阿里云centos7基于搭建VPN

时间:2022-03-15 12:38:51

本文参考自:http://www.xxkwz.cn/1495.html

前段时间使用pptp搭建了一个VPN,速度很快,但是用了大概一个月挂了,估计是被墙了吧,于是,用*重新搭建了一个,

参考了网友教程,结合自己的一些运维经验,终于搭建成功,先记录一下,希望可以帮助有需要的朋友。

一、服务器端配置

1、安装采用的是teddysun(github上可以搜索到)写的一键安装脚本,具体地址如下:

https://raw.githubusercontent.com/teddysun/*_install/master/*.sh

或者:

https://github.com/teddysun/*_install.git

下载后,使用root执行就OK,不再赘述。为防止链接失效,完整的脚本也可在本文末尾附录中看到。

2、修改默认配置

  配置文件路径:/etc/*.json

内容: 

{
    "server":"your_server_ip",
    "server_port":8989,
    "local_address":"127.0.0.1",
    "local_port":1080,
    "password":"yourpassword",
    "timeout":300,
    "method":"rc4-md5", "fast_open": false }

 加密方式改为:rc4-md5

 3、修改防火墙

  如果开启了iptables防火墙,需要开放上面的server_port端口

方法:

vi /etc/systemconfig/iptables

-A INPUT -m state --state NEW -m tcp -p tcp --dport 8989 -j ACCEPT

 4、重启服务

  systemctl restart *

二、客户端配置

  参考自:https://ttt.tt/150/  

  下载地址:

  Win:

  适合 Windows 7 用户,链接: http://pan.baidu.com/s/1ntoPuI1 密码: vrqh

  适合 Windows 8.1 用户,链接: http://pan.baidu.com/s/1hq6A1yG 密码: 6oe9

  OS X:http://pan.baidu.com/s/1i39qr8D 密码: pv6d

客户端配置界面如下:

注:其中的加密方式要改成 rc4-md5

阿里云centos7基于搭建VPN

客户端配置好后,需要设置浏览器的代理信息,以chrome为例:

1、进入chrome://settings/的高级设置

2、网络=》更改代理服务器设置

3、进入其中的局域网设置,截图如下:

阿里云centos7基于搭建VPN阿里云centos7基于搭建VPN

以上就是配置的全过程,欢迎提问探讨。

附录:

#!/usr/bin/env bash
PATH=/bin:/sbin:/usr/bin:/usr/sbin:/usr/local/bin:/usr/local/sbin:~/bin
export PATH
#=================================================================#
#   System Required:  CentOS 6+, Debian 7+, Ubuntu 12+            #
#   Description: One click Install *-Python server      #
#   Author: Teddysun <i@teddysun.com>                             #
#   Thanks: @clowwindy <https://twitter.com/clowwindy>            #
#   Intro:  https://teddysun.com/342.html                         #
#=================================================================#

clear
echo
echo "#############################################################"
echo "# One click Install *-Python server               #"
echo "# Intro: https://teddysun.com/342.html                      #"
echo "# Author: Teddysun <i@teddysun.com>                         #"
echo "# Github: https://github.com/*/*        #"
echo "#############################################################"
echo

#Current folder
cur_dir=`pwd`

# Make sure only root can run our script
rootness(){
    if [[ $EUID -ne 0 ]]; then
        echo "Error:This script must be run as root!" 1>&2
        exit 1
    fi
}

# Disable selinux
disable_selinux(){
    if [ -s /etc/selinux/config ] && grep 'SELINUX=enforcing' /etc/selinux/config; then
        sed -i 's/SELINUX=enforcing/SELINUX=disabled/g' /etc/selinux/config
        setenforce 0
    fi
}

#Check system
check_sys(){
    local checkType=$1
    local value=$2

    local release=''
    local systemPackage=''

    if [[ -f /etc/redhat-release ]]; then
        release="centos"
        systemPackage="yum"
    elif cat /etc/issue | grep -Eqi "debian"; then
        release="debian"
        systemPackage="apt"
    elif cat /etc/issue | grep -Eqi "ubuntu"; then
        release="ubuntu"
        systemPackage="apt"
    elif cat /etc/issue | grep -Eqi "centos|red hat|redhat"; then
        release="centos"
        systemPackage="yum"
    elif cat /proc/version | grep -Eqi "debian"; then
        release="debian"
        systemPackage="apt"
    elif cat /proc/version | grep -Eqi "ubuntu"; then
        release="ubuntu"
        systemPackage="apt"
    elif cat /proc/version | grep -Eqi "centos|red hat|redhat"; then
        release="centos"
        systemPackage="yum"
    fi

    if [[ ${checkType} == "sysRelease" ]]; then
        if [ "$value" == "$release" ]; then
            return 0
        else
            return 1
        fi
    elif [[ ${checkType} == "packageManager" ]]; then
        if [ "$value" == "$systemPackage" ]; then
            return 0
        else
            return 1
        fi
    fi
}

# Get version
getversion(){
    if [[ -s /etc/redhat-release ]]; then
        grep -oE  "[0-9.]+" /etc/redhat-release
    else
        grep -oE  "[0-9.]+" /etc/issue
    fi
}

# CentOS version
centosversion(){
    if check_sys sysRelease centos; then
        local code=$1
        local version="$(getversion)"
        local main_ver=${version%%.*}
        if [ "$main_ver" == "$code" ]; then
            return 0
        else
            return 1
        fi
    else
        return 1
    fi
}

# Get public IP address
get_ip(){
    local IP=$( ip addr | egrep -o '[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}' | egrep -v "^192\.168|^172\.1[6-9]\.|^172\.2[0-9]\.|^172\.3[0-2]\.|^10\.|^127\.|^255\.|^0\." | head -n 1 )
    [ -z ${IP} ] && IP=$( wget -qO- -t1 -T2 ipv4.icanhazip.com )
    [ -z ${IP} ] && IP=$( wget -qO- -t1 -T2 ipinfo.io/ip )
    [ ! -z ${IP} ] && echo ${IP} || echo
}

# Pre-installation settings
pre_install(){
    if check_sys packageManager yum || check_sys packageManager apt; then
        # Not support CentOS 5
        if centosversion 5; then
            echo "Error: Not supported CentOS 5, please change to CentOS 6+/Debian 7+/Ubuntu 12+ and try again."
            exit 1
        fi
    else
        echo "Error: Your OS is not supported. please change OS to CentOS/Debian/Ubuntu and try again."
        exit 1
    fi
    # Set * config password
    echo "Please input password for *-python:"
    read -p "(Default password: teddysun.com):" *pwd
    [ -z "${*pwd}" ] && *pwd="teddysun.com"
    echo
    echo "---------------------------"
    echo "password = ${*pwd}"
    echo "---------------------------"
    echo
    # Set * config port
    while true
    do
    echo -e "Please input port for *-python [1-65535]:"
    read -p "(Default port: 8989):" *port
    [ -z "$*port" ] && *port="8989"
    expr ${*port} + 0 &>/dev/null
    if [ $? -eq 0 ]; then
        if [ ${*port} -ge 1 ] && [ ${*port} -le 65535 ]; then
            echo
            echo "---------------------------"
            echo "port = ${*port}"
            echo "---------------------------"
            echo
            break
        else
            echo "Input error, please input correct number"
        fi
    else
        echo "Input error, please input correct number"
    fi
    done
    get_char(){
        SAVEDSTTY=`stty -g`
        stty -echo
        stty cbreak
        dd if=/dev/tty bs=1 count=1 2> /dev/null
        stty -raw
        stty echo
        stty $SAVEDSTTY
    }
    echo
    echo "Press any key to start...or Press Ctrl+C to cancel"
    char=`get_char`
    #Install necessary dependencies
    if check_sys packageManager yum; then
        yum install -y unzip openssl-devel gcc swig python python-devel python-setuptools autoconf libtool libevent automake make curl curl-devel zlib-devel perl perl-devel cpio expat-devel gettext-devel
    elif check_sys packageManager apt; then
        apt-get -y update
        apt-get -y install python python-dev python-pip python-setuptools python-m2crypto curl wget unzip gcc swig automake make perl cpio build-essential
    fi
    cd ${cur_dir}
}

# Download files
download_files(){
    # Download libsodium file
    if ! wget --no-check-certificate -O libsodium-1.0.11.tar.gz https://github.com/jedisct1/libsodium/releases/download/1.0.11/libsodium-1.0.11.tar.gz; then
        echo "Failed to download libsodium-1.0.11.tar.gz!"
        exit 1
    fi
    # Download * file
    if ! wget --no-check-certificate -O *-master.zip https://github.com/*/*/archive/master.zip; then
        echo "Failed to download * python file!"
        exit 1
    fi
    # Download * init script
    if check_sys packageManager yum; then
        if ! wget --no-check-certificate https://raw.githubusercontent.com/teddysun/*_install/master/* -O /etc/init.d/*; then
            echo "Failed to download * chkconfig file!"
            exit 1
        fi
    elif check_sys packageManager apt; then
        if ! wget --no-check-certificate https://raw.githubusercontent.com/teddysun/*_install/master/*-debian -O /etc/init.d/*; then
            echo "Failed to download * chkconfig file!"
            exit 1
        fi
    fi
}

# Config *
config_*(){
    cat > /etc/*.json<<-EOF
{
    "server":"0.0.0.0",
    "server_port":${*port},
    "local_address":"127.0.0.1",
    "local_port":1080,
    "password":"${*pwd}",
    "timeout":300,
    "method":"aes-256-cfb",
    "fast_open":false
}
EOF
}

# Firewall set
firewall_set(){
    echo "firewall set start..."
    if centosversion 6; then
        /etc/init.d/iptables status > /dev/null 2>&1
        if [ $? -eq 0 ]; then
            iptables -L -n | grep -i ${*port} > /dev/null 2>&1
            if [ $? -ne 0 ]; then
                iptables -I INPUT -m state --state NEW -m tcp -p tcp --dport ${*port} -j ACCEPT
                iptables -I INPUT -m state --state NEW -m udp -p udp --dport ${*port} -j ACCEPT
                /etc/init.d/iptables save
                /etc/init.d/iptables restart
            else
                echo "port ${*port} has been set up."
            fi
        else
            echo "WARNING: iptables looks like shutdown or not installed, please manually set it if necessary."
        fi
    elif centosversion 7; then
        systemctl status firewalld > /dev/null 2>&1
        if [ $? -eq 0 ]; then
            firewall-cmd --permanent --zone=public --add-port=${*port}/tcp
            firewall-cmd --permanent --zone=public --add-port=${*port}/udp
            firewall-cmd --reload
        else
            echo "Firewalld looks like not running, try to start..."
            systemctl start firewalld
            if [ $? -eq 0 ]; then
                firewall-cmd --permanent --zone=public --add-port=${*port}/tcp
                firewall-cmd --permanent --zone=public --add-port=${*port}/udp
                firewall-cmd --reload
            else
                echo "WARNING: Try to start firewalld failed. please enable port ${*port} manually if necessary."
            fi
        fi
    fi
    echo "firewall set completed..."
}

# Install *
install(){
    # Install libsodium
    tar zxf libsodium-1.0.11.tar.gz
    cd libsodium-1.0.11
    ./configure && make && make install
    if [ $? -ne 0 ]; then
        echo "libsodium install failed!"
        install_cleanup
        exit 1
    fi
    echo "/usr/local/lib" > /etc/ld.so.conf.d/local.conf
    ldconfig
    # Install *
    cd ${cur_dir}
    unzip -q *-master.zip
    if [ $? -ne 0 ];then
        echo "unzip *-master.zip failed! please check unzip command."
        install_cleanup
        exit 1
    fi

    cd ${cur_dir}/*-master
    python setup.py install --record /usr/local/*_install.log

    if [ -f /usr/bin/ssserver ] || [ -f /usr/local/bin/ssserver ]; then
        chmod +x /etc/init.d/*
        if check_sys packageManager yum; then
            chkconfig --add *
            chkconfig * on
        elif check_sys packageManager apt; then
            update-rc.d -f * defaults
        fi
        /etc/init.d/* start
    else
        echo
        echo "* install failed! please visit https://teddysun.com/342.html and contact."
        install_cleanup
        exit 1
    fi

    clear
    echo
    echo "Congratulations, * server install completed!"
    echo -e "Your Server IP: \033[41;37m $(get_ip) \033[0m"
    echo -e "Your Server Port: \033[41;37m ${*port} \033[0m"
    echo -e "Your Password: \033[41;37m ${*pwd} \033[0m"
    echo -e "Your Local IP: \033[41;37m 127.0.0.1 \033[0m"
    echo -e "Your Local Port: \033[41;37m 1080 \033[0m"
    echo -e "Your Encryption Method: \033[41;37m aes-256-cfb \033[0m"
    echo
    echo "Welcome to visit:https://teddysun.com/342.html"
    echo "Enjoy it!"
    echo
}

# Install cleanup
install_cleanup(){
    cd ${cur_dir}
    rm -rf *-master.zip *-master libsodium-1.0.11.tar.gz libsodium-1.0.11
}

# Uninstall *
uninstall_*(){
    printf "Are you sure uninstall *? (y/n) "
    printf "\n"
    read -p "(Default: n):" answer
    [ -z ${answer} ] && answer="n"
    if [ "${answer}" == "y" ] || [ "${answer}" == "Y" ]; then
        ps -ef | grep -v grep | grep -i "ssserver" > /dev/null 2>&1
        if [ $? -eq 0 ]; then
            /etc/init.d/* stop
        fi
        if check_sys packageManager yum; then
            chkconfig --del *
        elif check_sys packageManager apt; then
            update-rc.d -f * remove
        fi
        # delete config file
        rm -f /etc/*.json
        rm -f /var/run/*.pid
        rm -f /etc/init.d/*
        rm -f /var/log/*.log
        if [ -f /usr/local/*_install.log ]; then
            cat /usr/local/*_install.log | xargs rm -rf
        fi
        echo "* uninstall success!"
    else
        echo
        echo "uninstall cancelled, nothing to do..."
        echo
    fi
}

# Install *-python
install_*(){
    rootness
    disable_selinux
    pre_install
    download_files
    config_*
    if check_sys packageManager yum; then
        firewall_set
    fi
    install
    install_cleanup
}

# Initialization step
action=$1
[ -z $1 ] && action=install
case "$action" in
    install|uninstall)
    ${action}_*
    ;;
    *)
    echo "Arguments error! [${action}]"
    echo "Usage: `basename $0` {install|uninstall}"
    ;;
esac