1
Virtual private networks / Re: Vpn site to site Opnsense - Ubuntu
« on: March 05, 2021, 05:14:12 pm »
I am at a stale point.
Using a vm emulating the net configuration of the linux box i could create a client conf and certificate to upload on
ubuntu.
I removed the "odd" switches which ubuntu didn't like.
I started everything and something is going on as opnsense logs activity, but i have no link between the two parts.
Linux client.conf:
verb 4
dev-type tun
dev tun
writepid /var/run/openvpn_client1.pid
script-security 3
daemon
keepalive 10 60
ping-timer-rem
persist-tun
persist-key
proto udp4
cipher AES-256-CBC
auth SHA1
#multihome
lport 11940
#management /var/etc/openvpn/client1.sock unix
remote ipv4_opnsense_box port
ifconfig tunnel_ip_2 tunnel_ip_1
route opnsense_lan 255.255.255.0
# pre shared secret
secret /root/test_vpn/pd1/client1.secret
comp-lzo adaptive
opnsense server.conf
dev ovpns1
verb 4
dev-type tun
dev-node /dev/tun1
writepid /var/run/openvpn_server1.pid
script-security 3
daemon
keepalive 10 60
ping-timer-rem
persist-tun
persist-key
proto udp4
cipher AES-256-CBC
auth SHA1
up /usr/local/etc/inc/plugins.inc.d/openvpn/ovpn-linkup
down /usr/local/etc/inc/plugins.inc.d/openvpn/ovpn-linkdown
local wan_ip_address
client-connect "/usr/local/etc/inc/plugins.inc.d/openvpn/ovpn_setup_cso.php server1"
tls-server
server tunnel_network 255.255.255.0
client-config-dir /var/etc/openvpn-csc/1
ifconfig tunnel_ip_1 tunnel_ip_2
tls-verify "/usr/local/etc/inc/plugins.inc.d/openvpn/ovpn_auth_verify tls 'OPNsense.localdomain' 1"
lport local_port_number (same as client remote_port_number)
management /var/etc/openvpn/server1.sock unix
max-clients 2
push "route lan_net 255.255.255.0"
route remote_lan_linux 255.255.255.0
ca /var/etc/openvpn/server1.ca
cert /var/etc/openvpn/server1.cert
key /var/etc/openvpn/server1.key
dh /usr/local/etc/dh-parameters.2048.sample
tls-auth /var/etc/openvpn/server1.tls-auth 0
comp-lzo adaptive
Logs from the opnsense when i start from linux the connecrion:
MANAGEMENT: Client disconnected
MANAGEMENT: CMD 'quit'
MANAGEMENT: CMD 'status 2'
MANAGEMENT: Client connected from /var/etc/openvpn/server1.sock
Any hint would be really appreciated.
Thank you.
Using a vm emulating the net configuration of the linux box i could create a client conf and certificate to upload on
ubuntu.
I removed the "odd" switches which ubuntu didn't like.
I started everything and something is going on as opnsense logs activity, but i have no link between the two parts.
Linux client.conf:
verb 4
dev-type tun
dev tun
writepid /var/run/openvpn_client1.pid
script-security 3
daemon
keepalive 10 60
ping-timer-rem
persist-tun
persist-key
proto udp4
cipher AES-256-CBC
auth SHA1
#multihome
lport 11940
#management /var/etc/openvpn/client1.sock unix
remote ipv4_opnsense_box port
ifconfig tunnel_ip_2 tunnel_ip_1
route opnsense_lan 255.255.255.0
# pre shared secret
secret /root/test_vpn/pd1/client1.secret
comp-lzo adaptive
opnsense server.conf
dev ovpns1
verb 4
dev-type tun
dev-node /dev/tun1
writepid /var/run/openvpn_server1.pid
script-security 3
daemon
keepalive 10 60
ping-timer-rem
persist-tun
persist-key
proto udp4
cipher AES-256-CBC
auth SHA1
up /usr/local/etc/inc/plugins.inc.d/openvpn/ovpn-linkup
down /usr/local/etc/inc/plugins.inc.d/openvpn/ovpn-linkdown
local wan_ip_address
client-connect "/usr/local/etc/inc/plugins.inc.d/openvpn/ovpn_setup_cso.php server1"
tls-server
server tunnel_network 255.255.255.0
client-config-dir /var/etc/openvpn-csc/1
ifconfig tunnel_ip_1 tunnel_ip_2
tls-verify "/usr/local/etc/inc/plugins.inc.d/openvpn/ovpn_auth_verify tls 'OPNsense.localdomain' 1"
lport local_port_number (same as client remote_port_number)
management /var/etc/openvpn/server1.sock unix
max-clients 2
push "route lan_net 255.255.255.0"
route remote_lan_linux 255.255.255.0
ca /var/etc/openvpn/server1.ca
cert /var/etc/openvpn/server1.cert
key /var/etc/openvpn/server1.key
dh /usr/local/etc/dh-parameters.2048.sample
tls-auth /var/etc/openvpn/server1.tls-auth 0
comp-lzo adaptive
Logs from the opnsense when i start from linux the connecrion:
MANAGEMENT: Client disconnected
MANAGEMENT: CMD 'quit'
MANAGEMENT: CMD 'status 2'
MANAGEMENT: Client connected from /var/etc/openvpn/server1.sock
Any hint would be really appreciated.
Thank you.