このページの2つのバージョン間の差分を表示します。
両方とも前のリビジョン前のリビジョン次のリビジョン | 前のリビジョン | ||
05_network:04_vyatta:vyatta_openvpn [2012/12/07 09:04] – [openvpn設定] matsui | 05_network:04_vyatta:vyatta_openvpn [2012/12/14 08:23] (現在) – [vyatta-B] matsui | ||
---|---|---|---|
行 1: | 行 1: | ||
+ | ====== Vyatta Openvpn ====== | ||
+ | |Name|eth0|eth1|vtun0| | ||
+ | |vyatta-A|10.10.10.246/ | ||
+ | |vyatta-B|10.10.20.75/ | ||
+ | |||
+ | < | ||
+ | | ||
+ | | ||
+ | | ||
+ | -----+ vyatta-A +------------- | ||
+ | | ||
+ | | ||
+ | | ||
+ | </ | ||
+ | |||
+ | ====== インターフェース設定 ====== | ||
+ | ===== vyatta-A ===== | ||
+ | < | ||
+ | set system hostname router-A | ||
+ | set interfaces ethernet eth0 address 10.10.10.246/ | ||
+ | set interfaces ethernet eth1 address 192.168.10.246/ | ||
+ | set service nat rule 10 outbound-interface eth0 | ||
+ | set service nat rule 10 source address 192.168.10.246/ | ||
+ | set service nat rule 10 type masquerade | ||
+ | </ | ||
+ | |||
+ | |||
+ | ===== vyatta-B ===== | ||
+ | < | ||
+ | set system hostname router-B | ||
+ | set interfaces ethernet eth0 address 10.10.20.75/ | ||
+ | set interfaces ethernet eth1 address 192.168.20.75/ | ||
+ | set service nat rule 10 outbound-interface eth0 | ||
+ | set service nat rule 10 source address 192.168.20.75/ | ||
+ | set service nat rule 10 type masquerade | ||
+ | </ | ||
+ | |||
+ | ====== Generating Pre-Shared Key ====== | ||
+ | vyatta-A, vyatta-B ともに同じキーをコピーしておく。 | ||
+ | < | ||
+ | $ generate openvpn key / | ||
+ | </ | ||
+ | |||
+ | |||
+ | ====== openvpn設定 ====== | ||
+ | ===== vyatta-A ===== | ||
+ | < | ||
+ | set interfaces openvpn vtun0 | ||
+ | set interfaces openvpn vtun0 mode site-to-site | ||
+ | set interfaces openvpn vtun0 local-address 172.16.100.246 | ||
+ | set interfaces openvpn vtun0 remote-address 172.16.100.75 | ||
+ | set interfaces openvpn vtun0 shared-secret-key-file / | ||
+ | </ | ||
+ | |||
+ | ===== vyatta-B ===== | ||
+ | < | ||
+ | set interfaces openvpn vtun0 | ||
+ | set interfaces openvpn vtun0 mode site-to-site | ||
+ | set interfaces openvpn vtun0 local-address 172.16.100.75 | ||
+ | set interfaces openvpn vtun0 remote-address 172.16.100.246 | ||
+ | set interfaces openvpn vtun0 remote-host 10.10.10.246 | ||
+ | set interfaces openvpn vtun0 shared-secret-key-file / | ||
+ | </ | ||
+ | |||
+ | |||
+ | ====== static route ====== | ||
+ | ===== vyatta-A ===== | ||
+ | set protocols static route 192.168.20.0/ | ||
+ | |||
+ | ===== vyatta-B ===== | ||
+ | set protocols static route 192.168.10.0/ |