(Turn) very practical network technology solutions

 It would have a direct look at the original post  http://blog.chinaunix.net/uid-15790905-id-5169813.html

 


Inscription:
In large companies, there would have eggs egg; in a small company, you have to eat the eggs to raise a chicken. .
Originally, I just want to become a domain name within the system within the domain name, after all, to monitor the deployment of the system as well as in the control unit address exposed to the public network do not always feel at ease.
But the question is, Excavator ... wrong at home, how to access Ali cloud network address? Ah, you can use VPN, VPN but absolutely not sounded ah, I guess I was spoiled before the factory. .

our company Status:
1. Ali online server hosted on the cloud
2. office network, some machines, providing svn, compilation and other services
3. on the office network from home can not, like to mention a few lines of code, sorry, go to the company bar
4 at home / in the company can access the intranet Ali cloud (10.xxx) addresses directly, we are public addresses, embarrassed

sort and refine my needs:

1. vpn connection at home can access the office network (172 segments)
2. home / vpn connection in the company can access the network directly Ali cloud service and machinery (10 segments)
3. To access the office network and Ali cloud need to connect two LANs address only once vpn
4. vpn login with a username and password

design:
need to connect two vpn (a network office, Ali cloud a) the direct program fail, do not engage in less complex.
Hope is this, YY diagram below,


technology selection: openvpn
core technologies: virtual network card, tunnels, iptables, ssl

Additional information: 
the whole scheme effective pro-test, groping for a long time, a variety of Chinese and English searches. So your model should look like this
while (not handle) { 
   SLEEP; 
   retry; 
   IF (get?) {
       BREAK;
   }
}

from the beginning a clear need to achieve a step by step, are summarized as follows, in fact, is quite logical.

Guess you like

Origin www.cnblogs.com/xiaoxuebiye/p/11416588.html