当前位置:网站首页>Pfsense configuring tinc site to site tunneling tutorial
Pfsense configuring tinc site to site tunneling tutorial
2022-06-21 20:32:00 【51CTO】
tinc Is a virtual private network (VPN) A daemon , It uses encrypted tunnels in Internet Establish a secure private network between hosts on .tinc It's free software , according to GNU General public license No 2 Version or later is licensed . because VPN stay IP Level network code is represented as a common network device , There is no need to adapt any existing software , allow VPN Site through Internet Share information with each other , Without exposing any information to others .tinc It has the following characteristics :
- encryption 、 Authentication and compression : All flows are optional zlib or LZO Compress , Use LibreSSL or OpenSSL Encrypted traffic .
- Automatic full mesh routing : Set it up anyway tinc To connect with each other ,VPN Flow always ( If possible ) Send directly to the destination , Without having to go through an intermediate hop .
- NAT through : as long as VPN A node in allows public IP Incoming connections on addresses ( Even if it's dynamic IP Address ),tinc Then we can do NAT through , This allows direct communication between peers .
- Easily expand : When you need to add a new node , Just add an additional configuration file .
- You can bridge Ethernet segments : Multiple Ethernet segments can be linked together , Work like a single network segment .
- Support IPv6: Support... On various mainstream platforms IPv6 Application .
pfSense Provide for the right to tinc Good support for , You can install tinc Plug-in method to configure and use , Let's say pfSense plus 22.01 For example , Introduce how to pass between two firewalls tinc establish VPN The process of tunneling .
The network configuration
A firewall A( Dark screenshot ): A firewall B( Light color screenshot ):
WAN IP:202.10X.XX.XX 117.4X.XX.XX
LAN IP:192.168.11.1/24 192.168.12.1/24
install tinc
First, install... On two firewalls tinc plug-in unit . Navigate to the system separately > Plug-in management , On the available plug ins tab , Search for tinc, After finding , Click the Install button on the right to install . After installation , Just go ahead tinc Tunnel configuration .
On the firewall tinc Tunnel configuration is divided into tunnel settings 、 Remote host settings and firewall rules are added in three parts .
Tunnel setup
Navigate to VPN>tinc, On the Settings tab , Enter the following parameters :
SITEA:
- Enable TInc VPN: Choose
- name :SITEA
- Local IP:192.168.11.1
- Local subnet :192.168.11.0/24
- VPN Mask :255.255.0.0
- Address family :IPv4
- Generate RSA Key pair : Choose
Click to display advanced options , In addition Tinc Parameter bar , Enter the following options :
SITEB:
- Enable TInc VPN: Choose
- name :SITEB
- Local IP:192.168.12.1
- Local subnet :192.168.12.0/24
- VPN Mask :255.255.0.0
- Address family :IPv4
- Generate RSA Key pair : Choose
Additional... At advanced options Tinc Parameter bar , And SITEA Agreement .
Add host
Navigate to VPN>tinc, Hosts tab , Add each other as a remote host .
SITEA:
- name :SITEB
- Address :SITEB Of WAN Address , Here for 117.4X.XX.XX
- subnet :SITEB Of LAN subnet , Here for 192.168.12.0/24
- Connect on startup : No election , Just select at one end
- RSA The public key : from SITEB Of tinc vpn Copy on the tunnel
Click save and the list is as follows :
SITEB:
- name :SITEA
- Address :SITEA Of WAN Address , Here for 202.1X.XX.XX
- subnet :SITEA Of LAN subnet , Here for 192.168.11.0/24
- Connect on startup : Choose
- RSA The public key : from SITEA Of tinc vpn Copy on the tunnel
Click save and the list is as follows :
Add firewall rules
Add two firewall rules , One is to allow the tunnel to access any network , One is in wan Release on the interface tinc Default communication port for 655.
stay pkg_tinc On the tab , Add one any to any The rules , Allow access to any network through a tunnel .
stay wan On the tab , Add a release tcp agreement 655 Port rules , And put it at the top of the rules .
The rules of the two firewalls are the same , Here is just SITEA Example .
Connect the test
After the above settings are correct , Now it should be able to connect normally .
Navigate to status >Tinc VPN, You can view the connection information of the tunnel :
Use on the firewall PING To test , normal Ping Through remote gateway .
On the client computer , function Ping command , normal ping Through remote gateway :
Use iperf Speed measurement ,300M Uplink and downlink peer-to-peer private lines , Measured VPN The tunnel speed is as follows :
thus ,pfSense Upper Tinc VPN Site to site tunnel configuration is complete .
边栏推荐
- 现在CDC支持到MySQL5.几了?之前好像说是5.7,今天发现5.6的MySQL数据源也能实时更新
- 1157 Anniversary
- How to debug reorganization in jetpack compose
- SD集训6.21总结
- [icml2022] ctrlformer: learn the transferable state representation of visual control through the transformer
- 理财产品如果过了开放日期怎么赎回?
- 阿里云 ACK One、ACK 云原生 AI 套件新发布,解决算力时代下场景化需求
- SD6.20集训总结
- 高等代数_第9章:线性映射
- inno setup 更改安装路径学习
猜你喜欢

JMeter thread duration

inno setup 更改安装路径学习

技术实践 | 场景导向的音视频通话体验优化
![[wechat applet failed to change appid] wechat applet failed to modify appid all the time and reported an error. Tourist appid solution](/img/b7/6ce97e345a4f8fce7f3aeb2c472e13.png)
[wechat applet failed to change appid] wechat applet failed to modify appid all the time and reported an error. Tourist appid solution

点云转深度图:转化,保存,可视化

5月刚刚阿里面软件测试岗回来,3+1面任职阿里P7,年薪28*15薪

點雲轉深度圖:轉化,保存,可視化
![[cvpr2022] CMU tutorial on multimodal machine learning, 200+ pages to explain the knowledge of multimodal learning system with six challenges of representation, alignment, reasoning, migration, genera](/img/f6/6685902fca43163cb63cf2c55d76c6.jpg)
[cvpr2022] CMU tutorial on multimodal machine learning, 200+ pages to explain the knowledge of multimodal learning system with six challenges of representation, alignment, reasoning, migration, genera

What statements are added to MySQL

mysql如何实现分组求和
随机推荐
Assembly language greedy snake and Tetris dual task design implementation details (III) -- Tetris detailed design
zabbix6.0+timescaledb+企业微信告警
Gartner 网络研讨会 “九问数字化转型” 会后感
Rough reading of targeted supervised contractual learning for long tailed recognition
瀚高数据库自定义操作符'!~~'
张至顺道长自述
Selected articles of the research paper | interpretation of the trend of McKinsey's China's Digital Innovation future
5月刚刚阿里面软件测试岗回来,3+1面任职阿里P7,年薪28*15薪
Uniapp applet opens the map and selects the location demo effect wx Chooselocation
flink-connector-mysql-cdc-2.2.0,生成全量快照阶段,是按照Table
The 17th National University RT thread innovation special award
散户买基金哪个平台最好最安全
Snake game project full version
Jenkins定时构建并传递构建参数
Inno setup window drag learning
自然语言处理如何实现聊天机器人?
EasyCVR智能边缘网关硬件如何设置通电自启动?
大魚吃小魚小遊戲完整版
《跟老卫学 HarmonyOS 开发》:以父之名·码力全开!写段HarmonyOS祝父亲节
The highest monthly salary is 17k. As long as there is a field of hope in your heart, hard work will usher in a green land~