You are on page 1of 20

IPCOP ( )

http://www.ipcop.org
: http://www.itwizard.info/technology/linux/ipcop/install_ipcop.html
http://ball.narucha.com/setupIP-COP.html
http://www.itcompanion.co.th/Contents/IPCOP/IPCOP(Installing).html
http://www.linuxthai.org/index_linuxthai.html
http://www.itwizard.info/technology/linux/OpenVPN/OpenVPN_IPCop_host_to_net.html

16 .. 2551
IPCop



Linux
Kernel 2.4.x

GNU





IPCop
o HTTP 81 SSL
445

o IP Table
o
o

o
o
o
o
o
o
o


Squid Proxy
Snort IDS
Traffic Shaping
High
Medium Low
DHCP DHCP
IP address
Proxy,
System Log
Firewall, IDS/IPS
Cron Server

NTP Server
Certification Authority VPN Server

Linux

IPCop 6
Green

Red

Orange

Blue

Black

Magenta

Internal

Internet

DMZ

Wireless

Local

VPN


Green Red WAN (ADSL, Modem)
Network Card


Network Card

3
Green, Orange, Red

IPCop

IPcop VMware Green, Orange, Red

1. Boot
Enter

2. English Enter

3. Enter

4. CDROM HTTP/FTP HTTP/FTP




CDROM Enter

5. IPCop

IDE 1 Enter

6. Restore config ipcop Spacebar Skip OK

7. Lan Green Probe Scan

8. Detected Enter

9.
Green IP address Subnet mask
Enter

10. Fdisk /mbr


http://IPCop:81 https://IPCop:445 dial admin



IPCop OK

11.

, Keyboard US Enter

12. Timezone Asia/Bangkok Enter

Enter
13.

Enter
14.

15. ISDN Disable ISDN Enter

16. Network Green (RED is modem/ISDN) Network configuration


type Enter

17.

Green + Orange + Red Enter

18. Drivers and card assignments Enter

19.
Enter

20. Orange Enter Red Enter

21. Enter

22. Address settings OK

23.



Orange IP Green

24. IP address Subnet mask (Orange) OK

25. Red Enter IP Subnet Mask

Red
IP address DHCP Static PPPOE PPTP
manual IP Subnet mask
Set static ip: 192.168.200.218 OK
26. DNS and Gateway settings OK

27. Set IP gateway DNS IPCop (Gateway=IP router) OK

28. Done Enter

29. DHCP
Enable IP address


DNS OK

30. root password, Again OK

31. admin password, Again OK

32. backup backup password, Again OK

33. IPCop OK

IPCop

config
Web IE http://IPIPCop:81 https://IPIPCop:445
User admin password
31

Addons IPCop (
http://www.ipcop.org/index.php?module=pnWikka&tag=IPCopAddons)

External Access
https ssh Remote

IP Red (IP : 192.168.200.218 port 445)

Remote Putty Telnet Port 222

Remote WinSCP Port 222 Upload ( File


server) http://winscp.net

Advanced Proxy add-on






Proxy Server

Advanced Proxy http://www.advproxy.net

Client Advanced Proxy


IPCop
WinSCP /tmp
PuTTy
root@ipcop:/tmp # tar -xvzf ipcop-advproxy-2.1.9.tar.gz
root@ipcop:/tmp # cd ipcop-advproxy
root@ipcop:/tmp # ./install
Proxy Advanced

IPCop web GUI



Proxy

Copfilter add-on
Download copfilter http://www.copfilter.org/

copfilter-0.84beta3a
/tmp



- Service

Copfilter add-on

URL Filter
- Blacklist squidGuard
-
Categories hardcored
- schedule Blacklist
- constraints client time category
- commercial

URL Filter http://www.urlfilter.net/download.html


/tmp WinSCP


root@ipcop:/tmp # tar -xvzf ipcop-urlfilter-1.9.3.tar.tar
root@ipcop:/tmp # cd ipcop-urlfilter
root@ipcop:/tmp/ipcop-urlfilter # ./install

VPN

VPN

VPN


VPN Gateway

IPCop
IPCop

Cryptographic



VPN


(NAT)

IPCop

Green Encapsulate

OpenVPN Host-to-Net IPCop


: http://www.itwizard.info/technology/linux/OpenVPN/OpenVPN_IPCop_host_to_net.html
OpenVPN IPCop
1. Host-to-Net Virtual Private Network (RoadWarrior)
2. Net-to-Net Virtual Private Network

ZERINA OpenVPN addon addon IPCop VPN
Client OpenVPN GUI for Windows

OpenVPN IPCop Host-to-Net Virtual Private Network (RoadWarrior)

1. Enable ssh access


IPCop

2. ZERINA OpenVPN addon


ZERINA OpenVPN addon http://www.zerina.de/zerina/?q=download
ZERINA-0.9.4d-Installer.tar.tar
PC
IPCop
/tmp WinSCP


root@ipcop:/tmp # tar -xvzf ZERINA-0.9.5b-Installer.tar.gz
root@ipcop:/tmp # ./install
3. Configuration file





IPCop VPNs --> OpenVPN
Global settings

Advanced Server
options Save Advanced options

4. VPN

Global settings Save :
- Local VPN Hostname/IP Public IP IPCop
- OpenVPN Subnet : OpenVPN extra virtual subnet subnet

IPCop Client side
10.0.0.0/24 IP

Remote user (VPN Client)


connect
Remote IP
Green Interface
Green Interface

Certificate Authorities Generate Root/Host Certificates

PKCS12

Certificate
Generate Root/Host Certificates

Client Certificate

Add Client status and control

Host-to-Net Add

Save


(Download Client Package (zip))

VPN Client

config VPN Client

Start OpenVPN Start OpenVPN Server Current OpenVPN Server Status


RUNNING

5. OpenVPN GUI for Windows (VPN Client)


http://openvpn.se/
6. (unzip) client package

C:\Program
Files\OpenVPN\config
VPN Client VPN Server
7.

Connect

8.
( PKCS12 File password)
connect
icon VPN Client taskbar

VPN Server
9.
ipconfig
VPN Client

VPN IP

IP 10.0.0.6/255.255.255.252

VPN

10. ping

You might also like