EFW Support

Support => VPN Support => Topic started by: sisaendian on Friday 08 April 2016, 08:26:02 am



Title: How to OVPN with Endian 3.2.0 Comunity
Post by: sisaendian on Friday 08 April 2016, 08:26:02 am
Hello ,

Please give some help with this issue, I need to use OVPN in order to access my network from other places ouside Offoce.
I am usin Endian 3.2.0 Community edition with the following configuration:

OVPN Enabled
Authentication type:  x.509 certificate & PSK (two Factor)
Bind only to :   null
Port  :  1194
Device Type: TAP
Protocol : UDP
Bridged to:  Green
Dynamic Ip pool start address 192.168.0.1    -   end  :  192.168.0.254
Advanced options as default

CERTIFICATES
One as the main generated by the endian server
myname as certificate created for my account

AUTHENTICATION
Myname and my password
Certificate Configuration:   Don't Change

CLIENT CONFIGURATION:
client
dev tap
proto udp
remote MY_server_ip
resolv-retry infinite
nobind
persist-key
persist-tun
ca cacert.pem
auth-user-pass
comp-lzo


When I try to connect using this configuration, I get the following error:


Thu Apr 07 10:20:45 2016 WARNING: No server certificate verification method has been enabled.  See openvpn.net/howto.html#mitm for more info.
Thu Apr 07 10:20:45 2016 UDPv4 link local: [undef]
Thu Apr 07 10:20:45 2016 UDPv4 link remote: [AF_INET]My IP SERVER
Thu Apr 07 10:20:46 2016 VERIFY ERROR: depth=1, error=self signed certificate in certificate chain: C=IT, O=efw, CN=efw CA
Thu Apr 07 10:20:46 2016 TLS_ERROR: BIO read tls_read_plaintext error: error:14090086:SSL routines:SSL3_GET_SERVER_CERTIFICATE:certificate verify failed
Thu Apr 07 10:20:46 2016 TLS Error: TLS object -> incoming plaintext read error
Thu Apr 07 10:20:46 2016 TLS Error: TLS handshake failed
Thu Apr 07 10:20:46 2016 SIGUSR1[soft,tls-error] received, process restarting


If there is a step by step guide to config OVPN please let me know because I am not an expert on IT.

thanks for your help


Title: Re: How to OVPN with Endian 3.2.0 Comunity
Post by: kdouglas on Wednesday 10 August 2016, 12:19:41 pm
Good evening?

Where you download you certicate? am with no connect with the devices, only Endian problem, but this problema with tls I solve making the certificate download from OpenVPN Server option and not for certificates option