Cloudron makes it easy to run web apps like WordPress, Nextcloud, GitLab on your server. Find out more or install now.


Skip to content

OpenVPN

48 Topics 349 Posts
  • OpenVPN - TLS verify error

    Solved
    4
    0 Votes
    4 Posts
    1k Views
    robiR

    @nebulon Update: after restarting the OpenVPN App, it connects and verifies TLS just fine.

    Shrug, restart fixed it.

  • Making User Admin in config.ini

    Solved
    7
    0 Votes
    7 Posts
    281 Views
    aessenA

    @nebulon said in Making User Admin in config.ini:

    @aessen yes it has to be the Cloudron user's username.

    OMG you rock, all of you. That worked and it also helps me better understand the proper syntax for code like this. Many thanks.

  • Unable to connect to OpenVPN from Asus Router

    1
    0 Votes
    1 Posts
    163 Views
    No one has replied
  • Modify OpenVPN Server Config

    Moved Solved
    10
    0 Votes
    10 Posts
    647 Views
    andreasduerenA

    Hijacking this thread. I don't think. it's currently possible to do port forwarding, is it? Use case is: I would like to conect a raspberry pi running yunohost at home to the vpn to get a static IP address which I won't get at home.

  • OpenVPN shows local IP address

    8
    0 Votes
    8 Posts
    481 Views
    A

    @girish Thank you, all looking good so far!

  • Bad argument `eth0' openvpn after update

    24
    0 Votes
    24 Posts
    857 Views
    girishG

    Would be good if you guys put a note on which clients have this issue. See https://community.openvpn.net/openvpn/wiki/IPv6#Clientissues for OpenVPN/IPv6 issues.

    I mostly only tested only on Linux and it works there.

  • OpenVPN with Adguard

    35
    1 Votes
    35 Posts
    5k Views
    girishG

    @BrutalBirdie said in OpenVPN with Adguard:

    register-dns
    block-outside-dns

    Good to know these! Apparently, these are Windows only directives - https://iflorian.com/openvpn-block-outside-ds/

  • 0 Votes
    2 Posts
    540 Views
    girishG

    @timo-betz I missed this post somehow. Did you manage to figure this out?

  • Open VPN Page is not scrollable

    Moved Solved
    4
    1 Votes
    4 Posts
    277 Views
    S

    Thank you so much. Appreciate your help. I have updated the package, now working fine.
    Thank you again 🙂

  • Connection Reset

    Solved
    8
    0 Votes
    8 Posts
    615 Views
    J

    I actually just figured it out, somehow the profile had some sort of error in it. I generated another one and it fixed the problem. I appreciate the help!

  • OpenVPN on Port 443

    11
    0 Votes
    11 Posts
    1k Views
    7dowWilkes7

    thank you all. i've almost resigned myself to the fact that it doesn't work with simple gui settings. i also don't know enough to tinker with config files on my own. i asked my colleague again about his settings on synology. he redirects port 443 to the default port 1194 via his home router. So he uses the router-nat, is reachable from outside via 443 and simply routes to the VPN instance.

    there is probably no comparable NAT function in cloudron, is there?

    while searching the internet i found the "haproxy" in docker-hub. maybe such a container (app) could transparently redirect from a host with port 443 to an internal ip with port 7494. but this is probably going too far and i don't want to overuse your help.

  • OpenVPN config types

    4
    1 Votes
    4 Posts
    323 Views
    girishG

    @mehdi said in OpenVPN config types:

    In summary, we could defintely remove the least used ones, and leave only .ovpn embedded and .tblk. I think most others are less useful and these 2 can do the job in most, if not all, cases.

    right, this is the confirmation I needed. Looks like, we can remove the first 3. Will do that in next release then.

  • OpenVPN - Setting admin user gives admin to everyone.

    Solved
    3
    0 Votes
    3 Posts
    350 Views
    F

    @girish Awesome! That got it. Thanks. The first time I tried it it didn't take after the reboot but I added back in the " " marks and it worked as expected. Thank you so much. And again for the quick response!

  • 1 Votes
    7 Posts
    499 Views
    girishG

    I have also updated the app to use easyrsa3 now. This will roll out slowly since there is a lot of migration code .

  • "WARNING: Your certificate is not yet valid!"

    Solved
    5
    0 Votes
    5 Posts
    758 Views
    P

    @mehdi GMT +1 but my idea is that when I installed first time Cloudron has Los Angeles time... that's can a possible source of issue.

  • OpenVPN use case

    7
    0 Votes
    7 Posts
    402 Views
    timconsidineT

    @robi Thanks. Port-knocking sounds interesting to research. When time permits !

  • Change protocol from TCP to UDP

    7
    0 Votes
    7 Posts
    404 Views
    P

    @mehdi Thank's a lot! 🙂

  • 0 Votes
    3 Posts
    2k Views
    girishG

    This is more involved. First, there is HEAD request with /?embedded=true. Then, there is a POST request to /RPC2. We have to reverse engineer a bit to implement this.

    There's more info in parts at

    https://forums.openvpn.net/viewtopic.php?f=36&t=29767 https://github.com/ryanharrison554/pyovpn-as/blob/a5d4ad36a952b982cc74c4573595b9031369239a/pyovpn_as/api/cli.py * https://forums.openvpn.net/viewtopic.php?t=28491 http://blog.manton.im/2016/02/reverse-engineering-openvpn-as-login.html
  • 0 Votes
    7 Posts
    6k Views
    mehdiM

    Recognizing TCP OpenVPN traffic is really not easy, as it kinda looks like any other TLS encrypted stream. As far as I know, doing so requires advanced Deep Packet Inspection capabilities that are only available to few countries, and even this is not foolproof.

    May I ask, @hasan, where are you based?

  • Support VPN Client

    Moved
    15
    1 Votes
    15 Posts
    923 Views
    JOduMonTJ

    @mehdi said in Support VPN Client:

    I don't know a single commercial VPN provider that provides a public IP to each VPN connection

    It is probably because you didn't fell the need 🙂

    I lived in Switzerland and before in Canada, where Torrenting and self hosting is not an issue.
    But since I'm in Thailand; first, Torrenting is it as the Government fell about you, and the Internet is monitored and limited (not as much than China but still) they block several ports and websites.

    It took me a while to find and I chat with a lot of online support to find few of them
    Has I will not recommend it but still a good example PureVPN support this
    you control which port you open with OpenVPN but the IP is dynamic and yes it still through a NAT, and you could buy a static IP available via only PPTP (which they don't claim at loud).

    If I remember well mullvad also offer this kind of service

    My idea came from: https://labriqueinter.net