thảo luận Cộng đồng sử dụng Pfsense

  • Người tạo chủ đề Người tạo chủ đề chienbinhso13
  • Ngày bắt đầu Ngày bắt đầu
copy log đi bạn
mà add client thì nhớ outbound nat qua interface opvn nhé
Log đây anh
Không biết làm sai ở đâu nữa

Mã:
May 10 22:40:53    openvpn    6653    SIGUSR1[soft,ping-restart] received, process restarting
May 10 22:40:53    openvpn    6653    [UNDEF] Inactivity timeout (--ping-restart), restarting
May 10 22:40:25    openvpn    6653    TLS Error: cannot locate HMAC in incoming packet from [AF_INET]209.97.161.18:1197
May 10 22:40:08    openvpn    6653    TLS Error: cannot locate HMAC in incoming packet from [AF_INET]209.97.161.18:1197
May 10 22:40:00    openvpn    6653    TLS Error: cannot locate HMAC in incoming packet from [AF_INET]209.97.161.18:1197
May 10 22:39:56    openvpn    6653    TLS Error: cannot locate HMAC in incoming packet from [AF_INET]209.97.161.18:1197
May 10 22:39:53    openvpn    6653    TLS Error: cannot locate HMAC in incoming packet from [AF_INET]209.97.161.18:1197
May 10 22:39:53    openvpn    6653    UDPv4 link remote: [AF_INET]209.97.161.18:1197
May 10 22:39:53    openvpn    6653    UDPv4 link local (bound): [AF_INET]10.10.8.10:0
May 10 22:39:53    openvpn    6653    TCP/UDP: Preserving recently used remote address: [AF_INET]209.97.161.18:1197
May 10 22:39:53    openvpn    6653    NOTE: the current --script-security setting may allow this configuration to call user-defined scripts
May 10 22:37:59    openvpn    56339    SIGUSR1[soft,ping-restart] received, process restarting
May 10 22:37:59    openvpn    56339    [UNDEF] Inactivity timeout (--ping-restart), restarting
May 10 22:37:31    openvpn    56339    TLS Error: cannot locate HMAC in incoming packet from [AF_INET]194.156.98.181:1197
May 10 22:37:14    openvpn    56339    TLS Error: cannot locate HMAC in incoming packet from [AF_INET]194.156.98.181:1197
May 10 22:37:13    openvpn    6653    SIGUSR1[soft,ping-restart] received, process restarting
May 10 22:37:13    openvpn    6653    [UNDEF] Inactivity timeout (--ping-restart), restarting
May 10 22:37:07    openvpn    56339    TLS Error: cannot locate HMAC in incoming packet from [AF_INET]194.156.98.181:1197
May 10 22:37:02    openvpn    56339    TLS Error: cannot locate HMAC in incoming packet from [AF_INET]194.156.98.181:1197
May 10 22:36:59    openvpn    56339    TLS Error: cannot locate HMAC in incoming packet from [AF_INET]194.156.98.181:1197
May 10 22:36:59    openvpn    56339    UDPv4 link remote: [AF_INET]194.156.98.181:1197
May 10 22:36:59    openvpn    56339    UDPv4 link local (bound): [AF_INET]10.10.8.10:0
 
Sửa lần cuối:
Log đây anh
Không biết làm sai ở đâu nữa

Mã:
May 10 22:40:53    openvpn    6653    SIGUSR1[soft,ping-restart] received, process restarting
May 10 22:40:53    openvpn    6653    [UNDEF] Inactivity timeout (--ping-restart), restarting
May 10 22:40:25    openvpn    6653    TLS Error: cannot locate HMAC in incoming packet from [AF_INET]209.97.161.18:1197
May 10 22:40:08    openvpn    6653    TLS Error: cannot locate HMAC in incoming packet from [AF_INET]209.97.161.18:1197
May 10 22:40:00    openvpn    6653    TLS Error: cannot locate HMAC in incoming packet from [AF_INET]209.97.161.18:1197
May 10 22:39:56    openvpn    6653    TLS Error: cannot locate HMAC in incoming packet from [AF_INET]209.97.161.18:1197
May 10 22:39:53    openvpn    6653    TLS Error: cannot locate HMAC in incoming packet from [AF_INET]209.97.161.18:1197
May 10 22:39:53    openvpn    6653    UDPv4 link remote: [AF_INET]209.97.161.18:1197
May 10 22:39:53    openvpn    6653    UDPv4 link local (bound): [AF_INET]10.10.8.10:0
May 10 22:39:53    openvpn    6653    TCP/UDP: Preserving recently used remote address: [AF_INET]209.97.161.18:1197
May 10 22:39:53    openvpn    6653    NOTE: the current --script-security setting may allow this configuration to call user-defined scripts
May 10 22:37:59    openvpn    56339    SIGUSR1[soft,ping-restart] received, process restarting
May 10 22:37:59    openvpn    56339    [UNDEF] Inactivity timeout (--ping-restart), restarting
May 10 22:37:31    openvpn    56339    TLS Error: cannot locate HMAC in incoming packet from [AF_INET]194.156.98.181:1197
May 10 22:37:14    openvpn    56339    TLS Error: cannot locate HMAC in incoming packet from [AF_INET]194.156.98.181:1197
May 10 22:37:13    openvpn    6653    SIGUSR1[soft,ping-restart] received, process restarting
May 10 22:37:13    openvpn    6653    [UNDEF] Inactivity timeout (--ping-restart), restarting
May 10 22:37:07    openvpn    56339    TLS Error: cannot locate HMAC in incoming packet from [AF_INET]194.156.98.181:1197
May 10 22:37:02    openvpn    56339    TLS Error: cannot locate HMAC in incoming packet from [AF_INET]194.156.98.181:1197
May 10 22:36:59    openvpn    56339    TLS Error: cannot locate HMAC in incoming packet from [AF_INET]194.156.98.181:1197
May 10 22:36:59    openvpn    56339    UDPv4 link remote: [AF_INET]194.156.98.181:1197
May 10 22:36:59    openvpn    56339    UDPv4 link local (bound): [AF_INET]10.10.8.10:0
TLS key ko match
 
TLS key ko match
Có search TLS thì không có match, mà file config của thằng vpn thì không có key TLS ?
Mà tắt TLS trong Cryptographic Settings thì nó báo TLS Error, reconnecting

Còn log thì nó báo là

Mã:
May 10 23:20:48    openvpn    36654    SIGUSR1[soft,tls-error] received, process restarting
May 10 23:20:48    openvpn    36654    TLS Error: TLS handshake failed
May 10 23:20:48    openvpn    36654    TLS Error: TLS object -> incoming plaintext read error
May 10 23:20:48    openvpn    36654    TLS_ERROR: BIO read tls_read_plaintext error
May 10 23:20:48    openvpn    36654    OpenSSL: error:0A000086:SSL routines::certificate verify failed:
May 10 23:20:48    openvpn    36654    VERIFY ERROR: depth=2, error=self-signed certificate in certificate chain: C=US, ST=NY, L=New York, O=KeepSolid Inc., OU=KeepSolid Root CA, CN=KeepSolid Root CA, [email protected], serial=429164281094478856831696042475561970021707008630

Có anh hettien xài loại vpn này, để hỏi ảnh coi sao. :(
@hetien
 
Có anh trai nào biết cách thêm openvpn vào pfsense 2.7.2 không ? giúp với
Mình có file cấu hình openvpn, add vào phần mềm OpenVPN Connect trên PC thì kết nối bình thường, còn thêm vào pfsense thì không kết nối server được ? Không biết làm sai chỗ nào.

Mã:
client
dev tun
reneg-sec 0
persist-tun
persist-key
ping 5
nobind
allow-compression no
remote-random
remote-cert-tls server
auth-nocache
route-metric 1
cipher AES-256-CBC
auth sha512
<ca>
-----BEGIN CERTIFICATE-----

-----END CERTIFICATE-----
-----BEGIN CERTIFICATE-----

-----END CERTIFICATE-----
</ca>
<cert>

-----BEGIN CERTIFICATE-----

-----END CERTIFICATE-----
</cert>
<key>
-----BEGIN PRIVATE KEY-----

-----END PRIVATE KEY-----

</key>
remote sg.vpnunlimitedapp.com
proto udp

port 1197

File config nó không có key TLS (bên vpn nó cho như vậy thôi ?)

Xem tệp đính kèm 2486522
Xem tệp đính kèm 2486521Xem tệp đính kèm 2486534Xem tệp đính kèm 2486533Xem tệp đính kèm 2486532Xem tệp đính kèm 2486531Xem tệp đính kèm 2486530Xem tệp đính kèm 2486529
Xem tệp đính kèm 2486537

Nhờ mấy anh trai giúp đỡ
:(
1. trong cái phần TLS configuration, bỏ check cái use a TLS key đi.
2. thử bỏ check cái Server Certificate Key Usage Validation đi
 
1. trong cái phần TLS configuration, bỏ check cái use a TLS key đi.
2. thử bỏ check cái Server Certificate Key Usage Validation đi
Không được sếp, đợi anh hetien vào coi sao.
Nếu bỏ TLS và Key Usage Validation thì báo TLS Error, reconnecting và log báo

May 10 23:57:19openvpn33963SIGUSR1[soft,tls-error] received, process restarting
May 10 23:57:19openvpn33963TLS Error: TLS handshake failed
May 10 23:57:19openvpn33963TLS Error: TLS object -> incoming plaintext read error
May 10 23:57:19openvpn33963TLS_ERROR: BIO read tls_read_plaintext error
 
Không được sếp, đợi anh hetien vào coi sao.
Nếu bỏ TLS và Key Usage Validation thì báo TLS Error, reconnecting và log báo

May 10 23:57:19openvpn33963SIGUSR1[soft,tls-error] received, process restarting
May 10 23:57:19openvpn33963TLS Error: TLS handshake failed
May 10 23:57:19openvpn33963TLS Error: TLS object -> incoming plaintext read error
May 10 23:57:19openvpn33963TLS_ERROR: BIO read tls_read_plaintext error
nếu trong phần Client Certificate thím chọn cái Cer_Solid_SG thì có gì khác không?
 
nếu trong phần Client Certificate thím chọn cái Cer_Solid_SG thì có gì khác không?
Đã chọn Client Certificate là cer_solid_sg rồi đó thím.
ovpnc1
Solid-SG UDP4
TLS Error, reconnectingSat May 11 0:03:17 2024(pending)(pending)

Có cái lạ là log nó báo

May 11 00:05:07openvpn33963VERIFY ERROR: depth=1, error=unable to get issuer certificate: C=US, ST=NY, L=New York, O=KeepSolid Inc., OU=KeepSolid CA, CN=OpenVPN Server SubCA, emailAddress=[email protected], serial=86674844403071322814608619069874395722

Để mai hỏi anh hetien, giờ đi ngủ thôi.
 
Đã chọn Client Certificate là cer_solid_sg rồi đó thím.
ovpnc1
Solid-SG UDP4
TLS Error, reconnectingSat May 11 0:03:17 2024(pending)(pending)

Có cái lạ là log nó báo

May 11 00:05:07openvpn33963VERIFY ERROR: depth=1, error=unable to get issuer certificate: C=US, ST=NY, L=New York, O=KeepSolid Inc., OU=KeepSolid CA, CN=OpenVPN Server SubCA, emailAddress=[email protected], serial=86674844403071322814608619069874395722
Để mai hỏi anh hetien, giờ đi ngủ thôi.
bên dịch vụ vpn của thím nó có hướng dẫn cho pfsense nè.

trong hướng dẫn nó kêu xài port 1194. chắc đây là vấn đề cũng nên lolz
 
bên dịch vụ vpn của thím nó có hướng dẫn cho pfsense nè.

trong hướng dẫn nó kêu xài port 1194. chắc đây là vấn đề cũng nên lolz
Xài port 1194 trong hướng dẫn cũng y vậy à thím.

Còn trong file config nó tạo ra thì để port 1197 .... nó cũng báo lỗi đó à.

Mà thằng này có không có xài key TLS

notepad_h0xHM8zqVK.png



Mà quên nữa là đang cài bản 2.7.2 ( mới quá không biết nó chạy được không )


May 11 00:44:01openvpn53824SIGUSR1[soft,tls-error] received, process restarting
May 11 00:44:01openvpn53824TLS Error: TLS handshake failed
May 11 00:44:01openvpn53824TLS Error: TLS object -> incoming plaintext read error
May 11 00:44:01openvpn53824TLS_ERROR: BIO read tls_read_plaintext error
May 11 00:44:01openvpn53824OpenSSL: error:0A000086:SSL routines::certificate verify failed:
May 11 00:44:01openvpn53824VERIFY ERROR: depth=1, error=unable to get issuer certificate: C=US, ST=NY, L=New York, O=KeepSolid Inc., OU=KeepSolid CA, CN=OpenVPN Server SubCA, emailAddress=[email protected], serial=86674844403071322814608619069874395722
May 11 00:44:01openvpn53824TLS: Initial packet from [AF_INET]143.198.207.218:1197, sid=dfa11a95 64feb2c3
May 11 00:44:01openvpn53824UDPv4 link remote: [AF_INET]143.198.207.218:1197
May 11 00:44:01openvpn53824UDPv4 link local (bound): [AF_INET]10.10.8.10:0
May 11 00:44:01openvpn53824Socket Buffers: R=[42080->42080] S=[57344->57344]
May 11 00:44:01openvpn53824TCP/UDP: Preserving recently used remote address: [AF_INET]143.198.207.218:1197
May 11 00:44:01openvpn53824NOTE: the current --script-security setting may allow this configuration to call user-defined scripts
 
Sửa lần cuối:
Không được sếp, đợi anh hetien vào coi sao.
Nếu bỏ TLS và Key Usage Validation thì báo TLS Error, reconnecting và log báo

May 10 23:57:19openvpn33963SIGUSR1[soft,tls-error] received, process restarting
May 10 23:57:19openvpn33963TLS Error: TLS handshake failed
May 10 23:57:19openvpn33963TLS Error: TLS object -> incoming plaintext read error
May 10 23:57:19openvpn33963TLS_ERROR: BIO read tls_read_plaintext error
Openvpn chọn đúng mã hóa sha256 hoặc 512 bit.
Thiết lập chỗ Cert đúng chưa nhỉ?
 
Mong các Bác chỉ dẫn em làm. Định tuyến khi xem youtube sẽ chạy một wan khác. Em set ruler hoài không được :(
 
Mong các Bác chỉ dẫn em làm. Định tuyến khi xem youtube sẽ chạy một wan khác. Em set ruler hoài không được :(
youtube nó xài ti tỉ cái tên miền, nếu chơi Alias thì ko đc vì ko biết hết FQDN. có chơi theo dải IP google đẩy hết sang wan cụ thể thì may ra
 
Lên 2.7.2 xài wireguard luôn rồi.
E đang bị kẹt chỗ openwrt? Chiều về a cài lại openwrt trên 2.7.2
Em xài pfsense bản 2.7.2, còn vpn là của thằng solid unlimited
Tối nay em định về bản 2.6 hoặc 2.5 để thử lại. Mà không biết nên dùng bản 2.5 hay 2.6 nữa
 
Có anh trai nào biết cách thêm openvpn vào pfsense 2.7.2 không ? giúp với
Mình có file cấu hình openvpn, add vào phần mềm OpenVPN Connect trên PC thì kết nối bình thường, còn thêm vào pfsense thì không kết nối server được ? Không biết làm sai chỗ nào.

Mã:
client
dev tun
reneg-sec 0
persist-tun
persist-key
ping 5
nobind
allow-compression no
remote-random
remote-cert-tls server
auth-nocache
route-metric 1
cipher AES-256-CBC
auth sha512
<ca>
-----BEGIN CERTIFICATE-----

-----END CERTIFICATE-----
-----BEGIN CERTIFICATE-----

-----END CERTIFICATE-----
</ca>
<cert>

-----BEGIN CERTIFICATE-----

-----END CERTIFICATE-----
</cert>
<key>
-----BEGIN PRIVATE KEY-----

-----END PRIVATE KEY-----

</key>
remote sg.vpnunlimitedapp.com
proto udp

port 1197

File config nó không có key TLS (bên vpn nó
Nhờ mấy anh trai giúp đỡ
:(
Chỗ username & password để trống, e điền vào báo sai là đúng rồi.
TLS Config uncheck (các phần TLS ko có sử dụng. Keepsolid xác thực mạng bằng CA & Cert, Private rồi.
Dùng EAS-256-GCM (mấy cái khác bỏ đi)
 
Sửa lần cuối:
Chỗ username & password để trống, e điền vào báo sai là đúng rồi.
TLS Config uncheck (các phần TLS ko có sử dụng. Keepsolid xác thực mạng bằng CA & Cert, Private rồi.
Dùng EAS-256-GCM (mấy cái khác bỏ đi)
thử hết rồi anh, nó không xác thực được với CER

May 11 21:35:38openvpn66620SIGUSR1[soft,tls-error] received, process restarting
May 11 21:35:38openvpn66620TLS Error: TLS handshake failed
May 11 21:35:38openvpn66620TLS Error: TLS object -> incoming plaintext read error
May 11 21:35:38openvpn66620TLS_ERROR: BIO read tls_read_plaintext error
May 11 21:35:38openvpn66620OpenSSL: error:0A000086:SSL routines::certificate verify failed:
May 11 21:35:38openvpn66620VERIFY ERROR: depth=1, error=unable to get issuer certificate: C=US, ST=NY, L=New York, O=KeepSolid Inc., OU=KeepSolid CA, CN=OpenVPN Server SubCA, emailAddress=[email protected], serial=86674844403071322814608619069874395722

Em đang đổi qua wireguard coi sao
 

Thống kê chủ đề

Ngày tạo
chienbinhso13,
Người trả lời cuối
h3ti3n,
Trả lời
1.948
Lượt xem
150.707
Quay lại
Lên đầu trang