[OpenVPN home] [Date Prev] [Date Index] [Date Next]
[OpenVPN mailing lists] [Thread Prev] [Thread Index] [Thread Next]
Google
 
Web openvpn.net

Re: [Openvpn-users] RE: Routeing one way?


  • Subject: Re: [Openvpn-users] RE: Routeing one way?
  • From: Erich Titl <erich.titl@xxxxxxxx>
  • Date: Sat, 20 May 2006 18:38:10 +0200

Hi

Laurence Steele wrote:
To re-cap Capetown(SuSe) Johannesburg (2003)
LAN: 192.168.1.1 LAN: 10.0.0.1
OpenVPN: 192.168.2.1 OpenVPN: 192.168.2.2
ADSL: 165.0.0.0 (varies) ADSL: 165.0.0.0

I should have looked further down :-(





..



Might be firewall issues, depending on the type of traceroute tool. Some
use udp some icmp.


UDP

Do you allow UDP in the firewall rules for tunx, specifically with the long delays seen above?



To me it is not that obvious what's going on, you could use a tool like
tcpdump on SuSE and Ethereal on the Windoze box, run it on all
interfaces which you think traffic passes through. You will quickly see
where you get stuck.

Please let us know the results.

Unfortunately the Windoze box is 1500 km away, the Capetown box is 40km,
and while I can connect remotely,

Ok, you could at least try at the capetown box, see if your packets enter the tun interface and if a corresponding UDP



150 Opening BINARY mode data connection for ethereal-0.99.0-1.src.rpm (11268280 bytes). ################################################################################################################################ 421 Data timeout. Reconnect. Sorry.

Damn...

Mhhh... looks like your Capetown box has connection issues too.


I have turned the firewall off to no effect.

check iptables -L

I suspect a problem with
forwarding.

ctcmail:~ # cat /proc/sys/net/ipv4/ip_forward


	1
but I am not sure Suse firewall knows what the tun  interface is.  It
doesn't show in YAST.  There was a "custom" interface, unidentifable,
but it wasn't called tun0.

the above is for all interfaces

cheers

Erich

______________________
OpenVPN mailing lists
https://lists.sourceforge.net/lists/listinfo/openvpn-users