Page 1 of 1

Windows 8 client + Debian wheezy connects but no ping

Posted: Wed Aug 07, 2013 6:32 pm
by ganesh
Hi,

I've spent two days trying to get OpenVPN running but no success. The server comes up nicely and my windows 8 box connects fine but I can't ping through the tunnel.

Please see conf and log below.

-- ganesh

Re: Windows 8 client + Debian wheezy connects but no ping

Posted: Wed Aug 07, 2013 6:37 pm
by ganesh
Here's my server conf:

port 1194
proto udp
dev tun
ca /etc/openvpn/easy-rsa/keys/ca.crt
cert /etc/openvpn/easy-rsa/keys/server.crt
key /etc/openvpn/easy-rsa/keys/server.key
dh /etc/openvpn/easy-rsa/keys/dh4096.pem
server 10.8.13.0 255.255.255.0
ifconfig-pool-persist ipp.txt
push "redirect-gateway def1 bypass-dhcp"
push "dhcp-option DNS 208.67.222.222"
push "dhcp-option DNS 208.67.220.220"
keepalive 10 120
comp-lzo
user nobody
group nogroup
persist-key
persist-tun
status log/openvpn-status.log
log log/openvpn.log
verb 4

Re: Windows 8 client + Debian wheezy connects but no ping

Posted: Wed Aug 07, 2013 6:41 pm
by ganesh
Now this is the client conf:

client
dev tun
proto udp
remote zugangspunkt.de 1194
resolv-retry infinite
nobind
persist-key
persist-tun
ca ca.crt
cert ganesh.crt
key ganesh.key
ns-cert-type server
cipher BF-CBC
comp-lzo
verb 4
route-method exe

Re: Windows 8 client + Debian wheezy connects but no ping

Posted: Wed Aug 07, 2013 6:43 pm
by ganesh
On the server side I've also set the iptables:

s15315912:/etc/openvpn/log# iptables -L
Chain INPUT (policy ACCEPT)
target prot opt source destination

Chain FORWARD (policy ACCEPT)
target prot opt source destination
ACCEPT all -- anywhere anywhere state RELATED,ESTABLISHED
ACCEPT all -- 10.8.13.0/24 anywhere
REJECT all -- anywhere anywhere reject-with icmp-port-unreachable

Chain OUTPUT (policy ACCEPT)
target prot opt source destination

Re: Windows 8 client + Debian wheezy connects but no ping

Posted: Wed Aug 07, 2013 6:45 pm
by ganesh
The server comes up nicely (started teh debian way with /etc/init.d/openvpn start):

Wed Aug 7 19:56:30 2013 us=492685 Current Parameter Settings:
Wed Aug 7 19:56:30 2013 us=492849 config = '/etc/openvpn/server.conf'
Wed Aug 7 19:56:30 2013 us=492881 mode = 1
Wed Aug 7 19:56:30 2013 us=492907 persist_config = DISABLED
Wed Aug 7 19:56:30 2013 us=492933 persist_mode = 1
Wed Aug 7 19:56:30 2013 us=492959 show_ciphers = DISABLED
Wed Aug 7 19:56:30 2013 us=492984 show_digests = DISABLED
Wed Aug 7 19:56:30 2013 us=493009 show_engines = DISABLED
Wed Aug 7 19:56:30 2013 us=493035 genkey = DISABLED
Wed Aug 7 19:56:30 2013 us=493060 key_pass_file = '[UNDEF]'
Wed Aug 7 19:56:30 2013 us=493086 show_tls_ciphers = DISABLED
Wed Aug 7 19:56:30 2013 us=493112 Connection profiles [default]:
Wed Aug 7 19:56:30 2013 us=493138 proto = udp
Wed Aug 7 19:56:30 2013 us=493164 local = '[UNDEF]'
Wed Aug 7 19:56:30 2013 us=493189 local_port = 1194
Wed Aug 7 19:56:30 2013 us=493214 remote = '[UNDEF]'
Wed Aug 7 19:56:30 2013 us=493240 remote_port = 1194
Wed Aug 7 19:56:30 2013 us=493265 remote_float = DISABLED
Wed Aug 7 19:56:30 2013 us=493290 bind_defined = DISABLED
Wed Aug 7 19:56:30 2013 us=493315 bind_local = ENABLED
Wed Aug 7 19:56:30 2013 us=493340 connect_retry_seconds = 5
Wed Aug 7 19:56:30 2013 us=493365 connect_timeout = 10
Wed Aug 7 19:56:30 2013 us=493391 connect_retry_max = 0
Wed Aug 7 19:56:30 2013 us=493416 socks_proxy_server = '[UNDEF]'
Wed Aug 7 19:56:30 2013 us=493441 socks_proxy_port = 0
Wed Aug 7 19:56:30 2013 us=493467 socks_proxy_retry = DISABLED
Wed Aug 7 19:56:30 2013 us=493492 Connection profiles END
Wed Aug 7 19:56:30 2013 us=493517 remote_random = DISABLED
Wed Aug 7 19:56:30 2013 us=493543 ipchange = '[UNDEF]'
Wed Aug 7 19:56:30 2013 us=493572 dev = 'tun'
Wed Aug 7 19:56:30 2013 us=493670 dev_type = '[UNDEF]'
Wed Aug 7 19:56:30 2013 us=493695 dev_node = '[UNDEF]'
Wed Aug 7 19:56:30 2013 us=493723 lladdr = '[UNDEF]'
Wed Aug 7 19:56:30 2013 us=493748 topology = 1
Wed Aug 7 19:56:30 2013 us=493774 tun_ipv6 = DISABLED
Wed Aug 7 19:56:30 2013 us=493799 ifconfig_local = '10.8.13.1'
Wed Aug 7 19:56:30 2013 us=493832 ifconfig_remote_netmask = '10.8.13.2'
Wed Aug 7 19:56:30 2013 us=493859 ifconfig_noexec = DISABLED
Wed Aug 7 19:56:30 2013 us=493884 ifconfig_nowarn = DISABLED
Wed Aug 7 19:56:30 2013 us=493910 ifconfig_ipv6_local = '[UNDEF]'
Wed Aug 7 19:56:30 2013 us=493935 ifconfig_ipv6_netbits = 0
Wed Aug 7 19:56:30 2013 us=493961 ifconfig_ipv6_remote = '[UNDEF]'
Wed Aug 7 19:56:30 2013 us=493987 shaper = 0
Wed Aug 7 19:56:30 2013 us=494013 tun_mtu = 1500
Wed Aug 7 19:56:30 2013 us=494038 tun_mtu_defined = ENABLED
Wed Aug 7 19:56:30 2013 us=494064 link_mtu = 1500
Wed Aug 7 19:56:30 2013 us=494089 link_mtu_defined = DISABLED
Wed Aug 7 19:56:30 2013 us=494114 tun_mtu_extra = 0
Wed Aug 7 19:56:30 2013 us=494140 tun_mtu_extra_defined = DISABLED
Wed Aug 7 19:56:30 2013 us=498505 fragment = 0
Wed Aug 7 19:56:30 2013 us=498533 mtu_discover_type = -1
Wed Aug 7 19:56:30 2013 us=498560 mtu_test = 0
Wed Aug 7 19:56:30 2013 us=498585 mlock = DISABLED
Wed Aug 7 19:56:30 2013 us=498611 keepalive_ping = 10
Wed Aug 7 19:56:30 2013 us=498636 keepalive_timeout = 120
Wed Aug 7 19:56:30 2013 us=498662 inactivity_timeout = 0
Wed Aug 7 19:56:30 2013 us=498687 ping_send_timeout = 10
Wed Aug 7 19:56:30 2013 us=498712 ping_rec_timeout = 240
Wed Aug 7 19:56:30 2013 us=498737 ping_rec_timeout_action = 2
Wed Aug 7 19:56:30 2013 us=498762 ping_timer_remote = DISABLED
Wed Aug 7 19:56:30 2013 us=498788 remap_sigusr1 = 0
Wed Aug 7 19:56:30 2013 us=498814 explicit_exit_notification = 0
Wed Aug 7 19:56:30 2013 us=498839 persist_tun = ENABLED
Wed Aug 7 19:56:30 2013 us=498864 persist_local_ip = DISABLED
Wed Aug 7 19:56:30 2013 us=498889 persist_remote_ip = DISABLED
Wed Aug 7 19:56:30 2013 us=498915 persist_key = ENABLED
Wed Aug 7 19:56:30 2013 us=498941 mssfix = 1450
Wed Aug 7 19:56:30 2013 us=498966 passtos = DISABLED
Wed Aug 7 19:56:30 2013 us=498992 resolve_retry_seconds = 1000000000
Wed Aug 7 19:56:30 2013 us=499062 username = 'nobody'
Wed Aug 7 19:56:30 2013 us=499089 groupname = 'nogroup'
Wed Aug 7 19:56:30 2013 us=499115 chroot_dir = '[UNDEF]'
Wed Aug 7 19:56:30 2013 us=499140 cd_dir = '/etc/openvpn'
Wed Aug 7 19:56:30 2013 us=499167 writepid = '/var/run/openvpn.server.pid'
Wed Aug 7 19:56:30 2013 us=499192 up_script = '[UNDEF]'
Wed Aug 7 19:56:30 2013 us=499218 down_script = '[UNDEF]'
Wed Aug 7 19:56:30 2013 us=499243 down_pre = DISABLED
Wed Aug 7 19:56:30 2013 us=499268 up_restart = DISABLED
Wed Aug 7 19:56:30 2013 us=499294 up_delay = DISABLED
Wed Aug 7 19:56:30 2013 us=499319 daemon = ENABLED
Wed Aug 7 19:56:30 2013 us=499344 inetd = 0
Wed Aug 7 19:56:30 2013 us=499369 log = ENABLED
Wed Aug 7 19:56:30 2013 us=499395 suppress_timestamps = DISABLED
Wed Aug 7 19:56:30 2013 us=499420 nice = 0
Wed Aug 7 19:56:30 2013 us=499445 verbosity = 4
Wed Aug 7 19:56:30 2013 us=499471 mute = 0
Wed Aug 7 19:56:30 2013 us=499496 gremlin = 0
Wed Aug 7 19:56:30 2013 us=499522 status_file = 'log/openvpn-status.log'
Wed Aug 7 19:56:30 2013 us=499548 status_file_version = 1
Wed Aug 7 19:56:30 2013 us=499573 status_file_update_freq = 60
Wed Aug 7 19:56:30 2013 us=499599 occ = ENABLED
Wed Aug 7 19:56:30 2013 us=499624 rcvbuf = 65536
Wed Aug 7 19:56:30 2013 us=499650 sndbuf = 65536
Wed Aug 7 19:56:30 2013 us=499675 sockflags = 0
Wed Aug 7 19:56:30 2013 us=499700 fast_io = DISABLED
Wed Aug 7 19:56:30 2013 us=499726 lzo = 7
Wed Aug 7 19:56:30 2013 us=499759 route_script = '[UNDEF]'
Wed Aug 7 19:56:30 2013 us=499785 route_default_gateway = '[UNDEF]'
Wed Aug 7 19:56:30 2013 us=499810 route_default_metric = 0
Wed Aug 7 19:56:30 2013 us=499836 route_noexec = DISABLED
Wed Aug 7 19:56:30 2013 us=499866 route_delay = 0
Wed Aug 7 19:56:30 2013 us=499893 route_delay_window = 30
Wed Aug 7 19:56:30 2013 us=499919 route_delay_defined = DISABLED
Wed Aug 7 19:56:30 2013 us=499945 route_nopull = DISABLED
Wed Aug 7 19:56:30 2013 us=499971 route_gateway_via_dhcp = DISABLED
Wed Aug 7 19:56:30 2013 us=499997 max_routes = 100
Wed Aug 7 19:56:30 2013 us=500023 allow_pull_fqdn = DISABLED
Wed Aug 7 19:56:30 2013 us=500054 route 10.8.13.0/255.255.255.0/nil/nil
Wed Aug 7 19:56:30 2013 us=500082 management_addr = '[UNDEF]'
Wed Aug 7 19:56:30 2013 us=500108 management_port = 0
Wed Aug 7 19:56:30 2013 us=500133 management_user_pass = '[UNDEF]'
Wed Aug 7 19:56:30 2013 us=500160 management_log_history_cache = 250
Wed Aug 7 19:56:30 2013 us=500185 management_echo_buffer_size = 100
Wed Aug 7 19:56:30 2013 us=500211 management_write_peer_info_file = '[UNDEF]'
Wed Aug 7 19:56:30 2013 us=500237 management_client_user = '[UNDEF]'
Wed Aug 7 19:56:30 2013 us=500263 management_client_group = '[UNDEF]'
Wed Aug 7 19:56:30 2013 us=500289 management_flags = 0
Wed Aug 7 19:56:30 2013 us=500315 shared_secret_file = '[UNDEF]'
Wed Aug 7 19:56:30 2013 us=500341 key_direction = 0
Wed Aug 7 19:56:30 2013 us=500367 ciphername_defined = ENABLED
Wed Aug 7 19:56:30 2013 us=500392 ciphername = 'BF-CBC'
Wed Aug 7 19:56:30 2013 us=500418 authname_defined = ENABLED
Wed Aug 7 19:56:30 2013 us=500444 authname = 'SHA1'
Wed Aug 7 19:56:30 2013 us=500469 prng_hash = 'SHA1'
Wed Aug 7 19:56:30 2013 us=500495 prng_nonce_secret_len = 16
Wed Aug 7 19:56:30 2013 us=500521 keysize = 0
Wed Aug 7 19:56:30 2013 us=500547 engine = DISABLED
Wed Aug 7 19:56:30 2013 us=500573 replay = ENABLED
Wed Aug 7 19:56:30 2013 us=500599 mute_replay_warnings = DISABLED
Wed Aug 7 19:56:30 2013 us=500625 replay_window = 64
Wed Aug 7 19:56:30 2013 us=500651 replay_time = 15
Wed Aug 7 19:56:30 2013 us=500676 packet_id_file = '[UNDEF]'
Wed Aug 7 19:56:30 2013 us=500702 use_iv = ENABLED
Wed Aug 7 19:56:30 2013 us=500727 test_crypto = DISABLED
Wed Aug 7 19:56:30 2013 us=500753 tls_server = ENABLED
Wed Aug 7 19:56:30 2013 us=500778 tls_client = DISABLED
Wed Aug 7 19:56:30 2013 us=500804 key_method = 2
Wed Aug 7 19:56:30 2013 us=500858 ca_file = '/etc/openvpn/easy-rsa/keys/ca.crt'
Wed Aug 7 19:56:30 2013 us=500885 ca_path = '[UNDEF]'
Wed Aug 7 19:56:30 2013 us=500911 dh_file = '/etc/openvpn/easy-rsa/keys/dh4096.pem'
Wed Aug 7 19:56:30 2013 us=500937 cert_file = '/etc/openvpn/easy-rsa/keys/server.crt'
Wed Aug 7 19:56:30 2013 us=500963 priv_key_file = '/etc/openvpn/easy-rsa/keys/server.key'
Wed Aug 7 19:56:30 2013 us=500989 pkcs12_file = '[UNDEF]'
Wed Aug 7 19:56:30 2013 us=501014 cipher_list = '[UNDEF]'
Wed Aug 7 19:56:30 2013 us=501040 tls_verify = '[UNDEF]'
Wed Aug 7 19:56:30 2013 us=501065 tls_export_cert = '[UNDEF]'
Wed Aug 7 19:56:30 2013 us=501090 tls_remote = '[UNDEF]'
Wed Aug 7 19:56:30 2013 us=501116 crl_file = '[UNDEF]'
Wed Aug 7 19:56:30 2013 us=501141 ns_cert_type = 0
Wed Aug 7 19:56:30 2013 us=501167 remote_cert_ku = 0
Wed Aug 7 19:56:30 2013 us=501193 remote_cert_ku = 0
Wed Aug 7 19:56:30 2013 us=501218 remote_cert_ku = 0
Wed Aug 7 19:56:30 2013 us=501243 remote_cert_ku = 0
Wed Aug 7 19:56:30 2013 us=501268 remote_cert_ku = 0
Wed Aug 7 19:56:30 2013 us=501294 remote_cert_ku = 0
Wed Aug 7 19:56:30 2013 us=501319 remote_cert_ku = 0
Wed Aug 7 19:56:30 2013 us=501344 remote_cert_ku = 0
Wed Aug 7 19:56:30 2013 us=501370 remote_cert_ku = 0
Wed Aug 7 19:56:30 2013 us=501395 remote_cert_ku = 0
Wed Aug 7 19:56:30 2013 us=501420 remote_cert_ku[i] = 0
Wed Aug 7 19:56:30 2013 us=501446 remote_cert_ku[i] = 0
Wed Aug 7 19:56:30 2013 us=501471 remote_cert_ku[i] = 0
Wed Aug 7 19:56:30 2013 us=501497 remote_cert_ku[i] = 0
Wed Aug 7 19:56:30 2013 us=501522 remote_cert_ku[i] = 0
Wed Aug 7 19:56:30 2013 us=501547 remote_cert_ku[i] = 0
Wed Aug 7 19:56:30 2013 us=501573 remote_cert_eku = '[UNDEF]'
Wed Aug 7 19:56:30 2013 us=501632 tls_timeout = 2
Wed Aug 7 19:56:30 2013 us=501657 renegotiate_bytes = 0
Wed Aug 7 19:56:30 2013 us=501683 renegotiate_packets = 0
Wed Aug 7 19:56:30 2013 us=501708 renegotiate_seconds = 3600
Wed Aug 7 19:56:30 2013 us=501733 handshake_window = 60
Wed Aug 7 19:56:30 2013 us=501758 transition_window = 3600
Wed Aug 7 19:56:30 2013 us=501783 single_session = DISABLED
Wed Aug 7 19:56:30 2013 us=501809 push_peer_info = DISABLED
Wed Aug 7 19:56:30 2013 us=501834 tls_exit = DISABLED
Wed Aug 7 19:56:30 2013 us=501859 tls_auth_file = '[UNDEF]'
Wed Aug 7 19:56:30 2013 us=501885 pkcs11_protected_authentication = DISABLED
Wed Aug 7 19:56:30 2013 us=501911 pkcs11_protected_authentication = DISABLED
Wed Aug 7 19:56:30 2013 us=501936 pkcs11_protected_authentication = DISABLED
Wed Aug 7 19:56:30 2013 us=501962 pkcs11_protected_authentication = DISABLED
Wed Aug 7 19:56:30 2013 us=501987 pkcs11_protected_authentication = DISABLED
Wed Aug 7 19:56:30 2013 us=502012 pkcs11_protected_authentication = DISABLED
Wed Aug 7 19:56:30 2013 us=502038 pkcs11_protected_authentication = DISABLED
Wed Aug 7 19:56:30 2013 us=502063 pkcs11_protected_authentication = DISABLED
Wed Aug 7 19:56:30 2013 us=502088 pkcs11_protected_authentication = DISABLED
Wed Aug 7 19:56:30 2013 us=502114 pkcs11_protected_authentication = DISABLED
Wed Aug 7 19:56:30 2013 us=502139 pkcs11_protected_authentication = DISABLED
Wed Aug 7 19:56:30 2013 us=502164 pkcs11_protected_authentication = DISABLED
Wed Aug 7 19:56:30 2013 us=502190 pkcs11_protected_authentication = DISABLED
Wed Aug 7 19:56:30 2013 us=502215 pkcs11_protected_authentication = DISABLED
Wed Aug 7 19:56:30 2013 us=502241 pkcs11_protected_authentication = DISABLED
Wed Aug 7 19:56:30 2013 us=502266 pkcs11_protected_authentication = DISABLED
Wed Aug 7 19:56:30 2013 us=502293 pkcs11_private_mode = 00000000
Wed Aug 7 19:56:30 2013 us=502319 pkcs11_private_mode = 00000000
Wed Aug 7 19:56:30 2013 us=502345 pkcs11_private_mode = 00000000
Wed Aug 7 19:56:30 2013 us=502370 pkcs11_private_mode = 00000000
Wed Aug 7 19:56:30 2013 us=502395 pkcs11_private_mode = 00000000
Wed Aug 7 19:56:30 2013 us=502421 pkcs11_private_mode = 00000000
Wed Aug 7 19:56:30 2013 us=502473 pkcs11_private_mode = 00000000
Wed Aug 7 19:56:30 2013 us=502500 pkcs11_private_mode = 00000000
Wed Aug 7 19:56:30 2013 us=502526 pkcs11_private_mode = 00000000
Wed Aug 7 19:56:30 2013 us=502551 pkcs11_private_mode = 00000000
Wed Aug 7 19:56:30 2013 us=502577 pkcs11_private_mode = 00000000
Wed Aug 7 19:56:30 2013 us=502602 pkcs11_private_mode = 00000000
Wed Aug 7 19:56:30 2013 us=502628 pkcs11_private_mode = 00000000
Wed Aug 7 19:56:30 2013 us=502654 pkcs11_private_mode = 00000000
Wed Aug 7 19:56:30 2013 us=502679 pkcs11_private_mode = 00000000
Wed Aug 7 19:56:30 2013 us=502705 pkcs11_private_mode = 00000000
Wed Aug 7 19:56:30 2013 us=502730 pkcs11_cert_private = DISABLED
Wed Aug 7 19:56:30 2013 us=502756 pkcs11_cert_private = DISABLED
Wed Aug 7 19:56:30 2013 us=502781 pkcs11_cert_private = DISABLED
Wed Aug 7 19:56:30 2013 us=502806 pkcs11_cert_private = DISABLED
Wed Aug 7 19:56:30 2013 us=502832 pkcs11_cert_private = DISABLED
Wed Aug 7 19:56:30 2013 us=502857 pkcs11_cert_private = DISABLED
Wed Aug 7 19:56:30 2013 us=502882 pkcs11_cert_private = DISABLED
Wed Aug 7 19:56:30 2013 us=502908 pkcs11_cert_private = DISABLED
Wed Aug 7 19:56:30 2013 us=502933 pkcs11_cert_private = DISABLED
Wed Aug 7 19:56:30 2013 us=502958 pkcs11_cert_private = DISABLED
Wed Aug 7 19:56:30 2013 us=502984 pkcs11_cert_private = DISABLED
Wed Aug 7 19:56:30 2013 us=503009 pkcs11_cert_private = DISABLED
Wed Aug 7 19:56:30 2013 us=503035 pkcs11_cert_private = DISABLED
Wed Aug 7 19:56:30 2013 us=503060 pkcs11_cert_private = DISABLED
Wed Aug 7 19:56:30 2013 us=503085 pkcs11_cert_private = DISABLED
Wed Aug 7 19:56:30 2013 us=503111 pkcs11_cert_private = DISABLED
Wed Aug 7 19:56:30 2013 us=503137 pkcs11_pin_cache_period = -1
Wed Aug 7 19:56:30 2013 us=503162 pkcs11_id = '[UNDEF]'
Wed Aug 7 19:56:30 2013 us=503188 pkcs11_id_management = DISABLED
Wed Aug 7 19:56:30 2013 us=503219 server_network = 10.8.13.0
Wed Aug 7 19:56:30 2013 us=503247 server_netmask = 255.255.255.0
Wed Aug 7 19:56:30 2013 us=503292 server_network_ipv6 = ::
Wed Aug 7 19:56:30 2013 us=503321 server_netbits_ipv6 = 0
Wed Aug 7 19:56:30 2013 us=503349 server_bridge_ip = 0.0.0.0
Wed Aug 7 19:56:30 2013 us=503377 server_bridge_netmask = 0.0.0.0
Wed Aug 7 19:56:30 2013 us=503405 server_bridge_pool_start = 0.0.0.0
Wed Aug 7 19:56:30 2013 us=503433 server_bridge_pool_end = 0.0.0.0
Wed Aug 7 19:56:30 2013 us=503459 push_entry = 'redirect-gateway def1 bypass-dhcp'
Wed Aug 7 19:56:30 2013 us=503486 push_entry = 'dhcp-option DNS 10.8.13.1'
Wed Aug 7 19:56:30 2013 us=503512 push_entry = 'dhcp-option DNS 208.67.222.222'
Wed Aug 7 19:56:30 2013 us=503537 push_entry = 'dhcp-option DNS 208.67.220.220'
Wed Aug 7 19:56:30 2013 us=503563 push_entry = 'route 10.8.13.1'
Wed Aug 7 19:56:30 2013 us=503589 push_entry = 'topology net30'
Wed Aug 7 19:56:30 2013 us=503615 push_entry = 'ping 10'
Wed Aug 7 19:56:30 2013 us=503640 push_entry = 'ping-restart 120'
Wed Aug 7 19:56:30 2013 us=503666 ifconfig_pool_defined = ENABLED
Wed Aug 7 19:56:30 2013 us=503701 ifconfig_pool_start = 10.8.13.4
Wed Aug 7 19:56:30 2013 us=503732 ifconfig_pool_end = 10.8.13.251
Wed Aug 7 19:56:30 2013 us=503760 ifconfig_pool_netmask = 0.0.0.0
Wed Aug 7 19:56:30 2013 us=503786 ifconfig_pool_persist_filename = 'ipp.txt'
Wed Aug 7 19:56:30 2013 us=503813 ifconfig_pool_persist_refresh_freq = 600
Wed Aug 7 19:56:30 2013 us=503839 ifconfig_ipv6_pool_defined = DISABLED
Wed Aug 7 19:56:30 2013 us=503867 ifconfig_ipv6_pool_base = ::
Wed Aug 7 19:56:30 2013 us=503893 ifconfig_ipv6_pool_netbits = 0
Wed Aug 7 19:56:30 2013 us=503919 n_bcast_buf = 256
Wed Aug 7 19:56:30 2013 us=503944 tcp_queue_limit = 64
Wed Aug 7 19:56:30 2013 us=503970 real_hash_size = 256
Wed Aug 7 19:56:30 2013 us=503996 virtual_hash_size = 256
Wed Aug 7 19:56:30 2013 us=504021 client_connect_script = '[UNDEF]'
Wed Aug 7 19:56:30 2013 us=504047 learn_address_script = '[UNDEF]'
Wed Aug 7 19:56:30 2013 us=504096 client_disconnect_script = '[UNDEF]'
Wed Aug 7 19:56:30 2013 us=504123 client_config_dir = '[UNDEF]'
Wed Aug 7 19:56:30 2013 us=504148 ccd_exclusive = DISABLED
Wed Aug 7 19:56:30 2013 us=504174 tmp_dir = '/tmp'
Wed Aug 7 19:56:30 2013 us=504200 push_ifconfig_defined = DISABLED
Wed Aug 7 19:56:30 2013 us=504228 push_ifconfig_local = 0.0.0.0
Wed Aug 7 19:56:30 2013 us=504334 push_ifconfig_remote_netmask = 0.0.0.0
Wed Aug 7 19:56:30 2013 us=504366 push_ifconfig_ipv6_defined = DISABLED
Wed Aug 7 19:56:30 2013 us=504395 push_ifconfig_ipv6_local = ::/0
Wed Aug 7 19:56:30 2013 us=504421 push_ifconfig_ipv6_remote = ::
Wed Aug 7 19:56:30 2013 us=504447 enable_c2c = DISABLED
Wed Aug 7 19:56:30 2013 us=504472 duplicate_cn = DISABLED
Wed Aug 7 19:56:30 2013 us=504498 cf_max = 0
Wed Aug 7 19:56:30 2013 us=504523 cf_per = 0
Wed Aug 7 19:56:30 2013 us=504549 max_clients = 1024
Wed Aug 7 19:56:30 2013 us=504574 max_routes_per_client = 256
Wed Aug 7 19:56:30 2013 us=504599 auth_user_pass_verify_script = '[UNDEF]'
Wed Aug 7 19:56:30 2013 us=504626 auth_user_pass_verify_script_via_file = DISABLED
Wed Aug 7 19:56:30 2013 us=504651 ssl_flags = 0
Wed Aug 7 19:56:30 2013 us=504677 port_share_host = '[UNDEF]'
Wed Aug 7 19:56:30 2013 us=504702 port_share_port = 0
Wed Aug 7 19:56:30 2013 us=504727 client = DISABLED
Wed Aug 7 19:56:30 2013 us=504752 pull = DISABLED
Wed Aug 7 19:56:30 2013 us=504778 auth_user_pass_file = '[UNDEF]'
Wed Aug 7 19:56:30 2013 us=504813 OpenVPN 2.2.1 x86_64-linux-gnu [SSL] [LZO2] [EPOLL] [PKCS11] [eurephia] [MH] [PF_INET6] [IPv6 payload 20110424-2 (2.2RC2)] built on Jun 4 2013
Wed Aug 7 19:56:30 2013 us=505287 NOTE: OpenVPN 2.1 requires '--script-security 2' or higher to call user-defined scripts or executables
Wed Aug 7 19:56:30 2013 us=663072 Diffie-Hellman initialized with 4096 bit key
Wed Aug 7 19:56:30 2013 us=665333 TLS-Auth MTU parms [ L:1542 D:138 EF:38 EB:0 ET:0 EL:0 ]
Wed Aug 7 19:56:30 2013 us=665418 Socket Buffers: R=[229376->131072] S=[229376->131072]
Wed Aug 7 19:56:30 2013 us=665780 ROUTE default_gateway=10.255.255.1
Wed Aug 7 19:56:30 2013 us=667187 TUN/TAP device tun0 opened
Wed Aug 7 19:56:30 2013 us=667245 TUN/TAP TX queue length set to 100
Wed Aug 7 19:56:30 2013 us=667296 do_ifconfig, tt->ipv6=0, tt->did_ifconfig_ipv6_setup=0
Wed Aug 7 19:56:30 2013 us=667350 /sbin/ifconfig tun0 10.8.13.1 pointopoint 10.8.13.2 mtu 1500
Wed Aug 7 19:56:30 2013 us=672645 /sbin/route add -net 10.8.13.0 netmask 255.255.255.0 gw 10.8.13.2
Wed Aug 7 19:56:30 2013 us=675048 Data Channel MTU parms [ L:1542 D:1450 EF:42 EB:135 ET:0 EL:0 AF:3/1 ]
Wed Aug 7 19:56:30 2013 us=682090 GID set to nogroup
Wed Aug 7 19:56:30 2013 us=682251 UID set to nobody
Wed Aug 7 19:56:30 2013 us=682320 UDPv4 link local (bound): [undef]
Wed Aug 7 19:56:30 2013 us=682349 UDPv4 link remote: [undef]
Wed Aug 7 19:56:30 2013 us=682390 MULTI: multi_init called, r=256 v=256
Wed Aug 7 19:56:30 2013 us=682566 IFCONFIG POOL: base=10.8.13.4 size=62, ipv6=0
Wed Aug 7 19:56:30 2013 us=682617 ifconfig_pool_read(), in='ganesh,10.8.13.4', TODO: IPv6
Wed Aug 7 19:56:30 2013 us=682680 succeeded -> ifconfig_pool_set()
Wed Aug 7 19:56:30 2013 us=682716 IFCONFIG POOL LIST
Wed Aug 7 19:56:30 2013 us=682745 ganesh,10.8.13.4
Wed Aug 7 19:56:30 2013 us=682841 Initialization Sequence Completed
Wed Aug 7 19:56:45 2013 us=849323 MULTI: multi_create_instance called
Wed Aug 7 19:56:45 2013 us=849547 188.195.126.91:57954 Re-using SSL/TLS context
Wed Aug 7 19:56:45 2013 us=861911 188.195.126.91:57954 LZO compression initialized
Wed Aug 7 19:56:45 2013 us=862401 188.195.126.91:57954 Control Channel MTU parms [ L:1542 D:138 EF:38 EB:0 ET:0 EL:0 ]
Wed Aug 7 19:56:45 2013 us=862442 188.195.126.91:57954 Data Channel MTU parms [ L:1542 D:1450 EF:42 EB:135 ET:0 EL:0 AF:3/1 ]
Wed Aug 7 19:56:45 2013 us=862544 188.195.126.91:57954 Local Options String: 'V4,dev-type tun,link-mtu 1542,tun-mtu 1500,proto UDPv4,comp-lzo,cipher BF-CBC,auth SHA1,keysize 128,key-method 2,tls-server'
Wed Aug 7 19:56:45 2013 us=862625 188.195.126.91:57954 Expected Remote Options String: 'V4,dev-type tun,link-mtu 1542,tun-mtu 1500,proto UDPv4,comp-lzo,cipher BF-CBC,auth SHA1,keysize 128,key-method 2,tls-client'
Wed Aug 7 19:56:45 2013 us=862712 188.195.126.91:57954 Local Options hash (VER=V4): '530fdded'
Wed Aug 7 19:56:45 2013 us=862756 188.195.126.91:57954 Expected Remote Options hash (VER=V4): '41690919'
Wed Aug 7 19:56:45 2013 us=862871 188.195.126.91:57954 TLS: Initial packet from [AF_INET]188.195.126.91:57954, sid=5f6579ed ad9fee45
Wed Aug 7 19:57:00 2013 us=778687 188.195.126.91:57954 VERIFY OK: depth=1, /C=DE/ST=BV/L=Munich/O=GaneshPKI/OU=gnaeshpki/CN=ganesh/name=Ganesh/emailAddress=ganesh@apache.org
Wed Aug 7 19:57:00 2013 us=779626 188.195.126.91:57954 VERIFY OK: depth=0, /C=DE/ST=BV/L=Munich/O=GaneshPKI/OU=gnaeshpki/CN=ganesh/name=Ganesh/emailAddress=ganesh@apache.org
Wed Aug 7 19:57:01 2013 us=252746 188.195.126.91:57954 Data Channel Encrypt: Cipher 'BF-CBC' initialized with 128 bit key
Wed Aug 7 19:57:01 2013 us=252849 188.195.126.91:57954 Data Channel Encrypt: Using 160 bit message hash 'SHA1' for HMAC authentication
Wed Aug 7 19:57:01 2013 us=252974 188.195.126.91:57954 Data Channel Decrypt: Cipher 'BF-CBC' initialized with 128 bit key
Wed Aug 7 19:57:01 2013 us=253007 188.195.126.91:57954 Data Channel Decrypt: Using 160 bit message hash 'SHA1' for HMAC authentication
Wed Aug 7 19:57:01 2013 us=408737 188.195.126.91:57954 Control Channel: TLSv1, cipher TLSv1/SSLv3 DHE-RSA-AES256-SHA, 4096 bit RSA
Wed Aug 7 19:57:01 2013 us=408842 188.195.126.91:57954 [ganesh] Peer Connection Initiated with [AF_INET]188.195.126.91:57954
Wed Aug 7 19:57:01 2013 us=408925 ganesh/188.195.126.91:57954 MULTI_sva: pool returned IPv4=10.8.13.6, IPv6=1::1b00:0:217f:0
Wed Aug 7 19:57:01 2013 us=409028 ganesh/188.195.126.91:57954 MULTI: Learn: 10.8.13.6 -> ganesh/188.195.126.91:57954
Wed Aug 7 19:57:01 2013 us=409062 ganesh/188.195.126.91:57954 MULTI: primary virtual IP for ganesh/188.195.126.91:57954: 10.8.13.6
Wed Aug 7 19:57:07 2013 us=625602 ganesh/188.195.126.91:57954 PUSH: Received control message: 'PUSH_REQUEST'
Wed Aug 7 19:57:07 2013 us=625703 ganesh/188.195.126.91:57954 send_push_reply(): safe_cap=960
Wed Aug 7 19:57:07 2013 us=625810 ganesh/188.195.126.91:57954 SENT CONTROL [ganesh]: 'PUSH_REPLY,redirect-gateway def1 bypass-dhcp,dhcp-option DNS 208.67.222.222,dhcp-option DNS 208.67.220.220,route 10.8.13.1,topology net30,ping 10,ping-restart 120,ifconfig 10.8.13.6 10.8.13.5' (status=1)

Re: Windows 8 client + Debian wheezy connects but no ping

Posted: Wed Aug 07, 2013 6:48 pm
by ganesh
Neither on client side I can find an error in the logs:

Wed Aug 07 20:33:03 2013 us=890000 Current Parameter Settings:
Wed Aug 07 20:33:03 2013 us=890000 config = 'tun.ovpn'
Wed Aug 07 20:33:03 2013 us=890000 mode = 0
Wed Aug 07 20:33:03 2013 us=890000 show_ciphers = DISABLED
Wed Aug 07 20:33:03 2013 us=890000 show_digests = DISABLED
Wed Aug 07 20:33:03 2013 us=890000 show_engines = DISABLED
Wed Aug 07 20:33:03 2013 us=890000 genkey = DISABLED
Wed Aug 07 20:33:03 2013 us=890000 key_pass_file = '[UNDEF]'
Wed Aug 07 20:33:03 2013 us=890000 show_tls_ciphers = DISABLED
Wed Aug 07 20:33:03 2013 us=890000 Connection profiles [default]:
Wed Aug 07 20:33:03 2013 us=890000 proto = udp
Wed Aug 07 20:33:03 2013 us=890000 local = '[UNDEF]'
Wed Aug 07 20:33:03 2013 us=890000 local_port = 0
Wed Aug 07 20:33:03 2013 us=890000 remote = 'zugangspunkt.de'
Wed Aug 07 20:33:03 2013 us=890000 remote_port = 1194
Wed Aug 07 20:33:03 2013 us=890000 remote_float = DISABLED
Wed Aug 07 20:33:03 2013 us=890000 bind_defined = DISABLED
Wed Aug 07 20:33:03 2013 us=890000 bind_local = DISABLED
Wed Aug 07 20:33:03 2013 us=890000 connect_retry_seconds = 5
Wed Aug 07 20:33:03 2013 us=890000 connect_timeout = 10
Wed Aug 07 20:33:03 2013 us=890000 connect_retry_max = 0
Wed Aug 07 20:33:03 2013 us=890000 socks_proxy_server = '[UNDEF]'
Wed Aug 07 20:33:03 2013 us=890000 socks_proxy_port = 0
Wed Aug 07 20:33:03 2013 us=890000 socks_proxy_retry = DISABLED
Wed Aug 07 20:33:03 2013 us=890000 Connection profiles END
Wed Aug 07 20:33:03 2013 us=890000 remote_random = DISABLED
Wed Aug 07 20:33:03 2013 us=890000 ipchange = '[UNDEF]'
Wed Aug 07 20:33:03 2013 us=890000 dev = 'tun'
Wed Aug 07 20:33:03 2013 us=890000 dev_type = '[UNDEF]'
Wed Aug 07 20:33:03 2013 us=890000 dev_node = '[UNDEF]'
Wed Aug 07 20:33:03 2013 us=890000 lladdr = '[UNDEF]'
Wed Aug 07 20:33:03 2013 us=890000 topology = 1
Wed Aug 07 20:33:03 2013 us=890000 tun_ipv6 = DISABLED
Wed Aug 07 20:33:03 2013 us=890000 ifconfig_local = '[UNDEF]'
Wed Aug 07 20:33:03 2013 us=890000 ifconfig_remote_netmask = '[UNDEF]'
Wed Aug 07 20:33:03 2013 us=890000 ifconfig_noexec = DISABLED
Wed Aug 07 20:33:03 2013 us=890000 ifconfig_nowarn = DISABLED
Wed Aug 07 20:33:03 2013 us=890000 shaper = 0
Wed Aug 07 20:33:03 2013 us=890000 tun_mtu = 1500
Wed Aug 07 20:33:03 2013 us=890000 tun_mtu_defined = ENABLED
Wed Aug 07 20:33:03 2013 us=890000 link_mtu = 1500
Wed Aug 07 20:33:03 2013 us=890000 link_mtu_defined = DISABLED
Wed Aug 07 20:33:03 2013 us=890000 tun_mtu_extra = 0
Wed Aug 07 20:33:03 2013 us=890000 tun_mtu_extra_defined = DISABLED
Wed Aug 07 20:33:03 2013 us=890000 fragment = 0
Wed Aug 07 20:33:03 2013 us=890000 mtu_discover_type = -1
Wed Aug 07 20:33:03 2013 us=890000 mtu_test = 0
Wed Aug 07 20:33:03 2013 us=890000 mlock = DISABLED
Wed Aug 07 20:33:03 2013 us=890000 keepalive_ping = 0
Wed Aug 07 20:33:03 2013 us=890000 keepalive_timeout = 0
Wed Aug 07 20:33:03 2013 us=890000 inactivity_timeout = 0
Wed Aug 07 20:33:03 2013 us=890000 ping_send_timeout = 0
Wed Aug 07 20:33:03 2013 us=890000 ping_rec_timeout = 0
Wed Aug 07 20:33:03 2013 us=890000 ping_rec_timeout_action = 0
Wed Aug 07 20:33:03 2013 us=890000 ping_timer_remote = DISABLED
Wed Aug 07 20:33:03 2013 us=890000 remap_sigusr1 = 0
Wed Aug 07 20:33:03 2013 us=890000 explicit_exit_notification = 0
Wed Aug 07 20:33:03 2013 us=890000 persist_tun = ENABLED
Wed Aug 07 20:33:03 2013 us=890000 persist_local_ip = DISABLED
Wed Aug 07 20:33:03 2013 us=890000 persist_remote_ip = DISABLED
Wed Aug 07 20:33:03 2013 us=890000 persist_key = ENABLED
Wed Aug 07 20:33:03 2013 us=890000 mssfix = 1450
Wed Aug 07 20:33:03 2013 us=890000 resolve_retry_seconds = 1000000000
Wed Aug 07 20:33:03 2013 us=890000 username = '[UNDEF]'
Wed Aug 07 20:33:03 2013 us=890000 groupname = '[UNDEF]'
Wed Aug 07 20:33:03 2013 us=890000 chroot_dir = '[UNDEF]'
Wed Aug 07 20:33:03 2013 us=890000 cd_dir = '[UNDEF]'
Wed Aug 07 20:33:03 2013 us=890000 writepid = '[UNDEF]'
Wed Aug 07 20:33:03 2013 us=890000 up_script = '[UNDEF]'
Wed Aug 07 20:33:04 2013 us=125000 down_script = '[UNDEF]'
Wed Aug 07 20:33:04 2013 us=125000 down_pre = DISABLED
Wed Aug 07 20:33:04 2013 us=125000 up_restart = DISABLED
Wed Aug 07 20:33:04 2013 us=125000 up_delay = DISABLED
Wed Aug 07 20:33:04 2013 us=125000 daemon = DISABLED
Wed Aug 07 20:33:04 2013 us=125000 inetd = 0
Wed Aug 07 20:33:04 2013 us=125000 log = DISABLED
Wed Aug 07 20:33:04 2013 us=125000 suppress_timestamps = DISABLED
Wed Aug 07 20:33:04 2013 us=125000 nice = 0
Wed Aug 07 20:33:04 2013 us=125000 verbosity = 4
Wed Aug 07 20:33:04 2013 us=125000 mute = 0
Wed Aug 07 20:33:04 2013 us=125000 gremlin = 0
Wed Aug 07 20:33:04 2013 us=125000 status_file = '[UNDEF]'
Wed Aug 07 20:33:04 2013 us=125000 status_file_version = 1
Wed Aug 07 20:33:04 2013 us=125000 status_file_update_freq = 60
Wed Aug 07 20:33:04 2013 us=125000 occ = ENABLED
Wed Aug 07 20:33:04 2013 us=125000 rcvbuf = 0
Wed Aug 07 20:33:04 2013 us=125000 sndbuf = 0
Wed Aug 07 20:33:04 2013 us=171000 sockflags = 0
Wed Aug 07 20:33:04 2013 us=171000 fast_io = DISABLED
Wed Aug 07 20:33:04 2013 us=171000 lzo = 7
Wed Aug 07 20:33:04 2013 us=171000 route_script = '[UNDEF]'
Wed Aug 07 20:33:04 2013 us=171000 route_default_gateway = '[UNDEF]'
Wed Aug 07 20:33:04 2013 us=171000 route_default_metric = 0
Wed Aug 07 20:33:04 2013 us=171000 route_noexec = DISABLED
Wed Aug 07 20:33:04 2013 us=171000 route_delay = 5
Wed Aug 07 20:33:04 2013 us=171000 route_delay_window = 30
Wed Aug 07 20:33:04 2013 us=171000 route_delay_defined = ENABLED
Wed Aug 07 20:33:04 2013 us=171000 route_nopull = DISABLED
Wed Aug 07 20:33:04 2013 us=171000 route_gateway_via_dhcp = DISABLED
Wed Aug 07 20:33:04 2013 us=171000 max_routes = 100
Wed Aug 07 20:33:04 2013 us=171000 allow_pull_fqdn = DISABLED
Wed Aug 07 20:33:04 2013 us=171000 management_addr = '[UNDEF]'
Wed Aug 07 20:33:04 2013 us=171000 management_port = 0
Wed Aug 07 20:33:04 2013 us=203000 management_user_pass = '[UNDEF]'
Wed Aug 07 20:33:04 2013 us=203000 management_log_history_cache = 250
Wed Aug 07 20:33:04 2013 us=203000 management_echo_buffer_size = 100
Wed Aug 07 20:33:04 2013 us=203000 management_write_peer_info_file = '[UNDEF]'
Wed Aug 07 20:33:04 2013 us=203000 management_client_user = '[UNDEF]'
Wed Aug 07 20:33:04 2013 us=203000 management_client_group = '[UNDEF]'
Wed Aug 07 20:33:04 2013 us=203000 management_flags = 0
Wed Aug 07 20:33:04 2013 us=203000 shared_secret_file = '[UNDEF]'
Wed Aug 07 20:33:04 2013 us=203000 key_direction = 0
Wed Aug 07 20:33:04 2013 us=203000 ciphername_defined = ENABLED
Wed Aug 07 20:33:04 2013 us=203000 ciphername = 'BF-CBC'
Wed Aug 07 20:33:04 2013 us=203000 authname_defined = ENABLED
Wed Aug 07 20:33:04 2013 us=203000 authname = 'SHA1'
Wed Aug 07 20:33:04 2013 us=203000 prng_hash = 'SHA1'
Wed Aug 07 20:33:04 2013 us=203000 prng_nonce_secret_len = 16
Wed Aug 07 20:33:04 2013 us=203000 keysize = 0
Wed Aug 07 20:33:04 2013 us=234000 engine = DISABLED
Wed Aug 07 20:33:04 2013 us=234000 replay = ENABLED
Wed Aug 07 20:33:04 2013 us=234000 mute_replay_warnings = DISABLED
Wed Aug 07 20:33:04 2013 us=234000 replay_window = 64
Wed Aug 07 20:33:04 2013 us=234000 replay_time = 15
Wed Aug 07 20:33:04 2013 us=234000 packet_id_file = '[UNDEF]'
Wed Aug 07 20:33:04 2013 us=234000 use_iv = ENABLED
Wed Aug 07 20:33:04 2013 us=234000 test_crypto = DISABLED
Wed Aug 07 20:33:04 2013 us=234000 tls_server = DISABLED
Wed Aug 07 20:33:04 2013 us=234000 tls_client = ENABLED
Wed Aug 07 20:33:04 2013 us=234000 key_method = 2
Wed Aug 07 20:33:04 2013 us=234000 ca_file = 'ca.crt'
Wed Aug 07 20:33:04 2013 us=234000 ca_path = '[UNDEF]'
Wed Aug 07 20:33:04 2013 us=234000 dh_file = '[UNDEF]'
Wed Aug 07 20:33:04 2013 us=234000 cert_file = 'ganesh.crt'
Wed Aug 07 20:33:04 2013 us=234000 priv_key_file = 'ganesh.key'
Wed Aug 07 20:33:04 2013 us=234000 pkcs12_file = '[UNDEF]'
Wed Aug 07 20:33:04 2013 us=250000 cryptoapi_cert = '[UNDEF]'
Wed Aug 07 20:33:04 2013 us=250000 cipher_list = '[UNDEF]'
Wed Aug 07 20:33:04 2013 us=250000 tls_verify = '[UNDEF]'
Wed Aug 07 20:33:04 2013 us=250000 tls_export_cert = '[UNDEF]'
Wed Aug 07 20:33:04 2013 us=250000 tls_remote = '[UNDEF]'
Wed Aug 07 20:33:04 2013 us=250000 crl_file = '[UNDEF]'
Wed Aug 07 20:33:04 2013 us=250000 ns_cert_type = 64
Wed Aug 07 20:33:04 2013 us=250000 remote_cert_ku = 0
Wed Aug 07 20:33:04 2013 us=250000 remote_cert_ku = 0
Wed Aug 07 20:33:04 2013 us=250000 remote_cert_ku = 0
Wed Aug 07 20:33:04 2013 us=250000 remote_cert_ku = 0
Wed Aug 07 20:33:04 2013 us=250000 remote_cert_ku = 0
Wed Aug 07 20:33:04 2013 us=250000 remote_cert_ku = 0
Wed Aug 07 20:33:04 2013 us=250000 remote_cert_ku = 0
Wed Aug 07 20:33:04 2013 us=250000 remote_cert_ku = 0
Wed Aug 07 20:33:04 2013 us=250000 remote_cert_ku = 0
Wed Aug 07 20:33:04 2013 us=281000 remote_cert_ku = 0
Wed Aug 07 20:33:04 2013 us=281000 remote_cert_ku[i] = 0
Wed Aug 07 20:33:04 2013 us=281000 remote_cert_ku[i] = 0
Wed Aug 07 20:33:04 2013 us=281000 remote_cert_ku[i] = 0
Wed Aug 07 20:33:04 2013 us=281000 remote_cert_ku[i] = 0
Wed Aug 07 20:33:04 2013 us=281000 remote_cert_ku[i] = 0
Wed Aug 07 20:33:04 2013 us=281000 remote_cert_ku[i] = 0
Wed Aug 07 20:33:04 2013 us=281000 remote_cert_eku = '[UNDEF]'
Wed Aug 07 20:33:04 2013 us=281000 tls_timeout = 2
Wed Aug 07 20:33:04 2013 us=281000 renegotiate_bytes = 0
Wed Aug 07 20:33:04 2013 us=281000 renegotiate_packets = 0
Wed Aug 07 20:33:04 2013 us=281000 renegotiate_seconds = 3600
Wed Aug 07 20:33:04 2013 us=281000 handshake_window = 60
Wed Aug 07 20:33:04 2013 us=281000 transition_window = 3600
Wed Aug 07 20:33:04 2013 us=281000 single_session = DISABLED
Wed Aug 07 20:33:04 2013 us=281000 push_peer_info = DISABLED
Wed Aug 07 20:33:04 2013 us=281000 tls_exit = DISABLED
Wed Aug 07 20:33:04 2013 us=296000 tls_auth_file = '[UNDEF]'
Wed Aug 07 20:33:04 2013 us=296000 pkcs11_protected_authentication = DISABLED
Wed Aug 07 20:33:04 2013 us=296000 pkcs11_protected_authentication = DISABLED
Wed Aug 07 20:33:04 2013 us=296000 pkcs11_protected_authentication = DISABLED
Wed Aug 07 20:33:04 2013 us=296000 pkcs11_protected_authentication = DISABLED
Wed Aug 07 20:33:04 2013 us=296000 pkcs11_protected_authentication = DISABLED
Wed Aug 07 20:33:04 2013 us=296000 pkcs11_protected_authentication = DISABLED
Wed Aug 07 20:33:04 2013 us=296000 pkcs11_protected_authentication = DISABLED
Wed Aug 07 20:33:04 2013 us=296000 pkcs11_protected_authentication = DISABLED
Wed Aug 07 20:33:04 2013 us=296000 pkcs11_protected_authentication = DISABLED
Wed Aug 07 20:33:04 2013 us=296000 pkcs11_protected_authentication = DISABLED
Wed Aug 07 20:33:04 2013 us=296000 pkcs11_protected_authentication = DISABLED
Wed Aug 07 20:33:04 2013 us=296000 pkcs11_protected_authentication = DISABLED
Wed Aug 07 20:33:04 2013 us=375000 pkcs11_protected_authentication = DISABLED
Wed Aug 07 20:33:04 2013 us=375000 pkcs11_protected_authentication = DISABLED
Wed Aug 07 20:33:04 2013 us=375000 pkcs11_protected_authentication = DISABLED
Wed Aug 07 20:33:04 2013 us=375000 pkcs11_protected_authentication = DISABLED
Wed Aug 07 20:33:04 2013 us=375000 pkcs11_private_mode = 00000000
Wed Aug 07 20:33:04 2013 us=375000 pkcs11_private_mode = 00000000
Wed Aug 07 20:33:04 2013 us=375000 pkcs11_private_mode = 00000000
Wed Aug 07 20:33:04 2013 us=375000 pkcs11_private_mode = 00000000
Wed Aug 07 20:33:04 2013 us=375000 pkcs11_private_mode = 00000000
Wed Aug 07 20:33:04 2013 us=375000 pkcs11_private_mode = 00000000
Wed Aug 07 20:33:04 2013 us=375000 pkcs11_private_mode = 00000000
Wed Aug 07 20:33:04 2013 us=375000 pkcs11_private_mode = 00000000
Wed Aug 07 20:33:04 2013 us=375000 pkcs11_private_mode = 00000000
Wed Aug 07 20:33:04 2013 us=375000 pkcs11_private_mode = 00000000
Wed Aug 07 20:33:04 2013 us=468000 pkcs11_private_mode = 00000000
Wed Aug 07 20:33:04 2013 us=468000 pkcs11_private_mode = 00000000
Wed Aug 07 20:33:04 2013 us=468000 pkcs11_private_mode = 00000000
Wed Aug 07 20:33:04 2013 us=468000 pkcs11_private_mode = 00000000
Wed Aug 07 20:33:04 2013 us=468000 pkcs11_private_mode = 00000000
Wed Aug 07 20:33:04 2013 us=468000 pkcs11_private_mode = 00000000
Wed Aug 07 20:33:04 2013 us=468000 pkcs11_cert_private = DISABLED
Wed Aug 07 20:33:04 2013 us=468000 pkcs11_cert_private = DISABLED
Wed Aug 07 20:33:04 2013 us=468000 pkcs11_cert_private = DISABLED
Wed Aug 07 20:33:04 2013 us=468000 pkcs11_cert_private = DISABLED
Wed Aug 07 20:33:04 2013 us=468000 pkcs11_cert_private = DISABLED
Wed Aug 07 20:33:04 2013 us=468000 pkcs11_cert_private = DISABLED
Wed Aug 07 20:33:04 2013 us=468000 pkcs11_cert_private = DISABLED
Wed Aug 07 20:33:04 2013 us=468000 pkcs11_cert_private = DISABLED
Wed Aug 07 20:33:04 2013 us=546000 pkcs11_cert_private = DISABLED
Wed Aug 07 20:33:04 2013 us=546000 pkcs11_cert_private = DISABLED
Wed Aug 07 20:33:04 2013 us=546000 pkcs11_cert_private = DISABLED
Wed Aug 07 20:33:04 2013 us=546000 pkcs11_cert_private = DISABLED
Wed Aug 07 20:33:04 2013 us=546000 pkcs11_cert_private = DISABLED
Wed Aug 07 20:33:04 2013 us=546000 pkcs11_cert_private = DISABLED
Wed Aug 07 20:33:04 2013 us=546000 pkcs11_cert_private = DISABLED
Wed Aug 07 20:33:04 2013 us=546000 pkcs11_cert_private = DISABLED
Wed Aug 07 20:33:04 2013 us=546000 pkcs11_pin_cache_period = -1
Wed Aug 07 20:33:04 2013 us=546000 pkcs11_id = '[UNDEF]'
Wed Aug 07 20:33:04 2013 us=546000 pkcs11_id_management = DISABLED
Wed Aug 07 20:33:04 2013 us=546000 server_network = 0.0.0.0
Wed Aug 07 20:33:04 2013 us=546000 server_netmask = 0.0.0.0
Wed Aug 07 20:33:04 2013 us=546000 server_bridge_ip = 0.0.0.0
Wed Aug 07 20:33:04 2013 us=546000 server_bridge_netmask = 0.0.0.0
Wed Aug 07 20:33:04 2013 us=640000 server_bridge_pool_start = 0.0.0.0
Wed Aug 07 20:33:04 2013 us=640000 server_bridge_pool_end = 0.0.0.0
Wed Aug 07 20:33:04 2013 us=640000 ifconfig_pool_defined = DISABLED
Wed Aug 07 20:33:04 2013 us=640000 ifconfig_pool_start = 0.0.0.0
Wed Aug 07 20:33:04 2013 us=640000 ifconfig_pool_end = 0.0.0.0
Wed Aug 07 20:33:04 2013 us=640000 ifconfig_pool_netmask = 0.0.0.0
Wed Aug 07 20:33:04 2013 us=640000 ifconfig_pool_persist_filename = '[UNDEF]'
Wed Aug 07 20:33:04 2013 us=640000 ifconfig_pool_persist_refresh_freq = 600
Wed Aug 07 20:33:04 2013 us=640000 n_bcast_buf = 256
Wed Aug 07 20:33:04 2013 us=640000 tcp_queue_limit = 64
Wed Aug 07 20:33:04 2013 us=640000 real_hash_size = 256
Wed Aug 07 20:33:04 2013 us=640000 virtual_hash_size = 256
Wed Aug 07 20:33:04 2013 us=640000 client_connect_script = '[UNDEF]'
Wed Aug 07 20:33:04 2013 us=640000 learn_address_script = '[UNDEF]'
Wed Aug 07 20:33:04 2013 us=703000 client_disconnect_script = '[UNDEF]'
Wed Aug 07 20:33:04 2013 us=703000 client_config_dir = '[UNDEF]'
Wed Aug 07 20:33:04 2013 us=703000 ccd_exclusive = DISABLED
Wed Aug 07 20:33:04 2013 us=703000 tmp_dir = 'C:\Users\ganesh\AppData\Local\Temp\'
Wed Aug 07 20:33:04 2013 us=703000 push_ifconfig_defined = DISABLED
Wed Aug 07 20:33:04 2013 us=703000 push_ifconfig_local = 0.0.0.0
Wed Aug 07 20:33:04 2013 us=703000 push_ifconfig_remote_netmask = 0.0.0.0
Wed Aug 07 20:33:04 2013 us=703000 enable_c2c = DISABLED
Wed Aug 07 20:33:04 2013 us=703000 duplicate_cn = DISABLED
Wed Aug 07 20:33:04 2013 us=703000 cf_max = 0
Wed Aug 07 20:33:04 2013 us=703000 cf_per = 0
Wed Aug 07 20:33:04 2013 us=703000 max_clients = 1024
Wed Aug 07 20:33:04 2013 us=703000 max_routes_per_client = 256
Wed Aug 07 20:33:04 2013 us=703000 auth_user_pass_verify_script = '[UNDEF]'
Wed Aug 07 20:33:04 2013 us=765000 auth_user_pass_verify_script_via_file = DISABLED
Wed Aug 07 20:33:04 2013 us=765000 ssl_flags = 0
Wed Aug 07 20:33:04 2013 us=765000 client = ENABLED
Wed Aug 07 20:33:04 2013 us=765000 pull = ENABLED
Wed Aug 07 20:33:04 2013 us=765000 auth_user_pass_file = '[UNDEF]'
Wed Aug 07 20:33:04 2013 us=765000 show_net_up = DISABLED
Wed Aug 07 20:33:04 2013 us=765000 route_method = 2
Wed Aug 07 20:33:04 2013 us=765000 ip_win32_defined = DISABLED
Wed Aug 07 20:33:04 2013 us=765000 ip_win32_type = 3
Wed Aug 07 20:33:04 2013 us=765000 dhcp_masq_offset = 0
Wed Aug 07 20:33:04 2013 us=765000 dhcp_lease_time = 31536000
Wed Aug 07 20:33:04 2013 us=765000 tap_sleep = 0
Wed Aug 07 20:33:04 2013 us=765000 dhcp_options = DISABLED
Wed Aug 07 20:33:04 2013 us=765000 dhcp_renew = DISABLED
Wed Aug 07 20:33:04 2013 us=765000 dhcp_pre_release = DISABLED
Wed Aug 07 20:33:04 2013 us=765000 dhcp_release = DISABLED
Wed Aug 07 20:33:04 2013 us=859000 domain = '[UNDEF]'
Wed Aug 07 20:33:04 2013 us=859000 netbios_scope = '[UNDEF]'
Wed Aug 07 20:33:04 2013 us=859000 netbios_node_type = 0
Wed Aug 07 20:33:04 2013 us=859000 disable_nbt = DISABLED
Wed Aug 07 20:33:04 2013 us=859000 OpenVPN 2.2.2 Win32-MSVC++ [SSL] [LZO2] [PKCS11] built on Dec 15 2011
Wed Aug 07 20:33:04 2013 us=859000 NOTE: OpenVPN 2.1 requires '--script-security 2' or higher to call user-defined scripts or executables
Wed Aug 07 20:33:04 2013 us=953000 LZO compression initialized
Wed Aug 07 20:33:04 2013 us=953000 Control Channel MTU parms [ L:1542 D:138 EF:38 EB:0 ET:0 EL:0 ]
Wed Aug 07 20:33:04 2013 us=953000 Socket Buffers: R=[65536->65536] S=[65536->65536]
Wed Aug 07 20:33:05 2013 us=31000 Data Channel MTU parms [ L:1542 D:1450 EF:42 EB:135 ET:0 EL:0 AF:3/1 ]
Wed Aug 07 20:33:05 2013 us=31000 Local Options String: 'V4,dev-type tun,link-mtu 1542,tun-mtu 1500,proto UDPv4,comp-lzo,cipher BF-CBC,auth SHA1,keysize 128,key-method 2,tls-client'
Wed Aug 07 20:33:05 2013 us=31000 Expected Remote Options String: 'V4,dev-type tun,link-mtu 1542,tun-mtu 1500,proto UDPv4,comp-lzo,cipher BF-CBC,auth SHA1,keysize 128,key-method 2,tls-server'
Wed Aug 07 20:33:05 2013 us=31000 Local Options hash (VER=V4): '41690919'
Wed Aug 07 20:33:05 2013 us=31000 Expected Remote Options hash (VER=V4): '530fdded'
Wed Aug 07 20:33:05 2013 us=31000 UDPv4 link local: [undef]
Wed Aug 07 20:33:05 2013 us=31000 UDPv4 link remote: 87.106.68.63:1194
Wed Aug 07 20:33:05 2013 us=62000 TLS: Initial packet from 87.106.68.63:1194, sid=3fc5e9ee 5726b504
Wed Aug 07 20:33:05 2013 us=531000 VERIFY OK: depth=1, /C=DE/ST=BV/L=Munich/O=GaneshPKI/OU=gnaeshpki/CN=ganesh/name=Ganesh/emailAddress=ganesh@apache.org
Wed Aug 07 20:33:05 2013 us=531000 VERIFY OK: nsCertType=SERVER
Wed Aug 07 20:33:05 2013 us=531000 VERIFY OK: depth=0, /C=DE/ST=BV/L=Munich/O=GaneshPKI/OU=gnaeshpki/CN=server/name=Ganesh/emailAddress=ganesh@apache.org
Wed Aug 07 20:33:06 2013 us=796000 Data Channel Encrypt: Cipher 'BF-CBC' initialized with 128 bit key
Wed Aug 07 20:33:06 2013 us=796000 Data Channel Encrypt: Using 160 bit message hash 'SHA1' for HMAC authentication
Wed Aug 07 20:33:06 2013 us=796000 Data Channel Decrypt: Cipher 'BF-CBC' initialized with 128 bit key
Wed Aug 07 20:33:06 2013 us=796000 Data Channel Decrypt: Using 160 bit message hash 'SHA1' for HMAC authentication
Wed Aug 07 20:33:06 2013 us=812000 Control Channel: TLSv1, cipher TLSv1/SSLv3 DHE-RSA-AES256-SHA, 4096 bit RSA
Wed Aug 07 20:33:06 2013 us=812000 [server] Peer Connection Initiated with 87.106.68.63:1194
Wed Aug 07 20:33:08 2013 us=828000 SENT CONTROL [server]: 'PUSH_REQUEST' (status=1)
Wed Aug 07 20:33:08 2013 us=968000 PUSH: Received control message: 'PUSH_REPLY,redirect-gateway def1 bypass-dhcp,dhcp-option DNS 208.67.222.222,dhcp-option DNS 208.67.220.220,route 10.8.13.1,topology net30,ping 10,ping-restart 120,ifconfig 10.8.13.6 10.8.13.5'
Wed Aug 07 20:33:08 2013 us=968000 OPTIONS IMPORT: timers and/or timeouts modified
Wed Aug 07 20:33:08 2013 us=968000 OPTIONS IMPORT: --ifconfig/up options modified
Wed Aug 07 20:33:08 2013 us=968000 OPTIONS IMPORT: route options modified
Wed Aug 07 20:33:08 2013 us=968000 OPTIONS IMPORT: --ip-win32 and/or --dhcp-option options modified
Wed Aug 07 20:33:09 2013 ROUTE default_gateway=192.168.1.1
Wed Aug 07 20:33:09 2013 us=31000 TAP-WIN32 device [LAN-Verbindung] opened: \\.\Global\{E48C252D-7804-482E-9094-CE15B9CAB9DA}.tap
Wed Aug 07 20:33:09 2013 us=31000 TAP-Win32 Driver Version 9.9
Wed Aug 07 20:33:09 2013 us=31000 TAP-Win32 MTU=1500
Wed Aug 07 20:33:09 2013 us=31000 Notified TAP-Win32 driver to set a DHCP IP/netmask of 10.8.13.6/255.255.255.252 on interface {E48C252D-7804-482E-9094-CE15B9CAB9DA} [DHCP-serv: 10.8.13.5, lease-time: 31536000]
Wed Aug 07 20:33:09 2013 us=31000 DHCP option string: 0608d043 deded043 dcdc
Wed Aug 07 20:33:09 2013 us=31000 Successful ARP Flush on interface [21] {E48C252D-7804-482E-9094-CE15B9CAB9DA}
Wed Aug 07 20:33:14 2013 us=437000 TEST ROUTES: 2/2 succeeded len=1 ret=1 a=0 u/d=up
Wed Aug 07 20:33:14 2013 us=437000 C:\WINDOWS\system32\route.exe ADD 87.106.68.63 MASK 255.255.255.255 192.168.1.1
OK!
Wed Aug 07 20:33:14 2013 us=453000 C:\WINDOWS\system32\route.exe ADD 0.0.0.0 MASK 128.0.0.0 10.8.13.5
OK!
Wed Aug 07 20:33:14 2013 us=468000 C:\WINDOWS\system32\route.exe ADD 128.0.0.0 MASK 128.0.0.0 10.8.13.5
OK!
Wed Aug 07 20:33:14 2013 us=484000 C:\WINDOWS\system32\route.exe ADD 10.8.13.1 MASK 255.255.255.255 10.8.13.5
OK!
Wed Aug 07 20:33:14 2013 us=484000 Initialization Sequence Completed

Re: Windows 8 client + Debian wheezy connects but no ping

Posted: Wed Aug 07, 2013 7:00 pm
by ganesh
I've followed several tips to get OpenVPN up on windows:

- The firewall is disabled
- RAS is activated
- The Network Connections service is started
- OpenVPN is running with admin privileges

Still no success: the try icons turns green, everything looks fine, but I can't even ping through the tunnel:

C:\Users\ganesh>ping 10.8.13.0

Ping wird ausgeführt für 10.8.13.0 mit 32 Bytes Daten:
Zeitüberschreitung der Anforderung.
Zeitüberschreitung der Anforderung.
Zeitüberschreitung der Anforderung.
Zeitüberschreitung der Anforderung.

Ping-Statistik für 10.8.13.0:
Pakete: Gesendet = 4, Empfangen = 0, Verloren = 4
(100% Verlust)

As soon as I'm "connected" no more internet traffic is possible:

C:\Users\ganesh>nslookup heise.de
DNS request timed out.
timeout was 2 seconds.
Server: UnKnown
Address: 208.67.222.222

DNS request timed out.
timeout was 2 seconds.
DNS request timed out.
timeout was 2 seconds.
DNS request timed out.
timeout was 2 seconds.
DNS request timed out.
timeout was 2 seconds.
*** Zeitüberschreitung bei Anforderung an UnKnown.

Re: Windows 8 client + Debian wheezy connects but no ping

Posted: Wed Aug 07, 2013 7:02 pm
by ganesh
Any pitiful soul around with an idea what else I could try to penetrate this tunnel?

Re: Windows 8 client + Debian wheezy connects but no ping

Posted: Wed Aug 07, 2013 7:08 pm
by ganesh
I forgot to mention these two steps I took:

echo 1 > /proc/sys/net/ipv4/ip_forward

and

apt-get install dnsmasq

with /etc/dnsmasq.conf:

listen-address=127.0.0.1,10.8.0.1
bind-interfaces

/etc/init.d/dnsmasq restart

Re: Windows 8 client + Debian wheezy connects but no ping

Posted: Fri Sep 20, 2013 8:50 am
by leon_funnell@hotmail.com
Did you get it working? I have a similar issue using OpenVPN AS on Centos 5 with Windows 8 x64 client. It works fine when connecting from my Android device, but Windows 8 doesnt work. It says connected, but ipconfig doesnt show the assigned IP address, and route print doesnt show any routes to the VPN tunnel. Needless to say it doesnt work...

Re: Windows 8 client + Debian wheezy connects but no ping

Posted: Fri Sep 20, 2013 5:10 pm
by ganesh
No, still doesn't work. It seems OpenVPN with Linux server and Windows 8 client is not supported.