Как решить проблему TLS Error OpenVPN
Собственно есть настроенный OpenVPN сервер. Сделал пачку файлов для 1 машины - все хорошо, работает. понадобилось сделать сертификаты для второй машины. все сделал, конфиг скопировал, попутно изменив пути к файлам.
Ну и подключение не происходит. Причем если начать подключаться по первой пачке ключей - подключается без проблем. Пробуешь по второй - TLS key negotiation failed to occur within 60 seconds (check your network connectivity)
Логи:
Fri Jan 11 23:55:02 2019 library versions: OpenSSL 1.1.0h 27 Mar 2018, LZO 2.10
Enter Management Password:
Fri Jan 11 23:55:02 2019 MANAGEMENT: TCP Socket listening on [AF_INET]127.0.0.1:25342
Fri Jan 11 23:55:02 2019 Need hold release from management interface, waiting...
Fri Jan 11 23:55:02 2019 MANAGEMENT: Client connected from [AF_INET]127.0.0.1:25342
Fri Jan 11 23:55:03 2019 MANAGEMENT: CMD 'state on'
Fri Jan 11 23:55:03 2019 MANAGEMENT: CMD 'log all on'
Fri Jan 11 23:55:03 2019 MANAGEMENT: CMD 'echo all on'
Fri Jan 11 23:55:03 2019 MANAGEMENT: CMD 'bytecount 5'
Fri Jan 11 23:55:03 2019 MANAGEMENT: CMD 'hold off'
Fri Jan 11 23:55:03 2019 MANAGEMENT: CMD 'hold release'
Fri Jan 11 23:55:03 2019 WARNING: --ns-cert-type is DEPRECATED. Use --remote-cert-tls instead.
Fri Jan 11 23:55:03 2019 WARNING: Your certificate is not yet valid!
Fri Jan 11 23:55:03 2019 Outgoing Control Channel Authentication: Using 160 bit message hash 'SHA1' for HMAC authentication
Fri Jan 11 23:55:03 2019 Incoming Control Channel Authentication: Using 160 bit message hash 'SHA1' for HMAC authentication
Fri Jan 11 23:55:03 2019 TCP/UDP: Preserving recently used remote address: [AF_INET]78.108.195.126:1194
Fri Jan 11 23:55:03 2019 Socket Buffers: R=[8192->8192] S=[8192->8192]
Fri Jan 11 23:55:03 2019 UDP link local: (not bound)
Fri Jan 11 23:55:03 2019 UDP link remote: [AF_INET]78.108.195.126:1194
Fri Jan 11 23:55:03 2019 MANAGEMENT: >STATE:1547236503,WAIT,,,,
Fri Jan 11 23:55:03 2019 MANAGEMENT: >STATE:1547236503,AUTH,,,,
Fri Jan 11 23:55:03 2019 TLS: Initial packet from [AF_INET]78.108.195.126:1194, sid=b241af7d ca58f1e3
Fri Jan 11 23:55:03 2019 VERIFY OK: depth=1, C=RU, ST=Moscow, L=Moscow, O=TKP, OU=TKPUnit, CN=TKP CA, name=Michail, emailAddress=notemail
Fri Jan 11 23:55:03 2019 VERIFY OK: nsCertType=SERVER
Fri Jan 11 23:55:03 2019 VERIFY OK: depth=0, C=RU, ST=Moscow, L=Moscow, O=TKP, OU=TKPUnit, CN=ServerTPK, name=EasyRSA, emailAddress=notemail
Fri Jan 11 23:56:03 2019 TLS Error: TLS key negotiation failed to occur within 60 seconds (check your network connectivity)
Fri Jan 11 23:56:03 2019 TLS Error: TLS handshake failed
Fri Jan 11 23:56:03 2019 SIGUSR1[soft,tls-error] received, process restarting
Fri Jan 11 23:56:03 2019 MANAGEMENT: >STATE:1547236563,RECONNECTING,tls-error,,,,
Fri Jan 11 23:56:03 2019 Restart pause, 5 second(s)
Sat Jan 12 00:55:57 2019 WARNING: --ns-cert-type is DEPRECATED. Use --remote-cert-tls instead.
Sat Jan 12 00:55:57 2019 TCP/UDP: Preserving recently used remote address: [AF_INET]78.108.195.126:1194
Sat Jan 12 00:55:57 2019 Socket Buffers: R=[8192->8192] S=[8192->8192]
Sat Jan 12 00:55:57 2019 UDP link local: (not bound)
Sat Jan 12 00:55:57 2019 UDP link remote: [AF_INET]78.108.195.126:1194
Sat Jan 12 00:55:57 2019 MANAGEMENT: >STATE:1547240157,WAIT,,,,
Sat Jan 12 00:55:57 2019 MANAGEMENT: >STATE:1547240157,AUTH,,,,
Sat Jan 12 00:55:57 2019 TLS: Initial packet from [AF_INET]78.108.195.126:1194, sid=fc9050ab 2f37416e
Sat Jan 12 00:55:57 2019 VERIFY OK: depth=1, C=RU, ST=Moscow, L=Moscow, O=TKP, OU=TKPUnit, CN=TKP CA, name=Michail, emailAddress=notemail
Sat Jan 12 00:55:57 2019 VERIFY OK: nsCertType=SERVER
Sat Jan 12 00:55:57 2019 VERIFY OK: depth=0, C=RU, ST=Moscow, L=Moscow, O=TKP, OU=TKPUnit, CN=ServerTPK, name=EasyRSA, emailAddress=notemail
. Маскарад или snat на сервере настроен? ip_forward включен