Pular para o conteúdo principal

Ubuntu OpenVPN Server and Industrial VPN Router OpenVPN Client :

Comentários

49 comentários

  • Kyle Reynolds

    There is a setting on the eWON that discards pings by default on the WAN side. You can change this setting in the comcfg.txt file.
    image
    Default is "3" which discards pings. Change to "1" or "2" to reply to pings.

    0
  • ssmanku1699

    Hi Kyle ,

    Thanks for the reply . I checked the setting for WANItf Prot . Its 1 there .

    Thanks

    0
  • Kyle Reynolds

    I'm sorry, I mis-typed. Default is 1 and discards pings. Please change to 2 or 3.

    0
  • ssmanku1699

    Now in ewon real time logs following error is remaining :-

    echo "deb http://swupdate.openvpn.net/apt <OSRELEASE> main" > /etc/apt/sources.list.d/swupdate.openvpn.net.list

    And I cannot ping the ewon VPN IP Address 10.8.0.6 from the ubuntu server .

    Please assist !

    Thanks

    0
  • Kyle Reynolds

    Using our device with 3rd party software (anything other than eCatcher or eFive) is currently not supported, however we do have plans to release instructions for configuring with OpenVPN in the future. I would refer you to your local distributor in the meantime. Was this device purchased in India?

    0
  • Kyle Reynolds

    Hi @ssmanku1699,

    Here is the first draft of our instructions for connecting the eWON with an OpenVPN server instead of eCatcher. We have successfully tested these in a lab setting (using VirtualBox as in the instructions) and on Microsoft Azure, but there was some troubleshooting involved that may not be fully described in the document. You should expect to do some troubleshooting depending on your local environment and keep in mind that we are still in the early stages of testing this configuration. We don't recommend using this configuration as-is in a production environment, and significant security hardening should be done before deploying.

    openVPN App Note Rev1.pdf (268.1 KB)

    client.ovpn (251 Bytes)
    server.conf (11.0 KB)
    vars (8.2 KB)

    Kyle

     

    0
  • ssmanku1699

    Thanks so much Kyle . I will try out to configure exactly the way mentioned in your shared docs . If I stuck somewhere , get back to you .

    0
  • _OmniAuth_AuthHash_1

    Hi kyle,
    I tried to connect eWON with third party software. For that i refer document following by openVPN App Note Rev1.pdf. I am using amazon server as ubuntu server. But when i run scp command to transfer server.req to my local CA machine it gives me error like permission denied(publickey,password).

    Please do needful help,thank you in advance.

    0
  • Kyle Reynolds

    When you run the scp command on what? The eWON or the server?

    0
  • _OmniAuth_AuthHash_1

    When i run scp command for transferring the file from my machine to server(Amazon ubuntu server) it is running. But when i use scp command for transferring the file from my server (Amazon ubuntu server) to machine,it gives me error like permission denied (publickey,password).

    0
  • _OmniAuth_AuthHash_1

    Hi Kyle,

    when i start openvpn server with following command systemctl start openvpn@server
    it gives me error like

    OpenSSL: error:0B080074:x509 certificate routines:X509_check_private_key:key values mismatch

    Cannot load private key file /etc/openvpn/server.key

    Error: private key password verification failed

    Exiting due to fatal error

    How can i resolve this?

    Thank you in advance

    0
  • Kyle Reynolds

    The scp issue is a permissions issue. When you say your machine, is this a Linux or Windows PC? Either way you need to give write permission to the Amazon server to write to your machine.

    This OpenSSL error is happening because you put a password on your private key. Please create a new key without a password.

    0
  • _OmniAuth_AuthHash_1

    Thank you so much kyle. If I stuck somewhere , get back to you .

    0
  • _OmniAuth_AuthHash_1

    Hi kyle,

    I done all the configurations according to openVPN App Rev1 Document. But after completing all the steps i found in ewon summary page the status of the vpn is not configured.

    one confusion is what should i select in Setup>System>Communications>Networking>VPN Connection>Outgoing

    There is one option in outgoing page named Connect to:What should I select in that configuration.

    Other EWON/VPN Server/Efive VPN Server

    For better understanding I attached one image of this page.

    Thank you in advance

    0
  • Kyle Reynolds

    I"m sorry about the delay:

    Remote VPN WAN: looks correct (Defined Manually)

    Connect to : should be VPN Server and contain your Keys.

    Did you check the Logs? Are your keys right or is it not connecting to the VPN server?

    0
  • _OmniAuth_AuthHash_1

    Yes, my keys are right but it does not connect to the VPN Server. After adding certificates files in Flexy /usr directory, you mention in last step reboot the flexy. On reboot page what should i select None/Enable Remote Wizard.

    I tested with None and click on reboot. After rebooting the flexy i go to summary page and checked VPN Status. It is still show Not configured.

    Please tell me the above step that i have performed is okay or not.

    0
  • _OmniAuth_AuthHash_1

    Hi kyle,
    I have attached one document regarding difficulties found in flexy.

    Please revert me. Thank you in advance.

    Findind difficulties in flexy.docx (256 KB)

    0
  • Kyle Reynolds

    None. You just need to reboot or power cycle the Flexy.

    In the Word doc you sent you say, "After putting that configuration files in flexy GUI, I have facing one difficulty that when I refresh the browser page, my private key will automatically changed." The key has not changed, it is just hashed so that it is not showing in "plain text" for security reasons.

    You are missing the following line from you server.conf file:

    ns-cert-type client
    

    If this does not help, can you please share the logs from both the Server and clients.

    Thank you,

    Kyle

    0
  • _OmniAuth_AuthHash_1

    Do u have your skype id that we can have conversations faster ?

    0
  • _OmniAuth_AuthHash_1

    Hi kyle,

    I have attached server log file.

    How can i create client log file from ewon flexy side ?

    log.txt (4.19 KB)

    0
  • _OmniAuth_AuthHash_1

    Hi kyle,

    Sorry for the inconvenience, Refer this file as server log file.

    log.txt (1.65 KB)

    0
  • _OmniAuth_AuthHash_1

    Gentle reminder:

    0
  • Kyle Reynolds

    Sorry, I was tied up all day yesterday. I'd like to help you get this resolved today.

    The server log did not contain any errors and it looks like the client connected and received an IP address, so it appears the issue is with the eWON configuration. Can you please create a backup of the eWON using eBuddy (make sure to check "Include support files") and send that to me?

    0
  • _OmniAuth_AuthHash_1

    Hi kyle, I have attached the backup of eWON including support files. Check and revert me if any issue is there in eWON Configurations.

    Thank you in advance.

    MOVED TO STAFF NOTE (240 KB)

    0
  • Kyle Reynolds

    The real time log on the eWON is filled with this error:

    Your client.ovpn file contains this erroneous line:

    image

    Try removing it.

    0
  • _OmniAuth_AuthHash_1

    Hi kyle, I have tried with removing that but it still shows VPN Configuration is not connected.

    For your reference I sent you the backup of eWON with correction.

    MOVED TO STAFF NOTE (257 KB)

    0
  • Kyle Reynolds

    I'm sorry for the delay. I tried to recreate this today, but was unable to. Will work again on this tomorrow-

    How did you create your keys? Did you create a separate CA Server? Were you following this guide: https://www.digitalocean.com/community/tutorials/how-to-set-up-an-openvpn-server-on-ubuntu-18-04 ?

    In server.conf can you change verb to 9 here :

    [ Set the appropriate level of log file verbosity.

    0 is silent, except for fatal errors
    4 is reasonable for general usage
    5 and 6 can help to debug connection problems
    9 is extremely verbose
    HMS increase to 5 to help debug if there is an issue
    verb 9
    

    ]

    And in comcfg.txt make sure VPNDiag is set to 8.

    We need to get some kind of error in the logs to resolve this.

    0
  • Kyle Reynolds

    One thing I did not notice at first going through the instructions again is you need to make sure some settings are changed in the EasyRSA var file:

    Execute the steps shown in the Digital Ocean OpenVPN Setup Step 2 to build the CA. The default names will be used in this app note as shown in the Digital Ocean OpenVPN Setup. The following adjustments must be made to the vars file. The vars file must include the following lines uncommented.

    set_var EASYRSA_KEY_SIZE 2048
    set_var EASYRSA_NS_SUPPORT "yes"
    set_var EASYRSA_NS_COMMENT "Easy-RSA Generated Certificate"
    

    Check to make sure you have these settings in the var file and if not, please update them and re-create the certs.

    Kyle

    0
  • _OmniAuth_AuthHash_1

    Hi Kyle,

    We have holidays till Sunday.I will try on monday and update you.

    Thank you in advance

    0
  • _OmniAuth_AuthHash_1

    Hi Kyle,

    Do you have any immediate contact like skype id or anything else ?

    So that we will solve this problem easily.

    0

Por favor, entrar para comentar.