• Как сконфигурировать openvpn server, чтобы через него шёл не весь трафик от клиентов, а только на определённые адреса назначения?

    @onlyjusttruth Автор вопроса
    Radjah,
    закоментил
    # tun-ipv6
    # push tun-ipv6
    и вроде заработало как надо. Мне это кажется странным. Я думал маршруты для ipv4 отдельно, а для ipv6 отдельно.
  • Как сконфигурировать openvpn server, чтобы через него шёл не весь трафик от клиентов, а только на определённые адреса назначения?

    @onlyjusttruth Автор вопроса
    redirect-gateway ipv6
    Так этот пуш и не закоментен в конфиге. Меня в логах больше смущает
    Fri Feb 14 14:27:22 2020 TEST ROUTES: 1/1 succeeded len=0 ret=1 a=0 u/d=up
    Fri Feb 14 14:27:22 2020 C:\Windows\system32\route.exe ADD АЙПИ СЕРВЕРА MASK 255.255.255.255 192.168.1.1
    Fri Feb 14 14:27:22 2020 Route addition via service succeeded
    Fri Feb 14 14:27:22 2020 C:\Windows\system32\route.exe ADD 0.0.0.0 MASK 128.0.0.0 10.8.0.1
    Fri Feb 14 14:27:22 2020 Route addition via service succeeded
    Fri Feb 14 14:27:22 2020 C:\Windows\system32\route.exe ADD 128.0.0.0 MASK 128.0.0.0 10.8.0.1
    Fri Feb 14 14:27:22 2020 Route addition via service succeeded


    Делай серверу сначала stop, потом start, чтобы он точно конфиг перечитал.

    Пробовал и systemctl restart openvpn, и systemctl stop openvpn -> systemctl start openvpn, и даже перезагружал сервер полностью.
  • Как сконфигурировать openvpn server, чтобы через него шёл не весь трафик от клиентов, а только на определённые адреса назначения?

    @onlyjusttruth Автор вопроса
    Radjah, ну вот по логам подключения он создаёт маршруты к 0.0.0.0 через впн. Хотя мне непонятно, почему
    spoiler

    Fri Feb 14 14:27:15 2020 OpenVPN 2.4.7 x86_64-w64-mingw32 [SSL (OpenSSL)] [LZO] [LZ4] [PKCS11] [AEAD] built on Apr 25 2019
    Fri Feb 14 14:27:15 2020 Windows version 6.2 (Windows 8 or greater) 64bit
    Fri Feb 14 14:27:15 2020 library versions: OpenSSL 1.1.0j  20 Nov 2018, LZO 2.10
    Fri Feb 14 14:27:15 2020 MANAGEMENT: TCP Socket listening on [AF_INET]127.0.0.1:25341
    Fri Feb 14 14:27:15 2020 Need hold release from management interface, waiting...
    Fri Feb 14 14:27:15 2020 MANAGEMENT: Client connected from [AF_INET]127.0.0.1:25341
    Fri Feb 14 14:27:16 2020 MANAGEMENT: CMD 'state on'
    Fri Feb 14 14:27:16 2020 MANAGEMENT: CMD 'log all on'
    Fri Feb 14 14:27:16 2020 MANAGEMENT: CMD 'echo all on'
    Fri Feb 14 14:27:16 2020 MANAGEMENT: CMD 'bytecount 5'
    Fri Feb 14 14:27:16 2020 MANAGEMENT: CMD 'hold off'
    Fri Feb 14 14:27:16 2020 MANAGEMENT: CMD 'hold release'
    Fri Feb 14 14:27:16 2020 Outgoing Control Channel Encryption: Cipher 'AES-256-CTR' initialized with 256 bit key
    Fri Feb 14 14:27:16 2020 Outgoing Control Channel Encryption: Using 256 bit message hash 'SHA256' for HMAC authentication
    Fri Feb 14 14:27:16 2020 Incoming Control Channel Encryption: Cipher 'AES-256-CTR' initialized with 256 bit key
    Fri Feb 14 14:27:16 2020 Incoming Control Channel Encryption: Using 256 bit message hash 'SHA256' for HMAC authentication
    Fri Feb 14 14:27:16 2020 MANAGEMENT: >STATE:1581665236,RESOLVE,,,,,,
    Fri Feb 14 14:27:16 2020 TCP/UDP: Preserving recently used remote address: [AF_INET]АЙПИ СЕРВЕРА:ПОРТ ОПЕНВПН
    Fri Feb 14 14:27:16 2020 Socket Buffers: R=[65536->65536] S=[65536->65536]
    Fri Feb 14 14:27:16 2020 UDP link local: (not bound)
    Fri Feb 14 14:27:16 2020 UDP link remote: [AF_INET]АЙПИ СЕРВЕРА:ПОРТ ОПЕНВПН
    Fri Feb 14 14:27:16 2020 MANAGEMENT: >STATE:1581665236,WAIT,,,,,,
    Fri Feb 14 14:27:16 2020 MANAGEMENT: >STATE:1581665236,AUTH,,,,,,
    Fri Feb 14 14:27:16 2020 TLS: Initial packet from [AF_INET]АЙПИ СЕРВЕРА:ПОРТ ОПЕНВПН, sid=669b2d03 758d3332
    Fri Feb 14 14:27:16 2020 VERIFY OK: depth=1, CN=cn_IdMa7IO0oKxaPRI0
    Fri Feb 14 14:27:16 2020 VERIFY KU OK
    Fri Feb 14 14:27:16 2020 Validating certificate extended key usage
    Fri Feb 14 14:27:16 2020 ++ Certificate has EKU (str) TLS Web Server Authentication, expects TLS Web Server Authentication
    Fri Feb 14 14:27:16 2020 VERIFY EKU OK
    Fri Feb 14 14:27:16 2020 VERIFY X509NAME OK: CN=server_server
    Fri Feb 14 14:27:16 2020 VERIFY OK: depth=0, CN=server_server
    Fri Feb 14 14:27:16 2020 Control Channel: TLSv1.2, cipher TLSv1.2 ECDHE-ECDSA-AES128-GCM-SHA256, 256 bit EC, curve: prime256v1
    Fri Feb 14 14:27:16 2020 [server_server] Peer Connection Initiated with [AF_INET]АЙПИ СЕРВЕРА:ПОРТ ОПЕНВПН
    Fri Feb 14 14:27:17 2020 MANAGEMENT: >STATE:1581665237,GET_CONFIG,,,,,,
    Fri Feb 14 14:27:17 2020 SENT CONTROL [server_server]: 'PUSH_REQUEST' (status=1)
    Fri Feb 14 14:27:17 2020 PUSH: Received control message: 'PUSH_REPLY,route-ipv6 ::/0,redirect-gateway ipv6,tun-ipv6,route-gateway 10.8.0.1,topology subnet,ping 10,ping-restart 120,ifconfig-ipv6 АЙПИ6::1000/112 АЙПИ6::1,ifconfig 10.8.0.2 255.255.255.0,peer-id 0,cipher AES-192-GCM'
    Fri Feb 14 14:27:17 2020 Flag 'def1' added to --redirect-gateway (iservice is in use)
    Fri Feb 14 14:27:17 2020 OPTIONS IMPORT: timers and/or timeouts modified
    Fri Feb 14 14:27:17 2020 OPTIONS IMPORT: --ifconfig/up options modified
    Fri Feb 14 14:27:17 2020 OPTIONS IMPORT: route options modified
    Fri Feb 14 14:27:17 2020 OPTIONS IMPORT: route-related options modified
    Fri Feb 14 14:27:17 2020 OPTIONS IMPORT: peer-id set
    Fri Feb 14 14:27:17 2020 OPTIONS IMPORT: adjusting link_mtu to 1624
    Fri Feb 14 14:27:17 2020 OPTIONS IMPORT: data channel crypto options modified
    Fri Feb 14 14:27:17 2020 Outgoing Data Channel: Cipher 'AES-192-GCM' initialized with 192 bit key
    Fri Feb 14 14:27:17 2020 Incoming Data Channel: Cipher 'AES-192-GCM' initialized with 192 bit key
    Fri Feb 14 14:27:17 2020 interactive service msg_channel=632
    Fri Feb 14 14:27:17 2020 ROUTE_GATEWAY 192.168.1.1/255.255.255.0 I=19 HWADDR=MAC
    Fri Feb 14 14:27:17 2020 GDG6: remote_host_ipv6=n/a
    Fri Feb 14 14:27:17 2020 GetBestInterfaceEx() returned if=19
    Fri Feb 14 14:27:17 2020 GDG6: II=19 DP=::/0 NH=
    Fri Feb 14 14:27:17 2020 GDG6: Metric=256, Loopback=0, AA=1, I=0
    Fri Feb 14 14:27:17 2020 ROUTE6_GATEWAY ТУТ_IPV6 I=19
    Fri Feb 14 14:27:17 2020 open_tun
    Fri Feb 14 14:27:17 2020 TAP-WIN32 device [Ethernet 2] opened: \\.\Global\{DEA83B90-24C2-4432-B667-F624416583BF}.tap
    Fri Feb 14 14:27:17 2020 TAP-Windows Driver Version 9.23 
    Fri Feb 14 14:27:17 2020 Set TAP-Windows TUN subnet mode network/local/netmask = 10.8.0.0/10.8.0.2/255.255.255.0 [SUCCEEDED]
    Fri Feb 14 14:27:17 2020 Notified TAP-Windows driver to set a DHCP IP/netmask of 10.8.0.2/255.255.255.0 on interface {DEA83B90-24C2-4432-B667-F624416583BF} [DHCP-serv: 10.8.0.254, lease-time: 31536000]
    Fri Feb 14 14:27:17 2020 Successful ARP Flush on interface [18] {DEA83B90-24C2-4432-B667-F624416583BF}
    Fri Feb 14 14:27:17 2020 MANAGEMENT: >STATE:1581665237,ASSIGN_IP,,10.8.0.2,,,,,IPV6_IP::1000
    Fri Feb 14 14:27:17 2020 add_route_ipv6(АЙПИ6::/112 -> АЙПИ6::1000 metric 0) dev Ethernet 2
    Fri Feb 14 14:27:17 2020 IPv6 route addition via service succeeded
    Fri Feb 14 14:27:22 2020 TEST ROUTES: 1/1 succeeded len=0 ret=1 a=0 u/d=up
    Fri Feb 14 14:27:22 2020 C:\Windows\system32\route.exe ADD АЙПИ СЕРВЕРА MASK 255.255.255.255 192.168.1.1
    Fri Feb 14 14:27:22 2020 Route addition via service succeeded
    Fri Feb 14 14:27:22 2020 C:\Windows\system32\route.exe ADD 0.0.0.0 MASK 128.0.0.0 10.8.0.1
    Fri Feb 14 14:27:22 2020 Route addition via service succeeded
    Fri Feb 14 14:27:22 2020 C:\Windows\system32\route.exe ADD 128.0.0.0 MASK 128.0.0.0 10.8.0.1
    Fri Feb 14 14:27:22 2020 Route addition via service succeeded
    Fri Feb 14 14:27:22 2020 add_route_ipv6(::/0 -> АЙПИ6::1 metric -1) dev Ethernet 2
    Fri Feb 14 14:27:22 2020 IPv6 route addition via service succeeded
    Fri Feb 14 14:27:22 2020 add_route_ipv6(::/3 -> АЙПИ6::1 metric -1) dev Ethernet 2
    Fri Feb 14 14:27:22 2020 IPv6 route addition via service succeeded
    Fri Feb 14 14:27:22 2020 add_route_ipv6(2000::/4 -> АЙПИ6::1 metric -1) dev Ethernet 2
    Fri Feb 14 14:27:22 2020 IPv6 route addition via service succeeded
    Fri Feb 14 14:27:22 2020 add_route_ipv6(3000::/4 -> АЙПИ6::1 metric -1) dev Ethernet 2
    Fri Feb 14 14:27:22 2020 IPv6 route addition via service succeeded
    Fri Feb 14 14:27:22 2020 add_route_ipv6(fc00::/7 -> АЙПИ6::1 metric -1) dev Ethernet 2
    Fri Feb 14 14:27:22 2020 IPv6 route addition via service succeeded
    Fri Feb 14 14:27:22 2020 Initialization Sequence Completed
    Fri Feb 14 14:27:22 2020 MANAGEMENT: >STATE:1581665242,CONNECTED,SUCCESS,10.8.0.2,АЙПИ СЕРВЕРА,ПОРТ ОПЕНВПН,,,АЙПИ6::1000
  • Как сконфигурировать openvpn server, чтобы через него шёл не весь трафик от клиентов, а только на определённые адреса назначения?

    @onlyjusttruth Автор вопроса
    Так там ведь в начале строки знак комментирования? Разве # не действует на всю строку?