Re: [Openvpn-users] howto defend repeated connection requests

2019-11-26 Thread Boris
Hej David, thakn you for your statement! Please excuse my delay Am 18.11.19 um 14:19 schrieb David Sommerseth: [snip] This just gave me a little itch. Such old routers can often have quite poor random entropy - which can result in more predictable keys. This is especially more importa

Re: [Openvpn-users] howto defend repeated connection requests

2019-11-18 Thread David Sommerseth
On 16/11/2019 21:29, Gert Doering wrote: > Hi, > > On Sat, Nov 16, 2019 at 09:07:43PM +0100, Boris wrote: >>> Generally speaking: use tls-auth. This will stop all packets from >>> unauthorized sources from generating state and eating memory in the >>> openvpn server process (it will still eat up

Re: [Openvpn-users] howto defend repeated connection requests

2019-11-16 Thread Boris
Am 16.11.19 um 21:29 schrieb Gert Doering: > Hi, > > On Sat, Nov 16, 2019 at 09:07:43PM +0100, Boris wrote: >>> Generally speaking: use tls-auth. This will stop all packets from >>> unauthorized sources from generating state and eating memory in the >>> openvpn server process (it will still eat u

Re: [Openvpn-users] howto defend repeated connection requests

2019-11-16 Thread Gert Doering
Hi, On Sat, Nov 16, 2019 at 09:07:43PM +0100, Boris wrote: > > Generally speaking: use tls-auth. This will stop all packets from > > unauthorized sources from generating state and eating memory in the > > openvpn server process (it will still eat up some CPU, but if that is > > enough to crash th

Re: [Openvpn-users] howto defend repeated connection requests

2019-11-16 Thread Boris
Am 16.11.19 um 11:57 schrieb Gert Doering: > Hi, > > On Sat, Nov 16, 2019 at 11:01:24AM +0100, Boris wrote: >> on a friends linux router I found a running openvpn 2.0. We are in >> trouble with this router because of repeatedly connection requests that >> are unsuccessful but kill the openvpn serv

Re: [Openvpn-users] howto defend repeated connection requests

2019-11-16 Thread Gert Doering
Hi, On Sat, Nov 16, 2019 at 11:01:24AM +0100, Boris wrote: > on a friends linux router I found a running openvpn 2.0. We are in > trouble with this router because of repeatedly connection requests that > are unsuccessful but kill the openvpn server after some time. So the "openvpn 2.0" on the rou

[Openvpn-users] howto defend repeated connection requests

2019-11-16 Thread Boris
Hej list, on a friends linux router I found a running openvpn 2.0. We are in trouble with this router because of repeatedly connection requests that are unsuccessful but kill the openvpn server after some time. The source of the requests (IPs) are changing from time to time (amazon clou, google