На VPS поднял OpenVPN сервер
root@vps48680:~# uname -a
Linux vps48680.hyperhost.name 3.10.0-1160.21.1.vz7.174.13 #1 SMP Thu Apr 22 16:18:59 MSK 2021 x86_64 x86_64 x86_64 GNU/Linux
root@vps48680:~# iptables -L -n -v
Chain INPUT (policy ACCEPT 39453 packets, 2689K bytes)
pkts bytes target prot opt in out source destination
1563 198K ACCEPT tcp – * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:1194
Chain FORWARD (policy ACCEPT 0 packets, 0 bytes)
pkts bytes target prot opt in out source destination
9 756 ACCEPT all – * * 0.0.0.0/0 0.0.0.0/0 state RELATED,ESTABLISHED
1207 88644 ACCEPT all – * * 10.8.0.0/24 0.0.0.0/0
Chain OUTPUT (policy ACCEPT 42753 packets, 3636K bytes)
pkts bytes target prot opt in out source destination
Цепанул к нему клиента:
Dec 23 13:41:18 vps48680.hyperhost.name openvpn[81017]: TCP connection established with [AF_INET]XX.XX.XX.XX:49775
Dec 23 13:41:18 vps48680.hyperhost.name openvpn[81017]: XX.XX.XX.XX:49775 TLS: Initial packet from [AF_INET]XX.XX.XX.XX:49775, sid=a>
Dec 23 13:41:18 vps48680.hyperhost.name openvpn[81017]: XX.XX.XX.XX:49775 VERIFY OK: depth=1, CN=ChangeMe
Dec 23 13:41:18 vps48680.hyperhost.name openvpn[81017]: XX.XX.XX.XX:49775 VERIFY OK: depth=0, CN=roman
Dec 23 13:41:18 vps48680.hyperhost.name openvpn[81017]: XX.XX.XX.XX:49775 peer info: IV_VER=2.5.3
Dec 23 13:41:18 vps48680.hyperhost.name openvpn[81017]: XX.XX.XX.XX:49775 peer info: IV_PLAT=linux
Dec 23 13:41:18 vps48680.hyperhost.name openvpn[81017]: XX.XX.XX.XX:49775 peer info: IV_PROTO=6
Dec 23 13:41:18 vps48680.hyperhost.name openvpn[81017]: XX.XX.XX.XX:49775 peer info: IV_NCP=2
Dec 23 13:41:18 vps48680.hyperhost.name openvpn[81017]: XX.XX.XX.XX:49775 peer info: IV_CIPHERS=AES-256-GCM:AES-128-GCM:AES-256-CBC
Dec 23 13:41:18 vps48680.hyperhost.name openvpn[81017]: XX.XX.XX.XX:49775 peer info: IV_LZ4=1
Dec 23 13:41:18 vps48680.hyperhost.name openvpn[81017]: XX.XX.XX.XX:49775 peer info: IV_LZ4v2=1
Dec 23 13:41:18 vps48680.hyperhost.name openvpn[81017]: XX.XX.XX.XX:49775 peer info: IV_LZO=1
Dec 23 13:41:18 vps48680.hyperhost.name openvpn[81017]: XX.XX.XX.XX:49775 peer info: IV_COMP_STUB=1
Dec 23 13:41:18 vps48680.hyperhost.name openvpn[81017]: XX.XX.XX.XX:49775 peer info: IV_COMP_STUBv2=1
Dec 23 13:41:18 vps48680.hyperhost.name openvpn[81017]: XX.XX.XX.XX:49775 peer info: IV_TCPNL=1
Dec 23 13:41:19 vps48680.hyperhost.name openvpn[81017]: XX.XX.XX.XX:49775 Control Channel: TLSv1.3, cipher TLSv1.3 TLS_AES_256_GCM_S>
Dec 23 13:41:19 vps48680.hyperhost.name openvpn[81017]: XX.XX.XX.XX:49775 [roman] Peer Connection Initiated with [AF_INET]XX.XX.XX.XX>
Dec 23 13:41:19 vps48680.hyperhost.name openvpn[81017]: roman/XX.XX.XX.XX:49775 MULTI_sva: pool returned IPv4=10.8.0.2, IPv6=(Not en>
Dec 23 13:41:19 vps48680.hyperhost.name openvpn[81017]: roman/XX.XX.XX.XX:49775 MULTI: Learn: 10.8.0.2 -> roman/XX.XX.XX.XX:49775
Dec 23 13:41:19 vps48680.hyperhost.name openvpn[81017]: roman/XX.XX.XX.XX:49775 MULTI: primary virtual IP for roman/XX.XX.XX.XX:4977>
Dec 23 13:41:20 vps48680.hyperhost.name openvpn[81017]: roman/XX.XX.XX.XX:49775 PUSH: Received control message: ‘PUSH_REQUEST’
Dec 23 13:41:20 vps48680.hyperhost.name openvpn[81017]: roman/XX.XX.XX.XX:49775 SENT CONTROL [roman]: ’PUSH_REPLY,redirect-gateway d>
Dec 23 13:41:20 vps48680.hyperhost.name openvpn[81017]: roman/XX.XX.XX.XX:49775 Data Channel: using negotiated cipher ‘AES-256-GCM’
Dec 23 13:41:20 vps48680.hyperhost.name openvpn[81017]: roman/XX.XX.XX.XX:49775 Outgoing Data Channel: Cipher ‘AES-256-GCM’ initiali>
Dec 23 13:41:20 vps48680.hyperhost.name openvpn[81017]: roman/XX.XX.XX.XX:49775 Incoming Data Channel: Cipher ‘AES-256-GCM’ initiali>
Вот что при этом виднно на клиенте:
root@porteus:~/Documents# ifconfig
eth0: flags=4163<UP,BROADCAST,RUNNING,MULTICAST> mtu 1500
inet 10.0.2.15 netmask 255.255.255.0 broadcast 10.0.2.255
inet6 fe80::6ac5:89ba:a123:be13 prefixlen 64 scopeid 0x20
ether 08:00:27:1c:37:4c txqueuelen 1000 (Ethernet)
RX packets 136718 bytes 129329649 (123.3 MiB)
RX errors 29 dropped 0 overruns 0 frame 0
TX packets 84435 bytes 8689573 (8.2 MiB)
TX errors 0 dropped 0 overruns 0 carrier 0 collisions 0
device interrupt 19 base 0xd020
lo: flags=73<UP,LOOPBACK,RUNNING> mtu 65536
inet 127.0.0.1 netmask 255.0.0.0
inet6 ::1 prefixlen 128 scopeid 0x10
loop txqueuelen 1000 (Local Loopback)
RX packets 2 bytes 100 (100.0 B)
RX errors 0 dropped 0 overruns 0 frame 0
TX packets 2 bytes 100 (100.0 B)
TX errors 0 dropped 0 overruns 0 carrier 0 collisions 0
tun0: flags=4305<UP,POINTOPOINT,RUNNING,NOARP,MULTICAST> mtu 1500
inet 10.8.0.2 netmask 255.255.255.0 destination 10.8.0.2
inet6 fe80::43d2:8a51:9ba4:1ea prefixlen 64 scopeid 0x20
unspec 00-00-00-00-00-00-00-00-00-00-00-00-00-00-00-00 txqueuelen 500 (UNSPEC)
RX packets 0 bytes 0 (0.0 B)
RX errors 0 dropped 0 overruns 0 frame 0
TX packets 1976 bytes 145413 (142.0 KiB)
TX errors 0 dropped 0 overruns 0 carrier 0 collisions 0
root@porteus:~# ip route
0.0.0.0/1 via 10.8.0.1 dev tun0
default via 10.0.2.2 dev eth0 proto dhcp metric 100
10.0.2.0/24 dev eth0 proto kernel scope link src 10.0.2.15 metric 100
10.8.0.0/24 dev tun0 proto kernel scope link src 10.8.0.2
127.0.0.0/8 dev lo scope link
128.0.0.0/1 via 10.8.0.1 dev tun0
185.237.204.130 via 10.0.2.2 dev eth0
root@porteus:~# iptables -L -n -v
Chain INPUT (policy ACCEPT 286 packets, 36744 bytes)
pkts bytes target prot opt in out source destination
Chain FORWARD (policy ACCEPT 0 packets, 0 bytes)
pkts bytes target prot opt in out source destination
Chain OUTPUT (policy ACCEPT 479 packets, 64102 bytes)
pkts bytes target prot opt in out source destination
root@porteus:~# traceroute 8.8.8.8
traceroute to 8.8.8.8 (8.8.8.8), 30 hops max, 60 byte packets
1 10.8.0.1 (10.8.0.1) 23.929 ms 45.992 ms 45.985 ms
2 82.118.19.13 (82.118.19.13) 45.973 ms 45.138 ms 45.102 ms
3 185.1.63.152 (185.1.63.152) 45.089 ms 44.972 ms 44.923 ms
4 108.170.248.155 (108.170.248.155) 44.881 ms 44.865 ms 44.681 ms
5 72.14.239.111 (72.14.239.111) 44.629 ms 142.251.67.218 (142.251.67.218) 66.488 ms 66.410 ms
6 74.125.242.241 (74.125.242.241) 44.522 ms 46.172 ms 44.439 ms
7 142.251.65.223 (142.251.65.223) 65.300 ms 142.251.228.27 (142.251.228.27) 65.276 ms 216.239.35.183 (216.239.35.183) 65.344 ms
8 8.8.8.8 (8.8.8.8) 65.287 ms 142.251.65.217 (142.251.65.217) 65.286 ms 142.251.65.219 (142.251.65.219) 65.324 ms
Как видно, гугловый ДНС доступен. Но если я в броузере попробую пойти на любой сайт, то долго висит и обламывается с ненаходом сайта. Без VPN сайты открываются мухой. Что я делаю неправильно?