<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Some warnings on OpenVPN client connections]]></title><description><![CDATA[<p dir="auto">Hi all, I am using pfSENSE CE 2.6.0 in which I configured an OpenVPN server to which several clients connect using OpenVPN Connect V3 (Windows).<br />
The server works fine and the clients connect without problems with cipher AES-256-GCM. But there are some warnings in the OpenVPN server log that I would like to know what they are due to.</p>
<pre><code>May 30 15:37:26	openvpn	24642	152.171.135.2:26292 WARNING: 'keysize' is used inconsistently, local='keysize 192', remote='keysize 128'
May 30 15:37:26	openvpn	24642	152.171.135.2:26292 WARNING: 'auth' is used inconsistently, local='auth [null-digest]', remote='auth SHA256'
May 30 15:37:26	openvpn	24642	152.171.135.2:26292 WARNING: 'link-mtu' is used inconsistently, local='link-mtu 1549', remote='link-mtu 1553'
</code></pre>
<p dir="auto">This is the server and client configuration I am using.</p>
<p dir="auto"><strong>server:</strong></p>
<p dir="auto">&lt;openvpn&gt;<br />
&lt;openvpn-server&gt;<br />
&lt;vpnid&gt;1&lt;/vpnid&gt;<br />
&lt;mode&gt;server_tls&lt;/mode&gt;<br />
&lt;protocol&gt;UDP4&lt;/protocol&gt;<br />
&lt;dev_mode&gt;tun&lt;/dev_mode&gt;<br />
&lt;interface&gt;wan&lt;/interface&gt;<br />
&lt;ipaddr&gt;&lt;/ipaddr&gt;<br />
&lt;local_port&gt;1194&lt;/local_port&gt;<br />
&lt;description&gt;&lt;![CDATA[OpenVPN-TSA&rsqb;&rsqb;&gt;&lt;/description&gt;<br />
&lt;custom_options&gt;reneg-sec 0<br />
push "dhcp-option ADAPTER_DOMAIN_SUFFIX domain.local"&lt;/custom_options&gt;<br />
&lt;tls&gt;blablabla&lt;/tls&gt;<br />
&lt;tls_type&gt;crypt&lt;/tls_type&gt;<br />
&lt;tlsauth_keydir&gt;0&lt;/tlsauth_keydir&gt;<br />
&lt;caref&gt;628bd437b8d94&lt;/caref&gt;<br />
&lt;crlref&gt;628bd47295128&lt;/crlref&gt;<br />
&lt;ocspurl&gt;&lt;/ocspurl&gt;<br />
&lt;certref&gt;628bef8b0b14e&lt;/certref&gt;<br />
&lt;dh_length&gt;none&lt;/dh_length&gt;<br />
&lt;ecdh_curve&gt;none&lt;/ecdh_curve&gt;<br />
&lt;cert_depth&gt;1&lt;/cert_depth&gt;<br />
&lt;remote_cert_tls&gt;yes&lt;/remote_cert_tls&gt;<br />
&lt;data_ciphers_fallback&gt;AES-192-GCM&lt;/data_ciphers_fallback&gt;<br />
&lt;digest&gt;SHA256&lt;/digest&gt;<br />
&lt;engine&gt;rdrand&lt;/engine&gt;<br />
&lt;tunnel_network&gt;192.168.21.0/24&lt;/tunnel_network&gt;<br />
&lt;tunnel_networkv6&gt;&lt;/tunnel_networkv6&gt;<br />
&lt;remote_network&gt;&lt;/remote_network&gt;<br />
&lt;remote_networkv6&gt;&lt;/remote_networkv6&gt;<br />
&lt;gwredir&gt;&lt;/gwredir&gt;<br />
&lt;gwredir6&gt;&lt;/gwredir6&gt;<br />
&lt;local_network&gt;10.10.8.0/22,192.168.20.0/27,192.168.119.0/24&lt;/local_network&gt;<br />
&lt;local_networkv6&gt;&lt;/local_networkv6&gt;<br />
&lt;maxclients&gt;50&lt;/maxclients&gt;<br />
&lt;allow_compression&gt;no&lt;/allow_compression&gt;<br />
&lt;compression&gt;&lt;/compression&gt;<br />
&lt;compression_push&gt;&lt;/compression_push&gt;<br />
&lt;passtos&gt;&lt;/passtos&gt;<br />
&lt;client2client&gt;&lt;/client2client&gt;<br />
&lt;dynamic_ip&gt;yes&lt;/dynamic_ip&gt;<br />
&lt;topology&gt;subnet&lt;/topology&gt;<br />
&lt;serverbridge_dhcp&gt;&lt;/serverbridge_dhcp&gt;<br />
&lt;serverbridge_interface&gt;none&lt;/serverbridge_interface&gt;<br />
&lt;serverbridge_routegateway&gt;&lt;/serverbridge_routegateway&gt;<br />
&lt;serverbridge_dhcp_start&gt;&lt;/serverbridge_dhcp_start&gt;<br />
&lt;serverbridge_dhcp_end&gt;&lt;/serverbridge_dhcp_end&gt;<br />
&lt;dns_domain&gt;domain.local&lt;/dns_domain&gt;<br />
&lt;dns_server1&gt;10.10.8.3&lt;/dns_server1&gt;<br />
&lt;dns_server2&gt;10.10.8.2&lt;/dns_server2&gt;<br />
&lt;dns_server3&gt;&lt;/dns_server3&gt;<br />
&lt;dns_server4&gt;&lt;/dns_server4&gt;<br />
&lt;username_as_common_name&gt;&lt;![CDATA[disabled&rsqb;&rsqb;&gt;&lt;/username_as_common_name&gt;<br />
&lt;exit_notify&gt;1&lt;/exit_notify&gt;<br />
&lt;sndrcvbuf&gt;&lt;/sndrcvbuf&gt;<br />
&lt;push_register_dns&gt;yes&lt;/push_register_dns&gt;<br />
&lt;netbios_enable&gt;&lt;/netbios_enable&gt;<br />
&lt;netbios_ntype&gt;0&lt;/netbios_ntype&gt;<br />
&lt;netbios_scope&gt;&lt;/netbios_scope&gt;<br />
&lt;create_gw&gt;v4only&lt;/create_gw&gt;<br />
&lt;verbosity_level&gt;1&lt;/verbosity_level&gt;<br />
&lt;data_ciphers&gt;AES-256-GCM&lt;/data_ciphers&gt;<br />
&lt;ncp_enable&gt;enabled&lt;/ncp_enable&gt;<br />
&lt;ping_method&gt;keepalive&lt;/ping_method&gt;<br />
&lt;keepalive_interval&gt;10&lt;/keepalive_interval&gt;<br />
&lt;keepalive_timeout&gt;60&lt;/keepalive_timeout&gt;<br />
&lt;ping_seconds&gt;10&lt;/ping_seconds&gt;<br />
&lt;ping_push&gt;&lt;/ping_push&gt;<br />
&lt;ping_action&gt;ping_restart&lt;/ping_action&gt;<br />
&lt;ping_action_seconds&gt;60&lt;/ping_action_seconds&gt;<br />
&lt;ping_action_push&gt;&lt;/ping_action_push&gt;<br />
&lt;inactive_seconds&gt;300&lt;/inactive_seconds&gt;<br />
&lt;/openvpn-server&gt;</p>
<p dir="auto"><strong>client:</strong></p>
<p dir="auto">dev tun<br />
persist-tun<br />
persist-key<br />
data-ciphers AES-256-GCM:AES-192-GCM<br />
data-ciphers-fallback AES-192-GCM<br />
auth SHA256<br />
tls-client<br />
client<br />
resolv-retry infinite</p>
<p dir="auto">lport 0<br />
verify-x509-name "www.somedomain.com" name<br />
remote-cert-tls server<br />
explicit-exit-notify<br />
key-direction 1<br />
&lt;connection&gt;<br />
remote openvpn1.somedomain.com 1194 udp<br />
&lt;/connection&gt;<br />
&lt;connection&gt;<br />
remote openvpn2.somedomain.com 1194 udp<br />
&lt;/connection&gt;</p>
<p dir="auto">&lt;ca&gt;<br />
-----BEGIN CERTIFICATE-----<br />
-----END CERTIFICATE-----<br />
&lt;/ca&gt;<br />
&lt;cert&gt;<br />
-----BEGIN CERTIFICATE-----<br />
-----END CERTIFICATE-----<br />
&lt;/cert&gt;<br />
&lt;key&gt;<br />
-----BEGIN PRIVATE KEY-----<br />
-----END PRIVATE KEY-----<br />
&lt;/key&gt;<br />
&lt;tls-crypt&gt;</p>
<h1><a class="anchor-offset"></a></h1>
<h1><a class="anchor-offset" name="2048-bit-openvpn-static-key"></a>2048 bit OpenVPN static key</h1>
<h1><a class="anchor-offset"></a></h1>
<p dir="auto">-----BEGIN OpenVPN Static key V1-----<br />
-----END OpenVPN Static key V1-----<br />
&lt;/tls-crypt&gt;</p>
<p dir="auto">Any hints as to what these warnings are due to would be more than appreciated.</p>
<p dir="auto">Thanks<br />
Gabriel</p>
]]></description><link>https://forum.netgate.com/topic/172532/some-warnings-on-openvpn-client-connections</link><generator>RSS for Node</generator><lastBuildDate>Fri, 12 Jun 2026 02:40:48 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/172532.rss" rel="self" type="application/rss+xml"/><pubDate>Mon, 30 May 2022 19:15:31 GMT</pubDate><ttl>60</ttl></channel></rss>