aws install openvpn and its comparison

Overview

很多时候需要vpn(virtual private network)来保护网络privacy, 以及跨越一些restriction. 所以记录openvpn的安装过程及其对比,

  1. 使用aws安装openvpn的主要流程
  2. 列举安装后的openvpn与其他vpn之间的speedtest对比

How vpn works

利用encryption key在vpn-client与vpn-server之间加密/解密网络数据.

Only your computer and the VPN server know this key. image

vpn diff, credits drsoft

Install openvpn on aws

这里采用aws的ec2作为server, 当然可以采用更轻量级的lightsail.

sign up aws account

这里需要用到真实信用卡, 并临时扣除$1. 否则虽然可以login, 但是有很多restrictions, e.g., 不能launch ec2.

image

aws account homepage

launch ec2 with openvpn AMI

  1. choose openvpn AMI
  2. choose suitable ec2 instance
  3. create a new key pair (you can only download from the web once)

image

choose AMI

image

choose instance

image

create & download key pair

ps.

有需求的话, 这里可以使用shadowsocks来替换openvpn.

这次采用openvpn是因为aws free tier集成了它, 使得安装一键化.

当然如果是shadowsocks的话, 就是在linux下pip/wget来安装.

configure openvpn server using SSH

here ip1 is your Public IPv4 address, ip2 is your Private IPv4 address,

  1. ssh to ec2 from local with root
    • ssh -i somepath/your-key-pair.pem root@ec2-ip1.amazonaws.com
    • if the pem are too open, then chmod 400 somepath/your-key-pair.pem to make it private
    • initial openvpn access server config image
  2. ssh to ec2 from local with openvpnas
    • ssh -i somepath/your-key-pair.pem openvpnas@ec2-ip1.amazonaws.com
  3. setup password used by openvpn UI
    • sudo passwd openvpn
  4. login openvpn web UI(optional)
    • type ip1 in chrome

image

ip1 and ip2 in aws web

image

openvpn web UI login

image

openvpn web UI

connect to openvpn server using its client

我的设备是mac和iPhone,

mac

image

import profile in mac

image

login

ios

image

import profile in ios

current usage check

image

two users surfing

aws free tier limit

如果经常使用刚搭建的vpn上传out/下载in YouTube, 那么流量会飞快消耗. 此时很可能需要额外支付超过每月15GB的流量

image

check ec2 network usage

Comparison

details

vpn no vpn openvpn Hotspot Shield VPN - Super Unlimited Proxy
snapshot image image image image

summary

image

comparison

可以看出,

  1. normally多了一层vpn会慢一些(encrypt, etc.)
  2. openvpn较快
  3. hotspot shield较慢

Reference

  1. setup a FREE VPN server in the cloud(AWS)
  2. Amazon VPC是Amazon EC2的网络层
  3. What is a VPN?