NETGEAR is aware of a growing number of phone and online scams. To learn how to stay safe click here.

Forum Discussion

doubleos's avatar
Aug 12, 2014

openvpn on readynas duo v1 - intra/internet unavailable

I have set up the openvpn server on a readynas duo (v1-sparc). I can successfully connect via openvpn clients on ios and osx (tunnelblick). However, I can't access any hosts including the router except for the readynas duo on its subnet nor can I access the internet via ip/dns. This is my server.conf
local 192.168.0.13
port 1194
proto udp
mssfix 1400
push "dhcp-option DNS 8.8.8.8"
push "dhcp-option DNS 8.8.4.4"
dev tun
push "redirect-gateway def1"
ca /etc/openvpn/ca.crt
cert /etc/openvpn/MyVPNServer.crt
key /etc/openvpn/MyVPNServer.key
dh /etc/openvpn/dh1024.pem
server 10.8.0.0 255.255.255.0
ifconfig-pool-persist ipp.txt
push "route 192.168.0.0 255.255.255.0"
keepalive 10 120
cipher BF-CBC
comp-lzo
max-clients 100
persist-key
persist-tun
status openvpn-status.log
verb 1
user openvpn
group openvpn

This is my client ovpn
client
proto udp
dev tun
remote AAA.BBB.CCC.DDD 1194
resolv-retry infinite
redirect-gateway def1
nobind
persist-key
persist-tun
ca ca2.crt
cert Client02.crt
key Client02.key
cipher BF-CBC
comp-lzo
verb 3

Tunnelblick client log
2014-08-09 16:59:07 *Tunnelblick: OS X 10.9.4; Tunnelblick 3.4beta32 (build 3904)

2014-08-09 16:59:12 *Tunnelblick: Attempting connection with Client02 using shadow copy; Set nameserver = 1; monitoring connection

2014-08-09 16:59:12 *Tunnelblick: openvpnstart start Client02.tblk 1337 1 0 1 0 16689 -ptADGNWradsgnw 2.2.1

2014-08-09 16:59:12 *Tunnelblick: openvpnstart log:

Tunnelblick: Loading tun-signed.kext

Tunnelblick:

OpenVPN started successfully. Command used to start OpenVPN (one argument per displayed line):



/Applications/Tunnelblick.app/Contents/Resources/openvpn/openvpn-2.2.1/openvpn

--daemon

--log

/Library/Application Support/Tunnelblick/Logs/-SUsers-Slkaplan-SLibrary-SApplication Support-STunnelblick-SConfigurations-SClient02.tblk-SContents-SResources-Sconfig.ovpn.1_0_1_0_16689.1337.openvpn.log

--cd

/Library/Application Support/Tunnelblick/Users/lkaplan/Client02.tblk/Contents/Resources

--config

/Library/Application Support/Tunnelblick/Users/lkaplan/Client02.tblk/Contents/Resources/config.ovpn

--cd

/Library/Application Support/Tunnelblick/Users/lkaplan/Client02.tblk/Contents/Resources

--management

127.0.0.1

1337

--management-query-passwords

--management-hold

--script-security

2

--up

/Applications/Tunnelblick.app/Contents/Resources/client.up.tunnelblick.sh -m -w -d -f -ptADGNWradsgnw

--down

/Applications/Tunnelblick.app/Contents/Resources/client.down.tunnelblick.sh -m -w -d -f -ptADGNWradsgnw



2014-08-09 16:59:12 *Tunnelblick: Established communication with OpenVPN

2014-08-09 16:59:12 *Tunnelblick: openvpnstart starting OpenVPN

2014-08-09 16:59:12 OpenVPN 2.2.1 i386-apple-darwin [SSL] [LZO2] [PKCS11] [eurephia] built on Jul 17 2014

2014-08-09 16:59:12 MANAGEMENT: TCP Socket listening on 127.0.0.1:1337

2014-08-09 16:59:12 Need hold release from management interface, waiting...

2014-08-09 16:59:12 MANAGEMENT: Client connected from 127.0.0.1:1337

2014-08-09 16:59:12 MANAGEMENT: CMD 'pid'

2014-08-09 16:59:12 MANAGEMENT: CMD 'state on'

2014-08-09 16:59:12 MANAGEMENT: CMD 'state'

2014-08-09 16:59:12 MANAGEMENT: CMD 'bytecount 1'

2014-08-09 16:59:12 MANAGEMENT: CMD 'hold release'

2014-08-09 16:59:12 WARNING: No server certificate verification method has been enabled. See http://openvpn.net/howto.html#mitm for more info.

2014-08-09 16:59:12 NOTE: the current --script-security setting may allow this configuration to call user-defined scripts

2014-08-09 16:59:12 LZO compression initialized

2014-08-09 16:59:12 Control Channel MTU parms [ L:1542 D:138 EF:38 EB:0 ET:0 EL:0 ]

2014-08-09 16:59:12 Socket Buffers: R=[196724->65536] S=[9216->65536]

2014-08-09 16:59:12 MANAGEMENT: >STATE:1407628752,RESOLVE,,,

2014-08-09 16:59:16 Data Channel MTU parms [ L:1542 D:1450 EF:42 EB:135 ET:0 EL:0 AF:3/1 ]

2014-08-09 16:59:16 Local Options hash (VER=V4): '41690919'

2014-08-09 16:59:16 Expected Remote Options hash (VER=V4): '530fdded'

2014-08-09 16:59:16 UDPv4 link local: [undef]

2014-08-09 16:59:16 UDPv4 link remote: nnn.nnn.nnn.nnn:1194

2014-08-09 16:59:16 MANAGEMENT: >STATE:1407628756,WAIT,,,

2014-08-09 16:59:16 MANAGEMENT: >STATE:1407628756,AUTH,,,

2014-08-09 16:59:16 TLS: Initial packet from nnn.nnn.nnn.nnn:1194, sid=3d25d1e0 7d48b2f4

2014-08-09 16:59:18 VERIFY OK: depth=1, /C=US/ST=...
2014-08-09 16:59:18 VERIFY OK: depth=0, /C=US/ST=...

2014-08-09 16:59:19 Data Channel Encrypt: Cipher 'BF-CBC' initialized with 128 bit key

2014-08-09 16:59:19 Data Channel Encrypt: Using 160 bit message hash 'SHA1' for HMAC authentication

2014-08-09 16:59:19 Data Channel Decrypt: Cipher 'BF-CBC' initialized with 128 bit key

2014-08-09 16:59:19 Data Channel Decrypt: Using 160 bit message hash 'SHA1' for HMAC authentication

2014-08-09 16:59:19 Control Channel: TLSv1, cipher TLSv1/SSLv3 DHE-RSA-AES256-SHA, 1024 bit RSA

2014-08-09 16:59:19 [auburn] Peer Connection Initiated with nnn.nnn.nnn.nnn:1194

2014-08-09 16:59:20 MANAGEMENT: >STATE:1407628760,GET_CONFIG,,,

2014-08-09 16:59:21 SENT CONTROL [auburn]: 'PUSH_REQUEST' (status=1)

2014-08-09 16:59:22 PUSH: Received control message: 'PUSH_REPLY,dhcp-option DNS 8.8.8.8,dhcp-option DNS 8.8.4.4,redirect-gateway def1,route 192.168.0.0 255.255.255.0,route 10.8.0.1,ping 10,ping-restart 120,ifconfig 10.8.0.6 10.8.0.5'

2014-08-09 16:59:22 OPTIONS IMPORT: timers and/or timeouts modified

2014-08-09 16:59:22 OPTIONS IMPORT: --ifconfig/up options modified

2014-08-09 16:59:22 OPTIONS IMPORT: route options modified

2014-08-09 16:59:22 OPTIONS IMPORT: --ip-win32 and/or --dhcp-option options modified

2014-08-09 16:59:22 ROUTE default_gateway=192.168.1.1

2014-08-09 16:59:22 TUN/TAP device /dev/tun0 opened

2014-08-09 16:59:22 MANAGEMENT: >STATE:1407628762,ASSIGN_IP,,10.8.0.6,

2014-08-09 16:59:22 /sbin/ifconfig tun0 delete

ifconfig: ioctl (SIOCDIFADDR): Can't assign requested address

2014-08-09 16:59:22 NOTE: Tried to delete pre-existing tun/tap instance -- No Problem if failure

2014-08-09 16:59:22 /sbin/ifconfig tun0 10.8.0.6 10.8.0.5 mtu 1500 netmask 255.255.255.255 up

2014-08-09 16:59:22 /Applications/Tunnelblick.app/Contents/Resources/client.up.tunnelblick.sh -m -w -d -f -ptADGNWradsgnw tun0 1500 1542 10.8.0.6 10.8.0.5 init

**********************************************

Start of output from client.up.tunnelblick.sh

Retrieved from OpenVPN: name server(s) [ 10.8.0.1 8.8.8.8 8.8.4.4 ], search domain(s) [ ] and SMB server(s) [ ] and using default domain name [ openvpn ]

Not aggregating ServerAddresses because running on OS X 10.6 or higher

Setting search domains to 'openvpn' because running under OS X 10.6 or higher and the search domains were not set manually and 'Prepend domain name to search domains' was not selected

Saved the DNS and SMB configurations so they can be restored

Set ServerAddresses to 10.8.0.1 8.8.8.8 8.8.4.4

Set SearchDomains to openvpn

Set DomainName to openvpn

Flushed the DNS cache via dscacheutil

Notified mDNSResponder that the DNS cache was flushed

Setting up to monitor system configuration with process-network-changes

End of output from client.up.tunnelblick.sh

**********************************************

2014-08-09 16:59:25 *Tunnelblick: No 'connected.sh' script to execute

2014-08-09 16:59:25 /sbin/route add -net nnn.nnn.nnn 192.168.1.1 255.255.255.255

add net nnn.nnn.nnn: gateway 192.168.1.1

2014-08-09 16:59:25 /sbin/route add -net 0.0.0.0 10.8.0.5 128.0.0.0

add net 0.0.0.0: gateway 10.8.0.5

2014-08-09 16:59:25 /sbin/route add -net 128.0.0.0 10.8.0.5 128.0.0.0

add net 128.0.0.0: gateway 10.8.0.5

2014-08-09 16:59:25 MANAGEMENT: >STATE:1407628765,ADD_ROUTES,,,

2014-08-09 16:59:25 /sbin/route add -net 192.168.0.0 10.8.0.5 255.255.255.0

add net 192.168.0.0: gateway 10.8.0.5

2014-08-09 16:59:25 /sbin/route add -net 10.8.0.1 10.8.0.5 255.255.255.255

add net 10.8.0.1: gateway 10.8.0.5

2014-08-09 16:59:25 Initialization Sequence Completed

2014-08-09 16:59:25 MANAGEMENT: >STATE:1407628765,CONNECTED,SUCCESS,10.8.0.6,nnn.nnn.nnn.nnn

2014-08-09 16:59:30 *Tunnelblick process-network-changes: A system configuration change was ignored

2014-08-09 17:00:01 *Tunnelblick: After 30.0 seconds, gave up trying to fetch IP address information using the ipInfo host's name after connecting.

2014-08-09 17:00:31 *Tunnelblick: After 30.0 seconds, gave up trying to fetch IP address information using the ipInfo host's IP address after connecting.

ios client log
2014-08-11 20:38:55 LZO-ASYM init swap=0 asym=0
2014-08-11 20:38:55 EVENT: RESOLVE
2014-08-11 20:38:56 Contacting nnn.nnn.nnn.nnn:1194 via UDP
2014-08-11 20:38:56 EVENT: WAIT
2014-08-11 20:38:56 Connecting to nnn.nnn.nnn.nnn:1194 (nnn.nnn.nnn) via UDPv4
2014-08-11 20:38:56 EVENT: CONNECTING
2014-08-11 20:38:56 Tunnel Options:V4,dev-type tun,link-mtu 1542,tun-mtu 1500,proto UDPv4,comp-lzo,cipher BF-CBC,auth SHA1,keysize 128,key-method 2,tls-client
2014-08-11 20:38:56 Peer Info:
IV_GUI_VER=net.openvpn.connect.ios 1.0.4-140
IV_VER=3.0
IV_PLAT=ios
IV_NCP=1
IV_LZO=1

2014-08-11 20:38:58 VERIFY OK: depth=1
cert. version : 3
serial number : 99:F2:42:6A:37:4B:AE:B1
issuer name : C=US, ST=...
subject name : C=US, ST=...
issued on : 2014-08-05 21:51:46
expires on : 2024-08-02 21:51:46
signed using : RSA+SHA1
RSA key size : 1024 bits

2014-08-11 20:38:58 VERIFY OK: depth=0
cert. version : 3
serial number : 01
issuer name : C=US, ST=...
subject name : C=US, ST=...
issued on : 2014-08-05 21:52:56
expires on : 2024-08-02 21:52:56
signed using : RSA+MD5
RSA key size : 1024 bits

2014-08-11 20:39:00 SSL Handshake: TLSv1.0/TLS-DHE-RSA-WITH-AES-256-CBC-SHA
2014-08-11 20:39:00 Session is ACTIVE
2014-08-11 20:39:01 EVENT: GET_CONFIG
2014-08-11 20:39:01 Sending PUSH_REQUEST to server...
2014-08-11 20:39:01 OPTIONS:
0 [redirect-gateway] [def1]
1 [dhcp-option] [DNS] [8.8.8.8]
2 [dhcp-option] [DNS] [8.8.4.4]
3 [redirect-gateway] [def1]
4 [route] [192.168.0.0] [255.255.255.0]
5 [route] [10.8.0.1]
6 [ping] [10]
7 [ping-restart] [120]
8 [ifconfig] [10.8.0.6] [10.8.0.5]

2014-08-11 20:39:01 LZO-ASYM init swap=0 asym=0
2014-08-11 20:39:01 EVENT: ASSIGN_IP
2014-08-11 20:39:01 Connected via tun
2014-08-11 20:39:01 EVENT: CONNECTED @nnn.nnn.nnn:1194 (nnn.nnn.nnn) via /UDPv4 on tun/10.8.0.6/
2014-08-11 20:39:01 NET Internet:ReachableViaWWAN/WR t----l-
2014-08-11 20:39:01 NET WiFi:NotReachable/WR t------

Any ideas?

2 Replies

Replies have been turned off for this discussion
  • mdgm-ntgr's avatar
    mdgm-ntgr
    NETGEAR Employee Retired
    I hear this "is most likely a routing ip/forwarding problem (most definitely tcp_forwarding not enabled)"

NETGEAR Academy

Boost your skills with the Netgear Academy - Get trained, certified and stay ahead with the latest Netgear technology! 

Join Us!

ProSupport for Business

Comprehensive support plans for maximum network uptime and business peace of mind.

 

Learn More