OpenVpn's enabled on my server, and I took the CA certificate to make the authority:
Wasn't working if I didn't put in a password, so have a password set for the user. Yes, I'm putting it in correctly.
From OpenVpn client on router (note: I'm masking my ip on purpose):
Code: Select all
Nov 17 14:58:12 openvpn 17334 NOTE: the current --script-security setting may allow this configuration to call user-defined scripts
Nov 17 14:58:12 openvpn 17334 WARNING: experimental option --capath /var/etc/openvpn/client3/ca
Nov 17 14:58:17 openvpn 17334 TCP/UDP: Preserving recently used remote address: [AF_INET]****:1194
Nov 17 14:58:17 openvpn 17334 UDPv4 link local (bound): [AF_INET]****:0
Nov 17 14:58:17 openvpn 17334 UDPv4 link remote: [AF_INET]****:1194
Nov 17 14:58:17 openvpn 17334 WARNING: this configuration may cache passwords in memory -- use the auth-nocache option to prevent this
Nov 17 14:58:17 openvpn 17334 [ip-172-31-23-232.ec2.internal] Peer Connection Initiated with [AF_INET]****:1194
Nov 17 14:58:24 openvpn 17334 AUTH: Received control message: AUTH_FAILED
Nov 17 14:58:24 openvpn 17334 SIGUSR1[soft,auth-failure] received, process restarting
Nov 17 14:58:34 openvpn 17334 NOTE: the current --script-security setting may allow this configuration to call user-defined scripts
Nov 17 14:58:34 openvpn 17334 TCP/UDP: Preserving recently used remote address: [AF_INET]****:1194
Nov 17 14:58:34 openvpn 17334 UDPv4 link local (bound): [AF_INET]****:0
Nov 17 14:58:34 openvpn 17334 UDPv4 link remote: [AF_INET]****:1194
Nov 17 14:58:34 openvpn 17334 [ip-172-31-23-232.ec2.internal] Peer Connection Initiated with [AF_INET]****:1194
Nov 17 14:58:40 openvpn 17334 AUTH: Received control message: AUTH_FAILED
Nov 17 14:58:40 openvpn 17334 SIGUSR1[soft,auth-failure] received, process restarting
Nov 17 14:58:50 openvpn 17334 NOTE: the current --script-security setting may allow this configuration to call user-defined scripts
Nov 17 14:58:50 openvpn 17334 TCP/UDP: Preserving recently used remote address: [AF_INET]****:1194
Nov 17 14:58:50 openvpn 17334 UDPv4 link local (bound): [AF_INET]****:0
Nov 17 14:58:50 openvpn 17334 UDPv4 link remote: [AF_INET]****:1194
Nov 17 14:58:50 openvpn 17334 [ip-172-31-23-232.ec2.internal] Peer Connection Initiated with [AF_INET]****:1194
Nov 17 14:58:56 openvpn 17334 AUTH: Received control message: AUTH_FAILED
Nov 17 14:58:56 openvpn 17334 SIGUSR1[soft,auth-failure] received, process restarting
Nov 17 14:59:06 openvpn 17334 NOTE: the current --script-security setting may allow this configuration to call user-defined scripts
Nov 17 14:59:06 openvpn 17334 TCP/UDP: Preserving recently used remote address: [AF_INET]****:1194
Nov 17 14:59:06 openvpn 17334 UDPv4 link local (bound): [AF_INET]****:0
Nov 17 14:59:06 openvpn 17334 UDPv4 link remote: [AF_INET]****:1194
Nov 17 14:59:06 openvpn 17334 [ip-172-31-23-232.ec2.internal] Peer Connection Initiated with [AF_INET]****:1194
Nov 17 14:59:12 openvpn 17334 AUTH: Received control message: AUTH_FAILED
Nov 17 14:59:12 openvpn 17334 SIGUSR1[soft,auth-failure] received, process restarting
Nov 17 14:59:20 openvpn 17334 SIGTERM[hard,init_instance] received, process exiting
Code: Select all
2023-11-17 20:59:58.834 OpenVPN Session 7 (****:51767 -> Channel 0: Option Strings Received: "V4,dev-type tun,link-mtu 1557,tun-mtu 1500,proto UDPv4,cipher AES-128-CBC,auth SHA1,keysize 128,key-method 2,tls-client"
2023-11-17 20:59:58.834 OpenVPN Session 7 (****:51767 -> Channel 0: Client certificate is not provided, will use password authentication.
2023-11-17 20:59:58.834 OpenVPN Session 7 (****:51767 -> Channel 0: Option Strings to Send: "V4,dev-type tun,link-mtu 1557,tun-mtu 1500,proto UDPv4,cipher AES-128-CBC,auth SHA1,keysize 128,key-method 2,tls-server"
2023-11-17 21:00:00.063 On the TCP Listener (Port 0), a Client (IP address ****, Host name "****", Port number 51767) has connected.
2023-11-17 21:00:00.063 For the client (IP address: ****, host name: "****", port number: 51767), connection "CID-9" has been created.
2023-11-17 21:00:00.063 SSL communication for connection "CID-9" has been started. The encryption algorithm name is "(null)".
2023-11-17 21:00:00.063 [HUB "DEFAULT"] The connection "CID-9" (IP address: ****, Host name: ****, Port number: 51767, Client name: "OpenVPN Client", Version: 4.43, Build: 9799) is attempting to connect to the Virtual Hub. The auth type provided is "External server authentication" and the user name is "remote".
2023-11-17 21:00:00.063 [HUB "DEFAULT"] Connection "CID-9": Successfully authenticated as user "remote".
2023-11-17 21:00:00.063 [HUB "DEFAULT"] Connection "CID-9": The new session "SID-REMOTE-[OPENVPN_L3]-7" has been created. (IP address: ****, Port number: 51767, Physical underlying protocol: "Legacy VPN - OPENVPN_L3")
2023-11-17 21:00:00.063 [HUB "DEFAULT"] Session "SID-REMOTE-[OPENVPN_L3]-7": The parameter has been set. Max number of TCP connections: 1, Use of encryption: Yes, Use of compression: No, Use of Half duplex communication: No, Timeout: 20 seconds.
2023-11-17 21:00:00.063 [HUB "DEFAULT"] Session "SID-REMOTE-[OPENVPN_L3]-7": VPN Client details: (Client product name: "OpenVPN Client", Client version: 443, Client build number: 9799, Server product name: "SoftEther VPN Server (64 bit)", Server version: 443, Server build number: 9799, Client OS name: "OpenVPN Client", Client OS version: "-", Client product ID: "-", Client host name: "", Client IP address: "****", Client port number: 51767, Server host name: "", Server IP address: "", Server port number: 1194, Proxy host name: "", Proxy IP address: "", Proxy port number: 0, Virtual Hub name: "DEFAULT", Client unique ID: "43BA60E4B15A865A62DD2A5991C6C7F1")
2023-11-17 21:00:05.067 OpenVPN Session 7 (****:51767 -> Channel 0: Acquiring an IP address from the DHCP server failed. To accept a PPP session, you need to have a DHCP server. Make sure that a DHCP server is working normally in the Ethernet segment which the Virtual Hub belongs to. If you do not have a DHCP server, you can use the Virtual DHCP function of the SecureNAT on the Virtual Hub instead.
2023-11-17 21:00:05.067 OpenVPN Session 7 (****:51767 -> Channel 0: Failed to connect a channel.
2023-11-17 21:00:05.321 [HUB "DEFAULT"] Session "SID-REMOTE-[OPENVPN_L3]-7": The session has been terminated. The statistical information is as follows: Total outgoing data size: 0 bytes, Total incoming data size: 1276 bytes.
2023-11-17 21:00:05.341 Connection "CID-9" terminated by the cause "The VPN session has been deleted. It is possible that either the administrator disconnected the session or the connection from the client to the VPN Server has been disconnected." (code 11).
2023-11-17 21:00:05.341 Connection "CID-9" has been terminated.
2023-11-17 21:00:05.341 The connection with the client (IP address ****, Port number 51767) has been disconnected.
Code: Select all
vpncmd command - SoftEther VPN Command Line Management Utility
SoftEther VPN Command Line Management Utility (vpncmd command)
Version 4.43 Build 9799 (English)
Compiled 2023/08/31 10:50:49 by buildsan at crosswin with OpenSSL 3.0.9
Copyright (c) 2012-2023 SoftEther VPN Project. All Rights Reserved.
Connection has been established with VPN Server "" (port 5555).
You have administrator privileges for the entire VPN Server.
VPN Server>hub default
Hub command - Select Virtual Hub to Manage
The Virtual Hub "DEFAULT" has been selected.
The command completed successfully.
VPN Server/DEFAULT>natget
NatGet command - Get Virtual NAT Function Setting of SecureNAT Function
Item |Value
Use Virtual NAT Function |Yes
MTU Value |1500
TCP Session Timeout (Seconds) |1800
UDP Session Timeout (Seconds) |60
Save NAT and DHCP Operation Log|Yes
The command completed successfully.
VPN Server/DEFAULT>dhcpget
DhcpGet command - Get Virtual DHCP Server Function Setting of SecureNAT Function
Item |Value
Use Virtual DHCP Function |Yes
Start Distribution Address Band|
End Distribution Address Band |
Subnet Mask |
Lease Limit (Seconds) |7200
Default Gateway Address |None
DNS Server Address 1 |
DNS Server Address 2 |
Domain Name |
Save NAT and DHCP Operation Log|Yes
Static Routing Table to Push |
The command completed successfully.