- Mitglied seit
- 22 Jan 2007
- Beiträge
- 378
- Punkte für Reaktionen
- 0
- Punkte
- 16
Hallo!
Die VPN-Verbindung des Clients schlägt fehl.
In der Konsole sehe ich diese Meldungen:
Im Debug-Log des Servers finde ich diese Einträge:
Hier noch die Konfigurations-Dateien von Server und Client:
Ist die Ursache des Fehlers zu suchen im Zusammenhang mit der Konfiguration von "VPN IP-Adressen und Routing im VPN" und steht damit in Zusammenhang mit diesem Thread?
Die VPN-Verbindung des Clients schlägt fehl.
In der Konsole sehe ich diese Meldungen:
Code:
user@pc1 /etc/openvpn $ openvpn client.conf
Thu Nov 14 00:53:02 2013 OpenVPN 2.3.2 i486-pc-linux-gnu [SSL (OpenSSL)] [LZO] [EPOLL] [PKCS11] [eurephia] [MH] [IPv6] built on Jun 21 2013
Thu Nov 14 00:53:02 2013 WARNING: file 'pc1.key' is group or others accessible
Thu Nov 14 00:53:02 2013 WARNING: file 'ta.key' is group or others accessible
Thu Nov 14 00:53:02 2013 Control Channel Authentication: using 'ta.key' as a OpenVPN static key file
Thu Nov 14 00:53:02 2013 Outgoing Control Channel Authentication: Using 160 bit message hash 'SHA1' for HMAC authentication
Thu Nov 14 00:53:02 2013 Incoming Control Channel Authentication: Using 160 bit message hash 'SHA1' for HMAC authentication
Thu Nov 14 00:53:02 2013 Socket Buffers: R=[180224->131072] S=[180224->131072]
Thu Nov 14 00:53:02 2013 UDPv4 link local: [undef]
Thu Nov 14 00:53:02 2013 UDPv4 link remote: [AF_INET]91.89.xxx.xxx:1194
Thu Nov 14 00:53:02 2013 TLS: Initial packet from [AF_INET]91.89.xxx.xxx:1194, sid=af840xxx 762f8xxx
Thu Nov 14 00:53:03 2013 VERIFY OK: depth=1, C=DE, ST=BW, L=STADT, O=mydomain, CN=net2-FB7390, [email protected]
Thu Nov 14 00:53:03 2013 VERIFY OK: nsCertType=SERVER
Thu Nov 14 00:53:03 2013 VERIFY OK: depth=0, C=DE, ST=BW, L=STADT, O=mydomain, CN=server, [email protected]
Thu Nov 14 00:53:04 2013 Data Channel Encrypt: Cipher 'BF-CBC' initialized with 128 bit key
Thu Nov 14 00:53:04 2013 Data Channel Encrypt: Using 160 bit message hash 'SHA1' for HMAC authentication
Thu Nov 14 00:53:04 2013 Data Channel Decrypt: Cipher 'BF-CBC' initialized with 128 bit key
Thu Nov 14 00:53:04 2013 Data Channel Decrypt: Using 160 bit message hash 'SHA1' for HMAC authentication
Thu Nov 14 00:53:04 2013 Control Channel: TLSv1, cipher TLSv1/SSLv3 DHE-RSA-AES256-SHA, 2048 bit RSA
Thu Nov 14 00:53:04 2013 [server] Peer Connection Initiated with [AF_INET]91.89.xxx.xxx:1194
Thu Nov 14 00:53:06 2013 SENT CONTROL [server]: 'PUSH_REQUEST' (status=1)
Thu Nov 14 00:53:06 2013 PUSH: Received control message: 'PUSH_REPLY,route-gateway 10.0.0.1,route 192.168.100.0 255.255.255.0,route 10.0.0.0 255.255.255.0,ping 10,ping-restart 120,route 192.168.100.200 255.255.255.248 10.0.0.11,route 192.168.100.200 255.255.255.248 10.0.0.12,route 192.168.100.200 255.255.255.248 10.0.0.14,route 192.168.100.200 255.255.255.248 10.0.0.15,ifconfig 10.0.0.16 255.255.255.0'
Thu Nov 14 00:53:06 2013 OPTIONS IMPORT: timers and/or timeouts modified
Thu Nov 14 00:53:06 2013 OPTIONS IMPORT: --ifconfig/up options modified
Thu Nov 14 00:53:06 2013 OPTIONS IMPORT: route options modified
Thu Nov 14 00:53:06 2013 OPTIONS IMPORT: route-related options modified
Thu Nov 14 00:53:06 2013 ROUTE_GATEWAY 192.168.100.1/255.255.255.0 IFACE=eth1 HWADDR=00:1a:4d:47:b3:48
Thu Nov 14 00:53:06 2013 ERROR: Cannot ioctl TUNSETIFF tap: Operation not permitted (errno=1)
Thu Nov 14 00:53:06 2013 Exiting due to fatal error
Im Debug-Log des Servers finde ich diese Einträge:
Code:
root@net2-FB7390:/var/mod/root# cat /var/tmp/debug_openvpn.out
Thu Nov 14 00:51:15 2013 OpenVPN 2.3.2 mips-unknown-linux-gnu [SSL (OpenSSL)] [LZO] [IPv6] built on Aug 31 2013
Thu Nov 14 00:51:15 2013 Diffie-Hellman initialized with 2048 bit key
Thu Nov 14 00:51:15 2013 Control Channel Authentication: using '/tmp/flash/openvpn/static.key' as a OpenVPN static key file
Thu Nov 14 00:51:15 2013 Outgoing Control Channel Authentication: Using 160 bit message hash 'SHA1' for HMAC authentication
Thu Nov 14 00:51:15 2013 Incoming Control Channel Authentication: Using 160 bit message hash 'SHA1' for HMAC authentication
Thu Nov 14 00:51:15 2013 Socket Buffers: R=[202752->131072] S=[202752->131072]
Thu Nov 14 00:51:15 2013 TUN/TAP device tap0 opened
Thu Nov 14 00:51:15 2013 TUN/TAP TX queue length set to 100
Thu Nov 14 00:51:15 2013 do_ifconfig, tt->ipv6=0, tt->did_ifconfig_ipv6_setup=0
Thu Nov 14 00:51:15 2013 /sbin/ifconfig tap0 10.0.0.1 netmask 255.255.255.0 mtu 1500 broadcast 10.0.0.255
Thu Nov 14 00:51:15 2013 /sbin/route add -net 192.168.100.200 netmask 255.255.255.248 gw 10.0.0.11
Thu Nov 14 00:51:15 2013 /sbin/route add -net 192.168.100.200 netmask 255.255.255.248 gw 10.0.0.12
Thu Nov 14 00:51:15 2013 /sbin/route add -net 192.168.100.200 netmask 255.255.255.248 gw 10.0.0.14
Thu Nov 14 00:51:15 2013 /sbin/route add -net 192.168.100.200 netmask 255.255.255.248 gw 10.0.0.15
Thu Nov 14 00:51:15 2013 /sbin/route add -net 192.168.100.200 netmask 255.255.255.248 gw 10.0.0.16
Thu Nov 14 00:51:15 2013 chroot to '/tmp/openvpn' and cd to '/' succeeded
Thu Nov 14 00:51:15 2013 GID set to openvpn
Thu Nov 14 00:51:15 2013 UID set to openvpn
Thu Nov 14 00:51:15 2013 UDPv4 link local (bound): [undef]
Thu Nov 14 00:51:15 2013 UDPv4 link remote: [undef]
Thu Nov 14 00:51:15 2013 MULTI: multi_init called, r=256 v=256
Thu Nov 14 00:51:15 2013 IFCONFIG POOL: base=10.0.0.10 size=11, ipv6=0
Thu Nov 14 00:51:15 2013 Initialization Sequence Completed
Thu Nov 14 00:51:23 2013 TLS Error: cannot locate HMAC in incoming packet from [AF_INET]91.89.xxx.xxx:54337
Thu Nov 14 00:51:39 2013 TLS Error: cannot locate HMAC in incoming packet from [AF_INET]91.89.xxx.xxx:54337
[...]
Thu Nov 14 00:52:41 2013 TLS Error: cannot locate HMAC in incoming packet from [AF_INET]91.89.xxx.xxx:56875
Thu Nov 14 00:53:02 2013 91.89.xxx.xxx:55425 TLS: Initial packet from [AF_INET]91.89.xxx.xxx:55425, sid=55dc5xxx e2b1axxx
Thu Nov 14 00:53:03 2013 91.89.xxx.xxx:55425 VERIFY OK: depth=1, C=DE, ST=BW, L=STADT, O=mydomain, CN=net2-FB7390, [email protected]
Thu Nov 14 00:53:03 2013 91.89.xxx.xxx:55425 VERIFY OK: depth=0, C=DE, ST=BW, L=STADT, O=awesomeguyz, CN=pc1, [email protected]
Thu Nov 14 00:53:04 2013 91.89.xxx.xxx:55425 Data Channel Encrypt: Cipher 'BF-CBC' initialized with 128 bit key
Thu Nov 14 00:53:04 2013 91.89.xxx.xxx:55425 Data Channel Encrypt: Using 160 bit message hash 'SHA1' for HMAC authentication
Thu Nov 14 00:53:04 2013 91.89.xxx.xxx:55425 Data Channel Decrypt: Cipher 'BF-CBC' initialized with 128 bit key
Thu Nov 14 00:53:04 2013 91.89.xxx.xxx:55425 Data Channel Decrypt: Using 160 bit message hash 'SHA1' for HMAC authentication
Thu Nov 14 00:53:04 2013 91.89.xxx.xxx:55425 Control Channel: TLSv1, cipher TLSv1/SSLv3 DHE-RSA-AES256-SHA, 2048 bit RSA
Thu Nov 14 00:53:04 2013 91.89.xxx.xxx:55425 [pc1-gigabyte] Peer Connection Initiated with [AF_INET]91.89.xxx.xxx:55425
Thu Nov 14 00:53:04 2013 pc1/91.89.xxx.xxx:55425 OPTIONS IMPORT: reading client specific options from: /clients_openvpn/pc1-gigabyte
Thu Nov 14 00:53:06 2013 pc1/91.89.xxx.xxx:55425 PUSH: Received control message: 'PUSH_REQUEST'
Thu Nov 14 00:53:06 2013 pc1/91.89.xxx.xxx:55425 send_push_reply(): safe_cap=940
Thu Nov 14 00:53:06 2013 pc1/91.89.xxx.xxx:55425 SENT CONTROL [pc1]: 'PUSH_REPLY,route-gateway 10.0.0.1,route 192.168.100.0 255.255.255.0,route 10.0.0.0 255.255.255.0,ping 10,ping-restart 120,route 192.168.100.200 255.255.255.248 10.0.0.11,route 192.168.100.200 255.255.255.248 10.0.0.12,route 192.168.100.200 255.255.255.248 10.0.0.14,route 192.168.100.200 255.255.255.248 10.0.0.15,ifconfig 10.0.0.16 255.255.255.0' (status=1)
Thu Nov 14 00:53:13 2013 TLS Error: cannot locate HMAC in incoming packet from [AF_INET]91.89.xxx.xxx:40083
Hier noch die Konfigurations-Dateien von Server und Client:
Code:
server.conf
root@net2-FB7390:/var/mod/root# cat /var/mod/etc/openvpn.conf
# OpenVPN 2.1 Config, Thu Nov 14 00:51:14 CET 2013
proto udp
dev tap0
#Helperline for rc.openvpn to add tap0 to lan bridge
dev-node /dev/tun
ca /tmp/flash/openvpn/ca.crt
cert /tmp/flash/openvpn/box.crt
key /tmp/flash/openvpn/box.key
dh /tmp/flash/openvpn/dh.pem
tls-server
tls-auth /tmp/flash/openvpn/static.key 0
port 1194
ifconfig 10.0.0.1 255.255.255.0
push "route-gateway 10.0.0.1"
push "route 192.168.100.0 255.255.255.0"
max-clients 7
mode server
ifconfig-pool 10.0.0.10 10.0.0.20
push "route 10.0.0.0 255.255.255.0"
client-config-dir /clients_openvpn
route 192.168.100.200 255.255.255.248 10.0.0.11
route 192.168.100.200 255.255.255.248 10.0.0.12
route 192.168.100.200 255.255.255.248 10.0.0.14
route 192.168.100.200 255.255.255.248 10.0.0.15
route 192.168.100.200 255.255.255.248 10.0.0.16
client-to-client
tun-mtu 1500
mssfix
log /var/tmp/debug_openvpn.out
verb 3
cipher BF-CBC
comp-lzo
keepalive 10 120
status /var/log/openvpn.log
chroot /tmp/openvpn
user openvpn
group openvpn
persist-tun
persist-key
Code:
client.conf
user@pc1 /etc/openvpn $ cat client.conf
##############################################
# Sample client-side OpenVPN 2.0 config file #
# for connecting to multi-client server. #
# #
# This configuration can be used by multiple #
# clients, however each client should have #
# its own cert and key files. #
# #
# On Windows, you might want to rename this #
# file so it has a .ovpn extension #
##############################################
# Specify that we are a client and that we
# will be pulling certain config file directives
# from the server.
client
# Use the same setting as you are using on
# the server.
# On most systems, the VPN will not function
# unless you partially or fully disable
# the firewall for the TUN/TAP interface.
dev tap
;dev tun
# Windows needs the TAP-Win32 adapter name
# from the Network Connections panel
# if you have more than one. On XP SP2,
# you may need to disable the firewall
# for the TAP adapter.
;dev-node MyTap
# Are we connecting to a TCP or
# UDP server? Use the same setting as
# on the server.
;proto tcp
proto udp
# The hostname/IP and port of the server.
# You can have multiple remote entries
# to load balance between the servers.
remote cmonty.selfip.com 1194
;remote my-server-2 1194
# Choose a random host from the remote
# list for load-balancing. Otherwise
# try hosts in the order specified.
;remote-random
# Keep trying indefinitely to resolve the
# host name of the OpenVPN server. Very useful
# on machines which are not permanently connected
# to the internet such as laptops.
resolv-retry infinite
# Most clients don't need to bind to
# a specific local port number.
nobind
# Downgrade privileges after initialization (non-Windows only)
;user nobody
;group nogroup
# Try to preserve some state across restarts.
persist-key
persist-tun
# If you are connecting through an
# HTTP proxy to reach the actual OpenVPN
# server, put the proxy server/IP and
# port number here. See the man page
# if your proxy server requires
# authentication.
;http-proxy-retry # retry on connection failures
;http-proxy [proxy server] [proxy port #]
# Wireless networks often produce a lot
# of duplicate packets. Set this flag
# to silence duplicate packet warnings.
;mute-replay-warnings
# SSL/TLS parms.
# See the server config file for more
# description. It's best to use
# a separate .crt/.key file pair
# for each client. A single ca
# file can be used for all clients.
ca ca.crt
cert pc1-gigabyte.crt
key pc1-gigabyte.key
# Verify server certificate by checking
# that the certicate has the nsCertType
# field set to "server". This is an
# important precaution to protect against
# a potential attack discussed here:
# http://openvpn.net/howto.html#mitm
#
# To use this feature, you will need to generate
# your server certificates with the nsCertType
# field set to "server". The build-key-server
# script in the easy-rsa folder will do this.
ns-cert-type server
# If a tls-auth key is used on the server
# then every client must also have the key.
tls-auth ta.key 1
# Select a cryptographic cipher.
# If the cipher option is used on the server
# then you must also specify it here.
;cipher x
# Enable compression on the VPN link.
# Don't enable this unless it is also
# enabled in the server config file.
comp-lzo
# Set log file verbosity.
verb 3
# Silence repeating messages
;mute 20
Ist die Ursache des Fehlers zu suchen im Zusammenhang mit der Konfiguration von "VPN IP-Adressen und Routing im VPN" und steht damit in Zusammenhang mit diesem Thread?
Zuletzt bearbeitet: