From 98a08136d80dadb0c5bb6250d1f3613c2a4872a5 Mon Sep 17 00:00:00 2001 From: test2 Date: Tue, 10 Dec 2019 23:32:04 +0200 Subject: [PATCH] shorewall --- sec/495px-VPN_overview-en.svg.png | Bin 0 -> 22635 bytes sec/ex-4_iptables.adoc | 2 +- sec/ex-5_iptables.adoc | 277 ++++++++++++++++++++++++++++++ 3 files changed, 278 insertions(+), 1 deletion(-) create mode 100644 sec/495px-VPN_overview-en.svg.png create mode 100644 sec/ex-5_iptables.adoc diff --git a/sec/495px-VPN_overview-en.svg.png b/sec/495px-VPN_overview-en.svg.png new file mode 100644 index 0000000000000000000000000000000000000000..2e625d49979414ff3fd2da20935717ebd2d1257a GIT binary patch literal 22635 zcmZ@<1zTH9)5a-o#U)4z4-|KI3B|2QaVTyrP=dP^4HUOhC=_=n5Fjn??hY*uf#QU~ zm-h#JS8_$pCcCq=$Ch*wFmH&uPLxrW7CsP~5|;SwDUUZSF44v#`(0`dn&fJ7QSR9+5VUiZeD?i}yD`l*Pk zFNEZTkO6zl^}V|k&QHpVZ_iju1mZ9M!`e_;7;G4XFL}<2kx-d zk9Ac4Z|Tf9q|kcMKIv^=bmM2m!**~O%1PDvI*97|(mbwswqD6hz>VZB-W>A~&QRVp zxh#4z4?EK3e)1&%=AU_OiEMGT1pUvlB(zC&kWA;K^|(9s8QPyyo4*;O-&Ux4mZnHk zZWSFweI3f}<0oYETc$9T>Y_dH9EV)LMB8V{Oq)j88%pv04#34XxTfBJ7?e_9rOZ}y zqSX5_k|OnbZ@q@|V{R*~B#w6de=DIc$tuwX$B{JgZpQx?wwmfCjaneKQJRSANG3z|M->7SWG&q_#t<7alEicjP(gQ0TiBMgp@fdn#nHe+(JUCe$cxa*Q1k!#b zk00#zUd!gcSd3dUA=GT_*`q-VwOzT}=493!*42e=ybr9FXG$j=D^3h)&q2m%{*&~- z6HI)Cdih0RFU(qby>+Yy-!7erq3#C8xR;TH>uC{s!P;uC}iMvG_rRQ#)>!Ln8+>=0xV6VoV{cG)h{ zP)vT@iBdhoiBKF1UfTq(U>fG|j>c(jOCk7mIG=_Ye#d)E*jac_T0+t?s zqQ?1iDXWTCeSQbl69a?8kHais8P1YVDU#^*mFo0mJYFK_-Y&eOrt*UDYc)_~rUI9b z8rypbjc}uJ@OU{(`vix*$vY-&^QbSUL9Bxh!>5wN-F-~7Z1iy^6vDJsMtK1^KdF}Z zzOU<`KdH||AvNsRd6{b?)z6p5Vf~x8`l2s3tvHnxDL-;v8kZg1< z-~{mne_}oSwa+R$$cEepLlplY?O&I|&_|GazeWc-?xClFdCD=EK%hXUcDsqjmhR~u zCpjY}>i6~hEz;0#BVi@M=Snq`kXY%+G4@bnX2#$v#hlhPk_wbF=LPVF=>|vhFu9Y) z{!06@+qU>gP7_|^%0rdJqxd!~64F@J(vV|m987*LU9&GjSVGw(rArm??8um?Fjh(s zE{E=j@!DvrFmleH_$Sd_Byky>^*TB9J4R`Z3j|vdq@#EGPrgsuygCA59KbV)zIgEA zUHURK0Uy@E716@s{1NHygdi?Hbv$kryFvzY4*r-qEl0WJ^Yzs^MRKUskDgb>PpK}V zq3_z(DOMIJO+Vx1U1#YbavusiCZ$%WxfC}M=GeYqL4T2Y-oJNsQBeoCbI|6g0(+iI zSEa!irEWe?gxPL(MgzXxEV?`kK=Nmllzv)uggsO?pJ1_Q*AwPm!uM%^Lk&kIv38uEgnXCR_ZFfzSQJ z!^0D_JYAn76O=d^PJ4a#^eV2sT@XkZc(_TP#(u?PnBEgts-u!;_F$a7?}HI(79q(@ z?00FXk<8+HCiR2AMv(zsinSX9jpV5N!1Kn(DI#s;J*ZjbyDY%wDeUeQw|r*)g7DXZ z{Z#WovBbmy=(tb<9@n{s`T!7+P@T>@74Bm>;%7Mzf7HXC9OjBzU@d$2%ei9aY6F;e zq5sX@mma{m;~OG&?oL}3uKlPkI=TB5+z<##LH35-jx)DvAl4ii8cXbW~)jj1-a(K&u9ex?`Xe4(@Sa0Fzt z;3h$a(lpMcaY2n2Kj>_SNYe?(gi;?JcNu|G*bZ%Ei(|ZRwIwXipVUtGum94uFu27l zn-OYB=vY*jUaP)G;Sdmen!h@KV-k8CXPfNYUj17N5{S9?>9>`?>&5WJ<~^hW$h(`Z zS>}a*wYE@v ziToOh8&ez1qQ2i=Tnxu{T}@XUJSnC?(-C~b2Hgv`A89vWTxflDm=vOfiI{M_xuaPQ ztMPZFio6obvDTXYPnFpL?sMq^dYxaha@io_RA!?U?Ar2aOjR*ozR^E;I_xs!jo|7^ z`%r+V#NqI87qL1c!H)GkRa)qlwly8OEG54T@O(794)R~T^^61`FsMg)A(i9MzC6z? zu^Xo>CYe?|&OKhdRVGrL?nWUqgm*J8@PS#FOd@h2hj2xYp&Mn+cpnu@qm|=pIh2ici}XZ6(kIepw}ExAyKA zYG2Pa_OrN4iiG-$r7=C@9<^$(JTb-p{K1!gdLcmA>lD&D9o~cTJd8%-9RX(m>`yF* zC-bTz{q?V^#D)o-3c?B?)z%gJ|H%h2eAZ`wiM(nu#HrLxSlA5+Yzz_oDJ}C!>vYy~ z)l;l%AvbMRyoJ<#^1*b9HDD82ab{2DrsG~Rr#|Pjb$NgB3onPc?m5iHoz8!Cb?b20O5XjJJq75`=Gs0f1HBk#Rv z4oj%d15d5?4VoxXD67{AO^VI(SC)RyH;R~shGvc&rC~RhP z7usZ>Pgws;y()dz*lp|;N~s9>vT6Hs;-r@r`oO9!v`*@|_It`PkJa@fg}$S3a;X1^gPIA&A>*Bg|pNg7@VqveaE9k*as5M6@6ViJ#^%%_7jEQ1Q$A`WK(- zm{-r#DS%C#2Rd;Q`J33dGAuc5OjiUa-oHytWJ;g%ya*Hb@FH1JFs3WAv>b}Xxt^Vr zr~(ZeJVer~YFxZJ=jc=a=j2MP(|9n8D8Fg&C2*s$mGbd4UJlfQ%VNsg4}i*3^bmuw@cfsfuE&p-VWuERR^7*+J^4|knnVlwYHX%`l7C@c?p3#+ zY>Bm}-r2Rt_D1-LkPhC4r}6tG*^Jx_2HTsC{SJ-bUZCA|J6zI54wMqF&Js;cN{R)+azO zLS^QA3oy2kG`1PX)fl0*At8++Au-*P2CwCFx;G8vdS3ly@*`vv%Zi&4_T42au`HP6 z7le@aMdcl1WkMdR{cy{!nLEuba{fhJ|GnoD$0QPHNp#d2B?qv{QfP#IFTTWT@A90n zds`U>?+8C8&iu5px8#{sFEHoC$*rCMsqoRS;axN>3tbi4l4^NXiN`lxJ%juN%ApBb zh8=oT8|yfL7fo)vj(m{D?@@#d?_t!JOW+k;KL zN=85Bg(}7!T@f+?c!#R?QY7gBWB6gf+C9*loO`i{jg+HJo{i-5(AaRprbj|jHX&^c zp64z{h|XF6G;gtQ-<0-DPcQw4#9N~UnV<73v36dyWS2BI}1kDf)^}7hTZhvDZ2n@)KoJ=I=xaOCZfkX*LWHrCVWaytYx_ zLWPA4jgRLW4=l;#F>lK8X>Z+^# zuWd(p3oniK&;J5g!71dr!xHsJH4J#FW}7pO*6_1l*HJENyaayY;ZGSTtS-emiZ-}1 z=`1X;pPtu%N}JfT;9__}*0+rd!k?MjTgOYCg(=G+)fOHoAhpAg^fLRuk$(vBhy}>= zniFlZ(djA*MA(Uwfr%^B^T(mlug3UuW9(9WdZpeOps2liK7q9Au8VY=@FMGXej>K@ zM?4b(U|3+d>;h1=%=#MoPHYkLFYMHGg<6s&=g+6+q8TR)E{J~REsKVh6w6^h;eBqojWVueQ4Q0ZF zCGDK58^2IEBmc#tKU+^H!SE|4q3`sl-hFUo z6@T0RRz%*jiyNbRk=5e}q;J0Iz04$0%}-oe(Q$MGl3BA(b&?GZIR+a%lr1!)@`4;P zzWfB_#aC14&Te#*4FqZ216AkiWn_br1nRPOH1xd$rH(Im!Y9MKsw@S02iO_w7gD&N}&fukiTCqU^y^j(Pk8-N%9fGH^tOMqpbAZ zjQaBu9`h%F=^LF&Fl|iKwj0UV0{Y1^`_CJmu)%PpE6FC~|03;%Qe~A{F}*y(%oK5$ zneJqi>N0DmyKzjyZa25q%=7aSZZ~(<{KRi5`A4-1B;}Oy?y>AS4}P-C>HxO5fW{9l zTX5K>kG}o?25+8H!p+?cH;Qxa)Q$GTGQr4?0e)I0bth}Od-bp$irzDCCrbGa-49cZ zWp8SXYUb4|ng9NaJL*%ioFIBzrDo?^SEtfA%VSUzVDaPhH3%pT8G1Nw_|`yu*!LB4 z$7G2n6SFBS2P{W$7Xh-z&&ZfvOQaor_v5e)jY;KE@~!Z!grDjW9wDv+h9ldk%>VMr zAbK{V7sS@VBYA*cu%+>Mq`RJNso4Dpl4 z^L+3SzrOV%{?`%uJ#>E;N#ZhKi8jUtF?kd6M7~gKp~~8@HlCkDH9n!l)Eh%-U}{R} z!^T%9wc)4qNZo{;33Xo;9Y?Gwm&ALyfU6ATS4$&tgX5@C7rxfc3)l*4iKJZ)ZmZIkQ^8Kc!%yA zrlEknRnSF-?>PGp7DaBVVB7nD6rWrdYc*98;QSvo}Q7&i+!9!`#P+BobBN9faYEf@mqn7P|c7hHII=m ze6v3Om}GLv1Z05t%x_})%Wxp1^KVahUxd6 zE=MV>uB&p*TfX~jD#kYkr+dBZWN%AUTkOVjPtQXft;@08=pmw2fAM@YE<(5_v<489 z=OJ|d{z51cBHndMnRJ65Lmp4qixA(TAS@CV1~#XC$tW^DJ3 z$<)0ix}T=c6Uw&zMJ+6Y{M+uO>A&I@?{)2E5Vn*HY^1Tx?!IV}n8VqboPCCfqNMEC z^nbU{Vo5x8-v6Bt7o%FjgR2>gc6deKj&4|Wt&nhXKYG?hL@ZWR=kGX-WxHEA%eY3D zH2VW>0G? z-N@vD?E9ZU8NHB(e>{ByNlvRa(e~LkHgevGZIQ(FyYM)?5ksw$77&#P!_S4HKhkAqzFO=i zu$5%|EZ!`G8zlb`4-Jsw*N^D>;DMsL1@?>=MJBizMb&04t?yrJMTX zm5>=ch)PaN#}a;k3Zn#B){p~c{9%Em44Hvj@k@w7WbrcL?rmILW`6qn6B&WN2UCHU zzkh4xXAAY_el2Qr7|-=HuCqL!&J}@6ceyPi392eB@d=Pbx>%1&tLI=KNh`#jqAxWt}w{8<~^R8{)_+#1*9ULB2OkUV?d|GRbiSz^f5 zBmamUqOvEh-2!wE+hpTZ&SGUT9uM_yhkm zcR^RKA93;Lugv&d1%<_|3FVtGDTv6q+-yLT`)S188|muM*Wt-ri74nmnnI zH@X`%yCQabSmudd)y4M`Pjkb~W;Ae4v|H+>f20hMY zqa#ZBKa!_<>e{|_&l3#;_(?CYHgy^NIDn#(KfG>vY%S}m7vXZB+++!;P7-fp(Q(-- z-uH52GO4& z@nCw^-H$+AJoR`yTulnq6ZMu|y#Z=ARm>98qhb@GBk9gz2S*ysu5DkHv=r9O4?S#@ zt&@0>Pnyk&gNbtIC&V_gK}7R06P;umS>v(NtjQ%opFQ&&&dmw^M%SJ*qlMb%=k?c0`Uy7* z3r`W|law%9Yclb?r}5?)?D2NjxjUZ5TL7muxi>XAT+Oa0?;>$;+4$i9eQcGW+$e#p`<49Q6WAGGs!o~(#~!23oqo1Z64_Ku{kXmyI<=Y-@Pn-+_&<< zvC0@GI>IG6Qww?Gl+^Vl3H~Av-SRAPU*%Zui$DHYN^<&R#SrhDW+$g0o+^qLrcjB8 zu@>_Zy<%u@VDTWz;KLaW)HCl}(xwXQhk`uWVC@+5Gm!mqRlDY)fVEg(IWUKuDVfCEXcG{&SN5AncoM@l#Fu4puk{| zs*_r%ZpxupBMF1jH5RF3>aRW1nz> z?Gxo@i@Kvp>#;5e#O%r=74+)0@VmwZ2zx;|%885)0^go{u-{$RY};*g>7Q!b2<5Y*8{c zhF`G)Wp=MYPe*%TFDY~m7E5Rf+T#3$b?dw<)Pw`=nKiOkBS?CK9v&K9-b}KSCm?SXX;_u} z*veSWVyAj~X7l;`WM$~g;6W5ppU&aU zCbp@5-uIOtQz466C*ZS!RY4Tg0fi;Yse*9y2Ok20naynZUt?&`9^b`Usx9SrS50)p zqEV2keM=Gg$p7WKABBl7?OinB9J_1R)n?aU^MnTVl@{OdNp=hAifnRi`Oz=6RdAGLu{rxpI`dF5l{ibyt;Y2lcM`UjO;qaje8U96Q<<%* z8RgQ7b8l*8>4JX^+R9$NxifK#Na_F7bmm|mO&Ti=NMPJ6nNHDv_~!yh**w|3K<5dH zw=iTjW=)QIR-TzG!+&TB)A8LY;!IS@U*$FI9~Oqc)hwP+BrrOc=qtTr^xe;uH4<4j zFiIa6{v|@5ZkMU#Js|n}^fx-&9o1PYmeC>wfzG?N5+EY@;LQwg^)(puI-)TG~-F)>Tv!1}ZZ}oBUIrG^ZUI6S03X~x)#V3B2hcZ7VRHkFzjARnmF2Ky;iS|iCnG`~=Eb#Sw0 z-%B;=lL;?kJB}e%KfWvC?syKq{uNTogwc+x|8p0s@7+_S55CTPGl@#Rj%{(u-Zs*= z`rWOknD?HbeN79195b}mjF^zEGy1OH=DVR0l6XHP{5E{Kjr?bd@{SIDMZ9N%xUYLM z_^~J11XJwGLmMNxNIl<<(<+HNaf{fpfe;io&G;+BuZyBB=H+&8b~ysY&`&ZO9iJ%5=Y zfk5S9{zj{~tW4sYi#r)vs&~`@ObZVtC#rHjPIUoHWiP>WVAW`S$uIetz|V7>n-#PZ zMiDRHbzsNW^9#nglMTjfwy=h;8WucaZVjovIF&&Sq44=~Vo{b!Za#(1NO#a!PH&qL zN>zcgu^vLj#t{XUw%jS1?hKN)qzw>#duMV|7t$9u(GtW1z*`Lf3_}+U*COpdG0bU> zf2fw-4|OiPlmO}wKI+DiFw$K&EZNankV(Hz2$Bwg07ST|g9zox zFCJ@YAD#mr#@sVXeoI;F0Noa_zy$hXK(%%zfe(v)dqcT{aSr*KhAhOk%bHR^?lVVv zhPZFjr$NFGnxCgEO?u@G0UMfR8^5Z^hfi8+d;{4WqrlFG{D1_Rw8rMEnv_8up3LjR zVc`^0f2H420C7_Fe?D|Ogqf0ONtnFyN9;btNo=tPw-aR#`X(B9o~gc1V#lfUsubjU zzk;W6Zlsi?hU9Yfz=4f}=%u_5M_YQkg!6;8@0>M1nK(Tk*fnSbOLsRs;q)r5+`eJd z4M~dnY>x8?Ioddifgly7nKtJKci}Nb-#H_3YI5s`+0{gM-_Nl_S6Svy^*QFKV+M8x z^<@L~1fEw9b*&qVkB^KOi5sNXWE=M&_M#4~k9lU@#$S4W(*uu} z3+8chS(F}7*0S)$xAU(oT~}kWZ)Xg@0^r~M1O2A``nuCA#h{+gPClPTqV8S+5<~{0 zT12;lD?CEON(TdUDI0{yb9Nzdg|d?9a_@QqiR*Ko2RLq)i%)H_fD;+))C}Gw1_s-w-*9n#m3C?97Bzhl+3?w2~ePAIMTgSPe0n`+2eg;P7L_{rq3k_r&Ho|c1)HHR~ z{&9okpx78!0sxC)c*48~-9+SU?YQK9q0vkT?X+XTXI0yND`O(B|I&V)kWwD(vrK$M zLVz3+v^qt&in>0fT4>$t|yy9+ROid+3pn5qqZLe476(3+=ys$rR1Q%~#&7 z`B~=g8TKpg7A)zahieqZ9^0A`&Gb#7*gZT3VA#6yQlNZt-t+^1$r$aV3Lu5#9Oa$F zZ#&XoHdSATFl_+TOqXj>s9Y!aj=Wptkq)CWHK3=Hbs94U;%Z(QQOydS*2=qye$6L` zCQyV+u~KvK6pRY9vtdBK>%SquFGqGj^DC631YT@u`o8?u`eSIU%hM*?1h5~3T&=qbRN%d;7Rn2ZyK}l) zL`4Hq!SR~Q=>x5h^Q|)wB)!LB=r0u;aU^2d&gRbxN7lpm<69^()7s>q?QJ>G-+yy( z_nn!6$ICj~9EQ9^i+Q(MU2PlWT_1D!2<1?R)?HJc(k2pnM~f+_72kBXU3Ifgq4GeW&;dKMl`K4A{(FGJc2(8ri>pkA672((Nx1WQAO=%~kM~opdwq zY=@fRtSjoE@OXRN@Fag@Mg>S%qqk@m3?+s0!P+;sgLQp&UGt@8GcsiCwBGSCDQF^u zsySySXXDbNAjH2IlbE*c8rq9#5pT2{&E9RNPJ=)eWz&EPdC`#&BQ}j?MG^Rb%&bx@ z@xO+pOHQihK@_qF$G!K^d`$+-n*@;V4J~jIxr;2-LeLmNadHb^aJ0~kBKDiZ44go)hU4T5|94PZc?#^#y znR+$`ZH?v|fyDHgwI4(Q>hH}LyUNK8Su|qn-oz3$J7cNunptfV?R*Ww%%QYNZ#YQ= zJNh-2fqF6NlbEXhN?`u#8XDX!7ygwP2-Mg5VS%&$bS8;+;v(~F2rb_w$Fcb!Th~l- zV9@sOJQuphquCt+$f5BvHGj`Fyc4u%p2EzjwqH@7uO!$o)7ufM%jJWgR{NkVWtbw zuH_~oKc5y}CI!jI5*{9xOgk!)IQ<^n^+Tkkm5nj`$m%;vr7u|l=8_j)CsOU%mk#NT zrjWdP<&M&t${UGIM`S8XFg^H(PAb;hQPQ4LY_69i#OqCJE_x^B6pwHESWXr}OLc1c z7FNmj;#I6U06Xurdyxn;s@r2kjgej5%)bF2LS+=`48(RzH z6|IjO>4IYZyccuXs)N;4)6(5r59|(pcUo-<=5Bo_l;5H2IC&~qtxk-+A#Zy}RPyTJ z>!hlx7HhC@hsB859V;N|>03Ceno;Ty(R3ZGYw7*XrL)V(o48UQCpy|iFt4X>6$hQ; z=-Ei};zK3Nq(RM-Hu7=mrPewdad`Oo)8`|qpYq_%ve0MUlt3BspN-!`sx&9uElbU2 z7;Cl^JR$br4&04XVhh|U+4#S$nMNWV8SYULb*s6;D#b(w~cD#bSNwHlPjz^!d83paMK#Y3RUAAnv&fS z$w20-Wm`Dk(}^jESym;#K_L)%I~`08B+$^p3zqwDrBVH}{BuK$HzR2-zgyfhdSKqU zWswDB?ESHs{OYp?!6UIdNK!}G(reH*7E&Zf3%{M#@(%k@TYW-k{I>NQE&Pd<5RrL%&%il z-=Q*jaEg+kNq0CZwGq@<_in)*JRN}#~8@tmoo zEOBp7bL+~DkqqUDk-^-e=<(F2_+V&HJ8jFUVOe@{dpKF$w7Mi>G6O$Qb&p~i{rOn4 z8}z?$=ej_+7|$!uXAMp1e>&T}NaFE+tl;88uxUFcq+XvTvuqQeUrv>Ve#74ghA4A| zpW~Qv)S+48pAzi6Y?JU}PRo3#N)`FayD@iRJsZIFAxFBqg@$DIyjqlT-uxp@BUJ-w zw(3j+x_!YV`xb%7x^%IeA(OsOw|)yU1#+IGkqT|?Jh(-;a=a+VLMEIUL{$IEuaP?< z@7q4ZPZQ}%nSleUSI%cEKLmEYO;tuKf>dX{^K@Swv`tX70a!hNA02rfrEcUub~*|g z>vx?e+6ccwLe>z=B`=jraPLjrY@B$4KBFA;+uqt=xqkJ9K|i`l-iQv88U*}2Fu+(6 zw1>R-tcWC)JYy^l4rE?v?C&`JI~7u37#5q-L&&L)KP&4y1X#CB99YiZz6NzXKC4N=Hp2;06iMF>WG9#-Gvp{p>F%XlBS@Yu?}wGTcHYV?sbe6`dV!0;eNJWwcok! z@Nzy^f+S_u7;|aQ%GuM;HP19;)V!Xwt`M7LFW_0~?EEjHZhcy?48NNY9L=<*{JXeI zOWi6wESWA4I`EUGs(8#i#A?XvX;PbXvVC};w}+esW0C<9EOzV~K2K#|_TWf1{Ury? zD3W33KqtgvldLrE=x06#Kq$wJ}ETlU*)FHpEJ zkM>H630*peahJTDWgAGH9VC#O>TmCShL4Mf+9+bIkW;c_R#><)YtaKZDE94*l&Voo zGpJ9VodDiOHu-xX?FF(&^;uiF@`j;y<&t+Oz|Vw$fC4O7SoZr~uWwFPTZ;#;K)ueO zrc>#FhAg-zktlFtQe~{I%XAYV$oYQfg7H7@M?!eYy>nw4=;UZ*RL9jp=O2*(x#^q# zM$=*&@bR{33G!V82b_L~++dpK2aRYIJP1rAu^x`K;%)Sx$N|ASy^KbUaQYglI-Pf= zZ;X_FgE5-!2aDa?4q9a(CcPPw@9-B)S9H5*VCIwqO6r+$^fiMfwME#!MZ99}_^*&K zn_YXEPpPHM{OQ;Zm$L?EA|{t-KUM-Lhm~>y0=n)uKkZNX~<9txmI5@@y z?(s8Jhw`cO_2Vk#-kGmcRR^aKol;K>G)blDh@G6?b>*5Iu|X9y_kYoW!)2NCP|UVw z3bS!+a5txt(Ici*W=$voVHpTiMd}6;Cb55|iBBAk$B#!r85UWpyq9!E-KagJE%C65 zqyra>jWXou`6!OfzPetM1BmmgI3>>E$=^=3l5t5tCze_f0eV1=M%3wqR`M;E2I>Lw zdu-QzI{G|9V`wr1?;qN{51M$c#BE5_W3yd*S#WU={Z?HBAm58|ce{k&KB;qHgPhjO z?Hz10V`hwMxTKa!P~|NgY{c~v;qc9#ngx8FOq%3Dz6lng2hzUjySEf;*LK3TA*b^z z9&1@BOEfvz&~;M%o}yZJRia91fAC7Kf+ExWjl>GYYg=1k#%Gqx&$q%JYjl!V)_?>a z;-q)G$a))##>du}3f3F}8=GZ8wg+0Tn%vhLu9Oi{bnCSHXGT0s*2EKxrz0a9!&{?I z-2G;#nxXYSEZdc?sdM?SKW>)=33p&m$k5S|IBc)6pyE~&ch~n1aVlbVta^>FUj3;8 ztzB-Wx|#S(yl(F2JpITDF;V%)19IJY_he0sXjid`zr>=yBA$Q zsvp0Ude2D#$={)}31{QqR{tw?u7XjDC>0Tn5SOKAe)KpjMLK5>_g8Oe0DJo5%sV*$ zNBuy&NnaJ01zuA3Y@@QgratudAYu}Vjij&nCy9);rcO$QDgC^?2t1(Dy2n@dRg3kj zL+{3uPb;hv%VL@P>JCtXgQUJLYV=8FqfHk(S72Y2z=^7$t7S*_$N)889GkW`(R&UV zxHAY+^qlK9hA%s$^0zM|BUqVLK)>jN|J$yjZ1m{#BMp+$sf=k*;hX|bC$^vP%HZH` zUF_H&f?(l?OYW`$QNxtFO&VTy(@wE1!n8x9PW{{5hcCi}L7_@69p&kTZqTBEU64S2 z%tyXq>C<<5GFCm1c0zo-pZUE?eQG743p?s4I8BL4`>_%5A|sN5h_xsKI zvVd@hsxePwFQQ=@iHFuM#Jwg>S$ut6cr&lw+ti{dU8^FURbHX8quF)F#10TDR2#aO zgQ74gp5a@M1bYaUc<#{0lOjw6f3G;^jP4;J#tlu!_I+2U%XR znfu>M)K*usCKUBcQ?eh{(@FnOB%H4&6QtF1cQ1jUQRP4w02^C%UYx(AiG5_7M_{_E^~!bLbVp>#4>9gbw}Q|Hqk1y<1S z==z!b2=3Nc_Oxn|JSo}l0GK8(5f8t0vKLKAZLSC%xu*9Oa^x+6K3eB@nsIy!j#IWA ztp}esg@rnrt^ReqfOn$_SZqXmxf#mgclxZq1nZ&a6 zJC>zRqqbX2$cbO5LU7+Ay_PkD3^M|z8igv7Sz~zDn^pLWJ{@~K%+*;ZiCQ(T)zi4B zl)trTv0Nh~y#J;T%EkR~r-=8@Zl;|QQOQu>`B6zRF$8)OgkN?RIy*U$meA;}xlN;2G4RhF_DsS3+x2T6Um{kFLH z=Z{;&_U?~_Tg7w}7cbKa;FjxfL&l(mgQ#K-)v|On?Wykh9+9>BJke7Y=qBF&-UyB# zS;G>AER$!&h-<->f9Ft#-K=v6A9J!&4%^S~%9j5B5uO+TQnLP-tfnX|_|3ZiaxTxk zfPFcYV`~@fdcE_Dv8)QepG|S~<}G@w#100lBM^S7;Bcj*Qep& zoRqoYU%bVWIO*oI#Nz*{SSMp7Yc4xdZw0x}T9C#{rut4Aq=Mb4I|jVTVmtMGHF>oc z;!kDchPxPd8a78`lB#Xg`uvImUE6H{NjE4^fLomCmLBYU2&4M>1=kgRKcJmHV#Foa?`@L#u(g=$4N;}ExdoqwUh*8 zn`YaT%0Uur=K9}C=4iID|Kzbv8kR;Uo*1+ZB}^)>3g-S~D3t$T-k0kd4a&{wP5rr$ z?qq)5plDy?CAy<|C9(6u&|58iWmPA};WI(wf7ez@OGMe#BweUdV>Rk|91gVaNzw~@ zag+T7aVdSCLT?FB6GI)hykRt^kfrJz6VsA7X6-|N2&tB|O_-)t|8hawn7q^(ZuS=r zflf`bCTkI-UiS~rrH0I^l_;SOkyJolp$D-flOi1HH!Ed)n8@k`TGfOGp>v#_sdnn? zTM15iMI(S(kkQS;={-ml7Wjjy2BMA;@mWeUB^p@fKDq#LuXC6r+PyU`zIiH3J=LruCNP)-R z-a@#e{Q;wy1xMY;Prf*98cO(a&1z6f9TjN4XX$$-)D7jNtqYFc)O{;=Olj2zxIp}J zipI6JmTplcMM5}+Z1py{9G!#py5G@09}OV=6L5dOtNzv^Fyr@crL|IZ4bhKon5Gz= zqz#o%s)LAXSj)HM4WeOhMz#E!jtco_J*gwLI0KLr8(n>o9sImuAy50s(yI8Ivd&0Lx(Vwpm4$J5^#AI(&ZwrgrcFnhhzNL5 zI;eD%CLNVt6%9?AfFQj}4OIlB2QR%TASLt`T0%!a2%&?tgf4{8Aryh{nLgdTE2cds-q}K}hfk`?#B$?pMZ7g;7OZ%=-~S6k zHQ2tpBDKG4V|@X66GR$T7N+eq_9RGCbN~K^1*`GP>UdYvXs@W&+S=(SM{U%Qrp+Ko zbt#^~zT6|axrEHbbWdXpVxkchTFlO)MM$iMRJ9IIxL>i}bL&)^ZF^T{>`(kZ?rf;9 zYbp3RW_wXKIT2n`wx)G@cJTY>eM`^}-VKR;c(;z}#AmmagH#2nI|o&VAyoI#Tq)^} zjPsO5J#OeFZLQfqLc6-W;xpB>46~G_kwJ`fUNbT|@WRT38l^e4;L3ZPXYUfw-1XyCv)m&_M^dL*c-vLU%V&gbUl9)!dE&*jEP>pzdVwz}7M-BxyVy~q zPSohA-hOkR!Uf7Lws33wbY->_^-x=&LNb)4ferP13=;lyV~A+@g*--ymI}UqeqL}z z(W}9bg?-)!XL?MT&zLiy0muG`PV9*4Z$bM7l2VL*qeJDhG6A(+liWQE;tBBv&)orfcqlfbL(v zp0U#yy`(HCMdNtQ5xp!-A)oR0F}UF`kXJ7IoZP!IeQ_?RU%(KxAgKZ2WGUJ9MAw3M50ET0d7{xpsK_-t|P z!;NzL%(n9~S;mQ8^)}nY1Oo-*7x@=2|8_N}J$m$1p0CLLML9@U@R1aU>QrAMS>?-k zcgbbkDciDG%esUJ8n`(7g6#(l?%nkMg1As(l%ee3nIn@+-A;UTRYv-a#- zM6v1jfFvE;&jP}OZ%RVS7#Dxi9{@-S0-n7mxZszsi`gY`S_H4fvC0Qa4?7x zryeCjdWH;{OR}74`)#^2IFNg7(G=s;D`Z@t8gotB6W+R4H^mD@e?G3DSsOXIA*=6 zHdT+!FLvZ+>JRX@;F()@KqQU^1L9zIJ>XL)WjS8yJOC`G+DZ7`GeKhVmS zBibmOLUl zQ2nv6N7(_M5DU3z8xuFgPHyzLsn~e1T;Z3h2PU50DSA&ynRy@#e@^O-o4(!>#aONK zPs7CG45I`E%f6Lwr|||UQ$RG}Kolc9J=g5DYaTi$vjKzEJN(pW;%JWw$!Q1|znaW- zr4wa=VE>tdy_l*G#CG_Y#Lu1piJB5Pg(><4EM7cGkN{sPa6i zKngY)RfRg~8+S6K)n975yOA|Ng6B|gQ8M(^<4V|17;_;wE$)4;XU^qbjVtpgsXsGT z1YN%pwcqowGbgP#d1-QHbs?hg&~x^9;g5L9nMk20+x%(S+IEoRy~v%3M|o*Q2U5Gy zw%G!%>*x=h$y`o%Y9sw_EQ{5&VG?>1eqP9hKF==ex`+j0B*`fxfllUSXj+=mnoW&D zsv$_B?lQbL$B^w}dYG1V6wH!T5)Rllo1vAd8mSmxDGt$F%At%au$dMg5S+=xow(?G zB(8fjRzV|B7UqM#mMX>#@*J8S9?T69%K)0m0OL71W`voCRF*r#Ke`c2!;Hy;In2HD zUklr~b74WsMw40kEgio%p=2b+$@(slF=ou8-}}Zc?!(;D?d-WQBy7mO%p>Pdqw3)$ zs}eW`^ZUBo`ht{N<^WH1b zqzmVrjpK|OkC5j`8L(gAIx6JG#>u3vxQDBobkMmD76s7#RD_FeHgB?qoa?d$dF38w zZSD;r9daH?Soj%%ggIf|romoOyeQ*Vt)UrRJAAbA+|7e)8s83e6lko%vMrc7ELt0B zzr3=)_y!c;C&MqYG#^<0wz2)<@8RdEG~jnJ<<|}l)wgh*@ohPZsQBsfuU4)J0LWTu zRB@I0+A}?#1xN5GP$oUaooCMRESnkoT=>DscJp{LobVp0A__l)E^v<6W`d&W9Btv0 z*UwwSMgwpb&E5m|nNq-a;m z?$4{L;btdo_1?6LO7Z_*lQo4M9H5(~vK%LX=HHSBPYz~wV$`=D2IjVX`km*zI#xaS z5;-TFp}*0|^QXxlK5(xUJK|#UbZIeDX((2ugakMXB=fO&mylntEDU|>K7t6mM=8(- zrxIh+3oXa2O2m_`0IzS*^fJXP4@h*P8mjZc3BoJkw0C6;Q~*jo>H`7=4-A8(v#N62 z5K}1agsb+SIUN_Y=7+A2p^be~F0rt#<`+je?rgb^loW)G`8Yw-FTX&7ALg7Gwe-(k z=Unhjfh3lN9>B4M`oW#+=esN_+<~p7ukB5y3B+2CcS=DZxc@d=evnt9q;yvBl)I}TxN@&8D{KRB-VZe<<&Ug<{Vz?I9N+Mq1aOpS3z%npN^GlMXX3NbI#J}7 zRhk=Ib(SMPD!H4YfyM^FvfV&*%`So`%Ng{V(gvoB8%oyQ{AfH#yo5tK6Bc3HRN@KP zp^b+?XLeWZr{?ZaOiQ*C$J;{!eZv!dzpQn0LG09X(0jeha-FVu9!YawT+@>M!a zP^jyAD{pT>Cu6wWoGxVE_i^mTWunTY&6FlVMYAcyI1jvRN~Yzw_j-rQ_>}HcWgMp5 zcr^ke9m*vU8H;S^s7rPYN~;a{{kYsjAxdSa;rP5ayOau{nWA zQqU8^;Q9jU)?8iEPfoN_h3XRsdZn+MQ%;lk5??x?H;EGva28SY+RU}kpBYI+<5h28 zvYjjHYx10(zD2jVwCc>^gp|Dh0!gYcxcfYsK(;kl_`*+=MAl&bQgImGES=>-RkcWy zc*(}?zloTQnH2lLdo=%MF=TJ(xdptAQI3sy2_nc`XSaq5Ej_6tP_$+I@U_qFo^_Y? z@z1cin*VfSj)?+lf`eI=#J9gN4PDp9OtV{b&Z7dw15jjD3h7qJUjkNIZ0Nr?n^>Eu zN@{a$fko6?AX`f=o9lPq3}NYo=!#g5Yqu{{!d3EXJH=TnK?AcXFl z*D6R7$QLOMT#m7!lO3-*ECIfu?vrt#-TE%F*x!CO)3Q(xJxo8hQ%u3$uPYY%?zsR_erX=0DQpzL z;|`(r1a?aI2Su}@3?$>1s8j1@mA3R#9-Q3eXVT%t7}v|pN@B(9TLM$%*8M&&Pj+-t zhtYJWZK()Kl7&!_4!2PKu#Iw-e*n#X>)1s2vdH4E=x}pYlXz0&W}&X-GwuD=N%MuW zT*g~0{5`5r%avd6#V$$J*D@20>$ViFLcYoE-P~*00ny46$59xP)PW9zBkCWPiW7Dh z9fUvAw|J+~pyjyJS&_Ty6-kR>{Gt(N8bri23B%9y)Le!oh#=H4W%+)Vs%LU+#u9jd zgODl$?`~y;(ZMidB>=tD27m47jKB{MeSf@d_sI79$UZDNS;4$jCNjJK3*q$i%55)? zrpaM%-2hlfbGbQyAmW6DoZIB%ynnc zDIKO*0s)~K&A<+G`9==fhqia&ruDWcjVX*lUjE~X=ZSoCG=G)oGNheD%VLpeSQD^U&X*cCRcM zn6)~%=QMNe-6uVsc8JyyoEV^iLd!c`tWI8mKnyJdncX98d34gbSDdkJ2mx>BzU_h7=+!}A z!D&^$<0}pm1ekX({`fw@3@b;jyGxa5!;zZ7*X5>Dyj>T82Q&$*hxAUv>WcW-HRKF! zZ%4#dz||Jx+3DvW{H9kz<4wR-AE)yY;WYnuk11s+9fQS;p)W zl-Y@zJy$k39pJUNutbP8wD8U(0leU0#bqf8<4^Pl=A>)QQGJr9+iSV?!4}AC#!TrHr2$ zrdR;O(b}xs{UQW!rMR&>++pyoz;%~i=qA-Jzj6{1r-f-5u}7JFB^>376z>cq3n{rk zG&T!eq0)ZXqi;u^9#x+4sZhea;2K5afCWYYJ>hb6;P`U=>-+l;ssQ*G(TVM47vIMv z&Gs}n@OV^~pPE0$Na;Oi9yAvBaqoOMI7Gpq&RaHQ?6T__+*|P!0 z?F6qT6>iD%Bj27l&!81$ScWmicwk5|?aF42N}+x+r1Lb+&}+Bwo`?`KI7K#e&X+=j zo(->zk>+yh#6=gM8Dm2LwbV#A$;%D-ZuPj8Wl6>o)U*}(6#5aWTr{SiGNjoN#1#*g z#u#AOdBOhD(6?!FrMENbk0t@?J3KZp)I1Cg9Xsc5kn<-PBJvd}p2zM`JXER$$u;mZ z;WZbSec(?~K~lrMS6D@8Wd}6LO3?!UG5Y-}nZnQJ4w@DeBp~ka%^ZP`l(vBQDO1sV z;7@fICC~6gD;8_j180A=bZPqQaW2X5)O8+tf*N;eYGi^3XL7obJ_>IqE3ycO{kOxT zDcM!-m$y?4tB(b=CSevRP6Y>&a|Rtp788|kr?^D%GSD~%koC>n++Wg~@QjP^(h4Ws z#})Aj8t;b`~GN+!E>31#tAO% zLwuZ?&TK4$dYya2Ai%$s8w+W users/$CLIENTNAME.ovpn + + file="users/$CLIENTNAME.ovpn" + + ps='remote ' + pi="remote $IP $P udp" + grep -q "^$ps" $file && sed -i "s/^$ps.*/$pi/" $file || sed -i "5a $pi" $file + + ps='comp-lzo' + pi='comp-lzo no' + grep -q "^$ps" $file && sed -i "s/^$ps.*/$pi/" $file || sed -i "6a $pi" $file + + ps='resolv-retry' + pi='resolv-retry infinite' + grep -q "^$ps" $file && sed -i "s/^$ps.*/$pi/" $file || sed -i "7a $pi" $file + ps='persist-key' + pi='persist-key' + grep -q "^$ps" $file && sed -i "s/^$ps.*/$pi/" $file || sed -i "8a $pi" $file + + ps='persist-tun' + pi='persist-tun' + grep -q "^$ps" $file && sed -i "s/^$ps.*/$pi/" $file || sed -i "9a $pi" $file + + ps='keepalive' + pi='keepalive 15 60' + grep -q "^$ps" $file && sed -i "s/^$ps.*/$pi/" $file || sed -i "10a $pi" $file + + + +else + echo "no clientname" +fi +---- + + +== rm vpn user + +.rm-user.sh +[source,bash] +---- +#!/bin/bash +. ./config + +CLIENTNAME=$1 +U=$CLIENTNAME + +if [ $# -eq 1 ]; then + sudo rm -f $vpn_data/pki/reqs/$CLIENTNAME.req + sudo rm -f $vpn_data/pki/private/$CLIENTNAME.key + sudo rm -f $vpn_data/pki/issued/$CLIENTNAME.crt + sudo rm -f $vpn_data/server/ccd/$CLIENTNAME + sudo rm -f $vpn_data/ccd/$CLIENTNAME + pem=$(sudo grep "CN=$U$" $vpn_data/pki/index.txt | cut -f4) + #/var/lab/gswarm/vpn-data/pki/certs_by_serial/BACA61827E65D0E5F695245519410952.pem + sudo rm -f $vpn_data/pki/certs_by_serial/$pem.pem + sudo sed -i "/CN=$U$/d" $vpn_data/pki/index.txt + echo $pem + docker run -v $vpn_data:/etc/openvpn --log-driver=none --rm -it $docker ovpn_revokeclient $CLIENTNAME remove + + + sudo rm -f $vpn_data_user_config/$CLIENTNAME.ovpn + sudo rm -f $vpn_data_user_config1/$CLIENTNAME.ovpn +else + echo "no client" +fi + +---- + +== show all vpn users + +.show-user.sh +[source,bash] +---- +. ./config + +docker exec -it $NAME ovpn_listclients +---- + +== show all connected vpn users + +.show-conn-user.sh +[source,bash] +---- +. ./config + +docker exec -it $NAME cat /tmp/openvpn-status.log +---- + + + + + +:hardbreaks: + +{empty} + +{empty} + +{empty} + +:!hardbreaks: + +''' + +.Reminder +[NOTE] +==== +:hardbreaks: +Caminante, no hay camino, +se hace camino al andar. + +Wanderer, there is no path, +the path is made by walking. + +*Antonio Machado* Campos de Castilla +====