No i mam standardowo problem. Generalnie konfigurację OpenVPN wiem jak wykonać tylko nie rozumiem dlaczego po utworzeniu połączenia (interfejs tun0) tracę dostęp do neta, a jak wyłączę interfejs to połączenie wraca. Może ktoś coś?
root@Router:~# uci show openvpn
openvpn.expressvpn=openvpn
openvpn.expressvpn.dev='tun'
openvpn.expressvpn.nobind='1'
openvpn.expressvpn.verb='3'
openvpn.expressvpn.client='1'
openvpn.expressvpn.remote='luxembourg-ca-version-2.expressnetw.com'
openvpn.expressvpn.keysize='256'
openvpn.expressvpn.auth='SHA512'
openvpn.expressvpn.tls_client='1'
openvpn.expressvpn.cert='/etc/openvpn/express/client.crt'
openvpn.expressvpn.ca='/etc/openvpn/express/ca2.crt'
openvpn.expressvpn.key='/etc/openvpn/express/client.key'
openvpn.expressvpn.tun_mtu='1500'
openvpn.expressvpn.port='1195'
openvpn.expressvpn.ns_cert_type='server'
openvpn.expressvpn.persist_tun='1'
openvpn.expressvpn.persist_key='1'
openvpn.expressvpn.shaper='1300'
openvpn.expressvpn.route_delay='2'
openvpn.expressvpn.tls_auth='/etc/openvpn/express/ta.key 1'
openvpn.expressvpn.cipher='AES-256-CBC'
openvpn.expressvpn.status='/var/log/openvpn-client.log'
openvpn.expressvpn.comp_lzo='yes'
openvpn.expressvpn.enabled='1'
root@Router:~# cat /etc/config/network
config interface 'loopback'
option ifname 'lo'
option proto 'static'
option ipaddr '127.0.0.1'
option netmask '255.0.0.0'
config interface 'lan'
option type 'bridge'
option proto 'static'
option netmask '255.255.255.0'
option ipaddr '192.168.2.1'
option ifname 'eth0.1'
option dns '8.8.8.8 8.8.4.4'
config interface 'wan'
option _orig_ifname 'eth0.2'
option _orig_bridge 'false'
option proto 'dhcp'
option ifname 'eth0.2'
option macaddr 'F8:1A:67:BE:D4:74'
option dns '8.8.8.8 8.8.4.4'
config switch
option reset '1'
option enable_vlan '1'
option name 'switch0'
config switch_vlan
option vlan '1'
option ports '0t 2 3 4 5'
option device 'switch0'
config switch_vlan
option vlan '2'
option ports '0t 1'
option device 'switch0'
Mon Jan 2 00:49:51 2017 daemon.info dnsmasq-dhcp[2219]: DHCPREQUEST(br-lan) 192.168.2.151 08:d4:0c:db:78:7e
Mon Jan 2 00:49:51 2017 daemon.info dnsmasq-dhcp[2219]: DHCPACK(br-lan) 192.168.2.151 08:d4:0c:db:78:7e Maciek-Dell-7559
Mon Jan 2 00:50:01 2017 daemon.notice openvpn(expressvpn)[2157]: Data Channel Encrypt: Cipher 'AES-256-CBC' initialized with 256 bit key
Mon Jan 2 00:50:01 2017 daemon.notice openvpn(expressvpn)[2157]: Data Channel Encrypt: Using 512 bit message hash 'SHA512' for HMAC authentication
Mon Jan 2 00:50:01 2017 daemon.notice openvpn(expressvpn)[2157]: Data Channel Decrypt: Cipher 'AES-256-CBC' initialized with 256 bit key
Mon Jan 2 00:50:01 2017 daemon.notice openvpn(expressvpn)[2157]: Data Channel Decrypt: Using 512 bit message hash 'SHA512' for HMAC authentication
Mon Jan 2 00:50:01 2017 daemon.notice openvpn(expressvpn)[2157]: Control Channel: TLSv1, cipher TLSv1/SSLv3 DHE-RSA-AES256-SHA, 2048 bit RSA
Mon Jan 2 00:50:01 2017 daemon.notice openvpn(expressvpn)[2157]: [Server-338-1a] Peer Connection Initiated with [AF_INET]94.242.205.37:1195
Mon Jan 2 00:50:03 2017 daemon.notice openvpn(expressvpn)[2157]: SENT CONTROL [Server-338-1a]: 'PUSH_REQUEST' (status=1)
Mon Jan 2 00:50:03 2017 daemon.info dnsmasq-dhcp[2219]: DHCPDISCOVER(br-lan) 00:22:61:a3:bc:0d
Mon Jan 2 00:50:03 2017 daemon.info dnsmasq-dhcp[2219]: DHCPOFFER(br-lan) 192.168.2.245 00:22:61:a3:bc:0d
Mon Jan 2 00:50:03 2017 daemon.info dnsmasq-dhcp[2219]: DHCPREQUEST(br-lan) 192.168.2.245 00:22:61:a3:bc:0d
Mon Jan 2 00:50:03 2017 daemon.info dnsmasq-dhcp[2219]: DHCPACK(br-lan) 192.168.2.245 00:22:61:a3:bc:0d Harman-Kardon-AVR
Mon Jan 2 00:50:03 2017 daemon.notice openvpn(expressvpn)[2157]: PUSH: Received control message: 'PUSH_REPLY,redirect-gateway def1,dhcp-option DNS 10.31.0.1,route 10.31.0.1,topology net30,ping 10,ping-restart 60,ifconfig 10.31.0.154 10.31.0.153'
Mon Jan 2 00:50:03 2017 daemon.notice openvpn(expressvpn)[2157]: OPTIONS IMPORT: timers and/or timeouts modified
Mon Jan 2 00:50:03 2017 daemon.notice openvpn(expressvpn)[2157]: OPTIONS IMPORT: --ifconfig/up options modified
Mon Jan 2 00:50:03 2017 daemon.notice openvpn(expressvpn)[2157]: OPTIONS IMPORT: route options modified
Mon Jan 2 00:50:03 2017 daemon.notice openvpn(expressvpn)[2157]: OPTIONS IMPORT: --ip-win32 and/or --dhcp-option options modified
Mon Jan 2 00:50:03 2017 daemon.notice openvpn(expressvpn)[2157]: TUN/TAP device tun0 opened
Mon Jan 2 00:50:03 2017 daemon.notice openvpn(expressvpn)[2157]: TUN/TAP TX queue length set to 100
Mon Jan 2 00:50:03 2017 daemon.notice openvpn(expressvpn)[2157]: do_ifconfig, tt->ipv6=0, tt->did_ifconfig_ipv6_setup=0
Mon Jan 2 00:50:03 2017 daemon.notice openvpn(expressvpn)[2157]: /sbin/ifconfig tun0 10.31.0.154 pointopoint 10.31.0.153 mtu 1500
Mon Jan 2 00:50:05 2017 daemon.notice openvpn(expressvpn)[2157]: /sbin/route add -net 94.242.205.37 netmask 255.255.255.255 gw 130.255.155.1
Mon Jan 2 00:50:05 2017 daemon.notice openvpn(expressvpn)[2157]: /sbin/route add -net 0.0.0.0 netmask 128.0.0.0 gw 10.31.0.153
Mon Jan 2 00:50:05 2017 daemon.notice openvpn(expressvpn)[2157]: /sbin/route add -net 128.0.0.0 netmask 128.0.0.0 gw 10.31.0.153
Mon Jan 2 00:50:05 2017 daemon.notice openvpn(expressvpn)[2157]: /sbin/route add -net 10.31.0.1 netmask 255.255.255.255 gw 10.31.0.153
Mon Jan 2 00:50:05 2017 daemon.notice openvpn(expressvpn)[2157]: Initialization Sequence Completed
Mon Jan 2 00:50:34 2017 authpriv.info dropbear[2515]: Child connection from 192.168.2.151:63914
Mon Jan 2 00:50:40 2017 authpriv.notice dropbear[2515]: Password auth succeeded for 'root' from 192.168.2.151:63914
Mon Jan 2 00:51:03 2017 daemon.notice openvpn(expressvpn)[2157]: [Server-338-1a] Inactivity timeout (--ping-restart), restarting
Mon Jan 2 00:51:03 2017 daemon.notice openvpn(expressvpn)[2157]: SIGUSR1[soft,ping-restart] received, process restarting
Mon Jan 2 00:51:03 2017 daemon.notice openvpn(expressvpn)[2157]: Restart pause, 2 second(s)
Mon Jan 2 00:51:05 2017 daemon.notice openvpn(expressvpn)[2157]: Socket Buffers: R=[163840->131072] S=[163840->131072]
Mon Jan 2 00:51:20 2017 daemon.err openvpn(expressvpn)[2157]: RESOLVE: Cannot resolve host address: luxembourg-ca-version-2.expressnetw.com: Name or service not known
Mon Jan 2 00:51:20 2017 daemon.notice openvpn(expressvpn)[2157]: Output Traffic Shaping initialized at 1300 bytes per second
Mon Jan 2 00:51:35 2017 daemon.err openvpn(expressvpn)[2157]: RESOLVE: Cannot resolve host address: luxembourg-ca-version-2.expressnetw.com: Name or service not known
Mon Jan 2 00:51:55 2017 daemon.err openvpn(expressvpn)[2157]: RESOLVE: Cannot resolve host address: luxembourg-ca-version-2.expressnetw.com: Name or service not known
root@Router:~# ifconfig tun0 down
Mon Jan 2 00:54:20 2017 daemon.notice openvpn(expressvpn)[2157]: UDPv4 link local: [undef]
Mon Jan 2 00:54:20 2017 daemon.notice openvpn(expressvpn)[2157]: UDPv4 link remote: [AF_INET]94.242.205.37:1195
Mon Jan 2 00:54:20 2017 daemon.notice openvpn(expressvpn)[2157]: TLS: Initial packet from [AF_INET]94.242.205.37:1195, sid=b4e8f2b6 05348f7e
Mon Jan 2 00:54:23 2017 daemon.notice openvpn(expressvpn)[2157]: VERIFY OK: depth=1, C=VG, ST=BVI, O=ExpressVPN, OU=ExpressVPN, CN=ExpressVPN CA, emailAddress=support@expressvpn.com
Mon Jan 2 00:54:23 2017 daemon.notice openvpn(expressvpn)[2157]: VERIFY OK: nsCertType=SERVER
Mon Jan 2 00:54:23 2017 daemon.notice openvpn(expressvpn)[2157]: VERIFY OK: depth=0, C=VG, ST=BVI, O=ExpressVPN, OU=ExpressVPN, CN=Server-338-1a, emailAddress=support@expressvpn.com
Mon Jan 2 00:54:28 2017 daemon.notice openvpn(expressvpn)[2157]: Data Channel Encrypt: Cipher 'AES-256-CBC' initialized with 256 bit key
Mon Jan 2 00:54:28 2017 daemon.notice openvpn(expressvpn)[2157]: Data Channel Encrypt: Using 512 bit message hash 'SHA512' for HMAC authentication
Mon Jan 2 00:54:28 2017 daemon.notice openvpn(expressvpn)[2157]: Data Channel Decrypt: Cipher 'AES-256-CBC' initialized with 256 bit key
Mon Jan 2 00:54:28 2017 daemon.notice openvpn(expressvpn)[2157]: Data Channel Decrypt: Using 512 bit message hash 'SHA512' for HMAC authentication
Mon Jan 2 00:54:28 2017 daemon.notice openvpn(expressvpn)[2157]: Control Channel: TLSv1, cipher TLSv1/SSLv3 DHE-RSA-AES256-SHA, 2048 bit RSA
Mon Jan 2 00:54:28 2017 daemon.notice openvpn(expressvpn)[2157]: [Server-338-1a] Peer Connection Initiated with [AF_INET]94.242.205.37:1195
Mon Jan 2 00:54:30 2017 daemon.notice openvpn(expressvpn)[2157]: SENT CONTROL [Server-338-1a]: 'PUSH_REQUEST' (status=1)
Mon Jan 2 00:54:30 2017 daemon.notice openvpn(expressvpn)[2157]: PUSH: Received control message: 'PUSH_REPLY,redirect-gateway def1,dhcp-option DNS 10.31.0.1,route 10.31.0.1,topology net30,ping 10,ping-restart 60,ifconfig 10.31.0.154 10.31.0.153'
Mon Jan 2 00:54:30 2017 daemon.notice openvpn(expressvpn)[2157]: OPTIONS IMPORT: timers and/or timeouts modified
Mon Jan 2 00:54:30 2017 daemon.notice openvpn(expressvpn)[2157]: OPTIONS IMPORT: --ifconfig/up options modified
Mon Jan 2 00:54:30 2017 daemon.notice openvpn(expressvpn)[2157]: OPTIONS IMPORT: route options modified
Mon Jan 2 00:54:30 2017 daemon.notice openvpn(expressvpn)[2157]: OPTIONS IMPORT: --ip-win32 and/or --dhcp-option options modified
Mon Jan 2 00:54:30 2017 daemon.notice openvpn(expressvpn)[2157]: Preserving previous TUN/TAP instance: tun0
Mon Jan 2 00:54:30 2017 daemon.notice openvpn(expressvpn)[2157]: Initialization Sequence Completed