{"id":1029,"date":"2016-01-11T17:18:09","date_gmt":"2016-01-11T14:18:09","guid":{"rendered":"http:\/\/www.unixpin.com\/wordpress\/?p=1029"},"modified":"2016-01-11T17:29:45","modified_gmt":"2016-01-11T14:29:45","slug":"openvpn-over-amazon-ec2","status":"publish","type":"post","link":"https:\/\/www.unixpin.com\/?p=1029","title":{"rendered":"OpenVPN \u043d\u0430 Amazon EC2 \u0441\u0435\u0440\u0432\u0435\u0440\u0435"},"content":{"rendered":"<p>\u041a\u0430\u043a \u0438\u0437\u0432\u0435\u0441\u0442\u043d\u043e, amazon \u0434\u0430\u0435\u0442 \u0432\u043e\u0437\u043c\u043e\u0436\u043d\u043e\u0441\u0442\u044c \u0437\u0430\u043f\u0443\u0441\u0442\u0438\u0442\u044c \u0431\u0435\u0441\u043f\u043b\u0430\u0442\u043d\u043e \u0432\u0438\u0440\u0442\u0443\u0430\u043b\u044c\u043d\u044b\u0435 \u0441\u0435\u0440\u0432\u0435\u0440\u0430 \u0432 \u043e\u0431\u043b\u0430\u043a\u0435 ( 750 \u0447\u0430\u0441\u043e\u0432 \u0432 \u043c\u0435\u0441\u044f\u0446 \u0431\u0435\u0441\u043f\u043b\u0430\u0442\u043d\u043e, \u043d\u0430 \u043e\u0434\u0438\u043d \u0433\u043e\u0434 ). \u0420\u0430\u0437 \u0435\u0441\u0442\u044c \u0442\u0430\u043a\u0430\u044f \u0445\u0430\u043b\u044f\u0432\u0430, \u0442\u043e \u043d\u0443\u0436\u043d\u043e \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u044c, \u043d\u0443 \u043f\u043e\u043f\u0440\u043e\u0431\u0443\u0435\u043c \u0434\u043b\u044f \u043d\u0430\u0447\u0430\u043b\u0430\u00a0\u043d\u0430\u0441\u0442\u0440\u043e\u0438\u0442\u044c \u00a0OpenVPN.<br \/>\n\u041f\u0440\u043e\u043f\u0443\u0441\u043a\u0430\u044e \u0441\u043a\u0443\u0447\u043d\u044b\u0435 \u0434\u0435\u0442\u0430\u043b\u0438 \u043f\u0440\u043e \u0440\u0435\u0433\u0438\u0441\u0442\u0440\u0430\u0446\u0438\u044e \u043d\u0430 amazon, \u00a0\u0432\u044b\u0431\u043e\u0440 \u041e\u0421, \u0437\u0430\u043f\u0443\u0441\u043a \u0441\u0435\u0440\u0432\u0430\u043a\u0430, \u0433\u0435\u043d\u0435\u0440\u0430\u0446\u0438\u044e ssh-\u043a\u043b\u044e\u0447\u0438\u043a\u0430.<br \/>\n\u0418\u0442\u0430\u043a, \u0435\u0441\u0442\u044c \u0441\u0435\u0440\u0432\u0435\u0440, \u043d\u0430 amazon ec2, redhat 7.<\/p>\n<hr \/>\n<p><strong>\u0421\u0435\u0440\u0432\u0435\u0440.<\/strong><br \/>\n<!--more--><\/p>\n<p><code><br \/>\n# yum update &amp;&amp; yum install epel-release<br \/>\n# yum install openvpn easy-rsa<br \/>\n# cd \/usr\/share\/doc\/openvpn-*\/sample\/sample-config-files\/<br \/>\n# cp server.conf \/etc\/openvpn<\/code><\/p>\n<p># mkdir \/etc\/openvpn\/rsa<br \/>\n# cp \u2013rf \/usr\/share\/easy-rsa\/2.0\/* \/etc\/openvpn\/rsa<\/p>\n<p># vi \/etc\/openvpn\/rsa\/vars<br \/>\n# cd \/etc\/openvpn\/rsa<br \/>\n# source .\/vars<br \/>\n# .\/clean-all<br \/>\n# .\/build-ca<br \/>\n# .\/build-key-server server<br \/>\n# .\/build-dh<br \/>\n# .\/build-key client<\/p>\n<p># cd \/etc\/openvpn\/rsa\/keys<br \/>\n# cp ca.crt server.crt server.key \/..\/..<br \/>\n# cat &lt;&lt;&#8216;EOF&#8217; &gt; \/etc\/openvpn\/server.conf<br \/>\n############# server.conf<br \/>\nport 1194<br \/>\nproto tcp<br \/>\ndev tun<br \/>\nca ca.crt<br \/>\ncert server.crt<br \/>\nkey server.key<br \/>\ndh \/etc\/openvpn\/rsa\/keys\/dh2048.pem<br \/>\ntopology subnet<br \/>\nserver 10.8.0.0 255.255.255.0<br \/>\nifconfig-pool-persist ipp.txt<br \/>\npush &#171;redirect-gateway def1 bypass-dhcp&#187;<br \/>\npush &#171;dhcp-option DNS 8.8.8.8&#187;<br \/>\npush &#171;dhcp-option DNS 8.8.4.4&#187;<br \/>\nclient-to-client<br \/>\nkeepalive 10 120<br \/>\ncomp-lzo<br \/>\nuser nobody<br \/>\ngroup nobody<br \/>\npersist-key<br \/>\npersist-tun<br \/>\nstatus openvpn-status.log<br \/>\nlog openvpn.log<br \/>\nlog-append openvpn.log<br \/>\nverb 3<br \/>\n#<br \/>\nEOF<\/p>\n<p># systemctl -f enable openvpn@server<br \/>\n# systemctl start openvpn@server<br \/>\n# systemctl -l status openvpn@server<\/p>\n<p>\u0414\u043e\u0431\u0430\u0432\u043b\u044f\u0435\u043c \u0444\u043e\u0440\u0432\u0430\u0440\u0434\u0438\u043d\u0433<\/p>\n<p><code># echo \"1\" &gt; \/proc\/sys\/net\/ipv4\/ip_forward<br \/>\n# sysctl -w net.ipv4.ip_forward=1<br \/>\n# iptables -t nat -A POSTROUTING -o eth0 -j MASQUERADE<\/code><\/p>\n<p>\u0412 &#171;Amazon Dashboard EC2&#187; \u0432\u044b\u0431\u0438\u0440\u0430\u0435\u043c \u043d\u0430\u0441\u0442\u0440\u043e\u0439\u043a\u0438 &#171;Security Groups&#187; \u0438 \u0433\u0440\u0443\u043f\u043f\u0443 \u0437\u0430\u0432\u044f\u0437\u0430\u043d\u043d\u0443\u044e \u043d\u0430 \u043d\u0430\u0448 \u0441\u0435\u0440\u0432\u0435\u0440. \u0414\u043e\u0431\u0430\u0432\u043b\u044f\u0435\u043c \u043f\u0440\u0430\u0432\u0438\u043b\u043e &#8212; \u043f\u0440\u0438\u043d\u0438\u043c\u0430\u0442\u044c \u0437\u0430\u043f\u0440\u043e\u0441\u044b \u043d\u0430 \u043f\u043e\u0440\u0442<\/p>\n<p><a href=\"https:\/\/www.unixpin.com\/wp-content\/uploads\/2016\/01\/joxi_screenshot_1452522301150.png\" rel=\"attachment wp-att-1035\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-thumbnail wp-image-1035\" src=\"https:\/\/www.unixpin.com\/wp-content\/uploads\/2016\/01\/joxi_screenshot_1452522301150-150x150.png\" alt=\"joxi_screenshot_1452522301150\" width=\"150\" height=\"150\" \/><\/a><\/p>\n<hr \/>\n<p><strong>\u041a\u043b\u0438\u0435\u043d\u0442.<\/strong><br \/>\n\u0421\u043a\u0430\u0447\u0438\u0432\u0430\u0435\u043c Windows \u0432\u0435\u0440\u0441\u0438\u044e <a href=\"https:\/\/openvpn.net\/index.php\/open-source\/downloads.html\" target=\"_blank\">\u0437\u0434\u0435\u0441\u044c <\/a>, \u0443\u0441\u0442\u0430\u043d\u0430\u0432\u043b\u0438\u0432\u0430\u0435\u043c, \u043d\u0435 \u0437\u0430\u0431\u044b\u0432\u0430\u0435\u043c TAP \u0434\u0440\u0430\u0439\u0432\u0435\u0440.<br \/>\n\u041a\u043e\u043f\u0438\u0440\u0443\u0435\u043c \u0441 \u043a\u0430\u0442\u0430\u043b\u043e\u0433\u0430 \u0441\u0435\u0440\u0432\u0435\u0440\u0430 \/etc\/openvpn\/rsa\/keys \u0444\u0430\u0439\u043b\u0438\u043a\u0438 ca.crt client.crt client.key \u0432 \u043a\u0430\u0442\u0430\u043b\u043e\u0433 C:\\Program Files\\OpenVPN\\config \u043a\u043b\u0438\u0435\u043d\u0442\u0430<br \/>\n\u0421\u043e\u0437\u0434\u0430\u0435\u043c \u0432 \u043a\u0430\u0442\u0430\u043b\u043e\u0433\u0435 C:\\Program Files\\OpenVPN\\config \u0444\u0430\u0439\u043b client.orig, \u0441\u043e \u0441\u043b\u0435\u0434\u0443\u044e\u0449\u0438\u043c \u0441\u043e\u0434\u0435\u0440\u0436\u0438\u043c\u044b\u043c<\/p>\n<p><code>############ client.ovpn<br \/>\nclient<br \/>\nport 1194<br \/>\ndev tun<br \/>\nproto tcp<br \/>\nremote ec2-XXXXXXXXX.us-west-2.compute.amazonaws.com 1194<br \/>\nremote-cert-tls server<br \/>\nverb 3<br \/>\ncomp-lzo<br \/>\npersist-key<br \/>\npersist-tun<br \/>\nnobind<br \/>\nca ca.crt<br \/>\ncert client.crt<br \/>\nkey client.key<br \/>\nroute-method exe<br \/>\nroute-delay 2<br \/>\n###########################<\/code><\/p>\n<p>\u0417\u0430\u043f\u0443\u0441\u043a\u0430\u0435\u043c GUI \u043a\u043b\u0438\u0435\u043d\u0442\u0430 \u0438\u0437-\u043f\u043e\u0434 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u044f Administrator, \u0430 \u0442\u043e \u043a\u043e\u043c\u0430\u043d\u0434\u044b \u043c\u0430\u0440\u0448\u0440\u0443\u0442\u0438\u0437\u0430\u0446\u0438\u0438 \u043d\u0435 \u0441\u043c\u043e\u0433\u0443\u0442 \u043f\u0440\u043e\u043f\u0438\u0441\u0430\u0442\u044c\u0441\u044f.<br \/>\n\u041f\u0440\u043e\u0432\u0435\u0440\u044f\u0435\u043c, \u0447\u0442\u043e \u0442\u0435\u043f\u0435\u0440\u044c \u043d\u0430\u0448 ip \u0440\u0435\u0437\u043e\u043b\u0432\u0438\u0442\u0441\u044f \u0433\u0434\u0435-\u0442\u043e \u0432 \u0410\u043c\u0435\u0440\u0438\u043a\u0435&#8230;<\/p>\n<p><a href=\"https:\/\/www.unixpin.com\/wp-content\/uploads\/2016\/01\/joxi_screenshot_1452517530008.png\" rel=\"attachment wp-att-1030\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-thumbnail wp-image-1030\" src=\"https:\/\/www.unixpin.com\/wp-content\/uploads\/2016\/01\/joxi_screenshot_1452517530008-150x150.png\" alt=\"joxi_screenshot_1452517530008\" width=\"150\" height=\"150\" \/><\/a><\/p>\n<p>\u0421\u0441\u044b\u043b\u043a\u0438 \u0432 \u0442\u0435\u043c\u0443:<\/p>\n<ul>\n<li><a href=\"http:\/\/www.tecmint.com\/setup-openvpn-server-with-linux-and-windows-clients-in-centos-rhel\/\" target=\"_blank\">http:\/\/www.tecmint.com\/setup-openvpn-server-with-linux-and-windows-clients-in-centos-rhel\/<\/a><\/li>\n<li><a href=\"http:\/\/www.tecmint.com\/how-to-enable-epel-repository-for-rhel-centos-6-5\/\" target=\"_blank\">http:\/\/www.tecmint.com\/how-to-enable-epel-repository-for-rhel-centos-6-5\/<\/a><\/li>\n<li><a href=\"http:\/\/sypexgeo.net\/ru\/demo\/\" target=\"_blank\">\u041f\u0440\u043e\u0432\u0435\u0440\u0438\u0442\u044c ip \u043f\u043e \u0433\u0435\u043e\u0431\u0430\u0437\u0435<\/a><\/li>\n<\/ul>\n","protected":false},"excerpt":{"rendered":"<p>\u041a\u0430\u043a \u0438\u0437\u0432\u0435\u0441\u0442\u043d\u043e, amazon \u0434\u0430\u0435\u0442 \u0432\u043e\u0437\u043c\u043e\u0436\u043d\u043e\u0441\u0442\u044c \u0437\u0430\u043f\u0443\u0441\u0442\u0438\u0442\u044c \u0431\u0435\u0441\u043f\u043b\u0430\u0442\u043d\u043e \u0432\u0438\u0440\u0442\u0443\u0430\u043b\u044c\u043d\u044b\u0435 \u0441\u0435\u0440\u0432\u0435\u0440\u0430 \u0432 \u043e\u0431\u043b\u0430\u043a\u0435 ( 750 \u0447\u0430\u0441\u043e\u0432 \u0432 \u043c\u0435\u0441\u044f\u0446 \u0431\u0435\u0441\u043f\u043b\u0430\u0442\u043d\u043e, \u043d\u0430 \u043e\u0434\u0438\u043d \u0433\u043e\u0434 ). \u0420\u0430\u0437 \u0435\u0441\u0442\u044c \u0442\u0430\u043a\u0430\u044f \u0445\u0430\u043b\u044f\u0432\u0430, \u0442\u043e \u043d\u0443\u0436\u043d\u043e \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u044c, \u043d\u0443 \u043f\u043e\u043f\u0440\u043e\u0431\u0443\u0435\u043c \u0434\u043b\u044f \u043d\u0430\u0447\u0430\u043b\u0430\u00a0\u043d\u0430\u0441\u0442\u0440\u043e\u0438\u0442\u044c \u00a0OpenVPN. \u041f\u0440\u043e\u043f\u0443\u0441\u043a\u0430\u044e \u0441\u043a\u0443\u0447\u043d\u044b\u0435 \u0434\u0435\u0442\u0430\u043b\u0438 \u043f\u0440\u043e \u0440\u0435\u0433\u0438\u0441\u0442\u0440\u0430\u0446\u0438\u044e \u043d\u0430 amazon, \u00a0\u0432\u044b\u0431\u043e\u0440 \u041e\u0421, \u0437\u0430\u043f\u0443\u0441\u043a \u0441\u0435\u0440\u0432\u0430\u043a\u0430, \u0433\u0435\u043d\u0435\u0440\u0430\u0446\u0438\u044e ssh-\u043a\u043b\u044e\u0447\u0438\u043a\u0430. \u0418\u0442\u0430\u043a, \u0435\u0441\u0442\u044c \u0441\u0435\u0440\u0432\u0435\u0440, \u043d\u0430 amazon ec2, redhat 7. \u0421\u0435\u0440\u0432\u0435\u0440.<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-1029","post","type-post","status-publish","format-standard","hentry","category-uncategorized"],"_links":{"self":[{"href":"https:\/\/www.unixpin.com\/index.php?rest_route=\/wp\/v2\/posts\/1029","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.unixpin.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.unixpin.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.unixpin.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.unixpin.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=1029"}],"version-history":[{"count":5,"href":"https:\/\/www.unixpin.com\/index.php?rest_route=\/wp\/v2\/posts\/1029\/revisions"}],"predecessor-version":[{"id":1038,"href":"https:\/\/www.unixpin.com\/index.php?rest_route=\/wp\/v2\/posts\/1029\/revisions\/1038"}],"wp:attachment":[{"href":"https:\/\/www.unixpin.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=1029"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.unixpin.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=1029"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.unixpin.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=1029"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}