I-OpenVPN ingenye yezinketho ze-VPN (inethiwekhi yangasese yangasese noma amanethiwekhi wangasese angasese), okuvumela ukuthi kudluliselwe idatha kudatshana elibethelwe ngokukhethekile. Ngale ndlela, ungakwazi ukuxhuma amakhompyutha amabili noma ukwakha inethiwekhi eyinhloko ne-server namakhasimende amaningi. Kulesi sihloko sizofunda ukuthi singayakha kanjani iseva bese siyilungiselela.
Silungiselela iseva ye-OpenVPN
Njengoba kushiwo ngenhla, usebenzisa ubuchwepheshe obubucayi, singadlulisela ulwazi ngaphezu kwesiteshi sokuxhumana esiphephile. Lokhu kungaba ukwabelana ngefayela noma ukufinyelela okuphephile kwi-Inthanethi ngokusebenzisa iseva eyindlela evamile. Ukwenza, asidingi imishini eyengeziwe nolwazi olukhethekile - konke kwenziwa kwikhompyutha ohlela ukuyisebenzisa njengesiphakeli seVPN.
Ukuze uthole umsebenzi oqhubekayo, kuzodingeka futhi ulungiselele ohlangothini lweklayenti kwimishini yabasebenzisi benethiwekhi. Wonke umsebenzi wehla ekwakheni izihluthulelo nezitifiketi, ezidluliselwa kumakhasimende. Lawa mafayela akuvumela ukuba uthole ikheli le-IP uma uxhuma kwisiphakeli bese udala isiteshi esikhishwe ngokukhulunywe ngenhla. Lonke ulwazi oludluliselwa ngalo lungasetshenziswa kuphela ngesikhiye. Lesi sici singathuthukisa kakhulu ukuphepha futhi siqiniseke ubuqotho bemininingwane.
Ukufaka i-OpenVPN kumshini wesiphakeli
Ukufakwa kuyinkambiso ejwayelekile ngezimpawu ezithile, esizoxoxa ngazo ngokuningiliziwe.
- Isinyathelo sokuqala ukulanda uhlelo kusuka kusixhumanisi ngezansi.
Landa i-OpenVPN
- Okulandelayo, sebenzisa isifaki bese ufinyelela ewindini lokukhetha lezinto. Lapha sidinga ukubeka ubusuku eduze nento negama "EasyRSA"evumela ukuthi udale amafayela wezitifiketi nezinkinobho, futhi ulawule.
- Isinyathelo esilandelayo yikukhethwa kwendawo yokufaka. Ukuze kube lula, faka uhlelo emmpandeni wesistimu disk C:. Ukwenza lokhu, mane nje ususe okudlulele. Kufanele isebenze
C: OpenVPN
Senza lokhu ukuze sigweme ukwehluleka lapho senza izikripthi, ngoba izikhala azivunyelwe. Kodwa-ke, ungawafaka kumaphuzu, kodwa ukulalela kungase kuhluleke, futhi ukuthola amaphutha kulekhodi akulula.
- Emva kwazo zonke izilungiselelo, faka uhlelo kumodi evamile.
Ilungiselela uhlangothi lwesiphakeli
Uma wenza lokhu okulandelayo kufanele uqaphele ngangokunokwenzeka. Noma yiziphi iziphambeko ezizoholela ekusebenziseni iseva. Esinye isidingo - i-akhawunti yakho kufanele ibe namalungelo omlawuli.
- Iya kusiqondisi "lula-rsa"okuyinto esibhekene nayo iyatholakala
C: OpenVPN lula-rsa
Thola ifayela vars.bat.sample.
Qamba kabusha vars.bat (susa igama "isampuli" kanye nephuzu).
Vula leli fayela ku-Notepad ++ umhleli. Lokhu kubalulekile, ngoba leli bhuku elikuvumela ukuthi uhlele kahle futhi ulondoloze amakhodi, okusiza ukugwema amaphutha uma uwasebenzisa.
- Okokuqala, susa wonke amazwana agcizelelwe eluhlaza - azosivimbela kuphela. Sithola okulandelayo:
- Okulandelayo, shintsha indlela eya kufolda "lula-rsa" lowo esikukhulume ngesikhathi sokufakwa. Kulesi simo, vele ususe okuguquguqukayo. % UhleloFiles% bese uyishintsha C:.
- Imingcele emine elandelayo ishiywe ingashintshi.
- Imigqa eseleyo ayihambisani. Isibonelo ku-skrini.
- Londoloza ifayela.
- Kudingeka uhlele amafayela alandelayo:
- ukwakha-ca.bat
- ukwakha-dh.bat
- ukwakha-key.bat
- ukwakha-key-pass.bat
- ukwakha-ukhiye-pkcs12.bat
- ukwakha-key-server.bat
Kudingeka bashintshe ithimba
i-openssl
kuya endleleni ephelele eya efayeleni elihambelanayo openssl.exe. Ungakhohlwa ukugcina izinguquko.
- Manje vula ifolda "lula-rsa"ukuphoqa SHIFT bese uchofoza i-PKM esikhala samahhala (hhayi ngamafayela). Kumenyu yesimo, khetha into "I-Open Command Window".
Izoqala "Lawula umugqa" kanye nokushintshela esiqondisweni esiqondisiwe esivele sigcwalisiwe.
- Faka umyalo ngezansi bese uchofoza ENTER.
vars.bat
- Okulandelayo, sebenzisa enye ifayela "ye-batch."
ihlanzekile-all.bat
- Phinda umyalo wokuqala.
- Isinyathelo esilandelayo ukudala amafayela adingekayo. Ukuze wenze lokhu, sebenzisa umyalo
ukwakha-ca.bat
Ngemva kokubulawa, uhlelo luzohlinzeka ukuqinisekisa idatha esifakile kwifayili ye-vars.bat. Vele ucindezele izikhathi ezimbalwa. ENTERkuze kube khona intambo yokuqala.
- Dala ukhiye we-DH usebenzisa ifayela lokuqalisa
ukwakha-dh.bat
- Silungiselela isitifiketi senxenye yesiphakeli. Kukhona iphuzu elilodwa elibalulekile. Kudingeka abanike igama esibabhalisile kulo vars.bat emgqeni "KEY_NAME". Esikhathini sethu, lokhu Ama-Lumpics. Umyalo ungokulandelayo:
ukwakha-key-server.bat Lumpics
Lapha futhi kudingeka uqinisekise idatha usebenzisa ukhiye ENTER, bese ufaka incwadi kabili "y" (yebo) lapho kudingeka khona (bheka umfanekiso). Umzila womyalo ungavalwa.
- In ikhathalogi yethu "lula-rsa" Kukhona ifolda entsha negama "okhiye".
- Okuqukethwe kwayo kufanele kukopishwe futhi kufakwe kufolda. "ssl"okuyinto okumelwe idalwe emlandweni wempande ohlelweni.
Buka ifolda ngemuva kokufaka amafayela akopishiwe:
- Manje iya kusiqondisi
C: OpenVPN config
Lapha sakha idokhumenti yombhalo (i-PCM - Dala - idokhumenti yombhalo), uyiqambe kabusha iseva.ovpn futhi uvule ku-Notepad ++. Sifaka ikhodi elandelayo:
port 443
proto udp
dev tun
dev-node "i-VPN Lumpics"
dh C: OpenVPN ssl dh2048.pem
ca C: OpenVPN ssl ca.crt
isitifiketi C: OpenVPN ssl Lumpics.crt
ukhiye C: OpenVPN ssl Lumpics.key
iseva 172.16.10.0 255.255.255.0
amakhasimende amaningi 32
ukugcina 10 120
iklayenti-kuya-iklayenti
comp-lzo
ukuphikelela-ukhiye
ukuphikelela ku-tun
cipher DES-CBC
isimo C: OpenVPN log status.log
log C: OpenVPN log openvpn.log
isenzo 4
yisimungulu 20Sicela uqaphele ukuthi amagama ezitifiketi namakhi kufanele afane nalawo asefolda "ssl".
- Okulandelayo, vula "Iphaneli Yokulawula" bese uya "Isikhungo Sokulawula Inethiwekhi".
- Chofoza kusixhumanisi "Ukushintsha izilungiselelo ze-adapter".
- Lapha sidinga ukuthola uxhumano ngokusebenzisa "I-TAP-Windows Adapter V9". Lokhu kungenziwa ngokuchofoza ukuxhumana kwe-RMB nokuya ezindaweni zayo.
- Qamba kabusha "VPN Lumpics" ngaphandle izingcaphuno. Leli gama kufanele lihambisane nepharamitha. "dev-node" efayela iseva.ovpn.
- Isinyathelo sokugcina ukuqala isevisi. Cindezela inhlanganisela yokhiye Win + R, faka umugqa ngezansi bese uchofoza ENTER.
services.msc
- Thola isevisi ngegama "OpenVpnService", chofoza i-RMB bese uya ezindaweni zayo.
- Uhlobo lokuqalisa lushintshiwe "Okuzenzakalelayo", qala isevisi bese uchofoza "Faka isicelo".
- Uma senze konke ngokufanele, isiphambano esibomvu kufanele sishabalale eduze kwe-adaptha. Lokhu kusho ukuthi uxhumano lukulungele ukuya.
Ilungiselela ohlangothini lwekhasimende
Ngaphambi kokuba uqale ukumisa iklayenti, udinga ukwenza izinyathelo ezimbalwa kumshini wesiphakeli - ukhiqiza okhiye kanye nesitifiketi sokulungisa uxhumano.
- Iya kusiqondisi "lula-rsa"ke kufolda "okhiye" bese uvula ifayela index.txt.
- Vula ifayela, susa konke okuqukethwe bese ulondoloza.
- Buyela emuva "lula-rsa" bese ugijima "Lawula umugqa" (SHIFT + i-PCM - Vula iwindi lomyalo).
- Okulandelayo, run vars.batbese udala isitifiketi somthengi.
ukwakha-key.bat vpn-iklayenti
Lesi isitifiketi esijwayelekile sayo yonke imishini enethiwekhi. Ukuze uthole ukuphepha okwandisiwe, ungafaka amafayela akho kukhompyutha ngayinye, kodwa ubize ngokuhlukile (hhayi "vpn-client"futhi "vpn-client1" nokunye). Kulokhu, uzodinga ukuphinda zonke izinyathelo, uqale ngokuhlanza index.txt.
- Isinyathelo sokugcina ukudluliswa kwefayela. vpn-client.crt, i-vpn-client.key, ca.crt futhi dh2048.pem kumakhasimende. Ungakwenza lokhu kunoma iyiphi indlela elula, isibonelo, ubhalele ku-flash flash drive noma udlulisele kunethiwekhi.
Umsebenzi okufanele wenziwe kumshini wamakhasimende:
- Faka i-OpenVPN ngendlela evamile.
- Vula isiqondisi ngenhlelo efakiwe bese uya kufolda "config". Lapha udinga ukufaka isitifiketi sethu namafayela ayisihluthulelo.
- Kufolda efanayo, yakha ifayela lombhalo bese uyiqamba kabusha config.ovpn.
- Vula kumhleli bese ubhala ikhodi elandelayo:
iklayenti
i-resolv-zama futhi okungapheli
nobind
kude 192.168.0.15 443
proto udp
dev tun
comp-lzo
ca cacrt
i-cert vpn-client.crt
ukhiye we-vpn-client.key
dh dh2048.pem
float
cipher DES-CBC
ukugcina 10 120
ukuphikelela-ukhiye
ukuphikelela ku-tun
isenzo 0Kulayini "kude" Ungabhalisa i-IP yangaphandle-ikheli lomshini wesiphakeli - ngakho-ke sithola ukufinyelela kwi-inthanethi. Uma ushiya konke njengoba kunjalo, kuyokwazi kuphela ukuxhumeka kwiseva nge isiteshi sokubethela.
- Vula i-GUV OpenVPN egameni lomlawuli usebenzisa isinqamuleli kwideskithophu, bese usesitimeleni sithola isithonjana esifanayo, chofoza i-PCM bese ukhetha into yokuqala negama "Xhuma".
Lokhu kuqedela ukucushwa kweseva ye-OpenVPN kanye neklayenti.
Isiphetho
Ukuhlela inethiwekhi yakho ye-VPN kuyokuvumela ukuba uvikele ulwazi oludlulisiwe ngangokunokwenzeka, futhi wenze i-intanethi isebenze ngokuphepha nakakhulu. Into eyinhloko ukuthi uqaphele kakhulu lapho uhlela izingxenye zevava neklayenti, ngezenzo ezifanele ongasebenzisa zonke izinzuzo zenethiwekhi yangasese ye-virtual.