OpenWrt๋ฅผ ์‹คํ–‰ํ•˜๋Š” Mikrotik ๋ผ์šฐํ„ฐ์—์„œ WireGuard ์„ค์ •

OpenWrt๋ฅผ ์‹คํ–‰ํ•˜๋Š” Mikrotik ๋ผ์šฐํ„ฐ์—์„œ WireGuard ์„ค์ •
๋Œ€๋ถ€๋ถ„์˜ ๊ฒฝ์šฐ ๋ผ์šฐํ„ฐ๋ฅผ VPN์— ์—ฐ๊ฒฐํ•˜๋Š” ๊ฒƒ์€ ์–ด๋ ต์ง€ ์•Š์ง€๋งŒ ์ „์ฒด ๋„คํŠธ์›Œํฌ๋ฅผ ๋ณดํ˜ธํ•˜๋ฉด์„œ ๋™์‹œ์— ์ตœ์ ์˜ ์—ฐ๊ฒฐ ์†๋„๋ฅผ ์œ ์ง€ํ•˜๋ ค๋ฉด VPN ํ„ฐ๋„์„ ์‚ฌ์šฉํ•˜๋Š” ๊ฒƒ์ด ๊ฐ€์žฅ ์ข‹์Šต๋‹ˆ๋‹ค. ์™€์ด์–ด ๊ฐ€๋“œ.

๋ผ์šฐํ„ฐ ๋ฏธํฌ ๋กœํ‹ฑ ์‹ ๋ขฐํ•  ์ˆ˜ ์žˆ๊ณ  ๋งค์šฐ ์œ ์—ฐํ•œ ์†”๋ฃจ์…˜์ž„์ด ์ž…์ฆ๋˜์—ˆ์ง€๋งŒ ๋ถˆํ–‰ํžˆ๋„ RouterOS์—์„œ WireGurd ์ง€์› ์—ฌ์ „ํžˆ ์กด์žฌํ•˜์ง€ ์•Š์œผ๋ฉฐ ์–ธ์ œ ์–ด๋–ค ์„ฑ๋Šฅ์œผ๋กœ ๋‚˜ํƒ€๋‚ ์ง€ ์•Œ ์ˆ˜ ์—†์Šต๋‹ˆ๋‹ค. ์ตœ๊ทผ์— ๊ทธ๊ฒƒ์€ ์•Œ๋ ค์กŒ๋‹ค WireGuard VPN ํ„ฐ๋„ ๊ฐœ๋ฐœ์ž๊ฐ€ ์ œ์•ˆํ•œ ๋‚ด์šฉ์— ๋Œ€ํ•ด ํŒจ์น˜ ์„ธํŠธ, VPN ํ„ฐ๋„๋ง ์†Œํ”„ํŠธ์›จ์–ด๋ฅผ Linux ์ปค๋„์˜ ์ผ๋ถ€๋กœ ๋งŒ๋“ค ๊ฒƒ์ด๋ฉฐ ์ด๊ฒƒ์ด RouterOS์˜ ์ฑ„ํƒ์— ๊ธฐ์—ฌํ•˜๊ธฐ๋ฅผ ๋ฐ”๋ž๋‹ˆ๋‹ค.

ํ•˜์ง€๋งŒ ์•ˆํƒ€๊น๊ฒŒ๋„ Mikrotik ๋ผ์šฐํ„ฐ์—์„œ WireGuard๋ฅผ ๊ตฌ์„ฑํ•˜๋ ค๋ฉด ํŽŒ์›จ์–ด๋ฅผ ๋ณ€๊ฒฝํ•ด์•ผ ํ•ฉ๋‹ˆ๋‹ค.

Mikrotik ๊นœ๋ฐ•์ž„, OpenWrt ์„ค์น˜ ๋ฐ ๊ตฌ์„ฑ

๋จผ์ € OpenWrt๊ฐ€ ๋ชจ๋ธ์„ ์ง€์›ํ•˜๋Š”์ง€ ํ™•์ธํ•ด์•ผ ํ•ฉ๋‹ˆ๋‹ค. ๋ชจ๋ธ์ด ๋งˆ์ผ€ํŒ… ์ด๋ฆ„ ๋ฐ ์ด๋ฏธ์ง€์™€ ์ผ์น˜ํ•˜๋Š”์ง€ ํ™•์ธ mikrotik.com์„ ๋ฐฉ๋ฌธํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค..

openwrt.com์œผ๋กœ ์ด๋™ ํŽŒ์›จ์–ด ๋‹ค์šด๋กœ๋“œ ์„น์…˜์œผ๋กœ.

์ด ์žฅ์น˜์—๋Š” 2๊ฐœ์˜ ํŒŒ์ผ์ด ํ•„์š”ํ•ฉ๋‹ˆ๋‹ค.

downloads.openwrt.org/releases/18.06.2/targets/ar71xx/mikrotik/openwrt-18.06.2-ar71xx-mikrotik-rb-nor-flash-16M-initramfs-kernel.bin|elf

downloads.openwrt.org/releases/18.06.2/targets/ar71xx/mikrotik/openwrt-18.06.2-ar71xx-mikrotik-rb-nor-flash-16M-squashfs-sysupgrade.bin

๋‘ ํŒŒ์ผ์„ ๋ชจ๋‘ ๋‹ค์šด๋กœ๋“œํ•ด์•ผ ํ•ฉ๋‹ˆ๋‹ค. ์„ค์น˜ ะธ ์—…๊ทธ๋ ˆ์ด๋“œ.

OpenWrt๋ฅผ ์‹คํ–‰ํ•˜๋Š” Mikrotik ๋ผ์šฐํ„ฐ์—์„œ WireGuard ์„ค์ •

1. ๋„คํŠธ์›Œํฌ ์„ค์ •, PXE ์„œ๋ฒ„ ๋‹ค์šด๋กœ๋“œ ๋ฐ ์„ค์ •

๋‹ค์šด๋กœ๋“œ ์ดˆ์†Œํ˜• PXE ์„œ๋ฒ„ Windows ์ตœ์‹  ๋ฒ„์ „์˜ ๊ฒฝ์šฐ.

๋ณ„๋„์˜ ํด๋”์— ์••์ถ•์„ ํ’‰๋‹ˆ๋‹ค. config.ini ํŒŒ์ผ์—์„œ ๋งค๊ฐœ๋ณ€์ˆ˜๋ฅผ ์ถ”๊ฐ€ํ•ฉ๋‹ˆ๋‹ค. RFC951=1 ๋ถ€๋ถ„ [DHCP]. ์ด ๋งค๊ฐœ๋ณ€์ˆ˜๋Š” ๋ชจ๋“  Mikrotik ๋ชจ๋ธ์— ๋Œ€ํ•ด ๋™์ผํ•ฉ๋‹ˆ๋‹ค.

OpenWrt๋ฅผ ์‹คํ–‰ํ•˜๋Š” Mikrotik ๋ผ์šฐํ„ฐ์—์„œ WireGuard ์„ค์ •

๋„คํŠธ์›Œํฌ ์„ค์ •์œผ๋กœ ์ด๋™ํ•ด ๋ณด๊ฒ ์Šต๋‹ˆ๋‹ค. ์ปดํ“จํ„ฐ์˜ ๋„คํŠธ์›Œํฌ ์ธํ„ฐํŽ˜์ด์Šค ์ค‘ ํ•˜๋‚˜์— ๊ณ ์ • IP ์ฃผ์†Œ๋ฅผ ๋“ฑ๋กํ•ด์•ผ ํ•ฉ๋‹ˆ๋‹ค.

OpenWrt๋ฅผ ์‹คํ–‰ํ•˜๋Š” Mikrotik ๋ผ์šฐํ„ฐ์—์„œ WireGuard ์„ค์ •

IP ์ฃผ์†Œ: 192.168.1.10
๋„ท๋งˆ์Šคํฌ: 255.255.255.0

OpenWrt๋ฅผ ์‹คํ–‰ํ•˜๋Š” Mikrotik ๋ผ์šฐํ„ฐ์—์„œ WireGuard ์„ค์ •

์‹คํ–‰ ์ดˆ์†Œํ˜• PXE ์„œ๋ฒ„ ๊ด€๋ฆฌ์ž๋ฅผ ๋Œ€์‹ ํ•˜์—ฌ ํ•„๋“œ์—์„œ ์„ ํƒ DHCP ์„œ๋ฒ„ ์ฃผ์†Œ๊ฐ€ ์žˆ๋Š” ์„œ๋ฒ„ 192.168.1.10

์ผ๋ถ€ Windows ๋ฒ„์ „์—์„œ๋Š” ์ด ์ธํ„ฐํŽ˜์ด์Šค๊ฐ€ ์ด๋”๋„ท ์—ฐ๊ฒฐ ํ›„์—๋งŒ ๋‚˜ํƒ€๋‚  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ๋ผ์šฐํ„ฐ๋ฅผ ์—ฐ๊ฒฐํ•˜๊ณ  ์ฆ‰์‹œ ํŒจ์น˜ ์ฝ”๋“œ๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ ๋ผ์šฐํ„ฐ์™€ PC๋ฅผ ์ „ํ™˜ํ•˜๋Š” ๊ฒƒ์ด ์ข‹์Šต๋‹ˆ๋‹ค.

OpenWrt๋ฅผ ์‹คํ–‰ํ•˜๋Š” Mikrotik ๋ผ์šฐํ„ฐ์—์„œ WireGuard ์„ค์ •

"..." ๋ฒ„ํŠผ(์˜ค๋ฅธ์ชฝ ํ•˜๋‹จ)์„ ๋ˆ„๋ฅด๊ณ  Mikrotik์šฉ ํŽŒ์›จ์–ด ํŒŒ์ผ์„ ๋‹ค์šด๋กœ๋“œํ•œ ํด๋”๋ฅผ ์ง€์ •ํ•ฉ๋‹ˆ๋‹ค.

์ด๋ฆ„์ด "initramfs-kernel.bin ๋˜๋Š” elf"๋กœ ๋๋‚˜๋Š” ํŒŒ์ผ์„ ์„ ํƒํ•˜์‹ญ์‹œ์˜ค.

OpenWrt๋ฅผ ์‹คํ–‰ํ•˜๋Š” Mikrotik ๋ผ์šฐํ„ฐ์—์„œ WireGuard ์„ค์ •

2. PXE ์„œ๋ฒ„์—์„œ ๋ผ์šฐํ„ฐ ๋ถ€ํŒ…

์šฐ๋ฆฌ๋Š” ๋ผ์šฐํ„ฐ์˜ ์ฒซ ๋ฒˆ์งธ ํฌํŠธ(wan, ์ธํ„ฐ๋„ท, poe in, ...)์™€ ์œ ์„ ์œผ๋กœ PC๋ฅผ ์—ฐ๊ฒฐํ•ฉ๋‹ˆ๋‹ค. ๊ทธ ํ›„ ์ด์‘ค์‹œ๊ฐœ๋ฅผ ๊ฐ€์ ธ๋‹ค๊ฐ€ "์žฌ์„ค์ •"์ด๋ผ๊ณ  ์ ํžŒ ๊ตฌ๋ฉ์— ๋ถ™์ž…๋‹ˆ๋‹ค.

OpenWrt๋ฅผ ์‹คํ–‰ํ•˜๋Š” Mikrotik ๋ผ์šฐํ„ฐ์—์„œ WireGuard ์„ค์ •

๋ผ์šฐํ„ฐ์˜ ์ „์›์„ ์ผœ๊ณ  20์ดˆ๊ฐ„ ๊ธฐ๋‹ค๋ฆฐ ๋‹ค์Œ ์ด์‘ค์‹œ๊ฐœ๋ฅผ ๋†“์Šต๋‹ˆ๋‹ค.
๋‹ค์Œ XNUMX๋ถ„ ์ด๋‚ด์— ๋‹ค์Œ ๋ฉ”์‹œ์ง€๊ฐ€ Tiny PXE ์„œ๋ฒ„ ์ฐฝ์— ๋‚˜ํƒ€๋‚ฉ๋‹ˆ๋‹ค.

OpenWrt๋ฅผ ์‹คํ–‰ํ•˜๋Š” Mikrotik ๋ผ์šฐํ„ฐ์—์„œ WireGuard ์„ค์ •

๋ฉ”์‹œ์ง€๊ฐ€ ๋‚˜ํƒ€๋‚˜๋ฉด ์˜ฌ๋ฐ”๋ฅธ ๋ฐฉํ–ฅ์œผ๋กœ ๊ฐ€๊ณ  ์žˆ๋Š” ๊ฒƒ์ž…๋‹ˆ๋‹ค!

๋„คํŠธ์›Œํฌ ์–ด๋Œ‘ํ„ฐ์˜ ์„ค์ •์„ ๋ณต์›ํ•˜๊ณ  ์ฃผ์†Œ๋ฅผ ๋™์ ์œผ๋กœ ์ˆ˜์‹ ํ•˜๋„๋ก ์„ค์ •ํ•ฉ๋‹ˆ๋‹ค(DHCP๋ฅผ ํ†ตํ•ด).

๋™์ผํ•œ ํŒจ์น˜ ์ฝ”๋“œ๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ Mikrotik ๋ผ์šฐํ„ฐ(์ด ๊ฒฝ์šฐ 2โ€ฆ5)์˜ LAN ํฌํŠธ์— ์—ฐ๊ฒฐํ•ฉ๋‹ˆ๋‹ค. 1๋ฒˆ ํฌํŠธ์—์„œ 2๋ฒˆ ํฌํŠธ๋กœ ๋ฐ”๊ฟ”์ฃผ์‹œ๋ฉด ๋ฉ๋‹ˆ๋‹ค. ๊ณต๊ฐœ ์ฃผ์†Œ 192.168.1.1 ๋ธŒ๋ผ์šฐ์ €์—์„œ.

OpenWrt๋ฅผ ์‹คํ–‰ํ•˜๋Š” Mikrotik ๋ผ์šฐํ„ฐ์—์„œ WireGuard ์„ค์ •

OpenWRT ๊ด€๋ฆฌ ์ธํ„ฐํŽ˜์ด์Šค์— ๋กœ๊ทธ์ธํ•˜๊ณ  "์‹œ์Šคํ…œ -> ๋ฐฑ์—…/ํ”Œ๋ž˜์‹œ ํŽŒ์›จ์–ด" ๋ฉ”๋‰ด ์„น์…˜์œผ๋กœ ์ด๋™ํ•ฉ๋‹ˆ๋‹ค.

OpenWrt๋ฅผ ์‹คํ–‰ํ•˜๋Š” Mikrotik ๋ผ์šฐํ„ฐ์—์„œ WireGuard ์„ค์ •

"์ƒˆ ํŽŒ์›จ์–ด ์ด๋ฏธ์ง€ ํ”Œ๋ž˜์‹œ" ํ•˜์œ„ ์„น์…˜์—์„œ "ํŒŒ์ผ ์„ ํƒ(์ฐพ์•„๋ณด๊ธฐ)" ๋ฒ„ํŠผ์„ ํด๋ฆญํ•ฉ๋‹ˆ๋‹ค.

OpenWrt๋ฅผ ์‹คํ–‰ํ•˜๋Š” Mikrotik ๋ผ์šฐํ„ฐ์—์„œ WireGuard ์„ค์ •

์ด๋ฆ„์ด "-squashfs-sysupgrade.bin"์œผ๋กœ ๋๋‚˜๋Š” ํŒŒ์ผ์˜ ๊ฒฝ๋กœ๋ฅผ ์ง€์ •ํ•ฉ๋‹ˆ๋‹ค.

OpenWrt๋ฅผ ์‹คํ–‰ํ•˜๋Š” Mikrotik ๋ผ์šฐํ„ฐ์—์„œ WireGuard ์„ค์ •

๊ทธ๋Ÿฐ ๋‹ค์Œ "ํ”Œ๋ž˜์‹œ ์ด๋ฏธ์ง€"๋ฒ„ํŠผ์„ ํด๋ฆญํ•˜์‹ญ์‹œ์˜ค.

๋‹ค์Œ ์ฐฝ์—์„œ "์ง„ํ–‰" ๋ฒ„ํŠผ์„ ํด๋ฆญํ•ฉ๋‹ˆ๋‹ค. ํŽŒ์›จ์–ด๊ฐ€ ๋ผ์šฐํ„ฐ๋กœ ๋‹ค์šด๋กœ๋“œ๋˜๊ธฐ ์‹œ์ž‘ํ•ฉ๋‹ˆ๋‹ค.

OpenWrt๋ฅผ ์‹คํ–‰ํ•˜๋Š” Mikrotik ๋ผ์šฐํ„ฐ์—์„œ WireGuard ์„ค์ •

!!! ์–ด๋–ค ๊ฒฝ์šฐ์—๋„ ํŽŒ์›จ์–ด ํ”„๋กœ์„ธ์Šค ์ค‘์— ๋ผ์šฐํ„ฐ์˜ ์ „์›์„ ๋ถ„๋ฆฌํ•˜์ง€ ๋งˆ์‹ญ์‹œ์˜ค!!!

OpenWrt๋ฅผ ์‹คํ–‰ํ•˜๋Š” Mikrotik ๋ผ์šฐํ„ฐ์—์„œ WireGuard ์„ค์ •

๋ผ์šฐํ„ฐ๋ฅผ ํ”Œ๋ž˜์‹ฑํ•˜๊ณ  ์žฌ๋ถ€ํŒ…ํ•˜๋ฉด OpenWRT ํŽŒ์›จ์–ด๊ฐ€ ํฌํ•จ๋œ Mikrotik์„ ๋ฐ›๊ฒŒ ๋ฉ๋‹ˆ๋‹ค.

๊ฐ€๋Šฅํ•œ ๋ฌธ์ œ ๋ฐ ํ•ด๊ฒฐ ๋ฐฉ๋ฒ•

2019๋…„์— ์ถœ์‹œ๋œ ๋งŽ์€ Mikrotik ์žฅ์น˜๋Š” GD25Q15/Q16 ์œ ํ˜•์˜ FLASH-NOR ๋ฉ”๋ชจ๋ฆฌ ์นฉ์„ ์‚ฌ์šฉํ•ฉ๋‹ˆ๋‹ค. ๋ฌธ์ œ๋Š” ๊นœ๋ฐ•์ผ ๋•Œ ์žฅ์น˜ ๋ชจ๋ธ์— ๋Œ€ํ•œ ๋ฐ์ดํ„ฐ๊ฐ€ ์ €์žฅ๋˜์ง€ ์•Š๋Š”๋‹ค๋Š” ๊ฒƒ์ž…๋‹ˆ๋‹ค.

"์—…๋กœ๋“œ๋œ ์ด๋ฏธ์ง€ ํŒŒ์ผ์— ์ง€์›๋˜๋Š” ํ˜•์‹์ด ์—†์Šต๋‹ˆ๋‹ค. ํ”Œ๋žซํผ์— ๋งž๋Š” ์ผ๋ฐ˜ ์ด๋ฏธ์ง€ ํ˜•์‹์„ ์„ ํƒํ–ˆ๋Š”์ง€ ํ™•์ธํ•˜์„ธ์š”." ๊ทธ๋Ÿฌ๋ฉด ๋ฌธ์ œ๊ฐ€ ํ”Œ๋ž˜์‹œ์— ์žˆ์„ ๊ฐ€๋Šฅ์„ฑ์ด ํฝ๋‹ˆ๋‹ค.

์ด๊ฒƒ์„ ํ™•์ธํ•˜๋Š” ๊ฒƒ์€ ์‰ฝ์Šต๋‹ˆ๋‹ค: ์žฅ์น˜ ํ„ฐ๋ฏธ๋„์—์„œ ๋ชจ๋ธ ID๋ฅผ ํ™•์ธํ•˜๋Š” ๋ช…๋ น์„ ์‹คํ–‰ํ•˜์‹ญ์‹œ์˜ค.

root@OpenWrt: cat /tmp/sysinfo/board_name

"์•Œ ์ˆ˜ ์—†์Œ"์ด๋ผ๋Š” ๋Œ€๋‹ต์„ ๋ฐ›์œผ๋ฉด "rb-951-2nd" ํ˜•์‹์œผ๋กœ ์žฅ์น˜ ๋ชจ๋ธ์„ ์ˆ˜๋™์œผ๋กœ ์ง€์ •ํ•ด์•ผ ํ•ฉ๋‹ˆ๋‹ค.

์žฅ์น˜ ๋ชจ๋ธ์„ ๊ฐ€์ ธ์˜ค๋ ค๋ฉด ๋‹ค์Œ ๋ช…๋ น์„ ์‹คํ–‰ํ•˜์‹ญ์‹œ์˜ค.

root@OpenWrt: cat /tmp/sysinfo/model
MikroTik RouterBOARD RB951-2nd

๊ธฐ๊ธฐ ๋ชจ๋ธ์„ ๋ฐ›์€ ํ›„ ์ˆ˜๋™์œผ๋กœ ์„ค์น˜ํ•ฉ๋‹ˆ๋‹ค.

echo 'rb-951-2nd' > /tmp/sysinfo/board_name

๊ทธ๋Ÿฐ ๋‹ค์Œ ์›น ์ธํ„ฐํŽ˜์ด์Šค๋ฅผ ํ†ตํ•ด ๋˜๋Š” "sysupgrade" ๋ช…๋ น์„ ์‚ฌ์šฉํ•˜์—ฌ ์žฅ์น˜๋ฅผ ํ”Œ๋ž˜์‹œํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

WireGuard๋กœ VPN ์„œ๋ฒ„ ๋งŒ๋“ค๊ธฐ

WireGuard๊ฐ€ ๊ตฌ์„ฑ๋œ ์„œ๋ฒ„๊ฐ€ ์ด๋ฏธ ์žˆ๋Š” ๊ฒฝ์šฐ ์ด ๋‹จ๊ณ„๋ฅผ ๊ฑด๋„ˆ๋›ธ ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.
์• ํ”Œ๋ฆฌ์ผ€์ด์…˜์„ ์‚ฌ์šฉํ•˜์—ฌ ๊ฐœ์ธ VPN ์„œ๋ฒ„๋ฅผ ์„ค์ •ํ•˜๊ฒ ์Šต๋‹ˆ๋‹ค. MyVPN.RUN ๋‚˜๋Š” ์ด๋ฏธ ๊ณ ์–‘์ด์— ๋Œ€ํ•ด ๋ฆฌ๋ทฐ๋ฅผ ๊ฒŒ์‹œํ–ˆ์Šต๋‹ˆ๋‹ค.

OpenWRT์—์„œ WireGuard ํด๋ผ์ด์–ธํŠธ ๊ตฌ์„ฑ

SSH ํ”„๋กœํ† ์ฝœ์„ ํ†ตํ•ด ๋ผ์šฐํ„ฐ์— ์—ฐ๊ฒฐ:

ssh [email protected]

WireGuard ์„ค์น˜:

opkg update
opkg install wireguard

๊ตฌ์„ฑ์„ ์ค€๋น„ํ•ฉ๋‹ˆ๋‹ค(์•„๋ž˜ ์ฝ”๋“œ๋ฅผ ํŒŒ์ผ์— ๋ณต์‚ฌํ•˜๊ณ  ์ง€์ •๋œ ๊ฐ’์„ ์ž์‹ ์˜ ๊ฐ’์œผ๋กœ ๋ฐ”๊พธ๊ณ  ํ„ฐ๋ฏธ๋„์—์„œ ์‹คํ–‰).

MyVPN์„ ์‚ฌ์šฉํ•˜๋Š” ๊ฒฝ์šฐ ์•„๋ž˜ ๊ตฌ์„ฑ์—์„œ ๋ณ€๊ฒฝ๋งŒ ํ•˜๋ฉด ๋ฉ๋‹ˆ๋‹ค. WG_SERV - ์„œ๋ฒ„ IP WG_KEY - wireguard ๊ตฌ์„ฑ ํŒŒ์ผ์˜ ๊ฐœ์ธ ํ‚ค ๋ฐ WG_PUB - ๊ณต๊ฐœ ํ‚ค.

WG_IF="wg0"
WG_SERV="100.0.0.0" # ip ะฐะดั€ะตั ัะตั€ะฒะตั€ะฐ
WG_PORT="51820" # ะฟะพั€ั‚ wireguard
WG_ADDR="10.8.0.2/32" # ะดะธะฐะฟะฐะทะพะฝ ะฐะดั€ะตัะพะฒ wireguard

WG_KEY="xxxxx" # ะฟั€ะธะฒะฐั‚ะฝั‹ะน ะบะปัŽั‡
WG_PUB="xxxxx" # ะฟัƒะฑะปะธั‡ะฝั‹ะน ะบะปัŽั‡ 

# Configure firewall
uci rename firewall.@zone[0]="lan"
uci rename firewall.@zone[1]="wan"
uci rename firewall.@forwarding[0]="lan_wan"
uci del_list firewall.wan.network="${WG_IF}"
uci add_list firewall.wan.network="${WG_IF}"
uci commit firewall
/etc/init.d/firewall restart

# Configure network
uci -q delete network.${WG_IF}
uci set network.${WG_IF}="interface"
uci set network.${WG_IF}.proto="wireguard"
uci set network.${WG_IF}.private_key="${WG_KEY}"

uci add_list network.${WG_IF}.addresses="${WG_ADDR}"

# Add VPN peers
uci -q delete network.wgserver
uci set network.wgserver="wireguard_${WG_IF}"
uci set network.wgserver.public_key="${WG_PUB}"
uci set network.wgserver.preshared_key=""
uci set network.wgserver.endpoint_host="${WG_SERV}"
uci set network.wgserver.endpoint_port="${WG_PORT}"
uci set network.wgserver.route_allowed_ips="1"
uci set network.wgserver.persistent_keepalive="25"
uci add_list network.wgserver.allowed_ips="0.0.0.0/1"
uci add_list network.wgserver.allowed_ips="128.0.0.0/1"
uci add_list network.wgserver.allowed_ips="::/0"
uci commit network
/etc/init.d/network restart

์ด๊ฒƒ์œผ๋กœ WireGuard ์„ค์ •์ด ์™„๋ฃŒ๋˜์—ˆ์Šต๋‹ˆ๋‹ค! ์ด์ œ ์—ฐ๊ฒฐ๋œ ๋ชจ๋“  ์žฅ์น˜์˜ ๋ชจ๋“  ํŠธ๋ž˜ํ”ฝ์ด VPN ์—ฐ๊ฒฐ๋กœ ๋ณดํ˜ธ๋ฉ๋‹ˆ๋‹ค.

์ฐธ์กฐ

์ถœ์ฒ˜ #1
MyVPN์— ๋Œ€ํ•œ ์ˆ˜์ •๋œ ์ง€์นจ (ํ‘œ์ค€ Mikrotik ํŽŒ์›จ์–ด์—์„œ L2TP, PPTP ์„ค์ •์„ ์œ„ํ•œ ์ถ”๊ฐ€ ์ง€์นจ ์‚ฌ์šฉ ๊ฐ€๋Šฅ)
OpenWrt WireGuard ํด๋ผ์ด์–ธํŠธ

์ถœ์ฒ˜ : habr.com

์ฝ”๋ฉ˜ํŠธ๋ฅผ ์ถ”๊ฐ€