Re: [Openvpn-users] TLS key negotiation failed to occur ISP screws up the VPN

2024-05-20 Thread Gert Doering
Hi, On Mon, May 20, 2024 at 05:31:40AM +, shadowbladeee via Openvpn-users wrote: > Listen phal I been in IT since 15 years you can go on all day > long with this restart this restart that stuff but 99.99% of the > time if there is a working system there is a clear reason why that > stops

Re: [Openvpn-users] TLS key negotiation failed to occur ISP screws up the VPN

2024-05-19 Thread shadowbladeee via Openvpn-users
YEss please do NOT, exactly what I wanted to say ;) Listen phal I been in IT since 15 years you can go on all day long with this restart this restart that stuff but 99.99% of the time if there is a working system there is a clear reason why that stops functioning and if the reason is not

Re: [Openvpn-users] TLS key negotiation failed to occur ISP screws up the VPN

2024-05-18 Thread Selva Nair
On Sat, May 18, 2024 at 12:00 PM Bo Berglund wrote: > On Sat, 18 May 2024 11:22:37 +0200, Gert Doering > wrote: > > >Since you do not want to hear that, we won't tell you that 2.4.0 is > >8 years old, and a zillion improvements went into what is now 2.6.10, > > Just curious: > I am running

Re: [Openvpn-users] TLS key negotiation failed to occur ISP screws up the VPN

2024-05-18 Thread Selva Nair
> > > > This node where the logs were from (server): > OpenVPN 2.4.7 arm-unknown-linux-gnueabihf [SSL (OpenSSL)] [LZO] [LZ4] > [EPOLL] [PKCS11] [MH/PKTINFO] [AEAD] built on Feb 20 2019 > > Other (client) > OpenVPN 2.4.0 arm-unknown-linux-gnueabihf [SSL (OpenSSL)] [LZO] [LZ4] > [EPOLL] [PKCS11]

Re: [Openvpn-users] TLS key negotiation failed to occur ISP screws up the VPN

2024-05-18 Thread Bo Berglund
On Sat, 18 May 2024 11:22:37 +0200, Gert Doering wrote: >Since you do not want to hear that, we won't tell you that 2.4.0 is >8 years old, and a zillion improvements went into what is now 2.6.10, Just curious: I am running openvpn server on an Ubuntu 22.04.4 LTS and here is what I get from

Re: [Openvpn-users] TLS key negotiation failed to occur ISP screws up the VPN

2024-05-18 Thread Gert Doering
Hi, On Sat, May 18, 2024 at 08:05:33AM +, shadowbladeee via Openvpn-users wrote: > OpenVPN 2.4.7 arm-unknown-linux-gnueabihf [SSL (OpenSSL)] [LZO] [LZ4] [EPOLL] > [PKCS11] [MH/PKTINFO] [AEAD] built on Feb 20 2019 > OpenVPN 2.4.0 arm-unknown-linux-gnueabihf [SSL (OpenSSL)] [LZO] [LZ4] [EPOLL]

Re: [Openvpn-users] TLS key negotiation failed to occur ISP screws up the VPN

2024-05-18 Thread shadowbladeee via Openvpn-users
Hello, I can even send data on that udp port with netcat between the two like: netcat -ul 43000 ewqeqw kek lel test dah This node where the logs were from (server): OpenVPN 2.4.7 arm-unknown-linux-gnueabihf [SSL (OpenSSL)] [LZO] [LZ4] [EPOLL] [PKCS11] [MH/PKTINFO] [AEAD] built on Feb 20 2019

Re: [Openvpn-users] TLS key negotiation failed to occur ISP screws up the VPN

2024-05-17 Thread Selva Nair
Hi, > Fri May 17 13:23:15 2024 us=936860 SIGUSR1[soft,tls-error] received, process restarting > Fri May 17 13:23:15 2024 us=937343 Restart pause, 300 second(s) If this is the tls-server side of the p2p connection, this is weird. What version of OpenVPN is this? We fixed the backoff logic in

Re: [Openvpn-users] TLS key negotiation failed to occur ISP screws up the VPN

2024-05-17 Thread shadowbladeee via Openvpn-users
Nope and btw OpenVPN does not care about the CRL unless you specifically define it in the config. I even use the same CA, client cert as on the other openvpn node on this host on other port so even that issue is excluded. The fact that it worked for years and now misbehaves with no reason the

Re: [Openvpn-users] TLS key negotiation failed to occur ISP screws up the VPN

2024-05-17 Thread Jochen Bern
On 17.05.24 15:49, shadowbladeee via Openvpn-users wrote: Time is correct on the machines, certs expire in 2049. Any *CRLs* that might have expired? I note that the tcpdump shows only quite *small* packets. MTU issues that could lead to (persistent) loss of large ones from the other end?

Re: [Openvpn-users] TLS key negotiation failed to occur ISP screws up the VPN

2024-05-17 Thread Antonio Quartulli
On 17/05/2024 15:49, shadowbladeee wrote: Dude why do you say it is not responding when it clearly is both on the log file and tcpdump? Meh. You're right. I managed to fool myself. To make it even more annoying there is another point to point tunnel terminated there same udp on a different

Re: [Openvpn-users] TLS key negotiation failed to occur ISP screws up the VPN

2024-05-17 Thread shadowbladeee via Openvpn-users
Dude why do you say it is not responding when it clearly is both on the log file and tcpdump? WRWrrRWWRWrWRWFri May 17 15:42:17 2024 us=59314 TLS Error: TLS key negotiation failed to occur within 60 seconds (check your network connectivity) Isn't that r read

Re: [Openvpn-users] TLS key negotiation failed to occur ISP screws up the VPN

2024-05-17 Thread Antonio Quartulli
Hi, On 17/05/2024 14:12, shadowbladeee via Openvpn-users wrote: So here is what is interesting, packets are "sipping in" so you cannot say it's a firewall issue, especially as I said nothing changed from my side and all the components were even rebooted. Here is what I tried: 1, tried to

[Openvpn-users] TLS key negotiation failed to occur ISP screws up the VPN

2024-05-17 Thread shadowbladeee via Openvpn-users
Hello Folks, I have a VPN setup which works since years it's a simple peer to peer udp VPN. There was absolute zero change on the two endpoints, nothing on the routers, network equipment, servers etc. The VPN simply stopped functioning like a week ago with no reason. I have pretty much