{"id":364052,"date":"2024-05-21T02:09:08","date_gmt":"2024-05-21T02:09:08","guid":{"rendered":"http:\/\/savepearlharbor.com\/?p=364052"},"modified":"-0001-11-30T00:00:00","modified_gmt":"-0001-11-29T21:00:00","slug":"","status":"publish","type":"post","link":"https:\/\/savepearlharbor.com\/?p=364052","title":{"rendered":"<span>\u041f\u0440\u043e\u0435\u043a\u0442 \u044e\u043d\u043e\u0433\u043e DevOps \u0413\u043b\u0430\u0432\u0430 3: \u041d\u0430\u0441\u0442\u0440\u043e\u0439\u043a\u0430 OpenVPN<\/span>"},"content":{"rendered":"<div><!--[--><!--]--><\/div>\n<div id=\"post-content-body\">\n<div>\n<div class=\"article-formatted-body article-formatted-body article-formatted-body_version-2\">\n<div xmlns=\"http:\/\/www.w3.org\/1999\/xhtml\">\n<figure class=\"full-width\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/habrastorage.org\/r\/w1560\/getpro\/habr\/upload_files\/6a6\/fee\/c29\/6a6feec29a9f3bc0cc33df172b81000d.png\" width=\"1440\" height=\"816\" data-src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/6a6\/fee\/c29\/6a6feec29a9f3bc0cc33df172b81000d.png\"\/><\/figure>\n<p>\u0412 \u0434\u0430\u043d\u043d\u043e\u0439 \u0441\u0435\u0440\u0438\u0438 \u0441\u0442\u0430\u0442\u0435\u0439 \u043e\u043f\u0438\u0441\u0430\u043d \u043f\u0440\u043e\u0446\u0435\u0441\u0441 \u0441\u043e\u0437\u0434\u0430\u043d\u0438\u044f \u043f\u0435\u0440\u0432\u043e\u0433\u043e pet-\u043f\u0440\u043e\u0435\u043a\u0442\u0430 \u0434\u043b\u044f \u043d\u0430\u0447\u0438\u043d\u0430\u044e\u0449\u0435\u0433\u043e \u0438\u043d\u0436\u0435\u043d\u0435\u0440\u0430 \u0432 DevOps:<\/p>\n<p><a href=\"https:\/\/habr.com\/ru\/articles\/781746\/\" rel=\"noopener noreferrer nofollow\"><strong>\u0413\u043b\u0430\u0432\u0430 1: \u0412\u0432\u0435\u0434\u0435\u043d\u0438\u0435 \u0438 \u043f\u043e\u0434\u0433\u043e\u0442\u043e\u0432\u043a\u0430 \u0441\u0442\u0435\u043d\u0434\u0430<\/strong><\/a><\/p>\n<p><a href=\"https:\/\/habr.com\/ru\/articles\/789056\/\" rel=\"noopener noreferrer nofollow\"><strong>\u0413\u043b\u0430\u0432\u0430 2: \u041d\u0430\u0441\u0442\u0440\u043e\u0439\u043a\u0430 \u0446\u0435\u043d\u0442\u0440\u0430 \u0441\u0435\u0440\u0442\u0438\u0444\u0438\u043a\u0430\u0446\u0438\u0438 \u0438 \u0440\u0435\u043f\u043e\u0437\u0438\u0442\u043e\u0440\u0438\u044f<\/strong><\/a><\/p>\n<p><a href=\"https:\/\/habr.com\/ru\/articles\/783304\/\" rel=\"noopener noreferrer nofollow\"><strong>\u0413\u043b\u0430\u0432\u0430 3: \u041d\u0430\u0441\u0442\u0440\u043e\u0439\u043a\u0430 OpenVPN<\/strong><\/a><\/p>\n<p><a href=\"https:\/\/habr.com\/ru\/articles\/783572\/\" rel=\"noopener noreferrer nofollow\"><strong>\u0413\u043b\u0430\u0432\u0430 4: \u041d\u0430\u0441\u0442\u0440\u043e\u0439\u043a\u0430 \u043c\u043e\u043d\u0438\u0442\u043e\u0440\u0438\u043d\u0433\u0430<\/strong><\/a><\/p>\n<blockquote>\n<p>\u0414\u0440\u0443\u0437\u044c\u044f, \u0445\u043e\u0447\u0443 \u043e\u0442\u0432\u0435\u0442\u0438\u0442\u044c \u043d\u0430 \u043a\u043e\u043c\u043c\u0435\u043d\u0442\u0430\u0440\u0438\u0438 \u043e\u0431 \u043e\u0442\u0441\u0443\u0442\u0441\u0442\u0432\u0438\u0438 \u0432 \u0434\u0430\u043d\u043d\u043e\u0439 \u0441\u0435\u0440\u0438\u0438 \u0441\u0442\u0430\u0442\u0435\u0439 \u0438\u043d\u0441\u0442\u0440\u0443\u043c\u0435\u043d\u0442\u043e\u0432 DevOps &#8212; Terraform, Ansible, Kubernetes, GitLab CI\/CD \u0438 \u043f\u0440\u043e\u0447\u0438\u0445 \u0438\u043d\u0441\u0442\u0440\u0443\u043c\u0435\u043d\u0442\u043e\u0432. \u041f\u043e\u043b\u043d\u043e\u0441\u0442\u044c\u044e \u0441\u043e\u0433\u043b\u0430\u0441\u0435\u043d \u0441 \u0442\u0435\u043c, \u0447\u0442\u043e DevOps \u0431\u0435\u0437 \u0432\u044b\u0448\u0435\u0443\u043f\u043e\u043c\u044f\u043d\u0443\u0442\u044b\u0445 \u0438\u043d\u0441\u0442\u0440\u0443\u043c\u0435\u043d\u0442\u043e\u0432 \u0441\u0443\u0449\u0435\u0441\u0442\u0432\u043e\u0432\u0430\u0442\u044c \u043d\u0435 \u043c\u043e\u0436\u0435\u0442.<\/p>\n<p>\u0414\u0430\u043d\u043d\u0430\u044f \u0441\u0435\u0440\u0438\u044f \u0441\u0442\u0430\u0442\u0435\u0439 \u044f\u0432\u043b\u044f\u0435\u0442\u0441\u044f \u043e\u0442\u043f\u0440\u0430\u0432\u043d\u043e\u0439 \u0442\u043e\u0447\u043a\u043e\u0439 \u0432 \u0438\u0437\u0443\u0447\u0435\u043d\u0438\u0438 DevOps \u0438 \u0443\u0432\u0435\u0440\u0435\u043d, \u0447\u0442\u043e \u0438\u043c\u0435\u043d\u043d\u043e \u043d\u0430\u0447\u0438\u043d\u0430\u044e\u0449\u0438\u043c \u0438\u043d\u0436\u0435\u043d\u0435\u0440\u0430\u043c \u0434\u0430\u043d\u043d\u044b\u0439 \u043c\u0430\u0442\u0435\u0440\u0438\u0430\u043b \u0442\u043e\u0447\u043d\u043e \u0431\u0443\u0434\u0435\u0442 \u043f\u043e\u043b\u0435\u0437\u0435\u043d. \u0417\u0434\u0435\u0441\u044c \u0431\u043e\u043b\u044c\u0448\u043e\u0439 \u0430\u043a\u0446\u0435\u043d\u0442 \u0441\u0434\u0435\u043b\u0430\u043d \u043d\u0430 \u043d\u0430\u043f\u0438\u0441\u0430\u043d\u0438\u0438 \u0441\u043a\u0440\u0438\u043f\u0442\u043e\u0432. \u0426\u0435\u043b\u044c \u0434\u0430\u043d\u043d\u043e\u0433\u043e pet-\u043f\u0440\u043e\u0435\u043a\u0442\u0430 &#8212; \u043f\u0440\u0430\u043a\u0442\u0438\u0447\u0435\u0441\u043a\u043e\u0435 \u043e\u0437\u043d\u0430\u043a\u043e\u043c\u043b\u0435\u043d\u0438\u0435 \u0441 Linux \u043f\u0435\u0440\u0435\u0434 \u0442\u0435\u043c \u043a\u0430\u043a \u0434\u0432\u0438\u0433\u0430\u0442\u044c\u0441\u044f \u0434\u0430\u043b\u044c\u0448\u0435 \u0432 DevOps &#8212; \u0438\u043c\u0435\u043d\u043d\u043e \u043f\u043e\u044d\u0442\u043e\u043c\u0443 \u043d\u0430\u0437\u0432\u0430\u043d\u0438\u0435 \u00ab\u041f\u0440\u043e\u0435\u043a\u0442\u00a0<strong>\u044e\u043d\u043e\u0433\u043e<\/strong>\u00a0DevOps\u00bb. \u0412 \u043f\u043b\u0430\u043d\u0430\u0445 \u043d\u0430\u043f\u0438\u0441\u0430\u043d\u0438\u0435 \u0441\u043b\u0435\u0434\u0443\u044e\u0449\u0435\u0439 \u0441\u0435\u0440\u0438\u0438 \u0441\u0442\u0430\u0442\u0435\u0439 \u0443\u0436\u0435 \u0441 \u0443\u0433\u043b\u0443\u0431\u043b\u0435\u043d\u0438\u0435\u043c \u0432 DevOps \u0438 \u0435\u0433\u043e \u0438\u043d\u0441\u0442\u0440\u0443\u043c\u0435\u043d\u0442\u044b.<\/p>\n<p>\u0421\u043f\u0430\u0441\u0438\u0431\u043e \u0437\u0430 \u043a\u043e\u043d\u0441\u0442\u0440\u0443\u043a\u0442\u0438\u0432\u043d\u044b\u0435 \u043a\u043e\u043c\u043c\u0435\u043d\u0442\u0430\u0440\u0438\u0438, \u043a\u043e\u0442\u043e\u0440\u044b\u0435 \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0442 \u043e\u0442\u043a\u043e\u0440\u0440\u0435\u043a\u0442\u0438\u0440\u043e\u0432\u0430\u0442\u044c \u043c\u0430\u0442\u0435\u0440\u0438\u0430\u043b \u0438 \u0443\u043b\u0443\u0447\u0448\u0438\u0442\u044c \u0435\u0433\u043e \u043a\u0430\u0447\u0435\u0441\u0442\u0432\u043e. \u041f\u0440\u043e\u0448\u0443 \u043f\u043e\u0434\u0434\u0435\u0440\u0436\u0430\u0442\u044c \u043c\u043e\u0435 \u043d\u0430\u0447\u0438\u043d\u0430\u043d\u0438\u0435, \u0432\u0441\u0435\u043c \u0445\u043e\u0440\u043e\u0448\u0435\u0433\u043e \u0434\u043d\u044f!<\/p>\n<\/blockquote>\n<h3>\u041d\u0430\u0441\u0442\u0440\u043e\u0439\u043a\u0430 OpenVPN<\/h3>\n<p>\u0417\u0430\u0439\u0434\u0435\u043c \u043d\u0430 vm \u00abvpn\u00bb, \u043f\u0440\u0438\u043c\u0435\u043d\u0438\u043c bash-\u0441\u043a\u0440\u0438\u043f\u0442 \u00abvm-start.sh\u00bb \u0438 \u043f\u0440\u0438\u0441\u0442\u0443\u043f\u0438\u043c \u043a \u043d\u0430\u0441\u0442\u0440\u043e\u0439\u043a\u0435 OpenVPN:  <\/p>\n<p>\u0423\u0441\u0442\u0430\u043d\u043e\u0432\u0438\u043c Open-VPN \u0432\u0435\u0440\u0441\u0438\u0438 2.5.5:<\/p>\n<pre><code class=\"bash\">sudo apt-get install -y openvpn=2.5.5-1ubuntu3<\/code><\/pre>\n<details class=\"spoiler\">\n<summary>\u0417\u0430\u043c\u0435\u0442\u043a\u0430<\/summary>\n<div class=\"spoiler__content\">\n<p>\u0412 \u0434\u0440\u0443\u0433\u0438\u0445 \u0432\u0435\u0440\u0441\u0438\u044f\u0445 OpenVPN \u043f\u0440\u043e\u0446\u0435\u0441\u0441 \u0438 \u043e\u0441\u043e\u0431\u0435\u043d\u043d\u043e\u0441\u0442\u0438 \u043d\u0430\u0441\u0442\u0440\u043e\u0439\u043a\u0438 \u043c\u043e\u0433\u0443\u0442 \u043e\u0442\u043b\u0438\u0447\u0430\u0442\u044c\u0441\u044f \u043e\u0442 \u043e\u043f\u0438\u0441\u0430\u043d\u043d\u044b\u0445 \u0432 \u0434\u0430\u043d\u043d\u043e\u0439 \u0441\u0442\u0430\u0442\u044c\u0435.<\/p>\n<\/div>\n<\/details>\n<p>OpenVPN \u043f\u043e\u0434\u0434\u0435\u0440\u0436\u0438\u0432\u0430\u0435\u0442 \u0434\u0432\u0443\u043d\u0430\u043f\u0440\u0430\u0432\u043b\u0435\u043d\u043d\u0443\u044e \u0430\u0443\u0442\u0435\u043d\u0442\u0438\u0444\u0438\u043a\u0430\u0446\u0438\u044e \u043d\u0430 \u043e\u0441\u043d\u043e\u0432\u0435 \u0441\u0435\u0440\u0442\u0438\u0444\u0438\u043a\u0430\u0442\u043e\u0432, \u0447\u0442\u043e \u043e\u0437\u043d\u0430\u0447\u0430\u0435\u0442, \u0447\u0442\u043e \u043a\u043b\u0438\u0435\u043d\u0442 \u0434\u043e\u043b\u0436\u0435\u043d \u043f\u0440\u043e\u0432\u0435\u0440\u0438\u0442\u044c \u0441\u0435\u0440\u0442\u0438\u0444\u0438\u043a\u0430\u0442 \u0441\u0435\u0440\u0432\u0435\u0440\u0430, \u0430 \u0441\u0435\u0440\u0432\u0435\u0440 &#8212; \u0441\u0435\u0440\u0442\u0438\u0444\u0438\u043a\u0430\u0442 \u043a\u043b\u0438\u0435\u043d\u0442\u0430, \u043f\u0440\u0435\u0436\u0434\u0435 \u0447\u0435\u043c \u0431\u0443\u0434\u0435\u0442 \u0443\u0441\u0442\u0430\u043d\u043e\u0432\u043b\u0435\u043d\u043e \u0432\u0437\u0430\u0438\u043c\u043d\u043e\u0435 \u0434\u043e\u0432\u0435\u0440\u0438\u0435.<\/p>\n<p>\u0418 \u0441\u0435\u0440\u0432\u0435\u0440, \u0438 \u043a\u043b\u0438\u0435\u043d\u0442 \u0430\u0443\u0442\u0435\u043d\u0442\u0438\u0444\u0438\u0446\u0438\u0440\u0443\u044e\u0442 \u0434\u0440\u0443\u0433 \u0434\u0440\u0443\u0433\u0430, \u0441\u043d\u0430\u0447\u0430\u043b\u0430 \u043f\u0440\u043e\u0432\u0435\u0440\u044f\u044f, \u0447\u0442\u043e \u043f\u0440\u0435\u0434\u0441\u0442\u0430\u0432\u043b\u0435\u043d\u043d\u044b\u0439 \u0441\u0435\u0440\u0442\u0438\u0444\u0438\u043a\u0430\u0442 \u0431\u044b\u043b \u043f\u043e\u0434\u043f\u0438\u0441\u0430\u043d \u0433\u043b\u0430\u0432\u043d\u044b\u043c \u0446\u0435\u043d\u0442\u0440\u043e\u043c \u0441\u0435\u0440\u0442\u0438\u0444\u0438\u043a\u0430\u0446\u0438\u0438 (CA), \u0430 \u0437\u0430\u0442\u0435\u043c \u043f\u0440\u043e\u0432\u0435\u0440\u044f\u044f \u0438\u043d\u0444\u043e\u0440\u043c\u0430\u0446\u0438\u044e \u0432 \u0437\u0430\u0433\u043e\u043b\u043e\u0432\u043a\u0435 \u0441\u0435\u0440\u0442\u0438\u0444\u0438\u043a\u0430\u0442\u0430, \u043a\u043e\u0442\u043e\u0440\u044b\u0439 \u0442\u0435\u043f\u0435\u0440\u044c \u0430\u0443\u0442\u0435\u043d\u0442\u0438\u0444\u0438\u0446\u0438\u0440\u043e\u0432\u0430\u043d, \u043d\u0430\u043f\u0440\u0438\u043c\u0435\u0440 \u043e\u0431\u0449\u0435\u0435 \u0438\u043c\u044f \u0441\u0435\u0440\u0442\u0438\u0444\u0438\u043a\u0430\u0442\u0430 \u0438\u043b\u0438 \u0442\u0438\u043f \u0441\u0435\u0440\u0442\u0438\u0444\u0438\u043a\u0430\u0442\u0430 (\u043a\u043b\u0438\u0435\u043d\u0442 \u0438\u043b\u0438 \u0441\u0435\u0440\u0432\u0435\u0440).<\/p>\n<p>\u041f\u0435\u0440\u0435\u043d\u0435\u0441\u0435\u043c\u00a0<a href=\"https:\/\/habr.com\/ru\/articles\/789056\/#issue\" rel=\"noopener noreferrer nofollow\">\u043f\u043e\u0434\u043f\u0438\u0441\u0430\u043d\u043d\u044b\u0435<\/a>\u00a0\u043d\u0430 CA \u043a\u043b\u044e\u0447\u0438 \u0434\u043b\u044f vm \u00abvpn\u00bb \u0432 \u0440\u0430\u0431\u043e\u0447\u0443\u044e \u0434\u0438\u0440\u0435\u043a\u0442\u043e\u0440\u0438\u044e OpenVPN \u0438 \u043f\u0435\u0440\u0435\u0438\u043c\u0435\u043d\u0443\u0435\u043c:<\/p>\n<pre><code class=\"bash\">sudo cp ~\/vpn.justnikobird.ru.crt \/etc\/openvpn\/server\/server.crt sudo cp ~\/vpn.justnikobird.ru.key \/etc\/openvpn\/server\/server.key<\/code><\/pre>\n<p>\u041f\u0435\u0440\u0435\u043d\u0435\u0441\u0435\u043c\u00a0\u0441\u0435\u0440\u0442\u0438\u0444\u0438\u043a\u0430\u0442 \u043e\u0442\u043a\u0440\u044b\u0442\u043e\u0433\u043e \u043a\u043b\u044e\u0447\u0430 CA \u0432 \u0440\u0430\u0431\u043e\u0447\u0443\u044e \u0434\u0438\u0440\u0435\u043a\u0442\u043e\u0440\u0438\u044e OpenVPN:<\/p>\n<pre><code class=\"bash\">sudo cp ~\/ca.crt \/etc\/openvpn\/server\/<\/code><\/pre>\n<p>\u0421\u043a\u043e\u043f\u0438\u0440\u0443\u0435\u043c \u0448\u0430\u0431\u043b\u043e\u043d \u043a\u043e\u043d\u0444\u0438\u0433\u0443\u0440\u0430\u0446\u0438\u043e\u043d\u043d\u043e\u0433\u043e \u0444\u0430\u0439\u043b\u0430 \u0432 \u0440\u0430\u0431\u043e\u0447\u0443\u044e \u0434\u0438\u0440\u0435\u043a\u0442\u043e\u0440\u0438\u044e \u043f\u0440\u043e\u0433\u0440\u0430\u043c\u043c\u044b:<\/p>\n<pre><code class=\"bash\">sudo sudo cp \/usr\/share\/doc\/openvpn\/examples\/sample-config-files\/server.conf \/etc\/openvpn\/server\/ <\/code><\/pre>\n<p>\u0412\u044b\u043f\u043e\u043b\u043d\u0438\u043c \u043d\u0430\u0441\u0442\u0440\u043e\u0439\u043a\u0443 OpenVPN \u0432 \u043a\u043e\u043d\u0444\u0438\u0433\u0443\u0440\u0430\u0446\u0438\u043e\u043d\u043d\u043e\u043c \u0444\u0430\u0439\u043b\u0435 \u00ab<em>\/etc\/openvpn\/server\/server.conf<\/em>\u00bb, \u0438\u0437\u043c\u0435\u043d\u0438\u0432 \u0441\u043b\u0435\u0434\u0443\u044e\u0449\u0438\u0435 \u0441\u0442\u0440\u043e\u043a\u0438:<\/p>\n<pre><code class=\"bash\"># Diffie hellman parameters. # Generate your own with: #   openssl dhparam -out dh2048.pem 2048 ;dh dh2048.pem dh none  # If enabled, this directive will configure # all clients to redirect their default # network gateway through the VPN, causing # all IP traffic such as web browsing and # and DNS lookups to go through the VPN # (The OpenVPN server machine may need to NAT # or bridge the TUN\/TAP interface to the internet # in order for this to work properly). push \"redirect-gateway def1 bypass-dhcp\"  # Certain Windows-specific network settings # can be pushed to clients, such as DNS # or WINS server addresses.  CAVEAT: # http:\/\/openvpn.net\/faq.html#dhcpcaveats # The addresses below refer to the public # DNS servers provided by opendns.com. push \"dhcp-option DNS 208.67.222.222\" push \"dhcp-option DNS 208.67.220.220\"  # For extra security beyond that provided # by SSL\/TLS, create an \"HMAC firewall\" # to help block DoS attacks and UDP port flooding. # # Generate with: #   openvpn --genkey tls-auth ta.key # # The server and each client must have # a copy of this key. # The second parameter should be '0' # on the server and '1' on the clients. tls-crypt ta.key # This file is secret  # Select a cryptographic cipher. # This config item must be copied to # the client config file as well. # Note that v2.4 client\/server will automatically # negotiate AES-256-GCM in TLS mode. # See also the ncp-cipher option in the manpage cipher AES-256-GCM auth SHA256  # It's a good idea to reduce the OpenVPN # daemon's privileges after initialization. # # You can uncomment this out on # non-Windows systems. user nobody group nobody<\/code><\/pre>\n<details class=\"spoiler\">\n<summary>\u041a\u043e\u043d\u0444\u0438\u0433\u0443\u0440\u0430\u0446\u0438\u043e\u043d\u043d\u044b\u0439 \u0444\u0430\u0439\u043b OpenVPN \u0446\u0435\u043b\u0438\u043a\u043e\u043c<\/summary>\n<div class=\"spoiler__content\">\n<pre><code class=\"bash\">################################################# # Sample OpenVPN 2.0 config file for            # # multi-client server.                          # #                                               # # This file is for the server side              # # of a many-clients &lt;-> one-server              # # OpenVPN configuration.                        # #                                               # # OpenVPN also supports                         # # single-machine &lt;-> single-machine             # # configurations (See the Examples page         # # on the web site for more info).               # #                                               # # This config should work on Windows            # # or Linux\/BSD systems.  Remember on            # # Windows to quote pathnames and use            # # double backslashes, e.g.:                     # # \"C:\\\\Program Files\\\\OpenVPN\\\\config\\\\foo.key\" # #                                               # # Comments are preceded with '#' or ';'         # #################################################  # Which local IP address should OpenVPN # listen on? (optional) ;local a.b.c.d  # Which TCP\/UDP port should OpenVPN listen on? # If you want to run multiple OpenVPN instances # on the same machine, use a different port # number for each one.  You will need to # open up this port on your firewall. port 1194  # TCP or UDP server? ;proto tcp proto udp  # \"dev tun\" will create a routed IP tunnel, # \"dev tap\" will create an ethernet tunnel. # Use \"dev tap0\" if you are ethernet bridging # and have precreated a tap0 virtual interface # and bridged it with your ethernet interface. # If you want to control access policies # over the VPN, you must create firewall # rules for the the TUN\/TAP interface. # On non-Windows systems, you can give # an explicit unit number, such as tun0. # On Windows, use \"dev-node\" for this. # On most systems, the VPN will not function # unless you partially or fully disable # the firewall for the TUN\/TAP interface. ;dev tap dev tun  # Windows needs the TAP-Win32 adapter name # from the Network Connections panel if you # have more than one.  On XP SP2 or higher, # you may need to selectively disable the # Windows firewall for the TAP adapter. # Non-Windows systems usually don't need this. ;dev-node MyTap  # SSL\/TLS root certificate (ca), certificate # (cert), and private key (key).  Each client # and the server must have their own cert and # key file.  The server and all clients will # use the same ca file. # # See the \"easy-rsa\" directory for a series # of scripts for generating RSA certificates # and private keys.  Remember to use # a unique Common Name for the server # and each of the client certificates. # # Any X509 key management system can be used. # OpenVPN can also use a PKCS #12 formatted key file # (see \"pkcs12\" directive in man page). ca ca.crt cert server.crt key server.key  # This file should be kept secret  # Diffie hellman parameters. # Generate your own with: #   openssl dhparam -out dh2048.pem 2048 ;dh dh2048.pem dh none  # Network topology # Should be subnet (addressing via IP) # unless Windows clients v2.0.9 and lower have to # be supported (then net30, i.e. a \/30 per client) # Defaults to net30 (not recommended) ;topology subnet  # Configure server mode and supply a VPN subnet # for OpenVPN to draw client addresses from. # The server will take 10.8.0.1 for itself, # the rest will be made available to clients. # Each client will be able to reach the server # on 10.8.0.1. Comment this line out if you are # ethernet bridging. See the man page for more info. server 10.8.0.0 255.255.255.0  # Maintain a record of client &lt;-> virtual IP address # associations in this file.  If OpenVPN goes down or # is restarted, reconnecting clients can be assigned # the same virtual IP address from the pool that was # previously assigned. ifconfig-pool-persist \/var\/log\/openvpn\/ipp.txt  # Configure server mode for ethernet bridging. # You must first use your OS's bridging capability # to bridge the TAP interface with the ethernet # NIC interface.  Then you must manually set the # IP\/netmask on the bridge interface, here we # assume 10.8.0.4\/255.255.255.0.  Finally we # must set aside an IP range in this subnet # (start=10.8.0.50 end=10.8.0.100) to allocate # to connecting clients.  Leave this line commented # out unless you are ethernet bridging. ;server-bridge 10.8.0.4 255.255.255.0 10.8.0.50 10.8.0.100  # Configure server mode for ethernet bridging # using a DHCP-proxy, where clients talk # to the OpenVPN server-side DHCP server # to receive their IP address allocation # and DNS server addresses.  You must first use # your OS's bridging capability to bridge the TAP # interface with the ethernet NIC interface. # Note: this mode only works on clients (such as # Windows), where the client-side TAP adapter is # bound to a DHCP client. ;server-bridge  # Push routes to the client to allow it # to reach other private subnets behind # the server.  Remember that these # private subnets will also need # to know to route the OpenVPN client # address pool (10.8.0.0\/255.255.255.0) # back to the OpenVPN server. ;push \"route 192.168.10.0 255.255.255.0\" ;push \"route 192.168.20.0 255.255.255.0\"  # To assign specific IP addresses to specific # clients or if a connecting client has a private # subnet behind it that should also have VPN access, # use the subdirectory \"ccd\" for client-specific # configuration files (see man page for more info).  # EXAMPLE: Suppose the client # having the certificate common name \"Thelonious\" # also has a small subnet behind his connecting # machine, such as 192.168.40.128\/255.255.255.248. # First, uncomment out these lines: ;client-config-dir ccd ;route 192.168.40.128 255.255.255.248 # Then create a file ccd\/Thelonious with this line: #   iroute 192.168.40.128 255.255.255.248 # This will allow Thelonious' private subnet to # access the VPN.  This example will only work # if you are routing, not bridging, i.e. you are # using \"dev tun\" and \"server\" directives.  # EXAMPLE: Suppose you want to give # Thelonious a fixed VPN IP address of 10.9.0.1. # First uncomment out these lines: ;client-config-dir ccd ;route 10.9.0.0 255.255.255.252 # Then add this line to ccd\/Thelonious: #   ifconfig-push 10.9.0.1 10.9.0.2  # Suppose that you want to enable different # firewall access policies for different groups # of clients.  There are two methods: # (1) Run multiple OpenVPN daemons, one for each #     group, and firewall the TUN\/TAP interface #     for each group\/daemon appropriately. # (2) (Advanced) Create a script to dynamically #     modify the firewall in response to access #     from different clients.  See man #     page for more info on learn-address script. ;learn-address .\/script  # If enabled, this directive will configure # all clients to redirect their default # network gateway through the VPN, causing # all IP traffic such as web browsing and # and DNS lookups to go through the VPN # (The OpenVPN server machine may need to NAT # or bridge the TUN\/TAP interface to the internet # in order for this to work properly). push \"redirect-gateway def1 bypass-dhcp\"  # Certain Windows-specific network settings # can be pushed to clients, such as DNS # or WINS server addresses.  CAVEAT: # http:\/\/openvpn.net\/faq.html#dhcpcaveats # The addresses below refer to the public # DNS servers provided by opendns.com. push \"dhcp-option DNS 208.67.222.222\" push \"dhcp-option DNS 208.67.220.220\"  # Uncomment this directive to allow different # clients to be able to \"see\" each other. # By default, clients will only see the server. # To force clients to only see the server, you # will also need to appropriately firewall the # server's TUN\/TAP interface. ;client-to-client  # Uncomment this directive if multiple clients # might connect with the same certificate\/key # files or common names.  This is recommended # only for testing purposes.  For production use, # each client should have its own certificate\/key # pair. # # IF YOU HAVE NOT GENERATED INDIVIDUAL # CERTIFICATE\/KEY PAIRS FOR EACH CLIENT, # EACH HAVING ITS OWN UNIQUE \"COMMON NAME\", # UNCOMMENT THIS LINE OUT. ;duplicate-cn  # The keepalive directive causes ping-like # messages to be sent back and forth over # the link so that each side knows when # the other side has gone down. # Ping every 10 seconds, assume that remote # peer is down if no ping received during # a 120 second time period. keepalive 10 120  # For extra security beyond that provided # by SSL\/TLS, create an \"HMAC firewall\" # to help block DoS attacks and UDP port flooding. # # Generate with: #   openvpn --genkey tls-auth ta.key # # The server and each client must have # a copy of this key. # The second parameter should be '0' # on the server and '1' on the clients. tls-crypt ta.key # This file is secret  # Select a cryptographic cipher. # This config item must be copied to # the client config file as well. # Note that v2.4 client\/server will automatically # negotiate AES-256-GCM in TLS mode. # See also the ncp-cipher option in the manpage cipher AES-256-GCM auth SHA256  # Enable compression on the VPN link and push the # option to the client (v2.4+ only, for earlier # versions see below) ;compress lz4-v2 ;push \"compress lz4-v2\"  # For compression compatible with older clients use comp-lzo # If you enable it here, you must also # enable it in the client config file. ;comp-lzo  # The maximum number of concurrently connected # clients we want to allow. ;max-clients 100  # It's a good idea to reduce the OpenVPN # daemon's privileges after initialization. # # You can uncomment this out on # non-Windows systems. user nobody group nobody  # The persist options will try to avoid # accessing certain resources on restart # that may no longer be accessible because # of the privilege downgrade. persist-key persist-tun  # Output a short status file showing # current connections, truncated # and rewritten every minute. status \/var\/log\/openvpn\/openvpn-status.log  # By default, log messages will go to the syslog (or # on Windows, if running as a service, they will go to # the \"\\Program Files\\OpenVPN\\log\" directory). # Use log or log-append to override this default. # \"log\" will truncate the log file on OpenVPN startup, # while \"log-append\" will append to it.  Use one # or the other (but not both). ;log         \/var\/log\/openvpn\/openvpn.log ;log-append  \/var\/log\/openvpn\/openvpn.log  # Set the appropriate level of log # file verbosity. # # 0 is silent, except for fatal errors # 4 is reasonable for general usage # 5 and 6 can help to debug connection problems # 9 is extremely verbose verb 3  # Silence repeating messages.  At most 20 # sequential messages of the same message # category will be output to the log. ;mute 20  # Notify the client that when the server restarts so it # can automatically reconnect. explicit-exit-notify 1<\/code><\/pre>\n<\/p>\n<\/div>\n<\/details>\n<p>\u0421\u043e\u0437\u0434\u0430\u0434\u0438\u043c \u0433\u0440\u0443\u043f\u043f\u0443 \u00abnobody\u00bb \u0434\u043b\u044f \u043a\u043e\u0440\u0440\u0435\u043a\u0442\u043d\u043e\u0439 \u0440\u0430\u0431\u043e\u0442\u044b vpn-\u0441\u0435\u0440\u0432\u0438\u0441\u0430:<\/p>\n<pre><code class=\"bash\">sudo groupadd nobody<\/code><\/pre>\n<p>\u0413\u0440\u0443\u043f\u043f\u0430 nobody \u043d\u0443\u0436\u043d\u0430 \u0434\u043b\u044f \u0442\u043e\u0433\u043e \u0447\u0442\u043e\u0431\u044b OpenVPN-\u0441\u0435\u0440\u0432\u0435\u0440 \u043c\u043e\u0433 \u0440\u0430\u0431\u043e\u0442\u0430\u0442\u044c \u0441 \u043f\u043e\u043d\u0438\u0436\u0435\u043d\u043d\u044b\u043c\u0438 \u043f\u0440\u0438\u0432\u0438\u043b\u0435\u0433\u0438\u044f\u043c\u0438, \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u044f \u0434\u0438\u0440\u0435\u043a\u0442\u0438\u0432\u044b user nobody, group nobody \u0438 chroot, \u0438 \u043f\u0440\u0438 \u044d\u0442\u043e\u043c \u0431\u0443\u0434\u0435\u0442 \u0432\u043e\u0437\u043c\u043e\u0436\u043d\u043e\u0441\u0442\u044c \u0430\u0443\u0442\u0435\u043d\u0442\u0438\u0444\u0438\u0446\u0438\u0440\u043e\u0432\u0430\u0442\u044c\u0441\u044f \u043f\u043e \u0442\u0435\u043d\u0435\u0432\u043e\u043c\u0443 \u0444\u0430\u0439\u043b\u0443 \u043f\u0430\u0440\u043e\u043b\u0435\u0439, \u0434\u043e\u0441\u0442\u0443\u043f\u043d\u043e\u043c\u0443 \u0442\u043e\u043b\u044c\u043a\u043e \u0434\u043b\u044f \u0447\u0442\u0435\u043d\u0438\u044f root.<\/p>\n<h3>\u041d\u0430\u0441\u0442\u0440\u043e\u0439\u043a\u0430 tls-crypt-v2<\/h3>\n<p>tls-crypt &#8212; \u044d\u0442\u043e \u0444\u0443\u043d\u043a\u0446\u0438\u044f, \u043a\u043e\u0442\u043e\u0440\u0430\u044f \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u0435\u0442 \u043d\u0430\u043c \u0441\u043c\u044f\u0433\u0447\u0430\u0442\u044c DoS \u0438 DDoS-\u0430\u0442\u0430\u043a\u0438 \u043d\u0430 \u0441\u0435\u0440\u0432\u0435\u0440\u0430\u0445 OpenVPN, \u0431\u043b\u0430\u0433\u043e\u0434\u0430\u0440\u044f \u044d\u0442\u0438\u043c \u043a\u043b\u044e\u0447\u0430\u043c, \u043a\u043e\u0442\u043e\u0440\u044b\u0435 \u043c\u044b \u0441\u043e\u0437\u0434\u0430\u0435\u043c \u043d\u0435\u043f\u043e\u0441\u0440\u0435\u0434\u0441\u0442\u0432\u0435\u043d\u043d\u043e \u0432 OpenVPN, \u043c\u044b \u0441\u043c\u043e\u0436\u0435\u043c \u0432\u044b\u043f\u043e\u043b\u043d\u0438\u0442\u044c \u043f\u0440\u0435\u0434\u0432\u0430\u0440\u0438\u0442\u0435\u043b\u044c\u043d\u0443\u044e \u0430\u0443\u0442\u0435\u043d\u0442\u0438\u0444\u0438\u043a\u0430\u0446\u0438\u044e \u043a\u0430\u0436\u0434\u043e\u0433\u043e \u043a\u043b\u0438\u0435\u043d\u0442\u0430, \u0447\u0442\u043e\u0431\u044b \u043f\u043e\u0437\u0436\u0435 \u043f\u0435\u0440\u0435\u0439\u0442\u0438 \u043d\u0430 \u044d\u0442\u0430\u043f \u0430\u0443\u0442\u0435\u043d\u0442\u0438\u0444\u0438\u043a\u0430\u0446\u0438\u0438 \u0441 \u0441\u0435\u0440\u0442\u0438\u0444\u0438\u043a\u0430\u0442\u043e\u043c \u043a\u043b\u0438\u0435\u043d\u0442\u0430. \u041f\u0435\u0440\u0432\u0430\u044f \u0432\u0435\u0440\u0441\u0438\u044f tls-crypt \u0442\u0440\u0435\u0431\u0443\u0435\u0442, \u0447\u0442\u043e\u0431\u044b \u0438 \u0441\u0435\u0440\u0432\u0435\u0440, \u0438 \u0432\u0441\u0435 \u043a\u043b\u0438\u0435\u043d\u0442\u044b \u0438\u043c\u0435\u043b\u0438 \u043e\u0434\u0438\u043d \u0438 \u0442\u043e\u0442 \u0436\u0435 \u043a\u043b\u044e\u0447 tls-crypt. \u0421 \u043f\u043e\u043c\u043e\u0449\u044c\u044e tls-crypt-v2 \u043c\u044b \u043c\u043e\u0436\u0435\u043c \u0441\u0434\u0435\u043b\u0430\u0442\u044c \u0442\u0430\u043a, \u0447\u0442\u043e\u0431\u044b \u0443 \u043a\u0430\u0436\u0434\u043e\u0433\u043e \u043a\u043b\u0438\u0435\u043d\u0442\u0430 \u0431\u044b\u043b \u0441\u0432\u043e\u0439 \u0441\u043e\u0431\u0441\u0442\u0432\u0435\u043d\u043d\u044b\u0439 \u043a\u043b\u044e\u0447 tls-crypt, \u0442\u0430\u043a\u0438\u043c \u043e\u0431\u0440\u0430\u0437\u043e\u043c, \u043e\u0447\u0435\u043d\u044c \u043a\u0440\u0443\u043f\u043d\u044b\u0435 \u043e\u0440\u0433\u0430\u043d\u0438\u0437\u0430\u0446\u0438\u0438 \u0438\u043b\u0438 \u043f\u0440\u043e\u0432\u0430\u0439\u0434\u0435\u0440\u044b OpenVPN \u043c\u043e\u0433\u0443\u0442 \u0430\u0434\u0435\u043a\u0432\u0430\u0442\u043d\u043e \u0437\u0430\u0449\u0438\u0442\u0438\u0442\u044c \u0441\u0432\u043e\u0438 \u0441\u0435\u0440\u0432\u0435\u0440\u044b, \u0441\u043e\u0437\u0434\u0430\u0432 \u043d\u0435\u0441\u043a\u043e\u043b\u044c\u043a\u043e \u0442\u0430\u043a\u0438\u0445 \u043a\u043b\u044e\u0447\u0435\u0439.<\/p>\n<p>\u0421\u0433\u0435\u043d\u0435\u0440\u0438\u0440\u0443\u0435\u043c tls-crypt-v2 \u043a\u043b\u044e\u0447 \u0432 \u0440\u0430\u0431\u043e\u0447\u0435\u0439 \u0434\u0438\u0440\u0435\u043a\u0442\u043e\u0440\u0438\u0438 OpenVPN:<\/p>\n<pre><code class=\"bash\">cd \/etc\/openvpn\/server\/ sudo openvpn --genkey --secret ta.key<\/code><\/pre>\n<h3>\u0412\u043a\u043b\u044e\u0447\u0435\u043d\u0438\u0435 \u0444\u0443\u043d\u043a\u0446\u0438\u0438 \u043c\u0430\u0440\u0448\u0440\u0443\u0442\u0438\u0437\u0430\u0446\u0438\u0438<\/h3>\n<p>\u0412\u043a\u043b\u044e\u0447\u0438\u043c \u0444\u0443\u043d\u043a\u0446\u0438\u044e \u043c\u0430\u0440\u0448\u0440\u0443\u0442\u0438\u0437\u0430\u0446\u0438\u0438 \u0432 Linux \u0432 \u043a\u043e\u043d\u0444\u0438\u0433\u0443\u0440\u0430\u0446\u0438\u043e\u043d\u043d\u043e\u043c \u0444\u0430\u0439\u043b\u0435 \u00ab<em>\/etc\/sysctl.conf<\/em>\u00bb, \u0440\u0430\u0441\u043a\u043e\u043c\u043c\u0435\u043d\u0442\u0438\u0440\u043e\u0432\u0430\u0432 \u0441\u043b\u0435\u0434\u0443\u044e\u0449\u0443\u044e \u0441\u0442\u0440\u043e\u043a\u0443:<\/p>\n<pre><code class=\"bash\">net.ipv4.ip_forward=1<\/code><\/pre>\n<p>\u041f\u0435\u0440\u0435\u0437\u0430\u0433\u0440\u0443\u0437\u0438\u043c \u0441\u0435\u0440\u0432\u0438\u0441:<\/p>\n<pre><code class=\"bash\">sudo sysctl -p<\/code><\/pre>\n<h3>\u041d\u0430\u0441\u0442\u0440\u043e\u0439\u043a\u0430 iptables<\/h3>\n<p>\u0412\u044b\u043f\u043e\u043b\u043d\u0438\u043c \u043d\u0430\u0441\u0442\u0440\u043e\u0439\u043a\u0443 iptables \u0441\u043e\u0433\u043b\u0430\u0441\u043d\u043e \u0432\u044b\u043f\u043e\u043b\u043d\u0435\u043d\u043d\u044b\u043c \u0440\u0430\u043d\u0435\u0435 \u043d\u0430\u0441\u0442\u0440\u043e\u0439\u043a\u0430\u043c:<\/p>\n<pre><code class=\"bash\"># OpenVPN sudo iptables -A INPUT -i eth0 -m state --state NEW -p udp --dport 1194 -j ACCEPT -m comment --comment openvpn # Allow TUN interfaces connections to OpenVPN server sudo iptables -A INPUT -i tun+ -j ACCEPT -m comment --comment openvpn # Allow TUN interfaces connections to be forwarded through interfaces sudo iptables -A FORWARD -i tun+ -j ACCEPT -m comment --comment openvpn sudo iptables -A FORWARD -i tun+ -o eth0 -m state --state RELATED,ESTABLISHED -j ACCEPT -m comment --comment openvpn sudo iptables -A FORWARD -i eth0 -o tun+ -m state --state RELATED,ESTABLISHED -j ACCEPT -m comment --comment openvpn # NAT the VPN client traffic to the interface sudo iptables -t nat -A POSTROUTING -s 10.8.0.0\/24 -o eth0 -j MASQUERADE -m comment --comment openvpn<\/code><\/pre>\n<details class=\"spoiler\">\n<summary>\u041f\u043e\u044f\u0441\u043d\u0435\u043d\u0438\u0435 \u043a \u043d\u0430\u0441\u0442\u0440\u043e\u0439\u043a\u0430\u043c iptables<\/summary>\n<div class=\"spoiler__content\">\n<p>\u0417\u043d\u0430\u0447\u0435\u043d\u0438\u0435 \u00ab<strong>eth0\u00bb<\/strong>, \u043a\u043e\u0442\u043e\u0440\u043e\u0435 \u043f\u0440\u0438\u043c\u0435\u043d\u044f\u0442\u0441\u044f \u0432 \u043d\u0435\u0441\u043a\u043e\u043b\u044c\u043a\u0438\u0445 \u043e\u043f\u0446\u0438\u044f\u0445 &#8212; \u044d\u0442\u043e \u0438\u043c\u044f \u0438\u043d\u0442\u0435\u0440\u0444\u0435\u0439\u0441\u0430 vm, \u043a\u043e\u0442\u043e\u0440\u044b\u0439 \u0441\u043c\u043e\u0442\u0440\u0438\u0442 \u0432 \u0441\u0435\u0442\u044c &#8212; \u0432 \u0432\u0430\u0448\u0435\u043c \u0441\u043b\u0443\u0447\u0430\u0435 \u043e\u043d \u043c\u043e\u0436\u0435\u0442 \u043e\u0442\u043b\u0438\u0447\u0430\u0442\u044c\u0441\u044f:<\/p>\n<pre><code class=\"bash\">nikolay@vpn:~$ ip a 1: lo: &lt;LOOPBACK,UP,LOWER_UP> mtu 65536 qdisc noqueue state UNKNOWN group default qlen 1000     link\/loopback 00:00:00:00:00:00 brd 00:00:00:00:00:00     inet 127.0.0.1\/8 scope host lo        valid_lft forever preferred_lft forever 2: eth0: &lt;BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc fq_codel state UP group default qlen 1000     link\/ether 0a:67:45:3e:3f:03 brd ff:ff:ff:ff:ff:ff     altname enp0s3     altname ens3     inet 10.0.0.5\/24 metric 100 brd 10.0.0.255 scope global dynamic eth0        valid_lft 22804sec preferred_lft 22804sec<\/code><\/pre>\n<p>\u041e\u043f\u0446\u0438\u044f \u00ab<strong>-p\u00bb<\/strong> \u043c\u043e\u0436\u0435\u0442 \u0431\u044b\u0442\u044c \u0437\u0430\u0434\u0430\u043d\u0430 \u043a\u0430\u043a \u00abudp\u00bb \u0438\u043b\u0438 \u00abtcp\u00bb &#8212; \u044d\u0442\u043e \u0437\u0430\u0432\u0438\u0441\u0438\u0442 \u043e\u0442 \u043d\u0430\u0441\u0442\u0440\u043e\u0435\u043a OpenVPN (\u043f\u043e \u0443\u043c\u043e\u043b\u0447\u0430\u043d\u0438\u044e \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u0435\u0442\u0441\u044f \u00abudp\u00bb).<\/p>\n<p>\u041e\u043f\u0446\u0438\u044f \u00ab<strong>&#8212;dport<\/strong>\u00bb \u0442\u043e\u0436\u0435 \u043c\u043e\u0436\u0435\u0442 \u0431\u044b\u0442\u044c \u043e\u0442\u043b\u0438\u0447\u043d\u0430 \u043e\u0442 \u0437\u043d\u0430\u0447\u0435\u043d\u0438\u044f \u043f\u043e \u0443\u043c\u043e\u043b\u0447\u0430\u043d\u0438\u044e 1194 &#8212; \u044d\u0442\u043e \u0442\u043e\u0436\u0435 \u0437\u0430\u0434\u0430\u0435\u0442\u0441\u044f \u0432 \u043d\u0430\u0441\u0442\u0440\u043e\u0439\u043a\u0430\u0445 OpenVPN.<\/p>\n<\/div>\n<\/details>\n<p>\u0421\u043e\u0445\u0440\u0430\u043d\u0438\u043c \u043a\u043e\u043d\u0444\u0438\u0433\u0443\u0440\u0430\u0446\u0438\u044e iptables \u0441 \u043f\u043e\u043c\u043e\u0449\u044c\u044e \u0438\u043d\u0441\u0442\u0440\u0443\u043c\u0435\u043d\u0442\u0430 iptables-persistent:<\/p>\n<pre><code class=\"bash\">sudo apt-get install -y iptables-persistent sudo service netfilter-persistent save<\/code><\/pre>\n<p>\u041f\u0435\u0440\u0435\u0437\u0430\u0433\u0440\u0443\u0437\u0438\u043c \u0441\u0435\u0440\u0432\u0438\u0441 OpenVPN \u0438 \u043d\u0430\u0441\u0442\u0440\u043e\u0438\u043c \u0430\u0432\u0442\u043e\u043c\u0430\u0442\u0438\u0447\u0435\u0441\u043a\u0438\u0439 \u0437\u0430\u043f\u0443\u0441\u043a:<\/p>\n<pre><code class=\"bash\">sudo systemctl restart openvpn-server@server.service sudo systemctl enable openvpn-server@server.service<\/code><\/pre>\n<h3>\u041f\u043e\u0434\u0433\u043e\u0442\u043e\u0432\u043a\u0430 \u043a\u043e\u043d\u0444\u0438\u0433\u0443\u0440\u0430\u0446\u0438\u043e\u043d\u043d\u043e\u0433\u043e \u0444\u0430\u0439\u043b\u0430 \u0434\u043b\u044f \u043a\u043b\u0438\u0435\u043d\u0442\u0430<\/h3>\n<p>\u041f\u043e\u0434\u0433\u043e\u0442\u043e\u0432\u0438\u043c \u0441\u0440\u0435\u0434\u0443 \u0434\u043b\u044f \u0441\u0431\u043e\u0440\u043a\u0438:<\/p>\n<p>\u0421\u043e\u0437\u0434\u0430\u0434\u0438\u043c \u0434\u0438\u0440\u0435\u043a\u0442\u043e\u0440\u0438\u044e \u00ab<em>\u0441lients_config<\/em>\u00bb \u0432 \u0440\u0430\u0431\u043e\u0447\u0435\u043c \u043a\u0430\u0442\u0430\u043b\u043e\u0433\u0435 \u043f\u0440\u043e\u0433\u0440\u0430\u043c\u043c\u044b \u0441\u043e \u0441\u043b\u0435\u0434\u0443\u044e\u0449\u0435\u0439 \u0441\u0442\u0440\u0443\u043a\u0442\u0443\u0440\u043e\u0439:<\/p>\n<pre><code class=\"bash\">sudo mkdir -p \/etc\/openvpn\/clients_config\/confiles \/etc\/openvpn\/clients_config\/keys<\/code><\/pre>\n<p>\u0421\u043a\u043e\u043f\u0438\u0440\u0443\u0435\u043c \u0448\u0430\u0431\u043b\u043e\u043d \u043a\u043e\u043d\u0444\u0438\u0433\u0443\u0440\u0430\u0446\u0438\u043e\u043d\u043d\u043e\u0433\u043e \u0444\u0430\u0439\u043b\u0430 \u043a\u043b\u0438\u0435\u043d\u0442\u0430 \u0432 \u043e\u0434\u043d\u0443 \u0438\u0437 \u0441\u043e\u0437\u0434\u0430\u043d\u043d\u044b\u0445 \u043d\u0430\u043c\u0438 \u0434\u0438\u0440\u0435\u043a\u0442\u043e\u0440\u0438\u0439 \u0438 \u043f\u0435\u0440\u0435\u0438\u043c\u0435\u043d\u0443\u0435\u043c:<\/p>\n<pre><code class=\"bash\">sudo cp \/usr\/share\/doc\/openvpn\/examples\/sample-config-files\/client.conf \/etc\/openvpn\/clients_config\/confiles\/base.conf<\/code><\/pre>\n<p>\u0412\u043d\u0435\u0441\u0435\u043c \u0438\u0437\u043c\u0435\u043d\u0435\u043d\u0438\u044f \u0432 \u043a\u043b\u0438\u0435\u043d\u0442\u0441\u043a\u0438\u0439 \u043a\u043e\u043d\u0444\u0438\u0433\u0443\u0440\u0430\u0446\u0438\u043e\u043d\u043d\u044b\u0439 \u0444\u0430\u0439\u043b \u00ab<em>\/etc\/openvpn\/clients_config\/confiles\/base.conf<\/em>\u00bb:<\/p>\n<pre><code class=\"bash\"># The hostname\/IP and port of the server. # You can have multiple remote entries # to load balance between the servers. remote vpn.justnikobird.ru 1194  # Downgrade privileges after initialization (non-Windows only) user nobody group nobody  # SSL\/TLS parms. # See the server config file for more # description.  It's best to use # a separate .crt\/.key file pair # for each client.  A single ca # file can be used for all clients. ;ca ca.crt ;cert client.crt ;key client.key  # If a tls-auth key is used on the server # then every client must also have the key. ;tls-crypt ta.key 1  # Select a cryptographic cipher. # If the cipher option is used on the server # then you must also specify it here. # Note that v2.4 client\/server will automatically # negotiate AES-256-GCM in TLS mode. # See also the data-ciphers option in the manpage cipher AES-256-GCM auth SHA256 key-direction 1<\/code><\/pre>\n<details class=\"spoiler\">\n<summary>\u041a\u043e\u043d\u0444\u0438\u0433\u0443\u0440\u0430\u0446\u0438\u043e\u043d\u043d\u044b\u0439 \u0444\u0430\u0439\u043b \u043a\u043b\u0438\u0435\u043d\u0442\u0430 \u0446\u0435\u043b\u0438\u043a\u043e\u043c<\/summary>\n<div class=\"spoiler__content\">\n<pre><code class=\"bash\">############################################## # Sample client-side OpenVPN 2.0 config file # # for connecting to multi-client server.     # #                                            # # This configuration can be used by multiple # # clients, however each client should have   # # its own cert and key files.                # #                                            # # On Windows, you might want to rename this  # # file so it has a .ovpn extension           # ##############################################  # Specify that we are a client and that we # will be pulling certain config file directives # from the server. client  # Use the same setting as you are using on # the server. # On most systems, the VPN will not function # unless you partially or fully disable # the firewall for the TUN\/TAP interface. ;dev tap dev tun  # Windows needs the TAP-Win32 adapter name # from the Network Connections panel # if you have more than one.  On XP SP2, # you may need to disable the firewall # for the TAP adapter. ;dev-node MyTap  # Are we connecting to a TCP or # UDP server?  Use the same setting as # on the server. ;proto tcp proto udp  # The hostname\/IP and port of the server. # You can have multiple remote entries # to load balance between the servers. remote vpn.justnikobird.ru 1194 ;remote my-server-2 1194  # Choose a random host from the remote # list for load-balancing.  Otherwise # try hosts in the order specified. ;remote-random  # Keep trying indefinitely to resolve the # host name of the OpenVPN server.  Very useful # on machines which are not permanently connected # to the internet such as laptops. resolv-retry infinite  # Most clients don't need to bind to # a specific local port number. nobind  # Downgrade privileges after initialization (non-Windows only) user nobody group nobody  # Try to preserve some state across restarts. persist-key persist-tun  # If you are connecting through an # HTTP proxy to reach the actual OpenVPN # server, put the proxy server\/IP and # port number here.  See the man page # if your proxy server requires # authentication. ;http-proxy-retry # retry on connection failures ;http-proxy [proxy server] [proxy port #]  # Wireless networks often produce a lot # of duplicate packets.  Set this flag # to silence duplicate packet warnings. ;mute-replay-warnings  # SSL\/TLS parms. # See the server config file for more # description.  It's best to use # a separate .crt\/.key file pair # for each client.  A single ca # file can be used for all clients. ;ca ca.crt ;cert client.crt ;key client.key  # Verify server certificate by checking that the # certificate has the correct key usage set. # This is an important precaution to protect against # a potential attack discussed here: #  http:\/\/openvpn.net\/howto.html#mitm # # To use this feature, you will need to generate # your server certificates with the keyUsage set to #   digitalSignature, keyEncipherment # and the extendedKeyUsage to #   serverAuth # EasyRSA can do this for you. remote-cert-tls server  # If a tls-auth key is used on the server # then every client must also have the key. ;tls-crypt ta.key 1  # Select a cryptographic cipher. # If the cipher option is used on the server # then you must also specify it here. # Note that v2.4 client\/server will automatically # negotiate AES-256-GCM in TLS mode. # See also the data-ciphers option in the manpage cipher AES-256-GCM auth SHA256 key-direction 1  # Enable compression on the VPN link. # Don't enable this unless it is also # enabled in the server config file. #comp-lzo  # Set log file verbosity. verb 3  # Silence repeating messages ;mute 20<\/code><\/pre>\n<\/p>\n<\/div>\n<\/details>\n<p>\u041f\u0435\u0440\u0435\u043d\u0435\u0441\u0435\u043c\u00a0<a href=\"https:\/\/habr.com\/ru\/articles\/789056\/#issue\" rel=\"noopener noreferrer nofollow\">\u043f\u043e\u0434\u043f\u0438\u0441\u0430\u043d\u043d\u044b\u0435<\/a>\u00a0\u043d\u0430 CA \u043a\u043b\u044e\u0447\u0438 \u0434\u043b\u044f vpn-\u043a\u043b\u0438\u0435\u043d\u0442\u0430, \u0441\u0435\u0440\u0442\u0438\u0444\u0438\u043a\u0430\u0442 \u043e\u0442\u043a\u0440\u044b\u0442\u043e\u0433\u043e \u043a\u043b\u044e\u0447\u0430 CA \u0438 tls-crypt \u043a\u043b\u044e\u0447 \u0432 \u0434\u0438\u0440\u0435\u043a\u0442\u043e\u0440\u0438\u044e \u00ab<em>\/etc\/openvpn\/clients_config\/keys<\/em>\u00bb:<\/p>\n<pre><code class=\"bash\">sudo cp ~\/client-1.key \/etc\/openvpn\/clients_config\/keys\/ sudo cp ~\/client-1.crt \/etc\/openvpn\/clients_config\/keys\/ sudo cp \/etc\/openvpn\/server\/ca.crt \/etc\/openvpn\/clients_config\/keys\/ sudo cp \/etc\/openvpn\/server\/ta.key \/etc\/openvpn\/clients_config\/keys\/<\/code><\/pre>\n<p>\u041e\u0442 \u0438\u043c\u0435\u043d\u0438 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u044f \u00abroot\u00bb \u0441\u043e\u0437\u0434\u0430\u0434\u0438\u043c bash-\u0441\u043a\u0440\u0438\u043f\u0442 \u00ab<em>\/etc\/openvpn\/clients_config\/make_config.sh<\/em>\u00bb, \u043a\u043e\u0442\u043e\u0440\u044b\u0439 \u0441\u043e\u0431\u0435\u0440\u0435\u0442 \u043a\u043e\u043d\u0444\u0438\u0433\u0443\u0440\u0430\u0446\u0438\u043e\u043d\u043d\u044b\u0439 \u0444\u0430\u0439\u043b \u0434\u043b\u044f \u043f\u043e\u0434\u043a\u043b\u044e\u0447\u0435\u043d\u0438\u044f \u043a\u043b\u0438\u0435\u043d\u0442\u0430:<\/p>\n<pre><code class=\"bash\">#!\/bin\/bash  # $1 client cert # $2 client key # $3 client name  KEY_DIR=\/etc\/openvpn\/clients_config\/keys OUTPUT_DIR=\/etc\/openvpn\/clients_config BASE_CONFIG=\/etc\/openvpn\/clients_config\/confiles\/base.conf  cat ${BASE_CONFIG} \\     &lt;(echo -e '&lt;ca>') \\     ${KEY_DIR}\/ca.crt \\     &lt;(echo -e '&lt;\/ca>\\n&lt;cert>') \\     ${KEY_DIR}\/${1} \\     &lt;(echo -e '&lt;\/cert>\\n&lt;key>') \\     ${KEY_DIR}\/${2} \\     &lt;(echo -e '&lt;\/key>\\n&lt;tls-crypt>') \\     ${KEY_DIR}\/ta.key \\     &lt;(echo -e '&lt;\/tls-crypt>') \\     > ${OUTPUT_DIR}\/${3}.ovpn<\/code><\/pre>\n<p>\u0412\u044b\u0434\u0430\u0434\u0438\u043c \u043f\u0440\u0430\u0432\u0430 \u043d\u0430 \u0438\u0441\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u0435 \u0441\u043a\u0440\u0438\u043f\u0442\u0430:<\/p>\n<pre><code class=\"bash\">sudo chmod ug+x \/etc\/openvpn\/clients_config\/make_config.sh<\/code><\/pre>\n<p>\u0421\u043e\u0431\u0435\u0440\u0435\u043c \u043a\u043e\u043d\u0444\u0438\u0433\u0443\u0440\u0430\u0446\u0438\u043e\u043d\u043d\u044b\u0439 \u0444\u0430\u0439\u043b \u0434\u043b\u044f \u043a\u043b\u0438\u0435\u043d\u0442\u0430:<\/p>\n<pre><code class=\"bash\">sudo \/etc\/openvpn\/clients_config\/make_config.sh client-1.crt client-1.key client-1<\/code><\/pre>\n<p>\u0412 \u0440\u0435\u0437\u0443\u043b\u044c\u0442\u0430\u0442\u0435 \u0432\u044b\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u044f \u0441\u043a\u0440\u0438\u043f\u0442\u0430 \u0431\u044b\u043b \u0441\u043e\u0437\u0434\u0430\u043d \u0444\u0430\u0439\u043b \u00ab<strong><em>\/etc\/openvpn\/clients_config\/client-1.ovpn<\/em><\/strong>\u00bb, \u043a\u043e\u0442\u043e\u0440\u044b\u0439 \u043d\u0435\u043e\u0431\u0445\u043e\u0434\u0438\u043c\u043e \u043f\u0435\u0440\u0435\u043d\u0435\u0441\u0442\u0438 \u043d\u0430 \u043a\u043b\u0438\u0435\u043d\u0442\u0441\u043a\u0443\u044e \u043c\u0430\u0448\u0438\u043d\u0443 \u0438 \u0437\u0430\u043f\u0443\u0441\u0442\u0438\u0442\u044c \u0438\u0437 \u043a\u043b\u0438\u0435\u043d\u0442\u0430 OpenVPN.<\/p>\n<h3>\u041f\u043e\u0434\u043a\u043b\u044e\u0447\u0435\u043d\u0438\u0435 \u043a\u043b\u0438\u0435\u043d\u0442\u0430 \u043a OpenVPN<\/h3>\n<p>\u0423\u0441\u0442\u0430\u043d\u043e\u0432\u0438\u043c \u043f\u0440\u043e\u0433\u0440\u0430\u043c\u043c\u0443 OpenVPN \u043d\u0430 \u043a\u043b\u0438\u0435\u043d\u0442\u0441\u043a\u0443\u044e \u043c\u0430\u0448\u0438\u043d\u0443, \u043f\u0435\u0440\u0435\u043d\u0435\u0441\u0435\u043c \u0440\u0430\u043d\u0435\u0435 \u0441\u043e\u0431\u0440\u0430\u043d\u043d\u044b\u0439 \u043a\u043e\u043d\u0444\u0438\u0433\u0443\u0440\u0430\u0446\u0438\u043e\u043d\u043d\u044b\u0439 \u0444\u0430\u0439\u043b \u0438 \u0438\u043c\u043f\u043e\u0440\u0442\u0438\u0440\u0443\u0435\u043c \u0435\u0433\u043e \u0432 \u043f\u0440\u043e\u0433\u0440\u0430\u043c\u043c\u0443:<\/p>\n<figure class=\"full-width\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/habrastorage.org\/r\/w1560\/getpro\/habr\/upload_files\/a5d\/004\/758\/a5d0047582edc2431cae3c4f0e3b7994.png\" width=\"598\" height=\"109\" data-src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/a5d\/004\/758\/a5d0047582edc2431cae3c4f0e3b7994.png\"\/><\/figure>\n<p>\u041f\u043e\u0434\u043a\u043b\u044e\u0447\u0438\u043c\u0441\u044f \u043a OpenVPN-\u0441\u0435\u0440\u0432\u0435\u0440\u0443:<\/p>\n<figure class=\"\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/habrastorage.org\/r\/w1560\/getpro\/habr\/upload_files\/319\/de3\/908\/319de39085d952961510054c64f81977.png\" width=\"512\" height=\"253\" data-src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/319\/de3\/908\/319de39085d952961510054c64f81977.png\"\/><\/figure>\n<p>\u041f\u043e\u0434\u043a\u043b\u044e\u0447\u0435\u043d\u0438\u0435 \u0432\u044b\u043f\u043e\u043b\u043d\u0435\u043d\u043e \u0443\u0441\u043f\u0435\u0448\u043d\u043e:<\/p>\n<figure class=\"\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/habrastorage.org\/r\/w1560\/getpro\/habr\/upload_files\/388\/fff\/706\/388fff7068b0dff8a8a810ff59402359.png\" width=\"371\" height=\"174\" data-src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/388\/fff\/706\/388fff7068b0dff8a8a810ff59402359.png\"\/><\/figure>\n<p>\u0417\u0430\u0439\u0434\u0435\u043c \u043d\u0430 \u0441\u0430\u0439\u0442 \u00ab<a href=\"https:\/\/yandex.ru\/internet\/\" rel=\"noopener noreferrer nofollow\"><strong>https:\/\/yandex.ru\/internet<\/strong><\/a>\u00bb \u0438 \u0443\u0431\u0435\u0434\u0438\u043c\u0441\u044f \u0432 \u0442\u043e\u043c, \u0447\u0442\u043e \u0432 \u0441\u0435\u0442\u0438 \u043c\u044b \u0432\u0438\u0434\u043d\u044b \u0447\u0435\u0440\u0435\u0437 ip-\u0430\u0434\u0440\u0435\u0441 vm \u00abvpn\u00bb.<\/p>\n<h2>\u041f\u0435\u0440\u0435\u0441\u0431\u043e\u0440\u043a\u0430 deb-\u043f\u0430\u043a\u0435\u0442\u0430 OpenVPN<\/h2>\n<p>\u041f\u0435\u0440\u0435\u0441\u043e\u0431\u0435\u0440\u0435\u043c \u043f\u0430\u043a\u0435\u0442 OpenVPN \u0438 \u0434\u043e\u0431\u0430\u0432\u0438\u043c \u0432 \u043d\u0435\u0433\u043e \u0441\u043b\u0435\u0434\u0443\u044e\u0449\u0438\u0435 \u0444\u0430\u0439\u043b\u044b:<\/p>\n<ul>\n<li>\n<p><em>\/etc\/openvpn\/server\/server.conf<\/em> &#8212; \u0433\u043e\u0442\u043e\u0432\u044b\u0439 \u043a\u043e\u043d\u0444\u0438\u0433\u0443\u0440\u0430\u0446\u0438\u043e\u043d\u043d\u044b\u0439 \u0444\u0430\u0439\u043b \u0434\u043b\u044f OpenVPN-\u0441\u0435\u0440\u0432\u0435\u0440\u0430;<\/p>\n<\/li>\n<li>\n<p><em>\/etc\/openvpn\/clients_config<\/em> &#8212; \u0441\u0440\u0435\u0434\u0443 \u0434\u043b\u044f \u0441\u043e\u0437\u0434\u0430\u043d\u0438\u044f \u043a\u043b\u0438\u0435\u043d\u0442\u0441\u043a\u0438\u0445 \u043a\u043e\u043d\u0444\u0438\u0433\u0443\u0440\u0430\u0446\u0438\u043e\u043d\u043d\u044b\u0445 \u0444\u0430\u0439\u043b\u043e\u0432 \u0441\u043e \u0441\u043a\u0440\u0438\u043f\u0442\u043e\u043c \u00ab<em>make_config.sh<\/em>\u00bb \u0438 \u0444\u0430\u0439\u043b\u043e\u043c \u00ab<em>base.conf<\/em>\u00bb.<\/p>\n<\/li>\n<\/ul>\n<p>\u041f\u0440\u043e\u0446\u0435\u0441\u0441 \u043f\u0435\u0440\u0435\u0441\u0431\u043e\u0440\u043a\u0438 \u043f\u0430\u043a\u0435\u0442\u0430 OpenVPN \u043e\u043f\u0438\u0441\u0430\u043d \u0432 \u0441\u0442\u0430\u0442\u044c\u0435 \u00ab<a href=\"https:\/\/habr.com\/ru\/articles\/783076\/#rebuild\" rel=\"noopener noreferrer nofollow\"><strong>\u0420\u0430\u0431\u043e\u0442\u0430 \u0441 DEB-\u043f\u0430\u043a\u0435\u0442\u0430\u043c\u0438<\/strong><\/a><strong>\u00bb<\/strong>.<\/p>\n<p>\u041f\u043e\u0441\u043b\u0435 \u0441\u0431\u043e\u0440\u043a\u0438 \u043f\u0430\u043a\u0435\u0442\u0430, <a href=\"https:\/\/habr.com\/ru\/articles\/789056\/#repo_upload\" rel=\"noopener noreferrer nofollow\">\u0437\u0430\u0433\u0440\u0443\u0437\u0438\u043c<\/a> \u0435\u0433\u043e \u0432 \u043b\u043e\u043a\u0430\u043b\u044c\u043d\u044b\u0439 \u0440\u0435\u043f\u043e\u0437\u0438\u0442\u043e\u0440\u0438\u0439.<\/p>\n<h2>Bash-\u0441\u043a\u0440\u0438\u043f\u0442 \u0434\u043b\u044f OpenVPN-\u0441\u0435\u0440\u0432\u0435\u0440\u0430<\/h2>\n<p>\u041d\u0430\u0441\u0442\u0430\u043b\u043e \u0432\u0440\u0435\u043c\u044f \u043d\u0430\u043f\u0438\u0441\u0430\u0442\u044c bash-\u0441\u043a\u0440\u0438\u043f\u0442, \u043a\u043e\u0442\u043e\u0440\u044b\u0439 \u0441\u043c\u043e\u0436\u0435\u0442 \u0432\u044b\u043f\u043e\u043b\u043d\u0438\u0442\u044c \u043d\u0430\u0441\u0442\u0440\u043e\u0439\u043a\u0443 OpenVPN \u0430\u0432\u0442\u043e\u043c\u0430\u0442\u0438\u0447\u0435\u0441\u043a\u0438:<\/p>\n<details class=\"spoiler\">\n<summary>openvpn.sh<\/summary>\n<div class=\"spoiler__content\">\n<p><a href=\"https:\/\/github.com\/justnikobird\/young-devops-project\/blob\/main\/openvpn.sh\" rel=\"noopener noreferrer nofollow\"><strong>\u0412\u0435\u0440\u0441\u0438\u044f \u043d\u0430 GitHub<\/strong><\/a><\/p>\n<pre><code class=\"bash\">#!\/bin\/bash  # \u0430\u043a\u0442\u0438\u0432\u0438\u0440\u0443\u0435\u043c \u043e\u043f\u0446\u0438\u044e, \u043a\u043e\u0442\u043e\u0440\u0430\u044f \u043f\u0440\u0435\u0440\u044b\u0432\u0430\u0435\u0442 \u0432\u044b\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u0435 \u0441\u043a\u0440\u0438\u043f\u0442\u0430, \u0435\u0441\u043b\u0438 \u043b\u044e\u0431\u0430\u044f \u043a\u043e\u043c\u0430\u043d\u0434\u0430 \u0437\u0430\u0432\u0435\u0440\u0448\u0430\u0435\u0442\u0441\u044f \u0441 \u043d\u0435\u043d\u0443\u043b\u0435\u0432\u044b\u043c \u0441\u0442\u0430\u0442\u0443\u0441\u043e\u043c set -e  # \u043f\u0440\u043e\u0432\u0435\u0440\u0438\u043c, \u0437\u0430\u043f\u0443\u0449\u0435\u043d \u043b\u0438 \u0441\u043a\u0440\u0438\u043f\u0442 \u043e\u0442 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u044f root if [[ \"${UID}\" -ne 0 ]]; then   echo \"You need to run this script as root!\"   exit 1 fi  # \u043f\u0440\u043e\u0432\u0435\u0440\u0438\u043c \u043f\u043e\u0434\u043a\u043b\u044e\u0447\u0435\u043d \u043b\u0438 \u0440\u0435\u043f\u043e\u0437\u0438\u0442\u043e\u0440\u0438\u0439 if [[ ! $(grep -rhE ^deb \/etc\/apt\/sources.list*) == *\"deb https:\/\/repo.justnikobird.ru:1111\/lab focal main\"* ]]; then   echo -e \"Lab repo not connected!\\nPlease run vm_start.sh script!\\n\"   exit 1 fi  # \u0444\u0443\u043d\u043a\u0446\u0438\u044f, \u043a\u043e\u0442\u043e\u0440\u0430\u044f \u043f\u0440\u043e\u0432\u0435\u0440\u044f\u0435\u0442 \u043d\u0430\u043b\u0438\u0447\u0438\u0435 \u043f\u0430\u043a\u0435\u0442\u0430 \u0432 \u0441\u0438\u0441\u0442\u0435\u043c\u0435 \u0438 \u0432 \u0441\u043b\u0443\u0447\u0430\u0435 \u0435\u0433\u043e \u043e\u0442\u0441\u0443\u0442\u0441\u0442\u0432\u0438\u044f \u0432\u044b\u043f\u043e\u043b\u043d\u044f\u0435\u0442 \u0443\u0441\u0442\u0430\u043d\u043e\u0432\u043a\u0443 command_check() {   if ! command -v \"$1\" &amp;>\/dev\/null; then     echo -e \"\\n====================\\n$2 could not be found!\\nInstalling...\\n====================\\n\"     apt-get install -y \"$3\"     echo -e \"\\nDONE\\n\"   fi }  # \u0444\u0443\u043d\u043a\u0446\u0438\u044f, \u043a\u043e\u0442\u043e\u0440\u0430\u044f \u043f\u0440\u043e\u0432\u0435\u0440\u044f\u0435\u0442 \u043d\u0430\u043b\u0438\u0447\u0438\u0435 \u043f\u0440\u0430\u0432\u0438\u043b\u0430 \u0432 iptables \u0438 \u0432 \u0441\u043b\u0443\u0447\u0430\u0435 \u043e\u0442\u0441\u0443\u0442\u0441\u0442\u0432\u0438\u044f \u043f\u0440\u0438\u043c\u0435\u043d\u044f\u0435\u0442 \u0435\u0433\u043e iptables_add() {   if ! iptables -C \"$@\" &amp;>\/dev\/null; then     iptables -A \"$@\"   fi }  # \u0444\u0443\u043d\u043a\u0446\u0438\u044f, \u043a\u043e\u0442\u043e\u0440\u0430\u044f \u043f\u0440\u043e\u0432\u0435\u0440\u044f\u0435\u0442 \u043d\u0430\u043b\u0438\u0447\u0438\u0435 nat-\u043f\u0440\u0430\u0432\u0438\u043b\u0430 \u0432 iptables \u0438 \u0432 \u0441\u043b\u0443\u0447\u0430\u0435 \u043e\u0442\u0441\u0443\u0442\u0441\u0442\u0432\u0438\u044f \u043f\u0440\u0438\u043c\u0435\u043d\u044f\u0435\u0442 \u0435\u0433\u043e iptables_nat_add() {   if ! iptables -t nat -C \"$@\" &amp;>\/dev\/null; then     iptables -t nat -A \"$@\"   fi }  # \u0444\u0443\u043d\u043a\u0446\u0438\u044f, \u043a\u043e\u0442\u043e\u0440\u0430\u044f \u043f\u0440\u043e\u0432\u0435\u0440\u044f\u0435\u0442 \u0432\u0430\u043b\u0438\u0434\u043d\u043e\u0441\u0442\u044c \u043f\u0443\u0442\u0438 \u0432 linux-\u0441\u0438\u0441\u0442\u0435\u043c\u0435 path_request() {   while true; do     read -r -e -p $'\\n\\n'\"Please input valid path to ${1}: \" path     if [ -f \"$path\" ]; then       echo \"$path\"       break     fi   done }  # \u0432\u044b\u043f\u043e\u043b\u043d\u0438\u043c \u043d\u0430\u0441\u0442\u0440\u043e\u0439\u043a\u0435 OpenVPN echo -e \"\\n====================\\nOpenVPN server config\\n====================\"  while true; do   read -r -n 1 -p \"Continue or Skip? (c|s) \" cs   case $cs in   [Cc]*)      # \u0443\u0441\u0442\u0430\u043d\u043e\u0432\u0438\u043c \u0432\u0441\u0435 \u043d\u0435\u043e\u0431\u0445\u043e\u0434\u0438\u043c\u044b\u0435 \u043f\u0430\u043a\u0435\u0442\u044b \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u044f \u0444\u0443\u043d\u043a\u0446\u0438\u044e command_check     systemctl restart systemd-timesyncd.service     apt-get update     command_check openvpn \"Openvpn\" openvpn-lab     command_check iptables \"Iptables\" iptables     command_check netfilter-persistent \"Netfilter-persistent\" iptables-persistent     command_check basename \"Basename\" coreutils      # \u043f\u0440\u043e\u0432\u0435\u0440\u0438\u043c \u043d\u0430\u043b\u0438\u0447\u0438\u0435 \u0444\u0430\u0439\u043b\u0430 \/etc\/sysctl.conf \u0432 \u0441\u0438\u0441\u0442\u0435\u043c\u0435     if [ ! -f \/etc\/sysctl.conf ]; then       echo \"File \/etc\/sysctl.conf not found!\"       exit 1     fi      # \u0437\u0430\u043f\u0440\u043e\u0441\u0438\u043c \u043f\u0443\u0442\u044c \u0434\u043e \u0444\u0430\u0439\u043b\u0430 \u0441\u0435\u0440\u0442\u0438\u0444\u0438\u043a\u0430\u0442\u0430 \u0438 \u043f\u0435\u0440\u0435\u043d\u0435\u0441\u0435\u043c \u0435\u0433\u043e \u0432 \u0440\u0430\u0431\u043e\u0447\u0443\u044e \u0434\u0438\u0440\u0435\u043a\u0442\u043e\u0440\u0438\u044e \u043f\u0440\u043e\u0433\u0440\u0430\u043c\u043c\u044b     server_crt=$(path_request certificate)     cp \"$server_crt\" \/etc\/openvpn\/server\/     server_crt_file=$(basename \"$server_crt\")      # \u0437\u0430\u043f\u0440\u043e\u0441\u0438\u043c \u043f\u0443\u0442\u044c \u0434\u043e \u0444\u0430\u0439\u043b\u0430 \u043a\u043b\u044e\u0447\u0430 \u0438 \u043f\u0435\u0440\u0435\u043d\u0435\u0441\u0435\u043c \u0435\u0433\u043e \u0432 \u0440\u0430\u0431\u043e\u0447\u0443\u044e \u0434\u0438\u0440\u0435\u043a\u0442\u043e\u0440\u0438\u044e \u043f\u0440\u043e\u0433\u0440\u0430\u043c\u043c\u044b     server_key=$(path_request key)     cp \"$server_key\" \/etc\/openvpn\/server\/     server_key_file=$(basename \"$server_key\")      # \u0437\u0430\u043f\u0440\u043e\u0441\u0438\u043c \u043f\u0443\u0442\u044c \u0434\u043e \u0444\u0430\u0439\u043b\u0430 ca-\u0441\u0435\u0440\u0442\u0438\u0444\u0438\u043a\u0430\u0442\u0430 \u0438 \u043f\u0435\u0440\u0435\u043d\u0435\u0441\u0435\u043c \u0435\u0433\u043e \u0432 \u0440\u0430\u0431\u043e\u0447\u0443\u044e \u0434\u0438\u0440\u0435\u043a\u0442\u043e\u0440\u0438\u044e \u043f\u0440\u043e\u0433\u0440\u0430\u043c\u043c\u044b     ca_crt=$(path_request \"ca certificate\")     cp \"$ca_crt\" \/etc\/openvpn\/server\/     cp \"$ca_crt\" \/etc\/openvpn\/clients_config\/keys\/     ca_crt_file=$(basename \"$ca_crt\")      cd \/etc\/openvpn\/server\/      # \u0441\u0433\u0435\u043d\u0435\u0440\u0438\u0440\u0443\u0435\u043c \u043a\u043b\u044e\u0447 \u0434\u043b\u044f tls-crypt     openvpn --genkey --secret ta.key     cp \/etc\/openvpn\/server\/ta.key \/etc\/openvpn\/clients_config\/keys\/     echo -e \"\\n====================\\nTls-crypt-key generated \/etc\/openvpn\/server\/ta.key\\n====================\\n\"      # \u0432\u043d\u0435\u0441\u0435\u043c \u0438\u0437\u043c\u0435\u043d\u0435\u043d\u0438\u044f \u0432 \u043a\u043e\u043d\u0444\u0438\u0433\u0443\u0440\u0430\u0446\u0438\u043e\u043d\u043d\u044b\u0439 \u0444\u0430\u0439\u043b open-vpn     sed -r -i 's\/(^ca\\s).*$\/\\1'\"$ca_crt_file\"'\/' \/etc\/openvpn\/server\/server.conf     sed -r -i 's\/(^cert\\s).*$\/\\1'\"$server_crt_file\"'\/' \/etc\/openvpn\/server\/server.conf     sed -r -i 's\/(^key\\s).*$\/\\1'\"$server_key_file\"'\/' \/etc\/openvpn\/server\/server.conf      # \u0430\u043a\u0442\u0438\u0432\u0438\u0440\u0443\u0435\u043c \u0444\u0443\u043d\u043a\u0446\u0438\u044e \u043c\u0430\u0440\u0448\u0440\u0443\u0442\u0438\u0437\u0430\u0446\u0438\u0438     echo -e \"\\n====================\\nIp forward configing\\n====================\\n\"     sed -i 's\/#\\?\\(net.ipv4.ip_forward=1\\s*\\).*$\/\\1\/' \/etc\/sysctl.conf     sysctl -p     echo -e \"\\nDONE\\n\"      # c\u043e\u0437\u0434\u0430\u0434\u0438\u043c \u0433\u0440\u0443\u043f\u043f\u0443 nobody \u0434\u043b\u044f \u043a\u043e\u0440\u0440\u0435\u043a\u0442\u043d\u043e\u0439 \u0440\u0430\u0431\u043e\u0442\u044b vpn-\u0441\u0435\u0440\u0432\u0438\u0441\u0430     if ! grep -q \"nobody\" \/etc\/group; then       groupadd nobody       echo -e \"\\n====================\\nNobody group created\\n====================\\n\"     fi      # \u0432\u044b\u043f\u043e\u043b\u043d\u0438\u043c \u043d\u0430\u0441\u0442\u0440\u043e\u0439\u043a\u0443 openvpn     echo -e \"\\n====================\\nOpenVPN configuration\\n====================\\n\"      while true; do       # \u0432\u044b\u0432\u0435\u0434\u0435\u043c \u0437\u0430\u043f\u0440\u043e\u0441 \u0434\u043b\u044f \u0432\u044b\u0431\u043e\u0440\u0430 \u0442\u0440\u0430\u043d\u0441\u043f\u043e\u0440\u0442\u0430 \u0434\u043b\u044f vpn (udp \u0438\u043b\u0438 tcp)       read -r -n 3 -p $'\\n'\"OpenVPN protocol (tcp|udp) (default udp): \" proto       case $proto in       tcp)         # \u0432 \u0441\u043b\u0443\u0447\u0430\u0435 \u0432\u044b\u0431\u043e\u0440\u0430 tcp \u0432\u043d\u0435\u0441\u0435\u043c \u043d\u0430\u0441\u0442\u0440\u043e\u0439\u043a\u0438 \u0432 \u043a\u043e\u043d\u0444\u0438\u0433\u0443\u0440\u0430\u0446\u0438\u043e\u043d\u043d\u044b\u0435 \u0444\u0430\u0439\u043b\u044b openvpn         sed -r -i 's\/(^proto\\sudp$)\/\\;\\1\/' \/etc\/openvpn\/server\/server.conf         sed -r -i 's\/^\\;(proto\\stcp$)\/\\1\/' \/etc\/openvpn\/server\/server.conf         sed -r -i 's\/(^proto\\sudp$)\/\\;\\1\/' \/etc\/openvpn\/clients_config\/confiles\/base.conf         sed -r -i 's\/^\\;(proto\\stcp$)\/\\1\/' \/etc\/openvpn\/clients_config\/confiles\/base.conf         sed -r -i 's\/(^explicit-exit-notify\\s1$)\/\\;\\1\/' \/etc\/openvpn\/server\/server.conf         break         ;;       udp)         # \u0432 \u0441\u043b\u0443\u0447\u0430\u0435 \u0432\u044b\u0431\u043e\u0440\u0430 udp \u0432\u043d\u043e\u0441\u0438\u0442\u044c \u0438\u0437\u043c\u0435\u043d\u0435\u043d\u0438\u044f \u043d\u0435 \u043d\u0443\u0436\u043d\u043e, \u0442\u0430\u043a \u043a\u0430\u043a udp \u043d\u0430\u0441\u0442\u0440\u043e\u0435\u043d \u043f\u043e \u0443\u043c\u043e\u043b\u0447\u0430\u043d\u0438\u044e         break         ;;       *) echo -e \"\\nPlease answer tcp or udp!\\n\" ;;       esac     done      # \u0437\u0430\u043f\u0440\u043e\u0441\u0438\u043c \u0443 \u043e\u043f\u0435\u0440\u0430\u0442\u043e\u0440\u0430 \u0432\u0432\u0435\u0441\u0442\u0438 \u043f\u043e\u0440\u0442, \u0447\u0435\u0440\u0435\u0437 \u043a\u043e\u0442\u043e\u0440\u044b\u0439 \u0431\u0443\u0434\u0435\u0442 \u0440\u0430\u0431\u043e\u0442\u0430\u0442\u044c openvpn     while true; do       read -r -n 4 -p $'\\n\\n'\"OpenVPN port number (default 1194): \" port       re='^[0-9]+$'       if ! [[ $port =~ $re ]]; then         echo \"error: Not a number\" >&amp;2         exit 1       else         if [ \"$port\" == 1194 ]; then           break         else           # \u0432 \u0441\u043b\u0443\u0447\u0430\u0435 \u0435\u0441\u043b\u0438 \u043f\u043e\u0440\u0442 \u043e\u0442\u043b\u0438\u0447\u0430\u0435\u0442\u0441\u044f \u043e\u0442 1194, \u0432\u043d\u0435\u0441\u0435\u043c \u0438\u0437\u043c\u0435\u043d\u0435\u043d\u0438\u044f \u0432 \u043a\u043e\u043d\u0444\u0438\u0433\u0443\u0440\u0430\u0446\u0438\u043e\u043d\u043d\u044b\u0439 \u0444\u0430\u0439\u043b           sed -r -i 's\/(^port\\s).*$\/\\1'\"$port\"'\/' \/etc\/openvpn\/server\/server.conf           sed -r -i 's\/(^port\\s).*$\/\\1'\"$port\"'\/' \/etc\/openvpn\/clients_config\/confiles\/base.conf           break         fi       fi     done      echo -e \"\\n\"     ip a     echo -e \"\\n\"      # \u0437\u0430\u043f\u0440\u043e\u0441\u0438\u043c hostname \u0438\u043b\u0438 ip openvpn \u0441\u0435\u0440\u0432\u0435\u0440\u0430 \u0438 \u0437\u0430\u043d\u0435\u0441\u0435\u043c \u0432 \u043a\u043e\u043d\u0444\u0438\u0433\u0443\u0440\u0430\u0446\u0438\u043e\u043d\u043d\u044b\u0439 \u0444\u0430\u0439\u043b     read -r -p $'\\n'\"The hostname or IP of the server: \" host     sed -r -i 's\/(^remote\\s).*$\/\\1'\"$host\"' '\"$port\"'\/' \/etc\/openvpn\/clients_config\/confiles\/base.conf      echo -e \"\\n====================\\nIptables configuration\\n====================\\n\"      # \u0437\u0430\u043f\u0440\u043e\u0441\u0438\u043c \u0438\u043c\u044f vpn-\u0438\u043d\u0442\u0435\u0440\u0444\u0435\u0439\u0441\u0430 \u0434\u043b\u044f \u043d\u0430\u0441\u0442\u0440\u043e\u0439\u043a\u0438 iptables     while true; do       read -r -p $'\\n'\"VPN interface name: \" eth       if ! ip a | grep -q \"$eth\"; then         echo -e \"\\nWrong interface name!\\n\"       else         break       fi     done      # \u0432\u044b\u043f\u043e\u043b\u043d\u0438\u043c \u043d\u0430\u0441\u0442\u0440\u043e\u0439\u043a\u0443 iptables     # OpenVPN     iptables_add INPUT -i \"$eth\" -m state --state NEW -p \"$proto\" --dport \"$port\" -j ACCEPT -m comment --comment openvpn     # Allow TUN interfaces connections to OpenVPN server     iptables_add INPUT -i tun+ -j ACCEPT -m comment --comment openvpn     # Allow TUN interfaces connections to be forwarded through interfaces     iptables_add FORWARD -i tun+ -j ACCEPT -m comment --comment openvpn     iptables_add FORWARD -i tun+ -o \"$eth\" -m state --state RELATED,ESTABLISHED -j ACCEPT -m comment --comment openvpn     iptables_add FORWARD -i \"$eth\" -o tun+ -m state --state RELATED,ESTABLISHED -j ACCEPT -m comment --comment openvpn     # NAT the VPN client traffic to the interface     iptables_nat_add POSTROUTING -s 10.8.0.0\/24 -o \"$eth\" -j MASQUERADE -m comment --comment openvpn     echo -e \"\\n====================\\nSaving iptables config\\n====================\\n\"     service netfilter-persistent save     echo -e \"\\nDONE\\n\"      # \u043f\u0435\u0440\u0435\u0437\u0430\u0433\u0440\u0443\u0437\u0438\u043c \u0441\u0435\u0440\u0432\u0438\u0441 openvpn     echo -e \"\\n====================\\nRestarting Open-VPN service...\\n====================\\n\"     systemctl restart openvpn-server@server.service     systemctl enable openvpn-server@server.service     echo -e \"\\nDONE\\n\"     break     ;;   [Ss]*)     echo -e \"\\n\"     break     ;;   *) echo -e \"\\nPlease answer C or S!\\n\" ;;   esac done  # \u0432\u044b\u043f\u043e\u043b\u043d\u0438\u043c \u043d\u0430\u0441\u0442\u0440\u043e\u0439\u043a\u0443 \u043a\u043b\u0438\u0435\u043d\u0442\u0441\u043a\u043e\u0433\u043e \u043a\u043e\u043d\u0444\u0438\u0433\u0443\u0440\u0430\u0446\u0438\u043e\u043d\u043d\u043e\u0433\u043e \u0444\u0430\u0439\u043b\u0430 echo -e \"\\n====================\\nCreate OpenVPN client config-file\\n====================\"  while true; do   read -r -n 1 -p \"Continue or Skip? (c|s) \" cs   case $cs in   [Cc]*)     # \u0437\u0430\u043f\u0440\u043e\u0441\u0438\u043c \u043a\u043b\u0438\u0435\u043d\u0442\u0441\u043a\u0438\u0439 \u0441\u0435\u0440\u0442\u0438\u0444\u0438\u043a\u0430\u0442 \u0438 \u043f\u0435\u0440\u0435\u043d\u0435\u0441\u0435\u043c \u0432 \u0440\u0430\u0431\u043e\u0447\u0443\u044e \u0434\u0438\u0440\u0435\u043a\u0442\u043e\u0440\u0438\u044e \u043f\u0440\u043e\u0433\u0440\u0430\u043c\u043c\u044b     client_crt=$(path_request \"client certificate\")     cp \"$client_crt\" \/etc\/openvpn\/clients_config\/keys\/     client_crt_file=$(basename \"$client_crt\")      # \u0437\u0430\u043f\u0440\u043e\u0441\u0438\u043c \u043a\u043b\u0438\u0435\u043d\u0442\u0441\u043a\u0438\u0439 \u043a\u043b\u044e\u0447 \u0438 \u043f\u0435\u0440\u0435\u043d\u0435\u0441\u0435\u043c \u0432 \u0440\u0430\u0431\u043e\u0447\u0443\u044e \u0434\u0438\u0440\u0435\u043a\u0442\u043e\u0440\u0438\u044e \u043f\u0440\u043e\u0433\u0440\u0430\u043c\u043c\u044b     client_key=$(path_request \"client key\")     cp \"$client_key\" \/etc\/openvpn\/clients_config\/keys\/     client_key_file=$(basename \"$client_key\")      # \u0437\u0430\u043f\u0443\u0441\u0442\u0438\u043c \u0441\u043a\u0440\u0438\u043f\u0442 \u0434\u043b\u044f \u0433\u0435\u043d\u0435\u0440\u0430\u0446\u0438\u0438 \u043a\u043b\u0438\u0435\u043d\u0442\u0441\u043a\u043e\u0433\u043e \u043a\u043e\u043d\u0444\u0438\u0433\u0443\u0440\u0430\u0446\u0438\u043e\u043d\u043d\u043e\u0433\u043e \u0444\u0430\u0439\u043b\u0430     read -r -p $'\\n'\"Client name: \" client_name     if \/etc\/openvpn\/clients_config\/make_config.sh \"$client_crt_file\" \"$client_key_file\" \"$client_name\"; then       echo -e \"\\nDONE!\\n\\nCheck file \/etc\/openvpn\/clients_config\/${client_name}.ovpn\"     fi     break     ;;    [Ss]*)     echo -e \"\\n\"     break     ;;   *) echo -e \"\\nPlease answer C or S!\\n\" ;;   esac done  echo -e \"\\nOK\\n\" exit 0<\/code><\/pre>\n<\/p>\n<\/div>\n<\/details>\n<p>\u0422\u0430\u043a\u0436\u0435 \u0435\u0441\u043b\u0438 \u0432\u0430\u043c \u0438\u043d\u0442\u0435\u0440\u0435\u0441\u043d\u0430 \u0440\u0430\u0431\u043e\u0442\u0430 \u0441 \u0433\u0435\u043d\u0435\u0440\u0430\u0442\u043e\u0440\u0430\u043c\u0438 \u0442\u0440\u0430\u0444\u0438\u043a\u0430, \u0442\u043e \u043f\u0440\u0435\u0434\u043b\u0430\u0433\u0430\u044e \u043e\u0437\u043d\u0430\u043a\u043e\u043c\u0438\u0442\u044c\u0441\u044f \u0441 \u043c\u043e\u0435\u0439 \u0441\u0442\u0430\u0442\u044c\u0435\u0439 \u00ab<a href=\"https:\/\/habr.com\/ru\/articles\/781132\/\" rel=\"noopener noreferrer nofollow\"><strong>Cisco TRex \u043d\u0430 \u043f\u0440\u0430\u043a\u0442\u0438\u043a\u0435<\/strong><\/a>\u00bb. <\/p>\n<\/p>\n<\/div>\n<\/div>\n<\/div>\n<p><!----><!----><\/div>\n<p><!----><!----><br \/> \u0441\u0441\u044b\u043b\u043a\u0430 \u043d\u0430 \u043e\u0440\u0438\u0433\u0438\u043d\u0430\u043b \u0441\u0442\u0430\u0442\u044c\u0438 <a href=\"https:\/\/habr.com\/ru\/articles\/783304\/\"> https:\/\/habr.com\/ru\/articles\/783304\/<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<div><!--[--><!--]--><\/div>\n<div id=\"post-content-body\">\n<div>\n<div class=\"article-formatted-body article-formatted-body article-formatted-body_version-2\">\n<div xmlns=\"http:\/\/www.w3.org\/1999\/xhtml\">\n<figure class=\"full-width\"><\/figure>\n<p>\u0412 \u0434\u0430\u043d\u043d\u043e\u0439 \u0441\u0435\u0440\u0438\u0438 \u0441\u0442\u0430\u0442\u0435\u0439 \u043e\u043f\u0438\u0441\u0430\u043d \u043f\u0440\u043e\u0446\u0435\u0441\u0441 \u0441\u043e\u0437\u0434\u0430\u043d\u0438\u044f \u043f\u0435\u0440\u0432\u043e\u0433\u043e pet-\u043f\u0440\u043e\u0435\u043a\u0442\u0430 \u0434\u043b\u044f \u043d\u0430\u0447\u0438\u043d\u0430\u044e\u0449\u0435\u0433\u043e \u0438\u043d\u0436\u0435\u043d\u0435\u0440\u0430 \u0432 DevOps:<\/p>\n<p><a href=\"https:\/\/habr.com\/ru\/articles\/781746\/\" rel=\"noopener noreferrer nofollow\"><strong>\u0413\u043b\u0430\u0432\u0430 1: \u0412\u0432\u0435\u0434\u0435\u043d\u0438\u0435 \u0438 \u043f\u043e\u0434\u0433\u043e\u0442\u043e\u0432\u043a\u0430 \u0441\u0442\u0435\u043d\u0434\u0430<\/strong><\/a><\/p>\n<p><a href=\"https:\/\/habr.com\/ru\/articles\/789056\/\" rel=\"noopener noreferrer nofollow\"><strong>\u0413\u043b\u0430\u0432\u0430 2: \u041d\u0430\u0441\u0442\u0440\u043e\u0439\u043a\u0430 \u0446\u0435\u043d\u0442\u0440\u0430 \u0441\u0435\u0440\u0442\u0438\u0444\u0438\u043a\u0430\u0446\u0438\u0438 \u0438 \u0440\u0435\u043f\u043e\u0437\u0438\u0442\u043e\u0440\u0438\u044f<\/strong><\/a><\/p>\n<p><a href=\"https:\/\/habr.com\/ru\/articles\/783304\/\" rel=\"noopener noreferrer nofollow\"><strong>\u0413\u043b\u0430\u0432\u0430 3: \u041d\u0430\u0441\u0442\u0440\u043e\u0439\u043a\u0430 OpenVPN<\/strong><\/a><\/p>\n<p><a href=\"https:\/\/habr.com\/ru\/articles\/783572\/\" rel=\"noopener noreferrer nofollow\"><strong>\u0413\u043b\u0430\u0432\u0430 4: \u041d\u0430\u0441\u0442\u0440\u043e\u0439\u043a\u0430 \u043c\u043e\u043d\u0438\u0442\u043e\u0440\u0438\u043d\u0433\u0430<\/strong><\/a><\/p>\n<blockquote>\n<p>\u0414\u0440\u0443\u0437\u044c\u044f, \u0445\u043e\u0447\u0443 \u043e\u0442\u0432\u0435\u0442\u0438\u0442\u044c \u043d\u0430 \u043a\u043e\u043c\u043c\u0435\u043d\u0442\u0430\u0440\u0438\u0438 \u043e\u0431 \u043e\u0442\u0441\u0443\u0442\u0441\u0442\u0432\u0438\u0438 \u0432 \u0434\u0430\u043d\u043d\u043e\u0439 \u0441\u0435\u0440\u0438\u0438 \u0441\u0442\u0430\u0442\u0435\u0439 \u0438\u043d\u0441\u0442\u0440\u0443\u043c\u0435\u043d\u0442\u043e\u0432 DevOps &#8212; Terraform, Ansible, Kubernetes, GitLab CI\/CD \u0438 \u043f\u0440\u043e\u0447\u0438\u0445 \u0438\u043d\u0441\u0442\u0440\u0443\u043c\u0435\u043d\u0442\u043e\u0432. \u041f\u043e\u043b\u043d\u043e\u0441\u0442\u044c\u044e \u0441\u043e\u0433\u043b\u0430\u0441\u0435\u043d \u0441 \u0442\u0435\u043c, \u0447\u0442\u043e DevOps \u0431\u0435\u0437 \u0432\u044b\u0448\u0435\u0443\u043f\u043e\u043c\u044f\u043d\u0443\u0442\u044b\u0445 \u0438\u043d\u0441\u0442\u0440\u0443\u043c\u0435\u043d\u0442\u043e\u0432 \u0441\u0443\u0449\u0435\u0441\u0442\u0432\u043e\u0432\u0430\u0442\u044c \u043d\u0435 \u043c\u043e\u0436\u0435\u0442.<\/p>\n<p>\u0414\u0430\u043d\u043d\u0430\u044f \u0441\u0435\u0440\u0438\u044f \u0441\u0442\u0430\u0442\u0435\u0439 \u044f\u0432\u043b\u044f\u0435\u0442\u0441\u044f \u043e\u0442\u043f\u0440\u0430\u0432\u043d\u043e\u0439 \u0442\u043e\u0447\u043a\u043e\u0439 \u0432 \u0438\u0437\u0443\u0447\u0435\u043d\u0438\u0438 DevOps \u0438 \u0443\u0432\u0435\u0440\u0435\u043d, \u0447\u0442\u043e \u0438\u043c\u0435\u043d\u043d\u043e \u043d\u0430\u0447\u0438\u043d\u0430\u044e\u0449\u0438\u043c \u0438\u043d\u0436\u0435\u043d\u0435\u0440\u0430\u043c \u0434\u0430\u043d\u043d\u044b\u0439 \u043c\u0430\u0442\u0435\u0440\u0438\u0430\u043b \u0442\u043e\u0447\u043d\u043e \u0431\u0443\u0434\u0435\u0442 \u043f\u043e\u043b\u0435\u0437\u0435\u043d. \u0417\u0434\u0435\u0441\u044c \u0431\u043e\u043b\u044c\u0448\u043e\u0439 \u0430\u043a\u0446\u0435\u043d\u0442 \u0441\u0434\u0435\u043b\u0430\u043d \u043d\u0430 \u043d\u0430\u043f\u0438\u0441\u0430\u043d\u0438\u0438 \u0441\u043a\u0440\u0438\u043f\u0442\u043e\u0432. \u0426\u0435\u043b\u044c \u0434\u0430\u043d\u043d\u043e\u0433\u043e pet-\u043f\u0440\u043e\u0435\u043a\u0442\u0430 &#8212; \u043f\u0440\u0430\u043a\u0442\u0438\u0447\u0435\u0441\u043a\u043e\u0435 \u043e\u0437\u043d\u0430\u043a\u043e\u043c\u043b\u0435\u043d\u0438\u0435 \u0441 Linux \u043f\u0435\u0440\u0435\u0434 \u0442\u0435\u043c \u043a\u0430\u043a \u0434\u0432\u0438\u0433\u0430\u0442\u044c\u0441\u044f \u0434\u0430\u043b\u044c\u0448\u0435 \u0432 DevOps &#8212; \u0438\u043c\u0435\u043d\u043d\u043e \u043f\u043e\u044d\u0442\u043e\u043c\u0443 \u043d\u0430\u0437\u0432\u0430\u043d\u0438\u0435 \u00ab\u041f\u0440\u043e\u0435\u043a\u0442\u00a0<strong>\u044e\u043d\u043e\u0433\u043e<\/strong>\u00a0DevOps\u00bb. \u0412 \u043f\u043b\u0430\u043d\u0430\u0445 \u043d\u0430\u043f\u0438\u0441\u0430\u043d\u0438\u0435 \u0441\u043b\u0435\u0434\u0443\u044e\u0449\u0435\u0439 \u0441\u0435\u0440\u0438\u0438 \u0441\u0442\u0430\u0442\u0435\u0439 \u0443\u0436\u0435 \u0441 \u0443\u0433\u043b\u0443\u0431\u043b\u0435\u043d\u0438\u0435\u043c \u0432 DevOps \u0438 \u0435\u0433\u043e \u0438\u043d\u0441\u0442\u0440\u0443\u043c\u0435\u043d\u0442\u044b.<\/p>\n<p>\u0421\u043f\u0430\u0441\u0438\u0431\u043e \u0437\u0430 \u043a\u043e\u043d\u0441\u0442\u0440\u0443\u043a\u0442\u0438\u0432\u043d\u044b\u0435 \u043a\u043e\u043c\u043c\u0435\u043d\u0442\u0430\u0440\u0438\u0438, \u043a\u043e\u0442\u043e\u0440\u044b\u0435 \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0442 \u043e\u0442\u043a\u043e\u0440\u0440\u0435\u043a\u0442\u0438\u0440\u043e\u0432\u0430\u0442\u044c \u043c\u0430\u0442\u0435\u0440\u0438\u0430\u043b \u0438 \u0443\u043b\u0443\u0447\u0448\u0438\u0442\u044c \u0435\u0433\u043e \u043a\u0430\u0447\u0435\u0441\u0442\u0432\u043e. \u041f\u0440\u043e\u0448\u0443 \u043f\u043e\u0434\u0434\u0435\u0440\u0436\u0430\u0442\u044c \u043c\u043e\u0435 \u043d\u0430\u0447\u0438\u043d\u0430\u043d\u0438\u0435, \u0432\u0441\u0435\u043c \u0445\u043e\u0440\u043e\u0448\u0435\u0433\u043e \u0434\u043d\u044f!<\/p>\n<\/blockquote>\n<h3>\u041d\u0430\u0441\u0442\u0440\u043e\u0439\u043a\u0430 OpenVPN<\/h3>\n<p>\u0417\u0430\u0439\u0434\u0435\u043c \u043d\u0430 vm \u00abvpn\u00bb, \u043f\u0440\u0438\u043c\u0435\u043d\u0438\u043c bash-\u0441\u043a\u0440\u0438\u043f\u0442 \u00abvm-start.sh\u00bb \u0438 \u043f\u0440\u0438\u0441\u0442\u0443\u043f\u0438\u043c \u043a \u043d\u0430\u0441\u0442\u0440\u043e\u0439\u043a\u0435 OpenVPN:  <\/p>\n<p>\u0423\u0441\u0442\u0430\u043d\u043e\u0432\u0438\u043c Open-VPN \u0432\u0435\u0440\u0441\u0438\u0438 2.5.5:<\/p>\n<pre><code class=\"bash\">sudo apt-get install -y openvpn=2.5.5-1ubuntu3<\/code><\/pre>\n<details class=\"spoiler\">\n<summary>\u0417\u0430\u043c\u0435\u0442\u043a\u0430<\/summary>\n<div class=\"spoiler__content\">\n<p>\u0412 \u0434\u0440\u0443\u0433\u0438\u0445 \u0432\u0435\u0440\u0441\u0438\u044f\u0445 OpenVPN \u043f\u0440\u043e\u0446\u0435\u0441\u0441 \u0438 \u043e\u0441\u043e\u0431\u0435\u043d\u043d\u043e\u0441\u0442\u0438 \u043d\u0430\u0441\u0442\u0440\u043e\u0439\u043a\u0438 \u043c\u043e\u0433\u0443\u0442 \u043e\u0442\u043b\u0438\u0447\u0430\u0442\u044c\u0441\u044f \u043e\u0442 \u043e\u043f\u0438\u0441\u0430\u043d\u043d\u044b\u0445 \u0432 \u0434\u0430\u043d\u043d\u043e\u0439 \u0441\u0442\u0430\u0442\u044c\u0435.<\/p>\n<\/div>\n<\/details>\n<p>OpenVPN \u043f\u043e\u0434\u0434\u0435\u0440\u0436\u0438\u0432\u0430\u0435\u0442 \u0434\u0432\u0443\u043d\u0430\u043f\u0440\u0430\u0432\u043b\u0435\u043d\u043d\u0443\u044e \u0430\u0443\u0442\u0435\u043d\u0442\u0438\u0444\u0438\u043a\u0430\u0446\u0438\u044e \u043d\u0430 \u043e\u0441\u043d\u043e\u0432\u0435 \u0441\u0435\u0440\u0442\u0438\u0444\u0438\u043a\u0430\u0442\u043e\u0432, \u0447\u0442\u043e \u043e\u0437\u043d\u0430\u0447\u0430\u0435\u0442, \u0447\u0442\u043e \u043a\u043b\u0438\u0435\u043d\u0442 \u0434\u043e\u043b\u0436\u0435\u043d \u043f\u0440\u043e\u0432\u0435\u0440\u0438\u0442\u044c \u0441\u0435\u0440\u0442\u0438\u0444\u0438\u043a\u0430\u0442 \u0441\u0435\u0440\u0432\u0435\u0440\u0430, \u0430 \u0441\u0435\u0440\u0432\u0435\u0440 &#8212; \u0441\u0435\u0440\u0442\u0438\u0444\u0438\u043a\u0430\u0442 \u043a\u043b\u0438\u0435\u043d\u0442\u0430, \u043f\u0440\u0435\u0436\u0434\u0435 \u0447\u0435\u043c \u0431\u0443\u0434\u0435\u0442 \u0443\u0441\u0442\u0430\u043d\u043e\u0432\u043b\u0435\u043d\u043e \u0432\u0437\u0430\u0438\u043c\u043d\u043e\u0435 \u0434\u043e\u0432\u0435\u0440\u0438\u0435.<\/p>\n<p>\u0418 \u0441\u0435\u0440\u0432\u0435\u0440, \u0438 \u043a\u043b\u0438\u0435\u043d\u0442 \u0430\u0443\u0442\u0435\u043d\u0442\u0438\u0444\u0438\u0446\u0438\u0440\u0443\u044e\u0442 \u0434\u0440\u0443\u0433 \u0434\u0440\u0443\u0433\u0430, \u0441\u043d\u0430\u0447\u0430\u043b\u0430 \u043f\u0440\u043e\u0432\u0435\u0440\u044f\u044f, \u0447\u0442\u043e \u043f\u0440\u0435\u0434\u0441\u0442\u0430\u0432\u043b\u0435\u043d\u043d\u044b\u0439 \u0441\u0435\u0440\u0442\u0438\u0444\u0438\u043a\u0430\u0442 \u0431\u044b\u043b \u043f\u043e\u0434\u043f\u0438\u0441\u0430\u043d \u0433\u043b\u0430\u0432\u043d\u044b\u043c \u0446\u0435\u043d\u0442\u0440\u043e\u043c \u0441\u0435\u0440\u0442\u0438\u0444\u0438\u043a\u0430\u0446\u0438\u0438 (CA), \u0430 \u0437\u0430\u0442\u0435\u043c \u043f\u0440\u043e\u0432\u0435\u0440\u044f\u044f \u0438\u043d\u0444\u043e\u0440\u043c\u0430\u0446\u0438\u044e \u0432 \u0437\u0430\u0433\u043e\u043b\u043e\u0432\u043a\u0435 \u0441\u0435\u0440\u0442\u0438\u0444\u0438\u043a\u0430\u0442\u0430, \u043a\u043e\u0442\u043e\u0440\u044b\u0439 \u0442\u0435\u043f\u0435\u0440\u044c \u0430\u0443\u0442\u0435\u043d\u0442\u0438\u0444\u0438\u0446\u0438\u0440\u043e\u0432\u0430\u043d, \u043d\u0430\u043f\u0440\u0438\u043c\u0435\u0440 \u043e\u0431\u0449\u0435\u0435 \u0438\u043c\u044f \u0441\u0435\u0440\u0442\u0438\u0444\u0438\u043a\u0430\u0442\u0430 \u0438\u043b\u0438 \u0442\u0438\u043f \u0441\u0435\u0440\u0442\u0438\u0444\u0438\u043a\u0430\u0442\u0430 (\u043a\u043b\u0438\u0435\u043d\u0442 \u0438\u043b\u0438 \u0441\u0435\u0440\u0432\u0435\u0440).<\/p>\n<p>\u041f\u0435\u0440\u0435\u043d\u0435\u0441\u0435\u043c\u00a0<a href=\"https:\/\/habr.com\/ru\/articles\/789056\/#issue\" rel=\"noopener noreferrer nofollow\">\u043f\u043e\u0434\u043f\u0438\u0441\u0430\u043d\u043d\u044b\u0435<\/a>\u00a0\u043d\u0430 CA \u043a\u043b\u044e\u0447\u0438 \u0434\u043b\u044f vm \u00abvpn\u00bb \u0432 \u0440\u0430\u0431\u043e\u0447\u0443\u044e \u0434\u0438\u0440\u0435\u043a\u0442\u043e\u0440\u0438\u044e OpenVPN \u0438 \u043f\u0435\u0440\u0435\u0438\u043c\u0435\u043d\u0443\u0435\u043c:<\/p>\n<pre><code class=\"bash\">sudo cp ~\/vpn.justnikobird.ru.crt \/etc\/openvpn\/server\/server.crt sudo cp ~\/vpn.justnikobird.ru.key \/etc\/openvpn\/server\/server.key<\/code><\/pre>\n<p>\u041f\u0435\u0440\u0435\u043d\u0435\u0441\u0435\u043c\u00a0\u0441\u0435\u0440\u0442\u0438\u0444\u0438\u043a\u0430\u0442 \u043e\u0442\u043a\u0440\u044b\u0442\u043e\u0433\u043e \u043a\u043b\u044e\u0447\u0430 CA \u0432 \u0440\u0430\u0431\u043e\u0447\u0443\u044e \u0434\u0438\u0440\u0435\u043a\u0442\u043e\u0440\u0438\u044e OpenVPN:<\/p>\n<pre><code class=\"bash\">sudo cp ~\/ca.crt \/etc\/openvpn\/server\/<\/code><\/pre>\n<p>\u0421\u043a\u043e\u043f\u0438\u0440\u0443\u0435\u043c \u0448\u0430\u0431\u043b\u043e\u043d \u043a\u043e\u043d\u0444\u0438\u0433\u0443\u0440\u0430\u0446\u0438\u043e\u043d\u043d\u043e\u0433\u043e \u0444\u0430\u0439\u043b\u0430 \u0432 \u0440\u0430\u0431\u043e\u0447\u0443\u044e \u0434\u0438\u0440\u0435\u043a\u0442\u043e\u0440\u0438\u044e \u043f\u0440\u043e\u0433\u0440\u0430\u043c\u043c\u044b:<\/p>\n<pre><code class=\"bash\">sudo sudo cp \/usr\/share\/doc\/openvpn\/examples\/sample-config-files\/server.conf \/etc\/openvpn\/server\/ <\/code><\/pre>\n<p>\u0412\u044b\u043f\u043e\u043b\u043d\u0438\u043c \u043d\u0430\u0441\u0442\u0440\u043e\u0439\u043a\u0443 OpenVPN \u0432 \u043a\u043e\u043d\u0444\u0438\u0433\u0443\u0440\u0430\u0446\u0438\u043e\u043d\u043d\u043e\u043c \u0444\u0430\u0439\u043b\u0435 \u00ab<em>\/etc\/openvpn\/server\/server.conf<\/em>\u00bb, \u0438\u0437\u043c\u0435\u043d\u0438\u0432 \u0441\u043b\u0435\u0434\u0443\u044e\u0449\u0438\u0435 \u0441\u0442\u0440\u043e\u043a\u0438:<\/p>\n<pre><code class=\"bash\"># Diffie hellman parameters. # Generate your own with: #   openssl dhparam -out dh2048.pem 2048 ;dh dh2048.pem dh none  # If enabled, this directive will configure # all clients to redirect their default # network gateway through the VPN, causing # all IP traffic such as web browsing and # and DNS lookups to go through the VPN # (The OpenVPN server machine may need to NAT # or bridge the TUN\/TAP interface to the internet # in order for this to work properly). push \"redirect-gateway def1 bypass-dhcp\"  # Certain Windows-specific network settings # can be pushed to clients, such as DNS # or WINS server addresses.  CAVEAT: # http:\/\/openvpn.net\/faq.html#dhcpcaveats # The addresses below refer to the public # DNS servers provided by opendns.com. push \"dhcp-option DNS 208.67.222.222\" push \"dhcp-option DNS 208.67.220.220\"  # For extra security beyond that provided # by SSL\/TLS, create an \"HMAC firewall\" # to help block DoS attacks and UDP port flooding. # # Generate with: #   openvpn --genkey tls-auth ta.key # # The server and each client must have # a copy of this key. # The second parameter should be '0' # on the server and '1' on the clients. tls-crypt ta.key # This file is secret  # Select a cryptographic cipher. # This config item must be copied to # the client config file as well. # Note that v2.4 client\/server will automatically # negotiate AES-256-GCM in TLS mode. # See also the ncp-cipher option in the manpage cipher AES-256-GCM auth SHA256  # It's a good idea to reduce the OpenVPN # daemon's privileges after initialization. # # You can uncomment this out on # non-Windows systems. user nobody group nobody<\/code><\/pre>\n<details class=\"spoiler\">\n<summary>\u041a\u043e\u043d\u0444\u0438\u0433\u0443\u0440\u0430\u0446\u0438\u043e\u043d\u043d\u044b\u0439 \u0444\u0430\u0439\u043b OpenVPN \u0446\u0435\u043b\u0438\u043a\u043e\u043c<\/summary>\n<div class=\"spoiler__content\">\n<pre><code class=\"bash\">################################################# # Sample OpenVPN 2.0 config file for            # # multi-client server.                          # #                                               # # This file is for the server side              # # of a many-clients &lt;-> one-server              # # OpenVPN configuration.                        # #                                               # # OpenVPN also supports                         # # single-machine &lt;-> single-machine             # # configurations (See the Examples page         # # on the web site for more info).               # #                                               # # This config should work on Windows            # # or Linux\/BSD systems.  Remember on            # # Windows to quote pathnames and use            # # double backslashes, e.g.:                     # # \"C:\\\\Program Files\\\\OpenVPN\\\\config\\\\foo.key\" # #                                               # # Comments are preceded with '#' or ';'         # #################################################  # Which local IP address should OpenVPN # listen on? (optional) ;local a.b.c.d  # Which TCP\/UDP port should OpenVPN listen on? # If you want to run multiple OpenVPN instances # on the same machine, use a different port # number for each one.  You will need to # open up this port on your firewall. port 1194  # TCP or UDP server? ;proto tcp proto udp  # \"dev tun\" will create a routed IP tunnel, # \"dev tap\" will create an ethernet tunnel. # Use \"dev tap0\" if you are ethernet bridging # and have precreated a tap0 virtual interface # and bridged it with your ethernet interface. # If you want to control access policies # over the VPN, you must create firewall # rules for the the TUN\/TAP interface. # On non-Windows systems, you can give # an explicit unit number, such as tun0. # On Windows, use \"dev-node\" for this. # On most systems, the VPN will not function # unless you partially or fully disable # the firewall for the TUN\/TAP interface. ;dev tap dev tun  # Windows needs the TAP-Win32 adapter name # from the Network Connections panel if you # have more than one.  On XP SP2 or higher, # you may need to selectively disable the # Windows firewall for the TAP adapter. # Non-Windows systems usually don't need this. ;dev-node MyTap  # SSL\/TLS root certificate (ca), certificate # (cert), and private key (key).  Each client # and the server must have their own cert and # key file.  The server and all clients will # use the same ca file. # # See the \"easy-rsa\" directory for a series # of scripts for generating RSA certificates # and private keys.  Remember to use # a unique Common Name for the server # and each of the client certificates. # # Any X509 key management system can be used. # OpenVPN can also use a PKCS #12 formatted key file # (see \"pkcs12\" directive in man page). ca ca.crt cert server.crt key server.key  # This file should be kept secret  # Diffie hellman parameters. # Generate your own with: #   openssl dhparam -out dh2048.pem 2048 ;dh dh2048.pem dh none  # Network topology # Should be subnet (addressing via IP) # unless Windows clients v2.0.9 and lower have to # be supported (then net30, i.e. a \/30 per client) # Defaults to net30 (not recommended) ;topology subnet  # Configure server mode and supply a VPN subnet # for OpenVPN to draw client addresses from. # The server will take 10.8.0.1 for itself, # the rest will be made available to clients. # Each client will be able to reach the server # on 10.8.0.1. Comment this line out if you are # ethernet bridging. See the man page for more info. server 10.8.0.0 255.255.255.0  # Maintain a record of client &lt;-> virtual IP address # associations in this file.  If OpenVPN goes down or # is restarted, reconnecting clients can be assigned # the same virtual IP address from the pool that was # previously assigned. ifconfig-pool-persist \/var\/log\/openvpn\/ipp.txt  # Configure server mode for ethernet bridging. # You must first use your OS's bridging capability # to bridge the TAP interface with the ethernet # NIC interface.  Then you must manually set the # IP\/netmask on the bridge interface, here we # assume 10.8.0.4\/255.255.255.0.  Finally we # must set aside an IP range in this subnet # (start=10.8.0.50 end=10.8.0.100) to allocate # to connecting clients.  Leave this line commented # out unless you are ethernet bridging. ;server-bridge 10.8.0.4 255.255.255.0 10.8.0.50 10.8.0.100  # Configure server mode for ethernet bridging # using a DHCP-proxy, where clients talk # to the OpenVPN server-side DHCP server # to receive their IP address allocation # and DNS server addresses.  You must first use # your OS's bridging capability to bridge the TAP # interface with the ethernet NIC interface. # Note: this mode only works on clients (such as # Windows), where the client-side TAP adapter is # bound to a DHCP client. ;server-bridge  # Push routes to the client to allow it # to reach other private subnets behind # the server.  Remember that these # private subnets will also need # to know to route the OpenVPN client # address pool (10.8.0.0\/255.255.255.0) # back to the OpenVPN server. ;push \"route 192.168.10.0 255.255.255.0\" ;push \"route 192.168.20.0 255.255.255.0\"  # To assign specific IP addresses to specific # clients or if a connecting client has a private # subnet behind it that should also have VPN access, # use the subdirectory \"ccd\" for client-specific # configuration files (see man page for more info).  # EXAMPLE: Suppose the client # having the certificate common name \"Thelonious\" # also has a small subnet behind his connecting # machine, such as 192.168.40.128\/255.255.255.248. # First, uncomment out these lines: ;client-config-dir ccd ;route 192.168.40.128 255.255.255.248 # Then create a file ccd\/Thelonious with this line: #<\/code><\/pre>\n<\/div>\n<\/details>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[],"tags":[],"class_list":["post-364052","post","type-post","status-publish","format-standard","hentry"],"_links":{"self":[{"href":"https:\/\/savepearlharbor.com\/index.php?rest_route=\/wp\/v2\/posts\/364052","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/savepearlharbor.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/savepearlharbor.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/savepearlharbor.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/savepearlharbor.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=364052"}],"version-history":[{"count":0,"href":"https:\/\/savepearlharbor.com\/index.php?rest_route=\/wp\/v2\/posts\/364052\/revisions"}],"wp:attachment":[{"href":"https:\/\/savepearlharbor.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=364052"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/savepearlharbor.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=364052"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/savepearlharbor.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=364052"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}