Re: [Astlinux-users] OpenVPN on Yealink phones not very reliable

2017-09-10 Thread Michael Knill
Thanks Lonnie. I suspect that this is not the problem but I cant understand why I need to restart the server before it works. Regards Michael Knill -Original Message- From: Lonnie Abelbeck Reply-To: AstLinux List Date: Monday, 11 September 2017 at 1:24 pm To: AstLinux List Subject: Re

Re: [Astlinux-users] OpenVPN on Yealink phones not very reliable

2017-09-10 Thread Lonnie Abelbeck
Michael, You could try -- OpenVPN Server -- Raw Commands: duplicate-cn -- and see if that helps. But you need to understand if you really need "multiple clients using the same certificate or username to concurrently connect". Is there a OpenVPN client you forgot about ? Are any sharing a usern

Re: [Astlinux-users] OpenVPN on Yealink phones not very reliable

2017-09-10 Thread Michael Knill
Ah I did remember seeing something in the logs about this: Mon Sep 11 11:26:06 2017 us=913475 MULTI: new connection by client '001565F4634C' will cause previous active sessions by this client to be dropped. Remember to use the --duplicate-cn option if you want multiple clients using the same ce

Re: [Astlinux-users] OpenVPN on Yealink phones not very reliable

2017-09-10 Thread Lonnie Abelbeck
Michael, Judging from your error log the Yealink's client CN (Common Name) did not match any of the allowed (non-checked) Clients in the server. As long as you are certain the Yealink client cert is good. You are not "sharing" a client certificate are you ? If you are do you have the "duplic

Re: [Astlinux-users] OpenVPN on Yealink phones not very reliable

2017-09-10 Thread Michael Knill
Hi Lonnie Do you mean Client Name? Yes I do have one disabled if so but it is not the one I was having problems with. After testing I can now confirm that this issue occurs when I configure up a new phone and it goes away (and VPN establishes) when I restart the OpenVPN server. Can you think w

Re: [Astlinux-users] Firewall configuration

2017-09-10 Thread Paul Wills
Lonnie, Thanks!  That's what I was looking for; a bare-bones "firewalls for dummies" type approach. Actually, I have to admit that I did turn the firewall on without any rules set.  Thank goodness for the local console!  ;-) PDW Original Message Hi Paul, Actually, I

Re: [Astlinux-users] OpenVPN on Yealink phones not very reliable

2017-09-10 Thread Lonnie Abelbeck
Michael, On your OpenVPN Server configuration (at the bottom), you must have at least one CommonName disabled. Client Certificates and Keys: -> Disabled checked(correct ?) This will define the variable OVPN_VALIDCLIENTS and is checked with the /usr/sbin/openvpn-tls-verify script Is your

[Astlinux-users] OpenVPN on Yealink phones not very reliable

2017-09-10 Thread Michael Knill
I am having some issues with setting up OpenVPN on my Yealink phones. It used to be easy to set up but now it's a bit flakey. Once its up it seems to be fine but getting it to that stage is an issue. I noticed that I am getting these in the logs: Mon Sep 11 08:05:39 2017 us=888912 115.187.181.61:

[Astlinux-users] Firewall configuration

2017-09-10 Thread Paul Wills
Greetings, I am trying to get the Adaptive Ban plugin to work but know nothing about firewall configuration.  Is there a guide to using the AstLinux GUI firewall settings or, short of that, a suggested minimal configuration for SSH, IAX2, and SIP?  Actually, I never opened a port to the "outs