ืžืขื‘ืจ ืž-OpenVPN ืœ-WireGuard ื›ื“ื™ ืœืฉืœื‘ ืจืฉืชื•ืช ืœืจืฉืช L2 ืื—ืช

ืžืขื‘ืจ ืž-OpenVPN ืœ-WireGuard ื›ื“ื™ ืœืฉืœื‘ ืจืฉืชื•ืช ืœืจืฉืช L2 ืื—ืช

ื‘ืจืฆื•ื ื™ ืœื—ืœื•ืง ืืช ื”ื—ื•ื•ื™ื” ืฉืœื™ ื‘ืฉื™ืœื•ื‘ ืจืฉืชื•ืช ื‘ืฉืœื•ืฉ ื“ื™ืจื•ืช ืžืจื•ื—ืงื•ืช ื’ื™ืื•ื’ืจืคื™ืช, ืฉื›ืœ ืื—ืช ืžื”ืŸ ืžืฉืชืžืฉืช ื‘ื ืชื‘ื™ OpenWRT ื›ืฉืขืจ, ืœืจืฉืช ืื—ืช ืžืฉื•ืชืคืช. ื‘ื‘ื—ื™ืจืช ืฉื™ื˜ื” ืœืฉื™ืœื•ื‘ ืจืฉืชื•ืช ื‘ื™ืŸ L3 ืขื ื ื™ืชื•ื‘ ืจืฉืช ืžืฉื ื” ืœ-L2 ืขื ื’ื™ืฉื•ืจ, ื›ืืฉืจ ื›ืœ ืฆืžืชื™ ื”ืจืฉืช ื™ื”ื™ื• ื‘ืื•ืชื” ืจืฉืช ืžืฉื ื”, ื ื™ืชื ื” ื”ืขื“ืคื” ืœืฉื™ื˜ื” ื”ืฉื ื™ื™ื”, ืฉืงืฉื” ื™ื•ืชืจ ืœื”ื’ื“ื™ืจ ืื•ืชื”, ืืš ืžืกืคืงืช ื”ื–ื“ืžื ื•ื™ื•ืช ื’ื“ื•ืœื•ืช ื™ื•ืชืจ, ืฉื›ืŸ ืชื•ื›ื ืŸ ืฉื™ืžื•ืฉ ืฉืงื•ืฃ ื‘ื˜ื›ื ื•ืœื•ื’ื™ื•ืช ื‘ืจืฉืช ืฉื ื•ืฆืจืช Wake-on-Lan ื•-DLNA.

ื—ืœืง 1: ืจืงืข

OpenVPN ื ื‘ื—ืจ ื‘ืชื—ื™ืœื” ื›ืคืจื•ื˜ื•ืงื•ืœ ืœื™ื™ืฉื•ื ืžืฉื™ืžื” ื–ื•, ืฉื›ืŸ, ืจืืฉื™ืช, ื”ื•ื ื™ื›ื•ืœ ืœื™ืฆื•ืจ ื”ืชืงืŸ ื‘ืจื– ืฉื ื™ืชืŸ ืœื”ื•ืกื™ืฃ ืœื’ืฉืจ ืœืœื ื‘ืขื™ื•ืช, ื•ืฉื ื™ืช, OpenVPN ืชื•ืžืš ื‘ืคืขื•ืœื” ืขืœ ื’ื‘ื™ ืคืจื•ื˜ื•ืงื•ืœ TCP, ืžื” ืฉื’ื ื”ื™ื” ื—ืฉื•ื‘, ื›ื™ ืืฃ ืื—ื“ ืœื ืžื”ื“ื™ืจื•ืช ื”ื™ื™ืชื” ื›ืชื•ื‘ืช IP ื™ื™ืขื•ื“ื™ืช, ื•ืœื ื”ืฆืœื—ืชื™ ืœื”ืฉืชืžืฉ ื‘-STUN, ืžื›ื™ื•ื•ืŸ ืฉื”ืกืคืง ืฉืœื™ ื—ื•ืกื ืžืกื™ื‘ื” ื›ืœืฉื”ื™ ื—ื™ื‘ื•ืจื™ UDP ื ื›ื ืกื™ื ืžื”ืจืฉืชื•ืช ืฉืœื”ื, ื‘ืขื•ื“ ืฉืคืจื•ื˜ื•ืงื•ืœ TCP ืืคืฉืจ ืœื™ ืœื”ืขื‘ื™ืจ ืืช ื™ืฆื™ืืช ืฉืจืช ื”-VPN ืœ-VPS ืžื•ืฉื›ืจ ื‘ืืžืฆืขื•ืช SSH. ื›ืŸ, ื’ื™ืฉื” ื–ื• ื ื•ืชื ืช ืขื•ืžืก ื’ื“ื•ืœ, ืžื›ื™ื•ื•ืŸ ืฉื”ื ืชื•ื ื™ื ืžื•ืฆืคื ื™ื ืคืขืžื™ื™ื, ืื‘ืœ ืœื ืจืฆื™ืชื™ ืœื”ื›ื ื™ืก VPS ืœืจืฉืช ื”ืคืจื˜ื™ืช ืฉืœื™, ืžื›ื™ื•ื•ืŸ ืฉืขื“ื™ื™ืŸ ื”ื™ื” ืกื™ื›ื•ืŸ ืฉืฆื“ื“ื™ื ืฉืœื™ืฉื™ื™ื ื™ืฉื™ื’ื• ืฉืœื™ื˜ื” ืขืœื™ื•, ืœื›ืŸ, ื™ืฉ ืžื›ืฉื™ืจ ื›ื–ื” ื‘ืจืฉืช ื”ื‘ื™ืชื™ืช ืฉืœื™ ื”ื™ื” ืžืื•ื“ ืœื ืจืฆื•ื™ ื•ื”ื•ื—ืœื˜ ืœืฉืœื ืขื‘ื•ืจ ืื‘ื˜ื—ื” ืขื ืชืงื•ืจื” ื’ื“ื•ืœื”.

ื›ื“ื™ ืœื”ืขื‘ื™ืจ ืืช ื”ืคื•ืจื˜ ื‘ื ืชื‘ ืฉืขืœื™ื• ืชื•ื›ื ืŸ ืœืคืจื•ืก ืืช ื”ืฉืจืช, ื ืขืฉื” ืฉื™ืžื•ืฉ ื‘ืชื•ื›ื ื™ืช sshtunnel. ืœื ืืชืืจ ืืช ื”ืžื•ืจื›ื‘ื•ื™ื•ืช ืฉืœ ื”ืชืฆื•ืจื” ืฉืœื• - ื–ื” ื ืขืฉื” ื“ื™ ื‘ืงืœื•ืช, ืจืง ืืฆื™ื™ืŸ ืฉื”ืžืฉื™ืžื” ืฉืœื• ื”ื™ื™ืชื” ืœื”ืขื‘ื™ืจ ืืช ื™ืฆื™ืืช TCP 1194 ืžื”ื ืชื‘ ืœ-VPS. ืœืื—ืจ ืžื›ืŸ, ืฉืจืช OpenVPN ื”ื•ื’ื“ืจ ื‘ืžื›ืฉื™ืจ tap0, ืฉื”ื™ื” ืžื—ื•ื‘ืจ ืœื’ืฉืจ br-lan. ืœืื—ืจ ืฉื‘ื“ืงืชื™ ืืช ื”ื—ื™ื‘ื•ืจ ืœืฉืจืช ื”ื—ื“ืฉ ืฉื ื•ืฆืจ ืžื”ืžื—ืฉื‘ ื”ื ื™ื™ื“, ื”ืชื‘ืจืจ ืฉื”ืจืขื™ื•ืŸ ืฉืœ ื”ืขื‘ืจืช ืคื•ืจื˜ื™ื ื”ื™ื” ืžื•ืฆื“ืง ื•ื”ืžื—ืฉื‘ ื”ื ื™ื™ื“ ืฉืœื™ ื”ืคืš ืœื—ื‘ืจ ื‘ืจืฉืช ืฉืœ ื”ื ืชื‘, ืœืžืจื•ืช ืฉื”ื•ื ืœื ื”ื™ื” ื‘ื• ืคื™ื–ื™ืช.

ื ื•ืชืจ ืจืง ื“ื‘ืจ ืื—ื“ ืงื˜ืŸ ืœืขืฉื•ืช: ื”ื™ื” ืฆื•ืจืš ืœื”ืคื™ืฅ ื›ืชื•ื‘ื•ืช IP ื‘ื“ื™ืจื•ืช ืฉื•ื ื•ืช ื›ื“ื™ ืฉืœื ื™ืชื ื’ืฉื• ื•ืœื”ื’ื“ื™ืจ ืืช ื”ื ืชื‘ื™ื ื›ืœืงื•ื—ื•ืช OpenVPN.
ื ื‘ื—ืจื• ื›ืชื•ื‘ื•ืช ื”-IP ืฉืœ ื”ื ืชื‘ ื•ื˜ื•ื•ื—ื™ ืฉืจืชื™ ื”-DHCP ื”ื‘ืื™ื:

  • 192.168.10.1 ืขื ื˜ื•ื•ื— 192.168.10.2 - 192.168.10.80 ืขื‘ื•ืจ ื”ืฉืจืช
  • 192.168.10.100 ืขื ื˜ื•ื•ื— 192.168.10.101 - 192.168.10.149 ืœืจืื•ื˜ืจ ื‘ื“ื™ืจื” ืžืก' 2
  • 192.168.10.150 ืขื ื˜ื•ื•ื— 192.168.10.151 - 192.168.10.199 ืœืจืื•ื˜ืจ ื‘ื“ื™ืจื” ืžืก' 3

ื”ื™ื” ืฆื•ืจืš ื’ื ืœื”ืงืฆื•ืช ื‘ื“ื™ื•ืง ืืช ื”ื›ืชื•ื‘ื•ืช ื”ืœืœื• ืœื ืชื‘ื™ ื”ืœืงื•ื— ืฉืœ ืฉืจืช OpenVPN ืขืœ ื™ื“ื™ ื”ื•ืกืคืช ื”ืฉื•ืจื” ืœืชืฆื•ืจื” ืฉืœื•:

ifconfig-pool-persist /etc/openvpn/ipp.txt 0

ื•ื”ื•ืกืคืช ื”ืฉื•ืจื•ืช ื”ื‘ืื•ืช ืœืงื•ื‘ืฅ /etc/openvpn/ipp.txt:

flat1_id 192.168.10.100
flat2_id 192.168.10.150

ื›ืืฉืจ flat1_id ื•-flat2_id ื”ื ืฉืžื•ืช ื”ืžื›ืฉื™ืจื™ื ืฉืฆื•ื™ื ื• ื‘ืขืช ื™ืฆื™ืจืช ืื™ืฉื•ืจื™ื ืœื—ื™ื‘ื•ืจ ืœ-OpenVPN

ืœืื—ืจ ืžื›ืŸ, ืœืงื•ื—ื•ืช OpenVPN ื”ื•ื’ื“ืจื• ื‘ื ืชื‘ื™ื, ื”ืชืงื ื™ tap0 ื‘ืฉื ื™ื”ื ื ื•ืกืคื• ืœื’ืฉืจ br-lan. ื‘ืฉืœื‘ ื–ื”, ื ืจืื” ื”ื™ื” ืฉื”ื›ืœ ื‘ืกื“ืจ ืžื›ื™ื•ื•ืŸ ืฉื›ืœ ืฉืœื•ืฉ ื”ืจืฉืชื•ืช ื™ื›ืœื• ืœืจืื•ืช ื–ื• ืืช ื–ื• ื•ืœืขื‘ื•ื“ ื›ืื—ืช. ืขื ื–ืืช, ืคืจื˜ ืœื ื ืขื™ื ื‘ืžื™ื•ื—ื“ ืฆืฅ: ืœืคืขืžื™ื ืžื›ืฉื™ืจื™ื ื™ื›ืœื• ืœืงื‘ืœ ื›ืชื•ื‘ืช IP ืฉืœื ืžื”ื ืชื‘ ืฉืœื”ื, ืขื ื›ืœ ื”ื”ืฉืœื›ื•ืช ื”ื ื•ื‘ืขื•ืช ืžื›ืš. ืžืฉื•ื ืžื”, ื”ื ืชื‘ ื‘ืื—ืช ื”ื“ื™ืจื•ืช ืœื ื”ืกืคื™ืง ืœื”ื’ื™ื‘ ื‘ื–ืžืŸ ืœ-DHCPDISCOVER ื•ื”ืžื›ืฉื™ืจ ืงื™ื‘ืœ ื›ืชื•ื‘ืช ืฉืœื ื”ื™ื™ืชื” ืžื™ื•ืขื“ืช. ื”ื‘ื ืชื™ ืฉืื ื™ ืฆืจื™ืš ืœืกื ืŸ ื‘ืงืฉื•ืช ื›ืืœื” ื‘-tap0 ื‘ื›ืœ ืื—ื“ ืžื”ื ืชื‘ื™ื, ืื‘ืœ ื›ืคื™ ืฉื”ืชื‘ืจืจ, iptables ืœื ื™ื›ื•ืœื™ื ืœืขื‘ื•ื“ ืขื ื”ืžื›ืฉื™ืจ ืื ื”ื•ื ื—ืœืง ืžื’ืฉืจ ื•-ebtables ื—ื™ื™ื‘ื™ื ืœื‘ื•ื ืœืขื–ืจืชื™. ืœืฆืขืจื™, ื–ื” ืœื ื”ื™ื” ื‘ืงื•ืฉื—ื” ืฉืœื™ ื•ื”ื™ื™ืชื™ ืฆืจื™ืš ืœื‘ื ื•ืช ืžื—ื“ืฉ ืืช ื”ืชืžื•ื ื•ืช ืขื‘ื•ืจ ื›ืœ ืžื›ืฉื™ืจ. ืขืœ ื™ื“ื™ ื‘ื™ืฆื•ืข ืคืขื•ืœื” ื–ื• ื•ื”ื•ืกืคืช ืฉื•ืจื•ืช ืืœื” ืœ-/etc/rc.local ืฉืœ ื›ืœ ื ืชื‘, ื”ื‘ืขื™ื” ื ืคืชืจื”:

ebtables -A INPUT --in-interface tap0 --protocol ipv4 --ip-protocol udp --ip-destination-port 67:68 -j DROP
ebtables -A INPUT --in-interface tap0 --protocol ipv4 --ip-protocol udp --ip-source-port 67:68 -j DROP
ebtables -A FORWARD --out-interface tap0 --protocol ipv4 --ip-protocol udp --ip-destination-port 67:68 -j DROP
ebtables -A FORWARD --out-interface tap0 --protocol ipv4 --ip-protocol udp --ip-source-port 67:68 -j DROP

ืชืฆื•ืจื” ื–ื• ื ืžืฉื›ื” ืฉืœื•ืฉ ืฉื ื™ื.

ื—ืœืง 2: ื”ื™ื›ืจื•ืช ืขื WireGuard

ืœืื—ืจื•ื ื”, ืื ืฉื™ื ื‘ืื™ื ื˜ืจื ื˜ ื”ืชื—ื™ืœื• ื™ื•ืชืจ ื•ื™ื•ืชืจ ืœื“ื‘ืจ ืขืœ WireGuard, ืžืชืคืขืœื™ื ืžื”ืคืฉื˜ื•ืช ืฉืœ ื”ืชืฆื•ืจื” ืฉืœื•, ืžื”ื™ืจื•ืช ืฉื™ื“ื•ืจ ื’ื‘ื•ื”ื”, ืคื™ื ื’ ื ืžื•ืš ืขื ืื‘ื˜ื—ื” ื“ื•ืžื”. ื—ื™ืคื•ืฉ ืื—ืจ ืžื™ื“ืข ื ื•ืกืฃ ืขืœ ื–ื” ื”ื‘ื”ื™ืจ ืฉืœื ืขื‘ื•ื“ื” ื›ื—ื‘ืจ ื’ืฉืจ ื•ื’ื ืขื‘ื•ื“ื” ืขืœ ืคืจื•ื˜ื•ืงื•ืœ TCP ืœื ื ืชืžื›ื” ืขืœ ื™ื“ื™ ื–ื”, ืžื” ืฉื’ืจื ืœื™ ืœื—ืฉื•ื‘ ืฉืขื“ื™ื™ืŸ ืื™ืŸ ื—ืœื•ืคื•ืช ืœ-OpenVPN ืขื‘ื•ืจื™. ืื– ื“ื—ื™ืชื™ ืืช ื”ื”ื™ื›ืจื•ืช ืขื WireGuard.

ืœืคื ื™ ืžืกืคืจ ื™ืžื™ื, ื—ื“ืฉื•ืช ื”ืชืคืฉื˜ื• ืขืœ ืคื ื™ ืžืฉืื‘ื™ื ื›ืืœื” ืื• ืื—ืจื™ื ื”ืงืฉื•ืจื™ื ืœ-IT ื›ื™ WireGuard ื™ื™ื›ืœืœ ืกื•ืฃ ืกื•ืฃ ื‘ืœื™ื‘ืช ืœื™ื ื•ืงืก, ื”ื—ืœ ืžื’ืจืกื” 5.6. ื›ืชื‘ื•ืช ื—ื“ืฉื•ืช, ื›ืžื• ืชืžื™ื“, ืฉื™ื‘ื—ื• ืืช WireGuard. ืฉื•ื‘ ืฆืœืœืชื™ ื‘ื—ื™ืคื•ืฉ ืื—ืจ ื“ืจื›ื™ื ืœื”ื—ืœื™ืฃ ืืช OpenVPN ื”ื™ืฉืŸ ื•ื”ื˜ื•ื‘. ื”ืคืขื ื ืชืงืœืชื™ ืžืืžืจ ื–ื”. ื–ื” ื“ื™ื‘ืจ ืขืœ ื™ืฆื™ืจืช ืžื ื”ืจืช Ethernet ืขืœ L3 ื‘ืืžืฆืขื•ืช GRE. ื”ืžืืžืจ ื”ื–ื” ื ืชืŸ ืœื™ ืชืงื•ื•ื”. ืœื ื”ื™ื” ื‘ืจื•ืจ ืžื” ืœืขืฉื•ืช ืขื ืคืจื•ื˜ื•ืงื•ืœ UDP. ื”ื—ื™ืคื•ืฉ ื”ื•ื‘ื™ืœ ืื•ืชื™ ืœืžืืžืจื™ื ืขืœ ืฉื™ืžื•ืฉ ื‘- socat ื‘ืฉื™ืœื•ื‘ ืขื ืžื ื”ืจืช SSH ืœื”ืขื‘ืจืช ื™ืฆื™ืืช UDP, ืขื ื–ืืช, ื”ื ืฆื™ื™ื ื• ืฉื’ื™ืฉื” ื–ื• ืขื•ื‘ื“ืช ืจืง ื‘ืžืฆื‘ ื—ื™ื‘ื•ืจ ื™ื—ื™ื“, ื›ืœื•ืžืจ, ื”ืขื‘ื•ื“ื” ืฉืœ ืžืกืคืจ ืœืงื•ื—ื•ืช VPN ืชื”ื™ื” ื‘ืœืชื™ ืืคืฉืจื™ืช. ื”ื’ืขืชื™ ืœืจืขื™ื•ืŸ ืœื”ืชืงื™ืŸ ืฉืจืช VPN ื‘-VPS ื•ืœื”ื’ื“ื™ืจ GRE ืขื‘ื•ืจ ืœืงื•ื—ื•ืช, ืื‘ืœ ื›ืคื™ ืฉื”ืชื‘ืจืจ, GRE ืื™ื ื• ืชื•ืžืš ื‘ื”ืฆืคื ื”, ืžื” ืฉื™ื•ื‘ื™ืœ ืœื›ืš ืฉืื ืฆื“ื“ื™ื ืฉืœื™ืฉื™ื™ื ื™ืงื‘ืœื• ื’ื™ืฉื” ืœืฉืจืช , ื›ืœ ื”ืชืขื‘ื•ืจื” ื‘ื™ืŸ ื”ืจืฉืชื•ืช ืฉืœื™ ืชื”ื™ื” ื‘ื™ื“ื™ื™ื ืฉืœื”ื, ืžื” ืฉืœื ื”ืชืื™ื ืœื™ ื‘ื›ืœืœ.

ืฉื•ื‘, ื”ื”ื—ืœื˜ื” ื”ืชืงื‘ืœื” ืœื˜ื•ื‘ืช ื”ืฆืคื ื” ืžื™ื•ืชืจืช, ืขืœ ื™ื“ื™ ืฉื™ืžื•ืฉ ื‘-VPN ื“ืจืš VPN ื‘ืืžืฆืขื•ืช ื”ืกื›ื™ืžื” ื”ื‘ืื”:

VPN ื‘ืจืžื” XNUMX:
VPS ื–ื” ืฉืจืช ืขื ื›ืชื•ื‘ืช ืคื ื™ืžื™ืช 192.168.30.1
ืž.ืก. ื–ื” ืœึธืงื•ึผื—ึท VPS ืขื ื›ืชื•ื‘ืช ืคื ื™ืžื™ืช 192.168.30.2
MK2 ื–ื” ืœึธืงื•ึผื—ึท VPS ืขื ื›ืชื•ื‘ืช ืคื ื™ืžื™ืช 192.168.30.3
MK3 ื–ื” ืœึธืงื•ึผื—ึท VPS ืขื ื›ืชื•ื‘ืช ืคื ื™ืžื™ืช 192.168.30.4

VPN ื‘ืจืžื” ืฉื ื™ื™ื”:
ืž.ืก. ื–ื” ืฉืจืช ืขื ื›ืชื•ื‘ืช ื—ื™ืฆื•ื ื™ืช 192.168.30.2 ื•ื›ืชื•ื‘ืช ืคื ื™ืžื™ืช 192.168.31.1
MK2 ื–ื” ืœึธืงื•ึผื—ึท ืž.ืก. ืขื ื”ื›ืชื•ื‘ืช 192.168.30.2 ื•ื™ืฉ ืœื• IP ืคื ื™ืžื™ 192.168.31.2
MK3 ื–ื” ืœึธืงื•ึผื—ึท ืž.ืก. ืขื ื”ื›ืชื•ื‘ืช 192.168.30.2 ื•ื™ืฉ ืœื• IP ืคื ื™ืžื™ 192.168.31.3

* ืž.ืก. โ€” ืฉืจืช ื ืชื‘ ื‘ื“ื™ืจื” 1, MK2 - ื ืชื‘ ื‘ื“ื™ืจื” 2, MK3 - ื ืชื‘ ื‘ื“ื™ืจื” 3
* ืชืฆื•ืจื•ืช ื”ืžื›ืฉื™ืจ ืžืชืคืจืกืžื•ืช ื‘ืกืคื•ื™ืœืจ ื‘ืกื•ืฃ ื”ืžืืžืจ.

ื•ื›ืš, ืคื™ื ื’ื™ื ืคื•ืขืœื™ื ื‘ื™ืŸ ืฆืžืชื™ ืจืฉืช 192.168.31.0/24, ื”ื’ื™ืข ื”ื–ืžืŸ ืœืขื‘ื•ืจ ืœื”ื’ื“ืจืช ืžื ื”ืจืช GRE. ืœืคื ื™ ื›ืŸ, ื›ื“ื™ ืœื ืœืื‘ื“ ื’ื™ืฉื” ืœื ืชื‘ื™ื, ื›ื“ืื™ ืœื”ื’ื“ื™ืจ ืžื ื”ืจื•ืช SSH ืœื”ืขื‘ืจืช ื™ืฆื™ืื” 22 ืœ-VPS, ื›ืš, ืœืžืฉืœ, ื”ื ืชื‘ ืžื“ื™ืจื” 10022 ื™ื”ื™ื” ื ื’ื™ืฉ ื‘ื™ืฆื™ืื” 2 ืฉืœ ื”-VPS, ื•ื”-VPS. ื ืชื‘ ืžื“ื™ืจื” 11122 ื™ื”ื™ื” ื ื’ื™ืฉ ื‘ื ืชื‘ ื™ืฆื™ืื” 3 ืžื“ื™ืจื” XNUMX. ืขื“ื™ืฃ ืœื”ื’ื“ื™ืจ ื”ืขื‘ืจื” ื‘ืืžืฆืขื•ืช ืื•ืชื• sshtunnel, ืžื›ื™ื•ื•ืŸ ืฉื”ื•ื ื™ืฉื—ื–ืจ ืืช ื”ืžื ื”ืจื” ืื ื”ื™ื ืชื™ื›ืฉืœ.

ื”ืžื ื”ืจื” ืžื•ื’ื“ืจืช, ืืชื” ื™ื›ื•ืœ ืœื”ืชื—ื‘ืจ ืœ-SSH ื“ืจืš ื”ื™ืฆื™ืื” ื”ืžื•ืขื‘ืจืช:

ssh root@ะœะžะ™_VPS -p 10022

ื‘ืฉืœื‘ ื”ื‘ื ืขืœื™ืš ืœื”ืฉื‘ื™ืช ืืช OpenVPN:

/etc/init.d/openvpn stop

ืขื›ืฉื™ื• ื‘ื•ืื• ื ื’ื“ื™ืจ ืžื ื”ืจืช GRE ืขืœ ื”ื ืชื‘ ืžื“ื™ืจื” 2:

ip link add grelan0 type gretap remote 192.168.31.1 local 192.168.31.2
ip link set grelan0 up

ื•ื”ื•ืกื™ืคื• ืืช ื”ืžืžืฉืง ืฉื ื•ืฆืจ ืœื’ืฉืจ:

brctl addif br-lan grelan0

ื‘ื•ืื• ื ื‘ืฆืข ื”ืœื™ืš ื“ื•ืžื” ื‘ื ืชื‘ ื”ืฉืจืช:

ip link add grelan0 type gretap remote 192.168.31.2 local 192.168.31.1
ip link set grelan0 up

ื•ื’ื ื”ื•ืกืฃ ืืช ื”ืžืžืฉืง ืฉื ื•ืฆืจ ืœื’ืฉืจ:

brctl addif br-lan grelan0

ื”ื—ืœ ืžืจื’ืข ื–ื”, ืคื™ื ื’ื™ื ืžืชื—ื™ืœื™ื ืœืขื‘ื•ืจ ื‘ื”ืฆืœื—ื” ืœืจืฉืช ื”ื—ื“ืฉื” ื•ืื ื™, ื‘ืกื™ืคื•ืง, ื”ื•ืœืš ืœืฉืชื•ืช ืงืคื”. ืœืื—ืจ ืžื›ืŸ, ื›ื“ื™ ืœื”ืขืจื™ืš ื›ื™ืฆื“ ื”ืจืฉืช ืคื•ืขืœืช ื‘ืงืฆื” ื”ืฉื ื™ ืฉืœ ื”ืงื•, ืื ื™ ืžื ืกื” ืœื”ื›ื ื™ืก SSH ืœืื—ื“ ืžื”ืžื—ืฉื‘ื™ื ื‘ื“ื™ืจื” 2, ืืš ืœืงื•ื— ื”-ssh ืงื•ืคื ืžื‘ืœื™ ืœื‘ืงืฉ ืกื™ืกืžื”. ืื ื™ ืžื ืกื” ืœื”ืชื—ื‘ืจ ืœืžื—ืฉื‘ ื”ื–ื” ื“ืจืš telnet ื‘ื™ืฆื™ืื” 22 ื•ืื ื™ ืจื•ืื” ืงื• ืฉืžืžื ื• ืื ื™ ื™ื›ื•ืœ ืœื”ื‘ื™ืŸ ืฉื”ื—ื™ื‘ื•ืจ ื ื•ืฆืจ, ืฉืจืช ื”-SSH ืžื’ื™ื‘, ืื‘ืœ ืžืฉื•ื ืžื” ื–ื” ืคืฉื•ื˜ ืœื ืžื ื—ื” ืื•ืชื™ ืœื”ื™ื›ื ืก ื‘.

$ telnet 192.168.10.110 22
SSH-2.0-OpenSSH_8.1

ืื ื™ ืžื ืกื” ืœื”ืชื—ื‘ืจ ืืœื™ื• ื“ืจืš VNC ื•ืœืจืื•ืช ืžืกืš ืฉื—ื•ืจ. ืื ื™ ืžืฉื›ื ืข ืืช ืขืฆืžื™ ืฉื”ื‘ืขื™ื” ื”ื™ื ื‘ืžื—ืฉื‘ ื”ืžืจื•ื—ืง, ื›ื™ ืื ื™ ื™ื›ื•ืœ ื‘ืงืœื•ืช ืœื”ืชื—ื‘ืจ ืœืจืื•ื˜ืจ ืžื”ื“ื™ืจื” ื”ื–ื• ื‘ืืžืฆืขื•ืช ื”ื›ืชื•ื‘ืช ื”ืคื ื™ืžื™ืช. ืขื ื–ืืช, ืื ื™ ืžื—ืœื™ื˜ ืœื”ืชื—ื‘ืจ ืœ-SSH ืฉืœ ื”ืžื—ืฉื‘ ื”ื–ื” ื“ืจืš ื”ืจืื•ื˜ืจ ื•ืžื•ืคืชืข ืœื’ืœื•ืช ืฉื”ื—ื™ื‘ื•ืจ ื”ืฆืœื™ื—, ื•ื”ืžื—ืฉื‘ ื”ืžืจื•ื—ืง ืขื•ื‘ื“ ื“ื™ ืจื’ื™ืœ, ืื‘ืœ ื”ื•ื ื’ื ืœื ื™ื›ื•ืœ ืœื”ืชื—ื‘ืจ ืœืžื—ืฉื‘ ืฉืœื™.

ืื ื™ ืžืกื™ืจ ืืช ืžื›ืฉื™ืจ grelan0 ืžื”ื’ืฉืจ ื•ืžืคืขื™ืœ ืืช OpenVPN ืขืœ ื”ืจืื•ื˜ืจ ื‘ื“ื™ืจื” 2 ื•ืžื•ื•ื“ื ืฉื”ืจืฉืช ืฉื•ื‘ ืขื•ื‘ื“ืช ื›ืžืฆื•ืคื” ื•ื”ื—ื™ื‘ื•ืจื™ื ืœื ื ืคืœื•. ื‘ื—ื™ืคื•ืฉ ืื ื™ ื ืชืงืœ ื‘ืคื•ืจื•ืžื™ื ืฉื‘ื”ื ืื ืฉื™ื ืžืชืœื•ื ื ื™ื ืขืœ ืื•ืชืŸ ื‘ืขื™ื•ืช, ืฉื ืžื•ืžืœืฅ ืœื”ื ืœื”ืขืœื•ืช ืืช ื”-MTU. ืœื ืžื•ืงื“ื ื™ื•ืชืจ ืžืืฉืจ ื ืขืฉื”. ืขื ื–ืืช, ืขื“ ืฉื”-MTU ื”ื•ื’ื“ืจ ื’ื‘ื•ื” ืžืกืคื™ืง - 7000 ืขื‘ื•ืจ ื”ืชืงื ื™ gretap, ื ืฆืคื• ื—ื™ื‘ื•ืจื™ TCP ืฉื ืคืœื• ืื• ืงืฆื‘ื™ ื”ืขื‘ืจื” ื ืžื•ื›ื™ื. ื‘ืฉืœ ื”-MTU ื”ื’ื‘ื•ื” ืœ-gretap, ื”-MTUs ืขื‘ื•ืจ ื—ื™ื‘ื•ืจื™ WireGuard ืฉืœ ืฉื›ื‘ื” 8000 ื•ืฉื›ื‘ื” 7500 ื ืงื‘ืขื• ืœ-XNUMX ื•-XNUMX ื‘ื”ืชืืžื”.

ื‘ื™ืฆืขืชื™ ื”ื’ื“ืจื” ื“ื•ืžื” ืขืœ ื”ื ืชื‘ ืžื“ื™ืจื” 3, ื›ืฉื”ื”ื‘ื“ืœ ื”ื™ื—ื™ื“ ื”ื•ื ืฉื ื•ืกืฃ ืœื ืชื‘ ื”ืฉืจืช ืžืžืฉืง gretap ืฉื ื™ ื‘ืฉื grelan1, ืฉื ื•ืกืฃ ื’ื ืœื’ืฉืจ br-lan.

ื”ื›ืœ ืขื•ื‘ื“. ื›ืขืช ืืชื” ื™ื›ื•ืœ ืœื”ื›ื ื™ืก ืืช ืžื›ืœื•ืœ gretap ืœื”ืคืขืœื”. ืœื–ื”:

ืฉืžืชื™ ืืช ื”ืฉื•ืจื•ืช ื”ืืœื” ื‘-/etc/rc.local ื‘ื ืชื‘ ื‘ื“ื™ืจื” 2:

ip link add grelan0 type gretap remote 192.168.31.1 local 192.168.31.2
ip link set dev grelan0 mtu 7000
ip link set grelan0 up
brctl addif br-lan grelan0

ื”ื•ืกื™ืฃ ืืช ื–ื” ืœ-/etc/rc.local ื‘ื ืชื‘ ื‘ื“ื™ืจื” 3:

ip link add grelan0 type gretap remote 192.168.31.1 local 192.168.31.3
ip link set dev grelan0 mtu 7000
ip link set grelan0 up
brctl addif br-lan grelan0

ื•ื‘ื ืชื‘ ื”ืฉืจืช:

ip link add grelan0 type gretap remote 192.168.31.2 local 192.168.31.1
ip link set dev grelan0 mtu 7000
ip link set grelan0 up
brctl addif br-lan grelan0

ip link add grelan1 type gretap remote 192.168.31.3 local 192.168.31.1
ip link set dev grelan1 mtu 7000
ip link set grelan1 up
brctl addif br-lan grelan1

ืœืื—ืจ ืืชื—ื•ืœ ืžื—ื“ืฉ ืฉืœ ื ืชื‘ื™ ื”ืœืงื•ื—, ื’ื™ืœื™ืชื™ ืฉืžืฉื•ื ืžื” ื”ื ืœื ืžืชื—ื‘ืจื™ื ืœืฉืจืช. ืœืื—ืจ ื”ืชื—ื‘ืจื•ืช ืœ-SSH ืฉืœื”ื (ืœืžืจื‘ื” ื”ืžื–ืœ, ื”ื’ื“ืจืชื™ ื‘ืขื‘ืจ ืืช sshtunnel ืœื›ืš), ื”ืชื’ืœื” ืฉ-WireGuard ืžืกื™ื‘ื” ื›ืœืฉื”ื™ ื™ื•ืฆืจ ืžืกืœื•ืœ ืขื‘ื•ืจ ื ืงื•ื“ืช ื”ืงืฆื”, ืื‘ืœ ื”ื•ื ื”ื™ื” ืฉื’ื•ื™. ืื–, ืขื‘ื•ืจ 192.168.30.2, ื˜ื‘ืœืช ื”ืžืกืœื•ืœื™ื ืฆื™ื™ื ื” ืžืกืœื•ืœ ื“ืจืš ืžืžืฉืง pppoe-wan, ื›ืœื•ืžืจ ื“ืจืš ื”ืื™ื ื˜ืจื ื˜, ืœืžืจื•ืช ืฉื”ืžืกืœื•ืœ ืืœื™ื• ื”ื™ื” ืฆืจื™ืš ืœื”ื™ื•ืช ืžื ื•ืชื‘ ื“ืจืš ืžืžืฉืง wg0. ืœืื—ืจ ืžื—ื™ืงืช ื”ืžืกืœื•ืœ ื”ื–ื”, ื”ื—ื™ื‘ื•ืจ ืฉื•ื—ื–ืจ. ืœื ื”ืฆืœื—ืชื™ ืœืžืฆื•ื ื”ื•ืจืื•ืช ื‘ืฉื•ื ืžืงื•ื ื›ื™ืฆื“ ืœืืœืฅ ืืช WireGuard ืœื ืœื™ืฆื•ืจ ืืช ื”ืžืกืœื•ืœื™ื ื”ืœืœื•. ื™ืชืจ ืขืœ ื›ืŸ, ืืคื™ืœื• ืœื ื”ื‘ื ืชื™ ืื ื–ื• ืชื›ื•ื ื” ืฉืœ OpenWRT ืื• WireGuard ืขืฆืžื”. ื‘ืœื™ ืฆื•ืจืš ืœื”ืชืžื•ื“ื“ ืขื ื‘ืขื™ื” ื–ื• ื‘ืžืฉืš ื–ืžืŸ ืจื‘, ืคืฉื•ื˜ ื”ื•ืกืคืชื™ ืฉื•ืจื” ืœืฉื ื™ ื”ื ืชื‘ื™ื ื‘ืกืงืจื™ืคื˜ ืžืชื•ื–ืžืŸ ืฉืžื—ืง ืืช ื”ืžืกืœื•ืœ ื”ื–ื”:

route del 192.168.30.2

ืชืžืฆื•ืช

ืขื“ื™ื™ืŸ ืœื ื”ืฉื’ืชื™ ื ื˜ื™ืฉื” ืžื•ื—ืœื˜ืช ืฉืœ OpenVPN, ื›ื™ื•ื•ืŸ ืฉืœืคืขืžื™ื ืื ื™ ืฆืจื™ืš ืœื”ืชื—ื‘ืจ ืœืจืฉืช ื—ื“ืฉื” ืžืžื—ืฉื‘ ื ื™ื™ื“ ืื• ื˜ืœืคื•ืŸ, ื•ื”ื’ื“ืจืช ืžื›ืฉื™ืจ gretap ืขืœื™ื”ื ื‘ื“ืจืš ื›ืœืœ ื‘ืœืชื™ ืืคืฉืจื™ืช, ืื‘ืœ ืœืžืจื•ืช ื–ืืช, ืงื™ื‘ืœืชื™ ื™ืชืจื•ืŸ ื‘ืžื”ื™ืจื•ืช ืฉืœ ื”ืขื‘ืจืช ื ืชื•ื ื™ื ื‘ื™ืŸ ื“ื™ืจื•ืช ื•ืœืžืฉืœ ืฉื™ืžื•ืฉ ื‘-VNC ื›ื‘ืจ ืœื ื ื•ื—. ื”ืคื™ื ื’ ื™ืจื“ ืžืขื˜, ืืš ื”ืคืš ืœื™ืฆื™ื‘ ื™ื•ืชืจ:

ื‘ืขืช ืฉื™ืžื•ืฉ ื‘-OpenVPN:

[r0ck3r@desktop ~]$ ping -c 20 192.168.10.110
PING 192.168.10.110 (192.168.10.110) 56(84) bytes of data.
64 bytes from 192.168.10.110: icmp_seq=1 ttl=64 time=133 ms
...
64 bytes from 192.168.10.110: icmp_seq=20 ttl=64 time=125 ms

--- 192.168.10.110 ping statistics ---
20 packets transmitted, 20 received, 0% packet loss, time 19006ms
rtt min/avg/max/mdev = 124.722/126.152/136.907/3.065 ms

ื‘ืขืช ืฉื™ืžื•ืฉ ื‘-WireGuard:

[r0ck3r@desktop ~]$ ping -c 20 192.168.10.110
PING 192.168.10.110 (192.168.10.110) 56(84) bytes of data.
64 bytes from 192.168.10.110: icmp_seq=1 ttl=64 time=124 ms
...
64 bytes from 192.168.10.110: icmp_seq=20 ttl=64 time=124 ms
--- 192.168.10.110 ping statistics ---
20 packets transmitted, 20 received, 0% packet loss, time 19003ms
rtt min/avg/max/mdev = 123.954/124.423/126.708/0.675 ms

ื”ื•ื ืžื•ืฉืคืข ื™ื•ืชืจ ืžื”ืคื™ื ื’ ื”ื’ื‘ื•ื” ืœ-VPS, ืฉื”ื•ื ื‘ืขืจืš 61.5 ืืœืคื™ื•ืช ื”ืฉื ื™ื™ื”

ืขื ื–ืืช, ื”ืžื”ื™ืจื•ืช ืขืœืชื” ืžืฉืžืขื•ืชื™ืช. ืื–, ื‘ื“ื™ืจื” ืขื ื ืชื‘ ืฉืจืช ื™ืฉ ืœื™ ืžื”ื™ืจื•ืช ื—ื™ื‘ื•ืจ ืœืื™ื ื˜ืจื ื˜ ืฉืœ 30 Mbit/sec, ื•ื‘ื“ื™ืจื•ืช ืื—ืจื•ืช ื”ื™ื 5 Mbit/sec. ื™ื—ื“ ืขื ื–ืืช, ื‘ื–ืžืŸ ื”ืฉื™ืžื•ืฉ ื‘-OpenVPN, ืœื ื”ืฆืœื—ืชื™ ืœื”ืฉื™ื’ ืžื”ื™ืจื•ืช ื”ืขื‘ืจืช ื ืชื•ื ื™ื ื‘ื™ืŸ ืจืฉืชื•ืช ืฉืœ ื™ื•ืชืจ ืž-3,8 Mbit/sec ืœืคื™ ืงืจื™ืื•ืช iperf, ื‘ืขื•ื“ WireGuard "ื”ื’ื‘ื™ืจ" ืื•ืชื• ืœืื•ืชื 5 Mbit/sec.

ืชืฆื•ืจืช WireGuard ื‘-VPS[Interface] Address = 192.168.30.1/24
ListenPort = 51820
PrivateKey = <ะ—ะะšะ ะซะขะซะ™_ะšะ›ะฎะง_ะ”ะ›ะฏ_VPS>

[Peer] PublicKey = <ะžะขะšะ ะซะขะซะ™_ะšะ›ะฎะง_VPN_1_ะœะก>
AllowedIPs = 192.168.30.2/32

[Peer] PublicKey = <ะžะขะšะ ะซะขะซะ™_ะšะ›ะฎะง_VPN_2_ะœะš2>
AllowedIPs = 192.168.30.3/32

[Peer] PublicKey = <ะžะขะšะ ะซะขะซะ™_ะšะ›ะฎะง_VPN_2_ะœะš3>
AllowedIPs = 192.168.30.4/32

ืชืฆื•ืจืช WireGuard ื‘-MS (ื ื•ืกืคื” ืœ-/etc/config/network)

#VPN ะฟะตั€ะฒะพะณะพ ัƒั€ะพะฒะฝั - ะบะปะธะตะฝั‚
config interface 'wg0'
        option proto 'wireguard'
        list addresses '192.168.30.2/24'
        option private_key 'ะ—ะะšะ ะซะขะซะ™_ะšะ›ะฎะง_VPN_1_ะœะก'
        option auto '1'
        option mtu '8000'

config wireguard_wg0
        option public_key 'ะžะขะšะ ะซะขะซะ™_ะšะ›ะฎะง_VPN_1_VPS'
        option endpoint_port '51820'
        option route_allowed_ips '1'
        option persistent_keepalive '25'
        list allowed_ips '192.168.30.0/24'
        option endpoint_host 'IP_ะะ”ะ ะ•ะก_VPS'

#VPN ะฒั‚ะพั€ะพะณะพ ัƒั€ะพะฒะฝั - ัะตั€ะฒะตั€
config interface 'wg1'
        option proto 'wireguard'
        option private_key 'ะ—ะะšะ ะซะขะซะ™_ะšะ›ะฎะง_VPN_2_ะœะก'
        option listen_port '51821'
        list addresses '192.168.31.1/24'
        option auto '1'
        option mtu '7500'

config wireguard_wg1
        option public_key 'ะžะขะšะ ะซะขะซะ™_ะšะ›ะฎะง_VPN_2_ะœะš2'
        list allowed_ips '192.168.31.2'

config wireguard_wg1ip link add grelan0 type gretap remote 192.168.31.1 local 192.168.31.3

        option public_key 'ะžะขะšะ ะซะขะซะ™_ะšะ›ะฎะง_VPN_2_ะœะš3'
        list allowed_ips '192.168.31.3'

ืชืฆื•ืจืช WireGuard ื‘-MK2 (ื ื•ืกืคื” ืœ-/etc/config/network)

#VPN ะฟะตั€ะฒะพะณะพ ัƒั€ะพะฒะฝั - ะบะปะธะตะฝั‚
config interface 'wg0'
        option proto 'wireguard'
        list addresses '192.168.30.3/24'
        option private_key 'ะ—ะะšะ ะซะขะซะ™_ะšะ›ะฎะง_VPN_1_ะœะš2'
        option auto '1'
        option mtu '8000'

config wireguard_wg0
        option public_key 'ะžะขะšะ ะซะขะซะ™_ะšะ›ะฎะง_VPN_1_VPS'
        option endpoint_port '51820'
        option persistent_keepalive '25'
        list allowed_ips '192.168.30.0/24'
        option endpoint_host 'IP_ะะ”ะ ะ•ะก_VPS'

#VPN ะฒั‚ะพั€ะพะณะพ ัƒั€ะพะฒะฝั - ะบะปะธะตะฝั‚
config interface 'wg1'
        option proto 'wireguard'
        option private_key 'ะ—ะะšะ ะซะขะซะ™_ะšะ›ะฎะง_VPN_2_ะœะš2'
        list addresses '192.168.31.2/24'
        option auto '1'
        option listen_port '51821'
        option mtu '7500'

config wireguard_wg1
        option public_key 'ะžะขะšะ ะซะขะซะ™_ะšะ›ะฎะง_VPN_2_ะœะก'
        option endpoint_host '192.168.30.2'
        option endpoint_port '51821'
        option persistent_keepalive '25'
        list allowed_ips '192.168.31.0/24'

ืชืฆื•ืจืช WireGuard ื‘-MK3 (ื ื•ืกืคื” ืœ-/etc/config/network)

#VPN ะฟะตั€ะฒะพะณะพ ัƒั€ะพะฒะฝั - ะบะปะธะตะฝั‚
config interface 'wg0'
        option proto 'wireguard'
        list addresses '192.168.30.4/24'
        option private_key 'ะ—ะะšะ ะซะขะซะ™_ะšะ›ะฎะง_VPN_1_ะœะš3'
        option auto '1'
        option mtu '8000'

config wireguard_wg0
        option public_key 'ะžะขะšะ ะซะขะซะ™_ะšะ›ะฎะง_VPN_1_VPS'
        option endpoint_port '51820'
        option persistent_keepalive '25'
        list allowed_ips '192.168.30.0/24'
        option endpoint_host 'IP_ะะ”ะ ะ•ะก_VPS'

#VPN ะฒั‚ะพั€ะพะณะพ ัƒั€ะพะฒะฝั - ะบะปะธะตะฝั‚
config interface 'wg1'
        option proto 'wireguard'
        option private_key 'ะ—ะะšะ ะซะขะซะ™_ะšะ›ะฎะง_VPN_2_ะœะš3'
        list addresses '192.168.31.3/24'
        option auto '1'
        option listen_port '51821'
        option mtu '7500'

config wireguard_wg1
        option public_key 'ะžะขะšะ ะซะขะซะ™_ะšะ›ะฎะง_VPN_2_ะœะก'
        option endpoint_host '192.168.30.2'
        option endpoint_port '51821'
        option persistent_keepalive '25'
        list allowed_ips '192.168.31.0/24'

ื‘ืชืฆื•ืจื•ืช ื”ืžืชื•ืืจื•ืช ืœ-VPN ื‘ืจืžื” ืฉื ื™ื™ื”, ืื ื™ ืžืคื ื” ืœืœืงื•ื—ื•ืช WireGuard ืœื™ืฆื™ืื” 51821. ื‘ืชื™ืื•ืจื™ื”, ื–ื” ืœื ื”ื›ืจื—ื™, ืžื›ื™ื•ื•ืŸ ืฉื”ืœืงื•ื— ื™ื™ืฆื•ืจ ื—ื™ื‘ื•ืจ ืžื›ืœ ื™ืฆื™ืื” ื—ื•ืคืฉื™ืช ืœืœื ืคืจื™ื‘ื™ืœื’ื™ื”, ืื‘ืœ ืขืฉื™ืชื™ ื–ืืช ื›ืš ืฉื ื™ืชืŸ ื”ื™ื” ืœืืกื•ืจ ื›ืœ ื”ื—ื™ื‘ื•ืจื™ื ื”ื ื›ื ืกื™ื ื‘ืžืžืฉืงื™ wg0 ืฉืœ ื›ืœ ื”ื ืชื‘ื™ื ืœืžืขื˜ ื—ื™ื‘ื•ืจื™ UDP ื ื›ื ืกื™ื ืœื™ืฆื™ืื” 51821.

ืื ื™ ืžืงื•ื•ื” ืฉื”ืžืืžืจ ื™ื•ืขื™ืœ ืœืžื™ืฉื”ื•.

ื .ื‘. ื›ืžื• ื›ืŸ, ืื ื™ ืจื•ืฆื” ืœืฉืชืฃ ืืช ื”ืกืงืจื™ืคื˜ ืฉืœื™ ืฉืฉื•ืœื— ืœื™ ื”ื•ื“ืขืช PUSH ืœื˜ืœืคื•ืŸ ืฉืœื™ ื‘ืืคืœื™ืงืฆื™ื™ืช WirePusher ื›ืืฉืจ ืžื›ืฉื™ืจ ื—ื“ืฉ ืžื•ืคื™ืข ื‘ืจืฉืช ืฉืœื™. ื”ื ื” ื”ืงื™ืฉื•ืจ ืœืชืกืจื™ื˜: github.com/r0ck3r/device_discover.

ืขื“ื›ื•ืŸ: ืชืฆื•ืจื” ืฉืœ ืฉืจืช OpenVPN ื•ืœืงื•ื—ื•ืช

ืฉืจืช OpenVPN

client-to-client

ca /etc/openvpn/server/ca.crt
cert /etc/openvpn/server/vpn-server.crt
dh /etc/openvpn/server/dh.pem
key /etc/openvpn/server/vpn-server.key

dev tap
ifconfig-pool-persist /etc/openvpn/ipp.txt 0
keepalive 10 60
proto tcp4
server-bridge 192.168.10.1 255.255.255.0 192.168.10.80 192.168.10.254
status /var/log/openvpn-status.log
verb 3
comp-lzo

ืœืงื•ื— OpenVPN

client
tls-client
dev tap
proto tcp
remote VPS_IP 1194 # Change to your router's External IP
resolv-retry infinite
nobind

ca client/ca.crt
cert client/client.crt
key client/client.key
dh client/dh.pem

comp-lzo
persist-tun
persist-key
verb 3

ื”ืฉืชืžืฉืชื™ ื‘- easy-rsa ื›ื“ื™ ืœื”ืคื™ืง ืื™ืฉื•ืจื™ื

ืžืงื•ืจ: www.habr.com

ื”ื•ืกืคืช ืชื’ื•ื‘ื”