[problem help] 导入Open vpn配置后,无法正常访问网络
Tofloor
poster avatar
zhangsf
deepin
2023-11-06 23:15
Author

将使用.ovpn 配置文件改为.conf 后成功连接vpn,但常用网络无法正常访问。

Reply Favorite View the author
All Replies
zhangsf
deepin
2023-11-06 23:17
#1

配置文件如下

client
dev tun
proto tcp
remote xxx.xx.xx.xx 1194
resolv-retry infinite
nobind
persist-key
persist-tun
ca ca.crt
cert vsc-2zehq29zzi1her6xk4ktm.crt
key vsc-2zehq29zzi1her6xk4ktm.key
cipher AES-128-CBC
;comp-lzo
verb 4

Reply View the author
hotime
deepin
2023-11-07 00:01
#2
zhangsf

配置文件如下

client
dev tun
proto tcp
remote xxx.xx.xx.xx 1194
resolv-retry infinite
nobind
persist-key
persist-tun
ca ca.crt
cert vsc-2zehq29zzi1her6xk4ktm.crt
key vsc-2zehq29zzi1her6xk4ktm.key
cipher AES-128-CBC
;comp-lzo
verb 4

倒数第二行的配置comp-lzo,为什么行首多了分号?检查一下,移除这个分号再试试看

Reply View the author
zhangsf
deepin
2023-11-07 00:11
#3
hotime

倒数第二行的配置comp-lzo,为什么行首多了分号?检查一下,移除这个分号再试试看

不行,这个;号原来的ovpn里也有

Reply View the author
132******48
deepin
2023-11-07 00:22
#4
It has been deleted!
132******48
deepin
2023-11-07 00:52
#5

准备好指定位置的 cert.crt key.crt 文件,.conf文件内容如:

client
remote 'xxx.xxx.xxx'
cert '/xxx/cert.crt'
key '/xxx/key.crt'
cipher AES-256-CBC
dev tun
proto tcp
port xxxx
remote-cert-tls server
nobind
auth-nocache
script-security 2
persist-key
persist-tun
comp-lzo
user nm-openvpn
group nm-openvpn



-----BEGIN CERTIFICATE-----
**********放入你的***********
-----END CERTIFICATE-----


再导入.conf文件

Reply View the author
hotime
deepin
2023-11-07 00:54
#6
zhangsf

不行,这个;号原来的ovpn里也有

你这里提到的常用网络无法正常访问具体是什么情形?

是vpn那头的资源不能正常访问吗?
是浏览器里不能打开网站吗?
在终端中ping这些网站能ping通吗?
还是所有的ip都ping不通?
其他openvpn客户端有和你一样的情形吗?
在windows中有这样的情形吗?

Reply View the author
hotime
deepin
2023-11-07 01:03
#7
zhangsf

不行,这个;号原来的ovpn里也有

另外你有试过删掉这个分号再连接openvpn吗?

因为openvpn从服务端导出供客户端使用的配置文件中,如果服务端开启lzo压缩,那配置文件中就会有comp-lzo这项配置,如果服务端不开启lzo压缩,那配置文件中就干脆不会出现这项配置。(就我遇到的几个openvpn服务端而言)

而且,在lzo压缩配置与服务端不一致时,确实会出现用户成功连接openvpn服务端,但什么ip都ping不通的情况。

Reply View the author
我是昵称
deepin
2023-11-07 03:35
#8
输出的有什么错误提示的日志吗?
Reply View the author
zhangsf
deepin
2023-11-07 05:58
#9
hotime

另外你有试过删掉这个分号再连接openvpn吗?

因为openvpn从服务端导出供客户端使用的配置文件中,如果服务端开启lzo压缩,那配置文件中就会有comp-lzo这项配置,如果服务端不开启lzo压缩,那配置文件中就干脆不会出现这项配置。(就我遇到的几个openvpn服务端而言)

而且,在lzo压缩配置与服务端不一致时,确实会出现用户成功连接openvpn服务端,但什么ip都ping不通的情况。

vpn 的资源可以正常访问的,浏览器中百度之类正常网站是访问不了,ping百度的域名和ip都ping不通,windows是没问题的,把;comp-lzo前的分号删除后vpn也访问不了。整个儿(;comp-lzo)删除和有分号效果一样。

Reply View the author
hotime
deepin
2023-11-07 06:21
#10
zhangsf

vpn 的资源可以正常访问的,浏览器中百度之类正常网站是访问不了,ping百度的域名和ip都ping不通,windows是没问题的,把;comp-lzo前的分号删除后vpn也访问不了。整个儿(;comp-lzo)删除和有分号效果一样。

其他openvpn设备有这种情况吗?

我临时开一下爱快路由的openvpn服务端,你可以连接上看一下是否正常。如果不正常,那问题可能在你这边;如果正常,那问题可能在服务端那边。

注意下面的配置文件中,我会把IP地址隐藏掉,实际IP地址私信发你,你替换进去试试。

client
dev-type tun
dev tunx
proto tcp
tun-mtu 1400
cipher AES-128-CBC
remote xxx.xxx.xxx.xxx 1194
resolv-retry infinite
nobind
persist-key
persist-tun
verb 3
key-direction 1

-----BEGIN OpenVPN Static key V1-----
0f0467e777fa0ca58ccc85d6b170ba4f
244ff4a37feb03f8df23da8b77f1c6fc
4a05cf80e42a4bc53fcc0d442697c643
93f3375057133c4b7a4882aeb00ab451
cce7cd9f3d1c87344e0faa2f59503437
7da897e6aa34375df513c72f18f168f9
3c95e1c0ce2d31334e41984bc11a5c2e
afa8b1d64696ea3b76a2e7b1b3c8829a
24fc36dea21de31b6524b1a3a0b95fcc
dc2e06890bff3d1c2dca26eb0065e862
4804d5de26f5d0bd6ce3dec8ba070448
469ed26c5d3efab17bc2b9d2604734c3
06dee7709d64914ff6cf1006d92699e6
654a8311a7aab0afe4d89caf9b1bc26d
6e92c0e7597ff359ad3e5b7e6f4093aa
e2ad8c35132e1535848149efdd030dcc
-----END OpenVPN Static key V1-----



-----BEGIN CERTIFICATE-----
MIIC6jCCAdICBGVInU0wDQYJKoZIhvcNAQELBQAwNzELMAkGA1UEBhMCQ04xDjAM
BgNVBAoMBWlLdWFpMRgwFgYDVQQDDA9pS3VhaSBEZXZpY2UgQ0EwHhcNMjMxMTA2
MDgwMTE3WhcNMzMxMTAzMDgwMTE3WjA8MQswCQYDVQQGEwJDTjEOMAwGA1UECgwF
aUt1YWkxHTAbBgNVBAMMFGlLdWFpIE9wZW5WUE4gU2VydmVyMIIBIjANBgkqhkiG
9w0BAQEFAAOCAQ8AMIIBCgKCAQEAxSS1HNtw4zfC4eoAkU1Xj5wTqdo/uNKXngRu
f/HJWvRkeyYE1PIHPnZIQRY/Eteywy98B7WytOrIHtyYWS9uetizPx//mJQhcmaN
FtsE686Eyv42lFVNLucH3GWmDD066S1Ql7Ty7HwCIS5i9K3oZr//yosrarFwQL27
J/ZY03reNa/HHGXWHGla8qXPJ9Fz6eQnB0e2wprLmICuT1aAVNOmTGpflrAQfijU
SCIOJs9UU5r2OM79cgBYPkuDVXjPKyjpzXL0sSD4hUU8CJGvIS81iAiY6OvnBjmx
DnbBIsy+yho7f9m7S7PlG4lTh94OAnPVv5/PiXy6GVHyx61zdwIDAQABMA0GCSqG
SIb3DQEBCwUAA4IBAQCSujH+5NAjrteIq75lTMsheIwnQ5+tUULaV/vx0+1S472I
bpilSS9PMmOMLVRMqKfYKBykZEoDyIcwP0wwBPoEMpP9XTm3ooRjECT7wWqceD6p
EIAEPn9xUtJZI9ZPJsQNkVsxTO5HbvuEz/2tIX8f3KcBka+ePwD0MOv98ZVC6/p0
NZ8QU1LQvSuvKWc/zCxaU1FPiyNz4cZ23JtByAdkJfYeIcm2/W7j1ZtauJJIPL0L
yUzVsNdjSo+Cgi6hiatmV8iKR672Gj+O54WP95bhUQLNNUZwJ32lSAY6SKwjP6dZ
hXwvjaf3j3wnj7KPYvXYzweBYoPibTHs27ihe0MB
-----END CERTIFICATE-----



-----BEGIN RSA PRIVATE KEY-----
MIIEowIBAAKCAQEAxSS1HNtw4zfC4eoAkU1Xj5wTqdo/uNKXngRuf/HJWvRkeyYE
1PIHPnZIQRY/Eteywy98B7WytOrIHtyYWS9uetizPx//mJQhcmaNFtsE686Eyv42
lFVNLucH3GWmDD066S1Ql7Ty7HwCIS5i9K3oZr//yosrarFwQL27J/ZY03reNa/H
HGXWHGla8qXPJ9Fz6eQnB0e2wprLmICuT1aAVNOmTGpflrAQfijUSCIOJs9UU5r2
OM79cgBYPkuDVXjPKyjpzXL0sSD4hUU8CJGvIS81iAiY6OvnBjmxDnbBIsy+yho7
f9m7S7PlG4lTh94OAnPVv5/PiXy6GVHyx61zdwIDAQABAoIBADus1t37VvqQoH8+
FBnnrX+dIR6jH/LUXGzKrqAwEmFj5R6Z7ZCACs1PhKOfFkyf2k7XCtZSm9vDzfv5
jmxAvVKWUfvjtbz76fv1KvQmLCEtDGld9iuEfq6Z5HlEk7TUvAZlXyXs8jO/fe2J
Ww7xrY2cxNMMuYG8YFxYklSQb2bkHF8CdGnhd0syi3MVPjQzjSPDgq3tCTlFmDyb
GW5Fb1gisUGin+tvb6PUt8aUUo5wQSJTPB92mMChhEOANdo9Z/j4lEALw0hA6/UD
M9lrfF3PO9/YjOE1CIBNdlZR6z7Ng2sJwahF1335JcYDDw22tFfYCPEQGZ9AAlse
Ewhd2lECgYEA5lA1cFHYo2ZU8IkbZTKIrTC+Tl2QPql+thC9+yCpnUof4be7T2ZH
sCa6590gRLbmTw1YJmF1BqBlaUNCqWc67Yx/Ms0t/C0mcyHjY6VL7JWMVEaX0oTh
UnpWiZvH/OOF/nRaI9/4KmWCfhnwyVej2R+SZ0p9XBIxemlVaowiGQ0CgYEA2yFy
jVjj2YhL7C9brtLo53U8XzZ7oQBfwwQkl9vRLetemxn2nJbt+dZhJzG8RLeY6jF6
3QVIQZ+Vc1D4/LCKtk6sb1I9IivP7vK18iMeqXfYin9Z2N+J7QdH54WSVKO3JZpC
G/xjIWgOTim327WPYC/QAA7dnAU5AcHKBZt3FZMCgYBOHHfzTx7tVCCMr8OFz9zA
+F4iz+LDDdM2xnjYehxshx5G/Hxfkm3P1WLgjoOKKonz16/E3JrHE5ExYSlzsNow
hM0DGsl01I9MzvqC6iXU6Gd+ka6eLIkK4wkEhLwQDc59HVMRBb3yCxl10TBz6PBe
DDIoLABWQKldPepFR5+s5QKBgGhpQIbfEvokumBYlGvxrO4Ua2bGtBOb9QUcJT+C
iuJBYzuuHFayh8PihTpCtX1cqez1FKDZkntKSdC/hVQJ3p5NUFZerihpDdPCLDWq
zEJdi306fxoaMUMSlA1aFMZll6/AF73z/Vv+k8pkkGmM0js3rPlKHAfqaSZQKy2O
zSgnAoGBAIY+64hBQMgtICWzPryr3J6vwZhG2uESbSR86mFlThfAxjaMTz+3k4aO
oIOxiaCKlkx/fkZH05RbKgK8ebCwjGRTDnisslxvKO5dAPykbpqVgWeTaZ0AZOlP
cwSDJnE7h3TbVhJckyEaR646WUiXWveEwL3A3D30T/Lr6pRc0UPw
-----END RSA PRIVATE KEY-----


script-security 2


-----BEGIN CERTIFICATE-----
MIIDQTCCAimgAwIBAgIJAKr64kXbjaGXMA0GCSqGSIb3DQEBCwUAMDcxCzAJBgNV
BAYTAkNOMQ4wDAYDVQQKDAVpS3VhaTEYMBYGA1UEAwwPaUt1YWkgRGV2aWNlIENB
MB4XDTIzMTEwNjA4MDExN1oXDTMzMTEwMzA4MDExN1owNzELMAkGA1UEBhMCQ04x
DjAMBgNVBAoMBWlLdWFpMRgwFgYDVQQDDA9pS3VhaSBEZXZpY2UgQ0EwggEiMA0G
CSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDFJLUc23DjN8Lh6gCRTVePnBOp2j+4
0peeBG5/8cla9GR7JgTU8gc+dkhBFj8S17LDL3wHtbK06sge3JhZL2562LM/H/+Y
lCFyZo0W2wTrzoTK/jaUVU0u5wfcZaYMPTrpLVCXtPLsfAIhLmL0rehmv//Kiytq
sXBAvbsn9ljTet41r8ccZdYcaVrypc8n0XPp5CcHR7bCmsuYgK5PVoBU06ZMal+W
sBB+KNRIIg4mz1RTmvY4zv1yAFg+S4NVeM8rKOnNcvSxIPiFRTwIka8hLzWICJjo
6+cGObEOdsEizL7KGjt/2btLs+UbiVOH3g4Cc9W/n8+JfLoZUfLHrXN3AgMBAAGj
UDBOMB0GA1UdDgQWBBQESWmdFRIjr9rLaHH0zo5KKPwXFTAfBgNVHSMEGDAWgBQE
SWmdFRIjr9rLaHH0zo5KKPwXFTAMBgNVHRMEBTADAQH/MA0GCSqGSIb3DQEBCwUA
A4IBAQB37DUvNcb7duFaylTtMFmcWxLpkHzAMVyO/eDu8O37koKZW4JEkLVpfWGx
oSIndU9ooFUKAms4m5yyJY8lvp1nI43/WUd8pVaMecCm6RQO6P5Yo3dCRaD0IuU3
sYb3xTZINpUme7lWViFUednrWz0CaMrNxW+9ahKb29wyc72At+OhxKPfu0Pr8fBs
WVAsBOUQ0+I70MziMATXZdMr7aRgtniBNPOrxoSxFHPH5a9uwNmx44/2xyrWhwGJ
G/6ODCKasqt9wDhP2YFPyeTFKcLVQPdMiKMGhDbxeJtL5v0QaJgbf8lx841R4DAo
AM9eWQmKZ4jHfKKib7PrZk/WP9Ow
-----END CERTIFICATE-----



# redirect-gateway def1 bypass-dns  # uncomment to set as default gateway
# route-nopull  # uncomment to disable server route push
#

Screenshot_20231106-222618.jpg

Reply View the author
liuyongjin1987
deepin
2023-11-08 16:29
#11

vpn 的资源可以正常访问的,浏览器中百度之类正常网站是访问不了 这是vpn服务器设置的问题,不是你本地的事,当然了你也可以删掉默认路由 加静态路由实现,ip route看一下你默认的路由应该是走了vpn线路,所以外网上不了了,你需要删掉默认路由,然后让默认路由走原网卡,访问vpn资源在单独加静态路由~~~~~

Reply View the author
liuyongjin1987
deepin
2023-11-08 16:33
#12

解决OpenVPN客户端所有网络全走VPN的问题 - 技术分享 (ilxqx.com) 看看这个文章吧 也能从客户端设置不拉取服务器推送的配置~

Reply View the author