176

Odp: Gargoyle 1.5.5, nowy plugin OpenVPN

router się pinguje. A nas? masz na kliencie tablice routingu wskazującą że dana klasa adresowa występuje za routerem?

Masz niepotrzebny router, uszkodzony czy nie - chętnie przygarnę go.

177

Odp: Gargoyle 1.5.5, nowy plugin OpenVPN

Router tak NAS nie pinguje.
A to tablica routingu ale proszę o spradzenie jak to jest z tymi klasami adresowymi.

Tabela tras IPv4
===========================================================================
Aktywne trasy:
Miejsce docelowe w sieci   Maska sieci      Brama          Interfejs Metryka
          0.0.0.0          0.0.0.0      192.168.2.1    192.168.2.100     25
         10.8.0.0    255.255.255.0         On-link          10.8.0.2    286
         10.8.0.2  255.255.255.255         On-link          10.8.0.2    286
       10.8.0.255  255.255.255.255         On-link          10.8.0.2    286
        127.0.0.0        255.0.0.0         On-link         127.0.0.1    306
        127.0.0.1  255.255.255.255         On-link         127.0.0.1    306
  127.255.255.255  255.255.255.255         On-link         127.0.0.1    306
      192.168.1.0    255.255.255.0         10.8.0.1         10.8.0.2     30
      192.168.2.0    255.255.255.0         On-link     192.168.2.100    281
    192.168.2.100  255.255.255.255         On-link     192.168.2.100    281
    192.168.2.255  255.255.255.255         On-link     192.168.2.100    281
        224.0.0.0        240.0.0.0         On-link         127.0.0.1    306
        224.0.0.0        240.0.0.0         On-link          10.8.0.2    286
        224.0.0.0        240.0.0.0         On-link     192.168.2.100    281
  255.255.255.255  255.255.255.255         On-link         127.0.0.1    306
  255.255.255.255  255.255.255.255         On-link          10.8.0.2    286
  255.255.255.255  255.255.255.255         On-link     192.168.2.100    281
===========================================================================

178

Odp: Gargoyle 1.5.5, nowy plugin OpenVPN

Od początku: a pod jakim adresem masz tego nasa?

Masz niepotrzebny router, uszkodzony czy nie - chętnie przygarnę go.

179 (edytowany przez gonzales 2012-08-09 21:49:50)

Odp: Gargoyle 1.5.5, nowy plugin OpenVPN

192.168.1.8

Kiedyś jak pierwszy raz uruchamiałem OpenVPN to udawało mi się do niego dostać ale to była konfiguracja ze starego tutka.
W tak zwanym, międzyczasie w sofcie Nas dołożyli funkcję uruchomienia serwera OpenVPN, może tutaj coś nakombinowałem?

180

Odp: Gargoyle 1.5.5, nowy plugin OpenVPN

A router pod 192.168.1.1 daje się pingować?

Masz niepotrzebny router, uszkodzony czy nie - chętnie przygarnę go.

181 (edytowany przez gonzales 2012-08-09 22:31:23)

Odp: Gargoyle 1.5.5, nowy plugin OpenVPN

Tak, wszystko OK. z 192.168.1.1

Okazuje się, że przez przeglądarkę i web interface NASa mogę spokojnie na niego wejść aczkolwiek wcześniej wyłączyłem VPN w NASie.
Mój błąd polegał na próbie dostania się do zasobów poprzez zmapowany dysk w laptopie. A może to nie błąd. Kiedyś tak chyba robiłem.

Czy istnieją jakieś przeciwwskazania do uruchomienia również serwera OpenVPN na NASie?
Chodzi mi tutaj czy poza otwarciem portów w routerze powinienem zrobić coś jeszcze?

182

Odp: Gargoyle 1.5.5, nowy plugin OpenVPN

Raczej przekierować porty z routera do nas.

Masz niepotrzebny router, uszkodzony czy nie - chętnie przygarnę go.

183

Odp: Gargoyle 1.5.5, nowy plugin OpenVPN

jak sprawdzic poprawnośc ddns czy mam juz przypisany???

184

Odp: Gargoyle 1.5.5, nowy plugin OpenVPN

Raz to zaloguj się na stronie ddns i sprawdź jakie ip jest.
Dwa - zrób ping po nazwie i zobacz jakie ip zwraca
Trzy - po prostu w przeglądarce wklep nazwę i zobacz czy do routera się dostaniesz...

Masz niepotrzebny router, uszkodzony czy nie - chętnie przygarnę go.

185 (edytowany przez modelos 2012-08-10 11:41:27)

Odp: Gargoyle 1.5.5, nowy plugin OpenVPN

ok połączyłem się z routerem smile tylko zę zrobiłem dostep do urządzeń LAN, a nie mogę się dostać do 2 routera który jest w WDS o adresie 192.168.1.2

186

Odp: Gargoyle 1.5.5, nowy plugin OpenVPN

Prosta sprawa, skoro widzisz sie z zewnatrz, to skonfiguruj przekierowanie portu
http://fotozrzut.pl/zdjecia/487e21eef4.png

jak na screenie..
U mnie (screen) ap ma adres 192.168.1.100 a dostaje sie do niego poprzez http://moj_ip:1088

RB760iGS + RB260GS / Ryzen 5 2660 / 16G DDR4 / MiniITX - Inea 1G (https://i.imgur.com/TLbJVDw.png)
RB951-2HnD / Celeron J1900 / 4G DDR3 / MiniITX - Satpol 100M

187

Odp: Gargoyle 1.5.5, nowy plugin OpenVPN

nie musiałem tego zrobić bo poszło ale dziekuje za pomoc

188

Odp: Gargoyle 1.5.5, nowy plugin OpenVPN

Wszystko hula super (zmienilem port na 443 i tcp), ale do pelni szczescia brakuje tylko windowsowego \r\n w configu klienta.

MiniPC 6xRJ45 2Gb, N100, 16GB DDR5, 1TB NVMe (Gargoyle)
Linksys WRT3200ACM (Gargoyle)
Tp-link 1043NDv2 (Gargoyle)

189

Odp: Gargoyle 1.5.5, nowy plugin OpenVPN

Powiedzcie mi tylko, co mam zrobic zeby hulalo to na porcie 1194 i udp? Skoro dziala na 443 i tcp, to chyba przekierowanie portow?

MiniPC 6xRJ45 2Gb, N100, 16GB DDR5, 1TB NVMe (Gargoyle)
Linksys WRT3200ACM (Gargoyle)
Tp-link 1043NDv2 (Gargoyle)

190

Odp: Gargoyle 1.5.5, nowy plugin OpenVPN

Gargoyle samo robi odpowiednie reguły w firewallu. Nic ręcznie nie musisz robić.

Masz niepotrzebny router, uszkodzony czy nie - chętnie przygarnę go.

191

Odp: Gargoyle 1.5.5, nowy plugin OpenVPN

Cezary napisał/a:

Gargoyle samo robi odpowiednie reguły w firewallu. Nic ręcznie nie musisz robić.

Niestety, nawet jak zmieniam z TCP na UDP, to nie dziala. Klient tez jest zaktualizowany na UDP.

client
remote          xxxx 1194
dev             tun
proto           udp
status          current_status
resolv-retry    infinite
ns-cert-type    server
topology        subnet
verb            5

cipher          AES-256-CBC


ca              ca.crt
cert            aaa.crt
key             aaa.key
tls-auth        ta.key

nobind
persist-key
persist-tun
comp-lzo
MiniPC 6xRJ45 2Gb, N100, 16GB DDR5, 1TB NVMe (Gargoyle)
Linksys WRT3200ACM (Gargoyle)
Tp-link 1043NDv2 (Gargoyle)

192 (edytowany przez badziewiak 2012-08-10 20:46:05)

Odp: Gargoyle 1.5.5, nowy plugin OpenVPN

badziewiak napisał/a:
Cezary napisał/a:

Gargoyle samo robi odpowiednie reguły w firewallu. Nic ręcznie nie musisz robić.

Niestety, nawet jak zmieniam z TCP na UDP, to nie dziala. Klient tez jest zaktualizowany na UDP.

client
remote          xxxx 1194
dev             tun
proto           udp
status          current_status
resolv-retry    infinite
ns-cert-type    server
topology        subnet
verb            5

cipher          AES-256-CBC


ca              ca.crt
cert            aaa.crt
key             aaa.key
tls-auth        ta.key

nobind
persist-key
persist-tun
comp-lzo

Jeszcze logread po zmianie z 443 tcp-client na 443 udp:

Aug 10 21:38:11 Gargoyle cron.err crond[1046]: crond (busybox 1.15.3) started, log level 9
Aug 10 21:38:13 Gargoyle cron.err crond[1098]: crond (busybox 1.15.3) started, log level 9
Aug 10 21:38:15 Gargoyle daemon.err openvpn(custom_config)[30706]: aaaaa/192.168.1.238:58539 Connection reset, restarting [0]
Aug 10 21:38:15 Gargoyle daemon.notice openvpn(custom_config)[30706]: aaaaa/192.168.1.238:58539 SIGUSR1[soft,connection-reset] received, client-instance restarting
Aug 10 21:38:15 Gargoyle daemon.notice openvpn(custom_config)[30706]: TCP/UDP: Closing socket
Aug 10 21:38:18 Gargoyle user.info firewall: adding lan (br-lan) to zone lan
Aug 10 21:38:18 Gargoyle user.info firewall: adding wan (eth0.2) to zone wan
Aug 10 21:38:19 Gargoyle user.info firewall: adding vpn (tun0) to zone vpn
Aug 10 21:38:21 Gargoyle cron.err crond[1634]: crond (busybox 1.15.3) started, log level 9
Aug 10 21:38:23 Gargoyle cron.err crond[1975]: crond (busybox 1.15.3) started, log level 9
Aug 10 21:38:23 Gargoyle daemon.notice openvpn(custom_config)[30706]: TCP/UDP: Closing socket
Aug 10 21:38:23 Gargoyle daemon.notice openvpn(custom_config)[30706]: Closing TUN/TAP interface
Aug 10 21:38:23 Gargoyle daemon.notice openvpn(custom_config)[30706]: /sbin/ifconfig tun0 0.0.0.0
Aug 10 21:38:23 Gargoyle daemon.notice openvpn(custom_config)[30706]: SIGTERM[hard,] received, process exiting
Aug 10 21:38:24 Gargoyle daemon.notice openvpn(custom_config)[2012]: OpenVPN 2.2.2 mips-openwrt-linux [SSL] [LZO2] [EPOLL] built on Jul  6 2012
Aug 10 21:38:24 Gargoyle daemon.warn openvpn(custom_config)[2012]: NOTE: OpenVPN 2.1 requires '--script-security 2' or higher to call user-defined scripts or executables
Aug 10 21:38:24 Gargoyle daemon.notice openvpn(custom_config)[2012]: Diffie-Hellman initialized with 1024 bit key
Aug 10 21:38:24 Gargoyle daemon.notice openvpn(custom_config)[2012]: Control Channel Authentication: using '/etc/openvpn/ta.key' as a OpenVPN static key file
Aug 10 21:38:24 Gargoyle daemon.notice openvpn(custom_config)[2012]: Outgoing Control Channel Authentication: Using 160 bit message hash 'SHA1' for HMAC authentication
Aug 10 21:38:24 Gargoyle daemon.notice openvpn(custom_config)[2012]: Incoming Control Channel Authentication: Using 160 bit message hash 'SHA1' for HMAC authentication
Aug 10 21:38:24 Gargoyle daemon.notice openvpn(custom_config)[2012]: TLS-Auth MTU parms [ L:1558 D:166 EF:66 EB:0 ET:0 EL:0 ]
Aug 10 21:38:24 Gargoyle daemon.notice openvpn(custom_config)[2012]: Socket Buffers: R=[114688->131072] S=[114688->131072]
Aug 10 21:38:24 Gargoyle daemon.notice openvpn(custom_config)[2012]: TUN/TAP device tun0 opened
Aug 10 21:38:24 Gargoyle daemon.notice openvpn(custom_config)[2012]: TUN/TAP TX queue length set to 100
Aug 10 21:38:24 Gargoyle daemon.notice openvpn(custom_config)[2012]: /sbin/ifconfig tun0 10.8.0.1 netmask 255.255.255.0 mtu 1500 broadcast 10.8.0.255
Aug 10 21:38:24 Gargoyle daemon.notice openvpn(custom_config)[2012]: Data Channel MTU parms [ L:1558 D:1450 EF:58 EB:135 ET:0 EL:0 AF:3/1 ]
Aug 10 21:38:24 Gargoyle daemon.notice openvpn(custom_config)[2012]: UDPv4 link local (bound): [undef]:443
Aug 10 21:38:24 Gargoyle daemon.notice openvpn(custom_config)[2012]: UDPv4 link remote: [undef]
Aug 10 21:38:24 Gargoyle daemon.notice openvpn(custom_config)[2012]: MULTI: multi_init called, r=256 v=256
Aug 10 21:38:24 Gargoyle daemon.notice openvpn(custom_config)[2012]: Initialization Sequence Completed
Aug 10 21:38:25 Gargoyle user.notice ifup: Enabling Router Solicitations on vpn (tun0)
Aug 10 21:38:25 Gargoyle user.info firewall: removing vpn (tun0) from zone vpn
Aug 10 21:38:26 Gargoyle user.info firewall: adding vpn (tun0) to zone vpn
Aug 10 21:38:36 Gargoyle daemon.notice openvpn(custom_config)[2012]: MULTI: multi_create_instance called
Aug 10 21:38:36 Gargoyle daemon.notice openvpn(custom_config)[2012]: 192.168.1.238:54379 Re-using SSL/TLS context
Aug 10 21:38:36 Gargoyle daemon.notice openvpn(custom_config)[2012]: 192.168.1.238:54379 LZO compression initialized
Aug 10 21:38:36 Gargoyle daemon.notice openvpn(custom_config)[2012]: 192.168.1.238:54379 Control Channel MTU parms [ L:1558 D:166 EF:66 EB:0 ET:0 EL:0 ]
Aug 10 21:38:36 Gargoyle daemon.notice openvpn(custom_config)[2012]: 192.168.1.238:54379 Data Channel MTU parms [ L:1558 D:1450 EF:58 EB:135 ET:0 EL:0 AF:3/1 ]
Aug 10 21:38:36 Gargoyle daemon.notice openvpn(custom_config)[2012]: 192.168.1.238:54379 TLS: Initial packet from 192.168.1.238:54379, sid=841f8a38 ed9e6282
Aug 10 21:39:36 Gargoyle daemon.err openvpn(custom_config)[2012]: 192.168.1.238:54379 TLS Error: TLS key negotiation failed to occur within 60 seconds (check your network connectivity)
Aug 10 21:39:36 Gargoyle daemon.err openvpn(custom_config)[2012]: 192.168.1.238:54379 TLS Error: TLS handshake failed
Aug 10 21:39:36 Gargoyle daemon.notice openvpn(custom_config)[2012]: 192.168.1.238:54379 SIGUSR1[soft,tls-error] received, client-instance restarting
Aug 10 21:39:38 Gargoyle daemon.notice openvpn(custom_config)[2012]: MULTI: multi_create_instance called
Aug 10 21:39:38 Gargoyle daemon.notice openvpn(custom_config)[2012]: 192.168.1.238:59086 Re-using SSL/TLS context
Aug 10 21:39:38 Gargoyle daemon.notice openvpn(custom_config)[2012]: 192.168.1.238:59086 LZO compression initialized
Aug 10 21:39:38 Gargoyle daemon.notice openvpn(custom_config)[2012]: 192.168.1.238:59086 Control Channel MTU parms [ L:1558 D:166 EF:66 EB:0 ET:0 EL:0 ]
Aug 10 21:39:38 Gargoyle daemon.notice openvpn(custom_config)[2012]: 192.168.1.238:59086 Data Channel MTU parms [ L:1558 D:1450 EF:58 EB:135 ET:0 EL:0 AF:3/1 ]
Aug 10 21:39:38 Gargoyle daemon.notice openvpn(custom_config)[2012]: 192.168.1.238:59086 TLS: Initial packet from 192.168.1.238:59086, sid=fcfbe5fa 551e5440
Aug 10 21:40:38 Gargoyle daemon.err openvpn(custom_config)[2012]: 192.168.1.238:59086 TLS Error: TLS key negotiation failed to occur within 60 seconds (check your network connectivity)
Aug 10 21:40:38 Gargoyle daemon.err openvpn(custom_config)[2012]: 192.168.1.238:59086 TLS Error: TLS handshake failed
Aug 10 21:40:38 Gargoyle daemon.notice openvpn(custom_config)[2012]: 192.168.1.238:59086 SIGUSR1[soft,tls-error] received, client-instance restarting
Aug 10 21:40:41 Gargoyle daemon.notice openvpn(custom_config)[2012]: MULTI: multi_create_instance called
Aug 10 21:40:41 Gargoyle daemon.notice openvpn(custom_config)[2012]: 192.168.1.238:58580 Re-using SSL/TLS context
Aug 10 21:40:41 Gargoyle daemon.notice openvpn(custom_config)[2012]: 192.168.1.238:58580 LZO compression initialized
Aug 10 21:40:41 Gargoyle daemon.notice openvpn(custom_config)[2012]: 192.168.1.238:58580 Control Channel MTU parms [ L:1558 D:166 EF:66 EB:0 ET:0 EL:0 ]
Aug 10 21:40:41 Gargoyle daemon.notice openvpn(custom_config)[2012]: 192.168.1.238:58580 Data Channel MTU parms [ L:1558 D:1450 EF:58 EB:135 ET:0 EL:0 AF:3/1 ]
Aug 10 21:40:41 Gargoyle daemon.notice openvpn(custom_config)[2012]: 192.168.1.238:58580 TLS: Initial packet from 192.168.1.238:58580, sid=279a9bca d17414b4
Aug 10 21:41:41 Gargoyle daemon.err openvpn(custom_config)[2012]: 192.168.1.238:58580 TLS Error: TLS key negotiation failed to occur within 60 seconds (check your network connectivity)
Aug 10 21:41:41 Gargoyle daemon.err openvpn(custom_config)[2012]: 192.168.1.238:58580 TLS Error: TLS handshake failed
Aug 10 21:41:41 Gargoyle daemon.notice openvpn(custom_config)[2012]: 192.168.1.238:58580 SIGUSR1[soft,tls-error] received, client-instance restarting
Aug 10 21:41:42 Gargoyle daemon.notice openvpn(custom_config)[2012]: MULTI: multi_create_instance called
Aug 10 21:41:42 Gargoyle daemon.notice openvpn(custom_config)[2012]: 192.168.1.238:63182 Re-using SSL/TLS context
Aug 10 21:41:42 Gargoyle daemon.notice openvpn(custom_config)[2012]: 192.168.1.238:63182 LZO compression initialized
Aug 10 21:41:42 Gargoyle daemon.notice openvpn(custom_config)[2012]: 192.168.1.238:63182 Control Channel MTU parms [ L:1558 D:166 EF:66 EB:0 ET:0 EL:0 ]
Aug 10 21:41:42 Gargoyle daemon.notice openvpn(custom_config)[2012]: 192.168.1.238:63182 Data Channel MTU parms [ L:1558 D:1450 EF:58 EB:135 ET:0 EL:0 AF:3/1 ]
Aug 10 21:41:42 Gargoyle daemon.notice openvpn(custom_config)[2012]: 192.168.1.238:63182 TLS: Initial packet from 192.168.1.238:63182, sid=d59f6e60 e4a0eb02
Aug 10 21:42:42 Gargoyle daemon.err openvpn(custom_config)[2012]: 192.168.1.238:63182 TLS Error: TLS key negotiation failed to occur within 60 seconds (check your network connectivity)
Aug 10 21:42:42 Gargoyle daemon.err openvpn(custom_config)[2012]: 192.168.1.238:63182 TLS Error: TLS handshake failed
Aug 10 21:42:42 Gargoyle daemon.notice openvpn(custom_config)[2012]: 192.168.1.238:63182 SIGUSR1[soft,tls-error] received, client-instance restarting
Aug 10 21:42:44 Gargoyle daemon.notice openvpn(custom_config)[2012]: MULTI: multi_create_instance called
Aug 10 21:42:44 Gargoyle daemon.notice openvpn(custom_config)[2012]: 192.168.1.238:63188 Re-using SSL/TLS context
Aug 10 21:42:44 Gargoyle daemon.notice openvpn(custom_config)[2012]: 192.168.1.238:63188 LZO compression initialized
Aug 10 21:42:44 Gargoyle daemon.notice openvpn(custom_config)[2012]: 192.168.1.238:63188 Control Channel MTU parms [ L:1558 D:166 EF:66 EB:0 ET:0 EL:0 ]
Aug 10 21:42:44 Gargoyle daemon.notice openvpn(custom_config)[2012]: 192.168.1.238:63188 Data Channel MTU parms [ L:1558 D:1450 EF:58 EB:135 ET:0 EL:0 AF:3/1 ]
Aug 10 21:42:44 Gargoyle daemon.notice openvpn(custom_config)[2012]: 192.168.1.238:63188 TLS: Initial packet from 192.168.1.238:63188, sid=9219d5b1 319eb793
Aug 10 21:43:44 Gargoyle daemon.err openvpn(custom_config)[2012]: 192.168.1.238:63188 TLS Error: TLS key negotiation failed to occur within 60 seconds (check your network connectivity)
Aug 10 21:43:44 Gargoyle daemon.err openvpn(custom_config)[2012]: 192.168.1.238:63188 TLS Error: TLS handshake failed
Aug 10 21:43:44 Gargoyle daemon.notice openvpn(custom_config)[2012]: 192.168.1.238:63188 SIGUSR1[soft,tls-error] received, client-instance restarting
Aug 10 21:43:46 Gargoyle daemon.notice openvpn(custom_config)[2012]: MULTI: multi_create_instance called
Aug 10 21:43:46 Gargoyle daemon.notice openvpn(custom_config)[2012]: 192.168.1.238:63196 Re-using SSL/TLS context
Aug 10 21:43:46 Gargoyle daemon.notice openvpn(custom_config)[2012]: 192.168.1.238:63196 LZO compression initialized
Aug 10 21:43:46 Gargoyle daemon.notice openvpn(custom_config)[2012]: 192.168.1.238:63196 Control Channel MTU parms [ L:1558 D:166 EF:66 EB:0 ET:0 EL:0 ]
Aug 10 21:43:46 Gargoyle daemon.notice openvpn(custom_config)[2012]: 192.168.1.238:63196 Data Channel MTU parms [ L:1558 D:1450 EF:58 EB:135 ET:0 EL:0 AF:3/1 ]
Aug 10 21:43:46 Gargoyle daemon.notice openvpn(custom_config)[2012]: 192.168.1.238:63196 TLS: Initial packet from 192.168.1.238:63196, sid=87b1a444 5b3b5e93
Success
MiniPC 6xRJ45 2Gb, N100, 16GB DDR5, 1TB NVMe (Gargoyle)
Linksys WRT3200ACM (Gargoyle)
Tp-link 1043NDv2 (Gargoyle)

193

Odp: Gargoyle 1.5.5, nowy plugin OpenVPN

Niby dlaczego jest

Aug 10 21:41:41 Gargoyle daemon.err openvpn(custom_config)[2012]: 192.168.1.238:58580 TLS Error: TLS key negotiation failed to occur within 60 seconds (check your network connectivity)
Aug 10 21:41:41 Gargoyle daemon.err openvpn(custom_config)[2012]: 192.168.1.238:58580 TLS Error: TLS handshake failed

?

MiniPC 6xRJ45 2Gb, N100, 16GB DDR5, 1TB NVMe (Gargoyle)
Linksys WRT3200ACM (Gargoyle)
Tp-link 1043NDv2 (Gargoyle)

194

Odp: Gargoyle 1.5.5, nowy plugin OpenVPN

Poszlo na porcie 1194, ale TCP. Na UDP nie dziala. Jakies pomysly?

Aug 11 10:51:09 Gargoyle daemon.notice openvpn(custom_config)[16239]: aaaaa/192.168.1.238:63025 PUSH: Received control message: 'PUSH_REQUEST'
Aug 11 10:51:09 Gargoyle daemon.notice openvpn(custom_config)[16239]: aaaaa/192.168.1.238:63025 SENT CONTROL [aaaaa]: 'PUSH_REPLY,route-gateway 10.8.0.1,redirect-gateway def1,ping 25,ping-restart 180,route 192.168.1.0 255.255.255.0 10.8.0.1,ifconfig 10.8.0.2 255.255.255.0' 
Aug 11 10:54:23 Gargoyle cron.err crond[16813]: crond (busybox 1.15.3) started, log level 9
Aug 11 10:54:23 Gargoyle cron.err crond[16864]: crond (busybox 1.15.3) started, log level 9
Aug 11 10:54:29 Gargoyle user.info firewall: adding lan (br-lan) to zone lan
Aug 11 10:54:29 Gargoyle user.info firewall: adding wan (eth0.2) to zone wan
Aug 11 10:54:30 Gargoyle user.info firewall: adding vpn (tun0) to zone vpn
Aug 11 10:54:32 Gargoyle cron.err crond[17440]: crond (busybox 1.15.3) started, log level 9
Aug 11 10:54:34 Gargoyle cron.err crond[17781]: crond (busybox 1.15.3) started, log level 9
Aug 11 10:54:34 Gargoyle daemon.notice openvpn(custom_config)[16239]: TCP/UDP: Closing socket
Aug 11 10:54:34 Gargoyle daemon.notice openvpn(custom_config)[16239]: TCP/UDP: Closing socket
Aug 11 10:54:34 Gargoyle daemon.notice openvpn(custom_config)[16239]: Closing TUN/TAP interface
Aug 11 10:54:34 Gargoyle daemon.notice openvpn(custom_config)[16239]: /sbin/ifconfig tun0 0.0.0.0
Aug 11 10:54:34 Gargoyle daemon.notice openvpn(custom_config)[16239]: SIGTERM[hard,] received, process exiting
Aug 11 10:54:35 Gargoyle daemon.notice openvpn(custom_config)[17818]: OpenVPN 2.2.2 mips-openwrt-linux [SSL] [LZO2] [EPOLL] built on Jul  6 2012
Aug 11 10:54:35 Gargoyle daemon.warn openvpn(custom_config)[17818]: NOTE: OpenVPN 2.1 requires '--script-security 2' or higher to call user-defined scripts or executables
Aug 11 10:54:35 Gargoyle daemon.notice openvpn(custom_config)[17818]: Diffie-Hellman initialized with 1024 bit key
Aug 11 10:54:35 Gargoyle daemon.notice openvpn(custom_config)[17818]: Control Channel Authentication: using '/etc/openvpn/ta.key' as a OpenVPN static key file
Aug 11 10:54:35 Gargoyle daemon.notice openvpn(custom_config)[17818]: Outgoing Control Channel Authentication: Using 160 bit message hash 'SHA1' for HMAC authentication
Aug 11 10:54:35 Gargoyle daemon.notice openvpn(custom_config)[17818]: Incoming Control Channel Authentication: Using 160 bit message hash 'SHA1' for HMAC authentication
Aug 11 10:54:35 Gargoyle daemon.notice openvpn(custom_config)[17818]: TLS-Auth MTU parms [ L:1558 D:166 EF:66 EB:0 ET:0 EL:0 ]
Aug 11 10:54:35 Gargoyle daemon.notice openvpn(custom_config)[17818]: Socket Buffers: R=[114688->131072] S=[114688->131072]
Aug 11 10:54:36 Gargoyle user.notice ifup: Enabling Router Solicitations on vpn (tun0)
Aug 11 10:54:36 Gargoyle daemon.notice openvpn(custom_config)[17818]: TUN/TAP device tun0 opened
Aug 11 10:54:36 Gargoyle daemon.notice openvpn(custom_config)[17818]: TUN/TAP TX queue length set to 100
Aug 11 10:54:36 Gargoyle daemon.notice openvpn(custom_config)[17818]: /sbin/ifconfig tun0 10.8.0.1 netmask 255.255.255.0 mtu 1500 broadcast 10.8.0.255
Aug 11 10:54:36 Gargoyle daemon.notice openvpn(custom_config)[17818]: Data Channel MTU parms [ L:1558 D:1450 EF:58 EB:135 ET:0 EL:0 AF:3/1 ]
Aug 11 10:54:36 Gargoyle daemon.notice openvpn(custom_config)[17818]: UDPv4 link local (bound): [undef]:1194
Aug 11 10:54:36 Gargoyle daemon.notice openvpn(custom_config)[17818]: UDPv4 link remote: [undef]
Aug 11 10:54:36 Gargoyle daemon.notice openvpn(custom_config)[17818]: MULTI: multi_init called, r=256 v=256
Aug 11 10:54:36 Gargoyle daemon.notice openvpn(custom_config)[17818]: Initialization Sequence Completed
Aug 11 10:54:36 Gargoyle user.info firewall: removing vpn (tun0) from zone vpn
Aug 11 10:54:37 Gargoyle user.info firewall: adding vpn (tun0) to zone vpn
Aug 11 10:54:44 Gargoyle daemon.notice openvpn(custom_config)[17818]: MULTI: multi_create_instance called
Aug 11 10:54:44 Gargoyle daemon.notice openvpn(custom_config)[17818]: 192.168.1.238:61360 Re-using SSL/TLS context
Aug 11 10:54:44 Gargoyle daemon.notice openvpn(custom_config)[17818]: 192.168.1.238:61360 LZO compression initialized
Aug 11 10:54:44 Gargoyle daemon.notice openvpn(custom_config)[17818]: 192.168.1.238:61360 Control Channel MTU parms [ L:1558 D:166 EF:66 EB:0 ET:0 EL:0 ]
Aug 11 10:54:44 Gargoyle daemon.notice openvpn(custom_config)[17818]: 192.168.1.238:61360 Data Channel MTU parms [ L:1558 D:1450 EF:58 EB:135 ET:0 EL:0 AF:3/1 ]
Aug 11 10:54:44 Gargoyle daemon.notice openvpn(custom_config)[17818]: 192.168.1.238:61360 TLS: Initial packet from 192.168.1.238:61360, sid=f4711cd8 1c23472d
Aug 11 10:55:44 Gargoyle daemon.err openvpn(custom_config)[17818]: 192.168.1.238:61360 TLS Error: TLS key negotiation failed to occur within 60 seconds (check your network connectivity)
Aug 11 10:55:44 Gargoyle daemon.err openvpn(custom_config)[17818]: 192.168.1.238:61360 TLS Error: TLS handshake failed
Aug 11 10:55:44 Gargoyle daemon.notice openvpn(custom_config)[17818]: 192.168.1.238:61360 SIGUSR1[soft,tls-error] received, client-instance restarting
Aug 11 10:55:47 Gargoyle daemon.notice openvpn(custom_config)[17818]: MULTI: multi_create_instance called
Aug 11 10:55:47 Gargoyle daemon.notice openvpn(custom_config)[17818]: 192.168.1.238:61361 Re-using SSL/TLS context
Aug 11 10:55:47 Gargoyle daemon.notice openvpn(custom_config)[17818]: 192.168.1.238:61361 LZO compression initialized
Aug 11 10:55:47 Gargoyle daemon.notice openvpn(custom_config)[17818]: 192.168.1.238:61361 Control Channel MTU parms [ L:1558 D:166 EF:66 EB:0 ET:0 EL:0 ]
Aug 11 10:55:47 Gargoyle daemon.notice openvpn(custom_config)[17818]: 192.168.1.238:61361 Data Channel MTU parms [ L:1558 D:1450 EF:58 EB:135 ET:0 EL:0 AF:3/1 ]
Aug 11 10:55:47 Gargoyle daemon.notice openvpn(custom_config)[17818]: 192.168.1.238:61361 TLS: Initial packet from 192.168.1.238:61361, sid=990a2e8e c8baaa62
Aug 11 10:56:47 Gargoyle daemon.err openvpn(custom_config)[17818]: 192.168.1.238:61361 TLS Error: TLS key negotiation failed to occur within 60 seconds (check your network connectivity)
Aug 11 10:56:47 Gargoyle daemon.err openvpn(custom_config)[17818]: 192.168.1.238:61361 TLS Error: TLS handshake failed
Aug 11 10:56:47 Gargoyle daemon.notice openvpn(custom_config)[17818]: 192.168.1.238:61361 SIGUSR1[soft,tls-error] received, client-instance restarting
Aug 11 10:56:50 Gargoyle daemon.notice openvpn(custom_config)[17818]: MULTI: multi_create_instance called
Aug 11 10:56:50 Gargoyle daemon.notice openvpn(custom_config)[17818]: 192.168.1.238:61371 Re-using SSL/TLS context
Aug 11 10:56:50 Gargoyle daemon.notice openvpn(custom_config)[17818]: 192.168.1.238:61371 LZO compression initialized
Aug 11 10:56:50 Gargoyle daemon.notice openvpn(custom_config)[17818]: 192.168.1.238:61371 Control Channel MTU parms [ L:1558 D:166 EF:66 EB:0 ET:0 EL:0 ]
Aug 11 10:56:50 Gargoyle daemon.notice openvpn(custom_config)[17818]: 192.168.1.238:61371 Data Channel MTU parms [ L:1558 D:1450 EF:58 EB:135 ET:0 EL:0 AF:3/1 ]
Aug 11 10:56:50 Gargoyle daemon.notice openvpn(custom_config)[17818]: 192.168.1.238:61371 TLS: Initial packet from 192.168.1.238:61371, sid=b00cbd7e 214dd46e
Success
MiniPC 6xRJ45 2Gb, N100, 16GB DDR5, 1TB NVMe (Gargoyle)
Linksys WRT3200ACM (Gargoyle)
Tp-link 1043NDv2 (Gargoyle)

195 (edytowany przez tymmej 2012-08-11 12:13:39)

Odp: Gargoyle 1.5.5, nowy plugin OpenVPN

A jak ma się sprawa z backupem ustawień? Z tego co zauważyłem w wersji 1.5.5 nie jest kopiowany /etc/openvpn. Co wtedy z certyfikatami?

196

Odp: Gargoyle 1.5.5, nowy plugin OpenVPN

Nie jest. Albo ręcznie, ale generujesz jeszcze raz.

Masz niepotrzebny router, uszkodzony czy nie - chętnie przygarnę go.

197

Odp: Gargoyle 1.5.5, nowy plugin OpenVPN

Witam
Testuje z dość dalekiej odległości OpenVPN i powiem szczerze, że działa super i tak jak myślałem. Działa dostęp do zasobów lokalnych, TVNPlayer z zagranicy i drukarka w domu. Mam pytanie czy jest możliwość ustawienia aby kolejny, drugi klient nie miał dostępu do zasobów lokalnych, tylko sam net?
Dzieki i pozdrawiam

TL-WR1043ND Gargoyle:
1.6.2.2 (r42647),  by obsy oraz NAS z MiniDLNA i Transmission

wcześnej: HUB aktywny + drukarka + USB 2,5" + miniDLNA z napisami + torrent

198

Odp: Gargoyle 1.5.5, nowy plugin OpenVPN

Z gui nie. Możesz za to przecież dowolnie ręcznie zrobić konfiguracje openvpn.

Masz niepotrzebny router, uszkodzony czy nie - chętnie przygarnę go.

199

Odp: Gargoyle 1.5.5, nowy plugin OpenVPN

OK, chodzi o konfiguracje na serwerze, czy kliencie? Poszukam info.
dzieki!

TL-WR1043ND Gargoyle:
1.6.2.2 (r42647),  by obsy oraz NAS z MiniDLNA i Transmission

wcześnej: HUB aktywny + drukarka + USB 2,5" + miniDLNA z napisami + torrent

200

Odp: Gargoyle 1.5.5, nowy plugin OpenVPN

Konfiguracja serwera, iptables też możesz wyciąć ruch od tego klienta.

Masz niepotrzebny router, uszkodzony czy nie - chętnie przygarnę go.