[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: OpenVPN.



Talvez utilizando uma interface tap ao inves de tun?

Att,

Tobias
http://gnu.eti.br

-----BEGIN GEEK CODE BLOCK-----
Version: 3.12
GCS/CM/G/H/IT/L/SS d?(--) s++:+ a-- C+++>++++ UL++>++++ P+ L+++>+++++ !E@ W+++
!N o? K- w !O !M@ !V@ PS PE-- !Y@ PGP t+ 5? X? R+ !tv b+ DI>+ !D@ G e- h+ r-- y?
------END GEEK CODE BLOCK------



Em 4 de junho de 2013 16:11, Adiel de Lima Ribeiro <adiel.netadmin@gmail.com> escreveu:
Pessoal, boa tarde.
Instalei e configurei o OpenVPN, com a seguinte configuração:
################################################
local 192.168.254.122
port 1194
proto udp
dev tun
ca /usr/local/etc/openvpn/easy-rsa/keys/ca.crt
cert /usr/local/etc/openvpn/easy-rsa/keys/openvpn.crt
key /usr/local/etc/openvpn/easy-rsa/keys/openvpn.key
dh /usr/local/etc/openvpn/easy-rsa/keys/dh384.pem
server 172.20.0.0 255.255.255.240
push "route 192.168.254.0 255.255.255.0"
push "dhcp-options DNS 192.168.254.100"
keepalive 10 120
comp-lzo
max-clients 10
user nobody
group nobody
persist-key
persist-tun
status /var/log/openvpn.log
log /var/log/openvpn.log
log-append /var/log/openvpn.log
verb 3
mute 20
######################################################################
Estou utilizando um cliente Windows XP para me conectar, com a seguinte
configuração:
##################################################################
client
dev tun
proto udp
remote 10.0.0.4 1194
persist-key
persist-tun
comp-lzo
ca ca.crt
cert client1.crt
key client1.key
verb 3
mute-replay-warnings
mute 20
#######################################################################
O Iptables está fazendo o redirecionamento necessário.
Os clientes devem receber ips no range 172.20.0.0/28 e devem poder
acessar a nossa rede interna 192.168.254.0/24.
Tudo que chega em 10.0.0.4 é encaminhado ao ip 192.168.254.122 do
OpenVPN.
A VPN fecha corretamente e consigo enviar pings da máquina remota
cliente para a rede interna, mas fica intermitente.
Acessos como RDP e CIFS não funcionam, os logs não retornam nenhuma
anomalia.
Tcpdump também não retorna nada de errado.
Alguém tem alguma dica do que estou deixando passar?
Obrigado.
--
att,
Adiel de Lima Ribeiro
facebook.com/sembr.dyndns.info





--
To UNSUBSCRIBE, email to debian-user-portuguese-REQUEST@lists.debian.org
with a subject of "unsubscribe". Trouble? Contact listmaster@lists.debian.org
Archive: [🔎] 1370373111.21788.1.camel@Windows-NT4.0" target="_blank">http://lists.debian.org/[🔎] 1370373111.21788.1.camel@Windows-NT4.0



Reply to: