You've already forked www.colben.cn
update
This commit is contained in:
@@ -6,14 +6,14 @@ tags: ["openvpn"]
|
||||
categories: ["network"]
|
||||
---
|
||||
|
||||
# 环境
|
||||
## 环境
|
||||
|
||||
角色 | 主机名 | 操作系统 | IP
|
||||
---- | ---- | ---- | ----
|
||||
vpn 服务端 | vpn-server | CentOS7 | 192.168.1.90
|
||||
vpn 客户端 | vpn-client | CentOS7 | 192.168.1.91
|
||||
|
||||
# 两台服务器初始准备
|
||||
## 两台服务器初始准备
|
||||
- 关闭 SELinux
|
||||
- 关闭防火墙或放行 udp 端口 1194
|
||||
- 安装 openvpn
|
||||
@@ -24,7 +24,7 @@ vpn 客户端 | vpn-client | CentOS7 | 192.168.1.91
|
||||
yum install easy-rsa openvpn
|
||||
```
|
||||
|
||||
# 在 vpn-server 上创建证书
|
||||
## 在 vpn-server 上创建证书
|
||||
- 复制 easy-rsa 脚本到 /opt/easy-rsa/ 下
|
||||
```bash
|
||||
cp -af /usr/share/easy-rsa/3.0.3/ /opt/easy-rsa
|
||||
@@ -99,7 +99,7 @@ vpn 客户端 | vpn-client | CentOS7 | 192.168.1.91
|
||||
```
|
||||
- **该证书目录 /opt/easyrsa 需妥善保管,后期增加其他客户端证书时会用到**
|
||||
|
||||
# 配置 vpn-server
|
||||
## 配置 vpn-server
|
||||
- 开启路由转发,修改 /etc/sysctl.conf
|
||||
```bash
|
||||
sysctl -w 'net.ipv4.ip_forward = 1'
|
||||
@@ -126,7 +126,7 @@ vpn 客户端 | vpn-client | CentOS7 | 192.168.1.91
|
||||
tls-auth my-server0/ta.key 0
|
||||
```
|
||||
|
||||
# 启动 vpn-server 服务
|
||||
## 启动 vpn-server 服务
|
||||
- 启动 openvpn-server@my-server0.service 服务
|
||||
```bash
|
||||
systemctl start openvpn-server@my-server0.service
|
||||
@@ -136,7 +136,7 @@ vpn 客户端 | vpn-client | CentOS7 | 192.168.1.91
|
||||
systemd-tty-ask-password-agent --query
|
||||
```
|
||||
|
||||
# 配置 vpn-client
|
||||
## 配置 vpn-client
|
||||
- 复制 vpn-server 上的客户端证书到 openvpn 配置目录下
|
||||
```bash
|
||||
mkdir -p /etc/openvpn/client/my-client0
|
||||
@@ -156,7 +156,7 @@ vpn 客户端 | vpn-client | CentOS7 | 192.168.1.91
|
||||
tls-auth my-client0/ta.key 1
|
||||
```
|
||||
|
||||
# 启动 vpn-client 服务
|
||||
## 启动 vpn-client 服务
|
||||
- 启动 openvpn-client@my-client0 服务
|
||||
```bash
|
||||
systemctl start openvpn-client@my-client0.service
|
||||
@@ -166,10 +166,10 @@ vpn 客户端 | vpn-client | CentOS7 | 192.168.1.91
|
||||
systemd-tty-ask-password-agent --query
|
||||
```
|
||||
|
||||
# 验证
|
||||
## 验证
|
||||
- vpn server 新增网卡 tun0,地址是 10.8.0.1/24
|
||||
- vpn client 新增网卡 tun0,地址是 10.8.0.2/24
|
||||
|
||||
# 参考
|
||||
## 参考
|
||||
- [创建证书](https://blog.csdn.net/zhuwei_clark/article/details/87949043)
|
||||
|
||||
|
Reference in New Issue
Block a user