SYSTEM WARNING: 'date_default_timezone_get(): It is not safe to rely on the system's timezone settings. You are *required* to use the date.timezone setting or the date_default_timezone_set() function. In case you used any of those methods and you are still getting this warning, you most likely misspelled the timezone identifier. We selected the timezone 'UTC' for now, but please set date.timezone to select your timezone.' in '/usr/share/mantis/www/core.php' line 264
|Anonymous | Login||2022-01-25 08:20 UTC|
|Main | My View | View Issues | Change Log | Roadmap|
|View Issue Details|
|ID||Project||Category||View Status||Date Submitted||Last Update|
|0002682||Endian Firewall||Network related (VPN, uplinks)||public||2010-02-14 20:00||2012-07-20 12:00|
|Target Version||future||Fixed in Version|
|Summary||0002682: global OpenVPN DCHP Options not pushed when using X509 without having accounts|
|Description||Push domain, Push these nameservers options doesn't work. |
Would be nice to also have push "dhcp-option WINS a.b.c.d".
Workaround with adding
push "dhcp-option DNS a.b.c.d"
push "dhcp-option DNS a.b.c.d"
push "dhcp-option WINS a.b.c.d"
push "dhcp-option DOMAIN domain.tld"
|Is that happening with windows clients?|
|Yes. I only have Windows Clients here. Both XP and Windows7.|
these push values are confgurable for each user, therefore you will not find them within the global openvpn config file.
can you please check if you have the correct values in
the template for the user files is /var/openvpn/user.tmpl
WINS is not configurable right now, but DNS and DOMAIN should be pushed
|We use only X.509 certificates for OpenVPN, so there are no users on the firewall itself. "Global push options" don't apply in this case?|
Same here, migrating a fw + openvpn server to Endian.
Using X.509 (ca.crt, vpnserver.crt, vpnserver.key) and ended up messing with /etc/openvpn/openvpn.conf.tmpl
edited on: 2010-03-22 16:53
well, then it does not set it in the global openvpn configuration.
those values will only be set within the user's configuration.
so those global values really will not be taken in consideration right now with x509 authentication
thank you for bringing this to our attention
you can try to create an account called "DEFAULT", which then will be used as default configuration for those connectinos.
that should work
actually it is asking for a password, but as long as you don't use 2-factor auth it should not be used.
is this bug still existent? I got nearly the same behaviour with the EFW 2.4.1.
|2010-02-14 20:00||fabiana||New Issue|
|2010-02-15 08:47||luca-endian||Note Added: 0003785|
|2010-02-15 08:48||fabiana||Note Added: 0003786|
|2010-03-05 00:25||peter-endian||Note Added: 0003939|
|2010-03-05 00:25||peter-endian||Status||new => feedback|
|2010-03-05 06:06||fabiana||Note Added: 0003940|
|2010-03-20 15:29||volker||Note Added: 0004075|
|2010-03-22 16:51||peter-endian||Note Added: 0004080|
|2010-03-22 16:51||peter-endian||Status||feedback => confirmed|
|2010-03-22 16:52||peter-endian||Note Added: 0004081|
|2010-03-22 16:53||peter-endian||Note Edited: 0004080|
|2010-03-22 16:53||peter-endian||Note Deleted: 0004081|
|2010-03-22 16:54||peter-endian||Target Version||=> future|
|2010-09-23 13:20||peter-endian||Summary||OpenVPN DCHP Options not pushed => global OpenVPN DCHP Options not pushed when using X509 without having accounts|
|2010-09-23 13:20||peter-endian||Relationship added||has duplicate 0002187|
|2011-09-18 15:41||arno_filter||Note Added: 0007420|
|2012-07-20 11:59||luke-endian||Note Added: 0007954|
|2012-07-20 11:59||luke-endian||Note Edited: 0007954|
|2012-07-20 12:00||luke-endian||File Added: image001.png|
|2012-07-20 12:01||luke-endian||Note Edited: 0007954|
|2012-07-20 12:01||luke-endian||Tag Attached: purple|
|2012-07-23 14:55||luke-endian||File Deleted: image001.png|
|2012-07-23 14:55||luke-endian||Note Deleted: 0007954|
|Copyright © 2000 - 2012 MantisBT Group|