OPNsense
  • Home
  • Help
  • Search
  • Login
  • Register

  • OPNsense Forum »
  • English Forums »
  • Virtual private networks »
  • please add tls-crypt option in openvpn
« previous next »
  • Print
Pages: [1]

Author Topic: please add tls-crypt option in openvpn  (Read 5915 times)

yon

  • Newbie
  • *
  • Posts: 17
  • Karma: 0
    • View Profile
please add tls-crypt option in openvpn
« on: February 22, 2021, 07:58:19 am »
my openvpn 2.5 using tls-crypt ta.key, pfsense has this option, but opnsense has no this.
now i using opnsense can't connect to remote openvpn when no tls-crypt.

so please add tls-crypt support.
Logged
i have bgp ASN and network, welcome peering and transit.

Gauss23

  • Hero Member
  • *****
  • Posts: 766
  • Karma: 39
    • View Profile
    • BackendMedia
Re: please add tls-crypt option in openvpn
« Reply #1 on: February 22, 2021, 09:30:01 am »
You can use the advanced settings box for the moment:
Code: [Select]
<tls-crypt>
-----BEGIN OpenVPN Static key V1-----
Your static key here
-----END OpenVPN Static key V1-----
</tls-crypt>

Works for me.
Logged
„The S in IoT stands for Security!“ :)

yon

  • Newbie
  • *
  • Posts: 17
  • Karma: 0
    • View Profile
Re: please add tls-crypt option in openvpn
« Reply #2 on: February 22, 2021, 09:36:42 am »
i creat ta.key file put in etc and config it advanced settings, uncheck default tls option. vpn can up.

but i can't ping and route connect tunnel inside ipv4 and ipv6 remote ip.

VPN still can't normal work.


Code: [Select]
ifconfig 10.16.0.2 10.16.0.1
ifconfig-ipv6 2a0d:2408:512:a::3/124 2a0d:2408:512:a::2
Logged
i have bgp ASN and network, welcome peering and transit.

Gauss23

  • Hero Member
  • *****
  • Posts: 766
  • Karma: 39
    • View Profile
    • BackendMedia
Re: please add tls-crypt option in openvpn
« Reply #3 on: February 22, 2021, 10:01:28 am »
With that amount of information you won't get any help.

Please post your OpenVPN config (without public IP/FQDN and without tls crypt).
Screenshot would be the best option.
Logged
„The S in IoT stands for Security!“ :)

yon

  • Newbie
  • *
  • Posts: 17
  • Karma: 0
    • View Profile
Re: please add tls-crypt option in openvpn
« Reply #4 on: February 22, 2021, 04:40:06 pm »
Code: [Select]
ping 2a0d:2408:512:a::2
ping: cannot resolve 2a0d:2406:512:a::2: Unknown server error

pull-filter ignore peer-id
ifconfig-ipv6 2a0d:2408:512:a::3/124 2a0d:2408:512:a::2
reneg-sec 86400
persist-key
persist-tun
link-mtu 1500
ifconfig 10.16.0.2 10.16.0.1
auth-nocache
ping-timer-rem
remote-cert-tls server
tls-version-min 1.3
sndbuf 0
rcvbuf 0
tls-crypt /etc/openvpn/ta.key

now ipv4 can ping, but ipv6 can't ping and route.
Logged
i have bgp ASN and network, welcome peering and transit.

Gauss23

  • Hero Member
  • *****
  • Posts: 766
  • Karma: 39
    • View Profile
    • BackendMedia
Re: please add tls-crypt option in openvpn
« Reply #5 on: February 22, 2021, 04:50:20 pm »
Try it with
Code: [Select]
ping6 2a0d:2408:512:a::2
Logged
„The S in IoT stands for Security!“ :)

yon

  • Newbie
  • *
  • Posts: 17
  • Karma: 0
    • View Profile
Re: please add tls-crypt option in openvpn
« Reply #6 on: February 22, 2021, 07:54:43 pm »
Quote from: Gauss23 on February 22, 2021, 04:50:20 pm
Try it with
Code: [Select]
ping6 2a0d:2408:512:a::2

ok, this command ping6 work. Thanks.   ;)
Logged
i have bgp ASN and network, welcome peering and transit.

TheChickenMan

  • Newbie
  • *
  • Posts: 7
  • Karma: 0
    • View Profile
Re: please add tls-crypt option in openvpn
« Reply #7 on: March 01, 2021, 03:16:26 am »
Quote from: Gauss23 on February 22, 2021, 09:30:01 am
You can use the advanced settings box for the moment:
Code: [Select]
<tls-crypt>
-----BEGIN OpenVPN Static key V1-----
Your static key here
-----END OpenVPN Static key V1-----
</tls-crypt>

Works for me.


I've been using this method as well but the big warning about "this feature being removed in the future" is kind of scary. Would be nice if there was just a supported field for this information in the UI.
Logged

akha666

  • Newbie
  • *
  • Posts: 1
  • Karma: 0
    • View Profile
Re: please add tls-crypt option in openvpn
« Reply #8 on: March 11, 2021, 09:41:06 pm »
 :-[ What is the bad luck, I've registered to start post about this issue. But first I search for it, to not duplicate the thread.
I had this setting in pfSense
TLS Key Usage Mode
TLS keydir direction
any workaround?, I wish to add this feature.
Logged

3spi

  • Newbie
  • *
  • Posts: 1
  • Karma: 0
    • View Profile
Re: please add tls-crypt option in openvpn
« Reply #9 on: March 28, 2021, 05:45:31 pm »
Trying to do the exact same thing. As TheChickenMan replied, I also filled in my ta.key there.

My VPN client in OpnSense is generating this as output in the logging:
2021-03-28T17:42:43   openvpn[27646]: PO_CTL rwflags=0x0001 ev=6 arg=0x00000000
2021-03-28T17:42:42   openvpn[27646]: PO_CTL rwflags=0x0001 ev=6 arg=0x00000000
2021-03-28T17:42:41   openvpn[27646]: PO_CTL rwflags=0x0001 ev=6 arg=0x00000000
2021-03-28T17:42:40   openvpn[27646]: PO_CTL rwflags=0x0001 ev=6 arg=0x00000000
2021-03-28T17:42:39   openvpn[27646]: PO_CTL rwflags=0x0001 ev=6 arg=0x00000000
2021-03-28T17:42:38   openvpn[27646]: PO_CTL rwflags=0x0001 ev=6 arg=0x00000000

The connection status stays on "connecting". It doesn't look to go any further. Also my virtual SSL VPN adapter in the dashbord doesn't show an IP. Could this ta.key be the problem as well?
Logged

  • Print
Pages: [1]
« previous next »
  • OPNsense Forum »
  • English Forums »
  • Virtual private networks »
  • please add tls-crypt option in openvpn
 

OPNsense is an OSS project © Deciso B.V. 2015 - 2024 All rights reserved
  • SMF 2.0.19 | SMF © 2021, Simple Machines
    Privacy Policy
    | XHTML | RSS | WAP2