Koozali.org: home of the SME Server

sme9 and local network issue

Offline jameswilson

  • *
  • 792
  • +0/-0
    • Security Warehouse, trade security equipment
sme9 and local network issue
« on: September 05, 2023, 01:35:57 PM »
Hi all
One of my last servers i use at home has an issue i have created
I have had a new phone and wanted to add openvpn routed to it all seemed to fo well but after running

Code: [Select]
db configuration setprop openvpn-routed Network 192.168.79.0/255.255.255.0
i lost smaba access and other things
It looks like the server doesnt think the local ip range is local anymore so I dont have all the services i need etc.
I also cant see where to set this.
I tried adding the lan to the local networks settings but it errors saying it is already considered local

Ive tried modifying things in the admin console but doesnt work. VPN bridge still works though and allows samba etc

Offline jameswilson

  • *
  • 792
  • +0/-0
    • Security Warehouse, trade security equipment
Re: sme9 and local network issue
« Reply #1 on: September 05, 2023, 02:00:20 PM »
thinking about it more i may have broken it before that setting change but thats when i noticed.

Offline jameswilson

  • *
  • 792
  • +0/-0
    • Security Warehouse, trade security equipment
Re: sme9 and local network issue
« Reply #2 on: September 05, 2023, 03:32:06 PM »
I also notice on reboot I get this

RNETLINK answers: Network is unreachable

This repeats 7 times

Offline Jean-Philippe Pialasse

  • *
  • 2,907
  • +11/-0
  • aka Unnilennium
    • http://smeserver.pialasse.com
Re: sme9 and local network issue
« Reply #3 on: September 05, 2023, 08:04:29 PM »
it is more than time to upgrade to SME10.
SME 9 is EOL for years.

smeserver-openvpn-routed has recieved some improvements in SME10 so hard to speak about an unsuspected behaviour onr an EOL system

as you upgrade to SME 10 you might enjiy using the smeserver-wireguard contrib if you need vpn for your phone as the configuration will be much more easier  both on the server and on the phone (qr code).

I might emphasize that the Network property should not be you real SME LAN or any other network accessible to your SME or you will break routing table. This should be a dedicated network that is routed via the contrib to your LAN. only reason to change the default is if you already use this one for something else.

Offline jameswilson

  • *
  • 792
  • +0/-0
    • Security Warehouse, trade security equipment
Re: sme9 and local network issue
« Reply #4 on: September 05, 2023, 08:09:19 PM »
I know it has been EOL and that is on me. I have an issue with a website that i cant migrate else all would be on sme 10

however i need to fix this one and i didnt want to just remove the openvpn routed contrib incase that did more harm. Ive learned over the years to stop chnaging when i hit a problem.

If i remove the openvpn routed will it put my routing table back to how it should be?

Offline Jean-Philippe Pialasse

  • *
  • 2,907
  • +11/-0
  • aka Unnilennium
    • http://smeserver.pialasse.com
Re: sme9 and local network issue
« Reply #5 on: September 05, 2023, 08:27:31 PM »
this should.
only content of /etc/openvpn/routed you placed and configuration db entry should remain

Offline jameswilson

  • *
  • 792
  • +0/-0
    • Security Warehouse, trade security equipment
Re: sme9 and local network issue
« Reply #6 on: September 05, 2023, 08:31:07 PM »
so im going to run

Code: [Select]
yum  remove smeserver-openvpn-routed
and cross fingers?

Offline jameswilson

  • *
  • 792
  • +0/-0
    • Security Warehouse, trade security equipment
Re: sme9 and local network issue
« Reply #7 on: September 05, 2023, 09:08:46 PM »
Unfortunatly that hasnt resolved the issue.
THings on the lan are still thought of as not local.

Did the
Quote
yum  remove smeserver-openvpn-routed

then reconfigure and reboot

Offline Jean-Philippe Pialasse

  • *
  • 2,907
  • +11/-0
  • aka Unnilennium
    • http://smeserver.pialasse.com
Re: sme9 and local network issue
« Reply #8 on: September 06, 2023, 12:57:30 AM »
then you will need to tell more about your server and network configuration. 

Offline jameswilson

  • *
  • 792
  • +0/-0
    • Security Warehouse, trade security equipment
Re: sme9 and local network issue
« Reply #9 on: September 06, 2023, 04:25:12 AM »
then you will need to tell more about your server and network configuration.
Thanks JPP
Server gateway with Openvpn bridged and s2s
Did add routed but that has been removed
Other contribs id have to look but webstats, php-scl, and phpki for certs

Offline Jean-Philippe Pialasse

  • *
  • 2,907
  • +11/-0
  • aka Unnilennium
    • http://smeserver.pialasse.com
Re: sme9 and local network issue
« Reply #10 on: September 06, 2023, 05:06:47 AM »
and about the network?

Offline jameswilson

  • *
  • 792
  • +0/-0
    • Security Warehouse, trade security equipment
Re: sme9 and local network issue
« Reply #11 on: September 06, 2023, 01:56:05 PM »
sorry i dont understand what you want to know?

Offline Jean-Philippe Pialasse

  • *
  • 2,907
  • +11/-0
  • aka Unnilennium
    • http://smeserver.pialasse.com
Re: sme9 and local network issue
« Reply #12 on: September 06, 2023, 03:21:04 PM »
well you have network connectivity issue, so if you do not describe your network extensively ( what is on wan side of sme is it a modem or another LAN, what is on LAN side and what is the subnet…  ) you are on you own. 
Also be more precise on what is not working. “THings on the lan are still thought of as not local.” is not specific and is an interpretation, not what you see.

trying to access from lan side of sme to samba i get error x

trying to access from wifi behind another router with another subnet i get http error YYY.

Offline ReetP

  • *
  • 3,940
  • +6/-0
Re: sme9 and local network issue
« Reply #13 on: September 06, 2023, 07:09:47 PM »
I know it has been EOL and that is on me. I have an issue with a website that i cant migrate else all would be on sme 10

Said it before, say it again.

See No. 3 in my sig.

You had years to plan migration, and v10 has been out some while.

With any luck we'll have v11 out later next year. What are you going to do then? Still run your entirely unsecure site on v9?
And what happens when Cent 6/v9 repos get killed off  entirely?

Bite the bullet. Upgrade now.
...
1. Read the Manual
2. Read the Wiki
3. Don't ask for support on Unsupported versions of software
4. I have a job, wife, and kids and do this in my spare time. If you want something fixed, please help.

Bugs are easier than you think: http://wiki.contribs.org/Bugzilla_Help

If you love SME and don't want to lose it, join in: http://wiki.contribs.org/Koozali_Foundation

Offline jameswilson

  • *
  • 792
  • +0/-0
    • Security Warehouse, trade security equipment
Re: sme9 and local network issue
« Reply #14 on: September 08, 2023, 03:45:41 PM »
Quote
See No. 3 in my sig.

Fair enough