2010年9月8日星期三

linux 下vpn客户端配置

linux 下vpn客户端配置

配置步骤

1、安装软件包

(1)32位的包

#wget ftp://ftp.pbone.net/mirror/centos.karan.org/el5/extras/testing/i386/RPMS/lzo-2.02-3.el5.kb.i386.rpm #rpm -ivh lzo-2.02-3.el5.kb.i386.rpm #wget ftp://ftp.pbone.net/mirror/centos.karan.org/el5/extras/testing/i386/RPMS/openvpn-2.1-0.19.rc4.el5.kb.i386.rpm #rpm -ivh openvpn-2.1-0.19.rc4.el5.kb.i386.rpm 

(2)64位的包

#wget ftp://ftp.pbone.net/mirror/centos.karan.org/el5/extras/testing/x86_64/RPMS/lzo-2.02-3.el5.kb.x86_64.rpm #rpm -ivh lzo-2.02-3.el5.kb.x86_64.rpm #wget ftp://ftp.pbone.net/mirror/centos.karan.org/el5/extras/testing/x86_64/RPMS/openvpn-2.1-0.19.rc4.el5.kb.x86_64.rpm #rpm -ivh openvpn-2.1-0.19.rc4.el5.kb.x86_64.rpm 

2、配置文件

四个证书放在/etc/openvpn/ca/目录下

#vim /etc/openvpn/dev.ovpn  client dev tun proto tcp remote 公司网关IP 1194 float persist-key persist-tun ca /etc/openvpn/ca/ca.crt cert /etc/openvpn/ca/xxxx.crt key /etc/openvpn/ca/xxxx.key tls-auth /etc/openvpn/ca/ta.key 1 ns-cert-type server keepalive 10 30 comp-lzo verb 3 

#启动服务 # /etc/init.d/openvpn start # openvpn --config /etc/openvpn/dev.ovpn 2>&1 >/dev/null & 

这样就可以使用vpn了

没有评论: