现在的网络状况是:有一组linux服务器,网络段为10.0.1.0/24,现在用其中一台做vpn服务器 (vpn服务器不是其它服务器的网关), 其eth0: inet addr:10.0.1.4 Bcast:10.0.1.255 Mask:255.255.255.0, eth1: inet addr:221.10.24.214 Bcast:221.10.24.215 Mask:255.255.255.248,要实现在外部vpn拨入能访问整个服务器组。
server.conf配置如下:
local 221.10.24.214
port 1194
proto udp
dev tun
ca /usr/local/etc/vpnkeys/ca.crt
cert /usr/local/etc/vpnkeys/vpn_server.crt
key /usr/local/etc/vpnkeys/vpn_server.key
dh /usr/local/etc/vpnkeys/dh1024.pem
server 10.0.0.0 255.255.255.0
ifconfig-pool-persist /usr/local/etc/ipp.txt
push "route 10.0.1.0 255.255.255.0"
client-to-client
keepalive 10 120
comp-lzo
max-clients 100
persist-key
persist-tun
status /tmp/openvpn-status.log
verb 3
客户机配置文件:
client
dev tun
proto udp
remote 221.10.24.214 1194
resolv-retry infinite
nobind
persist-key
persist-tun
ca ca.crt
cert client01.crt
key client01.key
ns-cert-type server
comp-lzo
verb 3
客户端未拨号前路由表信息
Active Routes:
Network Destination Netmask Gateway Inte *** ce Metric
0.0.0.0 0.0.0.0 192.168.2.2 192.168.2.4 25
127.0.0.0 255.0.0.0 127.0.0.1 127.0.0.1 1
192.168.2.0 255.255.255.0 192.168.2.4 192.168.2.4 25
192.168.2.4 255.255.255.255 127.0.0.1 127.0.0.1 25
192.168.2.255 255.255.255.255 192.168.2.4 192.168.2.4 25
224.0.0.0 240.0.0.0 192.168.2.4 192.168.2.4 25
255.255.255.255 255.255.255.255 192.168.2.4 192.168.2.4 1
255.255.255.255 255.255.255.255 192.168.2.4 3 1
-
TAG标签 : 求助 192.168.2.4 10.0.0.6 服务器 127.0.0.1 /sbin/iptables
会员注册
会员登录
个人空间
发表评论