Portál AbcLinuxu, 9. května 2025 00:37
Mon Sep 28 15:48:58 2009 us=236806 Local Options String: 'V4,dev-type tap,link-mtu 1575,tun-mtu 1532,proto TCPv4_CLIENT,cipher BF-CBC,auth SHA1,keysize 128,tls-auth,key-method 2,tls-client' Mon Sep 28 15:48:58 2009 us=236820 Expected Remote Options String: 'V4,dev-type tap,link-mtu 1575,tun-mtu 1532,proto TCPv4_SERVER,cipher BF-CBC,auth SHA1,keysize 128,tls-auth,key-method 2,tls-server' Mon Sep 28 15:48:58 2009 us=236853 Local Options hash (VER=V4): '1355b641' Mon Sep 28 15:48:58 2009 us=236880 Expected Remote Options hash (VER=V4): 'ee75fd82' Mon Sep 28 15:48:58 2009 us=236953 Attempting to establish TCP connection with SS.SS.SS.SS:1194 Mon Sep 28 15:48:58 2009 us=261692 TCP connection established with SS.SS.SS.SS:1194 Mon Sep 28 15:48:58 2009 us=261766 Socket Buffers: R=[87380->131072] S=[16384->131072] Mon Sep 28 15:48:58 2009 us=261789 TCPv4_CLIENT link local: [undef] Mon Sep 28 15:48:58 2009 us=261806 TCPv4_CLIENT link remote: SS.SS.SS.SS:1194 WRMon Sep 28 15:48:58 2009 us=286697 TLS: Initial packet from SS.SS.SS.SS:1194, sid=c81d8e4b af0db82e WMon Sep 28 15:48:58 2009 us=295479 Connection reset, restarting [0] Mon Sep 28 15:48:58 2009 us=295695 TCP/UDP: Closing socket Mon Sep 28 15:48:58 2009 us=295804 SIGUSR1[soft,connection-reset] received, process restarting Mon Sep 28 15:48:58 2009 us=295832 Restart pause, 5 second(s)což se opakuje každých 5 sekund, server vypisuje poněkud smyslplněji:
Mon Sep 28 15:48:58 2009 us=281934 Local Options String: 'V4,dev-type tap,link-mtu 1575,tun-mtu 1532,proto TCPv4_SERVER,keydir 0,cipher BF-CBC,auth SHA1,keysize 128,tls-auth,key-method 2,tls-server' Mon Sep 28 15:48:58 2009 us=281965 Expected Remote Options String: 'V4,dev-type tap,link-mtu 1575,tun-mtu 1532,proto TCPv4_CLIENT,keydir 1,cipher BF-CBC,auth SHA1,keysize 128,tls-auth,key-method 2,tls-client' Mon Sep 28 15:48:58 2009 us=282030 Local Options hash (VER=V4): '47106f19' Mon Sep 28 15:48:58 2009 us=282079 Expected Remote Options hash (VER=V4): '8a6c6b5b' Mon Sep 28 15:48:58 2009 us=282152 TCP connection established with CC.CC.CC.CC:60563 Mon Sep 28 15:48:58 2009 us=282195 Socket Buffers: R=[131072->131072] S=[131072->131072] Mon Sep 28 15:48:58 2009 us=282237 TCPv4_SERVER link local: [undef] Mon Sep 28 15:48:58 2009 us=282269 TCPv4_SERVER link remote: CC.CC.CC.CC:60563 WRMon Sep 28 15:48:58 2009 us=288877 84.242.102.124:60563 TLS: Initial packet from CC.CC.CC.CC:60563, sid=2bd3390f 5eb6fbb7 Mon Sep 28 15:48:58 2009 us=288973 CC.CC.CC.CC:60563 Authenticate/Decrypt packet error: packet HMAC authentication failed Mon Sep 28 15:48:58 2009 us=289023 CC.CC.CC.CC:60563 TLS Error: incoming packet authentication failed from CC.CC.CC.CC:60563 Mon Sep 28 15:48:58 2009 us=289130 CC.CC.CC.CC:60563 Fatal TLS error (check_tls_errors_co), restarting Mon Sep 28 15:48:58 2009 us=289318 CC.CC.CC.CC:60563 SIGUSR1[soft,tls-error] received, client-instance restarting Mon Sep 28 15:48:58 2009 us=289550 TCP/UDP: Closing socketPrvní čeho jsem si všiml jsou rozdílné hashe nastavení(?) na obou stranách. Potom jsem googlil chybu HMAC a dostal jsem se ke tvrzení, že mám rozdílné klíče na obou stranách. Generoval jsem je ale společně na serverové straně, měly by být Okay..
ca /etc/openvpn/cacert.pem key /etc/openvpn/key.pem dh /etc/openvpn/dh1024.pem cert /etc/openvpn/vpnserver.crt tls-auth /etc/openvpn/secret.key 0 server 10.0.1.0 255.255.255.0 mode server tls-server dev tap0 proto tcp-server port 1194 status /tmp/vpn.status keepalive 10 30 client-to-client max-clients 5 verb 5 persist-key persist-tun log-append /var/log/openvpna client.conf:
remote SS.SS.SS.SS proto tcp-client port 1194 dev tap0 client mute-replay-warnings verb 5 tls-client tls-auth /etc/openvpn/secret.key ca /etc/openvpn/cacert.pem cert /etc/openvpn/klient.crt key /etc/openvpn/client.key log-append /var/log/openvpn
Tiskni
Sdílej:
ISSN 1214-1267, (c) 1999-2007 Stickfish s.r.o.