<?xml version="1.0" encoding="UTF-8" ?>
<rss version="2.0">
<channel>
<title><![CDATA[向东博客 专注WEB应用 构架之美 --- 构架之美，在于尽态极妍 | 应用之美，在于药到病除]]></title> 
<link>http://jackxiang.com/index.php</link> 
<description><![CDATA[赢在IT，Playin' with IT,Focus on Killer Application,Marketing Meets Technology.]]></description> 
<language>zh-cn</language> 
<copyright><![CDATA[向东博客 专注WEB应用 构架之美 --- 构架之美，在于尽态极妍 | 应用之美，在于药到病除]]></copyright>
<item>
<link>http://jackxiang.com/post//</link>
<title><![CDATA[CentOS 5 下 OpenVPN 和 Windows 下 OpenVPN GUI 安装笔记]]></title> 
<author>jack &lt;xdy108@126.com&gt;</author>
<category><![CDATA[WEB2.0]]></category>
<pubDate>Fri, 12 Mar 2010 05:35:14 +0000</pubDate> 
<guid>http://jackxiang.com/post//</guid> 
<description>
<![CDATA[ 
	此笔记,基于 "程序员小辉"的安装笔记修改 --------------------------------------------------------------------------------------------------------------------<br/><br/>一. OpenVPN 安装环境<br/>Server 端的环境<br/>CentOS, kernel版本: 2.6.18, IP 为 221.233.59.16(ADSL拨号) <br/>kernel 需要支持 tun 设备, 需要加载 iptables 模块. <br/>安装的 OpenVPN 的版本: 2.1.rc15.(目前最新版 可在http://openvpn.net 上下载). <br/>Client 端的环境:<br/>Windows XP SP2 <br/>openvpn-2.1_rc15-install.exe(此版本集成了 OpenVPN GUI 客户端) <br/>二. OpenVPN 服务端安装过程<br/><br/>用putty登录到CentOS <br/>下载LZO和OpenVPN 2.1.rc15 <br/>wget http://www.oberhumer.com/opensource/lzo/download/lzo-2.03.tar.gzwget http://openvpn.net/release/openvpn-2.1_rc15.tar.gzyum install -y openssl-devel安装LZO和OpenVPN <br/>tar zxvf lzo-2.03.tar.gzcd lzo-2.03./configuremakemake installcd ..tar zxvf openvpn-2.1_rc15.tar.gzcd openvpn-2.1_rc15./configuremakemake installcd ..cp /root/openvpn-2.1_rc15/easy-rsa/ -r /etc/openvpn生成证书 <br/>初始化PKI <br/><br/>cd /etc/openvpn/2.0/#可以设置下OpenVPN参数(也可以修改vars文件来配置)export D=`pwd`export KEY_CONFIG=$D/openssl.cnfexport KEY_DIR=$D/keysexport KEY_SIZE=1024export KEY_COUNTRY=CNexport KEY_PROVINCE=GDexport KEY_CITY=SZexport KEY_ORG="dvdmaster"export KEY_EMAIL="support@cooldvd.com"#也可以不用设置直接执行下面的命令. vars创建证书颁发机构(CA) <br/><br/>./clean-all./build-caGenerating a 1024 bit RSA private key................++++++........++++++writing new private key to 'ca.key'-----You are about to be asked to enter information that will be incorporatedinto your certificate request.What you are about to enter is what is called a Distinguished Name or a DN.There are quite a few fields but you can leave some blankFor some fields there will be a default value,If you enter '.', the field will be left blank.-----Country Name (2 letter code) [CN]:State or Province Name (full name) [GD]:Locality Name (eg, city) [SZ]:Organization Name (eg, company) [dvdmaster]:Organizational Unit Name (eg, section) []:dvdmasterCommon Name (eg, your name or your server's hostname) []:serverEmail Address [support@cooldvd.com]:建立server key <br/><br/>./build-key-server serverGenerating a 1024 bit RSA private key......++++++....................++++++writing new private key to 'server.key'-----You are about to be asked to enter information that will be incorporatedinto your certificate request.What you are about to enter is what is called a Distinguished Name or a DN.There are quite a few fields but you can leave some blankFor some fields there will be a default value,If you enter '.', the field will be left blank.-----Country Name (2 letter code) [CN]:State or Province Name (full name) [GD]:Locality Name (eg, city) [SZ]:Organization Name (eg, company) [dvdmaster]:Organizational Unit Name (eg, section) []:dvdmasterCommon Name (eg, your name or your server's hostname) []:serverEmail Address [support@cooldvd.com]:Please enter the following 'extra' attributesto be sent with your certificate requestA challenge password []:abcd1234An optional company name []:dvdmasterUsing configuration from /etc/openvpn/2.0/openssl.cnfCheck that the request matches the signatureSignature okThe Subject's Distinguished Name is as followscountryName&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; :PRINTABLE:'CN'stateOrProvinceName&nbsp;&nbsp; :PRINTABLE:'GD'localityName&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;:PRINTABLE:'SZ'organizationName&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;:PRINTABLE:'dvdmaster'organizationalUnitName:PRINTABLE:'dvdmaster'commonName&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;:PRINTABLE:'server'emailAddress&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;:IA5STRING:'support@cooldvd.com'Certificate is to be certified until Mar 19 08:15:31 2016 GMT (3650 days)Sign the certificate? [y/n]:y1 out of 1 certificate requests certified, commit? [y/n]yWrite out database with 1 new entriesData Base Updated生成客户端 key <br/><br/>./build-key client1Generating a 1024 bit RSA private key.....++++++......++++++writing new private key to 'client1.key'-----You are about to be asked to enter information that will be incorporatedinto your certificate request.What you are about to enter is what is called a Distinguished Name or a DN.There are quite a few fields but you can leave some blankFor some fields there will be a default value,If you enter '.', the field will be left blank.-----Country Name (2 letter code) [CN]:State or Province Name (full name) [GD]:Locality Name (eg, city) [SZ]:Organization Name (eg, company) [dvdmaster]:Organizational Unit Name (eg, section) []:dvdmasterCommon Name (eg, your name or your server's hostname) []:client1 #重要: 每个不同的client 生成的证书, 名字必须不同.Email Address [support@cooldvd.com]:Please enter the following 'extra' attributesto be sent with your certificate requestA challenge password []:abcd1234An optional company name []:dvdmasterUsing configuration from /etc/openvpn/2.0/openssl.cnfCheck that the request matches the signatureSignature okThe Subject's Distinguished Name is as followscountryName&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; :PRINTABLE:'CN'stateOrProvinceName&nbsp;&nbsp; :PRINTABLE:'GD'localityName&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;:PRINTABLE:'SZ'organizationName&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;:PRINTABLE:'dvdmaster'organizationalUnitName:PRINTABLE:'dvdmaster'commonName&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;:PRINTABLE:'client1'emailAddress&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;:IA5STRING:'support@cooldvd.com'Certificate is to be certified until Mar 19 08:22:00 2016 GMT (3650 days)Sign the certificate? [y/n]:y1 out of 1 certificate requests certified, commit? [y/n]yWrite out database with 1 new entriesData Base Updated以此类推建立其他客户端 key <br/><br/>./build-key client2./build-key client3注意在进入 Common Name (eg, your name or your server's hostname) []: 的输入时, 每个证书输入的名字必须不同. <br/><br/>生成Diffie Hellman参数 <br/>./build-dh将 keys 下的所有文件打包下载到本地(可以通过winscp,http,ftp等等......) <br/>tar zcvf yskeys.tar.gz keys/创建服务端配置文件 <br/>mkdir /etc/openvpn/2.0/confcp /root/openvpn-2.1_rc15/sample-config-files/server.conf /etc/openvpn/2.0/conf/server.conf<br/>服务端配置文件(server.conf)样例 <br/><br/>port 1194proto udpdev tunca /etc/openvpn/2.0/keys/ca.crtcert /etc/openvpn/2.0/keys/ovpnser.crtkey /etc/openvpn/2.0/keys/ovpnser.key&nbsp;&nbsp;# This file should be kept secretdh /etc/openvpn/2.0/keys/dh1024.pemserver 10.8.0.0 255.255.255.0ifconfig-pool-persist ipp.txtpush "redirect-gateway def1 bypass-dhcp"push "dhcp-option DNS 10.8.0.1"push "dhcp-option DNS 202.103.44.150" #客户端获得的DNS地址push "dhcp-option DNS 202.103.24.68" #客户端获得的DNS地址client-to-clientkeepalive 10 120comp-lzouser nobodygroup nobodypersist-keypersist-tunstatus openvpn-status.logverb 3启动OpenVPN <br/>/usr/local/sbin/openvpn --config /etc/openvpn/2.0/conf/server.conf &三. OpenVPN GUI For Windows 客户端安装过程<br/><br/>下载 openvpn-2.1_rc15-install.exe(此版本集成 OpenVPN&nbsp;&nbsp;GUI) <br/>官方下载地址:http://openvpn.net/release/openvpn-2.1_rc15-install.exe <br/><br/>依屏幕指示安装OpenVPN GUI <br/>配置 openvpn gui <br/><br/>将上面第6步打包的yskeys.tar.gz中的下列证书文件解压到 你的OpenVPN GUI安装路径&#92;OpenVPN&#92;config文件夹下 <br/><br/>ca.crtca.keyclient1.crtclient1.csrclient1.key修改client.ovpn <br/>把你的OpenVPN GUI安装路径&#92;OpenVPN&#92;sample-config下的client.ovpn文件复制到你的OpenVPN GUI安装路径&#92;OpenVPN&#92;config文件夹下,用记事本打开client.ovpn <br/><br/>#找到remote my-server-1 1194,把my-server-1改成你的ip地址remote 221.233.59.16 1194双击 client.ovpn 即可启动 openvpn, 或者通过 OpenVPN GUI 的控制启动 VPN. <br/>三. OpenVPN 访问外网的设置<br/><br/>开启CentOS 5 的路由转发功能 <br/>echo 1 > /proc/sys/net/ipv4/ip_forward#为了使CentOS重启后仍然开启路由转发功能我们需要再执行下列命令sysctl -w net.ipv4.ip_forward=1添加iptables转发规则 <br/>#因为我那天CentOS是ADSL拨号上网,所以把出口设置成ppp0,请根据实际情况设置iptables -t nat -A POSTROUTING -s 10.8.0.0/24 -o ppp0 -j MASQUERADE必须保证server.conf配置中,有下面三个配置 <br/>push "dhcp-option DNS 10.8.0.1"push "dhcp-option DNS 202.103.44.150" #客户端获得的DNS地址push "dhcp-option DNS 202.103.24.68" #客户端获得的DNS地址当 client 连接成功后, 在 cmd 下执行 ipconfig /all, 应该有这类似这样的输出: <br/><br/>Ethernet adapter 本地连接 2:&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Connection-specific DNS Suffix&nbsp;&nbsp;. :&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Description . . . . . . . . . . . : TAP-Win32 Adapter V9&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Physical Address. . . . . . . . . : 00-FF-F2-1A-44-BD&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Dhcp Enabled. . . . . . . . . . . : Yes&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Autoconfiguration Enabled . . . . : Yes&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;IP Address. . . . . . . . . . . . : 10.8.0.6&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Subnet Mask . . . . . . . . . . . : 255.255.255.252&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Default Gateway . . . . . . . . . : 10.8.0.5&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;DHCP Server . . . . . . . . . . . : 10.8.0.5&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;DNS Servers . . . . . . . . . . . : 10.8.0.1&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;202.103.44.150&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;202.103.24.68&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Lease Obtained. . . . . . . . . . : 2009年5月8日 23:55:06&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Lease Expires . . . . . . . . . . : 2010年5月8日 23:55:06四. 设置 OpenVPN 服务器 reboot后自动启动 openvpn<br/>执行<br/><br/>vi /etc/rc.local然后在最后面加入此行:<br/><br/>/usr/local/sbin/openvpn --config /etc/openvpn/2.0/conf/server.conf &五.OpenVPN 测试<br/>连接成功之后,去www.ip138.com上看看外网ip是多少,如果是CentOS系统的外网ip那说明测试成功了~<br/>来源：http://rashost.com/blog/centos-openvpn-install
]]>
</description>
</item><item>
<link>http://jackxiang.com/post//#blogcomment</link>
<title><![CDATA[[评论] CentOS 5 下 OpenVPN 和 Windows 下 OpenVPN GUI 安装笔记]]></title> 
<author> &lt;user@domain.com&gt;</author>
<category><![CDATA[评论]]></category>
<pubDate>Thu, 01 Jan 1970 00:00:00 +0000</pubDate> 
<guid>http://jackxiang.com/post//#blogcomment</guid> 
<description>
<![CDATA[ 
	
]]>
</description>
</item>
</channel>
</rss>