Portál AbcLinuxu, 6. května 2025 14:36
Mon Jan 31 12:13:37 2022 Attempting to establish TCP connection with [AF_INET]xxx.xxx.xxx.xxx:1194 [nonblock] Mon Jan 31 12:13:37 2022 MANAGEMENT: >STATE:1643627617,TCP_CONNECT,,,,,, Mon Jan 31 12:13:38 2022 TCP connection established with [AF_INET]xxx.xxx.xxx.xxx:1194 Mon Jan 31 12:13:38 2022 TCP_CLIENT link local: (not bound) Mon Jan 31 12:13:38 2022 TCP_CLIENT link remote: [AF_INET]xxx.xxx.xxx.xxx:1194 Mon Jan 31 12:13:38 2022 MANAGEMENT: >STATE:1643627618,WAIT,,,,,, Mon Jan 31 12:13:38 2022 MANAGEMENT: >STATE:1643627618,AUTH,,,,,, Mon Jan 31 12:13:38 2022 TLS: Initial packet from [AF_INET]xxx.xxx.xxx.xxx:1194, sid=fefa64f0 6af6217b Mon Jan 31 12:13:38 2022 VERIFY OK: depth=1, C=SK, ST=Slovakia, O=XXX, CN=CA-XXX Mon Jan 31 12:13:38 2022 VERIFY KU OK Mon Jan 31 12:13:38 2022 Validating certificate extended key usage Mon Jan 31 12:13:38 2022 ++ Certificate has EKU (str) TLS Web Server Authentication, expects TLS Web Server Authentication Mon Jan 31 12:13:38 2022 VERIFY EKU OK Mon Jan 31 12:13:38 2022 VERIFY OK: depth=0, C=SK, ST=Slovakia, O=XXX, CN=adresa.tld Mon Jan 31 12:13:38 2022 Connection reset, restarting [0] Mon Jan 31 12:13:38 2022 SIGUSR1[soft,connection-reset] received, process restarting Mon Jan 31 12:13:38 2022 MANAGEMENT: >STATE:1643627618,RECONNECTING,connection-reset,,,,, Mon Jan 31 12:13:38 2022 Restart pause, 5 second(s) Mon Jan 31 12:13:43 2022 MANAGEMENT: >STATE:1643627623,RESOLVE,,,,,, Mon Jan 31 12:13:43 2022 TCP/UDP: Preserving recently used remote address: [AF_INET]xxx.xxx.xxx.xxx:1194 Mon Jan 31 12:13:43 2022 Socket Buffers: R=[8192->8192] S=[8192->8192] Mon Jan 31 12:13:43 2022 Attempting to establish TCP connection with [AF_INET]xxx.xxx.xxx.xxx:1194 [nonblock] Mon Jan 31 12:13:43 2022 MANAGEMENT: >STATE:1643627623,TCP_CONNECT,,,,,, Mon Jan 31 12:13:44 2022 TCP connection established with [AF_INET]xxx.xxx.xxx.xxx:1194 Mon Jan 31 12:13:44 2022 TCP_CLIENT link local: (not bound) Mon Jan 31 12:13:44 2022 TCP_CLIENT link remote: [AF_INET]xxx.xxx.xxx.xxx:1194 Mon Jan 31 12:13:44 2022 MANAGEMENT: >STATE:1643627624,WAIT,,,,,, Mon Jan 31 12:13:44 2022 MANAGEMENT: >STATE:1643627624,AUTH,,,,,, Mon Jan 31 12:13:44 2022 TLS: Initial packet from [AF_INET]xxx.xxx.xxx.xxx:1194, sid=a8692c25 dde54586 Mon Jan 31 12:13:45 2022 VERIFY OK: depth=1, C=SK, ST=Slovakia, O=XXX, CN=CA-XXX Mon Jan 31 12:13:45 2022 VERIFY KU OK Mon Jan 31 12:13:45 2022 Validating certificate extended key usage Mon Jan 31 12:13:45 2022 ++ Certificate has EKU (str) TLS Web Server Authentication, expects TLS Web Server Authentication Mon Jan 31 12:13:45 2022 VERIFY EKU OK Mon Jan 31 12:13:45 2022 VERIFY OK: depth=0, C=SK, ST=Slovakia, O=XXX, CN=adresa.tld Mon Jan 31 12:13:45 2022 Connection reset, restarting [0] Mon Jan 31 12:13:45 2022 SIGUSR1[soft,connection-reset] received, process restarting Mon Jan 31 12:13:45 2022 MANAGEMENT: >STATE:1643627625,RECONNECTING,connection-reset,,,,, Mon Jan 31 12:13:45 2022 Restart pause, 5 second(s)a mikrotik pise:
12:12:28 ovpn,info TCP connection established from xx.xx.xx.xx 12:12:29 ovpn,debug,error,64748,44112,44300,43240,21920,48572,43872,44296,l2tp,info,44300,debug,update,65535,critical,62728,396,45968,update,48648,48584,2080,4043,48572,48572,62592,48572,error duplicate packet, dropping 12:12:31 ovpn,info : using encoding - AES-256-CBC/SHA1 12:12:36 ovpn,info TCP connection established from xx.xx.xx.xx 12:12:37 ovpn,debug,error,64748,44112,44300,43240,21920,48572,43872,44296,l2tp,info,44300,debug,update,65535,critical,62728,396,45968,update,48648,48584,2080,4043,48572,48572,62592,48572,error duplicate packet, dropping 12:12:37 ovpn,info : using encoding - AES-256-CBC/SHA1
client remote domena.tld 1194 auth-user-pass cipher AES-256-CBC auth sha1 dev tun proto tcp nobind auth-nocache script-security 2 persist-key persist-tun remote-cert-tls server verb 3 <ca> ... </ca> <cert> ... </cert> <key> ... </key>
/certificate add name=CA-XXX country="SK" state="Slovakia" organization="XXX" common-name=CA-XXX key-usage=key-cert-sign,crl-sign days-valid=3650 key-size=2048 /certificate sign CA-XXX ca-crl-host=domena.tld name=CA-XXX /certificate export-certificate CA-XXX /certificate set CA-XXX trusted=yes /certificate add name=OPENVPN-SERVER-tpl country="SK" state="Slovakia" organization="XXX" common-name="domena.tld" key-usage=digital-signature,key-encipherment,tls-server days-valid=3650 key-size=2048 /certificate sign OPENVPN-SERVER ca=CA-XXX name=OPENVPN-SERVER /certificate set OPENVPN-SERVER trusted=yes /certificate add name=client-tpl country="SK" state="SK" organization="XXX" common-name="client" days-valid=3650 key-size=4096 key-usage=tls-client /certificate add name=s7 copy-from="client-tpl" common-name="s7" /certificate sign s7 ca="CA-XXX" name="s7" /certificate export-certificate s7 export-passphrase=heslo /certificate set s7 trusted=yes
Tiskni
Sdílej:
ISSN 1214-1267, (c) 1999-2007 Stickfish s.r.o.