Old 02-09-2010, 05:26 PM   #1 (permalink)
Master Untangler
 
dbunyard's Avatar
 
Join Date: Nov 2008
Location: Westerville, Ohio, USA
Posts: 914
dbunyard is on a distinguished road
Default OpenVPN Connects but not Routing Traffic

I went to enable and configure OpenVPN tonight but am having some trouble. The internal network I'm connecting to has addresses in the 10.37.56.0/22 range, the network I'm connecting from is 192.168.9.0/24. I have OpenVPN set up to hand out 172.16.2.0/24 addresses. The Untangle device is running in bridged mode. The connection establishes just fine and assigns me an IP address but I am not able to access any of the network resources. I assumed that since the connection establishes that the port forward I set up is working correctly. I have the internal network in the "Exported Hosts and Networks" and it's enabled. I have checked the Packet Filter rule "Route VPN traffic that would go through the bridge" as well as configured a static route in my SonicWall device for the 172.16.2.0/24 network to use 10.37.59.236 (the Untangle's IP) as the gateway but it still will not work. The log in the OpenVPN client says this:
Code:
Tue Feb 09 19:16:11 2010 OpenVPN 2.0.9 Win32-MinGW [SSL] [LZO] built on Oct  1 2006
Tue Feb 09 19:16:11 2010 IMPORTANT: OpenVPN's default port number is now 1194, based on an official port number assignment by IANA.  OpenVPN 2.0-beta16 and earlier used 5000 as the default port.
Tue Feb 09 19:16:11 2010 LZO compression initialized
Tue Feb 09 19:16:11 2010 UDPv4 link local: [undef]
Tue Feb 09 19:16:11 2010 UDPv4 link remote: 209.143.16.8:1194
Tue Feb 09 19:16:12 2010 [server.does.not.exists] Peer Connection Initiated with 209.143.16.8:1194
Tue Feb 09 19:16:13 2010 TAP-WIN32 device [Local Area Connection 2] opened: \\.\Global\{8DD50EB2-E545-418C-9558-D5AC6C6E67A1}.tap
Tue Feb 09 19:16:13 2010 Notified TAP-Win32 driver to set a DHCP IP/netmask of 172.16.2.1/255.255.255.252 on interface {8DD50EB2-E545-418C-9558-D5AC6C6E67A1} [DHCP-serv: 172.16.2.2, lease-time: 31536000]
Tue Feb 09 19:16:13 2010 Successful ARP Flush on interface [22] {8DD50EB2-E545-418C-9558-D5AC6C6E67A1}
Tue Feb 09 19:16:15 2010 ROUTE: route addition failed using CreateIpForwardEntry: One or more arguments are not correct.   [if_index=22]
Tue Feb 09 19:16:15 2010 ROUTE: route addition failed using CreateIpForwardEntry: One or more arguments are not correct.   [if_index=22]
Tue Feb 09 19:16:15 2010 Initialization Sequence Completed
Tue Feb 09 19:17:58 2010 SIGTERM[hard,] received, process exiting
Any help would be appreciated, thanks!!!!
dbunyard is offline  
Old 02-09-2010, 05:28 PM   #2 (permalink)
Administrator
 
gotkimchi's Avatar
 
Join Date: Jan 2007
Location: Bay Area
Posts: 2,044
gotkimchi is on a distinguished road
Send a message via AIM to gotkimchi Send a message via MSN to gotkimchi Send a message via Yahoo to gotkimchi
Default

What OS are you using?
__________________
to be understood, you must first understand.
Attention: Support and help on the Untangle Forums is provided by volunteers and community members like yourself. If you need Untangle support please call or email support@untangle.com
gotkimchi is offline  
Old 02-09-2010, 05:48 PM   #3 (permalink)
Master Untangler
 
dbunyard's Avatar
 
Join Date: Nov 2008
Location: Westerville, Ohio, USA
Posts: 914
dbunyard is on a distinguished road
Default

Windows 7 x86. I have downloaded the latest client from http://openvpn.se/download.html and the client works with my Endian OpenVPN connection. I exported the configs for my user in the Untangle box and just put them into the config directory in OpenVPN under Program Files.
dbunyard is offline  
Old 02-09-2010, 05:50 PM   #4 (permalink)
Administrator
 
gotkimchi's Avatar
 
Join Date: Jan 2007
Location: Bay Area
Posts: 2,044
gotkimchi is on a distinguished road
Send a message via AIM to gotkimchi Send a message via MSN to gotkimchi Send a message via Yahoo to gotkimchi
Default

are you running it as an administrator, if not, could you try that and see if that works.
__________________
to be understood, you must first understand.
Attention: Support and help on the Untangle Forums is provided by volunteers and community members like yourself. If you need Untangle support please call or email support@untangle.com
gotkimchi is offline  
Old 02-09-2010, 05:51 PM   #5 (permalink)
Master Untangler
 
dbunyard's Avatar
 
Join Date: Nov 2008
Location: Westerville, Ohio, USA
Posts: 914
dbunyard is on a distinguished road
Default

UAC is disabled hence I don't have that option.
dbunyard is offline  
Old 02-09-2010, 05:58 PM   #6 (permalink)
Administrator
 
gotkimchi's Avatar
 
Join Date: Jan 2007
Location: Bay Area
Posts: 2,044
gotkimchi is on a distinguished road
Send a message via AIM to gotkimchi Send a message via MSN to gotkimchi Send a message via Yahoo to gotkimchi
Default

do you have a XP machine? I would try that first. If that works, most likely something to do with Windows7. If the XP does not work, most likely some setting(s) incorrect.
__________________
to be understood, you must first understand.
Attention: Support and help on the Untangle Forums is provided by volunteers and community members like yourself. If you need Untangle support please call or email support@untangle.com
gotkimchi is offline  
Old 02-09-2010, 06:11 PM   #7 (permalink)
Master Untangler
 
dbunyard's Avatar
 
Join Date: Nov 2008
Location: Westerville, Ohio, USA
Posts: 914
dbunyard is on a distinguished road
Default

The XP machine works fine so it must be something stupid in 7. I tried it again after I got the XP machine to work and the 7 machine will still not connect properly. I will play around with it here and see if I can come up with anything else.
dbunyard is offline  
Old 02-09-2010, 06:13 PM   #8 (permalink)
Untangle Ninja
 
sky-knight's Avatar
 
Join Date: Apr 2008
Location: Phoenix, AZ
URLs submitted: 8
Posts: 14,673
sky-knight is on a distinguished road
Default

Windows 7 requires the most current release from openvpn.net. Go download the new client and upgrade, see if that clears you up.
__________________
Rob Sandling, BS:SWE, MCP
Intouch Technology
Phone: 480-272-9889
rob@intouchtechllc.com

UntangleAppliances.com
Phone: 866-794-8879
sky-knight is online now  
Old 02-09-2010, 06:51 PM   #9 (permalink)
Master Untangler
 
dbunyard's Avatar
 
Join Date: Nov 2008
Location: Westerville, Ohio, USA
Posts: 914
dbunyard is on a distinguished road
Default

On the web site it says:
Code:
Client Web Interface:
The Client Web Interface can be accessed via a preferred web browser by inserting the following address into the address bar:
https://openvpnasip:943 (Please replace "openvpnasip" with the IP you allocated to your openvpn-as instance)


Once the client has logged into the Client Web Interface with their credentials they will have the option to download the Windows Installer with their pre-bundled certs of their individual certificate:
There is no link to download the client from there, only the server.
dbunyard is offline  
Old 02-09-2010, 06:55 PM   #10 (permalink)
Master Untangler
 
dbunyard's Avatar
 
Join Date: Nov 2008
Location: Westerville, Ohio, USA
Posts: 914
dbunyard is on a distinguished road
Default

Nevermind....I had a stupid Dan moment. I installed the latest client and it's working now, thanks for you help!!!!!!!!
dbunyard is offline  
Closed Thread

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 01:36 AM.


© 2010 Untangle, Inc. All Rights Reserved.   SEO by vBSEO 3.6.0