Spoiler
dev tun
server 192.168.10.0 255.255.255.0
push "route 192.168.1.0 255.255.255.0"
;push "dhcp-option DNS 8.8.8.8"
duplicate-cn
client-to-client
keepalive 10 120
auth MD5
cipher BF-CBC
port 1194
proto tcp-server
;push "redirect-gateway def1"
user root
group root
comp-lzo
persist-tun
persist-key
ca /etc/openvpn/keys/ca.crt
cert /etc/openvpn/keys/server.crt
key /etc/openvpn/keys/server.key
dh /etc/openvpn/keys/dh1024.pem
;status /var/log/openvpn-status.log
;log-append /var/log/openvpn.log
verb 5
server 192.168.10.0 255.255.255.0
push "route 192.168.1.0 255.255.255.0"
;push "dhcp-option DNS 8.8.8.8"
duplicate-cn
client-to-client
keepalive 10 120
auth MD5
cipher BF-CBC
port 1194
proto tcp-server
;push "redirect-gateway def1"
user root
group root
comp-lzo
persist-tun
persist-key
ca /etc/openvpn/keys/ca.crt
cert /etc/openvpn/keys/server.crt
key /etc/openvpn/keys/server.key
dh /etc/openvpn/keys/dh1024.pem
;status /var/log/openvpn-status.log
;log-append /var/log/openvpn.log
verb 5
То, что от рута запускается - сейчас не имеет значения.
На виндовых машинах имеем такой конфиг:
Spoiler
client
dev tun
proto tcp
port 1194
remote 8*.**.***.***
comp-lzo
auth MD5
cipher BF-CBC
persist-key
persist-tun
keepalive 10 120
tls-timeout 120
ca office_comp41\\ca.crt
cert office_comp41\\client.crt
key office_comp41\\client.key
route-method exe
route-delay 2
dev tun
proto tcp
port 1194
remote 8*.**.***.***
comp-lzo
auth MD5
cipher BF-CBC
persist-key
persist-tun
keepalive 10 120
tls-timeout 120
ca office_comp41\\ca.crt
cert office_comp41\\client.crt
key office_comp41\\client.key
route-method exe
route-delay 2
На машине с win 7 запускаем подключение с помощью OpenVPN GUI (c правами админа) и имеем такой лог:
Tue Nov 22 22:58:07 2011 OpenVPN 2.0.9 Win32-MinGW [SSL] [LZO] built on Oct 1 2006
Tue Nov 22 22:58:07 2011 WARNING: No server certificate verification method has been enabled. See http://openvpn.net/howto.html#mitm for more info.
Tue Nov 22 22:58:07 2011 LZO compression initialized
Tue Nov 22 22:58:07 2011 Attempting to establish TCP connection with 8*.**.***.***:1194
Tue Nov 22 22:58:07 2011 TCP connection established with 8*.**.***.***:1194
Tue Nov 22 22:58:07 2011 TCPv4_CLIENT link local: [undef]
Tue Nov 22 22:58:07 2011 TCPv4_CLIENT link remote: 8*.**.***.***:1194
Tue Nov 22 22:58:10 2011 [server] Peer Connection Initiated with 8*.**.***.***:1194
Tue Nov 22 22:58:12 2011 Options error: Unrecognized option or missing parameter(s) in [PUSH-OPTIONS]:3: topology (2.0.9)
Tue Nov 22 22:58:12 2011 TAP-WIN32 device [Подключение по локальной сети 2] opened: \\.\Global\{EDAF3772-C966-4F62-86C1-47F80DCB569D}.tap
Tue Nov 22 22:58:12 2011 Notified TAP-Win32 driver to set a DHCP IP/netmask of 192.168.10.6/255.255.255.252 on interface {EDAF3772-C966-4F62-86C1-47F80DCB569D} [DHCP-serv: 192.168.10.5, lease-time: 31536000]
Tue Nov 22 22:58:12 2011 Successful ARP Flush on interface [17] {EDAF3772-C966-4F62-86C1-47F80DCB569D}
ЋЉ
ЋЉ
Tue Nov 22 22:58:14 2011 Initialization Sequence Completed
Без прав админа, вот такой лог:
Tue Nov 22 23:12:02 2011 OpenVPN 2.0.9 Win32-MinGW [SSL] [LZO] built on Oct 1 2006
Tue Nov 22 23:12:02 2011 WARNING: No server certificate verification method has been enabled. See http://openvpn.net/howto.html#mitm for more info.
Tue Nov 22 23:12:02 2011 LZO compression initialized
Tue Nov 22 23:12:02 2011 Attempting to establish TCP connection with 8*.**.***.***:1194
Tue Nov 22 23:12:02 2011 TCP connection established with 8*.**.***.***:1194
Tue Nov 22 23:12:02 2011 TCPv4_CLIENT link local: [undef]
Tue Nov 22 23:12:02 2011 TCPv4_CLIENT link remote: 8*.**.***.***:1194
Tue Nov 22 23:12:05 2011 [server] Peer Connection Initiated with 8*.**.***.***:1194
Tue Nov 22 23:12:06 2011 Options error: Unrecognized option or missing parameter(s) in [PUSH-OPTIONS]:3: topology (2.0.9)
Tue Nov 22 23:12:06 2011 TAP-WIN32 device [Подключение по локальной сети 2] opened: \\.\Global\{EDAF3772-C966-4F62-86C1-47F80DCB569D}.tap
Tue Nov 22 23:12:06 2011 Notified TAP-Win32 driver to set a DHCP IP/netmask of 192.168.10.6/255.255.255.252 on interface {EDAF3772-C966-4F62-86C1-47F80DCB569D} [DHCP-serv: 192.168.10.5, lease-time: 31536000]
Tue Nov 22 23:12:06 2011 NOTE: FlushIpNetTable failed on interface [17] {EDAF3772-C966-4F62-86C1-47F80DCB569D} (status=5) : Отказано в доступе.
‡ Їа®иҐ п ®ЇҐа жЁп вॡгҐв Ї®ўл襨п.
Tue Nov 22 23:12:09 2011 ERROR: Windows route add command failed: system() returned error code 1
‡ Їа®иҐ п ®ЇҐа жЁп вॡгҐв Ї®ўл襨п.
Tue Nov 22 23:12:09 2011 ERROR: Windows route add command failed: system() returned error code 1
Tue Nov 22 23:12:09 2011 Initialization Sequence Completed
При этом, компы в сети за openVPN не пингуются, с самого компа с openVPN - пингуются.
Установка клиента на XP тоже не помогает.
Помогите решить проблему...