在FreeBSD上用mpd5構建PPTP VPN Server

來源:互聯網
上載者:User

在FreeBSD上用mpd5構建PPTP VPN Server   幫一個朋友公司維護伺服器,很變態,他們的伺服器放在某國企自建機房,設定了僅允許通過朋友公司路由器固定IP地址才能串連訪問,遠端管理維護極不方便。正好平時為了測試和組建管理方便,在他們公司內部搭建了一台伺服器,就用這個來做個跳板吧。 伺服器安裝的是FreeBSD 9.1  64位版,安裝過程就不贅述了,直接進主題: 1、更新ports #portsnap fetch update 2、安裝MPD5 #cd /usr/ports/net/mpd5 #make install clean 3、配置 #cp /usr/local/etc/mpd5/mpd.conf.sample mpd.conf #ee /usr/local/etc/mpd5/mpd.conf 修改 startup: default: pptp_server: 這三塊 部分粘貼如下,修改見備忘  startup:        # configure mpd users        set user shuqi888 loveosc ### 設定 mpd 的訪問帳號及密碼,通過 telnet 或 web 訪問時需要此帳號,此例中管理員名shuqi888,密碼loveosc        #set user foo1 bar1        # configure the console        set console self 127.0.0.1 5005        set console open        # configure the web server        set web self 0.0.0.0 5006        set web open# Default configuration is "dialup" default:        #load dialup   注釋掉dialup        load pptp_server ### 更改預設調用 pptp_server 模組pptp_server:## Mpd as a PPTP server compatible with Microsoft Dial-Up Networking clients.## Suppose you have a private Office LAN numbered 192.168.1.0/24 and the# machine running mpd is at 192.168.1.1, and also has an externally visible# IP address of 1.2.3.4.## We want to allow a client to connect to 1.2.3.4 from out on the Internet# via PPTP.  We will assign that client the address 192.168.1.50 and proxy-ARP# for that address, so the virtual PPP link will be numbered 192.168.1.1 local# and 192.168.1.50 remote.  From the client machine's perspective, it will# appear as if it is actually on the 192.168.1.0/24 network, even though in# reality it is somewhere far away out on the Internet.## Our DNS server is at 192.168.1.3 and our NBNS (WINS server) is at 192.168.1.4.# If you don't have an NBNS server, leave that line out.# # Define dynamic IP address pool.        set ippool add pool1 192.168.1.50 192.168.1.99 ##這裡可以設定撥入後的私人IP # Create clonable bundle template named B        create bundle template B        set iface enable proxy-arp        set iface idle 1800        set iface enable tcpmssfix        set ipcp yes vjcomp# Specify IP address pool for dynamic assigment.        set ipcp ranges 192.168.1.1/32 ippool pool1        set ipcp dns 8.8.8.8  ### 設定 dns,我喜歡Google的        #set ipcp nbns 192.168.1.4 ###如果你用不到 wins 的話,可以注釋掉這塊,# The five lines below enable Microsoft Point-to-Point encryption# (MPPE) using the ng_mppc(8) netgraph node type.        set bundle enable compression        set ccp yes mppc        set mppc yes e40        set mppc yes e128        set mppc yes stateless# Create clonable link template named L        create link template L pptp# Set bundle template to use        set link action bundle B# Multilink adds some overhead, but gives full 1500 MTU.        set link enable multilink        set link yes acfcomp protocomp        set link no pap chap eap        set link enable chap        # We can use use RADIUS authentication/accounting by including# another config section with label 'radius'.#       load radius        set link keep-alive 10 60# We reducing link mtu to avoid GRE packet fragmentation.        set link mtu 1460# Configure PPTP        set pptp self 192.168.1.201 ###設定 pptp 的監聽 ip 地址,也就是你的網卡的 真實IP 位址,這裡一定要注意,如果是通過路由器連接埠映射出去的主機,這裡不能填路由器地址,而應該是網卡上配置的真實IP地址。# Allow to accept calls        set link enable incoming儲存退出。 4、設定及啟動 #ee /etc/rc.conf 加入 mpd_enable="YES"啟動mpd5 #/usr/local/etc/rc.d/mpd5 start 添加VPN帳號 #ee /usr/local/etc/mpd5/mpd.secret 輸入使用者名稱和密碼,一行一個,如 vpnuser1    password001 啟用包轉寄(不做這一步,雖然可以連上VPN,但只能訪問內網,無法訪問外網) #sysctl net.inet.ip.forwarding=1 至此安裝配置完成,可以在Windows中建立一個VPN串連了。 通過web訪問可以看到當前撥入串連的狀態 

聯繫我們

該頁面正文內容均來源於網絡整理,並不代表阿里雲官方的觀點,該頁面所提到的產品和服務也與阿里云無關,如果該頁面內容對您造成了困擾,歡迎寫郵件給我們,收到郵件我們將在5個工作日內處理。

如果您發現本社區中有涉嫌抄襲的內容,歡迎發送郵件至: info-contact@alibabacloud.com 進行舉報並提供相關證據,工作人員會在 5 個工作天內聯絡您,一經查實,本站將立刻刪除涉嫌侵權內容。

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.