ok ja to rozumiem, tylko nie wiem czemu to mi teraz nie działa.
kiedyś na wersji 1.6.x czy też 1.9.x uruchamiałem i działało.
A teraz jakoś nie chce ruszyć.
Nie jesteś zalogowany. Proszę się zalogować lub zarejestrować.
eko.one.pl → Posty przez piratee
ok ja to rozumiem, tylko nie wiem czemu to mi teraz nie działa.
kiedyś na wersji 1.6.x czy też 1.9.x uruchamiałem i działało.
A teraz jakoś nie chce ruszyć.
tak jest tablica routingu na serwerze
root@Piratees:~# route
Kernel IP routing table
Destination Gateway Genmask Flags Metric Ref Use Iface
default host-89-228-24- 0.0.0.0 UG 0 0 0 eth0.2
10.8.0.0 * 255.255.255.0 U 0 0 0 tun0
89.228.24.0 * 255.255.248.0 U 0 0 0 eth0.2
172.20.1.0 * 255.255.255.0 U 0 0 0 br-lan
192.168.1.0 * 255.255.255.0 U 0 0 0 tun0
Witam
Usunąłem klienta na serwerze OpenVPN.
Wygenerowałem nowy certyfikat (bez definicji klasy adresowej podsieci klienta)
Po uruchomieniu tunel się zestawia i odcina dostęp do internetu.
Nie wiem czy to ma znaczenie ale serwer stoi na 1.12.0.2 a klient jest 1.13.0.0pre9
Od strony serwera mogę się dostać tylko na adres zestawionego tunelu 10.8.0.2
root@Gargoyle:~# route
Kernel IP routing table
Destination Gateway Genmask Flags Metric Ref Use Iface
default 10.8.0.1 128.0.0.0 UG 0 0 0 tun0
default 10.64.64.64 0.0.0.0 UG 0 0 0 3g-wan
10.8.0.0 * 255.255.255.0 U 0 0 0 tun0
10.64.64.64 * 255.255.255.255 UH 0 0 0 3g-wan
89.228.24.164 10.64.64.64 255.255.255.255 UGH 0 0 0 3g-wan
128.0.0.0 10.8.0.1 128.0.0.0 UG 0 0 0 tun0
172.20.1.0 10.8.0.1 255.255.255.0 UG 0 0 0 tun0
192.168.1.0 * 255.255.255.0 U 0 0 0 br-lan
na końcu definicji pliku server.conf był dwa wpisy
route 192.168.1.0 255.255.255.0 10.8.0.2
route 192.168.1.0 255.255.255.0 10.8.0.4
usunąłem je
server.conf
mode server
port 1194
proto tcp-server
tls-server
ifconfig 10.8.0.1 255.255.255.0
topology subnet
client-config-dir /etc/openvpn/ccd
script-security 2
tls-verify "/usr/lib/gargoyle/ovpn-cn-check.sh /etc/openvpn/verified-userlist"
crl-verify /etc/openvpn/crl.pem
client-to-client
cipher AES-256-GCM
dev tun
keepalive 25 180
status /var/run/openvpn_status
verb 3
dh /etc/openvpn/dh1024.pem
ca /etc/openvpn/ca.crt
cert /etc/openvpn/server.crt
key /etc/openvpn/server.key
tls-auth /etc/openvpn/ta.key 0
persist-key
persist-tun
comp-lzo
push "topology subnet"
push "route-gateway 10.8.0.1"
push "redirect-gateway def1"
tablica routingu servera
Kernel IP routing table
Destination Gateway Genmask Flags Metric Ref Use Iface
default host-89-228-24- 0.0.0.0 UG 0 0 0 eth0.2
10.8.0.0 * 255.255.255.0 U 0 0 0 tun0
89.228.24.0 * 255.255.248.0 U 0 0 0 eth0.2
172.20.1.0 * 255.255.255.0 U 0 0 0 br-lan
ale na kliencie dalej mam powielone wpisy dla 192.168.1.1
Kernel IP routing table
Destination Gateway Genmask Flags Metric Ref Use Iface
default 10.8.0.1 128.0.0.0 UG 0 0 0 tun0
default 10.64.64.64 0.0.0.0 UG 0 0 0 3g-wan
10.8.0.0 * 255.255.255.0 U 0 0 0 tun0
10.64.64.64 * 255.255.255.255 UH 0 0 0 3g-wan
89.228.24.164 10.64.64.64 255.255.255.255 UGH 0 0 0 3g-wan
128.0.0.0 10.8.0.1 128.0.0.0 UG 0 0 0 tun0
172.20.1.0 10.8.0.1 255.255.255.0 UG 0 0 0 tun0
192.168.1.0 10.8.0.1 255.255.255.0 UG 0 0 0 tun0
192.168.1.0 * 255.255.255.0 U 0 0 0 br-lan
i teraz już nie wiem dlaczego.
Wieczorem sprawdzę
Ale ja chce aby do obu sieci nawzajem był dostęp
Pozdrawiam
bo żeby się pingowały interfejsy w poprzednich wersjach trzeba było podać podsieć sieci która się łączy
https://ibb.co/Y8dcS6q
Może teraz trzeba to wyłączyć ?
ja nie ma zdefiniowanej klasy wewnętrzne takiej samej w obu lokalizacjach wiem, że to jest błąd.
w jednej lokalizacji jest 172.20.1.245 a w drugiej jest 192.168.1.1 tak jak pisałem wyżej
a to jest z klient
3g-wan Link encap:Point-to-Point Protocol
inet addr:100.83.84.52 P-t-P:10.64.64.64 Mask:255.255.255.255
UP POINTOPOINT RUNNING NOARP MULTICAST MTU:1500 Metric:1
RX packets:1540 errors:0 dropped:0 overruns:0 frame:0
TX packets:1779 errors:0 dropped:0 overruns:0 carrier:0
collisions:0 txqueuelen:3
RX bytes:249283 (243.4 KiB) TX bytes:649088 (633.8 KiB)
br-lan Link encap:Ethernet HWaddr B0:39:56:69:7E:D8
inet addr:192.168.1.1 Bcast:192.168.1.255 Mask:255.255.255.0
inet6 addr: fdc4:9166:692a::1/60 Scope:Global
inet6 addr: fe80::b239:56ff:fe69:7ed8/64 Scope:Link
UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1
RX packets:1698 errors:0 dropped:0 overruns:0 frame:0
TX packets:2055 errors:0 dropped:0 overruns:0 carrier:0
collisions:0 txqueuelen:1000
RX bytes:202199 (197.4 KiB) TX bytes:489542 (478.0 KiB)
eth0 Link encap:Ethernet HWaddr B0:39:56:69:7E:D8
inet6 addr: fe80::b239:56ff:fe69:7ed8/64 Scope:Link
UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1
RX packets:4840 errors:0 dropped:2 overruns:0 frame:0
TX packets:5184 errors:0 dropped:0 overruns:0 carrier:0
collisions:0 txqueuelen:1000
RX bytes:723217 (706.2 KiB) TX bytes:1788879 (1.7 MiB)
Interrupt:17
eth0.1 Link encap:Ethernet HWaddr B0:39:56:69:7E:D8
UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1
RX packets:1698 errors:0 dropped:0 overruns:0 frame:0
TX packets:2055 errors:0 dropped:0 overruns:0 carrier:0
collisions:0 txqueuelen:1000
RX bytes:202199 (197.4 KiB) TX bytes:489542 (478.0 KiB)
eth0.2 Link encap:Ethernet HWaddr B0:39:56:69:7E:D8
inet6 addr: fe80::b239:56ff:fe69:7ed8/64 Scope:Link
UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1
RX packets:0 errors:0 dropped:0 overruns:0 frame:0
TX packets:9 errors:0 dropped:0 overruns:0 carrier:0
collisions:0 txqueuelen:1000
RX bytes:0 (0.0 B) TX bytes:966 (966.0 B)
lo Link encap:Local Loopback
inet addr:127.0.0.1 Mask:255.0.0.0
inet6 addr: ::1/128 Scope:Host
UP LOOPBACK RUNNING MTU:65536 Metric:1
RX packets:275 errors:0 dropped:0 overruns:0 frame:0
TX packets:275 errors:0 dropped:0 overruns:0 carrier:0
collisions:0 txqueuelen:1000
RX bytes:20238 (19.7 KiB) TX bytes:20238 (19.7 KiB)
tun0 Link encap:UNSPEC HWaddr 00-00-00-00-00-00-00-00-00-00-00-00-00-00-00-00
inet addr:10.8.0.4 P-t-P:10.8.0.4 Mask:255.255.255.0
inet6 addr: fe80::af48:2995:fb43:e2bd/64 Scope:Link
UP POINTOPOINT RUNNING NOARP MULTICAST MTU:1500 Metric:1
RX packets:987 errors:0 dropped:0 overruns:0 frame:0
TX packets:1177 errors:0 dropped:0 overruns:0 carrier:0
collisions:0 txqueuelen:100
RX bytes:76482 (74.6 KiB) TX bytes:519893 (507.7 KiB)
wlan0 Link encap:Ethernet HWaddr B0:39:56:69:7E:D8
inet6 addr: fe80::b239:56ff:fe69:7ed8/64 Scope:Link
UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1
RX packets:0 errors:0 dropped:0 overruns:0 frame:0
TX packets:368 errors:0 dropped:0 overruns:0 carrier:0
collisions:0 txqueuelen:1000
RX bytes:0 (0.0 B) TX bytes:114380 (111.6 KiB)
wlan1 Link encap:Ethernet HWaddr B0:39:56:69:7E:DC
inet6 addr: fe80::b239:56ff:fe69:7edc/64 Scope:Link
UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1
RX packets:0 errors:0 dropped:0 overruns:0 frame:0
TX packets:365 errors:0 dropped:0 overruns:0 carrier:0
collisions:0 txqueuelen:1000
RX bytes:0 (0.0 B) TX bytes:114000 (111.3 KiB)
to się samo tworzy po uruchomieniu tunelu:
to jest zrzut z serwera z openvpn
br-lan Link encap:Ethernet HWaddr D8:07:B6:B6:81:D2
inet addr:172.20.1.245 Bcast:172.20.1.255 Mask:255.255.255.0
inet6 addr: fd2f:f89b:a423::1/60 Scope:Global
inet6 addr: fe80::da07:b6ff:feb6:81d2/64 Scope:Link
UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1
RX packets:46743054 errors:0 dropped:973 overruns:0 frame:0
TX packets:152829615 errors:0 dropped:0 overruns:0 carrier:0
collisions:0 txqueuelen:1000
RX bytes:8675841918 (8.0 GiB) TX bytes:170975760184 (159.2 GiB)
eth0 Link encap:Ethernet HWaddr D8:07:B6:B6:81:D2
inet6 addr: fe80::da07:b6ff:feb6:81d2/64 Scope:Link
UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1
RX packets:374100648 errors:0 dropped:0 overruns:9002 frame:0
TX packets:78817875 errors:0 dropped:0 overruns:0 carrier:0
collisions:0 txqueuelen:1000
RX bytes:1370584907 (1.2 GiB) TX bytes:1005088469 (958.5 MiB)
Interrupt:4
eth0.1 Link encap:Ethernet HWaddr D8:07:B6:B6:81:D2
UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1
RX packets:11449442 errors:0 dropped:5 overruns:0 frame:0
TX packets:32105491 errors:0 dropped:0 overruns:0 carrier:0
collisions:0 txqueuelen:1000
RX bytes:2726999631 (2.5 GiB) TX bytes:38396669491 (35.7 GiB)
eth0.2 Link encap:Ethernet HWaddr D8:07:B6:B6:81:D3
inet addr:89.228.24.164 Bcast:89.228.31.255 Mask:255.255.248.0
inet6 addr: fe80::da07:b6ff:feb6:81d3/64 Scope:Link
inet6 addr: fe80::da07:b6ff:feb6:81d3/64 Scope:Link
UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1
RX packets:362651199 errors:0 dropped:0 overruns:0 frame:0
TX packets:46713068 errors:0 dropped:0 overruns:0 carrier:0
collisions:0 txqueuelen:1000
RX bytes:176593366359 (164.4 GiB) TX bytes:9537851908 (8.8 GiB)
lo Link encap:Local Loopback
inet addr:127.0.0.1 Mask:255.0.0.0
inet6 addr: ::1/128 Scope:Host
UP LOOPBACK RUNNING MTU:65536 Metric:1
RX packets:8316 errors:0 dropped:0 overruns:0 frame:0
TX packets:8316 errors:0 dropped:0 overruns:0 carrier:0
collisions:0 txqueuelen:1
RX bytes:741273 (723.8 KiB) TX bytes:741273 (723.8 KiB)
tun0 Link encap:UNSPEC HWaddr 00-00-00-00-00-00-00-00-00-00-00-00-00-00-00 -00
inet addr:10.8.0.1 P-t-P:10.8.0.1 Mask:255.255.255.0
inet6 addr: fe80::2d88:5109:1af:4cde/64 Scope:Link
UP POINTOPOINT RUNNING NOARP MULTICAST MTU:1500 Metric:1
RX packets:53939 errors:0 dropped:0 overruns:0 frame:0
TX packets:67311 errors:0 dropped:0 overruns:0 carrier:0
collisions:0 txqueuelen:100
RX bytes:5632993 (5.3 MiB) TX bytes:42762111 (40.7 MiB)
wlan0 Link encap:Ethernet HWaddr D8:07:B6:B6:81:D1
inet6 addr: fe80::da07:b6ff:feb6:81d1/64 Scope:Link
UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1
RX packets:10333574 errors:0 dropped:0 overruns:0 frame:0
TX packets:40435625 errors:0 dropped:0 overruns:0 carrier:0
collisions:0 txqueuelen:1000
RX bytes:2848159394 (2.6 GiB) TX bytes:42014347366 (39.1 GiB)
wlan1 Link encap:Ethernet HWaddr D8:07:B6:B6:81:D2
inet6 addr: fe80::da07:b6ff:feb6:81d2/64 Scope:Link
UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1
RX packets:30230723 errors:0 dropped:0 overruns:0 frame:0
TX packets:97158830 errors:0 dropped:0 overruns:0 carrier:0
collisions:0 txqueuelen:1000
RX bytes:5112611959 (4.7 GiB) TX bytes:100394361384 (93.4 GiB)
ok w GUI stworzyło konfigurację ale odcieło mnie od strony wewnętrznej routera
Sun Jan 24 18:01:32 2021 daemon.notice openvpn(custom_config)[14632]: OPTIONS IMPORT: timers and/or timeouts modified
Sun Jan 24 18:01:32 2021 daemon.notice openvpn(custom_config)[14632]: OPTIONS IMPORT: --ifconfig/up options modified
Sun Jan 24 18:01:32 2021 daemon.notice openvpn(custom_config)[14632]: OPTIONS IMPORT: route options modified
Sun Jan 24 18:01:32 2021 daemon.notice openvpn(custom_config)[14632]: OPTIONS IMPORT: route-related options modified
Sun Jan 24 18:01:32 2021 daemon.notice openvpn(custom_config)[14632]: OPTIONS IMPORT: peer-id set
Sun Jan 24 18:01:32 2021 daemon.notice openvpn(custom_config)[14632]: OPTIONS IMPORT: adjusting link_mtu to 1627
Sun Jan 24 18:01:32 2021 daemon.notice openvpn(custom_config)[14632]: OPTIONS IMPORT: data channel crypto options modified
Sun Jan 24 18:01:32 2021 daemon.notice openvpn(custom_config)[14632]: Outgoing Data Channel: Cipher 'AES-256-GCM' initialized with 256 bit key
Sun Jan 24 18:01:32 2021 daemon.notice openvpn(custom_config)[14632]: Incoming Data Channel: Cipher 'AES-256-GCM' initialized with 256 bit key
Sun Jan 24 18:01:32 2021 daemon.notice openvpn(custom_config)[14632]: TUN/TAP device tun0 opened
Sun Jan 24 18:01:32 2021 daemon.notice openvpn(custom_config)[14632]: TUN/TAP TX queue length set to 100
Sun Jan 24 18:01:32 2021 daemon.notice openvpn(custom_config)[14632]: do_ifconfig, tt->did_ifconfig_ipv6_setup=0
Sun Jan 24 18:01:32 2021 daemon.notice openvpn(custom_config)[14632]: /sbin/ifconfig tun0 10.8.0.4 netmask 255.255.255.0 mtu 1500 broadcast 10.8.0.255
Sun Jan 24 18:01:32 2021 daemon.notice openvpn(custom_config)[14632]: /etc/openvpn.up tun0 1500 1555 10.8.0.4 255.255.255.0 init
Sun Jan 24 18:01:32 2021 user.notice root: openvpn up script called
Sun Jan 24 18:01:33 2021 daemon.notice openvpn(custom_config)[14632]: /sbin/route add -net 89.228.24.164 netmask 255.255.255.255 gw 10.64.64.64
Sun Jan 24 18:01:33 2021 daemon.notice openvpn(custom_config)[14632]: /sbin/route add -net 0.0.0.0 netmask 128.0.0.0 gw 10.8.0.1
Sun Jan 24 18:01:33 2021 daemon.notice openvpn(custom_config)[14632]: /sbin/route add -net 128.0.0.0 netmask 128.0.0.0 gw 10.8.0.1
Sun Jan 24 18:01:33 2021 daemon.notice openvpn(custom_config)[14632]: /sbin/route add -net 192.168.1.0 netmask 255.255.255.0 gw 10.8.0.1
Sun Jan 24 18:01:33 2021 daemon.notice openvpn(custom_config)[14632]: /sbin/route add -net 172.20.1.0 netmask 255.255.255.0 gw 10.8.0.1
Sun Jan 24 18:01:33 2021 daemon.warn openvpn(custom_config)[14632]: WARNING: this configuration may cache passwords in memory -- use the auth-nocache option to prevent this
Sun Jan 24 18:01:33 2021 daemon.notice openvpn(custom_config)[14632]: Initialization Sequence Completed
Kernel IP routing table
Destination Gateway Genmask Flags Metric Ref Use Iface
default 10.8.0.1 128.0.0.0 UG 0 0 0 tun0
default 10.64.64.64 0.0.0.0 UG 0 0 0 3g-wan
10.8.0.0 * 255.255.255.0 U 0 0 0 tun0
10.64.64.64 * 255.255.255.255 UH 0 0 0 3g-wan
89.228.24.164 10.64.64.64 255.255.255.255 UGH 0 0 0 3g-wan
128.0.0.0 10.8.0.1 128.0.0.0 UG 0 0 0 tun0
172.20.1.0 10.8.0.1 255.255.255.0 UG 0 0 0 tun0
192.168.1.0 10.8.0.1 255.255.255.0 UG 0 0 0 tun0
192.168.1.0 * 255.255.255.0 U 0 0 0 br-lan
Wyzerowałem i zrobię od początku.
po wykonaniu firstboot w /etc/config zostały stworzone pliki
"openvpn" z zawartością
config openvpn 'custom_config'
option enabled '0'
option config '/etc/openvpn/my-vpn.conf'
option script_security '2'
option up '/etc/openvpn.up'
option down '/etc/openvpn.down'
config openvpn 'sample_server'
option enabled '0'
option port '1194'
option proto 'udp'
option dev 'tun'
option ca '/etc/openvpn/ca.crt'
option cert '/etc/openvpn/server.crt'
option key '/etc/openvpn/server.key'
option dh '/etc/openvpn/dh1024.pem'
option server '10.8.0.0 255.255.255.0'
option ifconfig_pool_persist '/tmp/ipp.txt'
option keepalive '10 120'
option compress 'lzo'
option persist_key '1'
option persist_tun '1'
option user 'nobody'
option status '/tmp/openvpn-status.log'
option verb '3'
config openvpn 'sample_client'
option enabled '0'
option client '1'
option dev 'tun'
option proto 'udp'
list remote 'my_server_1 1194'
option resolv_retry 'infinite'
option nobind '1'
option persist_key '1'
option persist_tun '1'
option user 'nobody'
option ca '/etc/openvpn/ca.crt'
option cert '/etc/openvpn/client.crt'
option key '/etc/openvpn/client.key'
option compress 'lzo'
option verb '3'
oraz
"openvpn_gargoyle" z zawartością
config 'server' 'server'
option 'enabled' 'false'
option 'internal_ip' '10.8.0.1'
option 'internal_mask' '255.255.255.0'
option 'port' '1194'
option 'proto' 'udp'
option 'cipher' 'AES-256-CBC'
option 'client_to_client' 'false'
option 'duplicate_cn' 'false'
option 'redirect_gateway' 'true'
option 'subnet_access' 'false'
## client info, appears in server configuration
#config 'allowed_client' 'client_1'
# option 'id' 'client_1'
# option 'name' 'My First Client'
# option 'remote' 'myhost.chickenkiller.com'
# option 'ip' '10.8.0.2'
# option 'subnet_ip' '192.168.3.0'
# option 'subnet_mask' '255.255.255.0'
#
config 'client' 'client'
option 'enabled' 'false'
#option 'id' 'grouter_client_123456543210'
i teraz jak do tego podejść - usunąć - zmieniać i czy jak wstawię samego klienta to konfiguracja pojawi się na UI ??
przeglądając logread nie ma nawet linijki wpisu aby system chciał uruchomić openvpn-a
zrobię fristboot i zacznę od początku
Dodałem pliki konfiguracyjne ręcznie wg zrzutu.
https://ibb.co/JrHkHrq
Po zatwierdzeniu dostaję komunikat
https://ibb.co/bm4DgW5
"Błąd. Parametry zostały zapisane ale nie udało się nawiązać połączenia"
w katalogu /etc/config brak utworzenia pliku openvpn
zaś w katalogu są tworzone wszystkie pliki
grouter_client_daitlkmgtbwn.conf
grouter_client_daitlkmgtbwn.crt
grouter_client_daitlkmgtbwn.key
grouter_client_daitlkmgtbwn_ca.crt
grouter_client_daitlkmgtbwn_ta.key
tym samym klient Openvpn nie startuje
Wykonałem wszystko jeszcze raz, ale chciałbym dołączyć zrzuty - jak mogę to uczynić
Ja nie tupię napisałem jakie mam adresy IP.
Wyzeruję konfigurację i wykonam konfigurację ponownie, zobaczymy co będzie po imporcie.
na serwerze OpenVPN zdefiniowałem adres podsieci 192.168.1.0 aby się widziały nawzajem generując klucz.
W starszej wersji Gargoyle działało to prawidłowo, w pliku nie definiuję żadnych IP.
serwer na którym jest serwer OpenVPN jest adres 172.20.1.245
Serwer z OPENVPN SERWER (172.20.1.245) ---> klasa TUN 10.8.0.1 ---> Klient z OPENVPN (192.168.1.1)
Po imporcie w katalogu /etc/openvpn tworzy takie nazwy plików
grouter_client_cxcbtnjchjrx*.*
Konfigurację mam pobraną (zrobioną na 1.12.0.2 (27ec1e48) przez GUI są wygenerowane certyfikaty)
Wykonując przez GUI import na 1.13 wykrzacza mi się konfiguracja.
Adresów nie wprowadzałem ręcznie.
Adres serwera OPENVPN 10.8.0.1 (klasa wewnętrzna 172.20.1.245) zaś klient ma klasę 192.168.1.1
Może być powodem błędnego dziania istniejąca przykładowa konfiguracja która przyszła z plikiem factory??
Witam
Na R6220 zainstalowałem Gargoyle gargoyle-1.13.0.0pre9-ar71xx-generic-tl-wr1043nd-v1-squashfs-sysupgrade połączenie poprzez E3131 na Areo2.
Uruchomiłem ręcznie klienta OPENVPN bo nie chciało poprawnie uruchomić konfiguracji poprzez GUI (WWW)
Jak się podniesie interfejs klienta OPENVPN to automatycznie odcina mi dostęp od routera w sieci wewnętrznej jedyny dostęp to tylko i wyłącznie
poprzez drugi router ze świata.
Czy problemem może być zablokowanie ruchu na firewall-u, nic jeszcze nie konfigurowałem?
Konfiguracja
config openvpn 'custom_config'
option script_security '2'
option up '/etc/openvpn.up'
option down '/etc/openvpn.down'
option config '/etc/openvpn/rod.conf'
option enabled '1'
config openvpn 'rod'
option enabled '1'
option client '1'
option dev 'tun'
option proto 'udp'
list remote 'piratee.no-ip.pl 1194'
option resolv_retry 'infinite'
option nobind '1'
option persist_key '1'
option persist_tun '1'
option ca '/etc/openvpn/ca.crt'
option cert '/etc/openvpn/rod.crt'
option key '/etc/openvpn/rod.key'
option compress 'lzo'
option tls-auth ta.key 1
option verb '3'
option topology subnet
oraz
serwer OPENVPN
Kernel IP routing table
Destination Gateway Genmask Flags Metric Ref Use Iface
default host-89-228-24- 0.0.0.0 UG 0 0 0 eth0.2
10.8.0.0 * 255.255.255.0 U 0 0 0 tun0
89.228.24.0 * 255.255.248.0 U 0 0 0 eth0.2
172.20.1.0 * 255.255.255.0 U 0 0 0 br-lan
192.168.1.0 10.8.0.4 255.255.255.0 UG 0 0 0 tun0
192.168.1.0 10.8.0.2 255.255.255.0 UG 0 0 0 tun0
client OpenVPN
Kernel IP routing table
Destination Gateway Genmask Flags Metric Ref Use Iface
default 10.8.0.1 128.0.0.0 UG 0 0 0 tun0
default 10.64.64.64 0.0.0.0 UG 0 0 0 3g-wan
10.8.0.0 * 255.255.255.0 U 0 0 0 tun0
10.64.64.64 * 255.255.255.255 UH 0 0 0 3g-wan
89.228.24.164 10.64.64.64 255.255.255.255 UGH 0 0 0 3g-wan
128.0.0.0 10.8.0.1 128.0.0.0 UG 0 0 0 tun0
172.20.1.0 10.8.0.1 255.255.255.0 UG 0 0 0 tun0
192.168.1.0 10.8.0.1 255.255.255.0 UG 0 0 0 tun0
192.168.1.0 * 255.255.255.0 U 0 0 0 br-lan
Pozdrawiam
Witam
Czemu Gargoyle 1.12.02 nie widzi modemu USB E3131 w interfejsie www
W konfiguracji sieci wpisałem odpowiednie wpisy i zmieniam porty USB i to nic nie daje
config interface 'Areo2'
option delegate '0'
option proto '3g'
option username 'root'
option ipv6 'auto'
option apn 'darmowy'
option device '/dev/ttyUSB0'
option service 'umts_only'
Thu Apr 16 14:23:15 2020 kern.info kernel: [ 1326.207110] usb 1-1: USB disconnect, device number 6
Thu Apr 16 14:23:22 2020 kern.info kernel: [ 1333.173452] usb 1-1: new high-speed USB device number 7 using ehci-platform
Thu Apr 16 14:23:23 2020 kern.info kernel: [ 1333.367521] usb-storage 1-1:1.0: USB Mass Storage device detected
Thu Apr 16 14:23:23 2020 kern.info kernel: [ 1333.384105] scsi host0: usb-storage 1-1:1.0
Thu Apr 16 14:23:23 2020 kern.info kernel: [ 1333.389459] usb-storage 1-1:1.1: USB Mass Storage device detected
Thu Apr 16 14:23:23 2020 kern.info kernel: [ 1333.413832] scsi host1: usb-storage 1-1:1.1
Thu Apr 16 14:23:24 2020 kern.notice kernel: [ 1334.424286] scsi 0:0:0:0: CD-ROM HUAWEI Mass Storage 2.31 PQ: 0 ANSI: 2
Thu Apr 16 14:23:24 2020 kern.notice kernel: [ 1334.499293] scsi 1:0:0:0: Direct-Access HUAWEI SD Storage 2.31 PQ: 0 ANSI: 2
Thu Apr 16 14:23:24 2020 kern.notice kernel: [ 1334.513996] sd 1:0:0:0: [sda] Attached SCSI removable disk
Thu Apr 16 14:25:06 2020 kern.info kernel: [ 1437.151234] usb 1-1: USB disconnect, device number 7
Thu Apr 16 14:25:47 2020 kern.info kernel: [ 1477.533987] usb 1-1: new high-speed USB device number 8 using ehci-platform
Thu Apr 16 14:25:47 2020 kern.info kernel: [ 1477.737490] usb-storage 1-1:1.0: USB Mass Storage device detected
Thu Apr 16 14:25:47 2020 kern.info kernel: [ 1477.754051] scsi host0: usb-storage 1-1:1.0
Thu Apr 16 14:25:47 2020 kern.info kernel: [ 1477.759397] usb-storage 1-1:1.1: USB Mass Storage device detected
Thu Apr 16 14:25:47 2020 kern.info kernel: [ 1477.782449] scsi host1: usb-storage 1-1:1.1
Thu Apr 16 14:25:48 2020 kern.notice kernel: [ 1478.832734] scsi 1:0:0:0: Direct-Access HUAWEI SD Storage 2.31 PQ: 0 ANSI: 2
Thu Apr 16 14:25:48 2020 kern.notice kernel: [ 1478.844150] scsi 0:0:0:0: CD-ROM HUAWEI Mass Storage 2.31 PQ: 0 ANSI: 2
Thu Apr 16 14:25:48 2020 kern.notice kernel: [ 1478.858517] sd 1:0:0:0: [sda] Attached SCSI removable disk
Czyli konfigurację mogę przegrać i dodać własne reguły do firewall-a.
Szkoda, że nie robi się to w taki sam prosty sposób jak na Gargoyle ale powonieniem dać sobie radę.
Dzięki za pomoc i pozdrawiam
z przebojami uruchomiłem na 1043nd openwrt 19.07. (po sysupgrade router się nie podniósł)
- czy wystarczy, że włączę "flow offloadingu" w konfiguracji zapory sieciowej czy gdzieś jeszcze muszę to uczynić
- czy openVPN serwer muszę uruchamiać wg instrukcji na stronie i klucze generować z konsoli czy też mogę przegrać konfigurację z Gargoyle,
tam było to jak dla mnie prostsze i bardziej intuicyjne (chociaż wdaje mi się na pierwszy rzut oka, że OpenWRT ma więcej opcji)
nie używam Qos ,ale najpierw pobawię si 1043NDv1 z openWRT
ok czyli pozostaje OpenWRT
Dzięki
A Gargoyle będzie miało kiedyś wsparcie do HW flow offload
19.07 -rozumiem openWRT
a czy 1.13 gargoyle nie nie ma "flow offload"
eko.one.pl → Posty przez piratee
Forum oparte o PunBB, wspierane przez Informer Technologies, Inc