Witam. Mam wykupionego klienta nordvpn. Próbowałem zrobić według ich configów ale nie chciało ruszyć. Zrobiłem według @Cezarego i w końcu ruszył vpn, ale po chwili nie mam nigdzie internetu. Po restarcie brak internetu. Wyłączenie custom config internet powraca. Wersja @cezarego OpenWrt 18.06 luci.
To są logi po restarcie:
root@OpenWrt:~# logread
Thu Jul 4 18:52:00 2019 daemon.notice netifd: Interface 'wan' is enabled
Thu Jul 4 18:52:00 2019 daemon.notice netifd: Interface 'wan6' is enabled
Thu Jul 4 18:52:00 2019 daemon.notice netifd: bridge 'br-lan' link is up
Thu Jul 4 18:52:00 2019 daemon.notice netifd: Interface 'lan' has link connectivity
Thu Jul 4 18:52:00 2019 daemon.notice netifd: Network device 'eth0' link is up
Thu Jul 4 18:52:00 2019 daemon.notice netifd: VLAN 'eth0.1' link is up
Thu Jul 4 18:52:00 2019 daemon.notice netifd: Network device 'lo' link is up
Thu Jul 4 18:52:00 2019 daemon.notice netifd: Interface 'loopback' has link connectivity
Thu Jul 4 18:52:00 2019 daemon.notice netifd: Network device 'eth1' link is up
Thu Jul 4 18:52:00 2019 daemon.notice netifd: VLAN 'eth1.2' link is up
Thu Jul 4 18:52:00 2019 daemon.notice netifd: Interface 'wan' has link connectivity
Thu Jul 4 18:52:00 2019 daemon.notice netifd: Interface 'wan' is setting up now
Thu Jul 4 18:52:00 2019 daemon.notice netifd: Interface 'wan6' has link connectivity
Thu Jul 4 18:52:00 2019 daemon.notice netifd: Interface 'wan6' is setting up now
Thu Jul 4 18:52:00 2019 user.notice firewall: Reloading firewall due to ifup of lan (br-lan)
Thu Jul 4 18:52:00 2019 daemon.notice netifd: wan (2023): udhcpc: started, v1.28.4
Thu Jul 4 18:52:00 2019 daemon.err odhcp6c[2027]: Failed to send RS (Address not available)
Thu Jul 4 18:52:00 2019 daemon.notice netifd: wan (2023): udhcpc: sending discover
Thu Jul 4 18:52:00 2019 daemon.notice netifd: wan (2023): udhcpc: sending select for 10.9.146.169
Thu Jul 4 18:52:00 2019 daemon.notice netifd: wan (2023): udhcpc: lease of 10.9.146.169 obtained, lease time 3600
Thu Jul 4 18:52:00 2019 kern.debug kernel: [ 13.688694] ieee80211 phy1: regdomain: ETSI
Thu Jul 4 18:52:00 2019 kern.debug kernel: [ 13.688701] ieee80211 phy1: Channel: 1: 0x0 0x0 0xf
Thu Jul 4 18:52:00 2019 kern.debug kernel: [ 13.688706] ieee80211 phy1: a a a a a a a a a a a a 0 0 0 0
Thu Jul 4 18:52:00 2019 kern.debug kernel: [ 13.688709] ieee80211 phy1: Channel: 2: 0x0 0x0 0xf
Thu Jul 4 18:52:00 2019 kern.debug kernel: [ 13.688714] ieee80211 phy1: a a a a a a a a a a a a 0 0 0 0
Thu Jul 4 18:52:00 2019 kern.debug kernel: [ 13.688717] ieee80211 phy1: Channel: 3: 0x0 0x0 0xf
Thu Jul 4 18:52:00 2019 kern.debug kernel: [ 13.688722] ieee80211 phy1: a a a a a a a a a a a a 0 0 0 0
Thu Jul 4 18:52:00 2019 kern.debug kernel: [ 13.688725] ieee80211 phy1: Channel: 4: 0x0 0x0 0xf
Thu Jul 4 18:52:00 2019 kern.debug kernel: [ 13.688730] ieee80211 phy1: a a a a a a a a a a a a 0 0 0 0
Thu Jul 4 18:52:00 2019 kern.debug kernel: [ 13.688732] ieee80211 phy1: Channel: 5: 0x0 0x0 0xf
Thu Jul 4 18:52:00 2019 kern.debug kernel: [ 13.688737] ieee80211 phy1: a a a a a a a a a a a a 0 0 0 0
Thu Jul 4 18:52:00 2019 kern.debug kernel: [ 13.688740] ieee80211 phy1: Channel: 6: 0x0 0x0 0xf
Thu Jul 4 18:52:00 2019 kern.debug kernel: [ 13.688745] ieee80211 phy1: a a a a a a a a a a a a 0 0 0 0
Thu Jul 4 18:52:00 2019 kern.debug kernel: [ 13.688748] ieee80211 phy1: Channel: 7: 0x0 0x0 0xf
Thu Jul 4 18:52:00 2019 kern.debug kernel: [ 13.688753] ieee80211 phy1: a a a a a a a a a a a a 0 0 0 0
Thu Jul 4 18:52:00 2019 kern.debug kernel: [ 13.688756] ieee80211 phy1: Channel: 8: 0x0 0x0 0xf
Thu Jul 4 18:52:00 2019 kern.debug kernel: [ 13.688760] ieee80211 phy1: a a a a a a a a a a a a 0 0 0 0
Thu Jul 4 18:52:00 2019 kern.debug kernel: [ 13.688763] ieee80211 phy1: Channel: 9: 0x0 0x0 0xf
Thu Jul 4 18:52:00 2019 kern.debug kernel: [ 13.688768] ieee80211 phy1: a a a a a a a a a a a a 0 0 0 0
Thu Jul 4 18:52:00 2019 kern.debug kernel: [ 13.688771] ieee80211 phy1: Channel: 10: 0x0 0x0 0xf
Thu Jul 4 18:52:00 2019 kern.debug kernel: [ 13.688776] ieee80211 phy1: a a a a a a a a a a a a 0 0 0 0
Thu Jul 4 18:52:00 2019 kern.debug kernel: [ 13.688779] ieee80211 phy1: Channel: 11: 0x0 0x0 0xf
Thu Jul 4 18:52:00 2019 kern.debug kernel: [ 13.688784] ieee80211 phy1: a a a a a a a a a a a a 0 0 0 0
Thu Jul 4 18:52:00 2019 kern.debug kernel: [ 13.688787] ieee80211 phy1: Channel: 12: 0x0 0x0 0xf
Thu Jul 4 18:52:00 2019 kern.debug kernel: [ 13.688792] ieee80211 phy1: a a a a a a a a a a a a 0 0 0 0
Thu Jul 4 18:52:00 2019 kern.debug kernel: [ 13.688795] ieee80211 phy1: Channel: 13: 0x0 0x0 0xf
Thu Jul 4 18:52:00 2019 kern.debug kernel: [ 13.688799] ieee80211 phy1: a a a a a a a a a a a a 0 0 0 0
Thu Jul 4 18:52:00 2019 kern.debug kernel: [ 13.688820] ieee80211 phy0: regdomain: ETSI
Thu Jul 4 18:52:00 2019 kern.debug kernel: [ 13.688823] ieee80211 phy0: Channel: 36: 0x0 0x0 0xf
Thu Jul 4 18:52:00 2019 kern.debug kernel: [ 13.688828] ieee80211 phy0: d d d d d d d d e e e e e e e e
Thu Jul 4 18:52:00 2019 kern.debug kernel: [ 13.688833] ieee80211 phy0: Channel: 40: 0x0 0x0 0xf
Thu Jul 4 18:52:00 2019 kern.debug kernel: [ 13.688840] ieee80211 phy0: d d d d d d d d e e e e e e e e
Thu Jul 4 18:52:00 2019 kern.debug kernel: [ 13.688843] ieee80211 phy0: Channel: 44: 0x0 0x0 0xf
Thu Jul 4 18:52:00 2019 kern.debug kernel: [ 13.688848] ieee80211 phy0: d d d d d d d d e e e e e e e e
Thu Jul 4 18:52:00 2019 kern.debug kernel: [ 13.688850] ieee80211 phy0: Channel: 48: 0x0 0x0 0xf
Thu Jul 4 18:52:00 2019 kern.debug kernel: [ 13.688855] ieee80211 phy0: d d d d d d d d e e e e e e e e
Thu Jul 4 18:52:00 2019 kern.debug kernel: [ 13.688858] ieee80211 phy0: Channel: 52: 0x0 0x0 0xf
Thu Jul 4 18:52:00 2019 kern.debug kernel: [ 13.688863] ieee80211 phy0: d d d d d d d d e e e e e e e e
Thu Jul 4 18:52:00 2019 kern.debug kernel: [ 13.688874] ieee80211 phy0: Channel: 56: 0x0 0x0 0xf
Thu Jul 4 18:52:00 2019 kern.debug kernel: [ 13.688888] ieee80211 phy0: d d d d d d d d e e e e e e e e
Thu Jul 4 18:52:00 2019 kern.debug kernel: [ 13.688901] ieee80211 phy0: Channel: 60: 0x0 0x0 0xf
Thu Jul 4 18:52:00 2019 kern.debug kernel: [ 13.688907] ieee80211 phy0: d d d d d d d d e e e e e e e e
Thu Jul 4 18:52:00 2019 kern.debug kernel: [ 13.688917] ieee80211 phy0: Channel: 64: 0x0 0x0 0xf
Thu Jul 4 18:52:00 2019 kern.debug kernel: [ 13.688929] ieee80211 phy0: d d d d d d d d e e e e e e e e
Thu Jul 4 18:52:00 2019 kern.debug kernel: [ 13.688933] ieee80211 phy0: Channel: 100: 0x0 0x0 0xf
Thu Jul 4 18:52:00 2019 kern.debug kernel: [ 13.688938] ieee80211 phy0: d d d d d d d d e e e e e e e e
Thu Jul 4 18:52:00 2019 kern.debug kernel: [ 13.688941] ieee80211 phy0: Channel: 104: 0x0 0x0 0xf
Thu Jul 4 18:52:00 2019 kern.debug kernel: [ 13.688946] ieee80211 phy0: d d d d d d d d e e e e e e e e
Thu Jul 4 18:52:00 2019 kern.debug kernel: [ 13.688949] ieee80211 phy0: Channel: 108: 0x0 0x0 0xf
Thu Jul 4 18:52:00 2019 kern.debug kernel: [ 13.688961] ieee80211 phy0: d d d d d d d d e e e e e e e e
Thu Jul 4 18:52:00 2019 kern.debug kernel: [ 13.688974] ieee80211 phy0: Channel: 112: 0x0 0x0 0xf
Thu Jul 4 18:52:00 2019 kern.debug kernel: [ 13.688994] ieee80211 phy0: d d d d d d d d e e e e e e e e
Thu Jul 4 18:52:00 2019 kern.debug kernel: [ 13.689001] ieee80211 phy0: Channel: 116: 0x0 0x0 0xf
Thu Jul 4 18:52:00 2019 kern.debug kernel: [ 13.689021] ieee80211 phy0: d d d d d d d d e e e e e e e e
Thu Jul 4 18:52:00 2019 kern.debug kernel: [ 13.689025] ieee80211 phy0: Channel: 120: 0x0 0x0 0xf
Thu Jul 4 18:52:00 2019 kern.debug kernel: [ 13.689030] ieee80211 phy0: d d d d d d d d e e e e e e e e
Thu Jul 4 18:52:00 2019 kern.debug kernel: [ 13.689033] ieee80211 phy0: Channel: 124: 0x0 0x0 0xf
Thu Jul 4 18:52:00 2019 kern.debug kernel: [ 13.689038] ieee80211 phy0: d d d d d d d d e e e e e e e e
Thu Jul 4 18:52:00 2019 kern.debug kernel: [ 13.689041] ieee80211 phy0: Channel: 128: 0x0 0x0 0xf
Thu Jul 4 18:52:00 2019 kern.debug kernel: [ 13.689046] ieee80211 phy0: d d d d d d d d e e e e e e e e
Thu Jul 4 18:52:00 2019 kern.debug kernel: [ 13.689048] ieee80211 phy0: Channel: 132: 0x0 0x0 0xf
Thu Jul 4 18:52:00 2019 kern.debug kernel: [ 13.689053] ieee80211 phy0: d d d d d d d d e e e e e e e e
Thu Jul 4 18:52:00 2019 kern.debug kernel: [ 13.689066] ieee80211 phy0: Channel: 136: 0x0 0x0 0xf
Thu Jul 4 18:52:00 2019 kern.debug kernel: [ 13.689075] ieee80211 phy0: d d d d d d d d e e e e e e e e
Thu Jul 4 18:52:00 2019 kern.debug kernel: [ 13.689079] ieee80211 phy0: Channel: 140: 0x0 0x0 0xf
Thu Jul 4 18:52:00 2019 kern.debug kernel: [ 13.689087] ieee80211 phy0: d d d d d d d d e e e e e e e e
Thu Jul 4 18:52:00 2019 kern.debug kernel: [ 13.689091] ieee80211 phy0: Channel: 149: 0x0 0x0 0xf
Thu Jul 4 18:52:00 2019 kern.debug kernel: [ 13.689096] ieee80211 phy0: d d d d d d d d e e e e e e e e
Thu Jul 4 18:52:00 2019 user.notice ucitrack: Setting up /etc/config/network reload dependency on /etc/config/dhcp
Thu Jul 4 18:52:00 2019 user.notice ucitrack: Setting up /etc/config/network reload dependency on /etc/config/radvd
Thu Jul 4 18:52:00 2019 user.notice mac80211: Failed command: iw phy phy0 set antenna all all
Thu Jul 4 18:52:00 2019 daemon.notice netifd: radio0 (1966): command failed: Not supported (-95)
Thu Jul 4 18:52:00 2019 user.notice mac80211: Failed command: iw phy phy0 set distance 0
Thu Jul 4 18:52:00 2019 daemon.notice netifd: Interface 'wan' is now up
Thu Jul 4 18:52:00 2019 daemon.info dnsmasq[1685]: reading /tmp/resolv.conf.auto
Thu Jul 4 18:52:00 2019 daemon.info dnsmasq[1685]: using local addresses only for domain test
Thu Jul 4 18:52:00 2019 daemon.info dnsmasq[1685]: using local addresses only for domain onion
Thu Jul 4 18:52:00 2019 daemon.info dnsmasq[1685]: using local addresses only for domain localhost
Thu Jul 4 18:52:00 2019 daemon.info dnsmasq[1685]: using local addresses only for domain local
Thu Jul 4 18:52:00 2019 daemon.info dnsmasq[1685]: using local addresses only for domain invalid
Thu Jul 4 18:52:00 2019 daemon.info dnsmasq[1685]: using local addresses only for domain bind
Thu Jul 4 18:52:00 2019 daemon.info dnsmasq[1685]: using local addresses only for domain lan
Thu Jul 4 18:52:00 2019 daemon.info dnsmasq[1685]: using nameserver 83.175.144.9#53
Thu Jul 4 18:52:00 2019 daemon.info dnsmasq[1685]: using nameserver 83.175.144.14#53
Thu Jul 4 18:52:00 2019 user.notice ucitrack: Setting up /etc/config/wireless reload dependency on /etc/config/network
Thu Jul 4 18:52:00 2019 user.notice ucitrack: Setting up /etc/config/firewall reload dependency on /etc/config/luci-splash
Thu Jul 4 18:52:00 2019 user.notice ucitrack: Setting up /etc/config/firewall reload dependency on /etc/config/qos
Thu Jul 4 18:52:00 2019 user.notice ucitrack: Setting up /etc/config/firewall reload dependency on /etc/config/miniupnpd
Thu Jul 4 18:52:00 2019 user.notice firewall: Reloading firewall due to ifup of wan (eth1.2)
Thu Jul 4 18:52:00 2019 daemon.err hostapd: Configuration file: /var/run/hostapd-phy0.conf
Thu Jul 4 18:52:00 2019 user.notice ucitrack: Setting up /etc/config/dhcp reload dependency on /etc/config/odhcpd
Thu Jul 4 18:52:01 2019 user.notice ucitrack: Setting up non-init /etc/config/fstab reload handler: /sbin/block mount
Thu Jul 4 18:52:01 2019 user.notice ucitrack: Setting up /etc/config/system reload trigger for non-procd /etc/init.d/led
Thu Jul 4 18:52:01 2019 kern.debug kernel: [ 14.056305] ieee80211 phy0: change: 0xffffffff
Thu Jul 4 18:52:01 2019 user.notice ucitrack: Setting up /etc/config/system reload dependency on /etc/config/luci_statistics
Thu Jul 4 18:52:01 2019 daemon.err odhcp6c[2027]: Failed to send DHCPV6 message to ff02::1:2 (Address not available)
Thu Jul 4 18:52:01 2019 user.notice ucitrack: Setting up /etc/config/system reload dependency on /etc/config/dhcp
Thu Jul 4 18:52:01 2019 kern.info kernel: [ 14.194376] IPv6: ADDRCONF(NETDEV_UP): wlan0: link is not ready
Thu Jul 4 18:52:01 2019 kern.info kernel: [ 14.200360] IPv6: ADDRCONF(NETDEV_CHANGE): br-lan: link becomes ready
Thu Jul 4 18:52:01 2019 kern.info kernel: [ 14.216581] br-lan: port 2(wlan0) entered blocking state
Thu Jul 4 18:52:01 2019 kern.info kernel: [ 14.221959] br-lan: port 2(wlan0) entered disabled state
Thu Jul 4 18:52:01 2019 kern.info kernel: [ 14.227427] device wlan0 entered promiscuous mode
Thu Jul 4 18:52:01 2019 daemon.notice hostapd: wlan0: interface state UNINITIALIZED->COUNTRY_UPDATE
Thu Jul 4 18:52:01 2019 daemon.notice hostapd: wlan0: interface state COUNTRY_UPDATE->HT_SCAN
Thu Jul 4 18:52:01 2019 kern.debug kernel: [ 14.252993] ieee80211 phy0: change: 0x100
Thu Jul 4 18:52:01 2019 kern.debug kernel: [ 14.261468] ieee80211 phy0: change: 0x60
Thu Jul 4 18:52:01 2019 daemon.notice openvpn(custom_config)[2895]: OpenVPN 2.4.5 arm-openwrt-linux-gnu [SSL (OpenSSL)] [LZO] [LZ4] [EPOLL] [MH/PKTINFO] [AEAD]
Thu Jul 4 18:52:01 2019 daemon.notice openvpn(custom_config)[2895]: library versions: OpenSSL 1.0.2s 28 May 2019, LZO 2.10
Thu Jul 4 18:52:01 2019 daemon.warn openvpn(custom_config)[2895]: WARNING: --ping should normally be used with --ping-restart or --ping-exit
Thu Jul 4 18:52:01 2019 daemon.notice openvpn(custom_config)[2895]: Outgoing Control Channel Authentication: Using 512 bit message hash 'SHA512' for HMAC authentication
Thu Jul 4 18:52:01 2019 daemon.notice openvpn(custom_config)[2895]: Incoming Control Channel Authentication: Using 512 bit message hash 'SHA512' for HMAC authentication
Thu Jul 4 18:52:01 2019 daemon.notice openvpn(custom_config)[2895]: TCP/UDP: Preserving recently used remote address: [AF_INET]95.174.67.211:1194
Thu Jul 4 18:52:01 2019 daemon.notice openvpn(custom_config)[2895]: Socket Buffers: R=[163840->163840] S=[163840->163840]
Thu Jul 4 18:52:01 2019 daemon.notice openvpn(custom_config)[2895]: UDP link local: (not bound)
Thu Jul 4 18:52:01 2019 daemon.notice openvpn(custom_config)[2895]: UDP link remote: [AF_INET]95.174.67.211:1194
Thu Jul 4 18:52:01 2019 daemon.notice openvpn(custom_config)[2895]: TLS: Initial packet from [AF_INET]95.174.67.211:1194, sid=a19ad2bc 321f1a26
Thu Jul 4 18:52:01 2019 daemon.warn openvpn(custom_config)[2895]: WARNING: this configuration may cache passwords in memory -- use the auth-nocache option to prevent this
Thu Jul 4 18:52:01 2019 daemon.notice procd: /etc/rc.d/S96led: setting up led WAN
Thu Jul 4 18:52:01 2019 daemon.notice procd: /etc/rc.d/S96led: setting up led USB 1
Thu Jul 4 18:52:01 2019 daemon.notice procd: /etc/rc.d/S96led: setting up led USB 2
Thu Jul 4 18:52:01 2019 daemon.notice procd: /etc/rc.d/S96led: setting up led USB 2 SS
Thu Jul 4 18:52:01 2019 daemon.notice openvpn(custom_config)[2895]: VERIFY OK: depth=2, C=PA, O=NordVPN, CN=NordVPN Root CA
Thu Jul 4 18:52:01 2019 daemon.notice openvpn(custom_config)[2895]: VERIFY OK: depth=1, C=PA, O=NordVPN, CN=NordVPN CA3
Thu Jul 4 18:52:01 2019 daemon.notice openvpn(custom_config)[2895]: VERIFY KU OK
Thu Jul 4 18:52:01 2019 daemon.notice openvpn(custom_config)[2895]: Validating certificate extended key usage
Thu Jul 4 18:52:01 2019 daemon.notice openvpn(custom_config)[2895]: ++ Certificate has EKU (str) TLS Web Server Authentication, expects TLS Web Server Authentication
Thu Jul 4 18:52:01 2019 daemon.notice openvpn(custom_config)[2895]: VERIFY EKU OK
Thu Jul 4 18:52:01 2019 daemon.notice openvpn(custom_config)[2895]: VERIFY OK: depth=0, CN=nl370.nordvpn.com
Thu Jul 4 18:52:01 2019 kern.debug kernel: [ 14.531297] ieee80211 phy0: change: 0x40
Thu Jul 4 18:52:01 2019 user.notice mac80211: Failed command: iw phy phy1 set antenna all all
Thu Jul 4 18:52:01 2019 daemon.notice netifd: radio1 (1967): command failed: Not supported (-95)
Thu Jul 4 18:52:01 2019 user.notice mac80211: Failed command: iw phy phy1 set distance 0
Thu Jul 4 18:52:01 2019 user.notice ddns-scripts[2598]: myddns_ipv4: PID '2598' started at 2019-07-04 18:52
Thu Jul 4 18:52:01 2019 daemon.notice hostapd: wlan0: interface state HT_SCAN->DFS
Thu Jul 4 18:52:01 2019 daemon.notice hostapd: wlan0: DFS-CAC-START freq=5260 chan=52 sec_chan=1, width=1, seg0=58, seg1=0, cac_time=60s
Thu Jul 4 18:52:01 2019 kern.debug kernel: [ 14.751352] ieee80211 phy0: change: 0x60
Thu Jul 4 18:52:01 2019 daemon.info procd: - init complete -
Thu Jul 4 18:52:01 2019 daemon.notice openvpn(custom_config)[2895]: Control Channel: TLSv1.2, cipher TLSv1/SSLv3 ECDHE-RSA-AES256-GCM-SHA384, 4096 bit RSA
Thu Jul 4 18:52:01 2019 daemon.notice openvpn(custom_config)[2895]: [nl370.nordvpn.com] Peer Connection Initiated with [AF_INET]95.174.67.211:1194
Thu Jul 4 18:52:01 2019 kern.debug kernel: [ 14.855515] ieee80211 phy0: change: 0x100
Thu Jul 4 18:52:01 2019 kern.debug kernel: [ 14.864614] ieee80211 phy0: change: 0x100
Thu Jul 4 18:52:01 2019 kern.debug kernel: [ 14.873664] ieee80211 phy0: change: 0x42
Thu Jul 4 18:52:02 2019 kern.debug kernel: [ 14.979353] ieee80211 phy0: change: 0x40
Thu Jul 4 18:52:02 2019 daemon.err hostapd: Configuration file: /var/run/hostapd-phy1.conf
Thu Jul 4 18:52:02 2019 kern.debug kernel: [ 15.206300] ieee80211 phy1: change: 0xffffffff
Thu Jul 4 18:52:02 2019 kern.info kernel: [ 15.323604] IPv6: ADDRCONF(NETDEV_UP): wlan1: link is not ready
Thu Jul 4 18:52:02 2019 kern.info kernel: [ 15.331087] br-lan: port 3(wlan1) entered blocking state
Thu Jul 4 18:52:02 2019 kern.info kernel: [ 15.336466] br-lan: port 3(wlan1) entered disabled state
Thu Jul 4 18:52:02 2019 daemon.notice hostapd: wlan1: interface state UNINITIALIZED->COUNTRY_UPDATE
Thu Jul 4 18:52:02 2019 daemon.err hostapd: Using interface wlan1 with hwaddr 16:91:82:31:94:04 and ssid "HIUMAN"
Thu Jul 4 18:52:02 2019 kern.info kernel: [ 15.341966] device wlan1 entered promiscuous mode
Thu Jul 4 18:52:02 2019 kern.debug kernel: [ 15.412384] ieee80211 phy1: change: 0x100
Thu Jul 4 18:52:02 2019 kern.debug kernel: [ 15.421327] ieee80211 phy1: change: 0x42
Thu Jul 4 18:52:02 2019 kern.info kernel: [ 15.588751] IPv6: ADDRCONF(NETDEV_CHANGE): wlan1: link becomes ready
Thu Jul 4 18:52:02 2019 kern.info kernel: [ 15.595214] br-lan: port 3(wlan1) entered blocking state
Thu Jul 4 18:52:02 2019 kern.info kernel: [ 15.600550] br-lan: port 3(wlan1) entered forwarding state
Thu Jul 4 18:52:02 2019 daemon.notice hostapd: wlan1: interface state COUNTRY_UPDATE->ENABLED
Thu Jul 4 18:52:02 2019 daemon.notice hostapd: wlan1: AP-ENABLED
Thu Jul 4 18:52:02 2019 user.warn ddns-scripts[2598]: myddns_ipv4: Service section disabled! - TERMINATE
Thu Jul 4 18:52:02 2019 daemon.notice netifd: Network device 'wlan1' link is up
Thu Jul 4 18:52:02 2019 user.warn ddns-scripts[2598]: myddns_ipv4: PID '2598' exit WITH ERROR '1' at 2019-07-04 18:52
Thu Jul 4 19:13:26 2019 daemon.notice openvpn(custom_config)[2895]: SENT CONTROL [nl370.nordvpn.com]: 'PUSH_REQUEST' (status=1)
Thu Jul 4 19:13:26 2019 daemon.notice openvpn(custom_config)[2895]: PUSH: Received control message: 'PUSH_REPLY,redirect-gateway def1,dhcp-option DNS 103.86.96.100,dhcp-option DNS 103.86.99.100,sndbuf 524288,rcvbuf 524288,explicit-exit-notify,comp-lzo no,route-gateway 10.8.2.1,topology subnet,ping 60,ping-restart 180,ifconfig 10.8.2.10 255.255.255.0,peer-id 8,cipher AES-256-GCM'
Thu Jul 4 19:13:26 2019 daemon.notice openvpn(custom_config)[2895]: OPTIONS IMPORT: timers and/or timeouts modified
Thu Jul 4 19:13:26 2019 daemon.notice openvpn(custom_config)[2895]: OPTIONS IMPORT: explicit notify parm(s) modified
Thu Jul 4 19:13:26 2019 daemon.notice openvpn(custom_config)[2895]: OPTIONS IMPORT: compression parms modified
Thu Jul 4 19:13:26 2019 daemon.notice openvpn(custom_config)[2895]: OPTIONS IMPORT: --sndbuf/--rcvbuf options modified
Thu Jul 4 19:13:26 2019 daemon.notice openvpn(custom_config)[2895]: Socket Buffers: R=[163840->327680] S=[163840->327680]
Thu Jul 4 19:13:26 2019 daemon.notice openvpn(custom_config)[2895]: OPTIONS IMPORT: --ifconfig/up options modified
Thu Jul 4 19:13:26 2019 daemon.notice openvpn(custom_config)[2895]: OPTIONS IMPORT: route options modified
Thu Jul 4 19:13:26 2019 daemon.notice openvpn(custom_config)[2895]: OPTIONS IMPORT: route-related options modified
Thu Jul 4 19:13:26 2019 daemon.notice openvpn(custom_config)[2895]: OPTIONS IMPORT: --ip-win32 and/or --dhcp-option options modified
Thu Jul 4 19:13:26 2019 daemon.notice openvpn(custom_config)[2895]: OPTIONS IMPORT: peer-id set
Thu Jul 4 19:13:26 2019 daemon.notice openvpn(custom_config)[2895]: OPTIONS IMPORT: adjusting link_mtu to 1657
Thu Jul 4 19:13:26 2019 daemon.notice openvpn(custom_config)[2895]: OPTIONS IMPORT: data channel crypto options modified
Thu Jul 4 19:13:26 2019 daemon.notice openvpn(custom_config)[2895]: Data Channel: using negotiated cipher 'AES-256-GCM'
Thu Jul 4 19:13:26 2019 daemon.notice openvpn(custom_config)[2895]: Outgoing Data Channel: Cipher 'AES-256-GCM' initialized with 256 bit key
Thu Jul 4 19:13:26 2019 daemon.notice openvpn(custom_config)[2895]: Incoming Data Channel: Cipher 'AES-256-GCM' initialized with 256 bit key
Thu Jul 4 19:13:26 2019 daemon.notice openvpn(custom_config)[2895]: TUN/TAP device tun0 opened
Thu Jul 4 19:13:26 2019 daemon.notice openvpn(custom_config)[2895]: TUN/TAP TX queue length set to 100
Thu Jul 4 19:13:26 2019 daemon.notice openvpn(custom_config)[2895]: do_ifconfig, tt->did_ifconfig_ipv6_setup=0
Thu Jul 4 19:13:26 2019 daemon.notice openvpn(custom_config)[2895]: /sbin/ifconfig tun0 10.8.2.10 netmask 255.255.255.0 mtu 1500 broadcast 10.8.2.255
Thu Jul 4 19:13:26 2019 daemon.notice netifd: Interface 'vpn' is enabled
Thu Jul 4 19:13:26 2019 daemon.notice netifd: Network device 'tun0' link is up
Thu Jul 4 19:13:26 2019 daemon.notice netifd: Interface 'vpn' has link connectivity
Thu Jul 4 19:13:26 2019 daemon.notice netifd: Interface 'vpn' is setting up now
Thu Jul 4 19:13:26 2019 daemon.notice netifd: Interface 'vpn' is now up
Thu Jul 4 19:13:26 2019 daemon.notice openvpn(custom_config)[2895]: /sbin/route add -net 95.174.67.211 netmask 255.255.255.255 gw 10.9.147.254
Thu Jul 4 19:13:26 2019 daemon.notice openvpn(custom_config)[2895]: /sbin/route add -net 0.0.0.0 netmask 128.0.0.0 gw 10.8.2.1
Thu Jul 4 19:13:26 2019 daemon.notice openvpn(custom_config)[2895]: /sbin/route add -net 128.0.0.0 netmask 128.0.0.0 gw 10.8.2.1
Thu Jul 4 19:13:26 2019 daemon.notice openvpn(custom_config)[2895]: Initialization Sequence Completed
Thu Jul 4 19:13:26 2019 user.notice firewall: Reloading firewall due to ifup of vpn (tun0)
Thu Jul 4 19:13:28 2019 daemon.info dnsmasq[1685]: exiting on receipt of SIGTERM
Thu Jul 4 19:13:28 2019 daemon.info dnsmasq[4354]: started, version 2.80 cachesize 150
Thu Jul 4 19:13:28 2019 daemon.info dnsmasq[4354]: DNS service limited to local subnets
Thu Jul 4 19:13:28 2019 daemon.info dnsmasq[4354]: compile time options: IPv6 GNU-getopt no-DBus no-i18n no-IDN DHCP no-DHCPv6 no-Lua TFTP no-conntrack no-ipset no-auth no-DNSSEC no-ID loop-detect inotify dumpfile
Thu Jul 4 19:13:28 2019 daemon.info dnsmasq-dhcp[4354]: DHCP, IP range 192.168.1.100 -- 192.168.1.249, lease time 12h
Thu Jul 4 19:13:28 2019 daemon.info dnsmasq[4354]: using local addresses only for domain test
Thu Jul 4 19:13:28 2019 daemon.info dnsmasq[4354]: using local addresses only for domain onion
Thu Jul 4 19:13:28 2019 daemon.info dnsmasq[4354]: using local addresses only for domain localhost
Thu Jul 4 19:13:28 2019 daemon.info dnsmasq[4354]: using local addresses only for domain local
Thu Jul 4 19:13:28 2019 daemon.info dnsmasq[4354]: using local addresses only for domain invalid
Thu Jul 4 19:13:28 2019 daemon.info dnsmasq[4354]: using local addresses only for domain bind
Thu Jul 4 19:13:28 2019 daemon.info dnsmasq[4354]: using local addresses only for domain lan
Thu Jul 4 19:13:28 2019 daemon.info dnsmasq[4354]: reading /tmp/resolv.conf.auto
Thu Jul 4 19:13:28 2019 daemon.info dnsmasq[4354]: using local addresses only for domain test
Thu Jul 4 19:13:28 2019 daemon.info dnsmasq[4354]: using local addresses only for domain onion
Thu Jul 4 19:13:28 2019 daemon.info dnsmasq[4354]: using local addresses only for domain localhost
Thu Jul 4 19:13:28 2019 daemon.info dnsmasq[4354]: using local addresses only for domain local
Thu Jul 4 19:13:28 2019 daemon.info dnsmasq[4354]: using local addresses only for domain invalid
Thu Jul 4 19:13:28 2019 daemon.info dnsmasq[4354]: using local addresses only for domain bind
Thu Jul 4 19:13:28 2019 daemon.info dnsmasq[4354]: using local addresses only for domain lan
Thu Jul 4 19:13:28 2019 daemon.info dnsmasq[4354]: using nameserver 83.175.144.9#53
Thu Jul 4 19:13:28 2019 daemon.info dnsmasq[4354]: using nameserver 83.175.144.14#53
Thu Jul 4 19:13:28 2019 daemon.info dnsmasq[4354]: read /etc/hosts - 4 addresses
Thu Jul 4 19:13:28 2019 daemon.info dnsmasq[4354]: read /tmp/hosts/dhcp.cfg01411c - 4 addresses
Thu Jul 4 19:13:28 2019 daemon.info dnsmasq-dhcp[4354]: read /etc/ethers - 0 addresses
Thu Jul 4 19:13:31 2019 daemon.info hostapd: wlan1: STA 88:32:9b:b8:ff:d9 IEEE 802.11: authenticated
Thu Jul 4 19:13:31 2019 daemon.info hostapd: wlan1: STA 88:32:9b:b8:ff:d9 IEEE 802.11: associated (aid 1)
Thu Jul 4 19:13:31 2019 daemon.notice hostapd: wlan1: AP-STA-CONNECTED 88:32:9b:b8:ff:d9
Thu Jul 4 19:13:31 2019 daemon.info hostapd: wlan1: STA 88:32:9b:b8:ff:d9 WPA: pairwise key handshake completed (RSN)
Thu Jul 4 19:13:32 2019 daemon.info dnsmasq-dhcp[4354]: DHCPREQUEST(br-lan) 192.168.1.205 88:32:9b:b8:ff:d9
Thu Jul 4 19:13:32 2019 daemon.info dnsmasq-dhcp[4354]: DHCPACK(br-lan) 192.168.1.205 88:32:9b:b8:ff:d9 android-390527fd6d0f0b05
Thu Jul 4 19:13:39 2019 daemon.info dnsmasq-dhcp[4354]: DHCPDISCOVER(br-lan) 192.168.1.247 00:90:a9:e8:cf:ab
Thu Jul 4 19:13:39 2019 daemon.info dnsmasq-dhcp[4354]: DHCPOFFER(br-lan) 192.168.1.247 00:90:a9:e8:cf:ab
Thu Jul 4 19:13:39 2019 daemon.info dnsmasq-dhcp[4354]: DHCPREQUEST(br-lan) 192.168.1.247 00:90:a9:e8:cf:ab
Thu Jul 4 19:13:39 2019 daemon.info dnsmasq-dhcp[4354]: DHCPACK(br-lan) 192.168.1.247 00:90:a9:e8:cf:ab WdMyCloud
Thu Jul 4 19:14:30 2019 kern.debug kernel: [ 79.831249] ieee80211 phy0: change: 0x40
Thu Jul 4 19:14:30 2019 kern.info kernel: [ 79.854776] nf_conntrack: default automatic helper assignment has been turned off for security reasons and CT-based firewall rule not found. Use the iptables CT target to attach helpers instead.
Thu Jul 4 19:14:30 2019 kern.debug kernel: [ 79.950251] ieee80211 phy0: change: 0x100
Thu Jul 4 19:14:30 2019 daemon.notice hostapd: wlan0: DFS-CAC-COMPLETED success=1 freq=5260 ht_enabled=0 chan_offset=0 chan_width=3 cf1=5290 cf2=0
Thu Jul 4 19:14:30 2019 daemon.err hostapd: Using interface wlan0 with hwaddr 16:91:82:31:94:05 and ssid "HIUMAN_5GHz"
Thu Jul 4 19:14:30 2019 kern.debug kernel: [ 80.012407] ieee80211 phy0: change: 0x100
Thu Jul 4 19:14:30 2019 kern.debug kernel: [ 80.021242] ieee80211 phy0: change: 0x42
Thu Jul 4 19:14:31 2019 kern.debug kernel: [ 80.125251] ieee80211 phy0: change: 0x40
Thu Jul 4 19:14:31 2019 kern.info kernel: [ 80.319376] IPv6: ADDRCONF(NETDEV_CHANGE): wlan0: link becomes ready
Thu Jul 4 19:14:31 2019 kern.info kernel: [ 80.325864] br-lan: port 2(wlan0) entered blocking state
Thu Jul 4 19:14:31 2019 kern.info kernel: [ 80.331205] br-lan: port 2(wlan0) entered forwarding state
Thu Jul 4 19:14:31 2019 daemon.notice hostapd: wlan0: interface state DFS->ENABLED
Thu Jul 4 19:14:31 2019 daemon.notice hostapd: wlan0: AP-ENABLED
Thu Jul 4 19:14:31 2019 daemon.notice netifd: Network device 'wlan0' link is up
Thu Jul 4 19:15:06 2019 daemon.info hostapd: wlan1: STA b4:cd:27:a3:ed:01 IEEE 802.11: authenticated
Thu Jul 4 19:15:06 2019 daemon.info hostapd: wlan1: STA b4:cd:27:a3:ed:01 IEEE 802.11: associated (aid 2)
Thu Jul 4 19:15:06 2019 daemon.notice hostapd: wlan1: AP-STA-CONNECTED b4:cd:27:a3:ed:01
Thu Jul 4 19:15:06 2019 daemon.info hostapd: wlan1: STA b4:cd:27:a3:ed:01 WPA: pairwise key handshake completed (RSN)
Thu Jul 4 19:15:07 2019 daemon.info dnsmasq-dhcp[4354]: DHCPREQUEST(br-lan) 192.168.1.123 b4:cd:27:a3:ed:01
Thu Jul 4 19:15:07 2019 daemon.info dnsmasq-dhcp[4354]: DHCPACK(br-lan) 192.168.1.123 b4:cd:27:a3:ed:01 Honor_9_Lite-f4617896554a
Thu Jul 4 19:15:07 2019 daemon.info dnsmasq-dhcp[4354]: DHCPREQUEST(br-lan) 192.168.1.123 b4:cd:27:a3:ed:01
Thu Jul 4 19:15:07 2019 daemon.info dnsmasq-dhcp[4354]: DHCPACK(br-lan) 192.168.1.123 b4:cd:27:a3:ed:01 Honor_9_Lite-f4617896554a
Thu Jul 4 19:15:09 2019 daemon.info hostapd: wlan0: STA f0:03:8c:d8:a9:d5 IEEE 802.11: authenticated
Thu Jul 4 19:15:09 2019 daemon.info hostapd: wlan0: STA f0:03:8c:d8:a9:d5 IEEE 802.11: associated (aid 1)
Thu Jul 4 19:15:09 2019 daemon.notice hostapd: wlan0: AP-STA-CONNECTED f0:03:8c:d8:a9:d5
Thu Jul 4 19:15:09 2019 daemon.info hostapd: wlan0: STA f0:03:8c:d8:a9:d5 WPA: pairwise key handshake completed (RSN)
Thu Jul 4 19:15:09 2019 daemon.warn odhcpd[1825]: DHCPV6 SOLICIT IA_NA from 000100012479923188d7f6969cb2 on br-lan: ok fd8c:72b0:d940::bca/128
Thu Jul 4 19:15:09 2019 daemon.info dnsmasq[4354]: read /etc/hosts - 4 addresses
Thu Jul 4 19:15:09 2019 daemon.info dnsmasq[4354]: read /tmp/hosts/odhcpd - 0 addresses
Thu Jul 4 19:15:09 2019 daemon.info dnsmasq[4354]: read /tmp/hosts/dhcp.cfg01411c - 4 addresses
Thu Jul 4 19:15:09 2019 daemon.info dnsmasq-dhcp[4354]: read /etc/ethers - 0 addresses
Thu Jul 4 19:15:10 2019 daemon.warn odhcpd[1825]: DHCPV6 SOLICIT IA_NA from 000100012479923188d7f6969cb2 on br-lan: ok fd8c:72b0:d940::bca/128
Thu Jul 4 19:15:11 2019 daemon.warn odhcpd[1825]: DHCPV6 REQUEST IA_NA from 000100012479923188d7f6969cb2 on br-lan: ok fd8c:72b0:d940::bca/128
Thu Jul 4 19:15:11 2019 daemon.info dnsmasq[4354]: read /etc/hosts - 4 addresses
Thu Jul 4 19:15:11 2019 daemon.info dnsmasq[4354]: read /tmp/hosts/odhcpd - 1 addresses
Thu Jul 4 19:15:11 2019 daemon.info dnsmasq[4354]: read /tmp/hosts/dhcp.cfg01411c - 4 addresses
Thu Jul 4 19:15:11 2019 daemon.info dnsmasq-dhcp[4354]: read /etc/ethers - 0 addresses
Thu Jul 4 19:15:12 2019 daemon.warn odhcpd[1825]: DHCPV6 CONFIRM IA_NA from 000100012479923188d7f6969cb2 on br-lan: not on-link fd8c:72b0:d940::bca/128
Thu Jul 4 19:15:12 2019 daemon.warn odhcpd[1825]: DHCPV6 SOLICIT IA_NA from 000100012479923188d7f6969cb2 on br-lan: ok fd8c:72b0:d940::bca/128
Thu Jul 4 19:15:12 2019 daemon.info dnsmasq[4354]: read /etc/hosts - 4 addresses
Thu Jul 4 19:15:12 2019 daemon.info dnsmasq[4354]: read /tmp/hosts/odhcpd - 0 addresses
Thu Jul 4 19:15:12 2019 daemon.info dnsmasq[4354]: read /tmp/hosts/dhcp.cfg01411c - 4 addresses
Thu Jul 4 19:15:12 2019 daemon.info dnsmasq-dhcp[4354]: read /etc/ethers - 0 addresses
Thu Jul 4 19:15:13 2019 daemon.warn odhcpd[1825]: DHCPV6 REQUEST IA_NA from 000100012479923188d7f6969cb2 on br-lan: ok fd8c:72b0:d940::bca/128
Thu Jul 4 19:15:13 2019 daemon.info dnsmasq[4354]: read /etc/hosts - 4 addresses
Thu Jul 4 19:15:13 2019 daemon.info dnsmasq[4354]: read /tmp/hosts/odhcpd - 1 addresses
Thu Jul 4 19:15:13 2019 daemon.info dnsmasq[4354]: read /tmp/hosts/dhcp.cfg01411c - 4 addresses
Thu Jul 4 19:15:13 2019 daemon.info dnsmasq-dhcp[4354]: read /etc/ethers - 0 addresses
Thu Jul 4 19:15:14 2019 kern.debug kernel: [ 123.674398] ieee80211 phy0: Mac80211 start BA f0:03:8c:d8:a9:d5
Thu Jul 4 19:15:14 2019 daemon.info dnsmasq-dhcp[4354]: DHCPREQUEST(br-lan) 192.168.1.129 f0:03:8c:d8:a9:d5
Thu Jul 4 19:15:14 2019 daemon.info dnsmasq-dhcp[4354]: DHCPACK(br-lan) 192.168.1.129 f0:03:8c:d8:a9:d5 DESKTOP-OC3A6OM
Thu Jul 4 19:16:01 2019 daemon.err uhttpd[1919]: luci: accepted login on /admin for root from 192.168.1.129
root@OpenWrt:~# uci show network
network.loopback=interface
network.loopback.ifname='lo'
network.loopback.proto='static'
network.loopback.ipaddr='127.0.0.1'
network.loopback.netmask='255.0.0.0'
network.globals=globals
network.globals.ula_prefix='fd8c:72b0:d940::/48'
network.lan=interface
network.lan.type='bridge'
network.lan.ifname='eth0.1'
network.lan.proto='static'
network.lan.ipaddr='192.168.1.1'
network.lan.netmask='255.255.255.0'
network.lan.ip6assign='60'
network.wan=interface
network.wan.ifname='eth1.2'
network.wan.proto='dhcp'
network.wan6=interface
network.wan6.ifname='eth1.2'
network.wan6.proto='dhcpv6'
network.@switch[0]=switch
network.@switch[0].name='switch0'
network.@switch[0].reset='1'
network.@switch[0].enable_vlan='1'
network.@switch_vlan[0]=switch_vlan
network.@switch_vlan[0].device='switch0'
network.@switch_vlan[0].vlan='1'
network.@switch_vlan[0].ports='0 1 2 3 5t'
network.@switch_vlan[1]=switch_vlan
network.@switch_vlan[1].device='switch0'
network.@switch_vlan[1].vlan='2'
network.@switch_vlan[1].ports='4 6t'
network.vpn=interface
network.vpn.ifname='tun0'
network.vpn.proto='none'
root@OpenWrt:~# uci show firewall
firewall.@defaults[0]=defaults
firewall.@defaults[0].syn_flood='1'
firewall.@defaults[0].input='ACCEPT'
firewall.@defaults[0].output='ACCEPT'
firewall.@defaults[0].forward='REJECT'
firewall.@zone[0]=zone
firewall.@zone[0].name='lan'
firewall.@zone[0].network='lan'
firewall.@zone[0].input='ACCEPT'
firewall.@zone[0].output='ACCEPT'
firewall.@zone[0].forward='ACCEPT'
firewall.@zone[1]=zone
firewall.@zone[1].name='wan'
firewall.@zone[1].network='wan' 'wan6'
firewall.@zone[1].input='REJECT'
firewall.@zone[1].output='ACCEPT'
firewall.@zone[1].forward='REJECT'
firewall.@zone[1].masq='1'
firewall.@zone[1].mtu_fix='1'
firewall.@forwarding[0]=forwarding
firewall.@forwarding[0].src='lan'
firewall.@forwarding[0].dest='wan'
firewall.@rule[0]=rule
firewall.@rule[0].name='Allow-DHCP-Renew'
firewall.@rule[0].src='wan'
firewall.@rule[0].proto='udp'
firewall.@rule[0].dest_port='68'
firewall.@rule[0].target='ACCEPT'
firewall.@rule[0].family='ipv4'
firewall.@rule[1]=rule
firewall.@rule[1].name='Allow-Ping'
firewall.@rule[1].src='wan'
firewall.@rule[1].proto='icmp'
firewall.@rule[1].icmp_type='echo-request'
firewall.@rule[1].family='ipv4'
firewall.@rule[1].target='ACCEPT'
firewall.@rule[2]=rule
firewall.@rule[2].name='Allow-IGMP'
firewall.@rule[2].src='wan'
firewall.@rule[2].proto='igmp'
firewall.@rule[2].family='ipv4'
firewall.@rule[2].target='ACCEPT'
firewall.@rule[3]=rule
firewall.@rule[3].name='Allow-DHCPv6'
firewall.@rule[3].src='wan'
firewall.@rule[3].proto='udp'
firewall.@rule[3].src_ip='fc00::/6'
firewall.@rule[3].dest_ip='fc00::/6'
firewall.@rule[3].dest_port='546'
firewall.@rule[3].family='ipv6'
firewall.@rule[3].target='ACCEPT'
firewall.@rule[4]=rule
firewall.@rule[4].name='Allow-MLD'
firewall.@rule[4].src='wan'
firewall.@rule[4].proto='icmp'
firewall.@rule[4].src_ip='fe80::/10'
firewall.@rule[4].icmp_type='130/0' '131/0' '132/0' '143/0'
firewall.@rule[4].family='ipv6'
firewall.@rule[4].target='ACCEPT'
firewall.@rule[5]=rule
firewall.@rule[5].name='Allow-ICMPv6-Input'
firewall.@rule[5].src='wan'
firewall.@rule[5].proto='icmp'
firewall.@rule[5].icmp_type='echo-request' 'echo-reply' 'destination-unreachable' 'packet-too-big' 'time-exceeded' 'bad-header' 'unknown-header-type' 'router-solicitation' 'neighbour-solicitation' 'router-advertisement' 'neighbour-advertisement'
firewall.@rule[5].limit='1000/sec'
firewall.@rule[5].family='ipv6'
firewall.@rule[5].target='ACCEPT'
firewall.@rule[6]=rule
firewall.@rule[6].name='Allow-ICMPv6-Forward'
firewall.@rule[6].src='wan'
firewall.@rule[6].dest='*'
firewall.@rule[6].proto='icmp'
firewall.@rule[6].icmp_type='echo-request' 'echo-reply' 'destination-unreachable' 'packet-too-big' 'time-exceeded' 'bad-header' 'unknown-header-type'
firewall.@rule[6].limit='1000/sec'
firewall.@rule[6].family='ipv6'
firewall.@rule[6].target='ACCEPT'
firewall.@rule[7]=rule
firewall.@rule[7].name='Allow-IPSec-ESP'
firewall.@rule[7].src='wan'
firewall.@rule[7].dest='lan'
firewall.@rule[7].proto='esp'
firewall.@rule[7].target='ACCEPT'
firewall.@rule[8]=rule
firewall.@rule[8].name='Allow-ISAKMP'
firewall.@rule[8].src='wan'
firewall.@rule[8].dest='lan'
firewall.@rule[8].dest_port='500'
firewall.@rule[8].proto='udp'
firewall.@rule[8].target='ACCEPT'
firewall.@include[0]=include
firewall.@include[0].path='/etc/firewall.user'
firewall.@zone[2]=zone
firewall.@zone[2].name='vpn'
firewall.@zone[2].input='ACCEPT'
firewall.@zone[2].forward='ACCEPT'
firewall.@zone[2].output='ACCEPT'
firewall.@zone[2].network='vpn'
firewall.@zone[2].masq='1'
firewall.@forwarding[1]=forwarding
firewall.@forwarding[1].src='lan'
firewall.@forwarding[1].dest='vpn'
client
dev tun
proto udp
remote 95.174.67.211 1194
remote 185.104.184.228 1194
remote 192.230.46.140 1194
remote 193.9.113.133 1194
resolv-retry 10
remote-random
nobind
tun-mtu 1500
tun-mtu-extra 32
mssfix 1450
persist-key
persist-tun
ping 15
ping-restart 0
ping-timer-rem
reneg-sec 0
comp-lzo no
remote-cert-tls server
auth-user-pass /etc/openvpn/secret.txt
verb 3
pull
fast-io
cipher AES-256-CBC
auth SHA512
<ca>
-----BEGIN CERTIFICATE-----
MIIFCjCCAvKgAwIBAgIBATANBgkqhkiG9w0BAQ0FADA5MQswCQYDVQQGEwJQQTEQ
MA4GA1UEChMHTm9yZFZQTjEYMBYGA1UEAxMPTm9yZFZQTiBSb290IENBMB4XDTE2
MDEwMTAwMDAwMFoXDTM1MTIzMTIzNTk1OVowOTELMAkGA1UEBhMCUEExEDAOBgNV
BAoTB05vcmRWUE4xGDAWBgNVBAMTD05vcmRWUE4gUm9vdCBDQTCCAiIwDQYJKoZI
hvcNAQEBBQADggIPADCCAgoCggIBAMkr/BYhyo0F2upsIMXwC6QvkZps3NN2/eQF
kfQIS1gql0aejsKsEnmY0Kaon8uZCTXPsRH1gQNgg5D2gixdd1mJUvV3dE3y9FJr
XMoDkXdCGBodvKJyU6lcfEVF6/UxHcbBguZK9UtRHS9eJYm3rpL/5huQMCppX7kU
eQ8dpCwd3iKITqwd1ZudDqsWaU0vqzC2H55IyaZ/5/TnCk31Q1UP6BksbbuRcwOV
skEDsm6YoWDnn/IIzGOYnFJRzQH5jTz3j1QBvRIuQuBuvUkfhx1FEwhwZigrcxXu
MP+QgM54kezgziJUaZcOM2zF3lvrwMvXDMfNeIoJABv9ljw969xQ8czQCU5lMVmA
37ltv5Ec9U5hZuwk/9QO1Z+d/r6Jx0mlurS8gnCAKJgwa3kyZw6e4FZ8mYL4vpRR
hPdvRTWCMJkeB4yBHyhxUmTRgJHm6YR3D6hcFAc9cQcTEl/I60tMdz33G6m0O42s
Qt/+AR3YCY/RusWVBJB/qNS94EtNtj8iaebCQW1jHAhvGmFILVR9lzD0EzWKHkvy
WEjmUVRgCDd6Ne3eFRNS73gdv/C3l5boYySeu4exkEYVxVRn8DhCxs0MnkMHWFK6
MyzXCCn+JnWFDYPfDKHvpff/kLDobtPBf+Lbch5wQy9quY27xaj0XwLyjOltpiST
LWae/Q4vAgMBAAGjHTAbMAwGA1UdEwQFMAMBAf8wCwYDVR0PBAQDAgEGMA0GCSqG
SIb3DQEBDQUAA4ICAQC9fUL2sZPxIN2mD32VeNySTgZlCEdVmlq471o/bDMP4B8g
DxsT9vB/iZriTIEe/ILoOQF0Aqp7AgNCcLcLAmbxXQkXYCCSB35Vp06u+eTWjG0/
pyS5V14stGtw+fA0DJp5ZJV4eqJ5LqxMlYvEZ/qKTEdoCeaXv2QEmN6dVqjDoTAo
k0t5u4YRXzEVCfXAC3ocplNdtCA72wjFJcSbfif4BSC8bDACTXtnPC7nD0VndZLp
+RiNLeiENhk0oTC+UVdSc+n2nJOzkCK0vYu0Ads4JGIB7g8IB3z2t9ICmsWrgnhd
NdcOe15BincrGA8avQ1cWXsfIKEjbrnEuEk9b5jel6NfHtPKoHc9mDpRdNPISeVa
wDBM1mJChneHt59Nh8Gah74+TM1jBsw4fhJPvoc7Atcg740JErb904mZfkIEmojC
VPhBHVQ9LHBAdM8qFI2kRK0IynOmAZhexlP/aT/kpEsEPyaZQlnBn3An1CRz8h0S
PApL8PytggYKeQmRhl499+6jLxcZ2IegLfqq41dzIjwHwTMplg+1pKIOVojpWA==
-----END CERTIFICATE-----
</ca>
key-direction 1
<tls-auth>
#
# 2048 bit OpenVPN static key
#
-----BEGIN OpenVPN Static key V1-----
e685bdaf659a25a200e2b9e39e51ff03
0fc72cf1ce07232bd8b2be5e6c670143
f51e937e670eee09d4f2ea5a6e4e6996
5db852c275351b86fc4ca892d78ae002
d6f70d029bd79c4d1c26cf14e9588033
cf639f8a74809f29f72b9d58f9b8f5fe
fc7938eade40e9fed6cb92184abb2cc1
0eb1a296df243b251df0643d53724cdb
5a92a1d6cb817804c4a9319b57d53be5
80815bcfcb2df55018cc83fc43bc7ff8
2d51f9b88364776ee9d12fc85cc7ea5b
9741c4f598c485316db066d52db4540e
212e1518a9bd4828219e24b20d88f598
9427e7b372d348d352dc4c85e18cd4b9
3f8a56ddb2e64eb67adfc9b337157ff4
-----END OpenVPN Static key V1-----
</tls-auth>