在EC2的ubuntu上配置openvpn还是比较简单的,主要是参考了这篇文章。简单的说就是aptitude install openvpn lzop然后在/usr/share/doc/openvpn/examples/easy-rsa/2.0里面依次运行source vars./clean-all./build-ca 自签CA./build-key-server server 签发服务器证书./build-key client 签发客户端证书./build-dh 生成Diffie Hellman参数运行以上命令后会在key目录下生成服务端证书,客户端证书之后就是配置OpenVPN
[这篇文章](http://www.vpser.net/build/linode-install-openvpn.html)
port 50000 #端口50000proto udp #使用udpdev tun #使用tunca key/ca.crt #根证书cert key/server.crt #证书key key/server.key # This file should be kept secretdh key/dh1024.pemserver 10.10.0.0 255.255.255.0 #ip段ifconfig-pool-persist ipp.txtpush “dhcp-option DNS 8.8.8.8"push “dhcp-option DNS 8.8.4.4” #推送的dnskeepalive 10 30comp-lzo #开启压缩max-clients 60 #最多60个客户端user nobodygroup nogrouppersist-keypersist-tunstatus openvpn-status.logverb 3mute 20 iptables -t nat -A POSTROUTING -s 10.168.0.0/16 -o eth0 -j MASQUERADE内核参数添加net.ipv4.ip_forward = 1
windows和linux下的客户端配置基本都是一样的,以前在学校使用openvpn也是用相同的配置文件的 。clientdev tunproto udpremote xxxx.xxx.xxx 50000resolv-retry infinitenobindpersist-keypersist-tunca ca.crtcert client.crtkey client.keyns-cert-type servercomp-lzoverb 3mute 20keepalive 20 60redirect-gateway #一定注意这个,这个是修改默认路由策略。