Witam,
ustawiles routa na wany
config route
option interface 'wan3'
option target '10.0.0.0'
option netmask '0.0.0.0'
option gateway '10.64.64.66'
czy target to adres twojego lanu ?
Nie jesteś zalogowany. Proszę się zalogować lub zarejestrować.
eko.one.pl → Posty przez roblad
Witam,
ustawiles routa na wany
config route
option interface 'wan3'
option target '10.0.0.0'
option netmask '0.0.0.0'
option gateway '10.64.64.66'
czy target to adres twojego lanu ?
Cezary,
Czy uda Ci sie mi pomoc ?
Czesc,
Cezary i uda Ci sie cos wymyslec na ta konfiguracje ?
zrobilem config multiwana taki
cat /etc/config/multiwan
option 'enabled' '1'
option 'default_route' 'balancer'
option health_monitor 'serial'
config interface 'wan'
option weight '10'
option health_interval '5'
option icmp_hosts 'dns'
option timeout '5'
option health_fail_retries '3'
option health_recovery_retries '5'
option failover_to 'wan2'
option dns '208.67.220.220 208.67.222.222 8.8.8.8'
config interface 'wan2'
option weight '10'
option health_interval '10'
option icmp_hosts 'dns'
option timeout '5'
option health_fail_retries '3'
option health_recovery_retries '5'
[Aoption failover_to 'wan3'
option dns '208.67.220.220 208.67.222.222 8.8.8.8'
config interface 'wan3'
option weight 'disable'
option health_interval '15'
option icmp_hosts 'getway'
option timeout '8'
option health_fail_retries '10'
option health_recovery_retries '10'
option failover_to 'wan'
option dns '208.67.220.220 208.67.222.222 8.8.8.8'
config 'mwanfw'
option porto 'udp'
option ports '8086'
option wanrule 'wan'
#config 'mwanfw'
# option porto 'tcp'
# option ports '8085'
# option wanrule 'wan'
#config mwanfw
# option wanrule 'balancer'
#config mwanfw
# option wanrule 'balancer'
config mwanfw
option wanrule 'wan'Cos tam sie laczy ale mizernie to dziala, tyle ze ruting jest teraz przez WAN jak znika wan to moge sie polaczyc na vpn poprzez wan2 ale dalej cos sie wiesza i blokuje.
Nazazwe to tak - yy to router z openvpn tam wchodzi WAN i WAN2 i jest WAN3
Router xx to router posredniczacy tam wchodzi publiczny IP i z jego lanu wychodzi WAN2 wchodzacy na router yy jest tam ustawione przekierowanie portu 8086 z zony internet na lan (openvpn) przekierowanie 8085 do https.
Na routerze z openvpn jest WAN WAN2 i WAN3. WAN jest podpiety bezposrednio do routera z openvpn. WAN2 przychodzi z 2 routera xx, do ktorego jest wpiety publiczny IP i wychodzi z niego LAN jako WAN2 do routera z openvpn. WAN3 jest rezerwowym AERO2 jak by juz oba padly i miec jakis dostep do internetu.
Dlatego przechodzi przez inny router xx siec dajaca WAN2 na router yy zeby miec 2 niezalezne wifi jak cos robie z glownym routerem yy (tam jest openvpn) malzonaka moze laczyc sie dalej po wifi do xx do zasobow w pracy i pracowac i jej nie przeszkadzam.
Zauwazylem , ze mimo tego ze juz z forwardem portu 8086 tcpudp jest wszystko ok z routera xx do WAN2 to cos jest nie tak z multiwanem, on jakos ten ruting ustawia dziwnie i nie mozna sie polaczyc na openvpn z zewnatrz a to na router xx a to na router yy losowo to sie dzieje jakos. jak sie polacze na yy (czasami) to 2 polaczenia juz nie moge zrobic na yy a zato wiele na xx. jak sie polacze na xx to czasami moge sie polaczyc 2 klientem do openvpn na yy a czasami nie na xx wtedy moge podlaczys sie 2 klientem.
Czasami jest tak ze wogole nie moge sie polaczyc na xx a moge sie tylko polaczyc na yy.
kompletnie nie wiem jak ustawic multiwana i ruting tak aby to chodzilo jak zaplanowalem:
moge sie zawsze polaczyc do openvpn na routery xx i yy
moge sie polaczyc na openvpn jak nie ma internetu na routerze xx lacze sie wtedy na yy i odwrotnie.
Dodatkowo mam ustawiony loadbalancjing na routerze yy dla sieci WAN i WAN2 po zaniku WAN przelacza sie na WAN2 i po zaniku WAN2 przelacza sie na WAN3 jak powroci WAN lub WAN2 to z WAN 3 przelacza sie na nie - to jest na routerze yy.
Router xx jest tylko routerem posredniczacym dla WAN2 dla routera yy lub zapasowym do internetu po wifi - nic tam oprocz przekierowania portu 8085 i 8086 (na tym chodzi openwpn) nie ma. Port 8085 to https do GG na routerze xx.
Nie wiem czy mam cos w ustawieniach firewala zle - ale watpie bo laczy sie wszystko (czasami nie widzi openvpn lokalnych zasobow)
Czy moze rout_data musi byc inaczej ustawione
czey ewentualnie musze dodac regole w firewalu typu:
config rule
option name wan2_to_lan_through_router_backup
option src wan2
option dest lan
option target ACCEPT
config rule
option name lan_to_wan2_from_router_to_router_backup
option src lan
option dest wan2
option target ACCEPT
czy ustawic w /etc/config/network
defaultroute na '0'
peerdns '0'
dla wszystkich WAN,WAN1,WAN2
czy zmienic nazwe WAN na WAN1 i uzyc jej pozniej we wszystkich ustawieniach.
Wydaje mi sie ze multiwan jakos przestawia to wszystko nie tak jak trzeba.
nawet bez openvpn nie dziala tak jak bym chcial
chcialbym aby ruch glownie szedl na WAN z weight 7 na WAN2 z weight 3
wszystkie wan wan2 wan3 przelaczaly sie w failoverze z jednego na nastepny
Czy jest na to jakies lekarstwo ?
OBRAZEK wyslalem Ci na maila
Naprawde nikt nie pomoze, moze Cezary ty mogl bys zrknac na te konfigi i powiedziec gdzie jest problem, jak sie polacze na xx to na yy nie moge - bardzo zadko to dziala - a chodzi mi o UDP bo openvpn na androida chodzi na udp z tcp ma problem.
moje iptables
iptables -L
Chain INPUT (policy ACCEPT)
target prot opt source destination
bw_ingress all -- anywhere anywhere
delegate_input all -- anywhere anywhere
Chain FORWARD (policy DROP)
target prot opt source destination
bw_ingress all -- anywhere anywhere
ingress_restrictions all -- anywhere anywhere
egress_restrictions all -- anywhere anywhere
delegate_forward all -- anywhere anywhere
Chain OUTPUT (policy ACCEPT)
target prot opt source destination
delegate_output all -- anywhere anywhere
Chain MINIUPNPD (1 references)
target prot opt source destination
Chain bw_ingress (2 references)
target prot opt source destination
all -- anywhere anywhere bandwidth --id total1-download-2-449 --type combined --current_bandwidth 0 --reset_interval 2 --reset_time 2 --intervals_to_save 449
all -- anywhere anywhere match-set local_addr_set dst bandwidth --id bdist1-download-minute-15 --type individual_dst --reset_interval minute --intervals_to_save 15
all -- anywhere anywhere bandwidth --id total2-download-minute-359 --type combined --current_bandwidth 0 --reset_interval minute --intervals_to_save 359
all -- anywhere anywhere match-set local_addr_set dst bandwidth --id bdist2-download-900-24 --type individual_dst --reset_interval 900 --reset_time 900 --intervals_to_save 24
all -- anywhere anywhere bandwidth --id total3-download-180-479 --type combined --current_bandwidth 0 --reset_interval 180 --reset_time 180 --intervals_to_save 479
all -- anywhere anywhere match-set local_addr_set dst bandwidth --id bdist3-download-hour-24 --type individual_dst --reset_interval hour --intervals_to_save 24
all -- anywhere anywhere bandwidth --id total4-download-7200-359 --type combined --current_bandwidth 0 --reset_interval 7200 --reset_time 7200 --intervals_to_save 359
all -- anywhere anywhere match-set local_addr_set dst bandwidth --id bdist4-download-day-31 --type individual_dst --reset_interval day --intervals_to_save 31
all -- anywhere anywhere bandwidth --id total5-download-day-365 --type combined --current_bandwidth 0 --reset_interval day --intervals_to_save 365
all -- anywhere anywhere match-set local_addr_set dst bandwidth --id bdist5-download-month-12 --type individual_dst --reset_interval month --intervals_to_save 12
Chain delegate_forward (1 references)
target prot opt source destination
forwarding_rule all -- anywhere anywhere /* user chain for forwarding */
ACCEPT all -- anywhere anywhere ctstate RELATED,ESTABLISHED
zone_lan_forward all -- anywhere anywhere
zone_wan_forward all -- anywhere anywhere
zone_wan_forward all -- anywhere anywhere
zone_wan_forward all -- anywhere anywhere
zone_wan2_forward all -- anywhere anywhere
zone_wan3_forward all -- anywhere anywhere
zone_vpn_forward all -- anywhere anywhere
reject all -- anywhere anywhere
Chain delegate_input (1 references)
target prot opt source destination
ACCEPT all -- anywhere anywhere
input_rule all -- anywhere anywhere /* user chain for input */
ACCEPT all -- anywhere anywhere ctstate RELATED,ESTABLISHED
syn_flood tcp -- anywhere anywhere tcp flags:FIN,SYN,RST,ACK/SYN
zone_lan_input all -- anywhere anywhere
zone_wan_input all -- anywhere anywhere
zone_wan_input all -- anywhere anywhere
zone_wan_input all -- anywhere anywhere
zone_wan2_input all -- anywhere anywhere
zone_wan3_input all -- anywhere anywhere
zone_vpn_input all -- anywhere anywhere
Chain delegate_output (1 references)
target prot opt source destination
ACCEPT all -- anywhere anywhere
output_rule all -- anywhere anywhere /* user chain for output */
ACCEPT all -- anywhere anywhere ctstate RELATED,ESTABLISHED
zone_lan_output all -- anywhere anywhere
zone_wan_output all -- anywhere anywhere
zone_wan_output all -- anywhere anywhere
zone_wan_output all -- anywhere anywhere
zone_wan2_output all -- anywhere anywhere
zone_wan3_output all -- anywhere anywhere
zone_vpn_output all -- anywhere anywhere
Chain egress_restrictions (1 references)
target prot opt source destination
egress_whitelist all -- anywhere anywhere
Chain egress_whitelist (1 references)
target prot opt source destination
Chain forwarding_lan_rule (1 references)
target prot opt source destination
Chain forwarding_rule (1 references)
target prot opt source destination
Chain forwarding_vpn_rule (1 references)
target prot opt source destination
Chain forwarding_wan2_rule (1 references)
target prot opt source destination
Chain forwarding_wan3_rule (1 references)
target prot opt source destination
Chain forwarding_wan_rule (1 references)
target prot opt source destination
Chain ingress_restrictions (1 references)
target prot opt source destination
ingress_whitelist all -- anywhere anywhere
Chain ingress_whitelist (1 references)
target prot opt source destination
Chain input_lan_rule (1 references)
target prot opt source destination
Chain input_rule (1 references)
target prot opt source destination
Chain input_vpn_rule (1 references)
target prot opt source destination
Chain input_wan2_rule (1 references)
target prot opt source destination
Chain input_wan3_rule (1 references)
target prot opt source destination
Chain input_wan_rule (1 references)
target prot opt source destination
ACCEPT udp -- anywhere anywhere udp dpt:8086
ACCEPT tcp -- anywhere anywhere tcp dpt:https connmark match 0x80/0x80
Chain output_lan_rule (1 references)
target prot opt source destination
Chain output_rule (1 references)
target prot opt source destination
Chain output_vpn_rule (1 references)
target prot opt source destination
Chain output_wan2_rule (1 references)
target prot opt source destination
Chain output_wan3_rule (1 references)
target prot opt source destination
Chain output_wan_rule (1 references)
target prot opt source destination
Chain pf_loopback_B (0 references)
target prot opt source destination
Chain reject (7 references)
target prot opt source destination
REJECT tcp -- anywhere anywhere reject-with tcp-reset
REJECT all -- anywhere anywhere reject-with icmp-port-unreachable
Chain syn_flood (1 references)
target prot opt source destination
RETURN tcp -- anywhere anywhere tcp flags:FIN,SYN,RST,ACK/SYN limit: avg 25/sec burst 50
DROP all -- anywhere anywhere
Chain zone_lan_dest_ACCEPT (1 references)
target prot opt source destination
ACCEPT all -- anywhere anywhere
Chain zone_lan_forward (1 references)
target prot opt source destination
forwarding_lan_rule all -- anywhere anywhere /* user chain for forwarding */
zone_wan_dest_ACCEPT all -- anywhere anywhere /* forwarding lan -> wan */
zone_wan2_dest_ACCEPT all -- anywhere anywhere /* forwarding lan -> wan2 */
zone_wan3_dest_ACCEPT all -- anywhere anywhere /* forwarding lan -> wan3 */
zone_vpn_dest_ACCEPT all -- anywhere anywhere /* forwarding lan -> vpn */
zone_lan_src_REJECT all -- anywhere anywhere
Chain zone_lan_input (1 references)
target prot opt source destination
input_lan_rule all -- anywhere anywhere /* user chain for input */
zone_lan_src_ACCEPT all -- anywhere anywhere
Chain zone_lan_output (1 references)
target prot opt source destination
output_lan_rule all -- anywhere anywhere /* user chain for output */
zone_lan_dest_ACCEPT all -- anywhere anywhere
Chain zone_lan_src_ACCEPT (1 references)
target prot opt source destination
ACCEPT all -- anywhere anywhere
Chain zone_lan_src_REJECT (1 references)
target prot opt source destination
reject all -- anywhere anywhere
Chain zone_vpn_dest_ACCEPT (2 references)
target prot opt source destination
ACCEPT all -- anywhere anywhere
Chain zone_vpn_forward (1 references)
target prot opt source destination
forwarding_vpn_rule all -- anywhere anywhere /* user chain for forwarding */
zone_wan_dest_ACCEPT all -- anywhere anywhere /* forwarding vpn -> wan */
zone_vpn_src_ACCEPT all -- anywhere anywhere
Chain zone_vpn_input (1 references)
target prot opt source destination
input_vpn_rule all -- anywhere anywhere /* user chain for input */
zone_vpn_src_ACCEPT all -- anywhere anywhere
Chain zone_vpn_output (1 references)
target prot opt source destination
output_vpn_rule all -- anywhere anywhere /* user chain for output */
zone_vpn_dest_ACCEPT all -- anywhere anywhere
Chain zone_vpn_src_ACCEPT (2 references)
target prot opt source destination
ACCEPT all -- anywhere anywhere
Chain zone_wan2_dest_ACCEPT (2 references)
target prot opt source destination
ACCEPT all -- anywhere anywhere
Chain zone_wan2_forward (1 references)
target prot opt source destination
forwarding_wan2_rule all -- anywhere anywhere /* user chain for forwarding */
zone_wan2_src_REJECT all -- anywhere anywhere
Chain zone_wan2_input (1 references)
target prot opt source destination
input_wan2_rule all -- anywhere anywhere /* user chain for input */
ACCEPT icmp -- anywhere anywhere icmp echo-request /* Allow-Ping */
zone_wan2_src_REJECT all -- anywhere anywhere
Chain zone_wan2_output (1 references)
target prot opt source destination
output_wan2_rule all -- anywhere anywhere /* user chain for output */
zone_wan2_dest_ACCEPT all -- anywhere anywhere
Chain zone_wan2_src_REJECT (2 references)
target prot opt source destination
reject all -- anywhere anywhere
Chain zone_wan3_dest_ACCEPT (2 references)
target prot opt source destination
ACCEPT all -- anywhere anywhere
Chain zone_wan3_forward (1 references)
target prot opt source destination
forwarding_wan3_rule all -- anywhere anywhere /* user chain for forwarding */
zone_wan3_src_REJECT all -- anywhere anywhere
Chain zone_wan3_input (1 references)
target prot opt source destination
input_wan3_rule all -- anywhere anywhere /* user chain for input */
ACCEPT icmp -- anywhere anywhere icmp echo-request /* Allow-Ping */
zone_wan3_src_REJECT all -- anywhere anywhere
Chain zone_wan3_output (1 references)
target prot opt source destination
output_wan3_rule all -- anywhere anywhere /* user chain for output */
zone_wan3_dest_ACCEPT all -- anywhere anywhere
Chain zone_wan3_src_REJECT (2 references)
target prot opt source destination
reject all -- anywhere anywhere
Chain zone_wan_dest_ACCEPT (3 references)
target prot opt source destination
ACCEPT all -- anywhere anywhere
ACCEPT all -- anywhere anywhere
ACCEPT all -- anywhere anywhere
Chain zone_wan_forward (3 references)
target prot opt source destination
MINIUPNPD all -- anywhere anywhere
forwarding_wan_rule all -- anywhere anywhere /* user chain for forwarding */
zone_wan_src_REJECT all -- anywhere anywhere
Chain zone_wan_input (3 references)
target prot opt source destination
input_wan_rule all -- anywhere anywhere /* user chain for input */
ACCEPT udp -- anywhere anywhere udp dpt:bootpc /* Allow-DHCP-Renew */
ACCEPT icmp -- anywhere anywhere icmp echo-request /* Allow-Ping */
zone_wan_src_REJECT all -- anywhere anywhere
Chain zone_wan_output (3 references)
target prot opt source destination
output_wan_rule all -- anywhere anywhere /* user chain for output */
zone_wan_dest_ACCEPT all -- anywhere anywhere
Chain zone_wan_src_REJECT (2 references)
target prot opt source destination
reject all -- anywhere anywhere
reject all -- anywhere anywhere
reject all -- anywhere anywhereDodalem jeszcze takie wpisy
vi /etc/config/firewall
Towards the bottom append change the dest_port variable to your preference:
config 'rule'
option 'target' 'ACCEPT'
option 'dest_port' '1194'
option 'src' 'wan'
option 'proto' 'udp'
option 'family' 'ipv4' <<< to dodalem zgodnie z opisem na openwrti tu /etc/firewall.user
and add following lines to pass all via all tun* interfaces
iptables -I INPUT 1 -i tun+ -j ACCEPT
iptables -I OUTPUT 1 -o tun+ -j ACCEPT
iptables -I FORWARD 1 -o tun+ -j ACCEPT
iptables -I FORWARD 1 -i tun+ -j ACCEPTNo i nie moge odpalic np stronki routera czy dostac sie do jakiegos kompa po polaczeniu w sieci lokalnej - wczesniej mi to dzialalo - o co tu chodzi - czy nie moglo by byc prosciej ?
Witam,
powiem Panowie (bo Pan sie tu nie spodziewam) ze sie udalo czesciowo i laczy sie i tu i tu po UDP - (cos u provaidera musialo byc bo za duzo do mnie dzwonil i sie podpytywal a skad , a zebym mu trace robil a ze dlaczego na tych portach itd) nagle zaczelo dzialac - przekierowanie na routerze xx do routera yy tez normalnie chodzi bez zaciec.
Ale mam dziwny problem (chyba to konfiguracja multiwana) jak sie polacze na xx do openvpn to 2 klient bardzo zadko mnie laczy i ciagle oczekuje na siec, za to wtedy na yy laczy bezproblemowo (przynajmniej na poczatku tak bylo i przesatlo pozniej tak dzialac). sytuacja sie odwraca jak polacze sie 1 klientem na yy to wtedy szybciudko moge sie podlaczyc na xx bez problemu zadnego ale z podlaczeniem 2 klientem na yy jest identyczna sytuacja jak opisana wczesniej.
tzn - pare razy tak zadzialalo teraz moge sie polaczyc tylko na xx a na yy mam taki status klienta:
ktory se tak wisi i wisi
Tue Oct 08 22:28:31 2013 OpenVPN 2.1.4 i686-pc-mingw32 [SSL] [LZO2] [PKCS11] built on Nov 8 2010
Tue Oct 08 22:28:31 2013 NOTE: OpenVPN 2.1 requires '--script-security 2' or higher to call user-defined scripts or executables
Tue Oct 08 22:28:31 2013 Control Channel Authentication: using 'ta.key' as a OpenVPN static key file
Tue Oct 08 22:28:31 2013 Outgoing Control Channel Authentication: Using 160 bit message hash 'SHA1' for HMAC authentication
Tue Oct 08 22:28:31 2013 Incoming Control Channel Authentication: Using 160 bit message hash 'SHA1' for HMAC authentication
Tue Oct 08 22:28:31 2013 LZO compression initialized
Tue Oct 08 22:28:31 2013 Control Channel MTU parms [ L:1542 D:166 EF:66 EB:0 ET:0 EL:0 ]
Tue Oct 08 22:28:31 2013 Socket Buffers: R=[8192->8192] S=[8192->8192]
Tue Oct 08 22:28:31 2013 Data Channel MTU parms [ L:1542 D:1450 EF:42 EB:135 ET:0 EL:0 AF:3/1 ]
Tue Oct 08 22:28:31 2013 Local Options hash (VER=V4): '504e774e'
Tue Oct 08 22:28:31 2013 Expected Remote Options hash (VER=V4): '14168603'
Tue Oct 08 22:28:31 2013 UDPv4 link local: [undef]
Tue Oct 08 22:28:31 2013 UDPv4 link remote: yyy.yyy.yyy.yyyO co moze chodzic - chcialbym sie laczyc na yy a jak zniknie mi tam siec od 1 prowaidera to laczyc sie na xx wieloma klientami (czy dla kazdego klienta musze wygenerowac odrebne poswiadczenia - chyba nie - nie ma tam zadnego UID skoro opcja jest do 1 poswiadczenia dla wielu klientow) Definiowanie adresu w www gargoile dla klienta to wskazanie pozniej klientowi na jaki adres ma sie laczyc.
czsami wcale sie 2 klient na ten sam adres nie chce polaczyc - cuda ale i tak jest sukces
moze ktos pomoze z konfiguracja tak aby to wytuningowac w ten sposob jak napisalem
lacze sie standardowo na router yy a jak nie ma sieci (mam 2 radiowki) to lacze sie na xx
chodzi mi o to zeby caly czas miec mozliwosc polaczenia ze sterowaniem w domu i monitoringiem parametrow (pewnie zachodzicie w glowe po co tak kombinuje a no wlasnie po to)
moj config firewala
config defaults
option syn_flood '1'
option input 'ACCEPT'
option output 'ACCEPT'
option forward 'REJECT'
config zone
option name 'lan'
option network 'lan'
option input 'ACCEPT'
option output 'ACCEPT'
option forward 'REJECT'
config zone
option name 'wan'
option input 'REJECT'
option output 'ACCEPT'
option forward 'REJECT'
option masq '1'
option mtu_fix '1'
option network 'wan wan2 wan3'
config forwarding
option src 'lan'
option dest 'wan'
config zone
option name 'wan2'
option input 'REJECT'
option output 'ACCEPT'
option forward 'REJECT'
option masq '1'
option mtu_fix '1'
option network 'wan2'
config forwarding
option src 'lan'
option dest 'wan2'
config zone
option name 'wan3'
option input 'REJECT'
option output 'ACCEPT'
option forward 'REJECT'
option masq '1'
option mtu_fix '1'
option network 'wan3'
config forwarding
option src 'lan'
option dest 'wan3'
config rule
option name 'Allow-DHCP-Renew'
option src 'wan'
option proto 'udp'
option dest_port '68'
option target 'ACCEPT'
option family 'ipv4'
config rule
option name 'Allow-Ping'
option src 'wan'
option proto 'icmp'
option icmp_type 'echo-request'
option family 'ipv4'
option target 'ACCEPT'
config rule
option name 'Allow-Ping'
option src 'wan2'
option proto 'icmp'
option icmp_type 'echo-request'
option family 'ipv4'
option target 'ACCEPT'
config rule
option name 'Allow-Ping'
option src 'wan3'
option proto 'icmp'
option icmp_type 'echo-request'
option family 'ipv4'
option target 'ACCEPT'
config rule
option name 'Allow-DHCPv6'
option src 'wan'
option proto 'udp'
option src_ip 'fe80::/10'
option src_port '547'
option dest_ip 'fe80::/10'
option dest_port '546'
option family 'ipv6'
option target 'ACCEPT'
config rule
option name 'Allow-ICMPv6-Input'
option src 'wan'
option proto 'icmp'
list icmp_type 'echo-request'
list icmp_type 'echo-reply'
list icmp_type 'destination-unreachable'
list icmp_type 'packet-too-big'
list icmp_type 'time-exceeded'
list icmp_type 'bad-header'
list icmp_type 'unknown-header-type'
list icmp_type 'router-solicitation'
list icmp_type 'neighbour-solicitation'
list icmp_type 'router-advertisement'
list icmp_type 'neighbour-advertisement'
option limit '1000/sec'
option family 'ipv6'
option target 'ACCEPT'
config rule
option name 'Allow-ICMPv6-Forward'
option src 'wan'
option dest '*'
option proto 'icmp'
list icmp_type 'echo-request'
list icmp_type 'echo-request'
list icmp_type 'echo-reply'
list icmp_type 'destination-unreachable'
list icmp_type 'packet-too-big'
list icmp_type 'time-exceeded'
list icmp_type 'bad-header'
list icmp_type 'unknown-header-type'
option limit '1000/sec'
option family 'ipv6'
option target 'ACCEPT'
config include
option path '/etc/firewall.user'
config include
option path '/usr/lib/gargoyle_firewall_util/gargoyle_additions.firewall'
config include 'openvpn_include_file'
option path '/etc/openvpn.firewall'
option reload '1'
config remote_accept 'ra_openvpn'
option zone 'wan'
option local_port '8086'
option remote_port '8086'
option proto 'udp'
config include 'miniupnpd'
option type 'script'
option path '/usr/share/miniupnpd/firewall.include'
option family 'IPv4'
option reload '1'
config zone 'vpn_zone'
option name 'vpn'
option network 'vpn'
option input 'ACCEPT'
option output 'ACCEPT'
option mtu_fix '1'
option masq '1'
config forwarding 'vpn_lan_forwarding'
option src 'lan'
option dest 'vpn'
config forwarding 'vpn_wan_forwarding'
option src 'vpn'
option dest 'wan'
config remote_accept 'ra_443_8085'
option local_port '443'
option remote_port '8085'
option proto 'tcp'
option zone 'wan' rezultat restartu firewala
* Flushing IPv4 filter table
* Flushing IPv4 nat table
* Flushing IPv4 mangle table
* Flushing IPv4 raw table
* Flushing conntrack table ...
* Populating IPv4 filter table
* Zone 'lan'
* Zone 'wan'
* Zone 'wan2'
* Zone 'wan3'
* Zone 'vpn'
* Rule 'Allow-DHCP-Renew'
* Rule 'Allow-Ping'
* Rule 'Allow-Ping'
* Rule 'Allow-Ping'
* Forward 'lan' -> 'wan'
* Forward 'lan' -> 'wan2'
* Forward 'lan' -> 'wan3'
* Forward 'lan' -> 'vpn'
* Forward 'vpn' -> 'wan'
* Populating IPv4 nat table
* Zone 'lan'
* Zone 'wan'
* Zone 'wan2'
* Zone 'wan3'
* Zone 'vpn'
* Populating IPv4 mangle table
* Zone 'lan'
* Zone 'wan'
* Zone 'wan2'
* Zone 'wan3'
* Zone 'vpn'
* Populating IPv4 raw table
* Zone 'lan'
* Zone 'wan'
* Zone 'wan2'
* Zone 'wan3'
* Zone 'vpn'
* Set tcp_ecn to off
* Set tcp_syncookies to on
* Set tcp_window_scaling to on
* Running script '/etc/firewall.user'
* Running script '/usr/lib/gargoyle_firewall_util/gargoyle_additions.firewall'
* Running script '/etc/openvpn.firewall'
* Running script '/usr/share/miniupnpd/firewall.include'config multiwan
root@router_glowny_extroot:~# /etc/init.d/multiwan restart
root@router_glowny_extroot:~# cat /etc/config/multiwan
config multiwan 'config'
option health_monitor 'serial'
option 'default_route' 'wan'
config interface 'wan'
option weight '7'
option health_interval '5'
option icmp_hosts 'dns'
option timeout '5'
option health_fail_retries '3'
option health_recovery_retries '5'
option failover_to 'wan2'
option dns '208.67.220.220 208.67.222.222 8.8.8.8'
config interface 'wan2'
option weight '3'
option health_interval '10'
option icmp_hosts 'dns'
option timeout '5'
option health_fail_retries '3'
option health_recovery_retries '5'
option failover_to 'wan3'
option dns '208.67.220.220 208.67.222.222 8.8.8.8'
config interface 'wan3'
option weight 'disable'
option health_interval '15'
option icmp_hosts 'getway'
option timeout '8'
option health_fail_retries '10'
option health_recovery_retries '10'
option failover_to 'wan'
option dns '208.67.220.220 208.67.222.222 8.8.8.8'config openvpn
cat server.conf
mode server
port 8086
proto tcp-server
tls-server
ifconfig 10.8.0.1 255.255.255.0
topology subnet
client-config-dir /etc/openvpn/ccd
client-to-client
duplicate-cn
ifconfig-pool 10.8.0.2 10.8.0.254 255.255.255.0
cipher BF-CBC
keysize 128
dev tun
keepalive 25 180
status /var/openvpn/current_status
verb 3
dh /etc/openvpn/dh1024.pem
ca /etc/openvpn/ca.crt
cert /etc/openvpn/server.crt
key /etc/openvpn/server.key
tls-auth /etc/openvpn/ta.key 0
persist-key
persist-tun
comp-lzo
push "topology subnet"
push "route-gateway 10.8.0.1"route_data
192.168.100.0 255.255.255.0 10.8.0.1czy route data powinna byc:
10.8.0.0 255.255.255.0 10.8.0.1
config klienta
client
remote xxx.xxx.xxx.xxx [albo yyy.yyy.yyyy.yyy] 8086
dev tun
proto udp
status current_status
resolv-retry infinite
ns-cert-type server
topology subnet
verb 3
cipher BF-CBC
keysize 128
ca ca.crt
cert klient1.crt
key klient1.key
tls-auth ta.key 1
nobind
persist-key
persist-tun
comp-lzocos skubaniec poprawil bo juz mam port 8085 z https - jak wroce do domu to potestuje moze tu byc problem z moim /etc/config/firewall - cos tam moze byc namieszane - ale przejze jeszcze raz, jak narazie vpn mam ustawiony w tym pliku na 8086 na lan z wan
a co z wan2 i wan3 skad one beda wiedzialy ze tam jest na tym porcie open vpn - czy tam cos nie trzeba dodac jakis option list czy cos w podobie ?
Co to jest ten parametr w openvpn - Data Channel MTU parms [ L:1544 D:1450 EF:44 EB:135 ET:0 EL:0 AF:3/1 ] - provaider ma MTU1500 - sprawdza ruting - ma zagadke - bo nie wie dlaczego tak moze byc ze sa tylko 3 porty dostepne - podobno od wezlow do mnie wszystko jest pootwierane - wedlug niego - sprawdza wszystkie trasy teraz.
A co do blokowanych portow u provaidera - to sprawdza teraz gdzie moze byc zablokowane i co - chcial szukac odemnie w swiat - a mi tu chodzi o to zeby bylo do mnie ze swiata - zobaczymy co wymysli - zbadalem - pare godzin to trwalo ale okazuje sie ze do mnie jest 80 http/https 433 http/https i 22 ssh - to co moge zobaczyc ze swiata - na innych portach co kolwiek na wanie nie ustawie na inny port na nasluch nic sie nie dobija jest timeout caly czas.
Hmmm - o to jest pytanie - wrzuce jak wroce do domu configi jakie mam z firewala - dlaczego mi sie nie zapisuje nie wiem, moze zmien TCP w pliku firewala jak bedziesz mial udp i zmien na tcp przez www - moze gdzies cos cachuje albo gdzies parsuje zle firewalla - przekierowanie portow tez cos nie smiga raz sie zapisuje raz nie a to mowi ze adresu nie ma a raz ze port juz jest przekierowany. 1 mi napisal ze nie ma zdefiniowanego destination zone
Mam jeszcze 1 pytanie czy poswiadczenia moga byc takie same wszedzie dla wszystkich klientow ? Czy trzeba zawsze generowac nowa paczke ?
Witam,
Panowie - podlaczylem 2 router zamiast xx - i jest to samo - dalsza inwestygacja i okazuje sie ze mimo ze mam publiczne IP to provider wycina gdzies na swoich routerach albo na firewalach wszystkie porty oprocz 433 dla http i https 80 http 22 dla ssh - po innych portach nic nie dziala forwardzy na 2 routerze ustawione (cos sie baguje na gargoyle ostatnim- nie bardzo chce przez www ustawiac porty forwardowane - pisze ze juz jest albo mu znika destination itp)
odkrylem jeszcze 1 buga w samym openvpn i www stronce - zmiana z tcp > udp i udp na tcp - mam komunikat "Port serwera "OpenVPN koliduje z wartością wpisaną w polu port przekierowany na router Zmiany nie mogą być wprowadzone."
trzeba zmienic w /etc/config/firewal protokol openvpn na odwrotny ktory zamierarzamy uzyc i wtedy zmienia port przez WWW) - tu info dla Cezarego - niech zerknie na to.
Co do providera, narazie nie moge sie dodzwonic ale chce potwierdzic w 100 % ze farfocle wycieli ruch na inne porty niz wymienione powyzej lacznie z okresleniem protokolow jakie tymi portami maja smigac w kierunku z zewnatrz do mnie - dziwne troche bo wczesniej mnie zapewniali ze caly ruch jest otwarty na wszystkich portach - rozumiem ze GG nie ma problemow z przekierowaniem tak jak moj hinski router TENDA (ma skubany zaj... moc nadajnika widac go wszedzie i nie wiem nawet jak daleko siega bo mi sie chodzic za daleko nie chcialo)
Pozdrawiam,
Wymienie router i zobacze - cos mam podejzenia ze ten router xx nie forwarduje portow wszystkich tak jak trzeba - nie trzyma czasu - to jest hinski wynalazek ale strasznie mocne ma wifi -teoretycznie powinno wszystko chodzic - jesli to nie problem multiwana i openvpn to zostaje tylko przekierowanie portow na routerze, ze nie dziala - na kilku sprawdzilem - teoretycznie pry publicznym IP provider nie powinien blokowac portow -
i proba na router z publicznym IP z przekierowanym portem ktory jest WAN2 dla routera z 2 WANAMI
Mon Oct 07 23:49:44 2013 MANAGEMENT: CMD 'log all on'
Mon Oct 07 23:49:44 2013 MANAGEMENT: CMD 'hold off'
Mon Oct 07 23:49:44 2013 MANAGEMENT: CMD 'hold release'
Mon Oct 07 23:49:44 2013 NOTE: OpenVPN 2.1 requires '--script-security 2' or higher to call user-defined scripts or executables
Mon Oct 07 23:49:44 2013 Control Channel Authentication: using 'ta.key' as a OpenVPN static key file
Mon Oct 07 23:49:44 2013 Outgoing Control Channel Authentication: Using 160 bit message hash 'SHA1' for HMAC authentication
Mon Oct 07 23:49:44 2013 Incoming Control Channel Authentication: Using 160 bit message hash 'SHA1' for HMAC authentication
Mon Oct 07 23:49:44 2013 LZO compression initialized
Mon Oct 07 23:49:44 2013 Control Channel MTU parms [ L:1544 D:168 EF:68 EB:0 ET:0 EL:0 ]
Mon Oct 07 23:49:44 2013 Socket Buffers: R=[8192->8192] S=[8192->8192]
Mon Oct 07 23:49:44 2013 Data Channel MTU parms [ L:1544 D:1450 EF:44 EB:135 ET:0 EL:0 AF:3/1 ]
Mon Oct 07 23:49:44 2013 Local Options hash (VER=V4): 'ee93268d'
Mon Oct 07 23:49:44 2013 Expected Remote Options hash (VER=V4): 'bd577cd1'
Mon Oct 07 23:49:44 2013 Attempting to establish TCP connection with xx.xx.237.36:8086
Mon Oct 07 23:49:44 2013 MANAGEMENT: >STATE:1381182584,TCP_CONNECT,,,
Mon Oct 07 23:49:46 2013 TCP: connect to xx.xx.237.36:8086 failed, will try again in 5 seconds: Connection refused (WSAECONNREFUSED)
Mon Oct 07 23:49:51 2013 MANAGEMENT: >STATE:1381182591,TCP_CONNECT,,,
Mon Oct 07 23:50:08 2013 TCP: connect to xx.xx.237.36:8086 failed, will try again in 5 seconds: Connection timed out (WSAETIMEDOUT)
i poprzez AERO
Mon Oct 07 23:47:49 2013 OpenVPN 2.1.4 i686-pc-mingw32 [SSL] [LZO2] [PKCS11] built on Nov 8 2010
Enter Management Password:
Mon Oct 07 23:47:49 2013 MANAGEMENT: TCP Socket listening on 127.0.0.1:25340
Mon Oct 07 23:47:49 2013 Need hold release from management interface, waiting...
Mon Oct 07 23:47:49 2013 MANAGEMENT: Client connected from 127.0.0.1:25340
Mon Oct 07 23:47:49 2013 MANAGEMENT: CMD 'state on'
Mon Oct 07 23:47:49 2013 MANAGEMENT: CMD 'log all on'
Mon Oct 07 23:47:49 2013 MANAGEMENT: CMD 'hold off'
Mon Oct 07 23:47:49 2013 MANAGEMENT: CMD 'hold release'
Mon Oct 07 23:47:49 2013 NOTE: OpenVPN 2.1 requires '--script-security 2' or higher to call user-defined scripts or executables
Mon Oct 07 23:47:50 2013 Control Channel Authentication: using 'ta.key' as a OpenVPN static key file
Mon Oct 07 23:47:50 2013 Outgoing Control Channel Authentication: Using 160 bit message hash 'SHA1' for HMAC authentication
Mon Oct 07 23:47:50 2013 Incoming Control Channel Authentication: Using 160 bit message hash 'SHA1' for HMAC authentication
Mon Oct 07 23:47:50 2013 LZO compression initialized
Mon Oct 07 23:47:50 2013 Control Channel MTU parms [ L:1544 D:168 EF:68 EB:0 ET:0 EL:0 ]
Mon Oct 07 23:47:50 2013 Socket Buffers: R=[8192->8192] S=[8192->8192]
Mon Oct 07 23:47:50 2013 Data Channel MTU parms [ L:1544 D:1450 EF:44 EB:135 ET:0 EL:0 AF:3/1 ]
Mon Oct 07 23:47:50 2013 Local Options hash (VER=V4): 'ee93268d'
Mon Oct 07 23:47:50 2013 Expected Remote Options hash (VER=V4): 'bd577cd1'
Mon Oct 07 23:47:50 2013 Attempting to establish TCP connection with xx.xx.149.194:8086
Mon Oct 07 23:47:50 2013 MANAGEMENT: >STATE:1381182470,TCP_CONNECT,,,
Mon Oct 07 23:47:50 2013 TCP connection established with xx.xx.149.194:8086
Mon Oct 07 23:47:50 2013 TCPv4_CLIENT link local: [undef]
Mon Oct 07 23:47:50 2013 TCPv4_CLIENT link remote: xx.xx.149.194:8086
Mon Oct 07 23:47:50 2013 MANAGEMENT: >STATE:1381182470,WAIT,,,
Mon Oct 07 23:47:50 2013 MANAGEMENT: >STATE:1381182470,AUTH,,,
Mon Oct 07 23:47:50 2013 TLS: Initial packet from xx.xx.149.194:8086, sid=33bcfbf8 90009f18
Mon Oct 07 23:47:51 2013 VERIFY OK: depth=1, /C=__/ST=UnknownProvince/L=UnknownCity/O=UnknownOrg/OU=UnknownOrgUnit/CN=uknmbprkqqdhvxs/name=uknmbprkqqdhvxs/emailAddress=uknmbprkqqdhvxs@cidqvsdkuugrgon.com
Mon Oct 07 23:47:51 2013 VERIFY OK: nsCertType=SERVER
Mon Oct 07 23:47:51 2013 VERIFY OK: depth=0, /C=__/ST=UnknownProvince/L=UnknownCity/O=UnknownOrg/OU=UnknownOrgUnit/CN=uknmbprkqqdhvxs/name=uknmbprkqqdhvxs/emailAddress=uknmbprkqqdhvxs@cidqvsdkuugrgon.com
Mon Oct 07 23:47:54 2013 Data Channel Encrypt: Cipher 'BF-CBC' initialized with 128 bit key
Mon Oct 07 23:47:54 2013 Data Channel Encrypt: Using 160 bit message hash 'SHA1' for HMAC authentication
Mon Oct 07 23:47:54 2013 Data Channel Decrypt: Cipher 'BF-CBC' initialized with 128 bit key
Mon Oct 07 23:47:54 2013 Data Channel Decrypt: Using 160 bit message hash 'SHA1' for HMAC authentication
Mon Oct 07 23:47:54 2013 Control Channel: TLSv1, cipher TLSv1/SSLv3 DHE-RSA-AES256-SHA, 1024 bit RSA
Mon Oct 07 23:47:54 2013 [uknmbprkqqdhvxs] Peer Connection Initiated with xx.xx.149.194:8086
Mon Oct 07 23:47:55 2013 MANAGEMENT: >STATE:1381182475,GET_CONFIG,,,
Mon Oct 07 23:47:56 2013 SENT CONTROL [uknmbprkqqdhvxs]: 'PUSH_REQUEST' (status=1)
Mon Oct 07 23:47:57 2013 PUSH: Received control message: 'PUSH_REPLY,topology subnet,route-gateway 10.8.0.1,ping 25,ping-restart 180,route 192.168.100.0 255.255.255.0 10.8.0.1,ifconfig 10.8.0.3 255.255.255.0'
Mon Oct 07 23:47:57 2013 OPTIONS IMPORT: timers and/or timeouts modified
Mon Oct 07 23:47:57 2013 OPTIONS IMPORT: --ifconfig/up options modified
Mon Oct 07 23:47:57 2013 OPTIONS IMPORT: route options modified
Mon Oct 07 23:47:57 2013 OPTIONS IMPORT: route-related options modified
Mon Oct 07 23:47:57 2013 ROUTE default_gateway=192.168.5.1
Mon Oct 07 23:47:57 2013 MANAGEMENT: >STATE:1381182477,ASSIGN_IP,,10.8.0.3,
Mon Oct 07 23:47:57 2013 TAP-WIN32 device [Połączenie lokalne 2] opened: \\.\Global\{B72B5DBE-8CA0-4125-B25C-263ACDE3EEC6}.tap
Mon Oct 07 23:47:57 2013 TAP-Win32 Driver Version 9.7
Mon Oct 07 23:47:57 2013 TAP-Win32 MTU=1500
Mon Oct 07 23:47:57 2013 Set TAP-Win32 TUN subnet mode network/local/netmask = 10.8.0.0/10.8.0.3/255.255.255.0 [SUCCEEDED]
Mon Oct 07 23:47:57 2013 Notified TAP-Win32 driver to set a DHCP IP/netmask of 10.8.0.3/255.255.255.0 on interface {B72B5DBE-8CA0-4125-B25C-263ACDE3EEC6} [DHCP-serv: 10.8.0.254, lease-time: 31536000]
Mon Oct 07 23:47:57 2013 Successful ARP Flush on interface [26] {B72B5DBE-8CA0-4125-B25C-263ACDE3EEC6}
Mon Oct 07 23:48:02 2013 TEST ROUTES: 1/1 succeeded len=1 ret=1 a=0 u/d=up
Mon Oct 07 23:48:02 2013 MANAGEMENT: >STATE:1381182482,ADD_ROUTES,,,
Jak to nic nie nasluchuje skoro jak lacze sie na WAN to sie laczy (jakis dziwny getway sie pokazuje do WANU2 - tu jest chyba problem jakis)
Mon Oct 07 23:44:29 2013 OpenVPN 2.1.4 i686-pc-mingw32 [SSL] [LZO2] [PKCS11] built on Nov 8 2010
Enter Management Password:
Mon Oct 07 23:44:29 2013 MANAGEMENT: TCP Socket listening on 127.0.0.1:25340
Mon Oct 07 23:44:29 2013 Need hold release from management interface, waiting...
Mon Oct 07 23:44:30 2013 MANAGEMENT: Client connected from 127.0.0.1:25340
Mon Oct 07 23:44:30 2013 MANAGEMENT: CMD 'state on'
Mon Oct 07 23:44:30 2013 MANAGEMENT: CMD 'log all on'
Mon Oct 07 23:44:30 2013 MANAGEMENT: CMD 'hold off'
Mon Oct 07 23:44:30 2013 MANAGEMENT: CMD 'hold release'
Mon Oct 07 23:44:30 2013 NOTE: OpenVPN 2.1 requires '--script-security 2' or higher to call user-defined scripts or executables
Mon Oct 07 23:44:30 2013 Control Channel Authentication: using 'ta.key' as a OpenVPN static key file
Mon Oct 07 23:44:30 2013 Outgoing Control Channel Authentication: Using 160 bit message hash 'SHA1' for HMAC authentication
Mon Oct 07 23:44:30 2013 Incoming Control Channel Authentication: Using 160 bit message hash 'SHA1' for HMAC authentication
Mon Oct 07 23:44:30 2013 LZO compression initialized
Mon Oct 07 23:44:30 2013 Control Channel MTU parms [ L:1544 D:168 EF:68 EB:0 ET:0 EL:0 ]
Mon Oct 07 23:44:30 2013 Socket Buffers: R=[8192->8192] S=[8192->8192]
Mon Oct 07 23:44:30 2013 Data Channel MTU parms [ L:1544 D:1450 EF:44 EB:135 ET:0 EL:0 AF:3/1 ]
Mon Oct 07 23:44:30 2013 Local Options hash (VER=V4): 'ee93268d'
Mon Oct 07 23:44:30 2013 Expected Remote Options hash (VER=V4): 'bd577cd1'
Mon Oct 07 23:44:30 2013 Attempting to establish TCP connection with xx.xx.149.194:8086
Mon Oct 07 23:44:30 2013 MANAGEMENT: >STATE:1381182270,TCP_CONNECT,,,
Mon Oct 07 23:44:30 2013 TCP connection established with xx.xx.149.194:8086
Mon Oct 07 23:44:30 2013 TCPv4_CLIENT link local: [undef]
Mon Oct 07 23:44:30 2013 TCPv4_CLIENT link remote: xx.xx.149.194:8086
Mon Oct 07 23:44:30 2013 MANAGEMENT: >STATE:1381182270,WAIT,,,
Mon Oct 07 23:44:30 2013 MANAGEMENT: >STATE:1381182270,AUTH,,,
Mon Oct 07 23:44:30 2013 TLS: Initial packet from xx.xx.149.194:8086, sid=03bda3d4 61fad8a8
Mon Oct 07 23:44:30 2013 VERIFY OK: depth=1, /C=__/ST=UnknownProvince/L=UnknownCity/O=UnknownOrg/OU=UnknownOrgUnit/CN=uknmbprkqqdhvxs/name=uknmbprkqqdhvxs/emailAddress=uknmbprkqqdhvxs@cidqvsdkuugrgon.com
Mon Oct 07 23:44:30 2013 VERIFY OK: nsCertType=SERVER
Mon Oct 07 23:44:30 2013 VERIFY OK: depth=0, /C=__/ST=UnknownProvince/L=UnknownCity/O=UnknownOrg/OU=UnknownOrgUnit/CN=uknmbprkqqdhvxs/name=uknmbprkqqdhvxs/emailAddress=uknmbprkqqdhvxs@cidqvsdkuugrgon.com
Mon Oct 07 23:44:32 2013 Data Channel Encrypt: Cipher 'BF-CBC' initialized with 128 bit key
Mon Oct 07 23:44:32 2013 Data Channel Encrypt: Using 160 bit message hash 'SHA1' for HMAC authentication
Mon Oct 07 23:44:32 2013 Data Channel Decrypt: Cipher 'BF-CBC' initialized with 128 bit key
Mon Oct 07 23:44:32 2013 Data Channel Decrypt: Using 160 bit message hash 'SHA1' for HMAC authentication
Mon Oct 07 23:44:32 2013 Control Channel: TLSv1, cipher TLSv1/SSLv3 DHE-RSA-AES256-SHA, 1024 bit RSA
Mon Oct 07 23:44:32 2013 [uknmbprkqqdhvxs] Peer Connection Initiated with xx.xx.149.194:8086
Mon Oct 07 23:44:33 2013 MANAGEMENT: >STATE:1381182273,GET_CONFIG,,,
Mon Oct 07 23:44:34 2013 SENT CONTROL [uknmbprkqqdhvxs]: 'PUSH_REQUEST' (status=1)
Mon Oct 07 23:44:34 2013 PUSH: Received control message: 'PUSH_REPLY,topology subnet,route-gateway 10.8.0.1,ping 25,ping-restart 180,route 192.168.100.0 255.255.255.0 10.8.0.1,ifconfig 10.8.0.2 255.255.255.0'
Mon Oct 07 23:44:34 2013 OPTIONS IMPORT: timers and/or timeouts modified
Mon Oct 07 23:44:34 2013 OPTIONS IMPORT: --ifconfig/up options modified
Mon Oct 07 23:44:34 2013 OPTIONS IMPORT: route options modified
Mon Oct 07 23:44:34 2013 OPTIONS IMPORT: route-related options modified
Mon Oct 07 23:44:34 2013 ROUTE default_gateway=192.168.200.1
Mon Oct 07 23:44:34 2013 MANAGEMENT: >STATE:1381182274,ASSIGN_IP,,10.8.0.2,
Mon Oct 07 23:44:34 2013 TAP-WIN32 device [Połączenie lokalne 2] opened: \\.\Global\{B72B5DBE-8CA0-4125-B25C-263ACDE3EEC6}.tap
Mon Oct 07 23:44:34 2013 TAP-Win32 Driver Version 9.7
Mon Oct 07 23:44:34 2013 TAP-Win32 MTU=1500
Mon Oct 07 23:44:34 2013 Set TAP-Win32 TUN subnet mode network/local/netmask = 10.8.0.0/10.8.0.2/255.255.255.0 [SUCCEEDED]
Mon Oct 07 23:44:34 2013 Notified TAP-Win32 driver to set a DHCP IP/netmask of 10.8.0.2/255.255.255.0 on interface {B72B5DBE-8CA0-4125-B25C-263ACDE3EEC6} [DHCP-serv: 10.8.0.254, lease-time: 31536000]
Mon Oct 07 23:44:34 2013 Successful ARP Flush on interface [26] {B72B5DBE-8CA0-4125-B25C-263ACDE3EEC6}
Mon Oct 07 23:44:39 2013 TEST ROUTES: 1/1 succeeded len=1 ret=1 a=0 u/d=up
Mon Oct 07 23:44:39 2013 MANAGEMENT: >STATE:1381182279,ADD_ROUTES,,,
Mon Oct 07 23:44:39 2013 C:\WINDOWS\system32\route.exe ADD 192.168.100.0 MASK 255.255.255.0 10.8.0.1
Mon Oct 07 23:44:39 2013 ROUTE: CreateIpForwardEntry succeeded with dwForwardMetric1=30 and dwForwardType=4
Mon Oct 07 23:44:39 2013 Route addition via IPAPI succeeded [adaptive]
Mon Oct 07 23:44:39 2013 Initialization Sequence Completed
Mon Oct 07 23:44:39 2013 MANAGEMENT: >STATE:1381182279,CONNECTED,SUCCESS,10.8.0.2,xx.xx.149.194
bo openvpn nasluchuje na 2 routerze na WAN a nie na WAN2 na 8086 mam multiwan - i chodzi o to zeby nasluchiwal openvpn i na wan i na wan2 jak przekieruje port do interfejsu www gargoye normalnie dostaje sie przez adres publiczny poprzez przekierowany 443 na tym routerze do routera z gargoyle po WAN2.
to rezultat proby podlaczenia na adres publiczny
Mon Oct 07 23:34:11 2013 OpenVPN 2.1.4 i686-pc-mingw32 [SSL] [LZO2] [PKCS11] built on Nov 8 2010
Enter Management Password:
Mon Oct 07 23:34:11 2013 MANAGEMENT: TCP Socket listening on 127.0.0.1:25340
Mon Oct 07 23:34:11 2013 Need hold release from management interface, waiting...
Mon Oct 07 23:34:12 2013 MANAGEMENT: Client connected from 127.0.0.1:25340
Mon Oct 07 23:34:12 2013 MANAGEMENT: CMD 'state on'
Mon Oct 07 23:34:12 2013 MANAGEMENT: CMD 'log all on'
Mon Oct 07 23:34:12 2013 MANAGEMENT: CMD 'hold off'
Mon Oct 07 23:34:12 2013 MANAGEMENT: CMD 'hold release'
Mon Oct 07 23:34:12 2013 NOTE: OpenVPN 2.1 requires '--script-security 2' or higher to call user-defined scripts or executables
Mon Oct 07 23:34:12 2013 Control Channel Authentication: using 'ta.key' as a OpenVPN static key file
Mon Oct 07 23:34:12 2013 Outgoing Control Channel Authentication: Using 160 bit message hash 'SHA1' for HMAC authentication
Mon Oct 07 23:34:12 2013 Incoming Control Channel Authentication: Using 160 bit message hash 'SHA1' for HMAC authentication
Mon Oct 07 23:34:12 2013 LZO compression initialized
Mon Oct 07 23:34:12 2013 Control Channel MTU parms [ L:1544 D:168 EF:68 EB:0 ET:0 EL:0 ]
Mon Oct 07 23:34:12 2013 Socket Buffers: R=[8192->8192] S=[8192->8192]
Mon Oct 07 23:34:12 2013 Data Channel MTU parms [ L:1544 D:1450 EF:44 EB:135 ET:0 EL:0 AF:3/1 ]
Mon Oct 07 23:34:12 2013 Local Options hash (VER=V4): 'ee93268d'
Mon Oct 07 23:34:12 2013 Expected Remote Options hash (VER=V4): 'bd577cd1'
Mon Oct 07 23:34:12 2013 Attempting to establish TCP connection with xx.xx.237.36:8086
Mon Oct 07 23:34:12 2013 MANAGEMENT: >STATE:1381181652,TCP_CONNECT,,,
Mon Oct 07 23:34:13 2013 TCP: connect to xx.xx.237.36:8086 failed, will try again in 5 seconds: Connection refused (WSAECONNREFUSED)
Mon Oct 07 23:34:19 2013 MANAGEMENT: >STATE:1381181659,TCP_CONNECT,,,
Mon Oct 07 23:34:20 2013 TCP: connect to xx.xx.237.36:8086 failed, will try again in 5 seconds: Connection refused (WSAECONNREFUSED)
Mon Oct 07 23:34:25 2013 MANAGEMENT: >STATE:1381181665,TCP_CONNECT,,,
Mon Oct 07 23:34:26 2013 TCP: connect to xx.xx.237.36:8086 failed, will try again in 5 seconds: Connection refused (WSAECONNREFUSED)
Mon Oct 07 23:34:31 2013 MANAGEMENT: >STATE:1381181671,TCP_CONNECT,,,
Mon Oct 07 23:34:32 2013 TCP: connect to xx.xx.237.36:8086 failed, will try again in 5 seconds: Connection refused (WSAECONNREFUSED)
Mon Oct 07 23:34:37 2013 MANAGEMENT: >STATE:1381181677,TCP_CONNECT,,,
Mon Oct 07 23:34:39 2013 TCP: connect to xx.xx.237.36:8086 failed, will try again in 5 seconds: Connection refused (WSAECONNREFUSED)
Mon Oct 07 23:34:44 2013 MANAGEMENT: >STATE:1381181684,TCP_CONNECT,,,
Mon Oct 07 23:34:45 2013 TCP/UDP: Closing socket
Mon Oct 07 23:34:45 2013 SIGTERM[hard,init_instance] received, process exiting
Mon Oct 07 23:34:45 2013 MANAGEMENT: >STATE:1381181685,EXITING,init_instance,,
Tak
mam na nim dodatkowo dodac regule:
config remote_accept 'ra_8086_8086'
option local_port '8086'
option remote_port '8086'
option proto 'tcpudp'
option zone 'wan'
moj route
Kernel IP routing table
Destination Gateway Genmask Flags Metric Ref Use Iface
0.0.0.0 192.168.200.1 0.0.0.0 UG 0 0 0 eth0.3
0.0.0.0 10.0.0.1 0.0.0.0 UG 0 0 0 eth0.2
0.0.0.0 10.64.64.64 0.0.0.0 UG 30 0 0 3g-wan3
10.0.0.0 0.0.0.0 255.255.255.0 U 10 0 0 eth0.2
10.8.0.0 0.0.0.0 255.255.255.0 U 0 0 0 tun0
10.64.64.64 0.0.0.0 255.255.255.255 UH 0 0 0 3g-wan3
192.168.100.0 0.0.0.0 255.255.255.0 U 0 0 0 br-lan
192.168.200.0 0.0.0.0 255.255.255.0 U 20 0 0 eth0.3
openvpn jest na eth0.2
router z ktorego przychodzi wan2 to eth0.3
tun0 - chodzi na tym routerze
forward na routerze z adresem publicznym port 8086 z WAN na LAN
"<ip_publiczne>:8086 (czyli wan2) na adres komputera gdzie masz openvpn. Nie adres tuna, czy czegoś innego. Adres jaki ma ten komputer w sieci. Piszę to już po raz któryś tam, a i tak robisz po swojemu."
na routerze tam gdzie wchodzi adres publiczny mam przekierowany port 8086 na adres 192.168.200.100, ktory jest WAN2 routera gdzie stoii openvpn - mam przekierowane, czy cos musze zrobic na routerze gdzie jest WAN i WAN2 czyli tam gdzie stoii openvpn ?
ADRES wychodzacy z routera z adresem publicznym to 192.168.200.100 i wchodzi on na router z 2 WANAMI jako WAN2 - czy na tym routerze z 2 WANAMI gdzie stoii openvpn musze jakac regule dodac czy nie ?
Rozumiem co masz na mysli, ze wystarczy tylko forward zrobic na tym routerze z adresem publicznym portu 8086 z WAN do LAN i z tego lanu adres wprowadzic jako WAN2 do 2 routera gdzie jest openvpn serwer - teoretycznie powinno dzialac, ale nie dziala - wlasnie o to chodzi.
Polaczenie na zewnetrzby adres WAN (prywatny z forwardem portow 8086 u prowaidera - x.x.149.194:8086) jest to moj WAN na routerze z openvpn czasami chodzi czasmi nie.
polaczenie na zewnetrzny adres WAN na routerze z publicznym IP x.x.237.36:8086 ktory wchodzi na router gdzie jest foreward portu 8086 z WAN do LAN i pozniej jest to wpiete do 2 routera jako WAN2 z adresem 192.168.200.100 - nie dziala wogole.
Pytanie jest takie czy musze cos dodatkowo dodac jeszcze do routera z 2 WANami ?
zeby proba polaczenia na x.x.237.36:8086 do openvpn na tym routerze doszla do skutku ?
nie to 2 regula z 192.168.200.100 nie dzialalo - to adres przychodzacy z tego routera xx gdzie jest publiczny IP
napisales ze przekierowanie ma byc na komputer gdzie chodzi openvpn, a chodzi standardowo na 10.8.0.1
adres wan routera yy to 10.0.0.155
adres wan routera xx to <ip publiczne>
z routera xx wychodzi adres 192.168.200.100 i wchodzi jako wan2 na router yy
adres tuna 10.8.0.1
adres sieci yy 192.168.100.0
adrs sieci xx 192.168.200.0 -> WAN2 >do sieci 192.168.100.0
adres 10.0.0.0 -> WAN1 do sieci 192.168.100.0
openvpn serwer chodzi na 192.168.100.0
i gdzie co poprzekierowywac musze ?
bo rozumiem ze na xx (publiczne IP z WAN do LAN 8086)
z LANU z tego routera idzie na WAN2 routera yy
A co mam Ci pokazac , jaki config ?
klienta napisalem ze zmieniam mu pozniej IP po tym przekierowaniu cy to ma wygladac tak ?:
config redirect 'redirect_enabled_number_0'
option name 'openvpn_przez_nettel'
option dest 'lan'
option proto 'tcp'
option src_dport '8086'
option dest_ip '10.8.0.1'
option dest_port '8086'
option src 'wan2'
czy dodatkowo firewal powinien miec takie wpisy:
#config forwarding 'vpn_lan_forwarding_2'
# option src 'lan'
# option dest 'vpn'
#
#config forwarding 'vpn_wan_forwarding2'
# option src 'vpn'
# option dest 'wan2'
na routerze xx tam gdzie mi wchodzi publiczny IP zrobilem forward portow z 8086 do adresu wyjsciowego 192.168.200.100
nic nie dziala
nie mam koncepcji
na router yy sie laczy nawet po ustawieniu forwardy na routerze yy
zmienilem na TCP bo zaczelo sie cokolwiek laczyc styabilniej - jest teraz TCP
client
remote (adres przwatny) 8086 (to router yy)
dev tun
proto tcp-client
status current_status
resolv-retry infinite
ns-cert-type server
topology subnet
verb 3
cipher BF-CBC
keysize 128
ca ca.crt
cert klient1.crt
key klient1.key
tls-auth ta.key 1
nobind
persist-key
persist-tun
comp-lzo
na tym robie przekierowanie ?
w konfigu klienta pozniej zmieniam adres na ten publiczny na router xx
bo chyba certyfikatow nie trzeba generowac za kazdym razem przy zmianie konfigu ?
eko.one.pl → Posty przez roblad
Forum oparte o PunBB, wspierane przez Informer Technologies, Inc