請教,OpenVPN Config Problem, 同一config, 以前得, 現在唔得

TP-link 1043ND, Flash左去DD-wrt, 以前是version 2.4 SP2,好似甘上下, set左config都無問題, 雖然用PPTP多,不過用OpenVPN都無問題的, 半年前upgrade去V3.0,一直以前都是用PPTP多, 但昨日試返用OpenVPN, 但是顯示成功connected, 拿到ip是192.168.2.6, 但是完全上唔到網, 完成無頭緒,唔知咩問題, 想請教下各師兄,問題出現在哪裡了,關唔關version 3.0的事?

server:
push "route 192.168.1.0 255.255.255.0"
server 192.168.2.0 255.255.255.0
mode server
verb 5
dev tun0
proto udp
port 443
keepalive 10 120
client-to-client
duplicate-cn
cipher AES-128-CBC
tls-server
comp-lzo
daemon
management localhost 5001
dh /tmp/openvpn/dh.pem
ca /tmp/openvpn/ca.crt
cert /tmp/openvpn/cert.pem
key /tmp/openvpn/key.pem
push "dhcp-option DNS 8.8.8.8"   
push "dhcp-option DNS 8.8.4.4"
push "redirect-gateway def1"

Client:
remote xxxx.com 443
client
dev tun0
proto udp
resolv-retry infinite
nobind
persist-key
persist-tun
ca ca.crt
cert client1.crt
key client1.key
ns-cert-type server
cipher AES-128-CBC
comp-lzo
route-method exe
route-delay 2
float

firewall:
iptables -I INPUT -p tcp --dport 443 -j ACCEPT
iptables -I INPUT -p udp --dport 443 -j ACCEPT
iptables -I FORWARD 1 --source 192.168.2.0/24 -j ACCEPT

iptables -I FORWARD -i br0 -o tun0 -j ACCEPT
iptables -I FORWARD -i tun0 -o br0 -j ACCEPT

係咪你DD-WRT 未Set個default gateways?

TOP

係咪你DD-WRT 未Set個default gateways?
cyruschan112 發表於 2016-5-15 20:52


有啊,有set
附件: 您需要登錄才可以下載或查看附件。沒有帳號?註冊

TOP

本帖最後由 solexkey 於 2016-5-15 22:11 編輯

DD-WRT 絕對唔喺越新version越好

唔同version有唔同嘅bug..

如果你一定要用openvpn,都喺用番舊版好D

TOP

DD-WRT 絕對唔喺越新version越好

唔同version有唔同嘅bug..

如果你一定要用openvpn,都喺用番舊版 ...
solexkey 發表於 2016-5-15 22:07


我剛downgrade返去舊的Firmware(Firmware: DD-WRT v24-sp2 (05/27/13) std),試左都是一樣, 甘應該唔關新舊版本事了,但是我個dd-wrt既setting應該無變過的,甘真是唔知咩事咯

TOP

如果係喺大陸翻墙的話就算把啦 ! openvpn 喺大陸一早封死晒
就算set static key 行唔到5分鐘必死 !
依家唯一仲可以用嘅只有 刷 router 做shadowsocks  server ,自己google吓

TOP

本帖最後由 suiyan 於 2016-5-16 23:41 編輯

加入
push "topology subnet"
push "dhcp-option DNS 192.168.1.0"

TOP

回覆 7# suiyan


   師兄是否在server site config 加入? 試過都是唔得

TOP

本帖最後由 blackpig9336 於 2016-5-17 02:09 編輯
回覆  suiyan


   師兄是否在server site config 加入? 試過都是唔得
james21 發表於 2016-5-17 00:47


貼個 log file 上嚟睇吓边度出問題啦

仲有 , 如果你 client 係windows的話 , 應該要行tap而唔係tun喎......不過你又connect到......

試吓client 加 "route-gateway 192.168.1.1" 睇下得晤得 , 有時server未必push到去client度架

TOP

本帖最後由 james21 於 2016-5-17 10:01 編輯

回覆 9# blackpig9336


    加左都是唔得,其實同一個OVPN在windows,iOS試都是同樣連到,不過上唔到網

window log:

Tue May 17 09:35:48 2016 OpenVPN 2.3.11 x86_64-w64-mingw32 [SSL (OpenSSL)] [LZO] [PKCS11] [IPv6] built on May 10 2016
Tue May 17 09:35:48 2016 Windows version 6.2 (Windows 8 or greater) 64bit
Tue May 17 09:35:48 2016 library versions: OpenSSL 1.0.1t  3 May 2016, LZO 2.09
Enter Management Password:
Tue May 17 09:35:48 2016 UDPv4 link local: [undef]
Tue May 17 09:35:48 2016 UDPv4 link remote: [AF_INET]xxx.xxx.xxx.xxx:443
Tue May 17 09:35:49 2016 [Server] Peer Connection Initiated with [AF_INET]xxx.xxx.xxx.xxx:443
Tue May 17 09:35:52 2016 do_ifconfig, tt->ipv6=0, tt->did_ifconfig_ipv6_setup=0
Tue May 17 09:35:52 2016 open_tun, tt->ipv6=0
Tue May 17 09:35:52 2016 TAP-WIN32 device [Ethernet 2] opened: \\.\Global\{ECFA923E-16A7-439F-97EB-C51D0C821852}.tap
Tue May 17 09:35:52 2016 Notified TAP-Windows driver to set a DHCP IP/netmask of 192.168.2.6/255.255.255.252 on interface {ECFA923E-16A7-439F-97EB-C51D0C821852} [DHCP-serv: 192.168.2.5, lease-time: 31536000]
Tue May 17 09:35:52 2016 Successful ARP Flush on interface [14] {ECFA923E-16A7-439F-97EB-C51D0C821852}
Tue May 17 09:35:54 2016 env_block: add PATH=C:\Windows\System32;C:\Windows;C:\Windows\System32\Wbem
Tue May 17 09:35:54 2016 env_block: add PATH=C:\Windows\System32;C:\Windows;C:\Windows\System32\Wbem
Tue May 17 09:35:54 2016 env_block: add PATH=C:\Windows\System32;C:\Windows;C:\Windows\System32\Wbem
Tue May 17 09:35:54 2016 env_block: add PATH=C:\Windows\System32;C:\Windows;C:\Windows\System32\Wbem
Tue May 17 09:35:54 2016 env_block: add PATH=C:\Windows\System32;C:\Windows;C:\Windows\System32\Wbem
Tue May 17 09:35:54 2016 Initialization Sequence Completed

IP Config:
Windows IP Configuration


Ethernet adapter Ethernet:

   Connection-specific DNS Suffix  . : xxxxx.local
   Link-local IPv6 Address . . . . . : fe80::xx:91f2%9
   IPv4 Address. . . . . . . . . . . : 10.105.16.229
   Subnet Mask . . . . . . . . . . . : 255.255.248.0
   Default Gateway . . . . . . . . . : 10.105.16.2


Ethernet adapter Ethernet 2:

   Connection-specific DNS Suffix  . :
   Link-local IPv6 Address . . . . . : fe80::xx:7160%14
   IPv4 Address. . . . . . . . . . . : 192.168.2.6
   Subnet Mask . . . . . . . . . . . : 255.255.255.252
   Default Gateway . . . . . . . . . :


C:\Users\kww>route print
===========================================================================
Interface List
  9...00 01 6c 59 ac 52 ......Marvell Yukon 88E8057 PCI-E Gigabit Ethernet Controller
  6...00 50 56 c0 00 01 ......VMware Virtual Ethernet Adapter for VMnet1
  8...00 50 56 c0 00 08 ......VMware Virtual Ethernet Adapter for VMnet8
14...00 ff ec fa 92 3e ......TAP-Windows Adapter V9
  1...........................Software Loopback Interface 1
  4...00 00 00 00 00 00 00 e0 Microsoft ISATAP Adapter
  7...00 00 00 00 00 00 00 e0 Microsoft ISATAP Adapter #2
13...00 00 00 00 00 00 00 e0 Microsoft ISATAP Adapter #3
  2...00 00 00 00 00 00 00 e0 Microsoft ISATAP Adapter #4
===========================================================================

IPv4 Route Table
===========================================================================
Active Routes:
Network Destination        Netmask          Gateway       Interface  Metric
          0.0.0.0          0.0.0.0      10.105.16.2    10.105.16.229     21
          0.0.0.0        128.0.0.0      192.168.2.5      192.168.2.6     21
      10.105.16.0    255.255.248.0         On-link     10.105.16.229    276
    10.105.16.229  255.255.255.255         On-link     10.105.16.229    276
    10.105.23.255  255.255.255.255         On-link     10.105.16.229    276
        127.0.0.0        255.0.0.0         On-link         127.0.0.1    306
        127.0.0.1  255.255.255.255         On-link         127.0.0.1    306
  127.255.255.255  255.255.255.255         On-link         127.0.0.1    306
        128.0.0.0        128.0.0.0      192.168.2.5      192.168.2.6     21
   183.179.253.72  255.255.255.255      10.105.16.2    10.105.16.229     21
      192.168.1.0    255.255.255.0      192.168.2.5      192.168.2.6     21
      192.168.2.0    255.255.255.0      192.168.2.5      192.168.2.6     21
      192.168.2.4  255.255.255.252         On-link       192.168.2.6    276
      192.168.2.6  255.255.255.255         On-link       192.168.2.6    276
      192.168.2.7  255.255.255.255         On-link       192.168.2.6    276
    192.168.184.0    255.255.255.0         On-link     192.168.184.1    276
    192.168.184.1  255.255.255.255         On-link     192.168.184.1    276
  192.168.184.255  255.255.255.255         On-link     192.168.184.1    276
    192.168.222.0    255.255.255.0         On-link     192.168.222.1    276
    192.168.222.1  255.255.255.255         On-link     192.168.222.1    276
  192.168.222.255  255.255.255.255         On-link     192.168.222.1    276
        224.0.0.0        240.0.0.0         On-link         127.0.0.1    306
        224.0.0.0        240.0.0.0         On-link     192.168.222.1    276
        224.0.0.0        240.0.0.0         On-link     192.168.184.1    276
        224.0.0.0        240.0.0.0         On-link     10.105.16.229    276
        224.0.0.0        240.0.0.0         On-link       192.168.2.6    276
  255.255.255.255  255.255.255.255         On-link         127.0.0.1    306
  255.255.255.255  255.255.255.255         On-link     192.168.222.1    276
  255.255.255.255  255.255.255.255         On-link     192.168.184.1    276
  255.255.255.255  255.255.255.255         On-link     10.105.16.229    276
  255.255.255.255  255.255.255.255         On-link       192.168.2.6    276
===========================================================================
Persistent Routes:
  None




iOS Log:

2016-05-17 09:19:39 ----- OpenVPN Start -----
OpenVPN core 3.0 ios arm64 64-bit
2016-05-17 09:19:39 UNUSED OPTIONS
4 [resolv-retry] [infinite]
5 [nobind]
6 [persist-key]
7 [persist-tun]
11 [route-method] [exe]
12 [route-delay] [2]

2016-05-17 09:19:39 LZO-ASYM init swap=0 asym=0
2016-05-17 09:19:39 EVENT: RESOLVE
2016-05-17 09:19:40 Contacting xxx.xxx.xxx.xxx:443 via UDP
2016-05-17 09:19:40 EVENT: WAIT
2016-05-17 09:19:40 SetTunnelSocket returned 1
2016-05-17 09:19:40 Connecting to ChanTaiMan.xxx.xxx:443 (xxx.xxx.xxx.xxx) via UDPv4
2016-05-17 09:19:40 EVENT: CONNECTING
2016-05-17 09:19:40 Tunnel Options:V4,dev-type tun,link-mtu 1558,tun-mtu 1500,proto UDPv4,comp-lzo,cipher AES-128-CBC,auth SHA1,keysize 128,key-method 2,tls-client
2016-05-17 09:19:40 Peer Info:
IV_GUI_VER=net.openvpn.connect.ios 1.0.5-177
IV_VER=3.0
IV_PLAT=ios
IV_NCP=1
IV_LZO=1

2016-05-17 09:19:41 VERIFY OK: depth=1
cert. version     : 3
serial number     : 91:F7:18:3D:CC:D0:62:8F
issuer name       : C=HK, ST=HK, L=HongKong, O=ChanTaiMan, OU=JK, CN=ChanTaiMan, ??=ChanTaiMan, emailAddress=mail@host.domain
subject name      : C=HK, ST=HK, L=HongKong, O=ChanTaiMan, OU=JK, CN=ChanTaiMan, ??=ChanTaiMan, emailAddress=mail@host.domain
issued  on        : 2013-12-24 13:46:13
expires on        : 2023-12-22 13:46:13
signed using      : RSA with SHA1
RSA key size      : 1024 bits
basic constraints : CA=true

2016-05-17 09:19:41 VERIFY OK: depth=0
cert. version     : 3
serial number     : 01
issuer name       : C=HK, ST=HK, L=HongKong, O=ChanTaiMan, OU=JK, CN=ChanTaiMan, ??=ChanTaiMan, emailAddress=mail@host.domain
subject name      : C=HK, ST=HK, L=HongKong, O=ChanTaiMan, OU=JK, CN=Server, ??=ChanTaiMan, emailAddress=mail@host.domain
issued  on        : 2013-12-24 13:48:23
expires on        : 2023-12-22 13:48:23
signed using      : RSA with MD5
RSA key size      : 1024 bits
basic constraints : CA=false
cert. type        : SSL Server
key usage         : Digital Signature, Key Encipherment
ext key usage     : TLS Web Server Authentication

2016-05-17 09:19:41 SSL Handshake: TLSv1.0/TLS-DHE-RSA-WITH-AES-256-CBC-SHA
2016-05-17 09:19:41 Session is ACTIVE
2016-05-17 09:19:41 EVENT: GET_CONFIG
2016-05-17 09:19:41 Sending PUSH_REQUEST to server...
2016-05-17 09:19:41 OPTIONS:
0 [route] [192.168.1.0] [255.255.255.0]
1 [dhcp-option] [DNS] [8.8.8.8]
2 [dhcp-option] [DNS] [4.4.4.4]
3 [redirect-gateway] [def1]
4 [topology] [subnet]
5 [dhcp-option] [DNS] [192.168.1.0]
6 [route] [192.168.2.0] [255.255.255.0]
7 [topology] [net30]
8 [ping] [10]
9 [ping-restart] [120]
10 [ifconfig] [192.168.2.6] [192.168.2.5]

2016-05-17 09:19:41 LZO-ASYM init swap=0 asym=0
2016-05-17 09:19:41 EVENT: ASSIGN_IP
2016-05-17 09:19:41 Connected via tun
2016-05-17 09:19:41 EVENT: CONNECTED @ChanTaiMan.xxx.xxx:443 (xxx.xxx.xxx.xxx) via /UDPv4 on tun/192.168.2.6/
2016-05-17 09:19:41 SetStatus Connected
2016-05-17 09:20:25 TUN reset routes
2016-05-17 09:20:25 EVENT: DISCONNECTED
2016-05-17 09:20:25 Raw stats on disconnect:
  BYTES_IN : 4116
  BYTES_OUT : 26910
  PACKETS_IN : 41
  PACKETS_OUT : 262
  TUN_BYTES_IN : 12794
  TUN_PACKETS_IN : 223
2016-05-17 09:20:25 Performance stats on disconnect:
  CPU usage (microseconds): 70153
  Tunnel compression ratio (downlink): inf
  Network bytes per CPU second: 442261
  Tunnel bytes per CPU second: 182372
2016-05-17 09:20:25 ----- OpenVPN Stop -----

TOP