LINUX.ORG.RU

Помогите донастроить VPN

 


0

2

Устанавливал по этой инструкции https://serveradmin.ru/nastroyka-openvpn-na-centos-7/ (только у меня Cent OS 6.9 Final). Сделал сертификаты, лежат в /etc/openvpn/

ca.crt  
client.crt 
client.key 
dh.pem 
server.conf 
server.crt 
server.key

server.conf

mode server
dev tun
server 10.128.0.0 255.255.255.0
push "redirect-gateway def1"
push "dhcp-option DNS 8.8.8.8"
tls-server
ca ca.crt
cert server.crt
key server.key
dh dh.pem
proto tcp-server
port 11941
client-to-client
comp-lzo
keepalive 10 120
verb 4
cipher AES-256-CBC
user nobody
group nogroup
max-clients 10
client.conf
client
proto tcp
dev tun
remote ***.***.***.*** 11941
persist-key
persist-tun
ca ca.crt
cert client.crt
key client.key
cipher AES-256-CBC
comp-lzo
verb 3
В каталоге с client.conf
ca.crt  
client.conf  
client.crt  
client.key
Запускаю на сервере
[root@vps openvpn]# service openvpn start
Starting openvpn:                                          [  OK  ]
[root@vps openvpn]# 
На клиенте
 sudo openvpn --config client.conf

Tue May 16 14:03:23 2017 OpenVPN 2.4.2 x86_64-unknown-linux-gnu [SSL (OpenSSL)] [LZO] [LZ4] [EPOLL] [PKCS11] [MH/PKTINFO] [AEAD] built on May 11 2017
Tue May 16 14:03:23 2017 library versions: OpenSSL 1.1.0e  16 Feb 2017, LZO 2.10
Tue May 16 14:03:23 2017 WARNING: No server certificate verification method has been enabled.  See http://openvpn.net/howto.html#mitm for more info.
Enter Private Key Password: **********
Tue May 16 14:03:27 2017 WARNING: this configuration may cache passwords in memory -- use the auth-nocache option to prevent this
Tue May 16 14:03:27 2017 TCP/UDP: Preserving recently used remote address: [AF_INET]***.***.***.***:11941
Tue May 16 14:03:27 2017 Socket Buffers: R=[87380->87380] S=[16384->16384]
Tue May 16 14:03:27 2017 Attempting to establish TCP connection with [AF_INET]***.***.***.***:11941 [nonblock]
Tue May 16 14:03:28 2017 TCP: connect to [AF_INET]***.***.***.***:11941 failed: Connection refused
Tue May 16 14:03:28 2017 SIGUSR1[connection failed(soft),init_instance] received, process restarting
Tue May 16 14:03:28 2017 Restart pause, 5 second(s)
Tue May 16 14:03:33 2017 WARNING: No server certificate verification method has been enabled.  See http://openvpn.net/howto.html#mitm for more info.
Tue May 16 14:03:33 2017 TCP/UDP: Preserving recently used remote address: [AF_INET]***.***.***.***:11941
Tue May 16 14:03:33 2017 Socket Buffers: R=[87380->87380] S=[16384->16384]
Tue May 16 14:03:33 2017 Attempting to establish TCP connection with [AF_INET]***.***.***.***:11941 [nonblock]
Tue May 16 14:03:34 2017 TCP: connect to [AF_INET]***.***.***.***:11941 failed: Connection refused
Tue May 16 14:03:34 2017 SIGUSR1[connection failed(soft),init_instance] received, process restarting
Tue May 16 14:03:34 2017 Restart pause, 5 second(s)
^CTue May 16 14:03:35 2017 SIGINT[hard,init_instance] received, process exiting

★★★★

а на сервере какой лог?

ving2
()
Ответ на: комментарий от IPR

Да с чего бы он на впс блокировал порты? Тем более джаббер работает, сайт работает.

А домашний провайдер точно ничего не блокирует. К другому впну подключается.

dnb ★★★★
() автор топика
Последнее исправление: dnb (всего исправлений: 1)
Ответ на: комментарий от anonymous

verify-x509-name?
На это клиент вроде (судя по логу) только варнинг кидает, продолжает коннектиться, и уже потом отлуп от сервера получает.
Хотя вообще странно что он без verify-x509-name вообще пытается подключаться

MrClon ★★★★★
()
Ответ на: комментарий от MrClon

Я iptables отключил.

# Generated by iptables-save v1.4.7 on Tue May 16 16:20:42 2017
*raw
:PREROUTING ACCEPT [4580:591768]
:OUTPUT ACCEPT [4255:636352]
COMMIT
# Completed on Tue May 16 16:20:42 2017
# Generated by iptables-save v1.4.7 on Tue May 16 16:20:42 2017
*nat
:PREROUTING ACCEPT [407:25019]
:POSTROUTING ACCEPT [315:19730]
:OUTPUT ACCEPT [315:19730]
COMMIT
# Completed on Tue May 16 16:20:42 2017
# Generated by iptables-save v1.4.7 on Tue May 16 16:20:42 2017
*mangle
:PREROUTING ACCEPT [4580:591768]
:INPUT ACCEPT [4580:591768]
:FORWARD ACCEPT [0:0]
:OUTPUT ACCEPT [4255:636352]
:POSTROUTING ACCEPT [4255:636352]
COMMIT
# Completed on Tue May 16 16:20:42 2017
# Generated by iptables-save v1.4.7 on Tue May 16 16:20:42 2017
*filter
:INPUT ACCEPT [4580:591768]
:FORWARD ACCEPT [0:0]
:OUTPUT ACCEPT [4255:636352]
COMMIT
# Completed on Tue May 16 16:20:42 2017
[root@vps ~]# 

dnb ★★★★
() автор топика
Ответ на: комментарий от MrClon

Я не знаю как показать лог с сервера, с /var/log/ пусто. Там только логи самбы, httpd и yum.log

Клиент

Wed May 17 08:56:29 2017 OpenVPN 2.4.2 x86_64-unknown-linux-gnu [SSL (OpenSSL)] [LZO] [LZ4] [EPOLL] [PKCS11] [MH/PKTINFO] [AEAD] built on May 11 2017
Wed May 17 08:56:29 2017 library versions: OpenSSL 1.1.0e  16 Feb 2017, LZO 2.10
Wed May 17 08:56:29 2017 WARNING: No server certificate verification method has been enabled.  See http://openvpn.net/howto.html#mitm for more info.
Enter Private Key Password: **********
Wed May 17 08:56:33 2017 WARNING: this configuration may cache passwords in memory -- use the auth-nocache option to prevent this
Wed May 17 08:56:33 2017 TCP/UDP: Preserving recently used remote address: [AF_INET]ip:11941
Wed May 17 08:56:33 2017 Socket Buffers: R=[87380->87380] S=[16384->16384]
Wed May 17 08:56:33 2017 Attempting to establish TCP connection with [AF_INET]ip:11941 [nonblock]
Wed May 17 08:56:34 2017 TCP: connect to [AF_INET]ip:11941 failed: Connection refused
Wed May 17 08:56:34 2017 SIGUSR1[connection failed(soft),init_instance] received, process restarting
Wed May 17 08:56:34 2017 Restart pause, 5 second(s)
^CWed May 17 08:56:35 2017 SIGINT[hard,init_instance] received, process exiting

dnb ★★★★
() автор топика
Ответ на: комментарий от Deleted

Добавил, не помогло.

dnb ★★★★
() автор топика

с клиента, покажи выхлоп

nmap -p 11941 -sU -P0 $IP_VPN 
добавь в серверный конфиг по логам
status /var/log/openvpn/openvpn-status.log
log-append /var/log/openvpn/openvpn.log 

ving2
()
Вы не можете добавлять комментарии в эту тему. Тема перемещена в архив.