ืคึผืขืจื›ืึธื“ ืก OpenVPN ืื•ื™ืฃ WireGuard ืฆื• ืคึฟืึทืจืื™ื™ื ื™ืงืŸ ื ืขื˜ื•ื•ืึธืจืงืก ืื™ืŸ ืื™ื™ืŸ L2 ื ืขื˜ื•ื•ืึธืจืง

ืคึผืขืจื›ืึธื“ ืก OpenVPN ืื•ื™ืฃ WireGuard ืฆื• ืคึฟืึทืจืื™ื™ื ื™ืงืŸ ื ืขื˜ื•ื•ืึธืจืงืก ืื™ืŸ ืื™ื™ืŸ L2 ื ืขื˜ื•ื•ืึธืจืง

ืื™ืš ื•ื•ืึธืœื˜ ื•ื•ื™ ืฆื• ื˜ื™ื™ืœืŸ ืžื™ื™ืŸ ื“ืขืจืคืึทืจื•ื ื’ ืคื•ืŸ ืงืึทืžื‘ื™ื™ื ื™ื ื’ ื ืขื˜ื•ื•ืึธืจืงืก ืื™ืŸ ื“ืจื™ื™ ื“ื–ืฉื™ืึทื’ืจืึทืคื™ืงืœื™ ื•ื•ื™ื™ึทื˜ ืึทืคึผืึทืจื˜ืžืึทื ืฅ, ื™ืขื“ืขืจ ืคื•ืŸ ื•ื•ืึธืก ื ื™ืฆื˜ ืจืึธื•ื˜ืขืจืก ืžื™ื˜ OpenWRT ื•ื•ื™ ืึท ื’ื™ื™ื˜ื•ื•ื™ื™, ืื™ืŸ ืื™ื™ืŸ ืคึผืจืึธืกื˜ ื ืขืฅ. ื•ื•ืขืŸ ื˜ืฉื•ื–ื™ื ื’ ืึท ืื•ืคึฟืŸ ืคึฟืึทืจ ืงืึทืžื‘ื™ื™ื ื™ื ื’ ื ืขื˜ื•ื•ืึธืจืงืก ืฆื•ื•ื™ืฉืŸ L3 ืžื™ื˜ ืกื•ื‘ื ืขื˜ ืจื•ื˜ื™ื ื’ ืื•ืŸ L2 ืžื™ื˜ ื‘ืจื™ื“ื–ืฉื™ื ื’, ื•ื•ืขืŸ ืึทืœืข ื ืขืฅ ื ืึธื•ื“ื– ื•ื•ืขื˜ ื–ื™ื™ืŸ ืื™ืŸ ื“ืขืจ ื–ืขืœื‘ื™ืงืขืจ ืกื•ื‘ื ืขื˜, ื™ื™ื‘ืขืจื”ืึทื ื˜ ืื™ื– ื’ืขื’ืขื‘ืŸ ืฆื• ื“ื™ ืจื’ืข ืื•ืคึฟืŸ, ื•ื•ืึธืก ืื™ื– ืžืขืจ ืฉื•ื•ืขืจ ืฆื• ืงืึทื ืคื™ื’ื™ืขืจ, ืึธื‘ืขืจ ื’ื™ื˜ ื’ืจืขืกืขืจืข ืึทืคึผืขืจื˜ื•ื ืึทื˜ื™ื–, ื–ื™ื ื˜ ื“ื™ ื˜ืจืึทื ืกืคึผืขืจืึทื ื˜ ื ื•ืฆืŸ ืคื•ืŸ ื˜ืขืงื ืึทืœืึทื“ื–ืฉื™ื– ืื™ื– ื’ืขื•ื•ืขืŸ ืคึผืœืึทื ื ืขื“ ืื™ืŸ ื“ื™ ื ืขืฅ ื•ื•ืึธืก ืื™ื– ื‘ืืฉืืคืŸ Wake-on-Lan ืื•ืŸ DLNA.

ื˜ื™ื™ืœ 1: ื”ื™ื ื˜ืขืจื’ืจื•ื ื˜

ื“ืขืจ ืคึผืจืึธื˜ืึธืงืึธืœ ืื•ื™ืกื’ืขืงืœื™ื‘ืŸ ืฆื• ื“ื•ืจื›ืคื™ืจืŸ ื“ื™ ื“ืึธื–ื™ืงืข ืื•ื™ืคื’ืึทื‘ืข ืื™ื– ื’ืขื•ื•ืขืŸ ืึธื ื”ื™ื™ื‘ OpenVPN, ื•ื•ื™ื™ืœ, ืขืจืฉื˜ื ืก, ืงืขืŸ ืขืก ืฉืึทืคึฟืŸ ืึท ืฆืึทืคึผืŸ-ืึทืคึผืึทืจืึทื˜ ื•ื•ืึธืก ืžืขืŸ ืงืขืŸ ืฆื•ืœื™ื™ื’ืŸ ืฆื•ื ื‘ืจื™ืง ืึธืŸ ืงื™ื™ืŸ ืคึผืจืึธื‘ืœืขืžืขืŸ, ืื•ืŸ ืฆื•ื•ื™ื™ื˜ื ืก, OpenVPN ืขืก ืฉื˜ื™ืฆื˜ TCP, ื•ื•ืึธืก ืื™ื– ืื•ื™ืš ื’ืขื•ื•ืขืŸ ื•ื•ื™ื›ื˜ื™ืง, ื•ื•ื™ื™ืœ ืงื™ื™ืŸ ืื™ื™ื ืข ืคื•ืŸ โ€‹โ€‹ื“ื™ ื“ื™ืจื•ืช ื”ืื˜ ื ื™ืฉื˜ ื’ืขื”ืื˜ ืงื™ื™ืŸ ื‘ืึทื–ื•ื ื“ืขืจืข IP ืึทื“ืจืขืก. ืื™ืš ืงืขืŸ ื ื™ืฉื˜ ื ื•ืฆืŸ STUN ื•ื•ื™ื™ืœ ืžื™ื™ืŸ ISP, ืคึฟืึทืจ ืขืคืขืก ืึท ืกื™ื‘ื”, ื‘ืœืึธืงื™ืจื˜ ืึทืจืฒึทื ืงื•ืžืขื ื“ื™ืงืข UDP ืคึฟืึทืจื‘ื™ื ื“ื•ื ื’ืขืŸ ืคึฟื•ืŸ ืื™ืจืข ื ืขื˜ื•ื•ืึธืจืงืก. TCP ื”ืึธื˜ ืžื™ืจ ื“ืขืจืœื•ื™ื‘ื˜ ืฆื• ืคึฟืึธืจื•ื•ืขืจื“ืŸ ื“ืขื VPN ืกืขืจื•ื•ืขืจ ืคึผืึธืจื˜ ืฆื•ื ื’ืขื“ื™ื ื’ืขื ืขื VPS ื ื™ืฆื ื“ื™ืง SSH. ื›ืึธื˜ืฉ ื“ืขืจ ืฆื•ื’ืึทื ื’ ืฉืึทืคึฟื˜ ืึท ื‘ืึทื“ืฒึทื˜ื ื“ื™ืงืŸ ืึธื•ื•ื•ืขืจื›ืขื“, ื•ื•ื™ื™ืœ ื“ื™ ื“ืึทื˜ืŸ ื–ืขื ืขืŸ ื˜ืึธืคึผืœื˜-ืขื ืงืจื™ืคึผื˜ืขื“, ื”ืึธื‘ ืื™ืš ื ื™ืฉื˜ ื’ืขื•ื•ืึธืœื˜ ืื™ื ื˜ืขื’ืจื™ืจืŸ ื“ืขื VPS ืื™ืŸ ืžื™ื™ืŸ ืคึผืจื™ื•ื•ืึทื˜ืŸ ื ืขื˜ื•ื•ืึธืจืง, ื•ื•ื™ื™ืœ ืขืก ืื™ื– ื’ืขื•ื•ืขืŸ ืึท ืจื™ื–ื™ืงืข ืึทื– ื“ืจื™ื˜ืข ืคึผืึทืจื˜ื™ื™ืขืŸ ื–ืึธืœืŸ ื‘ืึทืงื•ืžืขืŸ ืงืึธื ื˜ืจืึธืœ ืื™ื‘ืขืจ ืื™ื. ื“ืขืจื™ื‘ืขืจ, ื”ืึธื‘ืŸ ืึทื–ืึท ืึท ืžื™ื˜ืœ ืื•ื™ืฃ ืžื™ื™ืŸ ื”ื™ื™ื ื ืขื˜ื•ื•ืึธืจืง ืื™ื– ื’ืขื•ื•ืขืŸ ื–ื™ื™ืขืจ ื ื™ืฉื˜ ื’ืขื•ื•ืื•ื ื˜ืฉืŸ, ืึทื–ื•ื™ ืื™ืš ื”ืึธื‘ ื‘ืึทืฉืœืึธืกืŸ ืฆื• ืฆืึธืœืŸ ืึท ื‘ืึทื“ืฒึทื˜ื ื“ื™ืงืŸ ืึธื•ื•ื•ืขืจื›ืขื“ ืคึฟืึทืจ ื–ื™ื›ืขืจื”ื™ื™ื˜.

ืฆื• ืคืึธืจื•ื•ืขืจื“ืŸ ื“ืขื ืคึผืึธืจื˜ ืื•ื™ืฃ ื“ืขื ืจืึทื•ื˜ืขืจ ื•ื•ืื• ื“ืขืจ ืกืขืจื•ื•ืขืจ ืื™ื– ื’ืขื•ื•ืขืŸ ืคึผืœืึทื ื™ืจื˜ ืฆื• ื•ื•ืขืจืŸ ื“ื™ืคึผืœื•ื™ื™ื“, ื”ืึธื‘ ืื™ืš ื’ืขื ื•ืฆื˜ ื“ื™ sshtunnel ืคึผืจืึธื’ืจืึทื. ืื™ืš ื•ื•ืขืœ ื ื™ืฉื˜ ืึทืจืฒึทื ื’ื™ื™ืŸ ืื™ืŸ ื“ื™ ืคืจื˜ื™ื ืคื•ืŸ ืื™ืจ ืงืึธื ืคื™ื’ื•ืจืึทืฆื™ืข - ืขืก ืื™ื– ื’ืึทื ืฅ ื’ืจื™ื ื’. ืื™ืš ื•ื•ืขืœ ื ืึธืจ ื‘ืึทืžืขืจืงืŸ ืึทื– ืื™ืจ ืฆื•ื•ืขืง ืื™ื– ื’ืขื•ื•ืขืŸ ืฆื• ืคืึธืจื•ื•ืขืจื“ืŸ TCP ืคึผืึธืจื˜ 1194 ืคึฟื•ืŸ ื“ืขื ืจืึทื•ื˜ืขืจ ืฆื•ื VPS. ื“ืขืจื ืึธืš, ื”ืึธื‘ ืื™ืš ืงืึธื ืคื™ื’ื•ืจื™ืจื˜ ื“ืขื ืกืขืจื•ื•ืขืจ. OpenVPN ืื•ื™ืฃ ื“ืขื tap0 ื“ืขื•ื•ื™ื™ืก, ื•ื•ืืก ืื™ื– ื’ืขื•ื•ืขืŸ ืคืืจื‘ื•ื ื“ืŸ ืฆื•ื br-lan ื‘ืจื™ืง. ื ืื›ื“ืขื ื•ื•ืืก ืื™ืš ื”ืื‘ ื’ืขื˜ืขืกื˜ ื“ื™ ืคืืจื‘ื™ื ื“ื•ื ื’ ืฆื•ื ื ื™ื™-ื’ืขืฉืืคืขื ืขื ืกืขืจื•ื•ืขืจ ืคื•ืŸ ืžื™ื™ืŸ ืœืขืคื˜ืืค, ืื™ื– ืขืก ืงืœืืจ ื’ืขื•ื•ืืจืŸ ืื– ื“ื™ ืคืืจื˜ ืคืืจื•ื•ืขืจื“ื™ื ื’ ื’ืขื“ืื ืง ื”ืื˜ ื’ืขืืจื‘ืขื˜, ืื•ืŸ ืžื™ื™ืŸ ืœืขืคื˜ืืค ืื™ื– ื’ืขื•ื•ืืจืŸ ื ืžื™ื˜ื’ืœื™ื“ ืคื•ื ืขื ืจืื•ื˜ืขืจ'ืก ื ืขื˜ื•ื•ืืจืง, ื›ืื˜ืฉ ืขืก ืื™ื– ื ื™ืฉื˜ ื’ืขื•ื•ืขืŸ ืคื™ื–ื™ืฉ ื ื˜ื™ื™ืœ ื“ืขืจืคื•ืŸ.

ื“ืึธืก ืื™ื™ื ืฆื™ืงืข ื•ื•ืึธืก ืื™ื– ื’ืขื‘ืœื™ื‘ืŸ ืฆื• ื˜ืึธืŸ ืื™ื– ื’ืขื•ื•ืขืŸ ืฆื• ืคึฟืึทืจื˜ื™ื™ืœืŸ IP ืึทื“ืจืขืกืŸ ืื™ืŸ ืคึฟืึทืจืฉื™ื“ืขื ืข ื•ื•ื•ื™ื ื•ื ื’ืขืŸ ืึทื–ื•ื™ ืึทื– ื–ื™ื™ ื–ืึธืœืŸ ื ื™ืฉื˜ ืงืึธื ืคืœื™ืงื˜ื™ืจืŸ ืื•ืŸ ืงืึธื ืคึฟื™ื’ื•ืจื™ืจืŸ ื“ื™ ืจืึธื•ื˜ืขืจืก ื•ื•ื™ OpenVPN-ืงืœื™ืขื ื˜ืŸ.
ื“ื™ ืคืืœื’ืขื ื“ืข ืจืึทื•ื˜ืขืจ IP ืึทื“ืจืขืกืขืก ืื•ืŸ DHCP ืกืขืจื•ื•ืขืจ ืจื™ื™ื ื“ื–ืฉืึทื– ื–ืขื ืขืŸ ืื•ื™ืกื’ืขืงืœื™ื‘ืŸ:

  • 192.168.10.1 ืžื™ื˜ ืงื™ื™ื˜ 192.168.10.2 - 192.168.10.80 ืคึฟืึทืจ ื“ื™ ืกืขืจื•ื•ืขืจ
  • 192.168.10.100 ืžื™ื˜ ืงื™ื™ื˜ 192.168.10.101 - 192.168.10.149 ืคึฟืึทืจ ื“ื™ ืจืึทื•ื˜ืขืจ ืื™ืŸ ื•ื•ื•ื™ื ื•ื ื’ ื ื•ืž 2
  • 192.168.10.150 ืžื™ื˜ ืงื™ื™ื˜ 192.168.10.151 - 192.168.10.199 ืคึฟืึทืจ ื“ื™ ืจืึทื•ื˜ืขืจ ืื™ืŸ ื•ื•ื•ื™ื ื•ื ื’ ื ื•ืž 3

ืขืก ืื™ื– ืื•ื™ืš ื’ืขื•ื•ืขืŸ ื ื™ื™ื˜ื™ืง ืฆื• ืฆื•ื˜ื™ื™ืœืŸ ื“ื™ ืึทื“ืจืขืกืŸ ืฆื• ื“ื™ ืงืœื™ืขื ื˜ ืจืึธื•ื˜ืขืจืก. OpenVPN-ืกืขืจื•ื•ืขืจ, ื“ื•ืจืš ืฆื•ืœื™ื™ื’ืŸ ื“ื™ ืคืืœื’ืขื ื“ืข ืฉื•ืจื” ืฆื• ื–ื™ื™ืŸ ืงืื ืคื™ื’ื•ืจืืฆื™ืข:

ifconfig-pool-persist /etc/openvpn/ipp.txt 0

ืื•ืŸ ืึทื“ื™ื ื’ ื“ื™ ืคืืœื’ืขื ื“ืข ืฉื•ืจื•ืช ืฆื• ื“ื™ /etc/openvpn/ipp.txt ื˜ืขืงืข:

flat1_id 192.168.10.100
flat2_id 192.168.10.150

ื•ื•ืื• flat1_id ืื•ืŸ flat2_id ื–ืขื ืขืŸ ื“ื™ ื“ืขื•ื•ื™ื™ืก ื ืขืžืขืŸ ื•ื•ืืก ื–ืขื ืขืŸ ืกืคืขืฆื™ืคื™ืจื˜ ื•ื•ืขืŸ ืžืขืŸ ืฉืืคื˜ ืกืขืจื˜ื™ืคื™ืงืื˜ืŸ ืคืืจืŸ ื–ื™ืš ืคืืจื‘ื™ื ื“ืŸ ืฆื• OpenVPN

ื“ืขืจื ืืš, ื“ื™ ืจืึธื•ื˜ืขืจืก ื–ืขื ืขืŸ ืงืึธื ืคื™ื’ื•ืจื™ืจื˜ ื’ืขื•ื•ืึธืจืŸ OpenVPN- ืงืœื™ืขื ื˜ืŸ, tap0 ื“ืขื•ื•ื™ื™ืกืขืก ืื•ื™ืฃ ื‘ื™ื™ื“ืข ื–ืขื ืขืŸ ืฆื•ื’ืขื’ืขื‘ืŸ ื’ืขื•ื•ืืจืŸ ืฆื•ื br-lan ื‘ืจื™ืง. ืื™ืŸ ื“ืขื ืคื•ื ืงื˜, ื”ืื˜ ืืœืขืก ืื•ื™ืกื’ืขื–ืขืŸ ื’ื•ื˜, ื•ื•ื™ื™ืœ ืืœืข ื“ืจื™ื™ ื ืขื˜ื•ื•ืื•ืจืงืก ื”ืื‘ืŸ ื’ืขืงืขื ื˜ ื–ืขืŸ ืื™ื™ื ืขืจ ื“ืขื ืื ื“ืขืจืŸ ืื•ืŸ ืคื•ื ืงืฆื™ืื ื™ืจืŸ ืืœืก ืื™ื™ืŸ ืื™ื™ื ื”ื™ื™ื˜. ืื‘ืขืจ, ื ื’ืื ืฅ ืื•ืžืื ื’ืขื ืขืžืข ื“ืขื˜ืืœ ืื™ื– ืืจื•ื™ืกื’ืขืงื•ืžืขืŸ: ืžืื chmal ื”ืื‘ืŸ ื“ืขื•ื•ื™ื™ืกืขืก ื‘ืืงื•ืžืขืŸ ืืŸ IP ืื“ืจืขืก ืคื•ืŸ ื“ืขื ืื•ืžืจืขื›ื˜ืŸ ืจืื•ื˜ืขืจ, ืžื™ื˜ ืืœืข ื ืื›ืคืืœื’ื ื“ืข ืงืื ืกืขืงื•ื•ืขื ืฆืŸ. ืคืืจ ืขืคืขืก ื ืกื™ื‘ื”, ื”ืื˜ ื“ืขืจ ืจืื•ื˜ืขืจ ืื™ืŸ ืื™ื™ื ืข ืคื•ืŸ โ€‹โ€‹ื“ื™ ื“ื™ืจื•ืช ื ื™ืฉื˜ ื’ืขืงืขื ื˜ ืจืขืื’ื™ืจืŸ ืฆื• DHCPDISCOVER ืื™ืŸ ืฆื™ื™ื˜, ืื•ืŸ ื“ืขืจ ื“ืขื•ื•ื™ื™ืก ื”ืื˜ ื‘ืืงื•ืžืขืŸ ื“ืขื ืื•ืžืจืขื›ื˜ืŸ ืื“ืจืขืก. ืื™ืš ื”ืื‘ ืื™ื™ื ื’ืขื–ืขืŸ ืื– ืื™ืš ื“ืืจืฃ ืคื™ืœื˜ืขืจืŸ ืื–ืขืœื›ืข ืคืืจืœืื ื’ืขืŸ ืื™ืŸ tap0 ืื•ื™ืฃ ื™ืขื“ืŸ ืจืื•ื˜ืขืจ, ืื‘ืขืจ ื•ื•ื™ ืขืก ื”ืื˜ ื–ื™ืš ืืจื•ื™ืกื’ืขืฉื˜ืขืœื˜, ืงืขื ืขืŸ iptables ื ื™ืฉื˜ ืืจื‘ืขื˜ืŸ ืžื™ื˜ ื ื“ืขื•ื•ื™ื™ืก ืื•ื™ื‘ ืขืก ืื™ื– ื˜ื™ื™ืœ ืคื•ืŸ ื ื‘ืจื™ืง, ื”ืื‘ ืื™ืš ื’ืขื“ืืจืคื˜ ื ื™ืฆืŸ ebtables. ืœื™ื™ื“ืขืจ, ื”ืื˜ ืžื™ื™ืŸ ืคื™ืจืžื•ื•ืขืจ ืขืก ื ื™ืฉื˜ ืืจื™ื™ื ื’ืขื ื•ืžืขืŸ, ื”ืื‘ ืื™ืš ื’ืขื“ืืจืคื˜ ืื™ื‘ืขืจื‘ื•ื™ืขืŸ ื“ื™ ื‘ื™ืœื“ืขืจ ืคืืจ ื™ืขื“ืŸ ื“ืขื•ื•ื™ื™ืก. ื ืื›ื“ืขื ื•ื•ืืก ืื™ืš ื”ืื‘ ื“ืืก ื’ืขื˜ืืŸ ืื•ืŸ ืฆื•ื’ืขืœื™ื™ื’ื˜ ื“ื™ ืคืืœื’ื ื“ืข ืฉื•ืจื•ืช ืฆื• /etc/rc.local ืื•ื™ืฃ ื™ืขื“ืŸ ืจืื•ื˜ืขืจ, ืื™ื– ื“ื™ ืคืจืื‘ืœืขื ื’ืขืœืขื–ื˜ ื’ืขื•ื•ืืจืŸ:

ebtables -A INPUT --in-interface tap0 --protocol ipv4 --ip-protocol udp --ip-destination-port 67:68 -j DROP
ebtables -A INPUT --in-interface tap0 --protocol ipv4 --ip-protocol udp --ip-source-port 67:68 -j DROP
ebtables -A FORWARD --out-interface tap0 --protocol ipv4 --ip-protocol udp --ip-destination-port 67:68 -j DROP
ebtables -A FORWARD --out-interface tap0 --protocol ipv4 --ip-protocol udp --ip-source-port 67:68 -j DROP

ื“ื™ ืงืึทื ืคื™ื’ื™ืขืจื™ื™ืฉืึทืŸ ืœืึทืกื˜ื™ื“ ืคึฟืึทืจ ื“ืจื™ื™ึท ื™ืืจ.

ื˜ื™ื™ืœ 2: ื‘ืึทืงืขื ืขืŸ ื–ื™ืš WireGuard

ืœืขืฆื˜ื ืก ื•ื•ืขืจื˜ ืžืขืจ ื’ืขืจืขื“ื˜ ืื•ื™ืฃ'ืŸ ืื™ื ื˜ืขืจื ืขืฅ ื•ื•ืขื’ืŸ WireGuard, ื‘ืึทื•ื•ืื•ื ื“ืขืจื ื“ื™ืง ื–ืฒึทืŸ ื’ืจื™ื ื’ืงื™ื™ื˜ ืคื•ืŸ ืงืึธื ืคื™ื’ื•ืจืึทืฆื™ืข, ื”ื•ื™ื›ืข ื˜ืจืึทื ืกืคืขืจ ื’ื™ื›ืงื™ื™ื˜, ื ื™ื“ืขืจื™ืงืข ืคื™ื ื’, ืื•ืŸ ืคืึทืจื’ืœืฒึทื›ืœืขื›ืข ื–ื™ื›ืขืจื”ื™ื™ื˜. ื ื–ื•ื›ืขื ื™ืฉ ืคึฟืึทืจ ื ืึธืš ืื™ื ืคึฟืึธืจืžืึทืฆื™ืข ื•ื•ืขื’ืŸ ืื™ื ื”ืึธื˜ ืึทื ื˜ืคึผืœืขืงื˜ ืึทื– ืขืก ืฉื˜ื™ืฆื˜ ื ื™ืฉื˜ ืงื™ื™ืŸ ื‘ืจื™ืง ืžื™ื˜ื’ืœื™ื“ ืึธื“ืขืจ TCP ืคึผืจืึธื˜ืึธืงืึธืœ ืฉื˜ื™ืฆืข, ื•ื•ืึธืก ื”ืึธื˜ ืžื™ืš ื’ืขืคึฟื™ืจื˜ ืฆื• ื’ืœื•ื™ื‘ืŸ ืึทื– ืขืก ืื™ื– ื ื™ืฉื˜ืึธ ืงื™ื™ืŸ ืึทืœื˜ืขืจื ืึทื˜ื™ื•ื•. OpenVPN ืคึฟืึทืจ ืžื™ืจ ืื™ื– ืขืก ื ืึธืš ืึทืœืฅ ื ื™ืฉื˜ ื“ืึธืจื˜. ืึทื–ื•ื™ ืื™ืš ื”ืึธื‘ ืึธืคึผื’ืขืฉื˜ืขืœื˜ ืฆื• ื‘ืึทืงืขื ืขืŸ ื–ื™ืš WireGuard.

ืคืืจ ื ืคืืจ ื˜ืขื’ ืฆื•ืจื™ืง, ื”ืื‘ืŸ ื–ื™ืš ื ื™ื™ืขืก ืคืืจืฉืคืจื™ื™ื˜ ื“ื•ืจืš ืจืขืกื•ืจืกืŸ ืคืืจื‘ื•ื ื“ืŸ ืžื™ื˜ ืื™ื ืคืืจืžืืฆื™ืข ื˜ืขื›ื ืืœืื’ื™ืข ืื•ื™ืฃ ืื™ื™ืŸ ืื“ืขืจ ืื ื“ืขืจืŸ ื•ื•ืขื’, ืื– WireGuard ื•ื•ืขื˜ ืขื ื“ืœืขืš ืืจื™ื™ื ื’ืขืจืขื›ื ื˜ ื•ื•ืขืจืŸ ืื™ืŸ ื“ืขื ืงืขืจื ืขืœ Linux, ืึธื ื”ื™ื™ื‘ื ื“ื™ืง ืžื™ื˜ ื•ื•ืขืจืกื™ืข 5.6. ื ื™ื™ืขืก ืึทืจื˜ื™ืงืœืขืŸ, ื•ื•ื™ ืฉื˜ืขื ื“ื™ืง, ื–ืขื ืขืŸ ื’ืขืœื•ื™ื‘ื˜ ื’ืขื•ื•ืึธืจืŸ. WireGuardืื™ืš ื‘ื™ืŸ ื ืื›ืืžืืœ ืืจื™ื™ื ื’ืขืคืืœืŸ ืื™ืŸ ื–ื•ื›ืŸ ื•ื•ืขื’ืŸ ืฆื• ืคืืจื˜ืจืขื˜ืŸ ื“ืืก ื’ื•ื˜ืข ืืœื˜ืข OpenVPNื“ืืก ืžืึธืœ ื‘ื™ืŸ ืื™ืš ืืจื™ื™ื ื’ืขืœืืคืŸ ืื™ืŸ ื“ืขื ืึทืจื˜ื™ืงืœ. ืขืก ื”ืึธื˜ ื’ืขืจืขื“ื˜ ื•ื•ืขื’ืŸ ืงืจื™ื™ื™ื˜ื™ื ื’ ืึทืŸ ืขื˜ื”ืขืจื ืขื˜ ื˜ื•ื ืขืœ ืื™ื‘ืขืจ L3 ื ื™ืฆืŸ GRE. ื“ืขืจ ืึทืจื˜ื™ืงืœ ื”ืื˜ ืžื™ืจ ื”ืึธืคืขื ื•ื ื’. ืขืก ืื™ื– ื’ืขื‘ืœื™ื‘ืŸ ื•ืžืงืœืึธืจ ื•ื•ืึธืก ืฆื• ื˜ืึธืŸ ืžื™ื˜ ื“ื™ UDP ืคึผืจืึธื˜ืึธืงืึธืœ. ื“ื™ ื–ื•ื›ืŸ ื’ืขืคื™ืจื˜ ืžื™ืจ ืฆื• ืึทืจื˜ื™ืงืœืขืŸ ื•ื•ืขื’ืŸ ื ื™ืฆืŸ ืกืึธืงืึทื˜ ืื™ืŸ ืงืึทื ื“ื–ืฉืึทื ื’ืงืฉืึทืŸ ืžื™ื˜ ืึท SSH ื˜ื•ื ืขืœ ืฆื• ืคืึธืจื•ื™ืก ืึท UDP ืคึผืึธืจื˜, ืึธื‘ืขืจ, ื–ื™ื™ ื‘ืืžืขืจืงื˜ ืึทื– ื“ืขืจ ืฆื•ื’ืึทื ื’ ืึทืจื‘ืขื˜ ื‘ืœื•ื™ื– ืื™ืŸ ืื™ื™ืŸ ืงืฉืจ ืžืึธื“ืข, ื“ืึธืก ืื™ื–, ื“ื™ ืึทืจื‘ืขื˜ ืคื•ืŸ ืขื˜ืœืขื›ืข VPN ืงืœื™ื™ืึทื ืฅ ื•ื•ืึธืœื˜ ื–ื™ื™ืŸ ืื•ืžืžืขื’ืœืขืš. ืื™ืš ื’ืขืงื•ืžืขืŸ ืžื™ื˜ ื“ืขื ื’ืขื“ืึทื ืง ืคื•ืŸ ื™ื ืกื˜ืึธืœื™ื ื’ ืึท ื•ื•ืคึผืŸ ืกืขืจื•ื•ืขืจ ืื•ื™ืฃ ืึท ื•ื•ืคึผืก ืื•ืŸ ื‘ืึทืฉื˜ืขื˜ื™ืงืŸ GRE ืคึฟืึทืจ ืงืœื™ื™ืึทื ืฅ, ืึธื‘ืขืจ ื•ื•ื™ ืขืก ืคืืจืงืขืจื˜ ืื•ื™ืก, GRE ืฉื˜ื™ืฆื˜ ื ื™ืฉื˜ ืขื ืงืจื™ืคึผืฉืึทืŸ, ื•ื•ืึธืก ื•ื•ืขื˜ ืคื™ืจืŸ ืฆื• ื“ื™ ืคืึทืงื˜ ืึทื– ืื•ื™ื‘ ื“ืจื™ื˜ ืคึผืึทืจื˜ื™ืขืก ื‘ืึทืงื•ืžืขืŸ ืึทืงืกืขืก ืฆื• ื“ื™ ืกืขืจื•ื•ืขืจ , ืึทืœืข ืคืึทืจืงืขืจ ืฆื•ื•ื™ืฉืŸ ืžื™ื™ืŸ ื ืขื˜ื•ื•ืึธืจืงืก ื•ื•ืขื˜ ื–ื™ื™ืŸ ืื™ืŸ ื–ื™ื™ืขืจ ื”ืขื ื˜, ื•ื•ืึธืก ื”ืื˜ ื ื™ืฉื˜ ืคึผืึทืกืŸ ืžื™ืจ ื‘ื™ื™ึท ืึทืœืข.

ืึทืžืึธืœ ื•ื•ื™ื“ืขืจ, ื“ืขืจ ื‘ืึทืฉืœื•ืก ืื™ื– ื’ืขืžืื›ื˜ ืื™ืŸ ื˜ื•ื™ื•ื•ืข ืคื•ืŸ โ€‹โ€‹ื™ื‘ืขืจื™ืง ืขื ืงืจื™ืคึผืฉืึทืŸ, ื“ื•ืจืš ื ื™ืฆืŸ VPN ืื™ื‘ืขืจ VPN ื ื™ืฆืŸ ื“ื™ ืคืืœื’ืขื ื“ืข ืกื›ืขืžืข:

ืฉื˜ืึทืคึผืœ XNUMX VPN:
ื•ื•ืคึผืก ืื™ื– ืกืขืจื•ื•ืขืจ ืžื™ื˜ ื™ื ืขืจืœืขืš ืึทื“ืจืขืก 192.168.30.1
MC ืื™ื– ืงืœื™ืขื ื˜ ื•ื•ืคึผืก ืžื™ื˜ ื™ื ืขืจืœืขืš ืึทื“ืจืขืก 192.168.30.2
MK2 ืื™ื– ืงืœื™ืขื ื˜ ื•ื•ืคึผืก ืžื™ื˜ ื™ื ืขืจืœืขืš ืึทื“ืจืขืก 192.168.30.3
MK3 ืื™ื– ืงืœื™ืขื ื˜ ื•ื•ืคึผืก ืžื™ื˜ ื™ื ืขืจืœืขืš ืึทื“ืจืขืก 192.168.30.4

ืฆื•ื•ื™ื™ื˜ืข ืžื“ืจื’ื” VPN:
MC ืื™ื– ืกืขืจื•ื•ืขืจ ืžื™ื˜ ืคื•ื ื“ืจื•ื™ืกื ื“ื™ืง ืึทื“ืจืขืก 192.168.30.2 ืื•ืŸ ื™ื ืขืจืœืขืš 192.168.31.1
MK2 ืื™ื– ืงืœื™ืขื ื˜ MC ืžื™ื˜ ื“ื™ ืึทื“ืจืขืก 192.168.30.2 ืื•ืŸ ืึทืŸ ื™ื ืขืจืœืขืš IP 192.168.31.2
MK3 ืื™ื– ืงืœื™ืขื ื˜ MC ืžื™ื˜ ื“ื™ ืึทื“ืจืขืก 192.168.30.2 ืื•ืŸ ืึทืŸ ื™ื ืขืจืœืขืš IP 192.168.31.3

* MC - ืจืึทื•ื˜ืขืจ ืกืขืจื•ื•ืขืจ ืื™ืŸ ื•ื•ื•ื™ื ื•ื ื’ 1, MK2 - ืจืึทื•ื˜ืขืจ ืื™ืŸ ื•ื•ื•ื™ื ื•ื ื’ 2, MK3 - ืจืึทื•ื˜ืขืจ ืื™ืŸ ื•ื•ื•ื™ื ื•ื ื’ 3
* ืžื™ื˜ืœ ืงืึทื ืคื™ื’ื™ืขืจื™ื™ืฉืึทื ื– ื–ืขื ืขืŸ ืืจื•ื™ืก ืื™ืŸ ื“ื™ ืกืคึผื•ื™ืœืขืจ ืื™ืŸ ื“ื™ ืกื•ืฃ ืคื•ืŸ ื“ืขื ืึทืจื˜ื™ืงืœ.

ืื•ืŸ ืึทื–ื•ื™, ืคึผื™ื ื’ืก ืœื•ื™ืคืŸ ืฆื•ื•ื™ืฉืŸ ื ืขืฅ ื ืึธื•ื“ื– 192.168.31.0/24, ืขืก ืื™ื– ืฆื™ื™ื˜ ืฆื• ืžืึทืš ืื•ื™ืฃ ืฆื• ื‘ืึทืฉื˜ืขื˜ื™ืงืŸ ืึท GRE ื˜ื•ื ืขืœ. ืื™ื™ื“ืขืจ ื“ืขื, ื›ึผื“ื™ ื ื™ืฉื˜ ืฆื• ืคืึทืจืœื™ืจืŸ ืึทืงืกืขืก ืฆื• ืจืึธื•ื˜ืขืจืก, ืขืก ืื™ื– ื•ื•ืขืจื˜ ืฆื• ืฉื˜ืขืœืŸ SSH ื˜ืึทื ืึทืœื– ืฆื• ืคืึธืจื•ื•ืขืจื“ื™ื“ ืคึผืึธืจื˜ 22 ืฆื• ื“ื™ ื•ื•ืคึผืก, ืึทื–ื•ื™ ืึทื–, ืœืžืฉืœ, ื“ื™ ืจืึทื•ื˜ืขืจ ืคื•ืŸ ื•ื•ื•ื™ื ื•ื ื’ 10022 ื•ื•ืขื˜ ื–ื™ื™ืŸ ืฆื•ื˜ืจื™ื˜ืœืขืš ืื•ื™ืฃ ืคึผืึธืจื˜ 2 ืคื•ืŸ ื“ื™ ื•ื•ืคึผืก, ืื•ืŸ ืจืึทื•ื˜ืขืจ ืคื•ืŸ ื•ื•ื•ื™ื ื•ื ื’ 11122 ื•ื•ืขื˜ ื–ื™ื™ืŸ ืฆื•ื˜ืจื™ื˜ืœืขืš ืื•ื™ืฃ ืคึผืึธืจื˜ 3 ืจืึทื•ื˜ืขืจ ืคื•ืŸ ื•ื•ื•ื™ื ื•ื ื’ XNUMX. ืขืก ืื™ื– ื‘ืขืกื˜ืขืจ ืฆื• ืงืึทื ืคื™ื’ื™ืขืจ ืคืึธืจื•ื•ืขืจื“ื™ื ื’ ื ื™ืฆืŸ ื“ื™ ื–ืขืœื‘ืข ืฉืฉื˜ื•ื ื ืขืœ, ื•ื•ื™ื™ึทืœ ืขืก ื•ื•ืขื˜ ื•ืžืงืขืจืŸ ื“ืขื ื˜ื•ื ืขืœ ืื•ื™ื‘ ืขืก ืคื™ื™ืœื–.

ื“ืขืจ ื˜ื•ื ืขืœ ืื™ื– ืงืึทื ืคื™ื’ื™ืขืจื“, ืื™ืจ ืงืขื ืขืŸ ืคืึทืจื‘ื™ื ื“ืŸ ืฆื• SSH ื“ื•ืจืš ื“ื™ ืคืึธืจื•ื•ืขืจื“ื™ื“ ืคึผืึธืจื˜:

ssh root@ะœะžะ™_VPS -p 10022

ื•ื•ื™ื™ื˜ืขืจ ื–ืึธืœืกื˜ื• ืื•ื™ืกืœืขืฉืŸ OpenVPN:

/etc/init.d/openvpn stop

ืื™ืฆื˜ ืœืึธืžื™ืจ ืฉื˜ืขืœืŸ ืึท GRE ื˜ื•ื ืขืœ ืื•ื™ืฃ ื“ื™ ืจืึทื•ื˜ืขืจ ืคึฟื•ืŸ ื•ื•ื•ื™ื ื•ื ื’ 2:

ip link add grelan0 type gretap remote 192.168.31.1 local 192.168.31.2
ip link set grelan0 up

ืื•ืŸ ืœื™ื™ื’ ื“ื™ ื‘ืืฉืืคืŸ ืฆื•ื‘ื™ื ื“ ืฆื• ื“ื™ ื‘ืจื™ืง:

brctl addif br-lan grelan0

ืœืึธืžื™ืจ ื“ื•ืจื›ืคื™ืจืŸ ืึท ืขื ืœืขืš ืคึผืจืึธืฆืขื“ื•ืจ ืื•ื™ืฃ ื“ื™ ืกืขืจื•ื•ืขืจ ืจืึทื•ื˜ืขืจ:

ip link add grelan0 type gretap remote 192.168.31.2 local 192.168.31.1
ip link set grelan0 up

ืื•ืŸ ืื•ื™ืš ืœื™ื™ื’ืŸ ื“ื™ ื‘ืืฉืืคืŸ ืฆื•ื‘ื™ื ื“ ืฆื• ื“ื™ ื‘ืจื™ืง:

brctl addif br-lan grelan0

ืกื˜ืึทืจื˜ื™ื ื’ ืคื•ืŸ ื“ืขื ืžืึธืžืขื ื˜, ืคึผื™ื ื’ืก ืึธื ื”ื™ื™ื‘ืŸ ืฆื• ื”ืฆืœื—ื” ื’ื™ื™ืŸ ืฆื• ื“ื™ ื ื™ื™ึท ื ืขืฅ ืื•ืŸ ืื™ืš, ืžื™ื˜ ืฆื•ืคึฟืจื™ื“ื ืงื™ื™ื˜, ื’ื™ื™ืŸ ืฆื• ื˜ืจื™ื ืงืขืŸ ืงืึทื•ื•ืข. ื“ืขืจื ืึธืš, ืฆื• ืึธืคึผืฉืึทืฆืŸ ื•ื•ื™ ื“ื™ ื ืขืฅ ืึทืจื‘ืขื˜ ืื•ื™ืฃ ื“ื™ ืื ื“ืขืจืข ืกื•ืฃ ืคื•ืŸ ื“ื™ ืฉื•ืจื”, ืื™ืš ืคึผืจื•ื‘ื™ืจืŸ ืฆื• SSH ืื™ืŸ ืื™ื™ื ืขืจ ืคื•ืŸ ื“ื™ ืงืึธืžืคึผื™ื•ื˜ืขืจืก ืื™ืŸ ื•ื•ื•ื™ื ื•ื ื’ 2, ืึธื‘ืขืจ ื“ืขืจ ssh ืงืœื™ืขื ื˜ ืคืจื™ื–ื™ื– ืึธืŸ ืคึผืจืึทืžืคึผื˜ื™ื ื’ ืึท ืคึผืึทืจืึธืœ. ืื™ืš ืคึผืจื•ึผื•ื•ื˜ ืฆื• ืคืึทืจื‘ื™ื ื“ืŸ ืฆื• ื“ืขื ืงืึธืžืคึผื™ื•ื˜ืขืจ ื“ื•ืจืš ื˜ืขืœื ืขื˜ ืื•ื™ืฃ ืคึผืึธืจื˜ 22 ืื•ืŸ ืื™ืš ื–ืขืŸ ืึท ืฉื•ืจื” ืคื•ืŸ ื•ื•ืึธืก ืื™ืš ืงืขื ืขืŸ ืคึฟืึทืจืฉื˜ื™ื™ืŸ ืึทื– ื“ื™ ืงืฉืจ ืื™ื– ื’ืขื’ืจื™ื ื“ืขื˜, ื“ื™ SSH ืกืขืจื•ื•ืขืจ ืจื™ืกืคึผืึทื ื“ื–, ืึธื‘ืขืจ ืคึฟืึทืจ ืขื˜ืœืขื›ืข ืกื™ื‘ื” ืขืก ื ืึธืจ ื ื™ืฉื˜ ืคืจืขื’ืŸ ืžื™ืจ ืฆื• ืงืœืึธืฅ. ืื™ืŸ.

$ telnet 192.168.10.110 22
SSH-2.0-OpenSSH_8.1

ืื™ืš ื‘ื™ืŸ ื˜ืจื™ื™ื ื’ ืฆื• ืคืึทืจื‘ื™ื ื“ืŸ ืฆื• ืขืก ื“ื•ืจืš VNC ืื•ืŸ ื–ืขืŸ ืึท ืฉื•ื•ืึทืจืฅ ืคืึทืจืฉื˜ืขืœืŸ. ืื™ืš ืื™ื‘ืขืจืฆื™ื™ื’ืŸ ื–ื™ืš ืึทื– ื“ื™ ืคึผืจืึธื‘ืœืขื ืื™ื– ืžื™ื˜ ื“ื™ ื•ื•ื™ื™ึทื˜ ืงืึธืžืคึผื™ื•ื˜ืขืจ, ื•ื•ื™ื™ึทืœ ืื™ืš ืงืขื ืขืŸ ืœื™ื™ื›ื˜ ืคืึทืจื‘ื™ื ื“ืŸ ืฆื• ื“ื™ ืจืึทื•ื˜ืขืจ ืคื•ืŸ ื“ืขื ื•ื•ื•ื™ื ื•ื ื’ ืžื™ื˜ ื“ื™ ื™ื ืขืจืœืขืš ืึทื“ืจืขืก. ืึธื‘ืขืจ, ืื™ืš ื‘ืึทืฉืœื™ืกืŸ ืฆื• ืคืึทืจื‘ื™ื ื“ืŸ ืฆื• ื“ื™ SSH ืคื•ืŸ ื“ืขื ืงืึธืžืคึผื™ื•ื˜ืขืจ ื“ื•ืจืš ื“ื™ ืจืึทื•ื˜ืขืจ ืื•ืŸ ืื™ืš ื‘ื™ืŸ ืกืึทืคึผืจื™ื™ื–ื“ ืฆื• ื’ืขืคึฟื™ื ืขืŸ ืึทื– ื“ื™ ืงืฉืจ ืื™ื– ื’ืขืจืึธื˜ืŸ, ืื•ืŸ ื“ื™ ื•ื•ื™ื™ึทื˜ ืงืึธืžืคึผื™ื•ื˜ืขืจ ืึทืจื‘ืขื˜ ื’ืึทื ืฅ ื ืึธืจืžืึทืœ, ืึธื‘ืขืจ ืขืก ืงืขืŸ ื ื™ืฉื˜ ืคืึทืจื‘ื™ื ื“ืŸ ืฆื• ืžื™ื™ืŸ ืงืึธืžืคึผื™ื•ื˜ืขืจ.

ืื™ืš ื ืขืขื ืืจื•ื™ืก ื“ืขื grelan0 ื“ืขื•ื•ื™ื™ืก ืคื•ื ืขื ื‘ืจื™ืง ืื•ืŸ ืœืื– ืขืก ืœื•ื™ืคืŸ OpenVPN ืื•ื™ืคืŸ ืจืื•ื˜ืขืจ ืื™ืŸ ื“ื™ืจื” 2, ื”ืื‘ ืื™ืš ื‘ืืฉื˜ืขื˜ื™ืงื˜ ืื– ื“ื™ ื ืขืฅ ืืจื‘ืขื˜ ื•ื•ื™ื“ืขืจ ืจื™ื›ื˜ื™ื’ ืื•ืŸ ื“ื™ ืงืื ืขืงืฉืื ืก ืคืืœืŸ ื ื™ืฉื˜ ืืค. ื–ื•ื›ืขื ื“ื™ื’, ื‘ื™ืŸ ืื™ืš ื’ืขื˜ืจืืคืŸ ืคืืจื•ืžืก ื•ื•ืื• ืžืขื ื˜ืฉืŸ ื”ืื‘ืŸ ื–ื™ืš ื‘ืืงืœืื’ื˜ ืื•ื™ืฃ ื“ื™ ื–ืขืœื‘ืข ืคืจืื‘ืœืขืžืขืŸ, ืื•ืŸ ื•ื•ืื• ืžืขืŸ ื”ืื˜ ื–ื™ื™ ื’ืขืจืื˜ืŸ ืฆื• ื”ืขื›ืขืจืŸ ื“ื™ MTU. ืงื•ื™ื ื’ืขื–ืื’ื˜ ื•ื•ื™ ื’ืขื˜ืืŸ. ืื‘ืขืจ, ื‘ื™ื– ื“ื™ MTU ืื™ื– ื’ืขื•ื•ืขืŸ ื’ืขืฉื˜ืขืœื˜ ื”ื•ื™ืš ื’ืขื ื•ื’ - 7000 ืคืืจ ื’ืจืขื˜ืืค ื“ืขื•ื•ื™ื™ืกืขืก - ื”ืื‘ ืื™ืš ื“ืขืจืคืืจืŸ ืื“ืขืจ ืคืืจืœื•ื™ืจืขื ืข TCP ืงืื ืขืงืฉืื ืก ืื“ืขืจ ื ื™ื“ืขืจื™ื’ืข ื˜ืจืื ืกืคืขืจ ื’ื™ื›ืงื™ื™ื˜ืŸ. ืฆื•ืœื™ื‘ ื“ื™ ื”ื•ื™ื›ืข MTU ืคืืจ ื’ืจืขื˜ืืค, ื“ื™ MTU ืคืืจ ืงืื ืขืงืฉืื ืก... WireGuard ื“ื™ ืขืจืฉื˜ืข ืื•ืŸ ืฆื•ื•ื™ื™ื˜ืข ืœืขื•ื•ืขืœืก ื–ืขื ืขืŸ ื‘ืึทืฉื˜ื™ืžื˜ ื’ืขื•ื•ืึธืจืŸ ืื•ื™ืฃ 8000 ืื•ืŸ 7500 ื‘ื”ืชืืžื”.

ืื™ืš ื”ืึธื‘ ื“ื•ืจื›ื’ืขืงืึธื›ื˜ ืึทืŸ ืขื ืœืขื›ืข ืกืขื˜ืึทืคึผ ืื•ื™ืฃ ื“ื™ ืจืึทื•ื˜ืขืจ ืคึฟื•ืŸ ื•ื•ื•ื™ื ื•ื ื’ 3, ืžื™ื˜ ื“ืขืจ ื‘ืœื•ื™ื– ื—ื™ืœื•ืง ืื™ื– ืึทื– ืึท ืฆื•ื•ื™ื™ื˜ ื’ืจืขื˜ืึทืคึผ ืฆื•ื‘ื™ื ื“ ื’ืขื”ื™ื™ืกืŸ grelan1 ืื™ื– ืฆื•ื’ืขื’ืขื‘ืŸ ืฆื• ื“ื™ ืกืขืจื•ื•ืขืจ ืจืึทื•ื˜ืขืจ, ื•ื•ืึธืก ืื™ื– ืื•ื™ืš ืฆื•ื’ืขื’ืขื‘ืŸ ืฆื• ื“ื™ br-lan ื‘ืจื™ืง.

ืึทืœืฅ ืึทืจื‘ืขื˜. ืื™ืฆื˜ ืื™ืจ ืงืขื ืขืŸ ืฉื˜ืขืœืŸ ื“ื™ ื’ืจืขื˜ืึทืคึผ ืคึฟืึทืจื–ืึทืžืœื•ื ื’ ืื™ืŸ ืกื˜ืึทืจื˜ืึทืคึผ. ืคึฟืึทืจ ื“ืขื:

ืื™ืš ืฉื˜ืขืœืŸ ื“ื™ ืฉื•ืจื•ืช ืื™ืŸ /etc/rc.local ืื•ื™ืฃ ื“ื™ ืจืึทื•ื˜ืขืจ ืื™ืŸ ื•ื•ื•ื™ื ื•ื ื’ 2:

ip link add grelan0 type gretap remote 192.168.31.1 local 192.168.31.2
ip link set dev grelan0 mtu 7000
ip link set grelan0 up
brctl addif br-lan grelan0

ืฆื•ื’ืขื’ืขื‘ืŸ ื“ืขื ืฆื• /etc/rc.local ืื•ื™ืฃ ื“ื™ ืจืึทื•ื˜ืขืจ ืื™ืŸ ื•ื•ื•ื™ื ื•ื ื’ 3:

ip link add grelan0 type gretap remote 192.168.31.1 local 192.168.31.3
ip link set dev grelan0 mtu 7000
ip link set grelan0 up
brctl addif br-lan grelan0

ืื•ืŸ ืื•ื™ืฃ ื“ื™ ืกืขืจื•ื•ืขืจ ืจืึทื•ื˜ืขืจ:

ip link add grelan0 type gretap remote 192.168.31.2 local 192.168.31.1
ip link set dev grelan0 mtu 7000
ip link set grelan0 up
brctl addif br-lan grelan0

ip link add grelan1 type gretap remote 192.168.31.3 local 192.168.31.1
ip link set dev grelan1 mtu 7000
ip link set grelan1 up
brctl addif br-lan grelan1

ื ืื›ื“ืขื ื•ื•ืืก ืื™ืš ื”ืื‘ ืจื™ืกื˜ืืจื˜ ื“ื™ ืงืœื™ืขื ื˜ ืจืื•ื˜ืขืจืก, ื”ืื‘ ืื™ืš ืื ื˜ื“ืขืงื˜ ืื– ืคืืจ ืขืคืขืก ื ืกื™ื‘ื” ื”ืื‘ืŸ ื–ื™ื™ ื–ื™ืš ื ื™ืฉื˜ ืคืืจื‘ื•ื ื“ืŸ ืฆื•ื ืกืขืจื•ื•ืขืจ. ื ืื›ื“ืขื ื•ื•ืืก ืื™ืš ื”ืื‘ ื–ื™ืš ืคืืจื‘ื•ื ื“ืŸ ืฆื• ื–ื™ื™ืขืจ SSH (ืฆื•ืž ื’ืœื™ืง, ื”ืื‘ ืื™ืš ืคืจื™ืขืจ ืงืื ืคื™ื’ื•ืจื™ืจื˜ sshtunnel ื“ืขืจืคืืจ), ื”ืื‘ ืื™ืš ืื ื˜ื“ืขืงื˜ ืื– WireGuard ืคึฟืึทืจ ืขืคืขืก ืึท ืกื™ื‘ื”, ืฉืึทืคึฟื˜ ืขืก ืึท ืจื•ื˜ ืคึฟืึทืจ ื“ืขื ืขื ื“ืคึผื•ื ืงื˜, ืึธื‘ืขืจ ืขืก ืื™ื– ื ื™ืฉื˜ ืจื™ื›ื˜ื™ืง. ืœืžืฉืœ, ืคึฟืึทืจ 192.168.30.2, ื”ืึธื˜ ื“ื™ ืจื•ื˜ ื˜ืึทื‘ืขืœืข ืกืคึผืขืฆื™ืคึฟื™ืฆื™ืจื˜ ืึท ืจื•ื˜ ื“ื•ืจืš ื“ืขื pppoe-wan ืื™ื ื˜ืขืจืคึฟื™ื™ืก, ื“.ื”. ื“ื•ืจืš ื“ืขื ืื™ื ื˜ืขืจื ืขื˜, ื›ืึธื˜ืฉ ื“ืขืจ ืจื•ื˜ ืฆื• ืื™ื ื–ืึธืœ ื”ืึธื‘ืŸ ื’ืขืคื™ืจื˜ ื’ืขื•ื•ืึธืจืŸ ื“ื•ืจืš ื“ืขื wg0 ืื™ื ื˜ืขืจืคึฟื™ื™ืก. ื ืึธืš ื“ืขื ื•ื•ื™ ืื™ืš ื”ืึธื‘ ืื•ื™ืกื’ืขืžืขืงื˜ ื“ืขื ืจื•ื˜, ืื™ื– ื“ื™ ืคึฟืึทืจื‘ื™ื ื“ื•ื ื’ ืฆื•ืจื™ืงื’ืขืฉื˜ืขืœื˜ ื’ืขื•ื•ืึธืจืŸ. ืงืขืŸ ืื™ืš ื’ืขืคึฟื™ื ืขืŸ ืื™ื ืกื˜ืจื•ืงืฆื™ืขืก ืขืจื’ืขืฅ ื•ื•ื™ ืึทื–ื•ื™ ืฆื• ืฆื•ื•ื™ื ื’ืขืŸ WireGuard ืื™ืš ื”ืึธื‘ ื ื™ืฉื˜ ื’ืขืงืขื ื˜ ืื•ื™ืกืžื™ื™ื“ืŸ ืฆื• ืฉืึทืคึฟืŸ ื“ื™ ืจื•ื˜ืขืก. ื“ืขืจืฆื•, ื”ืึธื‘ ืื™ืš ื ื™ื˜ ืึทืคึฟื™ืœื• ืคึฟืึทืจืฉื˜ืึทื ืขืŸ ืฆื™ ื“ืึธืก ืื™ื– ืึท ืคึฟื•ื ืงืฆื™ืข ืคึฟื•ืŸ OpenWRT ืฆื™ ืคึฟื•ืŸ ื“ื™ WireGuardืึธืŸ ืฆื• ืคึฟืึทืจื‘ืจืขื ื’ืขืŸ ืึท ืกืš ืฆืฒึทื˜ ืฆื• ืคึฟืึทืจืฉื˜ื™ื™ืŸ ื“ืึธืก ืคึผืจืึธื‘ืœืขื, ื”ืึธื‘ ืื™ืš ืคืฉื•ื˜ ืฆื•ื’ืขื’ืขื‘ืŸ ืึท ืฉื•ืจื” ืฆื•ื ื˜ืฒึทืžืขืจ-ืœื•ืคึผ ืกืงืจื™ืคึผื˜ ืื•ื™ืฃ ื‘ื™ื™ื“ืข ืจืึธื•ื˜ืขืจืก ื•ื•ืึธืก ื”ืึธื‘ืŸ ืื•ื™ืกื’ืขืžืขืงื˜ ื“ืขื ืจื•ื˜:

route del 192.168.30.2

ืกืึทืžืขืจื™ื™ื–ื™ื ื’

ื’ืึทื ืฅ ืึธืคึผื•ื•ืึทืจืฃ OpenVPN ืื™ืš ื”ืื‘ ื“ืืก ื ืื›ื ื™ืฉื˜ ื“ืขืจื’ืจื™ื™ื›ื˜, ื•ื•ื™ื™ืœ ืื™ืš ื“ืืจืฃ ืžืื chmal ื–ื™ืš ืคืืจื‘ื™ื ื“ืŸ ืฆื• ื ื ื™ื™ืขื ื ืขื˜ื•ื•ืืจืง ืคื•ืŸ ื ืœืขืคื˜ืืค ืื“ืขืจ ื˜ืขืœืขืคืืŸ, ืื•ืŸ ืื•ื™ืคืฉื˜ืขืœืŸ ื ื’ืจืขื˜ืืคึผ ื“ืขื•ื•ื™ื™ืก ืื•ื™ืฃ ื–ื™ื™ ืื™ื– ื‘ื›ืœืœ ื ื™ืฉื˜ ืžืขื’ืœืขืš. ืื‘ืขืจ, ื˜ืจืืฅ ื“ืขื, ื”ืื‘ ืื™ืš ื‘ืืงื•ืžืขืŸ ื ืคืืจื˜ื™ื™ืœ ืื™ืŸ ื“ืื˜ืŸ ื˜ืจืื ืกืคืขืจ ื’ื™ื›ืงื™ื™ื˜ ืฆื•ื•ื™ืฉืŸ ื“ื™ืจื•ืช, ืื•ืŸ ื ื™ืฆืŸ VNC, ืœืžืฉืœ, ืื™ื– ื™ืขืฆื˜ ืืŸ ืงื™ื™ืŸ ืคืจืื‘ืœืขืžืขืŸ. ืคื™ื ื’ ืื™ื– ืื‘ื™ืกืœ ื’ืขืคืืœืŸ ืื‘ืขืจ ืื™ื– ื’ืขื•ื•ืืจืŸ ืžืขืจ ืกื˜ืื‘ื™ืœ:

ื•ื•ืขืŸ ื ื™ืฆืŸ OpenVPN:

[r0ck3r@desktop ~]$ ping -c 20 192.168.10.110
PING 192.168.10.110 (192.168.10.110) 56(84) bytes of data.
64 bytes from 192.168.10.110: icmp_seq=1 ttl=64 time=133 ms
...
64 bytes from 192.168.10.110: icmp_seq=20 ttl=64 time=125 ms

--- 192.168.10.110 ping statistics ---
20 packets transmitted, 20 received, 0% packet loss, time 19006ms
rtt min/avg/max/mdev = 124.722/126.152/136.907/3.065 ms

ื•ื•ืขืŸ ื ื™ืฆืŸ WireGuard:

[r0ck3r@desktop ~]$ ping -c 20 192.168.10.110
PING 192.168.10.110 (192.168.10.110) 56(84) bytes of data.
64 bytes from 192.168.10.110: icmp_seq=1 ttl=64 time=124 ms
...
64 bytes from 192.168.10.110: icmp_seq=20 ttl=64 time=124 ms
--- 192.168.10.110 ping statistics ---
20 packets transmitted, 20 received, 0% packet loss, time 19003ms
rtt min/avg/max/mdev = 123.954/124.423/126.708/0.675 ms

ืขืก ืื™ื– ืžืขืจ ืึทืคืขืงื˜ืึทื“ ื“ื•ืจืš ื“ื™ ื”ื•ื™ืš ืคึผื™ื ื’ ืฆื• ื“ื™ VPS, ื•ื•ืึธืก ืื™ื– ื‘ืขืขืจืขืš 61.5 ืžื™ื–

ืื‘ืขืจ, ื“ื™ ืฉื ืขืœืงื™ื™ื˜ ื”ืื˜ ื–ื™ืš ื‘ืื“ื™ื™ื˜ื ื“ ืคืืจื’ืจืขืกืขืจื˜. ืื–ื•ื™, ืื™ืŸ ื“ืขืจ ื•ื•ืื•ื™ื ื•ื ื’ ืžื™ื˜ืŸ ืจืื•ื˜ืขืจ-ืกืขืจื•ื•ืขืจ, ื”ืื‘ ืื™ืš ืืŸ ืื™ื ื˜ืขืจื ืขื˜ ืงืื ืขืงืฉืืŸ ืฉื ืขืœืงื™ื™ื˜ ืคื•ืŸ 30 ืžืขื’ืื‘ื™ื˜ืกื‘ื™ื˜, ืื•ืŸ ืื™ืŸ ื“ื™ ืื ื“ืขืจืข ื•ื•ืื•ื™ื ื•ื ื’ืขืŸ ืื™ื– ืขืก 5 ืžืขื’ืื‘ื™ื˜ืกื‘ื™ื˜. ื“ืขืจืฆื•, ื‘ืขืชืŸ ื‘ืื ื•ืฅ OpenVPN ืื™ืš ื‘ื™ืŸ ื ื™ืฉื˜ ื’ืขื•ื•ืขืŸ ื‘ื™ื›ื•ืœืช ืฆื• ื“ืขืจื’ืจื™ื™ื›ืŸ ื ื“ืื˜ืŸ ื˜ืจืื ืกืคืขืจ ื’ื™ื›ืงื™ื™ื˜ ืฆื•ื•ื™ืฉืŸ ื ืขื˜ื•ื•ืึธืจืงืก ื’ืจืขืกืขืจ ื•ื•ื™ 3,8 Mbps ืœื•ื™ื˜ iperf ืœื™ื™ืขื ื•ื ื’ืขืŸ, ื‘ืฉืขืช WireGuard "ื’ืขืคืืžืคืขื˜" ืขืก ืืจื•ื™ืฃ ืฆื• ื“ื™ ื–ืขืœื‘ืข 5 ืžืขื‘ื™ื˜/ืกืขืง.

ืงืึธื ืคื™ื’ื•ืจืึทื˜ื™ืึธืŸ WireGuard ืื•ื™ืฃ VPS[Interface]
Address = 192.168.30.1/24
ListenPort = 51820
PrivateKey = <ะ—ะะšะ ะซะขะซะ™_ะšะ›ะฎะง_ะ”ะ›ะฏ_VPS>

[ื™ื™ึทื ืงื•ืงื  ื–ื™ืš]
ืคื•ื‘ืœื™ืง ืงื™ = <VPN_1_MS_PUBLIC_KEY>
ืึทืœืœืึธื•ื•ืขื“ื™ืคึผืก = 192.168.30.2/32

[ื™ื™ึทื ืงื•ืงื  ื–ื™ืš]
ืคื•ื‘ืœื™ืง ืงื™ = <VPN_2_MK2_PUBLIC_KEY>
ืึทืœืœืึธื•ื•ืขื“ื™ืคึผืก = 192.168.30.3/32

[ื™ื™ึทื ืงื•ืงื  ื–ื™ืš]
ืคื•ื‘ืœื™ืง ืงื™ = <VPN_2_MK3_PUBLIC_KEY>
ืึทืœืœืึธื•ื•ืขื“ื™ืคึผืก = 192.168.30.4/32

ืงืึธื ืคื™ื’ื•ืจืึทื˜ื™ืึธืŸ WireGuard ืื•ื™ืฃ MS (ืฆื•ื’ืขืœื™ื™ื’ื˜ ืฆื• /etc/config/network)

#VPN ะฟะตั€ะฒะพะณะพ ัƒั€ะพะฒะฝั - ะบะปะธะตะฝั‚
config interface 'wg0'
        option proto 'wireguard'
        list addresses '192.168.30.2/24'
        option private_key 'ะ—ะะšะ ะซะขะซะ™_ะšะ›ะฎะง_VPN_1_ะœะก'
        option auto '1'
        option mtu '8000'

config wireguard_wg0
        option public_key 'ะžะขะšะ ะซะขะซะ™_ะšะ›ะฎะง_VPN_1_VPS'
        option endpoint_port '51820'
        option route_allowed_ips '1'
        option persistent_keepalive '25'
        list allowed_ips '192.168.30.0/24'
        option endpoint_host 'IP_ะะ”ะ ะ•ะก_VPS'

#VPN ะฒั‚ะพั€ะพะณะพ ัƒั€ะพะฒะฝั - ัะตั€ะฒะตั€
config interface 'wg1'
        option proto 'wireguard'
        option private_key 'ะ—ะะšะ ะซะขะซะ™_ะšะ›ะฎะง_VPN_2_ะœะก'
        option listen_port '51821'
        list addresses '192.168.31.1/24'
        option auto '1'
        option mtu '7500'

config wireguard_wg1
        option public_key 'ะžะขะšะ ะซะขะซะ™_ะšะ›ะฎะง_VPN_2_ะœะš2'
        list allowed_ips '192.168.31.2'

config wireguard_wg1ip link add grelan0 type gretap remote 192.168.31.1 local 192.168.31.3

        option public_key 'ะžะขะšะ ะซะขะซะ™_ะšะ›ะฎะง_VPN_2_ะœะš3'
        list allowed_ips '192.168.31.3'

ืงืึธื ืคื™ื’ื•ืจืึทื˜ื™ืึธืŸ WireGuard ืื•ื™ืฃ MK2 (ืฆื•ื’ืขืœื™ื™ื’ื˜ ืฆื• /etc/config/network)

#VPN ะฟะตั€ะฒะพะณะพ ัƒั€ะพะฒะฝั - ะบะปะธะตะฝั‚
config interface 'wg0'
        option proto 'wireguard'
        list addresses '192.168.30.3/24'
        option private_key 'ะ—ะะšะ ะซะขะซะ™_ะšะ›ะฎะง_VPN_1_ะœะš2'
        option auto '1'
        option mtu '8000'

config wireguard_wg0
        option public_key 'ะžะขะšะ ะซะขะซะ™_ะšะ›ะฎะง_VPN_1_VPS'
        option endpoint_port '51820'
        option persistent_keepalive '25'
        list allowed_ips '192.168.30.0/24'
        option endpoint_host 'IP_ะะ”ะ ะ•ะก_VPS'

#VPN ะฒั‚ะพั€ะพะณะพ ัƒั€ะพะฒะฝั - ะบะปะธะตะฝั‚
config interface 'wg1'
        option proto 'wireguard'
        option private_key 'ะ—ะะšะ ะซะขะซะ™_ะšะ›ะฎะง_VPN_2_ะœะš2'
        list addresses '192.168.31.2/24'
        option auto '1'
        option listen_port '51821'
        option mtu '7500'

config wireguard_wg1
        option public_key 'ะžะขะšะ ะซะขะซะ™_ะšะ›ะฎะง_VPN_2_ะœะก'
        option endpoint_host '192.168.30.2'
        option endpoint_port '51821'
        option persistent_keepalive '25'
        list allowed_ips '192.168.31.0/24'

ืงืึธื ืคื™ื’ื•ืจืึทื˜ื™ืึธืŸ WireGuard ืื•ื™ืฃ MK3 (ืฆื•ื’ืขืœื™ื™ื’ื˜ ืฆื• /etc/config/network)

#VPN ะฟะตั€ะฒะพะณะพ ัƒั€ะพะฒะฝั - ะบะปะธะตะฝั‚
config interface 'wg0'
        option proto 'wireguard'
        list addresses '192.168.30.4/24'
        option private_key 'ะ—ะะšะ ะซะขะซะ™_ะšะ›ะฎะง_VPN_1_ะœะš3'
        option auto '1'
        option mtu '8000'

config wireguard_wg0
        option public_key 'ะžะขะšะ ะซะขะซะ™_ะšะ›ะฎะง_VPN_1_VPS'
        option endpoint_port '51820'
        option persistent_keepalive '25'
        list allowed_ips '192.168.30.0/24'
        option endpoint_host 'IP_ะะ”ะ ะ•ะก_VPS'

#VPN ะฒั‚ะพั€ะพะณะพ ัƒั€ะพะฒะฝั - ะบะปะธะตะฝั‚
config interface 'wg1'
        option proto 'wireguard'
        option private_key 'ะ—ะะšะ ะซะขะซะ™_ะšะ›ะฎะง_VPN_2_ะœะš3'
        list addresses '192.168.31.3/24'
        option auto '1'
        option listen_port '51821'
        option mtu '7500'

config wireguard_wg1
        option public_key 'ะžะขะšะ ะซะขะซะ™_ะšะ›ะฎะง_VPN_2_ะœะก'
        option endpoint_host '192.168.30.2'
        option endpoint_port '51821'
        option persistent_keepalive '25'
        list allowed_ips '192.168.31.0/24'

ืื™ืŸ ื“ื™ ื‘ืึทืฉืจื™ื‘ืขื ืข ืงืึธื ืคื™ื’ื•ืจืึทืฆื™ืขืก ืคึฟืึทืจ ื“ื™ ืฆื•ื•ื™ื™ื˜ืข ืžื“ืจื’ื” VPN, ื•ื•ืฒึทื– ืื™ืš ืึธืŸ ืฆื• ืงืœื™ืขื ื˜ืŸ WireGuard ืคึผืึธืจื˜ 51821. ื“ืึธืก ื–ืึธืœ ื ื™ืฉื˜ ื–ื™ื™ืŸ ื ื™ื™ื˜ื™ืง, ื•ื•ืฒึทืœ ื“ืขืจ ืงืœื™ืขื ื˜ ื•ื•ืขื˜ ืื•ื™ืคืฉื˜ืขืœืŸ ืึท ืคึฟืึทืจื‘ื™ื ื“ื•ื ื’ ืคึฟื•ืŸ ื™ืขื“ืŸ ืคึฟืจืฒึทืขืŸ, ื ื™ืฉื˜-ืคึผืจื™ื•ื•ื™ืœืขื’ื™ืจื˜ืŸ ืคึผืึธืจื˜, ืึธื‘ืขืจ ืื™ืš ื”ืึธื‘ ืขืก ื’ืขื˜ืึธืŸ ืื•ื™ืฃ ื“ืขื ืื•ืคึฟืŸ ื›ึผื“ื™ ืื™ืš ื–ืึธืœ ืงืขื ืขืŸ ืึธืคึผื–ืึธื’ืŸ ืึทืœืข ืึทืจืฒึทื ืงื•ืžืขื ื“ื™ืงืข ืคึฟืึทืจื‘ื™ื ื“ื•ื ื’ืขืŸ ืื•ื™ืฃ ื“ื™ wg0 ืื™ื ื˜ืขืจืคึฟื™ื™ืกืŸ ืคึฟื•ืŸ ืึทืœืข ืจืึธื•ื˜ืขืจืก, ืึทื—ื•ืฅ ืึทืจืฒึทื ืงื•ืžืขื ื“ื™ืงืข UDP ืคึฟืึทืจื‘ื™ื ื“ื•ื ื’ืขืŸ ืฆื• ืคึผืึธืจื˜ 51821.

ืื™ืš ื”ืึธืคึฟืŸ ืึทื– ื“ืขืจ ืึทืจื˜ื™ืงืœ ื•ื•ืขื˜ ื–ื™ื™ืŸ ื ื•ืฆื™ืง ืคึฟืึทืจ ืขืžืขืฆืขืจ.

ืคึผืก ืื•ื™ืš, ืื™ืš ื•ื•ื™ืœืŸ ืฆื• ื˜ื™ื™ืœืŸ ืžื™ื™ืŸ ืฉืจื™ืคื˜ ื•ื•ืึธืก ืกืขื ื“ื– ืžื™ืจ ืึท PUSH ืึธื ื–ืึธื’ ืฆื• ืžื™ื™ืŸ ื˜ืขืœืขืคืึธืŸ ืื™ืŸ ื“ื™ WirePusher ืึทืคึผืœืึทืงื™ื™ืฉืึทืŸ ื•ื•ืขืŸ ืึท ื ื™ื™ึทืข ืžื™ื˜ืœ ืื™ื– ืืจื•ื™ืก ืื•ื™ืฃ ืžื™ื™ืŸ ื ืขืฅ. ื“ืึธ ืื™ื– ื“ื™ ืœื™ื ืง ืฆื• ื“ื™ ืฉืจื™ืคื˜: github.com/r0ck3r/device_discover.

ื“ืขืจื”ื™ื™ึทื ื˜ื™ืงืŸ: ืงืึธื ืคื™ื’ื•ืจืึทื˜ื™ืึธืŸ OpenVPNืกืขืจื•ื•ืขืจืก ืื•ืŸ ืงืœื™ืขื ื˜ืŸ

OpenVPN-ืกืขืจื•ื•ืขืจ

client-to-client

ca /etc/openvpn/server/ca.crt
cert /etc/openvpn/server/vpn-server.crt
dh /etc/openvpn/server/dh.pem
key /etc/openvpn/server/vpn-server.key

dev tap
ifconfig-pool-persist /etc/openvpn/ipp.txt 0
keepalive 10 60
proto tcp4
server-bridge 192.168.10.1 255.255.255.0 192.168.10.80 192.168.10.254
status /var/log/openvpn-status.log
verb 3
comp-lzo

OpenVPNืงืœื™ืขื ื˜

client
tls-client
dev tap
proto tcp
remote VPS_IP 1194 # Change to your router's External IP
resolv-retry infinite
nobind

ca client/ca.crt
cert client/client.crt
key client/client.key
dh client/dh.pem

comp-lzo
persist-tun
persist-key
verb 3

ืื™ืš ื’ืขื•ื•ื™ื™ื ื˜ easy-rsa ืฆื• ื“ื–ืฉืขื ืขืจื™ื™ื˜ ืกืขืจื˜ื™ืคื™ืงืึทืฅ

ืžืงื•ืจ: www.habr.com

ืงื•ื™ืคืŸ ืคืึทืจืœืึธื–ืœืขืš ื”ืึธืกื˜ื™ื ื’ ืคึฟืึทืจ ื–ื™ื™ื˜ืœืขืš ืžื™ื˜ DDoS ืฉื•ืฅ, VPS VDS ืกืขืจื•ื•ืขืจืก ๐Ÿ”ฅ ืงื•ื™ืคื˜ ืคืึทืจืœืขืกืœืขื›ืข ื•ื•ืขื‘ื–ื™ื™ื˜ืœ ื”ืึธืกื˜ื™ื ื’ ืžื™ื˜ DDoS ืฉื•ืฅ, VPS VDS ืกืขืจื•ื•ืขืจืก | ProHoster