26 Listopada 2024 10:44:53
Nawigacja
· Strona Główna
· Forum

· Tomato by Shibby
· FreshTomato


Wątki na forum
Najnowsze dyskusje
· DIR868l OFW asus vs ...
· Nowe routery: UX, UC...
· [S] Asus RT-AC56U
· Szukam zaproszenia n...
· [MOD] FreshTomato-AR...
· Asus RT-AC5300 ,prob...
· archer c6 v3.20
· [S] Nighthawk R7000P...
· [S]Asus RT-AC5300 - ...
· Tanie N100 na promce...
· net z telefonu wifi+...
· Tomato - bugi/proble...
· HUAWEI z światłowodem
· Asus TUF-AX3000_V2 p...
· rt-ax88upro częste ...
· [Howto] Xpenology na...
· Jaki router pod Open...
· Ruter z tomato
· Czy to jeszcze NAS?
· RT AC66U B1
Najpopularniejsze obecnie wątki
· DIR868l OFW asus ... [11]
· Nowe routery: UX,... [0]
· [S] Asus RT-AC56U [0]
Ankieta
Jaki procesor posiada twój router?

Broadcom MIPSEL
Broadcom MIPSEL
36% [151 głosów]

Broadcom ARM
Broadcom ARM
52% [219 głosów]

Atheros
Atheros
5% [22 głosów]

Marvell
Marvell
1% [4 głosów]

Ralink
Ralink
1% [3 głosów]

Intel/AMD/VIA
Intel/AMD/VIA
1% [5 głosów]

Żaden z powyższych
Żaden z powyższych
4% [15 głosów]

Ogółem głosów: 419
Musisz zalogować się, aby móc zagłosować.
Rozpoczęto: 02/02/2015 09:38
Twoje IP
3.141.47.163
Zobacz wątek
OpenLinksys » :: OPROGRAMOWANIE :: » Tomato - firmware
 Drukuj wątek
Problem z OpenVPN - nie włącza się
Fifiel
Witam. Tak jak w temacie. Mam skonfigurowanego OpenVPN, klucze wygenerowane, wklejone do OpenVPN, klikam Uruchom i... Mieli, mieli i nie włącza się, status serwera nie został odczytany poprawnie lub serwer jest wyłączony. Czy ktoś mi pomoże?Sad
 
Dworniok
Z tego co mi się wydaje, musisz połączyć się klientem OpenVPN do serwera, aby pokazał się status.

Zmienił Ci się przycisk "uruchom teraz" na "zatrzymaj"? (nie wiem czy tak to jest tłumaczone bo mam ang. wersje Tomato).
 
Fifiel
No właśnie, że jest cały czas uruchom teraz :/ To jest ten problem...Sad
 
khain
Uruchom serwer i zobacz logi, być może masz jakiś zły wpis w pliku konfiguracyjnym
TP-LINK TL-WDR3600 @ Openwrt - 300/20Mbps
HP ProLiant DL360e Gen8 @ ESXi 7.0.1:2 x Intel Xeon CPU E5-2450L @ 1.80GHz, 160GB RAM ECC, 2x 1TB SSD
ASRock J4205-ITX @ Debian 11 16BG RAM, 2x 1TB SSD, 1x 1TB HDD
 
Fifiel
Jun 17 12:22:47 unknown user.info kernel: tun: Universal TUN/TAP device driver, 1.6
Jun 17 12:22:47 unknown user.info kernel: tun: (C) 1999-2004 Max Krasnyansky
Jun 17 12:22:47 unknown user.info kernel: device tap21 entered promiscuous mode
Jun 17 12:22:47 unknown user.info kernel: br0: topology change detected, propagating
Jun 17 12:22:47 unknown user.info kernel: br0: port 3(tap21) entering forwarding state
Jun 17 12:22:47 unknown daemon.notice openvpn[11236]: OpenVPN 2.3.0 mipsel-unknown-linux-gnu [SSL (OpenSSL)] [LZO] [EPOLL] [MH] [IPv6] built on Mar 27 2013
Jun 17 12:22:47 unknown daemon.warn openvpn[11236]: NOTE: when bridging your LAN adapter with the TAP adapter, note that the new bridge adapter will often take on its own IP address that is different from what the LAN adapter was previously set to
Jun 17 12:22:47 unknown daemon.warn openvpn[11236]: NOTE: OpenVPN 2.1 requires '--script-security 2' or higher to call user-defined scripts or executables
Jun 17 12:22:47 unknown daemon.err openvpn[11236]: Cannot load DH parameters from dh.pem: error:0906D06C:lib(9):func(109):reason(108)
Jun 17 12:22:47 unknown daemon.notice openvpn[11236]: Exiting due to fatal error

To są logi... Podpowiecie mi co jest nie tak? Z moich spostrzeżeń to chyba chodzi o DH, czyli o ten certyfikat...


Jak kliknełem drugi raz to wywaliło takie logi:

Jun 17 12:27:28 unknown user.info init[1]: VPN_LOG_ERROR: 603: Adding tunnel interface to bridge failed...
Jun 17 12:27:29 unknown user.info kernel: br0: port 3(tap21) entering disabled state
Jun 17 12:27:29 unknown user.info kernel: br0: port 3(tap21) entering disabled state
 
shibby
wygeneruj jeszcze raz certyfikat DH. Jeżeli masz optware i pełną paczkę openssl zainstalowaną to możesz to zrobić z poziomu routera komendą:
openssl dHParam -outform PEM -out dHParam.pem 1024
Router: Unifi Cloud Gateway Max
Switch: Netgear MS510TXPP
Switch: Unifi USW-Flex-Mini - szt. 2
Wi-Fi: Unifi U6-Lite - szt. 2
Proxmox VE: i5-13400T, 64GB RAM, 2x 512GB NVMe, 3x 2TB SSD, Intel X710-DA2 SFP+
VM #1: Synology SA6400
VM #2: Debian, WWW
VM #3: Home Assistant OS
 
Fifiel
Nie wiem czy mam optware, instalowałem Twoje tomato AIO... Nie jestem biegły w tomato więc prosiłbym o podpowiedź gdzie to sprawdzić.
 
shibby
optware to możliwość instalowania dodatkowych paczek. Jeżeli nie wiesz o czym mówię, to znaczy, że nie instalowałeś Wink

Możesz to zrobić. Potrzebujesz jedynie wolną partycję min 2GB, którą podmontujesz pod katalog /opt. A później to już dalej wg instrukcji w tutorialach Smile

No ale to mniejsza o to. Wygeneruj DH używając skryptu ./build-dh spod Windowsa. I pamiętaj, że musisz cały certyfikat (od BEGIN do END) umieścić w polu w tomato.
Router: Unifi Cloud Gateway Max
Switch: Netgear MS510TXPP
Switch: Unifi USW-Flex-Mini - szt. 2
Wi-Fi: Unifi U6-Lite - szt. 2
Proxmox VE: i5-13400T, 64GB RAM, 2x 512GB NVMe, 3x 2TB SSD, Intel X710-DA2 SFP+
VM #1: Synology SA6400
VM #2: Debian, WWW
VM #3: Home Assistant OS
 
Fifiel
W końcuuuuuu. Super, serwer włączył się i działa, kwestia wytestowania czy połączenie działa bo z mojej sieci do mojej sieci VPNem nie da się połączyć wywala błędy. Na PPTP tak miałem, że nie umiałem się połączyć, a z innej sieci łączył się bez problemu tyle, ze na PPTP nie widziałem nic z sieci nie pingało się nawet:/

UWAGA DLA PRZYSZŁYCH USERÓW:

kopiuje się od

-----BEGIN DH PARAMETERS-----

do

-----END DH PARAMETERS-----

i tak dla każdego certyfikatu, czy klucza servera, ale po ostatnim myślniku nie może być spacji ani entera ponieważ server nie odpali...

P.S. Dzięki shibby, bez Twoich podpowiedzi męczył bym się dalej z tym albo olałbym to i męczył się latając z jednej miejscowości do drugiej lub dzwoniąc co chwilę aby podawali mi konkretne dane z servera...

Połączony z 18 czerwiec 2013 13:05:23:
Dobra przetestowane i... Nie łączy się poniżzej logi:

Cytat

Tue Jun 18 13:02:14 2013 us=953000 Current Parameter Settings:
Tue Jun 18 13:02:14 2013 us=953000 config = 'client.ovpn'
Tue Jun 18 13:02:14 2013 us=953000 mode = 0
Tue Jun 18 13:02:14 2013 us=953000 show_ciphers = DISABLED
Tue Jun 18 13:02:14 2013 us=953000 show_digests = DISABLED
Tue Jun 18 13:02:14 2013 us=953000 show_engines = DISABLED
Tue Jun 18 13:02:14 2013 us=953000 genkey = DISABLED
Tue Jun 18 13:02:14 2013 us=953000 key_pass_file = '[UNDEF]'
Tue Jun 18 13:02:14 2013 us=953000 show_tls_ciphers = DISABLED
Tue Jun 18 13:02:14 2013 us=953000 Connection profiles [default]:
Tue Jun 18 13:02:14 2013 us=953000 proto = tcp-client
Tue Jun 18 13:02:14 2013 us=953000 local = '[UNDEF]'
Tue Jun 18 13:02:14 2013 us=953000 local_port = 0
Tue Jun 18 13:02:14 2013 us=953000 remote = '188.137.67.90'
Tue Jun 18 13:02:14 2013 us=953000 remote_port = 1194
Tue Jun 18 13:02:14 2013 us=953000 remote_float = DISABLED
Tue Jun 18 13:02:14 2013 us=953000 bind_defined = DISABLED
Tue Jun 18 13:02:14 2013 us=953000 bind_local = DISABLED
Tue Jun 18 13:02:14 2013 us=953000 connect_retry_seconds = 5
Tue Jun 18 13:02:14 2013 us=953000 connect_timeout = 10
Tue Jun 18 13:02:14 2013 us=953000 connect_retry_max = 0
Tue Jun 18 13:02:14 2013 us=953000 socks_proxy_server = '[UNDEF]'
Tue Jun 18 13:02:14 2013 us=953000 socks_proxy_port = 0
Tue Jun 18 13:02:14 2013 us=953000 socks_proxy_retry = DISABLED
Tue Jun 18 13:02:14 2013 us=953000 Connection profiles END
Tue Jun 18 13:02:14 2013 us=953000 remote_random = DISABLED
Tue Jun 18 13:02:14 2013 us=953000 ipchange = '[UNDEF]'
Tue Jun 18 13:02:14 2013 us=953000 dev = 'tun'
Tue Jun 18 13:02:14 2013 us=953000 dev_type = '[UNDEF]'
Tue Jun 18 13:02:14 2013 us=953000 dev_node = '[UNDEF]'
Tue Jun 18 13:02:14 2013 us=953000 lladdr = '[UNDEF]'
Tue Jun 18 13:02:14 2013 us=953000 topology = 1
Tue Jun 18 13:02:14 2013 us=953000 tun_ipv6 = DISABLED
Tue Jun 18 13:02:14 2013 us=953000 ifconfig_local = '[UNDEF]'
Tue Jun 18 13:02:14 2013 us=953000 ifconfig_remote_netmask = '[UNDEF]'
Tue Jun 18 13:02:14 2013 us=953000 ifconfig_noexec = DISABLED
Tue Jun 18 13:02:14 2013 us=953000 ifconfig_nowarn = DISABLED
Tue Jun 18 13:02:14 2013 us=953000 shaper = 0
Tue Jun 18 13:02:14 2013 us=953000 tun_mtu = 1500
Tue Jun 18 13:02:14 2013 us=953000 tun_mtu_defined = ENABLED
Tue Jun 18 13:02:14 2013 us=953000 link_mtu = 1500
Tue Jun 18 13:02:14 2013 us=953000 link_mtu_defined = DISABLED
Tue Jun 18 13:02:14 2013 us=953000 tun_mtu_extra = 0
Tue Jun 18 13:02:14 2013 us=953000 tun_mtu_extra_defined = DISABLED
Tue Jun 18 13:02:14 2013 us=953000 fragment = 0
Tue Jun 18 13:02:14 2013 us=953000 mtu_discover_type = -1
Tue Jun 18 13:02:14 2013 us=953000 mtu_test = 0
Tue Jun 18 13:02:14 2013 us=953000 mlock = DISABLED
Tue Jun 18 13:02:14 2013 us=953000 keepalive_ping = 0
Tue Jun 18 13:02:14 2013 us=953000 keepalive_timeout = 0
Tue Jun 18 13:02:14 2013 us=953000 inactivity_timeout = 0
Tue Jun 18 13:02:14 2013 us=953000 ping_send_timeout = 0
Tue Jun 18 13:02:14 2013 us=953000 ping_rec_timeout = 0
Tue Jun 18 13:02:14 2013 us=953000 ping_rec_timeout_action = 0
Tue Jun 18 13:02:14 2013 us=953000 ping_timer_remote = DISABLED
Tue Jun 18 13:02:14 2013 us=953000 remap_sigusr1 = 0
Tue Jun 18 13:02:14 2013 us=953000 explicit_exit_notification = 0
Tue Jun 18 13:02:14 2013 us=953000 persist_tun = ENABLED
Tue Jun 18 13:02:14 2013 us=953000 persist_local_ip = DISABLED
Tue Jun 18 13:02:14 2013 us=953000 persist_remote_ip = DISABLED
Tue Jun 18 13:02:14 2013 us=953000 persist_key = ENABLED
Tue Jun 18 13:02:14 2013 us=953000 mssfix = 1450
Tue Jun 18 13:02:14 2013 us=953000 resolve_retry_seconds = 1000000000
Tue Jun 18 13:02:14 2013 us=953000 username = '[UNDEF]'
Tue Jun 18 13:02:14 2013 us=953000 groupname = '[UNDEF]'
Tue Jun 18 13:02:14 2013 us=953000 chroot_dir = '[UNDEF]'
Tue Jun 18 13:02:14 2013 us=953000 cd_dir = '[UNDEF]'
Tue Jun 18 13:02:14 2013 us=953000 writepid = '[UNDEF]'
Tue Jun 18 13:02:15 2013 us=187000 up_script = '[UNDEF]'
Tue Jun 18 13:02:15 2013 us=187000 down_script = '[UNDEF]'
Tue Jun 18 13:02:15 2013 us=187000 down_pre = DISABLED
Tue Jun 18 13:02:15 2013 us=187000 up_restart = DISABLED
Tue Jun 18 13:02:15 2013 us=187000 up_delay = DISABLED
Tue Jun 18 13:02:15 2013 us=187000 daemon = DISABLED
Tue Jun 18 13:02:15 2013 us=187000 inetd = 0
Tue Jun 18 13:02:15 2013 us=187000 log = DISABLED
Tue Jun 18 13:02:15 2013 us=187000 suppress_timestamps = DISABLED
Tue Jun 18 13:02:15 2013 us=187000 nice = 0
Tue Jun 18 13:02:15 2013 us=187000 verbosity = 4
Tue Jun 18 13:02:15 2013 us=187000 mute = 0
Tue Jun 18 13:02:15 2013 us=187000 gremlin = 0
Tue Jun 18 13:02:15 2013 us=187000 status_file = '[UNDEF]'
Tue Jun 18 13:02:15 2013 us=187000 status_file_version = 1
Tue Jun 18 13:02:15 2013 us=187000 status_file_update_freq = 60
Tue Jun 18 13:02:15 2013 us=187000 occ = ENABLED
Tue Jun 18 13:02:15 2013 us=187000 rcvbuf = 0
Tue Jun 18 13:02:15 2013 us=187000 sndbuf = 0
Tue Jun 18 13:02:15 2013 us=187000 sockflags = 0
Tue Jun 18 13:02:15 2013 us=187000 fast_io = DISABLED
Tue Jun 18 13:02:15 2013 us=187000 lzo = 7
Tue Jun 18 13:02:15 2013 us=187000 route_script = '[UNDEF]'
Tue Jun 18 13:02:15 2013 us=187000 route_default_gateway = '[UNDEF]'
Tue Jun 18 13:02:15 2013 us=187000 route_default_metric = 0
Tue Jun 18 13:02:15 2013 us=187000 route_noexec = DISABLED
Tue Jun 18 13:02:15 2013 us=187000 route_delay = 5
Tue Jun 18 13:02:15 2013 us=187000 route_delay_window = 30
Tue Jun 18 13:02:15 2013 us=187000 route_delay_defined = ENABLED
Tue Jun 18 13:02:15 2013 us=187000 route_nopull = DISABLED
Tue Jun 18 13:02:15 2013 us=187000 route_gateway_via_dhcp = DISABLED
Tue Jun 18 13:02:15 2013 us=187000 max_routes = 100
Tue Jun 18 13:02:15 2013 us=187000 allow_pull_fqdn = DISABLED
Tue Jun 18 13:02:15 2013 us=187000 management_addr = '[UNDEF]'
Tue Jun 18 13:02:15 2013 us=187000 management_port = 0
Tue Jun 18 13:02:15 2013 us=203000 management_user_pass = '[UNDEF]'
Tue Jun 18 13:02:15 2013 us=203000 management_log_history_cache = 250
Tue Jun 18 13:02:15 2013 us=203000 management_echo_buffer_size = 100
Tue Jun 18 13:02:15 2013 us=203000 management_write_peer_info_file = '[UNDEF]'
Tue Jun 18 13:02:15 2013 us=203000 management_client_user = '[UNDEF]'
Tue Jun 18 13:02:15 2013 us=203000 management_client_group = '[UNDEF]'
Tue Jun 18 13:02:15 2013 us=203000 management_flags = 0
Tue Jun 18 13:02:15 2013 us=203000 shared_secret_file = '[UNDEF]'
Tue Jun 18 13:02:15 2013 us=203000 key_direction = 0
Tue Jun 18 13:02:15 2013 us=203000 ciphername_defined = ENABLED
Tue Jun 18 13:02:15 2013 us=203000 ciphername = 'AES-128-CBC'
Tue Jun 18 13:02:15 2013 us=203000 authname_defined = ENABLED
Tue Jun 18 13:02:15 2013 us=203000 authname = 'SHA1'
Tue Jun 18 13:02:15 2013 us=203000 prng_hash = 'SHA1'
Tue Jun 18 13:02:15 2013 us=203000 prng_nonce_secret_len = 16
Tue Jun 18 13:02:15 2013 us=203000 keysize = 0
Tue Jun 18 13:02:15 2013 us=218000 engine = DISABLED
Tue Jun 18 13:02:15 2013 us=218000 replay = ENABLED
Tue Jun 18 13:02:15 2013 us=218000 mute_replay_warnings = DISABLED
Tue Jun 18 13:02:15 2013 us=218000 replay_window = 64
Tue Jun 18 13:02:15 2013 us=218000 replay_time = 15
Tue Jun 18 13:02:15 2013 us=218000 packet_id_file = '[UNDEF]'
Tue Jun 18 13:02:15 2013 us=218000 use_iv = ENABLED
Tue Jun 18 13:02:15 2013 us=218000 test_crypto = DISABLED
Tue Jun 18 13:02:15 2013 us=218000 tls_server = DISABLED
Tue Jun 18 13:02:15 2013 us=218000 tls_client = ENABLED
Tue Jun 18 13:02:15 2013 us=218000 key_method = 2
Tue Jun 18 13:02:15 2013 us=218000 ca_file = 'ca.crt'
Tue Jun 18 13:02:15 2013 us=218000 ca_path = '[UNDEF]'
Tue Jun 18 13:02:15 2013 us=218000 dh_file = '[UNDEF]'
Tue Jun 18 13:02:15 2013 us=218000 cert_file = 'AF.crt'
Tue Jun 18 13:02:15 2013 us=218000 priv_key_file = 'AF.key'
Tue Jun 18 13:02:15 2013 us=218000 pkcs12_file = '[UNDEF]'
Tue Jun 18 13:02:15 2013 us=234000 cryptoapi_cert = '[UNDEF]'
Tue Jun 18 13:02:15 2013 us=234000 cipher_list = '[UNDEF]'
Tue Jun 18 13:02:15 2013 us=234000 tls_verify = '[UNDEF]'
Tue Jun 18 13:02:15 2013 us=234000 tls_remote = '[UNDEF]'
Tue Jun 18 13:02:15 2013 us=234000 crl_file = '[UNDEF]'
Tue Jun 18 13:02:15 2013 us=234000 ns_cert_type = 64
Tue Jun 18 13:02:15 2013 us=234000 remote_cert_ku[i] = 0
Tue Jun 18 13:02:15 2013 us=234000 remote_cert_ku[i] = 0
Tue Jun 18 13:02:15 2013 us=234000 remote_cert_ku[i] = 0
Tue Jun 18 13:02:15 2013 us=234000 remote_cert_ku[i] = 0
Tue Jun 18 13:02:15 2013 us=234000 remote_cert_ku[i] = 0
Tue Jun 18 13:02:15 2013 us=234000 remote_cert_ku[i] = 0
Tue Jun 18 13:02:15 2013 us=234000 remote_cert_ku[i] = 0
Tue Jun 18 13:02:15 2013 us=234000 remote_cert_ku[i] = 0
Tue Jun 18 13:02:15 2013 us=234000 remote_cert_ku[i] = 0
Tue Jun 18 13:02:15 2013 us=234000 remote_cert_ku[i] = 0
Tue Jun 18 13:02:15 2013 us=234000 remote_cert_ku[i] = 0
Tue Jun 18 13:02:15 2013 us=250000 remote_cert_ku[i] = 0
Tue Jun 18 13:02:15 2013 us=250000 remote_cert_ku[i] = 0
Tue Jun 18 13:02:15 2013 us=250000 remote_cert_ku[i] = 0
Tue Jun 18 13:02:15 2013 us=250000 remote_cert_ku[i] = 0
Tue Jun 18 13:02:15 2013 us=250000 remote_cert_ku[i] = 0
Tue Jun 18 13:02:15 2013 us=250000 remote_cert_eku = '[UNDEF]'
Tue Jun 18 13:02:15 2013 us=250000 tls_timeout = 2
Tue Jun 18 13:02:15 2013 us=250000 renegotiate_bytes = 0
Tue Jun 18 13:02:15 2013 us=250000 renegotiate_packets = 0
Tue Jun 18 13:02:15 2013 us=250000 renegotiate_seconds = 3600
Tue Jun 18 13:02:15 2013 us=250000 handshake_window = 60
Tue Jun 18 13:02:15 2013 us=250000 transition_window = 3600
Tue Jun 18 13:02:15 2013 us=250000 single_session = DISABLED
Tue Jun 18 13:02:15 2013 us=250000 push_peer_info = DISABLED
Tue Jun 18 13:02:15 2013 us=250000 tls_exit = DISABLED
Tue Jun 18 13:02:15 2013 us=250000 tls_auth_file = '[UNDEF]'
Tue Jun 18 13:02:15 2013 us=250000 pkcs11_protected_authentication = DISABLED
Tue Jun 18 13:02:15 2013 us=250000 pkcs11_protected_authentication = DISABLED
Tue Jun 18 13:02:15 2013 us=250000 pkcs11_protected_authentication = DISABLED
Tue Jun 18 13:02:15 2013 us=250000 pkcs11_protected_authentication = DISABLED
Tue Jun 18 13:02:15 2013 us=250000 pkcs11_protected_authentication = DISABLED
Tue Jun 18 13:02:15 2013 us=250000 pkcs11_protected_authentication = DISABLED
Tue Jun 18 13:02:15 2013 us=250000 pkcs11_protected_authentication = DISABLED
Tue Jun 18 13:02:15 2013 us=250000 pkcs11_protected_authentication = DISABLED
Tue Jun 18 13:02:15 2013 us=250000 pkcs11_protected_authentication = DISABLED
Tue Jun 18 13:02:15 2013 us=250000 pkcs11_protected_authentication = DISABLED
Tue Jun 18 13:02:15 2013 us=250000 pkcs11_protected_authentication = DISABLED
Tue Jun 18 13:02:15 2013 us=250000 pkcs11_protected_authentication = DISABLED
Tue Jun 18 13:02:15 2013 us=250000 pkcs11_protected_authentication = DISABLED
Tue Jun 18 13:02:15 2013 us=265000 pkcs11_protected_authentication = DISABLED
Tue Jun 18 13:02:15 2013 us=265000 pkcs11_protected_authentication = DISABLED
Tue Jun 18 13:02:15 2013 us=265000 pkcs11_protected_authentication = DISABLED
Tue Jun 18 13:02:15 2013 us=265000 pkcs11_private_mode = 00000000
Tue Jun 18 13:02:15 2013 us=265000 pkcs11_private_mode = 00000000
Tue Jun 18 13:02:15 2013 us=265000 pkcs11_private_mode = 00000000
Tue Jun 18 13:02:15 2013 us=265000 pkcs11_private_mode = 00000000
Tue Jun 18 13:02:15 2013 us=265000 pkcs11_private_mode = 00000000
Tue Jun 18 13:02:15 2013 us=265000 pkcs11_private_mode = 00000000
Tue Jun 18 13:02:15 2013 us=265000 pkcs11_private_mode = 00000000
Tue Jun 18 13:02:15 2013 us=265000 pkcs11_private_mode = 00000000
Tue Jun 18 13:02:15 2013 us=265000 pkcs11_private_mode = 00000000
Tue Jun 18 13:02:15 2013 us=265000 pkcs11_private_mode = 00000000
Tue Jun 18 13:02:15 2013 us=265000 pkcs11_private_mode = 00000000
Tue Jun 18 13:02:15 2013 us=281000 pkcs11_private_mode = 00000000
Tue Jun 18 13:02:15 2013 us=281000 pkcs11_private_mode = 00000000
Tue Jun 18 13:02:15 2013 us=281000 pkcs11_private_mode = 00000000
Tue Jun 18 13:02:15 2013 us=281000 pkcs11_private_mode = 00000000
Tue Jun 18 13:02:15 2013 us=281000 pkcs11_private_mode = 00000000
Tue Jun 18 13:02:15 2013 us=281000 pkcs11_cert_private = DISABLED
Tue Jun 18 13:02:15 2013 us=281000 pkcs11_cert_private = DISABLED
Tue Jun 18 13:02:15 2013 us=281000 pkcs11_cert_private = DISABLED
Tue Jun 18 13:02:15 2013 us=281000 pkcs11_cert_private = DISABLED
Tue Jun 18 13:02:15 2013 us=281000 pkcs11_cert_private = DISABLED
Tue Jun 18 13:02:15 2013 us=281000 pkcs11_cert_private = DISABLED
Tue Jun 18 13:02:15 2013 us=281000 pkcs11_cert_private = DISABLED
Tue Jun 18 13:02:15 2013 us=281000 pkcs11_cert_private = DISABLED
Tue Jun 18 13:02:15 2013 us=281000 pkcs11_cert_private = DISABLED
Tue Jun 18 13:02:15 2013 us=296000 pkcs11_cert_private = DISABLED
Tue Jun 18 13:02:15 2013 us=296000 pkcs11_cert_private = DISABLED
Tue Jun 18 13:02:15 2013 us=296000 pkcs11_cert_private = DISABLED
Tue Jun 18 13:02:15 2013 us=296000 pkcs11_cert_private = DISABLED
Tue Jun 18 13:02:15 2013 us=296000 pkcs11_cert_private = DISABLED
Tue Jun 18 13:02:15 2013 us=296000 pkcs11_cert_private = DISABLED
Tue Jun 18 13:02:15 2013 us=296000 pkcs11_cert_private = DISABLED
Tue Jun 18 13:02:15 2013 us=296000 pkcs11_pin_cache_period = -1
Tue Jun 18 13:02:15 2013 us=296000 pkcs11_id = '[UNDEF]'
Tue Jun 18 13:02:15 2013 us=296000 pkcs11_id_management = DISABLED
Tue Jun 18 13:02:15 2013 us=296000 server_network = 0.0.0.0
Tue Jun 18 13:02:15 2013 us=296000 server_netmask = 0.0.0.0
Tue Jun 18 13:02:15 2013 us=296000 server_bridge_ip = 0.0.0.0
Tue Jun 18 13:02:15 2013 us=296000 server_bridge_netmask = 0.0.0.0
Tue Jun 18 13:02:15 2013 us=312000 server_bridge_pool_start = 0.0.0.0
Tue Jun 18 13:02:15 2013 us=312000 server_bridge_pool_end = 0.0.0.0
Tue Jun 18 13:02:15 2013 us=312000 ifconfig_pool_defined = DISABLED
Tue Jun 18 13:02:15 2013 us=312000 ifconfig_pool_start = 0.0.0.0
Tue Jun 18 13:02:15 2013 us=312000 ifconfig_pool_end = 0.0.0.0
Tue Jun 18 13:02:15 2013 us=312000 ifconfig_pool_netmask = 0.0.0.0
Tue Jun 18 13:02:15 2013 us=312000 ifconfig_pool_persist_filename = '[UNDEF]'
Tue Jun 18 13:02:15 2013 us=312000 ifconfig_pool_persist_refresh_freq = 600
Tue Jun 18 13:02:15 2013 us=312000 n_bcast_buf = 256
Tue Jun 18 13:02:15 2013 us=312000 tcp_queue_limit = 64
Tue Jun 18 13:02:15 2013 us=312000 real_hash_size = 256
Tue Jun 18 13:02:15 2013 us=312000 virtual_hash_size = 256
Tue Jun 18 13:02:15 2013 us=312000 client_connect_script = '[UNDEF]'
Tue Jun 18 13:02:15 2013 us=312000 learn_address_script = '[UNDEF]'
Tue Jun 18 13:02:15 2013 us=312000 client_disconnect_script = '[UNDEF]'
Tue Jun 18 13:02:15 2013 us=312000 client_config_dir = '[UNDEF]'
Tue Jun 18 13:02:15 2013 us=312000 ccd_exclusive = DISABLED
Tue Jun 18 13:02:15 2013 us=312000 tmp_dir = '[UNDEF]'
Tue Jun 18 13:02:15 2013 us=312000 push_ifconfig_defined = DISABLED
Tue Jun 18 13:02:15 2013 us=312000 push_ifconfig_local = 0.0.0.0
Tue Jun 18 13:02:15 2013 us=312000 push_ifconfig_remote_netmask = 0.0.0.0
Tue Jun 18 13:02:15 2013 us=312000 enable_c2c = DISABLED
Tue Jun 18 13:02:15 2013 us=312000 duplicate_cn = DISABLED
Tue Jun 18 13:02:15 2013 us=312000 cf_max = 0
Tue Jun 18 13:02:15 2013 us=312000 cf_per = 0
Tue Jun 18 13:02:15 2013 us=312000 max_clients = 1024
Tue Jun 18 13:02:15 2013 us=312000 max_routes_per_client = 256
Tue Jun 18 13:02:15 2013 us=312000 auth_user_pass_verify_script = '[UNDEF]'
Tue Jun 18 13:02:15 2013 us=312000 auth_user_pass_verify_script_via_file = DISABLED
Tue Jun 18 13:02:15 2013 us=312000 ssl_flags = 0
Tue Jun 18 13:02:15 2013 us=328000 client = ENABLED
Tue Jun 18 13:02:15 2013 us=328000 pull = ENABLED
Tue Jun 18 13:02:15 2013 us=328000 auth_user_pass_file = '[UNDEF]'
Tue Jun 18 13:02:15 2013 us=328000 show_net_up = DISABLED
Tue Jun 18 13:02:15 2013 us=328000 route_method = 0
Tue Jun 18 13:02:15 2013 us=328000 ip_win32_defined = DISABLED
Tue Jun 18 13:02:15 2013 us=328000 ip_win32_type = 3
Tue Jun 18 13:02:15 2013 us=328000 dhcp_masq_offset = 0
Tue Jun 18 13:02:15 2013 us=328000 dhcp_lease_time = 31536000
Tue Jun 18 13:02:15 2013 us=328000 tap_sleep = 0
Tue Jun 18 13:02:15 2013 us=328000 dhcp_options = DISABLED
Tue Jun 18 13:02:15 2013 us=328000 dhcp_renew = DISABLED
Tue Jun 18 13:02:15 2013 us=328000 dhcp_pre_release = DISABLED
Tue Jun 18 13:02:15 2013 us=328000 dhcp_release = DISABLED
Tue Jun 18 13:02:15 2013 us=328000 domain = '[UNDEF]'
Tue Jun 18 13:02:15 2013 us=328000 netbios_scope = '[UNDEF]'
Tue Jun 18 13:02:15 2013 us=343000 netbios_node_type = 0
Tue Jun 18 13:02:15 2013 us=343000 disable_nbt = DISABLED
Tue Jun 18 13:02:15 2013 us=343000 OpenVPN 2.1.4 i686-pc-mingw32 [SSL] [LZO2] [PKCS11] built on Nov 8 2010
Tue Jun 18 13:02:15 2013 us=343000 NOTE: OpenVPN 2.1 requires '--script-security 2' or higher to call user-defined scripts or executables
Tue Jun 18 13:02:15 2013 us=531000 LZO compression initialized
Tue Jun 18 13:02:15 2013 us=531000 Control Channel MTU parms [ L:1560 D:140 EF:40 EB:0 ET:0 EL:0 ]
Tue Jun 18 13:02:15 2013 us=531000 Socket Buffers: R=[65536->65536] S=[65536->65536]
Tue Jun 18 13:02:15 2013 us=531000 Data Channel MTU parms [ L:1560 D:1450 EF:60 EB:135 ET:0 EL:0 AF:3/1 ]
Tue Jun 18 13:02:15 2013 us=531000 Local Options String: 'V4,dev-type tun,link-mtu 1560,tun-mtu 1500,proto TCPv4_CLIENT,comp-lzo,cipher AES-128-CBC,auth SHA1,keysize 128,key-method 2,tls-client'
Tue Jun 18 13:02:15 2013 us=531000 Expected Remote Options String: 'V4,dev-type tun,link-mtu 1560,tun-mtu 1500,proto TCPv4_SERVER,comp-lzo,cipher AES-128-CBC,auth SHA1,keysize 128,key-method 2,tls-server'
Tue Jun 18 13:02:15 2013 us=531000 Local Options hash (VER=V4): 'bc07730e'
Tue Jun 18 13:02:15 2013 us=531000 Expected Remote Options hash (VER=V4): 'b695cb4a'
Tue Jun 18 13:02:15 2013 us=531000 Attempting to establish TCP connection with 188.137.67.90:1194
Tue Jun 18 13:02:15 2013 us=546000 TCP connection established with 188.137.67.90:1194
Tue Jun 18 13:02:15 2013 us=546000 TCPv4_CLIENT link local: [undef]
Tue Jun 18 13:02:15 2013 us=546000 TCPv4_CLIENT link remote: 188.137.67.90:1194
Tue Jun 18 13:02:15 2013 us=562000 TLS: Initial packet from 188.137.67.90:1194, sid=36e1b5c6 72c8804f
Tue Jun 18 13:02:15 2013 us=890000 VERIFY OK: depth=1, /C=PL/ST=SL/L=Rydultowy/O=eXeTe/CN=eXeTe/emailAddress=biuro@exete.pl
Tue Jun 18 13:02:15 2013 us=890000 VERIFY OK: nsCertType=SERVER
Tue Jun 18 13:02:15 2013 us=890000 VERIFY OK: depth=0, /C=PL/ST=SL/O=eXeTe/CN=server/emailAddress=biuro@exete.pl
Tue Jun 18 13:02:16 2013 us=546000 NOTE: Options consistency check may be skewed by version differences
Tue Jun 18 13:02:16 2013 us=546000 WARNING: 'version' is used inconsistently, local='version V4', remote='version V0 UNDEF'
Tue Jun 18 13:02:16 2013 us=546000 WARNING: 'dev-type' is present in local config but missing in remote config, local='dev-type tun'
Tue Jun 18 13:02:16 2013 us=546000 WARNING: 'link-mtu' is present in local config but missing in remote config, local='link-mtu 1560'
Tue Jun 18 13:02:16 2013 us=546000 WARNING: 'tun-mtu' is present in local config but missing in remote config, local='tun-mtu 1500'
Tue Jun 18 13:02:16 2013 us=546000 WARNING: 'proto' is present in local config but missing in remote config, local='proto TCPv4_SERVER'
Tue Jun 18 13:02:16 2013 us=546000 WARNING: 'comp-lzo' is present in local config but missing in remote config, local='comp-lzo'
Tue Jun 18 13:02:16 2013 us=546000 WARNING: 'cipher' is present in local config but missing in remote config, local='cipher AES-128-CBC'
Tue Jun 18 13:02:16 2013 us=546000 WARNING: 'auth' is present in local config but missing in remote config, local='auth SHA1'
Tue Jun 18 13:02:16 2013 us=546000 WARNING: 'keysize' is present in local config but missing in remote config, local='keysize 128'
Tue Jun 18 13:02:16 2013 us=546000 WARNING: 'key-method' is present in local config but missing in remote config, local='key-method 2'
Tue Jun 18 13:02:16 2013 us=546000 WARNING: 'tls-server' is present in local config but missing in remote config, local='tls-server'
Tue Jun 18 13:02:16 2013 us=546000 Data Channel Encrypt: Cipher 'AES-128-CBC' initialized with 128 bit key
Tue Jun 18 13:02:16 2013 us=546000 Data Channel Encrypt: Using 160 bit message hash 'SHA1' for HMAC authentication
Tue Jun 18 13:02:16 2013 us=546000 Data Channel Decrypt: Cipher 'AES-128-CBC' initialized with 128 bit key
Tue Jun 18 13:02:16 2013 us=546000 Data Channel Decrypt: Using 160 bit message hash 'SHA1' for HMAC authentication
Tue Jun 18 13:02:16 2013 us=546000 Control Channel: TLSv1, cipher TLSv1/SSLv3 DHE-RSA-AES256-SHA, 1024 bit RSA
Tue Jun 18 13:02:16 2013 us=546000 [server] Peer Connection Initiated with 188.137.67.90:1194
Tue Jun 18 13:02:18 2013 us=250000 SENT CONTROL [server]: 'PUSH_REQUEST' (status=1)
Tue Jun 18 13:02:18 2013 us=765000 PUSH: Received control message: 'PUSH_REPLY,dhcp-option DNS 192.168.1.1,route-gateway dhcp,ping 15,ping-restart 60'
Tue Jun 18 13:02:18 2013 us=765000 OPTIONS IMPORT: timers and/or timeouts modified
Tue Jun 18 13:02:18 2013 us=765000 OPTIONS IMPORT: route-related options modified
Tue Jun 18 13:02:18 2013 us=765000 OPTIONS IMPORT: --ip-win32 and/or --dhcp-option options modified
Tue Jun 18 13:02:18 2013 us=765000 TAP-WIN32 device [Połączenie lokalne] opened: \\.\Global\{A4371C85-36DF-41F0-AFA5-1EAD84995071}.tap
Tue Jun 18 13:02:18 2013 us=765000 TAP-Win32 Driver Version 9.7
Tue Jun 18 13:02:18 2013 us=765000 TAP-Win32 MTU=1500
Tue Jun 18 13:02:18 2013 us=765000 ERROR: --dev tun also requires --ifconfig
Tue Jun 18 13:02:18 2013 us=765000 Exiting


Czy ktoś wie co go boli?Sad Robiłem wszystko wg tutoriala i nie chce się połączyćSad
Edytowany przez Fifiel dnia 18-06-2013 13:05
 
shibby
konfig klienta musi wyglądać tak:

Cytat

client
dev tun
comp-lzo
cipher none
resolv-retry infinite
mute-replay-warnings
keepalive 10 60
comp-lzo
verb 3
route-method exe
route-delay 2
proto tcp
remote
ca ca.crt
cert klient.crt
key klient.key


Ponadto w win7 i 8 musisz odpalać jako administrator (prawym, uruchom jako administrator).
Router: Unifi Cloud Gateway Max
Switch: Netgear MS510TXPP
Switch: Unifi USW-Flex-Mini - szt. 2
Wi-Fi: Unifi U6-Lite - szt. 2
Proxmox VE: i5-13400T, 64GB RAM, 2x 512GB NVMe, 3x 2TB SSD, Intel X710-DA2 SFP+
VM #1: Synology SA6400
VM #2: Debian, WWW
VM #3: Home Assistant OS
 
Fifiel
Uruchomiłem OpenVPN jako admin, zedytowałem configa na to co napisałeś Ty i... Nie działaSad

Konfiguracja:

Cytat

client
dev tun
comp-lzo
cipher AES-128-CBC
resolv-retry infinite
mute-replay-warnings
keepalive 10 60
comp-lzo
verb 3
route-method exe
route-delay 2
proto tcp
remote 188.137.67.90 1194
ca ca.crt
cert AF.crt
key AF.key



Logi:

Cytat

Tue Jun 18 13:30:17 2013 OpenVPN 2.1.4 i686-pc-mingw32 [SSL] [LZO2] [PKCS11] built on Nov 8 2010
Tue Jun 18 13:30:17 2013 WARNING: No server certificate verification method has been enabled. See http://openvpn.net/howto.html#mitm for more info.
Tue Jun 18 13:30:17 2013 NOTE: OpenVPN 2.1 requires '--script-security 2' or higher to call user-defined scripts or executables
Tue Jun 18 13:30:17 2013 LZO compression initialized
Tue Jun 18 13:30:17 2013 Control Channel MTU parms [ L:1560 D:140 EF:40 EB:0 ET:0 EL:0 ]
Tue Jun 18 13:30:17 2013 Socket Buffers: R=[65536->65536] S=[65536->65536]
Tue Jun 18 13:30:17 2013 Data Channel MTU parms [ L:1560 D:1450 EF:60 EB:135 ET:0 EL:0 AF:3/1 ]
Tue Jun 18 13:30:17 2013 Local Options hash (VER=V4): 'bc07730e'
Tue Jun 18 13:30:17 2013 Expected Remote Options hash (VER=V4): 'b695cb4a'
Tue Jun 18 13:30:17 2013 Attempting to establish TCP connection with 188.137.67.90:1194
Tue Jun 18 13:30:17 2013 TCP connection established with 188.137.67.90:1194
Tue Jun 18 13:30:17 2013 TCPv4_CLIENT link local: [undef]
Tue Jun 18 13:30:17 2013 TCPv4_CLIENT link remote: 188.137.67.90:1194
Tue Jun 18 13:30:17 2013 TLS: Initial packet from 188.137.67.90:1194, sid=f22051a3 06eba4c9
Tue Jun 18 13:30:18 2013 VERIFY OK: depth=1, /C=PL/ST=SL/L=Rydultowy/O=eXeTe/CN=eXeTe/emailAddress=biuro@exete.pl
Tue Jun 18 13:30:18 2013 VERIFY OK: depth=0, /C=PL/ST=SL/O=eXeTe/CN=server/emailAddress=biuro@exete.pl
Tue Jun 18 13:30:19 2013 Data Channel Encrypt: Cipher 'AES-128-CBC' initialized with 128 bit key
Tue Jun 18 13:30:19 2013 Data Channel Encrypt: Using 160 bit message hash 'SHA1' for HMAC authentication
Tue Jun 18 13:30:19 2013 Data Channel Decrypt: Cipher 'AES-128-CBC' initialized with 128 bit key
Tue Jun 18 13:30:19 2013 Data Channel Decrypt: Using 160 bit message hash 'SHA1' for HMAC authentication
Tue Jun 18 13:30:19 2013 Control Channel: TLSv1, cipher TLSv1/SSLv3 DHE-RSA-AES256-SHA, 1024 bit RSA
Tue Jun 18 13:30:19 2013 [server] Peer Connection Initiated with 188.137.67.90:1194
Tue Jun 18 13:30:21 2013 SENT CONTROL [server]: 'PUSH_REQUEST' (status=1)
Tue Jun 18 13:30:21 2013 PUSH: Received control message: 'PUSH_REPLY,dhcp-option DNS 192.168.1.1,route-gateway dhcp,ping 15,ping-restart 60'
Tue Jun 18 13:30:21 2013 OPTIONS IMPORT: timers and/or timeouts modified
Tue Jun 18 13:30:21 2013 OPTIONS IMPORT: route-related options modified
Tue Jun 18 13:30:21 2013 OPTIONS IMPORT: --ip-win32 and/or --dhcp-option options modified
Tue Jun 18 13:30:21 2013 TAP-WIN32 device [Połączenie lokalne] opened: \\.\Global\{A4371C85-36DF-41F0-AFA5-1EAD84995071}.tap
Tue Jun 18 13:30:21 2013 TAP-Win32 Driver Version 9.7
Tue Jun 18 13:30:21 2013 TAP-Win32 MTU=1500
Tue Jun 18 13:30:21 2013 ERROR: --dev tun also requires --ifconfig
Tue Jun 18 13:30:21 2013 Exiting


Masz jeszcze jakiś pomysł?Sad

Wcześniej miałem configa z tąd:
http://cdn.howtogeek.com/wp-content/uploads/2011/05/tomatoovpn251.png
Robiłem go razem z certyfikatami itd... wg tutoriala...
 
khain
A wrzuć jeszcze config serwera, nie masz czasem w ustawieniach serwera rodzaj połączenia TAP?
TP-LINK TL-WDR3600 @ Openwrt - 300/20Mbps
HP ProLiant DL360e Gen8 @ ESXi 7.0.1:2 x Intel Xeon CPU E5-2450L @ 1.80GHz, 160GB RAM ECC, 2x 1TB SSD
ASRock J4205-ITX @ Debian 11 16BG RAM, 2x 1TB SSD, 1x 1TB HDD
 
Fifiel
Mam na TAP bo chce żeby na VPNie było widać sieć wewnętrzną. A z tego co wyczytałem to na TUN tworzy inną podsieć, a na TAP pobiera IP z DHCP i wtedy Klient VPN jest jakby w sieci wewnętrznej.

EDIT:

Poradziłem sobie Smile

zamiast dev tun ma być dev tap0 i dziaaaałaaaaGrin jupiiiGrin
 
shibby
tap tworzy bridge czyli wszystkie broadcasty latają dobrowolnie po VPNie. Generuje to niepotrzebny ruch. TUN działa w innej podsieci ale tworzy routing miedzy podsieciami tam więc też jest wgląd do sieci wewnętrznej.
Router: Unifi Cloud Gateway Max
Switch: Netgear MS510TXPP
Switch: Unifi USW-Flex-Mini - szt. 2
Wi-Fi: Unifi U6-Lite - szt. 2
Proxmox VE: i5-13400T, 64GB RAM, 2x 512GB NVMe, 3x 2TB SSD, Intel X710-DA2 SFP+
VM #1: Synology SA6400
VM #2: Debian, WWW
VM #3: Home Assistant OS
 
Fifiel
Ale jak bede miał tun to jak wejde w siec to wyszuka mi wszystkie komputery? czy bede musial kokretne ip wpisywac aby dostac sie do zasobow danego komputera?
 
domestos007
To może ja się podepnę pod temat skonfigurowałem sobie połączenie openvpn w trybie tun wszystko pięknie ładnie się połączyło ale jest jeden problem nie widzę dysku podłączonego pod router, klientem jest Nexus 7 na androidzie i jemu przydziela adres 10.8.0.6 a routerowi 10.8.0.1 oba urządzenia widzą się między sobą tzn. mogę pingować z routera na Nexusa i vice versa ale dostępu do dysku brak, chodzi oczywiście o dostęp poprzez sambę. Jedynie co mi się udało to poprzez ftp, gdzie może tkwić błąd albo co trzeba jeszcze skonfigurować i lub gdzie dopisać regułkę ?
 
Przejdź do forum
Zaloguj
Wprowadź adres e-mail lub nazwę użytkownika

Hasło



Nie masz jeszcze konta? Zarejestruj się.

Zapomniałeś/aś hasła?
Aktualnie online
· Gości online: 78

· Użytkowników online: 1
zakk87

· Łącznie użytkowników: 24,115
· Najnowszy użytkownik: Ja
Czat
Musisz się zalogować, aby opublikować wiadomość.

Maniek91PL
06-11-2024 22:37
dzięki !Grin

maxikaaz
29-10-2024 14:27
@Maniek91PL - Administration=> Admin Access, i tam masz "Allow Wireless Access" do zaznaczenia

Maniek91PL
26-10-2024 22:07
siemka! ktoś przypomni co się ustawiało jeśli nie mogę wejść od strony wifi do tomato? od lan działa

overflow2
04-10-2024 17:34
Kupowałem Asusy n10u albo n12d1 ale nie widzę ich, chyba już nie produkują, Chodzi o coś nowego i taniego. Transfery niewielkie.

maxikaaz
04-10-2024 09:38
@overflow2 patrząc po dostępności funkcji w nowych kompilacjach, to chyba nawet WRT54G/GL jeszcze ma OpenVPN, albo jakiś odpowiednik... zależy, na jakie transfery liczysz.

overflow2
30-09-2024 20:53
Jaki aktualnie najtańszy router do tomato do openvpn?

maxikaaz
27-07-2024 15:07
@servee - na początek router do rozebrania i obejrzenia, ciężko wróżyć tak tylko po objawach

maxikaaz
27-07-2024 14:55
@servee - cały kontroler nie pada tak sobie z powodu "zbiegu okoliczności",
więc prawdopodobnie gdzieś przepięcie.

servee
25-07-2024 13:33
@maxikaaz: działało, aż pewnego pięknego dnia przestało działać. W tym dniu była też burza, ale to raczej zbieg okoliczności.

maxikaaz
25-07-2024 11:38
@servee - o ile problem jest w obrębie samych wyjść (dławiki, warystory), to naprawialne, ale jeśli w samym SoC - to nienaprawialne ze względu na koszta. A co było przyczyną?

95,848,532 unikalnych wizyt