Hi all, I have 2 astaro in HA configured with VPN SSL available to 50 users without problems except one of them.
The client is with Ubuntu 8.04 and openvpn 2.1_rc7 unique package available in the debian repos.
So, It's no possible to establish the connection in a right way, he connects but after 20 or 40 seconds of sending pings (for example) to one server the vpn hangs up, and the connection is lost.
I'm going to add log info to find help to the solution:
2008:08:15-22:13:54 (none) openvpn[19754]: MULTI: multi_create_instance called
2008:08:15-22:13:54 (none) openvpn[19754]: Re-using SSL/TLS context
2008:08:15-22:13:54 (none) openvpn[19754]: LZO compression initialized
2008:08:15-22:13:54 (none) openvpn[19754]: Control Channel MTU parms [ L:1556 D:140 EF:40 EB:0 ET:0 EL:0 ]
2008:08:15-22:13:54 (none) openvpn[19754]: Data Channel MTU parms [ L:1556 D:1450 EF:56 EB:135 ET:0 EL:0 AF:3/1 ]
2008:08:15-22:13:54 (none) openvpn[19754]: Local Options hash (VER=V4): 'a4f12474'
2008:08:15-22:13:54 (none) openvpn[19754]: Expected Remote Options hash (VER=V4): '619088b2'
2008:08:15-22:13:54 (none) openvpn[19754]: TCP connection established with *********X:60591
2008:08:15-22:13:54 (none) openvpn[19754]: Socket Buffers: R=[131072->131072] S=[131072->131072]
2008:08:15-22:13:54 (none) openvpn[19754]: TCPv4_SERVER link local: [undef]
2008:08:15-22:13:54 (none) openvpn[19754]: TCPv4_SERVER link remote: XX.XX.XX.XX:60591
2008:08:15-22:13:55 (none) openvpn[19754]: XX.XX.XX.XX:60591 TLS: Initial packet from XX.XX.XX.XX:60591, sid=06571082 c19a0ad3
2008:08:15-22:13:57 (none) openvpn[19754]: XX.XX.XX.XX:60591 VERIFY OK: depth=1,
PLUGIN_CALL: POST openvpn-auth-aua.so/PLUGIN_AUTH_USER_PASS_VERIFY status=0
2008:08:15-22:13:58 (none) openvpn[19754]: *********XX:60591 TLS: Username/Password authentication succeeded for username 'foobaar'
2008:08:15-22:13:58 (none) openvpn[19754]: *********X:60591 Data Channel Encrypt: Cipher 'AES-128-CBC' initialized with 128 bit key
2008:08:15-22:13:58 (none) openvpn[19754]: *********XX:60591 Data Channel Encrypt: Using 128 bit message hash 'MD5' for HMAC authentication
2008:08:15-22:13:58 (none) openvpn[19754]: *********X:60591 Data Channel Decrypt: Cipher 'AES-128-CBC' initialized with 128 bit key
2008:08:15-22:13:58 (none) openvpn[19754]: ************:60591 Data Channel Decrypt: Using 128 bit message hash 'MD5' for HMAC authentication
2008:08:15-22:13:58 (none) openvpn[19754]: *********X:60591 Control Channel: TLSv1, cipher TLSv1/SSLv3 DHE-RSA-AES256-SHA, 1024 bit RSA
2008:08:15-22:13:58 (none) openvpn[19754]: *********X:60591 [User_User] Peer Connection Initiated with *********XX:60591
2008:08:15-22:13:59 (none) openvpn[19754]: User_User/*********XX:60591 PLUGIN_CALL: POST openvpn-auth-aua.so/PLUGIN_CLIENT_CONNECT status=0
2008:08:15-22:13:59 (none) openvpn[19754]: user/*********X:60591 MULTI: Learn: 10.10.10.26 -> userrrr/******XX:60591
2008:08:15-22:13:59 (none) openvpn[19754]: Useerrrrr/******XX:60591 MULTI: primary virtual IP for User/*********X:60591: 10.10.10.26
2008:08:15-22:13:59 (none) openvpn[19754]: Useeeeeeeeeeer/************X:60591 PUSH: Received control message: 'PUSH_REQUEST'
2008:08:15-22:13:59 (none) openvpn[19754]: User/*********X:60591 SENT CONTROL [User]: 'PUSH_REPLY,ifconfig 10.10.10.26 10.10.10.25,ping-restart 120,ping 10,topology net30,route 10.10.10.1,dhcp-option DOMAIN mydomain.int,dhcp-option DNS 10.110.1.10,route 10.10.140.0 255.255.255.0,route 192.168.6.0 255.255.255.0,route 192.168.65.0 255.255.255.0,route 10.110.16.0 255.255.255.0,route 10.10.100.0 255.255.255.0,route 10.10.20.0 255.255.255.0,route 10.10.13.0 255.255.255.0,route 10.10.19.0 255.255.255.0,route 10.10.2.0 255.255.254.0' (status=1)
2008:08:15-22:14:23 (none) openvpn[19754]: User/*********X:60591 read TCPv4_SERVER []: No route to host (code=113)
2008:08:15-22:14:23 (none) openvpn[19754]: User/*********X:60591 read TCPv4_SERVER []: No route to host (code=113)
2008:08:15-22:14:23 (none) openvpn[19754]: User/*********X:60591 read TCPv4_SERVER []: No route to host (code=113)
2008:08:15-22:14:27 (none) openvpn[19754]: User/*********X:60591 read TCPv4_SERVER []: No route to host (code=113)
2008:08:15-22:14:27 (none) openvpn[19754]: User/*********X:60591 read TCPv4_SERVER []: No route to host (code=113)
2008:08:15-22:14:31 (none) openvpn[19754]: User/*********X:60591 read TCPv4_SERVER []: No route to host (code=113)
2008:08:15-22:14:31 (none) openvpn[19754]: User/*********X:60591 read TCPv4_SERVER []: No route to host (code=113)
2008:08:15-22:14:39 (none) openvpn[19754]: User/*********X:60591 read TCPv4_SERVER []: No route to host (code=113)
2008:08:15-22:14:39 (none) openvpn[19754]: User/*********X:60591 read TCPv4_SERVER []: No route to host (code=113)
2008:08:15-22:14:57 (none) openvpn[19754]: User/*********X:60591 read TCPv4_SERVER []: No route to host (code=113)
2008:08:15-22:14:57 (none) openvpn[19754]: User/*********X:60591 read TCPv4_SERVER []: No route to host (code=113)
2008:08:15-22:15:28 (none) openvpn[19754]: User/*********X:60591 Connection reset, restarting [-1]
2008:08:15-22:15:28 (none) openvpn[19754]: User/*********X:60591 SIGUSR1[soft,connection-reset] received, client-instance restarting
2008:08:15-22:15:29 (none) openvpn[19754]: PLUGIN_CALL: POST openvpn-auth-aua.so/PLUGIN_CLIENT_DISCONNECT status=0
2008:08:15-22:15:29 (none) openvpn[19754]: TCP/UDP: Closing socket
Any ideas? As I said previously the other 49 users had been connecting without problems.
Thanks in advance
This thread was automatically locked due to age.