Jan Just Keijser schreef op 27-05-2017 22:48:
if all external hosts can reach the server but you (internal host? vpn
server?) then it's - as always - a routing or NATting issue.
<shameless plug>
This _IS_ covered in a recipe of my OpenVPN cookbook
</shameless_plug>
I mean a mail log for myself from this morning shows first from the
server that the client disconnected at 10:18, then the cron job at the
client notifying me that tun0 was down, at 10:32, then one minute later
at 10:33 from the server that the client is reconnecting ;-).
System works like a charm ;-).
This is the last message before disconnect:
May 28 10:17:08 perfection ovpn-synology[29139]: [Diskstation]
Inactivity timeout (--ping-restart), restarting
May 28 10:17:08 perfection ovpn-synology[29139]: /sbin/ip addr del dev
tun0 local 10.8.20.25 peer 10.8.20.5
May 28 10:17:08 perfection ovpn-synology[29139]:
SIGUSR1[soft,ping-restart] received, process restarting
May 28 10:17:10 perfection ovpn-synology[29139]: UDPv4 link local
(bound): [undef]
May 28 10:17:10 perfection ovpn-synology[29139]: UDPv4 link remote:
[AF_INET]92.109.167.182:1194
May 28 10:17:29 perfection ovpn-synology[29139]: [Diskstation] Peer
Connection Initiated with [AF_INET]92.109.167.182:1194
May 28 10:17:31 perfection ovpn-synology[29139]: AUTH: Received control
message: AUTH_FAILED
May 28 10:17:31 perfection ovpn-synology[29139]:
SIGTERM[soft,auth-failure] received, process exiting
At that point the link had been up for 2 days straight.
After restart it again establishes an UDP connection.
So my link is apparently down for a few minutes, it tries one
ping-restart, fails to auth, and then stops trying.
Does connect-retry-max also apply to these things?
But it does not apply to UDP? So I think it should not have any bearing
on reconnects?
I can find no setting detailing any restart number or options.
Actually there does seem to be a problem on the server...
Sun May 28 10:18:25 2017 RADIUS-PLUGIN: FOREGROUND THREAD:
isAuthenticated()1Sun May 28 10:18:25 2017 RADIUS-PLUGIN: FOREGROUND
THREAD: isAcct()1Sun May 28 10:18:26 2017 RADIUS-PLUGIN: Got no response
from radius server.
Sun May 28 10:18:26 2017 RADIUS-PLUGIN: FOREGROUND THREAD: Error ar
rekeying!
Sun May 28 10:18:26 2017 RADIUS-PLUGIN: BACKGROUND-ACCT: Statusfile
could not opened.
Sun May 28 10:18:26 2017 Error: RADIUS-PLUGIN: BACKGROUND AUTH: Auth
failed!.
But I don't know, it was just a temporary glitch.
But the temporary glitch caused the connection to be dropped...
------------------------------------------------------------------------------
Check out the vibrant tech community on one of the world's most
engaging tech sites, Slashdot.org! http://sdm.link/slashdot
_______________________________________________
Openvpn-users mailing list
Openvpn-users@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/openvpn-users