Professional Documents
Culture Documents
Instalacin en Windows
1. Ejecutar el programa (sin GUI) Windows Installer openvpn-2.0.9-install.exe 2. Ejecutar el programa+GUI Installation Package (Both 32-bit and 64-bit TAP driver included): openvpn-2.0.9-gui-1.0.3-install.exe
Primer escenario
Cliente
10.8.0.2 10.8.0.1
Servidor VPN
192.168.100.2
192.168.100.5
cliente.ovpn remote 192.168.100.5 dev tun ifconfig 10.8.0.2 10.8.0.1 secret static.key
Segundo escenario
Cliente
10.8.0.2 10.0.100.2
cliente.ovpn remote 10.0.100.5 dev tun ifconfig 10.8.0.2 10.8.0.1 route 192.168.100.0 255.255.255.0 dhcp-option DNS 192.168.100.10 secret static.key
Tercer escenario
Cliente Firewall
Servidor VPN
server.ovpn cliente.ovpn remote 10.0.100.252 dev tun ifconfig 10.8.0.2 10.8.0.1 route 192.168.100.0 255.255.255.0 dhcp-option DNS 192.168.100.10 secret static.key dev tun ifconfig 10.8.0.1 10.8.0.2 secret static.key
Configurar el firewall
Habilitar el enrutado #echo 1 > /proc/sys/net/ipv4/ip_forward Establecer reglas de filtrado #iptables P INPUT DROP #iptables P OUTPUT DROP #iptables P FORWARD DROP #iptables t nat A PREROUTING p udp --dport 1194 j DNAT--to 192.168.100.5 #iptables A FORWARD d 192.168.100.5 p udp--dport 1194 j ACCEPT #iptables A FORWARD s 192.168.100.5 p udp--sport 1194 j ACCEPT
Ejecutar los siguientes comandos C:\> vars C:\> clean-all C:\> build-ca
Tercer escenario
Cliente Firewall
Servidor VPN
cliente.ovpn dev tap remote 10.0.100.252 ca ca.crt cert server.crt key server.key
server.ovpn dev tap server 10.8.0.0 255.255.255.0 push route 192.168.100.0 255.255.255.0 push dhcp-option DNS 192.168.100.10 ca ca.crt cert server.crt key server.key dh dh1024.pem
Configurar el firewall
Habilitar el enrutado #echo 1 > /proc/sys/net/ipv4/ip_forward Establecer reglas de filtrado #iptables P INPUT DROP #iptables P OUTPUT DROP #iptables P FORWARD DROP #iptables t nat A PREROUTING p udp --dport 1194 j DNAT--to 192.168.100.5 #iptables A FORWARD d 192.168.100.5 p udp--dport 1194 j ACCEPT #iptables A FORWARD s 192.168.100.5 p udp--sport 1194 j ACCEPT