Temat: OpenVPN - Brak dostępu do urządzeń za LAN-em.
Witam,
Posiadam poprawnie (tak mnie się wydaje) skonfigurowane OpenVPN do łączenia tunelowanego na LEDE. Z jakiegoś powodu nadal nie jestem w stanie ani pingować ani połączyć się z urządzeniami w LAN-ie.
Moje confingi:
config interface 'vpn'
option ifname 'tun0'
option proto 'none' config openvpn 'home'
option enabled '1'
option dev 'tun'
option proto 'udp'
option port '1194'
option log '/mnt/sda3/log/openvpn.log'
option verb '3'
option ca '/etc/openvpn/ca.crt'
option cert '/etc/openvpn/serwer.crt'
option key '/etc/openvpn/serwer.key'
option dh '/etc/openvpn/dh2048.pem'
option max_clients '5'
option client_to_client '1'
option keepalive '10 120'
option cipher 'AES-256-CBC'
option persist_tun '1'
option persist_key '1'
option fast_io 'on'
option comp_lzo 'adaptive'
list push 'comp_lzo adaptive'
option server '10.8.0.0 255.255.255.0'
list push 'route 192.168.2.0 255.255.255.0'
list push 'redirect-gateway def1'
list push 'dhcp-option WINS 192.168.2.1' config zone
option name 'vpn'
option input 'ACCEPT'
option forward 'ACCEPT'
option output 'ACCEPT'
option network 'vpn'
option masq '1'
config forwarding
option src 'vpn'
option dest 'wan'
config rule
option name 'LEDE'
option target 'ACCEPT'
option src 'wan'
option proto 'udp'
option dest_port '1194'
config forwarding
option src 'vpn'
option dest 'lan' Log z OpenVPN:
root@C2600_LEDE:~# cat /mnt/sda3/log/openvpn.log
Sat Sep 9 22:02:51 2017 OpenVPN 2.4.3 arm-openwrt-linux-gnu [SSL (OpenSSL)] [LZO] [LZ4] [EPOLL] [MH/PKTINFO] [AEAD]
Sat Sep 9 22:02:51 2017 library versions: OpenSSL 1.0.2k 26 Jan 2017, LZO 2.09
Sat Sep 9 22:02:51 2017 Diffie-Hellman initialized with 2048 bit key
Sat Sep 9 22:02:51 2017 TUN/TAP device tun0 opened
Sat Sep 9 22:02:51 2017 TUN/TAP TX queue length set to 100
Sat Sep 9 22:02:51 2017 do_ifconfig, tt->did_ifconfig_ipv6_setup=0
Sat Sep 9 22:02:51 2017 /sbin/ifconfig tun0 10.8.0.1 pointopoint 10.8.0.2 mtu 1500
Sat Sep 9 22:02:51 2017 /sbin/route add -net 10.8.0.0 netmask 255.255.255.0 gw 10.8.0.2
Sat Sep 9 22:02:51 2017 Could not determine IPv4/IPv6 protocol. Using AF_INET
Sat Sep 9 22:02:51 2017 Socket Buffers: R=[163840->163840] S=[163840->163840]
Sat Sep 9 22:02:51 2017 UDPv4 link local (bound): [AF_INET][undef]:1194
Sat Sep 9 22:02:51 2017 UDPv4 link remote: [AF_UNSPEC]
Sat Sep 9 22:02:51 2017 MULTI: multi_init called, r=256 v=256
Sat Sep 9 22:02:51 2017 IFCONFIG POOL: base=10.8.0.4 size=62, ipv6=0
Sat Sep 9 22:02:51 2017 Initialization Sequence Completed
Mon Sep 11 22:07:29 2017 94.254.148.82:35208 TLS: Initial packet from [AF_INET]94.254.148.82:35208, sid=e3a27b9c bd3666e6
Mon Sep 11 22:07:30 2017 94.254.148.82:35208 VERIFY OK: depth=1, C=PL, ST=Subcarpathian, L=RzeszÃow, O=Home, OU=Home, CN=LEDE Server, name=Router, emailAddress=adrian@draus.pl
Mon Sep 11 22:07:30 2017 94.254.148.82:35208 VERIFY OK: depth=0, C=PL, ST=Subcarpathian, L=Rzeszow, O=Home, OU=Home, CN=Adrian-ASUS, name=Router, emailAddress=adrian@draus.pl
Mon Sep 11 22:07:30 2017 94.254.148.82:35208 peer info: IV_VER=2.4.3
Mon Sep 11 22:07:30 2017 94.254.148.82:35208 peer info: IV_PLAT=win
Mon Sep 11 22:07:30 2017 94.254.148.82:35208 peer info: IV_PROTO=2
Mon Sep 11 22:07:30 2017 94.254.148.82:35208 peer info: IV_NCP=2
Mon Sep 11 22:07:30 2017 94.254.148.82:35208 peer info: IV_LZ4=1
Mon Sep 11 22:07:30 2017 94.254.148.82:35208 peer info: IV_LZ4v2=1
Mon Sep 11 22:07:30 2017 94.254.148.82:35208 peer info: IV_LZO=1
Mon Sep 11 22:07:30 2017 94.254.148.82:35208 peer info: IV_COMP_STUB=1
Mon Sep 11 22:07:30 2017 94.254.148.82:35208 peer info: IV_COMP_STUBv2=1
Mon Sep 11 22:07:30 2017 94.254.148.82:35208 peer info: IV_TCPNL=1
Mon Sep 11 22:07:30 2017 94.254.148.82:35208 peer info: IV_GUI_VER=OpenVPN_GUI_11
Mon Sep 11 22:07:30 2017 94.254.148.82:35208 Control Channel: TLSv1.2, cipher TLSv1/SSLv3 ECDHE-RSA-AES256-GCM-SHA384, 2048 bit RSA
Mon Sep 11 22:07:30 2017 94.254.148.82:35208 [Adrian-ASUS] Peer Connection Initiated with [AF_INET]94.254.148.82:35208
Mon Sep 11 22:07:30 2017 Adrian-ASUS/94.254.148.82:35208 MULTI_sva: pool returned IPv4=10.8.0.6, IPv6=(Not enabled)
Mon Sep 11 22:07:30 2017 Adrian-ASUS/94.254.148.82:35208 MULTI: Learn: 10.8.0.6 -> Adrian-ASUS/94.254.148.82:35208
Mon Sep 11 22:07:30 2017 Adrian-ASUS/94.254.148.82:35208 MULTI: primary virtual IP for Adrian-ASUS/94.254.148.82:35208: 10.8.0.6
Mon Sep 11 22:07:31 2017 Adrian-ASUS/94.254.148.82:35208 PUSH: Received control message: 'PUSH_REQUEST'
Mon Sep 11 22:07:31 2017 Adrian-ASUS/94.254.148.82:35208 SENT CONTROL [Adrian-ASUS]: 'PUSH_REPLY,comp_lzo adaptive,route 192.168.2.0 255.255.255.0,redirect-gateway def1,dhcp-option WINS 192.168.2.1,route 10.8.0.0 255.255.255.0,topology net30,ping 10,ping-restart 120,ifconfig 10.8.0.6 10.8.0.5,peer-id 0,cipher AES-256-GCM' (status=1)
Mon Sep 11 22:07:31 2017 Adrian-ASUS/94.254.148.82:35208 Data Channel: using negotiated cipher 'AES-256-GCM'
Mon Sep 11 22:07:31 2017 Adrian-ASUS/94.254.148.82:35208 Data Channel Encrypt: Cipher 'AES-256-GCM' initialized with 256 bit key
Mon Sep 11 22:07:31 2017 Adrian-ASUS/94.254.148.82:35208 Data Channel Decrypt: Cipher 'AES-256-GCM' initialized with 256 bit key
Mon Sep 11 22:16:16 2017 Adrian-ASUS/94.254.148.82:35208 [Adrian-ASUS] Inactivity timeout (--ping-restart), restarting
Mon Sep 11 22:16:16 2017 Adrian-ASUS/94.254.148.82:35208 SIGUSR1[soft,ping-restart] received, client-instance restarting
Mon Sep 11 22:18:03 2017 94.254.148.82:35208 TLS: Initial packet from [AF_INET]94.254.148.82:35208, sid=8e9f6ba1 25c1b8eb
Mon Sep 11 22:18:03 2017 94.254.148.82:35208 VERIFY OK: depth=1, C=PL, ST=Subcarpathian, L=RzeszÃow, O=Home, OU=Home, CN=LEDE Server, name=Router, emailAddress=adrian@draus.pl
Mon Sep 11 22:18:03 2017 94.254.148.82:35208 VERIFY OK: depth=0, C=PL, ST=Subcarpathian, L=Rzeszow, O=Home, OU=Home, CN=Adrian-ASUS, name=Router, emailAddress=adrian@draus.pl
Mon Sep 11 22:18:04 2017 94.254.148.82:35208 peer info: IV_VER=2.4.3
Mon Sep 11 22:18:04 2017 94.254.148.82:35208 peer info: IV_PLAT=win
Mon Sep 11 22:18:04 2017 94.254.148.82:35208 peer info: IV_PROTO=2
Mon Sep 11 22:18:04 2017 94.254.148.82:35208 peer info: IV_NCP=2
Mon Sep 11 22:18:04 2017 94.254.148.82:35208 peer info: IV_LZ4=1
Mon Sep 11 22:18:04 2017 94.254.148.82:35208 peer info: IV_LZ4v2=1
Mon Sep 11 22:18:04 2017 94.254.148.82:35208 peer info: IV_LZO=1
Mon Sep 11 22:18:04 2017 94.254.148.82:35208 peer info: IV_COMP_STUB=1
Mon Sep 11 22:18:04 2017 94.254.148.82:35208 peer info: IV_COMP_STUBv2=1
Mon Sep 11 22:18:04 2017 94.254.148.82:35208 peer info: IV_TCPNL=1
Mon Sep 11 22:18:04 2017 94.254.148.82:35208 peer info: IV_GUI_VER=OpenVPN_GUI_11
Mon Sep 11 22:18:04 2017 94.254.148.82:35208 Control Channel: TLSv1.2, cipher TLSv1/SSLv3 ECDHE-RSA-AES256-GCM-SHA384, 2048 bit RSA
Mon Sep 11 22:18:04 2017 94.254.148.82:35208 [Adrian-ASUS] Peer Connection Initiated with [AF_INET]94.254.148.82:35208
Mon Sep 11 22:18:04 2017 Adrian-ASUS/94.254.148.82:35208 MULTI_sva: pool returned IPv4=10.8.0.6, IPv6=(Not enabled)
Mon Sep 11 22:18:04 2017 Adrian-ASUS/94.254.148.82:35208 MULTI: Learn: 10.8.0.6 -> Adrian-ASUS/94.254.148.82:35208
Mon Sep 11 22:18:04 2017 Adrian-ASUS/94.254.148.82:35208 MULTI: primary virtual IP for Adrian-ASUS/94.254.148.82:35208: 10.8.0.6
Mon Sep 11 22:18:05 2017 Adrian-ASUS/94.254.148.82:35208 PUSH: Received control message: 'PUSH_REQUEST'
Mon Sep 11 22:18:05 2017 Adrian-ASUS/94.254.148.82:35208 SENT CONTROL [Adrian-ASUS]: 'PUSH_REPLY,comp_lzo adaptive,route 192.168.2.0 255.255.255.0,redirect-gateway def1,dhcp-option WINS 192.168.2.1,route 10.8.0.0 255.255.255.0,topology net30,ping 10,ping-restart 120,ifconfig 10.8.0.6 10.8.0.5,peer-id 0,cipher AES-256-GCM' (status=1)
Mon Sep 11 22:18:05 2017 Adrian-ASUS/94.254.148.82:35208 Data Channel: using negotiated cipher 'AES-256-GCM'
Mon Sep 11 22:18:05 2017 Adrian-ASUS/94.254.148.82:35208 Data Channel Encrypt: Cipher 'AES-256-GCM' initialized with 256 bit key
Mon Sep 11 22:18:05 2017 Adrian-ASUS/94.254.148.82:35208 Data Channel Decrypt: Cipher 'AES-256-GCM' initialized with 256 bit key
Pomoże mi ktoś odnaleźć problem?
Konfigurowane według tego poradnika: http://eko.one.pl/?p=openwrt-openvpntun