Ocserv
Ocserv
Ocserv
/usr/bin/env bash
PATH=/bin:/sbin:/usr/bin:/usr/sbin:/usr/local/bin:/usr/local/sbin:~/bin
export PATH
#=================================================
# System Required: Debian/Ubuntu
# Description: ocserv AnyConnect
# Version: 1.0.5
# Author: Toyo
# Blog: https://doub.io/vpnzy-7/
#=================================================
sh_ver="1.0.5"
file="/usr/local/sbin/ocserv"
conf_file="/etc/ocserv"
conf="/etc/ocserv/ocserv.conf"
passwd_file="/etc/ocserv/ocpasswd"
log_file="/tmp/ocserv.log"
ocserv_ver="0.11.8"
PID_FILE="/var/run/ocserv.pid"
CONFIG_DIR_OCSEREV="/etc/ocserv"
check_root(){
[[ $EUID != 0 ]] && echo -e "${Error} 当前非 ROOT 账号(或没有 ROOT 权限),无法继续操作,请更换 ROOT 账号
或使用 ${Green_background_prefix}sudo su${Font_color_suffix} 命令获取临时 ROOT 权限(执行后可能会提示输入当
前账号的密码)。" && exit 1
}
#检查系统
check_sys(){
if [[ -f /etc/redhat-release ]]; then
release="centos"
elif cat /etc/issue | grep -q -E -i "debian"; then
release="debian"
elif cat /etc/issue | grep -q -E -i "ubuntu"; then
release="ubuntu"
elif cat /etc/issue | grep -q -E -i "centos|red hat|redhat"; then
release="centos"
elif cat /proc/version | grep -q -E -i "debian"; then
release="debian"
elif cat /proc/version | grep -q -E -i "ubuntu"; then
release="ubuntu"
elif cat /proc/version | grep -q -E -i "centos|red hat|redhat"; then
release="centos"
fi
#bit=`uname -m`
}
check_installed_status(){
[[ ! -e ${file} ]] && echo -e "${Error} ocserv 没有安装,请检查 !" && exit 1
[[ ! -e ${conf} ]] && echo -e "${Error} ocserv 配置文件不存在,请检查 !" && [[ $1 !=
"un" ]] && exit 1
}
check_pid(){
if [[ ! -e ${PID_FILE} ]]; then
PID=""
else
PID=$(cat ${PID_FILE})
fi
}
Get_ip(){
ip=$(wget -qO- -t1 -T2 ipinfo.io/ip)
if [[ -z "${ip}" ]]; then
ip=$(wget -qO- -t1 -T2 api.ip.sb/ip)
if [[ -z "${ip}" ]]; then
ip=$(wget -qO- -t1 -T2 members.3322.org/dyndns/getip)
if [[ -z "${ip}" ]]; then
ip="VPS_IP"
fi
fi
fi
}
# ---------添加代码 BEGIN----------------
install_content() {
local _install_flags="$1"
local _content="$2"
local _destination="$3"
local _tmpfile="$(mktemp)"
rm -f "$_tmpfile"
}
# ---------添加代码 BEGIN----------------
tcp_anyconnect_ec_config(){
#auth = "plain[passwd=/etc/ocserv/ocpasswd]"
# listen-host = [IP|HOSTNAME]
auth = "certificate"
cert-user-oid = 2.5.4.3
tcp-port = $PORT_OCSERV
run-as-user = nobody
run-as-group = daemon
socket-file = /var/run/ocserv-socket
# ecc certicate
# -----BEGIN CERTIFICATE-----
server-cert = /etc/ocserv/ssl/server-cert.pem
server-key = /etc/ocserv/ssl/server-key.pem
ca-cert = /etc/ocserv/ssl/ca-cert.pem
# -----END CERTIFICATE-----
isolate-workers = true
banner = "欢迎使用铂金 2 代 VPN 技术"
max-clients = 10
max-same-clients = 10
rate-limit-ms = 0
server-stats-reset-time = 604800
keepalive = 32400
dpd = 90
mobile-dpd = 1800
switch-to-tcp-timeout = 25
try-mtu-discovery = false
tls-priorities = "NORMAL:%SERVER_PRECEDENCE:%COMPAT:-VERS-SSL3.0"
auth-timeout = 240
idle-timeout = 86400
mobile-idle-timeout = 86400
min-reauth-time = 300
max-ban-score = 80
ban-reset-time = 1200
cookie-timeout = 300
deny-roaming = false
rekey-time = 172800
rekey-method = ssl
use-occtl = true
pid-file = /var/run/ocserv.pid
net-priority = 6
device = vpns
predictable-ips = true
default-domain = example.com
ipv4-network = 192.168.1.0
ipv4-netmask = 255.255.255.0
# An alternative way of specifying the network:
#ipv4-network = 192.168.1.0/24
# The IPv6 subnet that leases will be given from.
#ipv6-network = fda9:4efe:7e3b:03ea::/48
# Specify the size of the network to provide to clients. It is
# generally recommended to provide clients with a /64 network in
# IPv6, but any subnet may be specified. To provide clients only
# with a single IP use the prefix 128.
#ipv6-subnet-prefix = 128
#ipv6-subnet-prefix = 64
# tunnel-all-dns = true
dns = 8.8.8.8
dns = 8.8.4.4
cisco-client-compat = true
dtls-legacy = true
route = 0.0.0.0/128.0.0.0
route = 128.0.0.0/128.0.0.0
EOF
}
# ---------添加代码 BEGIN----------------
# 生成用户模板
certtool --generate-privkey --outfile user-key.pem
echo -e 'cn = "platinum vpn test"
unit = "platinum"
expiration_days = 365
signing_key
tls_www_client ' > user.tmpl
# 生成用户证书 user-cert.pem
certtool --generate-certificate --load-privkey user-key.pem --load-ca-certificate
ca-cert.pem --load-ca-privkey ca-key.pem --template user.tmpl --outfile user-
cert.pem
mkdir N
mv ca-cert.pem /etc/ocserv/ssl/ca-cert.pem
mv ca-key.pem /etc/ocserv/ssl/ca-key.pem
mv server-cert.pem /etc/ocserv/ssl/server-cert.pem
mv server-key.pem /etc/ocserv/ssl/server-key.pem
# ---------添加代码 BEGIN-------------N
mv user-key.pem /etc/ocserv/ssl/user-key.pem
mv user-cert.pem /etc/ocserv/ssl/user-cert.pemn
mv ecc.p12 /etc/ocserv/ssl/ecc.p12NN
# ----------添加代码 END---------
ocserv -c /etc/ocserv/ecc.conf
}
Start_ocserv(){
check_installed_status
check_pid
[[ ! -z ${PID} ]] && echo -e "${Error} ocserv 正在运行,请检查 !" && exit 1
/etc/init.d/ocserv start
sleep 2s
check_pid
[[ ! -z ${PID} ]] && View_Config
# ---------添加代码 BEGIN----------------
ocserv -c /etc/ocserv/ecc.conf
[[ $? != 0 ]] && echo -e "${Error} 配置 ecc.conf 启动失败 !" && exit 1
if [[ $? = 0 ]] ; then
echo -e " 配置 ecc.conf 启动成功"
fi
}
Stop_ocserv(){
check_installed_status
check_pid
[[ -z ${PID} ]] && echo -e "${Error} ocserv 没有运行,请检查 !" && exit 1
/etc/init.d/ocserv stop
}
Restart_ocserv(){
check_installed_status
check_pid
[[ ! -z ${PID} ]] && /etc/init.d/ocserv stop
sleep 2
kill $(pgrep -f ocserv)
sleep 2
/etc/init.d/ocserv start
Start_ocserv_ec
sleep 2s
check_pid
[[ ! -z ${PID} ]] && View_Config
}
Set_ocserv(){
[[ ! -e ${conf} ]] && echo -e "${Error} ocserv 配置文件不存在 !" && exit 1
tcp_port=$(cat ${conf}|grep "tcp-port ="|awk -F ' = ' '{print $NF}')
udp_port=$(cat ${conf}|grep "udp-port ="|awk -F ' = ' '{print $NF}')
nano ${conf}
set_tcp_port=$(cat ${conf}|grep "tcp-port ="|awk -F ' = ' '{print $NF}')
set_udp_port=$(cat ${conf}|grep "udp-port ="|awk -F ' = ' '{print $NF}')
Del_iptables
Add_iptables
Save_iptables
echo "是否重启 ocserv ? (Y/n)"
read -e -p "(默认: Y):" yn
[[ -z ${yn} ]] && yn="y"
if [[ ${yn} == [Yy] ]]; then
Restart_ocserv
fi
}
Set_username(){
echo "请输入 要添加的 VPN 账号 用户名"
read -e -p "(默认: admin):" username
[[ -z "${username}" ]] && username="admin"
echo && echo -e " 用户名 : ${Red_font_prefix}${username}${Font_color_suffix}" &&
echo
}
Set_passwd(){
echo "请输入 要添加的 VPN 账号 密码"
read -e -p "(默认: doub.io):" userpass
[[ -z "${userpass}" ]] && userpass="doub.io"
echo && echo -e " 密码 : ${Red_font_prefix}${userpass}${Font_color_suffix}" &&
echo
}
Set_tcp_port(){
while true
do
echo -e "请输入 VPN 服务端的 TCP 端口"
read -e -p "(默认: 443):" set_tcp_port
[[ -z "$set_tcp_port" ]] && set_tcp_port="443"
echo $((${set_tcp_port}+0)) &>/dev/null
if [[ $? -eq 0 ]]; then
if [[ ${set_tcp_port} -ge 1 ]] && [[ ${set_tcp_port} -le 65535 ]]; then
echo && echo -e " TCP 端口 : ${Red_font_prefix}${set_tcp_port}$
{Font_color_suffix}" && echo
break
else
echo -e "${Error} 请输入正确的数字!"
fi
else
echo -e "${Error} 请输入正确的数字!"
fi
done
}
Set_udp_port(){
while true
do
echo -e "请输入 VPN 服务端的 UDP 端口"
read -e -p "(默认: ${set_tcp_port}):" set_udp_port
[[ -z "$set_udp_port" ]] && set_udp_port="${set_tcp_port}"
echo $((${set_udp_port}+0)) &>/dev/null
if [[ $? -eq 0 ]]; then
if [[ ${set_udp_port} -ge 1 ]] && [[ ${set_udp_port} -le 65535 ]]; then
echo && echo -e " TCP 端口 : ${Red_font_prefix}${set_udp_port}$
{Font_color_suffix}" && echo
break
else
echo -e "${Error} 请输入正确的数字!"
fi
else
echo -e "${Error} 请输入正确的数字!"
fi
done
}
Set_Config(){
Set_username
Set_passwd
echo -e "${userpass}\n${userpass}"|ocpasswd -c ${passwd_file} ${username}
Set_tcp_port
Set_udp_port
sed -i 's/tcp-port = '"$(echo ${tcp_port})"'/tcp-port = '"$(echo $
{set_tcp_port})"'/g' ${conf}
sed -i 's/udp-port = '"$(echo ${udp_port})"'/udp-port = '"$(echo $
{set_udp_port})"'/g' ${conf}
insert_str=$(sed -n '/ping-leases = false/=' /etc/ocserv/ocserv.conf) && sed
-i "$insert_str i route = 0.0.0.0/128.0.0.0" /etc/ocserv/ocserv.conf
insert_str=$(sed -n '/ping-leases = false/=' /etc/ocserv/ocserv.conf) && sed
-i "$insert_str i route = 128.0.0.0/128.0.0.0" /etc/ocserv/ocserv.conf
}
Read_config(){
[[ ! -e ${conf} ]] && echo -e "${Error} ocserv 配置文件不存在 !" && exit 1
conf_text=$(cat ${conf}|grep -v '#')
tcp_port=$(echo -e "${conf_text}"|grep "tcp-port ="|awk -F ' = ' '{print
$NF}')
udp_port=$(echo -e "${conf_text}"|grep "udp-port ="|awk -F ' = ' '{print
$NF}')
max_same_clients=$(echo -e "${conf_text}"|grep "max-same-clients ="|awk -F '
= ' '{print $NF}')
max_clients=$(echo -e "${conf_text}"|grep "max-clients ="|awk -F ' = '
'{print $NF}')
}
List_User(){
[[ ! -e ${passwd_file} ]] && echo -e "${Error} ocserv 账号配置文件不存在 !" && exit 1
User_text=$(cat ${passwd_file})
if [[ ! -z ${User_text} ]]; then
User_num=$(echo -e "${User_text}"|wc -l)
user_list_all=""
for((integer = 1; integer <= ${User_num}; integer++))
do
user_name=$(echo -e "${User_text}" | awk -F ':*:' '{print $1}' |
sed -n "${integer}p")
user_status=$(echo -e "${User_text}" | awk -F ':*:' '{print $NF}'
| sed -n "${integer}p"|cut -c 1)
if [[ ${user_status} == '!' ]]; then
user_status="禁用"
else
user_status="启用"
fi
user_list_all=${user_list_all}"用户名: "${user_name}" 账号状态: "$
{user_status}"\n"
done
echo && echo -e "用户总数 ${Green_font_prefix}"${User_num}"$
{Font_color_suffix}"
echo -e ${user_list_all}
fi
}
Add_User(){
Set_username
Set_passwd
user_status=$(cat "${passwd_file}"|grep "${username}"':*:')
[[ ! -z ${user_status} ]] && echo -e "${Error} 用户名已存在 ![ ${username} ]" &&
exit 1
echo -e "${userpass}\n${userpass}"|ocpasswd -c ${passwd_file} ${username}
user_status=$(cat "${passwd_file}"|grep "${username}"':*:')
if [[ ! -z ${user_status} ]]; then
echo -e "${Info} 账号添加成功 ![ ${username} ]"
else
echo -e "${Error} 账号添加失败 ![ ${username} ]" && exit 1
fi
}
Del_User(){
List_User
[[ ${User_num} == 1 ]] && echo -e "${Error} 当前仅剩一个账号配置,无法删除 !" && exit 1
echo -e "请输入要删除的 VPN 账号的用户名"
read -e -p "(默认取消):" Del_username
[[ -z "${Del_username}" ]] && echo "已取消..." && exit 1
user_status=$(cat "${passwd_file}"|grep "${Del_username}"':*:')
[[ -z ${user_status} ]] && echo -e "${Error} 用户名不存在 ! [${Del_username}]" &&
exit 1
ocpasswd -c ${passwd_file} -d ${Del_username}
user_status=$(cat "${passwd_file}"|grep "${Del_username}"':*:')
if [[ -z ${user_status} ]]; then
echo -e "${Info} 删除成功 ! [${Del_username}]"
else
echo -e "${Error} 删除失败 ! [${Del_username}]" && exit 1
fi
}
Modify_User_disabled(){
List_User
echo -e "请输入要启用/禁用的 VPN 账号的用户名"
read -e -p "(默认取消):" Modify_username
[[ -z "${Modify_username}" ]] && echo "已取消..." && exit 1
user_status=$(cat "${passwd_file}"|grep "${Modify_username}"':*:')
[[ -z ${user_status} ]] && echo -e "${Error} 用户名不存在 ! [${Modify_username}]"
&& exit 1
user_status=$(cat "${passwd_file}" | grep "${Modify_username}"':*:' | awk -F
':*:' '{print $NF}' |cut -c 1)
if [[ ${user_status} == '!' ]]; then
ocpasswd -c ${passwd_file} -u ${Modify_username}
user_status=$(cat "${passwd_file}" | grep "$
{Modify_username}"':*:' | awk -F ':*:' '{print $NF}' |cut -c 1)
if [[ ${user_status} != '!' ]]; then
echo -e "${Info} 启用成功 ! [${Modify_username}]"
else
echo -e "${Error} 启用失败 ! [${Modify_username}]" && exit 1
fi
else
ocpasswd -c ${passwd_file} -l ${Modify_username}
user_status=$(cat "${passwd_file}" | grep "$
{Modify_username}"':*:' | awk -F ':*:' '{print $NF}' |cut -c 1)
if [[ ${user_status} == '!' ]]; then
echo -e "${Info} 禁用成功 ! [${Modify_username}]"
else
echo -e "${Error} 禁用失败 ! [${Modify_username}]" && exit 1
fi
fi
}
Set_Pass(){
check_installed_status
echo && echo -e " 你要做什么?
}
# ---------添加代码 BEGIN ----------------
View_conf_ecc(){
}
# ---------添加代码 END ----------------
View_Log(){
[[ ! -e ${log_file} ]] && echo -e "${Error} ocserv 日志文件不存在 !" && exit 1
echo && echo -e "${Tip} 按 ${Red_font_prefix}Ctrl+C${Font_color_suffix} 终止查看日
志" && echo -e "如果需要查看完整日志内容,请用 ${Red_font_prefix}cat ${log_file}$
{Font_color_suffix} 命令。" && echo
tail -f ${log_file}
}
Uninstall_ocserv(){
check_installed_status "un"
echo "确定要卸载 ocserv ? (y/N)"
echo
read -e -p "(默认: n):" unyn
[[ -z ${unyn} ]] && unyn="n"
if [[ ${unyn} == [Yy] ]]; then
check_pid
[[ ! -z $PID ]] && kill -9 ${PID} && rm -f ${PID_FILE}
Read_config
Del_iptables
Save_iptables
update-rc.d -f ocserv remove
rm -rf /etc/init.d/ocserv
rm -rf "${conf_file}"
rm -rf "${log_file}"
cd '/usr/local/bin' && rm -f occtl
rm -f ocpasswd
cd '/usr/local/bin' && rm -f ocserv-fw
cd '/usr/local/sbin' && rm -f ocserv
cd '/usr/local/share/man/man8' && rm -f ocserv.8
rm -f ocpasswd.8
rm -f occtl.8
echo && echo "ocserv 卸载完成 !" && echo
else
echo && echo "卸载已取消..." && echo
fi
}
over(){
update-rc.d -f ocserv remove
rm -rf /etc/init.d/ocserv
rm -rf "${conf_file}"
rm -rf "${log_file}"
cd '/usr/local/bin' && rm -f occtl
rm -f ocpasswd
cd '/usr/local/bin' && rm -f ocserv-fw
cd '/usr/local/sbin' && rm -f ocserv
cd '/usr/local/share/man/man8' && rm -f ocserv.8
rm -f ocpasswd.8
rm -f occtl.8
echo && echo "安装过程错误,ocserv 卸载完成 !" && echo
}
Add_iptables(){
#解决连接上无网络的 debug
# ---------添加代码 BEGIN----------------
iptables -A FORWARD -o vpns+ -j ACCEPT
iptables -A FORWARD -i vpns+ -j ACCEPT
iptables -t nat -A POSTROUTING -s 192.168.1.0/24 -j MASQUERADE
iptables -I INPUT -m state --state NEW -m tcp -p tcp --dport ${PORT_OCSERV} -
j ACCEPT
# ---------添加代码 END----------------
iptables -I INPUT -m state --state NEW -m tcp -p tcp --dport ${set_tcp_port}
-j ACCEPT
iptables -I INPUT -m state --state NEW -m udp -p udp --dport ${set_udp_port}
-j ACCEPT
}
Del_iptables(){
iptables -D INPUT -m state --state NEW -m tcp -p tcp --dport ${tcp_port} -j
ACCEPT
iptables -D INPUT -m state --state NEW -m udp -p udp --dport ${udp_port} -j
ACCEPT
# ---------添加代码 BEGIN----------------
iptables -D INPUT -m state --state NEW -m udp -p udp --dport ${PORT_OCSERV} -
j ACCEPT
# ---------添加代码 END----------------
}
Save_iptables(){
iptables-save > /etc/iptables.up.rules
}
Set_iptables(){
echo -e "net.ipv4.ip_forward=1" >> /etc/sysctl.conf
sysctl -p
ifconfig_status=$(ifconfig)
if [[ -z ${ifconfig_status} ]]; then
echo -e "${Error} ifconfig 未安装 !"
read -e -p "请手动输入你的网卡名(一般情况下,网卡名为 eth0,Debian9 则为 ens3,CentOS Ubuntu 最新
版本可能为 enpXsX(X 代表数字或字母),OpenVZ 虚拟化则为 venet0):" Network_card
[[ -z "${Network_card}" ]] && echo "取消..." && exit 1
else
Network_card=$(ifconfig|grep "eth0")
if [[ ! -z ${Network_card} ]]; then
Network_card="eth0"
else
Network_card=$(ifconfig|grep "ens3")
if [[ ! -z ${Network_card} ]]; then
Network_card="ens3"
else
Network_card=$(ifconfig|grep "venet0")
if [[ ! -z ${Network_card} ]]; then
Network_card="venet0"
else
# ---------添加代码 BEGIN----------------
Network_card=$(ip route get 8.8.8.8 | awk -- '{printf
$5}')
# ---------添加代码 END----------------
[[ -z "${Network_card}" ]] && echo "取消..." && exit 1
fi
fi
fi
fi
iptables -t nat -A POSTROUTING -o ${Network_card} -j MASQUERADE
${Green_font_prefix}0.${Font_color_suffix} 升级脚本
————————————
${Green_font_prefix}1.${Font_color_suffix} 安装 ocserv
${Green_font_prefix}2.${Font_color_suffix} 卸载 ocserv
————————————
${Green_font_prefix}3.${Font_color_suffix} 启动 ocserv
${Green_font_prefix}4.${Font_color_suffix} 停止 ocserv
${Green_font_prefix}5.${Font_color_suffix} 重启 ocserv
————————————
${Green_font_prefix}6.${Font_color_suffix} 设置 账号配置
${Green_font_prefix}7.${Font_color_suffix} 查看 配置信息
${Green_font_prefix}8.${Font_color_suffix} 修改 配置文件
${Green_font_prefix}9.${Font_color_suffix} 查看 日志信息
${Green_font_prefix}10.${Font_color_suffix} 查看 日志 ecc 信息
————————————" && echo
if [[ -e ${file} ]]; then
check_pid
if [[ ! -z "${PID}" ]]; then
echo -e " 当前状态: ${Green_font_prefix}已安装${Font_color_suffix} 并 $
{Green_font_prefix}已启动${Font_color_suffix}"
else
echo -e " 当前状态: ${Green_font_prefix}已安装${Font_color_suffix} 但 $
{Red_font_prefix}未启动${Font_color_suffix}"
fi
else
echo -e " 当前状态: ${Red_font_prefix}未安装${Font_color_suffix}"
fi
echo
read -e -p " 请输入数字 [0-10]:" num
case "$num" in
0)
Update_Shell
;;
1)
Install_ocserv
;;
2)
Uninstall_ocserv
;;
3)
Start_ocserv
;;
4)
Stop_ocserv
;;
5)
Restart_ocserv
;;
6)
Set_Pass
;;
7)
View_Config
;;
8)
Set_ocserv
;;
9)
View_Log
;;
# ---------添加代码 BEGIN ----------------
10)
View_conf_ecc
;;
# ---------添加代码 END ----------------
*)
echo "请输入正确数字 [0-9]"
;;
esac