Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- #-------------------------------------------------------------------------
- installation guide (ubuntu 16):
- 1)Find and note down your public IP address
- 2)Download openvpn-install.sh script
- 3)Run openvpn-install.sh to install OpenVPN server
- 4)Connect an OpenVPN server using IOS/Android/Linux/Windows client
- 5)Verify your connectivity
- #-------------------------------------------------------------------------
- 1)
- #find local ip of machine
- ip addr show eth0
- #find public ip of machine
- dig TXT +short o-o.myaddr.l.google.com @ns1.google.com
- #if you are behind a nat, open the port 1194 tc/udp in the router
- #and forward it to the local ip of the machine
- #get a ddns hostname
- #-------------------------------------------------------------------------
- 2)
- #Download openvpn-install.sh script
- wget https://git.io/vpn -O openvpn-install.sh
- #-------------------------------------------------------------------------
- 3)
- #Run openvpn-install.sh to install OpenVPN server
- sudo bash openvpn-install.sh
- #the ip address is the local ip (e.g. 192.168.1.2)
- #the port should be 1194
- #the dns should be google (8.8.8.8, 8.8.4.4)
- #choose a client name
- #the external address should be the ddns hostname from 1)
- #Your OpenVPN server has been configured and ready to use.
- #You can see added firewall rules /etc/rc.local file:
- cat /etc/rc.local
- #sample output:
- #iptables -I FORWARD -m state --state RELATED,ESTABLISHED -j ACCEPT
- #iptables -I FORWARD -s 10.8.0.0/24 -j ACCEPT
- #iptables -I INPUT -p udp --dport 1194 -j ACCEPT
- #iptables -t nat -A POSTROUTING -s 10.8.0.0/24 -j SNAT --to 139.59.1.155
- #You can view your openvpn server config file generated by the script
- # as follows (do not edit this file by hand):
- sudo more /etc/openvpn/server.conf
- #sample
- #port 1194
- #proto udp
- #dev tun
- #sndbuf 0
- #rcvbuf 0
- #ca ca.crt
- #cert server.crt
- #key server.key
- #dh dh.pem
- #tls-auth ta.key 0
- #topology subnet
- #server 10.8.0.0 255.255.255.0
- #ifconfig-pool-persist ipp.txt
- #push "redirect-gateway def1 bypass-dhcp"
- #push "dhcp-option DNS 8.8.8.8"
- #push "dhcp-option DNS 8.8.4.4"
- #keepalive 10 120
- #cipher AES-128-CBC
- #how to start/stop/restart OpenVPN server
- sudo systemctl stop openvpn@server
- sudo systemctl start openvpn@server
- sudo systemctl restart openvpn@server
- #optional
- #How to configure and use the ufw firewall rules for the OpenVPN server
- #Type the following ufw command to open port 1194 and 22 (ssh)
- sudo ufw allow 1194/udp
- sudo ufw allow 22/tcp
- #Edit the file /etc/ufw/before.rules, enter:
- sudo nano /etc/ufw/before.rules
- #add at top:
- # START OPENVPN RULES by vg
- # NAT table rules
- *nat
- :POSTROUTING ACCEPT [0:0]
- #****************************************[README]*****************************************************#
- # Allow traffic from OpenVPN client to 139.59.1.155. Replace 139.59.1.155 with your actual IP address*#
- #****************************************[README]*****************************************************#
- -A POSTROUTING -s 10.8.0.0/24 -j SNAT --to-source <local ip, eg. 192.168.1.2>
- COMMIT
- # END OPENVPN RULES by vg
- #Next scroll down and find the comment that reads as follows:
- #"# ok icmp code for FORWARD"
- #and append this:
- #OpenVPN Forward by vg
- -A ufw-before-forward -m state --state RELATED,ESTABLISHED -j ACCEPT
- -A ufw-before-forward -s 10.8.0.0/24 -j ACCEPT
- -A ufw-before-forward -i tun+ -j ACCEPT
- -A ufw-before-forward -i tap+ -j ACCEPT
- #OpenVPN END by vg
- #Next edit the /etc/ufw/sysctl.conf file :
- sudo nano /etc/ufw/sysctl.conf
- #Find and uncomment the following line to allow this host to route packets between interfaces:
- #net/ipv4/ip_forward=1
- #Enable ufw or reload if already running:
- sudo ufw enable
- sudo ufw reload
- #Verify new firewall rules:
- sudo ufw status
- #-------------------------------------------------------------------------
- 4)
- #copy the <client>.ovpn that was generated
- #linux:
- sudo apt install openvpn
- sudo openvpn <client>.ovpn
- #android:
- #install OpenVPN connect
- #then import the .ovpn file
- #windows
- #install software from openvpn.net
- 5)
- #check new ip
- dig TXT +short o-o.myaddr.l.google.com @ns1.google.com
- #ping the OpenVPN server private IP:
- ping 10.8.0.1
Advertisement
Add Comment
Please, Sign In to add comment