[OPENVPN] Serv-Debian e Client-Windows: Não consigo estabelecer conexão fora da rede

1. [OPENVPN] Serv-Debian e Client-Windows: Não consigo estabelecer conexão fora da rede

Rodrigo Rodrigues
DrigoRJ

(usa Ubuntu)

Enviado em 07/10/2015 - 18:02h

Pessoal, boa noite!
Tentei, com um amigo, configurar uma conexão VPN num servidor Debian com clientes Windows, através do OpenVPN. Segui as instruções de 2 lugares:
http://sejalivre.org/configurando-openvpn-entre-maquinas-linux-e-windows/
https://www.youtube.com/watch?v=oAH5FUokOZc

Consegui realizar toda a configuração, quando vou conectar o OpenVPN estando na mesma rede do servidor, consigo realizar a conexão.
Porém quando saio da rede, não consigo. Não tenho o log no momento mas lembro que ficava no status WAIT e depois dava um erro relacionado a TLS key.

Alguém tem ideia do que pode ser? Mais tarde eu adiciono o log aqui para ficar mais fácil.


  


2. Log

Rodrigo Rodrigues
DrigoRJ

(usa Ubuntu)

Enviado em 08/10/2015 - 13:10h

Esse é o log

Sat Sep 26 16:07:00 2015 pkcs11_protected_authentication = DISABLED
Sat Sep 26 16:07:00 2015 pkcs11_protected_authentication = DISABLED
Sat Sep 26 16:07:00 2015 pkcs11_protected_authentication = DISABLED
Sat Sep 26 16:07:00 2015 pkcs11_protected_authentication = DISABLED
Sat Sep 26 16:07:00 2015 pkcs11_private_mode = 00000000
Sat Sep 26 16:07:00 2015 pkcs11_private_mode = 00000000
Sat Sep 26 16:07:00 2015 pkcs11_private_mode = 00000000
Sat Sep 26 16:07:00 2015 pkcs11_private_mode = 00000000
Sat Sep 26 16:07:00 2015 pkcs11_private_mode = 00000000
Sat Sep 26 16:07:00 2015 pkcs11_private_mode = 00000000
Sat Sep 26 16:07:00 2015 pkcs11_private_mode = 00000000
Sat Sep 26 16:07:00 2015 pkcs11_private_mode = 00000000
Sat Sep 26 16:07:00 2015 pkcs11_private_mode = 00000000
Sat Sep 26 16:07:00 2015 pkcs11_private_mode = 00000000
Sat Sep 26 16:07:00 2015 pkcs11_private_mode = 00000000
Sat Sep 26 16:07:00 2015 pkcs11_private_mode = 00000000
Sat Sep 26 16:07:00 2015 pkcs11_private_mode = 00000000
Sat Sep 26 16:07:00 2015 pkcs11_private_mode = 00000000
Sat Sep 26 16:07:00 2015 pkcs11_private_mode = 00000000
Sat Sep 26 16:07:00 2015 pkcs11_private_mode = 00000000
Sat Sep 26 16:07:00 2015 pkcs11_cert_private = DISABLED
Sat Sep 26 16:07:00 2015 pkcs11_cert_private = DISABLED
Sat Sep 26 16:07:00 2015 pkcs11_cert_private = DISABLED
Sat Sep 26 16:07:00 2015 pkcs11_cert_private = DISABLED
Sat Sep 26 16:07:00 2015 pkcs11_cert_private = DISABLED
Sat Sep 26 16:07:00 2015 pkcs11_cert_private = DISABLED
Sat Sep 26 16:07:00 2015 pkcs11_cert_private = DISABLED
Sat Sep 26 16:07:00 2015 pkcs11_cert_private = DISABLED
Sat Sep 26 16:07:00 2015 pkcs11_cert_private = DISABLED
Sat Sep 26 16:07:00 2015 pkcs11_cert_private = DISABLED
Sat Sep 26 16:07:00 2015 pkcs11_cert_private = DISABLED
Sat Sep 26 16:07:00 2015 pkcs11_cert_private = DISABLED
Sat Sep 26 16:07:00 2015 pkcs11_cert_private = DISABLED
Sat Sep 26 16:07:00 2015 pkcs11_cert_private = DISABLED
Sat Sep 26 16:07:00 2015 pkcs11_cert_private = DISABLED
Sat Sep 26 16:07:00 2015 pkcs11_cert_private = DISABLED
Sat Sep 26 16:07:00 2015 pkcs11_pin_cache_period = -1
Sat Sep 26 16:07:00 2015 pkcs11_id = '[UNDEF]'
Sat Sep 26 16:07:00 2015 pkcs11_id_management = DISABLED
Sat Sep 26 16:07:00 2015 server_network = 0.0.0.0
Sat Sep 26 16:07:00 2015 server_netmask = 0.0.0.0
Sat Sep 26 16:07:00 2015 server_network_ipv6 = ::
Sat Sep 26 16:07:00 2015 server_netbits_ipv6 = 0
Sat Sep 26 16:07:00 2015 server_bridge_ip = 0.0.0.0
Sat Sep 26 16:07:00 2015 server_bridge_netmask = 0.0.0.0
Sat Sep 26 16:07:00 2015 server_bridge_pool_start = 0.0.0.0
Sat Sep 26 16:07:00 2015 server_bridge_pool_end = 0.0.0.0
Sat Sep 26 16:07:00 2015 ifconfig_pool_defined = DISABLED
Sat Sep 26 16:07:00 2015 ifconfig_pool_start = 0.0.0.0
Sat Sep 26 16:07:00 2015 ifconfig_pool_end = 0.0.0.0
Sat Sep 26 16:07:00 2015 ifconfig_pool_netmask = 0.0.0.0
Sat Sep 26 16:07:00 2015 ifconfig_pool_persist_filename = '[UNDEF]'
Sat Sep 26 16:07:00 2015 ifconfig_pool_persist_refresh_freq = 600
Sat Sep 26 16:07:00 2015 ifconfig_ipv6_pool_defined = DISABLED
Sat Sep 26 16:07:00 2015 ifconfig_ipv6_pool_base = ::
Sat Sep 26 16:07:00 2015 ifconfig_ipv6_pool_netbits = 0
Sat Sep 26 16:07:00 2015 n_bcast_buf = 256
Sat Sep 26 16:07:00 2015 tcp_queue_limit = 64
Sat Sep 26 16:07:00 2015 real_hash_size = 256
Sat Sep 26 16:07:00 2015 virtual_hash_size = 256
Sat Sep 26 16:07:00 2015 client_connect_script = '[UNDEF]'
Sat Sep 26 16:07:00 2015 learn_address_script = '[UNDEF]'
Sat Sep 26 16:07:00 2015 client_disconnect_script = '[UNDEF]'
Sat Sep 26 16:07:00 2015 client_config_dir = '[UNDEF]'
Sat Sep 26 16:07:00 2015 ccd_exclusive = DISABLED
Sat Sep 26 16:07:00 2015 tmp_dir = 'C:\Users\karolina\AppData\Local\Temp\'
Sat Sep 26 16:07:00 2015 push_ifconfig_defined = DISABLED
Sat Sep 26 16:07:00 2015 push_ifconfig_local = 0.0.0.0
Sat Sep 26 16:07:00 2015 push_ifconfig_remote_netmask = 0.0.0.0
Sat Sep 26 16:07:00 2015 push_ifconfig_ipv6_defined = DISABLED
Sat Sep 26 16:07:00 2015 push_ifconfig_ipv6_local = ::/0
Sat Sep 26 16:07:00 2015 push_ifconfig_ipv6_remote = ::
Sat Sep 26 16:07:00 2015 enable_c2c = DISABLED
Sat Sep 26 16:07:00 2015 duplicate_cn = DISABLED
Sat Sep 26 16:07:00 2015 cf_max = 0
Sat Sep 26 16:07:00 2015 cf_per = 0
Sat Sep 26 16:07:00 2015 max_clients = 1024
Sat Sep 26 16:07:00 2015 max_routes_per_client = 256
Sat Sep 26 16:07:00 2015 auth_user_pass_verify_script = '[UNDEF]'
Sat Sep 26 16:07:00 2015 auth_user_pass_verify_script_via_file = DISABLED
Sat Sep 26 16:07:00 2015 client = ENABLED
Sat Sep 26 16:07:00 2015 pull = ENABLED
Sat Sep 26 16:07:00 2015 auth_user_pass_file = '[UNDEF]'
Sat Sep 26 16:07:00 2015 show_net_up = DISABLED
Sat Sep 26 16:07:00 2015 route_method = 0
Sat Sep 26 16:07:00 2015 ip_win32_defined = DISABLED
Sat Sep 26 16:07:00 2015 ip_win32_type = 3
Sat Sep 26 16:07:00 2015 dhcp_masq_offset = 0
Sat Sep 26 16:07:00 2015 dhcp_lease_time = 31536000
Sat Sep 26 16:07:00 2015 tap_sleep = 0
Sat Sep 26 16:07:00 2015 dhcp_options = DISABLED
Sat Sep 26 16:07:00 2015 dhcp_renew = DISABLED
Sat Sep 26 16:07:00 2015 dhcp_pre_release = DISABLED
Sat Sep 26 16:07:00 2015 dhcp_release = DISABLED
Sat Sep 26 16:07:00 2015 domain = '[UNDEF]'
Sat Sep 26 16:07:00 2015 netbios_scope = '[UNDEF]'
Sat Sep 26 16:07:00 2015 netbios_node_type = 0
Sat Sep 26 16:07:00 2015 disable_nbt = DISABLED
Sat Sep 26 16:07:00 2015 OpenVPN 2.3.7 x86_64-w64-mingw32 [SSL (OpenSSL)] [LZO] [PKCS11] [IPv6] built on Jun 8 2015
Sat Sep 26 16:07:00 2015 library versions: OpenSSL 1.0.1m 19 Mar 2015, LZO 2.08
Sat Sep 26 16:07:00 2015 MANAGEMENT: TCP Socket listening on [AF_INET]127.0.0.1:25340
Sat Sep 26 16:07:00 2015 Need hold release from management interface, waiting...
Sat Sep 26 16:07:00 2015 MANAGEMENT: Client connected from [AF_INET]127.0.0.1:25340
Sat Sep 26 16:07:00 2015 MANAGEMENT: CMD 'state on'
Sat Sep 26 16:07:00 2015 MANAGEMENT: CMD 'log all on'
Sat Sep 26 16:07:00 2015 MANAGEMENT: CMD 'hold off'
Sat Sep 26 16:07:00 2015 MANAGEMENT: CMD 'hold release'
Sat Sep 26 16:07:00 2015 WARNING: using --pull/--client and --ifconfig together is probably not what you want
Sat Sep 26 16:07:00 2015 WARNING: No server certificate verification method has been enabled. See http://openvpn.net/howto.html#mitm for more info.
Sat Sep 26 16:07:01 2015 LZO compression initialized
Sat Sep 26 16:07:01 2015 Control Channel MTU parms [ L:1542 D:138 EF:38 EB:0 ET:0 EL:3 ]
Sat Sep 26 16:07:01 2015 Socket Buffers: R=[8192->8192] S=[8192->8192]
Sat Sep 26 16:07:01 2015 Data Channel MTU parms [ L:1542 D:1450 EF:42 EB:143 ET:0 EL:3 AF:3/1 ]
Sat Sep 26 16:07:01 2015 Local Options String: 'V4,dev-type tun,link-mtu 1542,tun-mtu 1500,proto UDPv4,comp-lzo,cipher BF-CBC,auth SHA1,keysize 128,key-method 2,tls-client'
Sat Sep 26 16:07:01 2015 Expected Remote Options String: 'V4,dev-type tun,link-mtu 1542,tun-mtu 1500,proto UDPv4,comp-lzo,cipher BF-CBC,auth SHA1,keysize 128,key-method 2,tls-server'
Sat Sep 26 16:07:01 2015 Local Options hash (VER=V4): '41690919'
Sat Sep 26 16:07:01 2015 Expected Remote Options hash (VER=V4): '530fdded'
Sat Sep 26 16:07:01 2015 UDPv4 link local (bound): [undef]
Sat Sep 26 16:07:01 2015 UDPv4 link remote: [AF_INET]192.168.0.2:1194
Sat Sep 26 16:07:01 2015 MANAGEMENT: >STATE:1443294421,WAIT,,,
Sat Sep 26 16:08:01 2015 TLS Error: TLS key negotiation failed to occur within 60 seconds (check your network connectivity)
Sat Sep 26 16:08:01 2015 TLS Error: TLS handshake failed
Sat Sep 26 16:08:01 2015 TCP/UDP: Closing socket
Sat Sep 26 16:08:01 2015 SIGUSR1[soft,tls-error] received, process restarting
Sat Sep 26 16:08:01 2015 MANAGEMENT: >STATE:1443294481,RECONNECTING,tls-error,,
Sat Sep 26 16:08:01 2015 Restart pause, 2 second(s)
Sat Sep 26 16:08:03 2015 WARNING: No server certificate verification method has been enabled. See http://openvpn.net/howto.html#mitm for more info.
Sat Sep 26 16:08:03 2015 Re-using SSL/TLS context
Sat Sep 26 16:08:03 2015 LZO compression initialized
Sat Sep 26 16:08:03 2015 Control Channel MTU parms [ L:1542 D:138 EF:38 EB:0 ET:0 EL:3 ]
Sat Sep 26 16:08:03 2015 Socket Buffers: R=[8192->8192] S=[8192->8192]
Sat Sep 26 16:08:03 2015 Data Channel MTU parms [ L:1542 D:1450 EF:42 EB:143 ET:0 EL:3 AF:3/1 ]
Sat Sep 26 16:08:03 2015 Local Options String: 'V4,dev-type tun,link-mtu 1542,tun-mtu 1500,proto UDPv4,comp-lzo,cipher BF-CBC,auth SHA1,keysize 128,key-method 2,tls-client'
Sat Sep 26 16:08:03 2015 Expected Remote Options String: 'V4,dev-type tun,link-mtu 1542,tun-mtu 1500,proto UDPv4,comp-lzo,cipher BF-CBC,auth SHA1,keysize 128,key-method 2,tls-server'
Sat Sep 26 16:08:03 2015 Local Options hash (VER=V4): '41690919'
Sat Sep 26 16:08:03 2015 Expected Remote Options hash (VER=V4): '530fdded'
Sat Sep 26 16:08:03 2015 UDPv4 link local (bound): [undef]
Sat Sep 26 16:08:03 2015 UDPv4 link remote: [AF_INET]192.168.0.2:1194
Sat Sep 26 16:08:03 2015 MANAGEMENT: >STATE:1443294483,WAIT,,,


Por favor, quem puder me ajudar.


3. Re: [OPENVPN] Serv-Debian e Client-Windows: Não consigo estabelecer conexão fora da rede

Guilherme Isaac
guilhermisaac

(usa Arch Linux)

Enviado em 08/10/2015 - 13:41h

Teu servidor Debian já é o Gateway da sua rede ou tem algum firewall antes?
--
Att

Guilherme Isaac


4. Re: [OPENVPN] Serv-Debian e Client-Windows: Não consigo estabelecer conexão fora da rede

Rodrigo Rodrigues
DrigoRJ

(usa Ubuntu)

Enviado em 08/10/2015 - 15:01h


Ele já é o gateway. Não uso nenhum outro firewall não


5. Re: [OPENVPN] Serv-Debian e Client-Windows: Não consigo estabelecer conexão fora da rede

Andre Ribeiro da Costa
andr3ribeiro

(usa Arch Linux)

Enviado em 08/10/2015 - 16:10h

tem regra de Firewall pro do que vem de fora, pedindo porta 1194 para o IP 192.168.0.2 ???
Tem como postar suas regras de firewall pra gente dar uma olhada?


6. Re: [OPENVPN] Serv-Debian e Client-Windows: Não consigo estabelecer conexão fora da rede

Rodrigo Rodrigues
DrigoRJ

(usa Ubuntu)

Enviado em 13/10/2015 - 15:43h


Na verdade não temos firewall nesse servidor.
Até tentei verificar já se era isso mas o firewall já estava desativado.






Patrocínio

Site hospedado pelo provedor RedeHost.
Linux banner

Destaques

Artigos

Dicas

Tópicos

Top 10 do mês

Scripts