OpenVPNÀ¸·Î VPN ±¸ÃàÇϱâ
ÃÑ ÆäÀÌÁö ¼ö : 3224

Àüü ÇÔ¼ö/¿ë¾î»çÀü
Facebook Joinc ±×·ì   Joinc QA »çÀÌÆ®



joinc´Â Firefox¿Í chrome¿¡¼­ Å×½ºÆ® Çß½À´Ï´Ù. IE¿¡¼­´Â Å×À̺íÀÌ ±úÁö°Å³ª À̹ÌÁö°¡ º¸ÀÌÁö ¾ÊÀ» ¼ö ÀÖ½À´Ï´Ù. ƯÈ÷ ±¸±Û DocsÀ̹ÌÁöÀÇ °æ¿ì ¿¢¹Úó¸®µÉ ¼ö ÀÖ½À´Ï´Ù.

Contents

1 OpenVPNÀ» ÀÌ¿ëÇÑ VPN ȯ°æ ±¸Ãà
1.1 Å×½ºÆ® ȯ°æ
1.2 OpenVPN ¼­¹ö ¼³Ä¡
1.3 OpenVPN ¼­¹ö ¼³Á¤
1.4 ´Ù¸¥ ÀÎÁõ
1.5 subnet ÀÌ¿ë
1.6 OpenVPN Ŭ¶óÀÌ¾ðÆ® ¼³Ä¡
1.7 OpenVPN Ŭ¶óÀÌ¾ðÆ® ¼³Á¤

1 OpenVPNÀ» ÀÌ¿ëÇÑ VPN ȯ°æ ±¸Ãà

OpenVPNÀº ¿ÀÇ ¼Ò½º ÇÁ·Î±×·¥À¸·Î TUN/TAP¹æ½ÄÀÇ °¡»ó »ç¼³¸ÁÀ» ±¸ÃàÇÒ ¼ö ÀÖµµ·Ï ÇÑ´Ù. OpenSSH º¸´Ù´Â Á» ´õ º¹ÀâÇÏ´Ù´Â ´ÜÁ¡ÀÌ ÀÖÁö¸¸, ¿î¿µÃ¼Á¦¿¡ »ó°ü¾øÀÌ ¼³Ä¡ÇÒ ¼ö ÀÖ´Ù´Â ÀåÁ¡ÀÌ ÀÖ´Ù. ¿©±â¿¡¼­´Â routed VPN À̶ó°íµµ ºÒ¸®´Â tun¹æ½ÄÀ¸·Î ±¸ÃàÇÒ °ÍÀÌ´Ù.

OpenVPNÀº SSL±â¹ÝÀÇ VPNÀ¸·Î openssl¶óÀ̺귯¸®¸¦ »ç¿ëÇÑ´Ù.


TUN ¹æ½ÄÀº ¿î¿µÃ¼Á¦¿¡ °¡»óÀÇ ³×Æ®¿öÅ© µð¹ÙÀ̽º¸¦ ¸¸µç´Ù. ÀÌ µð¹ÙÀ̽ºÀÇ À̸§Àº tunÀ¸·Î ÈçÈ÷ tun µð¹ÙÀ̽º ¶ó°í ÇÑ´Ù. OpenVPN ¼­¹ö°¡ ¼³Ä¡µÇ´Â ÄÄÇ»ÅÍ´Â À̸¦Å×¸é °¡»ó »ç¼³¸ÁÀ» °ü¸®ÇÏ´Â ¶ó¿ìÅͰ¡ µÇ´Â ¼ÀÀÌ´Ù. OpenVPN Ŭ¶óÀÌ¾ðÆ® ¿ª½Ã tun µð¹ÙÀ̽º°¡ ¸¸µé¾î Áö°í, ÀÌ °¡»ó µð¹ÙÀ̽º¸¦ ÀÌ¿ëÇØ¼­ VPN ¼­¹öÀÇ tun ÀÎÅÍÆäÀ̽º¿¡ ¿¬°á µÈ´Ù.

À§ÀÇ ±×¸²Àº OpenVPN ¼­¹ö¿Í Ŭ¶óÀÌ¾ðÆ®¿¡ tun µð¹ÙÀ̽º°¡ ¸¸µé¾îÁö°í, ÀÌ µð¹ÙÀ̽º¸¦ ÀÌ¿ëÇØ¼­ 10.8.0.0 ÁÖ¼Ò¿µ¿ªÀ» °¡Áö´Â »ç¼³¸ÁÀÌ ¸¸µé¾î Áø°ÍÀ» º¸¿©ÁØ´Ù.

TUN¹æ½ÄÀº ´ÙÀ½°ú °°Àº ÀåÁ¡À» °¡Áø´Ù.
  • ³×Æ®¿öÅ© µð¹ÙÀ̽º¸¦ »ý¼ºÇÔÀ¸·Î½á, ³×Æ®¿öÅ© ±¸Á¶°¡ ¸íÈ®ÇÏ°í ºñ±³Àû ¾ÈÁ¤ÀûÀ¸·Î ÀÛµ¿ÇÑ´Ù´Â ÀåÁ¡À» °¡Áø´Ù.
  • °íÁ¤ IP¸¦ ÇÒ´çÇÒ ¼ö À־ À§Ä¡¿¡ °ü°è ¾øÀÌ ¾ÈÁ¤ÀûÀ¸·Î »ç¼³¸ÁÀ» À¯ÁöÇÒ ¼ö ÀÖµµ·Ï ÇÑ´Ù.
  • »ç¼³¸ÁÀ» À§ÇÑ DHCP, ³×ÀÓ¼­¹ö¸¦ ±¸ÃàÇÒ ¼ö ÀÖ´Ù.

1.1 Å×½ºÆ® ȯ°æ

VPN¸¦ Á¦´ë·Î Å×½ºÆ® ÇÏ·Á¸é ÃÖ´ëÇÑ 3´ëÀÇ ÄÄÇ»ÅͰ¡ ÇÊ¿äÇÒ °ÍÀÌ´Ù. ±×·¯³ª ±»ÀÌ ±×·² Çʿ䰡 ¾ø´Ù. PC °¡»óÈ­ ¼Ö·ù¼ÇÀÌ Àֱ⠶§¹®ÀÌ´Ù. ³ª´Â PC °¡»óÈ­ ¼Ö·ù¼Ç Áß ÇϳªÀÎ VirtualBox¸¦ ÀÌ¿ë ÇØ¼­ VPN Å×½ºÆ® ȯ°æÀ» ¸¸µé¾ú´Ù. °¡»óÈ­ ¼Ö·ù¼Ç Âü ÁÁ´Ù. ÇϳªÀÇ PC·Î ´Ù¾çÇÑ Å×½ºÆ®¸¦ ÇÒ ¼ö ÀÖ´Ù.

È£½ºÆ® ¿î¿µÃ¼Á¦´Â ¿ìºÐÅõ ¸®´ª½º 10.04 À̸ç, °Ô½ºÆ® ¿î¿µÃ¼Á¦·Î´Â Windows XP¿Í ¿ìºÐÅõ ¸®´ª½º¸¦ ¼³Ä¡Çß´Ù. ÀÌ È¯°æ¿¡¼­ VPN Å×½ºÆ®¸¦ ÇÒ °ÍÀÌ´Ù.


1.2 OpenVPN ¼­¹ö ¼³Ä¡

VPN GW¿¡ ÇØ´ç ÇÏ´Â OpenVPN ¼­¹ö¸¦ ¼³Ä¡ÇÏ°í ¼³Á¤ÇÏ´Â °úÁ¤À» Á¤¸®ÇÑ´Ù. ¿ìºÐÅõ ¸®´ª½º 10.0.4¸¦ ±âÁØÀ¸·Î ÇÑ´Ù.
  1. openvpn ÆÐŰÁö¸¦ ¼³Ä¡ÇÑ´Ù.

    # sudo apt-get install openvpn 
     
  2. openvpnÀÇ ¼³Á¤ÆÄÀÏÀÇ À§Ä¡¸¦ ÁöÁ¤ÇÑ´Ù. /etc/openvpnÀ¸·Î Çß´Ù.

    # echo "AUTOSTART=\"openvpn\"" >> /etc/default/openvpn 
     
  3. ras ¼³Á¤À» ÇØ¾ß ÇÑ´Ù. »ó´çÈ÷ º¹ÀâÇÑ °úÁ¤ÀÌÁö¸¸, openvpn¼³Ä¡½Ã Á¦°øµÇ´Â ¿¹Á¦ ÆÄÀÏÀ» ÀÌ¿ëÇØ¼­ ºñ±³Àû °£´ÜÈ÷ ¼³Ä¡ÇÒ ¼ö ÀÖ´Ù.

    # cp -r /usr/share/doc/openvpn/examples/easy-rea/ /etc/openvpn  
     
  4. var ÆÄÀÏÀº ras ¼³Á¤À» À§ÇÑ È¯°æ º¯¼ö¸¦ ´ã°í ÀÖ´Ù. source¸í·ÉÀ» ÀÌ¿ëÇØ¼­ ȯ°æÀ» ¼³Á¤ÇÑ´Ù.

    # source /etc/openvpn/easy-rsa/2.0/vars 
     
  5. private key¸¦ ¸¸µç´Ù. ÀÌÁ¦ ºÎÅÍ ÀÛ¾÷ µð·ºÅ丮´Â /etc/openvpn/easy-rsa/2.0ÀÌ´Ù. Sign the certificate¿Í 1 out of 1 certificate ...´Â ¸ðµÎ y¸¦ ¼±ÅÃÇÑ´Ù.

    root:/etc/openvpn/easy-rsa/2.0# ./build-ca  
    Generating a 1024 bit RSA private key 
    ....++++++ 
    ...............................++++++ 
    writing new private key to 'ca.key' 
    ----- 
    .... 
    .... 
     
    Sign the certificate? [y/n]:y 
    1 out of 1 certificate requests certified, commit? [y/n]y 
     
  6. ¼­¹ö key¸¦ ¸¸µç´Ù. ¿ª½Ã Sign the...¿Í 1 out of 1 certi...¸¦ y·Î ÇÑ´Ù.

    # root:/etc/openvpn/easy-rsa/2.0# ./build-key-server server 
    Generating a 1024 bit RSA private key                                                            
    ................++++++ 
    ......................++++++                                                                     
    writing new private key to 'server.key' 
    -----                                                                                            
    .... 
    .... 
    .... 
    Sign the certificate? [y/n]:y 
    1 out of 1 certificate requests certified, commit? [y/n]y 
     
  7. client key¸¦ ¸¸µç´Ù. °èÁ¤/¾ÏÈ£ ÀÎÁõ¹æ½ÄÀÌ ¾Æ´Ñ key¸¦ ÀÌ¿ëÇÑ ÀÎÁõ¹æ½Ä½Ã »ç¿ëÇÑ´Ù. ÀÌ Å°¸¦ Ŭ¶óÀÌ¾ðÆ®¿¡ ¹èÆ÷Çϸé, Ŭ¶óÀÌ¾ðÆ®´Â °èÁ¤/¾ÏÈ£ ¾øÀÌ ¼­¹ö¿¡ ¿¬°áÇÒ ¼ö ÀÖ´Ù. Ű´Â ¸»±×´ë·Î ¼­¹ö¿¡ µå³ªµé±â À§ÇÑ ¿­¼èÀ̹ǷΠ¹èÆ÷½Ã º¸¾È¿¡ ÁÖÀÇÇØ¾ß ÇÑ´Ù. ¸ÞÀÏÀ̳ª ftpµîÀ¸·Î ¹èÆ÷ÇÏ´Â ÀÏÀÌ ¾øµµ·Ï ÇÑ´Ù. client key´Â Ŭ¶óÀÌ¾ðÆ®¸¶´Ù ÇÊ¿äÇÏ´Ù. ±×·¯¹Ç·Î ¸¸¾à 100¸íÀÇ Å¬¶óÀÌ¾ðÆ®¸¦ °ü¸®ÇØ¾ß ÇÑ´Ù¸é, 100°³ÀÇ client key¸¦ ¸¸µé¾î¾ß ÇÑ´Ù. yundreamÀ̶ó´Â À̸§ÀÇ client key¸¦ ¸¸µé±â·Î Çß´Ù. À§ÀÇ Å° »ý¼º°úÁ¤°ú µ¿ÀÏÇÏ´Ù.

    #root:/etc/openvpn/easy-rsa/2.0# ./build-key yundream  
     
  8. Diffie Hellman ÆÄ¶ó¸ÞÅ͸¦ »ý¼ºÇÑ´Ù.

    root@yundream-laptop:/etc/openvpn/easy-rsa/2.0# ./build-dh  
    Generating DH parameters, 1024 bit long safe prime, generator 2 
    This is going to take a long time 
    ....................................... 
     
À̷μ­ ¼­¹öÃø ¼³Á¤À» ¸¶Ä¡°í, yundream»ç¿ëÀÚ¸¦ À§ÇÑ keyµµ ¸¸µé¾ú´Ù. yundream »ç¿ëÀÚ¿¡°Ô ¾Æ·¡ÀÇ key¸¦ ¹èÆ÷ÇÏ¸é µÈ´Ù.
ca.crt 
yundream.crt 
yundream.key 
 

1.3 OpenVPN ¼­¹ö ¼³Á¤

ÀÌÁ¦ ³²Àº °Ç ¼³Á¤ÆÄÀÏÀÌ´Ù. OpenVPNÀ» ¼Ò°³Çϴ åÀÌ µû·Î ÃâÆÇµÇ¾úÀ» Á¤µµ·Î OpenVPNÀº ¸¹Àº ±â´ÉÀ» Á¦°øÇÑ´Ù. ¿©±â¿¡¼­´Â TUN µð¹ÙÀ̽º¸¦ ÀÌ¿ëÇØ¼­ step 3 VPN ȯ°æ ±¸ÃàÀ» ÇÒ °ÍÀÌ´Ù.

  1. ¼³Á¤ÆÄÀÏ º¹»ç
    ¿¹Á¦ ¼³Á¤ÆÄÀÏÀÎ /usr/share/doc/openvpn/examples/sample-config-files/server.conf.gzÀ» /etc/openvpn/openvpn.conf·Î º¹»çÇØ¼­ »ç¿ëÇϱâ·Î Çß´Ù.
  2. key À§Ä¡ ÁöÁ¤. ´ÙÀ½ÀÇ key ÆÄÀÏÀÇ À§Ä¡¸¸ Á¶ÀýÇØ ÁÖ¸é µÈ´Ù. ÇöÀç ¿ì¸®°¡ ¸¸µç Ű´Â /etc/openvpn/easy-rsa/2.0/keys µð·ºÅ丮 ¹Ø¿¡ ÀÖ´Ù.

    ca /etc/openvpn/easy-rsa/2.0/keys/ca.crt 
    cert /etc/openvpn/easy-rsa/2.0/keys/server.crt 
    key /etc/openvpn/easy-rsa/2.0/keys/server.key  # This file should be kept secret 
    dh /etc/openvpn/easy-rsa/2.0/keys/dh1024.pem 
     
  3. ±âŸ ÁÖ¿ä ¼³Á¤. ÁÖ¼®À¸·Î ¼³¸íÀ» ´ë½ÅÇÑ´Ù.

    # udp 1194¸¦ »ç¿ëÇÑ´Ù. 
    proto udp 
     
    # tun µð¹ÙÀ̽º¸¦ »ç¿ëÇÑ´Ù. 
    dev tun 
     
    # ¼­¹ö key °ª ¼³Á¤ 
    ca /etc/openvpn/easy-rsa/2.0/keys/ca.crt 
    cert /etc/openvpn/easy-rsa/2.0/keys/server.crt 
    key /etc/openvpn/easy-rsa/2.0/keys/server.key  # This file should be kept secret 
    dh /etc/openvpn/easy-rsa/2.0/keys/dh1024.pem 
     
    # VPN ³×Æ®¿öÅ© ¿µ¿ªÀ» ÁöÁ¤ÇÑ´Ù. ±âº»À¸·Î 10.8.0.0À» »ç¿ëÇÑ´Ù. 
    server 10.8.0.0  255.255.255.0 
     
    # subnet¿¡ Á¢±ÙÇÏ´Â °ÍÀ» Çã¶ôÇÑ´Ù. 
    push "route 10.8.0.0  255.255.255.0" 
     
    client-to-client 
     
  4. Å×½ºÆ®. /etc/init.d/openvpn ½ºÅ©¸³Æ®¸¦ ÀÌ¿ëÇØµµ µÇÁö¸¸, ¿¡·¯ ¸Þ½ÃÁö È®ÀÎÀ» À§Çؼ­ ½©¿¡¼­ Á÷Á¢ ½ÇÇàÇß´Ù.

    # openvpn --config /etc/openvpn/openvpn.conf 
     
  5. ¼º°øÀûÀ¸·Î ½ÇÇàÇß´Ù¸é, tun µð¹ÙÀ̽º¸¦ È®ÀÎÇÒ ¼ö ÀÖÀ» °ÍÀÌ´Ù.

    # ifconfig 
    ...... 
    tun0      Link encap:UNSPEC  HWaddr 00-00-00-00-00-00-00-00-00-00-00-00-00-00-00-00   
              inet addr:10.8.0.1  P-t-P:10.8.0.2  Mask:255.255.255.255 
              UP POINTOPOINT RUNNING NOARP MULTICAST  MTU:1500  Metric:1 
              RX packets:0 errors:0 dropped:0 overruns:0 frame:0 
              TX packets:0 errors:0 dropped:0 overruns:0 carrier:0 
              collisions:0 txqueuelen:100  
              RX bytes:0 (0.0 B)  TX bytes:0 (0.0 B) 
    ...... 
     

1.4 ´Ù¸¥ ÀÎÁõ

openvpnÀº key ÀÎÁõ¿Ü¿¡ PAM ¸ðµâ ÀÎÁõÀ» Çã¿ëÇÑ´Ù. ±× Áß À¯´Ð½ºÀÇ ID/PASSWORD±â¹ÝÀÇ pam auth ¸ðµâÀ» ±âº»ÀûÀ¸·Î Á¦°ø ÇÑ´Ù. ÀÌ ¸ðµâÀ» ÀÌ¿ëÇϸé, ¾ÆÀ̵ð/ÆÐ½º¿öµå ÀÎÁõ±îÁö ÇÔ²² »ç¿ëÇÒ ¼ö ÀÖ´Ù.

¼­¹öÃø ¼³Á¤ÆÄÀÏ¿¡ ¾Æ·¡ ³»¿ëÀ» Ãß°¡ÇÑ´Ù.
# so ÆÄÀÏÀÇ °æ·Î´Â ¹èÆ÷ÆÇ¿¡ µû¶ó¼­ ¾à°£½Ä ´Ù¸¦ ¼ö ÀÖ´Ù. 
plugin /usr/lib/openvpn/openvpn-pam-auth.so login 
 

Ŭ¶óÀÌ¾ðÆ® ¼³Á¤ÆÄÀÏ¿¡ ´ÙÀ½ÀÇ ³»¿ëÀ» Ãß°¡ÇÑ´Ù.
auth-user-pass 
 
ÀÌÁ¦ vpn Ŭ¶óÀÌ¾ðÆ®¸¦ ½ÇÇàÇϸé, ¾ÆÀ̵ð ÆÐ½º¿öµå¸¦ ¹¯´Â °É È®ÀÎÇÒ ¼ö ÀÖÀ» °ÍÀÌ´Ù.

1.5 subnet ÀÌ¿ë

VPN server¸¦ gateway·Î ÇØ¼­ Gateway°¡ °ü¸®ÇÏ´Â subnet¿¡ Á¢±ÙÀ» ¿øÇÒ ¶§°¡ ÀÖ´Ù. ±×¸²°ú °°Àº °æ¿ì´Ù.

  • VPN GWÀÇ °¡»ó ÀÎÅÍÆäÀ̽º ÁÖ¼Ò : 192.168.100.1
  • VPN¿¡¼­ °ü¸®ÇÏ´Â °¡»ó ³×Æ®¿öÅ© ÁÖ¼Ò : 192.168.100.0
  • VPN GW¿¡¼­ °ü¸®ÇÏ´Â subnet ÁÖ¼Ò : 192.168.56.0
¿øÇÏ´Â °ÍÀº VPN Client°¡ 192.168.56.0ÀÇ ÁÖ¼Ò¸¦ °¡Áö´Â ÄÄÇ»ÅÍ¿¡ Á¢±ÙÇϵµ·Ï ÇÏ´Â °ÍÀÌ´Ù. VPN ¼­¹öÀÇ ¼³Á¤ÆÄÀÏ¿¡ ¾Æ·¡ÀÇ ºÎºÐÀ» Ãß°¡ÇÑ´Ù.
push "route 192.168.56.0 255.255.255.0 192.168.100.1" 
 
push´Â Ŭ¶óÀÌ¾ðÆ®¿¡ ¼³Á¤°ªÀ» ¹Ð¾î ³Ö±â À§Çؼ­ »ç¿ëÇÑ´Ù. ¾Æ·¡ÀÇ ¸í·ÉÀº Ŭ¶óÀÌ¾ðÆ®·Î ÇÏ¿©±Ý ´ÙÀ½°ú °°ÀÌ ¶ó¿ìÆÃ Å×À̺íÀ» ¼³Á¤Çϵµ·Ï ÇÒ °ÍÀÌ´Ù.
yundream@yundream-desktop:~$ route 
Kernel IP routing table 
Destination     Gateway         Genmask         Flags Metric Ref    Use Iface 
192.168.100.0   192.168.100.1   255.255.255.0   UG    0      0        0 tun0 
192.168.100.0   *               255.255.255.0   U     0      0        0 tun0 
192.168.1.0     *               255.255.255.0   U     2      0        0 wlan0 
192.168.56.0    192.168.100.1   255.255.255.0   UG    0      0        0 tun0 
... 
 

ÀÌÁ¦ VPN ¼­¹ö¿¡¼­ IP forwardingÀÌ °¡´ÉÇϵµ·Ï ¼³Á¤ÇÑ´Ù.
  1. ip forwad°¡ °¡´ÉÇϵµ·Ï ÇÑ´Ù.

    # echo 1 > /proc/sys/net/ipv4/ip_forward 
     
  2. ip_forward °ªÀº ¸®ºÎÆÃ ¶§¸¶´Ù ±âº»°ªÀÎ 0À¸·Î Àç ¼³Á¤µÈ´Ù. ±âº» °ªÀ» 1·Î ÇÏ°í ½Í´Ù¸é, /etc/sysctl.conf¿¡ ¾Æ·¡¿Í °°ÀÌ ¼³Á¤ÇÏ¸é µÈ´Ù.

    net.ipv4.ip-forward = 1 
     
  3. tun µð¹ÙÀ̽º¸¦ ip forwarding °¡´ÉÇϵµ·Ï ÇÑ´Ù.

    # iptables -A INPUT -i tun+ -j ACCEPT 
    # iptables -A FORWARD -i tun+ -j ACCEPT 
     

1.6 OpenVPN Ŭ¶óÀÌ¾ðÆ® ¼³Ä¡

OpenVPNÀº Ŭ¶óÀÌ¾ðÆ®¿Í ¼­¹ö ±¸ºÐÀÌ ¾øÀÌ ÇϳªÀÇ ÇÁ·Î±×·¥À¸·Î ¹èÆ÷µÈ´Ù. ¼³Á¤ÆÄÀÏ·Î ¼­¹ö·Î ½ÇÇàµÉÁö Ŭ¶óÀÌ¾ðÆ®·Î ½ÇÇàµÉÁö°¡ °áÁ¤µÈ´Ù.

1.7 OpenVPN Ŭ¶óÀÌ¾ðÆ® ¼³Á¤

¼³Á¤Àº ¸®´ª½º¿Í À©µµ¿ì ¸ðµÎ µ¿ÀÏÇÏ´Ù. ´Ù¸¸ °æ·Î ¼³Á¤ ¹æ½Ä¿¡ À־ Â÷À̰¡ ÀÖÀ» »ÓÀÌ´Ù. ¸®´ª½º Ŭ¶óÀÌ¾ðÆ® ¼³Á¤ÆÄÀÏÀ» ¼öÁ¤Çؼ­ ¾²¸é µÈ´Ù. À¯Àú À̸§Àº winvpnÀ¸·Î Openvpn ¼­¹ö¿¡¼­ »ý¼ºÇÑ Å° ÆÄÀÏÀÌ´Ù.
  1. openvpn ȯ°æ ¼³Á¤À» À§ÇÑ µð·ºÅ丮¸¦ ¸¸µç´Ù. ³ª´Â /home/yundream/openvpn µð·ºÅ丮¸¦ ¸¸µé¾ú´Ù.
  2. key¸¦ º¸°üÇϱâ À§ÇÑ µð·ºÅ丮¸¦ ¸¸µé¾ú´Ù. mkdir /home/yundream/openvpn/keys
  3. Ŭ¶óÀÌ¾ðÆ® Å° ÆÄÀÏÀ» º¹»çÇØ¿Í¼­ À§¿¡¼­ ¸¸µç key µð·ºÅ丮¿¡ À§Ä¡ÇÑ´Ù. Ű ÀÎÁõ ¹æ½ÄÀÌ ¾Æ´Ñ ID/PW ÀÎÁõ ¹æ½ÄÀ» »ç¿ëÇÒ ¼öµµ Àִµ¥, ÀÌ´Â ³ªÁß¿¡ ´Ù·ïº¼ »ý°¢ÀÌ´Ù.
  4. openvpn ¼³Á¤ ÆÄÀÏÀ» ¸¸µé¾î¾ß Çϴµ¥, ¼­¹ö ¼³Á¤ÆÄÀϰú ¸¶Âù°¡Áö·Î ¹Ì¸® ¸¸µé¾îÁ® ÀÖ´Â ¼ÀÇà ¼³Á¤ÆÄÀÏÀ» ¾à°£ ¼öÁ¤Çؼ­ »ç¿ëÇÏ¸é µÈ´Ù. /usr/share/doc/openvpn/examples/sample-config-files/client.confÆÄÀÏÀ» /home/yundream/openvpn µð·ºÅ丮·Î º¹»çÇÑ´ÙÀ½ ¾Æ·¡¿Í °°ÀÌ ¼öÁ¤Çß´Ù.

    dev tun 
    proto udp 
    ... 
    # openvpn ¼­¹öÀÇ ÁÖ¼Ò Á¤º¸ 
    remote 192.168.55.1 1194 
     
    # »ç¿ëÇÒ ip ´ë¿ª 
    ifconfig 10.8.0.2 10.8.0.1 
     
    # key À§Ä¡ 
    ca /home/yundream/openvpn/keys/ca.crt 
    cert /home/yundream/openvpn/keys/localvpn1.crt 
    key /home/yundream/openvpn/keys/localvpn1.key 
     

ÀÌÁ¦ OpenVPN Ŭ¶óÀÌ¾ðÆ®¸¦ ½ÇÇàÇÏ¸é µÈ´Ù.
# sudo openvpn --config client.conf 
 
ifconfig·Î tun µå¶óÀ̹ö¸¦ È®ÀÎÇØº¸ÀÚ.
# ifconfig 
... 
tun0      Link encap:UNSPEC  HWaddr 00-00-00-00-00-00-00-00-00-00-00-00-00-00-00-00   
          inet addr:10.8.0.6  P-t-P:10.8.0.5  Mask:255.255.255.255 
          UP POINTOPOINT RUNNING NOARP MULTICAST  MTU:1500  Metric:1 
          RX packets:0 errors:0 dropped:0 overruns:0 frame:0 
          TX packets:0 errors:0 dropped:0 overruns:0 carrier:0 
          collisions:0 txqueuelen:100  
          RX bytes:0 (0.0 B)  TX bytes:0 (0.0 B) 
 

À©µµ¿ìµµ ¸®´ª½º¿Í µ¿ÀÏÇÏ´Ù. ¼³Á¤ÆÄÀÏ¿¡¼­ ca ÆÄÀÏÀÇ °æ·Î¸¸ ´Ù¸£°Ô ÇÏ¸é µÈ´Ù. openvpnÀ» ½ÇÇàÇϸé tray¿¡ ¾ÆÀÌÄÜÀÌ »ý±â´Â°É È®ÀÎÇÒ ¼ö ÀÖ´Ù. connect¸¦ Ŭ¸¯ÇÏ¸é ¿¬°áÀÌ ÁøÇàµÈ´Ù. ¼º°øÀûÀ¸·Î ½ÇÇàµÈ ´ÙÀ½¿¡ ipconfig·Î È®ÀÎÇØ º¸¸é TUN µå¶óÀ̹ö°¡ »ý±ä°É È®ÀÎÇÒ ¼ö ÀÖÀ» °ÍÀÌ´Ù.
Ethernet adapter ·ÎÄà ¿µ¿ª ¿¬°á 3: 
 
        Connection-specific DNS Suffix  . : 
        Description . . . . . . . . . . . : TAP-Win32 Adapter V9 
        Physical Address. . . . . . . . . : 00-FF-60-C7-BD-75 
        Dhcp Enabled. . . . . . . . . . . : Yes 
        Autoconfiguration Enabled . . . . : Yes 
        IP Address. . . . . . . . . . . . : 10.8.0.14 
        Subnet Mask . . . . . . . . . . . : 255.255.255.252 
        IP Address. . . . . . . . . . . . : fe80::2ff:60ff:fec7:bd75%4 
        Default Gateway . . . . . . . . . : 
        DHCP Server . . . . . . . . . . . : 10.8.0.13 
        DNS Servers . . . . . . . . . . . : fec0:0:0:ffff::1%1 
                                            fec0:0:0:ffff::2%1 
                                            fec0:0:0:ffff::3%1 
        Lease Obtained. . . . . . . . . . : 2010³â 9¿ù 20ÀÏ ¿ù¿äÀÏ ¿ÀÈÄ 5:24:35 
        Lease Expires . . . . . . . . . . : 2011³â 9¿ù 20ÀÏ È­¿äÀÏ ¿ÀÈÄ 5:24:35 
 

¼­·Î ¿¬°áÀÌ µÇ´ÂÁö pingÀ» ÀÌ¿ëÇØ¼­ Å×½ºÆ®ÇØ º¸°í, ¹®Á¦°¡ ¾ø´Ù¸é ssh ¿¬°áµîµµ Å×½ºÆ® ÇØº¸ÀÚ.


category_management
category__15
EmailÀ» ±âÀÔÇϸé, ´ñ±ÛÀÌ ¸ÞÀÏ·Î Àü´ÞµË´Ï´Ù.