Insanityx
Newbie | Редактировать | Профиль | Сообщение | Цитировать | Сообщить модератору Здравствуйте, помогите разобраться подымаю 3 ovpn сервер правда этот на dd-wrt столкнулся с такой проблеммой: Клиент конектится к серверу получает IP маску, но не получает шлюза по умолчанию, после конекта клиент и сервер друг друга не видят тоесть 10.10.14.1\24 не пингует 10.10.14.2\24 и на оборот. Конфиг сервера: mode server proto tcp port 1194 dev tap0 keepalive 15 60 server 10.10.14.0 255.255.255.0 push "route-gateway 10.10.14.1" verb 3 comp-lzo tls-server daemon persist-key persist-tun client-to-client duplicate-cn ca /jffs/ca.crt dh /jffs/dh1024.pem cert /jffs/*****.crt key /jffs/*****.key Конфиг клиента: client tls-client dev tap0 proto tcp remote ********* 1194 route-gateway 10.10.14.1 resolv-retry infinite nobind route-method exe route-delay 2 persist-key persist-tun comp-lzo verb 3 ca ca.crt cert buh.crt key buh.key Интерфейсы на сервере: ath0 Link encap:Ethernet HWaddr 54:E6:FC:AE:54:FA UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1 RX packets:0 errors:0 dropped:0 overruns:0 frame:0 TX packets:34288 errors:0 dropped:0 overruns:0 carrier:0 collisions:0 txqueuelen:1000 RX bytes:0 (0.0 B) TX bytes:2403735 (2.2 MiB) br0 Link encap:Ethernet HWaddr 54:E6:FC:AE:54:FA inet addr:192.168.0.1 Bcast:192.168.0.255 Mask:255.255.255.0 UP BROADCAST RUNNING PROMISC MULTICAST MTU:1500 Metric:1 RX packets:59722 errors:0 dropped:0 overruns:0 frame:0 TX packets:39683 errors:0 dropped:0 overruns:0 carrier:0 collisions:0 txqueuelen:0 RX bytes:32918583 (31.3 MiB) TX bytes:16478437 (15.7 MiB) br0:0 Link encap:Ethernet HWaddr 54:E6:FC:AE:54:FA inet addr:169.254.255.1 Bcast:169.254.255.255 Mask:255.255.0.0 UP BROADCAST RUNNING PROMISC MULTICAST MTU:1500 Metric:1 eth0 Link encap:Ethernet HWaddr 54:E6:FC:AE:54:FA UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1 RX packets:163287 errors:0 dropped:0 overruns:0 frame:0 TX packets:98970 errors:0 dropped:0 overruns:0 carrier:0 collisions:0 txqueuelen:1000 RX bytes:54942149 (52.3 MiB) TX bytes:50949361 (48.5 MiB) lo Link encap:Local Loopback inet addr:127.0.0.1 Mask:255.0.0.0 UP LOOPBACK RUNNING MULTICAST MTU:16436 Metric:1 RX packets:1 errors:0 dropped:0 overruns:0 frame:0 TX packets:1 errors:0 dropped:0 overruns:0 carrier:0 collisions:0 txqueuelen:0 RX bytes:88 (88.0 B) TX bytes:88 (88.0 B) tap0 Link encap:Ethernet HWaddr DA:1F:B7:33:FF:1F inet addr:10.10.14.1 Bcast:10.10.14.255 Mask:255.255.255.0 UP BROADCAST RUNNING PROMISC MULTICAST MTU:1500 Metric:1 RX packets:123 errors:0 dropped:0 overruns:0 frame:0 TX packets:34115 errors:0 dropped:2 overruns:0 carrier:0 collisions:0 txqueuelen:100 RX bytes:15483 (15.1 KiB) TX bytes:2374687 (2.2 MiB) vlan1 Link encap:Ethernet HWaddr 54:E6:FC:AE:54:FA UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1 RX packets:59609 errors:0 dropped:0 overruns:0 frame:0 TX packets:54283 errors:0 dropped:0 overruns:0 carrier:0 collisions:0 txqueuelen:0 RX bytes:33177948 (31.6 MiB) TX bytes:17461655 (16.6 MiB) vlan2 Link encap:Ethernet HWaddr 54:E6:FC:AE:54:FB inet addr:79.122.131.180 Bcast:79.122.131.183 Mask:255.255.255.248 UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1 RX packets:103678 errors:0 dropped:0 overruns:0 frame:0 TX packets:44687 errors:0 dropped:0 overruns:0 carrier:0 collisions:0 txqueuelen:0 RX bytes:19478183 (18.5 MiB) TX bytes:33487706 (31.9 MiB) wifi0 Link encap:Ethernet HWaddr 54:E6:FC:AE:54:FA UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1 RX packets:7 errors:0 dropped:0 overruns:0 frame:61807 TX packets:34317 errors:0 dropped:0 overruns:0 carrier:0 collisions:0 txqueuelen:1000 RX bytes:322 (322.0 B) TX bytes:3710837 (3.5 MiB) Interrupt:2 Memory:b80c0000-b8100000 Логи клиента при подключении: Sun Apr 03 16:49:06 2011 OpenVPN 2.1.4 i686-pc-mingw32 [SSL] [LZO2] [PKCS11] built on Nov 8 2010 Sun Apr 03 16:49:06 2011 WARNING: No server certificate verification method has been enabled. See http://openvpn.net/howto.html#mitm for more info. Sun Apr 03 16:49:06 2011 NOTE: OpenVPN 2.1 requires '--script-security 2' or higher to call user-defined scripts or executables Sun Apr 03 16:49:06 2011 LZO compression initialized Sun Apr 03 16:49:06 2011 Control Channel MTU parms [ L:1576 D:140 EF:40 EB:0 ET:0 EL:0 ] Sun Apr 03 16:49:06 2011 Socket Buffers: R=[8192->8192] S=[8192->8192] Sun Apr 03 16:49:06 2011 Data Channel MTU parms [ L:1576 D:1450 EF:44 EB:135 ET:32 EL:0 AF:3/1 ] Sun Apr 03 16:49:06 2011 Local Options hash (VER=V4): '31fdf004' Sun Apr 03 16:49:06 2011 Expected Remote Options hash (VER=V4): '3e6d1056' Sun Apr 03 16:49:06 2011 Attempting to establish TCP connection with 79.122.131.180:1194 Sun Apr 03 16:49:06 2011 TCP connection established with 79.122.131.180:1194 Sun Apr 03 16:49:06 2011 TCPv4_CLIENT link local: [undef] Sun Apr 03 16:49:06 2011 TCPv4_CLIENT link remote: 79.122.131.180:1194 Sun Apr 03 16:49:06 2011 TLS: Initial packet from 79.122.131.180:1194, sid=da422583 83aec517 Sun Apr 03 16:49:07 2011 VERIFY OK: depth=1, /C=RU/ST=RU/L=Omsk/O=Nagaev/CN=Nagaev/emailAddress=admin@enima.ru Sun Apr 03 16:49:07 2011 VERIFY OK: depth=0, /C=RU/ST=RU/L=Omsk/O=Nagaev/CN=Nagaev/emailAddress=admin@enima.ru Sun Apr 03 16:50:04 2011 Data Channel Encrypt: Cipher 'BF-CBC' initialized with 128 bit key Sun Apr 03 16:50:04 2011 Data Channel Encrypt: Using 160 bit message hash 'SHA1' for HMAC authentication Sun Apr 03 16:50:04 2011 Data Channel Decrypt: Cipher 'BF-CBC' initialized with 128 bit key Sun Apr 03 16:50:04 2011 Data Channel Decrypt: Using 160 bit message hash 'SHA1' for HMAC authentication Sun Apr 03 16:50:04 2011 Control Channel: TLSv1, cipher TLSv1/SSLv3 DHE-RSA-AES256-SHA, 1024 bit RSA Sun Apr 03 16:50:04 2011 [Nagaev] Peer Connection Initiated with 79.122.131.180:1194 Sun Apr 03 16:50:06 2011 SENT CONTROL [Nagaev]: 'PUSH_REQUEST' (status=1) Sun Apr 03 16:50:06 2011 PUSH: Received control message: 'PUSH_REPLY,route-gateway 10.10.14.1,route-gateway 10.10.14.1,ping 15,ping-restart 60,ifconfig 10.10.14.2 255.255.255.0' Sun Apr 03 16:50:06 2011 OPTIONS IMPORT: timers and/or timeouts modified Sun Apr 03 16:50:06 2011 OPTIONS IMPORT: --ifconfig/up options modified Sun Apr 03 16:50:06 2011 OPTIONS IMPORT: route-related options modified Sun Apr 03 16:50:06 2011 TAP-WIN32 device [raduga] opened: \\.\Global\{2704E367-EBC6-4E55-9494-E90AA908932F}.tap Sun Apr 03 16:50:06 2011 TAP-Win32 Driver Version 9.7 Sun Apr 03 16:50:06 2011 TAP-Win32 MTU=1500 Sun Apr 03 16:50:06 2011 Notified TAP-Win32 driver to set a DHCP IP/netmask of 10.10.14.2/255.255.255.0 on interface {2704E367-EBC6-4E55-9494-E90AA908932F} [DHCP-serv: 10.10.14.0, lease-time: 31536000] Sun Apr 03 16:50:06 2011 Successful ARP Flush on interface [2] {2704E367-EBC6-4E55-9494-E90AA908932F} Sun Apr 03 16:50:08 2011 TEST ROUTES: 0/0 succeeded len=-1 ret=0 a=0 u/d=down Sun Apr 03 16:50:08 2011 Route: Waiting for TUN/TAP interface to come up... Sun Apr 03 16:50:10 2011 TEST ROUTES: 0/0 succeeded len=-1 ret=1 a=0 u/d=up Sun Apr 03 16:50:10 2011 Initialization Sequence Completed С сервера лог пока дать не могу завис роутер = )) Через пару часов дам.. |