FOR TIPS, gUIDES & TUTORIALS

subscribe to our Youtube

GO TO YOUTUBE

14455 questions

17168 answers

28195 comments

0 members

We are migrating to our new platform at https://community.teltonika.lt. Moving forward, you can continue discussions on this new platform. This current platform will be temporarily maintained for reference purposes.
0 votes
157 views 4 comments
by anonymous

Hi,

I have recently started working with a Teltonika RUT950 and am trying to get a OpenVPN server running on it, but it doesn't work :(

I created all the certificates according to Teltonika documentation and configured it according to this documentation:

https://wiki.teltonika-networks.com/view/How_to_generate_TLS_certificates_(Windows)%3F

https://wiki.teltonika-networks.com/view/Connecting_to_the_office_network_remotely_from_your_home_via_VPN_%28OpenVPN%29_using_RUTX

OpenVPN Server configuration


OpenVPN Client configuration


OpenVPN GUI output

I have attached pictures of the configuration for the moderators, those are easier to read.

Does anyone have any idea of what I have misconfigured?

Thanks in advance!

1 Answer

0 votes
by anonymous

Hello,

I would like you to attach a troubleshoot file from the router to your question by editing it. Please, replicate the issue, then access router's WebUI, go to System -> Administration -> Troubleshoot section and download troubleshoot file from there. The logs in the file might provide more insight into the issue.

Attached files are private and visible only to Teltonika Moderators.

Best regards,

Best answer
by anonymous
Hi,

Thank you for the quick response!

I have added the troubleshoot file after replicating the problem.
by anonymous

Both, client and server configuration sides seem correct.

The logs in the troubleshoot file stop at the beginning of connection establishment, thus appear to be incomplete.

Could you perform the following:

  • SSH into the RUT950;
  • Execute command below and leave it running:
    • logread -f | grep openvpn
  • On the client side simply press Reconnect button.
  • Copy the logs generated on the server side, paste them in some text file and send this file in a private message.

Also, could you check, if the connection is not blocked by the firewall on the client side by disabling it and trying to reconnect?

Best regards,

by anonymous
Hi ZygimantasBliu,

Right as I opened the SSH Traffic rule, the connection was established.

Why does SSH have to be enabled for the VPN to work? Because the VPN works on port 1194, that rule was already enabled.

How do I get the VPN working without SSH? Because now it is enabled for everyone on WAN and I don't want random people to connect to the Router. (disabled it again)

Also, is there a way to generate the certificates to never expire?

Thanks for your help.

Mistral
by anonymous

I do not see the correlation between SSH and OVPN connections. Maybe a packet capture could provide more details, but they should not be related.

As for the certificates, I do not think it is possible, and makes little sense from a security stand point. 

However, it is possible to generate certificates with a very long validity, using generation mechanism implemented in the router. Simply login to router's WebUI, navigate to System -> Administration -> Certificates and generate certificates according to your needs. There is a field Days valid, in which you can set certificate validity for up to 10 years.

Best regards,