[Gelöst] OpenVPN: ERROR: Cannot ioctl TUNSETIFF tap

cmonty14

Mitglied
Mitglied seit
22 Jan 2007
Beiträge
378
Punkte für Reaktionen
0
Punkte
16
Hallo!

Die VPN-Verbindung des Clients schlägt fehl.
In der Konsole sehe ich diese Meldungen:
Code:
user@pc1 /etc/openvpn $ openvpn client.conf 
Thu Nov 14 00:53:02 2013 OpenVPN 2.3.2 i486-pc-linux-gnu [SSL (OpenSSL)] [LZO] [EPOLL] [PKCS11] [eurephia] [MH] [IPv6] built on Jun 21 2013
Thu Nov 14 00:53:02 2013 WARNING: file 'pc1.key' is group or others accessible
Thu Nov 14 00:53:02 2013 WARNING: file 'ta.key' is group or others accessible
Thu Nov 14 00:53:02 2013 Control Channel Authentication: using 'ta.key' as a OpenVPN static key file
Thu Nov 14 00:53:02 2013 Outgoing Control Channel Authentication: Using 160 bit message hash 'SHA1' for HMAC authentication
Thu Nov 14 00:53:02 2013 Incoming Control Channel Authentication: Using 160 bit message hash 'SHA1' for HMAC authentication
Thu Nov 14 00:53:02 2013 Socket Buffers: R=[180224->131072] S=[180224->131072]
Thu Nov 14 00:53:02 2013 UDPv4 link local: [undef]
Thu Nov 14 00:53:02 2013 UDPv4 link remote: [AF_INET]91.89.xxx.xxx:1194
Thu Nov 14 00:53:02 2013 TLS: Initial packet from [AF_INET]91.89.xxx.xxx:1194, sid=af840xxx 762f8xxx
Thu Nov 14 00:53:03 2013 VERIFY OK: depth=1, C=DE, ST=BW, L=STADT, O=mydomain, CN=net2-FB7390, [email protected]
Thu Nov 14 00:53:03 2013 VERIFY OK: nsCertType=SERVER
Thu Nov 14 00:53:03 2013 VERIFY OK: depth=0, C=DE, ST=BW, L=STADT, O=mydomain, CN=server, [email protected]
Thu Nov 14 00:53:04 2013 Data Channel Encrypt: Cipher 'BF-CBC' initialized with 128 bit key
Thu Nov 14 00:53:04 2013 Data Channel Encrypt: Using 160 bit message hash 'SHA1' for HMAC authentication
Thu Nov 14 00:53:04 2013 Data Channel Decrypt: Cipher 'BF-CBC' initialized with 128 bit key
Thu Nov 14 00:53:04 2013 Data Channel Decrypt: Using 160 bit message hash 'SHA1' for HMAC authentication
Thu Nov 14 00:53:04 2013 Control Channel: TLSv1, cipher TLSv1/SSLv3 DHE-RSA-AES256-SHA, 2048 bit RSA
Thu Nov 14 00:53:04 2013 [server] Peer Connection Initiated with [AF_INET]91.89.xxx.xxx:1194
Thu Nov 14 00:53:06 2013 SENT CONTROL [server]: 'PUSH_REQUEST' (status=1)
Thu Nov 14 00:53:06 2013 PUSH: Received control message: 'PUSH_REPLY,route-gateway 10.0.0.1,route 192.168.100.0 255.255.255.0,route 10.0.0.0 255.255.255.0,ping 10,ping-restart 120,route 192.168.100.200 255.255.255.248 10.0.0.11,route 192.168.100.200 255.255.255.248 10.0.0.12,route 192.168.100.200 255.255.255.248 10.0.0.14,route 192.168.100.200 255.255.255.248 10.0.0.15,ifconfig 10.0.0.16 255.255.255.0'
Thu Nov 14 00:53:06 2013 OPTIONS IMPORT: timers and/or timeouts modified
Thu Nov 14 00:53:06 2013 OPTIONS IMPORT: --ifconfig/up options modified
Thu Nov 14 00:53:06 2013 OPTIONS IMPORT: route options modified
Thu Nov 14 00:53:06 2013 OPTIONS IMPORT: route-related options modified
Thu Nov 14 00:53:06 2013 ROUTE_GATEWAY 192.168.100.1/255.255.255.0 IFACE=eth1 HWADDR=00:1a:4d:47:b3:48
Thu Nov 14 00:53:06 2013 ERROR: Cannot ioctl TUNSETIFF tap: Operation not permitted (errno=1)
Thu Nov 14 00:53:06 2013 Exiting due to fatal error

Im Debug-Log des Servers finde ich diese Einträge:
Code:
root@net2-FB7390:/var/mod/root# cat /var/tmp/debug_openvpn.out 
Thu Nov 14 00:51:15 2013 OpenVPN 2.3.2 mips-unknown-linux-gnu [SSL (OpenSSL)] [LZO] [IPv6] built on Aug 31 2013
Thu Nov 14 00:51:15 2013 Diffie-Hellman initialized with 2048 bit key
Thu Nov 14 00:51:15 2013 Control Channel Authentication: using '/tmp/flash/openvpn/static.key' as a OpenVPN static key file
Thu Nov 14 00:51:15 2013 Outgoing Control Channel Authentication: Using 160 bit message hash 'SHA1' for HMAC authentication
Thu Nov 14 00:51:15 2013 Incoming Control Channel Authentication: Using 160 bit message hash 'SHA1' for HMAC authentication
Thu Nov 14 00:51:15 2013 Socket Buffers: R=[202752->131072] S=[202752->131072]
Thu Nov 14 00:51:15 2013 TUN/TAP device tap0 opened
Thu Nov 14 00:51:15 2013 TUN/TAP TX queue length set to 100
Thu Nov 14 00:51:15 2013 do_ifconfig, tt->ipv6=0, tt->did_ifconfig_ipv6_setup=0
Thu Nov 14 00:51:15 2013 /sbin/ifconfig tap0 10.0.0.1 netmask 255.255.255.0 mtu 1500 broadcast 10.0.0.255
Thu Nov 14 00:51:15 2013 /sbin/route add -net 192.168.100.200 netmask 255.255.255.248 gw 10.0.0.11
Thu Nov 14 00:51:15 2013 /sbin/route add -net 192.168.100.200 netmask 255.255.255.248 gw 10.0.0.12
Thu Nov 14 00:51:15 2013 /sbin/route add -net 192.168.100.200 netmask 255.255.255.248 gw 10.0.0.14
Thu Nov 14 00:51:15 2013 /sbin/route add -net 192.168.100.200 netmask 255.255.255.248 gw 10.0.0.15
Thu Nov 14 00:51:15 2013 /sbin/route add -net 192.168.100.200 netmask 255.255.255.248 gw 10.0.0.16
Thu Nov 14 00:51:15 2013 chroot to '/tmp/openvpn' and cd to '/' succeeded
Thu Nov 14 00:51:15 2013 GID set to openvpn
Thu Nov 14 00:51:15 2013 UID set to openvpn
Thu Nov 14 00:51:15 2013 UDPv4 link local (bound): [undef]
Thu Nov 14 00:51:15 2013 UDPv4 link remote: [undef]
Thu Nov 14 00:51:15 2013 MULTI: multi_init called, r=256 v=256
Thu Nov 14 00:51:15 2013 IFCONFIG POOL: base=10.0.0.10 size=11, ipv6=0
Thu Nov 14 00:51:15 2013 Initialization Sequence Completed
Thu Nov 14 00:51:23 2013 TLS Error: cannot locate HMAC in incoming packet from [AF_INET]91.89.xxx.xxx:54337
Thu Nov 14 00:51:39 2013 TLS Error: cannot locate HMAC in incoming packet from [AF_INET]91.89.xxx.xxx:54337
[...]
Thu Nov 14 00:52:41 2013 TLS Error: cannot locate HMAC in incoming packet from [AF_INET]91.89.xxx.xxx:56875
Thu Nov 14 00:53:02 2013 91.89.xxx.xxx:55425 TLS: Initial packet from [AF_INET]91.89.xxx.xxx:55425, sid=55dc5xxx e2b1axxx
Thu Nov 14 00:53:03 2013 91.89.xxx.xxx:55425 VERIFY OK: depth=1, C=DE, ST=BW, L=STADT, O=mydomain, CN=net2-FB7390, [email protected]
Thu Nov 14 00:53:03 2013 91.89.xxx.xxx:55425 VERIFY OK: depth=0, C=DE, ST=BW, L=STADT, O=awesomeguyz, CN=pc1, [email protected]
Thu Nov 14 00:53:04 2013 91.89.xxx.xxx:55425 Data Channel Encrypt: Cipher 'BF-CBC' initialized with 128 bit key
Thu Nov 14 00:53:04 2013 91.89.xxx.xxx:55425 Data Channel Encrypt: Using 160 bit message hash 'SHA1' for HMAC authentication
Thu Nov 14 00:53:04 2013 91.89.xxx.xxx:55425 Data Channel Decrypt: Cipher 'BF-CBC' initialized with 128 bit key
Thu Nov 14 00:53:04 2013 91.89.xxx.xxx:55425 Data Channel Decrypt: Using 160 bit message hash 'SHA1' for HMAC authentication
Thu Nov 14 00:53:04 2013 91.89.xxx.xxx:55425 Control Channel: TLSv1, cipher TLSv1/SSLv3 DHE-RSA-AES256-SHA, 2048 bit RSA
Thu Nov 14 00:53:04 2013 91.89.xxx.xxx:55425 [pc1-gigabyte] Peer Connection Initiated with [AF_INET]91.89.xxx.xxx:55425
Thu Nov 14 00:53:04 2013 pc1/91.89.xxx.xxx:55425 OPTIONS IMPORT: reading client specific options from: /clients_openvpn/pc1-gigabyte
Thu Nov 14 00:53:06 2013 pc1/91.89.xxx.xxx:55425 PUSH: Received control message: 'PUSH_REQUEST'
Thu Nov 14 00:53:06 2013 pc1/91.89.xxx.xxx:55425 send_push_reply(): safe_cap=940
Thu Nov 14 00:53:06 2013 pc1/91.89.xxx.xxx:55425 SENT CONTROL [pc1]: 'PUSH_REPLY,route-gateway 10.0.0.1,route 192.168.100.0 255.255.255.0,route 10.0.0.0 255.255.255.0,ping 10,ping-restart 120,route 192.168.100.200 255.255.255.248 10.0.0.11,route 192.168.100.200 255.255.255.248 10.0.0.12,route 192.168.100.200 255.255.255.248 10.0.0.14,route 192.168.100.200 255.255.255.248 10.0.0.15,ifconfig 10.0.0.16 255.255.255.0' (status=1)
Thu Nov 14 00:53:13 2013 TLS Error: cannot locate HMAC in incoming packet from [AF_INET]91.89.xxx.xxx:40083

Hier noch die Konfigurations-Dateien von Server und Client:
Code:
server.conf
root@net2-FB7390:/var/mod/root# cat /var/mod/etc/openvpn.conf 
#  OpenVPN 2.1 Config, Thu Nov 14 00:51:14 CET 2013
proto udp
dev tap0
#Helperline for rc.openvpn to add tap0 to lan bridge
dev-node /dev/tun
ca /tmp/flash/openvpn/ca.crt
cert /tmp/flash/openvpn/box.crt
key /tmp/flash/openvpn/box.key
dh /tmp/flash/openvpn/dh.pem
tls-server
tls-auth /tmp/flash/openvpn/static.key 0
port 1194
ifconfig 10.0.0.1 255.255.255.0
push "route-gateway 10.0.0.1"
push "route 192.168.100.0 255.255.255.0"
max-clients 7
mode server
ifconfig-pool 10.0.0.10 10.0.0.20
push "route 10.0.0.0 255.255.255.0"
client-config-dir /clients_openvpn
route 192.168.100.200 255.255.255.248 10.0.0.11
route 192.168.100.200 255.255.255.248 10.0.0.12
route 192.168.100.200 255.255.255.248 10.0.0.14
route 192.168.100.200 255.255.255.248 10.0.0.15
route 192.168.100.200 255.255.255.248 10.0.0.16
client-to-client
tun-mtu 1500
mssfix
log /var/tmp/debug_openvpn.out
verb 3
cipher BF-CBC
comp-lzo
keepalive 10 120
status /var/log/openvpn.log
chroot /tmp/openvpn
user openvpn
group openvpn
persist-tun
persist-key

Code:
client.conf
user@pc1 /etc/openvpn $ cat client.conf 
##############################################
# Sample client-side OpenVPN 2.0 config file #
# for connecting to multi-client server.     #
#                                            #
# This configuration can be used by multiple #
# clients, however each client should have   #
# its own cert and key files.                #
#                                            #
# On Windows, you might want to rename this  #
# file so it has a .ovpn extension           #
##############################################

# Specify that we are a client and that we
# will be pulling certain config file directives
# from the server.
client

# Use the same setting as you are using on
# the server.
# On most systems, the VPN will not function
# unless you partially or fully disable
# the firewall for the TUN/TAP interface.
dev tap
;dev tun

# Windows needs the TAP-Win32 adapter name
# from the Network Connections panel
# if you have more than one.  On XP SP2,
# you may need to disable the firewall
# for the TAP adapter.
;dev-node MyTap

# Are we connecting to a TCP or
# UDP server?  Use the same setting as
# on the server.
;proto tcp
proto udp

# The hostname/IP and port of the server.
# You can have multiple remote entries
# to load balance between the servers.
remote cmonty.selfip.com 1194
;remote my-server-2 1194

# Choose a random host from the remote
# list for load-balancing.  Otherwise
# try hosts in the order specified.
;remote-random

# Keep trying indefinitely to resolve the
# host name of the OpenVPN server.  Very useful
# on machines which are not permanently connected
# to the internet such as laptops.
resolv-retry infinite

# Most clients don't need to bind to
# a specific local port number.
nobind

# Downgrade privileges after initialization (non-Windows only)
;user nobody
;group nogroup

# Try to preserve some state across restarts.
persist-key
persist-tun

# If you are connecting through an
# HTTP proxy to reach the actual OpenVPN
# server, put the proxy server/IP and
# port number here.  See the man page
# if your proxy server requires
# authentication.
;http-proxy-retry # retry on connection failures
;http-proxy [proxy server] [proxy port #]

# Wireless networks often produce a lot
# of duplicate packets.  Set this flag
# to silence duplicate packet warnings.
;mute-replay-warnings

# SSL/TLS parms.
# See the server config file for more
# description.  It's best to use
# a separate .crt/.key file pair
# for each client.  A single ca
# file can be used for all clients.
ca ca.crt
cert pc1-gigabyte.crt
key pc1-gigabyte.key

# Verify server certificate by checking
# that the certicate has the nsCertType
# field set to "server".  This is an
# important precaution to protect against
# a potential attack discussed here:
#  http://openvpn.net/howto.html#mitm
#
# To use this feature, you will need to generate
# your server certificates with the nsCertType
# field set to "server".  The build-key-server
# script in the easy-rsa folder will do this.
ns-cert-type server

# If a tls-auth key is used on the server
# then every client must also have the key.
tls-auth ta.key 1

# Select a cryptographic cipher.
# If the cipher option is used on the server
# then you must also specify it here.
;cipher x

# Enable compression on the VPN link.
# Don't enable this unless it is also
# enabled in the server config file.
comp-lzo

# Set log file verbosity.
verb 3

# Silence repeating messages
;mute 20

Ist die Ursache des Fehlers zu suchen im Zusammenhang mit der Konfiguration von "VPN IP-Adressen und Routing im VPN" und steht damit in Zusammenhang mit diesem Thread?
 
Zuletzt bearbeitet:
@c.monty
Machst Du jetzt für jede Frage zu Deinem VPN einen neuen Thread auf? Und das auch noch, bevor Du überhaupt versucht hast, selbst etwas zu tun?
 
Nun, ich habe in der Annahme gehandelt, verschieden Probleme in verschiedenen Threads zu dokumentieren, um dadurch die Übersichtlichkeit zu erhöhen.
Selbstverständlich haben die Threads ein gemeinsames Thema: OpenVPN.
Aber die Fehlermeldungen stehen (vermeintlich) in keinem direkten Zusammehang, deshalb die verschiedenen Threads.

Und die Aussage, dass ich nichts versuche, um das Problem zu beheben, ist so nicht richtig.
Denn ich habe die Empfehlungen, die mir in den anderen Threads gegeben wurden, umgesetzt.
Wenn sich daraus neue Fehler ergeben, dann kann man hieraus nicht die Schlussfolgerung ziehen, dass ich nichts mache.
 
Ich kann versichern, dass ich die Internet-Suche und die Suche hier im Forum bemüht habe.
Nur weil ich die offensichtliche Lösung nicht gefunden habe bedeutet das nicht automatisch, dass ich mich nicht darum bemüht hätte, eine Lösung zu suchen.
Die Thematik ist (zumindest für mich) nicht trivial, und ich habe zumindest den Anspruch zu verstehen, welche Auswirkung eine Empfehlung hat.

Wenn ich eine verständliche Lösung für mein Problem gefunden hätte, dann hätte ich dies ohne Zögern in meinem Posting dokumentiert.

Meine anderen Posting sollten dieses Verhalten bestätigen, d.h. sobald mir eine Lösung bekannt ist oder bekannt gemacht wird, werden meine Postings entsprechend aktualisiert.

Ich habe bisher ausgesprochen gute Erfahrungen hier im Board gemacht.
Und ich bin auch sehr sicher, dass die Ursache des Problems dieses Threads richtig identifiziert wurde.

Update:
Problem gelöst durch Verwendung von "sudo".
 
Zuletzt bearbeitet:
Kostenlos!

Statistik des Forums

Themen
248,919
Beiträge
2,305,081
Mitglieder
378,640
Neuestes Mitglied
vapep43913