You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

OpenVPN 2.4.9服务器客户端连接卡在“TLS: Initial packet”循环的故障排查咨询

OpenVPN 2.4.9服务器客户端连接卡在“TLS: Initial packet”循环的故障排查咨询

我有一台OpenVPN 2.4.9服务器,原本计划支持多个客户端连接,但现在所有客户端都无法成功连接。我筛选了某一个客户端的日志信息,内容如下:

14:06:38 xxx.xxx.xxx.xxx:1209 Re-using SSL/TLS context

14:06:38 xxx.xxx.xxx.xxx:1209 LZO compression initializing

14:06:38 xxx.xxx.xxx.xxx:1209 Control Channel MTU parms [ L:1622 D:1212 EF:38 EB:0 ET:0 EL:3 ]

14:06:38 xxx.xxx.xxx.xxx:1209 Data Channel MTU parms [ L:1622 D:1450 EF:122 EB:406 ET:0 EL:3 ]

14:06:38 xxx.xxx.xxx.xxx:1209 Local Options String (VER=V4): 'V4,dev-type tun,link-mtu 1542,tun-mtu 1500,proto UDPv4,comp-lzo,cipher BF-CBC,auth SHA1,keysize 128,key-method 2,tls-server'

14:06:38 xxx.xxx.xxx.xxx:1209 Expected Remote Options String (VER=V4): 'V4,dev-type tun,link-mtu 1542,tun-mtu 1500,proto UDPv4,comp-lzo,cipher BF-CBC,auth SHA1,keysize 128,key-method 2,tls-client'

14:06:38 xxx.xxx.xxx.xxx:1209 TLS: Initial packet from [AF_INET]xxx.xxx.xxx.xxx:1209, sid=f5f87f34 db300e2a

14:07:37 xxx.xxx.xxx.xxx:1152 Re-using SSL/TLS context

14:07:37 xxx.xxx.xxx.xxx:1152 LZO compression initializing

14:07:37 xxx.xxx.xxx.xxx:1152 Control Channel MTU parms [ L:1622 D:1212 EF:38 EB:0 ET:0 EL:3 ]

14:07:37 xxx.xxx.xxx.xxx:1152 Data Channel MTU parms [ L:1622 D:1450 EF:122 EB:406 ET:0 EL:3 ]

14:07:37 xxx.xxx.xxx.xxx:1152 Local Options String (VER=V4): 'V4,dev-type tun,link-mtu 1542,tun-mtu 1500,proto UDPv4,comp-lzo,cipher BF-CBC,auth SHA1,keysize 128,key-method 2,tls-server'

14:07:37 xxx.xxx.xxx.xxx:1152 Expected Remote Options String (VER=V4): 'V4,dev-type tun,link-mtu 1542,tun-mtu 1500,proto UDPv4,comp-lzo,cipher BF-CBC,auth SHA1,keysize 128,key-method 2,tls-client'

14:07:37 xxx.xxx.xxx.xxx:1152 TLS: Initial packet from [AF_INET]xxx.xxx.xxx.xxx:1152, sid=a51c6653 918e9955

14:10:02 xxx.xxx.xxx.xxx:1070 Re-using SSL/TLS context

14:10:02 xxx.xxx.xxx.xxx:1070 LZO compression initializing

14:10:02 xxx.xxx.xxx.xxx:1070 Control Channel MTU parms [ L:1622 D:1212 EF:38 EB:0 ET:0 EL:3 ]

14:10:02 xxx.xxx.xxx.xxx:1070 Data Channel MTU parms [ L:1622 D:1450 EF:122 EB:406 ET:0 EL:3 ]

14:10:02 xxx.xxx.xxx.xxx:1070 Local Options String (VER=V4): 'V4,dev-type tun,link-mtu 1542,tun-mtu 1500,proto UDPv4,comp-lzo,cipher BF-CBC,auth SHA1,keysize 128,key-method 2,tls-server'

14:10:02 xxx.xxx.xxx.xxx:1070 Expected Remote Options String (VER=V4): 'V4,dev-type tun,link-mtu 1542,tun-mtu 1500,proto UDPv4,comp-lzo,cipher BF-CBC,auth SHA1,keysize 128,key-method 2,tls-client'

14:10:02 xxx.xxx.xxx.xxx:1070 TLS: Initial packet from [AF_INET]xxx.xxx.xxx.xxx:1070, sid=4783fc46 dc03a197

14:11:44 xxx.xxx.xxx.xxx:1055 Re-using SSL/TLS context

14:11:44 xxx.xxx.xxx.xxx:1055 LZO compression initializing

14:11:44 xxx.xxx.xxx.xxx:1055 Control Channel MTU parms [ L:1622 D:1212 EF:38 EB:0 ET:0 EL:3 ]

14:11:44 xxx.xxx.xxx.xxx:1055 Data Channel MTU parms [ L:1622 D:1450 EF:122 EB:406 ET:0 EL:3 ]

14:11:44 xxx.xxx.xxx.xxx:1055 Local Options String (VER=V4): 'V4,dev-type tun,link-mtu 1542,tun-mtu 1500,proto UDPv4,comp-lzo,cipher BF-CBC,auth SHA1,keysize 128,key-method 2,tls-server'

14:11:44 xxx.xxx.xxx.xxx:1055 Expected Remote Options String (VER=V4): 'V4,dev-type tun,link-mtu 1542,tun-mtu 1500,proto UDPv4,comp-lzo,cipher BF-CBC,auth SHA1,keysize 128,key-method 2,tls-client'

14:11:44 xxx.xxx.xxx.xxx:1055 TLS: Initial packet from [AF_INET]xxx.xxx.xxx.xxx:1055, sid=c49e2c9b 38019dec

14:12:49 xxx.xxx.xxx.xxx:1052 Re-using SSL/TLS context

14:12:49 xxx.xxx.xxx.xxx:1052 LZO compression initializing

14:12:49 xxx.xxx.xxx.xxx:1052 Control Channel MTU parms [ L:1622 D:1212 EF:38 EB:0 ET:0 EL:3 ]

14:12:49 xxx.xxx.xxx.xxx:1052 Data Channel MTU parms [ L:1622 D:1450 EF:122 EB:406 ET:0 EL:3 ]

14:12:49 xxx.xxx.xxx.xxx:1052 Local Options String (VER=V4): 'V4,dev-type tun,link-mtu 1542,tun-mtu 1500,proto UDPv4,comp-lzo,cipher BF-CBC,auth SHA1,keysize 128,key-method 2,tls-server'

14:12:49 xxx.xxx.xxx.xxx:1052 Expected Remote Options String (VER=V4): 'V4,dev-type tun,link-mtu 1542,tun-mtu 1500,proto UDPv4,comp-lzo,cipher BF-CBC,auth SHA1,keysize 128,key-method 2,tls-client'

14:12:49 xxx.xxx.xxx.xxx:1052 TLS: Initial packet from [AF_INET]xxx.xxx.xxx.xxx:1052, sid=fd3a21d4 1f68e97a

能看到每次出现TLS: Initial packet from这条日志后,大概60秒就会重复整个初始化流程,明显是连接超时了。我想搞清楚客户端到底在等待什么?为什么服务器没有返回它需要的内容?

为了尝试解决超时问题,我已经在服务器配置里添加了以下参数:

  • reneg-sec 3600
  • ping 120
  • ping-restart 120

备注:内容来源于stack exchange,提问作者KarlFri

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.04.22 11:43:12