Hi Guys,
I was able to connect to my openvpn server (PfSense 2.1.5) but I haven't seen any routes being pulled or propagate on my routing table inside my Asus gear, Please see System Logs I extract from the asus router.
Aug 24 21:59:50 kernel: tun: Universal TUN/TAP device driver, 1.6
Aug 24 21:59:50 kernel: tun: (C) 1999-2004 Max Krasnyansky <maxk@qualcomm.com>
Aug 24 21:59:52 openvpn[4276]: OpenVPN 2.3.11 arm-unknown-linux-gnu [SSL (OpenSSL)] [LZO] [EPOLL] [MH] [IPv6] built on Aug 4 2016
Aug 24 21:59:52 openvpn[4276]: library versions: OpenSSL 1.0.2h 3 May 2016, LZO 2.08
Aug 24 21:59:52 openvpn[4277]: NOTE: the current --script-security setting may allow this configuration to call user-defined scripts
Aug 24 21:59:52 openvpn[4277]: Control Channel Authentication: using 'static.key' as a OpenVPN static key file
Aug 24 21:59:52 openvpn[4277]: Outgoing Control Channel Authentication: Using 160 bit message hash 'SHA1' for HMAC authentication
Aug 24 21:59:52 openvpn[4277]: Incoming Control Channel Authentication: Using 160 bit message hash 'SHA1' for HMAC authentication
Aug 24 21:59:52 openvpn[4277]: Socket Buffers: R=[122880->122880] S=[122880->122880]
Aug 24 21:59:52 openvpn[4277]: UDPv4 link local: [undef]
Aug 24 21:59:52 openvpn[4277]: UDPv4 link remote: [AF_INET]122.52.xxx.xxx:1194
Aug 24 21:59:52 openvpn[4277]: TLS: Initial packet from [AF_INET]122.52.xxx.xxx:1194, sid=70589112 a399190f
Aug 24 21:59:52 openvpn[4277]: WARNING: this configuration may cache passwords in memory -- use the auth-nocache option to prevent this
Aug 24 21:59:52 openvpn[4277]: VERIFY OK: depth=1, C=PH, ST=Manila, L=Muntinlupa City, O=XXXX, emailAddress=rc@xxxx.com, CN=Local CA
Aug 24 21:59:52 openvpn[4277]: VERIFY OK: nsCertType=SERVER
Aug 24 21:59:52 openvpn[4277]: VERIFY X509NAME OK: C=PH, ST=Manila, L=Muntinlupa City, O=XXXX, emailAddress=rc@xxx.com, CN=Cert
Aug 24 21:59:52 openvpn[4277]: VERIFY OK: depth=0, C=PH, ST=Manila, L=Muntinlupa City, O=XXXX, emailAddress=rc@xxxx.com, CN=Cert
There should be a section like this below before the routes has been pulled on the server but I haven't seen this on the System Log on my Asus gear.
2016-08-24 21:11:13 Data Channel Encrypt: Cipher 'AES-128-CBC' initialized with 128 bit key
2016-08-24 21:11:13 Data Channel Encrypt: Using 160 bit message hash 'SHA1' for HMAC authentication
2016-08-24 21:11:13 Data Channel Decrypt: Cipher 'AES-128-CBC' initialized with 128 bit key
2016-08-24 21:11:13 Data Channel Decrypt: Using 160 bit message hash 'SHA1' for HMAC authentication
2016-08-24 21:11:13 Control Channel: TLSv1.2, cipher TLSv1/SSLv3 DHE-RSA-AES256-GCM-SHA384, 2048 bit RSA
2016-08-24 21:11:13 [Cert] Peer Connection Initiated with [AF_INET]122.52.xxx.xxx:1194
2016-08-24 21:11:14 MANAGEMENT: >STATE:1472044274,GET_CONFIG,,,
2016-08-24 21:11:15 SENT CONTROL [Cert]: 'PUSH_REQUEST' (status=1)
2016-08-24 21:11:15 PUSH: Received control message: 'PUSH_REPLY,route 192.168.0.0 255.255.255.0,dhcp-option DNS 192.168.0.202,dhcp-option DNS 8.8.8.8,route 192.168.250.1,topology net30,ping 10,ping-restart 60,ifconfig 192.168.250.6 192.168.250.5'
relevant custom configuration from my asus router the rest of the config was define on the GUI like certs,peers,protocol etc.
ns-cert-type server
resolv-retry infinite
verify-x509-name "Cert" name
Thanks in advance
I was able to connect to my openvpn server (PfSense 2.1.5) but I haven't seen any routes being pulled or propagate on my routing table inside my Asus gear, Please see System Logs I extract from the asus router.
Aug 24 21:59:50 kernel: tun: Universal TUN/TAP device driver, 1.6
Aug 24 21:59:50 kernel: tun: (C) 1999-2004 Max Krasnyansky <maxk@qualcomm.com>
Aug 24 21:59:52 openvpn[4276]: OpenVPN 2.3.11 arm-unknown-linux-gnu [SSL (OpenSSL)] [LZO] [EPOLL] [MH] [IPv6] built on Aug 4 2016
Aug 24 21:59:52 openvpn[4276]: library versions: OpenSSL 1.0.2h 3 May 2016, LZO 2.08
Aug 24 21:59:52 openvpn[4277]: NOTE: the current --script-security setting may allow this configuration to call user-defined scripts
Aug 24 21:59:52 openvpn[4277]: Control Channel Authentication: using 'static.key' as a OpenVPN static key file
Aug 24 21:59:52 openvpn[4277]: Outgoing Control Channel Authentication: Using 160 bit message hash 'SHA1' for HMAC authentication
Aug 24 21:59:52 openvpn[4277]: Incoming Control Channel Authentication: Using 160 bit message hash 'SHA1' for HMAC authentication
Aug 24 21:59:52 openvpn[4277]: Socket Buffers: R=[122880->122880] S=[122880->122880]
Aug 24 21:59:52 openvpn[4277]: UDPv4 link local: [undef]
Aug 24 21:59:52 openvpn[4277]: UDPv4 link remote: [AF_INET]122.52.xxx.xxx:1194
Aug 24 21:59:52 openvpn[4277]: TLS: Initial packet from [AF_INET]122.52.xxx.xxx:1194, sid=70589112 a399190f
Aug 24 21:59:52 openvpn[4277]: WARNING: this configuration may cache passwords in memory -- use the auth-nocache option to prevent this
Aug 24 21:59:52 openvpn[4277]: VERIFY OK: depth=1, C=PH, ST=Manila, L=Muntinlupa City, O=XXXX, emailAddress=rc@xxxx.com, CN=Local CA
Aug 24 21:59:52 openvpn[4277]: VERIFY OK: nsCertType=SERVER
Aug 24 21:59:52 openvpn[4277]: VERIFY X509NAME OK: C=PH, ST=Manila, L=Muntinlupa City, O=XXXX, emailAddress=rc@xxx.com, CN=Cert
Aug 24 21:59:52 openvpn[4277]: VERIFY OK: depth=0, C=PH, ST=Manila, L=Muntinlupa City, O=XXXX, emailAddress=rc@xxxx.com, CN=Cert
There should be a section like this below before the routes has been pulled on the server but I haven't seen this on the System Log on my Asus gear.
2016-08-24 21:11:13 Data Channel Encrypt: Cipher 'AES-128-CBC' initialized with 128 bit key
2016-08-24 21:11:13 Data Channel Encrypt: Using 160 bit message hash 'SHA1' for HMAC authentication
2016-08-24 21:11:13 Data Channel Decrypt: Cipher 'AES-128-CBC' initialized with 128 bit key
2016-08-24 21:11:13 Data Channel Decrypt: Using 160 bit message hash 'SHA1' for HMAC authentication
2016-08-24 21:11:13 Control Channel: TLSv1.2, cipher TLSv1/SSLv3 DHE-RSA-AES256-GCM-SHA384, 2048 bit RSA
2016-08-24 21:11:13 [Cert] Peer Connection Initiated with [AF_INET]122.52.xxx.xxx:1194
2016-08-24 21:11:14 MANAGEMENT: >STATE:1472044274,GET_CONFIG,,,
2016-08-24 21:11:15 SENT CONTROL [Cert]: 'PUSH_REQUEST' (status=1)
2016-08-24 21:11:15 PUSH: Received control message: 'PUSH_REPLY,route 192.168.0.0 255.255.255.0,dhcp-option DNS 192.168.0.202,dhcp-option DNS 8.8.8.8,route 192.168.250.1,topology net30,ping 10,ping-restart 60,ifconfig 192.168.250.6 192.168.250.5'
relevant custom configuration from my asus router the rest of the config was define on the GUI like certs,peers,protocol etc.
ns-cert-type server
resolv-retry infinite
verify-x509-name "Cert" name
Thanks in advance