Thanks @Shaamaan for your answer. I successfully replaced the default SHA1 certificate with an SHA-256 coded own certificate.
I followed this guide: https://community.openvpn.net/openvpn/wiki/EasyRSA3-OpenVPN-Howto#PKIprocedure:ProducingyourcompletePKIontheCAmachine (without easytls)
For...
@Shaamaan,
I'm on Ubuntu 22.04 (client) and I'm using RT-AX55 with factory default firmware (3.0.0.4.386.45934).
The behavior is similar to yours. I'm currently using factory default (weak) SHA1-based certificates with option "Internet and local network" on and I can't reach web pages exept...