官术网_书友最值得收藏!

Chapter 1. Point-to-Point Networks

In this chapter, we will cover:

  • Shortest setup possible
  • OpenVPN secret keys
  • Multiple secret keys
  • Plaintext tunnel
  • Routing
  • Configuration files versus the command-line
  • IP-less configurations
  • Complete site-to-site setup
  • 3-way routing

Introduction

The recipes in this chapter will provide an introduction into configuring OpenVPN. The recipes are based on a point-to-point style network, meaning that only a single client can connect at a time.

A point-to-point style network is very useful when connecting to a small number of sites or clients. It is easier to set up, as no certificates or Public Key Infrastructure (PKI) is required. Also, routing is slightly easier to configure, as no client-specific configuration files containing --iroute statements are required.

The drawbacks of a point-to-point style network are:

  • The lack of perfect forward secrecy— a key compromise may result in a total disclosure of previous sessions
  • The secret key must exist in plaintext form on each VPN peer
主站蜘蛛池模板: 宜黄县| 久治县| 合作市| 晋城| 肇东市| 定兴县| 繁峙县| 穆棱市| 美姑县| 龙岩市| 兴安盟| 莎车县| 衡南县| 朔州市| 分宜县| 山阴县| 襄城县| 尼玛县| 南汇区| 石城县| 东明县| 泸水县| 河间市| 桦川县| 即墨市| 墨竹工卡县| 灵寿县| 海宁市| 天峨县| 类乌齐县| 鄂尔多斯市| 开原市| 南丰县| 上饶县| 岐山县| 屏山县| 日土县| 永平县| 渝中区| 子洲县| 谢通门县|