Re: OpenVPN ne Red Hat

Flakob <[email protected]>
Newsgroups gmane.org.user-groups.linux.gulcr
Message-ID <[email protected]>
Hola buenas tardes.

En este momento lo estoy levantando como lo sugirió Alberto, como Bridge,
cuando inicio todo va bien, pero cuando trato de conectar tengo conexión
rechazada.

Ahora el problema parace ser con los certificados, "creo".

Las pruebas las estoy desde una maquina local, me corrigen por favor si esto
es errado hacerlo.

Gracias por la ayuda.


Este es el log de mi servidor:

*******************
Mon Feb  6 15:58:27 2006 TUN/TAP device tap0 opened
Mon Feb  6 15:58:27 2006 Data Channel MTU parms [ L:1574 D:1450 EF:42 EB:135
ET:32 EL:0 AF:3/1 ]
Mon Feb  6 15:58:27 2006 GID set to nobody
Mon Feb  6 15:58:27 2006 UID set to nobody
Mon Feb  6 15:58:27 2006 UDPv4 link local (bound): [undef]:1194
Mon Feb  6 15:58:27 2006 UDPv4 link remote: [undef]
Mon Feb  6 15:58:27 2006 MULTI: multi_init called, r=256 v=256
Mon Feb  6 15:58:27 2006 IFCONFIG POOL: base=10.10.2.205 size=6
Mon Feb  6 15:58:27 2006 IFCONFIG POOL LIST
Mon Feb  6 15:58:27 2006 Initialization Sequence Completed
Mon Feb  6 15:58:43 2006 MULTI: multi_create_instance called
Mon Feb  6 15:58:43 2006 10.10.2.50:1194 Re-using SSL/TLS context
Mon Feb  6 15:58:43 2006 10.10.2.50:1194 LZO compression initialized
Mon Feb  6 15:58:43 2006 10.10.2.50:1194 Control Channel MTU parms [ L:1574
D:138 EF:38 EB:0 ET:0 EL:0 ]
Mon Feb  6 15:58:43 2006 10.10.2.50:1194 Data Channel MTU parms [ L:1574
D:1450 EF:42 EB:135 ET:32 EL:0 AF:3/1 ]
Mon Feb  6 15:58:43 2006 10.10.2.50:1194 Local Options hash (VER=V4):
'f7df56b8'
Mon Feb  6 15:58:43 2006 10.10.2.50:1194 Expected Remote Options hash
(VER=V4): 'd79ca330'
Mon Feb  6 15:58:43 2006 10.10.2.50:1194 TLS: Initial packet from
10.10.2.201:1194, sid=08b68026 9226d5a8
Mon Feb  6 15:58:45 2006 read UDPv4
[ECONNREFUSED|ECONNREFUSED|ECONNREFUSED|ECONNREFUSED]: Connection refused
(code=111)
Mon Feb  6 15:58:45 2006 10.10.2.50:1194 TLS: new session incoming
connection from 10.10.2.50:1194
Mon Feb  6 15:58:47 2006 10.10.2.50:1194 write UDPv4
[ECONNREFUSED|ECONNREFUSED|ECONNREFUSED|ECONNREFUSED]: Connection refused
(code=111)
***********************

Y este el log del cliente:


**************************
Mon Feb 06 15:59:45 2006 OpenVPN 2.0.5 Win32-MinGW [SSL] [LZO] built on Nov
2 2005
Mon Feb 06 15:59:45 2006 WARNING: No server certificate verification method
has been enabled.  See http://openvpn.net/howto.html#mitm for more info.
Mon Feb 06 15:59:45 2006 UDPv4 link local (bound): [undef]:1194
Mon Feb 06 15:59:45 2006 UDPv4 link remote: 10.10.2.202:1194
Mon Feb 06 15:59:45 2006 VERIFY ERROR: depth=0, error=unable to get local
issuer certificate:
/C=CO/ST=Antioquia/O=MiEmpresa/OU=Area/CN=Empresa/[email protected]
Mon Feb 06 15:59:45 2006 TLS_ERROR: BIO read tls_read_plaintext error:
error:14090086:SSL routines:SSL3_GET_SERVER_CERTIFICATE:certificate verify
failed
Mon Feb 06 15:59:45 2006 TLS Error: TLS object -> incoming plaintext read
error
Mon Feb 06 15:59:45 2006 TLS Error: TLS handshake failed
Mon Feb 06 15:59:45 2006 SIGUSR1[soft,tls-error] received, process
restarting
Mon Feb 06 15:59:47 2006 WARNING: No server certificate verification method
has been enabled.  See http://openvpn.net/howto.html#mitm for more info.
Mon Feb 06 15:59:47 2006 UDPv4 link local (bound): [undef]:1194
Mon Feb 06 15:59:47 2006 UDPv4 link remote: 10.10.2.50:1194
Mon Feb 06 15:59:47 2006 VERIFY ERROR: depth=0, error=unable to get local
issuer certificate: /C=CO/ST=Antioquia/O=Mi
Empresa/OU=Area/CN=Empresa/[email protected]
Mon Feb 06 15:59:47 2006 TLS_ERROR: BIO read tls_read_plaintext error:
error:14090086:SSL routines:SSL3_GET_SERVER_CERTIFICATE:certificate verify
failed
Mon Feb 06 15:59:47 2006 TLS Error: TLS object -> incoming plaintext read
error
Mon Feb 06 15:59:47 2006 TLS Error: TLS handshake failed
Mon Feb 06 15:59:47 2006 SIGUSR1[soft,tls-error] received, process
restarting
Mon Feb 06 15:59:49 2006 WARNING: No server certificate verification method
has been enabled.  See http://openvpn.net/howto.html#mitm for more info.
Mon Feb 06 15:59:49 2006 UDPv4 link local (bound): [undef]:1194
Mon Feb 06 15:59:49 2006 UDPv4 link remote: 10.10.2.50:1194
Mon Feb 06 15:59:49 2006 TLS Error: Unroutable control packet received from
10.10.2.202:1194 (si=3 op=P_ACK_V1)
Mon Feb 06 15:59:51 2006 TLS Error: Unroutable control packet received from
10.10.2.202:1194 (si=3 op=P_CONTROL_V1)
Mon Feb 06 15:59:51 2006 TLS Error: Unroutable control packet received from
10.10.2.202:1194 (si=3 op=P_CONTROL_V1)
Mon Feb 06 15:59:51 2006 TLS Error: Unroutable control packet received from
10.10.2.202:1194 (si=3 op=P_CONTROL_V1)

******************

El día 6/02/06, Elias Torres Arroyo <[email protected]> escribió:
>
> El Thu, Feb 02, 2006 at 11:16:38AM -0600, Alberto Brealey Guzmán escribió:
> > Flakob escribió:
> > > servicios internos como accesar a directorios en maquinas windows y
> cosas
> > > como esas.
> >
> > Ok, lo más fácil entonces es que configure el VPN 'bridged', así las
> > máquinas remotas quedarían en la misma LAN y podrían ver los directorios
> > compartidos de Windows. Las razones están en [0] y de ahí hay un enlace
>
> O sino que el servidor de OpenVPN corra Samba como servidor WINS, y
> configurarlo ya sea en cada cliente o en la configuración de OpenVPN
> tener
>
> push "dhcp-option WINS ip-del-wins-server"
>
> si el servidor wins no es el servidor de OpenVPN, se debe tener cuidado
> de que los clientes puedan accesar ese ip, si este está en una red
> aparte pero accesible por el servidor de OpenVPN, por ejemplo,
> 192.168.99.0/24 puede poner el el archivo de configuración de OpenVPN:
>
> push "dhcp-option WINS 192.168.99.1"
> push "route 192.168.99.0 255.255.255.0"
>
> Saludos,
> --
> Elías Torres Arroyo
>
>
> --
> Desuscripción: escriba a [email protected], tema
> 'unsubscribe'
> Problemas a: [email protected].
> http://gulcr.org/ListasDeCorreo
>
>


--

Flakob.
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.