ubuntu openvpn安装配置-证书方式V1.2

六月 1st, 2010 Posted in SVN | 阅读次数: 462 次

uthor:gaojinbo
Time:2010-5-31

ubuntu openvpn安装配置-证书方式V1.2,针对v1.1版本对server.conf配置进行了优化

OpenVPN在连接成功之后会自动增加一些路由,把默认网关改成VPN的,使所有流量都从VPN走。OpenVPN提供了在配置文件中添加路由的功能,我们可以增加一些本地路由,使本地流量不走VPN,既节省了流量(如果限流量的话),又提高了上网的速度

 

1.环境:
vpn-vip        10.0.0.0/24
vpn-server    192.168.1.195

 

2.修改server.conf配置文件
vi /etc/openvpn/server.conf

port 1194
proto udp
dev tun 

ca /etc/openvpn/ca.crt
cert /etc/openvpn/server.crt
key /etc/openvpn/server.key
dh /etc/openvpn/dh1024.pem 

server 10.0.0.0 255.255.255.0
ifconfig-pool-persist ipp.txt 

push "redirect-gateway" 

push "route 192.168.1.0 255.255.255.0"
push "route 192.168.1.195 255.255.255.255 net_gateway"
push "dhcp-option DNS 202.96.128.166" 

keepalive 10 120
tls-auth /etc/openvpn/ta.key 0

comp-lzo

user nobody
group nogroup 

persist-key
persist-tun 

client-to-client
duplicate-cn 

status       /var/www/openvpn-status.log
log-append  /var/log/openvpn.log 

verb 3 

 

说明:请将上面的配置文件替换到server.conf即可,客户端配置无需修改,其他配置参考ubuntu openvpn安装配置-证书方式V1.1

 

完成!

相关日志:

Tags:

One Response to “ubuntu openvpn安装配置-证书方式V1.2”

  1. Serotonin Levels Says:

    Sites we Like……

    [...] Every once in a while we choose blogs that we read. Listed below are the latest sites that we choose [...]……


留下您的脚印