iKuai爱快流控路由

 找回密码
 立即注册

QQ登录

只需一步,快速开始

查看: 3547|回复: 10
打印 上一主题 下一主题

[问题反馈] openvpn客户端安卓正常连接PC伪连接

[复制链接]
跳转到指定楼层
楼主
发表于 2019-11-22 20:16:11 | 只看该作者 |只看大图 回帖奖励 |正序浏览 |阅读模式
openvpn客户端安卓正常连接(能正常访问服务端内网网段192.168.8.X)

PC伪连接,显示连接绿色成功,查IP仍然没有变化,不能访问服务端的内网,PING不通


Fri Nov 22 20:15:43 2019 OpenVPN 2.4.8 x86_64-w64-mingw32 [SSL (OpenSSL)] [LZO] [LZ4] [PKCS11] [AEAD] built on Oct 31 2019
Fri Nov 22 20:15:43 2019 Windows version 6.1 (Windows 7) 64bit
Fri Nov 22 20:15:43 2019 library versions: OpenSSL 1.1.0l  10 Sep 2019, LZO 2.10
Fri Nov 22 20:15:43 2019 MANAGEMENT: TCP Socket listening on [AF_INET]127.0.0.1:25340
Fri Nov 22 20:15:43 2019 Need hold release from management interface, waiting...
Fri Nov 22 20:15:44 2019 MANAGEMENT: Client connected from [AF_INET]127.0.0.1:25340
Fri Nov 22 20:15:44 2019 MANAGEMENT: CMD 'state on'
Fri Nov 22 20:15:44 2019 MANAGEMENT: CMD 'log all on'
Fri Nov 22 20:15:44 2019 MANAGEMENT: CMD 'echo all on'
Fri Nov 22 20:15:44 2019 MANAGEMENT: CMD 'bytecount 5'
Fri Nov 22 20:15:44 2019 MANAGEMENT: CMD 'hold off'
Fri Nov 22 20:15:44 2019 MANAGEMENT: CMD 'hold release'
Fri Nov 22 20:15:45 2019 MANAGEMENT: CMD 'username "Auth" "kang2"'
Fri Nov 22 20:15:45 2019 MANAGEMENT: CMD 'password [...]'
Fri Nov 22 20:15:45 2019 WARNING: No server certificate verification method has been enabled.  See http://openvpn.net/howto.html#mitm for more info.
Fri Nov 22 20:15:45 2019 WARNING: normally if you use --mssfix and/or --fragment, you should also set --tun-mtu 1500 (currently it is 1400)
Fri Nov 22 20:15:45 2019 TCP/UDP: Preserving recently used remote address: [AF_INET]
Fri Nov 22 20:15:45 2019 Socket Buffers: R=[8192->8192] S=[8192->8192]
Fri Nov 22 20:15:45 2019 UDP link local: (not bound)
Fri Nov 22 20:15:45 2019 UDP link remote: [AF_INET]
Fri Nov 22 20:15:45 2019 MANAGEMENT: >STATE:1574424945,WAIT,,,,,,
Fri Nov 22 20:15:45 2019 MANAGEMENT: >STATE:1574424945,AUTH,,,,,,
Fri Nov 22 20:15:45 2019 TLS: Initial packet from [AF_INET], sid=e9409184 e9d67615
Fri Nov 22 20:15:45 2019 WARNING: this configuration may cache passwords in memory -- use the auth-nocache option to prevent this
Fri Nov 22 20:15:45 2019 VERIFY OK: depth=1, C=CN, O=iKuai, CN=iKuai Device CA
Fri Nov 22 20:15:45 2019 VERIFY OK: depth=0, C=CN, O=iKuai, CN=iKuai OpenVPN Server
Fri Nov 22 20:15:45 2019 Control Channel: TLSv1.2, cipher TLSv1.2 DHE-RSA-AES256-GCM-SHA384, 2048 bit RSA
Fri Nov 22 20:15:45 2019 [iKuai OpenVPN Server] Peer Connection Initiated with [AF_INET]
Fri Nov 22 20:15:46 2019 MANAGEMENT: >STATE:1574424946,GET_CONFIG,,,,,,
Fri Nov 22 20:15:46 2019 SENT CONTROL [iKuai OpenVPN Server]: 'PUSH_REQUEST' (status=1)
Fri Nov 22 20:15:46 2019 PUSH: Received control message: 'PUSH_REPLY,route 10.7.0.0 255.255.0.0,route-gateway 10.7.7.1,topology subnet,ping 10,ping-restart 60,ifconfig 10.7.7.7 255.255.255.0'
Fri Nov 22 20:15:46 2019 OPTIONS IMPORT: timers and/or timeouts modified
Fri Nov 22 20:15:46 2019 OPTIONS IMPORT: --ifconfig/up options modified
Fri Nov 22 20:15:46 2019 OPTIONS IMPORT: route options modified
Fri Nov 22 20:15:46 2019 OPTIONS IMPORT: route-related options modified
Fri Nov 22 20:15:46 2019 Outgoing Data Channel: Cipher 'BF-CBC' initialized with 128 bit key
Fri Nov 22 20:15:46 2019 WARNING: INSECURE cipher with block size less than 128 bit (64 bit).  This allows attacks like SWEET32.  Mitigate by using a --cipher with a larger block size (e.g. AES-256-CBC).
Fri Nov 22 20:15:46 2019 Outgoing Data Channel: Using 160 bit message hash 'SHA1' for HMAC authentication
Fri Nov 22 20:15:46 2019 Incoming Data Channel: Cipher 'BF-CBC' initialized with 128 bit key
Fri Nov 22 20:15:46 2019 WARNING: INSECURE cipher with block size less than 128 bit (64 bit).  This allows attacks like SWEET32.  Mitigate by using a --cipher with a larger block size (e.g. AES-256-CBC).
Fri Nov 22 20:15:46 2019 Incoming Data Channel: Using 160 bit message hash 'SHA1' for HMAC authentication
Fri Nov 22 20:15:46 2019 WARNING: cipher with small block size in use, reducing reneg-bytes to 64MB to mitigate SWEET32 attacks.
Fri Nov 22 20:15:46 2019 interactive service msg_channel=0
Fri Nov 22 20:15:46 2019 ROUTE_GATEWAY 192.168.9.1/255.255.255.0 I=13 HWADDR=14:75:90:f8:77:ee
Fri Nov 22 20:15:46 2019 open_tun
Fri Nov 22 20:15:46 2019 TAP-WIN32 device [本地连接 4] opened: \\.\Global\{A761D491-6E38-4D04-A9CB-9A78E816428C}.tap
Fri Nov 22 20:15:46 2019 TAP-Windows Driver Version 9.24
Fri Nov 22 20:15:46 2019 Set TAP-Windows TUN subnet mode network/local/netmask = 10.7.7.0/10.7.7.7/255.255.255.0 [SUCCEEDED]
Fri Nov 22 20:15:46 2019 Notified TAP-Windows driver to set a DHCP IP/netmask of 10.7.7.7/255.255.255.0 on interface {A761D491-6E38-4D04-A9CB-9A78E816428C} [DHCP-serv: 10.7.7.254, lease-time: 31536000]
Fri Nov 22 20:15:46 2019 Successful ARP Flush on interface [26] {A761D491-6E38-4D04-A9CB-9A78E816428C}
Fri Nov 22 20:15:46 2019 MANAGEMENT: >STATE:1574424946,ASSIGN_IP,,10.7.7.7,,,,

分享到:  QQ好友和群QQ好友和群 QQ空间QQ空间 腾讯微博腾讯微博 腾讯朋友腾讯朋友
收藏收藏 支持支持 反对反对
11#
发表于 2019-11-24 16:57:03 | 只看该作者
a1683636416 发表于 2019-11-23 14:23
用文本编辑器(不要用 Windows 自带记事本)把 redirect-gateway 前面的 # 号去掉。
...

大神帮忙看看我的问题吧,万分感谢。https://bbs.ikuai8.com/thread-104994-1-1.html
10#
 楼主| 发表于 2019-11-23 14:42:50 | 只看该作者
a1683636416 发表于 2019-11-23 14:23
用文本编辑器(不要用 Windows 自带记事本)把 redirect-gateway 前面的 # 号去掉。
...

完美解决,多谢大神,两句话省了我小白几天功夫都没完成的事情
9#
发表于 2019-11-23 14:23:41 | 只看该作者
提示: 作者被禁止或删除 内容自动屏蔽
8#
 楼主| 发表于 2019-11-23 14:06:38 | 只看该作者
okango 发表于 2019-11-23 14:03
非常感谢这位朋友,加了这个后成功访问192.168.8.0网段,PC端好坑,手机端直接连接就可以访问服务端所有 ...

我发现一个情况,手机连接是全局方式的,比如连接后百度搜IP已经更改为服务端的ip

而PC端实际还是原IP,通过加路由推送只能手动访问该网段,不能全局自动,有什么方法可以全局方式连接吗
7#
 楼主| 发表于 2019-11-23 14:03:49 | 只看该作者
a1683636416 发表于 2019-11-23 13:53
你自己添加一条 192.168.8.0/24 的路由就可以了

非常感谢这位朋友,加了这个后成功访问192.168.8.0网段,PC端好坑,手机端直接连接就可以访问服务端所有网段,PC端真不友好
6#
发表于 2019-11-23 13:53:47 | 只看该作者
提示: 作者被禁止或删除 内容自动屏蔽
5#
 楼主| 发表于 2019-11-23 13:52:04 | 只看该作者
爱快技术支持03 发表于 2019-11-23 10:24
楼主,您好
服务端上需要配置上推送路由,PC客户端使用软件拨号的时候接受推送路由即可
OPen VPN客户端拨号 ...

你好,我安卓手机成功连接

win10我把导出的文件后缀改ovpn,然后用OpenVPN GUI软件直接导入连接,连接是成功的,但是没办法ping通服务端

请问你说的推送路由是什么方法呢

服务端配置推送路由貌似默认有的
【10.7.0.0 255.255.0.0(16)】

PC客户端如何设置接受推送路由呢
地板
 楼主| 发表于 2019-11-23 13:48:25 | 只看该作者
1978caijf 发表于 2019-11-23 08:16
你改成tcp协议再试试

TCP试了,win10没用,我手机安卓成功连接并使用局域网的
板凳
发表于 2019-11-23 10:24:34 | 只看该作者
楼主,您好
服务端上需要配置上推送路由,PC客户端使用软件拨号的时候接受推送路由即可
OPen VPN客户端拨号的时候,服务端创建的账号密码不能是固定IP地址哦
您需要登录后才可以回帖 登录 | 立即注册

本版积分规则

关闭

站长推荐上一条 /1 下一条

QQ|小黑屋|手机版|Archiver|论坛规章制度|iKuai Inc. ( 京ICP备13042604号 )

GMT+8, 2024-11-15 10:32

Powered by Discuz! X3.3

© 2001-2024 Comsenz Inc.

快速回复 返回顶部 返回列表