ืืื ืืืึธืื ืืื ืฆื ืืืืื ืืืื ืืขืจืคืึทืจืื ื ืคืื ืงืึทืืืืื ืื ื ื ืขืืืืึธืจืงืก ืืื ืืจืื ืืืฉืืึทืืจืึทืคืืงืื ืืืืึทื ืึทืคึผืึทืจืืืึทื ืฅ, ืืขืืขืจ ืคืื ืืืึธืก ื ืืฆื ืจืึธืืืขืจืก ืืื OpenWRT ืืื ืึท ืืืืืืืื, ืืื ืืืื ืคึผืจืึธืกื ื ืขืฅ. ืืืขื ืืฉืืืื ื ืึท ืืืคึฟื ืคึฟืึทืจ ืงืึทืืืืื ืื ื ื ืขืืืืึธืจืงืก ืฆืืืืฉื L3 ืืื ืกืืื ืขื ืจืืืื ื ืืื L2 ืืื ืืจืืืืฉืื ื, ืืืขื ืึทืืข ื ืขืฅ ื ืึธืืื ืืืขื ืืืื ืืื ืืขืจ ืืขืืืืงืขืจ ืกืืื ืขื, ืืืืขืจืืึทื ื ืืื ืืขืืขืื ืฆื ืื ืจืืข ืืืคึฟื, ืืืึธืก ืืื ืืขืจ ืฉืืืขืจ ืฆื ืงืึทื ืคืืืืขืจ, ืึธืืขืจ ืืื ืืจืขืกืขืจืข ืึทืคึผืขืจืืื ืึทืืื, ืืื ื ืื ืืจืึทื ืกืคึผืขืจืึทื ื ื ืืฆื ืคืื ืืขืงื ืึทืืึทืืืฉืื ืืื ืืขืืืขื ืคึผืืึทื ื ืขื ืืื ืื ื ืขืฅ ืืืึธืก ืืื ืืืฉืืคื Wake-on-Lan ืืื DLNA.
ืืืื 1: ืืื ืืขืจืืจืื ื
OpenVPN ืืื ืืืืืขืก ืืืืกืืขืจืืืืืื ืืื ืืขืจ ืคึผืจืึธืืึธืงืึธื ืคึฟืึทืจ ืืืคึผืืึทืืขื ืื ื ืืขื ืึทืจืืขื, ืืืืึทื, ืขืจืฉืืขืจ, ืขืก ืงืขื ืขื ืืึทืื ืึท ืฆืึทืคึผื ืืืื ืืืึธืก ืงืขื ืขื ืืืื ืืืกืืฃ ืฆื ืื ืืจืืง ืึธื ืคืจืืืืขืืขื, ืืื ืฆืืืืืื ืก, OpenVPN ืฉืืืฆื ืึธืคึผืขืจืึทืฆืืข ืืืืขืจ ืื TCP ืคึผืจืึธืืึธืงืึธื, ืืืึธืก ืืื ืืืื ืืืืืืืง ืืืืึทื ืืึธืจื ืื ืคืื ืื ืึทืคึผืึทืจืืืึทื ืฅ ืืึธืื ืึท ืืขืืึทืงืืืืึทื IP ืึทืืจืขืก, ืืื ืืื ืงืขื ื ืืฉื ื ืืฆื STUN, ืืืืึทื ืืืื ืฉืคึผืืึทืืขืจ ืคึฟืึทืจ ืขืืืขืืข ืกืืื ืืืึทืงืก ืื ืงืึทืืื ื UDP ืงืึทื ืขืงืฉืึทื ื ืคืื ืืืืขืจ ื ืขืืืืึธืจืงืก, ืืฉืขืช ืื ืืงืคึผ ืคึผืจืึธืืึธืงืึธื ืขืจืืืืื ืืืจ ืฆื ืคืึธืจืืืก ืื VPN ืกืขืจืืืขืจ ืคึผืึธืจื ืฆื ืจืขื ืืึทื ืืืคึผืก ื ืืฆื SSH. ืืึธ, ืืขื ืฆืืืึทื ื ืืื ืึท ืืจืืืก ืืึทืกืข, ืืืืึทื ืื ืืึทืื ืืขื ืขื ืื ืงืจืืคึผืืื ืฆืืืื ืืึธื, ืึธืืขืจ ืืื ืืื ื ืืฉื ืืืขืื ืฆื ืืึทืงืขื ืขื ืึท ืืืคึผืก ืืื ืืืื ืคึผืจืืืืึทื ื ืขืฅ, ืืืืึทื ืขืก ืืื ื ืึธื ืึท ืจืืืืงืืจื ืคืื ืืจืื ืคึผืึทืจืืืขืก ืฆื ืืึทืงืืืขื ืงืึธื ืืจืึธื ืืืืขืจ ืขืก, ืืขืจืืืขืจ, ืืื ืึทืืึท ืึท ืืืื ืืืืฃ ืืืื ืืืื ื ืขืฅ ืืื ืืขืืืขื ืืึธืจ ืึทื ืืืืืืจืึทืืึทื ืืื ืขืก ืืื ืืึทืฉืืึธืกื ืฆื ืืึทืฆืึธืื ืคึฟืึทืจ ืืืืขืจืืืื ืืื ืึท ืืจืืืก ืึธืืืืขืจืืขื.
ืฆื ืคืึธืจืืืก ืื ืคึผืึธืจื ืืืืฃ ืื ืจืึทืืืขืจ ืืืืฃ ืืืึธืก ืขืก ืืื ืคึผืืึทื ื ืขื ืฆื ืฆืขืืืืงืืขื ืื ืกืขืจืืืขืจ, ืื sshtunnel ืคึผืจืึธืืจืึทื ืืื ืืขื ืืฆื. ืืื ืืืขื ื ืืฉื ืืึทืฉืจืืึทืื ืื ืื ืืจืึทืงืึทืกืื ืคืื ืืืื ืงืึทื ืคืืืืขืจืืืฉืึทื - ืขืก ืืื ืืึทื ืฅ ืืืืื, ืืื ืืืขื ื ืึธืจ ืืึธื ืึทื ืืืื ืึทืจืืขื ืืื ืืขืืืขื ืฆื ืคืึธืจืืืก TCP ืคึผืึธืจื 1194 ืคึฟืื ืื ืจืึทืืืขืจ ืฆื ืื ืืืคึผืก. ืืขืจื ืึธื, ืื OpenVPN ืกืขืจืืืขืจ ืืื ืงืึทื ืคืืืืขืจื ืืืืฃ ืื tap0 ืืืื ืืืึธืก ืืื ืืขืืืขื ืงืึธื ื ืขืงืืขื ืฆื ืื br-lan ืืจืืง. ื ืึธื ืึธืคึผืืขืฉืืขืื ืื ืคึฟืึทืจืืื ืืื ื ืฆื ืื ื ืื ืืืฉืืคื ืกืขืจืืืขืจ ืคึฟืื ืื ืืึทืคึผืืึทืคึผ, ืขืก ืืื ืืขืืืืจื ืงืืึธืจ ืึทื ืืขืจ ืืขืืึทื ืง ืคืื ืคึผืึธืจื ืคืึธืจืืืขืจืืื ื ืืื ืืขืจืขืืืคืืจืืืงื ืืื ืืืื ืืึทืคึผืืึทืคึผ ืืื ืืขืืืืจื ืึท ืืืืืืื ืคืื ืืขืจ ืจืึทืืืขืจ ื ืขืฅ, ืืึธืืฉ ืขืก ืืื ื ืืฉื ืคืืืืงืื ืืื ืขืก.
ืขืก ืืื ืืืืื ืืืื ืงืืืื ืืึทื ืฆื ืืึธื: ืขืก ืืื ื ืืืืืง ืฆื ืคืึทืจืฉืคึผืจืืืื IP ืึทืืจืขืกืขืก ืืื ืคืึทืจืฉืืืขื ืข ืึทืคึผืึทืจืืืึทื ืฅ ืึทืืื ืึทื ืืื ืืขื ืขื ื ืืฉื ืงืึธื ืคืืืงื ืืื ืงืึทื ืคืืืืขืจ ืื ืจืึธืืืขืจืก ืืื OpenVPN ืงืืืืึทื ืฅ.
ืื ืคืืืืขื ืืข ืจืึทืืืขืจ IP ืึทืืจืขืกืขืก ืืื DHCP ืกืขืจืืืขืจ ืจืืื ืืืฉืึทื ืืขื ืขื ืืืืกืืขืงืืืื:
- 192.168.10.1 ืืื ืงืืื 192.168.10.2 - 192.168.10.80 ืคึฟืึทืจ ืื ืกืขืจืืืขืจ
- 192.168.10.100 ืืื ืงืืื 192.168.10.101 - 192.168.10.149 ืคึฟืึทืจ ืื ืจืึทืืืขืจ ืืื ืืืืื ืื ื ื ืื 2
- 192.168.10.150 ืืื ืงืืื 192.168.10.151 - 192.168.10.199 ืคึฟืึทืจ ืื ืจืึทืืืขืจ ืืื ืืืืื ืื ื ื ืื 3
ืขืก ืืื ืืืื ื ืืืืืง ืฆื ืืึทืฉืืืืขื ืคึผืื ืงื ืื ืึทืืจืขืกืขืก ืฆื ืื ืงืืืขื ื ืจืึธืืืขืจืก ืคืื ืื OpenVPN ืกืขืจืืืขืจ ืืืจื ืึทืืื ื ืื ืฉืืจื ืฆื ืืืื ืงืึทื ืคืืืืขืจืืืฉืึทื:
ifconfig-pool-persist /etc/openvpn/ipp.txt 0
ืืื ืึทืืื ื ืื ืคืืืืขื ืืข ืฉืืจืืช ืฆื ืื /etc/openvpn/ipp.txt ืืขืงืข:
flat1_id 192.168.10.100
flat2_id 192.168.10.150
ืืื flat1_id ืืื flat2_id ืืขื ืขื ืื ืืืื ื ืขืืขื ืกืคึผืขืกืืคืืขื ืืืขื ืงืจืืืืืื ื ืกืขืจืืืคืืงืึทืฅ ืคึฟืึทืจ ืงืึทื ืขืงืืื ื ืฆื OpenVPN
ืืขืจื ืึธื, OpenVPN ืงืืืืึทื ืฅ ืืขื ืขื ืงืึทื ืคืืืืขืจื ืืืืฃ ืื ืจืึธืืืขืจืก, ืืึทืคึผ0 ืืขืืืืกืขืก ืืืืฃ ืืืืืข ืืขื ืขื ืฆืืืขืืขืื ืฆื ืื br-lan ืืจืืง. ืืื ืืขื ืืื ืข, ืึทืืฅ ืกืืื ืฆื ืืืื ืคืืึทื ืืืืึทื ืึทืืข ืืจืื ื ืขืืืืึธืจืงืก ืงืขื ืืขื ืืขืืขืจ ืื ืืขืจืข ืืื ืึทืจืืขื ืืื ืืืื ืขืจ. ืึธืืขืจ, ืึท ื ืื ืืืืขืจ ืึธื ืืขื ืขื ืืขืืึทื ืืืขืจืืืฉื: ืืื ืืขืืืืกืขืก ืงืขื ืืึทืงืืืขื ืึทื IP ืึทืืจืขืก ื ืืฉื ืคึฟืื ืืืืขืจ ืจืึทืืืขืจ, ืืื ืึทืืข ืื ืงืึทื ืกืึทืงืืืขื ืกืึทื. ืคึฟืึทืจ ืขืืืขืืข ืกืืื, ืื ืจืึทืืืขืจ ืืื ืืืื ืขืจ ืคืื ืื ืึทืคึผืึทืจืืืึทื ืฅ ืืื ื ืืฉื ืืึธืื ืฆืืื ืฆื ืจืืกืคึผืึทื ื ืฆื DHCPDISCOVER ืืื ืฆืืื ืืื ืื ืืืื ืืืงืืืขื ืึทื ืึทืืจืขืก ืืืึธืก ืืื ื ืืฉื ืืืขื. ืืื ืืืื ืืขืืขื ืึทื ืืื ืืึทืจืคึฟื ืฆื ืคืืืืขืจ ืึทืืึท ืจืืงืืืขืก ืืื tap0 ืืืืฃ ืืขืืขืจ ืคืื ืื ืจืึธืืืขืจืก, ืึธืืขืจ ืืื ืขืก ืคืืจืงืขืจื ืืืืก, iptables ืงืขื ืขื ื ืืฉื ืึทืจืืขืื ืืื ืื ืืืื ืืืื ืขืก ืืื ืืืื ืคืื ืึท ืืจืืง ืืื ืขืืืึทืืืขืก ืืืื ืงืืืขื ืฆื ืืืื ืืืืฃ. ืฆื ืืืื ืืึทืืืืขืจื, ืขืก ืืื ื ืืฉื ืืื ืืืื ืคืืจืืืืึทืจืข ืืื ืืื ืืื ืฆื ืจืืืืื ืื ืืืืืขืจ ืคึฟืึทืจ ืืขืืขืจ ืืืื. ืืืจื ืืื ืืขื ืืื ืึทืืื ื ืื ืฉืืจืืช ืฆื /etc/rc.local ืคืื ืืขืืขืจ ืจืึทืืืขืจ, ืื ืคึผืจืึธืืืขื ืืื ืกืึทืืืื:
ebtables -A INPUT --in-interface tap0 --protocol ipv4 --ip-protocol udp --ip-destination-port 67:68 -j DROP
ebtables -A INPUT --in-interface tap0 --protocol ipv4 --ip-protocol udp --ip-source-port 67:68 -j DROP
ebtables -A FORWARD --out-interface tap0 --protocol ipv4 --ip-protocol udp --ip-destination-port 67:68 -j DROP
ebtables -A FORWARD --out-interface tap0 --protocol ipv4 --ip-protocol udp --ip-source-port 67:68 -j DROP
ืื ืงืึทื ืคืืืืขืจืืืฉืึทื ืืึทืกืืื ืคึฟืึทืจ ืืจืืึท ืืืจ.
ืืืื 2: ืื ืืจืึธืืืืกืื ื WireGuard
ืืขืฆืื ืก, ืืขื ืืฉื ืืืืฃ ืืขืจ ืืื ืืขืจื ืขืฅ ืืึธืื ืื ืงืจืืกืื ืืื ืื ืืขืืืืื ืฆื ืจืขืื ืืืขืื WireGuard, ืึทืืืืืจืื ื ืื ืคึผืึทืฉืืขืก ืคืื ืืืึทื ืงืึทื ืคืืืืขืจืืืฉืึทื, ืืืื ืืจืึทื ืกืืืกืืข ืืืืงืืึทื, ื ืืืขืจืืง ืคึผืื ื ืืื ืคืึทืจืืืืึทืืืขื ืืืืขืจืืืื. ืืืื ืคึฟืึทืจ ืืขืจ ืืื ืคึฟืึธืจืืึทืฆืืข ืืืขืื ืขืก ืืขืืืื ืขืก ืงืืึธืจ ืึทื ื ืื ืืจืืขืื ืืื ืึท ืืจืืง ืืืืืืื ืืืขืจ ืืจืืขืื ืืืืขืจ ืื TCP ืคึผืจืึธืืึธืงืึธื ืืื ืืขืฉืืืฆื ืืืจื ืขืก, ืืืึธืก ืืขืืืื ืืืจ ืืจืึทืืื ืึทื ืขืก ืืขื ืขื ื ืึธื ืงืืื ืึทืืืขืจื ืึทืืืืืขืก ืฆื OpenVPN ืคึฟืึทืจ ืืืจ. ืืขืจืคึฟืึทืจ ืืึธื ืืื ืึธืคึผืืขืฉืืขืื ืฆื ืืืืกื WireGuard.
ืืื ืขืืืขืืข ืืขื ืฆืืจืืง, ืื ื ืืึทืขืก ืืื ืคืึทืจืฉืคึผืจืืืื ืืืืขืจ ืจืืกืึธืจืกืื ืืื ืืืื ืึธืืขืจ ืื ืืขืจื ืืืขื ืืื ืขืก ืึทื WireGuard ืืขืกืึธืฃ ืืืขื ืืืื ืึทืจืืึทื ืืขืจืขืื ื ืืื ืื ืืื ืืงืก ืงืขืจื, ืกืืึทืจืืื ื ืืื ืืืขืจืกืืข 5.6. ื ืืึทืขืก ืึทืจืืืงืืขื, ืืื ืฉืืขื ืืืง, ืืขืืืืื WireGuard. ืืื ืืืืืขืจ ืคึผืืึทื ืืืฉื ืืื ืื ืืืื ืคึฟืึทืจ ืืืขืื ืฆื ืคืึทืจืืืึทืื ืื ืืื ืึทืื OpenVPN. ืืืก ืืื ืืื ืืขืืืคื ืืื
ืึทืืึธื ืืืืืขืจ, ืืขืจ ืืึทืฉืืืก ืืื ืืขืืืื ืืื ืืืืืืข ืคืื โโืืืขืจืืง ืขื ืงืจืืคึผืฉืึทื, ืืืจื ื ืืฆื VPN ืืืืขืจ VPN ื ืืฆื ืื ืคืืืืขื ืืข ืกืืขืืข:
ืฉืืึทืคึผื XNUMX VPN:
ืืืคึผืก ืืื ืกืขืจืืืขืจ ืืื ืื ืขืจืืขื ืึทืืจืขืก 192.168.30.1
MC ืืื ืงืืืขื ื ืืืคึผืก ืืื ืื ืขืจืืขื ืึทืืจืขืก 192.168.30.2
MK2 ืืื ืงืืืขื ื ืืืคึผืก ืืื ืื ืขืจืืขื ืึทืืจืขืก 192.168.30.3
MK3 ืืื ืงืืืขื ื ืืืคึผืก ืืื ืื ืขืจืืขื ืึทืืจืขืก 192.168.30.4
ืฆืืืืืืข ืืืจืื VPN:
MC ืืื ืกืขืจืืืขืจ ืืื ืคืื ืืจืืืกื ืืืง ืึทืืจืขืก 192.168.30.2 ืืื ืื ืขืจืืขื 192.168.31.1
MK2 ืืื ืงืืืขื ื MC ืืื ืื ืึทืืจืขืก 192.168.30.2 ืืื ืึทื ืื ืขืจืืขื IP 192.168.31.2
MK3 ืืื ืงืืืขื ื MC ืืื ืื ืึทืืจืขืก 192.168.30.2 ืืื ืึทื ืื ืขืจืืขื IP 192.168.31.3
* MC - ืจืึทืืืขืจ ืกืขืจืืืขืจ ืืื ืืืืื ืื ื 1, MK2 - ืจืึทืืืขืจ ืืื ืืืืื ืื ื 2, MK3 - ืจืึทืืืขืจ ืืื ืืืืื ืื ื 3
* ืืืื ืงืึทื ืคืืืืขืจืืืฉืึทื ื ืืขื ืขื ืืจืืืก ืืื ืื ืกืคึผืืืืขืจ ืืื ืื ืกืืฃ ืคืื ืืขื ืึทืจืืืงื.
ืืื ืึทืืื, ืคึผืื ืืก ืืืืคื ืฆืืืืฉื ื ืขืฅ ื ืึธืืื 192.168.31.0/24, ืขืก ืืื ืฆืืื ืฆื ืืึทื ืืืืฃ ืฆื ืืึทืฉืืขืืืงื ืึท GRE ืืื ืขื. ืืืืืขืจ ืืขื, ืึผืื ื ืืฉื ืฆื ืคืึทืจืืืจื ืึทืงืกืขืก ืฆื ืจืึธืืืขืจืก, ืขืก ืืื ืืืขืจื ืฆื ืฉืืขืื SSH ืืึทื ืึทืื ืฆื ืคืึธืจืืืขืจืืื ืคึผืึธืจื 22 ืฆื ืื ืืืคึผืก, ืึทืืื ืึทื, ืืืฉื, ืื ืจืึทืืืขืจ ืคืื ืืืืื ืื ื 10022 ืืืขื ืืืื ืฆืืืจืืืืขื ืืืืฃ ืคึผืึธืจื 2 ืคืื ืื ืืืคึผืก, ืืื ืจืึทืืืขืจ ืคืื ืืืืื ืื ื 11122 ืืืขื ืืืื ืฆืืืจืืืืขื ืืืืฃ ืคึผืึธืจื 3 ืจืึทืืืขืจ ืคืื ืืืืื ืื ื XNUMX. ืขืก ืืื ืืขืกืืขืจ ืฆื ืงืึทื ืคืืืืขืจ ืคืึธืจืืืขืจืืื ื ื ืืฆื ืื ืืขืืืข ืฉืฉืืื ื ืขื, ืืืืึทื ืขืก ืืืขื ืืืงืขืจื ืืขื ืืื ืขื ืืืื ืขืก ืคืืืื.
ืืขืจ ืืื ืขื ืืื ืงืึทื ืคืืืืขืจื, ืืืจ ืงืขื ืขื ืคืึทืจืืื ืื ืฆื SSH ืืืจื ืื ืคืึธืจืืืขืจืืื ืคึผืึธืจื:
ssh root@ะะะ_VPS -p 10022
ืืขืจื ืึธื ืืืจ ืืึธื ืืืกืืืืึทื OpenVPN:
/etc/init.d/openvpn stop
ืืืฆื ืืึธืืืจ ืฉืืขืื ืึท GRE ืืื ืขื ืืืืฃ ืื ืจืึทืืืขืจ ืคึฟืื ืืืืื ืื ื 2:
ip link add grelan0 type gretap remote 192.168.31.1 local 192.168.31.2
ip link set grelan0 up
ืืื ืืืื ืื ืืืฉืืคื ืฆืืืื ื ืฆื ืื ืืจืืง:
brctl addif br-lan grelan0
ืืึธืืืจ ืืืจืืคืืจื ืึท ืขื ืืขื ืคึผืจืึธืฆืขืืืจ ืืืืฃ ืื ืกืขืจืืืขืจ ืจืึทืืืขืจ:
ip link add grelan0 type gretap remote 192.168.31.2 local 192.168.31.1
ip link set grelan0 up
ืืื ืืืื ืืืืื ืื ืืืฉืืคื ืฆืืืื ื ืฆื ืื ืืจืืง:
brctl addif br-lan grelan0
ืกืืึทืจืืื ื ืคืื ืืขื ืืึธืืขื ื, ืคึผืื ืืก ืึธื ืืืืื ืฆื ืืฆืืื ืืืื ืฆื ืื ื ืืึท ื ืขืฅ ืืื ืืื, ืืื ืฆืืคึฟืจืืื ืงืืื, ืืืื ืฆื ืืจืื ืงืขื ืงืึทืืืข. ืืขืจื ืึธื, ืฆื ืึธืคึผืฉืึทืฆื ืืื ืื ื ืขืฅ ืึทืจืืขื ืืืืฃ ืื ืื ืืขืจืข ืกืืฃ ืคืื ืื ืฉืืจื, ืืื ืคึผืจืืืืจื ืฆื SSH ืืื ืืืื ืขืจ ืคืื ืื ืงืึธืืคึผืืืืขืจืก ืืื ืืืืื ืื ื 2, ืึธืืขืจ ืืขืจ ssh ืงืืืขื ื ืคืจืืืื ืึธื ืคึผืจืึทืืคึผืืื ื ืึท ืคึผืึทืจืึธื. ืืื ืคึผืจืึผืืื ืฆื ืคืึทืจืืื ืื ืฆื ืืขื ืงืึธืืคึผืืืืขืจ ืืืจื ืืขืื ืขื ืืืืฃ ืคึผืึธืจื 22 ืืื ืืื ืืขื ืึท ืฉืืจื ืคืื ืืืึธืก ืืื ืงืขื ืขื ืคึฟืึทืจืฉืืืื ืึทื ืื ืงืฉืจ ืืื ืืขืืจืื ืืขื, ืื SSH ืกืขืจืืืขืจ ืจืืกืคึผืึทื ืื, ืึธืืขืจ ืคึฟืึทืจ ืขืืืขืืข ืกืืื ืขืก ื ืึธืจ ื ืืฉื ืคืจืขืื ืืืจ ืฆื ืงืืึธืฅ. ืืื.
$ telnet 192.168.10.110 22
SSH-2.0-OpenSSH_8.1
ืืื ืืื ืืจืืื ื ืฆื ืคืึทืจืืื ืื ืฆื ืขืก ืืืจื VNC ืืื ืืขื ืึท ืฉืืืึทืจืฅ ืคืึทืจืฉืืขืื. ืืื ืืืืขืจืฆืืืื ืืื ืึทื ืื ืคึผืจืึธืืืขื ืืื ืืื ืื ืืืืึทื ืงืึธืืคึผืืืืขืจ, ืืืืึทื ืืื ืงืขื ืขื ืืืืื ืคืึทืจืืื ืื ืฆื ืื ืจืึทืืืขืจ ืคืื ืืขื ืืืืื ืื ื ืืื ืื ืื ืขืจืืขื ืึทืืจืขืก. ืึธืืขืจ, ืืื ืืึทืฉืืืกื ืฆื ืคืึทืจืืื ืื ืฆื ืื SSH ืคืื ืืขื ืงืึธืืคึผืืืืขืจ ืืืจื ืื ืจืึทืืืขืจ ืืื ืืื ืืื ืกืึทืคึผืจืืืื ืฆื ืืขืคึฟืื ืขื ืึทื ืื ืงืฉืจ ืืื ืืขืจืึธืื, ืืื ืื ืืืืึทื ืงืึธืืคึผืืืืขืจ ืึทืจืืขื ืืึทื ืฅ ื ืึธืจืืึทื, ืึธืืขืจ ืขืก ืงืขื ื ืืฉื ืคืึทืจืืื ืื ืฆื ืืืื ืงืึธืืคึผืืืืขืจ.
ืืื ืึทืจืึธืคึผื ืขืืขื ืื ืืจืขืืึทื 0 ืืืื ืคืื ืื ืืจืืง ืืื ืืืืคื OpenVPN ืืืืฃ ืื ืจืึทืืืขืจ ืืื ืืืืื ืื ื 2 ืืื ืืึทืื ืืืืขืจ ืึทื ืื ื ืขืฅ ืึทืจืืขื ืืื ืืขืจืืืึทืจื ืืืืืขืจ ืืื ืื ืงืึทื ืขืงืฉืึทื ื ืืขื ืขื ื ืืฉื ืืจืึทืคึผื. ืืืจื ืืืื ืงืื ืืื ืืืืฃ ืคืืจืืืก ืืืื ืืขื ืืึทืงืืึธืื ืืื ืืืืฃ ืื ืืขืืืข ืคืจืืืืขืืขื, ืืืื ืืขื ืืืขืจื ืจืขืืืืจื ืืืืคืฆืืืขืจื ืืขื MTU. ื ืื ืืืืขืจ ืืขืืืื ืืื ืืขืฉืขื. ืึธืืขืจ, ืืื ืื MTU ืืื ืืขืืืขื ืืึทืฉืืืื ืืืื ืืขื ืื - 7000 ืคึฟืึทืจ ืืจืขืืึทืคึผ ืืขืืืืกืขืก, ืึธืืขืจ ืืจืึทืคึผื ืืงืคึผ ืงืึทื ืขืงืฉืึทื ื ืึธืืขืจ ื ืืืขืจืืง ืึทืจืืืขืจืคืืจื ืจืืืฅ ืืขื ืขื ืืืืขืจืงื. ืจืขืื ืฆื ืืขืจ ืืืื MTU ืคึฟืึทืจ ืืจืขืืึทืคึผ, ืื MTUs ืคึฟืึทืจ Layer 8000 ืืื Layer 7500 WireGuard ืงืึทื ืขืงืฉืึทื ื ืืขื ืขื ืืึทืฉืืืื ืฆื XNUMX ืืื XNUMX ืจืืกืคึผืขืงืืืืืื.
ืืื ืืึธื ืืืจืืืขืงืึธืื ืึทื ืขื ืืขืืข ืกืขืืึทืคึผ ืืืืฃ ืื ืจืึทืืืขืจ ืคึฟืื ืืืืื ืื ื 3, ืืื ืืขืจ ืืืืื ืืืืืง ืืื ืึทื ืึท ืฆืืืืื ืืจืขืืึทืคึผ ืฆืืืื ื ืืขืืืืกื grelan1 ืืื ืฆืืืขืืขืื ืฆื ืื ืกืขืจืืืขืจ ืจืึทืืืขืจ, ืืืึธืก ืืื ืืืื ืฆืืืขืืขืื ืฆื ืื br-lan ืืจืืง.
ืึทืืฅ ืึทืจืืขื. ืืืฆื ืืืจ ืงืขื ืขื ืฉืืขืื ืื ืืจืขืืึทืคึผ ืคึฟืึทืจืืึทืืืื ื ืืื ืกืืึทืจืืึทืคึผ. ืคึฟืึทืจ ืืขื:
ืืื ืฉืืขืื ืื ืฉืืจืืช ืืื /etc/rc.local ืืืืฃ ืื ืจืึทืืืขืจ ืืื ืืืืื ืื ื 2:
ip link add grelan0 type gretap remote 192.168.31.1 local 192.168.31.2
ip link set dev grelan0 mtu 7000
ip link set grelan0 up
brctl addif br-lan grelan0
ืฆืืืขืืขืื ืืขื ืฆื /etc/rc.local ืืืืฃ ืื ืจืึทืืืขืจ ืืื ืืืืื ืื ื 3:
ip link add grelan0 type gretap remote 192.168.31.1 local 192.168.31.3
ip link set dev grelan0 mtu 7000
ip link set grelan0 up
brctl addif br-lan grelan0
ืืื ืืืืฃ ืื ืกืขืจืืืขืจ ืจืึทืืืขืจ:
ip link add grelan0 type gretap remote 192.168.31.2 local 192.168.31.1
ip link set dev grelan0 mtu 7000
ip link set grelan0 up
brctl addif br-lan grelan0
ip link add grelan1 type gretap remote 192.168.31.3 local 192.168.31.1
ip link set dev grelan1 mtu 7000
ip link set grelan1 up
brctl addif br-lan grelan1
ื ืึธื ืจืขืืึธืึธืืื ื ืื ืงืืืขื ื ืจืึธืืืขืจืก, ืืื ืืืกืงืึทืืืขืจื ืึทื ืคึฟืึทืจ ืขืืืขืืข ืกืืื ืืื ืืขื ืขื ื ืืฉื ืงืึทื ืขืงืืื ื ืฆื ืื ืกืขืจืืืขืจ. ื ืึธื ืงืึธื ื ืขืงืืขื ืฆื ืืืืขืจ SSH (ืฆืื ืืืืง, ืืื ืืื ืคืจืืขืจ ืงืึทื ืคืืืืขืจื sshtunnel ืคึฟืึทืจ ืืขื), ืขืก ืืื ืืขืืืขื ืืืกืงืึทืืืขืจื ืึทื WireGuard ืคึฟืึทืจ ืขืืืขืืข ืกืืื ืืื ืืขืืืขื ืงืจืืืืืื ื ืึท ืืึทืจืฉืจืื ืคึฟืึทืจ ืื ืขื ืืคึผืืื ื, ืึธืืขืจ ืขืก ืืื ืคืึทืืฉ. ืึทืืื, ืคึฟืึทืจ 192.168.30.2, ืืขืจ ืืึทืจืฉืจืื ืืืฉ ืืึธื ืึธื ืืขืืืืื ืึท ืืึทืจืฉืจืื ืืืจื ืื pppoe-wan ืฆืืืื ื, ืืึธืก ืืื, ืืืจื ืืขืจ ืืื ืืขืจื ืขืฅ, ืืึธืืฉ ืืขืจ ืืึทืจืฉืจืื ืฆื ืขืก ืืึธื ืืืื ืจืึทืืืื ืืืจื ืื wg0 ืฆืืืื ื. ื ืึธื ืืืืืืื ื ืืขื ืืึทืจืฉืจืื, ืื ืงืฉืจ ืืื ืืขืืื ื. ืืื ืงืขื ื ืืฉื ืืขืคึฟืื ืขื ืืื ืกืืจืืงืฆืืขืก ืขืจืืขืฅ ืืื ืฆื ืฆืืืื ืืขื WireGuard ื ืืฉื ืฆื ืฉืึทืคึฟื ืื ืจืืฅ. ืืขืจืฆื, ืืื ืืื ื ืืฉื ืืคืืื ืคึฟืึทืจืฉืืืื ืฆื ืืึธืก ืืื ืืขืืืขื ืึท ืฉืืจืื ืคืื OpenWRT ืึธืืขืจ WireGuard ืืื. ืึธื ืืึธืื ืฆื ืืึทื ืืืขื ืืื ืืขื ืคึผืจืึธืืืขื ืคึฟืึทืจ ืึท ืืึทื ื ืฆืืึทื, ืืื ืคืฉืื ืฆืืืขืืขืื ืึท ืฉืืจื ืฆื ืืืืืข ืจืึธืืืขืจืก ืืื ืึท ืืืืื ืฉืจืืคื ืืืึธืก ืืืืกืืขืืขืงื ืืขื ืืึทืจืฉืจืื:
route del 192.168.30.2
ืกืึทืืขืจืืืืื ื
ืืื ืืึธืื ื ืืฉื ื ืึธื ืึทืืฉืืืื ืึท ืืึทื ืฅ ืคืึทืจืืึธืื ืคืื OpenVPN, ืืืืึทื ืืื ืืื ืืึทืจืคึฟื ืฆื ืคืึทืจืืื ืื ืฆื ืึท ื ืืึท ื ืขืฅ ืคึฟืื ืึท ืืึทืคึผืืึทืคึผ ืึธืืขืจ ืืขืืขืคืึธื, ืืื ืืึทืฉืืขืืืงื ืึท ืืจืืืึทืคึผ ืืืื ืืืืฃ ืืื ืืื ืืืื ืืืืืขืืืขื, ืึธืืขืจ ืืจืึธืฅ ืืขื, ืืื ืืึธืื ืึท ืืืึทืืข ืืื ืื ืืืืงืืึทื. ืคืื ืืึทืื ืึทืจืืืขืจืคืืจื ืฆืืืืฉื ืึทืคึผืึทืจืืืึทื ืฅ ืืื, ืคึฟืึทืจ ืืืึทืฉืคึผืื, ื ืืฆื VNC ืืื ื ืื ืืขืจ ืืืืึทืงืืืขื. ืคึผืื ื ืืืงืจืืกื ืึท ืืืกื, ืึธืืขืจ ืืขืืืืจื ืืขืจ ืกืืึทืืื:
ืืืขื ื ืืฆื OpenVPN:
[r0ck3r@desktop ~]$ ping -c 20 192.168.10.110
PING 192.168.10.110 (192.168.10.110) 56(84) bytes of data.
64 bytes from 192.168.10.110: icmp_seq=1 ttl=64 time=133 ms
...
64 bytes from 192.168.10.110: icmp_seq=20 ttl=64 time=125 ms
--- 192.168.10.110 ping statistics ---
20 packets transmitted, 20 received, 0% packet loss, time 19006ms
rtt min/avg/max/mdev = 124.722/126.152/136.907/3.065 ms
ืืืขื ื ืืฆื WireGuard:
[r0ck3r@desktop ~]$ ping -c 20 192.168.10.110
PING 192.168.10.110 (192.168.10.110) 56(84) bytes of data.
64 bytes from 192.168.10.110: icmp_seq=1 ttl=64 time=124 ms
...
64 bytes from 192.168.10.110: icmp_seq=20 ttl=64 time=124 ms
--- 192.168.10.110 ping statistics ---
20 packets transmitted, 20 received, 0% packet loss, time 19003ms
rtt min/avg/max/mdev = 123.954/124.423/126.708/0.675 ms
ืขืก ืืื ืืขืจ ืึทืคืขืงืืึทื ืืืจื ืื ืืืื ืคึผืื ื ืฆื ืื VPS, ืืืึธืก ืืื ืืขืขืจืขื 61.5 ืืื
ืึธืืขืจ, ืื ืืืืงืืึทื ืืื ืืขืืืืงืกื ืืืืืืืืง. ืึทืืื, ืืื ืึท ืืืืื ืื ื ืืื ืึท ืกืขืจืืืขืจ ืจืึทืืืขืจ ืืื ืืึธืื ืึท ืืื ืืขืจื ืขื ืคึฟืึทืจืืื ืืื ื ืืืืงืืึทื ืคืื 30 ืืืื / ืกืขืง, ืืื ืืื ืื ืืขืจืข ืึทืคึผืึทืจืืืึทื ืฅ ืขืก ืืื 5 ืืืื / ืกืขืง. ืืื ืืขืจ ืืขืืืืงืขืจ ืฆืืื, ืืฉืขืช ืืื ื ืืฆื OpenVPN, ืืื ืงืขื ื ืืฉื ืืขืจืืจืืืื ืึท ืืึทืื ืึทืจืืืขืจืคืืจื ืืืืงืืึทื ืฆืืืืฉื ื ืขืืืืึธืจืงืก ืคืื ืืขืจ ืืื 3,8 ืืืื / ืกืขืง ืืืื iperf ืจืืืื ืื, ืืฉืขืช WireGuard "ืืืกืืื" ืขืก ืฆื ืื ืืขืืืข 5 ืืืื / ืกืขืง.
WireGuard ืงืึทื ืคืืืืขืจืืืฉืึทื ืืืืฃ VPS[Interface]
Address = 192.168.30.1/24
ListenPort = 51820
PrivateKey = <ะะะะ ะซะขะซะ_ะะะฎะง_ะะะฏ_VPS>
[Peer]
PublicKey = <ะะขะะ ะซะขะซะ_ะะะฎะง_VPN_1_ะะก>
AllowedIPs = 192.168.30.2/32
[Peer]
PublicKey = <ะะขะะ ะซะขะซะ_ะะะฎะง_VPN_2_ะะ2>
AllowedIPs = 192.168.30.3/32
[Peer]
PublicKey = <ะะขะะ ะซะขะซะ_ะะะฎะง_VPN_2_ะะ3>
AllowedIPs = 192.168.30.4/32
WireGuard ืงืึทื ืคืืืืขืจืืืฉืึทื ืืืืฃ MS (ืฆืืืขืืืืื ืฆื /etc/config/ื ืขืืืืึธืจืง)
#VPN ะฟะตัะฒะพะณะพ ััะพะฒะฝั - ะบะปะธะตะฝั
config interface 'wg0'
option proto 'wireguard'
list addresses '192.168.30.2/24'
option private_key 'ะะะะ ะซะขะซะ_ะะะฎะง_VPN_1_ะะก'
option auto '1'
option mtu '8000'
config wireguard_wg0
option public_key 'ะะขะะ ะซะขะซะ_ะะะฎะง_VPN_1_VPS'
option endpoint_port '51820'
option route_allowed_ips '1'
option persistent_keepalive '25'
list allowed_ips '192.168.30.0/24'
option endpoint_host 'IP_ะะะ ะะก_VPS'
#VPN ะฒัะพัะพะณะพ ััะพะฒะฝั - ัะตัะฒะตั
config interface 'wg1'
option proto 'wireguard'
option private_key 'ะะะะ ะซะขะซะ_ะะะฎะง_VPN_2_ะะก'
option listen_port '51821'
list addresses '192.168.31.1/24'
option auto '1'
option mtu '7500'
config wireguard_wg1
option public_key 'ะะขะะ ะซะขะซะ_ะะะฎะง_VPN_2_ะะ2'
list allowed_ips '192.168.31.2'
config wireguard_wg1ip link add grelan0 type gretap remote 192.168.31.1 local 192.168.31.3
option public_key 'ะะขะะ ะซะขะซะ_ะะะฎะง_VPN_2_ะะ3'
list allowed_ips '192.168.31.3'
WireGuard ืงืึทื ืคืืืืขืจืืืฉืึทื ืืืืฃ MK2 (ืฆืืืขืืืืื ืฆื /etc/config/ื ืขืืืืึธืจืง)
#VPN ะฟะตัะฒะพะณะพ ััะพะฒะฝั - ะบะปะธะตะฝั
config interface 'wg0'
option proto 'wireguard'
list addresses '192.168.30.3/24'
option private_key 'ะะะะ ะซะขะซะ_ะะะฎะง_VPN_1_ะะ2'
option auto '1'
option mtu '8000'
config wireguard_wg0
option public_key 'ะะขะะ ะซะขะซะ_ะะะฎะง_VPN_1_VPS'
option endpoint_port '51820'
option persistent_keepalive '25'
list allowed_ips '192.168.30.0/24'
option endpoint_host 'IP_ะะะ ะะก_VPS'
#VPN ะฒัะพัะพะณะพ ััะพะฒะฝั - ะบะปะธะตะฝั
config interface 'wg1'
option proto 'wireguard'
option private_key 'ะะะะ ะซะขะซะ_ะะะฎะง_VPN_2_ะะ2'
list addresses '192.168.31.2/24'
option auto '1'
option listen_port '51821'
option mtu '7500'
config wireguard_wg1
option public_key 'ะะขะะ ะซะขะซะ_ะะะฎะง_VPN_2_ะะก'
option endpoint_host '192.168.30.2'
option endpoint_port '51821'
option persistent_keepalive '25'
list allowed_ips '192.168.31.0/24'
WireGuard ืงืึทื ืคืืืืขืจืืืฉืึทื ืืืืฃ MK3 (ืฆืืืขืืืืื ืฆื /etc/config/ื ืขืืืืึธืจืง)
#VPN ะฟะตัะฒะพะณะพ ััะพะฒะฝั - ะบะปะธะตะฝั
config interface 'wg0'
option proto 'wireguard'
list addresses '192.168.30.4/24'
option private_key 'ะะะะ ะซะขะซะ_ะะะฎะง_VPN_1_ะะ3'
option auto '1'
option mtu '8000'
config wireguard_wg0
option public_key 'ะะขะะ ะซะขะซะ_ะะะฎะง_VPN_1_VPS'
option endpoint_port '51820'
option persistent_keepalive '25'
list allowed_ips '192.168.30.0/24'
option endpoint_host 'IP_ะะะ ะะก_VPS'
#VPN ะฒัะพัะพะณะพ ััะพะฒะฝั - ะบะปะธะตะฝั
config interface 'wg1'
option proto 'wireguard'
option private_key 'ะะะะ ะซะขะซะ_ะะะฎะง_VPN_2_ะะ3'
list addresses '192.168.31.3/24'
option auto '1'
option listen_port '51821'
option mtu '7500'
config wireguard_wg1
option public_key 'ะะขะะ ะซะขะซะ_ะะะฎะง_VPN_2_ะะก'
option endpoint_host '192.168.30.2'
option endpoint_port '51821'
option persistent_keepalive '25'
list allowed_ips '192.168.31.0/24'
ืืื ืื ืืืกืงืจืืืื ืงืึทื ืคืืืืขืจืืืฉืึทื ื ืคึฟืึทืจ ืฆืืืืื-ืืืจืื ืืืคึผื, ืืื ืคืื ื WireGuard ืงืืืืึทื ืฅ ืฆื ืคึผืึธืจื 51821. ืืื ืืขืึธืจืืข, ืืึธืก ืืื ื ืื ื ืืืืืง, ืืื ื ืืขืจ ืงืืืขื ื ืืืขื ืคืึทืจืืืืื ืึท ืงืฉืจ ืคืื ืงืืื ืคืจืื ืึทื ืคึผืจืืืืืืึทืืืฉื ืคึผืึธืจื, ืึธืืขืจ ืืื ืืขืืืื ืขืก ืึทืืื ืึทื ืขืก ืืื ืืขืืืขื ืฆื ืคืึทืจืืืขืจื ืึทืืข ืื ืงืึทืืื ื ืงืึทื ืขืงืฉืึทื ื ืืืืฃ ืื wg0 ืื ืืขืจืคืืืกืื ืคืื ืึทืืข ืจืึธืืืขืจืก ืึทืืืฅ ืื ืงืึทืืื ื UDP ืงืึทื ืขืงืฉืึทื ื ืฆื ืคึผืึธืจื 51821.
ืืื ืืึธืคึฟื ืึทื ืืขืจ ืึทืจืืืงื ืืืขื ืืืื ื ืืฆืืง ืคึฟืึทืจ ืขืืขืฆืขืจ.
ืคึผืก ืืืื, ืืื ืืืืื ืฆื ืืืืื ืืืื ืฉืจืืคื ืืืึธืก ืกืขื ืื ืืืจ ืึท PUSH ืึธื ืืึธื ืฆื ืืืื ืืขืืขืคืึธื ืืื ืื WirePusher ืึทืคึผืืึทืงืืืฉืึทื ืืืขื ืึท ื ืืึทืข ืืืื ืืื ืืจืืืก ืืืืฃ ืืืื ื ืขืฅ. ืืึธ ืืื ืื ืืื ืง ืฆื ืื ืฉืจืืคื:
ืืขืจืืืึทื ืืืงื: ืงืึทื ืคืืืืขืจืืืฉืึทื ืคืื OpenVPN ืกืขืจืืืขืจ ืืื ืงืืืืึทื ืฅ
OpenVPN ืกืขืจืืืขืจ
client-to-client
ca /etc/openvpn/server/ca.crt
cert /etc/openvpn/server/vpn-server.crt
dh /etc/openvpn/server/dh.pem
key /etc/openvpn/server/vpn-server.key
dev tap
ifconfig-pool-persist /etc/openvpn/ipp.txt 0
keepalive 10 60
proto tcp4
server-bridge 192.168.10.1 255.255.255.0 192.168.10.80 192.168.10.254
status /var/log/openvpn-status.log
verb 3
comp-lzo
OpenVPN ืงืืืขื ื
client
tls-client
dev tap
proto tcp
remote VPS_IP 1194 # Change to your router's External IP
resolv-retry infinite
nobind
ca client/ca.crt
cert client/client.crt
key client/client.key
dh client/dh.pem
comp-lzo
persist-tun
persist-key
verb 3
ืืื ืืขืืืืื ื easy-rsa ืฆื ืืืฉืขื ืขืจืืื ืกืขืจืืืคืืงืึทืฅ
ืืงืืจ: www.habr.com