Ok, I removed the whole “inbound” section and added the forwarding suggested by you. After that a router reboot.
Still no access.
Here the requested commands and their result
I have masked just the MAC addresses and my public IP from the VPS. Everything else is fine by me to share here.
root@OpenWrt:~# ubus call system board
{
"kernel": "6.12.71",
"hostname": "OpenWrt",
"system": "MediaTek MT7621 ver:1 eco:3",
"model": "Zyxel LTE3301-Plus",
"board_name": "zyxel,lte3301-plus",
"rootfs_type": "squashfs",
"release": {
"distribution": "OpenWrt",
"version": "25.12.0",
"firmware_url": "https://downloads.openwrt.org/",
"revision": "r32713-f919e7899d",
"target": "ramips/mt7621",
"description": "OpenWrt 25.12.0 r32713-f919e7899d",
"builddate": "1772496855"
}
}
root@OpenWrt:~# cat /etc/config/network
config interface 'loopback'
option device 'lo'
option proto 'static'
option ipaddr '127.0.0.1'
option netmask '255.0.0.0'
config globals 'globals'
option ula_prefix 'fd4e:0f69:3016::/48'
option packet_steering '1'
option dhcp_default_duid '00047bceaf28e31f46e19ca76cc1cf4fc2f8'
config device
option name 'br-lan'
option type 'bridge'
list ports 'lan1'
list ports 'lan2'
list ports 'lan3'
list ports 'lan4'
config interface 'lan'
option device 'br-lan'
option proto 'static'
option ipaddr '192.168.11.1'
option netmask '255.255.255.0'
option ip6assign '60'
config interface '4G'
option proto 'qmi'
option device '/dev/cdc-wdm0'
option apn 'internet.a1.bg'
option auth 'none'
option pdptype 'ipv4'
config interface 'openvpn'
option proto 'none'
option device 'tun0'
option defaultroute '0'
config interface 'guest'
option proto 'static'
option ipaddr '192.168.22.1'
option netmask '255.255.255.0'
root@OpenWrt:~# ip route show
default via 10.159.246.50 dev wwan0 proto static src 10.159.246.49
10.8.0.0/24 dev tun0 proto kernel scope link src 10.8.0.2
10.159.246.48/30 dev wwan0 proto kernel scope link src 10.159.246.49
192.168.11.0/24 dev br-lan proto kernel scope link src 192.168.11.1
192.168.22.0/24 dev phy0-ap1 proto kernel scope link src 192.168.22.1
root@OpenWrt:~# ifconfig
br-lan Link encap:Ethernet HWaddr XX:XX:XX:XX:XX:XX
inet addr:192.168.11.1 Bcast:192.168.11.255 Mask:255.255.255.0
inet6 addr: fd4e:f69:3016::1/60 Scope:Global
inet6 addr: fe80::7ac5:7dff:fe3e:ca14/64 Scope:Link
UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1
RX packets:6362 errors:0 dropped:0 overruns:0 frame:0
TX packets:4652 errors:0 dropped:2 overruns:0 carrier:0
collisions:0 txqueuelen:1000
RX bytes:1243847 (1.1 MiB) TX bytes:1542650 (1.4 MiB)
eth0 Link encap:Ethernet HWaddr XX:XX:XX:XX:XX:XX
inet6 addr: fe80::7ac5:7dff:fe3e:ca14/64 Scope:Link
UP BROADCAST RUNNING MULTICAST MTU:1504 Metric:1
RX packets:24 errors:0 dropped:0 overruns:0 frame:0
TX packets:4621 errors:0 dropped:0 overruns:0 carrier:0
collisions:0 txqueuelen:1000
RX bytes:2298 (2.2 KiB) TX bytes:748823 (731.2 KiB)
Interrupt:19
lan1 Link encap:Ethernet HWaddr XX:XX:XX:XX:XX:XX
UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1
RX packets:16 errors:0 dropped:0 overruns:0 frame:0
TX packets:2305 errors:0 dropped:4 overruns:0 carrier:0
collisions:0 txqueuelen:1000
RX bytes:1692 (1.6 KiB) TX bytes:333541 (325.7 KiB)
lan2 Link encap:Ethernet HWaddr XX:XX:XX:XX:XX:XX
UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1
RX packets:8 errors:0 dropped:0 overruns:0 frame:0
TX packets:2300 errors:0 dropped:0 overruns:0 carrier:0
collisions:0 txqueuelen:1000
RX bytes:510 (510.0 B) TX bytes:332854 (325.0 KiB)
lan3 Link encap:Ethernet HWaddr XX:XX:XX:XX:XX:XX
UP BROADCAST MULTICAST MTU:1500 Metric:1
RX packets:0 errors:0 dropped:0 overruns:0 frame:0
TX packets:0 errors:0 dropped:0 overruns:0 carrier:0
collisions:0 txqueuelen:1000
RX bytes:0 (0.0 B) TX bytes:0 (0.0 B)
lan4 Link encap:Ethernet HWaddr XX:XX:XX:XX:XX:XX
UP BROADCAST MULTICAST MTU:1500 Metric:1
RX packets:0 errors:0 dropped:0 overruns:0 frame:0
TX packets:0 errors:0 dropped:0 overruns:0 carrier:0
collisions:0 txqueuelen:1000
RX bytes:0 (0.0 B) TX bytes:0 (0.0 B)
lo Link encap:Local Loopback
inet addr:127.0.0.1 Mask:255.0.0.0
inet6 addr: ::1/128 Scope:Host
UP LOOPBACK RUNNING MTU:65536 Metric:1
RX packets:196 errors:0 dropped:0 overruns:0 frame:0
TX packets:196 errors:0 dropped:0 overruns:0 carrier:0
collisions:0 txqueuelen:1000
RX bytes:18497 (18.0 KiB) TX bytes:18497 (18.0 KiB)
phy0-ap0 Link encap:Ethernet HWaddr XX:XX:XX:XX:XX:XX
UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1
RX packets:799 errors:0 dropped:0 overruns:0 frame:0
TX packets:2997 errors:0 dropped:0 overruns:0 carrier:0
collisions:0 txqueuelen:1000
RX bytes:135515 (132.3 KiB) TX bytes:516067 (503.9 KiB)
phy0-ap1 Link encap:Ethernet HWaddr XX:XX:XX:XX:XX:XX
inet addr:192.168.22.1 Bcast:192.168.22.255 Mask:255.255.255.0
inet6 addr: fe80::c:43ff:fe26:6018/64 Scope:Link
UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1
RX packets:0 errors:0 dropped:0 overruns:0 frame:0
TX packets:9 errors:0 dropped:0 overruns:0 carrier:0
collisions:0 txqueuelen:1000
RX bytes:0 (0.0 B) TX bytes:1592 (1.5 KiB)
phy1-ap0 Link encap:Ethernet HWaddr XX:XX:XX:XX:XX:XX
UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1
RX packets:5842 errors:0 dropped:0 overruns:0 frame:0
TX packets:7963 errors:0 dropped:0 overruns:0 carrier:0
collisions:0 txqueuelen:1000
RX bytes:1211882 (1.1 MiB) TX bytes:2207357 (2.1 MiB)
tun0 Link encap:UNSPEC HWaddr 00-00-00-00-00-00-00-00-00-00-00-00-00-00-00-00
inet addr:10.8.0.2 P-t-P:10.8.0.2 Mask:255.255.255.0
inet6 addr: fe80::d97a:69ac:ff3f:22c2/64 Scope:Link
UP POINTOPOINT RUNNING NOARP MULTICAST MTU:1500 Metric:1
RX packets:43 errors:0 dropped:0 overruns:0 frame:0
TX packets:60 errors:0 dropped:0 overruns:0 carrier:0
collisions:0 txqueuelen:500
RX bytes:5411 (5.2 KiB) TX bytes:38179 (37.2 KiB)
wwan0 Link encap:UNSPEC HWaddr 00-00-00-00-00-00-00-00-00-00-00-00-00-00-00-00
inet addr:10.159.246.49 P-t-P:10.159.246.49 Mask:255.255.255.252
inet6 addr: fe80::d922:5e35:37dc:24f7/64 Scope:Link
UP POINTOPOINT RUNNING NOARP MULTICAST MTU:1500 Metric:1
RX packets:3878 errors:0 dropped:0 overruns:0 frame:0
TX packets:3972 errors:0 dropped:2 overruns:0 carrier:0
collisions:0 txqueuelen:1000
RX bytes:1378871 (1.3 MiB) TX bytes:952587 (930.2 KiB)
root@OpenWrt:~# logread | grep openvpn
Sun Mar 8 08:25:40 2026 daemon.warn openvpn(vpn_home)[2466]: Unrecognized option or missing or extra parameter(s) in vpn_home.ovpn:23: block-outside-dns (2.6.14)
Sun Mar 8 08:25:40 2026 daemon.notice openvpn(vpn_home)[2466]: Note: Kernel support for ovpn-dco missing, disabling data channel offload.
Sun Mar 8 08:25:40 2026 daemon.notice openvpn(vpn_home)[2466]: OpenVPN 2.6.14 mipsel-openwrt-linux-gnu [SSL (OpenSSL)] [LZO] [LZ4] [EPOLL] [MH/PKTINFO] [AEAD] [DCO]
Sun Mar 8 08:25:40 2026 daemon.notice openvpn(vpn_home)[2466]: library versions: OpenSSL 3.5.5 27 Jan 2026, LZO 2.10
Sun Mar 8 08:25:40 2026 daemon.notice openvpn(vpn_home)[2466]: DCO version: N/A
Sun Mar 8 08:25:40 2026 daemon.warn openvpn(vpn_home)[2466]: NOTE: the current --script-security setting may allow this configuration to call user-defined scripts
Sun Mar 8 08:25:40 2026 daemon.notice openvpn(vpn_home)[2466]: TCP/UDP: Preserving recently used remote address: [AF_INET]xx.xx.xx.xx:61951
Sun Mar 8 08:25:40 2026 daemon.notice openvpn(vpn_home)[2466]: Socket Buffers: R=[180224->180224] S=[180224->180224]
Sun Mar 8 08:25:40 2026 daemon.notice openvpn(vpn_home)[2466]: UDPv4 link local: (not bound)
Sun Mar 8 08:25:40 2026 daemon.notice openvpn(vpn_home)[2466]: UDPv4 link remote: [AF_INET]xx.xx.xx.xx:61951
Sun Mar 8 08:25:40 2026 daemon.err openvpn(vpn_home)[2466]: write UDPv4 []: Network unreachable (fd=5,code=128)
Sun Mar 8 08:25:40 2026 daemon.notice openvpn(vpn_home)[2466]: Network unreachable, restarting
Sun Mar 8 08:25:40 2026 daemon.notice openvpn(vpn_home)[2466]: SIGUSR1[soft,network-unreachable] received, process restarting
Sun Mar 8 08:25:40 2026 daemon.notice openvpn(vpn_home)[2466]: Restart pause, 1 second(s)
Sun Mar 8 08:25:41 2026 daemon.warn openvpn(vpn_home)[2466]: NOTE: the current --script-security setting may allow this configuration to call user-defined scripts
Sun Mar 8 08:25:41 2026 daemon.notice openvpn(vpn_home)[2466]: TCP/UDP: Preserving recently used remote address: [AF_INET]xx.xx.xx.xx:61951
Sun Mar 8 08:25:41 2026 daemon.notice openvpn(vpn_home)[2466]: Socket Buffers: R=[180224->180224] S=[180224->180224]
Sun Mar 8 08:25:41 2026 daemon.notice openvpn(vpn_home)[2466]: UDPv4 link local: (not bound)
Sun Mar 8 08:25:41 2026 daemon.notice openvpn(vpn_home)[2466]: UDPv4 link remote: [AF_INET]xx.xx.xx.xx:61951
Sun Mar 8 08:25:41 2026 daemon.err openvpn(vpn_home)[2466]: write UDPv4 []: Network unreachable (fd=5,code=128)
Sun Mar 8 08:25:41 2026 daemon.notice openvpn(vpn_home)[2466]: Network unreachable, restarting
Sun Mar 8 08:25:41 2026 daemon.notice openvpn(vpn_home)[2466]: SIGUSR1[soft,network-unreachable] received, process restarting
Sun Mar 8 08:25:41 2026 daemon.notice openvpn(vpn_home)[2466]: Restart pause, 1 second(s)
Sun Mar 8 08:25:42 2026 daemon.warn openvpn(vpn_home)[2466]: NOTE: the current --script-security setting may allow this configuration to call user-defined scripts
Sun Mar 8 08:25:42 2026 daemon.notice openvpn(vpn_home)[2466]: TCP/UDP: Preserving recently used remote address: [AF_INET]xx.xx.xx.xx:61951
Sun Mar 8 08:25:42 2026 daemon.notice openvpn(vpn_home)[2466]: Socket Buffers: R=[180224->180224] S=[180224->180224]
Sun Mar 8 08:25:42 2026 daemon.notice openvpn(vpn_home)[2466]: UDPv4 link local: (not bound)
Sun Mar 8 08:25:42 2026 daemon.notice openvpn(vpn_home)[2466]: UDPv4 link remote: [AF_INET]xx.xx.xx.xx:61951
Sun Mar 8 08:25:42 2026 daemon.err openvpn(vpn_home)[2466]: write UDPv4 []: Network unreachable (fd=5,code=128)
Sun Mar 8 08:25:42 2026 daemon.notice openvpn(vpn_home)[2466]: Network unreachable, restarting
Sun Mar 8 08:25:42 2026 daemon.notice openvpn(vpn_home)[2466]: SIGUSR1[soft,network-unreachable] received, process restarting
Sun Mar 8 08:25:42 2026 daemon.notice openvpn(vpn_home)[2466]: Restart pause, 1 second(s)
Sun Mar 8 08:25:43 2026 daemon.warn openvpn(vpn_home)[2466]: NOTE: the current --script-security setting may allow this configuration to call user-defined scripts
Sun Mar 8 08:25:43 2026 daemon.notice openvpn(vpn_home)[2466]: TCP/UDP: Preserving recently used remote address: [AF_INET]xx.xx.xx.xx:61951
Sun Mar 8 08:25:43 2026 daemon.notice openvpn(vpn_home)[2466]: Socket Buffers: R=[180224->180224] S=[180224->180224]
Sun Mar 8 08:25:43 2026 daemon.notice openvpn(vpn_home)[2466]: UDPv4 link local: (not bound)
Sun Mar 8 08:25:43 2026 daemon.notice openvpn(vpn_home)[2466]: UDPv4 link remote: [AF_INET]xx.xx.xx.xx:61951
Sun Mar 8 08:25:43 2026 daemon.err openvpn(vpn_home)[2466]: write UDPv4 []: Network unreachable (fd=5,code=128)
Sun Mar 8 08:25:43 2026 daemon.notice openvpn(vpn_home)[2466]: Network unreachable, restarting
Sun Mar 8 08:25:43 2026 daemon.notice openvpn(vpn_home)[2466]: SIGUSR1[soft,network-unreachable] received, process restarting
Sun Mar 8 08:25:43 2026 daemon.notice openvpn(vpn_home)[2466]: Restart pause, 1 second(s)
Sun Mar 8 08:25:44 2026 daemon.warn openvpn(vpn_home)[2466]: NOTE: the current --script-security setting may allow this configuration to call user-defined scripts
Sun Mar 8 08:25:44 2026 daemon.notice openvpn(vpn_home)[2466]: TCP/UDP: Preserving recently used remote address: [AF_INET]xx.xx.xx.xx:61951
Sun Mar 8 08:25:44 2026 daemon.notice openvpn(vpn_home)[2466]: Socket Buffers: R=[180224->180224] S=[180224->180224]
Sun Mar 8 08:25:44 2026 daemon.notice openvpn(vpn_home)[2466]: UDPv4 link local: (not bound)
Sun Mar 8 08:25:44 2026 daemon.notice openvpn(vpn_home)[2466]: UDPv4 link remote: [AF_INET]xx.xx.xx.xx:61951
Sun Mar 8 08:25:44 2026 daemon.err openvpn(vpn_home)[2466]: write UDPv4 []: Network unreachable (fd=5,code=128)
Sun Mar 8 08:25:44 2026 daemon.notice openvpn(vpn_home)[2466]: Network unreachable, restarting
Sun Mar 8 08:25:44 2026 daemon.notice openvpn(vpn_home)[2466]: SIGUSR1[soft,network-unreachable] received, process restarting
Sun Mar 8 08:25:44 2026 daemon.notice openvpn(vpn_home)[2466]: Restart pause, 2 second(s)
Sun Mar 8 08:25:46 2026 daemon.warn openvpn(vpn_home)[2466]: NOTE: the current --script-security setting may allow this configuration to call user-defined scripts
Sun Mar 8 08:25:46 2026 daemon.notice openvpn(vpn_home)[2466]: TCP/UDP: Preserving recently used remote address: [AF_INET]xx.xx.xx.xx:61951
Sun Mar 8 08:25:46 2026 daemon.notice openvpn(vpn_home)[2466]: Socket Buffers: R=[180224->180224] S=[180224->180224]
Sun Mar 8 08:25:46 2026 daemon.notice openvpn(vpn_home)[2466]: UDPv4 link local: (not bound)
Sun Mar 8 08:25:46 2026 daemon.notice openvpn(vpn_home)[2466]: UDPv4 link remote: [AF_INET]xx.xx.xx.xx:61951
Sun Mar 8 08:25:46 2026 daemon.err openvpn(vpn_home)[2466]: write UDPv4 []: Network unreachable (fd=5,code=128)
Sun Mar 8 08:25:46 2026 daemon.notice openvpn(vpn_home)[2466]: Network unreachable, restarting
Sun Mar 8 08:25:46 2026 daemon.notice openvpn(vpn_home)[2466]: SIGUSR1[soft,network-unreachable] received, process restarting
Sun Mar 8 08:25:46 2026 daemon.notice openvpn(vpn_home)[2466]: Restart pause, 4 second(s)
Sun Mar 8 08:25:50 2026 daemon.warn openvpn(vpn_home)[2466]: NOTE: the current --script-security setting may allow this configuration to call user-defined scripts
Sun Mar 8 08:25:50 2026 daemon.notice openvpn(vpn_home)[2466]: TCP/UDP: Preserving recently used remote address: [AF_INET]xx.xx.xx.xx:61951
Sun Mar 8 08:25:50 2026 daemon.notice openvpn(vpn_home)[2466]: Socket Buffers: R=[180224->180224] S=[180224->180224]
Sun Mar 8 08:25:50 2026 daemon.notice openvpn(vpn_home)[2466]: UDPv4 link local: (not bound)
Sun Mar 8 08:25:50 2026 daemon.notice openvpn(vpn_home)[2466]: UDPv4 link remote: [AF_INET]xx.xx.xx.xx:61951
Sun Mar 8 08:25:50 2026 daemon.err openvpn(vpn_home)[2466]: write UDPv4 []: Network unreachable (fd=5,code=128)
Sun Mar 8 08:25:50 2026 daemon.notice openvpn(vpn_home)[2466]: Network unreachable, restarting
Sun Mar 8 08:25:50 2026 daemon.notice openvpn(vpn_home)[2466]: SIGUSR1[soft,network-unreachable] received, process restarting
Sun Mar 8 08:25:50 2026 daemon.notice openvpn(vpn_home)[2466]: Restart pause, 8 second(s)
Sun Mar 8 08:25:58 2026 daemon.warn openvpn(vpn_home)[2466]: NOTE: the current --script-security setting may allow this configuration to call user-defined scripts
Sun Mar 8 08:25:58 2026 daemon.notice openvpn(vpn_home)[2466]: TCP/UDP: Preserving recently used remote address: [AF_INET]xx.xx.xx.xx:61951
Sun Mar 8 08:25:58 2026 daemon.notice openvpn(vpn_home)[2466]: Socket Buffers: R=[180224->180224] S=[180224->180224]
Sun Mar 8 08:25:58 2026 daemon.notice openvpn(vpn_home)[2466]: UDPv4 link local: (not bound)
Sun Mar 8 08:25:58 2026 daemon.notice openvpn(vpn_home)[2466]: UDPv4 link remote: [AF_INET]xx.xx.xx.xx:61951
Sun Mar 8 08:25:58 2026 daemon.err openvpn(vpn_home)[2466]: write UDPv4 []: Network unreachable (fd=5,code=128)
Sun Mar 8 08:25:58 2026 daemon.notice openvpn(vpn_home)[2466]: Network unreachable, restarting
Sun Mar 8 08:25:58 2026 daemon.notice openvpn(vpn_home)[2466]: SIGUSR1[soft,network-unreachable] received, process restarting
Sun Mar 8 08:25:58 2026 daemon.notice openvpn(vpn_home)[2466]: Restart pause, 16 second(s)
Sun Mar 8 08:26:14 2026 daemon.warn openvpn(vpn_home)[2466]: NOTE: the current --script-security setting may allow this configuration to call user-defined scripts
Sun Mar 8 08:26:14 2026 daemon.notice openvpn(vpn_home)[2466]: TCP/UDP: Preserving recently used remote address: [AF_INET]xx.xx.xx.xx:61951
Sun Mar 8 08:26:14 2026 daemon.notice openvpn(vpn_home)[2466]: Socket Buffers: R=[180224->180224] S=[180224->180224]
Sun Mar 8 08:26:14 2026 daemon.notice openvpn(vpn_home)[2466]: UDPv4 link local: (not bound)
Sun Mar 8 08:26:14 2026 daemon.notice openvpn(vpn_home)[2466]: UDPv4 link remote: [AF_INET]xx.xx.xx.xx:61951
Sun Mar 8 08:26:14 2026 daemon.notice openvpn(vpn_home)[2466]: TLS: Initial packet from [AF_INET]xx.xx.xx.xx:61951, sid=e4ff9900 0154c718
Sun Mar 8 08:26:14 2026 daemon.notice openvpn(vpn_home)[2466]: VERIFY OK: depth=1, CN=cn_HSPjtplMpuTTj9kz
Sun Mar 8 08:26:14 2026 daemon.notice openvpn(vpn_home)[2466]: VERIFY KU OK
Sun Mar 8 08:26:14 2026 daemon.notice openvpn(vpn_home)[2466]: Validating certificate extended key usage
Sun Mar 8 08:26:14 2026 daemon.notice openvpn(vpn_home)[2466]: ++ Certificate has EKU (str) TLS Web Server Authentication, expects TLS Web Server Authentication
Sun Mar 8 08:26:14 2026 daemon.notice openvpn(vpn_home)[2466]: VERIFY EKU OK
Sun Mar 8 08:26:14 2026 daemon.notice openvpn(vpn_home)[2466]: VERIFY X509NAME OK: CN=server_Yyp2Cp4AmPmQGb6x
Sun Mar 8 08:26:14 2026 daemon.notice openvpn(vpn_home)[2466]: VERIFY OK: depth=0, CN=server_Yyp2Cp4AmPmQGb6x
Sun Mar 8 08:26:14 2026 daemon.notice openvpn(vpn_home)[2466]: Control Channel: TLSv1.3, cipher TLSv1.3 TLS_AES_256_GCM_SHA384, peer certificate: 256 bits ECprime256v1, signature: ecdsa-with-SHA256, peer temporary key: 253 bits X25519
Sun Mar 8 08:26:14 2026 daemon.notice openvpn(vpn_home)[2466]: [server_Yyp2Cp4AmPmQGb6x] Peer Connection Initiated with [AF_INET]xx.xx.xx.xx:61951
Sun Mar 8 08:26:14 2026 daemon.notice openvpn(vpn_home)[2466]: TLS: move_session: dest=TM_ACTIVE src=TM_INITIAL reinit_src=1
Sun Mar 8 08:26:14 2026 daemon.notice openvpn(vpn_home)[2466]: TLS: tls_multi_process: initial untrusted session promoted to trusted
Sun Mar 8 08:26:14 2026 daemon.notice openvpn(vpn_home)[2466]: PUSH: Received control message: 'PUSH_REPLY,dhcp-option DNS 208.67.222.222,dhcp-option DNS 208.67.220.220,redirect-gateway def1 bypass-dhcp,route-gateway 10.8.0.1,topology subnet,ping 10,ping-restart 120,ifconfig 10.8.0.2 255.255.255.0,peer-id 1,cipher AES-128-GCM,protocol-flags cc-exit tls-ekm dyn-tls-crypt,tun-mtu 1500'
Sun Mar 8 08:26:14 2026 daemon.notice openvpn(vpn_home)[2466]: Pushed option removed by filter: 'redirect-gateway def1 bypass-dhcp'
Sun Mar 8 08:26:14 2026 daemon.notice openvpn(vpn_home)[2466]: OPTIONS IMPORT: --ifconfig/up options modified
Sun Mar 8 08:26:14 2026 daemon.notice openvpn(vpn_home)[2466]: OPTIONS IMPORT: route-related options modified
Sun Mar 8 08:26:14 2026 daemon.notice openvpn(vpn_home)[2466]: OPTIONS IMPORT: --ip-win32 and/or --dhcp-option options modified
Sun Mar 8 08:26:14 2026 daemon.notice openvpn(vpn_home)[2466]: OPTIONS IMPORT: tun-mtu set to 1500
Sun Mar 8 08:26:14 2026 daemon.notice openvpn(vpn_home)[2466]: TUN/TAP device tun0 opened
Sun Mar 8 08:26:14 2026 daemon.notice openvpn(vpn_home)[2466]: net_iface_mtu_set: mtu 1500 for tun0
Sun Mar 8 08:26:14 2026 daemon.notice openvpn(vpn_home)[2466]: net_iface_up: set tun0 up
Sun Mar 8 08:26:14 2026 daemon.notice openvpn(vpn_home)[2466]: net_addr_v4_add: 10.8.0.2/24 dev tun0
Sun Mar 8 08:26:14 2026 daemon.notice netifd: Interface 'openvpn' is enabled
Sun Mar 8 08:26:14 2026 daemon.notice openvpn(vpn_home)[2466]: /usr/libexec/openvpn-hotplug up vpn_home tun0 1500 0 10.8.0.2 255.255.255.0 init
Sun Mar 8 08:26:14 2026 daemon.notice netifd: Interface 'openvpn' has link connectivity
Sun Mar 8 08:26:14 2026 daemon.notice netifd: Interface 'openvpn' is setting up now
Sun Mar 8 08:26:15 2026 daemon.notice netifd: Interface 'openvpn' is now up
Sun Mar 8 08:26:15 2026 daemon.notice openvpn(vpn_home)[2466]: Initialization Sequence Completed
Sun Mar 8 08:26:15 2026 daemon.notice openvpn(vpn_home)[2466]: Data Channel: cipher 'AES-128-GCM', peer-id: 1
Sun Mar 8 08:26:15 2026 daemon.notice openvpn(vpn_home)[2466]: Timers: ping 10, ping-restart 120
Sun Mar 8 08:26:15 2026 daemon.notice openvpn(vpn_home)[2466]: Protocol options: explicit-exit-notify 1, protocol-flags cc-exit tls-ekm dyn-tls-crypt
Sun Mar 8 08:26:15 2026 user.notice firewall: Reloading firewall due to ifup of openvpn (tun0)
Sun Mar 8 08:26:25 2026 user.notice pbr [4456]: Setting up routing for 'openvpn/tun0/10.8.0.2' [✓]
Sun Mar 8 08:26:27 2026 user.notice pbr [4456]: Routing 'Roland-Laptop-TalkTalk' via openvpn [✓]
Sun Mar 8 08:26:29 2026 user.notice pbr [4456]: Setting interface trigger for openvpn [✓]
Sun Mar 8 08:26:29 2026 user.notice pbr [4456]: pbr 1.2.2-r8 monitoring interfaces: 4G openvpn ox
Sun Mar 8 08:26:37 2026 user.notice pbr [4456]: pbr 1.2.2-r8 started with gateways: 4G/wwan0/10.159.246.49 [✓] openvpn/tun0/10.8.0.2 ox/tun1/0.0.0.0
Sun Mar 8 08:29:33 2026 daemon.notice openvpn(vpn_home)[2466]: [server_Yyp2Cp4AmPmQGb6x] Inactivity timeout (--ping-restart), restarting
Sun Mar 8 08:29:33 2026 daemon.notice openvpn(vpn_home)[2466]: SIGUSR1[soft,ping-restart] received, process restarting
Sun Mar 8 08:29:33 2026 daemon.notice openvpn(vpn_home)[2466]: Restart pause, 1 second(s)
Sun Mar 8 08:29:34 2026 daemon.warn openvpn(vpn_home)[2466]: NOTE: the current --script-security setting may allow this configuration to call user-defined scripts
Sun Mar 8 08:29:34 2026 daemon.notice openvpn(vpn_home)[2466]: TCP/UDP: Preserving recently used remote address: [AF_INET]xx.xx.xx.xx:61951
Sun Mar 8 08:29:34 2026 daemon.notice openvpn(vpn_home)[2466]: Socket Buffers: R=[180224->180224] S=[180224->180224]
Sun Mar 8 08:29:34 2026 daemon.notice openvpn(vpn_home)[2466]: UDPv4 link local: (not bound)
Sun Mar 8 08:29:34 2026 daemon.notice openvpn(vpn_home)[2466]: UDPv4 link remote: [AF_INET]xx.xx.xx.xx:61951
Sun Mar 8 08:29:34 2026 daemon.notice openvpn(vpn_home)[2466]: TLS: Initial packet from [AF_INET]xx.xx.xx.xx:61951, sid=370a4d7a 0cb9156c
Sun Mar 8 08:29:35 2026 daemon.notice openvpn(vpn_home)[2466]: VERIFY OK: depth=1, CN=cn_HSPjtplMpuTTj9kz
Sun Mar 8 08:29:35 2026 daemon.notice openvpn(vpn_home)[2466]: VERIFY KU OK
Sun Mar 8 08:29:35 2026 daemon.notice openvpn(vpn_home)[2466]: Validating certificate extended key usage
Sun Mar 8 08:29:35 2026 daemon.notice openvpn(vpn_home)[2466]: ++ Certificate has EKU (str) TLS Web Server Authentication, expects TLS Web Server Authentication
Sun Mar 8 08:29:35 2026 daemon.notice openvpn(vpn_home)[2466]: VERIFY EKU OK
Sun Mar 8 08:29:35 2026 daemon.notice openvpn(vpn_home)[2466]: VERIFY X509NAME OK: CN=server_Yyp2Cp4AmPmQGb6x
Sun Mar 8 08:29:35 2026 daemon.notice openvpn(vpn_home)[2466]: VERIFY OK: depth=0, CN=server_Yyp2Cp4AmPmQGb6x
Sun Mar 8 08:29:35 2026 daemon.notice openvpn(vpn_home)[2466]: Control Channel: TLSv1.3, cipher TLSv1.3 TLS_AES_256_GCM_SHA384, peer certificate: 256 bits ECprime256v1, signature: ecdsa-with-SHA256, peer temporary key: 253 bits X25519
Sun Mar 8 08:29:35 2026 daemon.notice openvpn(vpn_home)[2466]: [server_Yyp2Cp4AmPmQGb6x] Peer Connection Initiated with [AF_INET]xx.xx.xx.xx:61951
Sun Mar 8 08:29:35 2026 daemon.notice openvpn(vpn_home)[2466]: TLS: move_session: dest=TM_ACTIVE src=TM_INITIAL reinit_src=1
Sun Mar 8 08:29:35 2026 daemon.notice openvpn(vpn_home)[2466]: TLS: tls_multi_process: initial untrusted session promoted to trusted
Sun Mar 8 08:29:35 2026 daemon.notice openvpn(vpn_home)[2466]: PUSH: Received control message: 'PUSH_REPLY,dhcp-option DNS 208.67.222.222,dhcp-option DNS 208.67.220.220,redirect-gateway def1 bypass-dhcp,route-gateway 10.8.0.1,topology subnet,ping 10,ping-restart 120,ifconfig 10.8.0.2 255.255.255.0,peer-id 2,cipher AES-128-GCM,protocol-flags cc-exit tls-ekm dyn-tls-crypt,tun-mtu 1500'
Sun Mar 8 08:29:35 2026 daemon.notice openvpn(vpn_home)[2466]: Pushed option removed by filter: 'redirect-gateway def1 bypass-dhcp'
Sun Mar 8 08:29:35 2026 daemon.notice openvpn(vpn_home)[2466]: OPTIONS IMPORT: --ifconfig/up options modified
Sun Mar 8 08:29:35 2026 daemon.notice openvpn(vpn_home)[2466]: OPTIONS IMPORT: route-related options modified
Sun Mar 8 08:29:35 2026 daemon.notice openvpn(vpn_home)[2466]: OPTIONS IMPORT: --ip-win32 and/or --dhcp-option options modified
Sun Mar 8 08:29:35 2026 daemon.notice openvpn(vpn_home)[2466]: OPTIONS IMPORT: tun-mtu set to 1500
Sun Mar 8 08:29:35 2026 daemon.notice openvpn(vpn_home)[2466]: Preserving previous TUN/TAP instance: tun0
Sun Mar 8 08:29:35 2026 daemon.notice openvpn(vpn_home)[2466]: Initialization Sequence Completed
Sun Mar 8 08:29:35 2026 daemon.notice openvpn(vpn_home)[2466]: Data Channel: cipher 'AES-128-GCM', peer-id: 2
Sun Mar 8 08:29:35 2026 daemon.notice openvpn(vpn_home)[2466]: Timers: ping 10, ping-restart 120
Sun Mar 8 08:29:35 2026 daemon.notice openvpn(vpn_home)[2466]: Protocol options: explicit-exit-notify 1, protocol-flags cc-exit tls-ekm dyn-tls-crypt