OpenVPN in Windows 8 consumer preview
Posted: Wed Mar 07, 2012 4:11 pm
Hello
I know this is a problem which was often diskussed on this forum. It is the problem with openvpn not be able to configure the tap adapter. With openvpn-2.2.2 I was happy to see, that the problem is solved for windows 7. It works great! With 2.1 the problem appeared mostly after a power resume (after standby).
Now I did some tests with the Windows 8 consumer preview. Sure this version is not yet released. But unfortunately the problem seems to be back. And in my opinion it is much worse.
I tried already with all the workarounds with route-delay options , route-method, TAP adaptor reset, tap-sleep, ip-win32 netsh, ...
Sometimes it is working good and then another time it absolutely won't configure the tap adapter (especially after a reboot).
I tried as well with openvpn-2.3-alpha1, but it doesn't change anything.
Did you notify already this problem? At the moment it is not a big issue as Windows 8 is not yet released. Has anyone an idea, why it is bad again?
Here the log output:
Fri Mar 02 12:51:13 2012 us=750000 Current Parameter Settings:
Fri Mar 02 12:51:13 2012 us=750000 config = 'sophiaconfig.ovpn'
Fri Mar 02 12:51:13 2012 us=750000 mode = 0
Fri Mar 02 12:51:13 2012 us=750000 show_ciphers = DISABLED
Fri Mar 02 12:51:13 2012 us=750000 show_digests = DISABLED
Fri Mar 02 12:51:13 2012 us=750000 show_engines = DISABLED
Fri Mar 02 12:51:13 2012 us=750000 genkey = DISABLED
Fri Mar 02 12:51:13 2012 us=750000 key_pass_file = '[UNDEF]'
Fri Mar 02 12:51:13 2012 us=750000 show_tls_ciphers = DISABLED
Fri Mar 02 12:51:13 2012 us=750000 Connection profiles [default]:
Fri Mar 02 12:51:13 2012 us=750000 proto = udp
Fri Mar 02 12:51:13 2012 us=750000 local = '[UNDEF]'
Fri Mar 02 12:51:13 2012 us=750000 local_port = 0
Fri Mar 02 12:51:13 2012 us=750000 remote = '10.10.2.4'
Fri Mar 02 12:51:13 2012 us=750000 remote_port = 1194
Fri Mar 02 12:51:13 2012 us=750000 remote_float = DISABLED
Fri Mar 02 12:51:13 2012 us=750000 bind_defined = DISABLED
Fri Mar 02 12:51:13 2012 us=750000 bind_local = DISABLED
Fri Mar 02 12:51:13 2012 us=750000 connect_retry_seconds = 5
Fri Mar 02 12:51:13 2012 us=750000 connect_timeout = 10
Fri Mar 02 12:51:13 2012 us=750000 NOTE: --mute triggered...
Fri Mar 02 12:51:13 2012 us=750000 253 variation(s) on previous 20 message(s) suppressed by --mute
Fri Mar 02 12:51:13 2012 us=750000 OpenVPN 2.2.2 Win32-MSVC++ [SSL] [LZO2] [PKCS11] built on Dec 15 2011
Fri Mar 02 12:51:13 2012 us=750000 WARNING: Make sure you understand the semantics of --tls-remote before using it (see the man page).
Fri Mar 02 12:51:13 2012 us=750000 NOTE: OpenVPN 2.1 requires '--script-security 2' or higher to call user-defined scripts or executables
Fri Mar 02 12:51:13 2012 us=890000 LZO compression initialized
Fri Mar 02 12:51:13 2012 us=890000 Control Channel MTU parms [ L:1574 D:138 EF:38 EB:0 ET:0 EL:0 ]
Fri Mar 02 12:51:13 2012 us=890000 Socket Buffers: R=[65536->65536] S=[65536->65536]
Fri Mar 02 12:51:13 2012 us=890000 Data Channel MTU parms [ L:1574 D:1450 EF:42 EB:135 ET:32 EL:0 AF:3/1 ]
Fri Mar 02 12:51:13 2012 us=890000 Local Options String: 'V4,dev-type tap,link-mtu 1574,tun-mtu 1532,proto UDPv4,comp-lzo,cipher BF-CBC,auth SHA1,keysize 128,key-method 2,tls-client'
Fri Mar 02 12:51:13 2012 us=890000 Expected Remote Options String: 'V4,dev-type tap,link-mtu 1574,tun-mtu 1532,proto UDPv4,comp-lzo,cipher BF-CBC,auth SHA1,keysize 128,key-method 2,tls-server'
Fri Mar 02 12:51:13 2012 us=890000 Local Options hash (VER=V4): 'd79ca330'
Fri Mar 02 12:51:13 2012 us=890000 Expected Remote Options hash (VER=V4): 'f7df56b8'
Fri Mar 02 12:51:13 2012 us=890000 UDPv4 link local: [undef]
Fri Mar 02 12:51:13 2012 us=890000 UDPv4 link remote: 10.10.2.4:1194
Fri Mar 02 12:51:13 2012 us=890000 TLS: Initial packet from 10.10.2.4:1194, sid=90fd922b 5c74dee1
Fri Mar 02 12:51:13 2012 us=921000 VERIFY OK: depth=1, /C=CH/L=Guemligen/O=USP/OU=ca/CN=chgut1ca.u-s-p.ch
Fri Mar 02 12:51:13 2012 us=921000 VERIFY X509NAME OK: /C=CH/L=Guemligen/O=USP/CN=chgut2fw01.u-s-p.ch
Fri Mar 02 12:51:13 2012 us=921000 VERIFY OK: depth=0, /C=CH/L=Guemligen/O=USP/CN=chgut2fw01.u-s-p.ch
Fri Mar 02 12:51:14 2012 Data Channel Encrypt: Cipher 'BF-CBC' initialized with 128 bit key
Fri Mar 02 12:51:14 2012 Data Channel Encrypt: Using 160 bit message hash 'SHA1' for HMAC authentication
Fri Mar 02 12:51:14 2012 Data Channel Decrypt: Cipher 'BF-CBC' initialized with 128 bit key
Fri Mar 02 12:51:14 2012 Data Channel Decrypt: Using 160 bit message hash 'SHA1' for HMAC authentication
Fri Mar 02 12:51:14 2012 us=140000 Control Channel: TLSv1, cipher TLSv1/SSLv3 DHE-RSA-AES256-SHA, 1024 bit RSA
Fri Mar 02 12:51:14 2012 us=140000 [chgut2fw01.u-s-p.ch] Peer Connection Initiated with 10.10.2.4:1194
Fri Mar 02 12:51:16 2012 us=468000 SENT CONTROL [chgut2fw01.u-s-p.ch]: 'PUSH_REQUEST' (status=1)
Fri Mar 02 12:51:16 2012 us=468000 PUSH: Received control message: 'PUSH_REPLY,route-gateway 10.255.250.1,ping 10,ping-restart 120,ip-win32 dynamic,route 172.16.20.0 255.255.255.192,route 172.16.20.64 255.255.255.192,route 172.16.20.128 255.255.255.192,route 172.16.20.192 255.255.255.192,ifconfig 10.255.250.2 255.255.255.0'
Fri Mar 02 12:51:16 2012 us=468000 OPTIONS IMPORT: timers and/or timeouts modified
Fri Mar 02 12:51:16 2012 us=468000 OPTIONS IMPORT: --ifconfig/up options modified
Fri Mar 02 12:51:16 2012 us=468000 OPTIONS IMPORT: route options modified
Fri Mar 02 12:51:16 2012 us=468000 OPTIONS IMPORT: route-related options modified
Fri Mar 02 12:51:16 2012 us=468000 OPTIONS IMPORT: --ip-win32 and/or --dhcp-option options modified
Fri Mar 02 12:51:16 2012 us=484000 ROUTE default_gateway=10.0.2.2
Fri Mar 02 12:51:16 2012 us=484000 TAP-WIN32 device [Local Area Connection] opened: \\.\Global\{96CA5E31-01B9-41F6-8078-2A760FDDFB09}.tap
Fri Mar 02 12:51:16 2012 us=484000 TAP-Win32 Driver Version 9.9
Fri Mar 02 12:51:16 2012 us=484000 TAP-Win32 MTU=1500
Fri Mar 02 12:51:16 2012 us=500000 Notified TAP-Win32 driver to set a DHCP IP/netmask of 10.255.250.2/255.255.255.0 on interface {96CA5E31-01B9-41F6-8078-2A760FDDFB09} [DHCP-serv: 10.255.250.0, lease-time: 31536000]
Fri Mar 02 12:51:16 2012 us=500000 Successful ARP Flush on interface [15] {96CA5E31-01B9-41F6-8078-2A760FDDFB09}
Fri Mar 02 12:51:21 2012 us=656000 TEST ROUTES: 0/0 succeeded len=4 ret=0 a=0 u/d=down
Fri Mar 02 12:51:21 2012 us=656000 Route: Waiting for TUN/TAP interface to come up...
Fri Mar 02 12:51:26 2012 us=812000 TEST ROUTES: 0/0 succeeded len=4 ret=0 a=0 u/d=down
Fri Mar 02 12:51:26 2012 us=812000 Route: Waiting for TUN/TAP interface to come up...
Fri Mar 02 12:51:27 2012 us=968000 TEST ROUTES: 0/0 succeeded len=4 ret=0 a=0 u/d=down
Fri Mar 02 12:51:27 2012 us=968000 Route: Waiting for TUN/TAP interface to come up...
Fri Mar 02 12:51:29 2012 us=125000 TEST ROUTES: 0/0 succeeded len=4 ret=0 a=0 u/d=down
Fri Mar 02 12:51:29 2012 us=125000 Route: Waiting for TUN/TAP interface to come up...
Fri Mar 02 12:51:30 2012 us=281000 TEST ROUTES: 0/0 succeeded len=4 ret=0 a=0 u/d=down
Fri Mar 02 12:51:30 2012 us=281000 Route: Waiting for TUN/TAP interface to come up...
Fri Mar 02 12:51:31 2012 us=437000 TEST ROUTES: 0/0 succeeded len=4 ret=0 a=0 u/d=down
Fri Mar 02 12:51:31 2012 us=437000 Route: Waiting for TUN/TAP interface to come up...
Fri Mar 02 12:51:32 2012 us=593000 TEST ROUTES: 0/0 succeeded len=4 ret=0 a=0 u/d=down
Fri Mar 02 12:51:32 2012 us=593000 Route: Waiting for TUN/TAP interface to come up...
Fri Mar 02 12:51:33 2012 us=750000 TEST ROUTES: 0/0 succeeded len=4 ret=0 a=0 u/d=down
Fri Mar 02 12:51:33 2012 us=750000 Route: Waiting for TUN/TAP interface to come up...
Fri Mar 02 12:51:34 2012 us=906000 TEST ROUTES: 0/0 succeeded len=4 ret=0 a=0 u/d=down
Fri Mar 02 12:51:34 2012 us=906000 Route: Waiting for TUN/TAP interface to come up...
Fri Mar 02 12:51:36 2012 us=62000 TEST ROUTES: 0/0 succeeded len=4 ret=0 a=0 u/d=down
Fri Mar 02 12:51:36 2012 us=62000 Route: Waiting for TUN/TAP interface to come up...
Fri Mar 02 12:51:37 2012 us=234000 TEST ROUTES: 0/0 succeeded len=4 ret=0 a=0 u/d=down
Fri Mar 02 12:51:37 2012 us=234000 Route: Waiting for TUN/TAP interface to come up...
Fri Mar 02 12:51:38 2012 us=468000 TEST ROUTES: 0/0 succeeded len=4 ret=0 a=0 u/d=down
Fri Mar 02 12:51:38 2012 us=468000 Route: Waiting for TUN/TAP interface to come up...
Fri Mar 02 12:51:39 2012 us=703000 TEST ROUTES: 0/0 succeeded len=4 ret=0 a=0 u/d=down
Fri Mar 02 12:51:39 2012 us=703000 Route: Waiting for TUN/TAP interface to come up...
Fri Mar 02 12:51:40 2012 us=937000 TEST ROUTES: 0/0 succeeded len=4 ret=0 a=0 u/d=down
Fri Mar 02 12:51:40 2012 us=937000 Route: Waiting for TUN/TAP interface to come up...
Fri Mar 02 12:51:42 2012 us=171000 TEST ROUTES: 0/0 succeeded len=4 ret=0 a=0 u/d=down
Fri Mar 02 12:51:42 2012 us=171000 Route: Waiting for TUN/TAP interface to come up...
Fri Mar 02 12:51:43 2012 us=406000 TEST ROUTES: 0/0 succeeded len=4 ret=0 a=0 u/d=down
Fri Mar 02 12:51:43 2012 us=406000 Route: Waiting for TUN/TAP interface to come up...
Fri Mar 02 12:51:44 2012 us=640000 TEST ROUTES: 0/0 succeeded len=4 ret=0 a=0 u/d=down
Fri Mar 02 12:51:44 2012 us=640000 Route: Waiting for TUN/TAP interface to come up...
Fri Mar 02 12:51:45 2012 us=875000 TEST ROUTES: 0/0 succeeded len=4 ret=0 a=0 u/d=down
Fri Mar 02 12:51:45 2012 us=875000 Route: Waiting for TUN/TAP interface to come up...
Fri Mar 02 12:51:47 2012 us=109000 TEST ROUTES: 0/0 succeeded len=4 ret=0 a=0 u/d=down
Fri Mar 02 12:51:47 2012 us=109000 Route: Waiting for TUN/TAP interface to come up...
Fri Mar 02 12:51:48 2012 us=281000 TEST ROUTES: 0/0 succeeded len=4 ret=0 a=0 u/d=down
Fri Mar 02 12:51:48 2012 us=281000 Route: Waiting for TUN/TAP interface to come up...
Fri Mar 02 12:51:49 2012 us=453000 TEST ROUTES: 0/0 succeeded len=4 ret=0 a=0 u/d=down
Fri Mar 02 12:51:49 2012 us=453000 Route: Waiting for TUN/TAP interface to come up...
Fri Mar 02 12:51:50 2012 us=625000 TEST ROUTES: 0/0 succeeded len=4 ret=0 a=0 u/d=down
Fri Mar 02 12:51:50 2012 us=625000 Route: Waiting for TUN/TAP interface to come up...
Fri Mar 02 12:51:51 2012 us=796000 TEST ROUTES: 0/0 succeeded len=4 ret=0 a=0 u/d=down
Fri Mar 02 12:51:51 2012 us=796000 C:\WINDOWS\system32\route.exe ADD 172.16.20.0 MASK 255.255.255.192 10.255.250.1
Fri Mar 02 12:51:51 2012 us=796000 Warning: route gateway is not reachable on any active network adapters: 10.255.250.1
Fri Mar 02 12:51:51 2012 us=796000 Route addition via IPAPI failed [adaptive]
Fri Mar 02 12:51:51 2012 us=796000 Route addition fallback to route.exe
OK!
Fri Mar 02 12:51:51 2012 us=812000 C:\WINDOWS\system32\route.exe ADD 172.16.20.64 MASK 255.255.255.192 10.255.250.1
Fri Mar 02 12:51:51 2012 us=812000 Warning: route gateway is not reachable on any active network adapters: 10.255.250.1
Fri Mar 02 12:51:51 2012 us=812000 Route addition via IPAPI failed [adaptive]
Fri Mar 02 12:51:51 2012 us=812000 Route addition fallback to route.exe
OK!
Fri Mar 02 12:51:51 2012 us=843000 C:\WINDOWS\system32\route.exe ADD 172.16.20.128 MASK 255.255.255.192 10.255.250.1
Fri Mar 02 12:51:51 2012 us=843000 Warning: route gateway is not reachable on any active network adapters: 10.255.250.1
Fri Mar 02 12:51:51 2012 us=843000 Route addition via IPAPI failed [adaptive]
Fri Mar 02 12:51:51 2012 us=843000 Route addition fallback to route.exe
OK!
Fri Mar 02 12:51:51 2012 us=859000 C:\WINDOWS\system32\route.exe ADD 172.16.20.192 MASK 255.255.255.192 10.255.250.1
Fri Mar 02 12:51:51 2012 us=875000 Warning: route gateway is not reachable on any active network adapters: 10.255.250.1
Fri Mar 02 12:51:51 2012 us=875000 Route addition via IPAPI failed [adaptive]
Fri Mar 02 12:51:51 2012 us=875000 Route addition fallback to route.exe
OK!
SYSTEM ROUTING TABLE
0.0.0.0 0.0.0.0 10.0.2.2 p=0 i=12 t=4 pr=3 a=3343 h=0 m=266/0/0/0/0
10.0.2.0 255.255.255.0 10.0.2.15 p=0 i=12 t=3 pr=2 a=3343 h=0 m=266/0/0/0/0
10.0.2.15 255.255.255.255 10.0.2.15 p=0 i=12 t=3 pr=2 a=3343 h=0 m=266/0/0/0/0
10.0.2.255 255.255.255.255 10.0.2.15 p=0 i=12 t=3 pr=2 a=3343 h=0 m=266/0/0/0/0
127.0.0.0 255.0.0.0 127.0.0.1 p=0 i=1 t=3 pr=2 a=3372 h=0 m=306/0/0/0/0
127.0.0.1 255.255.255.255 127.0.0.1 p=0 i=1 t=3 pr=2 a=3372 h=0 m=306/0/0/0/0
127.255.255.255 255.255.255.255 127.0.0.1 p=0 i=1 t=3 pr=2 a=3372 h=0 m=306/0/0/0/0
172.16.20.0 255.255.255.192 10.255.250.1 p=0 i=12 t=4 pr=3 a=0 h=0 m=11/0/0/0/0
172.16.20.64 255.255.255.192 10.255.250.1 p=0 i=12 t=4 pr=3 a=0 h=0 m=11/0/0/0/0
172.16.20.128 255.255.255.192 10.255.250.1 p=0 i=12 t=4 pr=3 a=0 h=0 m=11/0/0/0/0
172.16.20.192 255.255.255.192 10.255.250.1 p=0 i=12 t=4 pr=3 a=0 h=0 m=11/0/0/0/0
224.0.0.0 240.0.0.0 127.0.0.1 p=0 i=1 t=3 pr=2 a=3372 h=0 m=306/0/0/0/0
224.0.0.0 240.0.0.0 10.0.2.15 p=0 i=12 t=3 pr=2 a=3361 h=0 m=266/0/0/0/0
255.255.255.255 255.255.255.255 127.0.0.1 p=0 i=1 t=3 pr=2 a=3372 h=0 m=306/0/0/0/0
255.255.255.255 255.255.255.255 10.0.2.15 p=0 i=12 t=3 pr=2 a=3361 h=0 m=266/0/0/0/0
SYSTEM ADAPTER LIST
TAP-Win32 Adapter V9
Index = 15
GUID = {96CA5E31-01B9-41F6-8078-2A760FDDFB09}
IP = 0.0.0.0/0.0.0.0
MAC = 00:ff:96:ca:5e:31
GATEWAY = 0.0.0.0/255.255.255.255
DHCP SERV =
DHCP LEASE OBTAINED = Fri Mar 02 12:51:51 2012
DHCP LEASE EXPIRES = Wed Dec 31 16:00:00 1969
DNS SERV =
Intel(R) PRO/1000 MT Desktop Adapter
Index = 12
GUID = {55CAE6F0-EA1F-4629-8074-378F39C7A5FE}
IP = 10.0.2.15/255.255.255.0
MAC = 08:00:27:47:5e:2d
GATEWAY = 10.0.2.2/255.255.255.255
DHCP SERV = 10.0.2.2/255.255.255.255
DHCP LEASE OBTAINED = Fri Mar 02 11:56:08 2012
DHCP LEASE EXPIRES = Wed Dec 31 16:00:00 1969
DNS SERV = 192.168.1.29/255.255.255.255 192.168.1.38/255.255.255.255 172.17.4.212/255.255.255.255
Fri Mar 02 12:51:51 2012 us=984000 Initialization Sequence Completed With Errors ( see http://openvpn.net/faq.html#dhcpclientserv )
Client config:
client
dev tun
remote 10.10.2.4 1194
nobind
persist-key
persist-tun
tls-client
tls-remote chgut2fw01.u-s-p.ch
ca cacert/caCert.pem
cert cert/userCert.pem
key key/userKey.pem
comp-lzo
verb 4
mute 20
ping 10
ping-restart 60
# and optional with methods "route-delay 20", "route-method exe" and "tap-sleep 10"
Server config:
mode server
local 10.10.2.4
proto udp
port 1194
dev tun
topology subnet
user root
group root
cd /etc/openvpn
tls-server
ca cacerts/caCert.pem
cert cert/chgut2fwCert.pem
key key/chgut2fwKey.pem
crl-verify crls/crl.pem
dh key/dh1024.pem
ifconfig 10.255.250.1 255.255.255.0
ifconfig-pool 10.255.250.2 10.255.250.254 255.255.255.0
ifconfig-pool-persist /var/state/openvpn/ipp_wan0-udp-1194-0
push "topology subnet"
push "ip-win32 dynamic"
push "dhcp-option DOMAIN u-s-p.ch"
push "route-gateway 10.255.250.1"
push "route 172.16.20.0 255.255.255.0"
push "route 192.168.200.0 255.255.255.0"
push "route 192.168.220.0 255.255.255.0"
script-security 2 execve
client-to-client
keepalive 10 120
reneg-sec 3600
cipher BF-CBC
comp-lzo
max-clients 100
persist-key
persist-tun
status /var/state/openvpn/status_wan0-udp-1194-0 20
status-version 2
verb 4
mute 20
Thanks.
Best regards
Elmar
I know this is a problem which was often diskussed on this forum. It is the problem with openvpn not be able to configure the tap adapter. With openvpn-2.2.2 I was happy to see, that the problem is solved for windows 7. It works great! With 2.1 the problem appeared mostly after a power resume (after standby).
Now I did some tests with the Windows 8 consumer preview. Sure this version is not yet released. But unfortunately the problem seems to be back. And in my opinion it is much worse.
I tried already with all the workarounds with route-delay options , route-method, TAP adaptor reset, tap-sleep, ip-win32 netsh, ...
Sometimes it is working good and then another time it absolutely won't configure the tap adapter (especially after a reboot).
I tried as well with openvpn-2.3-alpha1, but it doesn't change anything.
Did you notify already this problem? At the moment it is not a big issue as Windows 8 is not yet released. Has anyone an idea, why it is bad again?
Here the log output:
Fri Mar 02 12:51:13 2012 us=750000 Current Parameter Settings:
Fri Mar 02 12:51:13 2012 us=750000 config = 'sophiaconfig.ovpn'
Fri Mar 02 12:51:13 2012 us=750000 mode = 0
Fri Mar 02 12:51:13 2012 us=750000 show_ciphers = DISABLED
Fri Mar 02 12:51:13 2012 us=750000 show_digests = DISABLED
Fri Mar 02 12:51:13 2012 us=750000 show_engines = DISABLED
Fri Mar 02 12:51:13 2012 us=750000 genkey = DISABLED
Fri Mar 02 12:51:13 2012 us=750000 key_pass_file = '[UNDEF]'
Fri Mar 02 12:51:13 2012 us=750000 show_tls_ciphers = DISABLED
Fri Mar 02 12:51:13 2012 us=750000 Connection profiles [default]:
Fri Mar 02 12:51:13 2012 us=750000 proto = udp
Fri Mar 02 12:51:13 2012 us=750000 local = '[UNDEF]'
Fri Mar 02 12:51:13 2012 us=750000 local_port = 0
Fri Mar 02 12:51:13 2012 us=750000 remote = '10.10.2.4'
Fri Mar 02 12:51:13 2012 us=750000 remote_port = 1194
Fri Mar 02 12:51:13 2012 us=750000 remote_float = DISABLED
Fri Mar 02 12:51:13 2012 us=750000 bind_defined = DISABLED
Fri Mar 02 12:51:13 2012 us=750000 bind_local = DISABLED
Fri Mar 02 12:51:13 2012 us=750000 connect_retry_seconds = 5
Fri Mar 02 12:51:13 2012 us=750000 connect_timeout = 10
Fri Mar 02 12:51:13 2012 us=750000 NOTE: --mute triggered...
Fri Mar 02 12:51:13 2012 us=750000 253 variation(s) on previous 20 message(s) suppressed by --mute
Fri Mar 02 12:51:13 2012 us=750000 OpenVPN 2.2.2 Win32-MSVC++ [SSL] [LZO2] [PKCS11] built on Dec 15 2011
Fri Mar 02 12:51:13 2012 us=750000 WARNING: Make sure you understand the semantics of --tls-remote before using it (see the man page).
Fri Mar 02 12:51:13 2012 us=750000 NOTE: OpenVPN 2.1 requires '--script-security 2' or higher to call user-defined scripts or executables
Fri Mar 02 12:51:13 2012 us=890000 LZO compression initialized
Fri Mar 02 12:51:13 2012 us=890000 Control Channel MTU parms [ L:1574 D:138 EF:38 EB:0 ET:0 EL:0 ]
Fri Mar 02 12:51:13 2012 us=890000 Socket Buffers: R=[65536->65536] S=[65536->65536]
Fri Mar 02 12:51:13 2012 us=890000 Data Channel MTU parms [ L:1574 D:1450 EF:42 EB:135 ET:32 EL:0 AF:3/1 ]
Fri Mar 02 12:51:13 2012 us=890000 Local Options String: 'V4,dev-type tap,link-mtu 1574,tun-mtu 1532,proto UDPv4,comp-lzo,cipher BF-CBC,auth SHA1,keysize 128,key-method 2,tls-client'
Fri Mar 02 12:51:13 2012 us=890000 Expected Remote Options String: 'V4,dev-type tap,link-mtu 1574,tun-mtu 1532,proto UDPv4,comp-lzo,cipher BF-CBC,auth SHA1,keysize 128,key-method 2,tls-server'
Fri Mar 02 12:51:13 2012 us=890000 Local Options hash (VER=V4): 'd79ca330'
Fri Mar 02 12:51:13 2012 us=890000 Expected Remote Options hash (VER=V4): 'f7df56b8'
Fri Mar 02 12:51:13 2012 us=890000 UDPv4 link local: [undef]
Fri Mar 02 12:51:13 2012 us=890000 UDPv4 link remote: 10.10.2.4:1194
Fri Mar 02 12:51:13 2012 us=890000 TLS: Initial packet from 10.10.2.4:1194, sid=90fd922b 5c74dee1
Fri Mar 02 12:51:13 2012 us=921000 VERIFY OK: depth=1, /C=CH/L=Guemligen/O=USP/OU=ca/CN=chgut1ca.u-s-p.ch
Fri Mar 02 12:51:13 2012 us=921000 VERIFY X509NAME OK: /C=CH/L=Guemligen/O=USP/CN=chgut2fw01.u-s-p.ch
Fri Mar 02 12:51:13 2012 us=921000 VERIFY OK: depth=0, /C=CH/L=Guemligen/O=USP/CN=chgut2fw01.u-s-p.ch
Fri Mar 02 12:51:14 2012 Data Channel Encrypt: Cipher 'BF-CBC' initialized with 128 bit key
Fri Mar 02 12:51:14 2012 Data Channel Encrypt: Using 160 bit message hash 'SHA1' for HMAC authentication
Fri Mar 02 12:51:14 2012 Data Channel Decrypt: Cipher 'BF-CBC' initialized with 128 bit key
Fri Mar 02 12:51:14 2012 Data Channel Decrypt: Using 160 bit message hash 'SHA1' for HMAC authentication
Fri Mar 02 12:51:14 2012 us=140000 Control Channel: TLSv1, cipher TLSv1/SSLv3 DHE-RSA-AES256-SHA, 1024 bit RSA
Fri Mar 02 12:51:14 2012 us=140000 [chgut2fw01.u-s-p.ch] Peer Connection Initiated with 10.10.2.4:1194
Fri Mar 02 12:51:16 2012 us=468000 SENT CONTROL [chgut2fw01.u-s-p.ch]: 'PUSH_REQUEST' (status=1)
Fri Mar 02 12:51:16 2012 us=468000 PUSH: Received control message: 'PUSH_REPLY,route-gateway 10.255.250.1,ping 10,ping-restart 120,ip-win32 dynamic,route 172.16.20.0 255.255.255.192,route 172.16.20.64 255.255.255.192,route 172.16.20.128 255.255.255.192,route 172.16.20.192 255.255.255.192,ifconfig 10.255.250.2 255.255.255.0'
Fri Mar 02 12:51:16 2012 us=468000 OPTIONS IMPORT: timers and/or timeouts modified
Fri Mar 02 12:51:16 2012 us=468000 OPTIONS IMPORT: --ifconfig/up options modified
Fri Mar 02 12:51:16 2012 us=468000 OPTIONS IMPORT: route options modified
Fri Mar 02 12:51:16 2012 us=468000 OPTIONS IMPORT: route-related options modified
Fri Mar 02 12:51:16 2012 us=468000 OPTIONS IMPORT: --ip-win32 and/or --dhcp-option options modified
Fri Mar 02 12:51:16 2012 us=484000 ROUTE default_gateway=10.0.2.2
Fri Mar 02 12:51:16 2012 us=484000 TAP-WIN32 device [Local Area Connection] opened: \\.\Global\{96CA5E31-01B9-41F6-8078-2A760FDDFB09}.tap
Fri Mar 02 12:51:16 2012 us=484000 TAP-Win32 Driver Version 9.9
Fri Mar 02 12:51:16 2012 us=484000 TAP-Win32 MTU=1500
Fri Mar 02 12:51:16 2012 us=500000 Notified TAP-Win32 driver to set a DHCP IP/netmask of 10.255.250.2/255.255.255.0 on interface {96CA5E31-01B9-41F6-8078-2A760FDDFB09} [DHCP-serv: 10.255.250.0, lease-time: 31536000]
Fri Mar 02 12:51:16 2012 us=500000 Successful ARP Flush on interface [15] {96CA5E31-01B9-41F6-8078-2A760FDDFB09}
Fri Mar 02 12:51:21 2012 us=656000 TEST ROUTES: 0/0 succeeded len=4 ret=0 a=0 u/d=down
Fri Mar 02 12:51:21 2012 us=656000 Route: Waiting for TUN/TAP interface to come up...
Fri Mar 02 12:51:26 2012 us=812000 TEST ROUTES: 0/0 succeeded len=4 ret=0 a=0 u/d=down
Fri Mar 02 12:51:26 2012 us=812000 Route: Waiting for TUN/TAP interface to come up...
Fri Mar 02 12:51:27 2012 us=968000 TEST ROUTES: 0/0 succeeded len=4 ret=0 a=0 u/d=down
Fri Mar 02 12:51:27 2012 us=968000 Route: Waiting for TUN/TAP interface to come up...
Fri Mar 02 12:51:29 2012 us=125000 TEST ROUTES: 0/0 succeeded len=4 ret=0 a=0 u/d=down
Fri Mar 02 12:51:29 2012 us=125000 Route: Waiting for TUN/TAP interface to come up...
Fri Mar 02 12:51:30 2012 us=281000 TEST ROUTES: 0/0 succeeded len=4 ret=0 a=0 u/d=down
Fri Mar 02 12:51:30 2012 us=281000 Route: Waiting for TUN/TAP interface to come up...
Fri Mar 02 12:51:31 2012 us=437000 TEST ROUTES: 0/0 succeeded len=4 ret=0 a=0 u/d=down
Fri Mar 02 12:51:31 2012 us=437000 Route: Waiting for TUN/TAP interface to come up...
Fri Mar 02 12:51:32 2012 us=593000 TEST ROUTES: 0/0 succeeded len=4 ret=0 a=0 u/d=down
Fri Mar 02 12:51:32 2012 us=593000 Route: Waiting for TUN/TAP interface to come up...
Fri Mar 02 12:51:33 2012 us=750000 TEST ROUTES: 0/0 succeeded len=4 ret=0 a=0 u/d=down
Fri Mar 02 12:51:33 2012 us=750000 Route: Waiting for TUN/TAP interface to come up...
Fri Mar 02 12:51:34 2012 us=906000 TEST ROUTES: 0/0 succeeded len=4 ret=0 a=0 u/d=down
Fri Mar 02 12:51:34 2012 us=906000 Route: Waiting for TUN/TAP interface to come up...
Fri Mar 02 12:51:36 2012 us=62000 TEST ROUTES: 0/0 succeeded len=4 ret=0 a=0 u/d=down
Fri Mar 02 12:51:36 2012 us=62000 Route: Waiting for TUN/TAP interface to come up...
Fri Mar 02 12:51:37 2012 us=234000 TEST ROUTES: 0/0 succeeded len=4 ret=0 a=0 u/d=down
Fri Mar 02 12:51:37 2012 us=234000 Route: Waiting for TUN/TAP interface to come up...
Fri Mar 02 12:51:38 2012 us=468000 TEST ROUTES: 0/0 succeeded len=4 ret=0 a=0 u/d=down
Fri Mar 02 12:51:38 2012 us=468000 Route: Waiting for TUN/TAP interface to come up...
Fri Mar 02 12:51:39 2012 us=703000 TEST ROUTES: 0/0 succeeded len=4 ret=0 a=0 u/d=down
Fri Mar 02 12:51:39 2012 us=703000 Route: Waiting for TUN/TAP interface to come up...
Fri Mar 02 12:51:40 2012 us=937000 TEST ROUTES: 0/0 succeeded len=4 ret=0 a=0 u/d=down
Fri Mar 02 12:51:40 2012 us=937000 Route: Waiting for TUN/TAP interface to come up...
Fri Mar 02 12:51:42 2012 us=171000 TEST ROUTES: 0/0 succeeded len=4 ret=0 a=0 u/d=down
Fri Mar 02 12:51:42 2012 us=171000 Route: Waiting for TUN/TAP interface to come up...
Fri Mar 02 12:51:43 2012 us=406000 TEST ROUTES: 0/0 succeeded len=4 ret=0 a=0 u/d=down
Fri Mar 02 12:51:43 2012 us=406000 Route: Waiting for TUN/TAP interface to come up...
Fri Mar 02 12:51:44 2012 us=640000 TEST ROUTES: 0/0 succeeded len=4 ret=0 a=0 u/d=down
Fri Mar 02 12:51:44 2012 us=640000 Route: Waiting for TUN/TAP interface to come up...
Fri Mar 02 12:51:45 2012 us=875000 TEST ROUTES: 0/0 succeeded len=4 ret=0 a=0 u/d=down
Fri Mar 02 12:51:45 2012 us=875000 Route: Waiting for TUN/TAP interface to come up...
Fri Mar 02 12:51:47 2012 us=109000 TEST ROUTES: 0/0 succeeded len=4 ret=0 a=0 u/d=down
Fri Mar 02 12:51:47 2012 us=109000 Route: Waiting for TUN/TAP interface to come up...
Fri Mar 02 12:51:48 2012 us=281000 TEST ROUTES: 0/0 succeeded len=4 ret=0 a=0 u/d=down
Fri Mar 02 12:51:48 2012 us=281000 Route: Waiting for TUN/TAP interface to come up...
Fri Mar 02 12:51:49 2012 us=453000 TEST ROUTES: 0/0 succeeded len=4 ret=0 a=0 u/d=down
Fri Mar 02 12:51:49 2012 us=453000 Route: Waiting for TUN/TAP interface to come up...
Fri Mar 02 12:51:50 2012 us=625000 TEST ROUTES: 0/0 succeeded len=4 ret=0 a=0 u/d=down
Fri Mar 02 12:51:50 2012 us=625000 Route: Waiting for TUN/TAP interface to come up...
Fri Mar 02 12:51:51 2012 us=796000 TEST ROUTES: 0/0 succeeded len=4 ret=0 a=0 u/d=down
Fri Mar 02 12:51:51 2012 us=796000 C:\WINDOWS\system32\route.exe ADD 172.16.20.0 MASK 255.255.255.192 10.255.250.1
Fri Mar 02 12:51:51 2012 us=796000 Warning: route gateway is not reachable on any active network adapters: 10.255.250.1
Fri Mar 02 12:51:51 2012 us=796000 Route addition via IPAPI failed [adaptive]
Fri Mar 02 12:51:51 2012 us=796000 Route addition fallback to route.exe
OK!
Fri Mar 02 12:51:51 2012 us=812000 C:\WINDOWS\system32\route.exe ADD 172.16.20.64 MASK 255.255.255.192 10.255.250.1
Fri Mar 02 12:51:51 2012 us=812000 Warning: route gateway is not reachable on any active network adapters: 10.255.250.1
Fri Mar 02 12:51:51 2012 us=812000 Route addition via IPAPI failed [adaptive]
Fri Mar 02 12:51:51 2012 us=812000 Route addition fallback to route.exe
OK!
Fri Mar 02 12:51:51 2012 us=843000 C:\WINDOWS\system32\route.exe ADD 172.16.20.128 MASK 255.255.255.192 10.255.250.1
Fri Mar 02 12:51:51 2012 us=843000 Warning: route gateway is not reachable on any active network adapters: 10.255.250.1
Fri Mar 02 12:51:51 2012 us=843000 Route addition via IPAPI failed [adaptive]
Fri Mar 02 12:51:51 2012 us=843000 Route addition fallback to route.exe
OK!
Fri Mar 02 12:51:51 2012 us=859000 C:\WINDOWS\system32\route.exe ADD 172.16.20.192 MASK 255.255.255.192 10.255.250.1
Fri Mar 02 12:51:51 2012 us=875000 Warning: route gateway is not reachable on any active network adapters: 10.255.250.1
Fri Mar 02 12:51:51 2012 us=875000 Route addition via IPAPI failed [adaptive]
Fri Mar 02 12:51:51 2012 us=875000 Route addition fallback to route.exe
OK!
SYSTEM ROUTING TABLE
0.0.0.0 0.0.0.0 10.0.2.2 p=0 i=12 t=4 pr=3 a=3343 h=0 m=266/0/0/0/0
10.0.2.0 255.255.255.0 10.0.2.15 p=0 i=12 t=3 pr=2 a=3343 h=0 m=266/0/0/0/0
10.0.2.15 255.255.255.255 10.0.2.15 p=0 i=12 t=3 pr=2 a=3343 h=0 m=266/0/0/0/0
10.0.2.255 255.255.255.255 10.0.2.15 p=0 i=12 t=3 pr=2 a=3343 h=0 m=266/0/0/0/0
127.0.0.0 255.0.0.0 127.0.0.1 p=0 i=1 t=3 pr=2 a=3372 h=0 m=306/0/0/0/0
127.0.0.1 255.255.255.255 127.0.0.1 p=0 i=1 t=3 pr=2 a=3372 h=0 m=306/0/0/0/0
127.255.255.255 255.255.255.255 127.0.0.1 p=0 i=1 t=3 pr=2 a=3372 h=0 m=306/0/0/0/0
172.16.20.0 255.255.255.192 10.255.250.1 p=0 i=12 t=4 pr=3 a=0 h=0 m=11/0/0/0/0
172.16.20.64 255.255.255.192 10.255.250.1 p=0 i=12 t=4 pr=3 a=0 h=0 m=11/0/0/0/0
172.16.20.128 255.255.255.192 10.255.250.1 p=0 i=12 t=4 pr=3 a=0 h=0 m=11/0/0/0/0
172.16.20.192 255.255.255.192 10.255.250.1 p=0 i=12 t=4 pr=3 a=0 h=0 m=11/0/0/0/0
224.0.0.0 240.0.0.0 127.0.0.1 p=0 i=1 t=3 pr=2 a=3372 h=0 m=306/0/0/0/0
224.0.0.0 240.0.0.0 10.0.2.15 p=0 i=12 t=3 pr=2 a=3361 h=0 m=266/0/0/0/0
255.255.255.255 255.255.255.255 127.0.0.1 p=0 i=1 t=3 pr=2 a=3372 h=0 m=306/0/0/0/0
255.255.255.255 255.255.255.255 10.0.2.15 p=0 i=12 t=3 pr=2 a=3361 h=0 m=266/0/0/0/0
SYSTEM ADAPTER LIST
TAP-Win32 Adapter V9
Index = 15
GUID = {96CA5E31-01B9-41F6-8078-2A760FDDFB09}
IP = 0.0.0.0/0.0.0.0
MAC = 00:ff:96:ca:5e:31
GATEWAY = 0.0.0.0/255.255.255.255
DHCP SERV =
DHCP LEASE OBTAINED = Fri Mar 02 12:51:51 2012
DHCP LEASE EXPIRES = Wed Dec 31 16:00:00 1969
DNS SERV =
Intel(R) PRO/1000 MT Desktop Adapter
Index = 12
GUID = {55CAE6F0-EA1F-4629-8074-378F39C7A5FE}
IP = 10.0.2.15/255.255.255.0
MAC = 08:00:27:47:5e:2d
GATEWAY = 10.0.2.2/255.255.255.255
DHCP SERV = 10.0.2.2/255.255.255.255
DHCP LEASE OBTAINED = Fri Mar 02 11:56:08 2012
DHCP LEASE EXPIRES = Wed Dec 31 16:00:00 1969
DNS SERV = 192.168.1.29/255.255.255.255 192.168.1.38/255.255.255.255 172.17.4.212/255.255.255.255
Fri Mar 02 12:51:51 2012 us=984000 Initialization Sequence Completed With Errors ( see http://openvpn.net/faq.html#dhcpclientserv )
Client config:
client
dev tun
remote 10.10.2.4 1194
nobind
persist-key
persist-tun
tls-client
tls-remote chgut2fw01.u-s-p.ch
ca cacert/caCert.pem
cert cert/userCert.pem
key key/userKey.pem
comp-lzo
verb 4
mute 20
ping 10
ping-restart 60
# and optional with methods "route-delay 20", "route-method exe" and "tap-sleep 10"
Server config:
mode server
local 10.10.2.4
proto udp
port 1194
dev tun
topology subnet
user root
group root
cd /etc/openvpn
tls-server
ca cacerts/caCert.pem
cert cert/chgut2fwCert.pem
key key/chgut2fwKey.pem
crl-verify crls/crl.pem
dh key/dh1024.pem
ifconfig 10.255.250.1 255.255.255.0
ifconfig-pool 10.255.250.2 10.255.250.254 255.255.255.0
ifconfig-pool-persist /var/state/openvpn/ipp_wan0-udp-1194-0
push "topology subnet"
push "ip-win32 dynamic"
push "dhcp-option DOMAIN u-s-p.ch"
push "route-gateway 10.255.250.1"
push "route 172.16.20.0 255.255.255.0"
push "route 192.168.200.0 255.255.255.0"
push "route 192.168.220.0 255.255.255.0"
script-security 2 execve
client-to-client
keepalive 10 120
reneg-sec 3600
cipher BF-CBC
comp-lzo
max-clients 100
persist-key
persist-tun
status /var/state/openvpn/status_wan0-udp-1194-0 20
status-version 2
verb 4
mute 20
Thanks.
Best regards
Elmar