ok, langsung saja to the point:
folder asli easy-rsa biasanya ada di /usr/share/doc/openvpn/examples/easy-rsa. Kita copy dulu folder ini ke/etc/openvpn agar kita tidak kehilangan file asli nya
masuk ke /etc/openvpn/easy-rsa/2.0
edit dulu file vars yang ada di folder tadi. Sesuaikan isinya dengan keinginan anda:
Code:
nano vars source vars ./clean-all
Code:
./pkitool --initca
Code:
./pkitool --pass --server RB450 openssl rsa -in keys/RB450.key -out keys/RB450.pem
Code:
./pkitool --pass client1 openssl rsa -in keys/client1.key -out keys/client1.pem
Ok, beres sudah pengerjaan pembuatan certificate untuk server dan client. Selajutnya kita upload file2 :
Code:
RB450.crt RB450.pem ca.crt
Code:
/certificate import file=RB450.crt import file=RB450.pem import file=ca.crt
Konfigurasi dasar ip address
Code:
/ip address add address=192.168.0.1/24 interface=ether1 comment=â€GW Client †/ip address add address=202.202.202.202/24 interface=ether2 comment=Internet
Code:
/ip pool add name=ovpn-pool ranges=192.168.0.4-192.168.0.10
Code:
/ppp profile add change-tcp-mss=default comment="" local-address=192.168.0.3 \ name=â€OpenVPN" only-one=default remote-address=ovpn-pool \ use-compression=default use-encryption=required use-vj-compression=default
Code:
/ppp secret add caller-id="" comment="" disabled=no limit-bytes-in=0 \ limit-bytes-out=0 name="username" password="password" \ routes="" service=any
Code:
/interface ovpn-server server set auth=sha1,md5 certificate=cert1 \ cipher=blowfish128,aes128,aes192,aes256 default-profile=your_profile \ enabled=yes keepalive-timeout=disabled max-mtu=1500 mode=ip netmask=24 \ port=1194 require-client-certificate=no
Code:
/ip firewall filter add action=accept chain=input comment="OpenVPN" disabled=no dst-port=1194 protocol=tcp
CONTOH KASUS :
wah udah coba2 nih akhirnya bisa connect
cuma ko ga bisa connect ke jaringan kantor yaa.. bingung juga ane.
topologinya sbb :
LAN Rumah (192.168.88.0/24)
|
|
Mikrotik Rb751 (192.168.88.1) - IP tunnel Ovpn 172.16.0.10 dhcp dr ovpn servernya
|
|
Internet (dynamic IP - Make TelkomFlash)
|
|
Firewall Kantor (static IP - 119.X.X.X)
|
|
OpenVPn Server(linux) (172.16.99.2) ip tunnel Ovpn 172.16.0.1
udah berhasih connect , cuma ane binggung ko tetep g bisa connect ke jaringan ane di kantor , bahkan untuk nge ping dari mikrotik ke
ping 172.16.0.1 time out
Ping 172.16.0.10 time out
padahal klo ane setup clientnya pake windows ngeping ke 172.16.0.1 dan 172.16.0.10 ga ada masalah
apa ane ada salah konfigur di sisi mikrotik client nya ya?? btw berikut konfigurasi mikrotik ane :
IPAddress
# ADDRESS NETWORK INTERFACE
0 192.168.88.1/24 192.168.88.0 bridge-local
1 D 182.4.252.25/32 10.112.112.130 ppp-out1 -- Dial Up Modem
2 D 172.16.0.10/32 172.16.0.1 ovpn-out2 -- interface OpenVpn client
IP Route
# DST-ADDRESS PREF-SRC GATEWAY DISTANCE
0 ADS 0.0.0.0/0 10.112.112.130 1
1 ADC 10.112.112.130/32 182.4.252.25 ppp-out1 0
2 ADC 172.16.0.1/32 172.16.0.10 ovpn-out2 0
3 A S 172.16.99.0/24 ovpn-out2 1
4 ADC 192.168.88.0/24 192.168.88.1 bridge-local 0
IP Firewall NAT
0 chain=srcnat action=masquerade dst-address=172.16.0.0
1 chain=srcnat action=masquerade dst-address=0.0.0.0/0
SOLUSI :
# ga support Compresion LZO