Portál AbcLinuxu, 7. května 2025 07:27
mode server
tls-server
keepalive 10 60
dev tun
server 10.10.10.0 255.255.255.0 #VPN sit
ifconfig-pool-persist /etc/openvpn/ipp.txt
dh dh1024.pem
ca ca.crt
cert server.crt
key server.key
push "route 192.168.1.0 255.255.255.0" # Sit Serveru (NAT)
route-up "route delete -net 10.10.10.0/24"
route-up "route add -net 10.10.10.0/24 tun0"
client-config-dir ccd
route 192.168.1.0 255.255.255.0 # Aby klienti na VPN mohli routovat do site
client-to-client # Aby mohli mezi sebou
push "route 192.168.2.0 255.255.255.0" # Pokud ma nejaky client za sebou nejakou jinou sit, bereme ji
persist-key
persist-tun
log-append /var/log/openvpn
status /var/log/openvpn-status
user openvpn
group openvpn
verb 3
comp-lzo
KAZDY client ma nastaveni UPLNE stejny:
dev tun
float
mssfix 1500
remote ip.adresa.serveru
tls-client
ns-cert-type server
ca ca.crt
cert client.crt
key client.key
persist-key
persist-tun
pull # Vezmi si VSE ze serveru
verb 3
comp-lzo
Jednoduche ne ??? Bridge je podobny, ale nechce se mi to postovat, jelikoz nesnasim tu aditaci zde na Abclinuxu, kdyz to za me neformatuje ....
<pre> ab cd </pre>udělá to:
ab cdTo je celé
proto udp mode server tls-server dev tap0 port 1194 ifconfig 10.1.0.1 255.255.255.0 ifconfig-pool 10.1.0.2 10.1.0.140 255.255.255.0 duplicate-cn client-to-client ca /etc/openvpn/ca.crt cert /etc/openvpn/server.crt key /etc/openvpn/server.key dh /etc/openvpn/dh2048.pem log-append /var/log/openvpn status /var/run/openvpn/vpn.status 10 user nobody group nogroup comp-lzo verb 3 keepalive 10 120 tls-auth ta.key 0KLIENT
remote server.cz 1194 proto udp tls-client dev tap pull nobind dhcp-option WINS 10.1.0.1 ca ca.crt cert client.crt key client.key comp-lzo ping 10 ping-restart 60 ping-timer-rem verb 3 ns-cert-type server up routy.bat down routy_down.bat persist-key persist-tun tls-auth ta.key 1routy.bat: route add 192.168.1.4 mask 255.255.255.255 10.1.0.1 metric 20 ...
interface tap0 VPN server all accept client all accept router internet2VPN inface eth0 outface tap0 route all accept router VPN2internet inface tap0 outface eth0 masquerade route all accept
Tiskni
Sdílej:
ISSN 1214-1267, (c) 1999-2007 Stickfish s.r.o.