VPN.... dove sbaglio?
Inviato: 22 set 2015, 09:27
Come da presentazione, sono un paio di giorni che sto litigando con la VPN con OpenVPN
I test li faccio da un iPad e/o da un iPhone.
Ho un account no-ip e l'ho configurato sul router (telecom) e da tempo fa il suo lavoro correttamente (VNC, WOL e quant'altro),
Ora, con il nuovo arrivato, vorrei far funzionare la VPN e quindi poter poi chiudere un po' di porte sul router.
Vi posto un paio di log e file di configurazione:
Log OpenVPN da iPad:
OpenVPN,opvn
config router:
I test li faccio da un iPad e/o da un iPhone.
Ho un account no-ip e l'ho configurato sul router (telecom) e da tempo fa il suo lavoro correttamente (VNC, WOL e quant'altro),
Ora, con il nuovo arrivato, vorrei far funzionare la VPN e quindi poter poi chiudere un po' di porte sul router.
Vi posto un paio di log e file di configurazione:
Log OpenVPN da iPad:
Codice: Seleziona tutto
2015-09-19 00:22:26 ----- OpenVPN Start -----
OpenVPN core 3.0 ios arm64 64-bit
2015-09-19 00:22:26 UNUSED OPTIONS
2 [script-security] [3]
5 [resolv-retry] [infinite]
6 [nobind]
10 [tls-cipher] [RSA+AES128:RSA+AES256:RSA+3DES:!MD5]
11 [set] [CLIENT_CERT] [0]
2015-09-19 00:22:26 LZO-ASYM init swap=0 asym=0
2015-09-19 00:22:26 EVENT: RESOLVE
2015-09-19 00:22:27 Contacting [64:ff9b::570f:d8b2]:1194 via UDP
2015-09-19 00:22:27 EVENT: WAIT
2015-09-19 00:22:27 SetTunnelSocket returned 1
2015-09-19 00:22:27 Transport Error: UDP connect error on 'Xxxxxxx:1194' ([64:ff9b::570f:d8b2]:1194): No route to host
2015-09-19 00:22:27 Client terminated, restarting in 2...
2015-09-19 00:22:29 EVENT: RECONNECTING
2015-09-19 00:22:29 LZO-ASYM init swap=0 asym=0
2015-09-19 00:22:29 Contacting xxx.xxx.xxx.xxx:1194 via UDP
2015-09-19 00:22:29 EVENT: WAIT
2015-09-19 00:22:29 SetTunnelSocket returned 1
2015-09-19 00:22:29 Connecting to Xxxxxxxxxxx:1194 (xxx.xxx.xxx.xxx) via UDPv4
2015-09-19 00:22:29 EVENT: CONNECTING
2015-09-19 00:22:29 Tunnel Options:V4,dev-type tun,link-mtu 1558,tun-mtu 1500,proto UDPv4,comp-lzo,cipher AES-256-CBC,auth SHA1,keysize 256,key-method 2,tls-client
2015-09-19 00:22:29 Creds: Username/Password
2015-09-19 00:22:29 Peer Info:
IV_GUI_VER=net.openvpn.connect.ios 1.0.5-177
IV_VER=3.0
IV_PLAT=ios
IV_NCP=1
IV_LZO=1
2015-09-19 00:23:10 Session invalidated: KEEPALIVE_TIMEOUT
2015-09-19 00:23:10 Client terminated, restarting in 2...
2015-09-19 00:23:12 EVENT: RECONNECTING
2015-09-19 00:23:12 LZO-ASYM init swap=0 asym=0
2015-09-19 00:23:12 EVENT: RESOLVE
2015-09-19 00:23:12 Contacting [64:ff9b::570f:d8b2]:1194 via UDP
2015-09-19 00:23:12 EVENT: WAIT
2015-09-19 00:23:12 SetTunnelSocket returned 1
2015-09-19 00:23:12 Transport Error: UDP connect error on 'Xxxxxxxxx:1194' ([64:ff9b::570f:d8b2]:1194): No route to host
2015-09-19 00:23:12 Client terminated, restarting in 2...
Codice: Seleziona tutto
client
dev tun
script-security 3
proto udp
remote Xxxxxxx 1194
resolv-retry infinite
nobind
#ca ca.crt
auth-user-pass
reneg-sec 0
cipher AES-256-CBC
tls-cipher RSA+AES128:RSA+AES256:RSA+3DES:!MD5
set CLIENT_CERT 0
comp-lzo
<ca>
-----BEGIN CERTIFICATE-----
MIIDxTCCAy6gAwIBAgIJAMBkg+J+dTwlMA0GCSqGSIb3DQEBBQUAMIGeMQswCQYD
VQQGEwJUVzEPMA0GA1UECBMGVGFpd2FuMQ8wDQYDVQQHEwZUYWlwZWkxGjAYBgNV
BAoTEVFOQVAgU3lzdGVtcyBJbmMuMQwwCgYDVQQLEwNOQVMxFjAUBgNVBAMTDVRT
IFNlcmllcyBOQVMxDDAKBgNVBCkTA05BUzEdMBsGCSqGSIb3DQEJARYOYWRtaW5A
cW5hcC5jb20wHhcNMTUwOTE1MDgwNzIzWhcNMjUwOTEyMDgwNzIzWjCBnjELMAkG
A1UEBhMCVFcxDzANBgNVBAgTBlRhaXdhbjEPMA0GA1UEBxMGVGFpcGVpMRowGAYD
VQQKExFRTkFQIFN5c3RlbXMgSW5jLjEMMAoGA1UECxMDTkFTMRYwFAYDVQQDEw1U
UyBTZXJpZXMgTkFTMQwwCgYDVQQpEwNOQVMxHTAbBgkqhkiG9w0BCQEWDmFkbWlu
QHFuYXAuY29tMIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDDXZslrmvgYiPG
WOnSNVqduPNsM4pGXK3mE6Oi0tfbdP90lEs1gtoYcSnwv/q14oLejkR6WtrwuOAc
J3TU4FL6R3oNAkAN3D0trh2/iV1JkjihxO4MWFMmScpj2Hgro8UrERq6POAe6dZG
W830fQQwqWtbxBiHu83WVKUJuwEXCwIDAQABo4IBBzCCAQMwHQYDVR0OBBYEFLkQ
6zW4Eyaedh/c1pBQIb8/bh4hMIHTBgNVHSMEgcswgciAFLkQ6zW4Eyaedh/c1pBQ
Ib8/bh4hoYGkpIGhMIGeMQswCQYDVQQGEwJUVzEPMA0GA1UECBMGVGFpd2FuMQ8w
DQYDVQQHEwZUYWlwZWkxGjAYBgNVBAoTEVFOQVAgU3lzdGVtcyBJbmMuMQwwCgYD
VQQLEwNOQVMxFjAUBgNVBAMTDVRTIFNlcmllcyBOQVMxDDAKBgNVBCkTA05BUzEd
MBsGCSqGSIb3DQEJARYOYWRtaW5AcW5hcC5jb22CCQDAZIPifnU8JTAMBgNVHRME
BTADAQH/MA0GCSqGSIb3DQEBBQUAA4GBACwee6dzKHmarJ1I6Mm5DplyCVBTaj1g
BOUzjrsY16b1yauxZEff2u4DBhDyYjzMMSoX2hb0c/RpzPlqdxXB21b91wXQ6gyE
z2ybFhCo54bYxHMO2M/wBGt40j2aV+AKwTu19bQFbl2eH/mwcnhH8gAj1QFIlt9G
nknMRZT8ZTV4
-----END CERTIFICATE-----
</ca>