ma001ta 0 Posted ... Can anyone tell me what I'm doing wrong here? I've uploaded the config file once it was generated yet I can't access the WAN once started. System log follows: Jul 11 00:37:13 rc_service: httpd 475:notify_rc start_vpnclient1Jul 11 00:37:13 kernel: tun: Universal TUN/TAP device driver, 1.6Jul 11 00:37:13 kernel: tun: © 1999-2004 Max Krasnyansky <maxk@qualcomm.com>Jul 11 00:37:13 openvpn[1132]: OpenVPN 2.3.7 arm-unknown-linux-gnu [sSL (OpenSSL)] [LZO] [EPOLL] [MH] [iPv6] built on Jul 3 2015Jul 11 00:37:13 openvpn[1132]: library versions: OpenSSL 1.0.2c 12 Jun 2015, LZO 2.08Jul 11 00:37:13 openvpn[1133]: NOTE: the current --script-security setting may allow this configuration to call user-defined scriptsJul 11 00:37:13 openvpn[1133]: Control Channel Authentication: using 'static.key' as a OpenVPN static key fileJul 11 00:37:13 openvpn[1133]: Outgoing Control Channel Authentication: Using 160 bit message hash 'SHA1' for HMAC authenticationJul 11 00:37:13 openvpn[1133]: Incoming Control Channel Authentication: Using 160 bit message hash 'SHA1' for HMAC authenticationJul 11 00:37:13 openvpn[1133]: Socket Buffers: R=[122880->131072] S=[122880->131072]Jul 11 00:37:13 openvpn[1133]: UDPv4 link local: [undef]Jul 11 00:37:13 openvpn[1133]: UDPv4 link remote: [AF_INET]46.29.125.13:443Jul 11 00:37:14 openvpn[1133]: TLS: Initial packet from [AF_INET]46.29.125.13:443, sid=58fd4adc ca787124Jul 11 00:37:14 openvpn[1133]: VERIFY OK: depth=1, C=IT, ST=IT, L=Perugia, O=airvpn.org, CN=airvpn.org CA, emailAddress=info@airvpn.orgJul 11 00:37:14 openvpn[1133]: Validating certificate key usageJul 11 00:37:14 openvpn[1133]: ++ Certificate has key usage 00a0, expects 00a0Jul 11 00:37:14 openvpn[1133]: VERIFY KU OKJul 11 00:37:14 openvpn[1133]: Validating certificate extended key usageJul 11 00:37:14 openvpn[1133]: ++ Certificate has EKU (str) TLS Web Server Authentication, expects TLS Web Server AuthenticationJul 11 00:37:14 openvpn[1133]: VERIFY EKU OKJul 11 00:37:14 openvpn[1133]: VERIFY OK: depth=0, C=IT, ST=IT, L=Perugia, O=airvpn.org, CN=server, emailAddress=info@airvpn.orgJul 11 00:37:18 openvpn[1133]: Data Channel Encrypt: Cipher 'AES-256-CBC' initialized with 256 bit keyJul 11 00:37:18 openvpn[1133]: Data Channel Encrypt: Using 160 bit message hash 'SHA1' for HMAC authenticationJul 11 00:37:18 openvpn[1133]: Data Channel Decrypt: Cipher 'AES-256-CBC' initialized with 256 bit keyJul 11 00:37:18 openvpn[1133]: Data Channel Decrypt: Using 160 bit message hash 'SHA1' for HMAC authenticationJul 11 00:37:18 openvpn[1133]: Control Channel: TLSv1, cipher TLSv1/SSLv3 DHE-RSA-AES256-SHA, 4096 bit RSAJul 11 00:37:18 openvpn[1133]: [server] Peer Connection Initiated with [AF_INET]46.29.125.13:443Jul 11 00:37:20 openvpn[1133]: SENT CONTROL [server]: 'PUSH_REQUEST' (status=1)Jul 11 00:37:21 openvpn[1133]: PUSH: Received control message: 'PUSH_REPLY,redirect-gateway def1 bypass-dhcp,dhcp-option DNS 10.4.0.1,comp-lzo no,route-gateway 10.4.0.1,topology subnet,ping 10,ping-restart 60,ifconfig 10.4.0.101 255.255.0.0'Jul 11 00:37:21 openvpn[1133]: OPTIONS IMPORT: timers and/or timeouts modifiedJul 11 00:37:21 openvpn[1133]: OPTIONS IMPORT: LZO parms modifiedJul 11 00:37:21 openvpn[1133]: OPTIONS IMPORT: --ifconfig/up options modifiedJul 11 00:37:21 openvpn[1133]: OPTIONS IMPORT: route options modifiedJul 11 00:37:21 openvpn[1133]: OPTIONS IMPORT: route-related options modifiedJul 11 00:37:21 openvpn[1133]: OPTIONS IMPORT: --ip-win32 and/or --dhcp-option options modifiedJul 11 00:37:21 openvpn[1133]: TUN/TAP device tun11 openedJul 11 00:37:21 openvpn[1133]: TUN/TAP TX queue length set to 100Jul 11 00:37:21 openvpn[1133]: do_ifconfig, tt->ipv6=0, tt->did_ifconfig_ipv6_setup=0Jul 11 00:37:21 openvpn[1133]: /usr/sbin/ip link set dev tun11 up mtu 1500Jul 11 00:37:21 openvpn[1133]: /usr/sbin/ip addr add dev tun11 10.4.0.101/16 broadcast 10.4.255.255Jul 11 00:37:26 openvpn[1133]: Ignore conflicted routing rule: 46.29.125.13 255.255.255.255Jul 11 00:37:26 openvpn[1133]: /usr/sbin/ip route add 0.0.0.0/1 via 10.4.0.1Jul 11 00:37:26 openvpn[1133]: /usr/sbin/ip route add 128.0.0.0/1 via 10.4.0.1Jul 11 00:37:26 openvpn-routing: Skipping, client 1 not in routing policy modeJul 11 00:37:26 openvpn[1133]: Initialization Sequence CompletedJul 11 00:38:12 openvpn[1133]: event_wait : Interrupted system call (code=4)Jul 11 00:38:12 openvpn[1133]: OpenVPN STATISTICSJul 11 00:38:12 openvpn[1133]: Updated,Sat Jul 11 00:38:12 2015Jul 11 00:38:12 openvpn[1133]: TUN/TAP read bytes,6665Jul 11 00:38:12 openvpn[1133]: TUN/TAP write bytes,5302Jul 11 00:38:12 openvpn[1133]: TCP/UDP read bytes,18229Jul 11 00:38:12 openvpn[1133]: TCP/UDP write bytes,20310Jul 11 00:38:12 openvpn[1133]: Auth read bytes,5334Jul 11 00:38:12 openvpn[1133]: pre-compress bytes,0Jul 11 00:38:12 openvpn[1133]: post-compress bytes,0Jul 11 00:38:12 openvpn[1133]: pre-decompress bytes,0Jul 11 00:38:12 openvpn[1133]: post-decompress bytes,0Jul 11 00:38:12 openvpn[1133]: ENDJul 11 00:38:18 rc_service: httpd 475:notify_rc stop_vpnclient1Jul 11 00:38:18 openvpn[1133]: event_wait : Interrupted system call (code=4)Jul 11 00:38:18 openvpn[1133]: SIGTERM received, sending exit notification to peerJul 11 00:38:19 dnsmasq[1115]: exiting on receipt of SIGTERMJul 11 00:38:20 dnsmasq[1191]: started, version 2.73rc8 cachesize 1500Jul 11 00:38:20 dnsmasq[1191]: warning: interface ppp1* does not currently existJul 11 00:38:20 dnsmasq[1191]: asynchronous logging enabled, queue limit is 5 messagesJul 11 00:38:20 dnsmasq-dhcp[1191]: DHCP, IP range 192.168.1.2 -- 192.168.1.254, lease time 1dJul 11 00:38:20 dnsmasq[1191]: read /etc/hosts - 5 addressesJul 11 00:38:20 dnsmasq[1191]: using nameserver 75.75.76.76#53 for domain localJul 11 00:38:20 dnsmasq[1191]: using nameserver 75.75.76.76#53 for domain hsd1.ct.comcast.netJul 11 00:38:20 dnsmasq[1191]: using nameserver 75.75.75.75#53 for domain localJul 11 00:38:20 dnsmasq[1191]: using nameserver 75.75.75.75#53 for domain hsd1.ct.comcast.netJul 11 00:38:20 dnsmasq[1191]: using nameserver 75.75.75.75#53Jul 11 00:38:20 dnsmasq[1191]: using nameserver 75.75.76.76#53 Quote Share this post Link to post
go558a83nk 364 Posted ... can't access the WAN literally or do you mean that nothing "works"? I would imagine it's your use of comcast DNS while connected to VPN. comcast probably rejects any DNS queries from IP other than their own network. In this case it would be coming from the VPN exit IP. you should certainly set your DNS to something other than ISP DNS to avoid their logging. In the openvpn client page set "accept DNS configuration" to exclusive. That way you'll be sure to use AirVPN DNS. Quote Share this post Link to post