Hello!

Just got almost the same situation - i.e. client stuck, but with 
different output:

Jul 29 14:46:43 polom-vpn openvpn[27732]: Data Channel Encrypt: Cipher 
'BF-CBC' initialized with 128 bit key
Jul 29 14:46:43 polom-vpn openvpn[27732]: Data Channel Encrypt: Using 
160 bit message hash 'SHA1' for HMAC authentication
Jul 29 14:46:43 polom-vpn openvpn[27732]: Data Channel Decrypt: Cipher 
'BF-CBC' initialized with 128 bit key
Jul 29 14:46:43 polom-vpn openvpn[27732]: Data Channel Decrypt: Using 
160 bit message hash 'SHA1' for HMAC authentication
Jul 29 14:46:43 polom-vpn openvpn[27732]: Control Channel: TLSv1, cipher 
TLSv1/SSLv3 DHE-RSA-AES256-SHA, 1024 bit RSA
Jul 29 15:11:59 polom-vpn openvpn[27732]: event_wait : Interrupted 
system call (code=4)


On server side server found that it lost connection, but client waited 
for something.

At 15:11:59 I restarted openvpn client, this -  event_wait : Interrupted 
system call (code=4) - is from openvpn stop.

centos 6 again, don't remember the same client , or not.

may be there is some option to limit system calls waiting?

Thank you!


15.07.2016 13:04, Dmitry Melekhov пишет:
> Hello!
>
> This night one of connections was not able to reconnect , last message 
> in log is:
>
> Peer Connection Initiated with
>
> and this is all, openvpn process was running, though.
>
> On server side I see:
> SENT CONTROL
> TLS Error: TLS key negotiation failed to occur within 60 seconds 
> (check your network connectivity)
> TLS Error: TLS handshake failed
> Inactivity timeout (--ping-restart), restarting
> SIGUSR1[soft,ping-restart] received, client-instance restarting
>
> So I killed openvpn client and started it again.
>
> But is it possible to do something to make client restart?
>
> btw, OpenVPN 2.3.11  on centos 6.
>
> Thank you!
>
>


------------------------------------------------------------------------------
_______________________________________________
Openvpn-users mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/openvpn-users

Reply via email to