Before you start the ssh daemon in Point-to-Point mode, you need to prepare a tun device for each server in advance. This can be done in two ways:
- Command ip tuntap:
ip tuntap add dev tun0 mode tun
- Keep your devices ready by adding a device to / etc / systemd / network / netdev:
[NetDev] Name=tun0 Kind=tun #Разрешить доступ пользователям входящим в группу vpn [Tun] Group=vpn
[NetDev] Name=tun0 Kind=tun #Разрешить доступ пользователям входящим в группу vpn [Tun] Group=vpn
And network file:
[Match] Name=tun0 [Address] Address=172.17.0.1/30 Peer=172.17.0.2/30 [Network] Address=172.17.0.1/30 [Route] Gateway=172.17.0.1 Destination=192.168.1.0/24
[Match] Name=tun0 [Address] Address=172.17.0.1/30 Peer=172.17.0.2/30 [Network] Address=172.17.0.1/30 [Route] Gateway=172.17.0.1 Destination=192.168.1.0/24
The second option is preferable because:
- firewall will know about the presence of such devices
- An unmovable user can open the tunnel
- You can set up routes in advance, and not register them every time you want to connect
Guide to raising a tunnel by unmovable users