NETGEAR is aware of a growing number of phone and online scams. To learn how to stay safe click here.
Forum Discussion
ThePie
Feb 20, 2016Aspirant
R8000 Open VPN Drops Internet Upon Connecting
I have a R8000 router and sometimes when I go to connect using the Open VPN connection it will show as connected but I won't have any internet access anymore. My connection log is below. The XXX is w...
- Mar 02, 2016
Actually I found a way around the issue. If you change the protocol from UDP to TCP everything works fine. Not sure what the issue is with UDP though.
ThePie
Feb 20, 2016Aspirant
Second Half
Fri Feb 19 22:00:12 2016 us=23665 remote_cert_ku[i] = 0
Fri Feb 19 22:00:12 2016 us=23665 remote_cert_ku[i] = 0
Fri Feb 19 22:00:12 2016 us=23665 remote_cert_ku[i] = 0
Fri Feb 19 22:00:12 2016 us=23665 remote_cert_ku[i] = 0
Fri Feb 19 22:00:12 2016 us=23665 remote_cert_ku[i] = 0
Fri Feb 19 22:00:12 2016 us=23665 remote_cert_ku[i] = 0
Fri Feb 19 22:00:12 2016 us=23665 remote_cert_ku[i] = 0
Fri Feb 19 22:00:12 2016 us=23665 remote_cert_ku[i] = 0
Fri Feb 19 22:00:12 2016 us=23665 remote_cert_eku = '[UNDEF]'
Fri Feb 19 22:00:12 2016 us=24165 ssl_flags = 0
Fri Feb 19 22:00:12 2016 us=24165 tls_timeout = 2
Fri Feb 19 22:00:12 2016 us=24165 renegotiate_bytes = 0
Fri Feb 19 22:00:12 2016 us=24165 renegotiate_packets = 0
Fri Feb 19 22:00:12 2016 us=24165 renegotiate_seconds = 3600
Fri Feb 19 22:00:12 2016 us=24165 handshake_window = 60
Fri Feb 19 22:00:12 2016 us=24165 transition_window = 3600
Fri Feb 19 22:00:12 2016 us=24165 single_session = DISABLED
Fri Feb 19 22:00:12 2016 us=24165 push_peer_info = DISABLED
Fri Feb 19 22:00:12 2016 us=24165 tls_exit = DISABLED
Fri Feb 19 22:00:12 2016 us=24165 tls_auth_file = '[UNDEF]'
Fri Feb 19 22:00:12 2016 us=24165 pkcs11_protected_authentication = DISABLED
Fri Feb 19 22:00:12 2016 us=24165 pkcs11_protected_authentication = DISABLED
Fri Feb 19 22:00:12 2016 us=24165 pkcs11_private_mode = 00000000
Fri Feb 19 22:00:12 2016 us=24165 pkcs11_private_mode = 00000000
Fri Feb 19 22:00:12 2016 us=24665 pkcs11_cert_private = DISABLED
Fri Feb 19 22:00:12 2016 us=24665 pkcs11_cert_private = DISABLED
Fri Feb 19 22:00:12 2016 us=24665 pkcs11_pin_cache_period = -1
Fri Feb 19 22:00:12 2016 us=24665 pkcs11_id = '[UNDEF]'
Fri Feb 19 22:00:12 2016 us=24665 pkcs11_id_management = DISABLED
Fri Feb 19 22:00:12 2016 us=24665 server_network = 0.0.0.0
Fri Feb 19 22:00:12 2016 us=24665 server_netmask = 0.0.0.0
Fri Feb 19 22:00:12 2016 us=26665 server_network_ipv6 = ::
Fri Feb 19 22:00:12 2016 us=26665 server_netbits_ipv6 = 0
Fri Feb 19 22:00:12 2016 us=27165 server_bridge_ip = 0.0.0.0
Fri Feb 19 22:00:12 2016 us=27165 server_bridge_netmask = 0.0.0.0
Fri Feb 19 22:00:12 2016 us=27165 server_bridge_pool_start = 0.0.0.0
Fri Feb 19 22:00:12 2016 us=27165 server_bridge_pool_end = 0.0.0.0
Fri Feb 19 22:00:12 2016 us=27165 ifconfig_pool_defined = DISABLED
Fri Feb 19 22:00:12 2016 us=27165 ifconfig_pool_start = 0.0.0.0
Fri Feb 19 22:00:12 2016 us=27165 ifconfig_pool_end = 0.0.0.0
Fri Feb 19 22:00:12 2016 us=27165 ifconfig_pool_netmask = 0.0.0.0
Fri Feb 19 22:00:12 2016 us=27165 ifconfig_pool_persist_filename = '[UNDEF]'
Fri Feb 19 22:00:12 2016 us=27165 ifconfig_pool_persist_refresh_freq = 600
Fri Feb 19 22:00:12 2016 us=27165 ifconfig_ipv6_pool_defined = DISABLED
Fri Feb 19 22:00:12 2016 us=27165 ifconfig_ipv6_pool_base = ::
Fri Feb 19 22:00:12 2016 us=27165 ifconfig_ipv6_pool_netbits = 0
Fri Feb 19 22:00:12 2016 us=27165 n_bcast_buf = 256
Fri Feb 19 22:00:12 2016 us=27165 tcp_queue_limit = 64
Fri Feb 19 22:00:12 2016 us=27165 real_hash_size = 256
Fri Feb 19 22:00:12 2016 us=27165 virtual_hash_size = 256
Fri Feb 19 22:00:12 2016 us=27165 client_connect_script = '[UNDEF]'
Fri Feb 19 22:00:12 2016 us=27165 learn_address_script = '[UNDEF]'
Fri Feb 19 22:00:12 2016 us=27165 client_disconnect_script = '[UNDEF]'
Fri Feb 19 22:00:12 2016 us=27165 client_config_dir = '[UNDEF]'
Fri Feb 19 22:00:12 2016 us=27165 ccd_exclusive = DISABLED
Fri Feb 19 22:00:12 2016 us=27165 tmp_dir = 'C:\Users\XXX\AppData\Local\Temp\'
Fri Feb 19 22:00:12 2016 us=27165 push_ifconfig_defined = DISABLED
Fri Feb 19 22:00:12 2016 us=27165 push_ifconfig_local = 0.0.0.0
Fri Feb 19 22:00:12 2016 us=27165 push_ifconfig_remote_netmask = 0.0.0.0
Fri Feb 19 22:00:12 2016 us=27165 push_ifconfig_ipv6_defined = DISABLED
Fri Feb 19 22:00:12 2016 us=27165 push_ifconfig_ipv6_local = ::/0
Fri Feb 19 22:00:12 2016 us=27165 push_ifconfig_ipv6_remote = ::
Fri Feb 19 22:00:12 2016 us=27165 enable_c2c = DISABLED
Fri Feb 19 22:00:12 2016 us=27165 duplicate_cn = DISABLED
Fri Feb 19 22:00:12 2016 us=27165 cf_max = 0
Fri Feb 19 22:00:12 2016 us=27165 cf_per = 0
Fri Feb 19 22:00:12 2016 us=27165 max_clients = 1024
Fri Feb 19 22:00:12 2016 us=27165 max_routes_per_client = 256
Fri Feb 19 22:00:12 2016 us=27165 auth_user_pass_verify_script = '[UNDEF]'
Fri Feb 19 22:00:12 2016 us=27666 auth_user_pass_verify_script_via_file = DISABLED
Fri Feb 19 22:00:12 2016 us=27666 client = ENABLED
Fri Feb 19 22:00:12 2016 us=27666 pull = ENABLED
Fri Feb 19 22:00:12 2016 us=27666 auth_user_pass_file = '[UNDEF]'
Fri Feb 19 22:00:12 2016 us=27666 show_net_up = DISABLED
Fri Feb 19 22:00:12 2016 us=27666 route_method = 0
Fri Feb 19 22:00:12 2016 us=27666 block_outside_dns = DISABLED
Fri Feb 19 22:00:12 2016 us=27666 ip_win32_defined = DISABLED
Fri Feb 19 22:00:12 2016 us=27666 ip_win32_type = 3
Fri Feb 19 22:00:12 2016 us=27666 dhcp_masq_offset = 0
Fri Feb 19 22:00:12 2016 us=27666 dhcp_lease_time = 31536000
Fri Feb 19 22:00:12 2016 us=27666 tap_sleep = 0
Fri Feb 19 22:00:12 2016 us=27666 dhcp_options = DISABLED
Fri Feb 19 22:00:12 2016 us=27666 dhcp_renew = DISABLED
Fri Feb 19 22:00:12 2016 us=27666 dhcp_pre_release = DISABLED
Fri Feb 19 22:00:12 2016 us=27666 dhcp_release = DISABLED
Fri Feb 19 22:00:12 2016 us=27666 domain = '[UNDEF]'
Fri Feb 19 22:00:12 2016 us=27666 netbios_scope = '[UNDEF]'
Fri Feb 19 22:00:12 2016 us=27666 netbios_node_type = 0
Fri Feb 19 22:00:12 2016 us=27666 disable_nbt = DISABLED
Fri Feb 19 22:00:12 2016 us=27666 OpenVPN 2.3.10 x86_64-w64-mingw32 [SSL (OpenSSL)] [LZO] [PKCS11] [IPv6] built on Feb 1 2016
Fri Feb 19 22:00:12 2016 us=27666 Windows version 6.2 (Windows 8 or greater)
Fri Feb 19 22:00:12 2016 us=27666 library versions: OpenSSL 1.0.1r 28 Jan 2016, LZO 2.09
Enter Management Password:
Fri Feb 19 22:00:12 2016 us=28166 MANAGEMENT: TCP Socket listening on [AF_INET]127.0.0.1:25340
Fri Feb 19 22:00:12 2016 us=28166 Need hold release from management interface, waiting...
Fri Feb 19 22:00:12 2016 us=506318 MANAGEMENT: Client connected from [AF_INET]127.0.0.1:25340
Fri Feb 19 22:00:12 2016 us=608663 MANAGEMENT: CMD 'state on'
Fri Feb 19 22:00:12 2016 us=609673 MANAGEMENT: CMD 'log all on'
Fri Feb 19 22:00:12 2016 us=773750 MANAGEMENT: CMD 'hold off'
Fri Feb 19 22:00:12 2016 us=776252 MANAGEMENT: CMD 'hold release'
Fri Feb 19 22:00:12 2016 us=777753 WARNING: No server certificate verification method has been enabled. See http://openvpn.net/howto.html#mitm for more info.
Fri Feb 19 22:00:12 2016 us=922944 LZO compression initialized
Fri Feb 19 22:00:12 2016 us=923944 Control Channel MTU parms [ L:1590 D:1212 EF:38 EB:0 ET:0 EL:3 ]
Fri Feb 19 22:00:12 2016 us=923944 Socket Buffers: R=[65536->65536] S=[65536->65536]
Fri Feb 19 22:00:12 2016 us=923944 MANAGEMENT: >STATE:1455937212,RESOLVE,,,
Fri Feb 19 22:00:12 2016 us=938808 Data Channel MTU parms [ L:1590 D:1450 EF:58 EB:143 ET:32 EL:3 AF:3/1 ]
Fri Feb 19 22:00:12 2016 us=938808 Local Options String: 'V4,dev-type tap,link-mtu 1590,tun-mtu 1532,proto UDPv4,comp-lzo,cipher AES-128-CBC,auth SHA1,keysize 128,key-method 2,tls-client'
Fri Feb 19 22:00:12 2016 us=938808 Expected Remote Options String: 'V4,dev-type tap,link-mtu 1590,tun-mtu 1532,proto UDPv4,comp-lzo,cipher AES-128-CBC,auth SHA1,keysize 128,key-method 2,tls-server'
Fri Feb 19 22:00:12 2016 us=939309 Local Options hash (VER=V4): 'b498be7c'
Fri Feb 19 22:00:12 2016 us=939309 Expected Remote Options hash (VER=V4): '26e19fc0'
Fri Feb 19 22:00:12 2016 us=939309 UDPv4 link local: [undef]
Fri Feb 19 22:00:12 2016 us=939309 UDPv4 link remote: [AF_INET]XXXExternalIPXXX:12970
Fri Feb 19 22:00:12 2016 us=939309 MANAGEMENT: >STATE:1455937212,WAIT,,,
Fri Feb 19 22:00:12 2016 us=959482 MANAGEMENT: >STATE:1455937212,AUTH,,,
Fri Feb 19 22:00:12 2016 us=959983 TLS: Initial packet from [AF_INET]XXX:12970, sid=9a5547fb ce87dc28
Fri Feb 19 22:00:13 2016 us=86658 VERIFY OK: depth=1, C=TW, ST=TW, L=Taipei, O=netgear, OU=netgear, CN=netgear, emailAddress=mail@netgear.com
Fri Feb 19 22:00:13 2016 us=87448 VERIFY OK: depth=0, C=TW, ST=TW, O=netgear, OU=netgear, CN=netgear, emailAddress=mail@netgear.com
Fri Feb 19 22:00:13 2016 us=184190 Data Channel Encrypt: Cipher 'AES-128-CBC' initialized with 128 bit key
Fri Feb 19 22:00:13 2016 us=184190 Data Channel Encrypt: Using 160 bit message hash 'SHA1' for HMAC authentication
Fri Feb 19 22:00:13 2016 us=184190 Data Channel Decrypt: Cipher 'AES-128-CBC' initialized with 128 bit key
Fri Feb 19 22:00:13 2016 us=184190 Data Channel Decrypt: Using 160 bit message hash 'SHA1' for HMAC authentication
Fri Feb 19 22:00:13 2016 us=184690 Control Channel: TLSv1, cipher TLSv1/SSLv3 DHE-RSA-AES256-SHA, 1024 bit RSA
Fri Feb 19 22:00:13 2016 us=184690 [netgear] Peer Connection Initiated with [AF_INET]XXX:12970
Fri Feb 19 22:00:14 2016 us=947107 MANAGEMENT: >STATE:1455937214,GET_CONFIG,,,
Fri Feb 19 22:00:15 2016 us=947967 SENT CONTROL [netgear]: 'PUSH_REQUEST' (status=1)
Fri Feb 19 22:00:15 2016 us=967487 PUSH: Received control message: 'PUSH_REPLY,route 192.168.1.1 255.255.255.0,route-delay 5,redirect-gateway def1,route-gateway dhcp,ping 10,ping-restart 120'
Fri Feb 19 22:00:15 2016 us=967487 OPTIONS IMPORT: timers and/or timeouts modified
Fri Feb 19 22:00:15 2016 us=967487 OPTIONS IMPORT: route options modified
Fri Feb 19 22:00:15 2016 us=967487 OPTIONS IMPORT: route-related options modified
Fri Feb 19 22:00:15 2016 us=970489 ROUTE_GATEWAY 192.168.1.1/255.255.255.0 I=22 HWADDR=fc:f8:ae:ad:04:ee
Fri Feb 19 22:00:15 2016 us=982506 OpenVPN ROUTE: OpenVPN needs a gateway parameter for a --route option and no default was specified by either --route-gateway or --ifconfig options
Fri Feb 19 22:00:15 2016 us=982506 OpenVPN ROUTE: failed to parse/resolve route for host/network: 192.168.1.1
Fri Feb 19 22:00:15 2016 us=984007 open_tun, tt->ipv6=0
Fri Feb 19 22:00:15 2016 us=985008 TAP-WIN32 device [NETGEAR-VPN] opened: \\.\Global\{B7A4985E-9669-4AFD-BCC2-BA2D9999BA5F}.tap
Fri Feb 19 22:00:15 2016 us=985008 TAP-Windows Driver Version 9.21
Fri Feb 19 22:00:15 2016 us=985008 TAP-Windows MTU=1500
Fri Feb 19 22:00:15 2016 us=985508 Successful ARP Flush on interface [25] {B7A4985E-9669-4AFD-BCC2-BA2D9999BA5F}
Fri Feb 19 22:00:16 2016 us=265760 Extracted DHCP router address: 192.168.1.1
Fri Feb 19 22:00:20 2016 us=104442 TEST ROUTES: 1/1 succeeded len=0 ret=1 a=1 u/d=up
Fri Feb 19 22:00:20 2016 us=104442 C:\WINDOWS\system32\route.exe ADD XXX MASK 255.255.255.255 192.168.1.1
Fri Feb 19 22:00:20 2016 us=106929 ROUTE: CreateIpForwardEntry succeeded with dwForwardMetric1=20 and dwForwardType=4
Fri Feb 19 22:00:20 2016 us=106929 Route addition via IPAPI succeeded [adaptive]
Fri Feb 19 22:00:20 2016 us=106929 C:\WINDOWS\system32\route.exe ADD 0.0.0.0 MASK 128.0.0.0 192.168.1.1
Fri Feb 19 22:00:20 2016 us=110431 ROUTE: CreateIpForwardEntry succeeded with dwForwardMetric1=20 and dwForwardType=4
Fri Feb 19 22:00:20 2016 us=110932 Route addition via IPAPI succeeded [adaptive]
Fri Feb 19 22:00:20 2016 us=110932 C:\WINDOWS\system32\route.exe ADD 128.0.0.0 MASK 128.0.0.0 192.168.1.1
Fri Feb 19 22:00:20 2016 us=114434 ROUTE: CreateIpForwardEntry succeeded with dwForwardMetric1=20 and dwForwardType=4
Fri Feb 19 22:00:20 2016 us=114434 Route addition via IPAPI succeeded [adaptive]
Fri Feb 19 22:00:20 2016 us=114434 Initialization Sequence Completed
Fri Feb 19 22:00:20 2016 us=114434 MANAGEMENT: >STATE:1455937220,CONNECTED,SUCCESS,,XXXJamesGL
Mar 02, 2016NETGEAR Employee Retired
Hi ThePie,
1. Is the main adapter still enabled and connected with valid IP address?
2. Make sure the main adapter doesn’t conflict with the OpenVPN router’s network. Ex if R8000 is 192.168.1.1, the outside LAN network should be on another subnet.
- ThePieMar 02, 2016Aspirant
Actually I found a way around the issue. If you change the protocol from UDP to TCP everything works fine. Not sure what the issue is with UDP though.