ืืจืื ืืื ืจืฆืืชื "ืืืขืช ืืืืืื ืฉืื" ืืฉืืจืืชื ืืื ืืจื ื ืขื ืืื ืืงืืช ืฉืจืช ืืื ืืจื ื ืืืคืก ืืฉืืจืืจื ืืืื ืืจื ื. ืืืืืจ ืื ืื ื ืจืืฆื ืืืืืง ืืช ืื ืืกืืื ืฉืื ืืืคืืืช ื ืชื ืืืชื ืืืืฉืืจ ืคืื ืงืฆืืื ืื ืืืืชืจ ืืฉืจืช ืืืขื ืืื.
ืืื ืืชืืื ืืื ืฉืื ืชื TP-Link TL-WR1043ND, ืฉืฉืืืฉ ื ืืื ื, ืืืจ ืื ืขื ื ืขื ืืฆืจืืื ืฉื ืจืฉืช ืืืชืืช, ืจืฆืืชื ืคืก 5 ืืืื-ืืจืฅ ืืืืฉื ืืืืจื ืืงืืฆืื ืืืชืงื ืืืกืื ืืืืืืจ ืื ืชื . ืืืืจ ืขืืื ืืคืืจืืืื ืืืืืืื (4pda, ixbt), ืืชืจืื ืขื ืืืงืืจืืช ืืขืืื ืืืืืจ ืืื ืืืืช ืืืงืืืืืช, ืืืืืชื ืืจืืืฉ ืืช Keenetic Ultra.
ืืืงืืจืืช ืืืืืช ืืืืขืืื ืคืขืื ืืืืืช ืืืืฉืืจ ืืืกืืื ืืื:
- ืืื ืืขืืืช ืขื ืืชืืืืืช ืืชืจ (ืืื ื ืืืฆื ื ืื ืืืฉ ืืช ืืืฆืจื Asus);
- ืืืื ืืช ืชืคืขืืืืช (ืืื ืืฆืืชื ืืช TP-Link);
- ืงื ืืืืืจื (ืคืืืชื ืฉืื ื ืื ืืืื ืืืชืืืื ืขื ืื ืืืืืงืชื ืืช Microtik).
ืืืืชื ืฆืจืื ืืืฉืืื ืขื ืืืกืจืื ืืช:
- ืืื WiFi6, ืจืฆืืชื ืืงืืช ืฆืืื ืขื ืจืืจืื ืืขืชืื;
- 4 ืืฆืืืืช LAN, ืจืฆืืชื ืืืชืจ, ืืื ืื ืืืจ ืื ืงืืืืจืื ืืืชืืช.
ืืชืืฆืื ืืื, ืงืืืื ื ืืช ื"ืฉืจืช" ืืื:
- ืืฉืืื ื ืืฆื ืืืกืืฃ ืืืืคืื ืฉื Rostelecom;
- ืืฆื ืืืื ื ืืฆื ืื ืชื ืื ืืกืืื ื ืฉืื ื;
- SSD 2 GB m.128 ืฉืืื ืืกืืื, ืืืืงื ืืงืืคืกืช USB3 ื- Aliexpress, ืืืืืจ ืื ืชื ืขื ืืื, ืืขืช ืืื ืืืชืงื ืืฆืืจื ืืกืืืจืช ืขื ืืงืืจ;
- ืืืืืช ืืื ืืื ืืืจืื ืขื ืฉืงืขืื ืื ืืชืงืื ืืืืคื ืขืฆืืื, ืืืื ืืื ื ืขืืืจ ื-UPS ืื ืืงืจ;
- ืืจืงืข ืืฉ ืฆืจืืจ ืืืืื ืืขืืืชืื - ืืฉืื ืฉืืคืืฅ ืืืืจื ืชืืื ื ืชื ืืื ืฉืงืขื RJ45 ืืืงืืืืช ืฉืืื ืืฆืืื ืืื ืืืืจ ืืืืืช ืืืืงื, ืืื ืื ืืืืืช ืชืืื ื-WiFi ืฉืืชืืืื.
ืื, ืืฉ ืื ื ืืช ืืฆืืื, ืื ืื ื ืฆืจืืืื ืืืืืืจ ืืืชื:
- ืืืืืจื ืืจืืฉืื ืืช ืฉื ืื ืชื ืืืจืืช ื-2 ืืงืืช, ืื ื ืืฆืืื ืื ืืกืคืง ืืช ืคืจืืืจื ืืืืืืจ (ืืืจืืื ื ืืืืคืื ืฉืื ืขืืืจ ืืืฆื ืืฉืจ, ืืืืืจ PPPoE ืืจืื ืืช ืื ืชื), ืฉื ืจืฉืช ื-WiFi ืืืกืืกืื - ืืขืฆื ืืื , ืื ืชื ืืืคืขื ืืขืืื.
ืืืืจื ื ืืขืืจื ืฉื ืืฆืืืืช ืืืฆืื ืืืช ืืืฆืืืืช ืฉื ืื ืชื ืขืฆืื ืืกืขืืฃ "ืืืื ืจืฉืช - ืืขืืจื":
ืขืืฉืื ืื ืื ื ืืืืืื ืืขืืืจ ืืืืง ื"ืืชืงืื", ืื ืฉืจืฆืืชื ืืื ืชื:
- ืคืื ืงืฆืืื ืืืืช ืฉื NAS ืงืื ืขืืืจ ืจืฉืช ืืืชืืช;
- ืืืฆืืข ืคืื ืงืฆืืืช ืฉืจืช ืืื ืืจื ื ืขืืืจ ืืกืคืจ ืืคืื ืคืจืืืื;
- ืคืื ืงืฆืืื ืืืืช ืขื ื ืืืฉืืช ืืืืฉื ืื ืชืื ืื ืืืฉืืื ืืื ืืงืื ืืขืืื.
ืืจืืฉืื ืืืืฉื ืืืืฆืขืืช ืืืื ืืืื ืื, ืืื ืฆืืจื ืืืืืฅ ืจื:
- ืื ื ืืืงืืื ืืื ื ืืืืืขื ืืชืคืงืื ืื (ืืื ื ืคืืืฉ, ืืจืืืก ืืืืจืื ืืงืืจื ืืจืืืกืื, ืืื ื ืงืฉืื ืื SSD ืืงืืคืกื ืืืฆืื ืืช ืืืคืจืืืื ืืืชื ื-Ext4 ืืืืฆืขืืช
ืืืืืืจื ืืืื ืืืช ืฉื ืืฉืฃ ืืืืืฆืืช (ืืื ืื ืืืฉื ืขื ืืื ืืงืก ืืืืฉื ืื, ืื ืืคืฉืจื ืขื ืืืื ืืืื ืื). ืืคื ืืื ืชื, ืืืื ืืคืขืืื ืืืขืจืืช ืืืชืืช ืจืง ืืืืื ืืืื ื ืืืืง, ืื ืฉืื ืชืืืื ืืืชื ืืืืจ ืืืืจืช ืืืขืจืืช, ืชืืื ืืืฉืชืืฉ ืื ืืืจืืืกื ืืืืจืื ืื ืืชื ืืชืืืื ืืืชืื ืืจืื ืืืขืชืื ืงืจืืืืช ืืืื ื - SSD ืื HDD ืืื ืืืชืจ.
ืืืืจ ืืื, ืื ื ืืืืจืื ืืช ืืืื ื ืื ืชื ืืฆืืคืื ืื ืืืกื ืฆื ืืืขืจืืช
ืืืฅ ืขื "ืืื ื ื USB ืืืืคืกืืช" ืืงืืข "ืืืฉืืืื" ืืืืืจ ืืช ืืฉืืชืืฃ ืืงืืข "ืจืฉืช Windows":
ืืืฉ ืื ื ืืฉืื ืจืฉืช ืฉื ืืชื ืืืฉืชืืฉ ืื ืืืืฉืื Windows, ืืืชืืืจ ืืืืกืง ืืืืืช ืืฆืืจื: ื ืื ืืฉืชืืฉ ื-y: \192.168.1.1SSD /persistent:yes
ืืืืืจืืช ืฉื NAS ืืืืืชืจ ืฉืืื ืืกืคืืงื ืืืื ืืฉืืืืฉ ืืืชื; ืขื ืืื ืืื ืืฉืชืืฉ ืืื ืืืืื-ืืื, ื-WiFi ืืืืืจืืช ืืื ืืขืจื 400-500 ืืื-ืืื.
ืืืืจืช ืืืกืื ืืื ืืื ืืฉืืืื ืืืจืืฉืื ืืืืืจืช ืืฉืจืช, ืื ืื ืื ื ืฆืจืืืื:
-
-
ืืืงื ืืกืคืจ ืฉืขืืช ืขื ืฉืืืืจืืช ืืืฆืืช ืืืืืืื ืื-DNS ืืืื ืกื ืืชืืงืฃ, ืืืื ืื ื ืืืืืจืื ืื-ืืื ืืช ืืช ืื ืชื.
ืจืืฉืืช, ืขืืื ื ืืืชืงืื ืืช ืืืืจ Entware, ืืื ื ื ืืื ืืืชืงืื ืืช ืืืืืืืช ืืืจืืฉืืช ืขื ืื ืชื. ื ืืฆืืชื
ืืืืจ ืฉืืฉืืช ืืืฉื ืืจื SSH, ืฉื ื ืืช ืืกืืกืื ืขื ืืคืงืืื passwd ืืืชืงื ืืช ืื ืืืืืืืช ืืืจืืฉืืช ืขื ืืคืงืืื opkg install [package names]:
ืืืืื ืืืืืจื, ืืืืืืืช ืืืืืช ืืืชืงื ื ืื ืชื (ืืคืื ืฉื ืืคืงืืื opkg list-installed):
ืจืฉืืืช ืืืืืืช
bash - 5.0-3
busybox - 1.31.1-1
ca-bundle - 20190110-2
ca-certificates - 20190110-2
coreutils - 8.31-1
coreutils-mktemp - 8.31-1
cron - 4.1-3
ืชืืชื - 7.69.0-1
diffutils - 3.7-2
dropbear - 2019.78-3
entware-release - 1.0-2
findutils - 4.7.0-1
glib2 - 2.58.3-5
grep - 3.4-1
ldconfig - 2.27-9
libattr - 2.4.48-2
libblkid - 2.35.1-1
libc - 2.27-9
libcurl - 7.69.0-1
libffi - 3.2.1-4
libgcc - 8.3.0-9
libiconv-full - 1.11.1-4
libintl-full - 0.19.8.1-2
liblua - 5.1.5-7
libmbedtls - 2.16.5-1
libmount - 2.35.1-1
libncurses - 6.2-1
libncursesw - 6.2-1
libndm - 1.1.10-1a
libopenssl - 1.1.1d-2
libopenssl-conf - 1.1.1d-2
libpcap - 1.9.1-2
libpcre - 8.43-2
libpcre2 - 10.34-1
libpthread - 2.27-9
libreadline - 8.0-1a
librt - 2.27-9
libslang2 - 2.3.2-4
libssh2 - 1.9.0-2
libssp - 8.3.0-9
libstdcpp - 8.3.0-9
libuid - 2.35.1-1
libxml2 - 2.9.10-1
ืืงืืืืช - 2.27-9
mc - 4.8.23-2
ndmq - 1.0.2-5a
nginx - 1.17.8-1
openssl-util - 1.1.1d-2
opkg โ 2019-06-14-dcbc142e-2
opt-ndmsv2 - 1.0-12
php7 - 7.4.3-1
php7-mod-openssl - 7.4.3-1
poorbox - 1.31.1-2
terminfo - 6.2-1
zlib - 1.2.11-3
zoneinfo-asia - 2019c-1
zoneinfo-europe - 2019c-1
ืืืื ืืื ืืื ืืฉืื ืืืืชืจ, ืืื ืืื ืืจืื ืืงืื ืืืื ื, ืื ืื ืืจืืชื ืืืืืง ืืช ืื.
ืืืืจ ืืชืงื ืช ืืืืืืืช, ืืืืจื ื ืืช nginx, ื ืืกืืชื ืืช ืื ืขื ืฉื ื ืืืืืื ืื - ืืฉื ื ืืืืืจ ืขื https, ืืืขืช ืขืชื ืืฉ ืืื. ืืฆืืืืช ืคื ืืืืืช 81 ื-433 ืืฉืืฉืืช ืืืงืื 80 ื-443, ืืืืืื ืฉืคืื ื ืื ืืืื ืฉื ืื ืชื ืชืืื ืืืฆืืืืช ืจืืืืืช.
etc/nginx/nginx.conf
user nobody;
worker_processes 1;
#error_log /opt/var/log/nginx/error.log;
#error_log /opt/var/log/nginx/error.log notice;
#error_log /opt/var/log/nginx/error.log info;
#pid /opt/var/run/nginx.pid;
events {
worker_connections 64;
}
http {
include mime.types;
default_type application/octet-stream;
#log_format main '$remote_addr - $remote_user [$time_local] "$request" '
# '$status $body_bytes_sent "$http_referer" '
# '"$http_user_agent" "$http_x_forwarded_for"';
#access_log /opt/var/log/nginx/access.log main;
sendfile on;
#tcp_nopush on;
#keepalive_timeout 0;
keepalive_timeout 65;
#gzip on;
server {
listen 81;
server_name milkov.su www.milkov.su;
return 301 https://milkov.su$request_uri;
}
server {
listen 433 ssl;
server_name milkov.su;
#SSL support
include ssl.conf;
location / {
root /opt/share/nginx/html;
index index.html index.htm;
error_page 500 502 503 504 /50x.html;
location = /50x.html {
root html;
}
}
}
</spoiler>
<spoiler title="etc/nginx/ssl.conf">
ssl_certificate /opt/etc/nginx/certs/milkov.su/fullchain.pem;
ssl_certificate_key /opt/etc/nginx/certs/milkov.su/privkey.pem;
ssl_ciphers 'ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-AES256-GCM-SHA384:DHE-RSA-AES128-GCM-SHA256:DHE-DSS-AES128-GCM-SHA256:kEDH+AESGCM:ECDHE-RSA-AES128-SHA256:ECDHE-ECDSA-AES128-SHA256:ECDHE-RSA-AES128-SHA:ECDHE-ECDSA-AES128-SHA:ECDHE-RSA-AES256-SHA384:ECDHE-ECDSA-AES256-SHA384:ECDHE-RSA-AES256-SHA:ECDHE-ECDSA-AES256-SHA:DHE-RSA-AES128-SHA256:DHE-RSA-AES128-SHA:DHE-DSS-AES128-SHA256:DHE-RSA-AES256-SHA256:DHE-DSS-AES256-SHA:DHE-RSA-AES256-SHA:AES128-GCM-SHA256:AES256-GCM-SHA384:AES128-SHA256:AES256-SHA256:AES128-SHA:AES256-SHA:AES:CAMELLIA:DES-CBC3-SHA:!aNULL:!eNULL:!EXPORT:!DES:!RC4:!MD5:!PSK:!aECDH:!EDH-DSS-DES-CBC3-SHA:!EDH-RSA-DES-CBC3-SHA:!KRB5-DES-CBC3-SHA';
ssl_prefer_server_ciphers on;
ssl_dhparam /opt/etc/nginx/dhparams.pem;
ssl_session_cache shared:SSL:10m;
ssl_session_timeout 5m;
ssl_stapling on;
ืืื ืฉืืืชืจ ืืขืืื ืืจื https, ืืฉืชืืฉืชื ืืกืงืจืืคื ืืืืืฉ ืืืืืข, ืืชืงื ืชื ืืืชื ืืืืฆืขืืช
[openssl_conf]
#engines=engines
ืืื ื ืืฆืืื ืฉืืฆืืจืช dhparams.pem ืขื ืืคืงืืื "openssl dhparam -out dhparams.pem 2048" ืื ืชื ืฉืื ืืืงื ืืืชืจ ืืฉืขืชืืื, ืืืืื ืืืืื ืืืชืงืืืืช, ืืืืชื ืืืื ืืช ืืกืืื ืืช ืืืคืขืื ืืืืฉ.
ืืืืจ ืงืืืช ืืืืฉืืจืื, ืืคืขื ืืืืฉ ืืช nginx ืขื ืืคืงืืื "/opt/etc/init.d/S80nginx restart". ืืืืคื ืขืงืจืื ื, ืืืืืจื ืืืฉืืื, ืืื ืืื ืขืืืื ืืชืจ - ืื ื ืื ืืก ืืช ืืงืืืฅ index.html ืืกืคืจืืืช /share/nginx/html, ื ืจืื ืกืืื.
index.html
<!DOCTYPE html>
<html>
<head>
<title>ะขะตััะพะฒะฐั ัััะฐะฝะธัะบะฐ!</title>
<style>
body {
width: 35em;
margin: 0 auto;
font-family: Tahoma, Verdana, Arial, sans-serif;
}
</style>
</head>
<body>
<h1>ะขะตััะพะฒะฐั ัััะฐะฝะธัะบะฐ!</h1>
<p>ะญัะพ ะฟัะพััะฐั ััะฐัะธัะตัะบะฐั ัะตััะพะฒะฐั ัััะฐะฝะธัะบะฐ, ะฐะฑัะพะปััะฝะพ ะฝะธัะตะณะพ ะธะฝัะตัะตัะฝะพะณะพ.</p>
</body>
</html>
ืืื ืืืงื ืืืืข ืืฆืืจื ืืคื, ืงื ืืืชืจ ืืื ืฉืืื ื ืืงืฆืืขื ืืืื ื ืืืฉืชืืฉ ืืชืื ืืืช ืืืื ืืช; ืืืืจ ืืืคืืฉ ืืจืื ืืงืืืืืื ืฉืื ืื, ืืฆืืชื
ืื ื ืืืืจืื ืชืื ืืช ืืชืืืื - ืืฉ ืืืื ืืืืืื ืืงืจืื, ืืืจืืื ืืช ืืืจืืืื ืืคืืจืงื ืืืชื ืืกืคืจืืืช /share/nginx/html, ืชืืืื ืืขืฉืืช ืืืช ืืืืืฉื, ืืื ืืขืจืื ืืช ืืชืื ืืช (ืืื ืชืฆืืจืื ืืืข ืืื ืืืื ืฉื HTML ืืื ืื ืืฉืืืจ ืืช ืืืื ื) ืืืืืืืฃ ืืช ืืืจืคืืงื ืืคื ืฉืืืฆื ืืืืืจ ืืืื.
ืชืงืฆืืจ: ืื ืชื ืื ืืชืืื ืืืืจืื ืืชืจ ืงื ืื, ืืืืคื ืขืงืจืื ื - ืื ืืชื ืื ืืฆืคื ืืขืืืก ืืืื, ืืชื ืืืื
ืืื ืจืืืืจ ืืื ืืืฉื ืจืืื? ื ืชื ืืื ืืื ืืืืงื ืืืืืจื ืืืืืืื ืฉื ืืืืฉื ืฉืขืืืืื ืืกืืื ืืฉืขืื ืืืืจืืช ืจืืืช; ื ืชื ืืืชื ืืืจื ืืื ืฉืงื ืืืืืืื ืืืชืจ ืงื ืขื ืคืืืช ืืืื ืืืงืืจืื ืืืื ืื ืืคืจืืข ืื ืืื.
ืืงืืจ: www.habr.com