##如果需要仅仅访问连接了vpn的设备而不走vpn的网络
只需要注释掉 /etc/openvpn/server.conf中
push "redirect-gateway def1"
push "block-outside-dns"
即可
树莓派安装pivpn
然后pivpn add 添加用户
##固定ip
server.conf 添加
client-config-dir /etc/openvpn/ccd
然后生成对应文件夹
$ sudo mkdir /etc/openvpn/ccd
然后根据配置名来建立,比如配置文件名叫 test
ifconfig-push 10.8.0.10 10.8.0.1
前者为固定ip 后者为服务器ip 类似test2就是
ifconfig-push 10.8.0.11 10.8.0.1
正确的应该是 10.8.0.11 255.255.255.0
然后重启服务
sudo systemctl restart openvpn
# windows 兼容性
ifconfig-push中的每一对IP地址表示虚拟客户端和服务器的IP端点。
它们必须从连续的/30子网网段中获取(这里是/30表示xxx.xxx.xxx.xxx/30,即子网掩码位数为30),
以便于与Windows客户端和TAP-Windows驱动兼容。
明确地说,每个端点的IP地址对的最后8位字节必须取自下面的集合:
[ 1, 2] [ 5, 6] [ 9, 10] [ 13, 14] [ 17, 18]
[ 21, 22] [ 25, 26] [ 29, 30] [ 33, 34] [ 37, 38]
[ 41, 42] [ 45, 46] [ 49, 50] [ 53, 54] [ 57, 58]
[ 61, 62] [ 65, 66] [ 69, 70] [ 73, 74] [ 77, 78]
[ 81, 82] [ 85, 86] [ 89, 90] [ 93, 94] [ 97, 98]
[101,102] [105,106] [109,110] [113,114] [117,118]
[121,122] [125,126] [129,130] [133,134] [137,138]
[141,142] [145,146] [149,150] [153,154] [157,158]
[161,162] [165,166] [169,170] [173,174] [177,178]
[181,182] [185,186] [189,190] [193,194] [197,198]
[201,202] [205,206] [209,210] [213,214] [217,218]
[221,222] [225,226] [229,230] [233,234]
国外文章和国内文章关于这个ip对的解释都错的
后面的ip不论设置成ip对的ip还是设置成服务器的ip,都访问不了
只能设置为255.255.255.0
耻辱柱:
1:http://dnaeon.github.io/static-ip-addresses-in-openvpn/
2:https://cloud.tencent.com/info/163c15beba92ea624b4a4277c239d42b.html
只有这个算对的:
https://github.com/OpenVPN/openvpn/blob/master/sample/sample-config-files/server.conf#L144-L170