OpenVPN DDWRT TLS Key Negotiaion Failed

Need help configuring your VPN? Just post here and you'll get that help.

Moderators: TinCanTech, TinCanTech, TinCanTech, TinCanTech, TinCanTech, TinCanTech

Forum rules
Please use the [oconf] BB tag for openvpn Configurations. See viewtopic.php?f=30&t=21589 for an example.
Post Reply
anthonywkho
OpenVpn Newbie
Posts: 3
Joined: Mon Jul 31, 2017 12:23 am

OpenVPN DDWRT TLS Key Negotiaion Failed

Post by anthonywkho » Mon Jul 31, 2017 2:07 am

Hi, I have a problem in connecting to a DDWRT flashed router via Openvpn (using a client of windows 10 machine), the client log is as follows and can anyone help? I researched a lot and tried most of the stuff suggested by people but still does not work. So your help is much appreciated.

Mon Jul 31 09:53:53 2017 OpenVPN 2.4.3 x86_64-w64-mingw32 [SSL (OpenSSL)] [LZO] [LZ4] [PKCS11] [AEAD] built on Jul 14 2017
Mon Jul 31 09:53:53 2017 Windows version 6.2 (Windows 8 or greater) 64bit
Mon Jul 31 09:53:53 2017 library versions: OpenSSL 1.0.2l 25 May 2017, LZO 2.10
Mon Jul 31 09:53:53 2017 MANAGEMENT: TCP Socket listening on [AF_INET]127.0.0.1:25341
Mon Jul 31 09:53:53 2017 Need hold release from management interface, waiting...
Mon Jul 31 09:53:54 2017 MANAGEMENT: Client connected from [AF_INET]127.0.0.1:25341
Mon Jul 31 09:53:54 2017 MANAGEMENT: CMD 'state on'
Mon Jul 31 09:53:54 2017 MANAGEMENT: CMD 'log all on'
Mon Jul 31 09:53:54 2017 MANAGEMENT: CMD 'echo all on'
Mon Jul 31 09:53:54 2017 MANAGEMENT: CMD 'hold off'
Mon Jul 31 09:53:54 2017 MANAGEMENT: CMD 'hold release'
Mon Jul 31 09:53:54 2017 Outgoing Control Channel Authentication: Using 160 bit message hash 'SHA1' for HMAC authentication
Mon Jul 31 09:53:54 2017 Incoming Control Channel Authentication: Using 160 bit message hash 'SHA1' for HMAC authentication
Mon Jul 31 09:53:54 2017 MANAGEMENT: >STATE:1501466034,RESOLVE,,,,,,
Mon Jul 31 09:53:54 2017 TCP/UDP: Preserving recently used remote address: [AF_INET]xx.xx.xx.xx:1194
Mon Jul 31 09:53:54 2017 Socket Buffers: R=[65536->65536] S=[65536->65536]
Mon Jul 31 09:53:54 2017 UDP link local: (not bound)
Mon Jul 31 09:53:54 2017 UDP link remote: [AF_INET]xx.xx.xx.xx:1194
Mon Jul 31 09:53:54 2017 MANAGEMENT: >STATE:1501466034,WAIT,,,,,,
Mon Jul 31 09:54:55 2017 TLS Error: TLS key negotiation failed to occur within 60 seconds (check your network connectivity)
Mon Jul 31 09:54:55 2017 TLS Error: TLS handshake failed
Mon Jul 31 09:54:55 2017 SIGUSR1[soft,tls-error] received, process restarting
Mon Jul 31 09:54:55 2017 MANAGEMENT: >STATE:1501466095,RECONNECTING,tls-error,,,,,
Mon Jul 31 09:54:55 2017 Restart pause, 5 second(s)
Mon Jul 31 09:55:00 2017 MANAGEMENT: >STATE:1501466100,RESOLVE,,,,,,
Mon Jul 31 09:55:00 2017 TCP/UDP: Preserving recently used remote address: [AF_INET]xx.xx.xx.xx:1194
Mon Jul 31 09:55:00 2017 Socket Buffers: R=[65536->65536] S=[65536->65536]
Mon Jul 31 09:55:00 2017 UDP link local: (not bound)
Mon Jul 31 09:55:00 2017 UDP link remote: [AF_INET]xx.xx.xx.xx:1194
Mon Jul 31 09:55:00 2017 MANAGEMENT: >STATE:1501466100,WAIT,,,,,,
Mon Jul 31 09:56:00 2017 TLS Error: TLS key negotiation failed to occur within 60 seconds (check your network connectivity)
Mon Jul 31 09:56:00 2017 TLS Error: TLS handshake failed
Mon Jul 31 09:56:00 2017 SIGUSR1[soft,tls-error] received, process restarting
Mon Jul 31 09:56:00 2017 MANAGEMENT: >STATE:1501466160,RECONNECTING,tls-error,,,,,
Mon Jul 31 09:56:00 2017 Restart pause, 5 second(s)

On the DD WRT (server), I have already changed the private IP subnet to 10.8.0.0 and also I copied the ta.key file content onto the section of TLS Auth (is it correct)? In the client.ovpn, i can see the line tls-auth ta.key 1 do i have to add tls-auth ta.key 0 in the router section as well?

I am quite tired in trying to get openvpn work but it took me too much time but I don't want to give up after spending so much time already.
Thanks

Post Reply