使用docker快速部署IPsec VPN 服务器
1,快速部署
使用如下命令快速创建 VPN 服务 server 端:
docker run --name ipsec-vpn-server --env-file /data/jump/vpn/.env --restart=always -p 500:500/udp -p 4500:4500/udp -v /lib/modules:/lib/modules:ro -d --privileged registry.cn-hangzhou.aliyuncs.com/eryajf/ipsec-vpn-server
其中用户名密码配置文件内容为:
$ cat /data/jump/vpn/.env
# Define your own values for these variables
# - DO NOT put "" or '' around values, or add space around =
# - DO NOT use these special characters within values: \ " '
VPN_IPSEC_PSK=6JhixxWU0u9REqATiFrEAG0
# 配置用于登陆VPN的账号和密码
VPN_USER=admin
VPN_PASSWORD=9s0RrJX4qEoQG7L32s9I
# 如下应该填写本机的外网IP
VPN_PUBLIC_IP=10.10.0.2
# (Optional) Define additional VPN users
# - Uncomment and replace with your own values
# - Usernames and passwords must be separated by spaces
# 配置额外的用户名和密码
VPN_ADDL_USERS=user1 user2
VPN_ADDL_PASSWORDS=pass1 pass2
# (Optional) Use alternative DNS servers
# - By default, clients are set to use Google Public DNS
# - Example below shows using Cloudflare's DNS service
VPN_DNS_SRV1=223.5.5.5
VPN_DNS_SRV2=223.6.6.6
一个用户名对应一个密码,如果需要新增, 更改配置文件,重启服务即可。注意服务器需要有外网 IP,以及放开对应端口。
查看 IPsec VPN 服务器状态
docker exec -it ipsec-vpn-server ipsec status
查看当前已建立的 VPN 连接
docker exec -it ipsec-vpn-server ipsec whack --trafficstatus
2. 客户端连接
参考配置 IPsec/L2TP VPN 客户端