Ciao a tutti,
ho creato una VPN con OpenVPN, sfruttando la parte Server fornita da un NAS Synology.
Il tutto è stato abbastanza semplice e l'obiettivo è che 2 client esterni alla rete del NAS, possano accedere alla sua Cartella Condivisa tramite VPN.
Le reti sono le seguenti:
Rete LAN in cui è presente il NAS: 192.168.1.0
Rete LAN in cui sono presenti i 2 clienti esterni: 192.168.1.0
Rete VPN creata da OpenVPN: 10.8.0.0/255.255.255.252
Funziona tutto a dovere, infatti i 2 client si collegano alla VPN, raggiungono la cartella condivisa e continuano a navigare utilizzando il gateway locale, il traffico infatti non è volutamente dirottato verso la VPN.
Fatta tutta la premessa veniamo al problema, magari per molti una banalità, ma non conosco molto le VPN se non per una configurazione passo-passo.
Quando collegati alla VPN, i client non vedono le risorse locali della propria rete, ad esempio non vedono una stampante WiFi che sta nella stessa stanza, come anche altri PC o telecamere.
C'è qualche opzione da aggiungere al file di Config?
Grazie in anticipo a tutti coloro che mi risponderanno.
OUTATIME
06-04-2020, 18:17
Verifica nel file di configurazione dei client di non avere una riga route 192.168.1.0
Nel caso, aggiungi la seguente riga nel file:
verb 5 e posta qui il risultato oscurando il tuo IP pubblico.
Ciao, innanzitutto grazie mille.
Allora, la riga che dici tu non c'è.
Non ho capito, devo mettere comunque verb 5 nel config e poi inviarti il log?
Allego il mio config dove ho asteriscato i dati:
dev tun
tls-client
remote *******
# The "float" tells OpenVPN to accept authenticated packets from any address,
# not only the address which was specified in the --remote option.
# This is useful when you are connecting to a peer which holds a dynamic address
# such as a dial-in user or DHCP client.
# (Please refer to the manual of OpenVPN for more information.)
#float
# If redirect-gateway is enabled, the client will redirect it's
# default network gateway through the VPN.
# It means the VPN connection will firstly connect to the VPN Server
# and then to the internet.
# (Please refer to the manual of OpenVPN for more information.)
#redirect-gateway def1
# dhcp-option DNS: To set primary domain name server address.
# Repeat this option to set secondary DNS server addresses.
dhcp-option DNS 192.168.1.1
pull
# If you want to connect by Server's IPv6 address, you should use
# "proto udp6" in UDP mode or "proto tcp6-client" in TCP mode
proto udp
script-security 2
comp-lzo
reneg-sec 0
cipher AES-256-CBC
auth SHA512
auth-user-pass
<ca>
-----BEGIN CERTIFICATE-----
****
-----END CERTIFICATE-----
</ca>
OUTATIME
06-04-2020, 19:41
Ok, in questo file aggiungi il verb 5, rifai la connessione e salva i log poi postali qui come hai fatto con i dati del file di configurazione, togliendo ovviamente l'ip pubblico.
Altra domanda, tu al nas fai accedere con \\192.168.1 o con \\10.0.8 ?
...
Altra domanda, tu al nas fai accedere con \\192.168.1 o con \\10.0.8 ?
Immagino intendi dai clienti dietro VPN, comunque da quelli accedo con \\10.8.0
Ecco il log, spero non ci siano dati sensibili:
Mon Apr 06 20:47:22 2020 us=984357 Current Parameter Settings:
Mon Apr 06 20:47:22 2020 us=985355 config = 'VPNConfig.ovpn'
Mon Apr 06 20:47:22 2020 us=985355 mode = 0
Mon Apr 06 20:47:22 2020 us=985355 show_ciphers = DISABLED
Mon Apr 06 20:47:22 2020 us=985355 show_digests = DISABLED
Mon Apr 06 20:47:22 2020 us=985355 show_engines = DISABLED
Mon Apr 06 20:47:22 2020 us=985355 genkey = DISABLED
Mon Apr 06 20:47:22 2020 us=985355 key_pass_file = '[UNDEF]'
Mon Apr 06 20:47:22 2020 us=985355 show_tls_ciphers = DISABLED
Mon Apr 06 20:47:22 2020 us=985355 connect_retry_max = 0
Mon Apr 06 20:47:22 2020 us=985355 Connection profiles [0]:
Mon Apr 06 20:47:22 2020 us=985355 proto = udp
Mon Apr 06 20:47:22 2020 us=985355 local = '[UNDEF]'
Mon Apr 06 20:47:22 2020 us=985355 local_port = '***'
Mon Apr 06 20:47:22 2020 us=985355 remote = '***'
Mon Apr 06 20:47:22 2020 us=985355 remote_port = '****'
Mon Apr 06 20:47:22 2020 us=985355 remote_float = DISABLED
Mon Apr 06 20:47:22 2020 us=985355 bind_defined = DISABLED
Mon Apr 06 20:47:22 2020 us=986355 bind_local = ENABLED
Mon Apr 06 20:47:22 2020 us=986355 bind_ipv6_only = DISABLED
Mon Apr 06 20:47:22 2020 us=986355 connect_retry_seconds = 5
Mon Apr 06 20:47:22 2020 us=986355 connect_timeout = 120
Mon Apr 06 20:47:22 2020 us=986355 socks_proxy_server = '[UNDEF]'
Mon Apr 06 20:47:22 2020 us=986355 socks_proxy_port = '[UNDEF]'
Mon Apr 06 20:47:22 2020 us=986355 tun_mtu = 1500
Mon Apr 06 20:47:22 2020 us=986355 tun_mtu_defined = ENABLED
Mon Apr 06 20:47:22 2020 us=986355 link_mtu = 1500
Mon Apr 06 20:47:22 2020 us=986355 link_mtu_defined = DISABLED
Mon Apr 06 20:47:22 2020 us=986355 tun_mtu_extra = 0
Mon Apr 06 20:47:22 2020 us=986355 tun_mtu_extra_defined = DISABLED
Mon Apr 06 20:47:22 2020 us=986355 mtu_discover_type = -1
Mon Apr 06 20:47:22 2020 us=986355 fragment = 0
Mon Apr 06 20:47:22 2020 us=986355 mssfix = 1450
Mon Apr 06 20:47:22 2020 us=986355 explicit_exit_notification = 0
Mon Apr 06 20:47:22 2020 us=986355 Connection profiles END
Mon Apr 06 20:47:22 2020 us=986355 remote_random = DISABLED
Mon Apr 06 20:47:22 2020 us=986355 ipchange = '[UNDEF]'
Mon Apr 06 20:47:22 2020 us=986355 dev = 'tun'
Mon Apr 06 20:47:22 2020 us=986355 dev_type = '[UNDEF]'
Mon Apr 06 20:47:22 2020 us=986355 dev_node = '[UNDEF]'
Mon Apr 06 20:47:22 2020 us=986355 lladdr = '[UNDEF]'
Mon Apr 06 20:47:22 2020 us=986355 topology = 1
Mon Apr 06 20:47:22 2020 us=986355 ifconfig_local = '[UNDEF]'
Mon Apr 06 20:47:22 2020 us=986355 ifconfig_remote_netmask = '[UNDEF]'
Mon Apr 06 20:47:22 2020 us=986355 ifconfig_noexec = DISABLED
Mon Apr 06 20:47:22 2020 us=986355 ifconfig_nowarn = DISABLED
Mon Apr 06 20:47:22 2020 us=986355 ifconfig_ipv6_local = '[UNDEF]'
Mon Apr 06 20:47:22 2020 us=986355 ifconfig_ipv6_netbits = 0
Mon Apr 06 20:47:22 2020 us=986355 ifconfig_ipv6_remote = '[UNDEF]'
Mon Apr 06 20:47:22 2020 us=986355 shaper = 0
Mon Apr 06 20:47:22 2020 us=986355 mtu_test = 0
Mon Apr 06 20:47:22 2020 us=986355 mlock = DISABLED
Mon Apr 06 20:47:22 2020 us=986355 keepalive_ping = 0
Mon Apr 06 20:47:22 2020 us=986355 keepalive_timeout = 0
Mon Apr 06 20:47:22 2020 us=986355 inactivity_timeout = 0
Mon Apr 06 20:47:22 2020 us=986355 ping_send_timeout = 0
Mon Apr 06 20:47:22 2020 us=986355 ping_rec_timeout = 0
Mon Apr 06 20:47:22 2020 us=986355 ping_rec_timeout_action = 0
Mon Apr 06 20:47:22 2020 us=986355 ping_timer_remote = DISABLED
Mon Apr 06 20:47:22 2020 us=986355 remap_sigusr1 = 0
Mon Apr 06 20:47:22 2020 us=986355 persist_tun = DISABLED
Mon Apr 06 20:47:22 2020 us=986355 persist_local_ip = DISABLED
Mon Apr 06 20:47:22 2020 us=986355 persist_remote_ip = DISABLED
Mon Apr 06 20:47:22 2020 us=986355 persist_key = DISABLED
Mon Apr 06 20:47:22 2020 us=986355 passtos = DISABLED
Mon Apr 06 20:47:22 2020 us=986355 resolve_retry_seconds = 1000000000
Mon Apr 06 20:47:22 2020 us=986355 resolve_in_advance = DISABLED
Mon Apr 06 20:47:22 2020 us=986355 username = '[UNDEF]'
Mon Apr 06 20:47:22 2020 us=986355 groupname = '[UNDEF]'
Mon Apr 06 20:47:22 2020 us=986355 chroot_dir = '[UNDEF]'
Mon Apr 06 20:47:22 2020 us=986355 cd_dir = '[UNDEF]'
Mon Apr 06 20:47:22 2020 us=986355 writepid = '[UNDEF]'
Mon Apr 06 20:47:22 2020 us=986355 up_script = '[UNDEF]'
Mon Apr 06 20:47:22 2020 us=986355 down_script = '[UNDEF]'
Mon Apr 06 20:47:22 2020 us=986355 down_pre = DISABLED
Mon Apr 06 20:47:22 2020 us=986355 up_restart = DISABLED
Mon Apr 06 20:47:22 2020 us=986355 up_delay = DISABLED
Mon Apr 06 20:47:22 2020 us=986355 daemon = DISABLED
Mon Apr 06 20:47:22 2020 us=986355 inetd = 0
Mon Apr 06 20:47:22 2020 us=986355 log = ENABLED
Mon Apr 06 20:47:22 2020 us=986355 suppress_timestamps = DISABLED
Mon Apr 06 20:47:22 2020 us=986355 machine_readable_output = DISABLED
Mon Apr 06 20:47:22 2020 us=986355 nice = 0
Mon Apr 06 20:47:22 2020 us=986355 verbosity = 5
Mon Apr 06 20:47:22 2020 us=986355 mute = 0
Mon Apr 06 20:47:22 2020 us=986355 gremlin = 0
Mon Apr 06 20:47:22 2020 us=986355 status_file = '[UNDEF]'
Mon Apr 06 20:47:22 2020 us=986355 status_file_version = 1
Mon Apr 06 20:47:22 2020 us=986355 status_file_update_freq = 60
Mon Apr 06 20:47:22 2020 us=986355 occ = ENABLED
Mon Apr 06 20:47:22 2020 us=986355 rcvbuf = 0
Mon Apr 06 20:47:22 2020 us=986355 sndbuf = 0
Mon Apr 06 20:47:22 2020 us=986355 sockflags = 0
Mon Apr 06 20:47:22 2020 us=986355 fast_io = DISABLED
Mon Apr 06 20:47:22 2020 us=986355 comp.alg = 2
Mon Apr 06 20:47:22 2020 us=986355 comp.flags = 1
Mon Apr 06 20:47:22 2020 us=986355 route_script = '[UNDEF]'
Mon Apr 06 20:47:22 2020 us=986355 route_default_gateway = '[UNDEF]'
Mon Apr 06 20:47:22 2020 us=986355 route_default_metric = 0
Mon Apr 06 20:47:22 2020 us=986355 route_noexec = DISABLED
Mon Apr 06 20:47:22 2020 us=986355 route_delay = 5
Mon Apr 06 20:47:22 2020 us=986355 route_delay_window = 30
Mon Apr 06 20:47:22 2020 us=986355 route_delay_defined = ENABLED
Mon Apr 06 20:47:22 2020 us=986355 route_nopull = DISABLED
Mon Apr 06 20:47:22 2020 us=986355 route_gateway_via_dhcp = DISABLED
Mon Apr 06 20:47:22 2020 us=986355 allow_pull_fqdn = DISABLED
Mon Apr 06 20:47:22 2020 us=986355 Pull filters:
Mon Apr 06 20:47:22 2020 us=986355 ignore "route-method"
Mon Apr 06 20:47:22 2020 us=986355 management_addr = '127.0.0.1'
Mon Apr 06 20:47:22 2020 us=986355 management_port = '25340'
Mon Apr 06 20:47:22 2020 us=986355 management_user_pass = 'stdin'
Mon Apr 06 20:47:22 2020 us=986355 management_log_history_cache = 250
Mon Apr 06 20:47:22 2020 us=986355 management_echo_buffer_size = 100
Mon Apr 06 20:47:22 2020 us=986355 management_write_peer_info_file = '[UNDEF]'
Mon Apr 06 20:47:22 2020 us=986355 management_client_user = '[UNDEF]'
Mon Apr 06 20:47:22 2020 us=986355 management_client_group = '[UNDEF]'
Mon Apr 06 20:47:22 2020 us=986355 management_flags = 6
Mon Apr 06 20:47:22 2020 us=987355 shared_secret_file = '[UNDEF]'
Mon Apr 06 20:47:22 2020 us=987355 key_direction = not set
Mon Apr 06 20:47:22 2020 us=987355 ciphername = 'AES-256-CBC'
Mon Apr 06 20:47:22 2020 us=987355 ncp_enabled = ENABLED
Mon Apr 06 20:47:22 2020 us=987355 ncp_ciphers = 'AES-256-GCM:AES-128-GCM'
Mon Apr 06 20:47:22 2020 us=987355 authname = 'SHA512'
Mon Apr 06 20:47:22 2020 us=987355 prng_hash = 'SHA1'
Mon Apr 06 20:47:22 2020 us=987355 prng_nonce_secret_len = 16
Mon Apr 06 20:47:22 2020 us=987355 keysize = 0
Mon Apr 06 20:47:22 2020 us=987355 engine = DISABLED
Mon Apr 06 20:47:22 2020 us=987355 replay = ENABLED
Mon Apr 06 20:47:22 2020 us=987355 mute_replay_warnings = DISABLED
Mon Apr 06 20:47:22 2020 us=987355 replay_window = 64
Mon Apr 06 20:47:22 2020 us=987355 replay_time = 15
Mon Apr 06 20:47:22 2020 us=987355 packet_id_file = '[UNDEF]'
Mon Apr 06 20:47:22 2020 us=987355 use_iv = ENABLED
Mon Apr 06 20:47:22 2020 us=987355 test_crypto = DISABLED
Mon Apr 06 20:47:22 2020 us=987355 tls_server = DISABLED
Mon Apr 06 20:47:22 2020 us=987355 tls_client = ENABLED
Mon Apr 06 20:47:22 2020 us=987355 key_method = 2
Mon Apr 06 20:47:22 2020 us=987355 ca_file = '[[INLINE]]'
Mon Apr 06 20:47:22 2020 us=987355 ca_path = '[UNDEF]'
Mon Apr 06 20:47:22 2020 us=987355 dh_file = '[UNDEF]'
Mon Apr 06 20:47:22 2020 us=987355 cert_file = '[UNDEF]'
Mon Apr 06 20:47:22 2020 us=987355 extra_certs_file = '[UNDEF]'
Mon Apr 06 20:47:22 2020 us=987355 priv_key_file = '[UNDEF]'
Mon Apr 06 20:47:22 2020 us=987355 pkcs12_file = '[UNDEF]'
Mon Apr 06 20:47:22 2020 us=987355 cryptoapi_cert = '[UNDEF]'
Mon Apr 06 20:47:22 2020 us=987355 cipher_list = '[UNDEF]'
Mon Apr 06 20:47:22 2020 us=987355 cipher_list_tls13 = '[UNDEF]'
Mon Apr 06 20:47:22 2020 us=987355 tls_cert_profile = '[UNDEF]'
Mon Apr 06 20:47:22 2020 us=987355 tls_verify = '[UNDEF]'
Mon Apr 06 20:47:22 2020 us=987355 tls_export_cert = '[UNDEF]'
Mon Apr 06 20:47:22 2020 us=987355 verify_x509_type = 0
Mon Apr 06 20:47:22 2020 us=987355 verify_x509_name = '[UNDEF]'
Mon Apr 06 20:47:22 2020 us=987355 crl_file = '[UNDEF]'
Mon Apr 06 20:47:22 2020 us=987355 ns_cert_type = 0
Mon Apr 06 20:47:22 2020 us=987355 remote_cert_ku[i] = 0
Mon Apr 06 20:47:22 2020 us=987355 remote_cert_ku[i] = 0
Mon Apr 06 20:47:22 2020 us=987355 remote_cert_ku[i] = 0
Mon Apr 06 20:47:22 2020 us=987355 remote_cert_ku[i] = 0
Mon Apr 06 20:47:22 2020 us=987355 remote_cert_ku[i] = 0
Mon Apr 06 20:47:22 2020 us=987355 remote_cert_ku[i] = 0
Mon Apr 06 20:47:22 2020 us=987355 remote_cert_ku[i] = 0
Mon Apr 06 20:47:22 2020 us=987355 remote_cert_ku[i] = 0
Mon Apr 06 20:47:22 2020 us=987355 remote_cert_ku[i] = 0
Mon Apr 06 20:47:22 2020 us=987355 remote_cert_ku[i] = 0
Mon Apr 06 20:47:22 2020 us=987355 remote_cert_ku[i] = 0
Mon Apr 06 20:47:22 2020 us=987355 remote_cert_ku[i] = 0
Mon Apr 06 20:47:22 2020 us=987355 remote_cert_ku[i] = 0
Mon Apr 06 20:47:22 2020 us=987355 remote_cert_ku[i] = 0
Mon Apr 06 20:47:22 2020 us=987355 remote_cert_ku[i] = 0
Mon Apr 06 20:47:22 2020 us=987355 remote_cert_ku[i] = 0
Mon Apr 06 20:47:22 2020 us=987355 remote_cert_eku = '[UNDEF]'
Mon Apr 06 20:47:22 2020 us=987355 ssl_flags = 0
Mon Apr 06 20:47:22 2020 us=987355 tls_timeout = 2
Mon Apr 06 20:47:22 2020 us=987355 renegotiate_bytes = -1
Mon Apr 06 20:47:22 2020 us=987355 renegotiate_packets = 0
Mon Apr 06 20:47:22 2020 us=987355 renegotiate_seconds = 0
Mon Apr 06 20:47:22 2020 us=987355 handshake_window = 60
Mon Apr 06 20:47:22 2020 us=987355 transition_window = 3600
Mon Apr 06 20:47:22 2020 us=987355 single_session = DISABLED
Mon Apr 06 20:47:22 2020 us=987355 push_peer_info = DISABLED
Mon Apr 06 20:47:22 2020 us=987355 tls_exit = DISABLED
Mon Apr 06 20:47:22 2020 us=987355 tls_auth_file = '[UNDEF]'
Mon Apr 06 20:47:22 2020 us=987355 tls_crypt_file = '[UNDEF]'
Mon Apr 06 20:47:22 2020 us=987355 pkcs11_protected_authentication = DISABLED
Mon Apr 06 20:47:22 2020 us=987355 pkcs11_protected_authentication = DISABLED
Mon Apr 06 20:47:22 2020 us=987355 pkcs11_protected_authentication = DISABLED
Mon Apr 06 20:47:22 2020 us=987355 pkcs11_protected_authentication = DISABLED
Mon Apr 06 20:47:22 2020 us=987355 pkcs11_protected_authentication = DISABLED
Mon Apr 06 20:47:22 2020 us=987355 pkcs11_protected_authentication = DISABLED
Mon Apr 06 20:47:22 2020 us=987355 pkcs11_protected_authentication = DISABLED
Mon Apr 06 20:47:22 2020 us=987355 pkcs11_protected_authentication = DISABLED
Mon Apr 06 20:47:22 2020 us=987355 pkcs11_protected_authentication = DISABLED
Mon Apr 06 20:47:22 2020 us=987355 pkcs11_protected_authentication = DISABLED
Mon Apr 06 20:47:22 2020 us=987355 pkcs11_protected_authentication = DISABLED
Mon Apr 06 20:47:22 2020 us=987355 pkcs11_protected_authentication = DISABLED
Mon Apr 06 20:47:22 2020 us=987355 pkcs11_protected_authentication = DISABLED
Mon Apr 06 20:47:22 2020 us=987355 pkcs11_protected_authentication = DISABLED
Mon Apr 06 20:47:22 2020 us=987355 pkcs11_protected_authentication = DISABLED
Mon Apr 06 20:47:22 2020 us=987355 pkcs11_protected_authentication = DISABLED
Mon Apr 06 20:47:22 2020 us=987355 pkcs11_private_mode = 00000000
Mon Apr 06 20:47:22 2020 us=987355 pkcs11_private_mode = 00000000
Mon Apr 06 20:47:22 2020 us=987355 pkcs11_private_mode = 00000000
Mon Apr 06 20:47:22 2020 us=987355 pkcs11_private_mode = 00000000
Mon Apr 06 20:47:22 2020 us=987355 pkcs11_private_mode = 00000000
Mon Apr 06 20:47:22 2020 us=987355 pkcs11_private_mode = 00000000
Mon Apr 06 20:47:22 2020 us=987355 pkcs11_private_mode = 00000000
Mon Apr 06 20:47:22 2020 us=988354 pkcs11_private_mode = 00000000
Mon Apr 06 20:47:22 2020 us=988354 pkcs11_private_mode = 00000000
Mon Apr 06 20:47:22 2020 us=988354 pkcs11_private_mode = 00000000
Mon Apr 06 20:47:22 2020 us=988354 pkcs11_private_mode = 00000000
Mon Apr 06 20:47:22 2020 us=988354 pkcs11_private_mode = 00000000
Mon Apr 06 20:47:22 2020 us=988354 pkcs11_private_mode = 00000000
Mon Apr 06 20:47:22 2020 us=988354 pkcs11_private_mode = 00000000
Mon Apr 06 20:47:22 2020 us=988354 pkcs11_private_mode = 00000000
Mon Apr 06 20:47:22 2020 us=988354 pkcs11_private_mode = 00000000
Mon Apr 06 20:47:22 2020 us=988354 pkcs11_cert_private = DISABLED
Mon Apr 06 20:47:22 2020 us=988354 pkcs11_cert_private = DISABLED
Mon Apr 06 20:47:22 2020 us=988354 pkcs11_cert_private = DISABLED
Mon Apr 06 20:47:22 2020 us=988354 pkcs11_cert_private = DISABLED
Mon Apr 06 20:47:22 2020 us=988354 pkcs11_cert_private = DISABLED
Mon Apr 06 20:47:22 2020 us=988354 pkcs11_cert_private = DISABLED
Mon Apr 06 20:47:22 2020 us=988354 pkcs11_cert_private = DISABLED
Mon Apr 06 20:47:22 2020 us=988354 pkcs11_cert_private = DISABLED
Mon Apr 06 20:47:22 2020 us=988354 pkcs11_cert_private = DISABLED
Mon Apr 06 20:47:22 2020 us=988354 pkcs11_cert_private = DISABLED
Mon Apr 06 20:47:22 2020 us=988354 pkcs11_cert_private = DISABLED
Mon Apr 06 20:47:22 2020 us=988354 pkcs11_cert_private = DISABLED
Mon Apr 06 20:47:22 2020 us=988354 pkcs11_cert_private = DISABLED
Mon Apr 06 20:47:22 2020 us=988354 pkcs11_cert_private = DISABLED
Mon Apr 06 20:47:22 2020 us=988354 pkcs11_cert_private = DISABLED
Mon Apr 06 20:47:22 2020 us=988354 pkcs11_cert_private = DISABLED
Mon Apr 06 20:47:22 2020 us=988354 pkcs11_pin_cache_period = -1
Mon Apr 06 20:47:22 2020 us=988354 pkcs11_id = '[UNDEF]'
Mon Apr 06 20:47:22 2020 us=988354 pkcs11_id_management = DISABLED
Mon Apr 06 20:47:22 2020 us=988354 server_network = 0.0.0.0
Mon Apr 06 20:47:22 2020 us=988354 server_netmask = 0.0.0.0
Mon Apr 06 20:47:22 2020 us=988354 server_network_ipv6 = ::
Mon Apr 06 20:47:22 2020 us=988354 server_netbits_ipv6 = 0
Mon Apr 06 20:47:22 2020 us=988354 server_bridge_ip = 0.0.0.0
Mon Apr 06 20:47:22 2020 us=988354 server_bridge_netmask = 0.0.0.0
Mon Apr 06 20:47:22 2020 us=988354 server_bridge_pool_start = 0.0.0.0
Mon Apr 06 20:47:22 2020 us=988354 server_bridge_pool_end = 0.0.0.0
Mon Apr 06 20:47:22 2020 us=988354 ifconfig_pool_defined = DISABLED
Mon Apr 06 20:47:22 2020 us=988354 ifconfig_pool_start = 0.0.0.0
Mon Apr 06 20:47:22 2020 us=988354 ifconfig_pool_end = 0.0.0.0
Mon Apr 06 20:47:22 2020 us=988354 ifconfig_pool_netmask = 0.0.0.0
Mon Apr 06 20:47:22 2020 us=988354 ifconfig_pool_persist_filename = '[UNDEF]'
Mon Apr 06 20:47:22 2020 us=988354 ifconfig_pool_persist_refresh_freq = 600
Mon Apr 06 20:47:22 2020 us=988354 ifconfig_ipv6_pool_defined = DISABLED
Mon Apr 06 20:47:22 2020 us=988354 ifconfig_ipv6_pool_base = ::
Mon Apr 06 20:47:22 2020 us=988354 ifconfig_ipv6_pool_netbits = 0
Mon Apr 06 20:47:22 2020 us=988354 n_bcast_buf = 256
Mon Apr 06 20:47:22 2020 us=988354 tcp_queue_limit = 64
Mon Apr 06 20:47:22 2020 us=988354 real_hash_size = 256
Mon Apr 06 20:47:22 2020 us=988354 virtual_hash_size = 256
Mon Apr 06 20:47:22 2020 us=988354 client_connect_script = '[UNDEF]'
Mon Apr 06 20:47:22 2020 us=988354 learn_address_script = '[UNDEF]'
Mon Apr 06 20:47:22 2020 us=988354 client_disconnect_script = '[UNDEF]'
Mon Apr 06 20:47:22 2020 us=988354 client_config_dir = '[UNDEF]'
Mon Apr 06 20:47:22 2020 us=988354 ccd_exclusive = DISABLED
Mon Apr 06 20:47:22 2020 us=988354 tmp_dir = '...\AppData\Local\Temp\'
Mon Apr 06 20:47:22 2020 us=988354 push_ifconfig_defined = DISABLED
Mon Apr 06 20:47:22 2020 us=988354 push_ifconfig_local = 0.0.0.0
Mon Apr 06 20:47:22 2020 us=988354 push_ifconfig_remote_netmask = 0.0.0.0
Mon Apr 06 20:47:22 2020 us=988354 push_ifconfig_ipv6_defined = DISABLED
Mon Apr 06 20:47:22 2020 us=988354 push_ifconfig_ipv6_local = ::/0
Mon Apr 06 20:47:22 2020 us=988354 push_ifconfig_ipv6_remote = ::
Mon Apr 06 20:47:22 2020 us=988354 enable_c2c = DISABLED
Mon Apr 06 20:47:22 2020 us=988354 duplicate_cn = DISABLED
Mon Apr 06 20:47:22 2020 us=988354 cf_max = 0
Mon Apr 06 20:47:22 2020 us=988354 cf_per = 0
Mon Apr 06 20:47:22 2020 us=988354 max_clients = 1024
Mon Apr 06 20:47:22 2020 us=988354 max_routes_per_client = 256
Mon Apr 06 20:47:22 2020 us=988354 auth_user_pass_verify_script = '[UNDEF]'
Mon Apr 06 20:47:22 2020 us=988354 auth_user_pass_verify_script_via_file = DISABLED
Mon Apr 06 20:47:22 2020 us=988354 auth_token_generate = DISABLED
Mon Apr 06 20:47:22 2020 us=988354 auth_token_lifetime = 0
Mon Apr 06 20:47:22 2020 us=988354 client = DISABLED
Mon Apr 06 20:47:22 2020 us=988354 pull = ENABLED
Mon Apr 06 20:47:22 2020 us=988354 auth_user_pass_file = 'stdin'
Mon Apr 06 20:47:22 2020 us=988354 show_net_up = DISABLED
Mon Apr 06 20:47:22 2020 us=988354 route_method = 3
Mon Apr 06 20:47:22 2020 us=988354 block_outside_dns = DISABLED
Mon Apr 06 20:47:22 2020 us=988354 ip_win32_defined = DISABLED
Mon Apr 06 20:47:22 2020 us=988354 ip_win32_type = 3
Mon Apr 06 20:47:22 2020 us=988354 dhcp_masq_offset = 0
Mon Apr 06 20:47:22 2020 us=988354 dhcp_lease_time = 31536000
Mon Apr 06 20:47:22 2020 us=988354 tap_sleep = 0
Mon Apr 06 20:47:22 2020 us=988354 dhcp_options = ENABLED
Mon Apr 06 20:47:22 2020 us=988354 dhcp_renew = DISABLED
Mon Apr 06 20:47:22 2020 us=988354 dhcp_pre_release = DISABLED
Mon Apr 06 20:47:22 2020 us=988354 domain = '[UNDEF]'
Mon Apr 06 20:47:22 2020 us=988354 netbios_scope = '[UNDEF]'
Mon Apr 06 20:47:22 2020 us=988354 netbios_node_type = 0
Mon Apr 06 20:47:22 2020 us=988354 disable_nbt = DISABLED
Mon Apr 06 20:47:22 2020 us=988354 DNS[0] = 192.168.1.1
Mon Apr 06 20:47:22 2020 us=988354 OpenVPN 2.4.8 x86_64-w64-mingw32 [SSL (OpenSSL)] [LZO] [LZ4] [PKCS11] [AEAD] built on Oct 31 2019
Mon Apr 06 20:47:22 2020 us=988354 Windows version 6.2 (Windows 8 or greater) 64bit
Mon Apr 06 20:47:22 2020 us=989353 library versions: OpenSSL 1.1.0l 10 Sep 2019, LZO 2.10
Enter Management Password:
Mon Apr 06 20:47:22 2020 us=990353 MANAGEMENT: TCP Socket listening on [AF_INET]127.0.0.1:25340
Mon Apr 06 20:47:22 2020 us=990353 Need hold release from management interface, waiting...
Mon Apr 06 20:47:23 2020 us=429085 MANAGEMENT: Client connected from [AF_INET]127.0.0.1:25340
Mon Apr 06 20:47:23 2020 us=530023 MANAGEMENT: CMD 'state on'
Mon Apr 06 20:47:23 2020 us=530023 MANAGEMENT: CMD 'log all on'
Mon Apr 06 20:47:23 2020 us=729896 MANAGEMENT: CMD 'echo all on'
Mon Apr 06 20:47:23 2020 us=732895 MANAGEMENT: CMD 'bytecount 5'
Mon Apr 06 20:47:23 2020 us=734893 MANAGEMENT: CMD 'hold off'
Mon Apr 06 20:47:23 2020 us=736892 MANAGEMENT: CMD 'hold release'
Mon Apr 06 20:47:28 2020 us=24250 MANAGEMENT: CMD 'username "Auth" "***"'
Mon Apr 06 20:47:28 2020 us=35243 MANAGEMENT: CMD 'password [...]'
Mon Apr 06 20:47:28 2020 us=35243 WARNING: No server certificate verification method has been enabled. See http://openvpn.net/howto.html#mitm for more info.
Mon Apr 06 20:47:28 2020 us=41239 LZO compression initializing
Mon Apr 06 20:47:28 2020 us=41239 Control Channel MTU parms [ L:1622 D:1212 EF:38 EB:0 ET:0 EL:3 ]
Mon Apr 06 20:47:28 2020 us=43240 MANAGEMENT: >STATE:1586198848,RESOLVE,,,,,,
Mon Apr 06 20:47:28 2020 us=94208 Data Channel MTU parms [ L:1622 D:1450 EF:122 EB:406 ET:0 EL:3 ]
Mon Apr 06 20:47:28 2020 us=94208 Local Options String (VER=V4): 'V4,dev-type tun,link-mtu 1602,tun-mtu 1500,proto UDPv4,comp-lzo,cipher AES-256-CBC,auth SHA512,keysize 256,key-method 2,tls-client'
Mon Apr 06 20:47:28 2020 us=94208 Expected Remote Options String (VER=V4): 'V4,dev-type tun,link-mtu 1602,tun-mtu 1500,proto UDPv4,comp-lzo,cipher AES-256-CBC,auth SHA512,keysize 256,key-method 2,tls-server'
Mon Apr 06 20:47:28 2020 us=94208 TCP/UDP: Preserving recently used remote address: [AF_INET]***
Mon Apr 06 20:47:28 2020 us=94208 Socket Buffers: R=[65536->65536] S=[65536->65536]
Mon Apr 06 20:47:28 2020 us=94208 UDP link local (bound): [AF_INET][undef]:***
Mon Apr 06 20:47:28 2020 us=94208 UDP link remote: [AF_INET]***:***
Mon Apr 06 20:47:28 2020 us=94208 MANAGEMENT: >STATE:1586198848,WAIT,,,,,,
Mon Apr 06 20:47:28 2020 us=126186 MANAGEMENT: >STATE:1586198848,AUTH,,,,,,
Mon Apr 06 20:47:28 2020 us=126186 TLS: Initial packet from [AF_INET]***:***, sid=b647f00e 4d9b739b
Mon Apr 06 20:47:28 2020 us=127186 WARNING: this configuration may cache passwords in memory -- use the auth-nocache option to prevent this
Mon Apr 06 20:47:28 2020 us=502958 VERIFY OK: depth=1, C=TW, L=Taipei, O=Synology Inc., CN=Synology Inc. CA
Mon Apr 06 20:47:28 2020 us=503954 VERIFY OK: depth=0, C=TW, L=Taipei, O=Synology Inc., CN=synology.com
Mon Apr 06 20:47:29 2020 us=412393 Control Channel: TLSv1.2, cipher TLSv1.2 DHE-RSA-AES256-GCM-SHA384, 2048 bit RSA
Mon Apr 06 20:47:29 2020 us=412393 [synology.com] Peer Connection Initiated with [AF_INET]***:***
Mon Apr 06 20:47:30 2020 us=420772 MANAGEMENT: >STATE:1586198850,GET_CONFIG,,,,,,
Mon Apr 06 20:47:30 2020 us=420772 SENT CONTROL [synology.com]: 'PUSH_REQUEST' (status=1)
Mon Apr 06 20:47:30 2020 us=452752 PUSH: Received control message: 'PUSH_REPLY,route 192.168.1.0 255.255.255.0,route 10.8.0.0 255.255.255.0,route 10.8.0.1,topology net30,ping 10,ping-restart 60,ifconfig 10.8.0.6 10.8.0.5'
Mon Apr 06 20:47:30 2020 us=452752 OPTIONS IMPORT: timers and/or timeouts modified
Mon Apr 06 20:47:30 2020 us=452752 OPTIONS IMPORT: --ifconfig/up options modified
Mon Apr 06 20:47:30 2020 us=452752 OPTIONS IMPORT: route options modified
Mon Apr 06 20:47:30 2020 us=452752 Data Channel MTU parms [ L:1602 D:1450 EF:102 EB:406 ET:0 EL:3 ]
Mon Apr 06 20:47:30 2020 us=452752 Outgoing Data Channel: Cipher 'AES-256-CBC' initialized with 256 bit key
Mon Apr 06 20:47:30 2020 us=452752 Outgoing Data Channel: Using 512 bit message hash 'SHA512' for HMAC authentication
Mon Apr 06 20:47:30 2020 us=452752 Incoming Data Channel: Cipher 'AES-256-CBC' initialized with 256 bit key
Mon Apr 06 20:47:30 2020 us=452752 Incoming Data Channel: Using 512 bit message hash 'SHA512' for HMAC authentication
Mon Apr 06 20:47:30 2020 us=452752 interactive service msg_channel=996
Mon Apr 06 20:47:30 2020 us=456749 ROUTE_GATEWAY 192.168.1.1/255.255.255.0 I=17 HWADDR=78:92:9c:0e:b9:1a
Mon Apr 06 20:47:30 2020 us=456749 open_tun
Mon Apr 06 20:47:30 2020 us=458749 TAP-WIN32 device [Connessione alla rete locale (LAN)] opened: \\.\Global\{8CA84889-3DD0-4FEE-A78F-7D4DABD24D24}.tap
Mon Apr 06 20:47:30 2020 us=458749 TAP-Windows Driver Version 9.24
Mon Apr 06 20:47:30 2020 us=458749 TAP-Windows MTU=1500
Mon Apr 06 20:47:30 2020 us=460747 Notified TAP-Windows driver to set a DHCP IP/netmask of 10.8.0.6/255.255.255.252 on interface {8CA84889-3DD0-4FEE-A78F-7D4DABD24D24} [DHCP-serv: 10.8.0.5, lease-time: 31536000]
Mon Apr 06 20:47:30 2020 us=460747 DHCP option string: 0604c0a8 0101
Mon Apr 06 20:47:30 2020 us=460747 Successful ARP Flush on interface [11] {8CA84889-3DD0-4FEE-A78F-7D4DABD24D24}
Mon Apr 06 20:47:30 2020 us=464746 do_ifconfig, tt->did_ifconfig_ipv6_setup=0
Mon Apr 06 20:47:30 2020 us=464746 MANAGEMENT: >STATE:1586198850,ASSIGN_IP,,10.8.0.6,,,,
Mon Apr 06 20:47:35 2020 us=89893 TEST ROUTES: 3/3 succeeded len=3 ret=1 a=0 u/d=up
Mon Apr 06 20:47:35 2020 us=89893 MANAGEMENT: >STATE:1586198855,ADD_ROUTES,,,,,,
Mon Apr 06 20:47:35 2020 us=89893 C:\WINDOWS\system32\route.exe ADD 192.168.1.0 MASK 255.255.255.0 10.8.0.5
Mon Apr 06 20:47:35 2020 us=91892 Route addition via service succeeded
Mon Apr 06 20:47:35 2020 us=91892 C:\WINDOWS\system32\route.exe ADD 10.8.0.0 MASK 255.255.255.0 10.8.0.5
Mon Apr 06 20:47:35 2020 us=94893 Route addition via service succeeded
Mon Apr 06 20:47:35 2020 us=94893 C:\WINDOWS\system32\route.exe ADD 10.8.0.1 MASK 255.255.255.255 10.8.0.5
Mon Apr 06 20:47:35 2020 us=96889 Route addition via service succeeded
Mon Apr 06 20:47:35 2020 us=96889 Initialization Sequence Completed
Mon Apr 06 20:47:35 2020 us=97889 MANAGEMENT: >STATE:1586198855,CONNECTED,SUCCESS,10.8.0.6,***,***,,
Temo di aver capito il problema e direi anche abbastanza scontato.
Le due reti che unisco con la VPN hanno lo stesso indirizzamento, sono entrambe sulla 192.168.1.0, infatti facendo un tracert sull'IP della stampante, me ne vado nella rete del NAS, ovviamente li non la trova la stampante.
Senza dover cambiare l'indirizzamento di una delle due reti, che mi costringerebbe a riconfigurare tutto, non è un modo di dire almeno al pc che deve prima guardare nella rete in cui è poi andare in quella VPN? O una configurazione della VPN?
OUTATIME
07-04-2020, 07:27
Temo di aver capito il problema e direi anche abbastanza scontato.
Le due reti che unisco con la VPN hanno lo stesso indirizzamento, sono entrambe sulla 192.168.1.0, infatti facendo un tracert sull'IP della stampante, me ne vado nella rete del NAS, ovviamente li non la trova la stampante.
Senza dover cambiare l'indirizzamento di una delle due reti, che mi costringerebbe a riconfigurare tutto, non è un modo di dire almeno al pc che deve prima guardare nella rete in cui è poi andare in quella VPN? O una configurazione della VPN?
Si, che il problema era quello lo avevo già capito, quello che mi rimaneva da capire era chi cofigurava la route, se il server o il file di configurazione client, per questo ti ho chiesto il file di configurazione, non trovando nulla.
Purtroppo i log confermano che la route viene configurata in push dal server:
Mon Apr 06 20:47:35 2020 us=89893 C:\WINDOWS\system32\route.exe ADD 192.168.1.0 MASK 255.255.255.0 10.8.0.5
Quindi devi cercare sul NAS la sezione route e eliminare la route tra la subnet 10.8.0 e 192.168.1
Su questo non so come aiutarti, non conosco Synology.
Ci provo, anche se non conosco molto bene il tema :(
EDIT: non c'è nulla come route statica.
OUTATIME
07-04-2020, 18:18
Ci provo, anche se non conosco molto bene il tema :(
EDIT: non c'è nulla come route statica.
Prova ad aggiungere nel file di configurazione:
pull-filter ignore "route 192.168.1.0"
Grande! Funziona!
Grazie mille!
OUTATIME
08-04-2020, 20:47
Grande! Funziona!
Grazie mille!
Ottimo.
vBulletin® v3.6.4, Copyright ©2000-2025, Jelsoft Enterprises Ltd.