services:openvpn
Differences
This shows you the differences between two versions of the page.
| Both sides previous revisionPrevious revisionNext revision | Previous revision | ||
| services:openvpn [2016/03/23 16:45] – dgalloway | services:openvpn [2020/10/27 19:22] (current) – old revision restored (2020/10/27 17:55) djgalloway | ||
|---|---|---|---|
| Line 1: | Line 1: | ||
| - | ====== | + | ====== OpenVPN ====== |
| ===== Summary ===== | ===== Summary ===== | ||
| - | Users access the sepia lab by tunnelling through an [[https:// | + | Users access the sepia lab by tunnelling through an [[https:// |
| + | |||
| + | Managed by Ansible using the gateway role in [[https://github.com/ceph/ | ||
| The process for requesting lab access is documented [[https:// | The process for requesting lab access is documented [[https:// | ||
| - | ===== Adding Users ===== | + | ===== Ops Tasks ===== |
| + | ==== Adding Users ==== | ||
| + | A ticket should be filed for paper trail purposes. | ||
| To grant a new user access to the VPN, | To grant a new user access to the VPN, | ||
| - Add the user's public key to the [[https:// | - Add the user's public key to the [[https:// | ||
| - | - Add their username and hashed password | + | - Add their credentials |
| - | - Once your PR has been merged, run the [[https:// | + | - If they **only** need VPN access, add them to '' |
| + | - Otherwise, add their username ('' | ||
| + | - Once your PR has been merged, run the [[https:// | ||
| < | < | ||
| + | |||
| + | ==== fail2ban ==== | ||
| + | fail2ban is configured via the gateway role. It's configured to work with firewalld. | ||
| + | |||
| + | An additional filter is in place in ''/ | ||
| + | |||
| + | < | ||
| + | ^%(__prefix_line)sReceived disconnect from < | ||
| + | </ | ||
| + | |||
| + | ==== Updating sepia-vpn-client.tar.gz ==== | ||
| + | This shouldn' | ||
| + | |||
| + | - '' | ||
| + | - '' | ||
| + | - '' | ||
| + | - '' | ||
| + | - Make your edits in the sepia dir | ||
| + | - When you're done, '' | ||
| + | - '' | ||
| + | - '' | ||
| + | - '' | ||
| + | |||
| + | ===== Troubleshooting ===== | ||
| + | ==== ValueError: need more than 2 values to unpack ==== | ||
| + | |||
| + | **Resolution: | ||
| + | |||
| + | ===== To-Do ===== | ||
| + | ==== DNS ==== | ||
| + | In order to stop serving our private DNS records, we're going to need an OS-agnostic script (shipped with the client archive) that will add the internal DNS server to OpenVPN clients' | ||
| ===== Historical Info ===== | ===== Historical Info ===== | ||
| - | Detailed information on our particular setup (how auth works and such) can be found in the old [[https:// | + | Detailed information on our particular setup (how auth works and such) can be found in the old [[https:// |
services/openvpn.1458751532.txt.gz · Last modified: by dgalloway
