Guest User

openvpn

a guest
Feb 18th, 2017
1,955
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 4.16 KB | None | 0 0
  1. #-------------------------------------------------------------------------
  2. installation guide (ubuntu 16):
  3.  
  4. 1)Find and note down your public IP address
  5. 2)Download openvpn-install.sh script
  6. 3)Run openvpn-install.sh to install OpenVPN server
  7. 4)Connect an OpenVPN server using IOS/Android/Linux/Windows client
  8. 5)Verify your connectivity
  9.  
  10. #-------------------------------------------------------------------------
  11. 1)
  12. #find local ip of machine
  13. ip addr show eth0
  14.  
  15. #find public ip of machine
  16. dig TXT +short o-o.myaddr.l.google.com @ns1.google.com
  17.  
  18. #if you are behind a nat, open the port 1194 tc/udp in the router
  19. #and forward it to the local ip of the machine
  20. #get a ddns hostname
  21. #-------------------------------------------------------------------------
  22. 2)
  23. #Download openvpn-install.sh script
  24. wget https://git.io/vpn -O openvpn-install.sh
  25. #-------------------------------------------------------------------------
  26. 3)
  27. #Run openvpn-install.sh to install OpenVPN server
  28. sudo bash openvpn-install.sh
  29.  
  30. #the ip address is the local ip (e.g. 192.168.1.2)
  31. #the port should be 1194
  32. #the dns should be google (8.8.8.8, 8.8.4.4)
  33. #choose a client name
  34. #the external address should be the ddns hostname from 1)
  35.  
  36. #Your OpenVPN server has been configured and ready to use.
  37. #You can see added firewall rules /etc/rc.local file:
  38. cat /etc/rc.local
  39.  
  40. #sample output:
  41. #iptables -I FORWARD -m state --state RELATED,ESTABLISHED -j ACCEPT
  42. #iptables -I FORWARD -s 10.8.0.0/24 -j ACCEPT
  43. #iptables -I INPUT -p udp --dport 1194 -j ACCEPT
  44. #iptables -t nat -A POSTROUTING -s 10.8.0.0/24 -j SNAT --to 139.59.1.155
  45.  
  46. #You can view your openvpn server config file generated by the script
  47. # as follows (do not edit this file by hand):
  48. sudo more /etc/openvpn/server.conf
  49.  
  50. #sample
  51. #port 1194
  52. #proto udp
  53. #dev tun
  54. #sndbuf 0
  55. #rcvbuf 0
  56. #ca ca.crt
  57. #cert server.crt
  58. #key server.key
  59. #dh dh.pem
  60. #tls-auth ta.key 0
  61. #topology subnet
  62. #server 10.8.0.0 255.255.255.0
  63. #ifconfig-pool-persist ipp.txt
  64. #push "redirect-gateway def1 bypass-dhcp"
  65. #push "dhcp-option DNS 8.8.8.8"
  66. #push "dhcp-option DNS 8.8.4.4"
  67. #keepalive 10 120
  68. #cipher AES-128-CBC
  69.  
  70. #how to start/stop/restart OpenVPN server
  71. sudo systemctl stop openvpn@server
  72. sudo systemctl start openvpn@server
  73. sudo systemctl restart openvpn@server
  74.  
  75. #optional
  76. #How to configure and use the ufw firewall rules for the OpenVPN server
  77. #Type the following ufw command to open port 1194 and 22 (ssh)
  78. sudo ufw allow 1194/udp
  79. sudo ufw allow 22/tcp
  80.  
  81. #Edit the file /etc/ufw/before.rules, enter:
  82. sudo nano /etc/ufw/before.rules
  83.  
  84. #add at top:
  85.  
  86. # START OPENVPN RULES by vg
  87. # NAT table rules
  88. *nat
  89. :POSTROUTING ACCEPT [0:0]
  90. #****************************************[README]*****************************************************#
  91. # Allow traffic from OpenVPN client to 139.59.1.155. Replace 139.59.1.155 with your actual IP address*#
  92. #****************************************[README]*****************************************************#
  93. -A POSTROUTING -s 10.8.0.0/24 -j SNAT --to-source <local ip, eg. 192.168.1.2>
  94. COMMIT
  95. # END OPENVPN RULES by vg
  96.  
  97.  
  98. #Next scroll down and find the comment that reads as follows:
  99. #"# ok icmp code for FORWARD"
  100.  
  101. #and append this:
  102.  
  103. #OpenVPN Forward by vg
  104. -A ufw-before-forward -m state --state RELATED,ESTABLISHED -j ACCEPT
  105. -A ufw-before-forward -s 10.8.0.0/24 -j ACCEPT
  106. -A ufw-before-forward -i tun+ -j ACCEPT
  107. -A ufw-before-forward -i tap+ -j ACCEPT
  108. #OpenVPN END by vg
  109.  
  110.  
  111. #Next edit the /etc/ufw/sysctl.conf file :
  112. sudo nano /etc/ufw/sysctl.conf
  113.  
  114. #Find and uncomment the following line to allow this host to route packets between interfaces:
  115. #net/ipv4/ip_forward=1
  116.  
  117. #Enable ufw or reload if already running:
  118. sudo ufw enable
  119. sudo ufw reload
  120.  
  121. #Verify new firewall rules:
  122. sudo ufw status
  123.  
  124. #-------------------------------------------------------------------------
  125. 4)
  126. #copy the <client>.ovpn that was generated
  127.  
  128. #linux:
  129. sudo apt install openvpn
  130. sudo openvpn <client>.ovpn
  131.  
  132. #android:
  133. #install OpenVPN connect
  134. #then import the .ovpn file
  135.  
  136. #windows
  137. #install software from openvpn.net
  138.  
  139. 5)
  140. #check new ip
  141. dig TXT +short o-o.myaddr.l.google.com @ns1.google.com
  142.  
  143. #ping the OpenVPN server private IP:
  144. ping 10.8.0.1
Advertisement
Add Comment
Please, Sign In to add comment