我最近格式化了我的 Windows 7 电脑,丢失了客户端的 OpenVPN 配置文件。我恢复了服务器上剩余的证书和默认配置,但我无法让整个系统重新运行。我认为服务器的配置和路由表没有问题,因为它之前运行正常(尽管已经是很久以前了)。
各位专家能帮忙吗?
服务器配置文件
# Serveur TCP/666
mode server
proto udp
port 666
dev tun
# Cles et certificats
ca ca.crt
cert server.crt
key server.key
dh dh1024.pem
tls-auth ta.key 0
cipher AES-256-CBC
# Reseau
server 10.8.0.0 255.255.255.0
#push "redirect-gateway def1 bypass-dhcp"
push "dhcp-option DNS 208.67.222.222"
push "dhcp-option DNS 208.67.220.220"
push "redirect-gateway def1"
keepalive 10 120
# Securite
user nobody
group nogroup
chroot /etc/openvpn/jail
persist-key
persist-tun
comp-lzo
# Log
verb 3
mute 20
status openvpn-status.log
log-append /var/log/openvpn.log
客户端配置文件
# Client
client
dev tun
proto udp
remote *my server's ip address*:666
cipher AES-256-CBC
# Cles
ca ca.crt
cert client1.crt
key client1.key
tls-auth ta.key 1
# Securite
nobind
persist-key
persist-tun
comp-lzo
verb 3
OpenVPN 服务器运行时 Debian 服务器上的路由表:
Destination Gateway Genmask Indic Metric Ref Use Iface
10.8.0.2 * 255.255.255.255 UH 0 0 0 tun0
10.8.0.0 10.8.0.2 255.255.255.0 UG 0 0 0 tun0
my server's ip * 255.255.255.0 U 0 0 0 eth0
default 72815.trg.dedic 0.0.0.0 UG 0 0 0 eth0
Windows 7 客户端上的路由表(OpenVPN 不起作用)
===========================================================================
Interface List
19...00 f0 8a 1b 6e 5c ......TAP-Win32 Adapter V9
12...90 2e 34 33 84 7b ......Atheros AR8151 PCI-E Gigabit Ethernet Controller (
NDIS 6.20)
1...........................Software Loopback Interface 1
12...00 00 00 00 00 00 00 e0 Microsoft ISATAP Adapter
13...00 00 00 00 00 00 00 e0 Teredo Tunneling Pseudo-Interface
16...00 00 00 00 00 00 00 e0 Microsoft ISATAP Adapter #2
===========================================================================
IPv4 Route Table
===========================================================================
Active Routes:
Network Destination Netmask Gateway Interface Metric
0.0.0.0 0.0.0.0 192.168.1.1 192.168.1.11 20
127.0.0.0 255.0.0.0 On-link 127.0.0.1 306
127.0.0.1 255.255.255.255 On-link 127.0.0.1 306
127.255.255.255 255.255.255.255 On-link 127.0.0.1 306
192.168.1.0 255.255.255.0 On-link 192.168.1.11 276
192.168.1.11 255.255.255.255 On-link 192.168.1.11 276
192.168.1.255 255.255.255.255 On-link 192.168.1.11 276
224.0.0.0 240.0.0.0 On-link 127.0.0.1 306
224.0.0.0 240.0.0.0 On-link 192.168.1.11 276
255.255.255.255 255.255.255.255 On-link 127.0.0.1 306
255.255.255.255 255.255.255.255 On-link 192.168.1.11 276
===========================================================================
Persistent Routes:
None
IPv6 Route Table
===========================================================================
Active Routes:
[...]
===========================================================================
Persistent Routes:
None
当我的客户端和服务器之间建立链接时:服务器的路由表保持不变。客户端的路由表变为:
===========================================================================
Interface List
19...00 f0 8a 1b 6e 5c ......TAP-Win32 Adapter V9
12...90 2e 34 33 84 7b ......Atheros AR8151 PCI-E Gigabit Ethernet Controller (
NDIS 6.20)
1...........................Software Loopback Interface 1
12...00 00 00 00 00 00 00 e0 Microsoft ISATAP Adapter
13...00 00 00 00 00 00 00 e0 Teredo Tunneling Pseudo-Interface
16...00 00 00 00 00 00 00 e0 Microsoft ISATAP Adapter #2
===========================================================================
IPv4 Route Table
===========================================================================
Active Routes:
Network Destination Netmask Gateway Interface Metric
0.0.0.0 0.0.0.0 192.168.1.1 192.168.1.11 20
0.0.0.0 128.0.0.0 10.8.0.5 10.8.0.6 30
10.8.0.1 255.255.255.255 10.8.0.5 10.8.0.6 30
10.8.0.4 255.255.255.252 On-link 10.8.0.6 286
10.8.0.6 255.255.255.255 On-link 10.8.0.6 286
10.8.0.7 255.255.255.255 On-link 10.8.0.6 286
my server's ip 255.255.255.255 192.168.1.1 192.168.1.11 20
127.0.0.0 255.0.0.0 On-link 127.0.0.1 306
127.0.0.1 255.255.255.255 On-link 127.0.0.1 306
127.255.255.255 255.255.255.255 On-link 127.0.0.1 306
128.0.0.0 128.0.0.0 10.8.0.5 10.8.0.6 30
192.168.1.0 255.255.255.0 On-link 192.168.1.11 276
192.168.1.11 255.255.255.255 On-link 192.168.1.11 276
192.168.1.255 255.255.255.255 On-link 192.168.1.11 276
224.0.0.0 240.0.0.0 On-link 127.0.0.1 306
224.0.0.0 240.0.0.0 On-link 192.168.1.11 276
224.0.0.0 240.0.0.0 On-link 10.8.0.6 286
255.255.255.255 255.255.255.255 On-link 127.0.0.1 306
255.255.255.255 255.255.255.255 On-link 192.168.1.11 276
255.255.255.255 255.255.255.255 On-link 10.8.0.6 286
===========================================================================
Persistent Routes:
None
正在起作用的是:
- 服务器和客户端确实相互连接,SSL 证书没有问题。
- 客户端从服务器获取 IP(10.8.0.6)
- OpenVPN 客户端以管理员身份启动。
但:
- 我无法从任意一边 ping 通另一个。
- 客户端的“网关”值为空(在适配器的“状态”窗口中)。
- 当链接接通时,客户端无法访问互联网。
理想配置:
- 我只希望客户端能够使用服务器的互联网访问并访问其资源(特别是 MySQL 服务器)。
- 我不需要或不想让服务器访问客户端的本地网络。
- 尽管所有互联网流量都应重定向到 VPN 链接,但客户端需要能够访问其本地网络。
我花了相当多的时间在这上面但它仍然没有作用,任何帮助都将非常感激。
谢谢 :)