Laxarus
Regular Contributor
Hello,
I was trying to setup a two-way site2site OpenVPN server and noticed a particular bug or configuration mistake.
RT-AC5300 with merlin fw 386.3_2 as openvpn server
RT-AX86U with merlin fw 386.4 as openvpn client.
I used server 2 since server 1 was in use.
I have created a user from the VPN Server menu and setup my VPN server with "Allow only specified clients" setting then I used the newly created username on it. However, I got an autharization failure on the client side. when trying to connect to the server. When I looked at the logs on the server, I noticed the error line like this:
Jan 15 14:37:42 ovpn-server2[10325]: 176.232.59.7:27913 TLS Auth Error: --client-config-dir authentication failed for common name 'client' file='ccd/client'
It appears that the vpn server CN setting is not relayed correctly since it is looking for 'ccd/client', however, it should look for 'ccd/Guneycity'. Since it was the CN I assigned.
I have created another entry under the "Allowed Clients" and named it client. This time my VPN client successfully connected.
I am not sure if this is fixed in the latest version if not I would like to report it @RMerlin and cannot access the server side since I am not on site.
I hope this will be helpful. I can provide more logs if requested.
I was trying to setup a two-way site2site OpenVPN server and noticed a particular bug or configuration mistake.
RT-AC5300 with merlin fw 386.3_2 as openvpn server
RT-AX86U with merlin fw 386.4 as openvpn client.
I used server 2 since server 1 was in use.
I have created a user from the VPN Server menu and setup my VPN server with "Allow only specified clients" setting then I used the newly created username on it. However, I got an autharization failure on the client side. when trying to connect to the server. When I looked at the logs on the server, I noticed the error line like this:
Jan 15 14:37:42 ovpn-server2[10325]: 176.232.59.7:27913 TLS Auth Error: --client-config-dir authentication failed for common name 'client' file='ccd/client'
It appears that the vpn server CN setting is not relayed correctly since it is looking for 'ccd/client', however, it should look for 'ccd/Guneycity'. Since it was the CN I assigned.
I have created another entry under the "Allowed Clients" and named it client. This time my VPN client successfully connected.
I am not sure if this is fixed in the latest version if not I would like to report it @RMerlin and cannot access the server side since I am not on site.
I hope this will be helpful. I can provide more logs if requested.