養成良好習慣,在安裝前先更新一下軟件包,多數軟件包更新主要是修補漏洞。 |
yum -y update
雖然也是可以不進行更新直接安裝。
安裝 OpenVPN、Firewalld 軟件包以及用於生成各種證書的 EasyRSA
yum -y install openvpn easy-rsa firewalld
如果未能成功安裝 OpenVPN,則可能需要先安裝一下 Epel 庫。
yum install epel-release -y
這裏步驟比較多。
cd ~ /usr/share/easy-rsa/3/easyrsa init-pki
/usr/share/easy-rsa/3/easyrsa build-ca nopass
其中 nopass 表示不加密私鑰,主要是方便後面導出公鑰與頒發服務器證書。
/usr/share/easy-rsa/3/easyrsa gen-dh
/usr/share/easy-rsa/3/easyrsa build-server-full vpn-server nopass
/usr/share/easy-rsa/3/easyrsa build-client-full vpn-client-01 nopass
/usr/share/easy-rsa/3/easyrsa gen-crl
openvpn --genkey --secret pki/ta.key
cp pki/ca.crt /etc/openvpn/ca.crt cp pki/dh.pem /etc/openvpn/dh.pem cp pki/issued/vpn-server.crt /etc/openvpn/server.crt cp pki/private/vpn-server.key /etc/openvpn/server.key cp pki/ta.key /etc/openvpn/ta.key cp pki/crl.pem /etc/openvpn/crl.pem
OpenVPN 配置文件有許多可定製化,具體請查閱官方文檔。
cd /etc/openvpn vim server.conf
將以下內容粘貼進去
# Secure OpenVPN Server Config # Basic Connection Config dev tun proto udp port 1194 keepalive 10 120 max-clients 5 # Certs ca ca.crt cert server.crt key server.key dh dh.pem tls-auth ta.key 0 # Ciphers and Hardening reneg-sec 0 remote-cert-tls client crl-verify crl.pem tls-version-min 1.2 cipher AES-256-CBC auth SHA512 tls-cipher TLS-DHE-RSA-WITH-AES-256-GCM-SHA384:TLS-DHE-RSA-WITH-AES-256-CBC-SHA256:TLS-DHE-RSA-WITH-AES-128-GCM-SHA256:TLS-DHE-RSA-WITH-AES-128-CBC-SHA256 # Drop Privs user nobody group nobody # IP pool server 172.31.100.0 255.255.255.0 topology subnet ifconfig-pool-persist ipp.txt client-config-dir client # Misc persist-key persist-tun comp-lzo # DHCP Push options force all traffic through VPN and sets DNS servers push "redirect-gateway def1 bypass-dhcp" push "dhcp-option DNS 8.8.8.8" push "dhcp-option DNS 8.8.4.4" # Logging log-append /var/log/openvpn.log verb 3
啓動服務端並讓其開機自動啓動
systemctl start openvpn@server systemctl enable openvpn@server
firewall-cmd --permanent --add-service openvpn firewall-cmd --permanent --add-masquerade firewall-cmd --reload
sysctl -a | grep net.ipv4.ip_forward
echo "net.ipv4.ip_forward = 1" >> /etc/sysctl.conf sysctl -p
cd ~ mkdir vpn-client-01-config cp pki/ca.crt vpn-client-01-config/ca.crt cp pki/issued/vpn-client-01.crt vpn-client-01-config/client.crt cp pki/private/vpn-client-01.key vpn-client-01-config/client.key cp pki/ta.key vpn-client-01-config/ta.key
# Secure OpenVPN Client Config #viscosity dns full #viscosity usepeerdns true #viscosity dhcp true tls-client pull client dev tun proto udp remote 123.123.123.123 1194 redirect-gateway def1 nobind persist-key persist-tun comp-lzo verb 3 ca ca.crt cert client.crt key client.key tls-auth ta.key 1 remote-cert-tls server ns-cert-type server key-direction 1 cipher AES-256-CBC tls-version-min 1.2 auth SHA512 tls-cipher TLS-DHE-RSA-WITH-AES-256-GCM-SHA384:TLS-DHE-RSA-WITH-AES-256-CBC-SHA256:TLS-DHE-RSA-WITH-AES-128-GCM-SHA256:TLS-DHE-RSA-WITH-AES-128-CBC-SHA256
remote後面填寫服務端IP地址和使用的端口號,然後將 vpn-client-01-config 的所有文件拷貝到需要鏈接的電腦上,即可開始使用。