Здравствуйте, помогите разобраться подымаю 3 ovpn сервер правда этот на dd-wrt столкнулся с такой проблеммой:
Клиент конектится к серверу получает IP маску, но не получает шлюза по умолчанию, после конекта клиент и сервер друг друга не видят тоесть 10.10.14.1\24 не пингует 10.10.14.2\24 и на оборот.
Конфиг сервера:
mode server
proto tcp
port 1194
dev tap0
keepalive 15 60
server 10.10.14.0 255.255.255.0
push "route-gateway 10.10.14.1"
verb 3
comp-lzo
tls-server
daemon
persist-key
persist-tun
client-to-client
duplicate-cn
ca /jffs/ca.crt
dh /jffs/dh1024.pem
cert /jffs/*****.crt
key /jffs/*****.key
Конфиг клиента:
client
tls-client
dev tap0
proto tcp
remote ********* 1194
route-gateway 10.10.14.1
resolv-retry infinite
nobind
route-method exe
route-delay 2
persist-key
persist-tun
comp-lzo
verb 3
ca ca.crt
cert buh.crt
key buh.key
Интерфейсы на сервере:
ath0 Link encap:Ethernet HWaddr 54:E6:FC:AE:54:FA
UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1
RX packets:0 errors:0 dropped:0 overruns:0 frame:0
TX packets:34288 errors:0 dropped:0 overruns:0 carrier:0
collisions:0 txqueuelen:1000
RX bytes:0 (0.0 B) TX bytes:2403735 (2.2 MiB)
br0 Link encap:Ethernet HWaddr 54:E6:FC:AE:54:FA
inet addr:192.168.0.1 Bcast:192.168.0.255 Mask:255.255.255.0
UP BROADCAST RUNNING PROMISC MULTICAST MTU:1500 Metric:1
RX packets:59722 errors:0 dropped:0 overruns:0 frame:0
TX packets:39683 errors:0 dropped:0 overruns:0 carrier:0
collisions:0 txqueuelen:0
RX bytes:32918583 (31.3 MiB) TX bytes:16478437 (15.7 MiB)
br0:0 Link encap:Ethernet HWaddr 54:E6:FC:AE:54:FA
inet addr:169.254.255.1 Bcast:169.254.255.255 Mask:255.255.0.0
UP BROADCAST RUNNING PROMISC MULTICAST MTU:1500 Metric:1
eth0 Link encap:Ethernet HWaddr 54:E6:FC:AE:54:FA
UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1
RX packets:163287 errors:0 dropped:0 overruns:0 frame:0
TX packets:98970 errors:0 dropped:0 overruns:0 carrier:0
collisions:0 txqueuelen:1000
RX bytes:54942149 (52.3 MiB) TX bytes:50949361 (48.5 MiB)
lo Link encap:Local Loopback
inet addr:127.0.0.1 Mask:255.0.0.0
UP LOOPBACK RUNNING MULTICAST MTU:16436 Metric:1
RX packets:1 errors:0 dropped:0 overruns:0 frame:0
TX packets:1 errors:0 dropped:0 overruns:0 carrier:0
collisions:0 txqueuelen:0
RX bytes:88 (88.0 B) TX bytes:88 (88.0 B)
tap0 Link encap:Ethernet HWaddr DA:1F:B7:33:FF:1F
inet addr:10.10.14.1 Bcast:10.10.14.255 Mask:255.255.255.0
UP BROADCAST RUNNING PROMISC MULTICAST MTU:1500 Metric:1
RX packets:123 errors:0 dropped:0 overruns:0 frame:0
TX packets:34115 errors:0 dropped:2 overruns:0 carrier:0
collisions:0 txqueuelen:100
RX bytes:15483 (15.1 KiB) TX bytes:2374687 (2.2 MiB)
vlan1 Link encap:Ethernet HWaddr 54:E6:FC:AE:54:FA
UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1
RX packets:59609 errors:0 dropped:0 overruns:0 frame:0
TX packets:54283 errors:0 dropped:0 overruns:0 carrier:0
collisions:0 txqueuelen:0
RX bytes:33177948 (31.6 MiB) TX bytes:17461655 (16.6 MiB)
vlan2 Link encap:Ethernet HWaddr 54:E6:FC:AE:54:FB
inet addr:79.122.131.180 Bcast:79.122.131.183 Mask:255.255.255.248
UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1
RX packets:103678 errors:0 dropped:0 overruns:0 frame:0
TX packets:44687 errors:0 dropped:0 overruns:0 carrier:0
collisions:0 txqueuelen:0
RX bytes:19478183 (18.5 MiB) TX bytes:33487706 (31.9 MiB)
wifi0 Link encap:Ethernet HWaddr 54:E6:FC:AE:54:FA
UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1
RX packets:7 errors:0 dropped:0 overruns:0 frame:61807
TX packets:34317 errors:0 dropped:0 overruns:0 carrier:0
collisions:0 txqueuelen:1000
RX bytes:322 (322.0 B) TX bytes:3710837 (3.5 MiB)
Interrupt:2 Memory:b80c0000-b8100000
Логи клиента при подключении:
Sun Apr 03 16:49:06 2011 OpenVPN 2.1.4 i686-pc-mingw32 [SSL] [LZO2] [PKCS11] built on Nov 8 2010
Sun Apr 03 16:49:06 2011 WARNING: No server certificate verification method has been enabled. See
http://openvpn.net/howto.html#mitm for more info.
Sun Apr 03 16:49:06 2011 NOTE: OpenVPN 2.1 requires '--script-security 2' or higher to call user-defined scripts or executables
Sun Apr 03 16:49:06 2011 LZO compression initialized
Sun Apr 03 16:49:06 2011 Control Channel MTU parms [ L:1576 D:140 EF:40 EB:0 ET:0 EL:0 ]
Sun Apr 03 16:49:06 2011 Socket Buffers: R=[8192->8192] S=[8192->8192]
Sun Apr 03 16:49:06 2011 Data Channel MTU parms [ L:1576 D:1450 EF:44 EB:135 ET:32 EL:0 AF:3/1 ]
Sun Apr 03 16:49:06 2011 Local Options hash (VER=V4): '31fdf004'
Sun Apr 03 16:49:06 2011 Expected Remote Options hash (VER=V4): '3e6d1056'
Sun Apr 03 16:49:06 2011 Attempting to establish TCP connection with 79.122.131.180:1194
Sun Apr 03 16:49:06 2011 TCP connection established with 79.122.131.180:1194
Sun Apr 03 16:49:06 2011 TCPv4_CLIENT link local: [undef]
Sun Apr 03 16:49:06 2011 TCPv4_CLIENT link remote: 79.122.131.180:1194
Sun Apr 03 16:49:06 2011 TLS: Initial packet from 79.122.131.180:1194, sid=da422583 83aec517
Sun Apr 03 16:49:07 2011 VERIFY OK: depth=1, /C=RU/ST=RU/L=Omsk/O=Nagaev/CN=Nagaev/emailAddress=admin@enima.ru
Sun Apr 03 16:49:07 2011 VERIFY OK: depth=0, /C=RU/ST=RU/L=Omsk/O=Nagaev/CN=Nagaev/emailAddress=admin@enima.ru
Sun Apr 03 16:50:04 2011 Data Channel Encrypt: Cipher 'BF-CBC' initialized with 128 bit key
Sun Apr 03 16:50:04 2011 Data Channel Encrypt: Using 160 bit message hash 'SHA1' for HMAC authentication
Sun Apr 03 16:50:04 2011 Data Channel Decrypt: Cipher 'BF-CBC' initialized with 128 bit key
Sun Apr 03 16:50:04 2011 Data Channel Decrypt: Using 160 bit message hash 'SHA1' for HMAC authentication
Sun Apr 03 16:50:04 2011 Control Channel: TLSv1, cipher TLSv1/SSLv3 DHE-RSA-AES256-SHA, 1024 bit RSA
Sun Apr 03 16:50:04 2011 [Nagaev] Peer Connection Initiated with 79.122.131.180:1194
Sun Apr 03 16:50:06 2011 SENT CONTROL [Nagaev]: 'PUSH_REQUEST' (status=1)
Sun Apr 03 16:50:06 2011 PUSH: Received control message: 'PUSH_REPLY,route-gateway 10.10.14.1,route-gateway 10.10.14.1,ping 15,ping-restart 60,ifconfig 10.10.14.2 255.255.255.0'
Sun Apr 03 16:50:06 2011 OPTIONS IMPORT: timers and/or timeouts modified
Sun Apr 03 16:50:06 2011 OPTIONS IMPORT: --ifconfig/up options modified
Sun Apr 03 16:50:06 2011 OPTIONS IMPORT: route-related options modified
Sun Apr 03 16:50:06 2011 TAP-WIN32 device [raduga] opened: \\.\Global\{2704E367-EBC6-4E55-9494-E90AA908932F}.tap
Sun Apr 03 16:50:06 2011 TAP-Win32 Driver Version 9.7
Sun Apr 03 16:50:06 2011 TAP-Win32 MTU=1500
Sun Apr 03 16:50:06 2011 Notified TAP-Win32 driver to set a DHCP IP/netmask of 10.10.14.2/255.255.255.0 on interface {2704E367-EBC6-4E55-9494-E90AA908932F} [DHCP-serv: 10.10.14.0, lease-time: 31536000]
Sun Apr 03 16:50:06 2011 Successful ARP Flush on interface [2] {2704E367-EBC6-4E55-9494-E90AA908932F}
Sun Apr 03 16:50:08 2011 TEST ROUTES: 0/0 succeeded len=-1 ret=0 a=0 u/d=down
Sun Apr 03 16:50:08 2011 Route: Waiting for TUN/TAP interface to come up...
Sun Apr 03 16:50:10 2011 TEST ROUTES: 0/0 succeeded len=-1 ret=1 a=0 u/d=up
Sun Apr 03 16:50:10 2011 Initialization Sequence Completed
С сервера лог пока дать не могу завис роутер = )) Через пару часов дам..