关于VPN
VPN(虚拟专用网络)是一种使用公共电信基础设施(如互联网)为远程办公室或旅行用户提供安全访问中央组织网络的网络。VPN 为组织提供了创建安全通信通道的优势,同时降低成本、提高安全性和增加性能。
VPN 访问类型
类型
描述
远程访问 VPN
远程访问 VPN,也称为虚拟专用拨号网络(VPDN),是一种用户到局域网的连接,适用于需要从各种远程位置连接到私有网络的公司员工。
站点到站点 VPN
站点到站点 VPN 连接整个网络,这意味着可以用来将分支机构或远程办公室网络连接到公司总部网络。每个站点都配备有 VPN 网关,如路由器、防火墙、VPN集线器或安全设备。
VPN 技术
VPN 技术基于隧道的概念。VPN 隧道涉及建立和维护逻辑网络连接(可能包含中间跳点)。在此连接上,按照特定VPN协议格式构建的数据包被封装在其他基础或承载协议中,然后在 VPN 客户端和服务器之间传输,最后在接收端解封装。有几种计算机网络协议专门用于 VPN 隧道。最流行的两种VPN隧道协议是 SSL(安全套接层)和 IPSec(互联网协议安全)。
SSL VPN
SSL VPN使用SSL协议和传输层安全(TLS)协议,在远程用户和内部网络资源之间提供安全连接。它可以与标准网页浏览器一起使用,不需要在终端用户设备上安装专门的客户端软件。SSL VPN 为各种设备上的用户提供了灵活性、易用性和细粒度控制,可以从多个位置访问资源。
IPSec VPN
IPSec VPN 使用标准的 IPSec 机制,通过公共互联网建立 VPN 连接。IPSec 是一个在网络或数据包处理层提供安全性的协议框架。IPSec VPN 需要在客户端设备上安装IPSec客户端软件,然后才能建立连接。IPSec 可以满足大多数安全目标:认证、完整性和机密性。
VPN 隧道的示例使用
一名员工拥有一个公共IP地址为120.42.10.100的电话,希望连接到公司网络内部的SIP服务器。SIP服务器的内部IP地址为192.168.1.199,无法公开访问。在到达该服务器之前,电话需要通过一个公共IP地址为120.42.10.150、内部地址为192.168.1.190的 VPN 服务器。电话和SIP服务器之间的所有数据都需要保持机密,因此使用了安全的VPN。
以下步骤说明了 VPN 客户端-服务器交互的原理:
VPN 客户端通过外部网络接口连接到VPN服务器。
VPN 服务器从其子网中为 VPN 客户端分配一个IP地址。客户端获得一个内部IP地址,例如192.168.1.192,并创建一个虚拟网络接口,通过该接口将加密的数据包发送到隧道的另一端点(隧道另一端的设备)。
当 VPN 客户端希望与SIP服务器通信时,它准备一个地址为192.168.1.199的数据包,加密并封装在外部 VPN 数据包中。然后该数据包通过公共互联网发送到IP地址为120.42.10.150的 VPN 服务器。内部数据包是加密的,因此即使有人在互联网中截获数据包,也无法从中获取任何信息。内部加密数据包的源地址为192.168.1.192,目标地址为192.168.1.199。外部数据包的源地址为120.42.10.100,目标地址为120.42.10.150。
当数据包从互联网到达 VPN 服务器时,VPN 服务器解封装内部数据包,解密,发现目标地址为192.168.1.199,然后将其转发到目标SIP服务器192.168.1.199。
一段时间后,VPN 服务器收到来自192.168.1.199的回复数据包,发送给192.168.1.192。VPN 服务器查询其路由表,知道该数据包是发送给远程设备(IP电话)的,必须通过 VPN。
VPN 服务器加密该回复数据包,封装在 VPN 数据包中,并通过互联网发送。内部加密数据包的源地址为192.168.1.199,目标地址为192.168.1.192。外部 VPN 数据包的源地址为120.42.10.150,目标地址为120.42.10.100。
VPN 客户端接收并解封装数据包,解密内部数据包,并将其传递给上层的适当软件。
安装 OpenVPN 服务器
如果你已经有 VPN 服务器,可以跳过此部分。
OpenVPN 服务器是一组安装和配置工具,简化了 VPN 远程访问解决方案的快速部署。它支持 Linux、Windows 和 MAC 平台。
Linux 平台
安装和配置 OpenVPN服务器
OpenVPN 服务器软件是免费的。本节提供了在 Linux 平台(例如 Centos 5.8 和内核:2.6.18 308.el5 i686)上安装 OpenVPN 服务器(例如 OpenVPN 2.1.4.tar.gz)的信息。在安装之前,请确保硬件和系统满足以下要求:
双网卡。
系统内核支持通用 TUN/TAP 设备驱动程序(内核2.6.0以上)并且 TUN/TAP 模块已加载到内核中。
安装所需的模块“OpenSSL和LZO”。
检查 TUN/TAP 模块是否加载到内核中:
打开终端窗口。
输入以下命令。
[root@localhost~]# cat /dev/net/tun
如果返回信息是“cat: /dev/net/tun: File descriptor in a bad state”,则表示TUN/TAP模块已加载到内核中。
如果返回信息是“cat: /dev/net/tun: No such device”,则需要执行以下命令加载TUN/TAP模块。
[root@localhost~]# cd /usr/src/kernels/2.6.18 308.el5 i686/
[root@localhost 2.6.18 308.el5 i686]# make menuconfig
在弹出的配置屏幕中,选择 Device Drivers–>Network device support–>Universal TUN/TAP device driver support 并设置为 M。
你可以在线下载 OpenSSL 模块:http://www.openssl.org/。以下以“openssl 1.0.0e.tar.gz”为例。下载并存储在根目录。
安装 OpenSSL 模块:
打开终端窗口。
将安装包解压到/etc目录。
[root@localhost~]# cd /etc/
[root@localhost etc]# tar zvxf /openssl 1.0.0e.tar.gz
进入解压后的目录。
[root@localhost etc]# cd openssl 1.0.0e
输入以下命令安装包。
[root@localhost openssl 1.0.0e]# ./config
[root@localhost openssl 1.0.0e]# make
[root@localhost openssl 1.0.0e]# make install
你可以在线下载 LZO 模块:http://www.oberhumer.com/opensource/lzo/download/。 以下以“lzo2.02.tar.gz”为例。下载并存储在根目录。
安装LZO模块:
打开终端窗口。
将安装包解压到 /etc 目录。
[root@localhost~]# cd /etc/
[root@localhost etc]# tar zvxf /lzo 2.02.tar.gz
进入解压后的目录。
[root@localhost etc]# cd lzo 2.02
输入以下命令安装包。
[root@localhost lzo 2.02]# ./configure
[root@localhost lzo 2.02]# make
[root@localhost lzo 2.02]# make install
你可以在线下载 OpenVPN 软件:http://openvpn.net/index.php/open source/downloads.html。下载并存储在根目录。
安装 OpenVPN 服务器:
打开终端窗口。
将安装包解压到/etc目录
[root@localhost~]# cd /etc/
[root@localhost etc]# tar zvxf /openvpn 2.1.4.tar.gz
进入解压后的目录
[root@localhost etc]# cd openvpn 2.1.4
输入以下命令安装包。
[root@localhost openvpn 2.1.4]# ./configure
[root@localhost openvpn 2.1.4]# make
[root@localhost openvpn 2.1.4]# make install
如果找不到头文件和库文件,你应该使用以下命令代替上面提到的“./configure”命令。
./configure prefix=/usr/local with lzo headers=/usr/local/include with lzo lib=/usr/local/lib with ssl headers=/usr/local/include/openssl with ssl lib=/usr/local/lib
添加 OpenVPN 服务。
[root@localhost openvpn 2.1.4]# cp p sample scripts/openvpn.init /etc/init.d/openvpn
[root@localhost openvpn 2.1.4]# chkconfig add openvpn
为 OpenVPN 服务器和电话生成证书文件:
进入用于生成证书文件的目录(不同版本可能有所不同)。
[root@localhost ~]# cd /etc/openvpn 2.1.4/easy rsa/2.0
输入以下命令。
[root@localhost 2.0]# export D=pwd
[root@localhost 2.0]# export KEY_CONFIG=$D/openssl.cnf
[root@localhost 2.0]# export KEY_DIR=$D/keys
[root@localhost 2.0]# export KEY_SIZE=1024
[root@localhost 2.0]# export KEY_COUNTRY=CN
[root@localhost 2.0]# export KEY_PROVINCE=FJ
[root@localhost 2.0]# export KEY_CITY=XM
[root@localhost 2.0]# export KEY_ORG="yealink.com"
[root@localhost 2.0]# export KEY_EMAIL="admin@yealink.com"
生成 CA 证书。
[root@localhost 2.0]# ./clean all
[root@localhost easy rsa]# ./build ca
屏幕提示以下信息(如果你不想更改默认设置,请按 ENTER 键,否则输入所需值然后按 ENTER 键):
Generating a 1024 bit RSA private key
.............++++++
.............................++++++
writing new private key to 'ca.key'
-----
You are about to be asked to enter information that will be incorporated into your certificate request. What you are about to enter is what is called a Distinguished Name or a DN.
There are quite a few fields but you can leave some blank
For some fields there will be a default value,
If you enter '.', the field will be left blank.
-----
Country Name (2 letter code) [CN]:
State or Province Name (full name) [FJ]:
Locality Name (eg, city) [XM]:
Organization Name (eg, company) [yealink.com]:
Organizational Unit Name (eg, section) []:yealink.com
Common Name (eg, your name or your server's hostname) [yealink.com CA]:server
Name []:
Email Address [admin@yealink.com]:
为 OpenVPN 服务器生成证书。
[root@localhost 2.0]# ./build key server server
屏幕提示以下信息(如果你不想更改默认设置,请按 ENTER 键,否则输入所需值然后按 ENTER 键):
Generating a 1024-bit RSA private key
.............++++++
.............................++++++
writing new private key to 'server.key'
-----
You are about to be asked to enter information that will be incorporated into your certificate request.
What you are about to enter is what is called a Distinguished Name or a DN.
There are quite a few fields but you can leave some blank
For some fields there will be a default value,
If you enter '.', the field will be left blank.
-----
Country Name (2 letter code) [CN]:
State or Province Name (full name) [FJ]:
Locality Name (eg, city) [XM]:
Organization Name (eg, company) [yealink.com]:
Organizational Unit Name (eg, section) []:yealink.com
Common Name (eg, your name or your server's hostname) [yealink.com CA]:server
Name []:
Email Address [admin@yealink.com]: yealink.com
Please enter the following 'extra' attributes
to be sent with your certificate request
A challenge password []:abcd1234
An optional company name []:yealink.com
Using configuration from /root/openvpn-2.1.4/easy rsa/2.0/openssl.cnf
Check that the request matches the signature
Signature ok
The Subject's Distinguished Name is as follows
countryName :PRINTABLE:'CN'
stateOrProvinceName :PRINTABLE:'FJ'
localityName :PRINTABLE:'XM'
organizationName :PRINTABLE:'yealink.com' organizationalUnitName:PRINTABLE:'yealink.com'
commonName :PRINTABLE:'server'
emailAddress :IA5STRING:'yealink.com'
Certificate is to be certified until May 18 11:53:36 2023 GMT (3650 days) Sign the certificate? [y/n]:y
1 out of 1 certificate requests certified, commit? [y/n]y
Write out database with 1 new entries
Data Base Updated
为客户端生成证书。
[root@localhost 2.0]# ./build key client
屏幕提示以下信息(如果你不想更改默认设置,请按 ENTER 键,否则输入所需值然后按 ENTER 键):
Generating a 1024 bit RSA private key
.............++++++
.............................++++++
writing new private key to 'server.key'
-----
You are about to be asked to enter information that will be incorporated into your certificate request.
What you are about to enter is what is called a Distinguished Name or a DN.
There are quite a few fields but you can leave some blank
For some fields there will be a default value,
If you enter '.', the field will be left blank.
-----
Country Name (2 letter code) [CN]:
State or Province Name (full name) [FJ]:
Locality Name (eg, city) [XM]:
Organization Name (eg, company) [yealink.com]:
Organizational Unit Name (eg, section) []:yealink.com
Common Name (eg, your name or your server's hostname) [yealink.com CA]:server
Name []:
Email Address [admin@yealink.com]:
Please enter the following 'extra' attributes
to be sent with your certificate request
A challenge password []:abcd1234
An optional company name []:yealink.com
Using configuration from /root/openvpn-2.1.4/easy rsa/2.0/openssl.cnf
Check that the request matches the signature
Signature ok
The Subject's Distinguished Name is as follows
countryName :PRINTABLE:'CN'
stateOrProvinceName :PRINTABLE:'FJ'
localityName :PRINTABLE:'XM'
organizationName :PRINTABLE:'yealink.com' organizationalUnitName:PRINTABLE:'yealink.com'
commonName :PRINTABLE:'server'
emailAddress :IA5STRING:'yealink.com'
Certificate is to be certified until May 18 11:53:36 2023 GMT (3650 days) Sign the certificate? [y/n]:y
1 out of 1 certificate requests certified, commit? [y/n]y
Write out database with 1 new entries
Data Base Updated
生成服务器的 dh1024.pem 文件。
[root@localhost 2.0]# ./build dh
屏幕提示以下信息:
Generating DH parameters, 1024 bit long safe prime, generator 2
This is going to take a long time
如果屏幕提示“./build dh: line 7: dhparam: command not found”,你需要编辑/etc/openvpn 2.1.4/easy rsa/2.0目录中的“build dh”文件。将“$OPENSSL”设置为“openssl”并保存文件。
所有证书文件生成在“/openvpn 2.1.4/easy rsa/2.0/keys”目录中。
配置服务器的配置文件:
在路径 /etc 下创建一个新目录“openvpn”。
[root@localhost ~]# mkdir /etc/openvpn
在路径 /etc/openvpn 下创建一个新目录“keys”
[root@localhost ~]# mkdir /etc/openvpn/keys
进入 OpenVPN 服务器的安装目录。
[root@localhost ~]# cd /etc/openvpn 2.1.4
将服务器所需的证书文件复制到上面创建的“keys”目录中。
[root@localhost openvpn 2.1.4]# cp easy rsa/2.0/keys/ca.crt /etc/openvpn/keys/
[root@localhost openvpn 2.1.4]# cp easy rsa/2.0/keys/dh1024.pem /etc/openvpn/keys/
[root@localhost openvpn 2.1.4]# cp easy rsa/2.0/keys/server.crt /etc/openvpn/keys/
[root@localhost openvpn 2.1.4]# cp easy rsa/2.0/keys/server.key /etc/openvpn/keys/
将示例配置文件目录中的“server.conf”文件复制到上面创建的“openvpn”目录中。
[root@localhost openvpn 2.1.4]# cp sample config files/server.conf /etc/openvpn
根据你的实际网络环境编辑“server.conf”文件并保存更改。
[root@localhost ~]# vi /etc/openvpn/server.conf
按“I”键进入插入模式并修改所需参数,然后按“Esc”键返回命令模式并输入“wq!”。以下是一个示例:
根据实际网络环境配置服务器的网络设置,如 TCP/IP 转发功能和 VPN 客户端与内网之间的路由条目。有关更多信息,请联系你的网络管理员。
启用 TCP/IP 转发:
打开一个终端窗口。
编辑/etc目录中的“sysctl.conf”文件并保存更改。
[root@localhost ~]# vi /etc/sysctl.conf
按“I”键进入插入模式并将“net.ipv4.ip_forward”设置为1,然后按“Esc”键返回命令模式并输入“wq!”。
启动 OpenVPN 服务:
进入 OpenVPN 服务器的安装目录。
[root@localhost ~]# cd /etc/openvpn 2.1.4
启动 OpenVPN 服务。
[root@localhost openvpn 2.1.4]# service openvpn start
为 VPN 客户端创建 OpenVPN TAR 文件
OpenVPN 需要使用证书来帮助建立连接到 OpenVPN 服务器的客户端的真实性。你需要从系统中获取 ca.crt、client.crt、client.key 和 vpn.cnf 文件,然后将这些文件打包为 TAR 格式。
配置客户端的配置文件:
在路径 /etc/openvpn 下创建一个新目录“client”。
[root@localhost ~]# mkdir /etc/openvpn/client
在路径 /etc/openvpn/client 下创建一个新目录“keys”。
[root@localhost ~]# mkdir /etc/openvpn/client/keys
进入 OpenVPN 服务器的安装目录。
[root@localhost ~]# cd /etc/openvpn 2.1.4
将客户端所需的证书文件复制到之前创建的“/etc/openvpn/client/keys”目录中。
[root@localhost openvpn 2.1.4]# cp easy rsa/2.0/keys/ca.crt /etc/openvpn/client/keys/
[root@localhost openvpn 2.1.4]# cp easy rsa/2.0/keys/client.crt /etc/openvpn/client/keys/
[root@localhost openvpn 2.1.4]# cp easy rsa/2.0/keys/client.key /etc/openvpn/client/keys/
将示例配置文件目录中的“client.conf”文件复制到上面创建的“client”目录中并将其重命名为vpn.cnf。
[root@localhost openvpn 2.1.4]# cp sample config files/client.conf /etc/openvpn/client/vpn.cnf
编辑“vpn.cnf”文件并保存更改。
[root@localhost openvpn 2.1.4]# cd /etc/openvpn/client [root@localhost client]# vi vpn.cnf
按“I”键进入插入模式并修改所需参数,然后按“Esc”键返回命令模式并输入“wq!”。
以下参数应与服务器的配置相同:
remote 218.107.220.201 1194 udp
dev tun
dev type tun
以下定义了亿联话机的 OpenVPN 证书和密钥:
ca ca.crt
cert client.crt
key client.key
以下图示显示了 vpn.cnf 文件的一部分供参考:
在 Linux 平台上打包 TAR 文件:
输入以下命令打包 TAR 文件:
[root@localhost ~]# cd /etc/openvpn/client
[root@localhost client]# tar cvpf openvpn.tar *
在 client 目录中生成一个 openvpn.tar 文件。
Windows 平台
安装和配置 OpenVPN 服务器
OpenVPN 服务器软件是免费的。你可以在线下载适用于 Windows 平台的 OpenVPN 服务器软件。本节提供了如何在 Windows XP 平台上安装 OpenVPN 服务器(例如,openvpn 2.1.1 install.exe)。在安装之前,确保硬件和系统满足以下要求:
双网卡。
系统内核支持 TUN/TAP 模块。
在 Windows XP 平台上安装 OpenVPN 服务器:
双击本地系统上的安装文件。
按照提示完成安装。默认安装目录是C:\Program Files\OpenVPN\。
为 OpenVPN 服务器和话机生成证书文件:
进入 OpenVPN 服务器的安装目录。
打开 easy rsa 文件夹中的 vars.bat 文件并编辑以下参数:
set KEY_COUNTRY=US
set KEY_PROVINCE=CA
set KEY_CITY=SanFrancisco
set KEY_ORG=OpenVPN
set KEY_EMAIL=mail@host.domain
以下是配置这些参数的示例:
set KEY_COUNTRY=CN
set KEY_PROVINCE=FJ
set KEY_CITY=XM
set KEY_ORG=Yealink
set KEY_EMAIL=admin@yealink.com
点击 开始–>运行。
在弹出的对话框中输入cmd 并点击 确定 打开命令提示符屏幕。
进入 OpenVPN 服务器安装目录中的 easy rsa 目录。
C:\Documents and Settings\Administrator>cd \Program Files\OpenVPN\easy rsa
输入以下命令。
C:\Program Files\OpenVPN\easy rsa>init config.bat
C:\Program Files\OpenVPN\easy rsa>vars
C:\Program Files\OpenVPN\easy rsa>clean all.bat
生成CA证书。
C:\Program Files\OpenVPN\easy rsa>build ca.bat
屏幕提示以下信息(如果你不想更改默认设置,按 ENTER 键,否则输入所需的值然后按 ENTER 键):
Loading 'screen' into random state done
Generating a 1024 bit RSA private key
................++++++
...............................++++++
writing new private key to 'keys\ca.key'
-----
You are about to be asked to enter information that will be incorporated into your certificate request.
What you are about to enter is what is called a Distinguished Name or a DN.
There are quite a few fields but you can leave some blank
For some fields there will be a default value,
If you enter '.', the field will be left blank.
-----
Country Name (2 letter code) [CN]:
State or Province Name (full name) [FJ]:
Locality Name (eg, city) [XM]:
Organization Name (eg, company) [Yealink]:
Organizational Unit Name (eg, section) []:
Common Name (eg, your name or your server's hostname) []: CA
Email Address [admin@yealink.com]:
生成服务器的 dh1024.pem 文件。
C:\Program Files\OpenVPN\easy rsa>build dh.bat
屏幕提示以下信息:
Loading 'screen' into random state done
Generating DH parameters, 1024 bit long safe prime, generator 2
This is going to take a long time
为 OpenVPN 服务器生成证书。
C:\Program Files\OpenVPN\easy rsa>build key server.bat server
屏幕提示以下信息(如果你不想更改默认设置,按 ENTER 键,否则输入所需的值然后按 ENTER 键):
Loading 'screen' into random state done
Generating a 1024 bit RSA private key
...............................................++++++
.....................++++++
writing new private key to 'keys\server.key'
-----
You are about to be asked to enter information that will be incorporated into your certificate request.
What you are about to enter is what is called a Distinguished Name or a DN.
There are quite a few fields but you can leave some blank
For some fields there will be a default value,
If you enter '.', the field will be left blank.
-----
Country Name (2 letter code) [CN]:
State or Province Name (full name) [FJ]:
Locality Name (eg, city) [XM]:
Organization Name (eg, company) [Yealink]:
Organizational Unit Name (eg, section) []:
Common Name (eg, your name or your server's hostname) []: Server
Email Address [admin@yealink.com]:
Please enter the following 'extra' attributes to be sent with your certificate request
A challenge password []:serverpwd
An optional company name []:
Using configuration from openssl.cnf
Loading 'screen' into random state-done
Check that the request matches the signature
Signature ok
The Subject's Distinguished Name is as follows
countryName :PRINTABLE:'CN'
stateOrProvinceName :PRINTABLE:'FJ'
localityName :PRINTABLE:'XM'
organizationName :PRINTABLE:'Yealink'
organizationalUnitName:PRINTABLE:'EMB'
commonName :PRINTABLE:'Server'
emailAddress :IA5STRING:'admin@yealink.com'
Certificate is to be certified until Jan 20 13:10:22 2023 GMT (3650 days)
Sign the certificate? [y/n]:y
1 out of 1 certificate requests certified, commit? [y/n]y
Write out database with 1 new entries
Data Base Updated
为客户端生成证书。
C:\Program Files\OpenVPN\easy rsa>build key.bat client
屏幕提示以下信息(如果你不想更改默认设置,按 ENTER 键,否则输入所需的值然后按 ENTER 键):
Loading 'screen' into random state done
Generating a 1024 bit RSA private key
...............................................++++++
.....................++++++
writing new private key to 'keys\Client.key'
-----
You are about to be asked to enter information that will be incorporated into your certificate request.
What you are about to enter is what is called a Distinguished Name or a DN.
There are quite a few fields but you can leave some blank
For some fields there will be a default value,
If you enter '.', the field will be left blank.
-----
Country Name (2 letter code) [CN]:
State or Province Name (full name) [FJ]:
Locality Name (eg, city) [XM]:
Organization Name (eg, company) [Yealink]:
Organizational Unit Name (eg, section) []:
Common Name (eg, your name or your server's hostname) []: Client
Email Address [admin@yealink.com]:
Please enter the following 'extra' attributes to be sent with your certificate request
A challenge password []:clientpwd
An optional company name []:
Using configuration from openssl.cnf
Loading 'screen' into random state-done
Check that the request matches the signature
Signature ok
The Subject's Distinguished Name is as follows
countryName :PRINTABLE:'CN'
state orProvinceName :PRINTABLE:'FJ'
localityName :PRINTABLE:'XM'
organizationName :PRINTABLE:'Yealink'
organizationalUnitName:PRINTABLE:'EMB'
commonName :PRINTABLE:'Client'
emailAddress :IA5STRING:'admin@yealink.com'
Certificate is to be certified until Jan 20 13:10:22 2023 GMT (3650 days)
Sign the certificate? [y/n]:y
1 out of 1 certificate requests certified, commit? [y/n]y
Write out database with 1 new entries
Data Base Updated
配置服务器的配置文件:
进入 OpenVPN 服务器的安装目录。
在目录中创建一个新文件夹“serverconfig”。
将示例配置文件夹中的“server.ovpn”文件复制到上面创建的 serverconfig 文件夹中。
根据你的实际网络环境编辑“server.ovpn”文件并保存更改。
以下是一个示例:
根据实际网络环境配置服务器的网络设置,如 TCP/IP 转发功能、Internet 连接共享功能和 VPN 客户端与内网之间的路由条目。有关更多信息,请联系你的网络管理员。
启用 TCP/IP 转发:
点击 开始 > 运行。
在弹出的对话框中输入 Regedit.exe 并点击 确定。
点击 HKEY_LOCAL_MACHINE–>SYSTEM–>CurrentControlSet–>Services–>Tcpip–>Parameters。
将 IPEnableRouter 设置为1。
为内部网卡启用 Internet 连接共享:
打开网络连接。
右键点击内部网卡的本地连接并选择属性。
在高级选项卡上,选中允许其他网络用户通过此计算机的Internet连接连接复选框。
从家庭网络连接下拉菜单中选择服务器的虚拟网卡。
点击确定保存更改。
为 VPN 客户端创建 OpenVPN TAR 文件
你可以使用 7-Zip 或 GnuWin32 工具在 Windows 平台上打包 TAR 文件。你可以在线下载7-Zip:http://www.7-zip.org/ 和GnuWin32:http://gnuwin32.sourceforge.net/packages/gtar.htm。本节提供了如何在 Windows XP 平台上使用 7-Zip 打包 TAR 文件。
配置客户端的配置文件:
在C:/目录中创建一个新文件夹“openvpn”。
将示例配置文件夹中的 client.ovpn 文件复制到 openvpn 文件夹中。
将 client.ovpn 文件重命名为 vpn.cnf。
在 openvpn 文件夹中创建一个新文件夹“keys”。
将 ca.crt、client.crt 和 client.key 文件复制到上面创建的 keys 文件夹中。
编辑 vpn.cnf 文件。以下参数应与服务器的配置相同:
remote 218.107.220.201 1194 udp
dev tun
dev type tun
以下定义了Yealink话机的OpenVPN证书和密钥:
ca ca.crt
cert client.crt
key client.key
以下图示显示了 vpn.cnf 文件的一部分供参考:
保存更改。
在 Windows 平台上使用 7-Zip 工具打包 TAR 文件:
下载并安装 7-Zip 到本地系统。
启动 7-Zip 文件管理器应用程序。
定位到本地系统中的 openvpn 文件夹。
点击添加按钮。
从归档格式下拉菜单中选择 tar。
点击确定按钮。一个 openvpn.tar 文件将在目录C:/openvpn中生成。
在话机上配置 OpenVPN 功能
OpenVPN 功能在话机中默认是禁用的。你可以通过配置文件、网页用户界面或话机用户界面来启用 OpenVPN 功能。要使用 OpenVPN 功能,你还需要将 OpenVPN TAR 文件上传到话机。
通过网页用户界面设置
在网页用户界面,选择:网络配置 > 高级设置 > VPN。
配置参数
static.network.vpn_enable
static.openvpn.url
static.network.openvpn_file.url
参数
允许值
默认值
描述
static.network.vpn_enable[1]
0-禁用1-启用
0
该参数启用或禁用OpenVPN功能。
static.openvpn.url
最多511字符的URL
空
该参数配置OpenVPN的*.tar文件的访问URL。
static.network.openvpn_file.url
最多512字符的字符串
空
该参数配置上传OpenVPN配置文件(vpn.cnf)的URL。
该参数仅在“static.network.vpn.mode”设置为1(OpenVPN)时生效。
[1]如果你更改此参数,话机将重启以使更改生效。
故障排除
为什么话机无法连接到 OpenVPN 服务器?
按顺序执行以下操作:
确保 OpenVPN 服务器正在运行。如果 OpenVPN 服务器运行正常,当你将鼠标指针悬停在 VPN 图标上时,将会显示分配给 OpenVPN 服务器的虚拟IP地址。系统托盘通知区域中的VPN图标如下所示:
确保上传到话机的 OpenVPN TAR 文件已正确创建。
解压TAR文件,确保证书文件夹命名为“keys”,客户端配置文件命名为“vpn.cnf”,如下所示:
确保客户端配置文件中定义的客户端证书和密钥的文件名正确。
进入“keys”目录检查客户端证书和密钥的文件名。
确保服务器配置文件和客户端配置文件中的以下配置完全匹配。
确保话机的时间和日期在证书的有效期内。
检查客户端证书的签名算法是否受话机支持。
话机支持 MD5 和 SHA 1 签名算法。双击客户端证书文件,检查证书的有效期和签名算法。
如何更改证书的签名算法?
如果客户端证书的签名算法不受话机支持,你需要更改签名算法,然后重新生成客户端证书。按以下步骤操作:
找到 OpenVPN 安装路径中 easy-rsa 文件夹内的 openssl.cnf 文件。文件名和存储路径可能因你的安装环境而异。
将参数 default_md的值配置为 md5 或 sha1,如下所示:
default_md = md5
或
default_md = sha1
按照“安装OpenVPN服务器”部分介绍的步骤重新生成客户端证书。
为什么话机在成功连接到 OpenVPN 服务器后无法注册到 SIP 服务器?
按顺序执行以下操作:
确保 OpenVPN 服务器有双网卡。
确保 OpenVPN 服务器和 SIP 服务器之间的连接通过 Ping 命令工作正常。
确保在 Windows 平台上启用了 OpenVPN 服务器上的 Internet 连接共享和 TCP/IP 转发。
确保已在服务器配置文件中为话机分配了 SIP 服务器网络段的访问权限。例如,SIP服务器的IP地址是192.168.3.6,服务器配置文件必须包含以下配置:
push "route 192.168.3.0 255.255.255.0"
为什么当话机上配置了 SIP 服务器的域名时无法注册?
按顺序执行以下操作:
确保 DNS 服务器的 IP 地址已添加到服务器配置文件中。例如,DNS服务器的IP地址是192.168.2.3.10,服务器配置文件必须包含以下配置。
push "dhcp-option DNS 192.168.2.3.10"
确保 DNS 服务器和话机之间的连接工作正常。
为什么通话中没有声音?
按以下步骤操作:
确保服务器配置文件中添加了配置 client-to-client。
重启 OpenVPN 服务器。
为什么语音质量差?
按以下步骤操作:
网络拥塞、RTP数据包丢失或延迟可能导致通话质量差。在这种情况下,你需要联系你的网络管理员。
确保在客户端配置文件中设置了适当的日志级别。亿联建议你将日志级别设置为3(在客户端配置文件中为“verb 3”)。如果日志级别设置得太高,话机会频繁记录话机事件。这可能会导致话机性能问题。
示例配置文件
以下列出示例配置文件,详细说明如何配置服务器和客户端配置文件。配置可能因不同的网络环境而异。
服务器配置文件
客户端配置文件