Welcome Guest ( Log In | Register )

Outline · [ Standard ] · Linear+

 Setting up your own OpenVPN, Information on how to set-up OpenVPN

views
     
SUSDiligent Sloth
post Mar 2 2007, 01:41 AM

Lowyat VPN provider
*****
Senior Member
880 posts

Joined: Jul 2006
From: Sibu, Sarawak



I'd be more than happy to help out here, I'm not making a profit out of my VPN service either but here goes (I'll keep it short and simple).

1.0: You'd best look for either a dedicated server / colocation service that offers at least 10mpbs connection, its better if its dedicated but if its shared among other users in the datacenter that's fine too. You'd probably want to check their TOS if its a truly unmetered connections or maybe something like 1000GB / month. Also important is the country's copyright laws.

2.0: www.openvpn.net has fairly detailed instructions on how to setup the server, the one that you might find a hassle is creating the certificates indivually, but there is an option to auth externally. Personally I'm using the cert solution (using a semi-automatic generation script) as I can set them to expire at the end of their subscription period, the downside of this is that I can't retract a cert thus enforcing a no refunds policy.

2.1: Not much to config here, most of the clients can work with the standard config file, the only changes that have to be made are to set the certificates and keys in place. Advanced tweaking is available, i.e what kind of routing you'd like but I feel that the default is good enough. However I am experimenting a bit with the MTU settings of the server/client to see if will give any performance improvement.

3.0: N/A

4.0: N/A

5.0: Since my server is hosted locally, I doubt the RIAA would bother to come checking Malaysia, however to cover my asses, I have banned a number of IP's that are known to be 'spies' from connecting to this server, whiles this is not a comprehensive solution, the list is updated whenever possible.


Additional Information
There are actually two ways to route your BT traffic through the VPN connection
1. Through a SOCKS proxy
This is the solution I am using, the problem occurs that the socks servers connections can be become saturated stuffing up your connections. I'm working on a script that will loadbalance the socks connections over a few proxies, and also to 'kill' off 'dead' connections.
2. Routing all traffic through the VPN
This is what is normally used under corporate VPNs whereby all traffic is routed via VPNs, the reason I don't use this is that it has unpredicatble results in a DHCP network like ours(especially on windows based machines), and it will cause additional bandwidth usage.


Hope this helps you guys and if anyone is interested in setting up another VPN server, do let me know, I'd love to setup another server but am seriously lacking the funds to do so atm.

This post has been edited by Diligent Sloth: Mar 2 2007, 01:57 AM
SUSDiligent Sloth
post Mar 2 2007, 11:51 AM

Lowyat VPN provider
*****
Senior Member
880 posts

Joined: Jul 2006
From: Sibu, Sarawak



QUOTE(mediumsliced @ Mar 2 2007, 11:12 AM)
Thanks for your input, Tentris. Now, when you say excessive usage, by that you mean utilizing more than the allocated 10 Mbps? I thought that it would be automatically limited by the hosts so we don't have to worry about having the service shut down on us?
*
It means that the servers are not on a dedicated 10 Mbps link, and that your server in general seems to be hogging the bandwidth making other servers on the same connection seem sluggish
SUSDiligent Sloth
post Mar 2 2007, 12:40 PM

Lowyat VPN provider
*****
Senior Member
880 posts

Joined: Jul 2006
From: Sibu, Sarawak



QUOTE(fairx @ Mar 2 2007, 12:04 PM)
that is very informative.

is there any reading / site that discuss this thoroughly?

BTW, there are calculations on how much vpn connection : RAM ratio ? I remember reading bout that somewhere.
*
You'd have to tweak that out yourself I guess, since its not just dependant on the VPN but on the services you run, ie. socks, http etc etc proxies.. yadda yadda..
SUSDiligent Sloth
post Mar 3 2007, 01:42 PM

Lowyat VPN provider
*****
Senior Member
880 posts

Joined: Jul 2006
From: Sibu, Sarawak



That's a semi limited solution, cause while the tracker will be there, who will actually bother to upload to it? You'd still need 'outside' content. biggrin.gif


SUSDiligent Sloth
post Mar 3 2007, 09:06 PM

Lowyat VPN provider
*****
Senior Member
880 posts

Joined: Jul 2006
From: Sibu, Sarawak



You'd also have to consider our route to the server lah, no point 100mps connection if our average download is too little
SUSDiligent Sloth
post Mar 6 2007, 01:26 PM

Lowyat VPN provider
*****
Senior Member
880 posts

Joined: Jul 2006
From: Sibu, Sarawak



QUOTE
IMPORTANT NOTICE: *All Payments To FDCservers.net LLC Are Non-Refundable

The following are considered violations of FDCservers.net AUP (acceptable use policy)
1. Illegal use: FDCservers.net LLC's services may not be used for illegal purposes, or in support of illegal activities. FDCservers.net LLC reserves the right to cooperate with legal authorities and/or injured third parties in the investigation of any suspected crime or civil wrongdoing.

2. Threats: Use of the FDCservers.net LLC service to transmit any material (by e-mail, uploading, posting or otherwise) that threatens or encourages bodily harm or destruction of property.

3. Harassment: Use of the FDCservers.net LLC service to transmit any material (by e-mail, uploading, posting or otherwise) that harasses another.

4. Forgery or impersonation: Adding, removing or modifying identifying network header information in an effort to deceive or mislead is prohibited. Attempting to impersonate any person by using forged headers or other identifying infrmation is prohibited. The use of anonymous remailers or nicknames does not constitute impersonation.

5. Fraudulent activity: Use of FDCservers.net LLC service to make fraudulent offers to sell or buy products, items, or services, or to advance any type of financial scam such as "pyramid schemes" and "chain letters."

6. Unsolicited commercial e-mail / Unsolicited bulk e-mail (SPAM) Use of the FDCservers.net LLC service to transmit any unsolicited commercial or unsolicited bulk e-mail is expressly prohibited. Violations of this type will result in the immediate termination of the offending FDCservers.net LLC account.

IMPORTANT NOTICE:
Anyone hosting websites or services on their server that support spammers or cause any of our IP space to be listed in any of the various Spam Databases will have their server immediately removed from our network. The server will not be reconnected until such time that you agree to remove ANY and ALL traces of the offending material immediately upon reconnection and agree to allow us access to the server to confirm that all material has been COMPLETELY removed. Severe violations may result in immediate and permanent removal of the server from our network without notice to the customer. Any server guilty of a second violation WILL be immediately and permanently removed from our network without notice.

7. E-mail / News Bombing: Malicious intent to impede another person's use of electronic mail services or news will result in the immediate termination of the offending FDCservers.net LLC account.

8. E-mail / Message Forging: Forging any message header, in part or whole, of any electronic transmission, originating or passing through the FDCservers.net LLC service is in violation of this AUP.

9. Usenet SPAMing: FDCservers.net LLC has a zero tolerance policy for the use of its network for the posting of messages or commercial advertisements, which violate the rules, regulations, FAQ or charter of any newsgroups or mailing list. Commercial messages that are appropriate under the rules of a newsgroup or mailing list or that are solicited by the recipients are permitted.

10. Unauthorized access: Use of the FDCservers.net LLC service to access, or to attempt to access, the accounts of others, or to penetrate, or attempt to penetrate, security measures of FDCservers.net LLC's or another entity's computer software or hardware, electronic communications system, or telecommunications system, whether or not the intrusion results in the corruption or loss of data, is expressly prohibited and the offending FDCservers.net LLC account is subject to immediate termination.

11. Copyright or trademark infringement: Use of the FDCservers.net LLC service to transmit any material (by e-mail, uploading, posting or otherwise) that infringes any copyright, trademark, patent, trade secret or other proprietary rights of any third party, including, but not limited to, the unauthorized copying of copyrighted material, the digitization and distribution of photographs from magazines, books, or other copyrighted sources, and the unauthorized transmittal of copyrighted software.

12. Collection of personal data: Use of the FDCservers.net LLC service to collect, or attempt to collect, personal information about third parties without their knowledge or consent.

13. Network disruptions and unfriendly activity: Use of the FDCservers.net LLC service for any activity which affects the ability of other people or systems to use FDCservers.net LLC Services or the Internet. This includes "denial of service" (DOS) attacks against another network host or individual user. Interference with or disruption of other network users, services or equipment is prohibited. It is the Member's responsibility to ensure that their network is configured in a secure manner. A Subscriber may not, through action or inaction, allow others to use their network for illegal or inappropriate actions. A Subscriber may not permit their network, through action or inaction, to be configured in such a way that gives a third party the capability to use their network in an illegal or inappropriate manner. Unauthorized entry and/or use of another company and/or individual's computer system will result in immediate account termination. FDCservers.net LLC will not tolerate any subscriber attempting to access the accounts of others, or penetrate security measures of other systems, whether or not the intrusion results in corruption or loss of data.

14. Fraud: Involves a knowing misrepresentation or misleading statement, writing or activity made with the intent that the person receiving it will act upon it.

15. Infringement of Copyright, Patent, Trademark, Trade Secret, or Intellectual Property Right: Distribution and/or posting of copyrighted or the aforementioned infringements will not be tolerated.

16. Distribution of Viruses: Intentional distributions of software that attempts to and/or causes damage, harassment, or annoyance to persons, data, and/or computer systems are prohibited. Such an offense will result in the immediate termination of the offending account.

17. Inappropriate Use of Software: Use of software or any device that would facilitate a continued connection, i.e. pinging, while using FDCservers.net LLC services could result in suspension service.

18. Third Party Accountability: FDCservers.net LLC subscribers will be held responsible and accountable for any activity by third parties, using their account, that violates guidelines created within the Acceptable Use Policy.

19. IRC networks: IRC is allowed only on our separate IRC network that was designated by FDCservers.net LLC for such a use. Clints found running IRC on our standard network will have their servers disconnected untill they agree to be moved to IRC network.

20. Adult content is allowed
I've highlighted 2-3 items you should look at in the AUP
SUSDiligent Sloth
post Mar 6 2007, 01:28 PM

Lowyat VPN provider
*****
Senior Member
880 posts

Joined: Jul 2006
From: Sibu, Sarawak



You can count out Hongkong, anti piracy laws extremely strict there
SUSDiligent Sloth
post Mar 8 2007, 02:02 AM

Lowyat VPN provider
*****
Senior Member
880 posts

Joined: Jul 2006
From: Sibu, Sarawak



Swedish servers generally have good backbone links to the rest of the internet, not a bad choice if I may say so myself
SUSDiligent Sloth
post Mar 9 2007, 12:28 PM

Lowyat VPN provider
*****
Senior Member
880 posts

Joined: Jul 2006
From: Sibu, Sarawak



How to test? Just run a connection to the server... and see it works, you'd prolly want to open up port 1194 on your server
SUSDiligent Sloth
post Mar 19 2007, 12:36 AM

Lowyat VPN provider
*****
Senior Member
880 posts

Joined: Jul 2006
From: Sibu, Sarawak



Of course, its on a shared pipe with the 100mpbs being burstable, on average you can expect anywhere from 10-35mbps average
SUSDiligent Sloth
post Mar 24 2007, 12:28 AM

Lowyat VPN provider
*****
Senior Member
880 posts

Joined: Jul 2006
From: Sibu, Sarawak



Yep, its good enough smile.gif

 

Change to:
| Lo-Fi Version
0.0159sec    1.50    6 queries    GZIP Disabled
Time is now: 18th December 2025 - 09:21 PM