Debian 6上的OpenVPN无法启动


2

我在Deabian 6 VPS(使用OpenVZ)上多次配置openvpn,但始终坚持“启动虚拟专用网络守护程序:客户端服务器失败!”

系统日志表明,tun / tan似乎有问题,但我无法解决问题:

Jan 14 17:00:05 netherlands ovpn-server[7359]: OpenVPN 2.1.3 i486-pc-linux-gnu [SSL] [LZO2] [EPOLL] [PKCS11] [MH] [PF_INET6] [eurephia] built on Jun  6 2013
Jan 14 17:00:05 netherlands ovpn-server[7359]: NOTE: OpenVPN 2.1 requires '--script-security 2' or higher to call user-defined scripts or executables
Jan 14 17:00:05 netherlands ovpn-server[7359]: Diffie-Hellman initialized with 1024 bit key
Jan 14 17:00:05 netherlands ovpn-server[7359]: WARNING: file 'netherlands.key' is group or others accessible
Jan 14 17:00:05 netherlands ovpn-server[7359]: /usr/bin/openssl-vulnkey -q -b 1024 -m <modulus omitted>
Jan 14 17:00:05 netherlands ovpn-server[7359]: TLS-Auth MTU parms [ L:1542 D:138 EF:38 EB:0 ET:0 EL:0 ]
Jan 14 17:00:05 netherlands ovpn-server[7359]: Socket Buffers: R=[245760->131072] S=[245760->131072]
Jan 14 17:00:05 netherlands ovpn-server[7359]: ROUTE: default_gateway=UNDEF
Jan 14 17:00:05 netherlands ovpn-server[7359]: Note: Cannot open TUN/TAP dev /dev/net/tun: Operation not permitted (errno=1)
Jan 14 17:00:05 netherlands ovpn-server[7359]: Note: Attempting fallback to kernel 2.2 TUN/TAP interface
Jan 14 17:00:05 netherlands ovpn-server[7359]: Cannot allocate TUN/TAP dev dynamically
Jan 14 17:00:05 netherlands ovpn-server[7359]: Exiting

有人可以帮我吗?


是否 /dev/net/tun 存在?你能 ls -la 它?
Paul

不,该文件夹甚至不存在。那是什么意思?
Lukas

@Paul也试过modprobe tun但我总是得到“致命:找不到模块。”
Lukas

您是否以root身份运行OpenVPN?你应该。您是否将语句script-security 2添加到conf文件中?请发布conf文件
MariusMatutiae

@MariusMatutiae是的,我以root身份开始使用OpenVPN,实际上我已经解决了问题的根源 - 只是OpenVZ没有提供tun模块,所以在将问题报告给主机后,我现在可以运行并连接到OpenVPN的。但是现在我需要解决这个问题,当我使用OpenVPN连接到我的服务器时,我无法访问互联网(net.ipv4.ip_forward和iptables已启用)。我的server.conf: pastebin.com/TtbNgdaG
Lukas

Answers:


0

使用OpenVZ在VPS上无法使用tun模块。它可以通过检查的存在来测试 /dev/net/tun - 文件夹或 modprobe tun - 如果模块不可用,则会出现致命错误 FATAL: Module tun not found。必须在OpenVZ中激活tun模块。您可以向托管商报告问题,也可以查看OpenVZ Wiki中的其他文章: http://wiki.openvz.org/VPN_via_the_TUN/TAP_device

By using our site, you acknowledge that you have read and understand our Cookie Policy and Privacy Policy.
Licensed under cc by-sa 3.0 with attribution required.