Thanks.
I added -sha512 because i've read that sha512 is more efficient on x64 enviroment and i've used PKCS12 but without pem files. Is that a good idea?
Before i gave the same certificate to all client so the server didn't recognize each client as different client and gave to all the same ip. Now it gives different ip to each other and the connection between my remote and my openvpn server it's working but not from my server and my openvpn server.
Also it dosen't work with comp-lzo enabled on the client side even if it's enabled on the server.
If i start the openvpn client on my server i will lose connection and it will start to be unstable even after i stop the openvpn on my router, to restore i need to reboot the server.
Client log (server same network as openvpn server)
hu Apr 19 13:50:24 2018 us=517604 WARNING: file '/etc/openvpn/client/my-client2.p12' is group or others access ible
Thu Apr 19 13:50:24 2018 us=517652 Current Parameter Settings:
Thu Apr 19 13:50:24 2018 us=517660 config = '/etc/openvpn/client/client.conf'
Thu Apr 19 13:50:24 2018 us=517667 mode = 0
Thu Apr 19 13:50:24 2018 us=517672 persist_config = DISABLED
Thu Apr 19 13:50:24 2018 us=517683 persist_mode = 1
Thu Apr 19 13:50:24 2018 us=517694 show_ciphers = DISABLED
Thu Apr 19 13:50:24 2018 us=517705 show_digests = DISABLED
Thu Apr 19 13:50:24 2018 us=517715 show_engines = DISABLED
Thu Apr 19 13:50:24 2018 us=517725 genkey = DISABLED
Thu Apr 19 13:50:24 2018 us=517735 key_pass_file = '[UNDEF]'
Thu Apr 19 13:50:24 2018 us=517744 show_tls_ciphers = DISABLED
Thu Apr 19 13:50:24 2018 us=517754 connect_retry_max = 0
Thu Apr 19 13:50:24 2018 us=517763 Connection profiles [0]:
Thu Apr 19 13:50:24 2018 us=517773 proto = udp
Thu Apr 19 13:50:24 2018 us=517782 local = '[UNDEF]'
Thu Apr 19 13:50:24 2018 us=517790 local_port = '[UNDEF]'
Thu Apr 19 13:50:24 2018 us=517807 remote = '192.168.1.1'
Thu Apr 19 13:50:24 2018 us=517817 remote_port = '5000'
Thu Apr 19 13:50:24 2018 us=517826 remote_float = ENABLED
Thu Apr 19 13:50:24 2018 us=517834 bind_defined = DISABLED
Thu Apr 19 13:50:24 2018 us=517843 bind_local = DISABLED
Thu Apr 19 13:50:24 2018 us=517858 bind_ipv6_only = DISABLED
Thu Apr 19 13:50:24 2018 us=517868 connect_retry_seconds = 5
Thu Apr 19 13:50:24 2018 us=517877 connect_timeout = 120
Thu Apr 19 13:50:24 2018 us=517886 socks_proxy_server = '[UNDEF]'
Thu Apr 19 13:50:24 2018 us=517895 socks_proxy_port = '[UNDEF]'
Thu Apr 19 13:50:24 2018 us=517909 tun_mtu = 48000
Thu Apr 19 13:50:24 2018 us=517917 tun_mtu_defined = ENABLED
Thu Apr 19 13:50:24 2018 us=517926 link_mtu = 1500
Thu Apr 19 13:50:24 2018 us=517935 link_mtu_defined = DISABLED
Thu Apr 19 13:50:24 2018 us=517944 tun_mtu_extra = 0
Thu Apr 19 13:50:24 2018 us=517952 tun_mtu_extra_defined = DISABLED
Thu Apr 19 13:50:24 2018 us=517966 mtu_discover_type = -1
Thu Apr 19 13:50:24 2018 us=517975 fragment = 0
Thu Apr 19 13:50:24 2018 us=517984 mssfix = 0
Thu Apr 19 13:50:24 2018 us=517993 explicit_exit_notification = 0
Thu Apr 19 13:50:24 2018 us=518002 Connection profiles END
Thu Apr 19 13:50:24 2018 us=518017 remote_random = DISABLED
Thu Apr 19 13:50:24 2018 us=518026 ipchange = '[UNDEF]'
Thu Apr 19 13:50:24 2018 us=518034 dev = 'tun'
Thu Apr 19 13:50:24 2018 us=518043 dev_type = '[UNDEF]'
Thu Apr 19 13:50:24 2018 us=518052 dev_node = '[UNDEF]'
Thu Apr 19 13:50:24 2018 us=518061 lladdr = '[UNDEF]'
Thu Apr 19 13:50:24 2018 us=518074 topology = 1
Thu Apr 19 13:50:24 2018 us=518084 ifconfig_local = '[UNDEF]'
Thu Apr 19 13:50:24 2018 us=518092 ifconfig_remote_netmask = '[UNDEF]'
Thu Apr 19 13:50:24 2018 us=518101 ifconfig_noexec = DISABLED
Thu Apr 19 13:50:24 2018 us=518110 ifconfig_nowarn = DISABLED
Thu Apr 19 13:50:24 2018 us=518124 ifconfig_ipv6_local = '[UNDEF]'
Thu Apr 19 13:50:24 2018 us=518133 ifconfig_ipv6_netbits = 0
Thu Apr 19 13:50:24 2018 us=518142 ifconfig_ipv6_remote = '[UNDEF]'
Thu Apr 19 13:50:24 2018 us=518151 shaper = 0
Thu Apr 19 13:50:24 2018 us=518160 mtu_test = 0
Thu Apr 19 13:50:24 2018 us=518169 mlock = DISABLED
Thu Apr 19 13:50:24 2018 us=518177 keepalive_ping = 0
Thu Apr 19 13:50:24 2018 us=518186 keepalive_timeout = 0
Thu Apr 19 13:50:24 2018 us=518195 inactivity_timeout = 0
Thu Apr 19 13:50:24 2018 us=518204 ping_send_timeout = 0
Thu Apr 19 13:50:24 2018 us=518213 ping_rec_timeout = 0
Thu Apr 19 13:50:24 2018 us=518221 ping_rec_timeout_action = 0
Thu Apr 19 13:50:24 2018 us=518230 ping_timer_remote = DISABLED
Thu Apr 19 13:50:24 2018 us=518239 remap_sigusr1 = 0
Thu Apr 19 13:50:24 2018 us=518248 persist_tun = ENABLED
Thu Apr 19 13:50:24 2018 us=518256 persist_local_ip = DISABLED
Thu Apr 19 13:50:24 2018 us=518265 persist_remote_ip = DISABLED
Thu Apr 19 13:50:24 2018 us=518274 persist_key = ENABLED
Thu Apr 19 13:50:24 2018 us=518282 passtos = DISABLED
Thu Apr 19 13:50:24 2018 us=518291 resolve_retry_seconds = 1000000000
Thu Apr 19 13:50:24 2018 us=518300 resolve_in_advance = DISABLED
Thu Apr 19 13:50:24 2018 us=518309 username = '[UNDEF]'
Thu Apr 19 13:50:24 2018 us=518318 groupname = '[UNDEF]'
Thu Apr 19 13:50:24 2018 us=518327 chroot_dir = '[UNDEF]'
Thu Apr 19 13:50:24 2018 us=518335 cd_dir = '[UNDEF]'
Thu Apr 19 13:50:24 2018 us=518344 writepid = '[UNDEF]'
Thu Apr 19 13:50:24 2018 us=518353 up_script = '[UNDEF]'
Thu Apr 19 13:50:24 2018 us=518362 down_script = '[UNDEF]'
Thu Apr 19 13:50:24 2018 us=518370 down_pre = DISABLED
Thu Apr 19 13:50:24 2018 us=518379 up_restart = DISABLED
Thu Apr 19 13:50:24 2018 us=518388 up_delay = DISABLED
Thu Apr 19 13:50:24 2018 us=518396 daemon = DISABLED
Thu Apr 19 13:50:24 2018 us=518405 inetd = 0
Thu Apr 19 13:50:24 2018 us=518414 log = DISABLED
Thu Apr 19 13:50:24 2018 us=518423 suppress_timestamps = DISABLED
Thu Apr 19 13:50:24 2018 us=518431 machine_readable_output = DISABLED
Thu Apr 19 13:50:24 2018 us=518440 nice = 0
Thu Apr 19 13:50:24 2018 us=518449 verbosity = 5
Thu Apr 19 13:50:24 2018 us=518458 mute = 0
Thu Apr 19 13:50:24 2018 us=518466 gremlin = 0
Thu Apr 19 13:50:24 2018 us=518475 status_file = '[UNDEF]'
Thu Apr 19 13:50:24 2018 us=518484 status_file_version = 1
Thu Apr 19 13:50:24 2018 us=518493 status_file_update_freq = 60
Thu Apr 19 13:50:24 2018 us=518501 occ = ENABLED
Thu Apr 19 13:50:24 2018 us=518510 rcvbuf = 0
Thu Apr 19 13:50:24 2018 us=518519 sndbuf = 0
Thu Apr 19 13:50:24 2018 us=518527 mark = 0
Thu Apr 19 13:50:24 2018 us=518536 sockflags = 0
Thu Apr 19 13:50:24 2018 us=518545 fast_io = DISABLED
Thu Apr 19 13:50:24 2018 us=518553 comp.alg = 0
Thu Apr 19 13:50:24 2018 us=518562 comp.flags = 0
Thu Apr 19 13:50:24 2018 us=518571 route_script = '[UNDEF]'
Thu Apr 19 13:50:24 2018 us=518580 route_default_gateway = '[UNDEF]'
Thu Apr 19 13:50:24 2018 us=518589 route_default_metric = 0
Thu Apr 19 13:50:24 2018 us=518597 route_noexec = DISABLED
Thu Apr 19 13:50:24 2018 us=518606 route_delay = 0
Thu Apr 19 13:50:24 2018 us=518615 route_delay_window = 30
Thu Apr 19 13:50:24 2018 us=518624 route_delay_defined = DISABLED
Thu Apr 19 13:50:24 2018 us=518633 route_nopull = DISABLED
Thu Apr 19 13:50:24 2018 us=518641 route_gateway_via_dhcp = DISABLED
Thu Apr 19 13:50:24 2018 us=518651 allow_pull_fqdn = DISABLED
Thu Apr 19 13:50:24 2018 us=518660 management_addr = '[UNDEF]'
Thu Apr 19 13:50:24 2018 us=518669 management_port = '[UNDEF]'
Thu Apr 19 13:50:24 2018 us=518677 management_user_pass = '[UNDEF]'
Thu Apr 19 13:50:24 2018 us=518686 management_log_history_cache = 250
Thu Apr 19 13:50:24 2018 us=518695 management_echo_buffer_size = 100
Thu Apr 19 13:50:24 2018 us=518704 management_write_peer_info_file = '[UNDEF]'
Thu Apr 19 13:50:24 2018 us=518713 management_client_user = '[UNDEF]'
Thu Apr 19 13:50:24 2018 us=518722 management_client_group = '[UNDEF]'
Thu Apr 19 13:50:24 2018 us=518731 management_flags = 0
Thu Apr 19 13:50:24 2018 us=518740 shared_secret_file = '[UNDEF]'
Thu Apr 19 13:50:24 2018 us=518749 key_direction = 1
Thu Apr 19 13:50:24 2018 us=518758 ciphername = 'AES-256-CBC'
Thu Apr 19 13:50:24 2018 us=518767 ncp_enabled = ENABLED
Thu Apr 19 13:50:24 2018 us=518776 ncp_ciphers = 'AES-256-GCM:AES-128-GCM'
Thu Apr 19 13:50:24 2018 us=518784 authname = 'SHA512'
Thu Apr 19 13:50:24 2018 us=518793 prng_hash = 'SHA1'
Thu Apr 19 13:50:24 2018 us=518803 prng_nonce_secret_len = 16
Thu Apr 19 13:50:24 2018 us=518812 keysize = 0
Thu Apr 19 13:50:24 2018 us=518821 engine = DISABLED
Thu Apr 19 13:50:24 2018 us=518830 replay = ENABLED
Thu Apr 19 13:50:24 2018 us=518839 mute_replay_warnings = DISABLED
Thu Apr 19 13:50:24 2018 us=518848 replay_window = 64
Thu Apr 19 13:50:24 2018 us=518856 replay_time = 15
Thu Apr 19 13:50:24 2018 us=518865 packet_id_file = '[UNDEF]'
Thu Apr 19 13:50:24 2018 us=518874 use_iv = ENABLED
Thu Apr 19 13:50:24 2018 us=518883 test_crypto = DISABLED
Thu Apr 19 13:50:24 2018 us=518892 tls_server = DISABLED
Thu Apr 19 13:50:24 2018 us=518901 tls_client = ENABLED
Thu Apr 19 13:50:24 2018 us=518909 key_method = 2
Thu Apr 19 13:50:24 2018 us=518918 ca_file = '[UNDEF]'
Thu Apr 19 13:50:24 2018 us=518927 ca_path = '[UNDEF]'
Thu Apr 19 13:50:24 2018 us=518936 dh_file = '[UNDEF]'
Thu Apr 19 13:50:24 2018 us=518945 cert_file = '[UNDEF]'
Thu Apr 19 13:50:24 2018 us=518954 extra_certs_file = '[UNDEF]'
Thu Apr 19 13:50:24 2018 us=518963 priv_key_file = '[UNDEF]'
Thu Apr 19 13:50:24 2018 us=518972 pkcs12_file = '/etc/openvpn/client/my-client2.p12'
Thu Apr 19 13:50:24 2018 us=518981 cipher_list = '[UNDEF]'
Thu Apr 19 13:50:24 2018 us=518990 tls_cert_profile = '[UNDEF]'
Thu Apr 19 13:50:24 2018 us=518999 tls_verify = '[UNDEF]'
Thu Apr 19 13:50:24 2018 us=519008 tls_export_cert = '[UNDEF]'
Thu Apr 19 13:50:24 2018 us=519017 verify_x509_type = 0
Thu Apr 19 13:50:24 2018 us=519025 verify_x509_name = '[UNDEF]'
Thu Apr 19 13:50:24 2018 us=519034 crl_file = '[UNDEF]'
Thu Apr 19 13:50:24 2018 us=519043 ns_cert_type = 0
Thu Apr 19 13:50:24 2018 us=519052 remote_cert_ku[i] = 0
Thu Apr 19 13:50:24 2018 us=519061 remote_cert_ku[i] = 0
Thu Apr 19 13:50:24 2018 us=519069 remote_cert_ku[i] = 0
Thu Apr 19 13:50:24 2018 us=519078 remote_cert_ku[i] = 0
Thu Apr 19 13:50:24 2018 us=519087 remote_cert_ku[i] = 0
Thu Apr 19 13:50:24 2018 us=519096 remote_cert_ku[i] = 0
Thu Apr 19 13:50:24 2018 us=519104 remote_cert_ku[i] = 0
Thu Apr 19 13:50:24 2018 us=519113 remote_cert_ku[i] = 0
Thu Apr 19 13:50:24 2018 us=519122 remote_cert_ku[i] = 0
Thu Apr 19 13:50:24 2018 us=519130 remote_cert_ku[i] = 0
Thu Apr 19 13:50:24 2018 us=519140 remote_cert_ku[i] = 0
Thu Apr 19 13:50:24 2018 us=519148 remote_cert_ku[i] = 0
Thu Apr 19 13:50:24 2018 us=519157 remote_cert_ku[i] = 0
Thu Apr 19 13:50:24 2018 us=519166 remote_cert_ku[i] = 0
Thu Apr 19 13:50:24 2018 us=519174 remote_cert_ku[i] = 0
Thu Apr 19 13:50:24 2018 us=519183 remote_cert_ku[i] = 0
Thu Apr 19 13:50:24 2018 us=519192 remote_cert_eku = 'TLS Web Server Authentication'
Thu Apr 19 13:50:24 2018 us=519201 ssl_flags = 192
Thu Apr 19 13:50:24 2018 us=519210 tls_timeout = 2
Thu Apr 19 13:50:24 2018 us=519219 renegotiate_bytes = -1
Thu Apr 19 13:50:24 2018 us=519228 renegotiate_packets = 0
Thu Apr 19 13:50:24 2018 us=519236 renegotiate_seconds = 3600
Thu Apr 19 13:50:24 2018 us=519245 handshake_window = 60
Thu Apr 19 13:50:24 2018 us=519254 transition_window = 3600
Thu Apr 19 13:50:24 2018 us=519263 single_session = DISABLED
Thu Apr 19 13:50:24 2018 us=519272 push_peer_info = DISABLED
Thu Apr 19 13:50:24 2018 us=519281 tls_exit = DISABLED
Thu Apr 19 13:50:24 2018 us=519289 tls_auth_file = '[[INLINE]]'
Thu Apr 19 13:50:24 2018 us=519298 tls_crypt_file = '[UNDEF]'
Thu Apr 19 13:50:24 2018 us=519307 pkcs11_protected_authentication = DISABLED
Thu Apr 19 13:50:24 2018 us=519316 pkcs11_protected_authentication = DISABLED
Thu Apr 19 13:50:24 2018 us=519325 pkcs11_protected_authentication = DISABLED
Thu Apr 19 13:50:24 2018 us=519333 pkcs11_protected_authentication = DISABLED
Thu Apr 19 13:50:24 2018 us=519342 pkcs11_protected_authentication = DISABLED
Thu Apr 19 13:50:24 2018 us=519352 pkcs11_protected_authentication = DISABLED
Thu Apr 19 13:50:24 2018 us=519361 pkcs11_protected_authentication = DISABLED
Thu Apr 19 13:50:24 2018 us=519370 pkcs11_protected_authentication = DISABLED
Thu Apr 19 13:50:24 2018 us=519378 pkcs11_protected_authentication = DISABLED
Thu Apr 19 13:50:24 2018 us=519387 pkcs11_protected_authentication = DISABLED
Thu Apr 19 13:50:24 2018 us=519396 pkcs11_protected_authentication = DISABLED
Thu Apr 19 13:50:24 2018 us=519405 pkcs11_protected_authentication = DISABLED
Thu Apr 19 13:50:24 2018 us=519414 pkcs11_protected_authentication = DISABLED
Thu Apr 19 13:50:24 2018 us=519423 pkcs11_protected_authentication = DISABLED
Thu Apr 19 13:50:24 2018 us=519431 pkcs11_protected_authentication = DISABLED
Thu Apr 19 13:50:24 2018 us=519440 pkcs11_protected_authentication = DISABLED
Thu Apr 19 13:50:24 2018 us=519450 pkcs11_private_mode = 00000000
Thu Apr 19 13:50:24 2018 us=519459 pkcs11_private_mode = 00000000
Thu Apr 19 13:50:24 2018 us=519468 pkcs11_private_mode = 00000000
Thu Apr 19 13:50:24 2018 us=519477 pkcs11_private_mode = 00000000
Thu Apr 19 13:50:24 2018 us=519485 pkcs11_private_mode = 00000000
Thu Apr 19 13:50:24 2018 us=519494 pkcs11_private_mode = 00000000
Thu Apr 19 13:50:24 2018 us=519503 pkcs11_private_mode = 00000000
Thu Apr 19 13:50:24 2018 us=519512 pkcs11_private_mode = 00000000
Thu Apr 19 13:50:24 2018 us=519520 pkcs11_private_mode = 00000000
Thu Apr 19 13:50:24 2018 us=519529 pkcs11_private_mode = 00000000
Thu Apr 19 13:50:24 2018 us=519538 pkcs11_private_mode = 00000000
Thu Apr 19 13:50:24 2018 us=519547 pkcs11_private_mode = 00000000
Thu Apr 19 13:50:24 2018 us=519556 pkcs11_private_mode = 00000000
Thu Apr 19 13:50:24 2018 us=519565 pkcs11_private_mode = 00000000
Thu Apr 19 13:50:24 2018 us=519573 pkcs11_private_mode = 00000000
Thu Apr 19 13:50:24 2018 us=519582 pkcs11_private_mode = 00000000
Thu Apr 19 13:50:24 2018 us=519591 pkcs11_cert_private = DISABLED
Thu Apr 19 13:50:24 2018 us=519600 pkcs11_cert_private = DISABLED
Thu Apr 19 13:50:24 2018 us=519608 pkcs11_cert_private = DISABLED
Thu Apr 19 13:50:24 2018 us=519617 pkcs11_cert_private = DISABLED
Thu Apr 19 13:50:24 2018 us=519626 pkcs11_cert_private = DISABLED
Thu Apr 19 13:50:24 2018 us=519635 pkcs11_cert_private = DISABLED
Thu Apr 19 13:50:24 2018 us=519643 pkcs11_cert_private = DISABLED
Thu Apr 19 13:50:24 2018 us=519652 pkcs11_cert_private = DISABLED
Thu Apr 19 13:50:24 2018 us=519661 pkcs11_cert_private = DISABLED
Thu Apr 19 13:50:24 2018 us=519670 pkcs11_cert_private = DISABLED
Thu Apr 19 13:50:24 2018 us=519678 pkcs11_cert_private = DISABLED
Thu Apr 19 13:50:24 2018 us=519687 pkcs11_cert_private = DISABLED
Thu Apr 19 13:50:24 2018 us=519696 pkcs11_cert_private = DISABLED
Thu Apr 19 13:50:24 2018 us=519704 pkcs11_cert_private = DISABLED
Thu Apr 19 13:50:24 2018 us=519713 pkcs11_cert_private = DISABLED
Thu Apr 19 13:50:24 2018 us=519722 pkcs11_cert_private = DISABLED
Thu Apr 19 13:50:24 2018 us=519731 pkcs11_pin_cache_period = -1
Thu Apr 19 13:50:24 2018 us=519740 pkcs11_id = '[UNDEF]'
Thu Apr 19 13:50:24 2018 us=519749 pkcs11_id_management = DISABLED
Thu Apr 19 13:50:24 2018 us=519760 server_network = 0.0.0.0
Thu Apr 19 13:50:24 2018 us=519769 server_netmask = 0.0.0.0
Thu Apr 19 13:50:24 2018 us=519783 server_network_ipv6 = ::
Thu Apr 19 13:50:24 2018 us=519792 server_netbits_ipv6 = 0
Thu Apr 19 13:50:24 2018 us=519802 server_bridge_ip = 0.0.0.0
Thu Apr 19 13:50:24 2018 us=519811 server_bridge_netmask = 0.0.0.0
Thu Apr 19 13:50:24 2018 us=519821 server_bridge_pool_start = 0.0.0.0
Thu Apr 19 13:50:24 2018 us=519831 server_bridge_pool_end = 0.0.0.0
Thu Apr 19 13:50:24 2018 us=519839 ifconfig_pool_defined = DISABLED
Thu Apr 19 13:50:24 2018 us=519849 ifconfig_pool_start = 0.0.0.0
Thu Apr 19 13:50:24 2018 us=519859 ifconfig_pool_end = 0.0.0.0
Thu Apr 19 13:50:24 2018 us=519868 ifconfig_pool_netmask = 0.0.0.0
Thu Apr 19 13:50:24 2018 us=519877 ifconfig_pool_persist_filename = '[UNDEF]'
Thu Apr 19 13:50:24 2018 us=519886 ifconfig_pool_persist_refresh_freq = 600
Thu Apr 19 13:50:24 2018 us=519895 ifconfig_ipv6_pool_defined = DISABLED
Thu Apr 19 13:50:24 2018 us=519905 ifconfig_ipv6_pool_base = ::
Thu Apr 19 13:50:24 2018 us=519914 ifconfig_ipv6_pool_netbits = 0
Thu Apr 19 13:50:24 2018 us=519923 n_bcast_buf = 256
Thu Apr 19 13:50:24 2018 us=519932 tcp_queue_limit = 64
Thu Apr 19 13:50:24 2018 us=519941 real_hash_size = 256
Thu Apr 19 13:50:24 2018 us=519950 virtual_hash_size = 256
Thu Apr 19 13:50:24 2018 us=519959 client_connect_script = '[UNDEF]'
Thu Apr 19 13:50:24 2018 us=519968 learn_address_script = '[UNDEF]'
Thu Apr 19 13:50:24 2018 us=519991 client_disconnect_script = '[UNDEF]'
Thu Apr 19 13:50:24 2018 us=520003 client_config_dir = '[UNDEF]'
Thu Apr 19 13:50:24 2018 us=520012 ccd_exclusive = DISABLED
Thu Apr 19 13:50:24 2018 us=520021 tmp_dir = '/tmp'
Thu Apr 19 13:50:24 2018 us=520030 push_ifconfig_defined = DISABLED
Thu Apr 19 13:50:24 2018 us=520040 push_ifconfig_local = 0.0.0.0
Thu Apr 19 13:50:24 2018 us=520050 push_ifconfig_remote_netmask = 0.0.0.0
Thu Apr 19 13:50:24 2018 us=520059 push_ifconfig_ipv6_defined = DISABLED
Thu Apr 19 13:50:24 2018 us=520068 push_ifconfig_ipv6_local = ::/0
Thu Apr 19 13:50:24 2018 us=520078 push_ifconfig_ipv6_remote = ::
Thu Apr 19 13:50:24 2018 us=520086 enable_c2c = DISABLED
Thu Apr 19 13:50:24 2018 us=520095 duplicate_cn = DISABLED
Thu Apr 19 13:50:24 2018 us=520104 cf_max = 0
Thu Apr 19 13:50:24 2018 us=520113 cf_per = 0
Thu Apr 19 13:50:24 2018 us=520122 max_clients = 1024
Thu Apr 19 13:50:24 2018 us=520131 max_routes_per_client = 256
Thu Apr 19 13:50:24 2018 us=520140 auth_user_pass_verify_script = '[UNDEF]'
Thu Apr 19 13:50:24 2018 us=520149 auth_user_pass_verify_script_via_file = DISABLED
Thu Apr 19 13:50:24 2018 us=520158 auth_token_generate = DISABLED
Thu Apr 19 13:50:24 2018 us=520167 auth_token_lifetime = 0
Thu Apr 19 13:50:24 2018 us=520176 port_share_host = '[UNDEF]'
Thu Apr 19 13:50:24 2018 us=520185 port_share_port = '[UNDEF]'
Thu Apr 19 13:50:24 2018 us=520194 client = ENABLED
Thu Apr 19 13:50:24 2018 us=520202 pull = ENABLED
Thu Apr 19 13:50:24 2018 us=520211 auth_user_pass_file = '[UNDEF]'
Thu Apr 19 13:50:24 2018 us=520222 OpenVPN 2.4.5 x86_64-pc-linux-gnu [SSL (OpenSSL)] [LZO] [LZ4] [EPOLL] [PKCS1 1] [MH/PKTINFO] [AEAD] built on Mar 1 2018
Thu Apr 19 13:50:24 2018 us=520238 library versions: OpenSSL 1.1.0h 27 Mar 2018, LZO 2.10
Thu Apr 19 13:50:24 2018 us=530437 Outgoing Control Channel Authentication: Using 512 bit message hash 'SHA512' for HMAC authentication
Thu Apr 19 13:50:24 2018 us=530472 Incoming Control Channel Authentication: Using 512 bit message hash 'SHA512' for HMAC authentication
Thu Apr 19 13:50:24 2018 us=531536 Control Channel MTU parms [ L:48121 D:1140 EF:110 EB:0 ET:0 EL:3 ]
Thu Apr 19 13:50:24 2018 us=531856 Data Channel MTU parms [ L:48121 D:48121 EF:121 EB:8156 ET:0 EL:3 ]
Thu Apr 19 13:50:24 2018 us=531905 Local Options String (VER=V4): 'V4,dev-type tun,link-mtu 48101,tun-mtu 48000 ,proto UDPv4,keydir 1,cipher AES-256-CBC,auth SHA512,keysize 256,tls-auth,key-method 2,tls-client'
Thu Apr 19 13:50:24 2018 us=531921 Expected Remote Options String (VER=V4): 'V4,dev-type tun,link-mtu 48101,tun -mtu 48000,proto UDPv4,keydir 0,cipher AES-256-CBC,auth SHA512,keysize 256,tls-auth,key-method 2,tls-server'
Thu Apr 19 13:50:24 2018 us=531944 TCP/UDP: Preserving recently used remote address: [AF_INET]192.168.1.1:5000
Thu Apr 19 13:50:24 2018 us=531977 Socket Buffers: R=[1048576->1048576] S=[1048576->1048576]
Thu Apr 19 13:50:24 2018 us=531990 UDP link local: (not bound)
Thu Apr 19 13:50:24 2018 us=532006 UDP link remote: [AF_INET]192.168.1.1:5000
WRThu Apr 19 13:50:24 2018 us=534538 TLS: Initial packet from [AF_INET]192.168.1.1:5000, sid=0e3c8eaa acc6b768
WWRWRWRThu Apr 19 13:50:24 2018 us=693474 VERIFY OK: depth=1, C=GB, ST=London, L=Locality, O=WWW Ltd., OU=LAN
Thu Apr 19 13:50:24 2018 us=694234 Validating certificate extended key usage
Thu Apr 19 13:50:24 2018 us=694268 ++ Certificate has EKU (str) TLS Web Server Authentication, expects TLS Web Server Authentication
Thu Apr 19 13:50:24 2018 us=694284 VERIFY EKU OK
Thu Apr 19 13:50:24 2018 us=694298 VERIFY OK: depth=0, CN=my-server
WRWWWWRRRRWRWThu Apr 19 13:50:24 2018 us=738364 Control Channel: TLSv1.2, cipher TLSv1.2 ECDHE-RSA-AES256-GCM-S HA384, 4096 bit RSA
Thu Apr 19 13:50:24 2018 us=738443 [my-server] Peer Connection Initiated with [AF_INET]192.168.1.1:5000
Thu Apr 19 13:50:25 2018 us=788644 SENT CONTROL [my-server]: 'PUSH_REQUEST' (status=1)
WRRThu Apr 19 13:50:25 2018 us=789907 PUSH: Received control message: 'PUSH_REPLY,route 192.168.1.0 255.255.255 .0,dhcp-option DNS 192.168.1.1,dhcp-option WINS 192.168.1.1,dhcp-option DNS 208.67.222.123,dhcp-option DNS 208.67.220.123,dhcp-option NTP 129.6.15.30,sndbuf 393216,rcvbuf 393216,route-gateway 10.1.0.1,topolo gy subnet,ping 10,ping-restart 120,ifconfig 10.1.0.2 255.255.255.240,peer-id 0,cipher AES-256-GCM'
Thu Apr 19 13:50:25 2018 us=790253 OPTIONS IMPORT: timers and/or timeouts modified
Thu Apr 19 13:50:25 2018 us=790286 OPTIONS IMPORT: --sndbuf/--rcvbuf options modified
Thu Apr 19 13:50:25 2018 us=790331 Socket Buffers: R=[1048576->786432] S=[1048576->786432]
Thu Apr 19 13:50:25 2018 us=790351 OPTIONS IMPORT: --ifconfig/up options modified
Thu Apr 19 13:50:25 2018 us=790374 OPTIONS IMPORT: route options modified
Thu Apr 19 13:50:25 2018 us=790396 OPTIONS IMPORT: route-related options modified
Thu Apr 19 13:50:25 2018 us=790419 OPTIONS IMPORT: --ip-win32 and/or --dhcp-option options modified
Thu Apr 19 13:50:25 2018 us=790441 OPTIONS IMPORT: peer-id set
Thu Apr 19 13:50:25 2018 us=790464 OPTIONS IMPORT: adjusting link_mtu to 48124
Thu Apr 19 13:50:25 2018 us=790485 OPTIONS IMPORT: data channel crypto options modified
Thu Apr 19 13:50:25 2018 us=790511 Data Channel: using negotiated cipher 'AES-256-GCM'
Thu Apr 19 13:50:25 2018 us=790561 Data Channel MTU parms [ L:48052 D:48052 EF:52 EB:8156 ET:0 EL:3 ]
Thu Apr 19 13:50:25 2018 us=790772 Outgoing Data Channel: Cipher 'AES-256-GCM' initialized with 256 bit key
Thu Apr 19 13:50:25 2018 us=790804 Incoming Data Channel: Cipher 'AES-256-GCM' initialized with 256 bit key
Thu Apr 19 13:50:25 2018 us=791049 ROUTE_GATEWAY 192.168.1.1/255.255.255.0 IFACE=enp0s31f6 HWADDR=d0:50:99:94:6 d:a2
Thu Apr 19 13:50:25 2018 us=804185 TUN/TAP device tun0 opened
Thu Apr 19 13:50:25 2018 us=804236 TUN/TAP TX queue length set to 100
Thu Apr 19 13:50:25 2018 us=804252 do_ifconfig, tt->did_ifconfig_ipv6_setup=0
Thu Apr 19 13:50:25 2018 us=804265 /usr/bin/ip link set dev tun0 up mtu 48000
Thu Apr 19 13:50:25 2018 us=829921 /usr/bin/ip addr add dev tun0 10.1.0.2/28 broadcast 10.1.0.15
Thu Apr 19 13:50:25 2018 us=831512 /usr/bin/ip route add 192.168.1.0/24 via 10.1.0.1
Thu Apr 19 13:50:25 2018 us=833036 Initialization Sequence Completed
WrWrThu Apr 19 13:50:25 2018 us=833174 Recursive routing detected, drop tun packet to [AF_INET]192.168.1.1:5000
rThu Apr 19 13:50:25 2018 us=833197 Recursive routing detected, drop tun packet to [AF_INET]192.168.1.1:5000
rWrThu Apr 19 13:50:29 2018 us=813533 Recursive routing detected, drop tun packet to [AF_INET]192.168.1.1:5000
rWrThu Apr 19 13:50:37 2018 us=706874 Recursive routing detected, drop tun packet to [AF_INET]192.168.1.1:5000
WrThu Apr 19 13:50:47 2018 us=436334 Recursive routing detected, drop tun packet to [AF_INET]192.168.1.1:5000
Server openpvn log:
Thu Apr 19 13:52:30 2018 us=793639 OpenVPN 2.4.5 arm-openwrt-linux-gnu [SSL (OpenSSL)] [LZO] [LZ4] [EPOLL] [MH/PKTINFO] [AEAD]
Thu Apr 19 13:52:30 2018 us=793706 library versions: OpenSSL 1.0.2n 7 Dec 2017, LZO 2.10
Thu Apr 19 13:52:30 2018 us=794451 Diffie-Hellman initialized with 2048 bit key
Thu Apr 19 13:52:30 2018 us=794567 No valid translation found for TLS cipher '!aNULL'
Thu Apr 19 13:52:30 2018 us=794621 No valid translation found for TLS cipher '!eNULL'
Thu Apr 19 13:52:30 2018 us=794686 No valid translation found for TLS cipher '!3DES'
Thu Apr 19 13:52:30 2018 us=794733 No valid translation found for TLS cipher '!MD5'
Thu Apr 19 13:52:30 2018 us=794779 No valid translation found for TLS cipher '!SHA'
Thu Apr 19 13:52:30 2018 us=794842 No valid translation found for TLS cipher '!PSK'
Thu Apr 19 13:52:30 2018 us=794906 No valid translation found for TLS cipher '!DSS'
Thu Apr 19 13:52:30 2018 us=794952 No valid translation found for TLS cipher '!RC4'
Thu Apr 19 13:52:30 2018 us=805571 Outgoing Control Channel Authentication: Using 512 bit message hash 'SHA512' for HMAC authentication
Thu Apr 19 13:52:30 2018 us=805638 Incoming Control Channel Authentication: Using 512 bit message hash 'SHA512' for HMAC authentication
Thu Apr 19 13:52:30 2018 us=805684 TLS-Auth MTU parms [ L:48121 D:1140 EF:110 EB:0 ET:0 EL:3 ]
Thu Apr 19 13:52:30 2018 us=806203 TUN/TAP device tun0 opened
Thu Apr 19 13:52:30 2018 us=806340 TUN/TAP TX queue length set to 100
Thu Apr 19 13:52:30 2018 us=806391 do_ifconfig, tt->did_ifconfig_ipv6_setup=0
Thu Apr 19 13:52:30 2018 us=806452 /sbin/ifconfig tun0 10.1.0.1 netmask 255.255.255.240 mtu 48000 broadcast 10.1.0.15
Thu Apr 19 13:52:30 2018 us=809739 Data Channel MTU parms [ L:48121 D:48121 EF:121 EB:8156 ET:0 EL:3 ]
Thu Apr 19 13:52:30 2018 us=809872 Could not determine IPv4/IPv6 protocol. Using AF_INET
Thu Apr 19 13:52:30 2018 us=809928 Socket Buffers: R=[163840->327680] S=[163840->327680]
Thu Apr 19 13:52:30 2018 us=809979 UDPv4 link local (bound): [AF_INET][undef]:5000
Thu Apr 19 13:52:30 2018 us=810011 UDPv4 link remote: [AF_UNSPEC]
Thu Apr 19 13:52:30 2018 us=810049 GID set to nogroup
Thu Apr 19 13:52:30 2018 us=810087 UID set to nobody
Thu Apr 19 13:52:30 2018 us=810129 MULTI: multi_init called, r=256 v=256
Thu Apr 19 13:52:30 2018 us=810188 IFCONFIG POOL: base=10.1.0.2 size=12, ipv6=0
Thu Apr 19 13:52:30 2018 us=810778 Initialization Sequence Completed
Thu Apr 19 13:52:36 2018 us=250749 MULTI: multi_create_instance called
Thu Apr 19 13:52:36 2018 us=250887 192.168.1.100:50669 Re-using SSL/TLS context
Thu Apr 19 13:52:36 2018 us=252508 192.168.1.100:50669 Control Channel MTU parms [ L:48121 D:1140 EF:110 EB:0 ET:0 EL:3 ]
Thu Apr 19 13:52:36 2018 us=252571 192.168.1.100:50669 Data Channel MTU parms [ L:48121 D:48121 EF:121 EB:8156 ET:0 EL:3 ]
Thu Apr 19 13:52:36 2018 us=252665 192.168.1.100:50669 Local Options String (VER=V4): 'V4,dev-type tun,link-mtu 48101,tun-mtu 48000,proto UDPv4,keydir 0,cipher AES-256-CBC,auth SHA512,keysize 256,tls-auth,key-method 2,tls-server'
Thu Apr 19 13:52:36 2018 us=252699 192.168.1.100:50669 Expected Remote Options String (VER=V4): 'V4,dev-type tun,link-mtu 48101,tun-mtu 48000,proto UDPv4,keydir 1,cipher AES-256-CBC,auth SHA512,keysize 256,tls-auth,key-method 2,tls-client'
RThu Apr 19 13:52:36 2018 us=252780 192.168.1.100:50669 TLS: Initial packet from [AF_INET]192.168.1.100:50669, sid=1c9642b5 1687e90d
WRRWWWWRRRRWRWRThu Apr 19 13:52:36 2018 us=448365 192.168.1.100:50669 VERIFY OK: depth=1, C=GB, ST=London, L=Locality, O=WWW Ltd., OU=LAN
Thu Apr 19 13:52:36 2018 us=450748 192.168.1.100:50669 VERIFY OK: depth=0, CN=my-client2
WRWRThu Apr 19 13:52:36 2018 us=456128 192.168.1.100:50669 peer info: IV_VER=2.4.5
Thu Apr 19 13:52:36 2018 us=456183 192.168.1.100:50669 peer info: IV_PLAT=linux
Thu Apr 19 13:52:36 2018 us=456217 192.168.1.100:50669 peer info: IV_PROTO=2
Thu Apr 19 13:52:36 2018 us=456266 192.168.1.100:50669 peer info: IV_NCP=2
Thu Apr 19 13:52:36 2018 us=456299 192.168.1.100:50669 peer info: IV_LZ4=1
Thu Apr 19 13:52:36 2018 us=456330 192.168.1.100:50669 peer info: IV_LZ4v2=1
Thu Apr 19 13:52:36 2018 us=456365 192.168.1.100:50669 peer info: IV_LZO=1
Thu Apr 19 13:52:36 2018 us=456397 192.168.1.100:50669 peer info: IV_COMP_STUB=1
Thu Apr 19 13:52:36 2018 us=456429 192.168.1.100:50669 peer info: IV_COMP_STUBv2=1
Thu Apr 19 13:52:36 2018 us=456459 192.168.1.100:50669 peer info: IV_TCPNL=1
WRThu Apr 19 13:52:36 2018 us=456967 192.168.1.100:50669 Control Channel: TLSv1.2, cipher TLSv1/SSLv3 ECDHE-RSA-AES256-GCM-SHA384, 4096 bit RSA
Thu Apr 19 13:52:36 2018 us=457035 192.168.1.100:50669 [my-client2] Peer Connection Initiated with [AF_INET]192.168.1.100:50669
Thu Apr 19 13:52:36 2018 us=457099 my-client2/192.168.1.100:50669 MULTI_sva: pool returned IPv4=10.1.0.2, IPv6=(Not enabled)
Thu Apr 19 13:52:36 2018 us=457242 my-client2/192.168.1.100:50669 MULTI: Learn: 10.1.0.2 -> my-client2/192.168.1.100:50669
Thu Apr 19 13:52:36 2018 us=457283 my-client2/192.168.1.100:50669 MULTI: primary virtual IP for my-client2/192.168.1.100:50669: 10.1.0.2
RThu Apr 19 13:52:37 2018 us=507503 my-client2/192.168.1.100:50669 PUSH: Received control message: 'PUSH_REQUEST'
Thu Apr 19 13:52:37 2018 us=507673 my-client2/192.168.1.100:50669 SENT CONTROL [my-client2]: 'PUSH_REPLY,route 192.168.1.0 255.255.255.0,dhcp-option DNS 192.168.1.1,dhcp-option WINS 192.168.1.1,dhcp-option DNS 208.67.222.123,dhcp-option DNS 208.67.220.123,dhcp-option NTP 129.6.15.30,sndbuf 393216,rcvbuf 393216,route-gateway 10.1.0.1,topology subnet,ping 10,ping-restart 120,ifconfig 10.1.0.2 255.255.255.240,peer-id 0,cipher AES-256-GCM' (status=1)
Thu Apr 19 13:52:37 2018 us=507717 my-client2/192.168.1.100:50669 Data Channel: using negotiated cipher 'AES-256-GCM'
Thu Apr 19 13:52:37 2018 us=507767 my-client2/192.168.1.100:50669 Data Channel MTU parms [ L:48049 D:48049 EF:49 EB:8156 ET:0 EL:3 ]
Thu Apr 19 13:52:37 2018 us=507965 my-client2/192.168.1.100:50669 Outgoing Data Channel: Cipher 'AES-256-GCM' initialized with 256 bit key
Thu Apr 19 13:52:37 2018 us=508007 my-client2/192.168.1.100:50669 Incoming Data Channel: Cipher 'AES-256-GCM' initialized with 256 bit key
Client (server same lan) conf:
# Config Type #
#------------------------------------------------
client
# Connection #
#------------------------------------------------
dev tun
proto udp
remote 192.168.1.1 5000
# Speed #
#------------------------------------------------
mssfix 0
fragment 0
tun-mtu 48000
# Reliability #
#------------------------------------------------
float
nobind
#comp-lzo
persist-key
persist-tun
resolv-retry infinite
# Encryption #
#------------------------------------------------
auth SHA512
auth-nocache
# --- SSL --- #
cipher AES-256-CBC
# --- TLS --- #
key-direction 1
tls-version-min 1.2
pkcs12 /etc/openvpn/client/my-client2.p12
remote-cert-eku "TLS Web Server Authentication"
<tls-auth>
-----BEGIN OpenVPN Static key V1-----
-----END OpenVPN Static key V1-----
</tls-auth>
# Logging #
#------------------------------------------------
verb 5