Skip to content

Instantly share code, notes, and snippets.

@zeroflow
Last active May 13, 2022 07:43
Show Gist options
  • Star 0 You must be signed in to star a gist
  • Fork 0 You must be signed in to fork a gist
  • Save zeroflow/d4570d5f192074af1807d36c1525507e to your computer and use it in GitHub Desktop.
Save zeroflow/d4570d5f192074af1807d36c1525507e to your computer and use it in GitHub Desktop.
OpenVPN connect problem
May 13 08:52:58 openvpn 73391 MANAGEMENT: Client disconnected
May 13 08:52:58 openvpn 73391 MANAGEMENT: CMD 'status 2'
May 13 08:52:58 openvpn 73391 MANAGEMENT: CMD 'state 1'
May 13 08:52:58 openvpn 73391 MANAGEMENT: Client connected from /var/etc/openvpn/client2/sock
May 13 08:52:58 openvpn 73391 MANAGEMENT: Client disconnected
May 13 08:52:58 openvpn 73391 MANAGEMENT: CMD 'status 2'
May 13 08:52:58 openvpn 73391 MANAGEMENT: CMD 'state 1'
May 13 08:52:58 openvpn 73391 MANAGEMENT: Client connected from /var/etc/openvpn/client2/sock
May 13 08:52:23 openvpn 73391 Initialization Sequence Completed
May 13 08:52:23 openvpn 73391 WARNING: this configuration may cache passwords in memory -- use the auth-nocache option to prevent this
May 13 08:52:23 openvpn 73391 /usr/local/sbin/ovpn-linkup ovpnc2 1500 1658 <VPN private IP> 255.255.255.0 init
May 13 08:52:23 openvpn 73391 /sbin/route add -net <VPN private IP> <VPN private IP> 255.255.255.0
May 13 08:52:23 openvpn 73391 /sbin/ifconfig ovpnc2 <VPN private IP> <VPN private IP> mtu 1500 netmask 255.255.255.0 up
May 13 08:52:23 openvpn 73391 ioctl(TUNSIFMODE): Device busy (errno=16)
May 13 08:52:23 openvpn 73391 TUN/TAP device /dev/tun2 opened
May 13 08:52:23 openvpn 73391 TUN/TAP device ovpnc2 exists previously, keep at program end
May 13 08:52:23 openvpn 73391 Incoming Data Channel: Using 512 bit message hash 'SHA512' for HMAC authentication
May 13 08:52:23 openvpn 73391 Incoming Data Channel: Cipher 'AES-256-CBC' initialized with 256 bit key
May 13 08:52:23 openvpn 73391 Outgoing Data Channel: Using 512 bit message hash 'SHA512' for HMAC authentication
May 13 08:52:23 openvpn 73391 Outgoing Data Channel: Cipher 'AES-256-CBC' initialized with 256 bit key
May 13 08:52:23 openvpn 73391 Using peer cipher 'AES-256-CBC'
May 13 08:52:23 openvpn 73391 OPTIONS IMPORT: adjusting link_mtu to 1658
May 13 08:52:23 openvpn 73391 OPTIONS IMPORT: peer-id set
May 13 08:52:23 openvpn 73391 OPTIONS IMPORT: route-related options modified
May 13 08:52:23 openvpn 73391 OPTIONS IMPORT: --ifconfig/up options modified
May 13 08:52:23 openvpn 73391 Socket Buffers: R=[65700->524288] S=[65700->524288]
May 13 08:52:23 openvpn 73391 OPTIONS IMPORT: --sndbuf/--rcvbuf options modified
May 13 08:52:23 openvpn 73391 OPTIONS IMPORT: compression parms modified
May 13 08:52:23 openvpn 73391 OPTIONS IMPORT: --explicit-exit-notify can only be used with --proto udp
May 13 08:52:23 openvpn 73391 OPTIONS IMPORT: timers and/or timeouts modified
May 13 08:52:23 openvpn 73391 Options error: option 'dhcp-option' cannot be used in this context ([PUSH-OPTIONS])
May 13 08:52:23 openvpn 73391 Options error: option 'dhcp-option' cannot be used in this context ([PUSH-OPTIONS])
May 13 08:52:23 openvpn 73391 Options error: option 'redirect-gateway' cannot be used in this context ([PUSH-OPTIONS])
May 13 08:52:23 openvpn 73391 PUSH: Received control message: 'PUSH_REPLY,redirect-gateway def1,dhcp-option DNS <VPN DNS IP>,dhcp-option DNS <VPN DNS IP>,sndbuf 524288,rcvbuf 524288,explicit-exit-notify,comp-lzo no,route-gateway <VPN private IP>,topology subnet,ping 60,ping-restart 180,ifconfig <VPN private IP> 255.255.255.0,peer-id 0'
May 13 08:52:23 openvpn 73391 SENT CONTROL [nnn.nordvpn.com]: 'PUSH_REQUEST' (status=1)
May 13 08:52:22 openvpn 73391 [nnn.nordvpn.com] Peer Connection Initiated with [AF_INET]<NordVPN Server IP>:443
May 13 08:52:22 openvpn 73391 Control Channel: TLSv1.3, cipher TLSv1.3 TLS_AES_256_GCM_SHA384, peer certificate: 4096 bit RSA, signature: RSA-SHA512
May 13 08:52:22 openvpn 73391 WARNING: 'comp-lzo' is present in remote config but missing in local config, remote='comp-lzo'
May 13 08:52:22 openvpn 73391 WARNING: 'link-mtu' is used inconsistently, local='link-mtu 1635', remote='link-mtu 1636'
May 13 08:52:21 openvpn 73391 VERIFY OK: depth=0, CN=nnn.nordvpn.com
May 13 08:52:21 openvpn 73391 VERIFY EKU OK
May 13 08:52:21 openvpn 73391 ++ Certificate has EKU (str) TLS Web Server Authentication, expects TLS Web Server Authentication
May 13 08:52:21 openvpn 73391 Validating certificate extended key usage
May 13 08:52:21 openvpn 73391 VERIFY KU OK
May 13 08:52:21 openvpn 73391 VERIFY OK: depth=1, C=PA, O=NordVPN, CN=NordVPN CA7
May 13 08:52:21 openvpn 73391 VERIFY OK: depth=2, C=PA, O=NordVPN, CN=NordVPN Root CA
May 13 08:52:21 openvpn 73391 VERIFY WARNING: depth=2, unable to get certificate CRL: C=PA, O=NordVPN, CN=NordVPN Root CA
May 13 08:52:21 openvpn 73391 VERIFY WARNING: depth=1, unable to get certificate CRL: C=PA, O=NordVPN, CN=NordVPN CA7
May 13 08:52:21 openvpn 73391 VERIFY WARNING: depth=0, unable to get certificate CRL: CN=nnn.nordvpn.com
May 13 08:52:21 openvpn 73391 TLS: Initial packet from [AF_INET]<NordVPN Server IP>:443, sid=110ecb47 b18281b6
May 13 08:52:21 openvpn 73391 TCPv4_CLIENT link remote: [AF_INET]<NordVPN Server IP>:443
May 13 08:52:21 openvpn 73391 TCPv4_CLIENT link local (bound): [AF_INET]<my wan IP>:0
May 13 08:52:21 openvpn 73391 TCP connection established with [AF_INET]<NordVPN Server IP>:443
May 13 08:52:21 openvpn 73391 Attempting to establish TCP connection with [AF_INET]<NordVPN Server IP>:443 [nonblock]
May 13 08:52:21 openvpn 73391 Socket Buffers: R=[65228->65228] S=[65228->65228]
May 13 08:52:21 openvpn 73391 TCP/UDP: Preserving recently used remote address: [AF_INET]<NordVPN Server IP>:443
May 13 08:52:16 openvpn 73391 Incoming Control Channel Authentication: Using 512 bit message hash 'SHA512' for HMAC authentication
May 13 08:52:16 openvpn 73391 Outgoing Control Channel Authentication: Using 512 bit message hash 'SHA512' for HMAC authentication
May 13 08:52:16 openvpn 73391 WARNING: experimental option --capath /var/etc/openvpn/client2/ca
May 13 08:52:16 openvpn 73391 NOTE: the current --script-security setting may allow this configuration to call user-defined scripts
May 13 08:52:16 openvpn 73391 MANAGEMENT: unix domain socket listening on /var/etc/openvpn/client2/sock
May 13 08:52:16 openvpn 73061 library versions: OpenSSL 1.1.1l-freebsd 24 Aug 2021, LZO 2.10
May 13 08:52:16 openvpn 73061 OpenVPN 2.5.4 amd64-portbld-freebsd12.3 [SSL (OpenSSL)] [LZO] [LZ4] [MH/RECVDA] [AEAD] built on Jan 12 2022
May 13 08:52:16 openvpn 73061 WARNING: file '/var/etc/openvpn/client2/up' is group or others accessible
May 13 08:52:16 openvpn 57200 Initialization Sequence Completed
May 13 08:52:16 openvpn 57200 UDPv4 link remote: [AF_UNSPEC]
May 13 08:52:16 openvpn 57200 UDPv4 link local (bound): [AF_INET]<my wan IP>:1194
May 13 08:52:16 openvpn 57200 /usr/local/sbin/ovpn-linkup ovpns1 1500 1621 <local VLAN IP> 255.255.255.0 init
May 13 08:52:16 openvpn 57200 /sbin/ifconfig ovpns1 <local VLAN IP> <local VLAN IP> mtu 1500 netmask 255.255.255.0 up
May 13 08:52:16 openvpn 57200 ioctl(TUNSIFMODE): Device busy (errno=16)
May 13 08:52:16 openvpn 57200 TUN/TAP device /dev/tun1 opened
May 13 08:52:16 openvpn 57200 TUN/TAP device ovpns1 exists previously, keep at program end
May 13 08:52:16 openvpn 57200 WARNING: experimental option --capath /var/etc/openvpn/server1/ca
May 13 08:52:16 openvpn 57200 Initializing OpenSSL support for engine 'rdrand'
May 13 08:52:16 openvpn 57200 NOTE: the current --script-security setting may allow this configuration to call user-defined scripts
May 13 08:52:16 openvpn 57200 GDG: problem writing to routing socket
May 13 08:52:16 openvpn 57200 WARNING: using --duplicate-cn and --client-config-dir together is probably not what you want
May 13 08:52:16 openvpn 57076 library versions: OpenSSL 1.1.1l-freebsd 24 Aug 2021, LZO 2.10
May 13 08:52:16 openvpn 57076 OpenVPN 2.5.4 amd64-portbld-freebsd12.3 [SSL (OpenSSL)] [LZO] [LZ4] [MH/RECVDA] [AEAD] built on Jan 12 2022
May 13 08:56:13 openvpn 84142 MANAGEMENT: Client disconnected
May 13 08:56:13 openvpn 84142 MANAGEMENT: CMD 'status 2'
May 13 08:56:13 openvpn 84142 MANAGEMENT: CMD 'state 1'
May 13 08:56:13 openvpn 84142 MANAGEMENT: Client connected from /var/etc/openvpn/client2/sock
May 13 08:56:10 openvpn 84142 Initialization Sequence Completed
May 13 08:56:10 openvpn 84142 WARNING: this configuration may cache passwords in memory -- use the auth-nocache option to prevent this
May 13 08:56:10 openvpn 84142 /usr/local/sbin/ovpn-linkup ovpnc2 1500 1658 <VPN private IP> 255.255.255.0 init
May 13 08:56:10 openvpn 84142 /sbin/route add -net <VPN private IP> <VPN private IP> 255.255.255.0
May 13 08:56:10 openvpn 84142 /sbin/ifconfig ovpnc2 <VPN private IP> <VPN private IP> mtu 1500 netmask 255.255.255.0 up
May 13 08:56:10 openvpn 84142 TUN/TAP device /dev/tun2 opened
May 13 08:56:10 openvpn 84142 TUN/TAP device ovpnc2 exists previously, keep at program end
May 13 08:56:10 openvpn 84142 Incoming Data Channel: Using 512 bit message hash 'SHA512' for HMAC authentication
May 13 08:56:10 openvpn 84142 Incoming Data Channel: Cipher 'AES-256-CBC' initialized with 256 bit key
May 13 08:56:10 openvpn 84142 Outgoing Data Channel: Using 512 bit message hash 'SHA512' for HMAC authentication
May 13 08:56:10 openvpn 84142 Outgoing Data Channel: Cipher 'AES-256-CBC' initialized with 256 bit key
May 13 08:56:10 openvpn 84142 Using peer cipher 'AES-256-CBC'
May 13 08:56:10 openvpn 84142 OPTIONS IMPORT: adjusting link_mtu to 1658
May 13 08:56:10 openvpn 84142 OPTIONS IMPORT: peer-id set
May 13 08:56:10 openvpn 84142 OPTIONS IMPORT: route-related options modified
May 13 08:56:10 openvpn 84142 OPTIONS IMPORT: --ifconfig/up options modified
May 13 08:56:10 openvpn 84142 Socket Buffers: R=[65700->524288] S=[65700->524288]
May 13 08:56:10 openvpn 84142 OPTIONS IMPORT: --sndbuf/--rcvbuf options modified
May 13 08:56:10 openvpn 84142 OPTIONS IMPORT: compression parms modified
May 13 08:56:10 openvpn 84142 OPTIONS IMPORT: --explicit-exit-notify can only be used with --proto udp
May 13 08:56:10 openvpn 84142 OPTIONS IMPORT: timers and/or timeouts modified
May 13 08:56:10 openvpn 84142 Options error: option 'dhcp-option' cannot be used in this context ([PUSH-OPTIONS])
May 13 08:56:10 openvpn 84142 Options error: option 'dhcp-option' cannot be used in this context ([PUSH-OPTIONS])
May 13 08:56:10 openvpn 84142 Options error: option 'redirect-gateway' cannot be used in this context ([PUSH-OPTIONS])
May 13 08:56:10 openvpn 84142 PUSH: Received control message: 'PUSH_REPLY,redirect-gateway def1,dhcp-option DNS <VPN DNS IP>,dhcp-option DNS <VPN DNS IP>,sndbuf 524288,rcvbuf 524288,explicit-exit-notify,comp-lzo no,route-gateway <VPN private IP>,topology subnet,ping 60,ping-restart 180,ifconfig <VPN private IP> 255.255.255.0,peer-id 0'
May 13 08:56:10 openvpn 84142 SENT CONTROL [nnn.nordvpn.com]: 'PUSH_REQUEST' (status=1)
May 13 08:56:09 openvpn 84142 [nnn.nordvpn.com] Peer Connection Initiated with [AF_INET]<NordVPN Server IP>:443
May 13 08:56:09 openvpn 84142 Control Channel: TLSv1.3, cipher TLSv1.3 TLS_AES_256_GCM_SHA384, peer certificate: 4096 bit RSA, signature: RSA-SHA512
May 13 08:56:09 openvpn 84142 WARNING: 'comp-lzo' is present in remote config but missing in local config, remote='comp-lzo'
May 13 08:56:09 openvpn 84142 WARNING: 'link-mtu' is used inconsistently, local='link-mtu 1635', remote='link-mtu 1636'
May 13 08:56:08 openvpn 84142 VERIFY OK: depth=0, CN=nnn.nordvpn.com
May 13 08:56:08 openvpn 84142 VERIFY EKU OK
May 13 08:56:08 openvpn 84142 ++ Certificate has EKU (str) TLS Web Server Authentication, expects TLS Web Server Authentication
May 13 08:56:08 openvpn 84142 Validating certificate extended key usage
May 13 08:56:08 openvpn 84142 VERIFY KU OK
May 13 08:56:08 openvpn 84142 VERIFY OK: depth=1, C=PA, O=NordVPN, CN=NordVPN CA7
May 13 08:56:08 openvpn 84142 VERIFY OK: depth=2, C=PA, O=NordVPN, CN=NordVPN Root CA
May 13 08:56:08 openvpn 84142 VERIFY WARNING: depth=2, unable to get certificate CRL: C=PA, O=NordVPN, CN=NordVPN Root CA
May 13 08:56:08 openvpn 84142 VERIFY WARNING: depth=1, unable to get certificate CRL: C=PA, O=NordVPN, CN=NordVPN CA7
May 13 08:56:08 openvpn 84142 VERIFY WARNING: depth=0, unable to get certificate CRL: CN=nnn.nordvpn.com
May 13 08:56:08 openvpn 84142 TLS: Initial packet from [AF_INET]<NordVPN Server IP>:443, sid=3dd15799 cec3cf88
May 13 08:56:08 openvpn 84142 TCPv4_CLIENT link remote: [AF_INET]<NordVPN Server IP>:443
May 13 08:56:08 openvpn 84142 TCPv4_CLIENT link local (bound): [AF_INET]<my wan IP>:0
May 13 08:56:08 openvpn 84142 TCP connection established with [AF_INET]<NordVPN Server IP>:443
May 13 08:56:08 openvpn 84142 Attempting to establish TCP connection with [AF_INET]<NordVPN Server IP>:443 [nonblock]
May 13 08:56:08 openvpn 84142 Socket Buffers: R=[65228->65228] S=[65228->65228]
May 13 08:56:08 openvpn 84142 TCP/UDP: Preserving recently used remote address: [AF_INET]<NordVPN Server IP>:443
May 13 08:56:08 openvpn 84142 Incoming Control Channel Authentication: Using 512 bit message hash 'SHA512' for HMAC authentication
May 13 08:56:08 openvpn 84142 Outgoing Control Channel Authentication: Using 512 bit message hash 'SHA512' for HMAC authentication
May 13 08:56:08 openvpn 84142 WARNING: experimental option --capath /var/etc/openvpn/client2/ca
May 13 08:56:08 openvpn 84142 NOTE: the current --script-security setting may allow this configuration to call user-defined scripts
May 13 08:56:08 openvpn 84142 MANAGEMENT: unix domain socket listening on /var/etc/openvpn/client2/sock
May 13 08:56:08 openvpn 84133 library versions: OpenSSL 1.1.1l-freebsd 24 Aug 2021, LZO 2.10
May 13 08:56:08 openvpn 84133 OpenVPN 2.5.4 amd64-portbld-freebsd12.3 [SSL (OpenSSL)] [LZO] [LZ4] [MH/RECVDA] [AEAD] built on Jan 12 2022
May 13 08:56:08 openvpn 84133 WARNING: file '/var/etc/openvpn/client2/up' is group or others accessible
May 13 08:56:08 openvpn 73391 SIGTERM[hard,] received, process exiting
May 13 08:56:08 openvpn 73391 /usr/local/sbin/ovpn-linkdown ovpnc2 1500 1658 <VPN private IP> 255.255.255.0 init
May 13 08:56:08 openvpn 73391 Closing TUN/TAP interface
May 13 08:56:08 openvpn 73391 event_wait : Interrupted system call (code=4)
May 13 08:56:01 openvpn 73391 MANAGEMENT: Client disconnected
May 13 08:56:01 openvpn 73391 MANAGEMENT: CMD 'status 2'
May 13 08:56:01 openvpn 73391 MANAGEMENT: CMD 'state 1'
May 13 08:56:01 openvpn 73391 MANAGEMENT: Client connected from /var/etc/openvpn/client2/sock
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment