OpenVPN跨Linux主机连接失败:配置异常定位求助
Hey there, let's break down why your OpenVPN connection isn't working—your logs and config files give us clear clues to fix this.
Root Cause: Mismatched TLS Encryption Configuration
The biggest issue here is a conflict between your server and client's TLS security settings:
- Your server config uses
tls-crypt ta.key 0— this option encrypts the entire TLS handshake using theta.keyfile, providing stronger security than the oldertls-auth. - But your client config has
tls-auth ta.key 1— this is the legacy HMAC authentication setting, which is incompatible withtls-crypton the server.
This mismatch directly causes the errors you're seeing:
Mon Jun 29 15:38:28 2020 tls-crypt unwrap error: packet authentication failed
Mon Jun 29 15:38:28 2020 TLS Error: tls-crypt unwrapping failed from [AF_INET]70.15.128.216:55352
And on the client side, it leads to the TLS handshake failure because the server can't decrypt the client's packets properly.
Fix for This:
Update your client configuration file:
Replace this line:
tls-auth ta.key 1
With:
tls-crypt ta.key 1
Make sure both the server and client are using the exact same ta.key file (copy it over securely to the client machine).
Additional Checks to Ensure Connection Success
Even after fixing the TLS setting, verify these points to rule out other potential issues:
- Certificate Consistency: Confirm that
ca.crt,client.crt,client.keyon the client are from the same CA that issuedca.crt,server.crt,server.keyon the server. Mixing certificates from different CAs will break authentication. - Firewall Rules: On the server, ensure UDP port 1194 is open. For Debian 10, you can run:
ufw allow 1194/udp ufw reload - File Permissions: You already set
client.keyto400, make sureta.keyandca.crton the client also have restrictive permissions (ideally400for keys,644for certificates) to avoid OpenVPN permission errors. - CRL Verification: If you're using
crl-verify crl.pemon the server, double-check that the client certificate hasn't been revoked in the CRL file. If you just set up the CA, this is probably not an issue, but it's worth confirming.
Once you update the client's TLS setting and verify these checks, restart both the OpenVPN server and client, then test the connection again.
内容的提问来源于stack exchange,提问作者Chris Rutherford

