OpenVPN VPN 0.1.4
Upgrade from 0.1.2 or 0.1.3 right away. On those versions the tunnel connects and reports connected, but carries no traffic at all.
Fix: the userspace data plane never started
0.1.2 renamed the app from OpenVPN to OpenVPN_VPN, but the tun probe still launched the netstack sidecar from the old /usr/local/packages/OpenVPN/lib path. The execl failed on every connect, so the data plane never came up:
- the transparent port forwarders never listened
- the inbound SOCKS5 proxy on the VPN address never listened
- the outbound HTTP and SOCKS5 proxies never listened
- the client logged
TUN write exception: Connection refusedand reconnected in a loop
0.1.0 and 0.1.1 were not affected.
The failure was invisible because the execl error path exited silently and the probe and sidecar logged under an OpenVPN syslog tag that the app log never shows. Both are fixed, so a future failure will be logged where you can see it.
Configurable forwarded ports
Also included, from 0.1.3: the directly forwarded ports are configurable instead of fixed at 80, 443 and 554. Add port 22 to reach SSH over the VPN.
80,443,554,22
Set it under Forwarded ports in Settings, or via the parameter API:
curl --digest -u <username>:<password> \
--data "action=update&root.OpenVPN_VPN.ForwardPorts=80,443,554,22" \
"http://<device-ip>/axis-cgi/param.cgi"Up to 16 ports. Duplicates, out-of-range values and stray whitespace are ignored, and an empty value restores the default.
Security: every listed port is reachable from the VPN. Control access with your server's client configuration and firewall rules, and keep the camera behind its normal authentication.
Verified
Tested on an AXIS D6310 (AXIS OS 13) against a real OpenVPN server: SSH and HTTPS both work over the tunnel on the configured ports, an unconfigured port stays closed, and the client no longer restart-loops.
Packages
| Package | For |
|---|---|
signed_OpenVPN_VPN_0_1_4_aarch64.eap |
Most cameras. AXIS OS 10.x - 13, 64-bit |
signed_OpenVPN_VPN_0_1_4_armv7hf.eap |
AXIS OS 10.x - 13, 32-bit |
Both are signed with the Axis ACAP signing service and install normally on AXIS OS 12.10 and later. Upgrading in place keeps your existing settings.