[除錯] OPENVPN客戶端config(已解決

作者: chenszhanx (czh)   2016-07-12 17:04:28
想要透過家中番茄路由VPN上網+使用區網資源
設置如下
client
proto udp
dev tap
remote XXXX.ddns.net
port 443
resolv-retry infinite
nobind
persist-key
persist-tun
ca ca.crt
cert client1.crt
key client1.key
comp-lzo
verb 3
因為發現對外流量並沒有透過VPN
查詢後在最後加入
redirect-gateway
結果會卡住 log如下
Tue Jul 12 17:01:33 2016 OpenVPN 2.3.11 x86_64-w64-mingw32 [SSL (OpenSSL)]
[LZO] [PKCS11] [IPv6] built on May 10 2016
Tue Jul 12 17:01:33 2016 Windows version 6.1 (Windows 7) 64bit
Tue Jul 12 17:01:33 2016 library versions: OpenSSL 1.0.1t 3 May 2016, LZO
2.09
Tue Jul 12 17:01:33 2016 MANAGEMENT: TCP Socket listening on
[AF_INET]127.0.0.1:25340
Tue Jul 12 17:01:33 2016 Need hold release from management interface,
waiting...
Tue Jul 12 17:01:34 2016 MANAGEMENT: Client connected from
[AF_INET]127.0.0.1:25340
Tue Jul 12 17:01:34 2016 MANAGEMENT: CMD 'state on'
Tue Jul 12 17:01:34 2016 MANAGEMENT: CMD 'log all on'
Tue Jul 12 17:01:34 2016 MANAGEMENT: CMD 'hold off'
Tue Jul 12 17:01:34 2016 MANAGEMENT: CMD 'hold release'
Tue Jul 12 17:01:34 2016 WARNING: No server certificate verification method
has been enabled. See http://openvpn.net/howto.html#mitm for more info.
Tue Jul 12 17:01:34 2016 Socket Buffers: R=[8192->8192] S=[8192->8192]
Tue Jul 12 17:01:34 2016 MANAGEMENT: >STATE:1468314094,RESOLVE,,,
Tue Jul 12 17:01:34 2016 UDPv4 link local: [undef]
Tue Jul 12 17:01:34 2016 UDPv4 link remote: [AF_INET]XXX.XX.XX.XX:443
Tue Jul 12 17:01:34 2016 MANAGEMENT: >STATE:1468314094,WAIT,,,
是否用TAP就不能將流量透過遠方出去?
但是我需要讓client ip透過同一個DHCP指派到同一個網段
在番茄路由VPN伺服器設置只能用TAP
用TUN就只能設到不同網段
請問有解決方法嗎 感謝
作者: chenszhanx (czh)   2016-07-13 09:31:00
以透過設置route gateway解決 

Links booklink

Contact Us: admin [ a t ] ucptt.com