IP Address not changing
Posted: Tue Apr 30, 2019 6:00 am
This is my first post in this forum. I recently installed openvpn in openwrt 18.06 in ASUS RT-AC58U.
1. My public ip is xx:xxx:xxx:xxx which is a static ip provided by my ISP.
2. The IP of my ASUS AC58c is 192.168.2.1
3. My Computer LAN Ip is 192.168.2.7
4. VPN Server IP is 10.8.0.1 and the IP of the VPN Client (my computer through Windows TAP adapter VP) is 10.8.0.3)
5. My vpnserver conf file is as below
# Install packages
opkg update
opkg install openvpn-openssl
# Generate TLS PSK
EASYRSA_PKI="/etc/easy-rsa/pki"
openvpn --genkey --secret "${EASYRSA_PKI}/tc.pem"
# Configuration parameters
VPN_DEV="$(uci get firewall.@zone[0].device)"
VPN_POOL="10.8.0.0 255.255.255.0"
VPN_DNS="${VPN_POOL%.* *}.1"
VPN_DOMAIN="$(uci get dhcp.@dnsmasq[0].domain)"
EASYRSA_PKI="/etc/easy-rsa/pki"
DH_KEY="$(cat "${EASYRSA_PKI}/dh.pem")"
TC_KEY="$(sed -e "/^#/d;/^\w/N;s/\n//" "${EASYRSA_PKI}/tc.pem")"
CA_CERT="$(openssl x509 -in "${EASYRSA_PKI}/ca.crt")"
NL=$'\n'
# Configure VPN server
grep -l -r -e "TLS Web Server Authentication" "${EASYRSA_PKI}/issued" \
| sed -e "s/^.*\///;s/\.\w*$//" \
| while read VPN_ID
do
VPN_CONF="/etc/openvpn/${VPN_ID}.conf"
VPN_CERT="$(openssl x509 -in "${EASYRSA_PKI}/issued/${VPN_ID}.crt")"
VPN_KEY="$(cat "${EASYRSA_PKI}/private/${VPN_ID}.key")"
cat << EOF > "${VPN_CONF}"
verb 3
user nobody
group nogroup
dev ${VPN_DEV}
port 1194
proto udp
server ${VPN_POOL}
topology subnet
keepalive 10 120
persist-tun
persist-key
push "dhcp-option DNS ${VPN_DNS}"
push "dhcp-option DOMAIN ${VPN_DOMAIN}"
push "redirect-gateway def1"
push "persist-tun"
push "persist-key"
<dh>${NL}${DH_KEY}${NL}</dh>
<tls-crypt>${NL}${TC_KEY}${NL}</tls-crypt>
<ca>${NL}${CA_CERT}${NL}</ca>
<cert>${NL}${VPN_CERT}${NL}</cert>
<key>${NL}${VPN_KEY}${NL}</key>
EOF
chmod "u=rw,g=,o=" "${VPN_CONF}"
done
service openvpn restart
6: My Vpnclient configuration file is as below
verb 5
dev tun
nobind
client
redirect-gateway def1
remote xx.230.xx.xxx 1194 udp
float
auth-nocache
remote-cert-tls server
<tls-crypt>
-----BEGIN OpenVPN Static key V1-----
xxxx
-----END OpenVPN Static key V1-----
</tls-crypt>
<ca>
-----BEGIN CERTIFICATE-----
xx
-----END CERTIFICATE-----
</ca>
<cert>
-----BEGIN CERTIFICATE-----
xxx
-----END CERTIFICATE-----
</cert>
<key>
-----BEGIN PRIVATE KEY-----
xxx
-----END PRIVATE KEY-----
</key>
user nobody
group nogroup
dev tun0
7: In the CCD folder the vpnclient file has the following details
ifconfig-push 192.168.8.2 255.255.255.0
ifconfig-ipv6-push fdf1:7610:d152:3a9c::2/64
iroute 192.168.100.0 255.255.255.0
8. I am able to ping VPN Server 10.8.0.1 from my computer and I am able to ping 10.8.2.3 from the the server
9 Internet is working fine.
10. The route Print from Windows 10 is as below
C:\WINDOWS\system32>route print
===========================================================================
Interface List
17...00 ff b6 53 3f 32 ......TAP-Windows Adapter V9
18...00 0f 0f 60 11 c1 ......Realtek RTL8188FTV Wireless LAN 802.11n USB 2.0 Network Adapter
10...02 0f 0f 60 11 c1 ......Microsoft Wi-Fi Direct Virtual Adapter
4...00 0f 0f 60 11 c1 ......Microsoft Wi-Fi Direct Virtual Adapter #2
5...00 d8 61 31 0a 35 ......Realtek PCIe GBE Family Controller
9...00 ff 36 06 3c 9a ......Kaspersky Security Data Escort Adapter
1...........................Software Loopback Interface 1
===========================================================================
IPv4 Route Table
===========================================================================
Active Routes:
Network Destination Netmask Gateway Interface Metric
0.0.0.0 0.0.0.0 192.168.2.1 192.168.2.7 35
0.0.0.0 128.0.0.0 10.8.0.1 10.8.0.3 259
10.8.0.0 255.255.255.0 On-link 10.8.0.3 259
10.8.0.3 255.255.255.255 On-link 10.8.0.3 259
10.8.0.255 255.255.255.255 On-link 10.8.0.3 259
127.0.0.0 255.0.0.0 On-link 127.0.0.1 331
127.0.0.1 255.255.255.255 On-link 127.0.0.1 331
127.255.255.255 255.255.255.255 On-link 127.0.0.1 331
128.0.0.0 128.0.0.0 10.8.0.1 10.8.0.3 259
192.168.2.0 255.255.255.0 On-link 192.168.2.7 291
192.168.2.1 255.255.255.255 192.168.2.1 192.168.2.7 291
192.168.2.7 255.255.255.255 On-link 192.168.2.7 291
192.168.2.255 255.255.255.255 On-link 192.168.2.7 291
224.0.0.0 240.0.0.0 On-link 127.0.0.1 331
224.0.0.0 240.0.0.0 On-link 10.8.0.3 259
224.0.0.0 240.0.0.0 On-link 192.168.2.7 291
255.255.255.255 255.255.255.255 On-link 127.0.0.1 331
255.255.255.255 255.255.255.255 On-link 10.8.0.3 259
255.255.255.255 255.255.255.255 On-link 192.168.2.7 291
===========================================================================
Persistent Routes:
None
IPv6 Route Table
===========================================================================
Active Routes:
If Metric Network Destination Gateway
1 331 ::1/128 On-link
5 291 fdb5:39cd:1ddc::/48 fe80::42b0:76ff:fe58:c858
5 291 fdb5:39cd:1ddc::/64 On-link
5 291 fdb5:39cd:1ddc::7/128 On-link
5 291 fdb5:39cd:1ddc:0:2162:a2a:5c04:a11/128
On-link
5 291 fdb5:39cd:1ddc:0:242f:336b:77e4:cb55/128
On-link
17 259 fe80::/64 On-link
5 291 fe80::/64 On-link
5 291 fe80::2162:a2a:5c04:a11/128
On-link
17 259 fe80::c913:f45d:7f7b:5ea2/128
On-link
1 331 ff00::/8 On-link
17 259 ff00::/8 On-link
5 291 ff00::/8 On-link
===========================================================================
Persistent Routes:
None
====================================================================
11: Route -n from vpnserver terminal is as below.
root@OpenWrt:/etc/openvpn# route -n
Kernel IP routing table
Destination Gateway Genmask Flags Metric Ref Use Iface
0.0.0.0 103.206.8.74 0.0.0.0 UG 0 0 0 pppoe-wan
10.8.0.0 0.0.0.0 255.255.255.0 U 0 0 0 tun0
103.206.8.74 0.0.0.0 255.255.255.255 UH 0 0 0 pppoe-wan
192.168.2.0 0.0.0.0 255.255.255.0 U 0 0 0 br-lan
12. Trace route of openwrt.org from vpnserver terminal is as below
root@OpenWrt:/etc/openvpn# traceroute openvpn.org
traceroute to openvpn.org (104.16.184.48), 30 hops max, 38 byte packets
1 103.206.8.74 (103.206.8.74) 0.903 ms 1.314 ms 1.231 ms
2 * * *
3 103.38.129.22 (103.38.129.22) 2.857 ms 1.493 ms 1.661 ms
4 * * *
5 14.143.172.17.static-Kolkatta.vsnl.net.in (14.143.172.17) 2.008 ms 1.489 ms 1.761 ms
6 172.23.78.238 (172.23.78.238) 33.567 ms 28.901 ms 33.056 ms
7 14.142.22.202.static-Mumbai.vsnl.net.in (14.142.22.202) 35.004 ms 35.213 ms 29.446 ms
8 * * *
9 220.227.70.97 (220.227.70.97) 34.847 ms 34.499 ms 40.082 ms
10 104.16.184.48 (104.16.184.48) 52.115 ms 34.127 ms 34.125 ms
root@OpenWrt:/etc/openvpn#
13. Trace route of openwrt.org from windows 10 command prompt with vpn connected is as below
C:\WINDOWS\system32>tracert openwrt.org
Tracing route to openwrt.org [139.59.209.225]
over a maximum of 30 hops:
1 1 ms 1 ms 1 ms 10.8.0.1
2 2 ms 1 ms 2 ms 103.206.8.74
3 4 ms * * 103.38.129.65
4 3 ms 2 ms 2 ms 14.143.172.17.static-Kolkatta.vsnl.net.in [14.143.172.17]
5 32 ms 33 ms 33 ms 172.23.183.134
6 37 ms 32 ms 32 ms ix-ae-0-100.tcore1.mlv-mumbai.as6453.net [180.87.38.5]
7 166 ms 166 ms 163 ms if-ae-5-2.tcore1.wyn-marseille.as6453.net [80.231.217.29]
8 164 ms 159 ms 163 ms if-ae-2-2.tcore2.wyn-marseille.as6453.net [80.231.217.2]
9 163 ms 162 ms 163 ms if-ae-7-2.tcore2.fnm-frankfurt.as6453.net [80.231.200.78]
10 153 ms 151 ms 150 ms if-ae-4-2.tcore1.fr0-frankfurt.as6453.net [195.219.87.18]
11 163 ms 163 ms 189 ms 195.219.50.42
12 * * * Request timed out.
13 170 ms 169 ms 166 ms wiki-01.infra.openwrt.org [139.59.209.225]
Trace complete.
14. Trace route of openvpn.org from windows10 command prompt without vpn connection is as below
C:\WINDOWS\system32>tracert openwrt.org
Tracing route to openwrt.org [139.59.209.225]
over a maximum of 30 hops:
1 <1 ms <1 ms <1 ms OpenWrt.lan [192.168.2.1]
2 1 ms <1 ms 1 ms 103.206.8.74
3 * * * Request timed out.
4 2 ms 3 ms 2 ms 14.143.172.17.static-Kolkatta.vsnl.net.in [14.143.172.17]
5 29 ms 29 ms 29 ms 172.23.183.134
6 31 ms 30 ms 29 ms ix-ae-0-100.tcore1.mlv-mumbai.as6453.net [180.87.38.5]
7 161 ms 161 ms 161 ms if-ae-5-2.tcore1.wyn-marseille.as6453.net [80.231.217.29]
8 158 ms 160 ms 163 ms if-ae-2-2.tcore2.wyn-marseille.as6453.net [80.231.217.2]
9 156 ms 156 ms 171 ms if-ae-7-2.tcore2.fnm-frankfurt.as6453.net [80.231.200.78]
10 147 ms 146 ms 146 ms if-ae-4-2.tcore1.fr0-frankfurt.as6453.net [195.219.87.18]
11 160 ms 160 ms 162 ms 195.219.50.42
12 * * * Request timed out.
13 164 ms 163 ms 163 ms wiki-01.infra.openwrt.org [139.59.209.225]
Trace complete.
14. Log of VPN Client is as below
Tue Apr 30 11:12:34 2019 us=700676 Current Parameter Settings:
Tue Apr 30 11:12:34 2019 us=700676 config = 'vpnclient1.ovpn'
Tue Apr 30 11:12:34 2019 us=700676 mode = 0
Tue Apr 30 11:12:34 2019 us=700676 show_ciphers = DISABLED
Tue Apr 30 11:12:34 2019 us=700676 show_digests = DISABLED
Tue Apr 30 11:12:34 2019 us=700676 show_engines = DISABLED
Tue Apr 30 11:12:34 2019 us=700676 genkey = DISABLED
Tue Apr 30 11:12:34 2019 us=700676 key_pass_file = '[UNDEF]'
Tue Apr 30 11:12:34 2019 us=700676 show_tls_ciphers = DISABLED
Tue Apr 30 11:12:34 2019 us=700676 connect_retry_max = 0
Tue Apr 30 11:12:34 2019 us=700676 Connection profiles [0]:
Tue Apr 30 11:12:34 2019 us=700676 proto = udp
Tue Apr 30 11:12:34 2019 us=700676 local = '[UNDEF]'
Tue Apr 30 11:12:34 2019 us=700676 local_port = '[UNDEF]'
Tue Apr 30 11:12:34 2019 us=700676 remote = '43.230.40.122'
Tue Apr 30 11:12:34 2019 us=700676 remote_port = '1194'
Tue Apr 30 11:12:34 2019 us=700676 remote_float = ENABLED
Tue Apr 30 11:12:34 2019 us=700676 bind_defined = DISABLED
Tue Apr 30 11:12:34 2019 us=700676 bind_local = DISABLED
Tue Apr 30 11:12:34 2019 us=700676 bind_ipv6_only = DISABLED
Tue Apr 30 11:12:34 2019 us=700676 connect_retry_seconds = 5
Tue Apr 30 11:12:34 2019 us=700676 connect_timeout = 120
Tue Apr 30 11:12:34 2019 us=700676 socks_proxy_server = '[UNDEF]'
Tue Apr 30 11:12:34 2019 us=700676 socks_proxy_port = '[UNDEF]'
Tue Apr 30 11:12:34 2019 us=700676 tun_mtu = 1500
Tue Apr 30 11:12:34 2019 us=700676 tun_mtu_defined = ENABLED
Tue Apr 30 11:12:34 2019 us=700676 link_mtu = 1500
Tue Apr 30 11:12:34 2019 us=700676 link_mtu_defined = DISABLED
Tue Apr 30 11:12:34 2019 us=700676 tun_mtu_extra = 0
Tue Apr 30 11:12:34 2019 us=700676 tun_mtu_extra_defined = DISABLED
Tue Apr 30 11:12:34 2019 us=700676 mtu_discover_type = -1
Tue Apr 30 11:12:34 2019 us=700676 fragment = 0
Tue Apr 30 11:12:34 2019 us=700676 mssfix = 1450
Tue Apr 30 11:12:34 2019 us=700676 explicit_exit_notification = 0
Tue Apr 30 11:12:34 2019 us=700676 Connection profiles END
Tue Apr 30 11:12:34 2019 us=700676 remote_random = DISABLED
Tue Apr 30 11:12:34 2019 us=700676 ipchange = '[UNDEF]'
Tue Apr 30 11:12:34 2019 us=700676 dev = 'tun'
Tue Apr 30 11:12:34 2019 us=700676 dev_type = '[UNDEF]'
Tue Apr 30 11:12:34 2019 us=700676 dev_node = '[UNDEF]'
Tue Apr 30 11:12:34 2019 us=700676 lladdr = '[UNDEF]'
Tue Apr 30 11:12:34 2019 us=700676 topology = 1
Tue Apr 30 11:12:34 2019 us=700676 ifconfig_local = '[UNDEF]'
Tue Apr 30 11:12:34 2019 us=700676 ifconfig_remote_netmask = '[UNDEF]'
Tue Apr 30 11:12:34 2019 us=701679 ifconfig_noexec = DISABLED
Tue Apr 30 11:12:34 2019 us=701679 ifconfig_nowarn = DISABLED
Tue Apr 30 11:12:34 2019 us=701679 ifconfig_ipv6_local = '[UNDEF]'
Tue Apr 30 11:12:34 2019 us=701679 ifconfig_ipv6_netbits = 0
Tue Apr 30 11:12:34 2019 us=701679 ifconfig_ipv6_remote = '[UNDEF]'
Tue Apr 30 11:12:34 2019 us=701679 shaper = 0
Tue Apr 30 11:12:34 2019 us=701679 mtu_test = 0
Tue Apr 30 11:12:34 2019 us=701679 mlock = DISABLED
Tue Apr 30 11:12:34 2019 us=701679 keepalive_ping = 0
Tue Apr 30 11:12:34 2019 us=701679 keepalive_timeout = 0
Tue Apr 30 11:12:34 2019 us=701679 inactivity_timeout = 0
Tue Apr 30 11:12:34 2019 us=701679 ping_send_timeout = 0
Tue Apr 30 11:12:34 2019 us=701679 ping_rec_timeout = 0
Tue Apr 30 11:12:34 2019 us=701679 ping_rec_timeout_action = 0
Tue Apr 30 11:12:34 2019 us=701679 ping_timer_remote = DISABLED
Tue Apr 30 11:12:34 2019 us=701679 remap_sigusr1 = 0
Tue Apr 30 11:12:34 2019 us=701679 persist_tun = DISABLED
Tue Apr 30 11:12:34 2019 us=701679 persist_local_ip = DISABLED
Tue Apr 30 11:12:34 2019 us=701679 persist_remote_ip = DISABLED
Tue Apr 30 11:12:34 2019 us=701679 persist_key = DISABLED
Tue Apr 30 11:12:34 2019 us=701679 passtos = DISABLED
Tue Apr 30 11:12:34 2019 us=701679 resolve_retry_seconds = 1000000000
Tue Apr 30 11:12:34 2019 us=701679 resolve_in_advance = DISABLED
Tue Apr 30 11:12:34 2019 us=701679 username = '[UNDEF]'
Tue Apr 30 11:12:34 2019 us=701679 groupname = '[UNDEF]'
Tue Apr 30 11:12:34 2019 us=701679 chroot_dir = '[UNDEF]'
Tue Apr 30 11:12:34 2019 us=701679 cd_dir = '[UNDEF]'
Tue Apr 30 11:12:34 2019 us=701679 writepid = '[UNDEF]'
Tue Apr 30 11:12:34 2019 us=701679 up_script = '[UNDEF]'
Tue Apr 30 11:12:34 2019 us=701679 down_script = '[UNDEF]'
Tue Apr 30 11:12:34 2019 us=701679 down_pre = DISABLED
Tue Apr 30 11:12:34 2019 us=701679 up_restart = DISABLED
Tue Apr 30 11:12:34 2019 us=701679 up_delay = DISABLED
Tue Apr 30 11:12:34 2019 us=701679 daemon = DISABLED
Tue Apr 30 11:12:34 2019 us=701679 inetd = 0
Tue Apr 30 11:12:34 2019 us=701679 log = ENABLED
Tue Apr 30 11:12:34 2019 us=701679 suppress_timestamps = DISABLED
Tue Apr 30 11:12:34 2019 us=701679 machine_readable_output = DISABLED
Tue Apr 30 11:12:34 2019 us=701679 nice = 0
Tue Apr 30 11:12:34 2019 us=701679 verbosity = 4
Tue Apr 30 11:12:34 2019 us=701679 mute = 0
Tue Apr 30 11:12:34 2019 us=701679 gremlin = 0
Tue Apr 30 11:12:34 2019 us=701679 status_file = '[UNDEF]'
Tue Apr 30 11:12:34 2019 us=701679 status_file_version = 1
Tue Apr 30 11:12:34 2019 us=701679 status_file_update_freq = 60
Tue Apr 30 11:12:34 2019 us=701679 occ = ENABLED
Tue Apr 30 11:12:34 2019 us=701679 rcvbuf = 0
Tue Apr 30 11:12:34 2019 us=701679 sndbuf = 0
Tue Apr 30 11:12:34 2019 us=701679 sockflags = 0
Tue Apr 30 11:12:34 2019 us=701679 fast_io = DISABLED
Tue Apr 30 11:12:34 2019 us=701679 comp.alg = 0
Tue Apr 30 11:12:34 2019 us=701679 comp.flags = 0
Tue Apr 30 11:12:34 2019 us=701679 route_script = '[UNDEF]'
Tue Apr 30 11:12:34 2019 us=701679 route_default_gateway = '[UNDEF]'
Tue Apr 30 11:12:34 2019 us=701679 route_default_metric = 0
Tue Apr 30 11:12:34 2019 us=701679 route_noexec = DISABLED
Tue Apr 30 11:12:34 2019 us=701679 route_delay = 5
Tue Apr 30 11:12:34 2019 us=701679 route_delay_window = 30
Tue Apr 30 11:12:34 2019 us=701679 route_delay_defined = ENABLED
Tue Apr 30 11:12:34 2019 us=701679 route_nopull = DISABLED
Tue Apr 30 11:12:34 2019 us=701679 route_gateway_via_dhcp = DISABLED
Tue Apr 30 11:12:34 2019 us=701679 allow_pull_fqdn = DISABLED
Tue Apr 30 11:12:34 2019 us=701679 Pull filters:
Tue Apr 30 11:12:34 2019 us=701679 ignore "route-method"
Tue Apr 30 11:12:34 2019 us=701679 [redirect_default_gateway local=0]
Tue Apr 30 11:12:34 2019 us=701679 management_addr = '127.0.0.1'
Tue Apr 30 11:12:34 2019 us=701679 management_port = '25341'
Tue Apr 30 11:12:34 2019 us=701679 management_user_pass = 'stdin'
Tue Apr 30 11:12:34 2019 us=701679 management_log_history_cache = 250
Tue Apr 30 11:12:34 2019 us=701679 management_echo_buffer_size = 100
Tue Apr 30 11:12:34 2019 us=701679 management_write_peer_info_file = '[UNDEF]'
Tue Apr 30 11:12:34 2019 us=701679 management_client_user = '[UNDEF]'
Tue Apr 30 11:12:34 2019 us=701679 management_client_group = '[UNDEF]'
Tue Apr 30 11:12:34 2019 us=701679 management_flags = 6
Tue Apr 30 11:12:34 2019 us=701679 shared_secret_file = '[UNDEF]'
Tue Apr 30 11:12:34 2019 us=701679 key_direction = not set
Tue Apr 30 11:12:34 2019 us=701679 ciphername = 'BF-CBC'
Tue Apr 30 11:12:34 2019 us=701679 ncp_enabled = ENABLED
Tue Apr 30 11:12:34 2019 us=701679 ncp_ciphers = 'AES-256-GCM:AES-128-GCM'
Tue Apr 30 11:12:34 2019 us=701679 authname = 'SHA1'
Tue Apr 30 11:12:34 2019 us=701679 prng_hash = 'SHA1'
Tue Apr 30 11:12:34 2019 us=701679 prng_nonce_secret_len = 16
Tue Apr 30 11:12:34 2019 us=701679 keysize = 0
Tue Apr 30 11:12:34 2019 us=701679 engine = DISABLED
Tue Apr 30 11:12:34 2019 us=701679 replay = ENABLED
Tue Apr 30 11:12:34 2019 us=701679 mute_replay_warnings = DISABLED
Tue Apr 30 11:12:34 2019 us=701679 replay_window = 64
Tue Apr 30 11:12:34 2019 us=701679 replay_time = 15
Tue Apr 30 11:12:34 2019 us=701679 packet_id_file = '[UNDEF]'
Tue Apr 30 11:12:34 2019 us=701679 use_iv = ENABLED
Tue Apr 30 11:12:34 2019 us=701679 test_crypto = DISABLED
Tue Apr 30 11:12:34 2019 us=701679 tls_server = DISABLED
Tue Apr 30 11:12:34 2019 us=701679 tls_client = ENABLED
Tue Apr 30 11:12:34 2019 us=701679 key_method = 2
Tue Apr 30 11:12:34 2019 us=701679 ca_file = '[[INLINE]]'
Tue Apr 30 11:12:34 2019 us=701679 ca_path = '[UNDEF]'
Tue Apr 30 11:12:34 2019 us=701679 dh_file = '[UNDEF]'
Tue Apr 30 11:12:34 2019 us=701679 cert_file = '[[INLINE]]'
Tue Apr 30 11:12:34 2019 us=701679 extra_certs_file = '[UNDEF]'
Tue Apr 30 11:12:34 2019 us=701679 priv_key_file = '[[INLINE]]'
Tue Apr 30 11:12:34 2019 us=701679 pkcs12_file = '[UNDEF]'
Tue Apr 30 11:12:34 2019 us=701679 cryptoapi_cert = '[UNDEF]'
Tue Apr 30 11:12:34 2019 us=701679 cipher_list = '[UNDEF]'
Tue Apr 30 11:12:34 2019 us=701679 cipher_list_tls13 = '[UNDEF]'
Tue Apr 30 11:12:34 2019 us=701679 tls_cert_profile = '[UNDEF]'
Tue Apr 30 11:12:34 2019 us=701679 tls_verify = '[UNDEF]'
Tue Apr 30 11:12:34 2019 us=701679 tls_export_cert = '[UNDEF]'
Tue Apr 30 11:12:34 2019 us=701679 verify_x509_type = 0
Tue Apr 30 11:12:34 2019 us=701679 verify_x509_name = '[UNDEF]'
Tue Apr 30 11:12:34 2019 us=701679 crl_file = '[UNDEF]'
Tue Apr 30 11:12:34 2019 us=701679 ns_cert_type = 0
Tue Apr 30 11:12:34 2019 us=701679 remote_cert_ku = 65535
Tue Apr 30 11:12:34 2019 us=701679 remote_cert_ku = 0
Tue Apr 30 11:12:34 2019 us=701679 remote_cert_ku = 0
Tue Apr 30 11:12:34 2019 us=701679 remote_cert_ku = 0
Tue Apr 30 11:12:34 2019 us=701679 remote_cert_ku = 0
Tue Apr 30 11:12:34 2019 us=701679 remote_cert_ku = 0
Tue Apr 30 11:12:34 2019 us=701679 remote_cert_ku = 0
Tue Apr 30 11:12:34 2019 us=701679 remote_cert_ku = 0
Tue Apr 30 11:12:34 2019 us=701679 remote_cert_ku = 0
Tue Apr 30 11:12:34 2019 us=701679 remote_cert_ku = 0
Tue Apr 30 11:12:34 2019 us=701679 remote_cert_ku[i] = 0
Tue Apr 30 11:12:34 2019 us=701679 remote_cert_ku[i] = 0
Tue Apr 30 11:12:34 2019 us=701679 remote_cert_ku[i] = 0
Tue Apr 30 11:12:34 2019 us=701679 remote_cert_ku[i] = 0
Tue Apr 30 11:12:34 2019 us=701679 remote_cert_ku[i] = 0
Tue Apr 30 11:12:34 2019 us=701679 remote_cert_ku[i] = 0
Tue Apr 30 11:12:34 2019 us=701679 remote_cert_eku = 'TLS Web Server Authentication'
Tue Apr 30 11:12:34 2019 us=701679 ssl_flags = 0
Tue Apr 30 11:12:34 2019 us=701679 tls_timeout = 2
Tue Apr 30 11:12:34 2019 us=701679 renegotiate_bytes = -1
Tue Apr 30 11:12:34 2019 us=701679 renegotiate_packets = 0
Tue Apr 30 11:12:34 2019 us=701679 renegotiate_seconds = 3600
Tue Apr 30 11:12:34 2019 us=701679 handshake_window = 60
Tue Apr 30 11:12:34 2019 us=701679 transition_window = 3600
Tue Apr 30 11:12:34 2019 us=701679 single_session = DISABLED
Tue Apr 30 11:12:34 2019 us=701679 push_peer_info = DISABLED
Tue Apr 30 11:12:34 2019 us=701679 tls_exit = DISABLED
Tue Apr 30 11:12:34 2019 us=701679 tls_auth_file = '[UNDEF]'
Tue Apr 30 11:12:34 2019 us=701679 tls_crypt_file = '[[INLINE]]'
Tue Apr 30 11:12:34 2019 us=701679 pkcs11_protected_authentication = DISABLED
Tue Apr 30 11:12:34 2019 us=701679 pkcs11_protected_authentication = DISABLED
Tue Apr 30 11:12:34 2019 us=701679 pkcs11_protected_authentication = DISABLED
Tue Apr 30 11:12:34 2019 us=701679 pkcs11_protected_authentication = DISABLED
Tue Apr 30 11:12:34 2019 us=701679 pkcs11_protected_authentication = DISABLED
Tue Apr 30 11:12:34 2019 us=701679 pkcs11_protected_authentication = DISABLED
Tue Apr 30 11:12:34 2019 us=702682 pkcs11_protected_authentication = DISABLED
Tue Apr 30 11:12:34 2019 us=702682 pkcs11_protected_authentication = DISABLED
Tue Apr 30 11:12:34 2019 us=702682 pkcs11_protected_authentication = DISABLED
Tue Apr 30 11:12:34 2019 us=702682 pkcs11_protected_authentication = DISABLED
Tue Apr 30 11:12:34 2019 us=702682 pkcs11_protected_authentication = DISABLED
Tue Apr 30 11:12:34 2019 us=702682 pkcs11_protected_authentication = DISABLED
Tue Apr 30 11:12:34 2019 us=702682 pkcs11_protected_authentication = DISABLED
Tue Apr 30 11:12:34 2019 us=702682 pkcs11_protected_authentication = DISABLED
Tue Apr 30 11:12:34 2019 us=702682 pkcs11_protected_authentication = DISABLED
Tue Apr 30 11:12:34 2019 us=702682 pkcs11_protected_authentication = DISABLED
Tue Apr 30 11:12:34 2019 us=702682 pkcs11_private_mode = 00000000
Tue Apr 30 11:12:34 2019 us=702682 pkcs11_private_mode = 00000000
Tue Apr 30 11:12:34 2019 us=702682 pkcs11_private_mode = 00000000
Tue Apr 30 11:12:34 2019 us=702682 pkcs11_private_mode = 00000000
Tue Apr 30 11:12:34 2019 us=702682 pkcs11_private_mode = 00000000
Tue Apr 30 11:12:34 2019 us=702682 pkcs11_private_mode = 00000000
Tue Apr 30 11:12:34 2019 us=702682 pkcs11_private_mode = 00000000
Tue Apr 30 11:12:34 2019 us=702682 pkcs11_private_mode = 00000000
Tue Apr 30 11:12:34 2019 us=702682 pkcs11_private_mode = 00000000
Tue Apr 30 11:12:34 2019 us=702682 pkcs11_private_mode = 00000000
Tue Apr 30 11:12:34 2019 us=702682 pkcs11_private_mode = 00000000
Tue Apr 30 11:12:34 2019 us=702682 pkcs11_private_mode = 00000000
Tue Apr 30 11:12:34 2019 us=702682 pkcs11_private_mode = 00000000
Tue Apr 30 11:12:34 2019 us=702682 pkcs11_private_mode = 00000000
Tue Apr 30 11:12:34 2019 us=702682 pkcs11_private_mode = 00000000
Tue Apr 30 11:12:34 2019 us=702682 pkcs11_private_mode = 00000000
Tue Apr 30 11:12:34 2019 us=702682 pkcs11_cert_private = DISABLED
Tue Apr 30 11:12:34 2019 us=702682 pkcs11_cert_private = DISABLED
Tue Apr 30 11:12:34 2019 us=702682 pkcs11_cert_private = DISABLED
Tue Apr 30 11:12:34 2019 us=702682 pkcs11_cert_private = DISABLED
Tue Apr 30 11:12:34 2019 us=702682 pkcs11_cert_private = DISABLED
Tue Apr 30 11:12:34 2019 us=702682 pkcs11_cert_private = DISABLED
Tue Apr 30 11:12:34 2019 us=702682 pkcs11_cert_private = DISABLED
Tue Apr 30 11:12:34 2019 us=702682 pkcs11_cert_private = DISABLED
Tue Apr 30 11:12:34 2019 us=702682 pkcs11_cert_private = DISABLED
Tue Apr 30 11:12:34 2019 us=702682 pkcs11_cert_private = DISABLED
Tue Apr 30 11:12:34 2019 us=702682 pkcs11_cert_private = DISABLED
Tue Apr 30 11:12:34 2019 us=702682 pkcs11_cert_private = DISABLED
Tue Apr 30 11:12:34 2019 us=702682 pkcs11_cert_private = DISABLED
Tue Apr 30 11:12:34 2019 us=702682 pkcs11_cert_private = DISABLED
Tue Apr 30 11:12:34 2019 us=702682 pkcs11_cert_private = DISABLED
Tue Apr 30 11:12:34 2019 us=702682 pkcs11_cert_private = DISABLED
Tue Apr 30 11:12:34 2019 us=702682 pkcs11_pin_cache_period = -1
Tue Apr 30 11:12:34 2019 us=702682 pkcs11_id = '[UNDEF]'
Tue Apr 30 11:12:34 2019 us=702682 pkcs11_id_management = DISABLED
Tue Apr 30 11:12:34 2019 us=702682 server_network = 0.0.0.0
Tue Apr 30 11:12:34 2019 us=702682 server_netmask = 0.0.0.0
Tue Apr 30 11:12:34 2019 us=702682 server_network_ipv6 = ::
Tue Apr 30 11:12:34 2019 us=702682 server_netbits_ipv6 = 0
Tue Apr 30 11:12:34 2019 us=702682 server_bridge_ip = 0.0.0.0
Tue Apr 30 11:12:34 2019 us=702682 server_bridge_netmask = 0.0.0.0
Tue Apr 30 11:12:34 2019 us=702682 server_bridge_pool_start = 0.0.0.0
Tue Apr 30 11:12:34 2019 us=702682 server_bridge_pool_end = 0.0.0.0
Tue Apr 30 11:12:34 2019 us=702682 ifconfig_pool_defined = DISABLED
Tue Apr 30 11:12:34 2019 us=702682 ifconfig_pool_start = 0.0.0.0
Tue Apr 30 11:12:34 2019 us=702682 ifconfig_pool_end = 0.0.0.0
Tue Apr 30 11:12:34 2019 us=702682 ifconfig_pool_netmask = 0.0.0.0
Tue Apr 30 11:12:34 2019 us=702682 ifconfig_pool_persist_filename = '[UNDEF]'
Tue Apr 30 11:12:34 2019 us=702682 ifconfig_pool_persist_refresh_freq = 600
Tue Apr 30 11:12:34 2019 us=702682 ifconfig_ipv6_pool_defined = DISABLED
Tue Apr 30 11:12:34 2019 us=702682 ifconfig_ipv6_pool_base = ::
Tue Apr 30 11:12:34 2019 us=702682 ifconfig_ipv6_pool_netbits = 0
Tue Apr 30 11:12:34 2019 us=702682 n_bcast_buf = 256
Tue Apr 30 11:12:34 2019 us=702682 tcp_queue_limit = 64
Tue Apr 30 11:12:34 2019 us=702682 real_hash_size = 256
Tue Apr 30 11:12:34 2019 us=702682 virtual_hash_size = 256
Tue Apr 30 11:12:34 2019 us=702682 client_connect_script = '[UNDEF]'
Tue Apr 30 11:12:34 2019 us=702682 learn_address_script = '[UNDEF]'
Tue Apr 30 11:12:34 2019 us=702682 client_disconnect_script = '[UNDEF]'
Tue Apr 30 11:12:34 2019 us=702682 client_config_dir = '[UNDEF]'
Tue Apr 30 11:12:34 2019 us=702682 ccd_exclusive = DISABLED
Tue Apr 30 11:12:34 2019 us=702682 tmp_dir = 'C:\Users\Bobra-AG\AppData\Local\Temp\'
Tue Apr 30 11:12:34 2019 us=702682 push_ifconfig_defined = DISABLED
Tue Apr 30 11:12:34 2019 us=702682 push_ifconfig_local = 0.0.0.0
Tue Apr 30 11:12:34 2019 us=702682 push_ifconfig_remote_netmask = 0.0.0.0
Tue Apr 30 11:12:34 2019 us=702682 push_ifconfig_ipv6_defined = DISABLED
Tue Apr 30 11:12:34 2019 us=702682 push_ifconfig_ipv6_local = ::/0
Tue Apr 30 11:12:34 2019 us=702682 push_ifconfig_ipv6_remote = ::
Tue Apr 30 11:12:34 2019 us=702682 enable_c2c = DISABLED
Tue Apr 30 11:12:34 2019 us=702682 duplicate_cn = DISABLED
Tue Apr 30 11:12:34 2019 us=702682 cf_max = 0
Tue Apr 30 11:12:34 2019 us=702682 cf_per = 0
Tue Apr 30 11:12:34 2019 us=702682 max_clients = 1024
Tue Apr 30 11:12:34 2019 us=702682 max_routes_per_client = 256
Tue Apr 30 11:12:34 2019 us=702682 auth_user_pass_verify_script = '[UNDEF]'
Tue Apr 30 11:12:34 2019 us=702682 auth_user_pass_verify_script_via_file = DISABLED
Tue Apr 30 11:12:34 2019 us=702682 auth_token_generate = DISABLED
Tue Apr 30 11:12:34 2019 us=702682 auth_token_lifetime = 0
Tue Apr 30 11:12:34 2019 us=702682 client = ENABLED
Tue Apr 30 11:12:34 2019 us=702682 pull = ENABLED
Tue Apr 30 11:12:34 2019 us=702682 auth_user_pass_file = '[UNDEF]'
Tue Apr 30 11:12:34 2019 us=702682 show_net_up = DISABLED
Tue Apr 30 11:12:34 2019 us=702682 route_method = 3
Tue Apr 30 11:12:34 2019 us=702682 block_outside_dns = DISABLED
Tue Apr 30 11:12:34 2019 us=702682 ip_win32_defined = DISABLED
Tue Apr 30 11:12:34 2019 us=702682 ip_win32_type = 3
Tue Apr 30 11:12:34 2019 us=702682 dhcp_masq_offset = 0
Tue Apr 30 11:12:34 2019 us=702682 dhcp_lease_time = 31536000
Tue Apr 30 11:12:34 2019 us=702682 tap_sleep = 0
Tue Apr 30 11:12:34 2019 us=702682 dhcp_options = DISABLED
Tue Apr 30 11:12:34 2019 us=702682 dhcp_renew = DISABLED
Tue Apr 30 11:12:34 2019 us=702682 dhcp_pre_release = DISABLED
Tue Apr 30 11:12:34 2019 us=702682 domain = '[UNDEF]'
Tue Apr 30 11:12:34 2019 us=702682 netbios_scope = '[UNDEF]'
Tue Apr 30 11:12:34 2019 us=702682 netbios_node_type = 0
Tue Apr 30 11:12:34 2019 us=702682 disable_nbt = DISABLED
Tue Apr 30 11:12:34 2019 us=702682 OpenVPN 2.4.7 x86_64-w64-mingw32 [SSL (OpenSSL)] [LZO] [LZ4] [PKCS11] [AEAD] built on Feb 21 2019
Tue Apr 30 11:12:34 2019 us=702682 Windows version 6.2 (Windows 8 or greater) 64bit
Tue Apr 30 11:12:34 2019 us=702682 library versions: OpenSSL 1.1.0j 20 Nov 2018, LZO 2.10
Enter Management Password:
Tue Apr 30 11:12:34 2019 us=703686 MANAGEMENT: TCP Socket listening on [AF_INET]127.0.0.1:25341
Tue Apr 30 11:12:34 2019 us=703686 Need hold release from management interface, waiting...
Tue Apr 30 11:12:35 2019 us=147261 MANAGEMENT: Client connected from [AF_INET]127.0.0.1:25341
Tue Apr 30 11:12:35 2019 us=248736 MANAGEMENT: CMD 'state on'
Tue Apr 30 11:12:35 2019 us=248736 MANAGEMENT: CMD 'log all on'
Tue Apr 30 11:12:35 2019 us=359083 MANAGEMENT: CMD 'echo all on'
Tue Apr 30 11:12:35 2019 us=361093 MANAGEMENT: CMD 'bytecount 5'
Tue Apr 30 11:12:35 2019 us=362094 MANAGEMENT: CMD 'hold off'
Tue Apr 30 11:12:35 2019 us=364100 MANAGEMENT: CMD 'hold release'
Tue Apr 30 11:12:35 2019 us=366109 Outgoing Control Channel Encryption: Cipher 'AES-256-CTR' initialized with 256 bit key
Tue Apr 30 11:12:35 2019 us=366109 Outgoing Control Channel Encryption: Using 256 bit message hash 'SHA256' for HMAC authentication
Tue Apr 30 11:12:35 2019 us=366109 Incoming Control Channel Encryption: Cipher 'AES-256-CTR' initialized with 256 bit key
Tue Apr 30 11:12:35 2019 us=366109 Incoming Control Channel Encryption: Using 256 bit message hash 'SHA256' for HMAC authentication
Tue Apr 30 11:12:35 2019 us=367111 Control Channel MTU parms [ L:1621 D:1156 EF:94 EB:0 ET:0 EL:3 ]
Tue Apr 30 11:12:35 2019 us=367111 Data Channel MTU parms [ L:1621 D:1450 EF:121 EB:406 ET:0 EL:3 ]
Tue Apr 30 11:12:35 2019 us=367111 Local Options String (VER=V4): 'V4,dev-type tun,link-mtu 1541,tun-mtu 1500,proto UDPv4,cipher BF-CBC,auth SHA1,keysize 128,key-method 2,tls-client'
Tue Apr 30 11:12:35 2019 us=367111 Expected Remote Options String (VER=V4): 'V4,dev-type tun,link-mtu 1541,tun-mtu 1500,proto UDPv4,cipher BF-CBC,auth SHA1,keysize 128,key-method 2,tls-server'
Tue Apr 30 11:12:35 2019 us=367111 TCP/UDP: Preserving recently used remote address: [AF_INET]43.230.40.122:1194
Tue Apr 30 11:12:35 2019 us=367111 Socket Buffers: R=[65536->65536] S=[65536->65536]
Tue Apr 30 11:12:35 2019 us=367111 UDP link local: (not bound)
Tue Apr 30 11:12:35 2019 us=367111 UDP link remote: [AF_INET]43.230.40.122:1194
Tue Apr 30 11:12:35 2019 us=367111 MANAGEMENT: >STATE:1556602955,WAIT,,,,,,
Tue Apr 30 11:12:35 2019 us=378146 MANAGEMENT: >STATE:1556602955,AUTH,,,,,,
Tue Apr 30 11:12:35 2019 us=378146 TLS: Initial packet from [AF_INET]192.168.2.1:1194, sid=1e88f158 77e8ecd6
Tue Apr 30 11:12:35 2019 us=447375 VERIFY OK: depth=1, CN=vpnca
Tue Apr 30 11:12:35 2019 us=447375 VERIFY KU OK
Tue Apr 30 11:12:35 2019 us=447375 Validating certificate extended key usage
Tue Apr 30 11:12:35 2019 us=447375 ++ Certificate has EKU (str) TLS Web Server Authentication, expects TLS Web Server Authentication
Tue Apr 30 11:12:35 2019 us=447375 VERIFY EKU OK
Tue Apr 30 11:12:35 2019 us=447375 VERIFY OK: depth=0, CN=vpnserver
Tue Apr 30 11:12:35 2019 us=476473 Control Channel: TLSv1.2, cipher TLSv1.2 ECDHE-RSA-AES256-GCM-SHA384, 2048 bit RSA
Tue Apr 30 11:12:35 2019 us=476473 [vpnserver] Peer Connection Initiated with [AF_INET]192.168.2.1:1194
Tue Apr 30 11:12:36 2019 us=736861 MANAGEMENT: >STATE:1556602956,GET_CONFIG,,,,,,
Tue Apr 30 11:12:36 2019 us=736861 SENT CONTROL [vpnserver]: 'PUSH_REQUEST' (status=1)
Tue Apr 30 11:12:36 2019 us=756928 PUSH: Received control message: 'PUSH_REPLY,dhcp-option DNS 10.8.0.1,dhcp-option DOMAIN lan,register-dns,block-outside-dns,redirect-gateway def1,persist-tun,persist-key,route-gateway 10.8.0.1,topology subnet,ping 10,ping-restart 120,ifconfig 10.8.0.3 255.255.255.0,peer-id 0,cipher AES-256-GCM'
Tue Apr 30 11:12:36 2019 us=756928 OPTIONS IMPORT: timers and/or timeouts modified
Tue Apr 30 11:12:36 2019 us=756928 OPTIONS IMPORT: --persist options modified
Tue Apr 30 11:12:36 2019 us=756928 OPTIONS IMPORT: --ifconfig/up options modified
Tue Apr 30 11:12:36 2019 us=756928 OPTIONS IMPORT: route options modified
Tue Apr 30 11:12:36 2019 us=756928 OPTIONS IMPORT: route-related options modified
Tue Apr 30 11:12:36 2019 us=756928 OPTIONS IMPORT: --ip-win32 and/or --dhcp-option options modified
Tue Apr 30 11:12:36 2019 us=756928 OPTIONS IMPORT: peer-id set
Tue Apr 30 11:12:36 2019 us=756928 OPTIONS IMPORT: adjusting link_mtu to 1624
Tue Apr 30 11:12:36 2019 us=756928 OPTIONS IMPORT: data channel crypto options modified
Tue Apr 30 11:12:36 2019 us=756928 Data Channel: using negotiated cipher 'AES-256-GCM'
Tue Apr 30 11:12:36 2019 us=756928 Data Channel MTU parms [ L:1552 D:1450 EF:52 EB:406 ET:0 EL:3 ]
Tue Apr 30 11:12:36 2019 us=757931 Outgoing Data Channel: Cipher 'AES-256-GCM' initialized with 256 bit key
Tue Apr 30 11:12:36 2019 us=757931 Incoming Data Channel: Cipher 'AES-256-GCM' initialized with 256 bit key
Tue Apr 30 11:12:36 2019 us=757931 interactive service msg_channel=824
Tue Apr 30 11:12:36 2019 us=765959 ROUTE_GATEWAY 192.168.2.1/255.255.255.0 I=5 HWADDR=00:d8:61:31:0a:35
Tue Apr 30 11:12:36 2019 us=789034 open_tun
Tue Apr 30 11:12:36 2019 us=790037 TAP-WIN32 device [Ethernet 4] opened: \\.\Global\{B6533F32-BEF9-4820-AACD-F92A95AD17EC}.tap
Tue Apr 30 11:12:36 2019 us=791041 TAP-Windows Driver Version 9.21
Tue Apr 30 11:12:36 2019 us=791041 TAP-Windows MTU=1500
Tue Apr 30 11:12:36 2019 us=796057 Set TAP-Windows TUN subnet mode network/local/netmask = 10.8.0.0/10.8.0.3/255.255.255.0 [SUCCEEDED]
Tue Apr 30 11:12:36 2019 us=796057 Notified TAP-Windows driver to set a DHCP IP/netmask of 10.8.0.3/255.255.255.0 on interface {B6533F32-BEF9-4820-AACD-F92A95AD17EC} [DHCP-serv: 10.8.0.254, lease-time: 31536000]
Tue Apr 30 11:12:36 2019 us=796057 DHCP option string: 0f036c61 6e06040a 080001
Tue Apr 30 11:12:36 2019 us=797061 Successful ARP Flush on interface [17] {B6533F32-BEF9-4820-AACD-F92A95AD17EC}
Tue Apr 30 11:12:36 2019 us=816125 do_ifconfig, tt->did_ifconfig_ipv6_setup=0
Tue Apr 30 11:12:36 2019 us=816125 MANAGEMENT: >STATE:1556602956,ASSIGN_IP,,10.8.0.3,,,,
Tue Apr 30 11:12:36 2019 us=816125 Blocking outside DNS
Tue Apr 30 11:12:36 2019 us=816125 Using service to add block dns filters
Tue Apr 30 11:12:36 2019 us=864284 Blocking outside dns using service succeeded.
Tue Apr 30 11:12:41 2019 us=268176 TEST ROUTES: 1/1 succeeded len=0 ret=1 a=0 u/d=up
Tue Apr 30 11:12:41 2019 us=268176 C:\WINDOWS\system32\route.exe ADD 192.168.2.1 MASK 255.255.255.255 192.168.2.1 IF 5
Tue Apr 30 11:12:41 2019 us=273195 Route addition via service succeeded
Tue Apr 30 11:12:41 2019 us=273195 C:\WINDOWS\system32\route.exe ADD 0.0.0.0 MASK 128.0.0.0 10.8.0.1
Tue Apr 30 11:12:41 2019 us=286236 Route addition via service succeeded
Tue Apr 30 11:12:41 2019 us=286236 C:\WINDOWS\system32\route.exe ADD 128.0.0.0 MASK 128.0.0.0 10.8.0.1
Tue Apr 30 11:12:41 2019 us=295265 Route addition via service succeeded
Tue Apr 30 11:12:41 2019 us=295265 Initialization Sequence Completed
Tue Apr 30 11:12:41 2019 us=295265 Register_dns request sent to the service
Tue Apr 30 11:12:41 2019 us=295265 MANAGEMENT: >STATE:1556602961,CONNECTED,SUCCESS,10.8.0.3,192.168.2.1,1194,,
15. Query on my public ip returns actuaally my public ip address without any change.
Can someone guide me further on this.
Thanks
1. My public ip is xx:xxx:xxx:xxx which is a static ip provided by my ISP.
2. The IP of my ASUS AC58c is 192.168.2.1
3. My Computer LAN Ip is 192.168.2.7
4. VPN Server IP is 10.8.0.1 and the IP of the VPN Client (my computer through Windows TAP adapter VP) is 10.8.0.3)
5. My vpnserver conf file is as below
# Install packages
opkg update
opkg install openvpn-openssl
# Generate TLS PSK
EASYRSA_PKI="/etc/easy-rsa/pki"
openvpn --genkey --secret "${EASYRSA_PKI}/tc.pem"
# Configuration parameters
VPN_DEV="$(uci get firewall.@zone[0].device)"
VPN_POOL="10.8.0.0 255.255.255.0"
VPN_DNS="${VPN_POOL%.* *}.1"
VPN_DOMAIN="$(uci get dhcp.@dnsmasq[0].domain)"
EASYRSA_PKI="/etc/easy-rsa/pki"
DH_KEY="$(cat "${EASYRSA_PKI}/dh.pem")"
TC_KEY="$(sed -e "/^#/d;/^\w/N;s/\n//" "${EASYRSA_PKI}/tc.pem")"
CA_CERT="$(openssl x509 -in "${EASYRSA_PKI}/ca.crt")"
NL=$'\n'
# Configure VPN server
grep -l -r -e "TLS Web Server Authentication" "${EASYRSA_PKI}/issued" \
| sed -e "s/^.*\///;s/\.\w*$//" \
| while read VPN_ID
do
VPN_CONF="/etc/openvpn/${VPN_ID}.conf"
VPN_CERT="$(openssl x509 -in "${EASYRSA_PKI}/issued/${VPN_ID}.crt")"
VPN_KEY="$(cat "${EASYRSA_PKI}/private/${VPN_ID}.key")"
cat << EOF > "${VPN_CONF}"
verb 3
user nobody
group nogroup
dev ${VPN_DEV}
port 1194
proto udp
server ${VPN_POOL}
topology subnet
keepalive 10 120
persist-tun
persist-key
push "dhcp-option DNS ${VPN_DNS}"
push "dhcp-option DOMAIN ${VPN_DOMAIN}"
push "redirect-gateway def1"
push "persist-tun"
push "persist-key"
<dh>${NL}${DH_KEY}${NL}</dh>
<tls-crypt>${NL}${TC_KEY}${NL}</tls-crypt>
<ca>${NL}${CA_CERT}${NL}</ca>
<cert>${NL}${VPN_CERT}${NL}</cert>
<key>${NL}${VPN_KEY}${NL}</key>
EOF
chmod "u=rw,g=,o=" "${VPN_CONF}"
done
service openvpn restart
6: My Vpnclient configuration file is as below
verb 5
dev tun
nobind
client
redirect-gateway def1
remote xx.230.xx.xxx 1194 udp
float
auth-nocache
remote-cert-tls server
<tls-crypt>
-----BEGIN OpenVPN Static key V1-----
xxxx
-----END OpenVPN Static key V1-----
</tls-crypt>
<ca>
-----BEGIN CERTIFICATE-----
xx
-----END CERTIFICATE-----
</ca>
<cert>
-----BEGIN CERTIFICATE-----
xxx
-----END CERTIFICATE-----
</cert>
<key>
-----BEGIN PRIVATE KEY-----
xxx
-----END PRIVATE KEY-----
</key>
user nobody
group nogroup
dev tun0
7: In the CCD folder the vpnclient file has the following details
ifconfig-push 192.168.8.2 255.255.255.0
ifconfig-ipv6-push fdf1:7610:d152:3a9c::2/64
iroute 192.168.100.0 255.255.255.0
8. I am able to ping VPN Server 10.8.0.1 from my computer and I am able to ping 10.8.2.3 from the the server
9 Internet is working fine.
10. The route Print from Windows 10 is as below
C:\WINDOWS\system32>route print
===========================================================================
Interface List
17...00 ff b6 53 3f 32 ......TAP-Windows Adapter V9
18...00 0f 0f 60 11 c1 ......Realtek RTL8188FTV Wireless LAN 802.11n USB 2.0 Network Adapter
10...02 0f 0f 60 11 c1 ......Microsoft Wi-Fi Direct Virtual Adapter
4...00 0f 0f 60 11 c1 ......Microsoft Wi-Fi Direct Virtual Adapter #2
5...00 d8 61 31 0a 35 ......Realtek PCIe GBE Family Controller
9...00 ff 36 06 3c 9a ......Kaspersky Security Data Escort Adapter
1...........................Software Loopback Interface 1
===========================================================================
IPv4 Route Table
===========================================================================
Active Routes:
Network Destination Netmask Gateway Interface Metric
0.0.0.0 0.0.0.0 192.168.2.1 192.168.2.7 35
0.0.0.0 128.0.0.0 10.8.0.1 10.8.0.3 259
10.8.0.0 255.255.255.0 On-link 10.8.0.3 259
10.8.0.3 255.255.255.255 On-link 10.8.0.3 259
10.8.0.255 255.255.255.255 On-link 10.8.0.3 259
127.0.0.0 255.0.0.0 On-link 127.0.0.1 331
127.0.0.1 255.255.255.255 On-link 127.0.0.1 331
127.255.255.255 255.255.255.255 On-link 127.0.0.1 331
128.0.0.0 128.0.0.0 10.8.0.1 10.8.0.3 259
192.168.2.0 255.255.255.0 On-link 192.168.2.7 291
192.168.2.1 255.255.255.255 192.168.2.1 192.168.2.7 291
192.168.2.7 255.255.255.255 On-link 192.168.2.7 291
192.168.2.255 255.255.255.255 On-link 192.168.2.7 291
224.0.0.0 240.0.0.0 On-link 127.0.0.1 331
224.0.0.0 240.0.0.0 On-link 10.8.0.3 259
224.0.0.0 240.0.0.0 On-link 192.168.2.7 291
255.255.255.255 255.255.255.255 On-link 127.0.0.1 331
255.255.255.255 255.255.255.255 On-link 10.8.0.3 259
255.255.255.255 255.255.255.255 On-link 192.168.2.7 291
===========================================================================
Persistent Routes:
None
IPv6 Route Table
===========================================================================
Active Routes:
If Metric Network Destination Gateway
1 331 ::1/128 On-link
5 291 fdb5:39cd:1ddc::/48 fe80::42b0:76ff:fe58:c858
5 291 fdb5:39cd:1ddc::/64 On-link
5 291 fdb5:39cd:1ddc::7/128 On-link
5 291 fdb5:39cd:1ddc:0:2162:a2a:5c04:a11/128
On-link
5 291 fdb5:39cd:1ddc:0:242f:336b:77e4:cb55/128
On-link
17 259 fe80::/64 On-link
5 291 fe80::/64 On-link
5 291 fe80::2162:a2a:5c04:a11/128
On-link
17 259 fe80::c913:f45d:7f7b:5ea2/128
On-link
1 331 ff00::/8 On-link
17 259 ff00::/8 On-link
5 291 ff00::/8 On-link
===========================================================================
Persistent Routes:
None
====================================================================
11: Route -n from vpnserver terminal is as below.
root@OpenWrt:/etc/openvpn# route -n
Kernel IP routing table
Destination Gateway Genmask Flags Metric Ref Use Iface
0.0.0.0 103.206.8.74 0.0.0.0 UG 0 0 0 pppoe-wan
10.8.0.0 0.0.0.0 255.255.255.0 U 0 0 0 tun0
103.206.8.74 0.0.0.0 255.255.255.255 UH 0 0 0 pppoe-wan
192.168.2.0 0.0.0.0 255.255.255.0 U 0 0 0 br-lan
12. Trace route of openwrt.org from vpnserver terminal is as below
root@OpenWrt:/etc/openvpn# traceroute openvpn.org
traceroute to openvpn.org (104.16.184.48), 30 hops max, 38 byte packets
1 103.206.8.74 (103.206.8.74) 0.903 ms 1.314 ms 1.231 ms
2 * * *
3 103.38.129.22 (103.38.129.22) 2.857 ms 1.493 ms 1.661 ms
4 * * *
5 14.143.172.17.static-Kolkatta.vsnl.net.in (14.143.172.17) 2.008 ms 1.489 ms 1.761 ms
6 172.23.78.238 (172.23.78.238) 33.567 ms 28.901 ms 33.056 ms
7 14.142.22.202.static-Mumbai.vsnl.net.in (14.142.22.202) 35.004 ms 35.213 ms 29.446 ms
8 * * *
9 220.227.70.97 (220.227.70.97) 34.847 ms 34.499 ms 40.082 ms
10 104.16.184.48 (104.16.184.48) 52.115 ms 34.127 ms 34.125 ms
root@OpenWrt:/etc/openvpn#
13. Trace route of openwrt.org from windows 10 command prompt with vpn connected is as below
C:\WINDOWS\system32>tracert openwrt.org
Tracing route to openwrt.org [139.59.209.225]
over a maximum of 30 hops:
1 1 ms 1 ms 1 ms 10.8.0.1
2 2 ms 1 ms 2 ms 103.206.8.74
3 4 ms * * 103.38.129.65
4 3 ms 2 ms 2 ms 14.143.172.17.static-Kolkatta.vsnl.net.in [14.143.172.17]
5 32 ms 33 ms 33 ms 172.23.183.134
6 37 ms 32 ms 32 ms ix-ae-0-100.tcore1.mlv-mumbai.as6453.net [180.87.38.5]
7 166 ms 166 ms 163 ms if-ae-5-2.tcore1.wyn-marseille.as6453.net [80.231.217.29]
8 164 ms 159 ms 163 ms if-ae-2-2.tcore2.wyn-marseille.as6453.net [80.231.217.2]
9 163 ms 162 ms 163 ms if-ae-7-2.tcore2.fnm-frankfurt.as6453.net [80.231.200.78]
10 153 ms 151 ms 150 ms if-ae-4-2.tcore1.fr0-frankfurt.as6453.net [195.219.87.18]
11 163 ms 163 ms 189 ms 195.219.50.42
12 * * * Request timed out.
13 170 ms 169 ms 166 ms wiki-01.infra.openwrt.org [139.59.209.225]
Trace complete.
14. Trace route of openvpn.org from windows10 command prompt without vpn connection is as below
C:\WINDOWS\system32>tracert openwrt.org
Tracing route to openwrt.org [139.59.209.225]
over a maximum of 30 hops:
1 <1 ms <1 ms <1 ms OpenWrt.lan [192.168.2.1]
2 1 ms <1 ms 1 ms 103.206.8.74
3 * * * Request timed out.
4 2 ms 3 ms 2 ms 14.143.172.17.static-Kolkatta.vsnl.net.in [14.143.172.17]
5 29 ms 29 ms 29 ms 172.23.183.134
6 31 ms 30 ms 29 ms ix-ae-0-100.tcore1.mlv-mumbai.as6453.net [180.87.38.5]
7 161 ms 161 ms 161 ms if-ae-5-2.tcore1.wyn-marseille.as6453.net [80.231.217.29]
8 158 ms 160 ms 163 ms if-ae-2-2.tcore2.wyn-marseille.as6453.net [80.231.217.2]
9 156 ms 156 ms 171 ms if-ae-7-2.tcore2.fnm-frankfurt.as6453.net [80.231.200.78]
10 147 ms 146 ms 146 ms if-ae-4-2.tcore1.fr0-frankfurt.as6453.net [195.219.87.18]
11 160 ms 160 ms 162 ms 195.219.50.42
12 * * * Request timed out.
13 164 ms 163 ms 163 ms wiki-01.infra.openwrt.org [139.59.209.225]
Trace complete.
14. Log of VPN Client is as below
Tue Apr 30 11:12:34 2019 us=700676 Current Parameter Settings:
Tue Apr 30 11:12:34 2019 us=700676 config = 'vpnclient1.ovpn'
Tue Apr 30 11:12:34 2019 us=700676 mode = 0
Tue Apr 30 11:12:34 2019 us=700676 show_ciphers = DISABLED
Tue Apr 30 11:12:34 2019 us=700676 show_digests = DISABLED
Tue Apr 30 11:12:34 2019 us=700676 show_engines = DISABLED
Tue Apr 30 11:12:34 2019 us=700676 genkey = DISABLED
Tue Apr 30 11:12:34 2019 us=700676 key_pass_file = '[UNDEF]'
Tue Apr 30 11:12:34 2019 us=700676 show_tls_ciphers = DISABLED
Tue Apr 30 11:12:34 2019 us=700676 connect_retry_max = 0
Tue Apr 30 11:12:34 2019 us=700676 Connection profiles [0]:
Tue Apr 30 11:12:34 2019 us=700676 proto = udp
Tue Apr 30 11:12:34 2019 us=700676 local = '[UNDEF]'
Tue Apr 30 11:12:34 2019 us=700676 local_port = '[UNDEF]'
Tue Apr 30 11:12:34 2019 us=700676 remote = '43.230.40.122'
Tue Apr 30 11:12:34 2019 us=700676 remote_port = '1194'
Tue Apr 30 11:12:34 2019 us=700676 remote_float = ENABLED
Tue Apr 30 11:12:34 2019 us=700676 bind_defined = DISABLED
Tue Apr 30 11:12:34 2019 us=700676 bind_local = DISABLED
Tue Apr 30 11:12:34 2019 us=700676 bind_ipv6_only = DISABLED
Tue Apr 30 11:12:34 2019 us=700676 connect_retry_seconds = 5
Tue Apr 30 11:12:34 2019 us=700676 connect_timeout = 120
Tue Apr 30 11:12:34 2019 us=700676 socks_proxy_server = '[UNDEF]'
Tue Apr 30 11:12:34 2019 us=700676 socks_proxy_port = '[UNDEF]'
Tue Apr 30 11:12:34 2019 us=700676 tun_mtu = 1500
Tue Apr 30 11:12:34 2019 us=700676 tun_mtu_defined = ENABLED
Tue Apr 30 11:12:34 2019 us=700676 link_mtu = 1500
Tue Apr 30 11:12:34 2019 us=700676 link_mtu_defined = DISABLED
Tue Apr 30 11:12:34 2019 us=700676 tun_mtu_extra = 0
Tue Apr 30 11:12:34 2019 us=700676 tun_mtu_extra_defined = DISABLED
Tue Apr 30 11:12:34 2019 us=700676 mtu_discover_type = -1
Tue Apr 30 11:12:34 2019 us=700676 fragment = 0
Tue Apr 30 11:12:34 2019 us=700676 mssfix = 1450
Tue Apr 30 11:12:34 2019 us=700676 explicit_exit_notification = 0
Tue Apr 30 11:12:34 2019 us=700676 Connection profiles END
Tue Apr 30 11:12:34 2019 us=700676 remote_random = DISABLED
Tue Apr 30 11:12:34 2019 us=700676 ipchange = '[UNDEF]'
Tue Apr 30 11:12:34 2019 us=700676 dev = 'tun'
Tue Apr 30 11:12:34 2019 us=700676 dev_type = '[UNDEF]'
Tue Apr 30 11:12:34 2019 us=700676 dev_node = '[UNDEF]'
Tue Apr 30 11:12:34 2019 us=700676 lladdr = '[UNDEF]'
Tue Apr 30 11:12:34 2019 us=700676 topology = 1
Tue Apr 30 11:12:34 2019 us=700676 ifconfig_local = '[UNDEF]'
Tue Apr 30 11:12:34 2019 us=700676 ifconfig_remote_netmask = '[UNDEF]'
Tue Apr 30 11:12:34 2019 us=701679 ifconfig_noexec = DISABLED
Tue Apr 30 11:12:34 2019 us=701679 ifconfig_nowarn = DISABLED
Tue Apr 30 11:12:34 2019 us=701679 ifconfig_ipv6_local = '[UNDEF]'
Tue Apr 30 11:12:34 2019 us=701679 ifconfig_ipv6_netbits = 0
Tue Apr 30 11:12:34 2019 us=701679 ifconfig_ipv6_remote = '[UNDEF]'
Tue Apr 30 11:12:34 2019 us=701679 shaper = 0
Tue Apr 30 11:12:34 2019 us=701679 mtu_test = 0
Tue Apr 30 11:12:34 2019 us=701679 mlock = DISABLED
Tue Apr 30 11:12:34 2019 us=701679 keepalive_ping = 0
Tue Apr 30 11:12:34 2019 us=701679 keepalive_timeout = 0
Tue Apr 30 11:12:34 2019 us=701679 inactivity_timeout = 0
Tue Apr 30 11:12:34 2019 us=701679 ping_send_timeout = 0
Tue Apr 30 11:12:34 2019 us=701679 ping_rec_timeout = 0
Tue Apr 30 11:12:34 2019 us=701679 ping_rec_timeout_action = 0
Tue Apr 30 11:12:34 2019 us=701679 ping_timer_remote = DISABLED
Tue Apr 30 11:12:34 2019 us=701679 remap_sigusr1 = 0
Tue Apr 30 11:12:34 2019 us=701679 persist_tun = DISABLED
Tue Apr 30 11:12:34 2019 us=701679 persist_local_ip = DISABLED
Tue Apr 30 11:12:34 2019 us=701679 persist_remote_ip = DISABLED
Tue Apr 30 11:12:34 2019 us=701679 persist_key = DISABLED
Tue Apr 30 11:12:34 2019 us=701679 passtos = DISABLED
Tue Apr 30 11:12:34 2019 us=701679 resolve_retry_seconds = 1000000000
Tue Apr 30 11:12:34 2019 us=701679 resolve_in_advance = DISABLED
Tue Apr 30 11:12:34 2019 us=701679 username = '[UNDEF]'
Tue Apr 30 11:12:34 2019 us=701679 groupname = '[UNDEF]'
Tue Apr 30 11:12:34 2019 us=701679 chroot_dir = '[UNDEF]'
Tue Apr 30 11:12:34 2019 us=701679 cd_dir = '[UNDEF]'
Tue Apr 30 11:12:34 2019 us=701679 writepid = '[UNDEF]'
Tue Apr 30 11:12:34 2019 us=701679 up_script = '[UNDEF]'
Tue Apr 30 11:12:34 2019 us=701679 down_script = '[UNDEF]'
Tue Apr 30 11:12:34 2019 us=701679 down_pre = DISABLED
Tue Apr 30 11:12:34 2019 us=701679 up_restart = DISABLED
Tue Apr 30 11:12:34 2019 us=701679 up_delay = DISABLED
Tue Apr 30 11:12:34 2019 us=701679 daemon = DISABLED
Tue Apr 30 11:12:34 2019 us=701679 inetd = 0
Tue Apr 30 11:12:34 2019 us=701679 log = ENABLED
Tue Apr 30 11:12:34 2019 us=701679 suppress_timestamps = DISABLED
Tue Apr 30 11:12:34 2019 us=701679 machine_readable_output = DISABLED
Tue Apr 30 11:12:34 2019 us=701679 nice = 0
Tue Apr 30 11:12:34 2019 us=701679 verbosity = 4
Tue Apr 30 11:12:34 2019 us=701679 mute = 0
Tue Apr 30 11:12:34 2019 us=701679 gremlin = 0
Tue Apr 30 11:12:34 2019 us=701679 status_file = '[UNDEF]'
Tue Apr 30 11:12:34 2019 us=701679 status_file_version = 1
Tue Apr 30 11:12:34 2019 us=701679 status_file_update_freq = 60
Tue Apr 30 11:12:34 2019 us=701679 occ = ENABLED
Tue Apr 30 11:12:34 2019 us=701679 rcvbuf = 0
Tue Apr 30 11:12:34 2019 us=701679 sndbuf = 0
Tue Apr 30 11:12:34 2019 us=701679 sockflags = 0
Tue Apr 30 11:12:34 2019 us=701679 fast_io = DISABLED
Tue Apr 30 11:12:34 2019 us=701679 comp.alg = 0
Tue Apr 30 11:12:34 2019 us=701679 comp.flags = 0
Tue Apr 30 11:12:34 2019 us=701679 route_script = '[UNDEF]'
Tue Apr 30 11:12:34 2019 us=701679 route_default_gateway = '[UNDEF]'
Tue Apr 30 11:12:34 2019 us=701679 route_default_metric = 0
Tue Apr 30 11:12:34 2019 us=701679 route_noexec = DISABLED
Tue Apr 30 11:12:34 2019 us=701679 route_delay = 5
Tue Apr 30 11:12:34 2019 us=701679 route_delay_window = 30
Tue Apr 30 11:12:34 2019 us=701679 route_delay_defined = ENABLED
Tue Apr 30 11:12:34 2019 us=701679 route_nopull = DISABLED
Tue Apr 30 11:12:34 2019 us=701679 route_gateway_via_dhcp = DISABLED
Tue Apr 30 11:12:34 2019 us=701679 allow_pull_fqdn = DISABLED
Tue Apr 30 11:12:34 2019 us=701679 Pull filters:
Tue Apr 30 11:12:34 2019 us=701679 ignore "route-method"
Tue Apr 30 11:12:34 2019 us=701679 [redirect_default_gateway local=0]
Tue Apr 30 11:12:34 2019 us=701679 management_addr = '127.0.0.1'
Tue Apr 30 11:12:34 2019 us=701679 management_port = '25341'
Tue Apr 30 11:12:34 2019 us=701679 management_user_pass = 'stdin'
Tue Apr 30 11:12:34 2019 us=701679 management_log_history_cache = 250
Tue Apr 30 11:12:34 2019 us=701679 management_echo_buffer_size = 100
Tue Apr 30 11:12:34 2019 us=701679 management_write_peer_info_file = '[UNDEF]'
Tue Apr 30 11:12:34 2019 us=701679 management_client_user = '[UNDEF]'
Tue Apr 30 11:12:34 2019 us=701679 management_client_group = '[UNDEF]'
Tue Apr 30 11:12:34 2019 us=701679 management_flags = 6
Tue Apr 30 11:12:34 2019 us=701679 shared_secret_file = '[UNDEF]'
Tue Apr 30 11:12:34 2019 us=701679 key_direction = not set
Tue Apr 30 11:12:34 2019 us=701679 ciphername = 'BF-CBC'
Tue Apr 30 11:12:34 2019 us=701679 ncp_enabled = ENABLED
Tue Apr 30 11:12:34 2019 us=701679 ncp_ciphers = 'AES-256-GCM:AES-128-GCM'
Tue Apr 30 11:12:34 2019 us=701679 authname = 'SHA1'
Tue Apr 30 11:12:34 2019 us=701679 prng_hash = 'SHA1'
Tue Apr 30 11:12:34 2019 us=701679 prng_nonce_secret_len = 16
Tue Apr 30 11:12:34 2019 us=701679 keysize = 0
Tue Apr 30 11:12:34 2019 us=701679 engine = DISABLED
Tue Apr 30 11:12:34 2019 us=701679 replay = ENABLED
Tue Apr 30 11:12:34 2019 us=701679 mute_replay_warnings = DISABLED
Tue Apr 30 11:12:34 2019 us=701679 replay_window = 64
Tue Apr 30 11:12:34 2019 us=701679 replay_time = 15
Tue Apr 30 11:12:34 2019 us=701679 packet_id_file = '[UNDEF]'
Tue Apr 30 11:12:34 2019 us=701679 use_iv = ENABLED
Tue Apr 30 11:12:34 2019 us=701679 test_crypto = DISABLED
Tue Apr 30 11:12:34 2019 us=701679 tls_server = DISABLED
Tue Apr 30 11:12:34 2019 us=701679 tls_client = ENABLED
Tue Apr 30 11:12:34 2019 us=701679 key_method = 2
Tue Apr 30 11:12:34 2019 us=701679 ca_file = '[[INLINE]]'
Tue Apr 30 11:12:34 2019 us=701679 ca_path = '[UNDEF]'
Tue Apr 30 11:12:34 2019 us=701679 dh_file = '[UNDEF]'
Tue Apr 30 11:12:34 2019 us=701679 cert_file = '[[INLINE]]'
Tue Apr 30 11:12:34 2019 us=701679 extra_certs_file = '[UNDEF]'
Tue Apr 30 11:12:34 2019 us=701679 priv_key_file = '[[INLINE]]'
Tue Apr 30 11:12:34 2019 us=701679 pkcs12_file = '[UNDEF]'
Tue Apr 30 11:12:34 2019 us=701679 cryptoapi_cert = '[UNDEF]'
Tue Apr 30 11:12:34 2019 us=701679 cipher_list = '[UNDEF]'
Tue Apr 30 11:12:34 2019 us=701679 cipher_list_tls13 = '[UNDEF]'
Tue Apr 30 11:12:34 2019 us=701679 tls_cert_profile = '[UNDEF]'
Tue Apr 30 11:12:34 2019 us=701679 tls_verify = '[UNDEF]'
Tue Apr 30 11:12:34 2019 us=701679 tls_export_cert = '[UNDEF]'
Tue Apr 30 11:12:34 2019 us=701679 verify_x509_type = 0
Tue Apr 30 11:12:34 2019 us=701679 verify_x509_name = '[UNDEF]'
Tue Apr 30 11:12:34 2019 us=701679 crl_file = '[UNDEF]'
Tue Apr 30 11:12:34 2019 us=701679 ns_cert_type = 0
Tue Apr 30 11:12:34 2019 us=701679 remote_cert_ku = 65535
Tue Apr 30 11:12:34 2019 us=701679 remote_cert_ku = 0
Tue Apr 30 11:12:34 2019 us=701679 remote_cert_ku = 0
Tue Apr 30 11:12:34 2019 us=701679 remote_cert_ku = 0
Tue Apr 30 11:12:34 2019 us=701679 remote_cert_ku = 0
Tue Apr 30 11:12:34 2019 us=701679 remote_cert_ku = 0
Tue Apr 30 11:12:34 2019 us=701679 remote_cert_ku = 0
Tue Apr 30 11:12:34 2019 us=701679 remote_cert_ku = 0
Tue Apr 30 11:12:34 2019 us=701679 remote_cert_ku = 0
Tue Apr 30 11:12:34 2019 us=701679 remote_cert_ku = 0
Tue Apr 30 11:12:34 2019 us=701679 remote_cert_ku[i] = 0
Tue Apr 30 11:12:34 2019 us=701679 remote_cert_ku[i] = 0
Tue Apr 30 11:12:34 2019 us=701679 remote_cert_ku[i] = 0
Tue Apr 30 11:12:34 2019 us=701679 remote_cert_ku[i] = 0
Tue Apr 30 11:12:34 2019 us=701679 remote_cert_ku[i] = 0
Tue Apr 30 11:12:34 2019 us=701679 remote_cert_ku[i] = 0
Tue Apr 30 11:12:34 2019 us=701679 remote_cert_eku = 'TLS Web Server Authentication'
Tue Apr 30 11:12:34 2019 us=701679 ssl_flags = 0
Tue Apr 30 11:12:34 2019 us=701679 tls_timeout = 2
Tue Apr 30 11:12:34 2019 us=701679 renegotiate_bytes = -1
Tue Apr 30 11:12:34 2019 us=701679 renegotiate_packets = 0
Tue Apr 30 11:12:34 2019 us=701679 renegotiate_seconds = 3600
Tue Apr 30 11:12:34 2019 us=701679 handshake_window = 60
Tue Apr 30 11:12:34 2019 us=701679 transition_window = 3600
Tue Apr 30 11:12:34 2019 us=701679 single_session = DISABLED
Tue Apr 30 11:12:34 2019 us=701679 push_peer_info = DISABLED
Tue Apr 30 11:12:34 2019 us=701679 tls_exit = DISABLED
Tue Apr 30 11:12:34 2019 us=701679 tls_auth_file = '[UNDEF]'
Tue Apr 30 11:12:34 2019 us=701679 tls_crypt_file = '[[INLINE]]'
Tue Apr 30 11:12:34 2019 us=701679 pkcs11_protected_authentication = DISABLED
Tue Apr 30 11:12:34 2019 us=701679 pkcs11_protected_authentication = DISABLED
Tue Apr 30 11:12:34 2019 us=701679 pkcs11_protected_authentication = DISABLED
Tue Apr 30 11:12:34 2019 us=701679 pkcs11_protected_authentication = DISABLED
Tue Apr 30 11:12:34 2019 us=701679 pkcs11_protected_authentication = DISABLED
Tue Apr 30 11:12:34 2019 us=701679 pkcs11_protected_authentication = DISABLED
Tue Apr 30 11:12:34 2019 us=702682 pkcs11_protected_authentication = DISABLED
Tue Apr 30 11:12:34 2019 us=702682 pkcs11_protected_authentication = DISABLED
Tue Apr 30 11:12:34 2019 us=702682 pkcs11_protected_authentication = DISABLED
Tue Apr 30 11:12:34 2019 us=702682 pkcs11_protected_authentication = DISABLED
Tue Apr 30 11:12:34 2019 us=702682 pkcs11_protected_authentication = DISABLED
Tue Apr 30 11:12:34 2019 us=702682 pkcs11_protected_authentication = DISABLED
Tue Apr 30 11:12:34 2019 us=702682 pkcs11_protected_authentication = DISABLED
Tue Apr 30 11:12:34 2019 us=702682 pkcs11_protected_authentication = DISABLED
Tue Apr 30 11:12:34 2019 us=702682 pkcs11_protected_authentication = DISABLED
Tue Apr 30 11:12:34 2019 us=702682 pkcs11_protected_authentication = DISABLED
Tue Apr 30 11:12:34 2019 us=702682 pkcs11_private_mode = 00000000
Tue Apr 30 11:12:34 2019 us=702682 pkcs11_private_mode = 00000000
Tue Apr 30 11:12:34 2019 us=702682 pkcs11_private_mode = 00000000
Tue Apr 30 11:12:34 2019 us=702682 pkcs11_private_mode = 00000000
Tue Apr 30 11:12:34 2019 us=702682 pkcs11_private_mode = 00000000
Tue Apr 30 11:12:34 2019 us=702682 pkcs11_private_mode = 00000000
Tue Apr 30 11:12:34 2019 us=702682 pkcs11_private_mode = 00000000
Tue Apr 30 11:12:34 2019 us=702682 pkcs11_private_mode = 00000000
Tue Apr 30 11:12:34 2019 us=702682 pkcs11_private_mode = 00000000
Tue Apr 30 11:12:34 2019 us=702682 pkcs11_private_mode = 00000000
Tue Apr 30 11:12:34 2019 us=702682 pkcs11_private_mode = 00000000
Tue Apr 30 11:12:34 2019 us=702682 pkcs11_private_mode = 00000000
Tue Apr 30 11:12:34 2019 us=702682 pkcs11_private_mode = 00000000
Tue Apr 30 11:12:34 2019 us=702682 pkcs11_private_mode = 00000000
Tue Apr 30 11:12:34 2019 us=702682 pkcs11_private_mode = 00000000
Tue Apr 30 11:12:34 2019 us=702682 pkcs11_private_mode = 00000000
Tue Apr 30 11:12:34 2019 us=702682 pkcs11_cert_private = DISABLED
Tue Apr 30 11:12:34 2019 us=702682 pkcs11_cert_private = DISABLED
Tue Apr 30 11:12:34 2019 us=702682 pkcs11_cert_private = DISABLED
Tue Apr 30 11:12:34 2019 us=702682 pkcs11_cert_private = DISABLED
Tue Apr 30 11:12:34 2019 us=702682 pkcs11_cert_private = DISABLED
Tue Apr 30 11:12:34 2019 us=702682 pkcs11_cert_private = DISABLED
Tue Apr 30 11:12:34 2019 us=702682 pkcs11_cert_private = DISABLED
Tue Apr 30 11:12:34 2019 us=702682 pkcs11_cert_private = DISABLED
Tue Apr 30 11:12:34 2019 us=702682 pkcs11_cert_private = DISABLED
Tue Apr 30 11:12:34 2019 us=702682 pkcs11_cert_private = DISABLED
Tue Apr 30 11:12:34 2019 us=702682 pkcs11_cert_private = DISABLED
Tue Apr 30 11:12:34 2019 us=702682 pkcs11_cert_private = DISABLED
Tue Apr 30 11:12:34 2019 us=702682 pkcs11_cert_private = DISABLED
Tue Apr 30 11:12:34 2019 us=702682 pkcs11_cert_private = DISABLED
Tue Apr 30 11:12:34 2019 us=702682 pkcs11_cert_private = DISABLED
Tue Apr 30 11:12:34 2019 us=702682 pkcs11_cert_private = DISABLED
Tue Apr 30 11:12:34 2019 us=702682 pkcs11_pin_cache_period = -1
Tue Apr 30 11:12:34 2019 us=702682 pkcs11_id = '[UNDEF]'
Tue Apr 30 11:12:34 2019 us=702682 pkcs11_id_management = DISABLED
Tue Apr 30 11:12:34 2019 us=702682 server_network = 0.0.0.0
Tue Apr 30 11:12:34 2019 us=702682 server_netmask = 0.0.0.0
Tue Apr 30 11:12:34 2019 us=702682 server_network_ipv6 = ::
Tue Apr 30 11:12:34 2019 us=702682 server_netbits_ipv6 = 0
Tue Apr 30 11:12:34 2019 us=702682 server_bridge_ip = 0.0.0.0
Tue Apr 30 11:12:34 2019 us=702682 server_bridge_netmask = 0.0.0.0
Tue Apr 30 11:12:34 2019 us=702682 server_bridge_pool_start = 0.0.0.0
Tue Apr 30 11:12:34 2019 us=702682 server_bridge_pool_end = 0.0.0.0
Tue Apr 30 11:12:34 2019 us=702682 ifconfig_pool_defined = DISABLED
Tue Apr 30 11:12:34 2019 us=702682 ifconfig_pool_start = 0.0.0.0
Tue Apr 30 11:12:34 2019 us=702682 ifconfig_pool_end = 0.0.0.0
Tue Apr 30 11:12:34 2019 us=702682 ifconfig_pool_netmask = 0.0.0.0
Tue Apr 30 11:12:34 2019 us=702682 ifconfig_pool_persist_filename = '[UNDEF]'
Tue Apr 30 11:12:34 2019 us=702682 ifconfig_pool_persist_refresh_freq = 600
Tue Apr 30 11:12:34 2019 us=702682 ifconfig_ipv6_pool_defined = DISABLED
Tue Apr 30 11:12:34 2019 us=702682 ifconfig_ipv6_pool_base = ::
Tue Apr 30 11:12:34 2019 us=702682 ifconfig_ipv6_pool_netbits = 0
Tue Apr 30 11:12:34 2019 us=702682 n_bcast_buf = 256
Tue Apr 30 11:12:34 2019 us=702682 tcp_queue_limit = 64
Tue Apr 30 11:12:34 2019 us=702682 real_hash_size = 256
Tue Apr 30 11:12:34 2019 us=702682 virtual_hash_size = 256
Tue Apr 30 11:12:34 2019 us=702682 client_connect_script = '[UNDEF]'
Tue Apr 30 11:12:34 2019 us=702682 learn_address_script = '[UNDEF]'
Tue Apr 30 11:12:34 2019 us=702682 client_disconnect_script = '[UNDEF]'
Tue Apr 30 11:12:34 2019 us=702682 client_config_dir = '[UNDEF]'
Tue Apr 30 11:12:34 2019 us=702682 ccd_exclusive = DISABLED
Tue Apr 30 11:12:34 2019 us=702682 tmp_dir = 'C:\Users\Bobra-AG\AppData\Local\Temp\'
Tue Apr 30 11:12:34 2019 us=702682 push_ifconfig_defined = DISABLED
Tue Apr 30 11:12:34 2019 us=702682 push_ifconfig_local = 0.0.0.0
Tue Apr 30 11:12:34 2019 us=702682 push_ifconfig_remote_netmask = 0.0.0.0
Tue Apr 30 11:12:34 2019 us=702682 push_ifconfig_ipv6_defined = DISABLED
Tue Apr 30 11:12:34 2019 us=702682 push_ifconfig_ipv6_local = ::/0
Tue Apr 30 11:12:34 2019 us=702682 push_ifconfig_ipv6_remote = ::
Tue Apr 30 11:12:34 2019 us=702682 enable_c2c = DISABLED
Tue Apr 30 11:12:34 2019 us=702682 duplicate_cn = DISABLED
Tue Apr 30 11:12:34 2019 us=702682 cf_max = 0
Tue Apr 30 11:12:34 2019 us=702682 cf_per = 0
Tue Apr 30 11:12:34 2019 us=702682 max_clients = 1024
Tue Apr 30 11:12:34 2019 us=702682 max_routes_per_client = 256
Tue Apr 30 11:12:34 2019 us=702682 auth_user_pass_verify_script = '[UNDEF]'
Tue Apr 30 11:12:34 2019 us=702682 auth_user_pass_verify_script_via_file = DISABLED
Tue Apr 30 11:12:34 2019 us=702682 auth_token_generate = DISABLED
Tue Apr 30 11:12:34 2019 us=702682 auth_token_lifetime = 0
Tue Apr 30 11:12:34 2019 us=702682 client = ENABLED
Tue Apr 30 11:12:34 2019 us=702682 pull = ENABLED
Tue Apr 30 11:12:34 2019 us=702682 auth_user_pass_file = '[UNDEF]'
Tue Apr 30 11:12:34 2019 us=702682 show_net_up = DISABLED
Tue Apr 30 11:12:34 2019 us=702682 route_method = 3
Tue Apr 30 11:12:34 2019 us=702682 block_outside_dns = DISABLED
Tue Apr 30 11:12:34 2019 us=702682 ip_win32_defined = DISABLED
Tue Apr 30 11:12:34 2019 us=702682 ip_win32_type = 3
Tue Apr 30 11:12:34 2019 us=702682 dhcp_masq_offset = 0
Tue Apr 30 11:12:34 2019 us=702682 dhcp_lease_time = 31536000
Tue Apr 30 11:12:34 2019 us=702682 tap_sleep = 0
Tue Apr 30 11:12:34 2019 us=702682 dhcp_options = DISABLED
Tue Apr 30 11:12:34 2019 us=702682 dhcp_renew = DISABLED
Tue Apr 30 11:12:34 2019 us=702682 dhcp_pre_release = DISABLED
Tue Apr 30 11:12:34 2019 us=702682 domain = '[UNDEF]'
Tue Apr 30 11:12:34 2019 us=702682 netbios_scope = '[UNDEF]'
Tue Apr 30 11:12:34 2019 us=702682 netbios_node_type = 0
Tue Apr 30 11:12:34 2019 us=702682 disable_nbt = DISABLED
Tue Apr 30 11:12:34 2019 us=702682 OpenVPN 2.4.7 x86_64-w64-mingw32 [SSL (OpenSSL)] [LZO] [LZ4] [PKCS11] [AEAD] built on Feb 21 2019
Tue Apr 30 11:12:34 2019 us=702682 Windows version 6.2 (Windows 8 or greater) 64bit
Tue Apr 30 11:12:34 2019 us=702682 library versions: OpenSSL 1.1.0j 20 Nov 2018, LZO 2.10
Enter Management Password:
Tue Apr 30 11:12:34 2019 us=703686 MANAGEMENT: TCP Socket listening on [AF_INET]127.0.0.1:25341
Tue Apr 30 11:12:34 2019 us=703686 Need hold release from management interface, waiting...
Tue Apr 30 11:12:35 2019 us=147261 MANAGEMENT: Client connected from [AF_INET]127.0.0.1:25341
Tue Apr 30 11:12:35 2019 us=248736 MANAGEMENT: CMD 'state on'
Tue Apr 30 11:12:35 2019 us=248736 MANAGEMENT: CMD 'log all on'
Tue Apr 30 11:12:35 2019 us=359083 MANAGEMENT: CMD 'echo all on'
Tue Apr 30 11:12:35 2019 us=361093 MANAGEMENT: CMD 'bytecount 5'
Tue Apr 30 11:12:35 2019 us=362094 MANAGEMENT: CMD 'hold off'
Tue Apr 30 11:12:35 2019 us=364100 MANAGEMENT: CMD 'hold release'
Tue Apr 30 11:12:35 2019 us=366109 Outgoing Control Channel Encryption: Cipher 'AES-256-CTR' initialized with 256 bit key
Tue Apr 30 11:12:35 2019 us=366109 Outgoing Control Channel Encryption: Using 256 bit message hash 'SHA256' for HMAC authentication
Tue Apr 30 11:12:35 2019 us=366109 Incoming Control Channel Encryption: Cipher 'AES-256-CTR' initialized with 256 bit key
Tue Apr 30 11:12:35 2019 us=366109 Incoming Control Channel Encryption: Using 256 bit message hash 'SHA256' for HMAC authentication
Tue Apr 30 11:12:35 2019 us=367111 Control Channel MTU parms [ L:1621 D:1156 EF:94 EB:0 ET:0 EL:3 ]
Tue Apr 30 11:12:35 2019 us=367111 Data Channel MTU parms [ L:1621 D:1450 EF:121 EB:406 ET:0 EL:3 ]
Tue Apr 30 11:12:35 2019 us=367111 Local Options String (VER=V4): 'V4,dev-type tun,link-mtu 1541,tun-mtu 1500,proto UDPv4,cipher BF-CBC,auth SHA1,keysize 128,key-method 2,tls-client'
Tue Apr 30 11:12:35 2019 us=367111 Expected Remote Options String (VER=V4): 'V4,dev-type tun,link-mtu 1541,tun-mtu 1500,proto UDPv4,cipher BF-CBC,auth SHA1,keysize 128,key-method 2,tls-server'
Tue Apr 30 11:12:35 2019 us=367111 TCP/UDP: Preserving recently used remote address: [AF_INET]43.230.40.122:1194
Tue Apr 30 11:12:35 2019 us=367111 Socket Buffers: R=[65536->65536] S=[65536->65536]
Tue Apr 30 11:12:35 2019 us=367111 UDP link local: (not bound)
Tue Apr 30 11:12:35 2019 us=367111 UDP link remote: [AF_INET]43.230.40.122:1194
Tue Apr 30 11:12:35 2019 us=367111 MANAGEMENT: >STATE:1556602955,WAIT,,,,,,
Tue Apr 30 11:12:35 2019 us=378146 MANAGEMENT: >STATE:1556602955,AUTH,,,,,,
Tue Apr 30 11:12:35 2019 us=378146 TLS: Initial packet from [AF_INET]192.168.2.1:1194, sid=1e88f158 77e8ecd6
Tue Apr 30 11:12:35 2019 us=447375 VERIFY OK: depth=1, CN=vpnca
Tue Apr 30 11:12:35 2019 us=447375 VERIFY KU OK
Tue Apr 30 11:12:35 2019 us=447375 Validating certificate extended key usage
Tue Apr 30 11:12:35 2019 us=447375 ++ Certificate has EKU (str) TLS Web Server Authentication, expects TLS Web Server Authentication
Tue Apr 30 11:12:35 2019 us=447375 VERIFY EKU OK
Tue Apr 30 11:12:35 2019 us=447375 VERIFY OK: depth=0, CN=vpnserver
Tue Apr 30 11:12:35 2019 us=476473 Control Channel: TLSv1.2, cipher TLSv1.2 ECDHE-RSA-AES256-GCM-SHA384, 2048 bit RSA
Tue Apr 30 11:12:35 2019 us=476473 [vpnserver] Peer Connection Initiated with [AF_INET]192.168.2.1:1194
Tue Apr 30 11:12:36 2019 us=736861 MANAGEMENT: >STATE:1556602956,GET_CONFIG,,,,,,
Tue Apr 30 11:12:36 2019 us=736861 SENT CONTROL [vpnserver]: 'PUSH_REQUEST' (status=1)
Tue Apr 30 11:12:36 2019 us=756928 PUSH: Received control message: 'PUSH_REPLY,dhcp-option DNS 10.8.0.1,dhcp-option DOMAIN lan,register-dns,block-outside-dns,redirect-gateway def1,persist-tun,persist-key,route-gateway 10.8.0.1,topology subnet,ping 10,ping-restart 120,ifconfig 10.8.0.3 255.255.255.0,peer-id 0,cipher AES-256-GCM'
Tue Apr 30 11:12:36 2019 us=756928 OPTIONS IMPORT: timers and/or timeouts modified
Tue Apr 30 11:12:36 2019 us=756928 OPTIONS IMPORT: --persist options modified
Tue Apr 30 11:12:36 2019 us=756928 OPTIONS IMPORT: --ifconfig/up options modified
Tue Apr 30 11:12:36 2019 us=756928 OPTIONS IMPORT: route options modified
Tue Apr 30 11:12:36 2019 us=756928 OPTIONS IMPORT: route-related options modified
Tue Apr 30 11:12:36 2019 us=756928 OPTIONS IMPORT: --ip-win32 and/or --dhcp-option options modified
Tue Apr 30 11:12:36 2019 us=756928 OPTIONS IMPORT: peer-id set
Tue Apr 30 11:12:36 2019 us=756928 OPTIONS IMPORT: adjusting link_mtu to 1624
Tue Apr 30 11:12:36 2019 us=756928 OPTIONS IMPORT: data channel crypto options modified
Tue Apr 30 11:12:36 2019 us=756928 Data Channel: using negotiated cipher 'AES-256-GCM'
Tue Apr 30 11:12:36 2019 us=756928 Data Channel MTU parms [ L:1552 D:1450 EF:52 EB:406 ET:0 EL:3 ]
Tue Apr 30 11:12:36 2019 us=757931 Outgoing Data Channel: Cipher 'AES-256-GCM' initialized with 256 bit key
Tue Apr 30 11:12:36 2019 us=757931 Incoming Data Channel: Cipher 'AES-256-GCM' initialized with 256 bit key
Tue Apr 30 11:12:36 2019 us=757931 interactive service msg_channel=824
Tue Apr 30 11:12:36 2019 us=765959 ROUTE_GATEWAY 192.168.2.1/255.255.255.0 I=5 HWADDR=00:d8:61:31:0a:35
Tue Apr 30 11:12:36 2019 us=789034 open_tun
Tue Apr 30 11:12:36 2019 us=790037 TAP-WIN32 device [Ethernet 4] opened: \\.\Global\{B6533F32-BEF9-4820-AACD-F92A95AD17EC}.tap
Tue Apr 30 11:12:36 2019 us=791041 TAP-Windows Driver Version 9.21
Tue Apr 30 11:12:36 2019 us=791041 TAP-Windows MTU=1500
Tue Apr 30 11:12:36 2019 us=796057 Set TAP-Windows TUN subnet mode network/local/netmask = 10.8.0.0/10.8.0.3/255.255.255.0 [SUCCEEDED]
Tue Apr 30 11:12:36 2019 us=796057 Notified TAP-Windows driver to set a DHCP IP/netmask of 10.8.0.3/255.255.255.0 on interface {B6533F32-BEF9-4820-AACD-F92A95AD17EC} [DHCP-serv: 10.8.0.254, lease-time: 31536000]
Tue Apr 30 11:12:36 2019 us=796057 DHCP option string: 0f036c61 6e06040a 080001
Tue Apr 30 11:12:36 2019 us=797061 Successful ARP Flush on interface [17] {B6533F32-BEF9-4820-AACD-F92A95AD17EC}
Tue Apr 30 11:12:36 2019 us=816125 do_ifconfig, tt->did_ifconfig_ipv6_setup=0
Tue Apr 30 11:12:36 2019 us=816125 MANAGEMENT: >STATE:1556602956,ASSIGN_IP,,10.8.0.3,,,,
Tue Apr 30 11:12:36 2019 us=816125 Blocking outside DNS
Tue Apr 30 11:12:36 2019 us=816125 Using service to add block dns filters
Tue Apr 30 11:12:36 2019 us=864284 Blocking outside dns using service succeeded.
Tue Apr 30 11:12:41 2019 us=268176 TEST ROUTES: 1/1 succeeded len=0 ret=1 a=0 u/d=up
Tue Apr 30 11:12:41 2019 us=268176 C:\WINDOWS\system32\route.exe ADD 192.168.2.1 MASK 255.255.255.255 192.168.2.1 IF 5
Tue Apr 30 11:12:41 2019 us=273195 Route addition via service succeeded
Tue Apr 30 11:12:41 2019 us=273195 C:\WINDOWS\system32\route.exe ADD 0.0.0.0 MASK 128.0.0.0 10.8.0.1
Tue Apr 30 11:12:41 2019 us=286236 Route addition via service succeeded
Tue Apr 30 11:12:41 2019 us=286236 C:\WINDOWS\system32\route.exe ADD 128.0.0.0 MASK 128.0.0.0 10.8.0.1
Tue Apr 30 11:12:41 2019 us=295265 Route addition via service succeeded
Tue Apr 30 11:12:41 2019 us=295265 Initialization Sequence Completed
Tue Apr 30 11:12:41 2019 us=295265 Register_dns request sent to the service
Tue Apr 30 11:12:41 2019 us=295265 MANAGEMENT: >STATE:1556602961,CONNECTED,SUCCESS,10.8.0.3,192.168.2.1,1194,,
15. Query on my public ip returns actuaally my public ip address without any change.
Can someone guide me further on this.
Thanks