Хостится это говно в амстердаме у digitalocean. После того как в 100500 раз эта херня не заработала по документации, я просто решил сделать по инструкции. Всё равно не работает. Соединение проходит, ip не меняется. Почему эта фигня не работает?
Лог клиента:
[romashev@dell ~]$ sudo openvpn ./amsterdam.ovpn
Thu Sep 22 14:11:28 2016 OpenVPN 2.3.12 x86_64-unknown-linux-gnu [SSL (OpenSSL)] [LZO] [EPOLL] [PKCS11] [MH] [IPv6] built on Aug 24 2016
Thu Sep 22 14:11:28 2016 library versions: OpenSSL 1.0.2h 3 May 2016, LZO 2.09
Thu Sep 22 14:11:28 2016 Control Channel Authentication: using 'ta.key' as a OpenVPN static key file
Thu Sep 22 14:11:28 2016 Outgoing Control Channel Authentication: Using 160 bit message hash 'SHA1' for HMAC authentication
Thu Sep 22 14:11:28 2016 Incoming Control Channel Authentication: Using 160 bit message hash 'SHA1' for HMAC authentication
Thu Sep 22 14:11:28 2016 Socket Buffers: R=[212992->212992] S=[212992->212992]
Thu Sep 22 14:11:28 2016 UDPv4 link local: [undef]
Thu Sep 22 14:11:28 2016 UDPv4 link remote: [AF_INET]95.85.7.38:1194
Thu Sep 22 14:11:28 2016 TLS: Initial packet from [AF_INET]95.85.7.38:1194, sid=5fea5ab2 9afb7da8
Thu Sep 22 14:11:28 2016 VERIFY OK: depth=1, CN=Unknown CA
Thu Sep 22 14:11:28 2016 Validating certificate key usage
Thu Sep 22 14:11:28 2016 ++ Certificate has key usage 00a0, expects 00a0
Thu Sep 22 14:11:28 2016 VERIFY KU OK
Thu Sep 22 14:11:28 2016 Validating certificate extended key usage
Thu Sep 22 14:11:28 2016 ++ Certificate has EKU (str) TLS Web Server Authentication, expects TLS Web Server Authentication
Thu Sep 22 14:11:28 2016 VERIFY EKU OK
Thu Sep 22 14:11:28 2016 VERIFY OK: depth=0, CN=vpn-server
Thu Sep 22 14:11:28 2016 Data Channel Encrypt: Cipher 'BF-CBC' initialized with 128 bit key
Thu Sep 22 14:11:28 2016 WARNING: this cipher's block size is less than 128 bit (64 bit). Consider using a --cipher with a larger block size.
Thu Sep 22 14:11:28 2016 Data Channel Encrypt: Using 160 bit message hash 'SHA1' for HMAC authentication
Thu Sep 22 14:11:28 2016 Data Channel Decrypt: Cipher 'BF-CBC' initialized with 128 bit key
Thu Sep 22 14:11:28 2016 WARNING: this cipher's block size is less than 128 bit (64 bit). Consider using a --cipher with a larger block size.
Thu Sep 22 14:11:28 2016 Data Channel Decrypt: Using 160 bit message hash 'SHA1' for HMAC authentication
Thu Sep 22 14:11:28 2016 Control Channel: TLSv1.2, cipher TLSv1/SSLv3 DHE-RSA-AES256-GCM-SHA384, 2048 bit RSA
Thu Sep 22 14:11:28 2016 [vpn-server] Peer Connection Initiated with [AF_INET]95.85.7.38:1194
Thu Sep 22 14:11:31 2016 SENT CONTROL [vpn-server]: 'PUSH_REQUEST' (status=1)
Thu Sep 22 14:11:31 2016 PUSH: Received control message: 'PUSH_REPLY,dhcp-option DNS 192.168.0.1,dhcp-option DOMAIN mydomain.com,route 192.168.0.0 255.255.254.0,route 10.15.0.1,topology net30,ping 10,ping-restart 900,ifconfig 10.15.0.6 10.15.0.5'
Thu Sep 22 14:11:31 2016 OPTIONS IMPORT: timers and/or timeouts modified
Thu Sep 22 14:11:31 2016 OPTIONS IMPORT: --ifconfig/up options modified
Thu Sep 22 14:11:31 2016 OPTIONS IMPORT: route options modified
Thu Sep 22 14:11:31 2016 OPTIONS IMPORT: --ip-win32 and/or --dhcp-option options modified
Thu Sep 22 14:11:31 2016 ROUTE_GATEWAY 192.168.43.1/255.255.255.0 IFACE=wlp2s0 HWADDR=b8:81:98:84:c9:20
Thu Sep 22 14:11:31 2016 TUN/TAP device tun0 opened
Thu Sep 22 14:11:31 2016 TUN/TAP TX queue length set to 100
Thu Sep 22 14:11:31 2016 do_ifconfig, tt->ipv6=0, tt->did_ifconfig_ipv6_setup=0
Thu Sep 22 14:11:31 2016 /usr/bin/ip link set dev tun0 up mtu 1500
Thu Sep 22 14:11:31 2016 /usr/bin/ip addr add dev tun0 local 10.15.0.6 peer 10.15.0.5
Thu Sep 22 14:11:31 2016 /usr/bin/ip route add 192.168.0.0/23 via 10.15.0.5
Thu Sep 22 14:11:31 2016 /usr/bin/ip route add 10.15.0.1/32 via 10.15.0.5
Thu Sep 22 14:11:31 2016 Initialization Sequence Completed
Какие ещё логи нужны?
P.S. Кто поможет, тому дам серты для подключения, таки халявный VPN.
UPD: Добавил в конфиг сервера push «redirect-gateway def1», интернета при коннекте к серверу openvpn нет.