OPNsense 23.1.9-amd64FreeBSD 13.1-RELEASE-p7OpenSSL 1.1.1t 7 Feb 2023OpenVPN 2.6.4 amd64-portbld-freebsd13.1 [SSL (OpenSSL)] [LZO] [LZ4] [PKCS11] [MH/RECVDA] [AEAD]library versions: OpenSSL 1.1.1t 7 Feb 2023, LZO 2.10
hw.model: Intel Xeon E3-12xx v2 (Ivy Bridge, IBRS)hw.machine: amd64hw.ncpu: 10last pid: 67728; load averages: 0.25, 2.12, 4.02 up 4+21:22:29 10:21:2465 processes: 1 running, 64 sleepingCPU: 0.0% user, 0.0% nice, 0.2% system, 0.2% interrupt, 99.6% idleMem: 112M Active, 2532M Inact, 2117M Wired, 1404M Buf, 26G FreeSwap: 8192M Total, 8192M Free
sendto(3,"<29>1 2023-06-07T09:21:50.719359"...,149,0,NULL,0) = 149 (0x95)__sysctl("kern.hostname",2,0x7fffffffbd80,0x7fffffff7c68,0x0,0) = 0 (0x0)getpid() = 74430 (0x122be)sendto(3,"<29>1 2023-06-07T09:21:50.719665"...,135,0,NULL,0) = 135 (0x87)__sysctl("kern.hostname",2,0x7fffffffbb10,0x7fffffff79f8,0x0,0) = 0 (0x0)getpid() = 74430 (0x122be)sendto(3,"<29>1 2023-06-07T09:21:50.719982"...,147,0,NULL,0) = 147 (0x93)__sysctl("kern.hostname",2,0x7fffffffb5b0,0x7fffffff7498,0x0,0) = 0 (0x0)getpid() = 74430 (0x122be)sendto(3,"<29>1 2023-06-07T09:21:50.720799"...,302,0,NULL,0) = 302 (0x12e)fork() = 60508 (0xec5c)wait4(60508,{ EXITED,val=0 },0x0,0x0) = 60508 (0xec5c)__sysctl("kern.hostname",2,0x7fffffffb5f0,0x7fffffff74d8,0x0,0) = 0 (0x0)getpid() = 74430 (0x122be)sendto(3,"<29>1 2023-06-07T09:21:58.818818"...,244,0,NULL,0) = 244 (0xf4)__sysctl("kern.hostname",2,0x7fffffffb780,0x7fffffff7668,0x0,0) = 0 (0x0)getpid() = 74430 (0x122be)sendto(3,"<29>1 2023-06-07T09:21:58.819194"...,237,0,NULL,0) = 237 (0xed)__sysctl("kern.hostname",2,0x7fffffffb5b0,0x7fffffff7498,0x0,0) = 0 (0x0)getpid() = 74430 (0x122be)sendto(3,"<29>1 2023-06-07T09:21:58.819902"...,293,0,NULL,0) = 293 (0x125)fork() = 19479 (0x4c17)wait4(19479,{ EXITED,val=0 },0x0,0x0) = 19479 (0x4c17)__sysctl("kern.hostname",2,0x7fffffffb5f0,0x7fffffff74d8,0x0,0) = 0 (0x0)getpid() = 74430 (0x122be)sendto(3,"<29>1 2023-06-07T09:22:07.267119"...,235,0,NULL,0) = 235 (0xeb)__sysctl("kern.hostname",2,0x7fffffffb780,0x7fffffff7668,0x0,0) = 0 (0x0)getpid() = 74430 (0x122be)sendto(3,"<29>1 2023-06-07T09:22:07.267640"...,228,0,NULL,0) = 228 (0xe4)__sysctl("kern.hostname",2,0x7fffffffbb10,0x7fffffff79f8,0x0,0) = 0 (0x0)getpid() = 74430 (0x122be)sendto(3,"<29>1 2023-06-07T09:22:07.268193"...,162,0,NULL,0) = 162 (0xa2)__sysctl("kern.hostname",2,0x7fffffffbb10,0x7fffffff79f8,0x0,0) = 0 (0x0)getpid() = 74430 (0x122be)sendto(3,"<29>1 2023-06-07T09:22:07.268821"...,162,0,NULL,0) = 162 (0xa2)__sysctl("kern.hostname",2,0x7fffffffbb10,0x7fffffff79f8,0x0,0) = 0 (0x0)getpid() = 74430 (0x122be)
<29>1 2023-06-07T09:21:50+00:00 our-server.com openvpn_server 74430 - [meta sequenceId="141560"] xxx.xxx.xxx.xxx:21943 SSL state (accept): TLSv1.3 early data<29>1 2023-06-07T09:21:50+00:00 our-server.com openvpn_server 74430 - [meta sequenceId="141561"] xxx.xxx.xxx.xxx:21943 TLS: executing verify command: /usr/local/opnsense/scripts/openvpn/ovpn_event.py 1 C=US, ST=Some-state, L=Some-city, O=Our-company, emailAddress=admin@our-company.com, CN=our-internal-ca<29>1 2023-06-07T09:21:58+00:00 our-server.com openvpn_server 74430 - [meta sequenceId="141562"] xxx.xxx.xxx.xxx:21943 VERIFY SCRIPT OK: depth=1, C=US, ST=Some-state, L=Some-city, O=Our-company, emailAddress=admin@our-company.com, CN=our-internal-ca<29>1 2023-06-07T09:21:58+00:00 our-server.com openvpn_server 74430 - [meta sequenceId="141563"] xxx.xxx.xxx.xxx:21943 VERIFY OK: depth=1, C=US, ST=Some-state, L=Some-city, O=Our-company, emailAddress=admin@our-server.com, CN=our-internal-ca<29>1 2023-06-07T09:21:58+00:00 our-server.com openvpn_server 74430 - [meta sequenceId="141564"] xxx.xxx.xxx.xxx:21943 TLS: executing verify command: /usr/local/opnsense/scripts/openvpn/ovpn_event.py 0 C=US, ST=Some-state, L=Some-city, O=Our-company, emailAddress=admin@our-company.com, CN=user2<29>1 2023-06-07T09:22:07+00:00 our-server.com openvpn_server 74430 - [meta sequenceId="141565"] xxx.xxx.xxx.xxx:21943 VERIFY SCRIPT OK: depth=0, C=US, ST=Some-state, L=Some-city, O=Our-company, emailAddress=admin@our-company.com, CN=user2<29>1 2023-06-07T09:22:07+00:00 our-server.com openvpn_server 74430 - [meta sequenceId="141566"] xxx.xxx.xxx.xxx:21943 VERIFY OK: depth=0, C=US, ST=Some-state, L=Some-city, O=Our-company, emailAddress=admin@our-company.com, CN=user2<29>1 2023-06-07T09:22:07+00:00 our-server.comm openvpn_server 74430 - [meta sequenceId="141567"] 46.211.230.220:21943 SSL state (accept): SSLv3/TLS read client certificate<29>1 2023-06-07T09:22:07+00:00 our-server.com openvpn_server 74430 - [meta sequenceId="141568"] xxx.xxx.xxx.xxx:21943 SSL state (accept): SSLv3/TLS read certificate verify
64 bytes from 10.110.210.1: icmp_seq=17 ttl=64 time=154 ms64 bytes from 10.110.210.1: icmp_seq=18 ttl=64 time=154 ms64 bytes from 10.110.210.1: icmp_seq=19 ttl=64 time=154 ms64 bytes from 10.110.210.1: icmp_seq=20 ttl=64 time=154 ms64 bytes from 10.110.210.1: icmp_seq=21 ttl=64 time=154 ms64 bytes from 10.110.210.1: icmp_seq=22 ttl=64 time=154 ms64 bytes from 10.110.210.1: icmp_seq=23 ttl=64 time=183 ms64 bytes from 10.110.210.1: icmp_seq=24 ttl=64 time=24941 ms64 bytes from 10.110.210.1: icmp_seq=25 ttl=64 time=23904 ms64 bytes from 10.110.210.1: icmp_seq=26 ttl=64 time=22880 ms64 bytes from 10.110.210.1: icmp_seq=27 ttl=64 time=21856 ms64 bytes from 10.110.210.1: icmp_seq=28 ttl=64 time=20833 ms64 bytes from 10.110.210.1: icmp_seq=29 ttl=64 time=19810 ms64 bytes from 10.110.210.1: icmp_seq=30 ttl=64 time=18787 ms64 bytes from 10.110.210.1: icmp_seq=31 ttl=64 time=17762 ms64 bytes from 10.110.210.1: icmp_seq=32 ttl=64 time=16740 ms64 bytes from 10.110.210.1: icmp_seq=33 ttl=64 time=15716 ms64 bytes from 10.110.210.1: icmp_seq=34 ttl=64 time=14693 ms64 bytes from 10.110.210.1: icmp_seq=35 ttl=64 time=13670 ms64 bytes from 10.110.210.1: icmp_seq=36 ttl=64 time=12646 ms64 bytes from 10.110.210.1: icmp_seq=37 ttl=64 time=11623 ms64 bytes from 10.110.210.1: icmp_seq=38 ttl=64 time=10599 ms64 bytes from 10.110.210.1: icmp_seq=39 ttl=64 time=9576 ms64 bytes from 10.110.210.1: icmp_seq=40 ttl=64 time=8552 ms64 bytes from 10.110.210.1: icmp_seq=41 ttl=64 time=7529 ms64 bytes from 10.110.210.1: icmp_seq=42 ttl=64 time=6505 ms64 bytes from 10.110.210.1: icmp_seq=43 ttl=64 time=5482 ms64 bytes from 10.110.210.1: icmp_seq=44 ttl=64 time=4459 ms64 bytes from 10.110.210.1: icmp_seq=45 ttl=64 time=3436 ms64 bytes from 10.110.210.1: icmp_seq=46 ttl=64 time=2412 ms64 bytes from 10.110.210.1: icmp_seq=47 ttl=64 time=1389 ms64 bytes from 10.110.210.1: icmp_seq=48 ttl=64 time=365 ms64 bytes from 10.110.210.1: icmp_seq=49 ttl=64 time=157 ms64 bytes from 10.110.210.1: icmp_seq=50 ttl=64 time=157 ms64 bytes from 10.110.210.1: icmp_seq=51 ttl=64 time=157 ms64 bytes from 10.110.210.1: icmp_seq=52 ttl=64 time=156 ms64 bytes from 10.110.210.1: icmp_seq=53 ttl=64 time=155 ms64 bytes from 10.110.210.1: icmp_seq=54 ttl=64 time=155 ms64 bytes from 10.110.210.1: icmp_seq=55 ttl=64 time=156 ms64 bytes from 10.110.210.1: icmp_seq=56 ttl=64 time=157 ms
dev ovpnsverb 11dev-type tundev-node /dev/tunwritepid /var/run/openvpn_server.pidscript-security 3daemon openvpn_serverkeepalive 10 60ping-timer-rempersist-tunpersist-keyproto udp4auth SHA256up /usr/local/etc/inc/plugins.inc.d/openvpn/ovpn-linkupdown /usr/local/etc/inc/plugins.inc.d/openvpn/ovpn-linkdownlocal xxx.xxx.xxx.xxxclient-connect "/usr/local/opnsense/scripts/openvpn/ovpn_event.py"tls-serverserver 10.110.210.0 255.255.255.0client-config-dir /var/etc/openvpn-csc/tls-verify "/usr/local/opnsense/scripts/openvpn/ovpn_event.py"lport 1199management /var/etc/openvpn/server.sock unixca /var/etc/openvpn/server.ca cert /var/etc/openvpn/server.cert key /var/etc/openvpn/server.key dh /usr/local/etc/inc/plugins.inc.d/openvpn/dh.rfc7919tls-auth /var/etc/openvpn/server.tls-auth 0topology subnet
dev tunpersist-tunpersist-keyauth SHA256clientresolv-retry infiniteremote xxx.xxx.xxx.xxx 1199 udp4lport 0verify-x509-name "C=US, ST=Some-state, L=Some-city, O=Our-company, emailAddress=admin@our-company.com, CN=our-internal-certificate" subjectremote-cert-tls server<ca>-----BEGIN CERTIFICATE----------END CERTIFICATE-----</ca><cert>-----BEGIN CERTIFICATE----------END CERTIFICATE-----</cert><key>-----BEGIN PRIVATE KEY----------END PRIVATE KEY-----</key><tls-auth>## 2048 bit OpenVPN static key#-----BEGIN OpenVPN Static key V1----------END OpenVPN Static key V1-----</tls-auth>key-direction 1