Isevisi ye-VPN yamahhala ye-Wireguard ku-AWS

Yini?

Ngokukhula kokuhlolwa kwe-inthanethi yimibuso enegunya, inani elikhulayo lezinsiza ze-inthanethi eziwusizo namasayithi ayavinjwa. Kubandakanya ulwazi lobuchwepheshe.
Ngakho-ke, kuba nzima ukusebenzisa i-inthanethi ngokugcwele futhi kwephula ilungelo eliyisisekelo lenkululeko yokukhuluma, elifakwe Isimemezelo Somhlaba Wonke Samalungelo Abantu.

I-Article 19
Wonke umuntu unelungelo lenkululeko yokubeka imibono yakhe nokuveza imizwa yakhe; leli lungelo lihlanganisa inkululeko yokuba nemibono ngaphandle kokuphazanyiswa kanye nokufuna, ukwamukela nokudlulisa ulwazi nemibono nganoma iyiphi imidiya futhi kungakhathalekile ukuthi ikuphi.

Kulo mhlahlandlela, sizosebenzisa i-freeware* yethu ngezinyathelo ezingu-6. Isevisi ye-VPN ngokusekelwe kwezobuchwepheshe I-Wire Guard, kungqalasizinda yamafu Ama-Web Web Services (AWS), usebenzisa i-akhawunti yamahhala (izinyanga eziyi-12), esimweni (umshini obonakalayo) ophethwe ngu Ubuntu Server 18.04LTS.
Ngizamile ukwenza lokhu kuhamba kube nobungane kubantu abangewona abe-IT ngangokunokwenzeka. Okuwukuphela kwento edingekayo ukuphikelela ekuphindaphindeni izinyathelo ezichazwe ngezansi.

Ukubhala

Izigaba

  1. Bhalisela i-akhawunti yamahhala ye-AWS
  2. Dala isibonelo se-AWS
  3. Ixhuma kusibonelo se-AWS
  4. Ukucushwa kwe-Wireguard
  5. Ilungiselela amaklayenti e-VPN
  6. Ihlola ukulunga kokufakwa kwe-VPN

Izixhumanisi eziwusizo

1. Ukubhalisa i-akhawunti ye-AWS

Ukubhalisela i-akhawunti yamahhala ye-AWS kudinga inombolo yocingo yangempela kanye nekhadi lesikweletu le-Visa noma le-Mastercard elivumelekile. Ngincoma ukusebenzisa amakhadi abonakalayo anikezwa mahhala Yandex.Money noma isikhwama semali. Ukuze uhlole ukufaneleka kwekhadi, i-$ 1 idonswa ngesikhathi sokubhaliswa, ebuyiselwa kamuva.

1.1. Ivula i-AWS Management Console

Udinga ukuvula isiphequluli bese uya ku: https://aws.amazon.com/ru/
Chofoza inkinobho ethi "Bhalisa".

Isevisi ye-VPN yamahhala ye-Wireguard ku-AWS

1.2. Ukugcwalisa idatha yomuntu siqu

Gcwalisa idatha bese uchofoza inkinobho ethi "Qhubeka".

Isevisi ye-VPN yamahhala ye-Wireguard ku-AWS

1.3. Ukugcwalisa imininingwane yokuxhumana

Gcwalisa imininingwane yokuxhumana.

Isevisi ye-VPN yamahhala ye-Wireguard ku-AWS

1.4. Icacisa ulwazi lokukhokha.

Inombolo yekhadi, usuku lokuphelelwa yisikhathi kanye negama lomnikazi wekhadi.

Isevisi ye-VPN yamahhala ye-Wireguard ku-AWS

1.5. Ukuqinisekiswa kwe-akhawunti

Kulesi sigaba, inombolo yocingo iqinisekisiwe futhi i-$ 1 idonswa ngokuqondile ekhadini lokukhokha. Ikhodi enamadijithi angu-4 iboniswa esikrinini sekhompyutha, futhi ifoni eshiwo ithola ucingo oluvela e-Amazon. Ngesikhathi socingo, kufanele ushayele ikhodi ekhonjiswe esibukweni.

Isevisi ye-VPN yamahhala ye-Wireguard ku-AWS

1.6. Ukukhetha uhlelo lwentela.

Khetha - Uhlelo oluyisisekelo (mahhala)

Isevisi ye-VPN yamahhala ye-Wireguard ku-AWS

1.7. Ngena ngemvume kukhonsoli yokuphatha

Isevisi ye-VPN yamahhala ye-Wireguard ku-AWS

1.8. Ukukhetha indawo yesikhungo sedatha

Isevisi ye-VPN yamahhala ye-Wireguard ku-AWS

1.8.1. Ukuhlola isivinini

Ngaphambi kokukhetha isikhungo sedatha, kunconywa ukuthi uhlole https://speedtest.net isivinini sokufinyelela kuzikhungo zedatha eziseduze, endaweni yami imiphumela elandelayo:

  • Ibhayisikobho yezimanga
    Isevisi ye-VPN yamahhala ye-Wireguard ku-AWS
  • EParis
    Isevisi ye-VPN yamahhala ye-Wireguard ku-AWS
  • UFrankfurt
    Isevisi ye-VPN yamahhala ye-Wireguard ku-AWS
  • Stockholm
    Isevisi ye-VPN yamahhala ye-Wireguard ku-AWS
  • ELondon
    Isevisi ye-VPN yamahhala ye-Wireguard ku-AWS

Isikhungo sedatha eLondon sibonisa imiphumela engcono kakhulu ngokuya ngesivinini. Ngakho ngikhethe yona ukuze ngiyenze ngezifiso.

2. Dala isibonelo se-AWS

2.1 Dala umshini obonakalayo

2.1.1. Ukukhetha uhlobo lwesibonelo

Ngokuzenzakalelayo, isibonelo se-t2.micro siyakhethwa, okuyikhona esikudingayo, mane ucindezele inkinobho Okulandelayo: Lungiselela Imininingwane Yesimo

Isevisi ye-VPN yamahhala ye-Wireguard ku-AWS

2.1.2. Ukusetha Izinketho Zesimo

Ngokuzayo, sizoxhuma i-IP yomphakathi unomphela esibonelweni sethu, ngakho kulesi sigaba sivala ukunikezwa okuzenzakalelayo kwe-IP yomphakathi, bese sicindezela inkinobho. Okulandelayo: Engeza Isitoreji

Isevisi ye-VPN yamahhala ye-Wireguard ku-AWS

2.1.3. Ukuxhumeka kwesitoreji

Cacisa usayizi "we-hard disk". Ngezinjongo zethu, amagigabhayithi angu-16 anele, futhi sicindezela inkinobho Okulandelayo: Engeza Omaka

Isevisi ye-VPN yamahhala ye-Wireguard ku-AWS

2.1.4. Isetha omaka

Uma sidale izimo ezimbalwa, zingase ziqoqwe ngomaka ukuze kube lula ukuphatha. Kulokhu, lokhu kusebenza kungaphezu kwamandla, cindezela inkinobho ngokushesha Okulandelayo: Lungiselela Iqembu Lokuvikela

Isevisi ye-VPN yamahhala ye-Wireguard ku-AWS

2.1.5. Ukuvula izimbobo

Kulesi sinyathelo, silungiselela i-firewall ngokuvula izimbobo ezidingekayo. Isethi yezimbobo ezivulekile ibizwa ngokuthi Iqembu Lezokuphepha. Kumelwe sakhe iqembu elisha lokuvikela, silinikeze igama, incazelo, sengeze imbobo ye-UDP (Umthetho We-UDP Ongokwezifiso), kunkambu ye-Rort Range, sinikeze inombolo yembobo ebangeni. amachweba ashukumisayo 49152-65535. Kulokhu, ngikhethe inombolo yechweba 54321.

Isevisi ye-VPN yamahhala ye-Wireguard ku-AWS

Ngemva kokugcwalisa idatha edingekayo, chofoza inkinobho Buyekeza futhi Yethule

2.1.6. Uhlolojikelele lwazo zonke izilungiselelo

Kuleli khasi kukhona uhlolojikelele lwazo zonke izilungiselelo zesibonelo sethu, sibheka ukuthi zonke izilungiselelo zihlelekile yini, bese ucindezela inkinobho. Qalisa

Isevisi ye-VPN yamahhala ye-Wireguard ku-AWS

2.1.7. Idala Okhiye Bokufinyelela

Okulandelayo kuza ibhokisi lengxoxo elinikeza ukudala noma ukwengeza ukhiye we-SSH okhona, esizoxhuma ngawo ukude esibonelweni sethu. Sikhetha inketho ethi "Dala ukhiye omusha" ukuze udale ukhiye omusha. Inikeze igama bese uchofoza inkinobho Landa i-Key Pairukulanda okhiye abakhiqiziwe. Zigcine endaweni ephephile kukhompuyutha yakho yangakini. Uma isilandiwe, chofoza inkinobho. Yethula Izigameko

Isevisi ye-VPN yamahhala ye-Wireguard ku-AWS

2.1.7.1. Ilondoloza Okhiye Bokufinyelela

Okuboniswa lapha isinyathelo sokulondoloza okhiye abakhiqiziwe esinyathelweni sangaphambilini. Ngemva kokuthi sicindezele inkinobho Landa i-Key Pair, ukhiye ugcinwa njengefayela lesitifiketi elinesandiso se-*.pem. Kulokhu, ngiyiqambe igama i-wireguard-awskey.pem

Isevisi ye-VPN yamahhala ye-Wireguard ku-AWS

2.1.8. Uhlolojikelele lwemiphumela yokudalwa kwemifanekiso

Okulandelayo, sibona umlayezo mayelana nokwethulwa ngempumelelo kwesibonelo esisanda kusidala. Singaya ohlwini lwezimo zethu ngokuchofoza inkinobho buka izimo

Isevisi ye-VPN yamahhala ye-Wireguard ku-AWS

2.2. Ukudala ikheli le-IP langaphandle

2.2.1. Ukuqala ukudalwa kwe-IP yangaphandle

Okulandelayo, sidinga ukudala ikheli le-IP langaphandle elingunaphakade lapho sizoxhuma khona kuseva yethu ye-VPN. Ukwenza lokhu, kuphaneli yokuzulazula ohlangothini lwesobunxele lwesikrini, khetha into I-Elastic IPs kusukela esigabeni INETHWEKH KANYE NE-SECTURITY bese ucindezela inkinobho Nikeza ikheli elisha

Isevisi ye-VPN yamahhala ye-Wireguard ku-AWS

2.2.2. Ilungiselela ukudalwa kwe-IP yangaphandle

Esinyathelweni esilandelayo, sidinga ukunika amandla inketho Ichibi lase-Amazon (kunikwe amandla ngokuzenzakalela), bese uchofoza inkinobho Nikezela

Isevisi ye-VPN yamahhala ye-Wireguard ku-AWS

2.2.3. Uhlolojikelele lwemiphumela yokudala ikheli le-IP langaphandle

Isikrini esilandelayo sizobonisa ikheli le-IP langaphandle esilitholile. Kutuswa ukuyibamba ngekhanda, futhi kungcono ngisho ukuyibhala phansi. izoba usizo ngaphezu kokukodwa ohlelweni lokuqhubeka nokusetha nokusebenzisa iseva ye-VPN. Kulo mhlahlandlela, ngisebenzisa ikheli le-IP njengesibonelo. 4.3.2.1. Uma usulifakile ikheli, cindezela inkinobho Close

Isevisi ye-VPN yamahhala ye-Wireguard ku-AWS

2.2.4. Uhlu lwamakheli e-IP angaphandle

Okulandelayo, sinikezwa uhlu lwamakheli ethu e-IP omphakathi angunaphakade (elastics IP).

Isevisi ye-VPN yamahhala ye-Wireguard ku-AWS

2.2.5. Ukwabela I-IP Yangaphandle Njengesibonelo

Kulolu hlu, sikhetha ikheli le-IP esilitholile, bese ucindezela inkinobho yegundane elingakwesokudla ukuze uveze imenyu yokudonsela phansi. Kuyo, khetha into ikheli elihlobeneukuze sinikeze isibonelo esisidale ngaphambilini.

Isevisi ye-VPN yamahhala ye-Wireguard ku-AWS

2.2.6. Isilungiselelo sokwabiwa kwe-IP yangaphandle

Esinyathelweni esilandelayo, khetha isibonelo sethu ohlwini lokudonsela phansi, bese ucindezela inkinobho Hlobanisa

Isevisi ye-VPN yamahhala ye-Wireguard ku-AWS

2.2.7. Uhlolojikelele Lwemiphumela Yomsebenzi Womsebenzi We-IP Yangaphandle

Ngemva kwalokho, singabona ukuthi isibonelo sethu kanye nekheli laso le-IP eliyimfihlo kuboshelwe ekhelini lethu le-IP yomphakathi unomphela.

Isevisi ye-VPN yamahhala ye-Wireguard ku-AWS

Manje sesingakwazi ukuxhuma kusibonelo sethu esisanda kwakhiwa ngaphandle, sisuka kukhompuyutha yethu nge-SSH.

3. Xhuma kusibonelo se-AWS

ssh iyiphrothokholi evikelekile yesilawuli kude samadivayisi wekhompyutha.

3.1. Ixhuma nge-SSH kukhompuyutha ye-Windows

Ukuze uxhume kukhompuyutha ye-Windows, udinga kuqala ukulanda futhi ufake uhlelo Putty.

3.1.1. Ngenisa ukhiye oyimfihlo we-Putty

3.1.1.1. Ngemuva kokufaka i-Putty, udinga ukusebenzisa insiza ye-PuTTYgen eza nayo ukuze ungenise ukhiye wesitifiketi ngefomethi ye-PEM, ngefomethi efanelekile ukusetshenziswa ku-Putty. Ukuze wenze lokhu, khetha into ekwimenyu ephezulu Ukuguqulwa->Ukhiye Wokungenisa

Isevisi ye-VPN yamahhala ye-Wireguard ku-AWS

3.1.1.2. Ukukhetha ukhiye we-AWS ngefomethi ye-PEM

Okulandelayo, khetha ukhiye esiwugcine ngaphambilini esinyathelweni 2.1.7.1, kithi igama lawo i-wireguard-awskey.pem

Isevisi ye-VPN yamahhala ye-Wireguard ku-AWS

3.1.1.3. Ukusetha izinketho zokungenisa eziyinhloko

Kulesi sinyathelo, sidinga ukucacisa amazwana alo khiye (incazelo) futhi simise iphasiwedi kanye nokuqinisekiswa kokuvikeleka. Izocelwa njalo uma uxhuma. Ngakho, sivikela ukhiye ngephasiwedi ekusetshenzisweni okungafanele. Akudingekile ukuthi usethe iphasiwedi, kodwa ivikeleke kancane uma ukhiye uwela ezandleni ezingalungile. Ngemva kokucindezela inkinobho Londoloza ukhiye oyimfihlo

Isevisi ye-VPN yamahhala ye-Wireguard ku-AWS

3.1.1.4. Ilondoloza ukhiye ongenisiwe

Ibhokisi lengxoxo lokulondoloza liyavula futhi silondoloza ukhiye wethu oyimfihlo njengefayela elinesandiso .ppkilungele ukusetshenziswa ohlelweni Putty.
Cacisa igama lokhiye (kithi wireguard-awskey.ppk) bese ucindezela inkinobho Londoloza.

Isevisi ye-VPN yamahhala ye-Wireguard ku-AWS

3.1.2. Ukudala nokumisa uxhumano ku-Putty

3.1.2.1. Dala uxhumano

Vula uhlelo lwe-Putty, khetha isigaba Session (ivulwa ngokuzenzakalelayo) kanye nasendle Igama Lombungazi faka ikheli le-IP lomphakathi leseva yethu, esilithole esinyathelweni 2.2.3. Ensimini Isikhathi Esilondoloziwe faka igama elingafanele ukuze uxhumane nathi (endabeni yami i-wireguard-aws-london), bese ucindezela inkinobho Londoloza ukulondoloza izinguquko esizenzile.

Isevisi ye-VPN yamahhala ye-Wireguard ku-AWS

3.1.2.2. Isetha ukungena ngemvume komsebenzisi

Okuningi esigabeni Connection, khetha isigatshana Idatha nasensimini Ngena ngokuzenzakalelayo igama lomsebenzisi faka igama lomsebenzisi ubuntu ungumsebenzisi ojwayelekile wesibonelo ku-AWS eno-Ubuntu.

Isevisi ye-VPN yamahhala ye-Wireguard ku-AWS

3.1.2.3. Ukukhetha ukhiye oyimfihlo wokuxhuma nge-SSH

Bese uye esigabeni esingaphansi Uxhumano/SSH/Auth futhi eduze kwenkundla Ifayela elingukhiye oyimfihlo lokuqinisekisa cindezela inkinobho Dlulisa amehlo… ukukhetha ifayela elinesitifiketi sikakhiye.

Isevisi ye-VPN yamahhala ye-Wireguard ku-AWS

3.1.2.4. Ivula ukhiye ongenisiwe

Cacisa ukhiye esiwungenise ngaphambilini esinyathelweni 3.1.1.4, kithi uyifayela i-wireguard-awskey.ppk, bese ucindezela inkinobho Vula.

Isevisi ye-VPN yamahhala ye-Wireguard ku-AWS

3.1.2.5. Ilondoloza izilungiselelo futhi iqalise uxhumano

Ibuyela ekhasini lesigaba Session cindezela inkinobho futhi Londoloza, ukulondoloza izinguquko esizenze ngaphambili ezinyathelweni zangaphambilini (3.1.2.2 - 3.1.2.4). Bese sicindezela inkinobho Vula ukuze uvule uxhumo olukude lwe-SSH esiludalile futhi salulungisa.

Isevisi ye-VPN yamahhala ye-Wireguard ku-AWS

3.1.2.7. Imisa ukwethembana phakathi kwababungazi

Esinyathelweni esilandelayo, okokuqala sizama ukuxhuma, sinikezwa isexwayiso, asinakho ukwethembana okulungiselelwe phakathi kwamakhompyutha amabili, futhi sibuza ukuthi sithembe ikhompuyutha ekude. Sizocindezela inkinobho Yebo, ngokwenza kanjalo iyengeza ohlwini lwababungazi abathenjwayo.

Isevisi ye-VPN yamahhala ye-Wireguard ku-AWS

3.1.2.8. Ifaka iphasiwedi ukuze ufinyelele ukhiye

Ngemva kwalokho, iwindi letheminali liyavuleka, lapho ucelwa khona iphasiwedi yokhiye, uma uyibeka ngaphambili esinyathelweni 3.1.1.3. Uma ufaka iphasiwedi, akukho senzo esenzeka esikrinini. Uma wenze iphutha, ungasebenzisa ukhiye I-Backspace.

Isevisi ye-VPN yamahhala ye-Wireguard ku-AWS

3.1.2.9. Umlayezo wokwamukela ekuxhumekeni okuyimpumelelo

Ngemva kokufaka iphasiwedi ngempumelelo, siboniswa umbhalo owamukelekayo kutheminali, ositshela ukuthi isistimu ekude isilungele ukusebenzisa imiyalo yethu.

Isevisi ye-VPN yamahhala ye-Wireguard ku-AWS

4. Ilungiselela i-Wireguard Server

Imiyalo yakamuva kakhulu yokufaka nokusebenzisa i-Wireguard usebenzisa imibhalo echazwe ngezansi ingatholakala endaweni yokugcina: https://github.com/isystem-io/wireguard-aws

4.1. Ifaka i-WireGuard

Kutheminali, faka imiyalo elandelayo (ungakopishela ebhodini lokunamathisela, bese unamathisele kutheminali ngokucindezela inkinobho yegundane engakwesokudla):

4.1.1. Ukuhlanganisa inqolobane

Vala indawo yokugcina ngemibhalo yokufaka ye-Wireguard

git clone https://github.com/pprometey/wireguard_aws.git wireguard_aws

4.1.2. Ukushintshela kuhla lwemibhalo olunemibhalo

Iya kumkhombandlela onenqolobane ehlanganisiwe

cd wireguard_aws

4.1.3 Ukusebenzisa umbhalo wokuqalisa

Qalisa njengomlawuli (umsebenzisi wezimpande) iskripthi sokufakwa kwe-Wireguard

sudo ./initial.sh

Inqubo yokufaka izocela idatha ethile edingekayo ukuze kulungiswe i-Wireguard

4.1.3.1. Okokufaka kwephoyinti lokuxhuma

Faka ikheli le-IP langaphandle kanye nembobo evulekile yeseva ye-Wireguard. Sithole ikheli le-IP langaphandle leseva esinyathelweni 2.2.3, futhi savula imbobo kusinyathelo 2.1.5. Siwabonisa ndawonye, ​​​​ngokwehlukanisa ngekholoni, isibonelo 4.3.2.1:54321bese ucindezela inkinobho Faka
Okukhiphayo okuyisampula:

Enter the endpoint (external ip and port) in format [ipv4:port] (e.g. 4.3.2.1:54321): 4.3.2.1:54321

4.1.3.2. Ifaka ikheli le-IP langaphakathi

Faka ikheli le-IP leseva ye-Wireguard ku-subnet ye-VPN evikelekile, uma ungayazi ukuthi iyini, vele ucindezele ukhiye u-Enter ukuze usethe inani elizenzakalelayo (10.50.0.1)
Okukhiphayo okuyisampula:

Enter the server address in the VPN subnet (CIDR format) ([ENTER] set to default: 10.50.0.1):

4.1.3.3. Icacisa iseva ye-DNS

Faka ikheli le-IP leseva ye-DNS, noma mane ucindezele ukhiye u-Enter ukuze usethe inani elimisiwe 1.1.1.1 (Cloudflare public DNS)
Okukhiphayo okuyisampula:

Enter the ip address of the server DNS (CIDR format) ([ENTER] set to default: 1.1.1.1):

4.1.3.4. Icacisa isixhumi esibonakalayo se-WAN

Okulandelayo, udinga ukufaka igama le-interface yenethiwekhi yangaphandle ezolalela ku-interface yenethiwekhi yangaphakathi ye-VPN. Vele ucindezele u-Enter ukuze usethe inani elizenzakalelayo le-AWS (eth0)
Okukhiphayo okuyisampula:

Enter the name of the WAN network interface ([ENTER] set to default: eth0):

4.1.3.5. Icacisa igama leklayenti

Faka igama lomsebenzisi we-VPN. Iqiniso liwukuthi iseva ye-Wireguard VPN ngeke ikwazi ukuqala kuze kube yilapho sekwengezwe okungenani iklayenti elilodwa. Kulokhu, ngifake igama Alex@mobile
Okukhiphayo okuyisampula:

Enter VPN user name: Alex@mobile

Ngemuva kwalokho, ikhodi ye-QR enokucushwa kweklayenti elisha kufanele iboniswe esikrinini, okufanele ifundwe kusetshenziswa iklayenti leselula le-Wireguard ku-Android noma i-iOS ukuze liyilungiselele. Futhi ngaphansi kwekhodi ye-QR, umbhalo wefayela lokucushwa uzovezwa uma kwenzeka ukumiswa ngesandla kwamakhasimende. Indlela yokwenza lokhu kuzoxoxwa ngayo ngezansi.

Isevisi ye-VPN yamahhala ye-Wireguard ku-AWS

4.2. Ingeza umsebenzisi omusha we-VPN

Ukwengeza umsebenzisi omusha, udinga ukusebenzisa iskripthi kutheminali add-client.sh

sudo ./add-client.sh

Umbhalo ucela igama lomsebenzisi:
Okukhiphayo okuyisampula:

Enter VPN user name: 

Futhi, igama labasebenzisi lingadluliswa njengepharamitha yeskripthi (kulokhu Alex@mobile):

sudo ./add-client.sh Alex@mobile

Njengomphumela wokwenziwa kombhalo, ohlwini lwemibhalo olunegama leklayenti endleleni /etc/wireguard/clients/{ИмяКлиента} ifayela lokumisa leklayenti lizokwakhiwa /etc/wireguard/clients/{ИмяКлиента}/{ИмяКлиента}.conf, futhi isikrini setheminali sizobonisa ikhodi ye-QR yokusetha amaklayenti eselula kanye nokuqukethwe kwefayela lokumisa.

4.2.1. Ifayela lokumisa lomsebenzisi

Ungakwazi ukubonisa okuqukethwe kwefayela elithi .conf esikrinini, ukuze ucushwe ngesandla seklayenti, usebenzisa umyalo cat

sudo cat /etc/wireguard/clients/Alex@mobile/[email protected]

umphumela wokwenza:

[Interface]
PrivateKey = oDMWr0toPVCvgKt5oncLLRfHRit+jbzT5cshNUi8zlM=
Address = 10.50.0.2/32
DNS = 1.1.1.1

[Peer]
PublicKey = mLnd+mul15U0EP6jCH5MRhIAjsfKYuIU/j5ml8Z2SEk=
PresharedKey = wjXdcf8CG29Scmnl5D97N46PhVn1jecioaXjdvrEkAc=
AllowedIPs = 0.0.0.0/0, ::/0
Endpoint = 4.3.2.1:54321

Incazelo yefayela lokumisa iklayenti:

[Interface]
PrivateKey = Приватный ключ клиента
Address = IP адрес клиента
DNS = ДНС используемый клиентом

[Peer]
PublicKey = Публичный ключ сервера
PresharedKey = Общи ключ сервера и клиента
AllowedIPs = Разрешенные адреса для подключения (все -  0.0.0.0/0, ::/0)
Endpoint = IP адрес и порт для подключения

4.2.2. Ikhodi ye-QR yokucushwa kweklayenti

Ungabonisa ikhodi ye-QR yokumisa yeklayenti edalwe ngaphambilini esikrinini setheminali usebenzisa umyalo qrencode -t ansiutf8 (kulesi sibonelo, kusetshenziswa iklayenti elibizwa ngo-Alex@mobile):

sudo cat /etc/wireguard/clients/Alex@mobile/[email protected] | qrencode -t ansiutf8

5. Ilungiselela amaKlayenti e-VPN

5.1. Isetha iklayenti leselula le-Android

Iklayenti elisemthethweni le-Wireguard le-Android lingaba faka kusukela ku-Google Play Isitolo esisemthethweni

Ngemuva kwalokho, kuyadingeka ukungenisa ukucushwa ngokufunda ikhodi ye-QR ngokucushwa kweklayenti (bheka isigaba 4.2.2) bese uyinikeza igama:

Isevisi ye-VPN yamahhala ye-Wireguard ku-AWS

Ngemva kokungenisa ngempumelelo ukucushwa, ungakwazi ukunika amandla umhubhe we-VPN. Uxhumano oluyimpumelelo luzoboniswa ngokufihlwa kokhiye kuthreyi yesistimu ye-Android

Isevisi ye-VPN yamahhala ye-Wireguard ku-AWS

5.2. Ukusethwa kweklayenti leWindows

Okokuqala udinga ukulanda futhi ufake uhlelo I-TunSafe yeWindows iyiklayenti le-Wireguard le-Windows.

5.2.1. Idala ifayela lokumisa lokungenisa

Chofoza kwesokudla ukuze udale ifayela lombhalo kudeskithophu.

Isevisi ye-VPN yamahhala ye-Wireguard ku-AWS

5.2.2. Kopisha okuqukethwe kwefayela lokumisa kusuka kuseva

Bese sibuyela ku-terminal ye-Putty futhi sibonise okuqukethwe kwefayela lokumisa lomsebenzisi oyifunayo, njengoba kuchazwe esinyathelweni 4.2.1.
Okulandelayo, chofoza kwesokudla umbhalo wokumisa kutheminali ye-Putty, ngemuva kokuthi ukukhethwa sekuqediwe, kuzokopishwa ngokuzenzakalelayo ebhodini lokunamathisela.

Isevisi ye-VPN yamahhala ye-Wireguard ku-AWS

5.2.3. Ikopisha ukucushwa kufayela lokucushwa lendawo

Kulo mkhakha, sibuyela efayeleni lombhalo esidale ngaphambili kudeskithophu, bese unamathisela umbhalo wokucushwa kuwo usuka ebhodini lokunamathisela.

Isevisi ye-VPN yamahhala ye-Wireguard ku-AWS

5.2.4. Ilondoloza ifayela lendawo lokucushwa

Londoloza ifayela ngesandiso .conf (kulesi simo okuthiwa london.conf)

Isevisi ye-VPN yamahhala ye-Wireguard ku-AWS

5.2.5. Ingenisa ifayela lendawo lokumisa

Okulandelayo, udinga ukungenisa ifayela lokumisa ohlelweni lwe-TunSafe.

Isevisi ye-VPN yamahhala ye-Wireguard ku-AWS

5.2.6. Isetha uxhumano lwe-VPN

Khetha leli fayela lokumisa bese uxhuma ngokuchofoza inkinobho Xhuma.
Isevisi ye-VPN yamahhala ye-Wireguard ku-AWS

6. Ihlola ukuthi uxhumano luphumelele yini

Ukuze uhlole impumelelo yokuxhumeka ngokusebenzisa umhubhe we-VPN, udinga ukuvula isiphequluli bese uya kusayithi https://2ip.ua/ru/

Isevisi ye-VPN yamahhala ye-Wireguard ku-AWS

Ikheli le-IP elibonisiwe kufanele lifane naleli esilitholile esinyathelweni esingu-2.2.3.
Uma kunjalo, khona-ke umhubhe we-VPN usebenza ngempumelelo.

Kutheminali ye-Linux, ungabheka ikheli lakho le-IP ngokubhala:

curl http://zx2c4.com/ip

Noma ungavele uye ku-pornhub uma useKazakhstan.

Source: www.habr.com

Engeza amazwana