Client logs:
user@usersX240 ~/Desktop/EdgeRouter $ sudo openvpn edgerouter.ovpn [sudo] password for user: Fri Jan 13 10:25:25 2017 OpenVPN 2.3.10 x86_64-pc-linux-gnu [SSL (OpenSSL)] [LZO] [EPOLL] [PKCS11] [MH] [IPv6] built on Feb 2 2016 Fri Jan 13 10:25:25 2017 library versions: OpenSSL 1.0.2g 1 Mar 2016, LZO 2.08 Fri Jan 13 10:25:25 2017 WARNING: No server certificate verification method has been enabled. See http://openvpn.net/howto.html#mitm for more info. Fri Jan 13 10:25:25 2017 WARNING: file '/home/user/certs/CLIENT-NOPASS.key' is group or others accessible Fri Jan 13 10:25:25 2017 Socket Buffers: R=[212992->212992] S=[212992->212992] Fri Jan 13 10:25:25 2017 UDPv4 link local: [undef] Fri Jan 13 10:25:25 2017 UDPv4 link remote: [AF_INET]xxx.xxx.xxx.xxx:1194 Fri Jan 13 10:25:25 2017 TLS: Initial packet from [AF_INET]xxx.xxx.xxx.xxx:1194, sid=6107cafb efe8557a Fri Jan 13 10:25:25 2017 VERIFY OK: depth=1, C=AT, ST=A, O=A, OU=A, CN=ROOT, emailAddress=user@test.com Fri Jan 13 10:25:25 2017 VERIFY OK: depth=0, C=AT, ST=A, L=A, O=A, OU=A, CN=SERVER, emailAddress=user@test.com Fri Jan 13 10:25:26 2017 Data Channel Encrypt: Cipher 'AES-256-CBC' initialized with 256 bit key Fri Jan 13 10:25:26 2017 Data Channel Encrypt: Using 256 bit message hash 'SHA256' for HMAC authentication Fri Jan 13 10:25:26 2017 Data Channel Decrypt: Cipher 'AES-256-CBC' initialized with 256 bit key Fri Jan 13 10:25:26 2017 Data Channel Decrypt: Using 256 bit message hash 'SHA256' for HMAC authentication Fri Jan 13 10:25:26 2017 Control Channel: TLSv1, cipher TLSv1/SSLv3 DHE-RSA-AES256-SHA, 2048 bit RSA Fri Jan 13 10:25:26 2017 [SERVER] Peer Connection Initiated with [AF_INET]xxx.xxx.xxx.xxx:1194 Fri Jan 13 10:25:28 2017 SENT CONTROL [SERVER]: 'PUSH_REQUEST' (status=1) Fri Jan 13 10:25:28 2017 PUSH: Received control message: 'PUSH_REPLY,dhcp-option DNS 192.168.1.1,route 192.168.1.0 255.255.255.0,route-gateway 192.168.1.1,redirect-gateway,dhcp-option DNS 208.67.222.222,dhcp-option DNS 208.67.220.220,route-gateway 192.168.100.1,topology subnet,ping 10,ping-restart 60,ifconfig 192.168.100.2 255.255.255.0' Fri Jan 13 10:25:28 2017 OPTIONS IMPORT: timers and/or timeouts modified Fri Jan 13 10:25:28 2017 OPTIONS IMPORT: --ifconfig/up options modified Fri Jan 13 10:25:28 2017 OPTIONS IMPORT: route options modified Fri Jan 13 10:25:28 2017 OPTIONS IMPORT: route-related options modified Fri Jan 13 10:25:28 2017 OPTIONS IMPORT: --ip-win32 and/or --dhcp-option options modified Fri Jan 13 10:25:28 2017 ROUTE_GATEWAY 192.168.30.1/255.255.255.0 IFACE=enp0s25 HWADDR=28:d2:44:64:53:5b Fri Jan 13 10:25:28 2017 TUN/TAP device tun0 opened Fri Jan 13 10:25:28 2017 TUN/TAP TX queue length set to 100 Fri Jan 13 10:25:28 2017 do_ifconfig, tt->ipv6=0, tt->did_ifconfig_ipv6_setup=0 Fri Jan 13 10:25:28 2017 /sbin/ip link set dev tun0 up mtu 1500 Fri Jan 13 10:25:28 2017 /sbin/ip addr add dev tun0 192.168.100.2/24 broadcast 192.168.100.255 Fri Jan 13 10:25:28 2017 /sbin/ip route add xxx.xxx.xxx.xxx/32 via 192.168.30.1 Fri Jan 13 10:25:28 2017 /sbin/ip route del 0.0.0.0/0 Fri Jan 13 10:25:28 2017 /sbin/ip route add 0.0.0.0/0 via 192.168.100.1 Fri Jan 13 10:25:28 2017 /sbin/ip route add 192.168.1.0/24 via 192.168.100.1 Fri Jan 13 10:25:28 2017 Initialization Sequence Completed
routing table:
user@usersX240 ~ $ netstat -nr Kernel IP routing table Destination Gateway Genmask Flags MSS Window irtt Iface 0.0.0.0 192.168.100.1 0.0.0.0 UG 0 0 0 tun0 xxx.xxx.xxx.xxx 192.168.30.1 255.255.255.255 UGH 0 0 0 enp0s25 169.254.0.0 0.0.0.0 255.255.0.0 U 0 0 0 virbr0 192.168.1.0 192.168.100.1 255.255.255.0 UG 0 0 0 tun0 192.168.30.0 0.0.0.0 255.255.255.0 U 0 0 0 enp0s25 192.168.100.0 0.0.0.0 255.255.255.0 U 0 0 0 tun0 192.168.122.0 0.0.0.0 255.255.255.0 U 0 0 0 virbr0