OpenVPN

Sekcia: Konfigurácia 01.12.2008 | 12:10
Avatar j4kub Debian  Používateľ
dobry den,
nakonfiguroval som OpenVPN, vygeneroval som kluce pripojil som sa z clienta ( windows ) na openvpn, kluce su overene, vpn klient dostane IP adresu 10.1.0.4 a chcem docielit aby som sa dokazal pripojit na pocitace ktore su v sieti 10.0.0.0 na strane servra, neviem kde robim chybu:

server configuracia:
port 1194
proto tcp
dev tap
ca ca.crt
cert server.crt
key server.key
dh dh1024.pem
server 10.1.0.0 255.255.255.0
ifconfig-pool-persist ipp.txt
ping 10
ping-restart 120
comp-lzo
user nobody
group users
persist-key
persist-tun
status openvpn-status.log
verb 3
route 10.0.0.0 255.255.255.0
route-gateway 10.1.0.1
client-to-client


client:
dev tap
proto tcp-client
remote 87.197.128.48 1194
ca C:\\Program\ Files\\OpenVPN\\config\\doma\\ca.crt
cert C:\\Program\ Files\\OpenVPN\\config\\doma\\jakub.crt
key C:\\Program\ Files\\OpenVPN\\config\\doma\\jakub.key
dh C:\\Program\ Files\\OpenVPN\\config\\doma\\dh1024.pem
tls-client
port 1194
ping 10
ping-restart 120
ping-timer-rem
persist-tun
persist-key
tun-mtu 1500
mute-replay-warnings
verb 3
cipher BF-CBC
keysize 128
auth SHA1
pull


a log z clienta z windowsu:
Mon Dec 01 11:03:04 2008 [server] Peer Connection Initiated with 87.197.128.48:1194
Mon Dec 01 11:03:05 2008 SENT CONTROL [server]: 'PUSH_REQUEST' (status=1)
Mon Dec 01 11:03:05 2008 PUSH: Received control message: 'PUSH_REPLY,route-gateway 10.1.0.1,ifconfig 10.1.0.4 255.255.255.0'
Mon Dec 01 11:03:05 2008 OPTIONS IMPORT: --ifconfig/up options modified
Mon Dec 01 11:03:05 2008 OPTIONS IMPORT: route-related options modified
Mon Dec 01 11:03:05 2008 ROUTE default_gateway=192.168.9.1
Mon Dec 01 11:03:07 2008 RESOLVE: Cannot resolve host address: -p: [HOST_NOT_FOUND] The specified host is unknown.
Mon Dec 01 11:03:07 2008 OpenVPN ROUTE: failed to parse/resolve route for host/network: -p
Mon Dec 01 11:03:07 2008 TAP-WIN32 device [Open VPN] opened: \\.\Global\{49DAD143-33FA-458C-89D6-2A8A5220F035}.tap
Mon Dec 01 11:03:07 2008 TAP-Win32 Driver Version 9.4
Mon Dec 01 11:03:07 2008 TAP-Win32 MTU=1500
Mon Dec 01 11:03:07 2008 Notified TAP-Win32 driver to set a DHCP IP/netmask of 10.1.0.4/255.255.255.0 on interface {49DAD143-33FA-458C-89D6-2A8A5220F035} [DHCP-serv: 10.1.0.0, lease-time: 31536000]
Mon Dec 01 11:03:07 2008 NOTE: FlushIpNetTable failed on interface [6] {49DAD143-33FA-458C-89D6-2A8A5220F035} (status=6) : Popisovač nie je platný.
Mon Dec 01 11:03:12 2008 TEST ROUTES: 0/0 succeeded len=0 ret=1 a=0 u/d=up
Mon Dec 01 11:03:12 2008 Initialization Sequence Completed

iptables:
Presix:/# iptables -L
Presix:/# iptables -L
Chain INPUT (policy ACCEPT)
target prot opt source destination

Chain FORWARD (policy ACCEPT)
target prot opt source destination
ACCEPT 0 -- 10.0.0.0/24 anywhere state NEW
ACCEPT 0 -- 10.1.0.0/24 10.0.0.0/24
ACCEPT 0 -- 10.0.0.0/24 10.1.0.0/24
ACCEPT 0 -- anywhere anywhere state RELATED,ESTABLISHED
ACCEPT tcp -- anywhere 10.0.0.3 state NEW tcp dpts:3389:3390

Chain OUTPUT (policy ACCEPT)
target prot opt source destination


Chain OUTPUT (policy ACCEPT)
target prot opt source destination
Presix:/#



poprosim o pomoc, za skoru odpoved vopred dakujem,
ale moj amatersky odhad je ze bude nieco s tymto:
Mon Dec 01 11:03:05 2008 PUSH: Received control message: 'PUSH_REPLY,route-gateway 10.1.0.1,ifconfig 10.1.0.4 255.255.255.0'

vopred dakujem
ucim sa debiana - berte na mna ohlad ...
    • Re: OpenVPN 02.12.2008 | 18:47
      j4kub   Návštevník
      prosim, ziadne rady?? :(
    • Re: OpenVPN 03.12.2008 | 02:30
      Tomas   Návštevník
      Skusil by som zmenit v konfiguraku servera riadok

      route 10.0.0.0 255.255.255.0

      na

      push "route 10.0.0.0 255.255.255.0"



      Mimochodom, preco na nadviazanie spojenia pouzivas TCP porty? Zda sa mi to byt zbytocne.
    • Re: OpenVPN 03.12.2008 | 11:18
      Avatar dm12   Používateľ
      To je jednoduse problem s routovanim. Musite na strane serveru pridat do routovaci tabulky routovani ze site vpn do vnitrni site pres sitovy adapter firewallu pripojujici vnitrni sit. Radek s timto routovanim pridate treba do souboru rc.local aby doslo k jeho spousteni pri startu serveru. Takze prikaz bude vypadat asi takto:
      route add -net 10.1.0.0 netmask 255.255.255.0 gw "adresa adapteru firewallu vnitrni site" dev eth?

      eth? je adapter firewallu do vnitrni site.

      To je vse. Melo by to fungovat. Dejte vedet jak to dopadlo.

      Jinak ja bych potreboval poradit s filtrovanim posty. Viz prispevek SMTP gateway - amavisd-new. Pokud vite sam nebo o nekom kdo vi, budu rad.
      • Re: OpenVPN 03.12.2008 | 13:14
        Avatar j4kub Debian  Používateľ
        cize ked mam spraveny subor nat.sh, v ktorom mam napisene routovanie a masquaradu, tak mi tam staci dopisat toto:
        route add -net 10.1.0.0 netmask 255.255.255.0 gw 10.0.0.1 dev eth0

        a by to malo ist?
        hned by som to vyskusal len mam ten server offline :/
        ale dam vediet ako to dopadlo
        ucim sa debiana - berte na mna ohlad ...
        • Re: OpenVPN 03.12.2008 | 13:15
          Avatar j4kub Debian  Používateľ
          zabudol som dotat ze subor nat.sh sa mi spusta pri starte
          ucim sa debiana - berte na mna ohlad ...
      • Re: OpenVPN 03.12.2008 | 13:53
        Avatar j4kub Debian  Používateľ
        s filtrovanim posty by som rad pomohol ale nemam najmensie ponatie :)
        s linuxom zacinam pomalicky a snazim sa co najviac spravit sam :)
        ucim sa debiana - berte na mna ohlad ...
      • Re: OpenVPN 03.12.2008 | 14:08
        Avatar j4kub Debian  Používateľ
        Presix:~# route add -net 10.1.0.0 netmask 255.255.255.0 gw 10.0.0.1 dev eth0
        SIOCADDRT: Sieť nie je dostupná

        takze nejde :D
        ucim sa debiana - berte na mna ohlad ...
        • Re: OpenVPN 03.12.2008 | 14:51
          Avatar dm12   Používateľ
          Mozna to bude tim ze pouzivam OpenVPN v rezimu "routed" a ne "briged" (dev tun a ne dev tap). Tam se potom chova odlisne a nevim presne jak. Zkusil bych to predelat na dev tun. Jak server, tak klienta.
    • Re: OpenVPN 03.12.2008 | 14:43
      Avatar j4kub Debian  Používateľ
      este ak vam pomoze tak prikladam vypis z windowsu
      print route

      C:\Documents and Settings\J4kub>route print
      ===========================================================================
      Zoznam rozhraní
      0x1 ........................... MS TCP Loopback interface
      0x2 ...7a 79 05 59 8a a8 ...... Hamachi Network Interface
      0x3 ...00 0e 35 b3 98 94 ...... Intel(R) PRO/Wireless 2200BG Network Connection
      - Packet Scheduler Miniport
      0x4 ...00 03 0d 24 23 cf ...... Realtek RTL8139 Family PCI Fast Ethernet NIC - P
      acket Scheduler Miniport
      0x5 ...00 0c 76 d4 19 54 ...... Bluetooth PAN Network Adapter - Packet Scheduler
      Miniport
      0x6 ...00 ff 49 da d1 43 ...... TAP-Win32 Adapter V9 - Packet Scheduler Miniport

      ===========================================================================
      ===========================================================================
      Aktívne trasy:
      Cieľ v sieti Maska siete Brána Rozhranie Metrika
      0.0.0.0 0.0.0.0 192.168.9.1 192.168.9.2 20
      5.0.0.0 255.0.0.0 5.89.138.168 5.89.138.168 20
      5.89.138.168 255.255.255.255 127.0.0.1 127.0.0.1 20
      5.255.255.255 255.255.255.255 5.89.138.168 5.89.138.168 20
      10.0.0.0 255.255.255.0 10.1.0.1 10.1.0.4 1
      10.1.0.0 255.255.255.0 10.1.0.4 10.1.0.4 30
      10.1.0.4 255.255.255.255 127.0.0.1 127.0.0.1 30
      10.255.255.255 255.255.255.255 10.1.0.4 10.1.0.4 30
      127.0.0.0 255.0.0.0 127.0.0.1 127.0.0.1 1
      192.168.9.0 255.255.255.0 192.168.9.2 192.168.9.2 20
      192.168.9.2 255.255.255.255 127.0.0.1 127.0.0.1 20
      192.168.9.255 255.255.255.255 192.168.9.2 192.168.9.2 20
      224.0.0.0 240.0.0.0 5.89.138.168 5.89.138.168 20
      224.0.0.0 240.0.0.0 10.1.0.4 10.1.0.4 30
      224.0.0.0 240.0.0.0 192.168.9.2 192.168.9.2 20
      255.255.255.255 255.255.255.255 5.89.138.168 5 1
      255.255.255.255 255.255.255.255 5.89.138.168 3 1
      255.255.255.255 255.255.255.255 5.89.138.168 5.89.138.168 1
      255.255.255.255 255.255.255.255 10.1.0.4 10.1.0.4 1
      255.255.255.255 255.255.255.255 192.168.9.2 192.168.9.2 1
      Predvolená brána: 192.168.9.1
      ===========================================================================
      Trvalé trasy:
      Žiadne

      C:\Documents and Settings\J4kub>
      ucim sa debiana - berte na mna ohlad ...
    • Re: OpenVPN 04.12.2008 | 22:48
      Avatar j4kub Debian  Používateľ
      prosim ziadne napady??
      ucim sa debiana - berte na mna ohlad ...
      • Re: OpenVPN 05.12.2008 | 14:46
        DM12   Návštevník
        A zkousel jsi uz OpenVPN v rezimu "routed" a ne "briged" (dev tun a ne dev tap)? V rezimu bridged se to potom chova odlisne. Zkusil bych to predelat na dev tun. Jak server, tak klienta.
        • Re: OpenVPN 06.12.2008 | 03:05
          Avatar j4kub Debian  Používateľ
          tun som skusal a az ked som doplnil riadoky

          push "ifconfig 10.1.0.6 10.1.0.5"
          push "route 10.1.0.0 255.255.255.0"

          tak konecne pignem ipcku 10.0.0.1
          ucim sa debiana - berte na mna ohlad ...