Giới thiệu VPN trên VyOS: WireGuard và OpenVPN
VPN (Virtual Private Network) là giải pháp bảo mật kết nối giữa các site hoặc truy cập từ xa. VyOS hỗ trợ nhiều loại VPN hiện đại như WireGuard, OpenVPN và IPsec. Bài này tập trung vào WireGuard và OpenVPN, hai giải pháp phổ biến với ưu điểm về hiệu năng, bảo mật và cấu hình linh hoạt.
WireGuard: Site-to-Site VPN
WireGuard là giao thức VPN hiện đại, đơn giản, hiệu năng cao. Để cấu hình site-to-site giữa hai VyOS:
# Tạo key pair trên mỗi VyOS run generate wireguard key # Lấy public key: run generate wireguard pubkey key <private-key>Cấu hình WireGuard interface
set interfaces wireguard wg0 address '10.10.10.1/24' set interfaces wireguard wg0 port '51820' set interfaces wireguard wg0 private-key '<private-key>'
Thêm peer
set interfaces wireguard wg0 peer <peer-public-key> allowed-ips '10.10.10.2/32' set interfaces wireguard wg0 peer <peer-public-key> endpoint 'WAN_IP_PEER:51820'
Thực hiện tương tự ở site bên kia, đổi địa chỉ IP và key.
WireGuard: Remote Access VPN
Cho phép client (laptop, điện thoại) truy cập mạng nội bộ qua WireGuard:
set interfaces wireguard wg0 address '10.10.20.1/24'
set interfaces wireguard wg0 port '51820'
set interfaces wireguard wg0 private-key '<server-private-key>'
set interfaces wireguard wg0 peer <client-public-key> allowed-ips '10.10.20.2/32'
Client cấu hình tương ứng với public key của server.
OpenVPN: Site-to-Site với Pre-Shared Key
set interfaces openvpn vtun0 mode site-to-site
set interfaces openvpn vtun0 local-address '10.20.20.1'
set interfaces openvpn vtun0 remote-address '10.20.20.2'
set interfaces openvpn vtun0 shared-secret-key-file '/config/auth/ovpn.key'
set interfaces openvpn vtun0 local-port '1194'
set interfaces openvpn vtun0 remote-host '<peer-wan-ip>'
OpenVPN: Remote Access với Certificates
set interfaces openvpn vtun1 mode server
set interfaces openvpn vtun1 server subnet '10.30.30.0/24'
set interfaces openvpn vtun1 tls ca-cert-file '/config/auth/ca.crt'
set interfaces openvpn vtun1 tls cert-file '/config/auth/server.crt'
set interfaces openvpn vtun1 tls key-file '/config/auth/server.key'
set interfaces openvpn vtun1 client-cert-required
So sánh WireGuard, OpenVPN và IPsec
- WireGuard: Hiệu năng cao, cấu hình đơn giản, mã nguồn nhỏ, hỗ trợ tốt trên VyOS 1.4/1.5.
- OpenVPN: Linh hoạt, nhiều chế độ, hỗ trợ certificate, nhưng hiệu năng thấp hơn WireGuard.
- IPsec: Chuẩn công nghiệp, tích hợp sâu, cấu hình phức tạp hơn.
Routing và Firewall cho VPN
Sau khi thiết lập tunnel, cần định tuyến traffic và mở firewall:
set protocols static route 192.168.2.0/24 next-hop 10.10.10.2
set firewall name VPN-IN default-action accept
set interfaces wireguard wg0 firewall in name VPN-IN
Lab thực hành: WireGuard Site-to-Site giữa 2 VyOS
- Trên mỗi VyOS, tạo key pair và trao đổi public key.
- Cấu hình interface wg0 với địa chỉ riêng, port, private key.
- Thêm peer với public key và endpoint của site bên kia.
- Định tuyến mạng nội bộ qua tunnel.
- Kiểm tra kết nối:
show interfaces wireguard,pingqua tunnel.
# Kiểm tra trạng thái WireGuard
show interfaces wireguard
# Kiểm tra routing
show ip route
Tổng kết
Bài này giúp bạn nắm vững cấu hình VPN với WireGuard và OpenVPN trên VyOS, so sánh ưu nhược điểm, thực hành site-to-site và remote access, routing và firewall cho VPN. Hãy thực hành lab để hiểu sâu hơn về vận hành thực tế.