<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Archives des VPN - CoffeeBreak Info</title>
	<atom:link href="https://coffeebreak.en-images.info/tag/vpn/feed/" rel="self" type="application/rss+xml" />
	<link>https://coffeebreak.en-images.info/tag/vpn/</link>
	<description>Une petite pause :)</description>
	<lastBuildDate>Sun, 03 Jul 2022 11:28:33 +0000</lastBuildDate>
	<language>fr-FR</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.9.1</generator>

<image>
	<url>https://coffeebreak.en-images.info/wp-content/uploads/2021/07/cropped-Tasse_Cafe-scaled-1-32x32.jpg</url>
	<title>Archives des VPN - CoffeeBreak Info</title>
	<link>https://coffeebreak.en-images.info/tag/vpn/</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>MODOP – Installation Tunnel GRE/Ipsec &#8211; Host to Host</title>
		<link>https://coffeebreak.en-images.info/modop-installation-tunnel-gre-ipsec-host-to-host/</link>
					<comments>https://coffeebreak.en-images.info/modop-installation-tunnel-gre-ipsec-host-to-host/#respond</comments>
		
		<dc:creator><![CDATA[chris]]></dc:creator>
		<pubDate>Sun, 03 Jul 2022 11:24:20 +0000</pubDate>
				<category><![CDATA[OS Linux]]></category>
		<category><![CDATA[RedHat/Centos Linux]]></category>
		<category><![CDATA[Sécurité]]></category>
		<category><![CDATA[Système]]></category>
		<category><![CDATA[VPN]]></category>
		<category><![CDATA[Centos]]></category>
		<category><![CDATA[Linux]]></category>
		<category><![CDATA[RockyLinux]]></category>
		<category><![CDATA[Securité]]></category>
		<category><![CDATA[Serveur]]></category>
		<guid isPermaLink="false">https://coffeebreak.en-images.info/?p=6779</guid>

					<description><![CDATA[<p>MODOP d'une encapsulation de paquets de données chiffrés via les services GRE et IPSec. Nous reprenons le MODP précédent sur la mise en place d'un tunnel GRE pour lui appliquer<br />
une couche de chiffrement avec clés partagées (IPSec) .Ce chiffrement va permettre de sécuriser les communications entre les deux équipements .Néanmoins quand on interconnecte deux sites avec<br />
cette solution ,  il n’y a aucun moyen de restreindre individuellement les accès des machines en cas de compromission de clef.</p>
<p>L’article <a href="https://coffeebreak.en-images.info/modop-installation-tunnel-gre-ipsec-host-to-host/">MODOP – Installation Tunnel GRE/Ipsec &#8211; Host to Host</a> est apparu en premier sur <a href="https://coffeebreak.en-images.info">CoffeeBreak Info</a>.</p>
]]></description>
										<content:encoded><![CDATA[<h2 style="text-align: center;"><span style="color: #000000;">Installation de la machine tun-hosta.house.cpb – RockyLinux</span></h2>
<h3><span style="color: #000000;"><strong>Spécification de la machine tun-hosta.house.cpb</strong></span></h3>
<p>Host&nbsp;:&nbsp;<strong>tun-hosta.house.cpb</strong></p>
<ul>
<li><strong>IP&nbsp;:192.168.1.56</strong>
<ul>
<li>VIP&nbsp;:<strong><span style="color: #0000ff;"> 10.10.10.1/24</span></strong></li>
</ul>
</li>
<li>OS&nbsp;:&nbsp;<strong>RockyLinux</strong></li>
<li>vCPU&nbsp;: 2</li>
<li>DD&nbsp;: 8Go</li>
<li>Ram&nbsp;: 2Go</li>
</ul>
<h3><span style="color: #000000;"><strong>Mise à jour de la machine </strong></span></h3>
<pre>[root@tun-hosta ~]# <span style="color: #ff0000;">dnf update -y</span></pre>
<h3><span style="color: #000000;"><strong>TimeDate</strong></span></h3>
<pre>[root@tun-hosta ~]# <span style="color: #ff0000;">timedatectl set-timezone "Europe/Paris"</span></pre>
<h3><span style="color: #000000;"><strong>Ajouter les hosts (Si pas de DNS)</strong></span></h3>
<pre>[root@tun-hosta ~]# <span style="color: #ff0000;">echo "192.168.1.56 tun-hosta tun-hosta.house.cpb" &gt;&gt; /etc/hosts</span>
[root@tun-hosta ~]# <span style="color: #ff0000;">echo "172.16.185.140 tun-hostb tun-hostb.house.cpb" &gt;&gt; /etc/hosts</span>
[root@tun-hosta ~]# <span style="color: #ff0000;">echo "10.10.10.1 tunipsec-grea tunipsec-grea.house.cpb" &gt;&gt; /etc/hosts</span>
[root@tun-hosta ~]# <span style="color: #ff0000;">echo "10.10.10.2 tunipsec-greb tunipsec-greb.house.cpb" &gt;&gt; /etc/hosts</span></pre>
<h3><span style="color: #000000;"><strong>Installation epel</strong></span></h3>
<pre>[root@tun-hosta ~]# <span style="color: #ff0000;">dnf install epel-release</span></pre>
<h3><span style="color: #000000;"><strong>Chargement Module GRE &#8211; CLI</strong></span></h3>
<pre>[root@tun-hosta ~]# <span style="color: #ff0000;">lsmod | grep ip_gre</span>
[root@tun-hosta ~]# <span style="color: #ff0000;">modprobe ip_gre</span>
[root@tun-hosta ~]# <span style="color: #ff0000;">lsmod | grep ip_gre</span></pre>
<p><img decoding="async" width="448" height="77" class="wp-image-6781" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/07/word-image-6779-2.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/07/word-image-6779-2.png 448w, https://coffeebreak.en-images.info/wp-content/uploads/2022/07/word-image-6779-2-300x52.png 300w" sizes="(max-width: 448px) 100vw, 448px" /></p>
<h3><span style="color: #000000;"><strong>Chargement Module GRE – On BOOT</strong></span></h3>
<pre>[root@tun-hosta ~]# <span style="color: #ff0000;">echo ip_gre &gt;&gt; /etc/modules-load.d/tun.conf</span>
[root@tun-hosta ~]# <span style="color: #ff0000;">ls -al /etc/modules-load.d/tun.conf</span>
<span style="color: #ff0000;"><em>-rw-r--r--. 1 root root 7 19 juin 12:13 /etc/modules-load.d/tun.conf</em></span></pre>
<h3><span style="color: #000000;"><strong>Configuration Réseau Tunnel GRE</strong></span></h3>
<h4><span style="text-decoration: underline;"><span style="color: #000000; text-decoration: underline;">Création du Tunnel tun0</span></span></h4>
<pre><span style="color: #ff0000;"><span style="color: #000000;">[root@tun-hosta ~]#</span> ip tunnel add tun0 mode gre remote <strong>172.16.185.140</strong> local <strong>192.168.1.56</strong> ttl 255</span></pre>
<h4><span style="text-decoration: underline;"><span style="color: #000000; text-decoration: underline;">Activation de la connexion tun0</span></span></h4>
<pre>[root@tun-hosta ~]# <span style="color: #ff0000;">ip link set tun0 up</span></pre>
<h4><span style="text-decoration: underline;"><span style="color: #000000; text-decoration: underline;">Création de l’adresse VIP</span></span></h4>
<pre>[root@tun-hosta ~]# <span style="color: #ff0000;">ip addr add <strong>10.10.10.1/24</strong> dev tun0</span></pre>
<h3><span style="color: #000000;"><strong>Chargement Tun0 – On BOOT</strong></span></h3>
<pre>[root@tun-hosta ~]# <span style="color: #ff0000;">echo "ip tunnel add tun0 mode gre remote <strong>172.16.185.140</strong> local <strong>192.168.1.56</strong> ttl 255" &gt;&gt; /etc/rc.local</span>
[root@tun-hosta ~]# <span style="color: #ff0000;">echo "ip link set tun0 up" &gt;&gt; /etc/rc.local</span>
[root@tun-hosta ~]# <span style="color: #ff0000;">echo "ip addr add 10.10.10.1/24 dev tun0" &gt;&gt; /etc/rc.local</span>
[root@tun-hosta ~]# <span style="color: #ff0000;">chmod +x /etc/rc.local</span></pre>
<h4><span style="text-decoration: underline;"><span style="color: #000000; text-decoration: underline;">Check de la connexion tun0</span></span></h4>
<pre>[root@tun-hosta ~]# <span style="color: #ff0000;">nmcli connection</span></pre>
<p><img fetchpriority="high" decoding="async" width="573" height="90" class="wp-image-6782" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/07/word-image-6779-3.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/07/word-image-6779-3.png 573w, https://coffeebreak.en-images.info/wp-content/uploads/2022/07/word-image-6779-3-300x47.png 300w" sizes="(max-width: 573px) 100vw, 573px" /></p>
<pre>[root@tun-hosta ~]# <span style="color: #ff0000;">ip a show tun0</span></pre>
<p><img decoding="async" width="892" height="132" class="wp-image-6783" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/07/word-image-6779-4.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/07/word-image-6779-4.png 892w, https://coffeebreak.en-images.info/wp-content/uploads/2022/07/word-image-6779-4-300x44.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2022/07/word-image-6779-4-768x114.png 768w" sizes="(max-width: 892px) 100vw, 892px" /></p>
<h3><span style="color: #000000;"><strong>Activer le Forward IPv4</strong></span></h3>
<pre>[root@tun-hosta ~]# <span style="color: #ff0000;">echo "net.ipv4.ip_forward=1" &gt; /etc/sysctl.conf</span>
[root@tun-hosta ~]# <span style="color: #ff0000;">echo "net.ipv4.conf.default.send_redirects=0</span>
<span style="color: #ff0000;">" &gt; /etc/sysctl.conf</span>
[root@tun-hosta ~]# <span style="color: #ff0000;">echo "net.ipv4.conf.default.accept_redirects=0</span>
<span style="color: #ff0000;">" &gt; /etc/sysctl.conf</span>
[root@tun-hosta ~]# <span style="color: #ff0000;">sysctl -p</span></pre>
<h3><span style="color: #000000;"><strong>Activer/désactiver les rules Firewall GRE</strong></span></h3>
<pre>[root@tun-hosta ~]# <span style="color: #ff0000;">firewall-cmd --remove-service={dhcpv6-client,cockpit} –permanent</span>
[root@tun-hosta ~]# <span style="color: #ff0000;">firewall-cmd --permanent --add-interface=tun0</span>
[root@tun-hosta ~]# <span style="color: #ff0000;">firewall-cmd --permanent --direct --add-rule ipv4 filter INPUT 0 -p gre -j ACCEPT</span>
[root@tun-hosta ~]# <span style="color: #ff0000;">firewall-cmd --reload</span></pre>
<h2 style="text-align: center;"><span style="color: #000000;">Installation de la machine tun-hostb.house.cpb – AlmaLinux8</span></h2>
<h3><span style="color: #000000;"><strong>Spécification de la machine tun-hostb.house.cpb</strong></span></h3>
<p>Host&nbsp;:&nbsp;<strong>tun-hostb.house.cpb</strong></p>
<ul>
<li><strong>IP&nbsp;:172.16.185.140</strong>
<ul>
<li>VIP&nbsp;: <strong><span style="color: #0000ff;">10.10.10.2/24</span></strong></li>
</ul>
</li>
<li>OS&nbsp;:&nbsp;<strong>AlmaLinux</strong></li>
<li>vCPU&nbsp;: 2</li>
<li>DD&nbsp;: 8Go</li>
<li>Ram&nbsp;: 2Go</li>
</ul>
<h3><span style="color: #000000;"><strong>Mise à jour de la machine </strong></span></h3>
<pre>[root@tun-hostb ~]# <span style="color: #ff0000;">yum -y update</span></pre>
<h3><span style="color: #000000;"><strong>TimeDate</strong></span></h3>
<pre>[root@tun-hostb ~]# <span style="color: #ff0000;">timedatectl set-timezone "Europe/Paris"</span></pre>
<h3><span style="color: #000000;"><strong>Ajouter les hosts (Si pas de DNS)</strong></span></h3>
<pre>[root@tun-hostb ~]#<span style="color: #ff0000;"> echo "192.168.1.56 tun-hosta tun-hosta.house.cpb" &gt;&gt; /etc/hosts</span>
[root@tun-hostb ~]# <span style="color: #ff0000;">echo "172.16.185.140 tun-hostb tun-hostb.house.cpb" &gt;&gt; /etc/hosts</span>

[root@tun-hostb ~]# <span style="color: #ff0000;">echo "10.10.10.1 tunipsec-grea tunipsec-grea.house.cpb" &gt;&gt; /etc/hosts</span>
[root@tun-hostb ~]# <span style="color: #ff0000;">echo "10.10.10.2 tunipsec-greb tunipsec-greb.house.cpb" &gt;&gt; /etc/hosts</span></pre>
<h3><span style="color: #000000;"><strong>Chargement Module GRE &#8211; CLI</strong></span></h3>
<pre>[root@tun-hostb ~]# <span style="color: #ff0000;">lsmod | grep ip_gre</span>
[root@tun-hostb ~]# <span style="color: #ff0000;">modprobe ip_gre</span></pre>
<h3><span style="color: #000000;"><strong>Chargement Module GRE – On BOOT</strong></span></h3>
<pre>[root@tun-hostb ~]# <span style="color: #ff0000;">echo ip_gre &gt;&gt; /etc/modules-load.d/tun.conf</span></pre>
<h3><span style="color: #000000;"><strong>Configuration Réseau Tunnel GRE</strong></span></h3>
<h4><span style="text-decoration: underline;"><span style="color: #000000; text-decoration: underline;">Création de l’interface tun0</span></span></h4>
<pre>[root@tun-hostb ~]# <span style="color: #ff0000;">ip tunnel add tun0 mode gre remote <strong>192.168.1.56</strong> local <strong>172.16.185.140</strong> ttl 255</span></pre>
<h4><span style="text-decoration: underline;"><span style="color: #000000; text-decoration: underline;">Activation de la connexion tun0</span></span></h4>
<pre>[root@tun-hostb ~]# <span style="color: #ff0000;">ip link set tun0</span></pre>
<h4><span style="text-decoration: underline;"><span style="color: #000000; text-decoration: underline;">Création de l’adresse VIP</span></span></h4>
<pre>[root@tun-hostb ~]# <span style="color: #ff0000;">ip addr add <strong>10.10.10.2/24</strong> dev tun0</span></pre>
<h3><span style="color: #000000;"><strong>Chargement Tun0 – On BOOT</strong></span></h3>
<pre>[root@tun-hosta ~]# <span style="color: #ff0000;">echo "ip tunnel add tun0 mode gre remote <strong>192.168.1.56</strong> local <strong>172.16.185.140</strong> ttl 255" &gt;&gt; /etc/rc.local</span>
[root@tun-hosta ~]# <span style="color: #ff0000;">echo "ip link set tun0 up" &gt;&gt; /etc/rc.local</span>
[root@tun-hosta ~]# <span style="color: #ff0000;">echo "ip addr add <strong>10.10.10.2/24</strong> dev tun0" &gt;&gt; /etc/rc.local</span>
[root@tun-hosta ~]#<span style="color: #ff0000;"> chmod +x /etc/rc.local</span></pre>
<h4><span style="text-decoration: underline; color: #000000;">Check de la connexion tun0</span></h4>
<pre>[root@tun-hostb ~]# <span style="color: #ff0000;">ip a show tun0</span></pre>
<p><img loading="lazy" decoding="async" width="873" height="130" class="wp-image-6784" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/07/word-image-6779-5.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/07/word-image-6779-5.png 873w, https://coffeebreak.en-images.info/wp-content/uploads/2022/07/word-image-6779-5-300x45.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2022/07/word-image-6779-5-768x114.png 768w" sizes="auto, (max-width: 873px) 100vw, 873px" /></p>
<pre>[root@tun-hostb ~]# <span style="color: #ff0000;">nmcli connection</span></pre>
<p><img loading="lazy" decoding="async" width="574" height="85" class="wp-image-6785" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/07/word-image-6779-6.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/07/word-image-6779-6.png 574w, https://coffeebreak.en-images.info/wp-content/uploads/2022/07/word-image-6779-6-300x44.png 300w" sizes="auto, (max-width: 574px) 100vw, 574px" /></p>
<h3><span style="color: #000000;"><strong>Activer le Forward IPv4</strong></span></h3>
<pre>[root@tun-hostb ~]# <span style="color: #ff0000;">echo "net.ipv4.ip_forward=1" &gt; /etc/sysctl.conf</span>
[root@tun-hostb ~]# <span style="color: #ff0000;">echo "net.ipv4.conf.default.send_redirects=0</span>
<span style="color: #ff0000;">" &gt; /etc/sysctl.conf</span>
[root@tun-hostb ~]# <span style="color: #ff0000;">echo "net.ipv4.conf.default.accept_redirects=0</span>
<span style="color: #ff0000;">" &gt; /etc/sysctl.conf</span>
[root@tun-hostb ~]# <span style="color: #ff0000;">sysctl -p</span></pre>
<h3><span style="color: #000000;"><strong>Activer/désactiver les rules Firewall GRE</strong></span></h3>
<pre>[root@tun-hostb ~]# <span style="color: #ff0000;">firewall-cmd --remove-service=dhcpv6-client –permanent</span>
[root@tun-hostb ~]# <span style="color: #ff0000;">firewall-cmd --permanent --add-interface=tun0</span>
[root@tun-hostb ~]# <span style="color: #ff0000;">firewall-cmd --permanent --direct --add-rule ipv4 filter INPUT 0 -p gre -j ACCEPT</span>
[root@tun-hostb ~]# <span style="color: #ff0000;">firewall-cmd --reload</span></pre>
<h2><span style="color: #000000;">Check des flux réseaux Public et Tunnel</span></h2>
<h4><span style="text-decoration: underline;"><span style="color: #000000; text-decoration: underline;">Serveur tun-hosta</span></span></h4>
<pre>[root@tun-hosta ~]# <span style="color: #ff0000;">ping -c 3 tunipsec-grea</span></pre>
<p><img loading="lazy" decoding="async" width="621" height="91" class="wp-image-6786" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/07/word-image-6779-7.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/07/word-image-6779-7.png 621w, https://coffeebreak.en-images.info/wp-content/uploads/2022/07/word-image-6779-7-300x44.png 300w" sizes="auto, (max-width: 621px) 100vw, 621px" /></p>
<pre>[root@tun-hosta ~]# <span style="color: #ff0000;">ping -c 3 tunipsec-greb</span></pre>
<p><img loading="lazy" decoding="async" width="620" height="95" class="wp-image-6787" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/07/word-image-6779-8.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/07/word-image-6779-8.png 620w, https://coffeebreak.en-images.info/wp-content/uploads/2022/07/word-image-6779-8-300x46.png 300w" sizes="auto, (max-width: 620px) 100vw, 620px" /></p>
<h4><span style="color: #000000;">Serveur tun-hostb</span></h4>
<pre>[root@tun-hostb ~]# <span style="color: #ff0000;">ping -c 3 tunipsec-grea</span></pre>
<p><img loading="lazy" decoding="async" width="620" height="86" class="wp-image-6788" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/07/word-image-6779-9.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/07/word-image-6779-9.png 620w, https://coffeebreak.en-images.info/wp-content/uploads/2022/07/word-image-6779-9-300x42.png 300w" sizes="auto, (max-width: 620px) 100vw, 620px" /></p>
<pre>[root@tun-hostb ~]# <span style="color: #ff0000;">ping -c 3 tunipsec-greb</span></pre>
<p><img loading="lazy" decoding="async" width="622" height="89" class="wp-image-6789" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/07/word-image-6779-10.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/07/word-image-6779-10.png 622w, https://coffeebreak.en-images.info/wp-content/uploads/2022/07/word-image-6779-10-300x43.png 300w" sizes="auto, (max-width: 622px) 100vw, 622px" /></p>
<h2 style="text-align: center;"><span style="color: #000000;">Installation Ipsec sur le Tunnel tun0</span></h2>
<h3><span style="color: #000000;"><strong>Inventaire du réseau tun0/Machine</strong></span></h3>
<p>Host&nbsp;:&nbsp;<strong>tunipsec-grea.house.cpb</strong></p>
<ul>
<li><strong>IP tun0</strong> :<span style="color: #3366ff;"> <strong>10.10.10.1/24</strong></span></li>
</ul>
<p>Host&nbsp;:&nbsp;<strong>tunipsec-greb.house.cpb</strong></p>
<ul>
<li><strong>IP tun0</strong> : <span style="color: #3366ff;"><strong>10.10.10.2/24</strong></span></li>
</ul>
<h3 style="padding-left: 80px;"><span style="color: #000000;"><strong>Ipsec – Machine tunipsec-grea.house.cpb</strong></span></h3>
<h4><span style="text-decoration: underline;"><span style="color: #000000; text-decoration: underline;">Désactiver «&nbsp;rp_filter&nbsp;»</span></span></h4>
<pre>[root@tun-hosta ~]# <span style="color: #ff0000;">echo "net.ipv4.conf.all.rp_filter = 0" &gt;&gt; /etc/sysctl.d/50-libreswan.conf</span>
[root@tun-hosta ~]# <span style="color: #ff0000;">sysctl --system</span></pre>
<h4><span style="text-decoration: underline;"><span style="color: #000000; text-decoration: underline;">Installer libreswan</span></span></h4>
<pre><span style="color: #000000;">[root@tun-hosta ~]# <span style="color: #ff0000;">yum install libreswan</span></span></pre>
<h4><span style="text-decoration: underline;"><span style="color: #000000; text-decoration: underline;">Initialisation de la base NSS</span></span></h4>
<pre>[root@tun-hosta ~]# <span style="color: #ff0000;">systemctl stop ipsec</span>
[root@tun-hosta ~]# <span style="color: #ff0000;">rm -f /etc/ipsec.d/*db</span>
[root@tun-hosta ~]# <span style="color: #ff0000;">ls -al /etc/ipsec.d/</span></pre>
<p><img loading="lazy" decoding="async" width="518" height="121" class="wp-image-6790" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/07/word-image-6779-11.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/07/word-image-6779-11.png 518w, https://coffeebreak.en-images.info/wp-content/uploads/2022/07/word-image-6779-11-300x70.png 300w" sizes="auto, (max-width: 518px) 100vw, 518px" /></p>
<pre>[root@tun-hosta ~]# <span style="color: #ff0000;">ipsec initnss</span>
<span style="color: #ff0000;"><em>Initializing NSS database</em></span>

[root@tun-hosta ~]# <span style="color: #ff0000;">ls -al /etc/ipsec.d/</span></pre>
<p><img loading="lazy" decoding="async" width="468" height="124" class="wp-image-6791" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/07/word-image-6779-12.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/07/word-image-6779-12.png 468w, https://coffeebreak.en-images.info/wp-content/uploads/2022/07/word-image-6779-12-300x79.png 300w" sizes="auto, (max-width: 468px) 100vw, 468px" /></p>
<h4><span style="text-decoration: underline;"><span style="color: #000000; text-decoration: underline;">Ajouter les rules ipsec – firewall</span></span></h4>
<pre>[root@tun-hosta ~]# <span style="color: #ff0000;">firewall-cmd --add-service=ipsec --permanent &amp;&amp; firewall-cmd –reload</span></pre>
<h4><span style="text-decoration: underline;"><span style="color: #000000; text-decoration: underline;">Démarrer Ipsec</span></span></h4>
<pre>[root@tun-hosta ~]# <span style="color: #ff0000;">systemctl enable ipsec --now</span></pre>
<h4><span style="text-decoration: underline;"><span style="color: #000000; text-decoration: underline;">Génerer une clef RSA pour hosta</span></span></h4>
<pre>[root@tun-hosta ~]# <span style="color: #ff0000;">ipsec newhostkey</span>
<span style="color: #ff0000;"><em>Generated RSA key pair with CKAID e60a1b0aba69d1a0f7dfc055899db6597ef1996f was stored in the NSS database</em></span>
<span style="color: #ff0000;"><em>The public key can be displayed using</em><strong><em>: ipsec showhostkey --left --ckaid e60a1b0aba69d1a0f7dfc055899db6597ef1996f</em></strong></span>

[root@tun-hosta ~]# <span style="color: #ff0000;"><strong>ipsec showhostkey --left --ckaid e60a1b0aba69d1a0f7dfc055899db6597ef1996f</strong></span>
<span style="color: #00ff00;"><strong><em> # rsakey AwEAAdnx8</em><em> leftrsasigkey=0sAwEAAdnx8WIZbGxrPh+bSDWuKhFLY0oNuFs68lfBrxCCH5UeeWrf53HFYBFKHvbUWQdu6CykibfB1SuJkvIojDhZbeKQg0MqMU/0jT29kncPOI+ar6DYIu0yXUnlIOYwqJQwFAWAXBPLA4b2JsePKZJFcjtlryRaItfWxdkDH39aO/WlSjLu/fMrHv9tDixH7kMfU/n5dSw3iCwix8I+PgXhdOTMRJEdcWnZEprDPlITmIB3gYN7x166V8DXLpFzAIFzD67wuReeq3z7V4podnfsLKtM+484SSpOjnLD9hs1DVP6V1N6SLPDgWjNXEaDjBXYfllrJzGl62If9+DiRHzA3XQn7XDXAxqzoDKpW4IBMVo6EHzK5Lj/GgC1qvJdBJLf7kG7PIZEv6LvbdmTm4JxSTCDtEM3DOk9wWwDdn5A2N3JbD5rwsxsGRa+dDadYS/KUxrYcKVOmh6UAFcP3AOuTaESaBy44PSWnG7jK/z8Lv4iyUxNAQQc9iMcuuSUZANpPvdX5ze3QXkr/ny7qw==</em></strong></span></pre>
<p><em><img loading="lazy" decoding="async" width="1125" height="146" class="wp-image-6792" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/07/word-image-6779-13.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/07/word-image-6779-13.png 1125w, https://coffeebreak.en-images.info/wp-content/uploads/2022/07/word-image-6779-13-300x39.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2022/07/word-image-6779-13-1024x133.png 1024w, https://coffeebreak.en-images.info/wp-content/uploads/2022/07/word-image-6779-13-768x100.png 768w" sizes="auto, (max-width: 1125px) 100vw, 1125px" /></em></p>
<h3 style="padding-left: 80px;"><span style="color: #000000;"><strong>Ipsec – Machine tunipsec-greb.house.cpb</strong></span></h3>
<h4><span style="text-decoration: underline;"><span style="color: #000000; text-decoration: underline;">Désactiver «&nbsp;rp_filter&nbsp;»</span></span></h4>
<pre>[root@tun-hostb ~]# <span style="color: #ff0000;">echo "net.ipv4.conf.all.rp_filter = 0" &gt;&gt; /etc/sysctl.d/50-libreswan.conf</span>
[root@tun-hostb ~]# <span style="color: #ff0000;">sysctl --system</span></pre>
<h4><span style="text-decoration: underline;"><span style="color: #000000; text-decoration: underline;">Installer libreswan</span></span></h4>
<pre>[root@tun-hostb ~]# <span style="color: #ff0000;">yum install libreswan</span></pre>
<h4><span style="text-decoration: underline;"><span style="color: #000000; text-decoration: underline;">Initialisation de la base NSS</span></span></h4>
<pre>[root@tun-hostb ~]# <span style="color: #ff0000;">systemctl stop ipsec</span>
[root@tun-hostb ~]# <span style="color: #ff0000;">rm -f /etc/ipsec.d/*db</span>

[root@tun-hostb ~]# <span style="color: #ff0000;">ipsec initnss</span>
<span style="color: #ff0000;"><em>Initializing NSS database</em></span>

[root@tun-hostb ~]# <span style="color: #ff0000;">ls -al /etc/ipsec.d/</span></pre>
<p><img loading="lazy" decoding="async" width="484" height="130" class="wp-image-6793" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/07/word-image-6779-14.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/07/word-image-6779-14.png 484w, https://coffeebreak.en-images.info/wp-content/uploads/2022/07/word-image-6779-14-300x81.png 300w" sizes="auto, (max-width: 484px) 100vw, 484px" /></p>
<h4><span style="text-decoration: underline;"><span style="color: #000000; text-decoration: underline;">Ajouter les rules ipsec – firewall</span></span></h4>
<pre>[root@tun-hostb ~]# <span style="color: #ff0000;">firewall-cmd --add-service=ipsec --permanent &amp;&amp; firewall-cmd --reload</span></pre>
<h4><span style="text-decoration: underline;"><span style="color: #000000; text-decoration: underline;">Démarrer Ipsec</span></span></h4>
<pre>[root@tun-hostb ~]# <span style="color: #ff0000;">systemctl enable ipsec --now</span>
[root@tun-hostb ~]# <span style="color: #ff0000;">systemctl status ipsec</span></pre>
<p><img loading="lazy" decoding="async" width="1151" height="426" class="wp-image-6794" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/07/word-image-6779-15.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/07/word-image-6779-15.png 1151w, https://coffeebreak.en-images.info/wp-content/uploads/2022/07/word-image-6779-15-300x111.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2022/07/word-image-6779-15-1024x379.png 1024w, https://coffeebreak.en-images.info/wp-content/uploads/2022/07/word-image-6779-15-768x284.png 768w" sizes="auto, (max-width: 1151px) 100vw, 1151px" /></p>
<h4><span style="color: #000000;">Génerer une clef RSA pour hostb</span></h4>
<pre>[root@tun-hostb ~]# <span style="color: #ff0000;">ipsec newhostkey</span>
<span style="color: #ff0000;"><em>Generated RSA key pair with CKAID 2f5cd8184f8878367711840329cd53904c8fc117 was stored in the NSS database</em></span>
<span style="color: #ff0000;"><em>The public key can be displayed using: ipsec showhostkey --left --ckaid 2f5cd8184f8878367711840329cd53904c8fc117</em></span>

[root@tun-hostb ~]# <span style="color: #ff0000;">ipsec showhostkey --left --ckaid 2f5cd8184f8878367711840329cd53904c8fc117</span>
<strong><span style="color: #800080;"><em> # rsakey AwEAAengQ</em></span></strong>
<strong><span style="color: #800080;"><em>leftrsasigkey=0sAwEAAengQzda3EZwsJSqi9zaF3EtlMy09xN4T1u5/i0pmXzJGUe3A0qfOEG4zueQ3Cy7VstC4EwdrrPccYJf82k1jX2yjgIR8enWbprkI2fDWt0++/e/lxw8/6HNEo9V7hWCPMWqo9TWTwu2qM/kZJgylY538SYe+LTG1MmsWDhoF4ZqfedwDL85ZGpsGsBlaJPxH1TNcLn2lLf8sTNJO2I6br8rSQl1OAp1SawAoBgwxgHsCLvpAUhQCtFRTYjf3WayrtMvEgmKZjcrV5xlNR1jYDHOx6RLd6eu1JMR9k8JUwuNeeEbtoKqdNBQBia7jZMi0Cl9NpaWtdcvMFq533hbitS8kHvzDHpOu4wsr9RCwGyyWfSPQbJr5fbCMa942SAOWLLXHdo4/VHXRlogj3Fj23BP/e4giB5ARdxHQxreSxZLUewilgxQlM4GaGsSGCu49ZikoQf0Fm1hEVeIjwgpEa26lLCtQ+mGGWw+y59xlPa+2pZDLQt26fTUIVovCGzqgzzEAo7qOXpQ7A9A7yykcV1yQzkVKmpeUmt2FzLL1r91qnIGy3E1mdt0Rom2xI9gJrneGH/rWq4GtVNfEsv6TImJCRyd9FIjK4qnH+hTyT1uPTM28cfWs3mUmbqtSb8uPRe9WFq0i459Qzwz2BWB5pM=</em></span></strong></pre>
<h3><span style="color: #000000;"><strong>Création&nbsp; Ipsec Host-to-Host</strong></span></h3>
<h4><span style="text-decoration: underline;"><span style="color: #000000; text-decoration: underline;">Inventaire des Hosts de l&rsquo;infrastructure</span></span></h4>
<p>Host&nbsp;:&nbsp;<strong>tunipsec-grea.house.cpb</strong></p>
<ul>
<li><strong>IP tun0</strong> : <strong><span style="color: #0000ff;">10.10.10.1/24</span></strong></li>
<li><strong>RSA&nbsp;: <span style="color: #00ff00;"><em>0sAwEAAdnx8WIZbGxrPh+bSDWuKhFLY0oNuFs68lfBrxCCH5UeeWrf53HFYBFKHvbUWQdu6CykibfB1SuJkvIojDhZbeKQg0MqMU/0jT29kncPOI+ar6DYIu0yXUnlIOYwqJQwFAWAXBPLA4b2JsePKZJFcjtlryRaItfWxdkDH39aO/WlSjLu/fMrHv9tDixH7kMfU/n5dSw3iCwix8I+PgXhdOTMRJEdcWnZEprDPlITmIB3gYN7x166V8DXLpFzAIFzD67wuReeq3z7V4podnfsLKtM+484SSpOjnLD9hs1DVP6V1N6SLPDgWjNXEaDjBXYfllrJzGl62If9+DiRHzA3XQn7XDXAxqzoDKpW4IBMVo6EHzK5Lj/GgC1qvJdBJLf7kG7PIZEv6LvbdmTm4JxSTCDtEM3DOk9wWwDdn5A2N3JbD5rwsxsGRa+dDadYS/KUxrYcKVOmh6UAFcP3AOuTaESaBy44PSWnG7jK/z8Lv4iyUxNAQQc9iMcuuSUZANpPvdX5ze3QXkr/ny7qw==</em></span></strong></li>
</ul>
<p>Host&nbsp;:&nbsp;<strong>tunipsec-greb.house.cpb</strong></p>
<ul>
<li><strong>IP tun0</strong> : <strong><span style="color: #0000ff;">10.10.10.2/24</span></strong></li>
<li><strong>RSA&nbsp;:<span style="color: #800080;"><em> 0sAwEAAengQzda3EZwsJSqi9zaF3EtlMy09xN4T1u5/i0pmXzJGUe3A0qfOEG4zueQ3Cy7VstC4EwdrrPccYJf82k1jX2yjgIR8enWbprkI2fDWt0++/e/lxw8/6HNEo9V7hWCPMWqo9TWTwu2qM/kZJgylY538SYe+LTG1MmsWDhoF4ZqfedwDL85ZGpsGsBlaJPxH1TNcLn2lLf8sTNJO2I6br8rSQl1OAp1SawAoBgwxgHsCLvpAUhQCtFRTYjf3WayrtMvEgmKZjcrV5xlNR1jYDHOx6RLd6eu1JMR9k8JUwuNeeEbtoKqdNBQBia7jZMi0Cl9NpaWtdcvMFq533hbitS8kHvzDHpOu4wsr9RCwGyyWfSPQbJr5fbCMa942SAOWLLXHdo4/VHXRlogj3Fj23BP/e4giB5ARdxHQxreSxZLUewilgxQlM4GaGsSGCu49ZikoQf0Fm1hEVeIjwgpEa26lLCtQ+mGGWw+y59xlPa+2pZDLQt26fTUIVovCGzqgzzEAo7qOXpQ7A9A7yykcV1yQzkVKmpeUmt2FzLL1r91qnIGy3E1mdt0Rom2xI9gJrneGH/rWq4GtVNfEsv6TImJCRyd9FIjK4qnH+hTyT1uPTM28cfWs3mUmbqtSb8uPRe9WFq0i459Qzwz2BWB5pM=</em></span></strong></li>
</ul>
<h4><span style="text-decoration: underline;"><span style="color: #000000; text-decoration: underline;">Fichier de conf Ipsec sur hosta</span></span></h4>
<pre>[root@tun-hosta ~]# <span style="color: #ff0000;">vi /etc/ipsec.d/host_to_host.conf</span></pre>
<pre><span style="color: #ff0000;">conn tunnelVPN</span>
<span style="color: #ff0000;">leftid=@west</span>
<span style="color: #ff0000;">left=10.10.10.1</span>
<span style="color: #00ff00;"><strong>leftrsasigkey</strong>=0sAwEAAdnx8WIZbGxrPh+bSDWuKhFLY0oNuFs68lfBrxCCH5UeeWrf53HFYBFKHvbUWQdu6CykibfB1SuJkvIojDhZbeKQg0MqMU/0jT29kncPOI+ar6DYIu0yXUnlIOYwqJQwFAWAXBPLA4b2JsePKZJFcjtlryRaItfWxdkDH39aO/WlSjLu/fMrHv9tDixH7kMfU/n5dSw3iCwix8I+PgXhdOTMRJEdcWnZEprDPlITmIB3gYN7x166V8DXLpFzAIFzD67wuReeq3z7V4podnfsLKtM+484SSpOjnLD9hs1DVP6V1N6SLPDgWjNXEaDjBXYfllrJzGl62If9+DiRHzA3XQn7XDXAxqzoDKpW4IBMVo6EHzK5Lj/GgC1qvJdBJLf7kG7PIZEv6LvbdmTm4JxSTCDtEM3DOk9wWwDdn5A2N3JbD5rwsxsGRa+dDadYS/KUxrYcKVOmh6UAFcP3AOuTaESaBy44PSWnG7jK/z8Lv4iyUxNAQQc9iMcuuSUZANpPvdX5ze3QXkr/ny7qw==</span>
<span style="color: #ff0000;">rightid=@east</span>
<span style="color: #ff0000;">right=10.10.10.2</span>
<span style="color: #800080;"><strong>rightrsasigkey</strong>=0sAwEAAengQzda3EZwsJSqi9zaF3EtlMy09xN4T1u5/i0pmXzJGUe3A0qfOEG4zueQ3Cy7VstC4EwdrrPccYJf82k1jX2yjgIR8enWbprkI2fDWt0++/e/lxw8/6HNEo9V7hWCPMWqo9TWTwu2qM/kZJgylY538SYe+LTG1MmsWDhoF4ZqfedwDL85ZGpsGsBlaJPxH1TNcLn2lLf8sTNJO2I6br8rSQl1OAp1SawAoBgwxgHsCLvpAUhQCtFRTYjf3WayrtMvEgmKZjcrV5xlNR1jYDHOx6RLd6eu1JMR9k8JUwuNeeEbtoKqdNBQBia7jZMi0Cl9NpaWtdcvMFq533hbitS8kHvzDHpOu4wsr9RCwGyyWfSPQbJr5fbCMa942SAOWLLXHdo4/VHXRlogj3Fj23BP/e4giB5ARdxHQxreSxZLUewilgxQlM4GaGsSGCu49ZikoQf0Fm1hEVeIjwgpEa26lLCtQ+mGGWw+y59xlPa+2pZDLQt26fTUIVovCGzqgzzEAo7qOXpQ7A9A7yykcV1yQzkVKmpeUmt2FzLL1r91qnIGy3E1mdt0Rom2xI9gJrneGH/rWq4GtVNfEsv6TImJCRyd9FIjK4qnH+hTyT1uPTM28cfWs3mUmbqtSb8uPRe9WFq0i459Qzwz2BWB5pM=</span>
<span style="color: #ff0000;">authby=rsasig</span>
<span style="color: #ff0000;">auto=start</span></pre>
<h4><span style="text-decoration: underline;"><span style="color: #000000; text-decoration: underline;">Mise en place du Tunnel Ipsec hosta &#8211; l’encapsulation tun0</span></span></h4>
<pre>[root@<strong><span style="color: #ff0000;">tun-</span><span style="color: #ff0000;">hosta</span></strong> ~]# <span style="color: #ff0000;">systemctl restart ipsec</span>
[root@<strong><span style="color: #ff0000;">tun-hosta</span></strong> ~]# <span style="color: #ff0000;">ipsec auto --add tunnelVPN</span>
<span style="color: #ff0000;"><em>002 "tunnelVPN": added IKEv2 connection</em></span></pre>
<h4><span style="text-decoration: underline;"><span style="color: #000000; text-decoration: underline;">Fichier de conf Ipsec sur hostb</span></span></h4>
<pre>[root@<strong><span style="color: #ff0000;">tun-hosta</span></strong> ~]# <span style="color: #ff0000;">scp /etc/ipsec.d/host_to_host.conf <a style="color: #ff0000;" href="mailto:root@tun-hostb:/etc/ipsec.d/host_to_host.conf">root@tun-hostb:/etc/ipsec.d/host_to_host.conf</a></span>

[root@<strong><span style="color: #ff0000;">tun-hostb</span></strong> ~]# <span style="color: #ff0000;"><em>ls -al /etc/ipsec.d/host_to_host.conf</em></span>
<span style="color: #ff0000;"><em>-rw-r--r--. 1 root root 1335 Jun 19 18:00 /etc/ipsec.d/host_to_host.conf</em></span></pre>
<h4><span style="text-decoration: underline;"><span style="color: #000000; text-decoration: underline;">Mise en place du Tunnel Ipsec hostb &#8211; l’encapsulation tun0</span></span></h4>
<pre>[root@tun-hostb ~]# <span style="color: #ff0000;">systemctl restart ipsec</span>
[root@tun-hostb ~]#<span style="color: #ff0000;"> ipsec auto --add tunnelVPN</span>
<span style="color: #ff0000;"><em>002 "tunnelVPN": added IKEv2 connection</em></span></pre>
<p><img loading="lazy" decoding="async" width="440" height="65" class="wp-image-6795" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/07/word-image-6779-16.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/07/word-image-6779-16.png 440w, https://coffeebreak.en-images.info/wp-content/uploads/2022/07/word-image-6779-16-300x44.png 300w" sizes="auto, (max-width: 440px) 100vw, 440px" /></p>
<h4><span style="text-decoration: underline;"><span style="color: #000000; text-decoration: underline;">Monter le tunnelVPN sur les deux machines</span></span></h4>
<pre>[root@<strong><span style="color: #ff0000;">tun-hostb</span></strong> ~]# <span style="color: #ff0000;">ipsec auto --up tunnelVPN</span></pre>
<p><img loading="lazy" decoding="async" width="1608" height="136" class="wp-image-6796" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/07/word-image-6779-17.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/07/word-image-6779-17.png 1608w, https://coffeebreak.en-images.info/wp-content/uploads/2022/07/word-image-6779-17-300x25.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2022/07/word-image-6779-17-1024x87.png 1024w, https://coffeebreak.en-images.info/wp-content/uploads/2022/07/word-image-6779-17-768x65.png 768w, https://coffeebreak.en-images.info/wp-content/uploads/2022/07/word-image-6779-17-1536x130.png 1536w" sizes="auto, (max-width: 1608px) 100vw, 1608px" /></p>
<pre>[root@<strong><span style="color: #ff0000;">tun-hosta</span></strong> ~]# <span style="color: #ff0000;">ipsec auto --up tunnelVPN</span></pre>
<p><img loading="lazy" decoding="async" width="1609" height="108" class="wp-image-6797" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/07/word-image-6779-18.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/07/word-image-6779-18.png 1609w, https://coffeebreak.en-images.info/wp-content/uploads/2022/07/word-image-6779-18-300x20.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2022/07/word-image-6779-18-1024x69.png 1024w, https://coffeebreak.en-images.info/wp-content/uploads/2022/07/word-image-6779-18-768x52.png 768w, https://coffeebreak.en-images.info/wp-content/uploads/2022/07/word-image-6779-18-1536x103.png 1536w" sizes="auto, (max-width: 1609px) 100vw, 1609px" /></p>
<h4><span style="text-decoration: underline;"><span style="color: #000000; text-decoration: underline;">Check le tunnelVPN sur les deux machines</span></span></h4>
<pre>[root@<strong><span style="color: #ff0000;">tun-hosta</span></strong> ~]# <span style="color: #ff0000;">ipsec verify</span></pre>
<p><img loading="lazy" decoding="async" width="680" height="316" class="wp-image-6798" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/07/word-image-6779-19.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/07/word-image-6779-19.png 680w, https://coffeebreak.en-images.info/wp-content/uploads/2022/07/word-image-6779-19-300x139.png 300w" sizes="auto, (max-width: 680px) 100vw, 680px" /></p>
<pre>[root@<strong><span style="color: #ff0000;">tun-hostb</span></strong> ~]# <span style="color: #ff0000;">ipsec verify</span></pre>
<p><img loading="lazy" decoding="async" width="670" height="325" class="wp-image-6799" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/07/word-image-6779-20.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/07/word-image-6779-20.png 670w, https://coffeebreak.en-images.info/wp-content/uploads/2022/07/word-image-6779-20-300x146.png 300w" sizes="auto, (max-width: 670px) 100vw, 670px" /></p>
<pre>[root@<strong><span style="color: #ff0000;">tun-hosta</span></strong> ~]# <span style="color: #ff0000;">journalctl -e</span></pre>
<p><img loading="lazy" decoding="async" width="1378" height="216" class="wp-image-6800" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/07/word-image-6779-21.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/07/word-image-6779-21.png 1378w, https://coffeebreak.en-images.info/wp-content/uploads/2022/07/word-image-6779-21-300x47.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2022/07/word-image-6779-21-1024x161.png 1024w, https://coffeebreak.en-images.info/wp-content/uploads/2022/07/word-image-6779-21-768x120.png 768w" sizes="auto, (max-width: 1378px) 100vw, 1378px" /></p>
<pre>[root@<strong><span style="color: #ff0000;">tun-hostb</span></strong> ~]# <span style="color: #ff0000;">journalctl -e</span></pre>
<p><img loading="lazy" decoding="async" width="1126" height="210" class="wp-image-6801" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/07/word-image-6779-22.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/07/word-image-6779-22.png 1126w, https://coffeebreak.en-images.info/wp-content/uploads/2022/07/word-image-6779-22-300x56.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2022/07/word-image-6779-22-1024x191.png 1024w, https://coffeebreak.en-images.info/wp-content/uploads/2022/07/word-image-6779-22-768x143.png 768w" sizes="auto, (max-width: 1126px) 100vw, 1126px" /></p>
<p><img loading="lazy" decoding="async" width="1396" height="281" class="wp-image-6802" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/07/word-image-6779-23.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/07/word-image-6779-23.png 1396w, https://coffeebreak.en-images.info/wp-content/uploads/2022/07/word-image-6779-23-300x60.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2022/07/word-image-6779-23-1024x206.png 1024w, https://coffeebreak.en-images.info/wp-content/uploads/2022/07/word-image-6779-23-768x155.png 768w" sizes="auto, (max-width: 1396px) 100vw, 1396px" /></p>
<pre>[root@<strong><span style="color: #ff0000;">tun-hosta</span></strong> ~]# <span style="color: #ff0000;">ipsec show</span>
<span style="color: #ff0000;"><em><strong>10.10.10.1/32</strong> &lt;=&gt; <strong>10.10.10.2/32</strong> using reqid 16389</em></span></pre>
<p><img loading="lazy" decoding="async" width="458" height="51" class="wp-image-6803" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/07/word-image-6779-24.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/07/word-image-6779-24.png 458w, https://coffeebreak.en-images.info/wp-content/uploads/2022/07/word-image-6779-24-300x33.png 300w" sizes="auto, (max-width: 458px) 100vw, 458px" /></p>
<pre>[root@<span style="color: #ff0000;"><strong>tun-hostb</strong></span> ~]# <span style="color: #ff0000;">ipsec show</span>
<span style="color: #ff0000;"><em><strong>10.10.10.2/32</strong> &lt;=&gt; <strong>10.10.10.1/32</strong> using reqid 16389</em></span></pre>
<p><img loading="lazy" decoding="async" width="445" height="52" class="wp-image-6804" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/07/word-image-6779-25.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/07/word-image-6779-25.png 445w, https://coffeebreak.en-images.info/wp-content/uploads/2022/07/word-image-6779-25-300x35.png 300w" sizes="auto, (max-width: 445px) 100vw, 445px" /></p>
<h3><span style="color: #000000;"><strong>Ajouter des logs pour Ipsec (les deux machines)</strong></span></h3>
<pre>[root@<strong><span style="color: #ff0000;">tun-hostx</span></strong> ~]#<span style="color: #ff0000;"> vi /etc/ipsec.conf</span>
<em><span style="color: #ff0000;">logfile=/var/log/pluto.log</span></em>
[root@<span style="color: #ff0000;"><strong>tun-hostx</strong></span> ~]# <span style="color: #ff0000;">systemctl restart ipsec</span></pre>
<pre>[root@<strong><span style="color: #ff0000;">tun-hosta</span></strong> ~]# <span style="color: #ff0000;">tail -30 /var/log/pluto.log</span></pre>
<p><img loading="lazy" decoding="async" width="1394" height="453" class="wp-image-6805" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/07/word-image-6779-26.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/07/word-image-6779-26.png 1394w, https://coffeebreak.en-images.info/wp-content/uploads/2022/07/word-image-6779-26-300x97.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2022/07/word-image-6779-26-1024x333.png 1024w, https://coffeebreak.en-images.info/wp-content/uploads/2022/07/word-image-6779-26-768x250.png 768w" sizes="auto, (max-width: 1394px) 100vw, 1394px" /></p>
<pre>[root@<strong><span style="color: #ff0000;">tun-hostb</span></strong> ~]# <span style="color: #ff0000;">tail -30 /var/log/pluto.log</span></pre>
<p><img loading="lazy" decoding="async" width="1396" height="466" class="wp-image-6806" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/07/word-image-6779-27.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/07/word-image-6779-27.png 1396w, https://coffeebreak.en-images.info/wp-content/uploads/2022/07/word-image-6779-27-300x100.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2022/07/word-image-6779-27-1024x342.png 1024w, https://coffeebreak.en-images.info/wp-content/uploads/2022/07/word-image-6779-27-768x256.png 768w" sizes="auto, (max-width: 1396px) 100vw, 1396px" /></p>
<h4><span style="color: #000000;">Check flux réseau</span></h4>
<pre>[root@<strong><span style="color: #ff0000;">tun-hosta</span></strong> ~]# <span style="color: #ff0000;">ping -c 3 tunipsec-grea</span></pre>
<p><img loading="lazy" decoding="async" width="665" height="91" class="wp-image-6807" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/07/word-image-6779-28.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/07/word-image-6779-28.png 665w, https://coffeebreak.en-images.info/wp-content/uploads/2022/07/word-image-6779-28-300x41.png 300w" sizes="auto, (max-width: 665px) 100vw, 665px" /></p>
<pre>[root@<strong><span style="color: #ff0000;">tun-hosta</span></strong> ~]# <span style="color: #ff0000;">ping -c 3 tunipsec-greb</span></pre>
<p><img loading="lazy" decoding="async" width="610" height="86" class="wp-image-6808" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/07/word-image-6779-29.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/07/word-image-6779-29.png 610w, https://coffeebreak.en-images.info/wp-content/uploads/2022/07/word-image-6779-29-300x42.png 300w" sizes="auto, (max-width: 610px) 100vw, 610px" /></p>
<pre>[root@<strong><span style="color: #ff0000;">tun-hostb</span></strong> ~]# <span style="color: #ff0000;">ping -c 3 tunipsec-grea</span>
[root@<strong><span style="color: #ff0000;">tun-hostb</span> </strong>~]# <span style="color: #ff0000;">ping -c 3 tunipsec-greb</span></pre>
<p><img loading="lazy" decoding="async" width="706" height="276" class="wp-image-6809" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/07/word-image-6779-30.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/07/word-image-6779-30.png 706w, https://coffeebreak.en-images.info/wp-content/uploads/2022/07/word-image-6779-30-300x117.png 300w" sizes="auto, (max-width: 706px) 100vw, 706px" /></p>
<p>Views: 8</p><p>L’article <a href="https://coffeebreak.en-images.info/modop-installation-tunnel-gre-ipsec-host-to-host/">MODOP – Installation Tunnel GRE/Ipsec &#8211; Host to Host</a> est apparu en premier sur <a href="https://coffeebreak.en-images.info">CoffeeBreak Info</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://coffeebreak.en-images.info/modop-installation-tunnel-gre-ipsec-host-to-host/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>MODOP – Installation Tunnel GRE Host to Host</title>
		<link>https://coffeebreak.en-images.info/modop-installation-tunnel-gre-host-to-host/</link>
					<comments>https://coffeebreak.en-images.info/modop-installation-tunnel-gre-host-to-host/#respond</comments>
		
		<dc:creator><![CDATA[chris]]></dc:creator>
		<pubDate>Sun, 03 Jul 2022 09:03:25 +0000</pubDate>
				<category><![CDATA[OS Linux]]></category>
		<category><![CDATA[RedHat/Centos Linux]]></category>
		<category><![CDATA[Sécurité]]></category>
		<category><![CDATA[Système]]></category>
		<category><![CDATA[VPN]]></category>
		<category><![CDATA[Centos]]></category>
		<category><![CDATA[Linux]]></category>
		<category><![CDATA[RockyLinux]]></category>
		<category><![CDATA[Serveur]]></category>
		<guid isPermaLink="false">https://coffeebreak.en-images.info/?p=6744</guid>

					<description><![CDATA[<p>MODOP d'une encapsulation de paquets de données à travers une connexion point à point entre deux client Linux via une tunnel GRE.<br />
Le service GRE (Generic Routing Encapsulation) permet d'encapsuler des flux/protocoles qui ne sont normalement pas pris en charge par un réseau.<br />
GRE est un moyen de charger un type de paquet dans un autre type de paquet afin que le premier paquet puisse circuler sur un réseau sur lequel il ne pourrait normalement pas circuler.</p>
<p>L’article <a href="https://coffeebreak.en-images.info/modop-installation-tunnel-gre-host-to-host/">MODOP – Installation Tunnel GRE Host to Host</a> est apparu en premier sur <a href="https://coffeebreak.en-images.info">CoffeeBreak Info</a>.</p>
]]></description>
										<content:encoded><![CDATA[<h2 style="text-align: center;"><span style="color: #000000;">Installation de la machine tun-greA.house.cpb – RockyLinux</span></h2>
<h3><span style="color: #000000;"><strong>Spécification de la machine tun-greA.house.cpb</strong></span></h3>
<p>Host : <strong>tun-greA.house.cpb</strong></p>
<ul>
<li><strong>IP :192.168.1.54</strong>
<ul>
<li>VIP : <strong><span style="color: #0000ff;">100.100.0.1/24</span></strong></li>
</ul>
</li>
<li>OS : <strong>RockyLinux</strong></li>
<li>vCPU : 2</li>
<li>DD : 8Go</li>
<li>Ram : 2Go</li>
</ul>
<h3><span style="color: #000000;"><strong>Mise à jour de la machine </strong></span></h3>
<pre>[root@tun-grea ~]# <span style="color: #ff0000;">dnf update -y</span></pre>
<h3><span style="color: #000000;"><strong>TimeDate</strong></span></h3>
<pre>[root@tun-grea ~]# <span style="color: #ff0000;">timedatectl set-timezone "Europe/Paris"</span>
[root@tun-grea ~]# <span style="color: #ff0000;">timedatect</span></pre>
<p><img loading="lazy" decoding="async" width="609" height="148" class="wp-image-6746" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/07/word-image-6744-2.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/07/word-image-6744-2.png 609w, https://coffeebreak.en-images.info/wp-content/uploads/2022/07/word-image-6744-2-300x73.png 300w" sizes="auto, (max-width: 609px) 100vw, 609px" /></p>
<h3><span style="color: #000000;"><strong>Ajouter les hosts (Si pas de DNS)</strong></span></h3>
<pre>[root@tun-grea ~]# <span style="color: #ff0000;">echo "192.168.1.54 tun-grea tun-grea.house.cpb" &gt;&gt; /etc/hosts</span>
[root@tun-grea ~]#<span style="color: #ff0000;"> echo "192.168.1.55 tun-greb tun-greb.house.cpb" &gt;&gt; /etc/hosts</span>

[root@tun-grea ~]#<span style="color: #ff0000;"> echo "100.100.0.1 tunnel-grea tunnel-grea.house.cpb" &gt;&gt; /etc/hosts</span>
[root@tun-grea ~]# <span style="color: #ff0000;">echo "100.100.0.2 tunnel-greb tunnel-greb.house.cpb" &gt;&gt; /etc/hosts</span></pre>
<h3><span style="color: #000000;"><strong>Installation epel</strong></span></h3>
<pre>[root@vpn-sita ~]# <span style="color: #ff0000;">dnf install epel-release</span></pre>
<h3><span style="color: #000000;"><strong>Chargement Module GRE &#8211; CLI</strong></span></h3>
<pre>[root@tun-grea ~]# <span style="color: #ff0000;">lsmod | grep ip_gre</span>
[root@tun-grea ~]# <span style="color: #ff0000;">modprobe ip_gre</span>
[root@tun-grea ~]# <span style="color: #ff0000;">lsmod | grep ip_gre</span></pre>
<p><img loading="lazy" decoding="async" width="455" height="115" class="wp-image-6747" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/07/word-image-6744-3.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/07/word-image-6744-3.png 455w, https://coffeebreak.en-images.info/wp-content/uploads/2022/07/word-image-6744-3-300x76.png 300w" sizes="auto, (max-width: 455px) 100vw, 455px" /></p>
<h3><span style="color: #000000;"><strong>Chargement Module GRE – On BOOT</strong></span></h3>
<pre>[root@tun-grea ~]# <span style="color: #ff0000;">echo ip_gre &gt;&gt; /etc/modules-load.d/tun.conf</span>

[root@tun-grea ~]#<span style="color: #ff0000;"> ls -al /etc/modules-load.d/tun.conf
<em>-rw-r--r--. 1 root root 7 30 mai 19:39 /etc/modules-load.d/tun.conf</em></span></pre>
<h3><span style="color: #000000;"><strong>Configuration Réseau Tunnel GRE</strong></span></h3>
<h4><span style="text-decoration: underline;"><span style="color: #000000; text-decoration: underline;">Création du Tunnel tun0</span></span></h4>
<pre>[root@tun-grea ~]#<span style="color: #ff0000;"> nmcli connection add type ip-tunnel ip-tunnel.mode ipip con-name tun0 ifname tun0 remote <strong>192.168.1.55</strong> local <strong>192.168.1.54</strong>
<em>Connexion « tun0 » (80e7cefb-c070-4b9a-8ac0-200edd9090a6) ajoutée avec succès.</em></span></pre>
<h4><span style="text-decoration: underline;"><span style="color: #000000; text-decoration: underline;">Création de l’adresse VIP</span></span></h4>
<pre>[root@tun-grea ~]# <span style="color: #ff0000;">nmcli connection modify tun0 ipv4.addresses '<strong>100.100.0.1/24</strong>'</span></pre>
<h4><span style="text-decoration: underline;"><span style="color: #000000; text-decoration: underline;">Configuration IPV4 sur tun0</span></span></h4>
<pre>[root@tun-grea ~]# <span style="color: #ff0000;">nmcli connection modify tun0 ipv4.method manual</span></pre>
<h4><span style="text-decoration: underline;"><span style="color: #000000; text-decoration: underline;">Configuration static route sur tun0</span></span></h4>
<pre>[root@tun-grea ~]# <span style="color: #ff0000;">nmcli connection modify tun0 +ipv4.routes "<strong>192.168.1.0/24 100.100.0.2</strong>"</span></pre>
<h4><span style="text-decoration: underline; color: #000000;">Activation de la connexion tun0</span></h4>
<pre>[root@tun-grea ~]# <span style="color: #ff0000;">nmcli connection up tun0
<em>Connexion activée (chemin D-Bus actif /org/freedesktop/NetworkManager/ActiveConnection/11)</em></span></pre>
<p><img loading="lazy" decoding="async" width="1188" height="118" class="wp-image-6748" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/07/word-image-6744-4.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/07/word-image-6744-4.png 1188w, https://coffeebreak.en-images.info/wp-content/uploads/2022/07/word-image-6744-4-300x30.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2022/07/word-image-6744-4-1024x102.png 1024w, https://coffeebreak.en-images.info/wp-content/uploads/2022/07/word-image-6744-4-768x76.png 768w" sizes="auto, (max-width: 1188px) 100vw, 1188px" /></p>
<h4><span style="text-decoration: underline;"><span style="color: #000000; text-decoration: underline;">Check de la connexion tun0</span></span></h4>
<pre>[root@tun-grea ~]# <span style="color: #ff0000;">nmcli connection</span></pre>
<p><img loading="lazy" decoding="async" width="787" height="110" class="wp-image-6749" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/07/word-image-6744-5.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/07/word-image-6744-5.png 787w, https://coffeebreak.en-images.info/wp-content/uploads/2022/07/word-image-6744-5-300x42.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2022/07/word-image-6744-5-768x107.png 768w" sizes="auto, (max-width: 787px) 100vw, 787px" /></p>
<pre>[root@tun-grea ~]# <span style="color: #ff0000;">ip a show tun0</span></pre>
<p><img loading="lazy" decoding="async" width="940" height="133" class="wp-image-6750" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/07/word-image-6744-6.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/07/word-image-6744-6.png 940w, https://coffeebreak.en-images.info/wp-content/uploads/2022/07/word-image-6744-6-300x42.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2022/07/word-image-6744-6-768x109.png 768w" sizes="auto, (max-width: 940px) 100vw, 940px" /></p>
<h3><span style="color: #000000;"><strong>Activer le Forward IPv4</strong></span></h3>
<pre>[root@tun-grea ~]# <span style="color: #ff0000;">echo "net.ipv4.ip_forward=1" &gt; /etc/sysctl.conf</span>
[root@tun-grea ~]# <span style="color: #ff0000;">sysctl -p
<em>net.ipv4.ip_forward = 1</em></span></pre>
<h3><span style="color: #000000;"><strong>Activer les rules Firewall GRE</strong></span></h3>
<pre>[root@tun-grea ~]# <span style="color: #ff0000;">firewall-cmd --permanent --direct --add-rule ipv4 filter INPUT 0 -p gre -j ACCEPT</span>
[root@tun-grea ~]# <span style="color: #ff0000;">firewall-cmd --remove-service={dhcpv6-client,cockpit} --permanent</span>
[root@tun-grea ~]# <span style="color: #ff0000;">firewall-cmd --reload</span>
[root@tun-grea ~]# <span style="color: #ff0000;">iptables -L</span></pre>
<p><img loading="lazy" decoding="async" width="706" height="159" class="wp-image-6751" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/07/word-image-6744-7.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/07/word-image-6744-7.png 706w, https://coffeebreak.en-images.info/wp-content/uploads/2022/07/word-image-6744-7-300x68.png 300w" sizes="auto, (max-width: 706px) 100vw, 706px" /></p>
<h2 style="text-align: center;"><strong><span style="color: #000000;">Installation de la machine tun-greB.house.cpb – Centos7</span></strong></h2>
<h3><span style="color: #000000;"><strong>Spécification de la machine tun-greB.house.cpb</strong></span></h3>
<p>Host : <strong>tun-greB.house.cpb</strong></p>
<ul>
<li><strong>IP :192.168.1.55</strong>
<ul>
<li>VIP : <strong><span style="color: #0000ff;">100.100.0.2/24</span></strong></li>
</ul>
</li>
<li>OS : <strong>Centos7</strong></li>
<li>vCPU : 2</li>
<li>DD : 8Go</li>
<li>Ram : 2Go</li>
</ul>
<h3><span style="color: #000000;"><strong>Mise à jour de la machine </strong></span></h3>
<pre>[root@tun-greb ~]# <span style="color: #ff0000;">yum -y update</span></pre>
<h3><span style="color: #000000;"><strong>TimeDate</strong></span></h3>
<pre>[root@tun-greb ~]# <span style="color: #ff0000;">timedatectl set-timezone "Europe/Paris"</span></pre>
<h3><strong>Ajouter les hosts (Si pas de DNS)</strong></h3>
<pre>[root@tun-greb ~]# <span style="color: #ff0000;">echo "192.168.1.54 tun-grea tun-grea.house.cpb" &gt;&gt; /etc/hosts</span>
[root@tun-greb ~]# <span style="color: #ff0000;">echo "192.168.1.55 tun-greb tun-greb.house.cpb" &gt;&gt; /etc/hosts</span>

[root@tun-greb ~]# <span style="color: #ff0000;">echo "100.100.0.1 tunnel-grea tunnel-grea.house.cpb" &gt;&gt; /etc/hosts</span>
[root@tun-greb ~]# <span style="color: #000000;">echo "100.100.0.2 tunnel-greb tunnel-greb.house.cpb" &gt;&gt; /etc/hosts</span></pre>
<h3><span style="color: #000000;"><strong>Désactiver l’IPv6 (non nécessaire)</strong></span></h3>
<pre>[root@tun-greb ~]# <span style="color: #ff0000;">echo "net.ipv6.conf.all.disable_ipv6 = 1" &gt;&gt; /etc/sysctl.conf</span>
[root@tun-greb ~]#<span style="color: #ff0000;"> echo "net.ipv6.conf.all.autoconf = 0" &gt;&gt; /etc/sysctl.conf</span>
[root@tun-greb ~]# <span style="color: #ff0000;">echo "net.ipv6.conf.default.disable_ipv6 = 1" &gt;&gt; /etc/sysctl.conf</span>
[root@tun-greb ~]# <span style="color: #ff0000;">echo "net.ipv6.conf.default.autoconf = 0" &gt;&gt; /etc/sysctl.conf</span>

[root@tun-greb ~]# <span style="color: #ff0000;">sysctl -p
<em>net.ipv6.conf.all.disable_ipv6 = 1</em>
<em>net.ipv6.conf.all.autoconf = 0</em>
<em>net.ipv6.conf.default.disable_ipv6 = 1</em>
<em>net.ipv6.conf.default.autoconf = 0</em>
</span></pre>
<pre>[root@tun-greb ~]# <span style="color: #ff0000;">ip a
</span></pre>
<p><img loading="lazy" decoding="async" width="847" height="151" class="wp-image-6752" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/07/word-image-6744-8.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/07/word-image-6744-8.png 847w, https://coffeebreak.en-images.info/wp-content/uploads/2022/07/word-image-6744-8-300x53.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2022/07/word-image-6744-8-768x137.png 768w" sizes="auto, (max-width: 847px) 100vw, 847px" /></p>
<h3><span style="color: #000000;"><strong>Chargement Module GRE &#8211; CLI</strong></span></h3>
<pre>[root@tun-greb ~]# <span style="color: #ff0000;">lsmod | grep ip_gre</span>
[root@tun-greb ~]# <span style="color: #ff0000;">modprobe ip_gre</span>
[root@tun-grea ~]# <span style="color: #ff0000;">lsmod | grep ip_gre
</span></pre>
<p><img loading="lazy" decoding="async" width="558" height="109" class="wp-image-6753" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/07/word-image-6744-9.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/07/word-image-6744-9.png 558w, https://coffeebreak.en-images.info/wp-content/uploads/2022/07/word-image-6744-9-300x59.png 300w" sizes="auto, (max-width: 558px) 100vw, 558px" /></p>
<h3><span style="color: #000000;"><strong>Chargement Module GRE – On BOOT</strong></span></h3>
<pre>[root@tun-greb ~]# <span style="color: #ff0000;">echo ip_gre &gt;&gt; /etc/modules-load.d/tun.conf</span>
[root@tun-greb ~]# ls <span style="color: #ff0000;">-al /etc/modules-load.d/tun.conf
<em>-rw-r--r--. 1 root root 7 18 juin 18:19 /etc/modules-load.d/tun.conf</em></span></pre>
<h3><span style="color: #000000;"><strong>Configuration Réseau Tunnel GRE</strong></span></h3>
<h4><span style="text-decoration: underline;"><span style="color: #000000; text-decoration: underline;">Création de l’interface tun0</span></span></h4>
<pre>[root@tun-greb ~]# <span style="color: #ff0000;">nmcli connection add type ip-tunnel ip-tunnel.mode ipip con-name tun0 ifname tun0 remote <strong>192.168.1.54 local 192.168.1.55</strong>
<em>Connexion « tun0 » (163dbe74-79b7-4ba9-90f6-6e0d4fec4271) ajoutée avec succès.</em></span></pre>
<h4><span style="text-decoration: underline;"><span style="color: #000000; text-decoration: underline;">Création de l’adresse VIP</span></span></h4>
<pre>[root@tun-greb ~]#<span style="color: #ff0000;"> nmcli connection modify tun0 ipv4.addresses '<strong>100.100.0.2/24</strong>'</span></pre>
<h4><span style="text-decoration: underline;"><span style="color: #000000; text-decoration: underline;">Configuration IPV4 sur tun0</span></span></h4>
<pre>[root@tun-greb ~]# <span style="color: #ff0000;">nmcli connection modify tun0 ipv4.method manual</span></pre>
<h4><span style="text-decoration: underline;"><span style="color: #000000; text-decoration: underline;">Configuration static route sur tun0</span></span></h4>
<pre>[root@tun-greb ~]# <span style="color: #ff0000;">nmcli connection modify tun0 +ipv4.routes "<strong>192.168.1.0/24 100.100.0.1</strong>"</span></pre>
<h4><span style="text-decoration: underline;"><span style="color: #000000; text-decoration: underline;">Activation de la connexion tun0</span></span></h4>
<pre>[root@tun-greb ~]# <span style="color: #ff0000;">nmcli connection up tun0
<em>Connexion activée (chemin D-Bus actif : /org/freedesktop/NetworkManager/ActiveConnection/6)</em>
</span></pre>
<p><img loading="lazy" decoding="async" width="1178" height="128" class="wp-image-6754" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/07/word-image-6744-10.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/07/word-image-6744-10.png 1178w, https://coffeebreak.en-images.info/wp-content/uploads/2022/07/word-image-6744-10-300x33.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2022/07/word-image-6744-10-1024x111.png 1024w, https://coffeebreak.en-images.info/wp-content/uploads/2022/07/word-image-6744-10-768x83.png 768w" sizes="auto, (max-width: 1178px) 100vw, 1178px" /></p>
<h4><span style="text-decoration: underline;"><span style="color: #000000; text-decoration: underline;">Check de la connexion tun0</span></span></h4>
<pre>[root@tun-greb ~]#<span style="color: #ff0000;"> ip a show tun0</span></pre>
<p><img loading="lazy" decoding="async" width="958" height="124" class="wp-image-6755" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/07/word-image-6744-11.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/07/word-image-6744-11.png 958w, https://coffeebreak.en-images.info/wp-content/uploads/2022/07/word-image-6744-11-300x39.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2022/07/word-image-6744-11-768x99.png 768w" sizes="auto, (max-width: 958px) 100vw, 958px" /></p>
<pre>[root@tun-greb ~]# <span style="color: #ff0000;">nmcli connection</span></pre>
<p><img loading="lazy" decoding="async" width="629" height="80" class="wp-image-6756" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/07/word-image-6744-12.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/07/word-image-6744-12.png 629w, https://coffeebreak.en-images.info/wp-content/uploads/2022/07/word-image-6744-12-300x38.png 300w" sizes="auto, (max-width: 629px) 100vw, 629px" /></p>
<h3><span style="color: #000000;"><strong>Activer le Forward IPv4</strong></span></h3>
<pre>[root@tun-greb ~]# <span style="color: #ff0000;">echo "net.ipv4.ip_forward=1" &gt; /etc/sysctl.conf</span>
[root@tun-greb ~]# <span style="color: #ff0000;">sysctl -p
<em>net.ipv4.ip_forward = 1</em></span></pre>
<h3><strong>Activer les rules Firewall GRE</strong></h3>
<pre>[root@tun-greb ~]# <span style="color: #ff0000;">firewall-cmd --permanent --direct --add-rule ipv4 filter INPUT 0 -p gre -j ACCEPT</span>
[root@tun-greb ~]# <span style="color: #ff0000;">firewall-cmd --remove-service=dhcpv6-client --permanent</span>
[root@tun-greb ~]# <span style="color: #ff0000;">firewall-cmd --reload</span>

[root@tun-greb ~]# <span style="color: #ff0000;">iptables -L |grep gre
<em>ACCEPT gre -- anywhere anywhere</em></span></pre>
<h2><span style="color: #000000;">Check des flux réseaux Public et Tunnel</span></h2>
<h4><span style="text-decoration: underline;"><span style="color: #000000; text-decoration: underline;">Serveur tun-grea</span></span></h4>
<pre>[root@tun-grea ~]# <span style="color: #ff0000;">ping -c 3 tunnel-grea</span></pre>
<p><img loading="lazy" decoding="async" width="608" height="96" class="wp-image-6757" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/07/word-image-6744-13.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/07/word-image-6744-13.png 608w, https://coffeebreak.en-images.info/wp-content/uploads/2022/07/word-image-6744-13-300x47.png 300w" sizes="auto, (max-width: 608px) 100vw, 608px" /></p>
<pre>[root@tun-grea ~]# <span style="color: #ff0000;">ping -c 3 tunnel-greb</span></pre>
<p><img loading="lazy" decoding="async" width="624" height="88" class="wp-image-6758" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/07/word-image-6744-14.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/07/word-image-6744-14.png 624w, https://coffeebreak.en-images.info/wp-content/uploads/2022/07/word-image-6744-14-300x42.png 300w" sizes="auto, (max-width: 624px) 100vw, 624px" /></p>
<h4><span style="text-decoration: underline;"><span style="color: #000000; text-decoration: underline;">Serveur tun-greb</span></span></h4>
<pre>[root@tun-greb ~]# <span style="color: #ff0000;">ping -c 3 tunnel-grea</span></pre>
<p><img loading="lazy" decoding="async" width="635" height="86" class="wp-image-6759" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/07/word-image-6744-15.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/07/word-image-6744-15.png 635w, https://coffeebreak.en-images.info/wp-content/uploads/2022/07/word-image-6744-15-300x41.png 300w" sizes="auto, (max-width: 635px) 100vw, 635px" /></p>
<pre>[root@tun-greb ~]# <span style="color: #ff0000;">ping -c 3 tunnel-greb</span></pre>
<p><img loading="lazy" decoding="async" width="601" height="86" class="wp-image-6760" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/07/word-image-6744-16.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/07/word-image-6744-16.png 601w, https://coffeebreak.en-images.info/wp-content/uploads/2022/07/word-image-6744-16-300x43.png 300w" sizes="auto, (max-width: 601px) 100vw, 601px" /></p>
<h2>[root@tun-greb ~]# <span style="color: #ff0000;">ssh -l root tunnel-grea</span></h2>
<p><img loading="lazy" decoding="async" width="737" height="178" class="wp-image-6761" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/07/word-image-6744-17.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/07/word-image-6744-17.png 737w, https://coffeebreak.en-images.info/wp-content/uploads/2022/07/word-image-6744-17-300x72.png 300w" sizes="auto, (max-width: 737px) 100vw, 737px" /></p>
<p>Views: 3</p><p>L’article <a href="https://coffeebreak.en-images.info/modop-installation-tunnel-gre-host-to-host/">MODOP – Installation Tunnel GRE Host to Host</a> est apparu en premier sur <a href="https://coffeebreak.en-images.info">CoffeeBreak Info</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://coffeebreak.en-images.info/modop-installation-tunnel-gre-host-to-host/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>MODOP installation VPN IPsec – Host to Host</title>
		<link>https://coffeebreak.en-images.info/modop-installation-vpn-ipsec-host-to-host/</link>
					<comments>https://coffeebreak.en-images.info/modop-installation-vpn-ipsec-host-to-host/#respond</comments>
		
		<dc:creator><![CDATA[chris]]></dc:creator>
		<pubDate>Wed, 25 May 2022 16:49:25 +0000</pubDate>
				<category><![CDATA[Applications]]></category>
		<category><![CDATA[OS Linux]]></category>
		<category><![CDATA[RedHat/Centos Linux]]></category>
		<category><![CDATA[Sécurité]]></category>
		<category><![CDATA[Système]]></category>
		<category><![CDATA[VPN]]></category>
		<category><![CDATA[IPsec]]></category>
		<category><![CDATA[Linux]]></category>
		<category><![CDATA[RockyLinux]]></category>
		<category><![CDATA[Serveur]]></category>
		<guid isPermaLink="false">https://coffeebreak.en-images.info/?p=6626</guid>

					<description><![CDATA[<p>MODOP sur la mise en place de IPsec  (Internet Protocol Security) entre deux machines clientes et de réseaux différents et cela afin d’assurer des communications privées et sécurisées via IP. Le But est de chiffrer et s’identifier auprès d’un hosts grâce à un échange de clefs Publiques host-to-host. IPsec se différencie de la plupart des systèmes des services pour la protection des réseaux IP car il fonctionne sur la couche 3 du modèle OSI. De fait, aucune application nécessaire à paramétrer. </p>
<p>L’article <a href="https://coffeebreak.en-images.info/modop-installation-vpn-ipsec-host-to-host/">MODOP installation VPN IPsec – Host to Host</a> est apparu en premier sur <a href="https://coffeebreak.en-images.info">CoffeeBreak Info</a>.</p>
]]></description>
										<content:encoded><![CDATA[<h3><span style="color: #003300;">Spécification de la machine vpn-ipsec-left.house.cpb</span></h3>
<p>Host&nbsp;: <strong>vpn-ipsec-left.house.cpb</strong></p>
<ul>
<li><strong>IP&nbsp;:192.168.1.56</strong></li>
<li>OS&nbsp;: <strong>RockyLinux</strong></li>
<li>vCPU&nbsp;: 2</li>
<li>DD&nbsp;: 8Go</li>
<li>Ram&nbsp;: 2Go</li>
</ul>
<h3>Spécification de la machine <span style="color: #003300;">vpn-ipsec-right.house.cpb</span></h3>
<p>Host&nbsp;: <strong>vpn-ipsec-right.house.cpb</strong></p>
<ul>
<li><strong>IP&nbsp;:172.32.185.31</strong></li>
<li>OS&nbsp;: <strong>RockyLinux </strong></li>
<li>vCPU&nbsp;: 2</li>
<li>DD&nbsp;: 8Go</li>
<li>Ram&nbsp;: 2Go</li>
</ul>
<h1 style="text-align: left;"><span style="color: #000000;">Machine vpn-ipsec-left.house.cpb – Site A</span></h1>
<p>Host&nbsp;: <strong>vpn-ipsec-left.house.cpb</strong></p>
<ul>
<li>vSwitch&nbsp;: <strong>vmbr0</strong>
<ul>
<li><strong>IP&nbsp;:192.168.1.56</strong></li>
</ul>
</li>
<li>OS&nbsp;: <strong>RockyLinux 8.4</strong></li>
<li>vCPU&nbsp;: 2</li>
<li>DD&nbsp;: 8Go</li>
<li>Ram&nbsp;: 2Go</li>
</ul>
<h3><span style="color: #003300;">Update de la machine</span></h3>
<pre>[root@vpn-ipsec-left ~]# <span style="color: #ff0000;">dnf -y update</span></pre>
<h3><span style="color: #000000;">TimeDate</span></h3>
<pre>[root@vpn-ipsec-left ~]# <span style="color: #ff0000;">timedatectl set-timezone "Europe/Paris"</span>
[root@vpn-ipsec-left ~]# <span style="color: #ff0000;">timedatectl</span></pre>
<p><img loading="lazy" decoding="async" width="695" height="144" class="wp-image-6628" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-176.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-176.png 695w, https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-176-300x62.png 300w" sizes="auto, (max-width: 695px) 100vw, 695px" /></p>
<h3><span style="color: #000000;">Ajout des hosts machines (si pas de DNS)</span></h3>
<pre>[root@vpn-ipsec-left ~]#<span style="color: #ff0000;"> echo "192.168.1.56 vpn-ipsec-left vpn-ipsec-left.house.cpb" &gt;&gt; /etc/hosts</span>
[root@vpn-ipsec-left ~]# <span style="color: #ff0000;">echo "172.32.185.31 vpn-ipsec-right vpn-ipsec-right.house.cpb" &gt;&gt; /etc/hosts</span></pre>
<h3><span style="color: #000000;">Désactiver «&nbsp;rp_filter&nbsp;» de Libreswan</span></h3>
<pre>[root@vpn-ipsec-left ~]# <span style="color: #ff0000;">echo "net.ipv4.conf.all.rp_filter = 0" &gt;&gt; /etc/sysctl.d/50-libreswan.conf</span>
[root@vpn-ipsec-left ~]# <span style="color: #ff0000;">sysctl --system</span></pre>
<h3><span style="color: #000000;">Installation package</span></h3>
<pre>[root@vpn-ipsec-left ~]# <span style="color: #ff0000;">yum install libreswan</span></pre>
<p><img loading="lazy" decoding="async" width="1603" height="264" class="wp-image-6629" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-177.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-177.png 1603w, https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-177-300x49.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-177-1024x169.png 1024w, https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-177-768x126.png 768w, https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-177-1536x253.png 1536w" sizes="auto, (max-width: 1603px) 100vw, 1603px" /></p>
<h3><span style="color: #000000;">Initialiser la base nss</span></h3>
<pre>[root@vpn-ipsec-left ~]#<span style="color: #ff0000;"> systemctl stop ipsec</span>
[root@vpn-ipsec-left ~]# <span style="color: #ff0000;">rm -f /etc/ipsec.d/*db</span>
[root@vpn-ipsec-left ~]# <span style="color: #ff0000;">ls -al /etc/ipsec.d/</span></pre>
<p><img loading="lazy" decoding="async" width="561" height="82" class="wp-image-6630" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-178.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-178.png 561w, https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-178-300x44.png 300w" sizes="auto, (max-width: 561px) 100vw, 561px" /></p>
<pre>[root@vpn-ipsec-left ~]# <span style="color: #ff0000;">ipsec initnss
<em>Initializing NSS database</em></span>

[root@vpn-ipsec-left ~]# <span style="color: #ff0000;">ls -al /etc/ipsec.d/</span></pre>
<p><img loading="lazy" decoding="async" width="577" height="125" class="wp-image-6631" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-179.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-179.png 577w, https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-179-300x65.png 300w" sizes="auto, (max-width: 577px) 100vw, 577px" /></p>
<h3><span style="color: #000000;">Ajouter les règles Firewall</span></h3>
<pre>[root@vpn-ipsec-left ~]# <span style="color: #ff0000;">firewall-cmd --add-service=ipsec --permanent</span>
[root@vpn-ipsec-left ~]# <span style="color: #ff0000;">firewall-cmd --remove-service={cockpit,dhcpv6-client} --permanent</span>
[root@vpn-ipsec-left ~]# <span style="color: #ff0000;">firewall-cmd --reload</span></pre>
<h3><span style="color: #000000;">Démarrer le service</span></h3>
<pre>[root@vpn-ipsec-left ~]# <span style="color: #ff0000;">systemctl enable ipsec --now</span>
[root@vpn-ipsec-left ~]# <span style="color: #ff0000;">systemctl status ipsec</span></pre>
<p><img loading="lazy" decoding="async" width="1193" height="428" class="wp-image-6632" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-180.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-180.png 1193w, https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-180-300x108.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-180-1024x367.png 1024w, https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-180-768x276.png 768w" sizes="auto, (max-width: 1193px) 100vw, 1193px" /></p>
<h3><span style="color: #000000;">Générer une cléf RSA</span></h3>
<pre>[root@vpn-ipsec-left ~]# <span style="color: #ff0000;">ipsec newhostkey</span>
<em><span style="color: #ff0000;">Generated RSA key pair with CKAID f2f80cb679336256ac8c159b119464430d5bc7f9 was stored in the NSS database
The public key can be displayed using: ipsec showhostkey --left --ckaid f2f80cb679336256ac8c159b119464430d5bc7f9</span></em>

[root@vpn-ipsec-left ~]# <span style="color: #ff0000;">ipsec showhostkey --<strong>left</strong> --ckaid</span> <span style="color: #ff0000;">f2f80cb679336256ac8c159b119464430d5bc7f9

<em> # rsakey AwEAAb9Rf</em>
<strong><em>leftrsasigkey</em></strong><em>=0sAwEAAb9RfAkykozOv4VudJodKC0RmQ+w2TueEo8Ma7Pa/Ru73h+1xFMI77nSHhDxVbIrTwDtiimwz86wDPHtY7Uz7NOkQshjCflb2tp2nQzVi0tA8+qxjnPuLe0AUKRf03QwwY8TCv4kHcP7nd0rZs8MFPvHPao7fZj5u0UBfREWS5QfXbXgtDjaicC40t6QW5ngwm7AmaoXpyLPbBBU4VeVCRNSnjky6orRpMhkDOTAg0198Iz35jNRxf5J2BxBdRjGag5HpzAkbAJX9MjBMerBTzLAC+a1XvQzelJGTTLsbeqG2ziPW4HvZ6A33hMb6TRCbJPmTyuO2fb9i9YQlOQJgJP5GcA5AQYCu0nCYOuyrQcoBQPOOoDZ2e3thpGP37qkQMYffeRsXMgIVezHhI45pAM1wylWaaeo5f3HoYgiMHUJl6S1LD+xzDXmR1fQWF9t3++mJEEWClZuAyK67YboM6+PwUCidOS4p01ISxS1LdkGDF99l8b2H0S+urn/L2U+DjMYOBA/THkjwuM=</em></span></pre>
<h3><span style="color: #000000;">Création fichier Machine left ⬄ Machine right</span></h3>
<pre>[root@vpn-ipsec-left ~]# <span style="color: #ff0000;">vi /etc/ipsec.d/host_to_host.conf</span></pre>
<pre><span style="color: #ff0000;"><em>conn tunnelVPN</em>
<em> leftid=@west</em>
<em> left=192.168.1.56</em>
<span style="color: #3366ff;"><em>Leftrsasigkey=0sAwEAAb9RfAkykozOv4VudJodKC0RmQ+w2TueEo8Ma7Pa/Ru73h+1xFMI77nSHhDxVbIrTwDtiimwz86wDPHtY7Uz7NOkQshjCflb2tp2nQzVi0tA8+qxjnPuLe0AUKRf03QwwY8TCv4kHcP7nd0rZs8MFPvHPao7fZj5u0UBfREWS5QfXbXgtDjaicC40t6QW5ngwm7AmaoXpyLPbBBU4VeVCRNSnjky6orRpMhkDOTAg0198Iz35jNRxf5J2BxBdRjGag5HpzAkbAJX9MjBMerBTzLAC+a1XvQzelJGTTLsbeqG2ziPW4HvZ6A33hMb6TRCbJPmTyuO2fb9i9YQlOQJgJP5GcA5AQYCu0nCYOuyrQcoBQPOOoDZ2e3thpGP37qkQMYffeRsXMgIVezHhI45pAM1wylWaaeo5f3HoYgiMHUJl6S1LD+xzDXmR1fQWF9t3++mJEEWClZuAyK67YboM6+PwUCidOS4p01ISxS1LdkGDF99l8b2H0S+urn/L2U+DjMYOBA/THkjwuM=</em></span>
<em> rightid=@east</em>
<em> right=172.32.185.31</em>
<span style="color: #ff6600;"><em>rightrsasigkey=0sAwEAAdptcCuPX9bb9VoI+Y8jW8CJTXNPFqXrg5Q1AGqLfrr/2Pyc9m3GkkaBtZDIWVYAE5JpSHwFAwrAvONaeldppssCjsch8tRXTYOCD0MnI44VTn1L1b6L/ofECV/Hm1CIfzE82MJiIWekrfxfj34AnZplSPc8oTZZm7J0n4yEUC452Y7zeWBH/OA4vIFRnk8MY3JrsKMI3zt4LkFL828mWyXhqU2qLtNm/cjPf2wlczv0U6EgFIB8V6XmnD+TZZkBid0NziNrXKc/BdSRB4ZFk0VbH2BoM7TcwgQurAacODb6dWRxG+fxyYAn0STQbwfVUwcymVtAjQFj3jT0GAUbc6IdEQiQNuGuS6K0uhYWShODE+P9fSDWHZnIEtHGQzyU/BDUZnjwYAVV2h6kZvdFQoMOCGQYVM8PIWR8yZTR8hHdj2dsLb/XM/AzLJaf35bBSYAnp1RJRwjtMMjXraxJ2ijx/ssezw80gu3Bvj/ntyQDhzFMwQaa37mlqbsHdjxIy7504ylBOyILVkHdqSKZB83kT2XuFWkXHjHVD0yzu/rlE/zQmOaiKuGDgXp6DYUwQN7MM1XdT35DHSBlxrcVs91xusxgeYSD7zFI/WwZtPPf3Bm7BcAlQUz93brQLTr3WuRREDe/pqdT4xDrQw==</em></span>
<em> authby=rsasig</em></span></pre>
<p><img loading="lazy" decoding="async" width="1102" height="253" class="wp-image-6633" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-181.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-181.png 1102w, https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-181-300x69.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-181-1024x235.png 1024w, https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-181-768x176.png 768w" sizes="auto, (max-width: 1102px) 100vw, 1102px" /></p>
<ul>
<li><strong><span style="color: #3366ff;">En bleu</span>&nbsp;: Clef site public A (left)</strong></li>
<li><strong><span style="color: #ff6600;">En orange</span>&nbsp;: Clef site public B (right)</strong></li>
</ul>
<h3><span style="color: #000000;">Mise en place du Tunnel</span></h3>
<pre>[root@vpn-ipsec-left ~]# <span style="color: #ff0000;">systemctl restart ipsec</span>
[root@vpn-ipsec-left ~]# <span style="color: #ff0000;">ipsec auto --add tunnelVPN
<em>002 "tunnelVPN": added IKEv2 connection</em></span></pre>
<p><span style="color: #ff0000;"><strong>LANCER La commande add tunelVPN sur les deux machines avant de lancer le UP</strong></span><br />
<strong><span style="color: #ff0000;">Quand le add tunnelVPN est lancé sur les deux machines.</span></strong></p>
<pre>[root@vpn-ipsec-left ~]# <span style="color: #ff0000;">ipsec auto --up tunnelVPN</span></pre>
<p><img loading="lazy" decoding="async" width="1612" height="87" class="wp-image-6634" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-182.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-182.png 1612w, https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-182-300x16.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-182-1024x55.png 1024w, https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-182-768x41.png 768w, https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-182-1536x83.png 1536w" sizes="auto, (max-width: 1612px) 100vw, 1612px" /></p>
<pre>[root@vpn-ipsec-left ~]# <span style="color: #ff0000;">ipsec verify</span></pre>
<p><img loading="lazy" decoding="async" width="776" height="321" class="wp-image-6635" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-183.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-183.png 776w, https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-183-300x124.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-183-768x318.png 768w" sizes="auto, (max-width: 776px) 100vw, 776px" /></p>
<h1><span style="color: #000000;">Machine vpn-ipsec-right.house.cpb – Site B</span></h1>
<p>Host&nbsp;: <strong>vpn-ipsec-right.house.cpb</strong></p>
<ul>
<li>vSwitch&nbsp;: <strong>vmbr2</strong>
<ul>
<li><strong>IP&nbsp;:172.32.185.31</strong></li>
</ul>
</li>
<li>OS&nbsp;: <strong>RockyLinux 8.4</strong></li>
<li>vCPU&nbsp;: 2</li>
<li>DD&nbsp;: 8Go</li>
<li>Ram&nbsp;: 2Go</li>
</ul>
<h2><span style="color: #000000;">Update de la machine</span></h2>
<pre>[root@vpn-ipsec-right ~]# <span style="color: #ff0000;">dnf -y update</span></pre>
<h3><span style="color: #000000;">TimeDate</span></h3>
<pre>[root@vpn-ipsec-right ~]# <span style="color: #ff0000;">timedatectl set-timezone "Europe/Paris"&nbsp;</span></pre>
<h3><span style="color: #000000;">Ajout des hosts machine (si pas de DNS)</span></h3>
<pre>[root@vpn-ipsec-right ~]# <span style="color: #ff0000;">echo "192.168.1.56 vpn-ipsec-left vpn-ipsec-left.house.cpb" &gt;&gt; /etc/hosts</span>
[root@vpn-ipsec-right ~]#<span style="color: #ff0000;"> echo "172.32.185.31 vpn-ipsec-right vpn-ipsec-right.house.cpb" &gt;&gt; /etc/hosts</span></pre>
<h3><span style="color: #000000;">Installation package</span></h3>
<pre>[root@vpn-ipsec-right ~]# <span style="color: #ff0000;">yum install libreswan</span></pre>
<h3><img loading="lazy" decoding="async" width="1603" height="264" class="wp-image-6636" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-184.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-184.png 1603w, https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-184-300x49.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-184-1024x169.png 1024w, https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-184-768x126.png 768w, https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-184-1536x253.png 1536w" sizes="auto, (max-width: 1603px) 100vw, 1603px" /></h3>
<h3><span style="color: #000000;">Initialiser la base nss</span></h3>
<pre>[root@vpn-ipsec-right ~]# <span style="color: #ff0000;">systemctl stop ipsec</span>
[root@vpn-ipsec-right ~]# <span style="color: #ff0000;">rm -f /etc/ipsec.d/*db</span>
[root@vpn-ipsec-right ~]# <span style="color: #ff0000;">ls -al /etc/ipsec.d/</span>

[root@vpn-ipsec-right ~]# <span style="color: #ff0000;">ipsec initnss
<em>Initializing NSS database</em></span></pre>
<h3><span style="color: #000000;">Ajouter les règles Firewall</span></h3>
<pre>[root@vpn-ipsec-right ~]# <span style="color: #ff0000;">firewall-cmd --add-service=ipsec --permanent</span>
[root@vpn-ipsec-right ~]# <span style="color: #ff0000;">firewall-cmd --remove-service={cockpit,dhcpv6-client} --permanent</span>
[root@vpn-ipsec-right ~]# <span style="color: #ff0000;">firewall-cmd --reload</span></pre>
<h3><span style="color: #000000;">Désactiver «&nbsp;rp_filter&nbsp;» de Libreswan</span></h3>
<pre>[root@vpn-ipsec-right ~]# <span style="color: #ff0000;">echo "net.ipv4.conf.all.rp_filter = 0" &gt;&gt; /etc/sysctl.d/50-libreswan.conf</span>
[root@vpn-ipsec-right ~]# <span style="color: #ff0000;">sysctl --system</span></pre>
<h3><span style="color: #000000;">Démarrer le service</span></h3>
<pre>[root@vpn-ipsec-right ~]# <span style="color: #ff0000;">systemctl enable ipsec --now</span>
[root@vpn-ipsec-right ~]# <span style="color: #ff0000;">systemctl status ipsec</span></pre>
<p><img loading="lazy" decoding="async" width="1244" height="434" class="wp-image-6637" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-185.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-185.png 1244w, https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-185-300x105.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-185-1024x357.png 1024w, https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-185-768x268.png 768w" sizes="auto, (max-width: 1244px) 100vw, 1244px" /></p>
<h3><span style="color: #000000;">Générer une cléf RSA</span></h3>
<pre>[root@vpn-ipsec-right ~]#<span style="color: #ff0000;"> ipsec newhostkey
<em>Generated RSA key pair with CKAID 957f4e4b42de1ec6a61af4e58796747e5dc264b3 was stored in the NSS database</em>
<em>The public key can be displayed using: ipsec showhostkey --left --ckaid 957f4e4b42de1ec6a61af4e58796747e5dc264b3</em></span>

[root@vpn-ipsec-right ~]# <span style="color: #ff0000;">ipsec showhostkey --<strong>right</strong> --ckaid</span> <span style="color: #ff0000;">957f4e4b42de1ec6a61af4e58796747e5dc264b3</span>
<span style="color: #ff0000;"><em>
 # rsakey AwEAAdptc</em>

<strong><em>rightrsasigkey</em></strong><em>=0sAwEAAdptcCuPX9bb9VoI+Y8jW8CJTXNPFqXrg5Q1AGqLfrr/2Pyc9m3GkkaBtZDIWVYAE5JpSHwFAwrAvONaeldppssCjsch8tRXTYOCD0MnI44VTn1L1b6L/ofECV/Hm1CIfzE82MJiIWekrfxfj34AnZplSPc8oTZZm7J0n4yEUC452Y7zeWBH/OA4vIFRnk8MY3JrsKMI3zt4LkFL828mWyXhqU2qLtNm/cjPf2wlczv0U6EgFIB8V6XmnD+TZZkBid0NziNrXKc/BdSRB4ZFk0VbH2BoM7TcwgQurAacODb6dWRxG+fxyYAn0STQbwfVUwcymVtAjQFj3jT0GAUbc6IdEQiQNuGuS6K0uhYWShODE+P9fSDWHZnIEtHGQzyU/BDUZnjwYAVV2h6kZvdFQoMOCGQYVM8PIWR8yZTR8hHdj2dsLb/XM/AzLJaf35bBSYAnp1RJRwjtMMjXraxJ2ijx/ssezw80gu3Bvj/ntyQDhzFMwQaa37mlqbsHdjxIy7504ylBOyILVkHdqSKZB83kT2XuFWkXHjHVD0yzu/rlE/zQmOaiKuGDgXp6DYUwQN7MM1XdT35DHSBlxrcVs91xusxgeYSD7zFI/WwZtPPf3Bm7BcAlQUz93brQLTr3WuRREDe/pqdT4xDrQw==</em></span></pre>
<h3><span style="color: #000000;">Récupération de la Conf Client left (certificats left et right)</span></h3>
<pre>[root@<strong>vpn-ipsec-left</strong> ~]# <span style="color: #ff0000;">scp /etc/ipsec.d/host_to_host.conf <a style="color: #ff0000;" href="mailto:root@vpn-ipsec-right:/etc/ipsec.d/host_to_host.conf">root@vpn-ipsec-right:/etc/ipsec.d/host_to_host.conf</a></span>

[root@vpn-ipsec-right ~]# <span style="color: #ff0000;">ls -al /etc/ipsec.d/host_to_host.conf
<em>-rw-r--r--. 1 root root 1353 May 22 14:50 /etc/ipsec.d/host_to_host.conf</em></span></pre>
<h3><span style="color: #000000;">Mise en place Tunnel entre les Hosts</span></h3>
<pre>[root@vpn-ipsec-right ~]# <span style="color: #ff0000;">systemctl restart ipsec</span>
[root@vpn-ipsec-right ~]# <span style="color: #ff0000;">ipsec auto --add tunnelVPN
<em>002 "tunnelVPN": added IKEv2 connection</em></span>

[root@vpn-ipsec-right ~]# <span style="color: #ff0000;">ipsec auto --up tunnelVPN</span></pre>
<p><img loading="lazy" decoding="async" width="1621" height="110" class="wp-image-6638" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-186.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-186.png 1621w, https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-186-300x20.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-186-1024x69.png 1024w, https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-186-768x52.png 768w, https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-186-1536x104.png 1536w" sizes="auto, (max-width: 1621px) 100vw, 1621px" /></p>
<pre>[root@vpn-ipsec-right ~]# <span style="color: #ff0000;">ipsec verify</span></pre>
<p><img loading="lazy" decoding="async" width="808" height="329" class="wp-image-6639" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-187.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-187.png 808w, https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-187-300x122.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-187-768x313.png 768w" sizes="auto, (max-width: 808px) 100vw, 808px" /></p>
<h1><span style="color: #000000;">Check le Tunnel entre les Hosts (2 machines)</span></h1>
<h3><span style="color: #000000;">Sur vpn-ipsec-right</span></h3>
<pre>[root@vpn-ipsec-right ~]# <span style="color: #ff0000;">journalctl –xe</span></pre>
<p><img loading="lazy" decoding="async" width="1598" height="592" class="wp-image-6640" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-188.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-188.png 1598w, https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-188-300x111.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-188-1024x379.png 1024w, https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-188-768x285.png 768w, https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-188-1536x569.png 1536w" sizes="auto, (max-width: 1598px) 100vw, 1598px" /></p>
<h3><span style="color: #000000;">Sur vpn-ipsec-left</span></h3>
<p><img loading="lazy" decoding="async" width="1596" height="386" class="wp-image-6641" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-189.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-189.png 1596w, https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-189-300x73.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-189-1024x248.png 1024w, https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-189-768x186.png 768w, https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-189-1536x371.png 1536w" sizes="auto, (max-width: 1596px) 100vw, 1596px" /></p>
<pre>[root@<strong><span style="color: #ff0000;">vpn-ipsec-left</span></strong> ~]# <span style="color: #ff0000;">ipsec show
<em>192.168.1.56/32 &lt;=&gt; 172.32.185.31/32 using reqid 16389</em></span></pre>
<p><img loading="lazy" decoding="async" width="549" height="60" class="wp-image-6642" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-190.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-190.png 549w, https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-190-300x33.png 300w" sizes="auto, (max-width: 549px) 100vw, 549px" /></p>
<pre>[root@<strong><span style="color: #ff0000;">vpn-ipsec-right</span></strong> ~]# <span style="color: #ff0000;">ipsec show
<em>172.32.185.31/32 &lt;=&gt; 192.168.1.56/32 using reqid 16389</em></span></pre>
<p><img loading="lazy" decoding="async" width="552" height="65" class="wp-image-6643" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-191.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-191.png 552w, https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-191-300x35.png 300w" sizes="auto, (max-width: 552px) 100vw, 552px" /></p>
<pre>[root@<span style="color: #ff0000;">vpn-ipsec-left</span> ~]# <span style="color: #ff0000;">ipsec look</span></pre>
<p><img loading="lazy" decoding="async" width="1418" height="837" class="wp-image-6644" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-192.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-192.png 1418w, https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-192-300x177.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-192-1024x604.png 1024w, https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-192-768x453.png 768w" sizes="auto, (max-width: 1418px) 100vw, 1418px" /></p>
<p><strong>Le tunnel VPN est bien étable entre les deux clients 192.168.1.56 vers 172.32.185.31</strong></p>
<h1><span style="color: #000000;">Ajoutons les logs(2 machines)</span></h1>
<pre>Editer le fichier <span style="color: #ff0000;">/etc/ipsec.conf</span></pre>
<pre>[root@<strong>vpn-ipsec-xxx</strong>~]# <span style="color: #ff0000;">vi /etc/ipsec.conf
<em>config setup</em>
<em> # If logfile= is unset, syslog is used to send log messages too.</em>
<em> # Note that on busy VPN servers, the amount of logging can trigger</em>
<em> # syslogd (or journald) to rate limit messages.</em>
<strong><em> logfile=/var/log/pluto</em>.log</strong></span></pre>
<h3><span style="color: #000000;">Restart ipsec &#8211; vpn-ipsec-left</span></h3>
<pre>[root@vpn-ipsec-left ~]# <span style="color: #ff0000;">systemctl restart ipsec</span>
[root@vpn-ipsec-left ~]# <span style="color: #ff0000;">ipsec auto --add tunnelVPN</span></pre>
<h3><span style="color: #000000;">Restart ipsec &#8211; vpn-ipsec-right</span></h3>
<pre>[root@vpn-ipsec-right ~]# <span style="color: #ff0000;">systemctl restart ipsec</span>
[root@vpn-ipsec-right ~]# <span style="color: #ff0000;">ipsec auto --add tunnelVPN</span></pre>
<h3><span style="color: #000000;">Restart tunnelVPN &#8211; vpn-ipsec-left et vpn-ipsec-right</span></h3>
<pre>[root@<strong><span style="color: #ff0000;">vpn-ipsec-left</span></strong> ~]# <span style="color: #ff0000;">ipsec auto --up tunnelVPN</span>
[root@<span style="color: #ff0000;"><strong>vpn-ipsec-right</strong></span> ~]# <span style="color: #ff0000;">ipsec auto --up tunnelVP</span></pre>
<h2><span style="color: #000000;">Check le log pluto</span></h2>
<h3><span style="color: #000000;">Check &#8211; vpn-ipsec-left</span></h3>
<pre>[root@vpn-ipsec-left ~]#<span style="color: #ff0000;"> tail -30 /var/log/pluto.log</span></pre>
<p><img loading="lazy" decoding="async" width="1603" height="260" class="wp-image-6645" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-193.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-193.png 1603w, https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-193-300x49.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-193-1024x166.png 1024w, https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-193-768x125.png 768w, https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-193-1536x249.png 1536w" sizes="auto, (max-width: 1603px) 100vw, 1603px" /></p>
<h3><span style="color: #000000;">Check &#8211; vpn-ipsec-right</span></h3>
<pre>[oot@vpn-ipsec-right ~]# <span style="color: #ff0000;">tail -30 /var/log/pluto.log</span></pre>
<p><img loading="lazy" decoding="async" width="1600" height="586" class="wp-image-6646" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-194.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-194.png 1600w, https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-194-300x110.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-194-1024x375.png 1024w, https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-194-768x281.png 768w, https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-194-1536x563.png 1536w" sizes="auto, (max-width: 1600px) 100vw, 1600px" /></p>
<h1><span style="color: #000000;">Ajoutons VPN start Automatique (2 machines)</span></h1>
<pre>[root@<span style="color: #ff0000;">vpn-ipsec-right</span> ~]# <span style="color: #ff0000;">echo "  auto=start" &gt;&gt; /etc/ipsec.d/host_to_host.conf</span>
[root@<span style="color: #ff0000;">vpn-ipsec-left</span> ~]# <span style="color: #ff0000;">echo "  auto=start" &gt;&gt; /etc/ipsec.d/host_to_host.conf</span>

[root@vpn-ipsec-left ~]# <span style="color: #ff0000;">cat /etc/ipsec.d/host_to_host.conf</span></pre>
<p><img loading="lazy" decoding="async" width="745" height="233" class="wp-image-6647" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-195.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-195.png 745w, https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-195-300x94.png 300w" sizes="auto, (max-width: 745px) 100vw, 745px" /></p>
<pre>[root@<strong><span style="color: #ff0000;">vpn-ipsec-left</span></strong> ~]# <span style="color: #ff0000;">ipsec stop &amp;&amp; ipsec start</span>
[root@<strong><span style="color: #ff0000;">vpn-ipsec-left</span></strong> ~]# <span style="color: #ff0000;">ipsec status</span></pre>
<p><img loading="lazy" decoding="async" width="1612" height="517" class="wp-image-6648" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-196.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-196.png 1612w, https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-196-300x96.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-196-1024x328.png 1024w, https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-196-768x246.png 768w, https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-196-1536x493.png 1536w" sizes="auto, (max-width: 1612px) 100vw, 1612px" /></p>
<pre>[root@<strong><span style="color: #ff0000;">vpn-ipsec-right</span></strong> ~]# <span style="color: #ff0000;">ipsec stop &amp;&amp; ipsec start</span>
[root@<strong><span style="color: #ff0000;">vpn-ipsec-right</span> </strong>~]# <span style="color: #ff0000;">ipsec status</span></pre>
<p><img loading="lazy" decoding="async" width="1343" height="291" class="wp-image-6649" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-197.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-197.png 1343w, https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-197-300x65.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-197-1024x222.png 1024w, https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-197-768x166.png 768w" sizes="auto, (max-width: 1343px) 100vw, 1343px" /></p>
<pre>[root@<strong><span style="color: #ff0000;">vpn-ipsec-left</span></strong> ~]# <span style="color: #ff0000;">ping -c 3 vpn-ipsec-right</span></pre>
<p><img loading="lazy" decoding="async" width="734" height="158" class="wp-image-6650" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-198.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-198.png 734w, https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-198-300x65.png 300w" sizes="auto, (max-width: 734px) 100vw, 734px" /></p>
<pre>[root@<span style="color: #ff0000;"><strong>vpn-ipsec-right</strong></span> ~]# <span style="color: #ff0000;">ping -c 3 vpn-ipsec-left</span></pre>
<p><img loading="lazy" decoding="async" width="710" height="158" class="wp-image-6651" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-199.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-199.png 710w, https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-199-300x67.png 300w" sizes="auto, (max-width: 710px) 100vw, 710px" /></p>
<pre>[root@<strong><span style="color: #ff0000;">vpn-ipsec-right</span> </strong>~]# <span style="color: #ff0000;">ipsec showstates</span></pre>
<p><img loading="lazy" decoding="async" width="1294" height="83" class="wp-image-6652" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-200.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-200.png 1294w, https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-200-300x19.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-200-1024x66.png 1024w, https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-200-768x49.png 768w" sizes="auto, (max-width: 1294px) 100vw, 1294px" /></p>
<h2><span style="color: #000000;">Check Transaction SSL entre vpn-ipsec-right =&gt; vpn-ipsec-left</span></h2>
<h3><span style="color: #000000;">Installation tcpflow sur vpn-ipsec-left</span></h3>
<pre>[root@<span style="color: #ff0000;"><strong>vpn-ipsec-left</strong></span> ~]#<span style="color: #ff0000;">dnf install wget</span>
[root@<strong><span style="color: #ff0000;">vpn-ipsec-left</span></strong> ~]#<span style="color: #ff0000;">dnf install https://forensics.cert.org/cert-forensics-tools-release-el8.rpm</span>
[root@<strong><span style="color: #ff0000;">vpn-ipsec-left</span></strong> ~]#<span style="color: #ff0000;">dnf install epel-release</span>
[root@<strong><span style="color: #ff0000;">vpn-ipsec-left</span> </strong>~]#<span style="color: #ff0000;">dnf --enablerepo=forensics install tcpflow</span></pre>
<h2><span style="color: #000000;">Lancement une écoute sur port 22 sur vpn-ipsec-left</span></h2>
<pre>[root@vpn-ipsec-left ~]# <span style="color: #ff0000;">tcpflow -c -p -i any dst port 22 &gt;&gt; ecoute.txt |tail -f ecoute.txt</span></pre>
<h3><span style="color: #000000;">Lancement d’un copie de fichier &#8211; vpn-ipsec-right =&gt; vpn-ipsec-left</span></h3>
<pre>[root@<strong><span style="color: #ff0000;">vpn-ipsec-right</span></strong> chris]# <span style="color: #ff0000;">touch titi.txt</span>
[root@<span style="color: #ff0000;"><strong>vpn-ipsec-right</strong></span> chris]# <span style="color: #ff0000;">scp titi.txt root@192.168.1.56:/home/chris/toto.txt</span>

[root@<span style="color: #ff0000;">vpn-ipsec-left</span> ~]# <span style="color: #ff0000;">cat ecoute.txt</span></pre>
<p><img loading="lazy" decoding="async" width="1549" height="401" class="wp-image-6653" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-201.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-201.png 1549w, https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-201-300x78.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-201-1024x265.png 1024w, https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-201-768x199.png 768w, https://coffeebreak.en-images.info/wp-content/uploads/2022/05/word-image-201-1536x398.png 1536w" sizes="auto, (max-width: 1549px) 100vw, 1549px" /></p>
<p>Views: 3</p><p>L’article <a href="https://coffeebreak.en-images.info/modop-installation-vpn-ipsec-host-to-host/">MODOP installation VPN IPsec – Host to Host</a> est apparu en premier sur <a href="https://coffeebreak.en-images.info">CoffeeBreak Info</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://coffeebreak.en-images.info/modop-installation-vpn-ipsec-host-to-host/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>MODOP – Ajout Client Win10 sur Serveur WireGuard Linux</title>
		<link>https://coffeebreak.en-images.info/modop-ajout-client-win10-sur-serveur-wireguard-linux/</link>
					<comments>https://coffeebreak.en-images.info/modop-ajout-client-win10-sur-serveur-wireguard-linux/#respond</comments>
		
		<dc:creator><![CDATA[chris]]></dc:creator>
		<pubDate>Thu, 14 Apr 2022 10:28:29 +0000</pubDate>
				<category><![CDATA[OS Linux]]></category>
		<category><![CDATA[RedHat/Centos Linux]]></category>
		<category><![CDATA[Sécurité]]></category>
		<category><![CDATA[Système]]></category>
		<category><![CDATA[VPN]]></category>
		<category><![CDATA[Centos]]></category>
		<category><![CDATA[Linux]]></category>
		<category><![CDATA[Serveur]]></category>
		<guid isPermaLink="false">https://coffeebreak.en-images.info/?p=6362</guid>

					<description><![CDATA[<p>En complément du dernier MODOP sur la mise en place d’un service WireGuard et d’un client VPN sous Linux. Nous allons ajouter un client Microsoft avec le client WireGuard. Le but est de connecter un client Win10 sur le serveur WireGuard Linux précédemment configuré, et ainsi permettre la connexion des deux équipements sur un réseau VPN. WireGuard permet la connexion d’OS hétérogène le rendant Multiplateforme.</p>
<p>L’article <a href="https://coffeebreak.en-images.info/modop-ajout-client-win10-sur-serveur-wireguard-linux/">MODOP – Ajout Client Win10 sur Serveur WireGuard Linux</a> est apparu en premier sur <a href="https://coffeebreak.en-images.info">CoffeeBreak Info</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>Host&nbsp;: <strong>open-client02.house.cpb</strong></p>
<ul>
<li>IP:<strong>&nbsp;172.32.185.40</strong></li>
<li>Subnet&nbsp;: 172.32.185.0/24</li>
<li>vSwitch&nbsp;: vmbr2</li>
<li>Disque&nbsp;: 50Go (Système)</li>
<li>RAM&nbsp;:8Go</li>
<li>vCPU&nbsp;: 4</li>
<li>OS&nbsp;:&nbsp;<strong>Windows10</strong></li>
</ul>
<p><img loading="lazy" decoding="async" width="794" height="250" class="wp-image-6363" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-102.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-102.png 794w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-102-300x94.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-102-768x242.png 768w" sizes="auto, (max-width: 794px) 100vw, 794px" /></p>
<h4><span style="color: #000000;"><strong>1°) Installer le Client WireGuard</strong></span></h4>
<ul>
<li><a href="https://download.wireguard.com/windows-client/">https://download.wireguard.com/windows-client/</a></li>
</ul>
<p><img loading="lazy" decoding="async" width="914" height="275" class="wp-image-6364" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-103.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-103.png 914w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-103-300x90.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-103-768x231.png 768w" sizes="auto, (max-width: 914px) 100vw, 914px" /><br />
Télécharger la version MSI souhaitée et lancée.</p>
<p><img loading="lazy" decoding="async" width="447" height="333" class="wp-image-6365" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-104.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-104.png 447w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-104-300x223.png 300w" sizes="auto, (max-width: 447px) 100vw, 447px" /><br />
«&nbsp;<strong>Exécute</strong>r&nbsp;»</p>
<p><img loading="lazy" decoding="async" width="459" height="336" class="wp-image-6366" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-105.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-105.png 459w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-105-300x220.png 300w" sizes="auto, (max-width: 459px) 100vw, 459px" /><br />
«&nbsp;<strong>Oui&nbsp;</strong>»</p>
<p><img loading="lazy" decoding="async" width="633" height="504" class="wp-image-6367" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-106.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-106.png 633w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-106-300x239.png 300w" sizes="auto, (max-width: 633px) 100vw, 633px" /><br />
WireGuard se lance.</p>
<h4><span style="color: #000000;"><strong>2°) Configurer WireGuard Client</strong></span></h4>
<p><img loading="lazy" decoding="async" width="758" height="163" class="wp-image-6368" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-107.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-107.png 758w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-107-300x65.png 300w" sizes="auto, (max-width: 758px) 100vw, 758px" /><br />
«&nbsp;<strong>Ajouter le tunnel</strong>&nbsp;» et «&nbsp;<strong>Ajouter un tunnel vide</strong>&nbsp;»</p>
<h5><span style="color: #000000;"><strong>Pour Rappel des données Serveur </strong></span></h5>
<ul>
<li>IP serveur&nbsp;: <span style="color: #ff0000;">172.16.185.40</span></li>
<li>Public Key Serveur : <span style="color: #ff0000;"><em>H9JrgVaNJh9wmB25K4wlQlG/fVii1um+mhkGApPJXUs=</em></span></li>
<li>Private Key Serveur&nbsp;: <span style="color: #ff0000;"><em>8DLZHyjeS2HHozkYpeaZJM64oGOwYDcbU/i+E1FjQ0Y=</em></span></li>
</ul>
<p><img loading="lazy" decoding="async" width="491" height="395" class="wp-image-6369" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-108.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-108.png 491w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-108-300x241.png 300w" sizes="auto, (max-width: 491px) 100vw, 491px" /><br />
«&nbsp;<strong>Enregistre</strong>r&nbsp;»</p>
<p><img loading="lazy" decoding="async" width="634" height="333" class="wp-image-6370" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-109.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-109.png 634w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-109-300x158.png 300w" sizes="auto, (max-width: 634px) 100vw, 634px" /></p>
<h4><span style="color: #000000;"><strong>3°) Ajout cléf Public du client sur le serveur WireGuard</strong></span></h4>
<ul>
<li>Récupérer la Clef Public du client01 : <span style="color: #ff0000;">IPfz1pVoJZLZf2dsRtsr08RhoGj3JCDsdacwXsUnels=</span></li>
<li>Adresse du Client sur le VPN&nbsp;: <span style="color: #ff0000;"><em>100.10.0.3</em></span></li>
</ul>
<pre>[root@wireguard-server wireguard]# <span style="color: #ff0000;">wg set wg0 peer IPfz1pVoJZLZf2dsRtsr08RhoGj3JCDsdacwXsUnels= allowed-ips 100.10.0.3</span></pre>
<p><img loading="lazy" decoding="async" width="620" height="144" class="wp-image-6371" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-110.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-110.png 620w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-110-300x70.png 300w" sizes="auto, (max-width: 620px) 100vw, 620px" /><br />
Démarrer la connexion VPN avec le server «&nbsp;<strong>Activer&nbsp;</strong>»</p>
<p><img loading="lazy" decoding="async" width="626" height="391" class="wp-image-6372" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-111.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-111.png 626w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-111-300x187.png 300w" sizes="auto, (max-width: 626px) 100vw, 626px" /><br />
La connexion est désormais activée et connectée au serveur wireguard-server</p>
<p><img loading="lazy" decoding="async" width="861" height="487" class="wp-image-6373" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-112.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-112.png 861w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-112-300x170.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-112-768x434.png 768w" sizes="auto, (max-width: 861px) 100vw, 861px" /></p>
<h4><span style="color: #000000;"><strong>4°) Check WireGuard client</strong></span></h4>
<p>Ouvrir un terminal CMD</p>
<pre>C:\Users\admin&gt;<span style="color: #ff0000;"> ipconfig /all</span></pre>
<p><img loading="lazy" decoding="async" width="900" height="470" class="wp-image-6374" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-113.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-113.png 900w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-113-300x157.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-113-768x401.png 768w" sizes="auto, (max-width: 900px) 100vw, 900px" /></p>
<h4><span style="color: #000000;"><strong>Check Client =&gt; Server wireguard via le VPN</strong></span></h4>
<p><img loading="lazy" decoding="async" width="702" height="192" class="wp-image-6375" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-114.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-114.png 702w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-114-300x82.png 300w" sizes="auto, (max-width: 702px) 100vw, 702px" /></p>
<h3><span style="color: #000000;"><strong>Connexion SFTP du client =&gt; Server wireguard via le VPN</strong></span></h3>
<p><img loading="lazy" decoding="async" width="550" height="222" class="wp-image-6376" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-115.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-115.png 550w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-115-300x121.png 300w" sizes="auto, (max-width: 550px) 100vw, 550px" /></p>
<p><img loading="lazy" decoding="async" width="468" height="359" class="wp-image-6377" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-116.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-116.png 468w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-116-300x230.png 300w" sizes="auto, (max-width: 468px) 100vw, 468px" /><br />
«&nbsp;<strong>Oui</strong>&nbsp;»</p>
<p><img loading="lazy" decoding="async" width="937" height="468" class="wp-image-6378" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-117.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-117.png 937w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-117-300x150.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-117-768x384.png 768w" sizes="auto, (max-width: 937px) 100vw, 937px" /></p>
<h5><strong>La connexion VPN est bien ouverte et active.</strong></h5>
<p>Views: 2</p><p>L’article <a href="https://coffeebreak.en-images.info/modop-ajout-client-win10-sur-serveur-wireguard-linux/">MODOP – Ajout Client Win10 sur Serveur WireGuard Linux</a> est apparu en premier sur <a href="https://coffeebreak.en-images.info">CoffeeBreak Info</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://coffeebreak.en-images.info/modop-ajout-client-win10-sur-serveur-wireguard-linux/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>MODOP – Installation WireGuard VPN</title>
		<link>https://coffeebreak.en-images.info/modop-installation-wireguard-vpn-client-serveur/</link>
					<comments>https://coffeebreak.en-images.info/modop-installation-wireguard-vpn-client-serveur/#respond</comments>
		
		<dc:creator><![CDATA[chris]]></dc:creator>
		<pubDate>Thu, 14 Apr 2022 10:08:14 +0000</pubDate>
				<category><![CDATA[OS Linux]]></category>
		<category><![CDATA[RedHat/Centos Linux]]></category>
		<category><![CDATA[Sécurité]]></category>
		<category><![CDATA[Système]]></category>
		<category><![CDATA[VPN]]></category>
		<category><![CDATA[Centos]]></category>
		<category><![CDATA[Linux]]></category>
		<category><![CDATA[Serveur]]></category>
		<guid isPermaLink="false">https://coffeebreak.en-images.info/?p=6323</guid>

					<description><![CDATA[<p>MODOP – Mise en action d’un VPN via le service WireGuard Cient/Serveur. Cette solution permet le chiffrement et l’authentification par un jeu de clef Public/privé afin de créer un tunnel sécurisé entre des équipements. Il est simple et rapide à mettre en place pour sécuriser vos transactions et cela sans avoir besoin de créer/utiliser des PKI spécifique. </p>
<p>L’article <a href="https://coffeebreak.en-images.info/modop-installation-wireguard-vpn-client-serveur/">MODOP – Installation WireGuard VPN</a> est apparu en premier sur <a href="https://coffeebreak.en-images.info">CoffeeBreak Info</a>.</p>
]]></description>
										<content:encoded><![CDATA[<h3><span style="color: #000000;">Inventaire des Machines</span></h3>
<p>Host&nbsp;:<strong> wireguard-server.house.cpb</strong></p>
<ul>
<li>IP:&nbsp;<strong>172.16.185.40</strong></li>
<li>Subnet&nbsp;: 172.16.185.0/24</li>
<li>vSwitch&nbsp;: vmbr1</li>
<li>Disque&nbsp;: 8Go (Système)</li>
<li>RAM&nbsp;:2Go</li>
<li>vCPU&nbsp;: 2</li>
<li>OS&nbsp;:&nbsp;RockyLinux 8</li>
</ul>
<p><img loading="lazy" decoding="async" width="1068" height="277" class="wp-image-6324" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-81.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-81.png 1068w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-81-300x78.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-81-1024x266.png 1024w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-81-768x199.png 768w" sizes="auto, (max-width: 1068px) 100vw, 1068px" /></p>
<p>Host&nbsp;: <strong>wireguard-client01.house.cpb</strong></p>
<ul>
<li>IP:&nbsp;<strong>10.10.0.40</strong></li>
<li>Subnet&nbsp;: 10.10.0.0/24</li>
<li>vSwitch&nbsp;: vmbr4</li>
<li>Disque&nbsp;: 8Go (Système)</li>
<li>RAM&nbsp;:2Go</li>
<li>vCPU&nbsp;: 2</li>
<li>OS&nbsp;:&nbsp;RockyLinux 8</li>
</ul>
<p><img loading="lazy" decoding="async" width="1020" height="289" class="wp-image-6325" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-82.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-82.png 1020w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-82-300x85.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-82-768x218.png 768w" sizes="auto, (max-width: 1020px) 100vw, 1020px" /></p>
<p>Les deux machines doivent être joignable mutuellement.</p>
<h4><span style="color: #000000;"><strong>Check wireguard-server (172.16.185.40) =&gt; wireguard-client01(10.10.0.40)</strong></span></h4>
<pre>[root@wireguard-server ~]# <span style="color: #ff0000;">echo "10.10.0.40 wireguard-client01" &gt;&gt; /etc/hosts</span>
[root@wireguard-server ~]# <span style="color: #ff0000;">ping -c 3 wireguard-client01</span></pre>
<p><img loading="lazy" decoding="async" width="733" height="175" class="wp-image-6326" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-83.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-83.png 733w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-83-300x72.png 300w" sizes="auto, (max-width: 733px) 100vw, 733px" /></p>
<h4><span style="color: #000000;"><strong>wireguard-client01(10.10.0.40) =&gt; Check wireguard-server (172.16.185.40)</strong></span></h4>
<pre>[root@wireguard-client01 ~]# <span style="color: #ff0000;">echo "172.16.185.40 wireguard-server" &gt;&gt; /etc/hosts</span>
[root@wireguard-client01 ~]# <span style="color: #ff0000;">ping -c 3 wireguard-server</span></pre>
<p><img loading="lazy" decoding="async" width="734" height="174" class="wp-image-6327" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-84.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-84.png 734w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-84-300x71.png 300w" sizes="auto, (max-width: 734px) 100vw, 734px" /></p>
<h2 style="text-align: center;"><span style="color: #000000;">Installation Serveur VPN WireGuard &#8211; RockyLinux</span></h2>
<h4><span style="color: #000000;"><strong>1°) Mise à jour</strong></span></h4>
<pre>[root@wireguard-server ~]#<span style="color: #ff0000;"> dnf -y update</span></pre>
<h4><span style="color: #000000;"><strong>2°) Désactivation IPv6 (Option)</strong></span></h4>
<pre>[root@open-serveurvpn ~]#<span style="color: #ff0000;"> echo "net.ipv6.conf.all.disable_ipv6 = 1" &gt;&gt; /etc/sysctl.conf</span>
[root@open-serveurvpn ~]# <span style="color: #ff0000;">echo "net.ipv6.conf.all.autoconf = 0" &gt;&gt; /etc/sysctl.conf</span>
[root@open-serveurvpn ~]# <span style="color: #ff0000;">echo "net.ipv6.conf.default.disable_ipv6 = 1" &gt;&gt; /etc/sysctl.conf</span>
[root@open-serveurvpn ~]# <span style="color: #ff0000;">echo "net.ipv6.conf.default.autoconf = 0" &gt;&gt; /etc/sysctl.conf</span>
[root@open-serveurvpn ~]# <span style="color: #ff0000;">sysctl -p</span></pre>
<h4><span style="color: #000000;"><strong>3°) Installation des dépendances </strong></span></h4>
<pre>[root@wireguard-server ~]# <span style="color: #ff0000;">dnf install epel-release</span>
[root@wireguard-server ~]#<span style="color: #ff0000;"> yum install elrepo-release</span></pre>
<h4><span style="color: #000000;"><strong>4°) Installation WireGuard VPN</strong></span></h4>
<p>[root@wireguard-server ~]#<span style="color: #ff0000;"> dnf search wireguard</span></p>
<p><img loading="lazy" decoding="async" width="938" height="143" class="wp-image-6328" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-85.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-85.png 938w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-85-300x46.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-85-768x117.png 768w" sizes="auto, (max-width: 938px) 100vw, 938px" /></p>
<pre>[root@wireguard-server ~]#<span style="color: #ff0000;"> dnf -y install wireguard-tools kmod-wireguard</span></pre>
<h4><span style="color: #000000;"><strong>5°) Création des clefs Public/Privée pour le&nbsp; Server </strong></span></h4>
<pre>[root@wireguard-server ~]# <span style="color: #ff0000;">cd /etc/wireguard/</span>
[root@wireguard-server wireguard]# <span style="color: #ff0000;">wg genkey | tee /etc/wireguard/privatekey | wg pubkey | tee /etc/wireguard/publickey</span>

[root@wireguard-server wireguard]# <span style="color: #ff0000;">cat publickey</span>
<span style="color: #ff0000;"><em>H9JrgVaNJh9wmB25K4wlQlG/fVii1um+mhkGApPJXUs=</em></span>

[root@wireguard-server wireguard]# <span style="color: #ff0000;">cat privatekey</span>
<span style="color: #ff0000;"><em>8DLZHyjeS2HHozkYpeaZJM64oGOwYDcbU/i+E1FjQ0Y=</em></span></pre>
<h4><span style="color: #000000;"><strong>6°) Création/Configuration du server VPN</strong></span></h4>
<pre>[root@wireguard-server wireguard]# <span style="color: #ff0000;">vi wg0.conf</span>

<em><span style="color: #ff0000;">[Interface]</span></em>
<em><span style="color: #ff0000;">Address = <strong>100.10.0.1/24</strong></span></em>
<em><span style="color: #ff0000;">SaveConfig = true</span></em>
<em><span style="color: #ff0000;">ListenPort = <strong>51820</strong></span></em>
<em><span style="color: #ff0000;">PrivateKey = <strong>8DLZHyjeS2HHozkYpeaZJM64oGOwYDcbU/i+E1FjQ0Y=</strong></span></em>
<em><span style="color: #ff0000;">PostUp = firewall-cmd --zone=public --add-port 51820/udp &amp;&amp; firewall-cmd --zone=public --add-masquerade</span></em>
<em><span style="color: #ff0000;">PostDown = firewall-cmd --zone=public --remove-port 51820/udp &amp;&amp; firewall-cmd --zone=public --remove-masquerade</span></em></pre>
<pre>[root@wireguard-server wireguard]# <span style="color: #ff0000;">chmod 600 /etc/wireguard/{privatekey,wg0.conf}</span></pre>
<pre>[root@wireguard-server wireguard]# <span style="color: #ff0000;">echo "net.ipv4.ip_forward = 1" &gt;&gt; /etc/sysctl.conf</span>
[root@wireguard-server wireguard]# <span style="color: #ff0000;">sysctl –p</span></pre>
<p><strong><img loading="lazy" decoding="async" width="736" height="125" class="wp-image-6329" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-86.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-86.png 736w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-86-300x51.png 300w" sizes="auto, (max-width: 736px) 100vw, 736px" /></strong></p>
<h4><span style="color: #000000;"><strong>7°) Démarrage du server VPN </strong></span></h4>
<pre>[root@wireguard-server wireguard]#<span style="color: #ff0000;"> wg-quick up wg0</span></pre>
<p><img loading="lazy" decoding="async" width="855" height="195" class="wp-image-6330" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-87.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-87.png 855w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-87-300x68.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-87-768x175.png 768w" sizes="auto, (max-width: 855px) 100vw, 855px" /></p>
<pre>[root@wireguard-server wireguard]# <span style="color: #ff0000;">ip addr</span></pre>
<p><img loading="lazy" decoding="async" width="877" height="229" class="wp-image-6331" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-88.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-88.png 877w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-88-300x78.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-88-768x201.png 768w" sizes="auto, (max-width: 877px) 100vw, 877px" /></p>
<p><strong>Le VPN est monté sur la Carte Virtuelle wg0 et le Subnet 100.10.0.0/24</strong></p>
<h4><span style="color: #000000;"><strong>8°) Démarrage du service  » boot machine »&nbsp;</strong></span></h4>
<pre>[root@wireguard-server wireguard]# <span style="color: #ff0000;">systemctl enable wg-quick@wg0</span>
[root@wireguard-server wireguard]# <span style="color: #ff0000;">wg-quick down wg0</span>
[root@wireguard-server wireguard]# <span style="color: #ff0000;">systemctl start wg-quick@wg0</span>
[root@wireguard-server wireguard]# <span style="color: #ff0000;">systemctl status wg-quick@wg0</span></pre>
<p><img loading="lazy" decoding="async" width="1253" height="372" class="wp-image-6332" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-89.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-89.png 1253w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-89-300x89.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-89-1024x304.png 1024w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-89-768x228.png 768w" sizes="auto, (max-width: 1253px) 100vw, 1253px" /></p>
<pre>[root@wireguard-server wireguard]# <span style="color: #ff0000;">wg show wg0</span></pre>
<p><img loading="lazy" decoding="async" width="584" height="105" class="wp-image-6333" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-90.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-90.png 584w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-90-300x54.png 300w" sizes="auto, (max-width: 584px) 100vw, 584px" /></p>
<pre>[root@wireguard-server wireguard]#<span style="color: #ff0000;"> ip a show wg0</span></pre>
<p><img loading="lazy" decoding="async" width="821" height="100" class="wp-image-6334" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-91.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-91.png 821w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-91-300x37.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-91-768x94.png 768w" sizes="auto, (max-width: 821px) 100vw, 821px" /></p>
<p><strong><span style="text-decoration: underline;">Côté Firewall</span></strong></p>
<pre>[root@wireguard-server wireguard]# <span style="color: #ff0000;">firewall-cmd --list-all</span></pre>
<p><span style="color: #000000;"><img loading="lazy" decoding="async" width="686" height="250" class="wp-image-6335" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-92.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-92.png 686w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-92-300x109.png 300w" sizes="auto, (max-width: 686px) 100vw, 686px" /> </span></p>
<h2 style="text-align: center;"><span style="color: #000000;">Installation Client Linux VPN WireGuard – RockyLinux</span></h2>
<h4><span style="color: #000000;"><strong>1°) Mise à jour</strong></span></h4>
<pre>[root@wireguard-client01 ~]# <span style="color: #ff0000;">dnf -y update</span></pre>
<h4><span style="color: #000000;"><strong>2°) Désactivation IPv6 (Option)</strong></span></h4>
<pre>[root@wireguard-client01 ~]# <span style="color: #ff0000;">echo "net.ipv6.conf.all.disable_ipv6 = 1" &gt;&gt; /etc/sysctl.conf</span>
[root@wireguard-client01 ~]# <span style="color: #ff0000;">echo "net.ipv6.conf.all.autoconf = 0" &gt;&gt; /etc/sysctl.conf</span>
[root@wireguard-client01 ~]#<span style="color: #ff0000;"> echo "net.ipv6.conf.default.disable_ipv6 = 1" &gt;&gt; /etc/sysctl.conf</span>
[root@wireguard-client01 ~]# <span style="color: #ff0000;">echo "net.ipv6.conf.default.autoconf = 0" &gt;&gt; /etc/sysctl.conf</span>
[root@wireguard-client01 ~]# <span style="color: #ff0000;">sysctl -p</span></pre>
<h4><span style="color: #000000;"><strong>3°) Installation des dépendances </strong></span></h4>
<pre>[root@wireguard-client01 ~]# <span style="color: #ff0000;">dnf install epel-release elrepo-release</span></pre>
<h4><span style="color: #000000;"><strong>4°) Installation WireGuard VPN</strong></span></h4>
<pre>[root@wireguard-client01 ~]# <span style="color: #ff0000;">dnf install kmod-wireguard wireguard-tools –y</span></pre>
<h4><span style="color: #000000;"><strong>5°) Création des certificats Client01</strong></span></h4>
<pre>[root@wireguard-client01 ~]#<span style="color: #ff0000;"> cd /etc/wireguard/</span>
[root@wireguard-client01 <span style="color: #ff0000;">wireguard]# wg genkey | tee /etc/wireguard/privatekey | wg pubkey | tee /etc/wireguard/publickey</span>

[root@wireguard-client01 wireguard]# <span style="color: #ff0000;">cat /etc/wireguard/privatekey</span>
<span style="color: #ff0000;"><em>gLHwqTDBJtw2wYfCdqvBthcmpDsDqtCC+FKeKOZaaVo=</em></span>

[root@wireguard-client01 wireguard]# <span style="color: #ff0000;">cat /etc/wireguard/publickey</span>
<span style="color: #ff0000;"><em>bXbsDi3C2PThp8Eq8dmPtmiwNteEhexjyq4NHAtg/0U=</em></span></pre>
<h4><span style="color: #000000;"><strong>6°) Création/Configuration du client01 VPN</strong></span></h4>
<pre>[root@wireguard-client01 wireguard]#<span style="color: #ff0000;"> vi wg0.conf</span></pre>
<p><img loading="lazy" decoding="async" width="592" height="150" class="wp-image-6336" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-93.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-93.png 592w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-93-300x76.png 300w" sizes="auto, (max-width: 592px) 100vw, 592px" /></p>
<pre><span style="color: #ff0000;"><em>[Interface]</em></span>
<span style="color: #ff0000;"><em>#Clef Privée du client</em></span>
<span style="color: #ff0000;"><em>PrivateKey = <strong>gLHwqTDBJtw2wYfCdqvBthcmpDsDqtCC+FKeKOZaaVo=</strong></em></span>
<span style="color: #ff0000;"><em>#Adresse du client sur le VPN</em></span>
<span style="color: #ff0000;"><em>Address = <strong>100.10.0.2/24</strong></em></span>

<span style="color: #ff0000;"><em>[Peer]</em></span>
<span style="color: #ff0000;"><em>#Clef Public du serveur</em></span>
<span style="color: #ff0000;"><em>PublicKey = <strong>H9JrgVaNJh9wmB25K4wlQlG/fVii1um+mhkGApPJXUs=</strong></em></span>
<span style="color: #ff0000;"><em>#Adresse et port du Serveur WireGuard</em></span>
<span style="color: #ff0000;"><em>Endpoint = <strong>wireguard-server:51820</strong></em></span>
<span style="color: #ff0000;"><em>AllowedIPs = 0.0.0.0/0</em></span></pre>
<h4><span style="color: #000000;"><strong>7°) Ajout Clef Public du client01 sur le serveur WireGuard</strong></span></h4>
<ul>
<li>Clef Public du client01&nbsp;:<span style="color: #ff0000;"> <em>bXbsDi3C2PThp8Eq8dmPtmiwNteEhexjyq4NHAtg/0U=</em></span></li>
<li>Adresse du Client sur le VPN&nbsp;:<span style="color: #ff0000;"> <em>100.10.0.2</em></span></li>
</ul>
<pre>[root@<span style="color: #ff0000;">wireguard-server</span> wireguard]# <span style="color: #ff0000;">wg set wg0 peer bXbsDi3C2PThp8Eq8dmPtmiwNteEhexjyq4NHAtg/0U= allowed-ips 100.10.0.2</span></pre>
<h4><span style="color: #000000;"><strong>8°) Démarrage du client VPN </strong></span></h4>
<pre>[root@wireguard-client01 wireguard]# <span style="color: #ff0000;">wg-quick up wg0</span></pre>
<p><img loading="lazy" decoding="async" width="951" height="191" class="wp-image-6337" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-94.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-94.png 951w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-94-300x60.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-94-768x154.png 768w" sizes="auto, (max-width: 951px) 100vw, 951px" /></p>
<pre>[root@wireguard-client01 wireguard]# <span style="color: #ff0000;">ip addr</span></pre>
<p><img loading="lazy" decoding="async" width="952" height="223" class="wp-image-6338" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-95.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-95.png 952w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-95-300x70.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-95-768x180.png 768w" sizes="auto, (max-width: 952px) 100vw, 952px" /></p>
<p><strong>Le VPN (Client01) est monté sur la Carte Virtuelle wg0 et le Subnet 100.10.0.0/24</strong></p>
<h4><span style="color: #000000;">9°) Démarrage du service « boot machine »</span></h4>
<pre>[root@wireguard-client01 wireguard]# <span style="color: #ff0000;">systemctl enable wg-quick@wg0</span>
[root@wireguard-client01 wireguard]# <span style="color: #ff0000;">wg-quick down wg0</span>
[root@wireguard-client01 wireguard]#<span style="color: #ff0000;"> systemctl start wg-quick@wg0</span>
[root@wireguard-client01 wireguard]#<span style="color: #ff0000;"> systemctl status wg-quick@wg0</span></pre>
<p><img loading="lazy" decoding="async" width="979" height="372" class="wp-image-6339" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-96.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-96.png 979w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-96-300x114.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-96-768x292.png 768w" sizes="auto, (max-width: 979px) 100vw, 979px" /></p>
<pre>[root@wireguard-client01 wireguard]# <span style="color: #ff0000;">wg show wg0</span></pre>
<p><img loading="lazy" decoding="async" width="697" height="184" class="wp-image-6340" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-97.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-97.png 697w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-97-300x79.png 300w" sizes="auto, (max-width: 697px) 100vw, 697px" /></p>
<pre>[root@wireguard-client01 wireguard]# <span style="color: #ff0000;">ip a show wg0</span></pre>
<p><img loading="lazy" decoding="async" width="866" height="100" class="wp-image-6341" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-98.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-98.png 866w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-98-300x35.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-98-768x89.png 768w" sizes="auto, (max-width: 866px) 100vw, 866px" /></p>
<h4><span style="color: #000000;"><strong>10°) Check connexion</strong></span></h4>
<h4><span style="color: #000000;">Check de wireguard-client01 =&gt; wireguard-server via réseau VPN</span></h4>
<pre>[root@wireguard-client01 wireguard]# <span style="color: #ff0000;">ping -c 3 100.10.0.1</span></pre>
<p><img loading="lazy" decoding="async" width="611" height="165" class="wp-image-6342" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-99.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-99.png 611w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-99-300x81.png 300w" sizes="auto, (max-width: 611px) 100vw, 611px" /></p>
<h4><span style="color: #000000;">Check de wireguard-server =&gt; wireguard-client01 via réseau VPN</span></h4>
<pre>[root@wireguard-server log]# <span style="color: #ff0000;">ping -c 3 100.10.0.2</span></pre>
<p><img loading="lazy" decoding="async" width="692" height="160" class="wp-image-6343" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-100.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-100.png 692w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-100-300x69.png 300w" sizes="auto, (max-width: 692px) 100vw, 692px" /></p>
<h4><span style="color: #000000;">Connexion SSH du client01 sur le Serveur</span></h4>
<pre>[root@wireguard-client01 wireguard]# <span style="color: #ff0000;">ssh -l root 100.10.0.1</span></pre>
<p><img loading="lazy" decoding="async" width="762" height="231" class="wp-image-6344" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-101.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-101.png 762w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-101-300x91.png 300w" sizes="auto, (max-width: 762px) 100vw, 762px" /></p>
<p>On se connecte bien sur la machine serveur à partir de notre client via le réseau VPN.</p>
<p>Views: 3</p><p>L’article <a href="https://coffeebreak.en-images.info/modop-installation-wireguard-vpn-client-serveur/">MODOP – Installation WireGuard VPN</a> est apparu en premier sur <a href="https://coffeebreak.en-images.info">CoffeeBreak Info</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://coffeebreak.en-images.info/modop-installation-wireguard-vpn-client-serveur/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>MODOP – Ajout Client Windows sur Serveur OpenVPN Linux</title>
		<link>https://coffeebreak.en-images.info/modop-ajout-client-windows-sur-serveur-openvpn-linux/</link>
					<comments>https://coffeebreak.en-images.info/modop-ajout-client-windows-sur-serveur-openvpn-linux/#respond</comments>
		
		<dc:creator><![CDATA[chris]]></dc:creator>
		<pubDate>Wed, 13 Apr 2022 10:40:26 +0000</pubDate>
				<category><![CDATA[OS Linux]]></category>
		<category><![CDATA[Sécurité]]></category>
		<category><![CDATA[Système]]></category>
		<category><![CDATA[VPN]]></category>
		<category><![CDATA[Windows]]></category>
		<category><![CDATA[Centos]]></category>
		<category><![CDATA[Linux]]></category>
		<category><![CDATA[Serveur]]></category>
		<category><![CDATA[WIndows]]></category>
		<guid isPermaLink="false">https://coffeebreak.en-images.info/?p=6276</guid>

					<description><![CDATA[<p>En complément du précédent mode opératoire sur la mise en place d’un service OpenVPN et d’un client VPN sous Linux. Nous allons aborder, dans ce nouveau MODOP,  le déploiement d’un client Microsoft avec le client OpenVPN GUI. Le but est de connecter un client Win10 sur le serveur OpenVPN Linux précédemment configuré, et ainsi permettre la connexion des deux équipements sur un réseau VPN.</p>
<p>L’article <a href="https://coffeebreak.en-images.info/modop-ajout-client-windows-sur-serveur-openvpn-linux/">MODOP – Ajout Client Windows sur Serveur OpenVPN Linux</a> est apparu en premier sur <a href="https://coffeebreak.en-images.info">CoffeeBreak Info</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p><img loading="lazy" decoding="async" width="1458" height="546" class="wp-image-6277" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-48.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-48.png 1458w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-48-300x112.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-48-1024x383.png 1024w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-48-768x288.png 768w" sizes="auto, (max-width: 1458px) 100vw, 1458px" /></p>
<p>Host : <strong>open-client02.house.cpb</strong></p>
<ul>
<li>IP: <strong>172.32.185.30</strong></li>
<li>Subnet : 172.32.185.0/24</li>
<li>vSwitch : vmbr2</li>
<li>Disque : 50Go (Système)</li>
<li>RAM :8Go</li>
<li>vCPU : 4</li>
<li>OS : Windows10</li>
</ul>
<p><img loading="lazy" decoding="async" width="883" height="259" class="wp-image-6278" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-49.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-49.png 883w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-49-300x88.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-49-768x225.png 768w" sizes="auto, (max-width: 883px) 100vw, 883px" /></p>
<p><span style="color: #ff0000;">Les deux machines doivent être joignable mutuellement.</span></p>
<h4><span style="text-decoration: underline; color: #000000;"><strong>Check open-serveurvpn (172.16.185.30) =&gt; open-client02(172.32.185.30)</strong></span></h4>
<pre>[root@open-servervpn pki]# <span style="color: #ff0000;">echo "172.32.185.30 open-client02" &gt;&gt; /etc/hosts</span>
[root@open-servervpn pki]# <span style="color: #ff0000;">ping -c 3 open-client02</span></pre>
<p><img loading="lazy" decoding="async" width="700" height="158" class="wp-image-6279" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-50.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-50.png 700w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-50-300x68.png 300w" sizes="auto, (max-width: 700px) 100vw, 700px" /></p>
<h4><span style="text-decoration: underline;"><span style="color: #000000; text-decoration: underline;"><strong>Check open-client02 (172.32.185.30) =&gt; open-serveurvpn (172.16.185.30)</strong></span></span></h4>
<p><strong><img loading="lazy" decoding="async" width="1199" height="477" class="wp-image-6280" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-51.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-51.png 1199w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-51-300x119.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-51-1024x407.png 1024w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-51-768x306.png 768w" sizes="auto, (max-width: 1199px) 100vw, 1199px" /></strong></p>
<pre>C:\Users\admin&gt; <span style="color: #ff0000;">ping open-servervpn</span></pre>
<p><img loading="lazy" decoding="async" width="761" height="177" class="wp-image-6281" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-52.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-52.png 761w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-52-300x70.png 300w" sizes="auto, (max-width: 761px) 100vw, 761px" /></p>
<h3><span style="color: #000000;"><strong>1°) Génération des certificats pour le client02 sur le Serveur OpenVPN</strong></span></h3>
<pre>[root@open-servervpn ~]# <span style="color: #ff0000;">cd /etc/openvpn</span></pre>
<h4><span style="color: #000000;"><strong>Création des certificats du Client</strong></span></h4>
<pre>[root@open-servervpn openvpn]# <span style="color: #ff0000;">./easyrsa gen-req open-client02 nopass</span></pre>
<p><img loading="lazy" decoding="async" width="1397" height="381" class="wp-image-6282" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-53.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-53.png 1397w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-53-300x82.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-53-1024x279.png 1024w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-53-768x209.png 768w" sizes="auto, (max-width: 1397px) 100vw, 1397px" /></p>
<h4><span style="color: #000000;"><strong>Signature du certificat du Client avec les RootCA</strong></span></h4>
<pre>[root@open-servervpn openvpn]# <span style="color: #ff0000;">./easyrsa sign-req client open-client02 nopass</span></pre>
<p><img loading="lazy" decoding="async" width="985" height="287" class="wp-image-6283" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-54.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-54.png 985w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-54-300x87.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-54-768x224.png 768w" sizes="auto, (max-width: 985px) 100vw, 985px" /></p>
<h4><span style="color: #000000;"><strong>Inventaire du certificat du Client</strong></span></h4>
<pre>[root@open-servervpn openvpn]# <span style="color: #ff0000;">ls -al /etc/openvpn/pki/{issued,private} |grep client02</span></pre>
<p><img loading="lazy" decoding="async" width="719" height="91" class="wp-image-6284" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-55.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-55.png 719w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-55-300x38.png 300w" sizes="auto, (max-width: 719px) 100vw, 719px" /></p>
<h4><span style="color: #000000;"><strong>Préparation pour le transfert </strong></span></h4>
<pre>[root@open-servervpn openvpn]#<span style="color: #ff0000;"> mkdir win10</span>
[root@open-servervpn openvpn]# <span style="color: #ff0000;">cp pki/ca.crt win10</span>
[root@open-servervpn openvpn]# <span style="color: #ff0000;">cp pki/private/open-client02.key win10</span>
[root@open-servervpn openvpn]# <span style="color: #ff0000;">cp pki/issued/open-client02.crt win10</span>
[root@open-servervpn openvpn]# <span style="color: #ff0000;">ls -al win10</span></pre>
<p><img loading="lazy" decoding="async" width="708" height="128" class="wp-image-6285" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-56.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-56.png 708w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-56-300x54.png 300w" sizes="auto, (max-width: 708px) 100vw, 708px" /></p>
<h3><span style="color: #000000;"><strong>2°) Installation du Client OpenVPN sur Windows10</strong></span></h3>
<ul>
<li><strong><em>https://openvpn.net/community-downloads/</em></strong></li>
</ul>
<p><img loading="lazy" decoding="async" width="958" height="588" class="wp-image-6286" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-57.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-57.png 958w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-57-300x184.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-57-768x471.png 768w" sizes="auto, (max-width: 958px) 100vw, 958px" /><br />
Choisir le client souhaité, pour ma part la version 64Bits et lancer celui-ci</p>
<p><img loading="lazy" decoding="async" width="454" height="271" class="wp-image-6287" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-58.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-58.png 454w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-58-300x179.png 300w" sizes="auto, (max-width: 454px) 100vw, 454px" /><br />
« <strong>Exécuter</strong> »</p>
<p><img loading="lazy" decoding="async" width="542" height="436" class="wp-image-6288" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-59.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-59.png 542w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-59-300x241.png 300w" sizes="auto, (max-width: 542px) 100vw, 542px" /><br />
« <strong>Install Now</strong> »</p>
<p><img loading="lazy" decoding="async" width="526" height="344" class="wp-image-6289" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-60.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-60.png 526w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-60-300x196.png 300w" sizes="auto, (max-width: 526px) 100vw, 526px" /><br />
« <strong>Oui</strong> »</p>
<p><img loading="lazy" decoding="async" width="527" height="292" class="wp-image-6290" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-61.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-61.png 527w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-61-300x166.png 300w" sizes="auto, (max-width: 527px) 100vw, 527px" /><br />
Laisser l’installation se dérouler</p>
<p><img loading="lazy" decoding="async" width="530" height="425" class="wp-image-6291" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-62.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-62.png 530w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-62-300x241.png 300w" sizes="auto, (max-width: 530px) 100vw, 530px" /><br />
« <strong>Close</strong> »</p>
<p><img loading="lazy" decoding="async" width="552" height="255" class="wp-image-6292" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-63.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-63.png 552w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-63-300x139.png 300w" sizes="auto, (max-width: 552px) 100vw, 552px" /></p>
<h3><span style="color: #000000;"><strong>3°) Récupérer les certificats Client </strong></span></h3>
<p>Lancer le client WinSCP</p>
<p><img loading="lazy" decoding="async" width="467" height="88" class="wp-image-6293" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-64.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-64.png 467w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-64-300x57.png 300w" sizes="auto, (max-width: 467px) 100vw, 467px" /></p>
<p><img loading="lazy" decoding="async" width="623" height="303" class="wp-image-6294" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-65.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-65.png 623w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-65-300x146.png 300w" sizes="auto, (max-width: 623px) 100vw, 623px" /><br />
Remplir les données de votre serveur OpenVPN et « <strong>connexion </strong>»</p>
<p><img loading="lazy" decoding="async" width="466" height="349" class="wp-image-6295" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-66.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-66.png 466w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-66-300x225.png 300w" sizes="auto, (max-width: 466px) 100vw, 466px" /><br />
«<strong> Oui</strong> »</p>
<p><img loading="lazy" decoding="async" width="939" height="327" class="wp-image-6296" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-67.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-67.png 939w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-67-300x104.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-67-768x267.png 768w" sizes="auto, (max-width: 939px) 100vw, 939px" /><br />
Copier vos certificats du serveur Linux vers <strong>c:\tmp\*.*</strong></p>
<p><img loading="lazy" decoding="async" width="977" height="592" class="wp-image-6297" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-68.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-68.png 977w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-68-300x182.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-68-768x465.png 768w" sizes="auto, (max-width: 977px) 100vw, 977px" /><br />
Déplacer vos certificats de<strong> c:\tmp\*.*</strong> vers <strong>c:\Programmes\OpenVPN\Config</strong></p>
<h3><span style="color: #000000;"><strong>4°) Configuration du Client OpenVPN</strong></span></h3>
<p><span style="color: #ff0000;"><em>Sur votre Serveur Linux, éviter de faire cela via le fichier « sample-client » pour des raisons de pré-formatage de caractère.</em></span></p>
<pre>[root@open-servervpn server]# <span style="color: #ff0000;">cd /etc/openvpn/client</span></pre>
<pre>[root@open-servervpn client]# <span style="color: #ff0000;">vi client.ovpn</span>

<span style="color: #ff0000;"><em>client</em></span>
<span style="color: #ff0000;"><em>dev tun</em></span>
<span style="color: #ff0000;"><em>proto udp</em></span>
<span style="color: #ff0000;"><em>remote <strong>open-servervpn</strong></em></span>
<span style="color: #ff0000;"><em>port 1194</em></span>
<strong><span style="color: #ff0000;"><em>ca ca.crt</em></span></strong>
<strong><span style="color: #ff0000;"><em>cert open-client02.crt</em></span></strong>
<strong><span style="color: #ff0000;"><em>key open-client02.key</em></span></strong>
<span style="color: #ff0000;"><em>verb 5</em></span>
<span style="color: #ff0000;"><em>remote-cert-tls server</em></span>
<span style="color: #ff0000;"><em>auth-nocache</em></span>
<span style="color: #ff0000;"><em>cipher AES-256-CGM</em></span></pre>
<p>Sauvegarder et transférer à votre client sur la ressource <strong>c:\Programmes\OpenVPN\Config\*</strong></p>
<h3><span style="color: #000000;"><strong>5°) Lancement du Client « Mode Test &#8211; Console »</strong></span></h3>
<p><img loading="lazy" decoding="async" width="1230" height="361" class="wp-image-6298" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-69.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-69.png 1230w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-69-300x88.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-69-1024x301.png 1024w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-69-768x225.png 768w" sizes="auto, (max-width: 1230px) 100vw, 1230px" /><br />
Clique droit de souris «<strong> Start OpenVPN on this config file </strong>»</p>
<p><img loading="lazy" decoding="async" width="929" height="531" class="wp-image-6299" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-70.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-70.png 929w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-70-300x171.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-70-768x439.png 768w" sizes="auto, (max-width: 929px) 100vw, 929px" /><br />
« <strong>Autoriser l’accès</strong> »<br />
Le terminal du fond, trace les interactions avec votre serveur de VPN</p>
<h3><span style="color: #000000;"><strong>6°) Check de connexion </strong></span></h3>
<h4><span style="color: #000000;"><strong>Côté logs Serveur </strong></span><br />
<img loading="lazy" decoding="async" width="1558" height="185" class="wp-image-6300" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-71.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-71.png 1558w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-71-300x36.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-71-1024x122.png 1024w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-71-768x91.png 768w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-71-1536x182.png 1536w" sizes="auto, (max-width: 1558px) 100vw, 1558px" /></h4>
<p><span style="color: #000000;"><strong>Côté Client</strong></span><br />
<span style="color: #000000;">Dans un terminal Wndows</span></p>
<pre>C:\Users\admin&gt; <span style="color: #ff0000;">ipconfig /all</span></pre>
<p><img loading="lazy" decoding="async" width="882" height="303" class="wp-image-6301" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-72.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-72.png 882w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-72-300x103.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-72-768x264.png 768w" sizes="auto, (max-width: 882px) 100vw, 882px" /></p>
<h4><span style="text-decoration: underline;"><span style="color: #000000;"><strong>Open-client02 =&gt; open-servervpn via réseau VPN 10.8.0.0/24</strong></span></span></h4>
<pre>C:\Users\admin&gt; <span style="color: #ff0000;">ping 10.8.0.1</span></pre>
<p><img loading="lazy" decoding="async" width="866" height="201" class="wp-image-6302" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-73.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-73.png 866w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-73-300x70.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-73-768x178.png 768w" sizes="auto, (max-width: 866px) 100vw, 866px" /></p>
<h4><span style="text-decoration: underline; color: #000000;"><strong>Open-client02 =&gt; open-client01 via réseau VPN 10.8.0.0/24</strong></span></h4>
<pre>C:\Users\admin&gt; <span style="color: #ff0000;">ping 10.8.0.2</span></pre>
<p><img loading="lazy" decoding="async" width="753" height="196" class="wp-image-6303" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-74.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-74.png 753w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-74-300x78.png 300w" sizes="auto, (max-width: 753px) 100vw, 753px" /></p>
<h3><span style="color: #000000;"><strong>7°) Lancement du Client « Mode GUI »</strong></span></h3>
<p><strong>Ajouter le fichier à OpenVPN-GUI</strong></p>
<p><img loading="lazy" decoding="async" width="979" height="292" class="wp-image-6304" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-75.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-75.png 979w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-75-300x89.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-75-768x229.png 768w" sizes="auto, (max-width: 979px) 100vw, 979px" /><br />
Clic droit sur le fichier et « <strong>import into OpenVPN-Gui</strong> »</p>
<p><img loading="lazy" decoding="async" width="431" height="104" class="wp-image-6305" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-76.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-76.png 431w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-76-300x72.png 300w" sizes="auto, (max-width: 431px) 100vw, 431px" /><br />
Lancer votre Client OpenVPN</p>
<p><img loading="lazy" decoding="async" width="511" height="130" class="wp-image-6306" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-77.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-77.png 511w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-77-300x76.png 300w" sizes="auto, (max-width: 511px) 100vw, 511px" /><br />
Se rendre en bas à droite et clic droit sur l’icône</p>
<p><img loading="lazy" decoding="async" width="538" height="248" class="wp-image-6307" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-78.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-78.png 538w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-78-300x138.png 300w" sizes="auto, (max-width: 538px) 100vw, 538px" /><br />
« <strong>Connecter</strong> »</p>
<p><img loading="lazy" decoding="async" width="618" height="365" class="wp-image-6308" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-79.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-79.png 618w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-79-300x177.png 300w" sizes="auto, (max-width: 618px) 100vw, 618px" /><br />
Le client va se connecter au serveur VPN</p>
<p><img loading="lazy" decoding="async" width="552" height="153" class="wp-image-6309" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-80.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-80.png 552w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-80-300x83.png 300w" sizes="auto, (max-width: 552px) 100vw, 552px" /><br />
L’icône OpenVPN passe au<strong><span style="color: #00ff00;"> vert</span></strong>.</p>
<h3><span style="color: #000000;">Vous êtes à présent connecté en VPN.</span></h3>
<p>Views: 18</p><p>L’article <a href="https://coffeebreak.en-images.info/modop-ajout-client-windows-sur-serveur-openvpn-linux/">MODOP – Ajout Client Windows sur Serveur OpenVPN Linux</a> est apparu en premier sur <a href="https://coffeebreak.en-images.info">CoffeeBreak Info</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://coffeebreak.en-images.info/modop-ajout-client-windows-sur-serveur-openvpn-linux/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>MODOP – Installation OpenVPN (Easy-RSA3) &#8211; Client/serveur</title>
		<link>https://coffeebreak.en-images.info/modop-installation-openvpn-easy-rsa3-client-serveur/</link>
					<comments>https://coffeebreak.en-images.info/modop-installation-openvpn-easy-rsa3-client-serveur/#respond</comments>
		
		<dc:creator><![CDATA[chris]]></dc:creator>
		<pubDate>Tue, 12 Apr 2022 10:23:14 +0000</pubDate>
				<category><![CDATA[Applications]]></category>
		<category><![CDATA[OS Linux]]></category>
		<category><![CDATA[RedHat/Centos Linux]]></category>
		<category><![CDATA[Sécurité]]></category>
		<category><![CDATA[Système]]></category>
		<category><![CDATA[Centos]]></category>
		<category><![CDATA[Linux]]></category>
		<category><![CDATA[Serveur]]></category>
		<category><![CDATA[Virtualisation]]></category>
		<category><![CDATA[VPN]]></category>
		<guid isPermaLink="false">https://coffeebreak.en-images.info/?p=6206</guid>

					<description><![CDATA[<p>MODOP – Mise en place d’une solution VPN avec l’aide des services OpenVPN et Easy-RSA afin de sécuriser du trafic de données entre deux Subnet/Infrastructure différents via un réseau virtuel privé. Les Certificats Racine CA, Serveur et Clients seront générés via le service Easy-RSA. Le tunnel (Réseau virtuel privé) VPN sera lancé via le service OpenVPN en s’appuyant sur les certificats générés précédemment. Le mécanisme du VPN permet de sécuriser, authentifier, encrypter des DATA bout à bout entre deux équipements et garanti la confidentialité et l’intégrité des transactions.</p>
<p>L’article <a href="https://coffeebreak.en-images.info/modop-installation-openvpn-easy-rsa3-client-serveur/">MODOP – Installation OpenVPN (Easy-RSA3) &#8211; Client/serveur</a> est apparu en premier sur <a href="https://coffeebreak.en-images.info">CoffeeBreak Info</a>.</p>
]]></description>
										<content:encoded><![CDATA[<h1><img loading="lazy" decoding="async" class="aligncenter wp-image-6207 size-full" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image.png" alt="" width="1466" height="424" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image.png 1466w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-300x87.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-1024x296.png 1024w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-768x222.png 768w" sizes="auto, (max-width: 1466px) 100vw, 1466px" /></h1>
<h3><span style="color: #000000;"><strong>Inventaire des Machines</strong></span></h3>
<p>Host&nbsp;: <strong>open-serveurVPN.house.cpb</strong></p>
<ul>
<li>IP:&nbsp;<strong>172.16.185.30</strong></li>
<li>Subnet&nbsp;: 172.16.185.0/24</li>
<li>vSwitch&nbsp;:<strong> vmbr1</strong></li>
<li>Disque&nbsp;: 8Go (Système)</li>
<li>RAM&nbsp;:2Go</li>
<li>vCPU&nbsp;: 2</li>
<li>OS&nbsp;:&nbsp;RockyLinux 8</li>
</ul>
<p><img loading="lazy" decoding="async" width="1043" height="277" class="wp-image-6208" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-1.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-1.png 1043w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-1-300x80.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-1-1024x272.png 1024w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-1-768x204.png 768w" sizes="auto, (max-width: 1043px) 100vw, 1043px" /></p>
<p>Host&nbsp;:<strong> open-client01.house.cpb</strong></p>
<ul>
<li>IP:<strong>&nbsp;10.10.0.30</strong></li>
<li>Subnet&nbsp;: 10.10.0.0/24</li>
<li>vSwitch&nbsp;:<strong> vmbr4</strong></li>
<li>Disque&nbsp;: 8Go (Système)</li>
<li>RAM&nbsp;:2Go</li>
<li>vCPU&nbsp;: 2</li>
<li>OS : RockyLinux 8</li>
</ul>
<p><img loading="lazy" decoding="async" width="1034" height="282" class="wp-image-6209" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-2.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-2.png 1034w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-2-300x82.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-2-1024x279.png 1024w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-2-768x209.png 768w" sizes="auto, (max-width: 1034px) 100vw, 1034px" /></p>
<p><strong>Le Pool de machine VPN</strong></p>
<p><img loading="lazy" decoding="async" width="1033" height="170" class="wp-image-6210" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-3.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-3.png 1033w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-3-300x49.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-3-1024x169.png 1024w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-3-768x126.png 768w" sizes="auto, (max-width: 1033px) 100vw, 1033px" /></p>
<p>Les deux machines doivent être joignable mutuellement.</p>
<h3><span style="color: #000000;"><strong>Check open-serveurvpn (172.16.185.30) =&gt; open-client01(10.10.0.30)</strong></span></h3>
<pre>[root@open-servervpn pki]# <span style="color: #ff0000;">echo "10.10.0.30 open-client01" &gt;&gt; /etc/hosts</span>
[root@open-servervpn pki]# <span style="color: #ff0000;">ping -c 3 open-client01</span></pre>
<p><img loading="lazy" decoding="async" width="761" height="174" class="wp-image-6211" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-4.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-4.png 761w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-4-300x69.png 300w" sizes="auto, (max-width: 761px) 100vw, 761px" /></p>
<h3><span style="color: #000000;"><strong>Check open-client01(10.10.0.30) =&gt; open-serveurvpn (172.16.185.30)</strong></span></h3>
<pre>[root@open-client01 ~]# <span style="color: #ff0000;">echo "172.16.185.30 open-servervpn" &gt;&gt; /etc/hosts</span>
[root@open-client01 ~]#<span style="color: #ff0000;"> ping -c 3 open-servervpn</span></pre>
<p><img loading="lazy" decoding="async" width="708" height="158" class="wp-image-6212" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-5.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-5.png 708w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-5-300x67.png 300w" sizes="auto, (max-width: 708px) 100vw, 708px" /></p>
<h2 style="text-align: center;"><span style="color: #000000;">Installation Serveur VPN &#8211; RockyLinux</span></h2>
<h4><span style="color: #000000;"><strong>1°) Mise à jour</strong></span></h4>
<pre>[root@open-serveurvpn ~]# <span style="color: #ff0000;">dnf -y update</span></pre>
<h4><span style="color: #000000;"><strong>2°) Désactivation IPv6 (Option)</strong></span></h4>
<pre>[root@open-serveurvpn ~]# <span style="color: #ff0000;">ip addr</span></pre>
<p><strong><img loading="lazy" decoding="async" width="894" height="198" class="wp-image-6213" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-6.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-6.png 894w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-6-300x66.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-6-768x170.png 768w" sizes="auto, (max-width: 894px) 100vw, 894px" /></strong></p>
<pre>[root@open-serveurvpn ~]# <span style="color: #ff0000;">echo "net.ipv6.conf.all.disable_ipv6 = 1" &gt;&gt; /etc/sysctl.conf</span>
[root@open-serveurvpn ~]# <span style="color: #ff0000;">echo "net.ipv6.conf.all.autoconf = 0" &gt;&gt; /etc/sysctl.conf</span>
[root@open-serveurvpn ~]# <span style="color: #ff0000;">echo "net.ipv6.conf.default.disable_ipv6 = 1" &gt;&gt; /etc/sysctl.conf</span>
[root@open-serveurvpn ~]# <span style="color: #ff0000;">echo "net.ipv6.conf.default.autoconf = 0" &gt;&gt; /etc/sysctl.conf</span>
[root@open-serveurvpn ~]# <span style="color: #ff0000;">sysctl -p</span></pre>
<pre>[root@open-serveurvpn ~]#<span style="color: #ff0000;"> ip addr</span></pre>
<p><img loading="lazy" decoding="async" width="987" height="154" class="wp-image-6214" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-7.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-7.png 987w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-7-300x47.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-7-768x120.png 768w" sizes="auto, (max-width: 987px) 100vw, 987px" /></p>
<h4><span style="color: #000000;"><strong>3°) Installation EPEL</strong></span></h4>
<pre>[root@open-serveurvpn ~]# <span style="color: #ff0000;">dnf install -y epel-release</span></pre>
<p><img loading="lazy" decoding="async" width="1576" height="473" class="wp-image-6215" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-8.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-8.png 1576w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-8-300x90.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-8-1024x307.png 1024w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-8-768x230.png 768w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-8-1536x461.png 1536w" sizes="auto, (max-width: 1576px) 100vw, 1576px" /></p>
<h4><span style="color: #000000;"><strong>4°) Installation OpenVPN et Paquets de création PKI</strong></span></h4>
<pre>[root@open-serveurvpn ~]# <span style="color: #ff0000;">dnf install -y openvpn easy-rsa</span></pre>
<p><img loading="lazy" decoding="async" width="1542" height="776" class="wp-image-6216" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-9.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-9.png 1542w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-9-300x151.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-9-1024x515.png 1024w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-9-768x386.png 768w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-9-1536x773.png 1536w" sizes="auto, (max-width: 1542px) 100vw, 1542px" /></p>
<h4><span style="color: #000000;"><strong>5°) Préparation de notre PKI </strong></span></h4>
<pre>[root@open-serveurvpn ~]# <span style="color: #ff0000;">cd /usr/share/easy-rsa/3.0.8</span>
[root@open-serveurvpn 3.0.8]# <span style="color: #ff0000;">ls -al</span></pre>
<p><img loading="lazy" decoding="async" width="629" height="144" class="wp-image-6217" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-10.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-10.png 629w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-10-300x69.png 300w" sizes="auto, (max-width: 629px) 100vw, 629px" /></p>
<pre>[root@open-serveurvpn 3.0.8]# <span style="color: #ff0000;">cp -r * /etc/openvpn/.</span>
[root@open-serveurvpn 3.0.8]# <span style="color: #ff0000;">cd /etc/openvpn/</span></pre>
<pre>[root@open-serveurvpn ]# <span style="color: #ff0000;">vi vars</span>

<span style="color: #ff0000;"><em>set_var EASYRSA "$PWD"</em></span>
<span style="color: #ff0000;"><em>set_var EASYRSA_PKI "$EASYRSA/pki"</em></span>
<span style="color: #ff0000;"><em>set_var EASYRSA_DN "cn_only"</em></span>
<span style="color: #ff0000;"><em>set_var EASYRSA_REQ_COUNTRY "FR"</em></span>
<span style="color: #ff0000;"><em>set_var EASYRSA_REQ_PROVINCE "PARIS"</em></span>
<span style="color: #ff0000;"><em>set_var EASYRSA_REQ_CITY "Fontenay ss Bois"</em></span>
<span style="color: #ff0000;"><em>set_var EASYRSA_REQ_ORG "House Corp"</em></span>
<span style="color: #ff0000;"><em>set_var EASYRSA_REQ_EMAIL "chris@house.cpb"</em></span>
<span style="color: #ff0000;"><em>set_var EASYRSA_REQ_OU "House Corp EASY CA"</em></span>
<span style="color: #ff0000;"><em>set_var EASYRSA_KEY_SIZE 4096</em></span>
<span style="color: #ff0000;"><em>set_var EASYRSA_ALGO rsa</em></span>
<span style="color: #ff0000;"><em>set_var EASYRSA_CA_EXPIRE 3650</em></span>
<span style="color: #ff0000;"><em>set_var EASYRSA_CERT_EXPIRE 3650</em></span>
<span style="color: #ff0000;"><em>set_var EASYRSA_NS_SUPPORT "no"</em></span>
<span style="color: #ff0000;"><em>set_var EASYRSA_NS_COMMENT "House Corp CERTIFICATE AUTHORITY"</em></span>
<span style="color: #ff0000;"><em>set_var EASYRSA_EXT_DIR "$EASYRSA/x509-types"</em></span>
<span style="color: #ff0000;"><em>set_var EASYRSA_SSL_CONF "$EASYRSA/openssl-easyrsa.cnf"</em></span>
<span style="color: #ff0000;"><em>set_var EASYRSA_DIGEST "sha256"</em></span></pre>
<pre>[root@open-serveurvpn ]# <span style="color: #ff0000;">chmod +x vars</span></pre>
<h4><span style="color: #000000;"><strong>7°) Initialisation des PKI</strong></span></h4>
<pre>[root@open-serveurvpn ]#<span style="color: #ff0000;"> ./easyrsa init-pki</span></pre>
<p><img loading="lazy" decoding="async" width="672" height="148" class="wp-image-6218" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-11.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-11.png 672w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-11-300x66.png 300w" sizes="auto, (max-width: 672px) 100vw, 672px" /></p>
<pre>[root@open-serveurvpn ]# <span style="color: #ff0000;">ls /etc/openvpn/vars</span>
<span style="color: #ff0000;"><em>/etc/openvpn/vars</em></span>

[root@open-serveurvpn ]# <span style="color: #ff0000;">ls /etc/openvpn/pki</span>
<span style="color: #ff0000;"><em>private reqs</em></span></pre>
<h4><span style="color: #000000;"><strong>8°) Création des certificats root CA</strong></span></h4>
<pre>[root@open-serveurvpn ]# <span style="color: #ff0000;">./easyrsa build-ca nopass</span></pre>
<p><img loading="lazy" decoding="async" width="1383" height="336" class="wp-image-6219" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-12.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-12.png 1383w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-12-300x73.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-12-1024x249.png 1024w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-12-768x187.png 768w" sizes="auto, (max-width: 1383px) 100vw, 1383px" /></p>
<pre>[root@open-serveurvpn ]# <span style="color: #ff0000;">ls /etc/openvpn/pki/<em>ca.crt</em></span>
<span style="color: #ff0000;"><em>/etc/openvpn/pki/ca.crt</em></span></pre>
<h4><span style="color: #000000;"><strong>9°) Création des certificats du Server</strong></span></h4>
<pre>[root@open-serveurvpn ]#<span style="color: #ff0000;">./easyrsa gen-req <strong>open-serveurvpn</strong> nopass</span></pre>
<p><img loading="lazy" decoding="async" width="1302" height="359" class="wp-image-6220" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-13.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-13.png 1302w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-13-300x83.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-13-1024x282.png 1024w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-13-768x212.png 768w" sizes="auto, (max-width: 1302px) 100vw, 1302px" /></p>
<pre>[root@open-serveurvpn ]# <span style="color: #ff0000;">ls -al /etc/openvpn/pki/{reqs,private}</span></pre>
<p><img loading="lazy" decoding="async" width="805" height="228" class="wp-image-6221" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-14.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-14.png 805w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-14-300x85.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-14-768x218.png 768w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-14-800x228.png 800w" sizes="auto, (max-width: 805px) 100vw, 805px" /></p>
<p><strong>Signature de la clef serveur avec le certificat CA</strong></p>
<pre>[root@open-serveurvpn ]#<span style="color: #ff0000;">./easyrsa sign-req server open-serveurvpn nopass</span></pre>
<p><img loading="lazy" decoding="async" width="1251" height="303" class="wp-image-6222" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-15.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-15.png 1251w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-15-300x73.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-15-1024x248.png 1024w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-15-768x186.png 768w" sizes="auto, (max-width: 1251px) 100vw, 1251px" /></p>
<pre>[root@open-serveurvpn ]# <span style="color: #ff0000;">ls -a /etc/openvpn/pki/issued/open-serveurvpn.crt</span>
<span style="color: #ff0000;"><em>/etc/openvpn/pki/issued/open-serveurvpn.crt</em></span></pre>
<h4><span style="color: #000000;"><strong>10°) Création des certificats du Client</strong></span></h4>
<pre>[root@open-servervpn openvpn]# <span style="color: #ff0000;">./easyrsa gen-req open-client01 nopass</span></pre>
<p><img loading="lazy" decoding="async" width="998" height="355" class="wp-image-6223" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-16.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-16.png 998w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-16-300x107.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-16-768x273.png 768w" sizes="auto, (max-width: 998px) 100vw, 998px" /></p>
<pre>[root@open-servervpn openvpn]# <span style="color: #ff0000;">./easyrsa sign-req client open-client01 nopass</span></pre>
<p><strong><img loading="lazy" decoding="async" width="836" height="266" class="wp-image-6224" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-17.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-17.png 836w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-17-300x95.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-17-768x244.png 768w" sizes="auto, (max-width: 836px) 100vw, 836px" /></strong></p>
<pre>[root@open-servervpn openvpn]# <span style="color: #ff0000;">ls -al /etc/openvpn/pki/{issued,private}</span></pre>
<p><strong><img loading="lazy" decoding="async" width="776" height="243" class="wp-image-6225" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-18.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-18.png 776w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-18-300x94.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-18-768x240.png 768w" sizes="auto, (max-width: 776px) 100vw, 776px" /></strong></p>
<h4><span style="color: #000000;"><strong>11°) Création du certificat « Diffie hellman »</strong></span></h4>
<pre>[root@open-servervpn openvpn]#<span style="color: #ff0000;"> ./easyrsa gen-dh</span></pre>
<p><img loading="lazy" decoding="async" width="1319" height="373" class="wp-image-6226" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-19.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-19.png 1319w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-19-300x85.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-19-1024x290.png 1024w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-19-768x217.png 768w" sizes="auto, (max-width: 1319px) 100vw, 1319px" /></p>
<p>….. Après quelques minutes</p>
<p><strong><img loading="lazy" decoding="async" width="1175" height="297" class="wp-image-6227" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-20.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-20.png 1175w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-20-300x76.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-20-1024x259.png 1024w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-20-768x194.png 768w" sizes="auto, (max-width: 1175px) 100vw, 1175px" /></strong></p>
<h4><span style="color: #000000;"><strong>Inventaire des PKI</strong></span></h4>
<pre>[root@open-servervpn openvpn]# <span style="color: #ff0000;">ls -al pki/{ca.crt,dh.pem,issued,private}</span></pre>
<p><strong><img loading="lazy" decoding="async" width="1041" height="299" class="wp-image-6228" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-21.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-21.png 1041w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-21-300x86.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-21-1024x294.png 1024w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-21-768x221.png 768w" sizes="auto, (max-width: 1041px) 100vw, 1041px" /></strong></p>
<h4><span style="color: #000000;"><strong>12°) Création fichier de conf OpenVPN server</strong></span></h4>
<pre>[root@open-servervpn openvpn]# <span style="color: #ff0000;">cd /etc/openvpn/server</span>
[root@open-servervpn server]# <span style="color: #ff0000;">cp /usr/share/doc/openvpn/sample/sample-config-files/server.conf .</span></pre>
<pre>[root@open-servervpn server]# <span style="color: #ff0000;">vi server.conf</span></pre>
<p><strong><span style="text-decoration: underline;">Ligne 78</span></strong></p>
<pre><span style="color: #ff0000;"><em>ca /etc/openvpn/pki/<strong>ca.crt</strong></em></span>
<span style="color: #ff0000;"><em>cert /etc/openvpn/pki/issued/<strong>open-serveurvpn.crt</strong></em></span>
<span style="color: #ff0000;"><em>key /etc/openvpn/pki/private/<strong>open-serveurvpn.key</strong></em></span></pre>
<p><img loading="lazy" decoding="async" width="573" height="87" class="wp-image-6229" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-22.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-22.png 573w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-22-300x46.png 300w" sizes="auto, (max-width: 573px) 100vw, 573px" /></p>
<p><strong><span style="text-decoration: underline;">Ligne 85</span></strong></p>
<pre><span style="color: #ff0000;"><em>dh /etc/openvpn/pki/<strong>dh.pem</strong></em></span></pre>
<p><img loading="lazy" decoding="async" width="440" height="63" class="wp-image-6230" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-23.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-23.png 440w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-23-300x43.png 300w" sizes="auto, (max-width: 440px) 100vw, 440px" /></p>
<p><strong><span style="text-decoration: underline;">Ligne 92</span></strong></p>
<pre><em>;topology subnet</em>
<span style="color: #ff0000;"><em>topology subnet</em></span></pre>
<p><img loading="lazy" decoding="async" width="477" height="68" class="wp-image-6231" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-24.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-24.png 477w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-24-300x43.png 300w" sizes="auto, (max-width: 477px) 100vw, 477px" /></p>
<p><strong><span style="text-decoration: underline;">Ligne 102</span></strong></p>
<pre><span style="color: #ff0000;"><em>server 10.8.0.0 255.255.255.0</em></span></pre>
<p><img loading="lazy" decoding="async" width="533" height="63" class="wp-image-6232" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-25.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-25.png 533w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-25-300x35.png 300w" sizes="auto, (max-width: 533px) 100vw, 533px" /></p>
<h6><span style="color: #ff0000;"><em>Il est fortement conseillé de changer le Subnet VIP pour les échanges sur le VPN.</em></span></h6>
<h6><span style="color: #ff0000;"><em>Dans notre MODOP nous allons laisser la conf d’orgine.</em></span></h6>
<p><span style="text-decoration: underline;"><strong>Ligne 193</strong></span></p>
<pre><span style="color: #ff0000;"><em>push "redirect-gateway def1 bypass-dhcp"</em></span></pre>
<p><img loading="lazy" decoding="async" width="464" height="74" class="wp-image-6233" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-26.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-26.png 464w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-26-300x48.png 300w" sizes="auto, (max-width: 464px) 100vw, 464px" /></p>
<p><strong><span style="text-decoration: underline;">Ligne 202</span></strong></p>
<pre><em>;push ;"dhcp-option DNS 208.67.222.222"</em>
<span style="color: #ff0000;"><em>push "dhcp-option DNS 8.8.8.8"</em></span>
<em>;push "dhcp-option DNS 208.67.220.220"</em>
<span style="color: #ff0000;"><em>push "dhcp-option DNS 8.8.4.4"</em></span></pre>
<p><img loading="lazy" decoding="async" width="548" height="95" class="wp-image-6234" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-27.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-27.png 548w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-27-300x52.png 300w" sizes="auto, (max-width: 548px) 100vw, 548px" /></p>
<p><span style="text-decoration: underline;"><strong>Ligne 247</strong></span></p>
<pre><em><span style="color: #ff0000;">#</span>tls-auth ta.key 0 # This file is secret</em></pre>
<p><img loading="lazy" decoding="async" width="431" height="58" class="wp-image-6235" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-28.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-28.png 431w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-28-300x40.png 300w" sizes="auto, (max-width: 431px) 100vw, 431px" /></p>
<p><strong><span style="text-decoration: underline;">Ligne 277</span></strong></p>
<pre><span style="color: #ff0000;"><em>user nobody</em></span>
<span style="color: #ff0000;"><em>group nobody</em></span></pre>
<p><img loading="lazy" decoding="async" width="342" height="52" class="wp-image-6236" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-29.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-29.png 342w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-29-300x46.png 300w" sizes="auto, (max-width: 342px) 100vw, 342px" /></p>
<p><strong>Sauvegarder le fichier et sortir.</strong></p>
<h4><span style="color: #000000;"><strong>13°) Configure partie réseau</strong></span></h4>
<p><strong>Activer le forward « ipv4 »</strong></p>
<pre>[root@open-servervpn server]# <span style="color: #ff0000;">echo "net.ipv4.ip_forward=1" &gt;&gt; /etc/sysctl.conf</span>
[root@open-servervpn server]# <span style="color: #ff0000;">sysctl -p</span></pre>
<p><img loading="lazy" decoding="async" width="539" height="117" class="wp-image-6237" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-30.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-30.png 539w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-30-300x65.png 300w" sizes="auto, (max-width: 539px) 100vw, 539px" /></p>
<p><strong>Régles Firewall</strong></p>
<pre>[root@open-servervpn server]# <span style="color: #ff0000;">firewall-cmd --set-default-zone=trusted</span>
[root@open-servervpn server]# <span style="color: #ff0000;">firewall-cmd --add-masquerade --permanent</span>
[root@open-servervpn server]# <span style="color: #ff0000;">firewall-cmd --add-service=openvpn --permanent</span>
[root@open-servervpn server]# <span style="color: #ff0000;">firewall-cmd --reload</span></pre>
<p><img loading="lazy" decoding="async" width="701" height="155" class="wp-image-6238" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-31.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-31.png 701w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-31-300x66.png 300w" sizes="auto, (max-width: 701px) 100vw, 701px" /></p>
<pre>[root@open-servervpn server]# <span style="color: #ff0000;">firewall-cmd --list-all</span></pre>
<p><img loading="lazy" decoding="async" width="605" height="250" class="wp-image-6239" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-32.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-32.png 605w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-32-300x124.png 300w" sizes="auto, (max-width: 605px) 100vw, 605px" /></p>
<h4><span style="color: #000000;"><strong>14°) Lancement OpenVPN serveur</strong></span></h4>
<p><strong>Désactivation SELinux</strong></p>
<pre>[root@open-servervpn server]# <span style="color: #ff0000;">getenforce</span>
<em><span style="color: #ff0000;">Enforcing</span> </em>

[root@open-servervpn server]# <span style="color: #ff0000;">setenforce 0</span></pre>
<pre>[root@open-servervpn server]# <span style="color: #ff0000;">vi /etc/sysconfig/selinux</span>
<span style="color: #ff0000;"><em>SELINUX=disabled</em></span></pre>
<p><strong>Test de la config</strong></p>
<pre>[root@open-servervpn server]# <span style="color: #ff0000;">openvpn --config server.conf</span></pre>
<p><img loading="lazy" decoding="async" width="1300" height="289" class="wp-image-6240" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-33.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-33.png 1300w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-33-300x67.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-33-1024x228.png 1024w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-33-768x171.png 768w" sizes="auto, (max-width: 1300px) 100vw, 1300px" /><br />
«&nbsp;<strong>CTR+C pour sortir&nbsp;</strong>»</p>
<p><strong>Lancement du service</strong></p>
<pre>[root@open-servervpn server]# <span style="color: #ff0000;">systemctl enable openvpn-server@server --now</span>
[root@open-servervpn server]# <span style="color: #ff0000;">systemctl status openvpn-server@server</span></pre>
<p><img loading="lazy" decoding="async" width="1569" height="418" class="wp-image-6241" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-34.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-34.png 1569w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-34-300x80.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-34-1024x273.png 1024w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-34-768x205.png 768w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-34-1536x409.png 1536w" sizes="auto, (max-width: 1569px) 100vw, 1569px" /></p>
<p><strong>Vérification du Tunnel</strong></p>
<pre>[root@open-servervpn server]# <span style="color: #ff0000;">ip addr</span></pre>
<p><img loading="lazy" decoding="async" width="1033" height="237" class="wp-image-6242" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-35.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-35.png 1033w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-35-300x69.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-35-1024x235.png 1024w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-35-768x176.png 768w" sizes="auto, (max-width: 1033px) 100vw, 1033px" /></p>
<h2 style="text-align: center;"><span style="color: #000000;">Installation OpenVPN Client RHEL 8</span></h2>
<h4><span style="color: #000000;"><strong>1°) Installation EPEL</strong></span></h4>
<pre>[root@open-client01 ~]# <span style="color: #ff0000;">dnf install -y epel-release</span></pre>
<h4><span style="color: #000000;"><strong>2°) Installation OpenVPN</strong></span></h4>
<pre>[root@open-client01 ~]# <span style="color: #ff0000;">dnf install -y openvpn</span></pre>
<h4><span style="color: #000000;"><strong>3°) Copie des certificats publics sur le client </strong></span></h4>
<h4><span style="text-decoration: underline;"><span style="color: #000000; text-decoration: underline;"><strong>Sur le serveur</strong></span></span></h4>
<p><strong>Cléf Public Autorité</strong></p>
<pre>[root@open-servervpn ~]#<span style="color: #ff0000;"> cd /etc/openvpn/pki</span>
[root@open-servervpn pki]# <span style="color: #ff0000;">scp ca.crt root@open-client01:/etc/openvpn/client/ca.crt</span></pre>
<p><img loading="lazy" decoding="async" width="1529" height="129" class="wp-image-6243" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-36.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-36.png 1529w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-36-300x25.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-36-1024x86.png 1024w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-36-768x65.png 768w" sizes="auto, (max-width: 1529px) 100vw, 1529px" /></p>
<h5><span style="text-decoration: underline; color: #000000;"><strong>Cléf Public Client </strong></span></h5>
<pre>[root@open-servervpn pki]# <span style="color: #ff0000;">cd issued/</span>
[root@open-servervpn issued]# <span style="color: #ff0000;">scp open-client01.crt <a style="color: #ff0000;" href="mailto:root@open-client01:/etc/openvpn/client/open-client01.crt">root@open-client01:/etc/openvpn/client/open-client01.crt</a></span></pre>
<p><img loading="lazy" decoding="async" width="1530" height="112" class="wp-image-6244" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-37.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-37.png 1530w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-37-300x22.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-37-1024x75.png 1024w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-37-768x56.png 768w" sizes="auto, (max-width: 1530px) 100vw, 1530px" /></p>
<h5><span style="text-decoration: underline;"><strong><span style="color: #000000; text-decoration: underline;">Cléf Privée Client</span> </strong></span></h5>
<pre>[root@open-servervpn issued]# <span style="color: #ff0000;">cd ../private/</span>
[root@open-servervpn private]# <span style="color: #ff0000;">scp open-client01.key root@open-client01:/etc/openvpn/client/open-client01.key</span></pre>
<p><img loading="lazy" decoding="async" width="1521" height="116" class="wp-image-6245" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-38.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-38.png 1521w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-38-300x23.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-38-1024x78.png 1024w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-38-768x59.png 768w" sizes="auto, (max-width: 1521px) 100vw, 1521px" /></p>
<h4><span style="text-decoration: underline; color: #000000;"><strong>Sur le Client </strong></span></h4>
<pre>[root@open-client01 ~]# <span style="color: #ff0000;">cd /etc/openvpn/client</span>
[root@open-client01 client]# <span style="color: #ff0000;">ls -al</span></pre>
<p><img loading="lazy" decoding="async" width="640" height="132" class="wp-image-6246" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-39.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-39.png 640w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-39-300x62.png 300w" sizes="auto, (max-width: 640px) 100vw, 640px" /></p>
<h4><span style="color: #000000;"><strong>4°) Configurer openvpn Client</strong></span></h4>
<pre>[root@open-client01 client]# <span style="color: #ff0000;">vi client.conf</span>

<span style="color: #ff0000;"><em>client</em></span>
<span style="color: #ff0000;"><em>dev tun</em></span>
<span style="color: #ff0000;"><em>proto udp</em></span>
<span style="color: #ff0000;"><em>remote <strong>open-servervpn</strong></em></span>
<span style="color: #ff0000;"><em>port <strong>1194</strong></em></span>
<strong><span style="color: #ff0000;"><em>ca ca.crt</em></span></strong>
<strong><span style="color: #ff0000;"><em>cert open-client01.crt</em></span></strong>
<strong><span style="color: #ff0000;"><em>key open-client01.key</em></span></strong>
<span style="color: #ff0000;"><em>verb 5</em></span>
<span style="color: #ff0000;"><em>remote-cert-tls server</em></span>
<span style="color: #ff0000;"><em>auth-nocache</em></span>
<span style="color: #ff0000;"><em>cipher AES-256-CBC</em></span></pre>
<p><img loading="lazy" decoding="async" width="552" height="230" class="wp-image-6247" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-40.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-40.png 552w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-40-300x125.png 300w" sizes="auto, (max-width: 552px) 100vw, 552px" /></p>
<h4><span style="color: #000000;"><strong>5°) Lancement OpenVPN client «&nbsp;open-client01&nbsp;»</strong></span></h4>
<p><strong>Test de la config</strong></p>
<pre>[root@open-client01 client]# <span style="color: #ff0000;">openvpn --config client.conf</span></pre>
<p><img loading="lazy" decoding="async" width="1387" height="643" class="wp-image-6248" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-41.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-41.png 1387w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-41-300x139.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-41-1024x475.png 1024w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-41-768x356.png 768w" sizes="auto, (max-width: 1387px) 100vw, 1387px" /></p>
<p><strong>Lancement du service</strong></p>
<pre>[root@open-client01 client]# <span style="color: #ff0000;">systemctl enable openvpn-client@client --now</span>
[root@open-client01 client]# <span style="color: #ff0000;">systemctl status openvpn-client@client</span></pre>
<p><img loading="lazy" decoding="async" width="1239" height="425" class="wp-image-6249" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-42.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-42.png 1239w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-42-300x103.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-42-1024x351.png 1024w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-42-768x263.png 768w" sizes="auto, (max-width: 1239px) 100vw, 1239px" /></p>
<p>[root@open-client01 client]#<span style="color: #ff0000;"> ip addr</span></p>
<p><img loading="lazy" decoding="async" width="1028" height="316" class="wp-image-6250" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-43.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-43.png 1028w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-43-300x92.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-43-1024x315.png 1024w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-43-768x236.png 768w" sizes="auto, (max-width: 1028px) 100vw, 1028px" /></p>
<p><strong>Côté log serveur</strong></p>
<p><img loading="lazy" decoding="async" width="1445" height="301" class="wp-image-6251" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-44.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-44.png 1445w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-44-300x62.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-44-1024x213.png 1024w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-44-768x160.png 768w" sizes="auto, (max-width: 1445px) 100vw, 1445px" /></p>
<h4><span style="color: #000000;"><strong>6°) Contrôle du Tunnel VPN </strong></span></h4>
<h4><span style="color: #000000;"><strong>Check du client open-client01 =&gt;&nbsp; open-servervpn via&nbsp; le réseau OpenVPN</strong></span></h4>
<pre>[root@open-servervpn private]# <span style="color: #ff0000;">ping -c 3 10.8.0.2</span></pre>
<p><img loading="lazy" decoding="async" width="653" height="168" class="wp-image-6252" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-45.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-45.png 653w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-45-300x77.png 300w" sizes="auto, (max-width: 653px) 100vw, 653px" /></p>
<h4><span style="color: #000000;">Check du server open-servervpn =&gt; copen-client01&nbsp; via le réseau OpenVPN</span></h4>
<pre>[root@open-client01 client]# <span style="color: #ff0000;">ping -c 3 10.8.0.1</span></pre>
<p><img loading="lazy" decoding="async" width="607" height="169" class="wp-image-6253" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-46.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-46.png 607w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-46-300x84.png 300w" sizes="auto, (max-width: 607px) 100vw, 607px" /></p>
<h4><span style="color: #000000;">Connexion du client open-client01 sur le serveur via le réseau OpenVPN</span></h4>
<pre>[root@open-client01 client]# <span style="color: #ff0000;">ssh root@10.8.0.1</span></pre>
<p><img loading="lazy" decoding="async" width="818" height="308" class="wp-image-6254" src="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-47.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-47.png 818w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-47-300x113.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2022/04/word-image-47-768x289.png 768w" sizes="auto, (max-width: 818px) 100vw, 818px" /></p>
<p>Views: 18</p><p>L’article <a href="https://coffeebreak.en-images.info/modop-installation-openvpn-easy-rsa3-client-serveur/">MODOP – Installation OpenVPN (Easy-RSA3) &#8211; Client/serveur</a> est apparu en premier sur <a href="https://coffeebreak.en-images.info">CoffeeBreak Info</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://coffeebreak.en-images.info/modop-installation-openvpn-easy-rsa3-client-serveur/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
	</channel>
</rss>
