Portál AbcLinuxu, 6. května 2025 06:31

Dotaz: OpenVPN na Mikrotik RouterBoard

26.5.2009 22:38 Eršin
OpenVPN na Mikrotik RouterBoard
Přečteno: 2519×
Odpovědět | Admin

Ahoj

Pokousim se rozchodit openVPN spojeni na Mikrotik Router Board. Konkretne jako X.509, bridgovane a pres TCP port.

Klient (winXP) se skoro pripoji, ale pak se spojeni restartuje, protoze klient dostane signal SIGUSR1. Nemate s tim nekdo zkusenosti? Diky  predem za kazdou reakci...

Log z OpenVPN klienta:

Tue May 26 22:29:17 2009 OpenVPN 2.0.9 Win32-MinGW [SSL] [LZO] built on Oct  1 2006
Tue May 26 22:29:20 2009 IMPORTANT: OpenVPN's default port number is now 1194, based on an official port number assignment by IANA.  OpenVPN 2.0-beta16 and earlier used 5000 as the default port.
Tue May 26 22:29:20 2009 Control Channel MTU parms [ L:1591 D:140 EF:40 EB:0 ET:0 EL:0 ]
Tue May 26 22:29:20 2009 Data Channel MTU parms [ L:1591 D:1450 EF:59 EB:4 ET:32 EL:0 ]
Tue May 26 22:29:20 2009 Local Options hash (VER=V4): 'b60e7885'
Tue May 26 22:29:20 2009 Expected Remote Options hash (VER=V4): 'fbeb66e6'
Tue May 26 22:29:20 2009 Attempting to establish TCP connection with 12.34.56.78:1194
Tue May 26 22:29:20 2009 TCP connection established with 12.34.56.78:1194
Tue May 26 22:29:20 2009 TCPv4_CLIENT link local: [undef]
Tue May 26 22:29:20 2009 TCPv4_CLIENT link remote: 12.34.56.78:1194
Tue May 26 22:29:20 2009 TLS: Initial packet from 12.34.56.78:1194, sid=ccbe1f1f e9ba5fb1
Tue May 26 22:29:22 2009 VERIFY OK: depth=1, /C=CZ/ST=Czech/L=Prague/O=Enso/CN=Enso-CA/emailAddress=admin@ensonet.cz
Tue May 26 22:29:22 2009 VERIFY OK: nsCertType=SERVER
Tue May 26 22:29:22 2009 VERIFY OK: depth=0, /C=CZ/ST=Czech/O=Enso/CN=server/emailAddress=admin@ensonet.cz
Tue May 26 22:29:25 2009 Data Channel Encrypt: Cipher 'AES-256-CBC' initialized with 256 bit key
Tue May 26 22:29:25 2009 Data Channel Encrypt: Using 160 bit message hash 'SHA1' for HMAC authentication
Tue May 26 22:29:25 2009 Data Channel Decrypt: Cipher 'AES-256-CBC' initialized with 256 bit key
Tue May 26 22:29:25 2009 Data Channel Decrypt: Using 160 bit message hash 'SHA1' for HMAC authentication
Tue May 26 22:29:25 2009 Control Channel: TLSv1, cipher TLSv1/SSLv3 DHE-RSA-AES256-SHA, 2048 bit RSA
Tue May 26 22:29:25 2009 [server] Peer Connection Initiated with 12.34.56.78:1194
Tue May 26 22:29:26 2009 SENT CONTROL [server]: 'PUSH_REQUEST' (status=1)
Tue May 26 22:29:26 2009 PUSH: Received control message: 'PUSH_REPLY,route-gateway 0.0.0.0,ifconfig 192.168.0.199 255.255.255.0'
Tue May 26 22:29:26 2009 OPTIONS IMPORT: --ifconfig/up options modified
Tue May 26 22:29:26 2009 OPTIONS IMPORT: route options modified
Tue May 26 22:29:26 2009 TAP-WIN32 device [openvpn] opened: \\.\Global\{80835E93-8507-4D8C-BE0E-C9C632E1FF9D}.tap
Tue May 26 22:29:26 2009 TAP-Win32 Driver Version 8.4
Tue May 26 22:29:26 2009 TAP-Win32 MTU=1500
Tue May 26 22:29:26 2009 Notified TAP-Win32 driver to set a DHCP IP/netmask of 192.168.0.199/255.255.255.0 on interface {80845E93-8507-4E8C-BE0E-C9E632D1EE9D} [DHCP-serv: 192.168.0.0, lease-time: 31536000]
Tue May 26 22:29:26 2009 Successful ARP Flush on interface [65542] {80845E93-8507-4E8C-BE0E-C9E632D1EE9D}
Tue May 26 22:29:26 2009 TEST ROUTES: 0/0 succeeded len=-1 ret=0 a=0 u/d=down
Tue May 26 22:29:26 2009 Route: Waiting for TUN/TAP interface to come up...
Tue May 26 22:29:26 2009 Connection reset, restarting [-1]
Tue May 26 22:29:26 2009 TCP/UDP: Closing socket
Tue May 26 22:29:26 2009 SIGUSR1[soft,connection-reset] received, process restarting
Tue May 26 22:29:26 2009 Restart pause, 5 second(s)
Nástroje: Začni sledovat (0) ?Zašle upozornění na váš email při vložení nového komentáře.

Odpovědi

27.5.2009 10:36 NN
Rozbalit Rozbalit vše Re: OpenVPN na Mikrotik RouterBoard
Odpovědět | | Sbalit | Link | Blokovat | Admin

Podlemeho je vse v poradku do momentu, kdy si ma TAP na woknech nahodit nove IP-cko..

Tue May 26 22:29:26 2009 Route: Waiting for TUN/TAP interface to come up...
Tue May 26 22:29:26 2009 Connection reset, restarting [-1]

Mozna skusit dat podrobnejsi 'verb'..neco resetuje to spojeni.

NN

27.5.2009 12:01 Eršin
Rozbalit Rozbalit vše Re: OpenVPN na Mikrotik RouterBoard

Jj, presne tak... Neco resetuje spojeni.

verb jsem zkusil hnat az na 6, ale v kritickem momente zadna nova hlaska nepribyla:-(

Založit nové vláknoNahoru

Tiskni Sdílej: Linkuj Jaggni to Vybrali.sme.sk Google Del.icio.us Facebook

ISSN 1214-1267, (c) 1999-2007 Stickfish s.r.o.