I am using OpenVPN server to access to internal network and some servers.
Clients are using laptops with Windows 10 and OpenVPN GUI (2.4.4-I601). Clients are using CA certificate, own certificate, key file and password to access to server. This configuration works fine for more than one year.
In last few weeks i am faced that some clients cant connect to server. In log i see:
Code: Select all
Tue Oct 03 08:25:03 2017 OpenVPN 2.4.4 x86_64-w64-mingw32 [SSL (OpenSSL)] [LZO] [LZ4] [PKCS11] [AEAD] built on Sep 26 2017
Tue Oct 03 08:25:03 2017 Windows version 6.2 (Windows 8 or greater) 64bit
Tue Oct 03 08:25:03 2017 library versions: OpenSSL 1.0.2l 25 May 2017, LZO 2.10
Enter Management Password:
Tue Oct 03 08:25:03 2017 MANAGEMENT: TCP Socket listening on [AF_INET]127.0.0.1:25340
Tue Oct 03 08:25:03 2017 Need hold release from management interface, waiting...
Tue Oct 03 08:25:03 2017 MANAGEMENT: Client connected from [AF_INET]127.0.0.1:25340
Tue Oct 03 08:25:04 2017 MANAGEMENT: CMD 'state on'
Tue Oct 03 08:25:04 2017 MANAGEMENT: CMD 'log all on'
Tue Oct 03 08:25:04 2017 MANAGEMENT: CMD 'echo all on'
Tue Oct 03 08:25:04 2017 MANAGEMENT: CMD 'hold off'
Tue Oct 03 08:25:04 2017 MANAGEMENT: CMD 'hold release'
Tue Oct 03 08:25:04 2017 WARNING: No server certificate verification method has been enabled. See http://openvpn.net/howto.html#mitm for more info.
Tue Oct 03 08:25:06 2017 MANAGEMENT: CMD 'password [...]'
Tue Oct 03 08:25:06 2017 MANAGEMENT: CMD '"'
I don't see any packets on client interface (TAP and physical too)
There wast any change on server or client configuration
Other clients dosnt have any issue
When i move client certificates to another client where VPN is working it will connect without any issue - so certificate is not demaged
I tried to reinstall OpenVPN gui to older version, newest version - no change
I tried to reinstall last windows update - no change
I tried to update windows latest version - no change
I tried to run Windows in Safe mode and run OpenVPN - no change
I am running OpenVPN like administartor.
Can you please give me some advice's what should i change in client configuration?
Thank you,
MEG