Я делал так
1) easyrsa init-pki
2) easyrsa gen-dh
3) easyrsa build-ca nopass
3) easyrsa build-server-full gwr nopass
4)easyrsa build-client-full test21 nopass
5) cd /usr/local/share/easy-rsa/pki
6) openvpn --genkey --secret ta.key
7)mkdir /usr/local/etc/openvpn

9)cp /usr/local/share/examples/openvpn/sample-config-files/server.conf /usr/local/etc/openvpn
10) В server.conf
Код: Выделить всё
port 2000
proto udp
dev tap0
ca ca.crt
cert gw.crt
key gw.key
dh dh.pem
client-config-dir ccd
auth MD5
mode server
tls-auth ta.key
ifconfig 10.127.213.1 255.255.255.128
route 192.168.0.1 255.255.255.0 10.127.213.2
keepalive 10 120
cipher BF-CBC
comp-lzo
persist-key
persist-tun
client-to-client
log openvpn.log
log-append openvpn.log
Файл test21.
В test21
Код: Выделить всё
ifconfig-push 10.127.213.3 255.255.255.128
push route 192.168.0.1 255.255.255.0 10.127.213.2
ca.crt
test21.crt
openvpn.opvpn
ta.key
test21.key
13) В openvpn.opvpn
Код: Выделить всё
remote мой WAN 2000
client
dev tap
auth MD5
cipher BF-CBC
ping 10
comp-lzo
proto udp
ca ca.crt
cert test21.crt
key test21.key
verb 3
Код: Выделить всё
Mon Mar 13 22:16:39 2017 OpenVPN 2.3.14 i686-w64-mingw32 [SSL (OpenSSL)] [LZO] [PKCS11] [IPv6] built on Feb 1 2017
Mon Mar 13 22:16:39 2017 Windows version 5.1 (Windows XP) 32bit
Mon Mar 13 22:16:39 2017 library versions: OpenSSL 1.0.2k 26 Jan 2017, LZO 2.09
Enter Management Password:
Mon Mar 13 22:16:39 2017 MANAGEMENT: TCP Socket listening on [AF_INET]127.0.0.1:25340
Mon Mar 13 22:16:39 2017 Need hold release from management interface, waiting...
Mon Mar 13 22:16:40 2017 MANAGEMENT: Client connected from [AF_INET]127.0.0.1:25340
Mon Mar 13 22:16:40 2017 MANAGEMENT: CMD 'state on'
Mon Mar 13 22:16:40 2017 MANAGEMENT: CMD 'log all on'
Mon Mar 13 22:16:40 2017 MANAGEMENT: CMD 'hold off'
Mon Mar 13 22:16:40 2017 MANAGEMENT: CMD 'hold release'
Mon Mar 13 22:16:40 2017 WARNING: No server certificate verification method has been enabled. See http://openvpn.net/howto.html#mitm for more info.
Mon Mar 13 22:16:40 2017 Socket Buffers: R=[8192->8192] S=[8192->8192]
Mon Mar 13 22:16:40 2017 UDPv4 link local (bound): [undef]
Mon Mar 13 22:16:40 2017 UDPv4 link remote: [AF_INET]Мой WAn:2000
Mon Mar 13 22:16:40 2017 MANAGEMENT: >STATE:1489432600,WAIT,,,
Mon Mar 13 22:17:40 2017 TLS Error: TLS key negotiation failed to occur within 60 seconds (check your network connectivity)
Mon Mar 13 22:17:40 2017 TLS Error: TLS handshake failed
Mon Mar 13 22:17:40 2017 SIGUSR1[soft,tls-error] received, process restarting
Mon Mar 13 22:17:40 2017 MANAGEMENT: >STATE:1489432660,RECONNECTING,tls-error,,
Mon Mar 13 22:17:40 2017 Restart pause, 2 second(s)
Mon Mar 13 22:17:42 2017 WARNING: No server certificate verification method has been enabled. See http://openvpn.net/howto.html#mitm for more info.
Mon Mar 13 22:17:42 2017 Socket Buffers: R=[8192->8192] S=[8192->8192]
Mon Mar 13 22:17:42 2017 UDPv4 link local (bound): [undef]
Mon Mar 13 22:17:42 2017 UDPv4 link remote: [AF_INET]МОй WAN:2000
Mon Mar 13 22:17:42 2017 MANAGEMENT: >STATE:1489432662,WAIT,,,
Mon Mar 13 22:18:43 2017 TLS Error: TLS key negotiation failed to occur within 60 seconds (check your network connectivity)
Mon Mar 13 22:18:43 2017 TLS Error: TLS handshake failed
Mon Mar 13 22:18:43 2017 SIGUSR1[soft,tls-error] received, process restarting
Mon Mar 13 22:18:43 2017 MANAGEMENT: >STATE:1489432723,RECONNECTING,tls-error,,
Mon Mar 13 22:18:43 2017 Restart pause, 2 second(s)
Mon Mar 13 22:18:45 2017 WARNING: No server certificate verification method has been enabled. See http://openvpn.net/howto.html#mitm for more info.
Mon Mar 13 22:18:45 2017 Socket Buffers: R=[8192->8192] S=[8192->8192]
Mon Mar 13 22:18:45 2017 UDPv4 link local (bound): [undef]
Mon Mar 13 22:18:45 2017 UDPv4 link remote: [AF_INET]Мой WAn:2000
Mon Mar 13 22:18:45 2017 MANAGEMENT: >STATE:1489432725,WAIT,,,
Mon Mar 13 22:19:45 2017 TLS Error: TLS key negotiation failed to occur within 60 seconds (check your network connectivity)
Mon Mar 13 22:19:45 2017 TLS Error: TLS handshake failed
Mon Mar 13 22:19:45 2017 SIGUSR1[soft,tls-error] received, process restarting
Mon Mar 13 22:19:45 2017 MANAGEMENT: >STATE:1489432785,RECONNECTING,tls-error,,
Mon Mar 13 22:19:45 2017 Restart pause, 2 second(s)
Mon Mar 13 22:19:47 2017 WARNING: No server certificate verification method has been enabled. See http://openvpn.net/howto.html#mitm for more info.
Mon Mar 13 22:19:47 2017 Socket Buffers: R=[8192->8192] S=[8192->8192]
Mon Mar 13 22:19:47 2017 UDPv4 link local (bound): [undef]
Mon Mar 13 22:19:47 2017 UDPv4 link remote: [AF_INET]мой WAN:2000
Mon Mar 13 22:19:47 2017 MANAGEMENT: >STATE:1489432787,WAIT,,,
Mon Mar 13 22:20:47 2017 TLS Error: TLS key negotiation failed to occur within 60 seconds (check your network connectivity)
Mon Mar 13 22:20:47 2017 TLS Error: TLS handshake failed
Mon Mar 13 22:20:47 2017 SIGUSR1[soft,tls-error] received, process restarting
Mon Mar 13 22:20:47 2017 MANAGEMENT: >STATE:1489432847,RECONNECTING,tls-error,,
Mon Mar 13 22:20:47 2017 Restart pause, 2 second(s)
Mon Mar 13 22:20:49 2017 WARNING: No server certificate verification method has been enabled. See http://openvpn.net/howto.html#mitm for more info.
Mon Mar 13 22:20:49 2017 Socket Buffers: R=[8192->8192] S=[8192->8192
]