What's new

VPN 128 encryption Needs updating

  • SNBForums Code of Conduct

    SNBForums is a community for everyone, no matter what their level of experience.

    Please be tolerant and patient of others, especially newcomers. We are all here to share and learn!

    The rules are simple: Be patient, be nice, be helpful or be gone!

Ametz

Occasional Visitor
Last edited:
OpenVPN has done some changes recently and are not accepting encryptions lower then 768 bits (And soon soon 1024)

More info:
https://groups.google.com/forum/#!topic/tunnelblick-discuss/AR7dLC2QcrI
https://forums.openvpn.net/topic19029.html#p52630

Google: openvpn 768 bits.

I have a RT N66U router and i can't use OpenVPN anymore. Since N66U only have 128 bits encryption.

Is this something you can fix in an update? (I running Firmware: 378.55)

Have you considered reading the changelog?

Code:
- FIXED: Automatically generated DH was too weak (512-bit) and preventing clients based on newer OpenSSL releases from connecting. We automatically replace any weak PEM with our 2048-bit one.

This was already fixed in 378.55.
 
Strange, i updated to your version just a few moments ago instead of the original but what i saw was just 128 bits in your version as well (see added image) I might not be a data wiz but can i be this stupid lol...
 

Attachments

  • asus.png
    asus.png
    5.7 KB · Views: 602
Strange, i updated to your version just a few moments ago instead of the original but what i saw was just 128 bits in your version as well (see added image) I might not be a data wiz but can i be this stupid lol...

That's PPTP, not OpenVPN.
 
Ok i see the problem now, im on the VPN settings NOT the OpenVPN settings...
Sometimes im alittle bit... well

Anyway... Gona take a look at that now.. sorry =P
 
By the way another problem i had before all of this was that i could connect to openVPN at school on my laptop.
And if i typed in my router IP 192.168.1.1 i got to the router interface.

But i could not access my home nas/server via \\DISKSTATION the same way i can do from my homecomputer (it just loading)
And if i went to a "whats my ip" i always had the schools IP so i did not surf from via my router, is that strange or normal behaviour?
(If i havent understood VPN) Is not VPN tunnel made so i should be able to surf via my home router and the school only see encrypted trafic to and from my home router?
 
The OpenVPN client must be run with administrator privileges so it can configure the new routes under Windows. Make sure you also tell the server to redirect client's Internet connections through itself.
 
Trying to start it but i get this error:

Thu Sep 03 20:02:19 2015 OpenVPN 2.3.8 x86_64-w64-mingw32 [SSL (OpenSSL)] [LZO] [PKCS11] [IPv6] built on Aug 4 2015
Thu Sep 03 20:02:19 2015 library versions: OpenSSL 1.0.1p 9 Jul 2015, LZO 2.08
Thu Sep 03 20:02:20 2015 UDPv4 link local: [undef]
Thu Sep 03 20:02:20 2015 UDPv4 link remote: [AF_INET]**.2*6.1**.*2:1194

Then it stops.. Any idé whats wrong?
 
Routers error messages (System log) says:

Sep 3 20:03:23 openvpn[1364]: 192.168.1.156:65187 TLS: Initial packet from [AF_INET]192.168.1.156:65187, sid=9c211d70 4248c703
Sep 3 20:04:23 openvpn[1364]: 192.168.1.156:65187 TLS Error: TLS key negotiation failed to occur within 60 seconds (check your network connectivity)
Sep 3 20:04:23 openvpn[1364]: 192.168.1.156:65187 TLS Error: TLS handshake failed
 
Hmm, seems i cant get it to work anyway. i have tested every kind of settings i have found.
No need to test anything more for today..
Btw will you add a "reset" button on the VPN/TLS settings in the future? to rebuild/make a new certificate/DH etc...
 
Hmm, seems i cant get it to work anyway. i have tested every kind of settings i have found.
No need to test anything more for today..
Btw will you add a "reset" button on the VPN/TLS settings in the future? to rebuild/make a new certificate/DH etc...

No need to. Just remove the existing key/certs, and they should automatically be re-generated when you restart the VPN server (if using those automatically generated by the router).
 

Similar threads

Latest threads

Sign Up For SNBForums Daily Digest

Get an update of what's new every day delivered to your mailbox. Sign up here!
Top