由于是gprs包月上网,只能cmwap,所以很多限制,连symantec杀毒软件也升级不了,所以只好想办法突破。用OpenVpn是一个不错的办法,不过速度不怎么样,可能因为我做的OpenVpn服务器是电信IP的缘故。
现将搭建OpenVpn的过程记录如下:
一、OpenVpn服务器端配置过程
修改 OpenVPN\easy-rsa\vars.bat.sample
set KEY_COUNTRY=CN
set KEY_PROVINCE=AnHui
set KEY_CITY=HeFei
set KEY_ORG=lizhenbao
set KEY_EMAIL=aa@aa.com
打开 cmd或command进入 OpenVPN\easy-rsa,运行以下命令
init-config
vars
clean-all
build-ca **这个命令用于创建根证书
Country Name (2 letter code) [CN]:
State or Province Name (full name) [AnHui]:
Locality Name (eg, city) [HeFei]:
Organization Name (eg, company) [lizhenbao]:
Organizational Unit Name (eg, section) []:
Common Name (eg, your name or your server's hostname) []:rootcr
Email Address [aaa@aa.com]:
build-dh
build-key-server server **创建服务器证书,server为机器名
Country Name (2 letter code) [CN]:
State or Province Name (full name) [AnHui]:
Locality Name (eg, city) [HeFei]:
Organization Name (eg, company) [lizhenbao]:
Organizational Unit Name (eg, section) []:
Common Name (eg, your name or your server's hostname) []:server
Email Address [lizhenbao@gmail.com]:
Please enter the following 'extra' attributes
to be sent with your certificate request
A challenge password []:password
An optional company name []:
build-key client **创建客户端证书,client为用户名
Country Name (2 letter code) [CN]:
State or Province Name (full name) [AnHui]:
Locality Name (eg, city) [HeFei]:
Organization Name (eg, company) [lizhenbao]:
Organizational Unit Name (eg, section) []:
Common Name (eg, your name or your server's hostname) []:client
Email Address [lizhenbao@gmail.com]:
Please enter the following 'extra' attributes
to be sent with your certificate request
A challenge password []:password
An optional company name []:
openvpn --genkey --secret keys/ta.key
将ca.crt,dh1024.pem,server.crt,server.key,ta.key复制到 OpenVPN\config目录下
拷贝server.ovpn到config目录下,修改后,用OpenVPN GUI启动服务器
至此OpenVpn服务器配置成功。如果想要OpenVpn服务器自动启动,则找到OpenVpn服务,将其启动方式设置为“自动”。
二、OpenVpn 客户端配置过程
将ca.crt client.crt client.key ta.key复制到 OpenVPN\config目录下
拷贝client.ovpn到config目录下,修改后,用OpenVPN GUI启动客户端
三、Openvpn 服务器端发放证书方法
启动cmd或command
进入easy-rsa目录
vars
build-key username **其中username为用户名 ,注意各证书的Common Name不能相同(http://www.cnitblog.com/lizhenbao)
为方便需要的朋友,将配置文件放到网络供下载。下载地址 http://www.bibidu.com/fileview-302845.html