Portál AbcLinuxu, 14. května 2025 02:11
port 5000 proto udp dev tun ca /etc/openvpn/ca.crt cert /etc/openvpn/admin.crt key /etc/openvpn/admin.key dh /etc/openvpn/dh1024.pem server 10.100.100.0 255.255.255.248 keepalive 10 120 comp-lzo max-clients 2 user openvpn group nogroup persist-key persist-tun status openvpn-status.log verb 3 push "route 10.100.100.0 255.255.255.0" push "route 192.168.101.0 255.255.255.0" push "dhcp-option DNS 192.168.101.1"klient
client dev tun proto udp remote www.wwww.ww 5000 float resolv-retry infinite nobind persist-key persist-tun ca ca.crt cert user.crt key user.key comp-lzo verb 3spojeni funguje jak ma, ale jedine s cim se spojim je ten server, ale ja se potrebuji mit k dispozici web server a ostatni prvky site.Dale vubec nedostanu na klientovi priedlelnou branu .. coz je podle me divne.. Kdyz jsem zadal push redirect-gateway tak mi to pridelilo sice branu, ale uplne nesmyslnou neexistujici. Otazka zni jak to spravne nastavit aby se to chovalo scela korektne.
/etc/openvpn/server.conf
radek
push "redirect-gateway def1"a funguje bez problemu.
mode server port 5000 proto udp dev tun ca /etc/openvpn/ca.crt cert /etc/openvpn/admin.crt key /etc/openvpn/admin.key dh /etc/openvpn/dh1024.pem server 10.100.100.0 255.255.255.0 ifconfig 10.100.100.1 10.100.100.2 keepalive 10 120 comp-lzo max-clients 2 user openvpn group nogroup persist-key persist-tun status openvpn-status.log verb 3 push "route 192.168.101.0 255.255.255.0" push "dhcp-option DNS 192.168.101.1" push "redirect-gateway def1"no a pri pripojeni mi to dava vsechny routy na 10.100.100.5 a totez ip je prideleno jako vychozi brana! Ale ta IP neexistuje, da se nejakym zpusobem dat na tvrdo ip adresu serveru a zadat bud rozsah nebo v konfiguraci klienta take nastavit na tvrdo IP ?
ifconfig
na OpenVPN gateway.
redirect gateway def1
by to mela byt gateway pro VPN sit. Posli prosit vypisy jak jsem psal drive.
push "route 192.168.101.0 255.255.255.0"mate tam zadáno že chcete do tunelu routovat provoz pro sit 192.168.101.0/24 ale nemate nikde za jakym routerem se nachazi. to znamena ze nemate u ni nastavenou GW. Podle me by ten radek mel vypadat takhle
push "route 192.168.101.0 255.255.255.0 GW(ip_tun_zarizeni_na_serveru)"Ja osobne vyuzivam teda tap a vsechno mi bezi bez problemu a tech rout takhle predavam x
mode server tls-server dev tap ifconfig 10.0.1.1 255.255.255.0 ifconfig-pool 10.0.1.101 10.0.1.254 255.255.255.0 push "route 192.168.0.0 255.255.252.0 10.0.1.1" push "route 10.11.12.0 255.255.255.0 10.0.1.1" port 10056 duplicate-cn ca /etc/openvpn/cert/cacert.pem cert /etc/openvpn/cert/vpncert.pem key /etc/openvpn/cert/vpnkey.pem dh /etc/openvpn/cert/dh1024.pem log-append /var/log/openvpn status /var/run/openvpn/vpn.status 10 user hates group users # comp-lzo verb 3CLIENT pro windows
remote IP_VPN_SERVERU tls-client port 10056 dev tap pull mute 10 ca cacert.pem cert vrbacert.pem key vrbakey.pem verb 3
SERVER mode server tls-server dev tap ifconfig 192.168.2.10 255.255.255.0 ifconfig-pool 192.168.2.100 192.168.2.200 255.255.255.0 push "route 192.168.2.0 255.255.255.0 192.168.1.9" push "route 192.168.1.0 255.255.255.0 192.168.1.9" duplicate-cn ca /etc/openvpn/cert/cacert.crt cert /etc/openvpn/cert/vpncert.crt key /etc/openvpn/cert/vpnkey.key dh /etc/openvpn/cert/dh1024.pem log-append /var/log/openvpn status /var/run/openvpn/vpn.status 10 user user group users comp-lzo verb 3 CLIENT pro windows remote IP_VPN_SERVERU tls-client dev tap pull mute 10 ca cacert.crt cert klient.crt key klient.key verb 3D9k za radu
Tiskni
Sdílej:
ISSN 1214-1267, (c) 1999-2007 Stickfish s.r.o.