Mar_w, Khain,
część problemów wynikała z tego, że dodałem do konfiga linijki "na później", które wydawało mi się, że "zakomentowałem" znakiem "#", jednak klient je interpretował...
ad.1)
mar_w nigdzie mi nie kazałeś, to była moja "inwencja":) Poprawiłem w kliencie i wpisałem aby wskazywało plik na dysku klienta.
ad.2)
Comon name to dudi, nazwa pliku dudi.
ad.3)
usunąłem chwilowo tę opcję z konfiga na serwerze i kliencie.
ad.4)
Tak, jest zrobione przekierowanie:)
Log z klienta po poprawkach, łączę się z innej sieci niż docelowa:
Sun Dec 31 19:11:30 2017 OpenVPN 2.4.4 x86_64-w64-mingw32 [SSL (OpenSSL)] [LZO] [LZ4] [PKCS11] [AEAD] built on Sep 26 2017
Sun Dec 31 19:11:30 2017 Windows version 6.2 (Windows 8 or greater) 64bit
Sun Dec 31 19:11:30 2017 library versions: OpenSSL 1.0.2l 25 May 2017, LZO 2.10
Enter Management Password:
Sun Dec 31 19:11:30 2017 MANAGEMENT: TCP Socket listening on [AF_INET]127.0.0.1:25341
Sun Dec 31 19:11:30 2017 Need hold release from management interface, waiting...
Sun Dec 31 19:11:30 2017 MANAGEMENT: Client connected from [AF_INET]127.0.0.1:25341
Sun Dec 31 19:11:31 2017 MANAGEMENT: CMD 'state on'
Sun Dec 31 19:11:31 2017 MANAGEMENT: CMD 'log all on'
Sun Dec 31 19:11:31 2017 MANAGEMENT: CMD 'echo all on'
Sun Dec 31 19:11:31 2017 MANAGEMENT: CMD 'hold off'
Sun Dec 31 19:11:31 2017 MANAGEMENT: CMD 'hold release'
Sun Dec 31 19:11:31 2017 Outgoing Control Channel Authentication: Using 160 bit message hash 'SHA1' for HMAC authentication
Sun Dec 31 19:11:31 2017 Incoming Control Channel Authentication: Using 160 bit message hash 'SHA1' for HMAC authentication
Sun Dec 31 19:11:31 2017 MANAGEMENT: >STATE:1514743891,RESOLVE,,,,,,
Sun Dec 31 19:11:31 2017 TCP/UDP: Preserving recently used remote address: [AF_INET]ddns:2123
Sun Dec 31 19:11:31 2017 Socket Buffers: R=[65536->65536] S=[65536->65536]
Sun Dec 31 19:11:31 2017 UDP link local (bound): [AF_INET][undef]:1194
Sun Dec 31 19:11:31 2017 UDP link remote: [AF_INET]ddns:2123
Sun Dec 31 19:11:31 2017 MANAGEMENT: >STATE:1514743891,WAIT,,,,,,
Sun Dec 31 19:11:31 2017 MANAGEMENT: >STATE:1514743891,AUTH,,,,,,
Sun Dec 31 19:11:31 2017 TLS: Initial packet from [AF_INET]ddns:2123, sid=0322b01e acc30312
Sun Dec 31 19:11:32 2017 VERIFY OK: depth=1, C=PL, ST=MA, L=Warsaw, O=FAM, OU=Home, CN=LEDE Server, name=Router, emailAddress=dudinr1@wp.pl
Sun Dec 31 19:11:32 2017 VERIFY KU OK
Sun Dec 31 19:11:32 2017 Validating certificate extended key usage
Sun Dec 31 19:11:32 2017 ++ Certificate has EKU (str) TLS Web Server Authentication, expects TLS Web Server Authentication
Sun Dec 31 19:11:32 2017 VERIFY EKU OK
Sun Dec 31 19:11:32 2017 VERIFY OK: depth=0, C=PL, ST=MA, L=Warsaw, O=FAM, OU=Home, CN=LEDE Server, name=Router, emailAddress=dudinr1@wp.pl
Sun Dec 31 19:11:32 2017 WARNING: 'link-mtu' is used inconsistently, local='link-mtu 1541', remote='link-mtu 1557'
Sun Dec 31 19:11:32 2017 WARNING: 'cipher' is used inconsistently, local='cipher BF-CBC', remote='cipher AES-256-CBC'
Sun Dec 31 19:11:32 2017 WARNING: 'keysize' is used inconsistently, local='keysize 128', remote='keysize 256'
Sun Dec 31 19:11:32 2017 Control Channel: TLSv1.2, cipher TLSv1/SSLv3 ECDHE-RSA-AES256-GCM-SHA384, 2048 bit RSA
Sun Dec 31 19:11:32 2017 [LEDE Server] Peer Connection Initiated with [AF_INET]ddns:2123
Sun Dec 31 19:11:34 2017 MANAGEMENT: >STATE:1514743894,GET_CONFIG,,,,,,
Sun Dec 31 19:11:34 2017 SENT CONTROL [LEDE Server]: 'PUSH_REQUEST' (status=1)
Sun Dec 31 19:11:34 2017 PUSH: Received control message: 'PUSH_REPLY,route-gateway 10.8.0.1,redirect-gateway def1,route 192.168.1.0 255.255.255.0 10.8.0.1,ping 25,ping-restart 180,ifconfig 10.8.0.2 255.255.255.0,peer-id 0,cipher AES-256-GCM'
Sun Dec 31 19:11:34 2017 OPTIONS IMPORT: timers and/or timeouts modified
Sun Dec 31 19:11:34 2017 OPTIONS IMPORT: --ifconfig/up options modified
Sun Dec 31 19:11:34 2017 OPTIONS IMPORT: route options modified
Sun Dec 31 19:11:34 2017 OPTIONS IMPORT: route-related options modified
Sun Dec 31 19:11:34 2017 OPTIONS IMPORT: peer-id set
Sun Dec 31 19:11:34 2017 OPTIONS IMPORT: adjusting link_mtu to 1624
Sun Dec 31 19:11:34 2017 OPTIONS IMPORT: data channel crypto options modified
Sun Dec 31 19:11:34 2017 Data Channel: using negotiated cipher 'AES-256-GCM'
Sun Dec 31 19:11:34 2017 Outgoing Data Channel: Cipher 'AES-256-GCM' initialized with 256 bit key
Sun Dec 31 19:11:34 2017 Incoming Data Channel: Cipher 'AES-256-GCM' initialized with 256 bit key
Sun Dec 31 19:11:34 2017 WARNING: Since you are using --dev tun with a point-to-point topology, the second argument to --ifconfig must be an IP address. You are using something (255.255.255.0) that looks more like a netmask. (silence this warning with --ifconfig-nowarn)
Sun Dec 31 19:11:34 2017 MANAGEMENT: Client disconnected
Sun Dec 31 19:11:34 2017 There is a problem in your selection of --ifconfig endpoints [local=10.8.0.2, remote=255.255.255.0]. The local and remote VPN endpoints must exist within the same 255.255.255.252 subnet. This is a limitation of --dev tun when used with the TAP-WIN32 driver. Try 'openvpn --show-valid-subnets' option for more info.
Sun Dec 31 19:11:34 2017 Exiting due to fatal error
*"You are using something (255.255.255.0) that looks more like a netmask."
*"There is a problem in your selection of --ifconfig endpoints [local=10.8.0.2, remote=255.255.255.0]. The local and remote VPN endpoints must exist within the same 255.255.255.252 subnet."
W pliku /etc/openvpn/ccd/dudi, mam:
ifconfig-push 10.8.0.2 255.255.255.0
iroute 172.16.1.0 255.255.255.0