100 Mbit Down / 100 Mbit Up LeitungCPU: Xeon E-2136 @3.30 GHz (12 cores)RAM: 32 GBStorage: SSD
100 Mbit Down / 20 Mbit Up LeitungLaptop mit i7-4700MQ 16 GB RAMM.2 SSD
Remote Access (SSL/TLS + User Auth)UDPtunDH Parameter: 4096 bitVerschlüsselung: AES-256-CBCAuthentifizierungs-Digestalgorithmus: SHA512 (512-bit)Komprimierung deaktiviert (hat bereits etwas mehr gebracht als auf default)
Evtl. ist doch der Client dein Problem?Und ja die RA Variante war in unseren Tests auch etwas weniger performant als Peer2Peer.
OpenVPN:Jul 2 10:25:50 SRVHTOPNSENSE002 openvpn[73738]: <clientIP>:55963 TLS: Initial packet from [AF_INET]<clientIP>:55963, sid=64020537 d55106c3Jul 2 10:25:50 SRVHTOPNSENSE002 openvpn[73738]: <clientIP>:55963 VERIFY SCRIPT OK: depth=1, <Zertifikatspfad>, CN=OPNsense-RootCAJul 2 10:25:50 SRVHTOPNSENSE002 openvpn[73738]: <clientIP>:55963 VERIFY OK: depth=1, <Zertifikatspfad>, CN=OPNsense-RootCAJul 2 10:25:50 SRVHTOPNSENSE002 openvpn[73738]: <clientIP>:55963 VERIFY SCRIPT OK: depth=0, <Zertifikatspfad>, CN=TestUserJul 2 10:25:50 SRVHTOPNSENSE002 openvpn[73738]: <clientIP>:55963 VERIFY OK: depth=0, <Zertifikatspfad>, CN=TestUserJul 2 10:25:50 SRVHTOPNSENSE002 openvpn[73738]: <clientIP>:55963 peer info: IV_VER=2.4.7 xxxxxxJul 2 10:25:50 SRVHTOPNSENSE002 openvpn[73738]: <clientIP>:55963 peer info: IV_PLAT=winJul 2 10:25:50 SRVHTOPNSENSE002 openvpn[73738]: <clientIP>:55963 peer info: IV_PROTO=2Jul 2 10:25:50 SRVHTOPNSENSE002 openvpn[73738]: <clientIP>:55963 peer info: IV_NCP=2Jul 2 10:25:50 SRVHTOPNSENSE002 openvpn[73738]: <clientIP>:55963 peer info: IV_LZ4=1Jul 2 10:25:50 SRVHTOPNSENSE002 openvpn[73738]: <clientIP>:55963 peer info: IV_LZ4v2=1Jul 2 10:25:50 SRVHTOPNSENSE002 openvpn[73738]: <clientIP>:55963 peer info: IV_LZO=1Jul 2 10:25:50 SRVHTOPNSENSE002 openvpn[73738]: <clientIP>:55963 peer info: IV_COMP_STUB=1Jul 2 10:25:50 SRVHTOPNSENSE002 openvpn[73738]: <clientIP>:55963 peer info: IV_COMP_STUBv2=1Jul 2 10:25:50 SRVHTOPNSENSE002 openvpn[73738]: <clientIP>:55963 peer info: IV_TCPNL=1Jul 2 10:25:50 SRVHTOPNSENSE002 openvpn[73738]: <clientIP>:55963 peer info: IV_GUI_VER=OpenVPN_GUI_11 xxxxxx Fehlt bei Pritunl komplettJul 2 10:25:50 SRVHTOPNSENSE002 openvpn: user 'TestUser' authenticated using 'LDAP-IT DC005'Jul 2 10:25:50 SRVHTOPNSENSE002 openvpn[73738]: <clientIP>:55963 TLS: Username/Password authentication succeeded for username 'TestUser' [CN SET]Jul 2 10:25:50 SRVHTOPNSENSE002 openvpn[73738]: <clientIP>:55963 Control Channel: TLSv1.2, cipher TLSv1/SSLv3 ECDHE-RSA-AES256-GCM-SHA384, 8192 bit RSAJul 2 10:25:50 SRVHTOPNSENSE002 openvpn[73738]: <clientIP>:55963 [TestUser] Peer Connection Initiated with [AF_INET]<clientIP>:55963Jul 2 10:25:50 SRVHTOPNSENSE002 openvpn[73738]: TestUser/<clientIP>:55963 MULTI_sva: pool returned IPv4=10.100.130.6, IPv6=(Not enabled)Jul 2 10:25:50 SRVHTOPNSENSE002 openvpn[73738]: TestUser/<clientIP>:55963 MULTI: Learn: 10.100.130.6 -> TestUser/<clientIP>:55963Jul 2 10:25:50 SRVHTOPNSENSE002 openvpn[73738]: TestUser/<clientIP>:55963 MULTI: primary virtual IP for TestUser/<clientIP>:55963: 10.100.130.6Jul 2 10:25:51 SRVHTOPNSENSE002 openvpn[73738]: TestUser/<clientIP>:55963 PUSH: Received control message: 'PUSH_REQUEST'Jul 2 10:25:51 SRVHTOPNSENSE002 openvpn[73738]: TestUser/<clientIP>:55963 SENT CONTROL [TestUser]: 'PUSH_REPLY,<Routenconfigs etc>ifconfig 10.100.130.6 10.100.130.5,peer-id 0,cipher AES-256-GCM' (status=1)Jul 2 10:25:51 SRVHTOPNSENSE002 openvpn[73738]: TestUser/<clientIP>:55963 Outgoing Data Channel: Cipher 'AES-256-GCM' initialized with 256 bit keyJul 2 10:25:51 SRVHTOPNSENSE002 openvpn[73738]: TestUser/<clientIP>:55963 Incoming Data Channel: Cipher 'AES-256-GCM' initialized with 256 bit keyPritunl:Jul 2 10:27:51 SRVHTOPNSENSE002 openvpn[73738]: <clientIP>:51399 TLS: Initial packet from [AF_INET]<clientIP>:51399, sid=b373918f d4eeeea8Jul 2 10:27:52 SRVHTOPNSENSE002 openvpn[73738]: <clientIP>:51399 VERIFY SCRIPT OK: depth=1, <Zertifikatspfad>, CN=OPNsense-RootCAJul 2 10:27:52 SRVHTOPNSENSE002 openvpn[73738]: <clientIP>:51399 VERIFY OK: depth=1, <Zertifikatspfad>, CN=OPNsense-RootCAJul 2 10:27:52 SRVHTOPNSENSE002 openvpn[73738]: <clientIP>:51399 VERIFY SCRIPT OK: depth=0, <Zertifikatspfad>, CN=TestUserJul 2 10:27:52 SRVHTOPNSENSE002 openvpn[73738]: <clientIP>:51399 VERIFY OK: depth=0, <Zertifikatspfad>, CN=TestUserJul 2 10:27:52 SRVHTOPNSENSE002 openvpn[73738]: <clientIP>:51399 peer info: IV_VER=2.4.6 xxxxxxJul 2 10:27:52 SRVHTOPNSENSE002 openvpn[73738]: <clientIP>:51399 peer info: IV_PLAT=winJul 2 10:27:52 SRVHTOPNSENSE002 openvpn[73738]: <clientIP>:51399 peer info: IV_PROTO=2Jul 2 10:27:52 SRVHTOPNSENSE002 openvpn[73738]: <clientIP>:51399 peer info: IV_NCP=2Jul 2 10:27:52 SRVHTOPNSENSE002 openvpn[73738]: <clientIP>:51399 peer info: IV_LZ4=1Jul 2 10:27:52 SRVHTOPNSENSE002 openvpn[73738]: <clientIP>:51399 peer info: IV_LZ4v2=1Jul 2 10:27:52 SRVHTOPNSENSE002 openvpn[73738]: <clientIP>:51399 peer info: IV_LZO=1Jul 2 10:27:52 SRVHTOPNSENSE002 openvpn[73738]: <clientIP>:51399 peer info: IV_COMP_STUB=1Jul 2 10:27:52 SRVHTOPNSENSE002 openvpn[73738]: <clientIP>:51399 peer info: IV_COMP_STUBv2=1Jul 2 10:27:52 SRVHTOPNSENSE002 openvpn[73738]: <clientIP>:51399 peer info: IV_TCPNL=1Jul 2 10:27:52 SRVHTOPNSENSE002 openvpn: user 'TestUser' authenticated using 'LDAP-IT DC005'Jul 2 10:27:52 SRVHTOPNSENSE002 openvpn[73738]: <clientIP>:51399 TLS: Username/Password authentication succeeded for username 'TestUser' [CN SET]Jul 2 10:27:52 SRVHTOPNSENSE002 openvpn[73738]: <clientIP>:51399 Control Channel: TLSv1.2, cipher TLSv1/SSLv3 ECDHE-RSA-AES256-GCM-SHA384, 8192 bit RSAJul 2 10:27:52 SRVHTOPNSENSE002 openvpn[73738]: <clientIP>:51399 [TestUser] Peer Connection Initiated with [AF_INET]<clientIP>:51399Jul 2 10:27:52 SRVHTOPNSENSE002 openvpn[73738]: TestUser/<clientIP>:51399 MULTI_sva: pool returned IPv4=10.100.130.10, IPv6=(Not enabled)Jul 2 10:27:52 SRVHTOPNSENSE002 openvpn[73738]: TestUser/<clientIP>:51399 MULTI: Learn: 10.100.130.10 -> TestUser/<clientIP>:51399Jul 2 10:27:52 SRVHTOPNSENSE002 openvpn[73738]: TestUser/<clientIP>:51399 MULTI: primary virtual IP for TestUser/<clientIP>:51399: 10.100.130.10Jul 2 10:27:53 SRVHTOPNSENSE002 openvpn[73738]: TestUser/<clientIP>:51399 PUSH: Received control message: 'PUSH_REQUEST'Jul 2 10:27:53 SRVHTOPNSENSE002 openvpn[73738]: TestUser/<clientIP>:51399 SENT CONTROL [TestUser]: 'PUSH_REPLY,<Routenconfigs etc>ifconfig 10.100.130.10 10.100.130.9,peer-id 1,cipher AES-256-GCM' (status=1)Jul 2 10:27:53 SRVHTOPNSENSE002 openvpn[73738]: TestUser/<clientIP>:51399 Outgoing Data Channel: Cipher 'AES-256-GCM' initialized with 256 bit keyJul 2 10:27:53 SRVHTOPNSENSE002 openvpn[73738]: TestUser/<clientIP>:51399 Incoming Data Channel: Cipher 'AES-256-GCM' initialized with 256 bit key
Du könntest dir die Implementierung von Softether anschauen, die spricht viele Protokolle: https://www.softether.org/Oder testweise mal den VPN-Client von Securepoint probieren, der basiert aber zu Teilen auch auf OpenVPN: https://www.securepoint.de/produkte/utm-firewalls/vpn-client.html
Jul 2 11:14:28 SRVHTOPNSENSE002 openvpn[73738]: <ÖffentlicheClientIP>:58026 TLS: Initial packet from [AF_INET]<ÖffentlicheClientIP>:58026, sid=c874de59 ebb786dcJul 2 11:14:28 SRVHTOPNSENSE002 openvpn[73738]: <ÖffentlicheClientIP>:58026 VERIFY SCRIPT OK: depth=1, <Zertifikatspfad>, CN=OPNsense-RootCAJul 2 11:14:28 SRVHTOPNSENSE002 openvpn[73738]: <ÖffentlicheClientIP>:58026 VERIFY OK: depth=1, <Zertifikatspfad>, CN=OPNsense-RootCAJul 2 11:14:28 SRVHTOPNSENSE002 openvpn[73738]: <ÖffentlicheClientIP>:58026 VERIFY SCRIPT OK: depth=0, <Zertifikatspfad>, CN=TestUserJul 2 11:14:28 SRVHTOPNSENSE002 openvpn[73738]: <ÖffentlicheClientIP>:58026 VERIFY OK: depth=0, <Zertifikatspfad>, CN=TestUserJul 2 11:14:28 SRVHTOPNSENSE002 openvpn[73738]: <ÖffentlicheClientIP>:58026 peer info: IV_VER=2.4.6Jul 2 11:14:28 SRVHTOPNSENSE002 openvpn[73738]: <ÖffentlicheClientIP>:58026 peer info: IV_PLAT=winJul 2 11:14:28 SRVHTOPNSENSE002 openvpn[73738]: <ÖffentlicheClientIP>:58026 peer info: IV_PROTO=2Jul 2 11:14:28 SRVHTOPNSENSE002 openvpn[73738]: <ÖffentlicheClientIP>:58026 peer info: IV_NCP=2Jul 2 11:14:28 SRVHTOPNSENSE002 openvpn[73738]: <ÖffentlicheClientIP>:58026 peer info: IV_LZ4=1Jul 2 11:14:28 SRVHTOPNSENSE002 openvpn[73738]: <ÖffentlicheClientIP>:58026 peer info: IV_LZ4v2=1Jul 2 11:14:28 SRVHTOPNSENSE002 openvpn[73738]: <ÖffentlicheClientIP>:58026 peer info: IV_LZO=1Jul 2 11:14:28 SRVHTOPNSENSE002 openvpn[73738]: <ÖffentlicheClientIP>:58026 peer info: IV_COMP_STUB=1Jul 2 11:14:28 SRVHTOPNSENSE002 openvpn[73738]: <ÖffentlicheClientIP>:58026 peer info: IV_COMP_STUBv2=1Jul 2 11:14:28 SRVHTOPNSENSE002 openvpn[73738]: <ÖffentlicheClientIP>:58026 peer info: IV_TCPNL=1Jul 2 11:14:28 SRVHTOPNSENSE002 openvpn: user 'TestUser' authenticated using 'LDAP-IT DC005'Jul 2 11:14:28 SRVHTOPNSENSE002 openvpn[73738]: <ÖffentlicheClientIP>:58026 TLS: Username/Password authentication succeeded for username 'TestUser' [CN SET]Jul 2 11:14:28 SRVHTOPNSENSE002 openvpn[73738]: <ÖffentlicheClientIP>:58026 Control Channel: TLSv1.2, cipher TLSv1/SSLv3 DHE-RSA-AES256-GCM-SHA384, 8192 bit RSAJul 2 11:14:28 SRVHTOPNSENSE002 openvpn[73738]: <ÖffentlicheClientIP>:58026 [TestUser] Peer Connection Initiated with [AF_INET]<ÖffentlicheClientIP>:58026Jul 2 11:14:28 SRVHTOPNSENSE002 openvpn[73738]: TestUser/<ÖffentlicheClientIP>:58026 MULTI_sva: pool returned IPv4=10.100.130.6, IPv6=(Not enabled)Jul 2 11:14:28 SRVHTOPNSENSE002 openvpn[73738]: TestUser/<ÖffentlicheClientIP>:58026 MULTI: Learn: 10.100.130.6 -> TestUser/<ÖffentlicheClientIP>:58026Jul 2 11:14:28 SRVHTOPNSENSE002 openvpn[73738]: TestUser/<ÖffentlicheClientIP>:58026 MULTI: primary virtual IP for TestUser/<ÖffentlicheClientIP>:58026: 10.100.130.6Jul 2 11:14:29 SRVHTOPNSENSE002 openvpn[73738]: TestUser/<ÖffentlicheClientIP>:58026 PUSH: Received control message: 'PUSH_REQUEST'Jul 2 11:14:29 SRVHTOPNSENSE002 openvpn[73738]: TestUser/<ÖffentlicheClientIP>:58026 SENT CONTROL [TestUser]: 'PUSH_REPLY,<Routenconfigs etc>,ifconfig 10.100.130.6 10.100.130.5,peer-id 0,cipher AES-256-GCM' (status=1)Jul 2 11:14:29 SRVHTOPNSENSE002 openvpn[73738]: TestUser/<ÖffentlicheClientIP>:58026 Outgoing Data Channel: Cipher 'AES-256-GCM' initialized with 256 bit keyJul 2 11:14:29 SRVHTOPNSENSE002 openvpn[73738]: TestUser/<ÖffentlicheClientIP>:58026 Incoming Data Channel: Cipher 'AES-256-GCM' initialized with 256 bit keyJul 2 11:14:58 SRVHTOPNSENSE002 openvpn[73738]: MANAGEMENT: Client connected from /var/etc/openvpn/server1.sockJul 2 11:14:58 SRVHTOPNSENSE002 openvpn[73738]: MANAGEMENT: CMD 'status 2'Jul 2 11:14:58 SRVHTOPNSENSE002 openvpn[73738]: MANAGEMENT: CMD 'quit'Jul 2 11:14:58 SRVHTOPNSENSE002 openvpn[73738]: MANAGEMENT: Client disconnectedJul 2 11:16:03 SRVHTOPNSENSE002 openvpn[73738]: MANAGEMENT: Client connected from /var/etc/openvpn/server1.sockJul 2 11:16:03 SRVHTOPNSENSE002 openvpn[73738]: MANAGEMENT: CMD 'status 2'Jul 2 11:16:03 SRVHTOPNSENSE002 openvpn[73738]: MANAGEMENT: CMD 'quit'Jul 2 11:16:03 SRVHTOPNSENSE002 openvpn[73738]: MANAGEMENT: Client disconnectedJul 2 11:16:12 SRVHTOPNSENSE002 openvpn[73738]: TestUser/<ÖffentlicheClientIP>:51989 [TestUser] Inactivity timeout (--ping-restart), restartingJul 2 11:16:12 SRVHTOPNSENSE002 openvpn[73738]: TestUser/<ÖffentlicheClientIP>:51989 SIGUSR1[soft,ping-restart] received, client-instance restartingJul 2 11:16:33 SRVHTOPNSENSE002 openvpn[79711]: NOTE: the current --script-security setting may allow this configuration to call user-defined scriptsJul 2 11:16:33 SRVHTOPNSENSE002 openvpn[79711]: TCP/UDP: Preserving recently used remote address: [AF_INET]<ÖffentlicheClientIP>:30383Jul 2 11:16:33 SRVHTOPNSENSE002 openvpn[79711]: Preserving previous TUN/TAP instance: ovpns9Jul 2 11:16:33 SRVHTOPNSENSE002 openvpn[79711]: TCP/UDP: Preserving recently used remote address: [AF_INET]<ÖffentlicheClientIP>:30383Jul 2 11:16:33 SRVHTOPNSENSE002 openvpn[79711]: Could not determine IPv4/IPv6 protocol. Using AF_INETJul 2 11:16:33 SRVHTOPNSENSE002 openvpn[79711]: UDPv4 link local (bound): [AF_INET]<ÖffentlicheServerIP>:7223Jul 2 11:16:33 SRVHTOPNSENSE002 openvpn[79711]: UDPv4 link remote: [AF_INET]<ÖffentlicheClientIP>:30383Jul 2 11:17:08 SRVHTOPNSENSE002 openvpn[73738]: MANAGEMENT: Client connected from /var/etc/openvpn/server1.sockJul 2 11:17:08 SRVHTOPNSENSE002 openvpn[73738]: MANAGEMENT: CMD 'status 2'Jul 2 11:17:08 SRVHTOPNSENSE002 openvpn[73738]: MANAGEMENT: CMD 'quit'Jul 2 11:17:08 SRVHTOPNSENSE002 openvpn[73738]: MANAGEMENT: Client disconnectedJul 2 11:17:33 SRVHTOPNSENSE002 openvpn[79711]: [UNDEF] Inactivity timeout (--ping-restart), restartingJul 2 11:17:33 SRVHTOPNSENSE002 openvpn[79711]: SIGUSR1[soft,ping-restart] received, process restartingJul 2 11:18:13 SRVHTOPNSENSE002 openvpn[73738]: MANAGEMENT: Client connected from /var/etc/openvpn/server1.sockJul 2 11:18:13 SRVHTOPNSENSE002 openvpn[73738]: MANAGEMENT: CMD 'status 2'Jul 2 11:18:13 SRVHTOPNSENSE002 openvpn[73738]: MANAGEMENT: CMD 'quit'Jul 2 11:18:13 SRVHTOPNSENSE002 openvpn[73738]: MANAGEMENT: Client disconnected