Ale... kłopotów ciąg dalszy.... (;
Openvpn uruchomiony ale działa tak na 50%
Łączy on dwie sieci w trybie tun.
192.168.11.0 klient openwrt II openwrt server 192.168.10.0
Jak pingam z sieci klienta sieć servera to ping działa.
Jak pingam z serwera interfejs lan klineta - to nie działa.
Jak pingam z serwera interfejs tun0 klineta - to działa.
ciekawa sprawa jest taka że na obu ruterach odpaliłem tcpduma, pingam z serwera i widzę na serwerze:
tcpdump -i 'tun0' icmp
tcpdump: verbose output suppressed, use -v or -vv for full protocol decode
listening on tun0, link-type RAW (Raw IP), capture size 65535 bytes
20:33:07.730480 IP 10.8.0.6 > 192.168.10.168: ICMP echo request, id 16268, seq 26, length 64
20:33:07.788253 IP 192.168.10.168 > 10.8.0.6: ICMP echo reply, id 16268, seq 26, le
ale już na tcpdumpie odpalonym na kliencie tego pinga nie widzę nic:
tcpdump -i tun0 icmp
tcpdump: verbose output suppressed, use -v or -vv for full protocol decode
listening on tun0, link-type RAW (Raw IP), capture size 65535 bytes
konfiguracja po stronie serwera:
config openvpn 'home'
option enabled '1'
option dev 'tun0'
option port '1194'
option proto 'udp'
option log '/tmp/openvpn.log'
option verb '3'
option ca '/etc/openvpn/ca.crt'
option server '10.8.0.0 255.255.255.0'
option client_to_client '1'
option client-config-dir '/etc/openvpn/clients'
option route '192.168.11.0 255.255.255.0'
option keepalive '10 60'
option dh '/etc/openvpn/dh2048.pem'
option cert '/etc/openvpn/serwer.crt'
option key '/etc/openvpn/serwer.key'
option push 'route 192.168.10.0 255.255.255.0'
cat /etc/openvpn/clients/XXX
iroute 192.168.11.0 255.255.255.0
root@XXX:~# route
Kernel IP routing table
Destination Gateway Genmask Flags Metric Ref Use Iface
default 192.168.0.1 0.0.0.0 UG 0 0 0 wlan0
10.8.0.0 10.8.0.2 255.255.255.0 UG 0 0 0 tun0
10.8.0.2 * 255.255.255.255 UH 0 0 0 tun0
192.168.0.0 * 255.255.255.0 U 0 0 0 wlan0
192.168.0.1 * 255.255.255.255 UH 0 0 0 wlan0
192.168.10.0 * 255.255.255.0 U 0 0 0 br-lan
192.168.11.0 10.8.0.2 255.255.255.0 UG 0 0 0 tun0
ifconfig:
tun0 Link encap:UNSPEC HWaddr 00-00-00-00-00-00-00-00-00-00-00-00-00-00-00-00
inet addr:10.8.0.1 P-t-P:10.8.0.2 Mask:255.255.255.255
UP POINTOPOINT RUNNING NOARP MULTICAST MTU:1500 Metric:1
RX packets:10744 errors:0 dropped:0 overruns:0 frame:0
TX packets:5711 errors:0 dropped:0 overruns:0 carrier:0
collisions:0 txqueuelen:100
RX bytes:3006254 (2.8 MiB) TX bytes:353998 (345.7 KiB)
Poproszę o pomoc w diagnozie problemu