So nun weis ich nicht ob ich ein neues Thema aufmachen soll oder… Dann denke ich mal schon.
Mit meine Box konnte ich Verbindung mit OpenVPN mit Static_Key auf aufbauen d.h. die Box als Client und als Server.
Nun Versuche ich es mal nach Anleitung hier und einer PDF-Doc. Früher habe ich mal eine OpenVPN Verbindung mit Zertifikaten (Verwaltung)aufgebaut auf ein Windows NT 4.0 Server aber das ist schon ein bissen her.
Jetzt habe ich hier diese Zenario.
Ich will eine Tun Verbindung zu meiner Fritzbox aufbauen per OpenVPN versteht sich, das mit fünf Clients die unterschiedlich auf die Box zugreifen können (sollen).
Dazu habe ich für jeden Client 5 passende Zertifikate und eins für die Box erstellt wo ja der Server OpenVPN läuft.
Zu denen habe ich dann die entsprechenden Clients Config erstellt.
Eine z.B. Sieht so aus.:
Auf der Box (Server) sieht das ganze so aus.
So nun wenn ich eine Verbindung aufbaue bricht die Verbindung ab besser gesagt OpenVPN auf meine Box Stopp den Dienst.
Wenn ich dann in Client-Logfile schaue sieht die Meldung so aus:
Die Log der Box sieht so aus:
Den Static-Key für die tls-auth habe ich vorher aus der Box entnommen und im Verzeichnis im Client gepackt.
Dann habe ich mal tls-auth abgestellt und im Client ein # gesetzt und das ganze noch mal versucht.
Dann kommt diese Meldung im Client-Logfile
Log der Box:
So jetzt weis ich auch nicht mehr weiter. Firewall ist für den Port offen 1194 und am Client 1 ebenfalls offen (Portweiterleitung)
Was mich wunder das auch hier OpenVPN gestoppt wird von der Box?
Dann das mit
Darum benötige ich die Hilfe von Euch Profis die mit OpenVPN mehr sich auskennen.
PS: Ich hoffe der Text ist nicht zu lang geworden.
Mit meine Box konnte ich Verbindung mit OpenVPN mit Static_Key auf aufbauen d.h. die Box als Client und als Server.
Nun Versuche ich es mal nach Anleitung hier und einer PDF-Doc. Früher habe ich mal eine OpenVPN Verbindung mit Zertifikaten (Verwaltung)aufgebaut auf ein Windows NT 4.0 Server aber das ist schon ein bissen her.
Jetzt habe ich hier diese Zenario.
Ich will eine Tun Verbindung zu meiner Fritzbox aufbauen per OpenVPN versteht sich, das mit fünf Clients die unterschiedlich auf die Box zugreifen können (sollen).
Dazu habe ich für jeden Client 5 passende Zertifikate und eins für die Box erstellt wo ja der Server OpenVPN läuft.
Zu denen habe ich dann die entsprechenden Clients Config erstellt.
Eine z.B. Sieht so aus.:
Code:
port 1194 #PORT ANPASSEN
remote fritz.box #SERVER ANPASSEN (URL oder IP)
proto udp
dev tun
tls-client
ns-cert-type server
comp-lzo
ca C:\\Server\\OpenVPN\\keys\\ca.crt
cert C:\\Server\\OpenVPN\\keys\\winserver2003.crt
key C:\\Server\\OpenVPN\\keys\\winserver2003.key
tls-auth "C:\\Server\\OpenVPN\\keys\\static.key" 1
tun-mtu 1500
tun-mtu-extra 32
mssfix
nobind
pull #Client verliert ohne das Pull bei Inaktivität die Verbindung
verb 3
mute 50
persist-key
persist-tun
Auf der Box (Server) sieht das ganze so aus.
Code:
# OpenVPN 2.1 Config
proto udp
port 1194
dev tun
ca /tmp/flash/ca.crt
cert /tmp/flash/box.crt
key /tmp/flash/box.key
mode server
tls-server
dh /tmp/flash/dh.pem
crl-verify /tmp/flash/crl.pem
tls-auth /tmp/flash/static.key 0
ifconfig-pool 192.168.200.100 192.168.200.150
ifconfig 192.168.200.1 192.168.200.2
route 192.168.200.0 255.255.255.0
push "route 192.168.200.0 255.255.255.0"
push "route 192.168.0.0 255.255.255.0"
push "dhcp-option DNS 192.168.0.1"
push "redirect-gateway"
max-clients 5
tun-mtu 1500
mssfix
daemon
verb 3
cipher BF-CBC
comp-lzo
float
keepalive 10 120
status /var/log/openvpn.log
So nun wenn ich eine Verbindung aufbaue bricht die Verbindung ab besser gesagt OpenVPN auf meine Box Stopp den Dienst.
Wenn ich dann in Client-Logfile schaue sieht die Meldung so aus:
Code:
Sat Jan 19 01:47:01 2008 OpenVPN 2.0.9 Win32-MinGW [SSL] [LZO] built on Oct 1 2006
Sat Jan 19 01:47:01 2008 Control Channel Authentication: using 'C:\Server\OpenVPN\keys\static.key' as a OpenVPN static key file
Sat Jan 19 01:47:01 2008 Outgoing Control Channel Authentication: Using 160 bit message hash 'SHA1' for HMAC authentication
Sat Jan 19 01:47:01 2008 Incoming Control Channel Authentication: Using 160 bit message hash 'SHA1' for HMAC authentication
Sat Jan 19 01:47:01 2008 LZO compression initialized
Sat Jan 19 01:47:01 2008 Control Channel MTU parms [ L:1574 D:166 EF:66 EB:0 ET:0 EL:0 ]
Sat Jan 19 01:47:02 2008 Data Channel MTU parms [ L:1574 D:1450 EF:42 EB:135 ET:32 EL:0 AF:3/1 ]
Sat Jan 19 01:47:02 2008 Local Options hash (VER=V4): 'ec497616'
Sat Jan 19 01:47:02 2008 Expected Remote Options hash (VER=V4): '7cd8ed90'
Sat Jan 19 01:47:02 2008 UDPv4 link local: [undef]
Sat Jan 19 01:47:02 2008 UDPv4 link remote: 192.168.0.1:1194
Sat Jan 19 01:47:02 2008 TLS: Initial packet from 192.168.0.1:1194, sid=63e3f9ea 4c764a5e
Sat Jan 19 01:47:02 2008 Authenticate/Decrypt packet error: bad packet ID (may be a replay): [ #1 / time = (1200703471) Sat Jan 19 01:44:31 2008 ] -- see the man page entry for --no-replay and --replay-window for more info or silence this warning with --mute-replay-warnings
Sat Jan 19 01:47:02 2008 TLS Error: incoming packet authentication failed from 192.168.0.1:1194
Sat Jan 19 01:47:04 2008 Authenticate/Decrypt packet error: bad packet ID (may be a replay): [ #2 / time = (1200703471) Sat Jan 19 01:44:31 2008 ] -- see the man page entry for --no-replay and --replay-window for more info or silence this warning with --mute-replay-warnings
Sat Jan 19 01:47:04 2008 TLS Error: incoming packet authentication failed from 192.168.0.1:1194
Sat Jan 19 01:47:04 2008 Authenticate/Decrypt packet error: bad packet ID (may be a replay): [ #3 / time = (1200703471) Sat Jan 19 01:44:31 2008 ] -- see the man page entry for --no-replay and --replay-window for more info or silence this warning with --mute-replay-warnings
Sat Jan 19 01:47:04 2008 TLS Error: incoming packet authentication failed from 192.168.0.1:1194
Sat Jan 19 01:47:04 2008 Authenticate/Decrypt packet error: bad packet ID (may be a replay): [ #4 / time = (1200703471) Sat Jan 19 01:44:31 2008 ] -- see the man page entry for --no-replay and --replay-window for more info or silence this warning with --mute-replay-warnings
Sat Jan 19 01:47:04 2008 TLS Error: incoming packet authentication failed from 192.168.0.1:1194
Sat Jan 19 01:47:04 2008 Authenticate/Decrypt packet error: bad packet ID (may be a replay): [ #5 / time = (1200703471) Sat Jan 19 01:44:31 2008 ] -- see the man page entry for --no-replay and --replay-window for more info or silence this warning with --mute-replay-warnings
Die Log der Box sieht so aus:
Code:
nel: mcfw_query_sent: cpmac:0,1,2,3:0.0.0.0 1000
Jan 19 01:39:52 fritz daemon.err openvpn[511]: 192.168.0.5:3317 TLS Error: TLS key negotiation failed to occur within 60 seconds (check your network connectivity)
Jan 19 01:39:52 fritz daemon.err openvpn[511]: 192.168.0.5:3317 TLS Error: TLS handshake failed
Jan 19 01:39:52 fritz daemon.notice openvpn[511]: 192.168.0.5:3317 SIGUSR1[soft,tls-error] received, client-instance restarting
Jan 19 01:39:54 fritz daemon.notice openvpn[511]: MULTI: multi_create_instance called
Jan 19 01:39:54 fritz daemon.notice openvpn[511]: 192.168.0.5:3350 Re-using SSL/TLS context
Jan 19 01:39:54 fritz daemon.notice openvpn[511]: 192.168.0.5:3350 LZO compression initialized
Jan 19 01:39:54 fritz daemon.notice openvpn[511]: 192.168.0.5:3350 Control Channel MTU parms [ L:1542 D:166 EF:66 EB:0 ET:0 EL:0 ]
Jan 19 01:39:54 fritz daemon.notice openvpn[511]: 192.168.0.5:3350 Data Channel MTU parms [ L:1542 D:1450 EF:42 EB:135 ET:0 EL:0 AF:3/1 ]
Jan 19 01:39:54 fritz daemon.notice openvpn[511]: 192.168.0.5:3350 TLS: Initial packet from 192.168.0.5:3350, sid=a996fa10 6084a021
Jan 19 01:40:54 fritz daemon.err openvpn[511]: 192.168.0.5:3350 TLS Error: TLS key negotiation failed to occur within 60 seconds (check your network connectivity)
Jan 19 01:40:54 fritz daemon.err openvpn[511]: 192.168.0.5:3350 TLS Error: TLS handshake failed
Jan 19 01:40:54 fritz daemon.notice openvpn[511]: 192.168.0.5:3350 SIGUSR1[soft,tls-error] received, client-instance restarting
Jan 19 01:40:56 fritz daemon.notice openvpn[511]: MULTI: multi_create_instance called
Jan 19 01:40:56 fritz daemon.notice openvpn[511]: 192.168.0.5:3378 Re-using SSL/TLS context
Jan 19 01:40:56 fritz daemon.notice openvpn[511]: 192.168.0.5:3378 LZO compression initialized
Jan 19 01:40:56 fritz daemon.notice openvpn[511]: 192.168.0.5:3378 Control Channel MTU parms [ L:1542 D:166 EF:66 EB:0 ET:0 EL:0 ]
Jan 19 01:40:56 fritz daemon.notice openvpn[511]: 192.168.0.5:3378 Data Channel MTU parms [ L:1542 D:1450 EF:42 EB:135 ET:0 EL:0 AF:3/1 ]
Jan 19 01:40:56 fritz daemon.notice openvpn[511]: 192.168.0.5:3378 TLS: Initial packet from 192.168.0.5:3378, sid=a0598e12 6db0cbd1
Jan 19 01:41:06 fritz daemon.err openvpn[511]: read UDPv4 [ECONNREFUSED]: Connection refused (code=146)
…
….
Den Static-Key für die tls-auth habe ich vorher aus der Box entnommen und im Verzeichnis im Client gepackt.
Dann habe ich mal tls-auth abgestellt und im Client ein # gesetzt und das ganze noch mal versucht.
Dann kommt diese Meldung im Client-Logfile
Code:
Sat Jan 19 02:20:57 2008 OpenVPN 2.0.9 Win32-MinGW [SSL] [LZO] built on Oct 1 2006
Sat Jan 19 02:20:57 2008 LZO compression initialized
Sat Jan 19 02:20:57 2008 Control Channel MTU parms [ L:1574 D:138 EF:38 EB:0 ET:0 EL:0 ]
Sat Jan 19 02:20:57 2008 Data Channel MTU parms [ L:1574 D:1450 EF:42 EB:135 ET:32 EL:0 AF:3/1 ]
Sat Jan 19 02:20:57 2008 Local Options hash (VER=V4): 'd3a7571a'
Sat Jan 19 02:20:57 2008 Expected Remote Options hash (VER=V4): '5b1533a2'
Sat Jan 19 02:20:57 2008 UDPv4 link local: [undef]
Sat Jan 19 02:20:57 2008 UDPv4 link remote: 192.168.0.1:1194
Sat Jan 19 02:20:57 2008 TLS: Initial packet from 192.168.0.1:1194, sid=d2886e4f 174c21ba
Sat Jan 19 02:20:59 2008 VERIFY OK: depth=1, /C=DE/ST=CA/L=Home/O=RCB/OU=RCB/CN=fritzbox/[email protected]
Sat Jan 19 02:20:59 2008 VERIFY OK: nsCertType=SERVER
Sat Jan 19 02:20:59 2008 VERIFY OK: depth=0, /C=DE/ST=CA/O=RCB/OU=RCB/CN=fritzbox/[email protected]
Sat Jan 19 02:21:01 2008 read UDPv4: Connection reset by peer (WSAECONNRESET) (code=10054)
Sat Jan 19 02:21:01 2008 read UDPv4: Connection reset by peer (WSAECONNRESET) (code=10054)
Sat Jan 19 02:21:05 2008 TCP/UDP: Closing socket
Log der Box:
Code:
Jan 19 02:17:45 fritz daemon.notice openvpn[1513]: OpenVPN 2.1_rc4 mipsel-linux [SSL] [LZO2] [EPOLL] built on Jan 14 2008
Jan 19 02:17:47 fritz daemon.notice openvpn[1513]: Diffie-Hellman initialized with 2048 bit key
Jan 19 02:17:47 fritz daemon.warn openvpn[1513]: WARNING: file '/tmp/flash/box.key' is group or others accessible
Jan 19 02:17:47 fritz daemon.notice openvpn[1513]: TLS-Auth MTU parms [ L:1542 D:138 EF:38 EB:0 ET:0 EL:0 ]
Jan 19 02:17:47 fritz daemon.notice openvpn[1513]: TUN/TAP device tun0 opened
Jan 19 02:17:47 fritz daemon.notice openvpn[1513]: TUN/TAP TX queue length set to 100
Jan 19 02:17:47 fritz daemon.notice openvpn[1513]: /sbin/ifconfig tun0 192.168.200.1 pointopoint 192.168.200.2 mtu 1500
Jan 19 02:17:47 fritz daemon.notice openvpn[1513]: /sbin/route add -net 192.168.200.0 netmask 255.255.255.0 gw 192.168.200.2
Jan 19 02:17:47 fritz daemon.notice openvpn[1513]: Data Channel MTU parms [ L:1542 D:1450 EF:42 EB:135 ET:0 EL:0 AF:3/1 ]
Jan 19 02:17:47 fritz daemon.notice openvpn[1520]: Socket Buffers: R=[109568->131072] S=[109568->131072]
Jan 19 02:17:47 fritz daemon.notice openvpn[1520]: UDPv4 link local (bound): [undef]:1194
Jan 19 02:17:47 fritz daemon.notice openvpn[1520]: UDPv4 link remote: [undef]
Jan 19 02:17:47 fritz daemon.notice openvpn[1520]: MULTI: multi_init called, r=256 v=256
Jan 19 02:17:47 fritz daemon.notice openvpn[1520]: IFCONFIG POOL: base=192.168.200.100 size=13
Jan 19 02:17:47 fritz daemon.notice openvpn[1520]: Initialization Sequence Completed
Jan 19 02:18:26 fritz daemon.notice openvpn[1520]: MULTI: multi_create_instance called
Jan 19 02:18:26 fritz daemon.notice openvpn[1520]: 192.168.0.5:3865 Re-using SSL/TLS context
Jan 19 02:18:26 fritz daemon.notice openvpn[1520]: 192.168.0.5:3865 LZO compression initialized
Jan 19 02:18:26 fritz daemon.notice openvpn[1520]: 192.168.0.5:3865 Control Channel MTU parms [ L:1542 D:138 EF:38 EB:0 ET:0 EL:0 ]
Jan 19 02:18:26 fritz daemon.notice openvpn[1520]: 192.168.0.5:3865 Data Channel MTU parms [ L:1542 D:1450 EF:42 EB:135 ET:0 EL:0 AF:3/1 ]
Jan 19 02:18:26 fritz daemon.notice openvpn[1520]: 192.168.0.5:3865 TLS: Initial packet from 192.168.0.5:3865, sid=3bdc7e8f e8a2bd95
Jan 19 02:18:29 fritz daemon.err openvpn[1520]: 192.168.0.5:3865 CRL: cannot read CRL from file /tmp/flash/crl.pem
So jetzt weis ich auch nicht mehr weiter. Firewall ist für den Port offen 1194 und am Client 1 ebenfalls offen (Portweiterleitung)
Was mich wunder das auch hier OpenVPN gestoppt wird von der Box?
Dann das mit
wundert mich ob wohl da doch nichts drin stehen muss nur doch für zurück gezogene Zertifikate?cannnot read file /tmp/flash/crl.pem
Darum benötige ich die Hilfe von Euch Profis die mit OpenVPN mehr sich auskennen.
PS: Ich hoffe der Text ist nicht zu lang geworden.
Zuletzt bearbeitet: