当前位置:网站首页>Deploy L2TP in VPN (Part 1)
Deploy L2TP in VPN (Part 1)
2022-06-24 07:31:00 【Chen Bucheng I】
One . brief introduction
L2TP(Layer 2 Tunneling Protocol) VPN It is used to carry PPP Message tunneling technology , This technology is mainly used in the remote office scenario to provide access services for travel employees to remotely access enterprise intranet resources .
Software required
openswan(ipsec) : Provide a key ppp : Provide user name and password xl2tpd : Provide L2TP service sysctl : Provide server internal forwarding iptables : Provide requests from inside the server to outside , The external response turns to the internal dependent environment of the server
Two . Deploy
ipsec
1. Installation dependency yum install -y make gcc gmp-devel xmlto bison flex xmlto libpcap-devel lsof vim-enhanced man
2.openswan(ipsec) install OpenSWan,Linux Next IPsec The best way to implement , It's powerful , It ensures the security of data transmission to the greatest extent 、 Integrity issues . yum install openswan
3. Next configure ipsec.ipsec The configuration file is /etc/ipsec.conf, Install well openswan after , The configuration file is the default . Make a backup before changing the file . mkdir ~/~etcmv /etc/ipsec.conf ~/~etc/ipsec.conf
vim ~/~etc/ipsec.conf
version 2.0
config setup
protostack=netkey
nhelpers=0
uniqueids=no
interfaces=%defaultroute
virtual_private=%v4:10.0.0.0/8,%v4:192.168.0.0/16,%v4:172.16.0.0/12,%v4:!192.168.2.0/24
conn l2tp-psk
rightsubnet=vhost:%priv
also=l2tp-psk-nonat
conn l2tp-psk-nonat
authby=secret
pfs=no
auto=add
keyingtries=3
rekey=no
ikelifetime=8h
keylife=1h
type=transport
left=%defaultroute
leftid=xxx.xx.xx.xx
leftprotoport=17/1701
right=%any
rightprotoport=17/%any
dpddelay=40
dpdtimeout=130
dpdaction=clear
sha2-truncbug=yes
There is a line on it leftid=xxx.xx.xx.xx, Here we have to put leftid The value of is changed to that of the server ip Address , Internet accessible IP Address .
4. Next, configure the key .L2TP Than PPTP One more key entry , It's also better than that PPTP One of the safer reasons . This key is actually a password , Different from the user's login password , It is equivalent to a key for communication between devices . Its configuration file is /etc/ipsec.secrets, In the same way , Let's back it up first , Then create a new one of our own : mv /etc/ipsec.secrets ~/~etc/ipsec.secretsvim /etc/ipsec.secrets
%any %any : PSK "RZSJ.COM"
Empathy ,%any Is all addresses , It can also be specified individually , And then there's ”YourPsk” Medium YourPsk Is the content of the key . You can change it to any string of your own . Anyway, when you connect to log in VPN When , I need this PSK Of .
5. function ipsec: systemctl restart ipsecsystemctl enable ipsec
边栏推荐
- How to select a third-party software testing company? 2022 ranking of domestic software testing institutions
- Summary of 2022 blue team HW elementary interview questions
- 【WordPress建站】5. 设置代码高亮
- Étalonnage de la caméra (objectif et principe d'étalonnage)
- 只显示两行,超出部分省略号显示
- 【帧率倍频】基于FPGA的视频帧率倍频系统verilog开发实现
- 基因检测,如何帮助患者对抗疾病?
- A penetration test of c/s Architecture - Request encryption, decryption and test
- PCL calculates the area of a polygon
- What is the mentality of spot gold worth learning from
猜你喜欢

Huawei cloud database advanced learning
![[WordPress website] 5 Set code highlight](/img/01/f669b70f236c334b98527a9320400c.png)
[WordPress website] 5 Set code highlight

利用微搭低代码实现级联选择

20个不容错过的ES6技巧

超宽带脉冲定位方案,UWB精准定位技术,无线室内定位应用

jarvisoj_ level2

蓝牙耳机怎么连接电脑使用,win10电脑如何连接蓝牙耳机

More than 60 million shovel excrement officials, can they hold a spring of domestic staple food?
![[tips] use the deep learning toolbox of MATLAB deepnetworkdesigner to quickly design](/img/74/f615191715a9ac58a8546f8d1e8f8d.png)
[tips] use the deep learning toolbox of MATLAB deepnetworkdesigner to quickly design

二分专题训练
随机推荐
How to turn on win11 notebook power saving mode? How to open win11 computer power saving mode
【图像融合】基于方向离散余弦变换和主成分分析的图像融合附matlab代码
buuctf misc [UTCTF2020]docx
取模软件 模拟显示验证取模数据正确性 逆向 把点阵数组bin文件转显示
Hyperledger fabric ledger snapshot - fast data synchronization
华为云图引擎服务
Huawei Cloud Database Advanced Learning
How to open the soft keyboard in the computer, and how to open the soft keyboard in win10
Ultra wideband pulse positioning scheme, UWB precise positioning technology, wireless indoor positioning application
The latest crawler tutorial in 2021: video demonstration of web crawling
Description of module data serial number positioning area code positioning refers to GBK code
In the era of industrial Internet, there are no more centers in the real sense, and these centers just turn tangible into intangible
与(&&)逻辑或(||),动态绑定结合三目运算
Accelerate large-scale data analysis based on Apache iceberg through data organization optimization
[pointnet] matlab simulation of 3D point cloud target classification and recognition based on pointnet
How to connect the Bluetooth headset to the computer and how to connect the win10 computer to the Bluetooth headset
【MySQL 使用秘籍】克隆数据表、保存查询数据至数据表以及创建临时表
Dichotomous special training
PCL calculates the area of a polygon
[OGeek2019]babyrop