|
|
On Jan 31, 2008 8:24 PM, Bonno Bloksma < b.bloksma@xxxxxx> wrote:
Hi,
I've attaches the message as a txt file as well to
make sure all loglines are readable.
Help, I'm at a loss. There is a lot of information
in the mail, I've tried to provide as much relevant information as
possible. I've been using OpenVPN for several years but this time I'm at a
loss. :-(
I've got several sites, most sites have a /20
network. For all sites but one it works. In the server log I can see lot's of
lines that tell me: Thu Jan 31 14:56:25 2008 linutr/194.109.163.129:63977
MULTI: bad source address from client [172.16.128.98], packet dropped Thu Jan
31 14:56:25 2008 linein2/194.109.165.42:63736 MULTI: bad source address from
client [172.16.212.212], packet dropped Thu Jan 31 14:56:25 2008
linein2/194.109.165.42:63736 MULTI: bad source address from client
[172.16.212.26], packet dropped Thu Jan 31 14:56:25 2008
linein2/194.109.165.42:63736 MULTI: bad source address from client
[172.16.208.107], packet dropped Thu Jan 31 14:56:26 2008
linein2/194.109.165.42:63736 MULTI: bad source address from client
[172.16.212.207], packet dropped
Maybe the error is obvious, but in case it isn't,
here is "some" ;-) extra info:
At one site I was still using a ssh prt-redir (ppp)
tunnel. The ppp tunnel at that site crashed yesterday and for whatever reason
the ppp device refused to be created So... Today I wanted to switch that last
site over to an OpenVPN (tun) tunnel thinking that might solve the
problem.
On the server I cannot ping the client side of the
tunnel, nor any of its interfaces So ping 172.16.1.101 does not work, nor
does ping 172.16.208.1
Now to mee this seems like a classic routing
problem but..... as far as I can see all routing lines are correct. I've also
disabled the firewall on the client machine to see if that was the problem, but
it's not.
Routing lines on the client:
Both Linux machines (client and server) have been
given a reboot just in case.... but as I feared, that wasn't the
solution.
About the log lines: Wed Jan 30 17:55:20 2008
linutr/194.109.163.129:64482 MULTI: bad source address from client
[172.16.128.98], packet dropped Wed Jan 30 17:55:22 2008
linutr/194.109.163.129:64482 MULTI: bad source address from client
[172.16.128.98], packet dropped Wed Jan 30 17:55:24 2008
linutr/194.109.163.129:64482 MULTI: bad source address from client
[172.16.128.98], packet dropped Wed Jan 30 17:55:27 2008
linutr/194.109.163.129:64482 MULTI: bad source address from client
[172.16.128.98], packet dropped Wed Jan 30 17:55:29 2008
linutr/194.109.163.129:64482 MULTI: bad source address from client
[172.16.128.98], packet dropped Wed Jan 30 17:55:32 2008
linutr/194.109.163.129:64482 MULTI: bad source address from client
[172.16.128.98], packet dropped [...] Thu Jan 31 14:56:25 2008
linutr/194.109.163.129:63977 MULTI: bad source address from client
[172.16.128.98], packet dropped Lines like these started to appear yesterday
at the moment I was unable to connect to the linein2 site. The 172.16.128.98
server is our network monitor that monitors several machines in the
172.16.0.0/16 network. The fact that these lines appear at the same time as the
error to the linein2 site started would indicate a relation to the problem with
the linein2 site. But, what would the relation be?
Thu Jan 31 14:56:25 2008
linein2/194.109.165.42:63736 MULTI: bad source address from client
[172.16.212.212], packet dropped Thu Jan 31 14:56:25 2008
linein2/194.109.165.42:63736 MULTI: bad source address from client
[172.16.212.26], packet dropped Thu Jan 31 14:56:25 2008
linein2/194.109.165.42:63736 MULTI: bad source address from client
[172.16.208.107], packet dropped Thu Jan 31 14:56:26 2008
linein2/194.109.165.42:63736 MULTI: bad source address from client
[172.16.212.207], packet dropped These are normal ip-numers at the linein2
site.
The default route on the Linux machines is to the local router. The
192.168.1.x network is local to the site and NOT routed between sites. These
have been duplicate at several sites before the problem
started.
Met vriendelijke groet, Bonno Bloksma hoofd systeembeheer
tio hogeschool hospitality en toerisme
------------------------------------------------------------------------- This SF.net email is sponsored by: Microsoft Defy all challenges. Microsoft(R) Visual Studio 2008. http://clk.atdmt.com/MRT/go/vse0120000070mrt/direct/01/
_______________________________________________ Openvpn-users mailing list Openvpn-users@xxxxxxxxxxxxxxxxxxxxx https://lists.sourceforge.net/lists/listinfo/openvpn-users
I have a configuration where I have not configured a site-to-site vpn. Just a client-to-server, and onto the internet from the server. Routing on the client is configured so that all traffic goes through the vpn.
Now, my client also happens to be the gateway to the internet for an internal network. It has a ppp link. Also, there are other machines on the internal client network. When I configure a vpn from the client (gateway machine) to the vpn server, routing from other machines
on the client network gets screwed up. (I havent bothered to see the reason why). That is, these other machines can't then access the Internet. But I get this "bad packet' message in the vpn server log corresponding to packets originating
from these other machines on the client network.
I am not saying this is your problem, but it could be.
regards, Samir
Warning: require_once(../../../archive_common.php) [function.require-once]: failed to open stream: No such file or directory in /home/openvpn/domains/openvpn.net/public_html/archive/openvpn-users/2008-02/msg00002.html on line 420
Fatal error: require_once() [function.require]: Failed opening required '../../../archive_common.php' (include_path='/usr/local/lib/php') in /home/openvpn/domains/openvpn.net/public_html/archive/openvpn-users/2008-02/msg00002.html on line 420
|