


| M1 |
|
| amvpn-keytool genca amvpn-keytool genkey amvpn-keytool gencert |
²£¥Íkey/cert ²£¥ÍVPN key/CSR ²£¥ÍVPN cert |
| M2 |
|
| amvpn-keytool
genkey amvpn-keytool -r root@M1:/usr/share/amvpn -c gencert |
²£¥ÍVPN key/CSR -c¥Nªí°õ¦æamvpn-keytool¥Ñ»·ºÝªº¾÷¾¹ |
| M1 | |
| amvpn-keytool -r root@M2:/usr/share/amvpn gencert | |
| M2 |
|
| amvpn-keytool validate |
0.99 |
| server(192.168.1.0) |
client(192.168.2.0) |
| tunnel-ip 192.168.16.1 route-ip 192.168.16.0 route-mask 255.255.255.0 route-ip 192.168.2.0 route-mask 255.255.255.0 #proxy(¥N²z¦øªA¾¹³]©w) #¦]¬°§Ú¤£»Ýn©Ò¥H¨S¦³³]©w #proxy-IP #proxy-port #proxy-user #proxy-password #SMB(ºô¸ôªÚ¾F)Âà°e³]©w #¥¦Âà°eUDP137ªº¸ê®Æ(¤À¨É¸ê·½¼s¼½) local-net 192.168.1.0 local-mask 255.255.255.0 remote-net 192.168.2.0 remote-mask 255.255.255.0 route-smb yes |
tunnel-ip 192.168.16.2 #server-ip "serverªºpublicªºIP" server-ip 111.222.333.444 route-ip 192.168.16.0 route-mask 255.255.255.0 route-ip 192.168.1.0 route-mask 255.255.255.0 #SMB(ºô¸ôªÚ¾F)Âà°e³]©w local-net 192.168.2.0 local-mask 255.255.255.0 remote-net 192.168.1.0 remote-mask 255.255.255.0 route-smb yes |
| server¥D¾÷ |
|
|
| ¬d¬Ý»Pclientªº³s½u Àˬdtun³]³Æ ¬d¬Ý¸ô¥Ñ ´ú¸Õ³s½u ´ú¸Õºô¸ôªÚ¾F ¦A¨Ó¨ì¨ä¥¦¹q¸£¤W¬d¬Ýºô¸ôªÚ¾F¤Wªº¾ãÓºô¸ô ¬Ý¬O§_¦³client¤Wªº¸s²Õ,¤Î¬O§_¥i¥Hª½±µ ³s½u¦pªG¥i¥H´N¦¨¥\¦pªG¥¢±Ñ½Ð¬Ý¤U± Âø¶µ°ÝÃD |
netstat ifconfig route ping 192.168.2.254 ping 192.168.2.x nmblookup teddy |
¥D¾÷¦WºÙ:7171 À³¸Ó¦s¦b ·|¦h¥X¤@Ótun0³]³Æ ·|¦h¤F¤@Ó¹h¹D 192.168.2.0 /tun0 192.168.16.0 /tun0 ping client ping client¤º³¡ªº¹q¸£ ¬d¸ßclient¤º³¡ªº¤@¥x¹q¸£¦WºÙ ¬d±o¨ì¤~¬O¥¿±` |
| client¥D¾÷ |
||
| ¬d¬Ý»Pserverªº³s½u Àˬdtun³]³Æ ¥H¤U¦P¤W |
netstat ifconfig route ping 192.168.1.254 ping 192.168.1.x nmblookup jim |
¥D¾÷¦WºÙ:7171 ·|¦h¥X¤@Ótun0³]³Æ ·|¦h¤F¤@Ó¹h¹D 192.168.1.0 /tun0 192.168.16.0 /tun0 ping server ping server¤º³¡ªº¹q¸£ ¬d¸ßserver¤º³¡ªº¬Y¥x¹q¸£¦WºÙ ¬dªº¨ì¤~¬O¥¿±` |
| 00 |
¤@¯ë¾÷¾¹ |
| 03 |
wins |
| 1B |
DBM |
| 1E |
Groupªº¦WºÙ |
| 01 |
Master Browser |
smtp-server-ip: ¶l¥ó¦øªA¾¹. notify-sender: ³Q³qª¾¤Hªº¶l¥ó«H½c. notify: «ü©w¨Æ¥óªº¦WºÙ:email-id1,email-id2 ®æ¦¡.
max-pending-mails: ³Ì¤jªºpending³qª¾¶l¥ó. connect:³s½u«Ø¥ß. disconnect: ³s½u¤¤Â_. keycert: ¤U±¤TÓÀɳQ×§ïVPN key, VPN cert,©M CA cert ÀÉ. Email-id ©ñ¸m¦b³qª¾«HªºfromÄæ¦ì.¨Ò¦p:
notify-sender-id admin@example.com
¦pªG³oÓ¥\¯à¨S¦³«ü©w¦bamvpnªºÀô¹ÒÀÉ,±N·|¨Ï¥Î¦p¤Uªº®æ¦¡:
<run-as-user>@<host-name>³oùتº <run-as-user> ¬Orun-as
-user¿ï¶µ©Ò«ü©wªº¨Ï¥ÎªÌ¦WºÙ,¦Ó<host-name>¬O¥»¾÷¥D¾÷ªº¦WºÙ.
¥i¥Îªº¨Æ¥ó¦p¤U. ¥¦¦³¤@¯ëªº®æ¦¡: notify
event-name:email-id-list. ¦Óemail-id-list¬O¤@өάO¦hÓªºemail.
¦hÓemail¥²¶·¨Ï¥Î,¤À¶}.¨Æ¥óªº¦WºÙ¥i¥H¬O¤U±ªº¥ô¤@Ó:
connect:³s½u«Ø¥ß. disconnect: ³s½u¤¤Â_. keycert: ¤U±¤TÓÀɳQ×§ïVPN key, VPN cert,©M CA cert ÀÉ.½d¨Ò¦p¤U:.
notify connect:abc@example.xyz.com,def@example.xyz.com
notify disconnect:abc@example.xyz.com notify keycert:abc@example.xyz.com ¦b³oºØ±¡ªp¤UºC³t³s½uªºemail³qª¾«H¥i¯àµo¶O³\¦h®É¶¡,¦Ó¥ý«eªº³qª¾«H¥i¯àÁÙ¥¼¦b°e,¦Ó¤U¤@Ó³qª¾«H¬O¥¿¦b³B²z¤¤.¬°¤FÁ×§K¤j¶qµ¥«Ý³q
ª¾n,¥i¯à¶OºÉ¨t²Îªº¸ê·½,³oÓ¿ï¶µ¥i¥H³Q¨Ï¥Î.¦pªG¨S¦³«ü©w¤º©w¬O5.
¦pªGamvpnµ{§Ç¬O³Q¨Ï¥Î('kill -9'§R°£),«h¥¦±NµLªk¶Ç°e³qª¾¶l¥ó.µM¦Ó³qª¾
±N·|±N·|¥Ñ¥t¤@ºÝ¨Ó¶Ç°e(¦pªG¥t¤@ºÝ¦³³]©w), ¦]¬°¥¦·|°»´ú¨ì¤@Ódisconnect.
¦]¦¹,«ØÄ³³Ì¦n¬O¨âÃä³£³]©w,¦p¦¹¥ô¤@Ãä³Qkill³£·|±o¨ì³qª¾.