Portál AbcLinuxu, 14. května 2025 02:08
#config server#
port 1194
proto udp
dev tun
ca ca.crt
cert birkof.crt
key birkof.key # This file should be kept secret
dh dh1024.pem
server 10.0.0.0 255.255.255.0
ifconfig-pool-persist ipp.txt
push "route 10.0.0.0 255.255.255.0"
client-to-client
keepalive 10 120
comp-lzo
persist-key
persist-tun
status openvpn-status.log
verb 3
#config client#
client
dev tun
proto udp
remote 86.xx.xx.xx 1194
resolv-retry infinite
nobind
persist-key
persist-tun
ca ca.crt
cert client.crt
key client.key
comp-lzo
verb 3
"server"
cat /etc/openvpn.conf
remote 0.0.0.0
ifconfig 172.20.0.1 255.255.255.0
port 1194
proto udp
dev tap0
secret /etc/openvpn/klic.key
ping 10
comp-lzo
verb 5
mute 10
user nobody
group nogroup
log-append /var/log/openvpn.log
up ./server.up
cat server.up
#!/bin/bash
route add -net 192.168.9.0 netmask 255.255.255.240 gw 172.20.0.253
--------------
klient
cat /etc/openvpn.conf
remote vpn.domena.lfd
ifconfig 172.20.0.253 255.255.255.0
port 1194
proto udp
dev tap0
secret /etc/openvpn/klic.key
ping 10
comp-lzo
verb 5
mute 10
user nobody
group nogroup
log-append /var/log/openvpn.log
up ./doma.up
cat doma.up
#!/bin/bash
route add -net 10.0.0.0 netmask 255.255.0.0 gw 172.20.0.1
route add -net 10.100.0.0 netmask 255.255.0.0 gw 172.20.0.1
route add -net 213.29.12.32 netmask 255.255.255.240 gw 172.20.0.1
Tato konfigurace mi funguje na OpenVPN verze 2.0.6
Mam takhle sestaveny "tunel" k rodicum kteru jsou za NATem a ja kdyz tam jsem na vikendy abych mohl v klidu courat po me siti o nekolik desitek km dal.
Tiskni
Sdílej:
ISSN 1214-1267, (c) 1999-2007 Stickfish s.r.o.