Re: [Openvpn-devel] windows client tests needed

2024-07-29 Thread Dmitry Melekhov
Hello! Hope we are not too late . We jist tested block-local using this client in Windows 10 Pro 22H2 and do not see any difference in behaviour comparing with 2.6. Thank you! 06.06.2024 16:23, Gert Doering пишет: Hi, we have new code in master that helps with the "TunnelCrack" and "T

Re: [Openvpn-devel] windows client tests needed

2024-06-06 Thread Dmitry Melekhov
06.06.2024 16:23, Gert Doering пишет: Hello! We used to have block-outside-dns to prevent Windows from doing DNS lookups "around the VPN" - the main intent of this was "make sure split DNS works", but a side effect has also been "avoid DNS leaks". Heiko has now extended this code to be ab

Re: [Openvpn-devel] OpenVPN 2.6.7 released

2023-11-13 Thread Dmitry Melekhov
14.11.2023 11:05, Gert Doering пишет: Hi, On Sun, Nov 12, 2023 at 06:08:48PM +, Greg Cox wrote: Spun this config up, then ran: iptables -t nat -A PREROUTING -i eth0 -p tcp -m multiport --dports 443,80 -j REDIRECT --to-ports 1194 Within 5 minutes the random web scanners found and segfaulte

Re: [Openvpn-devel] OpenVPN 2.6.7 released

2023-11-10 Thread Dmitry Melekhov
btw, what I missed, openvpn dies: openvpn[11346]: segfault at 0 ip 55e33503f5f3 sp 7fff33642390 error 4 in openvpn[55e334fc8000+8f000] but only  multipoint udp . 10.11.2023 11:35, Dmitry Melekhov пишет: 10.11.2023 11:23, Gert Doering пишет: Hi, On Fri, Nov 10, 2023 at 11:19

Re: [Openvpn-devel] OpenVPN 2.6.7 released

2023-11-09 Thread Dmitry Melekhov
10.11.2023 11:23, Gert Doering пишет: Hi, On Fri, Nov 10, 2023 at 11:19:58AM +0400, Dmitry Melekhov wrote: OK, now I know what is broken. I have so called multihomed server,  and multihomed udp does not work in 2.6.7. On server with only one external interface everything works OK. Are you

Re: [Openvpn-devel] OpenVPN 2.6.7 released

2023-11-09 Thread Dmitry Melekhov
10.11.2023 10:21, Dmitry Melekhov пишет: 10.11.2023 00:56, Yuriy Darnobyt пишет: The OpenVPN community project team is proud to release OpenVPN 2.6.7. something is broken in 2.6.7. it stops passing traffic after several seconds after connection when acts as server, so I reverted it back

Re: [Openvpn-devel] OpenVPN 2.6.7 released

2023-11-09 Thread Dmitry Melekhov
10.11.2023 00:56, Yuriy Darnobyt пишет: The OpenVPN community project team is proud to release OpenVPN 2.6.7. something is broken in 2.6.7. it stops passing traffic after several seconds after connection when acts as server, so I reverted it back to 2.6.6. compiled from sources on ubuntu 2

Re: [Openvpn-devel] OpenVPN 2.5.9 released

2023-02-16 Thread Dmitry Melekhov
16.02.2023 17:11, Jonathan K. Bullard пишет: Not yet seeing anything about 2.5.9 at https://openvpn.net/community-downloads/. (From the New York City metropolitan area.) Maybe caches need updating? use almost the same url as for 2.5.8 but change version, works for me. Best regards, Jon

Re: [Openvpn-devel] git master crashes on connect of 2.3 client with --enable-small

2020-07-13 Thread Dmitry Melekhov
13.07.2020 18:23, Marvin Adeff пишет: I’m wondering if the opposite of this scenario has been tested, where the server is running 2.3.18 (on Linux) and a client running 2.5 (on Windows) tries to connect? No, I did not tried this, because we run 2.4.9 on servers now. I know, I know, we sh

Re: [Openvpn-devel] git master crashes on connect of 2.3 client with --enable-small

2020-07-13 Thread Dmitry Melekhov
13.07.2020 10:58, Gert Doering пишет: Hi, On Mon, Jul 13, 2020 at 08:33:03AM +0200, Gert Doering wrote: On Mon, Jul 13, 2020 at 08:10:23AM +0200, Gert Doering wrote: Ouch. This is not good. My gut feeling is "2.3 with --enable-small = no OCC *and* no NCP = the server runs across a NULL point

Re: [Openvpn-devel] [PATCH] systemd: Change the default cipher to AES-256-GCM for server configs

2020-07-12 Thread Dmitry Melekhov
12.07.2020 04:05, Arne Schwabe пишет: Am 23.06.20 um 11:12 schrieb Dmitry Melekhov: 23.06.2020 13:02, Gert Doering пишет: That patch is from Steffan, and review has been sitting in my lap for way too long.  Need to see if it still applies. Unfortunately it is not compatible with 2.4.9

Re: [Openvpn-devel] [PATCH] systemd: Change the default cipher to AES-256-GCM for server configs

2020-06-24 Thread Dmitry Melekhov
24.06.2020 14:12, Arne Schwabe пишет: There are openvpn 2.3 clients in 3g routers which  are built without ability to inform server about cipher, so server uses default cipher for them, in case you need to change default cipher on server you can't do this , because clients will not work, it is

Re: [Openvpn-devel] [PATCH] systemd: Change the default cipher to AES-256-GCM for server configs

2020-06-23 Thread Dmitry Melekhov
23.06.2020 13:02, Gert Doering пишет: That patch is from Steffan, and review has been sitting in my lap for way too long. Need to see if it still applies. Unfortunately it is not compatible with 2.4.9, because of introduced change... ___ Op

Re: [Openvpn-devel] [PATCH] systemd: Change the default cipher to AES-256-GCM for server configs

2020-06-23 Thread Dmitry Melekhov
23.06.2020 12:34, Arne Schwabe пишет: Am 23.06.20 um 06:16 schrieb Dmitry Melekhov: 22.06.2020 20:58, Selva Nair пишет: +*WARNING*    This MAY break configurations where the client uses +    ``--disable-occ`` feature where the ``--cipher`` has +    not been explicitly

Re: [Openvpn-devel] [PATCH] systemd: Change the default cipher to AES-256-GCM for server configs

2020-06-22 Thread Dmitry Melekhov
22.06.2020 20:58, Selva Nair пишет: +*WARNING*This MAY break configurations where the client uses +``--disable-occ`` feature where the ``--cipher`` has +not been explicitly configured on both client and +server side. It is recommended to remove

[Openvpn-devel] 2.4.9 and cipher in ccd

2020-04-18 Thread Dmitry Melekhov
Hello! We use patch from https://community.openvpn.net/openvpn/ticket/845 for several years, it is still interesting for us and allows to set cipher per client in ccd. Unfortunately, 2.4.9 makes this patch incompatible. Is it possible to update this patch to 2.4.9 ? Unfortunately I have