
03-02-2008, 12:27
|
|
|
|
חבר מתאריך: 16.04.05
הודעות: 212
|
|
היי שימי,
התכוונתי ל-FW של הלינוקס.
כרגע ביטלתי אותו לגמרי. כשאני מבצע CAT אכן חוזר 1.
TRACE לשרת VPN בכתובת ה - 10.8.0.1 מהמחשב שלי בבית:
קוד:
Tracing route to 10.8.0.1 over a maximum of 30 hops
1 19 ms 18 ms 18 ms 10.8.0.1
Trace complete.
.
:VPN מהמחשב בבית לכתובת הפנימית של שרת ה
קוד:
Tracing route to 10.8.0.1 over a maximum of 30 hops
1 35 ms 67 ms 104 ms 10.8.0.1
Trace complete.
מהשרת במשרד לכתובת ה- 10.8.0.6 של המחשב בבית:
קוד:
traceroute 10.8.0.6
traceroute to 10.8.0.6 (10.8.0.6), 30 hops max, 40 byte packets
1 10.8.0.6 (10.8.0.6) 30.730 ms 26.712 ms 23.933 ms
מהשרת במשרד לכתובת ה-192.168.0.0 של המחשב בבית
קוד:
traceroute 192.168.1.2
traceroute to 192.168.1.2 (192.168.1.2), 30 hops max, 40 byte packets
1 * * *
2 * * *
3 * * *
4 * * *
5 * * *
6 192.168.1.62 (192.168.1.62)(H!) 2875.973 ms (H!) 2871.396 ms (H!) 2868.062 ms
מהשרת במשרד לתחנת עבודה במשרד:
קוד:
traceroute 192.168.100.50
traceroute to 192.168.100.50 (192.168.100.50), 30 hops max, 40 byte packets
1 XXXXXXXXXXX (192.168.100.50) 0.265 ms 0.261 ms 0.266 ms
כשאני מפעיל את השרת
קוד:
openvpn server.conf
Sun Feb 3 11:33:44 2008 OpenVPN 2.0.9 i686-suse-linux [SSL] [LZO] [EPOLL] built on Jan 22 2008
Sun Feb 3 11:33:44 2008 Diffie-Hellman initialized with 1024 bit key
Sun Feb 3 11:33:44 2008 TLS-Auth MTU parms [ L:1542 D:138 EF:38 EB:0 ET:0 EL:0 ]
Sun Feb 3 11:33:44 2008 TUN/TAP device tun0 opened
Sun Feb 3 11:33:44 2008 /sbin/ifconfig tun0 10.8.0.1 pointopoint 10.8.0.2 mtu 1500
Sun Feb 3 11:33:44 2008 /sbin/route add -net 10.8.0.0 netmask 255.255.255.0 gw 10.8.0.2
Sun Feb 3 11:33:44 2008 Data Channel MTU parms [ L:1542 D:1450 EF:42 EB:135 ET:0 EL:0 AF:3/1 ]
Sun Feb 3 11:33:44 2008 UDPv4 link local (bound): 192.168.1.62:1194
Sun Feb 3 11:33:44 2008 UDPv4 link remote: [undef]
Sun Feb 3 11:33:44 2008 MULTI: multi_init called, r=256 v=256
Sun Feb 3 11:33:44 2008 IFCONFIG POOL: base=10.8.0.4 size=62
Sun Feb 3 11:33:44 2008 IFCONFIG POOL LIST
Sun Feb 3 11:33:44 2008 Test,10.8.0.4
Sun Feb 3 11:33:44 2008 Initialization Sequence Completed
כשאני מפעיל את הלקוח:
קוד:
Sun Feb 03 12:20:05 2008 OpenVPN 2.0.9 Win32-MinGW [SSL] [LZO] built on Oct 1 2
006
Sun Feb 03 12:20:05 2008 IMPORTANT: OpenVPN's default port number is now 1194, b
ased on an official port number assignment by IANA. OpenVPN 2.0-beta16 and earl
ier used 5000 as the default port.
Sun Feb 03 12:20:05 2008 WARNING: No server certificate verification method has
been enabled. See http://openvpn.net/howto.html#mitm for more info.
Sun Feb 03 12:20:05 2008 LZO compression initialized
Sun Feb 03 12:20:05 2008 Control Channel MTU parms [ L:1542 D:138 EF:38 EB:0 ET:
0 EL:0 ]
Sun Feb 03 12:20:05 2008 Data Channel MTU parms [ L:1542 D:1450 EF:42 EB:135 ET:
0 EL:0 AF:3/1 ]
Sun Feb 03 12:20:05 2008 Local Options hash (VER=V4): '41690919'
Sun Feb 03 12:20:05 2008 Expected Remote Options hash (VER=V4): '530fdded'
Sun Feb 03 12:20:05 2008 UDPv4 link local: [undef]
Sun Feb 03 12:20:05 2008 UDPv4 link remote: X.X.X.X:1194
Sun Feb 03 12:20:06 2008 TLS: Initial packet from X.X.X.X:1194, sid=abbdc8
02 659704c1
Sun Feb 03 12:20:06 2008 VERIFY OK: depth=1, /C=IL/ST=Center/L=Herzliya/O=XXX/OU=IT/CN=Server/emailAddress=XXXXX
Sun Feb 03 12:20:06 2008 VERIFY OK: depth=0, /C=IL/ST=Center/O=XXX/OU=IT/CN
=Server1/emailAddress=XXXXXX
Sun Feb 03 12:20:06 2008 Data Channel Encrypt: Cipher 'BF-CBC' initialized with
128 bit key
Sun Feb 03 12:20:06 2008 Data Channel Encrypt: Using 160 bit message hash 'SHA1'
for HMAC authentication
Sun Feb 03 12:20:06 2008 Data Channel Decrypt: Cipher 'BF-CBC' initialized with
128 bit key
Sun Feb 03 12:20:06 2008 Data Channel Decrypt: Using 160 bit message hash 'SHA1'
for HMAC authentication
Sun Feb 03 12:20:06 2008 Control Channel: TLSv1, cipher TLSv1/SSLv3 DHE-RSA-AES2
56-SHA, 1024 bit RSA
Sun Feb 03 12:20:06 2008 [Server1] Peer Connection Initiated with X.X.X.X:
1194
Sun Feb 03 12:20:08 2008 SENT CONTROL [Server1]: 'PUSH_REQUEST' (status=1)
Sun Feb 03 12:20:08 2008 PUSH: Received control message: 'PUSH_REPLY,route 192.1
68.0.0 255.255.0.0 10.8.0.1,dhcp-option DNS 10.8.0.1,route 10.8.0.1,ping 10,ping
-restart 120,ifconfig 10.8.0.6 10.8.0.5'
Sun Feb 03 12:20:08 2008 OPTIONS IMPORT: timers and/or timeouts modified
Sun Feb 03 12:20:08 2008 OPTIONS IMPORT: --ifconfig/up options modified
Sun Feb 03 12:20:08 2008 OPTIONS IMPORT: route options modified
Sun Feb 03 12:20:08 2008 OPTIONS IMPORT: --ip-win32 and/or --dhcp-option options
modified
Sun Feb 03 12:20:08 2008 TAP-WIN32 device [Local Area Connection 3] opened: \\.\
Global\{482D9010-B504-429E-9FA8-0BC2ECB89EDE}.tap
Sun Feb 03 12:20:08 2008 TAP-Win32 Driver Version 8.4
Sun Feb 03 12:20:08 2008 TAP-Win32 MTU=1500
Sun Feb 03 12:20:08 2008 Notified TAP-Win32 driver to set a DHCP IP/netmask of 1
0.8.0.6/255.255.255.252 on interface {482D9010-B504-429E-9FA8-0BC2ECB89EDE} [DHC
P-serv: 10.8.0.5, lease-time: 31536000]
Sun Feb 03 12:20:08 2008 Successful ARP Flush on interface [3] {482D9010-B504-42
9E-9FA8-0BC2ECB89EDE}
Sun Feb 03 12:20:08 2008 TEST ROUTES: 1/2 succeeded len=2 ret=0 a=0 u/d=up
Sun Feb 03 12:20:08 2008 Route: Waiting for TUN/TAP interface to come up...
Sun Feb 03 12:20:09 2008 TEST ROUTES: 1/2 succeeded len=2 ret=0 a=0 u/d=up
Sun Feb 03 12:20:09 2008 Route: Waiting for TUN/TAP interface to come up...
Sun Feb 03 12:20:10 2008 TEST ROUTES: 1/2 succeeded len=2 ret=0 a=0 u/d=up
Sun Feb 03 12:20:10 2008 Route: Waiting for TUN/TAP interface to come up...
Sun Feb 03 12:20:11 2008 TEST ROUTES: 1/2 succeeded len=2 ret=0 a=0 u/d=up
Sun Feb 03 12:20:11 2008 Route: Waiting for TUN/TAP interface to come up...
Sun Feb 03 12:20:12 2008 TEST ROUTES: 1/2 succeeded len=2 ret=0 a=0 u/d=up
Sun Feb 03 12:20:12 2008 Route: Waiting for TUN/TAP interface to come up...
Sun Feb 03 12:20:14 2008 TEST ROUTES: 1/2 succeeded len=2 ret=0 a=0 u/d=up
Sun Feb 03 12:20:14 2008 Route: Waiting for TUN/TAP interface to come up...
Sun Feb 03 12:20:15 2008 TEST ROUTES: 1/2 succeeded len=2 ret=0 a=0 u/d=up
Sun Feb 03 12:20:15 2008 Route: Waiting for TUN/TAP interface to come up...
Sun Feb 03 12:20:16 2008 TEST ROUTES: 1/2 succeeded len=2 ret=0 a=0 u/d=up
Sun Feb 03 12:20:16 2008 Route: Waiting for TUN/TAP interface to come up...
Sun Feb 03 12:20:17 2008 TEST ROUTES: 1/2 succeeded len=2 ret=0 a=0 u/d=up
Sun Feb 03 12:20:17 2008 Route: Waiting for TUN/TAP interface to come up...
Sun Feb 03 12:20:18 2008 TEST ROUTES: 1/2 succeeded len=2 ret=0 a=0 u/d=up
Sun Feb 03 12:20:18 2008 Route: Waiting for TUN/TAP interface to come up...
Sun Feb 03 12:20:19 2008 TEST ROUTES: 1/2 succeeded len=2 ret=0 a=0 u/d=up
Sun Feb 03 12:20:19 2008 Route: Waiting for TUN/TAP interface to come up...
Sun Feb 03 12:20:20 2008 TEST ROUTES: 1/2 succeeded len=2 ret=0 a=0 u/d=up
Sun Feb 03 12:20:20 2008 Route: Waiting for TUN/TAP interface to come up...
Sun Feb 03 12:20:21 2008 TEST ROUTES: 1/2 succeeded len=2 ret=0 a=0 u/d=up
Sun Feb 03 12:20:21 2008 Route: Waiting for TUN/TAP interface to come up...
Sun Feb 03 12:20:22 2008 TEST ROUTES: 1/2 succeeded len=2 ret=0 a=0 u/d=up
Sun Feb 03 12:20:22 2008 Route: Waiting for TUN/TAP interface to come up...
Sun Feb 03 12:20:23 2008 TEST ROUTES: 1/2 succeeded len=2 ret=0 a=0 u/d=up
Sun Feb 03 12:20:23 2008 Route: Waiting for TUN/TAP interface to come up...
Sun Feb 03 12:20:25 2008 TEST ROUTES: 1/2 succeeded len=2 ret=0 a=0 u/d=up
Sun Feb 03 12:20:25 2008 Route: Waiting for TUN/TAP interface to come up...
Sun Feb 03 12:20:26 2008 TEST ROUTES: 1/2 succeeded len=2 ret=0 a=0 u/d=up
Sun Feb 03 12:20:26 2008 Route: Waiting for TUN/TAP interface to come up...
Sun Feb 03 12:20:27 2008 TEST ROUTES: 1/2 succeeded len=2 ret=0 a=0 u/d=up
Sun Feb 03 12:20:27 2008 Route: Waiting for TUN/TAP interface to come up...
Sun Feb 03 12:20:28 2008 TEST ROUTES: 1/2 succeeded len=2 ret=0 a=0 u/d=up
Sun Feb 03 12:20:28 2008 Route: Waiting for TUN/TAP interface to come up...
Sun Feb 03 12:20:30 2008 TEST ROUTES: 1/2 succeeded len=2 ret=0 a=0 u/d=up
Sun Feb 03 12:20:30 2008 Route: Waiting for TUN/TAP interface to come up...
Sun Feb 03 12:20:31 2008 TEST ROUTES: 1/2 succeeded len=2 ret=0 a=0 u/d=up
Sun Feb 03 12:20:31 2008 Route: Waiting for TUN/TAP interface to come up...
Sun Feb 03 12:20:32 2008 TEST ROUTES: 1/2 succeeded len=2 ret=0 a=0 u/d=up
Sun Feb 03 12:20:32 2008 Route: Waiting for TUN/TAP interface to come up...
Sun Feb 03 12:20:33 2008 TEST ROUTES: 1/2 succeeded len=2 ret=0 a=0 u/d=up
Sun Feb 03 12:20:33 2008 Route: Waiting for TUN/TAP interface to come up...
Sun Feb 03 12:20:34 2008 TEST ROUTES: 1/2 succeeded len=2 ret=0 a=0 u/d=up
Sun Feb 03 12:20:34 2008 Route: Waiting for TUN/TAP interface to come up...
Sun Feb 03 12:20:36 2008 TEST ROUTES: 1/2 succeeded len=2 ret=0 a=0 u/d=up
Sun Feb 03 12:20:36 2008 Route: Waiting for TUN/TAP interface to come up...
Sun Feb 03 12:20:37 2008 TEST ROUTES: 1/2 succeeded len=2 ret=0 a=0 u/d=up
Sun Feb 03 12:20:37 2008 Route: Waiting for TUN/TAP interface to come up...
Sun Feb 03 12:20:37 2008 TEST ROUTES: 1/2 succeeded len=2 ret=0 a=0 u/d=up
Sun Feb 03 12:20:37 2008 route ADD 192.168.0.0 MASK 255.255.0.0 10.8.0.1
Sun Feb 03 12:20:37 2008 Warning: route gateway is not reachable on any active n
etwork adapters: 10.8.0.1
Sun Feb 03 12:20:37 2008 Route addition via IPAPI failed
Sun Feb 03 12:20:37 2008 route ADD 10.8.0.1 MASK 255.255.255.255 10.8.0.5
Sun Feb 03 12:20:37 2008 Route addition via IPAPI succeeded
Sun Feb 03 12:20:37 2008 Initialization Sequence Completed With Errors ( see htt
p://openvpn.net/faq.html#dhcpclientserv )
cat /etc/sysctl.conf
קוד:
cat /etc/sysctl.conf
# Disable response to broadcasts.
# You don't want yourself becoming a Smurf amplifier.
net.ipv4.icmp_echo_ignore_broadcasts = 1
# enable route verification on all interfaces
net.ipv4.conf.all.rp_filter = 1
# enable ipV6 forwarding
#net.ipv6.conf.all.forwarding = 1
# increase the number of possible inotify(7) watches
fs.inotify.max_user_watches = 65536
net.ipv4.ip_forward = 1
הוספתי את מה שנראה לי רלוונטי, תגיד אם אתה זקוק לעוד משהו.
בברכה,
SonyEricsson.
_____________________________________
FIRST THEY IGONRE YOU...
THEN THEY LAUGH AT YOU...
THEN THEY FIGHT YOU...
THEN YOU WIN...
MOHANDAS GANDHI
|