What's new

OpenVPN TLS Error Message

  • SNBForums Code of Conduct

    SNBForums is a community for everyone, no matter what their level of experience.

    Please be tolerant and patient of others, especially newcomers. We are all here to share and learn!

    The rules are simple: Be patient, be nice, be helpful or be gone!

Col8eral

Regular Contributor
I have an ASUS RT-AX88U Running Merlin 3004.388.5

I am seeing a TLS error message in my system logs and wondered what it means, if I need to be worried and if it needs fixing some how.

Code:
Jan 16 09:03:22 ovpn-server1[1781]: TLS Error: cannot locate HMAC in incoming packet from [AF_INET]185.XXX.XX.XX:XXXX (via [AF_INET]XXX.XXX.XXX.XX%eth0)

Many thanks
 
This is a normal error message generated in response to internet port scanners. Totally expected if you run your VPN server on a common port like UDP 1194 or TCP 443. Change it to a different (random between 5001 to 32767) port and the messages will probably go away.
 
This is a normal error message generated in response to internet port scanners. Totally expected if you run your VPN server on a common port like UDP 1194 or TCP 443. Change it to a different (random between 5001 to 32767) port and the messages will probably go away.
Ah, OK. Got it. Thank you Colin.
 
I spoke too fast. I have just seen this in my system logs. I don't understand these logs - Is this an attack? Was it successful? I have switched my VPN off for now.

Code:
Jan 16 20:24:33 ovpn-server2[13317]: TCP connection established with [AF_INET]167.94.146.51:53066
Jan 16 20:25:33 ovpn-server2[13317]: 167.94.146.51:53066 Connection reset, restarting [-1]
Jan 16 20:25:33 ovpn-server2[13317]: 167.94.146.51:53066 SIGUSR1[soft,connection-reset] received, client-instance restarting
Jan 16 20:25:36 ovpn-server2[13317]: TCP connection established with [AF_INET]167.94.146.51:53224
Jan 16 20:25:39 ovpn-server2[13317]: 167.94.146.51:53224 Connection reset, restarting [-1]
Jan 16 20:25:39 ovpn-server2[13317]: 167.94.146.51:53224 SIGUSR1[soft,connection-reset] received, client-instance restarting
Jan 16 20:25:40 ovpn-server2[13317]: TCP connection established with [AF_INET]167.94.146.51:54034
Jan 16 20:25:40 ovpn-server2[13317]: 167.94.146.51:54034 WARNING: Bad encapsulated packet length from peer (5635), which must be > 0 and <= 1768 -- please ensure that --tun-mtu or --link-mtu is equal on both peers -- this condition could also indicate a possible active attack on the TCP link -- [Attempting restart...]
Jan 16 20:25:40 ovpn-server2[13317]: 167.94.146.51:54034 Connection reset, restarting [0]
Jan 16 20:25:40 ovpn-server2[13317]: 167.94.146.51:54034 SIGUSR1[soft,connection-reset] received, client-instance restarting
Jan 16 20:25:40 ovpn-server2[13317]: TCP connection established with [AF_INET]167.94.146.51:60240
Jan 16 20:25:43 ovpn-server2[13317]: 167.94.146.51:60240 WARNING: Bad encapsulated packet length from peer (18245), which must be > 0 and <= 1768 -- please ensure that --tun-mtu or --link-mtu is equal on both peers -- this condition could also indicate a possible active attack on the TCP link -- [Attempting restart...]
Jan 16 20:25:43 ovpn-server2[13317]: 167.94.146.51:60240 Connection reset, restarting [0]
Jan 16 20:25:43 ovpn-server2[13317]: 167.94.146.51:60240 SIGUSR1[soft,connection-reset] received, client-instance restarting
Jan 16 20:25:43 ovpn-server2[13317]: TCP connection established with [AF_INET]167.94.146.51:60460
Jan 16 20:25:43 ovpn-server2[13317]: 167.94.146.51:60460 Connection reset, restarting [-1]
Jan 16 20:25:43 ovpn-server2[13317]: 167.94.146.51:60460 SIGUSR1[soft,connection-reset] received, client-instance restarting

Many thanks
 
Thanks Colin. So are they a security company not someone trying to hack me? I'll go higher with my new port number.
 

Latest threads

Support SNBForums w/ Amazon

If you'd like to support SNBForums, just use this link and buy anything on Amazon. Thanks!

Sign Up For SNBForums Daily Digest

Get an update of what's new every day delivered to your mailbox. Sign up here!
Top