Não é realmente uma resposta, eu sei, apenas colei minhas configurações na solicitação de OPs.
Configuração do cliente:
remote xxxx.no-ip.info
port 1195
float
# network
dev tun0
ifconfig 192.168.7.98 192.168.7.97
route 192.168.7.64 255.255.255.224 192.168.7.97
route 192.168.7.128 255.255.255.224 192.168.7.97
# symmetrical key
secret /etc/openvpn/scalpel/static.key
# compression
comp-lzo
# Security
user nobody
group nogroup
# high availability options
keepalive 10 30
persist-tun
persist-key
verb 1
mute 2
# Logging
log-append /var/log/openvpn_scalpel.log
Configuração do servidor:
# Scalpel - OpenVPN Server (do lacznosci miedzy oddzialami)
# Last modified 2011.05.22
port 1195
# network
dev tun0
ifconfig 192.168.7.97 192.168.7.98
route 192.168.7.0 255.255.255.192 192.168.7.98
# symmetrical key
secret /etc/openvpn/scalpel/static.key
# compression
comp-lzo
# Security
user nobody
group nogroup
max-clients 1 # maximum number to clients allowed to connect
# high availability options
keepalive 10 30
persist-tun
persist-key
verb 1
mute 2
# Logging
log-append /var/log/openvpn_scalpel.log
Lado do servidor de rastreamento de pacotes:
0.000000 79.184.15.251 -> 192.168.7.66 UDP 102 Source port: 5117 Destination port: 1195
3.834972 192.168.7.66 -> 79.184.15.251 UDP 158 Source port: 1195 Destination port: 5117
3.927502 79.184.15.251 -> 192.168.7.66 UDP 166 Source port: 5117 Destination port: 1195
3.930257 192.168.7.66 -> 79.184.15.251 UDP 158 Source port: 1195 Destination port: 5117
4.022063 79.184.15.251 -> 192.168.7.66 UDP 166 Source port: 5117 Destination port: 1195
8.223466 79.184.15.251 -> 192.168.7.66 UDP 102 Source port: 5117 Destination port: 1195
14.436576 192.168.7.66 -> 79.184.15.251 UDP 102 Source port: 1195 Destination port: 5117
17.929467 79.184.15.251 -> 192.168.7.66 UDP 102 Source port: 5117 Destination port: 1195
17.929594 79.184.15.251 -> 192.168.7.66 UDP 102 Source port: 5117 Destination port: 1195
17.929685 192.168.7.66 -> 79.184.15.251 UDP 238 Source port: 1195 Destination port: 5117
27.989889 192.168.7.66 -> 79.184.15.251 UDP 102 Source port: 1195 Destination port: 5117
28.081743 79.184.15.251 -> 192.168.7.66 UDP 102 Source port: 5117 Destination port: 1195
38.104471 192.168.7.66 -> 79.184.15.251 UDP 102 Source port: 1195 Destination port: 5117
38.207144 79.184.15.251 -> 192.168.7.66 UDP 102 Source port: 5117 Destination port: 1195
44.063394 79.184.15.251 -> 192.168.7.66 UDP 254 Source port: 5117 Destination port: 1195
44.063662 79.184.15.251 -> 192.168.7.66 UDP 214 Source port: 5117 Destination port: 1195
48.249463 192.168.7.66 -> 79.184.15.251 UDP 102 Source port: 1195 Destination port: 5117
54.440786 79.184.15.251 -> 192.168.7.66 UDP 102 Source port: 5117 Destination port: 1195
58.703483 192.168.7.66 -> 79.184.15.251 UDP 102 Source port: 1195 Destination port: 5117
Wed Jul 29 14:40:02 2015 read UDPv4 [ECONNREFUSED]: Connection refused (code=111)
68.715974 192.168.7.66 -> 79.184.15.251 UDP 102 Source port: 1195 Destination port: 5117
Wed Jul 29 14:40:12 2015 NOTE: --mute triggered...
78.984871 192.168.7.66 -> 79.184.15.251 UDP 102 Source port: 1195 Destination port: 5117
Wed Jul 29 14:40:17 2015 1 variation(s) on previous 2 message(s) suppressed by --mute
Wed Jul 29 14:40:17 2015 Inactivity timeout (--ping-restart), restarting
Wed Jul 29 14:40:17 2015 SIGUSR1[soft,ping-restart] received, process restarting
Wed Jul 29 14:40:19 2015 NOTE: OpenVPN 2.1 requires '--script-security 2' or higher to call user-defined scripts or executables
Wed Jul 29 14:40:19 2015 Re-using pre-shared static key
Wed Jul 29 14:40:19 2015 LZO compression initialized
Wed Jul 29 14:40:19 2015 Preserving previous TUN/TAP instance: tun0
Wed Jul 29 14:40:19 2015 UDPv4 link local (bound): [undef]:1195
Wed Jul 29 14:40:19 2015 UDPv4 link remote: [undef]
Wed Jul 29 14:40:32 2015 Peer Connection Initiated with 79.184.15.251:5117
99.482520 79.184.15.251 -> 192.168.7.66 UDP 102 Source port: 5117 Destination port: 1195
Wed Jul 29 14:40:33 2015 Initialization Sequence Completed
106.579960 192.168.7.66 -> 79.184.15.251 UDP 102 Source port: 1195 Destination port: 5117
106.579994 192.168.7.66 -> 79.184.15.251 UDP 102 Source port: 1195 Destination port: 5117
106.671790 79.184.15.251 -> 192.168.7.66 UDP 238 Source port: 5117 Destination port: 1195
110.199108 79.184.15.251 -> 192.168.7.66 UDP 102 Source port: 5117 Destination port: 1195
110.199228 192.168.7.66 -> 79.184.15.251 UDP 238 Source port: 1195 Destination port: 5117
119.683353 79.184.15.251 -> 192.168.7.66 UDP 102 Source port: 5117 Destination port: 1195
120.784617 192.168.7.66 -> 79.184.15.251 UDP 102 Source port: 1195 Destination port: 5117
Lado do cliente de rastreamento de pacotes:
0.000000 192.168.7.2 -> 89.69.145.76 UDP Source port: 1195 Destination port: 1195
2.227622 192.168.7.2 -> 89.69.145.76 UDP Source port: 1195 Destination port: 1195
2.227651 192.168.7.2 -> 89.69.145.76 UDP Source port: 1195 Destination port: 1195
3.566194 89.69.145.76 -> 192.168.7.2 UDP Source port: 1195 Destination port: 1195
11.640422 192.168.7.2 -> 89.69.145.76 UDP Source port: 1195 Destination port: 1195
13.809216 89.69.145.76 -> 192.168.7.2 UDP Source port: 1195 Destination port: 1195
Wed Jul 29 14:43:02 2015 read UDPv4 [ECONNREFUSED]: Connection refused (code=111)
21.876795 192.168.7.2 -> 89.69.145.76 UDP Source port: 1195 Destination port: 1195
Wed Jul 29 14:43:12 2015 read UDPv4 [ECONNREFUSED]: Connection refused (code=111)
32.116168 192.168.7.2 -> 89.69.145.76 UDP Source port: 1195 Destination port: 1195
Wed Jul 29 14:43:22 2015 NOTE: --mute triggered...
42.283532 192.168.7.2 -> 89.69.145.76 UDP Source port: 1195 Destination port: 1195
42.283564 192.168.7.2 -> 89.69.145.76 UDP Source port: 1195 Destination port: 1195
Wed Jul 29 14:43:24 2015 2 variation(s) on previous 2 message(s) suppressed by --mute
Wed Jul 29 14:43:24 2015 Inactivity timeout (--ping-restart), restarting
Wed Jul 29 14:43:24 2015 SIGUSR1[soft,ping-restart] received, process restarting
Wed Jul 29 14:43:26 2015 Re-using pre-shared static key
Wed Jul 29 14:43:26 2015 LZO compression initialized
Wed Jul 29 14:43:27 2015 Preserving previous TUN/TAP instance: tun0
Wed Jul 29 14:43:27 2015 UDPv4 link local (bound): [undef]:1195
Wed Jul 29 14:43:27 2015 UDPv4 link remote: 89.69.145.76:1195
Wed Jul 29 14:43:27 2015 read UDPv4 [ECONNREFUSED]: Connection refused (code=111)
Wed Jul 29 14:43:27 2015 read UDPv4 [ECONNREFUSED]: Connection refused (code=111)
46.575799 192.168.7.2 -> 89.69.145.76 UDP Source port: 1195 Destination port: 1195
46.575822 192.168.7.2 -> 89.69.145.76 UDP Source port: 1195 Destination port: 1195
Wed Jul 29 14:43:31 2015 NOTE: --mute triggered...
51.283850 192.168.7.2 -> 89.69.145.76 UDP Source port: 1195 Destination port: 1195
57.386083 192.168.7.2 -> 89.69.145.76 UDP Source port: 1195 Destination port: 1195
66.606426 192.168.7.2 -> 89.69.145.76 UDP Source port: 1195 Destination port: 1195
66.606450 192.168.7.2 -> 89.69.145.76 UDP Source port: 1195 Destination port: 1195
Wed Jul 29 14:43:58 2015 4 variation(s) on previous 2 message(s) suppressed by --mute
Wed Jul 29 14:43:58 2015 Inactivity timeout (--ping-restart), restarting
Wed Jul 29 14:43:58 2015 SIGUSR1[soft,ping-restart] received, process restarting
79.480353 192.168.7.2 -> 89.69.145.76 UDP Source port: 1195 Destination port: 1195
Wed Jul 29 14:44:00 2015 Re-using pre-shared static key
Wed Jul 29 14:44:00 2015 LZO compression initialized
Wed Jul 29 14:44:00 2015 Preserving previous TUN/TAP instance: tun0
Wed Jul 29 14:44:00 2015 UDPv4 link local (bound): [undef]:1195
Wed Jul 29 14:44:00 2015 UDPv4 link remote: 89.69.145.76:1195
Wed Jul 29 14:44:00 2015 read UDPv4 [ECONNREFUSED]: Connection refused (code=111)
Wed Jul 29 14:44:10 2015 Peer Connection Initiated with 89.69.145.76:1195
89.588295 192.168.7.2 -> 89.69.145.76 UDP Source port: 1195 Destination port: 1195
89.588321 192.168.7.2 -> 89.69.145.76 UDP Source port: 1195 Destination port: 1195
89.680566 89.69.145.76 -> 192.168.7.2 UDP Source port: 1195 Destination port: 1195
Wed Jul 29 14:44:11 2015 Initialization Sequence Completed
92.180902 89.69.145.76 -> 192.168.7.2 UDP Source port: 1195 Destination port: 1195
92.181072 192.168.7.2 -> 89.69.145.76 UDP Source port: 1195 Destination port: 1195
92.405420 89.69.145.76 -> 192.168.7.2 UDP Source port: 1195 Destination port: 1195
92.405643 192.168.7.2 -> 89.69.145.76 UDP Source port: 1195 Destination port: 1195
92.409120 89.69.145.76 -> 192.168.7.2 UDP Source port: 1195 Destination port: 1195
92.409194 192.168.7.2 -> 89.69.145.76 UDP Source port: 1195 Destination port: 1195
92.501167 89.69.145.76 -> 192.168.7.2 UDP Source port: 1195 Destination port: 1195
92.501909 192.168.7.2 -> 89.69.145.76 UDP Source port: 1195 Destination port: 1195
92.504901 89.69.145.76 -> 192.168.7.2 UDP Source port: 1195 Destination port: 1195
92.505027 192.168.7.2 -> 89.69.145.76 UDP Source port: 1195 Destination port: 1195
O cliente e o servidor estão atrás do nat, ambos têm endereços IP públicos dinâmicos. Há também um encaminhamento de porta (1195) no roteador que conecta o servidor ao "Mundo".
Configuração do roteador - lado do servidor:
Configuraçãodoroteador,encaminhamentodeporta-ladodoservidor:
Configuraçãodoroteador-ladodocliente:
Lado do cliente do Conntrack:
udp 17 179 src=192.168.7.2 dst=89.69.145.76 sport=1195 dport=1195 packets=852493 bytes=480026440 src=89.69.145.76 dst=192.168.7.2 sport=1195 dport=1195 packets=1093350 bytes=1226684584 [ASSURED] mark=0 use=1