OPEN VPN自动故障转移

时间:2019-09-17 11:29:29

标签: failover openvpn

我正在尝试在openvpn中实现自动故障转移。我已经配置了2个openvpn服务器,并在client.conf中指定了两个服务器的ip。因此,当我停止一台服务器的OPENVPN服务时,在该服务器上一切正常,然后客户端成功连接到第二台openvpn服务器,但互联网无法正常工作。请参阅日志:

Sep 17 16:41:26 redismaster ovpn-rana[16403]: Attempting to establish TCP connection with [AF_INET]3.4.5.6:443 [nonblock]
Sep 17 16:41:27 redismaster ovpn-rana[16403]: TCP: connect to [AF_INET]1.2.3.4:443 failed, will try again in 5 seconds: Connection refused
Sep 17 16:41:27 redismaster ovpn-rana[16403]: SIGUSR1[soft,init_instance] received, process restarting
Sep 17 16:41:27 redismaster ovpn-rana[16403]: Restart pause, 5 second(s)
Sep 17 16:41:32 redismaster ovpn-rana[16403]: NOTE: the current --script-security setting may allow this configuration to call user-defined scripts
Sep 17 16:41:32 redismaster ovpn-rana[16403]: Socket Buffers: R=[87380->87380] S=[16384->16384]
Sep 17 16:41:32 redismaster ovpn-rana[16403]: Attempting to establish TCP connection with [AF_INET]1.2.3.4:443 [nonblock]
Sep 17 16:41:33 redismaster ovpn-rana[16403]: TCP connection established with [AF_INET]1.2.3.4:443
Sep 17 16:41:33 redismaster ovpn-rana[16403]: TCPv4_CLIENT link local: [undef]
Sep 17 16:41:33 redismaster ovpn-rana[16403]: TCPv4_CLIENT link remote: [AF_INET]1.2.3.4:443
Sep 17 16:41:34 redismaster ovpn-rana[16403]: TLS: Initial packet from [AF_INET]1.2.3.4:443, sid=181a2348 cfee5838
Sep 17 16:41:34 redismaster ovpn-rana[16403]: VERIFY OK: depth=1, C=IN, ST=MH, L=Pune, O=ABC Technology, OU=Community, CN=ABC Technology CA, name=Community, emailAddress=xyz@abc.com
Sep 17 16:41:34 redismaster ovpn-rana[16403]: Validating certificate key usage
Sep 17 16:41:34 redismaster ovpn-rana[16403]: ++ Certificate has key usage  00a0, expects 00a0
Sep 17 16:41:34 redismaster ovpn-rana[16403]: VERIFY KU OK
Sep 17 16:41:34 redismaster ovpn-rana[16403]: Validating certificate extended key usage
Sep 17 16:41:34 redismaster ovpn-rana[16403]: ++ Certificate has EKU (str) TLS Web Server Authentication, expects TLS Web Server Authentication
Sep 17 16:41:34 redismaster ovpn-rana[16403]: VERIFY EKU OK
Sep 17 16:41:34 redismaster ovpn-rana[16403]: VERIFY OK: depth=0, C=IN, ST=MH, L=Pune, O=ABC Technology, OU=Community, CN=server, name=Community, emailAddress=xyz@abc.com
Sep 17 16:41:35 redismaster ovpn-rana[16403]: Data Channel Encrypt: Cipher 'AES-128-CBC' initialized with 128 bit key
Sep 17 16:41:35 redismaster ovpn-rana[16403]: Data Channel Encrypt: Using 256 bit message hash 'SHA256' for HMAC authentication
Sep 17 16:41:35 redismaster ovpn-rana[16403]: Data Channel Decrypt: Cipher 'AES-128-CBC' initialized with 128 bit key
Sep 17 16:41:35 redismaster ovpn-rana[16403]: Data Channel Decrypt: Using 256 bit message hash 'SHA256' for HMAC authentication
Sep 17 16:41:35 redismaster ovpn-rana[16403]: Control Channel: TLSv1.2, cipher TLSv1/SSLv3 DHE-RSA-AES256-GCM-SHA384, 2048 bit RSA
Sep 17 16:41:35 redismaster ovpn-rana[16403]: [server] Peer Connection Initiated with [AF_INET]1.2.3.4:443
Sep 17 16:41:37 redismaster ovpn-rana[16403]: SENT CONTROL [server]: 'PUSH_REQUEST' (status=1)
Sep 17 16:41:38 redismaster ovpn-rana[16403]: PUSH: Received control message: 'PUSH_REPLY,redirect-gateway def1 bypass-dhcp,dhcp-option DNS 208.67.222.222,dhcp-option DNS 208.67.220.220,route 10.8.0.1,topology net30,ping 10,ping-restart 120,ifconfig 10.8.0.6 10.8.0.5'
Sep 17 16:41:38 redismaster ovpn-rana[16403]: OPTIONS IMPORT: timers and/or timeouts modified
Sep 17 16:41:38 redismaster ovpn-rana[16403]: OPTIONS IMPORT: --ifconfig/up options modified
Sep 17 16:41:38 redismaster ovpn-rana[16403]: OPTIONS IMPORT: route options modified
Sep 17 16:41:38 redismaster ovpn-rana[16403]: OPTIONS IMPORT: --ip-win32 and/or --dhcp-option options modified
Sep 17 16:41:38 redismaster ovpn-rana[16403]: Preserving previous TUN/TAP instance: tun0
Sep 17 16:41:38 redismaster ovpn-rana[16403]: Initialization Sequence Completed

您能帮我找出我的配置有什么问题吗?

谢谢。

0 个答案:

没有答案
相关问题