перестал работать VPN на своём сервере
у меня VPS в Германии, на нём поднят OpenVPN
сегодня днём он перестал отдавать Интернет
соединение, как будто бы, есть, но Интернета нет
Это уже РКН или ещё моя криворукость (хотя я ничего не трогал)?
лог с сервера:
79.135.120.97:2600 VERIFY OK: depth=1, CN=domain.ru
79.135.120.97:2600 VERIFY OK: depth=0, CN=nickname
79.135.120.97:2600 peer info: IV_VER=2.5.11
79.135.120.97:2600 peer info: IV_PLAT=linux
79.135.120.97:2600 peer info: IV_PROTO=6
79.135.120.97:2600 peer info: IV_CIPHERS=AES-256-CBC
79.135.120.97:2600 peer info: IV_LZ4=1
79.135.120.97:2600 peer info: IV_LZ4v2=1
79.135.120.97:2600 peer info: IV_LZO=1
79.135.120.97:2600 peer info: IV_COMP_STUB=1
79.135.120.97:2600 peer info: IV_COMP_STUBv2=1
79.135.120.97:2600 peer info: IV_TCPNL=1
79.135.120.97:2600 TLS: move_session: dest=TM_ACTIVE src=TM_INITIAL reinit_src=1
79.135.120.97:2600 TLS: tls_multi_process: initial untrusted session promoted to trusted
79.135.120.97:2600 Control Channel: TLSv1.3, cipher TLSv1.3 TLS_AES_256_GCM_SHA384, peer certificate: 2048 bit RSA, signature: RSA-SHA256
79.135.120.97:2600 [nickname] Peer Connection Initiated with [AF_INET]79.135.120.97:2600
MULTI: new connection by client 'nickname' will cause previous active sessions by this client to be dropped. Remember to use the --duplicate-cn option if you want multiple clients using the e certificate or username to concurrently connect.
MULTI_sva: pool returned IPv4=10.9.8.2, IPv6=(Not enabled)
SENT CONTROL [nickname]: 'PUSH_REPLY,route 192.168.0.0 255.255.255.0,redirect-gateway def1 bypass-dhcp,route-gateway 10.9.8.1,ping 10,ping-restart 120,ifconfig 10.9.8.2 255.255.255.0,peer-id 1,c
ipher AES-256-CBC' (status=1)
nickname/79.135.120.97:2600 MULTI: Learn: 86:a9:86:be:69:95@0 -> nickname/79.135.120.97:2600
nickname/79.135.120.97:2600 Data Channel: cipher 'AES-256-CBC', auth 'SHA1', peer-id: 0
nickname/79.135.120.97:2600 Timers: ping 10, ping-restart 240
nickname/79.135.120.97:2600 Protocol options: explicit-exit-notify 1
nickname/79.135.120.97:2600 [nickname] Inactivity timeout (--ping-restart), restarting
nickname/79.135.120.97:2600 SIGUSR1[soft,ping-restart] received, client-instance restarting
лог с клиента:
UDP WRITE [88] to [AF_INET]5.31.20.197:32209: P_DATA_V2 kid=0 DATA len=87
TUN READ [42]
UDP WRITE [88] to [AF_INET]5.31.20.197:32209: P_DATA_V2 kid=0 DATA len=87
TUN READ [42]
UDP WRITE [88] to [AF_INET]5.31.20.197:32209: P_DATA_V2 kid=0 DATA len=87
event_wait : Interrupted system call (code=4)
TCP/UDP: Closing socket
net_route_v4_del: 192.168.0.0/24 via 10.9.8.1 dev [NULL] table 0 metric -1
sitnl_send: checking for received messages
sitnl_send: rtnl: received 64 bytes
sitnl_send: rtnl: generic error (-1): Operation not permitted
ERROR: Linux route delete command failed
net_route_v4_del: 5.31.20.197/32 via 192.168.1.1 dev [NULL] table 0 metric -1
sitnl_send: checking for received messages
sitnl_send: rtnl: received 64 bytes
sitnl_send: rtnl: generic error (-1): Operation not permitted
ERROR: Linux route delete command failed
net_route_v4_del: 0.0.0.0/1 via 10.9.8.1 dev [NULL] table 0 metric -1
sitnl_send: checking for received messages
sitnl_send: rtnl: received 64 bytes
sitnl_send: rtnl: generic error (-1): Operation not permitted
ERROR: Linux route delete command failed
net_route_v4_del: 128.0.0.0/1 via 10.9.8.1 dev [NULL] table 0 metric -1
sitnl_send: checking for received messages
sitnl_send: rtnl: received 64 bytes
sitnl_send: rtnl: generic error (-1): Operation not permitted
ERROR: Linux route delete command failed
Closing TUN/TAP interface
net_addr_v4_del: 10.9.8.2 dev tap0
sitnl_send: checking for received messages
sitnl_send: rtnl: received 52 bytes
sitnl_send: rtnl: generic error (-1): Operation not permitted
Linux can't del IP from iface tap0
SIGTERM[hard,] received, process exiting