You can subscribe to this list here.
2006 |
Jan
|
Feb
|
Mar
|
Apr
|
May
|
Jun
(1) |
Jul
(1) |
Aug
|
Sep
|
Oct
(2) |
Nov
(1) |
Dec
(20) |
---|---|---|---|---|---|---|---|---|---|---|---|---|
2007 |
Jan
(91) |
Feb
(111) |
Mar
(226) |
Apr
(65) |
May
(197) |
Jun
(202) |
Jul
(92) |
Aug
(87) |
Sep
(120) |
Oct
(133) |
Nov
(89) |
Dec
(155) |
2008 |
Jan
(251) |
Feb
(136) |
Mar
(174) |
Apr
(149) |
May
(56) |
Jun
(32) |
Jul
(36) |
Aug
(171) |
Sep
(245) |
Oct
(244) |
Nov
(218) |
Dec
(272) |
2009 |
Jan
(113) |
Feb
(119) |
Mar
(192) |
Apr
(117) |
May
(93) |
Jun
(46) |
Jul
(80) |
Aug
(54) |
Sep
(109) |
Oct
(70) |
Nov
(145) |
Dec
(110) |
2010 |
Jan
(137) |
Feb
(87) |
Mar
(45) |
Apr
(157) |
May
(58) |
Jun
(99) |
Jul
(188) |
Aug
(136) |
Sep
(101) |
Oct
(100) |
Nov
(61) |
Dec
(60) |
2011 |
Jan
(84) |
Feb
(43) |
Mar
(70) |
Apr
(17) |
May
(69) |
Jun
(28) |
Jul
(43) |
Aug
(21) |
Sep
(151) |
Oct
(120) |
Nov
(84) |
Dec
(101) |
2012 |
Jan
(119) |
Feb
(82) |
Mar
(70) |
Apr
(115) |
May
(66) |
Jun
(131) |
Jul
(70) |
Aug
(65) |
Sep
(66) |
Oct
(86) |
Nov
(197) |
Dec
(81) |
2013 |
Jan
(65) |
Feb
(48) |
Mar
(32) |
Apr
(68) |
May
(98) |
Jun
(59) |
Jul
(41) |
Aug
(52) |
Sep
(42) |
Oct
(37) |
Nov
(10) |
Dec
(27) |
2014 |
Jan
(61) |
Feb
(34) |
Mar
(30) |
Apr
(52) |
May
(45) |
Jun
(40) |
Jul
(28) |
Aug
(9) |
Sep
(39) |
Oct
(69) |
Nov
(55) |
Dec
(19) |
2015 |
Jan
(13) |
Feb
(21) |
Mar
(5) |
Apr
(14) |
May
(30) |
Jun
(51) |
Jul
(31) |
Aug
(12) |
Sep
(29) |
Oct
(15) |
Nov
(24) |
Dec
(16) |
2016 |
Jan
(62) |
Feb
(76) |
Mar
(30) |
Apr
(43) |
May
(46) |
Jun
(62) |
Jul
(21) |
Aug
(49) |
Sep
(67) |
Oct
(27) |
Nov
(26) |
Dec
(38) |
2017 |
Jan
(7) |
Feb
(12) |
Mar
(69) |
Apr
(59) |
May
(54) |
Jun
(40) |
Jul
(76) |
Aug
(82) |
Sep
(92) |
Oct
(51) |
Nov
(32) |
Dec
(30) |
2018 |
Jan
(22) |
Feb
(25) |
Mar
(34) |
Apr
(35) |
May
(37) |
Jun
(21) |
Jul
(69) |
Aug
(55) |
Sep
(17) |
Oct
(67) |
Nov
(9) |
Dec
(5) |
2019 |
Jan
(19) |
Feb
(12) |
Mar
(15) |
Apr
(19) |
May
|
Jun
(27) |
Jul
(27) |
Aug
(25) |
Sep
(25) |
Oct
(27) |
Nov
(10) |
Dec
(14) |
2020 |
Jan
(22) |
Feb
(20) |
Mar
(36) |
Apr
(40) |
May
(52) |
Jun
(35) |
Jul
(21) |
Aug
(32) |
Sep
(71) |
Oct
(27) |
Nov
(11) |
Dec
(16) |
2021 |
Jan
(16) |
Feb
(21) |
Mar
(21) |
Apr
(27) |
May
(17) |
Jun
|
Jul
(2) |
Aug
(22) |
Sep
(23) |
Oct
(7) |
Nov
(11) |
Dec
(28) |
2022 |
Jan
(23) |
Feb
(18) |
Mar
(9) |
Apr
(15) |
May
(15) |
Jun
(7) |
Jul
(8) |
Aug
(15) |
Sep
(1) |
Oct
|
Nov
(11) |
Dec
(10) |
2023 |
Jan
(14) |
Feb
(10) |
Mar
(11) |
Apr
(13) |
May
(2) |
Jun
(30) |
Jul
(1) |
Aug
(15) |
Sep
(13) |
Oct
(3) |
Nov
(25) |
Dec
(5) |
2024 |
Jan
(3) |
Feb
(10) |
Mar
(9) |
Apr
|
May
(1) |
Jun
(15) |
Jul
(7) |
Aug
(10) |
Sep
(3) |
Oct
(8) |
Nov
(6) |
Dec
(15) |
2025 |
Jan
(3) |
Feb
(1) |
Mar
(7) |
Apr
(5) |
May
(13) |
Jun
(16) |
Jul
(1) |
Aug
(6) |
Sep
|
Oct
|
Nov
|
Dec
|
From: Dr. P. V. <pv...@uo...> - 2020-03-28 12:45:01
|
My AstLinux machine is a PC Engines APU1 and I would like to upgrade the strongly outdated Coreboot BIOS. Usualy, under Linux and FreeBSD there is a flash program called "flashrom" which can be used to flash the BIOS from the running Operating system (Linux or FreeBSD). E.g. for Debian and FreeBSD package information is available here: https://packages.debian.org/buster/flashrom https://www.freshports.org/sysutils/flashrom/ Almost three years ago I successfully did the BIOS upgrade from a running pfSense. Does AstLinux as well provide flashrom to do this job? Regards, Peter |
From: Lonnie A. <li...@lo...> - 2020-03-26 22:27:31
|
> On Mar 26, 2020, at 4:31 PM, Michael Knill <mic...@ip...> wrote: > > Hi Group > > I have a site that I cannot send mail from yet it is configured exactly the same, with the same Astlinux version as many others that are working to the same mail server (Office 365). > I get ‘msmtp: the server does not support TLS via the STARTTLS command msmtp: could not send mail (account default from /etc/msmtprc)‘ > > Now it is sitting behind a firewall with a bit of intelligence (or not) so I'm wondering if it is blocking something related to the TLS setup. > > Any ideas? I suppose an SMTP ALG in the firewall could be causing issues. Recall that encrypted mail can be sent via STARTTLS or TLS/SSL. TLS/SSL (typically port 465) is fully encrypted before any data is exchanged. STARTTLS starts out using plain text until STARTTLS is negotiated and switched to an encrypted connection. A SMTP ALG could make the STARTTLS not operate properly since it starts out as plain text. If you can, use TLS/SSL so the connection is fully encrypted. Lonnie |
From: Michael K. <mic...@ip...> - 2020-03-26 21:32:04
|
Hi Group I have a site that I cannot send mail from yet it is configured exactly the same, with the same Astlinux version as many others that are working to the same mail server (Office 365). I get ‘msmtp: the server does not support TLS via the STARTTLS command msmtp: could not send mail (account default from /etc/msmtprc)‘ Now it is sitting behind a firewall with a bit of intelligence (or not) so I'm wondering if it is blocking something related to the TLS setup. Any ideas? Regards Michael Knill |
From: nedi <ne...@gm...> - 2020-03-23 16:30:10
|
HI Can somebody help me with this tel.search script? Regard Nedi |
From: Lonnie A. <li...@lo...> - 2020-03-21 14:08:05
|
Release Candidate2 pre-1.3.8, please report any issues, ASAP. ** IMPORTANT NOTICE -- The PPTP VPN server has been removed. pfSense dropped support of PPTP VPN with version 2.3 in 2016. Apple dropped support of PPTP VPN with iOS 10 and macOS 10.12 in 2016. PPTP VPN (MS-CHAPv2) is insecure and is no longer supported in AstLinux. The AstLinux Team is regularly upgrading packages containing security and bug fixes as well as adding new features of our own. -- Linux Kernel 3.16.82 (version bump), security and bug fixes -- RUNNIX, version bump to runnix-0.5.11, with Linux Kernel 3.16.82, e2fsprogs 1.45.5 -- Asterisk 13.23.1 ('13se' version) Older than latest Asterisk 13.x version but more tested, built --without-pjproject -- Asterisk 13.31.0 (version bump) and 16.8.0 (version bump) -- OpenSSL, version bump to 1.1.1e, security fix: CVE-2019-1551 -- WireGuard VPN, module 0.0.20200318 (version bump), tools 1.0.20200319 (version bump) -- OpenVPN, version bump to 2.4.8 -- arnofw (AIF), simplify integration of AIF within the build system, no functional change. After which: == Set the version to '2.0.2-04-astlinux' == Remove 'pptpd' support in the adaptive-ban plugin == Remove the pptp-vpn plugin == Remove the parasitic-net plugin -- pppd, version bump to 2.4.8, security fix: CVE-2020-8597 -- acme-client, version bump to 2.8.5 -- arp-scan, version bump to 1.9.7, fixed with libpcap version 1.9.1 -- chrony, version bump to 4.0-pre1, adds 'maxsamples 1' and 'chronyc -N sources' support -- ncurses, version bump to 6.2 -- ne, version bump to 3.3.0 -- Complete Pre-Release ChangeLog: https://s3.amazonaws.com/beta.astlinux-project/astlinux-changelog/ChangeLog.txt The "AstLinux Pre-Release ChangeLog" and "Pre-Release Repository URL" entries can be found under the "Development" tab of the AstLinux Project web site ... AstLinux Project -> Development https://www.astlinux-project.org/dev.html AstLinux Team |
From: nedi <ne...@gm...> - 2020-03-18 19:24:31
|
Hi long time ago , I used one script to resolve the caller number trough tel.search.ch <http://tel.search.ch/> After update to ssl this script won’t work and after some time the tel.search.ch <http://tel.search.ch/> use api to check the caller id. And now the php changed from 5.6 to new one 7.3 Can anyone help me to fix this script again. I use one code in Astlinux ( I have a old one AstLinux Release: astlinux-1.2.6.1 i586 - Asterisk 1.8.32.3 Runnix Release: runnix-0.4-7671 GUI Version: 1.8.40) Last working php code and snoopy on my website to check the caller was : <?php $number = $_GET["tel"]; $url = "https://tel.search.ch/?was=".$number; include "Snoopy.class.php"; $snoopy = new Snoopy; $snoopy->fetch("$url"); $GrabStart = '<title>'; $GrabEnd = '</title>'; $GrabData = preg_match("/$grabStart(.*?)$grabEnd/i", $snoopy->results, $output1[1]); echo $name[0]; ?> And now I get the API Key and must rewrite those script to be compatible with php 7 and ssl on my website I use https The instruction is to use api key with this link to get the number https://tel.search.ch/api/?was=john+meier&key=c1e6a4c666c0a2ce9e38a69be7c6a I tried to change only this url $url = "https://tel.search.ch/api/?was=".$number&key=c1e6a4c666c0a2ce9e38a69be7c6a; But that dosn’t work. Regards Nedi |
From: Lonnie A. <li...@lo...> - 2020-03-17 18:38:44
|
Release Candidate pre-1.3.8, please report any issues, ASAP. ** IMPORTANT NOTICE -- The PPTP VPN server has been removed. pfSense dropped support of PPTP VPN with version 2.3 in 2016. Apple dropped support of PPTP VPN with iOS 10 and macOS 10.12 in 2016. PPTP VPN (MS-CHAPv2) is insecure and is no longer supported in AstLinux. The AstLinux Team is regularly upgrading packages containing security and bug fixes as well as adding new features of our own. -- Linux Kernel 3.16.82 (version bump), security and bug fixes -- Asterisk 13.23.1 ('13se' version) Older than latest Asterisk 13.x version but more tested, built --without-pjproject -- Asterisk 13.31.0 (version bump) and 16.8.0 (version bump) -- arnofw (AIF), simplify integration of AIF within the build system, no functional change. After which: == Set the version to '2.0.2-04-astlinux' == Remove 'pptpd' support in the adaptive-ban plugin == Remove the pptp-vpn plugin == Remove the parasitic-net plugin -- pppd, version bump to 2.4.8, security fix: CVE-2020-8597 -- acme-client, version bump to 2.8.5 -- arp-scan, version bump to 1.9.7, fixed with libpcap version 1.9.1 -- chrony, version bump to 4.0-pre1, adds 'maxsamples 1' and 'chronyc -N sources' support -- ncurses, version bump to 6.2 -- ne, version bump to 3.3.0 -- WireGuard VPN, module 0.0.20200215 (version bump), tools 1.0.20200206 (version bump) -- Complete Pre-Release ChangeLog: https://s3.amazonaws.com/beta.astlinux-project/astlinux-changelog/ChangeLog.txt The "AstLinux Pre-Release ChangeLog" and "Pre-Release Repository URL" entries can be found under the "Development" tab of the AstLinux Project web site ... AstLinux Project -> Development https://www.astlinux-project.org/dev.html AstLinux Team |
From: Tom C. <tom...@nn...> - 2020-03-13 11:13:24
|
> We have two conference rooms set up on a Jetway NF9HG-2930 with > 2GB RAM (I think). I am being asked how many users can dial in to these > conferences. My understanding is that limits are not hard/software-defined, > but rather depend on performance of the hardware. Can anyone confirm, > and if so, give an estimate, or let me know what other info might be needed > in order to estimate (such as codecs in use, or what else)? > > one limit would be the number of external trunk channels :-). > But I guess 10-12 users should be no problem (maybe more). > > Yes I suspect that you will run out of channels before you run out of > resources! In our case, no - we have 20 external SIP channels, and internal calls come in via VPN from another AstLinux box. So 10-12 (maybe more) is what I'll report back. Many thanks for the quick response Tom Tom Chadwin, ICT Manager Telephone: 01434 611530 Mob: Web: www.northumberlandnationalpark.org.uk<http://www.northumberlandnationalpark.org.uk/> IMPORTANT NOTICE - Disclaimer - This communication is from Northumberland National Park Authority (NNPA).The Authority’s head office and principal place of business is Eastburn, South Park, Hexham, Northumberland, NE46 1BS, United Kingdom. If you are not the intended recipient(s) please note that any form of disclosure, distribution, copying or use of this communication or the information in it or in any attachments is strictly prohibited and may be unlawful. If you have received this communication in error, please delete the email and destroy any copies of it. Any views or opinions presented are solely those of the author and do not necessarily represent those of NNPA.Contractors or potential contractors are reminded that a formal Order or Contract is needed for NNPA to be bound by any offer or acceptance of terms for the supply of goods or services Although this email and any attachments are believed to be free of any virus or other defects which might affect any computer or IT system into which they are received, no responsibility is accepted by the NNPA for any loss or damage arising in any way from the receipt or use thereof. Computer systems of this Authority may be monitored and communications carried out on them recorded, to secure the effective operation of the system and for other lawful purpose. |
From: Michael K. <mic...@ip...> - 2020-03-12 21:04:14
|
Yes I suspect that you will run out of channels before you run out of resources! Regards Michael Knill On 12/3/20, 11:38 pm, "Michael Keuter" <li...@mk...> wrote: > Am 12.03.2020 um 10:32 schrieb Tom Chadwin <tom...@nn...>: > > Hello > > We have two conference rooms set up on a Jetway NF9HG-2930 with 2GB RAM (I think). I am being asked how many users can dial in to these conferences. My understanding is that limits are not hard/software-defined, but rather depend on performance of the hardware. Can anyone confirm, and if so, give an estimate, or let me know what other info might be needed in order to estimate (such as codecs in use, or what else)? > > Many thanks > > Tom Hi Tom, one limit would be the number of external trunk channels :-). But I guess 10-12 users should be no problem (maybe more). Michael http://www.mksolutions.info _______________________________________________ Astlinux-users mailing list Ast...@li... https://lists.sourceforge.net/lists/listinfo/astlinux-users Donations to support AstLinux are graciously accepted via PayPal to pa...@kr.... |
From: Michael K. <li...@mk...> - 2020-03-12 12:38:10
|
> Am 12.03.2020 um 10:32 schrieb Tom Chadwin <tom...@nn...>: > > Hello > > We have two conference rooms set up on a Jetway NF9HG-2930 with 2GB RAM (I think). I am being asked how many users can dial in to these conferences. My understanding is that limits are not hard/software-defined, but rather depend on performance of the hardware. Can anyone confirm, and if so, give an estimate, or let me know what other info might be needed in order to estimate (such as codecs in use, or what else)? > > Many thanks > > Tom Hi Tom, one limit would be the number of external trunk channels :-). But I guess 10-12 users should be no problem (maybe more). Michael http://www.mksolutions.info |
From: Tom C. <tom...@nn...> - 2020-03-12 09:33:10
|
Hello We have two conference rooms set up on a Jetway NF9HG-2930 with 2GB RAM (I think). I am being asked how many users can dial in to these conferences. My understanding is that limits are not hard/software-defined, but rather depend on performance of the hardware. Can anyone confirm, and if so, give an estimate, or let me know what other info might be needed in order to estimate (such as codecs in use, or what else)? Many thanks Tom Tom Chadwin, ICT Manager Telephone: 01434 611530 Mob: Web: www.northumberlandnationalpark.org.uk<http://www.northumberlandnationalpark.org.uk/> IMPORTANT NOTICE - Disclaimer - This communication is from Northumberland National Park Authority (NNPA).The Authority’s head office and principal place of business is Eastburn, South Park, Hexham, Northumberland, NE46 1BS, United Kingdom. If you are not the intended recipient(s) please note that any form of disclosure, distribution, copying or use of this communication or the information in it or in any attachments is strictly prohibited and may be unlawful. If you have received this communication in error, please delete the email and destroy any copies of it. Any views or opinions presented are solely those of the author and do not necessarily represent those of NNPA.Contractors or potential contractors are reminded that a formal Order or Contract is needed for NNPA to be bound by any offer or acceptance of terms for the supply of goods or services Although this email and any attachments are believed to be free of any virus or other defects which might affect any computer or IT system into which they are received, no responsibility is accepted by the NNPA for any loss or damage arising in any way from the receipt or use thereof. Computer systems of this Authority may be monitored and communications carried out on them recorded, to secure the effective operation of the system and for other lawful purpose. |
From: Michael K. <mic...@ip...> - 2020-03-11 20:47:57
|
Grrrrr I forgot to add 'client-to-client' & 'client-config-dir /mnt/kd/openvpn/ccd' in my Raw Commands. All working fine now. That will teach me for not looking more closely at my notes. So yes that answers the question about the iroute then. Thanks again for your help. Regards Michael Knill On 12/3/20, 7:34 am, "Michael Knill" <mic...@ip...> wrote: Thanks Lonnie. So if that's the case then it must be the iroute that determines where to send the traffic destined for this subnet? Regards Michael Knill On 12/3/20, 7:08 am, "Lonnie Abelbeck" <li...@lo...> wrote: Michael, The OpenVPN server configuration created that route, and routing to the "server" seems correct. Just as the OpenVPN "client" should route to the server as well. I have an AstLinux OpenVPN client to server pair in my lab ... OpenVPN Server: (using tun0) pbx ~ # ip route show dev tun0 10.8.1.0/24 proto kernel scope link src 10.8.1.1 192.168.222.0/24 via 10.8.1.1 OpenVPN Client: (using tun2) pbx3 ~ # ip route show dev tun2 10.8.1.0/24 proto kernel scope link src 10.8.1.2 192.168.110.0/24 via 10.8.1.1 Ahh BTW, I always use Topology: "[subnet] ..." which should match with server / clients. Lonnie > On Mar 11, 2020, at 2:45 PM, Michael Knill <mic...@ip...> wrote: > > Thanks Lonnie. Just a question which I'm not sure of. > The Astlinux routing table points 172.16.16.0/24 to its own OpenVPN address (172.16.16.0/24 via 172.28.253.1 dev tun0). Is this correct? > Shouldn't it point to the remote site OpenVPN address or is this how it works? > > Regards > Michael Knill > > On 11/3/20, 11:39 pm, "Lonnie Abelbeck" <li...@lo...> wrote: > > Hi Michael, > > If you were using AstLinux instead of the Mikrotik in your home office I would point you to the Firewall tab ... > > Network -> Firewall Configuration -> Firewall Options: > > ___ Allow OpenVPN Client tunnel to the [ 1st ] LAN Interface(s) > > ___ Allow OpenVPN Server tunnel to the [ 1st ] LAN Interface(s) > > > So, for the Mikrotik it may be a similar firewall "forwarding" rule for the OpenVPN 'tun' interface <-> LAN interface. > > BTW, the proper OpenVPN config (your's looks good at a quick glance) will add the needed routes automatically. > > Lonnie > > > >> On Mar 11, 2020, at 6:31 AM, Michael Knill <mic...@ip...> wrote: >> >> Hi Group >> >> I have been trying out Mikrotik’s RouterOS v7 specifically to test UDP OpenVPN. >> I have set up OpenVPN from my Home Office router (OpenVPN Client) to my hosted Astlinux (OpenVPN Server) for telephony purposes only. >> The connection has come up fine and I can ping the OpenVPN addresses each way from the terminating devices but I cant for the life of me get connectivity working from the Home Office LAN to the Astlinux OpenVPN address. >> OpenVPN Subnet: 172.28.253.0/24. Astlinux gateway .1 >> Home Office LAN: 172.16.16.0/24 >> >> I have set up the iroute file: >> 3000-IPC_Prod-CM1 kd # cat openvpn/ccd/IPC_Home_Office >> iroute 172.16.16.0 255.255.255.0 >> >> 3000-IPC_Prod-CM1 kd # ip route >> default via 221.121.132.145 dev eth0 >> 172.16.16.0/24 via 172.28.253.1 dev tun0 >> 172.28.253.0/24 dev tun0 proto kernel scope link src 172.28.253.1 >> ....... >> >> ### gui.openvpn.conf - start ### >> ### >> ### Auth Method >> OVPN_USER_PASS_VERIFY="no" >> ### Device >> OVPN_DEV="tun0" >> ### Port Number >> OVPN_PORT="1194" >> ### Protocol >> OVPN_PROTOCOL="udp" >> ### Log Verbosity >> OVPN_VERBOSITY="4" >> ### Compression >> OVPN_LZO="no" >> ### QoS Passthrough >> OVPN_QOS="yes" >> ### Cipher >> OVPN_CIPHER="" >> ### Auth HMAC >> OVPN_AUTH="" >> ### Allowed External Hosts >> OVPN_TUNNEL_HOSTS="0/0" >> ### Client Isolation >> OVPN_CLIENT_ISOLATION="no" >> ### Server Hostname >> OVPN_HOSTNAME="30000.ipcaccess.net" >> ### Server IPv4 Network >> OVPN_SERVER="172.28.253.0 255.255.255.0" >> ### Server IPv6 Network >> OVPN_SERVERV6="" >> ### Topology >> OVPN_TOPOLOGY="subnet" >> ### Server Push >> OVPN_PUSH=" >> " >> ### Raw Commands >> OVPN_OTHER=" >> topology p2p >> route-gateway 172.28.253.1 >> route 172.16.16.0 255.255.255.0 >> " >> ### Private Key Size >> OVPN_CERT_KEYSIZE="2048" >> ### Signature Algorithm >> OVPN_CERT_ALGORITHM="sha256" >> ### CA File >> OVPN_CA="/mnt/kd/openvpn/webinterface/keys/ca.crt" >> ### CERT File >> OVPN_CERT="/mnt/kd/openvpn/webinterface/keys/server.crt" >> ### Key File >> OVPN_KEY="/mnt/kd/openvpn/webinterface/keys/server.key" >> ### DH File >> OVPN_DH="/mnt/kd/openvpn/webinterface/dh1024.pem" >> ### TLS-Auth File >> OVPN_TA="" >> ### Valid Clients >> OVPN_VALIDCLIENTS=" >> ........... >> IPC_Home_Office >> " >> ### gui.openvpn.conf - end ### >> >> I have looked at the firewall log on the Mikrotik and nothing comes up as being denied. Any ideas on where to go next? >> Yes I realise it's a Beta version but as I can ping the OpenVPN address each way, it just seems to be a routing problem. >> >> Thanks all. >> >> Regards >> Michael Knill >> _______________________________________________ >> Astlinux-users mailing list >> Ast...@li... >> https://lists.sourceforge.net/lists/listinfo/astlinux-users >> >> Donations to support AstLinux are graciously accepted via PayPal to pa...@kr.... > > > > _______________________________________________ > Astlinux-users mailing list > Ast...@li... > https://lists.sourceforge.net/lists/listinfo/astlinux-users > > Donations to support AstLinux are graciously accepted via PayPal to pa...@kr.... > > > _______________________________________________ > Astlinux-users mailing list > Ast...@li... > https://lists.sourceforge.net/lists/listinfo/astlinux-users > > Donations to support AstLinux are graciously accepted via PayPal to pa...@kr.... _______________________________________________ Astlinux-users mailing list Ast...@li... https://lists.sourceforge.net/lists/listinfo/astlinux-users Donations to support AstLinux are graciously accepted via PayPal to pa...@kr.... _______________________________________________ Astlinux-users mailing list Ast...@li... https://lists.sourceforge.net/lists/listinfo/astlinux-users Donations to support AstLinux are graciously accepted via PayPal to pa...@kr.... |
From: Michael K. <mic...@ip...> - 2020-03-11 20:34:30
|
Thanks Lonnie. So if that's the case then it must be the iroute that determines where to send the traffic destined for this subnet? Regards Michael Knill On 12/3/20, 7:08 am, "Lonnie Abelbeck" <li...@lo...> wrote: Michael, The OpenVPN server configuration created that route, and routing to the "server" seems correct. Just as the OpenVPN "client" should route to the server as well. I have an AstLinux OpenVPN client to server pair in my lab ... OpenVPN Server: (using tun0) pbx ~ # ip route show dev tun0 10.8.1.0/24 proto kernel scope link src 10.8.1.1 192.168.222.0/24 via 10.8.1.1 OpenVPN Client: (using tun2) pbx3 ~ # ip route show dev tun2 10.8.1.0/24 proto kernel scope link src 10.8.1.2 192.168.110.0/24 via 10.8.1.1 Ahh BTW, I always use Topology: "[subnet] ..." which should match with server / clients. Lonnie > On Mar 11, 2020, at 2:45 PM, Michael Knill <mic...@ip...> wrote: > > Thanks Lonnie. Just a question which I'm not sure of. > The Astlinux routing table points 172.16.16.0/24 to its own OpenVPN address (172.16.16.0/24 via 172.28.253.1 dev tun0). Is this correct? > Shouldn't it point to the remote site OpenVPN address or is this how it works? > > Regards > Michael Knill > > On 11/3/20, 11:39 pm, "Lonnie Abelbeck" <li...@lo...> wrote: > > Hi Michael, > > If you were using AstLinux instead of the Mikrotik in your home office I would point you to the Firewall tab ... > > Network -> Firewall Configuration -> Firewall Options: > > ___ Allow OpenVPN Client tunnel to the [ 1st ] LAN Interface(s) > > ___ Allow OpenVPN Server tunnel to the [ 1st ] LAN Interface(s) > > > So, for the Mikrotik it may be a similar firewall "forwarding" rule for the OpenVPN 'tun' interface <-> LAN interface. > > BTW, the proper OpenVPN config (your's looks good at a quick glance) will add the needed routes automatically. > > Lonnie > > > >> On Mar 11, 2020, at 6:31 AM, Michael Knill <mic...@ip...> wrote: >> >> Hi Group >> >> I have been trying out Mikrotik’s RouterOS v7 specifically to test UDP OpenVPN. >> I have set up OpenVPN from my Home Office router (OpenVPN Client) to my hosted Astlinux (OpenVPN Server) for telephony purposes only. >> The connection has come up fine and I can ping the OpenVPN addresses each way from the terminating devices but I cant for the life of me get connectivity working from the Home Office LAN to the Astlinux OpenVPN address. >> OpenVPN Subnet: 172.28.253.0/24. Astlinux gateway .1 >> Home Office LAN: 172.16.16.0/24 >> >> I have set up the iroute file: >> 3000-IPC_Prod-CM1 kd # cat openvpn/ccd/IPC_Home_Office >> iroute 172.16.16.0 255.255.255.0 >> >> 3000-IPC_Prod-CM1 kd # ip route >> default via 221.121.132.145 dev eth0 >> 172.16.16.0/24 via 172.28.253.1 dev tun0 >> 172.28.253.0/24 dev tun0 proto kernel scope link src 172.28.253.1 >> ....... >> >> ### gui.openvpn.conf - start ### >> ### >> ### Auth Method >> OVPN_USER_PASS_VERIFY="no" >> ### Device >> OVPN_DEV="tun0" >> ### Port Number >> OVPN_PORT="1194" >> ### Protocol >> OVPN_PROTOCOL="udp" >> ### Log Verbosity >> OVPN_VERBOSITY="4" >> ### Compression >> OVPN_LZO="no" >> ### QoS Passthrough >> OVPN_QOS="yes" >> ### Cipher >> OVPN_CIPHER="" >> ### Auth HMAC >> OVPN_AUTH="" >> ### Allowed External Hosts >> OVPN_TUNNEL_HOSTS="0/0" >> ### Client Isolation >> OVPN_CLIENT_ISOLATION="no" >> ### Server Hostname >> OVPN_HOSTNAME="30000.ipcaccess.net" >> ### Server IPv4 Network >> OVPN_SERVER="172.28.253.0 255.255.255.0" >> ### Server IPv6 Network >> OVPN_SERVERV6="" >> ### Topology >> OVPN_TOPOLOGY="subnet" >> ### Server Push >> OVPN_PUSH=" >> " >> ### Raw Commands >> OVPN_OTHER=" >> topology p2p >> route-gateway 172.28.253.1 >> route 172.16.16.0 255.255.255.0 >> " >> ### Private Key Size >> OVPN_CERT_KEYSIZE="2048" >> ### Signature Algorithm >> OVPN_CERT_ALGORITHM="sha256" >> ### CA File >> OVPN_CA="/mnt/kd/openvpn/webinterface/keys/ca.crt" >> ### CERT File >> OVPN_CERT="/mnt/kd/openvpn/webinterface/keys/server.crt" >> ### Key File >> OVPN_KEY="/mnt/kd/openvpn/webinterface/keys/server.key" >> ### DH File >> OVPN_DH="/mnt/kd/openvpn/webinterface/dh1024.pem" >> ### TLS-Auth File >> OVPN_TA="" >> ### Valid Clients >> OVPN_VALIDCLIENTS=" >> ........... >> IPC_Home_Office >> " >> ### gui.openvpn.conf - end ### >> >> I have looked at the firewall log on the Mikrotik and nothing comes up as being denied. Any ideas on where to go next? >> Yes I realise it's a Beta version but as I can ping the OpenVPN address each way, it just seems to be a routing problem. >> >> Thanks all. >> >> Regards >> Michael Knill >> _______________________________________________ >> Astlinux-users mailing list >> Ast...@li... >> https://lists.sourceforge.net/lists/listinfo/astlinux-users >> >> Donations to support AstLinux are graciously accepted via PayPal to pa...@kr.... > > > > _______________________________________________ > Astlinux-users mailing list > Ast...@li... > https://lists.sourceforge.net/lists/listinfo/astlinux-users > > Donations to support AstLinux are graciously accepted via PayPal to pa...@kr.... > > > _______________________________________________ > Astlinux-users mailing list > Ast...@li... > https://lists.sourceforge.net/lists/listinfo/astlinux-users > > Donations to support AstLinux are graciously accepted via PayPal to pa...@kr.... _______________________________________________ Astlinux-users mailing list Ast...@li... https://lists.sourceforge.net/lists/listinfo/astlinux-users Donations to support AstLinux are graciously accepted via PayPal to pa...@kr.... |
From: Lonnie A. <li...@lo...> - 2020-03-11 20:08:20
|
Michael, The OpenVPN server configuration created that route, and routing to the "server" seems correct. Just as the OpenVPN "client" should route to the server as well. I have an AstLinux OpenVPN client to server pair in my lab ... OpenVPN Server: (using tun0) pbx ~ # ip route show dev tun0 10.8.1.0/24 proto kernel scope link src 10.8.1.1 192.168.222.0/24 via 10.8.1.1 OpenVPN Client: (using tun2) pbx3 ~ # ip route show dev tun2 10.8.1.0/24 proto kernel scope link src 10.8.1.2 192.168.110.0/24 via 10.8.1.1 Ahh BTW, I always use Topology: "[subnet] ..." which should match with server / clients. Lonnie > On Mar 11, 2020, at 2:45 PM, Michael Knill <mic...@ip...> wrote: > > Thanks Lonnie. Just a question which I'm not sure of. > The Astlinux routing table points 172.16.16.0/24 to its own OpenVPN address (172.16.16.0/24 via 172.28.253.1 dev tun0). Is this correct? > Shouldn't it point to the remote site OpenVPN address or is this how it works? > > Regards > Michael Knill > > On 11/3/20, 11:39 pm, "Lonnie Abelbeck" <li...@lo...> wrote: > > Hi Michael, > > If you were using AstLinux instead of the Mikrotik in your home office I would point you to the Firewall tab ... > > Network -> Firewall Configuration -> Firewall Options: > > ___ Allow OpenVPN Client tunnel to the [ 1st ] LAN Interface(s) > > ___ Allow OpenVPN Server tunnel to the [ 1st ] LAN Interface(s) > > > So, for the Mikrotik it may be a similar firewall "forwarding" rule for the OpenVPN 'tun' interface <-> LAN interface. > > BTW, the proper OpenVPN config (your's looks good at a quick glance) will add the needed routes automatically. > > Lonnie > > > >> On Mar 11, 2020, at 6:31 AM, Michael Knill <mic...@ip...> wrote: >> >> Hi Group >> >> I have been trying out Mikrotik’s RouterOS v7 specifically to test UDP OpenVPN. >> I have set up OpenVPN from my Home Office router (OpenVPN Client) to my hosted Astlinux (OpenVPN Server) for telephony purposes only. >> The connection has come up fine and I can ping the OpenVPN addresses each way from the terminating devices but I cant for the life of me get connectivity working from the Home Office LAN to the Astlinux OpenVPN address. >> OpenVPN Subnet: 172.28.253.0/24. Astlinux gateway .1 >> Home Office LAN: 172.16.16.0/24 >> >> I have set up the iroute file: >> 3000-IPC_Prod-CM1 kd # cat openvpn/ccd/IPC_Home_Office >> iroute 172.16.16.0 255.255.255.0 >> >> 3000-IPC_Prod-CM1 kd # ip route >> default via 221.121.132.145 dev eth0 >> 172.16.16.0/24 via 172.28.253.1 dev tun0 >> 172.28.253.0/24 dev tun0 proto kernel scope link src 172.28.253.1 >> ....... >> >> ### gui.openvpn.conf - start ### >> ### >> ### Auth Method >> OVPN_USER_PASS_VERIFY="no" >> ### Device >> OVPN_DEV="tun0" >> ### Port Number >> OVPN_PORT="1194" >> ### Protocol >> OVPN_PROTOCOL="udp" >> ### Log Verbosity >> OVPN_VERBOSITY="4" >> ### Compression >> OVPN_LZO="no" >> ### QoS Passthrough >> OVPN_QOS="yes" >> ### Cipher >> OVPN_CIPHER="" >> ### Auth HMAC >> OVPN_AUTH="" >> ### Allowed External Hosts >> OVPN_TUNNEL_HOSTS="0/0" >> ### Client Isolation >> OVPN_CLIENT_ISOLATION="no" >> ### Server Hostname >> OVPN_HOSTNAME="30000.ipcaccess.net" >> ### Server IPv4 Network >> OVPN_SERVER="172.28.253.0 255.255.255.0" >> ### Server IPv6 Network >> OVPN_SERVERV6="" >> ### Topology >> OVPN_TOPOLOGY="subnet" >> ### Server Push >> OVPN_PUSH=" >> " >> ### Raw Commands >> OVPN_OTHER=" >> topology p2p >> route-gateway 172.28.253.1 >> route 172.16.16.0 255.255.255.0 >> " >> ### Private Key Size >> OVPN_CERT_KEYSIZE="2048" >> ### Signature Algorithm >> OVPN_CERT_ALGORITHM="sha256" >> ### CA File >> OVPN_CA="/mnt/kd/openvpn/webinterface/keys/ca.crt" >> ### CERT File >> OVPN_CERT="/mnt/kd/openvpn/webinterface/keys/server.crt" >> ### Key File >> OVPN_KEY="/mnt/kd/openvpn/webinterface/keys/server.key" >> ### DH File >> OVPN_DH="/mnt/kd/openvpn/webinterface/dh1024.pem" >> ### TLS-Auth File >> OVPN_TA="" >> ### Valid Clients >> OVPN_VALIDCLIENTS=" >> ........... >> IPC_Home_Office >> " >> ### gui.openvpn.conf - end ### >> >> I have looked at the firewall log on the Mikrotik and nothing comes up as being denied. Any ideas on where to go next? >> Yes I realise it's a Beta version but as I can ping the OpenVPN address each way, it just seems to be a routing problem. >> >> Thanks all. >> >> Regards >> Michael Knill >> _______________________________________________ >> Astlinux-users mailing list >> Ast...@li... >> https://lists.sourceforge.net/lists/listinfo/astlinux-users >> >> Donations to support AstLinux are graciously accepted via PayPal to pa...@kr.... > > > > _______________________________________________ > Astlinux-users mailing list > Ast...@li... > https://lists.sourceforge.net/lists/listinfo/astlinux-users > > Donations to support AstLinux are graciously accepted via PayPal to pa...@kr.... > > > _______________________________________________ > Astlinux-users mailing list > Ast...@li... > https://lists.sourceforge.net/lists/listinfo/astlinux-users > > Donations to support AstLinux are graciously accepted via PayPal to pa...@kr.... |
From: Michael K. <mic...@ip...> - 2020-03-11 19:45:56
|
Thanks Lonnie. Just a question which I'm not sure of. The Astlinux routing table points 172.16.16.0/24 to its own OpenVPN address (172.16.16.0/24 via 172.28.253.1 dev tun0). Is this correct? Shouldn't it point to the remote site OpenVPN address or is this how it works? Regards Michael Knill On 11/3/20, 11:39 pm, "Lonnie Abelbeck" <li...@lo...> wrote: Hi Michael, If you were using AstLinux instead of the Mikrotik in your home office I would point you to the Firewall tab ... Network -> Firewall Configuration -> Firewall Options: ___ Allow OpenVPN Client tunnel to the [ 1st ] LAN Interface(s) ___ Allow OpenVPN Server tunnel to the [ 1st ] LAN Interface(s) So, for the Mikrotik it may be a similar firewall "forwarding" rule for the OpenVPN 'tun' interface <-> LAN interface. BTW, the proper OpenVPN config (your's looks good at a quick glance) will add the needed routes automatically. Lonnie > On Mar 11, 2020, at 6:31 AM, Michael Knill <mic...@ip...> wrote: > > Hi Group > > I have been trying out Mikrotik’s RouterOS v7 specifically to test UDP OpenVPN. > I have set up OpenVPN from my Home Office router (OpenVPN Client) to my hosted Astlinux (OpenVPN Server) for telephony purposes only. > The connection has come up fine and I can ping the OpenVPN addresses each way from the terminating devices but I cant for the life of me get connectivity working from the Home Office LAN to the Astlinux OpenVPN address. > OpenVPN Subnet: 172.28.253.0/24. Astlinux gateway .1 > Home Office LAN: 172.16.16.0/24 > > I have set up the iroute file: > 3000-IPC_Prod-CM1 kd # cat openvpn/ccd/IPC_Home_Office > iroute 172.16.16.0 255.255.255.0 > > 3000-IPC_Prod-CM1 kd # ip route > default via 221.121.132.145 dev eth0 > 172.16.16.0/24 via 172.28.253.1 dev tun0 > 172.28.253.0/24 dev tun0 proto kernel scope link src 172.28.253.1 > ....... > > ### gui.openvpn.conf - start ### > ### > ### Auth Method > OVPN_USER_PASS_VERIFY="no" > ### Device > OVPN_DEV="tun0" > ### Port Number > OVPN_PORT="1194" > ### Protocol > OVPN_PROTOCOL="udp" > ### Log Verbosity > OVPN_VERBOSITY="4" > ### Compression > OVPN_LZO="no" > ### QoS Passthrough > OVPN_QOS="yes" > ### Cipher > OVPN_CIPHER="" > ### Auth HMAC > OVPN_AUTH="" > ### Allowed External Hosts > OVPN_TUNNEL_HOSTS="0/0" > ### Client Isolation > OVPN_CLIENT_ISOLATION="no" > ### Server Hostname > OVPN_HOSTNAME="30000.ipcaccess.net" > ### Server IPv4 Network > OVPN_SERVER="172.28.253.0 255.255.255.0" > ### Server IPv6 Network > OVPN_SERVERV6="" > ### Topology > OVPN_TOPOLOGY="subnet" > ### Server Push > OVPN_PUSH=" > " > ### Raw Commands > OVPN_OTHER=" > topology p2p > route-gateway 172.28.253.1 > route 172.16.16.0 255.255.255.0 > " > ### Private Key Size > OVPN_CERT_KEYSIZE="2048" > ### Signature Algorithm > OVPN_CERT_ALGORITHM="sha256" > ### CA File > OVPN_CA="/mnt/kd/openvpn/webinterface/keys/ca.crt" > ### CERT File > OVPN_CERT="/mnt/kd/openvpn/webinterface/keys/server.crt" > ### Key File > OVPN_KEY="/mnt/kd/openvpn/webinterface/keys/server.key" > ### DH File > OVPN_DH="/mnt/kd/openvpn/webinterface/dh1024.pem" > ### TLS-Auth File > OVPN_TA="" > ### Valid Clients > OVPN_VALIDCLIENTS=" > ........... > IPC_Home_Office > " > ### gui.openvpn.conf - end ### > > I have looked at the firewall log on the Mikrotik and nothing comes up as being denied. Any ideas on where to go next? > Yes I realise it's a Beta version but as I can ping the OpenVPN address each way, it just seems to be a routing problem. > > Thanks all. > > Regards > Michael Knill > _______________________________________________ > Astlinux-users mailing list > Ast...@li... > https://lists.sourceforge.net/lists/listinfo/astlinux-users > > Donations to support AstLinux are graciously accepted via PayPal to pa...@kr.... _______________________________________________ Astlinux-users mailing list Ast...@li... https://lists.sourceforge.net/lists/listinfo/astlinux-users Donations to support AstLinux are graciously accepted via PayPal to pa...@kr.... |
From: Lonnie A. <li...@lo...> - 2020-03-11 12:39:06
|
Hi Michael, If you were using AstLinux instead of the Mikrotik in your home office I would point you to the Firewall tab ... Network -> Firewall Configuration -> Firewall Options: ___ Allow OpenVPN Client tunnel to the [ 1st ] LAN Interface(s) ___ Allow OpenVPN Server tunnel to the [ 1st ] LAN Interface(s) So, for the Mikrotik it may be a similar firewall "forwarding" rule for the OpenVPN 'tun' interface <-> LAN interface. BTW, the proper OpenVPN config (your's looks good at a quick glance) will add the needed routes automatically. Lonnie > On Mar 11, 2020, at 6:31 AM, Michael Knill <mic...@ip...> wrote: > > Hi Group > > I have been trying out Mikrotik’s RouterOS v7 specifically to test UDP OpenVPN. > I have set up OpenVPN from my Home Office router (OpenVPN Client) to my hosted Astlinux (OpenVPN Server) for telephony purposes only. > The connection has come up fine and I can ping the OpenVPN addresses each way from the terminating devices but I cant for the life of me get connectivity working from the Home Office LAN to the Astlinux OpenVPN address. > OpenVPN Subnet: 172.28.253.0/24. Astlinux gateway .1 > Home Office LAN: 172.16.16.0/24 > > I have set up the iroute file: > 3000-IPC_Prod-CM1 kd # cat openvpn/ccd/IPC_Home_Office > iroute 172.16.16.0 255.255.255.0 > > 3000-IPC_Prod-CM1 kd # ip route > default via 221.121.132.145 dev eth0 > 172.16.16.0/24 via 172.28.253.1 dev tun0 > 172.28.253.0/24 dev tun0 proto kernel scope link src 172.28.253.1 > ....... > > ### gui.openvpn.conf - start ### > ### > ### Auth Method > OVPN_USER_PASS_VERIFY="no" > ### Device > OVPN_DEV="tun0" > ### Port Number > OVPN_PORT="1194" > ### Protocol > OVPN_PROTOCOL="udp" > ### Log Verbosity > OVPN_VERBOSITY="4" > ### Compression > OVPN_LZO="no" > ### QoS Passthrough > OVPN_QOS="yes" > ### Cipher > OVPN_CIPHER="" > ### Auth HMAC > OVPN_AUTH="" > ### Allowed External Hosts > OVPN_TUNNEL_HOSTS="0/0" > ### Client Isolation > OVPN_CLIENT_ISOLATION="no" > ### Server Hostname > OVPN_HOSTNAME="30000.ipcaccess.net" > ### Server IPv4 Network > OVPN_SERVER="172.28.253.0 255.255.255.0" > ### Server IPv6 Network > OVPN_SERVERV6="" > ### Topology > OVPN_TOPOLOGY="subnet" > ### Server Push > OVPN_PUSH=" > " > ### Raw Commands > OVPN_OTHER=" > topology p2p > route-gateway 172.28.253.1 > route 172.16.16.0 255.255.255.0 > " > ### Private Key Size > OVPN_CERT_KEYSIZE="2048" > ### Signature Algorithm > OVPN_CERT_ALGORITHM="sha256" > ### CA File > OVPN_CA="/mnt/kd/openvpn/webinterface/keys/ca.crt" > ### CERT File > OVPN_CERT="/mnt/kd/openvpn/webinterface/keys/server.crt" > ### Key File > OVPN_KEY="/mnt/kd/openvpn/webinterface/keys/server.key" > ### DH File > OVPN_DH="/mnt/kd/openvpn/webinterface/dh1024.pem" > ### TLS-Auth File > OVPN_TA="" > ### Valid Clients > OVPN_VALIDCLIENTS=" > ........... > IPC_Home_Office > " > ### gui.openvpn.conf - end ### > > I have looked at the firewall log on the Mikrotik and nothing comes up as being denied. Any ideas on where to go next? > Yes I realise it's a Beta version but as I can ping the OpenVPN address each way, it just seems to be a routing problem. > > Thanks all. > > Regards > Michael Knill > _______________________________________________ > Astlinux-users mailing list > Ast...@li... > https://lists.sourceforge.net/lists/listinfo/astlinux-users > > Donations to support AstLinux are graciously accepted via PayPal to pa...@kr.... |
From: Michael K. <mic...@ip...> - 2020-03-11 11:31:18
|
Hi Group I have been trying out Mikrotik’s RouterOS v7 specifically to test UDP OpenVPN. I have set up OpenVPN from my Home Office router (OpenVPN Client) to my hosted Astlinux (OpenVPN Server) for telephony purposes only. The connection has come up fine and I can ping the OpenVPN addresses each way from the terminating devices but I cant for the life of me get connectivity working from the Home Office LAN to the Astlinux OpenVPN address. OpenVPN Subnet: 172.28.253.0/24. Astlinux gateway .1 Home Office LAN: 172.16.16.0/24 I have set up the iroute file: 3000-IPC_Prod-CM1 kd # cat openvpn/ccd/IPC_Home_Office iroute 172.16.16.0 255.255.255.0 3000-IPC_Prod-CM1 kd # ip route default via 221.121.132.145 dev eth0 172.16.16.0/24 via 172.28.253.1 dev tun0 172.28.253.0/24 dev tun0 proto kernel scope link src 172.28.253.1 ....... ### gui.openvpn.conf - start ### ### ### Auth Method OVPN_USER_PASS_VERIFY="no" ### Device OVPN_DEV="tun0" ### Port Number OVPN_PORT="1194" ### Protocol OVPN_PROTOCOL="udp" ### Log Verbosity OVPN_VERBOSITY="4" ### Compression OVPN_LZO="no" ### QoS Passthrough OVPN_QOS="yes" ### Cipher OVPN_CIPHER="" ### Auth HMAC OVPN_AUTH="" ### Allowed External Hosts OVPN_TUNNEL_HOSTS="0/0" ### Client Isolation OVPN_CLIENT_ISOLATION="no" ### Server Hostname OVPN_HOSTNAME="30000.ipcaccess.net" ### Server IPv4 Network OVPN_SERVER="172.28.253.0 255.255.255.0" ### Server IPv6 Network OVPN_SERVERV6="" ### Topology OVPN_TOPOLOGY="subnet" ### Server Push OVPN_PUSH=" " ### Raw Commands OVPN_OTHER=" topology p2p route-gateway 172.28.253.1 route 172.16.16.0 255.255.255.0 " ### Private Key Size OVPN_CERT_KEYSIZE="2048" ### Signature Algorithm OVPN_CERT_ALGORITHM="sha256" ### CA File OVPN_CA="/mnt/kd/openvpn/webinterface/keys/ca.crt" ### CERT File OVPN_CERT="/mnt/kd/openvpn/webinterface/keys/server.crt" ### Key File OVPN_KEY="/mnt/kd/openvpn/webinterface/keys/server.key" ### DH File OVPN_DH="/mnt/kd/openvpn/webinterface/dh1024.pem" ### TLS-Auth File OVPN_TA="" ### Valid Clients OVPN_VALIDCLIENTS=" ........... IPC_Home_Office " ### gui.openvpn.conf - end ### I have looked at the firewall log on the Mikrotik and nothing comes up as being denied. Any ideas on where to go next? Yes I realise it's a Beta version but as I can ping the OpenVPN address each way, it just seems to be a routing problem. Thanks all. Regards Michael Knill |
From: Tom C. <tom...@nn...> - 2020-03-06 09:14:18
|
> Maybe dnsmasq is caching the data somewhere else until the lease expires … > I had the same issue also, but after some time (hours) the device gets the > new IP address. I guess you're right. The new reservations are all correct this morning. Thanks for the help, both Tom Tom Chadwin, ICT Manager Telephone: 01434 611530 Mob: Web: www.northumberlandnationalpark.org.uk<http://www.northumberlandnationalpark.org.uk/> IMPORTANT NOTICE - Disclaimer - This communication is from Northumberland National Park Authority (NNPA).The Authority’s head office and principal place of business is Eastburn, South Park, Hexham, Northumberland, NE46 1BS, United Kingdom. If you are not the intended recipient(s) please note that any form of disclosure, distribution, copying or use of this communication or the information in it or in any attachments is strictly prohibited and may be unlawful. If you have received this communication in error, please delete the email and destroy any copies of it. Any views or opinions presented are solely those of the author and do not necessarily represent those of NNPA.Contractors or potential contractors are reminded that a formal Order or Contract is needed for NNPA to be bound by any offer or acceptance of terms for the supply of goods or services Although this email and any attachments are believed to be free of any virus or other defects which might affect any computer or IT system into which they are received, no responsibility is accepted by the NNPA for any loss or damage arising in any way from the receipt or use thereof. Computer systems of this Authority may be monitored and communications carried out on them recorded, to secure the effective operation of the system and for other lawful purpose. |
From: Michael K. <li...@mk...> - 2020-03-05 16:37:12
|
> Am 05.03.2020 um 17:31 schrieb Tom Chadwin <tom...@nn...>: > >>> it's >> still getting its previous lease address. Is that because the lease has not yet >> expired? If so, can I delete the lease so it requests a new one, and hopefully >> gets the reservation? >> >> Yes, you can use the Edit tab and load the 'dnsmasq.leases' file and delete >> the old lease, "Save Changes" and "Restart DNS & DHCP". > > I've done that, but the device is not getting the reserved address even after I did that. I'll have a think and see if I can figure it out. I guess a phone factory reset would probably do the trick, but it's a while since I did one on that site, and I'm a tad nervous in case things go wrong. > > Thanks for the help > > Tom Maybe dnsmasq is caching the data somewhere else until the lease expires … I had the same issue also, but after some time (hours) the device gets the new IP address. Michael http://www.mksolutions.info |
From: Tom C. <tom...@nn...> - 2020-03-05 16:32:04
|
> > it's > still getting its previous lease address. Is that because the lease has not yet > expired? If so, can I delete the lease so it requests a new one, and hopefully > gets the reservation? > > Yes, you can use the Edit tab and load the 'dnsmasq.leases' file and delete > the old lease, "Save Changes" and "Restart DNS & DHCP". I've done that, but the device is not getting the reserved address even after I did that. I'll have a think and see if I can figure it out. I guess a phone factory reset would probably do the trick, but it's a while since I did one on that site, and I'm a tad nervous in case things go wrong. Thanks for the help Tom Tom Chadwin, ICT Manager Telephone: 01434 611530 Mob: Web: www.northumberlandnationalpark.org.uk<http://www.northumberlandnationalpark.org.uk/> IMPORTANT NOTICE - Disclaimer - This communication is from Northumberland National Park Authority (NNPA).The Authority’s head office and principal place of business is Eastburn, South Park, Hexham, Northumberland, NE46 1BS, United Kingdom. If you are not the intended recipient(s) please note that any form of disclosure, distribution, copying or use of this communication or the information in it or in any attachments is strictly prohibited and may be unlawful. If you have received this communication in error, please delete the email and destroy any copies of it. Any views or opinions presented are solely those of the author and do not necessarily represent those of NNPA.Contractors or potential contractors are reminded that a formal Order or Contract is needed for NNPA to be bound by any offer or acceptance of terms for the supply of goods or services Although this email and any attachments are believed to be free of any virus or other defects which might affect any computer or IT system into which they are received, no responsibility is accepted by the NNPA for any loss or damage arising in any way from the receipt or use thereof. Computer systems of this Authority may be monitored and communications carried out on them recorded, to secure the effective operation of the system and for other lawful purpose. |
From: Lonnie A. <li...@lo...> - 2020-03-05 15:45:23
|
> On Mar 5, 2020, at 9:39 AM, Tom Chadwin <tom...@nn...> wrote: > >>> What's the best way to set up reserved IP addresses for handsets given >> DHCP addresses by Astlinux? Do I look for best practice dnsmasq, or is there >> an approved Astlinux alternative method? >> >> in the "Network/Configure DNS Hosts" Tab. > > Thanks. I've added an entry, and rebooted the relevant handset, but it's still getting its previous lease address. Is that because the lease has not yet expired? If so, can I delete the lease so it requests a new one, and hopefully gets the reservation? > > Tom Yes, you can use the Edit tab and load the 'dnsmasq.leases' file and delete the old lease, "Save Changes" and "Restart DNS & DHCP". Lonnie |
From: Tom C. <tom...@nn...> - 2020-03-05 15:40:02
|
> > What's the best way to set up reserved IP addresses for handsets given > DHCP addresses by Astlinux? Do I look for best practice dnsmasq, or is there > an approved Astlinux alternative method? > > in the "Network/Configure DNS Hosts" Tab. Thanks. I've added an entry, and rebooted the relevant handset, but it's still getting its previous lease address. Is that because the lease has not yet expired? If so, can I delete the lease so it requests a new one, and hopefully gets the reservation? Tom Tom Chadwin, ICT Manager Telephone: 01434 611530 Mob: Web: www.northumberlandnationalpark.org.uk<http://www.northumberlandnationalpark.org.uk/> IMPORTANT NOTICE - Disclaimer - This communication is from Northumberland National Park Authority (NNPA).The Authority’s head office and principal place of business is Eastburn, South Park, Hexham, Northumberland, NE46 1BS, United Kingdom. If you are not the intended recipient(s) please note that any form of disclosure, distribution, copying or use of this communication or the information in it or in any attachments is strictly prohibited and may be unlawful. If you have received this communication in error, please delete the email and destroy any copies of it. Any views or opinions presented are solely those of the author and do not necessarily represent those of NNPA.Contractors or potential contractors are reminded that a formal Order or Contract is needed for NNPA to be bound by any offer or acceptance of terms for the supply of goods or services Although this email and any attachments are believed to be free of any virus or other defects which might affect any computer or IT system into which they are received, no responsibility is accepted by the NNPA for any loss or damage arising in any way from the receipt or use thereof. Computer systems of this Authority may be monitored and communications carried out on them recorded, to secure the effective operation of the system and for other lawful purpose. |
From: Michael K. <li...@mk...> - 2020-03-05 12:55:53
|
> Am 05.03.2020 um 12:23 schrieb Tom Chadwin <tom...@nn...>: > > Hello all > > What's the best way to set up reserved IP addresses for handsets given DHCP addresses by Astlinux? Do I look for best practice dnsmasq, or is there an approved Astlinux alternative method? > > Thanks > > Tom > > PS Huge apologies for my mammoth corporate email sig - I won't post to the list often... Hi Tom, in the "Network/Configure DNS Hosts" Tab. Michael http://www.mksolutions.info |
From: Tom C. <tom...@nn...> - 2020-03-05 11:38:46
|
Hello all What's the best way to set up reserved IP addresses for handsets given DHCP addresses by Astlinux? Do I look for best practice dnsmasq, or is there an approved Astlinux alternative method? Thanks Tom PS Huge apologies for my mammoth corporate email sig - I won't post to the list often... Tom Chadwin, ICT Manager Telephone: 01434 611530 Mob: Web: www.northumberlandnationalpark.org.uk<http://www.northumberlandnationalpark.org.uk/> IMPORTANT NOTICE - Disclaimer - This communication is from Northumberland National Park Authority (NNPA).The Authority’s head office and principal place of business is Eastburn, South Park, Hexham, Northumberland, NE46 1BS, United Kingdom. If you are not the intended recipient(s) please note that any form of disclosure, distribution, copying or use of this communication or the information in it or in any attachments is strictly prohibited and may be unlawful. If you have received this communication in error, please delete the email and destroy any copies of it. Any views or opinions presented are solely those of the author and do not necessarily represent those of NNPA.Contractors or potential contractors are reminded that a formal Order or Contract is needed for NNPA to be bound by any offer or acceptance of terms for the supply of goods or services Although this email and any attachments are believed to be free of any virus or other defects which might affect any computer or IT system into which they are received, no responsibility is accepted by the NNPA for any loss or damage arising in any way from the receipt or use thereof. Computer systems of this Authority may be monitored and communications carried out on them recorded, to secure the effective operation of the system and for other lawful purpose. |
From: Lonnie A. <li...@lo...> - 2020-02-23 19:01:50
|
Announcing Pre-Release Version: astlinux-1.3-4526-35c559 ** IMPORTANT NOTICE -- The PPTP VPN server has been removed. pfSense dropped support of PPTP VPN with version 2.3 in 2016. Apple dropped support of PPTP VPN with iOS 10 and macOS 10.12 in 2016. PPTP VPN (MS-CHAPv2) is insecure and is no longer supported in AstLinux. The AstLinux Team is regularly upgrading packages containing security and bug fixes as well as adding new features of our own. -- Linux Kernel 3.16.82 (version bump), security and bug fixes -- Asterisk 13.23.1 ('13se' version) Older than latest Asterisk 13.x version but more tested, built --without-pjproject -- Asterisk 13.31.0 (version bump) and 16.8.0 (version bump) -- pppd, version bump to 2.4.8, security fix: CVE-2020-8597 -- WireGuard VPN, module 0.0.20200215 (version bump), tools 1.0.20200206 (version bump) -- Complete Pre-Release ChangeLog: https://s3.amazonaws.com/beta.astlinux-project/astlinux-changelog/ChangeLog.txt The "AstLinux Pre-Release ChangeLog" and "Pre-Release Repository URL" entries can be found under the "Development" tab of the AstLinux Project web site ... AstLinux Project -> Development https://www.astlinux-project.org/dev.html AstLinux Team |