÷òî-òî ìíå íà ìîè âîïðîñû íà ýòîé ñòðàíèöå ïî ïîâîäó ìàðøðóòîâ íå îñîáî îòâåòèëè, êàê èõ äàâàòü íà êëèåíòñêóþ ñòîðîíó!
OlegaVB, à êóäà è â êàêîì ôîðìàòå âû èõ ïðîïèñûâàåòå?
ASUS wl-500gP with WL500gp-1.9.2.7-d-r473, asterisk, poptop, ether-wake, knockd.
Âîò ÷àñòü êîíôèãà OpenVPN ñåðâåðà
 äàííîì ñëó÷àå àäðåñ ñåðâåðà 10.8.0.1#çàäàåì IP-àäðåñ ñåðâåðà è ìàñêó ïîäñåòè
# (âèðòóàëüíîé ñåòè)
server 10.8.0.0 255.255.255.0
#çàäàåì ÌÀÐØÐÓÒ êîòîðûé ïåðåäà¸ì êëèåíòòó
# è ìàñêó ïîäñåòè äëÿ òîãî ÷òîáû îí "âèäåë"
# ñåòü çà îïåíâïí ñåðâåðîì (ñåòè 192.168.1.0/24 è 192.168.2.0/24)
push "route 192.168.1.0 255.255.255.0"
push "route 192.168.2.0 255.255.255.0"
#ýòîé ñòðîêîé îïèñûâàåì ìàðøðóòû ê ñåòÿì ê êîòîðûì õîäèòü ÷åðåç òóíåëü
route 192.168.1.0 255.255.255.0
route 192.168.2.0 255.255.255.0
Ñåòè çà ñåðâåðîì, êóäà áóäóò õîäèòü êëèåíòû 192.168.1.0/255.255.255.0 è 192.168.2.0/255.255.255.0
Ïðè ïîäêëþ÷åíèè êëèåíò ïîëó÷àåò àäðåñ 10.8.0.6
Ïðè ïîäêëþ÷åíèè ó êëèåíòà âûïîëíÿåòñÿÄëÿ âèíäû áóäóò âûïîëíÿòñÿ åå êîìàíäû, íî ñìûñë òîò æå.Oct 2 08:42:32 openvpn[1117]: /sbin/route add -net 192.168.1.0 netmask 255.255.255.0 gw 10.8.0.5
Oct 2 08:42:32 openvpn[1117]: /sbin/route add -net 192.168.2.0 netmask 255.255.255.0 gw 10.8.0.5
Oct 2 08:42:32 openvpn[1117]: /sbin/route add -net 10.8.0.1 netmask 255.255.255.255 gw 10.8.0.5
 ëþáîì ðóêîâîäñòâå ïî OpenVPN ýòî íàïèñàíî.
Asus RT-N16 1.9.2.7-rtn-r2730 + D-link DNS 323 1.08 + WDTV Live 1.01.24
À òåìà ïðî POPTOP, áóäó ðàä, åñëè âû è äëÿ POPTOP ïîäðîáíî âñå íàïèøèòå!Âîò ÷àñòü êîíôèãà OpenVPN ñåðâåðà
øëþçîì îí ÿâëÿåòñÿ òîëüêî äëÿ ìàøèí ñâîåé ëîêàëüíîé ñåòè, äëÿ óäàëåííûõ ìû æå ñíèìàåì ãàëî÷êó ïðî îñíîâíîé øëþç â íàñòðîéêàõ, ïîýòîìóÓ Âàñ VPN ñåðâåð ÿâëÿåòñÿ øëþçîì çà÷åì ÷òî ïðîïèñûâàòü ó êëèåíòà ???
åñëè ïîäñåòè áóäóò ðàçíûìè, òî óäàëåííàÿ ìàøèíà(åñëè áóäóò îòñóòñòâîâàòü ìàðøðóòû) äàæå íå áóäåò çíàòü ïðî ïîäñåòü ëîêàëüíîé ñåòè ðîóòåðà, îíè âñå çàïðîñû ê ýòèì ip àäðåñàì áóäóò îòïðàâëÿòü ÷åðåç ñâîé øëþç ïî-óìîë÷àíèþ!... âîïðîñ òàêîé âîçìîæíî èñïîëüçîâàòü â í¸ì ïîäñåòü îòëè÷íóþ îò ñåòè ñàìîãî ðîóòåðà ?
...
êàêèå èçìåíåíèÿ è äîïîëíåíèÿ ïðèä¸òñÿ ñäåëàòü ?
Ñïàñèáî çà íàâîäêó, ïîèñ÷ó, ïîòîìó êàê èíòåðåñíî óíèâåðñàëüíîå ðåøåíèå!))ß íå ïðîáîâàë îòïðàâëÿòü ìàðøåðóòû êëèåíòó íî ýòî äåàëàåòñÿ ñ peer-up ñêðèïòû ïîèèùèòå â èíåòå
ASUS wl-500gP with WL500gp-1.9.2.7-d-r473, asterisk, poptop, ether-wake, knockd.
ëîêàëêà ðîóòåð 172.16.20.1\24
ïîïòîï 10.16.253.49 ,10.16.253.50 êëèåíòó
íå õîäèò ñ êëèåíòà äàëüøå 10.16.253.49
îáúÿñíèòå êàê èñïðàâèòü ?
è åù¸ , ïðîïèñûâàþþ ñòàòèê ÷åðåç âýáìîðäó , ñîõðàíÿåòñÿ, íî â êîíñîëè route íå âûäà¸ò ýòèõ ìàðøðóòîâ (ñ ýòèì ïîíÿë, ÷åðåç âýá íåðàáîòàåò, ñòðàííî ïî÷åìó ïðî ýòî íåò â ôàêå)
ïðîøèâêà wl500g-1.9.2.7-d
Last edited by Kugel; 05-10-2009 at 11:35.
1) Ïðàâèëüíî ñîçäàéòå ïðàâèëà iptablesëîêàëêà ðîóòåð 172.16.20.1\24
ïîïòîï 10.16.253.49 ,10.16.253.50 êëèåíòó
íå õîäèò ñ êëèåíòà äàëüøå 10.16.253.49
îáúÿñíèòå êàê èñïðàâèòü ?
2) Êàê ïèñàëîñü âûøå ïðîïèøèòå â ñêðèïòàõ ip-up ip-down ïîäíÿòèå ðîóòîâ íà VPN êëåíòà
ïðàâèëà firewall
÷òî-òî â ýòîì ðîäåCode:iptables -I FORWARD -i ppp+ -s 10.16.253.49/28 -d 172.16.20.1/24 -j ACCETP iptables -I INPUT -i ppp+ -s 10.16.253.49/28 -d 172.16.20.1/24 -j ACCETP
ip-up
Code:route add 10.16.253.50 mask 255.255.255.255 gw 10.16.253.49
Ìîæåò ÷åì-òî ïîìîæåò.... Ïî÷èòàéòå ìîè ïîñòû íà÷èíàÿ ñ ýòîãî
ß èç-çà îòñóòñòâèÿ âðåìåíè ïîêà îòêàçàëñÿ îò çàòåè ñ ìàðøðóòàìè, ïðîñòî ñäåëàë òó ïîäñåòü, ÷òî è LAN
ASUS wl-500gP with WL500gp-1.9.2.7-d-r473, asterisk, poptop, ether-wake, knockd.
çàïóòàëñÿ ñ ìàðøðóòàìè..
êàê ñäåëàòü òàê, ÷òîáû íàðîäó äàâàòü äîñòóï â èíåò ÷åðåç ðîóòåð, òîëüêî ïîñëå ïîäíÿòèÿ âïí?
WAN - 192.168.2.226
WL 500gpv2 - 172.16.0.1
DHCP - 172.16.0.235-245
VPN server 172.16.0.2
VPN client 172.16.246-253
1) Ðàçäåëè ñåòè
2) Åñëè ñåòè íå ðàçäåëèòü òî â iptablec ñîçäàé ïðàâèëà áëîêèðîâêè ê WAN îò ëîêàëüíûìè ip êëèåíòîâ è ïðàâèëî íà äîñòóï ê Wan îò VPN-ip-êëèåíòîâ .
èäåþ ÿ ïîíÿë, à âîò ðåàëèçàöèþ )
êàê ðàç çàòðóäíåíèÿ â iptables
÷òî â òàêîì äóõå
ïîïèñûâàåòå äëÿ êàæäîãî àäðåñàCode:iptables -I FORWARD -s 172.16.0.235 -o WAN -j DROP iptables -I INTUP -s 172.16.0.235 -o WAN -j DROP iptables -I FORWARD -s 172.16.246 -o WAN -j ACCEPT iptables -I INTUP -s 172.16.0.235 -o WAN -j ACCETP
ãäå WAN íàçâàíèå âíåøíåãî èíòåðôåéñà äëÿ PPPoE PPTP L2TP ýòî ppp0 äëÿ ethernet vlan1
èëè åùå ÷òî íèáóòü â òàêîì ïëàíå
ìîæíî ñäåëàòü äëÿ ïîäñåòè óêàçàâ ìàñêó íî çäåñü ñâîè íî â ipables âûñòàâëåí broadcast àäðåñ äëÿ òîé ñåòè è åñëè ñåòè ïåðåñåêóòñÿ áóäóò êîíôëèêòû
iptables -I IOUTPUT -i WAN -d 172.16.0.235 -j DROP
òàêæå ìîæíî äîáàâèòü åùå ôèëüòàöèþ ïî MAC ïîñìîòðè ïî ôîðóìó. ß íå äåëàë
Last edited by Wolfgun; 07-10-2009 at 09:47.
Òîâàðèùè , âûëîæèòå ïëèç ôàéë /usr/lib/pptpd/pptpd-logwtmp.so
à òî ó ìåíÿ îí îòñóñòâóåò , ïîïòîï ïåðåóñòàíàâëèâàë ...
Oct 7 18:07:55 pptpd[196]: CTRL: Starting call (launching pppd, opening GRE)
Oct 7 18:07:55 pppd[197]: File not found
Oct 7 18:07:55 pppd[197]: Couldn't load plugin /usr/lib/pptpd/pptpd-logwtmp.so
Oct 7 18:07:55 pptpd[196]: GRE: read(fd=7,buffer=4205cc,len=8196) from PTY fail
ed: status = -1 error = Input/output error, usually caused by unexpected termina
tion of pppd, check option syntax and pppd logs
Oct 7 18:07:55 pptpd[196]: CTRL: PTY read or GRE write failed (pty,gre)=(7,8)