Den søndag 5.mar kl. 15:56 skrev Sameh Attia:
JonB,
I do appreciate your help.
How about deploying extra LDAP servers? or maybe a caching LDAP
server?
Which LDAP server is it running anyway?
Not available for the time being. They are running OpenLDAP and we
authenticate through it using the --client-connect option.
Also it is a physical problem with the LDAP server. Some
corruptions with the database.
Physical problems are bad, but i think you could easily run a caching
openLDAP.
Why does it re-authenticate?
That is what I am asking indeed. I would like to know.
Did you try increasing the verbosity? with level 5
you can see every time it sends and receives a packet.
Do your clients timeout? => Increase the timeout on
the server.
No. They do not.
Do you clients change ip? => --float
No they do not change IPs. All are PCs logged in to the company's
domain and they are not allowed to change their IPs.
i did not mean the openvpn ip address, i ment the one outside the
tunnel.
Does that change? If that does change use --float
Cheat your clients to think the tunnel is still open. Does the network
interface close when the network breaks down?
I was thinking it is a Windows problem. I tested a Linux client on
different distros and found the same every-two-minutes symptom.
I thought it might be closing the tunnel. I created a shell script
that was running in the background that is testing the tunnel and
the routing table. I found nothing; everything is okay; the tunnel
is there and the routing table is okay.
Here you are the configuration files.
Only the server one made it through the mailing list.
why do you use --duplicate-cn ?
-------------------------------------------------------
This SF.Net email is sponsored by xPML, a groundbreaking scripting language
that extends applications into web and mobile media. Attend the live webcast
and join the prime developer group breaking into this new coding territory!
Openvpn-users mailing list
Openvpn-users@xxxxxxxxxxxxxxxxxxxxx
https://lists.sourceforge.net/lists/listinfo/openvpn-users
|