Yes, one of our colleagues is in China and he must use our vpn to continue his 
work and he is strongly complaining regarding the slow download speed, and we 
cannot understand the reason. He is the only one who has this problem, others 
do not have slow download speed problem.

I would like to share one more problem here with you and I hope someone can 
help me. The other problem is that some of our colleagues complain that they 
cannot authenticate, and they receive a message that authentication failed and 
then after a while then they try, and they can authenticate. It is annoying, 
and it seems something is wrong, and it is regarding the Active Directory, but 
I am not sure.  IN that case I can see the following error in the log file.

openvpn.auth-user.php: ERROR! Could not bind to LDAP server ActiveDirectory 
ourCompany.local. Please check the bind credentials.
openvpn.auth-user.php: ERROR! Could not bind to LDAP server ActiveDirectory 
ourCompany.local. Please check the bind credentials.
openvpn.auth-user.php: ERROR! Could not bind to LDAP server ActiveDirectory 
ourCompany.local. Please check the bind credentials.


 I would be very happy if you could give me your suggestions. Thanks in advance.

Many regards,
Huma

-----Original Message-----
From: Ralf Hildebrandt via Openvpn-users <openvpn-users@lists.sourceforge.net> 
Sent: Friday, February 10, 2023 2:15 PM
To: openvpn-users@lists.sourceforge.net
Subject: Re: [Openvpn-users] [ext] Does anyone suggestion regarding this error?

* Huma Yari <huma.y...@kingart-games.com>:

> We are having openvpn and it is a few days that I can see the following error 
> in our server log file:

So, just a few guidelines how to approach this:

1) Find out something about that IP. Where's that located?
   Solution: Probably the city Sanya, province Hainan, China.
   The ISP is chinatelecom
   
2) Is at least one of my users there?
   
3) Does that particular user complain that he/she cannot use the VPN?

I would guess somebody is portscanning your VPN server and the you're just 
seeing the fallout from this!

> TLS Error: cannot locate HMAC in incoming packet from 
> [AF_INET]59.50.242.0:56359

I'm also seeing some entries:

2023-02-10 00:41:57 openvpn openvpn-udp TLS Error: cannot locate HMAC in 
incoming packet from [AF_INET6]::ffff:198.235.24.167:55046#
2023-02-10 00:43:06 openvpn openvpn-udp TLS Error: cannot locate HMAC in 
incoming packet from [AF_INET6]::ffff:167.248.133.143:3275
2023-02-10 01:11:37 openvpn openvpn-udp TLS Error: cannot locate HMAC in 
incoming packet from [AF_INET6]::ffff:198.235.24.14:52489
2023-02-10 02:31:01 openvpn openvpn-tcp 167.94.138.44:34694 TLS Error: cannot 
locate HMAC in incoming packet from [AF_INET6]::ffff:167.94.138.44:34694
2023-02-10 04:03:01 openvpn openvpn-tcp 178.79.139.171:32830 TLS Error: cannot 
locate HMAC in incoming packet from [AF_INET6]::ffff:178.79.139.171:32830
2023-02-10 04:24:20 openvpn openvpn-udp TLS Error: cannot locate HMAC in 
incoming packet from [AF_INET6]::ffff:80.82.77.33:26876
2023-02-10 04:35:02 openvpn openvpn-udp TLS Error: cannot locate HMAC in 
incoming packet from [AF_INET6]::ffff:146.88.240.4:60049
2023-02-10 04:38:01 openvpn openvpn-udp TLS Error: cannot locate HMAC in 
incoming packet from [AF_INET6]::ffff:146.88.240.4:51589
2023-02-10 04:39:26 openvpn openvpn-udp TLS Error: cannot locate HMAC in 
incoming packet from [AF_INET6]::ffff:146.88.240.4:44070
2023-02-10 04:41:17 openvpn openvpn-udp TLS Error: cannot locate HMAC in 
incoming packet from [AF_INET6]::ffff:146.88.240.4:59266
2023-02-10 04:43:27 openvpn openvpn-udp TLS Error: cannot locate HMAC in 
incoming packet from [AF_INET6]::ffff:146.88.240.4:49202
2023-02-10 04:50:16 openvpn openvpn-udp TLS Error: cannot locate HMAC in 
incoming packet from [AF_INET6]::ffff:205.210.31.54:53491
2023-02-10 09:42:58 openvpn openvpn-udp TLS Error: cannot locate HMAC in 
incoming packet from [AF_INET6]::ffff:185.200.118.72:56361
2023-02-10 09:58:38 openvpn openvpn-udp TLS Error: cannot locate HMAC in 
incoming packet from [AF_INET6]::ffff:185.200.118.72:33006
2023-02-10 10:19:15 openvpn openvpn-udp TLS Error: cannot locate HMAC in 
incoming packet from [AF_INET6]::ffff:185.200.118.72:51797
2023-02-10 10:21:44 openvpn openvpn-udp TLS Error: cannot locate HMAC in 
incoming packet from [AF_INET6]::ffff:185.200.118.72:36998
2023-02-10 10:51:30 openvpn openvpn-udp TLS Error: cannot locate HMAC in 
incoming packet from [AF_INET6]::ffff:185.200.118.72:59705
2023-02-10 12:23:29 openvpn openvpn-udp TLS Error: cannot locate HMAC in 
incoming packet from [AF_INET6]::ffff:205.210.31.44:55498
2023-02-10 14:05:31 openvpn openvpn-udp TLS Error: cannot locate HMAC in 
incoming packet from [AF_INET6]::ffff:198.235.24.167:56351

some of those are scans (censys-scanner.com, shodan.io, arbor-observatory.com)

--
Ralf Hildebrandt
Charité - Universitätsmedizin Berlin
Geschäftsbereich IT | Abteilung Netzwerk

Campus Benjamin Franklin (CBF)
Haus I | 1. OG | Raum 105
Hindenburgdamm 30 | D-12203 Berlin

Tel. +49 30 450 570 155
ralf.hildebra...@charite.de
https://www.charite.de


_______________________________________________
Openvpn-users mailing list
Openvpn-users@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/openvpn-users

_______________________________________________
Openvpn-users mailing list
Openvpn-users@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/openvpn-users

Reply via email to