/VPN.md (f1c8658a62d5be3c1726843db101a54df9c52f47) (1989 bytes) (mode 100644) (type blob)
## How to make a point-to-point VPN
Socat is a powerful tool which can work together with Tuntox.
On the server (where tuntox is already running):
socat -d -d 'TCP-LISTEN:9876' 'TUN:10.20.30.41/24,up'
On the client:
socat -d -d TUN:10.20.30.40/24,up 'SYSTEM:./tuntox -W 127.0.0.1@9876 -i 86e70ffe9f835b12667d296f2df9c307ba1aff06'
Viola, you have a point-to-point VPN. On client:
# ping 10.20.30.41
PING 10.20.30.41 (10.20.30.41) 56(84) bytes of data.
64 bytes from 10.20.30.41: icmp_seq=1 ttl=64 time=138 ms
64 bytes from 10.20.30.41: icmp_seq=2 ttl=64 time=169 ms
64 bytes from 10.20.30.41: icmp_seq=3 ttl=64 time=130 ms
64 bytes from 10.20.30.41: icmp_seq=4 ttl=64 time=90.8 ms
64 bytes from 10.20.30.41: icmp_seq=5 ttl=64 time=50.7 ms
## Full madness mode: tunnelling VPN over SSH over Tox
No need to log in run and run socat on the server.
Also: inefficient, insecure (requires PermitRootLogin yes on server).
On the client:
socat -d -d TUN:10.20.30.40/24,up 'SYSTEM:ssh root@localhost -o ProxyCommand=\"./tuntox -W "127.0.0.1:22" -d -i 86e70ffe9f835b12667d296f2df9c307ba1aff06\" socat -d -d - "TUN:10.20.30.41/24,up"'
# ping 10.20.30.41
PING 10.20.30.41 (10.20.30.41) 56(84) bytes of data.
64 bytes from 10.20.30.41: icmp_seq=1 ttl=64 time=50.6 ms
64 bytes from 10.20.30.41: icmp_seq=2 ttl=64 time=81.2 ms
64 bytes from 10.20.30.41: icmp_seq=3 ttl=64 time=50.3 ms
64 bytes from 10.20.30.41: icmp_seq=4 ttl=64 time=151 ms
64 bytes from 10.20.30.41: icmp_seq=5 ttl=64 time=50.3 ms
Based on [Ben Martin's article](https://web.archive.org/web/20160102211752/http://www.linux.com/news/software/developer/17942-socat-the-general-bidirectional-pipe-handler)
I've also heard about a new program called [ToxVPN](https://github.com/cleverca22/toxvpn), who knows - maybe it does a better job? And more recently someone created [toxtun](http://toxtun.jschwab.org/), slowclap.gif for the creative choice of name.
Mode |
Type |
Size |
Ref |
File |
100644 |
blob |
268 |
272c4eb3ad3672621962ce38f8c7472336729ec3 |
.gitignore |
100644 |
blob |
0 |
e69de29bb2d1d6434b8b29ae775ad8c2e48c5391 |
.sonarcloud.properties |
100644 |
blob |
2088 |
300c5a7e37f67cb8cdd88261756a10be561d51c5 |
.travis.yml |
100644 |
blob |
1934 |
9b63571486cca0d558fb18d7826e84f8983217de |
BUILD.md |
100644 |
blob |
4310 |
0d9bbb5e54e44c9cf3e2e824c3aa4f98e3a10660 |
FAQ.md |
100644 |
blob |
35058 |
2061be2b732ea86101a7c0d5f4df0bbbfb830a30 |
LICENSE.md |
100644 |
blob |
1258 |
808d57cc1b8ef4944a50798b8242f7587684983c |
Makefile |
100644 |
blob |
637 |
ee41cdaf376b4cb8eca51751b170e4c698167dda |
Makefile.mac |
100644 |
blob |
6215 |
b1c263d3db0d2728247d8fea652550653f6c6d1e |
README.md |
100644 |
blob |
1989 |
f1c8658a62d5be3c1726843db101a54df9c52f47 |
VPN.md |
100644 |
blob |
926 |
2c925ef05cf1a3edc1fb125d2f28a647982ef7e1 |
bitbucket-pipelines.yml |
100644 |
blob |
22776 |
3073e5d2a576980632303cf32fb9e568afea3375 |
client.c |
100644 |
blob |
759 |
be68f25ae57282e30acf01fd0eb619763045dc1e |
client.h |
040000 |
tree |
- |
2aa3072e8a8745616761031d04cf49836e23d0a8 |
debian |
100644 |
blob |
3389 |
3198cd41259d1954f69283b4e13ce279b4e04c46 |
generate_tox_bootstrap.py |
100644 |
blob |
265 |
8d1bb5fd5867d5068c9b04dc7456bdd4d42a86bf |
gitversion.c |
100644 |
blob |
62 |
fdb8a74df5ce4cf71d6b01d51400e763ddc9428b |
gitversion.h |
100644 |
blob |
3141 |
31244349cd221b4e8931f612b3325ae59faa58cb |
log.c |
100644 |
blob |
892 |
bcd4c9bb1af0a1f1c44b1e7a36c3a5971ba73b34 |
log.h |
100644 |
blob |
549 |
a9095f6b9cc0f97ddc698e07a4606b37822ba61c |
mach.c |
100644 |
blob |
287 |
5ac9a4e29fbb831ba2cfa6dc98589ffaf381b91b |
mach.h |
100644 |
blob |
47324 |
ed2020e40f2533421145fa89166ae9478184c804 |
main.c |
100644 |
blob |
3432 |
17fb9b9b2ec49ec1db69f89b4823d3d732c9b3d8 |
main.h |
040000 |
tree |
- |
9ea39ebb6fd8fb34f1a28a69d445d099d5001a37 |
screenshots |
040000 |
tree |
- |
c9901ad488b9ebc1c2ac4c1e4d8b181f3db48133 |
scripts |
100644 |
blob |
16457 |
368f84e6bd32a2eb99a3cef9c9f17bbe63bf358e |
tox_bootstrap.h |
100644 |
blob |
12536 |
75e9dc5ed9399120416e8da5f24d1ccde41cf901 |
utarray.h |
100644 |
blob |
61492 |
7205c67efa27c66884c8d4d1c8a105d4854a0548 |
uthash.h |
100644 |
blob |
4098 |
3e6a99c0eef2222c99c450bca028ef9b4f0f31ba |
util.c |
100644 |
blob |
638 |
7dced6b423b39797c2589660864ea61cc34d5416 |
util.h |
100644 |
blob |
55882 |
b5f3f04c104785a57d8280c37c1b19b36068e56e |
utlist.h |
100644 |
blob |
11555 |
867442c843dbe6bf096a488e3ce9ec6323809f7f |
utstring.h |
Hints:
Before first commit, do not forget to setup your git environment:
git config --global user.name "your_name_here"
git config --global user.email "your@email_here"
Clone this repository using HTTP(S):
git clone https://rocketgit.com/user/gdr/tuntox
Clone this repository using ssh (do not forget to upload a key first):
git clone ssh://rocketgit@ssh.rocketgit.com/user/gdr/tuntox
Clone this repository using git:
git clone git://git.rocketgit.com/user/gdr/tuntox
You are allowed to anonymously push to this repository.
This means that your pushed commits will automatically be transformed into a
merge request:
... clone the repository ...
... make some changes and some commits ...
git push origin main