NETGEAR is aware of a growing number of phone and online scams. To learn how to stay safe click here.

Forum Discussion

derjuden's avatar
derjuden
Initiate
Mar 15, 2021

OpenVPN TLS key negotation error

Hello I just bought a client a new R7000 router and setup openVPN.  I have a static IP and I setup dynDNS since I was having problems connecting.   Both ways give me the same error from a windows machine running openVPN client 2.5.1 and the previous version I had on the machine 2.4.8.  2.5.1 is the latest as of this posting.  Firmware on the router is V1.0.9.88_10.2.88 which it says is the latest via its auto updater. 

 Here are the logs https://drive.google.com/file/d/1FE_97j_aygop0gmVi4AexrWAC9o2gpkU/view?usp=sharing  with verbose 7 so you get more logging.  I would have just uploaded them .txt is not a valid file extension for there portal and there 20K character limit is a lie its much lower. From what I can see the connection between the router and my client works until the TLS handshake but I can't see it since the logs only give a bit of output of the packets.  then it times out and tries again. 

I know its not my client side because i can connect to other clients using the exact same router model just fine.  I've setup these routers before and there dead simple.  Netgear support is clueless when it comes to VPN.  They told me to put an IP into a DMZ ::facepalm:: 

 

I have a feeling theres just something wrong with this router and I should get a another one from amazon. 

I will be contacting the ISP just in case there is something funky with them but I really doubt Wiline that gives me a /29 IP range is blocking any ports. 

 

 

1 Reply

  • Okay for anyone reading this I have resolved the problem but now I'd like to know why this setting fixed it.  So one thing about this setup that is not factory default except for turning on the VPN is my client got SIP phones from Ringcentral.  They made some changes to the WAN setup tab.  It appears they set "NAT Filtering" to "secured" from open.  I'm not 100% sure what the default is supposed to be.  Anyways I changed that and then I got a error about not having a route gateway.  Well turns out my problem was that when i upgrade my openVPN client it reset the name of the TAP interfaces to the default and netgears configs are built using "NETGEAR-VPN"  changed that and it works.