Salut,
J’ai créé un tunnel avec Openvpn sur ma passerelle pfSense.
Je me connecte pour des essais avec mon eeepc sous squeeze (connecté par l’extérieur - ppp)
root@eee:~# openvpn /etc/openvpn/client.conf
...
Mon May 9 10:09:47 2011 Data Channel Encrypt: Cipher 'BF-CBC' initialized with 128 bit key
Mon May 9 10:09:47 2011 Data Channel Encrypt: Using 160 bit message hash 'SHA1' for HMAC authentication
Mon May 9 10:09:47 2011 Data Channel Decrypt: Cipher 'BF-CBC' initialized with 128 bit key
Mon May 9 10:09:47 2011 Data Channel Decrypt: Using 160 bit message hash 'SHA1' for HMAC authentication
Mon May 9 10:09:47 2011 Control Channel: TLSv1, cipher TLSv1/SSLv3 DHE-RSA-AES256-SHA, 2048 bit RSA
Mon May 9 10:09:47 2011 [www.hotspot.zehome.org] Peer Connection Initiated with [AF_INET]41.188.26.122:1194
Mon May 9 10:09:50 2011 SENT CONTROL [www.hotspot.zehome.org]: 'PUSH_REQUEST' (status=1)
Mon May 9 10:09:50 2011 PUSH: Received control message: 'PUSH_REPLY,route 192.168.0.0 255.255.252.0,route 192.168.100.1,topology net30,ping 10,ping-restart 60,ifconfig 192.168.100.6 192.168.100.5'
Mon May 9 10:09:50 2011 OPTIONS IMPORT: timers and/or timeouts modified
Mon May 9 10:09:50 2011 OPTIONS IMPORT: --ifconfig/up options modified
Mon May 9 10:09:50 2011 OPTIONS IMPORT: route options modified
Mon May 9 10:09:50 2011 ROUTE: default_gateway=UNDEF
Mon May 9 10:09:50 2011 TUN/TAP device tun0 opened
Mon May 9 10:09:50 2011 TUN/TAP TX queue length set to 100
Mon May 9 10:09:50 2011 /sbin/ifconfig tun0 192.168.100.6 pointopoint 192.168.100.5 mtu 1500
Mon May 9 10:09:50 2011 /sbin/route add -net 192.168.0.0 netmask 255.255.252.0 gw 192.168.100.5
Mon May 9 10:09:50 2011 /sbin/route add -net 192.168.100.1 netmask 255.255.255.255 gw 192.168.100.5
Mon May 9 10:09:50 2011 Initialization Sequence Completed
[code]$ netstat -ie
Table d’interfaces noyau
eth0 Link encap:Ethernet HWaddr 00:23:54:7c:fb:b1
adr inet6: fe80::223:54ff:fe7c:fbb1/64 Scope:Lien
UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1
RX packets:914 errors:0 dropped:0 overruns:0 frame:0
TX packets:100 errors:0 dropped:0 overruns:0 carrier:3
collisions:0 lg file transmission:1000
RX bytes:141459 (138.1 KiB) TX bytes:12520 (12.2 KiB)
Interruption:27
lo Link encap:Boucle locale
inet adr:127.0.0.1 Masque:255.0.0.0
adr inet6: ::1/128 Scope:Hôte
UP LOOPBACK RUNNING MTU:16436 Metric:1
RX packets:8 errors:0 dropped:0 overruns:0 frame:0
TX packets:8 errors:0 dropped:0 overruns:0 carrier:0
collisions:0 lg file transmission:0
RX bytes:560 (560.0 B) TX bytes:560 (560.0 B)
ppp0 Link encap:Protocole Point-à-Point
inet adr:10.128.7.210 P-t-P:10.6.6.6 Masque:255.255.255.255
UP POINTOPOINT RUNNING NOARP MULTICAST MTU:1500 Metric:1
RX packets:946 errors:0 dropped:0 overruns:0 frame:0
TX packets:1522 errors:0 dropped:0 overruns:0 carrier:0
collisions:0 lg file transmission:3
RX bytes:97099 (94.8 KiB) TX bytes:196801 (192.1 KiB)
tun0 Link encap:UNSPEC HWaddr 00-00-00-00-00-00-00-00-00-00-00-00-00-00-00-00
inet adr:192.168.100.6 P-t-P:192.168.100.5 Masque:255.255.255.255
UP POINTOPOINT RUNNING NOARP MULTICAST MTU:1500 Metric:1
RX packets:0 errors:0 dropped:0 overruns:0 frame:0
TX packets:443 errors:0 dropped:0 overruns:0 carrier:0
collisions:0 lg file transmission:100
RX bytes:0 (0.0 B) TX bytes:37024 (36.1 KiB)
wlan0 Link encap:Ethernet HWaddr 00:22:43:3b:e5:9b
UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1
RX packets:0 errors:0 dropped:2 overruns:0 frame:0
TX packets:90 errors:0 dropped:0 overruns:0 carrier:0
collisions:0 lg file transmission:1000
RX bytes:0 (0.0 B) TX bytes:3780 (3.6 KiB)
Interruption:18 Mémoire:f8080000-f8080100[/code]
root@eee:~# route -n
Table de routage IP du noyau
Destination Passerelle Genmask Indic Metric Ref Use Iface
192.168.100.1 192.168.100.5 255.255.255.255 UGH 0 0 0 tun0
192.168.100.5 0.0.0.0 255.255.255.255 UH 0 0 0 tun0
10.6.6.6 0.0.0.0 255.255.255.255 UH 0 0 0 ppp0
192.168.0.0 192.168.100.5 255.255.252.0 UG 0 0 0 tun0
0.0.0.0 0.0.0.0 0.0.0.0 U 0 0 0 ppp0
Maintenant je suis un peu couillon… Des pings sur les ip du réseau “tunnelé” ne donne rien… (sur 192.168.0.0/22 ou 192.168.100.0/24)
Que faire pour avoir accès aux machines de mon lan ?


