{"id":495,"date":"2011-11-06T13:52:32","date_gmt":"2011-11-06T13:52:32","guid":{"rendered":"http:\/\/hgtas.com\/?p=495"},"modified":"2011-11-06T14:04:38","modified_gmt":"2011-11-06T14:04:38","slug":"debian-install-openvpn-process-records","status":"publish","type":"post","link":"https:\/\/508.me\/?p=495","title":{"rendered":"Debian\u4e0b\u5b89\u88c5Openvpn\u8fc7\u7a0b\u8bb0\u5f55"},"content":{"rendered":"<p><strong>\u7cfb\u7edf\u4fe1\u606f\uff1a<\/strong><br \/>\n<strong>OS <\/strong> : Debian 6.0<\/p>\n<p>Openvpn\u7248\u672c\uff1a2.2.1<\/p>\n<p>&nbsp;<\/p>\n<p><strong>1. \u5b89\u88c5\u6240\u9700\u7684\u7f16\u8bd1\u5de5\u5177\uff1a<br \/>\n<strong>#apt-get install gcc g++ make pkg-config libpam0g-dev sasl2-bin<\/strong><\/strong><\/p>\n<p>2\uff0c\u4e0b\u8f7dlzo\u5e93[<a href=\"http:\/\/www.oberhumer.com\/opensource\/lzo\/download\/\" target=\"_blank\">http:\/\/www.oberhumer.com\/opensource\/lzo\/download\/ <\/a>]: <strong><\/strong><br \/>\n<strong>#wget <a href=\"http:\/\/www.oberhumer.com\/opensource\/lzo\/download\/lzo-2.06.tar.gz\">http:\/\/www.oberhumer.com\/opensource\/lzo\/download\/lzo-2.06.tar.gz<\/a> <\/strong><\/p>\n<p>\u8bf4\u660e\uff1alzo\u662f\u4e00\u4e2a\u5b9e\u7528\u7684\u65e0\u635f\u538b\u7f29\u5de5\u5177\u3002[\u53ef\u9009]<\/p>\n<p>3\uff0c\u4e0b\u8f7dopenssl[<a href=\"http:\/\/www.openssl.org\/\">http:\/\/www.openssl.org\/<\/a> ]:<br \/>\n<strong>#wget <a href=\"http:\/\/www.openssl.org\/source\/openssl-1.0.0e.tar.gz\">http:\/\/www.openssl.org\/source\/openssl-1.0.0e.tar.gz<\/a> <\/strong><\/p>\n<p>\u8bf4\u660e\uff1aOpenVPN\u4f9d\u8d56OpenSSL\u5e93\uff0c\u7528\u4e8e\u52a0\u5bc6\uff0c\u9700\u8981\u5b89\u88c5\u3002<\/p>\n<p>4\uff0c\u4e0b\u8f7dopenvpn[<a href=\"http:\/\/www.openvpn.net\/\">http:\/\/www.openvpn.net\/<\/a> ]:<br \/>\n<strong>#wget <a href=\"http:\/\/www.openvpn.net\/release\/openvpn-2.2.1.tar.gz\">http:\/\/www.openvpn.net\/release\/openvpn-2.2.1.tar.gz<\/a><\/strong><\/p>\n<p>&nbsp;<\/p>\n<p><strong>\u4e8c\uff0c\u5b89\u88c5OpenVPN\u53ca\u76f8\u5173\u8f6f\u4ef6\uff1a<\/strong><br \/>\n1\uff0c\u5b89\u88c5lzo:<br \/>\n<strong>#tar -zxvf lzo-2.06.tar.gz<\/strong> <strong><br \/>\n#cd lzo-2.06<br \/>\n#.\/configure \u2013prefix=\/usr\/local\/lzo<br \/>\n#make<br \/>\n#make install<\/strong><\/p>\n<p><strong> <\/strong> \u5728\/etc\/ld.so.conf\u4e2d\u52a0\u5165\u4ee5\u4e0b\u5185\u5bb9\uff1a<br \/>\n<strong>\/lib<br \/>\n\/usr\/lib<br \/>\n\/usr\/local\/lib<br \/>\n\/usr\/local\/lzo\/lib<\/strong><\/p>\n<p><strong>\u4f7f\u7528\/etc\/ld.so.conf\u4e2d\u7684\u5185\u5bb9\u751f\u6548\uff0c\u5373\u52a8\u6001\u8fde\u63a5\u5e93\u751f\u6548\uff1a<br \/>\n<strong>#ldconfig<\/strong><\/strong><\/p>\n<p><strong> <\/strong> 2\uff0c\u5b89\u88c5openssl:<br \/>\n<strong>#cd ..<br \/>\n#tar -zxvf openssl-1.0.0ek.tar.gz<br \/>\n#cd openssl-1.0.0ek<br \/>\n#.\/config \u2013prefix=\/usr\/local\/openssl<br \/>\n#make<br \/>\n#make install<br \/>\n<\/strong><br \/>\n3\uff0c\u5b89\u88c5openvpn:<br \/>\n<strong>#cd ..<br \/>\n#tar -zxvf openvpn-2.2.1.tar.gz<br \/>\n#cd openvpn-2.2.1<br \/>\n#.\/configure -prefix=\/usr\/local\/openvpn -with-lzo-headers=\/usr\/local\/lzo\/include -with-lzo-lib=\/usr\/local\/lzo\/lib -with-ssl-headers=\/usr\/local\/ssl\/include -with-ssl-lib=\/usr\/local\/ssl\/lib<\/strong><\/p>\n<p><strong>#make<br \/>\n#make install<\/strong><\/p>\n<p>&nbsp;<\/p>\n<p><strong>\u4e09\uff0c\u914d\u7f6eOpenVPN Server<\/strong><br \/>\n1,\u521b\u5efa\u914d\u7f6e\u73af\u5883<br \/>\n<strong># mkdir -p \/usr\/local\/openvpn\/etc<br \/>\n# cp -R \/usr\/local\/src\/openvpn\/openvpn-2.2.1\/easy-rsa \/usr\/local\/openvpn\/etc\/.<\/strong><\/p>\n<p><strong>#cd \/usr\/local\/openvpn\/etc\/easy-rsa\/2.0<br \/>\n#ls <\/strong><\/p>\n<p>\u7ed3\u679c\u662f\u7a0b\u5e8f\u4ee5\u53ca\u811a\u672c\uff0c\u8fd9\u91cc\u7b80\u8981\u7684\u8bf4\u660e\u4e00\u4e0b\uff1a<br \/>\nvars\u00a0\u00a0\u00a0 \u00a0\u00a0\u00a0 \u00a0\u00a0\u00a0 \u00a0\u00a0\u00a0 \u811a\u672c\uff0c\u662f\u7528\u6765\u521b\u5efa\u73af\u5883\u53d8\u91cf\uff0c\u8bbe\u7f6e\u6240\u9700\u8981\u7684\u53d8\u91cf\u7684\u811a\u672c<br \/>\nclean-all\u00a0\u00a0 \u00a0\u00a0\u00a0 \u00a0\u00a0\u00a0 \u811a\u672c\uff0c\u662f\u521b\u5efa\u751f\u6210ca\u8bc1\u4e66\u53ca\u5bc6\u94a5\u6587\u4ef6\u6240\u9700\u8981\u7684\u6587\u4ef6\u53ca\u76ee\u5f55<br \/>\nbuild-ca\u00a0\u00a0 \u00a0\u00a0 \u00a0 \u00a0\u00a0\u00a0 \u811a\u672c\uff0c\u751f\u6210ca\u8bc1\u4e66(\u4ea4\u4e92)<br \/>\nbuild-dh\u00a0\u00a0 \u00a0\u00a0 \u00a0 \u00a0\u00a0\u00a0 \u811a\u672c\uff0c\u751f\u6210Diff-Hellman\u6587\u4ef6(\u4ea4\u4e92)<br \/>\nbuild-key-server\u00a0\u00a0\u00a0 \u811a\u672c\uff0c\u751f\u6210\u670d\u52a1\u5668\u7aef\u5bc6\u94a5(\u4ea4\u4e92)<br \/>\nbuild-key\u00a0\u00a0 \u00a0\u00a0 \u00a0\u00a0 \u00a0 \u811a\u672c\uff0c\u751f\u6210\u5ba2\u6237\u7aef\u5bc6\u94a5(\u4ea4\u4e92)<br \/>\npkitool\u00a0\u00a0 \u00a0\u00a0 \u00a0\u00a0 \u00a0\u00a0\u00a0 \u811a\u672c\uff0c\u76f4\u63a5\u4f7f\u7528vars\u7684\u73af\u5883\u53d8\u91cf\u8bbe\u7f6e\uff0c\u76f4\u63a5\u751f\u6210\u8bc1\u4e66(\u975e\u4ea4\u4e92)<\/p>\n<p>2,\u751f\u6210CA\u8bc1\u4e66\u53ca\u5bc6\u94a5[\u6ce8\u610f\u5b57\u7b26\u8f93\u5165\u4e0d\u8981\u51fa\u9519]<br \/>\n\u521d\u59cb\u5316\u7cfb\u7edf\u73af\u5883\u53d8\u91cf\uff0c\u4f60\u53ef\u4ee5\u770b\u4e00\u4e0b\u8fd9\u4e2a\u811a\u672c\u7684\u5185\u5bb9\u5c31\u77e5\u9053\u5b83\u5728\u5e72\u4ec0\u4e48\u4e86\uff1a<br \/>\n<strong>#.\/vars<br \/>\nNOTE: If you run .\/clean-all, I will be doing a rm -rf on \/usr\/local\/openvpn\/etc\/easy-rsa\/2.0\/keys<\/strong><\/p>\n<p>\u8bf7\u7406\u89e3\u8b66\u544a\u7684\u610f\u601d\u3002<\/p>\n<p><strong>#chmod +rwx *<br \/>\n#source .\/vars<\/strong><\/p>\n<p>\u751f\u6210\u5e76\u521d\u59cbkeys\u6587\u4ef6\u5939<br \/>\n<strong>#.\/clean-all<\/strong><\/p>\n<p>\u4fee\u6539vars\u6587\u4ef6\uff0c\u5185\u5bb9\u5982\u4e0b\uff1a<br \/>\n<strong>export KEY_COUNTRY=\u201dCN\u201d<br \/>\nexport KEY_PROVINCE=\u201dGD\u201d<br \/>\nexport KEY_CITY=\u201dGZ\u201d<br \/>\nexport KEY_ORG=\u201dHGTA\u201d<br \/>\nexport KEY_EMAIL=<a href=\"mailto:hgta23@gmail.com\" target=\"_blank\">\u201chgta23@gmail.com\u201d<\/a><br \/>\n<\/strong><br \/>\n\u4fee\u6539\u5b8c\u4fdd\u5b58\u540e\uff0c\u5373\u53ef\u751f\u6210ca\u8bc1\u4e66\u53ca\u5bc6\u94a5\u6587\u4ef6\u4e86\uff1a<br \/>\n<strong>#source .\/vars<\/strong><\/p>\n<p>\u751f\u6210Root Ca\u8bc1\u4e66, \u7528\u4e8e\u7b7e\u53d1Server\u548cClient\u8bc1\u4e66<br \/>\n<strong>#.\/build-ca<br \/>\n# ls keys<\/strong><br \/>\n\u53ef\u4ee5\u770b\u5230\u5df2\u7ecf\u751f\u6210\u4e86ca.crt ca.key\u6587\u4ef6<br \/>\n\u751f\u6210Diffie-Hellman\u6587\u4ef6<br \/>\n<strong>#.\/build-dh<br \/>\n#ls -l keys\/dh1024.pem<\/strong><br \/>\n\u53ef\u4ee5\u770b\u5230\u751f\u6210\u4e861024\u4f4d\u7684Diffie-Hellman\u6587\u4ef6<br \/>\n\u751f\u6210\u670d\u52a1\u5668\u4f7f\u7528\u7684VPN server Ca\u8bc1\u4e66<br \/>\n<strong>#.\/build-key-server itcht-server<\/strong><br \/>\n\u6839\u636e\u63d0\u793a\u8f93\u5165\u76f8\u5173\u4fe1\u606f\uff0c<br \/>\nitcht-server\u662f\u4f60\u4e3aCA\u8bc1\u4e66\u8d77\u7684\u4e00\u4e2a\u540d\u5b57, \u4ee5server\u540d\u5b57\u4e3a\u4f8b,\u751f\u6210\u7684\u670d\u52a1\u5668\u4f7f\u7528\u7684CA\u8bc1\u4e66\u6587\u4ef6\u4e3a: itcht-server.crt itcht-server.key<br \/>\n\u5c06\u751f\u6210\u7684CA\u8bc1\u4e66\u53ca\u5bc6\u94a5\u62f7\u8d1d\u5230<strong>\/usr\/local\/openvpn\/etc<\/strong> \u4e0b\uff1a<\/p>\n<p><strong>#cp keys\/ca.* \/usr\/local\/openvpn\/etc\/.<br \/>\n#cp keys\/itcht-server.* \/usr\/local\/openvpn\/etc\/.<br \/>\n#cp keys\/dh1024.pem \/usr\/local\/openvpn\/etc\/.<\/strong><\/p>\n<p>\u751f\u6210\u5ba2\u6237\u7aefCA\u8bc1\u4e66\u53ca\u5bc6\u94a5<br \/>\n\u751f\u6210\u5ba2\u6237\u7aefCA\u8bc1\u4e66\u53ca\u5bc6\u94a5\u4f7f\u7528:build-key\u7a0b\u5e8f\u5373\u53ef<br \/>\n<strong>#.\/build-key itcht-user1<\/strong><br \/>\n\u6839\u636e\u63d0\u793a\u8f93\u5165\u76f8\u5173\u4fe1\u606f\uff0c<br \/>\n\u5c06\u5728keys\u76ee\u5f55\u4e0b\u751f\u6210itcht-user1.crt itcht-user1.csr itcht-user1.key\u4e09\u4e2a\u5ba2\u6237\u7aef\u8bc1\u4e66<br \/>\n\u5c06ca.crt ca.key itcht-user1.crt itcht-user1.csr itcht-user1.key\u4e94\u4e2a\u6587\u4ef6\u6253\u5305,\u4ee5\u5907\u5ba2\u6237\u7aefvpn\u4f7f\u7528<br \/>\n<strong><br \/>\n#mkdir itcht-user1-key<br \/>\n#cp keys\/ca.* .\/itcht-user1-key\/.<br \/>\n#cp keys\/itcht-user1.* .\/itcht-user1-key\/.<\/strong><\/p>\n<p><strong>#tar -czvf itcht-user1-key.tar.gz itcht-user1-key<br \/>\n<\/strong> \u4e0a\u9762\u8fd9\u4ef6\u6253\u5305\u6587\u4ef6\u8981COPY\u5230\u5ba2\u6237\u7aef\u65f6\u4f7f\u7528<\/p>\n<p>\u751f\u6210openvpn\u914d\u7f6e\u6587\u4ef6<br \/>\n\u521b\u5efaopenvpn \u914d\u7f6e\u6587\u4ef6\u6700\u597d\u7684\u65b9\u6cd5\u662f\u5148\u770bopenvpn \u7684\u6837\u4f8b\u6587\u4ef6,\u5728\u6e90\u7801\u76ee\u5f55\u4e0b\u7684sample-config-files\u4e0b,\u672c\u4f8b\u4e3a<br \/>\n\/usr\/local\/src\/openvpn\/openvpn-2.2.1\/sample-config-files<br \/>\n\u670d\u52a1\u5668\u7aef\u914d\u7f6e\u6587\u4ef6\u540d: server.conf<br \/>\n\u5ba2\u6237\u7aef\u914d\u7f6e\u6587\u4ef6\u540d\u4e3a: client.conf<br \/>\n\u53ef\u4ee5\u6839\u636e\u9700\u8981\u4fee\u6539.<br \/>\n<strong>#cp \/usr\/local\/src\/openvpn\/openvpn-2.2.1\/sample-config-files\/server.conf \/usr\/local\/openvpn\/etc\/server.conf<br \/>\n#mkdir -p \/usr\/local\/openvpn\/logs<br \/>\n#groupadd nobody<br \/>\n#vi\/usr\/local\/openvpn\/etc\/server.conf<\/strong><\/p>\n<p>&nbsp;<\/p>\n<p>\u5728 \/etc\/resolv.conf \u4e2d\u627e\u5230\u4f60\u670d\u52a1\u5668\u7684nameserver\u5730\u5740:<\/p>\n<p>\u5982\uff1a<\/p>\n<pre><tt>vi \/etc\/resolv.conf \r\nnameserver <tt><tt>218.85.157.99<\/tt><\/tt> \r\nnameserver <tt><tt>218.85.152.99<\/tt><\/tt> \r\n\u8fd9\u4e24\u4e2a\u5730\u5740\u7528\u5728\u586b\u5165\u4e0b\u9762\u7684conf\u7684\u4ee5\u4e0b\u4e24\u884c \r\npush \u201cdhcp-option DNS 218.85.157.99\u2033 \r\npush \u201cdhcp-option DNS 218.85.152.99\u2033 <\/tt><\/pre>\n<p><strong><span style=\"color: #ff0000;\">\u4ee5\u4e0bconf \u5185\u5bb9\u6211\u628a\u4e00\u4e9b\u6ce8\u91ca\u53bb\u6389\u4e86\uff0c\u6ca1\u8d34\u4e0a\u6765(#\u53f7\u548c;\u53f7\u90fd\u4ee3\u8868\u6ce8\u91ca\uff0c\u4ee5\u8fd9\u4e24\u4e2a\u5b57\u7b26\u5f00\u5934\u7684\u914d\u7f6e\u90fd\u662f\u4e0d\u8d77\u6548\u7684)<\/span><\/strong><\/p>\n<p>;local a.b.c.d<br \/>\n#port 1194<br \/>\nport 5194<br \/>\n#proto udp<br \/>\nproto tcp<br \/>\n;dev tap<br \/>\ndev tun<br \/>\n;dev-node MyTap<br \/>\nca \/usr\/local\/openvpn\/etc\/ca.crt<br \/>\n#cert server.crt<br \/>\ncert \/usr\/local\/openvpn\/etc\/itcht-server.crt<br \/>\nkey \/usr\/local\/openvpn\/etc\/ itcht-server.key\u00a0 # This file should be kept secret<br \/>\ndh \/usr\/local\/openvpn\/etc\/dh1024.pem<br \/>\n#server 10.8.0.0 255.255.255.0<br \/>\nserver 172.16.0.0 255.255.0.0<br \/>\nifconfig-pool-persist ipp.txt<br \/>\n;server-bridge 10.8.0.4 255.255.255.0 10.8.0.50 10.8.0.100<\/p>\n<p>;push \u201croute 192.168.10.0 255.255.255.0\u2033<br \/>\npush \u201croute 172.16.0.0 255.255.0.0\u2033<br \/>\n;push \u201croute 192.168.20.0 255.255.255.0\u2033;<\/p>\n<p>client-config-dir ccd<br \/>\n;route 192.168.40.128 255.255.255.248<br \/>\n;client-config-dir ccd<br \/>\n;route 10.9.0.0 255.255.255.252<br \/>\n#\u00a0\u00a0 ifconfig-push 10.9.0.1 10.9.0.2<br \/>\n;learn-address .\/script<br \/>\n# of 0.0.0.0\/0.0.0.0.<br \/>\n;push \u201credirect-gateway\u201d<br \/>\npush \u201credirect-gateway\u201d<br \/>\n;push \u201cdhcp-option DNS 10.8.0.1\u2033<br \/>\n<tt><tt># name server \u5730\u5740<\/tt><\/tt><\/p>\n<p><tt><tt><\/tt><\/tt> push \u201cdhcp-option DNS 218.85.157.99\u2033<br \/>\npush \u201cdhcp-option DNS 218.85.152.99\u2033<br \/>\n;push \u201cdhcp-option WINS 10.8.0.1\u2033<br \/>\n;client-to-client<br \/>\nclient-to-client<br \/>\n;duplicate-cn<br \/>\nduplicate-cn<br \/>\nkeepalive 10 120<br \/>\n;tls-auth ta.key 0 # This file is secret<br \/>\n;cipher BF-CBC\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 # Blowfish (default)<br \/>\n;cipher AES-128-CBC\u00a0\u00a0 # AES<br \/>\n;cipher DES-EDE3-CBC\u00a0 # Triple-DES<br \/>\ncomp-lzo<br \/>\n;max-clients 100<br \/>\nuser nobody<br \/>\ngroup nobody<br \/>\npersist-key<br \/>\npersist-tun<br \/>\nstatus \/usr\/local\/openvpn\/logs\/openvpn-status.log<br \/>\n;log\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 openvpn.log<br \/>\nlog\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 \/usr\/local\/openvpn\/logs\/openvpn.log<br \/>\n;log-append\u00a0 openvpn.log<br \/>\nlog-append\u00a0 \/usr\/local\/openvpn\/logs\/openvpn.log<br \/>\nverb 3<br \/>\n;mute 20<\/p>\n<pre><tt><tt>script-security 3<\/tt><\/tt><\/pre>\n<p>\u4ee5\u4e0a\u4e3aServer\u7aef\u914d\u7f6e\u6587\u4ef6\u5185\u5bb9\u3002<\/p>\n<p><strong>\u5207\u8bb0\uff1a\u4ee5\u4e0a\u7684\u6587\u7ae0\u4e2d\u4f7f\u7528\u5230\u7684\u6587\u4ef6\u6700\u597d\u7528\u7ea6\u5bf9\u8def\u5f84\u6765\u6307\u5b9a\u3002\u5426\u5219\u5728\u6267\u884c\u65f6\uff0c\u4e0d\u5728\u5f53\u524d\u76ee\u5f55\uff0c\u5c31\u65e0\u6cd5\u627e\u5230\u76f8\u5173 \u6587\u4ef6\u3002\u9020\u6210\u542f\u52a8\u5931\u8d25\u3002<\/strong><\/p>\n<p><strong>\u56db\uff0c\u670d\u52a1\u7aef\u7684NAT\u914d\u7f6e\uff1a<\/strong><br \/>\n\u7f16\u8f91:\/etc\/sysctl.conf,\u66f4\u6539<strong>net.ipv4.ip_forward=0 <\/strong> \u4e3a<strong>net.ipv4.ip_forward=1<\/strong><br \/>\n<strong>#vi \/etc\/sysctl.conf<br \/>\nnet.ipv4.ip_forward=1<\/strong><\/p>\n<p><strong>\u6216\u8005\uff1a<br \/>\n#echo \u201c1\u2033 &gt; \/proc\/sys\/net\/ipv4\/ip_forward<br \/>\n<\/strong><br \/>\n\u5e76\u6267\u884c\u5982\u4e0b\u6307\u4ee4[\u6211\u7684\u5916\u7f51\u7f51\u5361\u662feth0,\u4e3a\u4e24\u4e2a\u7f51\u6bb5\u505aNAT]<br \/>\n<strong>#\/sbin\/iptables -A POSTROUTING -t nat -s 192.168.0.0\/255.255.255.0 -o eth0 -j MASQUERADE<br \/>\n#\/sbin\/iptables -A POSTROUTING -t nat -s 172.16.0.0\/255.255.0.0 -o eth0 -j MASQUERADE<\/strong><\/p>\n<p>&nbsp;<\/p>\n<p><strong>\u4e94\uff0c\u542f\u52a8\u670d\u52a1\u5668<\/strong><br \/>\n\u542f\u52a8OpenSVN Server:<br \/>\n<strong>#\/usr\/local\/sbin\/openvpn &#8211;config \/usr\/local\/openvpn\/etc\/server.conf<\/strong><\/p>\n<p>&nbsp;<\/p>\n<p><strong>\u516d\uff0cWINDOWS XP\u5ba2\u6237\u7aef\u5b89\u88c5\u53ca\u8bbe\u7f6e\uff1a<\/strong><br \/>\n\u4e0b\u8f7d\u5ba2\u6237\u7aef[\u5207\u8bb0\u7248\u672c\u8981\u5bf9\u4e0a\u53f7\uff0c\u5426\u5219\u5c31\u4f1a\u4ea7\u751f\u4e00\u4e9b\u9ebb\u70e6]\uff1a<br \/>\n<a href=\"http:\/\/www.openvpn.net\/release\/openvpn-2.0.9-install.exe\">http:\/\/www.openvpn.net\/<\/a><\/p>\n<p>\u5230\u5b98\u7f51\u4e0b\u8f7dwindow\u5ba2\u6237\u7aef\u7248\u672c\u5373\u53ef<\/p>\n<p>\u5b89\u88c5\u4e4b\uff1a<br \/>\n\u5c06\u4e4b\u524d\u4ea7\u751f\u7684<strong>itcht-user1-key.tar.gz<\/strong> \u538b\u7f29\u6587\u4ef6\u89e3\u538b\u5230 C:\\Program Files\\OpenVPN\\config:<br \/>\n\u5176\u4e2d\u9700\u5c06client.conf\u6539\u4e3aclient.ovpn\uff0c\u5e76\u505a\u76f8\u5e94\u7684\u6539\u53d8\uff0c\u4e3b\u8981\u662f\uff1a<br \/>\n<strong>cert itcht-user1.crt<br \/>\nkey itcht-user1.key<\/strong><\/p>\n<p>\u5185\u5bb9\u5982\u4e0b:<br \/>\n<strong><span style=\"color: #ff0000;\">\u4ee5\u4e0bconf \u5185\u5bb9\u6211\u628a\u4e00\u4e9b\u6ce8\u91ca\u53bb\u6389\u4e86\uff0c\u6ca1\u8d34\u4e0a\u6765(#\u53f7\u548c;\u53f7\u90fd\u4ee3\u8868\u6ce8\u91ca\uff0c\u4ee5\u8fd9\u4e24\u4e2a\u5b57\u7b26\u5f00\u5934\u7684\u914d\u7f6e\u90fd\u662f\u4e0d\u8d77\u6548\u7684)<\/span><\/strong><\/p>\n<p># from the server.<br \/>\nclient<br \/>\n;dev tap<br \/>\ndev tun<br \/>\n;dev-node MyTap<br \/>\n;proto udp<br \/>\nproto tcp<br \/>\nremote \u8fd9\u91cc\u586b\u4f60\u670d\u52a1\u7684\u5730\u5740 5194<br \/>\n;remote-random<br \/>\nresolv-retry infinite<\/p>\n<p># Most clients don\u2019t need to bind to<br \/>\n# a specific local port number.<br \/>\nnobind<\/p>\n<p># Downgrade privileges after initialization (non-Windows only)<br \/>\n;user nobody<br \/>\n;group nobody<\/p>\n<p># Try to preserve some state across restarts.<br \/>\npersist-key<br \/>\npersist-tun<br \/>\n;http-proxy-retry # retry on connection failures<br \/>\n;http-proxy [proxy server] [proxy port #]<br \/>\n;mute-replay-warnings<br \/>\nca ca.crt<br \/>\ncert itcht-user1.crt<br \/>\nkey itcht-user1.key<br \/>\nns-cert-type server<br \/>\n;tls-auth ta.key 1<br \/>\n;cipher x<br \/>\ncomp-lzo<br \/>\nverb 3<br \/>\n;mute 20<\/p>\n<p><strong>\u4e03\uff0c\u8fde\u63a5OpenVPN\u670d\u52a1\u5668\uff1a<\/strong><br \/>\n<strong>\u53f3\u51fbclient.ovpn\u6587\u4ef6\uff0c\u9009\u62e9\u201dStart OpenVPN on this config file\u201d:<\/strong><br \/>\n\u7cfb\u7edf\u5c31\u4f1a\u6709\u5982\u4e0b\u4e00\u5806\u4fe1\u606f\uff1a<br \/>\n&#8230;&#8230;..<br \/>\nSat Sep 05 07:50:43 2009 C:\\WINDOWS\\system32\\route.exe ADD 0.0.0.0 MASK 128.0.0.0 172.16.0.5<br \/>\nSat Sep 05 07:50:43 2009 Route addition via IPAPI succeeded [adaptive]<br \/>\nSat Sep 05 07:50:43 2009 C:\\WINDOWS\\system32\\route.exe ADD 128.0.0.0 MASK 128.0.0.0 172.16.0.5<br \/>\nSat Sep 05 07:50:43 2009 Route addition via IPAPI succeeded [adaptive]<br \/>\nSat Sep 05 07:50:43 2009 C:\\WINDOWS\\system32\\route.exe ADD 172.16.0.0 MASK 255.255.0.0 172.16.0.5<br \/>\nSat Sep 05 07:50:43 2009 Route addition via IPAPI succeeded [adaptive]<br \/>\nSat Sep 05 07:50:43 2009 C:\\WINDOWS\\system32\\route.exe ADD 172.16.0.0 MASK 255.255.0.0 172.16.0.5<br \/>\nSat Sep 05 07:50:43 2009 Route addition via IPAPI succeeded [adaptive]<br \/>\nSat Sep 05 07:50:43 2009 Initialization Sequence Completed<\/p>\n<p>\u5230\u8fd9\u91cc\u7ed3\u675f\u5c31\u7b97\u6210\u529f\u4e86<\/p>\n<p>\u770b\u4e00\u4e0b\u6211\u7684IP\u4fe1\u606f\uff1a<br \/>\nC:\\ipconfig \/all<\/p>\n<p>\u4f1a\u6709\u7c7b\u4f3c\u5982\u4e0b\u4fe1\u606f<br \/>\nEthernet adapter Local Area Connection 3:<br \/>\nConnection-specific DNS Suffix . :<br \/>\nDescription . . . . . . . . . . . : TAP-Win32 Adapter V8<br \/>\nPhysical Address. . . . . . . . . : 00-FF-AA-B0-60-2B<br \/>\nDhcp Enabled. . . . . . . . . . . : Yes<br \/>\nAutoconfiguration Enabled . . . . : Yes<br \/>\nIP Address. . . . . . . . . . . . : 172.16.0.6<br \/>\nSubnet Mask . . . . . . . . . . . : 255.255.255.252<br \/>\nDefault Gateway . . . . . . . . . : 172.16.0.5<br \/>\nDHCP Server . . . . . . . . . . . : 172.16.0.5<br \/>\nDNS Servers . . . . . . . . . . . : \u8fd9\u91cc\u663e\u793adns server ip\u5730\u5740<br \/>\nLease Obtained. . . . . . . . . . : 2011\u5e7410\u670825\u65e5 15:13:52<br \/>\nLease Expires . . . . . . . . . . : 2011\u5e7410\u670825\u65e5 15:13:52<\/p>\n<p>\u53c2\u8003\u6587\u7ae0\uff1a <a href=\"http:\/\/blog.csdn.net\/msconfig_001\/article\/details\/6123949\" target=\"_blank\">http:\/\/blog.csdn.net\/msconfig_001\/article\/details\/6123949<\/a> <a href=\"http:\/\/www.xiaohui.com\/dev\/server\/20070514-install-openvpn.htm\" target=\"_blank\">http:\/\/www.xiaohui.com\/dev\/server\/20070514-install-openvpn.htm<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>\u7cfb\u7edf\u4fe1\u606f\uff1a OS : Debian 6.0 Openvpn\u7248\u672c\uff1a2.2.1 &nbsp; 1. \u5b89\u88c5\u6240\u9700\u7684\u7f16\u8bd1 [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[96],"tags":[134,135],"class_list":["post-495","post","type-post","status-publish","format-standard","hentry","category-96","tag-debian","tag-openvpn"],"_links":{"self":[{"href":"https:\/\/508.me\/index.php?rest_route=\/wp\/v2\/posts\/495","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/508.me\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/508.me\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/508.me\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/508.me\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=495"}],"version-history":[{"count":6,"href":"https:\/\/508.me\/index.php?rest_route=\/wp\/v2\/posts\/495\/revisions"}],"predecessor-version":[{"id":497,"href":"https:\/\/508.me\/index.php?rest_route=\/wp\/v2\/posts\/495\/revisions\/497"}],"wp:attachment":[{"href":"https:\/\/508.me\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=495"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/508.me\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=495"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/508.me\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=495"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}