OpenVPN 配置 - Windows 7 客户端和 Debian 服务器

OpenVPN 配置 - Windows 7 客户端和 Debian 服务器

我最近格式化了我的 Windows 7 电脑,丢失了客户端的 OpenVPN 配置文件。我恢复了服务器上剩余的证书和默认配置,但我无法让整个系统重新运行。我认为服务器的配置和路由表没有问题,因为它之前运行正常(尽管已经是很久以前了)。

各位专家能帮忙吗?

服务器配置文件

# Serveur TCP/666
mode server
proto udp
port 666
dev tun

# Cles et certificats
ca ca.crt
cert server.crt
key server.key
dh dh1024.pem
tls-auth ta.key 0
cipher AES-256-CBC

# Reseau
server 10.8.0.0 255.255.255.0
#push "redirect-gateway def1 bypass-dhcp"
push "dhcp-option DNS 208.67.222.222"
push "dhcp-option DNS 208.67.220.220"
push "redirect-gateway def1"
keepalive 10 120

# Securite
user nobody
group nogroup
chroot /etc/openvpn/jail
persist-key
persist-tun
comp-lzo

# Log
verb 3
mute 20
status openvpn-status.log
log-append /var/log/openvpn.log

客户端配置文件

# Client

client
dev tun
proto udp
remote *my server's ip address*:666
cipher AES-256-CBC

# Cles
ca ca.crt
cert client1.crt
key client1.key
tls-auth ta.key 1

# Securite
nobind
persist-key
persist-tun
comp-lzo
verb 3

OpenVPN 服务器运行时 Debian 服务器上的路由表:

Destination     Gateway      Genmask         Indic Metric Ref    Use Iface
10.8.0.2        *               255.255.255.255 UH    0      0        0 tun0
10.8.0.0        10.8.0.2        255.255.255.0   UG    0      0        0 tun0
my server's ip  *               255.255.255.0   U     0      0        0 eth0
default         72815.trg.dedic 0.0.0.0         UG    0      0        0 eth0

Windows 7 客户端上的路由表(OpenVPN 不起作用)

===========================================================================
Interface List
 19...00 f0 8a 1b 6e 5c ......TAP-Win32 Adapter V9
 12...90 2e 34 33 84 7b ......Atheros AR8151 PCI-E Gigabit Ethernet Controller (
NDIS 6.20)
  1...........................Software Loopback Interface 1
 12...00 00 00 00 00 00 00 e0 Microsoft ISATAP Adapter
 13...00 00 00 00 00 00 00 e0 Teredo Tunneling Pseudo-Interface
 16...00 00 00 00 00 00 00 e0 Microsoft ISATAP Adapter #2
===========================================================================

IPv4 Route Table
===========================================================================
Active Routes:
Network Destination        Netmask          Gateway       Interface  Metric
          0.0.0.0          0.0.0.0      192.168.1.1     192.168.1.11     20
        127.0.0.0        255.0.0.0         On-link         127.0.0.1    306
        127.0.0.1  255.255.255.255         On-link         127.0.0.1    306
  127.255.255.255  255.255.255.255         On-link         127.0.0.1    306
      192.168.1.0    255.255.255.0         On-link      192.168.1.11    276
     192.168.1.11  255.255.255.255         On-link      192.168.1.11    276
    192.168.1.255  255.255.255.255         On-link      192.168.1.11    276
        224.0.0.0        240.0.0.0         On-link         127.0.0.1    306
        224.0.0.0        240.0.0.0         On-link      192.168.1.11    276
  255.255.255.255  255.255.255.255         On-link         127.0.0.1    306
  255.255.255.255  255.255.255.255         On-link      192.168.1.11    276
===========================================================================
Persistent Routes:
  None

IPv6 Route Table
===========================================================================
Active Routes:

[...]

===========================================================================
Persistent Routes:
  None

当我的客户端和服务器之间建立链接时:服务器的路由表保持不变。客户端的路由表变为:

===========================================================================
    Interface List
     19...00 f0 8a 1b 6e 5c ......TAP-Win32 Adapter V9
     12...90 2e 34 33 84 7b ......Atheros AR8151 PCI-E Gigabit Ethernet Controller (
    NDIS 6.20)
      1...........................Software Loopback Interface 1
     12...00 00 00 00 00 00 00 e0 Microsoft ISATAP Adapter
     13...00 00 00 00 00 00 00 e0 Teredo Tunneling Pseudo-Interface
     16...00 00 00 00 00 00 00 e0 Microsoft ISATAP Adapter #2
===========================================================================

IPv4 Route Table
===========================================================================
Active Routes:
Network Destination        Netmask          Gateway       Interface  Metric
          0.0.0.0          0.0.0.0      192.168.1.1     192.168.1.11     20
          0.0.0.0        128.0.0.0         10.8.0.5         10.8.0.6     30
         10.8.0.1  255.255.255.255         10.8.0.5         10.8.0.6     30
         10.8.0.4  255.255.255.252         On-link          10.8.0.6    286
         10.8.0.6  255.255.255.255         On-link          10.8.0.6    286
         10.8.0.7  255.255.255.255         On-link          10.8.0.6    286
     my server's ip  255.255.255.255      192.168.1.1     192.168.1.11     20
        127.0.0.0        255.0.0.0         On-link         127.0.0.1    306
        127.0.0.1  255.255.255.255         On-link         127.0.0.1    306
  127.255.255.255  255.255.255.255         On-link         127.0.0.1    306
        128.0.0.0        128.0.0.0         10.8.0.5         10.8.0.6     30
      192.168.1.0    255.255.255.0         On-link      192.168.1.11    276
     192.168.1.11  255.255.255.255         On-link      192.168.1.11    276
    192.168.1.255  255.255.255.255         On-link      192.168.1.11    276
        224.0.0.0        240.0.0.0         On-link         127.0.0.1    306
        224.0.0.0        240.0.0.0         On-link      192.168.1.11    276
        224.0.0.0        240.0.0.0         On-link          10.8.0.6    286
  255.255.255.255  255.255.255.255         On-link         127.0.0.1    306
  255.255.255.255  255.255.255.255         On-link      192.168.1.11    276
  255.255.255.255  255.255.255.255         On-link          10.8.0.6    286
===========================================================================
Persistent Routes:
  None

正在起作用的是:

  • 服务器和客户端确实相互连接,SSL 证书没有问题。
  • 客户端从服务器获取 IP(10.8.0.6)
  • OpenVPN 客户端以管理员身份启动。

但:

  • 我无法从任意一边 ping 通另一个。
  • 客户端的“网关”值为空(在适配器的“状态”窗口中)。
  • 当链接接通时,客户端无法访问互联网。

理想配置:

  • 我只希望客户端能够使用服务器的互联网访问并访问其资源(特别是 MySQL 服务器)。
  • 我不需要或不想让服务器访问客户端的本地网络。
  • 尽管所有互联网流量都应重定向到 VPN 链接,但客户端需要能够访问其本地网络。

我花了相当多的时间在这上面但它仍然没有作用,任何帮助都将非常感激。

谢谢 :)

相关内容