This commit is contained in:
Vasco
2026-04-21 20:19:25 +01:00
parent d662860af4
commit 936cbd530a

View File

@@ -35,11 +35,11 @@ sysctl -p /etc/sysctl.conf
# --- nat forwardin de vpn para clientes --- #
# ?????????????????????????????????????????????????????????????????????
iptables -I INPUT -i tun0 -j ACCEPT
iptables -I OUTPUT -o tun0 -j ACCEPT
echo 0 > /proc/sys/net/ipv4/conf/all/rp_filter
echo 0 > /proc/sys/net/ipv4/conf/tun0/rp_filter
echo 0 > /proc/sys/net/ipv4/conf/default/rp_filter
# iptables -I INPUT -i tun0 -j ACCEPT
# iptables -I OUTPUT -o tun0 -j ACCEPT
# echo 0 > /proc/sys/net/ipv4/conf/all/rp_filter
# echo 0 > /proc/sys/net/ipv4/conf/tun0/rp_filter
# echo 0 > /proc/sys/net/ipv4/conf/default/rp_filter
iptables -A INPUT -p udp --dport 1194 -j ACCEPT # :O
iptables -A FORWARD -i $mega_tunel -o $if_dentro -j ACCEPT # :P
@@ -56,8 +56,6 @@ cp ca/ca.crt $vpn_dir
cp ca/vpn.key $vpn_dir
cp ca/vpn.crt $vpn_dir
cp vpn.conf $vpn_dir
openvpn --config "${vpn_dir}/vpn.conf"
# NOTA(vasco): o ficheiro conf vai ser vpn.conf pq isso é o nome do serviço
# o serviço nao funciona ????
# systemctl enable --now openvpn-server@vpn.service
# correr serviço
systemctl enable --now openvpn-server@vpn.service