Showing posts with label OpenVPN. Show all posts
Showing posts with label OpenVPN. Show all posts

Tuesday, 10 February 2015

Openvpn client source address on lan topic






I'm wanting my openvpn clients to keep their virtual IP address assigned by the openvpn server when connecting to other resources over the LAN on the openvpn server's network (As well as the internet via the openvpn server's network, the router should see the virtual address as the source address so I can handle the traffic separately from other LAN devices (force an different ext address))

Currently when doing this the other devices on the LAN report the openvpn server's address instead of the virtual address they're assigned.

I.E.


Code:


Server 172.19.195.18
Client 172.19.197.6
FTP 172.19.195.13


If I'm connected to openvpn as the client (172.19.197.6) and I make a connection to the FTP @ 172.19.195.13 it says I'm connecting from 172.19.195.18(Openvpn Server) I want the client to keep it's address ( 172.19.197.6, and I want the FTP server/device to report the client is connecting from there rather then the Openvpn server).

I've looked into Routed Lans,
And attempted integrating this but it doesn't seem to help in my situation.

Any advice/direction or help would be greatly appreciated,
So far I know that the directive "push redirect-gateway def1" should probably be removed and I should not be using NAT via iptables to handle the traffic or at least this is what I think from what I've read now.


server configuration

Code:


dev tun
proto tcp-server
port 1095

ca /etc/openvpn/ca.crt
cert /etc/openvpn/server.crt
key /etc/openvpn/server.key
dh /etc/openvpn/dh1024.pem
tls-auth /etc/openvpn/ta.key 0

client-cert-not-required
username-as-common-name

server 172.19.197.0 255.255.255.0

client-to-client
client-config-dir /etc/openvpn/ccd/


route 172.19.197.0 255.255.255.0
push "route 172.19.197.0 255.255.255.0"
push "dhcp-option DNS 8.8.8.8"
push "dhcp-option DNS 8.8.4.4"

push "redirect-gateway def1"

log-append /var/log/openvpn/server.log
tmp-dir /tmp

plugin /usr/local/lib/openvpn/openvpn-otp.so


client configuration

Code:


remote XXX 1095
ca [inline]
tls-auth [inline] 1

client
dev tun
tls-client
proto tcp-client
route-method exe
route-delay 2
resolv-retry infinite
nobind
persist-key
persist-tun
auth-user-pass
auth-nocache
reneg-sec 0
verb 3


ccd configuration

Code:


iroute 172.19.197.0 255.255.255.0







Saturday, 7 February 2015

Bridged OpenVPN Connection-how to create secure vpn connection with Ubuntu 14 topic






Looking at my syslogs on the client and server, it appears they are connecting on openvpn -restart. But I am unable to figure out how to make a secure VPN Connection. I am trying to use the Connection Manager, but it times out. I am not even sure you can connect that way, but that is what I have tried (VPN Connections -> Configure VPN).


My server log looks like:
eb 7 11:56:54 a9000 ovpn-server[1390]: XX.99.XXX.54:60771 Data Channel Encrypt: Cipher 'BF-CBC' initialized with 128 bit key
Feb 7 11:56:54 a9000 ovpn-server[1390]: XX.99.XXX.54:60771 Data Channel Encrypt: Using 160 bit message hash 'SHA1' for HMAC authentication
Feb 7 11:56:54 a9000 ovpn-server[1390]: XX.99.XXX.54:60771 Data Channel Decrypt: Cipher 'BF-CBC' initialized with 128 bit key
Feb 7 11:56:54 a9000 ovpn-server[1390]: XX.99.XXX.54:60771 Data Channel Decrypt: Using 160 bit message hash 'SHA1' for HMAC authentication
Feb 7 11:56:54 a9000 ovpn-server[1390]: XX.99.XXX.54:60771 Control Channel: TLSv1, cipher TLSv1/SSLv3 DHE-RSA-AES256-SHA, 2048 bit RSA
Feb 7 11:56:54 a9000 ovpn-server[1390]: XX.99.XXX.54:60771 [client] Peer Connection Initiated with [AF_INET]XX.99.XXX.54:60771
Feb 7 11:56:54 a9000 ovpn-server[1390]: MULTI: new connection by client 'client' will cause previous active sessions by this client to be dropped. Remember to use the --duplicate-cn option if you want multiple clients using the same certificate or username to concurrently connect.
Feb 7 11:56:54 a9000 ovpn-server[1390]: MULTI_sva: pool returned IPv4=192.168.1.100, IPv6=(Not enabled)
Feb 7 11:56:56 a9000 ovpn-server[1390]: client/XX.99.XXX.54:60771 PUSH: Received control message: 'PUSH_REQUEST'
Feb 7 11:56:56 a9000 ovpn-server[1390]: client/XX.99.XXX.54:60771 send_push_reply(): safe_cap=940
Feb 7 11:56:56 a9000 ovpn-server[1390]: client/XX.99.XXX.54:60771 SENT CONTROL [client]: 'PUSH_REPLY,route-gateway 192.168.1.107,ping 10,ping-restart 120,ifconfig 192.168.1.100 255.255.255.0' (status=1)
Feb 7 11:57:04 a9000 ovpn-server[1390]: client/XX.99.XXX.54:60771 MULTI: Learn: 9a:51:db:08:a6:e2 -> client/XX.99.XXX.54:60771


and the client looks like:
Feb 7 11:57:44 K55A nm-openvpn[6161]: Control Channel Authentication: using '/etc/openvpn/ta.key' as a OpenVPN static key file
Feb 7 11:57:44 K55A nm-openvpn[6161]: UDPv4 link local: [undef]
Feb 7 11:57:44 K55A nm-openvpn[6161]: UDPv4 link remote: [AF_INET]192.168.1.100:1194
Feb 7 11:58:24 K55A NetworkManager[1189]: <warn> VPN connection 'VPN connection 1' (IP Config Get) timeout exceeded.
Feb 7 11:58:24 K55A nm-openvpn[6161]: SIGTERM[hard,] received, process exiting
Feb 7 11:58:29 K55A NetworkManager[1189]: <info> VPN service 'openvpn' disappeared
Feb 7 12:03:53 K55A NetworkManager[1189]: <info> Starting VPN service 'openvpn'...
Feb 7 12:03:53 K55A NetworkManager[1189]: <info> VPN service 'openvpn' started (org.freedesktop.NetworkManager.openvpn), PID 6207
Feb 7 12:03:53 K55A NetworkManager[1189]: <info> VPN service 'openvpn' appeared; activating connections
Feb 7 12:03:53 K55A NetworkManager[1189]: <info> VPN plugin state changed: starting (3)
Feb 7 12:03:53 K55A NetworkManager[1189]: <info> VPN connection 'VPN connection 1' (Connect) reply received.
Feb 7 12:03:53 K55A nm-openvpn[6210]: OpenVPN 2.3.2 x86_64-pc-linux-gnu [SSL (OpenSSL)] [LZO] [EPOLL] [PKCS11] [eurephia] [MH] [IPv6] built on Dec 1 2014
Feb 7 12:03:53 K55A nm-openvpn[6210]: WARNING: No server certificate verification method has been enabled. See http://openvpn.net/howto.html#mitm for more info.
Feb 7 12:03:53 K55A nm-openvpn[6210]: NOTE: the current --script-security setting may allow this configuration to call user-defined scripts
Feb 7 12:03:53 K55A nm-openvpn[6210]: WARNING: file '/etc/openvpn/client.key' is group or others accessible
Feb 7 12:03:53 K55A nm-openvpn[6210]: WARNING: file '/etc/openvpn/ta.key' is group or others accessible
Feb 7 12:03:53 K55A nm-openvpn[6210]: Control Channel Authentication: using '/etc/openvpn/ta.key' as a OpenVPN static key file
Feb 7 12:03:53 K55A nm-openvpn[6210]: UDPv4 link local: [undef]
Feb 7 12:03:53 K55A nm-openvpn[6210]: UDPv4 link remote: [AF_INET]192.168.1.254:1194




Any help is appreciated!






Wednesday, 4 February 2015

Ubuntu 14.04 and Bridging for OpenVPN topic






I am trying to set up bridging for OpenVPN. I have searched high and low for a solutions, but keep finding conflicting solutions.


Any help setting up a new interfaces file is appreciated! Thanks in advance!


Suppose /etc/network/interfaces contains:


# interfaces(5) file used by ifup(8) and ifdown(8)
auto lo


And ifconfig returns:


eth0 Link encap:Ethernet HWaddr 09:00:12:90:e3:e5
inet addr:192.168.1.29 Bcast:192.168.1.255 Mask:255.255.255.0
inet6 addr: fe80::a00:27ff:fe70:e3f5/64 Scope:Link
UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1
RX packets:54071 errors:1 dropped:0 overruns:0 frame:0
TX packets:48515 errors:0 dropped:0 overruns:0 carrier:0
collisions:0 txqueuelen:1000
RX bytes:22009423 (20.9 MiB) TX bytes:25690847 (24.5 MiB)
Interrupt:10 Base address:0xd020


lo Link encap:Local Loopback
inet addr:127.0.0.1 Mask:255.0.0.0
inet6 addr: ::1/128 Scope:Host
UP LOOPBACK RUNNING MTU:16436 Metric:1
RX packets:83 errors:0 dropped:0 overruns:0 frame:0
TX packets:83 errors:0 dropped:0 overruns:0 carrier:0
collisions:0 txqueuelen:0
RX bytes:7766 (7.5 KiB) TX bytes:7766 (7.5 KiB)




Then what should the new /etc/network/interfaces contain?