Menu

Show posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.

Show posts Menu

Messages - Matteo

#1
German - Deutsch / Re: where used option
September 11, 2019, 09:38:17 AM
Hallo Franco,

danke erstmal für die Antwort. Das ist schonmal eine erste Hilfe Schön wäre es zu wissen wo ein bestimmtes Object/Alias in welcher Firewallregel verwendet wird.

Gr. Matteüs
#2
German - Deutsch / where used option
September 10, 2019, 02:50:32 PM
Gibt's auch bei opnsense die "where used" option.

Gr. Matteüs
#3
Hallo,

VPN Verbindung Status ist UP aber ich kann nichts erreichen.
wenn ich z.B. die 10.10.75.10 versuche an zu pingen dann taucht folgendes im Log.

openvpn[6787]: Bismarckstr26/37.138.195.203:18703 MULTI: bad source address from client [10.50.50.2], packet dropped



Server.conf

dev ovpns1
verb 4
dev-type tun
dev-node /dev/tun1
writepid /var/run/openvpn_server1.pid
script-security 3
daemon
keepalive 10 60
ping-timer-rem
persist-tun
persist-key
proto udp
cipher AES-256-CBC
auth SHA512
up /usr/local/etc/inc/plugins.inc.d/openvpn/ovpn-linkup
down /usr/local/etc/inc/plugins.inc.d/openvpn/ovpn-linkdown
local 172.16.0.58
client-connect "/usr/local/etc/inc/plugins.inc.d/openvpn/ovpn_setup_cso.php server1"
tls-server
server 10.60.6.0 255.255.255.0
client-config-dir /var/etc/openvpn-csc/1
tls-verify "/usr/local/etc/inc/plugins.inc.d/openvpn/ovpn_auth_verify tls 'Delmenhorst_CRT' 1"
lport 1194
management /var/etc/openvpn/server1.sock unix
push "redirect-gateway def1"
route 10.50.50.0 255.255.255.0
ca /var/etc/openvpn/server1.ca
cert /var/etc/openvpn/server1.cert
key /var/etc/openvpn/server1.key
dh /usr/local/etc/dh-parameters.4096.sample
tls-auth /var/etc/openvpn/server1.tls-auth 0
comp-lzo adaptive
persist-remote-ip
float

---------------------------------------------------------------------------------------------------------------

Client.conf

dev ovpnc1
verb 4
dev-type tun
dev-node /dev/tun1
writepid /var/run/openvpn_client1.pid
script-security 3
daemon
keepalive 10 60
ping-timer-rem
persist-tun
persist-key
proto udp
cipher AES-256-CBC
auth SHA512
up /usr/local/etc/inc/plugins.inc.d/openvpn/ovpn-linkup
down /usr/local/etc/inc/plugins.inc.d/openvpn/ovpn-linkdown
local 192.168.178.2
tls-client
client
lport 0
management /var/etc/openvpn/client1.sock unix
remote 80.150.10.21 1194
ifconfig 10.60.6.2 10.60.6.1
route 10.50.50.0 255.255.255.0
ca /var/etc/openvpn/client1.ca
cert /var/etc/openvpn/client1.cert
key /var/etc/openvpn/client1.key
tls-auth /var/etc/openvpn/client1.tls-auth 1
comp-lzo adaptive

------------------------------------------------------------------------------------------------------------

Vielen Dank schon mal!
Gruss
#4
VPN Verbindung komt tot stand. ik kann niets bereiken.
Log geeft volgende weer als ik probeer te pingen

openvpn[6787]: Bismarckstr26/37.138.195.203:18703 MULTI: bad source address from client [10.50.50.2], packet dropped



Server.conf

dev ovpns1
verb 4
dev-type tun
dev-node /dev/tun1
writepid /var/run/openvpn_server1.pid
script-security 3
daemon
keepalive 10 60
ping-timer-rem
persist-tun
persist-key
proto udp
cipher AES-256-CBC
auth SHA512
up /usr/local/etc/inc/plugins.inc.d/openvpn/ovpn-linkup
down /usr/local/etc/inc/plugins.inc.d/openvpn/ovpn-linkdown
local 172.16.0.58
client-connect "/usr/local/etc/inc/plugins.inc.d/openvpn/ovpn_setup_cso.php server1"
tls-server
server 10.60.6.0 255.255.255.0
client-config-dir /var/etc/openvpn-csc/1
tls-verify "/usr/local/etc/inc/plugins.inc.d/openvpn/ovpn_auth_verify tls 'Delmenhorst_CRT' 1"
lport 1194
management /var/etc/openvpn/server1.sock unix
push "redirect-gateway def1"
route 10.50.50.0 255.255.255.0
ca /var/etc/openvpn/server1.ca
cert /var/etc/openvpn/server1.cert
key /var/etc/openvpn/server1.key
dh /usr/local/etc/dh-parameters.4096.sample
tls-auth /var/etc/openvpn/server1.tls-auth 0
comp-lzo adaptive
persist-remote-ip
float

---------------------------------------------------------------------------------------------------------------

Client.conf

dev ovpnc1
verb 4
dev-type tun
dev-node /dev/tun1
writepid /var/run/openvpn_client1.pid
script-security 3
daemon
keepalive 10 60
ping-timer-rem
persist-tun
persist-key
proto udp
cipher AES-256-CBC
auth SHA512
up /usr/local/etc/inc/plugins.inc.d/openvpn/ovpn-linkup
down /usr/local/etc/inc/plugins.inc.d/openvpn/ovpn-linkdown
local 192.168.178.2
tls-client
client
lport 0
management /var/etc/openvpn/client1.sock unix
remote 80.150.10.21 1194
ifconfig 10.60.6.2 10.60.6.1
route 10.50.50.0 255.255.255.0
ca /var/etc/openvpn/client1.ca
cert /var/etc/openvpn/client1.cert
key /var/etc/openvpn/client1.key
tls-auth /var/etc/openvpn/client1.tls-auth 1
comp-lzo adaptive

------------------------------------------------------------------------------------------------------------