2013年5月12日 星期日

Latest News Clips 2013.05.13



  1. Asia Wrestles With a Flood of Cash 
Asian Central Banks Struggle to Tamp Down Strong Currencies 
    The Wall Street Journal   May 9, 2013 
HONG KONG—Central banks in Asia, Australia and New Zealand are ratcheting up moves to deal with an influx of capital that is keeping currencies strong and complicating efforts to manage growth. 
New Zealand's central bank said Wednesday it intervened in foreign-exchange markets to blunt the rise of its currency and would continue to do so, a day after Australia's central bank cut interest rates to a record low and noted the stubborn strength of the Australian dollar. Elsewhere, China is moving to curb bets on the rising yuan, while Thailand is considering efforts to curb the strongest baht since the 1997 Asian financial crisis. 
In a surprise move early Thursday, South Korea cut interest rates by a quarter of a percentage point, as the country grapples with a slowing economy. The cut in borrowing costs comes a day after a government official voiced concern about "one-sided" moves in foreign exchange, code for a rise in the value of the currency. 
The surging flows to the region are one more example of how investors are scouring the globe looking for higher returns on their money. Many central banks in the developed world are pumping in money in a bid to spur their economies, sending interest rates down and money flowing into alternative investments. In another example, the yield on junk bonds—like emerging markets, generally considered high-risk, high-reward investments—fell below 5% this week as investors flocked to the securities. Yields fall as prices rise. 


ratchet up: increase regularily,一步步增加
influx: surging flow
intervene in: interrupt and try to control,干涉,介入 
in a bid to: 努力為了to do something

  1. Anwar supporters hold protest over Malaysia election result 
         FT  2013.05.07 
   
Anwar Ibrahim leads a mass protest in Petaling Jaya 
Anwar Ibrahim, Malaysia’s opposition leader, led tens of thousands of supporters in a protest rally on Wednesday evening against his election defeat in a sign that concerns about the poll’s fairness are gaining traction. 
About 50,000 protesters, most of whom were wearing black, jammed the streets leading to a football stadium in the Kelana Jaya district of Selangor, an opposition-controlled state bordering Kuala Lumpur. Many were unable to get into the stadium’s overflowing stands and were squeezed out on to the street. 

 “This is the beginning of a battle between the people and an illegitimate, corrupt and arrogant government,” Mr Anwar told the chanting crowd. “We will continue this struggle and we will never surrender.” 
A large number were young ethnic Chinese who have been angered not only by what the opposition says was a fraudulent election but also by comments from Najib Razak, the prime minister, saying that his ruling coalition lost ground in the poll partly because of a “Chinese tsunami”. 
“We are not Chinese, we are Malaysian,” read some of the placards. 
Russ Chong, a 42-year-old property sales executive, said Mr Najib was “stupid to bring [the Chinese issue] up...All we want is a fair election,” he said. 
Many people at the rally conceded the result of the vote was unlikely to change but wanted to voice their concerns at what they called a flawed electoral system. 
Earlier on Wednesday, a study part-funded by the British and Canadian governments was published which found Sunday’s election, which the incumbent ruling coalition won, was “only partially free and not fair”. 
The findings,produced by two independent think-tanksinMalaysia, cast a cloud over an election the losing opposition claims was flawed. 

  1.  The Scientific 7-Minute Workout 
        The New York Times         2013.05.09 

Exercise science is a fine and intellectually fascinating thing. But sometimes you just want someone to lay out guidelines for how to put the newest fitness research into practice. 
An article in the May-June issue of the American College of Sports Medicine’s Health & Fitness Journal does just that. In 12 exercises deploying only body weight, a chair and a wall, it fulfills the latest mandates for high-intensity effort, which essentially combines a long run and a visit to the weight room into about seven minutes of steady discomfort — all of it based on science. 
“There’s very good evidence” that high-intensity interval training provides “many of the fitness benefits of prolonged endurance training but in much less time,” says Chris Jordan, the director of exercise physiology at the Human Performance Institute in Orlando, Fla., and co-author of the new article. 
Work by scientists at McMaster University in Hamilton, Ontario, and other institutions shows, for instance, that even a few minutes of training at an intensity approaching your maximum capacity produces molecular changes within muscles comparable to those of several hours of running or bike riding. 

  1.  South Korean president to Congress: "No North Korea provocations can     succeed" 
    CNN    May 9, 2013  

  
South Korean President Park Geun-hye says the future of the Korean peninsula relies on U.S. involvement in the peace process. 

Washington (CNN) -- The future of the Korean peninsula relies on U.S. involvement in the peace process, South Korean President Park Geun-hye told a joint meeting of Congress Wednesday. 
Park said that despite recent tensions with communist North Korea, reunification of the Koreas is possible, even if it "feels distant today." 
"North Korea continues to issue threats and provocations, firing long range missiles, staging nuclear tests and undermining peace on the peninsula and far beyond it," Park said. "The Korean government is reacting resolutely but calmly. We maintain the highest level of readiness." 
And as long as the United States and South Korea maintain their strong relationship, Park said, "You may rest assured, no North Koreans provocation can succeed." 

rest assured:放心

  1. Abused but alive: Lessons for Cleveland's survivors 
       CNN     May 11, 2013  



(CNN) -- The world will never fully know the unspeakable tortures they endured. But they survived. 
Elizabeth Smart was kidnapped from her bedroom at 14, declared a child bride by her captor and sexually assaulted for nine months. Jaycee Dugard, 11, was snatched from a roadside and held for 18 years, eventually bearing two babies fathered by her rapist kidnapper. Taken at 11, Shawn Hornbeck was sexually abused by his abductor for four years before police freed him. 
This week in Cleveland, three new names were added to that list of young abduction survivors. After a decade in captivity, Amanda Berry, Georgina "Gina" DeJesus and Michelle Knight now face a challenging journey toward recovery. 
What can they learn from the paths followed by Smart, Dugard, Hornbeck and others that led them from darkness to brighter lives? 
The resiliency of these survivors is nothing short of remarkable. Smart, now 25, is married. She formed a foundation to battle child abuse and travels the country as a public speaker. Nearly four years after regaining her freedom, Dugard, 33, heads her own group aimed at helping victims like herself. She wrote a book about her ordeal and has learned to ride horseback. Hornbeck, 21, works full-time and wants to finish his education. 
Experts credit much of their recovery to access to important health care resources and strong family support. 
There's another factor: faith. These survivors likely were more confident  that they would re-emerge into a safe world. 

2013年5月5日 星期日

Latest News Clips 2013.05.06


                   


1.      China calls Japan-U.S. island drill "provocative"
Reuters – Wed, Apr 24, 2013

Reuters/Reuters - An aerial photo shows a Chinese marine surveillance ship Haijian No. 66 (C) cruising next to Japan Coast Guard patrol ships in the East China Sea, near known as Senkaku isles in Japan and …more 
BEIJING (Reuters) - China said on Wednesday that "provocative actions" would not sway it from defending its territory, after Japan confirmed it would conduct military drills with the United States amid tension between Beijing and Tokyo over disputed islands.
Japan said on Tuesday that the joint drill, scheduled for June off California, involved the recapture of an isolated island but was not aimed at scenarios involving a specific country, Japan's Kyodo news agency reported.
China's Foreign Ministry spokeswoman, Hua Chunying, said "foreign pressure" could not sway China from protecting its territorial sovereignty in the East China Sea.
"For any related provocative actions, the Chinese government will maintain a resolute response," Hua told reporters at a regular news briefing when asked about the drills.
"We have always upheld the same stance on issues related to the Diaoyu Islands: to appropriately solve, manage and control the relevant issues through bilateral dialogue and negotiations."
Beijing and Tokyo have both protested over an incident on Tuesday in which Chinese patrol vessels played cat-and-mouse with a flotilla of Japanese nationalists near the uninhabited islands, known as the Senkaku in Japan and the Diaoyu in China.
The Japanese government bought the islands near rich fishing grounds and potentially lucrative maritime gas fields from a private Japanese owner last year, sparking sometimes-violent anti-Japanese protests across China.
The issue has brought Chinese-Japanese relations to their lowest point since normalization of relations more than 40 years ago.
China also chastised Japan for Tuesday's visits by at least 168 lawmakers to Tokyo's Yasukuni Shrine, which honors 14 leaders convicted as war criminals by an Allied tribunal along with Japan's war dead.

sway from: sway A from doing something
conduct military drills實行軍演
off California: off離開, 在此指加州外海的意思
uphold: defend and support
Senkaku :世界對釣魚台的稱呼
lucrative : 有利可圖的
spark:爆發(引起了)
chastise: 嚴厲譴責
convict:判...有罪


2.      Abe Uses First Russian Visit in Decade to Revive Peace Talks
The Bloomberg   April 29, 2013


Russian President Vladimir Putin and Japanese Prime Minister Shinzo Abe agreed to revive stalled talks on a peace treaty to formally end World War II hostilities between the two countries.
The two leaders instructed their foreign ministries to accelerate discussions of “mutually acceptable options” and voiced “determination” to use bilateral talks to bridge differences and sign a peace accord, according to a joint statement issued to reporters in Moscow today.
Abe is using the first trip to Russia by a Japanese premier in a decade to break an almost seven-decade-long territorial dispute and win more access to energy resources. Putin said the two sides are “sincere” in seeking a diplomatic breakthrough and want to harness stronger economic ties to advance the talks.
“I’ll personally deal with this issue, which is the biggest unsolved question in relations between our countries, and will apply all my efforts to solve it,” Abe said in the Kremlin in remarks translated into Russian.
Abe met Putin in the Kremlin midway through a three-day visit to discuss energy, trade and investment. The countries’ relationship has been hamstrung by a dispute over islands known as the Northern Territories in Japan and Southern Kurils in Russia that were seized by the Soviet Union in the final days of the war.
stall 陷入泥潭(停止)
hostility敵視
access取得
sincere: honest
harness :use利用
 A ties to B: 結合 
apply運用
hamstring阻礙
seize攻占

3.      Obama’s Mexico Trip Ties Immigration Debate to Economy

The Bloomberg   May 02, 2013



President Barack Obama arrived in Mexico today with a message that ties the immigration debate in the U.S. to economic growth on both sides of the border.
In his discussions with Mexican President Enrique Pena Nieto, Obama also will be conscious of his audience back home, where Congress next week resumes negotiating possible changes to immigration law. That debate will affect U.S. and Mexican businesses as well as the millions of Mexicans living in the U.S. illegally.

Obama and Pena Nieto are scheduled to meet for about an hour before holding a joint news conference at 4:10 p.m. local time.
The domestic debate is intertwined with the thorniest issues in U.S. relations with Latin America, including border security, drug trafficking and free trade.
“The White House is hoping to highlight the economic opportunities that would emanate from a modernized immigration system,” said Ana Navarro, a Republican strategist who met with Obama and other White House officials about the trip this week. “He doesn’t want security and violence issues to dominate this trip.”
Mexico’s economic expansion has been changing the dynamics of the U.S. immigration debate and opening opportunities for Obama to meet his goal of doubling U.S. exports by the end of next year. The Mexican economy has grown at about twice the pace of the U.S. since the end of 2009, lessening the lure of the U.S. for Mexican workers. Net Mexican migration dropped to zero from 2005 to 2010, according to a Pew Research Center study released a year ago.

tie A to B:結合 A to B
 be conscious of 意識到
traffic, trafficked,trafficked,trafficking
dynamics 活力(複)
4.         Willem-Alexander sworn in as king of the Netherlands
BBC    30 April 2013 



Willem-Alexander has been sworn in as king of the Netherlands following the abdication of Queen Beatrix.
He became the country's first king since 1890 when his 75-year-old mother signed the abdication deed earlier on Tuesday after 33 years on the throne.
Huge crowds of orange-clad partygoers are in Amsterdam to pay tribute.
Now known as Princess Beatrix, the former queen maintained a recent Dutch tradition of monarch's handing over power to a new generation.
Wearing the royal mantle, the new king swore to uphold the constitution at a colourful enthronement ceremony in the Nieuwe Kerk, a decommissioned church, before a joint session of the Dutch parliament.
"I swear that I shall defend and preserve the independence and territory of the state with all my powers," he said.
"That I shall protect the general and individual freedom and rights of all my subjects and shall use all available means granted to me by law for preserving and promoting general and individual prosperity as I befitting of a good king.... So help me God almighty."
Crowds in the square outside cheered as the announcement of his inauguration was made from a balcony overlooking the square amid trumpet fanfare.
In the evening, the royal family will take part in a water pageant.




'Happy and grateful'
The queen had announced her intention to stand down in January, saying her son was ready to reign and that it was time for the throne to be held by "a new generation".
She formally relinquished the throne at a short ceremony in the Royal Palace on Tuesday, signing a statement transferring the monarchy to her son "in   accordance with the statutes and the constitution of the Kingdom of the Netherlands".
There were huge cheers from the crowds outside in Dam Square, who were watching the ceremony on giant television screens, as she, her son and his wife Maxima - a 41-year-old Argentine-born investment banker - signed the deed of abdication.
Shortly afterwards, the three royals emerged on a balcony above the square.
The visibly emotional Princess Beatrix told the crowds: "I am happy and grateful to introduce to you your new king, Willem-Alexander."

take part參加

inauguration就職典禮 
balcony 陽台
 amid  trumpet fanfare在一陣號響聲中
relinquish 交出
adbicate:辭職(王位權力)
resign、quit


5.      Alibaba Buys a Stake in China’s Twitter

The New York Times   Apr. 29, 2013
    

The Internet giant Alibaba was once known as China’s answer to eBay. Now it is forging closer ties to the country’s counterpart to Twitter.
Alibaba agreed on Monday to buy an 18 percent stake in the Sina Corporation’s Weibo, the most popular of China’s microblogging services, for $586 million. It has the right to raise its stake to 30 percent in the future.
The deal values Weibo at about $3.3 billion — equivalent to Sina’s entire market value as of Friday.
Alibaba and Sina also agreed to cooperate in improving ways to marry social networking with e-commerce, as microblogging services like Sina’s continue to grow in popularity. Sina Weibo said that last year it had more than 46 million daily active users, an increase of 82 percent from the period a year earlier.
That remains a fraction of Twitter’s user base, however. And a recent study of about 30,000 Sina Weibo users found that about 57 percent of the sampled accounts had no measurable activity or posts.
Alibaba continues to grow, most recently being valued by analysts at more than $55 billion. It has reshuffled its management ranks ahead of a much-anticipated initial public offering that could come as soon as this year.
The growth of social networking and its close ties to the continuing boom in mobile Internet usage have prompted a natural response: how to make money from the phenomenon. Sina and Alibaba expect their efforts to yield about $380 million in advertising and commercial revenue for the Weibo service over the next three years.
“We believe that the cooperation of our two robust platforms will bring unique and valuable services to Weibo users, as well as making the mobile Internet a core part of Alibaba’s strategy,” Jack Ma, the Alibaba chairman, said in a statement.
forge形成、遞造
marry with與什麼結合
 the period a year earlier去年同期
yield 產出

2013年5月2日 星期四

Amazon AWS VPC With OpenVpn 筆記整理



  1. Create VPC                                                                                                                                                                            首先選擇  VPC with a Single Public Subnet Only,逐步按continue即可
  2. 這裡我們只使用一個subnet 10.0.0.0/24                                         
      
  3. Launch  EC2 instance with  OpenVpn                                                                                          首這裡比較需要注意是要溝選掛在EC2-VPC
        輸入keypair記得按download下來之後ssh登錄需要使用
因為我是要裝openvpn所以相關port要打開
安裝完之後會自動啟動, 根據文件disable Change Source/Dest. Check.
Disable Source/Dest checking on both instances by right-clicking the instances and selecting Change Source/Dest. Check.
  1. Configure the Linux instances to route traffic by editing /etc/sysctl.conf and change the net.ipv4.ip_forward variable from 0 to 1
  2. Prompt> sudo vi /etc/sysctl.conf
  3. net.ipv4.ip_forward = 1
  4. Restart your network settings for the network forwarding settings to take effect.
  5. Prompt> sudo service network restart

接下來Elastic IPs allocate一個ip給 instance,然後使用putty ssh登錄
參考阿正老師的登錄方式
因為EC2的金鑰是以.pem檔來儲存,Putty無法直接使用,因此我們必須先下載Puttygen來做金鑰的轉檔
若不想每次進去都要使用金鑰

Ubuntu版  第一次登錄時請使用帳號ubuntu
※免憑證登入EC2
如果覺得每次登入都給用金鑰很麻煩, 可以將金鑰登入方式改成帳號密碼..
1. 以root身份修改 sudo vim /etc/ssh/sshd_config, 把
PasswordAuthentication no 改成
PasswordAuthentication yes
2. 重新啟動sshd
sudo service ssh restart 跟centos 版不一樣
接著設定使用帳號的密碼即可.

Centos版 第一次登錄時請使用帳號ec2-user
因為ec2的vps預設不讓你用su指令切換成root,因此可以輸入下面這行指令換掉root的密碼:
sudo passwd root

1.以root的身份修改 /etc/ssh/sshd_config,找到第60行 PasswordAuthentication no,把no改成yes,如下圖
2.然後重新啟動sshd


sudo /sbin/service sshd restart
然後以root身份輸入
passwd ec2-user

改掉預設使用者「ec2-user」的密碼,以後再用putty登入ssh時就可以不用選擇金鑰檔,只要直接輸入密碼就可以登入EC2的虛擬機器了。

centos版openvpn安裝

yum  update

yum -y install openvpn

cd /usr/share/openvpn/easy-rsa/2.0 
可以先vim vars文件修改國家省份等資訊建憑證時要用

source vars
./clean-all  
./build-ca  
./build-key-server server  
./build-dh   
在此可順便建client的憑證 要使用幾個client就要建幾個,之後安裝client openvpn可以使用
./build-key client1  
./build-key client2 
./build-key client3  


這樣server端憑證就建完了會產生在一個keys的資料夾
cp  -r keys   /etc/openvpn

找到server.conf的sample來修改
cp /usr/share/doc/openvpn-2.2.2/sample-config-files/server.conf    /etc/openvpn

vim /server.conf 如下:

# Which local IP address should OpenVPN
# listen on? (optional)
;local a.b.c.d

# Which TCP/UDP port should OpenVPN listen on?
# If you want to run multiple OpenVPN instances
# on the same machine, use a different port
# number for each one.  You will need to
# open up this port on your firewall.
port 1194

# TCP or UDP server?
;proto tcp
proto udp

# "dev tun" will create a routed IP tunnel,
# "dev tap" will create an ethernet tunnel.
# Use "dev tap0" if you are ethernet bridging
# and have precreated a tap0 virtual interface
# and bridged it with your ethernet interface.
# If you want to control access policies
# over the VPN, you must create firewall
# rules for the the TUN/TAP interface.
# On non-Windows systems, you can give
# an explicit unit number, such as tun0.
# On Windows, use "dev-node" for this.
# On most systems, the VPN will not function
# unless you partially or fully disable
# the firewall for the TUN/TAP interface.
;dev tap
dev tun

# Windows needs the TAP-Win32 adapter name
# from the Network Connections panel if you
# have more than one.  On XP SP2 or higher,
# you may need to selectively disable the
# Windows firewall for the TAP adapter.
# Non-Windows systems usually don't need this.
;dev-node MyTap

# SSL/TLS root certificate (ca), certificate
# (cert), and private key (key).  Each client
# and the server must have their own cert and
# key file.  The server and all clients will
# use the same ca file.
#
# See the "easy-rsa" directory for a series
# of scripts for generating RSA certificates
# and private keys.  Remember to use
# a unique Common Name for the server
# and each of the client certificates.
#
# Any X509 key management system can be used.
# OpenVPN can also use a PKCS #12 formatted key file
# (see "pkcs12" directive in man page).
ca /etc/openvpn/keys/ca.crt
cert /etc/openvpn/keys/server.crt
key /etc/openvpn/keys/server.key  # This file should be kept secret
# Diffie hellman parameters.
# Generate your own with:
#   openssl dhparam -out dh1024.pem 1024
# Substitute 2048 for 1024 if you are using
# 2048 bit keys.
dh /etc/openvpn/keys/dh1024.pem

# Configure server mode and supply a VPN subnet
# for OpenVPN to draw client addresses from.
# The server will take 10.8.0.1 for itself,
# the rest will be made available to clients.
# Each client will be able to reach the server
# on 10.8.0.1. Comment this line out if you are
# ethernet bridging. See the man page for more info.
server 10.8.0.0 255.255.255.0 #openvpn 啟動時subnet會是10.8.0.1/24, ip:10.8.0.1

# Maintain a record of client <-> virtual IP address
# associations in this file.  If OpenVPN goes down or
# is restarted, reconnecting clients can be assigned
# the same virtual IP address from the pool that was
# previously assigned.
ifconfig-pool-persist ipp.txt

# Configure server mode for ethernet bridging.
# You must first use your OS's bridging capability
# to bridge the TAP interface with the ethernet
# NIC interface.  Then you must manually set the
# IP/netmask on the bridge interface, here we
# assume 10.8.0.4/255.255.255.0.  Finally we
# must set aside an IP range in this subnet
# (start=10.8.0.50 end=10.8.0.100) to allocate
# to connecting clients.  Leave this line commented
# out unless you are ethernet bridging.
;server-bridge 10.8.0.4 255.255.255.0 10.8.0.50 10.8.0.100

# Configure server mode for ethernet bridging
# using a DHCP-proxy, where clients talk
# to the OpenVPN server-side DHCP server
# to receive their IP address allocation
# and DNS server addresses.  You must first use
# your OS's bridging capability to bridge the TAP
# interface with the ethernet NIC interface.
# Note: this mode only works on clients (such as
# Windows), where the client-side TAP adapter is
# bound to a DHCP client.
;server-bridge

# Push routes to the client to allow it
# to reach other private subnets behind
# the server.  Remember that these
# private subnets will also need
# to know to route the OpenVPN client
# address pool (10.8.0.0/255.255.255.0)
# back to the OpenVPN server.
;push "route 192.168.10.0 255.255.255.0"
;push "route 192.168.20.0 255.255.255.0"
push "route 10.0.0.0 255.255.255.0"  
#push route vpc的subnet 10.0.0.0/24 這樣 10.8.0.0網段才可以連到10.0.0.0網段
 只設定上面筆電連上vpn後只能ping到vpn主機1.0.0.99(有設elastic ip)
另一台private ip卻ping不到,後來在vpc route tables add 10.8.0.0/24即可成功(要選擇 association with 10.0.0.0/24 subnet)

# To assign specific IP addresses to specific
# clients or if a connecting client has a private
# subnet behind it that should also have VPN access,
# use the subdirectory "ccd" for client-specific
# configuration files (see man page for more info).

# EXAMPLE: Suppose the client
# having the certificate common name "Thelonious"
# also has a small subnet behind his connecting
# machine, such as 192.168.40.128/255.255.255.248.
# First, uncomment out these lines:
;client-config-dir ccd
;route 192.168.40.128 255.255.255.248

#client-config-dir /etc/openvpn/ccd
#route 124.0.0.0 255.255.255.0
# Then create a file ccd/Thelonious with this line:
#   iroute 192.168.40.128 255.255.255.248
# This will allow Thelonious' private subnet to
# access the VPN.  This example will only work
# if you are routing, not bridging, i.e. you are
# using "dev tun" and "server" directives.

# EXAMPLE: Suppose you want to give
# Thelonious a fixed VPN IP address of 10.9.0.1.
# First uncomment out these lines:
;client-config-dir ccd
;route 10.9.0.0 255.255.255.252
# Then add this line to ccd/Thelonious:
#   ifconfig-push 10.9.0.1 10.9.0.2

# Suppose that you want to enable different
# firewall access policies for different groups
# of clients.  There are two methods:
# (1) Run multiple OpenVPN daemons, one for each
#     group, and firewall the TUN/TAP interface
#     for each group/daemon appropriately.
# (2) (Advanced) Create a script to dynamically
#     modify the firewall in response to access
#     from different clients.  See man
#     page for more info on learn-address script.
;learn-address ./script

# If enabled, this directive will configure
# all clients to redirect their default
# network gateway through the VPN, causing
# all IP traffic such as web browsing and
# and DNS lookups to go through the VPN
# (The OpenVPN server machine may need to NAT
# or bridge the TUN/TAP interface to the internet
# in order for this to work properly).
;push "redirect-gateway def1 bypass-dhcp"

# Certain Windows-specific network settings
# can be pushed to clients, such as DNS
# or WINS server addresses.  CAVEAT:
# http://openvpn.net/faq.html#dhcpcaveats
# The addresses below refer to the public
# DNS servers provided by opendns.com.
;push "dhcp-option DNS 208.67.222.222"
;push "dhcp-option DNS 208.67.220.220"

# Uncomment this directive to allow different
# clients to be able to "see" each other.
# By default, clients will only see the server.
# To force clients to only see the server, you
# will also need to appropriately firewall the
# server's TUN/TAP interface.
;client-to-client

# Uncomment this directive if multiple clients
# might connect with the same certificate/key
# files or common names.  This is recommended
# only for testing purposes.  For production use,
# each client should have its own certificate/key
# pair.
#
# IF YOU HAVE NOT GENERATED INDIVIDUAL
# CERTIFICATE/KEY PAIRS FOR EACH CLIENT,
# EACH HAVING ITS OWN UNIQUE "COMMON NAME",
# UNCOMMENT THIS LINE OUT.
;duplicate-cn

# The keepalive directive causes ping-like
# messages to be sent back and forth over
# the link so that each side knows when
# the other side has gone down.
# Ping every 10 seconds, assume that remote
# peer is down if no ping received during
# a 120 second time period.
keepalive 10 120

# For extra security beyond that provided
# by SSL/TLS, create an "HMAC firewall"
# to help block DoS attacks and UDP port flooding.
#
# Generate with:
#   openvpn --genkey --secret ta.key
#
# The server and each client must have
# a copy of this key.
# The second parameter should be '0'
# on the server and '1' on the clients.
;tls-auth ta.key 0 # This file is secret

# Select a cryptographic cipher.
# This config item must be copied to
# the client config file as well.
;cipher BF-CBC        # Blowfish (default)
;cipher AES-128-CBC   # AES
;cipher DES-EDE3-CBC  # Triple-DES

# Enable compression on the VPN link.
# If you enable it here, you must also
# enable it in the client config file.
comp-lzo

# The maximum number of concurrently connected
# clients we want to allow.
;max-clients 100

# It's a good idea to reduce the OpenVPN
# daemon's privileges after initialization.
#
:
#
# You can uncomment this out on
# non-Windows systems.
;user nobody
;group nobody

# The persist options will try to avoid
# accessing certain resources on restart
# that may no longer be accessible because
# of the privilege downgrade.
persist-key
persist-tun

# Output a short status file showing
# current connections, truncated
# and rewritten every minute.
status openvpn-status.log

# By default, log messages will go to the syslog (or
# on Windows, if running as a service, they will go to
# the "\Program Files\OpenVPN\log" directory).
# Use log or log-append to override this default.
# "log" will truncate the log file on OpenVPN startup,
# while "log-append" will append to it.  Use one
# or the other (but not both).
;log         openvpn.log
;log-append  openvpn.log

# Set the appropriate level of log
# file verbosity.
#
# 0 is silent, except for fatal errors
# 4 is reasonable for general usage
# 5 and 6 can help to debug connection problems
# 9 is extremely verbose
verb 3

# Silence repeating messages.  At most 20
# sequential messages of the same message
# category will be output to the log.
;mute 20


儲存後可開啟server

sudo service openvpn restart
sudo service openvpn stop
sudo /etc/init.d/openvpn restart
sudo /etc/init.d/openvpn stop


安裝window7 openvpn client



  • 開啟瀏覽器搜尋”openvpn gui”,搜尋後點選 “OpenVPN GUI for Windows” 。
  • Download 裡,點選一個stable選項。
  • 請選擇如下安裝:Installation Package(Both 32-bit and 64-bit TAP driver included):openvpn-2.0.9-gui-1.0.3-install.exe
  • 於下載好的位置,會看到openvpn-2.0.9-gui-1.0.3-install.exe軟體,請安裝好(安裝過程,都預設安裝即可) 。


  • win7安裝很多問題,記得去網路找
    openvpn-2.1_rc15-install這版本安裝,安裝前要先勾選如下圖,安裝時請按右鍵使用系統管理員身份安裝即可




    將keys產生的相關憑證copy至以下,要設定client.ovpn
     C:\Program Files (x86)\OpenVPN\config
    之後connect即可連上vpn






    也可以安裝商業版的有webadmin可以設定,但只有兩個free client
    其它references可參考
     http://mackung.blogspot.tw/2012/11/amazon-web-service-openvpn.html