<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="zh-Hans-CN">
	<id>https://wiki.linuxsa.org/index.php?action=history&amp;feed=atom&amp;title=CentOS7_install_and_configuration_OpenVPN</id>
	<title>CentOS7 install and configuration OpenVPN - 版本历史</title>
	<link rel="self" type="application/atom+xml" href="https://wiki.linuxsa.org/index.php?action=history&amp;feed=atom&amp;title=CentOS7_install_and_configuration_OpenVPN"/>
	<link rel="alternate" type="text/html" href="https://wiki.linuxsa.org/index.php?title=CentOS7_install_and_configuration_OpenVPN&amp;action=history"/>
	<updated>2026-04-23T10:45:56Z</updated>
	<subtitle>本wiki上该页面的版本历史</subtitle>
	<generator>MediaWiki 1.43.1</generator>
	<entry>
		<id>https://wiki.linuxsa.org/index.php?title=CentOS7_install_and_configuration_OpenVPN&amp;diff=199&amp;oldid=prev</id>
		<title>Evan：​/* see also */</title>
		<link rel="alternate" type="text/html" href="https://wiki.linuxsa.org/index.php?title=CentOS7_install_and_configuration_OpenVPN&amp;diff=199&amp;oldid=prev"/>
		<updated>2020-12-25T12:51:55Z</updated>

		<summary type="html">&lt;p&gt;&lt;span class=&quot;autocomment&quot;&gt;see also&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;新页面&lt;/b&gt;&lt;/p&gt;&lt;div&gt;=info=&lt;br /&gt;
&lt;br /&gt;
=添加iptables转发规则=&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
开启转发&lt;br /&gt;
[root@openvpn ~]# vim /etc/sysctl.conf &lt;br /&gt;
net.ipv4.ip_forward = 1&lt;br /&gt;
[root@openvpn ~]# sysctl -p&lt;br /&gt;
&lt;br /&gt;
服务器IP 172.18.140.173&lt;br /&gt;
(10.8.0.0/24为VPN的网段,eth0 为内网网卡，xxxx 为内网ip ) &lt;br /&gt;
&lt;br /&gt;
运行 iptables -t nat -A POSTROUTING -s 192.168.0.0/24 -j MASQUERADE  #添加 iptables 转发规则 改为自己的 10.8.0.0/24吧 &lt;br /&gt;
&lt;br /&gt;
#good 让vpn client 可以 直接内网连接其它内网机器 &lt;br /&gt;
iptables -t nat -A POSTROUTING -s 10.8.0.0/24 -o eh1 -j SNAT --to-source 172.18.140.173 &lt;br /&gt;
&lt;br /&gt;
#内网网关为192.168.0.1&lt;br /&gt;
iptables -t nat -A POSTROUTING -s 192.168.0.0/24 -o eth0 -j SNAT --to-source 172.18.140.173 &lt;br /&gt;
service iptables save&lt;br /&gt;
&lt;br /&gt;
 iptables -t nat -A POSTROUTING -s 172.18.0.0/24  -j MASQUERADE&lt;br /&gt;
 iptables -t nat -A POSTROUTING -s 10.8.0.0/24  -j MASQUERADE&lt;br /&gt;
 iptables -t nat -A POSTROUTING -s 172.18.0.0/24 -o eth1 -j SNATA --to-source 172.18.140.173&lt;br /&gt;
 iptables -t nat -A POSTROUTING -s 192.168.0.0/24 -o eth1 -j SNAT --to-source x.x.x.x&lt;br /&gt;
(192.168.0.0/24为VPN的网段,eth1 为外网网卡，xxxx 为外网ip ) &lt;br /&gt;
&lt;br /&gt;
iptables -L -n  -t nat &lt;br /&gt;
&lt;br /&gt;
也要注意 docker网络 &lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=see also=&lt;br /&gt;
[http://www.yunweipai.com/archives/12375.html 什么是VPN？看运维专家聊聊VPN的那些事儿]&lt;br /&gt;
&lt;br /&gt;
[http://wuhuizhong.iteye.com/blog/2037216 Openvpn完美解决公司网络没有固定公网IP的问题]&lt;br /&gt;
&lt;br /&gt;
[https://www.bbsmax.com/A/n2d9GlZ0JD/ OpenVPN 服务端（pritunl）的一些运维经验]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==install==&lt;br /&gt;
[http://www.cnblogs.com/xishuai/p/centos-openvpn.html CentOS 7 安装配置 OpenVPN 客户端]&lt;br /&gt;
&lt;br /&gt;
==iptalbes 转发 ==&lt;br /&gt;
&lt;br /&gt;
[https://blog.csdn.net/windeal3203/article/details/51111543 NAT、用iptables配置NAT]&lt;br /&gt;
&lt;br /&gt;
[http://www.mojidong.com/linux/2016/02/01/vpn-of-iptables/ vpn的iptables配置]&lt;br /&gt;
&lt;br /&gt;
[http://blog.51cto.com/lustlost/943110 IPtables之四：NAT原理和配置]&lt;br /&gt;
&lt;br /&gt;
[https://blog.csdn.net/donghaixiaolongwang/article/details/63263226 iptables——实战NAT（端口转发）]&lt;br /&gt;
&lt;br /&gt;
[https://forum.ubuntu.org.cn/viewtopic.php?f=124&amp;amp;t=473809 VPN或者NAT过来的流量怎么转发到指定端口出去]&lt;br /&gt;
&lt;br /&gt;
[https://unix.stackexchange.com/questions/283801/iptables-forward-traffic-to-vpn-tunnel-if-open iptables forward traffic to vpn tunnel if open]&lt;br /&gt;
&lt;br /&gt;
 [[category:ops]]&lt;/div&gt;</summary>
		<author><name>Evan</name></author>
	</entry>
</feed>