<?xml version="1.0" encoding="UTF-8" ?>
<rss version="2.0">
<channel>
<title><![CDATA[静怡家园]]></title> 
<link>http://www.zhanghaijun.com/index.php</link> 
<description><![CDATA[书山有路勤为径，学海无涯苦作舟！]]></description> 
<language>zh-cn</language> 
<copyright><![CDATA[静怡家园]]></copyright>
<item>
<link>http://www.zhanghaijun.com/post//</link>
<title><![CDATA[CentOS 5.5下OpenVPN和Windows下OpenVPN GUI安装笔记]]></title> 
<author>碟舞飞扬 &lt;webmaster@zhanghaijun.com&gt;</author>
<category><![CDATA[服务器类]]></category>
<pubDate>Wed, 18 May 2011 14:35:12 +0000</pubDate> 
<guid>http://www.zhanghaijun.com/post//</guid> 
<description>
<![CDATA[ 
	一. OpenVPN 安装环境<br/>Server 端的环境 <br/>1.CentOS, kernel版本: 2.6.18, IP 为 221.233.59.16(ADSL拨号)<br/>2.kernel 需要支持 tun 设备, 需要加载 iptables 模块.<br/>3.安装的 OpenVPN 的版本: 2.1.rc15.(目前最新版 可在http://openvpn.net 上下载).<br/>Client 端的环境: 1.Windows XP SP2<br/>2.openvpn-2.1_rc15-install.exe(此版本集成了 OpenVPN GUI 客户端)<br/> <br/>二. OpenVPN 服务端安装过程<br/>1.用putty登录到CentOS<br/>2.下载LZO和OpenVPN 2.1.rc15 wget http://www.oberhumer.com/opensource/lzo/download/lzo-2.03.tar.gz<br/>wget http://openvpn.net/release/openvpn-2.1_rc15.tar.gz yum install -y openssl-devel <br/>3.安装LZO和OpenVPN tar zxvf lzo-2.03.tar.gz<br/>cd lzo-2.03<br/>./configure<br/>make<br/>make install<br/>cd ..<br/>tar zxvf openvpn-2.1_rc15.tar.gz<br/>cd openvpn-2.1_rc15<br/>./configure<br/>make<br/>make install<br/>cd ..<br/>cp /root/openvpn-2.1_rc15/easy-rsa/ -r /etc/openvpn<br/> <br/>4.生成证书初始化PKI cd /etc/openvpn/2.0/#可以设置下OpenVPN参数(也可以修改vars文件来配置)<br/>export D=`pwd`<br/>export KEY_CONFIG=$D/openssl.cnf<br/>export KEY_DIR=$D/keys<br/>export KEY_SIZE=1024<br/>export KEY_COUNTRY=CN<br/>export KEY_PROVINCE=GD<br/>export KEY_CITY=SZ<br/>export KEY_ORG="dvdmaster"<br/>export KEY_EMAIL="support@cooldvd.com"<br/>#也可以不用设置直接执行下面的命令<br/>. vars<br/> <br/>创建证书颁发机构(CA)<br/> ./clean-all<br/>./build-ca<br/><br/>Generating a 1024 bit RSA private key<br/>................++++++<br/>........++++++<br/>writing new private key to 'ca.key'<br/>-----<br/>You are about to be asked to enter information that will be incorporated<br/>into your certificate request.<br/>What you are about to enter is what is called a Distinguished Name or a DN.<br/>There are quite a few fields but you can leave some blank<br/>For some fields there will be a default value,<br/>If you enter '.', the field will be left blank.<br/>-----<br/>Country Name (2 letter code) [CN]:<br/>State or Province Name (full name) [GD]:<br/>Locality Name (eg, city) [SZ]:<br/>Organization Name (eg, company) [dvdmaster]:<br/>Organizational Unit Name (eg, section) []:dvdmaster<br/>Common Name (eg, your name or your server's hostname) []:server<br/>Email Address [support@cooldvd.com]:<br/> <br/>建立server key<br/> ./build-key-server server<br/><br/>Generating a 1024 bit RSA private key<br/>......++++++<br/>....................++++++<br/>writing new private key to 'server.key'<br/>-----<br/>You are about to be asked to enter information that will be incorporated<br/>into your certificate request.<br/>What you are about to enter is what is called a Distinguished Name or a DN.<br/>There are quite a few fields but you can leave some blank<br/>For some fields there will be a default value,<br/>If you enter '.', the field will be left blank.<br/>-----<br/>Country Name (2 letter code) [CN]:<br/>State or Province Name (full name) [GD]:<br/>Locality Name (eg, city) [SZ]:<br/>Organization Name (eg, company) [dvdmaster]:<br/>Organizational Unit Name (eg, section) []:dvdmaster<br/>Common Name (eg, your name or your server's hostname) []:server<br/>Email Address [support@cooldvd.com]:<br/><br/>Please enter the following 'extra' attributes<br/>to be sent with your certificate request<br/>A challenge password []:abcd1234<br/>An optional company name []:dvdmaster<br/>Using configuration from /etc/openvpn/2.0/openssl.cnf<br/>Check that the request matches the signature<br/>Signature ok<br/>The Subject's Distinguished Name is as follows<br/>countryName&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; :PRINTABLE:'CN'<br/>stateOrProvinceName&nbsp;&nbsp; :PRINTABLE:'GD'<br/>localityName&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;:PRINTABLE:'SZ'<br/>organizationName&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;:PRINTABLE:'dvdmaster'<br/>organizationalUnitName:PRINTABLE:'dvdmaster'<br/>commonName&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;:PRINTABLE:'server'<br/>emailAddress&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;:IA5STRING:'support@cooldvd.com'<br/>Certificate is to be certified until Mar 19 08:15:31 2016 GMT (3650 days)<br/>Sign the certificate? [y/n]:y<br/><br/>1 out of 1 certificate requests certified, commit? [y/n]y<br/>Write out database with 1 new entries<br/>Data Base Updated<br/> <br/>生成客户端 key<br/> ./build-key client1<br/>Generating a 1024 bit RSA private key<br/>.....++++++<br/>......++++++<br/>writing new private key to 'client1.key'<br/>-----<br/>You are about to be asked to enter information that will be incorporated<br/>into your certificate request.<br/>What you are about to enter is what is called a Distinguished Name or a DN.<br/>There are quite a few fields but you can leave some blank<br/>For some fields there will be a default value,<br/>If you enter '.', the field will be left blank.<br/>-----<br/>Country Name (2 letter code) [CN]:<br/>State or Province Name (full name) [GD]:<br/>Locality Name (eg, city) [SZ]:<br/>Organization Name (eg, company) [dvdmaster]:<br/>Organizational Unit Name (eg, section) []:dvdmaster<br/>Common Name (eg, your name or your server's hostname) []:client1 #重要: 每个不同的client 生成的证书, 名字必须不同.<br/>Email Address [support@cooldvd.com]:<br/><br/>Please enter the following 'extra' attributes<br/>to be sent with your certificate request<br/>A challenge password []:abcd1234<br/>An optional company name []:dvdmaster<br/>Using configuration from /etc/openvpn/2.0/openssl.cnf<br/>Check that the request matches the signature<br/>Signature ok<br/>The Subject's Distinguished Name is as follows<br/>countryName&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; :PRINTABLE:'CN'<br/>stateOrProvinceName&nbsp;&nbsp; :PRINTABLE:'GD'<br/>localityName&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;:PRINTABLE:'SZ'<br/>organizationName&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;:PRINTABLE:'dvdmaster'<br/>organizationalUnitName:PRINTABLE:'dvdmaster'<br/>commonName&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;:PRINTABLE:'client1'<br/>emailAddress&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;:IA5STRING:'support@cooldvd.com'<br/>Certificate is to be certified until Mar 19 08:22:00 2016 GMT (3650 days)<br/>Sign the certificate? [y/n]:y<br/><br/>1 out of 1 certificate requests certified, commit? [y/n]y<br/>Write out database with 1 new entries<br/>Data Base Updated<br/> <br/>以此类推建立其他客户端 key<br/> ./build-key client2<br/>./build-key client3<br/> <br/>注意在进入 Common Name (eg, your name or your server’s hostname) []: 的输入时, 每个证书输入的名字必须不同.<br/><br/> 5.生成Diffie Hellman参数 ./build-dh<br/> <br/>6.将 keys 下的所有文件打包下载到本地(可以通过winscp,http,ftp等等……) tar zcvf yskeys.tar.gz keys/<br/> <br/>7.创建服务端配置文件 mkdir /etc/openvpn/2.0/conf<br/>cp /root/openvpn-2.1_rc15/sample-config-files/server.conf /etc/openvpn/2.0/conf/server.conf<br/> <br/>服务端配置文件(server.conf)样例<br/>port 1194<br/><br/>proto udp<br/><br/>dev tun<br/><br/>ca /etc/openvpn/2.0/keys/ca.crt<br/>cert /etc/openvpn/2.0/keys/ovpnser.crt<br/>key /etc/openvpn/2.0/keys/ovpnser.key&nbsp;&nbsp;# This file should be kept secret<br/><br/>dh /etc/openvpn/2.0/keys/dh1024.pem<br/><br/>server 10.8.0.0 255.255.255.0<br/><br/>ifconfig-pool-persist ipp.txt<br/><br/>push "redirect-gateway def1 bypass-dhcp"<br/><br/>push "dhcp-option DNS 10.8.0.1"<br/>push "dhcp-option DNS 202.103.44.150" #客户端获得的DNS地址<br/>push "dhcp-option DNS 202.103.24.68" #客户端获得的DNS地址<br/><br/>client-to-client<br/><br/>keepalive 10 120<br/><br/>comp-lzo<br/><br/>user nobody<br/>group nobody<br/><br/>persist-key<br/>persist-tun<br/><br/>status openvpn-status.log<br/><br/>verb 3<br/> <br/>8.启动OpenVPN /usr/local/sbin/openvpn --config /etc/openvpn/2.0/conf/server.conf &<br/> <br/><br/>三. OpenVPN GUI For Windows客户端安装过程<br/>1.下载 openvpn-2.1_rc15-install.exe(此版本集成 OpenVPN&nbsp;&nbsp;GUI)官方下载地址:http://openvpn.net/release/openvpn-2.1_rc15-install.exe<br/>2.依屏幕指示安装OpenVPN GUI<br/>3.配置 openvpn gui将上面第6步打包的yskeys.tar.gz中的下列证书文件解压到 你的OpenVPN GUI安装路径OpenVPNconfig文件夹下 ca.crt<br/>ca.key<br/>client1.crt<br/>client1.csr<br/>client1.key<br/> <br/>4.修改client.ovpn把你的OpenVPN GUI安装路径OpenVPNsample-config下的client.ovpn文件复制到你的OpenVPN GUI安装路径OpenVPNconfig文件夹下,用记事本打开client.ovpn #找到remote my-server-1 1194,把my-server-1改成你的ip地址<br/>remote 221.233.59.16 1194<br/> <br/>5.双击 client.ovpn 即可启动 openvpn, 或者通过 OpenVPN GUI 的控制启动 VPN.<br/> <br/>三. OpenVPN 访问外网的设置<br/> 1.开启CentOS 5 的路由转发功能 echo 1 > /proc/sys/net/ipv4/ip_forward<br/>#为了使CentOS重启后仍然开启路由转发功能我们需要再执行下列命令<br/>sysctl -w net.ipv4.ip_forward=1<br/> <br/>2.添加iptables转发规则 #因为我那天CentOS是ADSL拨号上网,所以把出口设置成ppp0,请根据实际情况设置<br/>iptables -t nat -A POSTROUTING -s 10.8.0.0/24 -o ppp0 -j MASQUERADE<br/> <br/>3.必须保证server.conf配置中,有下面三个配置 push "dhcp-option DNS 10.8.0.1"<br/>push "dhcp-option DNS 202.103.44.150" #客户端获得的DNS地址<br/>push "dhcp-option DNS 202.103.24.68" #客户端获得的DNS地址<br/> <br/>当 client 连接成功后, 在 cmd 下执行 ipconfig /all, 应该有这类似这样的输出:<br/> Ethernet adapter 本地连接 2:<br/><br/>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Connection-specific DNS Suffix&nbsp;&nbsp;. :<br/>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Description . . . . . . . . . . . : TAP-Win32 Adapter V9<br/>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Physical Address. . . . . . . . . : 00-FF-F2-1A-44-BD<br/>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Dhcp Enabled. . . . . . . . . . . : Yes<br/>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Autoconfiguration Enabled . . . . : Yes<br/>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;IP Address. . . . . . . . . . . . : 10.8.0.6<br/>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Subnet Mask . . . . . . . . . . . : 255.255.255.252<br/>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Default Gateway . . . . . . . . . : 10.8.0.5<br/>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;DHCP Server . . . . . . . . . . . : 10.8.0.5<br/>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;DNS Servers . . . . . . . . . . . : 10.8.0.1<br/>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;202.103.44.150<br/>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;202.103.24.68<br/>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Lease Obtained. . . . . . . . . . : 2009年5月8日 23:55:06<br/>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Lease Expires . . . . . . . . . . : 2010年5月8日 23:55:06 <br/><br/>四. 设置 OpenVPN 服务器 reboot后自动启动 openvpn<br/> <br/>执行<br/>vi /etc/rc.local<br/> <br/>然后在最后面加入此行:<br/>/usr/local/sbin/openvpn --config /etc/openvpn/2.0/conf/server.conf &<br/> <br/>五.OpenVPN 测试<br/> <br/>连接成功之后,去www.ip138.com上看看外网ip是多少,如果是CentOS系统的外网ip那说明测试成功了~<br/>Tags - <a href="http://www.zhanghaijun.com/tags/openvpn/" rel="tag">openvpn</a>
]]>
</description>
</item><item>
<link>http://www.zhanghaijun.com/post//#blogcomment</link>
<title><![CDATA[[评论] CentOS 5.5下OpenVPN和Windows下OpenVPN GUI安装笔记]]></title> 
<author> &lt;user@domain.com&gt;</author>
<category><![CDATA[评论]]></category>
<pubDate>Thu, 01 Jan 1970 00:00:00 +0000</pubDate> 
<guid>http://www.zhanghaijun.com/post//#blogcomment</guid> 
<description>
<![CDATA[ 
	
]]>
</description>
</item>
</channel>
</rss>