Hallo zusammen, ich habe meinen Openvpn_Server (mit pivpn) auf Dual-Stack umgestellt, um ipv6 leaks zu vermeiden. Getunnelt wird durch einen ipv4-Tunnel. Mit dem Handy klappts und mit Windoof auch, nur mit meinem Ubunturechner habe ich Probleme. Die Verbindung lässt sich mitlerweile aufbauen. Leider habe ich ein ipv6 Leak. Über Ideen wäre ich sehr dankbar.
CCD-Datei:
ifconfig-push 10.125.175.2 255.255.255.0 ifconfig-ipv6-push 2a02:3100:2590:ec01::1003/124 2a02:3100:2590:ec01::1/124 iroute-ipv6 2a02:3100:2590:ec01::1003/124
Netzwerkinfos vom Client:
ip -6 addr show tun0
34: tun0: <POINTOPOINT,MULTICAST,NOARP,UP,LOWER_UP> mtu 1500 qdisc fq_codel state UNKNOWN group default qlen 500
inet6 fe80::dd31:17aa:c4fa:f430/64 scope link stable-privacy
valid_lft forever preferred_lft forever
max@ugly-unicorn:~$ ip -6 route show
2a02:3100:1951:ca00::/64 dev wlx3498b53584d6 proto ra metric 600 pref medium
2a02:3100:1951:ca00::/64 via fe80::d624:ddff:fe1e:6170 dev wlx3498b53584d6 proto ra metric 605 pref medium
2a02:3100:1951:ca00::/56 via fe80::d624:ddff:fe1e:6170 dev wlx3498b53584d6 proto ra metric 600 pref medium
2a02:3100:2590:ec00::/64 dev wlx3498b53584d6 proto ra metric 600 pref medium
2a02:3100:2590:ec00::/56 via fe80::d624:ddff:fe1e:6170 dev wlx3498b53584d6 proto ra metric 600 pref medium
fd84:9c99:3e08::/64 dev wlx3498b53584d6 proto ra metric 600 pref medium
fd84:9c99:3e08::/64 via fe80::d624:ddff:fe1e:6170 dev wlx3498b53584d6 proto ra metric 605 pref medium
fe80::/64 dev tun0 proto kernel metric 256 pref medium
fe80::/64 dev wlx3498b53584d6 proto kernel metric 1024 pref medium
default via fe80::d624:ddff:fe1e:6170 dev wlx3498b53584d6 proto ra metric 600 pref mediumVPN-Log:
Sep 13 02:23:31 ugly-unicorn nm-openvpn[12179]: event_wait : Interrupted system call (fd=-1,code=4) Sep 13 02:23:31 ugly-unicorn nm-openvpn[12179]: SIGTERM[hard,] received, process exiting Sep 13 02:23:32 ugly-unicorn NetworkManager[1180]: <info> [1757723012.7025] vpn[0x578a181e5fc0,17fde95d-fadd-4991-bb8c-8b1520c77bc9,"Max_Laptop"]: starting openvpn Sep 13 02:23:32 ugly-unicorn nm-openvpn[12713]: Note: --cipher is not set. OpenVPN versions before 2.5 defaulted to BF-CBC as fallback when cipher negotiation failed in this case. If you need this fallback please add '--data-ciphers-fallback BF-CBC' to your configuration and/or add BF-CBC to --data-ciphers. Sep 13 02:23:32 ugly-unicorn nm-openvpn[12713]: OpenVPN 2.6.14 x86_64-pc-linux-gnu [SSL (OpenSSL)] [LZO] [LZ4] [EPOLL] [PKCS11] [MH/PKTINFO] [AEAD] [DCO] Sep 13 02:23:32 ugly-unicorn nm-openvpn[12713]: library versions: OpenSSL 3.0.13 30 Jan 2024, LZO 2.10 Sep 13 02:23:32 ugly-unicorn nm-openvpn[12713]: DCO version: N/A Sep 13 02:23:32 ugly-unicorn nm-openvpn[12713]: NOTE: the current --script-security setting may allow this configuration to call user-defined scripts Sep 13 02:23:32 ugly-unicorn nm-openvpn[12713]: TCP/UDP: Preserving recently used remote address: [AF_INET]93.128.184.84:1194 Sep 13 02:23:32 ugly-unicorn nm-openvpn[12713]: UDPv4 link local: (not bound) Sep 13 02:23:32 ugly-unicorn nm-openvpn[12713]: UDPv4 link remote: [AF_INET]93.128.184.84:1194 Sep 13 02:23:32 ugly-unicorn nm-openvpn[12713]: NOTE: UID/GID downgrade will be delayed because of --client, --pull, or --up-delay Sep 13 02:23:32 ugly-unicorn nm-openvpn[12713]: [clumsy-camel_67c1b959-7d87-48c4-a94c-298162db268e] Peer Connection Initiated with [AF_INET]93.128.184.84:1194 Sep 13 02:23:32 ugly-unicorn nm-openvpn[12713]: Options error: Unrecognized option or missing or extra parameter(s) in [PUSH-OPTIONS]:2: block-outside-dns (2.6.14) Sep 13 02:23:32 ugly-unicorn nm-openvpn[12713]: WARNING: You have specified redirect-gateway and redirect-private at the same time (or the same option multiple times). This is not well supported and may lead to unexpected results Sep 13 02:23:32 ugly-unicorn nm-openvpn[12713]: TUN/TAP device tun0 opened Sep 13 02:23:32 ugly-unicorn nm-openvpn[12713]: /usr/libexec/nm-openvpn-service-openvpn-helper --debug 0 12707 --bus-name org.freedesktop.NetworkManager.openvpn.Connection_64 --tun -- tun0 1500 0 10.125.175.2 255.255.255.0 init Sep 13 02:23:32 ugly-unicorn nm-openvpn[12713]: UID set to nm-openvpn Sep 13 02:23:32 ugly-unicorn nm-openvpn[12713]: GID set to nm-openvpn Sep 13 02:23:32 ugly-unicorn nm-openvpn[12713]: Capabilities retained: CAP_NET_ADMIN Sep 13 02:23:32 ugly-unicorn nm-openvpn[12713]: Initialization Sequence Completed
Danke schon mal.