/etc/openvpn/ipv6tunnel.conf
s obsahem:duplicate-cn
multihome
mode server
tls-server
persist-key
persist-tun
dev tapvpnserver
port 1194
proto udp
; soubory s certifikáty a klíčem (vygenerovat pomocí easy-rsa)
ca /vpn/ca/keys/ca.crt
cert /vpn/ca/keys/server.crt
key /vpn/ca/keys/server.key
dh /vpn/ca/keys/dh2048.pem
; skript spusteny po nastartovani (skript vytvořit)
script-security 2
up /vpn/up.sh
/etc/openvpn/ipv6tunnel.conf
s obsahem:client
;jméno serveru
remote VASE-IPV4-ADRESA-SERVERU-S-VPN 1194
dev tapipv6tunnel
dev-type tap
proto udp
nobind
persist-key
ns-cert-type server
; skript spusteny po nastartovani (skript vytvořit)
script-security 2
up /vpn/up.sh
<ca>
-----BEGIN CERTIFICATE-----
.....
-----END CERTIFICATE-----
</ca>
<cert>
-----BEGIN CERTIFICATE-----
.....
-----END CERTIFICATE-----
</cert>
<key>
-----BEGIN CERTIFICATE-----
.....
-----END CERTIFICATE-----
</key>
<ca>
-----BEGIN CERTIFICATE-----
.....
-----END CERTIFICATE-----
</ca>
up.sh
skriptů na serveru a na klientu./vpn/up.sh
s obsahem:ip link set tapvpnserver up
ip a a fe80::1/64 dev tapvpnserver
ip -6 route add VAS:IPV6:PREFIX::/64 via fe80::2 dev tapvpnserver
/vpn/up.sh
s obsahem:ip link set tapipv6tunnel up
ip a a fe80::2/64 dev tapipv6tunnel
ip -6 route add default via fe80::1 dev tapipv6tunnel
ip -6 a a VAS:IPV6:PREFIX::2/64 dev tapipv6tunnel
ping6 nix.cz
ip -6 a d VAS:IPV6:PREFIX::2/64 dev tapipv6tunnel
.radvd
.interface br-local
{
AdvSendAdvert on;
prefix VAS:IPV6:PREFIX::/64
{
};
};
ip -6 a a VAS:IPV6:PREFIX::2/64 dev br-local
echo 1 > /proc/sys/net/ipv6/conf/all/forwarding
/etc/sysctl.conf
net.ipv6.conf.all.forwarding=1