{"id":17620,"date":"2025-12-18T22:49:58","date_gmt":"2025-12-18T19:19:58","guid":{"rendered":"https:\/\/www.itpiran.net\/blog\/?p=17620"},"modified":"2025-12-18T22:57:27","modified_gmt":"2025-12-18T19:27:27","slug":"openconnect-ocserv-ubuntu-22-04","status":"publish","type":"post","link":"https:\/\/www.itpiran.net\/blog\/de\/os\/ubuntu\/openconnect-ocserv-ubuntu-22-04\/","title":{"rendered":"So installieren und konfigurieren Sie den OpenConnect-Server (ocserv) unter Ubuntu 22.04 mit Let&#039;s Encrypt"},"content":{"rendered":"\n<p>&nbsp;<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-intro\"><span id=\"%da%86%d9%87-%da%86%db%8c%d8%b2%d9%87%d8%a7%db%8c%db%8c-%d8%af%d8%b1-%d8%a7%db%8c%d9%86-%d8%b1%d8%a7%d9%87%d9%86%d9%85%d8%a7%db%8c-%d9%81%d9%86%db%8c-%d9%be%d9%88%d8%b4%d8%b4-%d8%af%d8%a7%d8%af%d9%87\">\u0686\u0647 \u0686\u06cc\u0632\u0647\u0627\u06cc\u06cc \u062f\u0631 \u0627\u06cc\u0646 \u0631\u0627\u0647\u0646\u0645\u0627\u06cc \u0641\u0646\u06cc \u067e\u0648\u0634\u0634 \u062f\u0627\u062f\u0647 \u0645\u06cc\u200c\u0634\u0648\u062f\u061f<\/span><\/h2>\n<p class=\"wp-block-paragraph\">\u062f\u0631 \u0627\u06cc\u0646 \u0631\u0627\u0647\u0646\u0645\u0627\u06cc \u0641\u0646\u06cc \u06af\u0627\u0645\u200c\u0628\u0647\u200c\u06af\u0627\u0645 \u0646\u062d\u0648\u0647\u0654 \u0631\u0627\u0647\u200c\u0627\u0646\u062f\u0627\u0632\u06cc \u0633\u0631\u0648\u06cc\u0633 <strong>OpenConnect (ocserv)<\/strong> \u0631\u0648\u06cc <em>Ubuntu 22.04<\/em> \u0647\u0645\u0631\u0627\u0647 \u0628\u0627 \u062f\u0631\u06cc\u0627\u0641\u062a \u0648 \u0645\u062f\u06cc\u0631\u06cc\u062a \u06af\u0648\u0627\u0647\u06cc\u200c\u0647\u0627\u06cc <strong>Let\u2019s Encrypt<\/strong>\u060c \u067e\u06cc\u06a9\u0631\u0628\u0646\u062f\u06cc \u0627\u0645\u0646\u060c \u062a\u0646\u0638\u06cc\u0645\u0627\u062a \u0641\u0627\u06cc\u0631\u0648\u0627\u0644 \u0648 NAT\u060c \u0627\u062d\u0631\u0627\u0632 \u0647\u0648\u06cc\u062a \u06a9\u0627\u0631\u0628\u0631\u0627\u0646\u060c \u0648 \u0646\u06a9\u0627\u062a \u0645\u0631\u0628\u0648\u0637 \u0628\u0647 \u0627\u062a\u0635\u0627\u0644 \u06a9\u0644\u0627\u06cc\u0646\u062a\u200c\u0647\u0627 \u0648 \u0627\u062a\u0648\u0645\u0627\u0633\u06cc\u0648\u0646 \u062a\u0645\u062f\u06cc\u062f \u06af\u0648\u0627\u0647\u06cc \u067e\u0648\u0634\u0634 \u062f\u0627\u062f\u0647 \u0634\u062f\u0647 \u0627\u0633\u062a.<\/p>\n<blockquote class=\"wp-block-quote\"><p>\u0628\u0631\u0627\u06cc \u0645\u062d\u06cc\u0637\u200c\u0647\u0627\u06cc \u062d\u0633\u0627\u0633 \u0645\u0627\u0646\u0646\u062f \u062a\u0631\u06cc\u062f\u060c \u06af\u06cc\u0645\u06cc\u0646\u06af \u06cc\u0627 \u062f\u0633\u062a\u0631\u0633\u06cc \u0633\u0627\u0632\u0645\u0627\u0646\u06cc\u060c \u0627\u0646\u062a\u062e\u0627\u0628 \u0644\u0648\u06a9\u06cc\u0634\u0646 \u0645\u0646\u0627\u0633\u0628 \u0648 \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u0627\u0632 \u0633\u0631\u0648\u0631\u0647\u0627\u06cc \u062f\u0627\u0631\u0627\u06cc \u062d\u0641\u0627\u0638\u062a \u0636\u062f DDoS \u0628\u0633\u06cc\u0627\u0631 \u0645\u0647\u0645 \u0627\u0633\u062a. \u0634\u0631\u06a9\u062a \u0645\u0627 \u0628\u06cc\u0634 \u0627\u0632 85+ \u0644\u0648\u06a9\u06cc\u0634\u0646 \u062c\u0647\u0627\u0646\u06cc\u060c \u0633\u0631\u0648\u0631\u0647\u0627\u06cc \u0636\u062f DDoS \u0648 \u0634\u0628\u06a9\u0647 BGP \u0631\u0627 \u0627\u0631\u0627\u0626\u0647 \u0645\u06cc\u200c\u062f\u0647\u062f.<\/p><\/blockquote>\n<p>&nbsp;<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-prereq\"><span id=\"%d9%be%db%8c%d8%b4%d9%86%db%8c%d8%a7%d8%b2%d9%87%d8%a7-%d9%88-%d8%a7%d9%86%d8%aa%d8%ae%d8%a7%d8%a8-%d9%84%d9%88%da%a9%db%8c%d8%b4%d9%86\">\u067e\u06cc\u0634\u200c\u0646\u06cc\u0627\u0632\u0647\u0627 \u0648 \u0627\u0646\u062a\u062e\u0627\u0628 \u0644\u0648\u06a9\u06cc\u0634\u0646<\/span><\/h2>\n<p class=\"wp-block-paragraph\">\u0642\u0628\u0644 \u0627\u0632 \u0634\u0631\u0648\u0639 \u0645\u0637\u0645\u0626\u0646 \u0634\u0648\u06cc\u062f \u06a9\u0647:<\/p>\n<ul>\n<li class=\"wp-block-paragraph\">\u06cc\u06a9 \u0633\u0631\u0648\u0631 <strong>Ubuntu 22.04<\/strong> \u0628\u0627 \u062f\u0633\u062a\u0631\u0633\u06cc root \u06cc\u0627 sudo \u062f\u0631 \u0627\u062e\u062a\u06cc\u0627\u0631 \u062f\u0627\u0631\u06cc\u062f.<\/li>\n<li class=\"wp-block-paragraph\">\u06cc\u06a9 \u062f\u0627\u0645\u0646\u0647 (\u0645\u062b\u0644\u0627\u064b <em>vpn.example.com<\/em>) \u0628\u0647 IP \u0633\u0631\u0648\u0631 \u0627\u0634\u0627\u0631\u0647 \u0645\u06cc\u200c\u06a9\u0646\u062f.<\/li>\n<li class=\"wp-block-paragraph\">\u067e\u0648\u0631\u062a\u200c\u0647\u0627\u06cc <strong>80<\/strong> \u0648 <strong>443<\/strong> \u0631\u0648\u06cc \u0641\u0627\u06cc\u0631\u0648\u0627\u0644 \u0628\u0631\u0627\u06cc \u062f\u0631\u06cc\u0627\u0641\u062a \u06af\u0648\u0627\u0647\u06cc Let\u2019s Encrypt \u0628\u0627\u0632 \u0647\u0633\u062a\u0646\u062f.<\/li>\n<\/ul>\n<p class=\"wp-block-paragraph\"><strong>\u0686\u0631\u0627 \u0644\u0648\u06a9\u06cc\u0634\u0646 \u0645\u0647\u0645 \u0627\u0633\u062a\u061f<\/strong><\/p>\n<ul>\n<li class=\"wp-block-paragraph\">\u0628\u0631\u0627\u06cc \u062a\u0631\u06cc\u062f\u0631\u0647\u0627 \u0648 \u06af\u06cc\u0645\u0631\u0647\u0627\u060c \u0627\u0646\u062a\u062e\u0627\u0628 \u0644\u0648\u06a9\u06cc\u0634\u0646 \u0628\u0627 \u067e\u06cc\u0646\u06af \u067e\u0627\u06cc\u06cc\u0646 (\u0645\u062b\u0644\u0627\u064b London\u060c Frankfurt \u06cc\u0627 Tokyo) \u0627\u0648\u0644\u0648\u06cc\u062a \u062f\u0627\u0631\u062f.<\/li>\n<li class=\"wp-block-paragraph\">\u0633\u0627\u0632\u0645\u0627\u0646\u200c\u0647\u0627 \u0645\u0645\u06a9\u0646 \u0627\u0633\u062a \u0628\u0647 \u0686\u0646\u062f \u0644\u0648\u06a9\u06cc\u0634\u0646 \u0628\u0627 BGP \u0648 CDN \u0646\u06cc\u0627\u0632 \u062f\u0627\u0634\u062a\u0647 \u0628\u0627\u0634\u0646\u062f \u062a\u0627 \u067e\u0627\u06cc\u062f\u0627\u0631\u06cc \u0627\u0641\u0632\u0627\u06cc\u0634 \u06cc\u0627\u0628\u062f.<\/li>\n<li class=\"wp-block-paragraph\">\u0628\u0631\u0627\u06cc \u062d\u0641\u0627\u0638\u062a \u0648 \u067e\u0627\u06cc\u062f\u0627\u0631\u06cc\u060c \u0633\u0631\u0648\u0631\u0647\u0627\u06cc \u062f\u0627\u0631\u0627\u06cc \u0645\u062d\u0627\u0641\u0638\u062a \u0636\u062f DDoS \u062a\u0648\u0635\u06cc\u0647 \u0645\u06cc\u200c\u0634\u0648\u0646\u062f.<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-install\"><span id=\"%d9%86%d8%b5%d8%a8-ocserv-%d9%88-%d8%a8%d8%b3%d8%aa%d9%87%d9%87%d8%a7%db%8c-%d9%85%d9%88%d8%b1%d8%af-%d9%86%db%8c%d8%a7%d8%b2\">\u0646\u0635\u0628 ocserv \u0648 \u0628\u0633\u062a\u0647\u200c\u0647\u0627\u06cc \u0645\u0648\u0631\u062f \u0646\u06cc\u0627\u0632<\/span><\/h2>\n<p class=\"wp-block-paragraph\">\u0627\u0628\u062a\u062f\u0627 \u0633\u06cc\u0633\u062a\u0645 \u0631\u0627 \u0628\u0647\u200c\u0631\u0648\u0632 \u06a9\u0646\u06cc\u062f \u0648 \u0628\u0633\u062a\u0647\u200c\u0647\u0627\u06cc \u067e\u0627\u06cc\u0647 \u0631\u0627 \u0646\u0635\u0628 \u06a9\u0646\u06cc\u062f:<\/p>\n<div class=\"hcb_wrap\">\n<pre class=\"prism line-numbers lang-bash\" data-lang=\"Bash\"><code>sudo apt update &amp;&amp; sudo apt upgrade -y\r\nsudo apt install ocserv certbot libnss3-tools -y<\/code><\/pre>\n<\/div>\n<p class=\"wp-block-paragraph\">\u0628\u0633\u062a\u0647\u200c\u0647\u0627\u06cc \u067e\u06cc\u0634\u0646\u0647\u0627\u062f\u06cc \u0628\u0631\u0627\u06cc \u0645\u062d\u06cc\u0637 \u0639\u0645\u0644\u06cc\u0627\u062a\u06cc:<\/p>\n<ul>\n<li class=\"wp-block-paragraph\">ufw \u06cc\u0627 nftables \u0628\u0631\u0627\u06cc \u0645\u062f\u06cc\u0631\u06cc\u062a \u0641\u0627\u06cc\u0631\u0648\u0627\u0644<\/li>\n<li class=\"wp-block-paragraph\">fail2ban \u0628\u0631\u0627\u06cc \u0645\u062d\u0627\u0641\u0638\u062a \u062f\u0631 \u0628\u0631\u0627\u0628\u0631 \u062d\u0645\u0644\u0627\u062a brute\u2011force<\/li>\n<li class=\"wp-block-paragraph\">openssl \u06cc\u0627 gnutls\u2011bin \u062f\u0631 \u0635\u0648\u0631\u062a \u0646\u06cc\u0627\u0632 \u0628\u0647 \u062a\u0633\u062a TLS<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-cert\"><span id=\"%d8%af%d8%b1%db%8c%d8%a7%d9%81%d8%aa-%da%af%d9%88%d8%a7%d9%87%db%8c-lets-encrypt-%d8%b1%d9%88%d8%b4%d9%87%d8%a7\">\u062f\u0631\u06cc\u0627\u0641\u062a \u06af\u0648\u0627\u0647\u06cc Let\u2019s Encrypt (\u0631\u0648\u0634\u200c\u0647\u0627)<\/span><\/h2>\n<p class=\"wp-block-paragraph\">\u062f\u0648 \u0631\u0648\u0634 \u0645\u0639\u0645\u0648\u0644 \u0628\u0631\u0627\u06cc \u062f\u0631\u06cc\u0627\u0641\u062a \u06af\u0648\u0627\u0647\u06cc:<\/p>\n<h3 class=\"wp-block-heading\" id=\"h-cert-nginx\"><span id=\"%d8%b1%d9%88%d8%b4-a-%d8%a8%d8%a7-%d8%a7%d8%b3%d8%aa%d9%81%d8%a7%d8%af%d9%87-%d8%a7%d8%b2-nginx-%d8%af%d8%b1-%d8%b5%d9%88%d8%b1%d8%aa-%d9%88%d8%ac%d9%88%d8%af-%d9%88%d8%a8%d8%b3\">\u0631\u0648\u0634 A \u2014 \u0628\u0627 \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u0627\u0632 nginx (\u062f\u0631 \u0635\u0648\u0631\u062a \u0648\u062c\u0648\u062f \u0648\u0628\u200c\u0633\u0631\u0648\u0631)<\/span><\/h3>\n<p class=\"wp-block-paragraph\">\u0627\u06af\u0631 nginx \u062f\u0627\u0631\u06cc\u062f\u060c \u0645\u06cc\u200c\u062a\u0648\u0627\u0646\u06cc\u062f virtual host \u0631\u0627 \u0641\u0639\u0627\u0644 \u06a9\u0631\u062f\u0647 \u0648 \u0627\u0632 certbot \u0628\u0627 \u067e\u0644\u0627\u06af\u06cc\u0646 nginx \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u06a9\u0646\u06cc\u062f:<\/p>\n<div class=\"hcb_wrap\">\n<pre class=\"prism line-numbers lang-bash\" data-lang=\"Bash\"><code>sudo apt install nginx\r\nsudo certbot --nginx -d vpn.example.com<\/code><\/pre>\n<\/div>\n<p class=\"wp-block-paragraph\">\u0633\u067e\u0633 \u062f\u0631 \u0641\u0627\u06cc\u0644 \u067e\u06cc\u06a9\u0631\u0628\u0646\u062f\u06cc ocserv \u0645\u0633\u06cc\u0631 \u06af\u0648\u0627\u0647\u06cc \u0631\u0627 \u0628\u0647\u200c\u0635\u0648\u0631\u062a \u0632\u06cc\u0631 \u062a\u0639\u06cc\u06cc\u0646 \u06a9\u0646\u06cc\u062f:<\/p>\n<div class=\"hcb_wrap\">\n<pre class=\"prism line-numbers lang-bash\" data-lang=\"Bash\"><code>server-cert = \/etc\/letsencrypt\/live\/vpn.example.com\/fullchain.pem\r\nserver-key = \/etc\/letsencrypt\/live\/vpn.example.com\/privkey.pem<\/code><\/pre>\n<\/div>\n<h3 class=\"wp-block-heading\" id=\"h-cert-standalone\"><span id=\"%d8%b1%d9%88%d8%b4-b-standalone-%d8%a7%da%af%d8%b1-nginx-%d9%86%d8%af%d8%a7%d8%b1%db%8c%d8%af\">\u0631\u0648\u0634 B \u2014 standalone (\u0627\u06af\u0631 nginx \u0646\u062f\u0627\u0631\u06cc\u062f)<\/span><\/h3>\n<p class=\"wp-block-paragraph\">\u0686\u0648\u0646 ocserv \u0628\u0647\u200c\u0637\u0648\u0631 \u067e\u06cc\u0634\u200c\u0641\u0631\u0636 \u0628\u0647 \u067e\u0648\u0631\u062a 443 \u06af\u0648\u0634 \u0645\u06cc\u200c\u062f\u0647\u062f\u060c \u0642\u0628\u0644 \u0627\u0632 \u0627\u062c\u0631\u0627\u06cc certbot standalone \u0628\u0627\u06cc\u062f ocserv \u0631\u0627 \u0645\u0648\u0642\u062a\u0627\u064b \u0645\u062a\u0648\u0642\u0641 \u06a9\u0646\u06cc\u062f \u06cc\u0627 \u0627\u0632 DNS challenge \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u06a9\u0646\u06cc\u062f:<\/p>\n<div class=\"hcb_wrap\">\n<pre class=\"prism line-numbers lang-bash\" data-lang=\"Bash\"><code>sudo systemctl stop ocserv\r\nsudo certbot certonly --standalone -d vpn.example.com\r\nsudo systemctl start ocserv<\/code><\/pre>\n<\/div>\n<div class=\"pk-alert pk-alert-warning\" role=\"alert\" >\n\u0628\u0631\u0627\u06cc \u062a\u062c\u062f\u06cc\u062f \u062e\u0648\u062f\u06a9\u0627\u0631 \u06af\u0648\u0627\u0647\u06cc\u060c \u0627\u06af\u0631 nginx \u06cc\u0627 reverse proxy \u062f\u0627\u0631\u06cc\u062f \u0627\u0632 reload \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u06a9\u0646\u06cc\u062f. \u0627\u06af\u0631 \u0627\u0632 standalone \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u0645\u06cc\u200c\u06a9\u0646\u06cc\u062f \u0648 ocserv \u0631\u0648\u06cc 443 \u0641\u0639\u0627\u0644 \u0627\u0633\u062a\u060c \u0628\u0647\u062a\u0631 \u0627\u0633\u062a \u0627\u0632 DNS challenge \u06cc\u0627 pre\/post hooks \u0628\u0647\u0631\u0647 \u0628\u0628\u0631\u06cc\u062f.<br \/>\n<\/div>\n<p>&nbsp;<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-config\"><span id=\"%d9%be%db%8c%da%a9%d8%b1%d8%a8%d9%86%d8%af%db%8c-ocserv-%d9%86%d9%85%d9%88%d9%86%d9%87-ocserv-conf\">\u067e\u06cc\u06a9\u0631\u0628\u0646\u062f\u06cc ocserv \u2014 \u0646\u0645\u0648\u0646\u0647 ocserv.conf<\/span><\/h2>\n<p class=\"wp-block-paragraph\">\u0641\u0627\u06cc\u0644 \u0627\u0635\u0644\u06cc \u067e\u06cc\u06a9\u0631\u0628\u0646\u062f\u06cc: <code>\/etc\/ocserv\/ocserv.conf<\/code>. \u0646\u0645\u0648\u0646\u0647 \u0628\u062e\u0634\u200c\u0647\u0627\u06cc \u06a9\u0644\u06cc\u062f\u06cc:<\/p>\n<div class=\"hcb_wrap\">\n<pre class=\"prism line-numbers lang-bash\" data-lang=\"Bash\"><code># ports\r\ntcp-port = 443\r\nudp-port = 443\r\n\r\n# certificates\r\nserver-cert = \/etc\/letsencrypt\/live\/vpn.example.com\/fullchain.pem\r\nserver-key = \/etc\/letsencrypt\/live\/vpn.example.com\/privkey.pem\r\n\r\n# network\r\ndefault-domain = vpn.example.com\r\ndns = 1.1.1.1\r\ndns = 1.0.0.1\r\nroute = 0.0.0.0\/0\r\nno-route = 192.168.0.0\/16\r\n\r\n# limits\r\nmax-clients = 250\r\nmax-same-clients = 2\r\n\r\n# security and performance\r\nkeepalive = 60\r\nauth = \"plain[passwd=\/etc\/ocserv\/ocpasswd]\"\r\ncompression = false\r\ntls-priorities = \"NORMAL:-VERS-TLS-ALL:+VERS-TLS1.2\"\r\nallow-roaming = true<\/code><\/pre>\n<\/div>\n<p class=\"wp-block-paragraph\"><strong>\u062a\u0648\u0636\u06cc\u062d\u0627\u062a \u0645\u0647\u0645:<\/strong> <em>route = 0.0.0.0\/0<\/em> \u0628\u0631\u0627\u06cc Full Tunnel \u0627\u0633\u062a. \u0628\u0631\u0627\u06cc Split\u2011Tunnel \u0641\u0642\u0637 \u0634\u0628\u06a9\u0647\u200c\u0647\u0627\u06cc \u0645\u0648\u0631\u062f \u0646\u06cc\u0627\u0632 \u0631\u0627 \u0627\u0636\u0627\u0641\u0647 \u06a9\u0646\u06cc\u062f. \u0628\u0647\u200c\u062f\u0644\u0627\u06cc\u0644 \u0627\u0645\u0646\u06cc\u062a\u06cc <em>compression = false<\/em> \u062a\u0648\u0635\u06cc\u0647 \u0645\u06cc\u200c\u0634\u0648\u062f.<\/p>\n<p>&nbsp;<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-firewall\"><span id=\"%d8%aa%d9%86%d8%b8%db%8c%d9%85%d8%a7%d8%aa-%d9%81%d8%a7%db%8c%d8%b1%d9%88%d8%a7%d9%84-%d9%88-nat-ip-forwarding\">\u062a\u0646\u0638\u06cc\u0645\u0627\u062a \u0641\u0627\u06cc\u0631\u0648\u0627\u0644 \u0648 NAT (IP forwarding)<\/span><\/h2>\n<p class=\"wp-block-paragraph\">\u0641\u0639\u0627\u0644\u200c\u0633\u0627\u0632\u06cc IP forwarding:<\/p>\n<div class=\"hcb_wrap\">\n<pre class=\"prism line-numbers lang-bash\" data-lang=\"Bash\"><code>sudo sysctl -w net.ipv4.ip_forward=1\r\necho \"net.ipv4.ip_forward=1\" | sudo tee -a \/etc\/sysctl.conf<\/code><\/pre>\n<\/div>\n<p class=\"wp-block-paragraph\">\u0646\u0645\u0648\u0646\u0647 \u0642\u0648\u0627\u0639\u062f iptables \u0628\u0631\u0627\u06cc NAT (\u0641\u0631\u0636 interface \u062e\u0631\u0648\u062c\u06cc eth0 \u0648 \u0634\u0628\u06a9\u0647 \u062f\u0627\u062e\u0644\u06cc 10.10.10.0\/24):<\/p>\n<div class=\"hcb_wrap\">\n<pre class=\"prism line-numbers lang-bash\" data-lang=\"Bash\"><code>sudo iptables -t nat -A POSTROUTING -o eth0 -j MASQUERADE\r\nsudo iptables -A FORWARD -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT\r\nsudo iptables -A FORWARD -s 10.10.10.0\/24 -j ACCEPT<\/code><\/pre>\n<\/div>\n<p class=\"wp-block-paragraph\">\u0628\u0631\u0627\u06cc \u062d\u0641\u0638 \u0642\u0648\u0627\u0639\u062f \u067e\u0633 \u0627\u0632 \u0631\u0627\u0647\u200c\u0627\u0646\u062f\u0627\u0632\u06cc \u0645\u062c\u062f\u062f \u0627\u0632 iptables-persistent \u06cc\u0627 \u0630\u062e\u06cc\u0631\u0647 config \u062f\u0631 nftables \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u06a9\u0646\u06cc\u062f.<\/p>\n<p class=\"wp-block-paragraph\">\u0646\u0645\u0648\u0646\u0647 \u062f\u0633\u062a\u0648\u0631\u0627\u062a UFW:<\/p>\n<div class=\"hcb_wrap\">\n<pre class=\"prism line-numbers lang-bash\" data-lang=\"Bash\"><code>sudo ufw allow 443\/tcp\r\nsudo ufw allow 443\/udp\r\nsudo ufw allow 80\/tcp\r\nsudo ufw enable<\/code><\/pre>\n<\/div>\n<p>&nbsp;<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-auth\"><span id=\"%d8%a7%d8%ad%d8%b1%d8%a7%d8%b2-%d9%87%d9%88%db%8c%d8%aa-%d9%88-%d9%85%d8%af%db%8c%d8%b1%db%8c%d8%aa-%da%a9%d8%a7%d8%b1%d8%a8%d8%b1%d8%a7%d9%86\">\u0627\u062d\u0631\u0627\u0632 \u0647\u0648\u06cc\u062a \u0648 \u0645\u062f\u06cc\u0631\u06cc\u062a \u06a9\u0627\u0631\u0628\u0631\u0627\u0646<\/span><\/h2>\n<p class=\"wp-block-paragraph\">\u0631\u0648\u0634 \u0633\u0627\u062f\u0647 \u0645\u0628\u062a\u0646\u06cc \u0628\u0631 \u0641\u0627\u06cc\u0644 passwd \u0645\u062d\u0644\u06cc:<\/p>\n<div class=\"hcb_wrap\">\n<pre class=\"prism line-numbers lang-bash\" data-lang=\"Bash\"><code>sudo ocpasswd -c \/etc\/ocserv\/ocpasswd alice<\/code><\/pre>\n<\/div>\n<p class=\"wp-block-paragraph\">\u0645\u06cc\u200c\u062a\u0648\u0627\u0646\u06cc\u062f \u0627\u0632 <em>PAM<\/em> \u0628\u0631\u0627\u06cc \u06cc\u06a9\u067e\u0627\u0631\u0686\u0647\u200c\u0633\u0627\u0632\u06cc \u0628\u0627 LDAP\/AD \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u06a9\u0646\u06cc\u062f (\u062a\u0646\u0638\u06cc\u0645 <code>auth = \"pam\"<\/code> \u062f\u0631 ocserv.conf).<\/p>\n<p class=\"wp-block-paragraph\">\u0628\u0631\u0627\u06cc \u0627\u062d\u0631\u0627\u0632 \u0647\u0648\u06cc\u062a \u0645\u0628\u062a\u0646\u06cc \u0628\u0631 \u06af\u0648\u0627\u0647\u06cc (x.509) \u062a\u0648\u0644\u06cc\u062f \u06a9\u0644\u06cc\u062f\/\u06af\u0648\u0627\u0647\u06cc \u06a9\u0644\u0627\u06cc\u0646\u062a:<\/p>\n<div class=\"hcb_wrap\">\n<pre class=\"prism line-numbers lang-bash\" data-lang=\"Bash\"><code>sudo certtool --generate-privkey --outfile client-key.pem\r\nsudo certtool --generate-certificate --load-privkey client-key.pem --outfile client-cert.pem --template client.tmpl<\/code><\/pre>\n<\/div>\n<p class=\"wp-block-paragraph\">\u0628\u0631\u0627\u06cc \u0627\u0641\u0632\u0648\u062f\u0646 2FA \u0645\u06cc\u200c\u062a\u0648\u0627\u0646\u06cc\u062f \u0627\u0632 <em>libpam-google-authenticator<\/em> \u0648 \u062a\u0646\u0638\u06cc\u0645 PAM \u062f\u0631 <code>\/etc\/pam.d\/ocserv<\/code> \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u06a9\u0646\u06cc\u062f.<\/p>\n<p>&nbsp;<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-hardening\"><span id=\"%d8%a7%d9%85%d9%86%db%8c%d8%aa%d8%8c-hardening-%d9%88-%d8%a8%d9%87%db%8c%d9%86%d9%87%d8%b3%d8%a7%d8%b2%db%8c\">\u0627\u0645\u0646\u06cc\u062a\u060c hardening \u0648 \u0628\u0647\u06cc\u0646\u0647\u200c\u0633\u0627\u0632\u06cc<\/span><\/h2>\n<ul>\n<li class=\"wp-block-paragraph\"><strong>\u0645\u062d\u062f\u0648\u062f \u06a9\u0631\u062f\u0646 \u0646\u0633\u062e\u0647\u200c\u0647\u0627\u06cc TLS<\/strong> \u0628\u0627 \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u0627\u0632 <code>tls-priorities<\/code>.<\/li>\n<li class=\"wp-block-paragraph\"><strong>\u063a\u06cc\u0631\u0641\u0639\u0627\u0644\u200c\u0633\u0627\u0632\u06cc compression<\/strong> \u0628\u0647 \u062f\u0644\u0627\u06cc\u0644 \u0627\u0645\u0646\u06cc\u062a\u06cc (\u0645\u0627\u0646\u0646\u062f CRIME).<\/li>\n<li class=\"wp-block-paragraph\">\u0645\u062d\u062f\u0648\u062f \u06a9\u0631\u062f\u0646 \u062a\u0639\u062f\u0627\u062f \u0627\u062a\u0635\u0627\u0644\u0627\u062a \u0647\u0645\u200c\u0632\u0645\u0627\u0646 (<code>max-same-clients<\/code>).<\/li>\n<li class=\"wp-block-paragraph\">\u0641\u0639\u0627\u0644 \u06a9\u0631\u062f\u0646 logging \u0648 \u0645\u0627\u0646\u06cc\u062a\u0648\u0631 \u0645\u0646\u0627\u0628\u0639.<\/li>\n<li class=\"wp-block-paragraph\">\u0646\u0635\u0628 \u0648 \u067e\u06cc\u06a9\u0631\u0628\u0646\u062f\u06cc fail2ban \u0628\u0631\u0627\u06cc \u062c\u0644\u0648\u06af\u06cc\u0631\u06cc \u0627\u0632 \u062a\u0644\u0627\u0634\u200c\u0647\u0627\u06cc \u0645\u06a9\u0631\u0631 \u0648\u0631\u0648\u062f.<\/li>\n<\/ul>\n<p class=\"wp-block-paragraph\">\u0646\u0645\u0648\u0646\u0647 \u062a\u0646\u0638\u06cc\u0645 \u0633\u0627\u062f\u0647 fail2ban:<\/p>\n<div class=\"hcb_wrap\">\n<pre class=\"prism line-numbers lang-bash\" data-lang=\"Bash\"><code>[ocserv]\r\nenabled = true\r\nport = 443\r\nfilter = ocserv\r\nlogpath = \/var\/log\/syslog\r\nmaxretry = 5<\/code><\/pre>\n<\/div>\n<p class=\"wp-block-paragraph\">\u0644\u0627\u0632\u0645 \u0627\u0633\u062a \u0641\u06cc\u0644\u062a\u0631 \u0645\u0646\u0627\u0633\u0628 (regex) \u0645\u0637\u0627\u0628\u0642 \u0644\u0627\u06af\u200c\u0647\u0627\u06cc ocserv \u0633\u0627\u062e\u062a\u0647 \u0634\u0648\u062f.<\/p>\n<p>&nbsp;<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-testing\"><span id=\"%d8%aa%d8%b3%d8%aa-%d9%88-%d8%a7%d8%aa%d8%b5%d8%a7%d9%84-%da%a9%d9%84%d8%a7%db%8c%d9%86%d8%aa%d9%87%d8%a7\">\u062a\u0633\u062a \u0648 \u0627\u062a\u0635\u0627\u0644 \u06a9\u0644\u0627\u06cc\u0646\u062a\u200c\u0647\u0627<\/span><\/h2>\n<p class=\"wp-block-paragraph\">\u06a9\u0644\u0627\u06cc\u0646\u062a \u062e\u0637 \u0641\u0631\u0645\u0627\u0646 \u0644\u06cc\u0646\u0648\u06a9\u0633 \u0628\u0627 <em>openconnect<\/em>:<\/p>\n<div class=\"hcb_wrap\">\n<pre class=\"prism line-numbers lang-bash\" data-lang=\"Bash\"><code>sudo apt install openconnect\r\nsudo openconnect vpn.example.com<\/code><\/pre>\n<\/div>\n<p class=\"wp-block-paragraph\">\u062f\u0631 \u062f\u0633\u06a9\u062a\u0627\u067e \u0644\u06cc\u0646\u0648\u06a9\u0633 \u0627\u0632 <em>network-manager-openconnect<\/em> \u0648 \u062f\u0631 Windows\/macOS \u0627\u0632 OpenConnect GUI \u06cc\u0627 Cisco AnyConnect-compatible clients \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u06a9\u0646\u06cc\u062f.<\/p>\n<p class=\"wp-block-paragraph\">\u0628\u0631\u0627\u06cc \u0628\u0631\u0631\u0633\u06cc \u0648\u0636\u0639\u06cc\u062a \u0633\u0631\u0648\u06cc\u0633:<\/p>\n<div class=\"hcb_wrap\">\n<pre class=\"prism line-numbers lang-bash\" data-lang=\"Bash\"><code>sudo systemctl status ocserv\r\nsudo journalctl -u ocserv -f<\/code><\/pre>\n<\/div>\n<p>&nbsp;<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-renewal\"><span id=\"%d8%a7%d8%aa%d9%88%d9%85%db%8c%d8%b4%d9%86-%d8%aa%d9%85%d8%af%db%8c%d8%af-%da%af%d9%88%d8%a7%d9%87%db%8c-%d9%88-%d9%86%da%af%d9%87%d8%af%d8%a7%d8%b1%db%8c\">\u0627\u062a\u0648\u200c\u0645\u06cc\u0634\u0646 \u062a\u0645\u062f\u06cc\u062f \u06af\u0648\u0627\u0647\u06cc \u0648 \u0646\u06af\u0647\u062f\u0627\u0631\u06cc<\/span><\/h2>\n<p class=\"wp-block-paragraph\">\u0627\u06af\u0631 \u0627\u0632 nginx \u06cc\u0627 apache \u0628\u0647\u200c\u0639\u0646\u0648\u0627\u0646 reverse proxy \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u0645\u06cc\u200c\u06a9\u0646\u06cc\u062f\u060c certbot \u0645\u0639\u0645\u0648\u0644\u0627\u064b \u0645\u06cc\u200c\u062a\u0648\u0627\u0646\u062f \u06af\u0648\u0627\u0647\u06cc \u0631\u0627 \u0628\u062f\u0648\u0646 \u062a\u0648\u0642\u0641 \u0633\u0631\u0648\u06cc\u0633 \u062a\u062c\u062f\u06cc\u062f \u06a9\u0646\u062f \u0648 \u067e\u0633 \u0627\u0632 \u062a\u062c\u062f\u06cc\u062f ocserv \u0631\u0627 \u0631\u06cc\u200c\u0644\u0648\u062f \u06a9\u0646\u06cc\u062f:<\/p>\n<div class=\"hcb_wrap\">\n<pre class=\"prism line-numbers lang-bash\" data-lang=\"Bash\"><code>sudo certbot renew --deploy-hook \"systemctl reload ocserv\"<\/code><\/pre>\n<\/div>\n<p class=\"wp-block-paragraph\">\u0627\u06af\u0631 \u0627\u0632 standalone \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u0645\u06cc\u200c\u06a9\u0646\u06cc\u062f \u0648 ocserv \u0631\u0648\u06cc 443 \u0641\u0639\u0627\u0644 \u0627\u0633\u062a\u060c \u06af\u0632\u06cc\u0646\u0647\u200c\u0647\u0627 \u0639\u0628\u0627\u0631\u062a\u200c\u0627\u0646\u062f \u0627\u0632 DNS challenge \u06cc\u0627 \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u0627\u0632 pre\/post hooks:<\/p>\n<div class=\"hcb_wrap\">\n<pre class=\"prism line-numbers lang-bash\" data-lang=\"Bash\"><code>sudo certbot renew --pre-hook \"systemctl stop ocserv\" --post-hook \"systemctl start ocserv\"<\/code><\/pre>\n<\/div>\n<div class=\"pk-alert pk-alert-info\" role=\"alert\" >\n\u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u0627\u0632 &#8211;deploy-hook \u0647\u0645\u0631\u0627\u0647 \u0628\u0627 \u0648\u0628\u200c\u0633\u0631\u0648\u0631 proxy \u0627\u0645\u0646\u200c\u062a\u0631 \u0627\u0633\u062a \u0632\u06cc\u0631\u0627 \u0646\u06cc\u0627\u0632 \u0628\u0647 \u062a\u0648\u0642\u0641 \u0633\u0631\u0648\u06cc\u0633 \u0631\u0627 \u062d\u0630\u0641 \u0645\u06cc\u200c\u06a9\u0646\u062f.<br \/>\n<\/div>\n<p>&nbsp;<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-tips\"><span id=\"%d9%86%da%a9%d8%a7%d8%aa-%d8%b9%d9%85%d9%84%db%8c-%d9%88-%d9%85%d9%88%d8%a7%d8%b1%d8%af-%d8%aa%d8%ae%d8%b5%d8%b5%db%8c-%d8%a8%d8%b1%d8%a7%db%8c-%da%a9%d8%a7%d8%b1%d8%a8%d8%b1%d8%af%d9%87%d8%a7\">\u0646\u06a9\u0627\u062a \u0639\u0645\u0644\u06cc \u0648 \u0645\u0648\u0627\u0631\u062f \u062a\u062e\u0635\u0635\u06cc \u0628\u0631\u0627\u06cc \u06a9\u0627\u0631\u0628\u0631\u062f\u0647\u0627<\/span><\/h2>\n<ul>\n<li class=\"wp-block-paragraph\"><strong>\u062a\u0631\u06cc\u062f:<\/strong> \u0633\u0631\u0648\u0631\u06cc \u062f\u0631 \u0646\u0632\u062f\u06cc\u06a9\u200c\u062a\u0631\u06cc\u0646 \u0644\u0648\u06a9\u06cc\u0634\u0646 \u0628\u0631\u0627\u06cc \u06a9\u0645\u062a\u0631\u06cc\u0646 latency \u0627\u0646\u062a\u062e\u0627\u0628 \u06a9\u0646\u06cc\u062f\u061b VPS\u0647\u0627\u06cc \u0645\u062e\u0635\u0648\u0635 \u062a\u0631\u06cc\u062f \u0628\u0627 \u067e\u0648\u0631\u062a 443 \u0648 UDP\/DTLS \u0645\u06cc\u200c\u062a\u0648\u0627\u0646\u0646\u062f \u0645\u0641\u06cc\u062f \u0628\u0627\u0634\u0646\u062f.<\/li>\n<li class=\"wp-block-paragraph\"><strong>\u06af\u06cc\u0645\u06cc\u0646\u06af:<\/strong> \u0627\u0632 split\u2011tunneling \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u06a9\u0646\u06cc\u062f \u062a\u0627 \u0641\u0642\u0637 \u062a\u0631\u0627\u0641\u06cc\u06a9 \u0644\u0627\u0632\u0645 \u0627\u0632 VPN \u0639\u0628\u0648\u0631 \u06a9\u0646\u062f \u0648 \u067e\u06cc\u0646\u06af \u0628\u0627\u0632\u06cc \u06a9\u0627\u0647\u0634 \u06cc\u0627\u0628\u062f.<\/li>\n<li class=\"wp-block-paragraph\"><strong>\u0647\u0648\u0634 \u0645\u0635\u0646\u0648\u0639\u06cc \u0648 \u0631\u0646\u062f\u0631\u06cc\u0646\u06af:<\/strong> \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u0627\u0632 \u0633\u0631\u0648\u0631\u0647\u0627\u06cc GPU \u062f\u0631 \u0647\u0645\u0627\u0646 \u0645\u0646\u0637\u0642\u0647 \u0645\u06cc\u200c\u062a\u0648\u0627\u0646\u062f \u0628\u0627\u0631 \u0634\u0628\u06a9\u0647 \u0648 \u062a\u0627\u062e\u06cc\u0631 \u0631\u0627 \u06a9\u0627\u0647\u0634 \u062f\u0647\u062f.<\/li>\n<li class=\"wp-block-paragraph\"><strong>\u0627\u0645\u0646\u06cc\u062a \u0633\u0627\u0632\u0645\u0627\u0646\u06cc:<\/strong> \u062a\u0631\u06a9\u06cc\u0628 LDAP\/AD\u060c 2FA\u060c \u0645\u0627\u0646\u06cc\u062a\u0648\u0631\u06cc\u0646\u06af \u0648 \u0633\u0631\u0648\u0631\u0647\u0627\u06cc \u0636\u062f DDoS \u062a\u0648\u0635\u06cc\u0647 \u0645\u06cc\u200c\u0634\u0648\u062f.<\/li>\n<\/ul>\n<p class=\"wp-block-paragraph\">\u0634\u0631\u06a9\u062a \u0645\u0627 \u0633\u0631\u0648\u06cc\u0633\u200c\u0647\u0627\u06cc \u0627\u0628\u0631\u06cc \u0628\u0627 \u0639\u0645\u0644\u06a9\u0631\u062f \u0628\u0627\u0644\u0627\u060c \u0633\u0631\u0648\u0631 \u06af\u0631\u0627\u0641\u06cc\u06a9\u06cc (GPU)\u060c VPS \u062a\u0631\u06cc\u062f\/\u06af\u06cc\u0645\u060c \u062b\u0628\u062a \u062f\u0627\u0645\u0646\u0647\u060c CDN \u0648 \u0634\u0628\u06a9\u0647 BGP \u062f\u0631 <strong>85+ \u0644\u0648\u06a9\u06cc\u0634\u0646 \u062c\u0647\u0627\u0646\u06cc<\/strong> \u0627\u0631\u0627\u0626\u0647 \u0645\u06cc\u200c\u062f\u0647\u062f \u062a\u0627 \u0628\u062a\u0648\u0627\u0646\u06cc\u062f VPN \u0631\u0627 \u0646\u0632\u062f\u06cc\u06a9 \u0628\u0647 \u06a9\u0627\u0631\u0628\u0631\u0627\u0646 \u062e\u0648\u062f \u0642\u0631\u0627\u0631 \u062f\u0647\u06cc\u062f \u0648 \u0627\u0632 \u062d\u0641\u0627\u0638\u062a DDoS \u0628\u0647\u0631\u0647\u200c\u0645\u0646\u062f \u0634\u0648\u06cc\u062f.<\/p>\n<p>&nbsp;<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-conclusion\"><span id=\"%d8%ac%d9%85%d8%b9%d8%a8%d9%86%d8%af%db%8c\">\u062c\u0645\u0639\u200c\u0628\u0646\u062f\u06cc<\/span><\/h2>\n<p class=\"wp-block-paragraph\">\u0627\u06cc\u0646 \u0631\u0627\u0647\u0646\u0645\u0627 \u0628\u0647\u200c\u0637\u0648\u0631 \u0639\u0645\u0644\u06cc \u0645\u0631\u0627\u062d\u0644 \u0631\u0627\u0647\u200c\u0627\u0646\u062f\u0627\u0632\u06cc OpenConnect (ocserv) \u0631\u0648\u06cc Ubuntu 22.04 \u0631\u0627 \u0627\u0632 \u0646\u0635\u0628 \u062a\u0627 \u062f\u0631\u06cc\u0627\u0641\u062a \u06af\u0648\u0627\u0647\u06cc Let\u2019s Encrypt\u060c \u067e\u06cc\u06a9\u0631\u0628\u0646\u062f\u06cc \u0627\u0645\u0646\u060c \u0641\u0627\u06cc\u0631\u0648\u0627\u0644 \u0648 NAT\u060c \u0627\u062d\u0631\u0627\u0632 \u0647\u0648\u06cc\u062a\u060c \u0628\u0647\u06cc\u0646\u0647\u200c\u0633\u0627\u0632\u06cc \u0648 \u0627\u062a\u0648\u0645\u0627\u0633\u06cc\u0648\u0646 \u062a\u0645\u062f\u06cc\u062f \u067e\u0648\u0634\u0634 \u062f\u0627\u062f.<\/p>\n<p class=\"wp-block-paragraph\">\u0628\u0627 \u0631\u0639\u0627\u06cc\u062a \u0646\u06a9\u0627\u062a \u0627\u0645\u0646\u06cc\u062a\u06cc \u0645\u0627\u0646\u0646\u062f <strong>TLS \u0645\u062f\u0631\u0646<\/strong>\u060c <strong>\u063a\u06cc\u0631\u0641\u0639\u0627\u0644\u200c\u0633\u0627\u0632\u06cc compression<\/strong>\u060c \u0645\u062d\u062f\u0648\u062f\u06cc\u062a \u0627\u062a\u0635\u0627\u0644\u0627\u062a\u060c \u0641\u0639\u0627\u0644\u200c\u0633\u0627\u0632\u06cc 2FA \u0648 fail2ban \u0645\u06cc\u200c\u062a\u0648\u0627\u0646 \u06cc\u06a9 \u0633\u0631\u0648\u06cc\u0633 VPN \u0627\u0645\u0646 \u0648 \u0642\u0627\u0628\u0644\u200c\u0627\u0639\u062a\u0645\u0627\u062f \u0628\u0631\u0627\u06cc \u062a\u06cc\u0645\u200c\u0647\u0627\u060c \u06af\u06cc\u0645\u0631\u0647\u0627 \u0648 \u062a\u0631\u06cc\u062f\u0631\u0647\u0627 \u0641\u0631\u0627\u0647\u0645 \u06a9\u0631\u062f.<\/p>\n<div id=\"collapsibles-6a03a9c66200d\" class=\"pk-collapsibles\" role=\"tablist\" aria-multiselectable=\"true\">\n<div class=\"pk-collapsible pk-card \">\n\t\t\t<div class=\"pk-card-header\" role=\"tab\" id=\"card-6a03a9c661f48\">\n\t\t\t\t<h6 class=\"pk-card-title pk-title\">\n\t\t\t\t\t<a data-toggle=\"collapse\" class=\"pk-font-heading\" href=\"#pk-collapse-6a03a9c661f48\" data-parent=\"#pk-collapsibles-6a03a9c66200d\" aria-controls=\"collapse-6a03a9c661f48\">\n\t\t\t\t\t\t\u06f1. \u0622\u06cc\u0627 \u0628\u0631\u0627\u06cc \u062f\u0631\u06cc\u0627\u0641\u062a \u06af\u0648\u0627\u0647\u06cc Let\u2019s Encrypt \u0628\u0627\u06cc\u062f ocserv \u0631\u0627 \u0645\u062a\u0648\u0642\u0641 \u06a9\u0646\u0645\u061f\n\t\t\t\t\t<\/a>\n\t\t\t\t<\/h6>\n\t\t\t<\/div>\n\n\t\t\t<div id=\"pk-collapse-6a03a9c661f48\" class=\"pk-collapse\" style=\"display:none;\" role=\"tabpanel\" aria-labelledby=\"card-6a03a9c661f48\">\n\t\t\t\t<div class=\"pk-card-body\">\n\t\t\t\t\t\n\u0627\u06af\u0631 \u0627\u0632 nginx \u06cc\u0627 reverse proxy \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u0645\u06cc\u200c\u06a9\u0646\u06cc\u062f \u0646\u06cc\u0627\u0632\u06cc \u0628\u0647 \u062a\u0648\u0642\u0641 ocserv \u0646\u06cc\u0633\u062a \u0648 \u0645\u06cc\u200c\u062a\u0648\u0627\u0646\u06cc\u062f \u0627\u0632 deploy-hook \u0628\u0631\u0627\u06cc reload \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u06a9\u0646\u06cc\u062f\u061b \u062f\u0631 \u062d\u0627\u0644\u062a standalone \u06cc\u0627 \u0628\u062f\u0648\u0646 proxy \u0645\u0645\u06a9\u0646 \u0627\u0633\u062a \u0646\u06cc\u0627\u0632 \u0628\u0647 \u062a\u0648\u0642\u0641 \u0645\u0648\u0642\u062a \u0633\u0631\u0648\u06cc\u0633 \u06cc\u0627 \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u0627\u0632 DNS challenge \u0628\u0627\u0634\u062f.<br \/>\n\n\t\t\t\t<\/div>\n\t\t\t<\/div>\n\t\t<\/div>\n\t\t\n<div class=\"pk-collapsible pk-card \">\n\t\t\t<div class=\"pk-card-header\" role=\"tab\" id=\"card-6a03a9c661f78\">\n\t\t\t\t<h6 class=\"pk-card-title pk-title\">\n\t\t\t\t\t<a data-toggle=\"collapse\" class=\"pk-font-heading\" href=\"#pk-collapse-6a03a9c661f78\" data-parent=\"#pk-collapsibles-6a03a9c66200d\" aria-controls=\"collapse-6a03a9c661f78\">\n\t\t\t\t\t\t\u06f2. \u0628\u0647\u062a\u0631\u06cc\u0646 \u062a\u0646\u0638\u06cc\u0645 \u0628\u0631\u0627\u06cc \u06a9\u0627\u0647\u0634 \u067e\u06cc\u0646\u06af \u0686\u06cc\u0633\u062a\u061f\n\t\t\t\t\t<\/a>\n\t\t\t\t<\/h6>\n\t\t\t<\/div>\n\n\t\t\t<div id=\"pk-collapse-6a03a9c661f78\" class=\"pk-collapse\" style=\"display:none;\" role=\"tabpanel\" aria-labelledby=\"card-6a03a9c661f78\">\n\t\t\t\t<div class=\"pk-card-body\">\n\t\t\t\t\t\n\u0627\u0646\u062a\u062e\u0627\u0628 \u0646\u0632\u062f\u06cc\u06a9\u200c\u062a\u0631\u06cc\u0646 \u0644\u0648\u06a9\u06cc\u0634\u0646 \u0628\u0647 \u06a9\u0627\u0631\u0628\u0631\u0627\u0646 \u06cc\u0627 \u0645\u0642\u0635\u062f \u0633\u0631\u0648\u06cc\u0633 \u0628\u0647\u062a\u0631\u06cc\u0646 \u0631\u0627\u0647 \u0628\u0631\u0627\u06cc \u06a9\u0627\u0647\u0634 \u067e\u06cc\u0646\u06af \u0627\u0633\u062a\u061b \u0628\u0631\u0627\u06cc \u06a9\u0627\u0631\u0628\u0631\u062f\u0647\u0627\u06cc \u062d\u0633\u0627\u0633 \u0627\u0632 \u0633\u0631\u0648\u0631\u0647\u0627\u06cc \u0645\u062e\u0635\u0648\u0635 \u062a\u0631\u06cc\u062f \u06cc\u0627 \u06af\u06cc\u0645 \u0628\u0627 \u0645\u062d\u0627\u0641\u0638\u062a DDoS \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u06a9\u0646\u06cc\u062f.<br \/>\n\n\t\t\t\t<\/div>\n\t\t\t<\/div>\n\t\t<\/div>\n\t\t\n<div class=\"pk-collapsible pk-card \">\n\t\t\t<div class=\"pk-card-header\" role=\"tab\" id=\"card-6a03a9c661fa0\">\n\t\t\t\t<h6 class=\"pk-card-title pk-title\">\n\t\t\t\t\t<a data-toggle=\"collapse\" class=\"pk-font-heading\" href=\"#pk-collapse-6a03a9c661fa0\" data-parent=\"#pk-collapsibles-6a03a9c66200d\" aria-controls=\"collapse-6a03a9c661fa0\">\n\t\t\t\t\t\t\u06f3. \u0622\u06cc\u0627 compression \u0631\u0627 \u0641\u0639\u0627\u0644 \u06a9\u0646\u0645\u061f\n\t\t\t\t\t<\/a>\n\t\t\t\t<\/h6>\n\t\t\t<\/div>\n\n\t\t\t<div id=\"pk-collapse-6a03a9c661fa0\" class=\"pk-collapse\" style=\"display:none;\" role=\"tabpanel\" aria-labelledby=\"card-6a03a9c661fa0\">\n\t\t\t\t<div class=\"pk-card-body\">\n\t\t\t\t\t\n\u062e\u06cc\u0631\u061b \u0628\u0647\u200c\u062f\u0644\u0627\u06cc\u0644 \u0627\u0645\u0646\u06cc\u062a\u06cc \u0648 \u062c\u0644\u0648\u06af\u06cc\u0631\u06cc \u0627\u0632 \u062d\u0645\u0644\u0627\u062a \u0645\u0627\u0646\u0646\u062f CRIME \u062a\u0648\u0635\u06cc\u0647 \u0645\u06cc\u200c\u0634\u0648\u062f compression \u0631\u0627 \u063a\u06cc\u0631\u0641\u0639\u0627\u0644 \u06a9\u0646\u06cc\u062f.<br \/>\n\n\t\t\t\t<\/div>\n\t\t\t<\/div>\n\t\t<\/div>\n\t\t\n<div class=\"pk-collapsible pk-card \">\n\t\t\t<div class=\"pk-card-header\" role=\"tab\" id=\"card-6a03a9c661fc6\">\n\t\t\t\t<h6 class=\"pk-card-title pk-title\">\n\t\t\t\t\t<a data-toggle=\"collapse\" class=\"pk-font-heading\" href=\"#pk-collapse-6a03a9c661fc6\" data-parent=\"#pk-collapsibles-6a03a9c66200d\" aria-controls=\"collapse-6a03a9c661fc6\">\n\t\t\t\t\t\t\u06f4. \u0686\u06af\u0648\u0646\u0647 \u06a9\u0627\u0631\u0628\u0631\u0627\u0646 \u0631\u0627 \u0628\u0647\u200c\u0635\u0648\u0631\u062a \u0645\u062d\u0644\u06cc \u0627\u0636\u0627\u0641\u0647 \u06a9\u0646\u0645\u061f\n\t\t\t\t\t<\/a>\n\t\t\t\t<\/h6>\n\t\t\t<\/div>\n\n\t\t\t<div id=\"pk-collapse-6a03a9c661fc6\" class=\"pk-collapse\" style=\"display:none;\" role=\"tabpanel\" aria-labelledby=\"card-6a03a9c661fc6\">\n\t\t\t\t<div class=\"pk-card-body\">\n\t\t\t\t\t\n\u0627\u0632 \u062f\u0633\u062a\u0648\u0631 ocpasswd \u0628\u0631\u0627\u06cc \u0627\u0641\u0632\u0648\u062f\u0646 \u06a9\u0627\u0631\u0628\u0631\u0627\u0646 \u0645\u062d\u0644\u06cc \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u06a9\u0646\u06cc\u062f\u060c \u0645\u062b\u0644\u0627\u064b: sudo ocpasswd -c \/etc\/ocserv\/ocpasswd alice<br \/>\n\n\t\t\t\t<\/div>\n\t\t\t<\/div>\n\t\t<\/div>\n\t\t\n<div class=\"pk-collapsible pk-card \">\n\t\t\t<div class=\"pk-card-header\" role=\"tab\" id=\"card-6a03a9c661fea\">\n\t\t\t\t<h6 class=\"pk-card-title pk-title\">\n\t\t\t\t\t<a data-toggle=\"collapse\" class=\"pk-font-heading\" href=\"#pk-collapse-6a03a9c661fea\" data-parent=\"#pk-collapsibles-6a03a9c66200d\" aria-controls=\"collapse-6a03a9c661fea\">\n\t\t\t\t\t\t\u06f5. \u0628\u0647\u062a\u0631\u06cc\u0646 \u0631\u0648\u0634 \u0628\u0631\u0627\u06cc \u062a\u0645\u062f\u06cc\u062f \u062e\u0648\u062f\u06a9\u0627\u0631 \u06af\u0648\u0627\u0647\u06cc \u0686\u06cc\u0633\u062a\u061f\n\t\t\t\t\t<\/a>\n\t\t\t\t<\/h6>\n\t\t\t<\/div>\n\n\t\t\t<div id=\"pk-collapse-6a03a9c661fea\" class=\"pk-collapse\" style=\"display:none;\" role=\"tabpanel\" aria-labelledby=\"card-6a03a9c661fea\">\n\t\t\t\t<div class=\"pk-card-body\">\n\t\t\t\t\t\n\u0627\u06af\u0631 \u0627\u0632 \u0648\u0628\u200c\u0633\u0631\u0648\u0631 proxy \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u0645\u06cc\u200c\u06a9\u0646\u06cc\u062f \u0627\u0632 certbot renew \u0628\u0627 &#8211;deploy-hook &#8220;systemctl reload ocserv&#8221; \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u06a9\u0646\u06cc\u062f\u061b \u062f\u0631 \u063a\u06cc\u0631 \u0627\u06cc\u0646 \u0635\u0648\u0631\u062a \u0627\u0632 DNS challenge \u06cc\u0627 pre\/post hooks \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u06a9\u0646\u06cc\u062f.<br \/>\n\n\t\t\t\t<\/div>\n\t\t\t<\/div>\n\t\t<\/div>\n\t\t\n<\/div>\n\t\t\n<p><script type=\"application\/ld+json\">{\"@context\":\"https:\/\/schema.org\",\"@type\":\"FAQPage\",\"mainEntity\":[{\"@type\":\"Question\",\"name\":\"\u0622\u06cc\u0627 \u0628\u0631\u0627\u06cc \u062f\u0631\u06cc\u0627\u0641\u062a \u06af\u0648\u0627\u0647\u06cc Let\u2019s Encrypt \u0628\u0627\u06cc\u062f ocserv \u0631\u0627 \u0645\u062a\u0648\u0642\u0641 \u06a9\u0646\u0645\u061f\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"\u0627\u06af\u0631 \u0627\u0632 nginx \u06cc\u0627 reverse proxy \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u0645\u06cc\u200c\u06a9\u0646\u06cc\u062f \u0646\u06cc\u0627\u0632\u06cc \u0628\u0647 \u062a\u0648\u0642\u0641 ocserv \u0646\u06cc\u0633\u062a \u0648 \u0645\u06cc\u200c\u062a\u0648\u0627\u0646\u06cc\u062f \u0627\u0632 deploy-hook \u0628\u0631\u0627\u06cc reload \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u06a9\u0646\u06cc\u062f\u061b \u062f\u0631 \u062d\u0627\u0644\u062a standalone \u06cc\u0627 \u0628\u062f\u0648\u0646 proxy \u0645\u0645\u06a9\u0646 \u0627\u0633\u062a \u0646\u06cc\u0627\u0632 \u0628\u0647 \u062a\u0648\u0642\u0641 \u0645\u0648\u0642\u062a \u0633\u0631\u0648\u06cc\u0633 \u06cc\u0627 \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u0627\u0632 DNS challenge \u0628\u0627\u0634\u062f.\"}},{\"@type\":\"Question\",\"name\":\"\u0628\u0647\u062a\u0631\u06cc\u0646 \u062a\u0646\u0638\u06cc\u0645 \u0628\u0631\u0627\u06cc \u06a9\u0627\u0647\u0634 \u067e\u06cc\u0646\u06af \u0686\u06cc\u0633\u062a\u061f\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"\u0627\u0646\u062a\u062e\u0627\u0628 \u0646\u0632\u062f\u06cc\u06a9\u200c\u062a\u0631\u06cc\u0646 \u0644\u0648\u06a9\u06cc\u0634\u0646 \u0628\u0647 \u06a9\u0627\u0631\u0628\u0631\u0627\u0646 \u06cc\u0627 \u0645\u0642\u0635\u062f \u0633\u0631\u0648\u06cc\u0633 \u0628\u0647\u062a\u0631\u06cc\u0646 \u0631\u0627\u0647 \u0628\u0631\u0627\u06cc \u06a9\u0627\u0647\u0634 \u067e\u06cc\u0646\u06af \u0627\u0633\u062a\u061b \u0628\u0631\u0627\u06cc \u06a9\u0627\u0631\u0628\u0631\u062f\u0647\u0627\u06cc \u062d\u0633\u0627\u0633 \u0627\u0632 \u0633\u0631\u0648\u0631\u0647\u0627\u06cc \u0645\u062e\u0635\u0648\u0635 \u062a\u0631\u06cc\u062f \u06cc\u0627 \u06af\u06cc\u0645 \u0628\u0627 \u0645\u062d\u0627\u0641\u0638\u062a DDoS \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u06a9\u0646\u06cc\u062f.\"}},{\"@type\":\"Question\",\"name\":\"\u0622\u06cc\u0627 compression \u0631\u0627 \u0641\u0639\u0627\u0644 \u06a9\u0646\u0645\u061f\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"\u062e\u06cc\u0631\u061b \u0628\u0647\u200c\u062f\u0644\u0627\u06cc\u0644 \u0627\u0645\u0646\u06cc\u062a\u06cc \u0648 \u062c\u0644\u0648\u06af\u06cc\u0631\u06cc \u0627\u0632 \u062d\u0645\u0644\u0627\u062a \u0645\u0627\u0646\u0646\u062f CRIME \u062a\u0648\u0635\u06cc\u0647 \u0645\u06cc\u200c\u0634\u0648\u062f compression \u0631\u0627 \u063a\u06cc\u0631\u0641\u0639\u0627\u0644 \u06a9\u0646\u06cc\u062f.\"}},{\"@type\":\"Question\",\"name\":\"\u0686\u06af\u0648\u0646\u0647 \u06a9\u0627\u0631\u0628\u0631\u0627\u0646 \u0631\u0627 \u0628\u0647\u200c\u0635\u0648\u0631\u062a \u0645\u062d\u0644\u06cc \u0627\u0636\u0627\u0641\u0647 \u06a9\u0646\u0645\u061f\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"\u0627\u0632 \u062f\u0633\u062a\u0648\u0631 ocpasswd \u0628\u0631\u0627\u06cc \u0627\u0641\u0632\u0648\u062f\u0646 \u06a9\u0627\u0631\u0628\u0631\u0627\u0646 \u0645\u062d\u0644\u06cc \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u06a9\u0646\u06cc\u062f\u060c \u0645\u062b\u0644\u0627\u064b: sudo ocpasswd -c \/etc\/ocserv\/ocpasswd alice\"}},{\"@type\":\"Question\",\"name\":\"\u0628\u0647\u062a\u0631\u06cc\u0646 \u0631\u0648\u0634 \u0628\u0631\u0627\u06cc \u062a\u0645\u062f\u06cc\u062f \u062e\u0648\u062f\u06a9\u0627\u0631 \u06af\u0648\u0627\u0647\u06cc \u0686\u06cc\u0633\u062a\u061f\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"\u0627\u06af\u0631 \u0627\u0632 \u0648\u0628\u200c\u0633\u0631\u0648\u0631 proxy \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u0645\u06cc\u200c\u06a9\u0646\u06cc\u062f \u0627\u0632 certbot renew \u0628\u0627 --deploy-hook \\\"systemctl reload ocserv\\\" \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u06a9\u0646\u06cc\u062f\u061b \u062f\u0631 \u063a\u06cc\u0631 \u0627\u06cc\u0646 \u0635\u0648\u0631\u062a \u0627\u0632 DNS challenge \u06cc\u0627 pre\/post hooks \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u06a9\u0646\u06cc\u062f.\"}}]}<\/script><\/p>\n","protected":false},"excerpt":{"rendered":"In diesem Artikel erfahren Sie, wie Sie den OpenConnect VPN-Server (ocserv) unter Ubuntu 22.04 mit Let&#039;s Encrypt-Zertifikaten einrichten. Diese Anleitung umfasst Installation, Konfiguration, Sicherheitstipps und Optimierung des VPN-Dienstes.","protected":false},"author":8,"featured_media":17622,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_yoast_wpseo_focuskw":"OpenConnect ocserv","_yoast_wpseo_title":"","_yoast_wpseo_metadesc":"\u0627\u06cc\u0646 \u0645\u0642\u0627\u0644\u0647 \u0628\u0647 \u0634\u0645\u0627 \u0622\u0645\u0648\u0632\u0634 \u0645\u06cc\u200c\u062f\u0647\u062f \u0686\u0637\u0648\u0631 OpenConnect Server (ocserv) \u0631\u0627 \u0628\u0631 \u0631\u0648\u06cc \u0627\u0648\u0628\u0648\u0646\u062a\u0648 22.04 \u0631\u0627\u0647\u200c\u0627\u0646\u062f\u0627\u0632\u06cc \u06a9\u0631\u062f\u0647 \u0648 \u0628\u0627 Let's Encrypt \u0628\u0647 \u0627\u0645\u0646\u06cc\u062a \u0622\u0646 \u0627\u0641\u0632\u0648\u062f\u0647 \u0648 \u06af\u0648\u0627\u0647\u06cc\u0646\u0627\u0645\u0647 \u062f\u0631\u06cc\u0627\u0641\u062a \u06a9\u0646\u06cc\u062f.","_yoast_wpseo_canonical":"","_yoast_wpseo_opengraph-description":"\u0627\u06cc\u0646 \u0645\u0642\u0627\u0644\u0647 \u0628\u0647 \u0634\u0645\u0627 \u0622\u0645\u0648\u0632\u0634 \u0645\u06cc\u200c\u062f\u0647\u062f \u0686\u0637\u0648\u0631 OpenConnect VPN Server (ocserv) \u0631\u0627 \u0628\u0631 \u0631\u0648\u06cc \u0627\u0648\u0628\u0648\u0646\u062a\u0648 22.04 \u0631\u0627\u0647\u200c\u0627\u0646\u062f\u0627\u0632\u06cc \u06a9\u0631\u062f\u0647 \u0648 \u0628\u0627 Let's Encrypt \u0628\u0647 \u0627\u0645\u0646\u06cc\u062a \u0622\u0646 \u0627\u0641\u0632\u0648\u062f\u0647 \u0648 \u06af\u0648\u0627\u0647\u06cc\u0646\u0627\u0645\u0647 \u062f\u0631\u06cc\u0627\u0641\u062a \u06a9\u0646\u06cc\u062f.","_yoast_wpseo_opengraph-image":"","_yoast_wpseo_twitter-description":"\u0627\u06cc\u0646 \u0645\u0642\u0627\u0644\u0647 \u0628\u0647 \u0634\u0645\u0627 \u0622\u0645\u0648\u0632\u0634 \u0645\u06cc\u200c\u062f\u0647\u062f \u0686\u0637\u0648\u0631 OpenConnect VPN Server (ocserv) \u0631\u0627 \u0628\u0631 \u0631\u0648\u06cc \u0627\u0648\u0628\u0648\u0646\u062a\u0648 22.04 \u0631\u0627\u0647\u200c\u0627\u0646\u062f\u0627\u0632\u06cc \u06a9\u0631\u062f\u0647 \u0648 \u0628\u0627 Let's Encrypt \u0628\u0647 \u0627\u0645\u0646\u06cc\u062a \u0622\u0646 \u0627\u0641\u0632\u0648\u062f\u0647 \u0648 \u06af\u0648\u0627\u0647\u06cc\u0646\u0627\u0645\u0647 \u062f\u0631\u06cc\u0627\u0641\u062a \u06a9\u0646\u06cc\u062f.","_yoast_wpseo_twitter-image":"","_yoast_wpseo_focuskeywords":"[]","_yoast_wpseo_primary_category":"473","footnotes":""},"categories":[473,324],"tags":[288,280,281],"class_list":{"0":"post-17620","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-ubuntu","8":"category-security","9":"tag-vpn","10":"tag-vps","11":"tag-vps-server"},"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.3 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>\u0622\u0645\u0648\u0632\u0634 \u0646\u0635\u0628 \u0648 \u0631\u0627\u0647\u200c\u0627\u0646\u062f\u0627\u0632\u06cc (ocserv) OpenConnect Server \u0628\u0631 \u0631\u0648\u06cc \u0627\u0648\u0628\u0648\u0646\u062a\u0648 22.04 \u0628\u0627 Let&#039;s Encrypt - \u0628\u0644\u0627\u06af ITPiran<\/title>\n<meta name=\"description\" content=\"\u0627\u06cc\u0646 \u0645\u0642\u0627\u0644\u0647 \u0628\u0647 \u0634\u0645\u0627 \u0622\u0645\u0648\u0632\u0634 \u0645\u06cc\u200c\u062f\u0647\u062f \u0686\u0637\u0648\u0631 OpenConnect Server (ocserv) \u0631\u0627 \u0628\u0631 \u0631\u0648\u06cc \u0627\u0648\u0628\u0648\u0646\u062a\u0648 22.04 \u0631\u0627\u0647\u200c\u0627\u0646\u062f\u0627\u0632\u06cc \u06a9\u0631\u062f\u0647 \u0648 \u0628\u0627 Let&#039;s Encrypt \u0628\u0647 \u0627\u0645\u0646\u06cc\u062a \u0622\u0646 \u0627\u0641\u0632\u0648\u062f\u0647 \u0648 \u06af\u0648\u0627\u0647\u06cc\u0646\u0627\u0645\u0647 \u062f\u0631\u06cc\u0627\u0641\u062a \u06a9\u0646\u06cc\u062f.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.itpiran.net\/blog\/de\/os\/ubuntu\/openconnect-ocserv-ubuntu-22-04\/\" \/>\n<meta property=\"og:locale\" content=\"de_DE\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"\u0622\u0645\u0648\u0632\u0634 \u0646\u0635\u0628 \u0648 \u0631\u0627\u0647\u200c\u0627\u0646\u062f\u0627\u0632\u06cc (ocserv) OpenConnect Server \u0628\u0631 \u0631\u0648\u06cc \u0627\u0648\u0628\u0648\u0646\u062a\u0648 22.04 \u0628\u0627 Let&#039;s Encrypt - \u0628\u0644\u0627\u06af ITPiran\" \/>\n<meta property=\"og:description\" content=\"\u0627\u06cc\u0646 \u0645\u0642\u0627\u0644\u0647 \u0628\u0647 \u0634\u0645\u0627 \u0622\u0645\u0648\u0632\u0634 \u0645\u06cc\u200c\u062f\u0647\u062f \u0686\u0637\u0648\u0631 OpenConnect VPN Server (ocserv) \u0631\u0627 \u0628\u0631 \u0631\u0648\u06cc \u0627\u0648\u0628\u0648\u0646\u062a\u0648 22.04 \u0631\u0627\u0647\u200c\u0627\u0646\u062f\u0627\u0632\u06cc \u06a9\u0631\u062f\u0647 \u0648 \u0628\u0627 Let&#039;s Encrypt \u0628\u0647 \u0627\u0645\u0646\u06cc\u062a \u0622\u0646 \u0627\u0641\u0632\u0648\u062f\u0647 \u0648 \u06af\u0648\u0627\u0647\u06cc\u0646\u0627\u0645\u0647 \u062f\u0631\u06cc\u0627\u0641\u062a \u06a9\u0646\u06cc\u062f.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.itpiran.net\/blog\/de\/os\/ubuntu\/openconnect-ocserv-ubuntu-22-04\/\" \/>\n<meta property=\"og:site_name\" content=\"\u0628\u0644\u0627\u06af ITPiran\" \/>\n<meta property=\"article:published_time\" content=\"2025-12-18T19:19:58+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2025-12-18T19:27:27+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/cdn.itpiran.net\/2025\/12\/18224931\/openconnect-vpn-ubuntu-22-04-17620.webp\" \/>\n\t<meta property=\"og:image:width\" content=\"1654\" \/>\n\t<meta property=\"og:image:height\" content=\"1024\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/webp\" \/>\n<meta name=\"author\" content=\"Elahe\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:description\" content=\"\u0627\u06cc\u0646 \u0645\u0642\u0627\u0644\u0647 \u0628\u0647 \u0634\u0645\u0627 \u0622\u0645\u0648\u0632\u0634 \u0645\u06cc\u200c\u062f\u0647\u062f \u0686\u0637\u0648\u0631 OpenConnect VPN Server (ocserv) \u0631\u0627 \u0628\u0631 \u0631\u0648\u06cc \u0627\u0648\u0628\u0648\u0646\u062a\u0648 22.04 \u0631\u0627\u0647\u200c\u0627\u0646\u062f\u0627\u0632\u06cc \u06a9\u0631\u062f\u0647 \u0648 \u0628\u0627 Let&#039;s Encrypt \u0628\u0647 \u0627\u0645\u0646\u06cc\u062a \u0622\u0646 \u0627\u0641\u0632\u0648\u062f\u0647 \u0648 \u06af\u0648\u0627\u0647\u06cc\u0646\u0627\u0645\u0647 \u062f\u0631\u06cc\u0627\u0641\u062a \u06a9\u0646\u06cc\u062f.\" \/>\n<meta name=\"twitter:label1\" content=\"Verfasst von\" \/>\n\t<meta name=\"twitter:data1\" content=\"Elahe\" \/>\n\t<meta name=\"twitter:label2\" content=\"Gesch\u00e4tzte Lesezeit\" \/>\n\t<meta name=\"twitter:data2\" content=\"8\u00a0Minuten\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.itpiran.net\\\/blog\\\/os\\\/ubuntu\\\/openconnect-ocserv-ubuntu-22-04\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.itpiran.net\\\/blog\\\/os\\\/ubuntu\\\/openconnect-ocserv-ubuntu-22-04\\\/\"},\"author\":{\"name\":\"Elahe\",\"@id\":\"https:\\\/\\\/www.itpiran.net\\\/blog\\\/#\\\/schema\\\/person\\\/f302f8428a00aaa2cabd5752d9c8fa65\"},\"headline\":\"\u0622\u0645\u0648\u0632\u0634 \u0646\u0635\u0628 \u0648 \u0631\u0627\u0647\u200c\u0627\u0646\u062f\u0627\u0632\u06cc (ocserv) OpenConnect Server \u0628\u0631 \u0631\u0648\u06cc \u0627\u0648\u0628\u0648\u0646\u062a\u0648 22.04 \u0628\u0627 Let&#8217;s Encrypt\",\"datePublished\":\"2025-12-18T19:19:58+00:00\",\"dateModified\":\"2025-12-18T19:27:27+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.itpiran.net\\\/blog\\\/os\\\/ubuntu\\\/openconnect-ocserv-ubuntu-22-04\\\/\"},\"wordCount\":286,\"publisher\":{\"@id\":\"https:\\\/\\\/www.itpiran.net\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.itpiran.net\\\/blog\\\/os\\\/ubuntu\\\/openconnect-ocserv-ubuntu-22-04\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/cdn.itpiran.net\\\/2025\\\/12\\\/18224931\\\/openconnect-vpn-ubuntu-22-04-17620.webp\",\"keywords\":[\"VPN\",\"vps\",\"vps server\"],\"articleSection\":[\"ubuntu\",\"\u0627\u0645\u0646\u06cc\u062a\"],\"inLanguage\":\"de\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.itpiran.net\\\/blog\\\/os\\\/ubuntu\\\/openconnect-ocserv-ubuntu-22-04\\\/\",\"url\":\"https:\\\/\\\/www.itpiran.net\\\/blog\\\/os\\\/ubuntu\\\/openconnect-ocserv-ubuntu-22-04\\\/\",\"name\":\"\u0622\u0645\u0648\u0632\u0634 \u0646\u0635\u0628 \u0648 \u0631\u0627\u0647\u200c\u0627\u0646\u062f\u0627\u0632\u06cc (ocserv) OpenConnect Server \u0628\u0631 \u0631\u0648\u06cc \u0627\u0648\u0628\u0648\u0646\u062a\u0648 22.04 \u0628\u0627 Let's Encrypt - \u0628\u0644\u0627\u06af ITPiran\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.itpiran.net\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.itpiran.net\\\/blog\\\/os\\\/ubuntu\\\/openconnect-ocserv-ubuntu-22-04\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.itpiran.net\\\/blog\\\/os\\\/ubuntu\\\/openconnect-ocserv-ubuntu-22-04\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/cdn.itpiran.net\\\/2025\\\/12\\\/18224931\\\/openconnect-vpn-ubuntu-22-04-17620.webp\",\"datePublished\":\"2025-12-18T19:19:58+00:00\",\"dateModified\":\"2025-12-18T19:27:27+00:00\",\"description\":\"\u0627\u06cc\u0646 \u0645\u0642\u0627\u0644\u0647 \u0628\u0647 \u0634\u0645\u0627 \u0622\u0645\u0648\u0632\u0634 \u0645\u06cc\u200c\u062f\u0647\u062f \u0686\u0637\u0648\u0631 OpenConnect Server (ocserv) \u0631\u0627 \u0628\u0631 \u0631\u0648\u06cc \u0627\u0648\u0628\u0648\u0646\u062a\u0648 22.04 \u0631\u0627\u0647\u200c\u0627\u0646\u062f\u0627\u0632\u06cc \u06a9\u0631\u062f\u0647 \u0648 \u0628\u0627 Let's Encrypt \u0628\u0647 \u0627\u0645\u0646\u06cc\u062a \u0622\u0646 \u0627\u0641\u0632\u0648\u062f\u0647 \u0648 \u06af\u0648\u0627\u0647\u06cc\u0646\u0627\u0645\u0647 \u062f\u0631\u06cc\u0627\u0641\u062a \u06a9\u0646\u06cc\u062f.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.itpiran.net\\\/blog\\\/os\\\/ubuntu\\\/openconnect-ocserv-ubuntu-22-04\\\/#breadcrumb\"},\"inLanguage\":\"de\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.itpiran.net\\\/blog\\\/os\\\/ubuntu\\\/openconnect-ocserv-ubuntu-22-04\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"de\",\"@id\":\"https:\\\/\\\/www.itpiran.net\\\/blog\\\/os\\\/ubuntu\\\/openconnect-ocserv-ubuntu-22-04\\\/#primaryimage\",\"url\":\"https:\\\/\\\/cdn.itpiran.net\\\/2025\\\/12\\\/18224931\\\/openconnect-vpn-ubuntu-22-04-17620.webp\",\"contentUrl\":\"https:\\\/\\\/cdn.itpiran.net\\\/2025\\\/12\\\/18224931\\\/openconnect-vpn-ubuntu-22-04-17620.webp\",\"width\":1654,\"height\":1024,\"caption\":\"\u0631\u0627\u0647\u0646\u0645\u0627\u06cc \u06af\u0627\u0645\u200c\u0628\u0647\u200c\u06af\u0627\u0645 \u0646\u0635\u0628 OpenConnect VPN Server (ocserv) \u0628\u0631 \u0631\u0648\u06cc \u0627\u0648\u0628\u0648\u0646\u062a\u0648 22.04 \u0648 \u062f\u0631\u06cc\u0627\u0641\u062a \u06af\u0648\u0627\u0647\u06cc Let\u2019s Encrypt.\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.itpiran.net\\\/blog\\\/os\\\/ubuntu\\\/openconnect-ocserv-ubuntu-22-04\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.itpiran.net\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"\u0633\u06cc\u0633\u062a\u0645 \u0639\u0627\u0645\u0644\",\"item\":\"https:\\\/\\\/www.itpiran.net\\\/blog\\\/category\\\/os\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"ubuntu\",\"item\":\"https:\\\/\\\/www.itpiran.net\\\/blog\\\/category\\\/os\\\/ubuntu\\\/\"},{\"@type\":\"ListItem\",\"position\":4,\"name\":\"\u0622\u0645\u0648\u0632\u0634 \u0646\u0635\u0628 \u0648 \u0631\u0627\u0647\u200c\u0627\u0646\u062f\u0627\u0632\u06cc (ocserv) OpenConnect Server \u0628\u0631 \u0631\u0648\u06cc \u0627\u0648\u0628\u0648\u0646\u062a\u0648 22.04 \u0628\u0627 Let&#8217;s Encrypt\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.itpiran.net\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.itpiran.net\\\/blog\\\/\",\"name\":\"\u0628\u0644\u0627\u06af ITPiran\",\"description\":\"\u0627\u062e\u0628\u0627\u0631 \u0648 \u0645\u0642\u0627\u0644\u0627\u062a \u062a\u062c\u0627\u0631\u062a \u067e\u0627\u06cc\u062f\u0627\u0631 \u0627\u06cc\u0631\u0627\u0646\u06cc\u0627\u0646\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.itpiran.net\\\/blog\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.itpiran.net\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"de\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.itpiran.net\\\/blog\\\/#organization\",\"name\":\"\u0628\u0644\u0627\u06af \u062a\u062c\u0627\u0631\u062a \u067e\u0627\u06cc\u062f\u0627\u0631 \u0627\u06cc\u0631\u0627\u0646\u06cc\u0627\u0646\",\"alternateName\":\"ITPIran Blog\",\"url\":\"https:\\\/\\\/www.itpiran.net\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"de\",\"@id\":\"https:\\\/\\\/www.itpiran.net\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/cdn.itpiran.net\\\/2023\\\/12\\\/27150508\\\/cropped-ITPIRAN-BLOG-LOGO-2.png\",\"contentUrl\":\"https:\\\/\\\/cdn.itpiran.net\\\/2023\\\/12\\\/27150508\\\/cropped-ITPIRAN-BLOG-LOGO-2.png\",\"width\":512,\"height\":512,\"caption\":\"\u0628\u0644\u0627\u06af \u062a\u062c\u0627\u0631\u062a \u067e\u0627\u06cc\u062f\u0627\u0631 \u0627\u06cc\u0631\u0627\u0646\u06cc\u0627\u0646\"},\"image\":{\"@id\":\"https:\\\/\\\/www.itpiran.net\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.itpiran.net\\\/blog\\\/#\\\/schema\\\/person\\\/f302f8428a00aaa2cabd5752d9c8fa65\",\"name\":\"Elahe\",\"url\":\"https:\\\/\\\/www.itpiran.net\\\/blog\\\/de\\\/author\\\/elahe\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Installation und Einrichtung des OpenConnect-Servers (ocserv) unter Ubuntu 22.04 mit Let&#039;s Encrypt \u2013 ITPiran-Blog","description":"Dieser Artikel zeigt Ihnen, wie Sie den OpenConnect-Server (ocserv) unter Ubuntu 22.04 einrichten, ihn mit Let&#039;s Encrypt sichern und ein Zertifikat erhalten.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.itpiran.net\/blog\/de\/os\/ubuntu\/openconnect-ocserv-ubuntu-22-04\/","og_locale":"de_DE","og_type":"article","og_title":"\u0622\u0645\u0648\u0632\u0634 \u0646\u0635\u0628 \u0648 \u0631\u0627\u0647\u200c\u0627\u0646\u062f\u0627\u0632\u06cc (ocserv) OpenConnect Server \u0628\u0631 \u0631\u0648\u06cc \u0627\u0648\u0628\u0648\u0646\u062a\u0648 22.04 \u0628\u0627 Let's Encrypt - \u0628\u0644\u0627\u06af ITPiran","og_description":"\u0627\u06cc\u0646 \u0645\u0642\u0627\u0644\u0647 \u0628\u0647 \u0634\u0645\u0627 \u0622\u0645\u0648\u0632\u0634 \u0645\u06cc\u200c\u062f\u0647\u062f \u0686\u0637\u0648\u0631 OpenConnect VPN Server (ocserv) \u0631\u0627 \u0628\u0631 \u0631\u0648\u06cc \u0627\u0648\u0628\u0648\u0646\u062a\u0648 22.04 \u0631\u0627\u0647\u200c\u0627\u0646\u062f\u0627\u0632\u06cc \u06a9\u0631\u062f\u0647 \u0648 \u0628\u0627 Let's Encrypt \u0628\u0647 \u0627\u0645\u0646\u06cc\u062a \u0622\u0646 \u0627\u0641\u0632\u0648\u062f\u0647 \u0648 \u06af\u0648\u0627\u0647\u06cc\u0646\u0627\u0645\u0647 \u062f\u0631\u06cc\u0627\u0641\u062a \u06a9\u0646\u06cc\u062f.","og_url":"https:\/\/www.itpiran.net\/blog\/de\/os\/ubuntu\/openconnect-ocserv-ubuntu-22-04\/","og_site_name":"\u0628\u0644\u0627\u06af ITPiran","article_published_time":"2025-12-18T19:19:58+00:00","article_modified_time":"2025-12-18T19:27:27+00:00","og_image":[{"width":1654,"height":1024,"url":"https:\/\/cdn.itpiran.net\/2025\/12\/18224931\/openconnect-vpn-ubuntu-22-04-17620.webp","type":"image\/webp"}],"author":"Elahe","twitter_card":"summary_large_image","twitter_description":"\u0627\u06cc\u0646 \u0645\u0642\u0627\u0644\u0647 \u0628\u0647 \u0634\u0645\u0627 \u0622\u0645\u0648\u0632\u0634 \u0645\u06cc\u200c\u062f\u0647\u062f \u0686\u0637\u0648\u0631 OpenConnect VPN Server (ocserv) \u0631\u0627 \u0628\u0631 \u0631\u0648\u06cc \u0627\u0648\u0628\u0648\u0646\u062a\u0648 22.04 \u0631\u0627\u0647\u200c\u0627\u0646\u062f\u0627\u0632\u06cc \u06a9\u0631\u062f\u0647 \u0648 \u0628\u0627 Let's Encrypt \u0628\u0647 \u0627\u0645\u0646\u06cc\u062a \u0622\u0646 \u0627\u0641\u0632\u0648\u062f\u0647 \u0648 \u06af\u0648\u0627\u0647\u06cc\u0646\u0627\u0645\u0647 \u062f\u0631\u06cc\u0627\u0641\u062a \u06a9\u0646\u06cc\u062f.","twitter_misc":{"Verfasst von":"Elahe","Gesch\u00e4tzte Lesezeit":"8\u00a0Minuten"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.itpiran.net\/blog\/os\/ubuntu\/openconnect-ocserv-ubuntu-22-04\/#article","isPartOf":{"@id":"https:\/\/www.itpiran.net\/blog\/os\/ubuntu\/openconnect-ocserv-ubuntu-22-04\/"},"author":{"name":"Elahe","@id":"https:\/\/www.itpiran.net\/blog\/#\/schema\/person\/f302f8428a00aaa2cabd5752d9c8fa65"},"headline":"\u0622\u0645\u0648\u0632\u0634 \u0646\u0635\u0628 \u0648 \u0631\u0627\u0647\u200c\u0627\u0646\u062f\u0627\u0632\u06cc (ocserv) OpenConnect Server \u0628\u0631 \u0631\u0648\u06cc \u0627\u0648\u0628\u0648\u0646\u062a\u0648 22.04 \u0628\u0627 Let&#8217;s Encrypt","datePublished":"2025-12-18T19:19:58+00:00","dateModified":"2025-12-18T19:27:27+00:00","mainEntityOfPage":{"@id":"https:\/\/www.itpiran.net\/blog\/os\/ubuntu\/openconnect-ocserv-ubuntu-22-04\/"},"wordCount":286,"publisher":{"@id":"https:\/\/www.itpiran.net\/blog\/#organization"},"image":{"@id":"https:\/\/www.itpiran.net\/blog\/os\/ubuntu\/openconnect-ocserv-ubuntu-22-04\/#primaryimage"},"thumbnailUrl":"https:\/\/cdn.itpiran.net\/2025\/12\/18224931\/openconnect-vpn-ubuntu-22-04-17620.webp","keywords":["VPN","vps","vps server"],"articleSection":["ubuntu","\u0627\u0645\u0646\u06cc\u062a"],"inLanguage":"de"},{"@type":"WebPage","@id":"https:\/\/www.itpiran.net\/blog\/os\/ubuntu\/openconnect-ocserv-ubuntu-22-04\/","url":"https:\/\/www.itpiran.net\/blog\/os\/ubuntu\/openconnect-ocserv-ubuntu-22-04\/","name":"Installation und Einrichtung des OpenConnect-Servers (ocserv) unter Ubuntu 22.04 mit Let&#039;s Encrypt \u2013 ITPiran-Blog","isPartOf":{"@id":"https:\/\/www.itpiran.net\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.itpiran.net\/blog\/os\/ubuntu\/openconnect-ocserv-ubuntu-22-04\/#primaryimage"},"image":{"@id":"https:\/\/www.itpiran.net\/blog\/os\/ubuntu\/openconnect-ocserv-ubuntu-22-04\/#primaryimage"},"thumbnailUrl":"https:\/\/cdn.itpiran.net\/2025\/12\/18224931\/openconnect-vpn-ubuntu-22-04-17620.webp","datePublished":"2025-12-18T19:19:58+00:00","dateModified":"2025-12-18T19:27:27+00:00","description":"Dieser Artikel zeigt Ihnen, wie Sie den OpenConnect-Server (ocserv) unter Ubuntu 22.04 einrichten, ihn mit Let&#039;s Encrypt sichern und ein Zertifikat erhalten.","breadcrumb":{"@id":"https:\/\/www.itpiran.net\/blog\/os\/ubuntu\/openconnect-ocserv-ubuntu-22-04\/#breadcrumb"},"inLanguage":"de","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.itpiran.net\/blog\/os\/ubuntu\/openconnect-ocserv-ubuntu-22-04\/"]}]},{"@type":"ImageObject","inLanguage":"de","@id":"https:\/\/www.itpiran.net\/blog\/os\/ubuntu\/openconnect-ocserv-ubuntu-22-04\/#primaryimage","url":"https:\/\/cdn.itpiran.net\/2025\/12\/18224931\/openconnect-vpn-ubuntu-22-04-17620.webp","contentUrl":"https:\/\/cdn.itpiran.net\/2025\/12\/18224931\/openconnect-vpn-ubuntu-22-04-17620.webp","width":1654,"height":1024,"caption":"\u0631\u0627\u0647\u0646\u0645\u0627\u06cc \u06af\u0627\u0645\u200c\u0628\u0647\u200c\u06af\u0627\u0645 \u0646\u0635\u0628 OpenConnect VPN Server (ocserv) \u0628\u0631 \u0631\u0648\u06cc \u0627\u0648\u0628\u0648\u0646\u062a\u0648 22.04 \u0648 \u062f\u0631\u06cc\u0627\u0641\u062a \u06af\u0648\u0627\u0647\u06cc Let\u2019s Encrypt."},{"@type":"BreadcrumbList","@id":"https:\/\/www.itpiran.net\/blog\/os\/ubuntu\/openconnect-ocserv-ubuntu-22-04\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.itpiran.net\/blog\/"},{"@type":"ListItem","position":2,"name":"\u0633\u06cc\u0633\u062a\u0645 \u0639\u0627\u0645\u0644","item":"https:\/\/www.itpiran.net\/blog\/category\/os\/"},{"@type":"ListItem","position":3,"name":"ubuntu","item":"https:\/\/www.itpiran.net\/blog\/category\/os\/ubuntu\/"},{"@type":"ListItem","position":4,"name":"\u0622\u0645\u0648\u0632\u0634 \u0646\u0635\u0628 \u0648 \u0631\u0627\u0647\u200c\u0627\u0646\u062f\u0627\u0632\u06cc (ocserv) OpenConnect Server \u0628\u0631 \u0631\u0648\u06cc \u0627\u0648\u0628\u0648\u0646\u062a\u0648 22.04 \u0628\u0627 Let&#8217;s Encrypt"}]},{"@type":"WebSite","@id":"https:\/\/www.itpiran.net\/blog\/#website","url":"https:\/\/www.itpiran.net\/blog\/","name":"ITPiran Blog","description":"Iranische Nachrichten und Artikel zum Thema nachhaltiger Handel","publisher":{"@id":"https:\/\/www.itpiran.net\/blog\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.itpiran.net\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"de"},{"@type":"Organization","@id":"https:\/\/www.itpiran.net\/blog\/#organization","name":"Nachhaltiger iranischer Unternehmensblog","alternateName":"ITPIran Blog","url":"https:\/\/www.itpiran.net\/blog\/","logo":{"@type":"ImageObject","inLanguage":"de","@id":"https:\/\/www.itpiran.net\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/cdn.itpiran.net\/2023\/12\/27150508\/cropped-ITPIRAN-BLOG-LOGO-2.png","contentUrl":"https:\/\/cdn.itpiran.net\/2023\/12\/27150508\/cropped-ITPIRAN-BLOG-LOGO-2.png","width":512,"height":512,"caption":"\u0628\u0644\u0627\u06af \u062a\u062c\u0627\u0631\u062a \u067e\u0627\u06cc\u062f\u0627\u0631 \u0627\u06cc\u0631\u0627\u0646\u06cc\u0627\u0646"},"image":{"@id":"https:\/\/www.itpiran.net\/blog\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/www.itpiran.net\/blog\/#\/schema\/person\/f302f8428a00aaa2cabd5752d9c8fa65","name":"Elahe","url":"https:\/\/www.itpiran.net\/blog\/de\/author\/elahe\/"}]}},"_links":{"self":[{"href":"https:\/\/www.itpiran.net\/blog\/de\/wp-json\/wp\/v2\/posts\/17620","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.itpiran.net\/blog\/de\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.itpiran.net\/blog\/de\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.itpiran.net\/blog\/de\/wp-json\/wp\/v2\/users\/8"}],"replies":[{"embeddable":true,"href":"https:\/\/www.itpiran.net\/blog\/de\/wp-json\/wp\/v2\/comments?post=17620"}],"version-history":[{"count":3,"href":"https:\/\/www.itpiran.net\/blog\/de\/wp-json\/wp\/v2\/posts\/17620\/revisions"}],"predecessor-version":[{"id":17624,"href":"https:\/\/www.itpiran.net\/blog\/de\/wp-json\/wp\/v2\/posts\/17620\/revisions\/17624"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.itpiran.net\/blog\/de\/wp-json\/wp\/v2\/media\/17622"}],"wp:attachment":[{"href":"https:\/\/www.itpiran.net\/blog\/de\/wp-json\/wp\/v2\/media?parent=17620"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.itpiran.net\/blog\/de\/wp-json\/wp\/v2\/categories?post=17620"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.itpiran.net\/blog\/de\/wp-json\/wp\/v2\/tags?post=17620"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}