TLS Handshake failed on remote connection
Posted: Wed Mar 13, 2013 4:43 am
I'm a first time user of OpenVPN and am trying to set this up at home for multiple users, using certificates. I've carefully gone through the HowTo documentation, configured port-forwarding and turned off all firewalls. It works great locally. My client machine is Windows 7 and the server machine is Server 2008R2. When I try to access via WAN IP address, I can't connect. I get this instead (of course I altered the ip address for this message, so don't get too excited):
Tue Mar 12 21:47:18 2013 Warning: cannot open --log file: C:\Program Files\OpenVPN\log\client1.log: The process cannot access the file because it is being used by another process. (errno=32)
Tue Mar 12 21:47:18 2013 OpenVPN 2.3.0 x86_64-w64-mingw32 [SSL (OpenSSL)] [LZO] [PKCS11] [eurephia] [IPv6] built on Feb 14 2013
Tue Mar 12 21:47:18 2013 MANAGEMENT: TCP Socket listening on [AF_INET]127.0.0.1:25340
Tue Mar 12 21:47:18 2013 Need hold release from management interface, waiting...
Tue Mar 12 21:47:19 2013 MANAGEMENT: Client connected from [AF_INET]127.0.0.1:25340
Tue Mar 12 21:47:19 2013 MANAGEMENT: CMD 'state on'
Tue Mar 12 21:47:19 2013 MANAGEMENT: CMD 'log all on'
Tue Mar 12 21:47:19 2013 MANAGEMENT: CMD 'hold off'
Tue Mar 12 21:47:19 2013 MANAGEMENT: CMD 'hold release'
Tue Mar 12 21:47:19 2013 NOTE: OpenVPN 2.1 requires '--script-security 2' or higher to call user-defined scripts or executables
Tue Mar 12 21:47:19 2013 Socket Buffers: R=[8192->8192] S=[8192->8192]
Tue Mar 12 21:47:19 2013 UDPv4 link local: [undef]
Tue Mar 12 21:47:19 2013 UDPv4 link remote: [AF_INET]161.42.38.61:1194
Tue Mar 12 21:47:19 2013 MANAGEMENT: >STATE:1363146439,WAIT,,,
Tue Mar 12 21:48:19 2013 TLS Error: TLS key negotiation failed to occur within 60 seconds (check your network connectivity)
Tue Mar 12 21:48:19 2013 TLS Error: TLS handshake failed
Tue Mar 12 21:48:19 2013 SIGUSR1[soft,tls-error] received, process restarting
Tue Mar 12 21:48:19 2013 MANAGEMENT: >STATE:1363146499,RECONNECTING,tls-error,,
Tue Mar 12 21:48:19 2013 Restart pause, 2 second(s)
When I run "netstat -an" on the server, I see this line referring to port 1194:
Proto Local Address Foreign Address State
UDP 0.0.0.0:1194 *:*
Here's my client1.opvn:
client
dev tun
dev-node MyTap
proto udp
remote 161.42.38.61 1194
resolv-retry infinite
nobind
persist-key
persist-tun
ca "c:\\program files\\openvpn\\config\\ca.crt"
cert "c:\\program files\\openvpn\\config\\client1.crt"
key "c:\\program files\\openvpn\\config\\client1.key"
ns-cert-type server
comp-lzo
verb 3
Here's my server.opvn:
port 1194
proto udp
dev tun
ca "C:\\Program Files\\OpenVPN\\easy-rsa\\keys\\ca.crt"
cert "C:\\Program Files\\OpenVPN\\easy-rsa\\keys\\server.crt"
key "C:\\Program Files\\OpenVPN\\easy-rsa\\keys\\server.key"
dh "C:\\Program Files\\OpenVPN\\easy-rsa\\keys\\dh1024.pem"
server 10.8.0.0 255.255.255.0
ifconfig-pool-persist ipp.txt
keepalive 10 120
comp-lzo
persist-key
persist-tun
status openvpn-status.log
verb 0
Any help would be greatly appreciated before I go totally bald.
~Steve
Tue Mar 12 21:47:18 2013 Warning: cannot open --log file: C:\Program Files\OpenVPN\log\client1.log: The process cannot access the file because it is being used by another process. (errno=32)
Tue Mar 12 21:47:18 2013 OpenVPN 2.3.0 x86_64-w64-mingw32 [SSL (OpenSSL)] [LZO] [PKCS11] [eurephia] [IPv6] built on Feb 14 2013
Tue Mar 12 21:47:18 2013 MANAGEMENT: TCP Socket listening on [AF_INET]127.0.0.1:25340
Tue Mar 12 21:47:18 2013 Need hold release from management interface, waiting...
Tue Mar 12 21:47:19 2013 MANAGEMENT: Client connected from [AF_INET]127.0.0.1:25340
Tue Mar 12 21:47:19 2013 MANAGEMENT: CMD 'state on'
Tue Mar 12 21:47:19 2013 MANAGEMENT: CMD 'log all on'
Tue Mar 12 21:47:19 2013 MANAGEMENT: CMD 'hold off'
Tue Mar 12 21:47:19 2013 MANAGEMENT: CMD 'hold release'
Tue Mar 12 21:47:19 2013 NOTE: OpenVPN 2.1 requires '--script-security 2' or higher to call user-defined scripts or executables
Tue Mar 12 21:47:19 2013 Socket Buffers: R=[8192->8192] S=[8192->8192]
Tue Mar 12 21:47:19 2013 UDPv4 link local: [undef]
Tue Mar 12 21:47:19 2013 UDPv4 link remote: [AF_INET]161.42.38.61:1194
Tue Mar 12 21:47:19 2013 MANAGEMENT: >STATE:1363146439,WAIT,,,
Tue Mar 12 21:48:19 2013 TLS Error: TLS key negotiation failed to occur within 60 seconds (check your network connectivity)
Tue Mar 12 21:48:19 2013 TLS Error: TLS handshake failed
Tue Mar 12 21:48:19 2013 SIGUSR1[soft,tls-error] received, process restarting
Tue Mar 12 21:48:19 2013 MANAGEMENT: >STATE:1363146499,RECONNECTING,tls-error,,
Tue Mar 12 21:48:19 2013 Restart pause, 2 second(s)
When I run "netstat -an" on the server, I see this line referring to port 1194:
Proto Local Address Foreign Address State
UDP 0.0.0.0:1194 *:*
Here's my client1.opvn:
client
dev tun
dev-node MyTap
proto udp
remote 161.42.38.61 1194
resolv-retry infinite
nobind
persist-key
persist-tun
ca "c:\\program files\\openvpn\\config\\ca.crt"
cert "c:\\program files\\openvpn\\config\\client1.crt"
key "c:\\program files\\openvpn\\config\\client1.key"
ns-cert-type server
comp-lzo
verb 3
Here's my server.opvn:
port 1194
proto udp
dev tun
ca "C:\\Program Files\\OpenVPN\\easy-rsa\\keys\\ca.crt"
cert "C:\\Program Files\\OpenVPN\\easy-rsa\\keys\\server.crt"
key "C:\\Program Files\\OpenVPN\\easy-rsa\\keys\\server.key"
dh "C:\\Program Files\\OpenVPN\\easy-rsa\\keys\\dh1024.pem"
server 10.8.0.0 255.255.255.0
ifconfig-pool-persist ipp.txt
keepalive 10 120
comp-lzo
persist-key
persist-tun
status openvpn-status.log
verb 0
Any help would be greatly appreciated before I go totally bald.
~Steve