151

Odp: Użycie komercyjnego klienta OpenVPN w OpenWrt.

Czy jak zainstaluje Gargoyle, to pozniej przez putty moge tak samo według tej instrukcji wyklikac klienta  vpna ?
Bede kombinował, najwyzej postawie serwer od nowa

152

Odp: Użycie komercyjnego klienta OpenVPN w OpenWrt.

W gargoyle masz klienta openvpn w dodatkach, robisz to z gui (o ile nie masz haseł). Nie rób tego ręcznie bo gargoyle parę rzeczy robi po swojemu z openvpn.

Masz niepotrzebny router, uszkodzony czy nie - chętnie przygarnę go.

153

Odp: Użycie komercyjnego klienta OpenVPN w OpenWrt.

a wireguarda moge przez terminal do gargoyla ?

154

Odp: Użycie komercyjnego klienta OpenVPN w OpenWrt.

Tylko przez konsolę. W gui tego nie ma.

Masz niepotrzebny router, uszkodzony czy nie - chętnie przygarnę go.

155

Odp: Użycie komercyjnego klienta OpenVPN w OpenWrt.

postawiłem serwer wireguarda na RPi3, wygenerowałem klienta i dostałęm gotowy plik client.conf mozna go wrzucic aby od razu działał, czy wszystko recznie trzeba dodac , soft 19.07

156

Odp: Użycie komercyjnego klienta OpenVPN w OpenWrt.

W openwrt konfiguruje się to raczej przez uci a nie z gotowego pliku.

Masz niepotrzebny router, uszkodzony czy nie - chętnie przygarnę go.

157

Odp: Użycie komercyjnego klienta OpenVPN w OpenWrt.

nie no bez sił, postawilem od nowa serwer, laptop łączy, android łączy, router nie.
Działało

root@OpenWrt:~# logread

Wed Jan 29 19:46:46 2020 kern.info kernel: [   22.337844] scsi host0: usb-storage 1-2:1.5
Wed Jan 29 19:46:47 2020 kern.notice kernel: [   23.354088] scsi 0:0:0:0: CD-ROM            L_T_E     USB SCSI CD-ROM  USB PQ: 0                                                                               ANSI: 0
Wed Jan 29 19:46:47 2020 kern.notice kernel: [   23.411887] scsi 0:0:0:1: Direct-Access     ZTE      MMC Storage      2.31 PQ: 0                                                                               ANSI: 0
Wed Jan 29 19:46:47 2020 kern.notice kernel: [   23.460921] sd 0:0:0:1: [sda] Attached SCSI removable disk
Wed Jan 29 19:46:48 2020 user.notice : Added device handler type: 8021ad
Wed Jan 29 19:46:48 2020 user.notice : Added device handler type: 8021q
Wed Jan 29 19:46:48 2020 user.notice : Added device handler type: macvlan
Wed Jan 29 19:46:48 2020 user.notice : Added device handler type: veth
Wed Jan 29 19:46:48 2020 user.notice : Added device handler type: bridge
Wed Jan 29 19:46:48 2020 user.notice : Added device handler type: Network device
Wed Jan 29 19:46:48 2020 user.notice : Added device handler type: tunnel
Wed Jan 29 19:46:48 2020 daemon.notice procd: /etc/init.d/network: 'radio1' is disabled
Wed Jan 29 19:46:49 2020 daemon.notice procd: /etc/init.d/network: 'radio1' is disabled
Wed Jan 29 19:46:53 2020 kern.info kernel: [   29.332381] mtk_soc_eth 1e100000.ethernet: PPE started
Wed Jan 29 19:46:53 2020 kern.info kernel: [   29.350155] br-lan: port 1(eth0.1) entered blocking state
Wed Jan 29 19:46:53 2020 kern.info kernel: [   29.361086] br-lan: port 1(eth0.1) entered disabled state
Wed Jan 29 19:46:53 2020 kern.info kernel: [   29.372615] device eth0.1 entered promiscuous mode
Wed Jan 29 19:46:53 2020 kern.info kernel: [   29.382202] device eth0 entered promiscuous mode
Wed Jan 29 19:46:53 2020 kern.info kernel: [   29.395316] br-lan: port 1(eth0.1) entered blocking state
Wed Jan 29 19:46:53 2020 kern.info kernel: [   29.406183] br-lan: port 1(eth0.1) entered forwarding state
Wed Jan 29 19:46:53 2020 kern.info kernel: [   29.417714] IPv6: ADDRCONF(NETDEV_UP): br-lan: link is not ready
Wed Jan 29 19:46:53 2020 daemon.notice netifd: Interface 'lan' is enabled
Wed Jan 29 19:46:53 2020 daemon.notice netifd: Interface 'lan' is setting up now
Wed Jan 29 19:46:53 2020 daemon.notice netifd: Interface 'lan' is now up
Wed Jan 29 19:46:53 2020 daemon.notice netifd: Interface 'loopback' is enabled
Wed Jan 29 19:46:53 2020 daemon.notice netifd: Interface 'loopback' is setting up now
Wed Jan 29 19:46:53 2020 daemon.notice netifd: Interface 'loopback' is now up
Wed Jan 29 19:46:53 2020 daemon.notice netifd: Interface 'wan' is setting up now
Wed Jan 29 19:46:53 2020 daemon.notice netifd: Interface 'wan6' is enabled
Wed Jan 29 19:46:53 2020 daemon.notice netifd: bridge 'br-lan' link is up
Wed Jan 29 19:46:53 2020 daemon.notice netifd: Interface 'lan' has link connectivity
Wed Jan 29 19:46:53 2020 daemon.notice netifd: Network device 'eth0' link is up
Wed Jan 29 19:46:53 2020 daemon.notice netifd: VLAN 'eth0.1' link is up
Wed Jan 29 19:46:53 2020 daemon.notice netifd: Network device 'lo' link is up
Wed Jan 29 19:46:53 2020 daemon.notice netifd: Interface 'loopback' has link connectivity
Wed Jan 29 19:46:53 2020 daemon.notice netifd: VLAN 'eth0.2' link is up
Wed Jan 29 19:46:53 2020 daemon.notice netifd: Interface 'wan6' has link connectivity
Wed Jan 29 19:46:53 2020 daemon.notice netifd: Interface 'wan6' is setting up now
Wed Jan 29 19:46:53 2020 daemon.notice netifd: wan (2027): Waiting for SIM initialization
Wed Jan 29 19:46:54 2020 daemon.err odhcp6c[2076]: Failed to send RS (Address not available)
Wed Jan 29 19:46:54 2020 user.notice firewall: Reloading firewall due to ifup of lan (br-lan)
Wed Jan 29 19:46:54 2020 daemon.notice netifd: wan (2027): PIN verification is disabled
Wed Jan 29 19:46:54 2020 kern.info kernel: [   30.392112] IPv6: ADDRCONF(NETDEV_CHANGE): br-lan: link becomes ready
Wed Jan 29 19:46:54 2020 daemon.err odhcpd[1793]: Failed to send to ff02::1%lan@br-lan (Address not available)
Wed Jan 29 19:46:54 2020 daemon.notice netifd: wan (2027): Waiting for network registration
Wed Jan 29 19:46:54 2020 daemon.err odhcp6c[2076]: Failed to send DHCPV6 message to ff02::1:2 (Address not available)
Wed Jan 29 19:46:55 2020 daemon.notice netifd: wan (2027): Starting network wan
Wed Jan 29 19:46:56 2020 daemon.notice netifd: wan (2027): Setting up wwan0
Wed Jan 29 19:46:56 2020 daemon.notice netifd: Interface 'wan' is now up
Wed Jan 29 19:46:56 2020 daemon.notice netifd: Network device 'wwan0' link is up
Wed Jan 29 19:46:56 2020 user.notice ucitrack: Setting up /etc/config/network reload dependency on /etc/config/dhcp
Wed Jan 29 19:46:56 2020 user.notice ucitrack: Setting up /etc/config/network reload dependency on /etc/config/radvd
Wed Jan 29 19:46:56 2020 daemon.notice netifd: Network alias 'wwan0' link is up
Wed Jan 29 19:46:56 2020 daemon.notice netifd: Interface 'wan_4' is enabled
Wed Jan 29 19:46:56 2020 daemon.notice netifd: Interface 'wan_4' has link connectivity
Wed Jan 29 19:46:56 2020 daemon.notice netifd: Interface 'wan_4' is setting up now
Wed Jan 29 19:46:56 2020 user.notice ucitrack: Setting up /etc/config/wireless reload dependency on /etc/config/network
Wed Jan 29 19:46:56 2020 user.notice mac80211: Failed command: iw phy phy0 set antenna 0xffffffff 0xffffffff
Wed Jan 29 19:46:56 2020 daemon.notice netifd: wan_4 (2428): udhcpc: started, v1.30.1
Wed Jan 29 19:46:56 2020 user.notice ucitrack: Setting up /etc/config/firewall reload dependency on /etc/config/luci-splash
Wed Jan 29 19:46:56 2020 user.notice ucitrack: Setting up /etc/config/firewall reload dependency on /etc/config/qos
Wed Jan 29 19:46:57 2020 daemon.notice netifd: wan_4 (2428): udhcpc: sending discover

Wed Jan 29 19:46:57 2020 daemon.info dnsmasq[1410]: using nameserver 10.2.9.7#53
Wed Jan 29 19:46:57 2020 daemon.info dnsmasq[1410]: using nameserver 10.2.9.8#53
Wed Jan 29 19:46:57 2020 user.notice ucitrack: Setting up /etc/config/dhcp reload dependency on /etc/config/odhcpd
Wed Jan 29 19:46:57 2020 daemon.err hostapd: Configuration file: /var/run/hostapd-phy0.conf
Wed Jan 29 19:46:57 2020 kern.info kernel: [   33.853645] IPv6: ADDRCONF(NETDEV_UP): wlan0: link is not ready
Wed Jan 29 19:46:57 2020 kern.info kernel: [   33.876332] br-lan: port 2(wlan0) entered blocking state
Wed Jan 29 19:46:57 2020 kern.info kernel: [   33.887012] br-lan: port 2(wlan0) entered disabled state
Wed Jan 29 19:46:57 2020 kern.info kernel: [   33.898177] device wlan0 entered promiscuous mode
Wed Jan 29 19:46:58 2020 daemon.notice hostapd: wlan0: interface state UNINITIALIZED->COUNTRY_UPDATE
Wed Jan 29 19:46:58 2020 daemon.err hostapd: Using interface wlan0 with hwaddr 8c:3b:ad:36:53:c0 and ssid "OpenWrt-2.4Ghz"
Wed Jan 29 19:46:58 2020 user.notice ucitrack: Setting up non-init /etc/config/fstab reload handler: /sbin/block mount
Wed Jan 29 19:46:58 2020 user.notice ucitrack: Setting up /etc/config/system reload trigger for non-procd /etc/init.d/led
Wed Jan 29 19:46:58 2020 user.notice ucitrack: Setting up /etc/config/system reload dependency on /etc/config/luci_statistics
Wed Jan 29 19:46:58 2020 user.notice ucitrack: Setting up /etc/config/system reload dependency on /etc/config/dhcp
Wed Jan 29 19:46:59 2020 kern.info kernel: [   34.926210] IPv6: ADDRCONF(NETDEV_CHANGE): wlan0: link becomes ready
Wed Jan 29 19:46:59 2020 kern.info kernel: [   34.939271] br-lan: port 2(wlan0) entered blocking state
Wed Jan 29 19:46:59 2020 kern.info kernel: [   34.949948] br-lan: port 2(wlan0) entered forwarding state
Wed Jan 29 19:46:59 2020 daemon.notice hostapd: wlan0: interface state COUNTRY_UPDATE->ENABLED
Wed Jan 29 19:46:59 2020 daemon.notice hostapd: wlan0: AP-ENABLED
Wed Jan 29 19:46:59 2020 user.notice firewall: Reloading firewall due to ifup of wan (wwan0)
Wed Jan 29 19:46:59 2020 daemon.notice netifd: Network device 'wlan0' link is up
Wed Jan 29 19:47:00 2020 daemon.err procd: unable to find /sbin/ujail: No such file or directory (-1)
Wed Jan 29 19:47:00 2020 daemon.info dnsmasq[1410]: exiting on receipt of SIGTERM
Wed Jan 29 19:47:00 2020 daemon.info dnsmasq[3030]: started, version 2.80 cachesize 150
Wed Jan 29 19:47:00 2020 daemon.info dnsmasq[3030]: DNS service limited to local subnets
Wed Jan 29 19:47:00 2020 daemon.info dnsmasq[3030]: compile time options: IPv6 GNU-getopt no-DBus no-i18n no-IDN DHCP no-DHCPv6 n                                                                              o-Lua TFTP no-conntrack
Wed Jan 29 19:47:00 2020 daemon.info dnsmasq[3030]: using nameserver 10.2.9.8#53
Wed Jan 29 19:47:00 2020 daemon.info dnsmasq[3030]: read /etc/hosts - 4 addresses
Wed Jan 29 19:47:00 2020 daemon.info dnsmasq[3030]: read /tmp/hosts/dhcp.cfg01411c - 2 addresses
Wed Jan 29 19:47:00 2020 daemon.notice openvpn(custom_config)[2960]: OpenVPN 2.4.7 mipsel-openwrt-linux-gnu [SSL (OpenSSL)] [LZO]                                                                               [LZ4] [EPOLL] [MH/PKTINFO] [AEAD]
Wed Jan 29 19:47:00 2020 daemon.notice openvpn(custom_config)[2960]: library versions: OpenSSL 1.1.1d  10 Sep 2019, LZO 2.10
Wed Jan 29 19:47:00 2020 daemon.err openvpn(custom_config)[2960]: neither stdin nor stderr are a tty device and you have neither                                                                               a controlling tty nor systemd - can't ask for 'Enter Private Key Password:'.  If you used --daemon, you need to use --askpass to                                                                               make passphrase-protected keys work, and you can not use --auth-nocache.
Wed Jan 29 19:47:00 2020 daemon.notice openvpn(custom_config)[2960]: Exiting due to fatal error
Wed Jan 29 19:47:01 2020 user.notice firewall: Reloading firewall due to ifup of wan_4 (wwan0)
Wed Jan 29 19:47:01 2020 daemon.info dnsmasq-dhcp[3030]: read /etc/ethers - 0 addresses
Wed Jan 29 19:47:01 2020 daemon.info dnsmasq[3030]: read /etc/hosts - 4 addresses
Wed Jan 29 19:47:01 2020 daemon.info dnsmasq[3030]: read /tmp/hosts/dhcp.cfg01411c - 2 addresses
Wed Jan 29 19:47:01 2020 daemon.info dnsmasq-dhcp[3030]: read /etc/ethers - 0 addresses
Wed Jan 29 19:47:02 2020 user.notice vpnbypass [3077]: service monitoring interfaces: vpn  ✓
Wed Jan 29 19:47:02 2020 user.notice ddns-scripts[2990]: myddns_ipv4: PID 2990 started at 2020-01-29 19:47
Wed Jan 29 19:47:03 2020 daemon.notice procd: /etc/rc.d/S96led: setting up led wan
Wed Jan 29 19:47:03 2020 user.warn ddns-scripts[2990]: myddns_ipv4: Service section disabled! - TERMINATE
Wed Jan 29 19:47:03 2020 user.info adblock-3.8.14[3243]: adblock is currently disabled, please set the config option 'adb_enabled                                                                              ' to '1' to use this service
Wed Jan 29 19:47:03 2020 user.warn ddns-scripts[2990]: myddns_ipv4: PID 2990 exit WITH ERROR 1 at 2020-01-29 19:47
Wed Jan 29 19:47:04 2020 daemon.info procd: - init complete -
Wed Jan 29 19:47:42 2020 daemon.notice openvpn(custom_config)[3643]: OpenVPN 2.4.7 mipsel-openwrt-linux-gnu [SSL (OpenSSL)] [LZO]                                                                               [LZ4] [EPOLL] [MH/PKTINFO] [AEAD]
Wed Jan 29 19:47:42 2020 daemon.notice openvpn(custom_config)[3643]: library versions: OpenSSL 1.1.1d  10 Sep 2019, LZO 2.10
Wed Jan 29 19:47:42 2020 daemon.err openvpn(custom_config)[3643]: neither stdin nor stderr are a tty device and you have neither                                                                               a controlling tty nor systemd - can't ask for 'Enter Private Key Password:'.  If you used --daemon, you need to use --askpass to                                                                               make passphrase-protected keys work, and you can not use --auth-nocache.
Wed Jan 29 19:47:42 2020 daemon.notice openvpn(custom_config)[3643]: Exiting due to fatal error
Wed Jan 29 19:47:47 2020 daemon.notice openvpn(custom_config)[3644]: OpenVPN 2.4.7 mipsel-openwrt-linux-gnu [SSL (OpenSSL)] [LZO]                                                                               [LZ4] [EPOLL] [MH/PKTINFO] [AEAD]
Wed Jan 29 19:47:47 2020 daemon.notice openvpn(custom_config)[3644]: library versions: OpenSSL 1.1.1d  10 Sep 2019, LZO 2.10
Wed Jan 29 19:47:47 2020 daemon.err openvpn(custom_config)[3644]: neither stdin nor stderr are a tty device and you have neither                                                                               a controlling tty nor systemd - can't ask for 'Enter Private Key Password:'.  If you used --daemon, you need to use --askpass to                                                                               make passphrase-protected keys work, and you can not use --auth-nocache.
Wed Jan 29 19:47:47 2020 daemon.notice openvpn(custom_config)[3644]: Exiting due to fatal error
Wed Jan 29 19:47:52 2020 daemon.notice openvpn(custom_config)[3645]: OpenVPN 2.4.7 mipsel-openwrt-linux-gnu [SSL (OpenSSL)] [LZO]                                                                               [LZ4] [EPOLL] [MH/PKTINFO] [AEAD]
Wed Jan 29 19:47:52 2020 daemon.notice openvpn(custom_config)[3645]: library versions: OpenSSL 1.1.1d  10 Sep 2019, LZO 2.10
Wed Jan 29 19:47:53 2020 daemon.err openvpn(custom_config)[3645]: neither stdin nor stderr are a tty device and you have neither                                                                               a controlling tty nor systemd - can't ask for 'Enter Private Key Password:'.  If you used --daemon, you need to use --askpass to                                                                               make passphrase-protected keys work, and you can not use --auth-nocache.
Wed Jan 29 19:47:53 2020 daemon.notice openvpn(custom_config)[3645]: Exiting due to fatal error
Wed Jan 29 19:47:58 2020 daemon.notice openvpn(custom_config)[3646]: OpenVPN 2.4.7 mipsel-openwrt-linux-gnu [SSL (OpenSSL)] [LZO]                                                                               [LZ4] [EPOLL] [MH/PKTINFO] [AEAD]
Wed Jan 29 19:47:58 2020 daemon.notice openvpn(custom_config)[3646]: library versions: OpenSSL 1.1.1d  10 Sep 2019, LZO 2.10
Wed Jan 29 19:47:58 2020 daemon.err openvpn(custom_config)[3646]: neither stdin nor stderr are a tty device and you have neither                                                                               a controlling tty nor systemd - can't ask for 'Enter Private Key Password:'.  If you used --daemon, you need to use --askpass to                                                                               make passphrase-protected keys work, and you can not use --auth-nocache.
Wed Jan 29 19:47:58 2020 daemon.notice openvpn(custom_config)[3646]: Exiting due to fatal error
Wed Jan 29 19:48:03 2020 daemon.notice openvpn(custom_config)[3647]: OpenVPN 2.4.7 mipsel-openwrt-linux-gnu [SSL (OpenSSL)] [LZO]                                                                               [LZ4] [EPOLL] [MH/PKTINFO] [AEAD]
Wed Jan 29 19:48:03 2020 daemon.notice openvpn(custom_config)[3647]: library versions: OpenSSL 1.1.1d  10 Sep 2019, LZO 2.10
Wed Jan 29 19:48:03 2020 daemon.err openvpn(custom_config)[3647]: neither stdin nor stderr are a tty device and you have neither                                                                               a controlling tty nor systemd - can't ask for 'Enter Private Key Password:'.  If you used --daemon, you need to use --askpass to                                                                               make passphrase-protected keys work, and you can not use --auth-nocache.
Wed Jan 29 19:48:03 2020 daemon.notice openvpn(custom_config)[3647]: Exiting due to fatal error
Wed Jan 29 19:48:08 2020 daemon.notice openvpn(custom_config)[3648]: OpenVPN 2.4.7 mipsel-openwrt-linux-gnu [SSL (OpenSSL)] [LZO]                                                                               [LZ4] [EPOLL] [MH/PKTINFO] [AEAD]
Wed Jan 29 19:48:08 2020 daemon.notice openvpn(custom_config)[3648]: library versions: OpenSSL 1.1.1d  10 Sep 2019, LZO 2.10
Wed Jan 29 19:48:08 2020 daemon.err openvpn(custom_config)[3648]: neither stdin nor stderr are a tty device and you have neither                                                                               a controlling tty nor systemd - can't ask for 'Enter Private Key Password:'.  If you used --daemon, you need to use --askpass to                                                                               make passphrase-protected keys work, and you can not use --auth-nocache.
Wed Jan 29 19:48:08 2020 daemon.notice openvpn(custom_config)[3648]: Exiting due to fatal error
Wed Jan 29 19:48:13 2020 daemon.notice openvpn(custom_config)[3649]: OpenVPN 2.4.7 mipsel-openwrt-linux-gnu [SSL (OpenSSL)] [LZO]                                                                               [LZ4] [EPOLL] [MH/PKTINFO] [AEAD]
Wed Jan 29 19:48:13 2020 daemon.notice openvpn(custom_config)[3649]: library versions: OpenSSL 1.1.1d  10 Sep 2019, LZO 2.10
Wed Jan 29 19:48:13 2020 daemon.err openvpn(custom_config)[3649]: neither stdin nor stderr are a tty device and you have neither                                                                               a controlling tty nor systemd - can't ask for 'Enter Private Key Password:'.  If you used --daemon, you need to use --askpass to                                                                               make passphrase-protected keys work, and you can not use --auth-nocache.
Wed Jan 29 19:48:13 2020 daemon.notice openvpn(custom_config)[3649]: Exiting due to fatal error
Wed Jan 29 19:48:18 2020 daemon.notice openvpn(custom_config)[3676]: OpenVPN 2.4.7 mipsel-openwrt-linux-gnu [SSL (OpenSSL)] [LZO]                                                                               [LZ4] [EPOLL] [MH/PKTINFO] [AEAD]
Wed Jan 29 19:48:18 2020 daemon.notice openvpn(custom_config)[3676]: library versions: OpenSSL 1.1.1d  10 Sep 2019, LZO 2.10
Wed Jan 29 19:48:18 2020 daemon.err openvpn(custom_config)[3676]: neither stdin nor stderr are a tty device and you have neither                                                                               a controlling tty nor systemd - can't ask for 'Enter Private Key Password:'.  If you used --daemon, you need to use --askpass to                                                                               make passphrase-protected keys work, and you can not use --auth-nocache.
Wed Jan 29 19:48:18 2020 daemon.notice openvpn(custom_config)[3676]: Exiting due to fatal error
Wed Jan 29 19:48:23 2020 daemon.notice openvpn(custom_config)[3677]: OpenVPN 2.4.7 mipsel-openwrt-linux-gnu [SSL (OpenSSL)] [LZO]                                                                               [LZ4] [EPOLL] [MH/PKTINFO] [AEAD]
Wed Jan 29 19:48:23 2020 daemon.notice openvpn(custom_config)[3677]: library versions: OpenSSL 1.1.1d  10 Sep 2019, LZO 2.10
Wed Jan 29 19:48:23 2020 daemon.err openvpn(custom_config)[3677]: neither stdin nor stderr are a tty device and you have neither                                                                               a controlling tty nor systemd - can't ask for 'Enter Private Key Password:'.  If you used --daemon, you need to use --askpass to                                                                               make passphrase-protected keys work, and you can not use --auth-nocache.
Wed Jan 29 19:48:23 2020 daemon.notice openvpn(custom_config)[3677]: Exiting due to fatal error
Wed Jan 29 19:48:28 2020 daemon.notice openvpn(custom_config)[3678]: OpenVPN 2.4.7 mipsel-openwrt-linux-gnu [SSL (OpenSSL)] [LZO]                                                                               [LZ4] [EPOLL] [MH/PKTINFO] [AEAD]
Wed Jan 29 19:48:28 2020 daemon.notice openvpn(custom_config)[3678]: library versions: OpenSSL 1.1.1d  10 Sep 2019, LZO 2.10
Wed Jan 29 19:48:28 2020 daemon.err openvpn(custom_config)[3678]: neither stdin nor stderr are a tty device and you have neither                                                                               a controlling tty nor systemd - can't ask for 'Enter Private Key Password:'.  If you used --daemon, you need to use --askpass to                                                                               make passphrase-protected keys work, and you can not use --auth-nocache.
Wed Jan 29 19:48:28 2020 daemon.notice openvpn(custom_config)[3678]: Exiting due to fatal error
Wed Jan 29 19:48:33 2020 daemon.notice openvpn(custom_config)[3679]: OpenVPN 2.4.7 mipsel-openwrt-linux-gnu [SSL (OpenSSL)] [LZO]                                                                               [LZ4] [EPOLL] [MH/PKTINFO] [AEAD]
Wed Jan 29 19:48:33 2020 daemon.notice openvpn(custom_config)[3679]: library versions: OpenSSL 1.1.1d  10 Sep 2019, LZO 2.10
Wed Jan 29 19:48:33 2020 daemon.err openvpn(custom_config)[3679]: neither stdin nor stderr are a tty device and you have neither                                                                               a controlling tty nor systemd - can't ask for 'Enter Private Key Password:'.  If you used --daemon, you need to use --askpass to                                                                               make passphrase-protected keys work, and you can not use --auth-nocache.
Wed Jan 29 19:48:33 2020 daemon.notice openvpn(custom_config)[3679]: Exiting due to fatal error
Wed Jan 29 19:48:38 2020 daemon.notice openvpn(custom_config)[3680]: OpenVPN 2.4.7 mipsel-openwrt-linux-gnu [SSL (OpenSSL)] [LZO]                                                                               [LZ4] [EPOLL] [MH/PKTINFO] [AEAD]
Wed Jan 29 19:48:38 2020 daemon.notice openvpn(custom_config)[3680]: library versions: OpenSSL 1.1.1d  10 Sep 2019, LZO 2.10
Wed Jan 29 19:48:38 2020 daemon.err openvpn(custom_config)[3680]: neither stdin nor stderr are a tty device and you have neither                                                                               a controlling tty nor systemd - can't ask for 'Enter Private Key Password:'.  If you used --daemon, you need to use --askpass to                                                                               make passphrase-protected keys work, and you can not use --auth-nocache.
Wed Jan 29 19:48:38 2020 daemon.notice openvpn(custom_config)[3680]: Exiting due to fatal error
Wed Jan 29 19:48:43 2020 daemon.notice openvpn(custom_config)[3681]: OpenVPN 2.4.7 mipsel-openwrt-linux-gnu [SSL (OpenSSL)] [LZO]                                                                               [LZ4] [EPOLL] [MH/PKTINFO] [AEAD]
Wed Jan 29 19:48:43 2020 daemon.notice openvpn(custom_config)[3681]: library versions: OpenSSL 1.1.1d  10 Sep 2019, LZO 2.10
Wed Jan 29 19:48:43 2020 daemon.err openvpn(custom_config)[3681]: neither stdin nor stderr are a tty device and you have neither                                                                               a controlling tty nor systemd - can't ask for 'Enter Private Key Password:'.  If you used --daemon, you need to use --askpass to                                                                               make passphrase-protected keys work, and you can not use --auth-nocache.
Wed Jan 29 19:48:43 2020 daemon.notice openvpn(custom_config)[3681]: Exiting due to fatal error
Wed Jan 29 19:48:48 2020 daemon.notice openvpn(custom_config)[3682]: OpenVPN 2.4.7 mipsel-openwrt-linux-gnu [SSL (OpenSSL)] [LZO]                                                                               [LZ4] [EPOLL] [MH/PKTINFO] [AEAD]
Wed Jan 29 19:48:48 2020 daemon.notice openvpn(custom_config)[3682]: library versions: OpenSSL 1.1.1d  10 Sep 2019, LZO 2.10
Wed Jan 29 19:48:48 2020 daemon.err openvpn(custom_config)[3682]: neither stdin nor stderr are a tty device and you have neither                                                                               a controlling tty nor systemd - can't ask for 'Enter Private Key Password:'.  If you used --daemon, you need to use --askpass to                                                                               make passphrase-protected keys work, and you can not use --auth-nocache.
Wed Jan 29 19:48:48 2020 daemon.notice openvpn(custom_config)[3682]: Exiting due to fatal error
Wed Jan 29 19:48:53 2020 daemon.notice openvpn(custom_config)[3691]: OpenVPN 2.4.7 mipsel-openwrt-linux-gnu [SSL (OpenSSL)] [LZO]                                                                               [LZ4] [EPOLL] [MH/PKTINFO] [AEAD]

Wed Jan 29 19:49:28 2020 daemon.err openvpn(custom_config)[3706]: neither stdin nor stderr are a tty device and you have neither                                                                               a controlling tty nor systemd - can't ask for 'Enter Private Key Password:'.  If you used --daemon, you need to use --askpass to                                                                               make passphrase-protected keys work, and you can not use --auth-nocache.
Wed Jan 29 19:49:28 2020 daemon.notice openvpn(custom_config)[3706]: Exiting due to fatal error
Wed Jan 29 19:49:33 2020 daemon.info hostapd: wlan0: STA b0:c1:9e:0a:6f:39 IEEE 802.11: authenticated
Wed Jan 29 19:49:33 2020 daemon.info hostapd: wlan0: STA b0:c1:9e:0a:6f:39 IEEE 802.11: associated (aid 1)
Wed Jan 29 19:49:33 2020 daemon.notice hostapd: wlan0: AP-STA-CONNECTED b0:c1:9e:0a:6f:39
Wed Jan 29 19:49:33 2020 daemon.info hostapd: wlan0: STA b0:c1:9e:0a:6f:39 WPA: pairwise key handshake completed (RSN)
Wed Jan 29 19:49:33 2020 daemon.notice openvpn(custom_config)[3707]: OpenVPN 2.4.7 mipsel-openwrt-linux-gnu [SSL (OpenSSL)] [LZO]                                                                               [LZ4] [EPOLL] [MH/PKTINFO] [AEAD]
Wed Jan 29 19:49:33 2020 daemon.notice openvpn(custom_config)[3707]: library versions: OpenSSL 1.1.1d  10 Sep 2019, LZO 2.10
Wed Jan 29 19:49:33 2020 daemon.err openvpn(custom_config)[3707]: neither stdin nor stderr are a tty device and you have neither                                                                               a controlling tty nor systemd - can't ask for 'Enter Private Key Password:'.  If you used --daemon, you need to use --askpass to                                                                               make passphrase-protected keys work, and you can not use --auth-nocache.
Wed Jan 29 19:49:33 2020 daemon.notice openvpn(custom_config)[3707]: Exiting due to fatal error
Wed Jan 29 19:49:36 2020 daemon.info dnsmasq-dhcp[3030]: DHCPDISCOVER(br-lan) b0:c1:9e:0a:6f:39
Wed Jan 29 19:49:36 2020 daemon.info dnsmasq-dhcp[3030]: DHCPOFFER(br-lan) 192.168.1.151 b0:c1:9e:0a:6f:39
Wed Jan 29 19:49:36 2020 daemon.info dnsmasq-dhcp[3030]: DHCPDISCOVER(br-lan) b0:c1:9e:0a:6f:39
Wed Jan 29 19:49:36 2020 daemon.info dnsmasq-dhcp[3030]: DHCPOFFER(br-lan) 192.168.1.151 b0:c1:9e:0a:6f:39
Wed Jan 29 19:49:36 2020 daemon.info dnsmasq-dhcp[3030]: DHCPREQUEST(br-lan) 192.168.1.151 b0:c1:9e:0a:6f:39
Wed Jan 29 19:49:36 2020 daemon.info dnsmasq-dhcp[3030]: DHCPACK(br-lan) 192.168.1.151
Wed Jan 29 19:49:48 2020 daemon.notice openvpn(custom_config)[3710]: Exiting due to fatal error
Wed Jan 29 19:49:53 2020 daemon.notice openvpn(custom_config)[3711]: OpenVPN 2.4.7 mipsel-openwrt-linux-gnu [SSL (OpenSSL)] [LZO]                                                                               [LZ4] [EPOLL] [MH/PKTINFO] [AEAD]
Wed Jan 29 19:49:53 2020 daemon.notice openvpn(custom_config)[3711]: library versions: OpenSSL 1.1.1d  10 Sep 2019, LZO 2.10
Wed Jan 29 19:49:53 2020 daemon.err openvpn(custom_config)[3711]: neither stdin nor stderr are a tty device and you have neither                                                                               a controlling tty nor systemd - can't ask for 'Enter Private Key Password:'.  If you used --daemon, you need to use --askpass to                                                                               make passphrase-protected keys work, and you can not use --auth-nocache.
Wed Jan 29 19:49:53 2020 daemon.notice openvpn(custom_config)[3711]: Exiting due to fatal error
Wed Jan 29 19:49:58 2020 daemon.notice openvpn(custom_config)[3720]: OpenVPN 2.4.7 mipsel-openwrt-linux-gnu [SSL (OpenSSL)] [LZO]                                                                               [LZ4] [EPOLL] [MH/PKTINFO] [AEAD]
Wed Jan 29 19:49:58 2020 daemon.notice openvpn(custom_config)[3720]: library versions: OpenSSL 1.1.1d  10 Sep 2019, LZO 2.10
Wed Jan 29 19:49:59 2020 daemon.err openvpn(custom_config)[3720]: neither stdin nor stderr are a tty device and you have neither                                                                               a controlling tty nor systemd - can't ask for 'Enter Private Key Password:'.  If you used --daemon, you need to use --askpass to                                                                               make passphrase-protected keys work, and you can not use --auth-nocache.
Wed Jan 29 19:49:59 2020 daemon.notice openvpn(custom_config)[3720]: Exiting due to fatal error
Wed Jan 29 19:50:04 2020 daemon.notice openvpn(custom_config)[3721]: OpenVPN 2.4.7 mipsel-openwrt-linux-gnu [SSL (OpenSSL)] [LZO]                                                                               [LZ4] [EPOLL] [MH/PKTINFO] [AEAD]
Wed Jan 29 19:50:04 2020 daemon.notice openvpn(custom_config)[3721]: library versions: OpenSSL 1.1.1d  10 Sep 2019, LZO 2.10
Wed Jan 29 19:50:04 2020 daemon.err openvpn(custom_config)[3721]: neither stdin nor stderr are a tty device and you have neither                                                                               a controlling tty nor systemd - can't ask for 'Enter Private Key Password:'.  If you used --daemon, you need to use --askpass to                                                                               make passphrase-protected keys work, and you can not use --auth-nocache.
Wed Jan 29 19:50:04 2020 daemon.notice openvpn(custom_config)[3721]: Exiting due to fatal error
Wed Jan 29 19:50:09 2020 daemon.notice openvpn(custom_config)[3722]: OpenVPN 2.4.7 mipsel-openwrt-linux-gnu [SSL (OpenSSL)] [LZO]                                                                               [LZ4] [EPOLL] [MH/PKTINFO] [AEAD]
Wed Jan 29 19:50:09 2020 daemon.notice openvpn(custom_config)[3722]: library versions: OpenSSL 1.1.1d  10 Sep 2019, LZO 2.10
Wed Jan 29 19:50:09 2020 daemon.err openvpn(custom_config)[3722]: neither stdin nor stderr are a tty device and you have neither                                                                               a controlling tty nor systemd - can't ask for 'Enter Private Key Password:'.  If you used --daemon, you need to use --askpass to                                                                               make passphrase-protected keys work, and you can not use --auth-nocache.
Wed Jan 29 19:50:09 2020 daemon.notice openvpn(custom_config)[3722]: Exiting due to fatal error
Wed Jan 29 19:50:14 2020 daemon.notice openvpn(custom_config)[3723]: OpenVPN 2.4.7 mipsel-openwrt-linux-gnu [SSL (OpenSSL)] [LZO]                                                                               [LZ4] [EPOLL] [MH/PKTINFO] [AEAD]
Wed Jan 29 19:50:14 2020 daemon.notice openvpn(custom_config)[3723]: library versions: OpenSSL 1.1.1d  10 Sep 2019, LZO 2.10
Wed Jan 29 19:50:14 2020 daemon.err openvpn(custom_config)[3723]: neither stdin nor stderr are a tty device and you have neither                                                                               a controlling tty nor systemd - can't ask for 'Enter Private Key Password:'.  If you used --daemon, you need to use --askpass to                                                                               make passphrase-protected keys work, and you can not use --auth-nocache.
Wed Jan 29 19:50:14 2020 daemon.notice openvpn(custom_config)[3723]: Exiting due to fatal error
Wed Jan 29 19:50:19 2020 daemon.notice openvpn(custom_config)[3724]: OpenVPN 2.4.7 mipsel-openwrt-linux-gnu [SSL (OpenSSL)] [LZO]                                                                               [LZ4] [EPOLL] [MH/PKTINFO] [AEAD]
Wed Jan 29 19:50:19 2020 daemon.notice openvpn(custom_config)[3724]: library versions: OpenSSL 1.1.1d  10 Sep 2019, LZO 2.10
Wed Jan 29 19:50:19 2020 daemon.err openvpn(custom_config)[3724]: neither stdin nor stderr are a tty device and you have neither                                                                               a controlling tty nor systemd - can't ask for 'Enter Private Key Password:'.  If you used --daemon, you need to use --askpass to                                                                               make passphrase-protected keys work, and you can not use --auth-nocache.
Wed Jan 29 19:50:19 2020 daemon.notice openvpn(custom_config)[3724]: Exiting due to fatal error
Wed Jan 29 19:50:24 2020 daemon.notice openvpn(custom_config)[3725]: OpenVPN 2.4.7 mipsel-openwrt-linux-gnu [SSL (OpenSSL)] [LZO]                                                                               [LZ4] [EPOLL] [MH/PKTINFO] [AEAD]
Wed Jan 29 19:50:24 2020 daemon.notice openvpn(custom_config)[3725]: library versions: OpenSSL 1.1.1d  10 Sep 2019, LZO 2.10
Wed Jan 29 19:50:24 2020 daemon.err openvpn(custom_config)[3725]: neither stdin nor stderr are a tty device and you have neither                                                                               a controlling tty nor systemd - can't ask for 'Enter Private Key Password:'.  If you used --daemon, you need to use --askpass to                                                                               make passphrase-protected keys work, and you can not use --auth-nocache.
Wed Jan 29 19:50:24 2020 daemon.notice openvpn(custom_config)[3725]: Exiting due to fatal error
Wed Jan 29 19:50:29 2020 daemon.notice openvpn(custom_config)[3726]: OpenVPN 2.4.7 mipsel-openwrt-linux-gnu [SSL (OpenSSL)] [LZO]                                                                               [LZ4] [EPOLL] [MH/PKTINFO] [AEAD]
Wed Jan 29 19:50:29 2020 daemon.notice openvpn(custom_config)[3726]: library versions: OpenSSL 1.1.1d  10 Sep 2019, LZO 2.10
Wed Jan 29 19:50:29 2020 daemon.err openvpn(custom_config)[3726]: neither stdin nor stderr are a tty device and you have neither                                                                               a controlling tty nor systemd - can't ask for 'Enter Private Key Password:'.  If you used --daemon, you need to use --askpass to                                                                               make passphrase-protected keys work, and you can not use --auth-nocache.
Wed Jan 29 19:50:29 2020 daemon.notice openvpn(custom_config)[3726]: Exiting due to fatal error
Wed Jan 29 19:50:33 2020 daemon.info hostapd: wlan0: STA 28:e3:47:d5:28:c0 IEEE 802.11: authenticated
Wed Jan 29 19:50:33 2020 daemon.info hostapd: wlan0: STA 28:e3:47:d5:28:c0 IEEE 802.11: associated (aid 2)
Wed Jan 29 19:50:33 2020 daemon.notice hostapd: wlan0: AP-STA-CONNECTED 28:e3:47:d5:28:c0
Wed Jan 29 19:50:33 2020 daemon.info hostapd: wlan0: STA 28:e3:47:d5:28:c0 WPA: pairwise key handshake completed (RSN)
Wed Jan 29 19:50:33 2020 daemon.info dnsmasq-dhcp[3030]: DHCPREQUEST(br-lan) 192.168.1.247 28:e3:47:d5:28:c0
Wed Jan 29 19:50:33 2020 daemon.info dnsmasq-dhcp[3030]: DHCPACK(br-lan) 192.168.1.247 28:e3:47:d5:28:c0 DESKTOP-DCFLMSB
Wed Jan 29 19:50:34 2020 daemon.notice openvpn(custom_config)[3727]: OpenVPN 2.4.7 mipsel-openwrt-linux-gnu [SSL (OpenSSL)] [LZO]                                                                               [LZ4] [EPOLL] [MH/PKTINFO] [AEAD]
Wed Jan 29 19:50:34 2020 daemon.notice openvpn(custom_config)[3727]: library versions: OpenSSL 1.1.1d  10 Sep 2019, LZO 2.10
Wed Jan 29 19:50:34 2020 daemon.err openvpn(custom_config)[3727]: neither stdin nor stderr are a tty device and you have neither                                                                               a controlling tty nor systemd - can't ask for 'Enter Private Key Password:'.  If you used --daemon, you need to use --askpass to                                                                               make passphrase-protected keys work, and you can not use --auth-nocache.
Wed Jan 29 19:50:34 2020 daemon.notice openvpn(custom_config)[3727]: Exiting due to fatal error
Wed Jan 29 19:50:34 2020 daemon.info dnsmasq[3030]: read /etc/hosts - 4 addresses
Wed Jan 29 19:50:34 2020 daemon.info dnsmasq[3030]: read /tmp/hosts/odhcpd - 0 addresses
Wed Jan 29 19:50:34 2020 daemon.info dnsmasq[3030]: read /tmp/hosts/dhcp.cfg01411c - 2 addresses
Wed Jan 29 19:50:34 2020 daemon.info dnsmasq-dhcp[3030]: read /etc/ethers - 0 addresses
Wed Jan 29 19:50:35 2020 daemon.info dnsmasq[3030]: read /etc/hosts - 4 addresses
Wed Jan 29 19:50:35 2020 daemon.info dnsmasq[3030]: read /tmp/hosts/odhcpd - 1 addresses
Wed Jan 29 19:50:35 2020 daemon.info dnsmasq[3030]: read /tmp/hosts/dhcp.cfg01411c - 2 addresses
Wed Jan 29 19:50:35 2020 daemon.info dnsmasq-dhcp[3030]: read /etc/ethers - 0 addresses
Wed Jan 29 19:50:36 2020 daemon.info dnsmasq-dhcp[3030]: DHCPREQUEST(br-lan) 192.168.1.247 28:e3:47:d5:28:c0
Wed Jan 29 19:50:36 2020 daemon.info dnsmasq-dhcp[3030]: DHCPACK(br-lan) 192.168.1.247 28:e3:47:d5:28:c0 DESKTOP-DCFLMSB
Wed Jan 29 19:50:39 2020 daemon.notice openvpn(custom_config)[3744]: OpenVPN 2.4.7 mipsel-openwrt-linux-gnu [SSL (OpenSSL)] [LZO]                                                                               [LZ4] [EPOLL] [MH/PKTINFO] [AEAD]
Wed Jan 29 19:50:39 2020 daemon.notice openvpn(custom_config)[3744]: library versions: OpenSSL 1.1.1d  10 Sep 2019, LZO 2.10
Wed Jan 29 19:50:39 2020 daemon.err openvpn(custom_config)[3744]: neither stdin nor stderr are a tty device and you have neither                                                                               a controlling tty nor systemd - can't ask for 'Enter Private Key Password:'.  If you used --daemon, you need to use --askpass to                                                                               make passphrase-protected keys work, and you can not use --auth-nocache.
Wed Jan 29 19:50:39 2020 daemon.notice openvpn(custom_config)[3744]: Exiting due to fatal error
Wed Jan 29 19:50:44 2020 daemon.notice openvpn(custom_config)[3768]: OpenVPN 2.4.7 mipsel-openwrt-linux-gnu [SSL (OpenSSL)] [LZO]                                                                               [LZ4] [EPOLL] [MH/PKTINFO] [AEAD]
Wed Jan 29 19:50:44 2020 daemon.notice openvpn(custom_config)[3768]: library versions: OpenSSL 1.1.1d  10 Sep 2019, LZO 2.10
Wed Jan 29 19:50:44 2020 daemon.err openvpn(custom_config)[3768]: neither stdin nor stderr are a tty device and you have neither                                                                               a controlling tty nor systemd - can't ask for 'Enter Private Key Password:'.  If you used --daemon, you need to use --askpass to                                                                               make passphrase-protected keys work, and you can not use --auth-nocache.
Wed Jan 29 19:50:44 2020 daemon.notice openvpn(custom_config)[3768]: Exiting due to fatal error
Wed Jan 29 19:50:44 2020 daemon.err uhttpd[1902]: luci: accepted login on /admin/vpn/openvpn for root from 192.168.1.247
Wed Jan 29 19:50:49 2020 daemon.notice openvpn(custom_config)[3851]: OpenVPN 2.4.7 mipsel-openwrt-linux-gnu [SSL (OpenSSL)] [LZO]                                                                               [LZ4] [EPOLL] [MH/PKTINFO] [AEAD]
Wed Jan 29 19:50:49 2020 daemon.notice openvpn(custom_config)[3851]: library versions: OpenSSL 1.1.1d  10 Sep 2019, LZO 2.10
Wed Jan 29 19:50:49 2020 daemon.err openvpn(custom_config)[3851]: neither stdin nor stderr are a tty device and you have neither                                                                               a controlling tty nor systemd - can't ask for 'Enter Private Key Password:'.  If you used --daemon, you need to use --askpass to                                                                               make passphrase-protected keys work, and you can not use --auth-nocache.
Wed Jan 29 19:50:49 2020 daemon.notice openvpn(custom_config)[3851]: Exiting due to fatal error
Wed Jan 29 19:50:54 2020 daemon.notice openvpn(custom_config)[3899]: OpenVPN 2.4.7 mipsel-openwrt-linux-gnu [SSL (OpenSSL)] [LZO]                                                                               [LZ4] [EPOLL] [MH/PKTINFO] [AEAD]
Wed Jan 29 19:50:54 2020 daemon.notice openvpn(custom_config)[3899]: library versions: OpenSSL 1.1.1d  10 Sep 2019, LZO 2.10
Wed Jan 29 19:50:54 2020 daemon.err openvpn(custom_config)[3899]: neither stdin nor stderr are a tty device and you have neither                                                                               a controlling tty nor systemd - can't ask for 'Enter Private Key Password:'.  If you used --daemon, you need to use --askpass to                                                                               make passphrase-protected keys work, and you can not use --auth-nocache.
Wed Jan 29 19:50:54 2020 daemon.notice openvpn(custom_config)[3899]: Exiting due to fatal error
Wed Jan 29 19:50:59 2020 daemon.notice openvpn(custom_config)[3900]: OpenVPN 2.4.7 mipsel-openwrt-linux-gnu [SSL (OpenSSL)] [LZO]                                                                               [LZ4] [EPOLL] [MH/PKTINFO] [AEAD]
Wed Jan 29 19:50:59 2020 daemon.notice openvpn(custom_config)[3900]: library versions: OpenSSL 1.1.1d  10 Sep 2019, LZO 2.10
Wed Jan 29 19:50:59 2020 daemon.err openvpn(custom_config)[3900]: neither stdin nor stderr are a tty device and you have neither                                                                               a controlling tty nor systemd - can't ask for 'Enter Private Key Password:'.  If you used --daemon, you need to use --askpass to                                                                               make passphrase-protected keys work, and you can not use --auth-nocache.
Wed Jan 29 19:50:59 2020 daemon.notice openvpn(custom_config)[3900]: Exiting due to fatal error
Wed Jan 29 19:51:04 2020 daemon.notice openvpn(custom_config)[3901]: OpenVPN 2.4.7 mipsel-openwrt-linux-gnu [SSL (OpenSSL)] [LZO]                                                                               [LZ4] [EPOLL] [MH/PKTINFO] [AEAD]
Wed Jan 29 19:51:04 2020 daemon.notice openvpn(custom_config)[3901]: library versions: OpenSSL 1.1.1d  10 Sep 2019, LZO 2.10
Wed Jan 29 19:51:04 2020 daemon.err openvpn(custom_config)[3901]: neither stdin nor stderr are a tty device and you have neither                                                                               a controlling tty nor systemd - can't ask for 'Enter Private Key Password:'.  If you used --daemon, you need to use --askpass to                                                                               make passphrase-protected keys work, and you can not use --auth-nocache.
Wed Jan 29 19:51:04 2020 daemon.notice openvpn(custom_config)[3901]: Exiting due to fatal error
Wed Jan 29 19:51:09 2020 daemon.notice openvpn(custom_config)[3902]: OpenVPN 2.4.7 mipsel-openwrt-linux-gnu [SSL (OpenSSL)] [LZO]                                                                               [LZ4] [EPOLL] [MH/PKTINFO] [AEAD]
Wed Jan 29 19:51:09 2020 daemon.notice openvpn(custom_config)[3902]: library versions: OpenSSL 1.1.1d  10 Sep 2019, LZO 2.10
Wed Jan 29 19:51:09 2020 daemon.err openvpn(custom_config)[3902]: neither stdin nor stderr are a tty device and you have neither                                                                               a controlling tty nor systemd - can't ask for 'Enter Private Key Password:'.  If you used --daemon, you need to use --askpass to                                                                               make passphrase-protected keys work, and you can not use --auth-nocache.
Wed Jan 29 19:51:09 2020 daemon.notice openvpn(custom_config)[3902]: Exiting due to fatal error
Wed Jan 29 19:51:14 2020 daemon.notice openvpn(custom_config)[3903]: OpenVPN 2.4.7 mipsel-openwrt-linux-gnu [SSL (OpenSSL)] [LZO]                                                                               [LZ4] [EPOLL] [MH/PKTINFO] [AEAD]
Wed Jan 29 19:51:14 2020 daemon.notice openvpn(custom_config)[3903]: library versions: OpenSSL 1.1.1d  10 Sep 2019, LZO 2.10
Wed Jan 29 19:51:14 2020 daemon.err openvpn(custom_config)[3903]: neither stdin nor stderr are a tty device and you have neither                                                                               a controlling tty nor systemd - can't ask for 'Enter Private Key Password:'.  If you used --daemon, you need to use --askpass to                                                                               make passphrase-protected keys work, and you can not use --auth-nocache.
Wed Jan 29 19:51:14 2020 daemon.notice openvpn(custom_config)[3903]: Exiting due to fatal error
Wed Jan 29 19:51:19 2020 daemon.notice openvpn(custom_config)[3904]: OpenVPN 2.4.7 mipsel-openwrt-linux-gnu [SSL (OpenSSL)] [LZO]                                                                               [LZ4] [EPOLL] [MH/PKTINFO] [AEAD]
Wed Jan 29 19:51:19 2020 daemon.notice openvpn(custom_config)[3904]: library versions: OpenSSL 1.1.1d  10 Sep 2019, LZO 2.10
Wed Jan 29 19:51:19 2020 daemon.err openvpn(custom_config)[3904]: neither stdin nor stderr are a tty device and you have neither                                                                               a controlling tty nor systemd - can't ask for 'Enter Private Key Password:'.  If you used --daemon, you need to use --askpass to                                                                               make passphrase-protected keys work, and you can not use --auth-nocache.
Wed Jan 29 19:51:19 2020 daemon.notice openvpn(custom_config)[3904]: Exiting due to fatal error
Wed Jan 29 19:51:24 2020 daemon.notice openvpn(custom_config)[3905]: OpenVPN 2.4.7 mipsel-openwrt-linux-gnu [SSL (OpenSSL)] [LZO]                                                                               [LZ4] [EPOLL] [MH/PKTINFO] [AEAD]
Wed Jan 29 19:51:24 2020 daemon.notice openvpn(custom_config)[3905]: library versions: OpenSSL 1.1.1d  10 Sep 2019, LZO 2.10
Wed Jan 29 19:51:24 2020 daemon.err openvpn(custom_config)[3905]: neither stdin nor stderr are a tty device and you have neither                                                                               a controlling tty nor systemd - can't ask for 'Enter Private Key Password:'.  If you used --daemon, you need to use --askpass to                                                                               make passphrase-protected keys work, and you can not use --auth-nocache.
Wed Jan 29 19:51:24 2020 daemon.notice openvpn(custom_config)[3905]: Exiting due to fatal error
Wed Jan 29 19:51:29 2020 daemon.notice openvpn(custom_config)[3906]: OpenVPN 2.4.7 mipsel-openwrt-linux-gnu [SSL (OpenSSL)] [LZO]                                                                               [LZ4] [EPOLL] [MH/PKTINFO] [AEAD]
Wed Jan 29 19:51:29 2020 daemon.notice openvpn(custom_config)[3906]: library versions: OpenSSL 1.1.1d  10 Sep 2019, LZO 2.10
Wed Jan 29 19:51:29 2020 daemon.err openvpn(custom_config)[3906]: neither stdin nor stderr are a tty device and you have neither                                                                               a controlling tty nor systemd - can't ask for 'Enter Private Key Password:'.  If you used --daemon, you need to use --askpass to                                                                               make passphrase-protected keys work, and you can not use --auth-nocache.
Wed Jan 29 19:51:29 2020 daemon.notice openvpn(custom_config)[3906]: Exiting due to fatal error
Wed Jan 29 19:51:34 2020 daemon.notice openvpn(custom_config)[3907]: OpenVPN 2.4.7 mipsel-openwrt-linux-gnu [SSL (OpenSSL)] [LZO]                                                                               [LZ4] [EPOLL] [MH/PKTINFO] [AEAD]
Wed Jan 29 19:51:34 2020 daemon.notice openvpn(custom_config)[3907]: library versions: OpenSSL 1.1.1d  10 Sep 2019, LZO 2.10
Wed Jan 29 19:51:34 2020 daemon.err openvpn(custom_config)[3907]: neither stdin nor stderr are a tty device and you have neither                                                                               a controlling tty nor systemd - can't ask for 'Enter Private Key Password:'.  If you used --daemon, you need to use --askpass to                                                                               make passphrase-protected keys work, and you can not use --auth-nocache.
Wed Jan 29 19:51:34 2020 daemon.notice openvpn(custom_config)[3907]: Exiting due to fatal error
Wed Jan 29 19:51:39 2020 daemon.notice openvpn(custom_config)[3908]: OpenVPN 2.4.7 mipsel-openwrt-linux-gnu [SSL (OpenSSL)] [LZO]                                                                               [LZ4] [EPOLL] [MH/PKTINFO] [AEAD]
Wed Jan 29 19:51:39 2020 daemon.notice openvpn(custom_config)[3908]: library versions: OpenSSL 1.1.1d  10 Sep 2019, LZO 2.10
Wed Jan 29 19:51:39 2020 daemon.err openvpn(custom_config)[3908]: neither stdin nor stderr are a tty device and you have neither                                                                               a controlling tty nor systemd - can't ask for 'Enter Private Key Password:'.  If you used --daemon, you need to use --askpass to                                                                               make passphrase-protected keys work, and you can not use --auth-nocache.
Wed Jan 29 19:51:39 2020 daemon.notice openvpn(custom_config)[3908]: Exiting due to fatal error
Wed Jan 29 19:51:44 2020 daemon.notice openvpn(custom_config)[3909]: OpenVPN 2.4.7 mipsel-openwrt-linux-gnu [SSL (OpenSSL)] [LZO]                                                                               [LZ4] [EPOLL] [MH/PKTINFO] [AEAD]
Wed Jan 29 19:51:44 2020 daemon.notice openvpn(custom_config)[3909]: library versions: OpenSSL 1.1.1d  10 Sep 2019, LZO 2.10
Wed Jan 29 19:51:44 2020 daemon.err openvpn(custom_config)[3909]: neither stdin nor stderr are a tty device and you have neither                                                                               a controlling tty nor systemd - can't ask for 'Enter Private Key Password:'.  If you used --daemon, you need to use --askpass to                                                                               make passphrase-protected keys work, and you can not use --auth-nocache.
Wed Jan 29 19:51:44 2020 daemon.notice openvpn(custom_config)[3909]: Exiting due to fatal error
Wed Jan 29 19:51:49 2020 daemon.notice openvpn(custom_config)[3910]: OpenVPN 2.4.7 mipsel-openwrt-linux-gnu [SSL (OpenSSL)] [LZO]                                                                               [LZ4] [EPOLL] [MH/PKTINFO] [AEAD]
Wed Jan 29 19:51:49 2020 daemon.notice openvpn(custom_config)[3910]: library versions: OpenSSL 1.1.1d  10 Sep 2019, LZO 2.10
Wed Jan 29 19:51:49 2020 daemon.err openvpn(custom_config)[3910]: neither stdin nor stderr are a tty device and you have neither                                                                               a controlling tty nor systemd - can't ask for 'Enter Private Key Password:'.  If you used --daemon, you need to use --askpass to                                                                               make passphrase-protected keys work, and you can not use --auth-nocache.
Wed Jan 29 19:51:49 2020 daemon.notice openvpn(custom_config)[3910]: Exiting due to fatal error
Wed Jan 29 19:51:54 2020 daemon.notice openvpn(custom_config)[3911]: OpenVPN 2.4.7 mipsel-openwrt-linux-gnu [SSL (OpenSSL)] [LZO]                                                                               [LZ4] [EPOLL] [MH/PKTINFO] [AEAD]
Wed Jan 29 19:51:54 2020 daemon.notice openvpn(custom_config)[3911]: library versions: OpenSSL 1.1.1d  10 Sep 2019, LZO 2.10
Wed Jan 29 19:51:54 2020 daemon.err openvpn(custom_config)[3911]: neither stdin nor stderr are a tty device and you have neither                                                                               a controlling tty nor systemd - can't ask for 'Enter Private Key Password:'.  If you used --daemon, you need to use --askpass to                                                                               make passphrase-protected keys work, and you can not use --auth-nocache.
Wed Jan 29 19:51:54 2020 daemon.notice openvpn(custom_config)[3911]: Exiting due to fatal error
Wed Jan 29 19:51:59 2020 daemon.notice openvpn(custom_config)[3912]: OpenVPN 2.4.7 mipsel-openwrt-linux-gnu [SSL (OpenSSL)] [LZO]                                                                               [LZ4] [EPOLL] [MH/PKTINFO] [AEAD]
Wed Jan 29 19:51:59 2020 daemon.notice openvpn(custom_config)[3912]: library versions: OpenSSL 1.1.1d  10 Sep 2019, LZO 2.10
Wed Jan 29 19:51:59 2020 daemon.err openvpn(custom_config)[3912]: neither stdin nor stderr are a tty device and you have neither                                                                               a controlling tty nor systemd - can't ask for 'Enter Private Key Password:'.  If you used --daemon, you need to use --askpass to                                                                               make passphrase-protected keys work, and you can not use --auth-nocache.
Wed Jan 29 19:51:59 2020 daemon.notice openvpn(custom_config)[3912]: Exiting due to fatal error
Wed Jan 29 19:52:04 2020 daemon.notice openvpn(custom_config)[3913]: OpenVPN 2.4.7 mipsel-openwrt-linux-gnu [SSL (OpenSSL)] [LZO]                                                                               [LZ4] [EPOLL] [MH/PKTINFO] [AEAD]
Wed Jan 29 19:52:04 2020 daemon.notice openvpn(custom_config)[3913]: library versions: OpenSSL 1.1.1d  10 Sep 2019, LZO 2.10
Wed Jan 29 19:52:04 2020 daemon.err openvpn(custom_config)[3913]: neither stdin nor stderr are a tty device and you have neither                                                                               a controlling tty nor systemd - can't ask for 'Enter Private Key Password:'.  If you used --daemon, you need to use --askpass to                                                                               make passphrase-protected keys work, and you can not use --auth-nocache.
Wed Jan 29 19:52:04 2020 daemon.notice openvpn(custom_config)[3913]: Exiting due to fatal error
Wed Jan 29 19:52:09 2020 daemon.notice openvpn(custom_config)[3914]: OpenVPN 2.4.7 mipsel-openwrt-linux-gnu [SSL (OpenSSL)] [LZO]                                                                               [LZ4] [EPOLL] [MH/PKTINFO] [AEAD]
Wed Jan 29 19:52:09 2020 daemon.notice openvpn(custom_config)[3914]: library versions: OpenSSL 1.1.1d  10 Sep 2019, LZO 2.10
Wed Jan 29 19:52:10 2020 daemon.err openvpn(custom_config)[3914]: neither stdin nor stderr are a tty device and you have neither                                                                               a controlling tty nor systemd - can't ask for 'Enter Private Key Password:'.  If you used --daemon, you need to use --askpass to                                                                               make passphrase-protected keys work, and you can not use --auth-nocache.
Wed Jan 29 19:52:10 2020 daemon.notice openvpn(custom_config)[3914]: Exiting due to fatal error
Wed Jan 29 19:52:15 2020 daemon.notice openvpn(custom_config)[3916]: OpenVPN 2.4.7 mipsel-openwrt-linux-gnu [SSL (OpenSSL)] [LZO]                                                                               [LZ4] [EPOLL] [MH/PKTINFO] [AEAD]
Wed Jan 29 19:52:15 2020 daemon.notice openvpn(custom_config)[3916]: library versions: OpenSSL 1.1.1d  10 Sep 2019, LZO 2.10
Wed Jan 29 19:52:15 2020 daemon.err openvpn(custom_config)[3916]: neither stdin nor stderr are a tty device and you have neither                                                                               a controlling tty nor systemd - can't ask for 'Enter Private Key Password:'.  If you used --daemon, you need to use --askpass to                                                                               make passphrase-protected keys work, and you can not use --auth-nocache.
Wed Jan 29 19:52:15 2020 daemon.notice openvpn(custom_config)[3916]: Exiting due to fatal error
Wed Jan 29 19:52:20 2020 daemon.notice openvpn(custom_config)[3917]: OpenVPN 2.4.7 mipsel-openwrt-linux-gnu [SSL (OpenSSL)] [LZO]                                                                               [LZ4] [EPOLL] [MH/PKTINFO] [AEAD]
Wed Jan 29 19:52:20 2020 daemon.notice openvpn(custom_config)[3917]: library versions: OpenSSL 1.1.1d  10 Sep 2019, LZO 2.10
Wed Jan 29 19:52:20 2020 daemon.err openvpn(custom_config)[3917]: neither stdin nor stderr are a tty device and you have neither                                                                               a controlling tty nor systemd - can't ask for 'Enter Private Key Password:'.  If you used --daemon, you need to use --askpass to                                                                               make passphrase-protected keys work, and you can not use --auth-nocache.
Wed Jan 29 19:52:20 2020 daemon.notice openvpn(custom_config)[3917]: Exiting due to fatal error
Wed Jan 29 19:52:25 2020 daemon.notice openvpn(custom_config)[3918]: OpenVPN 2.4.7 mipsel-openwrt-linux-gnu [SSL (OpenSSL)] [LZO]                                                                               [LZ4] [EPOLL] [MH/PKTINFO] [AEAD]
Wed Jan 29 19:52:25 2020 daemon.notice openvpn(custom_config)[3918]: library versions: OpenSSL 1.1.1d  10 Sep 2019, LZO 2.10
Wed Jan 29 19:52:25 2020 daemon.err openvpn(custom_config)[3918]: neither stdin nor stderr are a tty device and you have neither                                                                               a controlling tty nor systemd - can't ask for 'Enter Private Key Password:'.  If you used --daemon, you need to use --askpass to                                                                               make passphrase-protected keys work, and you can not use --auth-nocache.
Wed Jan 29 19:52:25 2020 daemon.notice openvpn(custom_config)[3918]: Exiting due to fatal error
Wed Jan 29 19:52:30 2020 daemon.notice openvpn(custom_config)[3919]: OpenVPN 2.4.7 mipsel-openwrt-linux-gnu [SSL (OpenSSL)] [LZO]                                                                               [LZ4] [EPOLL] [MH/PKTINFO] [AEAD]
Wed Jan 29 19:52:30 2020 daemon.notice openvpn(custom_config)[3919]: library versions: OpenSSL 1.1.1d  10 Sep 2019, LZO 2.10
Wed Jan 29 19:52:30 2020 daemon.err openvpn(custom_config)[3919]: neither stdin nor stderr are a tty device and you have neither                                                                               a controlling tty nor systemd - can't ask for 'Enter Private Key Password:'.  If you used --daemon, you need to use --askpass to                                                                               make passphrase-protected keys work, and you can not use --auth-nocache.
Wed Jan 29 19:52:30 2020 daemon.notice openvpn(custom_config)[3919]: Exiting due to fatal error
Wed Jan 29 19:52:35 2020 daemon.notice openvpn(custom_config)[3920]: OpenVPN 2.4.7 mipsel-openwrt-linux-gnu [SSL (OpenSSL)] [LZO]                                                                               [LZ4] [EPOLL] [MH/PKTINFO] [AEAD]
Wed Jan 29 19:52:35 2020 daemon.notice openvpn(custom_config)[3920]: library versions: OpenSSL 1.1.1d  10 Sep 2019, LZO 2.10
Wed Jan 29 19:52:35 2020 daemon.err openvpn(custom_config)[3920]: neither stdin nor stderr are a tty device and you have neither                                                                               a controlling tty nor systemd - can't ask for 'Enter Private Key Password:'.  If you used --daemon, you need to use --askpass to                                                                               make passphrase-protected keys work, and you can not use --auth-nocache.
Wed Jan 29 19:52:35 2020 daemon.notice openvpn(custom_config)[3920]: Exiting due to fatal error
Wed Jan 29 19:52:40 2020 daemon.notice openvpn(custom_config)[3921]: OpenVPN 2.4.7 mipsel-openwrt-linux-gnu [SSL (OpenSSL)] [LZO]                                                                               [LZ4] [EPOLL] [MH/PKTINFO] [AEAD]
Wed Jan 29 19:52:40 2020 daemon.notice openvpn(custom_config)[3921]: library versions: OpenSSL 1.1.1d  10 Sep 2019, LZO 2.10
Wed Jan 29 19:52:40 2020 daemon.err openvpn(custom_config)[3921]: neither stdin nor stderr are a tty device and you have neither                                                                               a controlling tty nor systemd - can't ask for 'Enter Private Key Password:'.  If you used --daemon, you need to use --askpass to                                                                               make passphrase-protected keys work, and you can not use --auth-nocache.
Wed Jan 29 19:52:40 2020 daemon.notice openvpn(custom_config)[3921]: Exiting due to fatal error
Wed Jan 29 19:52:45 2020 daemon.notice openvpn(custom_config)[3922]: OpenVPN 2.4.7 mipsel-openwrt-linux-gnu [SSL (OpenSSL)] [LZO]                                                                               [LZ4] [EPOLL] [MH/PKTINFO] [AEAD]
Wed Jan 29 19:52:45 2020 daemon.notice openvpn(custom_config)[3922]: library versions: OpenSSL 1.1.1d  10 Sep 2019, LZO 2.10
Wed Jan 29 19:52:45 2020 daemon.err openvpn(custom_config)[3922]: neither stdin nor stderr are a tty device and you have neither                                                                               a controlling tty nor systemd - can't ask for 'Enter Private Key Password:'.  If you used --daemon, you need to use --askpass to                                                                               make passphrase-protected keys work, and you can not use --auth-nocache.
Wed Jan 29 19:52:45 2020 daemon.notice openvpn(custom_config)[3922]: Exiting due to fatal error
Wed Jan 29 19:52:50 2020 daemon.notice openvpn(custom_config)[3923]: OpenVPN 2.4.7 mipsel-openwrt-linux-gnu [SSL (OpenSSL)] [LZO]                                                                               [LZ4] [EPOLL] [MH/PKTINFO] [AEAD]
Wed Jan 29 19:52:50 2020 daemon.notice openvpn(custom_config)[3923]: library versions: OpenSSL 1.1.1d  10 Sep 2019, LZO 2.10
Wed Jan 29 19:52:50 2020 daemon.err openvpn(custom_config)[3923]: neither stdin nor stderr are a tty device and you have neither                                                                               a controlling tty nor systemd - can't ask for 'Enter Private Key Password:'.  If you used --daemon, you need to use --askpass to                                                                               make passphrase-protected keys work, and you can not use --auth-nocache.
Wed Jan 29 19:52:50 2020 daemon.notice openvpn(custom_config)[3923]: Exiting due to fatal error
Wed Jan 29 19:52:55 2020 daemon.notice openvpn(custom_config)[3924]: OpenVPN 2.4.7 mipsel-openwrt-linux-gnu [SSL (OpenSSL)] [LZO]                                                                               [LZ4] [EPOLL] [MH/PKTINFO] [AEAD]
Wed Jan 29 19:52:55 2020 daemon.notice openvpn(custom_config)[3924]: library versions: OpenSSL 1.1.1d  10 Sep 2019, LZO 2.10
Wed Jan 29 19:52:55 2020 daemon.err openvpn(custom_config)[3924]: neither stdin nor stderr are a tty device and you have neither                                                                               a controlling tty nor systemd - can't ask for 'Enter Private Key Password:'.  If you used --daemon, you need to use --askpass to                                                                               make passphrase-protected keys work, and you can not use --auth-nocache.
Wed Jan 29 19:52:55 2020 daemon.notice openvpn(custom_config)[3924]: Exiting due to fatal error
Wed Jan 29 19:53:00 2020 daemon.notice openvpn(custom_config)[3925]: OpenVPN 2.4.7 mipsel-openwrt-linux-gnu [SSL (OpenSSL)] [LZO]                                                                               [LZ4] [EPOLL] [MH/PKTINFO] [AEAD]
Wed Jan 29 19:53:00 2020 daemon.notice openvpn(custom_config)[3925]: library versions: OpenSSL 1.1.1d  10 Sep 2019, LZO 2.10
Wed Jan 29 19:53:00 2020 daemon.err openvpn(custom_config)[3925]: neither stdin nor stderr are a tty device and you have neither                                                                               a controlling tty nor systemd - can't

158

Odp: Użycie komercyjnego klienta OpenVPN w OpenWrt.

Dlaczego sam nie czytasz tych logów?

Wed Jan 29 19:47:42 2020 daemon.err openvpn(custom_config)[3643]: neither stdin nor stderr are a tty device and you have neither                                                                               a controlling tty nor systemd - can't ask for 'Enter Private Key Password:'.  If you used --daemon, you need to use --askpass to                                                                               make passphrase-protected keys work, and you can not use --auth-nocache.
Wed Jan 29 19:47:42 2020 daemon.notice openvpn(custom_config)[3643]: Exiting due to fatal error

Wyraźnie napisał że masz gdzieś hasło ustawione w certyfikacie a na kliencie go nie ustawiłeś - a w konsoli sam się o hasło nie zapyta bo i jak.

Masz niepotrzebny router, uszkodzony czy nie - chętnie przygarnę go.

159 (edytowany przez behemoth 2020-04-06 22:04:44)

Odp: Użycie komercyjnego klienta OpenVPN w OpenWrt.

Panowie, wykonałem kroki dla OpenWRT w posiadanej przeze mnie wersji, natomiast ruch po restarcie routera nie idzie od razu przez tuner.
Mam na myśli kroki opisane tutaj:
4.1-a With Openwrt up to 18.06 and 19.07
czyli

Click on Network in the top bar and then on Interfaces to open the interfaces configuration page.
Click on button Add new Interface…
Fill the form with the following values: name = tun0, Protocole = Unmanaged, Interface = tun0. Then click on Create Interface.
Edit the interface.
In panel General Settings: unselect the checkbox Bring up on boot.
In panel Firewall Settings: Assign firewall-zone to wan.
Click on Save and Apply the new configuration.
Reboot the router.

Na czym mi zależy? Żeby cały ruch, zanim podniesie się tuner/wystartują usługi nie wychodził na świat otwartym łączem, czyli kill-switch.
Co trzeba poprawić w tym konfigu?

Nawet jak tunel się zestawi, to ruch potrafi iść przez "otwarty" internet:
https://scr.behemoth.be/2020/06/06-22-43-WA.png

No i na dokładkę plik ovpn:

client
verb 1
proto tcp
remote nl2-ovpn-udp.pointtoserver.com 80
connect-retry-max 3
connect-retry 3
resolv-retry 15
dev tun
auth-user-pass /etc/openvpn/PureVPN2.auth
persist-key
persist-tun
nobind
<ca>
-----BEGIN CERTIFICATE-----
MIIE6DCCA9CgAwIBAgIJAMjXFoeo5uSlMA0GCSqGSIb3DQEBCwUAMIGoMQswCQYD
VQQGEwJISzEQMA4GA1UECBMHQ2VudHJhbDELMAkGA1UEBxMCSEsxGDAWBgNVBAoT
D1NlY3VyZS1TZXJ2ZXJDQTELMAkGA1UECxMCSVQxGDAWBgNVBAMTD1NlY3VyZS1T
ZXJ2ZXJDQTEYMBYGA1UEKRMPU2VjdXJlLVNlcnZlckNBMR8wHQYJKoZIhvcNAQkB
FhBtYWlsQGhvc3QuZG9tYWluMB4XDTE2MDExNTE1MzQwOVoXDTI2MDExMjE1MzQw
OVowgagxCzAJBgNVBAYTAkhLMRAwDgYDVQQIEwdDZW50cmFsMQswCQYDVQQHEwJI
SzEYMBYGA1UEChMPU2VjdXJlLVNlcnZlckNBMQswCQYDVQQLEwJJVDEYMBYGA1UE
AxMPU2VjdXJlLVNlcnZlckNBMRgwFgYDVQQpEw9TZWN1cmUtU2VydmVyQ0ExHzAd
BgkqhkiG9w0BCQEWEG1haWxAaG9zdC5kb21haW4wggEiMA0GCSqGSIb3DQEBAQUA
A4IBDwAwggEKAoIBAQDluufhyLlyvXzPUL16kAWAdivl1roQv3QHbuRshyKacf/1
Er1JqEbtW3Mx9Fvr/u27qU2W8lQI6DaJhU2BfijPe/KHkib55mvHzIVvoexxya26
nk79F2c+d9PnuuMdThWQO3El5a/i2AASnM7T7piIBT2WRZW2i8RbfJaTT7G7LP7O
pMKIV1qyBg/cWoO7cIWQW4jmzqrNryIkF0AzStLN1DxvnQZwgXBGv0CwuAkfQuNS
Lu0PQgPp0PhdukNZFllv5D29IhPr0Z+kwPtrAgPQo+lHlOBHBMUpDT4XChTPeAvM
aUSBsqmonAE8UUHEabWrqYN/kWNHCNkYXMkiVmK1AgMBAAGjggERMIIBDTAdBgNV
HQ4EFgQU456ijsFrYnzHBShLAPpOUqQ+Z2cwgd0GA1UdIwSB1TCB0oAU456ijsFr
YnzHBShLAPpOUqQ+Z2ehga6kgaswgagxCzAJBgNVBAYTAkhLMRAwDgYDVQQIEwdD
ZW50cmFsMQswCQYDVQQHEwJISzEYMBYGA1UEChMPU2VjdXJlLVNlcnZlckNBMQsw
CQYDVQQLEwJJVDEYMBYGA1UEAxMPU2VjdXJlLVNlcnZlckNBMRgwFgYDVQQpEw9T
ZWN1cmUtU2VydmVyQ0ExHzAdBgkqhkiG9w0BCQEWEG1haWxAaG9zdC5kb21haW6C
CQDI1xaHqObkpTAMBgNVHRMEBTADAQH/MA0GCSqGSIb3DQEBCwUAA4IBAQCvga2H
MwOtUxWH/inL2qk24KX2pxLg939JNhqoyNrUpbDHag5xPQYXUmUpKrNJZ0z+o/Zn
NUPHydTSXE7Z7E45J0GDN5E7g4pakndKnDLSjp03NgGsCGW+cXnz6UBPM5FStFvG
dDeModeSUyoS9fjk+mYROvmiy5EiVDP91sKGcPLR7Ym0M7zl2aaqV7bb98HmMoBO
xpeZQinof67nKrCsgz/xjktWFgcmPl4/PQSsmqQD0fTtWxGuRX+FzwvF2OCMCAJg
p1RqJNlk2g50/kBIoJVPPCfjDFeDU5zGaWGSQ9+z1L6/z7VXdjUiHL0ouOcHwbiS
4ZjTr9nMn6WdAHU2
-----END CERTIFICATE-----
</ca>
<cert>
-----BEGIN CERTIFICATE-----
MIIEnzCCA4egAwIBAgIBAzANBgkqhkiG9w0BAQsFADCBqDELMAkGA1UEBhMCSEsx
EDAOBgNVBAgTB0NlbnRyYWwxCzAJBgNVBAcTAkhLMRgwFgYDVQQKEw9TZWN1cmUt
U2VydmVyQ0ExCzAJBgNVBAsTAklUMRgwFgYDVQQDEw9TZWN1cmUtU2VydmVyQ0Ex
GDAWBgNVBCkTD1NlY3VyZS1TZXJ2ZXJDQTEfMB0GCSqGSIb3DQEJARYQbWFpbEBo
b3N0LmRvbWFpbjAeFw0xNjAxMTUxNjE1MzhaFw0yNjAxMTIxNjE1MzhaMIGdMQsw
CQYDVQQGEwJISzEQMA4GA1UECBMHQ2VudHJhbDELMAkGA1UEBxMCSEsxFjAUBgNV
BAoTDVNlY3VyZS1DbGllbnQxCzAJBgNVBAsTAklUMRYwFAYDVQQDEw1TZWN1cmUt
Q2xpZW50MREwDwYDVQQpEwhjaGFuZ2VtZTEfMB0GCSqGSIb3DQEJARYQbWFpbEBo
b3N0LmRvbWFpbjCBnzANBgkqhkiG9w0BAQEFAAOBjQAwgYkCgYEAxsnyn4v6xxDP
nuDaYS0b9M1N8nxgg7OBPBlK+FWRxdTQ8yxt5U5CZGm7riVp7fya2J2iPZIgmHQE
v/KbxztsHAVlYSfYYlalrnhEL3bDP2tY+N43AwB1k5BrPq2s1pPLT2XG951drDKG
4PUuFHUP1sHzW5oQlfVCmxgIMAP8OYkCAwEAAaOCAV8wggFbMAkGA1UdEwQCMAAw
LQYJYIZIAYb4QgENBCAWHkVhc3ktUlNBIEdlbmVyYXRlZCBDZXJ0aWZpY2F0ZTAd
BgNVHQ4EFgQU9MwUnUDbQKKZKjoeieD2OD5NlAEwgd0GA1UdIwSB1TCB0oAU456i
jsFrYnzHBShLAPpOUqQ+Z2ehga6kgaswgagxCzAJBgNVBAYTAkhLMRAwDgYDVQQI
EwdDZW50cmFsMQswCQYDVQQHEwJISzEYMBYGA1UEChMPU2VjdXJlLVNlcnZlckNB
MQswCQYDVQQLEwJJVDEYMBYGA1UEAxMPU2VjdXJlLVNlcnZlckNBMRgwFgYDVQQp
Ew9TZWN1cmUtU2VydmVyQ0ExHzAdBgkqhkiG9w0BCQEWEG1haWxAaG9zdC5kb21h
aW6CCQDI1xaHqObkpTATBgNVHSUEDDAKBggrBgEFBQcDAjALBgNVHQ8EBAMCB4Aw
DQYJKoZIhvcNAQELBQADggEBAFyFo2VUX/UFixsdPdK9/Yt6mkCWc+XS1xbapGXX
b9U1d+h1iBCIV9odUHgNCXWpz1hR5Uu/OCzaZ0asLE4IFMZlQmJs8sMT0c1tfPPG
W45vxbL0lhqnQ8PNcBH7huNK7VFjUh4szXRKmaQPaM4S91R3L4CaNfVeHfAg7mN2
m9Zn5Gto1Q1/CFMGKu2hxwGEw5p+X1czBWEvg/O09ckx/ggkkI1NcZsNiYQ+6Pz8
DdGGX3+05YwLZu94+O6iIMrzxl/il0eK83g3YPbsOrASARvw6w/8sOnJCK5eOacl
21oww875KisnYdWjHB1FiI+VzQ1/gyoDsL5kPTJVuu2CoG8=
-----END CERTIFICATE-----
</cert>
<key>
-----BEGIN PRIVATE KEY-----
MIICdgIBADANBgkqhkiG9w0BAQEFAASCAmAwggJcAgEAAoGBAMbJ8p+L+scQz57g
2mEtG/TNTfJ8YIOzgTwZSvhVkcXU0PMsbeVOQmRpu64lae38mtidoj2SIJh0BL/y
m8c7bBwFZWEn2GJWpa54RC92wz9rWPjeNwMAdZOQaz6trNaTy09lxvedXawyhuD1
LhR1D9bB81uaEJX1QpsYCDAD/DmJAgMBAAECgYEAvTHbDupE5U0krUvHzBEIuHbl
ptGlcfNYHoDcD3oxYR3pOGeiuElBexv+mgHVzcFLBrsQfJUlHLPfCWi3xmjRvDQc
r7N7U1u7NIzazy/PpRBaKolMRiM1KMYi2DG0i4ZONwFT8bvNHOIrZzCLY54KDrqO
n55OzC70WYjWh4t5evkCQQDkkzZUAeskBC9+JP/zLps8jhwfoLBWGw/zbC9ePDmX
0N8MTZdcUpg6KUTf1wbkLUyVtIRjS2ao6qu1jWG6K0x3AkEA3qPWyaWQWCynhNDq
u2U1cPb2kh5AJip+gqxO3emikAdajsSxeoyEC2AfyBITbeB1tvCUZH17J4i/0+OF
TEQp/wJAb/zEOGJ8PzghwK8GC7JA8mk51DEZVAaMSRovFv9wxDXcoh191AjPdmdz
zCuAv9iF1i8MUc3GbWoUWK39PIYsPwJAWh63sqfx5b8tj/WBDpnJKBDPfhYAoXJS
A1L8GZeY1fQkE+ZKcPCwAmrGcpXeh3t0Krj3WDXyw+32uC5Apr5wwQJAPZwOORea
C4YNfBPZN9BdHvVjOYGGUffpI+X+hWpLRnQFJteAi+eqwyk0Oi0SkJB+a7jcerK2
d7q7xhec5WHlng==
-----END PRIVATE KEY-----
</key>
<tls-auth>
# 
# 2048 bit OpenVPN static key 
# 
-----BEGIN OpenVPN Static key V1-----
e30af995f56d07426d9ba1f824730521
d4283db4b4d0cdda9c6e8759a3799dcb
7939b6a5989160c9660de0f6125cbb1f
585b41c074b2fe88ecfcf17eab9a33be
1352379cdf74952b588fb161a93e13df
9135b2b29038231e02d657a6225705e6
868ccb0c384ed11614690a1894bfbeb2
74cebf1fe9c2329bdd5c8a40fe882062
4d2ea7540cd79ab76892db51fc371a3a
c5fc9573afecb3fffe3281e61d72e915
79d9b03d8cbf7909b3aebf4d90850321
ee6b7d0a7846d15c27d8290e031e951e
19438a4654663cad975e138f5bc5af89
c737ad822f27e19057731f41e1e254cc
9c95b7175c622422cde9f1f2cfd3510a
dd94498b4d7133d3729dd214a16b27fb
-----END OpenVPN Static key V1-----
</tls-auth>
key-direction 1
remote-cert-tls server
cipher AES-256-CBC
route-method exe 
route-delay 2 
route 0.0.0.0 0.0.0.0
script-security 2

160

Odp: Użycie komercyjnego klienta OpenVPN w OpenWrt.

To od serwera zależy nie od klienta.

Skasuj też to: route 0.0.0.0 0.0.0.0

Masz niepotrzebny router, uszkodzony czy nie - chętnie przygarnę go.

161

Odp: Użycie komercyjnego klienta OpenVPN w OpenWrt.

@Cezary, usunąłem linijkę route.
A takie rozwiązanie nie wchodzi w grę?
https://openwrt.org/docs/guide-user/ser … ill_switch

162

Odp: Użycie komercyjnego klienta OpenVPN w OpenWrt.

Ah, sorry, nie doczytałem. Wydawało mi się że napisałeś że ci cały ruch nie idzie przez vpn, a ty chcesz killswitcha. Moja wina.

Tak, możesz zrobić to tak jak jest na openwrt.org.

Masz niepotrzebny router, uszkodzony czy nie - chętnie przygarnę go.

163 (edytowany przez behemoth 2020-04-07 09:21:44)

Odp: Użycie komercyjnego klienta OpenVPN w OpenWrt.

Luzik smile
A to jeszcze chyba ostatnie pytanie - skrypt killswitch.sh, który jest tworzony na końcu - co z nim?
Bo jest tworzony, dostaje uprawnienia do wykonywania, ale nigdzie nie jest uruchamiany. Co z nim zrobić?

Niestety nie wszystkie rule firewallowe działają poprawnie, więc nie commitowałem zmian. Mógłbyś proszę zerknąć na to?

root@OpenWrt:~# uci -q delete firewall.vpn
root@OpenWrt:~# uci set firewall.vpn="zone"
root@OpenWrt:~# uci set firewall.vpn.name="vpn"
root@OpenWrt:~# uci set firewall.vpn.input="REJECT"
root@OpenWrt:~# uci set firewall.vpn.output="ACCEPT"
root@OpenWrt:~# uci set firewall.vpn.forward="REJECT"
root@OpenWrt:~# uci set firewall.vpn.masq="1"
root@OpenWrt:~# uci set firewall.vpn.mtu_fix="1"
root@OpenWrt:~# uci -q delete firewall.lan_vpn
root@OpenWrt:~# uci set firewall.lan_vpn="forwarding"
root@OpenWrt:~# uci set firewall.lan_vpn.src="lan"
root@OpenWrt:~# uci set firewall.lan_vpn.dest="vpn"
root@OpenWrt:~# uci del_list firewall.wan.device="tun0"
uci: Invalid argument
root@OpenWrt:~# uci add_list firewall.vpn.device="tun0"
root@OpenWrt:~# uci set firewall.lan_wan.enabled="0"
uci: Invalid argument

164

Odp: Użycie komercyjnego klienta OpenVPN w OpenWrt.

On po prostu wyłącza lub włącza openvpn. Możesz to podpiąć np. pod jakiś przycisk jak masz w routerze.

Prościej by było wyłączyć po prostu forwarding pomiędzy lan a wan na stałe. Wtedy jak padnie openvpn to żaden z klientów nie wyjdzie wanem.

Ty skopiowałeś tylko ostatnie reguły a patrz całościowo na poradnik. Bo tam wcześniej tworzą reguły o określonych nazwach które później używają a ty domyślnie takich nie masz.

Masz niepotrzebny router, uszkodzony czy nie - chętnie przygarnę go.

165 (edytowany przez behemoth 2020-04-07 09:29:55)

Odp: Użycie komercyjnego klienta OpenVPN w OpenWrt.

Zaktualizowałem chyba swój post jak pisałeś swoją odpowiedź o informacje dotyczące błędów podczas dodawania regułek na fw.
W tej chwili tak wyglądają u mnie zasady na firewallu (tamtych nie commitowałem przez błędy):
https://scr.behemoth.be/2020/07/07-10-27-La.png

Czy mógłbyś mnie proszę nieco naprowadzić?

Edit: faktycznie wcześniej są tworzone reguły. Chyba przerasta mnie przeanalizowanie ich na tyle, żeby ogarnąć samodzielnie temat.
A można jakoś łatwo ogarnąć wyłączenie routingu z LANu do WANu?

166

Odp: Użycie komercyjnego klienta OpenVPN w OpenWrt.

Tak, domyślnie masz w firewallu regułę formwardingu pomiędzy lan i wan. Po prostu ją wyłącz.

Masz niepotrzebny router, uszkodzony czy nie - chętnie przygarnę go.

167

Odp: Użycie komercyjnego klienta OpenVPN w OpenWrt.

Niestety po usunięciu tej reguły:
https://scr.behemoth.be/2020/07/07-10-49-lo.png
Odcięło mnie całkowicie, pomimo zapiętego tunelu vpn.

168

Odp: Użycie komercyjnego klienta OpenVPN w OpenWrt.

W firewallu powinieneś mieć za to regułę lan <> vpn. Jak masz to znaczy że ci tunel nie działa.

Masz niepotrzebny router, uszkodzony czy nie - chętnie przygarnę go.

169

Odp: Użycie komercyjnego klienta OpenVPN w OpenWrt.

Nie mam i nigdy tam takiej reguły nie było, a VPN działał smile
Czyli dodać regułę lan <> tun0?

170

Odp: Użycie komercyjnego klienta OpenVPN w OpenWrt.

lan vpn a nie a nie tun0. Przeczytaj pierwszy post tego wątku. Tak, tunel będzie działał bez tego, ale przeczytaj pierwszy post będziesz wiedział dlaczego.

Masz niepotrzebny router, uszkodzony czy nie - chętnie przygarnę go.

171

Odp: Użycie komercyjnego klienta OpenVPN w OpenWrt.

Dzięki.
Czyli instaluję OpenVPN, uruchamiam połączenie.
Następnie wykonuję kroki z instrukcji: https://openwrt.org/docs/guide-user/ser … lient-luci
4.1a lub 4.1b (obojętne?)

I następnie kroki z punktu 6 z pierwszej strony tego tematu?

172

Odp: Użycie komercyjnego klienta OpenVPN w OpenWrt.

Po co masz cokolwiek robić z instrukcji z openwrt? W pierwszym poście masz wszystko co jest potrzebne przecież

Masz niepotrzebny router, uszkodzony czy nie - chętnie przygarnę go.

173

Odp: Użycie komercyjnego klienta OpenVPN w OpenWrt.

Dzięki za cierpliwość smile
Zrobiłem faktycznie od podstaw z tutoriala z pierwszej strony i działa.
Rozumiem, że teraz w zakładce firewall, która obecnie wygląda tak:
https://scr.behemoth.be/2020/07/07-11-40-Ky.png
Mam wyedytować tę sekcję:
https://scr.behemoth.be/2020/07/07-11-42-sN.png
I w niej usunąć WAN:
https://scr.behemoth.be/2020/07/07-11-42-g9.png

Dobrze rozumiem?

174

Odp: Użycie komercyjnego klienta OpenVPN w OpenWrt.

Możesz skończyć z tymi screnshotami z luci? Krzywdę sobie kiedyś w ten sposób zrobisz.

Źle rozumiesz. Nie po to dodawałeś  forwarding vpn <> wan żeby go teraz usuwać. Masz usunąć forwarding lan <> wan. Spójrz do pliki /etc/config/firewall, tam jest tylko jeden wpis lan -> wan.

Masz niepotrzebny router, uszkodzony czy nie - chętnie przygarnę go.

175 (edytowany przez behemoth 2020-04-07 11:18:03)

Odp: Użycie komercyjnego klienta OpenVPN w OpenWrt.

Jasne, poprawiłem config z konsolki, zakomentowałem zgodnie z Twoją sugestią i śmiga!
Dzięki!
Edit: A czy requesty DNS też lecą przez tunel? Mam na myśli requesty samego routera.