Ò»¡¢×éÍøÐèÇó
ÈçͼËùʾ£¬Ä³¹«Ë¾ÄÚ²¿ÓÐһ̨OA·þÎñÆ÷£¬ÔÚÍâÒÆ¶¯°ì¹«µÄ¹¤×÷ÈËÔ±ÐèҪͨ¹ývpn,²¦Èëµ½¹«Ë¾ÄÚÍøÀ´¶ÔÄÚÍø·þOA·þÎñÆ÷½øÐзÃÎÊ£¬²ÉÓÃÖ¤ÊéÈÏÖ¤µÄ·½Ê½¡£
¶þ¡¢ÍøÂçÍØÆË
Èý¡¢ÅäÖÃÒªµã
1¡¢»ù±¾ÉÏÍøÅäÖã¨ÏêϸÇë²Î¼û¡±Â·ÓÉģʽÉÏÍøÅäÖÃÕ½ڡ°£©
2¡¢ÅäÖÃÖ¤Êé
3¡¢ÅäÖÃDHCP·þÎñÆ÷
4¡¢ÅäÖÃVRCÈÏÖ¤»ù±¾²ÎÊý
5¡¢ÅäÖÃÓû§¼°ÆäȨÏÞ
6¡¢ÅäÖ÷ÃÎÊ¿ØÖƲßÂÔ
7¡¢ÅäÖÃPCÉϵÄVRC¿Í»§¶Ë
ËÄ¡¢ÅäÖò½Öè
²½ÖèÒ»¡¢»ù±¾ÉÏÍøÅäÖÃ
1£©½Ó¿Ú¼ÓÈëµ½ÇøÓò
Ñ¡Ôñ ×ÊÔ´¹ÜÀí > ÇøÓò£¬È»ºóµã»÷¡°Ìí¼Ó¡±£¬ÔÚµ¯³öµÄ´°¿ÚÖÐÉèÖÃeth0ËùÊôÇøÓò£¨area_eth0£©¡£
ÇøÓòÅäÖÃÈçÏ£º
2£©¿ª·ÅÍøÂç²à½Ó¿Úeth0ËùÔÚÇøÓò¡°area_eth0¡±µÄIPSec VPN·þÎñ¡£
Ñ¡Ôñ ϵͳ¹ÜÀí > ÅäÖã¬È»ºó¼¤»î¡°¿ª·Å·þÎñ¡±Ò³Ç©£¬µã»÷¡°Ìí¼Ó¡±¿ª·ÅÇøÓòarea_eth0µÄIPSecVPN·þÎñ¡£
c.°ó¶¨Ðé½Ó¿Ú¡£
Ñ¡Ôñ ÐéÄâ×¨Íø > Ðé½Ó¿Ú°ó¶¨£¬µã»÷¡°Ìí¼Ó¡±£¬½«Ðé½Ó¿ÚÓëÎïÀí½Ó¿Úeth0°ó¶¨¡£
d.ÅäÖýӿÚIPµØÖ·¡£
Ñ¡Ôñ ÍøÂç¹ÜÀí > ½Ó¿Ú > ÎïÀí½Ó¿Ú£¬Ìí¼ÓÒ»¸öeth0ºÍeth1½Ó¿ÚµÄIPµØÖ··Ö±ðΪ100.1.1.2,192.168.0.1£¬ÈçÏÂͼËùʾ¡£
½Ó¿ÚIPÅäÖÃÈçÏ£º
e.ÅäÖ÷ÓÉ
Ñ¡Ôñ ÍøÂç¹ÜÀí > ·ÓÉ£¬È»ºó¼¤»î¡°Â·ÓÉ±í¡±Ò³Ç©£¬µã»÷¡°Ìí¼Ó¡±°´Å¥£¬Ìí¼ÓĬÈÏ·ÓÉ¡£
²½Öè¶þ¡¢ÅäÖÃÖ¤Êé
1£©´´½¨±¾µØ¸ùÖ¤Êé¡£
a.Ñ¡Ôñ PKIÉèÖà > ±¾µØCA²ßÂÔ£¬¼¤»î¡°¸ùÖ¤Ê顱ҳǩ£¬µã»÷¡°»ñȡ֤Ê顱Á´½Ó£¬ÅäÖÃÉú³ÉиùÖ¤ÊéµÄÐÅÏ¢¡£
Éú³ÉµÄÐÂÖ¤ÊéÈçÏ£º
b.µ¼³ö¸ùÖ¤Êé
µã»÷¡°µ¼³öÖ¤Ê顱°´Å¥£¬Ñ¡Ôñµ¼³ö¸ñʽΪ¡°DER¡±£¬µã»÷¡¾µ¼³ö¡¿°´Å¥£¬µã»÷½çÃæÏÔʾµÄ¡°Ö¤Êéµã»÷ÏÂÔØ¡±£¬½«¸ùÖ¤Êéµ¼³öµ½¹ÜÀíÖ÷»ú¡£
2£©µ¼Èë¸ùÖ¤Êéµ½µÚÈý·½CAÖ¤Êé
Ñ¡Ôñ PKIÉèÖà > µÚÈý·½CAÖ¤Ê飬µã»÷Ò³ÃæÓÒÉÏ·½µÄ¡°µ¼ÈëCA¡±£¬½øÈë¡°µ¼ÈëCAÖ¤Ê顱½çÃæ£¬µ¼Èë¸ùÖ¤Êé¡£
3£©Ç©·¢²¢ÏÂÔØÓû§Ö¤Êé
a.Ñ¡Ôñ PKIÉèÖà > ±¾µØCA²ßÂÔ£¬¼¤»î¡°Ç©·¢Ö¤Ê顱ҳǩ£¬µã»÷¡°Éú³ÉÐÂÖ¤Ê顱£¬ÎªVRCÓû§¡°ipsec_client¡±Éú³ÉÒ»¸öÐÂÖ¤Êé¡£
Óû§Ö¤ÊéÅäÖÃÈçÏ£º
b.ÔÚÖ¤ÊéÁбí½çÃæ£¬µã»÷¡°test¡±Óû§Ö¤ÊéÌõÄ¿ÓÒ²àµÄ¡°ÏÂÔØ¡±Í¼±ê£¬½«¿Í»§¶ËÖ¤ÊéÏÂÔØµ½±¾µØ£¬Ñ¡ÔñÖ¤ÊéÀàÐÍΪ¡°PKCS12¸ñʽ¡±£¬ÊäÈëÃÜÂë¡£
c.²ÎÊýÉèÖÃÍê³Éºó£¬µã»÷¡¾µ¼³öÖ¤Êé¡¿°´Å¥£¬ÈçÏÂͼËùʾ¡£
µã»÷¡°Ö¤Êéµã»÷ÏÂÔØ¡±Á´½Ó£¬µ¯³öÎļþ±£´æ¶Ô»°¿ò£¬µã»÷¡¾±£´æ¡¿°´Å¥£¬Ñ¡ÔñÎļþ±£´æÂ·¾¶ºó£¬½«Ö¤ÊéÎļþ±£´æµ½¹ÜÀíÖ÷»ú±¾µØ±¸Óá£
²½ÖèÈý¡¢ÅäÖÃDHCP·þÎñÆ÷
1£©ÅäÖÃDHCPµØÖ·³Ø
Ñ¡Ôñ ÍøÂç¹ÜÀí > DHCP£¬¼¤»î¡°DHCP·þÎñÆ÷¡±Ò³Ç©,µã»÷¡°Ìí¼ÓµØÖ·³Ø¡±£¬ÅäÖÃDHCPµØÖ·³Ø£¬ÓÃÓÚΪVRCÓû§·ÖÅäÐéÄâIP¡£
˵Ã÷
a.Ö»ÓÐÍ£Ö¹DHCP·þÎñÆ÷µÄÔËÐУ¬²ÅÄܹ»ÅäÖÃDHCPµØÖ·³Ø¡£
b.DHCPµØÖ·³Ø²»ÄÜÓëÄÚ²¿Íø¶ÎÓаüº¬¹ØÏµ£¬¸ü²»ÄÜ·ÖÅäÓëÄÚ²¿ÍøÂçÔÚÍ¬Ò»Íø¶ÎµÄµØÖ·³Ø¡£
2£©ÔÚlo½Ó¿ÚÆôÓÃDHCP·þÎñÆ÷
ÔÚÁбí¿òÖÐÑ¡Ôñ¡°lo¡±ÎªÔËÐнӿڣ¬µã»÷¡¾Æô¶¯¡¿°´Å¥£¬¼´¿ÉÔÚlo½Ó¿ÚÉÏÆôÓÃDHCP·þÎñÆ÷¡£
²½ÖèËÄ¡¢ÅäÖÃVRCÈÏÖ¤µÄ»ù±¾²ÎÊý
Ñ¡Ôñ ÐéÄâ×¨Íø > VRC¹ÜÀí£¬¼¤»î¡°»ù±¾ÉèÖá±Ò³Ç©£¬ÅäÖÃVRCÈÏÖ¤µÄ»ù±¾²ÎÊý¡£
²½ÖèÎå¡¢ÅäÖÃÓû§¼°ÆäȨÏÞ
1£©ÅäÖñ¾µØÓû§¡°ipsec_client¡±¡£¸ÃÓû§Ãû³Æ±ØÐëÓë²½Öè¶þÓû§»§Ö¤ÊéÖеÄVRCÓû§µÄÓû§Ö¤ÊéÃû³Æ±£³ÖÒ»Ö¡£
a.Ñ¡Ôñ Óû§ÈÏÖ¤ > Óû§¹ÜÀí£¬È»ºóÔÚÊ÷ÐÎĿ¼ÖÐÑ¡ÔñÒ»¸ö×飨Èçiv_user£©£¬µã»÷¡°Ìí¼ÓÓû§¡±ÉèÖÃVRCÓû§£¬ÈçÏÂͼËùʾ¡£
ÔÚiv_user×éÖп´µ½testÓû§£º
b.µã»÷Óû§ipsec_clientÌõÄ¿ÓÒ²àµÄ²Ù×÷°´Å¥£¬½øÈëÓû§ÈÏÖ¤²ßÂÔÐ޸ĽçÃæ£¬¼¤»î¡°ÈÏÖ¤²ßÂÔ¡±Ò³Ç©£¬²»Ñ¡Ôñ¡°Ê¹ÓÃÈ«¾ÖÈÏÖ¤ÉèÖá±£¬Ñ¡Ôñ¡°Ö¤ÊéÈÏÖ¤¡±ºÍ¡°¿ÚÁîÈÏÖ¤¡±¡£
2£©ÅäÖÃȨÏÞ¶ÔÏó
a.Ñ¡Ôñ ÐéÄâ×¨Íø > VRC¹ÜÀí£¬¼¤»î¡°È¨ÏÞ¶ÔÏó¡±Ò³Ç©£¬µã»÷ȨÏÞ¶ÔÏóÁбí×óÉÏ·½µÄ¡°Ìí¼Ó¡±£¬ÅäÖÃȨÏÞ¶ÔÏó¡£
ȨÏÞ¶ÔÏóÅäÖÃÈçÏ£º
3£©ÅäÖÃVRCÓû§¡°test¡±µÄÓû§È¨ÏÞ
a.Ñ¡Ôñ ÐéÄâ×¨Íø > VRC¹ÜÀí£¬¼¤»î¡°Óû§È¨ÏÞ¡±Ò³Ç©£¬µã»÷VRCÓû§¡°ipsec_client¡±ÓÒ²àµÄ¡°È¨ÏÞÉèÖá±Í¼±ê£¬¡£
b.½øÈë¡°ipsec_client¡±µÄÓû§È¨ÏÞÏÔʾ½çÃæ£¬µã»÷¡°Ìí¼Ó¡±£¬ÅäÖÃVRCÓû§¡°ipsec_client¡±µÄÓû§È¨ÏÞ£¬ÈçÏÂͼËùʾ¡£
ipsec_clientÓû§µÄȨÏÞÅäÖÃÈçÏ£º
²½ÖèÁù¡¢ÅäÖ÷ÃÎÊ¿ØÖƲßÂÔ
1£©Ñ¡Ôñ ×ÊÔ´¹ÜÀí > µØÖ·£¬È»ºóÑ¡Ôñ¡°×ÓÍø¡±Ò³Ç©£¬µã»÷¡°Ìí¼Ó¡±£¬Ìí¼Ó×ÓÍøµØÖ·×ÊÔ´¡£
¼¤»î¡°Ö÷»ú¡±Ò³Ç©£¬Ìí¼ÓÖ÷»ú×ÊÔ´¡£
µØÖ·×ÊÔ´ÅäÖÃÈçÏ£º
b.Ñ¡Ôñ ·À»ðǽ > ·ÃÎÊ¿ØÖÆ£¬µã»÷¡°Ìí¼Ó²ßÂÔ¡±°´Å¥£¬ÅäÖ÷ÃÎÊ¿ØÖƲßÂÔ¡£
·ÃÎÊ¿ØÖƹæÔòÅäÖÃÈçÏ£º
²½ÖèÆß¡¢ÅäÖÃPCÉϵÄVRC¿Í»§¶Ë
ÅäÖÃPCÉϵÄVRC¿Í»§¶Ë£¬ÑéÖ¤VRCÓû§¡°ipsec_client¡±Ê¹Óá°±¾µØ¿ÚÁî+Ö¤ÊéÈÏÖ¤¡±µÄÈÏÖ¤·½Ê½µÇ¼IPSec VPNÍø¹Øºó£¬»ñµÃÄÚÍøOA¡°192.168.0.10¡±µÄ·ÃÎÊȨÏÞ¡£
1£©ÔÚÔ¶³ÌVRC¿Í»§»úÆ÷Éϰ²×°VPNÔ¶³Ì¿Í»§¶Ë¡£
2£©´ò¿ªVPN¿Í»§¶Ë£¬µã»÷¡¾Ð½¨Á¬½Ó¡¿°´Å¥£¬½øÈëÅäÖÃÁ¬½ÓÊôÐԵĴ°¿Ú£¬ÊäÈëÁ¬½ÓÃû³Æ¡°abc¡±£¬Ñ¡ÔñÈÏÖ¤·½Ê½Îª¡°Ö¤Êé+¿ÚÁîÈÏÖ¤¡±£¬Ñ¡Ôñ¡°Í¨¹ýµØÖ·»òÓòÃûµÇ¼¡±£¬µã»÷¡¾Ìí¼Ó¡¿°´Å¥£¬Ìí¼ÓÒ»¸öµØÖ·Îª¡°100.1.1.2¡±£¬ÈçÏÂͼËùʾ¡£
3£©µã»÷¡¾Ö¤ÊéÉèÖá¿£¬¡°¼ÓÔØ·½Ê½¡±Ñ¡Ôñ¡°±¾µØÖ¤ÊéÎļþ¡±£¬¡°Îļþ¸ñʽ¡±Ñ¡Ôñ¡°PKCS12Ö¤ÊéÎļþ¡±£¬Í¨¹ýÑ¡ÔñÕýÈ·µÄÎļþ·¾¶À´µ¼ÈëÖ¤ÊéÎļþ£¬ÈçÏÂͼËùʾ¡£
4£©µã»÷¡¾¼ÓÔØÖ¤Êé¡¿°´Å¥£¬µ¯³ö¡°ÊäÈëÃÜÂ롱´°¿Ú£¬VRCÓû§¿ÉÒÔÔڸô°¿ÚÖÐÊäÈëµ¼³öÖ¤ÊéʱÉèÖõÄÃÜÂë¡£Èç¹ûûÓÐÉèÖÃÃÜÂ룬ֱ½Óµã»÷¡¾È·¶¨¡¿°´Å¥£¬µ¯³ö¡°µ¼ÈëÖ¤Êé³É¹¦¡±Ìáʾ¿ò¡£
5£©½çÃæÖУ¬ÊäÈëÓû§¡°ipsec_client¡±µÇ¼µÄÃÜÂë¡°123456¡±£¬È»ºóµã»÷¡¾Á¬½Ó¡¿°´Å¥£¬VPNÔ¶³Ì¿Í»§¶ËÓëVPNÍø¹Ø³É¹¦½¨Á¢VRCËíµÀ¡£
Îå¡¢¼ì²éÅäÖýá¹û
1£©²é¿´VPN¿Í»§¶ËµÄ¡°VPN¿Í»§¶ËÊôÐÔ¡±´°¿Ú¡£
״̬´°¿ÚÏÔʾËíµÀ»ù±¾ÐÅÏ¢£¬ÒÔ¼°ÅäÖÃVPNÔ¶³Ì¿Í»§¶ËµÄһЩ»ù±¾²ÎÊý¡£
¼¤»î¡°·ÃÎÊȨÏÞ¡±Ò³Ç©£¬¿ÉÒԲ鿴VRCÓû§µÄ·ÃÎÊȨÏÞ£¬ÈçÏÂͼËùʾ¡£
2£©ÔÚVRC¿Í»§¶ËÖ÷»úÖУ¬¿ÉÒÔͨ¹ýÃüÁî¡°route print¡±²é¿´±¾µØÂ·ÓÉÅäÖã¬ÈçÏÂͼËùʾ¡£
3£©Ñ¡Ôñ ÐéÄâ×¨Íø > VRC¹ÜÀí£¬È»ºó¼¤»î¡°ÔÚÏßÓû§¡±Ò³Ç©£¬¿ÉÒÔ²é¿´Íø¹ØÉϵÄVRCÓû§ÐÅÏ¢£¬ÈçÏÂͼËùʾ¡£
4£©ÔÚVRCÓû§Ö÷»úÖУ¬pingͨ¡°192.168.0.10¡±£¬²¢Äܳɹ¦µÇ¼OAϵͳ¡£
Áù¡¢×¢ÒâÊÂÏî
1£©ÔÚIPSec VPNÍø¹ØÖУ¬±ØÐ뿪ÆôÓë¿Í»§¶ËÖ÷»úÏàÁ¬µÄÍø¹Ø½Ó¿ÚËùÊôÇøÓòµÄIPSec¹¦ÄÜ£»±ØÐë¹Ø±Õ¡°°üУÑéºÍ¡±¿ª¹Ø£¨Ä¬ÈÏÇé¿öÏÂÊǹرյģ©¡£
2£©VRCÓû§·ÃÎÊÊÚȨ×ÊԴǰ£¬±ØÐë¹Ø±Õ¿Í»§¶ËÖ÷»úÖеÄÈí¼þ·À»ðǽºÍ·À²¡¶¾Èí¼þ£¬·ñÔò¼´Ê¹VRCËíµÀÐÉ̳ɹ¦£¬Ò²¿ÉÄÜ»áÎÞ·¨Õý³£Í¨Ñ¶¡£
3£©ÄÚÍø·þÎñÆ÷µÄĬÈÏÍø¹Ø±ØÐëÖ¸ÏòVPNÍø¹Ø¡£