[Support] Linuxserver.io - OpenVPN AS


Recommended Posts


[s6-init] making user provided files available at /var/run/s6/etc...exited 0.
[s6-init] ensuring user provided files have correct perms...exited 0.
[fix-attrs.d] applying ownership & permissions fixes...
[fix-attrs.d] done.
[cont-init.d] executing container initialization scripts...
[cont-init.d] 10-adduser: executing...

-------------------------------------
_ _ _
| |___| (_) ___
| / __| | |/ _ \
| \__ \ | | (_) |
|_|___/ |_|\___/
|_|

Brought to you by linuxserver.io
We gratefully accept donations at:
https://www.linuxserver.io/donations/
-------------------------------------
GID/UID
-------------------------------------
User uid: 99
User gid: 100
-------------------------------------

[cont-init.d] 10-adduser: exited 0.
[cont-init.d] 20-time: executing...

Current default time zone: 'America/New_York'
Local time is now: Sun May 7 15:29:34 EDT 2017.
Universal Time is now: Sun May 7 19:29:34 UTC 2017.

[cont-init.d] 20-time: exited 0.
[cont-init.d] 30-config: executing...
[cont-init.d] 30-config: exited 0.
[cont-init.d] 40-openvpn-init: executing...
[cont-init.d] 40-openvpn-init: exited 0.
[cont-init.d] 50-interface: executing...
MOD Default {} {}
MOD Default {} {}
MOD Default {} {}
MOD Default {} {}
[cont-init.d] 50-interface: exited 0.
[cont-init.d] done.
[services.d] starting services
[services.d] done.

Link to comment
On 5/2/2017 at 11:08 PM, huntjules said:

Hello. My question is around having OpenVPN retain/save user credentials and passwords if upgraded or re-image the config folder please? As every time I upgrade the OpenVPN docker, I need to SSH into tower and re-type in all the user credentials as OpenVPN doesn't retain the info - Any guidance appreciated.

 

with help of @strike I fixed my issue, and here are the instructions in case others need visual guidance also. 

OpenVPN user instructions.pdf

Link to comment
27 minutes ago, Ezro said:

Would someone be able to help me set this container up using a Windscribe .opvn file?

Can you describe what you want to accomplish? Normally this container is used to establish a VPN between two machines that you control, not from unraid to an anonymous endpoint. Unraid doesn't have any intrusion protection, so connecting it directly to a foreign VPN is a very bad idea.

Link to comment
Just now, jonathanm said:

Can you describe what you want to accomplish? Normally this container is used to establish a VPN between two machines that you control, not from unraid to an anonymous endpoint. Unraid doesn't have any intrusion protection, so connecting it directly to a foreign VPN is a very bad idea.

 

My endgoal is to have my unRAID host a VPN internally. Then I would get transmission docker container and point it to the OpenVPN.

 

With those two set up, I'd want to use my Windows 7 VM to point CouchPotato to the unRAID's transmission container.

Link to comment
3 minutes ago, Ezro said:

Then I would get transmission docker container and point it to the OpenVPN.

There are several torrent dockers with VPN securely baked in, so no exposing the unraid host to the VPN.

 

Now, in my brief look at the windscribe site, it doesn't look to me like they support port forwarding through the VPN, so torrent performance is going to be poor to unusable, depending on the tracker. I could be wrong, but in my experience, very few VPN providers have port forwarding. PIA does, but only through certain endpoints.

Link to comment
19 minutes ago, jonathanm said:

There are several torrent dockers with VPN securely baked in, so no exposing the unraid host to the VPN.

 

Now, in my brief look at the windscribe site, it doesn't look to me like they support port forwarding through the VPN, so torrent performance is going to be poor to unusable, depending on the tracker. I could be wrong, but in my experience, very few VPN providers have port forwarding. PIA does, but only through certain endpoints.

 

What do you think I should do in order to achieve my endgoal?

Link to comment

Trying to get this OpenVPN-as docker running.   The docker runs, but when I loggin and try to Start the Service, I got this error :

 

Error:
process started and then immediately exited: ['Tue May 16 23:41:23 2017 ERROR: Cannot open TUN/TAP dev /dev/net/tun: No such file or directory (errno=2)']
service failed to start or returned error status
process started and then immediately exited: ['Tue May 16 23:41:23 2017 ERROR: Cannot open TUN/TAP dev /dev/net/tun: No such file or directory (errno=2)']
service failed to start or returned error status
process started and then immediately exited: ['Tue May 16 23:41:24 2017 ERROR: Cannot open TUN/TAP dev /dev/net/tun: No such file or directory (errno=2)']
service failed to start or returned error status
process started and then immediately exited: ['Tue May 16 23:41:24 2017 ERROR: Cannot open TUN/TAP dev /dev/net/tun: No such file or directory (errno=2)']
service failed to start or returned error status
process started and then immediately exited: ['Tue May 16 23:41:24 2017 ERROR: Cannot open TUN/TAP dev /dev/net/tun: No such file or directory (errno=2)']
service failed to start or returned error status
process started and then immediately exited: ['Tue May 16 23:41:24 2017 ERROR: Cannot open TUN/TAP dev /dev/net/tun: No such file or directory (errno=2)']
service failed to start or returned error status
process started and then immediately exited: ['Tue May 16 23:41:24 2017 ERROR: Cannot open TUN/TAP dev /dev/net/tun: No such file or directory (errno=2)']
service failed to start or returned error status
process started and then immediately exited: ['Tue May 16 23:41:24 2017 ERROR: Cannot open TUN/TAP dev /dev/net/tun: No such file or directory (errno=2)']
service failed to start or returned error status
process started and then immediately exited: ['Tue May 16 23:41:23 2017 ERROR: Cannot open TUN/TAP dev /dev/net/tun: No such file or directory (errno=2)']
service failed to start or returned error status
process started and then immediately exited: ['Tue May 16 23:41:23 2017 ERROR: Cannot open TUN/TAP dev /dev/net/tun: No such file or directory (errno=2)']
service failed to start or returned error status
process started and then immediately exited: ['Tue May 16 23:41:23 2017 ERROR: Cannot open TUN/TAP dev /dev/net/tun: No such file or directory (errno=2)']
service failed to start or returned error status
process started and then immediately exited: ['Tue May 16 23:41:23 2017 ERROR: Cannot open TUN/TAP dev /dev/net/tun: No such file or directory (errno=2)']
service failed to start or returned error status
process started and then immediately exited: ['Tue May 16 23:41:24 2017 ERROR: Cannot open TUN/TAP dev /dev/net/tun: No such file or directory (errno=2)']
service failed to start or returned error status
process started and then immediately exited: ['Tue May 16 23:41:24 2017 ERROR: Cannot open TUN/TAP dev /dev/net/tun: No such file or directory (errno=2)']
service failed to start or returned error status
process started and then immediately exited: ['Tue May 16 23:41:24 2017 ERROR: Cannot open TUN/TAP dev /dev/net/tun: No such file or directory (errno=2)']
service failed to start or returned error status
process started and then immediately exited: ['Tue May 16 23:41:24 2017 ERROR: Cannot open TUN/TAP dev /dev/net/tun: No such file or directory (errno=2)']
service failed to start or returned error status

 

I'm running Mode: Host,  Priviledged. 

 

Any help would be appreciate!   BTW, I can run DelugeVPN docker without issue;  I suppose it use the same TUN/TAP device...   (tried restarting the the OpenVPN docker after I stopped the DelugeVPN, no changes.).   I also removed, delete image and delete the appdata folder, then reinstall, same result.  

 

I must be missing something!

 

Running on 6.3.3.

Link to comment
3 hours ago, CHBMB said:

@Pducharme Post your docker run command and are you using bonding of ethernet interfaces or anything else other than eth0?

 

Run: 

root@localhost:# /usr/local/emhttp/plugins/dynamix.docker.manager/scripts/docker run -d --name="openvpn-as" --net="host" --privileged="true" -e TZ="America/New_York" -e HOST_OS="unRAID" -e "TCP_PORT_943"="943" -e "TCP_PORT_9443"="9443" -e "UDP_PORT_1194"="1194" -e "PGID"="100" -e "PUID"="99" -v "/mnt/user/appdata/openvpn-as":"/config":rw linuxserver/openvpn-as
224dd408ca99b04dcd5cbac5e7c252305e62921e8aaf535f01c7c5a97352f859

The command finished successfully!

Bounding : No

Bridging : Yes

Member :  eth0

(why I have a bridge, is this normal/useful to be in a bridge if only 1 member ??)

Link to comment
  • 2 weeks later...

Is anyone running this with the "Allow Auto-Login" unchecked? I tried doing that and re-downloading the MSI to my windows machine,uninstalled old client and installed new one. When I goto connect I get prompted for my password (which is what I want) but it never connects, saying it cannot establish a connection. I re-added the check to "Allow Auto-Login", re-did the install process and it works fine.

I tried several times before I realized the problem was trying to run it without "Allow Auto-Login" checked.

 

 

Thanks,

Scott

Link to comment
16 hours ago, scottw said:

Is anyone running this with the "Allow Auto-Login" unchecked? I tried doing that and re-downloading the MSI to my windows machine,uninstalled old client and installed new one. When I goto connect I get prompted for my password (which is what I want) but it never connects, saying it cannot establish a connection. I re-added the check to "Allow Auto-Login", re-did the install process and it works fine.

I tried several times before I realized the problem was trying to run it without "Allow Auto-Login" checked.

 

 

Thanks,

Scott

Hi @scottw I find for me the windows client doent work well. Download the .ovpn file (Yourself (user-locked profile) Then download from here https://openvpn.net/index.php/open-source/downloads.html   and use that software with the .ovpn file. Works great.

Link to comment

Ran into an issue with user credentials being lost. Did some searching and found this in the readme (missed it at first)-

Quote

For user accounts to be persistent, switch the "Authentication" in the webui from "PAM" to "Local" and then set up the user accounts with their passwords.

 

It looks like that will fix my problem with user accounts surviving docker updates but what about the admin account? Will this also preserve admin password or is there a better way?

 

Edit: Switching authentication to local doesn't seem to work. Every time I tried to login it would get denied.

local auth failed: no stored password digest found in authcred attributes: auth/authlocal:35,web/http:1609,web/http:750,web/server:126,web/server:133,xml/authrpc:110,xml/authrpc:164,internet/defer:102,xml/authsess:50,sagent/saccess:86,xml/authrpc:244,xml/authsess:50,xml/authsess:103,auth/authdelegate:308,util/delegate:26,auth/authdelegate:237,util/defer:224,util/defer:246,internet/defer:190,internet/defer:181,internet/defer:323,util/defer:246,internet/defer:190,internet/defer:181,internet/defer:323,util/defer:245,internet/defer:102,auth/authdelegate:61,auth/authdelegate:240,util/delegate:26,auth/authlocal:35,util/error:61,util/error:44

 

Edited by wgstarks
Link to comment
16 hours ago, gridrunner said:

Hi @scottw I find for me the windows client doent work well. Download the .ovpn file (Yourself (user-locked profile) Then download from here https://openvpn.net/index.php/open-source/downloads.html   and use that software with the .ovpn file. Works great.

@gridrunner, thanks I will give that a shot. I would prefer to enter the password each time for security reasons. Using the ovpn on my iPhone prompts for password but I never thought of using that on Windows. I thought I had to use the pre-made msi.

 

Thanks,

Scott

Link to comment
Ran into an issue with user credentials being lost. Did some searching and found this in the readme (missed it at first)-
For user accounts to be persistent, switch the "Authentication" in the webui from "PAM" to "Local" and then set up the user accounts with their passwords.
 
It looks like that will fix my problem with user accounts surviving docker updates but what about the admin account? Will this also preserve admin password or is there a better way?
 
Edit: Switching authentication to local doesn't seem to work. Every time I tried to login it would get denied.
local auth failed: no stored password digest found in authcred attributes: auth/authlocal:35,web/http:1609,web/http:750,web/server:126,web/server:133,xml/authrpc:110,xml/authrpc:164,internet/defer:102,xml/authsess:50,sagent/saccess:86,xml/authrpc:244,xml/authsess:50,xml/authsess:103,auth/authdelegate:308,util/delegate:26,auth/authdelegate:237,util/defer:224,util/defer:246,internet/defer:190,internet/defer:181,internet/defer:323,util/defer:246,internet/defer:190,internet/defer:181,internet/defer:323,util/defer:245,internet/defer:102,auth/authdelegate:61,auth/authdelegate:240,util/delegate:26,auth/authlocal:35,util/error:61,util/error:44

 


After switching, did you recreate the user accounts and the ovpn config files?

Link to comment
3 minutes ago, aptalca said:

After switching, did you recreate the user accounts and the ovpn config files?

Yes. I actually deleted the docker and image (couldn't figure out how to just delete users). Re-installed the docker. Set verification to "local". And then added users and downloaded and installed new ovpn files on the clients.

 

If auto-login is disabled authentication fails with the error posted above. The only way I could connect is enabling auto-login and PAM.

Link to comment

Maybe this is something obvious but i can't seem to work it out.

Whenever i update my admin password in the docker from ssh i can login fine with the new password.

When i shutdown the docker and restart it, the admin password is changed back to password.

This worries me since its public facing, i've tried to also change the authentication method's but that doesn't seem to prevent this.

 

How do i make the admin password stick and not change. please help :)

Link to comment
  • trurl pinned and unpinned this topic

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.
Note: Your post will require moderator approval before it will be visible.

Guest
Reply to this topic...

×   Pasted as rich text.   Restore formatting

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.