Menu

Show posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.

Show posts Menu

Messages - s.messias

#1
The wierd thing it's that it was working without any problem in the past month. Today when I tried to connect it, gave me the error, and we didn't make any change anywhere.
I'm going to analyse your configuration and try again a bunch of new configurations just to see the result :P

I will give a feedback when I have the time.

Thank u so much.
#2
Thast's the tutorial I used to configure the server the first time, so yeah it's very similar. The only difference is that I use on server mode Remote Access (SSL/TLS). But I already tried to reconfigure with Remote Access (User Auth)and the result is the same =/
#3
Hello

Thank you so much for the suggestion, unfortunately, I'm the 1% :P

It didn't work
#4
18.1 Legacy Series / TLS Error: TLS handshake failed
March 21, 2018, 01:49:10 PM
Hello everyone.

I'm new to this world so please be pattient :P

I have a private server in the cloud in a company that uses OPNSense firewall, so with the help of this tutorial (https://docs.opnsense.org/manual/how-tos/sslvpn_client.html) I configured an OpenVPN Server. It worked like a charm.

Now without anyone making any change it just stopped working, I can't connect to the openvpn Server. I already reconfigured the server, changed to TCP, restarted the firewall/daemon, turned off the firewall on the client side, experimented on another pc or network, but nothing, it just doesn't connect. Ohhh and I also updated OpenVPN GUI. Can you guys please help me with this? I just don't know what to do next, this is just wierd.

This is my config file:

dev tun
persist-tun
persist-key
cipher AES-256-CBC
auth SHA512
tls-client
client
resolv-retry infinite
remote 62.xx.xxx.xxx 1194 udp
lport 0
verify-x509-name "SSLVPN Server Certificate" name
pkcs12 100001402-CloudWall-udp-1194-xxxxxx.p12
tls-auth 100001402-CloudWall-udp-1194-xxxxxx-tls.key 1
ns-cert-type server
comp-lzo adaptive


Client log file:

Wed Mar 21 12:44:31 2018 OpenVPN 2.4.5 x86_64-w64-mingw32 [SSL (OpenSSL)] [LZO] [LZ4] [PKCS11] [AEAD] built on Mar  1 2018
Wed Mar 21 12:44:31 2018 Windows version 6.2 (Windows 8 or greater) 64bit
Wed Mar 21 12:44:31 2018 library versions: OpenSSL 1.1.0f  25 May 2017, LZO 2.10
Wed Mar 21 12:44:32 2018 WARNING: --ns-cert-type is DEPRECATED.  Use --remote-cert-tls instead.
Wed Mar 21 12:44:32 2018 TCP/UDP: Preserving recently used remote address: [AF_INET]62.28.222.252:1194
Wed Mar 21 12:44:32 2018 UDP link local (bound): [AF_INET][undef]:0
Wed Mar 21 12:44:32 2018 UDP link remote: [AF_INET]62.28.222.252:1194
Wed Mar 21 12:45:32 2018 TLS Error: TLS key negotiation failed to occur within 60 seconds (check your network connectivity)
Wed Mar 21 12:45:32 2018 TLS Error: TLS handshake failed
Wed Mar 21 12:45:32 2018 SIGUSR1[soft,tls-error] received, process restarting


OpenVPN Log:
Mar 21 12:45:29   openvpn[2342]: MANAGEMENT: Client disconnected
Mar 21 12:45:29   openvpn[2342]: MANAGEMENT: CMD 'quit'
Mar 21 12:45:29   openvpn[2342]: MANAGEMENT: CMD 'status 2'
Mar 21 12:45:29   openvpn[2342]: MANAGEMENT: Client connected from /var/etc/openvpn/server1.sock
Mar 21 12:44:27   openvpn[2342]: MANAGEMENT: Client disconnected
Mar 21 12:44:27   openvpn[2342]: MANAGEMENT: CMD 'quit'
Mar 21 12:44:27   openvpn[2342]: MANAGEMENT: CMD 'status 2'
Mar 21 12:44:27   openvpn[2342]: MANAGEMENT: Client connected from /var/etc/openvpn/server1.sock
Mar 21 12:43:26   openvpn[2342]: MANAGEMENT: Client disconnected
Mar 21 12:43:26   openvpn[2342]: MANAGEMENT: CMD 'quit'
Mar 21 12:43:26   openvpn[2342]: MANAGEMENT: CMD 'status 2'
Mar 21 12:43:25   openvpn[2342]: MANAGEMENT: Client connected from /var/etc/openvpn/server1.sock
Mar 21 12:42:49   openvpn[2342]: MANAGEMENT: Client disconnected
Mar 21 12:42:49   openvpn[2342]: MANAGEMENT: CMD 'status 2'
Mar 21 12:42:49   openvpn[2342]: MANAGEMENT: Client connected from /var/etc/openvpn/server1.sock
Mar 21 12:42:24   openvpn[2342]: MANAGEMENT: Client disconnected.



#5
Bom dia a todos,

Adquiri um servidor privado na Cloud que utiliza a firewall OPNSense, no qual tenho um servidor OPENVPN configurado com a ajuda dos manuais existentes no site da OPNSense. Durante um mês tudo funcionou bem, agora de um momento para o outro, sem ninguém ter alterado nada já não consigo efectuar a ligação.
Segue o log de conexão

Wed Mar 21 11:58:34 2018 OpenVPN 2.4.5 x86_64-w64-mingw32 [SSL (OpenSSL)] [LZO] [LZ4] [PKCS11] [AEAD] built on Mar  1 2018
Wed Mar 21 11:58:34 2018 Windows version 6.2 (Windows 8 or greater) 64bit
Wed Mar 21 11:58:34 2018 library versions: OpenSSL 1.1.0f  25 May 2017, LZO 2.10
Wed Mar 21 11:58:35 2018 TCP/UDP: Preserving recently used remote address: [AF_INET]62.xxx.xxx.xxx:1194
Wed Mar 21 11:58:35 2018 UDP link local (bound): [AF_INET][undef]:0
Wed Mar 21 11:58:35 2018 UDP link remote: [AF_INET]62.xxx.xxx.xxx:1194
Wed Mar 21 11:59:36 2018 TLS Error: TLS key negotiation failed to occur within 60 seconds (check your network connectivity)
Wed Mar 21 11:59:36 2018 TLS Error: TLS handshake failed
Wed Mar 21 11:59:36 2018 SIGUSR1[soft,tls-error] received, process restarting
Wed Mar 21 11:59:41 2018 TCP/UDP: Preserving recently used remote address: [AF_INET]62.xxx.xxx.xxx:1194
Wed Mar 21 11:59:41 2018 UDP link local (bound): [AF_INET][undef]:0

Log do servidor:

Mar 21 12:09:35   openvpn[74888]: MANAGEMENT: Client disconnected
Mar 21 12:09:35   openvpn[74888]: MANAGEMENT: CMD 'quit'
Mar 21 12:09:34   openvpn[74888]: MANAGEMENT: CMD 'status 2'
Mar 21 12:09:34   openvpn[74888]: MANAGEMENT: Client connected from /var/etc/openvpn/server1.sock
Mar 21 12:08:33   openvpn[74888]: MANAGEMENT: Client disconnected
Mar 21 12:08:33   openvpn[74888]: MANAGEMENT: CMD 'quit'
Mar 21 12:08:33   openvpn[74888]: MANAGEMENT: CMD 'status 2'


Já reconfigurei o servidor, verifiquei os logs na firewall e não há tráfego a ser bloqueado, reiniciei a firewall e o daemon, atualizei o openvpn, desliguei firewalls nos vários clientes, experimentei estando ligada a outras redes, e nada... Tendo em conta que não foi alterada configuração absolutamente nenhuma o que acham que possa ser?

Obrigada pela atenção.