Hi,
I've tried to find info and just can't.
As I understood in v7 is updated kernel.
As kernel was the problem in previous versions, my question is :
Does OpenVPN working properly on v7 both TCP and UDP ?
Thank you in advance
Seems like its either TCP or UDP but not both.Hello,
OpenVPN UDP works like charm on 7.1.1, I didn't check the TCP.
Correct But why you wanna use TCP? TCP Is too damn slow in my country maybe you dont have this problem but just saying.Seems like its either TCP or UDP but not both.Hello,
OpenVPN UDP works like charm on 7.1.1, I didn't check the TCP.
recvd P_DATA packet, dropping
When udp is in use, the connection drops about once an hour with following errors on server sideClients are Linux/Android - no matterCode: Select allrecvd P_DATA packet, dropping
could you ever connect MT to MT?I had issues with 7.1 and 7.1.1
It was CHR ROS 7.2rc1. Now I downgraded to 7.1.1 due to high cpu utilization by "management" process.When udp is in use, the connection drops about once an hour with following errors on server sideClients are Linux/Android - no matterCode: Select allrecvd P_DATA packet, dropping
Correct. I never used an OVPN connection for that long before and after I did the same happened to me. What HW did you use? Was it a Virtual like CHR or x86 or an actual MT device?
I Can't Pass this part on MT to MT OVPN. No matter how I set my certificate and CRL. I even set the same NTP but doesn't matter.
LOG OPVN---->: <Client IP>: disconnected <TLS failed>
Hi, did you found a workaround for this?Hello everyone.
It is so, as I have been able to determine the error of 100% CPU "management" process, it persists in 7.3 beta.
Both with Open VPN udp and tcp.
This error only occurs when the OpenVPN server is activated and some connections are established.
Too bad we can't test the new TLS 1.2 in depth.
Hopefully this post will be observed by Mikrotik and they will solve this problem.
I will be pending.
Greetings,
FM,
connection established from XXX.XXX.XXX.XXX, port: XXXXX to XXX.XXX.XXX.XXX
recvd P_DATA packet, dropping
recvd P_DATA packet, dropping
<XXX.XXX.XXX.XXX>: disconnected <bad packet received>
connection established from XXX.XXX.XXX.XXX, port: XXXXX to XXX.XXX.XXX.XXX
sent P_CONTROL_HARD_RESET_SERVER_V2 kid=0 sid=9fe13697d12f8793 pid=0 DATA len=0
rcvd P_DATA kid=0 sid=a363e1b6d1f748c DATA len=136
You should use the OVPN legacy client v 2.5.7 Also, You should use "verb" in your config file with a value greater than 5. In recent versions verb option is shown as an unused option I don't know why.client shows nothing suspicious
That was a great hint. I wasn't aware of wireguard, but it seemed promising and I just set it up and replaced OpenVPN. Works flawlessly and is significantly faster than OpenVPN. Thanks!meanwhile wireguard is working fine fine fine
Thanks again for your help, highly appreciated. I switched to wireguard now and don't have any more resources for testing. Can you (for future reference) specify, what you mean by legacy client (Is there a second "hidden" client available on RouterOS?).@zerogYou should use the OVPN legacy client v 2.5.7 Also, You should use "verb" in your config file with a value greater than 5. In recent versions verb option is shown as an unused option I don't know why.client shows nothing suspicious
https://openvpn.net/community-downloads/what do you mean by the legacy client
I'm aware of those, but my client itself was a hap ac2. I can't install those with RouterOS, can I?@zeroghttps://openvpn.net/community-downloads/what do you mean by the legacy client
Ahhh, now I understand you@zerog
No, You can't. However, The amount of information that the OVPN client debugger will give you is sufficient to find out if the error is related to the server or the client.