最近我遇到了一些 OpenVPN 问题,OpenVPN 服务器托管在 VPS 上。它已经运行了几个月,但上周五我重启并更新升级,因为我的 PC 无法连接到 VPN 服务器。
当我检查日志时,有以下内容:
systemd[1]: [email protected]: Main process exited, code=exited, status=1/FAILURE
systemd[1]: [email protected]: Failed with result 'exit-code'.
systemd[1]: [email protected]: Service hold-off time over, scheduling restart.
systemd[1]: [email protected]: Scheduled restart job, restart counter is at 11865.
systemd[1]: Stopped OpenVPN connection to server.
systemd[1]: Failed to set devices.allow on /system.slice/system-openvpn.slice/[email protected]: Operation not permitted
systemd[1]: message repeated 2 times: [ Failed to set devices.allow on /system.slice/system-openvpn.slice/[email protected]: Operation not permitted]
systemd[1]: Starting OpenVPN connection to server...
ovpn-server[11903]: OpenVPN 2.4.4 x86_64-pc-linux-gnu [SSL (OpenSSL)] [LZO] [LZ4] [EPOLL] [PKCS11] [MH/PKTINFO] [AEAD] built on May 14 2019
ovpn-server[11903]: library versions: OpenSSL 1.1.1 11 Sep 2018, LZO 2.08
systemd[1]: Started OpenVPN connection to server.
ovpn-server[11903]: ECDH curve prime256v1 added
ovpn-server[11903]: Outgoing Control Channel Encryption: Cipher 'AES-256-CTR' initialized with 256 bit key
ovpn-server[11903]: Outgoing Control Channel Encryption: Using 256 bit message hash 'SHA256' for HMAC authentication
ovpn-server[11903]: Incoming Control Channel Encryption: Cipher 'AES-256-CTR' initialized with 256 bit key
ovpn-server[11903]: Incoming Control Channel Encryption: Using 256 bit message hash 'SHA256' for HMAC authentication
ovpn-server[11903]: ERROR: Cannot open TUN/TAP dev /dev/net/tun: Operation not permitted (errno=1)
ovpn-server[11903]: Exiting due to fatal error
看来OpenVPN无缘无故就不能使用TUN/TAP dev了。
有人知道吗?问题出在服务器上,而不是客户端(我猜)
谢谢,
更新:
Icon name: computer-container
Chassis: container
Machine ID: bf6e72f90b6d4e1f94220c683fccc1fc
Boot ID: ae58ef408533418a81641dbb52b363eb
Virtualization: openvz
Operating System: Ubuntu 18.04.3 LTS
Kernel: Linux 3.10.0-957.12.2.vz7.96.21
Architecture: x86-64
如何知道 SELINUX 是否已启用?应该启用还是禁用?