å°ççã«é¢ãã 3 ã€ã®ã¢ããŒãã®ãããã¯ãŒã¯ (ããããã OpenWRT ã«ãŒã¿ãŒãã²ãŒããŠã§ã€ãšããŠäœ¿çšããŠãã) ã 2 ã€ã®å
±éãããã¯ãŒã¯ã«çµåããç§ã®çµéšãå
±æããããšæããŸãã ãµãããã ã«ãŒãã£ã³ã°ã䜿çšãã LXNUMXââ ãšããªããžã䜿çšãã LXNUMX ã®éã§ãããã¯ãŒã¯ãçµã¿åãããæ¹æ³ãéžæãããšãããã¹ãŠã®ãããã¯ãŒã¯ ããŒããåããµããããå
ã«ããå ŽåãXNUMX çªç®ã®æ¹æ³ãåªå
ãããŸããããã¯æ§æãããå°é£ã§ããããã倧ããªæ©äŒãæäŸããŸããæ§ç¯äžã®ãããã¯ãŒã¯ã§ã¯ãWake-on-Lan ãš DLNA ã«ãããã¯ãããžãŒã®ééçãªäœ¿çšãèšç»ãããŸããã
ããŒã 1: èæ¯
OpenVPN ã¯ãæåã«ãã®ã¿ã¹ã¯ãå®è£ ããããã®ãããã³ã«ãšããŠéžæãããŸããããã®çç±ã¯ã第äžã«ãåé¡ãªãããªããžã«è¿œå ã§ããã¿ãã ããã€ã¹ãäœæã§ããããšã第äºã«ãOpenVPN 㯠TCP ãããã³ã«ãä»ããæäœããµããŒãããŠããããšããããéèŠã§ãããã¢ããŒãã®äžéšã«ã¯å°çšã® IP ã¢ãã¬ã¹ãããããããã€ããŒãäœããã®çç±ã§ãããã¯ãŒã¯ããã® UDP æ¥ç¶ããããã¯ããŠãããã STUN ã䜿çšã§ããŸããã§ããããTCP ãããã³ã«ã§ã¯ SSH ã䜿çšã㊠VPN ãµãŒã㌠ããŒããã¬ã³ã¿ã« VPS ã«è»¢éã§ããŸããã ã¯ãããã®ã¢ãããŒãã§ã¯ããŒã¿ã XNUMX åæå·åãããããã倧ããªè² è·ãããããŸããã第äžè ã VPS ãå¶åŸ¡ãããªã¹ã¯ãäŸç¶ãšããŠãã£ãããããã©ã€ããŒã ãããã¯ãŒã¯ã« VPS ãå°å ¥ããããããŸããã§ãããç§ã®ããŒã ãããã¯ãŒã¯ã§ã¯éåžžã«æãŸãããªããããã»ãã¥ãªãã£ã«ã¯å€§ããªãªãŒããŒããããããããšå€æãããŸããã
ãµãŒããŒãå±éããäºå®ã®ã«ãŒã¿ãŒäžã®ããŒãã転éããã«ã¯ãsshtunnel ããã°ã©ã ã䜿çšãããŸããã ãã®æ§æã®è€éãã«ã€ããŠã¯èª¬æããŸãããéåžžã«ç°¡åã«å®è¡ã§ããŸãããã®ã¿ã¹ã¯ãã«ãŒã¿ãŒãã VPS ã« TCP ããŒã 1194 ã転éããããšã§ãã£ãããšã ããè¿°ã¹ãŠãããŸãã 次ã«ãbr-lan ããªããžã«æ¥ç¶ããã Tap0 ããã€ã¹äžã« OpenVPN ãµãŒããŒãæ§æãããŸããã ã©ãããããããæ°ããäœæããããµãŒããŒãžã®æ¥ç¶ã確èªãããšãããããŒã転éã®èããæ£åœã§ãããç©ççã«ã¯ã«ãŒã¿ãŒã®ãããã¯ãŒã¯ã«å«ãŸããŠããªãã£ãã«ãããããããã©ããããããã«ãŒã¿ãŒã®ãããã¯ãŒã¯ã®ã¡ã³ããŒã«ãªã£ãããšãæããã«ãªããŸããã
ããã¹ãããšã¯ XNUMX ã€ã ãæ®ã£ãŠããŸãã競åããªãããã« IP ã¢ãã¬ã¹ãç°ãªãã¢ããŒãã«åæ£ããã«ãŒã¿ãŒã OpenVPN ã¯ã©ã€ã¢ã³ããšããŠæ§æããå¿
èŠããããŸããã
次ã®ã«ãŒã¿ãŒ IP ã¢ãã¬ã¹ãš DHCP ãµãŒããŒç¯å²ãéžæãããŸããã
- 192.168.10.1 ç¯å²ä»ã 192.168.10.2 - 192.168.10.80 ãµãŒããŒçš
- 192.168.10.100 ç¯å²ä»ã 192.168.10.101 - 192.168.10.149 ã¢ããŒãNo.2ã®ã«ãŒã¿ãŒçš
- 192.168.10.150 ç¯å²ä»ã 192.168.10.151 - 192.168.10.199 ã¢ããŒãNo.3ã®ã«ãŒã¿ãŒçš
ãŸããæ§æã«æ¬¡ã®è¡ãè¿œå ããŠããããã®ã¢ãã¬ã¹ã OpenVPN ãµãŒããŒã®ã¯ã©ã€ã¢ã³ã ã«ãŒã¿ãŒã«æ£ç¢ºã«å²ãåœãŠãå¿ èŠããããŸããã
ifconfig-pool-persist /etc/openvpn/ipp.txt 0
次ã®è¡ã /etc/openvpn/ipp.txt ãã¡ã€ã«ã«è¿œå ããŸãã
flat1_id 192.168.10.100
flat2_id 192.168.10.150
flat1_id ãš flat2_id ã¯ãOpenVPN ã«æ¥ç¶ããããã®èšŒææžãäœæãããšãã«æå®ããããã€ã¹åã§ãã
次ã«ãOpenVPN ã¯ã©ã€ã¢ã³ããã«ãŒã¿ãŒäžã§æ§æãããäž¡æ¹ã® Tap0 ããã€ã¹ã br-lan ããªããžã«è¿œå ãããŸããã ãã®æ®µéã§ã¯ã0 ã€ã®ãããã¯ãŒã¯ãã¹ãŠãçžäºã«èªèã§ããXNUMX ã€ãšããŠæ©èœããããããã¹ãŠãããŸããã£ãŠããããã«èŠããŸããã ãã ããããŸãæå¿«ã§ã¯ãªã詳现ãæããã«ãªããŸãããããã€ã¹ãã«ãŒã¿ããã§ã¯ãªã IP ã¢ãã¬ã¹ãåãåãå Žåãããããã®åŸã®ãã¹ãŠã®åœ±é¿ãçºçããå¯èœæ§ããããŸãã äœããã®çç±ã§ãã¢ããŒãã® XNUMX ã€ã®ã«ãŒã¿ãŒã« DHCPDISCOVER ãžã®å¿çãéã«åãããããã€ã¹ã¯æå³ããªãã¢ãã¬ã¹ãåä¿¡ããŸããã åã«ãŒã¿ãŒã®tapXNUMXã§ãã®ãããªãªã¯ãšã¹ãããã£ã«ã¿ãªã³ã°ããå¿ èŠãããããšã«æ°ã¥ããŸããããçµå±ã®ãšãããããã€ã¹ãããªããžã®äžéšã§ããå Žåãiptablesã¯ãã®ããã€ã¹ã§åäœã§ããªããããebtablesãå©ãã«ãªãå¿ èŠããããŸãã æ®å¿µãªããšã«ãããã¯ç§ã®ãã¡ãŒã ãŠã§ã¢ã«ã¯å«ãŸããŠããªãã£ããããããã€ã¹ããšã«ã€ã¡ãŒãžãåæ§ç¯ããå¿ èŠããããŸããã ãããå®è¡ãã次ã®è¡ãåã«ãŒã¿ãŒã® /etc/rc.local ã«è¿œå ããããšã§ãåé¡ã¯è§£æ±ºãããŸããã
ebtables -A INPUT --in-interface tap0 --protocol ipv4 --ip-protocol udp --ip-destination-port 67:68 -j DROP
ebtables -A INPUT --in-interface tap0 --protocol ipv4 --ip-protocol udp --ip-source-port 67:68 -j DROP
ebtables -A FORWARD --out-interface tap0 --protocol ipv4 --ip-protocol udp --ip-destination-port 67:68 -j DROP
ebtables -A FORWARD --out-interface tap0 --protocol ipv4 --ip-protocol udp --ip-source-port 67:68 -j DROP
ãã®æ§æ㯠XNUMX 幎éç¶ããŸããã
ããŒã 2: WireGuard ã®çŽ¹ä»
æè¿ãã€ã³ã¿ãŒãããäžã®äººã ã¯ãŸããŸã WireGuard ã«ã€ããŠè©±ãå§ãããã®æ§æã®ã·ã³ãã«ããé«ãäŒéé床ãäœã ping ãšåçã®ã»ãã¥ãªãã£ãè³è³ããŠããŸãã 詳ããæ å ±ãæ€çŽ¢ãããšãããããªããž ã¡ã³ããŒãšããŠã®åäœã TCP ãããã³ã«ã§ã®åäœããµããŒããããŠããªãããšãæããã«ãªã£ããããç§ã«ãšã£ãŠ OpenVPN ã«ä»£ããéžæè¢ã¯ãŸã ãªãã®ã§ã¯ãªãããšèããŸããã ãã®ãããWireGuard ã«ã€ããŠç¥ãã®ãå 延ã°ãã«ããŸããã
æ°æ¥åãWireGuard ãããŒãžã§ã³ 5.6 ãã Linux ã«ãŒãã«ã«æçµçã«å«ãŸãããšãããã¥ãŒã¹ã IT ã«é¢ä¿ãããªãœãŒã¹ã«åºãŸããŸããã ãã€ãã®ããã«ããã¥ãŒã¹èšäºã¯ WireGuard ãè³è³ããŸããã ç§ã¯åã³ãå€ãè¯ã OpenVPN ã«ä»£ããæ¹æ³ã®æš¡çŽ¢ã«åãçµã¿ãŸããã ä»åééããã®ã¯
ããã§ãã次ã®ã¹ããŒã ã䜿çšã㊠VPN over VPN ã䜿çšããããšã«ãããåé·æå·åãæ¯æãã決å®ãäžãããŸããã
ã¬ãã« XNUMX VPN:
VPS ã§ã ãµãŒã å
éšã¢ãã¬ã¹ 192.168.30.1
MS ã§ã ã¯ã©ã€ã¢ã³ã å
éšã¢ãã¬ã¹ 192.168.30.2 ã® VPS
MK2 ã§ã ã¯ã©ã€ã¢ã³ã å
éšã¢ãã¬ã¹ 192.168.30.3 ã® VPS
MK3 ã§ã ã¯ã©ã€ã¢ã³ã å
éšã¢ãã¬ã¹ 192.168.30.4 ã® VPS
第 XNUMX ã¬ãã«ã® VPN:
MS ã§ã ãµãŒã å€éšã¢ãã¬ã¹ 192.168.30.2 ãšå
éšã¢ãã¬ã¹ 192.168.31.1
MK2 ã§ã ã¯ã©ã€ã¢ã³ã MS ã¢ãã¬ã¹ã¯ 192.168.30.2 ã§ãå
éš IP 㯠192.168.31.2 ã§ãã
MK3 ã§ã ã¯ã©ã€ã¢ã³ã MS ã¢ãã¬ã¹ã¯ 192.168.30.2 ã§ãå
éš IP 㯠192.168.31.3 ã§ãã
* MS â ã¢ããŒã 1 ã®ã«ãŒã¿ãŒãµãŒããŒã MK2 - ã¢ããŒã2ã®ã«ãŒã¿ãŒã MK3 - ã¢ããŒãã®ã«ãŒã¿ãŒ 3
â»ç«¯æ«æ§æã¯èšäºæ«å°Ÿã®ãã¿ãã¬ã«ãŠæ²èŒããŠãããŸãã
ãããã¯ãŒã¯ ããŒã 192.168.31.0/24 é㧠ping ãå®è¡ãããŠãããããGRE ãã³ãã«ã®èšå®ã«é²ã¿ãŸãã ãã®åã«ãã«ãŒã¿ãŒãžã®ã¢ã¯ã»ã¹ã倱ããªãããã«ããããã«ãããŒã 22 ã VPS ã«è»¢éããããã« SSH ãã³ãã«ãèšå®ãã䟡å€ããããŸããããã«ãããããšãã°ãã¢ããŒã 10022 ã®ã«ãŒã¿ãŒã VPS ã®ããŒã 2 ã§ã¢ã¯ã»ã¹ã§ããããã«ãªããã¢ããŒã 11122 ã®ã«ãŒã¿ãŒã¯ãããŒã 3 ã§ã¢ã¯ã»ã¹ã§ããŸããã¢ããŒã XNUMX ã®ã«ãŒã¿ãŒã¯ãåã sshtunnel ã䜿çšããŠè»¢éãèšå®ããã®ãæåã§ããããã¯ãé害ãçºçããå Žåã«ãã³ãã«ã埩å ããããã§ãã
ãã³ãã«ãæ§æããã転éãããããŒããä»ã㊠SSH ã«æ¥ç¶ã§ããŸãã
ssh root@ÐÐÐ_VPS -p 10022
次ã«ãOpenVPN ãç¡å¹ã«ããå¿ èŠããããŸãã
/etc/init.d/openvpn stop
次ã«ãã¢ããŒã 2 ã®ã«ãŒã¿ãŒã« GRE ãã³ãã«ãèšå®ããŸãããã
ip link add grelan0 type gretap remote 192.168.31.1 local 192.168.31.2
ip link set grelan0 up
ãããŠãäœæããã€ã³ã¿ãŒãã§ã€ã¹ãããªããžã«è¿œå ããŸãã
brctl addif br-lan grelan0
ãµãŒããŒã«ãŒã¿ãŒã§ãåæ§ã®æé ãå®è¡ããŠã¿ãŸãããã
ip link add grelan0 type gretap remote 192.168.31.2 local 192.168.31.1
ip link set grelan0 up
ãŸããäœæããã€ã³ã¿ãŒãã§ã€ã¹ãããªããžã«è¿œå ããŸãã
brctl addif br-lan grelan0
ãã®ç¬éãããping ãæ°ãããããã¯ãŒã¯ã«æ£åžžã«éä¿¡ããå§ããæºè¶³ããŠã³ãŒããŒã飲ã¿ã«è¡ããŸãã 次ã«ãåç·ã®çžæåŽã§ãããã¯ãŒã¯ãã©ã®ããã«åäœããŠããããè©äŸ¡ããããã«ãã¢ããŒã 2 ã®ã³ã³ãã¥ãŒã¿ã® 22 å°ã« SSH æ¥ç¶ããããšããŸããããSSH ã¯ã©ã€ã¢ã³ãã¯ãã¹ã¯ãŒãã®å ¥åãæ±ããããã³ããã衚瀺ããã«ããªãŒãºããŸããã ããŒã XNUMX ã® Telnet çµç±ã§ãã®ã³ã³ãã¥ãŒã¿ã«æ¥ç¶ããããšãããšãæ¥ç¶ã確ç«ãããŠããããšãSSH ãµãŒããŒãå¿çããŠããããšãç解ã§ããè¡ã衚瀺ãããŸãããäœããã®çç±ã§ãã°ãæ±ããããã³ããã衚瀺ãããŸãããã§ã
$ telnet 192.168.10.110 22
SSH-2.0-OpenSSH_8.1
VNC çµç±ã§æ¥ç¶ããããšããŸããããé»ãç»é¢ã衚瀺ãããŸãã ãã®ã¢ããŒãããã¯å éšã¢ãã¬ã¹ã䜿çšããŠç°¡åã«ã«ãŒã¿ãŒã«æ¥ç¶ã§ãããããåé¡ã¯ãªã¢ãŒã ã³ã³ãã¥ãŒã¿ãŒã«ãããšèªåèªèº«ã«çŽåŸãããŸãã ããããã«ãŒã¿ãŒãä»ããŠãã®ã³ã³ãã¥ãŒã¿ãŒã® SSH ã«æ¥ç¶ããããšã«ãããšãããæ¥ç¶ã¯æåãããªã¢ãŒã ã³ã³ãã¥ãŒã¿ãŒã¯æ£åžžã«åäœããŠããã®ã«ãç§ã®ã³ã³ãã¥ãŒã¿ãŒã«ãæ¥ç¶ã§ããªãããšã«æ°ã¥ããŸããã
grelan0 ããã€ã¹ãããªããžããåé€ããã¢ããŒã 2 ã®ã«ãŒã¿ãŒã§ OpenVPN ãå®è¡ãããããã¯ãŒã¯ãåã³æåŸ ã©ããã«åäœããæ¥ç¶ãåæãããŠããªãããšã確èªããŸãã æ€çŽ¢ãããšãåãåé¡ã«ã€ããŠèŠæ ã蚎ãã人ã ãããŠãMTU ãäžããããã¢ããã€ã¹ãããŠãããã©ãŒã©ã ãèŠã€ããŸããã åŠãèšãã»ã©ãªãã ãã ããMTU ãååã«é«ãèšå®ããããŸã§ (gretap ããã€ã¹ã® 7000)ãTCP æ¥ç¶ã®ãããããŸãã¯äœã転éé床ã芳å¯ãããŸããã gretap ã® MTU ãé«ããããã¬ã€ã€ 8000 ããã³ã¬ã€ã€ 7500 WireGuard æ¥ç¶ã® MTU ã¯ãããã XNUMX ãš XNUMX ã«èšå®ãããŸããã
ã¢ããŒã 3 ã®ã«ãŒã¿ãŒã§ãåæ§ã®èšå®ãå®è¡ããŸããããå¯äžã®éãã¯ãgrelan1 ãšããååã® XNUMX çªç®ã® gretap ã€ã³ã¿ãŒãã§ã€ã¹ããµãŒã㌠ã«ãŒã¿ãŒã«è¿œå ãããbr-lan ããªããžã«ãè¿œå ãããããšã§ãã
ãã¹ãŠãæ©èœããŠããŸãã ããã§ãgretap ã¢ã»ã³ããªãã¹ã¿ãŒãã¢ããã«å ¥ããããšãã§ããŸãã ãã®ããã«ïŒ
ã¢ããŒã 2 ã®ã«ãŒã¿ãŒã® /etc/rc.local ã«æ¬¡ã®è¡ãé 眮ããŸããã
ip link add grelan0 type gretap remote 192.168.31.1 local 192.168.31.2
ip link set dev grelan0 mtu 7000
ip link set grelan0 up
brctl addif br-lan grelan0
ãããã¢ããŒã 3 ã®ã«ãŒã¿ãŒã® /etc/rc.local ã«è¿œå ããŸããã
ip link add grelan0 type gretap remote 192.168.31.1 local 192.168.31.3
ip link set dev grelan0 mtu 7000
ip link set grelan0 up
brctl addif br-lan grelan0
ãããŠãµãŒããŒã«ãŒã¿ãŒã§ã¯æ¬¡ã®ããã«ãªããŸãã
ip link add grelan0 type gretap remote 192.168.31.2 local 192.168.31.1
ip link set dev grelan0 mtu 7000
ip link set grelan0 up
brctl addif br-lan grelan0
ip link add grelan1 type gretap remote 192.168.31.3 local 192.168.31.1
ip link set dev grelan1 mtu 7000
ip link set grelan1 up
brctl addif br-lan grelan1
ã¯ã©ã€ã¢ã³ãã«ãŒã¿ãŒãåèµ·åããåŸãäœããã®çç±ã§ãµãŒããŒã«æ¥ç¶ããŠããªãããšãããããŸããã SSH ã«æ¥ç¶ãããš (幞ããªããšã«ããã®ããã«ä»¥åã« sshtunnel ãæ§æããŠããŸãã)ãäœããã®çç±ã§ WiââreGuard ããšã³ããã€ã³ãã®ã«ãŒããäœæããŠããããšãå€æããŸããããããã¯ééã£ãŠããŸããã ãããã£ãŠã192.168.30.2 ã®å Žåãã«ãŒã ããŒãã«ã¯ pppoe-wan ã€ã³ã¿ãŒãã§ã€ã¹ãã€ãŸãã€ã³ã¿ãŒããããçµç±ããã«ãŒãã瀺ããŠããŸãããããã®ã«ãŒããžã®ã«ãŒã㯠wg0 ã€ã³ã¿ãŒãã§ã€ã¹ãçµç±ããã¯ãã§ããã ãã®ã«ãŒããåé€ãããšãæ¥ç¶ã埩å ãããŸããã WireGuard ã«ãããã®ã«ãŒããäœæãããªãããã«ããæ¹æ³ã«é¢ãã説æã¯ã©ãã«ãèŠã€ãããŸããã§ããã ããã«ãããã OpenWRT ã®æ©èœãªã®ãããããšã WireGuard èªäœã®æ©èœãªã®ãããããããŸããã§ããã ãã®åé¡ã«é·ãé察åŠããå¿ èŠã¯ãªããåã«ãã®ã«ãŒããåé€ããæéæå®ã¹ã¯ãªããã®è¡ãäž¡æ¹ã®ã«ãŒã¿ãŒã«è¿œå ããŸããã
route del 192.168.30.2
èŠçŽ
ç§ã¯ãŸã OpenVPN ãå®å šã«æŸæ£ããããšã¯ã§ããŸãããã©ããããããæºåž¯é»è©±ããæ°ãããããã¯ãŒã¯ã«æ¥ç¶ããå¿ èŠãããããããã« gretap ããã€ã¹ãèšå®ããããšã¯éåžžäžå¯èœã§ããããã§ããããããããã«ãããããããé床ã®ç¹ã§å©ç¹ããããŸãããã¢ããŒãéã®ããŒã¿è»¢éã容æã«ãªããããšãã° VNC ã䜿çšããããšãäžäŸ¿ã§ã¯ãªããªããŸããã Ping ã¯ãããã«äœäžããŸããããããå®å®ããŸããã
OpenVPN ã䜿çšããå Žå:
[r0ck3r@desktop ~]$ ping -c 20 192.168.10.110
PING 192.168.10.110 (192.168.10.110) 56(84) bytes of data.
64 bytes from 192.168.10.110: icmp_seq=1 ttl=64 time=133 ms
...
64 bytes from 192.168.10.110: icmp_seq=20 ttl=64 time=125 ms
--- 192.168.10.110 ping statistics ---
20 packets transmitted, 20 received, 0% packet loss, time 19006ms
rtt min/avg/max/mdev = 124.722/126.152/136.907/3.065 ms
WireGuard ã䜿çšããå Žå:
[r0ck3r@desktop ~]$ ping -c 20 192.168.10.110
PING 192.168.10.110 (192.168.10.110) 56(84) bytes of data.
64 bytes from 192.168.10.110: icmp_seq=1 ttl=64 time=124 ms
...
64 bytes from 192.168.10.110: icmp_seq=20 ttl=64 time=124 ms
--- 192.168.10.110 ping statistics ---
20 packets transmitted, 20 received, 0% packet loss, time 19003ms
rtt min/avg/max/mdev = 123.954/124.423/126.708/0.675 ms
VPS ãžã®é«ã ping (çŽ 61.5 ããªç§) ã®åœ±é¿ããã倧ãããªããŸãã
ãã ããé床ã¯å€§å¹ ã«åäžããŸããã ãããã£ãŠããµãŒããŒã«ãŒã¿ãŒã®ããã¢ããŒãã§ã¯ã€ã³ã¿ãŒãããæ¥ç¶é床ã30 Mããã/ç§ã§ãããä»ã®ã¢ããŒãã§ã¯5 Mããã/ç§ã§ãã åæã«ãOpenVPN ã䜿çšããŠããéãiperf ã®æž¬å®å€ã«ããã°ããããã¯ãŒã¯éã®ããŒã¿è»¢éé床㯠3,8 Mbit/ç§ãè¶ ããããšãã§ããŸããã§ããããWireGuard ã¯ãããåã 5 Mbit/ç§ã«ãé«éåãããŸããã
VPS ã§ã® WireGuard æ§æ[Interface]
Address = 192.168.30.1/24
ListenPort = 51820
PrivateKey = <ÐÐÐРЫТЫÐ_ÐÐЮЧ_ÐÐЯ_VPS>
[Peer]
PublicKey = <ÐТÐРЫТЫÐ_ÐÐЮЧ_VPN_1_ÐС>
AllowedIPs = 192.168.30.2/32
[Peer]
PublicKey = <ÐТÐРЫТЫÐ_ÐÐЮЧ_VPN_2_ÐÐ2>
AllowedIPs = 192.168.30.3/32
[Peer]
PublicKey = <ÐТÐРЫТЫÐ_ÐÐЮЧ_VPN_2_ÐÐ3>
AllowedIPs = 192.168.30.4/32
MS äžã® WireGuard èšå® (/etc/config/network ã«è¿œå )
#VPN пеÑвПгП ÑÑÐŸÐ²ÐœÑ - клОеМÑ
config interface 'wg0'
option proto 'wireguard'
list addresses '192.168.30.2/24'
option private_key 'ÐÐÐРЫТЫÐ_ÐÐЮЧ_VPN_1_ÐС'
option auto '1'
option mtu '8000'
config wireguard_wg0
option public_key 'ÐТÐРЫТЫÐ_ÐÐЮЧ_VPN_1_VPS'
option endpoint_port '51820'
option route_allowed_ips '1'
option persistent_keepalive '25'
list allowed_ips '192.168.30.0/24'
option endpoint_host 'IP_ÐÐÐ ÐС_VPS'
#VPN вÑПÑПгП ÑÑÐŸÐ²ÐœÑ - ÑеÑвеÑ
config interface 'wg1'
option proto 'wireguard'
option private_key 'ÐÐÐРЫТЫÐ_ÐÐЮЧ_VPN_2_ÐС'
option listen_port '51821'
list addresses '192.168.31.1/24'
option auto '1'
option mtu '7500'
config wireguard_wg1
option public_key 'ÐТÐРЫТЫÐ_ÐÐЮЧ_VPN_2_ÐÐ2'
list allowed_ips '192.168.31.2'
config wireguard_wg1ip link add grelan0 type gretap remote 192.168.31.1 local 192.168.31.3
option public_key 'ÐТÐРЫТЫÐ_ÐÐЮЧ_VPN_2_ÐÐ3'
list allowed_ips '192.168.31.3'
MK2 ã® WireGuard èšå® (/etc/config/network ã«è¿œå )
#VPN пеÑвПгП ÑÑÐŸÐ²ÐœÑ - клОеМÑ
config interface 'wg0'
option proto 'wireguard'
list addresses '192.168.30.3/24'
option private_key 'ÐÐÐРЫТЫÐ_ÐÐЮЧ_VPN_1_ÐÐ2'
option auto '1'
option mtu '8000'
config wireguard_wg0
option public_key 'ÐТÐРЫТЫÐ_ÐÐЮЧ_VPN_1_VPS'
option endpoint_port '51820'
option persistent_keepalive '25'
list allowed_ips '192.168.30.0/24'
option endpoint_host 'IP_ÐÐÐ ÐС_VPS'
#VPN вÑПÑПгП ÑÑÐŸÐ²ÐœÑ - клОеМÑ
config interface 'wg1'
option proto 'wireguard'
option private_key 'ÐÐÐРЫТЫÐ_ÐÐЮЧ_VPN_2_ÐÐ2'
list addresses '192.168.31.2/24'
option auto '1'
option listen_port '51821'
option mtu '7500'
config wireguard_wg1
option public_key 'ÐТÐРЫТЫÐ_ÐÐЮЧ_VPN_2_ÐС'
option endpoint_host '192.168.30.2'
option endpoint_port '51821'
option persistent_keepalive '25'
list allowed_ips '192.168.31.0/24'
MK3 ã® WireGuard èšå® (/etc/config/network ã«è¿œå )
#VPN пеÑвПгП ÑÑÐŸÐ²ÐœÑ - клОеМÑ
config interface 'wg0'
option proto 'wireguard'
list addresses '192.168.30.4/24'
option private_key 'ÐÐÐРЫТЫÐ_ÐÐЮЧ_VPN_1_ÐÐ3'
option auto '1'
option mtu '8000'
config wireguard_wg0
option public_key 'ÐТÐРЫТЫÐ_ÐÐЮЧ_VPN_1_VPS'
option endpoint_port '51820'
option persistent_keepalive '25'
list allowed_ips '192.168.30.0/24'
option endpoint_host 'IP_ÐÐÐ ÐС_VPS'
#VPN вÑПÑПгП ÑÑÐŸÐ²ÐœÑ - клОеМÑ
config interface 'wg1'
option proto 'wireguard'
option private_key 'ÐÐÐРЫТЫÐ_ÐÐЮЧ_VPN_2_ÐÐ3'
list addresses '192.168.31.3/24'
option auto '1'
option listen_port '51821'
option mtu '7500'
config wireguard_wg1
option public_key 'ÐТÐРЫТЫÐ_ÐÐЮЧ_VPN_2_ÐС'
option endpoint_host '192.168.30.2'
option endpoint_port '51821'
option persistent_keepalive '25'
list allowed_ips '192.168.31.0/24'
説æãã第 51821 ã¬ãã« VPN ã®èšå®ã§ã¯ãWireGuard ã¯ã©ã€ã¢ã³ããããŒã 0 ã«åããŸããã¯ã©ã€ã¢ã³ãã¯ç©ºããŠããç¹æš©ã®ãªãããŒãããæ¥ç¶ã確ç«ãããããçè«çã«ã¯ããã¯å¿ èŠãããŸããããæ¥ç¶ãçŠæ¢ã§ããããã«ããŸãããããŒã 51821 ãžã®åä¿¡ UDP æ¥ç¶ãé€ãããã¹ãŠã®ã«ãŒã¿ãŒã® wgXNUMX ã€ã³ã¿ãŒãã§ã€ã¹äžã®ãã¹ãŠã®åä¿¡æ¥ç¶ã
ãã®èšäºã誰ãã®åœ¹ã«ç«ãŠã°å¹žãã§ãã
PS ãŸãããããã¯ãŒã¯äžã«æ°ããããã€ã¹ã衚瀺ããããšãã«ãWirePusher ã¢ããªã±ãŒã·ã§ã³ã§æºåž¯é»è©±ã« PUSH éç¥ãéä¿¡ããã¹ã¯ãªãããå
±æããããšèããŠããŸãã ã¹ã¯ãªãããžã®ãªã³ã¯ã¯æ¬¡ã®ãšããã§ãã
UPDATEïŒ OpenVPN ãµãŒããŒãšã¯ã©ã€ã¢ã³ãã®æ§æ
OpenVPNãµãŒããŒ
client-to-client
ca /etc/openvpn/server/ca.crt
cert /etc/openvpn/server/vpn-server.crt
dh /etc/openvpn/server/dh.pem
key /etc/openvpn/server/vpn-server.key
dev tap
ifconfig-pool-persist /etc/openvpn/ipp.txt 0
keepalive 10 60
proto tcp4
server-bridge 192.168.10.1 255.255.255.0 192.168.10.80 192.168.10.254
status /var/log/openvpn-status.log
verb 3
comp-lzo
OpenVPN ã¯ã©ã€ã¢ã³ã
client
tls-client
dev tap
proto tcp
remote VPS_IP 1194 # Change to your router's External IP
resolv-retry infinite
nobind
ca client/ca.crt
cert client/client.crt
key client/client.key
dh client/dh.pem
comp-lzo
persist-tun
persist-key
verb 3
easy-rsaã䜿çšããŠèšŒææžãçæããŸãã
åºæïŒ habr.com