Discussion:
[IPCop-user] ROUTE: route addition failed using CreateIpForwardEntry: One or more arguments are not correct
Mark Puck
2007-02-27 23:03:34 UTC
Permalink
Hi,



I'm fairly new to networking software and was hoping someone can clue me in
to why I can connect to IPCop via OpenVPN and use the internet, but not
access the local network. Looks like it has something to do with the ROUTE
command in the log file below. Any ideas on how to fix this?



TIA,



Mark









Tue Feb 27 11:14:58 2007 OpenVPN 2.0.9 Win32-MinGW [SSL] [LZO] built on Oct
1 2006



Tue Feb 27 11:14:58 2007 IMPORTANT: OpenVPN's default port number is now
1194, based on an official port number assignment by IANA. OpenVPN
2.0-beta16 and earlier used 5000 as the default port.



Tue Feb 27 11:15:05 2007 LZO compression initialized



Tue Feb 27 11:15:05 2007 WARNING: normally if you use --mssfix and/or
--fragment, you should also set --tun-mtu 1500 (currently it is 1400)



Tue Feb 27 11:15:05 2007 Control Channel MTU parms [ L:1442 D:138 EF:38 EB:0
ET:0 EL:0 ]



Tue Feb 27 11:15:06 2007 Data Channel MTU parms [ L:1442 D:1442 EF:42 EB:135
ET:0 EL:0 AF:3/1 ]



Tue Feb 27 11:15:06 2007 Local Options hash (VER=V4): 'a6ae7d69'



Tue Feb 27 11:15:06 2007 Expected Remote Options hash (VER=V4): '006a55ce'



Tue Feb 27 11:15:06 2007 UDPv4 link local (bound): [undef]:1194



Tue Feb 27 11:15:06 2007 UDPv4 link remote: 24.148.9.227:1194



Tue Feb 27 11:15:07 2007 TLS: Initial packet from 24.148.9.227:1194,
sid=e70650d4 29ba21e3



Tue Feb 27 11:15:16 2007 VERIFY OK: depth=1,
/C=US/O=SBS/CN=SBS_CA/emailAddress=***@notjustariver.com



Tue Feb 27 11:15:16 2007 VERIFY OK: nsCertType=SERVER



Tue Feb 27 11:15:16 2007 VERIFY OK: depth=0,
/C=US/O=SBS/CN=morecowbell.no-ip.org



Tue Feb 27 11:15:29 2007 Data Channel Encrypt: Cipher 'BF-CBC' initialized
with 128 bit key



Tue Feb 27 11:15:29 2007 Data Channel Encrypt: Using 160 bit message hash
'SHA1' for HMAC authentication



Tue Feb 27 11:15:29 2007 Data Channel Decrypt: Cipher 'BF-CBC' initialized
with 128 bit key



Tue Feb 27 11:15:29 2007 Data Channel Decrypt: Using 160 bit message hash
'SHA1' for HMAC authentication



Tue Feb 27 11:15:29 2007 Control Channel: TLSv1, cipher TLSv1/SSLv3
DHE-RSA-AES256-SHA, 1024 bit RSA



Tue Feb 27 11:15:29 2007 [morecowbell.no-ip.org] Peer Connection Initiated
with 24.148.9.227:1194



Tue Feb 27 11:15:30 2007 SENT CONTROL [morecowbell.no-ip.org]:
'PUSH_REQUEST' (status=1)



Tue Feb 27 11:15:31 2007 PUSH: Received control message: 'PUSH_REPLY,route
192.168.1.0 255.255.255.0,route 10.150.214.1,ifconfig 10.150.214.6
10.150.214.5'



Tue Feb 27 11:15:31 2007 OPTIONS IMPORT: --ifconfig/up options modified



Tue Feb 27 11:15:31 2007 OPTIONS IMPORT: route options modified



Tue Feb 27 11:15:31 2007 TAP-WIN32 device [Local Area Connection 2] opened:
\\.\Global\{C4CAF8B7-F9AC-453A-B781-ED808DA07CE1}.tap



Tue Feb 27 11:15:31 2007 TAP-Win32 Driver Version 8.4



Tue Feb 27 11:15:31 2007 TAP-Win32 MTU=1500



Tue Feb 27 11:15:31 2007 Notified TAP-Win32 driver to set a DHCP IP/netmask
of 10.150.214.6/255.255.255.252 on interface
{C4CAF8B7-F9AC-453A-B781-ED808DA07CE1} [DHCP-serv: 10.150.214.5, lease-time:
31536000]



Tue Feb 27 11:15:31 2007 Successful ARP Flush on interface [12]
{C4CAF8B7-F9AC-453A-B781-ED808DA07CE1}



Tue Feb 27 11:15:31 2007 TEST ROUTES: 2/2 succeeded len=2 ret=1 a=0 u/d=up



Tue Feb 27 11:15:31 2007 route ADD 192.168.1.0 MASK 255.255.255.0
10.150.214.5



Tue Feb 27 11:15:31 2007 ROUTE: route addition failed using
CreateIpForwardEntry: One or more arguments are not correct. [if_index=12]



Tue Feb 27 11:15:31 2007 Route addition via IPAPI failed



Tue Feb 27 11:15:31 2007 route ADD 10.150.214.1 MASK 255.255.255.255
10.150.214.5



Tue Feb 27 11:15:31 2007 ROUTE: route addition failed using
CreateIpForwardEntry: One or more arguments are not correct. [if_index=12]



Tue Feb 27 11:15:31 2007 Route addition via IPAPI failed



Tue Feb 27 11:15:31 2007 Initialization Sequence Completed





---------------------------------------------------------------



One person at on the OpenVPN mailing list suggested it might be a
permissions problem. I'm using the ZERINA-0.9.4g implementation of OpenVPN
on IPCop and there is no means that I can see to configure permissions. I
also tried to execute the statement as root at the command prompt and I
received the following:





login as: root

***@192.168.1.1's password:

Last login: Tue Feb 27 11:32:04 2007 from workstation1.localdomain
***@ipcop:~ # route ADD 10.150.214.1 MASK 255.255.255.255 10.150.214.5

Usage: route [-nNvee] [-FC] [<AF>] List kernel routing tables

route [-v] [-FC] {add|del|flush} ... Modify routing table for AF.



route {-h|--help} [<AF>] Detailed usage syntax for
specified AF.

route {-V|--version} Display version/author and
exit.



-v, --verbose be verbose

-n, --numeric don't resolve names

-e, --extend display other/more information

-F, --fib display Forwarding Information Base
(default)

-C, --cache display routing cache instead of FIB



<AF>=Use '-A <af>' or '--<af>'; default: inet

List of possible address families (which support routing):

inet (DARPA Internet)

***@ipcop:~ #
Jonathan Larsen
2007-02-28 07:03:51 UTC
Permalink
i did a quick google search for the error you were getting

Route addition via IPAPI failed

and came up with a whole lot of goodies.
i suggest that you go to openvpn forums and search for that. here's a few
pages i found.

http://openvpn.se/bb/viewtopic.php?t=911
http://openvpn.se/bb/viewtopic.php?t=419&sid=0a27d8dbcc0f226a322a050cb8288bb1

hope this helps... i've never used openvpn before but this is where i would
start.
Post by Mark Puck
Hi,
I'm fairly new to networking software and was hoping someone can clue me in
to why I can connect to IPCop via OpenVPN and use the internet, but not
access the local network. Looks like it has something to do with the ROUTE
command in the log file below. Any ideas on how to fix this?
TIA,
Mark
Tue Feb 27 11:14:58 2007 OpenVPN 2.0.9 Win32-MinGW [SSL] [LZO] built on Oct
1 2006
Tue Feb 27 11:14:58 2007 IMPORTANT: OpenVPN's default port number is now
1194, based on an official port number assignment by IANA. OpenVPN
2.0-beta16 and earlier used 5000 as the default port.
Tue Feb 27 11:15:05 2007 LZO compression initialized
Tue Feb 27 11:15:05 2007 WARNING: normally if you use --mssfix and/or
--fragment, you should also set --tun-mtu 1500 (currently it is 1400)
Tue Feb 27 11:15:05 2007 Control Channel MTU parms [ L:1442 D:138 EF:38 EB:0
ET:0 EL:0 ]
Tue Feb 27 11:15:06 2007 Data Channel MTU parms [ L:1442 D:1442 EF:42 EB:135
ET:0 EL:0 AF:3/1 ]
Tue Feb 27 11:15:06 2007 Local Options hash (VER=V4): 'a6ae7d69'
Tue Feb 27 11:15:06 2007 Expected Remote Options hash (VER=V4): '006a55ce'
Tue Feb 27 11:15:06 2007 UDPv4 link local (bound): [undef]:1194
Tue Feb 27 11:15:06 2007 UDPv4 link remote: 24.148.9.227:1194
Tue Feb 27 11:15:07 2007 TLS: Initial packet from 24.148.9.227:1194,
sid=e70650d4 29ba21e3
Tue Feb 27 11:15:16 2007 VERIFY OK: depth=1,
Tue Feb 27 11:15:16 2007 VERIFY OK: nsCertType=SERVER
Tue Feb 27 11:15:16 2007 VERIFY OK: depth=0,
/C=US/O=SBS/CN=morecowbell.no-ip.org
Tue Feb 27 11:15:29 2007 Data Channel Encrypt: Cipher 'BF-CBC' initialized
with 128 bit key
Tue Feb 27 11:15:29 2007 Data Channel Encrypt: Using 160 bit message hash
'SHA1' for HMAC authentication
Tue Feb 27 11:15:29 2007 Data Channel Decrypt: Cipher 'BF-CBC' initialized
with 128 bit key
Tue Feb 27 11:15:29 2007 Data Channel Decrypt: Using 160 bit message hash
'SHA1' for HMAC authentication
Tue Feb 27 11:15:29 2007 Control Channel: TLSv1, cipher TLSv1/SSLv3
DHE-RSA-AES256-SHA, 1024 bit RSA
Tue Feb 27 11:15:29 2007 [morecowbell.no-ip.org] Peer Connection Initiated
with 24.148.9.227:1194
'PUSH_REQUEST' (status=1)
Tue Feb 27 11:15:31 2007 PUSH: Received control message: 'PUSH_REPLY,route
192.168.1.0 255.255.255.0,route 10.150.214.1,ifconfig 10.150.214.6
10.150.214.5'
Tue Feb 27 11:15:31 2007 OPTIONS IMPORT: --ifconfig/up options modified
Tue Feb 27 11:15:31 2007 OPTIONS IMPORT: route options modified
\\.\Global\{C4CAF8B7-F9AC-453A-B781-ED808DA07CE1}.tap
Tue Feb 27 11:15:31 2007 TAP-Win32 Driver Version 8.4
Tue Feb 27 11:15:31 2007 TAP-Win32 MTU=1500
Tue Feb 27 11:15:31 2007 Notified TAP-Win32 driver to set a DHCP IP/netmask
of 10.150.214.6/255.255.255.252 on interface
31536000]
Tue Feb 27 11:15:31 2007 Successful ARP Flush on interface [12]
{C4CAF8B7-F9AC-453A-B781-ED808DA07CE1}
Tue Feb 27 11:15:31 2007 TEST ROUTES: 2/2 succeeded len=2 ret=1 a=0 u/d=up
Tue Feb 27 11:15:31 2007 route ADD 192.168.1.0 MASK 255.255.255.0
10.150.214.5
Tue Feb 27 11:15:31 2007 ROUTE: route addition failed using
CreateIpForwardEntry: One or more arguments are not correct.
[if_index=12]
Tue Feb 27 11:15:31 2007 Route addition via IPAPI failed
Tue Feb 27 11:15:31 2007 route ADD 10.150.214.1 MASK 255.255.255.255
10.150.214.5
Tue Feb 27 11:15:31 2007 ROUTE: route addition failed using
CreateIpForwardEntry: One or more arguments are not correct.
[if_index=12]
Tue Feb 27 11:15:31 2007 Route addition via IPAPI failed
Tue Feb 27 11:15:31 2007 Initialization Sequence Completed
---------------------------------------------------------------
One person at on the OpenVPN mailing list suggested it might be a
permissions problem. I'm using the ZERINA-0.9.4g implementation of OpenVPN
on IPCop and there is no means that I can see to configure permissions. I
also tried to execute the statement as root at the command prompt and I
login as: root
Last login: Tue Feb 27 11:32:04 2007 from workstation1.localdomain
Usage: route [-nNvee] [-FC] [<AF>] List kernel routing tables
route [-v] [-FC] {add|del|flush} ... Modify routing table for AF.
route {-h|--help} [<AF>] Detailed usage syntax for
specified AF.
route {-V|--version} Display version/author and
exit.
-v, --verbose be verbose
-n, --numeric don't resolve names
-e, --extend display other/more information
-F, --fib display Forwarding Information Base
(default)
-C, --cache display routing cache instead of FIB
<AF>=Use '-A <af>' or '--<af>'; default: inet
inet (DARPA Internet)
-------------------------------------------------------------------------
Take Surveys. Earn Cash. Influence the Future of IT
Join SourceForge.net's Techsay panel and you'll get the chance to share
your
opinions on IT & business topics through brief surveys-and earn cash
http://www.techsay.com/default.php?page=join.php&p=sourceforge&CID=DEVDEV
_______________________________________________
IPCop-user mailing list
https://lists.sourceforge.net/lists/listinfo/ipcop-user
Loading...