Obi-Wahn DD-WRT Novice
Joined: 21 Jun 2017 Posts: 3
|
Posted: Wed Jun 21, 2017 13:07 Post subject: Can't get OpenVPN to work |
|
Hi!
So, I want to connect to my home network for two reasons:
a.) Occasionally I need to print on my printer which is connected via LAN to my router
b.) I need to access shares on my pc.
All of that (mostly) with my android phone using the apps "HP everyday papers" and "Total Commander" with LAN plugin.
I configured OpenVPN accordingly to the tutorial in the 2nd post (https://www.dd-wrt.com/phpBB2/viewtopic.php?t=304754) but I can't get a connection.
When I look at the log, it says that I'll get a "TLS Error: TLS handshake failed".
Code: | 2017-06-21 14:55:59 New OpenVPN Status (VPN_GENERATE_CONFIG->LEVEL_START):
2017-06-21 14:55:59 New OpenVPN Status (VPN_GENERATE_CONFIG->LEVEL_START):
2017-06-21 14:55:59 started Socket Thread
2017-06-21 14:55:59 Netzwerkstatus: CONNECTED LTE to MOBILE a1.net
2017-06-21 14:55:59 Debug state info: CONNECTED LTE to MOBILE a1.net, pause: userPause, shouldbeconnected: true, network: SHOULDBECONNECTED
2017-06-21 14:55:59 Debug state info: CONNECTED LTE to MOBILE a1.net, pause: userPause, shouldbeconnected: true, network: SHOULDBECONNECTED
2017-06-21 14:55:59 P:Initializing Google Breakpad!
2017-06-21 14:55:59 Current Parameter Settings:
2017-06-21 14:55:59 config = '/data/user/0/de.blinkt.openvpn/cache/android.conf'
2017-06-21 14:55:59 Warte 0s Sekunden zwischen zwei Verbindungsversuchen
2017-06-21 14:55:59 mode = 0
2017-06-21 14:55:59 show_ciphers = DISABLED
2017-06-21 14:55:59 show_digests = DISABLED
2017-06-21 14:55:59 show_engines = DISABLED
2017-06-21 14:55:59 genkey = DISABLED
2017-06-21 14:55:59 key_pass_file = '[UNDEF]'
2017-06-21 14:55:59 show_tls_ciphers = DISABLED
2017-06-21 14:55:59 connect_retry_max = 0
2017-06-21 14:55:59 Connection profiles [0]:
2017-06-21 14:55:59 proto = tcp-client
2017-06-21 14:55:59 local = '[UNDEF]'
2017-06-21 14:55:59 local_port = '[UNDEF]'
2017-06-21 14:55:59 remote = '<ddns>'
2017-06-21 14:55:59 remote_port = '1194'
2017-06-21 14:55:59 remote_float = DISABLED
2017-06-21 14:55:59 bind_defined = DISABLED
2017-06-21 14:55:59 bind_local = DISABLED
2017-06-21 14:55:59 bind_ipv6_only = DISABLED
2017-06-21 14:55:59 connect_retry_seconds = 2
2017-06-21 14:55:59 connect_timeout = 120
2017-06-21 14:55:59 socks_proxy_server = '[UNDEF]'
2017-06-21 14:55:59 socks_proxy_port = '[UNDEF]'
2017-06-21 14:55:59 tun_mtu = 1500
2017-06-21 14:55:59 tun_mtu_defined = ENABLED
2017-06-21 14:55:59 link_mtu = 1500
2017-06-21 14:55:59 link_mtu_defined = DISABLED
2017-06-21 14:55:59 tun_mtu_extra = 0
2017-06-21 14:55:59 tun_mtu_extra_defined = DISABLED
2017-06-21 14:55:59 mtu_discover_type = -1
2017-06-21 14:55:59 fragment = 0
2017-06-21 14:55:59 mssfix = 1450
2017-06-21 14:55:59 explicit_exit_notification = 0
2017-06-21 14:55:59 Connection profiles END
2017-06-21 14:55:59 remote_random = DISABLED
2017-06-21 14:55:59 ipchange = '[UNDEF]'
2017-06-21 14:55:59 dev = 'tun'
2017-06-21 14:55:59 dev_type = '[UNDEF]'
2017-06-21 14:55:59 dev_node = '[UNDEF]'
2017-06-21 14:55:59 lladdr = '[UNDEF]'
2017-06-21 14:55:59 topology = 1
2017-06-21 14:55:59 ifconfig_local = '[UNDEF]'
2017-06-21 14:55:59 ifconfig_remote_netmask = '[UNDEF]'
2017-06-21 14:55:59 ifconfig_noexec = DISABLED
2017-06-21 14:55:59 ifconfig_nowarn = ENABLED
2017-06-21 14:55:59 ifconfig_ipv6_local = '[UNDEF]'
2017-06-21 14:55:59 ifconfig_ipv6_netbits = 0
2017-06-21 14:55:59 ifconfig_ipv6_remote = '[UNDEF]'
2017-06-21 14:55:59 shaper = 0
2017-06-21 14:55:59 mtu_test = 0
2017-06-21 14:55:59 mlock = DISABLED
2017-06-21 14:55:59 keepalive_ping = 0
2017-06-21 14:55:59 keepalive_timeout = 0
2017-06-21 14:55:59 inactivity_timeout = 0
2017-06-21 14:55:59 ping_send_timeout = 0
2017-06-21 14:55:59 ping_rec_timeout = 0
2017-06-21 14:55:59 ping_rec_timeout_action = 0
2017-06-21 14:55:59 ping_timer_remote = DISABLED
2017-06-21 14:55:59 remap_sigusr1 = 0
2017-06-21 14:55:59 persist_tun = DISABLED
2017-06-21 14:55:59 persist_local_ip = DISABLED
2017-06-21 14:55:59 persist_remote_ip = DISABLED
2017-06-21 14:55:59 persist_key = DISABLED
2017-06-21 14:55:59 passtos = DISABLED
2017-06-21 14:55:59 resolve_retry_seconds = 60
2017-06-21 14:55:59 resolve_in_advance = DISABLED
2017-06-21 14:55:59 username = '[UNDEF]'
2017-06-21 14:55:59 groupname = '[UNDEF]'
2017-06-21 14:55:59 chroot_dir = '[UNDEF]'
2017-06-21 14:55:59 cd_dir = '[UNDEF]'
2017-06-21 14:55:59 writepid = '[UNDEF]'
2017-06-21 14:55:59 up_script = '[UNDEF]'
2017-06-21 14:55:59 down_script = '[UNDEF]'
2017-06-21 14:55:59 down_pre = DISABLED
2017-06-21 14:55:59 up_restart = DISABLED
2017-06-21 14:55:59 up_delay = DISABLED
2017-06-21 14:55:59 daemon = DISABLED
2017-06-21 14:55:59 inetd = 0
2017-06-21 14:55:59 log = DISABLED
2017-06-21 14:55:59 suppress_timestamps = DISABLED
2017-06-21 14:55:59 machine_readable_output = ENABLED
2017-06-21 14:55:59 nice = 0
2017-06-21 14:55:59 verbosity = 4
2017-06-21 14:55:59 mute = 0
2017-06-21 14:55:59 gremlin = 0
2017-06-21 14:55:59 status_file = '[UNDEF]'
2017-06-21 14:55:59 status_file_version = 1
2017-06-21 14:55:59 status_file_update_freq = 60
2017-06-21 14:55:59 occ = ENABLED
2017-06-21 14:55:59 rcvbuf = 0
2017-06-21 14:55:59 sndbuf = 0
2017-06-21 14:55:59 sockflags = 0
2017-06-21 14:55:59 fast_io = DISABLED
2017-06-21 14:55:59 comp.alg = 2
2017-06-21 14:55:59 comp.flags = 1
2017-06-21 14:55:59 route_script = '[UNDEF]'
2017-06-21 14:55:59 route_default_gateway = '[UNDEF]'
2017-06-21 14:55:59 route_default_metric = 0
2017-06-21 14:55:59 route_noexec = DISABLED
2017-06-21 14:55:59 route_delay = 0
2017-06-21 14:55:59 route_delay_window = 30
2017-06-21 14:55:59 route_delay_defined = DISABLED
2017-06-21 14:55:59 route_nopull = DISABLED
2017-06-21 14:55:59 route_gateway_via_dhcp = DISABLED
2017-06-21 14:55:59 allow_pull_fqdn = DISABLED
2017-06-21 14:55:59 route 0.0.0.0/0.0.0.0/vpn_gateway/default (not set)
2017-06-21 14:55:59 management_addr = '/data/user/0/de.blinkt.openvpn/cache/mgmtsocket'
2017-06-21 14:55:59 management_port = 'unix'
2017-06-21 14:55:59 management_user_pass = '[UNDEF]'
2017-06-21 14:55:59 management_log_history_cache = 250
2017-06-21 14:55:59 management_echo_buffer_size = 100
2017-06-21 14:55:59 management_write_peer_info_file = '[UNDEF]'
2017-06-21 14:55:59 management_client_user = '[UNDEF]'
2017-06-21 14:55:59 management_client_group = '[UNDEF]'
2017-06-21 14:55:59 management_flags = 4902
2017-06-21 14:55:59 shared_secret_file = '[UNDEF]'
2017-06-21 14:55:59 key_direction = (null)
2017-06-21 14:55:59 ciphername = 'BF-CBC'
2017-06-21 14:55:59 ncp_enabled = ENABLED
2017-06-21 14:55:59 ncp_ciphers = 'AES-256-GCM:AES-128-GCM'
2017-06-21 14:55:59 authname = 'SHA1'
2017-06-21 14:55:59 prng_hash = 'SHA1'
2017-06-21 14:55:59 prng_nonce_secret_len = 16
2017-06-21 14:55:59 keysize = 0
2017-06-21 14:55:59 engine = DISABLED
2017-06-21 14:55:59 replay = ENABLED
2017-06-21 14:55:59 mute_replay_warnings = DISABLED
2017-06-21 14:55:59 replay_window = 64
2017-06-21 14:56:00 replay_time = 15
2017-06-21 14:56:00 packet_id_file = '[UNDEF]'
2017-06-21 14:56:00 test_crypto = DISABLED
2017-06-21 14:56:00 tls_server = DISABLED
2017-06-21 14:56:00 tls_client = ENABLED
2017-06-21 14:56:00 key_method = 2
2017-06-21 14:56:00 ca_file = '[[INLINE]]'
2017-06-21 14:56:00 ca_path = '[UNDEF]'
2017-06-21 14:56:00 dh_file = '[UNDEF]'
2017-06-21 14:56:00 cert_file = '[[INLINE]]'
2017-06-21 14:56:00 extra_certs_file = '[[INLINE]]'
2017-06-21 14:56:00 "priv_key_file" = EXTERNAL_PRIVATE_KEY
2017-06-21 14:56:00 pkcs12_file = '[UNDEF]'
2017-06-21 14:56:00 cipher_list = '[UNDEF]'
2017-06-21 14:56:00 tls_verify = '[UNDEF]'
2017-06-21 14:56:00 tls_export_cert = '[UNDEF]'
2017-06-21 14:56:00 verify_x509_type = 2
2017-06-21 14:56:00 verify_x509_name = '<ddns>'
2017-06-21 14:56:00 crl_file = '[UNDEF]'
2017-06-21 14:56:00 ns_cert_type = 0
2017-06-21 14:56:00 remote_cert_ku[i] = 0
2017-06-21 14:56:00 remote_cert_ku[i] = 0
2017-06-21 14:56:00 remote_cert_ku[i] = 0
2017-06-21 14:56:00 remote_cert_ku[i] = 0
2017-06-21 14:56:00 remote_cert_ku[i] = 0
2017-06-21 14:56:00 remote_cert_ku[i] = 0
2017-06-21 14:56:00 remote_cert_ku[i] = 0
2017-06-21 14:56:00 remote_cert_ku[i] = 0
2017-06-21 14:56:00 remote_cert_ku[i] = 0
2017-06-21 14:56:00 remote_cert_ku[i] = 0
2017-06-21 14:56:00 remote_cert_ku[i] = 0
2017-06-21 14:56:00 remote_cert_ku[i] = 0
2017-06-21 14:56:00 remote_cert_ku[i] = 0
2017-06-21 14:56:00 remote_cert_ku[i] = 0
2017-06-21 14:56:00 remote_cert_ku[i] = 0
2017-06-21 14:56:00 remote_cert_ku[i] = 0
2017-06-21 14:56:00 remote_cert_eku = '[UNDEF]'
2017-06-21 14:56:00 ssl_flags = 0
2017-06-21 14:56:00 tls_timeout = 2
2017-06-21 14:56:00 renegotiate_bytes = -1
2017-06-21 14:56:00 renegotiate_packets = 0
2017-06-21 14:56:00 renegotiate_seconds = 3600
2017-06-21 14:56:00 handshake_window = 60
2017-06-21 14:56:00 transition_window = 3600
2017-06-21 14:56:00 single_session = DISABLED
2017-06-21 14:56:00 push_peer_info = DISABLED
2017-06-21 14:56:00 tls_exit = DISABLED
2017-06-21 14:56:00 tls_auth_file = '[UNDEF]'
2017-06-21 14:56:00 tls_crypt_file = '[UNDEF]'
2017-06-21 14:56:00 client = ENABLED
2017-06-21 14:56:00 pull = ENABLED
2017-06-21 14:56:00 auth_user_pass_file = '[UNDEF]'
2017-06-21 14:56:00 OpenVPN 2.5-icsopenvpn [git:icsopenvpn-a3a71dc0a6604559] android-14-armeabi-v7a [SSL (OpenSSL)] [LZO] [LZ4] [EPOLL] [MH/PKTINFO] [AEAD] built on May 29 2017
2017-06-21 14:56:00 library versions: OpenSSL 1.0.2l 25 May 2017, LZO 2.09
2017-06-21 14:56:00 MANAGEMENT: Connected to management server at /data/user/0/de.blinkt.openvpn/cache/mgmtsocket
2017-06-21 14:56:00 MANAGEMENT: CMD 'hold release'
2017-06-21 14:56:00 MANAGEMENT: CMD 'proxy NONE'
2017-06-21 14:56:00 MANAGEMENT: CMD 'bytecount 2'
2017-06-21 14:56:00 MANAGEMENT: CMD 'state on'
2017-06-21 14:56:00 LZO compression initializing
2017-06-21 14:56:00 New OpenVPN Status (RESOLVE->LEVEL_CONNECTING_NO_SERVER_REPLY_YET): ,,,,,
2017-06-21 14:56:00 New OpenVPN Status (RESOLVE->LEVEL_CONNECTING_NO_SERVER_REPLY_YET): ,,,,,
2017-06-21 14:56:00 Control Channel MTU parms [ L:1624 D:1210 EF:40 EB:0 ET:0 EL:3 ]
2017-06-21 14:56:00 MANAGEMENT: >STATE:1498049760,RESOLVE,,,,,,
2017-06-21 14:56:01 Data Channel MTU parms [ L:1624 D:1450 EF:124 EB:406 ET:0 EL:3 ]
2017-06-21 14:56:01 New OpenVPN Status (TCP_CONNECT->LEVEL_CONNECTING_NO_SERVER_REPLY_YET): ,,,,,
2017-06-21 14:56:01 New OpenVPN Status (TCP_CONNECT->LEVEL_CONNECTING_NO_SERVER_REPLY_YET): ,,,,,
2017-06-21 14:56:01 Local Options String (VER=V4): 'V4,dev-type tun,link-mtu 1544,tun-mtu 1500,proto TCPv4_CLIENT,comp-lzo,cipher BF-CBC,auth SHA1,keysize 128,key-method 2,tls-client'
2017-06-21 14:56:01 Expected Remote Options String (VER=V4): 'V4,dev-type tun,link-mtu 1544,tun-mtu 1500,proto TCPv4_SERVER,comp-lzo,cipher BF-CBC,auth SHA1,keysize 128,key-method 2,tls-server'
2017-06-21 14:56:01 TCP/UDP: Preserving recently used remote address: [AF_INET]<WanIP>:1194
2017-06-21 14:56:01 Socket Buffers: R=[3145728->3145728] S=[3145728->3145728]
2017-06-21 14:56:01 Attempting to establish TCP connection with [AF_INET]<WanIP>:1194 [nonblock]
2017-06-21 14:56:01 MANAGEMENT: >STATE:1498049761,TCP_CONNECT,,,,,,
2017-06-21 14:56:01 MANAGEMENT: CMD 'needok 'PROTECTFD' ok'
2017-06-21 14:56:02 TCP connection established with [AF_INET]<WanIP>:1194
2017-06-21 14:56:02 MANAGEMENT: CMD 'needok 'PROTECTFD' ok'
2017-06-21 14:56:02 TCP_CLIENT link local: (not bound)
2017-06-21 14:56:02 TCP_CLIENT link remote: [AF_INET]<WanIP>:1194
2017-06-21 14:56:02 MANAGEMENT: >STATE:1498049762,WAIT,,,,,,
2017-06-21 14:56:02 New OpenVPN Status (WAIT->LEVEL_CONNECTING_NO_SERVER_REPLY_YET): ,,,,,
2017-06-21 14:56:02 New OpenVPN Status (WAIT->LEVEL_CONNECTING_NO_SERVER_REPLY_YET): ,,,,,
2017-06-21 14:56:02 New OpenVPN Status (AUTH->LEVEL_CONNECTING_SERVER_REPLIED): ,,,,,
2017-06-21 14:56:02 New OpenVPN Status (AUTH->LEVEL_CONNECTING_SERVER_REPLIED): ,,,,,
2017-06-21 14:56:02 MANAGEMENT: >STATE:1498049762,AUTH,,,,,,
2017-06-21 14:56:02 TLS: Initial packet from [AF_INET]<WanIP>:1194, sid=fba30b9e 5602cc1c
2017-06-21 14:56:03 VERIFY OK: depth=1, C=AT, ST=Wien, O=<org>, L=Wien, CN=AK, emailAddress=<eMail>
2017-06-21 14:56:03 VERIFY X509NAME ERROR: C=AT, ST=Wien, O=<org>, L=Wien, CN=Server, emailAddress=<eMail>, must be <ddns>
2017-06-21 14:56:03 OpenSSL: error:14090086:SSL routines:ssl3_get_server_certificate:certificate verify failed
2017-06-21 14:56:03 New OpenVPN Status (RECONNECTING->LEVEL_CONNECTING_NO_SERVER_REPLY_YET): tls-error,,,,,
2017-06-21 14:56:03 New OpenVPN Status (RECONNECTING->LEVEL_CONNECTING_NO_SERVER_REPLY_YET): tls-error,,,,,
2017-06-21 14:56:03 TLS_ERROR: BIO read tls_read_plaintext error
2017-06-21 14:56:03 New OpenVPN Status (CONNECTRETRY->LEVEL_CONNECTING_NO_SERVER_REPLY_YET): 2
2017-06-21 14:56:03 New OpenVPN Status (CONNECTRETRY->LEVEL_CONNECTING_NO_SERVER_REPLY_YET): 2
2017-06-21 14:56:03 TLS Error: TLS object -> incoming plaintext read error
2017-06-21 14:56:03 Warte 2s Sekunden zwischen zwei Verbindungsversuchen
2017-06-21 14:56:03 TLS Error: TLS handshake failed
2017-06-21 14:56:03 Fatal TLS error (check_tls_errors_co), restarting
2017-06-21 14:56:03 TCP/UDP: Closing socket
2017-06-21 14:56:03 SIGUSR1[soft,tls-error] received, process restarting
2017-06-21 14:56:03 MANAGEMENT: >STATE:1498049763,RECONNECTING,tls-error,,,,,
2017-06-21 14:56:05 MANAGEMENT: CMD 'hold release'
2017-06-21 14:56:05 MANAGEMENT: CMD 'proxy NONE'
2017-06-21 14:56:05 MANAGEMENT: CMD 'bytecount 2'
2017-06-21 14:56:05 MANAGEMENT: CMD 'state on'
2017-06-21 14:56:06 New OpenVPN Status (RESOLVE->LEVEL_CONNECTING_NO_SERVER_REPLY_YET): ,,,,,
2017-06-21 14:56:06 New OpenVPN Status (RESOLVE->LEVEL_CONNECTING_NO_SERVER_REPLY_YET): ,,,,,
2017-06-21 14:56:06 New OpenVPN Status (TCP_CONNECT->LEVEL_CONNECTING_NO_SERVER_REPLY_YET): ,,,,,
2017-06-21 14:56:06 New OpenVPN Status (TCP_CONNECT->LEVEL_CONNECTING_NO_SERVER_REPLY_YET): ,,,,,
2017-06-21 14:56:06 LZO compression initializing
2017-06-21 14:56:06 Control Channel MTU parms [ L:1624 D:1210 EF:40 EB:0 ET:0 EL:3 ]
2017-06-21 14:56:06 MANAGEMENT: >STATE:1498049766,RESOLVE,,,,,,
2017-06-21 14:56:06 Data Channel MTU parms [ L:1624 D:1450 EF:124 EB:406 ET:0 EL:3 ]
2017-06-21 14:56:06 Local Options String (VER=V4): 'V4,dev-type tun,link-mtu 1544,tun-mtu 1500,proto TCPv4_CLIENT,comp-lzo,cipher BF-CBC,auth SHA1,keysize 128,key-method 2,tls-client'
2017-06-21 14:56:06 Expected Remote Options String (VER=V4): 'V4,dev-type tun,link-mtu 1544,tun-mtu 1500,proto TCPv4_SERVER,comp-lzo,cipher BF-CBC,auth SHA1,keysize 128,key-method 2,tls-server'
2017-06-21 14:56:06 TCP/UDP: Preserving recently used remote address: [AF_INET]<WanIP>:1194
2017-06-21 14:56:06 Socket Buffers: R=[3145728->3145728] S=[3145728->3145728]
2017-06-21 14:56:06 Attempting to establish TCP connection with [AF_INET]<WanIP>:1194 [nonblock]
2017-06-21 14:56:06 MANAGEMENT: >STATE:1498049766,TCP_CONNECT,,,,,,
2017-06-21 14:56:06 MANAGEMENT: CMD 'needok 'PROTECTFD' ok'
2017-06-21 14:56:07 MANAGEMENT: CMD 'signal SIGINT'
2017-06-21 14:56:07 TCP/UDP: Closing socket
2017-06-21 14:56:07 SIGINT[hard,init_instance] received, process exiting
2017-06-21 14:56:07 MANAGEMENT: >STATE:1498049767,EXITING,init_instance,,,,,
2017-06-21 14:56:07 New OpenVPN Status (EXITING->LEVEL_NOTCONNECTED): init_instance,,,,,
2017-06-21 14:56:07 New OpenVPN Status (EXITING->LEVEL_NOTCONNECTED): init_instance,,,,,
2017-06-21 14:56:07 New OpenVPN Status (NOPROCESS->LEVEL_NOTCONNECTED): No process running.
2017-06-21 14:56:07 New OpenVPN Status (NOPROCESS->LEVEL_NOTCONNECTED): No process running. |
Any help is appreciated.
PS.: Yes, vpn SHOULD be running
Code: |
DD-WRT v24-sp2 std (c) 2013 NewMedia-NET GmbH
Release: 03/25/13 (SVN revision: 21061)
DD-WRT login: root
Password:
==========================================================
____ ___ __ ______ _____ ____ _ _
| _ \| _ \ \ \ / / _ \_ _| __ _|___ \| || |
|| | || ||____\ \ /\ / /| |_) || | \ \ / / __) | || |_
||_| ||_||_____\ V V / | _ < | | \ V / / __/|__ _|
|___/|___/ \_/\_/ |_| \_\|_| \_/ |_____| |_|
DD-WRT v24-sp2
http://www.dd-wrt.com
==========================================================
BusyBox v1.21.0 (2013-03-25 08:45:24 CET) built-in shell (ash)
Enter 'help' for a list of built-in commands.
root@DD-WRT:~# ps | grep vpn
7819 root 2264 S /tmp/openvpnserver --config /tmp/openvpn/openvpn.con
8247 root 1160 S grep vpn
root@DD-WRT:~# |
|
|