This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Remote Access and Log Review

Hello Sophos Comminity,

My connection is :  DSL Modem > Sophos UTM9 > Internal Network. (Opened port 22 on DSL Modem)

i have configured the remote acces for one User successfully.

Yesterday checked the ssl vpn log and find some curious aktivity.

Can somebody make a quick log review and tell me if this were some Hacking trys and if these were successfull or not.

What are the Current Parameter Settings in the log file ? Who can/could see this?

Regards Marco

(closed port 22 for now :) )

2018:07:24-00:00:02 109 openvpn[10973]: MANAGEMENT: Client connected from /var/run/openvpn_mgmt
2018:07:24-00:00:02 109 openvpn[10973]: MANAGEMENT: CMD 'status -1'
2018:07:24-00:00:12 109 openvpn[10973]: MANAGEMENT: Client disconnected
2018:07:24-00:32:22 109 openvpn[10973]: MULTI: multi_create_instance called
2018:07:24-00:32:22 109 openvpn[10973]: Re-using SSL/TLS context
2018:07:24-00:32:22 109 openvpn[10973]: LZO compression initialized
2018:07:24-00:32:22 109 openvpn[10973]: Control Channel MTU parms [ L:1572 D:140 EF:40 EB:0 ET:0 EL:0 ]
2018:07:24-00:32:22 109 openvpn[10973]: Data Channel MTU parms [ L:1572 D:1450 EF:72 EB:135 ET:0 EL:0 AF:3/1 ]
2018:07:24-00:32:22 109 openvpn[10973]: Local Options String: 'V4,dev-type tun,link-mtu 1572,tun-mtu 1500,proto TCPv4_SERVER,comp-lzo,cipher AES-256-CBC,auth SHA256,keysize 256,key-method 2,tls-server'
2018:07:24-00:32:22 109 openvpn[10973]: Expected Remote Options String: 'V4,dev-type tun,link-mtu 1572,tun-mtu 1500,proto TCPv4_CLIENT,comp-lzo,cipher AES-256-CBC,auth SHA256,keysize 256,key-method 2,tls-client'
2018:07:24-00:32:22 109 openvpn[10973]: Local Options hash (VER=V4): '372232dd'
2018:07:24-00:32:22 109 openvpn[10973]: Expected Remote Options hash (VER=V4): '2ba0d2f5'
2018:07:24-00:32:22 109 openvpn[10973]: TCP connection established with [AF_INET]188.246.234.62:51852 (via [AF_INET]192.168.0.11:443)
2018:07:24-00:32:22 109 openvpn[10973]: TCPv4_SERVER link local: [undef]
2018:07:24-00:32:22 109 openvpn[10973]: TCPv4_SERVER link remote: [AF_INET]188.246.234.62:51852
2018:07:24-00:32:22 109 openvpn[10973]: 188.246.234.62:51852 Non-OpenVPN client protocol detected
2018:07:24-00:32:22 109 openvpn[10973]: 188.246.234.62:51852 SIGTERM[soft,port-share-redirect] received, client-instance exiting
2018:07:24-00:32:22 109 openvpn[10973]: TCP/UDP: Closing socket
2018:07:24-00:37:36 109 openvpn[10973]: MULTI: multi_create_instance called
2018:07:24-00:37:36 109 openvpn[10973]: Re-using SSL/TLS context
2018:07:24-00:37:36 109 openvpn[10973]: LZO compression initialized
2018:07:24-00:37:36 109 openvpn[10973]: Control Channel MTU parms [ L:1572 D:140 EF:40 EB:0 ET:0 EL:0 ]
2018:07:24-00:37:36 109 openvpn[10973]: Data Channel MTU parms [ L:1572 D:1450 EF:72 EB:135 ET:0 EL:0 AF:3/1 ]
2018:07:24-00:37:36 109 openvpn[10973]: Local Options String: 'V4,dev-type tun,link-mtu 1572,tun-mtu 1500,proto TCPv4_SERVER,comp-lzo,cipher AES-256-CBC,auth SHA256,keysize 256,key-method 2,tls-server'
2018:07:24-00:37:36 109 openvpn[10973]: Expected Remote Options String: 'V4,dev-type tun,link-mtu 1572,tun-mtu 1500,proto TCPv4_CLIENT,comp-lzo,cipher AES-256-CBC,auth SHA256,keysize 256,key-method 2,tls-client'
2018:07:24-00:37:36 109 openvpn[10973]: Local Options hash (VER=V4): '372232dd'
2018:07:24-00:37:36 109 openvpn[10973]: Expected Remote Options hash (VER=V4): '2ba0d2f5'
2018:07:24-00:37:36 109 openvpn[10973]: TCP connection established with [AF_INET]188.246.234.62:42748 (via [AF_INET]192.168.0.11:443)
2018:07:24-00:37:36 109 openvpn[10973]: TCPv4_SERVER link local: [undef]
2018:07:24-00:37:36 109 openvpn[10973]: TCPv4_SERVER link remote: [AF_INET]188.246.234.62:42748
2018:07:24-00:37:36 109 openvpn[10973]: 188.246.234.62:42748 Non-OpenVPN client protocol detected
2018:07:24-00:37:36 109 openvpn[10973]: 188.246.234.62:42748 SIGTERM[soft,port-share-redirect] received, client-instance exiting
2018:07:24-00:37:36 109 openvpn[10973]: TCP/UDP: Closing socket
2018:07:24-03:37:15 109 openvpn[10973]: MULTI: multi_create_instance called
2018:07:24-03:37:15 109 openvpn[10973]: Re-using SSL/TLS context
2018:07:24-03:37:15 109 openvpn[10973]: LZO compression initialized
2018:07:24-03:37:15 109 openvpn[10973]: Control Channel MTU parms [ L:1572 D:140 EF:40 EB:0 ET:0 EL:0 ]
2018:07:24-03:37:15 109 openvpn[10973]: Data Channel MTU parms [ L:1572 D:1450 EF:72 EB:135 ET:0 EL:0 AF:3/1 ]
2018:07:24-03:37:15 109 openvpn[10973]: Local Options String: 'V4,dev-type tun,link-mtu 1572,tun-mtu 1500,proto TCPv4_SERVER,comp-lzo,cipher AES-256-CBC,auth SHA256,keysize 256,key-method 2,tls-server'
2018:07:24-03:37:15 109 openvpn[10973]: Expected Remote Options String: 'V4,dev-type tun,link-mtu 1572,tun-mtu 1500,proto TCPv4_CLIENT,comp-lzo,cipher AES-256-CBC,auth SHA256,keysize 256,key-method 2,tls-client'
2018:07:24-03:37:15 109 openvpn[10973]: Local Options hash (VER=V4): '372232dd'
2018:07:24-03:37:15 109 openvpn[10973]: Expected Remote Options hash (VER=V4): '2ba0d2f5'
2018:07:24-03:37:15 109 openvpn[10973]: TCP connection established with [AF_INET]168.1.128.38:56939 (via [AF_INET]192.168.0.11:443)
2018:07:24-03:37:15 109 openvpn[10973]: TCPv4_SERVER link local: [undef]
2018:07:24-03:37:15 109 openvpn[10973]: TCPv4_SERVER link remote: [AF_INET]168.1.128.38:56939
2018:07:24-03:37:15 109 openvpn[10973]: 168.1.128.38:56939 Non-OpenVPN client protocol detected
2018:07:24-03:37:15 109 openvpn[10973]: 168.1.128.38:56939 SIGTERM[soft,port-share-redirect] received, client-instance exiting
2018:07:24-03:37:15 109 openvpn[10973]: TCP/UDP: Closing socket
2018:07:24-07:11:49 109 openvpn[10973]: MULTI: multi_create_instance called
2018:07:24-07:11:49 109 openvpn[10973]: Re-using SSL/TLS context
2018:07:24-07:11:49 109 openvpn[10973]: LZO compression initialized
2018:07:24-07:11:49 109 openvpn[10973]: Control Channel MTU parms [ L:1572 D:140 EF:40 EB:0 ET:0 EL:0 ]
2018:07:24-07:11:49 109 openvpn[10973]: Data Channel MTU parms [ L:1572 D:1450 EF:72 EB:135 ET:0 EL:0 AF:3/1 ]
2018:07:24-07:11:49 109 openvpn[10973]: Local Options String: 'V4,dev-type tun,link-mtu 1572,tun-mtu 1500,proto TCPv4_SERVER,comp-lzo,cipher AES-256-CBC,auth SHA256,keysize 256,key-method 2,tls-server'
2018:07:24-07:11:49 109 openvpn[10973]: Expected Remote Options String: 'V4,dev-type tun,link-mtu 1572,tun-mtu 1500,proto TCPv4_CLIENT,comp-lzo,cipher AES-256-CBC,auth SHA256,keysize 256,key-method 2,tls-client'
2018:07:24-07:11:49 109 openvpn[10973]: Local Options hash (VER=V4): '372232dd'
2018:07:24-07:11:49 109 openvpn[10973]: Expected Remote Options hash (VER=V4): '2ba0d2f5'
2018:07:24-07:11:49 109 openvpn[10973]: TCP connection established with [AF_INET]196.52.43.84:6666 (via [AF_INET]192.168.0.11:443)
2018:07:24-07:11:49 109 openvpn[10973]: TCPv4_SERVER link local: [undef]
2018:07:24-07:11:49 109 openvpn[10973]: TCPv4_SERVER link remote: [AF_INET]196.52.43.84:6666
2018:07:24-07:11:51 109 openvpn[10973]: 196.52.43.84:6666 Non-OpenVPN client protocol detected
2018:07:24-07:11:51 109 openvpn[10973]: 196.52.43.84:6666 SIGTERM[soft,port-share-redirect] received, client-instance exiting
2018:07:24-07:11:51 109 openvpn[10973]: TCP/UDP: Closing socket
2018:07:24-07:37:28 109 openvpn[10973]: MULTI: multi_create_instance called
2018:07:24-07:37:28 109 openvpn[10973]: Re-using SSL/TLS context
2018:07:24-07:37:28 109 openvpn[10973]: LZO compression initialized
2018:07:24-07:37:28 109 openvpn[10973]: Control Channel MTU parms [ L:1572 D:140 EF:40 EB:0 ET:0 EL:0 ]
2018:07:24-07:37:28 109 openvpn[10973]: Data Channel MTU parms [ L:1572 D:1450 EF:72 EB:135 ET:0 EL:0 AF:3/1 ]
2018:07:24-07:37:28 109 openvpn[10973]: Local Options String: 'V4,dev-type tun,link-mtu 1572,tun-mtu 1500,proto TCPv4_SERVER,comp-lzo,cipher AES-256-CBC,auth SHA256,keysize 256,key-method 2,tls-server'
2018:07:24-07:37:28 109 openvpn[10973]: Expected Remote Options String: 'V4,dev-type tun,link-mtu 1572,tun-mtu 1500,proto TCPv4_CLIENT,comp-lzo,cipher AES-256-CBC,auth SHA256,keysize 256,key-method 2,tls-client'
2018:07:24-07:37:28 109 openvpn[10973]: Local Options hash (VER=V4): '372232dd'
2018:07:24-07:37:28 109 openvpn[10973]: Expected Remote Options hash (VER=V4): '2ba0d2f5'
2018:07:24-07:37:28 109 openvpn[10973]: TCP connection established with [AF_INET]218.211.168.176:50720 (via [AF_INET]192.168.0.11:443)
2018:07:24-07:37:28 109 openvpn[10973]: TCPv4_SERVER link local: [undef]
2018:07:24-07:37:28 109 openvpn[10973]: TCPv4_SERVER link remote: [AF_INET]218.211.168.176:50720
2018:07:24-07:37:28 109 openvpn[10973]: 218.211.168.176:50720 Non-OpenVPN client protocol detected
2018:07:24-07:37:28 109 openvpn[10973]: 218.211.168.176:50720 SIGTERM[soft,port-share-redirect] received, client-instance exiting
2018:07:24-07:37:28 109 openvpn[10973]: TCP/UDP: Closing socket
2018:07:24-08:49:28 109 openvpn[10973]: MULTI: multi_create_instance called
2018:07:24-08:49:28 109 openvpn[10973]: Re-using SSL/TLS context
2018:07:24-08:49:28 109 openvpn[10973]: LZO compression initialized
2018:07:24-08:49:28 109 openvpn[10973]: Control Channel MTU parms [ L:1572 D:140 EF:40 EB:0 ET:0 EL:0 ]
2018:07:24-08:49:28 109 openvpn[10973]: Data Channel MTU parms [ L:1572 D:1450 EF:72 EB:135 ET:0 EL:0 AF:3/1 ]
2018:07:24-08:49:28 109 openvpn[10973]: Local Options String: 'V4,dev-type tun,link-mtu 1572,tun-mtu 1500,proto TCPv4_SERVER,comp-lzo,cipher AES-256-CBC,auth SHA256,keysize 256,key-method 2,tls-server'
2018:07:24-08:49:28 109 openvpn[10973]: Expected Remote Options String: 'V4,dev-type tun,link-mtu 1572,tun-mtu 1500,proto TCPv4_CLIENT,comp-lzo,cipher AES-256-CBC,auth SHA256,keysize 256,key-method 2,tls-client'
2018:07:24-08:49:28 109 openvpn[10973]: Local Options hash (VER=V4): '372232dd'
2018:07:24-08:49:28 109 openvpn[10973]: Expected Remote Options hash (VER=V4): '2ba0d2f5'
2018:07:24-08:49:28 109 openvpn[10973]: TCP connection established with [AF_INET]71.6.202.204:37312 (via [AF_INET]192.168.0.11:443)
2018:07:24-08:49:28 109 openvpn[10973]: TCPv4_SERVER link local: [undef]
2018:07:24-08:49:28 109 openvpn[10973]: TCPv4_SERVER link remote: [AF_INET]71.6.202.204:37312
2018:07:24-08:49:28 109 openvpn[10973]: 71.6.202.204:37312 Non-OpenVPN client protocol detected
2018:07:24-08:49:28 109 openvpn[10973]: 71.6.202.204:37312 SIGTERM[soft,port-share-redirect] received, client-instance exiting
2018:07:24-08:49:28 109 openvpn[10973]: TCP/UDP: Closing socket
2018:07:24-09:16:05 109 openvpn[10973]: MULTI: multi_create_instance called
2018:07:24-09:16:05 109 openvpn[10973]: Re-using SSL/TLS context
2018:07:24-09:16:05 109 openvpn[10973]: LZO compression initialized
2018:07:24-09:16:05 109 openvpn[10973]: Control Channel MTU parms [ L:1572 D:140 EF:40 EB:0 ET:0 EL:0 ]
2018:07:24-09:16:05 109 openvpn[10973]: Data Channel MTU parms [ L:1572 D:1450 EF:72 EB:135 ET:0 EL:0 AF:3/1 ]
2018:07:24-09:16:05 109 openvpn[10973]: Local Options String: 'V4,dev-type tun,link-mtu 1572,tun-mtu 1500,proto TCPv4_SERVER,comp-lzo,cipher AES-256-CBC,auth SHA256,keysize 256,key-method 2,tls-server'
2018:07:24-09:16:05 109 openvpn[10973]: Expected Remote Options String: 'V4,dev-type tun,link-mtu 1572,tun-mtu 1500,proto TCPv4_CLIENT,comp-lzo,cipher AES-256-CBC,auth SHA256,keysize 256,key-method 2,tls-client'
2018:07:24-09:16:05 109 openvpn[10973]: Local Options hash (VER=V4): '372232dd'
2018:07:24-09:16:05 109 openvpn[10973]: Expected Remote Options hash (VER=V4): '2ba0d2f5'
2018:07:24-09:16:05 109 openvpn[10973]: TCP connection established with [AF_INET]46.29.161.74:42954 (via [AF_INET]192.168.0.11:443)
2018:07:24-09:16:05 109 openvpn[10973]: TCPv4_SERVER link local: [undef]
2018:07:24-09:16:05 109 openvpn[10973]: TCPv4_SERVER link remote: [AF_INET]46.29.161.74:42954
2018:07:24-09:16:06 109 openvpn[10973]: 46.29.161.74:42954 Non-OpenVPN client protocol detected
2018:07:24-09:16:06 109 openvpn[10973]: 46.29.161.74:42954 SIGTERM[soft,port-share-redirect] received, client-instance exiting
2018:07:24-09:16:06 109 openvpn[10973]: TCP/UDP: Closing socket
2018:07:24-10:25:46 109 openvpn[10973]: MULTI: multi_create_instance called
2018:07:24-10:25:46 109 openvpn[10973]: Re-using SSL/TLS context
2018:07:24-10:25:46 109 openvpn[10973]: LZO compression initialized
2018:07:24-10:25:46 109 openvpn[10973]: Control Channel MTU parms [ L:1572 D:140 EF:40 EB:0 ET:0 EL:0 ]
2018:07:24-10:25:46 109 openvpn[10973]: Data Channel MTU parms [ L:1572 D:1450 EF:72 EB:135 ET:0 EL:0 AF:3/1 ]
2018:07:24-10:25:46 109 openvpn[10973]: Local Options String: 'V4,dev-type tun,link-mtu 1572,tun-mtu 1500,proto TCPv4_SERVER,comp-lzo,cipher AES-256-CBC,auth SHA256,keysize 256,key-method 2,tls-server'
2018:07:24-10:25:46 109 openvpn[10973]: Expected Remote Options String: 'V4,dev-type tun,link-mtu 1572,tun-mtu 1500,proto TCPv4_CLIENT,comp-lzo,cipher AES-256-CBC,auth SHA256,keysize 256,key-method 2,tls-client'
2018:07:24-10:25:46 109 openvpn[10973]: Local Options hash (VER=V4): '372232dd'
2018:07:24-10:25:46 109 openvpn[10973]: Expected Remote Options hash (VER=V4): '2ba0d2f5'
2018:07:24-10:25:46 109 openvpn[10973]: TCP connection established with [AF_INET]96.126.100.87:45560 (via [AF_INET]192.168.0.11:443)
2018:07:24-10:25:46 109 openvpn[10973]: TCPv4_SERVER link local: [undef]
2018:07:24-10:25:46 109 openvpn[10973]: TCPv4_SERVER link remote: [AF_INET]96.126.100.87:45560
2018:07:24-10:25:46 109 openvpn[10973]: 96.126.100.87:45560 Non-OpenVPN client protocol detected
2018:07:24-10:25:46 109 openvpn[10973]: 96.126.100.87:45560 SIGTERM[soft,port-share-redirect] received, client-instance exiting
2018:07:24-10:25:46 109 openvpn[10973]: TCP/UDP: Closing socket
2018:07:24-11:21:07 109 openvpn[10973]: MULTI: multi_create_instance called
2018:07:24-11:21:07 109 openvpn[10973]: Re-using SSL/TLS context
2018:07:24-11:21:07 109 openvpn[10973]: LZO compression initialized
2018:07:24-11:21:07 109 openvpn[10973]: Control Channel MTU parms [ L:1572 D:140 EF:40 EB:0 ET:0 EL:0 ]
2018:07:24-11:21:07 109 openvpn[10973]: Data Channel MTU parms [ L:1572 D:1450 EF:72 EB:135 ET:0 EL:0 AF:3/1 ]
2018:07:24-11:21:07 109 openvpn[10973]: Local Options String: 'V4,dev-type tun,link-mtu 1572,tun-mtu 1500,proto TCPv4_SERVER,comp-lzo,cipher AES-256-CBC,auth SHA256,keysize 256,key-method 2,tls-server'
2018:07:24-11:21:07 109 openvpn[10973]: Expected Remote Options String: 'V4,dev-type tun,link-mtu 1572,tun-mtu 1500,proto TCPv4_CLIENT,comp-lzo,cipher AES-256-CBC,auth SHA256,keysize 256,key-method 2,tls-client'
2018:07:24-11:21:07 109 openvpn[10973]: Local Options hash (VER=V4): '372232dd'
2018:07:24-11:21:07 109 openvpn[10973]: Expected Remote Options hash (VER=V4): '2ba0d2f5'
2018:07:24-11:21:07 109 openvpn[10973]: TCP connection established with [AF_INET]141.212.122.16:24508 (via [AF_INET]192.168.0.11:443)
2018:07:24-11:21:07 109 openvpn[10973]: TCPv4_SERVER link local: [undef]
2018:07:24-11:21:07 109 openvpn[10973]: TCPv4_SERVER link remote: [AF_INET]141.212.122.16:24508
2018:07:24-11:21:07 109 openvpn[10973]: 141.212.122.16:24508 Non-OpenVPN client protocol detected
2018:07:24-11:21:07 109 openvpn[10973]: 141.212.122.16:24508 SIGTERM[soft,port-share-redirect] received, client-instance exiting
2018:07:24-11:21:07 109 openvpn[10973]: TCP/UDP: Closing socket
2018:07:24-13:28:54 109 openvpn[10973]: MULTI: multi_create_instance called
2018:07:24-13:28:54 109 openvpn[10973]: Re-using SSL/TLS context
2018:07:24-13:28:54 109 openvpn[10973]: LZO compression initialized
2018:07:24-13:28:54 109 openvpn[10973]: Control Channel MTU parms [ L:1572 D:140 EF:40 EB:0 ET:0 EL:0 ]
2018:07:24-13:28:54 109 openvpn[10973]: Data Channel MTU parms [ L:1572 D:1450 EF:72 EB:135 ET:0 EL:0 AF:3/1 ]
2018:07:24-13:28:54 109 openvpn[10973]: Local Options String: 'V4,dev-type tun,link-mtu 1572,tun-mtu 1500,proto TCPv4_SERVER,comp-lzo,cipher AES-256-CBC,auth SHA256,keysize 256,key-method 2,tls-server'
2018:07:24-13:28:54 109 openvpn[10973]: Expected Remote Options String: 'V4,dev-type tun,link-mtu 1572,tun-mtu 1500,proto TCPv4_CLIENT,comp-lzo,cipher AES-256-CBC,auth SHA256,keysize 256,key-method 2,tls-client'
2018:07:24-13:28:54 109 openvpn[10973]: Local Options hash (VER=V4): '372232dd'
2018:07:24-13:28:54 109 openvpn[10973]: Expected Remote Options hash (VER=V4): '2ba0d2f5'
2018:07:24-13:28:54 109 openvpn[10973]: TCP connection established with [AF_INET]5.8.10.202:57708 (via [AF_INET]192.168.0.11:443)
2018:07:24-13:28:54 109 openvpn[10973]: TCPv4_SERVER link local: [undef]
2018:07:24-13:28:54 109 openvpn[10973]: TCPv4_SERVER link remote: [AF_INET]5.8.10.202:57708
2018:07:24-13:28:54 109 openvpn[10973]: 5.8.10.202:57708 Non-OpenVPN client protocol detected
2018:07:24-13:28:54 109 openvpn[10973]: 5.8.10.202:57708 SIGTERM[soft,port-share-redirect] received, client-instance exiting
2018:07:24-13:28:54 109 openvpn[10973]: TCP/UDP: Closing socket
2018:07:24-14:46:12 109 openvpn[10973]: MULTI: multi_create_instance called
2018:07:24-14:46:12 109 openvpn[10973]: Re-using SSL/TLS context
2018:07:24-14:46:12 109 openvpn[10973]: LZO compression initialized
2018:07:24-14:46:12 109 openvpn[10973]: Control Channel MTU parms [ L:1572 D:140 EF:40 EB:0 ET:0 EL:0 ]
2018:07:24-14:46:12 109 openvpn[10973]: Data Channel MTU parms [ L:1572 D:1450 EF:72 EB:135 ET:0 EL:0 AF:3/1 ]
2018:07:24-14:46:12 109 openvpn[10973]: Local Options String: 'V4,dev-type tun,link-mtu 1572,tun-mtu 1500,proto TCPv4_SERVER,comp-lzo,cipher AES-256-CBC,auth SHA256,keysize 256,key-method 2,tls-server'
2018:07:24-14:46:12 109 openvpn[10973]: Expected Remote Options String: 'V4,dev-type tun,link-mtu 1572,tun-mtu 1500,proto TCPv4_CLIENT,comp-lzo,cipher AES-256-CBC,auth SHA256,keysize 256,key-method 2,tls-client'
2018:07:24-14:46:12 109 openvpn[10973]: Local Options hash (VER=V4): '372232dd'
2018:07:24-14:46:12 109 openvpn[10973]: Expected Remote Options hash (VER=V4): '2ba0d2f5'
2018:07:24-14:46:12 109 openvpn[10973]: TCP connection established with [AF_INET]139.162.113.204:56700 (via [AF_INET]192.168.0.11:443)
2018:07:24-14:46:12 109 openvpn[10973]: TCPv4_SERVER link local: [undef]
2018:07:24-14:46:12 109 openvpn[10973]: TCPv4_SERVER link remote: [AF_INET]139.162.113.204:56700
2018:07:24-14:46:12 109 openvpn[10973]: 139.162.113.204:56700 Non-OpenVPN client protocol detected
2018:07:24-14:46:12 109 openvpn[10973]: 139.162.113.204:56700 SIGTERM[soft,port-share-redirect] received, client-instance exiting
2018:07:24-14:46:12 109 openvpn[10973]: TCP/UDP: Closing socket
2018:07:24-16:36:34 109 openvpn[10973]: MULTI: multi_create_instance called
2018:07:24-16:36:34 109 openvpn[10973]: Re-using SSL/TLS context
2018:07:24-16:36:34 109 openvpn[10973]: LZO compression initialized
2018:07:24-16:36:34 109 openvpn[10973]: Control Channel MTU parms [ L:1572 D:140 EF:40 EB:0 ET:0 EL:0 ]
2018:07:24-16:36:34 109 openvpn[10973]: Data Channel MTU parms [ L:1572 D:1450 EF:72 EB:135 ET:0 EL:0 AF:3/1 ]
2018:07:24-16:36:34 109 openvpn[10973]: Local Options String: 'V4,dev-type tun,link-mtu 1572,tun-mtu 1500,proto TCPv4_SERVER,comp-lzo,cipher AES-256-CBC,auth SHA256,keysize 256,key-method 2,tls-server'
2018:07:24-16:36:34 109 openvpn[10973]: Expected Remote Options String: 'V4,dev-type tun,link-mtu 1572,tun-mtu 1500,proto TCPv4_CLIENT,comp-lzo,cipher AES-256-CBC,auth SHA256,keysize 256,key-method 2,tls-client'
2018:07:24-16:36:34 109 openvpn[10973]: Local Options hash (VER=V4): '372232dd'
2018:07:24-16:36:34 109 openvpn[10973]: Expected Remote Options hash (VER=V4): '2ba0d2f5'
2018:07:24-16:36:34 109 openvpn[10973]: TCP connection established with [AF_INET]74.82.47.5:45344 (via [AF_INET]192.168.0.11:443)
2018:07:24-16:36:34 109 openvpn[10973]: TCPv4_SERVER link local: [undef]
2018:07:24-16:36:34 109 openvpn[10973]: TCPv4_SERVER link remote: [AF_INET]74.82.47.5:45344
2018:07:24-16:36:34 109 openvpn[10973]: 74.82.47.5:45344 Non-OpenVPN client protocol detected
2018:07:24-16:36:34 109 openvpn[10973]: 74.82.47.5:45344 SIGTERM[soft,port-share-redirect] received, client-instance exiting
2018:07:24-16:36:34 109 openvpn[10973]: TCP/UDP: Closing socket
2018:07:24-16:36:46 109 openvpn[10973]: MULTI: multi_create_instance called
2018:07:24-16:36:46 109 openvpn[10973]: Re-using SSL/TLS context
2018:07:24-16:36:46 109 openvpn[10973]: LZO compression initialized
2018:07:24-16:36:46 109 openvpn[10973]: Control Channel MTU parms [ L:1572 D:140 EF:40 EB:0 ET:0 EL:0 ]
2018:07:24-16:36:46 109 openvpn[10973]: Data Channel MTU parms [ L:1572 D:1450 EF:72 EB:135 ET:0 EL:0 AF:3/1 ]
2018:07:24-16:36:46 109 openvpn[10973]: Local Options String: 'V4,dev-type tun,link-mtu 1572,tun-mtu 1500,proto TCPv4_SERVER,comp-lzo,cipher AES-256-CBC,auth SHA256,keysize 256,key-method 2,tls-server'
2018:07:24-16:36:46 109 openvpn[10973]: Expected Remote Options String: 'V4,dev-type tun,link-mtu 1572,tun-mtu 1500,proto TCPv4_CLIENT,comp-lzo,cipher AES-256-CBC,auth SHA256,keysize 256,key-method 2,tls-client'
2018:07:24-16:36:46 109 openvpn[10973]: Local Options hash (VER=V4): '372232dd'
2018:07:24-16:36:46 109 openvpn[10973]: Expected Remote Options hash (VER=V4): '2ba0d2f5'
2018:07:24-16:36:46 109 openvpn[10973]: TCP connection established with [AF_INET]74.82.47.5:18116 (via [AF_INET]192.168.0.11:443)
2018:07:24-16:36:46 109 openvpn[10973]: TCPv4_SERVER link local: [undef]
2018:07:24-16:36:46 109 openvpn[10973]: TCPv4_SERVER link remote: [AF_INET]74.82.47.5:18116
2018:07:24-16:36:46 109 openvpn[10973]: 74.82.47.5:18116 Non-OpenVPN client protocol detected
2018:07:24-16:36:46 109 openvpn[10973]: 74.82.47.5:18116 SIGTERM[soft,port-share-redirect] received, client-instance exiting
2018:07:24-16:36:46 109 openvpn[10973]: TCP/UDP: Closing socket
2018:07:24-16:37:16 109 openvpn[10973]: MULTI: multi_create_instance called
2018:07:24-16:37:16 109 openvpn[10973]: Re-using SSL/TLS context
2018:07:24-16:37:16 109 openvpn[10973]: LZO compression initialized
2018:07:24-16:37:16 109 openvpn[10973]: Control Channel MTU parms [ L:1572 D:140 EF:40 EB:0 ET:0 EL:0 ]
2018:07:24-16:37:16 109 openvpn[10973]: Data Channel MTU parms [ L:1572 D:1450 EF:72 EB:135 ET:0 EL:0 AF:3/1 ]
2018:07:24-16:37:16 109 openvpn[10973]: Local Options String: 'V4,dev-type tun,link-mtu 1572,tun-mtu 1500,proto TCPv4_SERVER,comp-lzo,cipher AES-256-CBC,auth SHA256,keysize 256,key-method 2,tls-server'
2018:07:24-16:37:16 109 openvpn[10973]: Expected Remote Options String: 'V4,dev-type tun,link-mtu 1572,tun-mtu 1500,proto TCPv4_CLIENT,comp-lzo,cipher AES-256-CBC,auth SHA256,keysize 256,key-method 2,tls-client'
2018:07:24-16:37:16 109 openvpn[10973]: Local Options hash (VER=V4): '372232dd'
2018:07:24-16:37:16 109 openvpn[10973]: Expected Remote Options hash (VER=V4): '2ba0d2f5'
2018:07:24-16:37:16 109 openvpn[10973]: TCP connection established with [AF_INET]74.82.47.5:25406 (via [AF_INET]192.168.0.11:443)
2018:07:24-16:37:16 109 openvpn[10973]: TCPv4_SERVER link local: [undef]
2018:07:24-16:37:16 109 openvpn[10973]: TCPv4_SERVER link remote: [AF_INET]74.82.47.5:25406
2018:07:24-16:37:16 109 openvpn[10973]: 74.82.47.5:25406 Non-OpenVPN client protocol detected
2018:07:24-16:37:16 109 openvpn[10973]: 74.82.47.5:25406 SIGTERM[soft,port-share-redirect] received, client-instance exiting
2018:07:24-16:37:16 109 openvpn[10973]: TCP/UDP: Closing socket
2018:07:24-19:29:21 109 openvpn[10973]: MANAGEMENT: Client connected from /var/run/openvpn_mgmt
2018:07:24-19:29:21 109 openvpn[10973]: MANAGEMENT: CMD 'status -1'
2018:07:24-19:29:31 109 openvpn[10973]: MANAGEMENT: Client disconnected
2018:07:24-20:19:32 109 openvpn[10973]: MULTI: multi_create_instance called
2018:07:24-20:19:32 109 openvpn[10973]: Re-using SSL/TLS context
2018:07:24-20:19:32 109 openvpn[10973]: LZO compression initialized
2018:07:24-20:19:32 109 openvpn[10973]: Control Channel MTU parms [ L:1572 D:140 EF:40 EB:0 ET:0 EL:0 ]
2018:07:24-20:19:32 109 openvpn[10973]: Data Channel MTU parms [ L:1572 D:1450 EF:72 EB:135 ET:0 EL:0 AF:3/1 ]
2018:07:24-20:19:32 109 openvpn[10973]: Local Options String: 'V4,dev-type tun,link-mtu 1572,tun-mtu 1500,proto TCPv4_SERVER,comp-lzo,cipher AES-256-CBC,auth SHA256,keysize 256,key-method 2,tls-server'
2018:07:24-20:19:32 109 openvpn[10973]: Expected Remote Options String: 'V4,dev-type tun,link-mtu 1572,tun-mtu 1500,proto TCPv4_CLIENT,comp-lzo,cipher AES-256-CBC,auth SHA256,keysize 256,key-method 2,tls-client'
2018:07:24-20:19:32 109 openvpn[10973]: Local Options hash (VER=V4): '372232dd'
2018:07:24-20:19:32 109 openvpn[10973]: Expected Remote Options hash (VER=V4): '2ba0d2f5'
2018:07:24-20:19:32 109 openvpn[10973]: TCP connection established with [AF_INET]5.8.10.202:31778 (via [AF_INET]192.168.0.11:443)
2018:07:24-20:19:32 109 openvpn[10973]: TCPv4_SERVER link local: [undef]
2018:07:24-20:19:32 109 openvpn[10973]: TCPv4_SERVER link remote: [AF_INET]5.8.10.202:31778
2018:07:24-20:19:32 109 openvpn[10973]: 5.8.10.202:31778 Non-OpenVPN client protocol detected
2018:07:24-20:19:32 109 openvpn[10973]: 5.8.10.202:31778 SIGTERM[soft,port-share-redirect] received, client-instance exiting
2018:07:24-20:19:32 109 openvpn[10973]: TCP/UDP: Closing socket
2018:07:24-20:23:54 109 openvpn[10973]: TCP/UDP: Closing socket
2018:07:24-20:23:54 109 openvpn[10973]: /bin/ip route del 10.242.2.0/24 proto 41
2018:07:24-20:23:54 109 openvpn[10973]: PLUGIN_CALL: POST /usr/lib/openvpn/plugins/openvpn-plugin-utm.so/PLUGIN_DOWN status=0
2018:07:24-20:23:54 109 openvpn[10973]: Closing TUN/TAP interface
2018:07:24-20:23:54 109 openvpn[10973]: /bin/ip addr del dev tun0 local 10.242.2.1 peer 10.242.2.2
2018:07:24-20:23:54 109 openvpn[10973]: PLUGIN_CLOSE: /usr/lib/openvpn/plugins/openvpn-plugin-utm.so
2018:07:24-20:23:54 109 openvpn[10973]: SIGTERM[hard,] received, process exiting
2018:07:24-20:23:54 109 openvpn[10973]: PORT SHARE: sendmsg failed -- unable to communicate with background process (9,-1,4,5): Connection refused (errno=111)
2018:07:24-20:23:55 109 openvpn[29019]: Current Parameter Settings:
2018:07:24-20:23:55 109 openvpn[29019]: config = '/etc/openvpn/openvpn.conf'
2018:07:24-20:23:55 109 openvpn[29019]: mode = 1
2018:07:24-20:23:55 109 openvpn[29019]: persist_config = DISABLED
2018:07:24-20:23:55 109 openvpn[29019]: persist_mode = 1
2018:07:24-20:23:55 109 openvpn[29019]: show_ciphers = DISABLED
2018:07:24-20:23:55 109 openvpn[29019]: show_digests = DISABLED
2018:07:24-20:23:55 109 openvpn[29019]: show_engines = DISABLED
2018:07:24-20:23:55 109 openvpn[29019]: genkey = DISABLED
2018:07:24-20:23:55 109 openvpn[29019]: key_pass_file = '[UNDEF]'
2018:07:24-20:23:55 109 openvpn[29019]: show_tls_ciphers = DISABLED
2018:07:24-20:23:55 109 openvpn[29019]: Connection profiles [default]:
2018:07:24-20:23:55 109 openvpn[29019]: proto = tcp-server
2018:07:24-20:23:55 109 openvpn[29019]: local = '0.0.0.0'
2018:07:24-20:23:55 109 openvpn[29019]: local_port = 443
2018:07:24-20:23:55 109 openvpn[29019]: remote = '[UNDEF]'
2018:07:24-20:23:55 109 openvpn[29019]: remote_port = 443
2018:07:24-20:23:55 109 openvpn[29019]: remote_float = DISABLED
2018:07:24-20:23:55 109 openvpn[29019]: bind_defined = DISABLED
2018:07:24-20:23:55 109 openvpn[29019]: bind_local = ENABLED
2018:07:24-20:23:55 109 openvpn[29019]: connect_retry_seconds = 5
2018:07:24-20:23:55 109 openvpn[29019]: connect_timeout = 10
2018:07:24-20:23:55 109 openvpn[29019]: connect_retry_max = 0
2018:07:24-20:23:55 109 openvpn[29019]: tun_mtu = 1500
2018:07:24-20:23:55 109 openvpn[29019]: tun_mtu_defined = ENABLED
2018:07:24-20:23:55 109 openvpn[29019]: link_mtu = 1500
2018:07:24-20:23:55 109 openvpn[29019]: link_mtu_defined = DISABLED
2018:07:24-20:23:55 109 openvpn[29019]: tun_mtu_extra = 0
2018:07:24-20:23:55 109 openvpn[29019]: tun_mtu_extra_defined = DISABLED
2018:07:24-20:23:55 109 openvpn[29019]: mtu_discover_type = -1
2018:07:24-20:23:55 109 openvpn[29019]: fragment = 0
2018:07:24-20:23:55 109 openvpn[29019]: mssfix = 1450
2018:07:24-20:23:55 109 openvpn[29019]: explicit_exit_notification = 0
2018:07:24-20:23:55 109 openvpn[29019]: Connection profiles END
2018:07:24-20:23:55 109 openvpn[29019]: remote_random = DISABLED
2018:07:24-20:23:55 109 openvpn[29019]: ipchange = '[UNDEF]'
2018:07:24-20:23:55 109 openvpn[29019]: dev = 'tun'
2018:07:24-20:23:55 109 openvpn[29019]: dev_type = '[UNDEF]'
2018:07:24-20:23:55 109 openvpn[29019]: dev_node = '[UNDEF]'
2018:07:24-20:23:55 109 openvpn[29019]: lladdr = '[UNDEF]'
2018:07:24-20:23:55 109 openvpn[29019]: topology = 1
2018:07:24-20:23:55 109 openvpn[29019]: tun_ipv6 = DISABLED
2018:07:24-20:23:55 109 openvpn[29019]: ifconfig_local = '10.242.2.1'
2018:07:24-20:23:55 109 openvpn[29019]: ifconfig_remote_netmask = '10.242.2.2'
2018:07:24-20:23:55 109 openvpn[29019]: ifconfig_noexec = DISABLED
2018:07:24-20:23:55 109 openvpn[29019]: ifconfig_nowarn = DISABLED
2018:07:24-20:23:55 109 openvpn[29019]: ifconfig_ipv6_local = '[UNDEF]'
2018:07:24-20:23:55 109 openvpn[29019]: ifconfig_ipv6_netbits = 0
2018:07:24-20:23:55 109 openvpn[29019]: ifconfig_ipv6_remote = '[UNDEF]'
2018:07:24-20:23:55 109 openvpn[29019]: shaper = 0
2018:07:24-20:23:55 109 openvpn[29019]: mtu_test = 0
2018:07:24-20:23:55 109 openvpn[29019]: mlock = DISABLED
2018:07:24-20:23:55 109 openvpn[29019]: keepalive_ping = 10
2018:07:24-20:23:55 109 openvpn[29019]: keepalive_timeout = 120
2018:07:24-20:23:55 109 openvpn[29019]: inactivity_timeout = 0
2018:07:24-20:23:55 109 openvpn[29019]: ping_send_timeout = 10
2018:07:24-20:23:55 109 openvpn[29019]: ping_rec_timeout = 240
2018:07:24-20:23:55 109 openvpn[29019]: ping_rec_timeout_action = 2
2018:07:24-20:23:55 109 openvpn[29019]: ping_timer_remote = DISABLED
2018:07:24-20:23:55 109 openvpn[29019]: remap_sigusr1 = 0
2018:07:24-20:23:55 109 openvpn[29019]: persist_tun = ENABLED
2018:07:24-20:23:55 109 openvpn[29019]: persist_local_ip = DISABLED
2018:07:24-20:23:55 109 openvpn[29019]: persist_remote_ip = DISABLED
2018:07:24-20:23:55 109 openvpn[29019]: persist_key = ENABLED
2018:07:24-20:23:55 109 openvpn[29019]: passtos = DISABLED
2018:07:24-20:23:55 109 openvpn[29019]: resolve_retry_seconds = 1000000000
2018:07:24-20:23:55 109 openvpn[29019]: username = '[UNDEF]'
2018:07:24-20:23:55 109 openvpn[29019]: groupname = '[UNDEF]'
2018:07:24-20:23:55 109 openvpn[29019]: chroot_dir = '[UNDEF]'
2018:07:24-20:23:55 109 openvpn[29019]: cd_dir = '[UNDEF]'
2018:07:24-20:23:55 109 openvpn[29019]: writepid = '/var/run/openvpn.pid'
2018:07:24-20:23:55 109 openvpn[29019]: up_script = '[UNDEF]'
2018:07:24-20:23:55 109 openvpn[29019]: down_script = '[UNDEF]'
2018:07:24-20:23:55 109 openvpn[29019]: down_pre = ENABLED
2018:07:24-20:23:55 109 openvpn[29019]: up_restart = DISABLED
2018:07:24-20:23:55 109 openvpn[29019]: up_delay = DISABLED
2018:07:24-20:23:55 109 openvpn[29019]: daemon = ENABLED
2018:07:24-20:23:55 109 openvpn[29019]: inetd = 0
2018:07:24-20:23:55 109 openvpn[29019]: log = DISABLED
2018:07:24-20:23:55 109 openvpn[29019]: suppress_timestamps = DISABLED
2018:07:24-20:23:55 109 openvpn[29019]: nice = 0
2018:07:24-20:23:55 109 openvpn[29019]: verbosity = 6
2018:07:24-20:23:55 109 openvpn[29019]: mute = 0
2018:07:24-20:23:55 109 openvpn[29019]: gremlin = 0
2018:07:24-20:23:55 109 openvpn[29019]: status_file = '/var/run/openvpn-status.log'
2018:07:24-20:23:55 109 openvpn[29019]: status_file_version = 1
2018:07:24-20:23:55 109 openvpn[29019]: status_file_update_freq = 60
2018:07:24-20:23:55 109 openvpn[29019]: occ = ENABLED
2018:07:24-20:23:55 109 openvpn[29019]: rcvbuf = 65536
2018:07:24-20:23:55 109 openvpn[29019]: sndbuf = 65536
2018:07:24-20:23:55 109 openvpn[29019]: mark = 4458
2018:07:24-20:23:55 109 openvpn[29019]: sockflags = 1
2018:07:24-20:23:55 109 openvpn[29019]: fast_io = DISABLED
2018:07:24-20:23:55 109 openvpn[29019]: lzo = 7
2018:07:24-20:23:55 109 openvpn[29019]: route_script = '[UNDEF]'
2018:07:24-20:23:55 109 openvpn[29019]: route_default_gateway = '[UNDEF]'
2018:07:24-20:23:55 109 openvpn[29019]: route_default_metric = 0
2018:07:24-20:23:55 109 openvpn[29019]: route_noexec = DISABLED
2018:07:24-20:23:55 109 openvpn[29019]: route_delay = 0
2018:07:24-20:23:55 109 openvpn[29019]: route_delay_window = 30
2018:07:24-20:23:55 109 openvpn[29019]: route_delay_defined = DISABLED
2018:07:24-20:23:55 109 openvpn[29019]: route_nopull = DISABLED
2018:07:24-20:23:55 109 openvpn[29019]: route_gateway_via_dhcp = DISABLED
2018:07:24-20:23:55 109 openvpn[29019]: allow_pull_fqdn = DISABLED
2018:07:24-20:23:55 109 openvpn[29019]: route 10.242.2.0/255.255.255.0/nil/nil
2018:07:24-20:23:55 109 openvpn[29019]: management_addr = '/var/run/openvpn_mgmt'
2018:07:24-20:23:55 109 openvpn[29019]: management_port = 0
2018:07:24-20:23:55 109 openvpn[29019]: management_user_pass = '[UNDEF]'
2018:07:24-20:23:55 109 openvpn[29019]: management_log_history_cache = 250
2018:07:24-20:23:55 109 openvpn[29019]: management_echo_buffer_size = 100
2018:07:24-20:23:55 109 openvpn[29019]: management_write_peer_info_file = '[UNDEF]'
2018:07:24-20:23:55 109 openvpn[29019]: management_client_user = 'root'
2018:07:24-20:23:55 109 openvpn[29019]: management_client_group = 'root'
2018:07:24-20:23:55 109 openvpn[29019]: management_flags = 256
2018:07:24-20:23:55 109 openvpn[29019]: plugin[0] /usr/lib/openvpn/plugins/openvpn-plugin-utm.so '[/usr/lib/openvpn/plugins/openvpn-plugin-utm.so]'
2018:07:24-20:23:55 109 openvpn[29019]: shared_secret_file = '[UNDEF]'
2018:07:24-20:23:55 109 openvpn[29019]: key_direction = 0
2018:07:24-20:23:55 109 openvpn[29019]: ciphername_defined = ENABLED
2018:07:24-20:23:55 109 openvpn[29019]: ciphername = 'AES-256-CBC'
2018:07:24-20:23:55 109 openvpn[29019]: authname_defined = ENABLED
2018:07:24-20:23:55 109 openvpn[29019]: authname = 'SHA256'
2018:07:24-20:23:55 109 openvpn[29019]: prng_hash = 'SHA1'
2018:07:24-20:23:55 109 openvpn[29019]: prng_nonce_secret_len = 16
2018:07:24-20:23:55 109 openvpn[29019]: keysize = 0
2018:07:24-20:23:55 109 openvpn[29019]: engine = DISABLED
2018:07:24-20:23:55 109 openvpn[29019]: replay = ENABLED
2018:07:24-20:23:55 109 openvpn[29019]: mute_replay_warnings = DISABLED
2018:07:24-20:23:55 109 openvpn[29019]: replay_window = 64
2018:07:24-20:23:55 109 openvpn[29019]: replay_time = 15
2018:07:24-20:23:55 109 openvpn[29019]: packet_id_file = '[UNDEF]'
2018:07:24-20:23:55 109 openvpn[29019]: use_iv = ENABLED
2018:07:24-20:23:55 109 openvpn[29019]: test_crypto = DISABLED
2018:07:24-20:23:55 109 openvpn[29019]: tls_server = ENABLED
2018:07:24-20:23:55 109 openvpn[29019]: tls_client = DISABLED
2018:07:24-20:23:55 109 openvpn[29019]: key_method = 2
2018:07:24-20:23:55 109 openvpn[29019]: ca_file = '[UNDEF]'
2018:07:24-20:23:55 109 openvpn[29019]: ca_path = '/etc/openvpn/ca.d'
2018:07:24-20:23:55 109 openvpn[29019]: dh_file = '/etc/openvpn/dh2048.local.pem'
2018:07:24-20:23:55 109 openvpn[29019]: cert_file = '/etc/openvpn/server.crt'
2018:07:24-20:23:55 109 openvpn[29019]: priv_key_file = '/etc/openvpn/server.key'
2018:07:24-20:23:55 109 openvpn[29019]: pkcs12_file = '[UNDEF]'
2018:07:24-20:23:55 109 openvpn[29019]: cipher_list = '[UNDEF]'
2018:07:24-20:23:55 109 openvpn[29019]: tls_verify = '[UNDEF]'
2018:07:24-20:23:55 109 openvpn[29019]: tls_export_cert = '[UNDEF]'
2018:07:24-20:23:55 109 openvpn[29019]: tls_remote = '[UNDEF]'
2018:07:24-20:23:55 109 openvpn[29019]: crl_file = '[UNDEF]'
2018:07:24-20:23:55 109 openvpn[29019]: ns_cert_type = 0
2018:07:24-20:23:55 109 openvpn[29019]: remote_cert_ku[i] = 0
2018:07:24-20:23:55 109 openvpn[29019]: remote_cert_ku[i] = 0
2018:07:24-20:23:55 109 openvpn[29019]: remote_cert_ku[i] = 0
2018:07:24-20:23:55 109 openvpn[29019]: remote_cert_ku[i] = 0
2018:07:24-20:23:55 109 openvpn[29019]: remote_cert_ku[i] = 0
2018:07:24-20:23:55 109 openvpn[29019]: remote_cert_ku[i] = 0
2018:07:24-20:23:55 109 openvpn[29019]: remote_cert_ku[i] = 0
2018:07:24-20:23:55 109 openvpn[29019]: remote_cert_ku[i] = 0
2018:07:24-20:23:55 109 openvpn[29019]: remote_cert_ku[i] = 0
2018:07:24-20:23:55 109 openvpn[29019]: remote_cert_ku[i] = 0
2018:07:24-20:23:55 109 openvpn[29019]: remote_cert_ku[i] = 0
2018:07:24-20:23:55 109 openvpn[29019]: remote_cert_ku[i] = 0
2018:07:24-20:23:55 109 openvpn[29019]: remote_cert_ku[i] = 0
2018:07:24-20:23:55 109 openvpn[29019]: remote_cert_ku[i] = 0
2018:07:24-20:23:55 109 openvpn[29019]: remote_cert_ku[i] = 0
2018:07:24-20:23:55 109 openvpn[29019]: remote_cert_ku[i] = 0
2018:07:24-20:23:55 109 openvpn[29019]: remote_cert_eku = '[UNDEF]'
2018:07:24-20:23:55 109 openvpn[29019]: ssl_flags = 2
2018:07:24-20:23:55 109 openvpn[29019]: tls_timeout = 2
2018:07:24-20:23:55 109 openvpn[29019]: renegotiate_bytes = 0
2018:07:24-20:23:55 109 openvpn[29019]: renegotiate_packets = 0
2018:07:24-20:23:55 109 openvpn[29019]: renegotiate_seconds = 1800
2018:07:24-20:23:55 109 openvpn[29019]: handshake_window = 60
2018:07:24-20:23:55 109 openvpn[29019]: transition_window = 3600
2018:07:24-20:23:55 109 openvpn[29019]: single_session = DISABLED
2018:07:24-20:23:55 109 openvpn[29019]: push_peer_info = DISABLED
2018:07:24-20:23:55 109 openvpn[29019]: tls_exit = DISABLED
2018:07:24-20:23:55 109 openvpn[29019]: tls_auth_file = '[UNDEF]'
2018:07:24-20:23:55 109 openvpn[29019]: server_network = 10.242.2.0
2018:07:24-20:23:55 109 openvpn[29019]: server_netmask = 255.255.255.0
2018:07:24-20:23:55 109 openvpn[29019]: server_network_ipv6 = ::
2018:07:24-20:23:55 109 openvpn[29019]: server_netbits_ipv6 = 0
2018:07:24-20:23:55 109 openvpn[29019]: server_bridge_ip = 0.0.0.0
2018:07:24-20:23:55 109 openvpn[29019]: server_bridge_netmask = 0.0.0.0
2018:07:24-20:23:55 109 openvpn[29019]: server_bridge_pool_start = 0.0.0.0
2018:07:24-20:23:55 109 openvpn[29019]: server_bridge_pool_end = 0.0.0.0
2018:07:24-20:23:55 109 openvpn[29019]: push_entry = 'route 10.242.2.1'
2018:07:24-20:23:55 109 openvpn[29019]: push_entry = 'topology net30'
2018:07:24-20:23:55 109 openvpn[29019]: push_entry = 'ping 10'
2018:07:24-20:23:55 109 openvpn[29019]: push_entry = 'ping-restart 120'
2018:07:24-20:23:55 109 openvpn[29019]: ifconfig_pool_defined = ENABLED
2018:07:24-20:23:55 109 openvpn[29019]: ifconfig_pool_start = 10.242.2.4
2018:07:24-20:23:55 109 openvpn[29019]: ifconfig_pool_end = 10.242.2.251
2018:07:24-20:23:55 109 openvpn[29019]: ifconfig_pool_netmask = 0.0.0.0
2018:07:24-20:23:55 109 openvpn[29019]: ifconfig_pool_persist_filename = '/var/run/ipp.txt'
2018:07:24-20:23:55 109 openvpn[29019]: ifconfig_pool_persist_refresh_freq = 600
2018:07:24-20:23:55 109 openvpn[29019]: ifconfig_ipv6_pool_defined = DISABLED
2018:07:24-20:23:55 109 openvpn[29019]: ifconfig_ipv6_pool_base = ::
2018:07:24-20:23:55 109 openvpn[29019]: ifconfig_ipv6_pool_netbits = 0
2018:07:24-20:23:55 109 openvpn[29019]: n_bcast_buf = 256
2018:07:24-20:23:55 109 openvpn[29019]: tcp_queue_limit = 64
2018:07:24-20:23:55 109 openvpn[29019]: real_hash_size = 256
2018:07:24-20:23:55 109 openvpn[29019]: virtual_hash_size = 256
2018:07:24-20:23:55 109 openvpn[29019]: client_connect_script = '[UNDEF]'
2018:07:24-20:23:55 109 openvpn[29019]: learn_address_script = '[UNDEF]'
2018:07:24-20:23:55 109 openvpn[29019]: client_disconnect_script = '[UNDEF]'
2018:07:24-20:23:55 109 openvpn[29019]: client_config_dir = '/etc/openvpn/conf.d'
2018:07:24-20:23:55 109 openvpn[29019]: ccd_exclusive = ENABLED
2018:07:24-20:23:55 109 openvpn[29019]: tmp_dir = '/tmp'
2018:07:24-20:23:55 109 openvpn[29019]: push_ifconfig_defined = DISABLED
2018:07:24-20:23:55 109 openvpn[29019]: push_ifconfig_local = 0.0.0.0
2018:07:24-20:23:55 109 openvpn[29019]: push_ifconfig_remote_netmask = 0.0.0.0
2018:07:24-20:23:55 109 openvpn[29019]: push_ifconfig_ipv6_defined = DISABLED
2018:07:24-20:23:55 109 openvpn[29019]: push_ifconfig_ipv6_local = ::/0
2018:07:24-20:23:55 109 openvpn[29019]: push_ifconfig_ipv6_remote = ::
2018:07:24-20:23:55 109 openvpn[29019]: enable_c2c = DISABLED
2018:07:24-20:23:55 109 openvpn[29019]: duplicate_cn = DISABLED
2018:07:24-20:23:55 109 openvpn[29019]: cf_max = 0
2018:07:24-20:23:55 109 openvpn[29019]: cf_per = 0
2018:07:24-20:23:55 109 openvpn[29019]: max_clients = 1024
2018:07:24-20:23:55 109 openvpn[29019]: max_routes_per_client = 256
2018:07:24-20:23:55 109 openvpn[29019]: auth_user_pass_verify_script = '[UNDEF]'
2018:07:24-20:23:55 109 openvpn[29019]: auth_user_pass_verify_script_via_file = DISABLED
2018:07:24-20:23:55 109 openvpn[29019]: port_share_host = '127.0.0.1'
2018:07:24-20:23:55 109 openvpn[29019]: port_share_port = 10443
2018:07:24-20:23:55 109 openvpn[29019]: client = DISABLED
2018:07:24-20:23:55 109 openvpn[29019]: pull = DISABLED
2018:07:24-20:23:55 109 openvpn[29019]: auth_user_pass_file = '[UNDEF]'
2018:07:24-20:23:55 109 openvpn[29019]: OpenVPN 2.3.0 i686-suse-linux-gnu [SSL (OpenSSL)] [LZO] [EPOLL] [MH] [IPv6] built on Jul 8 2015
2018:07:24-20:23:55 109 openvpn[29019]: MANAGEMENT: client_uid=0
2018:07:24-20:23:55 109 openvpn[29019]: MANAGEMENT: client_gid=0
2018:07:24-20:23:55 109 openvpn[29019]: MANAGEMENT: unix domain socket listening on /var/run/openvpn_mgmt
2018:07:24-20:23:55 109 openvpn[29019]: NOTE: your local LAN uses the extremely common subnet address 192.168.0.x or 192.168.1.x. Be aware that this might create routing conflicts if you connect to the VPN server from public locations such as internet cafes that use the same subnet.
2018:07:24-20:23:55 109 openvpn[29019]: NOTE: OpenVPN 2.1 requires '--script-security 2' or higher to call user-defined scripts or executables
2018:07:24-20:23:55 109 openvpn[29019]: PLUGIN_INIT: POST /usr/lib/openvpn/plugins/openvpn-plugin-utm.so '[/usr/lib/openvpn/plugins/openvpn-plugin-utm.so]' intercepted=PLUGIN_UP|PLUGIN_DOWN|PLUGIN_AUTH_USER_PASS_VERIFY|PLUGIN_CLIENT_CONNECT|PLUGIN_CLIENT_DISCONNECT
2018:07:24-20:23:55 109 openvpn[29019]: Diffie-Hellman initialized with 2048 bit key
2018:07:24-20:23:55 109 openvpn[29019]: WARNING: experimental option --capath /etc/openvpn/ca.d
2018:07:24-20:23:55 109 openvpn[29019]: TLS-Auth MTU parms [ L:1572 D:140 EF:40 EB:0 ET:0 EL:0 ]
2018:07:24-20:23:55 109 openvpn[29019]: Socket Buffers: R=[87380->131072] S=[16384->131072]
2018:07:24-20:23:55 109 openvpn[29019]: ROUTE_GATEWAY 192.168.0.1/255.255.255.0 IFACE=eth1 HWADDR=d4:6e:0e:1e:b7:6c
2018:07:24-20:23:55 109 openvpn[29019]: TUN/TAP device tun0 opened
2018:07:24-20:23:55 109 openvpn[29019]: TUN/TAP TX queue length set to 100
2018:07:24-20:23:55 109 openvpn[29019]: do_ifconfig, tt->ipv6=0, tt->did_ifconfig_ipv6_setup=0
2018:07:24-20:23:55 109 openvpn[29019]: /bin/ip link set dev tun0 up mtu 1500
2018:07:24-20:23:55 109 openvpn[29019]: /bin/ip addr add dev tun0 local 10.242.2.1 peer 10.242.2.2
2018:07:24-20:23:55 109 openvpn[29019]: PLUGIN_CALL: POST /usr/lib/openvpn/plugins/openvpn-plugin-utm.so/PLUGIN_UP status=0
2018:07:24-20:23:55 109 openvpn[29019]: /bin/ip route add 10.242.2.0/24 via 10.242.2.2 proto 41 dev tun0
2018:07:24-20:23:55 109 openvpn[29019]: Data Channel MTU parms [ L:1572 D:1450 EF:72 EB:135 ET:0 EL:0 AF:3/1 ]
2018:07:24-20:23:55 109 openvpn[29025]: Listening for incoming TCP connection on [undef]
2018:07:24-20:23:55 109 openvpn[29025]: TCPv4_SERVER link local (bound): [undef]
2018:07:24-20:23:55 109 openvpn[29025]: TCPv4_SERVER link remote: [undef]
2018:07:24-20:23:55 109 openvpn[29025]: MULTI: multi_init called, r=256 v=256
2018:07:24-20:23:55 109 openvpn[29025]: IFCONFIG POOL: base=10.242.2.4 size=62, ipv6=0
2018:07:24-20:23:55 109 openvpn[29025]: IFCONFIG POOL LIST
2018:07:24-20:23:55 109 openvpn[29025]: MULTI: TCP INIT maxclients=1024 maxevents=1028
2018:07:24-20:23:55 109 openvpn[29025]: Initialization Sequence Completed
2018:07:24-20:33:50 109 openvpn[29025]: MANAGEMENT: Client connected from /var/run/openvpn_mgmt
2018:07:24-20:33:50 109 openvpn[29025]: MANAGEMENT: CMD 'status -1'
2018:07:24-20:33:50 109 openvpn[29025]: MANAGEMENT: CMD 'status -1'
2018:07:24-20:34:00 109 openvpn[29025]: MANAGEMENT: Client disconnected
2018:07:24-22:59:59 109 openvpn[29025]: MANAGEMENT: Client connected from /var/run/openvpn_mgmt
2018:07:24-22:59:59 109 openvpn[29025]: MANAGEMENT: CMD 'status -1'
2018:07:24-22:59:59 109 openvpn[29025]: MANAGEMENT: CMD 'status -1'
2018:07:24-23:00:09 109 openvpn[29025]: MANAGEMENT: Client disconnected



This thread was automatically locked due to age.
Parents
  • Which part of the log do you find curious or suspicious?

  • hello JayJay,

    for example

    2018:07:24-07:11:49 109 openvpn[10973]: TCPv4_SERVER link local: [undef]
    2018:07:24-07:11:49 109 openvpn[10973]: TCPv4_SERVER link remote: [AF_INET]196.52.43.84:6666
    2018:07:24-07:11:51 109 openvpn[10973]: 196.52.43.84:6666 Non-OpenVPN client protocol detected
    2018:07:24-07:11:51 109 openvpn[10973]: 196.52.43.84:6666 SIGTERM[soft,port-share-redirect] received, client-instance exiting
    2018:07:24-07:11:51 109 openvpn[10973]: TCP/UDP: Closing socket
    2018:07:24-07:37:28 109 openvpn[10973]: MULTI: multi_create_instance called
    2018:07:24-07:37:28 109 openvpn[10973]: Re-using SSL/TLS context
    2018:07:24-07:37:28 109 openvpn[10973]: LZO compression initialized
    2018:07:24-07:37:28 109 openvpn[10973]: Control Channel MTU parms [ L:1572 D:140 EF:40 EB:0 ET:0 EL:0 ]
    2018:07:24-07:37:28 109 openvpn[10973]: Data Channel MTU parms [ L:1572 D:1450 EF:72 EB:135 ET:0 EL:0 AF:3/1 ]
    2018:07:24-07:37:28 109 openvpn[10973]: Local Options String: 'V4,dev-type tun,link-mtu 1572,tun-mtu 1500,proto TCPv4_SERVER,comp-lzo,cipher AES-256-CBC,auth SHA256,keysize 256,key-method 2,tls-server'
    2018:07:24-07:37:28 109 openvpn[10973]: Expected Remote Options String: 'V4,dev-type tun,link-mtu 1572,tun-mtu 1500,proto TCPv4_CLIENT,comp-lzo,cipher AES-256-CBC,auth SHA256,keysize 256,key-method 2,tls-client'
    2018:07:24-07:37:28 109 openvpn[10973]: Local Options hash (VER=V4): '372232dd'
    2018:07:24-07:37:28 109 openvpn[10973]: Expected Remote Options hash (VER=V4): '2ba0d2f5'
    2018:07:24-07:37:28 109 openvpn[10973]: TCP connection established with [AF_INET]218.211.168.176:50720 (via [AF_INET]192.168.0.11:443)

     

    it seems there is a connection established from 218.211.168.176:50720 that wasnt me and noone else that have the permission to do that so ....

    Can you explain what all these mean?

    Marco

  • That's an IP from taiwan trying to connect your TCP port 443 (https).

    What's strange is it's reporting the private ip - 192.168.0.11 rather than your public ip.  Is the utm behind another NAT (router or firewall).  Are you forwarding port 443 to the utm?

    Why are you using port 443 for the ssl server.  Also why TCP and not UDP protocol?

    2018:07:24-07:37:28 109 openvpn[10973]: 218.211.168.176:50720 Non-OpenVPN client protocol detected

    I get lots of inbound port 443 attempts.  I have them all blocked as I'm not running a web server here.... Are you?

    I advise using either the standard openvpn port 1194 UDP, or some nonstandard 5 digit UDP port.

    It's been a year since I started using UTM.  Still discovering all sorts of new things (like the powerful web filtering and ssl scanning options).

  • Hello,

    yes the UTM is behind a cable box with forwarding port for ssl server and this is 443

    192.168.0.0 is the transfer network between them 

    this address is only in my log right? this cant see the user which is trying to connect?

    How can TCP connection established with [AF_INET]218.211.168.176:50720 (via [AF_INET]192.168.0.11:443) ?

    Im using this port because in the utm  i saw this:

    Select the network ProtocolAddress and Port that all SSL VPN clients must use. By default, this is set to TCP port 443 on any address. Note that port 10443, the Sophos UTM Manager port 4422 and the port used by WebAdmin can not be used.
    For all SSL VPN connections, the Override hostname setting overrides the built-in choice of preferring a configured DynDNS name over the system hostname.

  • I'm not sure what 10443 is used for but here's a link to the reserved ports.

    https://community.sophos.com/products/unified-threat-management/f/general-discussion/100848/how-to-understand-utm-port-usage

    I'm not sure what you mean by see the user that's trying to connect.  You can see the IP address they're coming from, that's it.

    Again, 443 is an odd choice for a openvpn server.  Usually 443 is used for https.

    Instead of double natting, why don't you try to get your comcast modem into bridge mode so it passed the public ip directly to the utm box.  No need to mess with any port forwarding. Double natting, while it works for most things, there are may be issues with certain applications and/or adds another layer when troubleshooting something.

Reply Children