Sei sulla pagina 1di 2

cd /tmp openvpn --mktun --dev tap0 brctl addif br0 tap0 ifconfig tap0 0.0.0.

0 promisc up echo " # Tunnel options mode server proto udp port 1194 dev tap0 keepalive 15 60 daemon verb 3 comp-lzo

# # # # # # # #

Set OpenVPN major mode Setup the protocol (server) TCP/UDP port number TUN/TAP virtual network device Simplify the expression of --ping Become a daemon after all initialization Set output verbosity to n Use fast LZO compression

# OpenVPN server mode options client-to-client # tells OpenVPN to internally route client-to-client traffic duplicate-cn # Allow multiple clients with the same common name # TLS Mode Options tls-server # ca ca.crt # dh dh1024.pem # cert server.crt # key server.key # " > openvpn.conf Enable TLS and assume server role during TLS handshake Certificate authority (CA) file File containing Diffie Hellman parameters Local peer's signed certificate Local peer's private key

echo " -----BEGIN CERTIFICATE----MIIDnDCCAwWgAwIBAgIJAKHdfceiSTlZMA0GCSqGSIb3DQEBBQUAMIGRMQswCQYD VQQGEwJVUzELMAkGA1UECBMCQ0ExFTATBgNVBAcTDFNhbkZyYW5jaXNjbzEQMA4G A1UEChMHT3BlblZQTjELMAkGA1UECxMCY2ExCzAJBgNVBAMTAmNhMREwDwYDVQQp EwhjaGFuZ2VtZTEfMB0GCSqGSIb3DQEJARYQbWFpbEBob3N0LmRvbWFpbjAeFw0x MTA3MDgwODE4NDJaFw0yMTA3MDUwODE4NDJaMIGRMQswCQYDVQQGEwJVUzELMAkG A1UECBMCQ0ExFTATBgNVBAcTDFNhbkZyYW5jaXNjbzEQMA4GA1UEChMHT3BlblZQ TjELMAkGA1UECxMCY2ExCzAJBgNVBAMTAmNhMREwDwYDVQQpEwhjaGFuZ2VtZTEf MB0GCSqGSIb3DQEJARYQbWFpbEBob3N0LmRvbWFpbjCBnzANBgkqhkiG9w0BAQEF AAOBjQAwgYkCgYEAzv9/xg4kfd6bNVJaDTNaAr1UeFDYGwI1EvxMVym0OAq3gbtD uMv36/7ieZirhlzcH75fLoY2SZXp+1FjXQG62a+9QzqFnn+hdRknthOIEYW2pl1i hEYGil90Bhz1b7lTGhv1d+5+9DQdtmKZnkW79+YfaK9nKOg0RdFKcplpa88CAwEA AaOB+TCB9jAdBgNVHQ4EFgQUT6Go8ungWqiAVRS7k7fEiBgDUOswgcYGA1UdIwSB vjCBu4AUT6Go8ungWqiAVRS7k7fEiBgDUOuhgZekgZQwgZExCzAJBgNVBAYTAlVT MQswCQYDVQQIEwJDQTEVMBMGA1UEBxMMU2FuRnJhbmNpc2NvMRAwDgYDVQQKEwdP cGVuVlBOMQswCQYDVQQLEwJjYTELMAkGA1UEAxMCY2ExETAPBgNVBCkTCGNoYW5n ZW1lMR8wHQYJKoZIhvcNAQkBFhBtYWlsQGhvc3QuZG9tYWluggkAod19x6JJOVkw DAYDVR0TBAUwAwEB/zANBgkqhkiG9w0BAQUFAAOBgQAmaP1TAyof16Sp9GTli8GZ mdDzGws9mzy3Xg+UIa1UMDyKmHG6Z5XM3oxEMV3bQ1h6XaB22DzxDYIGGZczsE8I 5saiYw6mF5MahF/iGtwhyE9egsZVq4LVLJrwKmF0AJ2pPFOySpqJ6ntqx4JNA2ms vqc3eO+bOUUJMWgzdozZTQ== -----END CERTIFICATE----" > ca.crt echo " -----BEGIN PRIVATE KEY----MIICdwIBADANBgkqhkiG9w0BAQEFAASCAmEwggJdAgEAAoGBALixQbfmGwjMYLQX akN2SBFjaOA18aCCVIxuqniLbm9+py4n3Y0sxk4UJdEg3lfOoky5M+FQodUMSIFt 580QNaUnXGwG8WOdPDIBVrhVDXSoavCHKL99ruP1ozBDIuHHYDTjcBaPfasMPrPf eu3rY3Mhwkb2PsSmnWor79EInPYdAgMBAAECgYEAhaLcZm/9B7S6FBUNMpsXMl23 uOPPXdBv1N0ORAK/ebUuylrWGBxZsI0rf9JEj0xYayNmwpVRQ5KLs/sOSnZ8GTU0 r1QLHRbxNE/Z4p8vpD6DV7cznfE6rEnVrx1y7ncWtGhCYXMlEL/lIpYfVEfCchAk

AwmnVDusNUjDOi4FJoECQQDg3wLpS/Gc3TxozI2eVnau/J3DhMt9D4N7H5CuJ+UT JBibJJY7kwqSm2cEH+QZwJ0Oi9aT00Dfgxdr32rXsBnlAkEA0kJj/nj6AzsH0NL4 J+DNOXXN8h1qKWOjkbejidOkkSNHoK/RqketVxOvWjCixqbHNEirQ1VDMddElESk M/7H2QJAH9r3ypzbiWE94Yq4tSmCfp+CqePx/7Fm6tY55LH6HZALfE7eiWn3IXWq TkdGRO+oUBs3NpHCqucjNkDcHdnwkQJBANGEqtP3hVsWxbEHqZVDY/2wMGrleNaJ nYMlNWewaLrgJw4uZYWDK24sBX6gHHRL2RF2oILWQcE2u/XreJz/c/ECQAmfaUuU qNbtusMbI4PU6MVqqVM7NCF5PuPiiJeWJVVX32oeniL/KcnuSoJ8DgwE3cBtlv2s NXOQXcdsqgtY6rw= -----END PRIVATE KEY----" > server.key chmod 600 server.key echo " -----BEGIN CERTIFICATE----MIIECDCCA3GgAwIBAgIBATANBgkqhkiG9w0BAQQFADCBkTELMAkGA1UEBhMCVVMx CzAJBgNVBAgTAkNBMRUwEwYDVQQHEwxTYW5GcmFuY2lzY28xEDAOBgNVBAoTB09w ZW5WUE4xCzAJBgNVBAsTAmNhMQswCQYDVQQDEwJjYTERMA8GA1UEKRMIY2hhbmdl bWUxHzAdBgkqhkiG9w0BCQEWEG1haWxAaG9zdC5kb21haW4wHhcNMTEwNzA4MDgy MDA0WhcNMjEwNzA1MDgyMDA0WjCBmzELMAkGA1UEBhMCVVMxCzAJBgNVBAgTAkNB MRUwEwYDVQQHEwxTYW5GcmFuY2lzY28xEDAOBgNVBAoTB09wZW5WUE4xEDAOBgNV BAsTB3NlcnZlcjExEDAOBgNVBAMTB3NlcnZlcjExETAPBgNVBCkTCGNoYW5nZW1l MR8wHQYJKoZIhvcNAQkBFhBtYWlsQGhvc3QuZG9tYWluMIGfMA0GCSqGSIb3DQEB AQUAA4GNADCBiQKBgQC4sUG35hsIzGC0F2pDdkgRY2jgNfGgglSMbqp4i25vfqcu J92NLMZOFCXRIN5XzqJMuTPhUKHVDEiBbefNEDWlJ1xsBvFjnTwyAVa4VQ10qGrw hyi/fa7j9aMwQyLhx2A043AWj32rDD6z33rt62NzIcJG9j7Epp1qK+/RCJz2HQID AQABo4IBYjCCAV4wCQYDVR0TBAIwADARBglghkgBhvhCAQEEBAMCBkAwNAYJYIZI AYb4QgENBCcWJUVhc3ktUlNBIEdlbmVyYXRlZCBTZXJ2ZXIgQ2VydGlmaWNhdGUw HQYDVR0OBBYEFCRvA2vEFGonJHaaie9rLqYItL4LMIHGBgNVHSMEgb4wgbuAFE+h qPLp4FqogFUUu5O3xIgYA1DroYGXpIGUMIGRMQswCQYDVQQGEwJVUzELMAkGA1UE CBMCQ0ExFTATBgNVBAcTDFNhbkZyYW5jaXNjbzEQMA4GA1UEChMHT3BlblZQTjEL MAkGA1UECxMCY2ExCzAJBgNVBAMTAmNhMREwDwYDVQQpEwhjaGFuZ2VtZTEfMB0G CSqGSIb3DQEJARYQbWFpbEBob3N0LmRvbWFpboIJAKHdfceiSTlZMBMGA1UdJQQM MAoGCCsGAQUFBwMBMAsGA1UdDwQEAwIFoDANBgkqhkiG9w0BAQQFAAOBgQAUy2FD rid/5w4sZnizA7NGrsgjjAKAWDQLuCT2PvW6nQQwoPpKS7oyYnHrPyjj5h2P4Hp5 ntaT0Wto1CVQ1fMpwXrv+rP3sLHesWjVTxLE88FEfaqtmyrq9MYp/OY+52FlXxKV jJC6MnyFdkGDt2tV3cE3D0PuAd6OxTz3jQj2cw== -----END CERTIFICATE----" > server.crt echo " -----BEGIN DH PARAMETERS----MIGHAoGBANABY1E5GIK7Pw04UDVY1kfZI5QU3RElIst76IjctuC51NovUHy4OLof 3Df6uy4fsj2Vw6/1wQu7qXWzj2Tyh9wqnu49PGm1zpeiwxC/+IYDd/LbxFz+g0VO IsT0n5970IRO1D1TlCBtBF1xaslyHYfU8KUEnJhcUKT8B5H5UkZ7AgEC -----END DH PARAMETERS----" > dh1024.pem sleep 5 ln -s /usr/sbin/openvpn /tmp/myvpn /tmp/myvpn --config openvpn.conf route add -net 192.168.1.0/24 dev br0

Potrebbero piacerti anche