You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

OpenVPN跨Linux主机连接失败:配置异常定位求助

Troubleshooting Your OpenVPN Connection Failure

Hey there, let's break down why your OpenVPN connection isn't working—your logs and config files give us clear clues to fix this.

Root Cause: Mismatched TLS Encryption Configuration

The biggest issue here is a conflict between your server and client's TLS security settings:

  • Your server config uses tls-crypt ta.key 0 — this option encrypts the entire TLS handshake using the ta.key file, providing stronger security than the older tls-auth.
  • But your client config has tls-auth ta.key 1 — this is the legacy HMAC authentication setting, which is incompatible with tls-crypt on the server.

This mismatch directly causes the errors you're seeing:

Mon Jun 29 15:38:28 2020 tls-crypt unwrap error: packet authentication failed
Mon Jun 29 15:38:28 2020 TLS Error: tls-crypt unwrapping failed from [AF_INET]70.15.128.216:55352

And on the client side, it leads to the TLS handshake failure because the server can't decrypt the client's packets properly.

Fix for This:

Update your client configuration file:
Replace this line:

tls-auth ta.key 1

With:

tls-crypt ta.key 1

Make sure both the server and client are using the exact same ta.key file (copy it over securely to the client machine).

Additional Checks to Ensure Connection Success

Even after fixing the TLS setting, verify these points to rule out other potential issues:

  • Certificate Consistency: Confirm that ca.crt, client.crt, client.key on the client are from the same CA that issued ca.crt, server.crt, server.key on the server. Mixing certificates from different CAs will break authentication.
  • Firewall Rules: On the server, ensure UDP port 1194 is open. For Debian 10, you can run:
    ufw allow 1194/udp
    ufw reload
    
  • File Permissions: You already set client.key to 400, make sure ta.key and ca.crt on the client also have restrictive permissions (ideally 400 for keys, 644 for certificates) to avoid OpenVPN permission errors.
  • CRL Verification: If you're using crl-verify crl.pem on the server, double-check that the client certificate hasn't been revoked in the CRL file. If you just set up the CA, this is probably not an issue, but it's worth confirming.

Once you update the client's TLS setting and verify these checks, restart both the OpenVPN server and client, then test the connection again.

内容的提问来源于stack exchange,提问作者Chris Rutherford

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.08 09:37:42