Enviado em 16/03/2015 - 09:44h
Bom dia pessoal,
##Protocolo de conexão
#proto tcp / proto udp
proto udp
# Porta do servico (padrao openvpn)
port 51001
# Drive da interface
dev tun
# Seguranca na VPN
script-security 2
# Configura o IP do Tunel
ifconfig 172.32.1.1 172.32.1.2
# Acrescenta rotas aos clientes, informações da rede local
push "route 192.168.1.0 255.255.255.0"
# Compactacao lib LZO
comp-lzo
# Pinga a cada 10 segundos e derruba a conexao apos 120 segundos
keepalive 10 120
float
#ifconfig-pool-persist ipp.txt
max-clients 1
persist-key
persist-tun
log-append /var/log/openvpn.log
verb 3
# Servidor TLS
tls-server
# Chaves necessarias
dh /etc/openvpn/keys/dh1024.pem
ca /etc/openvpn/keys/ca.crt
cert /etc/openvpn/keys/matriz.crt
key /etc/openvpn/keys/matriz.key
# Chave secreta do servidor
#tls-auth /etc/openvpn/keys/chave.key
status /var/log/openvpn.stats
# Executa scripts
up /etc/openvpn/scripts/filial1.sh
client
dev tun
proto udp
remote x.x.x.x --> o ip está certo
port 51001
pull
comp-lzo
keepalive 10 120
float
tls-client
persist-tun
persist-key
dh /etc/openvpn/keys/dh1024.pem
ca /etc/openvpn/keys/ca.crt
cert /etc/openvpn/keys/filial1.crt
key /etc/openvpn/keys/filial1.key
tls-auth /etc/openvpn/keys/chave.key
route-method exe
route-delay 2
script-security 2
remote-cert-tls server
ifconfig 172.32.1.2 172.32.1.1
log /etc/openvpn/filial1.log
/sbin/iptables -A INPUT -p udp --dport 51001 -j ACCEPT
/sbin/iptables -A FORWARD -p udp --dport 51001 -j ACCEPT
/sbin/iptables -A OUTPUT -p udp --dport 51001 -j ACCEPT
/sbin/iptables -A INPUT -p udp --sport 51001 -j ACCEPT
/sbin/iptables -A FORWARD -p udp --sport 51001 -j ACCEPT
/sbin/iptables -A OUTPUT -p udp --sport 51001 -j ACCEPT
Mon Mar 16 09:42:09 2015 OpenVPN 2.2.1 x86_64-linux-gnu [SSL] [LZO2] [EPOLL] [PKCS11] [eurephia] [MH] [PF_INET6] [IPv6 payload 20110424-2 (2.2RC2)] built on Dec 1 2014
Mon Mar 16 09:42:09 2015 WARNING: using --pull/--client and --ifconfig together is probably not what you want
Mon Mar 16 09:42:09 2015 NOTE: the current --script-security setting may allow this configuration to call user-defined scripts
Mon Mar 16 09:42:09 2015 Control Channel Authentication: using '/etc/openvpn/keys/chave.key' as a OpenVPN static key file
Mon Mar 16 09:42:09 2015 LZO compression initialized
Mon Mar 16 09:42:09 2015 UDPv4 link local (bound): [undef]
Mon Mar 16 09:42:09 2015 UDPv4 link remote: [AF_INET]x.x.x.x:51001
Mon Mar 16 09:42:09 2015 read UDPv4 [ECONNREFUSED]: Connection refused (code=111)
Mon Mar 16 09:42:11 2015 read UDPv4 [ECONNREFUSED]: Connection refused (code=111)
Mon Mar 16 09:42:15 2015 read UDPv4 [ECONNREFUSED]: Connection refused (code=111)
Mon Mar 16 09:42:23 2015 TLS Error: cannot locate HMAC in incoming packet from [AF_INET]x.x.x.x:51001
Mon Mar 16 09:42:25 2015 TLS Error: cannot locate HMAC in incoming packet from [AF_INET]x.x.x.x:51001
Mon Mar 16 09:42:29 2015 TLS Error: cannot locate HMAC in incoming packet from [AF_INET]x.x.x.x:51001
Mon Mar 16 09:42:37 2015 TLS Error: cannot locate HMAC in incoming packet from [AF_INET]x.x.x.x:51001
Tue Jan 1 20:20:05 2002 Socket Buffers: R=[229376->131072] S=[229376->131072]
Tue Jan 1 20:20:05 2002 Preserving previous TUN/TAP instance: tun0
Tue Jan 1 20:20:05 2002 Data Channel MTU parms [ L:1542 D:1450 EF:42 EB:135 ET:0 EL:0 AF:3/1 ]
Tue Jan 1 20:20:05 2002 Local Options hash (VER=V4): '09ead35e'
Tue Jan 1 20:20:05 2002 Expected Remote Options hash (VER=V4): '32ab9cc9'
Tue Jan 1 20:20:05 2002 UDPv4 link local (bound): [undef]
Tue Jan 1 20:20:05 2002 UDPv4 link remote: [undef]
Tue Jan 1 20:20:05 2002 TLS: Initial packet from [AF_INET]y.y.y.y:51001, sid=03acb6bb b6cac87c
Tue Jan 1 20:20:05 2002 TLS Error: reading acknowledgement record from packet
Tue Jan 1 20:20:21 2002 TLS Error: reading acknowledgement record from packet
Tue Jan 1 20:20:53 2002 TLS: new session incoming connection from [AF_INET]y.y.y.y:51001
Tue Jan 1 20:20:53 2002 TLS Error: reading acknowledgement record from packet
Tue Jan 1 20:20:55 2002 TLS Error: reading acknowledgement record from packet
Tue Jan 1 20:20:59 2002 TLS Error: reading acknowledgement record from packet