Guest User

Untitled

a guest
Nov 18th, 2017
116
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 1.54 KB | None | 0 0
  1. (client1 LAN: 192.168.10.0/24
  2. (OpenVPN client: client1, 192.168.10.101)
  3. |
  4. |
  5. v
  6. (NAT router,
  7. *dynamic* internet IP: 178.1.2.3)
  8. |
  9. |
  10. (...internet...)
  11. |
  12. |
  13. v
  14. (OpenVPN server,
  15. *static* IP:
  16. 1.2.3.4) <--- (...internet...) <--- (OpenVPN client,
  17. *dynamic* internet IP:
  18. client2, 88.1.2.3)
  19.  
  20. # cat /etc/openvpn/graphyc.conf
  21. server 10.8.0.0 255.255.255.0
  22. verb 3
  23. key server-key.pem
  24. ca ca.pem
  25. cert server-cert.pem
  26. dh dh.pem
  27. keepalive 10 120
  28. persist-key
  29. persist-tun
  30. comp-lzo
  31.  
  32. user nobody
  33. group nogroup
  34.  
  35. # dir "clients" is chown'ed to nobody:nogroup
  36. client-config-dir clients
  37.  
  38. client-to-client
  39. push "route 192.168.10.0 255.255.255.0"
  40. route 192.168.10.0 255.255.255.0
  41.  
  42. proto udp
  43. port 1194
  44. dev tun
  45.  
  46. # cat /etc/openvpn/clients/client1
  47. ifconfig-push 10.8.0.101 10.8.0.5
  48. iroute 192.168.10.0 255.255.255.0
  49.  
  50. # cat /etc/openvpn/client1.conf
  51. client
  52. remote 1.2.3.4 1194 udp
  53. nobind
  54. dev tun
  55. comp-lzo yes
  56. verb 3
  57. explicit-exit-notify 5
  58. key /etc/openvpn/client1-key.pem
  59. cert /etc/openvpn/client1-cert.pem
  60. ca /etc/openvpn/ca.pem
  61.  
  62. # cat /etc/openvpn/client2.conf
  63. client
  64. remote 1.2.3.4 1194 udp
  65. nobind
  66. dev tun
  67. comp-lzo yes
  68. verb 3
  69. explicit-exit-notify 5
  70. key /etc/openvpn/client2-key.pem
  71. cert /etc/openvpn/client2-cert.pem
  72. ca /etc/openvpn/ca.pem
  73.  
  74. Sat Nov 18 11:48:29 2017 client2/88.1.2.3:48069 MULTI: Learn: 192.168.10.211 -> client1/178.1.2.3:52928
Add Comment
Please, Sign In to add comment