Hallo,
seit kurzem spinnt mein openvpn auf einem Server 11.4, nachdem es
jahrelang bestens funktionierte.
Und zwar wird kein tun-Interface mehr aufgebaut.
Geändert habe ich weder in der config was, noch Software updates
eingespielt.
Die Logs geben (für mich) nichts her.
Auch ein update auf openvpn 2.3.4 hat nichts geändert.
Mit openvpn --mktun --dev tun0
wird das device erzeugt und mit --rmtun entfernt
Auch der Freigabeport 1195 fehlt, wenn man mit nmap schaut.
Jede Hilfe ist willkommen, da auf dem Server noch viele andere Sachen
laufen, ist ein update nur schwer möglich.
mfg
K. Müller
Anbei das log:
Mon Jul 7 18:25:31 2014 us=387260 Current Parameter Settings:
Mon Jul 7 18:25:31 2014 us=387328 config = '/etc/openvpn/achsrv1.conf'
Mon Jul 7 18:25:31 2014 us=387338 mode = 0
Mon Jul 7 18:25:31 2014 us=387347 persist_config = DISABLED
Mon Jul 7 18:25:31 2014 us=387355 persist_mode = 1
Mon Jul 7 18:25:31 2014 us=387363 show_ciphers = DISABLED
Mon Jul 7 18:25:31 2014 us=387371 show_digests = DISABLED
Mon Jul 7 18:25:31 2014 us=387379 show_engines = DISABLED
Mon Jul 7 18:25:31 2014 us=387387 genkey = DISABLED
Mon Jul 7 18:25:31 2014 us=387396 key_pass_file = '[UNDEF]'
Mon Jul 7 18:25:31 2014 us=387404 show_tls_ciphers = DISABLED
Mon Jul 7 18:25:31 2014 us=387412 Connection profiles [default]:
Mon Jul 7 18:25:31 2014 us=387420 proto = tcp-server
Mon Jul 7 18:25:31 2014 us=387428 local = '192.168.70.1'
Mon Jul 7 18:25:31 2014 us=387436 local_port = 1195
Mon Jul 7 18:25:31 2014 us=387444 remote = '[UNDEF]'
Mon Jul 7 18:25:31 2014 us=387452 remote_port = 1195
Mon Jul 7 18:25:31 2014 us=387460 remote_float = DISABLED
Mon Jul 7 18:25:31 2014 us=387468 bind_defined = DISABLED
Mon Jul 7 18:25:31 2014 us=387475 bind_local = ENABLED
Mon Jul 7 18:25:31 2014 us=387484 connect_retry_seconds = 5
Mon Jul 7 18:25:31 2014 us=387492 connect_timeout = 10
Mon Jul 7 18:25:31 2014 us=387500 connect_retry_max = 0
Mon Jul 7 18:25:31 2014 us=387508 socks_proxy_server = '[UNDEF]'
Mon Jul 7 18:25:31 2014 us=387516 socks_proxy_port = 0
Mon Jul 7 18:25:31 2014 us=387524 socks_proxy_retry = DISABLED
Mon Jul 7 18:25:31 2014 us=387532 tun_mtu = 1500
Mon Jul 7 18:25:31 2014 us=387539 tun_mtu_defined = ENABLED
Mon Jul 7 18:25:31 2014 us=387548 link_mtu = 1500
Mon Jul 7 18:25:31 2014 us=387556 link_mtu_defined = DISABLED
Mon Jul 7 18:25:31 2014 us=387563 tun_mtu_extra = 0
Mon Jul 7 18:25:31 2014 us=387571 tun_mtu_extra_defined = DISABLED
Mon Jul 7 18:25:31 2014 us=387579 mtu_discover_type = -1
Mon Jul 7 18:25:31 2014 us=387587 fragment = 0
Mon Jul 7 18:25:31 2014 us=387595 mssfix = 1450
Mon Jul 7 18:25:31 2014 us=387603 explicit_exit_notification = 0
Mon Jul 7 18:25:31 2014 us=387830 Connection profiles END
Mon Jul 7 18:25:31 2014 us=387840 remote_random = DISABLED
Mon Jul 7 18:25:31 2014 us=387848 ipchange = '[UNDEF]'
Mon Jul 7 18:25:31 2014 us=387856 dev = 'tun0'
Mon Jul 7 18:25:31 2014 us=387864 dev_type = '[UNDEF]'
Mon Jul 7 18:25:31 2014 us=387872 dev_node = '[UNDEF]'
Mon Jul 7 18:25:31 2014 us=387880 lladdr = '[UNDEF]'
Mon Jul 7 18:25:31 2014 us=387888 topology = 1
Mon Jul 7 18:25:31 2014 us=387896 tun_ipv6 = DISABLED
Mon Jul 7 18:25:31 2014 us=387917 ifconfig_local = '192.168.1.1'
Mon Jul 7 18:25:31 2014 us=387925 ifconfig_remote_netmask = '192.168.1.3'
Mon Jul 7 18:25:31 2014 us=388146 ifconfig_noexec = DISABLED
Mon Jul 7 18:25:31 2014 us=388156 ifconfig_nowarn = DISABLED
Mon Jul 7 18:25:31 2014 us=388164 ifconfig_ipv6_local = '[UNDEF]'
Mon Jul 7 18:25:31 2014 us=388172 ifconfig_ipv6_netbits = 0
Mon Jul 7 18:25:31 2014 us=388180 ifconfig_ipv6_remote = '[UNDEF]'
Mon Jul 7 18:25:31 2014 us=388188 shaper = 0
Mon Jul 7 18:25:31 2014 us=388196 mtu_test = 0
Mon Jul 7 18:25:31 2014 us=388204 mlock = DISABLED
Mon Jul 7 18:25:31 2014 us=388212 keepalive_ping = 0
Mon Jul 7 18:25:31 2014 us=388220 keepalive_timeout = 0
Mon Jul 7 18:25:31 2014 us=388228 inactivity_timeout = 0
Mon Jul 7 18:25:31 2014 us=388236 ping_send_timeout = 15
Mon Jul 7 18:25:31 2014 us=388244 ping_rec_timeout = 45
Mon Jul 7 18:25:31 2014 us=388252 ping_rec_timeout_action = 2
Mon Jul 7 18:25:31 2014 us=388260 ping_timer_remote = ENABLED
Mon Jul 7 18:25:31 2014 us=388268 remap_sigusr1 = 0
Mon Jul 7 18:25:31 2014 us=388276 persist_tun = ENABLED
Mon Jul 7 18:25:31 2014 us=388284 persist_local_ip = DISABLED
Mon Jul 7 18:25:31 2014 us=388292 persist_remote_ip = DISABLED
Mon Jul 7 18:25:31 2014 us=388300 persist_key = ENABLED
Mon Jul 7 18:25:31 2014 us=388308 passtos = DISABLED
Mon Jul 7 18:25:31 2014 us=388316 resolve_retry_seconds = 1000000000
Mon Jul 7 18:25:31 2014 us=388329 username = 'nobody'
Mon Jul 7 18:25:31 2014 us=388338 groupname = 'nobody'
Mon Jul 7 18:25:31 2014 us=388346 chroot_dir = '[UNDEF]'
Mon Jul 7 18:25:31 2014 us=388353 cd_dir = '/etc/openvpn'
Mon Jul 7 18:25:31 2014 us=388362 writepid =
'/var/run/openvpn/achsrv1.pid'
Mon Jul 7 18:25:31 2014 us=388370 up_script = './achsrv1.up'
Mon Jul 7 18:25:31 2014 us=388378 down_script = './achsrv1.down'
Mon Jul 7 18:25:31 2014 us=388386 down_pre = DISABLED
Mon Jul 7 18:25:31 2014 us=388395 up_restart = DISABLED
Mon Jul 7 18:25:31 2014 us=388402 up_delay = ENABLED
Mon Jul 7 18:25:31 2014 us=388410 daemon = ENABLED
Mon Jul 7 18:25:31 2014 us=388418 inetd = 0
Mon Jul 7 18:25:31 2014 us=388426 log = ENABLED
Mon Jul 7 18:25:31 2014 us=388435 suppress_timestamps = DISABLED
Mon Jul 7 18:25:31 2014 us=388442 nice = 0
Mon Jul 7 18:25:31 2014 us=388451 verbosity = 8
Mon Jul 7 18:25:31 2014 us=388459 mute = 0
Mon Jul 7 18:25:31 2014 us=388467 gremlin = 0
Mon Jul 7 18:25:31 2014 us=388475 status_file = '[UNDEF]'
Mon Jul 7 18:25:31 2014 us=388483 status_file_version = 1
Mon Jul 7 18:25:31 2014 us=388491 status_file_update_freq = 60
Mon Jul 7 18:25:31 2014 us=388499 occ = ENABLED
Mon Jul 7 18:25:31 2014 us=388507 rcvbuf = 65536
Mon Jul 7 18:25:31 2014 us=388515 sndbuf = 65536
Mon Jul 7 18:25:31 2014 us=388523 mark = 0
Mon Jul 7 18:25:31 2014 us=388531 sockflags = 0
Mon Jul 7 18:25:31 2014 us=388539 fast_io = DISABLED
Mon Jul 7 18:25:31 2014 us=388547 lzo = 7
Mon Jul 7 18:25:31 2014 us=388555 route_script = '[UNDEF]'
Mon Jul 7 18:25:31 2014 us=388563 route_default_gateway = '[UNDEF]'
Mon Jul 7 18:25:31 2014 us=388571 route_default_metric = 0
Mon Jul 7 18:25:31 2014 us=388579 route_noexec = DISABLED
Mon Jul 7 18:25:31 2014 us=388588 route_delay = 0
Mon Jul 7 18:25:31 2014 us=388595 route_delay_window = 30
Mon Jul 7 18:25:31 2014 us=388604 route_delay_defined = DISABLED
Mon Jul 7 18:25:31 2014 us=388612 route_nopull = DISABLED
Mon Jul 7 18:25:31 2014 us=388620 route_gateway_via_dhcp = DISABLED
Mon Jul 7 18:25:31 2014 us=388628 max_routes = 100
Mon Jul 7 18:25:31 2014 us=388636 allow_pull_fqdn = DISABLED
Mon Jul 7 18:25:31 2014 us=388644 management_addr = '[UNDEF]'
Mon Jul 7 18:25:31 2014 us=388652 management_port = 0
Mon Jul 7 18:25:31 2014 us=388660 management_user_pass = '[UNDEF]'
Mon Jul 7 18:25:31 2014 us=388669 management_log_history_cache = 250
Mon Jul 7 18:25:31 2014 us=388677 management_echo_buffer_size = 100
Mon Jul 7 18:25:31 2014 us=388685 management_write_peer_info_file =
'[UNDEF]'
Mon Jul 7 18:25:31 2014 us=388693 management_client_user = '[UNDEF]'
Mon Jul 7 18:25:31 2014 us=388701 management_client_group = '[UNDEF]'
Mon Jul 7 18:25:31 2014 us=388709 management_flags = 0
Mon Jul 7 18:25:31 2014 us=388717 shared_secret_file = '[UNDEF]'
Mon Jul 7 18:25:31 2014 us=388726 key_direction = 0
Mon Jul 7 18:25:31 2014 us=388734 ciphername_defined = ENABLED
Mon Jul 7 18:25:31 2014 us=388742 ciphername = 'BF-CBC'
Mon Jul 7 18:25:31 2014 us=388750 authname_defined = ENABLED
Mon Jul 7 18:25:31 2014 us=388758 authname = 'SHA1'
Mon Jul 7 18:25:31 2014 us=388766 prng_hash = 'SHA1'
Mon Jul 7 18:25:31 2014 us=388774 prng_nonce_secret_len = 16
Mon Jul 7 18:25:31 2014 us=388782 keysize = 0
Mon Jul 7 18:25:31 2014 us=388790 engine = DISABLED
Mon Jul 7 18:25:31 2014 us=388798 replay = ENABLED
Mon Jul 7 18:25:31 2014 us=388806 mute_replay_warnings = DISABLED
Mon Jul 7 18:25:31 2014 us=388817 replay_window = 64
Mon Jul 7 18:25:31 2014 us=388826 replay_time = 15
Mon Jul 7 18:25:31 2014 us=388834 packet_id_file = '[UNDEF]'
Mon Jul 7 18:25:31 2014 us=388842 use_iv = ENABLED
Mon Jul 7 18:25:31 2014 us=388850 test_crypto = DISABLED
Mon Jul 7 18:25:31 2014 us=388858 tls_server = ENABLED
Mon Jul 7 18:25:31 2014 us=388891 tls_client = DISABLED
Mon Jul 7 18:25:31 2014 us=388901 key_method = 2
Mon Jul 7 18:25:31 2014 us=388917 ca_file = 'ca.crt'
Mon Jul 7 18:25:31 2014 us=388925 ca_path = '[UNDEF]'
Mon Jul 7 18:25:31 2014 us=388933 dh_file = 'dh1024.pem'
Mon Jul 7 18:25:31 2014 us=388941 cert_file = 'server.crt'
Mon Jul 7 18:25:31 2014 us=388949 priv_key_file = 'server.key'
Mon Jul 7 18:25:31 2014 us=388957 pkcs12_file = '[UNDEF]'
Mon Jul 7 18:25:31 2014 us=388965 cipher_list = '[UNDEF]'
Mon Jul 7 18:25:31 2014 us=388973 tls_verify = '[UNDEF]'
Mon Jul 7 18:25:31 2014 us=388981 tls_export_cert = '[UNDEF]'
Mon Jul 7 18:25:31 2014 us=388989 verify_x509_type = 0
Mon Jul 7 18:25:31 2014 us=388998 verify_x509_name = '[UNDEF]'
Mon Jul 7 18:25:31 2014 us=389007 crl_file = '[UNDEF]'
Mon Jul 7 18:25:31 2014 us=389014 ns_cert_type = 0
Mon Jul 7 18:25:31 2014 us=389023 remote_cert_ku[i] = 0
Mon Jul 7 18:25:31 2014 us=389031 remote_cert_ku[i] = 0
Mon Jul 7 18:25:31 2014 us=389039 remote_cert_ku[i] = 0
Mon Jul 7 18:25:31 2014 us=389047 remote_cert_ku[i] = 0
Mon Jul 7 18:25:31 2014 us=389054 remote_cert_ku[i] = 0
Mon Jul 7 18:25:31 2014 us=389062 remote_cert_ku[i] = 0
Mon Jul 7 18:25:31 2014 us=389070 remote_cert_ku[i] = 0
Mon Jul 7 18:25:31 2014 us=389078 remote_cert_ku[i] = 0
Mon Jul 7 18:25:31 2014 us=389086 remote_cert_ku[i] = 0
Mon Jul 7 18:25:31 2014 us=389094 remote_cert_ku[i] = 0
Mon Jul 7 18:25:31 2014 us=389102 remote_cert_ku[i] = 0
Mon Jul 7 18:25:31 2014 us=389110 remote_cert_ku[i] = 0
Mon Jul 7 18:25:31 2014 us=389118 remote_cert_ku[i] = 0
Mon Jul 7 18:25:31 2014 us=389126 remote_cert_ku[i] = 0
Mon Jul 7 18:25:31 2014 us=389134 remote_cert_ku[i] = 0
Mon Jul 7 18:25:31 2014 us=389142 remote_cert_ku[i] = 0
Mon Jul 7 18:25:31 2014 us=389150 remote_cert_eku = '[UNDEF]'
Mon Jul 7 18:25:31 2014 us=389158 ssl_flags = 0
Mon Jul 7 18:25:31 2014 us=389165 tls_timeout = 2
Mon Jul 7 18:25:31 2014 us=389174 renegotiate_bytes = 0
Mon Jul 7 18:25:31 2014 us=389182 renegotiate_packets = 0
Mon Jul 7 18:25:31 2014 us=389190 renegotiate_seconds = 3600
Mon Jul 7 18:25:31 2014 us=389198 handshake_window = 60
Mon Jul 7 18:25:31 2014 us=389207 transition_window = 3600
Mon Jul 7 18:25:31 2014 us=389214 single_session = DISABLED
Mon Jul 7 18:25:31 2014 us=389223 push_peer_info = DISABLED
Mon Jul 7 18:25:31 2014 us=389230 tls_exit = DISABLED
Mon Jul 7 18:25:31 2014 us=389239 tls_auth_file = '[UNDEF]'
Mon Jul 7 18:25:31 2014 us=389253 server_network = 0.0.0.0
Mon Jul 7 18:25:31 2014 us=389263 server_netmask = 0.0.0.0
Mon Jul 7 18:25:31 2014 us=389274 server_network_ipv6 = ::
Mon Jul 7 18:25:31 2014 us=389282 server_netbits_ipv6 = 0
Mon Jul 7 18:25:31 2014 us=389291 server_bridge_ip = 0.0.0.0
Mon Jul 7 18:25:31 2014 us=389299 server_bridge_netmask = 0.0.0.0
Mon Jul 7 18:25:31 2014 us=389308 server_bridge_pool_start = 0.0.0.0
Mon Jul 7 18:25:31 2014 us=389317 server_bridge_pool_end = 0.0.0.0
Mon Jul 7 18:25:31 2014 us=389325 ifconfig_pool_defined = DISABLED
Mon Jul 7 18:25:31 2014 us=389334 ifconfig_pool_start = 0.0.0.0
Mon Jul 7 18:25:31 2014 us=389342 ifconfig_pool_end = 0.0.0.0
Mon Jul 7 18:25:31 2014 us=389351 ifconfig_pool_netmask = 0.0.0.0
Mon Jul 7 18:25:31 2014 us=389359 ifconfig_pool_persist_filename =
'[UNDEF]'
Mon Jul 7 18:25:31 2014 us=389367 ifconfig_pool_persist_refresh_freq = 600
Mon Jul 7 18:25:31 2014 us=389377 ifconfig_ipv6_pool_defined = DISABLED
Mon Jul 7 18:25:31 2014 us=389386 ifconfig_ipv6_pool_base = ::
Mon Jul 7 18:25:31 2014 us=389394 ifconfig_ipv6_pool_netbits = 0
Mon Jul 7 18:25:31 2014 us=389402 n_bcast_buf = 256
Mon Jul 7 18:25:31 2014 us=389410 tcp_queue_limit = 64
Mon Jul 7 18:25:31 2014 us=389419 real_hash_size = 256
Mon Jul 7 18:25:31 2014 us=389427 virtual_hash_size = 256
Mon Jul 7 18:25:31 2014 us=389434 client_connect_script = '[UNDEF]'
Mon Jul 7 18:25:31 2014 us=389443 learn_address_script = '[UNDEF]'
Mon Jul 7 18:25:31 2014 us=389450 client_disconnect_script = '[UNDEF]'
Mon Jul 7 18:25:31 2014 us=389459 client_config_dir = '[UNDEF]'
Mon Jul 7 18:25:31 2014 us=389471 ccd_exclusive = DISABLED
Mon Jul 7 18:25:31 2014 us=389479 tmp_dir = '/tmp'
Mon Jul 7 18:25:31 2014 us=389487 push_ifconfig_defined = DISABLED
Mon Jul 7 18:25:31 2014 us=389496 push_ifconfig_local = 0.0.0.0
Mon Jul 7 18:25:31 2014 us=389506 push_ifconfig_remote_netmask = 0.0.0.0
Mon Jul 7 18:25:31 2014 us=389515 push_ifconfig_ipv6_defined = DISABLED
Mon Jul 7 18:25:31 2014 us=389523 push_ifconfig_ipv6_local = ::/0
Mon Jul 7 18:25:31 2014 us=389532 push_ifconfig_ipv6_remote = ::
Mon Jul 7 18:25:31 2014 us=389539 enable_c2c = DISABLED
Mon Jul 7 18:25:31 2014 us=389547 duplicate_cn = DISABLED
Mon Jul 7 18:25:31 2014 us=389556 cf_max = 0
Mon Jul 7 18:25:31 2014 us=389564 cf_per = 0
Mon Jul 7 18:25:31 2014 us=389572 max_clients = 1024
Mon Jul 7 18:25:31 2014 us=389580 max_routes_per_client = 256
Mon Jul 7 18:25:31 2014 us=389588 auth_user_pass_verify_script =
'[UNDEF]'
Mon Jul 7 18:25:31 2014 us=389596 auth_user_pass_verify_script_via_file
= DISABLED
Mon Jul 7 18:25:31 2014 us=389603 port_share_host = '[UNDEF]'
Mon Jul 7 18:25:31 2014 us=389612 port_share_port = 0
Mon Jul 7 18:25:31 2014 us=389620 client = DISABLED
Mon Jul 7 18:25:31 2014 us=389627 pull = DISABLED
Mon Jul 7 18:25:31 2014 us=389635 auth_user_pass_file = '[UNDEF]'
Mon Jul 7 18:25:31 2014 us=389646 OpenVPN 2.3.4
x86_64-unknown-linux-gnu [SSL (OpenSSL)] [LZO] [EPOLL] [MH] [IPv6] built
on Jul 7 2014
Mon Jul 7 18:25:31 2014 us=389658 library versions: OpenSSL 1.0.0k 5
Feb 2013, LZO 2.04
Mon Jul 7 18:25:31 2014 us=389802 NOTE: the current --script-security
setting may allow this configuration to call user-defined scripts
Mon Jul 7 18:25:31 2014 us=389820 PO_INIT maxevents=4 flags=0x00000002
Mon Jul 7 18:25:31 2014 us=391595 Diffie-Hellman initialized with 1024
bit key
Mon Jul 7 18:25:31 2014 us=392721 PRNG init md=SHA1 size=36
Mon Jul 7 18:25:31 2014 us=392751 LZO compression initialized
Mon Jul 7 18:25:31 2014 us=392764 MTU DYNAMIC mtu=0, flags=1, 0 -> 140
Mon Jul 7 18:25:31 2014 us=392776 PID packet_id_init tcp_mode=1
seq_backtrack=64 time_backtrack=15
Mon Jul 7 18:25:31 2014 us=392828 PID packet_id_init tcp_mode=1
seq_backtrack=64 time_backtrack=15
Mon Jul 7 18:25:31 2014 us=392838 PID packet_id_init tcp_mode=1
seq_backtrack=64 time_backtrack=15
Mon Jul 7 18:25:31 2014 us=392898 PID packet_id_init tcp_mode=1
seq_backtrack=64 time_backtrack=15
Mon Jul 7 18:25:31 2014 us=392910 Control Channel MTU parms [ L:1544
D:140 EF:40 EB:0 ET:0 EL:0 ]
Mon Jul 7 18:25:31 2014 us=392929 MTU DYNAMIC mtu=1450, flags=2, 1544
-> 1450
Mon Jul 7 18:25:31 2014 us=392953 Socket Buffers: R=[4194304->131072]
S=[4194304->131072]
Mon Jul 7 18:25:31 2014 us=393016 Data Channel MTU parms [ L:1544
D:1450 EF:44 EB:135 ET:0 EL:0 AF:3/1 ]
Mon Jul 7 18:25:31 2014 us=393109 Local Options String: 'V4,dev-type
tun,link-mtu 1544,tun-mtu 1500,proto TCPv4_SERVER,ifconfig 192.168.1.3
192.168.1.1,comp-lzo,cipher BF-CBC,auth SHA1,keysize 128,key-method
2,tls-server'
Mon Jul 7 18:25:31 2014 us=393118 Expected Remote Options String:
'V4,dev-type tun,link-mtu 1544,tun-mtu 1500,proto TCPv4_CLIENT,ifconfig
192.168.1.1 192.168.1.3,comp-lzo,cipher BF-CBC,auth SHA1,keysize
128,key-method 2,tls-client'
Mon Jul 7 18:25:31 2014 us=393351 Local Options hash (VER=V4): 'e6a0d64b'
Mon Jul 7 18:25:31 2014 us=393368 Expected Remote Options hash
(VER=V4): 'cd3cc9a5'
Mon Jul 7 18:25:31 2014 us=393899 NOTE: UID/GID downgrade will be
delayed because of --client, --pull, or --up-delay
Mon Jul 7 18:25:31 2014 us=393983 Listening for incoming TCP connection
on [AF_INET]192.168.70.1:1195