åŒç€Ÿã®ã¢ããªãšèšå®ã䜿çšããã«ã¯ããŸãExpressVPNã¢ã«ãŠã³ãã«ç»é²ããŠãã ããã
ãã®ãã¥ãŒããªã¢ã«ã§ã¯ãOpenVPNãããã³ã«ã䜿çšããŠTomatoã«ãŒã¿ãŒã«ExpressVPNãèšå®ããæ¹æ³ãã玹ä»ããŸãã
æåèšå®æ¥ç¶ã§ã¯ããã¹ãŠã®ExpressVPNãã±ãŒã·ã§ã³ãå©çšã§ããããã§ã¯ãããŸããã
ãã®èŠåã解é€ãããå Žåã¯ã.ovpnãã¡ã€ã«ãããã¹ããšãã£ã¿ã§éãã以äžã®ããããã®æäœãè¡ã£ãŠãã ããã
- keyizeãå«ãè¡ãåé€ãã
or - keyizeã®åã« # ãè¿œå ãã (#keysize 256).
ãªãããã®èŠåã¯ç¡èŠããŠãåé¡ã¯ãããŸããã
Tomatoã¯ã«ã¹ã¿ã ãã¡ãŒã ãŠã§ã¢ã§ãé«åºŠãªãããã¯ãŒã¯æ©èœãšOpenVPNãããã³ã«ãµããŒããæäŸããŸããäžã®æé ã¯ãAdvancedTomatoããŒãžã§ã³3.5-140ã§ãã¹ããããŸãããAdvancedTomato察å¿ã«ãŒã¿ãŒäžèŠ§ãã芧ãã ããã
å§ããåã«ãã䜿ãã®ã«ãŒã¿ãŒã«Tomatoãã¡ãŒã ãŠã§ã¢ãèšå®ããŠããããšãã確èªãã ããã
ç®æ¬¡
1. ExpressVPNã¢ã«ãŠã³ãèªèšŒæ
å ±ã®ç¢ºèª
2. Tomatoã«ãŒã¿ãŒã®èšå®
3. VPNãµãŒããŒãã±ãŒã·ã§ã³ãžã®æ¥ç¶
VPNãµãŒããŒãã±ãŒã·ã§ã³ããã®åæ
1. ExpressVPNã¢ã«ãŠã³ãèªèšŒæ å ±ã®ç¢ºèª
ExpressVPNèšå®ããŒãžã«ã¢ã¯ã»ã¹ããŸããããã³ããã衚瀺ãããããExpressVPNè³æ Œæ å ±ãå ¥åããŠãµã€ã³ã€ã³ãéžæããŸãã
ã¡ãŒã«ã¢ãã¬ã¹ã«éä¿¡ãããèªèšŒã³ãŒããå ¥åããŸãã
å³åŽã§ãŠãŒã¶ãŒåããã¹ã¯ãŒããOpenVPNèšå®ãã¡ã€ã«ãªã¹ãã確èªããããšãã§ããŸãã
æ¥ç¶ããããã±ãŒã·ã§ã³ãéžæããŸããããã«ãããã䜿ãã®ããã€ã¹ã«å¯Ÿå¿ããcorresponding .ovpnãã¡ã€ã«ãããŠã³ããŒããããŸãã
ãã®ãã©ãŠã¶ãŠã£ã³ããŠãéãããŸãŸã«ããŠãããŸããåŸã®èšå®ã§ãã®æ å ±ãå¿ èŠã§ãã
ãã«ããå¿ èŠã§ããïŒExpressVPNãµããŒãããŒã ã«åãåãããè¡ããè¿ éãªãµããŒããåããŸãããã
2. Tomatoã«ãŒã¿ãŒã®èšå®
ã䜿ãã®ãã©ãŠã¶ã®ã¢ãã¬ã¹ããŒã«ã«ãŒã¿ãŒã®IPã¢ãã¬ã¹ãå ¥åããŸãã
ãŠãŒã¶ãŒåãšãã¹ã¯ãŒããå ¥åããŸãïŒããã©ã«ãã§ã¯ãrootãšadminã§ãïŒããµã€ã³ã€ã³ãã¯ãªãã¯ããŸãã
å·Šã®ãµã€ãããŒã®ç®¡çè èšå®ã§ãVPN > OpenVPNã¯ã©ã€ã¢ã³ããã¯ãªãã¯ããŸãã
åºæ¬ã¿ãã«ä»¥äžã®æ å ±ãå ¥åããŸãã
- WANã§éå§ïŒãã®ããã¯ã¹ã«ãã§ãã¯ãå ¥ããŸã
- ã€ã³ã¿ãŒãã§ãŒã¹ã¿ã€ãïŒTUNãéžæããŸã
- ãããã³ã«ïŒUDPãéžæããŸã
- ãµãŒããŒã¢ãã¬ã¹ / ããŒãïŒãã®æ
å ±ã確èªããããã«ã¯ãå
ã»ã©ããŠã³ããŒããã.ovpnèšå®ãã¡ã€ã«ãå³ã¯ãªãã¯ããããã¹ããšãã£ã¿ã§éããŸããæåã®ãã£ãŒã«ãã«ã¯ããremoteãã®æåãšæåã®ãã£ãŒã«ãã®4æ¡ã®æ°åã®éã«èšèŒãããŠãããµãŒããŒã®ã¢ãã¬ã¹ãå
¥åããŸãã2çªç®ã®ãã£ãŒã«ãã«ã¯ããã®è¡ã®æåŸã«ãã4æ¡ã®æ°åãå
¥åããŠãã ããã
- ãã¡ã€ã€ãŒãŠã©ãŒã«ïŒèªåãéžæããŸã
- èªèšŒã¢ãŒãïŒTLSãéžæããŸã
- ãŠãŒã¶ãŒå/ ãã¹ã¯ãŒãèªèšŒïŒãã®ããã¯ã¹ã«ãã§ãã¯ãå ¥ããŸã
- ãŠãŒã¶ãŒåïŒå ã»ã©ç¢ºèªããOpenVPNãŠãŒã¶ãŒåãå ¥åããŸã
- ãã¹ã¯ãŒãïŒå ã»ã©ç¢ºèªããOpenVPNãã¹ã¯ãŒããå ¥åããŸã
- ãŠãŒã¶ãŒåèªèšŒã®ã¿ïŒãã§ãã¯ãå€ãããŸãŸã«ããŠãããŸã
- è¿œå ã®HMACèªèšŒ (tls-auth)ïŒç¶ç¶Â (1)ãéžæããŸã
- ãã³ãã«ã§NATãäœæïŒãã®ããã¯ã¹ã«ãã§ãã¯ãå ¥ããŸã
ä¿åãã¯ãªãã¯ããŸãã
詳现ã¿ããã¯ãªãã¯ããŸãã以äžã®æ å ±ãå ¥åããŸãã
- ããŒãªã³ã°ééïŒãã®ãŸãŸã«ããŠãããŸã
- ã€ã³ã¿ãŒããããã©ãã£ãã¯ã®åãæ¿ãïŒãã®ããã¯ã¹ã«ãã§ãã¯ãå ¥ããŸã
- DNSèšå®ã®åãå ¥ãïŒ ExclusiveãéžæããŸã
- æå·ãµã€ãã¡ãŒïŒAES-256 CBCãéžæããŸã
- å§çž®ïŒé©å¿ãããéžæããŸã
- TLSåããŽã·ãšãŒã·ã§ã³æéïŒ-1ãšå ¥åããŸã
- æ¥ç¶ãªãã©ã€ïŒ-1ãšå ¥åããŸã
- ãµãŒããŒèšŒææžèªèšŒïŒtls-remoteïŒïŒãã®ããã¯ã¹ã®ãã§ãã¯ãå€ããŸã
ã«ã¹ã¿ã èšå®ã«ã¯ãå ã»ã©éããããã¹ããšãã£ã¿ã§ä»¥äžã®ã¢ã€ãã ãèŠã€ããŠããã®ãã£ãŒã«ãã«è²Œãä»ããŸãã
- tun-mtu
- fragment
- mssfix
- keysize
- auth
- sndbuf
- rcvbuf
ããšãã°ãç±³åœ – ãã¥ãŒãšãŒã¯ã®.ovpnèšå®ãã¡ã€ã«ã䜿çšããŠããå Žåã以äžã®æ å ±ã貌ãä»ããŸãã
tun-mtu 1500
fragment 1300
mssfix 1200
keysize 256
auth SHA512
sndbuf 524288
rcvbuf 524288
ä¿åãã¯ãªãã¯ããŸãã
äžéšã§ãããŒã¿ããã¯ãªãã¯ãã.ovpnèšå®ãã¡ã€ã«ãã以äžã®ãã£ãŒã«ãã«ããã¹ããã³ããŒããŠè²Œãä»ããŸãã
- éçéµïŒ.ovpnãã¡ã€ã«ã®<tls-auth>ãš</tls-auth>ã¿ã°éã®ããã¹ããã³ããŒãããã®ãã£ãŒã«ãã«è²Œãä»ããŸãã
- èªèšŒå±ïŒ.ovpnãã¡ã€ã«ã®<ca>ãš</ca>ã¿ã°éã®ããã¹ããã³ããŒãããã®ãã£ãŒã«ãã«è²Œãä»ããŸãã
- ã¯ã©ã€ã¢ã³ã蚌ææžïŒ.ovpnãã¡ã€ã«ã®<cert>ãš</cert>ã¿ã°éã®ããã¹ããã³ããŒãããã®ãã£ãŒã«ãã«è²Œãä»ããŸãã
- ã¯ã©ã€ã¢ã³ãããŒïŒ.ovpnãã¡ã€ã«ã®<key>ãš</key>ã¿ã°éã®ããã¹ããã³ããŒãããã®ãã£ãŒã«ãã«è²Œãä»ããŸãã
ä¿åãã¯ãªãã¯ããŸãã
ãã«ããå¿ èŠã§ããïŒExpressVPNãµããŒãããŒã ã«åãåãããè¡ããè¿ éãªãµããŒããåããŸãããã
3. VPNãµãŒããŒãã±ãŒã·ã§ã³ãžã®æ¥ç¶
äžéšã«ããã¹ããŒã¿ã¹ã¿ããã¯ãªãã¯ããŸããããããâºãã¯ãªãã¯ããŸãã
æ¥ç¶ã§ãããšããRunningïŒå®è¡äžïŒããšããåèªã衚瀺ãããŸãã
æ¥ç¶ã確èªããããã«ã¯ãExpressVPNã®IPã¢ãã¬ã¹ãã§ãã«ãŒã䜿çšããŠãIPã¢ãã¬ã¹ã確èªã§ããŸããé©åã«æ¥ç¶ãããŠãããšã衚瀺ãããIPã¢ãã¬ã¹ã¯ãVPNãä»ããŠæ¥ç¶ããããã±ãŒã·ã§ã³ãšçžé¢ãããããšãããããŸãã
ãã«ããå¿ èŠã§ããïŒExpressVPNãµããŒãããŒã ã«åãåãããè¡ããè¿ éãªãµããŒããåããŸãããã
VPNãµãŒããŒãã±ãŒã·ã§ã³ããã®åæ
åæããããã«ã¯ãVPN > OpenVPNã¯ã©ã€ã¢ã³ã > ã¹ããŒã¿ã¹ã«ç§»åããŸããâ ãã¯ãªãã¯ããŸããVPNããåæãããŸãã
ãã«ããå¿ èŠã§ããïŒExpressVPNãµããŒãããŒã ã«åãåãããè¡ããè¿ éãªãµããŒããåããŸãããã