Date: Tue, 23 Apr 2019 21:16:56 -0500 From: Karl Denninger <karl@denninger.net> To: freebsd-questions@freebsd.org Subject: Re: openvpn Message-ID: <a2326e8d-5d5c-6030-7d10-72dee3216f8a@denninger.net> In-Reply-To: <0A8436BD-EFB8-4A54-B920-329096B89C5B@mail.sermon-archive.info> References: <0A8436BD-EFB8-4A54-B920-329096B89C5B@mail.sermon-archive.info>
next in thread | previous in thread | raw e-mail | index | archive | help
[-- Attachment #1 --]
On 4/22/2019 19:53, Doug Hardie wrote:
> I am trying to setup an openvpn server on my home network. Home machines are all running FBSD 12.0 Release. openvpn was installed as a package. The results are quite confusing. Ping from an external device works correctly to all the home machines. I can use tcpdump to see the request packets arriving at the openvpn server, being sent to the recipient machine, the response packets being sent from the recipient machine to the openvpn server, and then sent to the external device. The external device shows that the response was received with a reasonable response time given that it is a cell phone.
>
> However, when I try to access a web page on any of the servers, I see the same set of packets via tcpdump. In addition if I run ktrace on the openvpn server, I see the encrypted packets from the client being received. The decrypted packets sent to the home server. The unencrypted response from the home server, and the encrypted response sent to the phone. However, the phone says that the server dropped the connection, or it shows a blank page.
>
> My first thought was that there was an encryption issue, but if that were the case, ping would not work. Checking the ping packets shows that they are encrypted between the phone and the openvpn server. Likewise a routing issue in the home network does not seem to be the problem for the same reason. All the info I have found on the web about vpn indicates that a ping test should be sufficient. But, in this case it is not.
>
> Any ideas on how to track down the problem, or fix it? Thanks,
>
> -- Doug
IMHO -- post your configuration file to the list....
I use OpenVPN with ipfw's internal NAT and it works fine, but the config
file is a bit wonky and if you get it wrong you'll either have no DNS on
the client or packets won't get routed. Either way the connection comes
up but it doesn't work.
--
Karl Denninger
karl@denninger.net <mailto:karl@denninger.net>
/The Market Ticker/
/[S/MIME encrypted email preferred]/
[-- Attachment #2 --]
0 *H
010
`He 0 *H
00 H^Ōc!5
H0
*H
010 UUS10UFlorida10U Niceville10U
Cuda Systems LLC10UCuda Systems CA1!0UCuda Systems LLC 2017 CA0
170817164217Z
270815164217Z0{10 UUS10UFlorida10U
Cuda Systems LLC10UCuda Systems CA1%0#UCuda Systems LLC 2017 Int CA0"0
*H
0
h-5B>[;olӴ0~͎O9}9Ye*$g!ukvʶLzN`jL>MD'7U 45CB+kY`bd~b*c3Ny-78ju]9HeuέsӬDؽmgwER?&UURj'}9nWD i`XcbGz \gG=u%\Oi13ߝ4
K44pYQr]Ie/r0+eEޝݖ0C15Mݚ@JSZ(zȏ NTa(25DD5.l<g[[ZarQQ%Buȴ~~`IohRbʳڟu2MS8EdFUClCMaѳ !}ș+2k/bųE,n当ꖛ\(8WV8 d]b yXw ܊:I39
00U]^§Q\ӎ0U#0T039N0b010 UUS10UFlorida10U Niceville10U
Cuda Systems LLC10UCuda Systems CA1!0UCuda Systems LLC 2017 CA @Ui0U0 0U0
*H
:P U!>vJnio-#ן]WyujǑR̀Q
nƇ!GѦFg\yLxgw=OPycehf[}ܷ['4ڝ\[p 6\o.B&JF"ZC{;*o*mcCcLY߾`
t*S!(`]DHP5A~/NPp6=mhk밣'doA$86hm5ӚS@jެEgl
)0JG`%k35PaC?σ
׳HEt}!P㏏%*BxbQwaKG$6h¦Mve;[o-Iی&
I,Tcߎ#t wPA@l0P+KXBպT zGv;NcI3&JĬUPNa?/%W6G۟N000 k#Xd\=0
*H
0{10 UUS10UFlorida10U
Cuda Systems LLC10UCuda Systems CA1%0#UCuda Systems LLC 2017 Int CA0
170817212120Z
220816212120Z0W10 UUS10UFlorida10U
Cuda Systems LLC10Ukarl@denninger.net0"0
*H
0
T[I-ΆϏ dn;Å@שy.us~_ZG%<MYd\gvfnsa1'6Egyjs"C [{~_K Pn+<*pv#Q+H/7[-vqDV^U>f%GX)H.|l`M(Cr>е͇6#odc"YljҦln8@5SA0&ۖ"OGj?UDWZ5 dDB7k-)9Izs-JAv
J6L$Ն1SmY.Lqw*SH;EF'DĦH]MOgQQ|Mٙג2Z9y@y]}6ٽeY9Y2xˆ$T=eCǺǵbn֛{j|@LLt1[Dk5:$= ` M 00<+00.0,+0 http://ocsp.cudasystems.net:88880 U0 0 `HB0U0U%0++03 `HB
&$OpenSSL Generated Client Certificate0U%՞V=;bzQ0U#0]^§Q\ӎϡ010 UUS10UFlorida10U Niceville10U
Cuda Systems LLC10UCuda Systems CA1!0UCuda Systems LLC 2017 CA H^Ōc!5
H0U0karl@denninger.net0
*H
۠A0-j%--$%g2#ޡ1^>{K+uGEv1ş7Af&b&O;.;A5*U)ND2bF|\=]<sˋL!wrw٧>YMÄ3\mWR hSv!_zvl? 3_ xU%\^#O*Gk̍YI_&Fꊛ@&1n } ͬ:{hTP3B.;bU8:Z=^Gw8!k-@xE@i,+'Iᐚ:fhztX7/(hY` O.1}a`%RW^akǂpCAufgDix UTЩ/7}%=jnVZvcF<M=
2^GKH5魉
_O4ެByʈySkw=5@h.0z>
W1000{10 UUS10UFlorida10U
Cuda Systems LLC10UCuda Systems CA1%0#UCuda Systems LLC 2017 Int CA k#Xd\=0
`He E0 *H
1 *H
0 *H
1
190424021656Z0O *H
1B@JVzv-ňʺ9xǡɎ<*cy/Q2Ɛ$ (0l *H
1_0]0 `He*0 `He0
*H
0*H
0
*H
@0+0
*H
(0 +7100{10 UUS10UFlorida10U
Cuda Systems LLC10UCuda Systems CA1%0#UCuda Systems LLC 2017 Int CA k#Xd\=0*H
10{10 UUS10UFlorida10U
Cuda Systems LLC10UCuda Systems CA1%0#UCuda Systems LLC 2017 Int CA k#Xd\=0
*H
d|W
Y K
bR.ЮG-iWԽd!C^bqĢezLFm$ t;`"ݓua屣$'8м<7{g93{`u(1R]~-Z>9(Ԁg3MnZWh(:D3J`a)+!M c|L{H*szJ`>3OõO?,5֎2bljlӂWmmAuWQMNY<TvM1a>a+̈Tk.p%e/E3&qdoNM~YMY:ڮ),.:P`qbf{"n͝Ez\WHw&"/ 8sUv/]"3(류e9r'~3+)1"U$A#5oBLPW߅4{SԄp$XDgB侤zvAW
Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?a2326e8d-5d5c-6030-7d10-72dee3216f8a>
