Доброго дня, коллеги.локальная сеть 192.168.0.0/24
впн: 10.10.100.0/24
проходит пинг к: 10.10.100.1 а также к клиенту 10.10.100.6
но проблема:
1. с сервера не проходит пинг к 10.10.100.2 (а должен ли проходить?)
2. с сервера не проходит пинг в сети за клиентом
freebsd# ifconfig
vr0: flags=8843<UP,BROADCAST,RUNNING,SIMPLEX,MULTICAST> metric 0 mtu 1500
options=82808<VLAN_MTU,WOL_UCAST,WOL_MAGIC,LINKSTATE>
ether 84:c9:b2:70:21:c9
inet 81.30.20.126 netmask 0xfffffffc broadcast 81.30.20.127
inet6 fe80::86c9:b2ff:fe70:21c9%vr0 prefixlen 64 scopeid 0x6
nd6 options=29<PERFORMNUD,IFDISABLED,AUTO_LINKLOCAL>
media: Ethernet autoselect (100baseTX <full-duplex>)
status: active
rl0: flags=8843<UP,BROADCAST,RUNNING,SIMPLEX,MULTICAST> metric 0 mtu 1500
options=3808<VLAN_MTU,WOL_UCAST,WOL_MCAST,WOL_MAGIC>
ether 00:16:17:6e:94:7f
inet 192.168.0.254 netmask 0xffffff00 broadcast 192.168.0.255
inet6 fe80::216:17ff:fe6e:947f%rl0 prefixlen 64 scopeid 0x7
nd6 options=29<PERFORMNUD,IFDISABLED,AUTO_LINKLOCAL>
media: Ethernet autoselect (100baseTX <full-duplex>)
status: active
plip0: flags=8810<POINTOPOINT,SIMPLEX,MULTICAST> metric 0 mtu 1500
nd6 options=29<PERFORMNUD,IFDISABLED,AUTO_LINKLOCAL>
lo0: flags=8049<UP,LOOPBACK,RUNNING,MULTICAST> metric 0 mtu 16384
options=3<RXCSUM,TXCSUM>
inet6 ::1 prefixlen 128
inet6 fe80::1%lo0 prefixlen 64 scopeid 0x9
inet 127.0.0.1 netmask 0xff000000
nd6 options=21<PERFORMNUD,AUTO_LINKLOCAL>
pflog0: flags=141<UP,RUNNING,PROMISC> metric 0 mtu 33200
nd6 options=21<PERFORMNUD,AUTO_LINKLOCAL>
tun0: flags=8051<UP,POINTOPOINT,RUNNING,MULTICAST> metric 0 mtu 1500
options=80000<LINKSTATE>
inet6 fe80::86c9:b2ff:fe70:21c9%tun0 prefixlen 64 scopeid 0xb
inet 10.10.100.1 --> 10.10.100.2 netmask 0xffffffff
nd6 options=21<PERFORMNUD,AUTO_LINKLOCAL>
Opened by PID 7309
freebsd# netstat -nr
Routing tables
Internet:
Destination Gateway Flags Refs Use Netif Expire
default 81.30.201.125 UGS 0 522964 vr0
10.10.100.0/24 10.10.100.2 UGS 0 25686 tun0
10.10.100.1 link#11 UHS 0 7 lo0
10.10.100.2 link#11 UH 0 157 tun0
81.30.201.124/30 link#6 U 0 0 vr0
81.30.201.126 link#6 UHS 0 0 lo0
127.0.0.1 link#9 UH 0 128 lo0
192.168.0.0/24 link#7 U 0 1015082 rl0
192.168.0.254 link#7 UHS 0 0 lo0
192.168.1.0/24 10.10.100.2 UGS 0 521 tun0
freebsd# less /var/log/openvpn/openvpn-status.log
OpenVPN CLIENT LIST
Updated,Wed May 2 13:44:13 2012
Common Name,Real Address,Bytes Received,Bytes Sent,Connected Since
client1,194.67.41.94:1194,4451462,7460691,Wed May 2 09:15:34 2012
ROUTING TABLE
Virtual Address,Common Name,Real Address,Last Ref
10.10.100.6,client1,194.67.41.94:1194,Wed May 2 13:43:35 2012
GLOBAL STATS
Max bcast/mcast queue length,0
END
OS FINGERPRINTS:
700 fingerprints loaded
freebsd# tcpdump -n -i tun0
tcpdump: verbose output suppressed, use -v or -vv for full protocol decode
listening on tun0, link-type NULL (BSD loopback), capture size 65535 bytes
13:56:11.689914 IP 10.10.100.1 > 10.10.100.2: ICMP echo request, id 8486, seq 11, length 64
13:56:12.690909 IP 10.10.100.1 > 10.10.100.2: ICMP echo request, id 8486, seq 12, length 64
13:56:13.691910 IP 10.10.100.1 > 10.10.100.2: ICMP echo request, id 8486, seq 13, length 64
13:56:14.692908 IP 10.10.100.1 > 10.10.100.2: ICMP echo request, id 8486, seq 14, length 64
13:56:15.693911 IP 10.10.100.1 > 10.10.100.2: ICMP echo request, id 8486, seq 15, length 64
freebsd# tcpdump -n -i tun0
tcpdump: verbose output suppressed, use -v or -vv for full protocol decode
listening on tun0, link-type NULL (BSD loopback), capture size 65535 bytes
13:57:34.569911 IP 10.10.100.1 > 10.10.100.6: ICMP echo request, id 9254, seq 43, length 64
13:57:34.621914 IP 10.10.100.6 > 10.10.100.1: ICMP echo reply, id 9254, seq 43, length 64
13:57:35.570909 IP 10.10.100.1 > 10.10.100.6: ICMP echo request, id 9254, seq 44, length 64
13:57:35.623921 IP 10.10.100.6 > 10.10.100.1: ICMP echo reply, id 9254, seq 44, length 64
13:57:36.571914 IP 10.10.100.1 > 10.10.100.6: ICMP echo request, id 9254, seq 45, length 64
13:57:36.622229 IP 10.10.100.6 > 10.10.100.1: ICMP echo reply, id 9254, seq 45, length 64
13:57:37.572913 IP 10.10.100.1 > 10.10.100.6: ICMP echo request, id 9254, seq 46, length 64
13:57:37.626593 IP 10.10.100.6 > 10.10.100.1: ICMP echo reply, id 9254, seq 46, length 64
13:57:38.573914 IP 10.10.100.1 > 10.10.100.6: ICMP echo request, id 9254, seq 47, length 64