OpenVPN: Building and Integrating Virtual Private Networks. Learn how to build secure VPNs using this powerful Open Source application - Helion
Tytuł oryginału: OpenVPN: Building and Integrating Virtual Private Networks. Learn how to build secure VPNs using this powerful Open Source application
ISBN: 9781847190680
Format: ebook
Data wydania: 2006-05-11
Księgarnia: Helion
Cena książki: 189,00 zł
OpenVPN is a powerful, open source SSL VPN application. It can secure site-to-site connections, WiFi and enterprise-scale remote connections. While being a full-featured VPN solution, OpenVPN is easy to use and does not suffer from the complexity that characterizes other IPSec VPN implementations. It uses the secure and stable TLS/SSL mechanisms for authentication and encryption.
This book is an easy introduction to this popular VPN application. After introducing the basics of security and VPN, the book moves on to cover using OpenVPN, from installing it on various platforms, through configuring basic tunnels, to more advanced features, such as using the application with firewalls, routers, proxy servers, and OpenVPN scripting.
While providing only necessary theoretical background, the book takes a practical approach, presenting plenty of examples.
Osoby które kupowały "OpenVPN: Building and Integrating Virtual Private Networks. Learn how to build secure VPNs using this powerful Open Source application", wybierały także:
- Windows Media Center. Domowe centrum rozrywki 66,67 zł, (8,00 zł -88%)
- Ruby on Rails. Ćwiczenia 18,75 zł, (3,00 zł -84%)
- Przywództwo w świecie VUCA. Jak być skutecznym liderem w niepewnym środowisku 58,64 zł, (12,90 zł -78%)
- Scrum. O zwinnym zarządzaniu projektami. Wydanie II rozszerzone 58,64 zł, (12,90 zł -78%)
- Od hierarchii do turkusu, czyli jak zarządzać w XXI wieku 58,64 zł, (12,90 zł -78%)
Spis treści
OpenVPN: Building and Integrating Virtual Private Networks. Learn how to build secure VPNs using this powerful Open Source application eBook -- spis treści
- OpenVPN
- Table of Contents
- OpenVPN
- Credits
- About the Author
- About the Reviewers
- Preface
- What This Book Covers
- What You Need for This Book
- Conventions
- Reader Feedback
- Customer Support
- Errata
- Questions
- 1. VPNVirtual Private Network
- Branches Connected by Dedicated Lines
- Broadband Internet Access and VPNs
- How Does a VPN Work?
- What are VPNs Used For?
- Networking ConceptsProtocols and Layers
- Tunneling and Overhead
- VPN ConceptsOverview
- A Proposed Standard for Tunneling
- Protocols Implemented on OSI Layer 2
- Protocols Implemented on OSI Layer 3
- Protocols Implemented on OSI Layer 4
- OpenVPNAn SSL/TLS-Based Solution
- Summary
- Branches Connected by Dedicated Lines
- 2. VPN Security
- VPN Security
- PrivacyEncrypting the Traffic
- Symmetric Encryption and Pre-Shared Keys
- Reliability and Authentication
- The Problem of Complexity in Classic VPNs
- Asymmetric Encryption with SSL/TLS
- SSL/TLS Security
- Understanding SSL/TLS Certificates
- Trusted Certificates
- Self-Signed Certificates
- Certificates and VPNs
- Summary
- 3. OpenVPN
- Advantages of OpenVPN
- History of OpenVPN
- OpenVPN Version 1
- OpenVPN Version 2
- Networking with OpenVPN
- OpenVPN and Firewalls
- Configuring OpenVPN
- Problems with OpenVPN
- OpenVPN Compared to IPsec VPN
- Sources for Help and Documentation
- The Project Community
- Documentation in the Software Packages
- Summary
- 4. Installing OpenVPN
- Prerequisites
- Obtaining the Software
- Installing OpenVPN on Windows
- Downloading and Starting Installation
- Selecting Components and Location
- Finishing Installation
- Testing the InstallationA First Look at the Panel Applet
- Installing OpenVPN on Mac OS X (Tunnelblick)
- Testing the InstallationThe Tunnelblick Panel Applet
- Installing OpenVPN on SuSE Linux
- Using YaST to Install Software
- Installing OpenVPN on Redhat Fedora Using yum
- Installing OpenVPN on RPM-Based Systems
- Using wget to Download OpenVPN RPMs
- Testing Installation and Installing with rpm
- Installing OpenVPN and the LZO Library with wget and RPM
- Using rpm to Obtain Information on the Installed OpenVPN Version
- Installing OpenVPN on Debian
- Installing Debian Packages
- Using Aptitude to Search and Install Packages
- OpenVPNThe Files Installed on Debian
- Installing OpenVPN on FreeBSD
- Installing a Newer Version of OpenVPN on FreeBSDThe Port System
- Installing the Port System with sysinstall
- Downloading and Installing a BSD Port
- Installing a Newer Version of OpenVPN on FreeBSDThe Port System
- TroubleshootingAdvanced Installation Methods
- Installing OpenVPN from Source Code
- Building Your Own RPM File from the OpenVPN Source Code
- Building and Distributing Your Own DEB Packages
- Enabling Linux Kernel Support for TUN/TAP Devices
- Using Menuconfig to Enable TUN/TAP Support
- Internet Links, Installation Guidelines, and Help
- Summary
- 5. Configuring an OpenVPN ServerThe First Tunnel
- OpenVPN on Microsoft Windows
- Generating a Static OpenVPN Key
- Creating a Sample Connection
- Adapting the Sample Configuration File Provided by OpenVPN
- Starting and Testing the Tunnel
- A Brief Look at Windows OpenVPN Network Interfaces
- Generating a Static OpenVPN Key
- Connecting Windows and Linux
- File Exchange between Windows and Linux
- Installing WinSCP
- Transferring the Key File from Windows to Linux with WinSCP
- The Second PitfallCarriage Return/End of Line
- Configuring the Linux System
- Testing the Tunnel
- A Look at the Linux Network Interfaces
- Running OpenVPN Automatically
- OpenVPN as Server on Windows
- OpenVPN as Server on Linux
- Runlevels and init Scripts on Linux
- Using runlevel and init to Change and Check Runlevels
- The System Control for Runlevels
- Managing init Scripts
- Using Webmin to Manage init Scripts
- Using SuSEs YaST Module System Services (Runlevel)
- File Exchange between Windows and Linux
- Troubleshooting Firewall Issues
- Deactivating Windows XP Service Pack 2 Firewall
- Stopping the SuSE Firewall
- Summary
- OpenVPN on Microsoft Windows
- 6. Setting Up OpenVPN with X509 Certificates
- Creating Certificates
- Certificate Generation on Windows XP with easy-rsa
- Setting VariablesEditing vars.bat
- Creating the Diffie-Hellman Key
- Building the Certificate Authority
- Generating Server and Client Keys
- Distributing the Files to the VPN Partners
- Configuring OpenVPN to Use Certificates
- Using easy-rsa on Linux
- Preparing Variables in vars
- Creating the Diffie-Hellman Key and the Certificate Authority
- Creating the First Server Certificate/Key Pair
- Creating Further Certificates and Keys
- Troubleshooting
- Summary
- 7. The Command openvpn and its Configuration File
- Syntax of openvpn
- OpenVPN Command-Line Parameters
- Using OpenVPN at the Command Line
- Parameters Used in the Standard Configuration File for a Static Key Client
- Compressing the Data
- Controlling and Restarting the Tunnel
- Debugging OutputTroubleshooting
- Configuring OpenVPN with CertificatesSimple TLS Mode
- Overview of OpenVPN Parameters
- General Tunnel Options
- Routing
- Controlling the Tunnel
- Scripting
- Logging
- Specifying a User and Group
- The Management Interface
- Proxies
- Encryption Parameters
- Testing the Crypto System with --test-crypto
- SSL InformationCommand Line
- Server Mode
- Server Mode Parameters
- --client-config Options
- Client Mode Parameters
- Push Options
- Important Windows-Specific Options
- Summary
- Syntax of openvpn
- 8. Securing OpenVPN Tunnels and Servers
- Securing and Stabilizing OpenVPN
- Linux and Firewalls
- Debian Linux and Webmin with Shorewall
- Installing Webmin and Shorewall
- Preparing Webmin and Shorewall for the First Start
- Starting Webmin
- Configuring the Shorewall with Webmin
- Creating Zones
- Editing Interfaces
- Default Policies
- Adding Firewall Rules
- Troubleshooting ShorewallEditing the Configuration Files
- OpenVPN and SuSEfirewall
- Troubleshooting OpenVPN Routing and Firewalls
- Configuring a Router without a Firewall
- iptablesThe Standard Linux Firewall Tool
- Debian Linux and Webmin with Shorewall
- Configuring the Windows Firewall for OpenVPN
- Summary
- 9. Advanced Certificate Management
- Certificate Management and Security
- Installing xca
- Using xca
- Creating a Database
- Importing a CA Certificate
- Creating and Signing a New Server/Client Certificate
- Revoking Certificates with xca
- Using TinyCA2 to Manage Certificates
- Importing Our CA
- Using TinyCA2 for CA Administration
- Creating New Certificates and Keys
- Exporting Keys and Certificates with TinyCA2
- Revoking Certificates with TinyCA2
- Summary
- 10. Advanced OpenVPN Configuration
- Tunneling a Proxy Server and Protecting the Proxy
- Scripting OpenVPNAn Overview
- Using Authentication Methods
- Using a Client Configuration Directory with Per-Client Configurations
- Individual Firewall Rules for Connecting Clients
- Distributed Compilation through VPN Tunnels with distcc
- Ethernet Bridging with OpenVPN
- Automatic Installation for Windows Clients
- Summary
- 11. Troubleshooting and Monitoring
- Testing the Network Connectivity
- Checking Interfaces, Routing, and Connectivity on the VPN Servers
- Debugging with tcpdump and IPTraf
- Using OpenVPN Protocol and Status Files for Debugging
- Scanning Servers with Nmap
- Monitoring Tools
- ntop
- Munin
- Hints to Other Tools
- Summary
- A. Internet Resources
- VPN Basics
- OpenVPN Resources
- Configuration
- Scripts and More
- Network Tools
- Howtos
- Openvpn GUIs
- Index