{"id":4548,"date":"2014-10-22T03:48:06","date_gmt":"2014-10-21T18:48:06","guid":{"rendered":"http:\/\/www.vincentina.net\/?p=4548"},"modified":"2014-10-22T03:48:06","modified_gmt":"2014-10-21T18:48:06","slug":"lpic303-openvpn-02","status":"publish","type":"post","link":"https:\/\/www.vincentina.net\/?p=4548","title":{"rendered":"lpic303 openvpn 02"},"content":{"rendered":"<p class=\"entry-title\"><a href=\"http:\/\/www.vincentina.net\/?p=4544\" rel=\"bookmark\">lpic303 openvpn 01<\/a><\/p>\n<p>\u3055\u3066\u3001OpenVPN\u3067\u3059\u304c\u3001\u30b5\u30fc\u30d0\u30fc\u306b\u5165\u3063\u3066\u307f\u305f\u3089\u904e\u53bb\u306b\u8a2d\u5b9a\u6e08\u307f\u3060\u3063\u305fOpenVPN\u304c\u6b8b\u3063\u3066\u3044\u305f\u306e\u3067\u3001\u30a4\u30f3\u30b9\u30c8\u30fc\u30eb\u306e\u30ed\u30b0\u3092\u4e26\u3079\u3066\u8efd\u304f\u8aac\u660e\u3063\u3066\u306e\u3082\u6bce\u5ea6\u306e\u6bce\u5ea6\u306e\u4e8b\u306a\u306e\u3067\u3001\u8a2d\u5b9a\u6e08\u307f\u306e\u3082\u306e\u3092\u5f04\u308a\u306a\u304c\u3089\u8aac\u660e\u3092\u52a0\u3048\u306a\u304c\u3089\u9032\u3081\u305f\u3044\u3068\u601d\u3044\u307e\u3059\u3002<\/p>\n<p>OpenVPN\u306e\u30c7\u30d5\u30a9\u30eb\u30c8\u306e\u30dd\u30fc\u30c8\u756a\u53f7\u306f1194\u756a\u3067\u3059\u3002OpenVPN\u306fHTTP\u30d7\u30ed\u30ad\u30b7\u7d4c\u7531\u3067\u306e\u63a5\u7d9a\u3082\u53ef\u80fd\u306a\u306e\u3067\u3001\u300c\u826f\u3044\u4e32\u4f5c\u308d\u3046OpenVPN\u300d\u3068\u899a\u3048\u3066\u3082\u3044\u3044\u304b\u3082\u306d\u3002\u52d8\u9055\u3044\u3057\u305d\u3046\u3060\u3051\u308c\u3069\u3002<\/p>\n<p>\u30b5\u30fc\u30d0\u30fc\u306e\u8a2d\u5b9a\u306f\/etc\/openvpn\/server.conf\u3067\u884c\u3044\u307e\u3059\u3002\u3060\u3044\u305f\u3044\/usr\/share\/doc\/openvpn-2.2.2\/sample-config-files\/server.conf\u306e\u30b5\u30f3\u30d7\u30eb\u3092\u30b3\u30d4\u30fc\u3057\u3066\u8a2d\u5b9a\u3092\u9032\u3081\u3066\u3044\u304d\u307e\u3059\u3002<\/p>\n<p>\u73fe\u5728\u306econf\u30d5\u30a1\u30a4\u30eb\u3092\u898b\u306a\u304c\u3089\u9032\u3081\u307e\u3057\u3087\u3046\u3002\u4ee5\u4e0b\u306e\u30b3\u30de\u30f3\u30c9\u306e\u7d50\u679c\u3092\u4e26\u3079\u3066\u884c\u304d\u307e\u3059\u3002<\/p>\n<pre># cat \/etc\/openvpn\/server.conf | egrep -v \"^#|^\\s*$\"<\/pre>\n<p>\u30c7\u30d5\u30a9\u30eb\u30c8\u30dd\u30fc\u30c8\u3067\u554f\u984c\u306a\u3051\u308c\u3070\u3053\u306e\u307e\u307e\u3067\u3002<\/p>\n<pre>port 1194<\/pre>\n<p>UDP\u304c\u30c7\u30d5\u30a9\u3067\u3059\u304c\u3001TCP\u304c\u826f\u3051\u308c\u3070TCP\u306b\u5909\u66f4\u3059\u308c\u3070OK\u3067\u3059\u3002<br \/>\nIptables\u306a\u3069FW\u306e\u8a2d\u5b9a\u306b\u6c17\u3092\u4ed8\u3051\u308b\u3079\u3057\u3002<\/p>\n<pre>;proto tcp\r\nproto udp<\/pre>\n<p>VPN\u30a4\u30f3\u30bf\u30fc\u30d5\u30a7\u30fc\u30b9\u3068\u3057\u3066tap\u304btun\u306e\u3069\u3061\u3089\u3092\u4f7f\u3046\u304b\u3002\u3067\u3076\u305f\u3093\u3068\u898b\u308b\u3068\u4f55\u3068\u306a\u304f\u304b\u308f\u3044\u3044\u3067\u3059\u304c\u3001\u30c8\u30f3\u30cd\u30ea\u30f3\u30b0\u30c7\u30d0\u30a4\u30b9\u306e\u4e8b\u3092\u6307\u3057\u3066\u307e\u3059\u3002<br \/>\n\u3053\u3053\u3067\u306ftun\u3092\u4f7f\u3063\u3066\u3044\u307e\u3059\u304c\u3001tun\u306fL3\u901a\u4fe1\u3067Point-to-Point\u3002<br \/>\ntap\u306fL2\u901a\u4fe1\u3067\u3059\u3002<\/p>\n<pre>;dev tap\r\ndev tun<\/pre>\n<p>ifconfig\u3092\u898b\u308b\u3068\u5206\u304b\u308a\u307e\u3059\u3002<\/p>\n<pre>tun0\u00a0\u00a0\u00a0\u00a0\u00a0 Link encap:UNSPEC\u00a0 HWaddr 00-00-00-00-00-00-00-00-00-00-00-00-00-00-00-00\r\n\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 inet addr:192.168.2.1\u00a0 P-t-P:192.168.2.2\u00a0 Mask:255.255.255.255\r\n\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 UP POINTOPOINT RUNNING NOARP MULTICAST\u00a0 MTU:1500\u00a0 Metric:1<\/pre>\n<p>peer to peer \u3068\u306f\u9055\u3044\u307e\u3059\u3088\u3002<\/p>\n<p>\u7d9a\u3044\u3066\u306f\u6697\u53f7\u5316\u95a2\u9023\u304c\u7d9a\u3044\u3066\u3044\u307e\u3059\u306d\u3002\u8a3c\u660e\u66f8\u3084\u6697\u53f7\u9375\u306e\u751f\u6210\u306a\u3069\u306fVPN\u3068\u3044\u3046\u3088\u308aSSL\u901a\u4fe1\u306e\u7bc4\u7587\u306b\u306a\u308b\u304b\u3068\u601d\u3046\u306e\u3067\u3056\u3063\u304f\u308a\u9032\u3081\u307e\u3059\u3002<\/p>\n<p>\/etc\/openvpn\/easy-rsa\/2.0\/vars\u30d5\u30a1\u30a4\u30eb\u3092\u4fee\u6b63\u3057\u3066\u9375\u60c5\u5831\u3092\u5165\u529b\u3057\u307e\u3059\u3002<br \/>\n\/etc\/openvpn\/easy-rsa\/2.0\u30c7\u30a3\u30ec\u30af\u30c8\u30ea\u5185\u306b\u751f\u6210\u30b9\u30af\u30ea\u30d7\u30c8\u304c\u5165\u3063\u3066\u3044\u308b\u306e\u3067\u3001\u30b9\u30af\u30ea\u30d7\u30c8\u3067\u51fa\u6765\u4e0a\u304c\u3063\u305f\u9375\u3084\u8a3c\u660e\u66f8\u3092\/etc\/openvpn\/easy-rsa\/2.0\/keys\/\u30c7\u30a3\u30ec\u30af\u30c8\u30ea\u306b\u7f6e\u3044\u3066\u304a\u304d\u307e\u3059\u3002<br \/>\nserver.conf\u306b\u8a18\u8ff0\u3059\u308c\u3070\u5b8c\u4e86\u3067\u3059\u3002<\/p>\n<pre>ca ca.crt\r\ncert server.crt\r\nkey server.key\u00a0 # This file should be kept secret\r\ndh dh1024.pem<\/pre>\n<p>\u7d9a\u3044\u3066\u306fDHCP\u3068\u3057\u3066\u306e\u8a18\u8ff0\u3067\u3001\u30af\u30e9\u30a4\u30a2\u30f3\u30c8\u306b\u6e21\u3059IP\u306e\u7bc4\u56f2\u3067\u3059\u306a\u3002<\/p>\n<pre>server 192.168.2.0 255.255.255.0<\/pre>\n<p>10\u79d2\u30671\u56de\u306e\u6b7b\u6d3b\u76e3\u8996\u3067\u3059\u3002120\u79d2\u5fdc\u7b54\u304c\u306a\u3051\u308c\u3070\u30bb\u30c3\u30b7\u30e7\u30f3\u304c\u5207\u308c\u307e\u3059\u3002<\/p>\n<pre>keepalive 10 120<\/pre>\n<p>\u5171\u901a\u6697\u53f7\u5316\u9375\u3092\u4f7f\u7528\u3057\u3066\u3059\u308b\u5834\u5408\u306f\u3001\u6307\u5b9a\u3059\u308b\u3002<\/p>\n<pre>tls-auth ta.key 0 # This file is secret<\/pre>\n<p>LZO\u5727\u7e2e\u3092\u5229\u7528\u3059\u308b\u304b\u3002<\/p>\n<pre>comp-lzo<\/pre>\n<p>\u304a\u306a\u3058\u307f\u306e\u3042\u308c\u3067\u3059\u304c\u3001\u6700\u5927\u540c\u6642\u63a5\u7d9a\u6570\u3067\u3059\u3002<\/p>\n<pre>max-clients 2<\/pre>\n<p>\u30e6\u30fc\u30b6\u30fc\u6a29\u9650\u306e\u5b9f\u884c\u3068\u306a\u308b\u306e\u3067\u3001Unix\u7cfbOS\u3092\u4f7f\u7528\u3057\u3066\u3044\u308b\u5834\u5408\u306f\u30bb\u30ad\u30e5\u30a2\u306b\u306a\u308a\u307e\u3059\u3002<\/p>\n<pre>user nobody\r\ngroup nobody<\/pre>\n<p>\u4e0d\u610f\u306b\u5207\u65ad\u3057\u305f\u6642\u306b\u3001\u518d\u63a5\u7d9a\u6642\u306b\u8a18\u61b6\u3057\u3066\u304a\u304f\u304b\u3002<\/p>\n<pre>persist-key\r\npersist-tun<\/pre>\n<p>\u3053\u306e3\u884c\u306f\u30ed\u30b0\u95a2\u9023\u3067\u3059\u3002<br \/>\n\u4e0a\u304b\u3089\u63a5\u7d9a\u4e2d\u306e\u30af\u30e9\u30a4\u30a2\u30f3\u30c8\u30ea\u30b9\u30c8\u3002VPN\u306e\u30ed\u30b0\u3002\u30ed\u30b0\u30ec\u30d9\u30eb\u3002\u3067\u3057\uff01\uff01<\/p>\n<pre>status openvpn-status.log\r\nlog-append \/var\/log\/openvpn.log\r\nverb 3<\/pre>\n<p>\u5f8c\u306e4\u884c\u306f\u697d\u306b\u4f7f\u3048\u308b\u3088\u3046\u306b\u3069\u3053\u304b\u3067\u30b0\u30b0\u3063\u3066\u304d\u305f\u8a2d\u5b9a\u3067\u3059\u3002<br \/>\n\u30c7\u30d5\u30a9\u30eb\u30c8\u3067\u306f push &#8220;route 192.168.10.0 255.255.255.0&#8221; \u306e\u3088\u3046\u306a\u8a18\u8ff0\u3067\u3001\u30af\u30e9\u30a4\u30a2\u30f3\u30c8\u306e\u30c7\u30d5\u30a9\u30eb\u30c8\u30b2\u30fc\u30c8\u30a6\u30a7\u30a4\u3092VPN\u7d4c\u7531\u306b\u3059\u308b\u3088\u3046\u306b\u30eb\u30fc\u30c6\u30a3\u30f3\u30b0\u30c6\u30fc\u30d6\u30eb\u3092\u8a2d\u5b9a\u3057\u307e\u3059\u3002<br \/>\n\u4e00\u756a\u4e0b\u306e\u306f\u540c\u3058\u9375\u304c\u4f7f\u3048\u308b\u3088\u3046\u306b\u306a\u308a\u307e\u3059\u3002<br \/>\n\u3054\u89a7\u306e\u3088\u3046\u306b\u30bb\u30ad\u30e5\u30a2\u306b\u3057\u305f\u3044\u306a\u3089\u3084\u3089\u306a\u3044\u65b9\u304c\u3044\u3044\u304b\u306a\uff1f<\/p>\n<pre>push \"redirect-gateway def1\"\r\npush \"dhcp-option DNS 8.8.8.8\"\r\npush \"dhcp-option DNS 8.8.4.4\"\r\nduplicate-cn<\/pre>\n<p>\u53c2\u8003\u30b5\u30a4\u30c8<\/p>\n<p><a href=\"http:\/\/blog.8796.jp\/8796kanri\/\">8796.jp\u7ba1\u7406\u65e5\u8a8c<\/a><\/p>\n<p><a href=\"http:\/\/www.openvpn.jp\/document\/how-to\/\" target=\"_blank\">OpenVPN.JP<\/a><\/p>\n<p>unixuser.org\u306e\u30da\u30fc\u30b8\u3000<a href=\"http:\/\/www.unixuser.org\/~euske\/doc\/openssh\/openssh-vpn.html\" target=\"_blank\">OpenSSH\u3092\u4f7f\u3063\u305f\u7c21\u6613VPN\u306e\u69cb\u7bc9<\/a><\/p>\n<p class=\"entry-title\"><a href=\"http:\/\/sourceforge.jp\/magazine\/11\/05\/10\/1025227\/5\" target=\"_blank\">\u6bce\u6708\u9032\u5316\u3059\u308b490\u5186\/\u6708\u306eVPS\u300cServersMan@VPS\u300d\u3092\u30aa\u30f3\u30e9\u30a4\u30f3\u30b9\u30c8\u30ec\u30fc\u30b8\u3084VPN\u3067\u6d3b\u7528\u3057\u3088\u3046<\/a><\/p>\n<p class=\"entry-title\">\n<p class=\"entry-title\">\u7720\u3044\u30fb\u30fb|\u0434\uff9f)<br \/>\n\u6b21\u56de\u306b\u3064\u3065\u304f\uff01\uff01<\/p>\n<p class=\"entry-title\">\n<div class='wp_social_bookmarking_light'>        <div class=\"wsbl_twitter\"><a href=\"https:\/\/twitter.com\/share\" class=\"twitter-share-button\" data-url=\"https:\/\/www.vincentina.net\/?p=4548\" data-text=\"lpic303 openvpn 02\" data-via=\"TakekenTw\" data-lang=\"ja\">Tweet<\/a><\/div><\/div>\n<br class='wp_social_bookmarking_light_clear' \/>\n","protected":false},"excerpt":{"rendered":"<p>lpic303 openvpn 01 \u3055\u3066\u3001OpenVPN\u3067\u3059\u304c\u3001\u30b5\u30fc\u30d0\u30fc\u306b\u5165\u3063\u3066\u307f\u305f\u3089\u904e\u53bb\u306b\u8a2d\u5b9a\u6e08\u307f\u3060\u3063\u305fOpenVPN\u304c\u6b8b\u3063\u3066\u3044\u305f\u306e\u3067\u3001\u30a4\u30f3\u30b9\u30c8\u30fc\u30eb\u306e\u30ed\u30b0\u3092\u4e26\u3079\u3066\u8efd\u304f\u8aac\u660e\u3063\u3066\u306e\u3082\u6bce\u5ea6\u306e\u6bce\u5ea6\u306e\u4e8b\u306a\u306e\u3067\u3001\u8a2d\u5b9a\u6e08\u307f\u306e\u3082\u306e\u3092 &hellip; <a href=\"https:\/\/www.vincentina.net\/?p=4548\" class=\"more-link\"><span class=\"screen-reader-text\">&#8220;lpic303 openvpn 02&#8221; \u306e<\/span>\u7d9a\u304d\u3092\u8aad\u3080<\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6],"tags":[],"class_list":["post-4548","post","type-post","status-publish","format-standard","hentry","category-server"],"_links":{"self":[{"href":"https:\/\/www.vincentina.net\/index.php?rest_route=\/wp\/v2\/posts\/4548","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.vincentina.net\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.vincentina.net\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.vincentina.net\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.vincentina.net\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=4548"}],"version-history":[{"count":0,"href":"https:\/\/www.vincentina.net\/index.php?rest_route=\/wp\/v2\/posts\/4548\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.vincentina.net\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=4548"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.vincentina.net\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=4548"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.vincentina.net\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=4548"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}