Salut !
Tout d’abord, merci de ta réponse, je commence à désespérer !!!
J’arrête pas de faire des tonnes de test, de changer de tuto, mais j’ai toujours le même problème.
J’attends d’avoir ta solution tenter le client-client, même si je crois que c’est un mode utilisé pour faire communiquer plusieurs clients via le serveur VPN sans qu’il passe par le système du serveur (rien de sur).
J’ai d’ailleurs lors de mes multiples tests remarqué que les téléchargement en cours ne s’arrête pas lors de la connexion sur le VPN.
Voici d’autres infos issues de mes derniers tests :
log VPN serveur :
Tue Oct 21 11:46:39 2014 OpenVPN 2.2.1 x86_64-linux-gnu [SSL] [LZO2] [EPOLL] [PKCS11] [eurephia] [MH] [PF_INET6] [IPv6 payload 20110424-2 (2.2RC2)] built on Jun 18 2013
Tue Oct 21 11:46:39 2014 NOTE: OpenVPN 2.1 requires '--script-security 2' or higher to call user-defined scripts or executables
Tue Oct 21 11:46:39 2014 Diffie-Hellman initialized with 1024 bit key
Tue Oct 21 11:46:39 2014 Control Channel Authentication: using 'key/ta.key' as a OpenVPN static key file
Tue Oct 21 11:46:39 2014 Outgoing Control Channel Authentication: Using 160 bit message hash 'SHA1' for HMAC authentication
Tue Oct 21 11:46:39 2014 Incoming Control Channel Authentication: Using 160 bit message hash 'SHA1' for HMAC authentication
Tue Oct 21 11:46:39 2014 TLS-Auth MTU parms [ L:1560 D:168 EF:68 EB:0 ET:0 EL:0 ]
Tue Oct 21 11:46:39 2014 Socket Buffers: R=[87380->131072] S=[16384->131072]
Tue Oct 21 11:46:39 2014 ROUTE default_gateway=XXX.XXX.XXX.XXX
Tue Oct 21 11:46:39 2014 TUN/TAP device tun0 opened
Tue Oct 21 11:46:39 2014 TUN/TAP TX queue length set to 100
Tue Oct 21 11:46:39 2014 do_ifconfig, tt->ipv6=0, tt->did_ifconfig_ipv6_setup=0
Tue Oct 21 11:46:39 2014 /sbin/ifconfig tun0 10.8.0.1 pointopoint 10.8.0.2 mtu 1500
Tue Oct 21 11:46:39 2014 /sbin/route add -net 10.8.0.0 netmask 255.255.255.0 gw 10.8.0.2
Tue Oct 21 11:46:39 2014 Data Channel MTU parms [ L:1560 D:1450 EF:60 EB:135 ET:0 EL:0 AF:3/1 ]
Tue Oct 21 11:46:39 2014 GID set to nogroup
Tue Oct 21 11:46:39 2014 UID set to nobody
Tue Oct 21 11:46:39 2014 Listening for incoming TCP connection on [undef]
Tue Oct 21 11:46:39 2014 TCPv4_SERVER link local (bound): [undef]
Tue Oct 21 11:46:39 2014 TCPv4_SERVER link remote: [undef]
Tue Oct 21 11:46:39 2014 PORT SHARE PROXY: proxy starting
Tue Oct 21 11:46:39 2014 MULTI: multi_init called, r=256 v=256
Tue Oct 21 11:46:39 2014 IFCONFIG POOL: base=10.8.0.4 size=62, ipv6=0
Tue Oct 21 11:46:39 2014 MULTI: TCP INIT maxclients=1024 maxevents=1028
Tue Oct 21 11:46:39 2014 Initialization Sequence Completed
Tue Oct 21 11:47:03 2014 MULTI: multi_create_instance called
Tue Oct 21 11:47:03 2014 Re-using SSL/TLS context
Tue Oct 21 11:47:03 2014 LZO compression initialized
Tue Oct 21 11:47:03 2014 Control Channel MTU parms [ L:1560 D:168 EF:68 EB:0 ET:0 EL:0 ]
Tue Oct 21 11:47:03 2014 Data Channel MTU parms [ L:1560 D:1450 EF:60 EB:135 ET:0 EL:0 AF:3/1 ]
Tue Oct 21 11:47:03 2014 Local Options hash (VER=V4): '9915e4a2'
Tue Oct 21 11:47:03 2014 Expected Remote Options hash (VER=V4): '2f2c6498'
Tue Oct 21 11:47:03 2014 TCP connection established with [AF_INET]YYY.YYY.YYY.YYY:60725
Tue Oct 21 11:47:03 2014 TCPv4_SERVER link local: [undef]
Tue Oct 21 11:47:03 2014 TCPv4_SERVER link remote: [AF_INET]YYY.YYY.YYY.YYY:60725
Tue Oct 21 11:47:03 2014 YYY.YYY.YYY.YYY:60725 TLS: Initial packet from [AF_INET]YYY.YYY.YYY.YYY:60725, sid=62a8d2f1 64dab47c
Tue Oct 21 11:47:10 2014 YYY.YYY.YYY.YYY:60725 VERIFY OK: depth=1, /C=FR/ST=Here/L=HereAgain/O=domain/OU=login_OU/CN=login/name=login/emailAddress=log.login@gmail.com
Tue Oct 21 11:47:10 2014 YYY.YYY.YYY.YYY:60725 VERIFY OK: depth=0, /C=FR/ST=Here/L=HereAgain/O=domain/OU=login_OU/CN=login/name=login_NAME/emailAddress=log.login@gmail.com
Tue Oct 21 11:47:12 2014 YYY.YYY.YYY.YYY:60725 Data Channel Encrypt: Cipher 'AES-256-CBC' initialized with 256 bit key
Tue Oct 21 11:47:12 2014 YYY.YYY.YYY.YYY:60725 Data Channel Encrypt: Using 160 bit message hash 'SHA1' for HMAC authentication
Tue Oct 21 11:47:12 2014 YYY.YYY.YYY.YYY:60725 Data Channel Decrypt: Cipher 'AES-256-CBC' initialized with 256 bit key
Tue Oct 21 11:47:12 2014 YYY.YYY.YYY.YYY:60725 Data Channel Decrypt: Using 160 bit message hash 'SHA1' for HMAC authentication
Tue Oct 21 11:47:13 2014 YYY.YYY.YYY.YYY:60725 Control Channel: TLSv1, cipher TLSv1/SSLv3 DHE-RSA-AES256-SHA, 1024 bit RSA
Tue Oct 21 11:47:13 2014 YYY.YYY.YYY.YYY:60725 [login] Peer Connection Initiated with [AF_INET]YYY.YYY.YYY.YYY:60725
Tue Oct 21 11:47:13 2014 login/YYY.YYY.YYY.YYY:60725 MULTI_sva: pool returned IPv4=10.8.0.6, IPv6=1::1800:0:ab7f:0
Tue Oct 21 11:47:13 2014 login/YYY.YYY.YYY.YYY:60725 MULTI: Learn: 10.8.0.6 -> login/YYY.YYY.YYY.YYY:60725
Tue Oct 21 11:47:13 2014 login/YYY.YYY.YYY.YYY:60725 MULTI: primary virtual IP for login/YYY.YYY.YYY.YYY:60725: 10.8.0.6
Tue Oct 21 11:47:15 2014 login/YYY.YYY.YYY.YYY:60725 PUSH: Received control message: 'PUSH_REQUEST'
Tue Oct 21 11:47:15 2014 login/YYY.YYY.YYY.YYY:60725 send_push_reply(): safe_cap=960
Tue Oct 21 11:47:15 2014 login/YYY.YYY.YYY.YYY:60725 SENT CONTROL [login]: 'PUSH_REPLY,redirect-gateway def1 bypass-dhcp,dhcp-option DNS 8.8.8.8,dhcp-option DNS 8.8.4.4,route 10.8.0.1,topology net30,ping 10,ping-restart 120,ifconfig 10.8.0.6 10.8.0.5' (status=1)
Tue Oct 21 11:47:54 2014 MULTI: multi_create_instance called
Tue Oct 21 11:47:54 2014 Re-using SSL/TLS context
Tue Oct 21 11:47:54 2014 LZO compression initialized
Tue Oct 21 11:47:54 2014 Control Channel MTU parms [ L:1560 D:168 EF:68 EB:0 ET:0 EL:0 ]
Tue Oct 21 11:47:54 2014 Data Channel MTU parms [ L:1560 D:1450 EF:60 EB:135 ET:0 EL:0 AF:3/1 ]
Tue Oct 21 11:47:54 2014 Local Options hash (VER=V4): '9915e4a2'
Tue Oct 21 11:47:54 2014 Expected Remote Options hash (VER=V4): '2f2c6498'
Tue Oct 21 11:47:54 2014 TCP connection established with [AF_INET]YYY.YYY.YYY.YYY:51910
Tue Oct 21 11:47:54 2014 TCPv4_SERVER link local: [undef]
Tue Oct 21 11:47:54 2014 TCPv4_SERVER link remote: [AF_INET]YYY.YYY.YYY.YYY:51910
Tue Oct 21 11:47:54 2014 YYY.YYY.YYY.YYY:51910 MULTI: multi_create_instance called
Tue Oct 21 11:47:54 2014 YYY.YYY.YYY.YYY:51910 Re-using SSL/TLS context
Tue Oct 21 11:47:54 2014 YYY.YYY.YYY.YYY:51910 LZO compression initialized
Tue Oct 21 11:47:54 2014 YYY.YYY.YYY.YYY:51910 Control Channel MTU parms [ L:1560 D:168 EF:68 EB:0 ET:0 EL:0 ]
Tue Oct 21 11:47:54 2014 YYY.YYY.YYY.YYY:51910 Data Channel MTU parms [ L:1560 D:1450 EF:60 EB:135 ET:0 EL:0 AF:3/1 ]
Tue Oct 21 11:47:54 2014 YYY.YYY.YYY.YYY:51910 Local Options hash (VER=V4): '9915e4a2'
Tue Oct 21 11:47:54 2014 YYY.YYY.YYY.YYY:51910 Expected Remote Options hash (VER=V4): '2f2c6498'
Tue Oct 21 11:47:54 2014 YYY.YYY.YYY.YYY:51910 TCP connection established with [AF_INET]YYY.YYY.YYY.YYY:51911
Tue Oct 21 11:47:54 2014 YYY.YYY.YYY.YYY:51910 TCPv4_SERVER link local: [undef]
Tue Oct 21 11:47:54 2014 YYY.YYY.YYY.YYY:51910 TCPv4_SERVER link remote: [AF_INET]YYY.YYY.YYY.YYY:51911
Tue Oct 21 11:47:54 2014 YYY.YYY.YYY.YYY:51910 Non-OpenVPN client protocol detected
Tue Oct 21 11:47:54 2014 YYY.YYY.YYY.YYY:51910 SIGTERM[soft,port-share-redirect] received, client-instance exiting
Tue Oct 21 11:47:54 2014 TCP/UDP: Closing socket
Tue Oct 21 11:47:54 2014 YYY.YYY.YYY.YYY:51911 Non-OpenVPN client protocol detected
Tue Oct 21 11:47:54 2014 YYY.YYY.YYY.YYY:51911 SIGTERM[soft,port-share-redirect] received, client-instance exiting
Tue Oct 21 11:47:54 2014 TCP/UDP: Closing socket
Tue Oct 21 11:47:55 2014 MULTI: multi_create_instance called
Tue Oct 21 11:47:55 2014 Re-using SSL/TLS context
Tue Oct 21 11:47:55 2014 LZO compression initialized
Tue Oct 21 11:47:55 2014 Control Channel MTU parms [ L:1560 D:168 EF:68 EB:0 ET:0 EL:0 ]
Tue Oct 21 11:47:55 2014 Data Channel MTU parms [ L:1560 D:1450 EF:60 EB:135 ET:0 EL:0 AF:3/1 ]
Tue Oct 21 11:47:55 2014 Local Options hash (VER=V4): '9915e4a2'
Tue Oct 21 11:47:55 2014 Expected Remote Options hash (VER=V4): '2f2c6498'
Tue Oct 21 11:47:55 2014 TCP connection established with [AF_INET]YYY.YYY.YYY.YYY:51912
Tue Oct 21 11:47:55 2014 TCPv4_SERVER link local: [undef]
Tue Oct 21 11:47:55 2014 TCPv4_SERVER link remote: [AF_INET]YYY.YYY.YYY.YYY:51912
Tue Oct 21 11:47:55 2014 YYY.YYY.YYY.YYY:51912 Non-OpenVPN client protocol detected
Tue Oct 21 11:47:55 2014 YYY.YYY.YYY.YYY:51912 SIGTERM[soft,port-share-redirect] received, client-instance exiting
Tue Oct 21 11:47:55 2014 TCP/UDP: Closing socket
Tue Oct 21 11:47:55 2014 MULTI: multi_create_instance called
Tue Oct 21 11:47:55 2014 Re-using SSL/TLS context
Tue Oct 21 11:47:55 2014 LZO compression initialized
Tue Oct 21 11:47:55 2014 Control Channel MTU parms [ L:1560 D:168 EF:68 EB:0 ET:0 EL:0 ]
Tue Oct 21 11:47:55 2014 Data Channel MTU parms [ L:1560 D:1450 EF:60 EB:135 ET:0 EL:0 AF:3/1 ]
Tue Oct 21 11:47:55 2014 Local Options hash (VER=V4): '9915e4a2'
Tue Oct 21 11:47:55 2014 Expected Remote Options hash (VER=V4): '2f2c6498'
Tue Oct 21 11:47:55 2014 TCP connection established with [AF_INET]YYY.YYY.YYY.YYY:51913
Tue Oct 21 11:47:55 2014 TCPv4_SERVER link local: [undef]
Tue Oct 21 11:47:55 2014 TCPv4_SERVER link remote: [AF_INET]YYY.YYY.YYY.YYY:51913
Tue Oct 21 11:47:55 2014 YYY.YYY.YYY.YYY:51913 Non-OpenVPN client protocol detected
Tue Oct 21 11:47:55 2014 YYY.YYY.YYY.YYY:51913 SIGTERM[soft,port-share-redirect] received, client-instance exiting
Tue Oct 21 11:47:55 2014 TCP/UDP: Closing socket
Tue Oct 21 11:47:55 2014 MULTI: multi_create_instance called
Tue Oct 21 11:47:55 2014 Re-using SSL/TLS context
Tue Oct 21 11:47:55 2014 LZO compression initialized
Tue Oct 21 11:47:55 2014 Control Channel MTU parms [ L:1560 D:168 EF:68 EB:0 ET:0 EL:0 ]
Tue Oct 21 11:47:55 2014 Data Channel MTU parms [ L:1560 D:1450 EF:60 EB:135 ET:0 EL:0 AF:3/1 ]
Tue Oct 21 11:47:55 2014 Local Options hash (VER=V4): '9915e4a2'
Tue Oct 21 11:47:55 2014 Expected Remote Options hash (VER=V4): '2f2c6498'
Tue Oct 21 11:47:55 2014 TCP connection established with [AF_INET]YYY.YYY.YYY.YYY:51914
Tue Oct 21 11:47:55 2014 TCPv4_SERVER link local: [undef]
Tue Oct 21 11:47:55 2014 TCPv4_SERVER link remote: [AF_INET]YYY.YYY.YYY.YYY:51914
Tue Oct 21 11:47:55 2014 YYY.YYY.YYY.YYY:51914 Non-OpenVPN client protocol detected
Tue Oct 21 11:47:55 2014 YYY.YYY.YYY.YYY:51914 SIGTERM[soft,port-share-redirect] received, client-instance exiting
Tue Oct 21 11:47:55 2014 TCP/UDP: Closing socket
Tue Oct 21 11:47:56 2014 MULTI: multi_create_instance called
Tue Oct 21 11:47:56 2014 Re-using SSL/TLS context
Tue Oct 21 11:47:56 2014 LZO compression initialized
Tue Oct 21 11:47:56 2014 Control Channel MTU parms [ L:1560 D:168 EF:68 EB:0 ET:0 EL:0 ]
Tue Oct 21 11:47:56 2014 Data Channel MTU parms [ L:1560 D:1450 EF:60 EB:135 ET:0 EL:0 AF:3/1 ]
Tue Oct 21 11:47:56 2014 Local Options hash (VER=V4): '9915e4a2'
Tue Oct 21 11:47:56 2014 Expected Remote Options hash (VER=V4): '2f2c6498'
Tue Oct 21 11:47:56 2014 TCP connection established with [AF_INET]YYY.YYY.YYY.YYY:51915
Tue Oct 21 11:47:56 2014 TCPv4_SERVER link local: [undef]
Tue Oct 21 11:47:56 2014 TCPv4_SERVER link remote: [AF_INET]YYY.YYY.YYY.YYY:51915
Tue Oct 21 11:47:56 2014 YYY.YYY.YYY.YYY:51915 Non-OpenVPN client protocol detected
Tue Oct 21 11:47:56 2014 YYY.YYY.YYY.YYY:51915 SIGTERM[soft,port-share-redirect] received, client-instance exiting
Tue Oct 21 11:47:56 2014 TCP/UDP: Closing socket
Tue Oct 21 11:47:56 2014 MULTI: multi_create_instance called
Tue Oct 21 11:47:56 2014 Re-using SSL/TLS context
Tue Oct 21 11:47:56 2014 LZO compression initialized
Tue Oct 21 11:47:56 2014 Control Channel MTU parms [ L:1560 D:168 EF:68 EB:0 ET:0 EL:0 ]
Tue Oct 21 11:47:56 2014 Data Channel MTU parms [ L:1560 D:1450 EF:60 EB:135 ET:0 EL:0 AF:3/1 ]
Tue Oct 21 11:47:56 2014 Local Options hash (VER=V4): '9915e4a2'
Tue Oct 21 11:47:56 2014 Expected Remote Options hash (VER=V4): '2f2c6498'
Tue Oct 21 11:47:56 2014 TCP connection established with [AF_INET]YYY.YYY.YYY.YYY:51916
Tue Oct 21 11:47:56 2014 TCPv4_SERVER link local: [undef]
Tue Oct 21 11:47:56 2014 TCPv4_SERVER link remote: [AF_INET]YYY.YYY.YYY.YYY:51916
Tue Oct 21 11:47:56 2014 YYY.YYY.YYY.YYY:51916 Non-OpenVPN client protocol detected
Tue Oct 21 11:47:56 2014 YYY.YYY.YYY.YYY:51916 SIGTERM[soft,port-share-redirect] received, client-instance exiting
Tue Oct 21 11:47:56 2014 TCP/UDP: Closing socket
Tue Oct 21 11:47:57 2014 MULTI: multi_create_instance called
Tue Oct 21 11:47:57 2014 Re-using SSL/TLS context
Tue Oct 21 11:47:57 2014 LZO compression initialized
Tue Oct 21 11:47:57 2014 Control Channel MTU parms [ L:1560 D:168 EF:68 EB:0 ET:0 EL:0 ]
Tue Oct 21 11:47:57 2014 Data Channel MTU parms [ L:1560 D:1450 EF:60 EB:135 ET:0 EL:0 AF:3/1 ]
Tue Oct 21 11:47:57 2014 Local Options hash (VER=V4): '9915e4a2'
Tue Oct 21 11:47:57 2014 Expected Remote Options hash (VER=V4): '2f2c6498'
Tue Oct 21 11:47:57 2014 TCP connection established with [AF_INET]YYY.YYY.YYY.YYY:51917
Tue Oct 21 11:47:57 2014 TCPv4_SERVER link local: [undef]
Tue Oct 21 11:47:57 2014 TCPv4_SERVER link remote: [AF_INET]YYY.YYY.YYY.YYY:51917
Tue Oct 21 11:47:57 2014 YYY.YYY.YYY.YYY:51917 Non-OpenVPN client protocol detected
Tue Oct 21 11:47:57 2014 YYY.YYY.YYY.YYY:51917 SIGTERM[soft,port-share-redirect] received, client-instance exiting
Tue Oct 21 11:47:57 2014 TCP/UDP: Closing socket
Tue Oct 21 11:47:57 2014 MULTI: multi_create_instance called
Tue Oct 21 11:47:57 2014 Re-using SSL/TLS context
Tue Oct 21 11:47:57 2014 LZO compression initialized
Tue Oct 21 11:47:57 2014 Control Channel MTU parms [ L:1560 D:168 EF:68 EB:0 ET:0 EL:0 ]
Tue Oct 21 11:47:57 2014 Data Channel MTU parms [ L:1560 D:1450 EF:60 EB:135 ET:0 EL:0 AF:3/1 ]
Tue Oct 21 11:47:57 2014 Local Options hash (VER=V4): '9915e4a2'
Tue Oct 21 11:47:57 2014 Expected Remote Options hash (VER=V4): '2f2c6498'
Tue Oct 21 11:47:57 2014 TCP connection established with [AF_INET]YYY.YYY.YYY.YYY:51920
Tue Oct 21 11:47:57 2014 TCPv4_SERVER link local: [undef]
Tue Oct 21 11:47:57 2014 TCPv4_SERVER link remote: [AF_INET]YYY.YYY.YYY.YYY:51920
Tue Oct 21 11:47:57 2014 YYY.YYY.YYY.YYY:51920 Non-OpenVPN client protocol detected
Tue Oct 21 11:47:57 2014 YYY.YYY.YYY.YYY:51920 SIGTERM[soft,port-share-redirect] received, client-instance exiting
Tue Oct 21 11:47:57 2014 TCP/UDP: Closing socket
Tue Oct 21 11:48:08 2014 login/YYY.YYY.YYY.YYY:60725 Connection reset, restarting [-1]
Tue Oct 21 11:48:08 2014 login/YYY.YYY.YYY.YYY:60725 SIGUSR1[soft,connection-reset] received, client-instance restarting
Tue Oct 21 11:48:08 2014 TCP/UDP: Closing socket
log VPN client:
Tue Oct 21 13:46:54 2014 OpenVPN 2.3.4 x86_64-w64-mingw32 [SSL (OpenSSL)] [LZO] [PKCS11] [IPv6] built on Aug 7 2014
Tue Oct 21 13:46:54 2014 library versions: OpenSSL 1.0.1i 6 Aug 2014, LZO 2.05
Enter Management Password:
Tue Oct 21 13:46:54 2014 MANAGEMENT: TCP Socket listening on [AF_INET]127.0.0.1:25341
Tue Oct 21 13:46:54 2014 Need hold release from management interface, waiting...
Tue Oct 21 13:46:54 2014 MANAGEMENT: Client connected from [AF_INET]127.0.0.1:25341
Tue Oct 21 13:46:54 2014 MANAGEMENT: CMD 'state on'
Tue Oct 21 13:46:54 2014 MANAGEMENT: CMD 'log all on'
Tue Oct 21 13:46:54 2014 MANAGEMENT: CMD 'hold off'
Tue Oct 21 13:46:54 2014 MANAGEMENT: CMD 'hold release'
Tue Oct 21 13:46:54 2014 WARNING: No server certificate verification method has been enabled. See http://openvpn.net/howto.html#mitm for more info.
Tue Oct 21 13:47:01 2014 MANAGEMENT: CMD 'password [...]'
Tue Oct 21 13:47:01 2014 WARNING: this configuration may cache passwords in memory -- use the auth-nocache option to prevent this
Tue Oct 21 13:47:01 2014 Control Channel Authentication: using 'ta.key' as a OpenVPN static key file
Tue Oct 21 13:47:01 2014 Outgoing Control Channel Authentication: Using 160 bit message hash 'SHA1' for HMAC authentication
Tue Oct 21 13:47:01 2014 Incoming Control Channel Authentication: Using 160 bit message hash 'SHA1' for HMAC authentication
Tue Oct 21 13:47:01 2014 Socket Buffers: R=[8192->8192] S=[8192->8192]
Tue Oct 21 13:47:01 2014 Attempting to establish TCP connection with [AF_INET]XXX.XXX.XXX.XXX:443
Tue Oct 21 13:47:01 2014 MANAGEMENT: >STATE:1413884821,TCP_CONNECT,,,
Tue Oct 21 13:47:01 2014 TCP connection established with [AF_INET]XXX.XXX.XXX.XXX:443
Tue Oct 21 13:47:01 2014 TCPv4_CLIENT link local: [undef]
Tue Oct 21 13:47:01 2014 TCPv4_CLIENT link remote: [AF_INET]XXX.XXX.XXX.XXX:443
Tue Oct 21 13:47:01 2014 MANAGEMENT: >STATE:1413884821,WAIT,,,
Tue Oct 21 13:47:02 2014 MANAGEMENT: >STATE:1413884822,AUTH,,,
Tue Oct 21 13:47:02 2014 TLS: Initial packet from [AF_INET]XXX.XXX.XXX.XXX:443, sid=f458c65b 4813aa79
Tue Oct 21 13:47:05 2014 VERIFY OK: depth=1, C=FR, ST=Here, L=HereAgain, O=login, OU=login_OU, CN=login, name=login, emailAddress=log.login@gmail.com
Tue Oct 21 13:47:05 2014 VERIFY OK: depth=0, C=FR, ST=Here, L=HereAgain, O=login, OU=login_OU, CN=login, name=login, emailAddress=log.login@gmail.com
Tue Oct 21 13:47:11 2014 Data Channel Encrypt: Cipher 'AES-256-CBC' initialized with 256 bit key
Tue Oct 21 13:47:11 2014 Data Channel Encrypt: Using 160 bit message hash 'SHA1' for HMAC authentication
Tue Oct 21 13:47:11 2014 Data Channel Decrypt: Cipher 'AES-256-CBC' initialized with 256 bit key
Tue Oct 21 13:47:11 2014 Data Channel Decrypt: Using 160 bit message hash 'SHA1' for HMAC authentication
Tue Oct 21 13:47:11 2014 Control Channel: TLSv1, cipher TLSv1/SSLv3 DHE-RSA-AES256-SHA, 1024 bit RSA
Tue Oct 21 13:47:11 2014 [login] Peer Connection Initiated with [AF_INET]XXX.XXX.XXX.XXX:443
Tue Oct 21 13:47:12 2014 MANAGEMENT: >STATE:1413884832,GET_CONFIG,,,
Tue Oct 21 13:47:13 2014 SENT CONTROL [login]: 'PUSH_REQUEST' (status=1)
Tue Oct 21 13:47:14 2014 PUSH: Received control message: 'PUSH_REPLY,redirect-gateway def1 bypass-dhcp,dhcp-option DNS 8.8.8.8,dhcp-option DNS 8.8.4.4,route 10.8.0.1,topology net30,ping 10,ping-restart 120,ifconfig 10.8.0.6 10.8.0.5'
Tue Oct 21 13:47:14 2014 OPTIONS IMPORT: timers and/or timeouts modified
Tue Oct 21 13:47:14 2014 OPTIONS IMPORT: --ifconfig/up options modified
Tue Oct 21 13:47:14 2014 OPTIONS IMPORT: route options modified
Tue Oct 21 13:47:14 2014 OPTIONS IMPORT: --ip-win32 and/or --dhcp-option options modified
Tue Oct 21 13:47:14 2014 do_ifconfig, tt->ipv6=0, tt->did_ifconfig_ipv6_setup=0
Tue Oct 21 13:47:14 2014 MANAGEMENT: >STATE:1413884834,ASSIGN_IP,,10.8.0.6,
Tue Oct 21 13:47:14 2014 open_tun, tt->ipv6=0
Tue Oct 21 13:47:14 2014 TAP-WIN32 device [Connexion au réseau local 2] opened: \\.\Global\{ECCF8E7A-B639-4B27-A9CD-9F230C98FDFC}.tap
Tue Oct 21 13:47:14 2014 TAP-Windows Driver Version 9.9
Tue Oct 21 13:47:14 2014 Notified TAP-Windows driver to set a DHCP IP/netmask of 10.8.0.6/255.255.255.252 on interface {ECCF8E7A-B639-4B27-A9CD-9F230C98FDFC} [DHCP-serv: 10.8.0.5, lease-time: 31536000]
Tue Oct 21 13:47:14 2014 Successful ARP Flush on interface [15] {ECCF8E7A-B639-4B27-A9CD-9F230C98FDFC}
Tue Oct 21 13:47:19 2014 TEST ROUTES: 2/2 succeeded len=1 ret=1 a=0 u/d=up
Tue Oct 21 13:47:19 2014 C:\Windows\system32\route.exe ADD XXX.XXX.XXX.XXX MASK 255.255.255.255 YYY.YYY.YYY.YYY
Tue Oct 21 13:47:19 2014 ROUTE: CreateIpForwardEntry succeeded with dwForwardMetric1=20 and dwForwardType=4
Tue Oct 21 13:47:19 2014 Route addition via IPAPI succeeded [adaptive]
Tue Oct 21 13:47:19 2014 C:\Windows\system32\route.exe ADD 193.51.113.1 MASK 255.255.255.255 YYY.YYY.YYY.YYY IF 11
Tue Oct 21 13:47:19 2014 ROUTE: CreateIpForwardEntry succeeded with dwForwardMetric1=20 and dwForwardType=4
Tue Oct 21 13:47:19 2014 Route addition via IPAPI succeeded [adaptive]
Tue Oct 21 13:47:19 2014 C:\Windows\system32\route.exe ADD 0.0.0.0 MASK 128.0.0.0 10.8.0.5
Tue Oct 21 13:47:19 2014 ROUTE: CreateIpForwardEntry succeeded with dwForwardMetric1=30 and dwForwardType=4
Tue Oct 21 13:47:19 2014 Route addition via IPAPI succeeded [adaptive]
Tue Oct 21 13:47:19 2014 C:\Windows\system32\route.exe ADD 128.0.0.0 MASK 128.0.0.0 10.8.0.5
Tue Oct 21 13:47:20 2014 ROUTE: CreateIpForwardEntry succeeded with dwForwardMetric1=30 and dwForwardType=4
Tue Oct 21 13:47:20 2014 Route addition via IPAPI succeeded [adaptive]
Tue Oct 21 13:47:20 2014 MANAGEMENT: >STATE:1413884840,ADD_ROUTES,,,
Tue Oct 21 13:47:20 2014 C:\Windows\system32\route.exe ADD 10.8.0.1 MASK 255.255.255.255 10.8.0.5
Tue Oct 21 13:47:20 2014 ROUTE: CreateIpForwardEntry succeeded with dwForwardMetric1=30 and dwForwardType=4
Tue Oct 21 13:47:20 2014 Route addition via IPAPI succeeded [adaptive]
Tue Oct 21 13:47:20 2014 Initialization Sequence Completed
Tue Oct 21 13:47:20 2014 MANAGEMENT: >STATE:1413884840,CONNECTED,SUCCESS,10.8.0.6,XXX.XXX.XXX.XXX
Tue Oct 21 13:48:07 2014 C:\Windows\system32\route.exe DELETE 10.8.0.1 MASK 255.255.255.255 10.8.0.5
Tue Oct 21 13:48:07 2014 Route deletion via IPAPI succeeded [adaptive]
Tue Oct 21 13:48:07 2014 C:\Windows\system32\route.exe DELETE XXX.XXX.XXX.XXX MASK 255.255.255.255 YYY.YYY.YYY.YYY
Tue Oct 21 13:48:07 2014 Route deletion via IPAPI succeeded [adaptive]
Tue Oct 21 13:48:07 2014 C:\Windows\system32\route.exe DELETE 193.51.113.1 MASK 255.255.255.255 YYY.YYY.YYY.YYY
Tue Oct 21 13:48:07 2014 Route deletion via IPAPI succeeded [adaptive]
Tue Oct 21 13:48:07 2014 C:\Windows\system32\route.exe DELETE 0.0.0.0 MASK 128.0.0.0 10.8.0.5
Tue Oct 21 13:48:07 2014 Route deletion via IPAPI succeeded [adaptive]
Tue Oct 21 13:48:07 2014 C:\Windows\system32\route.exe DELETE 128.0.0.0 MASK 128.0.0.0 10.8.0.5
Tue Oct 21 13:48:07 2014 Route deletion via IPAPI succeeded [adaptive]
Tue Oct 21 13:48:07 2014 Closing TUN/TAP interface
Tue Oct 21 13:48:07 2014 SIGTERM[hard,] received, process exiting
Tue Oct 21 13:48:07 2014 MANAGEMENT: >STATE:1413884887,EXITING,SIGTERM,,
iptables-save :
[code]*filter
:INPUT DROP [59:3189]
:FORWARD DROP [1075:63661]
:OUTPUT DROP [1041:188059]
:fail2ban-apache - [0:0]
:fail2ban-apache-badbots - [0:0]
:fail2ban-apache-nohome - [0:0]
:fail2ban-apache-noscript - [0:0]
:fail2ban-apache-overflows - [0:0]
:fail2ban-exim - [0:0]
:fail2ban-pam-generic - [0:0]
:fail2ban-php-url-fopen - [0:0]
:fail2ban-ssh - [0:0]
:fail2ban-ssh-ddos - [0:0]
-A INPUT -p tcp -m multiport --dports 25,465 -j fail2ban-exim
-A INPUT -p tcp -m multiport --dports 80,443 -j fail2ban-php-url-fopen
-A INPUT -p tcp -m multiport --dports 80,443 -j fail2ban-apache-nohome
-A INPUT -p tcp -j fail2ban-apache-badbots
-A INPUT -p tcp -m multiport --dports 80,443 -j fail2ban-apache-overflows
-A INPUT -p tcp -m multiport --dports 80,443 -j fail2ban-apache-noscript
-A INPUT -p tcp -m multiport --dports 80,443 -j fail2ban-apache
-A INPUT -p tcp -m multiport --dports 22 -j fail2ban-ssh-ddos
-A INPUT -p tcp -j fail2ban-pam-generic
-A INPUT -p tcp -m multiport --dports 22 -j fail2ban-ssh
-A INPUT -j LOG
-A INPUT -m state --state RELATED,ESTABLISHED -j ACCEPT
-A INPUT -i lo -j ACCEPT
-A INPUT -p icmp -j ACCEPT
-A INPUT -p tcp -m tcp --dport 443 -j ACCEPT
-A INPUT -p tcp -m tcp --dport XXXX -j ACCEPT
-A INPUT -p tcp -m tcp --dport YYYY -j ACCEPT
-A OUTPUT -j LOG
-A OUTPUT -m state --state RELATED,ESTABLISHED -j ACCEPT
-A OUTPUT -o lo -j ACCEPT
-A OUTPUT -p tcp -m tcp --dport 25 -j ACCEPT
-A OUTPUT -p tcp -m tcp --dport 465 -j ACCEPT
-A fail2ban-apache -j RETURN
-A fail2ban-apache-badbots -j RETURN
-A fail2ban-apache-nohome -j RETURN
-A fail2ban-apache-noscript -j RETURN
-A fail2ban-apache-overflows -j RETURN
-A fail2ban-exim -j RETURN
-A fail2ban-pam-generic -j RETURN
-A fail2ban-php-url-fopen -j RETURN
-A fail2ban-ssh -j RETURN
-A fail2ban-ssh-ddos -j RETURN
COMMIT
Completed on Tue Oct 21 12:01:05 2014
Generated by iptables-save v1.4.14 on Tue Oct 21 12:01:05 2014
*nat
:PREROUTING ACCEPT [1495:106542]
:INPUT ACCEPT [98:6028]
:OUTPUT ACCEPT [1102:191773]
:POSTROUTING ACCEPT [49:2982]
-A POSTROUTING -o eth0 -j MASQUERADE
-A POSTROUTING -s 10.8.0.0/24 -o eth0 -j MASQUERADE
COMMIT
[/code]
nouveau server.conf openvpn
[code]# Serveur TCP/443
mode server
proto tcp
port 443
port-share 127.0.0.1 XXXX
dev tun
Clés certificats
ca key/ca.crt
cert key/server.crt
key key/server.key
dh key/dh1024.pem
tls-auth key/ta.key 1
key-direction 0
cipher AES-256-CBC
Réseau
server 10.8.0.0 255.255.255.0
push "redirect-gateway def1 bypass-dhcp"
push "dhcp-option DNS 8.8.8.8"
push "dhcp-option DNS 8.8.4.4"
keepalive 10 120
Sécurité
user nobody
group nogroup
persist-key
persist-tun
comp-lzo
Log
verb 3
mute 20
status openvpn-status.log
log-append /var/log/openvpn.log
[/code]
Nouveau client.ovpn
[code]# Client
client
dev tun
proto tcp-client
remote XXX.XXX.XXX.XXX
resolv-retry infinite
cipher AES-256-CBC
Clé
ca ca.crt
cert login.crt
key login.key
tls-auth ta.key 1
key-direction 1
Sécurité
nobind
persist-key
persist-tun
comp-lzo
verb 3[/code]
Voila, merci d’avance !