RalfFriedl
IPPF-Urgestein
- Mitglied seit
- 22 Apr 2007
- Beiträge
- 12,343
- Punkte für Reaktionen
- 1
- Punkte
- 0
Wenn jetzt schon ein Ping von der Konsole nicht mehr funktioniert, dann prüfe zuerst die VPN-Verbindung.
Thu Nov 11 13:52:46 2010 OpenVPN 2.1.3 mipsel-linux [SSL] [LZO2] [EPOLL] [MH] [PF_INET6] built on Nov 8 2010
Thu Nov 11 13:52:46 2010 WARNING: file '/var/media/ftp/uStor01/vpnuk-password.txt' is group or others accessible
Thu Nov 11 13:52:46 2010 NOTE: OpenVPN 2.1 requires '--script-security 2' or higher to call user-defined scripts or executables
Thu Nov 11 13:52:46 2010 WARNING: file '/var/media/ftp/uStor01/ta.key' is group or others accessible
Thu Nov 11 13:52:46 2010 Control Channel Authentication: using '/var/media/ftp/uStor01/ta.key' as a OpenVPN static key file
Thu Nov 11 13:52:46 2010 Outgoing Control Channel Authentication: Using 160 bit message hash 'SHA1' for HMAC authentication
Thu Nov 11 13:52:46 2010 Incoming Control Channel Authentication: Using 160 bit message hash 'SHA1' for HMAC authentication
Thu Nov 11 13:52:46 2010 LZO compression initialized
Thu Nov 11 13:52:46 2010 Control Channel MTU parms [ L:1542 D:166 EF:66 EB:0 ET:0 EL:0 ]
Thu Nov 11 13:52:46 2010 Socket Buffers: R=[108544->131072] S=[108544->131072]
Thu Nov 11 13:52:46 2010 Data Channel MTU parms [ L:1542 D:1450 EF:42 EB:135 ET:0 EL:0 AF:3/1 ]
Thu Nov 11 13:52:46 2010 UDPv4 link local: [undef]
Thu Nov 11 13:52:46 2010 UDPv4 link remote: [AF_INET]213.229.71.81:1194
Thu Nov 11 13:52:46 2010 TLS: Initial packet from [AF_INET]213.229.71.81:1194, sid=f96f6f59 fe79973f
Thu Nov 11 13:52:46 2010 WARNING: this configuration may cache passwords in memory -- use the auth-nocache option to prevent this
Thu Nov 11 13:52:46 2010 VERIFY OK: depth=1, /C=GB/ST=GB/L=London/O=VPNUK/CN=VPNUK_CA/[email protected]
Thu Nov 11 13:52:46 2010 VERIFY OK: nsCertType=SERVER
Thu Nov 11 13:52:46 2010 VERIFY OK: depth=0, /C=GB/ST=GB/L=London/O=VPNUK/CN=server/[email protected]
Thu Nov 11 13:52:47 2010 Data Channel Encrypt: Cipher 'BF-CBC' initialized with 128 bit key
Thu Nov 11 13:52:47 2010 Data Channel Encrypt: Using 160 bit message hash 'SHA1' for HMAC authentication
Thu Nov 11 13:52:47 2010 Data Channel Decrypt: Cipher 'BF-CBC' initialized with 128 bit key
Thu Nov 11 13:52:47 2010 Data Channel Decrypt: Using 160 bit message hash 'SHA1' for HMAC authentication
Thu Nov 11 13:52:47 2010 Control Channel: TLSv1, cipher TLSv1/SSLv3 DHE-RSA-AES256-SHA, 1024 bit RSA
Thu Nov 11 13:52:47 2010 [server] Peer Connection Initiated with [AF_INET]213.229.71.81:1194
Thu Nov 11 13:52:49 2010 SENT CONTROL [server]: 'PUSH_REQUEST' (status=1)
Thu Nov 11 13:52:49 2010 PUSH: Received control message: 'PUSH_REPLY,redirect-gateway def1,dhcp-option NTP 10.10.11.1,dhcp-option DNS 10.10.11.1,ping-timer-rem,route 10.10.11.0 255.255.255.0,topology net30,ping 10,ping-restart 60,ifconfig 10.10.11.30 10.10.11.29'
Thu Nov 11 13:52:49 2010 OPTIONS IMPORT: timers and/or timeouts modified
Thu Nov 11 13:52:49 2010 OPTIONS IMPORT: --ifconfig/up options modified
Thu Nov 11 13:52:49 2010 OPTIONS IMPORT: route options modified
Thu Nov 11 13:52:49 2010 OPTIONS IMPORT: --ip-win32 and/or --dhcp-option options modified
Thu Nov 11 13:52:49 2010 TUN/TAP device tun0 opened
Thu Nov 11 13:52:49 2010 TUN/TAP TX queue length set to 100
Thu Nov 11 13:52:49 2010 /sbin/ifconfig tun0 10.10.11.30 pointopoint 10.10.11.29 mtu 1500
Thu Nov 11 13:52:51 2010 NOTE: unable to redirect default gateway -- Cannot read current default gateway from system
Thu Nov 11 13:52:51 2010 /sbin/route add -net 10.10.11.0 netmask 255.255.255.0 gw 10.10.11.29
Thu Nov 11 13:52:51 2010 Initialization Sequence Completed
ip ro add 213.229.71.81 dev dsl
ip ro del default
ip ro add default via 10.10.11.29
dauerhaft ausführbar machen.ip ro add 213.229.71.81 dev dsl
ip ro del default
ip ro add default via 10.10.11.29
Das dürfte vermutlich ein bekannter "Fehler" von AVM sein. Eine mögliche Änderung/Korrektur findest du im Ticket 783. Die sollte bei dir möglich sein, denn der Nebeneffekt, dass das AVM-VPN damit nicht mehr geht, sollte auf der 5140 ja egal sein...Es wäre sinnvoll, herauszufinden, warum er nicht das aktuelle Gateway auslesen kann.
Kernel IP routing table
Destination Gateway Genmask Flags Metric Ref Use Iface
192.168.180.1 * 255.255.255.255 UH 2 0 0 dsl
91.xx.134.xx * 255.255.255.255 UH 2 0 0 dsl
192.168.180.2 * 255.255.255.255 UH 2 0 0 dsl
192.168.200.2 * 255.255.255.255 UH 0 0 0 tun0
192.168.178.0 * 255.255.255.0 U 0 0 0 lan
192.168.179.0 * 255.255.255.0 U 0 0 0 guest
169.254.0.0 * 255.255.0.0 U 0 0 0 lan
default * 0.0.0.0 U 2 0 0 dsl