TLS handshake failed
dev ovpns9verb 3dev-type tundev-node /dev/tun9writepid /var/run/openvpn_server9.pidscript-security 3daemon openvpn_server9keepalive 10 60ping-timer-rempersist-tunpersist-keyproto udp4cipher AES-256-GCMauth SHA256up /usr/local/etc/inc/plugins.inc.d/openvpn/ovpn-linkupdown /usr/local/etc/inc/plugins.inc.d/openvpn/ovpn-linkdownclient-connect "/usr/local/opnsense/scripts/openvpn/ovpn_event.py '9'"tls-serverserver 172.16.6.0 255.255.255.240client-config-dir /var/etc/openvpn-csc/9server-ipv6 2001:X:X:X::/112client-config-dir /var/etc/openvpn-csc/9tls-verify "/usr/local/opnsense/scripts/openvpn/ovpn_event.py '9'"lport XXXXmanagement /var/etc/openvpn/server9.sock unixmax-clients 20push "dhcp-option DOMAIN XYZ.net"push "dhcp-option DNS 172.16.1.47"push "dhcp-option DNS 172.16.6.1"push "dhcp-option DNS 2001:X:X:X::1"push "dhcp-option DNS 2001:X:X:X::47"push "dhcp-option NTP 172.16.6.1"push "dhcp-option NTP 2001:X:X:X::1"push "redirect-gateway def1"client-to-clientca /var/etc/openvpn/server9.ca cert /var/etc/openvpn/server9.cert key /var/etc/openvpn/server9.key dh /usr/local/etc/inc/plugins.inc.d/openvpn/dh.rfc7919tls-crypt /var/etc/openvpn/server9.tls-crypt passtospersist-remote-ipfloattopology subnetpush "redirect-gateway ipv6 def1 block-local"persist-local-ippersist-remote-ipfast-ioifconfig-pool-persist ipp.txtscript-security 2allow-pull-fqdntun-mtu 1500tun-mtu-extra 32mssfix 1450local X.X.X.Xuser openvpngroup openvpntls-version-min 1.3tls-ciphersuites TLS_AES_256_GCM_SHA384:TLS_CHACHA20_POLY1305_SHA256:TLS_AES_128_GCM_SHA256
....The only issue was, that our main gateway was dropped while updating. The issue occured on both our firewalls.Perhaps this happened to you, too.
172.16.4.2:55011 TLS Error: Unroutable control packet received from [AF_INET]172.16.4.2:55011 (si=3 op=P_CONTROL_V1)
2024-02-23T20:13:23 Error openvpn_server9 172.16.4.2:50060 TLS Error: Unroutable control packet received from [AF_INET]172.16.4.2:50060 (si=3 op=P_CONTROL_V1) 2024-02-23T20:13:23 Error openvpn_server9 172.16.4.2:50060 TLS Error: TLS handshake failed 2024-02-23T20:13:23 Error openvpn_server9 172.16.4.2:50060 TLS Error: TLS object -> incoming plaintext read error 2024-02-23T20:13:23 Error openvpn_server9 172.16.4.2:50060 TLS_ERROR: BIO read tls_read_plaintext error 2024-02-23T20:13:23 Error openvpn_server9 172.16.4.2:50060 OpenSSL: error:0A000086:SSL routines::certificate verify failed::ssl/statem/statem_srvr.c:3524:tls_process_client_certificate 2024-02-23T20:13:23 Warning openvpn_server9 172.16.4.2:50060 WARNING: Failed running command (--tls-verify script): external program exited with error status: 255 2024-02-23T20:13:10 Warning openvpn_server9 NOTE: the current --script-security setting may allow this configuration to call user-defined scripts
user openvpngroup openvpn
# id openvpnuid=301(openvpn) gid=301(openvpn) groups=301(openvpn)
tls-verify "/usr/local/opnsense/scripts/openvpn/ovpn_event.py '9'"
-rwxr-xr-x 1 root wheel 4522 Feb 21 12:49 ovpn_event.py