Openvpn net2net psk: Unterschied zwischen den Versionen

Aus Xinux Wiki
Zur Navigation springen Zur Suche springen
Zeile 12: Zeile 12:
 
*root@tiazel:~# *openvpn --genkey --secret /etc/openvpn/preshared.key
 
*root@tiazel:~# *openvpn --genkey --secret /etc/openvpn/preshared.key
 
*root@tiazel:~# scp /etc/openvpn/preshared.key 10.84.252.31:/etc/openvpn/
 
*root@tiazel:~# scp /etc/openvpn/preshared.key 10.84.252.31:/etc/openvpn/
 +
=tiazel=
 +
==/etc/openvpn/server.conf==
 +
<pre>
 +
remote 10.84.252.31
 +
local  10.84.252.32
 +
dev tun
 +
ifconfig 192.168.61.2 192.168.61.1
 +
secret /etc/openvpn/preshared.key
 +
ping 20
 +
ping-restart 45
 +
ping-timer-rem
 +
persist-tun
 +
persist-key
 +
comp-lzo
 +
port 5005
 +
float
 +
script-security 2
 +
up /etc/openvpn/deu-fra.up
 +
#down /etc/openvpn/deu-fra.down
 +
verb 3
 +
 +
</pre>

Version vom 25. Juli 2017, 13:20 Uhr

Scenario

Two Hosts

  • tiazel
    • IP:10.84.252.32
    • NET:172.16.32.0
  • zee
    • IP:10.84.252.31
    • NET:172.16.31.0

Install

Create a PSK

  • root@tiazel:~# *openvpn --genkey --secret /etc/openvpn/preshared.key
  • root@tiazel:~# scp /etc/openvpn/preshared.key 10.84.252.31:/etc/openvpn/

tiazel

/etc/openvpn/server.conf

remote 10.84.252.31
local  10.84.252.32
dev tun
ifconfig 192.168.61.2 192.168.61.1
secret /etc/openvpn/preshared.key
ping 20
ping-restart 45
ping-timer-rem
persist-tun
persist-key
comp-lzo
port 5005
float
script-security 2
up /etc/openvpn/deu-fra.up
#down /etc/openvpn/deu-fra.down
verb 3