Hi' i sent fully logs :
בתאריך יום א׳, 17 בנוב׳ 2024 ב-3:03 מאת Johan Draaisma < jo...@openvpn.com>: > Hello Natanel/Netanel, > > We still don't see the issue, exponential backoff is how this type of > situation is handled in other common protocols too, it is a not a security > vulnerability. And just in case someone messes with the client side and > tries endlessly reconnecting much faster in an attempt to stress the > server, we also have other defenses in place. > > You also appear to be confusing server-side behavior with client-side > behavior. What you are writing is that when the client is having a problem > with the TLS handshake, that the server automatically restarts, as in, the > process stops and is restarted. That is simply not true. If it were true it > would mean failed TLS handshakes from one client would affect all other > connected clients too, and that's something we don't see happening. But if > you have proof that says otherwise, show it to us with verbatim log lines, > and a way to reproduce it that includes version of client and server > software used (and please, supported versions only, not versions from 8 > years ago), client and server configurations, and the steps to reach this > supposedly problematic state. My guess however is that you are > misinterpreting the message that the client is going to do a restart of the > connection, which would likely be visible in the server logs, and would be > expected and normal. > > Yes, there is theoretical potential to exhaust server resources from > repeatedly hammering the server with failing connections, as is the case > with many network programs. But we have various defenses in place for that. > Currently with the description given I don't believe you have found > something that broke through those defenses. But I could be wrong. But if > so, I want to see proof, not just a story. You write that the server is > automatically restarting in response to multiple failed TLS handshakes. > Show us the evidence please. > > Until then, we don't have anything to go on, sorry. > > Kind regards, > Johan Draaisma > On 16-11-2024 17:22, נתי שטרן wrote: > > Hi, > it's same on 2.6 version: > > Subject: Possible DoS Vulnerability - OpenVPN Server Showing Repeated TLS > Handshake Failures > > Dear OpenVPN Security Team, > > I am writing to report a potential vulnerability to Denial-of-Service > (DoS) attacks that I have observed in an OpenVPN server's logs. The server > is exhibiting consistent TLS handshake failures, resulting in repeated > process restarts. While the exact cause isn't immediately apparent, the > symptoms strongly suggest a vulnerability to an attack vector that > overwhelms the server with unsuccessful connection attempts. > > The logs demonstrate repeated errors of the form: "TLS key negotiation > failed to occur within 5 seconds (check your network connectivity)" and > "TLS handshake failed," followed by automatic server restarts. The server > appears to be attempting to mitigate by increasing the restart delay with > each failure, but this is only a temporary workaround, and the underlying > issue persists. > > The observed behavior is highly suggestive of a DoS attack, where an > attacker is attempting to exhaust server resources by triggering multiple > failed TLS handshakes. This, along with the server automatically restarting > in response, suggests a DoS mitigation procedure is in place that can only > temporarily avoid service outages. > > While I do not have direct access to the server configuration or the full > scope of logs, I believe the behavior described poses a significant > security risk. I have attached the partial log file demonstrating the > repeated errors. > > I would greatly appreciate it if you could investigate this potential > vulnerability and provide any guidance or recommendations for strengthening > the server's resilience against this type of attack. If further information > is needed, please do not hesitate to ask. > > Sincerely, > > Netanel > > > > בתאריך יום ו׳, 15 בנוב׳ 2024 ב-17:30 מאת Arne Schwabe < > a...@rfc2549.org>: > >> Am 15.11.24 um 13:56 schrieb נתי שטרן: >> > I pentested openvpn 2.4 on client and I need to write cve on TLS Key >> > Negotiation Timeout Leading to DoS on 2.4 version >> >> >> You are free to publish your finding but they do not qualify for a CVE >> for two reasons >> >> - currently only proven that an EOL version affected >> - the reported behaviour is expected behaviour and we do not see any >> security problems/implication in that behaviour, so no security problem, >> no CVE. >> > > > -- > <https://netanel.ml> > > -- <https://netanel.ml>
Sun Nov 17 05:48:00 2024 us=229500 Current Parameter Settings: Sun Nov 17 05:48:00 2024 us=229547 config = '/root/openvpn-ca/1.ovpn' Sun Nov 17 05:48:00 2024 us=229553 mode = 0 Sun Nov 17 05:48:00 2024 us=229558 persist_config = DISABLED Sun Nov 17 05:48:00 2024 us=229563 persist_mode = 1 Sun Nov 17 05:48:00 2024 us=229567 show_ciphers = DISABLED Sun Nov 17 05:48:00 2024 us=229571 show_digests = DISABLED Sun Nov 17 05:48:00 2024 us=229575 show_engines = DISABLED Sun Nov 17 05:48:00 2024 us=229579 genkey = DISABLED Sun Nov 17 05:48:00 2024 us=229584 key_pass_file = '[UNDEF]' Sun Nov 17 05:48:00 2024 us=229588 show_tls_ciphers = DISABLED Sun Nov 17 05:48:00 2024 us=229592 connect_retry_max = 0 Sun Nov 17 05:48:00 2024 us=229596 Connection profiles [0]: Sun Nov 17 05:48:00 2024 us=229601 proto = udp Sun Nov 17 05:48:00 2024 us=229605 local = '[UNDEF]' Sun Nov 17 05:48:00 2024 us=229610 local_port = '[UNDEF]' Sun Nov 17 05:48:00 2024 us=229614 remote = '103.6.170.21' Sun Nov 17 05:48:00 2024 us=229618 remote_port = '1194' Sun Nov 17 05:48:00 2024 us=229622 remote_float = DISABLED Sun Nov 17 05:48:00 2024 us=229626 bind_defined = DISABLED Sun Nov 17 05:48:00 2024 us=229631 NOTE: --mute triggered... Sun Nov 17 05:48:00 2024 us=229643 262 variation(s) on previous 20 message(s) suppressed by --mute Sun Nov 17 05:48:00 2024 us=229649 OpenVPN 2.4.12 x86_64-pc-linux-gnu [SSL (OpenSSL)] [LZO] [LZ4] [EPOLL] [PKCS11] [MH/PKTINFO] [AEAD] built on Jun 27 2024 Sun Nov 17 05:48:00 2024 us=229665 library versions: OpenSSL 1.1.1f 31 Mar 2020, LZO 2.10 Sun Nov 17 05:48:00 2024 us=229749 PO_INIT maxevents=4 flags=0x00000002 Sun Nov 17 05:48:00 2024 us=231298 PRNG init md=SHA1 size=36 Sun Nov 17 05:48:00 2024 us=231454 Outgoing Control Channel Authentication: Using 256 bit message hash 'SHA256' for HMAC authentication Sun Nov 17 05:48:00 2024 us=231468 Outgoing Control Channel Authentication: HMAC KEY: b4fffbf6 cec0f6d6 ca1aada2 a9671581 9eb0ea9e b4c29e13 77555ba2 0a47795d Sun Nov 17 05:48:00 2024 us=231473 Outgoing Control Channel Authentication: HMAC size=32 block_size=32 Sun Nov 17 05:48:00 2024 us=231479 Incoming Control Channel Authentication: Using 256 bit message hash 'SHA256' for HMAC authentication Sun Nov 17 05:48:00 2024 us=231486 Incoming Control Channel Authentication: HMAC KEY: 69b84f8a f6d85f67 b42957fb c16b35b0 759b3488 5000985c f877d830 5d1aff2c Sun Nov 17 05:48:00 2024 us=231490 Incoming Control Channel Authentication: HMAC size=32 block_size=32 Sun Nov 17 05:48:00 2024 us=231495 crypto_adjust_frame_parameters: Adjusting frame parameters for crypto by 40 bytes Sun Nov 17 05:48:00 2024 us=231505 LZO compression initializing Sun Nov 17 05:48:00 2024 us=231526 WARNING: normally if you use --mssfix and/or --fragment, you should also set --tun-mtu 1500 (currently it is 1450) Sun Nov 17 05:48:00 2024 us=231537 PID packet_id_init seq_backtrack=64 time_backtrack=15 Sun Nov 17 05:48:00 2024 us=231571 PID packet_id_init seq_backtrack=64 time_backtrack=15 Sun Nov 17 05:48:00 2024 us=231580 PID packet_id_init seq_backtrack=64 time_backtrack=15 Sun Nov 17 05:48:00 2024 us=231611 PID packet_id_init seq_backtrack=64 time_backtrack=15 Sun Nov 17 05:48:00 2024 us=231628 Control Channel MTU parms [ L:1572 D:1172 EF:78 EB:0 ET:0 EL:3 ] Sun Nov 17 05:48:00 2024 us=231649 MTU DYNAMIC mtu=1450, flags=2, 1572 -> 1450 Sun Nov 17 05:48:00 2024 us=231674 RESOLVE_REMOTE flags=0x0901 phase=1 rrs=0 sig=-1 status=0 Sun Nov 17 05:48:00 2024 us=231684 Data Channel MTU parms [ L:1572 D:1450 EF:122 EB:398 ET:0 EL:3 ] Sun Nov 17 05:48:00 2024 us=231697 crypto_adjust_frame_parameters: Adjusting frame parameters for crypto by 68 bytes Sun Nov 17 05:48:00 2024 us=231705 calc_options_string_link_mtu: link-mtu 1572 -> 1520 Sun Nov 17 05:48:00 2024 us=231716 crypto_adjust_frame_parameters: Adjusting frame parameters for crypto by 68 bytes Sun Nov 17 05:48:00 2024 us=231723 calc_options_string_link_mtu: link-mtu 1572 -> 1520 Sun Nov 17 05:48:00 2024 us=231729 Local Options String (VER=V4): 'V4,dev-type [unknown-dev-type],link-mtu 1520,tun-mtu 1450,proto UDPv4,comp-lzo,keydir 1,cipher AES-256-CBC,auth SHA256,keysize 256,tls-auth,key-method 2,tls-client' Sun Nov 17 05:48:00 2024 us=231734 Expected Remote Options String (VER=V4): 'V4,dev-type [unknown-dev-type],link-mtu 1520,tun-mtu 1450,proto UDPv4,comp-lzo,keydir 0,cipher AES-256-CBC,auth SHA256,keysize 256,tls-auth,key-method 2,tls-server' Sun Nov 17 05:48:00 2024 us=231742 TCP/UDP: Preserving recently used remote address: [AF_INET]103.6.170.21:1194 Sun Nov 17 05:48:00 2024 us=231768 Socket Buffers: R=[212992->212992] S=[212992->212992] Sun Nov 17 05:48:00 2024 us=231781 UDP link local: (not bound) Sun Nov 17 05:48:00 2024 us=231786 UDP link remote: [AF_INET]103.6.170.21:1194 Sun Nov 17 05:48:00 2024 us=231804 TLS Warning: no data channel send key available: [key#0 state=S_INITIAL id=0 sid=00000000 00000000] [key#1 state=S_UNDEF id=0 sid=00000000 00000000] [key#2 state=S_UNDEF id=0 sid=00000000 00000000] Sun Nov 17 05:48:00 2024 us=231812 SENT PING Sun Nov 17 05:48:00 2024 us=231817 TIMER: coarse timer wakeup 1 seconds Sun Nov 17 05:48:00 2024 us=231822 ACK mark active outgoing ID 0 Sun Nov 17 05:48:00 2024 us=231827 ACK reliable_can_send active=1 current=1 : [1] 0 Sun Nov 17 05:48:00 2024 us=231835 ACK reliable_send ID 0 (size=4 to=2) Sun Nov 17 05:48:00 2024 us=231842 ACK reliable_send_timeout 2 [1] 0 Sun Nov 17 05:48:00 2024 us=231852 RANDOM USEC=217485 Sun Nov 17 05:48:00 2024 us=231859 PO_CTL rwflags=0x0003 ev=3 arg=0x556f345c0198 Sun Nov 17 05:48:00 2024 us=231868 I/O WAIT T?|T?|SR|SW [1/217485] Sun Nov 17 05:48:00 2024 us=231875 PO_WAIT[0,0] fd=3 rev=0x00000004 rwflags=0x0002 arg=0x556f345c0198 Sun Nov 17 05:48:00 2024 us=231880 I/O WAIT status=0x0002 Sun Nov 17 05:48:00 2024 us=231887 UDP WRITE [54] to [AF_INET]103.6.170.21:1194: P_CONTROL_HARD_RESET_CLIENT_V2 kid=0 pid=[ #1 ] [ ] pid=0 DATA len=0 Sun Nov 17 05:48:00 2024 us=231930 ACK reliable_can_send active=1 current=0 : [1] 0 Sun Nov 17 05:48:00 2024 us=231971 SSL state (connect): before SSL initialization Sun Nov 17 05:48:00 2024 us=232089 SSL state (connect): SSLv3/TLS write client hello Sun Nov 17 05:48:00 2024 us=232101 ACK reliable_send_timeout 2 [1] 0 Sun Nov 17 05:48:00 2024 us=232107 PO_CTL rwflags=0x0001 ev=3 arg=0x556f345c0198 Sun Nov 17 05:48:00 2024 us=232113 I/O WAIT T?|T?|SR|Sw [1/217485] Sun Nov 17 05:48:01 2024 us=450377 I/O WAIT status=0x0020 Sun Nov 17 05:48:01 2024 us=450411 TIMER: coarse timer wakeup 1 seconds Sun Nov 17 05:48:01 2024 us=450422 ACK reliable_can_send active=1 current=0 : [1] 0 Sun Nov 17 05:48:01 2024 us=450437 ACK reliable_send_timeout 1 [1] 0 Sun Nov 17 05:48:01 2024 us=450444 PO_CTL rwflags=0x0001 ev=3 arg=0x556f345c0198 Sun Nov 17 05:48:01 2024 us=450452 I/O WAIT T?|T?|SR|Sw [1/217485] Sun Nov 17 05:48:02 2024 us=668725 I/O WAIT status=0x0020 Sun Nov 17 05:48:02 2024 us=668765 TIMER: coarse timer wakeup 1 seconds Sun Nov 17 05:48:02 2024 us=668777 ACK reliable_can_send active=1 current=1 : [1] 0 Sun Nov 17 05:48:02 2024 us=668782 ACK reliable_send ID 0 (size=4 to=4) Sun Nov 17 05:48:02 2024 us=668794 ACK reliable_send_timeout 4 [1] 0 Sun Nov 17 05:48:02 2024 us=668800 PO_CTL rwflags=0x0003 ev=3 arg=0x556f345c0198 Sun Nov 17 05:48:02 2024 us=668807 I/O WAIT T?|T?|SR|SW [1/217485] Sun Nov 17 05:48:02 2024 us=668814 PO_WAIT[0,0] fd=3 rev=0x00000004 rwflags=0x0002 arg=0x556f345c0198 Sun Nov 17 05:48:02 2024 us=668819 NOTE: --mute triggered... Sun Nov 17 05:48:02 2024 us=668824 1 variation(s) on previous 20 message(s) suppressed by --mute Sun Nov 17 05:48:02 2024 us=668834 UDP WRITE [54] to [AF_INET]103.6.170.21:1194: P_CONTROL_HARD_RESET_CLIENT_V2 kid=0 pid=[ #2 ] [ ] pid=0 DATA len=0 Sun Nov 17 05:48:02 2024 us=668891 ACK reliable_can_send active=1 current=0 : [1] 0 Sun Nov 17 05:48:02 2024 us=668906 ACK reliable_send_timeout 4 [1] 0 Sun Nov 17 05:48:02 2024 us=668911 PO_CTL rwflags=0x0001 ev=3 arg=0x556f345c0198 Sun Nov 17 05:48:02 2024 us=668916 I/O WAIT T?|T?|SR|Sw [1/217485] Sun Nov 17 05:48:03 2024 us=887179 I/O WAIT status=0x0020 Sun Nov 17 05:48:03 2024 us=887224 TIMER: coarse timer wakeup 1 seconds Sun Nov 17 05:48:03 2024 us=887237 ACK reliable_can_send active=1 current=0 : [1] 0 Sun Nov 17 05:48:03 2024 us=887256 ACK reliable_send_timeout 3 [1] 0 Sun Nov 17 05:48:03 2024 us=887265 PO_CTL rwflags=0x0001 ev=3 arg=0x556f345c0198 Sun Nov 17 05:48:03 2024 us=887274 I/O WAIT T?|T?|SR|Sw [1/217485] Sun Nov 17 05:48:05 2024 us=105547 I/O WAIT status=0x0020 Sun Nov 17 05:48:05 2024 us=105583 TIMER: coarse timer wakeup 1 seconds Sun Nov 17 05:48:05 2024 us=105593 TLS Error: TLS key negotiation failed to occur within 5 seconds (check your network connectivity) Sun Nov 17 05:48:05 2024 us=105598 TLS Error: TLS handshake failed Sun Nov 17 05:48:05 2024 us=105603 PID packet_id_free Sun Nov 17 05:48:05 2024 us=105642 PID packet_id_free Sun Nov 17 05:48:05 2024 us=105653 PID packet_id_free Sun Nov 17 05:48:05 2024 us=105664 PID packet_id_init seq_backtrack=64 time_backtrack=15 Sun Nov 17 05:48:05 2024 us=105704 PID packet_id_init seq_backtrack=64 time_backtrack=15 Sun Nov 17 05:48:05 2024 us=105741 PID packet_id_free Sun Nov 17 05:48:05 2024 us=105757 PID packet_id_free Sun Nov 17 05:48:05 2024 us=105762 PID packet_id_free Sun Nov 17 05:48:05 2024 us=105766 PID packet_id_free Sun Nov 17 05:48:05 2024 us=105775 PID packet_id_free Sun Nov 17 05:48:05 2024 us=105783 PID packet_id_free Sun Nov 17 05:48:05 2024 us=105787 PID packet_id_free Sun Nov 17 05:48:05 2024 us=105792 PID packet_id_free Sun Nov 17 05:48:05 2024 us=105797 TCP/UDP: Closing socket Sun Nov 17 05:48:05 2024 us=105812 PID packet_id_free Sun Nov 17 05:48:05 2024 us=105819 SIGUSR1[soft,tls-error] received, process restarting Sun Nov 17 05:48:05 2024 us=105835 Restart pause, 5 second(s) Sun Nov 17 05:48:10 2024 us=105936 PO_INIT maxevents=4 flags=0x00000002 Sun Nov 17 05:48:10 2024 us=105971 Re-using SSL/TLS context Sun Nov 17 05:48:10 2024 us=105979 crypto_adjust_frame_parameters: Adjusting frame parameters for crypto by 40 bytes Sun Nov 17 05:48:10 2024 us=105988 LZO compression initializing Sun Nov 17 05:48:10 2024 us=106023 WARNING: normally if you use --mssfix and/or --fragment, you should also set --tun-mtu 1500 (currently it is 1450) Sun Nov 17 05:48:10 2024 us=106046 PID packet_id_init seq_backtrack=64 time_backtrack=15 Sun Nov 17 05:48:10 2024 us=106085 PID packet_id_init seq_backtrack=64 time_backtrack=15 Sun Nov 17 05:48:10 2024 us=106095 PID packet_id_init seq_backtrack=64 time_backtrack=15 Sun Nov 17 05:48:10 2024 us=106108 PID packet_id_init seq_backtrack=64 time_backtrack=15 Sun Nov 17 05:48:10 2024 us=106115 Control Channel MTU parms [ L:1572 D:1172 EF:78 EB:0 ET:0 EL:3 ] Sun Nov 17 05:48:10 2024 us=106123 MTU DYNAMIC mtu=1450, flags=2, 1572 -> 1450 Sun Nov 17 05:48:10 2024 us=106162 RESOLVE_REMOTE flags=0x0901 phase=1 rrs=0 sig=-1 status=0 Sun Nov 17 05:48:10 2024 us=106192 Data Channel MTU parms [ L:1572 D:1450 EF:122 EB:398 ET:0 EL:3 ] Sun Nov 17 05:48:10 2024 us=106214 crypto_adjust_frame_parameters: Adjusting frame parameters for crypto by 68 bytes Sun Nov 17 05:48:10 2024 us=106224 calc_options_string_link_mtu: link-mtu 1572 -> 1520 Sun Nov 17 05:48:10 2024 us=106234 crypto_adjust_frame_parameters: Adjusting frame parameters for crypto by 68 bytes Sun Nov 17 05:48:10 2024 us=106242 calc_options_string_link_mtu: link-mtu 1572 -> 1520 Sun Nov 17 05:48:10 2024 us=106250 Local Options String (VER=V4): 'V4,dev-type [unknown-dev-type],link-mtu 1520,tun-mtu 1450,proto UDPv4,comp-lzo,keydir 1,cipher AES-256-CBC,auth SHA256,keysize 256,tls-auth,key-method 2,tls-client' Sun Nov 17 05:48:10 2024 us=106254 Expected Remote Options String (VER=V4): 'V4,dev-type [unknown-dev-type],link-mtu 1520,tun-mtu 1450,proto UDPv4,comp-lzo,keydir 0,cipher AES-256-CBC,auth SHA256,keysize 256,tls-auth,key-method 2,tls-server' Sun Nov 17 05:48:10 2024 us=106263 TCP/UDP: Preserving recently used remote address: [AF_INET]103.6.170.21:1194 Sun Nov 17 05:48:10 2024 us=106288 Socket Buffers: R=[212992->212992] S=[212992->212992] Sun Nov 17 05:48:10 2024 us=106302 UDP link local: (not bound) Sun Nov 17 05:48:10 2024 us=106309 UDP link remote: [AF_INET]103.6.170.21:1194 Sun Nov 17 05:48:10 2024 us=106331 TLS Warning: no data channel send key available: [key#0 state=S_INITIAL id=0 sid=00000000 00000000] [key#1 state=S_UNDEF id=0 sid=00000000 00000000] [key#2 state=S_UNDEF id=0 sid=00000000 00000000] Sun Nov 17 05:48:10 2024 us=106336 SENT PING Sun Nov 17 05:48:10 2024 us=106492 TIMER: coarse timer wakeup 1 seconds Sun Nov 17 05:48:10 2024 us=106511 ACK mark active outgoing ID 0 Sun Nov 17 05:48:10 2024 us=106517 ACK reliable_can_send active=1 current=1 : [1] 0 Sun Nov 17 05:48:10 2024 us=106522 ACK reliable_send ID 0 (size=4 to=2) Sun Nov 17 05:48:10 2024 us=106531 ACK reliable_send_timeout 2 [1] 0 Sun Nov 17 05:48:10 2024 us=106542 RANDOM USEC=111969 Sun Nov 17 05:48:10 2024 us=106547 PO_CTL rwflags=0x0003 ev=3 arg=0x556f345c0198 Sun Nov 17 05:48:10 2024 us=106554 I/O WAIT T?|T?|SR|SW [1/111969] Sun Nov 17 05:48:10 2024 us=106561 PO_WAIT[0,0] fd=3 rev=0x00000004 rwflags=0x0002 arg=0x556f345c0198 Sun Nov 17 05:48:10 2024 us=106566 I/O WAIT status=0x0002 Sun Nov 17 05:48:10 2024 us=106596 UDP WRITE [54] to [AF_INET]103.6.170.21:1194: P_CONTROL_HARD_RESET_CLIENT_V2 kid=0 pid=[ #1 ] [ ] pid=0 DATA len=0 Sun Nov 17 05:48:10 2024 us=106658 ACK reliable_can_send active=1 current=0 : [1] 0 Sun Nov 17 05:48:10 2024 us=106704 SSL state (connect): before SSL initialization Sun Nov 17 05:48:10 2024 us=106815 SSL state (connect): SSLv3/TLS write client hello Sun Nov 17 05:48:10 2024 us=106823 ACK reliable_send_timeout 2 [1] 0 Sun Nov 17 05:48:10 2024 us=106829 PO_CTL rwflags=0x0001 ev=3 arg=0x556f345c0198 Sun Nov 17 05:48:10 2024 us=106838 I/O WAIT T?|T?|SR|Sw [1/111969] Sun Nov 17 05:48:11 2024 us=220018 I/O WAIT status=0x0020 Sun Nov 17 05:48:11 2024 us=220060 TIMER: coarse timer wakeup 1 seconds Sun Nov 17 05:48:11 2024 us=220072 ACK reliable_can_send active=1 current=0 : [1] 0 Sun Nov 17 05:48:11 2024 us=220087 ACK reliable_send_timeout 1 [1] 0 Sun Nov 17 05:48:11 2024 us=220094 PO_CTL rwflags=0x0001 ev=3 arg=0x556f345c0198 Sun Nov 17 05:48:11 2024 us=220103 I/O WAIT T?|T?|SR|Sw [1/111969] Sun Nov 17 05:48:12 2024 us=333254 I/O WAIT status=0x0020 Sun Nov 17 05:48:12 2024 us=333285 TIMER: coarse timer wakeup 1 seconds Sun Nov 17 05:48:12 2024 us=333297 ACK reliable_can_send active=1 current=1 : [1] 0 Sun Nov 17 05:48:12 2024 us=333302 ACK reliable_send ID 0 (size=4 to=4) Sun Nov 17 05:48:12 2024 us=333314 ACK reliable_send_timeout 4 [1] 0 Sun Nov 17 05:48:12 2024 us=333320 PO_CTL rwflags=0x0003 ev=3 arg=0x556f345c0198 Sun Nov 17 05:48:12 2024 us=333327 I/O WAIT T?|T?|SR|SW [1/111969] Sun Nov 17 05:48:12 2024 us=333335 PO_WAIT[0,0] fd=3 rev=0x00000004 rwflags=0x0002 arg=0x556f345c0198 Sun Nov 17 05:48:12 2024 us=333339 NOTE: --mute triggered... Sun Nov 17 05:48:12 2024 us=333344 1 variation(s) on previous 20 message(s) suppressed by --mute Sun Nov 17 05:48:12 2024 us=333355 UDP WRITE [54] to [AF_INET]103.6.170.21:1194: P_CONTROL_HARD_RESET_CLIENT_V2 kid=0 pid=[ #2 ] [ ] pid=0 DATA len=0 Sun Nov 17 05:48:12 2024 us=333395 ACK reliable_can_send active=1 current=0 : [1] 0 Sun Nov 17 05:48:12 2024 us=333412 ACK reliable_send_timeout 4 [1] 0 Sun Nov 17 05:48:12 2024 us=333417 PO_CTL rwflags=0x0001 ev=3 arg=0x556f345c0198 Sun Nov 17 05:48:12 2024 us=333422 I/O WAIT T?|T?|SR|Sw [1/111969] Sun Nov 17 05:48:13 2024 us=446568 I/O WAIT status=0x0020 Sun Nov 17 05:48:13 2024 us=446603 TIMER: coarse timer wakeup 1 seconds Sun Nov 17 05:48:13 2024 us=446615 ACK reliable_can_send active=1 current=0 : [1] 0 Sun Nov 17 05:48:13 2024 us=446630 ACK reliable_send_timeout 3 [1] 0 Sun Nov 17 05:48:13 2024 us=446637 PO_CTL rwflags=0x0001 ev=3 arg=0x556f345c0198 Sun Nov 17 05:48:13 2024 us=446644 I/O WAIT T?|T?|SR|Sw [1/111969] Sun Nov 17 05:48:14 2024 us=559792 I/O WAIT status=0x0020 Sun Nov 17 05:48:14 2024 us=559824 TIMER: coarse timer wakeup 1 seconds Sun Nov 17 05:48:14 2024 us=559831 PO_CTL rwflags=0x0001 ev=3 arg=0x556f345c0198 Sun Nov 17 05:48:14 2024 us=559838 I/O WAIT T?|T?|SR|Sw [1/111969] Sun Nov 17 05:48:15 2024 us=672049 I/O WAIT status=0x0020 Sun Nov 17 05:48:15 2024 us=672085 TIMER: coarse timer wakeup 1 seconds Sun Nov 17 05:48:15 2024 us=672094 TLS Error: TLS key negotiation failed to occur within 5 seconds (check your network connectivity) Sun Nov 17 05:48:15 2024 us=672099 TLS Error: TLS handshake failed Sun Nov 17 05:48:15 2024 us=672104 PID packet_id_free Sun Nov 17 05:48:15 2024 us=672137 PID packet_id_free Sun Nov 17 05:48:15 2024 us=672142 PID packet_id_free Sun Nov 17 05:48:15 2024 us=672151 PID packet_id_init seq_backtrack=64 time_backtrack=15 Sun Nov 17 05:48:15 2024 us=672169 PID packet_id_init seq_backtrack=64 time_backtrack=15 Sun Nov 17 05:48:15 2024 us=672179 PID packet_id_free Sun Nov 17 05:48:15 2024 us=672186 PID packet_id_free Sun Nov 17 05:48:15 2024 us=672191 PID packet_id_free Sun Nov 17 05:48:15 2024 us=672195 PID packet_id_free Sun Nov 17 05:48:15 2024 us=672204 PID packet_id_free Sun Nov 17 05:48:15 2024 us=672208 PID packet_id_free Sun Nov 17 05:48:15 2024 us=672213 PID packet_id_free Sun Nov 17 05:48:15 2024 us=672217 PID packet_id_free Sun Nov 17 05:48:15 2024 us=672222 TCP/UDP: Closing socket Sun Nov 17 05:48:15 2024 us=672238 PID packet_id_free Sun Nov 17 05:48:15 2024 us=672247 SIGUSR1[soft,tls-error] received, process restarting Sun Nov 17 05:48:15 2024 us=672264 Restart pause, 5 second(s) Sun Nov 17 05:48:20 2024 us=672372 PO_INIT maxevents=4 flags=0x00000002 Sun Nov 17 05:48:20 2024 us=672415 Re-using SSL/TLS context Sun Nov 17 05:48:20 2024 us=672424 crypto_adjust_frame_parameters: Adjusting frame parameters for crypto by 40 bytes Sun Nov 17 05:48:20 2024 us=672431 LZO compression initializing Sun Nov 17 05:48:20 2024 us=672438 WARNING: normally if you use --mssfix and/or --fragment, you should also set --tun-mtu 1500 (currently it is 1450) Sun Nov 17 05:48:20 2024 us=672452 PID packet_id_init seq_backtrack=64 time_backtrack=15 Sun Nov 17 05:48:20 2024 us=672505 PID packet_id_init seq_backtrack=64 time_backtrack=15 Sun Nov 17 05:48:20 2024 us=672516 PID packet_id_init seq_backtrack=64 time_backtrack=15 Sun Nov 17 05:48:20 2024 us=672531 PID packet_id_init seq_backtrack=64 time_backtrack=15 Sun Nov 17 05:48:20 2024 us=672542 Control Channel MTU parms [ L:1572 D:1172 EF:78 EB:0 ET:0 EL:3 ] Sun Nov 17 05:48:20 2024 us=672550 MTU DYNAMIC mtu=1450, flags=2, 1572 -> 1450 Sun Nov 17 05:48:20 2024 us=672559 RESOLVE_REMOTE flags=0x0901 phase=1 rrs=0 sig=-1 status=0 Sun Nov 17 05:48:20 2024 us=672564 Data Channel MTU parms [ L:1572 D:1450 EF:122 EB:398 ET:0 EL:3 ] Sun Nov 17 05:48:20 2024 us=672578 crypto_adjust_frame_parameters: Adjusting frame parameters for crypto by 68 bytes Sun Nov 17 05:48:20 2024 us=672588 calc_options_string_link_mtu: link-mtu 1572 -> 1520 Sun Nov 17 05:48:20 2024 us=672597 crypto_adjust_frame_parameters: Adjusting frame parameters for crypto by 68 bytes Sun Nov 17 05:48:20 2024 us=672601 calc_options_string_link_mtu: link-mtu 1572 -> 1520 Sun Nov 17 05:48:20 2024 us=672608 Local Options String (VER=V4): 'V4,dev-type [unknown-dev-type],link-mtu 1520,tun-mtu 1450,proto UDPv4,comp-lzo,keydir 1,cipher AES-256-CBC,auth SHA256,keysize 256,tls-auth,key-method 2,tls-client' Sun Nov 17 05:48:20 2024 us=672612 Expected Remote Options String (VER=V4): 'V4,dev-type [unknown-dev-type],link-mtu 1520,tun-mtu 1450,proto UDPv4,comp-lzo,keydir 0,cipher AES-256-CBC,auth SHA256,keysize 256,tls-auth,key-method 2,tls-server' Sun Nov 17 05:48:20 2024 us=672620 TCP/UDP: Preserving recently used remote address: [AF_INET]103.6.170.21:1194 Sun Nov 17 05:48:20 2024 us=672647 Socket Buffers: R=[212992->212992] S=[212992->212992] Sun Nov 17 05:48:20 2024 us=672660 UDP link local: (not bound) Sun Nov 17 05:48:20 2024 us=672665 UDP link remote: [AF_INET]103.6.170.21:1194 Sun Nov 17 05:48:20 2024 us=672685 TLS Warning: no data channel send key available: [key#0 state=S_INITIAL id=0 sid=00000000 00000000] [key#1 state=S_UNDEF id=0 sid=00000000 00000000] [key#2 state=S_UNDEF id=0 sid=00000000 00000000] Sun Nov 17 05:48:20 2024 us=672694 SENT PING Sun Nov 17 05:48:20 2024 us=672698 TIMER: coarse timer wakeup 1 seconds Sun Nov 17 05:48:20 2024 us=672705 ACK mark active outgoing ID 0 Sun Nov 17 05:48:20 2024 us=672711 ACK reliable_can_send active=1 current=1 : [1] 0 Sun Nov 17 05:48:20 2024 us=672716 ACK reliable_send ID 0 (size=4 to=2) Sun Nov 17 05:48:20 2024 us=672726 ACK reliable_send_timeout 2 [1] 0 Sun Nov 17 05:48:20 2024 us=672732 RANDOM USEC=125610 Sun Nov 17 05:48:20 2024 us=672738 PO_CTL rwflags=0x0003 ev=3 arg=0x556f345c0198 Sun Nov 17 05:48:20 2024 us=672744 I/O WAIT T?|T?|SR|SW [1/125610] Sun Nov 17 05:48:20 2024 us=672752 PO_WAIT[0,0] fd=3 rev=0x00000004 rwflags=0x0002 arg=0x556f345c0198 Sun Nov 17 05:48:20 2024 us=672756 I/O WAIT status=0x0002 Sun Nov 17 05:48:20 2024 us=672764 UDP WRITE [54] to [AF_INET]103.6.170.21:1194: P_CONTROL_HARD_RESET_CLIENT_V2 kid=0 pid=[ #1 ] [ ] pid=0 DATA len=0 Sun Nov 17 05:48:20 2024 us=672830 ACK reliable_can_send active=1 current=0 : [1] 0 Sun Nov 17 05:48:20 2024 us=672869 SSL state (connect): before SSL initialization Sun Nov 17 05:48:20 2024 us=672981 SSL state (connect): SSLv3/TLS write client hello Sun Nov 17 05:48:20 2024 us=672994 ACK reliable_send_timeout 2 [1] 0 Sun Nov 17 05:48:20 2024 us=672999 PO_CTL rwflags=0x0001 ev=3 arg=0x556f345c0198 Sun Nov 17 05:48:20 2024 us=673005 I/O WAIT T?|T?|SR|Sw [1/125610] Sun Nov 17 05:48:21 2024 us=800174 I/O WAIT status=0x0020 Sun Nov 17 05:48:21 2024 us=800211 TIMER: coarse timer wakeup 1 seconds Sun Nov 17 05:48:21 2024 us=800222 ACK reliable_can_send active=1 current=0 : [1] 0 Sun Nov 17 05:48:21 2024 us=800237 ACK reliable_send_timeout 1 [1] 0 Sun Nov 17 05:48:21 2024 us=800244 PO_CTL rwflags=0x0001 ev=3 arg=0x556f345c0198 Sun Nov 17 05:48:21 2024 us=800252 I/O WAIT T?|T?|SR|Sw [1/125610] Sun Nov 17 05:48:22 2024 us=927423 I/O WAIT status=0x0020 Sun Nov 17 05:48:22 2024 us=927459 TIMER: coarse timer wakeup 1 seconds Sun Nov 17 05:48:22 2024 us=927470 ACK reliable_can_send active=1 current=1 : [1] 0 Sun Nov 17 05:48:22 2024 us=927476 ACK reliable_send ID 0 (size=4 to=4) Sun Nov 17 05:48:22 2024 us=927487 ACK reliable_send_timeout 4 [1] 0 Sun Nov 17 05:48:22 2024 us=927494 PO_CTL rwflags=0x0003 ev=3 arg=0x556f345c0198 Sun Nov 17 05:48:22 2024 us=927502 I/O WAIT T?|T?|SR|SW [1/125610] Sun Nov 17 05:48:22 2024 us=927509 PO_WAIT[0,0] fd=3 rev=0x00000004 rwflags=0x0002 arg=0x556f345c0198 Sun Nov 17 05:48:22 2024 us=927514 NOTE: --mute triggered... Sun Nov 17 05:48:22 2024 us=927519 1 variation(s) on previous 20 message(s) suppressed by --mute Sun Nov 17 05:48:22 2024 us=927531 UDP WRITE [54] to [AF_INET]103.6.170.21:1194: P_CONTROL_HARD_RESET_CLIENT_V2 kid=0 pid=[ #2 ] [ ] pid=0 DATA len=0 Sun Nov 17 05:48:22 2024 us=927567 ACK reliable_can_send active=1 current=0 : [1] 0 Sun Nov 17 05:48:22 2024 us=927580 ACK reliable_send_timeout 4 [1] 0 Sun Nov 17 05:48:22 2024 us=927588 PO_CTL rwflags=0x0001 ev=3 arg=0x556f345c0198 Sun Nov 17 05:48:22 2024 us=927593 I/O WAIT T?|T?|SR|Sw [1/125610] Sun Nov 17 05:48:24 2024 us=54752 I/O WAIT status=0x0020 Sun Nov 17 05:48:24 2024 us=54789 TIMER: coarse timer wakeup 1 seconds Sun Nov 17 05:48:24 2024 us=54796 PO_CTL rwflags=0x0001 ev=3 arg=0x556f345c0198 Sun Nov 17 05:48:24 2024 us=54804 I/O WAIT T?|T?|SR|Sw [1/125610] Sun Nov 17 05:48:25 2024 us=181977 I/O WAIT status=0x0020 Sun Nov 17 05:48:25 2024 us=182016 TIMER: coarse timer wakeup 1 seconds Sun Nov 17 05:48:25 2024 us=182025 TLS Error: TLS key negotiation failed to occur within 5 seconds (check your network connectivity) Sun Nov 17 05:48:25 2024 us=182030 TLS Error: TLS handshake failed Sun Nov 17 05:48:25 2024 us=182035 PID packet_id_free Sun Nov 17 05:48:25 2024 us=182069 PID packet_id_free Sun Nov 17 05:48:25 2024 us=182074 PID packet_id_free Sun Nov 17 05:48:25 2024 us=182083 PID packet_id_init seq_backtrack=64 time_backtrack=15 Sun Nov 17 05:48:25 2024 us=182101 PID packet_id_init seq_backtrack=64 time_backtrack=15 Sun Nov 17 05:48:25 2024 us=182110 PID packet_id_free Sun Nov 17 05:48:25 2024 us=182117 PID packet_id_free Sun Nov 17 05:48:25 2024 us=182121 PID packet_id_free Sun Nov 17 05:48:25 2024 us=182125 PID packet_id_free Sun Nov 17 05:48:25 2024 us=182134 PID packet_id_free Sun Nov 17 05:48:25 2024 us=182139 PID packet_id_free Sun Nov 17 05:48:25 2024 us=182143 PID packet_id_free Sun Nov 17 05:48:25 2024 us=182147 PID packet_id_free Sun Nov 17 05:48:25 2024 us=182152 TCP/UDP: Closing socket Sun Nov 17 05:48:25 2024 us=182168 PID packet_id_free Sun Nov 17 05:48:25 2024 us=182175 SIGUSR1[soft,tls-error] received, process restarting Sun Nov 17 05:48:25 2024 us=182192 Restart pause, 5 second(s) Sun Nov 17 05:48:30 2024 us=182280 PO_INIT maxevents=4 flags=0x00000002 Sun Nov 17 05:48:30 2024 us=182318 Re-using SSL/TLS context Sun Nov 17 05:48:30 2024 us=182325 crypto_adjust_frame_parameters: Adjusting frame parameters for crypto by 40 bytes Sun Nov 17 05:48:30 2024 us=182332 LZO compression initializing Sun Nov 17 05:48:30 2024 us=182339 WARNING: normally if you use --mssfix and/or --fragment, you should also set --tun-mtu 1500 (currently it is 1450) Sun Nov 17 05:48:30 2024 us=182350 PID packet_id_init seq_backtrack=64 time_backtrack=15 Sun Nov 17 05:48:30 2024 us=182379 PID packet_id_init seq_backtrack=64 time_backtrack=15 Sun Nov 17 05:48:30 2024 us=182385 PID packet_id_init seq_backtrack=64 time_backtrack=15 Sun Nov 17 05:48:30 2024 us=182398 PID packet_id_init seq_backtrack=64 time_backtrack=15 Sun Nov 17 05:48:30 2024 us=182404 Control Channel MTU parms [ L:1572 D:1172 EF:78 EB:0 ET:0 EL:3 ] Sun Nov 17 05:48:30 2024 us=182412 MTU DYNAMIC mtu=1450, flags=2, 1572 -> 1450 Sun Nov 17 05:48:30 2024 us=182420 RESOLVE_REMOTE flags=0x0901 phase=1 rrs=0 sig=-1 status=0 Sun Nov 17 05:48:30 2024 us=182426 Data Channel MTU parms [ L:1572 D:1450 EF:122 EB:398 ET:0 EL:3 ] Sun Nov 17 05:48:30 2024 us=182440 crypto_adjust_frame_parameters: Adjusting frame parameters for crypto by 68 bytes Sun Nov 17 05:48:30 2024 us=182444 calc_options_string_link_mtu: link-mtu 1572 -> 1520 Sun Nov 17 05:48:30 2024 us=182453 crypto_adjust_frame_parameters: Adjusting frame parameters for crypto by 68 bytes Sun Nov 17 05:48:30 2024 us=182505 calc_options_string_link_mtu: link-mtu 1572 -> 1520 Sun Nov 17 05:48:30 2024 us=182525 Local Options String (VER=V4): 'V4,dev-type [unknown-dev-type],link-mtu 1520,tun-mtu 1450,proto UDPv4,comp-lzo,keydir 1,cipher AES-256-CBC,auth SHA256,keysize 256,tls-auth,key-method 2,tls-client' Sun Nov 17 05:48:30 2024 us=182530 Expected Remote Options String (VER=V4): 'V4,dev-type [unknown-dev-type],link-mtu 1520,tun-mtu 1450,proto UDPv4,comp-lzo,keydir 0,cipher AES-256-CBC,auth SHA256,keysize 256,tls-auth,key-method 2,tls-server' Sun Nov 17 05:48:30 2024 us=182539 TCP/UDP: Preserving recently used remote address: [AF_INET]103.6.170.21:1194 Sun Nov 17 05:48:30 2024 us=182566 Socket Buffers: R=[212992->212992] S=[212992->212992] Sun Nov 17 05:48:30 2024 us=182576 UDP link local: (not bound) Sun Nov 17 05:48:30 2024 us=182581 UDP link remote: [AF_INET]103.6.170.21:1194 Sun Nov 17 05:48:30 2024 us=182601 TLS Warning: no data channel send key available: [key#0 state=S_INITIAL id=0 sid=00000000 00000000] [key#1 state=S_UNDEF id=0 sid=00000000 00000000] [key#2 state=S_UNDEF id=0 sid=00000000 00000000] Sun Nov 17 05:48:30 2024 us=182606 SENT PING Sun Nov 17 05:48:30 2024 us=182610 TIMER: coarse timer wakeup 1 seconds Sun Nov 17 05:48:30 2024 us=182617 ACK mark active outgoing ID 0 Sun Nov 17 05:48:30 2024 us=182622 ACK reliable_can_send active=1 current=1 : [1] 0 Sun Nov 17 05:48:30 2024 us=182627 ACK reliable_send ID 0 (size=4 to=2) Sun Nov 17 05:48:30 2024 us=182636 ACK reliable_send_timeout 2 [1] 0 Sun Nov 17 05:48:30 2024 us=182644 RANDOM USEC=9309 Sun Nov 17 05:48:30 2024 us=182649 PO_CTL rwflags=0x0003 ev=3 arg=0x556f345c0198 Sun Nov 17 05:48:30 2024 us=182656 I/O WAIT T?|T?|SR|SW [1/9309] Sun Nov 17 05:48:30 2024 us=182664 PO_WAIT[0,0] fd=3 rev=0x00000004 rwflags=0x0002 arg=0x556f345c0198 Sun Nov 17 05:48:30 2024 us=182669 I/O WAIT status=0x0002 Sun Nov 17 05:48:30 2024 us=182676 UDP WRITE [54] to [AF_INET]103.6.170.21:1194: P_CONTROL_HARD_RESET_CLIENT_V2 kid=0 pid=[ #1 ] [ ] pid=0 DATA len=0 Sun Nov 17 05:48:30 2024 us=182745 ACK reliable_can_send active=1 current=0 : [1] 0 Sun Nov 17 05:48:30 2024 us=182772 SSL state (connect): before SSL initialization Sun Nov 17 05:48:30 2024 us=182875 SSL state (connect): SSLv3/TLS write client hello Sun Nov 17 05:48:30 2024 us=182890 ACK reliable_send_timeout 2 [1] 0 Sun Nov 17 05:48:30 2024 us=182895 PO_CTL rwflags=0x0001 ev=3 arg=0x556f345c0198 Sun Nov 17 05:48:30 2024 us=182901 I/O WAIT T?|T?|SR|Sw [1/9309] Sun Nov 17 05:48:31 2024 us=192482 I/O WAIT status=0x0020 Sun Nov 17 05:48:31 2024 us=192510 TIMER: coarse timer wakeup 1 seconds Sun Nov 17 05:48:31 2024 us=192520 ACK reliable_can_send active=1 current=0 : [1] 0 Sun Nov 17 05:48:31 2024 us=192535 ACK reliable_send_timeout 1 [1] 0 Sun Nov 17 05:48:31 2024 us=192542 PO_CTL rwflags=0x0001 ev=3 arg=0x556f345c0198 Sun Nov 17 05:48:31 2024 us=192549 I/O WAIT T?|T?|SR|Sw [1/9309] Sun Nov 17 05:48:32 2024 us=201611 I/O WAIT status=0x0020 Sun Nov 17 05:48:32 2024 us=201635 TIMER: coarse timer wakeup 1 seconds Sun Nov 17 05:48:32 2024 us=201645 ACK reliable_can_send active=1 current=1 : [1] 0 Sun Nov 17 05:48:32 2024 us=201650 ACK reliable_send ID 0 (size=4 to=4) Sun Nov 17 05:48:32 2024 us=201662 ACK reliable_send_timeout 4 [1] 0 Sun Nov 17 05:48:32 2024 us=201669 PO_CTL rwflags=0x0003 ev=3 arg=0x556f345c0198 Sun Nov 17 05:48:32 2024 us=201676 I/O WAIT T?|T?|SR|SW [1/9309] Sun Nov 17 05:48:32 2024 us=201684 PO_WAIT[0,0] fd=3 rev=0x00000004 rwflags=0x0002 arg=0x556f345c0198 Sun Nov 17 05:48:32 2024 us=201688 NOTE: --mute triggered... Sun Nov 17 05:48:32 2024 us=201693 1 variation(s) on previous 20 message(s) suppressed by --mute Sun Nov 17 05:48:32 2024 us=201703 UDP WRITE [54] to [AF_INET]103.6.170.21:1194: P_CONTROL_HARD_RESET_CLIENT_V2 kid=0 pid=[ #2 ] [ ] pid=0 DATA len=0 Sun Nov 17 05:48:32 2024 us=201745 ACK reliable_can_send active=1 current=0 : [1] 0 Sun Nov 17 05:48:32 2024 us=201758 ACK reliable_send_timeout 4 [1] 0 Sun Nov 17 05:48:32 2024 us=201763 PO_CTL rwflags=0x0001 ev=3 arg=0x556f345c0198 Sun Nov 17 05:48:32 2024 us=201769 I/O WAIT T?|T?|SR|Sw [1/9309] Sun Nov 17 05:48:33 2024 us=211835 I/O WAIT status=0x0020 Sun Nov 17 05:48:33 2024 us=211867 TIMER: coarse timer wakeup 1 seconds Sun Nov 17 05:48:33 2024 us=211878 ACK reliable_can_send active=1 current=0 : [1] 0 Sun Nov 17 05:48:33 2024 us=211893 ACK reliable_send_timeout 3 [1] 0 Sun Nov 17 05:48:33 2024 us=211900 PO_CTL rwflags=0x0001 ev=3 arg=0x556f345c0198 Sun Nov 17 05:48:33 2024 us=211907 I/O WAIT T?|T?|SR|Sw [1/9309] Sun Nov 17 05:48:34 2024 us=221975 I/O WAIT status=0x0020 Sun Nov 17 05:48:34 2024 us=222018 TIMER: coarse timer wakeup 1 seconds Sun Nov 17 05:48:34 2024 us=222028 PO_CTL rwflags=0x0001 ev=3 arg=0x556f345c0198 Sun Nov 17 05:48:34 2024 us=222038 I/O WAIT T?|T?|SR|Sw [1/9309] Sun Nov 17 05:48:35 2024 us=232032 I/O WAIT status=0x0020 Sun Nov 17 05:48:35 2024 us=232068 TIMER: coarse timer wakeup 1 seconds Sun Nov 17 05:48:35 2024 us=232078 TLS Error: TLS key negotiation failed to occur within 5 seconds (check your network connectivity) Sun Nov 17 05:48:35 2024 us=232083 TLS Error: TLS handshake failed Sun Nov 17 05:48:35 2024 us=232087 PID packet_id_free Sun Nov 17 05:48:35 2024 us=232118 PID packet_id_free Sun Nov 17 05:48:35 2024 us=232123 PID packet_id_free Sun Nov 17 05:48:35 2024 us=232133 PID packet_id_init seq_backtrack=64 time_backtrack=15 Sun Nov 17 05:48:35 2024 us=232153 PID packet_id_init seq_backtrack=64 time_backtrack=15 Sun Nov 17 05:48:35 2024 us=232162 PID packet_id_free Sun Nov 17 05:48:35 2024 us=232168 PID packet_id_free Sun Nov 17 05:48:35 2024 us=232173 PID packet_id_free Sun Nov 17 05:48:35 2024 us=232177 PID packet_id_free Sun Nov 17 05:48:35 2024 us=232185 PID packet_id_free Sun Nov 17 05:48:35 2024 us=232190 PID packet_id_free Sun Nov 17 05:48:35 2024 us=232194 PID packet_id_free Sun Nov 17 05:48:35 2024 us=232198 PID packet_id_free Sun Nov 17 05:48:35 2024 us=232203 TCP/UDP: Closing socket Sun Nov 17 05:48:35 2024 us=232218 PID packet_id_free Sun Nov 17 05:48:35 2024 us=232225 SIGUSR1[soft,tls-error] received, process restarting Sun Nov 17 05:48:35 2024 us=232242 Restart pause, 5 second(s) Sun Nov 17 05:48:40 2024 us=232325 PO_INIT maxevents=4 flags=0x00000002 Sun Nov 17 05:48:40 2024 us=232358 Re-using SSL/TLS context Sun Nov 17 05:48:40 2024 us=232365 crypto_adjust_frame_parameters: Adjusting frame parameters for crypto by 40 bytes Sun Nov 17 05:48:40 2024 us=232372 LZO compression initializing Sun Nov 17 05:48:40 2024 us=232379 WARNING: normally if you use --mssfix and/or --fragment, you should also set --tun-mtu 1500 (currently it is 1450) Sun Nov 17 05:48:40 2024 us=232391 PID packet_id_init seq_backtrack=64 time_backtrack=15 Sun Nov 17 05:48:40 2024 us=232419 PID packet_id_init seq_backtrack=64 time_backtrack=15 Sun Nov 17 05:48:40 2024 us=232425 PID packet_id_init seq_backtrack=64 time_backtrack=15 Sun Nov 17 05:48:40 2024 us=232438 PID packet_id_init seq_backtrack=64 time_backtrack=15 Sun Nov 17 05:48:40 2024 us=232456 Control Channel MTU parms [ L:1572 D:1172 EF:78 EB:0 ET:0 EL:3 ] Sun Nov 17 05:48:40 2024 us=232463 MTU DYNAMIC mtu=1450, flags=2, 1572 -> 1450 Sun Nov 17 05:48:40 2024 us=232472 RESOLVE_REMOTE flags=0x0901 phase=1 rrs=0 sig=-1 status=0 Sun Nov 17 05:48:40 2024 us=232477 Data Channel MTU parms [ L:1572 D:1450 EF:122 EB:398 ET:0 EL:3 ] Sun Nov 17 05:48:40 2024 us=232489 crypto_adjust_frame_parameters: Adjusting frame parameters for crypto by 68 bytes Sun Nov 17 05:48:40 2024 us=232493 calc_options_string_link_mtu: link-mtu 1572 -> 1520 Sun Nov 17 05:48:40 2024 us=232502 crypto_adjust_frame_parameters: Adjusting frame parameters for crypto by 68 bytes Sun Nov 17 05:48:40 2024 us=232507 calc_options_string_link_mtu: link-mtu 1572 -> 1520 Sun Nov 17 05:48:40 2024 us=232513 Local Options String (VER=V4): 'V4,dev-type [unknown-dev-type],link-mtu 1520,tun-mtu 1450,proto UDPv4,comp-lzo,keydir 1,cipher AES-256-CBC,auth SHA256,keysize 256,tls-auth,key-method 2,tls-client' Sun Nov 17 05:48:40 2024 us=232518 Expected Remote Options String (VER=V4): 'V4,dev-type [unknown-dev-type],link-mtu 1520,tun-mtu 1450,proto UDPv4,comp-lzo,keydir 0,cipher AES-256-CBC,auth SHA256,keysize 256,tls-auth,key-method 2,tls-server' Sun Nov 17 05:48:40 2024 us=232525 TCP/UDP: Preserving recently used remote address: [AF_INET]103.6.170.21:1194 Sun Nov 17 05:48:40 2024 us=232552 Socket Buffers: R=[212992->212992] S=[212992->212992] Sun Nov 17 05:48:40 2024 us=232563 UDP link local: (not bound) Sun Nov 17 05:48:40 2024 us=232568 UDP link remote: [AF_INET]103.6.170.21:1194 Sun Nov 17 05:48:40 2024 us=232588 TLS Warning: no data channel send key available: [key#0 state=S_INITIAL id=0 sid=00000000 00000000] [key#1 state=S_UNDEF id=0 sid=00000000 00000000] [key#2 state=S_UNDEF id=0 sid=00000000 00000000] Sun Nov 17 05:48:40 2024 us=232594 SENT PING Sun Nov 17 05:48:40 2024 us=232599 TIMER: coarse timer wakeup 1 seconds Sun Nov 17 05:48:40 2024 us=232605 ACK mark active outgoing ID 0 Sun Nov 17 05:48:40 2024 us=232610 ACK reliable_can_send active=1 current=1 : [1] 0 Sun Nov 17 05:48:40 2024 us=232615 ACK reliable_send ID 0 (size=4 to=2) Sun Nov 17 05:48:40 2024 us=232623 ACK reliable_send_timeout 2 [1] 0 Sun Nov 17 05:48:40 2024 us=232629 RANDOM USEC=7253 Sun Nov 17 05:48:40 2024 us=232634 PO_CTL rwflags=0x0003 ev=3 arg=0x556f345c0198 Sun Nov 17 05:48:40 2024 us=232641 I/O WAIT T?|T?|SR|SW [1/7253] Sun Nov 17 05:48:40 2024 us=232648 PO_WAIT[0,0] fd=3 rev=0x00000004 rwflags=0x0002 arg=0x556f345c0198 Sun Nov 17 05:48:40 2024 us=232653 I/O WAIT status=0x0002 Sun Nov 17 05:48:40 2024 us=232660 UDP WRITE [54] to [AF_INET]103.6.170.21:1194: P_CONTROL_HARD_RESET_CLIENT_V2 kid=0 pid=[ #1 ] [ ] pid=0 DATA len=0 Sun Nov 17 05:48:40 2024 us=232707 ACK reliable_can_send active=1 current=0 : [1] 0 Sun Nov 17 05:48:40 2024 us=232732 SSL state (connect): before SSL initialization Sun Nov 17 05:48:40 2024 us=232827 SSL state (connect): SSLv3/TLS write client hello Sun Nov 17 05:48:40 2024 us=232836 ACK reliable_send_timeout 2 [1] 0 Sun Nov 17 05:48:40 2024 us=232841 PO_CTL rwflags=0x0001 ev=3 arg=0x556f345c0198 Sun Nov 17 05:48:40 2024 us=232847 I/O WAIT T?|T?|SR|Sw [1/7253] Sun Nov 17 05:48:41 2024 us=240903 I/O WAIT status=0x0020 Sun Nov 17 05:48:41 2024 us=240944 TIMER: coarse timer wakeup 1 seconds Sun Nov 17 05:48:41 2024 us=240956 ACK reliable_can_send active=1 current=0 : [1] 0 Sun Nov 17 05:48:41 2024 us=240972 ACK reliable_send_timeout 1 [1] 0 Sun Nov 17 05:48:41 2024 us=240979 PO_CTL rwflags=0x0001 ev=3 arg=0x556f345c0198 Sun Nov 17 05:48:41 2024 us=240986 I/O WAIT T?|T?|SR|Sw [1/7253] Sun Nov 17 05:48:42 2024 us=248051 I/O WAIT status=0x0020 Sun Nov 17 05:48:42 2024 us=248082 TIMER: coarse timer wakeup 1 seconds Sun Nov 17 05:48:42 2024 us=248093 ACK reliable_can_send active=1 current=1 : [1] 0 Sun Nov 17 05:48:42 2024 us=248099 ACK reliable_send ID 0 (size=4 to=4) Sun Nov 17 05:48:42 2024 us=248110 ACK reliable_send_timeout 4 [1] 0 Sun Nov 17 05:48:42 2024 us=248117 PO_CTL rwflags=0x0003 ev=3 arg=0x556f345c0198 Sun Nov 17 05:48:42 2024 us=248124 I/O WAIT T?|T?|SR|SW [1/7253] Sun Nov 17 05:48:42 2024 us=248132 PO_WAIT[0,0] fd=3 rev=0x00000004 rwflags=0x0002 arg=0x556f345c0198 Sun Nov 17 05:48:42 2024 us=248136 NOTE: --mute triggered... Sun Nov 17 05:48:42 2024 us=248141 1 variation(s) on previous 20 message(s) suppressed by --mute Sun Nov 17 05:48:42 2024 us=248152 UDP WRITE [54] to [AF_INET]103.6.170.21:1194: P_CONTROL_HARD_RESET_CLIENT_V2 kid=0 pid=[ #2 ] [ ] pid=0 DATA len=0 Sun Nov 17 05:48:42 2024 us=248192 ACK reliable_can_send active=1 current=0 : [1] 0 Sun Nov 17 05:48:42 2024 us=248207 ACK reliable_send_timeout 4 [1] 0 Sun Nov 17 05:48:42 2024 us=248212 PO_CTL rwflags=0x0001 ev=3 arg=0x556f345c0198 Sun Nov 17 05:48:42 2024 us=248220 I/O WAIT T?|T?|SR|Sw [1/7253] Sun Nov 17 05:48:43 2024 us=256271 I/O WAIT status=0x0020 Sun Nov 17 05:48:43 2024 us=256309 TIMER: coarse timer wakeup 1 seconds Sun Nov 17 05:48:43 2024 us=256321 ACK reliable_can_send active=1 current=0 : [1] 0 Sun Nov 17 05:48:43 2024 us=256336 ACK reliable_send_timeout 3 [1] 0 Sun Nov 17 05:48:43 2024 us=256343 PO_CTL rwflags=0x0001 ev=3 arg=0x556f345c0198 Sun Nov 17 05:48:43 2024 us=256350 I/O WAIT T?|T?|SR|Sw [1/7253] Sun Nov 17 05:48:44 2024 us=264401 I/O WAIT status=0x0020 Sun Nov 17 05:48:44 2024 us=264442 TIMER: coarse timer wakeup 1 seconds Sun Nov 17 05:48:44 2024 us=264450 PO_CTL rwflags=0x0001 ev=3 arg=0x556f345c0198 Sun Nov 17 05:48:44 2024 us=264458 I/O WAIT T?|T?|SR|Sw [1/7253] Sun Nov 17 05:48:45 2024 us=272038 I/O WAIT status=0x0020 Sun Nov 17 05:48:45 2024 us=272074 TIMER: coarse timer wakeup 1 seconds Sun Nov 17 05:48:45 2024 us=272084 TLS Error: TLS key negotiation failed to occur within 5 seconds (check your network connectivity) Sun Nov 17 05:48:45 2024 us=272089 TLS Error: TLS handshake failed Sun Nov 17 05:48:45 2024 us=272093 PID packet_id_free Sun Nov 17 05:48:45 2024 us=272126 PID packet_id_free Sun Nov 17 05:48:45 2024 us=272131 PID packet_id_free Sun Nov 17 05:48:45 2024 us=272140 PID packet_id_init seq_backtrack=64 time_backtrack=15 Sun Nov 17 05:48:45 2024 us=272158 PID packet_id_init seq_backtrack=64 time_backtrack=15 Sun Nov 17 05:48:45 2024 us=272166 PID packet_id_free Sun Nov 17 05:48:45 2024 us=272173 PID packet_id_free Sun Nov 17 05:48:45 2024 us=272177 PID packet_id_free Sun Nov 17 05:48:45 2024 us=272181 PID packet_id_free Sun Nov 17 05:48:45 2024 us=272190 PID packet_id_free Sun Nov 17 05:48:45 2024 us=272194 PID packet_id_free Sun Nov 17 05:48:45 2024 us=272198 PID packet_id_free Sun Nov 17 05:48:45 2024 us=272202 PID packet_id_free Sun Nov 17 05:48:45 2024 us=272207 TCP/UDP: Closing socket Sun Nov 17 05:48:45 2024 us=272223 PID packet_id_free Sun Nov 17 05:48:45 2024 us=272230 SIGUSR1[soft,tls-error] received, process restarting Sun Nov 17 05:48:45 2024 us=272246 Restart pause, 10 second(s)
_______________________________________________ Openvpn-devel mailing list Openvpn-devel@lists.sourceforge.net https://lists.sourceforge.net/lists/listinfo/openvpn-devel