Re: [Openvpn-users] Client-to-client setup fails mysteriously...

2021-06-04 Thread tincantech via Openvpn-users
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Correction: ‐‐‐ Original Message ‐‐‐ On Friday, 4 June 2021 20:49, tincantech via Openvpn-users wrote: > Hi, > > ‐‐‐ Original Message ‐‐‐ > On Friday, 4 June 2021 19:17, Bo Berglund bo.bergl...@gmail.com wrote: >

Re: [Openvpn-users] Client-to-client setup fails mysteriously...

2021-06-04 Thread tincantech via Openvpn-users
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Hi, ‐‐‐ Original Message ‐‐‐ On Friday, 4 June 2021 21:23, Bo Berglund wrote: > On Fri, 04 Jun 2021 19:49:36 +, tincantech via Openvpn-users > openvpn-users@lists.sourceforge.net wrote: > > > > I have set up an O

Re: [Openvpn-users] The preferred way to run a client on linux?

2021-06-07 Thread tincantech via Openvpn-users
> I am still confused, see below > > > > I have seen different ways of accomplishing this: > > > > > > 1. Via the openvpn defaults > > > > > > In this case the client.ovpn file is renamed to client.conf and placed in > > > /etc/openvpn. >

Re: [Openvpn-users] The preferred way to run a client on linux?

2021-06-07 Thread tincantech via Openvpn-users
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Silly typo correction: ‐‐‐ Original Message ‐‐‐ On Monday, 7 June 2021 21:34, tincantech via Openvpn-users wrote: > Hi, > > ‐‐‐ Original Message ‐‐‐ > On Monday, 7 June 2021 20:54, Bo Berglund bo.bergl...@gma

Re: [Openvpn-users] figuring out connection interface

2021-06-08 Thread tincantech via Openvpn-users
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Hi, ‐‐‐ Original Message ‐‐‐ On Tuesday, 8 June 2021 22:31, Aleksandar Ivanisevic wrote: > I looked around a bit and haven’t found a way for a non commercial user to > open a change request with openvpn team, please point me out

Re: [Openvpn-users] On-demand OVPN connection from Windows 10?

2021-06-12 Thread tincantech via Openvpn-users
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Hi, ‐‐‐ Original Message ‐‐‐ On Saturday, 12 June 2021 18:51, Bo Berglund wrote: > I am using the OpenVPN Gui application on my Windows 10 laptop to connect to a > variety of locations where I have put OpenVPN servers. > This h

[Openvpn-users] MULTI_sva: pool returned IPv4

2021-06-17 Thread tincantech via Openvpn-users
m aEZb/JJFRYRG+sEGzHEqtl/6KWkCcmz3DP+i+NeRDxWApdDegB+K1XOg2ock plY6a1oYrNdQKXs15nZfyo/zUXyggVcmZ8huD3nBvlskl6y722RgLw== =tMm+ -END PGP SIGNATURE- publickey - tincantech@protonmail.com - 0x09BC3D44.asc Description: application/pgp-keys publickey - tincantech@protonmail.com - 0x09BC3D44.asc.sig Description: PGP

Re: [Openvpn-users] Setting up a tighter OpenVPN configuration setup

2021-07-01 Thread tincantech via Openvpn-users
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Hi, all you basically need can be found at pivpn.io ‐‐‐ Original Message ‐‐‐ On Saturday, June 26th, 2021 at 19:49, David Mehler wrote: > Hello, > > I'm wanting to set up an OpenVPN external client to an internal >

Re: [Openvpn-users] How to use config file requiring a private key with systemctl?

2021-07-02 Thread tincantech via Openvpn-users
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Your openvpn config file needs to have --askpass. You can read more about it in the manual. ‐‐‐ Original Message ‐‐‐ On Friday, July 2nd, 2021 at 05:52, Austin Witmer wrote: > I am wondering how to start a service that require

Re: [Openvpn-users] Setting up a tighter OpenVPN configuration setup

2021-07-02 Thread tincantech via Openvpn-users
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Hi, we don't provide support for PiVPN here, you should start with: https://github.com/pivpn/pivpn#readme WRT a 512bit elliptic curve, I don't believe there is one, at least not one that Openvpn supports. The closest is maybe secp521

Re: [Openvpn-users] OpenVPN freezes few seconds after each connection

2021-07-04 Thread tincantech via Openvpn-users
wrote: > Dear OpenVPN community, > > I'm writing as I obtain a systematic freeze on a production machine today. > Problem is that is gets frozen systematically few seconds after connection. > It is not the first time and seem to be random. This is preventing any remote &g

Re: [Openvpn-users] OpenVPN freezes few seconds after each connection

2021-07-04 Thread tincantech via Openvpn-users
gt; > I haven't dived into all details of your email, but if you want to > > ignore a parameter sent by the server, you can do so by adding > > "pull-filter ignore $param-to-ignore-here". > > You can check the manpage for further details. Of course, you can a

Re: [Openvpn-users] OpenVPN freezes few seconds after each connection

2021-07-05 Thread Hans via Openvpn-users
Hi Thibault, There might be countless reasons for that you described. Personally, I met with them twice. One irregular returning, was caused by an unstable DNS-server, causing random delays. The other was caused by the single-thread auth architecture of openvpn, where the connection set-up by

Re: [Openvpn-users] TLS version

2021-07-15 Thread tincantech via Openvpn-users
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Hi, Sent with ProtonMail Secure Email, which cannot handle a simple reply properly. ‐‐‐ Original Message ‐‐‐ On Thursday, July 15th, 2021 at 11:17, Ralf Hildebrandt wrote: > I have quite a few users with old openvpn versions out th

[Openvpn-users] Providing routing for a whole IPv6 subnet

2021-07-17 Thread dashdruid via Openvpn-users
te for the network on the VPN server it does not go into the tunnel interface: ip -6 r a 2a02:111::1::/64 via 2a02:111::333::1000 I assume I might messed something up with the subnetting. Any ideas? Thanks _______ Openvpn-use

Re: [Openvpn-users] Providing routing for a whole IPv6 subnet

2021-07-17 Thread dashdruid via Openvpn-users
tulli wrote: > Hi, > > Glad to see more people playing with IPv6 subnets :-) > > On 17/07/2021 11:52, dashdruid via Openvpn-users wrote: > > > Hello List, > > > > I have the following setup. > > > > Internet -> VPNServer -> VPNClient -> LA

[Openvpn-users] Easy-TLS v2.3

2021-07-20 Thread tincantech via Openvpn-users
WGZBVSZImx/8IsZ3H/of456YMcgtQ== =DNea -END PGP SIGNATURE- publickey - tincantech@protonmail.com - 0x09BC3D44.asc Description: application/pgp-keys publickey - tincantech@protonmail.com - 0x09BC3D44.asc.sig Description: PGP signature _______ Ope

Re: [Openvpn-users] TLS version

2021-07-27 Thread tincantech via Openvpn-users
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Hi, On Tuesday, July 27th, 2021 at 14:16, Gert Doering wrote: > Hi, > > On Thu, Jul 15, 2021 at 12:17:45PM +0200, Ralf Hildebrandt wrote: > > > I have quite a few users with old openvpn versions out there which are >

[Openvpn-users] Some MACS don't get resolved properly with the bridge

2021-07-31 Thread dashdruid via Openvpn-users
Hello List, I have this old problem I did not find a solution yet. The endpoints are running OpenVPN 2.4.6 respectively. The setup is bridged like this: Net A ---> (br0) Debian OpenVPN Bridge server 1 (tap0) --> Internet --> (tap0) Debian OpenVPN Bridge server 2 (br0) --> Net B

Re: [Openvpn-users] On-demand OVPN connection from Windows 10?

2021-09-21 Thread tincantech via Openvpn-users
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Hi, Sent with ProtonMail Secure Email. ‐‐‐ Original Message ‐‐‐ On Tuesday, September 21st, 2021 at 13:39, Bo Berglund wrote: > I have noted that the OpenVPN GUI application runs a very long time (maybe > > forever) if th

Re: [Openvpn-users] On-demand OVPN connection from Windows 10?

2021-09-22 Thread tincantech via Openvpn-users
blocking until all pending VPN client connections are > > established (or have given up)" command? > > openvpn-gui --command wait > > (I have no idea how complex this would be, I just go out and ask for > > things) > @selva, how difficult would it be to have the GUI support

[Openvpn-users] multiple server instances with own easy-rsa path?

2021-10-29 Thread lejeczek via Openvpn-users
Hi guys. Having an instance(s) of a daemon/server with systemd - is it possible to give it, tell it use separate, specific easy-rsa path for all the cets? By an server instance I mean, the same binaries from the same Ovpn installation using dedicated conf file in /etc/openvpn/server many

Re: [Openvpn-users] multiple server instances with own easy-rsa path?

2021-10-30 Thread lejeczek via Openvpn-users
On 29/10/2021 20:04, Bo Berglund wrote: On Fri, 29 Oct 2021 18:18:51 +0100, lejeczek via Openvpn-users wrote: Hi guys. Having an instance(s) of a daemon/server with systemd - is it possible to give it, tell it use separate, specific easy-rsa path for all the cets? By an server instance I

[Openvpn-users] Linux client DNS resolver - does it even work?

2021-11-10 Thread lejeczek via Openvpn-users
t server pushes, namely DNS server & domains but, really nothing comes out of it. It cannot be some limitation of Linuxes - I'm on latest Fedora - I must be missing something and what that might be, if you care to suggest, I'll appreciate. many thanks, L. ______

Re: [Openvpn-users] Linux client DNS resolver - does it even work?

2021-11-13 Thread lejeczek via Openvpn-users
On 11/11/2021 05:25, Gert Doering wrote: Hi, On Wed, Nov 10, 2021 at 10:18:02PM +, lejeczek via Openvpn-users wrote: I have, I'd like to think a "regular" server setup where clients from Windowze and Macs do get name resolution work apparently very well, whereas Lin

[Openvpn-users] client-to-client NO with exceptions ?

2021-11-13 Thread lejeczek via Openvpn-users
Hi guys. I wonder if that would be pipe wishes to think it should be possible - to deny clients to clients and then work with exception, exclusion where a given client(s) would be allowed a) to all b) to one/some ? many thanks, L. ___ Openvpn

Re: [Openvpn-users] push-reset / override defaults in ccd files ?

2021-11-16 Thread tincantech via Openvpn-users
nnects on its own :( > > I tried adding > > push-reset > > push "keepalive 5 30" > > to the ccd file, but that doesnt seem to work.  Any ideas ? > Try --push-remove (v2.5 server required) More details here: https://build.openvpn.net/man/openvpn-2.5/openv

Re: [Openvpn-users] push-reset / override defaults in ccd files ?

2021-11-16 Thread tincantech via Openvpn-users
KPxosXtU0R/bS/uFQDgONoq5IXEHlnw== =eYkR -END PGP SIGNATURE- publickey - tincantech@protonmail.com - 0x09BC3D44.asc Description: application/pgp-keys publickey - tincantech@protonmail.com - 0x09BC3D44.asc.sig Description: PGP signature ________

Re: [Openvpn-users] Linux client DNS resolver - does it even work?

2021-11-19 Thread lejeczek via Openvpn-users
On 15/11/2021 13:31, Gert Doering wrote: Hi, On Sat, Nov 13, 2021 at 09:05:19PM +, lejeczek via Openvpn-users wrote: On Linux, OpenVPN does not modify the DNS servers itself (unlike Windows). There's two ways to make it happen - use Network Manager to run OpenVPN - it will

Re: [Openvpn-users] client-to-client NO with exceptions ?

2021-11-19 Thread lejeczek via Openvpn-users
On 13/11/2021 22:21, Gert Doering wrote: Hi, On Sat, Nov 13, 2021 at 09:11:03PM +, lejeczek via Openvpn-users wrote: I wonder if that would be pipe wishes to think it should be possible - to deny clients to clients and then work with exception, exclusion where a given client(s) would be

Re: [Openvpn-users] client-to-client NO with exceptions ?

2021-11-19 Thread lejeczek via Openvpn-users
On 19/11/2021 13:57, Gert Doering wrote: Hi, On Fri, Nov 19, 2021 at 01:52:20PM +, lejeczek via Openvpn-users wrote: unset client-to-client in the openvpn config, make sure "a given client" has a known IP address (ifconfig-push in ccd/), then do the filtering by iptables on

Re: [Openvpn-users] client-to-client NO with exceptions ?

2021-11-19 Thread André via Openvpn-users
Hi, this might help: https://community.openvpn.net/openvpn/wiki/HowPacketsFlow https://community.openvpn.net/openvpn/wiki/AvoidRoutingConflicts Pippin Sent with ProtonMail Secure Email. ‐‐‐ Original Message ‐‐‐ Op vrijdag 19 november 2021 om 15:53 schreef lejeczek via Openvpn

Re: [Openvpn-users] client-to-client NO with exceptions ?

2021-11-19 Thread lejeczek via Openvpn-users
On 19/11/2021 15:08, Joe Patterson wrote: client-to-client bypasses nftables entirely. With it enabled, client-to-client packets are routed internally to openvpn via the iroute table without ever being handed off to the kernel for inspection, firewalling, routing, counting, capturing

Re: [Openvpn-users] client-to-client NO with exceptions ?

2021-11-20 Thread lejeczek via Openvpn-users
On 19/11/2021 19:13, Gert Doering wrote: Hi, On Fri, Nov 19, 2021 at 02:53:17PM +, lejeczek via Openvpn-users wrote: client-to-client works. I did disable it as per your suggestion to "unset" and am trying to work it out through rules which would allow. But similarly enabled

Re: [Openvpn-users] client-to-client NO with exceptions ?

2021-11-20 Thread lejeczek via Openvpn-users
On 20/11/2021 18:18, lejeczek via Openvpn-users wrote: On 19/11/2021 19:13, Gert Doering wrote: Hi, On Fri, Nov 19, 2021 at 02:53:17PM +, lejeczek via Openvpn-users wrote: client-to-client works. I did disable it as per your suggestion to "unset" and am trying to work it o

Re: [Openvpn-users] Multiple IPs on one client

2021-11-29 Thread tincantech via Openvpn-users
push out > multiple IP addresses to particular clients? You can use client --up script to add a second IP: `/bin/ip a a ${ip.add}/${mask} dev ${mytun}` `/bin/ip` is required because Openvpn does not configure PATH for Linux. Regards tct -BEGIN PGP SIGNATURE- Version

Re: [Openvpn-users] topology subnet and ifconfig-push

2021-12-01 Thread tincantech via Openvpn-users
; > dev tun0 > > server 192.168.13.0 255.255.255.0 > > and one CCD with ifconfig-push 192.168.13.5 192.168.13.6 > > the rest of the clients have empty ccd's > > I read that default topology is going away soon, so I wanted to switch to > subnet, and I did exactly as writ

Re: [Openvpn-users] (no subject)

2021-12-02 Thread tincantech via Openvpn-users
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Hi, ‐‐‐ Original Message ‐‐‐ On Thursday, December 2nd, 2021 at 22:44, Stella Ashburne wrote: > Hi Gert > > Thanks for your reply. > > > OK. I surfed to https://build.openvpn.net/man/openvpn-2.5/openvpn.8.html >

Re: [Openvpn-users] (no subject)

2021-12-02 Thread tincantech via Openvpn-users
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Hi, ‐‐‐ Original Message ‐‐‐ On Friday, December 3rd, 2021 at 05:49, Nathan Stratton Treadway wrote: > On Thu, Dec 02, 2021 at 23:42:04 +, tincantech via Openvpn-users wrote: > > > On Thursday, December 2nd, 2021 at 2

Re: [Openvpn-users] [ext] (no subject)

2021-12-03 Thread Hans via Openvpn-users
From: "Stella Ashburne" mailto:rewe...@gmx.com>> Date: Thursday, 2 December 2021 at 17:15:23 To: "openvpn-users@lists.sourceforge.net" mailto:openvpn-users@lists.sourceforge.net>> Subject: Re: [Openvpn-users] [ext] (no subject No, I don't have access to th

Re: [Openvpn-users] replay warnings not muted?

2021-12-07 Thread tincantech via Openvpn-users
c 6 08:39:58 xxx01 openvpn[2542576]: /xx.xx.xx.xx:38581 PID_ERR replay > [32] [SSL-0] [] 0:40 0:8 > t=1638776398[0] r=[0,64,15,32,1] sl=[2 > > 4,40,64,528] I believe the reason is, the message above is a "Packet-ID Error", which --mute-

Re: [Openvpn-users] replay warnings not muted?

2021-12-08 Thread tincantech via Openvpn-users
t; > On Tuesday, December 7th, 2021 at 08:55, Aleksandar Ivanisevic > > aleksan...@ivanisevic.de wrote: > > > > > Hi, > > > > > > I still see this in the server log, although I have mute-replay-warnings > > > in the server conf. > > >

Re: [Openvpn-users] OpenVPN 2.5.5 released

2021-12-15 Thread tincantech via Openvpn-users
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 It seems only fair to warn the OpenVPN community that Version 2.5.5 has had bugs identified. A new release v2.5.6 is planned for the coming week, or so.. Regards Richard Sent with ProtonMail Secure Email. ‐‐‐ Original Message ‐‐‐ On

Re: [Openvpn-users] OpenVPN 2.5.5 released

2021-12-15 Thread tincantech via Openvpn-users
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Seems I was too hasty here. OpenVPN 2.5.5 is the current release and there are no bugs severe enough to warrant a version 2.5.6, at this time. Sorry for the confusion. Regards Richard Sent with ProtonMail Secure Email. ‐‐‐ Original Message

Re: [Openvpn-users] LAN-LAN connection via ASUS Router OpenVPN?

2022-01-15 Thread tincantech via Openvpn-users
r > manual/support channel for the specifics of your router. > > However, from the server config you posted, two notes: > > 1. It is likely that the "Custom Configuration" is where you will need to > add the openvpn --iroute in a client-config-file. > 2. Yes, your server

Re: [Openvpn-users] LAN-LAN connection via ASUS Router OpenVPN?

2022-01-15 Thread tincantech via Openvpn-users
I have my main > inbound > > OpenVPN server. Been running it for years now and it is quite reliable. > Everything here is good, except for the inclusion of compression. See: https://community.openvpn.net/openvpn/wiki/Compression In future, Openvpn intend to remove all compression but

Re: [Openvpn-users] How to modify old OpenVPN installation to new way of operation?

2022-01-16 Thread tincantech via Openvpn-users
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Some help found here: https://github.com/OpenVPN/openvpn/blob/master/distro/systemd/README.systemd https://community.openvpn.net/openvpn/wiki/OpenVPN-systemd-use To get started.. -BEGIN PGP SIGNATURE- Version: ProtonMail

Re: [Openvpn-users] How to modify old OpenVPN installation to new way of operation?

2022-01-17 Thread tincantech via Openvpn-users
signature _______ Openvpn-users mailing list Openvpn-users@lists.sourceforge.net https://lists.sourceforge.net/lists/listinfo/openvpn-users

Re: [Openvpn-users] How to modify old OpenVPN installation to new way of operation?

2022-01-17 Thread tincantech via Openvpn-users
O2 -END PGP SIGNATURE- publickey - tincantech@protonmail.com - 0x09BC3D44.asc Description: application/pgp-keys publickey - tincantech@protonmail.com - 0x09BC3D44.asc.sig Description: PGP signature _______ Openvpn-users mailing list Openvpn-users@li

[Openvpn-users] dual gateway - which openvpn server must use - ?

2022-01-26 Thread lejeczek via Openvpn-users
TLS handshake failed 10.1.3.144:39293 SIGUSR1[soft,tls-error] received, client-instance restarting ... many thanks, L. ___________ Openvpn-users mailing list Openvpn-users@lists.sourceforge.net https://lists.sourceforge.net/lists/listinfo/openvpn-users

Re: [Openvpn-users] dual gateway - which openvpn server must use - ?

2022-01-26 Thread lejeczek via Openvpn-users
On 26/01/2022 13:27, Gert Doering wrote: Hi, On Wed, Jan 26, 2022 at 01:16:44PM +, lejeczek via Openvpn-users wrote: I have a box which has two gateways: -> $ ip ro default via 10.0.16.1 dev eth2 proto static metric 99 default via 10.0.0.1 dev eth0 proto static metric 100 .. With use

Re: [Openvpn-users] services on vpn server and client

2022-01-28 Thread tincantech via Openvpn-users
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Hi, Sent with ProtonMail Secure Email. ‐‐‐ Original Message ‐‐‐ On Friday, January 28th, 2022 at 14:10, openvpn wrote: > Hi folks :-) > > I've my office lan with one server (1) linux lamp 192.168.1.100 and wan > >

Re: [Openvpn-users] Expected transfer speed LAN-LAN using OpenVPN?

2022-01-30 Thread tincantech via Openvpn-users
, Bo Berglund wrote: > Bo Berglund > > Developer in Sweden > > Openvpn-users mailing list > > Openvpn-users@lists.sourceforge.net > > https://lists.sourceforge.net/lists/listinfo/openvpn-users -BEGIN PGP SIGNATURE- Version: ProtonMail

Re: [Openvpn-users] Expected transfer speed LAN-LAN using OpenVPN?

2022-02-20 Thread tincantech via Openvpn-users
manual. > > Sent with ProtonMail Secure Email. > > --- Original Message --- > > On Sunday, February 20th, 2022 at 22:23, Bo Berglund bo.bergl...@gmail.com > wrote: > > > On Sun, 20 Feb 2022 21:51:20 +, tincantech via Openvpn-users > > > > openvpn-users@

Re: [Openvpn-users] Expected transfer speed LAN-LAN using OpenVPN?

2022-02-21 Thread André via Openvpn-users
Hi, According to "RMerlin Asuswrt-Merlin dev" the Asus RT-AC-86U can "hit 200 Mbps of OpenVPN throughput". "LouisvilleUK" states "I'm getting full 200 down throughput with PrivateTunnel VPN using AES-128-GCM on the RT-AC86U". https://www.snbfor

[Openvpn-users] OpenVPN Bridge log IPs

2022-03-16 Thread dashdruid via Openvpn-users
Hello, This is an example output for OpenVPN with verb 3 logging: 18:58:39+01:00 server : client1/7.7.7.7:5111 MULTI: Learn: 46:73:8a:e7:e6:b4 -> client1/7.7.7.7:5111 18:58:39+01:00 server : client1/7.7.7.7:5111 MULTI: Learn: 21:ba:ed:15:65:7e -> client1/7.7.7.7:5111 18:58:39+01:00

Re: [Openvpn-users] Request .deb package of OpenVPN 2.5.6

2022-03-18 Thread André via Openvpn-users
Hi Stella Ashburne, Regarding the link: https://community.openvpn.net/openvpn/wiki/OpenvpnSoftwareRepos Verzonden met ProtonMail beveiligde e-mail. --- Original Message --- Op vrijdag 18 maart 2022 om 02:55 schreef Stella Ashburne : > Hi Samuli > > Thank you, Samuli an

[Openvpn-users] wireguard - forward to/from

2022-04-05 Thread lejeczek via Openvpn-users
e much appreciated. many thanks, L. _______ Openvpn-users mailing list Openvpn-users@lists.sourceforge.net https://lists.sourceforge.net/lists/listinfo/openvpn-users

Re: [Openvpn-users] wireguard - forward to/from

2022-04-06 Thread lejeczek via Openvpn-users
On 05/04/2022 20:53, Gert Doering wrote: Hi, On Tue, Apr 05, 2022 at 08:33:00PM +0100, lejeczek via Openvpn-users wrote: I wonder this might be something someone sussed out already - make wg & tun "talk" to each other? Or more specifically have oVPN roadwarriors talk to Wire

Re: [Openvpn-users] OpenVPN Bridge log IPs

2022-04-08 Thread dashdruid via Openvpn-users
Hello, Yes I understand but having some patch for it which can do this would be extremely useful. I know about arpwatch and I use it on many networks but I working on a solution which parses the log files from a central openvpn tap server where multiple l2 networks are bridged together to

[Openvpn-users] Fw: OpenVPN CCD Client Advertising LAN Route to Server

2022-04-12 Thread me.meekone--- via Openvpn-users
Hi guys, I have a rather simple issue but I cannot get it working Atm I have a VPS acting as the OpenVPN server and a OpenVPN client running on my home lan All works well and the VPN is solid until I’m advertising the home lan (10.10.10.0/24) from my raspi The VPN drops when I’m adding the

[Openvpn-users] Openvpn Client Advertising /24 LAN network

2022-04-14 Thread me.meekone--- via Openvpn-users
om/raw/cUtnDgg0Best Regards, Stefan___ Openvpn-users mailing list Openvpn-users@lists.sourceforge.net https://lists.sourceforge.net/lists/listinfo/openvpn-users

Re: [Openvpn-users] Authenticate/Decrypt packet error: bad packet ID (may be a replay)

2022-04-19 Thread tincantech via Openvpn-users
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Hi, --- Original Message --- On Thursday, April 14th, 2022 at 08:09, Ml Ml via Openvpn-users wrote: > Hello, > > from time to time i get flooded this in my Logs: > > 2022-04-14T07:28:28 Error openvpn Authenticate/Decry

Re: [Openvpn-users] How do I prevent IPv6 routes from being added to my connection?

2022-04-29 Thread tincantech via Openvpn-users
nnDTUlAxSzbmanBw/uQOTk5KPYY037AnQACAFX7wQpGcUt+g== =scvm -END PGP SIGNATURE- publickey - tincantech@protonmail.com - 0x09BC3D44.asc Description: application/pgp-keys publickey - tincantech@protonmail.com - 0x09BC3D44.asc.sig Description: PGP signature ___ Openvpn-us

Re: [Openvpn-users] How do I prevent IPv6 routes from being added to my connection?

2022-04-29 Thread André via Openvpn-users
f my parole? > > It's none of your business why someone might want to use the tool in > this way. Can you do it or not? > > That's the only question you're being asked. > > It's super annoying to see this kind of behavior. > > /jordan > > &

Re: [Openvpn-users] How do I prevent IPv6 routes from being added to my connection?

2022-04-30 Thread tincantech via Openvpn-users
28 20:23:17 MANAGEMENT: > >STATE:1651321397,ASSIGN_IP,,10.5.0.3,fdda:d0d0:cafe:443::1001 > > 2022-04-28 20:23:17 IPv4 MTU set to 1500 on interface 20 using service > 2022-04-28 20:23:17 INET6 address service: add fdda:d0d0:cafe:443::1001/128 > 2022-04-28 20:23:17 add_rout

Re: [Openvpn-users] UDPv4 link local?

2022-06-04 Thread tincantech via Openvpn-users
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Hi, Sent with Proton Mail secure email. --- Original Message --- On Saturday, June 4th, 2022 at 16:02, Matthew Guberman-Pfeffer wrote: > Dear OpenVPN community, > I'm trying to setup a VPN on a linux computer that I log i

Re: [Openvpn-users] UDPv4 link local?

2022-06-04 Thread tincantech via Openvpn-users
Guberman-Pfeffer wrote: > I found the below, but I’m not sure if this is anymore helpful for resolving > my problem. > > OpenVPN 2.4.3 x86_64-suse-linux-gnu [SSL (OpenSSL)] [LZO] [LZ4] [EPOLL] > [PKCS11] [MH/PKTINFO] [AEAD] built on Jun 20 2017 > library versions: OpenSSL 1.1.0

Re: [Openvpn-users] CA private key: password vs. passphrase?

2022-06-08 Thread tincantech via Openvpn-users
ntech@protonmail.com - 0x09BC3D44.asc Description: application/pgp-keys publickey - tincantech@protonmail.com - 0x09BC3D44.asc.sig Description: PGP signature ___ Openvpn-users mailing list Openvpn-users@lists.sourceforge.net https://lists.sourceforge.net/lists/listinfo/openvpn-users

Re: [Openvpn-users] CA private key: password vs. passphrase?

2022-06-08 Thread tincantech via Openvpn-users
passwords/phrases are known as "PEM passphrases". > > > > HTH > > > -- > Fabio@Ticinocom > > -- > Lampo@Gmail -BEGIN PGP SIGNATURE- Version: ProtonMail wsBzBAEBCAAGBQJioQHwACEJEE+XnPZrkLidFiEECbw9RGejjXJ5xVVVT5ec 9muQuJ3dTgf8DGnBZtFTY/+ciGRJkwTWUWozxnTMLG6pRQUPTq7

Re: [Openvpn-users] CA private key: password vs. passphrase?

2022-06-08 Thread tincantech via Openvpn-users
== =KGjd -END PGP SIGNATURE- publickey - tincantech@protonmail.com - 0x09BC3D44.asc Description: application/pgp-keys publickey - tincantech@protonmail.com - 0x09BC3D44.asc.sig Description: PGP signature ___ Openvpn-users mailing list Openvpn

Re: [Openvpn-users] CA private key: password vs. passphrase?

2022-06-09 Thread tincantech via Openvpn-users
jmOOZ3mSWl Xu7Lo/1lq02/TPCYNsaqYztgxtB3DooAlFykiWtUUctuuQh9L7R0WOpI2n4j gVXlC/9FgSbePl0aoboCuxZpXznKtY5WheMjZOq+Xroj3VvS8cSiOmf1HDdS euoauW9COuc2Ita5AtvPg+juj4JFS0w13/4JJ97MiwGosurShTl6lVgxeadT yK64x/jtxI+3rpln3V0dV+GhU819CUqxAsEOTsqWIm9sq6TELfP+3w== =Qvm6 -END PGP SIGNATURE- publickey - tincantech@protonmail.com - 0x09BC3D44.asc Description: application/pgp-keys publickey - tincantech@protonmail.com - 0x09BC3D44.asc.sig Description: PGP signature ___ Openvpn-users mailing list Openvpn-users@lists.sourceforge.net https://lists.sourceforge.net/lists/listinfo/openvpn-users

Re: [Openvpn-users] CA private key: password vs. passphrase?

2022-06-09 Thread tincantech via Openvpn-users
nt-full' does not ask for it. > Yes it does. I am not prepared to continue with this dialogue because you do not copy the openvpn-users mailing list. Along with numerous other reasons .. I suggest you read the help. EG: `easyrsa help` -- -BEGIN PGP SIGNATURE- Versio

Re: [Openvpn-users] How to enable timestamps in server logfile?

2022-06-15 Thread tincantech via Openvpn-users
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Hi, this is a setting in the openvpn systemd unit file. The setting to remove is --suppress-timestamps from the 'ExecStart=' line. Regards Sent with Proton Mail secure email. --- Original Message --- On Wednesday, June 15th,

Re: [Openvpn-users] How to enable timestamps in server logfile?

2022-06-15 Thread tincantech via Openvpn-users
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Hi, alternatively, you can view the log file with `journalctl`. This will then include timestamps from the journal. Something like `journalctl -u openvpn-server01` Regards Sent with Proton Mail secure email. --- Original Message --- On

Re: [Openvpn-users] How to enable timestamps in server logfile?

2022-06-18 Thread tincantech via Openvpn-users
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Hi, --- Original Message --- On Saturday, June 18th, 2022 at 09:26, Bo Berglund wrote: > The way I did that: > > 1) sudo systemctl stop openvpn > sudo systemctl stop openvpn@server.service > sudo systemc

Re: [Openvpn-users] How to enable timestamps in server logfile?

2022-06-18 Thread tincantech via Openvpn-users
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Hi, --- Original Message --- On Saturday, June 18th, 2022 at 18:03, Bo Berglund wrote: > On Sat, 18 Jun 2022 13:46:09 +, tincantech via Openvpn-users > openvpn-users@lists.sourceforge.net wrote: > > > -BEGIN PGP

Re: [Openvpn-users] How to enable timestamps in server logfile?

2022-06-18 Thread tincantech via Openvpn-users
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Hi, --- Original Message --- On Saturday, June 18th, 2022 at 22:20, Bo Berglund wrote: > On Sat, 18 Jun 2022 20:01:10 +, tincantech via Openvpn-users > openvpn-users@lists.sourceforge.net wrote: > > > > > If y

Re: [Openvpn-users] How to enable timestamps in server logfile?

2022-06-19 Thread tincantech via Openvpn-users
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Hi, --- Original Message --- On Sunday, June 19th, 2022 at 06:35, Bo Berglund wrote: > On Sat, 18 Jun 2022 22:00:20 +, tincantech via Openvpn-users > openvpn-users@lists.sourceforge.net wrote: > > > You haven't

Re: [Openvpn-users] Problem with service on windows server

2022-06-27 Thread tincantech via Openvpn-users
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Hi, I must point this out: > > > > I am setting up an OpenVPN server on a windows server for a > > > > client, but ran into the problem where the openvpn service in > > > > services doesn’t pick up the conf

Re: [Openvpn-users] Problem with service on windows server

2022-06-27 Thread tincantech via Openvpn-users
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Correction: 2.5.7-I602 not 2.5.5 --- Original Message --- On Monday, June 27th, 2022 at 22:35, tincantech via Openvpn-users wrote: > Hi, > > I must point this out: > > > > > > > > I am setting up an O

Re: [Openvpn-users] Problem with service on windows server

2022-06-27 Thread tincantech via Openvpn-users
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Hi, the \\config-auto folder is only created if the 'openVPN Service' is selected *manually* during installation. However, the 'Interactive-Service' *is* installed by default. This feels *needlessly* complicated. As a long-

[Openvpn-users] Fw: Re: Problem with service on windows server

2022-06-28 Thread tincantech via Openvpn-users
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Forwarding to openvpn-devel, as requested. CC'ing -users FTR. --- Original Message --- On Tuesday, June 28th, 2022 at 02:59, Selva Nair wrote: > Hi, > > > > > > the \\config-auto folder is only created i

[Openvpn-users] Failover Openvpn

2022-08-25 Thread mensagens--- via Openvpn-users
Hi there, In this moment i have 2 machines running openvpn, in high availability with heartbeat and crm But now , I am build one new environment with openvpn, and i think would can be simplify this model. I think would be one good idea use this model, but i have questions about this

Re: [Openvpn-users] Failover Openvpn

2022-08-26 Thread Hans via Openvpn-users
server internally towards your company network. In case the different vpn-servers reside on different locations, and have nothing (!!!) in common, you can configure each vpn-server to hand-out the same IP-pool. ) From: "mensagens--- via Openvpn-users" mailto:openvpn-users@lists.sourc

Re: [Openvpn-users] How to block clients access to local LAN?

2022-09-02 Thread tincantech via Openvpn-users
.151, in total 16 addresses. > > So by using ccd on clients that are not supposed to access the LAN and give > them > an IP in that range blocks them from the LAN while still accessing the web. > > > -- > Bo Berglund > Developer in Sweden > > > > __

Re: [Openvpn-users] Commanding remote client to reconnect following server reboot?

2022-09-05 Thread tincantech via Openvpn-users
--- On Monday, September 5th, 2022 at 21:02, Bo Berglund wrote: > On Sun, 04 Sep 2022 11:33:31 +0200, Bo Berglund bo.bergl...@gmail.com wrote: > > > On Sun, 04 Sep 2022 10:42:52 +0200, Bo Berglund bo.bergl...@gmail.com wrote: > > > > > I have a number of OVPN clien

Re: [Openvpn-users] Commanding remote client to reconnect following server reboot?

2022-09-07 Thread tincantech via Openvpn-users
t have a mandatory extra charge as it is NORMAL > internet access. > Provided that the ISP does not also charge extra for IPV6. > Met vriendelijke groet, > Bonno Bloksma > > > > ___ > Openvpn-users mailing list > Op

Re: [Openvpn-users] Correct way to handle routing when on home network?

2022-09-22 Thread tincantech via Openvpn-users
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Hi, Sent with Proton Mail secure email. --- Original Message --- On Thursday, September 22nd, 2022 at 15:06, Sebastian Arcus wrote: > I use openvpn on laptops to access the vpn server and the network behind > it. When the lapto

Re: [Openvpn-users] Correct way to handle routing when on home network?

2022-09-27 Thread tincantech via Openvpn-users
> s.ar...@open-t.co.uk wrote: > > Server: openvpn 2.5.7, Linux Slackware > > Client: openvpn 2.5.7, Windows 10 > > OpenVPN server lan subnet: 192.168.112.0/24 > > OpenVPN subnet: 192.168.114.0/24 > > > > server.conf > > > > proto udp > &g

Re: [Openvpn-users] Checking server and client certificates expiration?

2022-09-28 Thread tincantech via Openvpn-users
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Hi Bo, the imminent release of Easy-RSA version 3.1.1 has tools to manage your PKI with relative ease. https://github.com/OpenVPN/easy-rsa Command `show-expire` will list your entire PKI, a subset of it or an individual certificate, at your

Re: [Openvpn-users] Checking server and client certificates expiration?

2022-09-28 Thread tincantech via Openvpn-users
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Hi, Sent with Proton Mail secure email. --- Original Message --- On Wednesday, September 28th, 2022 at 18:18, Bo Berglund wrote: > On Wed, 28 Sep 2022 16:03:11 +, tincantech via Openvpn-users > openvpn-users@lists.sourcefor

Re: [Openvpn-users] Correct way to handle routing when on home network?

2022-09-28 Thread André via Openvpn-users
g the LAN IP of the server like \\192.168.112.xx and see whether that > makes a difference? > > tcpdump could also help figure out why there are two smb streams one using > LAN IP and other using the VPN, which is carrying what traffic, which one > gets established first etc.. > > Selva___ Openvpn-users mailing list Openvpn-users@lists.sourceforge.net https://lists.sourceforge.net/lists/listinfo/openvpn-users

Re: [Openvpn-users] Dealing with CA expiration

2022-10-27 Thread tincantech via Openvpn-users
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Hi, --- Original Message --- On Thursday, October 27th, 2022 at 5:16 AM, Leroy Tennison via Openvpn-users wrote: > After 10 years this happened to us, fortunately on a small VPN.  In rushing > to get service restored, i used easy

Re: [Openvpn-users] Dealing with CA expiration

2022-10-31 Thread tincantech via Openvpn-users
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Hi Leroy, It sounds like we are, more or less, on the same page. For me, only two points remain: 1. > In case it matters, the server versions are OpenVPN 2.3.10/OpenSSL 1.0.2g It matters and, after *ten* years, it is time that you underst

Re: [Openvpn-users] 2.6rc2 server with DCO and 2.6rc2 client with DCO: not working

2023-01-18 Thread tincantech via Openvpn-users
ntech@protonmail.com - 0x09BC3D44.asc Description: application/pgp-keys publickey - tincantech@protonmail.com - 0x09BC3D44.asc.sig Description: PGP signature ___ Openvpn-users mailing list Openvpn-users@lists.sourceforge.net https://lists.sourceforg

Re: [Openvpn-users] buglet in crt_not_after computation?

2023-01-18 Thread tincantech via Openvpn-users
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Hi, EasyRSA version 3.0.x 'build-x-full' does not use date. You must be using version 3.1.x Please check which version you are using. Releases are available, please try latest: https://github.com/OpenVPN/easy-rsa/releases If t

Re: [Openvpn-users] buglet in crt_not_after computation?

2023-01-18 Thread tincantech via Openvpn-users
06:17, tincantech via Openvpn-users wrote: > Hi, > > EasyRSA version 3.0.x 'build-x-full' does not use date. > > You must be using version 3.1.x > > Please check which version you are using. > > Releases are available, please try latest: > http

Re: [Openvpn-users] buglet in crt_not_after computation?

2023-01-23 Thread tincantech via Openvpn-users
TYbqptmyOK6uaET9etcIxlpYCkFR2R7Z2cr5w== =+cRx -END PGP SIGNATURE- publickey - tincantech@protonmail.com - 0x09BC3D44.asc Description: application/pgp-keys publickey - tincantech@protonmail.com - 0x09BC3D44.asc.sig Description: PGP signature ___________

Re: [Openvpn-users] buglet in crt_not_after computation?

2023-01-23 Thread tincantech via Openvpn-users
LNwTw== =73wk -END PGP SIGNATURE- publickey - tincantech@protonmail.com - 0x09BC3D44.asc Description: application/pgp-keys publickey - tincantech@protonmail.com - 0x09BC3D44.asc.sig Description: PGP signature ___ Openvpn-users mailing list Openvpn-users@lists.sourceforge.net https://lists.sourceforge.net/lists/listinfo/openvpn-users

<    1   2   3   4   5   6   7   8   9   >