Chuyển đến nội dung chính

Bài 11: VPN — WireGuard và OpenVPN

Hướng dẫn cấu hình VPN trên VyOS với WireGuard và OpenVPN, so sánh hiệu năng, bảo mật, thực hành site-to-site và remote access, routing và firewall cho VPN.

VPN — WireGuard và OpenVPN

Giới thiệu VPN trên VyOS: WireGuard và OpenVPN

VPN (Virtual Private Network) là giải pháp bảo mật kết nối giữa các site hoặc truy cập từ xa. VyOS hỗ trợ nhiều loại VPN hiện đại như WireGuard, OpenVPN và IPsec. Bài này tập trung vào WireGuard và OpenVPN, hai giải pháp phổ biến với ưu điểm về hiệu năng, bảo mật và cấu hình linh hoạt.

WireGuard: Site-to-Site VPN

WireGuard là giao thức VPN hiện đại, đơn giản, hiệu năng cao. Để cấu hình site-to-site giữa hai VyOS:

# Tạo key pair trên mỗi VyOS
run generate wireguard key
# Lấy public key: run generate wireguard pubkey key <private-key>

Cấu hình WireGuard interface

set interfaces wireguard wg0 address '10.10.10.1/24' set interfaces wireguard wg0 port '51820' set interfaces wireguard wg0 private-key '<private-key>'

Thêm peer

set interfaces wireguard wg0 peer <peer-public-key> allowed-ips '10.10.10.2/32' set interfaces wireguard wg0 peer <peer-public-key> endpoint 'WAN_IP_PEER:51820'

Thực hiện tương tự ở site bên kia, đổi địa chỉ IP và key.

WireGuard: Remote Access VPN

Cho phép client (laptop, điện thoại) truy cập mạng nội bộ qua WireGuard:

set interfaces wireguard wg0 address '10.10.20.1/24'
set interfaces wireguard wg0 port '51820'
set interfaces wireguard wg0 private-key '<server-private-key>'
set interfaces wireguard wg0 peer <client-public-key> allowed-ips '10.10.20.2/32'

Client cấu hình tương ứng với public key của server.

OpenVPN: Site-to-Site với Pre-Shared Key

set interfaces openvpn vtun0 mode site-to-site
set interfaces openvpn vtun0 local-address '10.20.20.1'
set interfaces openvpn vtun0 remote-address '10.20.20.2'
set interfaces openvpn vtun0 shared-secret-key-file '/config/auth/ovpn.key'
set interfaces openvpn vtun0 local-port '1194'
set interfaces openvpn vtun0 remote-host '<peer-wan-ip>'

OpenVPN: Remote Access với Certificates

set interfaces openvpn vtun1 mode server
set interfaces openvpn vtun1 server subnet '10.30.30.0/24'
set interfaces openvpn vtun1 tls ca-cert-file '/config/auth/ca.crt'
set interfaces openvpn vtun1 tls cert-file '/config/auth/server.crt'
set interfaces openvpn vtun1 tls key-file '/config/auth/server.key'
set interfaces openvpn vtun1 client-cert-required

So sánh WireGuard, OpenVPN và IPsec

  • WireGuard: Hiệu năng cao, cấu hình đơn giản, mã nguồn nhỏ, hỗ trợ tốt trên VyOS 1.4/1.5.
  • OpenVPN: Linh hoạt, nhiều chế độ, hỗ trợ certificate, nhưng hiệu năng thấp hơn WireGuard.
  • IPsec: Chuẩn công nghiệp, tích hợp sâu, cấu hình phức tạp hơn.

Routing và Firewall cho VPN

Sau khi thiết lập tunnel, cần định tuyến traffic và mở firewall:

set protocols static route 192.168.2.0/24 next-hop 10.10.10.2
set firewall name VPN-IN default-action accept
set interfaces wireguard wg0 firewall in name VPN-IN

Lab thực hành: WireGuard Site-to-Site giữa 2 VyOS

  1. Trên mỗi VyOS, tạo key pair và trao đổi public key.
  2. Cấu hình interface wg0 với địa chỉ riêng, port, private key.
  3. Thêm peer với public key và endpoint của site bên kia.
  4. Định tuyến mạng nội bộ qua tunnel.
  5. Kiểm tra kết nối: show interfaces wireguard, ping qua tunnel.
# Kiểm tra trạng thái WireGuard
show interfaces wireguard
# Kiểm tra routing
show ip route

Tổng kết

Bài này giúp bạn nắm vững cấu hình VPN với WireGuard và OpenVPN trên VyOS, so sánh ưu nhược điểm, thực hành site-to-site và remote access, routing và firewall cho VPN. Hãy thực hành lab để hiểu sâu hơn về vận hành thực tế.