Skip site navigation (1)Skip section navigation (2)
Date:      Tue, 23 Apr 2019 21:16:56 -0500
From:      Karl Denninger <karl@denninger.net>
To:        freebsd-questions@freebsd.org
Subject:   Re: openvpn
Message-ID:  <a2326e8d-5d5c-6030-7d10-72dee3216f8a@denninger.net>
In-Reply-To: <0A8436BD-EFB8-4A54-B920-329096B89C5B@mail.sermon-archive.info>
References:  <0A8436BD-EFB8-4A54-B920-329096B89C5B@mail.sermon-archive.info>

next in thread | previous in thread | raw e-mail | index | archive | help

[-- Attachment #1 --]

On 4/22/2019 19:53, Doug Hardie wrote:
> I am trying to setup an openvpn server on my home network.  Home machines are all running FBSD 12.0 Release.  openvpn was installed as a package.  The results are quite confusing.  Ping from an external device works correctly to all the home machines.  I can use tcpdump to see the request packets arriving at the openvpn server, being sent to the recipient machine, the response packets being sent from the recipient machine to the openvpn server, and then sent to the external device.  The external device shows that the response was received with a reasonable response time given that it is a cell phone.  
>
> However, when I try to access a web page on any of the servers, I see the same set of packets via tcpdump.  In addition if I run ktrace on the openvpn server, I see the encrypted packets from the client being received.  The decrypted packets sent to the home server.  The unencrypted response from the home server, and the encrypted response sent to the phone.  However, the phone says that the server dropped the connection, or it shows a blank page.
>
> My first thought was that there was an encryption issue, but if that were the case, ping would not work.  Checking the ping packets shows that they are encrypted between the phone and the openvpn server.  Likewise a routing issue in the home network does not seem to be the problem for the same reason.  All the info I have found on the web about vpn indicates that a ping test should be sufficient.  But, in this case it is not.
>
> Any ideas on how to track down the problem, or fix it?  Thanks,
>
> -- Doug

IMHO -- post your configuration file to the list....

I use OpenVPN with ipfw's internal NAT and it works fine, but the config
file is a bit wonky and if you get it wrong you'll either have no DNS on
the client or packets won't get routed.  Either way the connection comes
up but it doesn't work.

-- 
Karl Denninger
karl@denninger.net <mailto:karl@denninger.net>
/The Market Ticker/
/[S/MIME encrypted email preferred]/

[-- Attachment #2 --]
0	*H
010
	`He0	*H

00H^Ōc!5
H0
	*H
010	UUS10UFlorida10U	Niceville10U
Cuda Systems LLC10UCuda Systems CA1!0UCuda Systems LLC 2017 CA0
170817164217Z
270815164217Z0{10	UUS10UFlorida10U
Cuda Systems LLC10UCuda Systems CA1%0#UCuda Systems LLC 2017 Int CA0"0
	*H
0
h-5B>[;olӴ0~͎O9}9Ye*$g!ukvʶLzN`jL>MD'7U45CB+kY`bd~b*c3Ny-78ju]9HeuέsӬDؽmgwER?&UURj'}9nWD i`XcbGz\gG=u%\Oi13ߝ4
K44pYQr]Ie/r0+eEޝݖ0C15Mݚ@JSZ(zȏNTa(25DD5.l<g[[ZarQQ%Buȴ~~`IohRbʳڟu2MS8EdFUClCMaѳ!}ș+2k/bųE,n当ꖛ\(8WV8	d]b	yXw	܊:I39
00U]^§Q\ӎ0U#0T039N0b010	UUS10UFlorida10U	Niceville10U
Cuda Systems LLC10UCuda Systems CA1!0UCuda Systems LLC 2017 CA	@Ui0U00U0
	*H
:P U!>vJnio-#ן]WyujǑR̀Q
nƇ!GѦFg\yLxgw=OPycehf[}ܷ['4ڝ\[p6\o.B&JF"ZC{;*o*mcCcLY߾`
t*S!񫶭(`]DHP5A~/NPp6=mhk밣'doA$86hm5ӚS@jެEgl
)0JG`%k35PaC?σ
׳HEt}!P㏏%*BxbQwaKG$6h¦Mve;[o-Iی&
I,Tcߎ#t wPA@l0P+KXBպT	zGv;NcI3&JĬUPNa?/%W6G۟N000k#Xd\=0
	*H
0{10	UUS10UFlorida10U
Cuda Systems LLC10UCuda Systems CA1%0#UCuda Systems LLC 2017 Int CA0
170817212120Z
220816212120Z0W10	UUS10UFlorida10U
Cuda Systems LLC10Ukarl@denninger.net0"0
	*H
0
T[I-ΆϏdn;Å@שy.us~_ZG%<MYd\gvfnsa1'6Egyjs"C [{~_KPn+<*pv#Q+H/7[-vqDV^U>f%GX)H.|l`M(Cr>е͇6#odc"YljҦln8@5SA0&ۖ"OGj?UDWZ5	dDB7k-)9Izs-JAv
J6L$Ն1SmY.Lqw*SH;EF'DĦH]MOgQQ|Mٙג2Z9y@y]}6ٽeY9Y2xˆ$T=eCǺǵbn֛{j|@LLt1[Dk5:$=	`	M00<+00.0,+0 http://ocsp.cudasystems.net:88880	U00	`HB0U0U%0++03	`HB
&$OpenSSL Generated Client Certificate0U%՞V=؁;bzQ0U#0]^§Q\ӎϡ010	UUS10UFlorida10U	Niceville10U
Cuda Systems LLC10UCuda Systems CA1!0UCuda Systems LLC 2017 CAH^Ōc!5
H0U0karl@denninger.net0
	*H
۠A0-j%--$%g2#ޡ1^>{K+uGEv1ş7Af&b&O;.;A5*U)ND2bF|\=]<sˋL!wrw٧>YMÄ3\mWR hSv!_zvl? 3_ xU%\^#O*Gk̍YI_&Fꊛ@&1n”} ͬ:{hTP3B.;bU8:Z=^Gw8!k-@xE@i,+'Iᐚ:fhztX7/(hY` O.1}a`%RW^akǂpCAufgDixUTЩ/7}%=jnVZvcF<M=
2^GKH5魉
_O4ެByʈySkw=5@h.0z>
W1000{10	UUS10UFlorida10U
Cuda Systems LLC10UCuda Systems CA1%0#UCuda Systems LLC 2017 Int CAk#Xd\=0
	`HeE0	*H
	1	*H
0	*H
	1
190424021656Z0O	*H
	1B@JVzv-ňʺ9xǡɎ<*cy/Q2Ɛ$ (0l	*H
	1_0]0	`He*0	`He0
*H
0*H
0
*H
@0+0
*H
(0	+7100{10	UUS10UFlorida10U
Cuda Systems LLC10UCuda Systems CA1%0#UCuda Systems LLC 2017 Int CAk#Xd\=0*H
	10{10	UUS10UFlorida10U
Cuda Systems LLC10UCuda Systems CA1%0#UCuda Systems LLC 2017 Int CAk#Xd\=0
	*H
d|W
Y	K
bR.ЮG-iWԽd!C^bqĢezLFm$ t;`"ݓua屣$'8м<7{g93{`u(1R]~-Z>9(Ԁg3MnZWh(:D3J`a)+!Mc|L{H*szJ`>3OõO?,5֎2bljlӂWmmAuWQMNY<TvM1a>a+̈Tk.p%e/E3&qdoNM~YMY:ڮ),.:P`qbf{"n͝Ez\WHw&"/	8sUv/]"3(류e9r'~3+)1"U$A#5oBLPW߅4{SԄp$XDgB侤zvAW

Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?a2326e8d-5d5c-6030-7d10-72dee3216f8a>