【问题标题】:start-iap-tunnel unable to connect to a listening portstart-iap-tunnel 无法连接到监听端口
【发布时间】:2022-01-24 20:46:56
【问题描述】:

我正在 Google Cloud 实例上安装 OpenVPN 访问服务器。它的 webUI 使用 https 侦听端口 943。它有一个自签名证书,其名称与服务器的主机名 (10.150.0.2) 不匹配。我无法启动 SSH 隧道。我正在寻找一种方法来解决从 IAP 服务到我的服务器的连接问题。

我正在运行的命令是gcloud compute start-iap-tunnel vpn 943 --local-host-port=localhost:943 我收到正常的Testing if tunnel connection works 消息。

ERROR: (gcloud.compute.start-iap-tunnel) While checking if a connection can be made: Error while connecting [4003: 'failed to connect to backend']. (Failed to connect to port 943) 出错了

如果我将--log-http 添加到命令调用中,则相关信息如下(它看起来像一个正常的请求/响应周期,我假设是从我的客户端到 IAP 服务的 200):

Testing if tunnel connection works.
=======================
==== request start ====
uri: https://oauth2.googleapis.com/token
method: POST
== headers start ==
b'content-type': b'application/x-www-form-urlencoded'
b'user-agent': b'google-cloud-sdk gcloud/367.0.0 command/gcloud.compute.start-iap-tunnel invocation-id/db27de82264f47fcb63f6680afaa8327 environment/None environment-version/None interactive/False from-script/False python/3.7.9 term/xterm-256color (Macintosh; Intel Mac OS X 21.2.0)'
== headers end ==
== body start ==
Body redacted: Contains oauth token. Set log_http_redact_token property to false to print the body of this request.
== body end ==
==== request end ====
---- response start ----
status: 200
-- headers start --
Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000,h3-Q050=":443"; ma=2592000,h3-Q046=":443"; ma=2592000,h3-Q043=":443"; ma=2592000,quic=":443"; ma=2592000; v="46,43"
Cache-Control: no-cache, no-store, max-age=0, must-revalidate
Content-Encoding: gzip
Content-Type: application/json; charset=utf-8
Date: Fri, 24 Dec 2021 02:11:52 GMT
Expires: Mon, 01 Jan 1990 00:00:00 GMT
Pragma: no-cache
Server: scaffolding on HTTPServer2
Transfer-Encoding: chunked
Vary: Origin, X-Origin, Referer
X-Content-Type-Options: nosniff
X-Frame-Options: SAMEORIGIN
X-XSS-Protection: 0
-- headers end --
-- body start --
Body redacted: Contains oauth token. Set log_http_redact_token property to false to print the body of this response.
-- body end --
total round trip time (request+response): 0.246 secs
---- response end ----
----------------------
ERROR: (gcloud.compute.start-iap-tunnel) While checking if a connection can be made: Error while connecting [4003: 'failed to connect to backend']. (Failed to connect to port 943)

据我所知,这是start-tap-tunnel 易于访问的故障排除的限制。

在生成 la 证书之前,我们可以连接到 10.150.0.2:943 的本地计算机。

root@viongier:/usr/local/openvpn_as# wget https://10.150.0.2:943
--2021-12-24 02:01:47--  https://10.150.0.2:943/
Connecting to 10.150.0.2:943... connected.
ERROR: The certificate of ‘10.150.0.2’ is not trusted.
ERROR: The certificate of ‘10.150.0.2’ doesn't have a known issuer.
The certificate's owner does not match hostname ‘10.150.0.2’

在我看来,我的客户端很高兴连接到 IAP 服务,但无法连接到我的服务器。如果由于证书而出错,我希望看到 IAP 错误。我唯一能想到的测试方法是生成一个发行者谷歌喜欢的证书。 (例如 LetsEncrypt。)

【问题讨论】:

    标签: ssl google-cloud-platform openvpn-connect


    【解决方案1】:

    此消息表示后端在侦听状态下没有打开套接字。常见原因是没有启动服务或防火墙阻止了端口。

    要允许 Identity Aware Proxy 进入您的 VPC,请允许来自 35.​​235.240.0/20 的流量。

    错误:(gcloud.compute.start-iap-tunnel)在检查是否有 可以建立连接:连接时出错 [4003: 'failed to 连接到后端']。 (连接943端口失败)

    此错误表示提供的证书与建立连接的地址不匹配:

    错误:“10.150.0.2”的证书不受信任。错误: “10.150.0.2”的证书没有已知的颁发者。这 证书的所有者与主机名“10.150.0.2”不匹配

    某些客户端,例如 wget 支持忽略 SSL 证书验证。对于 wget,请参阅 --no-check-certificate 标志。

    一旦你解决了这个问题,你就会遇到另一组问题:

    1. 在正常情况下,您不能将 HTTPS 与隧道一起使用。隧道是中间人的一种形式。有一些技巧可以使用,但没有一个是安全的。

    2. 商业 SSL 证书不支持 IP 地址,仅支持公共域名。您需要创建自己的自签名证书,该证书不受信任或不验证证书。

    3. 最后一个问题是 HTTPS 端点需要来自客户端的加密协商。 start-iap-tunnel 命令不会启动加密(TLS 协商)。此命令也不进行任何形式的证书交换,这就是您看不到有关证书的 IAP 错误的原因。此命令仅在隧道端点之间传输数据。

    总而言之,如果不部署有悖于 HTTPS 目的的技巧和/或禁用功能,就无法将 HTTPS 与 TCP / SSH 隧道一起使用。

    【讨论】:

    • 很抱歉,您的回答没有回答我的问题,即“如何解决 IAP 服务与我的服务器之间的连接问题”。解决您的问题:是的,没有与后端建立连接,这是问题所在。再一次,是的,证书没有正确签名并且名称不匹配。然而,这向我们展示了在端口 943 上侦听的东西。IAP 隧道是一个 HTTPS 隧道。我的 SSH 隧道将通过它。感谢您提醒我,普遍接受的证书不能绑定到 IP;我忘记了。
    • 您的防火墙规则如何?您必须允许端口 943 上的 IAP 端口范围。
    • @guillaume 我凌晨 3 点起床,并这么想。我确定这就是问题所在。非常感谢!
    【解决方案2】:

    允许 IAP 流量通过防火墙允许我的外部客户端通过 IAP 隧道连接到内部端口 943。

    允许来自 35.235.240.0/20 的端口 943 解决了我的问题。

    更多信息请访问GCP IAP docs

    【讨论】:

      猜你喜欢
      • 2018-03-05
      • 2016-12-13
      • 2013-04-26
      • 2017-11-20
      • 1970-01-01
      • 2015-03-12
      • 1970-01-01
      • 1970-01-01
      • 2021-07-15
      相关资源
      最近更新 更多