We have moved to a new Sailfish OS Forum. Please start new discussions there.

Revision history [back]

click to hide/show revision 1
initial version

posted 2017-02-08 19:51:33 +0200

openvpn stuff with 2.1.0.9

I tried openvpn with the 2.1.0.9 mimikry. I have a more or less complicated configuration with v6

  • udp via tun
  • route-ipv6
  • tun-ipv6
  • tun-mtu
  • ca/key/cert
  • redirect gateway def1
  • route 0.0.0.0 0.0.0.0 gateway
  • tls-auth
  • dhcp-option DNS
  • dhcp-option DOMAIN

first I tried to directly import .ovpn file -> crash of preferences. I tried to make variations of complicated options (no ipv6 and stuff) crash

Then I build up a new openvpn setup -> Advanced. I tried to setup the certificates via gui. when then setting the .ovpn file the tunnel can be build up. Deleting the certificate stuff in gui works too (cert confs via ovpn)

But no ipv6. I am not sure what happens with dns resolving (trying it from inside) so I need to make the test from a foreign network tomorow.

Works v4:

  • starting
  • routing

I once had an openvpn crash and in preferences active was still shown.

No ipv6 at all (options are not passed to the openvpn command). Actual I do not know

  • if resolving works with dns behind tunnel
  • default gateway works via redirect-gateway or via route option (redirect-gateway is needed for v6)

@coderus: Please find the VPN button for powermenu ;-)

openvpn stuff with 2.1.0.9

I tried openvpn with the 2.1.0.9 mimikry. I have a more or less complicated configuration with v6

  • udp via tun
  • route-ipv6
  • tun-ipv6
  • tun-mtu
  • ca/key/cert
  • redirect gateway def1
  • route 0.0.0.0 0.0.0.0 gateway
  • tls-auth
  • dhcp-option DNS
  • dhcp-option DOMAIN

first I tried to directly import .ovpn file -> crash of preferences. I tried to make variations of complicated options (no ipv6 and stuff) crash

Then I build up a new openvpn setup -> Advanced. I tried to setup the certificates via gui. when then setting the .ovpn file the tunnel can be build up. Deleting the certificate stuff in gui works too (cert confs via ovpn)

But no ipv6. I am not sure what happens with dns resolving (trying it from inside) so I need to make the test from a foreign network tomorow.

Works v4:

  • starting
  • routing

I once had an openvpn crash and in preferences active was still shown.

No ipv6 at all (options are not passed to the openvpn command). Actual I do not know

  • if resolving works with dns behind tunnel
  • default gateway works via redirect-gateway or via route option (redirect-gateway is needed for v6)

ipv6 should work especially when starting up the tunnel in a dual stack environment -> v6 bypasses then!

@coderus: Please find the VPN button for powermenu ;-)

openvpn stuff with 2.1.0.9

I tried openvpn with the 2.1.0.9 mimikry. I have a more or less complicated configuration with v6

  • udp via tun
  • route-ipv6
  • tun-ipv6
  • tun-mtu
  • ca/key/cert
  • redirect gateway def1
  • route 0.0.0.0 0.0.0.0 gateway
  • tls-auth
  • dhcp-option DNS
  • dhcp-option DOMAIN

first I tried to directly import .ovpn file -> crash of preferences. I tried to make variations of complicated options (no ipv6 and stuff) crash

Then I build built up a new openvpn setup -> Advanced. I tried to setup the certificates via gui. when then setting the .ovpn file the tunnel can be build up. Deleting the certificate stuff in gui works too (cert confs via ovpn)

But no ipv6. I am not sure what happens with dns resolving (trying it from inside) so I need to make the test from a foreign network tomorow.

Works v4:

  • starting
  • routing

I once had an openvpn crash and in preferences active was still shown.

No ipv6 at all (options are not passed to the openvpn command). Actual I do not know

  • if resolving works with dns behind tunnel
  • default gateway works via redirect-gateway or via route option (redirect-gateway is needed for v6)

ipv6 should work especially when starting up the tunnel in a dual stack environment -> v6 bypasses then!

@coderus: Please find the VPN button for powermenu ;-)

[bug][test] openvpn stuff with 2.1.0.9

I tried openvpn with the 2.1.0.9 mimikry. I have a more or less complicated configuration with v6

  • udp via tun
  • route-ipv6
  • tun-ipv6
  • tun-mtu
  • ca/key/cert
  • redirect gateway def1
  • route 0.0.0.0 0.0.0.0 gateway
  • tls-auth
  • dhcp-option DNS
  • dhcp-option DOMAIN

first I tried to directly import .ovpn file -> crash of preferences. I tried to make variations of complicated options (no ipv6 and stuff) crash

Then I built up a new openvpn setup -> Advanced. I tried to setup the certificates via gui. when then setting the .ovpn file the tunnel can be build up. Deleting the certificate stuff in gui works too (cert confs via ovpn)

But no ipv6. I am not sure what happens with dns resolving (trying it from inside) so I need to make the test from a foreign network tomorow.

Works v4:

  • starting
  • routing

I once had an openvpn crash and in preferences active was still shown.

No ipv6 at all (options are not passed to the openvpn command). Actual I do not know

  • if resolving works with dns behind tunnel
  • default gateway works via redirect-gateway or via route option (redirect-gateway is needed for v6)

ipv6 should work especially when starting up the tunnel in a dual stack environment -> v6 bypasses then!

@coderus: Please find the VPN button for powermenu ;-)

[bug][test] openvpn stuff with 2.1.0.9

I tried openvpn with the 2.1.0.9 mimikry. I have a more or less complicated configuration with v6

  • udp via tun
  • route-ipv6
  • tun-ipv6
  • tun-mtu
  • ca/key/cert
  • redirect gateway def1
  • route 0.0.0.0 0.0.0.0 gateway
  • tls-auth
  • dhcp-option DNS
  • dhcp-option DOMAIN

first I tried to directly import .ovpn file -> crash of preferences. I tried to make variations of complicated options (no ipv6 and stuff) crash

Then I built up a new openvpn setup -> Advanced. I tried to setup the certificates via gui. when then setting the .ovpn file the tunnel can be build up. Deleting the certificate stuff in gui works too (cert confs via ovpn)

But no ipv6. I am not sure what happens with dns resolving (trying it from inside) so I need to make the test from a foreign network tomorow.

Works v4:

  • starting
  • routing

I once had an openvpn crash and in preferences active was still shown.

No ipv6 at all (options are not passed to the openvpn command). Actual I do not know

  • if resolving works with dns behind tunnel
  • default gateway works via redirect-gateway or via route option (redirect-gateway is needed for v6)

ipv6 should work especially when starting up the tunnel in a dual stack environment -> v6 bypasses then!

@coderus: Please find the VPN button for powermenu ;-);-) @jolla: Event screen options: Link to the VPN menu is ok, but a fast action to enable/disable the VPN would be fine

[bug][test] openvpn stuff with 2.1.0.9

I tried openvpn with the 2.1.0.9 mimikry. I have a more or less complicated configuration with v6

  • udp via tun
  • route-ipv6
  • tun-ipv6
  • tun-mtu
  • ca/key/cert
  • redirect gateway def1
  • route 0.0.0.0 0.0.0.0 gateway
  • tls-auth
  • dhcp-option DNS
  • dhcp-option DOMAIN

first I tried to directly import .ovpn file -> crash of preferences. I tried to make variations of complicated options (no ipv6 and stuff) crash

Then I built up a new openvpn setup -> Advanced. I tried to setup the certificates via gui. when then setting the .ovpn file the tunnel can be build up. Deleting the certificate stuff in gui works too (cert confs via ovpn)

But no ipv6. I am not sure what happens with dns resolving (trying it from inside) so I need to make the test from a foreign network tomorow.

Works v4:

  • starting
  • routing

I once had an openvpn crash and in preferences active was still shown.

No ipv6 at all (options are not passed to the openvpn command). Actual I do not know

  • if resolving works with dns behind tunnel
  • default gateway works via redirect-gateway or via route option (redirect-gateway is needed for v6)

ipv6 should work especially when starting up the tunnel in a dual stack environment -> v6 bypasses then!

@coderus: Please find the VPN button for powermenu ;-) @jolla: Event screen options: Link to the VPN menu is ok, but a fast action to enable/disable the VPN would be fine

[Update] the whole dhcp-option stuff does not work: You cannot resolv your internal addresses from inside the tunnel.

Hm... from the point of an end user this is not usable - especially from the security point of view (v6 bypassing). I will open another thread with a tunnel wishlist...