Intro
目前 Client 支援各大裝置平台的 VPN 軟體套件,簡單架設的話可以使用有網頁管理介面的商業版本 OpenVPN Access Server,目前提供無限期2個VPN連線授權可免費試用。
安裝
Launch OpenVPN Access Server On Ubuntu - OpenVPN
Port原理
- 設定完成的 Access Server,會依照設定的 TCP 和 UDP port 提供服務 (另外也有 Web server port)
- Client 可利用 URL 方式設定 config file,依照 Host 位址指定 TCP port 訪問並會執行 auth 驗證,成功後建立 profile
- config file 內主要有
host位址和UDP port以供VPN連線參照,此資訊是由 Access Server 設定內容下載而來,並非為 URL 設定時輸入的資訊 - Client 最後對已建好 config file 的 profile 進行連線 (預設會走 UDP port)
預設 port: - TCP: 443 - UDP: 1194
Set the interface and ports for the OpenVPN daemons - OpenVPN
Log 機制
- Client: 目前介面右上角提供 log 方便追查
-
Server: 一般路徑在
/var/log/openvpnas.log
Split vs Full Tunneling (Routing)
OpenVPN Access Server 預設開啟 Split Tunneling。
預設僅「私有內網流量」走 VPN 隧道,其餘一般上網流量走使用者原本的本地網路。
核心差異
| 項目 | Full Tunneling(全流量) | Split Tunneling(分流/預設) |
|---|---|---|
| 流量走向 | 全部流量走 VPN | 僅私有內網流量走 VPN |
| 出口 IP | 統一顯示 VPN IP | 內網顯示 VPN IP,其餘顯示本地 IP |
| 優點 | 資安管控嚴密、防護最高 | 節省伺服器頻寬、連線速度最快 |
| 缺點 | 全流量佔用 VPN 頻寬 | 非全流量受 VPN 加密保護 |
後台切換步驟 (Admin Web UI)
路徑:Configuration > VPN Settings > Routing
- 切換模式:
- Should client Internet traffic be routed through the VPN?
Yes➔ 切換為 Full TunnelingNo➔ 切換為 Split Tunneling(預設)
- Should client Internet traffic be routed through the VPN?
- 指定內網網段(僅 Split Tunneling 需要):
- 在 Specify the private subnets... 填入內網 IP(例如
10.8.0.0/24)。
- 在 Specify the private subnets... 填入內網 IP(例如