Important note about SSL VPN compatibility for 20.0 MR1 with EoL SFOS versions and UTM9 OS. Learn more in the release notes.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Public IP address needed in override hostname?

Hello Sophos community,

I bought a Sophos XG 106 for home use and to learn more about internet security. 

But now, I have a question about the VPN access from : https://community.sophos.com/kb/en-us/122769

I followed all steps but I was wondering what I have to type in the "override hostname" field?

Do i need to add here my public IP from my internet isp?

Cause when i try to connect with the vpn client I see this in the logs : 

Wed Dec 18 12:07:12 2019 Attempting to establish TCP connection with [AF_INET]84.197.138.2:8443 [nonblock]
Wed Dec 18 12:07:12 2019 MANAGEMENT: >STATE:1576667232,TCP_CONNECT,,,,,,
Wed Dec 18 12:07:22 2019 TCP: connect to [AF_INET]84.197.138.2:8443 failed, will try again in 5 seconds: The system tried to join a drive to a directory on a joined drive.
Wed Dec 18 12:07:27 2019 MANAGEMENT: >STATE:1576667247,TCP_CONNECT,,,,,,
Wed Dec 18 12:07:37 2019 TCP: connect to [AF_INET]84.197.138.2:8443 failed, will try again in 5 seconds: The system tried to join a drive to a directory on a joined drive.
Wed Dec 18 12:07:42 2019 MANAGEMENT: >STATE:1576667262,TCP_CONNECT,,,,,,
Wed Dec 18 12:07:52 2019 TCP: connect to [AF_INET]84.197.138.2:8443 failed, will try again in 5 seconds: The system tried to join a drive to a directory on a joined drive.
Wed Dec 18 12:07:57 2019 MANAGEMENT: >STATE:1576667277,TCP_CONNECT,,,,,,

So I can't seem to connect to my firewall through vpn, but i have no clue what's wrong with my current config.

Thanks a lot

regards

Frederiek



This thread was automatically locked due to age.
  • Frederiek Pascal said:
    2019-12-22 17:32:58.441161 MANAGEMENT: >STATE:1577032378,TCP_CONNECT,,,,,,

    After this, is it at least giving you: "failed, will try again in 5 seconds: Operation timed out" ?


    If a post solves your question use the 'Verify Answer' button.

    Ryzen 5600U + I226-V (KVM) v21 GA @ Home

    Sophos ZTNA (KVM) @ Home

  • If it is, can you SSH in to XG, go to advanced shell and give the output of "cat /log/sslvpn.log", if there's any errors in it then post it here, of course if there is it's better to wait for a sophos dev to answer, if there isn't It seems a problem when establishing the connection with XG.

    A good thing you can do, If your ISP router supports, and you don't have a special use for it, it's putting in bridge and authenticating with XG.


    If a post solves your question use the 'Verify Answer' button.

    Ryzen 5600U + I226-V (KVM) v21 GA @ Home

    Sophos ZTNA (KVM) @ Home

  • hello,

    here ya go :-)

     

     

    XG106_XN01_SFOS 17.5.9 MR-9# cat /log/sslvpn.log

    Wed Dec 18 11:32:55 2019 [5140] OpenVPN 2.3.6 i486-openwrt-linux-gnu [SSL (OpenSSL)] [LZO] [EPOLL] [MH] [IPv6] built on Nov  1 2019

    Wed Dec 18 11:32:55 2019 [5140] library versions: OpenSSL 1.0.2k-fips  26 Jan 2017, LZO 2.09

    Wed Dec 18 11:32:55 2019 [5140] MANAGEMENT: client_uid=0

    Wed Dec 18 11:32:55 2019 [5140] MANAGEMENT: unix domain socket listening on /tmp/openvpn_mgmt

    /scripts/vpn/sslvpn/user-cleanup.sh: line 4: DELETE: not found

    Wed Dec 18 11:32:55 2019 [5140] cleanup success

    Wed Dec 18 11:32:55 2019 [5140] WARNING: using --duplicate-cn and --client-config-dir together is probably not what you want

    Wed Dec 18 11:32:55 2019 [5140] WARNING: --ifconfig-pool-persist will not work with --duplicate-cn

    Wed Dec 18 11:32:55 2019 [5140] NOTE: the current --script-security setting may allow this configuration to call user-defined scripts

    grhandle=0x8322270

    Authentication server 127.0.0.1 gave login response code 2

    Wed Dec 18 11:32:55 2019 [5140] PLUGIN_INIT: POST /lib/openvpn-plugin-utm.so '[/lib/openvpn-plugin-utm.so]' intercepted=PLUGIN_AUTH_USER_PASS_VERIFY|PLUGIN_CLIENT_CONNECT|PLUGIN_CLIENT_DISCONNECT

    Wed Dec 18 11:32:55 2019 [5140] Diffie-Hellman initialized with 2048 bit key

    Wed Dec 18 11:32:55 2019 [5140] WARNING: file '/conf/certificate/private/ApplianceCertificate.key' is group or others accessible

    Wed Dec 18 11:32:55 2019 [5140] WARNING: experimental option --capath /conf/certificate/openvpn

    Wed Dec 18 11:32:55 2019 [5140] Socket Buffers: R=[87380->131072] S=[16384->131072]

    Wed Dec 18 11:32:55 2019 [5140] TUN/TAP device tun0 opened

    Wed Dec 18 11:32:55 2019 [5140] TUN/TAP TX queue length set to 100

    Wed Dec 18 11:32:55 2019 [5140] do_ifconfig, tt->ipv6=1, tt->did_ifconfig_ipv6_setup=1

    Wed Dec 18 11:32:55 2019 [5140] /bin/ip link set dev tun0 up mtu 1500

    Wed Dec 18 11:32:55 2019 [5140] /bin/ip addr add dev tun0 10.81.234.5/24 broadcast 10.81.234.255

    Wed Dec 18 11:32:55 2019 [5140] /bin/ip -6 addr add 2001:db8::1:0/64 dev tun0

    Wed Dec 18 11:32:55 2019 [5140] CSC service status updated to RUNNING

    Wed Dec 18 11:32:55 2019 [5140] Listening for incoming TCP connection on [undef]

    Wed Dec 18 11:32:55 2019 [5140] TCPv6_SERVER link local (bound): [undef]

    Wed Dec 18 11:32:55 2019 [5140] TCPv6_SERVER link remote: [undef]

    Wed Dec 18 11:32:55 2019 [5140] MULTI: multi_init called, r=256 v=256

    Wed Dec 18 11:32:55 2019 [5140] IFCONFIG POOL IPv6: (IPv4) size=50, size_ipv6=65536, netbits=64, base_ipv6=2001:db8::1:1

    Wed Dec 18 11:32:55 2019 [5140] IFCONFIG POOL: base=10.81.234.6 size=50, ipv6=1

    Wed Dec 18 11:32:55 2019 [5140] IFCONFIG POOL LIST

    Wed Dec 18 11:32:55 2019 [5140] MULTI: TCP INIT maxclients=5000 maxevents=5004

    Wed Dec 18 11:32:55 2019 [5140] Initialization Sequence Completed

    Wed Dec 18 11:36:28 2019 [5140] Closing TUN/TAP interface

    Wed Dec 18 11:36:28 2019 [5140] /bin/ip addr del dev tun0 10.81.234.5/24

    Wed Dec 18 11:36:28 2019 [5140] /bin/ip -6 addr del 2001:db8::1:0/64 dev tun0

    Wed Dec 18 11:36:28 2019 [5140] PLUGIN_CLOSE: /lib/openvpn-plugin-utm.so

    Wed Dec 18 11:36:28 2019 [5140] SIGTERM[hard,] received, process exiting

    Wed Dec 18 11:36:32 2019 [5708] OpenVPN 2.3.6 i486-openwrt-linux-gnu [SSL (OpenSSL)] [LZO] [EPOLL] [MH] [IPv6] built on Nov  1 2019

    Wed Dec 18 11:36:32 2019 [5708] library versions: OpenSSL 1.0.2k-fips  26 Jan 2017, LZO 2.09

    Wed Dec 18 11:36:32 2019 [5708] MANAGEMENT: client_uid=0

    Wed Dec 18 11:36:32 2019 [5708] MANAGEMENT: unix domain socket listening on /tmp/openvpn_mgmt

    /scripts/vpn/sslvpn/user-cleanup.sh: line 4: DELETE: not found

    Wed Dec 18 11:36:32 2019 [5708] cleanup success

    Wed Dec 18 11:36:32 2019 [5708] WARNING: using --duplicate-cn and --client-config-dir together is probably not what you want

    Wed Dec 18 11:36:32 2019 [5708] WARNING: --ifconfig-pool-persist will not work with --duplicate-cn

    Wed Dec 18 11:36:32 2019 [5708] NOTE: the current --script-security setting may allow this configuration to call user-defined scripts

    grhandle=0x9658270

    Authentication server 127.0.0.1 gave login response code 2

    Wed Dec 18 11:36:32 2019 [5708] PLUGIN_INIT: POST /lib/openvpn-plugin-utm.so '[/lib/openvpn-plugin-utm.so]' intercepted=PLUGIN_AUTH_USER_PASS_VERIFY|PLUGIN_CLIENT_CONNECT|PLUGIN_CLIENT_DISCONNECT

    Wed Dec 18 11:36:32 2019 [5708] Diffie-Hellman initialized with 2048 bit key

    Wed Dec 18 11:36:32 2019 [5708] WARNING: file '/conf/certificate/private/ApplianceCertificate.key' is group or others accessible

    Wed Dec 18 11:36:32 2019 [5708] WARNING: experimental option --capath /conf/certificate/openvpn

    Wed Dec 18 11:36:32 2019 [5708] Socket Buffers: R=[87380->131072] S=[16384->131072]

    Wed Dec 18 11:36:32 2019 [5708] TUN/TAP device tun0 opened

    Wed Dec 18 11:36:32 2019 [5708] TUN/TAP TX queue length set to 100

    Wed Dec 18 11:36:32 2019 [5708] do_ifconfig, tt->ipv6=1, tt->did_ifconfig_ipv6_setup=1

    Wed Dec 18 11:36:32 2019 [5708] /bin/ip link set dev tun0 up mtu 1500

    Wed Dec 18 11:36:32 2019 [5708] /bin/ip addr add dev tun0 10.81.234.5/24 broadcast 10.81.234.255

    Wed Dec 18 11:36:32 2019 [5708] /bin/ip -6 addr add 2001:db8::1:0/64 dev tun0

    Wed Dec 18 11:36:32 2019 [5708] CSC service status updated to RUNNING

    Wed Dec 18 11:36:32 2019 [5708] Listening for incoming TCP connection on [undef]

    Wed Dec 18 11:36:32 2019 [5708] TCPv6_SERVER link local (bound): [undef]

    Wed Dec 18 11:36:32 2019 [5708] TCPv6_SERVER link remote: [undef]

    Wed Dec 18 11:36:32 2019 [5708] MULTI: multi_init called, r=256 v=256

    Wed Dec 18 11:36:32 2019 [5708] IFCONFIG POOL IPv6: (IPv4) size=50, size_ipv6=65536, netbits=64, base_ipv6=2001:db8::1:1

    Wed Dec 18 11:36:32 2019 [5708] IFCONFIG POOL: base=10.81.234.6 size=50, ipv6=1

    Wed Dec 18 11:36:32 2019 [5708] IFCONFIG POOL LIST

    Wed Dec 18 11:36:32 2019 [5708] MULTI: TCP INIT maxclients=5000 maxevents=5004

    Wed Dec 18 11:36:32 2019 [5708] Initialization Sequence Completed

    Wed Dec 18 11:59:34 2019 [5708] Closing TUN/TAP interface

    Wed Dec 18 11:59:34 2019 [5708] /bin/ip addr del dev tun0 10.81.234.5/24

    Wed Dec 18 11:59:34 2019 [5708] /bin/ip -6 addr del 2001:db8::1:0/64 dev tun0

    Wed Dec 18 11:59:34 2019 [5708] PLUGIN_CLOSE: /lib/openvpn-plugin-utm.so

    Wed Dec 18 11:59:34 2019 [5708] SIGTERM[hard,] received, process exiting

    Wed Dec 18 11:59:38 2019 [9123] OpenVPN 2.3.6 i486-openwrt-linux-gnu [SSL (OpenSSL)] [LZO] [EPOLL] [MH] [IPv6] built on Nov  1 2019

    Wed Dec 18 11:59:38 2019 [9123] library versions: OpenSSL 1.0.2k-fips  26 Jan 2017, LZO 2.09

    Wed Dec 18 11:59:38 2019 [9123] MANAGEMENT: client_uid=0

    Wed Dec 18 11:59:38 2019 [9123] MANAGEMENT: unix domain socket listening on /tmp/openvpn_mgmt

    /scripts/vpn/sslvpn/user-cleanup.sh: line 4: DELETE: not found

    Wed Dec 18 11:59:38 2019 [9123] cleanup success

    Wed Dec 18 11:59:38 2019 [9123] WARNING: using --duplicate-cn and --client-config-dir together is probably not what you want

    Wed Dec 18 11:59:38 2019 [9123] WARNING: --ifconfig-pool-persist will not work with --duplicate-cn

    Wed Dec 18 11:59:38 2019 [9123] NOTE: the current --script-security setting may allow this configuration to call user-defined scripts

    grhandle=0x823f270

    Authentication server 127.0.0.1 gave login response code 2

    Wed Dec 18 11:59:38 2019 [9123] PLUGIN_INIT: POST /lib/openvpn-plugin-utm.so '[/lib/openvpn-plugin-utm.so]' intercepted=PLUGIN_AUTH_USER_PASS_VERIFY|PLUGIN_CLIENT_CONNECT|PLUGIN_CLIENT_DISCONNECT

    Wed Dec 18 11:59:38 2019 [9123] Diffie-Hellman initialized with 2048 bit key

    Wed Dec 18 11:59:38 2019 [9123] WARNING: file '/conf/certificate/private/ApplianceCertificate.key' is group or others accessible

    Wed Dec 18 11:59:38 2019 [9123] WARNING: experimental option --capath /conf/certificate/openvpn

    Wed Dec 18 11:59:38 2019 [9123] Socket Buffers: R=[87380->131072] S=[16384->131072]

    Wed Dec 18 11:59:38 2019 [9123] TUN/TAP device tun0 opened

    Wed Dec 18 11:59:38 2019 [9123] TUN/TAP TX queue length set to 100

    Wed Dec 18 11:59:38 2019 [9123] do_ifconfig, tt->ipv6=1, tt->did_ifconfig_ipv6_setup=1

    Wed Dec 18 11:59:38 2019 [9123] /bin/ip link set dev tun0 up mtu 1500

    Wed Dec 18 11:59:38 2019 [9123] /bin/ip addr add dev tun0 10.81.234.5/24 broadcast 10.81.234.255

    Wed Dec 18 11:59:38 2019 [9123] /bin/ip -6 addr add 2001:db8::1:0/64 dev tun0

    Wed Dec 18 11:59:38 2019 [9123] CSC service status updated to RUNNING

    Wed Dec 18 11:59:38 2019 [9123] Listening for incoming TCP connection on [undef]

    Wed Dec 18 11:59:38 2019 [9123] TCPv6_SERVER link local (bound): [undef]

    Wed Dec 18 11:59:38 2019 [9123] TCPv6_SERVER link remote: [undef]

    Wed Dec 18 11:59:38 2019 [9123] MULTI: multi_init called, r=256 v=256

    Wed Dec 18 11:59:38 2019 [9123] IFCONFIG POOL IPv6: (IPv4) size=50, size_ipv6=65536, netbits=64, base_ipv6=2001:db8::1:1

    Wed Dec 18 11:59:38 2019 [9123] IFCONFIG POOL: base=10.81.234.6 size=50, ipv6=1

    Wed Dec 18 11:59:38 2019 [9123] IFCONFIG POOL LIST

    Wed Dec 18 11:59:38 2019 [9123] MULTI: TCP INIT maxclients=5000 maxevents=5004

    Wed Dec 18 11:59:38 2019 [9123] Initialization Sequence Completed

    Wed Dec 18 12:05:22 2019 [9123] Closing TUN/TAP interface

    Wed Dec 18 12:05:22 2019 [9123] /bin/ip addr del dev tun0 10.81.234.5/24

    Wed Dec 18 12:05:22 2019 [9123] /bin/ip -6 addr del 2001:db8::1:0/64 dev tun0

    Wed Dec 18 12:05:22 2019 [9123] PLUGIN_CLOSE: /lib/openvpn-plugin-utm.so

    Wed Dec 18 12:05:22 2019 [9123] SIGTERM[hard,] received, process exiting

    Wed Dec 18 12:05:26 2019 [9654] OpenVPN 2.3.6 i486-openwrt-linux-gnu [SSL (OpenSSL)] [LZO] [EPOLL] [MH] [IPv6] built on Nov  1 2019

    Wed Dec 18 12:05:26 2019 [9654] library versions: OpenSSL 1.0.2k-fips  26 Jan 2017, LZO 2.09

    Wed Dec 18 12:05:26 2019 [9654] MANAGEMENT: client_uid=0

    Wed Dec 18 12:05:26 2019 [9654] MANAGEMENT: unix domain socket listening on /tmp/openvpn_mgmt

    /scripts/vpn/sslvpn/user-cleanup.sh: line 4: DELETE: not found

    Wed Dec 18 12:05:26 2019 [9654] cleanup success

    Wed Dec 18 12:05:26 2019 [9654] WARNING: using --duplicate-cn and --client-config-dir together is probably not what you want

    Wed Dec 18 12:05:26 2019 [9654] WARNING: --ifconfig-pool-persist will not work with --duplicate-cn

    Wed Dec 18 12:05:26 2019 [9654] NOTE: the current --script-security setting may allow this configuration to call user-defined scripts

    grhandle=0x9355270

    Authentication server 127.0.0.1 gave login response code 2

    Wed Dec 18 12:05:26 2019 [9654] PLUGIN_INIT: POST /lib/openvpn-plugin-utm.so '[/lib/openvpn-plugin-utm.so]' intercepted=PLUGIN_AUTH_USER_PASS_VERIFY|PLUGIN_CLIENT_CONNECT|PLUGIN_CLIENT_DISCONNECT

    Wed Dec 18 12:05:26 2019 [9654] Diffie-Hellman initialized with 2048 bit key

    Wed Dec 18 12:05:26 2019 [9654] WARNING: file '/conf/certificate/private/ApplianceCertificate.key' is group or others accessible

    Wed Dec 18 12:05:26 2019 [9654] WARNING: experimental option --capath /conf/certificate/openvpn

    Wed Dec 18 12:05:26 2019 [9654] Socket Buffers: R=[87380->131072] S=[16384->131072]

    Wed Dec 18 12:05:26 2019 [9654] TUN/TAP device tun0 opened

    Wed Dec 18 12:05:26 2019 [9654] TUN/TAP TX queue length set to 100

    Wed Dec 18 12:05:26 2019 [9654] do_ifconfig, tt->ipv6=1, tt->did_ifconfig_ipv6_setup=1

    Wed Dec 18 12:05:26 2019 [9654] /bin/ip link set dev tun0 up mtu 1500

    Wed Dec 18 12:05:26 2019 [9654] /bin/ip addr add dev tun0 10.81.234.5/24 broadcast 10.81.234.255

    Wed Dec 18 12:05:26 2019 [9654] /bin/ip -6 addr add 2001:db8::1:0/64 dev tun0

    Wed Dec 18 12:05:26 2019 [9654] CSC service status updated to RUNNING

    Wed Dec 18 12:05:26 2019 [9654] Listening for incoming TCP connection on [undef]

    Wed Dec 18 12:05:26 2019 [9654] TCPv6_SERVER link local (bound): [undef]

    Wed Dec 18 12:05:26 2019 [9654] TCPv6_SERVER link remote: [undef]

    Wed Dec 18 12:05:26 2019 [9654] MULTI: multi_init called, r=256 v=256

    Wed Dec 18 12:05:26 2019 [9654] IFCONFIG POOL IPv6: (IPv4) size=50, size_ipv6=65536, netbits=64, base_ipv6=2001:db8::1:1

    Wed Dec 18 12:05:26 2019 [9654] IFCONFIG POOL: base=10.81.234.6 size=50, ipv6=1

    Wed Dec 18 12:05:26 2019 [9654] IFCONFIG POOL LIST

    Wed Dec 18 12:05:26 2019 [9654] MULTI: TCP INIT maxclients=5000 maxevents=5004

    Wed Dec 18 12:05:26 2019 [9654] Initialization Sequence Completed

    Wed Dec 18 12:08:06 2019 [9654] Closing TUN/TAP interface

    Wed Dec 18 12:08:06 2019 [9654] /bin/ip addr del dev tun0 10.81.234.5/24

    Wed Dec 18 12:08:06 2019 [9654] /bin/ip -6 addr del 2001:db8::1:0/64 dev tun0

    Wed Dec 18 12:08:06 2019 [9654] PLUGIN_CLOSE: /lib/openvpn-plugin-utm.so

    Wed Dec 18 12:08:06 2019 [9654] SIGTERM[hard,] received, process exiting

    Wed Dec 18 12:08:10 2019 [10009] OpenVPN 2.3.6 i486-openwrt-linux-gnu [SSL (OpenSSL)] [LZO] [EPOLL] [MH] [IPv6] built on Nov  1 2019

    Wed Dec 18 12:08:10 2019 [10009] library versions: OpenSSL 1.0.2k-fips  26 Jan 2017, LZO 2.09

    Wed Dec 18 12:08:10 2019 [10009] MANAGEMENT: client_uid=0

    Wed Dec 18 12:08:10 2019 [10009] MANAGEMENT: unix domain socket listening on /tmp/openvpn_mgmt

    /scripts/vpn/sslvpn/user-cleanup.sh: line 4: DELETE: not found

    Wed Dec 18 12:08:10 2019 [10009] cleanup success

    Wed Dec 18 12:08:10 2019 [10009] WARNING: using --duplicate-cn and --client-config-dir together is probably not what you want

    Wed Dec 18 12:08:10 2019 [10009] WARNING: --ifconfig-pool-persist will not work with --duplicate-cn

    Wed Dec 18 12:08:10 2019 [10009] NOTE: the current --script-security setting may allow this configuration to call user-defined scripts

    grhandle=0x8128270

    Authentication server 127.0.0.1 gave login response code 2

    Wed Dec 18 12:08:10 2019 [10009] PLUGIN_INIT: POST /lib/openvpn-plugin-utm.so '[/lib/openvpn-plugin-utm.so]' intercepted=PLUGIN_AUTH_USER_PASS_VERIFY|PLUGIN_CLIENT_CONNECT|PLUGIN_CLIENT_DISCONNECT

    Wed Dec 18 12:08:10 2019 [10009] Diffie-Hellman initialized with 2048 bit key

    Wed Dec 18 12:08:10 2019 [10009] WARNING: file '/conf/certificate/private/ApplianceCertificate.key' is group or others accessible

    Wed Dec 18 12:08:10 2019 [10009] WARNING: experimental option --capath /conf/certificate/openvpn

    Wed Dec 18 12:08:10 2019 [10009] Socket Buffers: R=[87380->131072] S=[16384->131072]

    Wed Dec 18 12:08:10 2019 [10009] TUN/TAP device tun0 opened

    Wed Dec 18 12:08:10 2019 [10009] TUN/TAP TX queue length set to 100

    Wed Dec 18 12:08:10 2019 [10009] do_ifconfig, tt->ipv6=1, tt->did_ifconfig_ipv6_setup=1

    Wed Dec 18 12:08:10 2019 [10009] /bin/ip link set dev tun0 up mtu 1500

    Wed Dec 18 12:08:10 2019 [10009] /bin/ip addr add dev tun0 10.81.234.5/24 broadcast 10.81.234.255

    Wed Dec 18 12:08:10 2019 [10009] /bin/ip -6 addr add 2001:db8::1:0/64 dev tun0

    Wed Dec 18 12:08:10 2019 [10009] CSC service status updated to RUNNING

    Wed Dec 18 12:08:10 2019 [10009] Listening for incoming TCP connection on [undef]

    Wed Dec 18 12:08:10 2019 [10009] TCPv6_SERVER link local (bound): [undef]

    Wed Dec 18 12:08:10 2019 [10009] TCPv6_SERVER link remote: [undef]

    Wed Dec 18 12:08:10 2019 [10009] MULTI: multi_init called, r=256 v=256

    Wed Dec 18 12:08:10 2019 [10009] IFCONFIG POOL IPv6: (IPv4) size=50, size_ipv6=65536, netbits=64, base_ipv6=2001:db8::1:1

    Wed Dec 18 12:08:10 2019 [10009] IFCONFIG POOL: base=10.81.234.6 size=50, ipv6=1

    Wed Dec 18 12:08:10 2019 [10009] IFCONFIG POOL LIST

    Wed Dec 18 12:08:10 2019 [10009] MULTI: TCP INIT maxclients=5000 maxevents=5004

    Wed Dec 18 12:08:10 2019 [10009] Initialization Sequence Completed

    Wed Dec 18 13:16:18 2019 [10009] Closing TUN/TAP interface

    Wed Dec 18 13:16:18 2019 [10009] /bin/ip addr del dev tun0 10.81.234.5/24

    Wed Dec 18 13:16:18 2019 [10009] /bin/ip -6 addr del 2001:db8::1:0/64 dev tun0

    Wed Dec 18 13:16:18 2019 [10009] PLUGIN_CLOSE: /lib/openvpn-plugin-utm.so

    Wed Dec 18 13:16:18 2019 [10009] SIGTERM[hard,] received, process exiting

    Wed Dec 18 13:16:22 2019 [15707] OpenVPN 2.3.6 i486-openwrt-linux-gnu [SSL (OpenSSL)] [LZO] [EPOLL] [MH] [IPv6] built on Nov  1 2019

    Wed Dec 18 13:16:22 2019 [15707] library versions: OpenSSL 1.0.2k-fips  26 Jan 2017, LZO 2.09

    Wed Dec 18 13:16:22 2019 [15707] MANAGEMENT: client_uid=0

    Wed Dec 18 13:16:22 2019 [15707] MANAGEMENT: unix domain socket listening on /tmp/openvpn_mgmt

    /scripts/vpn/sslvpn/user-cleanup.sh: line 4: DELETE: not found

    Wed Dec 18 13:16:22 2019 [15707] cleanup success

    Wed Dec 18 13:16:22 2019 [15707] WARNING: using --duplicate-cn and --client-config-dir together is probably not what you want

    Wed Dec 18 13:16:22 2019 [15707] WARNING: --ifconfig-pool-persist will not work with --duplicate-cn

    Wed Dec 18 13:16:22 2019 [15707] NOTE: the current --script-security setting may allow this configuration to call user-defined scripts

    grhandle=0x8e45270

    Authentication server 127.0.0.1 gave login response code 2

    Wed Dec 18 13:16:22 2019 [15707] PLUGIN_INIT: POST /lib/openvpn-plugin-utm.so '[/lib/openvpn-plugin-utm.so]' intercepted=PLUGIN_AUTH_USER_PASS_VERIFY|PLUGIN_CLIENT_CONNECT|PLUGIN_CLIENT_DISCONNECT

    Wed Dec 18 13:16:22 2019 [15707] Diffie-Hellman initialized with 2048 bit key

    Wed Dec 18 13:16:22 2019 [15707] WARNING: file '/conf/certificate/private/ApplianceCertificate.key' is group or others accessible

    Wed Dec 18 13:16:22 2019 [15707] WARNING: experimental option --capath /conf/certificate/openvpn

    Wed Dec 18 13:16:22 2019 [15707] Socket Buffers: R=[87380->131072] S=[16384->131072]

    Wed Dec 18 13:16:22 2019 [15707] TUN/TAP device tun0 opened

    Wed Dec 18 13:16:22 2019 [15707] TUN/TAP TX queue length set to 100

    Wed Dec 18 13:16:22 2019 [15707] do_ifconfig, tt->ipv6=1, tt->did_ifconfig_ipv6_setup=1

    Wed Dec 18 13:16:22 2019 [15707] /bin/ip link set dev tun0 up mtu 1500

    Wed Dec 18 13:16:22 2019 [15707] /bin/ip addr add dev tun0 10.81.234.5/24 broadcast 10.81.234.255

    Wed Dec 18 13:16:22 2019 [15707] /bin/ip -6 addr add 2001:db8::1:0/64 dev tun0

    Wed Dec 18 13:16:22 2019 [15707] CSC service status updated to RUNNING

    Wed Dec 18 13:16:22 2019 [15707] Listening for incoming TCP connection on [undef]

    Wed Dec 18 13:16:22 2019 [15707] TCPv6_SERVER link local (bound): [undef]

    Wed Dec 18 13:16:22 2019 [15707] TCPv6_SERVER link remote: [undef]

    Wed Dec 18 13:16:22 2019 [15707] MULTI: multi_init called, r=256 v=256

    Wed Dec 18 13:16:22 2019 [15707] IFCONFIG POOL IPv6: (IPv4) size=50, size_ipv6=65536, netbits=64, base_ipv6=2001:db8::1:1

    Wed Dec 18 13:16:22 2019 [15707] IFCONFIG POOL: base=10.81.234.6 size=50, ipv6=1

    Wed Dec 18 13:16:22 2019 [15707] IFCONFIG POOL LIST

    Wed Dec 18 13:16:22 2019 [15707] MULTI: TCP INIT maxclients=5000 maxevents=5004

    Wed Dec 18 13:16:22 2019 [15707] Initialization Sequence Completed

    Wed Dec 18 19:59:37 2019 [15707] MANAGEMENT: Client connected from /tmp/openvpn_mgmt

    Wed Dec 18 19:59:37 2019 [15707] MANAGEMENT: CMD 'status -1'

    Wed Dec 18 19:59:47 2019 [15707] MANAGEMENT: Client disconnected

    Thu Dec 19 10:41:18 2019 [15707] TCP connection established with [AF_INET6]::ffff:88.198.46.51:44680

    Thu Dec 19 10:41:19 2019 [15707] ::ffff:88.198.46.51 Connection reset, restarting [0]

    Thu Dec 19 10:41:19 2019 [15707] ::ffff:88.198.46.51 SIGUSR1[soft,connection-reset] received, client-instance restarting

    Thu Dec 19 13:55:42 2019 [15707] TCP connection established with [AF_INET6]::ffff:184.105.247.195:53622

    Thu Dec 19 13:55:42 2019 [15707] ::ffff:184.105.247.195 WARNING: Bad encapsulated packet length from peer (5635), which must be > 0 and <= 1572 -- please ensure that --tun-mtu or --link-mtu is equal on both peers -- this condition could also indicate a possible active attack on the TCP link -- [Attempting restart...]

    Thu Dec 19 13:55:42 2019 [15707] ::ffff:184.105.247.195 Connection reset, restarting [0]

    Thu Dec 19 13:55:42 2019 [15707] ::ffff:184.105.247.195 SIGUSR1[soft,connection-reset] received, client-instance restarting

    Thu Dec 19 19:21:34 2019 [15707] TCP connection established with [AF_INET6]::ffff:51.91.212.81:49652

    Thu Dec 19 19:21:36 2019 [15707] CID is :2

    Thu Dec 19 19:21:38 2019 [15707] ::ffff:51.91.212.81 WARNING: Bad encapsulated packet length from peer (5635), which must be > 0 and <= 1572 -- please ensure that --tun-mtu or --link-mtu is equal on both peers -- this condition could also indicate a possible active attack on the TCP link -- [Attempting restart...]

    Thu Dec 19 19:21:38 2019 [15707] ::ffff:51.91.212.81 Connection reset, restarting [0]

    Thu Dec 19 19:21:38 2019 [15707] ::ffff:51.91.212.81 SIGUSR1[soft,connection-reset] received, client-instance restarting

    Thu Dec 19 19:41:31 2019 [15707] TCP connection established with [AF_INET6]::ffff:77.247.110.64:57566

    Thu Dec 19 19:41:31 2019 [15707] ::ffff:77.247.110.64 WARNING: Bad encapsulated packet length from peer (5635), which must be > 0 and <= 1572 -- please ensure that --tun-mtu or --link-mtu is equal on both peers -- this condition could also indicate a possible active attack on the TCP link -- [Attempting restart...]

    Thu Dec 19 19:41:31 2019 [15707] ::ffff:77.247.110.64 Connection reset, restarting [0]

    Thu Dec 19 19:41:31 2019 [15707] ::ffff:77.247.110.64 SIGUSR1[soft,connection-reset] received, client-instance restarting

    Thu Dec 19 19:41:32 2019 [15707] TCP connection established with [AF_INET6]::ffff:77.247.110.64:57601

    Thu Dec 19 19:41:32 2019 [15707] ::ffff:77.247.110.64 WARNING: Bad encapsulated packet length from peer (5635), which must be > 0 and <= 1572 -- please ensure that --tun-mtu or --link-mtu is equal on both peers -- this condition could also indicate a possible active attack on the TCP link -- [Attempting restart...]

    Thu Dec 19 19:41:32 2019 [15707] ::ffff:77.247.110.64 Connection reset, restarting [0]

    Thu Dec 19 19:41:32 2019 [15707] ::ffff:77.247.110.64 SIGUSR1[soft,connection-reset] received, client-instance restarting

    Thu Dec 19 20:43:18 2019 [15707] TCP connection established with [AF_INET6]::ffff:138.99.216.171:61000

    Thu Dec 19 20:43:20 2019 [15707] ::ffff:138.99.216.171 WARNING: Bad encapsulated packet length from peer (5635), which must be > 0 and <= 1572 -- please ensure that --tun-mtu or --link-mtu is equal on both peers -- this condition could also indicate a possible active attack on the TCP link -- [Attempting restart...]

    Thu Dec 19 20:43:20 2019 [15707] ::ffff:138.99.216.171 Connection reset, restarting [0]

    Thu Dec 19 20:43:20 2019 [15707] ::ffff:138.99.216.171 SIGUSR1[soft,connection-reset] received, client-instance restarting

    Thu Dec 19 21:53:19 2019 [15707] TCP connection established with [AF_INET6]::ffff:196.52.43.131:58614

    Thu Dec 19 21:53:21 2019 [15707] ::ffff:196.52.43.131 WARNING: Bad encapsulated packet length from peer (5635), which must be > 0 and <= 1572 -- please ensure that --tun-mtu or --link-mtu is equal on both peers -- this condition could also indicate a possible active attack on the TCP link -- [Attempting restart...]

    Thu Dec 19 21:53:21 2019 [15707] ::ffff:196.52.43.131 Connection reset, restarting [0]

    Thu Dec 19 21:53:21 2019 [15707] ::ffff:196.52.43.131 SIGUSR1[soft,connection-reset] received, client-instance restarting

    Thu Dec 19 22:30:18 2019 [15707] TCP connection established with [AF_INET6]::ffff:185.173.35.37:46702

    Thu Dec 19 22:30:18 2019 [15707] ::ffff:185.173.35.37 WARNING: Bad encapsulated packet length from peer (5635), which must be > 0 and <= 1572 -- please ensure that --tun-mtu or --link-mtu is equal on both peers -- this condition could also indicate a possible active attack on the TCP link -- [Attempting restart...]

    Thu Dec 19 22:30:18 2019 [15707] ::ffff:185.173.35.37 Connection reset, restarting [0]

    Thu Dec 19 22:30:18 2019 [15707] ::ffff:185.173.35.37 SIGUSR1[soft,connection-reset] received, client-instance restarting

    Fri Dec 20 17:51:03 2019 [15707] TCP connection established with [AF_INET6]::ffff:184.105.139.67:49104

    Fri Dec 20 17:51:03 2019 [15707] ::ffff:184.105.139.67 WARNING: Bad encapsulated packet length from peer (5635), which must be > 0 and <= 1572 -- please ensure that --tun-mtu or --link-mtu is equal on both peers -- this condition could also indicate a possible active attack on the TCP link -- [Attempting restart...]

    Fri Dec 20 17:51:03 2019 [15707] ::ffff:184.105.139.67 Connection reset, restarting [0]

    Fri Dec 20 17:51:03 2019 [15707] ::ffff:184.105.139.67 SIGUSR1[soft,connection-reset] received, client-instance restarting

    Fri Dec 20 19:06:19 2019 [15707] TCP connection established with [AF_INET6]::ffff:198.143.155.138:46560

    Fri Dec 20 19:06:19 2019 [15707] ::ffff:198.143.155.138 WARNING: Bad encapsulated packet length from peer (5635), which must be > 0 and <= 1572 -- please ensure that --tun-mtu or --link-mtu is equal on both peers -- this condition could also indicate a possible active attack on the TCP link -- [Attempting restart...]

    Fri Dec 20 19:06:19 2019 [15707] ::ffff:198.143.155.138 Connection reset, restarting [0]

    Fri Dec 20 19:06:19 2019 [15707] ::ffff:198.143.155.138 SIGUSR1[soft,connection-reset] received, client-instance restarting

    Fri Dec 20 19:06:22 2019 [15707] TCP connection established with [AF_INET6]::ffff:198.143.155.138:50320

    Fri Dec 20 19:06:22 2019 [15707] ::ffff:198.143.155.138 WARNING: Bad encapsulated packet length from peer (18245), which must be > 0 and <= 1572 -- please ensure that --tun-mtu or --link-mtu is equal on both peers -- this condition could also indicate a possible active attack on the TCP link -- [Attempting restart...]

    Fri Dec 20 19:06:22 2019 [15707] ::ffff:198.143.155.138 Connection reset, restarting [0]

    Fri Dec 20 19:06:22 2019 [15707] ::ffff:198.143.155.138 SIGUSR1[soft,connection-reset] received, client-instance restarting

    Fri Dec 20 19:06:24 2019 [15707] TCP connection established with [AF_INET6]::ffff:198.143.155.138:53275

    Fri Dec 20 19:06:25 2019 [15707] ::ffff:198.143.155.138 CID is :11

    Fri Dec 20 19:06:29 2019 [15707] ::ffff:198.143.155.138 Connection reset, restarting [0]

    Fri Dec 20 19:06:29 2019 [15707] ::ffff:198.143.155.138 SIGUSR1[soft,connection-reset] received, client-instance restarting

    Fri Dec 20 19:06:31 2019 [15707] TCP connection established with [AF_INET6]::ffff:198.143.155.138:35108

    Fri Dec 20 19:06:31 2019 [15707] ::ffff:198.143.155.138 WARNING: Bad encapsulated packet length from peer (5635), which must be > 0 and <= 1572 -- please ensure that --tun-mtu or --link-mtu is equal on both peers -- this condition could also indicate a possible active attack on the TCP link -- [Attempting restart...]

    Fri Dec 20 19:06:31 2019 [15707] ::ffff:198.143.155.138 Connection reset, restarting [0]

    Fri Dec 20 19:06:31 2019 [15707] ::ffff:198.143.155.138 SIGUSR1[soft,connection-reset] received, client-instance restarting

    Fri Dec 20 19:06:35 2019 [15707] TCP connection established with [AF_INET6]::ffff:198.143.155.138:38868

    Fri Dec 20 19:06:35 2019 [15707] ::ffff:198.143.155.138 WARNING: Bad encapsulated packet length from peer (5635), which must be > 0 and <= 1572 -- please ensure that --tun-mtu or --link-mtu is equal on both peers -- this condition could also indicate a possible active attack on the TCP link -- [Attempting restart...]

    Fri Dec 20 19:06:35 2019 [15707] ::ffff:198.143.155.138 Connection reset, restarting [0]

    Fri Dec 20 19:06:35 2019 [15707] ::ffff:198.143.155.138 SIGUSR1[soft,connection-reset] received, client-instance restarting

    Fri Dec 20 19:06:37 2019 [15707] TCP connection established with [AF_INET6]::ffff:198.143.155.138:43164

    Fri Dec 20 19:06:37 2019 [15707] ::ffff:198.143.155.138 WARNING: Bad encapsulated packet length from peer (32814), which must be > 0 and <= 1572 -- please ensure that --tun-mtu or --link-mtu is equal on both peers -- this condition could also indicate a possible active attack on the TCP link -- [Attempting restart...]

    Fri Dec 20 19:06:37 2019 [15707] ::ffff:198.143.155.138 Connection reset, restarting [0]

    Fri Dec 20 19:06:37 2019 [15707] ::ffff:198.143.155.138 SIGUSR1[soft,connection-reset] received, client-instance restarting

    Fri Dec 20 19:06:39 2019 [15707] TCP connection established with [AF_INET6]::ffff:198.143.155.138:46056

    Fri Dec 20 19:06:40 2019 [15707] ::ffff:198.143.155.138 CID is :15

    Fri Dec 20 19:06:44 2019 [15707] ::ffff:198.143.155.138 Connection reset, restarting [0]

    Fri Dec 20 19:06:44 2019 [15707] ::ffff:198.143.155.138 SIGUSR1[soft,connection-reset] received, client-instance restarting

    Fri Dec 20 19:06:46 2019 [15707] TCP connection established with [AF_INET6]::ffff:198.143.155.138:55389

    Fri Dec 20 19:06:51 2019 [15707] ::ffff:198.143.155.138 Connection reset, restarting [0]

    Fri Dec 20 19:06:51 2019 [15707] ::ffff:198.143.155.138 SIGUSR1[soft,connection-reset] received, client-instance restarting

    Fri Dec 20 19:06:53 2019 [15707] TCP connection established with [AF_INET6]::ffff:198.143.155.138:36788

    Fri Dec 20 19:06:55 2019 [15707] ::ffff:198.143.155.138 CID is :17

    Fri Dec 20 19:06:58 2019 [15707] ::ffff:198.143.155.138 Connection reset, restarting [0]

    Fri Dec 20 19:06:58 2019 [15707] ::ffff:198.143.155.138 SIGUSR1[soft,connection-reset] received, client-instance restarting

    Fri Dec 20 19:24:45 2019 [15707] TCP connection established with [AF_INET6]::ffff:138.99.216.147:61000

    Fri Dec 20 19:24:47 2019 [15707] ::ffff:138.99.216.147 WARNING: Bad encapsulated packet length from peer (5635), which must be > 0 and <= 1572 -- please ensure that --tun-mtu or --link-mtu is equal on both peers -- this condition could also indicate a possible active attack on the TCP link -- [Attempting restart...]

    Fri Dec 20 19:24:47 2019 [15707] ::ffff:138.99.216.147 Connection reset, restarting [0]

    Fri Dec 20 19:24:47 2019 [15707] ::ffff:138.99.216.147 SIGUSR1[soft,connection-reset] received, client-instance restarting

    Sat Dec 21 01:44:45 2019 [15707] Closing TUN/TAP interface

    Sat Dec 21 01:44:45 2019 [15707] /bin/ip addr del dev tun0 10.81.234.5/24

    Sat Dec 21 01:44:45 2019 [15707] /bin/ip -6 addr del 2001:db8::1:0/64 dev tun0

    Sat Dec 21 01:44:45 2019 [15707] PLUGIN_CLOSE: /lib/openvpn-plugin-utm.so

    Sat Dec 21 01:44:45 2019 [15707] SIGTERM[hard,] received, process exiting

    Sat Dec 21 01:44:49 2019 [5028] OpenVPN 2.3.6 i486-openwrt-linux-gnu [SSL (OpenSSL)] [LZO] [EPOLL] [MH] [IPv6] built on Nov  1 2019

    Sat Dec 21 01:44:49 2019 [5028] library versions: OpenSSL 1.0.2k-fips  26 Jan 2017, LZO 2.09

    Sat Dec 21 01:44:49 2019 [5028] MANAGEMENT: client_uid=0

    Sat Dec 21 01:44:49 2019 [5028] MANAGEMENT: unix domain socket listening on /tmp/openvpn_mgmt

    /scripts/vpn/sslvpn/user-cleanup.sh: line 4: DELETE: not found

    Sat Dec 21 01:44:49 2019 [5028] cleanup success

    Sat Dec 21 01:44:49 2019 [5028] WARNING: using --duplicate-cn and --client-config-dir together is probably not what you want

    Sat Dec 21 01:44:49 2019 [5028] WARNING: --ifconfig-pool-persist will not work with --duplicate-cn

    Sat Dec 21 01:44:49 2019 [5028] NOTE: the current --script-security setting may allow this configuration to call user-defined scripts

    grhandle=0x8566270

    Authentication server 127.0.0.1 gave login response code 2

    Sat Dec 21 01:44:49 2019 [5028] PLUGIN_INIT: POST /lib/openvpn-plugin-utm.so '[/lib/openvpn-plugin-utm.so]' intercepted=PLUGIN_AUTH_USER_PASS_VERIFY|PLUGIN_CLIENT_CONNECT|PLUGIN_CLIENT_DISCONNECT

    Sat Dec 21 01:44:49 2019 [5028] Diffie-Hellman initialized with 2048 bit key

    Sat Dec 21 01:44:49 2019 [5028] WARNING: file '/conf/certificate/private/ApplianceCertificate.key' is group or others accessible

    Sat Dec 21 01:44:49 2019 [5028] WARNING: experimental option --capath /conf/certificate/openvpn

    Sat Dec 21 01:44:49 2019 [5028] Socket Buffers: R=[87380->131072] S=[16384->131072]

    Sat Dec 21 01:44:49 2019 [5028] TUN/TAP device tun0 opened

    Sat Dec 21 01:44:49 2019 [5028] TUN/TAP TX queue length set to 100

    Sat Dec 21 01:44:49 2019 [5028] do_ifconfig, tt->ipv6=1, tt->did_ifconfig_ipv6_setup=1

    Sat Dec 21 01:44:49 2019 [5028] /bin/ip link set dev tun0 up mtu 1500

    Sat Dec 21 01:44:49 2019 [5028] /bin/ip addr add dev tun0 10.81.234.5/24 broadcast 10.81.234.255

    Sat Dec 21 01:44:49 2019 [5028] /bin/ip -6 addr add 2001:db8::1:0/64 dev tun0

    Sat Dec 21 01:44:49 2019 [5028] CSC service status updated to RUNNING

    Sat Dec 21 01:44:49 2019 [5028] Listening for incoming TCP connection on [undef]

    Sat Dec 21 01:44:49 2019 [5028] TCPv6_SERVER link local (bound): [undef]

    Sat Dec 21 01:44:49 2019 [5028] TCPv6_SERVER link remote: [undef]

    Sat Dec 21 01:44:49 2019 [5028] MULTI: multi_init called, r=256 v=256

    Sat Dec 21 01:44:49 2019 [5028] IFCONFIG POOL IPv6: (IPv4) size=50, size_ipv6=65536, netbits=64, base_ipv6=2001:db8::1:1

    Sat Dec 21 01:44:49 2019 [5028] IFCONFIG POOL: base=10.81.234.6 size=50, ipv6=1

    Sat Dec 21 01:44:49 2019 [5028] IFCONFIG POOL LIST

    Sat Dec 21 01:44:49 2019 [5028] MULTI: TCP INIT maxclients=5000 maxevents=5004

    Sat Dec 21 01:44:49 2019 [5028] Initialization Sequence Completed

    Sat Dec 21 02:07:32 2019 [5028] Closing TUN/TAP interface

    Sat Dec 21 02:07:32 2019 [5028] /bin/ip addr del dev tun0 10.81.234.5/24

    Sat Dec 21 02:07:33 2019 [5028] /bin/ip -6 addr del 2001:db8::1:0/64 dev tun0

    Sat Dec 21 02:07:33 2019 [5028] PLUGIN_CLOSE: /lib/openvpn-plugin-utm.so

    Sat Dec 21 02:07:33 2019 [5028] SIGTERM[hard,] received, process exiting

    Sat Dec 21 02:07:37 2019 [10980] OpenVPN 2.3.6 i486-openwrt-linux-gnu [SSL (OpenSSL)] [LZO] [EPOLL] [MH] [IPv6] built on Nov  1 2019

    Sat Dec 21 02:07:37 2019 [10980] library versions: OpenSSL 1.0.2k-fips  26 Jan 2017, LZO 2.09

    Sat Dec 21 02:07:37 2019 [10980] MANAGEMENT: client_uid=0

    Sat Dec 21 02:07:37 2019 [10980] MANAGEMENT: unix domain socket listening on /tmp/openvpn_mgmt

    /scripts/vpn/sslvpn/user-cleanup.sh: line 4: DELETE: not found

    Sat Dec 21 02:07:37 2019 [10980] cleanup success

    Sat Dec 21 02:07:37 2019 [10980] WARNING: using --duplicate-cn and --client-config-dir together is probably not what you want

    Sat Dec 21 02:07:37 2019 [10980] WARNING: --ifconfig-pool-persist will not work with --duplicate-cn

    Sat Dec 21 02:07:37 2019 [10980] NOTE: the current --script-security setting may allow this configuration to call user-defined scripts

    grhandle=0x96a9270

    Authentication server 127.0.0.1 gave login response code 2

    Sat Dec 21 02:07:37 2019 [10980] PLUGIN_INIT: POST /lib/openvpn-plugin-utm.so '[/lib/openvpn-plugin-utm.so]' intercepted=PLUGIN_AUTH_USER_PASS_VERIFY|PLUGIN_CLIENT_CONNECT|PLUGIN_CLIENT_DISCONNECT

    Sat Dec 21 02:07:37 2019 [10980] Diffie-Hellman initialized with 2048 bit key

    Sat Dec 21 02:07:37 2019 [10980] WARNING: file '/conf/certificate/private/ApplianceCertificate.key' is group or others accessible

    Sat Dec 21 02:07:37 2019 [10980] WARNING: experimental option --capath /conf/certificate/openvpn

    Sat Dec 21 02:07:37 2019 [10980] Socket Buffers: R=[87380->131072] S=[16384->131072]

    Sat Dec 21 02:07:37 2019 [10980] TUN/TAP device tun0 opened

    Sat Dec 21 02:07:37 2019 [10980] TUN/TAP TX queue length set to 100

    Sat Dec 21 02:07:37 2019 [10980] do_ifconfig, tt->ipv6=1, tt->did_ifconfig_ipv6_setup=1

    Sat Dec 21 02:07:37 2019 [10980] /bin/ip link set dev tun0 up mtu 1500

    Sat Dec 21 02:07:37 2019 [10980] /bin/ip addr add dev tun0 10.81.234.5/24 broadcast 10.81.234.255

    Sat Dec 21 02:07:37 2019 [10980] /bin/ip -6 addr add 2001:db8::1:0/64 dev tun0

    Sat Dec 21 02:07:37 2019 [10980] CSC service status updated to RUNNING

    Sat Dec 21 02:07:37 2019 [10980] Listening for incoming TCP connection on [undef]

    Sat Dec 21 02:07:37 2019 [10980] TCPv6_SERVER link local (bound): [undef]

    Sat Dec 21 02:07:37 2019 [10980] TCPv6_SERVER link remote: [undef]

    Sat Dec 21 02:07:37 2019 [10980] MULTI: multi_init called, r=256 v=256

    Sat Dec 21 02:07:37 2019 [10980] IFCONFIG POOL IPv6: (IPv4) size=50, size_ipv6=65536, netbits=64, base_ipv6=2001:db8::1:1

    Sat Dec 21 02:07:37 2019 [10980] IFCONFIG POOL: base=10.81.234.6 size=50, ipv6=1

    Sat Dec 21 02:07:37 2019 [10980] IFCONFIG POOL LIST

    Sat Dec 21 02:07:37 2019 [10980] MULTI: TCP INIT maxclients=5000 maxevents=5004

    Sat Dec 21 02:07:37 2019 [10980] Initialization Sequence Completed

    Sat Dec 21 06:31:20 2019 [10980] TCP connection established with [AF_INET6]::ffff:45.136.108.22:2690

    Sat Dec 21 06:31:35 2019 [10980] CID is :0

    Sat Dec 21 06:31:51 2019 [10980] CID is :0

    Sat Dec 21 06:32:06 2019 [10980] CID is :0

    Sat Dec 21 06:32:21 2019 [10980] CID is :0

    Sat Dec 21 06:32:21 2019 [10980] ::ffff:45.136.108.22 TLS Error: TLS key negotiation failed to occur within 60 seconds (check your network connectivity)

    Sat Dec 21 06:32:21 2019 [10980] ::ffff:45.136.108.22 TLS Error: TLS handshake failed

    Sat Dec 21 06:32:21 2019 [10980] ::ffff:45.136.108.22 Fatal TLS error (check_tls_errors_co), restarting

    Sat Dec 21 06:32:21 2019 [10980] ::ffff:45.136.108.22 SIGUSR1[soft,tls-error] received, client-instance restarting

    Sat Dec 21 13:58:30 2019 [10980] TCP connection established with [AF_INET6]::ffff:184.105.139.69:62216

    Sat Dec 21 13:58:31 2019 [10980] ::ffff:184.105.139.69 WARNING: Bad encapsulated packet length from peer (5635), which must be > 0 and <= 1572 -- please ensure that --tun-mtu or --link-mtu is equal on both peers -- this condition could also indicate a possible active attack on the TCP link -- [Attempting restart...]

    Sat Dec 21 13:58:31 2019 [10980] ::ffff:184.105.139.69 Connection reset, restarting [0]

    Sat Dec 21 13:58:31 2019 [10980] ::ffff:184.105.139.69 SIGUSR1[soft,connection-reset] received, client-instance restarting

    Sat Dec 21 15:43:51 2019 [10980] TCP connection established with [AF_INET6]::ffff:159.203.201.112:54536

    Sat Dec 21 15:44:01 2019 [10980] ::ffff:159.203.201.112 Connection reset, restarting [0]

    Sat Dec 21 15:44:01 2019 [10980] ::ffff:159.203.201.112 SIGUSR1[soft,connection-reset] received, client-instance restarting

    Sat Dec 21 18:50:58 2019 [10980] TCP connection established with [AF_INET6]::ffff:51.91.212.81:36482

    Sat Dec 21 18:50:58 2019 [10980] ::ffff:51.91.212.81 WARNING: Bad encapsulated packet length from peer (5635), which must be > 0 and <= 1572 -- please ensure that --tun-mtu or --link-mtu is equal on both peers -- this condition could also indicate a possible active attack on the TCP link -- [Attempting restart...]

    Sat Dec 21 18:50:58 2019 [10980] ::ffff:51.91.212.81 Connection reset, restarting [0]

    Sat Dec 21 18:50:58 2019 [10980] ::ffff:51.91.212.81 SIGUSR1[soft,connection-reset] received, client-instance restarting

    Sat Dec 21 20:52:24 2019 [10980] TCP connection established with [AF_INET6]::ffff:1.192.193.15:59928

    Sat Dec 21 20:52:27 2019 [10980] TCP connection established with [AF_INET6]::ffff:1.192.193.15:62550

    Sat Dec 21 20:52:27 2019 [10980] ::ffff:1.192.193.15 WARNING: Bad encapsulated packet length from peer (5635), which must be > 0 and <= 1572 -- please ensure that --tun-mtu or --link-mtu is equal on both peers -- this condition could also indicate a possible active attack on the TCP link -- [Attempting restart...]

    Sat Dec 21 20:52:27 2019 [10980] ::ffff:1.192.193.15 Connection reset, restarting [0]

    Sat Dec 21 20:52:27 2019 [10980] ::ffff:1.192.193.15 SIGUSR1[soft,connection-reset] received, client-instance restarting

    Sat Dec 21 20:52:28 2019 [10980] ::ffff:1.192.193.15 Connection reset, restarting [0]

    Sat Dec 21 20:52:28 2019 [10980] ::ffff:1.192.193.15 SIGUSR1[soft,connection-reset] received, client-instance restarting

    Sat Dec 21 22:57:40 2019 [10980] TCP connection established with [AF_INET6]::ffff:71.6.232.4:43234

    Sat Dec 21 22:57:40 2019 [10980] ::ffff:71.6.232.4 WARNING: Bad encapsulated packet length from peer (5635), which must be > 0 and <= 1572 -- please ensure that --tun-mtu or --link-mtu is equal on both peers -- this condition could also indicate a possible active attack on the TCP link -- [Attempting restart...]

    Sat Dec 21 22:57:40 2019 [10980] ::ffff:71.6.232.4 Connection reset, restarting [0]

    Sat Dec 21 22:57:40 2019 [10980] ::ffff:71.6.232.4 SIGUSR1[soft,connection-reset] received, client-instance restarting

    Sun Dec 22 00:19:55 2019 [10980] MANAGEMENT: Client connected from /tmp/openvpn_mgmt

    Sun Dec 22 00:19:55 2019 [10980] MANAGEMENT: CMD 'status -1'

    Sun Dec 22 00:20:05 2019 [10980] MANAGEMENT: Client disconnected

    Sun Dec 22 00:37:07 2019 [10980] Closing TUN/TAP interface

    Sun Dec 22 00:37:07 2019 [10980] /bin/ip addr del dev tun0 10.81.234.5/24

    Sun Dec 22 00:37:07 2019 [10980] /bin/ip -6 addr del 2001:db8::1:0/64 dev tun0

    Sun Dec 22 00:37:08 2019 [10980] PLUGIN_CLOSE: /lib/openvpn-plugin-utm.so

    Sun Dec 22 00:37:08 2019 [10980] SIGTERM[hard,] received, process exiting

    Sun Dec 22 00:37:12 2019 [30145] OpenVPN 2.3.6 i486-openwrt-linux-gnu [SSL (OpenSSL)] [LZO] [EPOLL] [MH] [IPv6] built on Nov  1 2019

    Sun Dec 22 00:37:12 2019 [30145] library versions: OpenSSL 1.0.2k-fips  26 Jan 2017, LZO 2.09

    Sun Dec 22 00:37:12 2019 [30145] MANAGEMENT: client_uid=0

    Sun Dec 22 00:37:12 2019 [30145] MANAGEMENT: unix domain socket listening on /tmp/openvpn_mgmt

    /scripts/vpn/sslvpn/user-cleanup.sh: line 4: DELETE: not found

    Sun Dec 22 00:37:12 2019 [30145] cleanup success

    Sun Dec 22 00:37:12 2019 [30145] WARNING: using --duplicate-cn and --client-config-dir together is probably not what you want

    Sun Dec 22 00:37:12 2019 [30145] WARNING: --ifconfig-pool-persist will not work with --duplicate-cn

    Sun Dec 22 00:37:12 2019 [30145] NOTE: the current --script-security setting may allow this configuration to call user-defined scripts

    grhandle=0x8c00270

    Authentication server 127.0.0.1 gave login response code 2

    Sun Dec 22 00:37:12 2019 [30145] PLUGIN_INIT: POST /lib/openvpn-plugin-utm.so '[/lib/openvpn-plugin-utm.so]' intercepted=PLUGIN_AUTH_USER_PASS_VERIFY|PLUGIN_CLIENT_CONNECT|PLUGIN_CLIENT_DISCONNECT

    Sun Dec 22 00:37:12 2019 [30145] Diffie-Hellman initialized with 2048 bit key

    Sun Dec 22 00:37:12 2019 [30145] WARNING: file '/conf/certificate/private/ApplianceCertificate.key' is group or others accessible

    Sun Dec 22 00:37:12 2019 [30145] WARNING: experimental option --capath /conf/certificate/openvpn

    Sun Dec 22 00:37:12 2019 [30145] Socket Buffers: R=[87380->131072] S=[16384->131072]

    Sun Dec 22 00:37:12 2019 [30145] TUN/TAP device tun0 opened

    Sun Dec 22 00:37:12 2019 [30145] TUN/TAP TX queue length set to 100

    Sun Dec 22 00:37:12 2019 [30145] do_ifconfig, tt->ipv6=1, tt->did_ifconfig_ipv6_setup=1

    Sun Dec 22 00:37:12 2019 [30145] /bin/ip link set dev tun0 up mtu 1500

    Sun Dec 22 00:37:12 2019 [30145] /bin/ip addr add dev tun0 10.81.234.5/24 broadcast 10.81.234.255

    Sun Dec 22 00:37:12 2019 [30145] /bin/ip -6 addr add 2001:db8::1:0/64 dev tun0

    Sun Dec 22 00:37:12 2019 [30145] CSC service status updated to RUNNING

    Sun Dec 22 00:37:12 2019 [30145] Listening for incoming TCP connection on [undef]

    Sun Dec 22 00:37:12 2019 [30145] TCPv6_SERVER link local (bound): [undef]

    Sun Dec 22 00:37:12 2019 [30145] TCPv6_SERVER link remote: [undef]

    Sun Dec 22 00:37:12 2019 [30145] MULTI: multi_init called, r=256 v=256

    Sun Dec 22 00:37:12 2019 [30145] IFCONFIG POOL IPv6: (IPv4) size=50, size_ipv6=65536, netbits=64, base_ipv6=2001:db8::1:1

    Sun Dec 22 00:37:12 2019 [30145] IFCONFIG POOL: base=10.81.234.6 size=50, ipv6=1

    Sun Dec 22 00:37:12 2019 [30145] IFCONFIG POOL LIST

    Sun Dec 22 00:37:12 2019 [30145] MULTI: TCP INIT maxclients=5000 maxevents=5004

    Sun Dec 22 00:37:12 2019 [30145] Initialization Sequence Completed

    Sun Dec 22 00:41:24 2019 [30145] TCP connection established with [AF_INET6]::ffff:88.198.46.51:37598

    Sun Dec 22 00:41:24 2019 [30145] ::ffff:88.198.46.51 Connection reset, restarting [0]

    Sun Dec 22 00:41:24 2019 [30145] ::ffff:88.198.46.51 SIGUSR1[soft,connection-reset] received, client-instance restarting

    Sun Dec 22 00:42:44 2019 [30145] Closing TUN/TAP interface

    Sun Dec 22 00:42:44 2019 [30145] /bin/ip addr del dev tun0 10.81.234.5/24

    Sun Dec 22 00:42:44 2019 [30145] /bin/ip -6 addr del 2001:db8::1:0/64 dev tun0

    Sun Dec 22 00:42:45 2019 [30145] PLUGIN_CLOSE: /lib/openvpn-plugin-utm.so

    Sun Dec 22 00:42:45 2019 [30145] SIGTERM[hard,] received, process exiting

    Sun Dec 22 00:42:49 2019 [30733] OpenVPN 2.3.6 i486-openwrt-linux-gnu [SSL (OpenSSL)] [LZO] [EPOLL] [MH] [IPv6] built on Nov  1 2019

    Sun Dec 22 00:42:49 2019 [30733] library versions: OpenSSL 1.0.2k-fips  26 Jan 2017, LZO 2.09

    Sun Dec 22 00:42:49 2019 [30733] MANAGEMENT: client_uid=0

    Sun Dec 22 00:42:49 2019 [30733] MANAGEMENT: unix domain socket listening on /tmp/openvpn_mgmt

    /scripts/vpn/sslvpn/user-cleanup.sh: line 4: DELETE: not found

    Sun Dec 22 00:42:49 2019 [30733] cleanup success

    Sun Dec 22 00:42:49 2019 [30733] WARNING: using --duplicate-cn and --client-config-dir together is probably not what you want

    Sun Dec 22 00:42:49 2019 [30733] WARNING: --ifconfig-pool-persist will not work with --duplicate-cn

    Sun Dec 22 00:42:49 2019 [30733] NOTE: the current --script-security setting may allow this configuration to call user-defined scripts

    grhandle=0x8f13270

    Authentication server 127.0.0.1 gave login response code 2

    Sun Dec 22 00:42:49 2019 [30733] PLUGIN_INIT: POST /lib/openvpn-plugin-utm.so '[/lib/openvpn-plugin-utm.so]' intercepted=PLUGIN_AUTH_USER_PASS_VERIFY|PLUGIN_CLIENT_CONNECT|PLUGIN_CLIENT_DISCONNECT

    Sun Dec 22 00:42:49 2019 [30733] Diffie-Hellman initialized with 2048 bit key

    Sun Dec 22 00:42:49 2019 [30733] WARNING: file '/conf/certificate/private/ApplianceCertificate.key' is group or others accessible

    Sun Dec 22 00:42:49 2019 [30733] WARNING: experimental option --capath /conf/certificate/openvpn

    Sun Dec 22 00:42:49 2019 [30733] Socket Buffers: R=[229376->131072] S=[229376->131072]

    Sun Dec 22 00:42:49 2019 [30733] TUN/TAP device tun0 opened

    Sun Dec 22 00:42:49 2019 [30733] TUN/TAP TX queue length set to 100

    Sun Dec 22 00:42:49 2019 [30733] do_ifconfig, tt->ipv6=1, tt->did_ifconfig_ipv6_setup=1

    Sun Dec 22 00:42:49 2019 [30733] /bin/ip link set dev tun0 up mtu 1500

    Sun Dec 22 00:42:49 2019 [30733] /bin/ip addr add dev tun0 10.81.234.5/24 broadcast 10.81.234.255

    Sun Dec 22 00:42:49 2019 [30733] /bin/ip -6 addr add 2001:db8::1:0/64 dev tun0

    Sun Dec 22 00:42:49 2019 [30733] CSC service status updated to RUNNING

    Sun Dec 22 00:42:49 2019 [30733] UDPv6 link local (bound): [undef]

    Sun Dec 22 00:42:49 2019 [30733] UDPv6 link remote: [undef]

    Sun Dec 22 00:42:49 2019 [30733] MULTI: multi_init called, r=256 v=256

    Sun Dec 22 00:42:49 2019 [30733] IFCONFIG POOL IPv6: (IPv4) size=50, size_ipv6=65536, netbits=64, base_ipv6=2001:db8::1:1

    Sun Dec 22 00:42:49 2019 [30733] IFCONFIG POOL: base=10.81.234.6 size=50, ipv6=1

    Sun Dec 22 00:42:49 2019 [30733] IFCONFIG POOL LIST

    Sun Dec 22 00:42:49 2019 [30733] Initialization Sequence Completed

    Sun Dec 22 00:44:23 2019 [30733] event_wait : Interrupted system call (code=4)

    Sun Dec 22 00:44:23 2019 [30733] Closing TUN/TAP interface

    Sun Dec 22 00:44:23 2019 [30733] /bin/ip addr del dev tun0 10.81.234.5/24

    Sun Dec 22 00:44:23 2019 [30733] /bin/ip -6 addr del 2001:db8::1:0/64 dev tun0

    Sun Dec 22 00:44:23 2019 [30733] PLUGIN_CLOSE: /lib/openvpn-plugin-utm.so

    Sun Dec 22 00:44:23 2019 [30733] SIGTERM[hard,] received, process exiting

    Sun Dec 22 00:44:27 2019 [31021] OpenVPN 2.3.6 i486-openwrt-linux-gnu [SSL (OpenSSL)] [LZO] [EPOLL] [MH] [IPv6] built on Nov  1 2019

    Sun Dec 22 00:44:27 2019 [31021] library versions: OpenSSL 1.0.2k-fips  26 Jan 2017, LZO 2.09

    Sun Dec 22 00:44:27 2019 [31021] MANAGEMENT: client_uid=0

    Sun Dec 22 00:44:27 2019 [31021] MANAGEMENT: unix domain socket listening on /tmp/openvpn_mgmt

    /scripts/vpn/sslvpn/user-cleanup.sh: line 4: DELETE: not found

    Sun Dec 22 00:44:27 2019 [31021] cleanup success

    Sun Dec 22 00:44:27 2019 [31021] WARNING: using --duplicate-cn and --client-config-dir together is probably not what you want

    Sun Dec 22 00:44:27 2019 [31021] WARNING: --ifconfig-pool-persist will not work with --duplicate-cn

    Sun Dec 22 00:44:27 2019 [31021] NOTE: the current --script-security setting may allow this configuration to call user-defined scripts

    grhandle=0x8a3a270

    Authentication server 127.0.0.1 gave login response code 2

    Sun Dec 22 00:44:27 2019 [31021] PLUGIN_INIT: POST /lib/openvpn-plugin-utm.so '[/lib/openvpn-plugin-utm.so]' intercepted=PLUGIN_AUTH_USER_PASS_VERIFY|PLUGIN_CLIENT_CONNECT|PLUGIN_CLIENT_DISCONNECT

    Sun Dec 22 00:44:27 2019 [31021] Diffie-Hellman initialized with 2048 bit key

    Sun Dec 22 00:44:27 2019 [31021] WARNING: file '/conf/certificate/private/ApplianceCertificate.key' is group or others accessible

    Sun Dec 22 00:44:27 2019 [31021] WARNING: experimental option --capath /conf/certificate/openvpn

    Sun Dec 22 00:44:27 2019 [31021] Socket Buffers: R=[87380->131072] S=[16384->131072]

    Sun Dec 22 00:44:27 2019 [31021] TUN/TAP device tun0 opened

    Sun Dec 22 00:44:27 2019 [31021] TUN/TAP TX queue length set to 100

    Sun Dec 22 00:44:27 2019 [31021] do_ifconfig, tt->ipv6=1, tt->did_ifconfig_ipv6_setup=1

    Sun Dec 22 00:44:27 2019 [31021] /bin/ip link set dev tun0 up mtu 1500

    Sun Dec 22 00:44:27 2019 [31021] /bin/ip addr add dev tun0 10.81.234.5/24 broadcast 10.81.234.255

    Sun Dec 22 00:44:27 2019 [31021] /bin/ip -6 addr add 2001:db8::1:0/64 dev tun0

    Sun Dec 22 00:44:27 2019 [31021] CSC service status updated to RUNNING

    Sun Dec 22 00:44:27 2019 [31021] Listening for incoming TCP connection on [undef]

    Sun Dec 22 00:44:27 2019 [31021] TCPv6_SERVER link local (bound): [undef]

    Sun Dec 22 00:44:27 2019 [31021] TCPv6_SERVER link remote: [undef]

    Sun Dec 22 00:44:27 2019 [31021] MULTI: multi_init called, r=256 v=256

    Sun Dec 22 00:44:27 2019 [31021] IFCONFIG POOL IPv6: (IPv4) size=50, size_ipv6=65536, netbits=64, base_ipv6=2001:db8::1:1

    Sun Dec 22 00:44:27 2019 [31021] IFCONFIG POOL: base=10.81.234.6 size=50, ipv6=1

    Sun Dec 22 00:44:27 2019 [31021] IFCONFIG POOL LIST

    Sun Dec 22 00:44:27 2019 [31021] MULTI: TCP INIT maxclients=5000 maxevents=5004

    Sun Dec 22 00:44:27 2019 [31021] Initialization Sequence Completed

    Sun Dec 22 01:18:07 2019 [31021] Closing TUN/TAP interface

    Sun Dec 22 01:18:07 2019 [31021] /bin/ip addr del dev tun0 10.81.234.5/24

    Sun Dec 22 01:18:07 2019 [31021] /bin/ip -6 addr del 2001:db8::1:0/64 dev tun0

    Sun Dec 22 01:18:07 2019 [31021] PLUGIN_CLOSE: /lib/openvpn-plugin-utm.so

    Sun Dec 22 01:18:07 2019 [31021] SIGTERM[hard,] received, process exiting

    Sun Dec 22 01:18:11 2019 [1488] OpenVPN 2.3.6 i486-openwrt-linux-gnu [SSL (OpenSSL)] [LZO] [EPOLL] [MH] [IPv6] built on Nov  1 2019

    Sun Dec 22 01:18:11 2019 [1488] library versions: OpenSSL 1.0.2k-fips  26 Jan 2017, LZO 2.09

    Sun Dec 22 01:18:11 2019 [1488] MANAGEMENT: client_uid=0

    Sun Dec 22 01:18:11 2019 [1488] MANAGEMENT: unix domain socket listening on /tmp/openvpn_mgmt

    /scripts/vpn/sslvpn/user-cleanup.sh: line 4: DELETE: not found

    Sun Dec 22 01:18:11 2019 [1488] cleanup success

    Sun Dec 22 01:18:11 2019 [1488] WARNING: using --duplicate-cn and --client-config-dir together is probably not what you want

    Sun Dec 22 01:18:11 2019 [1488] WARNING: --ifconfig-pool-persist will not work with --duplicate-cn

    Sun Dec 22 01:18:11 2019 [1488] NOTE: the current --script-security setting may allow this configuration to call user-defined scripts

    grhandle=0x8dd2270

    Authentication server 127.0.0.1 gave login response code 2

    Sun Dec 22 01:18:11 2019 [1488] PLUGIN_INIT: POST /lib/openvpn-plugin-utm.so '[/lib/openvpn-plugin-utm.so]' intercepted=PLUGIN_AUTH_USER_PASS_VERIFY|PLUGIN_CLIENT_CONNECT|PLUGIN_CLIENT_DISCONNECT

    Sun Dec 22 01:18:11 2019 [1488] Diffie-Hellman initialized with 2048 bit key

    Sun Dec 22 01:18:11 2019 [1488] WARNING: file '/conf/certificate/private/ApplianceCertificate.key' is group or others accessible

    Sun Dec 22 01:18:11 2019 [1488] WARNING: experimental option --capath /conf/certificate/openvpn

    Sun Dec 22 01:18:11 2019 [1488] Socket Buffers: R=[87380->131072] S=[16384->131072]

    Sun Dec 22 01:18:11 2019 [1488] TUN/TAP device tun0 opened

    Sun Dec 22 01:18:11 2019 [1488] TUN/TAP TX queue length set to 100

    Sun Dec 22 01:18:11 2019 [1488] do_ifconfig, tt->ipv6=1, tt->did_ifconfig_ipv6_setup=1

    Sun Dec 22 01:18:11 2019 [1488] /bin/ip link set dev tun0 up mtu 1500

    Sun Dec 22 01:18:11 2019 [1488] /bin/ip addr add dev tun0 10.81.234.5/24 broadcast 10.81.234.255

    Sun Dec 22 01:18:11 2019 [1488] /bin/ip -6 addr add 2001:db8::1:0/64 dev tun0

    Sun Dec 22 01:18:11 2019 [1488] CSC service status updated to RUNNING

    Sun Dec 22 01:18:11 2019 [1488] Listening for incoming TCP connection on [undef]

    Sun Dec 22 01:18:11 2019 [1488] TCPv6_SERVER link local (bound): [undef]

    Sun Dec 22 01:18:11 2019 [1488] TCPv6_SERVER link remote: [undef]

    Sun Dec 22 01:18:11 2019 [1488] MULTI: multi_init called, r=256 v=256

    Sun Dec 22 01:18:11 2019 [1488] IFCONFIG POOL IPv6: (IPv4) size=50, size_ipv6=65536, netbits=64, base_ipv6=2001:db8::1:1

    Sun Dec 22 01:18:11 2019 [1488] IFCONFIG POOL: base=10.81.234.6 size=50, ipv6=1

    Sun Dec 22 01:18:11 2019 [1488] IFCONFIG POOL LIST

    Sun Dec 22 01:18:11 2019 [1488] MULTI: TCP INIT maxclients=5000 maxevents=5004

    Sun Dec 22 01:18:11 2019 [1488] Initialization Sequence Completed

    Sun Dec 22 02:32:31 2019 [1488] TCP connection established with [AF_INET6]::ffff:139.162.116.230:52608

    Sun Dec 22 02:32:31 2019 [1488] ::ffff:139.162.116.230 WARNING: Bad encapsulated packet length from peer (18245), which must be > 0 and <= 1572 -- please ensure that --tun-mtu or --link-mtu is equal on both peers -- this condition could also indicate a possible active attack on the TCP link -- [Attempting restart...]

    Sun Dec 22 02:32:31 2019 [1488] ::ffff:139.162.116.230 Connection reset, restarting [0]

    Sun Dec 22 02:32:31 2019 [1488] ::ffff:139.162.116.230 SIGUSR1[soft,connection-reset] received, client-instance restarting

    Sun Dec 22 14:05:36 2019 [1488] Closing TUN/TAP interface

    Sun Dec 22 14:05:36 2019 [1488] /bin/ip addr del dev tun0 10.81.234.5/24

    Sun Dec 22 14:05:36 2019 [1488] /bin/ip -6 addr del 2001:db8::1:0/64 dev tun0

    Sun Dec 22 14:05:37 2019 [1488] PLUGIN_CLOSE: /lib/openvpn-plugin-utm.so

    Sun Dec 22 14:05:37 2019 [1488] SIGTERM[hard,] received, process exiting

    Sun Dec 22 14:05:41 2019 [32378] OpenVPN 2.3.6 i486-openwrt-linux-gnu [SSL (OpenSSL)] [LZO] [EPOLL] [MH] [IPv6] built on Nov  1 2019

    Sun Dec 22 14:05:41 2019 [32378] library versions: OpenSSL 1.0.2k-fips  26 Jan 2017, LZO 2.09

    Sun Dec 22 14:05:41 2019 [32378] MANAGEMENT: client_uid=0

    Sun Dec 22 14:05:41 2019 [32378] MANAGEMENT: unix domain socket listening on /tmp/openvpn_mgmt

    /scripts/vpn/sslvpn/user-cleanup.sh: line 4: DELETE: not found

    Sun Dec 22 14:05:41 2019 [32378] cleanup success

    Sun Dec 22 14:05:41 2019 [32378] WARNING: using --duplicate-cn and --client-config-dir together is probably not what you want

    Sun Dec 22 14:05:41 2019 [32378] WARNING: --ifconfig-pool-persist will not work with --duplicate-cn

    Sun Dec 22 14:05:41 2019 [32378] NOTE: the current --script-security setting may allow this configuration to call user-defined scripts

    grhandle=0x9ce9270

    Authentication server 127.0.0.1 gave login response code 2

    Sun Dec 22 14:05:41 2019 [32378] PLUGIN_INIT: POST /lib/openvpn-plugin-utm.so '[/lib/openvpn-plugin-utm.so]' intercepted=PLUGIN_AUTH_USER_PASS_VERIFY|PLUGIN_CLIENT_CONNECT|PLUGIN_CLIENT_DISCONNECT

    Sun Dec 22 14:05:41 2019 [32378] Diffie-Hellman initialized with 2048 bit key

    Sun Dec 22 14:05:41 2019 [32378] WARNING: file '/conf/certificate/private/ApplianceCertificate.key' is group or others accessible

    Sun Dec 22 14:05:41 2019 [32378] WARNING: experimental option --capath /conf/certificate/openvpn

    Sun Dec 22 14:05:41 2019 [32378] Socket Buffers: R=[87380->131072] S=[16384->131072]

    Sun Dec 22 14:05:41 2019 [32378] TUN/TAP device tun0 opened

    Sun Dec 22 14:05:41 2019 [32378] TUN/TAP TX queue length set to 100

    Sun Dec 22 14:05:41 2019 [32378] do_ifconfig, tt->ipv6=1, tt->did_ifconfig_ipv6_setup=1

    Sun Dec 22 14:05:41 2019 [32378] /bin/ip link set dev tun0 up mtu 1500

    Sun Dec 22 14:05:41 2019 [32378] /bin/ip addr add dev tun0 10.81.234.5/24 broadcast 10.81.234.255

    Sun Dec 22 14:05:41 2019 [32378] /bin/ip -6 addr add 2001:db8::1:0/64 dev tun0

    Sun Dec 22 14:05:41 2019 [32378] CSC service status updated to RUNNING

    Sun Dec 22 14:05:41 2019 [32378] Listening for incoming TCP connection on [undef]

    Sun Dec 22 14:05:41 2019 [32378] TCPv6_SERVER link local (bound): [undef]

    Sun Dec 22 14:05:41 2019 [32378] TCPv6_SERVER link remote: [undef]

    Sun Dec 22 14:05:41 2019 [32378] MULTI: multi_init called, r=256 v=256

    Sun Dec 22 14:05:41 2019 [32378] IFCONFIG POOL IPv6: (IPv4) size=50, size_ipv6=65536, netbits=64, base_ipv6=2001:db8::1:1

    Sun Dec 22 14:05:41 2019 [32378] IFCONFIG POOL: base=10.81.234.6 size=50, ipv6=1

    Sun Dec 22 14:05:41 2019 [32378] IFCONFIG POOL LIST

    Sun Dec 22 14:05:41 2019 [32378] MULTI: TCP INIT maxclients=5000 maxevents=5004

    Sun Dec 22 14:05:41 2019 [32378] Initialization Sequence Completed

    Sun Dec 22 14:07:48 2019 [32378] Closing TUN/TAP interface

    Sun Dec 22 14:07:48 2019 [32378] /bin/ip addr del dev tun0 10.81.234.5/24

    Sun Dec 22 14:07:48 2019 [32378] /bin/ip -6 addr del 2001:db8::1:0/64 dev tun0

    Sun Dec 22 14:07:48 2019 [32378] PLUGIN_CLOSE: /lib/openvpn-plugin-utm.so

    Sun Dec 22 14:07:48 2019 [32378] SIGTERM[hard,] received, process exiting

    Sun Dec 22 14:07:52 2019 [32678] OpenVPN 2.3.6 i486-openwrt-linux-gnu [SSL (OpenSSL)] [LZO] [EPOLL] [MH] [IPv6] built on Nov  1 2019

    Sun Dec 22 14:07:52 2019 [32678] library versions: OpenSSL 1.0.2k-fips  26 Jan 2017, LZO 2.09

    Sun Dec 22 14:07:52 2019 [32678] MANAGEMENT: client_uid=0

    Sun Dec 22 14:07:52 2019 [32678] MANAGEMENT: unix domain socket listening on /tmp/openvpn_mgmt

    /scripts/vpn/sslvpn/user-cleanup.sh: line 4: DELETE: not found

    Sun Dec 22 14:07:52 2019 [32678] cleanup success

    Sun Dec 22 14:07:52 2019 [32678] WARNING: using --duplicate-cn and --client-config-dir together is probably not what you want

    Sun Dec 22 14:07:52 2019 [32678] WARNING: --ifconfig-pool-persist will not work with --duplicate-cn

    Sun Dec 22 14:07:52 2019 [32678] NOTE: the current --script-security setting may allow this configuration to call user-defined scripts

    grhandle=0x84d2270

    Authentication server 127.0.0.1 gave login response code 2

    Sun Dec 22 14:07:52 2019 [32678] PLUGIN_INIT: POST /lib/openvpn-plugin-utm.so '[/lib/openvpn-plugin-utm.so]' intercepted=PLUGIN_AUTH_USER_PASS_VERIFY|PLUGIN_CLIENT_CONNECT|PLUGIN_CLIENT_DISCONNECT

    Sun Dec 22 14:07:52 2019 [32678] Diffie-Hellman initialized with 2048 bit key

    Sun Dec 22 14:07:52 2019 [32678] WARNING: file '/conf/certificate/private/ApplianceCertificate.key' is group or others accessible

    Sun Dec 22 14:07:52 2019 [32678] WARNING: experimental option --capath /conf/certificate/openvpn

    Sun Dec 22 14:07:52 2019 [32678] Socket Buffers: R=[87380->131072] S=[16384->131072]

    Sun Dec 22 14:07:52 2019 [32678] TUN/TAP device tun0 opened

    Sun Dec 22 14:07:52 2019 [32678] TUN/TAP TX queue length set to 100

    Sun Dec 22 14:07:52 2019 [32678] do_ifconfig, tt->ipv6=1, tt->did_ifconfig_ipv6_setup=1

    Sun Dec 22 14:07:52 2019 [32678] /bin/ip link set dev tun0 up mtu 1500

    Sun Dec 22 14:07:52 2019 [32678] /bin/ip addr add dev tun0 10.81.234.5/24 broadcast 10.81.234.255

    Sun Dec 22 14:07:52 2019 [32678] /bin/ip -6 addr add 2001:db8::1:0/64 dev tun0

    Sun Dec 22 14:07:52 2019 [32678] CSC service status updated to RUNNING

    Sun Dec 22 14:07:52 2019 [32678] Listening for incoming TCP connection on [undef]

    Sun Dec 22 14:07:52 2019 [32678] TCPv6_SERVER link local (bound): [undef]

    Sun Dec 22 14:07:52 2019 [32678] TCPv6_SERVER link remote: [undef]

    Sun Dec 22 14:07:52 2019 [32678] MULTI: multi_init called, r=256 v=256

    Sun Dec 22 14:07:52 2019 [32678] IFCONFIG POOL IPv6: (IPv4) size=50, size_ipv6=65536, netbits=64, base_ipv6=2001:db8::1:1

    Sun Dec 22 14:07:52 2019 [32678] IFCONFIG POOL: base=10.81.234.6 size=50, ipv6=1

    Sun Dec 22 14:07:52 2019 [32678] IFCONFIG POOL LIST

    Sun Dec 22 14:07:52 2019 [32678] MULTI: TCP INIT maxclients=5000 maxevents=5004

    Sun Dec 22 14:07:52 2019 [32678] Initialization Sequence Completed

    Sun Dec 22 15:04:28 2019 [32678] TCP connection established with [AF_INET6]::ffff:184.105.139.69:59512

    Sun Dec 22 15:04:28 2019 [32678] ::ffff:184.105.139.69 WARNING: Bad encapsulated packet length from peer (5635), which must be > 0 and <= 1572 -- please ensure that --tun-mtu or --link-mtu is equal on both peers -- this condition could also indicate a possible active attack on the TCP link -- [Attempting restart...]

    Sun Dec 22 15:04:28 2019 [32678] ::ffff:184.105.139.69 Connection reset, restarting [0]

    Sun Dec 22 15:04:28 2019 [32678] ::ffff:184.105.139.69 SIGUSR1[soft,connection-reset] received, client-instance restarting

    Sun Dec 22 17:54:24 2019 [32678] TCP connection established with [AF_INET6]::ffff:198.199.98.246:33023

    Sun Dec 22 17:54:24 2019 [32678] ::ffff:198.199.98.246 Connection reset, restarting [0]

    Sun Dec 22 17:54:24 2019 [32678] ::ffff:198.199.98.246 SIGUSR1[soft,connection-reset] received, client-instance restarting

    Sun Dec 22 18:14:55 2019 [32678] TCP connection established with [AF_INET6]::ffff:88.198.46.51:32932

    Sun Dec 22 18:14:55 2019 [32678] ::ffff:88.198.46.51 Connection reset, restarting [0]

    Sun Dec 22 18:14:55 2019 [32678] ::ffff:88.198.46.51 SIGUSR1[soft,connection-reset] received, client-instance restarting

    Sun Dec 22 18:15:21 2019 [32678] TCP connection established with [AF_INET6]::ffff:81.240.98.110:49766

    Sun Dec 22 18:15:21 2019 [32678] ::ffff:81.240.98.110 WARNING: Bad encapsulated packet length from peer (18245), which must be > 0 and <= 1572 -- please ensure that --tun-mtu or --link-mtu is equal on both peers -- this condition could also indicate a possible active attack on the TCP link -- [Attempting restart...]

    Sun Dec 22 18:15:21 2019 [32678] ::ffff:81.240.98.110 Connection reset, restarting [0]

    Sun Dec 22 18:15:21 2019 [32678] ::ffff:81.240.98.110 SIGUSR1[soft,connection-reset] received, client-instance restarting

    Sun Dec 22 18:15:21 2019 [32678] TCP connection established with [AF_INET6]::ffff:81.240.98.110:49768

    Sun Dec 22 18:15:21 2019 [32678] ::ffff:81.240.98.110 WARNING: Bad encapsulated packet length from peer (18245), which must be > 0 and <= 1572 -- please ensure that --tun-mtu or --link-mtu is equal on both peers -- this condition could also indicate a possible active attack on the TCP link -- [Attempting restart...]

    Sun Dec 22 18:15:21 2019 [32678] ::ffff:81.240.98.110 Connection reset, restarting [0]

    Sun Dec 22 18:15:21 2019 [32678] ::ffff:81.240.98.110 SIGUSR1[soft,connection-reset] received, client-instance restarting

    Sun Dec 22 18:15:24 2019 [32678] TCP connection established with [AF_INET6]::ffff:81.240.98.110:49770

    Sun Dec 22 18:15:24 2019 [32678] ::ffff:81.240.98.110 WARNING: Bad encapsulated packet length from peer (5635), which must be > 0 and <= 1572 -- please ensure that --tun-mtu or --link-mtu is equal on both peers -- this condition could also indicate a possible active attack on the TCP link -- [Attempting restart...]

    Sun Dec 22 18:15:24 2019 [32678] ::ffff:81.240.98.110 Connection reset, restarting [0]

    Sun Dec 22 18:15:24 2019 [32678] ::ffff:81.240.98.110 SIGUSR1[soft,connection-reset] received, client-instance restarting

    Sun Dec 22 18:15:26 2019 [32678] TCP connection established with [AF_INET6]::ffff:81.240.98.110:49773

    Sun Dec 22 18:15:26 2019 [32678] ::ffff:81.240.98.110 WARNING: Bad encapsulated packet length from peer (5635), which must be > 0 and <= 1572 -- please ensure that --tun-mtu or --link-mtu is equal on both peers -- this condition could also indicate a possible active attack on the TCP link -- [Attempting restart...]

    Sun Dec 22 18:15:26 2019 [32678] ::ffff:81.240.98.110 Connection reset, restarting [0]

    Sun Dec 22 18:15:26 2019 [32678] ::ffff:81.240.98.110 SIGUSR1[soft,connection-reset] received, client-instance restarting

    Sun Dec 22 18:15:27 2019 [32678] TCP connection established with [AF_INET6]::ffff:81.240.98.110:49775

    Sun Dec 22 18:15:27 2019 [32678] ::ffff:81.240.98.110 WARNING: Bad encapsulated packet length from peer (5635), which must be > 0 and <= 1572 -- please ensure that --tun-mtu or --link-mtu is equal on both peers -- this condition could also indicate a possible active attack on the TCP link -- [Attempting restart...]

    Sun Dec 22 18:15:27 2019 [32678] ::ffff:81.240.98.110 Connection reset, restarting [0]

    Sun Dec 22 18:15:27 2019 [32678] ::ffff:81.240.98.110 SIGUSR1[soft,connection-reset] received, client-instance restarting

    Sun Dec 22 18:15:28 2019 [32678] TCP connection established with [AF_INET6]::ffff:81.240.98.110:49777

    Sun Dec 22 18:15:28 2019 [32678] ::ffff:81.240.98.110 WARNING: Bad encapsulated packet length from peer (18245), which must be > 0 and <= 1572 -- please ensure that --tun-mtu or --link-mtu is equal on both peers -- this condition could also indicate a possible active attack on the TCP link -- [Attempting restart...]

    Sun Dec 22 18:15:28 2019 [32678] ::ffff:81.240.98.110 Connection reset, restarting [0]

    Sun Dec 22 18:15:28 2019 [32678] ::ffff:81.240.98.110 SIGUSR1[soft,connection-reset] received, client-instance restarting

    Sun Dec 22 18:15:29 2019 [32678] TCP connection established with [AF_INET6]::ffff:81.240.98.110:49779

    Sun Dec 22 18:15:29 2019 [32678] ::ffff:81.240.98.110 WARNING: Bad encapsulated packet length from peer (18245), which must be > 0 and <= 1572 -- please ensure that --tun-mtu or --link-mtu is equal on both peers -- this condition could also indicate a possible active attack on the TCP link -- [Attempting restart...]

    Sun Dec 22 18:15:29 2019 [32678] ::ffff:81.240.98.110 Connection reset, restarting [0]

    Sun Dec 22 18:15:29 2019 [32678] ::ffff:81.240.98.110 SIGUSR1[soft,connection-reset] received, client-instance restarting

    Sun Dec 22 18:15:29 2019 [32678] TCP connection established with [AF_INET6]::ffff:81.240.98.110:49781

    Sun Dec 22 18:15:29 2019 [32678] ::ffff:81.240.98.110 WARNING: Bad encapsulated packet length from peer (18245), which must be > 0 and <= 1572 -- please ensure that --tun-mtu or --link-mtu is equal on both peers -- this condition could also indicate a possible active attack on the TCP link -- [Attempting restart...]

    Sun Dec 22 18:15:29 2019 [32678] ::ffff:81.240.98.110 Connection reset, restarting [0]

    Sun Dec 22 18:15:29 2019 [32678] ::ffff:81.240.98.110 SIGUSR1[soft,connection-reset] received, client-instance restarting

    Sun Dec 22 18:15:35 2019 [32678] TCP connection established with [AF_INET6]::ffff:81.240.98.110:49784

    Sun Dec 22 18:15:35 2019 [32678] ::ffff:81.240.98.110 WARNING: Bad encapsulated packet length from peer (18245), which must be > 0 and <= 1572 -- please ensure that --tun-mtu or --link-mtu is equal on both peers -- this condition could also indicate a possible active attack on the TCP link -- [Attempting restart...]

    Sun Dec 22 18:15:35 2019 [32678] ::ffff:81.240.98.110 Connection reset, restarting [0]

    Sun Dec 22 18:15:35 2019 [32678] ::ffff:81.240.98.110 SIGUSR1[soft,connection-reset] received, client-instance restarting

    Sun Dec 22 18:23:26 2019 [32678] TCP connection established with [AF_INET6]::ffff:85.10.218.146:53644

    Sun Dec 22 18:23:28 2019 [32678] ::ffff:85.10.218.146 Connection reset, restarting [0]

    Sun Dec 22 18:23:28 2019 [32678] ::ffff:85.10.218.146 SIGUSR1[soft,connection-reset] received, client-instance restarting

    XG106_XN01_SFOS 17.5.9 MR-9#

  • I called a "senior sophos friend" and I made a user for him to test.

    He was able to connect to my network without any problem. 

    So i tried to connect through a hotspot from my mobile and it's working. 

    2019-12-22 18:47:39.495174 Initialization Sequence Completed

    2019-12-22 18:47:39.495237 MANAGEMENT: >STATE:1577036859,CONNECTED,SUCCESS,10.81.234.6,84.197.138.2,8443,172.20.10.11,53107

    This error took me 50 hours to solve lol :-D