Ostatni fragment z logu serwera:
Kod: Zaznacz cały
/etc/openvpn/openvpn.log 406270/397K 100%
Fri Sep 23 12:25:55 2016 ROUTE_GATEWAY 217.61.1.1/255.255.255.0 IFACE=eth0 HWADDR=00:50:56:9f:3d:66
Fri Sep 23 12:25:55 2016 TUN/TAP device tun0 opened
Fri Sep 23 12:25:55 2016 TUN/TAP TX queue length set to 100
Fri Sep 23 12:25:55 2016 do_ifconfig, tt->ipv6=0, tt->did_ifconfig_ipv6_setup=0
Fri Sep 23 12:25:55 2016 /usr/sbin/ip link set dev tun0 up mtu 1500
Fri Sep 23 12:25:55 2016 /usr/sbin/ip addr add dev tun0 local 10.8.0.1 peer 10.8.0.2
Fri Sep 23 12:25:55 2016 /usr/sbin/ip route add 10.8.0.0/24 via 10.8.0.2
Fri Sep 23 12:25:55 2016 GID set to nobody
Fri Sep 23 12:25:55 2016 UID set to nobody
Fri Sep 23 12:25:55 2016 UDPv4 link local (bound): [undef]
Fri Sep 23 12:25:55 2016 UDPv4 link remote: [undef]
Fri Sep 23 12:25:55 2016 MULTI: multi_init called, r=256 v=256
Fri Sep 23 12:25:55 2016 IFCONFIG POOL: base=10.8.0.4 size=62, ipv6=0
Fri Sep 23 12:25:55 2016 ifconfig_pool_read(), in='client,10.8.0.4', TODO: IPv6
Fri Sep 23 12:25:55 2016 succeeded -> ifconfig_pool_set()
Fri Sep 23 12:25:55 2016 IFCONFIG POOL LIST
Fri Sep 23 12:25:55 2016 client,10.8.0.4
Fri Sep 23 12:25:55 2016 Initialization Sequence Completed
Sat Sep 24 15:36:53 2016 OpenVPN 2.3.12 x86_64-redhat-linux-gnu [SSL (OpenSSL)] [LZO] [EPOLL] [PKCS11] [MH] [IPv6] built on Aug 23 2016
Sat Sep 24 15:36:53 2016 library versions: OpenSSL 1.0.1e-fips 11 Feb 2013, LZO 2.06
Sat Sep 24 15:36:53 2016 Diffie-Hellman initialized with 2048 bit key
Sat Sep 24 15:36:53 2016 Socket Buffers: R=[212992->212992] S=[212992->212992]
Sat Sep 24 15:36:53 2016 ROUTE_GATEWAY 217.61.1.1/255.255.255.0 IFACE=eth0 HWADDR=00:50:56:9f:3d:66
Sat Sep 24 15:36:53 2016 TUN/TAP device tun0 opened
Sat Sep 24 15:36:53 2016 TUN/TAP TX queue length set to 100
Sat Sep 24 15:36:53 2016 do_ifconfig, tt->ipv6=0, tt->did_ifconfig_ipv6_setup=0
Sat Sep 24 15:36:53 2016 /usr/sbin/ip link set dev tun0 up mtu 1500
Sat Sep 24 15:36:53 2016 /usr/sbin/ip addr add dev tun0 local 10.8.0.1 peer 10.8.0.2
Sat Sep 24 15:36:53 2016 /usr/sbin/ip route add 10.8.0.0/24 via 10.8.0.2
Sat Sep 24 15:36:53 2016 GID set to nobody
Sat Sep 24 15:36:53 2016 UID set to nobody
Sat Sep 24 15:36:53 2016 UDPv4 link local (bound): [undef]
Sat Sep 24 15:36:53 2016 UDPv4 link remote: [undef]
Sat Sep 24 15:36:53 2016 MULTI: multi_init called, r=256 v=256
Sat Sep 24 15:36:53 2016 IFCONFIG POOL: base=10.8.0.4 size=62, ipv6=0
Sat Sep 24 15:36:53 2016 ifconfig_pool_read(), in='client,10.8.0.4', TODO: IPv6
Sat Sep 24 15:36:53 2016 succeeded -> ifconfig_pool_set()
Sat Sep 24 15:36:53 2016 IFCONFIG POOL LIST
Sat Sep 24 15:36:53 2016 client,10.8.0.4
Sat Sep 24 15:36:53 2016 Initialization Sequence Completed
Sat Sep 24 15:39:41 2016 213.92.164.227:61344 TLS: Initial packet from [AF_INET]213.92.164.227:61344, sid=c2ade4c7 d9fb5c10
Sat Sep 24 15:39:41 2016 213.92.164.227:61344 VERIFY OK: depth=1, C=US, ST=CA, L=SanFrancisco, O=Fort-Funston, OU=MyOrganizationalUnit, CN=Fort-Funston CA, name=server, [email protected]
Sat Sep 24 15:39:41 2016 213.92.164.227:61344 VERIFY OK: depth=0, C=US, ST=CA, L=SanFrancisco, O=Fort-Funston, OU=MyOrganizationalUnit, CN=client, name=server, [email protected]
Sat Sep 24 15:39:41 2016 213.92.164.227:61344 WARNING: 'keydir' is present in remote config but missing in local config, remote='keydir 1'
Sat Sep 24 15:39:41 2016 213.92.164.227:61344 Data Channel Encrypt: Cipher 'BF-CBC' initialized with 128 bit key
Sat Sep 24 15:39:41 2016 213.92.164.227:61344 WARNING: this cipher's block size is less than 128 bit (64 bit). Consider using a --cipher with a larger block size.
Sat Sep 24 15:39:41 2016 213.92.164.227:61344 Data Channel Encrypt: Using 160 bit message hash 'SHA1' for HMAC authentication
Sat Sep 24 15:39:41 2016 213.92.164.227:61344 Data Channel Decrypt: Cipher 'BF-CBC' initialized with 128 bit key
Sat Sep 24 15:39:41 2016 213.92.164.227:61344 WARNING: this cipher's block size is less than 128 bit (64 bit). Consider using a --cipher with a larger block size.
Sat Sep 24 15:39:41 2016 213.92.164.227:61344 Data Channel Decrypt: Using 160 bit message hash 'SHA1' for HMAC authentication
Sat Sep 24 15:39:41 2016 213.92.164.227:61344 Control Channel: TLSv1.2, cipher TLSv1/SSLv3 DHE-RSA-AES256-GCM-SHA384, 2048 bit RSA
Sat Sep 24 15:39:41 2016 213.92.164.227:61344 [client] Peer Connection Initiated with [AF_INET]213.92.164.227:61344
Sat Sep 24 15:39:41 2016 client/213.92.164.227:61344 MULTI_sva: pool returned IPv4=10.8.0.6, IPv6=(Not enabled)
Sat Sep 24 15:39:41 2016 client/213.92.164.227:61344 MULTI: Learn: 10.8.0.6 -> client/213.92.164.227:61344
Sat Sep 24 15:39:41 2016 client/213.92.164.227:61344 MULTI: primary virtual IP for client/213.92.164.227:61344: 10.8.0.6
Sat Sep 24 15:39:43 2016 client/213.92.164.227:61344 PUSH: Received control message: 'PUSH_REQUEST'
Sat Sep 24 15:39:43 2016 client/213.92.164.227:61344 send_push_reply(): safe_cap=940
Sat Sep 24 15:39:43 2016 client/213.92.164.227:61344 SENT CONTROL [client]: 'PUSH_REPLY,redirect-gateway def1 bypass-dhcp,dhcp-option DNS 8.8.8.8,dhcp-option DNS 8.8.4.4,redirect-gateway def1,route 10.8.0.1,topology net30,ping 10,ping-re
start 120,ifconfig 10.8.0.6 10.8.0.5' (status=1)
konfig klienta:
Kod: Zaznacz cały
client
port 1194
remote 217.61.1.233
comp-lzo yes
dev tun
proto udp
nobind
auth-nocache
persist-key
persist-tun
verb 2
key-direction 1
<ca>
-----BEGIN CERTIFICATE-----
xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
-----END CERTIFICATE-----
</ca>
<cert>
-----BEGIN CERTIFICATE-----
xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
-----END CERTIFICATE-----
</cert>
<key>
-----BEGIN PRIVATE KEY-----
xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
-----END PRIVATE KEY-----
</key>