This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Public IP address needed in override hostname?

Hello Sophos community,

I bought a Sophos XG 106 for home use and to learn more about internet security. 

But now, I have a question about the VPN access from : https://community.sophos.com/kb/en-us/122769

I followed all steps but I was wondering what I have to type in the "override hostname" field?

Do i need to add here my public IP from my internet isp?

Cause when i try to connect with the vpn client I see this in the logs : 

Wed Dec 18 12:07:12 2019 Attempting to establish TCP connection with [AF_INET]84.197.138.2:8443 [nonblock]
Wed Dec 18 12:07:12 2019 MANAGEMENT: >STATE:1576667232,TCP_CONNECT,,,,,,
Wed Dec 18 12:07:22 2019 TCP: connect to [AF_INET]84.197.138.2:8443 failed, will try again in 5 seconds: The system tried to join a drive to a directory on a joined drive.
Wed Dec 18 12:07:27 2019 MANAGEMENT: >STATE:1576667247,TCP_CONNECT,,,,,,
Wed Dec 18 12:07:37 2019 TCP: connect to [AF_INET]84.197.138.2:8443 failed, will try again in 5 seconds: The system tried to join a drive to a directory on a joined drive.
Wed Dec 18 12:07:42 2019 MANAGEMENT: >STATE:1576667262,TCP_CONNECT,,,,,,
Wed Dec 18 12:07:52 2019 TCP: connect to [AF_INET]84.197.138.2:8443 failed, will try again in 5 seconds: The system tried to join a drive to a directory on a joined drive.
Wed Dec 18 12:07:57 2019 MANAGEMENT: >STATE:1576667277,TCP_CONNECT,,,,,,

So I can't seem to connect to my firewall through vpn, but i have no clue what's wrong with my current config.

Thanks a lot

regards

Frederiek



This thread was automatically locked due to age.
  • Frederiek Pascal said:
    2019-12-22 17:32:58.441161 MANAGEMENT: >STATE:1577032378,TCP_CONNECT,,,,,,

    After this, is it at least giving you: "failed, will try again in 5 seconds: Operation timed out" ?

  • If it is, can you SSH in to XG, go to advanced shell and give the output of "cat /log/sslvpn.log", if there's any errors in it then post it here, of course if there is it's better to wait for a sophos dev to answer, if there isn't It seems a problem when establishing the connection with XG.

    A good thing you can do, If your ISP router supports, and you don't have a special use for it, it's putting in bridge and authenticating with XG.

  • hello,

    here ya go :-)

     

     

    XG106_XN01_SFOS 17.5.9 MR-9# cat /log/sslvpn.log

    Wed Dec 18 11:32:55 2019 [5140] OpenVPN 2.3.6 i486-openwrt-linux-gnu [SSL (OpenSSL)] [LZO] [EPOLL] [MH] [IPv6] built on Nov  1 2019

    Wed Dec 18 11:32:55 2019 [5140] library versions: OpenSSL 1.0.2k-fips  26 Jan 2017, LZO 2.09

    Wed Dec 18 11:32:55 2019 [5140] MANAGEMENT: client_uid=0

    Wed Dec 18 11:32:55 2019 [5140] MANAGEMENT: unix domain socket listening on /tmp/openvpn_mgmt

    /scripts/vpn/sslvpn/user-cleanup.sh: line 4: DELETE: not found

    Wed Dec 18 11:32:55 2019 [5140] cleanup success

    Wed Dec 18 11:32:55 2019 [5140] WARNING: using --duplicate-cn and --client-config-dir together is probably not what you want

    Wed Dec 18 11:32:55 2019 [5140] WARNING: --ifconfig-pool-persist will not work with --duplicate-cn

    Wed Dec 18 11:32:55 2019 [5140] NOTE: the current --script-security setting may allow this configuration to call user-defined scripts

    grhandle=0x8322270

    Authentication server 127.0.0.1 gave login response code 2

    Wed Dec 18 11:32:55 2019 [5140] PLUGIN_INIT: POST /lib/openvpn-plugin-utm.so '[/lib/openvpn-plugin-utm.so]' intercepted=PLUGIN_AUTH_USER_PASS_VERIFY|PLUGIN_CLIENT_CONNECT|PLUGIN_CLIENT_DISCONNECT

    Wed Dec 18 11:32:55 2019 [5140] Diffie-Hellman initialized with 2048 bit key

    Wed Dec 18 11:32:55 2019 [5140] WARNING: file '/conf/certificate/private/ApplianceCertificate.key' is group or others accessible

    Wed Dec 18 11:32:55 2019 [5140] WARNING: experimental option --capath /conf/certificate/openvpn

    Wed Dec 18 11:32:55 2019 [5140] Socket Buffers: R=[87380->131072] S=[16384->131072]

    Wed Dec 18 11:32:55 2019 [5140] TUN/TAP device tun0 opened

    Wed Dec 18 11:32:55 2019 [5140] TUN/TAP TX queue length set to 100

    Wed Dec 18 11:32:55 2019 [5140] do_ifconfig, tt->ipv6=1, tt->did_ifconfig_ipv6_setup=1

    Wed Dec 18 11:32:55 2019 [5140] /bin/ip link set dev tun0 up mtu 1500

    Wed Dec 18 11:32:55 2019 [5140] /bin/ip addr add dev tun0 10.81.234.5/24 broadcast 10.81.234.255

    Wed Dec 18 11:32:55 2019 [5140] /bin/ip -6 addr add 2001:db8::1:0/64 dev tun0

    Wed Dec 18 11:32:55 2019 [5140] CSC service status updated to RUNNING

    Wed Dec 18 11:32:55 2019 [5140] Listening for incoming TCP connection on [undef]

    Wed Dec 18 11:32:55 2019 [5140] TCPv6_SERVER link local (bound): [undef]

    Wed Dec 18 11:32:55 2019 [5140] TCPv6_SERVER link remote: [undef]

    Wed Dec 18 11:32:55 2019 [5140] MULTI: multi_init called, r=256 v=256

    Wed Dec 18 11:32:55 2019 [5140] IFCONFIG POOL IPv6: (IPv4) size=50, size_ipv6=65536, netbits=64, base_ipv6=2001:db8::1:1

    Wed Dec 18 11:32:55 2019 [5140] IFCONFIG POOL: base=10.81.234.6 size=50, ipv6=1

    Wed Dec 18 11:32:55 2019 [5140] IFCONFIG POOL LIST

    Wed Dec 18 11:32:55 2019 [5140] MULTI: TCP INIT maxclients=5000 maxevents=5004

    Wed Dec 18 11:32:55 2019 [5140] Initialization Sequence Completed

    Wed Dec 18 11:36:28 2019 [5140] Closing TUN/TAP interface

    Wed Dec 18 11:36:28 2019 [5140] /bin/ip addr del dev tun0 10.81.234.5/24

    Wed Dec 18 11:36:28 2019 [5140] /bin/ip -6 addr del 2001:db8::1:0/64 dev tun0

    Wed Dec 18 11:36:28 2019 [5140] PLUGIN_CLOSE: /lib/openvpn-plugin-utm.so

    Wed Dec 18 11:36:28 2019 [5140] SIGTERM[hard,] received, process exiting

    Wed Dec 18 11:36:32 2019 [5708] OpenVPN 2.3.6 i486-openwrt-linux-gnu [SSL (OpenSSL)] [LZO] [EPOLL] [MH] [IPv6] built on Nov  1 2019

    Wed Dec 18 11:36:32 2019 [5708] library versions: OpenSSL 1.0.2k-fips  26 Jan 2017, LZO 2.09

    Wed Dec 18 11:36:32 2019 [5708] MANAGEMENT: client_uid=0

    Wed Dec 18 11:36:32 2019 [5708] MANAGEMENT: unix domain socket listening on /tmp/openvpn_mgmt

    /scripts/vpn/sslvpn/user-cleanup.sh: line 4: DELETE: not found

    Wed Dec 18 11:36:32 2019 [5708] cleanup success

    Wed Dec 18 11:36:32 2019 [5708] WARNING: using --duplicate-cn and --client-config-dir together is probably not what you want

    Wed Dec 18 11:36:32 2019 [5708] WARNING: --ifconfig-pool-persist will not work with --duplicate-cn

    Wed Dec 18 11:36:32 2019 [5708] NOTE: the current --script-security setting may allow this configuration to call user-defined scripts

    grhandle=0x9658270

    Authentication server 127.0.0.1 gave login response code 2

    Wed Dec 18 11:36:32 2019 [5708] PLUGIN_INIT: POST /lib/openvpn-plugin-utm.so '[/lib/openvpn-plugin-utm.so]' intercepted=PLUGIN_AUTH_USER_PASS_VERIFY|PLUGIN_CLIENT_CONNECT|PLUGIN_CLIENT_DISCONNECT

    Wed Dec 18 11:36:32 2019 [5708] Diffie-Hellman initialized with 2048 bit key

    Wed Dec 18 11:36:32 2019 [5708] WARNING: file '/conf/certificate/private/ApplianceCertificate.key' is group or others accessible

    Wed Dec 18 11:36:32 2019 [5708] WARNING: experimental option --capath /conf/certificate/openvpn

    Wed Dec 18 11:36:32 2019 [5708] Socket Buffers: R=[87380->131072] S=[16384->131072]

    Wed Dec 18 11:36:32 2019 [5708] TUN/TAP device tun0 opened

    Wed Dec 18 11:36:32 2019 [5708] TUN/TAP TX queue length set to 100

    Wed Dec 18 11:36:32 2019 [5708] do_ifconfig, tt->ipv6=1, tt->did_ifconfig_ipv6_setup=1

    Wed Dec 18 11:36:32 2019 [5708] /bin/ip link set dev tun0 up mtu 1500

    Wed Dec 18 11:36:32 2019 [5708] /bin/ip addr add dev tun0 10.81.234.5/24 broadcast 10.81.234.255

    Wed Dec 18 11:36:32 2019 [5708] /bin/ip -6 addr add 2001:db8::1:0/64 dev tun0

    Wed Dec 18 11:36:32 2019 [5708] CSC service status updated to RUNNING

    Wed Dec 18 11:36:32 2019 [5708] Listening for incoming TCP connection on [undef]

    Wed Dec 18 11:36:32 2019 [5708] TCPv6_SERVER link local (bound): [undef]

    Wed Dec 18 11:36:32 2019 [5708] TCPv6_SERVER link remote: [undef]

    Wed Dec 18 11:36:32 2019 [5708] MULTI: multi_init called, r=256 v=256

    Wed Dec 18 11:36:32 2019 [5708] IFCONFIG POOL IPv6: (IPv4) size=50, size_ipv6=65536, netbits=64, base_ipv6=2001:db8::1:1

    Wed Dec 18 11:36:32 2019 [5708] IFCONFIG POOL: base=10.81.234.6 size=50, ipv6=1

    Wed Dec 18 11:36:32 2019 [5708] IFCONFIG POOL LIST

    Wed Dec 18 11:36:32 2019 [5708] MULTI: TCP INIT maxclients=5000 maxevents=5004

    Wed Dec 18 11:36:32 2019 [5708] Initialization Sequence Completed

    Wed Dec 18 11:59:34 2019 [5708] Closing TUN/TAP interface

    Wed Dec 18 11:59:34 2019 [5708] /bin/ip addr del dev tun0 10.81.234.5/24

    Wed Dec 18 11:59:34 2019 [5708] /bin/ip -6 addr del 2001:db8::1:0/64 dev tun0

    Wed Dec 18 11:59:34 2019 [5708] PLUGIN_CLOSE: /lib/openvpn-plugin-utm.so

    Wed Dec 18 11:59:34 2019 [5708] SIGTERM[hard,] received, process exiting

    Wed Dec 18 11:59:38 2019 [9123] OpenVPN 2.3.6 i486-openwrt-linux-gnu [SSL (OpenSSL)] [LZO] [EPOLL] [MH] [IPv6] built on Nov  1 2019

    Wed Dec 18 11:59:38 2019 [9123] library versions: OpenSSL 1.0.2k-fips  26 Jan 2017, LZO 2.09

    Wed Dec 18 11:59:38 2019 [9123] MANAGEMENT: client_uid=0

    Wed Dec 18 11:59:38 2019 [9123] MANAGEMENT: unix domain socket listening on /tmp/openvpn_mgmt

    /scripts/vpn/sslvpn/user-cleanup.sh: line 4: DELETE: not found

    Wed Dec 18 11:59:38 2019 [9123] cleanup success

    Wed Dec 18 11:59:38 2019 [9123] WARNING: using --duplicate-cn and --client-config-dir together is probably not what you want

    Wed Dec 18 11:59:38 2019 [9123] WARNING: --ifconfig-pool-persist will not work with --duplicate-cn

    Wed Dec 18 11:59:38 2019 [9123] NOTE: the current --script-security setting may allow this configuration to call user-defined scripts

    grhandle=0x823f270

    Authentication server 127.0.0.1 gave login response code 2

    Wed Dec 18 11:59:38 2019 [9123] PLUGIN_INIT: POST /lib/openvpn-plugin-utm.so '[/lib/openvpn-plugin-utm.so]' intercepted=PLUGIN_AUTH_USER_PASS_VERIFY|PLUGIN_CLIENT_CONNECT|PLUGIN_CLIENT_DISCONNECT

    Wed Dec 18 11:59:38 2019 [9123] Diffie-Hellman initialized with 2048 bit key

    Wed Dec 18 11:59:38 2019 [9123] WARNING: file '/conf/certificate/private/ApplianceCertificate.key' is group or others accessible

    Wed Dec 18 11:59:38 2019 [9123] WARNING: experimental option --capath /conf/certificate/openvpn

    Wed Dec 18 11:59:38 2019 [9123] Socket Buffers: R=[87380->131072] S=[16384->131072]

    Wed Dec 18 11:59:38 2019 [9123] TUN/TAP device tun0 opened

    Wed Dec 18 11:59:38 2019 [9123] TUN/TAP TX queue length set to 100

    Wed Dec 18 11:59:38 2019 [9123] do_ifconfig, tt->ipv6=1, tt->did_ifconfig_ipv6_setup=1

    Wed Dec 18 11:59:38 2019 [9123] /bin/ip link set dev tun0 up mtu 1500

    Wed Dec 18 11:59:38 2019 [9123] /bin/ip addr add dev tun0 10.81.234.5/24 broadcast 10.81.234.255

    Wed Dec 18 11:59:38 2019 [9123] /bin/ip -6 addr add 2001:db8::1:0/64 dev tun0

    Wed Dec 18 11:59:38 2019 [9123] CSC service status updated to RUNNING

    Wed Dec 18 11:59:38 2019 [9123] Listening for incoming TCP connection on [undef]

    Wed Dec 18 11:59:38 2019 [9123] TCPv6_SERVER link local (bound): [undef]

    Wed Dec 18 11:59:38 2019 [9123] TCPv6_SERVER link remote: [undef]

    Wed Dec 18 11:59:38 2019 [9123] MULTI: multi_init called, r=256 v=256

    Wed Dec 18 11:59:38 2019 [9123] IFCONFIG POOL IPv6: (IPv4) size=50, size_ipv6=65536, netbits=64, base_ipv6=2001:db8::1:1

    Wed Dec 18 11:59:38 2019 [9123] IFCONFIG POOL: base=10.81.234.6 size=50, ipv6=1

    Wed Dec 18 11:59:38 2019 [9123] IFCONFIG POOL LIST

    Wed Dec 18 11:59:38 2019 [9123] MULTI: TCP INIT maxclients=5000 maxevents=5004

    Wed Dec 18 11:59:38 2019 [9123] Initialization Sequence Completed

    Wed Dec 18 12:05:22 2019 [9123] Closing TUN/TAP interface

    Wed Dec 18 12:05:22 2019 [9123] /bin/ip addr del dev tun0 10.81.234.5/24

    Wed Dec 18 12:05:22 2019 [9123] /bin/ip -6 addr del 2001:db8::1:0/64 dev tun0

    Wed Dec 18 12:05:22 2019 [9123] PLUGIN_CLOSE: /lib/openvpn-plugin-utm.so

    Wed Dec 18 12:05:22 2019 [9123] SIGTERM[hard,] received, process exiting

    Wed Dec 18 12:05:26 2019 [9654] OpenVPN 2.3.6 i486-openwrt-linux-gnu [SSL (OpenSSL)] [LZO] [EPOLL] [MH] [IPv6] built on Nov  1 2019

    Wed Dec 18 12:05:26 2019 [9654] library versions: OpenSSL 1.0.2k-fips  26 Jan 2017, LZO 2.09

    Wed Dec 18 12:05:26 2019 [9654] MANAGEMENT: client_uid=0

    Wed Dec 18 12:05:26 2019 [9654] MANAGEMENT: unix domain socket listening on /tmp/openvpn_mgmt

    /scripts/vpn/sslvpn/user-cleanup.sh: line 4: DELETE: not found

    Wed Dec 18 12:05:26 2019 [9654] cleanup success

    Wed Dec 18 12:05:26 2019 [9654] WARNING: using --duplicate-cn and --client-config-dir together is probably not what you want

    Wed Dec 18 12:05:26 2019 [9654] WARNING: --ifconfig-pool-persist will not work with --duplicate-cn

    Wed Dec 18 12:05:26 2019 [9654] NOTE: the current --script-security setting may allow this configuration to call user-defined scripts

    grhandle=0x9355270

    Authentication server 127.0.0.1 gave login response code 2

    Wed Dec 18 12:05:26 2019 [9654] PLUGIN_INIT: POST /lib/openvpn-plugin-utm.so '[/lib/openvpn-plugin-utm.so]' intercepted=PLUGIN_AUTH_USER_PASS_VERIFY|PLUGIN_CLIENT_CONNECT|PLUGIN_CLIENT_DISCONNECT

    Wed Dec 18 12:05:26 2019 [9654] Diffie-Hellman initialized with 2048 bit key

    Wed Dec 18 12:05:26 2019 [9654] WARNING: file '/conf/certificate/private/ApplianceCertificate.key' is group or others accessible

    Wed Dec 18 12:05:26 2019 [9654] WARNING: experimental option --capath /conf/certificate/openvpn

    Wed Dec 18 12:05:26 2019 [9654] Socket Buffers: R=[87380->131072] S=[16384->131072]

    Wed Dec 18 12:05:26 2019 [9654] TUN/TAP device tun0 opened

    Wed Dec 18 12:05:26 2019 [9654] TUN/TAP TX queue length set to 100

    Wed Dec 18 12:05:26 2019 [9654] do_ifconfig, tt->ipv6=1, tt->did_ifconfig_ipv6_setup=1

    Wed Dec 18 12:05:26 2019 [9654] /bin/ip link set dev tun0 up mtu 1500

    Wed Dec 18 12:05:26 2019 [9654] /bin/ip addr add dev tun0 10.81.234.5/24 broadcast 10.81.234.255

    Wed Dec 18 12:05:26 2019 [9654] /bin/ip -6 addr add 2001:db8::1:0/64 dev tun0

    Wed Dec 18 12:05:26 2019 [9654] CSC service status updated to RUNNING

    Wed Dec 18 12:05:26 2019 [9654] Listening for incoming TCP connection on [undef]

    Wed Dec 18 12:05:26 2019 [9654] TCPv6_SERVER link local (bound): [undef]

    Wed Dec 18 12:05:26 2019 [9654] TCPv6_SERVER link remote: [undef]

    Wed Dec 18 12:05:26 2019 [9654] MULTI: multi_init called, r=256 v=256

    Wed Dec 18 12:05:26 2019 [9654] IFCONFIG POOL IPv6: (IPv4) size=50, size_ipv6=65536, netbits=64, base_ipv6=2001:db8::1:1

    Wed Dec 18 12:05:26 2019 [9654] IFCONFIG POOL: base=10.81.234.6 size=50, ipv6=1

    Wed Dec 18 12:05:26 2019 [9654] IFCONFIG POOL LIST

    Wed Dec 18 12:05:26 2019 [9654] MULTI: TCP INIT maxclients=5000 maxevents=5004

    Wed Dec 18 12:05:26 2019 [9654] Initialization Sequence Completed

    Wed Dec 18 12:08:06 2019 [9654] Closing TUN/TAP interface

    Wed Dec 18 12:08:06 2019 [9654] /bin/ip addr del dev tun0 10.81.234.5/24

    Wed Dec 18 12:08:06 2019 [9654] /bin/ip -6 addr del 2001:db8::1:0/64 dev tun0

    Wed Dec 18 12:08:06 2019 [9654] PLUGIN_CLOSE: /lib/openvpn-plugin-utm.so

    Wed Dec 18 12:08:06 2019 [9654] SIGTERM[hard,] received, process exiting

    Wed Dec 18 12:08:10 2019 [10009] OpenVPN 2.3.6 i486-openwrt-linux-gnu [SSL (OpenSSL)] [LZO] [EPOLL] [MH] [IPv6] built on Nov  1 2019

    Wed Dec 18 12:08:10 2019 [10009] library versions: OpenSSL 1.0.2k-fips  26 Jan 2017, LZO 2.09

    Wed Dec 18 12:08:10 2019 [10009] MANAGEMENT: client_uid=0

    Wed Dec 18 12:08:10 2019 [10009] MANAGEMENT: unix domain socket listening on /tmp/openvpn_mgmt

    /scripts/vpn/sslvpn/user-cleanup.sh: line 4: DELETE: not found

    Wed Dec 18 12:08:10 2019 [10009] cleanup success

    Wed Dec 18 12:08:10 2019 [10009] WARNING: using --duplicate-cn and --client-config-dir together is probably not what you want

    Wed Dec 18 12:08:10 2019 [10009] WARNING: --ifconfig-pool-persist will not work with --duplicate-cn

    Wed Dec 18 12:08:10 2019 [10009] NOTE: the current --script-security setting may allow this configuration to call user-defined scripts

    grhandle=0x8128270

    Authentication server 127.0.0.1 gave login response code 2

    Wed Dec 18 12:08:10 2019 [10009] PLUGIN_INIT: POST /lib/openvpn-plugin-utm.so '[/lib/openvpn-plugin-utm.so]' intercepted=PLUGIN_AUTH_USER_PASS_VERIFY|PLUGIN_CLIENT_CONNECT|PLUGIN_CLIENT_DISCONNECT

    Wed Dec 18 12:08:10 2019 [10009] Diffie-Hellman initialized with 2048 bit key

    Wed Dec 18 12:08:10 2019 [10009] WARNING: file '/conf/certificate/private/ApplianceCertificate.key' is group or others accessible

    Wed Dec 18 12:08:10 2019 [10009] WARNING: experimental option --capath /conf/certificate/openvpn

    Wed Dec 18 12:08:10 2019 [10009] Socket Buffers: R=[87380->131072] S=[16384->131072]

    Wed Dec 18 12:08:10 2019 [10009] TUN/TAP device tun0 opened

    Wed Dec 18 12:08:10 2019 [10009] TUN/TAP TX queue length set to 100

    Wed Dec 18 12:08:10 2019 [10009] do_ifconfig, tt->ipv6=1, tt->did_ifconfig_ipv6_setup=1

    Wed Dec 18 12:08:10 2019 [10009] /bin/ip link set dev tun0 up mtu 1500

    Wed Dec 18 12:08:10 2019 [10009] /bin/ip addr add dev tun0 10.81.234.5/24 broadcast 10.81.234.255

    Wed Dec 18 12:08:10 2019 [10009] /bin/ip -6 addr add 2001:db8::1:0/64 dev tun0

    Wed Dec 18 12:08:10 2019 [10009] CSC service status updated to RUNNING

    Wed Dec 18 12:08:10 2019 [10009] Listening for incoming TCP connection on [undef]

    Wed Dec 18 12:08:10 2019 [10009] TCPv6_SERVER link local (bound): [undef]

    Wed Dec 18 12:08:10 2019 [10009] TCPv6_SERVER link remote: [undef]

    Wed Dec 18 12:08:10 2019 [10009] MULTI: multi_init called, r=256 v=256

    Wed Dec 18 12:08:10 2019 [10009] IFCONFIG POOL IPv6: (IPv4) size=50, size_ipv6=65536, netbits=64, base_ipv6=2001:db8::1:1

    Wed Dec 18 12:08:10 2019 [10009] IFCONFIG POOL: base=10.81.234.6 size=50, ipv6=1

    Wed Dec 18 12:08:10 2019 [10009] IFCONFIG POOL LIST

    Wed Dec 18 12:08:10 2019 [10009] MULTI: TCP INIT maxclients=5000 maxevents=5004

    Wed Dec 18 12:08:10 2019 [10009] Initialization Sequence Completed

    Wed Dec 18 13:16:18 2019 [10009] Closing TUN/TAP interface

    Wed Dec 18 13:16:18 2019 [10009] /bin/ip addr del dev tun0 10.81.234.5/24

    Wed Dec 18 13:16:18 2019 [10009] /bin/ip -6 addr del 2001:db8::1:0/64 dev tun0

    Wed Dec 18 13:16:18 2019 [10009] PLUGIN_CLOSE: /lib/openvpn-plugin-utm.so

    Wed Dec 18 13:16:18 2019 [10009] SIGTERM[hard,] received, process exiting

    Wed Dec 18 13:16:22 2019 [15707] OpenVPN 2.3.6 i486-openwrt-linux-gnu [SSL (OpenSSL)] [LZO] [EPOLL] [MH] [IPv6] built on Nov  1 2019

    Wed Dec 18 13:16:22 2019 [15707] library versions: OpenSSL 1.0.2k-fips  26 Jan 2017, LZO 2.09

    Wed Dec 18 13:16:22 2019 [15707] MANAGEMENT: client_uid=0

    Wed Dec 18 13:16:22 2019 [15707] MANAGEMENT: unix domain socket listening on /tmp/openvpn_mgmt

    /scripts/vpn/sslvpn/user-cleanup.sh: line 4: DELETE: not found

    Wed Dec 18 13:16:22 2019 [15707] cleanup success

    Wed Dec 18 13:16:22 2019 [15707] WARNING: using --duplicate-cn and --client-config-dir together is probably not what you want

    Wed Dec 18 13:16:22 2019 [15707] WARNING: --ifconfig-pool-persist will not work with --duplicate-cn

    Wed Dec 18 13:16:22 2019 [15707] NOTE: the current --script-security setting may allow this configuration to call user-defined scripts

    grhandle=0x8e45270

    Authentication server 127.0.0.1 gave login response code 2

    Wed Dec 18 13:16:22 2019 [15707] PLUGIN_INIT: POST /lib/openvpn-plugin-utm.so '[/lib/openvpn-plugin-utm.so]' intercepted=PLUGIN_AUTH_USER_PASS_VERIFY|PLUGIN_CLIENT_CONNECT|PLUGIN_CLIENT_DISCONNECT

    Wed Dec 18 13:16:22 2019 [15707] Diffie-Hellman initialized with 2048 bit key

    Wed Dec 18 13:16:22 2019 [15707] WARNING: file '/conf/certificate/private/ApplianceCertificate.key' is group or others accessible

    Wed Dec 18 13:16:22 2019 [15707] WARNING: experimental option --capath /conf/certificate/openvpn

    Wed Dec 18 13:16:22 2019 [15707] Socket Buffers: R=[87380->131072] S=[16384->131072]

    Wed Dec 18 13:16:22 2019 [15707] TUN/TAP device tun0 opened

    Wed Dec 18 13:16:22 2019 [15707] TUN/TAP TX queue length set to 100

    Wed Dec 18 13:16:22 2019 [15707] do_ifconfig, tt->ipv6=1, tt->did_ifconfig_ipv6_setup=1

    Wed Dec 18 13:16:22 2019 [15707] /bin/ip link set dev tun0 up mtu 1500

    Wed Dec 18 13:16:22 2019 [15707] /bin/ip addr add dev tun0 10.81.234.5/24 broadcast 10.81.234.255

    Wed Dec 18 13:16:22 2019 [15707] /bin/ip -6 addr add 2001:db8::1:0/64 dev tun0

    Wed Dec 18 13:16:22 2019 [15707] CSC service status updated to RUNNING

    Wed Dec 18 13:16:22 2019 [15707] Listening for incoming TCP connection on [undef]

    Wed Dec 18 13:16:22 2019 [15707] TCPv6_SERVER link local (bound): [undef]

    Wed Dec 18 13:16:22 2019 [15707] TCPv6_SERVER link remote: [undef]

    Wed Dec 18 13:16:22 2019 [15707] MULTI: multi_init called, r=256 v=256

    Wed Dec 18 13:16:22 2019 [15707] IFCONFIG POOL IPv6: (IPv4) size=50, size_ipv6=65536, netbits=64, base_ipv6=2001:db8::1:1

    Wed Dec 18 13:16:22 2019 [15707] IFCONFIG POOL: base=10.81.234.6 size=50, ipv6=1

    Wed Dec 18 13:16:22 2019 [15707] IFCONFIG POOL LIST

    Wed Dec 18 13:16:22 2019 [15707] MULTI: TCP INIT maxclients=5000 maxevents=5004

    Wed Dec 18 13:16:22 2019 [15707] Initialization Sequence Completed

    Wed Dec 18 19:59:37 2019 [15707] MANAGEMENT: Client connected from /tmp/openvpn_mgmt

    Wed Dec 18 19:59:37 2019 [15707] MANAGEMENT: CMD 'status -1'

    Wed Dec 18 19:59:47 2019 [15707] MANAGEMENT: Client disconnected

    Thu Dec 19 10:41:18 2019 [15707] TCP connection established with [AF_INET6]::ffff:88.198.46.51:44680

    Thu Dec 19 10:41:19 2019 [15707] ::ffff:88.198.46.51 Connection reset, restarting [0]

    Thu Dec 19 10:41:19 2019 [15707] ::ffff:88.198.46.51 SIGUSR1[soft,connection-reset] received, client-instance restarting

    Thu Dec 19 13:55:42 2019 [15707] TCP connection established with [AF_INET6]::ffff:184.105.247.195:53622

    Thu Dec 19 13:55:42 2019 [15707] ::ffff:184.105.247.195 WARNING: Bad encapsulated packet length from peer (5635), which must be > 0 and <= 1572 -- please ensure that --tun-mtu or --link-mtu is equal on both peers -- this condition could also indicate a possible active attack on the TCP link -- [Attempting restart...]

    Thu Dec 19 13:55:42 2019 [15707] ::ffff:184.105.247.195 Connection reset, restarting [0]

    Thu Dec 19 13:55:42 2019 [15707] ::ffff:184.105.247.195 SIGUSR1[soft,connection-reset] received, client-instance restarting

    Thu Dec 19 19:21:34 2019 [15707] TCP connection established with [AF_INET6]::ffff:51.91.212.81:49652

    Thu Dec 19 19:21:36 2019 [15707] CID is :2

    Thu Dec 19 19:21:38 2019 [15707] ::ffff:51.91.212.81 WARNING: Bad encapsulated packet length from peer (5635), which must be > 0 and <= 1572 -- please ensure that --tun-mtu or --link-mtu is equal on both peers -- this condition could also indicate a possible active attack on the TCP link -- [Attempting restart...]

    Thu Dec 19 19:21:38 2019 [15707] ::ffff:51.91.212.81 Connection reset, restarting [0]

    Thu Dec 19 19:21:38 2019 [15707] ::ffff:51.91.212.81 SIGUSR1[soft,connection-reset] received, client-instance restarting

    Thu Dec 19 19:41:31 2019 [15707] TCP connection established with [AF_INET6]::ffff:77.247.110.64:57566

    Thu Dec 19 19:41:31 2019 [15707] ::ffff:77.247.110.64 WARNING: Bad encapsulated packet length from peer (5635), which must be > 0 and <= 1572 -- please ensure that --tun-mtu or --link-mtu is equal on both peers -- this condition could also indicate a possible active attack on the TCP link -- [Attempting restart...]

    Thu Dec 19 19:41:31 2019 [15707] ::ffff:77.247.110.64 Connection reset, restarting [0]

    Thu Dec 19 19:41:31 2019 [15707] ::ffff:77.247.110.64 SIGUSR1[soft,connection-reset] received, client-instance restarting

    Thu Dec 19 19:41:32 2019 [15707] TCP connection established with [AF_INET6]::ffff:77.247.110.64:57601

    Thu Dec 19 19:41:32 2019 [15707] ::ffff:77.247.110.64 WARNING: Bad encapsulated packet length from peer (5635), which must be > 0 and <= 1572 -- please ensure that --tun-mtu or --link-mtu is equal on both peers -- this condition could also indicate a possible active attack on the TCP link -- [Attempting restart...]

    Thu Dec 19 19:41:32 2019 [15707] ::ffff:77.247.110.64 Connection reset, restarting [0]

    Thu Dec 19 19:41:32 2019 [15707] ::ffff:77.247.110.64 SIGUSR1[soft,connection-reset] received, client-instance restarting

    Thu Dec 19 20:43:18 2019 [15707] TCP connection established with [AF_INET6]::ffff:138.99.216.171:61000

    Thu Dec 19 20:43:20 2019 [15707] ::ffff:138.99.216.171 WARNING: Bad encapsulated packet length from peer (5635), which must be > 0 and <= 1572 -- please ensure that --tun-mtu or --link-mtu is equal on both peers -- this condition could also indicate a possible active attack on the TCP link -- [Attempting restart...]

    Thu Dec 19 20:43:20 2019 [15707] ::ffff:138.99.216.171 Connection reset, restarting [0]

    Thu Dec 19 20:43:20 2019 [15707] ::ffff:138.99.216.171 SIGUSR1[soft,connection-reset] received, client-instance restarting

    Thu Dec 19 21:53:19 2019 [15707] TCP connection established with [AF_INET6]::ffff:196.52.43.131:58614

    Thu Dec 19 21:53:21 2019 [15707] ::ffff:196.52.43.131 WARNING: Bad encapsulated packet length from peer (5635), which must be > 0 and <= 1572 -- please ensure that --tun-mtu or --link-mtu is equal on both peers -- this condition could also indicate a possible active attack on the TCP link -- [Attempting restart...]

    Thu Dec 19 21:53:21 2019 [15707] ::ffff:196.52.43.131 Connection reset, restarting [0]

    Thu Dec 19 21:53:21 2019 [15707] ::ffff:196.52.43.131 SIGUSR1[soft,connection-reset] received, client-instance restarting

    Thu Dec 19 22:30:18 2019 [15707] TCP connection established with [AF_INET6]::ffff:185.173.35.37:46702

    Thu Dec 19 22:30:18 2019 [15707] ::ffff:185.173.35.37 WARNING: Bad encapsulated packet length from peer (5635), which must be > 0 and <= 1572 -- please ensure that --tun-mtu or --link-mtu is equal on both peers -- this condition could also indicate a possible active attack on the TCP link -- [Attempting restart...]

    Thu Dec 19 22:30:18 2019 [15707] ::ffff:185.173.35.37 Connection reset, restarting [0]

    Thu Dec 19 22:30:18 2019 [15707] ::ffff:185.173.35.37 SIGUSR1[soft,connection-reset] received, client-instance restarting

    Fri Dec 20 17:51:03 2019 [15707] TCP connection established with [AF_INET6]::ffff:184.105.139.67:49104

    Fri Dec 20 17:51:03 2019 [15707] ::ffff:184.105.139.67 WARNING: Bad encapsulated packet length from peer (5635), which must be > 0 and <= 1572 -- please ensure that --tun-mtu or --link-mtu is equal on both peers -- this condition could also indicate a possible active attack on the TCP link -- [Attempting restart...]

    Fri Dec 20 17:51:03 2019 [15707] ::ffff:184.105.139.67 Connection reset, restarting [0]

    Fri Dec 20 17:51:03 2019 [15707] ::ffff:184.105.139.67 SIGUSR1[soft,connection-reset] received, client-instance restarting

    Fri Dec 20 19:06:19 2019 [15707] TCP connection established with [AF_INET6]::ffff:198.143.155.138:46560

    Fri Dec 20 19:06:19 2019 [15707] ::ffff:198.143.155.138 WARNING: Bad encapsulated packet length from peer (5635), which must be > 0 and <= 1572 -- please ensure that --tun-mtu or --link-mtu is equal on both peers -- this condition could also indicate a possible active attack on the TCP link -- [Attempting restart...]

    Fri Dec 20 19:06:19 2019 [15707] ::ffff:198.143.155.138 Connection reset, restarting [0]

    Fri Dec 20 19:06:19 2019 [15707] ::ffff:198.143.155.138 SIGUSR1[soft,connection-reset] received, client-instance restarting

    Fri Dec 20 19:06:22 2019 [15707] TCP connection established with [AF_INET6]::ffff:198.143.155.138:50320

    Fri Dec 20 19:06:22 2019 [15707] ::ffff:198.143.155.138 WARNING: Bad encapsulated packet length from peer (18245), which must be > 0 and <= 1572 -- please ensure that --tun-mtu or --link-mtu is equal on both peers -- this condition could also indicate a possible active attack on the TCP link -- [Attempting restart...]

    Fri Dec 20 19:06:22 2019 [15707] ::ffff:198.143.155.138 Connection reset, restarting [0]

    Fri Dec 20 19:06:22 2019 [15707] ::ffff:198.143.155.138 SIGUSR1[soft,connection-reset] received, client-instance restarting

    Fri Dec 20 19:06:24 2019 [15707] TCP connection established with [AF_INET6]::ffff:198.143.155.138:53275

    Fri Dec 20 19:06:25 2019 [15707] ::ffff:198.143.155.138 CID is :11

    Fri Dec 20 19:06:29 2019 [15707] ::ffff:198.143.155.138 Connection reset, restarting [0]

    Fri Dec 20 19:06:29 2019 [15707] ::ffff:198.143.155.138 SIGUSR1[soft,connection-reset] received, client-instance restarting

    Fri Dec 20 19:06:31 2019 [15707] TCP connection established with [AF_INET6]::ffff:198.143.155.138:35108

    Fri Dec 20 19:06:31 2019 [15707] ::ffff:198.143.155.138 WARNING: Bad encapsulated packet length from peer (5635), which must be > 0 and <= 1572 -- please ensure that --tun-mtu or --link-mtu is equal on both peers -- this condition could also indicate a possible active attack on the TCP link -- [Attempting restart...]

    Fri Dec 20 19:06:31 2019 [15707] ::ffff:198.143.155.138 Connection reset, restarting [0]

    Fri Dec 20 19:06:31 2019 [15707] ::ffff:198.143.155.138 SIGUSR1[soft,connection-reset] received, client-instance restarting

    Fri Dec 20 19:06:35 2019 [15707] TCP connection established with [AF_INET6]::ffff:198.143.155.138:38868

    Fri Dec 20 19:06:35 2019 [15707] ::ffff:198.143.155.138 WARNING: Bad encapsulated packet length from peer (5635), which must be > 0 and <= 1572 -- please ensure that --tun-mtu or --link-mtu is equal on both peers -- this condition could also indicate a possible active attack on the TCP link -- [Attempting restart...]

    Fri Dec 20 19:06:35 2019 [15707] ::ffff:198.143.155.138 Connection reset, restarting [0]

    Fri Dec 20 19:06:35 2019 [15707] ::ffff:198.143.155.138 SIGUSR1[soft,connection-reset] received, client-instance restarting

    Fri Dec 20 19:06:37 2019 [15707] TCP connection established with [AF_INET6]::ffff:198.143.155.138:43164

    Fri Dec 20 19:06:37 2019 [15707] ::ffff:198.143.155.138 WARNING: Bad encapsulated packet length from peer (32814), which must be > 0 and <= 1572 -- please ensure that --tun-mtu or --link-mtu is equal on both peers -- this condition could also indicate a possible active attack on the TCP link -- [Attempting restart...]

    Fri Dec 20 19:06:37 2019 [15707] ::ffff:198.143.155.138 Connection reset, restarting [0]

    Fri Dec 20 19:06:37 2019 [15707] ::ffff:198.143.155.138 SIGUSR1[soft,connection-reset] received, client-instance restarting

    Fri Dec 20 19:06:39 2019 [15707] TCP connection established with [AF_INET6]::ffff:198.143.155.138:46056

    Fri Dec 20 19:06:40 2019 [15707] ::ffff:198.143.155.138 CID is :15

    Fri Dec 20 19:06:44 2019 [15707] ::ffff:198.143.155.138 Connection reset, restarting [0]

    Fri Dec 20 19:06:44 2019 [15707] ::ffff:198.143.155.138 SIGUSR1[soft,connection-reset] received, client-instance restarting

    Fri Dec 20 19:06:46 2019 [15707] TCP connection established with [AF_INET6]::ffff:198.143.155.138:55389

    Fri Dec 20 19:06:51 2019 [15707] ::ffff:198.143.155.138 Connection reset, restarting [0]

    Fri Dec 20 19:06:51 2019 [15707] ::ffff:198.143.155.138 SIGUSR1[soft,connection-reset] received, client-instance restarting

    Fri Dec 20 19:06:53 2019 [15707] TCP connection established with [AF_INET6]::ffff:198.143.155.138:36788

    Fri Dec 20 19:06:55 2019 [15707] ::ffff:198.143.155.138 CID is :17

    Fri Dec 20 19:06:58 2019 [15707] ::ffff:198.143.155.138 Connection reset, restarting [0]

    Fri Dec 20 19:06:58 2019 [15707] ::ffff:198.143.155.138 SIGUSR1[soft,connection-reset] received, client-instance restarting

    Fri Dec 20 19:24:45 2019 [15707] TCP connection established with [AF_INET6]::ffff:138.99.216.147:61000

    Fri Dec 20 19:24:47 2019 [15707] ::ffff:138.99.216.147 WARNING: Bad encapsulated packet length from peer (5635), which must be > 0 and <= 1572 -- please ensure that --tun-mtu or --link-mtu is equal on both peers -- this condition could also indicate a possible active attack on the TCP link -- [Attempting restart...]

    Fri Dec 20 19:24:47 2019 [15707] ::ffff:138.99.216.147 Connection reset, restarting [0]

    Fri Dec 20 19:24:47 2019 [15707] ::ffff:138.99.216.147 SIGUSR1[soft,connection-reset] received, client-instance restarting

    Sat Dec 21 01:44:45 2019 [15707] Closing TUN/TAP interface

    Sat Dec 21 01:44:45 2019 [15707] /bin/ip addr del dev tun0 10.81.234.5/24

    Sat Dec 21 01:44:45 2019 [15707] /bin/ip -6 addr del 2001:db8::1:0/64 dev tun0

    Sat Dec 21 01:44:45 2019 [15707] PLUGIN_CLOSE: /lib/openvpn-plugin-utm.so

    Sat Dec 21 01:44:45 2019 [15707] SIGTERM[hard,] received, process exiting

    Sat Dec 21 01:44:49 2019 [5028] OpenVPN 2.3.6 i486-openwrt-linux-gnu [SSL (OpenSSL)] [LZO] [EPOLL] [MH] [IPv6] built on Nov  1 2019

    Sat Dec 21 01:44:49 2019 [5028] library versions: OpenSSL 1.0.2k-fips  26 Jan 2017, LZO 2.09

    Sat Dec 21 01:44:49 2019 [5028] MANAGEMENT: client_uid=0

    Sat Dec 21 01:44:49 2019 [5028] MANAGEMENT: unix domain socket listening on /tmp/openvpn_mgmt

    /scripts/vpn/sslvpn/user-cleanup.sh: line 4: DELETE: not found

    Sat Dec 21 01:44:49 2019 [5028] cleanup success

    Sat Dec 21 01:44:49 2019 [5028] WARNING: using --duplicate-cn and --client-config-dir together is probably not what you want

    Sat Dec 21 01:44:49 2019 [5028] WARNING: --ifconfig-pool-persist will not work with --duplicate-cn

    Sat Dec 21 01:44:49 2019 [5028] NOTE: the current --script-security setting may allow this configuration to call user-defined scripts

    grhandle=0x8566270

    Authentication server 127.0.0.1 gave login response code 2

    Sat Dec 21 01:44:49 2019 [5028] PLUGIN_INIT: POST /lib/openvpn-plugin-utm.so '[/lib/openvpn-plugin-utm.so]' intercepted=PLUGIN_AUTH_USER_PASS_VERIFY|PLUGIN_CLIENT_CONNECT|PLUGIN_CLIENT_DISCONNECT

    Sat Dec 21 01:44:49 2019 [5028] Diffie-Hellman initialized with 2048 bit key

    Sat Dec 21 01:44:49 2019 [5028] WARNING: file '/conf/certificate/private/ApplianceCertificate.key' is group or others accessible

    Sat Dec 21 01:44:49 2019 [5028] WARNING: experimental option --capath /conf/certificate/openvpn

    Sat Dec 21 01:44:49 2019 [5028] Socket Buffers: R=[87380->131072] S=[16384->131072]

    Sat Dec 21 01:44:49 2019 [5028] TUN/TAP device tun0 opened

    Sat Dec 21 01:44:49 2019 [5028] TUN/TAP TX queue length set to 100

    Sat Dec 21 01:44:49 2019 [5028] do_ifconfig, tt->ipv6=1, tt->did_ifconfig_ipv6_setup=1

    Sat Dec 21 01:44:49 2019 [5028] /bin/ip link set dev tun0 up mtu 1500

    Sat Dec 21 01:44:49 2019 [5028] /bin/ip addr add dev tun0 10.81.234.5/24 broadcast 10.81.234.255

    Sat Dec 21 01:44:49 2019 [5028] /bin/ip -6 addr add 2001:db8::1:0/64 dev tun0

    Sat Dec 21 01:44:49 2019 [5028] CSC service status updated to RUNNING

    Sat Dec 21 01:44:49 2019 [5028] Listening for incoming TCP connection on [undef]

    Sat Dec 21 01:44:49 2019 [5028] TCPv6_SERVER link local (bound): [undef]

    Sat Dec 21 01:44:49 2019 [5028] TCPv6_SERVER link remote: [undef]

    Sat Dec 21 01:44:49 2019 [5028] MULTI: multi_init called, r=256 v=256

    Sat Dec 21 01:44:49 2019 [5028] IFCONFIG POOL IPv6: (IPv4) size=50, size_ipv6=65536, netbits=64, base_ipv6=2001:db8::1:1

    Sat Dec 21 01:44:49 2019 [5028] IFCONFIG POOL: base=10.81.234.6 size=50, ipv6=1

    Sat Dec 21 01:44:49 2019 [5028] IFCONFIG POOL LIST

    Sat Dec 21 01:44:49 2019 [5028] MULTI: TCP INIT maxclients=5000 maxevents=5004

    Sat Dec 21 01:44:49 2019 [5028] Initialization Sequence Completed

    Sat Dec 21 02:07:32 2019 [5028] Closing TUN/TAP interface

    Sat Dec 21 02:07:32 2019 [5028] /bin/ip addr del dev tun0 10.81.234.5/24

    Sat Dec 21 02:07:33 2019 [5028] /bin/ip -6 addr del 2001:db8::1:0/64 dev tun0

    Sat Dec 21 02:07:33 2019 [5028] PLUGIN_CLOSE: /lib/openvpn-plugin-utm.so

    Sat Dec 21 02:07:33 2019 [5028] SIGTERM[hard,] received, process exiting

    Sat Dec 21 02:07:37 2019 [10980] OpenVPN 2.3.6 i486-openwrt-linux-gnu [SSL (OpenSSL)] [LZO] [EPOLL] [MH] [IPv6] built on Nov  1 2019

    Sat Dec 21 02:07:37 2019 [10980] library versions: OpenSSL 1.0.2k-fips  26 Jan 2017, LZO 2.09

    Sat Dec 21 02:07:37 2019 [10980] MANAGEMENT: client_uid=0

    Sat Dec 21 02:07:37 2019 [10980] MANAGEMENT: unix domain socket listening on /tmp/openvpn_mgmt

    /scripts/vpn/sslvpn/user-cleanup.sh: line 4: DELETE: not found

    Sat Dec 21 02:07:37 2019 [10980] cleanup success

    Sat Dec 21 02:07:37 2019 [10980] WARNING: using --duplicate-cn and --client-config-dir together is probably not what you want

    Sat Dec 21 02:07:37 2019 [10980] WARNING: --ifconfig-pool-persist will not work with --duplicate-cn

    Sat Dec 21 02:07:37 2019 [10980] NOTE: the current --script-security setting may allow this configuration to call user-defined scripts

    grhandle=0x96a9270

    Authentication server 127.0.0.1 gave login response code 2

    Sat Dec 21 02:07:37 2019 [10980] PLUGIN_INIT: POST /lib/openvpn-plugin-utm.so '[/lib/openvpn-plugin-utm.so]' intercepted=PLUGIN_AUTH_USER_PASS_VERIFY|PLUGIN_CLIENT_CONNECT|PLUGIN_CLIENT_DISCONNECT

    Sat Dec 21 02:07:37 2019 [10980] Diffie-Hellman initialized with 2048 bit key

    Sat Dec 21 02:07:37 2019 [10980] WARNING: file '/conf/certificate/private/ApplianceCertificate.key' is group or others accessible

    Sat Dec 21 02:07:37 2019 [10980] WARNING: experimental option --capath /conf/certificate/openvpn

    Sat Dec 21 02:07:37 2019 [10980] Socket Buffers: R=[87380->131072] S=[16384->131072]

    Sat Dec 21 02:07:37 2019 [10980] TUN/TAP device tun0 opened

    Sat Dec 21 02:07:37 2019 [10980] TUN/TAP TX queue length set to 100

    Sat Dec 21 02:07:37 2019 [10980] do_ifconfig, tt->ipv6=1, tt->did_ifconfig_ipv6_setup=1

    Sat Dec 21 02:07:37 2019 [10980] /bin/ip link set dev tun0 up mtu 1500

    Sat Dec 21 02:07:37 2019 [10980] /bin/ip addr add dev tun0 10.81.234.5/24 broadcast 10.81.234.255

    Sat Dec 21 02:07:37 2019 [10980] /bin/ip -6 addr add 2001:db8::1:0/64 dev tun0

    Sat Dec 21 02:07:37 2019 [10980] CSC service status updated to RUNNING

    Sat Dec 21 02:07:37 2019 [10980] Listening for incoming TCP connection on [undef]

    Sat Dec 21 02:07:37 2019 [10980] TCPv6_SERVER link local (bound): [undef]

    Sat Dec 21 02:07:37 2019 [10980] TCPv6_SERVER link remote: [undef]

    Sat Dec 21 02:07:37 2019 [10980] MULTI: multi_init called, r=256 v=256

    Sat Dec 21 02:07:37 2019 [10980] IFCONFIG POOL IPv6: (IPv4) size=50, size_ipv6=65536, netbits=64, base_ipv6=2001:db8::1:1

    Sat Dec 21 02:07:37 2019 [10980] IFCONFIG POOL: base=10.81.234.6 size=50, ipv6=1

    Sat Dec 21 02:07:37 2019 [10980] IFCONFIG POOL LIST

    Sat Dec 21 02:07:37 2019 [10980] MULTI: TCP INIT maxclients=5000 maxevents=5004

    Sat Dec 21 02:07:37 2019 [10980] Initialization Sequence Completed

    Sat Dec 21 06:31:20 2019 [10980] TCP connection established with [AF_INET6]::ffff:45.136.108.22:2690

    Sat Dec 21 06:31:35 2019 [10980] CID is :0

    Sat Dec 21 06:31:51 2019 [10980] CID is :0

    Sat Dec 21 06:32:06 2019 [10980] CID is :0

    Sat Dec 21 06:32:21 2019 [10980] CID is :0

    Sat Dec 21 06:32:21 2019 [10980] ::ffff:45.136.108.22 TLS Error: TLS key negotiation failed to occur within 60 seconds (check your network connectivity)

    Sat Dec 21 06:32:21 2019 [10980] ::ffff:45.136.108.22 TLS Error: TLS handshake failed

    Sat Dec 21 06:32:21 2019 [10980] ::ffff:45.136.108.22 Fatal TLS error (check_tls_errors_co), restarting

    Sat Dec 21 06:32:21 2019 [10980] ::ffff:45.136.108.22 SIGUSR1[soft,tls-error] received, client-instance restarting

    Sat Dec 21 13:58:30 2019 [10980] TCP connection established with [AF_INET6]::ffff:184.105.139.69:62216

    Sat Dec 21 13:58:31 2019 [10980] ::ffff:184.105.139.69 WARNING: Bad encapsulated packet length from peer (5635), which must be > 0 and <= 1572 -- please ensure that --tun-mtu or --link-mtu is equal on both peers -- this condition could also indicate a possible active attack on the TCP link -- [Attempting restart...]

    Sat Dec 21 13:58:31 2019 [10980] ::ffff:184.105.139.69 Connection reset, restarting [0]

    Sat Dec 21 13:58:31 2019 [10980] ::ffff:184.105.139.69 SIGUSR1[soft,connection-reset] received, client-instance restarting

    Sat Dec 21 15:43:51 2019 [10980] TCP connection established with [AF_INET6]::ffff:159.203.201.112:54536

    Sat Dec 21 15:44:01 2019 [10980] ::ffff:159.203.201.112 Connection reset, restarting [0]

    Sat Dec 21 15:44:01 2019 [10980] ::ffff:159.203.201.112 SIGUSR1[soft,connection-reset] received, client-instance restarting

    Sat Dec 21 18:50:58 2019 [10980] TCP connection established with [AF_INET6]::ffff:51.91.212.81:36482

    Sat Dec 21 18:50:58 2019 [10980] ::ffff:51.91.212.81 WARNING: Bad encapsulated packet length from peer (5635), which must be > 0 and <= 1572 -- please ensure that --tun-mtu or --link-mtu is equal on both peers -- this condition could also indicate a possible active attack on the TCP link -- [Attempting restart...]

    Sat Dec 21 18:50:58 2019 [10980] ::ffff:51.91.212.81 Connection reset, restarting [0]

    Sat Dec 21 18:50:58 2019 [10980] ::ffff:51.91.212.81 SIGUSR1[soft,connection-reset] received, client-instance restarting

    Sat Dec 21 20:52:24 2019 [10980] TCP connection established with [AF_INET6]::ffff:1.192.193.15:59928

    Sat Dec 21 20:52:27 2019 [10980] TCP connection established with [AF_INET6]::ffff:1.192.193.15:62550

    Sat Dec 21 20:52:27 2019 [10980] ::ffff:1.192.193.15 WARNING: Bad encapsulated packet length from peer (5635), which must be > 0 and <= 1572 -- please ensure that --tun-mtu or --link-mtu is equal on both peers -- this condition could also indicate a possible active attack on the TCP link -- [Attempting restart...]

    Sat Dec 21 20:52:27 2019 [10980] ::ffff:1.192.193.15 Connection reset, restarting [0]

    Sat Dec 21 20:52:27 2019 [10980] ::ffff:1.192.193.15 SIGUSR1[soft,connection-reset] received, client-instance restarting

    Sat Dec 21 20:52:28 2019 [10980] ::ffff:1.192.193.15 Connection reset, restarting [0]

    Sat Dec 21 20:52:28 2019 [10980] ::ffff:1.192.193.15 SIGUSR1[soft,connection-reset] received, client-instance restarting

    Sat Dec 21 22:57:40 2019 [10980] TCP connection established with [AF_INET6]::ffff:71.6.232.4:43234

    Sat Dec 21 22:57:40 2019 [10980] ::ffff:71.6.232.4 WARNING: Bad encapsulated packet length from peer (5635), which must be > 0 and <= 1572 -- please ensure that --tun-mtu or --link-mtu is equal on both peers -- this condition could also indicate a possible active attack on the TCP link -- [Attempting restart...]

    Sat Dec 21 22:57:40 2019 [10980] ::ffff:71.6.232.4 Connection reset, restarting [0]

    Sat Dec 21 22:57:40 2019 [10980] ::ffff:71.6.232.4 SIGUSR1[soft,connection-reset] received, client-instance restarting

    Sun Dec 22 00:19:55 2019 [10980] MANAGEMENT: Client connected from /tmp/openvpn_mgmt

    Sun Dec 22 00:19:55 2019 [10980] MANAGEMENT: CMD 'status -1'

    Sun Dec 22 00:20:05 2019 [10980] MANAGEMENT: Client disconnected

    Sun Dec 22 00:37:07 2019 [10980] Closing TUN/TAP interface

    Sun Dec 22 00:37:07 2019 [10980] /bin/ip addr del dev tun0 10.81.234.5/24

    Sun Dec 22 00:37:07 2019 [10980] /bin/ip -6 addr del 2001:db8::1:0/64 dev tun0

    Sun Dec 22 00:37:08 2019 [10980] PLUGIN_CLOSE: /lib/openvpn-plugin-utm.so

    Sun Dec 22 00:37:08 2019 [10980] SIGTERM[hard,] received, process exiting

    Sun Dec 22 00:37:12 2019 [30145] OpenVPN 2.3.6 i486-openwrt-linux-gnu [SSL (OpenSSL)] [LZO] [EPOLL] [MH] [IPv6] built on Nov  1 2019

    Sun Dec 22 00:37:12 2019 [30145] library versions: OpenSSL 1.0.2k-fips  26 Jan 2017, LZO 2.09

    Sun Dec 22 00:37:12 2019 [30145] MANAGEMENT: client_uid=0

    Sun Dec 22 00:37:12 2019 [30145] MANAGEMENT: unix domain socket listening on /tmp/openvpn_mgmt

    /scripts/vpn/sslvpn/user-cleanup.sh: line 4: DELETE: not found

    Sun Dec 22 00:37:12 2019 [30145] cleanup success

    Sun Dec 22 00:37:12 2019 [30145] WARNING: using --duplicate-cn and --client-config-dir together is probably not what you want

    Sun Dec 22 00:37:12 2019 [30145] WARNING: --ifconfig-pool-persist will not work with --duplicate-cn

    Sun Dec 22 00:37:12 2019 [30145] NOTE: the current --script-security setting may allow this configuration to call user-defined scripts

    grhandle=0x8c00270

    Authentication server 127.0.0.1 gave login response code 2

    Sun Dec 22 00:37:12 2019 [30145] PLUGIN_INIT: POST /lib/openvpn-plugin-utm.so '[/lib/openvpn-plugin-utm.so]' intercepted=PLUGIN_AUTH_USER_PASS_VERIFY|PLUGIN_CLIENT_CONNECT|PLUGIN_CLIENT_DISCONNECT

    Sun Dec 22 00:37:12 2019 [30145] Diffie-Hellman initialized with 2048 bit key

    Sun Dec 22 00:37:12 2019 [30145] WARNING: file '/conf/certificate/private/ApplianceCertificate.key' is group or others accessible

    Sun Dec 22 00:37:12 2019 [30145] WARNING: experimental option --capath /conf/certificate/openvpn

    Sun Dec 22 00:37:12 2019 [30145] Socket Buffers: R=[87380->131072] S=[16384->131072]

    Sun Dec 22 00:37:12 2019 [30145] TUN/TAP device tun0 opened

    Sun Dec 22 00:37:12 2019 [30145] TUN/TAP TX queue length set to 100

    Sun Dec 22 00:37:12 2019 [30145] do_ifconfig, tt->ipv6=1, tt->did_ifconfig_ipv6_setup=1

    Sun Dec 22 00:37:12 2019 [30145] /bin/ip link set dev tun0 up mtu 1500

    Sun Dec 22 00:37:12 2019 [30145] /bin/ip addr add dev tun0 10.81.234.5/24 broadcast 10.81.234.255

    Sun Dec 22 00:37:12 2019 [30145] /bin/ip -6 addr add 2001:db8::1:0/64 dev tun0

    Sun Dec 22 00:37:12 2019 [30145] CSC service status updated to RUNNING

    Sun Dec 22 00:37:12 2019 [30145] Listening for incoming TCP connection on [undef]

    Sun Dec 22 00:37:12 2019 [30145] TCPv6_SERVER link local (bound): [undef]

    Sun Dec 22 00:37:12 2019 [30145] TCPv6_SERVER link remote: [undef]

    Sun Dec 22 00:37:12 2019 [30145] MULTI: multi_init called, r=256 v=256

    Sun Dec 22 00:37:12 2019 [30145] IFCONFIG POOL IPv6: (IPv4) size=50, size_ipv6=65536, netbits=64, base_ipv6=2001:db8::1:1

    Sun Dec 22 00:37:12 2019 [30145] IFCONFIG POOL: base=10.81.234.6 size=50, ipv6=1

    Sun Dec 22 00:37:12 2019 [30145] IFCONFIG POOL LIST

    Sun Dec 22 00:37:12 2019 [30145] MULTI: TCP INIT maxclients=5000 maxevents=5004

    Sun Dec 22 00:37:12 2019 [30145] Initialization Sequence Completed

    Sun Dec 22 00:41:24 2019 [30145] TCP connection established with [AF_INET6]::ffff:88.198.46.51:37598

    Sun Dec 22 00:41:24 2019 [30145] ::ffff:88.198.46.51 Connection reset, restarting [0]

    Sun Dec 22 00:41:24 2019 [30145] ::ffff:88.198.46.51 SIGUSR1[soft,connection-reset] received, client-instance restarting

    Sun Dec 22 00:42:44 2019 [30145] Closing TUN/TAP interface

    Sun Dec 22 00:42:44 2019 [30145] /bin/ip addr del dev tun0 10.81.234.5/24

    Sun Dec 22 00:42:44 2019 [30145] /bin/ip -6 addr del 2001:db8::1:0/64 dev tun0

    Sun Dec 22 00:42:45 2019 [30145] PLUGIN_CLOSE: /lib/openvpn-plugin-utm.so

    Sun Dec 22 00:42:45 2019 [30145] SIGTERM[hard,] received, process exiting

    Sun Dec 22 00:42:49 2019 [30733] OpenVPN 2.3.6 i486-openwrt-linux-gnu [SSL (OpenSSL)] [LZO] [EPOLL] [MH] [IPv6] built on Nov  1 2019

    Sun Dec 22 00:42:49 2019 [30733] library versions: OpenSSL 1.0.2k-fips  26 Jan 2017, LZO 2.09

    Sun Dec 22 00:42:49 2019 [30733] MANAGEMENT: client_uid=0

    Sun Dec 22 00:42:49 2019 [30733] MANAGEMENT: unix domain socket listening on /tmp/openvpn_mgmt

    /scripts/vpn/sslvpn/user-cleanup.sh: line 4: DELETE: not found

    Sun Dec 22 00:42:49 2019 [30733] cleanup success

    Sun Dec 22 00:42:49 2019 [30733] WARNING: using --duplicate-cn and --client-config-dir together is probably not what you want

    Sun Dec 22 00:42:49 2019 [30733] WARNING: --ifconfig-pool-persist will not work with --duplicate-cn

    Sun Dec 22 00:42:49 2019 [30733] NOTE: the current --script-security setting may allow this configuration to call user-defined scripts

    grhandle=0x8f13270

    Authentication server 127.0.0.1 gave login response code 2

    Sun Dec 22 00:42:49 2019 [30733] PLUGIN_INIT: POST /lib/openvpn-plugin-utm.so '[/lib/openvpn-plugin-utm.so]' intercepted=PLUGIN_AUTH_USER_PASS_VERIFY|PLUGIN_CLIENT_CONNECT|PLUGIN_CLIENT_DISCONNECT

    Sun Dec 22 00:42:49 2019 [30733] Diffie-Hellman initialized with 2048 bit key

    Sun Dec 22 00:42:49 2019 [30733] WARNING: file '/conf/certificate/private/ApplianceCertificate.key' is group or others accessible

    Sun Dec 22 00:42:49 2019 [30733] WARNING: experimental option --capath /conf/certificate/openvpn

    Sun Dec 22 00:42:49 2019 [30733] Socket Buffers: R=[229376->131072] S=[229376->131072]

    Sun Dec 22 00:42:49 2019 [30733] TUN/TAP device tun0 opened

    Sun Dec 22 00:42:49 2019 [30733] TUN/TAP TX queue length set to 100

    Sun Dec 22 00:42:49 2019 [30733] do_ifconfig, tt->ipv6=1, tt->did_ifconfig_ipv6_setup=1

    Sun Dec 22 00:42:49 2019 [30733] /bin/ip link set dev tun0 up mtu 1500

    Sun Dec 22 00:42:49 2019 [30733] /bin/ip addr add dev tun0 10.81.234.5/24 broadcast 10.81.234.255

    Sun Dec 22 00:42:49 2019 [30733] /bin/ip -6 addr add 2001:db8::1:0/64 dev tun0

    Sun Dec 22 00:42:49 2019 [30733] CSC service status updated to RUNNING

    Sun Dec 22 00:42:49 2019 [30733] UDPv6 link local (bound): [undef]

    Sun Dec 22 00:42:49 2019 [30733] UDPv6 link remote: [undef]

    Sun Dec 22 00:42:49 2019 [30733] MULTI: multi_init called, r=256 v=256

    Sun Dec 22 00:42:49 2019 [30733] IFCONFIG POOL IPv6: (IPv4) size=50, size_ipv6=65536, netbits=64, base_ipv6=2001:db8::1:1

    Sun Dec 22 00:42:49 2019 [30733] IFCONFIG POOL: base=10.81.234.6 size=50, ipv6=1

    Sun Dec 22 00:42:49 2019 [30733] IFCONFIG POOL LIST

    Sun Dec 22 00:42:49 2019 [30733] Initialization Sequence Completed

    Sun Dec 22 00:44:23 2019 [30733] event_wait : Interrupted system call (code=4)

    Sun Dec 22 00:44:23 2019 [30733] Closing TUN/TAP interface

    Sun Dec 22 00:44:23 2019 [30733] /bin/ip addr del dev tun0 10.81.234.5/24

    Sun Dec 22 00:44:23 2019 [30733] /bin/ip -6 addr del 2001:db8::1:0/64 dev tun0

    Sun Dec 22 00:44:23 2019 [30733] PLUGIN_CLOSE: /lib/openvpn-plugin-utm.so

    Sun Dec 22 00:44:23 2019 [30733] SIGTERM[hard,] received, process exiting

    Sun Dec 22 00:44:27 2019 [31021] OpenVPN 2.3.6 i486-openwrt-linux-gnu [SSL (OpenSSL)] [LZO] [EPOLL] [MH] [IPv6] built on Nov  1 2019

    Sun Dec 22 00:44:27 2019 [31021] library versions: OpenSSL 1.0.2k-fips  26 Jan 2017, LZO 2.09

    Sun Dec 22 00:44:27 2019 [31021] MANAGEMENT: client_uid=0

    Sun Dec 22 00:44:27 2019 [31021] MANAGEMENT: unix domain socket listening on /tmp/openvpn_mgmt

    /scripts/vpn/sslvpn/user-cleanup.sh: line 4: DELETE: not found

    Sun Dec 22 00:44:27 2019 [31021] cleanup success

    Sun Dec 22 00:44:27 2019 [31021] WARNING: using --duplicate-cn and --client-config-dir together is probably not what you want

    Sun Dec 22 00:44:27 2019 [31021] WARNING: --ifconfig-pool-persist will not work with --duplicate-cn

    Sun Dec 22 00:44:27 2019 [31021] NOTE: the current --script-security setting may allow this configuration to call user-defined scripts

    grhandle=0x8a3a270

    Authentication server 127.0.0.1 gave login response code 2

    Sun Dec 22 00:44:27 2019 [31021] PLUGIN_INIT: POST /lib/openvpn-plugin-utm.so '[/lib/openvpn-plugin-utm.so]' intercepted=PLUGIN_AUTH_USER_PASS_VERIFY|PLUGIN_CLIENT_CONNECT|PLUGIN_CLIENT_DISCONNECT

    Sun Dec 22 00:44:27 2019 [31021] Diffie-Hellman initialized with 2048 bit key

    Sun Dec 22 00:44:27 2019 [31021] WARNING: file '/conf/certificate/private/ApplianceCertificate.key' is group or others accessible

    Sun Dec 22 00:44:27 2019 [31021] WARNING: experimental option --capath /conf/certificate/openvpn

    Sun Dec 22 00:44:27 2019 [31021] Socket Buffers: R=[87380->131072] S=[16384->131072]

    Sun Dec 22 00:44:27 2019 [31021] TUN/TAP device tun0 opened

    Sun Dec 22 00:44:27 2019 [31021] TUN/TAP TX queue length set to 100

    Sun Dec 22 00:44:27 2019 [31021] do_ifconfig, tt->ipv6=1, tt->did_ifconfig_ipv6_setup=1

    Sun Dec 22 00:44:27 2019 [31021] /bin/ip link set dev tun0 up mtu 1500

    Sun Dec 22 00:44:27 2019 [31021] /bin/ip addr add dev tun0 10.81.234.5/24 broadcast 10.81.234.255

    Sun Dec 22 00:44:27 2019 [31021] /bin/ip -6 addr add 2001:db8::1:0/64 dev tun0

    Sun Dec 22 00:44:27 2019 [31021] CSC service status updated to RUNNING

    Sun Dec 22 00:44:27 2019 [31021] Listening for incoming TCP connection on [undef]

    Sun Dec 22 00:44:27 2019 [31021] TCPv6_SERVER link local (bound): [undef]

    Sun Dec 22 00:44:27 2019 [31021] TCPv6_SERVER link remote: [undef]

    Sun Dec 22 00:44:27 2019 [31021] MULTI: multi_init called, r=256 v=256

    Sun Dec 22 00:44:27 2019 [31021] IFCONFIG POOL IPv6: (IPv4) size=50, size_ipv6=65536, netbits=64, base_ipv6=2001:db8::1:1

    Sun Dec 22 00:44:27 2019 [31021] IFCONFIG POOL: base=10.81.234.6 size=50, ipv6=1

    Sun Dec 22 00:44:27 2019 [31021] IFCONFIG POOL LIST

    Sun Dec 22 00:44:27 2019 [31021] MULTI: TCP INIT maxclients=5000 maxevents=5004

    Sun Dec 22 00:44:27 2019 [31021] Initialization Sequence Completed

    Sun Dec 22 01:18:07 2019 [31021] Closing TUN/TAP interface

    Sun Dec 22 01:18:07 2019 [31021] /bin/ip addr del dev tun0 10.81.234.5/24

    Sun Dec 22 01:18:07 2019 [31021] /bin/ip -6 addr del 2001:db8::1:0/64 dev tun0

    Sun Dec 22 01:18:07 2019 [31021] PLUGIN_CLOSE: /lib/openvpn-plugin-utm.so

    Sun Dec 22 01:18:07 2019 [31021] SIGTERM[hard,] received, process exiting

    Sun Dec 22 01:18:11 2019 [1488] OpenVPN 2.3.6 i486-openwrt-linux-gnu [SSL (OpenSSL)] [LZO] [EPOLL] [MH] [IPv6] built on Nov  1 2019

    Sun Dec 22 01:18:11 2019 [1488] library versions: OpenSSL 1.0.2k-fips  26 Jan 2017, LZO 2.09

    Sun Dec 22 01:18:11 2019 [1488] MANAGEMENT: client_uid=0

    Sun Dec 22 01:18:11 2019 [1488] MANAGEMENT: unix domain socket listening on /tmp/openvpn_mgmt

    /scripts/vpn/sslvpn/user-cleanup.sh: line 4: DELETE: not found

    Sun Dec 22 01:18:11 2019 [1488] cleanup success

    Sun Dec 22 01:18:11 2019 [1488] WARNING: using --duplicate-cn and --client-config-dir together is probably not what you want

    Sun Dec 22 01:18:11 2019 [1488] WARNING: --ifconfig-pool-persist will not work with --duplicate-cn

    Sun Dec 22 01:18:11 2019 [1488] NOTE: the current --script-security setting may allow this configuration to call user-defined scripts

    grhandle=0x8dd2270

    Authentication server 127.0.0.1 gave login response code 2

    Sun Dec 22 01:18:11 2019 [1488] PLUGIN_INIT: POST /lib/openvpn-plugin-utm.so '[/lib/openvpn-plugin-utm.so]' intercepted=PLUGIN_AUTH_USER_PASS_VERIFY|PLUGIN_CLIENT_CONNECT|PLUGIN_CLIENT_DISCONNECT

    Sun Dec 22 01:18:11 2019 [1488] Diffie-Hellman initialized with 2048 bit key

    Sun Dec 22 01:18:11 2019 [1488] WARNING: file '/conf/certificate/private/ApplianceCertificate.key' is group or others accessible

    Sun Dec 22 01:18:11 2019 [1488] WARNING: experimental option --capath /conf/certificate/openvpn

    Sun Dec 22 01:18:11 2019 [1488] Socket Buffers: R=[87380->131072] S=[16384->131072]

    Sun Dec 22 01:18:11 2019 [1488] TUN/TAP device tun0 opened

    Sun Dec 22 01:18:11 2019 [1488] TUN/TAP TX queue length set to 100

    Sun Dec 22 01:18:11 2019 [1488] do_ifconfig, tt->ipv6=1, tt->did_ifconfig_ipv6_setup=1

    Sun Dec 22 01:18:11 2019 [1488] /bin/ip link set dev tun0 up mtu 1500

    Sun Dec 22 01:18:11 2019 [1488] /bin/ip addr add dev tun0 10.81.234.5/24 broadcast 10.81.234.255

    Sun Dec 22 01:18:11 2019 [1488] /bin/ip -6 addr add 2001:db8::1:0/64 dev tun0

    Sun Dec 22 01:18:11 2019 [1488] CSC service status updated to RUNNING

    Sun Dec 22 01:18:11 2019 [1488] Listening for incoming TCP connection on [undef]

    Sun Dec 22 01:18:11 2019 [1488] TCPv6_SERVER link local (bound): [undef]

    Sun Dec 22 01:18:11 2019 [1488] TCPv6_SERVER link remote: [undef]

    Sun Dec 22 01:18:11 2019 [1488] MULTI: multi_init called, r=256 v=256

    Sun Dec 22 01:18:11 2019 [1488] IFCONFIG POOL IPv6: (IPv4) size=50, size_ipv6=65536, netbits=64, base_ipv6=2001:db8::1:1

    Sun Dec 22 01:18:11 2019 [1488] IFCONFIG POOL: base=10.81.234.6 size=50, ipv6=1

    Sun Dec 22 01:18:11 2019 [1488] IFCONFIG POOL LIST

    Sun Dec 22 01:18:11 2019 [1488] MULTI: TCP INIT maxclients=5000 maxevents=5004

    Sun Dec 22 01:18:11 2019 [1488] Initialization Sequence Completed

    Sun Dec 22 02:32:31 2019 [1488] TCP connection established with [AF_INET6]::ffff:139.162.116.230:52608

    Sun Dec 22 02:32:31 2019 [1488] ::ffff:139.162.116.230 WARNING: Bad encapsulated packet length from peer (18245), which must be > 0 and <= 1572 -- please ensure that --tun-mtu or --link-mtu is equal on both peers -- this condition could also indicate a possible active attack on the TCP link -- [Attempting restart...]

    Sun Dec 22 02:32:31 2019 [1488] ::ffff:139.162.116.230 Connection reset, restarting [0]

    Sun Dec 22 02:32:31 2019 [1488] ::ffff:139.162.116.230 SIGUSR1[soft,connection-reset] received, client-instance restarting

    Sun Dec 22 14:05:36 2019 [1488] Closing TUN/TAP interface

    Sun Dec 22 14:05:36 2019 [1488] /bin/ip addr del dev tun0 10.81.234.5/24

    Sun Dec 22 14:05:36 2019 [1488] /bin/ip -6 addr del 2001:db8::1:0/64 dev tun0

    Sun Dec 22 14:05:37 2019 [1488] PLUGIN_CLOSE: /lib/openvpn-plugin-utm.so

    Sun Dec 22 14:05:37 2019 [1488] SIGTERM[hard,] received, process exiting

    Sun Dec 22 14:05:41 2019 [32378] OpenVPN 2.3.6 i486-openwrt-linux-gnu [SSL (OpenSSL)] [LZO] [EPOLL] [MH] [IPv6] built on Nov  1 2019

    Sun Dec 22 14:05:41 2019 [32378] library versions: OpenSSL 1.0.2k-fips  26 Jan 2017, LZO 2.09

    Sun Dec 22 14:05:41 2019 [32378] MANAGEMENT: client_uid=0

    Sun Dec 22 14:05:41 2019 [32378] MANAGEMENT: unix domain socket listening on /tmp/openvpn_mgmt

    /scripts/vpn/sslvpn/user-cleanup.sh: line 4: DELETE: not found

    Sun Dec 22 14:05:41 2019 [32378] cleanup success

    Sun Dec 22 14:05:41 2019 [32378] WARNING: using --duplicate-cn and --client-config-dir together is probably not what you want

    Sun Dec 22 14:05:41 2019 [32378] WARNING: --ifconfig-pool-persist will not work with --duplicate-cn

    Sun Dec 22 14:05:41 2019 [32378] NOTE: the current --script-security setting may allow this configuration to call user-defined scripts

    grhandle=0x9ce9270

    Authentication server 127.0.0.1 gave login response code 2

    Sun Dec 22 14:05:41 2019 [32378] PLUGIN_INIT: POST /lib/openvpn-plugin-utm.so '[/lib/openvpn-plugin-utm.so]' intercepted=PLUGIN_AUTH_USER_PASS_VERIFY|PLUGIN_CLIENT_CONNECT|PLUGIN_CLIENT_DISCONNECT

    Sun Dec 22 14:05:41 2019 [32378] Diffie-Hellman initialized with 2048 bit key

    Sun Dec 22 14:05:41 2019 [32378] WARNING: file '/conf/certificate/private/ApplianceCertificate.key' is group or others accessible

    Sun Dec 22 14:05:41 2019 [32378] WARNING: experimental option --capath /conf/certificate/openvpn

    Sun Dec 22 14:05:41 2019 [32378] Socket Buffers: R=[87380->131072] S=[16384->131072]

    Sun Dec 22 14:05:41 2019 [32378] TUN/TAP device tun0 opened

    Sun Dec 22 14:05:41 2019 [32378] TUN/TAP TX queue length set to 100

    Sun Dec 22 14:05:41 2019 [32378] do_ifconfig, tt->ipv6=1, tt->did_ifconfig_ipv6_setup=1

    Sun Dec 22 14:05:41 2019 [32378] /bin/ip link set dev tun0 up mtu 1500

    Sun Dec 22 14:05:41 2019 [32378] /bin/ip addr add dev tun0 10.81.234.5/24 broadcast 10.81.234.255

    Sun Dec 22 14:05:41 2019 [32378] /bin/ip -6 addr add 2001:db8::1:0/64 dev tun0

    Sun Dec 22 14:05:41 2019 [32378] CSC service status updated to RUNNING

    Sun Dec 22 14:05:41 2019 [32378] Listening for incoming TCP connection on [undef]

    Sun Dec 22 14:05:41 2019 [32378] TCPv6_SERVER link local (bound): [undef]

    Sun Dec 22 14:05:41 2019 [32378] TCPv6_SERVER link remote: [undef]

    Sun Dec 22 14:05:41 2019 [32378] MULTI: multi_init called, r=256 v=256

    Sun Dec 22 14:05:41 2019 [32378] IFCONFIG POOL IPv6: (IPv4) size=50, size_ipv6=65536, netbits=64, base_ipv6=2001:db8::1:1

    Sun Dec 22 14:05:41 2019 [32378] IFCONFIG POOL: base=10.81.234.6 size=50, ipv6=1

    Sun Dec 22 14:05:41 2019 [32378] IFCONFIG POOL LIST

    Sun Dec 22 14:05:41 2019 [32378] MULTI: TCP INIT maxclients=5000 maxevents=5004

    Sun Dec 22 14:05:41 2019 [32378] Initialization Sequence Completed

    Sun Dec 22 14:07:48 2019 [32378] Closing TUN/TAP interface

    Sun Dec 22 14:07:48 2019 [32378] /bin/ip addr del dev tun0 10.81.234.5/24

    Sun Dec 22 14:07:48 2019 [32378] /bin/ip -6 addr del 2001:db8::1:0/64 dev tun0

    Sun Dec 22 14:07:48 2019 [32378] PLUGIN_CLOSE: /lib/openvpn-plugin-utm.so

    Sun Dec 22 14:07:48 2019 [32378] SIGTERM[hard,] received, process exiting

    Sun Dec 22 14:07:52 2019 [32678] OpenVPN 2.3.6 i486-openwrt-linux-gnu [SSL (OpenSSL)] [LZO] [EPOLL] [MH] [IPv6] built on Nov  1 2019

    Sun Dec 22 14:07:52 2019 [32678] library versions: OpenSSL 1.0.2k-fips  26 Jan 2017, LZO 2.09

    Sun Dec 22 14:07:52 2019 [32678] MANAGEMENT: client_uid=0

    Sun Dec 22 14:07:52 2019 [32678] MANAGEMENT: unix domain socket listening on /tmp/openvpn_mgmt

    /scripts/vpn/sslvpn/user-cleanup.sh: line 4: DELETE: not found

    Sun Dec 22 14:07:52 2019 [32678] cleanup success

    Sun Dec 22 14:07:52 2019 [32678] WARNING: using --duplicate-cn and --client-config-dir together is probably not what you want

    Sun Dec 22 14:07:52 2019 [32678] WARNING: --ifconfig-pool-persist will not work with --duplicate-cn

    Sun Dec 22 14:07:52 2019 [32678] NOTE: the current --script-security setting may allow this configuration to call user-defined scripts

    grhandle=0x84d2270

    Authentication server 127.0.0.1 gave login response code 2

    Sun Dec 22 14:07:52 2019 [32678] PLUGIN_INIT: POST /lib/openvpn-plugin-utm.so '[/lib/openvpn-plugin-utm.so]' intercepted=PLUGIN_AUTH_USER_PASS_VERIFY|PLUGIN_CLIENT_CONNECT|PLUGIN_CLIENT_DISCONNECT

    Sun Dec 22 14:07:52 2019 [32678] Diffie-Hellman initialized with 2048 bit key

    Sun Dec 22 14:07:52 2019 [32678] WARNING: file '/conf/certificate/private/ApplianceCertificate.key' is group or others accessible

    Sun Dec 22 14:07:52 2019 [32678] WARNING: experimental option --capath /conf/certificate/openvpn

    Sun Dec 22 14:07:52 2019 [32678] Socket Buffers: R=[87380->131072] S=[16384->131072]

    Sun Dec 22 14:07:52 2019 [32678] TUN/TAP device tun0 opened

    Sun Dec 22 14:07:52 2019 [32678] TUN/TAP TX queue length set to 100

    Sun Dec 22 14:07:52 2019 [32678] do_ifconfig, tt->ipv6=1, tt->did_ifconfig_ipv6_setup=1

    Sun Dec 22 14:07:52 2019 [32678] /bin/ip link set dev tun0 up mtu 1500

    Sun Dec 22 14:07:52 2019 [32678] /bin/ip addr add dev tun0 10.81.234.5/24 broadcast 10.81.234.255

    Sun Dec 22 14:07:52 2019 [32678] /bin/ip -6 addr add 2001:db8::1:0/64 dev tun0

    Sun Dec 22 14:07:52 2019 [32678] CSC service status updated to RUNNING

    Sun Dec 22 14:07:52 2019 [32678] Listening for incoming TCP connection on [undef]

    Sun Dec 22 14:07:52 2019 [32678] TCPv6_SERVER link local (bound): [undef]

    Sun Dec 22 14:07:52 2019 [32678] TCPv6_SERVER link remote: [undef]

    Sun Dec 22 14:07:52 2019 [32678] MULTI: multi_init called, r=256 v=256

    Sun Dec 22 14:07:52 2019 [32678] IFCONFIG POOL IPv6: (IPv4) size=50, size_ipv6=65536, netbits=64, base_ipv6=2001:db8::1:1

    Sun Dec 22 14:07:52 2019 [32678] IFCONFIG POOL: base=10.81.234.6 size=50, ipv6=1

    Sun Dec 22 14:07:52 2019 [32678] IFCONFIG POOL LIST

    Sun Dec 22 14:07:52 2019 [32678] MULTI: TCP INIT maxclients=5000 maxevents=5004

    Sun Dec 22 14:07:52 2019 [32678] Initialization Sequence Completed

    Sun Dec 22 15:04:28 2019 [32678] TCP connection established with [AF_INET6]::ffff:184.105.139.69:59512

    Sun Dec 22 15:04:28 2019 [32678] ::ffff:184.105.139.69 WARNING: Bad encapsulated packet length from peer (5635), which must be > 0 and <= 1572 -- please ensure that --tun-mtu or --link-mtu is equal on both peers -- this condition could also indicate a possible active attack on the TCP link -- [Attempting restart...]

    Sun Dec 22 15:04:28 2019 [32678] ::ffff:184.105.139.69 Connection reset, restarting [0]

    Sun Dec 22 15:04:28 2019 [32678] ::ffff:184.105.139.69 SIGUSR1[soft,connection-reset] received, client-instance restarting

    Sun Dec 22 17:54:24 2019 [32678] TCP connection established with [AF_INET6]::ffff:198.199.98.246:33023

    Sun Dec 22 17:54:24 2019 [32678] ::ffff:198.199.98.246 Connection reset, restarting [0]

    Sun Dec 22 17:54:24 2019 [32678] ::ffff:198.199.98.246 SIGUSR1[soft,connection-reset] received, client-instance restarting

    Sun Dec 22 18:14:55 2019 [32678] TCP connection established with [AF_INET6]::ffff:88.198.46.51:32932

    Sun Dec 22 18:14:55 2019 [32678] ::ffff:88.198.46.51 Connection reset, restarting [0]

    Sun Dec 22 18:14:55 2019 [32678] ::ffff:88.198.46.51 SIGUSR1[soft,connection-reset] received, client-instance restarting

    Sun Dec 22 18:15:21 2019 [32678] TCP connection established with [AF_INET6]::ffff:81.240.98.110:49766

    Sun Dec 22 18:15:21 2019 [32678] ::ffff:81.240.98.110 WARNING: Bad encapsulated packet length from peer (18245), which must be > 0 and <= 1572 -- please ensure that --tun-mtu or --link-mtu is equal on both peers -- this condition could also indicate a possible active attack on the TCP link -- [Attempting restart...]

    Sun Dec 22 18:15:21 2019 [32678] ::ffff:81.240.98.110 Connection reset, restarting [0]

    Sun Dec 22 18:15:21 2019 [32678] ::ffff:81.240.98.110 SIGUSR1[soft,connection-reset] received, client-instance restarting

    Sun Dec 22 18:15:21 2019 [32678] TCP connection established with [AF_INET6]::ffff:81.240.98.110:49768

    Sun Dec 22 18:15:21 2019 [32678] ::ffff:81.240.98.110 WARNING: Bad encapsulated packet length from peer (18245), which must be > 0 and <= 1572 -- please ensure that --tun-mtu or --link-mtu is equal on both peers -- this condition could also indicate a possible active attack on the TCP link -- [Attempting restart...]

    Sun Dec 22 18:15:21 2019 [32678] ::ffff:81.240.98.110 Connection reset, restarting [0]

    Sun Dec 22 18:15:21 2019 [32678] ::ffff:81.240.98.110 SIGUSR1[soft,connection-reset] received, client-instance restarting

    Sun Dec 22 18:15:24 2019 [32678] TCP connection established with [AF_INET6]::ffff:81.240.98.110:49770

    Sun Dec 22 18:15:24 2019 [32678] ::ffff:81.240.98.110 WARNING: Bad encapsulated packet length from peer (5635), which must be > 0 and <= 1572 -- please ensure that --tun-mtu or --link-mtu is equal on both peers -- this condition could also indicate a possible active attack on the TCP link -- [Attempting restart...]

    Sun Dec 22 18:15:24 2019 [32678] ::ffff:81.240.98.110 Connection reset, restarting [0]

    Sun Dec 22 18:15:24 2019 [32678] ::ffff:81.240.98.110 SIGUSR1[soft,connection-reset] received, client-instance restarting

    Sun Dec 22 18:15:26 2019 [32678] TCP connection established with [AF_INET6]::ffff:81.240.98.110:49773

    Sun Dec 22 18:15:26 2019 [32678] ::ffff:81.240.98.110 WARNING: Bad encapsulated packet length from peer (5635), which must be > 0 and <= 1572 -- please ensure that --tun-mtu or --link-mtu is equal on both peers -- this condition could also indicate a possible active attack on the TCP link -- [Attempting restart...]

    Sun Dec 22 18:15:26 2019 [32678] ::ffff:81.240.98.110 Connection reset, restarting [0]

    Sun Dec 22 18:15:26 2019 [32678] ::ffff:81.240.98.110 SIGUSR1[soft,connection-reset] received, client-instance restarting

    Sun Dec 22 18:15:27 2019 [32678] TCP connection established with [AF_INET6]::ffff:81.240.98.110:49775

    Sun Dec 22 18:15:27 2019 [32678] ::ffff:81.240.98.110 WARNING: Bad encapsulated packet length from peer (5635), which must be > 0 and <= 1572 -- please ensure that --tun-mtu or --link-mtu is equal on both peers -- this condition could also indicate a possible active attack on the TCP link -- [Attempting restart...]

    Sun Dec 22 18:15:27 2019 [32678] ::ffff:81.240.98.110 Connection reset, restarting [0]

    Sun Dec 22 18:15:27 2019 [32678] ::ffff:81.240.98.110 SIGUSR1[soft,connection-reset] received, client-instance restarting

    Sun Dec 22 18:15:28 2019 [32678] TCP connection established with [AF_INET6]::ffff:81.240.98.110:49777

    Sun Dec 22 18:15:28 2019 [32678] ::ffff:81.240.98.110 WARNING: Bad encapsulated packet length from peer (18245), which must be > 0 and <= 1572 -- please ensure that --tun-mtu or --link-mtu is equal on both peers -- this condition could also indicate a possible active attack on the TCP link -- [Attempting restart...]

    Sun Dec 22 18:15:28 2019 [32678] ::ffff:81.240.98.110 Connection reset, restarting [0]

    Sun Dec 22 18:15:28 2019 [32678] ::ffff:81.240.98.110 SIGUSR1[soft,connection-reset] received, client-instance restarting

    Sun Dec 22 18:15:29 2019 [32678] TCP connection established with [AF_INET6]::ffff:81.240.98.110:49779

    Sun Dec 22 18:15:29 2019 [32678] ::ffff:81.240.98.110 WARNING: Bad encapsulated packet length from peer (18245), which must be > 0 and <= 1572 -- please ensure that --tun-mtu or --link-mtu is equal on both peers -- this condition could also indicate a possible active attack on the TCP link -- [Attempting restart...]

    Sun Dec 22 18:15:29 2019 [32678] ::ffff:81.240.98.110 Connection reset, restarting [0]

    Sun Dec 22 18:15:29 2019 [32678] ::ffff:81.240.98.110 SIGUSR1[soft,connection-reset] received, client-instance restarting

    Sun Dec 22 18:15:29 2019 [32678] TCP connection established with [AF_INET6]::ffff:81.240.98.110:49781

    Sun Dec 22 18:15:29 2019 [32678] ::ffff:81.240.98.110 WARNING: Bad encapsulated packet length from peer (18245), which must be > 0 and <= 1572 -- please ensure that --tun-mtu or --link-mtu is equal on both peers -- this condition could also indicate a possible active attack on the TCP link -- [Attempting restart...]

    Sun Dec 22 18:15:29 2019 [32678] ::ffff:81.240.98.110 Connection reset, restarting [0]

    Sun Dec 22 18:15:29 2019 [32678] ::ffff:81.240.98.110 SIGUSR1[soft,connection-reset] received, client-instance restarting

    Sun Dec 22 18:15:35 2019 [32678] TCP connection established with [AF_INET6]::ffff:81.240.98.110:49784

    Sun Dec 22 18:15:35 2019 [32678] ::ffff:81.240.98.110 WARNING: Bad encapsulated packet length from peer (18245), which must be > 0 and <= 1572 -- please ensure that --tun-mtu or --link-mtu is equal on both peers -- this condition could also indicate a possible active attack on the TCP link -- [Attempting restart...]

    Sun Dec 22 18:15:35 2019 [32678] ::ffff:81.240.98.110 Connection reset, restarting [0]

    Sun Dec 22 18:15:35 2019 [32678] ::ffff:81.240.98.110 SIGUSR1[soft,connection-reset] received, client-instance restarting

    Sun Dec 22 18:23:26 2019 [32678] TCP connection established with [AF_INET6]::ffff:85.10.218.146:53644

    Sun Dec 22 18:23:28 2019 [32678] ::ffff:85.10.218.146 Connection reset, restarting [0]

    Sun Dec 22 18:23:28 2019 [32678] ::ffff:85.10.218.146 SIGUSR1[soft,connection-reset] received, client-instance restarting

    XG106_XN01_SFOS 17.5.9 MR-9#

  • I called a "senior sophos friend" and I made a user for him to test.

    He was able to connect to my network without any problem. 

    So i tried to connect through a hotspot from my mobile and it's working. 

    2019-12-22 18:47:39.495174 Initialization Sequence Completed

    2019-12-22 18:47:39.495237 MANAGEMENT: >STATE:1577036859,CONNECTED,SUCCESS,10.81.234.6,84.197.138.2,8443,172.20.10.11,53107

    This error took me 50 hours to solve lol :-D