sudo su cd /etc/openvpn/easy-rsa/ source vars ./clean-all #删除keys文件夹 ./build-ca cp keys/ca.crt /etc/openvpn/
制作 Server 端证书
./build-key-server server ./build-dh cp keys/server.crt keys/server.key keys/dh1024.pem /etc/openvpn/
制作 Client 端证书
./build-key client
配置 Server 端
cp /usr/share/doc/openvpn/examples/sample-config-files/server.conf.gz /etc/openvpn/ cd /etc/openvpn/ gzip -d server.conf.gz vi /etc/openvpn/server.conf
server.conf
port 1194 proto tcp dev tun ca ca.crt cert server.crt key server.key dh dh1024.pem server 10.8.0.0 255.255.255.0 ifconfig-pool-persist ipp.txt push"redirect-gateway def1 bypass-dhcp" push"dhcp-option DNS 114.114.114.114" push"dhcp-option DNS 114.114.115.115" duplicate-cn keepalive 10 120 comp-lzo user nobody group nogroup persist-key persist-tun status openvpn-status.log verb 3