OpenVPN3.0 (very old client) is not able to connect with OpenVPN Server 2.6.12 #340
Replies: 9 comments 3 replies
-
Try starting with making the configs simpler. Like removing the Also, the You must also ensure the |
Beta Was this translation helpful? Give feedback.
-
This must be an ancient client or something that is not OpenVPN Connect. Do you have a screenshot or exact name of that client? This is so old that from the IV_NCP, it does not even seem to support AES-GCM, ie it is even older than the 2.4 client you tested.
Hardcoding tls-cipher to one is probably a bad idea. |
Beta Was this translation helpful? Give feedback.
-
As suggested, I removed tls-cipher, tls-min-version, tls-timeout, and updated the comp-lzo option to compress migrate. Also verified tls-auth keys are same on server and ios client. I'm still not able to connect ios client to vpn server. The version of IOS client is openvpn 3.0, it too old :( I'm not clear, exactly which step is failing in TLS handshake. Also I tried to change cipher AES-256-CBC option to data-ciphers AES-256-GCM:AES-128-GCM:AES-256-CBC, however it failed. Any pointers will be really helpful here, my knowledge is very limited. The communication is encrypted it cant be analyzed using wireshark. Is there any way, to set any option to understand where it is failing. Can I turn off encryption or additional logging on client side. Please see the logs below server logs
client logs
|
Beta Was this translation helpful? Give feedback.
-
To be honest, it is very probably that you an OpenSSL update at the same time as the OpenVPN update and the newer OpenSSL version doesn't like your client. OpenSSL has gotten a lot strict in TLS standards than it used to be. You can also try |
Beta Was this translation helpful? Give feedback.
-
Are there any reasons you can't upgrade your Connect client to a newer version? https://apps.apple.com/us/app/openvpn-connect-openvpn-app/id590379981 |
Beta Was this translation helpful? Give feedback.
-
hi @schwabe , @dsommers, |
Beta Was this translation helpful? Give feedback.
-
Sharing further update, I'm able to connect to IOS client 3.0, VPN server 2.6.12 via TCP protocol. The server logs gave me clear information that no common cipher between client and server, so I modified the setting and it is connecting via tcp I'm still not able to connect via UDP, even after doing the changes in shared cipher. |
Beta Was this translation helpful? Give feedback.
-
and NOT setting tls-cipher |
Beta Was this translation helpful? Give feedback.
-
Hi @schwabe , @dsommers, thank you for help so far, sharing further update, |
Beta Was this translation helpful? Give feedback.
-
Hi team,
I'm new to OpenVPN, I have recently upgraded my openvpn server from 2.5.6. to 2.6.12
Post openvpn server upgrade, Android clients version 2.4 version (old), is able to connect to openvpn server 2.6.12.
However the IOS client (3.0) version is not able to connect to open vpn server anymore.
Sharing the client and server config config files and failure logs.
If i revert the openvpn server, the openvpn connection will start working.
I understand that openvpn client is very old, but it can still connect. I did not find any documentation that points to compatibility issue.
Please help, I'm stuck in this state from last one week.
server.conf
client.conf
Beta Was this translation helpful? Give feedback.
All reactions