WIP: openvpn
This commit is contained in:
7
services/openvpn/config/openvpn.conf
Normal file
7
services/openvpn/config/openvpn.conf
Normal file
@@ -0,0 +1,7 @@
|
||||
port 1194
|
||||
proto udp
|
||||
dev tun
|
||||
|
||||
topology subnet
|
||||
|
||||
# TODO
|
||||
11
services/openvpn/install.sh
Normal file
11
services/openvpn/install.sh
Normal file
@@ -0,0 +1,11 @@
|
||||
#!/bin/sh
|
||||
echo "Setting up OpenVPN..."
|
||||
apk add openvpn
|
||||
|
||||
rc-update add openvpn
|
||||
modprobe tun
|
||||
echo tun >> /etc/modules-load.d/tun.conf
|
||||
|
||||
# Enable IP forwarding, persistent
|
||||
echo "net.ipv4.ip_forward=1" >> /etc/sysctl.d/ip_forward.conf
|
||||
sysctl -p /etc/sysctl.d/ip_forward.conf
|
||||
14
services/openvpn/openvpn.policy.json
Normal file
14
services/openvpn/openvpn.policy.json
Normal file
@@ -0,0 +1,14 @@
|
||||
{
|
||||
"description": "Allow OpenVPN server access from the internet",
|
||||
"service": {
|
||||
"openvpn": { "port": 1194, "proto": "udp" }
|
||||
},
|
||||
"filter": [
|
||||
{
|
||||
"in": "WAN",
|
||||
"out": "_fw",
|
||||
"service": "openvpn",
|
||||
"action": "accept"
|
||||
}
|
||||
]
|
||||
}
|
||||
2
services/openvpn/update.sh
Normal file
2
services/openvpn/update.sh
Normal file
@@ -0,0 +1,2 @@
|
||||
#!/bin/sh
|
||||
ln -sf ./config/openvpn.conf /etc/openvpn/openvpn.conf
|
||||
Reference in New Issue
Block a user