I'm stuck, thank you for your ideas
client
dev tun
proto udp
remote domain.com 1194
cipher AES-256-CBC
auth SHA256
resolv-retry infinite
redirect-gateway def1
nobind
comp-lzo yes
persist-tun
user nobody
group nogroup
verb 3
ca abc.pem
cert 123.pem
key 123_npwd.key
I will try with a different client config, but I still thinking that something is missing in the firewall.