OpenVpn hjälp. Kan conecta men inte pinga.

Permalänk
Medlem

OpenVpn hjälp. Kan conecta men inte pinga.

Hej, Behöver hjälp med min openvpn instalation.
Jag har kommit så långt att jag kan conecta från min XP burk till min ubuntu server men jag kan inte pinga eller köra nån typ av trafik dvs samba ftp osv. Hur kan jag lösa detta. Lägger in mina config filer här nedan så får ni gärna komma med förslag.

Min server har lokalt ip nr 192.168.0.1 Som ni kan se i server configen så har jag satt openvpn rangen till 192.168.10.0 Vad är det jag saknar. Xp burken har ingen brandvägg.
Servern har ingen så porten ska vara öppen utan problem. Den står också rakt ut på internet utan router emellan. Om ni behöver mer info så säg till så ska jag försöka komplitera.

Xp client

client
dev tun
proto tcp
remote ***(min servers publica ip) 523
resolv-retry infinite
nobind
persist-key
persist-tun
ca "C:\\Program Files\\OpenVPN\\ubuntu\\ca.crt"
cert "C:\\Program Files\\OpenVPN\\ubuntu\\windowsklient.crt"
key "C:\\Program Files\\OpenVPN\\ubuntu\\windowsklient.key"
ns-cert-type server
tls-auth "C:\\Program Files\\OpenVPN\\ubuntu\\ta.key_1"
cipher BF-CBC
comp-lzo
verb 3

Ubuntu server

port 524
proto tcp
dev tun
ca /etc/openvpn/ca.crt
cert /etc/openvpn/eriksson25.crt
key /etc/openvpn/eriksson25.key
dh /etc/openvpn/dh1024.pem
server 192.168.10.0 255.255.255.0
ifconfig-pool-persist ipp.txt
keepalive 10 120
tls-auth ta.key_0
cipher BF-CBC
comp-lzo
persist-key
persist-tun
status openvpn-status.log
log openvpn.log
verb 3

Anslutnings log

Sun Dec 07 00:59:12 2008 OpenVPN 2.1_rc15 i686-pc-mingw32 [SSL] [LZO2] [PKCS11] built on Nov 19 2008
Sun Dec 07 00:59:12 2008 NOTE: OpenVPN 2.1 requires '--script-security 2' or higher to call user-defined scripts or executables
Sun Dec 07 00:59:12 2008 Control Channel Authentication: using 'C:\Program Files\OpenVPN\ubuntu\ta.key_1' as a OpenVPN static key file
Sun Dec 07 00:59:12 2008 Outgoing Control Channel Authentication: Using 160 bit message hash 'SHA1' for HMAC authentication
Sun Dec 07 00:59:12 2008 Incoming Control Channel Authentication: Using 160 bit message hash 'SHA1' for HMAC authentication
Sun Dec 07 00:59:12 2008 LZO compression initialized
Sun Dec 07 00:59:12 2008 Control Channel MTU parms [ L:1544 D:168 EF:68 EB:0 ET:0 EL:0 ]
Sun Dec 07 00:59:12 2008 Data Channel MTU parms [ L:1544 D:1450 EF:44 EB:135 ET:0 EL:0 AF:3/1 ]
Sun Dec 07 00:59:12 2008 Local Options hash (VER=V4): '863ad621'
Sun Dec 07 00:59:12 2008 Expected Remote Options hash (VER=V4): '64e96fc1'
Sun Dec 07 00:59:12 2008 Attempting to establish TCP connection with *****************:523
Sun Dec 07 00:59:12 2008 TCP connection established with ***************:523
Sun Dec 07 00:59:12 2008 Socket Buffers: R=[8192->8192] S=[8192->8192]
Sun Dec 07 00:59:12 2008 TCPv4_CLIENT link local: [undef]
Sun Dec 07 00:59:12 2008 TCPv4_CLIENT link remote: *******************:523
Sun Dec 07 00:59:12 2008 TLS: Initial packet from *****************:523, sid=d1446f51 840db072
Sun Dec 07 00:59:13 2008 VERIFY OK: depth=1, /C=SE/ST=Jonkoping/L=Jonkoping/O=eriksson25/CN=erikisson25/emailAddress=************@hotmail.com
Sun Dec 07 00:59:13 2008 VERIFY OK: nsCertType=SERVER
Sun Dec 07 00:59:13 2008 VERIFY OK: depth=0, /C=SE/ST=Jonkoping/L=Jonkoping/O=eriksson25/CN=eriksson25/emailAddress=**************@hotmail.com
Sun Dec 07 00:59:14 2008 Data Channel Encrypt: Cipher 'BF-CBC' initialized with 128 bit key
Sun Dec 07 00:59:14 2008 Data Channel Encrypt: Using 160 bit message hash 'SHA1' for HMAC authentication
Sun Dec 07 00:59:14 2008 Data Channel Decrypt: Cipher 'BF-CBC' initialized with 128 bit key
Sun Dec 07 00:59:14 2008 Data Channel Decrypt: Using 160 bit message hash 'SHA1' for HMAC authentication
Sun Dec 07 00:59:14 2008 Control Channel: TLSv1, cipher TLSv1/SSLv3 DHE-RSA-AES256-SHA, 1024 bit RSA
Sun Dec 07 00:59:14 2008 [eriksson25] Peer Connection Initiated with ***************:523
Sun Dec 07 00:59:15 2008 SENT CONTROL [eriksson25]: 'PUSH_REQUEST' (status=1)
Sun Dec 07 00:59:15 2008 PUSH: Received control message: 'PUSH_REPLY,route 192.168.10.1,topology net30,ping 10,ping-restart 120,ifconfig 192.168.10.6 192.168.10.5'
Sun Dec 07 00:59:15 2008 OPTIONS IMPORT: timers and/or timeouts modified
Sun Dec 07 00:59:15 2008 OPTIONS IMPORT: --ifconfig/up options modified
Sun Dec 07 00:59:15 2008 OPTIONS IMPORT: route options modified
Sun Dec 07 00:59:15 2008 ROUTE default_gateway=192.168.2.3
Sun Dec 07 00:59:15 2008 TAP-WIN32 device [Local Area Connection 3] opened: \\.\Global\{E798B781-F521-47E7-A044-9CBC3AF5DBF6}.tap
Sun Dec 07 00:59:15 2008 TAP-Win32 Driver Version 9.4
Sun Dec 07 00:59:15 2008 TAP-Win32 MTU=1500
Sun Dec 07 00:59:15 2008 Notified TAP-Win32 driver to set a DHCP IP/netmask of 192.168.10.6/255.255.255.252 on interface {E798B781-F521-47E7-A044-9CBC3AF5DBF6} [DHCP-serv: 192.168.10.5, lease-time: 31536000]
Sun Dec 07 00:59:15 2008 Successful ARP Flush on interface [3] {E798B781-F521-47E7-A044-9CBC3AF5DBF6}
Sun Dec 07 00:59:20 2008 TEST ROUTES: 1/1 succeeded len=1 ret=1 a=0 u/d=up
Sun Dec 07 00:59:20 2008 C:\WINDOWS\system32\route.exe ADD 192.168.10.1 MASK 255.255.255.255 192.168.10.5
Sun Dec 07 00:59:20 2008 Route addition via IPAPI succeeded [adaptive]
Sun Dec 07 00:59:20 2008 Initialization Sequence Completed

Visa signatur

Main: GA-P35-DQ6, Q6600,8800GTS, 2gig Balistik 8500
Server: "4300, 12TB Lagring

Permalänk

Du måste pusha en route från servern till klienten, typ:

push "route 192.168.0.0 255.255.255.0"

Som referens kan jag lägga in konfigurationsfiler som jag kör på ett ställe och som jag vet fungerar:

Server

dev tun local x.x.x.x port 1194 proto udp server 10.10.10.0 255.255.255.0 ifconfig-pool-persist ipp.txt ca /usr/local/etc/openvpn/keys/ca.crt cert /usr/local/etc/openvpn/keys/server.crt key /usr/local/etc/openvpn/keys/server.key dh /usr/local/etc/openvpn/keys/dh2048.pem push "route 172.20.20.0 255.255.255.0" comp-lzo keepalive 10 60 ping-timer-rem persist-tun persist-key group nobody daemon

Klient

client remote x.x.x.x 1194 dev tun ca ca.crt cert client1.crt key client1.key comp-lzo keepalive 10 60 ping-timer-rem persist-tun persist-key verb 3

Visa signatur

"Linux is good because it keeps people out of real kernels"