Wireguard Inkonzo yeVPN yasimahla kwi-AWS

Yenzelwe ntoni?

Ngokunyuka kokuhlolwa kwe-Intanethi ngoorhulumente abagunyazisiweyo, inani elandayo lezixhobo ze-Intanethi eziluncedo kunye neziza ziyavalwa. Kubandakanya ulwazi lobugcisa.
Ke, kuba nzima ukusebenzisa i-Intanethi ngokupheleleyo kwaye kunyhasha ilungelo elisisiseko lenkululeko yokuthetha, ebhalwe IsiBhengezo seHlabathi samaLungelo oLuntu.

Inqaku 19
Wonke umntu unelungelo lenkululeko yokuvakalisa izimvo zakhe; eli lungelo libandakanya inkululeko yokubamba uluvo ngaphandle kokuphazamiseka nokufuna, ukufumana nokudlulisela ulwazi neembono ngawo nawaphi na amajelo eendaba nokuba yeyiphi na imida.

Kwesi sikhokelo, siza kuthumela eyethu i-freeware* ngamanyathelo ama-6. Inkonzo yeVPN ngokusekelwe kwiteknoloji Umgcini, kwisiseko selifu IiNkonzo ze-Amazon Web (AWS), usebenzisa i-akhawunti yasimahla (kwiinyanga ezili-12), kumzekelo (umatshini obonakalayo) olawulwa ngu Umncedisi we-Ubuntu 18.04 LTS.
Ndizamile ukwenza le walkthrough ibenobuhlobo kubantu abangeyo-IT kangangoko ndinako. Ekuphela kwento efunekayo kukuzingisa ekuphindaphindeni la manyathelo achazwe ngezantsi.

Qaphela:

Amanqanaba

  1. Bhalisela i-akhawunti ye-AWS yasimahla
  2. Yenza umzekelo we-AWS
  3. Ukuqhagamshela kumzekelo we-AWS
  4. Uqwalaselo lweWireguard
  5. Ukuqwalasela abaxhasi beVPN
  6. Ukujonga ukuchaneka kofakelo lweVPN

amakhonkco aluncedo

1. Ukubhalisa i-akhawunti ye-AWS

Ukubhalisela i-akhawunti ye-AWS yasimahla kufuna inombolo yokwenyani yefowuni kunye neVisa okanye ikhadi letyala le-Mastercard elisebenzayo. Ndincoma ukusebenzisa amakhadi enyani abonelelwa simahla Yandex.Money okanye qiwi wallet. Ukujonga ukunyaniseka kwekhadi, i-$ 1 itsalwa ngexesha lokubhalisa, elibuyiselwa kamva.

1.1. Ukuvula i-AWS Management Console

Kufuneka uvule isikhangeli kwaye uye ku: https://aws.amazon.com/ru/
Cofa kwiqhosha elithi "Register".

Wireguard Inkonzo yeVPN yasimahla kwi-AWS

1.2. Ukuzalisa iinkcukacha zobuqu

Gcwalisa idatha kwaye nqakraza kwiqhosha elithi "Qhubeka".

Wireguard Inkonzo yeVPN yasimahla kwi-AWS

1.3. Ukuzalisa iinkcukacha zoqhagamshelwano

Gcwalisa iinkcukacha zoqhagamshelwano.

Wireguard Inkonzo yeVPN yasimahla kwi-AWS

1.4. Ichaza iinkcukacha zentlawulo.

Inombolo yekhadi, umhla wokuphelelwa kunye negama lomnini wekhadi.

Wireguard Inkonzo yeVPN yasimahla kwi-AWS

1.5. Ukuqinisekiswa kweakhawunti

Ngeli nqanaba, inombolo yefowuni iqinisekisiwe kwaye i-$ 1 itsalwa ngokuthe ngqo kwikhadi lokuhlawula. Ikhowudi enamanani ama-4 iboniswa kwiscreen sekhompyuter, kwaye ifowuni echaziweyo ifumana umnxeba ovela kwiAmazon. Ngexesha lokufowuna, kufuneka ucofe ikhowudi eboniswe esikrinini.

Wireguard Inkonzo yeVPN yasimahla kwi-AWS

1.6. Ukukhetha isicwangciso sentlawulo.

Khetha - Isicwangciso esisisiseko (simahla)

Wireguard Inkonzo yeVPN yasimahla kwi-AWS

1.7. Ngena kwikhonsoli yolawulo

Wireguard Inkonzo yeVPN yasimahla kwi-AWS

1.8. Ukukhetha indawo yeziko ledatha

Wireguard Inkonzo yeVPN yasimahla kwi-AWS

1.8.1. Uvavanyo lwesantya

Ngaphambi kokukhetha iziko ledatha, kuyacetyiswa ukuba uvavanye https://speedtest.net isantya sofikelelo kumaziko edatha akufutshane, kwindawo yam ezi ziphumo zilandelayo:

  • Π‘ΠΈΠ½Π³Π°ΠΏΡƒΡ€
    Wireguard Inkonzo yeVPN yasimahla kwi-AWS
  • EParis
    Wireguard Inkonzo yeVPN yasimahla kwi-AWS
  • EFranfurt
    Wireguard Inkonzo yeVPN yasimahla kwi-AWS
  • Stockholm
    Wireguard Inkonzo yeVPN yasimahla kwi-AWS
  • ELondon
    Wireguard Inkonzo yeVPN yasimahla kwi-AWS

Iziko ledatha eLondon libonisa iziphumo ezilungileyo ngokwesantya. Ngoko ke ndiyikhethele ukwenza ngokwezifiso ngakumbi.

2. Yenza umzekelo we-AWS

2.1 Yenza umatshini wenyani

2.1.1. Ukukhetha uhlobo lomzekelo

Ngokungagqibekanga, umzekelo we-t2.micro ukhethiwe, siyawufuna, cofa nje iqhosha Okulandelayo: Lungisa iiNkcukacha zoMfanekiso

Wireguard Inkonzo yeVPN yasimahla kwi-AWS

2.1.2. Ukuseta Iinketho zoMfanekiso

Kwixesha elizayo, siya kudibanisa i-IP yoluntu esisigxina kumzekelo wethu, ngoko kweli nqanaba sicima i-auto-assignment ye-IP yoluntu, kwaye cinezela iqhosha. Okulandelayo: Yongeza uGcino

Wireguard Inkonzo yeVPN yasimahla kwi-AWS

2.1.3. Uqhagamshelo lokugcina

Cacisa ubungakanani be "hard disk". Ngeenjongo zethu, iigigabhayithi ezili-16 zanele, kwaye sicinezela iqhosha Okulandelayo: Yongeza iithegi

Wireguard Inkonzo yeVPN yasimahla kwi-AWS

2.1.4. Ukuseta iithegi

Ukuba sidale iimeko ezininzi, ngoko ke zinokudityaniswa ngeethegi ukuququzelela ulawulo. Kule meko, oku kusebenza kungaphezulu, ngoko nangoko cofa iqhosha Okulandelayo: Qwalasela iQela loKhuseleko

Wireguard Inkonzo yeVPN yasimahla kwi-AWS

2.1.5. Ukuvula amazibuko

Kweli nyathelo, siqwalasela i-firewall ngokuvula amazibuko afunekayo. Iseti yamazibuko avuliweyo ibizwa ngokuba liQela loKhuseleko. Kufuneka senze iqela elitsha lokhuseleko, silinike igama, inkcazo, yongeza izibuko le-UDP (Umthetho we-UDP yesiko), kwi-Rort Range field, kufuneka unikeze inombolo yezibuko ukusuka kuluhlu. amazibuko aguqukayo 49152-65535. Kule meko, ndakhetha inombolo ye-port 54321.

Wireguard Inkonzo yeVPN yasimahla kwi-AWS

Emva kokugcwalisa idatha efunekayo, nqakraza kwiqhosha Ukuphonononga kunye nokuQalisa

2.1.6. Isishwankathelo sazo zonke iisetingi

Kweli phepha kukho isishwankathelo sazo zonke izicwangciso zomzekelo wethu, sijonga ukuba zonke izicwangciso zimi ngolungelelwano, kwaye cinezela iqhosha. Qalisa

Wireguard Inkonzo yeVPN yasimahla kwi-AWS

2.1.7. Ukudala amaqhosha okufikelela

Okulandelayo kuza ibhokisi yencoko yababini enikezela ukwenza okanye ukongeza isitshixo se-SSH esele sikhona, esiya kuthi kamva siqhagamshele ukude kumzekelo wethu. Sikhetha i "Yenza iperi yesitshixo esitsha" ukhetho lokudala iqhosha elitsha. Yinike igama kwaye ucofe iqhosha Khuphela izibini ezingundoqoukukhuphela izitshixo ezenziweyo. Zigcine kwindawo ekhuselekileyo kwikhompyuter yakho yasekhaya. Nje ukuba ukhutshelwe, cofa iqhosha. Iimeko zokuQalisa

Wireguard Inkonzo yeVPN yasimahla kwi-AWS

2.1.7.1. Ukugcina amaqhosha okufikelela

Iboniswe apha linyathelo lokugcina izitshixo ezenziweyo ukusuka kwinqanaba langaphambili. Emva kokuba sicofe iqhosha Khuphela izibini ezingundoqo, iqhosha ligcinwa njengefayile yesatifikethi nge *.pem ulwandiso. Kule meko, ndiyinike igama wireguard-awskey.pem

Wireguard Inkonzo yeVPN yasimahla kwi-AWS

2.1.8. Isishwankathelo seZiphumo zokuDala iMizekelo

Okulandelayo, sibona umyalezo malunga nokuqaliswa ngempumelelo komzekelo esisandula ukuwudala. Singaya kuluhlu lweemeko zethu ngokucofa iqhosha jonga iimeko

Wireguard Inkonzo yeVPN yasimahla kwi-AWS

2.2. Ukudala idilesi ye-IP yangaphandle

2.2.1. Ukuqala ukudalwa kwe-IP yangaphandle

Emva koko, kufuneka senze idilesi ye-IP yangaphandle esisigxina apho siya kuxhuma kwi-server yethu ye-VPN. Ukwenza oku, kwiphaneli yokukhangela kwicala lasekhohlo lesikrini, khetha into Elastic IPs ukusuka kudidi INEWEKHI & ICANDELO kwaye ucofe iqhosha Nikela idilesi entsha

Wireguard Inkonzo yeVPN yasimahla kwi-AWS

2.2.2. Ukuqwalasela ukudalwa kwe-IP yangaphandle

Kwinqanaba elilandelayo, kufuneka sikwazi ukwenza ukhetho Iphuli yeAmazon (yenziwe ngokuzenzekelayo), kwaye ucofe iqhosha Nikezela

Wireguard Inkonzo yeVPN yasimahla kwi-AWS

2.2.3. Isishwankathelo seziphumo zokwenza idilesi ye-IP yangaphandle

Isikrini esilandelayo siya kubonisa idilesi ye-IP yangaphandle esiyifumene. Kucetyiswa ukuba uyinkqaye, kwaye kungcono nokuba uyibhale phantsi. iya kuba luncedo ngaphezu kweyodwa kwinkqubo yokuseta ngakumbi kunye nokusebenzisa iseva yeVPN. Kwesi sikhokelo, ndisebenzisa idilesi ye-IP njengomzekelo. 4.3.2.1. Wakuba uyifakile idilesi, cofa iqhosha Vala

Wireguard Inkonzo yeVPN yasimahla kwi-AWS

2.2.4. Uluhlu lweedilesi ze-IP zangaphandle

Okulandelayo, sinikwa uluhlu lweedilesi zethu ze-IP ezisisigxina zikawonkewonke (elastics IP).

Wireguard Inkonzo yeVPN yasimahla kwi-AWS

2.2.5. Ukwabela i-IP yangaphandle kwiSimo

Kolu luhlu, sikhetha idilesi ye-IP esiyifumeneyo, kwaye ucinezele iqhosha lasekunene lemouse ukuzisa imenyu eyehlayo. Kuyo, khetha into idilesi yonxulumanoukuyabela kumzekelo esiwudale ngaphambili.

Wireguard Inkonzo yeVPN yasimahla kwi-AWS

2.2.6. Isetingi yesabelo se-IP yangaphandle

Kwinqanaba elilandelayo, khetha umzekelo wethu kuluhlu oluhlayo, kwaye ucinezele iqhosha Nxu lumene

Wireguard Inkonzo yeVPN yasimahla kwi-AWS

2.2.7. Isishwankathelo seZiphumo zeZabelo ze-IP zangaphandle

Emva koko, sinokubona ukuba umzekelo wethu kunye nedilesi yayo yangasese ye-IP ibotshelelwe kwidilesi yethu ye-IP esisigxina.

Wireguard Inkonzo yeVPN yasimahla kwi-AWS

Ngoku sinokuqhagamshela kumzekelo wethu osanda kwenziwa ngaphandle, kwikhompyuter yethu nge-SSH.

3. Qhagamshela kumzekelo we-AWS

SSH yiprothokholi ekhuselekileyo yolawulo olukude lwezixhobo zekhompyuter.

3.1. Ukuqhagamshela nge-SSH kwikhompyuter yeWindows

Ukuqhagamshela kwikhompyuter yeWindows, kufuneka uqale ukhuphele kwaye ufake inkqubo Putty.

3.1.1. Thatha ngaphandle iqhosha labucala lePutty

3.1.1.1. Emva kokufaka iPutty, kufuneka usebenzise into eluncedo yePuTTYgen eza nayo ukungenisa isitshixo sesatifikethi kwifomathi ye-PEM, kwifomathi elungele ukusetyenziswa kwiPutty. Ukwenza oku, khetha into ekwimenyu ephezulu Uguqulo->Isitshixo sokuNgenisa

Wireguard Inkonzo yeVPN yasimahla kwi-AWS

3.1.1.2. Ukukhetha iqhosha le-AWS kwiFomathi yePEM

Emva koko, khetha isitshixo esisigcinileyo ngaphambili kwinqanaba 2.1.7.1, kwimeko yethu igama layo wireguard-awskey.pem

Wireguard Inkonzo yeVPN yasimahla kwi-AWS

3.1.1.3. Ukuseta iinketho eziphambili zokungeniswa

Kule nyathelo, kufuneka sicacise inkcazo yesi sitshixo (inkcazo) kwaye usethe igama eligqithisiweyo kunye nokuqinisekisa ukhuseleko. Iza kucelwa ngalo lonke ixesha uqhagamshela. Ngaloo ndlela, sikhusela isitshixo kunye negama lokugqitha ekusetyenzisweni okungafanelekanga. Akunyanzelekanga ukuba usete igama eligqithisiweyo, kodwa ayikhuselekanga kangako ukuba isitshixo siwela kwizandla ezingalunganga. Emva kokuba sicofa iqhosha Gcina isitshixo sabucala

Wireguard Inkonzo yeVPN yasimahla kwi-AWS

3.1.1.4. Ukugcina isitshixo esithathwe ngaphandle

Ingxoxo yefayile yokugcina ivula kwaye sigcina isitshixo sethu sabucala njengefayile enolwandiso .ppkilungele ukusetyenziswa kudweliso lwenkqubo Putty.
Chaza igama lesitshixo (kwimeko yethu wireguard-awskey.ppk) kwaye cinezela iqhosha Gcina.

Wireguard Inkonzo yeVPN yasimahla kwi-AWS

3.1.2. Ukudala kunye nokuqwalasela umdibaniso kwiPutty

3.1.2.1. Yenza uqhagamshelwano

Vula inkqubo yePutty, khetha udidi iKhusi (ivulwa ngokungagqibekanga) kwaye ebaleni Igama lomamkeli ngenisa idilesi ye-IP yoluntu yomncedisi wethu, esiyifumene kwinqanaba 2.2.3. Endle Iseshoni egciniweyo ngenisa igama elingenasizathu kuqhagamshelo lwethu (kwimeko yam wireguard-aws-london), kwaye ucofe iqhosha Gcina ukugcina utshintsho esilwenzileyo.

Wireguard Inkonzo yeVPN yasimahla kwi-AWS

3.1.2.2. Ukumisela i-autologin yomsebenzisi

Okunye kudidi Uxhumano, khetha udidi Iinkcukacha nasentsimini Ngena ngokuzenzekela igama lomsebenzisi ngenisa igama lomsebenzisi ubun- ngumsebenzisi osemgangathweni womzekelo kwi-AWS enoBuntu.

Wireguard Inkonzo yeVPN yasimahla kwi-AWS

3.1.2.3. Ukukhetha iqhosha labucala lokuqhagamshela nge-SSH

Emva koko uye kuluhlu olungaphantsi Uqhagamshelwano/SSH/Auth nasecaleni kwebala Ifayile yesitshixo yabucala yoqinisekiso cofa iqhosha Dlulisa amehlo ... ukukhetha ifayile enesatifikethi sesitshixo.

Wireguard Inkonzo yeVPN yasimahla kwi-AWS

3.1.2.4. Ukuvula isitshixo esithathwe ngaphandle

Cacisa isitshixo esisingenise ngaphambili kwinyathelo 3.1.1.4, kwimeko yethu yifayile wireguard-awskey.ppk, kwaye ucofe iqhosha Vula.

Wireguard Inkonzo yeVPN yasimahla kwi-AWS

3.1.2.5. Ukugcina useto kwaye uqalise uqhagamshelo

Ukubuyela kwiphepha lodidi iKhusi cofa iqhosha kwakhona Gcina, ukugcina utshintsho esilwenzile ngaphambili kumanyathelo angaphambili (3.1.2.2 - 3.1.2.4). Kwaye ke sicinezela iqhosha vula ukuvula udibaniso olukude lwe-SSH esilwenzileyo saluqwalasela.

Wireguard Inkonzo yeVPN yasimahla kwi-AWS

3.1.2.7. Ukumisela ukuthembana phakathi kwababuki zindwendwe

Kwinqanaba elilandelayo, okokuqala sizama ukudibanisa, sinikwa isilumkiso, asinalo ithemba elimiselweyo phakathi kweekhomputha ezimbini, kwaye sibuza ukuba sithembele kwikhompyutheni ekude. Sicofa iqhosha ukuba, ngokwenza oko idibanisa kuluhlu lweenginginya ezithenjiweyo.

Wireguard Inkonzo yeVPN yasimahla kwi-AWS

3.1.2.8. Ukufaka igama lokugqitha ukufikelela iqhosha

Emva koko, ifestile ye-terminal ivula, apho ubuzwa khona igama eligqithisiweyo leqhosha, ukuba uyibeka ngaphambili kwinqanaba 3.1.1.3. Xa ufaka igama lokugqitha, akukho senzo kwiskrini senzekayo. Ukuba wenza impazamo, ungasebenzisa isitshixo Backspace.

Wireguard Inkonzo yeVPN yasimahla kwi-AWS

3.1.2.9. Umyalezo owamkelekileyo kuqhagamshelo oluyimpumelelo

Emva kokungena ngempumelelo igama eligqithisiweyo, siboniswa isicatshulwa esamkelekileyo kwi-terminal, esisixelela ukuba inkqubo ekude ilungele ukwenza imiyalelo yethu.

Wireguard Inkonzo yeVPN yasimahla kwi-AWS

4. Ukuqwalasela iseva ye-Wireguard

Eyona miyalelo isexesheni yokuhlohla kunye nokusebenzisa i-Wireguard usebenzisa izikripthi ezichazwe ngezantsi inokufumaneka kwindawo yokugcina: https://github.com/isystem-io/wireguard-aws

4.1. Ifakela i-WireGuard

Kwi-terminal, ngenisa le miyalelo ilandelayo (ungakopa kwibhodi eqhotyoshwayo, kwaye uncamathisele kwi-terminal ngokucinezela iqhosha lasekunene lemouse):

4.1.1. Ukuvala indawo yokugcina

Vala uvimba wogcino ngemibhalo yokufakela yeWireguard

git clone https://github.com/pprometey/wireguard_aws.git wireguard_aws

4.1.2. Ukutshintshela kuluhlu lwezikripthi

Yiya kuluhlu olunogcino oluhlanganisiweyo

cd wireguard_aws

4.1.3 Ukusebenzisa iscript sokuqalisa

Baleka njengomlawuli (umsebenzisi wengcambu) i Wireguard yokufakela umbhalo

sudo ./initial.sh

Inkqubo yokuhlohla iyakucela idatha ethile efunekayo ukumisela i-Wireguard

4.1.3.1. Inqaku loqhagamshelo

Ngenisa idilesi ye-IP yangaphandle kwaye uvule izibuko lomncedisi we-Wireguard. Sifumene idilesi ye-IP yangaphandle yomncedisi kwinqanaba le-2.2.3, kwaye savula i-port kwisinyathelo 2.1.5. Sibabonisa kunye, sihlukanise ngekholoni, umzekelo 4.3.2.1:54321uze ucofe iqhosha faka
Isampulu yemveliso:

Enter the endpoint (external ip and port) in format [ipv4:port] (e.g. 4.3.2.1:54321): 4.3.2.1:54321

4.1.3.2. Ukufaka idilesi ye-IP yangaphakathi

Ngenisa idilesi ye-IP yomncedisi we-Wireguard kwi-subnet ye-VPN ekhuselekileyo, ukuba awuyazi ukuba yintoni na, cinezela nje iqhosha elithi Ngena ukuseta ixabiso elingagqibekanga (10.50.0.1)
Isampulu yemveliso:

Enter the server address in the VPN subnet (CIDR format) ([ENTER] set to default: 10.50.0.1):

4.1.3.3. Ichaza iseva yeDNS

Ngenisa idilesi ye-IP yeseva ye-DNS, okanye ucinezele nje u-Enter iqhosha ukuseta ixabiso elingagqibekanga 1.1.1.1 (Cloudflare public DNS)
Isampulu yemveliso:

Enter the ip address of the server DNS (CIDR format) ([ENTER] set to default: 1.1.1.1):

4.1.3.4. Ichaza i-WAN interface

Emva koko, kufuneka ufake igama le-interface yenethiwekhi yangaphandle eya kumamela kwi-interface ye-VPN yangaphakathi. Cinezela nje u-Enter ukuseta ixabiso elingagqibekanga le-AWS (eth0)
Isampulu yemveliso:

Enter the name of the WAN network interface ([ENTER] set to default: eth0):

4.1.3.5. Ichaza igama lomxhasi

Faka igama lomsebenzisi weVPN. Inyani yeyokuba iWireguard VPN iseva ayinakukwazi ukuqalisa de kube kufakwe umxhasi omnye. Kule meko, ndifake igama Alex@mobile
Isampulu yemveliso:

Enter VPN user name: Alex@mobile

Emva koko, ikhowudi ye-QR kunye nokucwangciswa komthengi osanda kufakwa kufuneka iboniswe kwisikrini, ekufuneka ifundwe usebenzisa i-Wireguard iklayenti yeselula kwi-Android okanye i-iOS ukuyiqwalasela. Kwaye kwakhona ngaphantsi kwekhowudi ye-QR, itekisi yefayile yoqwalaselo iya kuboniswa kwimeko yoqwalaselo lwesandla lwabathengi. Indlela yokwenza oku kuya kuxutyushwa ngezantsi.

Wireguard Inkonzo yeVPN yasimahla kwi-AWS

4.2. Ukongeza umsebenzisi omtsha weVPN

Ukongeza umsebenzisi omtsha, kufuneka uphumeze iskripthi kwi-terminal add-client.sh

sudo ./add-client.sh

Umbhalo ucela igama lomsebenzisi:
Isampulu yemveliso:

Enter VPN user name: 

Kwakhona, igama labasebenzisi lingagqithiswa njengeparameter yeskripthi (kule meko Alex@mobile):

sudo ./add-client.sh Alex@mobile

Njengesiphumo sophumezo lweskripthi, kulawulo olunegama lomxhasi ecaleni kwendlela /etc/wireguard/clients/{Π˜ΠΌΡΠšΠ»ΠΈΠ΅Π½Ρ‚Π°} ifayile yoqwalaselo lomxhasi iyakwenziwa /etc/wireguard/clients/{Π˜ΠΌΡΠšΠ»ΠΈΠ΅Π½Ρ‚Π°}/{Π˜ΠΌΡΠšΠ»ΠΈΠ΅Π½Ρ‚Π°}.conf, kwaye isikrini se-terminal siya kubonisa ikhowudi ye-QR yokumisela abaxhasi beselula kunye nemixholo yefayile yoqwalaselo.

4.2.1. Ifayile yoqwalaselo lomsebenzisi

Ungabonisa imixholo yefayile ye .conf kwikhusi, ukwenzela uqwalaselo ngesandla lomxhasi, usebenzisa umyalelo cat

sudo cat /etc/wireguard/clients/Alex@mobile/[email protected]

isiphumo sokwenziwa:

[Interface]
PrivateKey = oDMWr0toPVCvgKt5oncLLRfHRit+jbzT5cshNUi8zlM=
Address = 10.50.0.2/32
DNS = 1.1.1.1

[Peer]
PublicKey = mLnd+mul15U0EP6jCH5MRhIAjsfKYuIU/j5ml8Z2SEk=
PresharedKey = wjXdcf8CG29Scmnl5D97N46PhVn1jecioaXjdvrEkAc=
AllowedIPs = 0.0.0.0/0, ::/0
Endpoint = 4.3.2.1:54321

Inkcazelo yefayile yoqwalaselo lomxhasi:

[Interface]
PrivateKey = ΠŸΡ€ΠΈΠ²Π°Ρ‚Π½Ρ‹ΠΉ ΠΊΠ»ΡŽΡ‡ ΠΊΠ»ΠΈΠ΅Π½Ρ‚Π°
Address = IP адрСс ΠΊΠ»ΠΈΠ΅Π½Ρ‚Π°
DNS = ДНБ ΠΈΡΠΏΠΎΠ»ΡŒΠ·ΡƒΠ΅ΠΌΡ‹ΠΉ ΠΊΠ»ΠΈΠ΅Π½Ρ‚ΠΎΠΌ

[Peer]
PublicKey = ΠŸΡƒΠ±Π»ΠΈΡ‡Π½Ρ‹ΠΉ ΠΊΠ»ΡŽΡ‡ сСрвСра
PresharedKey = ΠžΠ±Ρ‰ΠΈ ΠΊΠ»ΡŽΡ‡ сСрвСра ΠΈ ΠΊΠ»ΠΈΠ΅Π½Ρ‚Π°
AllowedIPs = Π Π°Π·Ρ€Π΅ΡˆΠ΅Π½Π½Ρ‹Π΅ адрСса для ΠΏΠΎΠ΄ΠΊΠ»ΡŽΡ‡Π΅Π½ΠΈΡ (всС -  0.0.0.0/0, ::/0)
Endpoint = IP адрСс ΠΈ ΠΏΠΎΡ€Ρ‚ для ΠΏΠΎΠ΄ΠΊΠ»ΡŽΡ‡Π΅Π½ΠΈΡ

4.2.2. Ikhowudi yeQR yoqwalaselo lomxumi

Ungabonisa ikhowudi ye-QR yoqwalaselo kumxhasi owenziwe ngaphambili kwi-terminal screen usebenzisa umyalelo qrencode -t ansiutf8 (kulo mzekelo, umxhasi ogama linguAlex@mobile uyasetyenziswa):

sudo cat /etc/wireguard/clients/Alex@mobile/[email protected] | qrencode -t ansiutf8

5. Ukuqwalasela abaxhasi beVPN

5.1. Ukumisela umxhasi weselula we-Android

Umxhasi osemthethweni we-Wireguard ye-Android ingaba faka kwiGoogle Play Store esemthethweni

Emva koko, kufuneka ungenise ukucwangciswa ngokufunda ikhowudi ye-QR kunye noqwalaselo lomxhasi (jonga umhlathi 4.2.2) kwaye unike igama:

Wireguard Inkonzo yeVPN yasimahla kwi-AWS

Emva kokungenisa ngempumelelo ubumbeko, unokwenza itonela yeVPN. Uqhagamshelo oluphumeleleyo luya kuboniswa yi-stash engundoqo kwi-tray ye-Android system

Wireguard Inkonzo yeVPN yasimahla kwi-AWS

5.2. Ukuseta umxhasi weWindows

Okokuqala kufuneka ukhuphele kwaye ufake inkqubo TunSafe yeWindows ngumxhasi weWireguard weWindows.

5.2.1. Ukwenza ifayile yoqwalaselo yokungenisa

Cofa ekunene ukwenza ifayile yokubhaliweyo kwidesktop.

Wireguard Inkonzo yeVPN yasimahla kwi-AWS

5.2.2. Khuphela imixholo yefayile yoqwalaselo evela kumncedisi

Emva koko sibuyela kwi-terminal ye-Putty kwaye sibonise imixholo yefayile yoqwalaselo yomsebenzisi oyifunayo, njengoko kuchazwe kwisinyathelo 4.2.1.
Okulandelayo, cofa ekunene umbhalo woqwalaselo kwi-terminal ye-Putty, emva kokuba ukhetho lugqityiwe, luya kukhutshelwa ngokuzenzekelayo kwibhodi eqhotyoshwayo.

Wireguard Inkonzo yeVPN yasimahla kwi-AWS

5.2.3. Ukukhuphela ubumbeko kwifayile yoqwalaselo yendawo

Kulo mmandla, sibuyela kwifayile yokubhaliweyo esiyenzileyo ngaphambili kwidesktop, kwaye uncamathisele okubhaliweyo koqwalaselo kuyo kwibhodi eqhotyoshwayo.

Wireguard Inkonzo yeVPN yasimahla kwi-AWS

5.2.4. Ukugcina ifayile yoqwalaselo yasekuhlaleni

Gcina ifayile kunye nolwandiso .conf (kule meko ibizwa ngegama london.conf)

Wireguard Inkonzo yeVPN yasimahla kwi-AWS

5.2.5. Kuthathwa ngaphandle ifayile yoqwalaselo yasekhaya

Okulandelayo, kufuneka ungenise ifayile yoqwalaselo kwinkqubo yeTunSafe.

Wireguard Inkonzo yeVPN yasimahla kwi-AWS

5.2.6. Ukuseta uqhagamshelo lweVPN

Khetha le fayile yoqwalaselo kwaye uqhagamshele ngokunqakraza iqhosha Dibanisa.
Wireguard Inkonzo yeVPN yasimahla kwi-AWS

6. Ukukhangela ukuba unxibelelwano luphumelele na

Ukujonga impumelelo yoqhagamshelo nge-tunnel ye-VPN, kufuneka uvule isiphequluli kwaye uye kwindawo https://2ip.ua/ru/

Wireguard Inkonzo yeVPN yasimahla kwi-AWS

Idilesi ye-IP ebonisiweyo kufuneka ihambelane naleyo siyifumene kwinqanaba 2.2.3.
Ukuba kunjalo, ke itonela yeVPN isebenza ngempumelelo.

Ukusuka kwi-terminal ye-Linux, ungajonga idilesi yakho ye-IP ngokuchwetheza:

curl http://zx2c4.com/ip

Okanye ungaya kwi-pornhub ukuba useKazakhstan.

umthombo: www.habr.com

Yongeza izimvo