OpenVPN³¤
¢¡¥µ¡¼¥Ð¦¤Î½àÈ÷
1.openvpn-2.0.5-install.exe¤òhttp://openvpn.net/download.html¤«¤é¥À¥¦¥ó¥í¡¼
¥É
2.openvpn-2.0.5-install.exe¤ò¼Â¹Ô¤·¤Æ¥¤¥ó¥¹¥È¡¼¥ë
3.¥¤¥ó¥¹¥È¡¼¥ë¸å¡¢¼«Æ°ºîÀ®¤µ¤ì¤Æ¤¤¤ë²¾ÁÛNIC¤Î̾Á°¤òȽ¤ê¤ä¤¹¤¤¤â¤Î¤ËÊѹ¹
¡ÖTAP-Win32 Adapter¡×¢ª¡ÖVPN1¡×
¢¡¾ÚÌÀ½ñºîÀ®
1.DOSÁë¤Ò¤é¤¤¤Æ
cd "C:\Program Files\OpenVPN\easy-rsa"
2.°ú¤Â³¤DOSÁë¤Ç
init-config
3.¥Æ¥¥¹¥È¥¨¥Ç¥£¥¿¤Ç
"C:\Program Files\OpenVPN\easy-rsa\vars.bat"¤Î
°Ê²¼¤Î5¹Ô¤òŬÅö¤ËÊÔ½¸
set KEY_COUNTRY=JP
set KEY_PROVINCE=Tokyo
set KEY_CITY=Odaiba
set KEY_ORG=hogehoge
set KEY_EMAIL=hoge@hoge.local
4.DOSÁë¤Ç
vars
clean-all
5.DOSÁë¤Ç
build-ca
ÂÐÏü°¤Î¼ÁÌä¤ËÅú¤¨¤ë
¥¨¥ó¥¿¡¼¥¡¼¤Ç¥Ç¥Õ¥©¥ë¥ÈÃÍ¡§Àè¤Û¤É¤Îvars.bat¤ÎÆâÍÆ
Common Name¤À¤±¼êư¤ÇÆþÎϤ¹¤ëɬÍפ¢¤ê¡ÊŬÅö¤Ëhogehoge-CA¤È¤·¤¿¡Ë
Country Name (2 letter code) [JP]:
State or Province Name (full name) [Tokyo]:
Locality Name (eg, city) [Odaiba]:
Organization Name (eg, company) [hogehoge]:
Organizational Unit Name (eg, section) []:
Common Name (eg, your name or your server’s hostname) []:hogehoge-CA
Email Address [hoge@hoge.local]:
6.DOSÁë¤Ç
build-key-server server
Á°¤Î¥¹¥Æ¥Ã¥×¤ÈƱÍÍ
Common Name¤Ï server
¼¡¤ÎÆó²Õ½ê¤Ïy¤ÈÅú¤¨¤ë
"Sign the certificate? [y/n]"
"1 out of 1 certificate requests certified, commit? [y/n]"
7.DOSÁë¤Ç
build-key client1
¥µ¡¼¥ÐÍÑ¤ÈÆ±Íͤ˥¯¥é¥¤¥¢¥ó¥ÈÍѤξÚÌÀ½ñ¤òºîÀ®
Common Name¤Ï client1 ¢¨build-key¥³¥Þ¥ó¥É¤Ç»ØÄꤷ¤¿¥¯¥é¥¤¥¢¥ó¥È̾¤ÈCommon Name¤òƱ¤¸¤Ë¤¹¤ë
ɬÍפǤ¢¤ì¤ÐɬÍפʥ¯¥é¥¤¥¢¥ó¥È¿ô¤À¤±ºîÀ®
build-key client2
build-key client3
build-key home1
build-key home2
build-key note1
build-key office
¡¦
¡¦
¡¦
¡¦
8.DOSÁë¤Ç
build-dh
openvpn −−genkey −−secret ta.key
9."C:\Program Files\OpenVPN\easy-rsa\keys"¤Ë³Æ¾ÚÌÀ½ñ¥Õ¥¡¥¤¥ë¤¬½ÐÍè¾å¤¬¤Ã¤Æ¤¤¤ë¤Î¤Ç¡¢³Îǧ¤¹¤ë¡£
¥Õ¥¡¥¤¥ë̾ | ɬÍפȤ¹¤ë¥Þ¥·¥ó | ÌÜŪ | ÈëÌ©¤Ë¤¹¤ëɬÍפ¬¤¢¤ë |
ca.crt | ¥µ¡¼¥Ð¤È¥¯¥é¥¤¥¢¥ó¥È | CA¾ÚÌÀ½ñ | ¤¤¤¤¤¨ |
ca.key | ¸°½ð̾¥Þ¥·¥ó¤À¤± | CA¸° | ¤Ï¤¤ |
dh1024.pem | ¥µ¡¼¥Ð¤À¤± | DH¥Ñ¥é¥á¡¼¥¿ | ¤¤¤¤¤¨ |
server.crt | ¥µ¡¼¥Ð¤À¤± | ¥µ¡¼¥Ð¾ÚÌÀ½ñ | ¤¤¤¤¤¨ |
server.key | ¥µ¡¼¥Ð¤À¤± | ¥µ¡¼¥Ð¸° | ¤Ï¤¤ |
client1.crt | ¥¯¥é¥¤¥¢¥ó¥È1¤À¤± | ¥¯¥é¥¤¥¢¥ó¥È1¾ÚÌÀ½ñ | ¤¤¤¤¤¨ |
client1.key | ¥¯¥é¥¤¥¢¥ó¥È1¤À¤± | ¥¯¥é¥¤¥¢¥ó¥È1¸° | ¤Ï¤¤ |
client2.crt | ¥¯¥é¥¤¥¢¥ó¥È2¤À¤± | ¥¯¥é¥¤¥¢¥ó¥È2¾ÚÌÀ½ñ | ¤¤¤¤¤¨ |
client2.key | ¥¯¥é¥¤¥¢¥ó¥È2¤À¤± | ¥¯¥é¥¤¥¢¥ó¥È2¸° | ¤Ï¤¤ |
client3.crt | ¥¯¥é¥¤¥¢¥ó¥È3¤À¤± | ¥¯¥é¥¤¥¢¥ó¥È3¾ÚÌÀ½ñ | ¤¤¤¤¤¨ |
client3.key | ¥¯¥é¥¤¥¢¥ó¥È3¤À¤± | ¥¯¥é¥¤¥¢¥ó¥È3¸° | ¤Ï¤¤ |
¡¦
¡¦
¡¦
|
|||
ta.key | ¥µ¡¼¥Ð¤È¥¯¥é¥¤¥¢¥ó¥È | TLS¾ÚÌÀÍÑ | ¤Ï¤¤ |
¢¨¥³¥Ô¡¼¤¹¤ëºÝ¤Ë¤Ï°ÂÁ´¤ÊÊýË¡¤Ç¡ª
10.¥µ¡¼¥ÐÍÑÀßÄê¥Õ¥¡¥¤¥ë "C:\Program Files\OpenVPN\config\server.ovpn"
port 1194
proto udp
mode serverdev tap
dev-node VPN1ca ca.crt
cert server.crt
key server.key # This file should be kept secret
dh dh1024.pem
cipher BF-CBC # Blowfish (default)tls-server
tls-auth ta.key 0 # This file is secretfloat
inactive 600
keepalive 10 120comp-lzo
persist-key
persist-tunstatus openvpn-status.log
verb 3
client-to-client
log-append openvpn.log
¢¡¥µ¡¼¥Ðµ¯Æ°
1.¥Õ¥¡¥¤¥¢¥¦¥©¡¼¥ë¡¦¥ë¡¼¥¿¤ÎÀßÄê¤ò³Îǧ¤¹¤ë
* ¥Õ¥¡¥¤¥¢¥¦¥©¡¼¥ë¤ÇUDP¥Ý¡¼¥È1194¡Ê¤Þ¤¿¤Ï¼«Ê¬¤¬ÀßÄꤷ¤¿Â¾¤ÎTCP/UDP¥Ý¡¼¥È¡Ë¤ò³«¤±¤ë
* ¥ë¡¼¥¿¤ÇUDP¥Ý¡¼¥È1194°¸¤Î¥Ñ¥±¥Ã¥È¤òOpenVPN¥µ¡¼¥Ð¤ËžÁ÷¤¹¤ë¥ë¡¼¥ë¤òÀßÄê¡Ê¥Ý¡¼¥ÈžÁ÷¡Ë
2."C:\Program Files\OpenVPN\config\server.ovpn"¤ò±¦¥¯¥ê¥Ã¥¯¡äStart OpenVPN on this config file
¤Þ¤À¥Æ¥¹¥È¤Ê¤Î¤Ç¡¢DOSÁë¤Çư¤«¤¹¡ÊF4¥¡¼¤Ç½ªÎ»¤Ç¤¤ë¡Ë
¥¨¥é¡¼¤¬½Ð¤Æ¤¤¤ë¤è¤¦¤Ê¤éº£¤Þ¤Ç¤Îºî¶È¤Î¸«Ä¾¤·
¥¯¥é¥¤¥¢¥ó¥È¤«¤é¤ÎÀܳ¤â´Þ¤á¡¢Æ°ºî³Îǧ¤¬½ÐÍ褿¤é¡¢
¥³¥ó¥È¥í¡¼¥ë¥Ñ¥Í¥ë ¡ä ´ÉÍý¥Ä¡¼¥ë ¡ä ¥µ¡¼¥Ó¥¹ ¤ÎÃæ¤Î
OpenVPN Service¤ò¼«Æ°µ¯Æ°¤Ë¤¹¤ë¡£
¢¡Ethernet Bridge 2.0¤Î½àÈ÷
1.Ethernet Bridge 2.0 (x86 build) ebridge_x86.zip¤ò¥À¥¦¥ó¥í¡¼¥Éhttp://www.ntkernel.com/w&p.php?id=20
2.ebridge_x86.zip¤ò²òÅष¤Æebridge_x86.exe¤ò¼Â¹Ô¡¢¥¤¥ó¥¹¥È¡¼¥ë
3.DOSÁë¤Ç
"C:\Program Files\Ethernet Bridge\bin\bridge_cmd.exe"¤ò¼Â¹Ô
°Ê²¼¤Î¤è¤¦¤Ê¾ðÊó¤¬É½¼¨
The following Ethernet interfaces are available to MSTCP:DEVICE{AAAAAAAA-AAAA-BBBB-CCCC-DDDDDDDDDDDD}
Relates to: Local Area Connection 2
Current MAC: 123456789012
Medium: 0x00000000
Current MTU: 1500
Current bridge status = NOT BRIDGEDDEVICE{11111111-2222-3333-4444-555555555555}
Relates to: Local Area Connection
Current MAC: 210987654321
Medium: 0x00000000
Current MTU: 1500
Current bridge status = NOT BRIDGED
4.¥µ¡¼¥Ó¥¹²½ÍѤΥ³¥Þ¥ó¥É¤Ï°Ê²¼¤Î¤è¤¦¤Ë¤Ê¤ê¤Þ¤¹¡£
"C:\Program Files\Ethernet Bridge\binbridge_cmd.exe" DEVICE{AAAAAAAA-AAAA-BBBB-CCCC-DDDDDDDDDDDD} DEVICE{11111111-2222-3333-4444-555555555555}
¢¨¥µ¡¼¥Ó¥¹²½¤Ë¤Ä¤¤¤Æ¤Ï¡¢¤¤¤¯¤Ä¤«¥Ä¡¼¥ë¤¬¤¢¤ê¤Þ¤¹¡£¥Í¥Ã¥È¾å¤Ç¸¡º÷¤·¤Æ¤¯¤À¤µ¤¤¡£
¢¡¥¯¥é¥¤¥¢¥ó¥È¤Î½àÈ÷
1.openvpn-2.0.5-gui-1.0.3-install.exe¤òhttp://openvpn.se/download.html¤«¤é¥À¥¦¥ó¥í¡¼¥É
2.openvpn-2.0.5-gui-1.0.3-install.exe¤ò¼Â¹Ô¤·¤Æ¥¤¥ó¥¹¥È¡¼¥ë
3.¥¤¥ó¥¹¥È¡¼¥ë¸å¡¢¼«Æ°ºîÀ®¤µ¤ì¤Æ¤¤¤ë²¾ÁÛNIC¤Î̾Á°¤òȽ¤ê¤ä¤¹¤¤¤â¤Î¤ËÊѹ¹
¡ÖTAP-Win32 Adapter¡×¢ª¡ÖVPN1¡×
4.¥¯¥é¥¤¥¢¥ó¥ÈÍÑÀßÄê¥Õ¥¡¥¤¥ë "C:\Program Files\OpenVPN\config\client1.ovpn"
proto udpdev tap
dev-node VPN1remote ¥µ¡¼¥Ð¤ÎIP¥¢¥É¥ì¥¹ 1194
resolv-retry infinitenobind
persist-key
persist-tunca ca.crt
cert client1.crt
key client1.keyns-cert-type server
tls-client
tls-auth ta.key 1cipher BF-CBC
comp-lzoverb 3
mute 10keepalive 10 120
5.ɬÍפʾÚÌÀ½ñ¥Õ¥¡¥¤¥ë¤ò¥µ¡¼¥Ð¤«¤é¥³¥Ô¡¼¤·¤Æ¤¯¤ë
"C:\Program Files\OpenVPN\config"¤Ë¥³¥Ô¡¼
¢¨¥³¥Ô¡¼¤¹¤ëºÝ¤Ë¤Ï°ÂÁ´¤ÊÊýË¡¤Ç¡ª
¢¡¥¯¥é¥¤¥¢¥ó¥Èµ¯Æ°¡Ê¥µ¡¼¥Ð¤ËÀܳ¡Ë
1.¥Õ¥¡¥¤¥¢¥¦¥©¡¼¥ëÅù¤Î³Îǧ
2.¥·¥¹¥Æ¥à¥È¥ì¥¤¤Î OpenVPN GUI ¤òW¥¯¥ê¥Ã¥¯¡ÊËô¤Ï±¦¥¯¥ê¥Ã¥¯¡äConnect¡Ë
3.±¦¥¯¥ê¥Ã¥¯¡äView Log¤Ç¥í¥°¤Î³Îǧ¤¬½ÐÍè¤ë
4.ÀÚÃǤϡ¢±¦¥¯¥ê¥Ã¥¯¡äDisconnect
»²¾È¡§http://degas.is.utsunomiya-u.ac.jp/member/zhao/freesw/ovpn2_howto_ja.html
¤³¤ì¤é¤Î¥Ä¡¼¥ë¤Ï¡¢¥»¥¥å¥ê¥Æ¥£¡¼¤ÎÌ̤ǿ¼¹ï¤ÊÌäÂê¤ò°ú¤µ¯¤³¤¹²ÄǽÀ¤¬¤¢¤ê¤Þ¤¹¡£
±¿ÍѤˤϽ½Ê¬¤ËÃí°Õ¤·¤Æ¤¯¤À¤µ¤¤¡£
´ÉÍý¿Í¤ÏÀÕǤ¤òÉ餤¤Þ¤»¤ó¡£
¥³¥á¥ó¥È
TrackBack URL : http://www.monopo.com/modules/wordpress/wp-trackback.php/62
¥³¥á¥ó¥È¤ÎÅê¹Æ
²þ¹Ô¤äÃÊÍî¤Ï¼«Æ°¤Ç¤¹
URL¤È¥á¡¼¥ë¥¢¥É¥ì¥¹¤Ï¼«Æ°Åª¤Ë¥ê¥ó¥¯¤µ¤ì¤Þ¤¹¤Î¤Ç¡¢<a>¥¿¥°¤ÏÉÔÍפǤ¹¡£
°Ê²¼¤ÎHTML¥¿¥°¤¬»ÈÍѲÄǽ¤Ç¤¹¡£<a href="" title="" rel=""> <abbr title=""> <acronym title=""> <b> <br> <code> <em> <i> <strike> <strong>
¥¯¥é¥¤¥¢¥ó¥È¾ÚÌÀ¤ÎÄɲÃȯ¹Ô»þ¤Ë¤Ï
vars
build-key clientHogehoge
Comment by ken — @
openvpn¥Ð¡¼¥¸¥ç¥ó¥¢¥Ã¥×»þ¤ËTAP¤¬ÃÖ¤´¹¤ï¤Ã¤Æ¤·¤Þ¤¤¡¢¤Ï¤Þ¤Ã¤¿¤Î¤Ç¥á¥â¡Ê´À
http://hehao1.seesaa.net/article/24849903.html
instsrv.exe ¤ª¤è¤Ó srvany.exe ¤ò»ÈÍѤ·¤Æ¥µ¡¼¥Ó¥¹¤òÅÐÏ¿¤¹¤ë¤Ë¤Ï°Ê²¼¤Î¼ê½ç¤Ç¹Ô¤¦¡£
1. Windows NT ¤Þ¤¿¤Ï Windows 2000 ¤Î¥ê¥½¡¼¥¹¥¥Ã¥È¤ò¥¤¥ó¥¹¥È¡¼¥ë¤¹¤ë
2. ¥³¥Þ¥ó¥É¥×¥í¥ó¥×¥È¤ò³«¤¡¢°Ê²¼¤Î¥³¥Þ¥ó¥É¤ò¼Â¹Ô¤¹¤ë
Îã¡Ë¡¡c:ntreskitinstsrv ¥µ¡¼¥Ó¥¹Ì¾ c:ntreskitsrvany.exe
¢¨ instsrv ¤È srvany ¤Ï¡¢¤½¤ì¤¾¤ì¤Î¥Õ¥¡¥¤¥ë¤Î¥Ñ¥¹¤ò»ØÄꤹ¤ë¡£
3. ¡ÖThe service was successfuly added!¡×¤Èɽ¼¨¤µ¤ì¤ì¤ÐÅÐÏ¿´°Î»¡£¥³¥Þ¥ó¥É¥×¥í¥ó¥×¥È¤òÊĤ¸¤ë
4. ¥ì¥¸¥¹¥È¥ê¥¨¥Ç¥£¥¿¤òµ¯Æ°¤¹¤ë
5. °Ê²¼¤Î¥¡¼¤ò³«¤¯
HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServices
6. ¼ê½ç 2. ¤ÇÄɲä·¤¿¥µ¡¼¥Ó¥¹Ì¾¤Î¥¡¼¤òÁªÂò¤·¡¢¥á¥Ë¥å¡¼¤«¤é¡ÎÊÔ½¸¡Ï¢ª¡Î¿·µ¬¡Ï¢ª¡Î¥¡¼¡Ï¤ÈÁªÂò¤·¡¢¿·µ¬¥¡¼¤òºîÀ®¤¹¤ë
7. ºîÀ®¤·¤¿¥¡¼¤Î̾Á°¤ò¡ÖParameters¡×¤ËÊѹ¹¤¹¤ë
8. ¿·µ¬ºîÀ®¤·¤¿¡ÖParameters¡×¥¡¼¤òÁªÂò¤·¡¢¥á¥Ë¥å¡¼¤«¤é¡ÎÊÔ½¸¡Ï¢ª¡Î¿·µ¬¡Ï¢ª¡Îʸ»úÎó¡Ï¤ÈÁªÂò¤·¡¢¿·µ¬¥¨¥ó¥È¥ê¤òºîÀ®¤¹¤ë
9. ºîÀ®¤·¤¿¥¨¥ó¥È¥ê¤Î̾Á°¤ò¡ÖApplication¡×¤È¤¹¤ë
10. ¿·µ¬ºîÀ®¤·¤¿¡ÖApplication¡×¥¨¥ó¥È¥ê¤ò¥À¥Ö¥ë¥¯¥ê¥Ã¥¯¤·¡¢¼ê½ç 2. ¤Ç¥µ¡¼¥Ó¥¹¤ËÅÐÏ¿¤·¤¿¥×¥í¥°¥é¥à¤Î¥Õ¥ë¥Ñ¥¹¤òȾ³Ñ¤ÇÆþÎϤ·¡¢¡ÎOK¡Ï¥Ü¥¿¥ó¤ò¥¯¥ê¥Ã¥¯¤¹¤ë
11. ¼ê½ç 8. °Ê¹ß¤ÈƱÍͤμê½ç¤ÇƱ¤¸¾ì½ê¤Ë¡ÖAppDirectry¡×¥¨¥ó¥È¥ê¤òºîÀ®¤·¡¢¼ê½ç 10. ¤Ç»ØÄꤷ¤¿¥×¥í¥°¥é¥à¤Î¥Ç¥£¥ì¥¯¥È¥ê¤ò»ØÄꤹ¤ë
12. ¥×¥í¥°¥é¥à¤Ë°ú¿ô¤ò»ØÄꤹ¤ëɬÍפ¬¤¢¤ë¾ì¹ç¡¢Æ±Íͤμê½ç¤Ç¡ÖAppParameters¡×¥¨¥ó¥È¥ê¤òºîÀ®¤·¡¢°ú¿ô¤ò»ØÄꤹ¤ë
13. ¼ê½ç 5. ¡Á 12. ¤Îºî¶È¤Ë´Ö°ã¤¤¤¬¤Ê¤¤¤³¤È¤ò³Îǧ¤·¡¢¥ì¥¸¥¹¥È¥ê¥¨¥Ç¥£¥¿¤òÊĤ¸¤ë
14. Windows ¤Î¥µ¡¼¥Ó¥¹¥³¥ó¥½¡¼¥ë¤ò³«¤¯
15. ¼ê½ç 2. ¤ÇÅÐÏ¿¤·¤¿¥µ¡¼¥Ó¥¹¤¬Â¸ºß¤¹¤ë¤³¤È¤ò³Îǧ¤·¡¢¥µ¡¼¥Ó¥¹¤òµ¯Æ°¤¹¤ë
Comment by ken — @