CENTOS6.5 架设PPTPD 实现远程VPN

首先有个脚本:

yum remove -y pptpd ppp
iptables –flush POSTROUTING –table nat
iptables –flush FORWARD
rm -rf /etc/pptpd.conf
rm -rf /etc/ppp
yum -y install make libpcap iptables gcc-c++ logrotate tar cpio perl pam tcp_wrappers
yum -y dkms-2.0.17.5-1.noarch.rpm
yum -y kernel_ppp_mppe-1.0.2-3dkms.noarch.rpm
rpm -qa kernel_ppp_mppe
yum -y ppp-2.4.4-9.0.rhel5.i386.rpm
yum -y pptpd-1.3.4-1.rhel5.1.i386.rpm
mknod /dev/ppp c 108 0
echo 1 > /proc/sys/net/ipv4/ip_forward
echo “mknod /dev/ppp c 108 0” >> /etc/rc.local
echo “echo 1 > /proc/sys/net/ipv4/ip_forward” >> /etc/rc.local
echo “localip 192.168.168.1” >> /etc/pptpd.conf
echo “remoteip 192.168.168.12-254” >> /etc/pptpd.conf
echo “ms-dns 8.8.8.8” >> /etc/ppp/options.pptpd
echo “ms-dns 8.8.4.4” >> /etc/ppp/options.pptpd
pass=`openssl rand 6 -base64`
if [ “$1” != “” ]
then pass=$1
fi
echo “vpn pptpd ${pass} *” >> /etc/ppp/chap-secrets
iptables -t nat -A POSTROUTING -s 192.168.168.0/24 -j SNAT –to-source `ifconfig  | grep ‘inet addr:’| grep -v ‘127.0.0.1’ | cut -d: -f2 | awk ‘NR==1 { print $1}’`
iptables -A FORWARD -p tcp –syn -s 172.16.36.0/24 -j TCPMSS –set-mss 1356
service iptables save
chkconfig iptables on
chkconfig pptpd on
service iptables start
service pptpd start
echo “请输入连接密码${pass}”

然后修改转发:

vi /etc/sysctl.conf
修改其中的net.ipv4.ip_forward = 1

然后敲入

sysctl -p

修改DNS:

vi /etc/ppp/options.pptpd
找到 ms-dns x.x.x.x 修改为想用的DNS

修改

vi /etc/ppp/chap-secrets
“username” pptpd “password” *
用户名 密码。
最后在iptables里面添加转发规则:
iptables -t nat -A POSTROUTING -s 192.168.12.0/24 -o eth0 -j MASQUERADE
#这条命令里的 eth0代表外网接口,-s 192.168.12.0/24代表内网段
最后别忘了保存一下防火墙规则,否则重启之后就失效了!
vim /etc/pptpd.conf
上面是设置PPTP的分配内网地址
chkcconfig pptpd on
设置开机自动启动

 

分享到:

评论已关闭。