¢¡¥µ¡¼¥Ð¦¤Î½àÈ÷
1.openvpn-2.0.5-install.exe¤òhttp://openvpn.net/download.html¤«¤é¥À¥¦¥ó¥í¡¼
¥É
2.openvpn-2.0.5-install.exe¤ò¼Â¹Ô¤·¤Æ¥¤¥ó¥¹¥È¡¼¥ë
3.¥¤¥ó¥¹¥È¡¼¥ë¸å¡¢¼«Æ°ºîÀ®¤µ¤ì¤Æ¤¤¤ë²¾ÁÛNIC¤Î̾Á°¤òȽ¤ê¤ä¤¹¤¤¤â¤Î¤ËÊѹ¹
¡ÖTAP-Win32 Adapter¡×¢ª¡ÖVPN1¡×
¢¡¾ÚÌÀ½ñºîÀ®
1.DOSÁë¤Ò¤é¤¤¤Æ
cd "C:\Program Files\OpenVPN\easy-rsa"
2.°ú¤Â³¤DOSÁë¤Ç
init-config
3.¥Æ¥¥¹¥È¥¨¥Ç¥£¥¿¤Ç
"C:\Program Files\OpenVPN\easy-rsa\vars.bat"¤Î
°Ê²¼¤Î5¹Ô¤òŬÅö¤ËÊÔ½¸
set KEY_COUNTRY=JP
set KEY_PROVINCE=Tokyo
set KEY_CITY=Odaiba
set KEY_ORG=hogehoge
set KEY_EMAIL=hoge@hoge.local
4.DOSÁë¤Ç
vars
clean-all
5.DOSÁë¤Ç
build-ca
ÂÐÏü°¤Î¼ÁÌä¤ËÅú¤¨¤ë
¥¨¥ó¥¿¡¼¥¡¼¤Ç¥Ç¥Õ¥©¥ë¥ÈÃÍ¡§Àè¤Û¤É¤Îvars.bat¤ÎÆâÍÆ
Common Name¤À¤±¼êư¤ÇÆþÎϤ¹¤ëɬÍפ¢¤ê¡ÊŬÅö¤Ëhogehoge-CA¤È¤·¤¿¡Ë
Country Name (2 letter code) [JP]:
State or Province Name (full name) [Tokyo]:
Locality Name (eg, city) [Odaiba]:
Organization Name (eg, company) [hogehoge]:
Organizational Unit Name (eg, section) []:
Common Name (eg, your name or your server’s hostname) []:hogehoge-CA
Email Address [hoge@hoge.local]:
6.DOSÁë¤Ç
build-key-server server
Á°¤Î¥¹¥Æ¥Ã¥×¤ÈƱÍÍ
Common Name¤Ï server
¼¡¤ÎÆó²Õ½ê¤Ïy¤ÈÅú¤¨¤ë
"Sign the certificate? [y/n]"
"1 out of 1 certificate requests certified, commit? [y/n]"
7.DOSÁë¤Ç
build-key client1
¥µ¡¼¥ÐÍÑ¤ÈÆ±Íͤ˥¯¥é¥¤¥¢¥ó¥ÈÍѤξÚÌÀ½ñ¤òºîÀ®
Common Name¤Ï client1 ¢¨build-key¥³¥Þ¥ó¥É¤Ç»ØÄꤷ¤¿¥¯¥é¥¤¥¢¥ó¥È̾¤ÈCommon Name¤òƱ¤¸¤Ë¤¹¤ë
ɬÍפǤ¢¤ì¤ÐɬÍפʥ¯¥é¥¤¥¢¥ó¥È¿ô¤À¤±ºîÀ®
build-key client2
build-key client3
build-key home1
build-key home2
build-key note1
build-key office
¡¦
¡¦
¡¦
¡¦
8.DOSÁë¤Ç
build-dh
openvpn −−genkey −−secret ta.key
9."C:\Program Files\OpenVPN\easy-rsa\keys"¤Ë³Æ¾ÚÌÀ½ñ¥Õ¥¡¥¤¥ë¤¬½ÐÍè¾å¤¬¤Ã¤Æ¤¤¤ë¤Î¤Ç¡¢³Îǧ¤¹¤ë¡£
¥Õ¥¡¥¤¥ë̾ |
ɬÍפȤ¹¤ë¥Þ¥·¥ó |
ÌÜŪ |
ÈëÌ©¤Ë¤¹¤ëɬÍפ¬¤¢¤ë |
ca.crt |
¥µ¡¼¥Ð¤È¥¯¥é¥¤¥¢¥ó¥È |
CA¾ÚÌÀ½ñ |
¤¤¤¤¤¨ |
ca.key |
¸°½ð̾¥Þ¥·¥ó¤À¤± |
CA¸° |
¤Ï¤¤ |
dh1024.pem |
¥µ¡¼¥Ð¤À¤± |
DH¥Ñ¥é¥á¡¼¥¿ |
¤¤¤¤¤¨ |
server.crt |
¥µ¡¼¥Ð¤À¤± |
¥µ¡¼¥Ð¾ÚÌÀ½ñ |
¤¤¤¤¤¨ |
server.key |
¥µ¡¼¥Ð¤À¤± |
¥µ¡¼¥Ð¸° |
¤Ï¤¤ |
client1.crt |
¥¯¥é¥¤¥¢¥ó¥È1¤À¤± |
¥¯¥é¥¤¥¢¥ó¥È1¾ÚÌÀ½ñ |
¤¤¤¤¤¨ |
client1.key |
¥¯¥é¥¤¥¢¥ó¥È1¤À¤± |
¥¯¥é¥¤¥¢¥ó¥È1¸° |
¤Ï¤¤ |
client2.crt |
¥¯¥é¥¤¥¢¥ó¥È2¤À¤± |
¥¯¥é¥¤¥¢¥ó¥È2¾ÚÌÀ½ñ |
¤¤¤¤¤¨ |
client2.key |
¥¯¥é¥¤¥¢¥ó¥È2¤À¤± |
¥¯¥é¥¤¥¢¥ó¥È2¸° |
¤Ï¤¤ |
client3.crt |
¥¯¥é¥¤¥¢¥ó¥È3¤À¤± |
¥¯¥é¥¤¥¢¥ó¥È3¾ÚÌÀ½ñ |
¤¤¤¤¤¨ |
client3.key |
¥¯¥é¥¤¥¢¥ó¥È3¤À¤± |
¥¯¥é¥¤¥¢¥ó¥È3¸° |
¤Ï¤¤ |
¡¦
¡¦
¡¦
|
|
|
|
ta.key |
¥µ¡¼¥Ð¤È¥¯¥é¥¤¥¢¥ó¥È |
TLS¾ÚÌÀÍÑ |
¤Ï¤¤ |
¸å¤ÇɬÍפȤ¹¤ë¥Þ¥·¥ó¤Ë³Æ¥Õ¥¡¥¤¥ë¤ò¥³¥Ô¡¼¤·¤Þ¤¹¡£
¢¨¥³¥Ô¡¼¤¹¤ëºÝ¤Ë¤Ï°ÂÁ´¤ÊÊýË¡¤Ç¡ª
10.¥µ¡¼¥ÐÍÑÀßÄê¥Õ¥¡¥¤¥ë "C:\Program Files\OpenVPN\config\server.ovpn"
port 1194
proto udp
mode server
dev tap
dev-node VPN1
ca ca.crt
cert server.crt
key server.key # This file should be kept secret
dh dh1024.pem
cipher BF-CBC # Blowfish (default)
tls-server
tls-auth ta.key 0 # This file is secret
float
inactive 600
keepalive 10 120
comp-lzo
persist-key
persist-tun
status openvpn-status.log
verb 3
client-to-client
log-append openvpn.log |
¢¡¥µ¡¼¥Ðµ¯Æ°
1.¥Õ¥¡¥¤¥¢¥¦¥©¡¼¥ë¡¦¥ë¡¼¥¿¤ÎÀßÄê¤ò³Îǧ¤¹¤ë
* ¥Õ¥¡¥¤¥¢¥¦¥©¡¼¥ë¤ÇUDP¥Ý¡¼¥È1194¡Ê¤Þ¤¿¤Ï¼«Ê¬¤¬ÀßÄꤷ¤¿Â¾¤ÎTCP/UDP¥Ý¡¼¥È¡Ë¤ò³«¤±¤ë
* ¥ë¡¼¥¿¤ÇUDP¥Ý¡¼¥È1194°¸¤Î¥Ñ¥±¥Ã¥È¤òOpenVPN¥µ¡¼¥Ð¤ËžÁ÷¤¹¤ë¥ë¡¼¥ë¤òÀßÄê¡Ê¥Ý¡¼¥ÈžÁ÷¡Ë
2."C:\Program Files\OpenVPN\config\server.ovpn"¤ò±¦¥¯¥ê¥Ã¥¯¡äStart OpenVPN on this config file
¤Þ¤À¥Æ¥¹¥È¤Ê¤Î¤Ç¡¢DOSÁë¤Çư¤«¤¹¡ÊF4¥¡¼¤Ç½ªÎ»¤Ç¤¤ë¡Ë
¥¨¥é¡¼¤¬½Ð¤Æ¤¤¤ë¤è¤¦¤Ê¤éº£¤Þ¤Ç¤Îºî¶È¤Î¸«Ä¾¤·
¥¯¥é¥¤¥¢¥ó¥È¤«¤é¤ÎÀܳ¤â´Þ¤á¡¢Æ°ºî³Îǧ¤¬½ÐÍ褿¤é¡¢
¥³¥ó¥È¥í¡¼¥ë¥Ñ¥Í¥ë ¡ä ´ÉÍý¥Ä¡¼¥ë ¡ä ¥µ¡¼¥Ó¥¹ ¤ÎÃæ¤Î
OpenVPN Service¤ò¼«Æ°µ¯Æ°¤Ë¤¹¤ë¡£
¢¡Ethernet Bridge 2.0¤Î½àÈ÷
1.Ethernet Bridge 2.0 (x86 build) ebridge_x86.zip¤ò¥À¥¦¥ó¥í¡¼¥Éhttp://www.ntkernel.com/w&p.php?id=20
2.ebridge_x86.zip¤ò²òÅष¤Æebridge_x86.exe¤ò¼Â¹Ô¡¢¥¤¥ó¥¹¥È¡¼¥ë
3.DOSÁë¤Ç
"C:\Program Files\Ethernet Bridge\bin\bridge_cmd.exe"¤ò¼Â¹Ô
°Ê²¼¤Î¤è¤¦¤Ê¾ðÊó¤¬É½¼¨
The following Ethernet interfaces are available to MSTCP:
DEVICE{AAAAAAAA-AAAA-BBBB-CCCC-DDDDDDDDDDDD}
Relates to: Local Area Connection 2
Current MAC: 123456789012
Medium: 0x00000000
Current MTU: 1500
Current bridge status = NOT BRIDGED
DEVICE{11111111-2222-3333-4444-555555555555}
Relates to: Local Area Connection
Current MAC: 210987654321
Medium: 0x00000000
Current MTU: 1500
Current bridge status = NOT BRIDGED |
4.¥µ¡¼¥Ó¥¹²½ÍѤΥ³¥Þ¥ó¥É¤Ï°Ê²¼¤Î¤è¤¦¤Ë¤Ê¤ê¤Þ¤¹¡£
"C:\Program Files\Ethernet Bridge\binbridge_cmd.exe" DEVICE{AAAAAAAA-AAAA-BBBB-CCCC-DDDDDDDDDDDD} DEVICE{11111111-2222-3333-4444-555555555555}
¢¨¥µ¡¼¥Ó¥¹²½¤Ë¤Ä¤¤¤Æ¤Ï¡¢¤¤¤¯¤Ä¤«¥Ä¡¼¥ë¤¬¤¢¤ê¤Þ¤¹¡£¥Í¥Ã¥È¾å¤Ç¸¡º÷¤·¤Æ¤¯¤À¤µ¤¤¡£ 
¢¡¥¯¥é¥¤¥¢¥ó¥È¤Î½àÈ÷
1.openvpn-2.0.5-gui-1.0.3-install.exe¤òhttp://openvpn.se/download.html¤«¤é¥À¥¦¥ó¥í¡¼¥É
2.openvpn-2.0.5-gui-1.0.3-install.exe¤ò¼Â¹Ô¤·¤Æ¥¤¥ó¥¹¥È¡¼¥ë
3.¥¤¥ó¥¹¥È¡¼¥ë¸å¡¢¼«Æ°ºîÀ®¤µ¤ì¤Æ¤¤¤ë²¾ÁÛNIC¤Î̾Á°¤òȽ¤ê¤ä¤¹¤¤¤â¤Î¤ËÊѹ¹
¡ÖTAP-Win32 Adapter¡×¢ª¡ÖVPN1¡×
4.¥¯¥é¥¤¥¢¥ó¥ÈÍÑÀßÄê¥Õ¥¡¥¤¥ë "C:\Program Files\OpenVPN\config\client1.ovpn"
proto udp
dev tap
dev-node VPN1
remote ¥µ¡¼¥Ð¤ÎIP¥¢¥É¥ì¥¹ 1194
resolv-retry infinite
nobind
persist-key
persist-tun
ca ca.crt
cert client1.crt
key client1.key
ns-cert-type server
tls-client
tls-auth ta.key 1
cipher BF-CBC
comp-lzo
verb 3
mute 10
keepalive 10 120 |
5.ɬÍפʾÚÌÀ½ñ¥Õ¥¡¥¤¥ë¤ò¥µ¡¼¥Ð¤«¤é¥³¥Ô¡¼¤·¤Æ¤¯¤ë
"C:\Program Files\OpenVPN\config"¤Ë¥³¥Ô¡¼
¢¨¥³¥Ô¡¼¤¹¤ëºÝ¤Ë¤Ï°ÂÁ´¤ÊÊýË¡¤Ç¡ª
¢¡¥¯¥é¥¤¥¢¥ó¥Èµ¯Æ°¡Ê¥µ¡¼¥Ð¤ËÀܳ¡Ë
1.¥Õ¥¡¥¤¥¢¥¦¥©¡¼¥ëÅù¤Î³Îǧ
2.¥·¥¹¥Æ¥à¥È¥ì¥¤¤Î OpenVPN GUI ¤òW¥¯¥ê¥Ã¥¯¡ÊËô¤Ï±¦¥¯¥ê¥Ã¥¯¡äConnect¡Ë
3.±¦¥¯¥ê¥Ã¥¯¡äView Log¤Ç¥í¥°¤Î³Îǧ¤¬½ÐÍè¤ë
4.ÀÚÃǤϡ¢±¦¥¯¥ê¥Ã¥¯¡äDisconnect
»²¾È¡§http://degas.is.utsunomiya-u.ac.jp/member/zhao/freesw/ovpn2_howto_ja.html
¤³¤ì¤é¤Î¥Ä¡¼¥ë¤Ï¡¢¥»¥¥å¥ê¥Æ¥£¡¼¤ÎÌ̤ǿ¼¹ï¤ÊÌäÂê¤ò°ú¤µ¯¤³¤¹²ÄǽÀ¤¬¤¢¤ê¤Þ¤¹¡£
±¿ÍѤˤϽ½Ê¬¤ËÃí°Õ¤·¤Æ¤¯¤À¤µ¤¤¡£
´ÉÍý¿Í¤ÏÀÕǤ¤òÉ餤¤Þ¤»¤ó¡£