Archer MR600 - TLS handshake failed (OpenVPN connection problem)

This thread has been locked for further replies. You can start a new thread to share your ideas or ask questions.

Archer MR600 - TLS handshake failed (OpenVPN connection problem)

This thread has been locked for further replies. You can start a new thread to share your ideas or ask questions.
Archer MR600 - TLS handshake failed (OpenVPN connection problem)
Archer MR600 - TLS handshake failed (OpenVPN connection problem)
2019-11-09 15:17:35 - last edited 2019-11-20 07:29:51
Model: Archer MR600  
Hardware Version: V1
Firmware Version: 1.1.0 0.9.1 v0001.0 Build 190412 Rel.66770n

Hello,

 

I've problem on TP-Link MR600 with connection by OpenVPN from external.

 

I configured MR600:

- Time synchronisation from Internet, later I added: 0.pl.pool.ntp.org; 194.146.251.100

- DDNS from TP Link Cloud

- OpenVPN (Enable, UDP, Internet and home); Saved; Certyficate generated

- Client used on Windows 10 (OpenVPN 2.4.8, tested also on other clients) and Android (OpenVPN for Android by Arne Schwabe)

 

LOG:

 

2019-11-09 16:04:40 WARNING: No server certificate verification method has been enabled.  See http://openvpn.net/howto.html#mitm for more info. 

2019-11-09 16:04:40 LZO compression initializing 

2019-11-09 16:04:40 Control Channel MTU parms [ L:1622 D:1212 EF:38 EB:0 ET:0 EL:3 ] 

2019-11-09 16:04:40 Data Channel MTU parms [ L:1622 D:1450 EF:122 EB:406 ET:0 EL:3 ] 

2019-11-09 16:04:40 Local Options String (VER=V4): 'V4,dev-type tun,link-mtu 1558,tun-mtu 1500,proto UDPv4,comp-lzo,cipher AES-128-CBC,auth SHA1,keysize 128,key-method 2,tls-client' 

2019-11-09 16:04:40 Expected Remote Options String (VER=V4): 'V4,dev-type tun,link-mtu 1558,tun-mtu 1500,proto UDPv4,comp-lzo,cipher AES-128-CBC,auth SHA1,keysize 128,key-method 2,tls-server' 

2019-11-09 16:04:40 TCP/UDP: Preserving recently used remote address: [AF_INET]xxx.xxx.xxx.xxx:1194 

2019-11-09 16:04:40 Socket Buffers: R=[229376->229376] S=[229376->229376] 

2019-11-09 16:04:40 MANAGEMENT: CMD 'needok 'PROTECTFD' ok' 

2019-11-09 16:04:40 UDP link local: (not bound) 

2019-11-09 16:04:40 UDP link remote: [AF_INET]xxx.xxx.xxx.xxx:1194 

2019-11-09 16:04:40 MANAGEMENT: >STATE:1573311880,WAIT,,,,,, 

2019-11-09 16:05:40 TLS Error: TLS key negotiation failed to occur within 60 seconds (check your network connectivity) 

2019-11-09 16:05:40 TLS Error: TLS handshake failed 

2019-11-09 16:05:40 TCP/UDP: Closing socket 

2019-11-09 16:05:40 SIGUSR1[soft,tls-error] received, process restarting 

2019-11-09 16:05:40 MANAGEMENT: >STATE:1573311940,RECONNECTING,tls-error,,,,, 

 

Kindly ask for support.

Thank you!

 

  0      
  0      
#1
Options
1 Accepted Solution
Re:Archer MR600 - TLS handshake failed (OpenVPN connection problem)-Solution
2019-11-16 16:37:07 - last edited 2019-11-20 07:29:51

OK. Problem solved. smiley

 

I got from my mobile internet operator "direct" dynamic IP (additianally paid) and now VPN works perfectly (using TP Link DDNS).

Recommended Solution
  1  
  1  
#4
Options
3 Reply
Re:Archer MR600 - TLS handshake failed (OpenVPN connection problem)
2019-11-11 13:01:17

Hello All,

 

probably I found problem. My mobile internet provider is giving IP address behind NAT.

IP address which I see in TP-Link configuration (blow) is like: 10.x.x.x

 

 

when I check my IP address which is visible "from internet" looks like below: 5.x.x.x

 

 

 

Addresses differ so I think my Mobile Internet Provider is not giving me external dynamic IP, but some NAT IP.

 

I'll discus with my mobile ISP and try to get external dynamic (or static) IP address (not "behind NAT" / under heavy NAT address).

I'll let you know if it solved my problem.

 

 

 

  0  
  0  
#3
Options
Re:Archer MR600 - TLS handshake failed (OpenVPN connection problem)-Solution
2019-11-16 16:37:07 - last edited 2019-11-20 07:29:51

OK. Problem solved. smiley

 

I got from my mobile internet operator "direct" dynamic IP (additianally paid) and now VPN works perfectly (using TP Link DDNS).

Recommended Solution
  1  
  1  
#4
Options
Re:Archer MR600 - TLS handshake failed (OpenVPN connection problem)
2019-11-20 07:29:45

@zook 

 

Thanks for your updates, glad to hear that you figured it out.

 

Now you can enjoy the internet with the Archer MR600.

 

If need more help, please let us know.

 

Best regards. 

Nice to Meet You in Our TP-Link Community. Check Out the Latest Posts: Connect TP-Link Archer BE550 to Germany's DS-Lite (Dual Stack Lite) Internet via WAN Archer GE550 - BE9300 Tri-Band Wi-Fi 7 Gaming Router EasyMesh Is Available When Wi-Fi Routers Work in AP Mode as A Controller. Archer AX55V2 Supports WireGuard VPN, EasyMesh Ethernet Backhaul, IoT Network, Speed Limit,and More If you found a post or response helpful, please click Helpful (arrow pointing upward icon). If you are the author of a topic, remember to mark a helpful reply as the "Recommended Solution" (star icon) so that others can benefit from it.
  0  
  0  
#5
Options