staging.inyokaproject.org

ipv6 leak bei openvpn

Status: Gelöst | Ubuntu-Version: Kubuntu 24.04 (Noble Numbat)
Antworten |

gazrilla92

Anmeldungsdatum:
16. Januar 2024

Beiträge: 71

Hallo zusammen, ich betreibe einen raspy mit pivpn. Das Setup habe ich so umgebaut, dass der Server per Dual Stack ipv4 und ipv6 durch den ipv4-Tunnel routet. Das Subnetz und diverse zu setzende Regeln werden durch ein Skript abgeleitet, wenn sich die ipv6 ändert. Die server.conf und die ccd-Dateien werden automatisch angepasst. Mit dem Handy bekomme ich den Full-Tunnel hin. Beim Laptop scheitert es jedoch und ich weiß einfach nicht mehr weiter. Über Hilfe und Ratschläge würde ich mich sehr freuen.

max@ugly-unicorn:~$ ip a
1: lo: <LOOPBACK,UP,LOWER_UP> mtu 65536 qdisc noqueue state UNKNOWN group default qlen 1000
    link/loopback 00:00:00:00:00:00 brd 00:00:00:00:00:00
    inet 127.0.0.1/8 scope host lo
       valid_lft forever preferred_lft forever
    inet6 ::1/128 scope host noprefixroute 
       valid_lft forever preferred_lft forever
2: wlo1: <NO-CARRIER,BROADCAST,MULTICAST,UP> mtu 1500 qdisc noqueue state DOWN group default qlen 1000
    link/ether 40:1a:58:26:5e:72 brd ff:ff:ff:ff:ff:ff
    altname wlp1s0
9: wlx3498b53584d6: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc noqueue state UP group default qlen 1000
    link/ether 34:98:b5:35:84:d6 brd ff:ff:ff:ff:ff:ff
    inet 192.168.178.24/24 brd 192.168.178.255 scope global dynamic noprefixroute wlx3498b53584d6
       valid_lft 863133sec preferred_lft 863133sec
    inet6 2a02:3100:2343:c200:d604:efd1:c6e:f153/64 scope global temporary dynamic 
       valid_lft 7066sec preferred_lft 3466sec
    inet6 2a02:3100:2343:c200:2019:6275:34c:b85d/64 scope global dynamic mngtmpaddr noprefixroute 
       valid_lft 7066sec preferred_lft 3466sec
    inet6 fd84:9c99:3e08:0:6bb7:7d50:9e00:aa72/64 scope global temporary dynamic 
       valid_lft 7066sec preferred_lft 3466sec
    inet6 fd84:9c99:3e08:0:7908:5372:48dc:e786/64 scope global dynamic mngtmpaddr noprefixroute 
       valid_lft 7066sec preferred_lft 3466sec
    inet6 fe80::9be0:2aae:3d3b:55db/64 scope link noprefixroute 
       valid_lft forever preferred_lft forever
10: tun0: <POINTOPOINT,MULTICAST,NOARP,UP,LOWER_UP> mtu 1500 qdisc fq_codel state UNKNOWN group default qlen 500
    link/none 
    inet 10.125.175.2/24 brd 10.125.175.255 scope global noprefixroute tun0
       valid_lft forever preferred_lft forever
    inet6 fe80::6e56:47ce:6f8f:4d67/64 scope link stable-privacy 
       valid_lft forever preferred_lft forever
max@ugly-unicorn:~$ ip -6 route show
2a02:3100:2343:c200::/64 dev wlx3498b53584d6 proto ra metric 600 pref medium
2a02:3100:2343:c200::/56 via fe80::d624:ddff:fe1e:6170 dev wlx3498b53584d6 proto ra metric 600 pref medium
fd84:9c99:3e08::/64 dev wlx3498b53584d6 proto ra metric 600 pref medium
fd84:9c99:3e08::/64 via fe80::d624:ddff:fe1e:6170 dev wlx3498b53584d6 proto ra metric 605 pref medium
fe80::/64 dev tun0 proto kernel metric 256 pref medium
fe80::/64 dev wlx3498b53584d6 proto kernel metric 1024 pref medium
default via fe80::d624:ddff:fe1e:6170 dev wlx3498b53584d6 proto ra metric 600 pref medium

Danke schon mal

Liebe Grüße

gazrilla92

(Themenstarter)

Anmeldungsdatum:
16. Januar 2024

Beiträge: 71

das ist meine server conf:

dev tun
proto udp
port 1194
ca /etc/openvpn/easy-rsa/pki/ca.crt
cert /etc/openvpn/easy-rsa/pki/issued/clumsy-camel_67c1b959-7d87-48c4-a94c-298162db268e.crt
key /etc/openvpn/easy-rsa/pki/private/clumsy-camel_67c1b959-7d87-48c4-a94c-298162db268e.key
dh none
ecdh-curve secp384r1
topology subnet
server 10.125.175.0 255.255.255.0
# Set your primary domain name server address for clients
push "dhcp-option DNS 10.125.175.1"
push "block-outside-dns"
# Override the Client default gateway by using 0.0.0.0/1 and
# 128.0.0.0/1 rather than 0.0.0.0/0. This has the benefit of
# overriding but not wiping out the original default gateway.
push "redirect-gateway def1"
# IPv6 VPN-Subnetz (Dual-Stack)
server-ipv6 2a02:3100:1abc:9c01::/64

# IPv6 Clients sollen alles routen
push "redirect-gateway ipv6"
push "route-ipv6 ::/0"

# IPv6 DNS (Cloudflare / Google)
push "dhcp-option DNS 192.168.178.100"
push "dhcp-option DNS ::fab1:318b:198f:30a7"

client-to-client
client-config-dir /etc/openvpn/ccd
keepalive 15 120
remote-cert-tls client
tls-version-min 1.3
tls-crypt-v2 /etc/openvpn/easy-rsa/pki/tc-v2/server.key
tls-crypt-v2-verify /opt/pivpn/openvpn/TLSCryptV2Verify.sh
script-security 2
cipher AES-256-CBC
auth SHA256
user openvpn
group openvpn
persist-key
persist-tun
crl-verify /etc/openvpn/crl.pem
status /var/log/openvpn-status.log 20
status-version 3
syslog
verb 3

mittlerweile hat sich die ipv6 geändert, das hat seine Richtigkeit.

DJKUhpisse Team-Icon

Supporter, Wikiteam
Avatar von DJKUhpisse

Anmeldungsdatum:
18. Oktober 2016

Beiträge: 18245

Kannst du beim Tunnelaufbau ggf. mal in die Logs am Client und am Server schauen? Ggf auf verbose-Logs umstellen.

Nimmst du den Networkmanager oder einen anderen Client?

gazrilla92

(Themenstarter)

Anmeldungsdatum:
16. Januar 2024

Beiträge: 71

Hey danke für deine Antwort. Wie und wo sehe ich denn die Logos? Unter Linux verbinde ich mich mit dem Networkmanager, unter Android mit der App.

DJKUhpisse Team-Icon

Supporter, Wikiteam
Avatar von DJKUhpisse

Anmeldungsdatum:
18. Oktober 2016

Beiträge: 18245

nmcli general logging

bietet sich an, da gibt es verschiedene Domains und Loglevel.

gazrilla92

(Themenstarter)

Anmeldungsdatum:
16. Januar 2024

Beiträge: 71

nmcli general logging
LEVEL  DOMAINS                                                                                                                                                                                                                       
INFO   PLATFORM,RFKILL,ETHER,WIFI,BT,MB,DHCP4,DHCP6,PPP,IP4,IP6,AUTOIP4,DNS,VPN,SHARING,SUPPLICANT,AGENTS,SETTINGS,SUSPEND,CORE,DEVICE,OLPC,INFINIBAND,FIREWALL,ADSL,BOND,VLAN,BRIDGE,TEAM,CONCHECK,DCB,DISPATCH,AUDIT,SYSTEMD,PROXY 

Mit den meisten Optionen bekomme ich keine Ausgabe.

journalctl -u NetworkManager -f
Sep 08 23:40:21 ugly-unicorn NetworkManager[1171]: <debug> [1757367621.2421] platform: (wlx3498b53584d6) signal: link changed: 3: wlx3498b53584d6 <UP,LOWER_UP;broadcast,multicast,up,running,lowerup> mtu 1500 arp 1 wifi? init addrgenmode none addr 34:98:B5:35:84:D6 permaddr 34:98:B5:35:84:D6 brd FF:FF:FF:FF:FF:FF driver rtw_8822bu tx-queue-len 1000 gso-max-size 65536 gso-max-segs 65535 gro-max-size 65536 rx:12143,3029116 tx:8267,2640172
Sep 08 23:40:21 ugly-unicorn NetworkManager[1171]: <trace> [1757367621.2421] l3cfg[54dd9751830c9bcd,ifindex=3]: emit signal (platform-change, obj-type=link, change=changed, obj=3: wlx3498b53584d6 <UP,LOWER_UP;broadcast,multicast,up,running,lowerup> mtu 1500 arp 1 wifi? init addrgenmode none addr 34:98:B5:35:84:D6 permaddr 34:98:B5:35:84:D6 brd FF:FF:FF:FF:FF:FF driver rtw_8822bu tx-queue-len 1000 gso-max-size 65536 gso-max-segs 65535 gro-max-size 65536 rx:12143,3029116 tx:8267,2640172)
Sep 08 23:40:21 ugly-unicorn NetworkManager[1171]: <debug> [1757367621.2421] device[e44fe1fa71210445] (wlx3498b53584d6): queued link change for ifindex 3
Sep 08 23:40:21 ugly-unicorn NetworkManager[1171]: <trace> [1757367621.2421] l3cfg[54dd9751830c9bcd,ifindex=3]: emit signal (platform-change-on-idle, obj-type-flags=0x2)
Sep 08 23:40:21 ugly-unicorn NetworkManager[1171]: <trace> [1757367621.6458] device[7fdd286ca9965dd3] (wlo1): stats: refresh 2
Sep 08 23:40:21 ugly-unicorn NetworkManager[1171]: <debug> [1757367621.6458] platform-linux: do-request-link: 2 
Sep 08 23:40:21 ugly-unicorn NetworkManager[1171]: <trace> [1757367621.6459] platform-linux: event-notification: RTM_NEWLINK, flags 0, seq 8378: 2: wlo1 <UP;broadcast,multicast,up> mtu 1500 arp 1 wifi? not-init addrgenmode none addr 40:1A:58:26:5E:72 permaddr 40:1A:58:26:5E:72 brd FF:FF:FF:FF:FF:FF tx-queue-len 1000 gso-max-size 65536 gso-max-segs 65535 gro-max-size 65536 rx:14293,13463955 tx:5486,2111465
Sep 08 23:40:21 ugly-unicorn NetworkManager[1171]: <trace> [1757367621.7421] device[e44fe1fa71210445] (wlx3498b53584d6): stats: refresh 3
Sep 08 23:40:21 ugly-unicorn NetworkManager[1171]: <debug> [1757367621.7421] platform-linux: do-request-link: 3 
Sep 08 23:40:21 ugly-unicorn NetworkManager[1171]: <trace> [1757367621.7422] platform-linux: event-notification: RTM_NEWLINK, flags 0, seq 8379: 3: wlx3498b53584d6 <UP,LOWER_UP;broadcast,multicast,up,running,lowerup> mtu 1500 arp 1 wifi? not-init addrgenmode none addr 34:98:B5:35:84:D6 permaddr 34:98:B5:35:84:D6 brd FF:FF:FF:FF:FF:FF tx-queue-len 1000 gso-max-size 65536 gso-max-segs 65535 gro-max-size 65536 rx:12143,3029116 tx:8267,2640172
Sep 08 23:40:22 ugly-unicorn NetworkManager[1171]: <trace> [1757367622.1467] device[7fdd286ca9965dd3] (wlo1): stats: refresh 2
Sep 08 23:40:22 ugly-unicorn NetworkManager[1171]: <debug> [1757367622.1467] platform-linux: do-request-link: 2 
Sep 08 23:40:22 ugly-unicorn NetworkManager[1171]: <trace> [1757367622.1468] platform-linux: event-notification: RTM_NEWLINK, flags 0, seq 8380: 2: wlo1 <UP;broadcast,multicast,up> mtu 1500 arp 1 wifi? not-init addrgenmode none addr 40:1A:58:26:5E:72 permaddr 40:1A:58:26:5E:72 brd FF:FF:FF:FF:FF:FF tx-queue-len 1000 gso-max-size 65536 gso-max-segs 65535 gro-max-size 65536 rx:14293,13463955 tx:5486,2111465
Sep 08 23:40:22 ugly-unicorn NetworkManager[1171]: <trace> [1757367622.2430] device[e44fe1fa71210445] (wlx3498b53584d6): stats: refresh 3
Sep 08 23:40:22 ugly-unicorn NetworkManager[1171]: <debug> [1757367622.2430] platform-linux: do-request-link: 3 
Sep 08 23:40:22 ugly-unicorn NetworkManager[1171]: <trace> [1757367622.2431] platform-linux: event-notification: RTM_NEWLINK, flags 0, seq 8381: 3: wlx3498b53584d6 <UP,LOWER_UP;broadcast,multicast,up,running,lowerup> mtu 1500 arp 1 wifi? not-init addrgenmode none addr 34:98:B5:35:84:D6 permaddr 34:98:B5:35:84:D6 brd FF:FF:FF:FF:FF:FF tx-queue-len 1000 gso-max-size 65536 gso-max-segs 65535 gro-max-size 65536 rx:12143,3029116 tx:8267,2640172
Sep 08 23:40:22 ugly-unicorn NetworkManager[1171]: <trace> [1757367622.6476] device[7fdd286ca9965dd3] (wlo1): stats: refresh 2
Sep 08 23:40:22 ugly-unicorn NetworkManager[1171]: <debug> [1757367622.6476] platform-linux: do-request-link: 2 
Sep 08 23:40:22 ugly-unicorn NetworkManager[1171]: <trace> [1757367622.6477] platform-linux: event-notification: RTM_NEWLINK, flags 0, seq 8382: 2: wlo1 <UP;broadcast,multicast,up> mtu 1500 arp 1 wifi? not-init addrgenmode none addr 40:1A:58:26:5E:72 permaddr 40:1A:58:26:5E:72 brd FF:FF:FF:FF:FF:FF tx-queue-len 1000 gso-max-size 65536 gso-max-segs 65535 gro-max-size 65536 rx:14293,13463955 tx:5486,2111465

Wie lese ich die Logs am Server aus? Danke dir erstmal bis hier her. ☺)

DJKUhpisse Team-Icon

Supporter, Wikiteam
Avatar von DJKUhpisse

Anmeldungsdatum:
18. Oktober 2016

Beiträge: 18245

Du musst schon die Logs vom VPN zeigen. Gab es solche? Die Liste kann hier sehr lang sein.

gazrilla92

(Themenstarter)

Anmeldungsdatum:
16. Januar 2024

Beiträge: 71

ed to BF-CBC as fallback when cipher negotiation failed in this case. If you need this fallback please add '--data-ciphers-fallback BF-CBC' to your configuration and/or add BF-CBC to --data-ciphers.
Sep 07 22:58:29 ugly-unicorn nm-openvpn[19328]: OpenVPN 2.6.14 x86_64-pc-linux-gnu [SSL (OpenSSL)] [LZO] [LZ4] [EPOLL] [PKCS11] [MH/PKTINFO] [AEAD] [DCO]
Sep 07 22:58:29 ugly-unicorn nm-openvpn[19328]: library versions: OpenSSL 3.0.13 30 Jan 2024, LZO 2.10
Sep 07 22:58:29 ugly-unicorn nm-openvpn[19328]: DCO version: N/A
Sep 07 22:58:29 ugly-unicorn nm-openvpn[19328]: NOTE: the current --script-security setting may allow this configuration to call user-defined scripts
Sep 07 22:58:29 ugly-unicorn nm-openvpn[19328]: TCP/UDP: Preserving recently used remote address: [AF_INET]92.224.216.192:1194
Sep 07 22:58:29 ugly-unicorn nm-openvpn[19328]: UDPv4 link local: (not bound)
Sep 07 22:58:29 ugly-unicorn nm-openvpn[19328]: UDPv4 link remote: [AF_INET]92.224.216.192:1194
Sep 07 22:58:29 ugly-unicorn nm-openvpn[19328]: NOTE: UID/GID downgrade will be delayed because of --client, --pull, or --up-delay
Sep 07 22:58:29 ugly-unicorn nm-openvpn[19328]: [clumsy-camel_67c1b959-7d87-48c4-a94c-298162db268e] Peer Connection Initiated with [AF_INET]92.224.216.192:1194
Sep 07 22:58:29 ugly-unicorn nm-openvpn[19328]: Options error: Unrecognized option or missing or extra parameter(s) in [PUSH-OPTIONS]:2: block-outside-dns (2.6.14)
Sep 07 22:58:29 ugly-unicorn nm-openvpn[19328]: WARNING: You have specified redirect-gateway and redirect-private at the same time (or the same option multiple times). This is not well supported and may lead to unexpected results
Sep 07 22:58:29 ugly-unicorn nm-openvpn[19328]: Options error: ifconfig-ipv6: /netbits must be between 64 and 124, not '/128'
Sep 07 22:58:29 ugly-unicorn nm-openvpn[19328]: TUN/TAP device tun0 opened
Sep 07 22:58:29 ugly-unicorn nm-openvpn[19328]: /usr/libexec/nm-openvpn-service-openvpn-helper --debug 0 19313 --bus-name org.freedesktop.NetworkManager.openvpn.Connection_70 --tun -- tun0 1500 0 10.125.175.2 255.255.255.0 init
Sep 07 22:58:29 ugly-unicorn nm-openvpn[19328]: UID set to nm-openvpn
Sep 07 22:58:29 ugly-unicorn nm-openvpn[19328]: GID set to nm-openvpn
Sep 07 22:58:29 ugly-unicorn nm-openvpn[19328]: Capabilities retained: CAP_NET_ADMIN
Sep 07 22:58:29 ugly-unicorn nm-openvpn[19328]: Initialization Sequence Completed
Sep 07 23:00:44 ugly-unicorn nm-openvpn[19328]: event_wait : Interrupted system call (fd=-1,code=4)
Sep 07 23:00:45 ugly-unicorn nm-openvpn[19328]: SIGTERM[hard,] received, process exiting
Sep 08 00:02:20 ugly-unicorn NetworkManager[1131]: <info>  [1757282540.5481] vpn[0x58cc62e98550,e9dfa2a6-40a8-4980-9870-eb809ccfa382,"Max_Laptop"]: starting openvpn
Sep 08 00:02:24 ugly-unicorn nm-openvpn[3628]: Note: --cipher is not set. OpenVPN versions before 2.5 defaulted to BF-CBC as fallback when cipher negotiation failed in this case. If you need this fallback please add '--data-ciphers-fallback BF-CBC' to your configuration and/or add BF-CBC to --data-ciphers.
Sep 08 00:02:24 ugly-unicorn nm-openvpn[3628]: OpenVPN 2.6.14 x86_64-pc-linux-gnu [SSL (OpenSSL)] [LZO] [LZ4] [EPOLL] [PKCS11] [MH/PKTINFO] [AEAD] [DCO]
Sep 08 00:02:24 ugly-unicorn nm-openvpn[3628]: library versions: OpenSSL 3.0.13 30 Jan 2024, LZO 2.10
Sep 08 00:02:24 ugly-unicorn nm-openvpn[3628]: DCO version: N/A
Sep 08 00:02:24 ugly-unicorn nm-openvpn[3628]: NOTE: the current --script-security setting may allow this configuration to call user-defined scripts
Sep 08 00:02:25 ugly-unicorn nm-openvpn[3628]: TCP/UDP: Preserving recently used remote address: [AF_INET]92.224.216.192:1194
Sep 08 00:02:25 ugly-unicorn nm-openvpn[3628]: UDPv4 link local: (not bound)
Sep 08 00:02:25 ugly-unicorn nm-openvpn[3628]: UDPv4 link remote: [AF_INET]92.224.216.192:1194
Sep 08 00:02:25 ugly-unicorn nm-openvpn[3628]: NOTE: UID/GID downgrade will be delayed because of --client, --pull, or --up-delay
Sep 08 00:02:25 ugly-unicorn nm-openvpn[3628]: [clumsy-camel_67c1b959-7d87-48c4-a94c-298162db268e] Peer Connection Initiated with [AF_INET]92.224.216.192:1194
Sep 08 00:02:25 ugly-unicorn nm-openvpn[3628]: Options error: Unrecognized option or missing or extra parameter(s) in [PUSH-OPTIONS]:2: block-outside-dns (2.6.14)
Sep 08 00:02:25 ugly-unicorn nm-openvpn[3628]: WARNING: You have specified redirect-gateway and redirect-private at the same time (or the same option multiple times). This is not well supported and may lead to unexpected results
Sep 08 00:02:25 ugly-unicorn nm-openvpn[3628]: Options error: ifconfig-ipv6: /netbits must be between 64 and 124, not '/128'
Sep 08 00:02:25 ugly-unicorn nm-openvpn[3628]: TUN/TAP device tun0 opened
Sep 08 00:02:25 ugly-unicorn nm-openvpn[3628]: /usr/libexec/nm-openvpn-service-openvpn-helper --debug 0 3617 --bus-name org.freedesktop.NetworkManager.openvpn.Connection_4 --tun -- tun0 1500 0 10.125.175.2 255.255.255.0 init
Sep 08 00:02:25 ugly-unicorn nm-openvpn[3628]: UID set to nm-openvpn
Sep 08 00:02:25 ugly-unicorn nm-openvpn[3628]: GID set to nm-openvpn
Sep 08 00:02:25 ugly-unicorn nm-openvpn[3628]: Capabilities retained: CAP_NET_ADMIN
Sep 08 00:02:25 ugly-unicorn nm-openvpn[3628]: Initialization Sequence Completed
Sep 08 00:05:07 ugly-unicorn nm-openvpn[3628]: [clumsy-camel_67c1b959-7d87-48c4-a94c-298162db268e] Inactivity timeout (--ping-restart), restarting
Sep 08 00:05:07 ugly-unicorn nm-openvpn[3628]: SIGUSR1[soft,ping-restart] received, process restarting
Sep 08 00:05:08 ugly-unicorn nm-openvpn[3628]: NOTE: the current --script-security setting may allow this configuration to call user-defined scripts
Sep 08 00:05:08 ugly-unicorn nm-openvpn[3628]: TCP/UDP: Preserving recently used remote address: [AF_INET]92.224.216.192:1194
Sep 08 00:05:08 ugly-unicorn nm-openvpn[3628]: UDPv4 link local: (not bound)
Sep 08 00:05:08 ugly-unicorn nm-openvpn[3628]: UDPv4 link remote: [AF_INET]92.224.216.192:1194
Sep 08 00:05:08 ugly-unicorn nm-openvpn[3628]: [clumsy-camel_67c1b959-7d87-48c4-a94c-298162db268e] Peer Connection Initiated with [AF_INET]92.224.216.192:1194
Sep 08 00:05:08 ugly-unicorn nm-openvpn[3628]: Options error: Unrecognized option or missing or extra parameter(s) in [PUSH-OPTIONS]:2: block-outside-dns (2.6.14)
Sep 08 00:05:08 ugly-unicorn nm-openvpn[3628]: WARNING: You have specified redirect-gateway and redirect-private at the same time (or the same option multiple times). This is not well supported and may lead to unexpected results
Sep 08 00:05:08 ugly-unicorn nm-openvpn[3628]: Options error: ifconfig-ipv6: /netbits must be between 64 and 124, not '/128'
Sep 08 00:05:08 ugly-unicorn nm-openvpn[3628]: Preserving previous TUN/TAP instance: tun0
Sep 08 00:05:08 ugly-unicorn nm-openvpn[3628]: /usr/libexec/nm-openvpn-service-openvpn-helper --debug 0 3617 --bus-name org.freedesktop.NetworkManager.openvpn.Connection_4 --tun -- tun0 1500 0 10.125.175.2 255.255.255.0 restart
Sep 08 00:05:08 ugly-unicorn nm-openvpn[3628]: Initialization Sequence Completed
Sep 08 00:09:52 ugly-unicorn nm-openvpn[3628]: event_wait : Interrupted system call (fd=-1,code=4)
Sep 08 00:09:52 ugly-unicorn nm-openvpn[3628]: SIGTERM[hard,] received, process exiting
Sep 08 00:10:02 ugly-unicorn NetworkManager[1131]: <info>  [1757283002.8859] vpn[0x58cc62e5e9b0,e9dfa2a6-40a8-4980-9870-eb809ccfa382,"Max_Laptop"]: starting openvpn
Sep 08 00:10:07 ugly-unicorn nm-openvpn[4541]: Note: --cipher is not set. OpenVPN versions before 2.5 defaulted to BF-CBC as fallback when cipher negotiation failed in this case. If you need this fallback please add '--data-ciphers-fallback BF-CBC' to your configuration and/or add BF-CBC to --data-ciphers.
Sep 08 00:10:07 ugly-unicorn nm-openvpn[4541]: OpenVPN 2.6.14 x86_64-pc-linux-gnu [SSL (OpenSSL)] [LZO] [LZ4] [EPOLL] [PKCS11] [MH/PKTINFO] [AEAD] [DCO]
Sep 08 00:10:07 ugly-unicorn nm-openvpn[4541]: library versions: OpenSSL 3.0.13 30 Jan 2024, LZO 2.10
Sep 08 00:10:07 ugly-unicorn nm-openvpn[4541]: DCO version: N/A
Sep 08 00:10:07 ugly-unicorn nm-openvpn[4541]: NOTE: the current --script-security setting may allow this configuration to call user-defined scripts
Sep 08 00:10:07 ugly-unicorn nm-openvpn[4541]: TCP/UDP: Preserving recently used remote address: [AF_INET]92.224.216.192:1194
Sep 08 00:10:07 ugly-unicorn nm-openvpn[4541]: UDPv4 link local: (not bound)
Sep 08 00:10:07 ugly-unicorn nm-openvpn[4541]: UDPv4 link remote: [AF_INET]92.224.216.192:1194
Sep 08 00:10:07 ugly-unicorn nm-openvpn[4541]: NOTE: UID/GID downgrade will be delayed because of --client, --pull, or --up-delay
Sep 08 00:10:07 ugly-unicorn nm-openvpn[4541]: [clumsy-camel_67c1b959-7d87-48c4-a94c-298162db268e] Peer Connection Initiated with [AF_INET]92.224.216.192:1194
Sep 08 00:10:07 ugly-unicorn nm-openvpn[4541]: Options error: Unrecognized option or missing or extra parameter(s) in [PUSH-OPTIONS]:2: block-outside-dns (2.6.14)
Sep 08 00:10:07 ugly-unicorn nm-openvpn[4541]: WARNING: You have specified redirect-gateway and redirect-private at the same time (or the same option multiple times). This is not well supported and may lead to unexpected results
Sep 08 00:10:07 ugly-unicorn nm-openvpn[4541]: Options error: ifconfig-ipv6: /netbits must be between 64 and 124, not '/128'
Sep 08 00:10:07 ugly-unicorn nm-openvpn[4541]: TUN/TAP device tun0 opened
Sep 08 00:10:07 ugly-unicorn nm-openvpn[4541]: /usr/libexec/nm-openvpn-service-openvpn-helper --debug 0 4528 --bus-name org.freedesktop.NetworkManager.openvpn.Connection_6 --tun -- tun0 1500 0 10.125.175.2 255.255.255.0 init
Sep 08 00:10:07 ugly-unicorn nm-openvpn[4541]: UID set to nm-openvpn
Sep 08 00:10:07 ugly-unicorn nm-openvpn[4541]: GID set to nm-openvpn
Sep 08 00:10:07 ugly-unicorn nm-openvpn[4541]: Capabilities retained: CAP_NET_ADMIN
Sep 08 00:10:07 ugly-unicorn nm-openvpn[4541]: Initialization Sequence Completed
Sep 08 00:13:32 ugly-unicorn nm-openvpn[4541]: event_wait : Interrupted system call (fd=-1,code=4)
Sep 08 00:13:32 ugly-unicorn nm-openvpn[4541]: SIGTERM[hard,] received, process exiting
Sep 08 00:14:14 ugly-unicorn NetworkManager[1131]: <info>  [1757283254.1854] vpn[0x58cc62ec5010,bca50f5a-2d01-4042-8d15-32033e76d2a8,"Max_Laptop"]: starting openvpn
Sep 08 00:14:17 ugly-unicorn nm-openvpn[4908]: Note: --cipher is not set. OpenVPN versions before 2.5 defaulted to BF-CBC as fallback when cipher negotiation failed in this case. If you need this fallback please add '--data-ciphers-fallback BF-CBC' to your configuration and/or add BF-CBC to --data-ciphers.
Sep 08 00:14:17 ugly-unicorn nm-openvpn[4908]: OpenVPN 2.6.14 x86_64-pc-linux-gnu [SSL (OpenSSL)] [LZO] [LZ4] [EPOLL] [PKCS11] [MH/PKTINFO] [AEAD] [DCO]
Sep 08 00:14:17 ugly-unicorn nm-openvpn[4908]: library versions: OpenSSL 3.0.13 30 Jan 2024, LZO 2.10
Sep 08 00:14:17 ugly-unicorn nm-openvpn[4908]: DCO version: N/A
Sep 08 00:14:17 ugly-unicorn nm-openvpn[4908]: NOTE: the current --script-security setting may allow this configuration to call user-defined scripts
Sep 08 00:14:17 ugly-unicorn nm-openvpn[4908]: TCP/UDP: Preserving recently used remote address: [AF_INET]92.224.216.192:1194
Sep 08 00:14:17 ugly-unicorn nm-openvpn[4908]: UDPv4 link local: (not bound)
Sep 08 00:14:17 ugly-unicorn nm-openvpn[4908]: UDPv4 link remote: [AF_INET]92.224.216.192:1194
Sep 08 00:14:17 ugly-unicorn nm-openvpn[4908]: NOTE: UID/GID downgrade will be delayed because of --client, --pull, or --up-delay
Sep 08 00:14:18 ugly-unicorn nm-openvpn[4908]: [clumsy-camel_67c1b959-7d87-48c4-a94c-298162db268e] Peer Connection Initiated with [AF_INET]92.224.216.192:1194
Sep 08 00:14:18 ugly-unicorn nm-openvpn[4908]: Options error: Unrecognized option or missing or extra parameter(s) in [PUSH-OPTIONS]:2: block-outside-dns (2.6.14)
Sep 08 00:14:18 ugly-unicorn nm-openvpn[4908]: WARNING: You have specified redirect-gateway and redirect-private at the same time (or the same option multiple times). This is not well supported and may lead to unexpected results
Sep 08 00:14:18 ugly-unicorn nm-openvpn[4908]: Options error: ifconfig-ipv6: /netbits must be between 64 and 124, not '/128'
Sep 08 00:14:18 ugly-unicorn nm-openvpn[4908]: TUN/TAP device tun0 opened
Sep 08 00:14:18 ugly-unicorn nm-openvpn[4908]: /usr/libexec/nm-openvpn-service-openvpn-helper --debug 0 4894 --bus-name org.freedesktop.NetworkManager.openvpn.Connection_8 --tun -- tun0 1500 0 10.125.175.2 255.255.255.0 init
Sep 08 00:14:18 ugly-unicorn nm-openvpn[4908]: UID set to nm-openvpn
Sep 08 00:14:18 ugly-unicorn nm-openvpn[4908]: GID set to nm-openvpn
Sep 08 00:14:18 ugly-unicorn nm-openvpn[4908]: Capabilities retained: CAP_NET_ADMIN
Sep 08 00:14:18 ugly-unicorn nm-openvpn[4908]: Initialization Sequence Completed
Sep 08 00:15:36 ugly-unicorn nm-openvpn[4908]: event_wait : Interrupted system call (fd=-1,code=4)
Sep 08 00:15:36 ugly-unicorn nm-openvpn[4908]: SIGTERM[hard,] received, process exiting
Sep 08 00:15:38 ugly-unicorn NetworkManager[1131]: <info>  [1757283338.7523] vpn[0x58cc62ec07a0,bca50f5a-2d01-4042-8d15-32033e76d2a8,"Max_Laptop"]: starting openvpn
Sep 08 00:15:42 ugly-unicorn nm-openvpn[5001]: Note: --cipher is not set. OpenVPN versions before 2.5 defaulted to BF-CBC as fallback when cipher negotiation failed in this case. If you need this fallback please add '--data-ciphers-fallback BF-CBC' to your configuration and/or add BF-CBC to --data-ciphers.
Sep 08 00:15:42 ugly-unicorn nm-openvpn[5001]: OpenVPN 2.6.14 x86_64-pc-linux-gnu [SSL (OpenSSL)] [LZO] [LZ4] [EPOLL] [PKCS11] [MH/PKTINFO] [AEAD] [DCO]
Sep 08 00:15:42 ugly-unicorn nm-openvpn[5001]: library versions: OpenSSL 3.0.13 30 Jan 2024, LZO 2.10
Sep 08 00:15:42 ugly-unicorn nm-openvpn[5001]: DCO version: N/A
Sep 08 00:15:42 ugly-unicorn nm-openvpn[5001]: NOTE: the current --script-security setting may allow this configuration to call user-defined scripts
Sep 08 00:15:42 ugly-unicorn nm-openvpn[5001]: TCP/UDP: Preserving recently used remote address: [AF_INET]92.224.216.192:1194
Sep 08 00:15:42 ugly-unicorn nm-openvpn[5001]: UDPv4 link local: (not bound)
Sep 08 00:15:42 ugly-unicorn nm-openvpn[5001]: UDPv4 link remote: [AF_INET]92.224.216.192:1194
Sep 08 00:15:42 ugly-unicorn nm-openvpn[5001]: NOTE: UID/GID downgrade will be delayed because of --client, --pull, or --up-delay
Sep 08 00:15:42 ugly-unicorn nm-openvpn[5001]: [clumsy-camel_67c1b959-7d87-48c4-a94c-298162db268e] Peer Connection Initiated with [AF_INET]92.224.216.192:1194
Sep 08 00:15:42 ugly-unicorn nm-openvpn[5001]: Options error: Unrecognized option or missing or extra parameter(s) in [PUSH-OPTIONS]:2: block-outside-dns (2.6.14)
Sep 08 00:15:42 ugly-unicorn nm-openvpn[5001]: WARNING: You have specified redirect-gateway and redirect-private at the same time (or the same option multiple times). This is not well supported and may lead to unexpected results
Sep 08 00:15:42 ugly-unicorn nm-openvpn[5001]: Options error: ifconfig-ipv6: /netbits must be between 64 and 124, not '/128'
Sep 08 00:15:42 ugly-unicorn nm-openvpn[5001]: TUN/TAP device tun0 opened
Sep 08 00:15:42 ugly-unicorn nm-openvpn[5001]: /usr/libexec/nm-openvpn-service-openvpn-helper --debug 0 4989 --bus-name org.freedesktop.NetworkManager.openvpn.Connection_10 --tun -- tun0 1500 0 10.125.175.2 255.255.255.0 init
Sep 08 00:15:42 ugly-unicorn nm-openvpn[5001]: UID set to nm-openvpn
Sep 08 00:15:42 ugly-unicorn nm-openvpn[5001]: GID set to nm-openvpn
Sep 08 00:15:42 ugly-unicorn nm-openvpn[5001]: Capabilities retained: CAP_NET_ADMIN
Sep 08 00:15:42 ugly-unicorn nm-openvpn[5001]: Initialization Sequence Completed
Sep 08 00:20:26 ugly-unicorn nm-openvpn[5001]: event_wait : Interrupted system call (fd=-1,code=4)
Sep 08 00:20:26 ugly-unicorn nm-openvpn[5001]: SIGTERM[hard,] received, process exiting
Sep 08 00:20:27 ugly-unicorn NetworkManager[1131]: <info>  [1757283627.7318] vpn[0x58cc62ec07a0,bca50f5a-2d01-4042-8d15-32033e76d2a8,"Max_Laptop"]: starting openvpn
Sep 08 00:20:31 ugly-unicorn nm-openvpn[5146]: Note: --cipher is not set. OpenVPN versions before 2.5 defaulted to BF-CBC as fallback when cipher negotiation failed in this case. If you need this fallback please add '--data-ciphers-fallback BF-CBC' to your configuration and/or add BF-CBC to --data-ciphers.
Sep 08 00:20:31 ugly-unicorn nm-openvpn[5146]: OpenVPN 2.6.14 x86_64-pc-linux-gnu [SSL (OpenSSL)] [LZO] [LZ4] [EPOLL] [PKCS11] [MH/PKTINFO] [AEAD] [DCO]
Sep 08 00:20:31 ugly-unicorn nm-openvpn[5146]: library versions: OpenSSL 3.0.13 30 Jan 2024, LZO 2.10
Sep 08 00:20:31 ugly-unicorn nm-openvpn[5146]: DCO version: N/A
Sep 08 00:20:31 ugly-unicorn nm-openvpn[5146]: NOTE: the current --script-security setting may allow this configuration to call user-defined scripts
Sep 08 00:20:31 ugly-unicorn nm-openvpn[5146]: TCP/UDP: Preserving recently used remote address: [AF_INET]92.224.216.192:1194
Sep 08 00:20:31 ugly-unicorn nm-openvpn[5146]: UDPv4 link local: (not bound)
Sep 08 00:20:31 ugly-unicorn nm-openvpn[5146]: UDPv4 link remote: [AF_INET]92.224.216.192:1194
Sep 08 00:20:31 ugly-unicorn nm-openvpn[5146]: NOTE: UID/GID downgrade will be delayed because of --client, --pull, or --up-delay
Sep 08 00:20:31 ugly-unicorn nm-openvpn[5146]: [clumsy-camel_67c1b959-7d87-48c4-a94c-298162db268e] Peer Connection Initiated with [AF_INET]92.224.216.192:1194
Sep 08 00:20:31 ugly-unicorn nm-openvpn[5146]: Options error: Unrecognized option or missing or extra parameter(s) in [PUSH-OPTIONS]:2: block-outside-dns (2.6.14)
Sep 08 00:20:31 ugly-unicorn nm-openvpn[5146]: WARNING: You have specified redirect-gateway and redirect-private at the same time (or the same option multiple times). This is not well supported and may lead to unexpected results
Sep 08 00:20:31 ugly-unicorn nm-openvpn[5146]: Options error: ifconfig-ipv6: /netbits must be between 64 and 124, not '/128'
Sep 08 00:20:31 ugly-unicorn nm-openvpn[5146]: TUN/TAP device tun0 opened
Sep 08 00:20:31 ugly-unicorn nm-openvpn[5146]: /usr/libexec/nm-openvpn-service-openvpn-helper --debug 0 5134 --bus-name org.freedesktop.NetworkManager.openvpn.Connection_12 --tun -- tun0 1500 0 10.125.175.2 255.255.255.0 init
Sep 08 00:20:31 ugly-unicorn nm-openvpn[5146]: UID set to nm-openvpn
Sep 08 00:20:31 ugly-unicorn nm-openvpn[5146]: GID set to nm-openvpn
Sep 08 00:20:31 ugly-unicorn nm-openvpn[5146]: Capabilities retained: CAP_NET_ADMIN
Sep 08 00:20:31 ugly-unicorn nm-openvpn[5146]: Initialization Sequence Completed
Sep 08 00:22:46 ugly-unicorn nm-openvpn[5146]: event_wait : Interrupted system call (fd=-1,code=4)
Sep 08 00:22:46 ugly-unicorn nm-openvpn[5146]: SIGTERM[hard,] received, process exiting
Sep 08 00:23:10 ugly-unicorn NetworkManager[1131]: <info>  [1757283790.8066] vpn[0x58cc62ea9660,86b4e0a4-b0af-4925-94de-05383c7e0e21,"Max_Laptop"]: starting openvpn
Sep 08 00:23:14 ugly-unicorn nm-openvpn[5491]: Note: --cipher is not set. OpenVPN versions before 2.5 defaulted to BF-CBC as fallback when cipher negotiation failed in this case. If you need this fallback please add '--data-ciphers-fallback BF-CBC' to your configuration and/or add BF-CBC to --data-ciphers.
Sep 08 00:23:14 ugly-unicorn nm-openvpn[5491]: OpenVPN 2.6.14 x86_64-pc-linux-gnu [SSL (OpenSSL)] [LZO] [LZ4] [EPOLL] [PKCS11] [MH/PKTINFO] [AEAD] [DCO]
Sep 08 00:23:14 ugly-unicorn nm-openvpn[5491]: library versions: OpenSSL 3.0.13 30 Jan 2024, LZO 2.10
Sep 08 00:23:14 ugly-unicorn nm-openvpn[5491]: DCO version: N/A
Sep 08 00:23:14 ugly-unicorn nm-openvpn[5491]: NOTE: the current --script-security setting may allow this configuration to call user-defined scripts
Sep 08 00:23:14 ugly-unicorn nm-openvpn[5491]: TCP/UDP: Preserving recently used remote address: [AF_INET]92.224.216.192:1194
Sep 08 00:23:14 ugly-unicorn nm-openvpn[5491]: UDPv4 link local: (not bound)
Sep 08 00:23:14 ugly-unicorn nm-openvpn[5491]: UDPv4 link remote: [AF_INET]92.224.216.192:1194
Sep 08 00:23:14 ugly-unicorn nm-openvpn[5491]: NOTE: UID/GID downgrade will be delayed because of --client, --pull, or --up-delay
Sep 08 00:23:14 ugly-unicorn nm-openvpn[5491]: [clumsy-camel_67c1b959-7d87-48c4-a94c-298162db268e] Peer Connection Initiated with [AF_INET]92.224.216.192:1194
Sep 08 00:23:14 ugly-unicorn nm-openvpn[5491]: Options error: Unrecognized option or missing or extra parameter(s) in [PUSH-OPTIONS]:2: block-outside-dns (2.6.14)
Sep 08 00:23:14 ugly-unicorn nm-openvpn[5491]: WARNING: You have specified redirect-gateway and redirect-private at the same time (or the same option multiple times). This is not well supported and may lead to unexpected results
Sep 08 00:23:14 ugly-unicorn nm-openvpn[5491]: Options error: ifconfig-ipv6: /netbits must be between 64 and 124, not '/128'
Sep 08 00:23:14 ugly-unicorn nm-openvpn[5491]: TUN/TAP device tun0 opened
Sep 08 00:23:14 ugly-unicorn nm-openvpn[5491]: /usr/libexec/nm-openvpn-service-openvpn-helper --debug 0 5480 --bus-name org.freedesktop.NetworkManager.openvpn.Connection_14 --tun -- tun0 1500 0 10.125.175.2 255.255.255.0 init
Sep 08 00:23:14 ugly-unicorn nm-openvpn[5491]: UID set to nm-openvpn
Sep 08 00:23:14 ugly-unicorn nm-openvpn[5491]: GID set to nm-openvpn
Sep 08 00:23:14 ugly-unicorn nm-openvpn[5491]: Capabilities retained: CAP_NET_ADMIN
Sep 08 00:23:14 ugly-unicorn nm-openvpn[5491]: Initialization Sequence Completed
Sep 08 00:25:07 ugly-unicorn nm-openvpn[5491]: event_wait : Interrupted system call (fd=-1,code=4)
Sep 08 00:25:07 ugly-unicorn nm-openvpn[5491]: SIGTERM[hard,] received, process exiting
Sep 08 00:27:32 ugly-unicorn NetworkManager[1131]: <info>  [1757284052.8046] vpn[0x58cc62eb4250,86b4e0a4-b0af-4925-94de-05383c7e0e21,"Max_Laptop"]: starting openvpn
Sep 08 00:27:36 ugly-unicorn nm-openvpn[5888]: Note: --cipher is not set. OpenVPN versions before 2.5 defaulted to BF-CBC as fallback when cipher negotiation failed in this case. If you need this fallback please add '--data-ciphers-fallback BF-CBC' to your configuration and/or add BF-CBC to --data-ciphers.
Sep 08 00:27:36 ugly-unicorn nm-openvpn[5888]: OpenVPN 2.6.14 x86_64-pc-linux-gnu [SSL (OpenSSL)] [LZO] [LZ4] [EPOLL] [PKCS11] [MH/PKTINFO] [AEAD] [DCO]
Sep 08 00:27:36 ugly-unicorn nm-openvpn[5888]: library versions: OpenSSL 3.0.13 30 Jan 2024, LZO 2.10
Sep 08 00:27:36 ugly-unicorn nm-openvpn[5888]: DCO version: N/A
Sep 08 00:27:36 ugly-unicorn nm-openvpn[5888]: NOTE: the current --script-security setting may allow this configuration to call user-defined scripts
Sep 08 00:27:36 ugly-unicorn nm-openvpn[5888]: TCP/UDP: Preserving recently used remote address: [AF_INET]92.224.216.192:1194
Sep 08 00:27:36 ugly-unicorn nm-openvpn[5888]: UDPv4 link local: (not bound)
Sep 08 00:27:36 ugly-unicorn nm-openvpn[5888]: UDPv4 link remote: [AF_INET]92.224.216.192:1194
Sep 08 00:27:36 ugly-unicorn nm-openvpn[5888]: NOTE: UID/GID downgrade will be delayed because of --client, --pull, or --up-delay
Sep 08 00:27:36 ugly-unicorn nm-openvpn[5888]: [clumsy-camel_67c1b959-7d87-48c4-a94c-298162db268e] Peer Connection Initiated with [AF_INET]92.224.216.192:1194
Sep 08 00:27:36 ugly-unicorn nm-openvpn[5888]: Options error: Unrecognized option or missing or extra parameter(s) in [PUSH-OPTIONS]:2: block-outside-dns (2.6.14)
Sep 08 00:27:36 ugly-unicorn nm-openvpn[5888]: WARNING: You have specified redirect-gateway and redirect-private at the same time (or the same option multiple times). This is not well supported and may lead to unexpected results
Sep 08 00:27:36 ugly-unicorn nm-openvpn[5888]: Options error: ifconfig-ipv6: /netbits must be between 64 and 124, not '/128'
Sep 08 00:27:36 ugly-unicorn nm-openvpn[5888]: sitnl_send: rtnl: generic error (-101): Network is unreachable
Sep 08 00:27:36 ugly-unicorn nm-openvpn[5888]: TUN/TAP device tun0 opened
Sep 08 00:27:36 ugly-unicorn nm-openvpn[5888]: /usr/libexec/nm-openvpn-service-openvpn-helper --debug 0 5875 --bus-name org.freedesktop.NetworkManager.openvpn.Connection_16 --tun -- tun0 1500 0 10.125.175.2 255.255.255.0 init
Sep 08 00:27:36 ugly-unicorn nm-openvpn[5888]: UID set to nm-openvpn
Sep 08 00:27:36 ugly-unicorn nm-openvpn[5888]: GID set to nm-openvpn
Sep 08 00:27:36 ugly-unicorn nm-openvpn[5888]: Capabilities retained: CAP_NET_ADMIN
Sep 08 00:27:36 ugly-unicorn nm-openvpn[5888]: Initialization Sequence Completed
Sep 08 00:36:49 ugly-unicorn nm-openvpn[5888]: event_wait : Interrupted system call (fd=-1,code=4)
Sep 08 00:36:49 ugly-unicorn nm-openvpn[5888]: SIGTERM[hard,] received, process exiting
Sep 08 00:40:39 ugly-unicorn NetworkManager[1133]: <info>  [1757284839.8037] vpn[0x5ec62779bc20,86b4e0a4-b0af-4925-94de-05383c7e0e21,"Max_Laptop"]: starting openvpn
Sep 08 00:40:43 ugly-unicorn nm-openvpn[3398]: Note: --cipher is not set. OpenVPN versions before 2.5 defaulted to BF-CBC as fallback when cipher negotiation failed in this case. If you need this fallback please add '--data-ciphers-fallback BF-CBC' to your configuration and/or add BF-CBC to --data-ciphers.
Sep 08 00:40:43 ugly-unicorn nm-openvpn[3398]: OpenVPN 2.6.14 x86_64-pc-linux-gnu [SSL (OpenSSL)] [LZO] [LZ4] [EPOLL] [PKCS11] [MH/PKTINFO] [AEAD] [DCO]
Sep 08 00:40:43 ugly-unicorn nm-openvpn[3398]: library versions: OpenSSL 3.0.13 30 Jan 2024, LZO 2.10
Sep 08 00:40:43 ugly-unicorn nm-openvpn[3398]: DCO version: N/A
Sep 08 00:40:43 ugly-unicorn nm-openvpn[3398]: NOTE: the current --script-security setting may allow this configuration to call user-defined scripts
Sep 08 00:40:43 ugly-unicorn nm-openvpn[3398]: TCP/UDP: Preserving recently used remote address: [AF_INET]92.224.216.192:1194
Sep 08 00:40:43 ugly-unicorn nm-openvpn[3398]: UDPv4 link local: (not bound)
Sep 08 00:40:43 ugly-unicorn nm-openvpn[3398]: UDPv4 link remote: [AF_INET]92.224.216.192:1194
Sep 08 00:40:43 ugly-unicorn nm-openvpn[3398]: NOTE: UID/GID downgrade will be delayed because of --client, --pull, or --up-delay
Sep 08 00:40:43 ugly-unicorn nm-openvpn[3398]: [clumsy-camel_67c1b959-7d87-48c4-a94c-298162db268e] Peer Connection Initiated with [AF_INET]92.224.216.192:1194
Sep 08 00:40:43 ugly-unicorn nm-openvpn[3398]: Options error: Unrecognized option or missing or extra parameter(s) in [PUSH-OPTIONS]:2: block-outside-dns (2.6.14)
Sep 08 00:40:43 ugly-unicorn nm-openvpn[3398]: WARNING: You have specified redirect-gateway and redirect-private at the same time (or the same option multiple times). This is not well supported and may lead to unexpected results
Sep 08 00:40:43 ugly-unicorn nm-openvpn[3398]: Options error: ifconfig-ipv6: /netbits must be between 64 and 124, not '/128'
Sep 08 00:40:43 ugly-unicorn nm-openvpn[3398]: TUN/TAP device tun0 opened
Sep 08 00:40:43 ugly-unicorn nm-openvpn[3398]: /usr/libexec/nm-openvpn-service-openvpn-helper --debug 0 3387 --bus-name org.freedesktop.NetworkManager.openvpn.Connection_4 --tun -- tun0 1500 0 10.125.175.2 255.255.255.0 init
Sep 08 00:40:43 ugly-unicorn nm-openvpn[3398]: UID set to nm-openvpn
Sep 08 00:40:43 ugly-unicorn nm-openvpn[3398]: GID set to nm-openvpn
Sep 08 00:40:43 ugly-unicorn nm-openvpn[3398]: Capabilities retained: CAP_NET_ADMIN
Sep 08 00:40:43 ugly-unicorn nm-openvpn[3398]: Initialization Sequence Completed
Sep 08 00:44:26 ugly-unicorn nm-openvpn[3398]: read UDPv4 [ECONNREFUSED]: Connection refused (fd=5,code=111)
Sep 08 00:44:41 ugly-unicorn nm-openvpn[3398]: read UDPv4 [ECONNREFUSED]: Connection refused (fd=5,code=111)
Sep 08 00:44:57 ugly-unicorn nm-openvpn[3398]: read UDPv4 [ECONNREFUSED]: Connection refused (fd=5,code=111)
Sep 08 00:44:57 ugly-unicorn nm-openvpn[3398]: read UDPv4 [ECONNREFUSED]: Connection refused (fd=5,code=111)
Sep 08 00:44:57 ugly-unicorn nm-openvpn[3398]: read UDPv4 [ECONNREFUSED|ECONNREFUSED]: Connection refused (fd=5,code=111)
Sep 08 00:44:59 ugly-unicorn nm-openvpn[3398]: read UDPv4 [ECONNREFUSED]: Connection refused (fd=5,code=111)
Sep 08 00:45:02 ugly-unicorn nm-openvpn[3398]: read UDPv4 [ECONNREFUSED]: Connection refused (fd=5,code=111)
Sep 08 00:45:02 ugly-unicorn nm-openvpn[3398]: read UDPv4 [ECONNREFUSED|ECONNREFUSED]: Connection refused (fd=5,code=111)
Sep 08 00:45:07 ugly-unicorn nm-openvpn[3398]: read UDPv4 [ECONNREFUSED]: Connection refused (fd=5,code=111)
Sep 08 00:45:07 ugly-unicorn nm-openvpn[3398]: read UDPv4 [ECONNREFUSED|ECONNREFUSED]: Connection refused (fd=5,code=111)
Sep 08 00:45:13 ugly-unicorn nm-openvpn[3398]: read UDPv4 [ECONNREFUSED]: Connection refused (fd=5,code=111)
Sep 08 00:45:13 ugly-unicorn nm-openvpn[3398]: read UDPv4 [ECONNREFUSED|ECONNREFUSED]: Connection refused (fd=5,code=111)
Sep 08 00:45:18 ugly-unicorn nm-openvpn[3398]: read UDPv4 [ECONNREFUSED]: Connection refused (fd=5,code=111)
Sep 08 00:45:18 ugly-unicorn nm-openvpn[3398]: read UDPv4 [ECONNREFUSED|ECONNREFUSED]: Connection refused (fd=5,code=111)
Sep 08 00:45:23 ugly-unicorn nm-openvpn[3398]: read UDPv4 [ECONNREFUSED]: Connection refused (fd=5,code=111)
Sep 08 00:45:23 ugly-unicorn nm-openvpn[3398]: read UDPv4 [ECONNREFUSED]: Connection refused (fd=5,code=111)
Sep 08 00:45:28 ugly-unicorn nm-openvpn[3398]: read UDPv4 [ECONNREFUSED]: Connection refused (fd=5,code=111)
Sep 08 00:45:32 ugly-unicorn nm-openvpn[3398]: read UDPv4 [ECONNREFUSED]: Connection refused (fd=5,code=111)
Sep 08 00:45:32 ugly-unicorn nm-openvpn[3398]: read UDPv4 [ECONNREFUSED]: Connection refused (fd=5,code=111)
Sep 08 00:45:32 ugly-unicorn nm-openvpn[3398]: read UDPv4 [ECONNREFUSED]: Connection refused (fd=5,code=111)
Sep 08 00:46:02 ugly-unicorn nm-openvpn[3398]: SIGTERM[hard,] received, process exiting
Sep 08 00:46:04 ugly-unicorn NetworkManager[1133]: <info>  [1757285164.4693] vpn[0x5ec6277a8760,86b4e0a4-b0af-4925-94de-05383c7e0e21,"Max_Laptop"]: starting openvpn
Sep 08 00:46:08 ugly-unicorn nm-openvpn[3757]: Note: --cipher is not set. OpenVPN versions before 2.5 defaulted to BF-CBC as fallback when cipher negotiation failed in this case. If you need this fallback please add '--data-ciphers-fallback BF-CBC' to your configuration and/or add BF-CBC to --data-ciphers.
Sep 08 00:46:08 ugly-unicorn nm-openvpn[3757]: OpenVPN 2.6.14 x86_64-pc-linux-gnu [SSL (OpenSSL)] [LZO] [LZ4] [EPOLL] [PKCS11] [MH/PKTINFO] [AEAD] [DCO]
Sep 08 00:46:08 ugly-unicorn nm-openvpn[3757]: library versions: OpenSSL 3.0.13 30 Jan 2024, LZO 2.10
Sep 08 00:46:08 ugly-unicorn nm-openvpn[3757]: DCO version: N/A
Sep 08 00:46:08 ugly-unicorn nm-openvpn[3757]: NOTE: the current --script-security setting may allow this configuration to call user-defined scripts
Sep 08 00:46:08 ugly-unicorn nm-openvpn[3757]: TCP/UDP: Preserving recently used remote address: [AF_INET]92.224.216.192:1194
Sep 08 00:46:08 ugly-unicorn nm-openvpn[3757]: UDPv4 link local: (not bound)
Sep 08 00:46:08 ugly-unicorn nm-openvpn[3757]: UDPv4 link remote: [AF_INET]92.224.216.192:1194
Sep 08 00:46:08 ugly-unicorn nm-openvpn[3757]: NOTE: UID/GID downgrade will be delayed because of --client, --pull, or --up-delay
Sep 08 00:46:08 ugly-unicorn nm-openvpn[3757]: [clumsy-camel_67c1b959-7d87-48c4-a94c-298162db268e] Peer Connection Initiated with [AF_INET]92.224.216.192:1194
Sep 08 00:46:08 ugly-unicorn nm-openvpn[3757]: Options error: Unrecognized option or missing or extra parameter(s) in [PUSH-OPTIONS]:2: block-outside-dns (2.6.14)
Sep 08 00:46:08 ugly-unicorn nm-openvpn[3757]: WARNING: You have specified redirect-gateway and redirect-private at the same time (or the same option multiple times). This is not well supported and may lead to unexpected results
Sep 08 00:46:08 ugly-unicorn nm-openvpn[3757]: Options error: ifconfig-ipv6: /netbits must be between 64 and 124, not '/128'
Sep 08 00:46:08 ugly-unicorn nm-openvpn[3757]: TUN/TAP device tun0 opened
Sep 08 00:46:08 ugly-unicorn nm-openvpn[3757]: /usr/libexec/nm-openvpn-service-openvpn-helper --debug 0 3746 --bus-name org.freedesktop.NetworkManager.openvpn.Connection_6 --tun -- tun0 1500 0 10.125.175.2 255.255.255.0 init
Sep 08 00:46:08 ugly-unicorn nm-openvpn[3757]: UID set to nm-openvpn
Sep 08 00:46:08 ugly-unicorn nm-openvpn[3757]: GID set to nm-openvpn
Sep 08 00:46:08 ugly-unicorn nm-openvpn[3757]: Capabilities retained: CAP_NET_ADMIN
Sep 08 00:46:08 ugly-unicorn nm-openvpn[3757]: Initialization Sequence Completed
Sep 08 00:47:59 ugly-unicorn nm-openvpn[3757]: event_wait : Interrupted system call (fd=-1,code=4)
Sep 08 00:47:59 ugly-unicorn nm-openvpn[3757]: SIGTERM[hard,] received, process exiting
Sep 08 00:48:39 ugly-unicorn NetworkManager[1133]: <info>  [1757285319.6986] vpn[0x5ec627802130,542d9bae-97c0-4918-8e08-fbb21bbe88f8,"Max_Laptop"]: starting openvpn
Sep 08 00:48:43 ugly-unicorn nm-openvpn[4130]: Note: --cipher is not set. OpenVPN versions before 2.5 defaulted to BF-CBC as fallback when cipher negotiation failed in this case. If you need this fallback please add '--data-ciphers-fallback BF-CBC' to your configuration and/or add BF-CBC to --data-ciphers.
Sep 08 00:48:43 ugly-unicorn nm-openvpn[4130]: OpenVPN 2.6.14 x86_64-pc-linux-gnu [SSL (OpenSSL)] [LZO] [LZ4] [EPOLL] [PKCS11] [MH/PKTINFO] [AEAD] [DCO]
Sep 08 00:48:43 ugly-unicorn nm-openvpn[4130]: library versions: OpenSSL 3.0.13 30 Jan 2024, LZO 2.10
Sep 08 00:48:43 ugly-unicorn nm-openvpn[4130]: DCO version: N/A
Sep 08 00:48:43 ugly-unicorn nm-openvpn[4130]: NOTE: the current --script-security setting may allow this configuration to call user-defined scripts
Sep 08 00:48:43 ugly-unicorn nm-openvpn[4130]: TCP/UDP: Preserving recently used remote address: [AF_INET]92.224.216.192:1194
Sep 08 00:48:43 ugly-unicorn nm-openvpn[4130]: UDPv4 link local: (not bound)
Sep 08 00:48:43 ugly-unicorn nm-openvpn[4130]: UDPv4 link remote: [AF_INET]92.224.216.192:1194
Sep 08 00:48:43 ugly-unicorn nm-openvpn[4130]: NOTE: UID/GID downgrade will be delayed because of --client, --pull, or --up-delay
Sep 08 00:48:43 ugly-unicorn nm-openvpn[4130]: [clumsy-camel_67c1b959-7d87-48c4-a94c-298162db268e] Peer Connection Initiated with [AF_INET]92.224.216.192:1194
Sep 08 00:48:43 ugly-unicorn nm-openvpn[4130]: Options error: Unrecognized option or missing or extra parameter(s) in [PUSH-OPTIONS]:2: block-outside-dns (2.6.14)
Sep 08 00:48:43 ugly-unicorn nm-openvpn[4130]: WARNING: You have specified redirect-gateway and redirect-private at the same time (or the same option multiple times). This is not well supported and may lead to unexpected results
Sep 08 00:48:43 ugly-unicorn nm-openvpn[4130]: Options error: ifconfig-ipv6: /netbits must be between 64 and 124, not '/128'
Sep 08 00:48:43 ugly-unicorn nm-openvpn[4130]: TUN/TAP device tun0 opened
Sep 08 00:48:43 ugly-unicorn nm-openvpn[4130]: /usr/libexec/nm-openvpn-service-openvpn-helper --debug 0 4117 --bus-name org.freedesktop.NetworkManager.openvpn.Connection_8 --tun -- tun0 1500 0 10.125.175.2 255.255.255.0 init
Sep 08 00:48:43 ugly-unicorn nm-openvpn[4130]: UID set to nm-openvpn
Sep 08 00:48:43 ugly-unicorn nm-openvpn[4130]: GID set to nm-openvpn
Sep 08 00:48:43 ugly-unicorn nm-openvpn[4130]: Capabilities retained: CAP_NET_ADMIN
Sep 08 00:48:43 ugly-unicorn nm-openvpn[4130]: Initialization Sequence Completed
Sep 08 00:50:48 ugly-unicorn nm-openvpn[4130]: event_wait : Interrupted system call (fd=-1,code=4)
Sep 08 00:50:48 ugly-unicorn nm-openvpn[4130]: SIGTERM[hard,] received, process exiting
Sep 08 00:50:51 ugly-unicorn NetworkManager[1133]: <info>  [1757285451.0690] vpn[0x5ec6277fbe90,542d9bae-97c0-4918-8e08-fbb21bbe88f8,"Max_Laptop"]: starting openvpn
Sep 08 00:50:51 ugly-unicorn nm-openvpn[4294]: Note: --cipher is not set. OpenVPN versions before 2.5 defaulted to BF-CBC as fallback when cipher negotiation failed in this case. If you need this fallback please add '--data-ciphers-fallback BF-CBC' to your configuration and/or add BF-CBC to --data-ciphers.
Sep 08 00:50:51 ugly-unicorn nm-openvpn[4294]: OpenVPN 2.6.14 x86_64-pc-linux-gnu [SSL (OpenSSL)] [LZO] [LZ4] [EPOLL] [PKCS11] [MH/PKTINFO] [AEAD] [DCO]
Sep 08 00:50:51 ugly-unicorn nm-openvpn[4294]: library versions: OpenSSL 3.0.13 30 Jan 2024, LZO 2.10
Sep 08 00:50:51 ugly-unicorn nm-openvpn[4294]: DCO version: N/A
Sep 08 00:50:51 ugly-unicorn nm-openvpn[4294]: NOTE: the current --script-security setting may allow this configuration to call user-defined scripts
Sep 08 00:50:51 ugly-unicorn nm-openvpn[4294]: TCP/UDP: Preserving recently used remote address: [AF_INET]92.224.216.192:1194
Sep 08 00:50:51 ugly-unicorn nm-openvpn[4294]: UDPv4 link local: (not bound)
Sep 08 00:50:51 ugly-unicorn nm-openvpn[4294]: UDPv4 link remote: [AF_INET]92.224.216.192:1194
Sep 08 00:50:51 ugly-unicorn nm-openvpn[4294]: NOTE: UID/GID downgrade will be delayed because of --client, --pull, or --up-delay
Sep 08 00:50:51 ugly-unicorn nm-openvpn[4294]: [clumsy-camel_67c1b959-7d87-48c4-a94c-298162db268e] Peer Connection Initiated with [AF_INET]92.224.216.192:1194
Sep 08 00:50:51 ugly-unicorn nm-openvpn[4294]: Options error: Unrecognized option or missing or extra parameter(s) in [PUSH-OPTIONS]:2: block-outside-dns (2.6.14)
Sep 08 00:50:51 ugly-unicorn nm-openvpn[4294]: WARNING: You have specified redirect-gateway and redirect-private at the same time (or the same option multiple times). This is not well supported and may lead to unexpected results
Sep 08 00:50:51 ugly-unicorn nm-openvpn[4294]: Options error: ifconfig-ipv6: /netbits must be between 64 and 124, not '/128'
Sep 08 00:50:51 ugly-unicorn nm-openvpn[4294]: TUN/TAP device tun0 opened
Sep 08 00:50:51 ugly-unicorn nm-openvpn[4294]: /usr/libexec/nm-openvpn-service-openvpn-helper --debug 0 4288 --bus-name org.freedesktop.NetworkManager.openvpn.Connection_10 --tun -- tun0 1500 0 10.125.175.2 255.255.255.0 init
Sep 08 00:50:51 ugly-unicorn nm-openvpn[4294]: UID set to nm-openvpn
Sep 08 00:50:51 ugly-unicorn nm-openvpn[4294]: GID set to nm-openvpn
Sep 08 00:50:51 ugly-unicorn nm-openvpn[4294]: Capabilities retained: CAP_NET_ADMIN
Sep 08 00:50:51 ugly-unicorn nm-openvpn[4294]: Initialization Sequence Completed
Sep 08 00:52:43 ugly-unicorn nm-openvpn[4294]: event_wait : Interrupted system call (fd=-1,code=4)
Sep 08 00:52:43 ugly-unicorn nm-openvpn[4294]: SIGTERM[hard,] received, process exiting
Sep 08 01:04:42 ugly-unicorn NetworkManager[1133]: <info>  [1757286282.6149] vpn[0x5ec62779b7a0,17fde95d-fadd-4991-bb8c-8b1520c77bc9,"Max_Laptop"]: starting openvpn
Sep 08 01:04:42 ugly-unicorn nm-openvpn[4904]: Note: --cipher is not set. OpenVPN versions before 2.5 defaulted to BF-CBC as fallback when cipher negotiation failed in this case. If you need this fallback please add '--data-ciphers-fallback BF-CBC' to your configuration and/or add BF-CBC to --data-ciphers.
Sep 08 01:04:42 ugly-unicorn nm-openvpn[4904]: OpenVPN 2.6.14 x86_64-pc-linux-gnu [SSL (OpenSSL)] [LZO] [LZ4] [EPOLL] [PKCS11] [MH/PKTINFO] [AEAD] [DCO]
Sep 08 01:04:42 ugly-unicorn nm-openvpn[4904]: library versions: OpenSSL 3.0.13 30 Jan 2024, LZO 2.10
Sep 08 01:04:42 ugly-unicorn nm-openvpn[4904]: DCO version: N/A
Sep 08 01:04:42 ugly-unicorn nm-openvpn[4904]: NOTE: the current --script-security setting may allow this configuration to call user-defined scripts
Sep 08 01:04:42 ugly-unicorn nm-openvpn[4904]: TCP/UDP: Preserving recently used remote address: [AF_INET]92.224.216.192:1194
Sep 08 01:04:42 ugly-unicorn nm-openvpn[4904]: UDPv4 link local: (not bound)
Sep 08 01:04:42 ugly-unicorn nm-openvpn[4904]: UDPv4 link remote: [AF_INET]92.224.216.192:1194
Sep 08 01:04:42 ugly-unicorn nm-openvpn[4904]: NOTE: UID/GID downgrade will be delayed because of --client, --pull, or --up-delay
Sep 08 01:04:42 ugly-unicorn nm-openvpn[4904]: [clumsy-camel_67c1b959-7d87-48c4-a94c-298162db268e] Peer Connection Initiated with [AF_INET]92.224.216.192:1194
Sep 08 01:04:42 ugly-unicorn nm-openvpn[4904]: Options error: Unrecognized option or missing or extra parameter(s) in [PUSH-OPTIONS]:2: block-outside-dns (2.6.14)
Sep 08 01:04:42 ugly-unicorn nm-openvpn[4904]: WARNING: You have specified redirect-gateway and redirect-private at the same time (or the same option multiple times). This is not well supported and may lead to unexpected results
Sep 08 01:04:42 ugly-unicorn nm-openvpn[4904]: Options error: ifconfig-ipv6: /netbits must be between 64 and 124, not '/128'
Sep 08 01:04:42 ugly-unicorn nm-openvpn[4904]: TUN/TAP device tun0 opened
Sep 08 01:04:42 ugly-unicorn nm-openvpn[4904]: /usr/libexec/nm-openvpn-service-openvpn-helper --debug 0 4898 --bus-name org.freedesktop.NetworkManager.openvpn.Connection_13 --tun -- tun0 1500 0 10.125.175.2 255.255.255.0 init
Sep 08 01:04:42 ugly-unicorn nm-openvpn[4904]: UID set to nm-openvpn
Sep 08 01:04:42 ugly-unicorn nm-openvpn[4904]: GID set to nm-openvpn
Sep 08 01:04:42 ugly-unicorn nm-openvpn[4904]: Capabilities retained: CAP_NET_ADMIN
Sep 08 01:04:42 ugly-unicorn nm-openvpn[4904]: Initialization Sequence Completed
Sep 08 01:22:28 ugly-unicorn nm-openvpn[4904]: event_wait : Interrupted system call (fd=-1,code=4)
Sep 08 01:22:28 ugly-unicorn nm-openvpn[4904]: SIGTERM[hard,] received, process exiting
Sep 08 01:25:35 ugly-unicorn NetworkManager[1133]: <info>  [1757287535.9186] vpn[0x5ec62779b7a0,17fde95d-fadd-4991-bb8c-8b1520c77bc9,"Max_Laptop"]: starting openvpn
Sep 08 01:25:35 ugly-unicorn nm-openvpn[6510]: Note: --cipher is not set. OpenVPN versions before 2.5 defaulted to BF-CBC as fallback when cipher negotiation failed in this case. If you need this fallback please add '--data-ciphers-fallback BF-CBC' to your configuration and/or add BF-CBC to --data-ciphers.
Sep 08 01:25:35 ugly-unicorn nm-openvpn[6510]: OpenVPN 2.6.14 x86_64-pc-linux-gnu [SSL (OpenSSL)] [LZO] [LZ4] [EPOLL] [PKCS11] [MH/PKTINFO] [AEAD] [DCO]
Sep 08 01:25:35 ugly-unicorn nm-openvpn[6510]: library versions: OpenSSL 3.0.13 30 Jan 2024, LZO 2.10
Sep 08 01:25:35 ugly-unicorn nm-openvpn[6510]: DCO version: N/A
Sep 08 01:25:35 ugly-unicorn nm-openvpn[6510]: NOTE: the current --script-security setting may allow this configuration to call user-defined scripts
Sep 08 01:25:36 ugly-unicorn nm-openvpn[6510]: TCP/UDP: Preserving recently used remote address: [AF_INET]92.224.216.192:1194
Sep 08 01:25:36 ugly-unicorn nm-openvpn[6510]: UDPv4 link local: (not bound)
Sep 08 01:25:36 ugly-unicorn nm-openvpn[6510]: UDPv4 link remote: [AF_INET]92.224.216.192:1194
Sep 08 01:25:36 ugly-unicorn nm-openvpn[6510]: NOTE: UID/GID downgrade will be delayed because of --client, --pull, or --up-delay
Sep 08 01:26:36 ugly-unicorn nm-openvpn-serv[6504]: Connect timer expired, disconnecting.
Sep 08 01:26:36 ugly-unicorn nm-openvpn[6510]: [UNDEF] Inactivity timeout (--ping-restart), restarting
Sep 08 01:26:36 ugly-unicorn nm-openvpn[6510]: SIGTERM[hard,] received, process exiting
Sep 08 01:45:05 ugly-unicorn NetworkManager[1133]: <info>  [1757288705.5558] vpn[0x5ec6277c2470,17fde95d-fadd-4991-bb8c-8b1520c77bc9,"Max_Laptop"]: starting openvpn
Sep 08 01:45:05 ugly-unicorn nm-openvpn[6795]: Note: --cipher is not set. OpenVPN versions before 2.5 defaulted to BF-CBC as fallback when cipher negotiation failed in this case. If you need this fallback please add '--data-ciphers-fallback BF-CBC' to your configuration and/or add BF-CBC to --data-ciphers.
Sep 08 01:45:05 ugly-unicorn nm-openvpn[6795]: OpenVPN 2.6.14 x86_64-pc-linux-gnu [SSL (OpenSSL)] [LZO] [LZ4] [EPOLL] [PKCS11] [MH/PKTINFO] [AEAD] [DCO]
Sep 08 01:45:05 ugly-unicorn nm-openvpn[6795]: library versions: OpenSSL 3.0.13 30 Jan 2024, LZO 2.10
Sep 08 01:45:05 ugly-unicorn nm-openvpn[6795]: DCO version: N/A
Sep 08 01:45:05 ugly-unicorn nm-openvpn[6795]: NOTE: the current --script-security setting may allow this configuration to call user-defined scripts
Sep 08 01:45:05 ugly-unicorn nm-openvpn[6795]: TCP/UDP: Preserving recently used remote address: [AF_INET]77.11.137.63:1194
Sep 08 01:45:05 ugly-unicorn nm-openvpn[6795]: UDPv4 link local: (not bound)
Sep 08 01:45:05 ugly-unicorn nm-openvpn[6795]: UDPv4 link remote: [AF_INET]77.11.137.63:1194
Sep 08 01:45:05 ugly-unicorn nm-openvpn[6795]: NOTE: UID/GID downgrade will be delayed because of --client, --pull, or --up-delay
Sep 08 01:45:05 ugly-unicorn nm-openvpn[6795]: [clumsy-camel_67c1b959-7d87-48c4-a94c-298162db268e] Peer Connection Initiated with [AF_INET]77.11.137.63:1194
Sep 08 01:45:05 ugly-unicorn nm-openvpn[6795]: Options error: Unrecognized option or missing or extra parameter(s) in [PUSH-OPTIONS]:2: block-outside-dns (2.6.14)
Sep 08 01:45:05 ugly-unicorn nm-openvpn[6795]: WARNING: You have specified redirect-gateway and redirect-private at the same time (or the same option multiple times). This is not well supported and may lead to unexpected results
Sep 08 01:45:05 ugly-unicorn nm-openvpn[6795]: Options error: ifconfig-ipv6: /netbits must be between 64 and 124, not '/128'
Sep 08 01:45:05 ugly-unicorn nm-openvpn[6795]: TUN/TAP device tun0 opened
Sep 08 01:45:05 ugly-unicorn nm-openvpn[6795]: /usr/libexec/nm-openvpn-service-openvpn-helper --debug 0 6789 --bus-name org.freedesktop.NetworkManager.openvpn.Connection_16 --tun -- tun0 1500 0 10.125.175.2 255.255.255.0 init
Sep 08 01:45:05 ugly-unicorn nm-openvpn[6795]: UID set to nm-openvpn
Sep 08 01:45:05 ugly-unicorn nm-openvpn[6795]: GID set to nm-openvpn
Sep 08 01:45:05 ugly-unicorn nm-openvpn[6795]: Capabilities retained: CAP_NET_ADMIN
Sep 08 01:45:05 ugly-unicorn nm-openvpn[6795]: Initialization Sequence Completed
Sep 08 01:51:39 ugly-unicorn nm-openvpn[6795]: [clumsy-camel_67c1b959-7d87-48c4-a94c-298162db268e] Inactivity timeout (--ping-restart), restarting
Sep 08 01:51:39 ugly-unicorn nm-openvpn[6795]: SIGUSR1[soft,ping-restart] received, process restarting
Sep 08 01:51:40 ugly-unicorn nm-openvpn[6795]: NOTE: the current --script-security setting may allow this configuration to call user-defined scripts
Sep 08 01:51:40 ugly-unicorn nm-openvpn[6795]: TCP/UDP: Preserving recently used remote address: [AF_INET]77.11.137.63:1194
Sep 08 01:51:40 ugly-unicorn nm-openvpn[6795]: UDPv4 link local: (not bound)
Sep 08 01:51:40 ugly-unicorn nm-openvpn[6795]: UDPv4 link remote: [AF_INET]77.11.137.63:1194
Sep 08 01:51:40 ugly-unicorn nm-openvpn[6795]: [clumsy-camel_67c1b959-7d87-48c4-a94c-298162db268e] Peer Connection Initiated with [AF_INET]77.11.137.63:1194
Sep 08 01:51:40 ugly-unicorn nm-openvpn[6795]: Options error: Unrecognized option or missing or extra parameter(s) in [PUSH-OPTIONS]:2: block-outside-dns (2.6.14)
Sep 08 01:51:40 ugly-unicorn nm-openvpn[6795]: WARNING: You have specified redirect-gateway and redirect-private at the same time (or the same option multiple times). This is not well supported and may lead to unexpected results
Sep 08 01:51:40 ugly-unicorn nm-openvpn[6795]: Options error: ifconfig-ipv6: /netbits must be between 64 and 124, not '/128'
Sep 08 01:51:40 ugly-unicorn nm-openvpn[6795]: Preserving previous TUN/TAP instance: tun0
Sep 08 01:51:40 ugly-unicorn nm-openvpn[6795]: /usr/libexec/nm-openvpn-service-openvpn-helper --debug 0 6789 --bus-name org.freedesktop.NetworkManager.openvpn.Connection_16 --tun -- tun0 1500 0 10.125.175.2 255.255.255.0 restart
Sep 08 01:51:40 ugly-unicorn nm-openvpn[6795]: Initialization Sequence Completed
Sep 08 01:55:39 ugly-unicorn nm-openvpn[6795]: [clumsy-camel_67c1b959-7d87-48c4-a94c-298162db268e] Inactivity timeout (--ping-restart), restarting
Sep 08 01:55:39 ugly-unicorn nm-openvpn[6795]: SIGUSR1[soft,ping-restart] received, process restarting
Sep 08 01:55:40 ugly-unicorn nm-openvpn[6795]: NOTE: the current --script-security setting may allow this configuration to call user-defined scripts
Sep 08 01:55:40 ugly-unicorn nm-openvpn[6795]: TCP/UDP: Preserving recently used remote address: [AF_INET]77.11.137.63:1194
Sep 08 01:55:40 ugly-unicorn nm-openvpn[6795]: UDPv4 link local: (not bound)
Sep 08 01:55:40 ugly-unicorn nm-openvpn[6795]: UDPv4 link remote: [AF_INET]77.11.137.63:1194
Sep 08 01:55:40 ugly-unicorn nm-openvpn[6795]: [clumsy-camel_67c1b959-7d87-48c4-a94c-298162db268e] Peer Connection Initiated with [AF_INET]77.11.137.63:1194
Sep 08 01:55:40 ugly-unicorn nm-openvpn[6795]: Options error: Unrecognized option or missing or extra parameter(s) in [PUSH-OPTIONS]:2: block-outside-dns (2.6.14)
Sep 08 01:55:40 ugly-unicorn nm-openvpn[6795]: WARNING: You have specified redirect-gateway and redirect-private at the same time (or the same option multiple times). This is not well supported and may lead to unexpected results
Sep 08 01:55:40 ugly-unicorn nm-openvpn[6795]: Options error: ifconfig-ipv6: /netbits must be between 64 and 124, not '/128'
Sep 08 01:55:40 ugly-unicorn nm-openvpn[6795]: Preserving previous TUN/TAP instance: tun0
Sep 08 01:55:40 ugly-unicorn nm-openvpn[6795]: /usr/libexec/nm-openvpn-service-openvpn-helper --debug 0 6789 --bus-name org.freedesktop.NetworkManager.openvpn.Connection_16 --tun -- tun0 1500 0 10.125.175.2 255.255.255.0 restart
Sep 08 01:55:40 ugly-unicorn nm-openvpn[6795]: Initialization Sequence Completed
Sep 08 01:57:33 ugly-unicorn nm-openvpn[6795]: event_wait : Interrupted system call (fd=-1,code=4)
Sep 08 01:57:33 ugly-unicorn nm-openvpn[6795]: SIGTERM[hard,] received, process exiting
Sep 08 02:38:14 ugly-unicorn NetworkManager[1133]: <info>  [1757291894.5347] vpn[0x5ec6277c29e0,17fde95d-fadd-4991-bb8c-8b1520c77bc9,"Max_Laptop"]: starting openvpn
Sep 08 02:38:14 ugly-unicorn nm-openvpn[8022]: Note: --cipher is not set. OpenVPN versions before 2.5 defaulted to BF-CBC as fallback when cipher negotiation failed in this case. If you need this fallback please add '--data-ciphers-fallback BF-CBC' to your configuration and/or add BF-CBC to --data-ciphers.
Sep 08 02:38:14 ugly-unicorn nm-openvpn[8022]: OpenVPN 2.6.14 x86_64-pc-linux-gnu [SSL (OpenSSL)] [LZO] [LZ4] [EPOLL] [PKCS11] [MH/PKTINFO] [AEAD] [DCO]
Sep 08 02:38:14 ugly-unicorn nm-openvpn[8022]: library versions: OpenSSL 3.0.13 30 Jan 2024, LZO 2.10
Sep 08 02:38:14 ugly-unicorn nm-openvpn[8022]: DCO version: N/A
Sep 08 02:38:14 ugly-unicorn nm-openvpn[8022]: NOTE: the current --script-security setting may allow this configuration to call user-defined scripts
Sep 08 02:38:14 ugly-unicorn nm-openvpn[8022]: TCP/UDP: Preserving recently used remote address: [AF_INET]77.11.137.63:1194
Sep 08 02:38:14 ugly-unicorn nm-openvpn[8022]: UDPv4 link local: (not bound)
Sep 08 02:38:14 ugly-unicorn nm-openvpn[8022]: UDPv4 link remote: [AF_INET]77.11.137.63:1194
Sep 08 02:38:14 ugly-unicorn nm-openvpn[8022]: NOTE: UID/GID downgrade will be delayed because of --client, --pull, or --up-delay
Sep 08 02:38:14 ugly-unicorn nm-openvpn[8022]: [clumsy-camel_67c1b959-7d87-48c4-a94c-298162db268e] Peer Connection Initiated with [AF_INET]77.11.137.63:1194
Sep 08 02:38:14 ugly-unicorn nm-openvpn[8022]: Options error: Unrecognized option or missing or extra parameter(s) in [PUSH-OPTIONS]:2: block-outside-dns (2.6.14)
Sep 08 02:38:14 ugly-unicorn nm-openvpn[8022]: WARNING: You have specified redirect-gateway and redirect-private at the same time (or the same option multiple times). This is not well supported and may lead to unexpected results
Sep 08 02:38:14 ugly-unicorn nm-openvpn[8022]: Options error: ifconfig-ipv6: /netbits must be between 64 and 124, not '/128'
Sep 08 02:38:14 ugly-unicorn nm-openvpn[8022]: TUN/TAP device tun0 opened
Sep 08 02:38:14 ugly-unicorn nm-openvpn[8022]: /usr/libexec/nm-openvpn-service-openvpn-helper --debug 0 8016 --bus-name org.freedesktop.NetworkManager.openvpn.Connection_19 --tun -- tun0 1500 0 10.125.175.2 255.255.255.0 init
Sep 08 02:38:14 ugly-unicorn nm-openvpn[8022]: UID set to nm-openvpn
Sep 08 02:38:14 ugly-unicorn nm-openvpn[8022]: GID set to nm-openvpn
Sep 08 02:38:14 ugly-unicorn nm-openvpn[8022]: Capabilities retained: CAP_NET_ADMIN
Sep 08 02:38:14 ugly-unicorn nm-openvpn[8022]: Initialization Sequence Completed
Sep 08 02:41:01 ugly-unicorn nm-openvpn[8022]: [clumsy-camel_67c1b959-7d87-48c4-a94c-298162db268e] Inactivity timeout (--ping-restart), restarting
Sep 08 02:41:01 ugly-unicorn nm-openvpn[8022]: SIGUSR1[soft,ping-restart] received, process restarting
Sep 08 02:41:02 ugly-unicorn nm-openvpn[8022]: NOTE: the current --script-security setting may allow this configuration to call user-defined scripts
Sep 08 02:41:02 ugly-unicorn nm-openvpn[8022]: TCP/UDP: Preserving recently used remote address: [AF_INET]77.11.137.63:1194
Sep 08 02:41:02 ugly-unicorn nm-openvpn[8022]: UDPv4 link local: (not bound)
Sep 08 02:41:02 ugly-unicorn nm-openvpn[8022]: UDPv4 link remote: [AF_INET]77.11.137.63:1194
Sep 08 02:41:02 ugly-unicorn nm-openvpn[8022]: [clumsy-camel_67c1b959-7d87-48c4-a94c-298162db268e] Peer Connection Initiated with [AF_INET]77.11.137.63:1194
Sep 08 02:41:02 ugly-unicorn nm-openvpn[8022]: Options error: Unrecognized option or missing or extra parameter(s) in [PUSH-OPTIONS]:2: block-outside-dns (2.6.14)
Sep 08 02:41:02 ugly-unicorn nm-openvpn[8022]: WARNING: You have specified redirect-gateway and redirect-private at the same time (or the same option multiple times). This is not well supported and may lead to unexpected results
Sep 08 02:41:02 ugly-unicorn nm-openvpn[8022]: Options error: ifconfig-ipv6: /netbits must be between 64 and 124, not '/128'
Sep 08 02:41:02 ugly-unicorn nm-openvpn[8022]: Preserving previous TUN/TAP instance: tun0
Sep 08 02:41:02 ugly-unicorn nm-openvpn[8022]: /usr/libexec/nm-openvpn-service-openvpn-helper --debug 0 8016 --bus-name org.freedesktop.NetworkManager.openvpn.Connection_19 --tun -- tun0 1500 0 10.125.175.2 255.255.255.0 restart
Sep 08 02:41:02 ugly-unicorn nm-openvpn[8022]: Initialization Sequence Completed
Sep 08 02:44:01 ugly-unicorn nm-openvpn[8022]: [clumsy-camel_67c1b959-7d87-48c4-a94c-298162db268e] Inactivity timeout (--ping-restart), restarting
Sep 08 02:44:01 ugly-unicorn nm-openvpn[8022]: SIGUSR1[soft,ping-restart] received, process restarting
Sep 08 02:44:02 ugly-unicorn nm-openvpn[8022]: NOTE: the current --script-security setting may allow this configuration to call user-defined scripts
Sep 08 02:44:02 ugly-unicorn nm-openvpn[8022]: TCP/UDP: Preserving recently used remote address: [AF_INET]77.11.137.63:1194
Sep 08 02:44:02 ugly-unicorn nm-openvpn[8022]: UDPv4 link local: (not bound)
Sep 08 02:44:02 ugly-unicorn nm-openvpn[8022]: UDPv4 link remote: [AF_INET]77.11.137.63:1194
Sep 08 02:44:02 ugly-unicorn nm-openvpn[8022]: [clumsy-camel_67c1b959-7d87-48c4-a94c-298162db268e] Peer Connection Initiated with [AF_INET]77.11.137.63:1194
Sep 08 02:44:02 ugly-unicorn nm-openvpn[8022]: Options error: Unrecognized option or missing or extra parameter(s) in [PUSH-OPTIONS]:2: block-outside-dns (2.6.14)
Sep 08 02:44:02 ugly-unicorn nm-openvpn[8022]: WARNING: You have specified redirect-gateway and redirect-private at the same time (or the same option multiple times). This is not well supported and may lead to unexpected results
Sep 08 02:44:02 ugly-unicorn nm-openvpn[8022]: Options error: ifconfig-ipv6: /netbits must be between 64 and 124, not '/128'
Sep 08 02:44:02 ugly-unicorn nm-openvpn[8022]: Preserving previous TUN/TAP instance: tun0
Sep 08 02:44:02 ugly-unicorn nm-openvpn[8022]: /usr/libexec/nm-openvpn-service-openvpn-helper --debug 0 8016 --bus-name org.freedesktop.NetworkManager.openvpn.Connection_19 --tun -- tun0 1500 0 10.125.175.2 255.255.255.0 restart
Sep 08 02:44:02 ugly-unicorn nm-openvpn[8022]: Initialization Sequence Completed
Sep 08 02:47:02 ugly-unicorn nm-openvpn[8022]: [clumsy-camel_67c1b959-7d87-48c4-a94c-298162db268e] Inactivity timeout (--ping-restart), restarting
Sep 08 02:47:02 ugly-unicorn nm-openvpn[8022]: SIGUSR1[soft,ping-restart] received, process restarting
Sep 08 02:47:03 ugly-unicorn nm-openvpn[8022]: NOTE: the current --script-security setting may allow this configuration to call user-defined scripts
Sep 08 02:47:03 ugly-unicorn nm-openvpn[8022]: TCP/UDP: Preserving recently used remote address: [AF_INET]77.11.137.63:1194
Sep 08 02:47:03 ugly-unicorn nm-openvpn[8022]: UDPv4 link local: (not bound)
Sep 08 02:47:03 ugly-unicorn nm-openvpn[8022]: UDPv4 link remote: [AF_INET]77.11.137.63:1194
Sep 08 02:47:03 ugly-unicorn nm-openvpn[8022]: [clumsy-camel_67c1b959-7d87-48c4-a94c-298162db268e] Peer Connection Initiated with [AF_INET]77.11.137.63:1194
Sep 08 02:47:03 ugly-unicorn nm-openvpn[8022]: Options error: Unrecognized option or missing or extra parameter(s) in [PUSH-OPTIONS]:2: block-outside-dns (2.6.14)
Sep 08 02:47:03 ugly-unicorn nm-openvpn[8022]: WARNING: You have specified redirect-gateway and redirect-private at the same time (or the same option multiple times). This is not well supported and may lead to unexpected results
Sep 08 02:47:03 ugly-unicorn nm-openvpn[8022]: Options error: ifconfig-ipv6: /netbits must be between 64 and 124, not '/128'
Sep 08 02:47:03 ugly-unicorn nm-openvpn[8022]: Preserving previous TUN/TAP instance: tun0
Sep 08 02:47:03 ugly-unicorn nm-openvpn[8022]: /usr/libexec/nm-openvpn-service-openvpn-helper --debug 0 8016 --bus-name org.freedesktop.NetworkManager.openvpn.Connection_19 --tun -- tun0 1500 0 10.125.175.2 255.255.255.0 restart
Sep 08 02:47:03 ugly-unicorn nm-openvpn[8022]: Initialization Sequence Completed
Sep 08 02:48:10 ugly-unicorn nm-openvpn[8022]: event_wait : Interrupted system call (fd=-1,code=4)
Sep 08 02:48:10 ugly-unicorn nm-openvpn[8022]: SIGTERM[hard,] received, process exiting
Sep 08 02:48:16 ugly-unicorn NetworkManager[1133]: <info>  [1757292496.3548] vpn[0x5ec62778ee50,17fde95d-fadd-4991-bb8c-8b1520c77bc9,"Max_Laptop"]: starting openvpn
Sep 08 02:48:16 ugly-unicorn nm-openvpn[8381]: Note: --cipher is not set. OpenVPN versions before 2.5 defaulted to BF-CBC as fallback when cipher negotiation failed in this case. If you need this fallback please add '--data-ciphers-fallback BF-CBC' to your configuration and/or add BF-CBC to --data-ciphers.
Sep 08 02:48:16 ugly-unicorn nm-openvpn[8381]: OpenVPN 2.6.14 x86_64-pc-linux-gnu [SSL (OpenSSL)] [LZO] [LZ4] [EPOLL] [PKCS11] [MH/PKTINFO] [AEAD] [DCO]
Sep 08 02:48:16 ugly-unicorn nm-openvpn[8381]: library versions: OpenSSL 3.0.13 30 Jan 2024, LZO 2.10
Sep 08 02:48:16 ugly-unicorn nm-openvpn[8381]: DCO version: N/A
Sep 08 02:48:16 ugly-unicorn nm-openvpn[8381]: NOTE: the current --script-security setting may allow this configuration to call user-defined scripts
Sep 08 02:48:16 ugly-unicorn nm-openvpn[8381]: TCP/UDP: Preserving recently used remote address: [AF_INET]77.11.137.63:1194
Sep 08 02:48:16 ugly-unicorn nm-openvpn[8381]: UDPv4 link local: (not bound)
Sep 08 02:48:16 ugly-unicorn nm-openvpn[8381]: UDPv4 link remote: [AF_INET]77.11.137.63:1194
Sep 08 02:48:16 ugly-unicorn nm-openvpn[8381]: NOTE: UID/GID downgrade will be delayed because of --client, --pull, or --up-delay
Sep 08 02:48:16 ugly-unicorn nm-openvpn[8381]: [clumsy-camel_67c1b959-7d87-48c4-a94c-298162db268e] Peer Connection Initiated with [AF_INET]77.11.137.63:1194
Sep 08 02:48:16 ugly-unicorn nm-openvpn[8381]: Options error: Unrecognized option or missing or extra parameter(s) in [PUSH-OPTIONS]:2: block-outside-dns (2.6.14)
Sep 08 02:48:16 ugly-unicorn nm-openvpn[8381]: WARNING: You have specified redirect-gateway and redirect-private at the same time (or the same option multiple times). This is not well supported and may lead to unexpected results
Sep 08 02:48:16 ugly-unicorn nm-openvpn[8381]: Options error: ifconfig-ipv6: /netbits must be between 64 and 124, not '/128'
Sep 08 02:48:16 ugly-unicorn nm-openvpn[8381]: TUN/TAP device tun0 opened
Sep 08 02:48:16 ugly-unicorn nm-openvpn[8381]: /usr/libexec/nm-openvpn-service-openvpn-helper --debug 0 8375 --bus-name org.freedesktop.NetworkManager.openvpn.Connection_22 --tun -- tun0 1500 0 10.125.175.2 255.255.255.0 init
Sep 08 02:48:16 ugly-unicorn nm-openvpn[8381]: UID set to nm-openvpn
Sep 08 02:48:16 ugly-unicorn nm-openvpn[8381]: GID set to nm-openvpn
Sep 08 02:48:16 ugly-unicorn nm-openvpn[8381]: Capabilities retained: CAP_NET_ADMIN
Sep 08 02:48:16 ugly-unicorn nm-openvpn[8381]: Initialization Sequence Completed
Sep 08 02:51:01 ugly-unicorn nm-openvpn[8381]: [clumsy-camel_67c1b959-7d87-48c4-a94c-298162db268e] Inactivity timeout (--ping-restart), restarting
Sep 08 02:51:01 ugly-unicorn nm-openvpn[8381]: SIGUSR1[soft,ping-restart] received, process restarting
Sep 08 02:51:02 ugly-unicorn nm-openvpn[8381]: NOTE: the current --script-security setting may allow this configuration to call user-defined scripts
Sep 08 02:51:02 ugly-unicorn nm-openvpn[8381]: TCP/UDP: Preserving recently used remote address: [AF_INET]77.11.137.63:1194
Sep 08 02:51:02 ugly-unicorn nm-openvpn[8381]: UDPv4 link local: (not bound)
Sep 08 02:51:02 ugly-unicorn nm-openvpn[8381]: UDPv4 link remote: [AF_INET]77.11.137.63:1194
Sep 08 02:51:03 ugly-unicorn nm-openvpn[8381]: [clumsy-camel_67c1b959-7d87-48c4-a94c-298162db268e] Peer Connection Initiated with [AF_INET]77.11.137.63:1194
Sep 08 02:51:03 ugly-unicorn nm-openvpn[8381]: Options error: Unrecognized option or missing or extra parameter(s) in [PUSH-OPTIONS]:2: block-outside-dns (2.6.14)
Sep 08 02:51:03 ugly-unicorn nm-openvpn[8381]: WARNING: You have specified redirect-gateway and redirect-private at the same time (or the same option multiple times). This is not well supported and may lead to unexpected results
Sep 08 02:51:03 ugly-unicorn nm-openvpn[8381]: Options error: ifconfig-ipv6: /netbits must be between 64 and 124, not '/128'
Sep 08 02:51:03 ugly-unicorn nm-openvpn[8381]: Preserving previous TUN/TAP instance: tun0
Sep 08 02:51:03 ugly-unicorn nm-openvpn[8381]: /usr/libexec/nm-openvpn-service-openvpn-helper --debug 0 8375 --bus-name org.freedesktop.NetworkManager.openvpn.Connection_22 --tun -- tun0 1500 0 10.125.175.2 255.255.255.0 restart
Sep 08 02:51:03 ugly-unicorn nm-openvpn[8381]: Initialization Sequence Completed
Sep 08 02:53:01 ugly-unicorn nm-openvpn[8381]: event_wait : Interrupted system call (fd=-1,code=4)
Sep 08 02:53:01 ugly-unicorn nm-openvpn[8381]: SIGTERM[hard,] received, process exiting
Sep 08 03:15:21 ugly-unicorn NetworkManager[1133]: <info>  [1757294121.4788] vpn[0x5ec6277e5050,17fde95d-fadd-4991-bb8c-8b1520c77bc9,"Max_Laptop"]: starting openvpn
Sep 08 03:15:21 ugly-unicorn nm-openvpn[9146]: Note: --cipher is not set. OpenVPN versions before 2.5 defaulted to BF-CBC as fallback when cipher negotiation failed in this case. If you need this fallback please add '--data-ciphers-fallback BF-CBC' to your configuration and/or add BF-CBC to --data-ciphers.
Sep 08 03:15:21 ugly-unicorn nm-openvpn[9146]: OpenVPN 2.6.14 x86_64-pc-linux-gnu [SSL (OpenSSL)] [LZO] [LZ4] [EPOLL] [PKCS11] [MH/PKTINFO] [AEAD] [DCO]
Sep 08 03:15:21 ugly-unicorn nm-openvpn[9146]: library versions: OpenSSL 3.0.13 30 Jan 2024, LZO 2.10
Sep 08 03:15:21 ugly-unicorn nm-openvpn[9146]: DCO version: N/A
Sep 08 03:15:21 ugly-unicorn nm-openvpn[9146]: NOTE: the current --script-security setting may allow this configuration to call user-defined scripts
Sep 08 03:15:21 ugly-unicorn nm-openvpn[9146]: TCP/UDP: Preserving recently used remote address: [AF_INET]77.11.137.63:1194
Sep 08 03:15:21 ugly-unicorn nm-openvpn[9146]: UDPv4 link local: (not bound)
Sep 08 03:15:21 ugly-unicorn nm-openvpn[9146]: UDPv4 link remote: [AF_INET]77.11.137.63:1194
Sep 08 03:15:21 ugly-unicorn nm-openvpn[9146]: NOTE: UID/GID downgrade will be delayed because of --client, --pull, or --up-delay
Sep 08 03:16:21 ugly-unicorn nm-openvpn-serv[9140]: Connect timer expired, disconnecting.
Sep 08 23:33:49 ugly-unicorn NetworkManager[1171]: <info>  [1757367229.4342] vpn[0x5ed2f268c300,17fde95d-fadd-4991-bb8c-8b1520c77bc9,"Max_Laptop"]: starting openvpn
Sep 08 23:33:49 ugly-unicorn nm-openvpn[3659]: Note: --cipher is not set. OpenVPN versions before 2.5 defaulted to BF-CBC as fallback when cipher negotiation failed in this case. If you need this fallback please add '--data-ciphers-fallback BF-CBC' to your configuration and/or add BF-CBC to --data-ciphers.
Sep 08 23:33:49 ugly-unicorn nm-openvpn[3659]: OpenVPN 2.6.14 x86_64-pc-linux-gnu [SSL (OpenSSL)] [LZO] [LZ4] [EPOLL] [PKCS11] [MH/PKTINFO] [AEAD] [DCO]
Sep 08 23:33:49 ugly-unicorn nm-openvpn[3659]: library versions: OpenSSL 3.0.13 30 Jan 2024, LZO 2.10
Sep 08 23:33:49 ugly-unicorn nm-openvpn[3659]: DCO version: N/A
Sep 08 23:33:49 ugly-unicorn nm-openvpn[3659]: NOTE: the current --script-security setting may allow this configuration to call user-defined scripts
Sep 08 23:33:49 ugly-unicorn nm-openvpn[3659]: TCP/UDP: Preserving recently used remote address: [AF_INET]77.188.186.193:1194
Sep 08 23:33:49 ugly-unicorn nm-openvpn[3659]: UDPv4 link local: (not bound)
Sep 08 23:33:49 ugly-unicorn nm-openvpn[3659]: UDPv4 link remote: [AF_INET]77.188.186.193:1194
Sep 08 23:33:49 ugly-unicorn nm-openvpn[3659]: NOTE: UID/GID downgrade will be delayed because of --client, --pull, or --up-delay
Sep 08 23:33:49 ugly-unicorn nm-openvpn[3659]: [clumsy-camel_67c1b959-7d87-48c4-a94c-298162db268e] Peer Connection Initiated with [AF_INET]77.188.186.193:1194
Sep 08 23:33:49 ugly-unicorn nm-openvpn[3659]: Options error: Unrecognized option or missing or extra parameter(s) in [PUSH-OPTIONS]:2: block-outside-dns (2.6.14)
Sep 08 23:33:49 ugly-unicorn nm-openvpn[3659]: WARNING: You have specified redirect-gateway and redirect-private at the same time (or the same option multiple times). This is not well supported and may lead to unexpected results
Sep 08 23:33:49 ugly-unicorn nm-openvpn[3659]: Options error: ifconfig-ipv6: /netbits must be between 64 and 124, not '/128'
Sep 08 23:33:49 ugly-unicorn nm-openvpn[3659]: TUN/TAP device tun0 opened
Sep 08 23:33:49 ugly-unicorn nm-openvpn[3659]: /usr/libexec/nm-openvpn-service-openvpn-helper --debug 0 3653 --bus-name org.freedesktop.NetworkManager.openvpn.Connection_6 --tun -- tun0 1500 0 10.125.175.2 255.255.255.0 init
Sep 08 23:33:49 ugly-unicorn nm-openvpn[3659]: UID set to nm-openvpn
Sep 08 23:33:49 ugly-unicorn nm-openvpn[3659]: GID set to nm-openvpn
Sep 08 23:33:49 ugly-unicorn nm-openvpn[3659]: Capabilities retained: CAP_NET_ADMIN
Sep 08 23:33:49 ugly-unicorn nm-openvpn[3659]: Initialization Sequence Completed
Sep 08 23:36:20 ugly-unicorn nm-openvpn[3659]: event_wait : Interrupted system call (fd=-1,code=4)
Sep 08 23:36:20 ugly-unicorn nm-openvpn[3659]: SIGTERM[hard,] received, process exiting
Sep 08 23:36:31 ugly-unicorn NetworkManager[1171]: <info>  [1757367391.0000] vpn[0x5ed2f26a3ef0,17fde95d-fadd-4991-bb8c-8b1520c77bc9,"Max_Laptop"]: starting openvpn
Sep 08 23:36:31 ugly-unicorn nm-openvpn[4453]: Note: --cipher is not set. OpenVPN versions before 2.5 defaulted to BF-CBC as fallback when cipher negotiation failed in this case. If you need this fallback please add '--data-ciphers-fallback BF-CBC' to your configuration and/or add BF-CBC to --data-ciphers.
Sep 08 23:36:31 ugly-unicorn nm-openvpn[4453]: OpenVPN 2.6.14 x86_64-pc-linux-gnu [SSL (OpenSSL)] [LZO] [LZ4] [EPOLL] [PKCS11] [MH/PKTINFO] [AEAD] [DCO]
Sep 08 23:36:31 ugly-unicorn nm-openvpn[4453]: library versions: OpenSSL 3.0.13 30 Jan 2024, LZO 2.10
Sep 08 23:36:31 ugly-unicorn nm-openvpn[4453]: DCO version: N/A
Sep 08 23:36:31 ugly-unicorn nm-openvpn[4453]: NOTE: the current --script-security setting may allow this configuration to call user-defined scripts
Sep 08 23:36:31 ugly-unicorn nm-openvpn[4453]: TCP/UDP: Preserving recently used remote address: [AF_INET]77.188.186.193:1194
Sep 08 23:36:31 ugly-unicorn nm-openvpn[4453]: UDPv4 link local: (not bound)
Sep 08 23:36:31 ugly-unicorn nm-openvpn[4453]: UDPv4 link remote: [AF_INET]77.188.186.193:1194
Sep 08 23:36:31 ugly-unicorn nm-openvpn[4453]: NOTE: UID/GID downgrade will be delayed because of --client, --pull, or --up-delay
Sep 08 23:36:31 ugly-unicorn nm-openvpn[4453]: [clumsy-camel_67c1b959-7d87-48c4-a94c-298162db268e] Peer Connection Initiated with [AF_INET]77.188.186.193:1194
Sep 08 23:36:31 ugly-unicorn nm-openvpn[4453]: Options error: Unrecognized option or missing or extra parameter(s) in [PUSH-OPTIONS]:2: block-outside-dns (2.6.14)
Sep 08 23:36:31 ugly-unicorn nm-openvpn[4453]: WARNING: You have specified redirect-gateway and redirect-private at the same time (or the same option multiple times). This is not well supported and may lead to unexpected results
Sep 08 23:36:31 ugly-unicorn nm-openvpn[4453]: Options error: ifconfig-ipv6: /netbits must be between 64 and 124, not '/128'
Sep 08 23:36:31 ugly-unicorn nm-openvpn[4453]: TUN/TAP device tun0 opened
Sep 08 23:36:31 ugly-unicorn nm-openvpn[4453]: /usr/libexec/nm-openvpn-service-openvpn-helper --debug 0 4447 --bus-name org.freedesktop.NetworkManager.openvpn.Connection_8 --tun -- tun0 1500 0 10.125.175.2 255.255.255.0 init
Sep 08 23:36:31 ugly-unicorn nm-openvpn[4453]: UID set to nm-openvpn
Sep 08 23:36:31 ugly-unicorn nm-openvpn[4453]: GID set to nm-openvpn
Sep 08 23:36:31 ugly-unicorn nm-openvpn[4453]: Capabilities retained: CAP_NET_ADMIN
Sep 08 23:36:31 ugly-unicorn nm-openvpn[4453]: Initialization Sequence Completed
Sep 08 23:45:02 ugly-unicorn NetworkManager[1171]: <trace> [1757367902.5967] vpn[0x5ed2f26a3ef0,17fde95d-fadd-4991-bb8c-8b1520c77bc9,"Max_Laptop",if:5,dev:3:(tun0)]: dbus: call Disconnect on org.freedesktop.NetworkManager.openvpn.Connection_8
Sep 08 23:45:02 ugly-unicorn nm-openvpn[4453]: event_wait : Interrupted system call (fd=-1,code=4)
Sep 08 23:45:02 ugly-unicorn nm-openvpn[4453]: SIGTERM[hard,] received, process exiting
Sep 09 00:13:59 ugly-unicorn NetworkManager[1171]: <info>  [1757369639.4076] vpn[0x5ed2f2664160,17fde95d-fadd-4991-bb8c-8b1520c77bc9,"Max_Laptop"]: starting openvpn
Sep 09 00:13:59 ugly-unicorn NetworkManager[1171]: <debug> [1757369639.4076] vpn[0x5ed2f2664160,17fde95d-fadd-4991-bb8c-8b1520c77bc9,"Max_Laptop"]: starting: watch D-Bus service org.freedesktop.NetworkManager.openvpn.Connection_11
Sep 09 00:13:59 ugly-unicorn NetworkManager[1171]: <trace> [1757369639.4082] vpn[0x5ed2f2664160,17fde95d-fadd-4991-bb8c-8b1520c77bc9,"Max_Laptop"]: dbus: no name owner for org.freedesktop.NetworkManager.openvpn.Connection_11 (start VPN service)
Sep 09 00:13:59 ugly-unicorn NetworkManager[1171]: <trace> [1757369639.4176] vpn[0x5ed2f2664160,17fde95d-fadd-4991-bb8c-8b1520c77bc9,"Max_Laptop"]: dbus: name owner :1.143 for org.freedesktop.NetworkManager.openvpn.Connection_11
Sep 09 00:13:59 ugly-unicorn NetworkManager[1171]: <trace> [1757369639.4184] vpn[0x5ed2f2664160,17fde95d-fadd-4991-bb8c-8b1520c77bc9,"Max_Laptop"]: dbus: call NeedSecrets on org.freedesktop.NetworkManager.openvpn.Connection_11
Sep 09 00:13:59 ugly-unicorn NetworkManager[1171]: <trace> [1757369639.4226] vpn[0x5ed2f2664160,17fde95d-fadd-4991-bb8c-8b1520c77bc9,"Max_Laptop"]: dbus: call NeedSecrets on org.freedesktop.NetworkManager.openvpn.Connection_11
Sep 09 00:13:59 ugly-unicorn NetworkManager[1171]: <trace> [1757369639.4235] vpn[0x5ed2f2664160,17fde95d-fadd-4991-bb8c-8b1520c77bc9,"Max_Laptop"]: dbus: call ConnectInteractive on org.freedesktop.NetworkManager.openvpn.Connection_11
Sep 09 00:13:59 ugly-unicorn nm-openvpn[5559]: Note: --cipher is not set. OpenVPN versions before 2.5 defaulted to BF-CBC as fallback when cipher negotiation failed in this case. If you need this fallback please add '--data-ciphers-fallback BF-CBC' to your configuration and/or add BF-CBC to --data-ciphers.
Sep 09 00:13:59 ugly-unicorn nm-openvpn[5559]: OpenVPN 2.6.14 x86_64-pc-linux-gnu [SSL (OpenSSL)] [LZO] [LZ4] [EPOLL] [PKCS11] [MH/PKTINFO] [AEAD] [DCO]
Sep 09 00:13:59 ugly-unicorn nm-openvpn[5559]: library versions: OpenSSL 3.0.13 30 Jan 2024, LZO 2.10
Sep 09 00:13:59 ugly-unicorn nm-openvpn[5559]: DCO version: N/A
Sep 09 00:13:59 ugly-unicorn nm-openvpn[5559]: NOTE: the current --script-security setting may allow this configuration to call user-defined scripts
Sep 09 00:13:59 ugly-unicorn nm-openvpn[5559]: TCP/UDP: Preserving recently used remote address: [AF_INET]77.188.186.193:1194
Sep 09 00:13:59 ugly-unicorn nm-openvpn[5559]: UDPv4 link local: (not bound)
Sep 09 00:13:59 ugly-unicorn nm-openvpn[5559]: UDPv4 link remote: [AF_INET]77.188.186.193:1194
Sep 09 00:13:59 ugly-unicorn nm-openvpn[5559]: NOTE: UID/GID downgrade will be delayed because of --client, --pull, or --up-delay
Sep 09 00:13:59 ugly-unicorn nm-openvpn[5559]: [clumsy-camel_67c1b959-7d87-48c4-a94c-298162db268e] Peer Connection Initiated with [AF_INET]77.188.186.193:1194
Sep 09 00:13:59 ugly-unicorn nm-openvpn[5559]: Options error: Unrecognized option or missing or extra parameter(s) in [PUSH-OPTIONS]:2: block-outside-dns (2.6.14)
Sep 09 00:13:59 ugly-unicorn nm-openvpn[5559]: WARNING: You have specified redirect-gateway and redirect-private at the same time (or the same option multiple times). This is not well supported and may lead to unexpected results
Sep 09 00:13:59 ugly-unicorn nm-openvpn[5559]: Options error: ifconfig-ipv6: /netbits must be between 64 and 124, not '/128'
Sep 09 00:13:59 ugly-unicorn nm-openvpn[5559]: TUN/TAP device tun0 opened
Sep 09 00:13:59 ugly-unicorn nm-openvpn[5559]: /usr/libexec/nm-openvpn-service-openvpn-helper --debug 0 5553 --bus-name org.freedesktop.NetworkManager.openvpn.Connection_11 --tun -- tun0 1500 0 10.125.175.2 255.255.255.0 init
Sep 09 00:13:59 ugly-unicorn nm-openvpn[5559]: UID set to nm-openvpn
Sep 09 00:13:59 ugly-unicorn nm-openvpn[5559]: GID set to nm-openvpn
Sep 09 00:13:59 ugly-unicorn nm-openvpn[5559]: Capabilities retained: CAP_NET_ADMIN
Sep 09 00:13:59 ugly-unicorn nm-openvpn[5559]: Initialization Sequence Completed
Sep 09 00:43:20 ugly-unicorn NetworkManager[1171]: <trace> [1757371400.6440] vpn[0x5ed2f2664160,17fde95d-fadd-4991-bb8c-8b1520c77bc9,"Max_Laptop",if:7,dev:6:(tun0)]: dbus: call Disconnect on org.freedesktop.NetworkManager.openvpn.Connection_11
Sep 09 00:43:20 ugly-unicorn nm-openvpn[5559]: event_wait : Interrupted system call (fd=-1,code=4)
Sep 09 00:43:20 ugly-unicorn nm-openvpn[5559]: SIGTERM[hard,] received, process exiting
Sep 09 00:43:27 ugly-unicorn NetworkManager[1171]: <info>  [1757371407.4964] vpn[0x5ed2f26de090,17fde95d-fadd-4991-bb8c-8b1520c77bc9,"Max_Laptop"]: starting openvpn
Sep 09 00:43:27 ugly-unicorn NetworkManager[1171]: <debug> [1757371407.4964] vpn[0x5ed2f26de090,17fde95d-fadd-4991-bb8c-8b1520c77bc9,"Max_Laptop"]: starting: watch D-Bus service org.freedesktop.NetworkManager.openvpn.Connection_13
Sep 09 00:43:27 ugly-unicorn NetworkManager[1171]: <trace> [1757371407.4970] vpn[0x5ed2f26de090,17fde95d-fadd-4991-bb8c-8b1520c77bc9,"Max_Laptop"]: dbus: no name owner for org.freedesktop.NetworkManager.openvpn.Connection_13 (start VPN service)
Sep 09 00:43:27 ugly-unicorn NetworkManager[1171]: <trace> [1757371407.5078] vpn[0x5ed2f26de090,17fde95d-fadd-4991-bb8c-8b1520c77bc9,"Max_Laptop"]: dbus: name owner :1.178 for org.freedesktop.NetworkManager.openvpn.Connection_13
Sep 09 00:43:27 ugly-unicorn NetworkManager[1171]: <trace> [1757371407.5087] vpn[0x5ed2f26de090,17fde95d-fadd-4991-bb8c-8b1520c77bc9,"Max_Laptop"]: dbus: call NeedSecrets on org.freedesktop.NetworkManager.openvpn.Connection_13
Sep 09 00:43:27 ugly-unicorn NetworkManager[1171]: <trace> [1757371407.5132] vpn[0x5ed2f26de090,17fde95d-fadd-4991-bb8c-8b1520c77bc9,"Max_Laptop"]: dbus: call NeedSecrets on org.freedesktop.NetworkManager.openvpn.Connection_13
Sep 09 00:43:27 ugly-unicorn NetworkManager[1171]: <trace> [1757371407.5142] vpn[0x5ed2f26de090,17fde95d-fadd-4991-bb8c-8b1520c77bc9,"Max_Laptop"]: dbus: call ConnectInteractive on org.freedesktop.NetworkManager.openvpn.Connection_13
Sep 09 00:43:27 ugly-unicorn nm-openvpn[13597]: Note: --cipher is not set. OpenVPN versions before 2.5 defaulted to BF-CBC as fallback when cipher negotiation failed in this case. If you need this fallback please add '--data-ciphers-fallback BF-CBC' to your configuration and/or add BF-CBC to --data-ciphers.
Sep 09 00:43:27 ugly-unicorn nm-openvpn[13597]: OpenVPN 2.6.14 x86_64-pc-linux-gnu [SSL (OpenSSL)] [LZO] [LZ4] [EPOLL] [PKCS11] [MH/PKTINFO] [AEAD] [DCO]
Sep 09 00:43:27 ugly-unicorn nm-openvpn[13597]: library versions: OpenSSL 3.0.13 30 Jan 2024, LZO 2.10
Sep 09 00:43:27 ugly-unicorn nm-openvpn[13597]: DCO version: N/A
Sep 09 00:43:27 ugly-unicorn nm-openvpn[13597]: NOTE: the current --script-security setting may allow this configuration to call user-defined scripts
Sep 09 00:43:27 ugly-unicorn nm-openvpn[13597]: TCP/UDP: Preserving recently used remote address: [AF_INET]77.188.186.193:1194
Sep 09 00:43:27 ugly-unicorn nm-openvpn[13597]: UDPv4 link local: (not bound)
Sep 09 00:43:27 ugly-unicorn nm-openvpn[13597]: UDPv4 link remote: [AF_INET]77.188.186.193:1194
Sep 09 00:43:27 ugly-unicorn nm-openvpn[13597]: NOTE: UID/GID downgrade will be delayed because of --client, --pull, or --up-delay
Sep 09 00:43:27 ugly-unicorn nm-openvpn[13597]: [clumsy-camel_67c1b959-7d87-48c4-a94c-298162db268e] Peer Connection Initiated with [AF_INET]77.188.186.193:1194
Sep 09 00:43:27 ugly-unicorn nm-openvpn[13597]: Options error: Unrecognized option or missing or extra parameter(s) in [PUSH-OPTIONS]:2: block-outside-dns (2.6.14)
Sep 09 00:43:27 ugly-unicorn nm-openvpn[13597]: WARNING: You have specified redirect-gateway and redirect-private at the same time (or the same option multiple times). This is not well supported and may lead to unexpected results
Sep 09 00:43:27 ugly-unicorn nm-openvpn[13597]: Options error: ifconfig-ipv6: /netbits must be between 64 and 124, not '/128'
Sep 09 00:43:27 ugly-unicorn nm-openvpn[13597]: TUN/TAP device tun0 opened
Sep 09 00:43:27 ugly-unicorn nm-openvpn[13597]: /usr/libexec/nm-openvpn-service-openvpn-helper --debug 0 13591 --bus-name org.freedesktop.NetworkManager.openvpn.Connection_13 --tun -- tun0 1500 0 10.125.175.2 255.255.255.0 init
Sep 09 00:43:27 ugly-unicorn nm-openvpn[13597]: UID set to nm-openvpn
Sep 09 00:43:27 ugly-unicorn nm-openvpn[13597]: GID set to nm-openvpn
Sep 09 00:43:27 ugly-unicorn nm-openvpn[13597]: Capabilities retained: CAP_NET_ADMIN
Sep 09 00:43:27 ugly-unicorn nm-openvpn[13597]: Initialization Sequence Completed
Sep 09 00:44:45 ugly-unicorn NetworkManager[1171]: <trace> [1757371485.3487] vpn[0x5ed2f26de090,17fde95d-fadd-4991-bb8c-8b1520c77bc9,"Max_Laptop",if:8,dev:6:(tun0)]: dbus: call Disconnect on org.freedesktop.NetworkManager.openvpn.Connection_13
Sep 09 00:44:45 ugly-unicorn nm-openvpn[13597]: event_wait : Interrupted system call (fd=-1,code=4)
Sep 09 00:44:45 ugly-unicorn nm-openvpn[13597]: SIGTERM[hard,] received, process exiting
Sep 09 00:46:03 ugly-unicorn NetworkManager[1133]: <info>  [1757371563.5170] vpn[0x5ca0bac0f6a0,17fde95d-fadd-4991-bb8c-8b1520c77bc9,"Max_Laptop"]: starting openvpn
Sep 09 00:46:03 ugly-unicorn nm-openvpn[3093]: Note: --cipher is not set. OpenVPN versions before 2.5 defaulted to BF-CBC as fallback when cipher negotiation failed in this case. If you need this fallback please add '--data-ciphers-fallback BF-CBC' to your configuration and/or add BF-CBC to --data-ciphers.
Sep 09 00:46:03 ugly-unicorn nm-openvpn[3093]: OpenVPN 2.6.14 x86_64-pc-linux-gnu [SSL (OpenSSL)] [LZO] [LZ4] [EPOLL] [PKCS11] [MH/PKTINFO] [AEAD] [DCO]
Sep 09 00:46:03 ugly-unicorn nm-openvpn[3093]: library versions: OpenSSL 3.0.13 30 Jan 2024, LZO 2.10
Sep 09 00:46:03 ugly-unicorn nm-openvpn[3093]: DCO version: N/A
Sep 09 00:46:03 ugly-unicorn nm-openvpn[3093]: NOTE: the current --script-security setting may allow this configuration to call user-defined scripts
Sep 09 00:46:03 ugly-unicorn nm-openvpn[3093]: TCP/UDP: Preserving recently used remote address: [AF_INET]77.188.186.193:1194
Sep 09 00:46:03 ugly-unicorn nm-openvpn[3093]: UDPv4 link local: (not bound)
Sep 09 00:46:03 ugly-unicorn nm-openvpn[3093]: UDPv4 link remote: [AF_INET]77.188.186.193:1194
Sep 09 00:46:03 ugly-unicorn nm-openvpn[3093]: NOTE: UID/GID downgrade will be delayed because of --client, --pull, or --up-delay
Sep 09 00:46:03 ugly-unicorn nm-openvpn[3093]: [clumsy-camel_67c1b959-7d87-48c4-a94c-298162db268e] Peer Connection Initiated with [AF_INET]77.188.186.193:1194
Sep 09 00:46:03 ugly-unicorn nm-openvpn[3093]: Options error: Unrecognized option or missing or extra parameter(s) in [PUSH-OPTIONS]:2: block-outside-dns (2.6.14)
Sep 09 00:46:03 ugly-unicorn nm-openvpn[3093]: WARNING: You have specified redirect-gateway and redirect-private at the same time (or the same option multiple times). This is not well supported and may lead to unexpected results
Sep 09 00:46:03 ugly-unicorn nm-openvpn[3093]: Options error: ifconfig-ipv6: /netbits must be between 64 and 124, not '/128'
Sep 09 00:46:03 ugly-unicorn nm-openvpn[3093]: TUN/TAP device tun0 opened
Sep 09 00:46:03 ugly-unicorn nm-openvpn[3093]: /usr/libexec/nm-openvpn-service-openvpn-helper --debug 0 3087 --bus-name org.freedesktop.NetworkManager.openvpn.Connection_4 --tun -- tun0 1500 0 10.125.175.2 255.255.255.0 init
Sep 09 00:46:03 ugly-unicorn nm-openvpn[3093]: UID set to nm-openvpn
Sep 09 00:46:03 ugly-unicorn nm-openvpn[3093]: GID set to nm-openvpn
Sep 09 00:46:03 ugly-unicorn nm-openvpn[3093]: Capabilities retained: CAP_NET_ADMIN
Sep 09 00:46:03 ugly-unicorn nm-openvpn[3093]: Initialization Sequence Completed
Sep 09 01:11:58 ugly-unicorn nm-openvpn[3093]: SIGTERM[hard,] received, process exiting
Sep 09 15:11:11 ugly-unicorn NetworkManager[1383]: <info>  [1757423471.3902] vpn[0x558c713b8d20,17fde95d-fadd-4991-bb8c-8b1520c77bc9,"Max_Laptop"]: starting openvpn
Sep 09 15:11:11 ugly-unicorn nm-openvpn[3862]: Note: --cipher is not set. OpenVPN versions before 2.5 defaulted to BF-CBC as fallback when cipher negotiation failed in this case. If you need this fallback please add '--data-ciphers-fallback BF-CBC' to your configuration and/or add BF-CBC to --data-ciphers.
Sep 09 15:11:11 ugly-unicorn nm-openvpn[3862]: OpenVPN 2.6.14 x86_64-pc-linux-gnu [SSL (OpenSSL)] [LZO] [LZ4] [EPOLL] [PKCS11] [MH/PKTINFO] [AEAD] [DCO]
Sep 09 15:11:11 ugly-unicorn nm-openvpn[3862]: library versions: OpenSSL 3.0.13 30 Jan 2024, LZO 2.10
Sep 09 15:11:11 ugly-unicorn nm-openvpn[3862]: DCO version: N/A
Sep 09 15:11:11 ugly-unicorn nm-openvpn[3862]: NOTE: the current --script-security setting may allow this configuration to call user-defined scripts
Sep 09 15:11:11 ugly-unicorn nm-openvpn[3862]: TCP/UDP: Preserving recently used remote address: [AF_INET]93.128.25.155:1194
Sep 09 15:11:11 ugly-unicorn nm-openvpn[3862]: UDPv4 link local: (not bound)
Sep 09 15:11:11 ugly-unicorn nm-openvpn[3862]: UDPv4 link remote: [AF_INET]93.128.25.155:1194
Sep 09 15:11:11 ugly-unicorn nm-openvpn[3862]: NOTE: UID/GID downgrade will be delayed because of --client, --pull, or --up-delay
Sep 09 15:11:11 ugly-unicorn nm-openvpn[3862]: [clumsy-camel_67c1b959-7d87-48c4-a94c-298162db268e] Peer Connection Initiated with [AF_INET]93.128.25.155:1194
Sep 09 15:11:11 ugly-unicorn nm-openvpn[3862]: Options error: Unrecognized option or missing or extra parameter(s) in [PUSH-OPTIONS]:2: block-outside-dns (2.6.14)
Sep 09 15:11:11 ugly-unicorn nm-openvpn[3862]: WARNING: You have specified redirect-gateway and redirect-private at the same time (or the same option multiple times). This is not well supported and may lead to unexpected results
Sep 09 15:11:11 ugly-unicorn nm-openvpn[3862]: Options error: ifconfig-ipv6: /netbits must be between 64 and 124, not '/128'
Sep 09 15:11:11 ugly-unicorn nm-openvpn[3862]: TUN/TAP device tun0 opened
Sep 09 15:11:11 ugly-unicorn nm-openvpn[3862]: /usr/libexec/nm-openvpn-service-openvpn-helper --debug 0 3856 --bus-name org.freedesktop.NetworkManager.openvpn.Connection_5 --tun -- tun0 1500 0 10.125.175.2 255.255.255.0 init
Sep 09 15:11:11 ugly-unicorn nm-openvpn[3862]: UID set to nm-openvpn
Sep 09 15:11:11 ugly-unicorn nm-openvpn[3862]: GID set to nm-openvpn
Sep 09 15:11:11 ugly-unicorn nm-openvpn[3862]: Capabilities retained: CAP_NET_ADMIN
Sep 09 15:11:11 ugly-unicorn nm-openvpn[3862]: Initialization Sequence Completed

DJKUhpisse Team-Icon

Supporter, Wikiteam
Avatar von DJKUhpisse

Anmeldungsdatum:
18. Oktober 2016

Beiträge: 18245

Options error: ifconfig-ipv6: /netbits must be between 64 and 124, not '/128'

/128 will der nicht, kannst du dem /124 geben?

gazrilla92

(Themenstarter)

Anmeldungsdatum:
16. Januar 2024

Beiträge: 71

Super, das hat geklappt. 😎 Hab vielen lieben Dank. ♥

Liebe Grüße

gazrilla92

(Themenstarter)

Anmeldungsdatum:
16. Januar 2024

Beiträge: 71

Kann ich dich noch etwas anderes fragen? Ich habe noch irgendwo einen Bug in meinem Skript, den ich einfach nicht finden kann. Wäre echt lieb, wenn du mal ein Auge darüber werfen könntest. Das Skript läuft bei ipv6-Änderungen sauber durch. Ich bekomme aber keine Verbindung mit meinen Clients mehr hin. Erst wenn ich die ipv6 in der server.conf ändere und das Skript nochmal durchlaufen lasse, klappt es. Hast du eine Idee?

#!/bin/bash
# -----------------------------
# OpenVPN IPv6 Update Script
# -----------------------------
CONFIG="/etc/openvpn/server.conf"
BACKUP_DIR="/etc/openvpn/backups"
MAX_BACKUPS=3
WAN_IF="eth0"
TUN_IF="tun0"
CCD_DIR="/etc/openvpn/ccd"

ts() { date "+%a %d %b %T %Z %Y"; }

# -----------------------------
# 1. Aktuelles Präfix via curl
# -----------------------------
WAN_ADDR=$(curl -6 -s ifconfig.co)

if [ -z "$WAN_ADDR" ]; then
    echo "$(ts) - Fehler: konnte keine öffentliche IPv6 ermitteln"
    exit 1
fi

# -----------------------------
# 2. VPN-Subnetz berechnen: 4. Block +1
# -----------------------------
VPN_SUBNET=$(python3 - <<EOF
import ipaddress
addr = ipaddress.IPv6Address("$WAN_ADDR")
hextets = addr.exploded.split(":")
b1,b2,b3,b4 = hextets[:4]
new4 = f"{(int(b4,16)+1) & 0xFFFF:04x}"
print(f"{b1}:{b2}:{b3}:{new4}::/64")
EOF
)

if [ -z "$VPN_SUBNET" ]; then
    echo "$(ts) - Fehler: VPN-SUBNET konnte nicht ermittelt werden"
    exit 1
fi

echo "$(ts) - WAN_ADDR=$WAN_ADDR, VPN_SUBNET=$VPN_SUBNET"

# Prüfen, ob Änderung nötig
CURRENT_CONF=$(grep "^server-ipv6" "$CONFIG" | awk '{print $2}' | tr -d '[:space:]')
if [ "$CURRENT_CONF" = "$VPN_SUBNET" ]; then
    echo "$(ts) - Keine Änderung nötig ($CURRENT_CONF)"
    exit 0
fi
echo "$(ts) - Präfix geändert: $CURRENT_CONF -> $VPN_SUBNET"

# -----------------------------
# 3. Backup Config
# -----------------------------
mkdir -p "$BACKUP_DIR"
TIMESTAMP=$(date +%Y%m%d%H%M)
cp "$CONFIG" "$BACKUP_DIR/server.conf.$TIMESTAMP"
ls -1t "$BACKUP_DIR"/server.conf.* | tail -n +$((MAX_BACKUPS+1)) | xargs -r rm

# -----------------------------
# 4. Config aktualisieren
# -----------------------------
if grep -q "^server-ipv6" "$CONFIG"; then
    sed -i "s|^server-ipv6.*|server-ipv6 $VPN_SUBNET|" "$CONFIG"
else
    echo "server-ipv6 $VPN_SUBNET" >> "$CONFIG"
fi
echo "$(ts) - server-ipv6 auf $VPN_SUBNET gesetzt"

# -----------------------------
# 5. OpenVPN neu starten
# -----------------------------
if command -v systemctl >/dev/null 2>&1; then
    systemctl restart openvpn
else
    service openvpn restart 2>/dev/null
fi
echo "$(ts) - OpenVPN neu gestartet"

# 5 Sekunden warten, damit OpenVPN das neue server-ipv6 übernimmt
sleep 5
echo "$(ts) - Wartezeit nach OpenVPN-Neustart abgeschlossen"

# -----------------------------
# 6. Alte IPv6-Adressen vom TUN-Interface entfernen
# -----------------------------
ip link set dev "$TUN_IF" up
ip -6 addr show dev "$TUN_IF" scope global | grep -oP '([0-9a-f:]+/\d+)' | while read oldip; do
    ip -6 addr del "$oldip" dev "$TUN_IF" 2>/dev/null
    echo "$(ts) - Alte Adresse entfernt: $oldip"
done

SERVER_IP="${VPN_SUBNET%/*}1/64"
ip -6 addr add "$SERVER_IP" dev "$TUN_IF"
echo "$(ts) - Neue Server-IP auf $TUN_IF gesetzt: $SERVER_IP"

# -----------------------------
# 7. CCD-Dateien aktualisieren (Clients ab 1001, /124)
# -----------------------------
HOST_START=1001
if [ -d "$CCD_DIR" ]; then
    i=$HOST_START
    PREFIX_NO_SLASH="${VPN_SUBNET%/64}"
    SERVER_IP_NO_PREFIX="${PREFIX_NO_SLASH}::1"

    find "$CCD_DIR" -type f | sort | while read -r ccdfile; do
        sed -i '/^ifconfig-ipv6-push/d' "$ccdfile"
        sed -i '/^iroute-ipv6/d' "$ccdfile"

        client_subnet="${PREFIX_NO_SLASH}::${i}/124"
        echo "ifconfig-ipv6-push ${client_subnet} ${SERVER_IP_NO_PREFIX}/124" >> "$ccdfile"
        echo "iroute-ipv6 ${client_subnet}" >> "$ccdfile"

        echo "$(ts) - CCD-Datei aktualisiert: $(basename "$ccdfile") -> ${client_subnet}"
        i=$((i+1))
    done
fi

# -----------------------------
# 8. NAT66 anpassen
# -----------------------------
# Alte NAT66-Regeln entfernen
while read -r line; do
    delete_cmd="${line/-A/-D}"
    ip6tables -t nat $delete_cmd 2>/dev/null
    echo "$(ts) - Alte NAT66-Regel entfernt: $delete_cmd"
done < <(ip6tables -t nat -S POSTROUTING | grep "openvpn-nat-rule")

# Neue NAT66-Regel
ip6tables -t nat -A POSTROUTING -s "$VPN_SUBNET" -o "$WAN_IF" \
    -j MASQUERADE -m comment --comment "openvpn-nat-rule"
echo "$(ts) - NAT66 gesetzt: $VPN_SUBNET -> $WAN_IF"

# -----------------------------
# 9. VPN-Routen aktualisieren
# -----------------------------
# Alte Routen löschen
ip -6 route show dev "$TUN_IF" | awk '{print $1}' | while read oldroute; do
    ip -6 route del "$oldroute" dev "$TUN_IF" 2>/dev/null
done

# Neue Routen setzen: VPN-Subnetz + alle Client-/124 Subnets
ip -6 route add "$VPN_SUBNET" dev "$TUN_IF"
if [ -d "$CCD_DIR" ]; then
    i=$HOST_START
    find "$CCD_DIR" -type f | sort | while read -r ccdfile; do
        client_subnet="${PREFIX_NO_SLASH}::${i}/124"
        ip -6 route add "$client_subnet" dev "$TUN_IF" 2>/dev/null
        i=$((i+1))
    done
fi
echo "$(ts) - VPN-Routen gesetzt"

schwarzheit Team-Icon

Supporter
Avatar von schwarzheit

Anmeldungsdatum:
31. Dezember 2007

Beiträge: 5329

Bitte erstelle für jede Frage / jedes Problem ein eigenes Thema im passenden Unterforum. → Forum/Kurzanleitung (Abschnitt „Eine-Frage-ein-Thema“)
Beachte dabei bitte die als wichtig markierten Themen („Welche Themen gehören hier her und welche nicht?“) in jedem Forenbereich.
Und wähle bitte auch einen aussagekräftigen Titel! Danke.


Markiere den Thread bitte noch als gelöst.
Forum/Syntax (Abschnitt „geloest-ungeloest“)

gazrilla92

(Themenstarter)

Anmeldungsdatum:
16. Januar 2024

Beiträge: 71

.

Antworten |