What's new

388.2 RT-AX86UPRO ovpn client not working ( Error - check configuration! )

  • SNBForums Code of Conduct

    SNBForums is a community for everyone, no matter what their level of experience.

    Please be tolerant and patient of others, especially newcomers. We are all here to share and learn!

    The rules are simple: Be patient, be nice, be helpful or be gone!


Occasional Visitor

after upgrading without reset from 388.1 to 388.2 the ovpn client stopped working and gives the message :
Error - check configuration! .
i do reset with 388.2 and set it up from scratch same message again and finaly... without doing a reset to 388.2 (same settings) I install 388.1 and ovpnclient works fine.
From the changelog:

- UPDATED: openvpn to 2.6.2.  If your client fails to connect
             then your custom settings must contain settings no
             longer supported by OpenVPN 2.6.  Review the System
             Log, then remove unsupported settings that are
             reported in your log.

Perhaps you had Compression enabled?
Compression is set to none
Have you read the system log as I wrote in the Changelog to determine what is causing the issue?
kernel: CFG80211-ERROR) wl_dfs_cac_notify_status :
kernel: In wl_dfs_cac_notify_status chanspec 0xe06a DFS state 2

openvpn: Resetting VPN client 1 to default settings
rc_service: httpd 2273:notify_rc start_vpnrouting1
rc_service: httpd 2273:notify_rc start_vpnclient1
kernel: tun: Universal TUN/TAP device driver, 1.6
ovpn-client1[6778]: Options error: Unrecognized option or missing or extra parameter(s) in config.ovpn:43: keysize (2.6.2)
ovpn-client1[6778]: Use --help for more information.
openvpn: Starting OpenVPN client 1 failed!
openvpn-routing: Clearing routing table for VPN client 1
ovpn-client1[6778]: Options error: Unrecognized option or missing or extra parameter(s) in config.ovpn:43: keysize (2.6.2)
There you go. Remove that option, it`s no longer supported by OpenVPN 2.6, and in fact it hasn`t been doing anything for years since that option was only needed 5+ years ago when people were still using BF-CBC rather than AES-*.

A lot of VPN service providers visibly don't know what the hell they are doing considering they still use that setting in their config files...
thank you very much for your answers.
in the .ovpn file i add the symbol ' # ' before the word ' keysize ' and now works
however, it strikes me that it is possible for the most expensive provider expressvpn to use outdated standards...

Similar threads

Latest threads

Sign Up For SNBForums Daily Digest

Get an update of what's new every day delivered to your mailbox. Sign up here!