Re: [Openvpn-users] Problems setting up dual-stack OpenVPN server on a Windows 10 host

2016-11-17 Thread Gert Doering
erally not done for v6. gert -- USENET is *not* the non-clickable part of WWW! //www.muc.de/~gert/ Gert Doering - Munich, Germany g...@greenie.muc.de fax: +49-89-35655025g...

Re: [Openvpn-users] openvpn udp server and vrrp

2016-11-15 Thread Gert Doering
t* the non-clickable part of WWW! //www.muc.de/~gert/ Gert Doering - Munich, Germany g...@greenie.muc.de fax: +49-89-35655025g...@net.informatik.tu-muenchen.de signature.asc D

Re: [Openvpn-users] Recently started IP/DNS leak?

2016-10-31 Thread Gert Doering
s totally impossible to give a meaningful reply to this. gert -- USENET is *not* the non-clickable part of WWW! //www.muc.de/~gert/ Gert Doering - Munich, Germany g...@greenie.muc.de fax: +49-89-35655

Re: [Openvpn-users] Recently started IP/DNS leak?

2016-10-31 Thread Gert Doering
WWW! //www.muc.de/~gert/ Gert Doering - Munich, Germany g...@greenie.muc.de fax: +49-89-35655025g...@net.informatik.tu-muenchen.de signature.asc Description: PGP signat

Re: [Openvpn-users] Recently started IP/DNS leak?

2016-10-31 Thread Gert Doering
is *not* the non-clickable part of WWW! //www.muc.de/~gert/ Gert Doering - Munich, Germany g...@greenie.muc.de fax: +49-89-35655025g...@net.informatik.tu-muenchen.de si

Re: [Openvpn-users] question about "WARNING: this cipher's block size is less than 128 bit"

2016-11-04 Thread Gert Doering
hed), or have to move to a new server with a different "--cipher" in the config. Apologies for the inconvenience... this is why we have cipher negotiation and AEAD in 2.4... gert -- USENET is *not* the non-clickable part of WWW!

Re: [Openvpn-users] Can I preserve the tun device from being deleted on the client side after the connection was closed or the server side is unavailable?

2016-10-16 Thread Gert Doering
everything on linux... gert -- USENET is *not* the non-clickable part of WWW! //www.muc.de/~gert/ Gert Doering - Munich, Germany g...@greenie.muc.de fax: +49-89-35655025g...@net.informatik.tu-muenchen.de signature.asc Description: PGP signature

Re: [Openvpn-users] Can I preserve the tun device from being deleted on the client side after the connection was closed or the server side is unavailable?

2016-10-15 Thread Gert Doering
(on BSDs, one would do "ifconfig tun4 create", but Linux' ifconfig cannot do that) gert -- USENET is *not* the non-clickable part of WWW! //www.muc.de/~gert/ Gert Doering - Munich, Germany g...@green

Re: [Openvpn-users] Problem with CPU usage when running with systemd on 2.4-rc1

2016-12-08 Thread Gert Doering
Hi, please do not send HTML mails... On Thu, Dec 08, 2016 at 07:07:50PM +1100, Chris Anderson wrote: > Hi I have a problem with openvpn running from > systemd (not using the suplied systemd unit files) consuming 100% cpu on > single thread when running from systemd. When I run this from a root

Re: [Openvpn-users] Can openvpn use compressed config file directly, say ``--config file.tar.gz''?

2016-12-14 Thread Gert Doering
part of WWW! //www.muc.de/~gert/ Gert Doering - Munich, Germany g...@greenie.muc.de fax: +49-89-35655025g...@net.informatik.tu-muenchen.de signature.asc Description: P

Re: [Openvpn-users] Can openvpn use compressed config file directly, say ``--config file.tar.gz''?

2016-12-15 Thread Gert Doering
nt that can do this sort of redirect. But as said earlier, the benefits of using gzip'ed config files is minimal, given that the files are so small anyway. gert -- USENET is *not* the non-clickable part of WWW! //www.muc.de/~gert/ Ge

Re: [Openvpn-users] Can openvpn use compressed config file directly, say ``--config file.tar.gz''?

2016-12-14 Thread Gert Doering
around a container format like .tar or .zip either. gert -- USENET is *not* the non-clickable part of WWW! //www.muc.de/~gert/ Gert Doering - Munich, Germany g...@greenie.muc.de fax: +49-89-35

Re: [Openvpn-users] question about "WARNING: this cipher's block size is less than 128 bit"

2016-12-17 Thread Gert Doering
Hi, On Sat, Dec 17, 2016 at 01:23:53PM +0100, David Sommerseth wrote: > On 17/12/16 11:13, Gert Doering wrote: > > (Main reason we can't stick to BF-CBC is that we use OTP passwords and > > with "reneg-bytes 64M" it's asking way too often for user+password...) > >

Re: [Openvpn-users] question about "WARNING: this cipher's block size is less than 128 bit"

2016-12-17 Thread Gert Doering
Not saying that this is the way it has to be done, but it's a nice way to transact a large user base without a flag day. (Main reason we can't stick to BF-CBC is that we use OTP passwords and with "reneg-bytes 64M" it's asking way too often for user+password...) gert -- USENET is *n

Re: [Openvpn-users] Does windows (10) client need admin rights?

2016-12-17 Thread Gert Doering
of WWW! //www.muc.de/~gert/ Gert Doering - Munich, Germany g...@greenie.muc.de fax: +49-89-35655025g...@net.informatik.tu-muenchen.de signature.asc Description: PGP sig

Re: [Openvpn-users] Experts' opinions needed: Lack of AES-256-CBC support

2016-12-01 Thread Gert Doering
rver side does this, and you'll see renegotiations in the log file. Of course, upgrading to 2.4 and using AES would be much nicer :-) gert -- USENET is *not* the non-clickable part of WWW! //www.muc.de/~gert/ Gert Doering - Munich

Re: [Openvpn-users] Launching OpenVPN-GUI automatically on user login?

2016-11-29 Thread Gert Doering
ot* the non-clickable part of WWW! //www.muc.de/~gert/ Gert Doering - Munich, Germany g...@greenie.muc.de fax: +49-89-35655025g...@net.informatik.tu-muenchen.de signature.asc

Re: [Openvpn-users] Question about tls-crypt and port 443 firewall ducking

2017-01-03 Thread Gert Doering
-choice? :-)) gert -- USENET is *not* the non-clickable part of WWW! //www.muc.de/~gert/ Gert Doering - Munich, Germany g...@greenie.muc.de fax: +49-89-35655025g...@net

Re: [Openvpn-users] OpenVPN over ssh tunnel

2017-01-02 Thread Gert Doering
in your openvpn config) gert -- USENET is *not* the non-clickable part of WWW! //www.muc.de/~gert/ Gert Doering - Munich, Germany g...@greenie.muc.de fax: +49-89-35655025g...@net

Re: [Openvpn-users] 2.4, windows tap driver problem

2016-12-29 Thread Gert Doering
rt of WWW! //www.muc.de/~gert/ Gert Doering - Munich, Germany g...@greenie.muc.de fax: +49-89-35655025g...@net.informatik.tu-muenchen.de signature.asc Description: PGP

Re: [Openvpn-users] 2.4, windows tap driver problem

2016-12-29 Thread Gert Doering
tive service, and running OpenVPN from the GUI? If not, you should :-) gert -- USENET is *not* the non-clickable part of WWW! //www.muc.de/~gert/ Gert Doering - Munich, Germany g...@greenie.muc.de

Re: [Openvpn-users] TLS Key negotiation failed

2016-12-21 Thread Gert Doering
of WWW! //www.muc.de/~gert/ Gert Doering - Munich, Germany g...@greenie.muc.de fax: +49-89-35655025g...@net.informatik.tu-muenchen.de signature.asc Description: PGP sig

Re: [Openvpn-users] 2.4, windows tap driver problem

2016-12-28 Thread Gert Doering
erver, > tun address should be 192.168.31.6, gui says so, > > but real address on tun is 10.1.10.6. Log file? gert -- USENET is *not* the non-clickable part of WWW! //www.muc.de/~gert/ Gert Doering - Munich, Germany

Re: [Openvpn-users] Experts' opinions needed: Is my VPN provider using weak or strong encryption algorithms?

2016-12-25 Thread Gert Doering
n-clickable part of WWW! //www.muc.de/~gert/ Gert Doering - Munich, Germany g...@greenie.muc.de fax: +49-89-35655025g...@net.informatik.tu-muenchen.de signature.asc Descriptio

Re: [Openvpn-users] question about "WARNING: this cipher's block size is less than 128 bit"

2016-12-22 Thread Gert Doering
Hi, On Thu, Dec 22, 2016 at 11:26:14AM -0500, Selva Nair wrote: > On Sat, Dec 17, 2016 at 5:13 AM, Gert Doering <g...@greenie.muc.de> wrote: > > > (Main reason we can't stick to BF-CBC is that we use OTP passwords and > > with "reneg-bytes 64M" it's aski

Re: [Openvpn-users] How to verify a working tunnel on the client side

2017-03-30 Thread Gert Doering
he data channel and see if something useful comes back. gert -- USENET is *not* the non-clickable part of WWW! //www.muc.de/~gert/ Gert Doering - Munich, Germany g...@greenie.muc.de fax: +49-89-35655025

[Openvpn-users] [PATCH] Make ENABLE_OCC no longer depend on !ENABLE_SMALL

2017-03-19 Thread Gert Doering
-off-by: Gert Doering <g...@greenie.muc.de> --- src/openvpn/syshead.h | 2 -- 1 file changed, 2 deletions(-) diff --git a/src/openvpn/syshead.h b/src/openvpn/syshead.h index a1b6047..f445864 100644 --- a/src/openvpn/syshead.h +++ b/src/openvpn/syshead.h @@ -589,9 +589,7 @@ socket_defined

Re: [Openvpn-users] win10, openvpn gui latest, and openvpn 2.4 server tls negotiation configuration error

2017-04-20 Thread Gert Doering
not need TCP *and* UDP, unless you run two server processes, one for TCP and one for UDP. gert -- USENET is *not* the non-clickable part of WWW! //www.muc.de/~gert/ Gert Doering - Munich, Germany g...@gree

Re: [Openvpn-users] Fully automate openvpn setup and key generation on linux

2017-03-13 Thread Gert Doering
*not* the non-clickable part of WWW! //www.muc.de/~gert/ Gert Doering - Munich, Germany g...@greenie.muc.de fax: +49-89-35655025g...@net.informatik.tu-muenchen.de sign

Re: [Openvpn-users] NCP ciphers negotiation question

2017-04-14 Thread Gert Doering
o far" out, so 2.3 users can slowly migrate to AEAD. gert -- USENET is *not* the non-clickable part of WWW! //www.muc.de/~gert/ Gert Doering - Munich, Germany g...@greenie.muc.de fax: +49-89-35655025

Re: [Openvpn-users] win10, openvpn gui latest, and openvpn 2.4 server tls negotiation configuration error

2017-04-17 Thread Gert Doering
ickable part of WWW! //www.muc.de/~gert/ Gert Doering - Munich, Germany g...@greenie.muc.de fax: +49-89-35655025g...@net.informatik.tu-muenchen.de signature.asc Descrip

Re: [Openvpn-users] Win10 default gateway not being redirected

2017-04-24 Thread Gert Doering
s what happened here. gert -- USENET is *not* the non-clickable part of WWW! //www.muc.de/~gert/ Gert Doering - Munich, Germany g...@greenie.muc.de fax: +49-89-35655025g...@net.informatik.tu

Re: [Openvpn-users] Win10 default gateway not being redirected

2017-04-24 Thread Gert Doering
Hi, On Mon, Apr 24, 2017 at 01:36:02PM -0400, Selva Nair wrote: > On Mon, Apr 24, 2017 at 1:12 PM, Gert Doering <g...@greenie.muc.de> wrote: > > > ... except that it really shouldn't do this, if you running the GUI without > > Admin privileges... which you *are* doin

Re: [Openvpn-users] Win10 default gateway not being redirected

2017-04-24 Thread Gert Doering
t you? gert -- USENET is *not* the non-clickable part of WWW! //www.muc.de/~gert/ Gert Doering - Munich, Germany g...@greenie.muc.de fax: +49-89-35655025g...@net.inform

Re: [Openvpn-users] --no-iv option deprecation

2017-07-31 Thread Gert Doering
"do not just hijack existing threats" first. gert PS: yeah, someone will come and yell at me that I'm so mean. Go for it. -- USENET is *not* the non-clickable part of WWW! //www.muc.de/~gert/ Gert Doering - Munich, Germany

Re: [Openvpn-users] Fwd: --no-iv option deprecation

2017-07-31 Thread Gert Doering
is *not* the non-clickable part of WWW! //www.muc.de/~gert/ Gert Doering - Munich, Germany g...@greenie.muc.de fax: +49-89-35655025g...@net.informatik.tu-muenchen.de signature.asc Descriptio

Re: [Openvpn-users] VPN without encryption and auth

2017-08-02 Thread Gert Doering
x. gert -- USENET is *not* the non-clickable part of WWW! //www.muc.de/~gert/ Gert Doering - Munich, Germany g...@greenie.muc.de fax: +49-89-35655025g...@net.informatik.tu-muenchen.de signature.a

Re: [Openvpn-users] VPN clients disconnecting since 2.4

2017-07-18 Thread Gert Doering
gert -- USENET is *not* the non-clickable part of WWW! //www.muc.de/~gert/ Gert Doering - Munich, Germany g...@greenie.muc.de fax: +49-89-35655025g...@net.informatik.tu

Re: [Openvpn-users] Default behaviour of ncp-ciphers on the server

2017-06-29 Thread Gert Doering
(unless you put it there). (As a side note: please upgrade to 2.4.3) gert -- USENET is *not* the non-clickable part of WWW! //www.muc.de/~gert/ Gert Doering - Munich, Germany g...@greenie.muc.de fa

Re: [Openvpn-users] Issue with single user, implicit ncp-ciphers connections

2017-06-30 Thread Gert Doering
e - do not use --ncp-disable and varying --cipher settings unless there is a very specific situation that you need this for gert -- USENET is *not* the non-clickable part of WWW! //www.muc.de/~gert/ Gert Doering - Munich, Germany

Re: [Openvpn-users] Issue with single user, implicit ncp-ciphers connections

2017-07-03 Thread Gert Doering
t help (because that will ensure the server knows "client went away") - but otherwise, this is turning into a "if I do this, it hurts" - "then don't do this" thread. gert -- USENET is *not* the non-clickable part of WWW!

Re: [Openvpn-users] logrotate

2017-07-03 Thread Gert Doering
a copy and truncate trick. > > Is there a "proper" way now to use the Linux logrotate feature without the > copytruncate option? --syslog? gert -- USENET is *not* the non-clickable part of WWW! //www.muc.de

Re: [Openvpn-users] push vs. client file options

2017-04-27 Thread Gert Doering
ds to be correct before a connection can be established at all. So, not pushable. gert -- USENET is *not* the non-clickable part of WWW! //www.muc.de/~gert/ Gert Doering - Munich, Germany g...@green

Re: [Openvpn-users] Openvpn and samba

2017-04-27 Thread Gert Doering
You can make them listen to the tun IP on the server, and restrict client access to "openvpn client IPs" - that should work. gert -- USENET is *not* the non-clickable part of WWW! //www.muc.de/~gert/ Gert Doerin

Re: [Openvpn-users] Win10 default gateway not being redirected

2017-04-24 Thread Gert Doering
ted packets going to your VPN server (and traffic local to the LAN network). gert -- USENET is *not* the non-clickable part of WWW! //www.muc.de/~gert/ Gert Doering - Munich, Germany g...@greenie.muc.de fax: +49-89

Re: [Openvpn-users] --no-iv option deprecation

2017-07-31 Thread Gert Doering
the non-clickable part of WWW! //www.muc.de/~gert/ Gert Doering - Munich, Germany g...@greenie.muc.de fax: +49-89-35655025g...@net.informatik.tu-muenchen.de signature.a

Re: [Openvpn-users] Is it possible for a server to set up one tun interface for each of the client?

2017-08-23 Thread Gert Doering
- USENET is *not* the non-clickable part of WWW! //www.muc.de/~gert/ Gert Doering - Munich, Germany g...@greenie.muc.de fax: +49-89-35655025g...@net.informatik.tu-muench

Re: [Openvpn-users] standby tunnel

2017-06-08 Thread Gert Doering
//www.muc.de/~gert/ Gert Doering - Munich, Germany g...@greenie.muc.de fax: +49-89-35655025g...@net.informatik.tu-muenchen.de signature.asc Description: PGP signature

Re: [Openvpn-users] standby tunnel

2017-06-08 Thread Gert Doering
* the non-clickable part of WWW! //www.muc.de/~gert/ Gert Doering - Munich, Germany g...@greenie.muc.de fax: +49-89-35655025g...@net.informatik.tu-muenchen.de signature

Re: [Openvpn-users] standby tunnel

2017-06-12 Thread Gert Doering
on-clickable part of WWW! //www.muc.de/~gert/ Gert Doering - Munich, Germany g...@greenie.muc.de fax: +49-89-35655025g...@net.informatik.tu-muenchen.de signature.asc Description: PGP signature

Re: [Openvpn-users] standby tunnel

2017-06-09 Thread Gert Doering
not answer *why* it thinks it wants to send a packet. gert -- USENET is *not* the non-clickable part of WWW! //www.muc.de/~gert/ Gert Doering - Munich, Germany g...@greenie.muc.de fax: +49-89-356550

Re: [Openvpn-users] standby tunnel

2017-06-09 Thread Gert Doering
l packet (maybe it *is* a --ping packet after all). gert -- USENET is *not* the non-clickable part of WWW! //www.muc.de/~gert/ Gert Doering - Munich, Germany g...@greenie.muc.de fax: +49-89-35655025

Re: [Openvpn-users] Request 2.4.2-openvpn .deb package that is compatible with Debian Stretch

2017-06-19 Thread Gert Doering
ess to the internal of X509_OBJECT OpenSSL: don't use direct access to the internal of RSA_METHOD OpenSSL: SSLeay symbols are no longer available in OpenSSL 1.1 OpenSSL: use EVP_CipherInit_ex() instead of EVP_CipherInit() Eric Thorpe (1): Fix Building Using MSVC Gert Doe

Re: [Openvpn-users] Remove me, please

2017-06-20 Thread Gert Doering
/lists/listinfo/openvpn-users ... this is what is appended to every single mail, so you can click on it and remove yourself. gert -- USENET is *not* the non-clickable part of WWW! //www.muc.de/~gert/ Gert Doering -

Re: [Openvpn-users] * UPDATE * OpenVPN v2.4.3 and v2.3.17 releases

2017-06-23 Thread Gert Doering
your VPN, and bored kids can find out which networks you use internally in the VPN and can send packets there, upgrade. gert -- USENET is *not* the non-clickable part of WWW! //www.muc.de/~gert/ Gert Doering - Munich, Germany

Re: [Openvpn-users] learn address script

2017-05-22 Thread Gert Doering
rather hard to use openvpn. It's always nice to hear kind words from users :-) gert -- USENET is *not* the non-clickable part of WWW! //www.muc.de/~gert/ Gert Doering - Munich, Germany g...@greenie.muc.de f

Re: [Openvpn-users] learn address script

2017-05-28 Thread Gert Doering
g "auth-retry nointeract" might be what you need on the client side to work karound this. gert -- USENET is *not* the non-clickable part of WWW! //www.muc.de/~gert/ Gert Doering - Munich, Germany

Re: [Openvpn-users] openvpn server / Windows Server 2016 Standard / assign server IP problem

2017-05-16 Thread Gert Doering
d --topology subnet > nowadays. net30 exists because ptp didn't work on windows and nobody had one subnet yet :-) gert -- USENET is *not* the non-clickable part of WWW! //www.muc.de/~gert/ Gert Doering - Munich, Germany

Re: [Openvpn-users] standby tunnel

2017-06-08 Thread Gert Doering
the non-clickable part of WWW! //www.muc.de/~gert/ Gert Doering - Munich, Germany g...@greenie.muc.de fax: +49-89-35655025g...@net.informatik.tu-muenchen.de signature.

Re: [Openvpn-users] standby tunnel

2017-06-08 Thread Gert Doering
gert -- USENET is *not* the non-clickable part of WWW! //www.muc.de/~gert/ Gert Doering - Munich, Germany g...@greenie.muc.de fax: +49-89-35655025g...@net.informatik.tu-muenchen.de signatu

Re: [Openvpn-users] standby tunnel

2017-06-08 Thread Gert Doering
tion" to be "initiated", as everything is static anyway. So it's not fully clear to me what it is doing there. (But I've never used static key mode in earnest, so I'll learn something new here :) ) gert -- USENET is *not* the non-clickable part of WWW!

Re: [Openvpn-users] Packet flow and ICMP/MTU question

2017-06-15 Thread Gert Doering
rt -- USENET is *not* the non-clickable part of WWW! //www.muc.de/~gert/ Gert Doering - Munich, Germany g...@greenie.muc.de fax: +49-89-35655025g...@net.informatik.tu-mu

Re: [Openvpn-users] Packet flow and ICMP/MTU question

2017-06-15 Thread Gert Doering
ween openvpn and the "tun0 thing" in the kernel, and iptables/routing are really on the "app side" of the tun0). Language can be confusing. gert -- USENET is *not* the non-clickable part of WWW! //www.muc.de/~ger

Re: [Openvpn-users] standby tunnel

2017-06-10 Thread Gert Doering
Worth a test. gert -- USENET is *not* the non-clickable part of WWW! //www.muc.de/~gert/ Gert Doering - Munich, Germany g...@greenie.muc.de fax: +49-89-35655025g...@net.info

Re: [Openvpn-users] standby tunnel

2017-06-11 Thread Gert Doering
on program end" :-) gert -- USENET is *not* the non-clickable part of WWW! //www.muc.de/~gert/ Gert Doering - Munich, Germany g...@greenie.muc.de fax: +49-89-35655025g...@n

Re: [Openvpn-users] Need help with Ubuntu 16.04 LTS OpenVPN 2.4 Dual-Stack Server Firewall Configuration

2017-06-10 Thread Gert Doering
t router's LAN and WAN interface) when you do the traceroutes, and see where the packets show up gert -- USENET is *not* the non-clickable part of WWW! //www.muc.de/~gert/ Gert Doering - Munich, Germany g...@gre

Re: [Openvpn-users] Need help with Ubuntu 16.04 LTS OpenVPN 2.4 Dual-Stack Server Firewall Configuration

2017-06-10 Thread Gert Doering
like "firewall" to me. gert -- USENET is *not* the non-clickable part of WWW! //www.muc.de/~gert/ Gert Doering - Munich, Germany g...@greenie.muc.de fax: +49-89-35655025

Re: [Openvpn-users] Need help with Ubuntu 16.04 LTS OpenVPN 2.4 Dual-Stack Server Firewall Configuration

2017-06-12 Thread Gert Doering
n. Have you been following the check list in my "it's always routing" mail? If yes, what's the outcome? gert -- USENET is *not* the non-clickable part of WWW! //www.muc.de/~gert/ Gert Doering - Munich, Germany

Re: [Openvpn-users] Packet flow and ICMP/MTU question

2017-06-14 Thread Gert Doering
cond set of firewall rules, but those are "OpenVPN pf rules", not related (and not visible to) host side iptables. gert -- USENET is *not* the non-clickable part of WWW! //www.muc.de/~gert/ Gert Doering - Munich, Germany

Re: [Openvpn-users] Packet flow and ICMP/MTU question

2017-06-14 Thread Gert Doering
gert -- USENET is *not* the non-clickable part of WWW! //www.muc.de/~gert/ Gert Doering - Munich, Germany g...@greenie.muc.de fax: +49-89-35655025g...@net.informatik.tu-muenchen.de signature.asc Description: PGP signature -

Re: [Openvpn-users] Packet flow and ICMP/MTU question

2017-06-14 Thread Gert Doering
it back *after firewall inspection*. gert -- USENET is *not* the non-clickable part of WWW! //www.muc.de/~gert/ Gert Doering - Munich, Germany g...@greenie.muc.de fax: +49-89-35655025

Re: [Openvpn-users] Request 2.4.2-openvpn .deb package that is compatible with Debian Stretch

2017-06-18 Thread Gert Doering
o have Strech-compatible .deb for future relases which are not going to be available out of the box right away) gert -- USENET is *not* the non-clickable part of WWW! //www.muc.de/~gert/ Gert Doering - Munich, G

Re: [Openvpn-users] Need help with Ubuntu 16.04 LTS OpenVPN 2.4 Dual-Stack Server Firewall Configuration

2017-06-11 Thread Gert Doering
le forwarding (because "traditionally", routers do not listen to router advertisements) /proc/sys/net/ipv6/conf/default/accept_ra /proc/sys/net/ipv6/conf/enp0s25/accept_ra gert -- USENET is *not* the non-clickable part of WWW!

Re: [Openvpn-users] standby tunnel

2017-06-09 Thread Gert Doering
Hi, On Fri, Jun 09, 2017 at 08:09:13PM +0200, richard lucassen wrote: > On Fri, 9 Jun 2017 08:22:11 +0200 > Gert Doering <g...@greenie.muc.de> wrote: > > > > Setting verb to 8 makes a lot of noise :) That's why I just looked > > > with tcpdump. > > >

Re: [Openvpn-users] dual-stack setup on OpenBSD?

2017-06-18 Thread Gert Doering
One possible workaround might be to use pf(4) on the server to setup a v6/v4 rdr NAT rule and have the firewall provide the "dual-stacking", but I'm not sure it actually works - never tried. But let's see the server logs first. gert -- USENET is *not* the non-clickable part of WWW!

Re: [Openvpn-users] OpenVPN per client cipher

2017-09-15 Thread Gert Doering
pher patch - this is definitely useful. Interaction with NCP needs a bit more thought, it seems. gert -- USENET is *not* the non-clickable part of WWW! //www.muc.de/~gert/ Gert Doering - Munich, Germany g...

Re: [Openvpn-users] Donation

2017-09-30 Thread Gert Doering
gert -- USENET is *not* the non-clickable part of WWW! //www.muc.de/~gert/ Gert Doering - Munich, Germany g...@greenie.muc.de fax: +49-89-35655025g...@net.informatik.tu-muenchen.de

Re: [Openvpn-users] Why the tun device hasn't mac address?

2017-08-24 Thread Gert Doering
WWW! //www.muc.de/~gert/ Gert Doering - Munich, Germany g...@greenie.muc.de fax: +49-89-35655025g...@net.informatik.tu-muenchen.de signature.asc Description: PGP signat

Re: [Openvpn-users] Why the tun device hasn't mac address?

2017-08-24 Thread Gert Doering
rt of WWW! //www.muc.de/~gert/ Gert Doering - Munich, Germany g...@greenie.muc.de fax: +49-89-35655025g...@net.informatik.tu-muenchen.de signature.asc Description: PGP

Re: [Openvpn-users] OpenVPN with LZ4

2017-08-24 Thread Gert Doering
ut running "ldd openvpn" on your openvpn binary - if liblz4. shows up, it needs the dynamic library. Everything that does *not* show up is built-in (or not a direct dependency). gert -- USENET is *not* the non-clickable part of WWW!

Re: [Openvpn-users] explicit-exit-notify is ignored by previous blocks.

2017-08-28 Thread Gert Doering
-- USENET is *not* the non-clickable part of WWW! //www.muc.de/~gert/ Gert Doering - Munich, Germany g...@greenie.muc.de fax: +49-89-35655025g...@net.informatik.tu-muenchen.de signature.asc Description: PGP signature

Re: [Openvpn-users] tcp-client: large ping during transfers (fwd)

2017-11-10 Thread Gert Doering
stop the kernel from doing its own stuff, which it mostly "buffering" for "packets inside a TCP stream"). gert -- USENET is *not* the non-clickable part of WWW! //www.muc.de/~gert/ Gert Doering - Munich, German

Re: [Openvpn-users] Client mobility in bridged mode

2017-11-28 Thread Gert Doering
@ mailing lists, as not all OpenVPN developers interested in "network" are subscribed to -users gert -- now what should I write here... Gert Doering - Munich, Germany g...@greenie.muc.de signature.asc Description: PGP signature

Re: [Openvpn-users] Management interface "echo" command standardization

2017-11-25 Thread Gert Doering
eave the specifics of that to you :-) (I'm sure Arne will have some ideas as well) gert -- now what should I write here... Gert Doering - Munich, Germany g...@greenie.muc.de signature.asc Description: PGP signature ---

Re: [Openvpn-users] keepalive/connect-retry interaction

2017-12-03 Thread Gert Doering
e in your logs that the remote "went away", but protocol-wise, it does not go away either - there is no connection setup / teardown in p2p-static-key mode. Just "packets that can be decrypted" and "remote IP address to send to-be-encrypted packets to&qu

Re: [Openvpn-users] Force connections/DNS lookup only over IPv4?

2017-12-13 Thread Gert Doering
.x.y 1194 > > that is the IPv4 address. Was wondering if there is an option (like that > in SSH) to explicitly provide for an address family: Just use "protocol udp4" to force IPv4-only (or "tcp4"). gert -- now what should I write here... Gert Doering - Munich, Ger

Re: [Openvpn-users] Force connections/DNS lookup only over IPv4?

2017-12-13 Thread Gert Doering
s hard, sorry. gert -- now what should I write here... Gert Doering - Munich, Germany g...@greenie.muc.de signature.asc Description: PGP signature -- Check out the vibrant tech community on o

Re: [Openvpn-users] Displaying messages to users by means of the GUI?

2017-11-21 Thread Gert Doering
lude the --pull-filter. > > Would running openvpn-GUI on the modified config negate the pushed echo? Of course it would. If you filter push messages, they do not arrive. As for any other pushed option. gert -- now what should I write here... Gert Doering - Munich, Germany

Re: [Openvpn-users] Displaying messages to users by means of the GUI?

2017-11-21 Thread Gert Doering
ary which does whatever he wants) gert -- now what should I write here... Gert Doering - Munich, Germany g...@greenie.muc.de signature.asc Description: PGP signature -- Check out the vibrant te

Re: [Openvpn-users] migrating from lzo to lz4

2017-11-17 Thread Gert Doering
t;); push @outline, 'push "compress lz4"', 'compress lz4'; (the server can speak different compression algorithms at a time, but for reasons lost in the mists of time it needs to be told what to expect - even though the compression byte is actually telling it) gert -- now what sh

Re: [Openvpn-users] tcp-client: large ping during transfers (fwd)

2017-11-09 Thread Gert Doering
routers / carrier-grade NAT boxes", etc. gert -- USENET is *not* the non-clickable part of WWW! //www.muc.de/~gert/ Gert Doering - Munich, Germany g...@greenie.muc.de fax: +49-89-35655025

Re: [Openvpn-users] tcp-client: large ping during transfers (fwd)

2017-11-09 Thread Gert Doering
m achievable limit will make sure the queues are never filling up. gert -- USENET is *not* the non-clickable part of WWW! //www.muc.de/~gert/ Gert Doering - Munich, Germany g...@greenie.muc.d

Re: [Openvpn-users] tcp-client: large ping during transfers (fwd)

2017-11-09 Thread Gert Doering
"large buffers with smart queueing" vs. "shallow buffers, drop early, leave this to the upper layer protocol to sort out") gert -- USENET is *not* the non-clickable part of WWW! //www.muc.de/~gert/ Gert Doering - Munich,

Re: [Openvpn-users] arp over routed VPN

2017-11-09 Thread Gert Doering
not* the non-clickable part of WWW! //www.muc.de/~gert/ Gert Doering - Munich, Germany g...@greenie.muc.de fax: +49-89-35655025g...@net.informatik.tu-muenchen.de signat

Re: [Openvpn-users] tcp-client: large ping during transfers (fwd)

2017-11-09 Thread Gert Doering
rch on over the last 20 years. But that's quite a bit of work... gert -- USENET is *not* the non-clickable part of WWW! //www.muc.de/~gert/ Gert Doering - Munich, Germany g...@greenie.muc.de fax: +49-89-3565

Re: [Openvpn-users] Push explicit-exit-notify ?

2018-05-04 Thread Gert Doering
gert -- "If was one thing all people took for granted, was conviction that if you feed honest figures into a computer, honest figures come out. Never doubted it myself till I met a computer with a sense of humor." Robert A. Heinlein, The Moon is a Harsh Mistress Gert

Re: [Openvpn-users] dd-wrt router openVPN server version and client version must be the same?

2018-05-14 Thread Gert Doering
eral, you should be fine. gert -- "If was one thing all people took for granted, was conviction that if you feed honest figures into a computer, honest figures come out. Never doubted it myself till I met a computer with a sense of humor." Robert A. Heinlein,

Re: [Openvpn-users] Push explicit-exit-notify ?

2018-05-04 Thread Gert Doering
myself till I met a computer with a sense of humor." Robert A. Heinlein, The Moon is a Harsh Mistress Gert Doering - Munich, Germany g...@greenie.muc.de signatu

Re: [Openvpn-users] Push explicit-exit-notify ?

2018-05-04 Thread Gert Doering
If was one thing all people took for granted, was conviction that if you feed honest figures into a computer, honest figures come out. Never doubted it myself till I met a computer with a sense of humor." Robert A. Heinlein, The Moon is a Harsh Mistress Gert

Re: [Openvpn-users] OpenVPN network throughput vs raw network throughput

2018-06-08 Thread Gert Doering
Hi, On Fri, Jun 08, 2018 at 11:27:42AM +0200, Gert Doering wrote: > So "TCP over naked IP" is exactly what you want to compare to "TCP over > OpenVPN over UDP/IP" - so "iperf3 tcp" is a valid test for "how does > the performance vary if OpenVPN/UDP i

<    1   2   3   4   5   6   7   8   9   >