...wie erzeugst Du den kleinen Strich nach den p?Tja, dann muss ich mal schauen, ob mir noch was anderes einfällt.
Einzige Möglichkeit, das zu umgehen wäre, vor dem Aufruf des OpenVPN die Route von Hand zu setzen:
Code:p') dev dsl
...wie erzeugst Du den kleinen Strich nach den p?Tja, dann muss ich mal schauen, ob mir noch was anderes einfällt.
Einzige Möglichkeit, das zu umgehen wäre, vor dem Aufruf des OpenVPN die Route von Hand zu setzen:
Code:p') dev dsl
iptables -t nat -A POSTROUTING -o tap0 -j MASQUERADE
Die GUI hab ich bisher nie genutzt, nur direkt bei "Rules" meine Regeln eingetragen (o.k., die GUI nutze ich zum "Einschalten" von iptables, aber eben nicht für die Regeln).
Dort bei Rules sollte reichen:
-t nat -A POSTROUTING -o tap0 -j MASQUERADE
und dann "übernehmen"
Starting openvpn ... Wed Mar 30 19:37:38 2011 OpenVPN 2.1.4 mipsel-linux [SSL] [LZO2] [EPOLL] [MH] [PF_INET6] built on Mar 20 2011
Wed Mar 30 19:37:38 2011 WARNING: file '/tmp/flash/openvpn/meine.txt' is group or others accessible
Wed Mar 30 19:37:38 2011 NOTE: OpenVPN 2.1 requires '--script-security 2' or higher to call user-defined scripts or executables
Wed Mar 30 19:37:38 2011 LZO compression initialized
Wed Mar 30 19:37:38 2011 RESOLVE: NOTE: melissa.vpntunnel.se resolves to 9 addresses
Wed Mar 30 19:37:38 2011 UDPv4 link local: [undef]
Wed Mar 30 19:37:38 2011 UDPv4 link remote: [AF_INET]178.73.212.232:10010
Wed Mar 30 19:37:38 2011 TLS Error: local/remote TLS keys are out of sync: [AF_INET]178.73.212.235:10020 [0]
Wed Mar 30 19:37:38 2011 TLS Error: local/remote TLS keys are out of sync: [AF_INET]178.73.212.235:10010 [0]
Wed Mar 30 19:37:38 2011 WARNING: this configuration may cache passwords in memory -- use the auth-nocache option to prevent this
Wed Mar 30 19:37:38 2011 TLS Error: local/remote TLS keys are out of sync: [AF_INET]178.73.212.234:1194 [0]
Wed Mar 30 19:37:38 2011 TLS Error: local/remote TLS keys are out of sync: [AF_INET]178.73.212.234:1194 [0]
Wed Mar 30 19:37:38 2011 TLS Error: local/remote TLS keys are out of sync: [AF_INET]178.73.212.235:10020 [0]
Wed Mar 30 19:37:38 2011 TLS Error: local/remote TLS keys are out of sync: [AF_INET]178.73.212.235:10010 [0]
Wed Mar 30 19:37:38 2011 TLS Error: local/remote TLS keys are out of sync: [AF_INET]178.73.212.234:1194 [0]
Wed Mar 30 19:37:38 2011 TLS Error: local/remote TLS keys are out of sync: [AF_INET]178.73.212.235:10020 [0]
Wed Mar 30 19:37:38 2011 TLS Error: local/remote TLS keys are out of sync: [AF_INET]178.73.212.235:10010 [0]
Wed Mar 30 19:37:38 2011 TLS Error: local/remote TLS keys are out of sync: [AF_INET]178.73.212.235:10020 [0]
Wed Mar 30 19:37:38 2011 TLS Error: local/remote TLS keys are out of sync: [AF_INET]178.73.212.235:10010 [0]
Wed Mar 30 19:37:38 2011 TLS Error: local/remote TLS keys are out of sync: [AF_INET]178.73.212.234:1194 [0]
Wed Mar 30 19:37:38 2011 TLS Error: local/remote TLS keys are out of sync: [AF_INET]178.73.212.234:1194 [0]
Wed Mar 30 19:37:38 2011 TLS Error: local/remote TLS keys are out of sync: [AF_INET]178.73.212.235:10020 [0]
Wed Mar 30 19:37:38 2011 TLS Error: local/remote TLS keys are out of sync: [AF_INET]178.73.212.235:10010 [0]
Wed Mar 30 19:37:38 2011 TLS Error: local/remote TLS keys are out of sync: [AF_INET]178.73.212.234:1194 [0]
Wed Mar 30 19:37:38 2011 TLS Error: local/remote TLS keys are out of sync: [AF_INET]178.73.212.234:1194 [0]
Wed Mar 30 19:37:38 2011 TLS Error: local/remote TLS keys are out of sync: [AF_INET]178.73.212.235:10020 [0]
Wed Mar 30 19:37:38 2011 TLS Error: local/remote TLS keys are out of sync: [AF_INET]178.73.212.235:10010 [0]
Wed Mar 30 19:37:38 2011 TLS Error: local/remote TLS keys are out of sync: [AF_INET]178.73.212.234:1194 [0]
Wed Mar 30 19:37:38 2011 TLS Error: local/remote TLS keys are out of sync: [AF_INET]178.73.212.234:1194 [0]
Wed Mar 30 19:37:38 2011 TLS Error: local/remote TLS keys are out of sync: [AF_INET]178.73.212.235:10020 [0]
Wed Mar 30 19:37:38 2011 TLS Error: local/remote TLS keys are out of sync: [AF_INET]178.73.212.235:10010 [0]
Wed Mar 30 19:37:38 2011 TLS Error: local/remote TLS keys are out of sync: [AF_INET]178.73.212.234:1194 [0]
Wed Mar 30 19:37:38 2011 TLS Error: local/remote TLS keys are out of sync: [AF_INET]178.73.212.234:1194 [0]
Wed Mar 30 19:37:38 2011 TLS Error: local/remote TLS keys are out of sync: [AF_INET]178.73.212.234:1194 [0]
Wed Mar 30 19:37:38 2011 TLS Error: local/remote TLS keys are out of sync: [AF_INET]178.73.212.234:1194 [0]
Wed Mar 30 19:37:38 2011 TLS Error: local/remote TLS keys are out of sync: [AF_INET]178.73.212.235:10020 [0]
Wed Mar 30 19:37:39 2011 TLS Error: local/remote TLS keys are out of sync: [AF_INET]178.73.212.235:10010 [0]
Wed Mar 30 19:37:39 2011 TLS Error: local/remote TLS keys are out of sync: [AF_INET]178.73.212.234:1194 [0]
Wed Mar 30 19:37:39 2011 TLS Error: local/remote TLS keys are out of sync: [AF_INET]178.73.212.234:1194 [0]
Wed Mar 30 19:37:39 2011 TLS Error: Unroutable control packet received from [AF_INET]178.73.212.234:1194 (si=3 op=P_CONTROL_V1)
Wed Mar 30 19:37:39 2011 TLS Error: local/remote TLS keys are out of sync: [AF_INET]178.73.212.234:1194 [0]
Wed Mar 30 19:37:39 2011 TLS Error: local/remote TLS keys are out of sync: [AF_INET]178.73.212.234:1194 [0]
Wed Mar 30 19:37:39 2011 TLS Error: local/remote TLS keys are out of sync: [AF_INET]178.73.212.234:1194 [0]
Wed Mar 30 19:37:39 2011 [server] Peer Connection Initiated with [AF_INET]178.73.212.232:10010
Wed Mar 30 19:37:39 2011 TLS Error: local/remote TLS keys are out of sync: [AF_INET]178.73.212.235:10020 [0]
Wed Mar 30 19:37:39 2011 TLS Error: local/remote TLS keys are out of sync: [AF_INET]178.73.212.235:10010 [0]
Wed Mar 30 19:37:39 2011 TLS Error: local/remote TLS keys are out of sync: [AF_INET]178.73.212.235:10020 [0]
Wed Mar 30 19:37:39 2011 TLS Error: local/remote TLS keys are out of sync: [AF_INET]178.73.212.234:1194 [0]
Wed Mar 30 19:37:39 2011 TLS Error: local/remote TLS keys are out of sync: [AF_INET]178.73.212.235:10010 [0]
Wed Mar 30 19:37:39 2011 TLS Error: local/remote TLS keys are out of sync: [AF_INET]178.73.212.234:1194 [0]
Wed Mar 30 19:37:39 2011 TLS Error: local/remote TLS keys are out of sync: [AF_INET]178.73.212.234:1194 [0]
Wed Mar 30 19:37:39 2011 TLS Error: local/remote TLS keys are out of sync: [AF_INET]178.73.212.234:1194 [0]
Wed Mar 30 19:37:39 2011 TLS Error: local/remote TLS keys are out of sync: [AF_INET]178.73.212.234:1194 [0]
Wed Mar 30 19:37:39 2011 TLS Error: local/remote TLS keys are out of sync: [AF_INET]178.73.212.234:1194 [0]
Wed Mar 30 19:37:39 2011 TLS Error: local/remote TLS keys are out of sync: [AF_INET]178.73.212.235:10020 [0]
Wed Mar 30 19:37:39 2011 TLS Error: local/remote TLS keys are out of sync: [AF_INET]178.73.212.235:10010 [0]
Wed Mar 30 19:37:39 2011 TLS Error: local/remote TLS keys are out of sync: [AF_INET]178.73.212.234:1194 [0]
Wed Mar 30 19:37:39 2011 TLS Error: local/remote TLS keys are out of sync: [AF_INET]178.73.212.234:1194 [0]
Wed Mar 30 19:37:39 2011 TLS Error: local/remote TLS keys are out of sync: [AF_INET]178.73.212.235:10020 [0]
Wed Mar 30 19:37:39 2011 TLS Error: local/remote TLS keys are out of sync: [AF_INET]178.73.212.235:10010 [0]
Wed Mar 30 19:37:39 2011 TLS Error: local/remote TLS keys are out of sync: [AF_INET]178.73.212.234:1194 [0]
Wed Mar 30 19:37:39 2011 TLS Error: local/remote TLS keys are out of sync: [AF_INET]178.73.212.234:1194 [0]
Wed Mar 30 19:37:39 2011 TLS Error: local/remote TLS keys are out of sync: [AF_INET]178.73.212.235:10010 [0]
Wed Mar 30 19:37:39 2011 TLS Error: local/remote TLS keys are out of sync: [AF_INET]178.73.212.235:10020 [0]
Wed Mar 30 19:37:39 2011 TLS Error: local/remote TLS keys are out of sync: [AF_INET]178.73.212.235:10010 [0]
Wed Mar 30 19:37:39 2011 TLS Error: local/remote TLS keys are out of sync: [AF_INET]178.73.212.234:1194 [0]
Wed Mar 30 19:37:39 2011 TLS Error: local/remote TLS keys are out of sync: [AF_INET]178.73.212.235:10010 [0]
Wed Mar 30 19:37:39 2011 TLS Error: local/remote TLS keys are out of sync: [AF_INET]178.73.212.235:10020 [0]
Wed Mar 30 19:37:39 2011 TLS Error: local/remote TLS keys are out of sync: [AF_INET]178.73.212.235:10020 [0]
Wed Mar 30 19:37:39 2011 TLS Error: local/remote TLS keys are out of sync: [AF_INET]178.73.212.235:10020 [0]
Wed Mar 30 19:37:39 2011 TLS Error: local/remote TLS keys are out of sync: [AF_INET]178.73.212.235:10010 [0]
Wed Mar 30 19:37:39 2011 TLS Error: local/remote TLS keys are out of sync: [AF_INET]178.73.212.234:1194 [0]
Wed Mar 30 19:37:39 2011 TLS Error: local/remote TLS keys are out of sync: [AF_INET]178.73.212.235:10020 [0]
Wed Mar 30 19:37:39 2011 TLS Error: local/remote TLS keys are out of sync: [AF_INET]178.73.212.235:10010 [0]
Wed Mar 30 19:37:39 2011 TLS Error: local/remote TLS keys are out of sync: [AF_INET]178.73.212.234:1194 [0]
Wed Mar 30 19:37:39 2011 TLS Error: local/remote TLS keys are out of sync: [AF_INET]178.73.212.235:10020 [0]
Wed Mar 30 19:37:39 2011 TLS Error: local/remote TLS keys are out of sync: [AF_INET]178.73.212.235:10020 [0]
Wed Mar 30 19:37:39 2011 TLS Error: local/remote TLS keys are out of sync: [AF_INET]178.73.212.235:10010 [0]
Wed Mar 30 19:37:39 2011 TLS Error: local/remote TLS keys are out of sync: [AF_INET]178.73.212.234:1194 [0]
Wed Mar 30 19:37:39 2011 TLS Error: local/remote TLS keys are out of sync: [AF_INET]178.73.212.234:1194 [0]
Wed Mar 30 19:37:39 2011 TLS Error: local/remote TLS keys are out of sync: [AF_INET]178.73.212.235:10020 [0]
Wed Mar 30 19:37:39 2011 TLS Error: local/remote TLS keys are out of sync: [AF_INET]178.73.212.235:10010 [0]
Wed Mar 30 19:37:39 2011 TLS Error: local/remote TLS keys are out of sync: [AF_INET]178.73.212.234:1194 [0]
Wed Mar 30 19:37:39 2011 TLS Error: local/remote TLS keys are out of sync: [AF_INET]178.73.212.235:10020 [0]
Wed Mar 30 19:37:39 2011 TLS Error: local/remote TLS keys are out of sync: [AF_INET]178.73.212.235:10010 [0]
Wed Mar 30 19:37:39 2011 TLS Error: local/remote TLS keys are out of sync: [AF_INET]178.73.212.234:1194 [0]
Wed Mar 30 19:37:39 2011 TLS Error: local/remote TLS keys are out of sync: [AF_INET]178.73.212.234:1194 [0]
Wed Mar 30 19:37:39 2011 TLS Error: local/remote TLS keys are out of sync: [AF_INET]178.73.212.235:10020 [0]
Wed Mar 30 19:37:39 2011 TLS Error: local/remote TLS keys are out of sync: [AF_INET]178.73.212.235:10010 [0]
Wed Mar 30 19:37:39 2011 TLS Error: local/remote TLS keys are out of sync: [AF_INET]178.73.212.234:1194 [0]
Wed Mar 30 19:37:39 2011 TLS Error: local/remote TLS keys are out of sync: [AF_INET]178.73.212.234:1194 [0]
Wed Mar 30 19:37:39 2011 TLS Error: local/remote TLS keys are out of sync: [AF_INET]178.73.212.235:10020 [0]
Wed Mar 30 19:37:39 2011 TLS Error: local/remote TLS keys are out of sync: [AF_INET]178.73.212.235:10010 [0]
Wed Mar 30 19:37:39 2011 TLS Error: local/remote TLS keys are out of sync: [AF_INET]178.73.212.234:1194 [0]
Wed Mar 30 19:37:39 2011 TLS Error: local/remote TLS keys are out of sync: [AF_INET]178.73.212.235:10020 [0]
Wed Mar 30 19:37:39 2011 TLS Error: local/remote TLS keys are out of sync: [AF_INET]178.73.212.235:10010 [0]
Wed Mar 30 19:37:39 2011 TLS Error: local/remote TLS keys are out of sync: [AF_INET]178.73.212.234:1194 [0]
Wed Mar 30 19:37:39 2011 TLS Error: local/remote TLS keys are out of sync: [AF_INET]178.73.212.235:10020 [0]
Wed Mar 30 19:37:39 2011 TLS Error: local/remote TLS keys are out of sync: [AF_INET]178.73.212.235:10010 [0]
Wed Mar 30 19:37:39 2011 TLS Error: local/remote TLS keys are out of sync: [AF_INET]178.73.212.234:1194 [0]
Wed Mar 30 19:37:39 2011 TLS Error: local/remote TLS keys are out of sync: [AF_INET]178.73.212.234:1194 [0]
Wed Mar 30 19:37:39 2011 TLS Error: local/remote TLS keys are out of sync: [AF_INET]178.73.212.234:1194 [0]
Wed Mar 30 19:37:39 2011 TLS Error: local/remote TLS keys are out of sync: [AF_INET]178.73.212.235:10020 [0]
Wed Mar 30 19:37:39 2011 TLS Error: local/remote TLS keys are out of sync: [AF_INET]178.73.212.235:10010 [0]
Wed Mar 30 19:37:39 2011 TLS Error: local/remote TLS keys are out of sync: [AF_INET]178.73.212.234:1194 [0]
Wed Mar 30 19:37:40 2011 TLS Error: local/remote TLS keys are out of sync: [AF_INET]178.73.212.234:1194 [0]
Wed Mar 30 19:37:40 2011 TLS Error: local/remote TLS keys are out of sync: [AF_INET]178.73.212.234:1194 [0]
Wed Mar 30 19:37:40 2011 TLS Error: local/remote TLS keys are out of sync: [AF_INET]178.73.212.234:1194 [0]
Wed Mar 30 19:37:40 2011 TLS Error: local/remote TLS keys are out of sync: [AF_INET]178.73.212.234:1194 [0]
Wed Mar 30 19:37:40 2011 TLS Error: local/remote TLS keys are out of sync: [AF_INET]178.73.212.235:10020 [0]
Wed Mar 30 19:37:40 2011 TLS Error: local/remote TLS keys are out of sync: [AF_INET]178.73.212.235:10010 [0]
Wed Mar 30 19:37:40 2011 TLS Error: local/remote TLS keys are out of sync: [AF_INET]178.73.212.234:1194 [0]
Wed Mar 30 19:37:40 2011 TLS Error: local/remote TLS keys are out of sync: [AF_INET]178.73.212.235:10020 [0]
Wed Mar 30 19:37:40 2011 TLS Error: local/remote TLS keys are out of sync: [AF_INET]178.73.212.235:10010 [0]
Wed Mar 30 19:37:40 2011 TLS Error: local/remote TLS keys are out of sync: [AF_INET]178.73.212.234:1194 [0]
In Kürze: Speichere das Cert als "CA-Zertifikat" mit den "normalen" OpenVPN-Einstellungen auf deiner Box, dann liegt es unter "/tmp/flash/openvpn/ca.crt". Abspeichern einer "eigenen Config" kannst du z.B. mit der Trunk-Version recht einfach erreichen, indem du die Datei als "/tmp/flash/openvpn/own_openvpn.conf" ablegst (danach mit "modsave" resetfest sichern). Dann werden die GUI-Einstellungen ignoriert und nur diese Datei wird genutzt...
#daemon
float
client
dev tun
proto udp
nobind
log /var/tmp/debug_own_openvpn.out
status /var/log/openvpn.log
group openvpn
user openvpn
auth-nocache
ca /tmp/flash/openvpn/ca.crt
ns-cert-type server
cipher BF-CBC
chroot /tmp/openvpn
remote-random
remote melissa.vpntunnel.se 30001
remote melissa.vpntunnel.se 30002
remote melissa.vpntunnel.se 30003
remote melissa.vpntunnel.se 30004
resolv-retry infinite
script-security 3
auth-user-pass /tmp/flash/openvpn/pass.txt
persist-key
persist-tun
comp-lzo
verb 6
forwardrules = "udp 0.0.0.0:30001+4 0.0.0.0:30001 0 # vpntunnel.se";
forwardrules = "udp 0.0.0.0:30001+4 0.0.0.0:30001+4 0 # vpntunnel.se";
brinterfaces {
name = "lan";
dhcp = no;
ipaddr = 192.168.42.1;
netmask = 255.255.255.0;
dstipaddr = 0.0.0.0;
interfaces = "eth0", "ath0", "ath1", "wdsup0", "wdsup1",
"wdsup2", "wdsup3", "wdsup4", "wdsdw0",
"wdsdw1", "wdsdw2", "wdsdw3", "wdsdw4", "tap0";
NOTE: unable to redirect default gateway -- Cannot read current default gateway from system
route add default gw $(ifconfig dsl | sed -n '/inet addr/ s/.*P-t-P:\([0-9\.]*\)[ ]*.*/\1/ p') dev dsl
# jetzt das Openvpn aufrufen, das sollte jetzt sogar mit dem "normalen" (über die GUI zu starten) gehen
#
# später dann ggf wieder löschen, sollte aber nicht zwingend nötig sein
route del default gw $(ifconfig dsl | sed -n '/inet addr/ s/.*P-t-P:\([0-9\.]*\)[ ]*.*/\1/ p') dev dsl
===>>> Ursprungszustand
Kernel IP routing table
Destination Gateway Genmask Flags Metric Ref Use Iface
192.168.180.1 0.0.0.0 255.255.255.255 UH 2 0 0 dsl
192.168.180.2 0.0.0.0 255.255.255.255 UH 2 0 0 dsl
192.168.179.0 0.0.0.0 255.255.255.0 U 0 0 0 guest
192.168.178.0 0.0.0.0 255.255.255.0 U 0 0 0 lan
50.123.102.0 0.0.0.0 255.255.252.0 U 2 0 0 dsl
159.254.0.0 0.0.0.0 255.255.0.0 U 0 0 0 lan
0.0.0.0 0.0.0.0 0.0.0.0 U 2 0 0 dsl
===>>> Befehl eingegeben
[CODE]route add default gw $(ifconfig dsl | sed -n '/inet addr/ s/.*P-t-P:\([0-9\.]*\)[ ]*.*/\1/ p') dev dsl
route del default gw $(ifconfig dsl | sed -n '/inet addr/ s/.*P-t-P:\([0-9\.]*\)[ ]*.*/\1/ p') dev dsl
route add default gw $(ifconfig dsl | sed -n '/inet addr/ s/.*P-t-P:\([0-9\.]*\)[ ]*.*/\1/ p') dev dsl
route del default gw $(ifconfig dsl | sed -n '/inet addr/ s/.*P-t-P:\([0-9\.]*\)[ ]*.*/\1/ p') dev dsl
#!/bin/sh
# IP der gegenseite (DynDNS-Namen eintragen)
VPNS=$(ping -c1 -W1 kdl4d2.zapto.org | sed -n '/PING/ s/^[^(]*(\([0-9\.]*\).*/\1/p')
# Route für VPN-Server über dsld
route add $VPNS dev dsld
# Route durchs VPN
route add net 0.0.0.0/1 dev tap0
route add net 128.00.0/1 dev tap0
Add nat rules to the firewall
Browse: Administration → Scripts → Firewall
In the firewall section you paste this:
iptables -I FORWARD -i br0 -o tap0 -j ACCEPT
iptables -I FORWARD -i tap0 -o br0 -j ACCEPT
iptables -I INPUT -i tap0 -j REJECT
iptables -t nat -A POSTROUTING -o tap0 -j MASQUERADE
"fritz daemon.err openvpn[2504]: read UDPv4 [EHOSTUNREACH|EHOSTUNREACH|EHOSTUNREACH]: No route to host (code=148)".
"clientAnton/XX.XXX.XXX.XXX:2053 Authenticate/Decrypt packet error: bad packet ID (may be a replay): [ #5348 ] -- see the man page entry for --no-replay and --replay-window for more info or silence this warning with --mute-replay-warnings"
Destination Gateway Genmask Flags Metric Ref Use Iface
192.168.200.0 0.0.0.0 255.255.255.0 U 0 0 0 lan
169.254.0.0 0.0.0.0 255.255.0.0 U 0 0 0 lan
0.0.0.0 192.168.200.1 0.0.0.0 UG 9 0 0 lan
192.168.100.0 192.168.101.1 255.255.255.0 UG 0 0 0 tap0
192.168.101.0 0.0.0.0 255.255.255.0 U 0 0 0 tap0
192.168.200.0 0.0.0.0 255.255.255.0 U 0 0 0 lan
169.254.0.0 0.0.0.0 255.255.0.0 U 0 0 0 lan
0.0.0.0 192.168.200.1 0.0.0.0 UG 9 0 0 lan
Bescheid! Wie sollte man einen Fehler in einer Config finden, die man nicht kennt??Sollten noch die Config's benötigt werden, dann bitte einfach Bescheid geben.