openvpn serwer:
root@router:/tmp# cat openvpn.log
2021-09-20 21:33:21 --cipher is not set. Previous OpenVPN version defaulted to BF-CBC as fallback when cipher negotiation failed in this case. If you need this fallback please add '--data-ciphers-fallback BF-CBC' to your configuration and/or add BF-CBC to --data-ciphers.
2021-09-20 21:33:21 OpenVPN 2.5.3 arm-openwrt-linux-gnu [SSL (OpenSSL)] [LZO] [LZ4] [EPOLL] [MH/PKTINFO] [AEAD]
2021-09-20 21:33:21 library versions: OpenSSL 1.1.1l 24 Aug 2021, LZO 2.10
2021-09-20 21:33:22 WARNING: --keepalive option is missing from server config
2021-09-20 21:33:22 net_route_v4_best_gw query: dst 0.0.0.0
2021-09-20 21:33:22 net_route_v4_best_gw result: via x.x.x.x dev wan
2021-09-20 21:33:22 NOTE: the current --script-security setting may allow this configuration to call user-defined scripts
2021-09-20 21:33:22 Diffie-Hellman initialized with 2048 bit key
2021-09-20 21:33:22 TUN/TAP device tun0 opened
2021-09-20 21:33:22 net_iface_mtu_set: mtu 1500 for tun0
2021-09-20 21:33:22 net_iface_up: set tun0 up
2021-09-20 21:33:22 net_addr_v4_add: 10.8.0.1/24 dev tun0
2021-09-20 21:33:22 /usr/libexec/openvpn-hotplug up home tun0 1500 1621 10.8.0.1 255.255.255.0 init
2021-09-20 21:33:22 Could not determine IPv4/IPv6 protocol. Using AF_INET
2021-09-20 21:33:22 Socket Buffers: R=[180224->180224] S=[180224->180224]
2021-09-20 21:33:22 UDPv4 link local (bound): [AF_INET][undef]:1194
2021-09-20 21:33:22 UDPv4 link remote: [AF_UNSPEC]
2021-09-20 21:33:22 MULTI: multi_init called, r=256 v=256
2021-09-20 21:33:22 IFCONFIG POOL IPv4: base=10.8.0.2 size=252
2021-09-20 21:33:22 Initialization Sequence Completed
2021-09-20 21:36:39 192.168.1.239:1194 TLS: Initial packet from [AF_INET]192.168.1.239:1194, sid=d3d9fd3a 727d5733
2021-09-20 21:37:39 192.168.1.239:1194 TLS Error: TLS key negotiation failed to occur within 60 seconds (check your network connectivity)
2021-09-20 21:37:39 192.168.1.239:1194 TLS Error: TLS handshake failed
2021-09-20 21:37:39 192.168.1.239:1194 SIGUSR1[soft,tls-error] received, client-instance restarting
2021-09-20 21:38:18 37.47.28.48:20011 TLS: Initial packet from [AF_INET]37.47.28.48:20011, sid=9142178d 6193d5b2
2021-09-20 21:38:18 37.47.28.48:20011 VERIFY OK: depth=1, CN=IT Zone CA
2021-09-20 21:38:18 37.47.28.48:20011 VERIFY OK: depth=0, CN=client
2021-09-20 21:38:18 37.47.28.48:20011 peer info: IV_VER=2.4.4
2021-09-20 21:38:18 37.47.28.48:20011 peer info: IV_PLAT=win
2021-09-20 21:38:18 37.47.28.48:20011 peer info: IV_PROTO=2
2021-09-20 21:38:18 37.47.28.48:20011 peer info: IV_NCP=2
2021-09-20 21:38:18 37.47.28.48:20011 peer info: IV_LZ4=1
2021-09-20 21:38:18 37.47.28.48:20011 peer info: IV_LZ4v2=1
2021-09-20 21:38:18 37.47.28.48:20011 peer info: IV_LZO=1
2021-09-20 21:38:18 37.47.28.48:20011 peer info: IV_COMP_STUB=1
2021-09-20 21:38:18 37.47.28.48:20011 peer info: IV_COMP_STUBv2=1
2021-09-20 21:38:18 37.47.28.48:20011 peer info: IV_TCPNL=1
2021-09-20 21:38:18 37.47.28.48:20011 peer info: IV_GUI_VER=OpenVPN_GUI_11
2021-09-20 21:38:18 37.47.28.48:20011 Control Channel: TLSv1.2, cipher TLSv1.2 ECDHE-RSA-AES256-GCM-SHA384, peer certificate: 2048 bit RSA, signature: RSA-SHA256
2021-09-20 21:38:18 37.47.28.48:20011 [client] Peer Connection Initiated with [AF_INET]37.47.28.48:20011
2021-09-20 21:38:18 client/37.47.28.48:20011 MULTI_sva: pool returned IPv4=10.8.0.2, IPv6=(Not enabled)
2021-09-20 21:38:18 client/37.47.28.48:20011 MULTI: Learn: 10.8.0.2 -> client/37.47.28.48:20011
2021-09-20 21:38:18 client/37.47.28.48:20011 MULTI: primary virtual IP for client/37.47.28.48:20011: 10.8.0.2
2021-09-20 21:38:18 client/37.47.28.48:20011 Data Channel: using negotiated cipher 'AES-256-GCM'
2021-09-20 21:38:18 client/37.47.28.48:20011 Outgoing Data Channel: Cipher 'AES-256-GCM' initialized with 256 bit key
2021-09-20 21:38:18 client/37.47.28.48:20011 Incoming Data Channel: Cipher 'AES-256-GCM' initialized with 256 bit key
2021-09-20 21:38:20 client/37.47.28.48:20011 PUSH: Received control message: 'PUSH_REQUEST'
2021-09-20 21:38:20 client/37.47.28.48:20011 SENT CONTROL [client]: 'PUSH_REPLY,route 192.168.1.0 255.255.255.0,route-gateway 10.8.0.1,topology subnet,ifconfig 10.8.0.2 255.255.255.0,peer-id 0,cipher AES-256-GCM' (status=1)
openvpn windows client:
Mon Sep 20 21:38:16 2021 OpenVPN 2.4.4 x86_64-w64-mingw32 [SSL (OpenSSL)] [LZO] [LZ4] [PKCS11] [AEAD] built on Sep 26 2017
Mon Sep 20 21:38:16 2021 Windows version 6.2 (Windows 8 or greater) 64bit
Mon Sep 20 21:38:16 2021 library versions: OpenSSL 1.0.2l 25 May 2017, LZO 2.10
Enter Management Password:
Mon Sep 20 21:38:16 2021 MANAGEMENT: TCP Socket listening on [AF_INET]127.0.0.1:25340
Mon Sep 20 21:38:16 2021 Need hold release from management interface, waiting...
Mon Sep 20 21:38:17 2021 MANAGEMENT: Client connected from [AF_INET]127.0.0.1:25340
Mon Sep 20 21:38:17 2021 MANAGEMENT: CMD 'state on'
Mon Sep 20 21:38:17 2021 MANAGEMENT: CMD 'log all on'
Mon Sep 20 21:38:17 2021 MANAGEMENT: CMD 'echo all on'
Mon Sep 20 21:38:17 2021 MANAGEMENT: CMD 'hold off'
Mon Sep 20 21:38:17 2021 MANAGEMENT: CMD 'hold release'
Mon Sep 20 21:38:17 2021 TCP/UDP: Preserving recently used remote address: [AF_INET]46.31.39.119:1194
Mon Sep 20 21:38:17 2021 Socket Buffers: R=[65536->65536] S=[65536->65536]
Mon Sep 20 21:38:17 2021 UDP link local (bound): [AF_INET][undef]:1194
Mon Sep 20 21:38:17 2021 UDP link remote: [AF_INET]46.31.39.119:1194
Mon Sep 20 21:38:17 2021 MANAGEMENT: >STATE:1632166697,WAIT,,,,,,
Mon Sep 20 21:38:17 2021 MANAGEMENT: >STATE:1632166697,AUTH,,,,,,
Mon Sep 20 21:38:17 2021 TLS: Initial packet from [AF_INET]46.31.39.119:1194, sid=56d7e95f 27f14fc8
Mon Sep 20 21:38:17 2021 VERIFY OK: depth=1, CN=IT Zone CA
Mon Sep 20 21:38:17 2021 VERIFY KU OK
Mon Sep 20 21:38:17 2021 Validating certificate extended key usage
Mon Sep 20 21:38:17 2021 ++ Certificate has EKU (str) TLS Web Server Authentication, expects TLS Web Server Authentication
Mon Sep 20 21:38:17 2021 VERIFY EKU OK
Mon Sep 20 21:38:17 2021 VERIFY OK: depth=0, CN=serwer
Mon Sep 20 21:38:17 2021 WARNING: 'cipher' is present in local config but missing in remote config, local='cipher BF-CBC'
Mon Sep 20 21:38:17 2021 Control Channel: TLSv1.2, cipher TLSv1/SSLv3 ECDHE-RSA-AES256-GCM-SHA384, 2048 bit RSA
Mon Sep 20 21:38:17 2021 [serwer] Peer Connection Initiated with [AF_INET]x.x.x.x:1194
Mon Sep 20 21:38:18 2021 MANAGEMENT: >STATE:1632166698,GET_CONFIG,,,,,,
Mon Sep 20 21:38:18 2021 SENT CONTROL [serwer]: 'PUSH_REQUEST' (status=1)
Mon Sep 20 21:38:18 2021 PUSH: Received control message: 'PUSH_REPLY,route 192.168.1.0 255.255.255.0,route-gateway 10.8.0.1,topology subnet,ifconfig 10.8.0.2 255.255.255.0,peer-id 0,cipher AES-256-GCM'
Mon Sep 20 21:38:18 2021 OPTIONS IMPORT: --ifconfig/up options modified
Mon Sep 20 21:38:18 2021 OPTIONS IMPORT: route options modified
Mon Sep 20 21:38:18 2021 OPTIONS IMPORT: route-related options modified
Mon Sep 20 21:38:18 2021 OPTIONS IMPORT: peer-id set
Mon Sep 20 21:38:18 2021 OPTIONS IMPORT: adjusting link_mtu to 1624
Mon Sep 20 21:38:18 2021 OPTIONS IMPORT: data channel crypto options modified
Mon Sep 20 21:38:18 2021 Data Channel: using negotiated cipher 'AES-256-GCM'
Mon Sep 20 21:38:18 2021 Outgoing Data Channel: Cipher 'AES-256-GCM' initialized with 256 bit key
Mon Sep 20 21:38:18 2021 Incoming Data Channel: Cipher 'AES-256-GCM' initialized with 256 bit key
Mon Sep 20 21:38:18 2021 interactive service msg_channel=564
Mon Sep 20 21:38:18 2021 ROUTE_GATEWAY 192.168.161.41/255.255.255.0 I=4 HWADDR=f8:59:71:7b:f2:6e
Mon Sep 20 21:38:18 2021 open_tun
Mon Sep 20 21:38:18 2021 TAP-WIN32 device [Ethernet 3] opened: \\.\Global\....tap
Mon Sep 20 21:38:18 2021 TAP-Windows Driver Version 9.21
Mon Sep 20 21:38:18 2021 Set TAP-Windows TUN subnet mode network/local/netmask = 10.8.0.0/10.8.0.2/255.255.255.0 [SUCCEEDED]
Mon Sep 20 21:38:18 2021 Notified TAP-Windows driver to set a DHCP IP/netmask of 10.8.0.2/255.255.255.0 on interface ... [DHCP-serv: 10.8.0.254, lease-time: 31536000]
Mon Sep 20 21:38:18 2021 Successful ARP Flush on interface [23] ...
Mon Sep 20 21:38:18 2021 do_ifconfig, tt->did_ifconfig_ipv6_setup=0
Mon Sep 20 21:38:18 2021 MANAGEMENT: >STATE:1632166698,ASSIGN_IP,,10.8.0.2,,,,
Mon Sep 20 21:38:23 2021 TEST ROUTES: 1/1 succeeded len=1 ret=1 a=0 u/d=up
Mon Sep 20 21:38:23 2021 MANAGEMENT: >STATE:1632166703,ADD_ROUTES,,,,,,
Mon Sep 20 21:38:23 2021 C:\WINDOWS\system32\route.exe ADD 192.168.1.0 MASK 255.255.255.0 10.8.0.1
Mon Sep 20 21:38:23 2021 Route addition via service succeeded
Mon Sep 20 21:38:23 2021 WARNING: this configuration may cache passwords in memory -- use the auth-nocache option to prevent this
Mon Sep 20 21:38:23 2021 Initialization Sequence Completed
Mon Sep 20 21:38:23 2021 MANAGEMENT: >STATE:1632166703,CONNECTED,SUCCESS,10.8.0.2,46.31.39.119,1194,,
ROUTE na windowsie:
route PRINT
...
IPv4 Route Table
===========================================================================
Active Routes:
Network Destination Netmask Gateway Interface Metric
0.0.0.0 0.0.0.0 192.168.161.41 192.168.161.157 35
10.8.0.0 255.255.255.0 On-link 10.8.0.2 291
10.8.0.2 255.255.255.255 On-link 10.8.0.2 291
10.8.0.255 255.255.255.255 On-link 10.8.0.2 291
127.0.0.0 255.0.0.0 On-link 127.0.0.1 331
127.0.0.1 255.255.255.255 On-link 127.0.0.1 331
127.255.255.255 255.255.255.255 On-link 127.0.0.1 331
192.168.1.0 255.255.255.0 10.8.0.1 10.8.0.2 291
192.168.161.0 255.255.255.0 On-link 192.168.161.157 291
192.168.161.157 255.255.255.255 On-link 192.168.161.157 291
192.168.161.255 255.255.255.255 On-link 192.168.161.157 291
224.0.0.0 240.0.0.0 On-link 127.0.0.1 331
224.0.0.0 240.0.0.0 On-link 10.8.0.2 291
224.0.0.0 240.0.0.0 On-link 192.168.161.157 291
255.255.255.255 255.255.255.255 On-link 127.0.0.1 331
255.255.255.255 255.255.255.255 On-link 10.8.0.2 291
255.255.255.255 255.255.255.255 On-link 192.168.161.157 291
===========================================================================
Persistent Routes:
Network Address Netmask Gateway Address Metric
0.0.0.0 0.0.0.0 192.168.1.1 Default
===========================================================================