Hallo
ich habe ein Problem mit OpenVPN beim Verbindungsaufbau von WinXP OpenVPN 2.1rc15 als Client zum Server 2.1rc13 auf meiner Fritz!Box 7270 mit Freetz rev.2874.
Hier der Client-Log:
Meine (generierte) server.conf:
Und hier noch die client.conf:
Ich hoffe, jemand kann mir dabei helfen. Ich blicke da zuwenig durch...
Danke!
ich habe ein Problem mit OpenVPN beim Verbindungsaufbau von WinXP OpenVPN 2.1rc15 als Client zum Server 2.1rc13 auf meiner Fritz!Box 7270 mit Freetz rev.2874.
Hier der Client-Log:
Code:
Thu Dec 18 14:26:22 2008 OpenVPN 2.1_rc15 i686-pc-mingw32 [SSL] [LZO2] [PKCS11]
built on Nov 19 2008
Thu Dec 18 14:26:22 2008 NOTE: OpenVPN 2.1 requires '--script-security 2' or hig
her to call user-defined scripts or executables
Thu Dec 18 14:26:22 2008 LZO compression initialized
Thu Dec 18 14:26:22 2008 Control Channel MTU parms [ L:1542 D:138 EF:38 EB:0 ET:
0 EL:0 ]
Thu Dec 18 14:26:22 2008 Data Channel MTU parms [ L:1542 D:1450 EF:42 EB:135 ET:
0 EL:0 AF:3/1 ]
Thu Dec 18 14:26:22 2008 Local Options hash (VER=V4): '827c9ed0'
Thu Dec 18 14:26:22 2008 Expected Remote Options hash (VER=V4): '974bef3f'
Thu Dec 18 14:26:22 2008 Socket Buffers: R=[8192->8192] S=[8192->8192]
Thu Dec 18 14:26:22 2008 UDPv4 link local: [undef]
Thu Dec 18 14:26:22 2008 UDPv4 link remote: 81.221.123.203:1194
Thu Dec 18 14:26:22 2008 TLS: Initial packet from 81.221.123.203:1194, sid=905c8
59a 6cb0692c
Thu Dec 18 14:26:22 2008 VERIFY OK: depth=1, /C=CH/ST=BL/L=Anwil/O=Stocker/CN=st
ocker.nu/[email protected]
Thu Dec 18 14:26:22 2008 VERIFY OK: nsCertType=SERVER
Thu Dec 18 14:26:22 2008 VERIFY OK: depth=0, /C=CH/ST=BL/O=Stocker/CN=server/ema
[email protected]
Thu Dec 18 14:26:25 2008 Data Channel Encrypt: Cipher 'DES-EDE3-CBC' initialized
with 192 bit key
Thu Dec 18 14:26:25 2008 Data Channel Encrypt: Using 160 bit message hash 'SHA1'
for HMAC authentication
Thu Dec 18 14:26:25 2008 Data Channel Decrypt: Cipher 'DES-EDE3-CBC' initialized
with 192 bit key
Thu Dec 18 14:26:25 2008 Data Channel Decrypt: Using 160 bit message hash 'SHA1'
for HMAC authentication
Thu Dec 18 14:26:25 2008 Control Channel: TLSv1, cipher TLSv1/SSLv3 DHE-RSA-AES2
56-SHA, 1024 bit RSA
Thu Dec 18 14:26:25 2008 [server] Peer Connection Initiated with 81.221.123.203:
1194
Thu Dec 18 14:26:26 2008 SENT CONTROL [server]: 'PUSH_REQUEST' (status=1)
Thu Dec 18 14:26:26 2008 PUSH: Received control message: 'PUSH_REPLY,route 172.1
6.1.1 ,route-gateway 172.16.1.1 ,route 192.168.1.0 255.255.255.0,ping 10,ping-re
start 120,ifconfig 172.16.1.10 172.16.1.9'
Thu Dec 18 14:26:26 2008 OPTIONS IMPORT: timers and/or timeouts modified
Thu Dec 18 14:26:26 2008 OPTIONS IMPORT: --ifconfig/up options modified
Thu Dec 18 14:26:26 2008 OPTIONS IMPORT: route options modified
Thu Dec 18 14:26:26 2008 OPTIONS IMPORT: route-related options modified
Thu Dec 18 14:26:26 2008 ROUTE default_gateway=192.168.1.1
Thu Dec 18 14:26:26 2008 TAP-WIN32 device [LAN-Verbindung 6] opened: \\.\Global\
{29385B1D-B0D4-4BB5-A626-DA232E1F0158}.tap
Thu Dec 18 14:26:26 2008 TAP-Win32 Driver Version 9.4
Thu Dec 18 14:26:26 2008 TAP-Win32 MTU=1500
Thu Dec 18 14:26:26 2008 Notified TAP-Win32 driver to set a DHCP IP/netmask of 1
72.16.1.10/255.255.255.252 on interface {29385B1D-B0D4-4BB5-A626-DA232E1F0158} [
DHCP-serv: 172.16.1.9, lease-time: 31536000]
Thu Dec 18 14:26:26 2008 Successful ARP Flush on interface [1835012] {29385B1D-B
0D4-4BB5-A626-DA232E1F0158}
Thu Dec 18 14:26:31 2008 TEST ROUTES: 0/0 succeeded len=2 ret=0 a=0 u/d=down
Thu Dec 18 14:26:31 2008 Route: Waiting for TUN/TAP interface to come up...
Thu Dec 18 14:26:36 2008 TEST ROUTES: 0/0 succeeded len=2 ret=0 a=0 u/d=down
Thu Dec 18 14:26:36 2008 Route: Waiting for TUN/TAP interface to come up...
Thu Dec 18 14:26:37 2008 TEST ROUTES: 0/2 succeeded len=2 ret=0 a=0 u/d=up
Thu Dec 18 14:26:37 2008 Route: Waiting for TUN/TAP interface to come up...
Thu Dec 18 14:26:38 2008 TEST ROUTES: 0/2 succeeded len=2 ret=0 a=0 u/d=up
Thu Dec 18 14:26:38 2008 Route: Waiting for TUN/TAP interface to come up...
...
...
Thu Dec 18 14:27:01 2008 TEST ROUTES: 0/2 succeeded len=2 ret=0 a=0 u/d=up
Thu Dec 18 14:27:01 2008 OpenVPN ROUTE: omitted no-op route: 172.16.1.1/255.255.
255.255 -> 172.16.1.1
Thu Dec 18 14:27:01 2008 WARNING: potential route subnet conflict between local
LAN [192.168.1.0/255.255.255.0] and remote VPN [192.168.1.0/255.255.255.0]
Thu Dec 18 14:27:01 2008 C:\WINDOWS\system32\route.exe ADD 192.168.1.0 MASK 255.
255.255.0 172.16.1.1
Thu Dec 18 14:27:01 2008 Warning: route gateway is not reachable on any active n
etwork adapters: 172.16.1.1
Thu Dec 18 14:27:01 2008 Route addition via IPAPI failed [adaptive]
Thu Dec 18 14:27:01 2008 Route addition fallback to route.exe
Hinzufügen der Route fehlgeschlagen: Entweder ist der Schnittstellenindex ungült
ig oder das Gateway befindet sich nicht im gleichen Netzwerk wie die Schnittstel
le. Überprüfen Sie die IP-Adresstabelle für diesen Rechner.
Meine (generierte) server.conf:
Code:
# OpenVPN 2.1 Config, Thu Dec 18 14:05:44 CET 2008
proto udp
dev tun
ca /tmp/flash/ca.crt
cert /tmp/flash/box.crt
key /tmp/flash/box.key
dh /tmp/flash/dh.pem
tls-server
port 1194
mode server
ifconfig-pool 172.16.1.10 172.16.1.20
push "route 172.16.1.1 "
push "route-gateway 172.16.1.1 "
ifconfig 172.16.1.1 172.16.1.2
push "route 192.168.1.0 255.255.255.0"
tun-mtu 1500
mssfix
verb 3
daemon
cipher DES-EDE3-CBC
comp-lzo
keepalive 10 120
Und hier noch die client.conf:
Code:
client
dev tun
proto udp
remote 81.221.123.203 1194
nobind
persist-key
persist-tun
ca ca.crt
cert client1.crt
key client1.key
ns-cert-type server
# tls-auth secret.key 1
cipher DES-EDE3-CBC
comp-lzo
verb 3
Ich hoffe, jemand kann mir dabei helfen. Ich blicke da zuwenig durch...
Danke!