Hi,
mal ein Bericht mit Deiner neuesten Version vom 12.08.
Zur Erinnerung:
192.168.200.x ist das VPN Netz.
192.168.201.x ist das Netz des Servers
192.168.202.x ist der erste Client (Zertifikatname: Client202)
192.168.203.x ist der zweite Client (Zertifikatname: Client203)
Auf allen Boxen lege ich die Dateien in /var/tmp/flash ab. Danach führe ich folgendes aus, um die Dateien zu "aktivieren":
Code:
mount -o bind /var/tmp/flash/rc.openvpn-lzo /etc/init.d/rc.openvpn-lzo
mount -o bind /var/tmp/flash/openvpn-lzo.cgi /usr/lib/cgi-bin/openvpn-lzo.cgi
mount -o bind /var/tmp/flash/openvpn-lzo.cfg /etc/default.openvpn-lzo/openvpn-lzo.cfg
mount -o bind /var/tmp/flash/openvpn-lzo.cfg /var/mod/etc/conf/openvpn-lzo.cfg
mount -o bind /var/tmp/flash/openvpn-lzo_conf /etc/default.openvpn-lzo/openvpn-lzo_conf
Prinzipiell sollte das doch stimmern, oder? (voll die Newbie-Frage
)
Danach konfiguriere ihc über das Webinterface.
Auf dem Server sieht alles gut aus. Die erzeugte Conf inkl. client-Dir:
Code:
/var/tmp $ cat /mod/etc/openvpn-lzo.conf
##############################################################
#
# OpenVPN 2.1 Config, generated Mon Aug 13 10:32:28 CEST 2007
#
##############################################################
proto udp
port 1194
dev tun
ca /tmp/flash/ca.crt
cert /tmp/flash/box.crt
key /tmp/flash/box.key
dh /tmp/flash/dh.pem
tls-server
ifconfig 192.168.200.1 255.255.255.0
mode server
client-config-dir /var/tmp/ovpn
topology subnet
max-clients 2
push "route 192.168.201.0 255.255.255.0 192.168.200.1"
route 192.168.202.0 255.255.255.0 192.168.200.2
route 192.168.203.0 255.255.255.0 192.168.200.3
tun-mtu 1500
mssfix
log /var/tmp/openvpn-debug.out
daemon
verb 6
cipher AES-128-CBC
comp-lzo
keepalive 10 120
status /var/log/openvpn.log
/var/tmp/ovpn $ cat client202
ifconfig-push 192.168.200.2 192.168.200.1
push "topology subnet"
iroute 192.168.202.0 255.255.255.0
push "route 192.168.203.0 255.255.255.0 192.168.200.3 "
/var/tmp/ovpn $ cat client203
ifconfig-push 192.168.200.3 192.168.200.1
push "topology subnet"
iroute 192.168.203.0 255.255.255.0
push "route 192.168.202.0 255.255.255.0 192.168.200.2 "
/var/tmp/ovpn $
der Server läuft.
Jetzt noch die Config des Clients (hier Client203):
Code:
/var/tmp/flash $ cat /mod/etc/openvpn-lzo.conf
##############################################################
#
# OpenVPN 2.1 Config, generated Mon Aug 13 10:36:07 CEST 2007
#
##############################################################
proto udp
port 1194
dev tun
ca /tmp/flash/ca.crt
cert /tmp/flash/box.crt
key /tmp/flash/box.key
tls-client
ns-cert-type server
remote yyyyyy.dyndns.org
nobind
pull
ifconfig 192.168.200.3 192.168.200.1
tun-mtu 1500
mssfix
log /var/tmp/openvpn-debug.out
daemon
verb 6
cipher AES-128-CBC
comp-lzo
keepalive 10 120
resolv-retry infinite
status /var/log/openvpn.log
/var/tmp/flash $
Allerdings erhalte ich im Log am Client Folgendes:
Code:
/var/tmp $ cat openvpn-debug.out
Mon Aug 13 10:36:07 2007 us=406053 OpenVPN 2.1_rc4 mipsel-linux [SSL] [LZO2] [EPOLL] built on Jul 9 2007
Mon Aug 13 10:36:07 2007 us=408759 WARNING: using --pull/--client and --ifconfig together is probably not what you want
Mon Aug 13 10:36:07 2007 us=424820 WARNING: file '/tmp/flash/box.key' is group or others accessible
Mon Aug 13 10:36:07 2007 us=440150 LZO compression initialized
Mon Aug 13 10:36:07 2007 us=445519 Control Channel MTU parms [ L:1558 D:138 EF:38 EB:0 ET:0 EL:0 ]
Mon Aug 13 10:36:07 2007 us=616480 Data Channel MTU parms [ L:1558 D:1450 EF:58 EB:135 ET:0 EL:0 AF:3/1 ]
Mon Aug 13 10:36:07 2007 us=625092 Socket Buffers: R=[110592->131072] S=[110592->131072]
Mon Aug 13 10:36:07 2007 us=626292 UDPv4 link local: [undef]
Mon Aug 13 10:36:07 2007 us=627205 UDPv4 link remote: 84.177.50.123:1194
Mon Aug 13 10:36:07 2007 us=634382 UDPv4 WRITE [14] to 84.177.50.123:1194: P_CONTROL_HARD_RESET_CLIENT_V2 kid=0 [ ] pid=0 DATA len=0
Mon Aug 13 10:36:07 2007 us=815970 UDPv4 READ [26] from 84.177.50.123:1194: P_CONTROL_HARD_RESET_SERVER_V2 kid=0 [ 0 ] pid=0 DATA len=0
Mon Aug 13 10:36:07 2007 us=816943 TLS: Initial packet from 84.177.50.123:1194, sid=77e12fc7 c42c06f9
Mon Aug 13 10:36:07 2007 us=818444 UDPv4 WRITE [22] to 84.177.50.123:1194: P_ACK_V1 kid=0 [ 0 ]
Mon Aug 13 10:36:07 2007 us=822256 UDPv4 WRITE [100] to 84.177.50.123:1194: P_CONTROL_V1 kid=0 [ ] pid=1 DATA len=86
Mon Aug 13 10:36:08 2007 us=244811 UDPv4 READ [126] from 84.177.50.123:1194: P_CONTROL_V1 kid=0 [ 1 ] pid=1 DATA len=100
Mon Aug 13 10:36:08 2007 us=248285 UDPv4 WRITE [22] to 84.177.50.123:1194: P_ACK_V1 kid=0 [ 1 ]
Mon Aug 13 10:36:08 2007 us=252271 UDPv4 READ [114] from 84.177.50.123:1194: P_CONTROL_V1 kid=0 [ ] pid=2 DATA len=100
Mon Aug 13 10:36:08 2007 us=254182 UDPv4 WRITE [22] to 84.177.50.123:1194: P_ACK_V1 kid=0 [ 2 ]
Mon Aug 13 10:36:08 2007 us=256345 UDPv4 READ [114] from 84.177.50.123:1194: P_CONTROL_V1 kid=0 [ ] pid=3 DATA len=100
Mon Aug 13 10:36:08 2007 us=258246 UDPv4 WRITE [22] to 84.177.50.123:1194: P_ACK_V1 kid=0 [ 3 ]
Mon Aug 13 10:36:08 2007 us=261315 UDPv4 READ [114] from 84.177.50.123:1194: P_CONTROL_V1 kid=0 [ ] pid=4 DATA len=100
Mon Aug 13 10:36:08 2007 us=263211 UDPv4 WRITE [22] to 84.177.50.123:1194: P_ACK_V1 kid=0 [ 4 ]
Mon Aug 13 10:36:08 2007 us=314182 UDPv4 READ [114] from 84.177.50.123:1194: P_CONTROL_V1 kid=0 [ ] pid=5 DATA len=100
Mon Aug 13 10:36:08 2007 us=317293 UDPv4 WRITE [22] to 84.177.50.123:1194: P_ACK_V1 kid=0 [ 5 ]
Mon Aug 13 10:36:08 2007 us=320425 UDPv4 READ [114] from 84.177.50.123:1194: P_CONTROL_V1 kid=0 [ ] pid=6 DATA len=100
Mon Aug 13 10:36:08 2007 us=322765 UDPv4 WRITE [22] to 84.177.50.123:1194: P_ACK_V1 kid=0 [ 6 ]
Mon Aug 13 10:36:08 2007 us=325464 UDPv4 READ [114] from 84.177.50.123:1194: P_CONTROL_V1 kid=0 [ ] pid=7 DATA len=100
Mon Aug 13 10:36:08 2007 us=327362 UDPv4 WRITE [22] to 84.177.50.123:1194: P_ACK_V1 kid=0 [ 7 ]
Mon Aug 13 10:36:08 2007 us=329526 UDPv4 READ [114] from 84.177.50.123:1194: P_CONTROL_V1 kid=0 [ ] pid=8 DATA len=100
Mon Aug 13 10:36:08 2007 us=332579 UDPv4 WRITE [22] to 84.177.50.123:1194: P_ACK_V1 kid=0 [ 8 ]
Mon Aug 13 10:36:08 2007 us=345972 UDPv4 READ [114] from 84.177.50.123:1194: P_CONTROL_V1 kid=0 [ ] pid=9 DATA len=100
Mon Aug 13 10:36:08 2007 us=348843 UDPv4 WRITE [22] to 84.177.50.123:1194: P_ACK_V1 kid=0 [ 9 ]
Mon Aug 13 10:36:08 2007 us=352002 UDPv4 READ [114] from 84.177.50.123:1194: P_CONTROL_V1 kid=0 [ ] pid=10 DATA len=100
Mon Aug 13 10:36:08 2007 us=354486 UDPv4 WRITE [22] to 84.177.50.123:1194: P_ACK_V1 kid=0 [ 10 ]
Mon Aug 13 10:36:08 2007 us=357157 UDPv4 READ [114] from 84.177.50.123:1194: P_CONTROL_V1 kid=0 [ ] pid=11 DATA len=100
Mon Aug 13 10:36:08 2007 us=359053 UDPv4 WRITE [22] to 84.177.50.123:1194: P_ACK_V1 kid=0 [ 11 ]
Mon Aug 13 10:36:08 2007 us=361708 UDPv4 READ [114] from 84.177.50.123:1194: P_CONTROL_V1 kid=0 [ ] pid=12 DATA len=100
Mon Aug 13 10:36:08 2007 us=364199 UDPv4 WRITE [22] to 84.177.50.123:1194: P_ACK_V1 kid=0 [ 12 ]
Mon Aug 13 10:36:08 2007 us=369624 UDPv4 READ [114] from 84.177.50.123:1194: P_CONTROL_V1 kid=0 [ ] pid=13 DATA len=100
Mon Aug 13 10:36:08 2007 us=372894 UDPv4 WRITE [22] to 84.177.50.123:1194: P_ACK_V1 kid=0 [ 13 ]
Mon Aug 13 10:36:08 2007 us=375416 UDPv4 READ [114] from 84.177.50.123:1194: P_CONTROL_V1 kid=0 [ ] pid=14 DATA len=100
Mon Aug 13 10:36:08 2007 us=377313 UDPv4 WRITE [22] to 84.177.50.123:1194: P_ACK_V1 kid=0 [ 14 ]
Mon Aug 13 10:36:08 2007 us=380740 UDPv4 READ [114] from 84.177.50.123:1194: P_CONTROL_V1 kid=0 [ ] pid=15 DATA len=100
Mon Aug 13 10:36:08 2007 us=382643 UDPv4 WRITE [22] to 84.177.50.123:1194: P_ACK_V1 kid=0 [ 15 ]
Mon Aug 13 10:36:08 2007 us=385309 UDPv4 READ [114] from 84.177.50.123:1194: P_CONTROL_V1 kid=0 [ ] pid=16 DATA len=100
Mon Aug 13 10:36:08 2007 us=387201 UDPv4 WRITE [22] to 84.177.50.123:1194: P_ACK_V1 kid=0 [ 16 ]
Mon Aug 13 10:36:08 2007 us=393769 UDPv4 READ [114] from 84.177.50.123:1194: P_CONTROL_V1 kid=0 [ ] pid=17 DATA len=100
Mon Aug 13 10:36:08 2007 us=396230 UDPv4 WRITE [22] to 84.177.50.123:1194: P_ACK_V1 kid=0 [ 17 ]
Mon Aug 13 10:36:08 2007 us=398889 UDPv4 READ [114] from 84.177.50.123:1194: P_CONTROL_V1 kid=0 [ ] pid=18 DATA len=100
Mon Aug 13 10:36:08 2007 us=425443 VERIFY OK: depth=1, /C=DE/ST=HE/L=yyyyy/O=wengi/CN=CA/[email protected]
Mon Aug 13 10:36:08 2007 us=432730 VERIFY OK: nsCertType=SERVER
Mon Aug 13 10:36:08 2007 us=433188 VERIFY OK: depth=0, /C=DE/ST=HE/O=wengi/CN=server201/[email protected]
Mon Aug 13 10:36:08 2007 us=435903 UDPv4 WRITE [22] to 84.177.50.123:1194: P_ACK_V1 kid=0 [ 18 ]
Mon Aug 13 10:36:08 2007 us=438134 UDPv4 READ [114] from 84.177.50.123:1194: P_CONTROL_V1 kid=0 [ ] pid=19 DATA len=100
Mon Aug 13 10:36:08 2007 us=440555 UDPv4 WRITE [22] to 84.177.50.123:1194: P_ACK_V1 kid=0 [ 19 ]
Mon Aug 13 10:36:08 2007 us=442730 UDPv4 READ [114] from 84.177.50.123:1194: P_CONTROL_V1 kid=0 [ ] pid=20 DATA len=100
Mon Aug 13 10:36:08 2007 us=445266 UDPv4 WRITE [22] to 84.177.50.123:1194: P_ACK_V1 kid=0 [ 20 ]
Mon Aug 13 10:36:08 2007 us=447439 UDPv4 READ [114] from 84.177.50.123:1194: P_CONTROL_V1 kid=0 [ ] pid=21 DATA len=100
Mon Aug 13 10:36:08 2007 us=449352 UDPv4 WRITE [22] to 84.177.50.123:1194: P_ACK_V1 kid=0 [ 21 ]
Mon Aug 13 10:36:08 2007 us=458335 UDPv4 READ [114] from 84.177.50.123:1194: P_CONTROL_V1 kid=0 [ ] pid=22 DATA len=100
Mon Aug 13 10:36:08 2007 us=468035 UDPv4 WRITE [22] to 84.177.50.123:1194: P_ACK_V1 kid=0 [ 22 ]
Mon Aug 13 10:36:08 2007 us=470651 UDPv4 READ [73] from 84.177.50.123:1194: P_CONTROL_V1 kid=0 [ ] pid=23 DATA len=59
Mon Aug 13 10:36:09 2007 us=89258 UDPv4 WRITE [126] to 84.177.50.123:1194: P_CONTROL_V1 kid=0 [ 23 ] pid=2 DATA len=100
Mon Aug 13 10:36:09 2007 us=92562 UDPv4 WRITE [114] to 84.177.50.123:1194: P_CONTROL_V1 kid=0 [ ] pid=3 DATA len=100
Mon Aug 13 10:36:09 2007 us=94813 UDPv4 WRITE [114] to 84.177.50.123:1194: P_CONTROL_V1 kid=0 [ ] pid=4 DATA len=100
Mon Aug 13 10:36:09 2007 us=97059 UDPv4 WRITE [114] to 84.177.50.123:1194: P_CONTROL_V1 kid=0 [ ] pid=5 DATA len=100
Mon Aug 13 10:36:09 2007 us=182655 UDPv4 READ [22] from 84.177.50.123:1194: P_ACK_V1 kid=0 [ 2 ]
Mon Aug 13 10:36:09 2007 us=185284 UDPv4 WRITE [114] to 84.177.50.123:1194: P_CONTROL_V1 kid=0 [ ] pid=6 DATA len=100
Mon Aug 13 10:36:09 2007 us=187985 UDPv4 READ [22] from 84.177.50.123:1194: P_ACK_V1 kid=0 [ 3 ]
Mon Aug 13 10:36:09 2007 us=189653 UDPv4 WRITE [114] to 84.177.50.123:1194: P_CONTROL_V1 kid=0 [ ] pid=7 DATA len=100
Mon Aug 13 10:36:09 2007 us=192321 UDPv4 READ [22] from 84.177.50.123:1194: P_ACK_V1 kid=0 [ 4 ]
Mon Aug 13 10:36:09 2007 us=194405 UDPv4 WRITE [114] to 84.177.50.123:1194: P_CONTROL_V1 kid=0 [ ] pid=8 DATA len=100
Mon Aug 13 10:36:09 2007 us=197068 UDPv4 READ [22] from 84.177.50.123:1194: P_ACK_V1 kid=0 [ 5 ]
Mon Aug 13 10:36:09 2007 us=198659 UDPv4 WRITE [114] to 84.177.50.123:1194: P_CONTROL_V1 kid=0 [ ] pid=9 DATA len=100
Mon Aug 13 10:36:09 2007 us=314288 UDPv4 READ [22] from 84.177.50.123:1194: P_ACK_V1 kid=0 [ 6 ]
Mon Aug 13 10:36:09 2007 us=316461 UDPv4 WRITE [114] to 84.177.50.123:1194: P_CONTROL_V1 kid=0 [ ] pid=10 DATA len=100
Mon Aug 13 10:36:09 2007 us=318619 UDPv4 READ [22] from 84.177.50.123:1194: P_ACK_V1 kid=0 [ 7 ]
Mon Aug 13 10:36:09 2007 us=320933 UDPv4 WRITE [114] to 84.177.50.123:1194: P_CONTROL_V1 kid=0 [ ] pid=11 DATA len=100
Mon Aug 13 10:36:09 2007 us=323101 UDPv4 READ [22] from 84.177.50.123:1194: P_ACK_V1 kid=0 [ 8 ]
Mon Aug 13 10:36:09 2007 us=325256 UDPv4 WRITE [114] to 84.177.50.123:1194: P_CONTROL_V1 kid=0 [ ] pid=12 DATA len=100
Mon Aug 13 10:36:09 2007 us=327407 UDPv4 READ [22] from 84.177.50.123:1194: P_ACK_V1 kid=0 [ 9 ]
Mon Aug 13 10:36:09 2007 us=328978 UDPv4 WRITE [114] to 84.177.50.123:1194: P_CONTROL_V1 kid=0 [ ] pid=13 DATA len=100
Mon Aug 13 10:36:09 2007 us=338859 UDPv4 READ [22] from 84.177.50.123:1194: P_ACK_V1 kid=0 [ 10 ]
Mon Aug 13 10:36:09 2007 us=341334 UDPv4 WRITE [114] to 84.177.50.123:1194: P_CONTROL_V1 kid=0 [ ] pid=14 DATA len=100
Mon Aug 13 10:36:09 2007 us=344505 UDPv4 READ [22] from 84.177.50.123:1194: P_ACK_V1 kid=0 [ 11 ]
Mon Aug 13 10:36:09 2007 us=346063 UDPv4 WRITE [114] to 84.177.50.123:1194: P_CONTROL_V1 kid=0 [ ] pid=15 DATA len=100
Mon Aug 13 10:36:09 2007 us=349241 UDPv4 READ [22] from 84.177.50.123:1194: P_ACK_V1 kid=0 [ 12 ]
Mon Aug 13 10:36:09 2007 us=351275 UDPv4 WRITE [114] to 84.177.50.123:1194: P_CONTROL_V1 kid=0 [ ] pid=16 DATA len=100
Mon Aug 13 10:36:09 2007 us=353793 UDPv4 READ [22] from 84.177.50.123:1194: P_ACK_V1 kid=0 [ 13 ]
Mon Aug 13 10:36:09 2007 us=355340 UDPv4 WRITE [114] to 84.177.50.123:1194: P_CONTROL_V1 kid=0 [ ] pid=17 DATA len=100
Mon Aug 13 10:36:09 2007 us=362252 UDPv4 READ [22] from 84.177.50.123:1194: P_ACK_V1 kid=0 [ 14 ]
Mon Aug 13 10:36:09 2007 us=364364 UDPv4 WRITE [114] to 84.177.50.123:1194: P_CONTROL_V1 kid=0 [ ] pid=18 DATA len=100
Mon Aug 13 10:36:09 2007 us=367431 UDPv4 READ [22] from 84.177.50.123:1194: P_ACK_V1 kid=0 [ 15 ]
Mon Aug 13 10:36:09 2007 us=368970 UDPv4 WRITE [114] to 84.177.50.123:1194: P_CONTROL_V1 kid=0 [ ] pid=19 DATA len=100
Mon Aug 13 10:36:09 2007 us=372671 UDPv4 READ [22] from 84.177.50.123:1194: P_ACK_V1 kid=0 [ 16 ]
Mon Aug 13 10:36:09 2007 us=374206 UDPv4 WRITE [114] to 84.177.50.123:1194: P_CONTROL_V1 kid=0 [ ] pid=20 DATA len=100
Mon Aug 13 10:36:09 2007 us=376907 UDPv4 READ [22] from 84.177.50.123:1194: P_ACK_V1 kid=0 [ 17 ]
Mon Aug 13 10:36:09 2007 us=378423 UDPv4 WRITE [103] to 84.177.50.123:1194: P_CONTROL_V1 kid=0 [ ] pid=21 DATA len=89
Mon Aug 13 10:36:09 2007 us=416944 UDPv4 READ [22] from 84.177.50.123:1194: P_ACK_V1 kid=0 [ 18 ]
Mon Aug 13 10:36:09 2007 us=681555 UDPv4 READ [22] from 84.177.50.123:1194: P_ACK_V1 kid=0 [ 19 ]
Mon Aug 13 10:36:09 2007 us=686387 UDPv4 READ [22] from 84.177.50.123:1194: P_ACK_V1 kid=0 [ 20 ]
Mon Aug 13 10:36:09 2007 us=706711 UDPv4 READ [85] from 84.177.50.123:1194: P_CONTROL_V1 kid=0 [ 21 ] pid=24 DATA len=59
Mon Aug 13 10:36:09 2007 us=712823 UDPv4 WRITE [126] to 84.177.50.123:1194: P_CONTROL_V1 kid=0 [ 24 ] pid=22 DATA len=100
Mon Aug 13 10:36:09 2007 us=714609 UDPv4 WRITE [114] to 84.177.50.123:1194: P_CONTROL_V1 kid=0 [ ] pid=23 DATA len=100
Mon Aug 13 10:36:09 2007 us=716950 UDPv4 WRITE [16] to 84.177.50.123:1194: P_CONTROL_V1 kid=0 [ ] pid=24 DATA len=2
Mon Aug 13 10:36:09 2007 us=736899 UDPv4 READ [22] from 84.177.50.123:1194: P_ACK_V1 kid=0 [ 22 ]
Mon Aug 13 10:36:09 2007 us=739055 UDPv4 READ [22] from 84.177.50.123:1194: P_ACK_V1 kid=0 [ 23 ]
Mon Aug 13 10:36:09 2007 us=758329 UDPv4 READ [126] from 84.177.50.123:1194: P_CONTROL_V1 kid=0 [ 24 ] pid=25 DATA len=100
Mon Aug 13 10:36:09 2007 us=761109 UDPv4 WRITE [22] to 84.177.50.123:1194: P_ACK_V1 kid=0 [ 25 ]
Mon Aug 13 10:36:09 2007 us=764435 UDPv4 READ [68] from 84.177.50.123:1194: P_CONTROL_V1 kid=0 [ ] pid=26 DATA len=54
Mon Aug 13 10:36:09 2007 us=772379 Data Channel Encrypt: Cipher 'AES-128-CBC' initialized with 128 bit key
Mon Aug 13 10:36:09 2007 us=773064 Data Channel Encrypt: Using 160 bit message hash 'SHA1' for HMAC authentication
Mon Aug 13 10:36:09 2007 us=773689 Data Channel Decrypt: Cipher 'AES-128-CBC' initialized with 128 bit key
Mon Aug 13 10:36:09 2007 us=774289 Data Channel Decrypt: Using 160 bit message hash 'SHA1' for HMAC authentication
Mon Aug 13 10:36:09 2007 us=775312 UDPv4 WRITE [22] to 84.177.50.123:1194: P_ACK_V1 kid=0 [ 26 ]
Mon Aug 13 10:36:09 2007 us=776953 Control Channel: TLSv1, cipher TLSv1/SSLv3 DHE-RSA-AES256-SHA, 1024 bit RSA
Mon Aug 13 10:36:09 2007 us=777786 [server201] Peer Connection Initiated with 84.177.50.123:1194
Mon Aug 13 10:36:10 2007 us=891077 SENT CONTROL [server201]: 'PUSH_REQUEST' (status=1)
Mon Aug 13 10:36:10 2007 us=892711 UDPv4 WRITE [104] to 84.177.50.123:1194: P_CONTROL_V1 kid=0 [ ] pid=25 DATA len=90
Mon Aug 13 10:36:10 2007 us=934652 UDPv4 READ [22] from 84.177.50.123:1194: P_ACK_V1 kid=0 [ 25 ]
Mon Aug 13 10:36:10 2007 us=937627 UDPv4 READ [114] from 84.177.50.123:1194: P_CONTROL_V1 kid=0 [ ] pid=27 DATA len=100
Mon Aug 13 10:36:10 2007 us=940611 UDPv4 WRITE [22] to 84.177.50.123:1194: P_ACK_V1 kid=0 [ 27 ]
Mon Aug 13 10:36:10 2007 us=942873 UDPv4 READ [114] from 84.177.50.123:1194: P_CONTROL_V1 kid=0 [ ] pid=28 DATA len=100
Mon Aug 13 10:36:10 2007 us=944099 UDPv4 WRITE [22] to 84.177.50.123:1194: P_ACK_V1 kid=0 [ 28 ]
Mon Aug 13 10:36:10 2007 us=945898 UDPv4 READ [64] from 84.177.50.123:1194: P_CONTROL_V1 kid=0 [ ] pid=29 DATA len=50
Mon Aug 13 10:36:10 2007 us=948172 PUSH: Received control message: 'PUSH_REPLY,route 192.168.201.0 255.255.255.0 192.168.200.1,ping 10,ping-restart 120,topology subnet,route 192.168.202.0 255.255.255.0 192.168.200.2 ,ifconfig 192.168.200.3 192.168.200.1'
Mon Aug 13 10:36:10 2007 us=949274 OPTIONS IMPORT: timers and/or timeouts modified
Mon Aug 13 10:36:10 2007 us=950200 OPTIONS IMPORT: --ifconfig/up options modified
Mon Aug 13 10:36:10 2007 us=950662 OPTIONS IMPORT: route options modified
Mon Aug 13 10:36:10 2007 us=964696 TUN/TAP device tun0 opened
Mon Aug 13 10:36:10 2007 us=965353 TUN/TAP TX queue length set to 100
Mon Aug 13 10:36:10 2007 us=966071 /sbin/ifconfig tun0 192.168.200.3 netmask 192.168.200.1 mtu 1500 broadcast 255.255.255.255
ifconfig: SIOCSIFNETMASK: Invalid argument
Mon Aug 13 10:36:11 2007 us=44393 Linux ifconfig failed: shell command exited with error status: 1
Mon Aug 13 10:36:11 2007 us=44917 Exiting
/var/tmp $
Log am Server hänge ich als Datei an. Ist für den Beitrag zu lang.
Der Tunnel wird also aufgebaut.
Der Client hat aber ein Problem das Interface zu erstellen.
Hier stimmt allerdings die Netmask nicht:
Code:
/sbin/ifconfig tun0 192.168.200.3 netmask 192.168.200.1 mtu 1500 broadcast 255.255.255.255
Da es sich um eine Push-Option handelt tippe ich auf die Server-Config.
Die Zeile mit dem "ifconfig-push" Befehl wird in den Client Dateien (hier /var/tmp/ovpn/client203) nicht richtig erzeugt. Ich hab das auf dem Server mal geändert:
Code:
/var/tmp $ cat /var/tmp/ovpn/client203
ifconfig-push 192.168.200.3 255.255.255.0
push "topology subnet"
iroute 192.168.203.0 255.255.255.0
push "route 192.168.202.0 255.255.255.0 192.168.200.2 "
/var/tmp $
Jetzt klappts auch mit dem Nachbarn
In der openvpn-lzo_conf , Zeile 144, liegt wohl der Fehler:
Code:
echo "ifconfig-push $ip $OPENVPN_LZO_BOX_IP" > $CCD/$name
Leider weis ich nicht, ob einfach nur die Netmask reinnehmen "sauber" genug ist.
Wenn Ja, dann:
Code:
echo "ifconfig-push $ip $mask" > $CCD/$name
wengi
PS: Die Zeiten der Boxen sind genau synchron. Das Problem tritt laut Logs genau um 10:36:11 Uhr auf.