<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Archives des Sécurité - CoffeeBreak Info</title>
	<atom:link href="https://coffeebreak.en-images.info/tag/securite/feed/" rel="self" type="application/rss+xml" />
	<link>https://coffeebreak.en-images.info/tag/securite/</link>
	<description>Une petite pause :)</description>
	<lastBuildDate>Sun, 03 Jul 2022 09:03:25 +0000</lastBuildDate>
	<language>fr-FR</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.9.1</generator>

<image>
	<url>https://coffeebreak.en-images.info/wp-content/uploads/2021/07/cropped-Tasse_Cafe-scaled-1-32x32.jpg</url>
	<title>Archives des Sécurité - CoffeeBreak Info</title>
	<link>https://coffeebreak.en-images.info/tag/securite/</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>MODOP – Installation Tunnel GRE Host to Host</title>
		<link>https://coffeebreak.en-images.info/modop-installation-tunnel-gre-host-to-host/</link>
					<comments>https://coffeebreak.en-images.info/modop-installation-tunnel-gre-host-to-host/#respond</comments>
		
		<dc:creator><![CDATA[chris]]></dc:creator>
		<pubDate>Sun, 03 Jul 2022 09:03:25 +0000</pubDate>
				<category><![CDATA[OS Linux]]></category>
		<category><![CDATA[RedHat/Centos Linux]]></category>
		<category><![CDATA[Sécurité]]></category>
		<category><![CDATA[Système]]></category>
		<category><![CDATA[VPN]]></category>
		<category><![CDATA[Centos]]></category>
		<category><![CDATA[Linux]]></category>
		<category><![CDATA[RockyLinux]]></category>
		<category><![CDATA[Serveur]]></category>
		<guid isPermaLink="false">https://coffeebreak.en-images.info/?p=6744</guid>

					<description><![CDATA[<p>MODOP d'une encapsulation de paquets de données à travers une connexion point à point entre deux client Linux via une tunnel GRE.<br />
Le service GRE (Generic Routing Encapsulation) permet d'encapsuler des flux/protocoles qui ne sont normalement pas pris en charge par un réseau.<br />
GRE est un moyen de charger un type de paquet dans un autre type de paquet afin que le premier paquet puisse circuler sur un réseau sur lequel il ne pourrait normalement pas circuler.</p>
<p>L’article <a href="https://coffeebreak.en-images.info/modop-installation-tunnel-gre-host-to-host/">MODOP – Installation Tunnel GRE Host to Host</a> est apparu en premier sur <a href="https://coffeebreak.en-images.info">CoffeeBreak Info</a>.</p>
]]></description>
										<content:encoded><![CDATA[<h2 style="text-align: center;"><span style="color: #000000;">Installation de la machine tun-greA.house.cpb – RockyLinux</span></h2>
<h3><span style="color: #000000;"><strong>Spécification de la machine tun-greA.house.cpb</strong></span></h3>
<p>Host : <strong>tun-greA.house.cpb</strong></p>
<ul>
<li><strong>IP :192.168.1.54</strong>
<ul>
<li>VIP : <strong><span style="color: #0000ff;">100.100.0.1/24</span></strong></li>
</ul>
</li>
<li>OS : <strong>RockyLinux</strong></li>
<li>vCPU : 2</li>
<li>DD : 8Go</li>
<li>Ram : 2Go</li>
</ul>
<h3><span style="color: #000000;"><strong>Mise à jour de la machine </strong></span></h3>
<pre>[root@tun-grea ~]# <span style="color: #ff0000;">dnf update -y</span></pre>
<h3><span style="color: #000000;"><strong>TimeDate</strong></span></h3>
<pre>[root@tun-grea ~]# <span style="color: #ff0000;">timedatectl set-timezone "Europe/Paris"</span>
[root@tun-grea ~]# <span style="color: #ff0000;">timedatect</span></pre>
<p><img fetchpriority="high" decoding="async" width="609" height="148" class="wp-image-6746" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/07/word-image-6744-2.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/07/word-image-6744-2.png 609w, https://coffeebreak.en-images.info/wp-content/uploads/2022/07/word-image-6744-2-300x73.png 300w" sizes="(max-width: 609px) 100vw, 609px" /></p>
<h3><span style="color: #000000;"><strong>Ajouter les hosts (Si pas de DNS)</strong></span></h3>
<pre>[root@tun-grea ~]# <span style="color: #ff0000;">echo "192.168.1.54 tun-grea tun-grea.house.cpb" &gt;&gt; /etc/hosts</span>
[root@tun-grea ~]#<span style="color: #ff0000;"> echo "192.168.1.55 tun-greb tun-greb.house.cpb" &gt;&gt; /etc/hosts</span>

[root@tun-grea ~]#<span style="color: #ff0000;"> echo "100.100.0.1 tunnel-grea tunnel-grea.house.cpb" &gt;&gt; /etc/hosts</span>
[root@tun-grea ~]# <span style="color: #ff0000;">echo "100.100.0.2 tunnel-greb tunnel-greb.house.cpb" &gt;&gt; /etc/hosts</span></pre>
<h3><span style="color: #000000;"><strong>Installation epel</strong></span></h3>
<pre>[root@vpn-sita ~]# <span style="color: #ff0000;">dnf install epel-release</span></pre>
<h3><span style="color: #000000;"><strong>Chargement Module GRE &#8211; CLI</strong></span></h3>
<pre>[root@tun-grea ~]# <span style="color: #ff0000;">lsmod | grep ip_gre</span>
[root@tun-grea ~]# <span style="color: #ff0000;">modprobe ip_gre</span>
[root@tun-grea ~]# <span style="color: #ff0000;">lsmod | grep ip_gre</span></pre>
<p><img decoding="async" width="455" height="115" class="wp-image-6747" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/07/word-image-6744-3.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/07/word-image-6744-3.png 455w, https://coffeebreak.en-images.info/wp-content/uploads/2022/07/word-image-6744-3-300x76.png 300w" sizes="(max-width: 455px) 100vw, 455px" /></p>
<h3><span style="color: #000000;"><strong>Chargement Module GRE – On BOOT</strong></span></h3>
<pre>[root@tun-grea ~]# <span style="color: #ff0000;">echo ip_gre &gt;&gt; /etc/modules-load.d/tun.conf</span>

[root@tun-grea ~]#<span style="color: #ff0000;"> ls -al /etc/modules-load.d/tun.conf
<em>-rw-r--r--. 1 root root 7 30 mai 19:39 /etc/modules-load.d/tun.conf</em></span></pre>
<h3><span style="color: #000000;"><strong>Configuration Réseau Tunnel GRE</strong></span></h3>
<h4><span style="text-decoration: underline;"><span style="color: #000000; text-decoration: underline;">Création du Tunnel tun0</span></span></h4>
<pre>[root@tun-grea ~]#<span style="color: #ff0000;"> nmcli connection add type ip-tunnel ip-tunnel.mode ipip con-name tun0 ifname tun0 remote <strong>192.168.1.55</strong> local <strong>192.168.1.54</strong>
<em>Connexion « tun0 » (80e7cefb-c070-4b9a-8ac0-200edd9090a6) ajoutée avec succès.</em></span></pre>
<h4><span style="text-decoration: underline;"><span style="color: #000000; text-decoration: underline;">Création de l’adresse VIP</span></span></h4>
<pre>[root@tun-grea ~]# <span style="color: #ff0000;">nmcli connection modify tun0 ipv4.addresses '<strong>100.100.0.1/24</strong>'</span></pre>
<h4><span style="text-decoration: underline;"><span style="color: #000000; text-decoration: underline;">Configuration IPV4 sur tun0</span></span></h4>
<pre>[root@tun-grea ~]# <span style="color: #ff0000;">nmcli connection modify tun0 ipv4.method manual</span></pre>
<h4><span style="text-decoration: underline;"><span style="color: #000000; text-decoration: underline;">Configuration static route sur tun0</span></span></h4>
<pre>[root@tun-grea ~]# <span style="color: #ff0000;">nmcli connection modify tun0 +ipv4.routes "<strong>192.168.1.0/24 100.100.0.2</strong>"</span></pre>
<h4><span style="text-decoration: underline; color: #000000;">Activation de la connexion tun0</span></h4>
<pre>[root@tun-grea ~]# <span style="color: #ff0000;">nmcli connection up tun0
<em>Connexion activée (chemin D-Bus actif /org/freedesktop/NetworkManager/ActiveConnection/11)</em></span></pre>
<p><img decoding="async" width="1188" height="118" class="wp-image-6748" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/07/word-image-6744-4.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/07/word-image-6744-4.png 1188w, https://coffeebreak.en-images.info/wp-content/uploads/2022/07/word-image-6744-4-300x30.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2022/07/word-image-6744-4-1024x102.png 1024w, https://coffeebreak.en-images.info/wp-content/uploads/2022/07/word-image-6744-4-768x76.png 768w" sizes="(max-width: 1188px) 100vw, 1188px" /></p>
<h4><span style="text-decoration: underline;"><span style="color: #000000; text-decoration: underline;">Check de la connexion tun0</span></span></h4>
<pre>[root@tun-grea ~]# <span style="color: #ff0000;">nmcli connection</span></pre>
<p><img loading="lazy" decoding="async" width="787" height="110" class="wp-image-6749" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/07/word-image-6744-5.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/07/word-image-6744-5.png 787w, https://coffeebreak.en-images.info/wp-content/uploads/2022/07/word-image-6744-5-300x42.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2022/07/word-image-6744-5-768x107.png 768w" sizes="auto, (max-width: 787px) 100vw, 787px" /></p>
<pre>[root@tun-grea ~]# <span style="color: #ff0000;">ip a show tun0</span></pre>
<p><img loading="lazy" decoding="async" width="940" height="133" class="wp-image-6750" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/07/word-image-6744-6.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/07/word-image-6744-6.png 940w, https://coffeebreak.en-images.info/wp-content/uploads/2022/07/word-image-6744-6-300x42.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2022/07/word-image-6744-6-768x109.png 768w" sizes="auto, (max-width: 940px) 100vw, 940px" /></p>
<h3><span style="color: #000000;"><strong>Activer le Forward IPv4</strong></span></h3>
<pre>[root@tun-grea ~]# <span style="color: #ff0000;">echo "net.ipv4.ip_forward=1" &gt; /etc/sysctl.conf</span>
[root@tun-grea ~]# <span style="color: #ff0000;">sysctl -p
<em>net.ipv4.ip_forward = 1</em></span></pre>
<h3><span style="color: #000000;"><strong>Activer les rules Firewall GRE</strong></span></h3>
<pre>[root@tun-grea ~]# <span style="color: #ff0000;">firewall-cmd --permanent --direct --add-rule ipv4 filter INPUT 0 -p gre -j ACCEPT</span>
[root@tun-grea ~]# <span style="color: #ff0000;">firewall-cmd --remove-service={dhcpv6-client,cockpit} --permanent</span>
[root@tun-grea ~]# <span style="color: #ff0000;">firewall-cmd --reload</span>
[root@tun-grea ~]# <span style="color: #ff0000;">iptables -L</span></pre>
<p><img loading="lazy" decoding="async" width="706" height="159" class="wp-image-6751" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/07/word-image-6744-7.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/07/word-image-6744-7.png 706w, https://coffeebreak.en-images.info/wp-content/uploads/2022/07/word-image-6744-7-300x68.png 300w" sizes="auto, (max-width: 706px) 100vw, 706px" /></p>
<h2 style="text-align: center;"><strong><span style="color: #000000;">Installation de la machine tun-greB.house.cpb – Centos7</span></strong></h2>
<h3><span style="color: #000000;"><strong>Spécification de la machine tun-greB.house.cpb</strong></span></h3>
<p>Host : <strong>tun-greB.house.cpb</strong></p>
<ul>
<li><strong>IP :192.168.1.55</strong>
<ul>
<li>VIP : <strong><span style="color: #0000ff;">100.100.0.2/24</span></strong></li>
</ul>
</li>
<li>OS : <strong>Centos7</strong></li>
<li>vCPU : 2</li>
<li>DD : 8Go</li>
<li>Ram : 2Go</li>
</ul>
<h3><span style="color: #000000;"><strong>Mise à jour de la machine </strong></span></h3>
<pre>[root@tun-greb ~]# <span style="color: #ff0000;">yum -y update</span></pre>
<h3><span style="color: #000000;"><strong>TimeDate</strong></span></h3>
<pre>[root@tun-greb ~]# <span style="color: #ff0000;">timedatectl set-timezone "Europe/Paris"</span></pre>
<h3><strong>Ajouter les hosts (Si pas de DNS)</strong></h3>
<pre>[root@tun-greb ~]# <span style="color: #ff0000;">echo "192.168.1.54 tun-grea tun-grea.house.cpb" &gt;&gt; /etc/hosts</span>
[root@tun-greb ~]# <span style="color: #ff0000;">echo "192.168.1.55 tun-greb tun-greb.house.cpb" &gt;&gt; /etc/hosts</span>

[root@tun-greb ~]# <span style="color: #ff0000;">echo "100.100.0.1 tunnel-grea tunnel-grea.house.cpb" &gt;&gt; /etc/hosts</span>
[root@tun-greb ~]# <span style="color: #000000;">echo "100.100.0.2 tunnel-greb tunnel-greb.house.cpb" &gt;&gt; /etc/hosts</span></pre>
<h3><span style="color: #000000;"><strong>Désactiver l’IPv6 (non nécessaire)</strong></span></h3>
<pre>[root@tun-greb ~]# <span style="color: #ff0000;">echo "net.ipv6.conf.all.disable_ipv6 = 1" &gt;&gt; /etc/sysctl.conf</span>
[root@tun-greb ~]#<span style="color: #ff0000;"> echo "net.ipv6.conf.all.autoconf = 0" &gt;&gt; /etc/sysctl.conf</span>
[root@tun-greb ~]# <span style="color: #ff0000;">echo "net.ipv6.conf.default.disable_ipv6 = 1" &gt;&gt; /etc/sysctl.conf</span>
[root@tun-greb ~]# <span style="color: #ff0000;">echo "net.ipv6.conf.default.autoconf = 0" &gt;&gt; /etc/sysctl.conf</span>

[root@tun-greb ~]# <span style="color: #ff0000;">sysctl -p
<em>net.ipv6.conf.all.disable_ipv6 = 1</em>
<em>net.ipv6.conf.all.autoconf = 0</em>
<em>net.ipv6.conf.default.disable_ipv6 = 1</em>
<em>net.ipv6.conf.default.autoconf = 0</em>
</span></pre>
<pre>[root@tun-greb ~]# <span style="color: #ff0000;">ip a
</span></pre>
<p><img loading="lazy" decoding="async" width="847" height="151" class="wp-image-6752" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/07/word-image-6744-8.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/07/word-image-6744-8.png 847w, https://coffeebreak.en-images.info/wp-content/uploads/2022/07/word-image-6744-8-300x53.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2022/07/word-image-6744-8-768x137.png 768w" sizes="auto, (max-width: 847px) 100vw, 847px" /></p>
<h3><span style="color: #000000;"><strong>Chargement Module GRE &#8211; CLI</strong></span></h3>
<pre>[root@tun-greb ~]# <span style="color: #ff0000;">lsmod | grep ip_gre</span>
[root@tun-greb ~]# <span style="color: #ff0000;">modprobe ip_gre</span>
[root@tun-grea ~]# <span style="color: #ff0000;">lsmod | grep ip_gre
</span></pre>
<p><img loading="lazy" decoding="async" width="558" height="109" class="wp-image-6753" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/07/word-image-6744-9.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/07/word-image-6744-9.png 558w, https://coffeebreak.en-images.info/wp-content/uploads/2022/07/word-image-6744-9-300x59.png 300w" sizes="auto, (max-width: 558px) 100vw, 558px" /></p>
<h3><span style="color: #000000;"><strong>Chargement Module GRE – On BOOT</strong></span></h3>
<pre>[root@tun-greb ~]# <span style="color: #ff0000;">echo ip_gre &gt;&gt; /etc/modules-load.d/tun.conf</span>
[root@tun-greb ~]# ls <span style="color: #ff0000;">-al /etc/modules-load.d/tun.conf
<em>-rw-r--r--. 1 root root 7 18 juin 18:19 /etc/modules-load.d/tun.conf</em></span></pre>
<h3><span style="color: #000000;"><strong>Configuration Réseau Tunnel GRE</strong></span></h3>
<h4><span style="text-decoration: underline;"><span style="color: #000000; text-decoration: underline;">Création de l’interface tun0</span></span></h4>
<pre>[root@tun-greb ~]# <span style="color: #ff0000;">nmcli connection add type ip-tunnel ip-tunnel.mode ipip con-name tun0 ifname tun0 remote <strong>192.168.1.54 local 192.168.1.55</strong>
<em>Connexion « tun0 » (163dbe74-79b7-4ba9-90f6-6e0d4fec4271) ajoutée avec succès.</em></span></pre>
<h4><span style="text-decoration: underline;"><span style="color: #000000; text-decoration: underline;">Création de l’adresse VIP</span></span></h4>
<pre>[root@tun-greb ~]#<span style="color: #ff0000;"> nmcli connection modify tun0 ipv4.addresses '<strong>100.100.0.2/24</strong>'</span></pre>
<h4><span style="text-decoration: underline;"><span style="color: #000000; text-decoration: underline;">Configuration IPV4 sur tun0</span></span></h4>
<pre>[root@tun-greb ~]# <span style="color: #ff0000;">nmcli connection modify tun0 ipv4.method manual</span></pre>
<h4><span style="text-decoration: underline;"><span style="color: #000000; text-decoration: underline;">Configuration static route sur tun0</span></span></h4>
<pre>[root@tun-greb ~]# <span style="color: #ff0000;">nmcli connection modify tun0 +ipv4.routes "<strong>192.168.1.0/24 100.100.0.1</strong>"</span></pre>
<h4><span style="text-decoration: underline;"><span style="color: #000000; text-decoration: underline;">Activation de la connexion tun0</span></span></h4>
<pre>[root@tun-greb ~]# <span style="color: #ff0000;">nmcli connection up tun0
<em>Connexion activée (chemin D-Bus actif : /org/freedesktop/NetworkManager/ActiveConnection/6)</em>
</span></pre>
<p><img loading="lazy" decoding="async" width="1178" height="128" class="wp-image-6754" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/07/word-image-6744-10.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/07/word-image-6744-10.png 1178w, https://coffeebreak.en-images.info/wp-content/uploads/2022/07/word-image-6744-10-300x33.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2022/07/word-image-6744-10-1024x111.png 1024w, https://coffeebreak.en-images.info/wp-content/uploads/2022/07/word-image-6744-10-768x83.png 768w" sizes="auto, (max-width: 1178px) 100vw, 1178px" /></p>
<h4><span style="text-decoration: underline;"><span style="color: #000000; text-decoration: underline;">Check de la connexion tun0</span></span></h4>
<pre>[root@tun-greb ~]#<span style="color: #ff0000;"> ip a show tun0</span></pre>
<p><img loading="lazy" decoding="async" width="958" height="124" class="wp-image-6755" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/07/word-image-6744-11.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/07/word-image-6744-11.png 958w, https://coffeebreak.en-images.info/wp-content/uploads/2022/07/word-image-6744-11-300x39.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2022/07/word-image-6744-11-768x99.png 768w" sizes="auto, (max-width: 958px) 100vw, 958px" /></p>
<pre>[root@tun-greb ~]# <span style="color: #ff0000;">nmcli connection</span></pre>
<p><img loading="lazy" decoding="async" width="629" height="80" class="wp-image-6756" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/07/word-image-6744-12.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/07/word-image-6744-12.png 629w, https://coffeebreak.en-images.info/wp-content/uploads/2022/07/word-image-6744-12-300x38.png 300w" sizes="auto, (max-width: 629px) 100vw, 629px" /></p>
<h3><span style="color: #000000;"><strong>Activer le Forward IPv4</strong></span></h3>
<pre>[root@tun-greb ~]# <span style="color: #ff0000;">echo "net.ipv4.ip_forward=1" &gt; /etc/sysctl.conf</span>
[root@tun-greb ~]# <span style="color: #ff0000;">sysctl -p
<em>net.ipv4.ip_forward = 1</em></span></pre>
<h3><strong>Activer les rules Firewall GRE</strong></h3>
<pre>[root@tun-greb ~]# <span style="color: #ff0000;">firewall-cmd --permanent --direct --add-rule ipv4 filter INPUT 0 -p gre -j ACCEPT</span>
[root@tun-greb ~]# <span style="color: #ff0000;">firewall-cmd --remove-service=dhcpv6-client --permanent</span>
[root@tun-greb ~]# <span style="color: #ff0000;">firewall-cmd --reload</span>

[root@tun-greb ~]# <span style="color: #ff0000;">iptables -L |grep gre
<em>ACCEPT gre -- anywhere anywhere</em></span></pre>
<h2><span style="color: #000000;">Check des flux réseaux Public et Tunnel</span></h2>
<h4><span style="text-decoration: underline;"><span style="color: #000000; text-decoration: underline;">Serveur tun-grea</span></span></h4>
<pre>[root@tun-grea ~]# <span style="color: #ff0000;">ping -c 3 tunnel-grea</span></pre>
<p><img loading="lazy" decoding="async" width="608" height="96" class="wp-image-6757" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/07/word-image-6744-13.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/07/word-image-6744-13.png 608w, https://coffeebreak.en-images.info/wp-content/uploads/2022/07/word-image-6744-13-300x47.png 300w" sizes="auto, (max-width: 608px) 100vw, 608px" /></p>
<pre>[root@tun-grea ~]# <span style="color: #ff0000;">ping -c 3 tunnel-greb</span></pre>
<p><img loading="lazy" decoding="async" width="624" height="88" class="wp-image-6758" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/07/word-image-6744-14.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/07/word-image-6744-14.png 624w, https://coffeebreak.en-images.info/wp-content/uploads/2022/07/word-image-6744-14-300x42.png 300w" sizes="auto, (max-width: 624px) 100vw, 624px" /></p>
<h4><span style="text-decoration: underline;"><span style="color: #000000; text-decoration: underline;">Serveur tun-greb</span></span></h4>
<pre>[root@tun-greb ~]# <span style="color: #ff0000;">ping -c 3 tunnel-grea</span></pre>
<p><img loading="lazy" decoding="async" width="635" height="86" class="wp-image-6759" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/07/word-image-6744-15.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/07/word-image-6744-15.png 635w, https://coffeebreak.en-images.info/wp-content/uploads/2022/07/word-image-6744-15-300x41.png 300w" sizes="auto, (max-width: 635px) 100vw, 635px" /></p>
<pre>[root@tun-greb ~]# <span style="color: #ff0000;">ping -c 3 tunnel-greb</span></pre>
<p><img loading="lazy" decoding="async" width="601" height="86" class="wp-image-6760" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/07/word-image-6744-16.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/07/word-image-6744-16.png 601w, https://coffeebreak.en-images.info/wp-content/uploads/2022/07/word-image-6744-16-300x43.png 300w" sizes="auto, (max-width: 601px) 100vw, 601px" /></p>
<h2>[root@tun-greb ~]# <span style="color: #ff0000;">ssh -l root tunnel-grea</span></h2>
<p><img loading="lazy" decoding="async" width="737" height="178" class="wp-image-6761" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/07/word-image-6744-17.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/07/word-image-6744-17.png 737w, https://coffeebreak.en-images.info/wp-content/uploads/2022/07/word-image-6744-17-300x72.png 300w" sizes="auto, (max-width: 737px) 100vw, 737px" /></p>
<p>Views: 3</p><p>L’article <a href="https://coffeebreak.en-images.info/modop-installation-tunnel-gre-host-to-host/">MODOP – Installation Tunnel GRE Host to Host</a> est apparu en premier sur <a href="https://coffeebreak.en-images.info">CoffeeBreak Info</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://coffeebreak.en-images.info/modop-installation-tunnel-gre-host-to-host/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>MODOP – Bloquer les IP Botnet malveillant</title>
		<link>https://coffeebreak.en-images.info/modop-bloquer-les-ip-botnet-malveillant/</link>
					<comments>https://coffeebreak.en-images.info/modop-bloquer-les-ip-botnet-malveillant/#respond</comments>
		
		<dc:creator><![CDATA[chris]]></dc:creator>
		<pubDate>Fri, 27 May 2022 11:37:00 +0000</pubDate>
				<category><![CDATA[RedHat/Centos Linux]]></category>
		<category><![CDATA[Sécurité]]></category>
		<category><![CDATA[Système]]></category>
		<category><![CDATA[Botnet]]></category>
		<category><![CDATA[cybersécurité]]></category>
		<category><![CDATA[Firewall]]></category>
		<category><![CDATA[Linux]]></category>
		<category><![CDATA[RockyLinux]]></category>
		<category><![CDATA[Serveur]]></category>
		<guid isPermaLink="false">https://coffeebreak.en-images.info/?p=6691</guid>

					<description><![CDATA[<p>MODOP sur la mise en place d’un script BASH permettant de bloquer des IP de Botnet sur vos serveurs de Production afin d’éviter d’éventuelles attaques groupées. Le principe est de s’appuyer sur un site de veille en cybersécurité et ainsi récupérer la liste journalière des Botnet référencés. Le script inscrira dans le Firewall un « REJECT » Pour chaque IP Botnet désignées dans la liste . Une tâche Crontab devrait permettre de mettre à jour le firewall à chaque édition du fichier de veille Botnet.</p>
<p>L’article <a href="https://coffeebreak.en-images.info/modop-bloquer-les-ip-botnet-malveillant/">MODOP – Bloquer les IP Botnet malveillant</a> est apparu en premier sur <a href="https://coffeebreak.en-images.info">CoffeeBreak Info</a>.</p>
]]></description>
										<content:encoded><![CDATA[<h3><span style="color: #000000;"><strong>Le but </strong></span></h3>
<p><span style="color: #000000;">Lancer un script BASH permettant de récupérer une liste d’IP Botnet malveillant une fois par jour via crontab ,&nbsp; afin de les ajouter à vos règles firewall.</span></p>
<ul>
<li><a href="https://feodotracker.abuse.ch/downloads/ipblocklist_recommended.txt">https://feodotracker.abuse.ch/downloads/ipblocklist_recommended.txt</a></li>
</ul>
<p><img loading="lazy" decoding="async" width="1036" height="508" class="wp-image-6692" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-202.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-202.png 1036w, https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-202-300x147.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-202-1024x502.png 1024w, https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-202-768x377.png 768w" sizes="auto, (max-width: 1036px) 100vw, 1036px" /></p>
<h3><span style="color: #000000;"><strong>Création du répertoire Projet</strong></span></h3>
<pre>[root@XXXXXXXX chris]#<span style="color: #ff0000;"> mkdir Ban_BotNet</span>
[root@XXXXXXXX chris]# # <span style="color: #ff0000;">cd Ban_BotNet</span></pre>
<h3><span style="color: #000000;"><strong>Installation Dos2unix </strong></span></h3>
<pre>[root@XXXXXXXX Ban_BotNet]# <span style="color: #ff0000;">yum install dos2unix</span></pre>
<h3><span style="color: #000000;"><strong>Le Script</strong></span></h3>
<pre><span style="color: #ff0000;"><em style="color: #ff0000;">#!/bin/bash</em>
<em style="color: #ff0000;">
APP_LOG=BanBotnet.log</em>
<em style="color: #ff0000;">APP_HOME=/home/chris/Ban_BotNet</em>
<em style="color: #ff0000;">URL_BOT=https://feodotracker.abuse.ch/downloads/ipblocklist_recommended.txt</em>
<em style="color: #ff0000;">CE_JOUR=`date +%F`</em>

<em style="color: #ff0000;">echo "-------------------------------------------"</em>
<em style="color: #ff0000;">echo " Suppression des fichiers périmés J-1 "</em>
<em style="color: #ff0000;">echo "-------------------------------------------"</em>
<em style="color: #ff0000;">echo ""</em>
<em style="color: #ff0000;">
if [[ -f $APP_HOME/ipblocklist_recommended-1.txt ]]</em>
<em style="color: #ff0000;">then</em>
<em style="color: #ff0000;"> echo "On efface le fichier d'hier..."</em>
<em style="color: #ff0000;"> rm -f $APP_HOME/ipblocklist_recommended-1.txt</em>
<em style="color: #ff0000;">fi</em>

<em style="color: #ff0000;">if [[ -f $APP_HOME/ipblocklist_recommended.txt ]]</em>
<em style="color: #ff0000;">then</em>
<em style="color: #ff0000;"> echo "On efface le fichier d'hier..."</em>
<em style="color: #ff0000;"> rm -f $APP_HOME/ipblocklist_recommended.txt</em>
<em style="color: #ff0000;">fi</em>

<em style="color: #ff0000;">if [[ -f $APP_HOME/ip_firewall_block.txt ]]</em>
<em style="color: #ff0000;">then</em>
<em style="color: #ff0000;"> echo "On efface le fichier d'hier..."</em>
<em style="color: #ff0000;"> rm -f $APP_HOME/ip_firewall_block.txt</em>
<em style="color: #ff0000;">fi</em>

<em style="color: #ff0000;">echo "-------------------------------------------"</em>
<em style="color: #ff0000;">echo "On récupère le fichier des BOTNET du jour "</em>
<em style="color: #ff0000;">echo "-------------------------------------------"</em>
<em style="color: #ff0000;">echo ""</em>
<em style="color: #ff0000;">wget -O - https://feodotracker.abuse.ch/downloads/ipblocklist_recommended.txt |grep -v "#" &gt;&gt; $APP_HOME/ipblocklist_recommended.txt</em>
<em style="color: #ff0000;">touch $APP_HOME/ipblocklist_recommended-1.txt</em>
<em style="color: #ff0000;">dos2unix -850 -n $APP_HOME/ipblocklist_recommended.txt $APP_HOME/ipblocklist_recommended-1.txt</em>

<em style="color: #ff0000;">echo "-------------------------------------------"</em>
<em style="color: #ff0000;">echo "On récupère la liste des IP déjà bloquées "</em>
<em style="color: #ff0000;">echo "-------------------------------------------"</em>
<em style="color: #ff0000;">echo ""</em>
<em style="color: #ff0000;">firewall-cmd --list-all &gt;&gt; $APP_HOME/ip_firewall_block.txt</em>

<em style="color: #ff0000;">## Traitement des IP à Bannir</em>
<em style="color: #ff0000;">for IP in `cat $APP_HOME/ipblocklist_recommended-1.txt`</em>
<em style="color: #ff0000;"> do</em>
<em style="color: #ff0000;"> ## Verifie si Déja Bloqué</em>
<em style="color: #ff0000;"> FIRE=`cat $APP_HOME/ip_firewall_block.txt |grep $IP |wc -l`</em>
<em style="color: #ff0000;"> if [[ $FIRE != 0 ]]</em>
<em style="color: #ff0000;"> then</em>
<em style="color: #ff0000;">
 echo "-----------------------------------------------------------------"</em>
<em><span style="color: #ff0000;"> echo "Cette IP : $IP est déjà bloquée dans le Firewall"</span></em>
<em style="color: #ff0000;"> echo "-----------------------------------------------------------------"</em>
<em><span style="color: #ff0000;"> echo "$CE_JOUR : $IP est déjà bloquée dans le Firewall" &gt;&gt; $APP_HOME/$APP_LOG</span></em>

<em style="color: #ff0000;">else</em>
<em style="color: #ff0000;"> echo "-----------------------------------------------------------------"</em>
<em style="color: #ff0000;"> echo " Mise en Reject de l'IP : $IP dans le Firewall"</em>
<em style="color: #ff0000;"> echo "-----------------------------------------------------------------"</em>
<strong><em style="color: #ff0000;"> firewall-cmd --add-rich-rule='rule family=ipv4 source address='$IP' reject' --permanent</em></strong>
<em style="color: #ff0000;"> echo "$CE_JOUR : $IP ajouter dans le Firewall" &gt;&gt; $APP_HOME/$APP_LOG</em>
<em style="color: #ff0000;"> echo ""</em>
<em style="color: #ff0000;"> fi</em>
<em style="color: #ff0000;"> done</em>

<em style="color: #ff0000;">echo "------------------------------------------------------------"</em>
<em style="color: #ff0000;">echo "Application des nouvelles règles de Blocage sur le Firewall "</em>
<em style="color: #ff0000;">echo "------------------------------------------------------------"</em>
<em style="color: #ff0000;">echo ""</em>

<em style="color: #ff0000;">firewall-cmd --reload</em></span></pre>
<h3><span style="color: #000000;"><strong>Lancement du Script</strong></span></h3>
<pre>[root@ XXXXXXXX Ban_BotNet]# <span style="color: #ff0000;">./Bannir_Botnet.sh</span></pre>
<p><img loading="lazy" decoding="async" width="1584" height="385" class="wp-image-6693" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-203.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-203.png 1584w, https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-203-300x73.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-203-1024x249.png 1024w, https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-203-768x187.png 768w, https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-203-1536x373.png 1536w" sizes="auto, (max-width: 1584px) 100vw, 1584px" /></p>
<p>Lancement du script et récupération des prérequis pour le traitement des IP à Bannir</p>
<p><img loading="lazy" decoding="async" width="1001" height="549" class="wp-image-6694" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-204.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-204.png 1001w, https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-204-300x165.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-204-768x421.png 768w, https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-204-800x440.png 800w" sizes="auto, (max-width: 1001px) 100vw, 1001px" /></p>
<p>Lancement des bannissements des IP s’ils ne sont pas présente dans le Firewall.</p>
<p><img loading="lazy" decoding="async" width="781" height="233" class="wp-image-6695" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-205.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-205.png 781w, https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-205-300x90.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-205-768x229.png 768w" sizes="auto, (max-width: 781px) 100vw, 781px" /></p>
<p>Application des nouveaux bannissements dans les «&nbsp;Rules&nbsp;» du firewall.</p>
<pre>[root@XXXXXXXX Ban_BotNet]# <span style="color: #ff0000;">firewall-cmd --list-all</span></pre>
<p><img loading="lazy" decoding="async" width="755" height="479" class="wp-image-6696" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-206.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-206.png 755w, https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-206-300x190.png 300w" sizes="auto, (max-width: 755px) 100vw, 755px" /></p>
<p>IP des BotNet bloquées par votre Firewall.</p>
<h3><span style="color: #000000;"><strong>Dans le log de notre Script</strong></span></h3>
<pre>[root@XXXXXXXX Ban_BotNet]#<span style="color: #ff0000;"> cat BanBotnet.log</span></pre>
<p><img loading="lazy" decoding="async" width="788" height="400" class="wp-image-6697" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-207.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-207.png 788w, https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-207-300x152.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-207-768x390.png 768w" sizes="auto, (max-width: 788px) 100vw, 788px" /></p>


<p>Il vous reste à présent , de positionner votre script dans un crontab tous les matins à 6H00</p>



<p></p>
<p>Views: 28</p><p>L’article <a href="https://coffeebreak.en-images.info/modop-bloquer-les-ip-botnet-malveillant/">MODOP – Bloquer les IP Botnet malveillant</a> est apparu en premier sur <a href="https://coffeebreak.en-images.info">CoffeeBreak Info</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://coffeebreak.en-images.info/modop-bloquer-les-ip-botnet-malveillant/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>MODOP – Ajout Client Win10 sur Serveur WireGuard Linux</title>
		<link>https://coffeebreak.en-images.info/modop-ajout-client-win10-sur-serveur-wireguard-linux/</link>
					<comments>https://coffeebreak.en-images.info/modop-ajout-client-win10-sur-serveur-wireguard-linux/#respond</comments>
		
		<dc:creator><![CDATA[chris]]></dc:creator>
		<pubDate>Thu, 14 Apr 2022 10:28:29 +0000</pubDate>
				<category><![CDATA[OS Linux]]></category>
		<category><![CDATA[RedHat/Centos Linux]]></category>
		<category><![CDATA[Sécurité]]></category>
		<category><![CDATA[Système]]></category>
		<category><![CDATA[VPN]]></category>
		<category><![CDATA[Centos]]></category>
		<category><![CDATA[Linux]]></category>
		<category><![CDATA[Serveur]]></category>
		<guid isPermaLink="false">https://coffeebreak.en-images.info/?p=6362</guid>

					<description><![CDATA[<p>En complément du dernier MODOP sur la mise en place d’un service WireGuard et d’un client VPN sous Linux. Nous allons ajouter un client Microsoft avec le client WireGuard. Le but est de connecter un client Win10 sur le serveur WireGuard Linux précédemment configuré, et ainsi permettre la connexion des deux équipements sur un réseau VPN. WireGuard permet la connexion d’OS hétérogène le rendant Multiplateforme.</p>
<p>L’article <a href="https://coffeebreak.en-images.info/modop-ajout-client-win10-sur-serveur-wireguard-linux/">MODOP – Ajout Client Win10 sur Serveur WireGuard Linux</a> est apparu en premier sur <a href="https://coffeebreak.en-images.info">CoffeeBreak Info</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>Host&nbsp;: <strong>open-client02.house.cpb</strong></p>
<ul>
<li>IP:<strong>&nbsp;172.32.185.40</strong></li>
<li>Subnet&nbsp;: 172.32.185.0/24</li>
<li>vSwitch&nbsp;: vmbr2</li>
<li>Disque&nbsp;: 50Go (Système)</li>
<li>RAM&nbsp;:8Go</li>
<li>vCPU&nbsp;: 4</li>
<li>OS&nbsp;:&nbsp;<strong>Windows10</strong></li>
</ul>
<p><img loading="lazy" decoding="async" width="794" height="250" class="wp-image-6363" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-102.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-102.png 794w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-102-300x94.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-102-768x242.png 768w" sizes="auto, (max-width: 794px) 100vw, 794px" /></p>
<h4><span style="color: #000000;"><strong>1°) Installer le Client WireGuard</strong></span></h4>
<ul>
<li><a href="https://download.wireguard.com/windows-client/">https://download.wireguard.com/windows-client/</a></li>
</ul>
<p><img loading="lazy" decoding="async" width="914" height="275" class="wp-image-6364" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-103.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-103.png 914w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-103-300x90.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-103-768x231.png 768w" sizes="auto, (max-width: 914px) 100vw, 914px" /><br />
Télécharger la version MSI souhaitée et lancée.</p>
<p><img loading="lazy" decoding="async" width="447" height="333" class="wp-image-6365" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-104.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-104.png 447w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-104-300x223.png 300w" sizes="auto, (max-width: 447px) 100vw, 447px" /><br />
«&nbsp;<strong>Exécute</strong>r&nbsp;»</p>
<p><img loading="lazy" decoding="async" width="459" height="336" class="wp-image-6366" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-105.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-105.png 459w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-105-300x220.png 300w" sizes="auto, (max-width: 459px) 100vw, 459px" /><br />
«&nbsp;<strong>Oui&nbsp;</strong>»</p>
<p><img loading="lazy" decoding="async" width="633" height="504" class="wp-image-6367" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-106.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-106.png 633w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-106-300x239.png 300w" sizes="auto, (max-width: 633px) 100vw, 633px" /><br />
WireGuard se lance.</p>
<h4><span style="color: #000000;"><strong>2°) Configurer WireGuard Client</strong></span></h4>
<p><img loading="lazy" decoding="async" width="758" height="163" class="wp-image-6368" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-107.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-107.png 758w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-107-300x65.png 300w" sizes="auto, (max-width: 758px) 100vw, 758px" /><br />
«&nbsp;<strong>Ajouter le tunnel</strong>&nbsp;» et «&nbsp;<strong>Ajouter un tunnel vide</strong>&nbsp;»</p>
<h5><span style="color: #000000;"><strong>Pour Rappel des données Serveur </strong></span></h5>
<ul>
<li>IP serveur&nbsp;: <span style="color: #ff0000;">172.16.185.40</span></li>
<li>Public Key Serveur : <span style="color: #ff0000;"><em>H9JrgVaNJh9wmB25K4wlQlG/fVii1um+mhkGApPJXUs=</em></span></li>
<li>Private Key Serveur&nbsp;: <span style="color: #ff0000;"><em>8DLZHyjeS2HHozkYpeaZJM64oGOwYDcbU/i+E1FjQ0Y=</em></span></li>
</ul>
<p><img loading="lazy" decoding="async" width="491" height="395" class="wp-image-6369" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-108.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-108.png 491w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-108-300x241.png 300w" sizes="auto, (max-width: 491px) 100vw, 491px" /><br />
«&nbsp;<strong>Enregistre</strong>r&nbsp;»</p>
<p><img loading="lazy" decoding="async" width="634" height="333" class="wp-image-6370" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-109.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-109.png 634w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-109-300x158.png 300w" sizes="auto, (max-width: 634px) 100vw, 634px" /></p>
<h4><span style="color: #000000;"><strong>3°) Ajout cléf Public du client sur le serveur WireGuard</strong></span></h4>
<ul>
<li>Récupérer la Clef Public du client01 : <span style="color: #ff0000;">IPfz1pVoJZLZf2dsRtsr08RhoGj3JCDsdacwXsUnels=</span></li>
<li>Adresse du Client sur le VPN&nbsp;: <span style="color: #ff0000;"><em>100.10.0.3</em></span></li>
</ul>
<pre>[root@wireguard-server wireguard]# <span style="color: #ff0000;">wg set wg0 peer IPfz1pVoJZLZf2dsRtsr08RhoGj3JCDsdacwXsUnels= allowed-ips 100.10.0.3</span></pre>
<p><img loading="lazy" decoding="async" width="620" height="144" class="wp-image-6371" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-110.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-110.png 620w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-110-300x70.png 300w" sizes="auto, (max-width: 620px) 100vw, 620px" /><br />
Démarrer la connexion VPN avec le server «&nbsp;<strong>Activer&nbsp;</strong>»</p>
<p><img loading="lazy" decoding="async" width="626" height="391" class="wp-image-6372" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-111.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-111.png 626w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-111-300x187.png 300w" sizes="auto, (max-width: 626px) 100vw, 626px" /><br />
La connexion est désormais activée et connectée au serveur wireguard-server</p>
<p><img loading="lazy" decoding="async" width="861" height="487" class="wp-image-6373" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-112.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-112.png 861w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-112-300x170.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-112-768x434.png 768w" sizes="auto, (max-width: 861px) 100vw, 861px" /></p>
<h4><span style="color: #000000;"><strong>4°) Check WireGuard client</strong></span></h4>
<p>Ouvrir un terminal CMD</p>
<pre>C:\Users\admin&gt;<span style="color: #ff0000;"> ipconfig /all</span></pre>
<p><img loading="lazy" decoding="async" width="900" height="470" class="wp-image-6374" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-113.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-113.png 900w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-113-300x157.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-113-768x401.png 768w" sizes="auto, (max-width: 900px) 100vw, 900px" /></p>
<h4><span style="color: #000000;"><strong>Check Client =&gt; Server wireguard via le VPN</strong></span></h4>
<p><img loading="lazy" decoding="async" width="702" height="192" class="wp-image-6375" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-114.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-114.png 702w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-114-300x82.png 300w" sizes="auto, (max-width: 702px) 100vw, 702px" /></p>
<h3><span style="color: #000000;"><strong>Connexion SFTP du client =&gt; Server wireguard via le VPN</strong></span></h3>
<p><img loading="lazy" decoding="async" width="550" height="222" class="wp-image-6376" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-115.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-115.png 550w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-115-300x121.png 300w" sizes="auto, (max-width: 550px) 100vw, 550px" /></p>
<p><img loading="lazy" decoding="async" width="468" height="359" class="wp-image-6377" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-116.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-116.png 468w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-116-300x230.png 300w" sizes="auto, (max-width: 468px) 100vw, 468px" /><br />
«&nbsp;<strong>Oui</strong>&nbsp;»</p>
<p><img loading="lazy" decoding="async" width="937" height="468" class="wp-image-6378" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-117.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-117.png 937w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-117-300x150.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-117-768x384.png 768w" sizes="auto, (max-width: 937px) 100vw, 937px" /></p>
<h5><strong>La connexion VPN est bien ouverte et active.</strong></h5>
<p>Views: 2</p>
<p>L’article <a href="https://coffeebreak.en-images.info/modop-ajout-client-win10-sur-serveur-wireguard-linux/">MODOP – Ajout Client Win10 sur Serveur WireGuard Linux</a> est apparu en premier sur <a href="https://coffeebreak.en-images.info">CoffeeBreak Info</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://coffeebreak.en-images.info/modop-ajout-client-win10-sur-serveur-wireguard-linux/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>MODOP – Installation WireGuard VPN</title>
		<link>https://coffeebreak.en-images.info/modop-installation-wireguard-vpn-client-serveur/</link>
					<comments>https://coffeebreak.en-images.info/modop-installation-wireguard-vpn-client-serveur/#respond</comments>
		
		<dc:creator><![CDATA[chris]]></dc:creator>
		<pubDate>Thu, 14 Apr 2022 10:08:14 +0000</pubDate>
				<category><![CDATA[OS Linux]]></category>
		<category><![CDATA[RedHat/Centos Linux]]></category>
		<category><![CDATA[Sécurité]]></category>
		<category><![CDATA[Système]]></category>
		<category><![CDATA[VPN]]></category>
		<category><![CDATA[Centos]]></category>
		<category><![CDATA[Linux]]></category>
		<category><![CDATA[Serveur]]></category>
		<guid isPermaLink="false">https://coffeebreak.en-images.info/?p=6323</guid>

					<description><![CDATA[<p>MODOP – Mise en action d’un VPN via le service WireGuard Cient/Serveur. Cette solution permet le chiffrement et l’authentification par un jeu de clef Public/privé afin de créer un tunnel sécurisé entre des équipements. Il est simple et rapide à mettre en place pour sécuriser vos transactions et cela sans avoir besoin de créer/utiliser des PKI spécifique. </p>
<p>L’article <a href="https://coffeebreak.en-images.info/modop-installation-wireguard-vpn-client-serveur/">MODOP – Installation WireGuard VPN</a> est apparu en premier sur <a href="https://coffeebreak.en-images.info">CoffeeBreak Info</a>.</p>
]]></description>
										<content:encoded><![CDATA[<h3><span style="color: #000000;">Inventaire des Machines</span></h3>
<p>Host&nbsp;:<strong> wireguard-server.house.cpb</strong></p>
<ul>
<li>IP:&nbsp;<strong>172.16.185.40</strong></li>
<li>Subnet&nbsp;: 172.16.185.0/24</li>
<li>vSwitch&nbsp;: vmbr1</li>
<li>Disque&nbsp;: 8Go (Système)</li>
<li>RAM&nbsp;:2Go</li>
<li>vCPU&nbsp;: 2</li>
<li>OS&nbsp;:&nbsp;RockyLinux 8</li>
</ul>
<p><img loading="lazy" decoding="async" width="1068" height="277" class="wp-image-6324" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-81.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-81.png 1068w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-81-300x78.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-81-1024x266.png 1024w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-81-768x199.png 768w" sizes="auto, (max-width: 1068px) 100vw, 1068px" /></p>
<p>Host&nbsp;: <strong>wireguard-client01.house.cpb</strong></p>
<ul>
<li>IP:&nbsp;<strong>10.10.0.40</strong></li>
<li>Subnet&nbsp;: 10.10.0.0/24</li>
<li>vSwitch&nbsp;: vmbr4</li>
<li>Disque&nbsp;: 8Go (Système)</li>
<li>RAM&nbsp;:2Go</li>
<li>vCPU&nbsp;: 2</li>
<li>OS&nbsp;:&nbsp;RockyLinux 8</li>
</ul>
<p><img loading="lazy" decoding="async" width="1020" height="289" class="wp-image-6325" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-82.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-82.png 1020w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-82-300x85.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-82-768x218.png 768w" sizes="auto, (max-width: 1020px) 100vw, 1020px" /></p>
<p>Les deux machines doivent être joignable mutuellement.</p>
<h4><span style="color: #000000;"><strong>Check wireguard-server (172.16.185.40) =&gt; wireguard-client01(10.10.0.40)</strong></span></h4>
<pre>[root@wireguard-server ~]# <span style="color: #ff0000;">echo "10.10.0.40 wireguard-client01" &gt;&gt; /etc/hosts</span>
[root@wireguard-server ~]# <span style="color: #ff0000;">ping -c 3 wireguard-client01</span></pre>
<p><img loading="lazy" decoding="async" width="733" height="175" class="wp-image-6326" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-83.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-83.png 733w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-83-300x72.png 300w" sizes="auto, (max-width: 733px) 100vw, 733px" /></p>
<h4><span style="color: #000000;"><strong>wireguard-client01(10.10.0.40) =&gt; Check wireguard-server (172.16.185.40)</strong></span></h4>
<pre>[root@wireguard-client01 ~]# <span style="color: #ff0000;">echo "172.16.185.40 wireguard-server" &gt;&gt; /etc/hosts</span>
[root@wireguard-client01 ~]# <span style="color: #ff0000;">ping -c 3 wireguard-server</span></pre>
<p><img loading="lazy" decoding="async" width="734" height="174" class="wp-image-6327" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-84.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-84.png 734w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-84-300x71.png 300w" sizes="auto, (max-width: 734px) 100vw, 734px" /></p>
<h2 style="text-align: center;"><span style="color: #000000;">Installation Serveur VPN WireGuard &#8211; RockyLinux</span></h2>
<h4><span style="color: #000000;"><strong>1°) Mise à jour</strong></span></h4>
<pre>[root@wireguard-server ~]#<span style="color: #ff0000;"> dnf -y update</span></pre>
<h4><span style="color: #000000;"><strong>2°) Désactivation IPv6 (Option)</strong></span></h4>
<pre>[root@open-serveurvpn ~]#<span style="color: #ff0000;"> echo "net.ipv6.conf.all.disable_ipv6 = 1" &gt;&gt; /etc/sysctl.conf</span>
[root@open-serveurvpn ~]# <span style="color: #ff0000;">echo "net.ipv6.conf.all.autoconf = 0" &gt;&gt; /etc/sysctl.conf</span>
[root@open-serveurvpn ~]# <span style="color: #ff0000;">echo "net.ipv6.conf.default.disable_ipv6 = 1" &gt;&gt; /etc/sysctl.conf</span>
[root@open-serveurvpn ~]# <span style="color: #ff0000;">echo "net.ipv6.conf.default.autoconf = 0" &gt;&gt; /etc/sysctl.conf</span>
[root@open-serveurvpn ~]# <span style="color: #ff0000;">sysctl -p</span></pre>
<h4><span style="color: #000000;"><strong>3°) Installation des dépendances </strong></span></h4>
<pre>[root@wireguard-server ~]# <span style="color: #ff0000;">dnf install epel-release</span>
[root@wireguard-server ~]#<span style="color: #ff0000;"> yum install elrepo-release</span></pre>
<h4><span style="color: #000000;"><strong>4°) Installation WireGuard VPN</strong></span></h4>
<p>[root@wireguard-server ~]#<span style="color: #ff0000;"> dnf search wireguard</span></p>
<p><img loading="lazy" decoding="async" width="938" height="143" class="wp-image-6328" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-85.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-85.png 938w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-85-300x46.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-85-768x117.png 768w" sizes="auto, (max-width: 938px) 100vw, 938px" /></p>
<pre>[root@wireguard-server ~]#<span style="color: #ff0000;"> dnf -y install wireguard-tools kmod-wireguard</span></pre>
<h4><span style="color: #000000;"><strong>5°) Création des clefs Public/Privée pour le&nbsp; Server </strong></span></h4>
<pre>[root@wireguard-server ~]# <span style="color: #ff0000;">cd /etc/wireguard/</span>
[root@wireguard-server wireguard]# <span style="color: #ff0000;">wg genkey | tee /etc/wireguard/privatekey | wg pubkey | tee /etc/wireguard/publickey</span>

[root@wireguard-server wireguard]# <span style="color: #ff0000;">cat publickey</span>
<span style="color: #ff0000;"><em>H9JrgVaNJh9wmB25K4wlQlG/fVii1um+mhkGApPJXUs=</em></span>

[root@wireguard-server wireguard]# <span style="color: #ff0000;">cat privatekey</span>
<span style="color: #ff0000;"><em>8DLZHyjeS2HHozkYpeaZJM64oGOwYDcbU/i+E1FjQ0Y=</em></span></pre>
<h4><span style="color: #000000;"><strong>6°) Création/Configuration du server VPN</strong></span></h4>
<pre>[root@wireguard-server wireguard]# <span style="color: #ff0000;">vi wg0.conf</span>

<em><span style="color: #ff0000;">[Interface]</span></em>
<em><span style="color: #ff0000;">Address = <strong>100.10.0.1/24</strong></span></em>
<em><span style="color: #ff0000;">SaveConfig = true</span></em>
<em><span style="color: #ff0000;">ListenPort = <strong>51820</strong></span></em>
<em><span style="color: #ff0000;">PrivateKey = <strong>8DLZHyjeS2HHozkYpeaZJM64oGOwYDcbU/i+E1FjQ0Y=</strong></span></em>
<em><span style="color: #ff0000;">PostUp = firewall-cmd --zone=public --add-port 51820/udp &amp;&amp; firewall-cmd --zone=public --add-masquerade</span></em>
<em><span style="color: #ff0000;">PostDown = firewall-cmd --zone=public --remove-port 51820/udp &amp;&amp; firewall-cmd --zone=public --remove-masquerade</span></em></pre>
<pre>[root@wireguard-server wireguard]# <span style="color: #ff0000;">chmod 600 /etc/wireguard/{privatekey,wg0.conf}</span></pre>
<pre>[root@wireguard-server wireguard]# <span style="color: #ff0000;">echo "net.ipv4.ip_forward = 1" &gt;&gt; /etc/sysctl.conf</span>
[root@wireguard-server wireguard]# <span style="color: #ff0000;">sysctl –p</span></pre>
<p><strong><img loading="lazy" decoding="async" width="736" height="125" class="wp-image-6329" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-86.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-86.png 736w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-86-300x51.png 300w" sizes="auto, (max-width: 736px) 100vw, 736px" /></strong></p>
<h4><span style="color: #000000;"><strong>7°) Démarrage du server VPN </strong></span></h4>
<pre>[root@wireguard-server wireguard]#<span style="color: #ff0000;"> wg-quick up wg0</span></pre>
<p><img loading="lazy" decoding="async" width="855" height="195" class="wp-image-6330" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-87.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-87.png 855w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-87-300x68.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-87-768x175.png 768w" sizes="auto, (max-width: 855px) 100vw, 855px" /></p>
<pre>[root@wireguard-server wireguard]# <span style="color: #ff0000;">ip addr</span></pre>
<p><img loading="lazy" decoding="async" width="877" height="229" class="wp-image-6331" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-88.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-88.png 877w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-88-300x78.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-88-768x201.png 768w" sizes="auto, (max-width: 877px) 100vw, 877px" /></p>
<p><strong>Le VPN est monté sur la Carte Virtuelle wg0 et le Subnet 100.10.0.0/24</strong></p>
<h4><span style="color: #000000;"><strong>8°) Démarrage du service  » boot machine »&nbsp;</strong></span></h4>
<pre>[root@wireguard-server wireguard]# <span style="color: #ff0000;">systemctl enable wg-quick@wg0</span>
[root@wireguard-server wireguard]# <span style="color: #ff0000;">wg-quick down wg0</span>
[root@wireguard-server wireguard]# <span style="color: #ff0000;">systemctl start wg-quick@wg0</span>
[root@wireguard-server wireguard]# <span style="color: #ff0000;">systemctl status wg-quick@wg0</span></pre>
<p><img loading="lazy" decoding="async" width="1253" height="372" class="wp-image-6332" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-89.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-89.png 1253w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-89-300x89.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-89-1024x304.png 1024w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-89-768x228.png 768w" sizes="auto, (max-width: 1253px) 100vw, 1253px" /></p>
<pre>[root@wireguard-server wireguard]# <span style="color: #ff0000;">wg show wg0</span></pre>
<p><img loading="lazy" decoding="async" width="584" height="105" class="wp-image-6333" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-90.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-90.png 584w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-90-300x54.png 300w" sizes="auto, (max-width: 584px) 100vw, 584px" /></p>
<pre>[root@wireguard-server wireguard]#<span style="color: #ff0000;"> ip a show wg0</span></pre>
<p><img loading="lazy" decoding="async" width="821" height="100" class="wp-image-6334" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-91.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-91.png 821w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-91-300x37.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-91-768x94.png 768w" sizes="auto, (max-width: 821px) 100vw, 821px" /></p>
<p><strong><span style="text-decoration: underline;">Côté Firewall</span></strong></p>
<pre>[root@wireguard-server wireguard]# <span style="color: #ff0000;">firewall-cmd --list-all</span></pre>
<p><span style="color: #000000;"><img loading="lazy" decoding="async" width="686" height="250" class="wp-image-6335" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-92.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-92.png 686w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-92-300x109.png 300w" sizes="auto, (max-width: 686px) 100vw, 686px" /> </span></p>
<h2 style="text-align: center;"><span style="color: #000000;">Installation Client Linux VPN WireGuard – RockyLinux</span></h2>
<h4><span style="color: #000000;"><strong>1°) Mise à jour</strong></span></h4>
<pre>[root@wireguard-client01 ~]# <span style="color: #ff0000;">dnf -y update</span></pre>
<h4><span style="color: #000000;"><strong>2°) Désactivation IPv6 (Option)</strong></span></h4>
<pre>[root@wireguard-client01 ~]# <span style="color: #ff0000;">echo "net.ipv6.conf.all.disable_ipv6 = 1" &gt;&gt; /etc/sysctl.conf</span>
[root@wireguard-client01 ~]# <span style="color: #ff0000;">echo "net.ipv6.conf.all.autoconf = 0" &gt;&gt; /etc/sysctl.conf</span>
[root@wireguard-client01 ~]#<span style="color: #ff0000;"> echo "net.ipv6.conf.default.disable_ipv6 = 1" &gt;&gt; /etc/sysctl.conf</span>
[root@wireguard-client01 ~]# <span style="color: #ff0000;">echo "net.ipv6.conf.default.autoconf = 0" &gt;&gt; /etc/sysctl.conf</span>
[root@wireguard-client01 ~]# <span style="color: #ff0000;">sysctl -p</span></pre>
<h4><span style="color: #000000;"><strong>3°) Installation des dépendances </strong></span></h4>
<pre>[root@wireguard-client01 ~]# <span style="color: #ff0000;">dnf install epel-release elrepo-release</span></pre>
<h4><span style="color: #000000;"><strong>4°) Installation WireGuard VPN</strong></span></h4>
<pre>[root@wireguard-client01 ~]# <span style="color: #ff0000;">dnf install kmod-wireguard wireguard-tools –y</span></pre>
<h4><span style="color: #000000;"><strong>5°) Création des certificats Client01</strong></span></h4>
<pre>[root@wireguard-client01 ~]#<span style="color: #ff0000;"> cd /etc/wireguard/</span>
[root@wireguard-client01 <span style="color: #ff0000;">wireguard]# wg genkey | tee /etc/wireguard/privatekey | wg pubkey | tee /etc/wireguard/publickey</span>

[root@wireguard-client01 wireguard]# <span style="color: #ff0000;">cat /etc/wireguard/privatekey</span>
<span style="color: #ff0000;"><em>gLHwqTDBJtw2wYfCdqvBthcmpDsDqtCC+FKeKOZaaVo=</em></span>

[root@wireguard-client01 wireguard]# <span style="color: #ff0000;">cat /etc/wireguard/publickey</span>
<span style="color: #ff0000;"><em>bXbsDi3C2PThp8Eq8dmPtmiwNteEhexjyq4NHAtg/0U=</em></span></pre>
<h4><span style="color: #000000;"><strong>6°) Création/Configuration du client01 VPN</strong></span></h4>
<pre>[root@wireguard-client01 wireguard]#<span style="color: #ff0000;"> vi wg0.conf</span></pre>
<p><img loading="lazy" decoding="async" width="592" height="150" class="wp-image-6336" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-93.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-93.png 592w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-93-300x76.png 300w" sizes="auto, (max-width: 592px) 100vw, 592px" /></p>
<pre><span style="color: #ff0000;"><em>[Interface]</em></span>
<span style="color: #ff0000;"><em>#Clef Privée du client</em></span>
<span style="color: #ff0000;"><em>PrivateKey = <strong>gLHwqTDBJtw2wYfCdqvBthcmpDsDqtCC+FKeKOZaaVo=</strong></em></span>
<span style="color: #ff0000;"><em>#Adresse du client sur le VPN</em></span>
<span style="color: #ff0000;"><em>Address = <strong>100.10.0.2/24</strong></em></span>

<span style="color: #ff0000;"><em>[Peer]</em></span>
<span style="color: #ff0000;"><em>#Clef Public du serveur</em></span>
<span style="color: #ff0000;"><em>PublicKey = <strong>H9JrgVaNJh9wmB25K4wlQlG/fVii1um+mhkGApPJXUs=</strong></em></span>
<span style="color: #ff0000;"><em>#Adresse et port du Serveur WireGuard</em></span>
<span style="color: #ff0000;"><em>Endpoint = <strong>wireguard-server:51820</strong></em></span>
<span style="color: #ff0000;"><em>AllowedIPs = 0.0.0.0/0</em></span></pre>
<h4><span style="color: #000000;"><strong>7°) Ajout Clef Public du client01 sur le serveur WireGuard</strong></span></h4>
<ul>
<li>Clef Public du client01&nbsp;:<span style="color: #ff0000;"> <em>bXbsDi3C2PThp8Eq8dmPtmiwNteEhexjyq4NHAtg/0U=</em></span></li>
<li>Adresse du Client sur le VPN&nbsp;:<span style="color: #ff0000;"> <em>100.10.0.2</em></span></li>
</ul>
<pre>[root@<span style="color: #ff0000;">wireguard-server</span> wireguard]# <span style="color: #ff0000;">wg set wg0 peer bXbsDi3C2PThp8Eq8dmPtmiwNteEhexjyq4NHAtg/0U= allowed-ips 100.10.0.2</span></pre>
<h4><span style="color: #000000;"><strong>8°) Démarrage du client VPN </strong></span></h4>
<pre>[root@wireguard-client01 wireguard]# <span style="color: #ff0000;">wg-quick up wg0</span></pre>
<p><img loading="lazy" decoding="async" width="951" height="191" class="wp-image-6337" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-94.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-94.png 951w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-94-300x60.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-94-768x154.png 768w" sizes="auto, (max-width: 951px) 100vw, 951px" /></p>
<pre>[root@wireguard-client01 wireguard]# <span style="color: #ff0000;">ip addr</span></pre>
<p><img loading="lazy" decoding="async" width="952" height="223" class="wp-image-6338" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-95.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-95.png 952w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-95-300x70.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-95-768x180.png 768w" sizes="auto, (max-width: 952px) 100vw, 952px" /></p>
<p><strong>Le VPN (Client01) est monté sur la Carte Virtuelle wg0 et le Subnet 100.10.0.0/24</strong></p>
<h4><span style="color: #000000;">9°) Démarrage du service « boot machine »</span></h4>
<pre>[root@wireguard-client01 wireguard]# <span style="color: #ff0000;">systemctl enable wg-quick@wg0</span>
[root@wireguard-client01 wireguard]# <span style="color: #ff0000;">wg-quick down wg0</span>
[root@wireguard-client01 wireguard]#<span style="color: #ff0000;"> systemctl start wg-quick@wg0</span>
[root@wireguard-client01 wireguard]#<span style="color: #ff0000;"> systemctl status wg-quick@wg0</span></pre>
<p><img loading="lazy" decoding="async" width="979" height="372" class="wp-image-6339" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-96.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-96.png 979w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-96-300x114.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-96-768x292.png 768w" sizes="auto, (max-width: 979px) 100vw, 979px" /></p>
<pre>[root@wireguard-client01 wireguard]# <span style="color: #ff0000;">wg show wg0</span></pre>
<p><img loading="lazy" decoding="async" width="697" height="184" class="wp-image-6340" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-97.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-97.png 697w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-97-300x79.png 300w" sizes="auto, (max-width: 697px) 100vw, 697px" /></p>
<pre>[root@wireguard-client01 wireguard]# <span style="color: #ff0000;">ip a show wg0</span></pre>
<p><img loading="lazy" decoding="async" width="866" height="100" class="wp-image-6341" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-98.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-98.png 866w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-98-300x35.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-98-768x89.png 768w" sizes="auto, (max-width: 866px) 100vw, 866px" /></p>
<h4><span style="color: #000000;"><strong>10°) Check connexion</strong></span></h4>
<h4><span style="color: #000000;">Check de wireguard-client01 =&gt; wireguard-server via réseau VPN</span></h4>
<pre>[root@wireguard-client01 wireguard]# <span style="color: #ff0000;">ping -c 3 100.10.0.1</span></pre>
<p><img loading="lazy" decoding="async" width="611" height="165" class="wp-image-6342" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-99.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-99.png 611w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-99-300x81.png 300w" sizes="auto, (max-width: 611px) 100vw, 611px" /></p>
<h4><span style="color: #000000;">Check de wireguard-server =&gt; wireguard-client01 via réseau VPN</span></h4>
<pre>[root@wireguard-server log]# <span style="color: #ff0000;">ping -c 3 100.10.0.2</span></pre>
<p><img loading="lazy" decoding="async" width="692" height="160" class="wp-image-6343" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-100.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-100.png 692w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-100-300x69.png 300w" sizes="auto, (max-width: 692px) 100vw, 692px" /></p>
<h4><span style="color: #000000;">Connexion SSH du client01 sur le Serveur</span></h4>
<pre>[root@wireguard-client01 wireguard]# <span style="color: #ff0000;">ssh -l root 100.10.0.1</span></pre>
<p><img loading="lazy" decoding="async" width="762" height="231" class="wp-image-6344" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-101.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-101.png 762w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-101-300x91.png 300w" sizes="auto, (max-width: 762px) 100vw, 762px" /></p>
<p>On se connecte bien sur la machine serveur à partir de notre client via le réseau VPN.</p>
<p>Views: 3</p>
<p>L’article <a href="https://coffeebreak.en-images.info/modop-installation-wireguard-vpn-client-serveur/">MODOP – Installation WireGuard VPN</a> est apparu en premier sur <a href="https://coffeebreak.en-images.info">CoffeeBreak Info</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://coffeebreak.en-images.info/modop-installation-wireguard-vpn-client-serveur/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>MODOP – Ajout Client Windows sur Serveur OpenVPN Linux</title>
		<link>https://coffeebreak.en-images.info/modop-ajout-client-windows-sur-serveur-openvpn-linux/</link>
					<comments>https://coffeebreak.en-images.info/modop-ajout-client-windows-sur-serveur-openvpn-linux/#respond</comments>
		
		<dc:creator><![CDATA[chris]]></dc:creator>
		<pubDate>Wed, 13 Apr 2022 10:40:26 +0000</pubDate>
				<category><![CDATA[OS Linux]]></category>
		<category><![CDATA[Sécurité]]></category>
		<category><![CDATA[Système]]></category>
		<category><![CDATA[VPN]]></category>
		<category><![CDATA[Windows]]></category>
		<category><![CDATA[Centos]]></category>
		<category><![CDATA[Linux]]></category>
		<category><![CDATA[Serveur]]></category>
		<category><![CDATA[WIndows]]></category>
		<guid isPermaLink="false">https://coffeebreak.en-images.info/?p=6276</guid>

					<description><![CDATA[<p>En complément du précédent mode opératoire sur la mise en place d’un service OpenVPN et d’un client VPN sous Linux. Nous allons aborder, dans ce nouveau MODOP,  le déploiement d’un client Microsoft avec le client OpenVPN GUI. Le but est de connecter un client Win10 sur le serveur OpenVPN Linux précédemment configuré, et ainsi permettre la connexion des deux équipements sur un réseau VPN.</p>
<p>L’article <a href="https://coffeebreak.en-images.info/modop-ajout-client-windows-sur-serveur-openvpn-linux/">MODOP – Ajout Client Windows sur Serveur OpenVPN Linux</a> est apparu en premier sur <a href="https://coffeebreak.en-images.info">CoffeeBreak Info</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p><img loading="lazy" decoding="async" width="1458" height="546" class="wp-image-6277" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-48.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-48.png 1458w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-48-300x112.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-48-1024x383.png 1024w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-48-768x288.png 768w" sizes="auto, (max-width: 1458px) 100vw, 1458px" /></p>
<p>Host : <strong>open-client02.house.cpb</strong></p>
<ul>
<li>IP: <strong>172.32.185.30</strong></li>
<li>Subnet : 172.32.185.0/24</li>
<li>vSwitch : vmbr2</li>
<li>Disque : 50Go (Système)</li>
<li>RAM :8Go</li>
<li>vCPU : 4</li>
<li>OS : Windows10</li>
</ul>
<p><img loading="lazy" decoding="async" width="883" height="259" class="wp-image-6278" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-49.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-49.png 883w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-49-300x88.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-49-768x225.png 768w" sizes="auto, (max-width: 883px) 100vw, 883px" /></p>
<p><span style="color: #ff0000;">Les deux machines doivent être joignable mutuellement.</span></p>
<h4><span style="text-decoration: underline; color: #000000;"><strong>Check open-serveurvpn (172.16.185.30) =&gt; open-client02(172.32.185.30)</strong></span></h4>
<pre>[root@open-servervpn pki]# <span style="color: #ff0000;">echo "172.32.185.30 open-client02" &gt;&gt; /etc/hosts</span>
[root@open-servervpn pki]# <span style="color: #ff0000;">ping -c 3 open-client02</span></pre>
<p><img loading="lazy" decoding="async" width="700" height="158" class="wp-image-6279" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-50.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-50.png 700w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-50-300x68.png 300w" sizes="auto, (max-width: 700px) 100vw, 700px" /></p>
<h4><span style="text-decoration: underline;"><span style="color: #000000; text-decoration: underline;"><strong>Check open-client02 (172.32.185.30) =&gt; open-serveurvpn (172.16.185.30)</strong></span></span></h4>
<p><strong><img loading="lazy" decoding="async" width="1199" height="477" class="wp-image-6280" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-51.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-51.png 1199w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-51-300x119.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-51-1024x407.png 1024w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-51-768x306.png 768w" sizes="auto, (max-width: 1199px) 100vw, 1199px" /></strong></p>
<pre>C:\Users\admin&gt; <span style="color: #ff0000;">ping open-servervpn</span></pre>
<p><img loading="lazy" decoding="async" width="761" height="177" class="wp-image-6281" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-52.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-52.png 761w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-52-300x70.png 300w" sizes="auto, (max-width: 761px) 100vw, 761px" /></p>
<h3><span style="color: #000000;"><strong>1°) Génération des certificats pour le client02 sur le Serveur OpenVPN</strong></span></h3>
<pre>[root@open-servervpn ~]# <span style="color: #ff0000;">cd /etc/openvpn</span></pre>
<h4><span style="color: #000000;"><strong>Création des certificats du Client</strong></span></h4>
<pre>[root@open-servervpn openvpn]# <span style="color: #ff0000;">./easyrsa gen-req open-client02 nopass</span></pre>
<p><img loading="lazy" decoding="async" width="1397" height="381" class="wp-image-6282" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-53.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-53.png 1397w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-53-300x82.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-53-1024x279.png 1024w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-53-768x209.png 768w" sizes="auto, (max-width: 1397px) 100vw, 1397px" /></p>
<h4><span style="color: #000000;"><strong>Signature du certificat du Client avec les RootCA</strong></span></h4>
<pre>[root@open-servervpn openvpn]# <span style="color: #ff0000;">./easyrsa sign-req client open-client02 nopass</span></pre>
<p><img loading="lazy" decoding="async" width="985" height="287" class="wp-image-6283" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-54.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-54.png 985w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-54-300x87.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-54-768x224.png 768w" sizes="auto, (max-width: 985px) 100vw, 985px" /></p>
<h4><span style="color: #000000;"><strong>Inventaire du certificat du Client</strong></span></h4>
<pre>[root@open-servervpn openvpn]# <span style="color: #ff0000;">ls -al /etc/openvpn/pki/{issued,private} |grep client02</span></pre>
<p><img loading="lazy" decoding="async" width="719" height="91" class="wp-image-6284" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-55.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-55.png 719w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-55-300x38.png 300w" sizes="auto, (max-width: 719px) 100vw, 719px" /></p>
<h4><span style="color: #000000;"><strong>Préparation pour le transfert </strong></span></h4>
<pre>[root@open-servervpn openvpn]#<span style="color: #ff0000;"> mkdir win10</span>
[root@open-servervpn openvpn]# <span style="color: #ff0000;">cp pki/ca.crt win10</span>
[root@open-servervpn openvpn]# <span style="color: #ff0000;">cp pki/private/open-client02.key win10</span>
[root@open-servervpn openvpn]# <span style="color: #ff0000;">cp pki/issued/open-client02.crt win10</span>
[root@open-servervpn openvpn]# <span style="color: #ff0000;">ls -al win10</span></pre>
<p><img loading="lazy" decoding="async" width="708" height="128" class="wp-image-6285" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-56.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-56.png 708w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-56-300x54.png 300w" sizes="auto, (max-width: 708px) 100vw, 708px" /></p>
<h3><span style="color: #000000;"><strong>2°) Installation du Client OpenVPN sur Windows10</strong></span></h3>
<ul>
<li><strong><em>https://openvpn.net/community-downloads/</em></strong></li>
</ul>
<p><img loading="lazy" decoding="async" width="958" height="588" class="wp-image-6286" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-57.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-57.png 958w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-57-300x184.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-57-768x471.png 768w" sizes="auto, (max-width: 958px) 100vw, 958px" /><br />
Choisir le client souhaité, pour ma part la version 64Bits et lancer celui-ci</p>
<p><img loading="lazy" decoding="async" width="454" height="271" class="wp-image-6287" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-58.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-58.png 454w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-58-300x179.png 300w" sizes="auto, (max-width: 454px) 100vw, 454px" /><br />
« <strong>Exécuter</strong> »</p>
<p><img loading="lazy" decoding="async" width="542" height="436" class="wp-image-6288" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-59.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-59.png 542w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-59-300x241.png 300w" sizes="auto, (max-width: 542px) 100vw, 542px" /><br />
« <strong>Install Now</strong> »</p>
<p><img loading="lazy" decoding="async" width="526" height="344" class="wp-image-6289" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-60.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-60.png 526w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-60-300x196.png 300w" sizes="auto, (max-width: 526px) 100vw, 526px" /><br />
« <strong>Oui</strong> »</p>
<p><img loading="lazy" decoding="async" width="527" height="292" class="wp-image-6290" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-61.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-61.png 527w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-61-300x166.png 300w" sizes="auto, (max-width: 527px) 100vw, 527px" /><br />
Laisser l’installation se dérouler</p>
<p><img loading="lazy" decoding="async" width="530" height="425" class="wp-image-6291" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-62.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-62.png 530w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-62-300x241.png 300w" sizes="auto, (max-width: 530px) 100vw, 530px" /><br />
« <strong>Close</strong> »</p>
<p><img loading="lazy" decoding="async" width="552" height="255" class="wp-image-6292" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-63.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-63.png 552w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-63-300x139.png 300w" sizes="auto, (max-width: 552px) 100vw, 552px" /></p>
<h3><span style="color: #000000;"><strong>3°) Récupérer les certificats Client </strong></span></h3>
<p>Lancer le client WinSCP</p>
<p><img loading="lazy" decoding="async" width="467" height="88" class="wp-image-6293" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-64.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-64.png 467w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-64-300x57.png 300w" sizes="auto, (max-width: 467px) 100vw, 467px" /></p>
<p><img loading="lazy" decoding="async" width="623" height="303" class="wp-image-6294" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-65.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-65.png 623w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-65-300x146.png 300w" sizes="auto, (max-width: 623px) 100vw, 623px" /><br />
Remplir les données de votre serveur OpenVPN et « <strong>connexion </strong>»</p>
<p><img loading="lazy" decoding="async" width="466" height="349" class="wp-image-6295" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-66.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-66.png 466w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-66-300x225.png 300w" sizes="auto, (max-width: 466px) 100vw, 466px" /><br />
«<strong> Oui</strong> »</p>
<p><img loading="lazy" decoding="async" width="939" height="327" class="wp-image-6296" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-67.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-67.png 939w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-67-300x104.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-67-768x267.png 768w" sizes="auto, (max-width: 939px) 100vw, 939px" /><br />
Copier vos certificats du serveur Linux vers <strong>c:\tmp\*.*</strong></p>
<p><img loading="lazy" decoding="async" width="977" height="592" class="wp-image-6297" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-68.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-68.png 977w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-68-300x182.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-68-768x465.png 768w" sizes="auto, (max-width: 977px) 100vw, 977px" /><br />
Déplacer vos certificats de<strong> c:\tmp\*.*</strong> vers <strong>c:\Programmes\OpenVPN\Config</strong></p>
<h3><span style="color: #000000;"><strong>4°) Configuration du Client OpenVPN</strong></span></h3>
<p><span style="color: #ff0000;"><em>Sur votre Serveur Linux, éviter de faire cela via le fichier « sample-client » pour des raisons de pré-formatage de caractère.</em></span></p>
<pre>[root@open-servervpn server]# <span style="color: #ff0000;">cd /etc/openvpn/client</span></pre>
<pre>[root@open-servervpn client]# <span style="color: #ff0000;">vi client.ovpn</span>

<span style="color: #ff0000;"><em>client</em></span>
<span style="color: #ff0000;"><em>dev tun</em></span>
<span style="color: #ff0000;"><em>proto udp</em></span>
<span style="color: #ff0000;"><em>remote <strong>open-servervpn</strong></em></span>
<span style="color: #ff0000;"><em>port 1194</em></span>
<strong><span style="color: #ff0000;"><em>ca ca.crt</em></span></strong>
<strong><span style="color: #ff0000;"><em>cert open-client02.crt</em></span></strong>
<strong><span style="color: #ff0000;"><em>key open-client02.key</em></span></strong>
<span style="color: #ff0000;"><em>verb 5</em></span>
<span style="color: #ff0000;"><em>remote-cert-tls server</em></span>
<span style="color: #ff0000;"><em>auth-nocache</em></span>
<span style="color: #ff0000;"><em>cipher AES-256-CGM</em></span></pre>
<p>Sauvegarder et transférer à votre client sur la ressource <strong>c:\Programmes\OpenVPN\Config\*</strong></p>
<h3><span style="color: #000000;"><strong>5°) Lancement du Client « Mode Test &#8211; Console »</strong></span></h3>
<p><img loading="lazy" decoding="async" width="1230" height="361" class="wp-image-6298" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-69.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-69.png 1230w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-69-300x88.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-69-1024x301.png 1024w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-69-768x225.png 768w" sizes="auto, (max-width: 1230px) 100vw, 1230px" /><br />
Clique droit de souris «<strong> Start OpenVPN on this config file </strong>»</p>
<p><img loading="lazy" decoding="async" width="929" height="531" class="wp-image-6299" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-70.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-70.png 929w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-70-300x171.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-70-768x439.png 768w" sizes="auto, (max-width: 929px) 100vw, 929px" /><br />
« <strong>Autoriser l’accès</strong> »<br />
Le terminal du fond, trace les interactions avec votre serveur de VPN</p>
<h3><span style="color: #000000;"><strong>6°) Check de connexion </strong></span></h3>
<h4><span style="color: #000000;"><strong>Côté logs Serveur </strong></span><br />
<img loading="lazy" decoding="async" width="1558" height="185" class="wp-image-6300" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-71.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-71.png 1558w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-71-300x36.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-71-1024x122.png 1024w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-71-768x91.png 768w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-71-1536x182.png 1536w" sizes="auto, (max-width: 1558px) 100vw, 1558px" /></h4>
<p><span style="color: #000000;"><strong>Côté Client</strong></span><br />
<span style="color: #000000;">Dans un terminal Wndows</span></p>
<pre>C:\Users\admin&gt; <span style="color: #ff0000;">ipconfig /all</span></pre>
<p><img loading="lazy" decoding="async" width="882" height="303" class="wp-image-6301" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-72.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-72.png 882w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-72-300x103.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-72-768x264.png 768w" sizes="auto, (max-width: 882px) 100vw, 882px" /></p>
<h4><span style="text-decoration: underline;"><span style="color: #000000;"><strong>Open-client02 =&gt; open-servervpn via réseau VPN 10.8.0.0/24</strong></span></span></h4>
<pre>C:\Users\admin&gt; <span style="color: #ff0000;">ping 10.8.0.1</span></pre>
<p><img loading="lazy" decoding="async" width="866" height="201" class="wp-image-6302" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-73.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-73.png 866w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-73-300x70.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-73-768x178.png 768w" sizes="auto, (max-width: 866px) 100vw, 866px" /></p>
<h4><span style="text-decoration: underline; color: #000000;"><strong>Open-client02 =&gt; open-client01 via réseau VPN 10.8.0.0/24</strong></span></h4>
<pre>C:\Users\admin&gt; <span style="color: #ff0000;">ping 10.8.0.2</span></pre>
<p><img loading="lazy" decoding="async" width="753" height="196" class="wp-image-6303" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-74.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-74.png 753w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-74-300x78.png 300w" sizes="auto, (max-width: 753px) 100vw, 753px" /></p>
<h3><span style="color: #000000;"><strong>7°) Lancement du Client « Mode GUI »</strong></span></h3>
<p><strong>Ajouter le fichier à OpenVPN-GUI</strong></p>
<p><img loading="lazy" decoding="async" width="979" height="292" class="wp-image-6304" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-75.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-75.png 979w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-75-300x89.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-75-768x229.png 768w" sizes="auto, (max-width: 979px) 100vw, 979px" /><br />
Clic droit sur le fichier et « <strong>import into OpenVPN-Gui</strong> »</p>
<p><img loading="lazy" decoding="async" width="431" height="104" class="wp-image-6305" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-76.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-76.png 431w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-76-300x72.png 300w" sizes="auto, (max-width: 431px) 100vw, 431px" /><br />
Lancer votre Client OpenVPN</p>
<p><img loading="lazy" decoding="async" width="511" height="130" class="wp-image-6306" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-77.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-77.png 511w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-77-300x76.png 300w" sizes="auto, (max-width: 511px) 100vw, 511px" /><br />
Se rendre en bas à droite et clic droit sur l’icône</p>
<p><img loading="lazy" decoding="async" width="538" height="248" class="wp-image-6307" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-78.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-78.png 538w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-78-300x138.png 300w" sizes="auto, (max-width: 538px) 100vw, 538px" /><br />
« <strong>Connecter</strong> »</p>
<p><img loading="lazy" decoding="async" width="618" height="365" class="wp-image-6308" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-79.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-79.png 618w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-79-300x177.png 300w" sizes="auto, (max-width: 618px) 100vw, 618px" /><br />
Le client va se connecter au serveur VPN</p>
<p><img loading="lazy" decoding="async" width="552" height="153" class="wp-image-6309" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-80.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-80.png 552w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-80-300x83.png 300w" sizes="auto, (max-width: 552px) 100vw, 552px" /><br />
L’icône OpenVPN passe au<strong><span style="color: #00ff00;"> vert</span></strong>.</p>
<h3><span style="color: #000000;">Vous êtes à présent connecté en VPN.</span></h3>
<p>Views: 18</p>
<p>L’article <a href="https://coffeebreak.en-images.info/modop-ajout-client-windows-sur-serveur-openvpn-linux/">MODOP – Ajout Client Windows sur Serveur OpenVPN Linux</a> est apparu en premier sur <a href="https://coffeebreak.en-images.info">CoffeeBreak Info</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://coffeebreak.en-images.info/modop-ajout-client-windows-sur-serveur-openvpn-linux/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>MODOP – Installation OpenVPN (Easy-RSA3) &#8211; Client/serveur</title>
		<link>https://coffeebreak.en-images.info/modop-installation-openvpn-easy-rsa3-client-serveur/</link>
					<comments>https://coffeebreak.en-images.info/modop-installation-openvpn-easy-rsa3-client-serveur/#respond</comments>
		
		<dc:creator><![CDATA[chris]]></dc:creator>
		<pubDate>Tue, 12 Apr 2022 10:23:14 +0000</pubDate>
				<category><![CDATA[Applications]]></category>
		<category><![CDATA[OS Linux]]></category>
		<category><![CDATA[RedHat/Centos Linux]]></category>
		<category><![CDATA[Sécurité]]></category>
		<category><![CDATA[Système]]></category>
		<category><![CDATA[Centos]]></category>
		<category><![CDATA[Linux]]></category>
		<category><![CDATA[Serveur]]></category>
		<category><![CDATA[Virtualisation]]></category>
		<category><![CDATA[VPN]]></category>
		<guid isPermaLink="false">https://coffeebreak.en-images.info/?p=6206</guid>

					<description><![CDATA[<p>MODOP – Mise en place d’une solution VPN avec l’aide des services OpenVPN et Easy-RSA afin de sécuriser du trafic de données entre deux Subnet/Infrastructure différents via un réseau virtuel privé. Les Certificats Racine CA, Serveur et Clients seront générés via le service Easy-RSA. Le tunnel (Réseau virtuel privé) VPN sera lancé via le service OpenVPN en s’appuyant sur les certificats générés précédemment. Le mécanisme du VPN permet de sécuriser, authentifier, encrypter des DATA bout à bout entre deux équipements et garanti la confidentialité et l’intégrité des transactions.</p>
<p>L’article <a href="https://coffeebreak.en-images.info/modop-installation-openvpn-easy-rsa3-client-serveur/">MODOP – Installation OpenVPN (Easy-RSA3) &#8211; Client/serveur</a> est apparu en premier sur <a href="https://coffeebreak.en-images.info">CoffeeBreak Info</a>.</p>
]]></description>
										<content:encoded><![CDATA[<h1><img loading="lazy" decoding="async" class="aligncenter wp-image-6207 size-full" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image.png" alt="" width="1466" height="424" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image.png 1466w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-300x87.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-1024x296.png 1024w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-768x222.png 768w" sizes="auto, (max-width: 1466px) 100vw, 1466px" /></h1>
<h3><span style="color: #000000;"><strong>Inventaire des Machines</strong></span></h3>
<p>Host&nbsp;: <strong>open-serveurVPN.house.cpb</strong></p>
<ul>
<li>IP:&nbsp;<strong>172.16.185.30</strong></li>
<li>Subnet&nbsp;: 172.16.185.0/24</li>
<li>vSwitch&nbsp;:<strong> vmbr1</strong></li>
<li>Disque&nbsp;: 8Go (Système)</li>
<li>RAM&nbsp;:2Go</li>
<li>vCPU&nbsp;: 2</li>
<li>OS&nbsp;:&nbsp;RockyLinux 8</li>
</ul>
<p><img loading="lazy" decoding="async" width="1043" height="277" class="wp-image-6208" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-1.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-1.png 1043w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-1-300x80.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-1-1024x272.png 1024w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-1-768x204.png 768w" sizes="auto, (max-width: 1043px) 100vw, 1043px" /></p>
<p>Host&nbsp;:<strong> open-client01.house.cpb</strong></p>
<ul>
<li>IP:<strong>&nbsp;10.10.0.30</strong></li>
<li>Subnet&nbsp;: 10.10.0.0/24</li>
<li>vSwitch&nbsp;:<strong> vmbr4</strong></li>
<li>Disque&nbsp;: 8Go (Système)</li>
<li>RAM&nbsp;:2Go</li>
<li>vCPU&nbsp;: 2</li>
<li>OS : RockyLinux 8</li>
</ul>
<p><img loading="lazy" decoding="async" width="1034" height="282" class="wp-image-6209" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-2.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-2.png 1034w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-2-300x82.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-2-1024x279.png 1024w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-2-768x209.png 768w" sizes="auto, (max-width: 1034px) 100vw, 1034px" /></p>
<p><strong>Le Pool de machine VPN</strong></p>
<p><img loading="lazy" decoding="async" width="1033" height="170" class="wp-image-6210" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-3.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-3.png 1033w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-3-300x49.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-3-1024x169.png 1024w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-3-768x126.png 768w" sizes="auto, (max-width: 1033px) 100vw, 1033px" /></p>
<p>Les deux machines doivent être joignable mutuellement.</p>
<h3><span style="color: #000000;"><strong>Check open-serveurvpn (172.16.185.30) =&gt; open-client01(10.10.0.30)</strong></span></h3>
<pre>[root@open-servervpn pki]# <span style="color: #ff0000;">echo "10.10.0.30 open-client01" &gt;&gt; /etc/hosts</span>
[root@open-servervpn pki]# <span style="color: #ff0000;">ping -c 3 open-client01</span></pre>
<p><img loading="lazy" decoding="async" width="761" height="174" class="wp-image-6211" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-4.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-4.png 761w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-4-300x69.png 300w" sizes="auto, (max-width: 761px) 100vw, 761px" /></p>
<h3><span style="color: #000000;"><strong>Check open-client01(10.10.0.30) =&gt; open-serveurvpn (172.16.185.30)</strong></span></h3>
<pre>[root@open-client01 ~]# <span style="color: #ff0000;">echo "172.16.185.30 open-servervpn" &gt;&gt; /etc/hosts</span>
[root@open-client01 ~]#<span style="color: #ff0000;"> ping -c 3 open-servervpn</span></pre>
<p><img loading="lazy" decoding="async" width="708" height="158" class="wp-image-6212" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-5.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-5.png 708w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-5-300x67.png 300w" sizes="auto, (max-width: 708px) 100vw, 708px" /></p>
<h2 style="text-align: center;"><span style="color: #000000;">Installation Serveur VPN &#8211; RockyLinux</span></h2>
<h4><span style="color: #000000;"><strong>1°) Mise à jour</strong></span></h4>
<pre>[root@open-serveurvpn ~]# <span style="color: #ff0000;">dnf -y update</span></pre>
<h4><span style="color: #000000;"><strong>2°) Désactivation IPv6 (Option)</strong></span></h4>
<pre>[root@open-serveurvpn ~]# <span style="color: #ff0000;">ip addr</span></pre>
<p><strong><img loading="lazy" decoding="async" width="894" height="198" class="wp-image-6213" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-6.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-6.png 894w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-6-300x66.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-6-768x170.png 768w" sizes="auto, (max-width: 894px) 100vw, 894px" /></strong></p>
<pre>[root@open-serveurvpn ~]# <span style="color: #ff0000;">echo "net.ipv6.conf.all.disable_ipv6 = 1" &gt;&gt; /etc/sysctl.conf</span>
[root@open-serveurvpn ~]# <span style="color: #ff0000;">echo "net.ipv6.conf.all.autoconf = 0" &gt;&gt; /etc/sysctl.conf</span>
[root@open-serveurvpn ~]# <span style="color: #ff0000;">echo "net.ipv6.conf.default.disable_ipv6 = 1" &gt;&gt; /etc/sysctl.conf</span>
[root@open-serveurvpn ~]# <span style="color: #ff0000;">echo "net.ipv6.conf.default.autoconf = 0" &gt;&gt; /etc/sysctl.conf</span>
[root@open-serveurvpn ~]# <span style="color: #ff0000;">sysctl -p</span></pre>
<pre>[root@open-serveurvpn ~]#<span style="color: #ff0000;"> ip addr</span></pre>
<p><img loading="lazy" decoding="async" width="987" height="154" class="wp-image-6214" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-7.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-7.png 987w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-7-300x47.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-7-768x120.png 768w" sizes="auto, (max-width: 987px) 100vw, 987px" /></p>
<h4><span style="color: #000000;"><strong>3°) Installation EPEL</strong></span></h4>
<pre>[root@open-serveurvpn ~]# <span style="color: #ff0000;">dnf install -y epel-release</span></pre>
<p><img loading="lazy" decoding="async" width="1576" height="473" class="wp-image-6215" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-8.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-8.png 1576w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-8-300x90.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-8-1024x307.png 1024w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-8-768x230.png 768w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-8-1536x461.png 1536w" sizes="auto, (max-width: 1576px) 100vw, 1576px" /></p>
<h4><span style="color: #000000;"><strong>4°) Installation OpenVPN et Paquets de création PKI</strong></span></h4>
<pre>[root@open-serveurvpn ~]# <span style="color: #ff0000;">dnf install -y openvpn easy-rsa</span></pre>
<p><img loading="lazy" decoding="async" width="1542" height="776" class="wp-image-6216" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-9.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-9.png 1542w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-9-300x151.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-9-1024x515.png 1024w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-9-768x386.png 768w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-9-1536x773.png 1536w" sizes="auto, (max-width: 1542px) 100vw, 1542px" /></p>
<h4><span style="color: #000000;"><strong>5°) Préparation de notre PKI </strong></span></h4>
<pre>[root@open-serveurvpn ~]# <span style="color: #ff0000;">cd /usr/share/easy-rsa/3.0.8</span>
[root@open-serveurvpn 3.0.8]# <span style="color: #ff0000;">ls -al</span></pre>
<p><img loading="lazy" decoding="async" width="629" height="144" class="wp-image-6217" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-10.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-10.png 629w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-10-300x69.png 300w" sizes="auto, (max-width: 629px) 100vw, 629px" /></p>
<pre>[root@open-serveurvpn 3.0.8]# <span style="color: #ff0000;">cp -r * /etc/openvpn/.</span>
[root@open-serveurvpn 3.0.8]# <span style="color: #ff0000;">cd /etc/openvpn/</span></pre>
<pre>[root@open-serveurvpn ]# <span style="color: #ff0000;">vi vars</span>

<span style="color: #ff0000;"><em>set_var EASYRSA "$PWD"</em></span>
<span style="color: #ff0000;"><em>set_var EASYRSA_PKI "$EASYRSA/pki"</em></span>
<span style="color: #ff0000;"><em>set_var EASYRSA_DN "cn_only"</em></span>
<span style="color: #ff0000;"><em>set_var EASYRSA_REQ_COUNTRY "FR"</em></span>
<span style="color: #ff0000;"><em>set_var EASYRSA_REQ_PROVINCE "PARIS"</em></span>
<span style="color: #ff0000;"><em>set_var EASYRSA_REQ_CITY "Fontenay ss Bois"</em></span>
<span style="color: #ff0000;"><em>set_var EASYRSA_REQ_ORG "House Corp"</em></span>
<span style="color: #ff0000;"><em>set_var EASYRSA_REQ_EMAIL "chris@house.cpb"</em></span>
<span style="color: #ff0000;"><em>set_var EASYRSA_REQ_OU "House Corp EASY CA"</em></span>
<span style="color: #ff0000;"><em>set_var EASYRSA_KEY_SIZE 4096</em></span>
<span style="color: #ff0000;"><em>set_var EASYRSA_ALGO rsa</em></span>
<span style="color: #ff0000;"><em>set_var EASYRSA_CA_EXPIRE 3650</em></span>
<span style="color: #ff0000;"><em>set_var EASYRSA_CERT_EXPIRE 3650</em></span>
<span style="color: #ff0000;"><em>set_var EASYRSA_NS_SUPPORT "no"</em></span>
<span style="color: #ff0000;"><em>set_var EASYRSA_NS_COMMENT "House Corp CERTIFICATE AUTHORITY"</em></span>
<span style="color: #ff0000;"><em>set_var EASYRSA_EXT_DIR "$EASYRSA/x509-types"</em></span>
<span style="color: #ff0000;"><em>set_var EASYRSA_SSL_CONF "$EASYRSA/openssl-easyrsa.cnf"</em></span>
<span style="color: #ff0000;"><em>set_var EASYRSA_DIGEST "sha256"</em></span></pre>
<pre>[root@open-serveurvpn ]# <span style="color: #ff0000;">chmod +x vars</span></pre>
<h4><span style="color: #000000;"><strong>7°) Initialisation des PKI</strong></span></h4>
<pre>[root@open-serveurvpn ]#<span style="color: #ff0000;"> ./easyrsa init-pki</span></pre>
<p><img loading="lazy" decoding="async" width="672" height="148" class="wp-image-6218" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-11.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-11.png 672w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-11-300x66.png 300w" sizes="auto, (max-width: 672px) 100vw, 672px" /></p>
<pre>[root@open-serveurvpn ]# <span style="color: #ff0000;">ls /etc/openvpn/vars</span>
<span style="color: #ff0000;"><em>/etc/openvpn/vars</em></span>

[root@open-serveurvpn ]# <span style="color: #ff0000;">ls /etc/openvpn/pki</span>
<span style="color: #ff0000;"><em>private reqs</em></span></pre>
<h4><span style="color: #000000;"><strong>8°) Création des certificats root CA</strong></span></h4>
<pre>[root@open-serveurvpn ]# <span style="color: #ff0000;">./easyrsa build-ca nopass</span></pre>
<p><img loading="lazy" decoding="async" width="1383" height="336" class="wp-image-6219" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-12.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-12.png 1383w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-12-300x73.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-12-1024x249.png 1024w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-12-768x187.png 768w" sizes="auto, (max-width: 1383px) 100vw, 1383px" /></p>
<pre>[root@open-serveurvpn ]# <span style="color: #ff0000;">ls /etc/openvpn/pki/<em>ca.crt</em></span>
<span style="color: #ff0000;"><em>/etc/openvpn/pki/ca.crt</em></span></pre>
<h4><span style="color: #000000;"><strong>9°) Création des certificats du Server</strong></span></h4>
<pre>[root@open-serveurvpn ]#<span style="color: #ff0000;">./easyrsa gen-req <strong>open-serveurvpn</strong> nopass</span></pre>
<p><img loading="lazy" decoding="async" width="1302" height="359" class="wp-image-6220" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-13.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-13.png 1302w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-13-300x83.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-13-1024x282.png 1024w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-13-768x212.png 768w" sizes="auto, (max-width: 1302px) 100vw, 1302px" /></p>
<pre>[root@open-serveurvpn ]# <span style="color: #ff0000;">ls -al /etc/openvpn/pki/{reqs,private}</span></pre>
<p><img loading="lazy" decoding="async" width="805" height="228" class="wp-image-6221" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-14.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-14.png 805w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-14-300x85.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-14-768x218.png 768w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-14-800x228.png 800w" sizes="auto, (max-width: 805px) 100vw, 805px" /></p>
<p><strong>Signature de la clef serveur avec le certificat CA</strong></p>
<pre>[root@open-serveurvpn ]#<span style="color: #ff0000;">./easyrsa sign-req server open-serveurvpn nopass</span></pre>
<p><img loading="lazy" decoding="async" width="1251" height="303" class="wp-image-6222" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-15.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-15.png 1251w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-15-300x73.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-15-1024x248.png 1024w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-15-768x186.png 768w" sizes="auto, (max-width: 1251px) 100vw, 1251px" /></p>
<pre>[root@open-serveurvpn ]# <span style="color: #ff0000;">ls -a /etc/openvpn/pki/issued/open-serveurvpn.crt</span>
<span style="color: #ff0000;"><em>/etc/openvpn/pki/issued/open-serveurvpn.crt</em></span></pre>
<h4><span style="color: #000000;"><strong>10°) Création des certificats du Client</strong></span></h4>
<pre>[root@open-servervpn openvpn]# <span style="color: #ff0000;">./easyrsa gen-req open-client01 nopass</span></pre>
<p><img loading="lazy" decoding="async" width="998" height="355" class="wp-image-6223" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-16.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-16.png 998w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-16-300x107.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-16-768x273.png 768w" sizes="auto, (max-width: 998px) 100vw, 998px" /></p>
<pre>[root@open-servervpn openvpn]# <span style="color: #ff0000;">./easyrsa sign-req client open-client01 nopass</span></pre>
<p><strong><img loading="lazy" decoding="async" width="836" height="266" class="wp-image-6224" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-17.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-17.png 836w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-17-300x95.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-17-768x244.png 768w" sizes="auto, (max-width: 836px) 100vw, 836px" /></strong></p>
<pre>[root@open-servervpn openvpn]# <span style="color: #ff0000;">ls -al /etc/openvpn/pki/{issued,private}</span></pre>
<p><strong><img loading="lazy" decoding="async" width="776" height="243" class="wp-image-6225" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-18.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-18.png 776w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-18-300x94.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-18-768x240.png 768w" sizes="auto, (max-width: 776px) 100vw, 776px" /></strong></p>
<h4><span style="color: #000000;"><strong>11°) Création du certificat « Diffie hellman »</strong></span></h4>
<pre>[root@open-servervpn openvpn]#<span style="color: #ff0000;"> ./easyrsa gen-dh</span></pre>
<p><img loading="lazy" decoding="async" width="1319" height="373" class="wp-image-6226" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-19.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-19.png 1319w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-19-300x85.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-19-1024x290.png 1024w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-19-768x217.png 768w" sizes="auto, (max-width: 1319px) 100vw, 1319px" /></p>
<p>….. Après quelques minutes</p>
<p><strong><img loading="lazy" decoding="async" width="1175" height="297" class="wp-image-6227" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-20.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-20.png 1175w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-20-300x76.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-20-1024x259.png 1024w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-20-768x194.png 768w" sizes="auto, (max-width: 1175px) 100vw, 1175px" /></strong></p>
<h4><span style="color: #000000;"><strong>Inventaire des PKI</strong></span></h4>
<pre>[root@open-servervpn openvpn]# <span style="color: #ff0000;">ls -al pki/{ca.crt,dh.pem,issued,private}</span></pre>
<p><strong><img loading="lazy" decoding="async" width="1041" height="299" class="wp-image-6228" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-21.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-21.png 1041w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-21-300x86.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-21-1024x294.png 1024w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-21-768x221.png 768w" sizes="auto, (max-width: 1041px) 100vw, 1041px" /></strong></p>
<h4><span style="color: #000000;"><strong>12°) Création fichier de conf OpenVPN server</strong></span></h4>
<pre>[root@open-servervpn openvpn]# <span style="color: #ff0000;">cd /etc/openvpn/server</span>
[root@open-servervpn server]# <span style="color: #ff0000;">cp /usr/share/doc/openvpn/sample/sample-config-files/server.conf .</span></pre>
<pre>[root@open-servervpn server]# <span style="color: #ff0000;">vi server.conf</span></pre>
<p><strong><span style="text-decoration: underline;">Ligne 78</span></strong></p>
<pre><span style="color: #ff0000;"><em>ca /etc/openvpn/pki/<strong>ca.crt</strong></em></span>
<span style="color: #ff0000;"><em>cert /etc/openvpn/pki/issued/<strong>open-serveurvpn.crt</strong></em></span>
<span style="color: #ff0000;"><em>key /etc/openvpn/pki/private/<strong>open-serveurvpn.key</strong></em></span></pre>
<p><img loading="lazy" decoding="async" width="573" height="87" class="wp-image-6229" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-22.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-22.png 573w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-22-300x46.png 300w" sizes="auto, (max-width: 573px) 100vw, 573px" /></p>
<p><strong><span style="text-decoration: underline;">Ligne 85</span></strong></p>
<pre><span style="color: #ff0000;"><em>dh /etc/openvpn/pki/<strong>dh.pem</strong></em></span></pre>
<p><img loading="lazy" decoding="async" width="440" height="63" class="wp-image-6230" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-23.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-23.png 440w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-23-300x43.png 300w" sizes="auto, (max-width: 440px) 100vw, 440px" /></p>
<p><strong><span style="text-decoration: underline;">Ligne 92</span></strong></p>
<pre><em>;topology subnet</em>
<span style="color: #ff0000;"><em>topology subnet</em></span></pre>
<p><img loading="lazy" decoding="async" width="477" height="68" class="wp-image-6231" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-24.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-24.png 477w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-24-300x43.png 300w" sizes="auto, (max-width: 477px) 100vw, 477px" /></p>
<p><strong><span style="text-decoration: underline;">Ligne 102</span></strong></p>
<pre><span style="color: #ff0000;"><em>server 10.8.0.0 255.255.255.0</em></span></pre>
<p><img loading="lazy" decoding="async" width="533" height="63" class="wp-image-6232" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-25.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-25.png 533w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-25-300x35.png 300w" sizes="auto, (max-width: 533px) 100vw, 533px" /></p>
<h6><span style="color: #ff0000;"><em>Il est fortement conseillé de changer le Subnet VIP pour les échanges sur le VPN.</em></span></h6>
<h6><span style="color: #ff0000;"><em>Dans notre MODOP nous allons laisser la conf d’orgine.</em></span></h6>
<p><span style="text-decoration: underline;"><strong>Ligne 193</strong></span></p>
<pre><span style="color: #ff0000;"><em>push "redirect-gateway def1 bypass-dhcp"</em></span></pre>
<p><img loading="lazy" decoding="async" width="464" height="74" class="wp-image-6233" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-26.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-26.png 464w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-26-300x48.png 300w" sizes="auto, (max-width: 464px) 100vw, 464px" /></p>
<p><strong><span style="text-decoration: underline;">Ligne 202</span></strong></p>
<pre><em>;push ;"dhcp-option DNS 208.67.222.222"</em>
<span style="color: #ff0000;"><em>push "dhcp-option DNS 8.8.8.8"</em></span>
<em>;push "dhcp-option DNS 208.67.220.220"</em>
<span style="color: #ff0000;"><em>push "dhcp-option DNS 8.8.4.4"</em></span></pre>
<p><img loading="lazy" decoding="async" width="548" height="95" class="wp-image-6234" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-27.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-27.png 548w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-27-300x52.png 300w" sizes="auto, (max-width: 548px) 100vw, 548px" /></p>
<p><span style="text-decoration: underline;"><strong>Ligne 247</strong></span></p>
<pre><em><span style="color: #ff0000;">#</span>tls-auth ta.key 0 # This file is secret</em></pre>
<p><img loading="lazy" decoding="async" width="431" height="58" class="wp-image-6235" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-28.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-28.png 431w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-28-300x40.png 300w" sizes="auto, (max-width: 431px) 100vw, 431px" /></p>
<p><strong><span style="text-decoration: underline;">Ligne 277</span></strong></p>
<pre><span style="color: #ff0000;"><em>user nobody</em></span>
<span style="color: #ff0000;"><em>group nobody</em></span></pre>
<p><img loading="lazy" decoding="async" width="342" height="52" class="wp-image-6236" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-29.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-29.png 342w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-29-300x46.png 300w" sizes="auto, (max-width: 342px) 100vw, 342px" /></p>
<p><strong>Sauvegarder le fichier et sortir.</strong></p>
<h4><span style="color: #000000;"><strong>13°) Configure partie réseau</strong></span></h4>
<p><strong>Activer le forward « ipv4 »</strong></p>
<pre>[root@open-servervpn server]# <span style="color: #ff0000;">echo "net.ipv4.ip_forward=1" &gt;&gt; /etc/sysctl.conf</span>
[root@open-servervpn server]# <span style="color: #ff0000;">sysctl -p</span></pre>
<p><img loading="lazy" decoding="async" width="539" height="117" class="wp-image-6237" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-30.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-30.png 539w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-30-300x65.png 300w" sizes="auto, (max-width: 539px) 100vw, 539px" /></p>
<p><strong>Régles Firewall</strong></p>
<pre>[root@open-servervpn server]# <span style="color: #ff0000;">firewall-cmd --set-default-zone=trusted</span>
[root@open-servervpn server]# <span style="color: #ff0000;">firewall-cmd --add-masquerade --permanent</span>
[root@open-servervpn server]# <span style="color: #ff0000;">firewall-cmd --add-service=openvpn --permanent</span>
[root@open-servervpn server]# <span style="color: #ff0000;">firewall-cmd --reload</span></pre>
<p><img loading="lazy" decoding="async" width="701" height="155" class="wp-image-6238" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-31.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-31.png 701w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-31-300x66.png 300w" sizes="auto, (max-width: 701px) 100vw, 701px" /></p>
<pre>[root@open-servervpn server]# <span style="color: #ff0000;">firewall-cmd --list-all</span></pre>
<p><img loading="lazy" decoding="async" width="605" height="250" class="wp-image-6239" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-32.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-32.png 605w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-32-300x124.png 300w" sizes="auto, (max-width: 605px) 100vw, 605px" /></p>
<h4><span style="color: #000000;"><strong>14°) Lancement OpenVPN serveur</strong></span></h4>
<p><strong>Désactivation SELinux</strong></p>
<pre>[root@open-servervpn server]# <span style="color: #ff0000;">getenforce</span>
<em><span style="color: #ff0000;">Enforcing</span> </em>

[root@open-servervpn server]# <span style="color: #ff0000;">setenforce 0</span></pre>
<pre>[root@open-servervpn server]# <span style="color: #ff0000;">vi /etc/sysconfig/selinux</span>
<span style="color: #ff0000;"><em>SELINUX=disabled</em></span></pre>
<p><strong>Test de la config</strong></p>
<pre>[root@open-servervpn server]# <span style="color: #ff0000;">openvpn --config server.conf</span></pre>
<p><img loading="lazy" decoding="async" width="1300" height="289" class="wp-image-6240" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-33.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-33.png 1300w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-33-300x67.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-33-1024x228.png 1024w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-33-768x171.png 768w" sizes="auto, (max-width: 1300px) 100vw, 1300px" /><br />
«&nbsp;<strong>CTR+C pour sortir&nbsp;</strong>»</p>
<p><strong>Lancement du service</strong></p>
<pre>[root@open-servervpn server]# <span style="color: #ff0000;">systemctl enable openvpn-server@server --now</span>
[root@open-servervpn server]# <span style="color: #ff0000;">systemctl status openvpn-server@server</span></pre>
<p><img loading="lazy" decoding="async" width="1569" height="418" class="wp-image-6241" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-34.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-34.png 1569w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-34-300x80.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-34-1024x273.png 1024w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-34-768x205.png 768w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-34-1536x409.png 1536w" sizes="auto, (max-width: 1569px) 100vw, 1569px" /></p>
<p><strong>Vérification du Tunnel</strong></p>
<pre>[root@open-servervpn server]# <span style="color: #ff0000;">ip addr</span></pre>
<p><img loading="lazy" decoding="async" width="1033" height="237" class="wp-image-6242" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-35.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-35.png 1033w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-35-300x69.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-35-1024x235.png 1024w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-35-768x176.png 768w" sizes="auto, (max-width: 1033px) 100vw, 1033px" /></p>
<h2 style="text-align: center;"><span style="color: #000000;">Installation OpenVPN Client RHEL 8</span></h2>
<h4><span style="color: #000000;"><strong>1°) Installation EPEL</strong></span></h4>
<pre>[root@open-client01 ~]# <span style="color: #ff0000;">dnf install -y epel-release</span></pre>
<h4><span style="color: #000000;"><strong>2°) Installation OpenVPN</strong></span></h4>
<pre>[root@open-client01 ~]# <span style="color: #ff0000;">dnf install -y openvpn</span></pre>
<h4><span style="color: #000000;"><strong>3°) Copie des certificats publics sur le client </strong></span></h4>
<h4><span style="text-decoration: underline;"><span style="color: #000000; text-decoration: underline;"><strong>Sur le serveur</strong></span></span></h4>
<p><strong>Cléf Public Autorité</strong></p>
<pre>[root@open-servervpn ~]#<span style="color: #ff0000;"> cd /etc/openvpn/pki</span>
[root@open-servervpn pki]# <span style="color: #ff0000;">scp ca.crt root@open-client01:/etc/openvpn/client/ca.crt</span></pre>
<p><img loading="lazy" decoding="async" width="1529" height="129" class="wp-image-6243" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-36.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-36.png 1529w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-36-300x25.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-36-1024x86.png 1024w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-36-768x65.png 768w" sizes="auto, (max-width: 1529px) 100vw, 1529px" /></p>
<h5><span style="text-decoration: underline; color: #000000;"><strong>Cléf Public Client </strong></span></h5>
<pre>[root@open-servervpn pki]# <span style="color: #ff0000;">cd issued/</span>
[root@open-servervpn issued]# <span style="color: #ff0000;">scp open-client01.crt <a style="color: #ff0000;" href="mailto:root@open-client01:/etc/openvpn/client/open-client01.crt">root@open-client01:/etc/openvpn/client/open-client01.crt</a></span></pre>
<p><img loading="lazy" decoding="async" width="1530" height="112" class="wp-image-6244" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-37.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-37.png 1530w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-37-300x22.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-37-1024x75.png 1024w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-37-768x56.png 768w" sizes="auto, (max-width: 1530px) 100vw, 1530px" /></p>
<h5><span style="text-decoration: underline;"><strong><span style="color: #000000; text-decoration: underline;">Cléf Privée Client</span> </strong></span></h5>
<pre>[root@open-servervpn issued]# <span style="color: #ff0000;">cd ../private/</span>
[root@open-servervpn private]# <span style="color: #ff0000;">scp open-client01.key root@open-client01:/etc/openvpn/client/open-client01.key</span></pre>
<p><img loading="lazy" decoding="async" width="1521" height="116" class="wp-image-6245" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-38.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-38.png 1521w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-38-300x23.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-38-1024x78.png 1024w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-38-768x59.png 768w" sizes="auto, (max-width: 1521px) 100vw, 1521px" /></p>
<h4><span style="text-decoration: underline; color: #000000;"><strong>Sur le Client </strong></span></h4>
<pre>[root@open-client01 ~]# <span style="color: #ff0000;">cd /etc/openvpn/client</span>
[root@open-client01 client]# <span style="color: #ff0000;">ls -al</span></pre>
<p><img loading="lazy" decoding="async" width="640" height="132" class="wp-image-6246" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-39.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-39.png 640w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-39-300x62.png 300w" sizes="auto, (max-width: 640px) 100vw, 640px" /></p>
<h4><span style="color: #000000;"><strong>4°) Configurer openvpn Client</strong></span></h4>
<pre>[root@open-client01 client]# <span style="color: #ff0000;">vi client.conf</span>

<span style="color: #ff0000;"><em>client</em></span>
<span style="color: #ff0000;"><em>dev tun</em></span>
<span style="color: #ff0000;"><em>proto udp</em></span>
<span style="color: #ff0000;"><em>remote <strong>open-servervpn</strong></em></span>
<span style="color: #ff0000;"><em>port <strong>1194</strong></em></span>
<strong><span style="color: #ff0000;"><em>ca ca.crt</em></span></strong>
<strong><span style="color: #ff0000;"><em>cert open-client01.crt</em></span></strong>
<strong><span style="color: #ff0000;"><em>key open-client01.key</em></span></strong>
<span style="color: #ff0000;"><em>verb 5</em></span>
<span style="color: #ff0000;"><em>remote-cert-tls server</em></span>
<span style="color: #ff0000;"><em>auth-nocache</em></span>
<span style="color: #ff0000;"><em>cipher AES-256-CBC</em></span></pre>
<p><img loading="lazy" decoding="async" width="552" height="230" class="wp-image-6247" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-40.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-40.png 552w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-40-300x125.png 300w" sizes="auto, (max-width: 552px) 100vw, 552px" /></p>
<h4><span style="color: #000000;"><strong>5°) Lancement OpenVPN client «&nbsp;open-client01&nbsp;»</strong></span></h4>
<p><strong>Test de la config</strong></p>
<pre>[root@open-client01 client]# <span style="color: #ff0000;">openvpn --config client.conf</span></pre>
<p><img loading="lazy" decoding="async" width="1387" height="643" class="wp-image-6248" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-41.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-41.png 1387w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-41-300x139.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-41-1024x475.png 1024w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-41-768x356.png 768w" sizes="auto, (max-width: 1387px) 100vw, 1387px" /></p>
<p><strong>Lancement du service</strong></p>
<pre>[root@open-client01 client]# <span style="color: #ff0000;">systemctl enable openvpn-client@client --now</span>
[root@open-client01 client]# <span style="color: #ff0000;">systemctl status openvpn-client@client</span></pre>
<p><img loading="lazy" decoding="async" width="1239" height="425" class="wp-image-6249" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-42.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-42.png 1239w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-42-300x103.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-42-1024x351.png 1024w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-42-768x263.png 768w" sizes="auto, (max-width: 1239px) 100vw, 1239px" /></p>
<p>[root@open-client01 client]#<span style="color: #ff0000;"> ip addr</span></p>
<p><img loading="lazy" decoding="async" width="1028" height="316" class="wp-image-6250" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-43.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-43.png 1028w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-43-300x92.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-43-1024x315.png 1024w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-43-768x236.png 768w" sizes="auto, (max-width: 1028px) 100vw, 1028px" /></p>
<p><strong>Côté log serveur</strong></p>
<p><img loading="lazy" decoding="async" width="1445" height="301" class="wp-image-6251" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-44.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-44.png 1445w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-44-300x62.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-44-1024x213.png 1024w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-44-768x160.png 768w" sizes="auto, (max-width: 1445px) 100vw, 1445px" /></p>
<h4><span style="color: #000000;"><strong>6°) Contrôle du Tunnel VPN </strong></span></h4>
<h4><span style="color: #000000;"><strong>Check du client open-client01 =&gt;&nbsp; open-servervpn via&nbsp; le réseau OpenVPN</strong></span></h4>
<pre>[root@open-servervpn private]# <span style="color: #ff0000;">ping -c 3 10.8.0.2</span></pre>
<p><img loading="lazy" decoding="async" width="653" height="168" class="wp-image-6252" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-45.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-45.png 653w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-45-300x77.png 300w" sizes="auto, (max-width: 653px) 100vw, 653px" /></p>
<h4><span style="color: #000000;">Check du server open-servervpn =&gt; copen-client01&nbsp; via le réseau OpenVPN</span></h4>
<pre>[root@open-client01 client]# <span style="color: #ff0000;">ping -c 3 10.8.0.1</span></pre>
<p><img loading="lazy" decoding="async" width="607" height="169" class="wp-image-6253" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-46.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-46.png 607w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-46-300x84.png 300w" sizes="auto, (max-width: 607px) 100vw, 607px" /></p>
<h4><span style="color: #000000;">Connexion du client open-client01 sur le serveur via le réseau OpenVPN</span></h4>
<pre>[root@open-client01 client]# <span style="color: #ff0000;">ssh root@10.8.0.1</span></pre>
<p><img loading="lazy" decoding="async" width="818" height="308" class="wp-image-6254" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-47.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-47.png 818w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-47-300x113.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-47-768x289.png 768w" sizes="auto, (max-width: 818px) 100vw, 818px" /></p>
<p>Views: 18</p>
<p>L’article <a href="https://coffeebreak.en-images.info/modop-installation-openvpn-easy-rsa3-client-serveur/">MODOP – Installation OpenVPN (Easy-RSA3) &#8211; Client/serveur</a> est apparu en premier sur <a href="https://coffeebreak.en-images.info">CoffeeBreak Info</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://coffeebreak.en-images.info/modop-installation-openvpn-easy-rsa3-client-serveur/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>MODOP – Bloquer/Débloquer Subnet IPv4 d’un pays sur firewall</title>
		<link>https://coffeebreak.en-images.info/modop-bloquer-debloquer-subnet-ipv4-dun-pays-sur-firewall/</link>
					<comments>https://coffeebreak.en-images.info/modop-bloquer-debloquer-subnet-ipv4-dun-pays-sur-firewall/#respond</comments>
		
		<dc:creator><![CDATA[chris]]></dc:creator>
		<pubDate>Sat, 05 Mar 2022 17:53:07 +0000</pubDate>
				<category><![CDATA[OS Linux]]></category>
		<category><![CDATA[RedHat/Centos Linux]]></category>
		<category><![CDATA[Sécurité]]></category>
		<category><![CDATA[Système]]></category>
		<category><![CDATA[Centos]]></category>
		<category><![CDATA[Firewall]]></category>
		<category><![CDATA[Linux]]></category>
		<category><![CDATA[Serveur]]></category>
		<guid isPermaLink="false">https://coffeebreak.en-images.info/?p=6079</guid>

					<description><![CDATA[<p>MODOP – Installation de règle Firewall pour bloquer un Pays sur vos serveurs Linux. Le but est de récupérer toutes les « range Subnet » pour un pays et les « set » dans le firewall afin de réaliser un « REJECT » de toute les demandes d’accès via ce pays. Le but est de filtrer toutes les requêtes provenant d’un pays pour mieux contrôler les accès à vos équipements. Dans certain contexte d’infrastructure , bloquer/Filtrer des sources d’IP est indispensable… surtout en ce moment avec les faits en UKRAINE .<br />
<b><font color="red">FREE UKRAINE</font></b></p>
<p>L’article <a href="https://coffeebreak.en-images.info/modop-bloquer-debloquer-subnet-ipv4-dun-pays-sur-firewall/">MODOP – Bloquer/Débloquer Subnet IPv4 d’un pays sur firewall</a> est apparu en premier sur <a href="https://coffeebreak.en-images.info">CoffeeBreak Info</a>.</p>
]]></description>
										<content:encoded><![CDATA[<h3><span style="text-decoration: underline; color: #000000;"><strong>La liste des Subnet/Country</strong></span></h3>
<ul>
<li><a href="https://www.ipdeny.com/ipblocks/">https://www.ipdeny.com/ipblocks/</a></li>
</ul>
<p><img loading="lazy" decoding="async" width="1291" height="808" class="wp-image-6080" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/03/word-image-25.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/03/word-image-25.png 1291w, https://coffeebreak.en-images.info/wp-content/uploads/2022/03/word-image-25-300x188.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2022/03/word-image-25-1024x641.png 1024w, https://coffeebreak.en-images.info/wp-content/uploads/2022/03/word-image-25-768x481.png 768w" sizes="auto, (max-width: 1291px) 100vw, 1291px" /></p>
<p>Dans notre exemple nous allons bannir l’ISLANDE d’accès sur un serveur VPS.</p>
<p><img loading="lazy" decoding="async" width="717" height="189" class="wp-image-6081" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/03/word-image-26.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/03/word-image-26.png 717w, https://coffeebreak.en-images.info/wp-content/uploads/2022/03/word-image-26-300x79.png 300w" sizes="auto, (max-width: 717px) 100vw, 717px" /></p>
<p>L’iso Code est : <strong>IS</strong> et ce pays possède <strong>136 Subnet</strong>.</p>
<ul>
<li><a href="https://www.ipdeny.com/ipblocks/data/countries/is.zone">https://www.ipdeny.com/ipblocks/data/countries/is.zone</a></li>
</ul>
<h4><strong><span style="color: #ff0000;">Pour la RUSSIE , l’ISO code est : ru <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/263a.png" alt="☺" class="wp-smiley" style="height: 1em; max-height: 1em;" /></span></strong></h4>
<p><img loading="lazy" decoding="async" width="531" height="371" class="wp-image-6082" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/03/word-image-27.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/03/word-image-27.png 531w, https://coffeebreak.en-images.info/wp-content/uploads/2022/03/word-image-27-300x210.png 300w" sizes="auto, (max-width: 531px) 100vw, 531px" /></p>
<p>Le but est donc d’ajouter au firewall les 136 block.</p>
<h3><span style="text-decoration: underline;"><span style="color: #000000;"><strong>Script BASH </strong></span></span></h3>
<pre>[root@vps-xxxxxxxx chris]# <span style="color: #ff0000;">vi Bannir_country.sh</span></pre>
<pre><span style="color: #ff0000;"><em>#!/bin/bash</em></span><br /><span style="color: #ff0000;"><em>PAYS_ISO=$1</em></span><br /><span style="color: #ff0000;"><em> echo "Ban IP of country $PAYS_ISO"</em></span><br /><span style="color: #ff0000;"><em>for IP in `wget -O - https://www.ipdeny.com/ipblocks/data/countries/"${PAYS_ISO[@]}".zone --no-check-certificate`</em></span><br /><span style="color: #ff0000;"><em> do</em></span><br /><span style="color: #ff0000;"><em> echo " Bloquer le range $IP"</em></span><br /><span style="color: #ff0000;"><strong><em>firewall-cmd --permanent --add-rich-rule="rule family='ipv4' source address='$IP' reject"</em></strong></span><br /><span style="color: #ff0000;"><em> done</em></span><br /><span style="color: #ff0000;"><em>firewall-cmd --reload</em></span></pre>
<pre>[root@vps-xxxxxxxx chris]# <span style="color: #ff0000;">chmod +x Bannir_country.sh</span></pre>
<h3><span style="text-decoration: underline; color: #000000;"><strong>Le principe du script </strong></span></h3>
<pre>[root@vps-xxxxxxxx chris]# <span style="color: #ff0000;">./Bannir_country.sh<strong> « ISO Country »</strong></span></pre>
<p>Je me connecte en VPN via l’ISLANDE pour accéder à mon serveur en France et se positionner comme un Islandais souhaitant se connecter sur le serveur Français.</p>
<p><img loading="lazy" decoding="async" width="1069" height="641" class="wp-image-6083" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/03/word-image-28.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/03/word-image-28.png 1069w, https://coffeebreak.en-images.info/wp-content/uploads/2022/03/word-image-28-300x180.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2022/03/word-image-28-1024x614.png 1024w, https://coffeebreak.en-images.info/wp-content/uploads/2022/03/word-image-28-768x461.png 768w" sizes="auto, (max-width: 1069px) 100vw, 1069px" /></p>
<p>Donc je suis en Islande et plus précisément à Keflavik.(Sans bouger de mon canapé <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/263a.png" alt="☺" class="wp-smiley" style="height: 1em; max-height: 1em;" /> )</p>
<p><img loading="lazy" decoding="async" width="1149" height="118" class="wp-image-6084" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/03/word-image-29.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/03/word-image-29.png 1149w, https://coffeebreak.en-images.info/wp-content/uploads/2022/03/word-image-29-300x31.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2022/03/word-image-29-1024x105.png 1024w, https://coffeebreak.en-images.info/wp-content/uploads/2022/03/word-image-29-768x79.png 768w" sizes="auto, (max-width: 1149px) 100vw, 1149px" /></p>
<p>Mon IP dans cette ville est « <strong>45.133.192.108</strong> »</p>
<p><img loading="lazy" decoding="async" width="1021" height="255" class="wp-image-6085" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/03/word-image-30.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/03/word-image-30.png 1021w, https://coffeebreak.en-images.info/wp-content/uploads/2022/03/word-image-30-300x75.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2022/03/word-image-30-768x192.png 768w" sizes="auto, (max-width: 1021px) 100vw, 1021px" /></p>
<h3><span style="text-decoration: underline;"><span style="color: #000000;"><strong>Lancement du script boquant l’Islande sur le Serveur </strong></span></span></h3>
<pre>[root@vps-xxxxxxxx chris]# <span style="color: #ff0000;">./Bannir_country.sh <strong>is</strong></span></pre>
<p><strong><img loading="lazy" decoding="async" width="1381" height="479" class="wp-image-6086" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/03/word-image-31.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/03/word-image-31.png 1381w, https://coffeebreak.en-images.info/wp-content/uploads/2022/03/word-image-31-300x104.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2022/03/word-image-31-1024x355.png 1024w, https://coffeebreak.en-images.info/wp-content/uploads/2022/03/word-image-31-768x266.png 768w" sizes="auto, (max-width: 1381px) 100vw, 1381px" /></strong></p>
<p><strong><img loading="lazy" decoding="async" width="1173" height="282" class="wp-image-6087" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/03/word-image-32.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/03/word-image-32.png 1173w, https://coffeebreak.en-images.info/wp-content/uploads/2022/03/word-image-32-300x72.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2022/03/word-image-32-1024x246.png 1024w, https://coffeebreak.en-images.info/wp-content/uploads/2022/03/word-image-32-768x185.png 768w" sizes="auto, (max-width: 1173px) 100vw, 1173px" /></strong></p>
<h3><span style="text-decoration: underline; color: #000000;"><strong>Check «Block » IP Islande (Côté serveur)</strong></span></h3>
<p>Mon IP de provenance est 45.133.192.108 vérifions que celle-ci est bien « Banni » par le Firewall.</p>
<pre>[root@vps-xxxxxxxx chris]# <span style="color: #ff0000;">firewall-cmd --list-rich-rules |grep<strong> 45.133</strong></span></pre>
<p><img loading="lazy" decoding="async" width="694" height="182" class="wp-image-6088" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/03/word-image-33.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/03/word-image-33.png 694w, https://coffeebreak.en-images.info/wp-content/uploads/2022/03/word-image-33-300x79.png 300w" sizes="auto, (max-width: 694px) 100vw, 694px" /></p>
<pre>[root@vps-xxxxxxxx chris]# <span style="color: #ff0000;">iptables -L &gt; liste_firewall</span><br />[root@vps-xxxxxxxx chris]# <span style="color: #ff0000;">cat liste_firewall |grep <strong>45.133</strong></span></pre>
<p><img loading="lazy" decoding="async" width="900" height="183" class="wp-image-6089" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/03/word-image-34.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/03/word-image-34.png 900w, https://coffeebreak.en-images.info/wp-content/uploads/2022/03/word-image-34-300x61.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2022/03/word-image-34-768x156.png 768w" sizes="auto, (max-width: 900px) 100vw, 900px" /></p>
<h3><span style="text-decoration: underline; color: #000000;"><strong>Check «Block » IP Islande (Côté client en ISLANDE)</strong></span></h3>
<p><strong><img loading="lazy" decoding="async" width="898" height="181" class="wp-image-6090" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/03/word-image-35.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/03/word-image-35.png 898w, https://coffeebreak.en-images.info/wp-content/uploads/2022/03/word-image-35-300x60.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2022/03/word-image-35-768x155.png 768w" sizes="auto, (max-width: 898px) 100vw, 898px" /></strong></p>
<p>L’accès Apache au site Français via l’ISLANDE</p>
<p><img loading="lazy" decoding="async" width="1369" height="560" class="wp-image-6091" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/03/word-image-36.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/03/word-image-36.png 1369w, https://coffeebreak.en-images.info/wp-content/uploads/2022/03/word-image-36-300x123.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2022/03/word-image-36-1024x419.png 1024w, https://coffeebreak.en-images.info/wp-content/uploads/2022/03/word-image-36-768x314.png 768w" sizes="auto, (max-width: 1369px) 100vw, 1369px" /></p>
<h3><span style="text-decoration: underline; color: #000000;"><strong>Débloquer le pays récemment « REJECT »</strong></span></h3>
<h4><span style="color: #000000;">Script BASH </span></h4>
<pre>[root@vps-xxxxxxxx chris]#<span style="color: #ff0000;"> touch Accept_country.sh</span><br />[root@vps-xxxxxxxx chris]# <span style="color: #ff0000;">vi Accept_country.sh</span></pre>
<pre><span style="color: #ff0000;"><em>#!/bin/bash</em></span><br /><span style="color: #ff0000;"><em>PAYS_ISO=$1</em></span><br /><span style="color: #ff0000;"><em> echo "Ban IP of country $PAYS_ISO"</em></span><br /><span style="color: #ff0000;"><em>for IP in `wget -O - https://www.ipdeny.com/ipblocks/data/countries/"${PAYS_ISO[@]}".zone --no-check-certificate`</em></span><br /><span style="color: #ff0000;"><em> do</em></span><br /><span style="color: #ff0000;"><em> echo " Bloquer le range $IP"</em></span><br /><span style="color: #ff0000;"><strong><em>firewall-cmd --permanent --remove-rich-rule="rule family='ipv4' source address='$IP' reject"</em></strong></span><br /><span style="color: #ff0000;"><em> done</em></span><br /><span style="color: #ff0000;"><em>firewall-cmd --reload</em></span></pre>
<pre>[root@vps-xxxxxxxx chris]# <span style="color: #ff0000;">chmod +x Accept_country.sh</span></pre>
<pre>[root@vps-xxxxxxxx chris]# <span style="color: #ff0000;">./Accept_country.sh <strong>is<br /></strong></span></pre>
<p><img loading="lazy" decoding="async" width="946" height="394" class="wp-image-6092" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/03/word-image-37.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/03/word-image-37.png 946w, https://coffeebreak.en-images.info/wp-content/uploads/2022/03/word-image-37-300x125.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2022/03/word-image-37-768x320.png 768w" sizes="auto, (max-width: 946px) 100vw, 946px" /></p>


<p></p>



<p></p>
<p>Views: 34</p><p>L’article <a href="https://coffeebreak.en-images.info/modop-bloquer-debloquer-subnet-ipv4-dun-pays-sur-firewall/">MODOP – Bloquer/Débloquer Subnet IPv4 d’un pays sur firewall</a> est apparu en premier sur <a href="https://coffeebreak.en-images.info">CoffeeBreak Info</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://coffeebreak.en-images.info/modop-bloquer-debloquer-subnet-ipv4-dun-pays-sur-firewall/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>MODOP – Autoriser connexions Distantes à MariaDB via SSL</title>
		<link>https://coffeebreak.en-images.info/modop-autoriser-connexions-distantes-a-mariadb-via-ssl/</link>
					<comments>https://coffeebreak.en-images.info/modop-autoriser-connexions-distantes-a-mariadb-via-ssl/#respond</comments>
		
		<dc:creator><![CDATA[chris]]></dc:creator>
		<pubDate>Tue, 09 Nov 2021 18:01:38 +0000</pubDate>
				<category><![CDATA[Cluster Mysql/MariaDB]]></category>
		<category><![CDATA[RedHat/Centos Linux]]></category>
		<category><![CDATA[Sécurité]]></category>
		<category><![CDATA[Système]]></category>
		<category><![CDATA[Centos]]></category>
		<category><![CDATA[Linux]]></category>
		<category><![CDATA[Mysql]]></category>
		<category><![CDATA[Serveur]]></category>
		<guid isPermaLink="false">https://coffeebreak.en-images.info/?p=4715</guid>

					<description><![CDATA[<p>Ce MODOP décrit la mise en place d’une connexion SSL entre un client et un serveur de base de données MariaDB.<br />
Le but est de crypter toute transaction lorsque qu’un utilisateurs SSL, habilité et référencé, souhaite échanger des flux de données sur une base hébergée sur une machine serveur MariaDB distante.<br />
Il est fortement conseillé d’ajouter des certificats SSL pour communiquer entre client/serveur.  </p>
<p>L’article <a href="https://coffeebreak.en-images.info/modop-autoriser-connexions-distantes-a-mariadb-via-ssl/">MODOP – Autoriser connexions Distantes à MariaDB via SSL</a> est apparu en premier sur <a href="https://coffeebreak.en-images.info">CoffeeBreak Info</a>.</p>
]]></description>
										<content:encoded><![CDATA[<h3><span style="text-decoration: underline; color: #000000;"><strong>Serveur sqlss.house.cpb</strong></span></h3>
<p><strong>Installation TCPFlow</strong></p>
<pre>[root@sqlssl ~]# <span style="color: #ff0000;">dnf install wget</span>
[root@sqlssl ~]#<span style="color: #ff0000;"> dnf install wget <a style="color: #ff0000;" href="https://forensics.cert.org/cert-forensics-tools-release-el8.rpm">https://forensics.cert.org/cert-forensics-tools-release-el8.rpm</a></span>
[root@sqlssl ~]# <span style="color: #ff0000;">dnf install epel-release</span>
[root@sqlssl ~]# <span style="color: #ff0000;">dnf --enablerepo=forensics install tcpflow</span>
[root@sqlssl ~]# <span style="color: #ff0000;">tcpflow -c -p -i any dst port 3306</span></pre>
<h3><span style="text-decoration: underline; color: #000000;"><strong>Client Mysql sql-client.house.cpb</strong></span></h3>
<pre>[root@sql-client01 ~]# <span style="color: #ff0000;">mysql -u chris -p -h sqlssl</span></pre>
<p><img loading="lazy" decoding="async" width="603" height="172" class="wp-image-4717" src="https://coffeebreak.en-images.info/wp-content/uploads/2021/11/word-image-152.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2021/11/word-image-152.png 603w, https://coffeebreak.en-images.info/wp-content/uploads/2021/11/word-image-152-300x86.png 300w" sizes="auto, (max-width: 603px) 100vw, 603px" /><br />
mysql&gt; <span style="color: #ff0000;">select user,host from mysql.user;</span><br />
<img loading="lazy" decoding="async" width="435" height="155" class="wp-image-4718" src="https://coffeebreak.en-images.info/wp-content/uploads/2021/11/word-image-153.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2021/11/word-image-153.png 435w, https://coffeebreak.en-images.info/wp-content/uploads/2021/11/word-image-153-300x107.png 300w" sizes="auto, (max-width: 435px) 100vw, 435px" /></p>
<h3><span style="text-decoration: underline;"><span style="color: #000000;"><strong>Serveur sqlss.house.cpb</strong></span></span></h3>
<p><img loading="lazy" decoding="async" width="931" height="133" class="wp-image-4719" src="https://coffeebreak.en-images.info/wp-content/uploads/2021/11/word-image-154.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2021/11/word-image-154.png 931w, https://coffeebreak.en-images.info/wp-content/uploads/2021/11/word-image-154-300x43.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2021/11/word-image-154-768x110.png 768w" sizes="auto, (max-width: 931px) 100vw, 931px" /><br />
On remarque bien les flux de données en claire sur le réseau ce qui pose un réel souci de sécurité.<br />
On peut vérifier les paramètre SSL sur MariaDB</p>
<p>MariaDB [(none)]&gt; <span style="color: #ff0000;">show variables LIKE « %ssl% »;</span><br />
<img loading="lazy" decoding="async" width="502" height="234" class="wp-image-4720" src="https://coffeebreak.en-images.info/wp-content/uploads/2021/11/word-image-155.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2021/11/word-image-155.png 502w, https://coffeebreak.en-images.info/wp-content/uploads/2021/11/word-image-155-300x140.png 300w" sizes="auto, (max-width: 502px) 100vw, 502px" /><br />
MariaDB [(none)]&gt; <span style="color: #ff0000;">status</span><br />
<img loading="lazy" decoding="async" width="1002" height="335" class="wp-image-4721" src="https://coffeebreak.en-images.info/wp-content/uploads/2021/11/word-image-156.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2021/11/word-image-156.png 1002w, https://coffeebreak.en-images.info/wp-content/uploads/2021/11/word-image-156-300x100.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2021/11/word-image-156-768x257.png 768w" sizes="auto, (max-width: 1002px) 100vw, 1002px" /></p>
<p><strong>Création des répertoires des certificats </strong></p>
<pre>[root@sqlssl ~]# <span style="color: #ff0000;">mkdir -p /etc/mysql/newcerts/</span>
[root@sqlssl ~]# <span style="color: #ff0000;">cd /etc/mysql/newcerts/</span></pre>
<p><strong>Génération et auto-signature du Certificat d’autorité </strong></p>
<pre>[root@sqlssl newcerts]#<span style="color: #ff0000;"> openssl genrsa 4096 &gt; ca-key.pem</span></pre>
<p><img loading="lazy" decoding="async" width="478" height="97" class="wp-image-4722" src="https://coffeebreak.en-images.info/wp-content/uploads/2021/11/word-image-157.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2021/11/word-image-157.png 478w, https://coffeebreak.en-images.info/wp-content/uploads/2021/11/word-image-157-300x61.png 300w" sizes="auto, (max-width: 478px) 100vw, 478px" /></p>
<pre>[root@sqlssl newcerts]# <span style="color: #ff0000;">openssl req -new -x509 -nodes -days 3650 -key ca-key.pem -out ca-cert.pem</span></pre>
<p><img loading="lazy" decoding="async" width="812" height="237" class="wp-image-4723" src="https://coffeebreak.en-images.info/wp-content/uploads/2021/11/word-image-158.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2021/11/word-image-158.png 812w, https://coffeebreak.en-images.info/wp-content/uploads/2021/11/word-image-158-300x88.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2021/11/word-image-158-768x224.png 768w" sizes="auto, (max-width: 812px) 100vw, 812px" /></p>
<p><strong>Génération et auto-signature du Certificat serveur sqlssl.house.cpb</strong></p>
<pre>[root@sqlssl newcerts]# <span style="color: #ff0000;">openssl req -newkey rsa:4096 -days 365000 -nodes -keyout server-key.pem -out server-req.pem</span></pre>
<p><img loading="lazy" decoding="async" width="1196" height="387" class="wp-image-4724" src="https://coffeebreak.en-images.info/wp-content/uploads/2021/11/word-image-159.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2021/11/word-image-159.png 1196w, https://coffeebreak.en-images.info/wp-content/uploads/2021/11/word-image-159-300x97.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2021/11/word-image-159-1024x331.png 1024w, https://coffeebreak.en-images.info/wp-content/uploads/2021/11/word-image-159-768x249.png 768w" sizes="auto, (max-width: 1196px) 100vw, 1196px" /></p>
<pre>[root@sqlssl newcerts]#<span style="color: #ff0000;"> openssl rsa -in <strong>server-key.pem</strong> -out <strong>server-key.pem</strong></span></pre>
<p><span style="color: #ff0000;"><em>writing RSA key</em></span></p>
<pre>[root@sqlssl newcerts]# <span style="color: #ff0000;">openssl x509 -req -in <strong>server-req.pem</strong> -days 3650 -CA <strong>ca-cert.pem</strong> -CAkey <strong>ca-key.pem</strong> -set_serial 01 -out <strong>server-cert.pem</strong></span></pre>
<p><img loading="lazy" decoding="async" width="1042" height="120" class="wp-image-4725" src="https://coffeebreak.en-images.info/wp-content/uploads/2021/11/word-image-160.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2021/11/word-image-160.png 1042w, https://coffeebreak.en-images.info/wp-content/uploads/2021/11/word-image-160-300x35.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2021/11/word-image-160-1024x118.png 1024w, https://coffeebreak.en-images.info/wp-content/uploads/2021/11/word-image-160-768x88.png 768w" sizes="auto, (max-width: 1042px) 100vw, 1042px" /></p>
<p><strong>Certificats nécessaire à Mysql</strong><br />
[root@sqlssl newcerts]#<span style="color: #ff0000;"> ls -al</span><br />
<img loading="lazy" decoding="async" width="587" height="155" class="wp-image-4726" src="https://coffeebreak.en-images.info/wp-content/uploads/2021/11/word-image-161.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2021/11/word-image-161.png 587w, https://coffeebreak.en-images.info/wp-content/uploads/2021/11/word-image-161-300x79.png 300w" sizes="auto, (max-width: 587px) 100vw, 587px" /></p>
<p><strong>Installer les certificats dans Mysql</strong></p>
<pre>[root@sqlssl newcerts]#<span style="color: #ff0000;"> chmod 644 *</span>
[root@sqlssl newcerts]# <span style="color: #ff0000;">vi /etc/my.cnf</span></pre>
<pre><em>ssl-ca=/etc/mysql/newcerts/ca-cert.pem</em>
<em>ssl-cert=/etc/mysql/newcerts/server-cert.pem</em>
<em>ssl-key=/etc/mysql/newcerts/server-key.pem</em>
<em>ssl-cipher = ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-CHACHA20-POLY1305:ECDHE-RSA-CHACHA20-POLY1305:DHE-RSA-AES128-GCM-SHA256:DHE-RSA-AES256-GCM-SHA384</em></pre>
<p>[root@sqlssl newcerts]# <span style="color: #ff0000;">systemctl restart mysqld</span><br />
[root@sqlssl newcerts]# <span style="color: #ff0000;">mysql -u root -p</span></p>
<p>mysql&gt; <span style="color: #ff0000;">show variables LIKE « %ssl% »;</span><br />
<img loading="lazy" decoding="async" width="1623" height="429" class="wp-image-4727" src="https://coffeebreak.en-images.info/wp-content/uploads/2021/11/word-image-162.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2021/11/word-image-162.png 1623w, https://coffeebreak.en-images.info/wp-content/uploads/2021/11/word-image-162-300x79.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2021/11/word-image-162-1024x271.png 1024w, https://coffeebreak.en-images.info/wp-content/uploads/2021/11/word-image-162-768x203.png 768w, https://coffeebreak.en-images.info/wp-content/uploads/2021/11/word-image-162-1536x406.png 1536w" sizes="auto, (max-width: 1623px) 100vw, 1623px" /></p>
<p><strong>Création d’un utilisateur « chrisSSL@</strong> <strong>sqlssl-client.house.cpb » avec privlège SSL</strong><br />
mysql&gt; <span style="color: #ff0000;">CREATE USER « chrisSSL »@ »sql-client.house.cpb » IDENTIFIED BY « Votre_mot_de_passe »</span> <span style="color: #ff0000;">REQUIRE SSL;</span><br />
<span style="color: #ff0000;"><em>Query OK, 0 rows affected (0,02 sec)</em></span></p>
<p>mysql&gt; <span style="color: #ff0000;">GRANT SELECT, SHOW DATABASES ON *.* TO « chrisSSL »@ »sql-client.house.cpb » ;</span><br />
<span style="color: #ff0000;"><em>Query OK, 0 rows affected (0,01 sec)</em></span></p>
<p>mysql&gt; <span style="color: #ff0000;">FLUSH PRIVILEGES;</span><br />
<span style="color: #ff0000;"><em>Query OK, 0 rows affected (0,00 sec)</em></span></p>
<p>mysql&gt; <span style="color: #ff0000;">select user,host,ssl_type from mysql.user;</span><br />
<img loading="lazy" decoding="async" width="626" height="181" class="wp-image-4728" src="https://coffeebreak.en-images.info/wp-content/uploads/2021/11/word-image-163.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2021/11/word-image-163.png 626w, https://coffeebreak.en-images.info/wp-content/uploads/2021/11/word-image-163-300x87.png 300w" sizes="auto, (max-width: 626px) 100vw, 626px" /></p>
<p><strong>Génération et auto-signature pour le client sql-client.house.cpb</strong></p>
<pre>[root@sqlssl newcerts]# <span style="color: #ff0000;">openssl req -newkey rsa:2048 -days 3650 -nodes -keyout <strong>client-key.pem</strong> -out <strong>client-req.pem</strong></span></pre>
<p><img loading="lazy" decoding="async" width="1052" height="404" class="wp-image-4729" src="https://coffeebreak.en-images.info/wp-content/uploads/2021/11/word-image-164.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2021/11/word-image-164.png 1052w, https://coffeebreak.en-images.info/wp-content/uploads/2021/11/word-image-164-300x115.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2021/11/word-image-164-1024x393.png 1024w, https://coffeebreak.en-images.info/wp-content/uploads/2021/11/word-image-164-768x295.png 768w" sizes="auto, (max-width: 1052px) 100vw, 1052px" /></p>
<pre>[root@sqlssl newcerts]# <span style="color: #ff0000;">openssl rsa -in <strong>client-key.pem</strong> -out <strong>client-key.pem</strong></span>
<span style="color: #ff0000;"><em>writing RSA key</em></span></pre>
<pre>[root@sqlssl newcerts]# <span style="color: #ff0000;">openssl x509 -req -in<strong> client-req.pem</strong> -days 3650 -CA <strong>ca-cert.pem</strong> -CAkey <strong>ca-key.pem</strong> -set_serial 01 -out <strong>client-cert.pem</strong></span></pre>
<p><img loading="lazy" decoding="async" width="1017" height="112" class="wp-image-4730" src="https://coffeebreak.en-images.info/wp-content/uploads/2021/11/word-image-165.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2021/11/word-image-165.png 1017w, https://coffeebreak.en-images.info/wp-content/uploads/2021/11/word-image-165-300x33.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2021/11/word-image-165-768x85.png 768w" sizes="auto, (max-width: 1017px) 100vw, 1017px" /></p>
<p><strong>Copie des certificats clients à vos/votre client(s)</strong></p>
<pre>[root@sqlssl newcerts]# <span style="color: #ff0000;">scp ca-cert.pem root@sql-client:/etc/ssl/certs/</span>
[root@sqlssl newcerts]# <span style="color: #ff0000;">scp client-cert.pem root@sql-client:/etc/ssl/certs/</span>
[root@sqlssl newcerts]# <span style="color: #ff0000;">scp client-key.pem root@sql-client:/etc/ssl/certs/</span></pre>
<p><img loading="lazy" decoding="async" width="1610" height="144" class="wp-image-4731" src="https://coffeebreak.en-images.info/wp-content/uploads/2021/11/word-image-166.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2021/11/word-image-166.png 1610w, https://coffeebreak.en-images.info/wp-content/uploads/2021/11/word-image-166-300x27.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2021/11/word-image-166-1024x92.png 1024w, https://coffeebreak.en-images.info/wp-content/uploads/2021/11/word-image-166-768x69.png 768w, https://coffeebreak.en-images.info/wp-content/uploads/2021/11/word-image-166-1536x137.png 1536w" sizes="auto, (max-width: 1610px) 100vw, 1610px" /></p>
<h3><span style="text-decoration: underline;"><span style="color: #000000; text-decoration: underline;">CLIENT sql-client.house.cpb</span></span></h3>
<p><strong>Ajout des certificats à Mysql </strong></p>
<pre>[root@sqlssl-client ~]# <span style="color: #ff0000;">cd /etc/ssl/certs/</span>
[root@sqlssl-client certs]# <span style="color: #ff0000;">chmod 644 *.pem</span>
[root@sqlssl-client certs]# <span style="color: #ff0000;">la -al</span></pre>
<p><img loading="lazy" decoding="async" width="1008" height="167" class="wp-image-4732" src="https://coffeebreak.en-images.info/wp-content/uploads/2021/11/word-image-167.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2021/11/word-image-167.png 1008w, https://coffeebreak.en-images.info/wp-content/uploads/2021/11/word-image-167-300x50.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2021/11/word-image-167-768x127.png 768w" sizes="auto, (max-width: 1008px) 100vw, 1008px" /></p>
<p><strong>Connexion en spécifiant les certificats en ligne de commande</strong></p>
<pre>[root@sqlssl-client certs]# <span style="color: #ff0000;">mysql --ssl-ca=<strong>ca-cert.pem</strong> --ssl-cert=<strong>client-cert.pem</strong> --ssl-key=<strong>client-key.pem</strong> -h sqlssl -u chrisSSL -p</span></pre>
<p><img loading="lazy" decoding="async" width="1272" height="179" class="wp-image-4733" src="https://coffeebreak.en-images.info/wp-content/uploads/2021/11/word-image-168.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2021/11/word-image-168.png 1272w, https://coffeebreak.en-images.info/wp-content/uploads/2021/11/word-image-168-300x42.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2021/11/word-image-168-1024x144.png 1024w, https://coffeebreak.en-images.info/wp-content/uploads/2021/11/word-image-168-768x108.png 768w" sizes="auto, (max-width: 1272px) 100vw, 1272px" /></p>
<p>mysql&gt; <span style="color: #ff0000;">select user,host from mysql.user;</span><br />
<img loading="lazy" decoding="async" width="590" height="207" class="wp-image-4734" src="https://coffeebreak.en-images.info/wp-content/uploads/2021/11/word-image-169.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2021/11/word-image-169.png 590w, https://coffeebreak.en-images.info/wp-content/uploads/2021/11/word-image-169-300x105.png 300w" sizes="auto, (max-width: 590px) 100vw, 590px" /></p>
<p><strong>Côté flux serveur</strong><br />
<img loading="lazy" decoding="async" width="1629" height="401" class="wp-image-4735" src="https://coffeebreak.en-images.info/wp-content/uploads/2021/11/word-image-170.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2021/11/word-image-170.png 1629w, https://coffeebreak.en-images.info/wp-content/uploads/2021/11/word-image-170-300x74.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2021/11/word-image-170-1024x252.png 1024w, https://coffeebreak.en-images.info/wp-content/uploads/2021/11/word-image-170-768x189.png 768w, https://coffeebreak.en-images.info/wp-content/uploads/2021/11/word-image-170-1536x378.png 1536w" sizes="auto, (max-width: 1629px) 100vw, 1629px" /><br />
Toutes les transactions sont désormais cryptées entre le client et le serveur.</p>
<p>mysql&gt; <span style="color: #ff0000;">status</span><br />
<img loading="lazy" decoding="async" width="974" height="345" class="wp-image-4736" src="https://coffeebreak.en-images.info/wp-content/uploads/2021/11/word-image-171.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2021/11/word-image-171.png 974w, https://coffeebreak.en-images.info/wp-content/uploads/2021/11/word-image-171-300x106.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2021/11/word-image-171-768x272.png 768w" sizes="auto, (max-width: 974px) 100vw, 974px" /></p>
<p><strong>Ajouter les clefs sur le fichier client my.cnf</strong></p>
<pre>[root@sqlssl-client certs]# <span style="color: #ff0000;">vi /etc/my.cnf.d/client.cnf</span></pre>
<pre><em>[client]</em>
<em>ssl-ca=/etc/ssl/certs/ca-cert.pem</em>
<em>ssl-cert=/etc/ssl/certs/client-cert.pem</em>
<em>ssl-key=/etc/ssl/certs/client-key.pem</em></pre>
<p>[root@sql-client certs]# <span style="color: #ff0000;">mysql -h sqlssl -u chrisSSL -p</span><br />
<img loading="lazy" decoding="async" width="692" height="233" class="wp-image-4737" src="https://coffeebreak.en-images.info/wp-content/uploads/2021/11/word-image-172.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2021/11/word-image-172.png 692w, https://coffeebreak.en-images.info/wp-content/uploads/2021/11/word-image-172-300x101.png 300w" sizes="auto, (max-width: 692px) 100vw, 692px" /></p>
<p><strong>Côté serveur </strong><br />
<img loading="lazy" decoding="async" width="1638" height="302" class="wp-image-4738" src="https://coffeebreak.en-images.info/wp-content/uploads/2021/11/word-image-173.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2021/11/word-image-173.png 1638w, https://coffeebreak.en-images.info/wp-content/uploads/2021/11/word-image-173-300x55.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2021/11/word-image-173-1024x189.png 1024w, https://coffeebreak.en-images.info/wp-content/uploads/2021/11/word-image-173-768x142.png 768w, https://coffeebreak.en-images.info/wp-content/uploads/2021/11/word-image-173-1536x283.png 1536w" sizes="auto, (max-width: 1638px) 100vw, 1638px" /></p>
<p><strong>Sur le Client</strong><br />
<img loading="lazy" decoding="async" width="1157" height="576" class="wp-image-4739" src="https://coffeebreak.en-images.info/wp-content/uploads/2021/11/word-image-174.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2021/11/word-image-174.png 1157w, https://coffeebreak.en-images.info/wp-content/uploads/2021/11/word-image-174-300x149.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2021/11/word-image-174-1024x510.png 1024w, https://coffeebreak.en-images.info/wp-content/uploads/2021/11/word-image-174-768x382.png 768w" sizes="auto, (max-width: 1157px) 100vw, 1157px" /></p>
<p><strong>Sur le Serveur</strong><br />
<img loading="lazy" decoding="async" width="899" height="169" class="wp-image-4740" src="https://coffeebreak.en-images.info/wp-content/uploads/2021/11/word-image-175.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2021/11/word-image-175.png 899w, https://coffeebreak.en-images.info/wp-content/uploads/2021/11/word-image-175-300x56.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2021/11/word-image-175-768x144.png 768w" sizes="auto, (max-width: 899px) 100vw, 899px" /></p>
<p>Views: 17</p>
<p>L’article <a href="https://coffeebreak.en-images.info/modop-autoriser-connexions-distantes-a-mariadb-via-ssl/">MODOP – Autoriser connexions Distantes à MariaDB via SSL</a> est apparu en premier sur <a href="https://coffeebreak.en-images.info">CoffeeBreak Info</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://coffeebreak.en-images.info/modop-autoriser-connexions-distantes-a-mariadb-via-ssl/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>MODOP – Installation rkhunter – Détection RootKIT</title>
		<link>https://coffeebreak.en-images.info/modop-installation-rkhunter-detection-rootkit/</link>
					<comments>https://coffeebreak.en-images.info/modop-installation-rkhunter-detection-rootkit/#respond</comments>
		
		<dc:creator><![CDATA[chris]]></dc:creator>
		<pubDate>Mon, 08 Nov 2021 11:10:45 +0000</pubDate>
				<category><![CDATA[Applications]]></category>
		<category><![CDATA[OS Linux]]></category>
		<category><![CDATA[RedHat/Centos Linux]]></category>
		<category><![CDATA[Sécurité]]></category>
		<category><![CDATA[Système]]></category>
		<category><![CDATA[Centos]]></category>
		<category><![CDATA[Linux]]></category>
		<category><![CDATA[Serveur]]></category>
		<guid isPermaLink="false">https://coffeebreak.en-images.info/?p=4639</guid>

					<description><![CDATA[<p>MODOP sur l’installation d’un « chasseur » de rootkit .<br />
Au même titre que les antivirus, rkhunter est en charge de scanner/détecter les rootkits, portes dérobées et exploits sur des machines. Il est en charge de veiller et alerter en cas de compromission de machine.<br />
Les check rootkit sont basés sur les rainbow table hash pour déceler une infection machine.</p>
<p>L’article <a href="https://coffeebreak.en-images.info/modop-installation-rkhunter-detection-rootkit/">MODOP – Installation rkhunter – Détection RootKIT</a> est apparu en premier sur <a href="https://coffeebreak.en-images.info">CoffeeBreak Info</a>.</p>
]]></description>
										<content:encoded><![CDATA[<h3><span style="color: #000000;"><strong>Installation de rkhunter</strong></span></h3>
<pre>[root@coffee chris]# <span style="color: #ff0000;">yum --enablerepo=epel -y install rkhunter</span>
[root@coffee chris]#<span style="color: #ff0000;"> rkhunter --versioncheck</span></pre>
<p><img loading="lazy" decoding="async" width="522" height="97" class="wp-image-4640" src="https://coffeebreak.en-images.info/wp-content/uploads/2021/11/word-image-113.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2021/11/word-image-113.png 522w, https://coffeebreak.en-images.info/wp-content/uploads/2021/11/word-image-113-300x56.png 300w" sizes="auto, (max-width: 522px) 100vw, 522px" /></p>
<h3><span style="color: #000000;"><strong>Configurer rkhunter</strong></span></h3>
<pre>[root@coffee chris]#<span style="color: #ff0000;"> vi /etc/sysconfig/rkhunter</span></pre>
<pre><em># System configuration file for Rootkit Hunter which</em>
<em># stores RPM system specifics for cron run, etc.</em>
<em>#</em>
<em># MAILTO= &lt;email address to send scan report&gt;</em>
<em># DIAG_SCAN= no - perform normal report scan</em>
<em># yes - perform detailed report scan</em>
<em># (includes application check)</em>
<em>MAILTO=</em><span style="color: #ff0000;"><strong><em>chris@en-images.info</em></strong></span>
<em>DIAG_SCAN=</em><span style="color: #ff0000;"><strong><em>yes</em></strong> </span></pre>
<h3><span style="color: #000000;"><strong>Update base rkhunter et porperties</strong></span></h3>
<pre>[root@coffee chris]# <span style="color: #ff0000;">rkhunter --update</span></pre>
<p><img loading="lazy" decoding="async" width="756" height="262" class="wp-image-4641" src="https://coffeebreak.en-images.info/wp-content/uploads/2021/11/word-image-114.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2021/11/word-image-114.png 756w, https://coffeebreak.en-images.info/wp-content/uploads/2021/11/word-image-114-300x104.png 300w" sizes="auto, (max-width: 756px) 100vw, 756px" /></p>
<pre>[root@coffee chris]#<span style="color: #ff0000;"> rkhunter --propupd</span></pre>
<p><img loading="lazy" decoding="async" width="492" height="65" class="wp-image-4642" src="https://coffeebreak.en-images.info/wp-content/uploads/2021/11/word-image-115.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2021/11/word-image-115.png 492w, https://coffeebreak.en-images.info/wp-content/uploads/2021/11/word-image-115-300x40.png 300w" sizes="auto, (max-width: 492px) 100vw, 492px" /></p>
<h3><span style="color: #000000;"><strong>Check Rootkit</strong></span></h3>
<pre>[root@coffee chris]#<span style="color: #ff0000;"> rkhunter --check --sk</span></pre>
<p><img loading="lazy" decoding="async" width="998" height="397" class="wp-image-4643" src="https://coffeebreak.en-images.info/wp-content/uploads/2021/11/word-image-116.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2021/11/word-image-116.png 998w, https://coffeebreak.en-images.info/wp-content/uploads/2021/11/word-image-116-300x119.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2021/11/word-image-116-768x306.png 768w" sizes="auto, (max-width: 998px) 100vw, 998px" /><br />
Il va check tous les binaires</p>
<p><img loading="lazy" decoding="async" width="931" height="543" class="wp-image-4644" src="https://coffeebreak.en-images.info/wp-content/uploads/2021/11/word-image-117.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2021/11/word-image-117.png 931w, https://coffeebreak.en-images.info/wp-content/uploads/2021/11/word-image-117-300x175.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2021/11/word-image-117-768x448.png 768w" sizes="auto, (max-width: 931px) 100vw, 931px" /><br />
Check des rootkit présent sur la machine</p>
<p><img loading="lazy" decoding="async" width="716" height="129" class="wp-image-4645" src="https://coffeebreak.en-images.info/wp-content/uploads/2021/11/word-image-118.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2021/11/word-image-118.png 716w, https://coffeebreak.en-images.info/wp-content/uploads/2021/11/word-image-118-300x54.png 300w" sizes="auto, (max-width: 716px) 100vw, 716px" /><br />
Check la partie réseau</p>
<p><img loading="lazy" decoding="async" width="1084" height="433" class="wp-image-4646" src="https://coffeebreak.en-images.info/wp-content/uploads/2021/11/word-image-119.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2021/11/word-image-119.png 1084w, https://coffeebreak.en-images.info/wp-content/uploads/2021/11/word-image-119-300x120.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2021/11/word-image-119-1024x409.png 1024w, https://coffeebreak.en-images.info/wp-content/uploads/2021/11/word-image-119-768x307.png 768w" sizes="auto, (max-width: 1084px) 100vw, 1084px" /><br />
Check le local hosts</p>
<p><img loading="lazy" decoding="async" width="951" height="311" class="wp-image-4647" src="https://coffeebreak.en-images.info/wp-content/uploads/2021/11/word-image-120.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2021/11/word-image-120.png 951w, https://coffeebreak.en-images.info/wp-content/uploads/2021/11/word-image-120-300x98.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2021/11/word-image-120-768x251.png 768w" sizes="auto, (max-width: 951px) 100vw, 951px" /><br />
Résumé des scans de fichier via rkhunter</p>
<h3><span style="color: #000000;"><strong>Automatiser le scan </strong></span></h3>
<pre>[root@coffee chris]# <span style="color: #ff0000;">vi /home/rkhunter.sh</span></pre>
<pre><em>#!/bin/sh</em>
<em>(</em>
<em>/usr/bin/rkhunter --versioncheck</em>
<em>/usr/bin/rkhunter --update</em>
<em>/usr/bin/rkhunter --cronjob --report-warnings-only</em>
<em>) | /bin/mail -s 'rkhunter Daily Scan Report (<span style="color: #ff0000;">coffeebrea</span>k)' <span style="color: #ff0000;">chris@en-images.info</span></em></pre>
<pre>[root@coffee chris]# <span style="color: #ff0000;">chmod +x /home/rkhunter.sh</span></pre>
<pre>[root@coffee chris]#<span style="color: #ff0000;"> vi /etc/rkhunter.conf</span>
<em>MAIL-ON-WARNING=&nbsp;"</em><span style="color: #ff0000;"><a style="color: #ff0000;" href="mailto:chris@en-images.info"><em>chris@en-images.info</em></a></span><em>"</em>
<em>MAIL_CMD=mail -s "[rkhunter] Warnings found for ${HOST_NAME}"</em>
<em>ALLOW_SSH_ROOT_USER=yes</em></pre>
<h3><span style="color: #000000;"><strong>Autoriser root Login SSH</strong></span></h3>
<pre>[root@coffee chris]# <span style="color: #ff0000;">vi /etc/ssh/sshd_config</span>
<span style="color: #ff0000;"><em>PermitRootLogin yes</em></span>
[root@coffee chris]# <span style="color: #ff0000;">systemctl reload sshd</span></pre>
<h3><span style="color: #000000;"><strong>Crontab tous les jours à 12H00</strong></span></h3>
<pre>[root@coffee chris]#<span style="color: #ff0000;"> systemctl start crond.service</span>
[root@coffee chris]# <span style="color: #ff0000;">systemctl enable crond.service</span></pre>
<pre>[root@coffee chris]# <span style="color: #ff0000;">crontab -e</span>
<span style="color: #ff0000;"><em># Tous les jours à 12H00</em></span>
<span style="color: #ff0000;"><em>00 12 * * * /usr/bin/sh /home/rkhunter.sh</em></span></pre>
<pre>[root@coffee chris]# <span style="color: #ff0000;">tail -f /var/log/rkhunter/rkhunter.log</span></pre>
<p><strong>Dans les logs </strong><br />
<img loading="lazy" decoding="async" width="1324" height="408" class="wp-image-4648" src="https://coffeebreak.en-images.info/wp-content/uploads/2021/11/word-image-121.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2021/11/word-image-121.png 1324w, https://coffeebreak.en-images.info/wp-content/uploads/2021/11/word-image-121-300x92.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2021/11/word-image-121-1024x316.png 1024w, https://coffeebreak.en-images.info/wp-content/uploads/2021/11/word-image-121-768x237.png 768w" sizes="auto, (max-width: 1324px) 100vw, 1324px" /><br />
<img loading="lazy" decoding="async" width="1370" height="435" class="wp-image-4649" src="https://coffeebreak.en-images.info/wp-content/uploads/2021/11/word-image-122.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2021/11/word-image-122.png 1370w, https://coffeebreak.en-images.info/wp-content/uploads/2021/11/word-image-122-300x95.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2021/11/word-image-122-1024x325.png 1024w, https://coffeebreak.en-images.info/wp-content/uploads/2021/11/word-image-122-768x244.png 768w" sizes="auto, (max-width: 1370px) 100vw, 1370px" /><br />
Check des rootKIT</p>
<p><img loading="lazy" decoding="async" width="1029" height="398" class="wp-image-4650" src="https://coffeebreak.en-images.info/wp-content/uploads/2021/11/word-image-123.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2021/11/word-image-123.png 1029w, https://coffeebreak.en-images.info/wp-content/uploads/2021/11/word-image-123-300x116.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2021/11/word-image-123-1024x396.png 1024w, https://coffeebreak.en-images.info/wp-content/uploads/2021/11/word-image-123-768x297.png 768w" sizes="auto, (max-width: 1029px) 100vw, 1029px" /><br />
Check TCP port RootKit</p>
<p><img loading="lazy" decoding="async" width="889" height="273" class="wp-image-4651" src="https://coffeebreak.en-images.info/wp-content/uploads/2021/11/word-image-124.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2021/11/word-image-124.png 889w, https://coffeebreak.en-images.info/wp-content/uploads/2021/11/word-image-124-300x92.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2021/11/word-image-124-768x236.png 768w" sizes="auto, (max-width: 889px) 100vw, 889px" /></p>
<h3><span style="color: #000000;"><strong>Mail Rapport de rootKIT </strong></span></h3>
<p><strong><img loading="lazy" decoding="async" width="1001" height="247" class="wp-image-4652" src="https://coffeebreak.en-images.info/wp-content/uploads/2021/11/word-image-125.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2021/11/word-image-125.png 1001w, https://coffeebreak.en-images.info/wp-content/uploads/2021/11/word-image-125-300x74.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2021/11/word-image-125-768x190.png 768w" sizes="auto, (max-width: 1001px) 100vw, 1001px" /></strong></p>
<h3><span style="color: #000000;"><strong>Message Mail «&nbsp;Infection&nbsp;» </strong></span></h3>
<p><strong><img loading="lazy" decoding="async" width="806" height="272" class="wp-image-4653" src="https://coffeebreak.en-images.info/wp-content/uploads/2021/11/word-image-126.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2021/11/word-image-126.png 806w, https://coffeebreak.en-images.info/wp-content/uploads/2021/11/word-image-126-300x101.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2021/11/word-image-126-768x259.png 768w" sizes="auto, (max-width: 806px) 100vw, 806px" /></strong></p>
<p>Views: 11</p>
<p>L’article <a href="https://coffeebreak.en-images.info/modop-installation-rkhunter-detection-rootkit/">MODOP – Installation rkhunter – Détection RootKIT</a> est apparu en premier sur <a href="https://coffeebreak.en-images.info">CoffeeBreak Info</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://coffeebreak.en-images.info/modop-installation-rkhunter-detection-rootkit/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>MODOP – Fail2ban &#8211; Surveiller/Protéger service SSH d’un VPS</title>
		<link>https://coffeebreak.en-images.info/modop-fail2ban-surveiller-proteger-service-ssh-dun-vps/</link>
					<comments>https://coffeebreak.en-images.info/modop-fail2ban-surveiller-proteger-service-ssh-dun-vps/#respond</comments>
		
		<dc:creator><![CDATA[chris]]></dc:creator>
		<pubDate>Sat, 07 Aug 2021 14:56:47 +0000</pubDate>
				<category><![CDATA[OS Linux]]></category>
		<category><![CDATA[RedHat/Centos Linux]]></category>
		<category><![CDATA[Sécurité]]></category>
		<category><![CDATA[WordPress]]></category>
		<category><![CDATA[Centos]]></category>
		<category><![CDATA[Fail2ban]]></category>
		<category><![CDATA[Linux]]></category>
		<category><![CDATA[Système]]></category>
		<category><![CDATA[VPS]]></category>
		<category><![CDATA[Wordpress]]></category>
		<guid isPermaLink="false">https://coffeebreak.en-images.info/?p=3783</guid>

					<description><![CDATA[<p>Mise en place de la surveillance des connexions SSH sur une machine VPS. Celle-ci est effectuée par l’application Fail2ban qui examine les connexions via le fichier LOG « secure ».<br />
Chaque tentative de connexion est « check » par fail2ban et si cela échoue à plusieurs reprises alors l’IP de l’invité est bloqué via le firewall de la machine Serveur.</p>
<p>L’article <a href="https://coffeebreak.en-images.info/modop-fail2ban-surveiller-proteger-service-ssh-dun-vps/">MODOP – Fail2ban &#8211; Surveiller/Protéger service SSH d’un VPS</a> est apparu en premier sur <a href="https://coffeebreak.en-images.info">CoffeeBreak Info</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p><img loading="lazy" decoding="async" class="aligncenter wp-image-3784" src="https://coffeebreak.en-images.info/wp-content/uploads/2021/08/word-image-36.png" alt="" width="2528" height="800" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2021/08/word-image-36.png 1792w, https://coffeebreak.en-images.info/wp-content/uploads/2021/08/word-image-36-300x95.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2021/08/word-image-36-1024x324.png 1024w, https://coffeebreak.en-images.info/wp-content/uploads/2021/08/word-image-36-768x243.png 768w, https://coffeebreak.en-images.info/wp-content/uploads/2021/08/word-image-36-1536x486.png 1536w" sizes="auto, (max-width: 2528px) 100vw, 2528px" /></p>
<h3><span style="text-decoration: underline;"><span style="color: #000000;"><strong>1° ) Installation de Fail2ban</strong></span></span></h3>
<pre>[root@vps-xxxxxxxxx chris]# <span style="color: #ff0000;"><strong>yum update</strong></span>
[root@vps-xxxxxxxxx chris]#<strong><span style="color: #ff0000;"> yum install fail2ban</span></strong></pre>
<h3><span style="text-decoration: underline;"><span style="color: #000000;"><strong>2°Configuration de fail2ban</strong></span></span></h3>
<pre>[root@vps-xxxxxxxxx chris]# <span style="color: #ff0000;"><strong>vi /etc/fail2ban/jail.d/sshd.local</strong></span>

<em>[DEFAULT]</em>
<em>bantime = 86400</em>
<em>findtime = 600</em>
<em>maxretry = 3</em>
<em>ignoreip = IP_votre_Server IP_Client_Admin</em>
<em>banaction = iptables-multiport</em>
<em>[sshd]</em>
<em>enabled = true</em></pre>
<p><strong>Configuration Fail2ban – SSH</strong></p>
<pre>[root@vps-xxxxxxxxx chris]# <strong><span style="color: #ff0000;">vi /etc/fail2ban/filter.d/sshd.conf</span></strong>

<em>before = paths-fedora.conf</em>
<em>destemail = </em><a href="mailto:fail2ban@house.cpb"><em>fail2ban@house.cpb</em></a>
<em>sender = </em><a href="mailto:vps@house.cpb"><em>vps@house.cpb</em></a>
<em>action = %(action_mwl)s</em></pre>
<h3><span style="text-decoration: underline; color: #000000;"><strong>3°) Démarrer le service Fail2ban</strong></span></h3>
<pre>[root@vps-xxxxxxxxx chris]#<span style="color: #ff0000;"><strong> systemctl start fail2ban &amp;&amp; systemctl enable fail2ban</strong></span>
[root@vps-xxxxxxxxx chris]# <span style="color: #ff0000;"><strong>systemctl status fail2ban</strong></span></pre>
<p><img loading="lazy" decoding="async" width="838" height="217" class="wp-image-3785" src="https://coffeebreak.en-images.info/wp-content/uploads/2021/08/word-image-37.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2021/08/word-image-37.png 838w, https://coffeebreak.en-images.info/wp-content/uploads/2021/08/word-image-37-300x78.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2021/08/word-image-37-768x199.png 768w" sizes="auto, (max-width: 838px) 100vw, 838px" /></p>
<h3><span style="text-decoration: underline;"><span style="color: #000000;"><strong>4°) Vérifier les premières connexions frauduleuses.(Assez rapide)</strong></span></span></h3>
<pre>[root@vps-xxxxxxxxx chris]# <span style="color: #ff0000;"><strong>grep 'sshd.*Failed password for' /var/log/secure | head -10</strong></span></pre>
<p><img loading="lazy" decoding="async" width="1009" height="169" class="wp-image-3786" src="https://coffeebreak.en-images.info/wp-content/uploads/2021/08/word-image-38.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2021/08/word-image-38.png 1009w, https://coffeebreak.en-images.info/wp-content/uploads/2021/08/word-image-38-300x50.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2021/08/word-image-38-768x129.png 768w" sizes="auto, (max-width: 1009px) 100vw, 1009px" /></p>
<p><strong>Les IP « BAN » via Fail2ban.log</strong></p>
<pre>[root@vps-xxxxxxxxx chris]# <span style="color: #ff0000;"><strong>tail -f /var/log/fail2ban.log</strong></span></pre>
<p><img loading="lazy" decoding="async" width="936" height="169" class="wp-image-3787" src="https://coffeebreak.en-images.info/wp-content/uploads/2021/08/word-image-39.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2021/08/word-image-39.png 936w, https://coffeebreak.en-images.info/wp-content/uploads/2021/08/word-image-39-300x54.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2021/08/word-image-39-768x139.png 768w" sizes="auto, (max-width: 936px) 100vw, 936px" /></p>
<p><strong>Côté Firewall</strong></p>
<pre>[root@vps-xxxxxxxxx chris]#<span style="color: #ff0000;"><strong> iptables -L f2b-sshd -n –v</strong></span></pre>
<p>Tous les bannis<br />
<img loading="lazy" decoding="async" width="1109" height="487" class="wp-image-3788" src="https://coffeebreak.en-images.info/wp-content/uploads/2021/08/word-image-40.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2021/08/word-image-40.png 1109w, https://coffeebreak.en-images.info/wp-content/uploads/2021/08/word-image-40-300x132.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2021/08/word-image-40-1024x450.png 1024w, https://coffeebreak.en-images.info/wp-content/uploads/2021/08/word-image-40-768x337.png 768w" sizes="auto, (max-width: 1109px) 100vw, 1109px" /></p>
<pre>[root@vps-xxxxxxxxx chris]#<span style="color: #ff0000;"><strong> iptables -S |grep f2b-sshd</strong></span></pre>
<p><img loading="lazy" decoding="async" width="792" height="484" class="wp-image-3789" src="https://coffeebreak.en-images.info/wp-content/uploads/2021/08/word-image-41.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2021/08/word-image-41.png 792w, https://coffeebreak.en-images.info/wp-content/uploads/2021/08/word-image-41-300x183.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2021/08/word-image-41-768x469.png 768w" sizes="auto, (max-width: 792px) 100vw, 792px" /></p>
<p><strong>Côté Jail de Fail2ban</strong></p>
<pre>[root@vps-xxxxxxxxx chris]# <span style="color: #ff0000;"><strong>fail2ban-client status sshd</strong></span></pre>
<p><img loading="lazy" decoding="async" width="1726" height="170" class="wp-image-3790" src="https://coffeebreak.en-images.info/wp-content/uploads/2021/08/word-image-42.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2021/08/word-image-42.png 1726w, https://coffeebreak.en-images.info/wp-content/uploads/2021/08/word-image-42-300x30.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2021/08/word-image-42-1024x101.png 1024w, https://coffeebreak.en-images.info/wp-content/uploads/2021/08/word-image-42-768x76.png 768w, https://coffeebreak.en-images.info/wp-content/uploads/2021/08/word-image-42-1536x151.png 1536w" sizes="auto, (max-width: 1726px) 100vw, 1726px" /></p>
<h3><span style="text-decoration: underline; color: #000000;"><strong>5°) Notifications</strong></span></h3>
<h3><img loading="lazy" decoding="async" width="1661" height="196" class="wp-image-3791" src="https://coffeebreak.en-images.info/wp-content/uploads/2021/08/word-image-43.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2021/08/word-image-43.png 1661w, https://coffeebreak.en-images.info/wp-content/uploads/2021/08/word-image-43-300x35.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2021/08/word-image-43-1024x121.png 1024w, https://coffeebreak.en-images.info/wp-content/uploads/2021/08/word-image-43-768x91.png 768w, https://coffeebreak.en-images.info/wp-content/uploads/2021/08/word-image-43-1536x181.png 1536w" sizes="auto, (max-width: 1661px) 100vw, 1661px" /><br />
<img loading="lazy" decoding="async" width="1886" height="432" class="wp-image-3792" src="https://coffeebreak.en-images.info/wp-content/uploads/2021/08/word-image-44.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2021/08/word-image-44.png 1886w, https://coffeebreak.en-images.info/wp-content/uploads/2021/08/word-image-44-300x69.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2021/08/word-image-44-1024x235.png 1024w, https://coffeebreak.en-images.info/wp-content/uploads/2021/08/word-image-44-768x176.png 768w, https://coffeebreak.en-images.info/wp-content/uploads/2021/08/word-image-44-1536x352.png 1536w" sizes="auto, (max-width: 1886px) 100vw, 1886px" /></h3>
<p>Views: 60</p>
<p>L’article <a href="https://coffeebreak.en-images.info/modop-fail2ban-surveiller-proteger-service-ssh-dun-vps/">MODOP – Fail2ban &#8211; Surveiller/Protéger service SSH d’un VPS</a> est apparu en premier sur <a href="https://coffeebreak.en-images.info">CoffeeBreak Info</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://coffeebreak.en-images.info/modop-fail2ban-surveiller-proteger-service-ssh-dun-vps/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
	</channel>
</rss>
