Skip to content

Commit 62bbf80

Browse files
committed
gateway-server: finalize config for openvpn-user6
Also delete custom data-cipher config because we do not have old APs with old firmware connecting here.
1 parent 1ba3004 commit 62bbf80

File tree

3 files changed

+8
-22
lines changed

3 files changed

+8
-22
lines changed

Diff for: roles/gateway-server/tasks/main.yml

+1-1
Original file line numberDiff line numberDiff line change
@@ -7,7 +7,7 @@
77
- include_tasks: web.yml
88
- include_tasks: speed-tests.yml
99
- include_tasks: user6-ferm.yml
10+
- include_tasks: user6-openvpn.yml
1011
#TODO
11-
#- include_tasks: openvpn-user6.yml
1212
#- include_tasks: radvd.yml
1313
#- include_tasks: dhcpd6.yml

Diff for: roles/gateway-server/templates/openvpn/opennet_user6-ifup.sh

+4-4
Original file line numberDiff line numberDiff line change
@@ -1,11 +1,11 @@
11
#!/bin/bash
22

33
#set IP on interface
4-
ip addr add 2a0a:4580:1010:0002::1/64 dev {{ openvpn_users_l2_v6_interface }}
5-
#set IF up
6-
ip link set dev tap-users-v6 up
4+
ip addr add 2a0a:4580:1010:0002::1/64 dev {{ openvpn_user6_interface }}
5+
#activate interface
6+
ip link set dev {{ openvpn_user6_interface }} up
77
#add routing for dhcpv6-pd range
8-
ip route add 2a0a:4580:1010:1000::/52 dev tap-users-v6
8+
ip route add 2a0a:4580:1010:1000::/52 dev {{ openvpn_user6_interface }}
99

1010
#restart services which rely on this interface
1111
systemctl restart isc-dhcp-server

Diff for: roles/gateway-server/templates/openvpn/opennet_user6.conf

+3-17
Original file line numberDiff line numberDiff line change
@@ -9,20 +9,6 @@ port 1700
99
proto udp6
1010
max-clients 100
1111

12-
{% if debian_release != "buster" %}
13-
# Ältere Clients (u.a. v.0.5.3) können sich Clients seit Debian Bullseye
14-
# (OpenVPN 2.5) nicht mehr verbinden. Laut der OpenVPN-Doku ist dieses Problem
15-
# gegenüber Clients der Version 2.3 (Opennet Firmware 0.5.3) oder älter erwartbar.
16-
# Laut OpenVPN-Doku hätte eigentlich die Verwendung von
17-
# "--data-ciphers-fallback BF-CBC" für unsere Konstellation passend sein sollen
18-
# (da wir die Build-Option "--enable-small" auf den Routern einsetzen), allerdings
19-
# funktioniert dann aus unklaren Gründen der Verbindungsaufbau nicht.
20-
# Daher verwenden wir eine explizite Ciphers-Liste, die auch für v2.3-Clients
21-
# verwendbar ist.
22-
# Quelle: https://community.openvpn.net/openvpn/wiki/CipherNegotiation#Serverversion2.5Configuring:--data-ciphers
23-
data-ciphers AES-256-GCM:AES-128-GCM:AES-256-CBC:BF-CBC
24-
{% endif %}
25-
2612
# Zertifikate
2713
ca /etc/openvpn/opennet_users/ca.crt
2814
cert {{ openvpn_ugw_cert_file }}
@@ -43,7 +29,7 @@ group openvpn
4329

4430
# Netzwerkschnittstelle
4531
dev-type tap
46-
dev {{ openvpn_users_l2_v6_interface }}
32+
dev {{ openvpn_user6_interface }}
4733
persist-key
4834
persist-tun
4935

@@ -55,8 +41,8 @@ up opennet_user6-ifup.sh
5541
down opennet_user6-ifdown.sh
5642

5743
# Logging
58-
status /var/log/openvpn/opennet_user_l2vpn_v6.status.log
44+
status /var/log/openvpn/opennet_user6.status.log
5945
# nur im Notfall fuer Debugging kurzfristig aktivieren und verbosity erhoehen
60-
#log-append /var/log/openvpn/opennet_user_l2vpn_v6.log
46+
#log-append /var/log/openvpn/opennet_user6.log
6147
verb 0
6248
management localhost 7507

0 commit comments

Comments
 (0)