Re: OpenVPN ne Red Hat
Flakob <[email protected]>
| Newsgroups | gmane.org.user-groups.linux.gulcr |
|---|---|
| Message-ID | <[email protected]> |
Hola buenas tardes. En este momento lo estoy levantando como lo sugirió Alberto, como Bridge, cuando inicio todo va bien, pero cuando trato de conectar tengo conexión rechazada. Ahora el problema parace ser con los certificados, "creo". Las pruebas las estoy desde una maquina local, me corrigen por favor si esto es errado hacerlo. Gracias por la ayuda. Este es el log de mi servidor: ******************* Mon Feb 6 15:58:27 2006 TUN/TAP device tap0 opened Mon Feb 6 15:58:27 2006 Data Channel MTU parms [ L:1574 D:1450 EF:42 EB:135 ET:32 EL:0 AF:3/1 ] Mon Feb 6 15:58:27 2006 GID set to nobody Mon Feb 6 15:58:27 2006 UID set to nobody Mon Feb 6 15:58:27 2006 UDPv4 link local (bound): [undef]:1194 Mon Feb 6 15:58:27 2006 UDPv4 link remote: [undef] Mon Feb 6 15:58:27 2006 MULTI: multi_init called, r=256 v=256 Mon Feb 6 15:58:27 2006 IFCONFIG POOL: base=10.10.2.205 size=6 Mon Feb 6 15:58:27 2006 IFCONFIG POOL LIST Mon Feb 6 15:58:27 2006 Initialization Sequence Completed Mon Feb 6 15:58:43 2006 MULTI: multi_create_instance called Mon Feb 6 15:58:43 2006 10.10.2.50:1194 Re-using SSL/TLS context Mon Feb 6 15:58:43 2006 10.10.2.50:1194 LZO compression initialized Mon Feb 6 15:58:43 2006 10.10.2.50:1194 Control Channel MTU parms [ L:1574 D:138 EF:38 EB:0 ET:0 EL:0 ] Mon Feb 6 15:58:43 2006 10.10.2.50:1194 Data Channel MTU parms [ L:1574 D:1450 EF:42 EB:135 ET:32 EL:0 AF:3/1 ] Mon Feb 6 15:58:43 2006 10.10.2.50:1194 Local Options hash (VER=V4): 'f7df56b8' Mon Feb 6 15:58:43 2006 10.10.2.50:1194 Expected Remote Options hash (VER=V4): 'd79ca330' Mon Feb 6 15:58:43 2006 10.10.2.50:1194 TLS: Initial packet from 10.10.2.201:1194, sid=08b68026 9226d5a8 Mon Feb 6 15:58:45 2006 read UDPv4 [ECONNREFUSED|ECONNREFUSED|ECONNREFUSED|ECONNREFUSED]: Connection refused (code=111) Mon Feb 6 15:58:45 2006 10.10.2.50:1194 TLS: new session incoming connection from 10.10.2.50:1194 Mon Feb 6 15:58:47 2006 10.10.2.50:1194 write UDPv4 [ECONNREFUSED|ECONNREFUSED|ECONNREFUSED|ECONNREFUSED]: Connection refused (code=111) *********************** Y este el log del cliente: ************************** Mon Feb 06 15:59:45 2006 OpenVPN 2.0.5 Win32-MinGW [SSL] [LZO] built on Nov 2 2005 Mon Feb 06 15:59:45 2006 WARNING: No server certificate verification method has been enabled. See http://openvpn.net/howto.html#mitm for more info. Mon Feb 06 15:59:45 2006 UDPv4 link local (bound): [undef]:1194 Mon Feb 06 15:59:45 2006 UDPv4 link remote: 10.10.2.202:1194 Mon Feb 06 15:59:45 2006 VERIFY ERROR: depth=0, error=unable to get local issuer certificate: /C=CO/ST=Antioquia/O=MiEmpresa/OU=Area/CN=Empresa/[email protected] Mon Feb 06 15:59:45 2006 TLS_ERROR: BIO read tls_read_plaintext error: error:14090086:SSL routines:SSL3_GET_SERVER_CERTIFICATE:certificate verify failed Mon Feb 06 15:59:45 2006 TLS Error: TLS object -> incoming plaintext read error Mon Feb 06 15:59:45 2006 TLS Error: TLS handshake failed Mon Feb 06 15:59:45 2006 SIGUSR1[soft,tls-error] received, process restarting Mon Feb 06 15:59:47 2006 WARNING: No server certificate verification method has been enabled. See http://openvpn.net/howto.html#mitm for more info. Mon Feb 06 15:59:47 2006 UDPv4 link local (bound): [undef]:1194 Mon Feb 06 15:59:47 2006 UDPv4 link remote: 10.10.2.50:1194 Mon Feb 06 15:59:47 2006 VERIFY ERROR: depth=0, error=unable to get local issuer certificate: /C=CO/ST=Antioquia/O=Mi Empresa/OU=Area/CN=Empresa/[email protected] Mon Feb 06 15:59:47 2006 TLS_ERROR: BIO read tls_read_plaintext error: error:14090086:SSL routines:SSL3_GET_SERVER_CERTIFICATE:certificate verify failed Mon Feb 06 15:59:47 2006 TLS Error: TLS object -> incoming plaintext read error Mon Feb 06 15:59:47 2006 TLS Error: TLS handshake failed Mon Feb 06 15:59:47 2006 SIGUSR1[soft,tls-error] received, process restarting Mon Feb 06 15:59:49 2006 WARNING: No server certificate verification method has been enabled. See http://openvpn.net/howto.html#mitm for more info. Mon Feb 06 15:59:49 2006 UDPv4 link local (bound): [undef]:1194 Mon Feb 06 15:59:49 2006 UDPv4 link remote: 10.10.2.50:1194 Mon Feb 06 15:59:49 2006 TLS Error: Unroutable control packet received from 10.10.2.202:1194 (si=3 op=P_ACK_V1) Mon Feb 06 15:59:51 2006 TLS Error: Unroutable control packet received from 10.10.2.202:1194 (si=3 op=P_CONTROL_V1) Mon Feb 06 15:59:51 2006 TLS Error: Unroutable control packet received from 10.10.2.202:1194 (si=3 op=P_CONTROL_V1) Mon Feb 06 15:59:51 2006 TLS Error: Unroutable control packet received from 10.10.2.202:1194 (si=3 op=P_CONTROL_V1) ****************** El día 6/02/06, Elias Torres Arroyo <[email protected]> escribió: > > El Thu, Feb 02, 2006 at 11:16:38AM -0600, Alberto Brealey Guzmán escribió: > > Flakob escribió: > > > servicios internos como accesar a directorios en maquinas windows y > cosas > > > como esas. > > > > Ok, lo más fácil entonces es que configure el VPN 'bridged', así las > > máquinas remotas quedarían en la misma LAN y podrían ver los directorios > > compartidos de Windows. Las razones están en [0] y de ahí hay un enlace > > O sino que el servidor de OpenVPN corra Samba como servidor WINS, y > configurarlo ya sea en cada cliente o en la configuración de OpenVPN > tener > > push "dhcp-option WINS ip-del-wins-server" > > si el servidor wins no es el servidor de OpenVPN, se debe tener cuidado > de que los clientes puedan accesar ese ip, si este está en una red > aparte pero accesible por el servidor de OpenVPN, por ejemplo, > 192.168.99.0/24 puede poner el el archivo de configuración de OpenVPN: > > push "dhcp-option WINS 192.168.99.1" > push "route 192.168.99.0 255.255.255.0" > > Saludos, > -- > Elías Torres Arroyo > > > -- > Desuscripción: escriba a [email protected], tema > 'unsubscribe' > Problemas a: [email protected]. > http://gulcr.org/ListasDeCorreo > > -- Flakob.