1

Temat: openwrt 15.05 i openvpn

Chciałbym posiadać działający serwer openvpn TUN z kluczem statycznym na openwrt 15.05 chaos calmer. Kombinuję na różne sposoby, niestety coś jest nie tak, klient nie łączy się z serwerem, podczas prób łączenia w logu systemowym serwera nie pojawiają się żadne wpisy.

cat /tmp/openvpn.log

OpenVPN STATISTICS
Updated,Tue Apr 12 11:46:58 2016
TUN/TAP read bytes,0
TUN/TAP write bytes,0
TCP/UDP read bytes,0
TCP/UDP write bytes,0
Auth read bytes,0
END

cat /etc/config/network

config interface 'vpn'      
        option ifname 'tun0'
        option proto 'none' 

cat /etc/config/firewall

config zone                               
        option name 'vpn'      
        option input 'ACCEPT'     
        option forward 'ACCEPT'       
        option output 'ACCEPT'       
        option network 'vpn'      
                                                
config forwarding                      
        option src 'vpn'              
        option dest 'wan'          
                                            
config rule                      
        option name 'OpenVPN'      
        option target 'ACCEPT'        
        option dest_port '1194'
        option proto 'udp'    
        option src 'wan'

cat /etc/config/openvpn

config openvpn 'myvpn'
        option config '/etc/openvpn/my-vpn.conf'
        option enable '1'
        option log '/tmp/openvpn.log'
        option server '10.8.0.0 255.255.255.0'

cat /etc/openvpn/my-vpn.conf

port 1194
proto udp
dev tun0
#keepalive 10 120
status /tmp/openvpn.log
verb 3
secret /etc/openvpn/secret.key

cat /etc/openvpn/secret.key

#
# 2048 bit OpenVPN static key
#
-----BEGIN OpenVPN Static key V1-----
...
-----END OpenVPN Static key V1-----

/etc/init.d/openvpn start

Tue Apr 12 12:32:16 2016 daemon.notice openvpn(myvpn)[19840]: OpenVPN 2.3.6 mips-openwrt-linux-gnu [SSL (OpenSSL)] [LZO] [EPOLL] [MH] [IPv6] built on Jul 25 2015
Tue Apr 12 12:32:16 2016 daemon.notice openvpn(myvpn)[19840]: library versions: OpenSSL 1.0.2e 3 Dec 2015, LZO 2.08
Tue Apr 12 12:32:16 2016 daemon.notice openvpn(myvpn)[19840]: Static Encrypt: Cipher 'BF-CBC' initialized with 128 bit key
Tue Apr 12 12:32:16 2016 daemon.notice openvpn(myvpn)[19840]: Static Encrypt: Using 160 bit message hash 'SHA1' for HMAC authentication
Tue Apr 12 12:32:16 2016 daemon.notice openvpn(myvpn)[19840]: Static Decrypt: Cipher 'BF-CBC' initialized with 128 bit key
Tue Apr 12 12:32:16 2016 daemon.notice openvpn(myvpn)[19840]: Static Decrypt: Using 160 bit message hash 'SHA1' for HMAC authentication
Tue Apr 12 12:32:16 2016 daemon.notice openvpn(myvpn)[19840]: Socket Buffers: R=[163840->131072] S=[163840->131072]
Tue Apr 12 12:32:16 2016 daemon.notice netifd: Interface 'vpn' is enabled
Tue Apr 12 12:32:16 2016 daemon.notice netifd: Network device 'tun0' link is up
Tue Apr 12 12:32:16 2016 daemon.notice netifd: Interface 'vpn' has link connectivity 
Tue Apr 12 12:32:16 2016 daemon.notice netifd: Interface 'vpn' is setting up now
Tue Apr 12 12:32:16 2016 daemon.notice openvpn(myvpn)[19840]: TUN/TAP device tun0 opened
Tue Apr 12 12:32:16 2016 daemon.notice openvpn(myvpn)[19840]: TUN/TAP TX queue length set to 100
Tue Apr 12 12:32:16 2016 daemon.notice openvpn(myvpn)[19840]: UDPv4 link local (bound): [undef]
Tue Apr 12 12:32:16 2016 daemon.notice openvpn(myvpn)[19840]: UDPv4 link remote: [undef]
Tue Apr 12 12:32:16 2016 daemon.notice netifd: Interface 'vpn' is now up
Tue Apr 12 12:32:17 2016 user.notice firewall: Reloading firewall due to ifup of vpn (tun0)
Tue Apr 12 12:32:17 2016 user.notice root: starting ntpclient

2

Odp: openwrt 15.05 i openvpn

Kto jest dostawcą internetu?

Masz niepotrzebny router, uszkodzony czy nie - chętnie przygarnę go.

3

Odp: openwrt 15.05 i openvpn

adsl t-mobile po drutach orange, ddns skonfigurowany prawidłowo, na router przez internet loguję się bez problemu.

4

Odp: openwrt 15.05 i openvpn

A ty przez internet (nie lan) potrafisz się zalogować do routera?

Masz niepotrzebny router, uszkodzony czy nie - chętnie przygarnę go.

5 (edytowany przez kiton 2016-04-12 12:52:08)

Odp: openwrt 15.05 i openvpn

Przez internet tak, tylko nie przez vpn. Np. subdomena http://kiton.homenet.org/ dzała (i nawet lighttpd dzała :-)

6 (edytowany przez khain 2016-04-12 13:05:02)

Odp: openwrt 15.05 i openvpn

Wrzuć logi klienta. I albo masz port zablokowany albo usługa openvpn jest w tej chwili wyłączona.

TP-Link TL-WDR3600 v1.5 -  OpenWrt Chaos Calmer 15.05.1 with Luci +Microsoft LifeCam VX-3000
RaspberryPi 2 - OMV Stone Burner 2.0.15 +Creative SB Play +Medion OR24V +DVB-T Media-Tech MT4163  +MP00202AC +3xDS18B20 +HIH-4000-002 +MPXHZ6115A +Samsung SPF-85H +D-Link DUB-H7

7

Odp: openwrt 15.05 i openvpn

klient jest na ubuntu: cat /etc/openvpn/openvpn.log

Tue Apr 12 11:12:09 2016 OpenVPN 2.3.2 x86_64-pc-linux-gnu [SSL (OpenSSL)] [LZO] [EPOLL] [PKCS11] [eurephia] [MH] [IPv6] built on Dec  1 2014
Tue Apr 12 11:12:09 2016 WARNING: file '/etc/openvpn/1.key' is group or others accessible
Tue Apr 12 11:12:09 2016 TUN/TAP device tun0 opened
Tue Apr 12 11:12:09 2016 do_ifconfig, tt->ipv6=0, tt->did_ifconfig_ipv6_setup=0
Tue Apr 12 11:12:09 2016 /sbin/ip link set dev tun0 up mtu 1500
Tue Apr 12 11:12:09 2016 /sbin/ip addr add dev tun0 local 10.8.0.2 peer 10.8.0.1
Tue Apr 12 11:12:09 2016 GID set to nogroup
Tue Apr 12 11:12:09 2016 UID set to nobody
Tue Apr 12 11:12:09 2016 Attempting to establish TCP connection with [AF_INET]178.183.231.126:1194 [nonblock]
Tue Apr 12 11:12:10 2016 TCP: connect to [AF_INET]178.183.231.126:1194 failed, will try again in 5 seconds: Connection refused
Tue Apr 12 11:12:35 2016 RESOLVE: Cannot resolve host address: in.myftp.org: Temporary failure in name resolution
Tue Apr 12 11:12:36 2016 TCP: connect to [AF_INET]178.183.231.126:1194 failed, will try again in 5 seconds: Connection refused
Tue Apr 12 11:13:01 2016 RESOLVE: Cannot resolve host address: in.myftp.org: Temporary failure in name resolution
Tue Apr 12 11:13:02 2016 TCP: connect to [AF_INET]178.183.231.126:1194 failed, will try again in 5 seconds: Connection refused
Tue Apr 12 11:13:17 2016 RESOLVE: Cannot resolve host address: in.myftp.org: Temporary failure in name resolution
Tue Apr 12 11:13:27 2016 TCP: connect to [AF_INET]178.183.231.126:1194 failed, will try again in 5 seconds: Connection timed out
Tue Apr 12 11:13:33 2016 TCP: connect to [AF_INET]178.183.231.126:1194 failed, will try again in 5 seconds: Connection refused
Tue Apr 12 11:13:40 2016 TCP: connect to [AF_INET]178.183.231.126:1194 failed, will try again in 5 seconds: Connection refused
Tue Apr 12 11:13:46 2016 TCP: connect to [AF_INET]178.183.231.126:1194 failed, will try again in 5 seconds: Connection refused
Tue Apr 12 11:13:52 2016 TCP: connect to [AF_INET]178.183.231.126:1194 failed, will try again in 5 seconds: Connection refused
Tue Apr 12 11:13:59 2016 TCP: connect to [AF_INET]178.183.231.126:1194 failed, will try again in 5 seconds: Connection refused

cat /etc/openvpn/client.conf

remote kiton.homenet.org
dev tun
proto tcp-client
comp-lzo adaptive
keepalive 15 60
ifconfig 10.8.0.2 10.8.0.1
secret /etc/openvpn/1.key
route 192.168.1.0 255.255.255.0
persist-key
persist-tun
nobind
redirect-gateway
dhcp-option DNS 192.168.123.1
user nobody
group nogroup
log openvpn.log
status openvpn-status.log

8

Odp: openwrt 15.05 i openvpn

connect to [AF_INET]178.183.231.126:1194 failed, will try again in 5 seconds: Connection refused

Odrzucone połączenie. TCP a ty masz udp.

Masz niepotrzebny router, uszkodzony czy nie - chętnie przygarnę go.

9

Odp: openwrt 15.05 i openvpn

Dziękuję za pomoc. Postęp nastąpił - pojawia się informacja w logu serwera gdy klient próbuje się połączyć, ale jeszcze nie działa tak jak powinno. Teraz wygląda to tak.
/etc/init.d/openvpn start

Wed Apr 13 08:38:10 2016 daemon.notice openvpn(my-vpn)[28593]: OpenVPN 2.3.6 mips-openwrt-linux-gnu [SSL (OpenSSL)] [LZO] [EPOLL] [MH] [IPv6] built on Jul 25 2015
Wed Apr 13 08:38:10 2016 daemon.notice openvpn(my-vpn)[28593]: library versions: OpenSSL 1.0.2e 3 Dec 2015, LZO 2.08
Wed Apr 13 08:38:10 2016 daemon.notice openvpn(my-vpn)[28593]: Static Encrypt: Cipher 'BF-CBC' initialized with 128 bit key
Wed Apr 13 08:38:10 2016 daemon.notice openvpn(my-vpn)[28593]: Static Encrypt: Using 160 bit message hash 'SHA1' for HMAC authentication
Wed Apr 13 08:38:10 2016 daemon.notice openvpn(my-vpn)[28593]: Static Decrypt: Cipher 'BF-CBC' initialized with 128 bit key
Wed Apr 13 08:38:10 2016 daemon.notice openvpn(my-vpn)[28593]: Static Decrypt: Using 160 bit message hash 'SHA1' for HMAC authentication
Wed Apr 13 08:38:10 2016 daemon.notice openvpn(my-vpn)[28593]: Socket Buffers: R=[163840->131072] S=[163840->131072]
Wed Apr 13 08:38:10 2016 daemon.notice netifd: Interface 'vpn' is enabled
Wed Apr 13 08:38:10 2016 daemon.notice netifd: Network device 'tun0' link is up
Wed Apr 13 08:38:10 2016 daemon.notice netifd: Interface 'vpn' has link connectivity 
Wed Apr 13 08:38:10 2016 daemon.notice netifd: Interface 'vpn' is setting up now
Wed Apr 13 08:38:10 2016 daemon.notice openvpn(my-vpn)[28593]: TUN/TAP device tun0 opened
Wed Apr 13 08:38:10 2016 daemon.notice openvpn(my-vpn)[28593]: TUN/TAP TX queue length set to 100
Wed Apr 13 08:38:10 2016 daemon.notice openvpn(my-vpn)[28593]: UDPv4 link local (bound): [undef]
Wed Apr 13 08:38:10 2016 daemon.notice openvpn(my-vpn)[28593]: UDPv4 link remote: [undef]
Wed Apr 13 08:38:10 2016 daemon.err openvpn(sample_server)[28592]: Options error: --server and --secret cannot be used together (you must use SSL/TLS keys)
Wed Apr 13 08:38:10 2016 daemon.warn openvpn(sample_server)[28592]: Use --help for more information.
Wed Apr 13 08:38:10 2016 daemon.notice netifd: Interface 'vpn' is now up
Wed Apr 13 08:38:10 2016 user.notice firewall: Reloading firewall due to ifup of vpn (tun0)
Wed Apr 13 08:38:11 2016 user.notice root: starting ntpclient
Wed Apr 13 08:38:15 2016 daemon.err openvpn(sample_server)[28735]: Options error: --server and --secret cannot be used together (you must use SSL/TLS keys)
Wed Apr 13 08:38:15 2016 daemon.warn openvpn(sample_server)[28735]: Use --help for more information.
Wed Apr 13 08:38:20 2016 daemon.err openvpn(sample_server)[28736]: Options error: --server and --secret cannot be used together (you must use SSL/TLS keys)
Wed Apr 13 08:38:20 2016 daemon.warn openvpn(sample_server)[28736]: Use --help for more information.
Wed Apr 13 08:38:25 2016 daemon.err openvpn(sample_server)[28741]: Options error: --server and --secret cannot be used together (you must use SSL/TLS keys)
Wed Apr 13 08:38:25 2016 daemon.warn openvpn(sample_server)[28741]: Use --help for more information.
Wed Apr 13 08:38:30 2016 daemon.err openvpn(sample_server)[28742]: Options error: --server and --secret cannot be used together (you must use SSL/TLS keys)
Wed Apr 13 08:38:30 2016 daemon.warn openvpn(sample_server)[28742]: Use --help for more information.
Wed Apr 13 08:38:35 2016 daemon.err openvpn(sample_server)[28743]: Options error: --server and --secret cannot be used together (you must use SSL/TLS keys)
Wed Apr 13 08:38:35 2016 daemon.warn openvpn(sample_server)[28743]: Use --help for more information.
Wed Apr 13 08:38:35 2016 daemon.info procd: Instance openvpn::instance1 s in a crash loop 6 crashes, 0 seconds since last crash

przy próbie łączenia kilenta na serwerze pojawia się:

Wed Apr 13 08:49:01 2016 daemon.notice openvpn(my-vpn)[28593]: Peer Connection Initiated with [AF_INET]5.172.247.233:16950
Wed Apr 13 08:49:01 2016 daemon.notice openvpn(my-vpn)[28593]: Initialization Sequence Completed
Wed Apr 13 08:49:01 2016 daemon.err openvpn(my-vpn)[28593]: write to TUN/TAP : Invalid argument (code=22)
Wed Apr 13 08:49:01 2016 daemon.err openvpn(my-vpn)[28593]: write to TUN/TAP : Invalid argument (code=22)
Wed Apr 13 08:49:01 2016 daemon.err openvpn(my-vpn)[28593]: write to TUN/TAP : Invalid argument (code=22)

cat /etc/config/openvpn

config openvpn 'sample_server'
        option enabled '1'
        option server '1'
        option port '1194'
        option proto 'udp'
#       option dev 'tun0'
#       option ca '/etc/openvpn/ca.crt'
#       option cert '/etc/openvpn/server.crt'
#       option key '/etc/openvpn/secret.key'
#       option dh '/etc/openvpn/dh1024.pem'
        option server '10.8.0.0 255.255.255.0'
#       option ifconfig_pool_persist '/tmp/ipp.txt'
        option keepalive '10 120'
#       option comp_lzo 'yes'
        option persist_key '1'
#       option persist 'key'
        option persist_tun '1'
#       option user 'nobody'
        option status '/tmp/openvpn.log'
        option verb '3'
        option secret '/etc/openvpn/secret.key'

cat /tmp/openvpn.log

OpenVPN STATISTICS
Updated,Wed Apr 13 09:07:15 2016
TUN/TAP read bytes,0
TUN/TAP write bytes,0
TCP/UDP read bytes,65192
TCP/UDP write bytes,0
Auth read bytes,50277
END

klient ubuntu: /etc/openvpn/openvpn.log

Wed Apr 13 08:49:42 2016 OpenVPN 2.3.2 x86_64-pc-linux-gnu [SSL (OpenSSL)] [LZO] [EPOLL] [PKCS11] [eurephia] [MH] [IPv6] built on Dec  1 2014
Wed Apr 13 08:49:42 2016 WARNING: you are using user/group/chroot/setcon without persist-tun -- this may cause restarts to fail
Wed Apr 13 08:49:42 2016 WARNING: file '/etc/openvpn/1.key' is group or others accessible
Wed Apr 13 08:49:42 2016 TUN/TAP device tun0 opened
Wed Apr 13 08:49:42 2016 do_ifconfig, tt->ipv6=0, tt->did_ifconfig_ipv6_setup=0
Wed Apr 13 08:49:42 2016 /sbin/ip link set dev tun0 up mtu 1500
Wed Apr 13 08:49:42 2016 /sbin/ip addr add dev tun0 local 10.8.0.2 peer 10.8.0.1
Wed Apr 13 08:49:43 2016 GID set to nogroup
Wed Apr 13 08:49:43 2016 UID set to nobody
Wed Apr 13 08:49:43 2016 UDPv4 link local: [undef]
Wed Apr 13 08:49:43 2016 UDPv4 link remote: [AF_INET]178.183.228.132:1194
RTNETLINK answers: Operation not permitted
Wed Apr 13 08:50:35 2016 ERROR: Linux route delete command failed: external program exited with error status: 2
RTNETLINK answers: Operation not permitted
Wed Apr 13 08:50:35 2016 ERROR: Linux route delete command failed: external program exited with error status: 2
RTNETLINK answers: Operation not permitted
Wed Apr 13 08:50:35 2016 ERROR: Linux route delete command failed: external program exited with error status: 2
RTNETLINK answers: Operation not permitted
Wed Apr 13 08:50:35 2016 ERROR: Linux route add command failed: external program exited with error status: 2
Wed Apr 13 08:50:35 2016 /sbin/ip addr del dev tun0 local 10.8.0.2 peer 10.8.0.1
RTNETLINK answers: Operation not permitted
Wed Apr 13 08:50:35 2016 Linux ip addr del failed: external program exited with error status: 2
Wed Apr 13 08:50:35 2016 SIGTERM[hard,] received, process exiting

cat /etc/openvpn/client.conf

remote kiton.homenet.org 1194
dev tun
comp-lzo adaptive
keepalive 15 60
ifconfig 10.8.0.2 10.8.0.1
secret /etc/openvpn/1.key
route 192.168.1.0 255.255.255.0
persist-key
nobind
redirect-gateway
dhcp-option DNS 192.168.123.1
user nobody
group nogroup
log openvpn.log
status openvpn-status.log

10

Odp: openwrt 15.05 i openvpn

option server '10.8.0.0 255.255.255.0'
option server '1'

Na pewno to drugą opcję chciałeś ustawić? Ona jest błędna. Jest u mnie na eko.one.pl gotowy poradnik, skorzystaj.

Masz niepotrzebny router, uszkodzony czy nie - chętnie przygarnę go.

11

Odp: openwrt 15.05 i openvpn

Korzystam, korzystam, jestem godny podziwu za wszystkie Twoje poradniki. Ale chyba jestem za mało kreatywny, inteligentny aby ogarnąć to wszystko i dostosować do moich potrzeb i oprogramowania. Póki co zmieniłem config serwera, ale nic to nie pomogło.
/etc/init.d/openvpn start

Wed Apr 13 09:48:02 2016 daemon.notice openvpn(my-vpn)[32384]: OpenVPN 2.3.6 mips-openwrt-linux-gnu [SSL (OpenSSL)] [LZO] [EPOLL] [MH] [IPv6] built on Jul 25 2015
Wed Apr 13 09:48:02 2016 daemon.notice openvpn(my-vpn)[32384]: library versions: OpenSSL 1.0.2e 3 Dec 2015, LZO 2.08
Wed Apr 13 09:48:02 2016 daemon.notice openvpn(my-vpn)[32384]: Static Encrypt: Cipher 'BF-CBC' initialized with 128 bit key
Wed Apr 13 09:48:02 2016 daemon.notice openvpn(my-vpn)[32384]: Static Encrypt: Using 160 bit message hash 'SHA1' for HMAC authentication
Wed Apr 13 09:48:02 2016 daemon.notice openvpn(my-vpn)[32384]: Static Decrypt: Cipher 'BF-CBC' initialized with 128 bit key
Wed Apr 13 09:48:02 2016 daemon.notice openvpn(my-vpn)[32384]: Static Decrypt: Using 160 bit message hash 'SHA1' for HMAC authentication
Wed Apr 13 09:48:03 2016 daemon.notice openvpn(my-vpn)[32384]: Socket Buffers: R=[163840->131072] S=[163840->131072]
Wed Apr 13 09:48:03 2016 daemon.notice netifd: Interface 'vpn' is enabled
Wed Apr 13 09:48:03 2016 daemon.notice netifd: Network device 'tun0' link is up
Wed Apr 13 09:48:03 2016 daemon.notice netifd: Interface 'vpn' has link connectivity 
Wed Apr 13 09:48:03 2016 daemon.notice netifd: Interface 'vpn' is setting up now
Wed Apr 13 09:48:03 2016 daemon.notice openvpn(my-vpn)[32384]: TUN/TAP device tun0 opened
Wed Apr 13 09:48:03 2016 daemon.notice openvpn(my-vpn)[32384]: TUN/TAP TX queue length set to 100
Wed Apr 13 09:48:03 2016 daemon.notice openvpn(my-vpn)[32384]: UDPv4 link local (bound): [undef]
Wed Apr 13 09:48:03 2016 daemon.notice openvpn(my-vpn)[32384]: UDPv4 link remote: [undef]
Wed Apr 13 09:48:03 2016 daemon.err openvpn(sample_server)[32383]: Options error: --server and --secret cannot be used together (you must use SSL/TLS keys)
Wed Apr 13 09:48:03 2016 daemon.warn openvpn(sample_server)[32383]: Use --help for more information.
Wed Apr 13 09:48:03 2016 daemon.notice netifd: Interface 'vpn' is now up
Wed Apr 13 09:48:03 2016 user.notice firewall: Reloading firewall due to ifup of vpn (tun0)
Wed Apr 13 09:48:03 2016 user.notice root: starting ntpclient
Wed Apr 13 09:48:08 2016 daemon.err openvpn(sample_server)[32515]: Options error: --server and --secret cannot be used together (you must use SSL/TLS keys)
Wed Apr 13 09:48:08 2016 daemon.warn openvpn(sample_server)[32515]: Use --help for more information.
Wed Apr 13 09:48:13 2016 daemon.err openvpn(sample_server)[32537]: Options error: --server and --secret cannot be used together (you must use SSL/TLS keys)
Wed Apr 13 09:48:13 2016 daemon.warn openvpn(sample_server)[32537]: Use --help for more information.
Wed Apr 13 09:48:18 2016 daemon.err openvpn(sample_server)[32538]: Options error: --server and --secret cannot be used together (you must use SSL/TLS keys)
Wed Apr 13 09:48:18 2016 daemon.warn openvpn(sample_server)[32538]: Use --help for more information.
Wed Apr 13 09:48:23 2016 daemon.err openvpn(sample_server)[32543]: Options error: --server and --secret cannot be used together (you must use SSL/TLS keys)
Wed Apr 13 09:48:23 2016 daemon.warn openvpn(sample_server)[32543]: Use --help for more information.
Wed Apr 13 09:48:28 2016 daemon.err openvpn(sample_server)[32547]: Options error: --server and --secret cannot be used together (you must use SSL/TLS keys)
Wed Apr 13 09:48:28 2016 daemon.warn openvpn(sample_server)[32547]: Use --help for more information.
Wed Apr 13 09:48:28 2016 daemon.info procd: Instance openvpn::instance1 s in a crash loop 6 crashes, 0 seconds since last crash

cat /etc/config/openvpn

config openvpn 'sample_server'
    option enabled '1'
    option port '1194'
    option proto 'udp'
    option dev 'tun'
#    option ca '/etc/openvpn/ca.crt'
#    option cert '/etc/openvpn/server.crt'
#    option key '/etc/openvpn/secret.key'
    option dh '/etc/openvpn/dh1024.pem'
    option server '10.8.0.0 255.255.255.0'
#    option ifconfig_pool_persist '/tmp/ipp.txt'
    option keepalive '10 120'
#    option comp_lzo 'yes'
#    option persist_key '1'
    option persist 'key'
#    option persist_tun '1'
#    option user 'nobody'
    option status '/tmp/openvpn.log'
    option verb '3'
    option secret '/etc/openvpn/secret.key'

12

Odp: openwrt 15.05 i openvpn

Nie wiem dlaczego się buntuje, więc zgodnie z tym co napisał wygeneruj sobie certyfikaty zamiast hasła.

Masz niepotrzebny router, uszkodzony czy nie - chętnie przygarnę go.

13

Odp: openwrt 15.05 i openvpn

A co właściwie powinno być zainstalowane gdy ma się zamiar korzystać z haseł współdzielonych:
openvpn-nossl czy openvpn-openssl ?

14

Odp: openwrt 15.05 i openvpn

To pierwsze jeżeli w ogóle nie korzystasz z szyfrowania.

Masz niepotrzebny router, uszkodzony czy nie - chętnie przygarnę go.

15

Odp: openwrt 15.05 i openvpn

Przełącznik --secret używany jest do konfigu, który łączy punkt-punkt (dev tap) i nie możesz go używać z --server, który używany jest przy konfigu wielu-użytkowników->serwer (dev tun), więc albo wygenerujesz certyfikaty dla klientów albo zmieniasz na dev tap (wtedy zastosuj przełącznik server-bridge zamiast server)

TP-Link TL-WDR3600 v1.5 -  OpenWrt Chaos Calmer 15.05.1 with Luci +Microsoft LifeCam VX-3000
RaspberryPi 2 - OMV Stone Burner 2.0.15 +Creative SB Play +Medion OR24V +DVB-T Media-Tech MT4163  +MP00202AC +3xDS18B20 +HIH-4000-002 +MPXHZ6115A +Samsung SPF-85H +D-Link DUB-H7

16

Odp: openwrt 15.05 i openvpn

Wygenerowałem certyfikaty zgodnie z poradnikiem: http://eko.one.pl/?p=openwrt-openvpntun.
Nie pojawił się dh2048.pem (plik z parametrami algorytmu Diffiego-Hellm?). Czy mam go sobie wygenerować poleceniem:

# openssl dhparam -out dh2048.pem 2048

17

Odp: openwrt 15.05 i openvpn

build-dh jak już.

Masz niepotrzebny router, uszkodzony czy nie - chętnie przygarnę go.

18

Odp: openwrt 15.05 i openvpn

Wygenerowałem certyfikaty od nowa, plik "dh2048.pem" pojawił się, klient łączy się z serwerem.
Mam jeszcze kilka pytań związanych z tematem. Klient na ubuntu łączy się z wszystkimi urządzeniami w sieci lokalnej oprócz jednego AP. Taki sam problem występował również w poprzednim routerze (tomato), łącząc się z nim przez openvpn. Będąc fizycznie z tym laptopem z ubuntu w sieci lokalnej nie ma problemu z zalogowaniem się na ten AP. Wydaje się że coś ubuntu ma gdzieś zapisane, tylko co i gdzie tego szukać?

19

Odp: openwrt 15.05 i openvpn

Albo raczej AP nie ma ustawionego gatewaya poprawie.

Masz niepotrzebny router, uszkodzony czy nie - chętnie przygarnę go.

20

Odp: openwrt 15.05 i openvpn

O, faktycznie, dziękuję!
Do czasu gdy vpn nie działało, żeby zalogować od strony lan na modem adsl, po każdym wznowieniu połączenia pppoe, musiałem zrestartować firewall. Teraz nie mogę w ogóle zalogować się na modem. Adres modemu to: 192.168.254.254, adres routera: 192.168.123.1.
Konfigurując sugerowałem się http://openrouter.info/index.php?option … ;Itemid=61
W /etc/firewall.user mam:

ifconfig eth0.2 192.168.254.253
iptables -t nat -I postrouting_rule -p tcp --src 192.168.123.0/24 --dst 192.168.254.254 --dport 80 -j SNAT --to 192.168.254.253
iptables -I zone_lan_forward -p tcp --src 192.168.123.0/24 --dst 192.168.254.254 --dport 80 -j ACCEPT

Może dałoby się także podejrzeć co się modemem przez vpn?

21

Odp: openwrt 15.05 i openvpn

Pewnie robiąc jakieś zabawy z firewalem ew specjalnie ustawiając trasę dodatkową na ip modemu.

Masz niepotrzebny router, uszkodzony czy nie - chętnie przygarnę go.