VPN 設定 DHCP

  1. DHCPSET 設定 DHCP 參數,gateway 及 dns 不要設定,只做 192.168.1.0/24 綱段的互連。
    VPN Server/vpn>dhcpset /start:192.168.1.10 /end:192.168.1.19 /mask:255.255.255.0 \
    /expire:1000 /gw /dns /dns2 /DOMAIN /log:yes
    DhcpSet command - Change Virtual DHCP Server Function Setting of SecureNAT Function
    The command completed successfully.
    
  2. 設定都存於 /usr/local/vpnserver/vpn_server.config,也可以先關閉 vpnserver,直接編輯此檔後再啟動一樣可以更改設定。
    [root@dyw219 ~]# vim /usr/local/vpnserver/vpn_server.config
    [root@dyw219 ~]# grep 'declare SecureNAT' -A30 -m1 /usr/local/vpnserver/vpn_server.config
    			declare SecureNAT
    			{
    				bool Disabled true
    				bool SaveLog true
    
    				declare VirtualDhcpServer
    				{
    					string DhcpDnsServerAddress 192.168.1.1
    					string DhcpDnsServerAddress2 0.0.0.0
    					string DhcpDomainName $
    					bool DhcpEnabled true
    					uint DhcpExpireTimeSpan 7200
    					string DhcpGatewayAddress 192.168.1.1
    					string DhcpLeaseIPEnd 192.168.1.20
    					string DhcpLeaseIPStart 192.168.1.10
    					string DhcpPushRoutes $
    					string DhcpSubnetMask 255.255.255.0
    				}
    				declare VirtualHost
    				{
    					string VirtualHostIp 192.168.1.1
    					string VirtualHostIpSubnetMask 255.255.255.0
    					string VirtualHostMacAddress 00-AC-43-22-56-80
    				}
    				declare VirtualRouter
    				{
    					bool NatEnabled true
    					uint NatMtu 1500
    					uint NatTcpTimeout 1800
    					uint NatUdpTimeout 60
    				}