OpenVPN / openvpn-gui

OpenVPN GUI is a graphical frontend for OpenVPN running on Windows 7 / 8 / 10. It creates an icon in the notification area from which you can control OpenVPN to start/stop your VPN tunnels, view the log and do other useful things.
Other
1.42k stars 400 forks source link

OpenVPN connects with errors on Windows 10 #380

Closed guicampos21 closed 3 years ago

guicampos21 commented 3 years ago

OpenVPN connects, receives the IP and other settings, but cannot apply to the adapter. Has anyone ever experienced this? Below is the log (with public ip hidden).

2020-11-11 08:50:28 DEPRECATED OPTION: ncp-disable. Disabling cipher negotiation is a deprecated debug feature that will be removed in OpenVPN 2.6 2020-11-11 08:50:28 DEPRECATED OPTION: --cipher set to 'AES-256-CBC' but missing in --data-ciphers (AES-256-GCM:AES-128-GCM). Future OpenVPN version will ignore --cipher for cipher negotiations. Add 'AES-256-CBC' to --data-ciphers or change --cipher 'AES-256-CBC' to --data-ciphers-fallback 'AES-256-CBC' to silence this warning. 2020-11-11 08:50:28 OpenVPN 2.5.0 x86_64-w64-mingw32 [SSL (OpenSSL)] [LZO] [LZ4] [PKCS11] [AEAD] built on Oct 28 2020 2020-11-11 08:50:28 Windows version 10.0 (Windows 10 or greater) 64bit 2020-11-11 08:50:28 library versions: OpenSSL 1.1.1h 22 Sep 2020, LZO 2.10 Enter Management Password: 2020-11-11 08:50:30 TCP/UDP: Preserving recently used remote address: [AF_INET]xxx.xx.51.58:1194 2020-11-11 08:50:30 UDPv4 link local (bound): [AF_INET][undef]:1194 2020-11-11 08:50:30 UDPv4 link remote: [AF_INET]xxx.xx.51.58:1194 2020-11-11 08:50:30 WARNING: this configuration may cache passwords in memory -- use the auth-nocache option to prevent this 2020-11-11 08:50:33 [CA-Server] Peer Connection Initiated with [AF_INET]xxx.xx.51.58:1194 2020-11-11 08:50:39 open_tun 2020-11-11 08:50:39 tap-windows6 device [OpenVPN TAP-Windows6] opened 2020-11-11 08:50:39 Notified TAP-Windows driver to set a DHCP IP/netmask of 10.230.231.162/255.255.255.252 on interface {96CA1981-12AB-4DCA-B616-CC9CB3243EE8} [DHCP-serv: 10.230.231.161, lease-time: 31536000] 2020-11-11 08:50:39 Successful ARP Flush on interface [47] {96CA1981-12AB-4DCA-B616-CC9CB3243EE8} 2020-11-11 08:50:39 IPv4 MTU set to 1500 on interface 47 using service 2020-11-11 08:51:14 Warning: route gateway is not reachable on any active network adapters: 10.230.231.161 2020-11-11 08:51:14 Warning: route gateway is not reachable on any active network adapters: 10.230.231.161 SYSTEM ROUTING TABLE 0.0.0.0 0.0.0.0 192.168.1.1 p=0 i=2 t=4 pr=3 a=142 h=0 m=311/0/0/0/0 127.0.0.0 255.0.0.0 127.0.0.1 p=0 i=1 t=3 pr=2 a=5852 h=0 m=331/0/0/0/0 127.0.0.1 255.255.255.255 127.0.0.1 p=0 i=1 t=3 pr=2 a=5852 h=0 m=331/0/0/0/0 127.255.255.255 255.255.255.255 127.0.0.1 p=0 i=1 t=3 pr=2 a=5852 h=0 m=331/0/0/0/0 169.254.0.0 255.255.0.0 169.254.175.120 p=0 i=47 t=3 pr=2 a=445 h=0 m=281/0/0/0/0 169.254.175.120 255.255.255.255 169.254.175.120 p=0 i=47 t=3 pr=2 a=445 h=0 m=281/0/0/0/0 169.254.255.255 255.255.255.255 169.254.175.120 p=0 i=47 t=3 pr=2 a=445 h=0 m=281/0/0/0/0 192.168.1.0 255.255.255.0 192.168.1.103 p=0 i=2 t=3 pr=2 a=139 h=0 m=311/0/0/0/0 192.168.1.103 255.255.255.255 192.168.1.103 p=0 i=2 t=3 pr=2 a=139 h=0 m=311/0/0/0/0 192.168.1.255 255.255.255.255 192.168.1.103 p=0 i=2 t=3 pr=2 a=139 h=0 m=311/0/0/0/0 224.0.0.0 240.0.0.0 127.0.0.1 p=0 i=1 t=3 pr=2 a=5852 h=0 m=331/0/0/0/0 224.0.0.0 240.0.0.0 192.168.1.103 p=0 i=2 t=3 pr=2 a=5845 h=0 m=311/0/0/0/0 224.0.0.0 240.0.0.0 169.254.175.120 p=0 i=47 t=3 pr=2 a=455 h=0 m=281/0/0/0/0 255.255.255.255 255.255.255.255 127.0.0.1 p=0 i=1 t=3 pr=2 a=5852 h=0 m=331/0/0/0/0 255.255.255.255 255.255.255.255 192.168.1.103 p=0 i=2 t=3 pr=2 a=5845 h=0 m=311/0/0/0/0 255.255.255.255 255.255.255.255 169.254.175.120 p=0 i=47 t=3 pr=2 a=455 h=0 m=281/0/0/0/0 SYSTEM ADAPTER LIST Wintun Userspace Tunnel Index = 46 GUID = {7E24FBA1-E7C9-4473-805E-F5237913F6CA} IP = 0.0.0.0/0.0.0.0 MAC = GATEWAY = 0.0.0.0/255.255.255.255 DNS SERV =
TAP-Windows Adapter V9 Index = 47 GUID = {96CA1981-12AB-4DCA-B616-CC9CB3243EE8} IP = 169.254.175.120/255.255.0.0 MAC = 00:ff:96:ca:19:81 GATEWAY = 0.0.0.0/255.255.255.255 DHCP SERV = 0.0.0.0/255.255.255.255 DHCP LEASE OBTAINED = 2020-11-11 08:51:14 DHCP LEASE EXPIRES = 2020-11-11 08:51:14 DNS SERV =
Qualcomm Atheros QCA9377 Wireless Network Adapter Index = 2 GUID = {00915C10-41BB-4DB1-B3BB-CEF0BDB10FF4} IP = 192.168.1.103/255.255.255.0 MAC = a4:63:a1:40:2f:95 GATEWAY = 192.168.1.1/255.255.255.255 DNS SERV = 8.8.8.8/255.255.255.255 8.8.4.4/255.255.255.255 Microsoft Wi-Fi Direct Virtual Adapter #3 Index = 16 GUID = {779EE08B-AC65-414D-8D7B-AFD167E99298} IP = 0.0.0.0/0.0.0.0 MAC = a6:63:a1:40:2f:95 GATEWAY = 0.0.0.0/255.255.255.255 DHCP SERV =
DHCP LEASE OBTAINED = 2020-11-11 08:51:14 DHCP LEASE EXPIRES = 2020-11-11 08:51:14 DNS SERV =
Microsoft Wi-Fi Direct Virtual Adapter #4 Index = 3 GUID = {05C6CC93-596D-4CA4-B584-616E01602341} IP = 0.0.0.0/0.0.0.0 MAC = b6:63:a1:40:2f:95 GATEWAY = 0.0.0.0/255.255.255.255 DHCP SERV =
DHCP LEASE OBTAINED = 2020-11-11 08:51:14 DHCP LEASE EXPIRES = 2020-11-11 08:51:14 DNS SERV =
2020-11-11 08:51:14 Initialization Sequence Completed With Errors ( see http://openvpn.net/faq.html#dhcpclientserv ) 2020-11-11 08:52:14 SIGTERM[hard,] received, process exiting

selvanair commented 3 years ago

OpenVPN is failing to set the tunnel IP via dhcp. As none of your adapters (including wifi) appears to have a dynamic IP, its possible that dhcp media sense is globally disabled. Check using netsh int ipv4 show global-- if disabled, enable it. Also, adding the option dhcp-renew to the config helps in some cases.

Logs at verb=4 could help.

guicampos21 commented 3 years ago

Good afternoon @selvanair ,

1- I ran the command netsh int ipv4 show global and the DHCP Media Sense was disabled. 2- Navigated to HKEY_LOCAL_MACHINE \ System \ CurrentControlSet \ Services \ Tcpip \ Parameters 3- Within Parameters I created an entry: Name: DisableDHCPMediaSense Data type: REG_DWORD Value: 0 4- After making changes, just save, restart the machine and connect to OpenVPN.

Reference: https://docs.microsoft.com/en-us/troubleshoot/windows-server/networking/disable-media-sensing-feature-for-tcpip

Thanks a lot for the help :)

OpenVPN is failing to set the tunnel IP via dhcp. As none of your adapters (including wifi) appears to have a dynamic IP, its possible that dhcp media sense is globally disabled. Check using netsh int ipv4 show global-- if disabled, enable it. Also, adding the option dhcp-renew to the config helps in some cases.

Logs at verb=4 could help.