Hi
On 23 Jan., 22:28, Lupus <
a...@seqlab.de> wrote:
> ... Now that I'm trying to connect from home, it isn't working.
As an update to my previous post: it is working now. The problem was
related to the bridge interface. I used the bridge-start and bridge-
stop scripts from the Debian bridge-utils package as recommended by
the
openvpn.net HOWTO
http://www.openvpn.net/index.php/open-source/documentation/miscellaneous/76-ethernet-bridging.html
. Apparently the default route is lost during setup, and thus the
openvpn-server had no connectivity to the outside world at all. I
didn't notice that while testing inside the company's private subnet.
Back to my original problem: the TB-client should receive an IP-
address from the company's DHCP-server. But before proceeding I really
should post my setup.
The remote (company) network can be reached via two different public
IP-addresses (load-balanced) and has a private network in the
192.168.101.0/24 range.
The router is at 192.168.101.1, the DHCP-server at 192.168.101.6, and
the OpenVPN-server at 192.168.101.10. On the public side port 9010 is
opened and forwarded to port 1194 on the OpenVPN-server
(192.168.101.10). That part is working ok, I think. On the OpenVPN-
server the (relevant) interfaces look like this (after running bridge-
start):
# ifconfig -a
br0 Link encap:Ethernet HWaddr 00:25:90:1d:1e:e8
inet addr:192.168.101.10 Bcast:192.168.101.255 Mask:
255.255.255.0
inet6 addr: fe80::225:90ff:fe1d:1ee8/64 Scope:Link
UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1
RX packets:3717329 errors:0 dropped:0 overruns:0 frame:0
TX packets:4374725 errors:0 dropped:0 overruns:0 carrier:0
collisions:0 txqueuelen:0
RX bytes:
2837890783 (2.6 GiB) TX bytes:
4143672206 (3.8 GiB)
eth0 Link encap:Ethernet HWaddr 00:25:90:1d:1e:e8
inet6 addr: fe80::225:90ff:fe1d:1ee8/64 Scope:Link
UP BROADCAST RUNNING PROMISC MULTICAST MTU:1500 Metric:1
RX packets:4960381 errors:0 dropped:0 overruns:0 frame:0
TX packets:5733252 errors:0 dropped:0 overruns:0 carrier:0
collisions:0 txqueuelen:1000
RX bytes:2970969373 (2.7 GiB) TX bytes:4219961987 (3.9 GiB)
Memory:fafe0000-fb000000
tap0 Link encap:Ethernet HWaddr 7e:24:40:71:2e:a5
BROADCAST MULTICAST MTU:1500 Metric:1
RX packets:81 errors:0 dropped:0 overruns:0 frame:0
TX packets:0 errors:0 dropped:0 overruns:0 carrier:0
collisions:0 txqueuelen:100
RX bytes:27081 (26.4 KiB) TX bytes:0 (0.0 B)
So the bridge-interface has correctly taken the IP from the former
dhcp-configured eth0 interface. The server.conf file for the openvpn
server looks like this:
# cat server.conf
local 192.168.101.10
port 1194
proto tcp-server
tls-server
dev tap0
ca /etc/openvpn/keys/ca.crt
cert /etc/openvpn/keys/server.crt
key /etc/openvpn/keys/server.key # This file should be kept secret
dh /etc/openvpn/keys/dh1024.pem
server-bridge
push "redirect-gateway"
keepalive 10 120
comp-lzo
max-clients 10
;user nobody
;group nogroup
persist-key
persist-tun
status openvpn-status.log
;log openvpn.log
log-append openvpn.log
verb 4
;mute 20
My home situation is a private subnet behind a home-router
(
192.168.178.0/24) The Tunnelblick client is configured as:
client
dev tap
proto tcp
remote 77.20.123.xxx 9010
remote 193.175.25.xxx 9010
resolv-retry infinite
nobind
# Client1 specific pseudo-Mac-address
lladdr 00:03:93:57:57:57
;user nobody
;group nobody
persist-key
persist-tun
ca ca.crt
cert client1.crt
key client1.key
comp-lzo
verb 4
;mute 20
The logs look like this
server:
Wed Jan 25 13:28:01 2012 us=673611 MULTI: multi_create_instance called
Wed Jan 25 13:28:01 2012 us=673681 Re-using SSL/TLS context
Wed Jan 25 13:28:01 2012 us=673709 LZO compression initialized
Wed Jan 25 13:28:01 2012 us=673805 Control Channel MTU parms [ L:1576
D:140 EF:40 EB:0 ET:0 EL:0 ]
Wed Jan 25 13:28:01 2012 us=673824 Data Channel MTU parms [ L:1576 D:
1450 EF:44 EB:135 ET:32 EL:0 AF:3/1 ]
Wed Jan 25 13:28:01 2012 us=673849 Local Options String: 'V4,dev-type
tap,link-mtu 1576,tun-mtu 1532,proto TCPv4_SERVER,comp-lzo,cipher BF-
CBC,auth SHA1,keysize 128,key-method 2,tls-server'
Wed Jan 25 13:28:01 2012 us=673857 Expected Remote Options String:
'V4,dev-type tap,link-mtu 1576,tun-mtu 1532,proto TCPv4_CLIENT,comp-
lzo,cipher BF-CBC,auth SHA1,keysize 128,key-method 2,tls-client'
Wed Jan 25 13:28:01 2012 us=673877 Local Options hash (VER=V4):
'3e6d1056'
Wed Jan 25 13:28:01 2012 us=673889 Expected Remote Options hash
(VER=V4): '31fdf004'
Wed Jan 25 13:28:01 2012 us=673911 TCP connection established with
77.22.5.xx:62043
Wed Jan 25 13:28:01 2012 us=673924 Socket Buffers: R=[131072->131072]
S=[131072->131072]
Wed Jan 25 13:28:01 2012 us=673934 TCPv4_SERVER link local: [undef]
Wed Jan 25 13:28:01 2012 us=673944 TCPv4_SERVER link remote:
77.22.5.21:62043
Wed Jan 25 13:28:02 2012 us=653550 77.22.5.xx:62043 TLS: Initial
packet from 77.22.5.xx:62043, sid=8fbc3386 ea3c6874
Wed Jan 25 13:28:03 2012 us=406028 77.22.5.xx:62043 VERIFY OK:
depth=1, /C=DE/ST=NS/L=GOETTINGEN/O=SEQLAB/OU=IT-Department/
CN=cruncher/emailAddress=
x...@seqlab.de
Wed Jan 25 13:28:03 2012 us=406195 77.22.5.xx:62043 VERIFY OK:
depth=0, /C=DE/ST=NS/O=SEQLAB/OU=IT-Department/CN=client1/
emailAddress=
x...@seqlab.de
Wed Jan 25 13:28:03 2012 us=649286 77.22.5.xx:62043 Data Channel
Encrypt: Cipher 'BF-CBC' initialized with 128 bit key
Wed Jan 25 13:28:03 2012 us=649330 77.22.5.xx:62043 Data Channel
Encrypt: Using 160 bit message hash 'SHA1' for HMAC authentication
Wed Jan 25 13:28:03 2012 us=649392 77.22.5.xx:62043 Data Channel
Decrypt: Cipher 'BF-CBC' initialized with 128 bit key
Wed Jan 25 13:28:03 2012 us=649402 77.22.5.xx:62043 Data Channel
Decrypt: Using 160 bit message hash 'SHA1' for HMAC authentication
Wed Jan 25 13:28:03 2012 us=750047 77.22.5.xx:62043 Control Channel:
TLSv1, cipher TLSv1/SSLv3 DHE-RSA-AES256-SHA, 1024 bit RSA
Wed Jan 25 13:28:03 2012 us=750091 77.22.5.xx:62043 [client1] Peer
Connection Initiated with 77.22.5.xx:62043
Wed Jan 25 13:28:03 2012 us=750146 client1/77.22.5.xx:62043 MULTI: no
dynamic or static remote --ifconfig address is available for
client1/77.22.5.x:62043
Wed Jan 25 13:28:06 2012 us=169190 client1/77.22.5.xx:62043 PUSH:
Received control message: 'PUSH_REQUEST'
Wed Jan 25 13:28:06 2012 us=169288 client1/77.22.5.xx:62043 SENT
CONTROL [client1]: 'PUSH_REPLY,redirect-gateway,route-gateway
dhcp,ping 10,ping-restart 120' (status=1)
Wed Jan 25 13:28:09 2012 us=45882 client1/77.22.5.xx:62043 MULTI:
Learn: 00:03:93:57:57:57 -> client1/77.22.5.xx:62043
######################################################################
TB client:
2012-01-25 13:28:00 *Tunnelblick: OS X 10.6.5; Tunnelblick 3.2.2
(build 2891.2917)
...
2012-01-25 13:28:01 us=498205 proto = tcp-client
2012-01-25 13:28:01 us=498217 local = '[UNDEF]'
2012-01-25 13:28:01 us=498228 local_port = 0
2012-01-25 13:28:01 us=498239 remote = '77.20.123.xxx'
2012-01-25 13:28:01 us=498251 remote_port = 9010
2012-01-25 13:28:01 us=498262 remote_float = DISABLED
2012-01-25 13:28:01 us=498273 bind_defined = DISABLED
2012-01-25 13:28:01 us=498284 bind_local = DISABLED
2012-01-25 13:28:01 us=498296 connect_retry_seconds = 5
2012-01-25 13:28:01 us=498307 connect_timeout = 10
2012-01-25 13:28:01 us=498318 connect_retry_max = 0
2012-01-25 13:28:01 us=498329 socks_proxy_server = '[UNDEF]'
2012-01-25 13:28:01 us=498340 socks_proxy_port = 0
2012-01-25 13:28:01 us=498351 socks_proxy_retry = DISABLED
2012-01-25 13:28:01 us=498363 Connection profiles [1]:
2012-01-25 13:28:01 us=498374 proto = tcp-client
2012-01-25 13:28:01 us=498385 local = '[UNDEF]'
2012-01-25 13:28:01 us=498396 local_port = 0
2012-01-25 13:28:01 us=498408 remote = '193.175.25.222'
2012-01-25 13:28:01 us=498419 remote_port = 9010
2012-01-25 13:28:01 us=498430 remote_float = DISABLED
2012-01-25 13:28:01 us=498441 bind_defined = DISABLED
2012-01-25 13:28:01 us=498452 bind_local = DISABLED
2012-01-25 13:28:01 us=498464 connect_retry_seconds = 5
2012-01-25 13:28:01 us=498475 connect_timeout = 10
2012-01-25 13:28:01 us=498486 connect_retry_max = 0
2012-01-25 13:28:01 us=498497 socks_proxy_server = '[UNDEF]'
2012-01-25 13:28:01 us=498508 socks_proxy_port = 0
2012-01-25 13:28:01 us=498520 socks_proxy_retry = DISABLED
2012-01-25 13:28:01 us=498531 Connection profiles END
2012-01-25 13:28:01 us=498542 remote_random = DISABLED
2012-01-25 13:28:01 us=498553 ipchange = '[UNDEF]'
2012-01-25 13:28:01 us=498565 dev = 'tap'
2012-01-25 13:28:01 us=498576 dev_type = '[UNDEF]'
2012-01-25 13:28:01 us=498587 dev_node = '[UNDEF]'
2012-01-25 13:28:01 us=498598 lladdr = '00:03:93:57:57:57'
2012-01-25 13:28:01 us=498610 topology = 1
2012-01-25 13:28:01 us=498621 tun_ipv6 = DISABLED
2012-01-25 13:28:01 us=498632 ifconfig_local = '[UNDEF]'
2012-01-25 13:28:01 us=498643 ifconfig_remote_netmask = '[UNDEF]'
2012-01-25 13:28:01 us=498655 ifconfig_noexec = DISABLED
2012-01-25 13:28:01 us=498666 ifconfig_nowarn = DISABLED
2012-01-25 13:28:01 us=498692 shaper = 0
2012-01-25 13:28:01 us=498704 tun_mtu = 1500
2012-01-25 13:28:01 us=498715 tun_mtu_defined = ENABLED
2012-01-25 13:28:01 us=498726 link_mtu = 1500
2012-01-25 13:28:01 us=498737 link_mtu_defined = DISABLED
2012-01-25 13:28:01 us=498749 tun_mtu_extra = 32
2012-01-25 13:28:01 us=498760 tun_mtu_extra_defined = ENABLED
2012-01-25 13:28:01 us=498771 fragment = 0
2012-01-25 13:28:01 us=498783 mtu_discover_type = -1
2012-01-25 13:28:01 us=498794 mtu_test = 0
2012-01-25 13:28:01 us=498805 mlock = DISABLED
2012-01-25 13:28:01 us=498817 keepalive_ping = 0
2012-01-25 13:28:01 us=498828 keepalive_timeout = 0
2012-01-25 13:28:01 us=498839 inactivity_timeout = 0
2012-01-25 13:28:01 us=498850 ping_send_timeout = 0
2012-01-25 13:28:01 us=498861 ping_rec_timeout = 0
2012-01-25 13:28:01 us=498877 ping_rec_timeout_action = 0
2012-01-25 13:28:01 us=498888 ping_timer_remote = DISABLED
2012-01-25 13:28:01 us=498900 remap_sigusr1 = 0
2012-01-25 13:28:01 us=498911 explicit_exit_notification = 0
2012-01-25 13:28:01 us=498922 persist_tun = ENABLED
2012-01-25 13:28:01 us=498934 persist_local_ip = DISABLED
2012-01-25 13:28:01 us=498945 persist_remote_ip = DISABLED
2012-01-25 13:28:01 us=498959 persist_key = ENABLED
2012-01-25 13:28:01 us=498971 mssfix = 1450
2012-01-25 13:28:01 us=498982 passtos = DISABLED
2012-01-25 13:28:01 us=498994 resolve_retry_seconds = 1000000000
2012-01-25 13:28:01 us=499005 username = '[UNDEF]'
2012-01-25 13:28:01 us=499017 groupname = '[UNDEF]'
2012-01-25 13:28:01 us=499028 chroot_dir = '[UNDEF]'
2012-01-25 13:28:01 us=499039 cd_dir = '/Users/Lupus/Library/
Application Support/Tunnelblick/Configurations/cruncherglobal.tblk/
Contents/Resources'
2012-01-25 13:28:01 us=499051 writepid = '[UNDEF]'
2012-01-25 13:28:01 us=499062 up_script = '/Applications/
Tunnelblick.app/Contents/Resources/
client.up.tunnelblick.sh -m -w -d -
a -atDASNGWrdasngw'
2012-01-25 13:28:01 us=499078 down_script = '/Applications/
Tunnelblick.app/Contents/Resources/
client.down.tunnelblick.sh -m -w -d
-a -atDASNGWrdasngw'
2012-01-25 13:28:01 us=499091 down_pre = DISABLED
2012-01-25 13:28:01 us=499106 up_restart = ENABLED
2012-01-25 13:28:01 us=499118 up_delay = DISABLED
2012-01-25 13:28:01 us=499130 daemon = ENABLED
2012-01-25 13:28:01 us=499142 inetd = 0
2012-01-25 13:28:01 us=499153 log = ENABLED
2012-01-25 13:28:01 us=499165 suppress_timestamps = DISABLED
2012-01-25 13:28:01 us=499177 nice = 0
2012-01-25 13:28:01 us=499189 verbosity = 4
2012-01-25 13:28:01 us=499201 mute = 0
2012-01-25 13:28:01 us=499212 gremlin = 0
2012-01-25 13:28:01 us=499224 status_file = '[UNDEF]'
2012-01-25 13:28:01 us=499236 status_file_version = 1
2012-01-25 13:28:01 us=499247 status_file_update_freq = 60
2012-01-25 13:28:01 us=499259 occ = ENABLED
2012-01-25 13:28:01 us=499271 rcvbuf = 65536
2012-01-25 13:28:01 us=499283 sndbuf = 65536
2012-01-25 13:28:01 us=499294 sockflags = 0
2012-01-25 13:28:01 us=499309 fast_io = DISABLED
2012-01-25 13:28:01 us=499321 lzo = 7
2012-01-25 13:28:01 us=499333 route_script = '[UNDEF]'
2012-01-25 13:28:01 us=499345 route_default_gateway = '[UNDEF]'
2012-01-25 13:28:01 us=499357 route_default_metric = 0
2012-01-25 13:28:01 us=499369 route_noexec = DISABLED
2012-01-25 13:28:01 us=499381 route_delay = 0
2012-01-25 13:28:01 us=499392 route_delay_window = 30
2012-01-25 13:28:01 us=499404 route_delay_defined = DISABLED
2012-01-25 13:28:01 us=499416 route_nopull = DISABLED
2012-01-25 13:28:01 us=499428 route_gateway_via_dhcp = DISABLED
2012-01-25 13:28:01 us=499440 max_routes = 100
2012-01-25 13:28:01 us=499452 allow_pull_fqdn = DISABLED
2012-01-25 13:28:01 us=499463 management_addr = '127.0.0.1'
2012-01-25 13:28:01 us=499490 management_port = 1337
2012-01-25 13:28:01 us=499502 management_user_pass = '[UNDEF]'
2012-01-25 13:28:01 us=499514 management_log_history_cache = 250
2012-01-25 13:28:01 us=499526 management_echo_buffer_size = 100
2012-01-25 13:28:01 us=499538 management_write_peer_info_file =
'[UNDEF]'
2012-01-25 13:28:01 us=499550 management_client_user = '[UNDEF]'
2012-01-25 13:28:01 us=499562 management_client_group = '[UNDEF]'
2012-01-25 13:28:01 us=499574 management_flags = 6
2012-01-25 13:28:01 us=499585 shared_secret_file = '[UNDEF]'
2012-01-25 13:28:01 us=499597 key_direction = 0
2012-01-25 13:28:01 us=499609 ciphername_defined = ENABLED
2012-01-25 13:28:01 us=499620 ciphername = 'BF-CBC'
2012-01-25 13:28:01 us=499632 authname_defined = ENABLED
2012-01-25 13:28:01 us=499643 authname = 'SHA1'
2012-01-25 13:28:01 us=499655 prng_hash = 'SHA1'
2012-01-25 13:28:01 us=499666 prng_nonce_secret_len = 16
2012-01-25 13:28:01 us=499678 keysize = 0
2012-01-25 13:28:01 us=499689 engine = DISABLED
2012-01-25 13:28:01 us=499701 replay = ENABLED
2012-01-25 13:28:01 us=499713 mute_replay_warnings = DISABLED
2012-01-25 13:28:01 us=499724 replay_window = 64
2012-01-25 13:28:01 us=499736 replay_time = 15
2012-01-25 13:28:01 us=499747 packet_id_file = '[UNDEF]'
2012-01-25 13:28:01 us=499759 use_iv = ENABLED
2012-01-25 13:28:01 us=499774 test_crypto = DISABLED
2012-01-25 13:28:01 us=499786 tls_server = DISABLED
2012-01-25 13:28:01 us=499798 tls_client = ENABLED
2012-01-25 13:28:01 us=499809 key_method = 2
2012-01-25 13:28:01 us=499821 ca_file = 'ca.crt'
2012-01-25 13:28:01 us=499832 ca_path = '[UNDEF]'
2012-01-25 13:28:01 us=499844 dh_file = '[UNDEF]'
2012-01-25 13:28:01 us=499855 cert_file = 'client1.crt'
2012-01-25 13:28:01 us=499867 priv_key_file = 'client1.key'
2012-01-25 13:28:01 us=499878 pkcs12_file = '[UNDEF]'
2012-01-25 13:28:01 us=499890 cipher_list = '[UNDEF]'
2012-01-25 13:28:01 us=499902 tls_verify = '[UNDEF]'
2012-01-25 13:28:01 us=499913 tls_export_cert = '[UNDEF]'
2012-01-25 13:28:01 us=499925 tls_remote = '[UNDEF]'
2012-01-25 13:28:01 us=499936 crl_file = '[UNDEF]'
2012-01-25 13:28:01 us=499948 ns_cert_type = 0
2012-01-25 13:28:01 us=499981 remote_cert_ku[i] = 0
….
2012-01-25 13:28:01 us=500166 remote_cert_eku = '[UNDEF]'
2012-01-25 13:28:01 us=500177 tls_timeout = 2
2012-01-25 13:28:01 us=500189 renegotiate_bytes = 0
2012-01-25 13:28:01 us=500200 renegotiate_packets = 0
2012-01-25 13:28:01 us=500212 renegotiate_seconds = 3600
2012-01-25 13:28:01 us=500223 handshake_window = 60
2012-01-25 13:28:01 us=500234 transition_window = 3600
2012-01-25 13:28:01 us=500246 single_session = DISABLED
2012-01-25 13:28:01 us=500257 push_peer_info = DISABLED
2012-01-25 13:28:01 us=500269 tls_exit = DISABLED
2012-01-25 13:28:01 us=500280 tls_auth_file = '[UNDEF]'
2012-01-25 13:28:01 us=500306 pkcs11_protected_authentication =
DISABLED
…
2012-01-25 13:28:01 us=500503 pkcs11_private_mode = 00000000
...
2012-01-25 13:28:01 us=500703 pkcs11_cert_private = DISABLED
...
2012-01-25 13:28:01 us=500889 pkcs11_pin_cache_period = -1
2012-01-25 13:28:01 us=500900 pkcs11_id = '[UNDEF]'
2012-01-25 13:28:01 us=500912 pkcs11_id_management = DISABLED
2012-01-25 13:28:01 us=500933 server_network = 0.0.0.0
2012-01-25 13:28:01 us=500946 server_netmask = 0.0.0.0
2012-01-25 13:28:01 us=500959 server_bridge_ip = 0.0.0.0
2012-01-25 13:28:01 us=500972 server_bridge_netmask = 0.0.0.0
2012-01-25 13:28:01 us=500985 server_bridge_pool_start = 0.0.0.0
2012-01-25 13:28:01 us=500998 server_bridge_pool_end = 0.0.0.0
2012-01-25 13:28:01 us=501010 ifconfig_pool_defined = DISABLED
2012-01-25 13:28:01 us=501037 ifconfig_pool_start = 0.0.0.0
2012-01-25 13:28:01 us=501052 ifconfig_pool_end = 0.0.0.0
2012-01-25 13:28:01 us=501065 ifconfig_pool_netmask = 0.0.0.0
2012-01-25 13:28:01 us=501077 ifconfig_pool_persist_filename =
'[UNDEF]'
2012-01-25 13:28:01 us=501089 ifconfig_pool_persist_refresh_freq =
600
2012-01-25 13:28:01 us=501101 n_bcast_buf = 256
2012-01-25 13:28:01 us=501113 tcp_queue_limit = 64
2012-01-25 13:28:01 us=501124 real_hash_size = 256
2012-01-25 13:28:01 us=501136 virtual_hash_size = 256
2012-01-25 13:28:01 us=501147 client_connect_script = '[UNDEF]'
2012-01-25 13:28:01 us=501159 learn_address_script = '[UNDEF]'
2012-01-25 13:28:01 us=501171 client_disconnect_script = '[UNDEF]'
2012-01-25 13:28:01 us=501183 client_config_dir = '[UNDEF]'
2012-01-25 13:28:01 us=501194 ccd_exclusive = DISABLED
2012-01-25 13:28:01 us=501206 tmp_dir = '/var/folders/Vg/
VgdNz5IJEBGy6ie8zTeU9k+++TI/-Tmp-/'
2012-01-25 13:28:01 us=501218 push_ifconfig_defined = DISABLED
2012-01-25 13:28:01 us=501231 push_ifconfig_local = 0.0.0.0
2012-01-25 13:28:01 us=501244 push_ifconfig_remote_netmask = 0.0.0.0
2012-01-25 13:28:01 us=501255 enable_c2c = DISABLED
2012-01-25 13:28:01 us=501267 duplicate_cn = DISABLED
2012-01-25 13:28:01 us=501279 cf_max = 0
2012-01-25 13:28:01 us=501290 cf_per = 0
2012-01-25 13:28:01 us=501301 max_clients = 1024
2012-01-25 13:28:01 us=501313 max_routes_per_client = 256
2012-01-25 13:28:01 us=501325 auth_user_pass_verify_script =
'[UNDEF]'
2012-01-25 13:28:01 us=501336 auth_user_pass_verify_script_via_file
= DISABLED
2012-01-25 13:28:01 us=501348 ssl_flags = 0
2012-01-25 13:28:01 us=501360 port_share_host = '[UNDEF]'
2012-01-25 13:28:01 us=501371 port_share_port = 0
2012-01-25 13:28:01 us=501383 client = ENABLED
2012-01-25 13:28:01 us=501394 pull = ENABLED
2012-01-25 13:28:01 us=501406 auth_user_pass_file = '[UNDEF]'
2012-01-25 13:28:01 us=501423 OpenVPN 2.2.1 i386-apple-darwin10.8.0
[SSL] [LZO2] [PKCS11] [eurephia] built on Jan 8 2012
2012-01-25 13:28:01 us=501565 MANAGEMENT: TCP Socket listening on
127.0.0.1:1337
2012-01-25 13:28:01 us=502290 Need hold release from management
interface, waiting...
2012-01-25 13:28:01 us=568076 MANAGEMENT: Client connected from
127.0.0.1:1337
2012-01-25 13:28:01 us=578578 MANAGEMENT: CMD 'pid'
2012-01-25 13:28:01 us=578698 MANAGEMENT: CMD 'state on'
2012-01-25 13:28:01 us=578792 MANAGEMENT: CMD 'state'
2012-01-25 13:28:01 us=578931 MANAGEMENT: CMD 'hold release'
2012-01-25 13:28:01 us=579262 WARNING: No server certificate
verification method has been enabled. See
http://openvpn.net/howto.html#mitm
for more info.
2012-01-25 13:28:01 us=579282 NOTE: the current --script-security
setting may allow this configuration to call user-defined scripts
2012-01-25 13:28:01 us=588274 WARNING: file 'client1.key' is group or
others accessible
2012-01-25 13:28:01 us=589115 LZO compression initialized
2012-01-25 13:28:01 us=589269 Control Channel MTU parms [ L:1576 D:140
EF:40 EB:0 ET:0 EL:0 ]
2012-01-25 13:28:01 us=589372 Socket Buffers: R=[262140->65536]
S=[131070->65536]
2012-01-25 13:28:01 us=589394 Data Channel MTU parms [ L:1576 D:1450
EF:44 EB:135 ET:32 EL:0 AF:3/1 ]
2012-01-25 13:28:01 us=589435 Local Options String: 'V4,dev-type
tap,link-mtu 1576,tun-mtu 1532,proto TCPv4_CLIENT,comp-lzo,cipher BF-
CBC,auth SHA1,keysize 128,key-method 2,tls-client'
2012-01-25 13:28:01 us=589448 Expected Remote Options String: 'V4,dev-
type tap,link-mtu 1576,tun-mtu 1532,proto TCPv4_SERVER,comp-lzo,cipher
BF-CBC,auth SHA1,keysize 128,key-method 2,tls-server'
2012-01-25 13:28:01 us=589475 Local Options hash (VER=V4): '31fdf004'
2012-01-25 13:28:01 us=589493 Expected Remote Options hash (VER=V4):
'3e6d1056'
2012-01-25 13:28:01 us=589533 Attempting to establish TCP connection
with 77.20.123.xxx:9010 [nonblock]
2012-01-25 13:28:01 us=589588 MANAGEMENT: >STATE:
1327494481,TCP_CONNECT,,,
2012-01-25 13:28:01 *Tunnelblick: Established communication with
OpenVPN
2012-01-25 13:28:02 us=590393 TCP connection established with
77.20.123.xxx:9010
2012-01-25 13:28:02 us=590504 TCPv4_CLIENT link local: [undef]
2012-01-25 13:28:02 us=590538 TCPv4_CLIENT link remote: 77.20.123.xxx:
9010
2012-01-25 13:28:02 us=590618 MANAGEMENT: >STATE:1327494482,WAIT,,,
2012-01-25 13:28:02 us=610722 MANAGEMENT: >STATE:1327494482,AUTH,,,
2012-01-25 13:28:02 us=610798 TLS: Initial packet from 77.20.123.xxx:
9010, sid=0ea52f1d 8fa08a56
2012-01-25 13:28:02 us=998254 VERIFY OK: depth=1, /C=DE/ST=NS/
L=GOETTINGEN/O=SEQLAB/OU=IT-Department/CN=cruncher/
emailAddress=
a...@seqlab.de
2012-01-25 13:28:02 us=998564 VERIFY OK: depth=0, /C=DE/ST=NS/O=SEQLAB/
OU=IT-Department/CN=cruncher/emailAddress=
a...@seqlab.de
2012-01-25 13:28:03 us=631867 Data Channel Encrypt: Cipher 'BF-CBC'
initialized with 128 bit key
2012-01-25 13:28:03 us=631925 Data Channel Encrypt: Using 160 bit
message hash 'SHA1' for HMAC authentication
2012-01-25 13:28:03 us=632007 Data Channel Decrypt: Cipher 'BF-CBC'
initialized with 128 bit key
2012-01-25 13:28:03 us=632024 Data Channel Decrypt: Using 160 bit
message hash 'SHA1' for HMAC authentication
2012-01-25 13:28:03 us=632171 Control Channel: TLSv1, cipher TLSv1/
SSLv3 DHE-RSA-AES256-SHA, 1024 bit RSA
2012-01-25 13:28:03 us=632209 [cruncher] Peer Connection Initiated
with 77.20.123.xxx:9010
2012-01-25 13:28:04 us=869605 MANAGEMENT: >STATE:
1327494484,GET_CONFIG,,,
2012-01-25 13:28:06 us=107189 SENT CONTROL [cruncher]:
'PUSH_REQUEST' (status=1)
2012-01-25 13:28:06 us=150895 PUSH: Received control message:
'PUSH_REPLY,redirect-gateway,route-gateway dhcp,ping 10,ping-restart
120'
2012-01-25 13:28:06 us=151018 OPTIONS IMPORT: timers and/or timeouts
modified
2012-01-25 13:28:06 us=151061 OPTIONS IMPORT: route options modified
2012-01-25 13:28:06 us=151074 OPTIONS IMPORT: route-related options
modified
2012-01-25 13:28:06 us=151186 ROUTE default_gateway=192.168.178.1
2012-01-25 13:28:06 us=152351 TUN/TAP device /dev/tap0 opened
2012-01-25 13:28:06 us=152824 /sbin/ifconfig tap0 lladdr
00:03:93:57:57:57
2012-01-25 13:28:06 us=157671 TUN/TAP link layer address set to
00:03:93:57:57:57
2012-01-25 13:28:06 us=157810 /Applications/Tunnelblick.app/Contents/
Resources/
client.up.tunnelblick.sh -m -w -d -a -atDASNGWrdasngw tap0
1500 1576 init
2012-01-25 13:28:08 us=928758 NOTE: unable to redirect default gateway
-- VPN gateway parameter (--route-gateway or --ifconfig) is missing
2012-01-25 13:28:08 us=928843 Initialization Sequence Completed
2012-01-25 13:28:08 us=928866 MANAGEMENT: >STATE:
1327494488,CONNECTED,SUCCESS,,77.20.123.xxx
2012-01-25 13:28:09 *Tunnelblick: Flushed the DNS cache
2012-01-25 13:28:11 *Tunnelblick
client.up.tunnelblick.sh: Sleeping
for 0 seconds to wait for DHCP to finish setup.
2012-01-25 13:28:11 *Tunnelblick
client.up.tunnelblick.sh: Sleeping
for 1 seconds to wait for DHCP to finish setup.
2012-01-25 13:28:13 *Tunnelblick
client.up.tunnelblick.sh: Sleeping
for 2 seconds to wait for DHCP to finish setup.
2012-01-25 13:28:15 *Tunnelblick
client.up.tunnelblick.sh: Sleeping
for 3 seconds to wait for DHCP to finish setup.
2012-01-25 13:28:18 *Tunnelblick
client.up.tunnelblick.sh: Sleeping
for 4 seconds to wait for DHCP to finish setup.
#########################################################################################
I hope this is not too much of info. Did I miss anything in the
configs? Would you say the problem is on the server or on the client
side?
Thanks, Lupus