auf unserer neuen RC300 10.5.1 habe ich die Zertifikatskonfig und das Anlegen eines SSL-VPN-Users gem. Anleitung durchgeführt.
Auch die IP 192.168.250.10 hat eine Firewallregel, um alles im internen Netz zu dürfen.
Der Tunnel wird vom entfernten Standort aufgebaut und gilt als OK.
Allerdings kann ich im Zielnetz keine Maschinen erreichen. Das Zielnetz hat 10.4.0.0/17.
Log anbei. Irgendwas habe ich sicher vergessen. Aberda es mit den alten Appliances und OpenVPN so simpel war kann ich mir nciht vorstellen, dass es etwas wahnsinnig kompliziertes ist.
Kann mir jemand helfen?
Danke und Gruss
Jan
Code: Alles auswählen
Fri Apr 15 11:08:14 2011 OpenVPN 2.1.1 i386-pc-mingw32 [SSL] [LZO2] built on Apr 14 2010
Fri Apr 15 11:08:24 2011 WARNING: No server certificate verification method has been enabled. See http://openvpn.net/howto.html#mitm for more info.
Fri Apr 15 11:08:24 2011 NOTE: OpenVPN 2.1 requires '--script-security 2' or higher to call user-defined scripts or executables
Fri Apr 15 11:08:24 2011 Control Channel MTU parms [ L:1541 D:138 EF:38 EB:0 ET:0 EL:0 ]
Fri Apr 15 11:08:24 2011 Data Channel MTU parms [ L:1541 D:1450 EF:41 EB:4 ET:0 EL:0 ]
Fri Apr 15 11:08:24 2011 Local Options hash (VER=V4): '3514370b'
Fri Apr 15 11:08:24 2011 Expected Remote Options hash (VER=V4): '239669a8'
Fri Apr 15 11:08:24 2011 Socket Buffers: R=[8192->8192] S=[8192->8192]
Fri Apr 15 11:08:24 2011 UDPv4 link local: [undef]
Fri Apr 15 11:08:24 2011 UDPv4 link remote: WANIP:1194
Fri Apr 15 11:08:24 2011 TLS: Initial packet from WANIP:1194, sid=9c9c6da2 33a3c06d
Fri Apr 15 11:08:24 2011 WARNING: this configuration may cache passwords in memory -- use the auth-nocache option to prevent this
Fri Apr 15 11:08:24 2011 VERIFY OK: depth=1, /C=DE/ST=Deutschland/L=ORT/O=FIRMA/OU=IT/CN=FIRMA_ORT/emailAddress=EMAIL
Fri Apr 15 11:08:24 2011 VERIFY OK: depth=0, /C=DE/ST=Deutschland/L=ORT/O=FIRMA/OU=IT/CN=SSL_Server_ORT/emailAddress=EMAIL
Fri Apr 15 11:08:25 2011 Data Channel Encrypt: Cipher 'BF-CBC' initialized with 128 bit key
Fri Apr 15 11:08:25 2011 Data Channel Encrypt: Using 160 bit message hash 'SHA1' for HMAC authentication
Fri Apr 15 11:08:25 2011 Data Channel Decrypt: Cipher 'BF-CBC' initialized with 128 bit key
Fri Apr 15 11:08:25 2011 Data Channel Decrypt: Using 160 bit message hash 'SHA1' for HMAC authentication
Fri Apr 15 11:08:25 2011 Control Channel: TLSv1, cipher TLSv1/SSLv3 DHE-RSA-AES256-SHA, 1024 bit RSA
Fri Apr 15 11:08:25 2011 [SSL_Server_ORT] Peer Connection Initiated with WAN_IP:1194
Fri Apr 15 11:08:27 2011 SENT CONTROL [SSL_Server_ORT]: 'PUSH_REQUEST' (status=1)
Fri Apr 15 11:08:27 2011 PUSH: Received control message: 'PUSH_REPLY,dhcp-option DNS 10.4.0.1,route 192.168.250.1,topology net30,ping 10,ping-restart 120,ifconfig 192.168.250.10 192.168.250.9'
Fri Apr 15 11:08:27 2011 OPTIONS IMPORT: timers and/or timeouts modified
Fri Apr 15 11:08:27 2011 OPTIONS IMPORT: --ifconfig/up options modified
Fri Apr 15 11:08:27 2011 OPTIONS IMPORT: route options modified
Fri Apr 15 11:08:27 2011 OPTIONS IMPORT: --ip-win32 and/or --dhcp-option options modified
Fri Apr 15 11:08:27 2011 ROUTE default_gateway=192.168.178.253
Fri Apr 15 11:08:27 2011 TAP-WIN32 device [LAN-Verbindung] opened: \\\\.\\Global\\{8E1FB8D3-BDAC-44EA-B99B-C82EA4C50090}.tap
Fri Apr 15 11:08:27 2011 TAP-Win32 Driver Version 9.6
Fri Apr 15 11:08:27 2011 TAP-Win32 MTU=1500
Fri Apr 15 11:08:27 2011 Notified TAP-Win32 driver to set a DHCP IP/netmask of 192.168.250.10/255.255.255.252 on interface {8E1FB8D3-BDAC-44EA-B99B-C82EA4C50090} [DHCP-serv: 192.168.250.9, lease-time: 31536000]
Fri Apr 15 11:08:27 2011 Successful ARP Flush on interface [28] {8E1FB8D3-BDAC-44EA-B99B-C82EA4C50090}
Fri Apr 15 11:08:29 2011 TEST ROUTES: 1/1 succeeded len=1 ret=1 a=0 u/d=up
Fri Apr 15 11:08:29 2011 C:\\WINDOWS\\system32\\route.exe ADD 192.168.250.1 MASK 255.255.255.255 192.168.250.9
Fri Apr 15 11:08:29 2011 Initialization Sequence Completed