Portál AbcLinuxu, 12. května 2025 12:45
mode server port 88 proto tcp-server tls-server dev tap0 server-bridge 192.168.2.113 255.255.255.0 192.168.2.60 192.168.2.70 duplicate-cn ca /etc/openvpn/cert/cacert.pem cert /etc/openvpn/cert/cert.pem key /etc/openvpn/cert/key.pem dh /etc/openvpn/cert/dh1024.pem log-append /var/log/openvpn status /tmp/vpn.status 10 user openvpn group openvpn comp-lzo verb 3 #push "route-gateway 192.168.2.1" #push "route 0.0.0.0 0.0.0.0" #push "redirect-gateway " push "dhcp-option DNS 8.8.8.8" persist-tun persist-key keepalive 1 220konfigurace klienta:
remote moje-adresa proto tcp-client tls-client port 88 dev tap pull ns-cert-type server mute 10 ca cacert.pem cert cert.pem key key.pem comp-lzo verb 3
Řešení dotazu:
# server side: /etc/openvpn/client.conf: local ServerPublicIP port 1194 proto udp dev tap0 up up.sh down down.sh ca /etc/openvpn/easy-rsa/keys/ca.crt cert /etc/openvpn/easy-rsa/keys/server.crt key /etc/openvpn/easy-rsa/keys/server.key dh /etc/pki/tls/certs/openvpn-dh1024.pem ifconfig-pool-persist ipp.txt server-bridge 192.168.101.99 255.255.254.0 192.168.100.120 192.168.100.197 push "redirect-gateway" keepalive 10 120 comp-lzo persist-key persist-tun status openvpn-status.log #verb 3 #!/bin/sh # server side: /etc/openvpn/up.sh # the tap interface name is passed as first argument bridge=br0 logger -t openvpn-up "#=$#, @:$@" /usr/sbin/brctl addif "$bridge" "$1" /sbin/ip link set $1 up #!/bin/sh # server side: /etc/openvpn/down.sh # the tap interface name is passed as first argument bridge=br0 logger -t openvpn-down "#=$#, @:$@" /sbin/ip link set $1 down /usr/sbin/brctl delif "$bridge" "$1" # client side: /etc/openvpn/client.conf: client dev tap proto udp remote ServerIP-or-FQDN 1194 resolv-retry infinite nobind persist-key persist-tun ca /etc/openvpn/easy-rsa/keys/ca.crt cert /etc/openvpn/easy-rsa/keys/client3.crt key /etc/openvpn/easy-rsa/keys/client3.key ns-cert-type server comp-lzo #verb 3 #!/bin/sh # client /etc/openvpn/up.sh # the tap interface name is passed as first argument logger -t openvpn-up "client #=$#, @:$@" nastav_DNS_servery #!/bin/sh # client /etc/openvpn/down.sh # the tap interface name is passed as first argument logger -t openvpn-down "client #=$#, @:$@" navrat_puvodni_DNS_servery
up up.sh down down.sh
Tiskni
Sdílej:
ISSN 1214-1267, (c) 1999-2007 Stickfish s.r.o.