centos7安装openv皮n
作者:小小傻瓜牙能上网的机器
我的centos7的ip 是192.168.10.88
先看看服务器时间,不能比现实的时间快
yum -y install epel-release 安装epel扩展源 (不行就reboot一下)
安装openvpn和easy-rsa
1 yum -y install openvpn easy-rsa
复制easy-rsa文件
1 [root@server ~]# cp -r /usr/share/easy-rsa/ /etc/openvpn/easy-rsa 2 3 [root@server ~]# cd /etc/openvpn/easy-rsa/ 4 5 [root@server easy-rsa]# ls 6 7 3 3.0 3.0.6 8 9 [root@server easy-rsa]# \rm 3 3.0 10 11 [root@server easy-rsa]# ls 12 13 3.0.3 14 15 [root@server easy-rsa]# cd 3.0.6/ 16 17 [root@server 3.0.6]# find / -type f -name "vars.example" | xargs -i cp {} . && mv vars.example vars
1 [root@server 3.0.6]# ls 2 3 easyrsa openssl-1.0.cnf vars x509-types
生成CA证书
创建一个新的 PKI 和 CA
1 [root@server 3.0.6]# ./easyrsa init-pki
Note: using Easy-RSA configuration from: ./vars
init-pki complete; you may now create a CA or requests.
Your newly created PKI dir is: /etc/openvpn/easy-rsa/3.0.6/pki
创建新的CA,不使用密码
1 [root@server 3.0.6]# ./easyrsa build-ca nopass
Note: using Easy-RSA configuration from: ./vars
Generating a 2048 bit RSA private key
.......................+++
...........+++
writing new private key to '/etc/openvpn/easy-rsa/3.0.6/pki/private/ca.key.KPmAlNfnU3'
-----
You are about to be asked to enter information that will be incorporated
into your certificate request.
What you are about to enter is what is called a Distinguished Name or a DN.
There are quite a few fields but you can leave some blank
For some fields there will be a default value,
If you enter '.', the field will be left blank.
-----
Common Name (eg: your user, host, or server name) [Easy-RSA CA]:回车
CA creation complete and you may now import and sign cert requests.
Your new CA certificate file for publishing is at:
/etc/openvpn/easy-rsa/3.0.6/pki/ca.crt
创建服务端证书
1 [root@server 3.0.6]# ./easyrsa gen-req server nopass
Note: using Easy-RSA configuration from: ./vars
Generating a 2048 bit RSA private key
...........................................+++
................................................................................................................................................................................+++
writing new private key to '/etc/openvpn/easy-rsa/3.0.6/pki/private/server.key.NH1k6T6KaF'
-----
You are about to be asked to enter information that will be incorporated
into your certificate request.
What you are about to enter is what is called a Distinguished Name or a DN.
There are quite a few fields but you can leave some blank
For some fields there will be a default value,
If you enter '.', the field will be left blank.
-----
Common Name (eg: your user, host, or server name) [server]:回车
Keypair and certificate request completed. Your files are:
req: /etc/openvpn/easy-rsa/3.0.6/pki/reqs/server.req
key: /etc/openvpn/easy-rsa/3.0.6/pki/private/server.key
签约服务端证书
1 [root@server 3.0.6]# ./easyrsa sign server server
Note: using Easy-RSA configuration from: ./vars
You are about to sign the following certificate.
Please check over the details shown below for accuracy. Note that this request
has not been cryptographically verified. Please be sure it came from a trusted
source or that you have verified the request checksum with the sender.
Request subject, to be signed as a server certificate for 3650 days:
subject=
commonName = server
Type the word 'yes' to continue, or any other input to abort.
Confirm request details: yes
Using configuration from ./openssl-1.0.cnf
Check that the request matches the signature
Signature ok
The Subject's Distinguished Name is as follows
commonName :ASN.1 12:'server'
Certificate is to be certified until Apr 16 16:35:35 2029 GMT (3650 days)
Write out database with 1 new entries
Data Base Updated
Certificate created at: /etc/openvpn/easy-rsa/3.0.6/pki/issued/server.crt
创建Diffie-Hellman,确保key穿越不安全网络的命令,回车后,等的时间稍微长一点
1 [root@server 3.0.6]# ./easyrsa gen-dh
............................++*++*
DH parameters of size 2048 created at /etc/openvpn/easy-rsa/3.0.6/pki/dh.pem
生成ta密钥文件
1 openvpn --genkey --secret /etc/openvpn/easy-rsa/ta.key
不执行此命令,会报错
整理证书
1 [root@server 3.0.6]# cd /etc/openvpn 2 3 [root@server openvpn]# cp easy-rsa/3.0.6/pki/dh.pem . 4 5 [root@server openvpn]# cp easy-rsa/3.0.6/pki/ca.crt . 6 7 [root@server openvpn]# cp easy-rsa/3.0.6/pki/issued/server.crt . 8 9 [root@server openvpn]# cp easy-rsa/3.0.6/pki/private/server.key . 10 11 [root@server openvpn]# cp easy-rsa/ta.key . 12 13 [root@server openvpn]# ll 16 17 -rw------- 1 root root 1172 Apr 20 00:41 ca.crt 18 19 drwxr-x--- 2 root openvpn 6 Feb 20 23:23 client 20 21 -rw------- 1 root root 424 Apr 20 00:41 dh.pem 22 23 drwxr-xr-x 3 root root 33 Apr 20 00:39 easy-rsa 24 25 drwxr-x--- 2 root openvpn 6 Feb 20 23:23 server 26 27 -rw------- 1 root root 4552 Apr 20 00:41 server.crt 28 29 -rw------- 1 root root 1704 Apr 20 00:42 server.key 30 31 -rw------- 1 root root 636 Apr 20 00:42 ta.key
创建客户端证书
复制文件
1 [root@server ~]# cp -r /usr/share/easy-rsa/ /etc/openvpn/client 2 3 [root@server ~]# cd /etc/openvpn/client/easy-rsa/ 4 5 [root@server easy-rsa]# \rm 3 3.0 6 7 [root@server easy-rsa]# cd 3.0.6/ 8 9 [root@server 3.0.6]# find / -type f -name "vars.example" | xargs -i cp {} . && mv vars.example vars
生成客户端证书
1 [root@server 3.0.6]# pwd 2 3 /etc/openvpn/client/easy-rsa/3.0.6 4 5 [root@server 3.0.6]# ./easyrsa init-pki 创建新的pki
Note: using Easy-RSA configuration from: ./vars
init-pki complete; you may now create a CA or requests.
Your newly created PKI dir is: /etc/openvpn/client/easy-rsa/3.0.6/pki
1 [root@server 3.0.6]# ./easyrsa gen-req client nopass 客户证书名,无密码
Note: using Easy-RSA configuration from: ./vars
Generating a 2048 bit RSA private key
............................................+++
.....................+++
writing new private key to '/etc/openvpn/client/easy-rsa/3.0.6/pki/private/client.key.FO8om8Ji9T'
-----
You are about to be asked to enter information that will be incorporated
into your certificate request.
What you are about to enter is what is called a Distinguished Name or a DN.
There are quite a few fields but you can leave some blank
For some fields there will be a default value,
If you enter '.', the field will be left blank.
-----
Common Name (eg: your user, host, or server name) [client]:回车
Keypair and certificate request completed. Your files are:
req: /etc/openvpn/client/easy-rsa/3.0.6/pki/reqs/client.req
key: /etc/openvpn/client/easy-rsa/3.0.6/pki/private/client.key
签约客户端证书
1 [root@server 3.0.6]# cd /etc/openvpn/easy-rsa/3.0.6/ 2 3 [root@server 3.0.6]# pwd 4 5 /etc/openvpn/easy-rsa/3.0.6 6 7 [root@server 3.0.6]# ./easyrsa import-req /etc/openvpn/client/easy-rsa/3.0.6/pki/reqs/client.req client
Note: using Easy-RSA configuration from: ./vars
The request has been successfully imported with a short name of: client
You may now use this name to perform signing operations on this request.
[root@server 3.0.6]# ./easyrsa sign client client
Note: using Easy-RSA configuration from: ./vars
You are about to sign the following certificate.
Please check over the details shown below for accuracy. Note that this request
has not been cryptographically verified. Please be sure it came from a trusted
source or that you have verified the request checksum with the sender.
Request subject, to be signed as a client certificate for 3650 days:
subject=
commonName = client
Type the word 'yes' to continue, or any other input to abort.
Confirm request details: yes
Using configuration from ./openssl-1.0.cnf
Check that the request matches the signature
Signature ok
The Subject's Distinguished Name is as follows
commonName :ASN.1 12:'client'
Certificate is to be certified until Apr 16 16:50:25 2029 GMT (3650 days)
Write out database with 1 new entries
Data Base Updated
Certificate created at: /etc/openvpn/easy-rsa/3.0.6/pki/issued/client.crt
整理证书
1 [root@server 3.0.6]# cd /etc/openvpn/client 2 3 [root@server client]# ls 4 5 easy-rsa 6 7 [root@server client]# cp /etc/openvpn/easy-rsa/3.0.6/pki/ca.crt . 8 9 [root@serverclient]# cp /etc/openvpn/easy-rsa/3.0.6/pki/issued/client.crt . 10 11 [root@serverclient]# cp /etc/openvpn/client/easy-rsa/3.0.6/pki/private/client.key . 12 13 [root@server client]# cp /etc/openvpn/easy-rsa/ta.key .
配置文件
1 [root@server client]# cd /etc/openvpn/ 2 3 [root@server openvpn]# vim server.conf (内容如下) 4 5 port 11194 7 proto tcp 9 dev tun 11 ca /etc/openvpn/ca.crt 13 cert /etc/openvpn/server.crt 15 key /etc/openvpn/server.key 17 dh /etc/openvpn/dh.pem 19 server 10.8.0.0 255.255.255.0 21 ifconfig-pool-persist ipp.txt 23 push "route 192.168.10.0 255.255.255.0" 25 push "route 192.168.20.0 255.255.255.0" 27 push "route 127.11.170.0 255.255.255.0" 29 push "route 10.8.0.0 255.255.255.0" 31 push "dhcp-option DNS 8.8.8.8" 33 push "dhcp-option DNS 8.8.4.4" 35 keepalive 10 120 37 tls-auth /etc/openvpn/ta.key 0 #服务器是0,客户端是1 39 client-to-client 41 comp-lzo 43 user nobody 45 group nobody 47 persist-key 49 persist-tun 51 status openvpn-status.log 53 verb 3
开启转发
说的是centos7的/etc/sysctl.conf不能用
要用/usr/lib/sysctl.d/50-default.conf
我是两个都写了(云服务器我只写了第一个)
[root@server ~]# vim /etc/sysctl.conf
加一行 net.ipv4.ip_forward = 1
vim /usr/lib/sysctl.d/50-default.conf
net.ipv4.ip_forward = 1
[root@server ~]# sysctl -p
net.ipv4.ip_forward = 1
开机启动VPN
在centos7中,/etc/rc.d/rc.local的权限被降低了,赋予其可执行权限,建议777
[root@server ~]# chmod 777 /etc/rc.d/rc.local
vim /etc/rc.d/rc.local
加入
openvpn /etc/openvpn/server.conf &
客户端(我是桥接模式)如果不能上网 这包很难按
安装 epel yum 源
rpm -ivh http://mirrors.sohu.com/fedora-epel/6/x86_64/epel-release-6-8.noarch.rpm
yum 安装 openvpn
yum -y install openvpn
把服务器上创建的客户端证书文件上传到客户机的/etc/openvpn/里
ca.crt client.crt client.key ta.key
创建文件
1 cd /etc/openvpn/ 2 3 vim client.conf 4 5 内容如下 6 7 client 9 dev tun 11 proto tcp 13 remote 域名IP地址指向的ip:诊断域名后的端口 15 resolv-retry infinite 17 nobind 19 user nobody 21 group nobody 23 persist-key 25 persist-tun 27 ca /etc/openvpn/ca.crt 29 cert /etc/openvpn/client.crt 31 key /etc/openvpn/client.key 33 remote-cert-tls server 35 tls-auth /etc/openvpn/ta.key 1 #(服务器0 客户机1) 37 comp-lzo 39 verb 3
启动VPN如果是
openvpn /etc/openvpn/client.conf &
最后可以将上述命令加到/etc/rc.d/rc.local里开机启动
在centos7中,/etc/rc.d/rc.local文件的权限被降低了,没有执行权限,需要给它添加可执行权限(最好777)。
chmod 777 /etc/rc.d/rc.local
然后就可以在里面添加你要开机自启的命令了
openvpn /etc/openvpn/client.conf &

浙公网安备 33010602011771号