Page 1 of 1

Ping does not work through a tunnel ( Server: Win 2003 SBS)

Posted: Sat Jul 16, 2011 10:57 pm
by cevacevikus
Hi,

I have a problem with the OpenVPN setup on server with Windows 2003 SBS.

I need to set up a classic Road Warrior scenario: access to shared files on the server, connecting to the exchange, remote desktop from clients copmuters...

Establishing the connection works, but ping is a 100 % packet loss.

Topology
Internet == WAN NIC == SBS Server == LAN NIC

LAN NIC IP:192.168.16.2
OpenVPN server IP:10.8.0.1
OpenVPN client IP:10.8.0.10

Server config: (Win 2003 SBS)

Code: Select all

port 1194
proto udp
dev tun
ca ca.crt
cert server.crt
key server.key  # This file should be kept secret
dh dh1024.pem
server 10.8.0.0 255.255.255.0
ifconfig-pool-persist ipp.txt
push "route 10.8.0.0 255.255.255.0"
push "route 192.168.1.0 255.255.255.0"
push "dhcp-option DNS 192.168.16.2"
push "dhcp-option WINS 192.168.16.2"
client-to-client
keepalive 10 120
comp-lzo
persist-key
persist-tun
status openvpn-status.log
verb 6
mute 20
Server netstat -nr:
(Žádné = None)

Code: Select all

IPv4 Směrovací tabulka
===========================================================================
Seznam rozhraní
0x1 ........................... MS TCP Loopback interface
0x2 ...00 ff cb ba bf 67 ...... TAP-Win32 Adapter V9
0x10004 ...00 00 5a 75 59 e0 ...... SysKonnect SK-9521 V2.0 10/100/1000Base-T Ad
apter, PCI, Copper RJ-45
0x10005 ...00 19 99 33 1e a3 ...... Intel(R) 82566DM-2 Gigabit Network Connectio
n
===========================================================================
===========================================================================
Aktivní směrování:
         Cíl v síti   Síťová maska            Brána        Rozhraní Metrika
          0.0.0.0          0.0.0.0    89.190.76.129    89.190.76.WAN      1
         10.8.0.0  255.255.255.252         10.8.0.1         10.8.0.1     30
         10.8.0.1  255.255.255.255        127.0.0.1        127.0.0.1     30
   10.255.255.255  255.255.255.255         10.8.0.1         10.8.0.1     30
    89.190.76.128  255.255.255.192    89.190.76.WAN    89.190.76.WAN     10
    89.190.76.WAN  255.255.255.255        127.0.0.1        127.0.0.1     10
   89.255.255.255  255.255.255.255    89.190.76.WAN    89.190.76.WAN     10
        127.0.0.0        255.0.0.0        127.0.0.1        127.0.0.1      1
     192.168.16.0    255.255.255.0     192.168.16.2     192.168.16.2     20
     192.168.16.2  255.255.255.255        127.0.0.1        127.0.0.1     20
   192.168.16.255  255.255.255.255     192.168.16.2     192.168.16.2     20
        224.0.0.0        240.0.0.0         10.8.0.1         10.8.0.1     30
        224.0.0.0        240.0.0.0    89.190.76.WAN    89.190.76.WAN     10
        224.0.0.0        240.0.0.0     192.168.16.2     192.168.16.2     20
  255.255.255.255  255.255.255.255         10.8.0.1         10.8.0.1      1
  255.255.255.255  255.255.255.255    89.190.76.WAN    89.190.76.WAN      1
  255.255.255.255  255.255.255.255     192.168.16.2     192.168.16.2      1
Výchozí brána:     89.190.76.129
===========================================================================
Trvalé trasy:
  Žádné
Server log:

Code: Select all

Mon Jul 18 01:45:40 2011 us=468000 Current Parameter Settings:
Mon Jul 18 01:45:40 2011 us=468000   config = 'server.ovpn'
Mon Jul 18 01:45:40 2011 us=468000   mode = 1
Mon Jul 18 01:45:40 2011 us=468000   show_ciphers = DISABLED
Mon Jul 18 01:45:40 2011 us=468000   show_digests = DISABLED
Mon Jul 18 01:45:40 2011 us=468000   show_engines = DISABLED
Mon Jul 18 01:45:40 2011 us=468000   genkey = DISABLED
Mon Jul 18 01:45:40 2011 us=468000   key_pass_file = '[UNDEF]'
Mon Jul 18 01:45:40 2011 us=468000   show_tls_ciphers = DISABLED
Mon Jul 18 01:45:40 2011 us=468000 Connection profiles [default]:
Mon Jul 18 01:45:40 2011 us=468000   proto = udp
Mon Jul 18 01:45:40 2011 us=468000   local = '[UNDEF]'
Mon Jul 18 01:45:40 2011 us=468000   local_port = 1194
Mon Jul 18 01:45:40 2011 us=468000   remote = '[UNDEF]'
Mon Jul 18 01:45:40 2011 us=468000   remote_port = 1194
Mon Jul 18 01:45:40 2011 us=468000   remote_float = DISABLED
Mon Jul 18 01:45:40 2011 us=468000   bind_defined = DISABLED
Mon Jul 18 01:45:40 2011 us=468000   bind_local = ENABLED
Mon Jul 18 01:45:40 2011 us=468000   connect_retry_seconds = 5
Mon Jul 18 01:45:40 2011 us=468000   connect_timeout = 10
Mon Jul 18 01:45:40 2011 us=468000 NOTE: --mute triggered...
Mon Jul 18 01:45:40 2011 us=468000 210 variation(s) on previous 20 message(s) suppressed by --mute
Mon Jul 18 01:45:40 2011 us=468000 OpenVPN 2.2.1 Win32-MSVC++ [SSL] [LZO2] built on Jul  1 2011
Mon Jul 18 01:45:40 2011 us=468000 NOTE: OpenVPN 2.1 requires '--script-security 2' or higher to call user-defined scripts or executables
Mon Jul 18 01:45:40 2011 us=968000 Diffie-Hellman initialized with 1024 bit key
Mon Jul 18 01:45:41 2011 us=218000 TLS-Auth MTU parms [ L:1542 D:138 EF:38 EB:0 ET:0 EL:0 ]
Mon Jul 18 01:45:41 2011 us=218000 Socket Buffers: R=[8192->8192] S=[8192->8192]
Mon Jul 18 01:45:41 2011 us=250000 ROUTE default_gateway=89.190.76.129
Mon Jul 18 01:45:41 2011 us=281000 TAP-WIN32 device [OpenVPN] opened: \\.\Global\{CBBABF67-377D-42CF-9615-8E080CDB553E}.tap
Mon Jul 18 01:45:41 2011 us=281000 TAP-Win32 Driver Version 9.8 
Mon Jul 18 01:45:41 2011 us=281000 TAP-Win32 MTU=1500
Mon Jul 18 01:45:41 2011 us=281000 Notified TAP-Win32 driver to set a DHCP IP/netmask of 10.8.0.1/255.255.255.252 on interface {CBBABF67-377D-42CF-9615-8E080CDB553E} [DHCP-serv: 10.8.0.2, lease-time: 31536000]
Mon Jul 18 01:45:41 2011 us=281000 Sleeping for 10 seconds...
Mon Jul 18 01:45:51 2011 us=312000 NOTE: FlushIpNetTable failed on interface [2] {CBBABF67-377D-42CF-9615-8E080CDB553E} (status=1413) : Neplatný index.  
Mon Jul 18 01:45:51 2011 us=312000 C:\WINDOWS\system32\route.exe ADD 10.8.0.0 MASK 255.255.255.0 10.8.0.2
Mon Jul 18 01:45:51 2011 us=312000 Warning: route gateway is not reachable on any active network adapters: 10.8.0.2
Mon Jul 18 01:45:51 2011 us=312000 Route addition via IPAPI failed [adaptive]
Mon Jul 18 01:45:51 2011 us=312000 Route addition fallback to route.exe
Pýid nˇ trasy se nezdaýilo: BuÔ je index rozhranˇ chybně, nebo br na nenˇ ve stejn‚ sˇti jako
rozhranˇ. Zkontrolujte u tohoto poźˇtaźe tabulku adres IP.
Mon Jul 18 01:45:51 2011 us=640000 Data Channel MTU parms [ L:1542 D:1450 EF:42 EB:135 ET:0 EL:0 AF:3/1 ]
Mon Jul 18 01:45:51 2011 us=640000 UDPv4 link local (bound): [undef]:1194
Mon Jul 18 01:45:51 2011 us=640000 UDPv4 link remote: [undef]
Mon Jul 18 01:45:51 2011 us=640000 MULTI: multi_init called, r=256 v=256
Mon Jul 18 01:45:51 2011 us=640000 IFCONFIG POOL: base=10.8.0.4 size=62
Mon Jul 18 01:45:51 2011 us=640000 IFCONFIG POOL LIST
Mon Jul 18 01:45:51 2011 us=640000 *DNSname*.nsys.cz,10.8.0.4
Mon Jul 18 01:45:51 2011 us=640000 server,10.8.0.8
Mon Jul 18 01:45:51 2011 us=640000 Initialization Sequence Completed
Mon Jul 18 01:48:36 2011 us=171000 MULTI: multi_create_instance called
Mon Jul 18 01:48:36 2011 us=171000 89.190.95.44:50415 Re-using SSL/TLS context
Mon Jul 18 01:48:36 2011 us=171000 89.190.95.44:50415 LZO compression initialized
Mon Jul 18 01:48:36 2011 us=171000 89.190.95.44:50415 Control Channel MTU parms [ L:1542 D:138 EF:38 EB:0 ET:0 EL:0 ]
Mon Jul 18 01:48:36 2011 us=171000 89.190.95.44:50415 Data Channel MTU parms [ L:1542 D:1450 EF:42 EB:135 ET:0 EL:0 AF:3/1 ]
Mon Jul 18 01:48:36 2011 us=171000 89.190.95.44:50415 Local Options String: 'V4,dev-type tun,link-mtu 1542,tun-mtu 1500,proto UDPv4,comp-lzo,cipher BF-CBC,auth SHA1,keysize 128,key-method 2,tls-server'
Mon Jul 18 01:48:36 2011 us=171000 89.190.95.44:50415 Expected Remote Options String: 'V4,dev-type tun,link-mtu 1542,tun-mtu 1500,proto UDPv4,comp-lzo,cipher BF-CBC,auth SHA1,keysize 128,key-method 2,tls-client'
Mon Jul 18 01:48:36 2011 us=171000 89.190.95.44:50415 Local Options hash (VER=V4): '530fdded'
Mon Jul 18 01:48:36 2011 us=171000 89.190.95.44:50415 Expected Remote Options hash (VER=V4): '41690919'
Mon Jul 18 01:48:36 2011 us=171000 89.190.95.44:50415 UDPv4 READ [14] from 89.190.95.44:50415: P_CONTROL_HARD_RESET_CLIENT_V2 kid=0 [ ] pid=0 DATA len=0
Mon Jul 18 01:48:36 2011 us=171000 89.190.95.44:50415 TLS: Initial packet from 89.190.95.44:50415, sid=c6371ef0 ae7af44e
Mon Jul 18 01:48:36 2011 us=171000 89.190.95.44:50415 UDPv4 WRITE [26] to 89.190.95.44:50415: P_CONTROL_HARD_RESET_SERVER_V2 kid=0 [ 0 ] pid=0 DATA len=0
Mon Jul 18 01:48:36 2011 us=187000 89.190.95.44:50415 UDPv4 READ [22] from 89.190.95.44:50415: P_ACK_V1 kid=0 [ 0 ]
Mon Jul 18 01:48:36 2011 us=187000 89.190.95.44:50415 UDPv4 READ [114] from 89.190.95.44:50415: P_CONTROL_V1 kid=0 [ ] pid=1 DATA len=100
Mon Jul 18 01:48:36 2011 us=187000 89.190.95.44:50415 UDPv4 WRITE [22] to 89.190.95.44:50415: P_ACK_V1 kid=0 [ 1 ]
Mon Jul 18 01:48:36 2011 us=187000 89.190.95.44:50415 UDPv4 READ [114] from 89.190.95.44:50415: P_CONTROL_V1 kid=0 [ ] pid=2 DATA len=100
Mon Jul 18 01:48:36 2011 us=187000 89.190.95.44:50415 UDPv4 WRITE [22] to 89.190.95.44:50415: P_ACK_V1 kid=0 [ 2 ]
Mon Jul 18 01:48:36 2011 us=187000 89.190.95.44:50415 UDPv4 READ [24] from 89.190.95.44:50415: P_CONTROL_V1 kid=0 [ ] pid=3 DATA len=10
Mon Jul 18 01:48:36 2011 us=203000 89.190.95.44:50415 UDPv4 WRITE [126] to 89.190.95.44:50415: P_CONTROL_V1 kid=0 [ 3 ] pid=1 DATA len=100
Mon Jul 18 01:48:36 2011 us=203000 89.190.95.44:50415 UDPv4 WRITE [114] to 89.190.95.44:50415: P_CONTROL_V1 kid=0 [ ] pid=2 DATA len=100
Mon Jul 18 01:48:36 2011 us=203000 89.190.95.44:50415 UDPv4 WRITE [114] to 89.190.95.44:50415: P_CONTROL_V1 kid=0 [ ] pid=3 DATA len=100
Mon Jul 18 01:48:36 2011 us=203000 89.190.95.44:50415 UDPv4 WRITE [114] to 89.190.95.44:50415: P_CONTROL_V1 kid=0 [ ] pid=4 DATA len=100
Mon Jul 18 01:48:36 2011 us=218000 89.190.95.44:50415 UDPv4 READ [22] from 89.190.95.44:50415: P_ACK_V1 kid=0 [ 1 ]
Mon Jul 18 01:48:36 2011 us=218000 89.190.95.44:50415 UDPv4 WRITE [114] to 89.190.95.44:50415: P_CONTROL_V1 kid=0 [ ] pid=5 DATA len=100
Mon Jul 18 01:48:36 2011 us=218000 89.190.95.44:50415 UDPv4 READ [22] from 89.190.95.44:50415: P_ACK_V1 kid=0 [ 2 ]
Mon Jul 18 01:48:36 2011 us=218000 89.190.95.44:50415 UDPv4 WRITE [114] to 89.190.95.44:50415: P_CONTROL_V1 kid=0 [ ] pid=6 DATA len=100
Mon Jul 18 01:48:36 2011 us=218000 89.190.95.44:50415 UDPv4 READ [22] from 89.190.95.44:50415: P_ACK_V1 kid=0 [ 3 ]
Mon Jul 18 01:48:36 2011 us=218000 89.190.95.44:50415 UDPv4 WRITE [114] to 89.190.95.44:50415: P_CONTROL_V1 kid=0 [ ] pid=7 DATA len=100
Mon Jul 18 01:48:36 2011 us=218000 89.190.95.44:50415 UDPv4 READ [22] from 89.190.95.44:50415: P_ACK_V1 kid=0 [ 4 ]
Mon Jul 18 01:48:36 2011 us=218000 89.190.95.44:50415 UDPv4 WRITE [114] to 89.190.95.44:50415: P_CONTROL_V1 kid=0 [ ] pid=8 DATA len=100
Mon Jul 18 01:48:36 2011 us=234000 89.190.95.44:50415 UDPv4 READ [22] from 89.190.95.44:50415: P_ACK_V1 kid=0 [ 5 ]
Mon Jul 18 01:48:36 2011 us=234000 89.190.95.44:50415 NOTE: --mute triggered...
Mon Jul 18 01:48:36 2011 us=468000 89.190.95.44:50415 83 variation(s) on previous 20 message(s) suppressed by --mute
Mon Jul 18 01:48:36 2011 us=468000 89.190.95.44:50415 VERIFY OK: depth=1, *Cert info*
Mon Jul 18 01:48:36 2011 us=468000 89.190.95.44:50415 VERIFY OK: depth=0, *Cert info*
Mon Jul 18 01:48:36 2011 us=468000 89.190.95.44:50415 UDPv4 WRITE [22] to 89.190.95.44:50415: P_ACK_V1 kid=0 [ 24 ]
Mon Jul 18 01:48:36 2011 us=468000 89.190.95.44:50415 UDPv4 READ [114] from 89.190.95.44:50415: P_CONTROL_V1 kid=0 [ ] pid=25 DATA len=100
Mon Jul 18 01:48:36 2011 us=468000 89.190.95.44:50415 UDPv4 WRITE [22] to 89.190.95.44:50415: P_ACK_V1 kid=0 [ 25 ]
Mon Jul 18 01:48:36 2011 us=468000 89.190.95.44:50415 UDPv4 READ [114] from 89.190.95.44:50415: P_CONTROL_V1 kid=0 [ ] pid=26 DATA len=100
Mon Jul 18 01:48:36 2011 us=468000 89.190.95.44:50415 UDPv4 WRITE [22] to 89.190.95.44:50415: P_ACK_V1 kid=0 [ 26 ]
Mon Jul 18 01:48:36 2011 us=484000 89.190.95.44:50415 UDPv4 READ [114] from 89.190.95.44:50415: P_CONTROL_V1 kid=0 [ ] pid=27 DATA len=100
Mon Jul 18 01:48:36 2011 us=515000 89.190.95.44:50415 UDPv4 WRITE [22] to 89.190.95.44:50415: P_ACK_V1 kid=0 [ 27 ]
Mon Jul 18 01:48:36 2011 us=515000 89.190.95.44:50415 UDPv4 READ [51] from 89.190.95.44:50415: P_CONTROL_V1 kid=0 [ ] pid=28 DATA len=37
Mon Jul 18 01:48:36 2011 us=515000 89.190.95.44:50415 UDPv4 WRITE [126] to 89.190.95.44:50415: P_CONTROL_V1 kid=0 [ 28 ] pid=29 DATA len=100
Mon Jul 18 01:48:36 2011 us=515000 89.190.95.44:50415 UDPv4 WRITE [114] to 89.190.95.44:50415: P_CONTROL_V1 kid=0 [ ] pid=30 DATA len=100
Mon Jul 18 01:48:36 2011 us=515000 89.190.95.44:50415 UDPv4 WRITE [114] to 89.190.95.44:50415: P_CONTROL_V1 kid=0 [ ] pid=31 DATA len=100
Mon Jul 18 01:48:36 2011 us=515000 89.190.95.44:50415 UDPv4 WRITE [114] to 89.190.95.44:50415: P_CONTROL_V1 kid=0 [ ] pid=32 DATA len=100
Mon Jul 18 01:48:36 2011 us=531000 89.190.95.44:50415 UDPv4 READ [22] from 89.190.95.44:50415: P_ACK_V1 kid=0 [ 29 ]
Mon Jul 18 01:48:36 2011 us=531000 89.190.95.44:50415 UDPv4 WRITE [114] to 89.190.95.44:50415: P_CONTROL_V1 kid=0 [ ] pid=33 DATA len=100
Mon Jul 18 01:48:36 2011 us=531000 89.190.95.44:50415 UDPv4 READ [22] from 89.190.95.44:50415: P_ACK_V1 kid=0 [ 30 ]
Mon Jul 18 01:48:36 2011 us=531000 89.190.95.44:50415 UDPv4 WRITE [114] to 89.190.95.44:50415: P_CONTROL_V1 kid=0 [ ] pid=34 DATA len=100
Mon Jul 18 01:48:36 2011 us=531000 89.190.95.44:50415 UDPv4 READ [22] from 89.190.95.44:50415: P_ACK_V1 kid=0 [ 31 ]
Mon Jul 18 01:48:36 2011 us=531000 89.190.95.44:50415 UDPv4 WRITE [114] to 89.190.95.44:50415: P_CONTROL_V1 kid=0 [ ] pid=35 DATA len=100
Mon Jul 18 01:48:36 2011 us=546000 89.190.95.44:50415 UDPv4 READ [22] from 89.190.95.44:50415: P_ACK_V1 kid=0 [ 32 ]
Mon Jul 18 01:48:36 2011 us=546000 89.190.95.44:50415 UDPv4 WRITE [114] to 89.190.95.44:50415: P_CONTROL_V1 kid=0 [ ] pid=36 DATA len=100
Mon Jul 18 01:48:36 2011 us=546000 89.190.95.44:50415 NOTE: --mute triggered...
Mon Jul 18 01:48:36 2011 us=609000 89.190.95.44:50415 22 variation(s) on previous 20 message(s) suppressed by --mute
Mon Jul 18 01:48:36 2011 us=609000 89.190.95.44:50415 Data Channel Encrypt: Cipher 'BF-CBC' initialized with 128 bit key
Mon Jul 18 01:48:36 2011 us=609000 89.190.95.44:50415 Data Channel Encrypt: Using 160 bit message hash 'SHA1' for HMAC authentication
Mon Jul 18 01:48:36 2011 us=609000 89.190.95.44:50415 Data Channel Decrypt: Cipher 'BF-CBC' initialized with 128 bit key
Mon Jul 18 01:48:36 2011 us=609000 89.190.95.44:50415 Data Channel Decrypt: Using 160 bit message hash 'SHA1' for HMAC authentication
Mon Jul 18 01:48:36 2011 us=609000 89.190.95.44:50415 UDPv4 WRITE [126] to 89.190.95.44:50415: P_CONTROL_V1 kid=0 [ 32 ] pid=43 DATA len=100
Mon Jul 18 01:48:36 2011 us=609000 89.190.95.44:50415 UDPv4 WRITE [114] to 89.190.95.44:50415: P_CONTROL_V1 kid=0 [ ] pid=44 DATA len=100
Mon Jul 18 01:48:36 2011 us=609000 89.190.95.44:50415 UDPv4 WRITE [80] to 89.190.95.44:50415: P_CONTROL_V1 kid=0 [ ] pid=45 DATA len=66
Mon Jul 18 01:48:36 2011 us=625000 89.190.95.44:50415 UDPv4 READ [22] from 89.190.95.44:50415: P_ACK_V1 kid=0 [ 43 ]
Mon Jul 18 01:48:36 2011 us=625000 89.190.95.44:50415 UDPv4 READ [22] from 89.190.95.44:50415: P_ACK_V1 kid=0 [ 44 ]
Mon Jul 18 01:48:36 2011 us=625000 89.190.95.44:50415 UDPv4 READ [22] from 89.190.95.44:50415: P_ACK_V1 kid=0 [ 45 ]
Mon Jul 18 01:48:36 2011 us=625000 89.190.95.44:50415 Control Channel: TLSv1, cipher TLSv1/SSLv3 DHE-RSA-AES256-SHA, 1024 bit RSA
Mon Jul 18 01:48:36 2011 us=625000 89.190.95.44:50415 [server] Peer Connection Initiated with 89.190.95.44:50415
Mon Jul 18 01:48:36 2011 us=625000 server/89.190.95.44:50415 MULTI: Learn: 10.8.0.10 -> server/89.190.95.44:50415
Mon Jul 18 01:48:36 2011 us=625000 server/89.190.95.44:50415 MULTI: primary virtual IP for server/89.190.95.44:50415: 10.8.0.10
Mon Jul 18 01:48:38 2011 us=812000 server/89.190.95.44:50415 UDPv4 READ [104] from 89.190.95.44:50415: P_CONTROL_V1 kid=0 [ ] pid=33 DATA len=90
Mon Jul 18 01:48:38 2011 us=812000 server/89.190.95.44:50415 PUSH: Received control message: 'PUSH_REQUEST'
Mon Jul 18 01:48:38 2011 us=812000 server/89.190.95.44:50415 SENT CONTROL [server]: 'PUSH_REPLY,route 192.168.1.0 255.255.255.0,dhcp-option DNS 192.168.1.2,dhcp-option WINS 192.168.1.2,route 10.8.0.1,topology net30,ping 10,ping-restart 120,ifconfig 10.8.0.10 10.8.0.9' (status=1)
Mon Jul 18 01:48:38 2011 us=812000 server/89.190.95.44:50415 UDPv4 WRITE [22] to 89.190.95.44:50415: P_ACK_V1 kid=0 [ 33 ]
Mon Jul 18 01:48:38 2011 us=812000 server/89.190.95.44:50415 UDPv4 WRITE [114] to 89.190.95.44:50415: P_CONTROL_V1 kid=0 [ ] pid=46 DATA len=100
Mon Jul 18 01:48:38 2011 us=812000 server/89.190.95.44:50415 UDPv4 WRITE [114] to 89.190.95.44:50415: P_CONTROL_V1 kid=0 [ ] pid=47 DATA len=100
Mon Jul 18 01:48:38 2011 us=812000 server/89.190.95.44:50415 UDPv4 WRITE [64] to 89.190.95.44:50415: P_CONTROL_V1 kid=0 [ ] pid=48 DATA len=50
Mon Jul 18 01:48:38 2011 us=828000 server/89.190.95.44:50415 UDPv4 READ [22] from 89.190.95.44:50415: P_ACK_V1 kid=0 [ 46 ]
Mon Jul 18 01:48:38 2011 us=828000 server/89.190.95.44:50415 UDPv4 READ [22] from 89.190.95.44:50415: P_ACK_V1 kid=0 [ 47 ]
Mon Jul 18 01:48:38 2011 us=875000 server/89.190.95.44:50415 UDPv4 READ [22] from 89.190.95.44:50415: P_ACK_V1 kid=0 [ 48 ]
Mon Jul 18 01:48:48 2011 us=750000 server/89.190.95.44:50415 UDPv4 WRITE [53] to 89.190.95.44:50415: P_DATA_V1 kid=0 DATA len=52
Mon Jul 18 01:48:48 2011 us=750000 server/89.190.95.44:50415 UDPv4 READ [53] from 89.190.95.44:50415: P_DATA_V1 kid=0 DATA len=52
Mon Jul 18 01:48:59 2011 us=62000 server/89.190.95.44:50415 UDPv4 WRITE [53] to 89.190.95.44:50415: P_DATA_V1 kid=0 DATA len=52
Mon Jul 18 01:48:59 2011 us=62000 server/89.190.95.44:50415 UDPv4 READ [53] from 89.190.95.44:50415: P_DATA_V1 kid=0 DATA len=52
Mon Jul 18 01:49:09 2011 us=250000 server/89.190.95.44:50415 UDPv4 READ [53] from 89.190.95.44:50415: P_DATA_V1 kid=0 DATA len=52
Mon Jul 18 01:49:09 2011 us=250000 server/89.190.95.44:50415 UDPv4 WRITE [53] to 89.190.95.44:50415: P_DATA_V1 kid=0 DATA len=52
Mon Jul 18 01:49:18 2011 us=796000 server/89.190.95.44:50415 UDPv4 READ [53] from 89.190.95.44:50415: P_DATA_V1 kid=0 DATA len=52
Mon Jul 18 01:49:19 2011 us=937000 server/89.190.95.44:50415 UDPv4 WRITE [53] to 89.190.95.44:50415: P_DATA_V1 kid=0 DATA len=52
Mon Jul 18 01:49:29 2011 us=31000 server/89.190.95.44:50415 UDPv4 WRITE [53] to 89.190.95.44:50415: P_DATA_V1 kid=0 DATA len=52
Mon Jul 18 01:49:29 2011 us=31000 server/89.190.95.44:50415 UDPv4 READ [53] from 89.190.95.44:50415: P_DATA_V1 kid=0 DATA len=52
Client config: (Win 7 x64 Pro)

Code: Select all

client
dev tun
proto udp
remote *DNSname*.nsys.cz 1194
resolv-retry infinite
nobind
persist-key
persist-tun
ca ca.crt
cert client.crt
key client.key
ns-cert-type server
comp-lzo
verb 6
mute 20
route-method exe
route-delay 2  
Client netstat -nr:
(Propojené = Connected)

(Žádné = None)

Code: Select all

Seznam rozhraní
 37...00 ff 80 56 df 53 ......TAP-Win32 Adapter V9
 10...00 1f d0 97 bf 0b ......Realtek PCIe GBE Family Controller
  1...........................Software Loopback Interface 1
 21...00 00 00 00 00 00 00 e0 Microsoft ISATAP Adapter
 20...00 00 00 00 00 00 00 e0 Teredo Tunneling Pseudo-Interface
 26...00 00 00 00 00 00 00 e0 Microsoft 6to4 Adapter #6
 29...00 00 00 00 00 00 00 e0 Microsoft ISATAP Adapter #2
===========================================================================

IPv4 Směrovací tabulka
===========================================================================
Aktivní směrování:
         Cíl v síti   Síťová maska            Brána        Rozhraní Metrika
          0.0.0.0          0.0.0.0      192.168.1.1     192.168.1.30     20
         10.8.0.1  255.255.255.255         10.8.0.9        10.8.0.10     31
         10.8.0.8  255.255.255.252       Propojené         10.8.0.10    286
        10.8.0.10  255.255.255.255       Propojené         10.8.0.10    286
        10.8.0.11  255.255.255.255       Propojené         10.8.0.10    286
        127.0.0.0        255.0.0.0       Propojené         127.0.0.1    306
        127.0.0.1  255.255.255.255       Propojené         127.0.0.1    306
  127.255.255.255  255.255.255.255       Propojené         127.0.0.1    306
      192.168.1.0    255.255.255.0       Propojené      192.168.1.30    276
     192.168.1.30  255.255.255.255       Propojené      192.168.1.30    276
    192.168.1.255  255.255.255.255       Propojené      192.168.1.30    276
     192.168.16.0    255.255.255.0       Propojené         10.8.0.10     31
     192.168.16.0    255.255.255.0         10.8.0.9        10.8.0.10     31
   192.168.16.255  255.255.255.255       Propojené         10.8.0.10    286
        224.0.0.0        240.0.0.0       Propojené         127.0.0.1    306
        224.0.0.0        240.0.0.0       Propojené      192.168.1.30    276
        224.0.0.0        240.0.0.0       Propojené         10.8.0.10    286
  255.255.255.255  255.255.255.255       Propojené         127.0.0.1    306
  255.255.255.255  255.255.255.255       Propojené      192.168.1.30    276
  255.255.255.255  255.255.255.255       Propojené         10.8.0.10    286
===========================================================================
Trvalé trasy:
  Žádné

Client log:

Code: Select all


Mon Jul 18 01:48:06 2011 us=151000 Current Parameter Settings:
Mon Jul 18 01:48:06 2011 us=151000   config = 'client.ovpn'
Mon Jul 18 01:48:06 2011 us=151000   mode = 0
Mon Jul 18 01:48:06 2011 us=151000   show_ciphers = DISABLED
Mon Jul 18 01:48:06 2011 us=151000   show_digests = DISABLED
Mon Jul 18 01:48:06 2011 us=151000   show_engines = DISABLED
Mon Jul 18 01:48:06 2011 us=151000   genkey = DISABLED
Mon Jul 18 01:48:06 2011 us=151000   key_pass_file = '[UNDEF]'
Mon Jul 18 01:48:06 2011 us=151000   show_tls_ciphers = DISABLED
Mon Jul 18 01:48:06 2011 us=151000 Connection profiles [default]:
Mon Jul 18 01:48:06 2011 us=151000   proto = udp
Mon Jul 18 01:48:06 2011 us=151000   local = '[UNDEF]'
Mon Jul 18 01:48:06 2011 us=151000   local_port = 0
Mon Jul 18 01:48:06 2011 us=151000   remote = '*DNSname*.nsys.cz'
Mon Jul 18 01:48:06 2011 us=151000   remote_port = 1194
Mon Jul 18 01:48:06 2011 us=151000   remote_float = DISABLED
Mon Jul 18 01:48:06 2011 us=151000   bind_defined = DISABLED
Mon Jul 18 01:48:06 2011 us=151000   bind_local = DISABLED
Mon Jul 18 01:48:06 2011 us=151000   connect_retry_seconds = 5
Mon Jul 18 01:48:06 2011 us=151000   connect_timeout = 10
Mon Jul 18 01:48:06 2011 us=151000 NOTE: --mute triggered...
Mon Jul 18 01:48:06 2011 us=151000 202 variation(s) on previous 20 message(s) suppressed by --mute
Mon Jul 18 01:48:06 2011 us=151000 OpenVPN 2.2.1 Win32-MSVC++ [SSL] [LZO2] built on Jul  1 2011
Mon Jul 18 01:48:06 2011 us=151000 NOTE: OpenVPN 2.1 requires '--script-security 2' or higher to call user-defined scripts or executables
Mon Jul 18 01:48:06 2011 us=432000 LZO compression initialized
Mon Jul 18 01:48:06 2011 us=432000 Control Channel MTU parms [ L:1542 D:138 EF:38 EB:0 ET:0 EL:0 ]
Mon Jul 18 01:48:06 2011 us=432000 Socket Buffers: R=[8192->8192] S=[8192->8192]
Mon Jul 18 01:48:06 2011 us=432000 Data Channel MTU parms [ L:1542 D:1450 EF:42 EB:135 ET:0 EL:0 AF:3/1 ]
Mon Jul 18 01:48:06 2011 us=432000 Local Options String: 'V4,dev-type tun,link-mtu 1542,tun-mtu 1500,proto UDPv4,comp-lzo,cipher BF-CBC,auth SHA1,keysize 128,key-method 2,tls-client'
Mon Jul 18 01:48:06 2011 us=432000 Expected Remote Options String: 'V4,dev-type tun,link-mtu 1542,tun-mtu 1500,proto UDPv4,comp-lzo,cipher BF-CBC,auth SHA1,keysize 128,key-method 2,tls-server'
Mon Jul 18 01:48:06 2011 us=432000 Local Options hash (VER=V4): '41690919'
Mon Jul 18 01:48:06 2011 us=432000 Expected Remote Options hash (VER=V4): '530fdded'
Mon Jul 18 01:48:06 2011 us=432000 UDPv4 link local: [undef]
Mon Jul 18 01:48:06 2011 us=432000 UDPv4 link remote: 89.190.76.WAN:1194
Mon Jul 18 01:48:06 2011 us=432000 UDPv4 WRITE [14] to 89.190.76.WAN:1194: P_CONTROL_HARD_RESET_CLIENT_V2 kid=0 [ ] pid=0 DATA len=0
Mon Jul 18 01:48:06 2011 us=432000 UDPv4 READ [0] from [undef]: DATA UNDEF len=-1
Mon Jul 18 01:48:08 2011 us=835000 UDPv4 WRITE [14] to 89.190.76.WAN:1194: P_CONTROL_HARD_RESET_CLIENT_V2 kid=0 [ ] pid=0 DATA len=0
Mon Jul 18 01:48:12 2011 us=438000 UDPv4 WRITE [14] to 89.190.76.WAN:1194: P_CONTROL_HARD_RESET_CLIENT_V2 kid=0 [ ] pid=0 DATA len=0
Mon Jul 18 01:48:20 2011 us=207000 UDPv4 WRITE [14] to 89.190.76.WAN:1194: P_CONTROL_HARD_RESET_CLIENT_V2 kid=0 [ ] pid=0 DATA len=0
Mon Jul 18 01:48:36 2011 us=634000 UDPv4 WRITE [14] to 89.190.76.WAN:1194: P_CONTROL_HARD_RESET_CLIENT_V2 kid=0 [ ] pid=0 DATA len=0
Mon Jul 18 01:48:36 2011 us=650000 UDPv4 READ [26] from 89.190.76.WAN:1194: P_CONTROL_HARD_RESET_SERVER_V2 kid=0 [ 0 ] pid=0 DATA len=0
Mon Jul 18 01:48:36 2011 us=650000 TLS: Initial packet from 89.190.76.WAN:1194, sid=7b2553d6 6d0c9292
Mon Jul 18 01:48:36 2011 us=650000 UDPv4 WRITE [22] to 89.190.76.WAN:1194: P_ACK_V1 kid=0 [ 0 ]
Mon Jul 18 01:48:36 2011 us=650000 UDPv4 WRITE [114] to 89.190.76.WAN:1194: P_CONTROL_V1 kid=0 [ ] pid=1 DATA len=100
Mon Jul 18 01:48:36 2011 us=650000 UDPv4 WRITE [114] to 89.190.76.WAN:1194: P_CONTROL_V1 kid=0 [ ] pid=2 DATA len=100
Mon Jul 18 01:48:36 2011 us=650000 UDPv4 WRITE [24] to 89.190.76.WAN:1194: P_CONTROL_V1 kid=0 [ ] pid=3 DATA len=10
Mon Jul 18 01:48:36 2011 us=665000 UDPv4 READ [22] from 89.190.76.WAN:1194: P_ACK_V1 kid=0 [ 1 ]
Mon Jul 18 01:48:36 2011 us=681000 UDPv4 READ [22] from 89.190.76.WAN:1194: P_ACK_V1 kid=0 [ 2 ]
Mon Jul 18 01:48:36 2011 us=681000 UDPv4 READ [126] from 89.190.76.WAN:1194: P_CONTROL_V1 kid=0 [ 3 ] pid=1 DATA len=100
Mon Jul 18 01:48:36 2011 us=681000 UDPv4 WRITE [22] to 89.190.76.WAN:1194: P_ACK_V1 kid=0 [ 1 ]
Mon Jul 18 01:48:36 2011 us=681000 UDPv4 READ [114] from 89.190.76.WAN:1194: P_CONTROL_V1 kid=0 [ ] pid=2 DATA len=100
Mon Jul 18 01:48:36 2011 us=681000 UDPv4 WRITE [22] to 89.190.76.WAN:1194: P_ACK_V1 kid=0 [ 2 ]
Mon Jul 18 01:48:36 2011 us=681000 UDPv4 READ [114] from 89.190.76.WAN:1194: P_CONTROL_V1 kid=0 [ ] pid=3 DATA len=100
Mon Jul 18 01:48:36 2011 us=681000 UDPv4 WRITE [22] to 89.190.76.WAN:1194: P_ACK_V1 kid=0 [ 3 ]
Mon Jul 18 01:48:36 2011 us=681000 UDPv4 READ [114] from 89.190.76.WAN:1194: P_CONTROL_V1 kid=0 [ ] pid=4 DATA len=100
Mon Jul 18 01:48:36 2011 us=681000 UDPv4 WRITE [22] to 89.190.76.WAN:1194: P_ACK_V1 kid=0 [ 4 ]
Mon Jul 18 01:48:36 2011 us=696000 UDPv4 READ [114] from 89.190.76.WAN:1194: P_CONTROL_V1 kid=0 [ ] pid=5 DATA len=100
Mon Jul 18 01:48:36 2011 us=696000 UDPv4 WRITE [22] to 89.190.76.WAN:1194: P_ACK_V1 kid=0 [ 5 ]
Mon Jul 18 01:48:36 2011 us=696000 UDPv4 READ [114] from 89.190.76.WAN:1194: P_CONTROL_V1 kid=0 [ ] pid=6 DATA len=100
Mon Jul 18 01:48:36 2011 us=696000 UDPv4 WRITE [22] to 89.190.76.WAN:1194: P_ACK_V1 kid=0 [ 6 ]
Mon Jul 18 01:48:36 2011 us=712000 UDPv4 READ [114] from 89.190.76.WAN:1194: P_CONTROL_V1 kid=0 [ ] pid=7 DATA len=100
Mon Jul 18 01:48:36 2011 us=712000 UDPv4 WRITE [22] to 89.190.76.WAN:1194: P_ACK_V1 kid=0 [ 7 ]
Mon Jul 18 01:48:36 2011 us=712000 NOTE: --mute triggered...
Mon Jul 18 01:48:36 2011 us=774000 29 variation(s) on previous 20 message(s) suppressed by --mute
Mon Jul 18 01:48:36 2011 us=774000 VERIFY OK: depth=1, *Cert info*
Mon Jul 18 01:48:36 2011 us=774000 VERIFY OK: nsCertType=SERVER
Mon Jul 18 01:48:36 2011 us=774000 VERIFY OK: depth=0, *Cert info*
Mon Jul 18 01:48:36 2011 us=774000 UDPv4 WRITE [22] to 89.190.76.WAN:1194: P_ACK_V1 kid=0 [ 22 ]
Mon Jul 18 01:48:36 2011 us=790000 UDPv4 READ [114] from 89.190.76.WAN:1194: P_CONTROL_V1 kid=0 [ ] pid=23 DATA len=100
Mon Jul 18 01:48:36 2011 us=790000 UDPv4 WRITE [22] to 89.190.76.WAN:1194: P_ACK_V1 kid=0 [ 23 ]
Mon Jul 18 01:48:36 2011 us=790000 UDPv4 READ [114] from 89.190.76.WAN:1194: P_CONTROL_V1 kid=0 [ ] pid=24 DATA len=100
Mon Jul 18 01:48:36 2011 us=790000 UDPv4 WRITE [22] to 89.190.76.WAN:1194: P_ACK_V1 kid=0 [ 24 ]
Mon Jul 18 01:48:36 2011 us=806000 UDPv4 READ [114] from 89.190.76.WAN:1194: P_CONTROL_V1 kid=0 [ ] pid=25 DATA len=100
Mon Jul 18 01:48:36 2011 us=806000 UDPv4 WRITE [22] to 89.190.76.WAN:1194: P_ACK_V1 kid=0 [ 25 ]
Mon Jul 18 01:48:36 2011 us=806000 UDPv4 READ [114] from 89.190.76.WAN:1194: P_CONTROL_V1 kid=0 [ ] pid=26 DATA len=100
Mon Jul 18 01:48:36 2011 us=806000 UDPv4 WRITE [22] to 89.190.76.WAN:1194: P_ACK_V1 kid=0 [ 26 ]
Mon Jul 18 01:48:36 2011 us=821000 UDPv4 READ [114] from 89.190.76.WAN:1194: P_CONTROL_V1 kid=0 [ ] pid=27 DATA len=100
Mon Jul 18 01:48:36 2011 us=821000 UDPv4 WRITE [22] to 89.190.76.WAN:1194: P_ACK_V1 kid=0 [ 27 ]
Mon Jul 18 01:48:36 2011 us=821000 UDPv4 READ [99] from 89.190.76.WAN:1194: P_CONTROL_V1 kid=0 [ ] pid=28 DATA len=85
Mon Jul 18 01:48:36 2011 us=837000 UDPv4 WRITE [126] to 89.190.76.WAN:1194: P_CONTROL_V1 kid=0 [ 28 ] pid=4 DATA len=100
Mon Jul 18 01:48:36 2011 us=837000 UDPv4 WRITE [114] to 89.190.76.WAN:1194: P_CONTROL_V1 kid=0 [ ] pid=5 DATA len=100
Mon Jul 18 01:48:36 2011 us=837000 UDPv4 WRITE [114] to 89.190.76.WAN:1194: P_CONTROL_V1 kid=0 [ ] pid=6 DATA len=100
Mon Jul 18 01:48:36 2011 us=837000 UDPv4 WRITE [114] to 89.190.76.WAN:1194: P_CONTROL_V1 kid=0 [ ] pid=7 DATA len=100
Mon Jul 18 01:48:36 2011 us=852000 UDPv4 READ [22] from 89.190.76.WAN:1194: P_ACK_V1 kid=0 [ 4 ]
Mon Jul 18 01:48:36 2011 us=852000 UDPv4 WRITE [114] to 89.190.76.WAN:1194: P_CONTROL_V1 kid=0 [ ] pid=8 DATA len=100
Mon Jul 18 01:48:36 2011 us=852000 UDPv4 READ [22] from 89.190.76.WAN:1194: P_ACK_V1 kid=0 [ 5 ]
Mon Jul 18 01:48:36 2011 us=852000 UDPv4 WRITE [114] to 89.190.76.WAN:1194: P_CONTROL_V1 kid=0 [ ] pid=9 DATA len=100
Mon Jul 18 01:48:36 2011 us=868000 NOTE: --mute triggered...
Mon Jul 18 01:48:37 2011 us=86000 80 variation(s) on previous 20 message(s) suppressed by --mute
Mon Jul 18 01:48:37 2011 us=86000 Data Channel Encrypt: Cipher 'BF-CBC' initialized with 128 bit key
Mon Jul 18 01:48:37 2011 us=86000 Data Channel Encrypt: Using 160 bit message hash 'SHA1' for HMAC authentication
Mon Jul 18 01:48:37 2011 us=86000 Data Channel Decrypt: Cipher 'BF-CBC' initialized with 128 bit key
Mon Jul 18 01:48:37 2011 us=86000 Data Channel Decrypt: Using 160 bit message hash 'SHA1' for HMAC authentication
Mon Jul 18 01:48:37 2011 us=86000 UDPv4 WRITE [22] to 89.190.76.WAN:1194: P_ACK_V1 kid=0 [ 45 ]
Mon Jul 18 01:48:37 2011 us=86000 Control Channel: TLSv1, cipher TLSv1/SSLv3 DHE-RSA-AES256-SHA, 1024 bit RSA
Mon Jul 18 01:48:37 2011 us=86000 [server] Peer Connection Initiated with 89.190.76.WAN:1194
Mon Jul 18 01:48:39 2011 us=270000 SENT CONTROL [server]: 'PUSH_REQUEST' (status=1)
Mon Jul 18 01:48:39 2011 us=270000 UDPv4 WRITE [104] to 89.190.76.WAN:1194: P_CONTROL_V1 kid=0 [ ] pid=33 DATA len=90
Mon Jul 18 01:48:39 2011 us=302000 UDPv4 READ [22] from 89.190.76.WAN:1194: P_ACK_V1 kid=0 [ 33 ]
Mon Jul 18 01:48:39 2011 us=302000 UDPv4 READ [114] from 89.190.76.WAN:1194: P_CONTROL_V1 kid=0 [ ] pid=46 DATA len=100
Mon Jul 18 01:48:39 2011 us=302000 UDPv4 WRITE [22] to 89.190.76.WAN:1194: P_ACK_V1 kid=0 [ 46 ]
Mon Jul 18 01:48:39 2011 us=302000 UDPv4 READ [114] from 89.190.76.WAN:1194: P_CONTROL_V1 kid=0 [ ] pid=47 DATA len=100
Mon Jul 18 01:48:39 2011 us=302000 UDPv4 WRITE [22] to 89.190.76.WAN:1194: P_ACK_V1 kid=0 [ 47 ]
Mon Jul 18 01:48:39 2011 us=302000 UDPv4 READ [64] from 89.190.76.WAN:1194: P_CONTROL_V1 kid=0 [ ] pid=48 DATA len=50
Mon Jul 18 01:48:39 2011 us=302000 PUSH: Received control message: 'PUSH_REPLY,route 192.168.1.0 255.255.255.0,dhcp-option DNS 192.168.1.2,dhcp-option WINS 192.168.1.2,route 10.8.0.1,topology net30,ping 10,ping-restart 120,ifconfig 10.8.0.10 10.8.0.9'
Mon Jul 18 01:48:39 2011 us=302000 OPTIONS IMPORT: timers and/or timeouts modified
Mon Jul 18 01:48:39 2011 us=302000 OPTIONS IMPORT: --ifconfig/up options modified
Mon Jul 18 01:48:39 2011 us=302000 OPTIONS IMPORT: route options modified
Mon Jul 18 01:48:39 2011 us=302000 OPTIONS IMPORT: --ip-win32 and/or --dhcp-option options modified
Mon Jul 18 01:48:39 2011 us=302000 ROUTE default_gateway=192.168.1.1
Mon Jul 18 01:48:39 2011 us=317000 TAP-WIN32 device [OpenVPN] opened: \\.\Global\{8056DF53-9521-4C96-BB8A-77DB47B506A3}.tap
Mon Jul 18 01:48:39 2011 us=317000 TAP-Win32 Driver Version 9.8 
Mon Jul 18 01:48:39 2011 us=317000 TAP-Win32 MTU=1500
Mon Jul 18 01:48:39 2011 us=317000 Notified TAP-Win32 driver to set a DHCP IP/netmask of 10.8.0.10/255.255.255.252 on interface {8056DF53-9521-4C96-BB8A-77DB47B506A3} [DHCP-serv: 10.8.0.9, lease-time: 31536000]
Mon Jul 18 01:48:39 2011 us=317000 DHCP option string: 0604c0a8 10022c04 c0a81002
Mon Jul 18 01:48:39 2011 us=317000 Successful ARP Flush on interface [37] {8056DF53-9521-4C96-BB8A-77DB47B506A3}
Mon Jul 18 01:48:39 2011 us=348000 UDPv4 WRITE [22] to 89.190.76.WAN:1194: P_ACK_V1 kid=0 [ 48 ]
Mon Jul 18 01:48:41 2011 us=532000 TEST ROUTES: 2/2 succeeded len=2 ret=1 a=0 u/d=up
Mon Jul 18 01:48:41 2011 us=532000 C:\WINDOWS\system32\route.exe ADD 192.168.1.0 MASK 255.255.255.0 10.8.0.9
 OK!
Mon Jul 18 01:48:41 2011 us=595000 C:\WINDOWS\system32\route.exe ADD 10.8.0.1 MASK 255.255.255.255 10.8.0.9
 OK!
Mon Jul 18 01:48:41 2011 us=626000 Initialization Sequence Completed
Mon Jul 18 01:48:49 2011 us=223000 UDPv4 READ [53] from 89.190.76.WAN:1194: P_DATA_V1 kid=0 DATA len=52
Mon Jul 18 01:48:49 2011 us=223000 UDPv4 WRITE [53] to 89.190.76.WAN:1194: P_DATA_V1 kid=0 DATA len=52
Mon Jul 18 01:48:59 2011 us=535000 UDPv4 READ [53] from 89.190.76.WAN:1194: P_DATA_V1 kid=0 DATA len=52
Mon Jul 18 01:48:59 2011 us=535000 UDPv4 WRITE [53] to 89.190.76.WAN:1194: P_DATA_V1 kid=0 DATA len=52
Mon Jul 18 01:49:09 2011 us=722000 UDPv4 WRITE [53] to 89.190.76.WAN:1194: P_DATA_V1 kid=0 DATA len=52
Mon Jul 18 01:49:09 2011 us=737000 UDPv4 READ [53] from 89.190.76.WAN:1194: P_DATA_V1 kid=0 DATA len=52
Mon Jul 18 01:49:19 2011 us=269000 UDPv4 WRITE [53] to 89.190.76.WAN:1194: P_DATA_V1 kid=0 DATA len=52
Mon Jul 18 01:49:20 2011 us=408000 UDPv4 READ [53] from 89.190.76.WAN:1194: P_DATA_V1 kid=0 DATA len=52
Mon Jul 18 01:49:29 2011 us=518000 UDPv4 READ [53] from 89.190.76.WAN:1194: P_DATA_V1 kid=0 DATA len=52
Mon Jul 18 01:49:29 2011 us=518000 UDPv4 WRITE [53] to 89.190.76.WAN:1194: P_DATA_V1 kid=0 DATA len=52
Mon Jul 18 01:49:39 2011 us=222000 UDPv4 WRITE [53] to 89.190.76.WAN:1194: P_DATA_V1 kid=0 DATA len=52
Mon Jul 18 01:49:40 2011 us=438000 UDPv4 READ [53] from 89.190.76.WAN:1194: P_DATA_V1 kid=0 DATA len=52
OpenVPN server/client network adapters not sending/recieve any packets.

Do you have anyone have any idea how to solve this problem?

Thanks, Cevacevikus

Re: Ping does not work through a tunnel ( Server: Win 2003 S

Posted: Sun Jul 17, 2011 11:20 am
by maikcat
please post the output of netstat -nr of your win2003 sbs server..

also post server logs as well


Michael.

Re: Ping does not work through a tunnel ( Server: Win 2003 S

Posted: Mon Jul 18, 2011 12:23 am
by cevacevikus
I edited my first post...

I see that there is a problem in routing, but even if I delete and then add the route manually, even though the connection does not work...

Re: Ping does not work through a tunnel ( Server: Win 2003 S

Posted: Mon Jul 18, 2011 12:55 pm
by maikcat
hi there

the missing route is this

10.8.0.0 255.255.255.0 10.8.0.2 10.8.0.1

so type in cmd *after* you start the service..

route add 10.8.0.0 mask 255.255.255.0 10.8.0.2

it also happened to me on 2003 sbs server ,the only workaround
i had is to use up script to bring the missing route...

btw,is the above the route you added?

Michael.


also remove this from server.conf

>push "route 10.8.0.0 255.255.255.0"

Re: Ping does not work through a tunnel ( Server: Win 2003 S

Posted: Mon Jul 18, 2011 1:20 pm
by cevacevikus
Thanks a lot! Ping from the server is now working but ping from the client to server still does not work...

I thought that the gate other than the address of network adapter is an error so I added the route with another gateway...

Now I would like to ask how to do functional client ping the server?

Netstat - nr on client does not show "Connected" on the lines with OpenVPN routes.

Is this normal or is something else needed to set up Win 7 x64PRO?
(UAC off, OpenVPN GUI is launched as admin)

Re: Ping does not work through a tunnel ( Server: Win 2003 S

Posted: Mon Jul 18, 2011 3:13 pm
by maikcat
can you please post the output of ipconfig & netstat -nr on client?

if you can ping the client from the server then you have connectivity..

does your server has firewall enabled?
or RAS?

Michael.

Re: Ping does not work through a tunnel ( Server: Win 2003 S

Posted: Mon Jul 18, 2011 5:01 pm
by cevacevikus
I have firewall enabled only on the WAN interface, on the others is disabled.

RAS is enabled to access the server. I don't have a public IP address so I can not connect but my boss needs to use RAS...

Now I tried to temporarily disable the RAS, but it did not help...

Edit:
ipconfig

Code: Select all

   DNS Suffix . . . : 
   Description . . . . . . . . . . . . . . : TAP-Win32 Adapter V9
   Physical Address. . . . . . . . . . : 00-FF-80-56-DF-53
   DHCP Enabled . . . . . . : Yes
   Autoconfiguration Enabled  : Yes
   IPv4 address . . . . . . . . . . . : 10.8.0.10(Preferred) 
   Subnet Mask . . . . . . . . . . : 255.255.255.252
   Borrowed . . . . . . . . . . . . : 18. July 2011 18:58:23
   Borrow expires . . . . . . . . . : 17. July 2012 18:58:22
   Default Gateway . . . . . . . . . . : 
   DHCP Server. . . . . . . . . . . : 10.8.0.9
   DNS Server . . . . . . . . . . . : 192.168.16.2
   Primary WINS server. . . . . . . : 192.168.16.2
   NetBIOS over TCP / IP. . . . . . . . : Povoleno
netstat -nr

Code: Select all

===========================================================================
Seznam rozhraní
 37...00 ff 80 56 df 53 ......TAP-Win32 Adapter V9
 10...00 1f d0 97 bf 0b ......Realtek PCIe GBE Family Controller
  1...........................Software Loopback Interface 1
 21...00 00 00 00 00 00 00 e0 Microsoft ISATAP Adapter
 20...00 00 00 00 00 00 00 e0 Teredo Tunneling Pseudo-Interface
 26...00 00 00 00 00 00 00 e0 Microsoft 6to4 Adapter #6
 29...00 00 00 00 00 00 00 e0 Microsoft ISATAP Adapter #2
===========================================================================

IPv4 Směrovací tabulka
===========================================================================
Aktivní směrování:
         Cíl v síti   Síťová maska            Brána        Rozhraní Metrika
          0.0.0.0          0.0.0.0      192.168.1.1     192.168.1.30     20
         10.8.0.0    255.255.255.0         10.8.0.9        10.8.0.10     31
         10.8.0.8  255.255.255.252       Propojené         10.8.0.10    286
        10.8.0.10  255.255.255.255       Propojené         10.8.0.10    286
        10.8.0.11  255.255.255.255       Propojené         10.8.0.10    286
        127.0.0.0        255.0.0.0       Propojené         127.0.0.1    306
        127.0.0.1  255.255.255.255       Propojené         127.0.0.1    306
  127.255.255.255  255.255.255.255       Propojené         127.0.0.1    306
      192.168.1.0    255.255.255.0       Propojené      192.168.1.30    276
     192.168.1.30  255.255.255.255       Propojené      192.168.1.30    276
    192.168.1.255  255.255.255.255       Propojené      192.168.1.30    276
     192.168.16.0    255.255.255.0         10.8.0.9        10.8.0.10     31
        224.0.0.0        240.0.0.0       Propojené         127.0.0.1    306
        224.0.0.0        240.0.0.0       Propojené         10.8.0.10    286
        224.0.0.0        240.0.0.0       Propojené      192.168.1.30    276
  255.255.255.255  255.255.255.255       Propojené         127.0.0.1    306
  255.255.255.255  255.255.255.255       Propojené         10.8.0.10    286
  255.255.255.255  255.255.255.255       Propojené      192.168.1.30    276
===========================================================================
Trvalé trasy:
  Žádné

Re: Ping does not work through a tunnel ( Server: Win 2003 S

Posted: Tue Jul 19, 2011 12:05 pm
by Mimiko
Some time to correctly add routes on server you must add following to the config file of OpenVPN server:

Code: Select all

route-delay 60 60
ip-win32 ipapi
Because, of this:

Code: Select all

Mon Jul 18 01:45:51 2011 us=312000 Warning: route gateway is not reachable on any active network adapters: 10.8.0.2
it seems that OpenVPN service tries to add the routes before Windows brings up the VPN adapter. So we have to delay route addishion till VPN adapter is connected.

The same I reccomend on client config file.

Re: Ping does not work through a tunnel ( Server: Win 2003 S

Posted: Tue Jul 19, 2011 12:40 pm
by cevacevikus
Unfortunately it did not help.

Ipconfig server:

Code: Select all

Adaptér sítě Ethernet OpenVPN:

   Přípona DNS podle připojení . . . :
   Popis . . . . . . . . . . . . . . : TAP-Win32 Adapter V9
   Fyzická Adresa. . . . . . . . . . : 00-FF-CB-BA-BF-67
   Protokol DHCP povolen . . . . . . : Ano
   Automatická konfigurace povolena  : Ano
   Adresa IP . . . . . . . . . . . . : 10.8.0.1
   Maska podsítě . . . . . . . . . . : 255.255.255.252
   IP Adresa automatické konfigurace : 169.254.2.205
   Maska podsítě . . . . . . . . . . : 255.255.0.0
   Výchozí brána . . . . . . . . . . :
nestat -nr server:

Code: Select all

IPv4 Směrovací tabulka
===========================================================================
Seznam rozhraní
0x1 ........................... MS TCP Loopback interface
0x2 ...00 ff cb ba bf 67 ...... TAP-Win32 Adapter V9
0x10003 ...00 53 45 00 00 00 ...... WAN (PPP/SLIP) Interface
0x10004 ...00 00 5a 75 59 e0 ...... SysKonnect SK-9521 V2.0 10/100/1000Base-T Ad
apter, PCI, Copper RJ-45
0x10005 ...00 19 99 33 1e a3 ...... Intel(R) 82566DM-2 Gigabit Network Connectio
n
===========================================================================
===========================================================================
Aktivní směrování:
         Cíl v síti   Síťová maska            Brána        Rozhraní Metrika
          0.0.0.0          0.0.0.0    89.190.76.129    89.190.76.164      1
         10.8.0.0  255.255.255.252         10.8.0.1    169.254.2.205     30
         10.8.0.0    255.255.255.0         10.8.0.2    169.254.2.205      1
         10.8.0.1  255.255.255.255        127.0.0.1        127.0.0.1     30
   10.255.255.255  255.255.255.255    169.254.2.205    169.254.2.205     30
    89.190.76.128  255.255.255.192    89.190.76.164    89.190.76.164     10
    89.190.76.164  255.255.255.255        127.0.0.1        127.0.0.1     10
   89.255.255.255  255.255.255.255    89.190.76.164    89.190.76.164     10
        127.0.0.0        255.0.0.0        127.0.0.1        127.0.0.1      1
      169.254.0.0      255.255.0.0    169.254.2.205    169.254.2.205     30
    169.254.2.205  255.255.255.255        127.0.0.1        127.0.0.1     30
  169.254.255.255  255.255.255.255    169.254.2.205    169.254.2.205     30
     192.168.16.0    255.255.255.0     192.168.16.2     192.168.16.2     20
     192.168.16.2  255.255.255.255        127.0.0.1        127.0.0.1     20
    192.168.16.16  255.255.255.255        127.0.0.1        127.0.0.1     50
   192.168.16.255  255.255.255.255     192.168.16.2     192.168.16.2     20
        224.0.0.0        240.0.0.0    89.190.76.164    89.190.76.164     10
        224.0.0.0        240.0.0.0    169.254.2.205    169.254.2.205     30
        224.0.0.0        240.0.0.0     192.168.16.2     192.168.16.2     20
  255.255.255.255  255.255.255.255    89.190.76.164    89.190.76.164      1
  255.255.255.255  255.255.255.255    169.254.2.205    169.254.2.205      1
  255.255.255.255  255.255.255.255     192.168.16.2     192.168.16.2      1
Výchozí brána:     89.190.76.129
===========================================================================
Trvalé trasy:
  Žádné
Ipconfig client:

Code: Select all

Adaptér sítě Ethernet OpenVPN:

   Přípona DNS podle připojení . . . : 
   Popis . . . . . . . . . . . . . . : TAP-Win32 Adapter V9
   Fyzická Adresa. . . . . . . . . . : 00-FF-80-56-DF-53
   Protokol DHCP povolen . . . . . . : Ano
   Automatická konfigurace povolena  : Ano
   Adresa IP automatické konfigurace : 169.254.138.84(Preferované) 
   Maska podsítě . . . . . . . . . . : 255.255.0.0
   Výchozí brána . . . . . . . . . . : 
   Rozhraní NetBios nad protokolem TCP/IP. . . . . . . . : Povoleno
nestat -nr client:

Code: Select all

===========================================================================
Seznam rozhraní
 37...00 ff 80 56 df 53 ......TAP-Win32 Adapter V9
 10...00 1f d0 97 bf 0b ......Realtek PCIe GBE Family Controller
  1...........................Software Loopback Interface 1
 21...00 00 00 00 00 00 00 e0 Microsoft ISATAP Adapter
 20...00 00 00 00 00 00 00 e0 Teredo Tunneling Pseudo-Interface
 26...00 00 00 00 00 00 00 e0 Microsoft 6to4 Adapter #6
 29...00 00 00 00 00 00 00 e0 Microsoft ISATAP Adapter #2
===========================================================================

IPv4 Směrovací tabulka
===========================================================================
Aktivní směrování:
         Cíl v síti   Síťová maska            Brána        Rozhraní Metrika
          0.0.0.0          0.0.0.0      192.168.1.1     192.168.1.30     20
         10.8.0.0    255.255.255.0         10.8.0.9     192.168.1.30     21
        127.0.0.0        255.0.0.0       Propojené         127.0.0.1    306
        127.0.0.1  255.255.255.255       Propojené         127.0.0.1    306
  127.255.255.255  255.255.255.255       Propojené         127.0.0.1    306
      169.254.0.0      255.255.0.0       Propojené    169.254.138.84    286
   169.254.138.84  255.255.255.255       Propojené    169.254.138.84    286
  169.254.255.255  255.255.255.255       Propojené    169.254.138.84    286
      192.168.1.0    255.255.255.0       Propojené      192.168.1.30    276
     192.168.1.30  255.255.255.255       Propojené      192.168.1.30    276
    192.168.1.255  255.255.255.255       Propojené      192.168.1.30    276
     192.168.16.0    255.255.255.0         10.8.0.9     192.168.1.30     21
        224.0.0.0        240.0.0.0       Propojené         127.0.0.1    306
        224.0.0.0        240.0.0.0       Propojené    169.254.138.84    286
        224.0.0.0        240.0.0.0       Propojené      192.168.1.30    276
  255.255.255.255  255.255.255.255       Propojené         127.0.0.1    306
  255.255.255.255  255.255.255.255       Propojené    169.254.138.84    286
  255.255.255.255  255.255.255.255       Propojené      192.168.1.30    276
===========================================================================
Trvalé trasy:
  Žádné

Re: Ping does not work through a tunnel ( Server: Win 2003 S

Posted: Tue Jul 19, 2011 4:18 pm
by Mimiko
Did you made correction to client's config file too?

If does not help, uninstall OpenVPN and isntall it again. I recommend using a portable version of OpenVPN when there are installed only virtual ethernet adapter.

I had same problem in the morning. The only thing that helped me is uninstalling and a fresh installing TAP-driver.

Re: Ping does not work through a tunnel ( Server: Win 2003 S

Posted: Thu Jul 21, 2011 12:32 pm
by cevacevikus
Yes, I made a change in both configuration files.

Meanwhile thank you very much for your help, I 'll try a clean install when I get back from vacation.

Re: Ping does not work through a tunnel ( Server: Win 2003 S

Posted: Sun Nov 13, 2011 10:49 pm
by cevacevikus
Finally, we solved all problems by purchasing Mikrotik RouterBOARD and forwarding one port on the OpenVPN on SBS.

According to all was previously the biggest problem activated RAS service. After switching off the RAS service works OpenVPN on SBS great.

Now working tunnel to Mikrotik and the tunnel to SBS.

The only problem is the low speed SAMBA share, but now it is not so much bad as it was...

Thank you all...