ããã«ã¡ã¯ãhabralyudiã äŒçµ±çãªãããã¯Habréã«é¢ããç§ã®æåã®ãããã¯ã§ããå³å¯ã«å€æããªãã§ãã ãããã ããã©ããããæ£åœåãããæ¹å€ã¯æè¿ãããŸãã ç§ã¯èšäºãæžããçµéšãããŸããªãã®ã§ãã©ããªåå¿ã«ãæè¬ããŸãã
èŠåã®åæ°ã ãã®æçš¿ã¯ãããããããããã¯ãŒã¯ã®äžçã®ç¬¬äžäººè ã«ãšã£ãŠèå³æ·±ããã®ã§ã¯ãªãã§ãããã äž»ã«ITã®äžçã®ä»ã®åéã«é¢å¿ããã人ã«åããããŠããŸããã圌ãã¯å¥œå¥å¿ãç¹åŸŽã§ããããã¹ãŠã®æ°ããããšã«èå³ããããŸãã ãããã£ãŠããäž»é¡ãã«ãã人ã ã«ãšã£ãŠãããã¹ãã¯ããç¥ãããçå®ãšãã©ãã£ãã¥ãŒãã®éãŸãã®ããã«èŠãããããããŸããã 玳士ãç§ã¯ããªããé©ãããã®ã§ã¯ãªãããã®åéã®ããŸãé²æ©ããŠããªã人ãå©ããããã«åªåããŸãã 以äžã¯ãã¹ãŠãç°ãªãããŒãžã§ã³ã®Windowsãå®è¡ããŠããã³ã³ãã¥ãŒã¿ãŒã«ã®ã¿é©çšãããŸãã
èŠåãã³ãç«ã ãŸããç§ã¯èªåèªèº«ã第äžäººè ãšã¯èŠãªããŠããããäžéšã®çºèšãå€æã§ééããäžæ£ç¢ºãªããšããããŸãã ãã ãã調æŽã®ããã®ã¢ã¯ã·ã§ã³ã®ã¢ã«ãŽãªãºã ã¯æ©èœããŠãããå人çã«æ€èšŒãããŠããŸãã
èŠå3ã ããããã®æçŽã ãã®çµæãç§ã¯æå³çã«è©³çŽ°ã«ãåºç¯å²ã«æžã蟌ã¿ãŸãã
äžèšã§æãããªãå Žåã¯ãå§ããŸãããã
ãŸããwikiã䜿çšããŠãVPNãšã¯äœããå®éã«ã¯ã©ã®ããã«åœ¹ç«ã€ããæãåºããŸãã VPNïŒEngãVirtual Private NetworkïŒã¯ã1ã€ä»¥äžã®ãããã¯ãŒã¯æ¥ç¶ïŒè«çãããã¯ãŒã¯ïŒãå¥ã®ãããã¯ãŒã¯ïŒããšãã°ãã€ã³ã¿ãŒãããïŒçµç±ã§èš±å¯ããæè¡ã®äžè¬çãªååã§ãã ä»ãã·ã¢èªã§ã å¿ èŠã«å¿ããŠãä»»æã®ãªã¢ãŒãã³ã³ãã¥ãŒã¿ãŒãå®å šã«çµã¿åãããŠãã€ã³ã¿ãŒãããã¢ã¯ã»ã¹ããããã°ããã¹ãŠã®å©ç¹ãšèšåãåããåãããŒã«ã«ãããã¯ãŒã¯ã®ã¡ã³ããŒã§ãããšèŠãªãããšãã§ããŸãã
äŸ1ïŒããªãã®ããŒã ãããã€ããŒã¯äºéã®é¢çšãããŒã«ã«ïŒå®äŸ¡ã§ã¹ããŒããªæ¥ç¶ïŒãšå€éšã®ãäžçãžãïŒããé«äŸ¡ã§é ãïŒãæã£ãŠããŸãã ã¢ã¯ã»ã¹ã§ããé家åºçšã³ã³ãã¥ãŒã¿ãŒã®1ã€ïŒããšãã°ã皌åäžã®ã³ã³ãã¥ãŒã¿ãŒïŒã«ã¯ãé«éã®anlim-internetããããŸãã ç§ãã¡ã¯é埳çãå«ççãæ³çåŽé¢ãæšãŠãŸãããçŽç²ã«æè¡çãªåŽé¢ã«èå³ããããŸã-ããŒã«ã«ãã©ãã£ãã¯ã®é床ã§äžèšã®anlimãã£ã³ãã«ãéããŠäžçã«ã¢ã¯ã»ã¹ã§ããŸããïŒ çãã¯ãVPNãç§ãã¡ãå©ããããšãã§ãããšããããšã§ãã
äŸ2ïŒèªå® ããé¢ããŠããå Žåãèªå® ã®ã³ã³ãã¥ãŒã¿ãŒäžã®ãã¡ã€ã«ã«ã¢ã¯ã»ã¹ããå¿ èŠããããŸãã ãããã¯ãŒã¯ã«ã¯ïŒããããããŒã«ã«ã®ïŒåå¿è ã®Kulhackerãååã«ååšãããããã®å€ãã¯ã¹ããŒãã£ã³ã°ãTCP / IPã¹ã¿ãã¯ãããã³ãã®ä»ã®ããªãããŒãªãã¢ãã«ãã«é¢ããããããã®æŠå¿µããæã£ãŠããªããããã¢ã¯ã»ã¹ã¯ç¢ºå®ã«æå·åããå¿ èŠããããŸãããå®è¡æ¹æ³ã¯ç¥ã£ãŠããŸããCainïŒAbelãã®ãããªããã°ã©ã ã¯ãå°éå¯èœãªãããã¯ãŒã¯ã»ã°ã¡ã³ãã§éä¿¡ããããã¹ã¯ãŒãã®å€§éšåãååã§ããã ãã§ãªããæå·åãããŠãããããŸãéžæãããŠããªããã¹ã¯ãŒãããã«ãŒããã©ãŒã¹ããããšãã§ããŸãã ä»ã®æ¹æ³ãšåæ§ã«ãVPNã¯åã³åœ¹ç«ã¡ãŸãããã¹ãŠã®ãã©ãã£ãã¯ã¯ãé·å¹Žã«ããã£ãŠãªãŒãã³ã§å®çžŸã®ããã¢ã«ãŽãªãºã ãšã¡ã«ããºã ã䜿çšããŠå®å šã«æå·åãããŸãã
VPNãç·šæããã«ã¯ãç·šæãããŠãããã£ãã«ã®å°ãªããšãçåŽã«ãæ£çŽãªãIPã¢ãã¬ã¹ãããããšãæãŸããã NATãŸãã¯ãããã·ãµãŒããŒã®èåŸã«ããã°ã¬ãŒã®IPã¢ãã¬ã¹ãæã€2ã€ã®ãã©ã€ããŒããããã¯ãŒã¯éã§å®è£ ã§ããŸããè¿œå ã§Hamachiãå©çšãããããŸãã¯ããŒããã©ã¯ãŒãã£ã³ã°ïŒãããã·ã®ãæ¥ç¶ãæ¹æ³ïŒãè¡ãå¿ èŠããããŸãããµãŒããŒ/ã«ãŒã¿ãŒã®èšå®ã ããã«ãç§ã¯ãŸãã«ãã®ãããªå Žåãæ€èšããŸãã
ä»®æ³ãã©ã€ããŒããã£ã³ãã«ãæŽçããããã®ãªãã·ã§ã³ã¯ãããããããŸããååã瀺ãããã«ãç¡æã§å ¬éãããŠãããã®ãã¡ã®1ã€ãã€ãŸãOpenVPNã«ã€ããŠã話ããããšæããŸãã ãã®ãœãããŠã§ã¢ã®ãã1ã€ã®å©ç¹ã¯ãã¯ãã¹ãã©ãããã©ãŒã ã§ããããšã§ãã æ¥ç¶ãããã³ã³ãã¥ãŒã¿ãŒã¯ã* nixãå«ãããŸããŸãªOSãæã€ããšãã§ããŸããããã®ãããªãã·ã³ã®ã»ããã¢ããã¯ãã®èšäºã®ç¯å²å€ã§ãã
ééããªããé¡æãšç¹å®ã®æ°žç¶æ§ãæã€èª°ãããã®ã¯ã©ã€ã¢ã³ããµãŒããŒãœãããŠã§ã¢ã®ã€ã³ã¹ããŒã«æ¹æ³ãšæ§ææ¹æ³ãç¬èªã«ææ¡ã§ããããããã®èšäºã®ç®çã¯ãä»äººãèªåã®åæãè¡ãæéãç¯çŽããããã«ç§ãå¶ç¶çãã ã¬ãŒãã«ã€ããŠèŠåããããšã§ãã ããã§ïŒæçµçã«ïŒïŒäœãã©ã®ããã«è¡ãã®ã§ããïŒ
1. ãœãããŠã§ã¢ãããŠã³ããŒããã
2.å ¥ããŸãã æåã«å°æ¥ã®ãµãŒããŒã®åŽã«ã 次ã«ãã¯ã©ã€ã¢ã³ãåŽã§ç¹°ãè¿ããŸãïŒããã¯å°ãç°¡åã§ãïŒããé åºã¯éèŠã§ã¯ãããŸããã ç§ã¯æ laãªçãç©ãšããŠãããã©ã«ãã®ã€ã³ã¹ããŒã«ãã¹ïŒCïŒ\ Program Files \ OpenVPN \ïŒã«åæããŸããã
åé¡ïŒäœæ¥äžããœãããŠã§ã¢ã¯ã¹ããŒã¹ãå«ãæ§æãã¡ã€ã«ãžã®ãã¹ã誀ã£ãŠåŠçããŸãã
解決çïŒååã«ã¹ããŒã¹ãå«ãŸãªãå¥ã®ãµããã©ã«ããŒã«ãã£ã¹ã¯ã®ã«ãŒããé 眮ããããåŸã§æ§æå ã®ãã®ãããªãã¹ãåŒçšç¬Šã§ãã¹ã¯ãªãŒãã³ã°ãããŸãã ã¹ã¯ãªãŒãã³ã°ãè¡ããŸãããã詳现ãªèª¬æã¯æšæºã®ã€ã³ã¹ããŒã«ãã¹ã«åºã¥ããŠããŸãã
3.ãªã¢ãŒããã·ã³ãšã®æå·åãããæ¥ç¶ã確ç«ããã«ã¯ãä»®æ³ãã£ãã«ã®äž¡åŽã®èšŒææžãå¿ èŠã«ãªããŸããããã«ãããèªåãæ¬äººã§ããããšãæ£ç¢ºã«ç¢ºèªãããŸãã å€ãã®èªèšŒæ©é¢ïŒCAïŒã®1ã€ã§è³Œå ¥ã§ããŸãïŒæ倧90æ¥éã®è©Šçšãªãã·ã§ã³ããããŸããã幎éæ°çŸãã«ïŒã ãã®ãããªãœãªã¥ãŒã·ã§ã³ã®å©ç¹ã¯ããªãã¬ãŒãã£ã³ã°ã·ã¹ãã ããã©ãŠã¶ãã蚌ææžãäžæãªãã³ããŒãšãææè ãããªããä¿¡ããŠãããã©ãããèãããã«ãã£ãŠçºè¡ãããããšããã¹ããªãŒããªãããšã§ãã æ¬ ç¹ã¯æããã§ã-ã³ã¹ãã 2çªç®ã®ãªãã·ã§ã³ã¯ãå人ã®ããŒãºã«åãããŠç¬èªã®ããŒã«ã«CAãæ§ç¯ããããšã«ããããã®ãããªèšŒææžãèªåã§äœæããããšã§ãã ãããè¡ãã«ã¯å€ãã®æ¹æ³ããããŸããOpenVPNã§ææ¡ããããããããªããäœæãããã®ã§ã¯ãªãããšã確èªããæ¢è£œã®èšŒææžã®ãã©ã¡ãŒã¿ãŒã泚ææ·±ãæ€èšããããšã ããéèŠã§ãïŒã€ãŸããçæããã³ãããã€ããããæçŽãïŒæçŽãŸãã¯ããã·ã¥ïŒãæ¯èŒããããšïŒããžãã¹éä¿¡ã®
蚌ææžãäœæããæ¹æ³ã¯2ã€ãããããŸããã 1ã€ã¯ãµãŒããŒWindowsã䜿çšããããšã§ãã æé ã¯æéã§æãæçœã§ã¯ãããŸããããéåžžã«å®è¡å¯èœã§ãã ãã ãããã®å Žåã¯ã2ã€ç®ã®Windowsã®OpenVPNèªäœã®çµã¿èŸŒã¿ããŒã«ã䜿çšããæ¹ã䟿å©ã§ãã
ããã«ä»ã®äººã®ééããç¹°ãè¿ãããšãæããªã人ã®ããã«ïŒããŒãšèšŒææžã®äœæã«ã€ããŠä»¥äžã«æžãããŠãããã¹ãŠã¯ããã¡ã€ã«CïŒ\ Program Files \ OpenVPN \ easy-rsa \ README.txtã«è±èªã§èŠçŽãããŠããŸãã
ç§ã¯ãã詳现ã«æžããŠãåé¡ãç§ã«ãã£ããã®ãããªãã«è©±ããŸãã
èªèšŒå±ãããŒã蚌ææž
aã CïŒ\ Program Files \ OpenVPN \ easy-rsaã«ç§»åããŸã
bã openssl.cnf.sampleãéããå¿ èŠã«å¿ããŠç·šéããŸãã ãããããªã-觊ããªãããšããæšæºçãªã«ãŒã«ããããŸãã ã¡ãªã¿ã«ããã®ãã¡ã€ã«ã¯ãŸã£ããå€æŽã§ããŸãããããã©ã«ãèšå®ã¯éåžžã«æ©èœããŠããŸãã ããããæã®æ©ã¿ïŒããšãã°ã蚌ææžãäœæãããšãã«ãŠãŒã¶ãŒãå ¥åããå€æ°å€ãå¿ èŠã«ãªãå ŽåããããŸãããããã©ã«ãã§äºåã«èšå®ã§ããè§æ¬åŒ§å ã®åçãªãã·ã§ã³ãšããŠè¡šç€ºãããEnterããŒãæŒãã ãã§é©çšã§ããŸãã ãã®ãããªå€æ°ã¯äžèŽã«ãã£ãŠç€ºãããŸãã äžèŠãªãã©ã¡ãŒã¿ãŒã¯ããªãã·ã§ã³ãã§ç€ºãããŸãã æ¯åæåã§å ¥åããå¿ èŠã®ããå ¥åå¿ é ãã©ã¡ãŒã¿ãšäžæã®ãã©ã¡ãŒã¿ã«ã¯ããæäŸæžã¿ãã®ããŒã¯ãä»ããããŠããŸãïŒãã®ãããªå€æ°ãå¥ã®ã¹ããŒã¿ã¹ã«è»¢éããããšã¯ãå§ãããŸããïŒã
蚌ææžã®æå¹æéïŒããã©ã«ãã§ã¯10幎ïŒããŠãŒã¶ãŒé£çµ¡å æ å ±ã®é·ãã®å¶éãªã©ãæ§æã§ããŸãã openssl.cnfãšããŠä¿åããŸãã
cã init-config.batãå®è¡ããŸã
泚æã çæã¯å¯èœã§ãïŒ ãã®ãã¡ã€ã«ãšããã«ç¶ããã¹ãŠã®* .batãã¡ã€ã«ã¯ãããã«ã¯ãªãã¯ã§ã¯ãªãWindowsã³ã³ãœãŒã«ã§èµ·åããããšããå§ãããŸãã ããã䜿çšãã人ã«ãšã£ãŠã¯ããã¹ãã³ããŒããŠç®çã®ãã©ã«ãã«ãã°ãã移åããããšã§ãããªãã®ç掻ãå°ã楜ã«ããããšãã§ããããšã¯ã»ãšãã©æãåºããŸããã ãšã¯ã¹ãããŒã©ãŒ->ãã©ã«ããŒãžã®ãã¹ãéžæ->ã³ããŒ->ã³ã³ãœãŒã«ã«ç§»åïŒwin + r-> cmdïŒ->ããŠã¹ã®å³ãã¿ã³->貌ãä»ãïŒCtrl + Vã¯æ©èœããŸããïŒïŒ ãã¹ãã³ã³ãœãŒã«ãããããã¡ã«ã³ããŒããå¿ èŠãããå ŽåïŒããŠã¹ã®å³ãã¿ã³->ããŒã¯->ç®çã®ããã¹ããéžæ-> Enterã
CïŒ\ Program Files \ OpenVPN \ easy-rsaãã©ã«ããŒã®ã³ã³ãœãŒã«ã«ç§»åããinit-config.batãå®è¡ããŸãã
dã ãšã¯ã¹ãããŒã©ãŒã§easy-rsaã«æ»ããvars.batãã¡ã€ã«ãç·šéããŸãïŒã¯ãŒããããã§éãããšããå§ãããŸããExplorerã®ã³ã³ããã¹ãã¡ãã¥ãŒãããå€æŽãã¡ãã¥ãŒãéããšãå¥ã®ã¬ãŒããååŸã§ããŸããéäžã§ãã¹ãŠåãã®ã£ããïŒã ãã¹ãŠã®ãã©ã¡ãŒã¿ãŒã«ã¯ã³ã¡ã³ããä»ããŠãããäœãç°¡åãªã®ããããããŸãã æŠããŠããã¹ãŠãããã©ã«ãã§ããã«æ®ãããšãã§ããŸãããæåœçãªçç±ãããåœãéœåžãå€æŽããããé»åã¡ãŒã«ãå ¥åãããã§ããŸãã ããã¯äœã«ã圱é¿ããŸãããã蚌ææžã®æ å ±ãšããŠåã«è¡šç€ºãããŸãã å€æ°KEY_DIR = keysã«æ³šæããŠãã ããã ããã¯ãvars.batãeasy-rsaã«ä¿åããåŸã«äœæããå¿ èŠããããµããã©ã«ããŒã®ååã§ãæå·åã«å¿ èŠãªããŒãšèšŒææžãå«ãŸããŸãã ååã¯å€æŽã§ããŸãããå€æ°KEY_DIRã«è¡šç€ºããããšãå¿ããªãã§ãã ããã
eã ããŒãã©ã«ããŒãŸãã¯ååãªãã·ã§ã³ãäœæããããšãå¿ããªãã§ãã ããã
fã ããŒã«æ°ãã空ã®ãindex.txtãããã³ãserialããã¡ã€ã«ãäœæããŸãã Easy-rsaã«ã¯ãã§ã«index.txt.startãã¡ã€ã«ãšserial.startãã¡ã€ã«ãå«ãŸããŠããŸãããããã®ãã¡ã€ã«ãããŒã«ã³ããŒãã.startæ¡åŒµåãåé€ããŠååãå€æŽã§ããŸãã ã·ãªã¢ã«ã§ã¯ãçºè¡ãããCA蚌ææžã®æ°ïŒæåã¯CAèªäœã®èšŒææžïŒãindex.txt-çºè¡ããã蚌ææžã«é¢ããæ å ±ã«ãªããŸãã
gã vars.batãéå§ããclean-all.batãéå§ããŸãïŒã³ã³ãœãŒã«ã§åã³å¿ããªãã§ãã ããïŒïŒ
hã èªèšŒå±ããŒãäœæããŸãïŒvars.batãèµ·åããbuild-ca.batãèµ·åããŠè³ªåã«çããŸãã ææ¡ãããããã©ã«ããªãã·ã§ã³ã䜿çšããŠEnterããŒã§ãã¹ãŠã«çããããšãã§ããŸããããCommon Nameã質åã«å¯Ÿããäžæã®çãïŒã€ãŸããååãŸãã¯ã³ã³ãã¥ãŒã¿ãŒåïŒãé€ããŸãã æå³ãæ°å確èªãã眲åã«åæããŸãã
çµæïŒKeysãã©ã«ããŒå ã®CA蚌ææžãã¡ã€ã«ca.crtããã³CA ca.keyç§å¯éµãã¡ã€ã«ã ãã¹ãŠã®ç§å¯éµã¯å®å šã«ä¿åããå¿ èŠãããããããããã¹ãŠå³éãã€æ éã«æå·åããŠåŸ©å·åã§ããŸãã
iã Diffie-HellmanããŒãäœæããŸãïŒãã®å 容ãšçç±-Wikiã§èªãããšãã§ããŸããæ ããŠããå Žåã¯ãå¿ èŠã§ãããšããäºå®ãåãå ¥ããŠãã ããïŒïŒvars.batãå®è¡ããbuild-dh.batãå®è¡ããå°ãåŸ ã£ãŠããããã»ã¹ã楜ããã§ãã ããã ã³ã³ãœãŒã«ã§ã¯ãªãããŠã¹ã䜿çšããŠbuild-dh.batãå®è¡ãããšãäœãèµ·ãããŸãããç¹°ãè¿ããŸããããã®ã¬ãŒãã«æ°æéãè²»ãããŸããã
jã ãµãŒããŒã®ç§å¯éµãšèšŒææžãäœæããŸãïŒvars.batãå®è¡ããbuild-key-server.bat <servername>ãå®è¡ããŸãã ãµãŒããŒåããã©ã¡ãŒã¿ãŒãšããŠæå®ããããšã匷ããå§ãããŸããèµ·åæã«ããããã¡ã€ã«ã®ååã«ã¹ããŒã¹ã§åºåã£ãŠæå®ããããšããå§ãããŸããããã©ã«ãã§ã¯ãåãæ¡åŒµåãæã€ååã®ãªãããŒãã¡ã€ã«ãšèšŒææžãã¡ã€ã«ãåãåããããå Žåã«ãã£ãŠã¯ååãªãã§äœæãããä»ã®èšŒææžãšããŒãäžæžãã§ããŸãïŒãã1ã€ã®ã¬ãŒã ïŒã
kã ã¯ã©ã€ã¢ã³ãã®ç§å¯éµãäœæããŸãïŒvars.batãå®è¡ããbuild-key.bat <client_name>ãå®è¡ããŸãã ååã«ããæšå¥šãåæ§ã§ã-瀺ãããšãæãŸããã§ãã ãã®çµæãããŒãPEM圢åŒã§ååŸããŸãã ïŒãã®ãããbuild-key.bat <customer_name>ã®ä»£ããã«PKCS N12圢åŒã§ããŒãäœæããããšãã§ããŸããbuild-key-pkcs12.bat<customer_name>ãå®è¡ããå¿ èŠããããŸãã圢åŒã®éãã«ã€ããŠã¯èª¬æããŸãããå¿ èŠã«å¿ããŠGoogleã§æ€çŽ¢ã§ããŸãïŒã
lã ããã ãã§ã 30åãããããã«ãã¯ã©ã€ã¢ã³ããšãµãŒããŒã«å¿ èŠãªããŒãšèšŒææžãäœæããæ°çŸãã«ãç¯çŽããŸããã
ã«ã¹ã¿ãã€ãº
4. OpenVPNã®å®éã®æ§æã ç¹°ãè¿ããŸãããèšå®ãã¡ã€ã«ãç·šéããå¿ èŠããããŸããããã¯ããã°ã©ã ã®linux-rootsã®éºç£ã§ãã CïŒ\ Program Files \ OpenVPN \ sample-configã«ç§»åããããããclient.ovpnãšserver.ovpnãã³ããŒããŠãCïŒ\ Program Files \ OpenVPN \ configã«é 眮ããŸãã
aã ã¯ã©ã€ã¢ã³ãã®ã»ããã¢ãã
CïŒ\ Program Files \ OpenVPN \ configã§client.ovpnãéãïŒåçŽã«ããã«ã¯ãªãã¯ã§ããŸãïŒãåå€æ°ã®ã³ã¡ã³ããèªã¿ãå¿ èŠãªãã®ãå€æŽããŸãã ã³ã¡ã³ãã¢ãŠãããããªãã·ã§ã³ã¯ãã;ãã§å§ãŸããæå¹ïŒæšå¥šïŒã§ããå é ã«ã»ãã³ãã³ã¯ãããŸããã æšå¥šããããã©ã¡ãŒã¿ãŒã®ã»ãšãã©ã«åæã§ããŸããå°ãªããšã次ã®ãã©ã¡ãŒã¿ãŒãå€æŽããå¿ èŠããããŸãã
ãCa ca.crtãã ããã§ã¯ã蚌ææ©é¢ã®èšŒææžãžã®ãã«ãã¹ãæå®ããå¿ èŠããããŸãã ã€ã³ã¹ããŒã«ãã¹ãç§ã®ã€ã³ã¹ããŒã«ãã¹ãšäžèŽããå Žåãeasy-rsa \ããŒã«ãããŸãã 泚æã rake ïŒãã¡ã€ã«ãã¹ã®ãµãŒããŒãšã¯ã©ã€ã¢ã³ãã®æ§æã§ã¯ãåäžã§ã¯ãªãäºéã®ã¹ã©ãã·ã¥ã䜿çšããå¿ èŠããããŸãã ããã¯ããã°ã©ã ã®æ©èœã§ãã å ã«ãã1ã€ã¬ãŒãã«ã€ããŠèª¬æããŸããããã¹ã«ã¯ã¹ããŒã¹ãå«ãŸããŠãããããåŒçšç¬Šã§å²ãå¿ èŠããããŸãã caå€æ°ã¯æ¬¡ã®ããã«ãªããŸãã
ca "CïŒ\\ããã°ã©ã ãã¡ã€ã«\\ OpenVPN \\ easy-rsa \\ããŒ\\ ca.crt"
certããã³ããŒã¯ã©ã€ã¢ã³ãå€æ°ã§ãåãããšãè¡ããŸãã
cert "CïŒ\\ããã°ã©ã ãã¡ã€ã«\\ OpenVPN \\ easy-rsa \\ããŒ\\ <customer_name> .crt"
key "CïŒ\\ Program Files \\ OpenVPN \\ easy-rsa \\ keys \\ <customer_name> .key"
remoteïŒããã§ã¯ããµãŒããŒã®IPã¢ãã¬ã¹ãšãã¹ããŒã¹ã®åŸã«çä¿¡æ¥ç¶ããªãã¹ã³ããããŒããæå®ããå¿ èŠããããŸãïŒããŒãã¯ãµãŒããŒã®æ§ææã«æ§æãããŸãïŒã
å°ããªäœè«ã ã¯ã©ã€ã¢ã³ããµãŒããŒã¢ãã«ã®æ¥ç¶ã®ã€ãã·ãšãŒã¿ãŒã¯ã¯ã©ã€ã¢ã³ãã§ããããããæ£çŽãªãIPã¢ãã¬ã¹ãæã€å¿ èŠãããã®ã¯ãµãŒããŒã§ããããå°ãªããšãã¢ã¯ã»ã¹ã§ãããµãŒããŒ/ã«ãŒã¿ãŒã®èåŸã«ããå¿ èŠããããŸãã äœæ¥äžã®ïŒNATã®èåŸã«ããïŒã³ã³ãã¥ãŒã¿ãŒãšèªå® ã®ïŒåæ§ã«ïŒã³ã³ãã¥ãŒã¿ãŒã®éã«VPNãèšå®ããŸããèªå® ã®ã³ã³ãã¥ãŒã¿ãŒã¯ãç°è²ãã®IPã¢ãã¬ã¹ãæã£ãŠããŸãããã«ãŒã¿ãŒã®ããŒãïŒ7000ãéžæïŒããã®ã³ã³ãã¥ãŒã¿ãŒã«è»¢éããããšã§ç°¡åã«è§£æ±ºã§ããŸããããããŠãæ£çŽãªããããã¯ãŒã¯ã¢ãã¬ã¹ã
æ®ãã®å€æ°ã¯ããã©ã«ãã§æ®ããŸããããå¿ èŠãªãã®ãå€æŽã§ããŸãããããã¯ãã説æãããŠããŸãã
bã ãµãŒããŒã®ã»ããã¢ãã
ããŒãå€æ°-ãµãŒããŒããªãã¹ã³ããUDPããŒãïŒãŸãã¯ãprotoå€æ°ã§ãããã³ã«ãå€æŽããå Žåã¯ãã¯ã©ã€ã¢ã³ãåŽãšãµãŒããŒåŽã§äžèŽããprotoå€ã®ã¿ãå¿ èŠã§ãïŒã瀺ããŸãã 1025ãã65535ãŸã§ã®ä»»æã®å€ãéžæã§ããŸããä»ã®ãµãŒããŒãœãããŠã§ã¢ïŒãŸãã¯ããã¬ã³ãããŠã³ããŒããªã©ã®ç¹å®ã®ããŒãã«é¢é£ä»ããããšãã§ããä»ã®ããã°ã©ã ïŒãšç«¶åããªãããšãéèŠã§ãã
ã¯ã©ã€ã¢ã³ãå€æ°ãããŒããã³èšŒææžå€æ°ãšåæ§ïŒ
ca "CïŒ\\ Program Files \\ OpenVPN \\ easy-rsa \\ keys \\ ca.crt"ïŒCA蚌ææžã¯åãã§ããåãããšãã¯ã©ã€ã¢ã³ããšãµãŒããŒã«æå®ãããŠããŸãïŒ
cert "CïŒ\\ããã°ã©ã ãã¡ã€ã«\\ OpenVPN \\ easy-rsa \\ããŒ\\ <ãµãŒããŒå> .crt"
key "CïŒ\\ Program Files \\ OpenVPN \\ easy-rsa \\ keys \\ <ãµãŒããŒå> .key"
ããã«ãDiffie-HellmanããŒïŒ
dh "CïŒ\\ããã°ã©ã ãã¡ã€ã«\\ OpenVPN \\ easy-rsa \\ããŒ\\ dh1024.pem"
ãµãŒããŒå€æ°ã æ¥ç¶ãããã³ã³ãã¥ãŒã¿ãŒã®IPã¢ãã¬ã¹ãéžæãããç¯å²ããããã©ã€ããŒãïŒãã°ã¬ãŒãïŒãããã¯ãŒã¯ãå®çŸ©ããŸãã OpenVPNã䜿çšããŠVPNãæŽçãããšããµãŒããŒãšã¯ã©ã€ã¢ã³ãã«æ°ããä»®æ³ãããã¯ãŒã¯ã€ã³ã¿ãŒãã§ã€ã¹ã衚瀺ãããŸããWindowsã¯ãå«ãŸããŠãããã©ã€ããŒã®ãããã§ãå®å šã«æ©èœããå®éã®ãããã¯ãŒã¯ã«ãŒãã§ãããšèŠãªããŸãã ãããã®èšå®ã¯ããã®å€æ°ã«ãã£ãŠæ±ºå®ãããŸãã ã»ãšãã©ã®å Žåãããã©ã«ãã®ãŸãŸã«ããŠããããšãã§ããŸãã
ä»ã®å€æ°ãå€æŽããã«æ®ãããšãã§ããŸã;åè©å€æ°ã«ã€ããŠã®ã¿èšåããŸãã ãã¹ãŠã®ã€ãã³ããšãšã©ãŒã«ã€ããŠãµãŒããŒåŽã§ç¶æããããã°ã®è©³çŽ°ã決å®ããŸãã å€1ã¯æã詳现床ãäœããå€9ã¯å°è±¡çã§ãã ãã®ãããæ¥ç¶è©Šè¡ã1å倱æãããšãçŽ600 kbã®ãã°ãã¡ã€ã«ãåãåããŸããã ãšã©ãŒã®åŸ¹åºçãªåæã3ã®ãŸãŸã«ããããå¿ èŠã«å¿ããŠ4ã5ã«å¢ããã®ã劥åœã§ãã
5.ããã§ããµãŒããŒåŽãšã¯ã©ã€ã¢ã³ãåŽã«å¿ èŠãªãã¡ã€ã«ãé 眮ããå¿ èŠããããŸãã æãç°¡åãªãªãã·ã§ã³ã¯ãããã°ã©ã ãäž¡åŽã«ã€ã³ã¹ããŒã«ããäžèšã®ã¢ã«ãŽãªãºã ã«åŸã£ãŠæ§æããããã¹ãŠã®ãã¡ã€ã«ãé©åãªãã©ã«ããŒã«ã³ããŒããããšã§ãã æ éãã€æšæºçã«ã¢ãããŒãããå Žå-ã¯ã©ã€ã¢ã³ãåŽã§ã¯ãã¯ã©ã€ã¢ã³ãããŒã蚌ææžãããã³èšŒææ©é¢ã®èšŒææžã®ã¿ãæ®ããCAããã³ãµãŒããŒã«é¢é£ãããã¹ãŠãåé€ãããµãŒããŒåŽã§ã¯ããã¹ãŠã®ã¯ã©ã€ã¢ã³ãããŒãåé€ããŸãã åçç-äºåããã¯ã¢ããã
èµ·åããŸãã
6.ã»ããã¢ãããå®äºããŸãããããããã¹ãŠå®è¡ããŠã¿ãŠãã ããã ïŒãã¡ã€ã¢ãŠã©ãŒã«ã§å¿ èŠãªããŒããšIPã¢ãã¬ã¹ãéãããšãå¿ããªãã§ãã ããïŒïŒããã«ã¯2ã€ã®ãªãã·ã§ã³ããããŸãã
aã CïŒ\ Program Files \ OpenVPN \ configã®ãµãŒããŒã«ç§»åããserver.ovpnãå³ã¯ãªãã¯ããŠããã®æ§æãã¡ã€ã«ã§OpenVPNãèµ·åããŸãã client.ovpnãã¡ã€ã«ã䜿çšããã¯ã©ã€ã¢ã³ãåŽã§ãåæ§ã§ãã ãããã®å Žåããã¡ãã»ãŒãžã芳å¯ããã¯ã©ã€ã¢ã³ãã幞éã§ããå ŽåãæåŸã®è¡ã«è¡šç€ºãããŸãã
ãåæåã·ãŒã±ã³ã¹ãå®äºããŸããã
ãŸãã¯
bã ã°ã©ãã£ã«ã«ã·ã§ã«Cãèµ·åããŸãïŒ\ Program Files \ OpenVPN \ bin \ openvpn-gui-1.0.3.exe-ãã¬ã€ã¢ã€ã³ã³ãå³ã¯ãªãã¯-ãµãŒããŒ-æ¥ç¶ïŒã¯ã©ã€ã¢ã³ã-ã¯ã©ã€ã¢ã³ã-æ¥ç¶ïŒ ã¯ã©ã€ã¢ã³ãã§æåããå Žåããã¬ã€ãã¥ãŒãããããã¢ãããŠã£ã³ããŠã衚瀺ãããŸãã
ãå²ãåœãŠãããIPïŒ10.8.0.6ããšã¢ã€ã³ã³ãç·è²ã«å€ãããŸãã
7.ãã1ã€ãç§ãå¶ç¶åºäŒã£ãæåŸã®ã¬ãŒã ã ãDHCPã¯ã©ã€ã¢ã³ããã·ã¹ãã ãµãŒãã¹ãã¯ã©ã€ã¢ã³ãã§å®è¡ãããŠããªãå ŽåïŒãã·ã³ã®IPã¢ãã¬ã¹ãäžå®ã§ãããããWindowsãã€ã³ã¹ããŒã«ããçŽåŸã«æå³çã«ç¡å¹ã«ããŸããïŒããµãŒããŒãæäŸããããšããIPã¢ãã¬ã¹ãååŸã§ããŸããã ããã«ãã°ã©ãã£ã«ã«ã·ã§ã«ã¯ã¢ãã¬ã¹ãåä¿¡ãããããšãå ±åããŸãããã·ã¹ãã ã«ãŒãã£ã³ã°ããŒãã«ã®ãããã¯ãŒã¯æ¥ç¶ã«ã¯è¡šç€ºãããŸããã
ç³èŸŒã¿
8.ã³ãã¥ãã±ãŒã·ã§ã³ã¯ä»ãäœã§ããïŒ ãããŠä»-ããã¯ãã¹ãŠããªãã®æ³ååã«äŸåããŸãã ä»®æ³ãã£ã³ãã«ã®IPã¢ãã¬ã¹ããªãã¹ã³ããFTPãµãŒããŒãèªå® ã«çœ®ãããšãã§ããŸãïŒãããªããFTPçµç±ã®ãªãŒãã³ãã°ã€ã³ãšãã¹ã¯ãŒãã®åé¡ïŒãR-AdminãŸãã¯ãã®ç¡æã®TightVNCã®ãããªãã®ã䜿çšã§ããŸããããªãã¯å®¶ã«è¡ãããšãã§ããŸããªã¢ãŒãã²ãŒããŠã§ã€çµç±ã®ã€ã³ã¿ãŒãããïŒäŸ1ããã ãããã®ããã«ã¯ããªã¢ãŒãã²ãŒããŠã§ã€ã§ã®ã«ãŒãã£ã³ã°ãå°ãå€æŽããïŒå°ãªããšãæå¹ã«ããïŒå¿ èŠããããŸããããã©ã«ãã²ãŒããŠã§ã€ããªã¢ãŒãã²ãŒããŠã§ã€ã«å€æŽããã ãã§ããã³ãã«ãšãšãã«ã€ã³ã¿ãŒãããã倱ãããããšãå¿ããªãã§ãã ãããã³ã¡ã³ãã解é€ããã®ã«äŸ¿å©ã§ã RoykoãµãŒããŒå€æ°ããã·ã¥Â«ãªãã€ã¬ã¯ãã²ãŒããŠã§ã€DEF1ãã€ãã¹-DHCP»ïŒã ãªã¢ãŒããã¡ã€ã«åæãæ§æã§ããŸãã äžè¬ã«ãããŒã«ã«ãããã¯ãŒã¯ã§ã§ããããšã¯ãã¹ãŠå®è¡ã§ããŸãã ãããŠããã¯å®å šã§ãã ãã³ãã«ã¯OSIãã©ã³ã¹ããŒãã¬ãã«ã§äžæããããããããã¯ãŒã¯ã¢ããªã±ãŒã·ã§ã³ã¯ãã®äžã«ãã©ãããã§ããŸãã
ãŸããWake-On-Lanãããã«åºå®ãããšãããŸããŸãªã¢ããªã±ãŒã·ã§ã³ã«ãšã£ãŠéåžžã«äŸ¿å©ãªããšãããããŸãã
PSã ããé¿ããããã«ãOpenVPNãããžã§ã¯ããšã¯é¢ä¿ãããŸããã
PPSåçã¯æ£çŽã«çãŸãããªã³ã¯ãååšããŸãã
UPDãæžåŒèšå®ãå°ãä¿®æ£ãããŸããã
ããã«ãæ確ã«ããå¿ èŠããããŸããç§ã¯ãOpen VPNããŒããå ¬éããããšããã¿ã¹ã¯ãèªåã§èšå®ããŸããã§ããããã®ããã«ã詳现ãªããã¥ã¡ã³ããèšèŒããã察å¿ãããµã€ãããããŸããç§ã¯ãèšå®å ã®ãã¹ãŠã®å€æ°ã説æãããšããç®æšãèªåã§èšå®ããŸããã§ããããããã¯ãæ§æãã¡ã€ã«èªäœã§ãã§ã«èª¬æãããŠãããããããã«æå°ã®æ®µèœããããŸãããããŠããã®ãããªè©³çŽ°ãªãã¬ãŒã³ããŒã·ã§ã³ã§ã¯ããã®èšäºã¯ãŸã£ããèªããã巚倧ã§éå±ãªãã®ã«ãªã£ãŠããã§ãããããã¹ãŠãéå§ããããã«æäœéå¿ èŠãªã¢ã¯ã·ã§ã³ã®ã»ããã説æãããã£ãã®ã§ããããã«ãç¹å®ã®ã¿ã¹ã¯ãšãããã¯ãŒã¯æ§æã®ãããªããã¥ãŒãã³ã°ãšåŸ®èª¿æŽ-ããã¯å¥ã®èšäºã®ãããã¯ã§ãã
UPD-2ããœãããŠã§ã¢ã¯OpenVPN 2.1.1ïŒ2009.12.11ã«ãªãªãŒã¹ïŒã«æŽæ°ããããããèšäºã®ãªã³ã¯ãæŽæ°ãããŸãããå€æŽç¹ã¯ãã¡ãã