Skip to content

Instantly share code, notes, and snippets.

@sherylynn
Last active November 28, 2022 12:57
Show Gist options
  • Select an option

  • Save sherylynn/ea08152072b7335eb23c87f3238e3c6b to your computer and use it in GitHub Desktop.

Select an option

Save sherylynn/ea08152072b7335eb23c87f3238e3c6b to your computer and use it in GitHub Desktop.
openvpn configure

##如果需要仅仅访问连接了vpn的设备而不走vpn的网络

只需要注释掉 /etc/openvpn/server.conf中

push "redirect-gateway def1"
push "block-outside-dns"

即可

树莓派安装pivpn

然后pivpn add 添加用户

##固定ip

server.conf 添加

client-config-dir /etc/openvpn/ccd

然后生成对应文件夹

$ sudo mkdir /etc/openvpn/ccd

然后根据配置名来建立,比如配置文件名叫 test

ifconfig-push 10.8.0.10 10.8.0.1

前者为固定ip 后者为服务器ip 类似test2就是

ifconfig-push 10.8.0.11 10.8.0.1

正确的应该是 10.8.0.11 255.255.255.0

然后重启服务

sudo systemctl restart openvpn

# windows 兼容性 ifconfig-push中的每一对IP地址表示虚拟客户端和服务器的IP端点。

它们必须从连续的/30子网网段中获取(这里是/30表示xxx.xxx.xxx.xxx/30,即子网掩码位数为30),

以便于与Windows客户端和TAP-Windows驱动兼容。

明确地说,每个端点的IP地址对的最后8位字节必须取自下面的集合:

	[  1,  2]   [  5,  6]   [  9, 10]   [ 13, 14]   [ 17, 18]
	[ 21, 22]   [ 25, 26]   [ 29, 30]   [ 33, 34]   [ 37, 38]
	[ 41, 42]   [ 45, 46]   [ 49, 50]   [ 53, 54]   [ 57, 58]
	[ 61, 62]   [ 65, 66]   [ 69, 70]   [ 73, 74]   [ 77, 78]
	[ 81, 82]   [ 85, 86]   [ 89, 90]   [ 93, 94]   [ 97, 98]
	[101,102]   [105,106]   [109,110]   [113,114]   [117,118]
	[121,122]   [125,126]   [129,130]   [133,134]   [137,138]
	[141,142]   [145,146]   [149,150]   [153,154]   [157,158]
	[161,162]   [165,166]   [169,170]   [173,174]   [177,178]
	[181,182]   [185,186]   [189,190]   [193,194]   [197,198]
	[201,202]   [205,206]   [209,210]   [213,214]   [217,218]
	[221,222]   [225,226]   [229,230]   [233,234]  

耻辱柱

国外文章和国内文章关于这个ip对的解释都错的

后面的ip不论设置成ip对的ip还是设置成服务器的ip,都访问不了

只能设置为255.255.255.0

耻辱柱:

1:http://dnaeon.github.io/static-ip-addresses-in-openvpn/

2:https://cloud.tencent.com/info/163c15beba92ea624b4a4277c239d42b.html

只有这个算对的:

https://www.shan.info/item/524-%E7%BB%99openvpn%E5%AE%A2%E6%88%B7%E5%88%86%E9%85%8D%E5%9B%BA%E5%AE%9Aip.html

@hzbd

hzbd commented Nov 28, 2022

Copy link
Copy Markdown

https://github.com/OpenVPN/openvpn/blob/master/sample/sample-config-files/server.conf#L144-L170

# To assign specific IP addresses to specific
# clients or if a connecting client has a private
# subnet behind it that should also have VPN access,
# use the subdirectory "ccd" for client-specific
# configuration files (see man page for more info).

# EXAMPLE: Suppose the client
# having the certificate common name "Thelonious"
# also has a small subnet behind his connecting
# machine, such as 192.168.40.128/255.255.255.248.
# First, uncomment out these lines:
;client-config-dir ccd
;route 192.168.40.128 255.255.255.248
# Then create a file ccd/Thelonious with this line:
#   iroute 192.168.40.128 255.255.255.248
# This will allow Thelonious' private subnet to
# access the VPN.  This example will only work
# if you are routing, not bridging, i.e. you are
# using "dev tun" and "server" directives.

# EXAMPLE: Suppose you want to give
# Thelonious a fixed VPN IP address of 10.9.0.1.
# First uncomment out these lines:
;client-config-dir ccd
;route 10.9.0.0 255.255.255.252
# Then add this line to ccd/Thelonious:
#   ifconfig-push 10.9.0.1 10.9.0.2

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment