Page 1 of 1

Cant establish TCP connection , please help

Posted: Fri May 08, 2020 3:15 pm
by zakdz
Hello :)
So I've installed OpenVPN GUI and it was working perfectly fine , i was connected through my mobile data , and then i switched to my router and i cant connect anymore and i've been experiencing this problem for the past 4 days and i've done a lot of googling but nothing lead to anything helpful , all lead to dead ends , i'll attach the log files below , as previously mentioned i only face this problem whilst using the router ; i've reinstalled OpenVPN several times yet the problem is still there , and another thing i noticed is that i can connect only using one kind of a sim but not the others meaning not all sims can connect ; i've also tried disabling the router's firewall even though there isn't an option for that but you can un-check all the given methods of protection and that's what i did , as i said i used to share my mobile's data with the pc through a usb cable and i've compared the details of both side to side and except for the difference of IpV4 i noticed that my router has IPv6 default gateway and dns server set whilst for the ethernet connection on my mobile its empty , and i've tried to empty them on my router but needless to say i wasn't able to as if i leave it empty it doesn't save the settings , i'm using a Dlink router will provide the type if necessary , i'm also pretty sure the problem doesn't involve the server nor the config because both were were and still working absolutely fine on my mobile's data , i've also tried creating new 5 configs they all seemed to work suing mobile data but not using the router's , i've also googled the error i've been getting and nothing came in handy.
I wanted to add that i just figured out that out of the 3 services installed "OpenVPNServiceInteractive" "OpenVPNServiceLegacy" and "OpenVPNService" , the lastly mentioned which is under "C:\Program Files\OpenVPN\bin\openvpnserv2.exe" , is the only that i can't execute or start through 'Services' , i get this pop up :
"Windows could not start the OpeVpnService on local computer.
Error 1053 : The service did not respond to the start or control request in a timely fashion"
Any help would be hugely appreciated , thanks a lot for your time <3 and have a nice day !
The attached logs contain both logs of when the connection was done through the mobile data and succeeded and when it was through the router and failed , i've tried remove the personal data but i kept a copy with no modifications whatsoever if needed

Code: Select all

Thu May 07 05:10:40 2020 OpenVPN 2.4.9 i686-w64-mingw32 [SSL (OpenSSL)] [LZO] [LZ4] [PKCS11] [AEAD] built on Apr 16 2020
Thu May 07 05:10:40 2020 Windows version 6.2 (Windows 8 or greater) 32bit
Thu May 07 05:10:40 2020 library versions: OpenSSL 1.1.1f  31 Mar 2020, LZO 2.10
Enter Management Password:
Thu May 07 05:10:40 2020 TCP/UDP: Preserving recently used remote address: [AF_INET]xxxxxx:1194
Thu May 07 05:10:40 2020 Attempting to establish TCP connection with [AF_INET]xxxx:1194 [nonblock]
Thu May 07 05:10:41 2020 TCP connection established with [AF_INET]xxxx:1194
Thu May 07 05:10:41 2020 TCP_CLIENT link local: (not bound)
Thu May 07 05:10:41 2020 TCP_CLIENT link remote: [AF_INET]1x.x.x.x1194
Thu May 07 05:10:43 2020 [xxxxxxxx] Peer Connection Initiated with [AF_INET]1xxxxxx:1194
Thu May 07 05:10:44 2020 WARNING: INSECURE cipher with block size less than 128 bit (64 bit).  This allows attacks like SWEET32.  Mitigate by using a --cipher with a larger block size (e.g. AES-256-CBC).
Thu May 07 05:10:44 2020 WARNING: INSECURE cipher with block size less than 128 bit (64 bit).  This allows attacks like SWEET32.  Mitigate by using a --cipher with a larger block size (e.g. AES-256-CBC).
Thu May 07 05:10:44 2020 WARNING: cipher with small block size in use, reducing reneg-bytes to 64MB to mitigate SWEET32 attacks.
Thu May 07 05:10:44 2020 open_tun
Thu May 07 05:10:45 2020 TAP-WIN32 device [Local Area Connection 3] opened: \\.\Global\{xxxxx}.tap
Thu May 07 05:10:45 2020 Notified TAP-Windows driver to set a DHCP IP/netmask of xxxxx on interface {xx [DHCP-serv: 1xx, lease-time: 315xxxx0]
Thu May 07 05:10:45 2020 Successful ARP Flush on interface [2] {xxxxxx}
Thu May 07 05:10:50 2020 WARNING: this configuration may cache passwords in memory -- use the auth-nocache option to prevent this
Thu May 07 05:10:50 2020 Initialization Sequence Completed
Thu May 07 05:20:12 2020 SIGTERM[hard,] received, process exiting

Code: Select all

Thu May 07 04:28:32 2020 OpenVPN 2.4.9 i686-w64-mingw32 [SSL (OpenSSL)] [LZO] [LZ4] [PKCS11] [AEAD] built on Apr 16 2020
Thu May 07 04:28:32 2020 Windows version 6.2 (Windows 8 or greater) 32bit
Thu May 07 04:28:32 2020 library versions: OpenSSL 1.1.1f  31 Mar 2020, LZO 2.10
Enter Management Password:
Thu May 07 04:28:33 2020 TCP/UDP: Preserving recently used remote address: [AF_INET]1xxxx:1194
Thu May 07 04:28:33 2020 Attempting to establish TCP connection with [AF_INET]xxxxx [nonblock]
Thu May 07 04:28:34 2020 TCP connection established with [AF_INET]xxxxx:1194
Thu May 07 04:28:34 2020 TCP_CLIENT link local: (not bound)
Thu May 07 04:28:34 2020 TCP_CLIENT link remote: [AF_INET]xxxxx:1194
Thu May 07 04:28:36 2020 [xxxxxx] Peer Connection Initiated with [AF_INET]xxxxxx:1194
Thu May 07 04:28:37 2020 WARNING: INSECURE cipher with block size less than 128 bit (64 bit).  This allows attacks like SWEET32.  Mitigate by using a --cipher with a larger block size (e.g. AES-256-CBC).
Thu May 07 04:28:37 2020 WARNING: INSECURE cipher with block size less than 128 bit (64 bit).  This allows attacks like SWEET32.  Mitigate by using a --cipher with a larger block size (e.g. AES-256-CBC).
Thu May 07 04:28:37 2020 WARNING: cipher with small block size in use, reducing reneg-bytes to 64MB to mitigate SWEET32 attacks.
Thu May 07 04:28:37 2020 open_tun
Thu May 07 04:28:37 2020 TAP-WIN32 device [Local Area Connection 3] opened: \\.\Global\{xxxxx}.tap
Thu May 07 04:28:37 2020 Notified TAP-Windows driver to set a DHCP IP/netmask of xxxxx on interface {xxx} [DHCP-serv:xxxx, lease-time: 31536000]
Thu May 07 04:28:37 2020 Successful ARP Flush on interface [40] {xxxxx}
Thu May 07 04:28:43 2020 WARNING: this configuration may cache passwords in memory -- use the auth-nocache option to prevent this
Thu May 07 04:28:43 2020 Initialization Sequence Completed
Thu May 07 04:28:48 2020 SIGTERM[hard,] received, process exiting

Code: Select all

Fri May 08 03:36:30 2020 OpenVPN 2.4.9 i686-w64-mingw32 [SSL (OpenSSL)] [LZO] [LZ4] [PKCS11] [AEAD] built on Apr 16 2020
Fri May 08 03:36:30 2020 Windows version 6.2 (Windows 8 or greater) 32bit
Fri May 08 03:36:30 2020 library versions: OpenSSL 1.1.1f  31 Mar 2020, LZO 2.10
Enter Management Password:
Fri May 08 03:36:31 2020 TCP/UDP: Preserving recently used remote address: [AF_INET]xxxxxxxx
Fri May 08 2020 Attempting to establish TCP connection with [AF_INET]xxxxx[nonblock]
Fri May 08 03:38:32 2020 TCP: connect to [AF_INET]xxxxxx failed: Unknown error
Fri May 08 03:38:32 2020 SIGUSR1[connection failed(soft),init_instance] received, process restarting
Fri May 08 03:38:37 2020 TCP/UDP: Preserving recently used remote address: [AF_INET]xxxxxx
Fri May 08 03:38:37 2020 Attempting to establish TCP connection with [AF_INET]xxxxxx [nonblock]
Fri May 08 03:40:37 2020 TCP: connect to [AF_INET]xxxxxxx failed: Unknown error
Fri May 08 03:40:37 2020 SIGUSR1[connection failed(soft),init_instance] received, process restarting
Fri May 08 03:40:42 2020 TCP/UDP: Preserving recently used remote address: [AF_INET]xxxxxxx
Fri May 08 03:40:42 2020 Attempting to establish TCP connection with [AF_INET]xxxxxx [nonblock]
Fri May 08 03:42:43 2020 TCP: connect to [AF_INET]xxxxxx failed: Unknown error
Fri May 08 03:42:43 2020 SIGUSR1[connection failed(soft),init_instance] received, process restarting
Fri May 08 03:42:48 2020 TCP/UDP: Preserving recently used remote address: [AF_INET]xxxxxxxx
Fri May 08 03:42:48 2020 Attempting to establish TCP connection with [AF_INET]xxxxxxxxx [nonblock]
Fri May 08 03:44:15 2020 SIGTERM[hard,init_instance] received, process exiting

Code: Select all

Thu May 07 11:30:02 2020 OpenVPN 2.4.9 i686-w64-mingw32 [SSL (OpenSSL)] [LZO] [LZ4] [PKCS11] [AEAD] built on Apr 16 2020
Thu May 07 11:30:02 2020 Windows version 6.2 (Windows 8 or greater) 32bit
Thu May 07 11:30:02 2020 library versions: OpenSSL 1.1.1f  31 Mar 2020, LZO 2.10
Enter Management Password:
Thu May 07 11:30:02 2020 TCP/UDP: Preserving recently used remote address: [AF_INET]xxxxxx:1194
Thu May 07 11:30:02 2020 Attempting to establish TCP connection with [AF_INET]xxxxx94 [nonblock]
Thu May 07 11:30:15 2020 SIGTERM[hard,init_instance] received, process exiting
[code]
[code]Thu May 07 08:24:16 2020 OpenVPN 2.4.9 i686-w64-mingw32 [SSL (OpenSSL)] [LZO] [LZ4] [PKCS11] [AEAD] built on Apr 16 2020
Thu May 07 08:24:16 2020 Windows version 6.2 (Windows 8 or greater) 32bit
Thu May 07 08:24:16 2020 library versions: OpenSSL 1.1.1f  31 Mar 2020, LZO 2.10
Enter Management Password:
Thu May 07 08:24:17 2020 TCP/UDP: Preserving recently used remote address: [AF_INET]xxxxx:1194
Thu May 07 08:24:17 2020 Attempting to establish TCP connection with [AF_INET]xxxx:1194 [nonblock]
Thu May 07 08:25:31 2020 SIGTERM[hard,init_instance] received, process exiting
i think i might misused this bbcode , but i think this is what i should use to sumbit the log file , i've also deleted the remote ip and some of the first letters of each long code ( the private key , certificate , etc)
Client config

client
nobind
dev tun
key-direction 1
remote-cert-tls server

remote xxxxxxx tcp


<key>
-----BEGIN PRIVATE KEY-----

-----END PRIVATE KEY-----
</key>
<cert>
-----BEGIN CERTIFICATE-----

-----END CERTIFICATE-----
</cert>
<ca>
-----BEGIN CERTIFICATE-----

-----END CERTIFICATE-----
</ca>
<tls-auth>
#
# 2048 bit OpenVPN static key
#
-----BEGIN OpenVPN Static key V1-----

-----END OpenVPN Static key V1-----
</tls-auth>
key-direction 1

i do think that one file configuration would be enough as the problem is concerning the router not the configs files
Once again thanks for your time and have a nice day <3 :)

Re: Cant establish TCP connection , please help

Posted: Fri May 08, 2020 3:17 pm
by zakdz
i obviously failed to use [oconf=] : (

Re: Cant establish TCP connection , please help

Posted: Fri May 08, 2020 3:56 pm
by TinCanTech
zakdz wrote:
Fri May 08, 2020 3:15 pm
I've tried remove the personal data but
but .. you posted your private key and server ca .. so that's compromised now.

All I can say from your logs is that your client cannot connect to your server.

Please read this for further information:
viewtopic.php?f=30&t=22603

Re: Cant establish TCP connection , please help

Posted: Fri May 08, 2020 5:15 pm
by Pippin
Next time use the Preview button before posting,
Thanks.

Re: Cant establish TCP connection , please help

Posted: Fri May 08, 2020 9:46 pm
by zakdz
TinCanTech wrote:
Fri May 08, 2020 3:56 pm
zakdz wrote:
Fri May 08, 2020 3:15 pm
I've tried remove the personal data but
but .. you posted your private key and server ca .. so that's compromised now.

All I can say from your logs is that your client cannot connect to your server.

Please read this for further information:
viewtopic.php?f=30&t=22603
i deleted the first letters of each and i've already read that , i guess by that you can't help me :'( , do you know anywhere else where i can post this and receive help and do you any idea what might've caused the issue besides my client not being able to connect to the server ?

Re: Cant establish TCP connection , please help

Posted: Fri May 08, 2020 9:47 pm
by zakdz
Pippin wrote:
Fri May 08, 2020 5:15 pm
Next time use the Preview button before posting,
Thanks.
good idea

Re: Cant establish TCP connection , please help

Posted: Fri May 08, 2020 10:05 pm
by TinCanTech
zakdz wrote:
Fri May 08, 2020 3:15 pm
then i switched to my router and i cant connect anymore
If your router is actually running openvpn then there will be a log somewhere.

DLink .. I don't know where ..

Re: Cant establish TCP connection , please help

Posted: Fri May 08, 2020 10:07 pm
by zakdz
TinCanTech wrote:
Fri May 08, 2020 10:05 pm
zakdz wrote:
Fri May 08, 2020 3:15 pm
then i switched to my router and i cant connect anymore
If your router is actuall running openvpn then there will be a log somewhere.

DLink .. I don't know where ..
you mean open vpn's log or my router's
incase its my router's i found the firewall log and its just tcp connections with the target being "drop" , i've googled it but i couldn't find anything

Re: Cant establish TCP connection , please help

Posted: Sat May 09, 2020 1:57 pm
by zakdz
I've come to a conclusion , in my 3rd world country we only have one internet provider and besides it being so so shit and yet expensive it for some reason refuses to connect to tcp servers and it's not just my router its everyone's , but we have 3 types of sims provided by three different companies and amongst the three of them only one works ;'( , my other most unlikely theory is that it has something to do with region but its just a theory to make me feel better