Client-to-client Wrong routing

Scripts to manage certificates or generate config files

Moderators: TinCanTech, TinCanTech, TinCanTech, TinCanTech, TinCanTech, TinCanTech

Post Reply
sliman
OpenVpn Newbie
Posts: 1
Joined: Fri Mar 28, 2014 6:15 pm

Client-to-client Wrong routing

Post by sliman » Fri Mar 28, 2014 9:04 pm

Hello everyone.

I want to configure a client-to-client connection, a closed network without routing client networks.
But it doesn't work :-(.

1. line: Why the server route this to the wrong nic?
2. line: Why is here a wrong gateway? It should be 10.8.0.1

Code: Select all

10.8.0.0 255.255.255.0 10.8.0.1 p=0 i=3 t=4 pr=3 a=0 h=0 m=3/0/0/0/0
10.8.0.0 255.255.255.0 10.8.0.5 p=0 i=20 t=4 pr=3 a=0 h=0 m=1/0/0/0/0
What does this do? Here is a wrong gateway, too

Code: Select all

10.8.0.4 255.255.255.252 10.8.0.6 p=0 i=20 t=3 pr=2 a=34 h=0 m=257/0/0/0/0
10.8.0.6 255.255.255.255 10.8.0.6 p=0 i=20 t=3 pr=2 a=34 h=0 m=257/0/0/0/0
10.8.0.7 255.255.255.255 10.8.0.6 p=0 i=20 t=3 pr=2 a=34 h=0 m=257/0/0/0/0


Here the routing part of my server.conf:

Code: Select all

# General settings
[...]

# Routing settings
server 10.8.0.0 255.255.255.0

ifconfig-pool-persist ipp.txt

# What can I do with this as example?
# I think, you use your server as router and brigdes to another NIC.
;server-bridge 10.8.0.4 255.255.255.0 10.8.0.50 10.8.0.100
;server-bridge

# I tried to push... (second line is not used)
;push "route 10.8.0.0 255.255.255.0 10.8.0.1 1" 
;push "route 192.168.20.0 255.255.255.0"

# I tried this option, too
;push "redirect-gateway 10.8.0.1"
;push "redirect-gateway def1 bypass-dhcp"

# I think, maybe relevant for me
;push "dhcp-option DNS 208.67.222.222"
;push "dhcp-option DNS 208.67.220.220"

client-to-client

# Auth and login settings
[...]
And here my client.log

Code: Select all

[...]
Fri Mar 28 21:35:23 2014 [xxx.xxx.xxx.xxx] Peer Connection Initiated with [AF_INET]xxx.xxx.xxx.xxx:1194
Fri Mar 28 21:35:24 2014 MANAGEMENT: >STATE:1396038924,GET_CONFIG,,,
Fri Mar 28 21:35:25 2014 SENT CONTROL [xxx.xxx.xxx.xxx]: 'PUSH_REQUEST' (status=1)
Fri Mar 28 21:35:25 2014 PUSH: Received control message: 'PUSH_REPLY,route 10.8.0.0 255.255.255.0 10.8.0.1 1,route 10.8.0.0 255.255.255.0,topology net30,ping 10,ping-restart 120,ifconfig 10.8.0.6 10.8.0.5'
Fri Mar 28 21:35:25 2014 OPTIONS IMPORT: timers and/or timeouts modified
Fri Mar 28 21:35:25 2014 OPTIONS IMPORT: --ifconfig/up options modified
Fri Mar 28 21:35:25 2014 OPTIONS IMPORT: route options modified
Fri Mar 28 21:35:25 2014 do_ifconfig, tt->ipv6=0, tt->did_ifconfig_ipv6_setup=0
Fri Mar 28 21:35:25 2014 MANAGEMENT: >STATE:1396038925,ASSIGN_IP,,10.8.0.6,
Fri Mar 28 21:35:25 2014 open_tun, tt->ipv6=0
Fri Mar 28 21:35:25 2014 TAP-WIN32 device [OpenVPN] opened: \\.\Global\{4D611F79-AC15-43C7-8DF0-6320FD00E800}.tap
Fri Mar 28 21:35:25 2014 TAP-Windows Driver Version 9.9 
Fri Mar 28 21:35:25 2014 Notified TAP-Windows driver to set a DHCP IP/netmask of 10.8.0.6/255.255.255.252 on interface {4D611F79-AC15-43C7-8DF0-6320FD00E800} [DHCP-serv: 10.8.0.5, lease-time: 31536000]
Fri Mar 28 21:35:25 2014 Successful ARP Flush on interface [20] {4D611F79-AC15-43C7-8DF0-6320FD00E800}
Fri Mar 28 21:35:30 2014 TEST ROUTES: 1/2 succeeded len=2 ret=0 a=0 u/d=up
Fri Mar 28 21:35:30 2014 Route: Waiting for TUN/TAP interface to come up...
[...]
Fri Mar 28 21:36:00 2014 TEST ROUTES: 1/2 succeeded len=2 ret=0 a=0 u/d=up
Fri Mar 28 21:36:00 2014 MANAGEMENT: >STATE:1396038960,ADD_ROUTES,,,
Fri Mar 28 21:36:00 2014 C:\Windows\system32\route.exe ADD 10.8.0.0 MASK 255.255.255.0 10.8.0.1 METRIC 1
Fri Mar 28 21:36:00 2014 Warning: route gateway is not reachable on any active network adapters: 10.8.0.1
Fri Mar 28 21:36:00 2014 Route addition via IPAPI failed [adaptive]
Fri Mar 28 21:36:00 2014 Route addition fallback to route.exe
Fri Mar 28 21:36:00 2014 env_block: add PATH=C:\Windows\System32;C:\WINDOWS;C:\WINDOWS\System32\Wbem
Fri Mar 28 21:36:00 2014 C:\Windows\system32\route.exe ADD 10.8.0.0 MASK 255.255.255.0 10.8.0.5
Fri Mar 28 21:36:00 2014 Route addition via IPAPI succeeded [adaptive]
SYSTEM ROUTING TABLE
0.0.0.0 0.0.0.0 192.168.2.1 p=0 i=3 t=4 pr=3 a=278127 h=0 m=4/0/0/0/0
10.8.0.0 255.255.255.0 10.8.0.1 p=0 i=3 t=4 pr=3 a=0 h=0 m=3/0/0/0/0
10.8.0.0 255.255.255.0 10.8.0.5 p=0 i=20 t=4 pr=3 a=0 h=0 m=1/0/0/0/0
10.8.0.4 255.255.255.252 10.8.0.6 p=0 i=20 t=3 pr=2 a=34 h=0 m=257/0/0/0/0
10.8.0.6 255.255.255.255 10.8.0.6 p=0 i=20 t=3 pr=2 a=34 h=0 m=257/0/0/0/0
10.8.0.7 255.255.255.255 10.8.0.6 p=0 i=20 t=3 pr=2 a=34 h=0 m=257/0/0/0/0
127.0.0.0 255.0.0.0 127.0.0.1 p=0 i=1 t=3 pr=2 a=278141 h=0 m=306/0/0/0/0
127.0.0.1 255.255.255.255 127.0.0.1 p=0 i=1 t=3 pr=2 a=278141 h=0 m=306/0/0/0/0
127.255.255.255 255.255.255.255 127.0.0.1 p=0 i=1 t=3 pr=2 a=278141 h=0 m=306/0/0/0/0
192.168.2.0 255.255.255.0 192.168.2.105 p=0 i=3 t=3 pr=2 a=278127 h=0 m=258/0/0/0/0
192.168.2.105 255.255.255.255 192.168.2.105 p=0 i=3 t=3 pr=2 a=278127 h=0 m=258/0/0/0/0
192.168.2.255 255.255.255.255 192.168.2.105 p=0 i=3 t=3 pr=2 a=278127 h=0 m=258/0/0/0/0
192.168.154.0 255.255.255.0 192.168.154.1 p=0 i=9 t=3 pr=2 a=9831 h=0 m=276/0/0/0/0
192.168.154.1 255.255.255.255 192.168.154.1 p=0 i=9 t=3 pr=2 a=9831 h=0 m=276/0/0/0/0
192.168.154.255 255.255.255.255 192.168.154.1 p=0 i=9 t=3 pr=2 a=9831 h=0 m=276/0/0/0/0
192.168.254.0 255.255.255.0 192.168.254.1 p=0 i=7 t=3 pr=2 a=9831 h=0 m=276/0/0/0/0
192.168.254.1 255.255.255.255 192.168.254.1 p=0 i=7 t=3 pr=2 a=9831 h=0 m=276/0/0/0/0
192.168.254.255 255.255.255.255 192.168.254.1 p=0 i=7 t=3 pr=2 a=9831 h=0 m=276/0/0/0/0
224.0.0.0 240.0.0.0 127.0.0.1 p=0 i=1 t=3 pr=2 a=278141 h=0 m=306/0/0/0/0
224.0.0.0 240.0.0.0 192.168.2.105 p=0 i=3 t=3 pr=2 a=278129 h=0 m=258/0/0/0/0
224.0.0.0 240.0.0.0 10.8.0.6 p=0 i=20 t=3 pr=2 a=184270 h=0 m=257/0/0/0/0
224.0.0.0 240.0.0.0 192.168.254.1 p=0 i=7 t=3 pr=2 a=9834 h=0 m=276/0/0/0/0
224.0.0.0 240.0.0.0 192.168.154.1 p=0 i=9 t=3 pr=2 a=9834 h=0 m=276/0/0/0/0
255.255.255.255 255.255.255.255 127.0.0.1 p=0 i=1 t=3 pr=2 a=278141 h=0 m=306/0/0/0/0
255.255.255.255 255.255.255.255 192.168.2.105 p=0 i=3 t=3 pr=2 a=278129 h=0 m=258/0/0/0/0
255.255.255.255 255.255.255.255 10.8.0.6 p=0 i=20 t=3 pr=2 a=184270 h=0 m=257/0/0/0/0
255.255.255.255 255.255.255.255 192.168.254.1 p=0 i=7 t=3 pr=2 a=9834 h=0 m=276/0/0/0/0
255.255.255.255 255.255.255.255 192.168.154.1 p=0 i=9 t=3 pr=2 a=9834 h=0 m=276/0/0/0/0
SYSTEM ADAPTER LIST
TAP-Windows Adapter V9
  Index = 20
  GUID = {4D611F79-AC15-43C7-8DF0-6320FD00E800}
  IP = 10.8.0.6/255.255.255.252 
  MAC = 00:ff:4d:61:1f:79
  GATEWAY = 0.0.0.0/255.255.255.255 
  DHCP SERV = 10.8.0.5/255.255.255.255 
  DHCP LEASE OBTAINED = Fri Mar 28 21:35:25 2014
  DHCP LEASE EXPIRES  = Sat Mar 28 21:35:25 2015
  DNS SERV =  
TeamViewer VPN Adapter
  Index = 6
  GUID = {F3EA0C82-091C-43BC-803D-A630D55C68D2}
  IP = 0.0.0.0/0.0.0.0 
  MAC = 00:ff:f3:ea:0c:82
  GATEWAY = 0.0.0.0/255.255.255.255 
  DHCP SERV =  
  DHCP LEASE OBTAINED = Fri Mar 28 21:36:00 2014
  DHCP LEASE EXPIRES  = Fri Mar 28 21:36:00 2014
  DNS SERV =  
PCI-E-Gigabit-Ethernet-Controller der Familie Marvell Yukon 88E8057
  Index = 3
  GUID = {B153F42D-D579-4F19-ADEB-DCC437C38591}
  IP = 192.168.2.105/255.255.255.0 
  MAC = 38:60:77:dd:b5:13
  GATEWAY = 192.168.2.1/255.255.255.255 
  DHCP SERV = 192.168.2.1/255.255.255.255 
  DHCP LEASE OBTAINED = Fri Mar 28 18:52:09 2014
  DHCP LEASE EXPIRES  = Fri Apr 18 19:52:09 2014
  DNS SERV = 8.8.4.4/255.255.255.255 8.8.8.8/255.255.255.255 
VMware Virtual Ethernet Adapter for VMnet1
  Index = 7
  GUID = {E4736BD5-339E-40B6-9538-DD62B9F3163D}
  IP = 192.168.254.1/255.255.255.0 
  MAC = 00:50:56:c0:00:01
  GATEWAY = 0.0.0.0/255.255.255.255 
  DNS SERV =  
VMware Virtual Ethernet Adapter for VMnet8
  Index = 9
  GUID = {A0AE5F0C-BFFD-46AD-B5B3-78258F37D84C}
  IP = 192.168.154.1/255.255.255.0 
  MAC = 00:50:56:c0:00:08
  GATEWAY = 0.0.0.0/255.255.255.255 
  DNS SERV =  
Fri Mar 28 21:36:00 2014 Initialization Sequence Completed With Errors ( see http://openvpn.net/faq.html#dhcpclientserv )
Fri Mar 28 21:36:00 2014 MANAGEMENT: >STATE:1396038960,CONNECTED,ERROR,10.8.0.6,xxx.xxx.xxx.xxx

User avatar
maikcat
Forum Team
Posts: 4200
Joined: Wed Jan 12, 2011 9:23 am
Location: Athens,Greece
Contact:

Re: Client-to-client Wrong routing

Post by maikcat » Mon Mar 31, 2014 5:52 am

please post your FULL configs/logs.

what exactly is not working?
what OS are you using on both client/server?

Michael.
Amiga 500 , Zx +2 owner
Long live Dino Dini (Kick off 2 Creator)

Inflammable means flammable? (Dr Nick Riviera,Simsons Season13)

"objects in mirror are losing"

Post Reply