You are not logged in.
I am having problems with my VPN communication. It connects perfectly but after I send some data, the packets drops here is a video that maybe can help.
tracepath
https://youtu.be/IfxtEUVuhEI
mtr
https://youtu.be/-SI7K92kiv8
Here some journal entry. I use dnscrypt but don't know if that can be the issue.
if you check the VPN Connection reset a few times and I have some modules failing but no idea how to fix them.
Mar 02 10:17:34 myuser nm-openvpn[1902]: Connection reset, restarting [0]
$ journalctl -p err -xb
-- Logs begin at Wed 2016-12-14 11:03:23 AEST, end at Thu 2017-03-02 10:10:12
Mar 02 09:37:24 myuser kernel: ACPI Error: [\_SB_.PCI0.SAT1] Namespace lookup
Mar 02 09:37:24 myuser kernel: ACPI Exception: AE_NOT_FOUND, During name looku
Mar 02 09:37:24 myuser kernel: ACPI Exception: AE_NOT_FOUND, (SSDT:IdeTable) w
Mar 02 09:37:24 myuser kernel: ACPI Error: 1 table load failures, 8 successful
Mar 02 09:37:24 myuser kernel: DMAR: DRHD: handling fault status reg 2
Mar 02 09:37:24 myuser kernel: DMAR: [INTR-REMAP] Request device [f0:1f.0] fau
Mar 02 09:37:24 myuser systemd-modules-load[241]: Failed to insert 'vboxguest'
Mar 02 09:37:24 myuser systemd-modules-load[241]: Failed to insert 'vboxsf': N
Mar 02 09:37:24 myuser systemd-modules-load[241]: Failed to insert 'vboxvideo'
Mar 02 09:37:24 myuser systemd[1]: Failed to start Load Kernel Modules.
-- Subject: Unit systemd-modules-load.service has failed
-- Defined-By: systemd
-- Support: http://lists.freedesktop.org/mailman/listinfo/systemd-devel
--
-- Unit systemd-modules-load.service has failed.
--
-- The result is failed.
Mar 02 09:37:25 myuser kernel: brcmfmac: brcmf_c_preinit_dcmds: Firmware versi
Mar 02 09:37:25 myuser kernel: brcmfmac: brcmf_cfg80211_reg_notifier: not a IS
Mar 02 09:37:28 myuser kernel: brcmfmac: brcmf_p2p_create_p2pdev: set p2p_disc
Mar 02 09:37:28 myuser kernel: brcmfmac: brcmf_cfg80211_add_iface: add iface p
Mar 02 09:37:48 myuser systemd[611]: [/usr/lib/systemd/user/zeitgeist-fts.serv
Mar 02 09:37:48 myuser systemd[611]: zeitgeist-fts.service: Service lacks both
Mar 02 09:38:55 myuser kernel: brcmfmac: brcmf_p2p_create_p2pdev: set p2p_disc
Mar 02 09:38:55 myuser kernel: brcmfmac: brcmf_cfg80211_add_iface: add iface p
Mar 02 09:40:53 myuser sudo[1199]: myuser : 3 incorrect password attempts ;
Mar 02 10:03:19 myuser nm-openvpn[1761]: Connection reset, restarting [0]
Mar 02 10:04:03 myuser nm-openvpn[1761]: Connection reset, restarting [0]
Mar 02 10:05:50 myuser nm-openvpn[1761]: Connection reset, restarting [0]
Mar 02 10:06:26 myuser nm-openvpn[1761]: Connection reset, restarting [0]
journalctl -f -u NetworkManager
Mar 02 10:17:13 myuser NetworkManager[446]: <info> [1488413833.4795] audit: op="connection-activate" uuid="a36d6ba5-9c04-43ef-918b-8eb901d48d9b" name="Trust.Zone" pid=670 uid=1000 result="success"
Mar 02 10:17:13 myuser NetworkManager[446]: <info> [1488413833.4886] vpn-connection[0xb68300,a36d6ba5-9c04-43ef-918b-8eb901d48d9b,"Trust.Zone",0]: Started the VPN service, PID 1896
Mar 02 10:17:13 myuser NetworkManager[446]: <info> [1488413833.4994] vpn-connection[0xb68300,a36d6ba5-9c04-43ef-918b-8eb901d48d9b,"Trust.Zone",0]: Saw the service appear; activating connection
Mar 02 10:17:13 myuser nm-openvpn[1902]: OpenVPN 2.4.0 x86_64-unknown-linux-gnu [SSL (OpenSSL)] [LZO] [LZ4] [EPOLL] [PKCS11] [MH/PKTINFO] [AEAD] built on Dec 28 2016
Mar 02 10:17:13 myuser nm-openvpn[1902]: library versions: OpenSSL 1.0.2k 26 Jan 2017, LZO 2.09
Mar 02 10:17:13 myuser NetworkManager[446]: <info> [1488413833.6444] vpn-connection[0xb68300,a36d6ba5-9c04-43ef-918b-8eb901d48d9b,"Trust.Zone",0]: VPN plugin: state changed: starting (3)
Mar 02 10:17:13 myuser NetworkManager[446]: <info> [1488413833.6445] vpn-connection[0xb68300,a36d6ba5-9c04-43ef-918b-8eb901d48d9b,"Trust.Zone",0]: VPN connection: (ConnectInteractive) reply received
Mar 02 10:17:13 myuser nm-openvpn[1902]: NOTE: the current --script-security setting may allow this configuration to call user-defined scripts
Mar 02 10:17:14 myuser nm-openvpn[1902]: TCP/UDP: Preserving recently used remote address: [AF_INET]221.121.158.231:443
Mar 02 10:17:14 myuser nm-openvpn[1902]: Attempting to establish TCP connection with [AF_INET]221.121.158.231:443 [nonblock]
Mar 02 10:17:15 myuser nm-openvpn[1902]: TCP connection established with [AF_INET]221.121.158.231:443
Mar 02 10:17:15 myuser nm-openvpn[1902]: TCP_CLIENT link local: (not bound)
Mar 02 10:17:15 myuser nm-openvpn[1902]: TCP_CLIENT link remote: [AF_INET]221.121.158.231:443
Mar 02 10:17:15 myuser nm-openvpn[1902]: NOTE: UID/GID downgrade will be delayed because of --client, --pull, or --up-delay
Mar 02 10:17:15 myuser nm-openvpn[1902]: [vpn.trust.zone] Peer Connection Initiated with [AF_INET]221.121.158.231:443
Mar 02 10:17:22 myuser nm-openvpn[1902]: TUN/TAP device tun0 opened
Mar 02 10:17:22 myuser nm-openvpn[1902]: /usr/lib/NetworkManager/nm-openvpn-service-openvpn-helper --debug 0 1896 --bus-name org.freedesktop.NetworkManager.openvpn.Connection_5 --tun -- tun0 1500 1571 10.12.35.165 10.12.35.166 init
Mar 02 10:17:22 myuser NetworkManager[446]: <info> [1488413842.4139] manager: (tun0): new Tun device (/org/freedesktop/NetworkManager/Devices/4)
Mar 02 10:17:22 myuser NetworkManager[446]: <info> [1488413842.4461] vpn-connection[0xb68300,a36d6ba5-9c04-43ef-918b-8eb901d48d9b,"Trust.Zone",0]: VPN connection: (IP Config Get) reply received.
Mar 02 10:17:22 myuser NetworkManager[446]: <info> [1488413842.4491] vpn-connection[0xb68300,a36d6ba5-9c04-43ef-918b-8eb901d48d9b,"Trust.Zone",4:(tun0)]: VPN connection: (IP4 Config Get) reply received
Mar 02 10:17:22 myuser nm-openvpn[1902]: GID set to nm-openvpn
Mar 02 10:17:22 myuser nm-openvpn[1902]: UID set to nm-openvpn
Mar 02 10:17:22 myuser nm-openvpn[1902]: Initialization Sequence Completed
Mar 02 10:17:22 myuser NetworkManager[446]: <info> [1488413842.4512] vpn-connection[0xb68300,a36d6ba5-9c04-43ef-918b-8eb901d48d9b,"Trust.Zone",4:(tun0)]: Data: VPN Gateway: 221.121.158.231
Mar 02 10:17:22 myuser NetworkManager[446]: <info> [1488413842.4514] vpn-connection[0xb68300,a36d6ba5-9c04-43ef-918b-8eb901d48d9b,"Trust.Zone",4:(tun0)]: Data: Tunnel Device: "tun0"
Mar 02 10:17:22 myuser NetworkManager[446]: <info> [1488413842.4516] vpn-connection[0xb68300,a36d6ba5-9c04-43ef-918b-8eb901d48d9b,"Trust.Zone",4:(tun0)]: Data: IPv4 configuration:
Mar 02 10:17:22 myuser NetworkManager[446]: <info> [1488413842.4518] vpn-connection[0xb68300,a36d6ba5-9c04-43ef-918b-8eb901d48d9b,"Trust.Zone",4:(tun0)]: Data: Internal Gateway: 10.12.35.166
Mar 02 10:17:22 myuser NetworkManager[446]: <info> [1488413842.4519] vpn-connection[0xb68300,a36d6ba5-9c04-43ef-918b-8eb901d48d9b,"Trust.Zone",4:(tun0)]: Data: Internal Address: 10.12.35.165
Mar 02 10:17:22 myuser NetworkManager[446]: <info> [1488413842.4519] vpn-connection[0xb68300,a36d6ba5-9c04-43ef-918b-8eb901d48d9b,"Trust.Zone",4:(tun0)]: Data: Internal Prefix: 32
Mar 02 10:17:22 myuser NetworkManager[446]: <info> [1488413842.4519] vpn-connection[0xb68300,a36d6ba5-9c04-43ef-918b-8eb901d48d9b,"Trust.Zone",4:(tun0)]: Data: Internal Point-to-Point Address: 10.12.35.166
Mar 02 10:17:22 myuser NetworkManager[446]: <info> [1488413842.4519] vpn-connection[0xb68300,a36d6ba5-9c04-43ef-918b-8eb901d48d9b,"Trust.Zone-",4:(tun0)]: Data: Maximum Segment Size (MSS): 0
Mar 02 10:17:22 myuser NetworkManager[446]: <info> [1488413842.4519] vpn-connection[0xb68300,a36d6ba5-9c04-43ef-918b-8eb901d48d9b,"Trust.Zone",4:(tun0)]: Data: Forbid Default Route: no
Mar 02 10:17:22 myuser NetworkManager[446]: <info> [1488413842.4519] vpn-connection[0xb68300,a36d6ba5-9c04-43ef-918b-8eb901d48d9b,"Trust.Zone",4:(tun0)]: Data: Internal DNS: 8.8.8.8
Mar 02 10:17:22 myuser NetworkManager[446]: <info> [1488413842.4519] vpn-connection[0xb68300,a36d6ba5-9c04-43ef-918b-8eb901d48d9b,"Trust.Zone",4:(tun0)]: Data: Internal DNS: 8.8.4.4
Mar 02 10:17:22 myuser NetworkManager[446]: <info> [1488413842.4519] vpn-connection[0xb68300,a36d6ba5-9c04-43ef-918b-8eb901d48d9b,"Trust.Zone",4:(tun0)]: Data: DNS Domain: '(none)'
Mar 02 10:17:22 myuser NetworkManager[446]: <info> [1488413842.4519] vpn-connection[0xb68300,a36d6ba5-9c04-43ef-918b-8eb901d48d9b,"Trust.Zone",4:(tun0)]: Data: No IPv6 configuration
Mar 02 10:17:22 myuser NetworkManager[446]: <info> [1488413842.4520] vpn-connection[0xb68300,a36d6ba5-9c04-43ef-918b-8eb901d48d9b,"Trust.Zone",4:(tun0)]: VPN plugin: state changed: started (4)
Mar 02 10:17:22 myuser NetworkManager[446]: <info> [1488413842.4548] vpn-connection[0xb68300,a36d6ba5-9c04-43ef-918b-8eb901d48d9b,"Trust.Zone",4:(tun0)]: VPN connection: (IP Config Get) complete
Mar 02 10:17:22 myuser NetworkManager[446]: <info> [1488413842.4550] device (tun0): state change: unmanaged -> unavailable (reason 'connection-assumed') [10 20 41]
Mar 02 10:17:22 myuser NetworkManager[446]: <info> [1488413842.4589] manager: NetworkManager state is now CONNECTED_LOCAL
Mar 02 10:17:22 myuser NetworkManager[446]: <info> [1488413842.4590] manager: NetworkManager state is now CONNECTED_GLOBAL
Mar 02 10:17:22 myuser NetworkManager[446]: <info> [1488413842.4629] keyfile: add connection in-memory (a4cac24e-6d29-4137-b0d3-670274f3a688,"tun0")
Mar 02 10:17:22 myuser NetworkManager[446]: <info> [1488413842.4637] device (tun0): state change: unavailable -> disconnected (reason 'connection-assumed') [20 30 41]
Mar 02 10:17:22 myuser NetworkManager[446]: <info> [1488413842.4649] device (tun0): Activation: starting connection 'tun0' (a4cac24e-6d29-4137-b0d3-670274f3a688)
Mar 02 10:17:22 myuser NetworkManager[446]: <info> [1488413842.5033] device (tun0): state change: disconnected -> prepare (reason 'none') [30 40 0]
Mar 02 10:17:22 myuser NetworkManager[446]: <info> [1488413842.5043] device (tun0): state change: prepare -> config (reason 'none') [40 50 0]
Mar 02 10:17:22 myuser NetworkManager[446]: <info> [1488413842.5045] device (tun0): state change: config -> ip-config (reason 'none') [50 70 0]
Mar 02 10:17:22 myuser NetworkManager[446]: <info> [1488413842.5178] device (tun0): state change: ip-config -> ip-check (reason 'none') [70 80 0]
Mar 02 10:17:22 myuser NetworkManager[446]: <info> [1488413842.5182] device (tun0): state change: ip-check -> secondaries (reason 'none') [80 90 0]
Mar 02 10:17:22 myuser NetworkManager[446]: <info> [1488413842.5189] device (tun0): state change: secondaries -> activated (reason 'none') [90 100 0]
Mar 02 10:17:22 myuser NetworkManager[446]: <info> [1488413842.5256] manager: NetworkManager state is now CONNECTED_LOCAL
Mar 02 10:17:22 myuser NetworkManager[446]: <info> [1488413842.5257] manager: NetworkManager state is now CONNECTED_GLOBAL
Mar 02 10:17:22 myuser NetworkManager[446]: <info> [1488413842.5257] policy: set 'tun0' (tun0) as default for IPv4 routing and DNS
Mar 02 10:17:22 myuser NetworkManager[446]: <info> [1488413842.5258] device (tun0): Activation: successful, device activated.
Mar 02 10:17:34 myuser nm-openvpn[1902]: Connection reset, restarting [0]
Mar 02 10:17:34 myuser nm-openvpn[1902]: SIGUSR1[soft,connection-reset] received, process restarting
Mar 02 10:17:39 myuser nm-openvpn[1902]: NOTE: the current --script-security setting may allow this configuration to call user-defined scripts
Mar 02 10:17:39 myuser nm-openvpn[1902]: TCP/UDP: Preserving recently used remote address: [AF_INET]221.121.158.231:443
Mar 02 10:17:39 myuser nm-openvpn[1902]: Attempting to establish TCP connection with [AF_INET]221.121.158.231:443 [nonblock]
Mar 02 10:17:40 myuser nm-openvpn[1902]: TCP connection established with [AF_INET]221.121.158.231:443
Mar 02 10:17:40 myuser nm-openvpn[1902]: TCP_CLIENT link local: (not bound)
Mar 02 10:17:40 myuser nm-openvpn[1902]: TCP_CLIENT link remote: [AF_INET]221.121.158.231:443
Mar 02 10:17:40 myuser nm-openvpn[1902]: [vpn.trust.zone] Peer Connection Initiated with [AF_INET]221.121.158.231:443
Mar 02 10:17:43 myuser nm-openvpn[1902]: Preserving previous TUN/TAP instance: tun0
Mar 02 10:17:43 myuser nm-openvpn[1902]: /usr/lib/NetworkManager/nm-openvpn-service-openvpn-helper --debug 0 1896 --bus-name org.freedesktop.NetworkManager.openvpn.Connection_5 --tun -- tun0 1500 1571 10.12.35.165 10.12.35.166 restart
Mar 02 10:17:43 myuser nm-openvpn[1902]: Initialization Sequence Completed
Mar 02 10:17:55 myuser nm-openvpn[1902]: Connection reset, restarting [0]
Mar 02 10:17:55 myuser nm-openvpn[1902]: SIGUSR1[soft,connection-reset] received, process restarting
Last edited by EchoJoe (2017-03-03 00:53:44)
Offline
Your output of 'journalctl -p err -xb' is truncated, that doesn't help.
Try using openvpn directly and see if it works, if it does then the problem is with network manager, if not then the output of openvpn might contain clues as to why it is not working.
R00KIE
Tm90aGluZyB0byBzZWUgaGVyZSwgbW92ZSBhbG9uZy4K
Offline
Colud you guide me how to post the output of openvpn? I think the problem could be the network manager as it resets the connection for some reason...
Offline
Colud you guide me how to post the output of openvpn? I think the problem could be the network manager as it resets the connection for some reason...
Copy/paste? Make sure you use code tags. https://wiki.archlinux.org/index.php/Co … s_and_code
R00KIE
Tm90aGluZyB0byBzZWUgaGVyZSwgbW92ZSBhbG9uZy4K
Offline
So using openvpn directly (without network manager) seems to work smoothly. I can be sure now networkmanager is the issue here.
This problem started after OpenVPN was updated in 2016-12-30 making networkmanager restart the conection. I am going to update the tittle since it seems to be a networkmanager problem. Can ths be related to this bug https://community.openvpn.net/openvpn/ticket/812 ? Is there anything else I can provide to check farther?
openvpn output
[root@mypc client]# openvpn /etc/openvpn/client/client.conf
Fri Mar 10 12:07:36 2017 WARNING: file 'login.conf' is group or others accessible
Fri Mar 10 12:07:36 2017 OpenVPN 2.4.0 x86_64-unknown-linux-gnu [SSL (OpenSSL)] [LZO] [LZ4] [EPOLL] [PKCS11] [MH/PKTINFO] [AEAD] built on Dec 28 2016
Fri Mar 10 12:07:36 2017 library versions: OpenSSL 1.0.2k 26 Jan 2017, LZO 2.10
Fri Mar 10 12:07:36 2017 WARNING: No server certificate verification method has been enabled. See http://openvpn.net/howto.html#mitm for more info.
Fri Mar 10 12:07:37 2017 TCP/UDP: Preserving recently used remote address: [AF_INET]221.121.158.231:443
Fri Mar 10 12:07:37 2017 Socket Buffers: R=[212992->212992] S=[212992->212992]
Fri Mar 10 12:07:37 2017 UDP link local: (not bound)
Fri Mar 10 12:07:37 2017 UDP link remote: [AF_INET]221.121.158.231:443
Fri Mar 10 12:07:37 2017 NOTE: UID/GID downgrade will be delayed because of --client, --pull, or --up-delay
Fri Mar 10 12:07:37 2017 TLS: Initial packet from [AF_INET]221.121.158.231:443, sid=87b3043e f082e94a
Fri Mar 10 12:07:37 2017 WARNING: this configuration may cache passwords in memory -- use the auth-nocache option to prevent this
Fri Mar 10 12:07:37 2017 VERIFY OK: depth=0, CN=vpn.trust.zone
Fri Mar 10 12:07:37 2017 Control Channel: TLSv1, cipher TLSv1/SSLv3 DHE-RSA-AES256-SHA, 2048 bit RSA
Fri Mar 10 12:07:37 2017 [vpn.trust.zone] Peer Connection Initiated with [AF_INET]221.121.158.231:443
Fri Mar 10 12:07:38 2017 SENT CONTROL [vpn.trust.zone]: 'PUSH_REQUEST' (status=1)
Fri Mar 10 12:07:43 2017 SENT CONTROL [vpn.trust.zone]: 'PUSH_REQUEST' (status=1)
Fri Mar 10 12:07:43 2017 PUSH: Received control message: 'PUSH_REPLY,ping 3,ping-restart 10,ifconfig 10.0.16.189 10.0.16.190,dhcp-option DNS 8.8.8.8,dhcp-option DNS 8.8.4.4,route-gateway 10.0.16.190,redirect-gateway def1'
Fri Mar 10 12:07:43 2017 OPTIONS IMPORT: timers and/or timeouts modified
Fri Mar 10 12:07:43 2017 OPTIONS IMPORT: --ifconfig/up options modified
Fri Mar 10 12:07:43 2017 OPTIONS IMPORT: route options modified
Fri Mar 10 12:07:43 2017 OPTIONS IMPORT: route-related options modified
Fri Mar 10 12:07:43 2017 OPTIONS IMPORT: --ip-win32 and/or --dhcp-option options modified
Fri Mar 10 12:07:43 2017 Data Channel Encrypt: Cipher 'AES-256-CBC' initialized with 256 bit key
Fri Mar 10 12:07:43 2017 Data Channel Encrypt: Using 160 bit message hash 'SHA1' for HMAC authentication
Fri Mar 10 12:07:43 2017 Data Channel Decrypt: Cipher 'AES-256-CBC' initialized with 256 bit key
Fri Mar 10 12:07:43 2017 Data Channel Decrypt: Using 160 bit message hash 'SHA1' for HMAC authentication
Fri Mar 10 12:07:43 2017 ROUTE_GATEWAY 192.168.1.1/255.255.255.0 IFACE=wlp58s0 HWADDR=54:8c:a0:a2:f1:97
Fri Mar 10 12:07:43 2017 TUN/TAP device tun0 opened
Fri Mar 10 12:07:43 2017 TUN/TAP TX queue length set to 100
Fri Mar 10 12:07:43 2017 do_ifconfig, tt->did_ifconfig_ipv6_setup=0
Fri Mar 10 12:07:43 2017 /usr/bin/ip link set dev tun0 up mtu 1500
Fri Mar 10 12:07:43 2017 /usr/bin/ip addr add dev tun0 local 10.0.16.189 peer 10.0.16.190
Fri Mar 10 12:07:43 2017 /usr/bin/ip route add 221.121.158.231/32 via 192.168.1.1
Fri Mar 10 12:07:43 2017 /usr/bin/ip route add 0.0.0.0/1 via 10.0.16.190
Fri Mar 10 12:07:43 2017 /usr/bin/ip route add 128.0.0.0/1 via 10.0.16.190
Fri Mar 10 12:07:43 2017 GID set to nobody
Fri Mar 10 12:07:43 2017 UID set to nobody
Fri Mar 10 12:07:43 2017 Initialization Sequence Completed
Last edited by EchoJoe (2017-03-10 02:49:38)
Offline
Have you found a solution to this? I am having the same problem both on a XPS15 9550 and Thinkpad T440s
Offline