã¢ãŒãïŒ88.83.201.253:1194 Wed Dec 31 10:44:51 2008 TLS ErrorïŒTLSããŒããŽã·ãšãŒã·ã§ã³ã¯60ç§ä»¥å ã«çºçããŸããã§ããïŒãããã¯ãŒã¯æ¥ç¶ã確èªããŠãã ããïŒ 2008幎12æ31æ¥æ°Žææ¥10:44:51 TLSãšã©ãŒïŒTLSãã³ãã·ã§ã€ã¯ã«å€±æããŸãã 2008幎12æ31æ¥æ°Žææ¥10:44:51 2008èŽåœçãªTLSãšã©ãŒïŒcheck_tls_errors_coïŒãåèµ·åäž 2008幎12æ31æ¥æ°Žææ¥10:44:51 2008 SIGUSR1 [softãtls-error]ãåä¿¡ããããã»ã¹ãåèµ·åããŠããŸã Wed Dec 31 10:44:56 2008éèŠïŒOpenVPNã®ããã©ã«ãã®ããŒãçªå·ã¯ãIANAã«ããå ¬åŒã®ããŒãçªå·å²ãåœãŠã«åºã¥ããŠ1194ã«ãªããŸããã OpenVPN 2.0-beta16以åã§ã¯ãããã©ã«ãããŒããšããŠ5000ã䜿çšãããŠããŸããã Wed Dec 31 10:44:56 2008 SSL / TLSã³ã³ããã¹ãã®åå©çš æ°Ž12æ31æ¥10:44:56 2008 LZOå§çž®ãåæåãããŸãã Wed Dec 31 10:44:56 2008 88.83.201.253:1194ãšTCPæ¥ç¶ã確ç«ããããšããŠããŸã æ°Ž12æ31æ¥10:44:56 2008 TCPæ¥ç¶ã¯88.83.201.253:1194ã§ç¢ºç«ãããŸãã æ°Ž12æ31æ¥10:44:56 2008 TCPv4_CLIENTãªã³ã¯ããŒã«ã«ïŒ[undef] Wed Dec 31 10:44:56 2008 TCPv4_CLIENT link remoteïŒ88.83.201.253:1194 æ°Ž12æ31æ¥10:45:11 2008 [ãªãã£ã¹] 88.83.201.253:1194ã§éå§ããããã¢æ¥ç¶ Wed Dec 31 10:45:13 2008ãã®ã·ã¹ãã äžã®ãã¹ãŠã®TAP-Win32ã¢ããã¿ãŒã¯çŸåšäœ¿çšäžã§ãã 2008幎12æ31æ¥æ°Žææ¥10:45:13 2008çµäº ç¶è¡ããã«ã¯ä»»æã®ããŒãæŒããŠãã ãã...
OpenVPNãã°ã¯ãã¯ã©ã€ã¢ã³ãããµãŒããŒã«æ£åžžã«æ¥ç¶ãããã°ã€ã³ããããä»®æ³ãããã¯ãŒã¯ãä»®æ³ã¢ããã¿ãŒã«ãã€ã³ãã§ããªãã£ãããšã瀺ããŠããŸãã ãããããä»ã®ããã€ãã®ããã»ã¹ããã·ã¹ãã å ã®ãã¹ãŠã®TAP-Win32ã¢ããã¿ãŒã«ãã§ã«åœ±é¿ãåãŒããŠããŸãã OpenVPNèªäœããã³ã°ããã¢ããã¿ãŒãæŸæ£ããªãå¯èœæ§ããããŸãã
åèµ·åããããããããã©ã®ãããªããã»ã¹ã§ããããèŠã€ããŠåŒ·å¶çã«çµäºããããšã§åŠçãããŸãã
åç §è³æ
ãã®èšäºãæžããšãã次ã®ãœãŒã¹ã䜿çšãããŸããã
- Gentoo Linux Wiki-ãµãŒããŒèšŒææžã«ããEthenetããªããžã³ã°ã®ããã®HOWTO OpenVPNãµãŒã㌠ïŒãã®ããŒãžã®ã³ããŒã¯http://www.gentoo-wiki.info/HOWTO_OpenVPN_Server_for_Ethernet_Bridging_with_Server_Certificatesã«ãããŸã ããªã³ã¯ãããããšãããããŸã ïŒïŒ
- Gentoo Linux Wiki-HOWTO OpenVPN LinuxãµãŒããŒWindowsã¯ã©ã€ã¢ã³ã
- OpenVPNããã¥ã¡ã³ã-HOWTO
- ãããã¯ãŒã¯ãããã³ã«ãšã³ãµã€ã¯ãããã£ã¢-IPã¹ã¿ãã¯ã®sysctlãã©ã¡ãŒã¿ãŒ
- Linuxã§ããªããžãæ§ç¯ãã
PSäžéšã®ãœãŒã¹ã¯äŒã¿ãŸããã ãªã³ã¯ã¯åé€ããŸããããèŠããŠãã䟡å€ã¯ãããŸãã