V
V
Vasily Kokhansky2015-02-23 00:21:02
openvpn
Vasily Kokhansky, 2015-02-23 00:21:02

OpenVPN: Mikrotik - server, OpenWRT - client, how to connect?

There is a working OpenVPN server on Mikrotik (x86 arch), I connect from any clients: Ubuntu (x64), Debian (ARM), Android 4.4.2 (ARM), Windows 7 (x64) but not with OpenWRT (MIPS, Barrier Breaker 14.07) , D-Link DIR-825 C1 rev.). When changing the platform, the config did not change, it works fine.
Config:
client
remote 127.0.0.1 1194
proto tcp
dev tap
persist-key
persist-tun
ca ca.crt
cert MikroTik_OpenVPN_Client.crt
key MikroTik_OpenVPN_Client.key
script-security 2 system
up /etc/openvpn/routes
log /var/log/openvpn. log
verb 5
auth-user-pass auth.cfg
log verb 10:
Sun Feb 22 20:46:28 2015 us=93066 WARNING: No server certificate verification method has been enabled. See openvpn.net/howto.html#mitm for more info.
Sun Feb 22 20:46:28 2015 us=93325 Re-using SSL/TLS context
Sun Feb 22 20:46:28 2015 us=93938 Control Channel MTU parms [ L:1575 D:140 EF:40 EB:0 ET: 0 EL:0 ]
Sun Feb 22 20:46:28 2015 us=94210 Socket Buffers: R=[87380->131072] S=[16384->131072]
Sun Feb 22 20:46:28 2015 us=94398 Data Channel MTU parms [ L:1575 D:1450 EF:43 EB:4 ET:32 EL:0 ]
Sun Feb 22 20:46:28 2015 us=94563 Attempting to establish TCP connection with [AF_INET]127.0.0.1:1194 [nonblock ]
Sun Feb 22 20:46:29 2015 us=95106 TCP connection established with [AF_INET]127.0.0.1:1194
Sun Feb 22 20:46:29 2015 us=95297 TCPv4_CLIENT link local: [undef]
Sun Feb 22 20:46:29 2015 us=95436 TCPv4_CLIENT link remote: [AF_INET]127.0.0.1:1194
Sun Feb 22 20:46: 29 2015 us=95686 event_wait returned 1
Sun Feb 22 20:46:29 2015 us=95958 TCPv4_CLIENT WRITE [14] to [AF_INET]127.0.0.1:1194: P_CONTROL_HARD_RESET_CLIENT_V2 kid=0 sid=2ea43bb4 7ab924= DATA p [
] Feb 22 20:46:29 2015 us=96213 TCPv4_CLIENT write returned 16
Sun Feb 22 20:46:29 2015 us=96743 event_wait returned 1
Sun Feb 22 20:46:29 2015 us=96944 TCPv4_CLIENT read returned 14
Sun Feb 22 20 :46:29 2015 us=97196 TCPv4_CLIENT READ [14] from [AF_INET]127.0.0.1:1194: P_CONTROL_HARD_RESET_SERVER_V2 kid=0 sid=a1a6943c 252e2fe7 [ ] pid=0 DATA
Sun Feb 22 20:46:29 2015 us=97392 TLS: Initial packet from [AF_INET]127.0.0.1:1194, sid=a1a6943c 252e2fe7
Sun Feb 22 20:46:29 2015 us=97591 event_wait returned 1
Sun Feb 22 20: 46:29 2015 us=97895 TCPv4_CLIENT WRITE [26] to [AF_INET]127.0.0.1:1194: P_CONTROL_HARD_RESET_CLIENT_V2 kid=0 sid=2ea43bb4 7ab924a5 [ 0 sid=a1a6943c 2592e2fe7 ] pid=0 DATA Feb2:41:41 DATA
Feb2 us=98042 TCPv4_CLIENT write returned 28
Sun Feb 22 20:46:29 2015 us=110711 event_wait returned 1
Sun Feb 22 20:46:29 2015 us=110918 TCPv4_CLIENT read returned 22
Sun Feb 22 20:46:29 2015 us=111206 TCPv4_CLIENT READ [22] from [AF_INET]127.0.0.1:1194: P_ACK_V1 kid=0 sid=a1a6943c 252e2fe7 [ 0 sid=2ea43bb4 7ab924a5 ]
Sun Feb 22 20:46:29 2015 us=111725 event_wait returned 1
Sun Feb 22 20:46:29 2015 US = 112532 TCPV4_CLIENT WRITE [114] TO [AF_INET] 127.0.0.1:1194: p_control_v1 kid = 0 sid = 2EA43BB4 7AB924A5 [] PID = 1 DATA 16030100 A5010000 A10301A1 EE37A1B9 D860317A 237BDF29 E1A2EF1E 51B5970 [ more...]
Sun Feb 22 20:46:29 2015 us=112683 TCPv4_CLIENT write returned 116
Sun Feb 22 20:46:29 2015 us=112995 event_wait returned 1
Sun Feb 22 20:46:29 2015 us=113694 TCPv4_CLIENT WRITE [84] To [af_inet] 127.0.0.1:1194: p_control_v1 kid = 0 sid = 2EA43BB4 7AB924A5 [] PID = 2 DATA C00DC003 000A0015 00120009 00140011 00080006 000300FFF 02010000 29000B0 [more ...]
Sun Feb 22 20:46:29 2015 us=113880 TCPv4_CLIENT write returned 86
Sun Feb 22 20:46:29 2015 us=175625 event_wait returned 1
Sun Feb 22 20:46:29 2015 us=175832 TCPv4_CLIENT read returned 22
Sun Feb 22 20:46:29 2015 us=176119 TCPv4_CLIENT READ [22] from [AF_INET]127.0.0.1:1194: P_ACK_V1 kid=0 sid=a1a6943c 252e2fe7 [ 1 sid=2ea43bb4 7ab924a5 ]
Sun Feb 22:20:29 2015 us=190086 event_wait returned 1
Sun Feb 22 20:46:29 2015 us=190297 TCPv4_CLIENT read returned 22
Sun Feb 22 20:46:29 P_ACK_V1 kid=0 sid=a1a6943c 252e2fe7 [ 2 sid=2ea43bb4 7ab924a5 ]
Sun Feb 22 20:46:29 2015 us=190918 TCPv4_CLIENT read returned 1275
Sun Feb 22 20:46:29 2015 us READ=197923 TCPv4_CLIENT [ AF_INET]127.0.0.1:1194: P_CONTROL_V1 kid=0 sid=a1a6943c 252e2fe7 [ ] pid=1 DATA 16030100 56020000 520301a7 fed7bc0f 1056caf2 1c0f9df6 cd9e15d3 5f228fe[more...
Sun Feb 22 20:46:29 2015 us=201667 VERIFY OK: depth=1, C=UA, ST=UA, L=XXX, O=YYY, OU=IT Dep, CN=YYY CA, name=Mikrotik_OpenVPN, emailAddress [email protected]
Sun Feb 22 20:46:29 2015 us=204419 VERIFY OK: depth=0, C=UA, ST=UA, L=XXX, O=YYY, OU=IT Dep, CN=MikroTik_OpenVPN_Server, name=Mikrotik_OpenVPN, [email protected]
Sun Feb 22 20:46:29 2015 us=208779 event_wait returned 1
Sun Feb 22 20:46:29 2015 us=209645 TCPv4_CLIENT WRITE [126] to [AF_INET]127.0.0.1 : 1194: P_CONTROL_V1 kid = 0 sid = 2ea43bb4 7ab924a5 [1 sid = a1a6943c 252e2fe7] pid = 3 DATA 16030100 86100000 83688504 820080aa 6a2be6cf 0df1ebcd 959357c 369d90d2 [more ...]
Sun 22 Feb 2015 20:46:29 us = 209,925 TCPv4_CLIENT write returned 128
Sun Feb 22 20:46:29 2015 us=210281 event_wait returned 1
Sun Feb 22 20:46:29 2015 us = 211066 TCPv4_CLIENT WRITE [112] to [AF_INET] 127.0.0.1:1194: P_CONTROL_V1 kid = 0 sid = 2ea43bb4 7ab924a5 [] pid = 4 DATA 76c6ea59 585cee60 07bd6852 196cc68b 4a9feb46 43615619 e9c8040f 3fb404e [ more...]
Sun Feb 22 20:46:29 2015 us=211209 TCPv4_CLIENT write returned 114
Sun Feb 22 20:46:29 2015 us=224351 event_wait returned 1
Sun Feb 22 20:46:29 2015 us=224555 TCPv4_CLIENT read returned 22
Sun Feb 22 20:46:29 2015 us=224939 TCPv4_CLIENT READ [22] from [AF_INET]127.0.0.1:1194: P_ACK_V1 kid=0 sid=a1a6943c 252e2fe7 [ 3 sid=2ea43bb4 7ab924a5 ]
Sun 20 Feb 22 :29 2015 us=238795 event_wait returned 1
Sun Feb 22 20:46:29 2015 us=238993 TCPv4_CLIENT read returned 22
Sun Feb 22 20:46:29 2015 us=239277 TCPv4_CLIENT READ [22] from [AF_INET]127.0.0.1:1194: P_ACK_V1 kid=0 sid=a1a6943c 252e2fe7 [ 4 sid=2ea43bb4 7ab924a5 ]
Sun Feb 22:20:29 2015 us=289176 event_wait returned 1
Sun Feb 22 20:46:29 2015 us=289412 TCPv4_CLIENT read returned 73
Sun Feb 22 20:46:29 P_CONTROL_V1 kid=0 sid=a1a6943c 252e2fe7 [ ] pid=2 DATA 14030100 01011603 010030a1 392018a9 f52552e4 3e714508 720b78db 36638ec[more91...]
Sun Feb 22 20:46:2 returned
Sun Feb 22 20:46:29 2015 US = 292463 TCPV4_CLIENT WRITE [126] TO [AF_INET] 127.0.0.1:1194: p_control_v1 kid = 0 sid = 2EA43BB4 7AB924A5 [2 SID = A1A6943C 252E2FE7] PID = 5 DATA 17030100 20D556F6 2AA440BB 85D4B592 818c46cb 0c96f3f6 5e3f33f4 127b1b2[more...]
Sun Feb 22 20:46:29 2015 us=292724 TCPv4_CLIENT write returned 128
Sun Feb 22 20:46:29 2015 us=292983 event_wait returned 1
Sun Feb 22 20:20:25 US = 293769 TCPV4_CLIENT WRITE [114] TO [AF_INET] 127.0.0.0.1:1194: p_control_v1 kid = 0 sid = 2EA43BB4 7AB924A5 [] PID = 6 DATA 18905CD1 24EF3E5A 6DAB1378 E8FEA8C8 2904A59B CFCD5123 EECDECE6 28804CF [more ...] SUN FEB
22 20 :46:29 2015 us=293919 TCPv4_CLIENT write returned 116
Sun Feb 22 20:46:29 2015 us=294138 event_wait returned 1
Sun Feb 22 20:46:29 2015 us = 294803 TCPv4_CLIENT WRITE [80] to [AF_INET] 127.0.0.1:1194: P_CONTROL_V1 kid = 0 sid = 2ea43bb4 7ab924a5 [] pid = 7 DATA 9ccd55ac b53205b0 26be6f7e 128848ef 3e93c2e6 e24eba46 72c8c29e f73f564 [ more...]
Sun Feb 22 20:46:29 2015 us=295007 TCPv4_CLIENT write returned 82
Sun Feb 22 20:46:29 2015 us=307178 event_wait returned 1
Sun Feb 22 20:46:29 2015 us=307384 TCPv4_CLIENT read returned 22
Sun Feb 22 20:46:29 2015 us=307669 TCPv4_CLIENT READ [22] from [AF_INET]127.0.0.1:1194: P_ACK_V1 kid=0 sid=a1a6943c 252e2fe7 [ 5 sid=2ea43bb4 7ab924a5 ]
Sun 20 Feb 22:46 :29 2015 us=321472 event_wait returned 1
Sun Feb 22 20:46:29 2015 us=321671 TCPv4_CLIENT read returned 22
Sun Feb 22 20:46:29 2015 us=321954 TCPv4_CLIENT READ [22] from [AF_INET]127.0.0.1:1194: P_ACK_V1 kid=0 sid=a1a6943c 252e2fe7 [ 6 sid=2ea43bb4 7ab924a5 ]
Sun Feb 22:20:29 2015 us=369054 event_wait returned 1
Sun Feb 22 20:46:29 2015 us=369258 TCPv4_CLIENT read returned 22
Sun Feb 22 20:46:29 P_ACK_V1 kid=0 sid=a1a6943c 252e2fe7 [ 7 sid=2ea43bb4 7ab924a5 ]
Sun Feb 22 20:46:29 2015 us=381259 event_wait returned 1
Sun Feb 22 20:46:29 2015 us=381446 reset Connection, restarting [0]
Sun Feb 22 20:46:29 2015 us=382241 TCP/UDP: Closing socket
Sun Feb 22 20:46:29 2015 us=382623 SIGUSR1[soft,connection-reset] received, process restarting
Sun Feb 22 20:46:29 2015 us=382787 Restart pause, 5 second(s)
Where could be the problem?

Answer the question

In order to leave comments, you need to log in

2 answer(s)
V
Vasily Kokhansky, 2015-03-22
@just_a_man

There is a source of problems: Mikrotik uses openssl 0.9.8 (2005), ubuntu 1.0.1f (2014), and openwrt 1.0.2 (2015). The network says that the new version of openssl does not have support for older versions, hence the problems.

C
Cool Admin, 2015-02-23
@ifaustrue

The line
remote 127.0.0.1 1194
is obviously wrong.
This is what the log says:
Sun Feb 22 20:46:29 2015 us=211066 TCPv4_CLIENT WRITE [112] to [AF_INET]127.0.0.1:1194: P_CONTROL_V1 kid=0

Didn't find what you were looking for?

Ask your question

Ask a Question

731 491 924 answers to any question