Question Help with DD-WRT and OpenVPN ?

Jun 17, 2025
6
0
10
sh: eval: line 0: Date: not found

Is my date!!
Can you help?!!
Thanks


OpenVPN Status

StateClient: CONNECTED SUCCESS


Local Address: 10.103.XXX.YYY [Moderator note: masked the last two IP address octets.]
Remote Address:

Status


VPN Client Stats

TUN/TAP read bytes160
TUN/TAP write bytes500
TCP/UDP read bytes15370
TCP/UDP write bytes14500
Auth read bytes2004
pre-compress bytes0
post-compress bytes0
pre-decompress bytes0
post-decompress bytes0

LogClient Log:
19700101 01:00:24 W WARNING: Compression for receiving enabled. Compression has been used in the past to break encryption. Sent packets are not compressed unless "allow-compression yes" is also set.
19700101 01:00:24 Note: '--allow-compression' is not set to 'no' disabling data channel offload.
19700101 01:00:24 W WARNING: Using --management on a TCP port WITHOUT passwords is STRONGLY discouraged and considered insecure
19700101 01:00:24 W WARNING: file '/tmp/openvpncl/credentials' is group or others accessible
19700101 01:00:24 I OpenVPN 2.6.14 arm-unknown-linux-gnu [SSL (OpenSSL)] [LZO] [EPOLL] [MH/PKTINFO] [AEAD] [DCO]
19700101 01:00:24 I library versions: OpenSSL 1.1.1w 11 Sep 2023 LZO 2.10
19700101 01:00:24 I DCO version: N/A
19700101 01:00:24 MANAGEMENT: TCP Socket listening on [AF_INET]127.0.0.1:16
19700101 01:00:24 W NOTE: the current --script-security setting may allow this configuration to call user-defined scripts
20250617 15:01:28 W WARNING: if you use --mssfix and --fragment you should use the "mtu" flag for both or none of of them.
20250617 15:01:29 I TCP/UDP: Preserving recently used remote address: [AF_INET]212.2.238.214:1195
20250617 15:01:29 Socket Buffers: R=[262144->262144] S=[262144->262144]
20250617 15:01:29 I UDPv4 link local: (not bound)
20250617 15:01:29 I UDPv4 link remote: [AF_INET]212.2.238.214:1195
20250617 15:01:29 TLS: Initial packet from [AF_INET]212.2.238.214:1195 sid=c9d3025a ab2ad1b6
20250617 15:01:29 W WARNING: this configuration may cache passwords in memory -- use the auth-nocache option to prevent this
20250617 15:01:29 VERIFY OK: depth=1 C=VG ST=BVI O=ExpressVPN OU=ExpressVPN CN=ExpressVPN CA emailAddress=support@ [Moderator edit to mask full email address.]
20250617 15:01:29 NOTE: --mute triggered...
20250617 15:01:29 6 variation(s) on previous 3 message(s) suppressed by --mute
20250617 15:01:29 I [Server-11618-0a] Peer Connection Initiated with [AF_INET]212.2.238.214:1195
20250617 15:01:29 TLS: move_session: dest=TM_ACTIVE src=TM_INITIAL reinit_src=1
20250617 15:01:29 NOTE: --mute triggered...
20250617 15:01:30 1 variation(s) on previous 3 message(s) suppressed by --mute
20250617 15:01:30 SENT CONTROL [Server-11618-0a]: 'PUSH_REQUEST' (status=1)
20250617 15:01:30 NOTE: --mute triggered...
20250617 15:01:30 6 variation(s) on previous 3 message(s) suppressed by --mute
20250617 15:01:30 net_route_v4_best_gw query: dst 0.0.0.0
20250617 15:01:30 net_route_v4_best_gw result: via 192.168.1.1 dev br0
20250617 15:01:30 I TUN/TAP device tun0 opened
20250617 15:01:30 I net_iface_mtu_set: mtu 1500 for tun0
20250617 15:01:30 I net_iface_up: set tun0 up
20250617 15:01:30 I net_addr_v4_add: 10.103.0.36/16 dev tun0
20250617 15:01:30 net_route_v4_add: 212.2.238.214/32 via 192.168.1.1 dev [NULL] table 0 metric -1
20250617 15:01:30 net_route_v4_add: 0.0.0.0/1 via 10.103.0.1 dev [NULL] table 0 metric -1
20250617 15:01:30 net_route_v4_add: 128.0.0.0/1 via 10.103.0.1 dev [NULL] table 0 metric -1
20250617 15:01:30 I Initialization Sequence Completed
20250617 15:01:30 Data Channel: cipher 'AES-256-CBC' auth 'SHA512' peer-id: 35 compression: 'stub'
20250617 15:01:30 NOTE: --mute triggered...
20250617 15:17:33 2 variation(s) on previous 3 message(s) suppressed by --mute
20250617 15:17:33 MANAGEMENT: Client connected from [AF_INET]127.0.0.1:55828
20250617 15:17:33 D MANAGEMENT: CMD 'state'
20250617 15:17:33 MANAGEMENT: Client disconnected
20250617 15:17:33 NOTE: --mute triggered...
20250617 15:17:33 1 variation(s) on previous 3 message(s) suppressed by --mute
20250617 15:17:33 D MANAGEMENT: CMD 'state'
20250617 15:17:33 MANAGEMENT: Client disconnected
20250617 15:17:33 NOTE: --mute triggered...
20250617 15:17:33 1 variation(s) on previous 3 message(s) suppressed by --mute
20250617 15:17:33 D MANAGEMENT: CMD 'state'
20250617 15:17:33 MANAGEMENT: Client disconnected
20250617 15:17:33 NOTE: --mute triggered...
20250617 15:17:33 1 variation(s) on previous 3 message(s) suppressed by --mute
20250617 15:17:33 D MANAGEMENT: CMD 'status 2'
20250617 15:17:33 MANAGEMENT: Client disconnected
20250617 15:17:33 NOTE: --mute triggered...
20250617 15:17:33 1 variation(s) on previous 3 message(s) suppressed by --mute
20250617 15:17:33 D MANAGEMENT: CMD 'log 500'
19700101 01:00:00


https://ibb.co/Vcgd4xWd
https://ibb.co/1t9n8jZm
 
Last edited by a moderator:
Note: I masked out the source IP address and the email address shown in the presented log.

= = = =

@Tomsuser2

More information needed about what you are attempting to do and how you are making that attempt.

Make and model router (or modem/router if being used)?

Is there some sort of script or code involved?

What specific problem or problems are being encountered?
 
I had hoped someone saw something or the original poster would have updated a bit.

I know little about this but it seems that a vpn session might have established at least part way. You see it assign a tunnel IP 10.103.0.36.

There then is a 15 minute gap with a bunch of messages that mean nothing to me.
 
Note: I masked out the source IP address and the email address shown in the presented log.

= = = =

@Tomsuser2

More information needed about what you are attempting to do and how you are making that attempt.

Make and model router (or modem/router if being used)?

Is there some sort of script or code involved?

What specific problem or problems are being encountered?
Hi
I will use this behind a livebox 4 (france) modem router with fiber 0.4 G
My second router is a r7000 netgear with openvpn express vpn
The livebox has a dedicated port to pass on
Note: I masked out the source IP address and the email address shown in the presented log.

= = = =

@Tomsuser2

More information needed about what you are attempting to do and how you are making that attempt.

Make and model router (or modem/router if being used)?

Is there some sort of script or code involved?

What specific problem or problems are being encountered?

Hi behind a french livebox 4 and nd dhcp dmz ip adress assigned a r7000 netgear openvpn expressvpn is setup as close as possible to their tutorial it seems close to working but not

20250618 17:15:54 NOTE: --mute triggered...
20250618 17:15:54 1 variation(s) on previous 3 message(s) suppressed by --mute
20250618 17:15:54 D MANAGEMENT: CMD 'status 2'
20250618 17:15:54 MANAGEMENT: Client disconnected
20250618 17:15:55 NOTE: --mute triggered...
20250618 17:15:55 1 variation(s) on previous 3 message(s) suppressed by --mute
20250618 17:15:55 D MANAGEMENT: CMD 'log 500'
20250618 17:15:55 MANAGEMENT: Client disconnected
20250618 17:16:50 I [Server-11618-0a] Inactivity timeout (--ping-restart) restarting
20250618 17:16:50 I /tmp/openvpncl/route-down.sh tun1 1500 0 10.103.0.108 255.255.0.0 init
20250618 17:16:50 net_route_v4_del: 212.2.238.214/32 via 192.168.1.1 dev [NULL] table 0 metric -1
20250618 17:16:50 net_route_v4_del: 0.0.0.0/1 via 10.103.0.1 dev [NULL] table 0 metric -1
20250618 17:16:50 net_route_v4_del: 128.0.0.0/1 via 10.103.0.1 dev [NULL] table 0 metric -1
20250618 17:16:50 Closing TUN/TAP interface
20250618 17:16:50 I net_addr_v4_del: 10.103.0.108 dev tun1
20250618 17:16:50 I SIGUSR1[soft ping-restart] received process restarting
20250618 17:16:50 Restart pause 1 second(s)
20250618 17:16:51 W NOTE: the current --script-security setting may allow this configuration to call user-defined scripts
20250618 17:16:51 I TCP/UDP: Preserving recently used remote address: [AF_INET]212.2.238.214:1195
20250618 17:16:51 Socket Buffers: R=[262144->262144] S=[262144->262144]
20250618 17:16:51 I UDPv4 link local: (not bound)
20250618 17:16:51 I UDPv4 link remote: [AF_INET]212.2.238.214:1195
20250618 17:16:51 TLS: Initial packet from [AF_INET]212.2.238.214:1195 sid=291df43b 4131b259
20250618 17:16:51 NOTE: --mute triggered...
20250618 17:16:51 7 variation(s) on previous 3 message(s) suppressed by --mute
20250618 17:16:51 I [Server-11618-0a] Peer Connection Initiated with [AF_INET]212.2.238.214:1195
20250618 17:16:51 TLS: move_session: dest=TM_ACTIVE src=TM_INITIAL reinit_src=1
20250618 17:16:51 NOTE: --mute triggered...
20250618 17:16:52 1 variation(s) on previous 3 message(s) suppressed by --mute
20250618 17:16:52 SENT CONTROL [Server-11618-0a]: 'PUSH_REQUEST' (status=1)
20250618 17:16:52 NOTE: --mute triggered...
20250618 17:16:52 6 variation(s) on previous 3 message(s) suppressed by --mute
20250618 17:16:52 net_route_v4_best_gw query: dst 0.0.0.0
20250618 17:16:52 net_route_v4_best_gw result: via 192.168.1.1 dev br0
20250618 17:16:52 I TUN/TAP device tun1 opened
20250618 17:16:52 I net_iface_mtu_set: mtu 1500 for tun1
20250618 17:16:52 I net_iface_up: set tun1 up
20250618 17:16:52 I net_addr_v4_add: 10.103.0.10/16 dev tun1
20250618 17:16:52 net_route_v4_add: 212.2.238.214/32 via 192.168.1.1 dev [NULL] table 0 metric -1
20250618 17:16:52 net_route_v4_add: 0.0.0.0/1 via 10.103.0.1 dev [NULL] table 0 metric -1
20250618 17:16:52 net_route_v4_add: 128.0.0.0/1 via 10.103.0.1 dev [NULL] table 0 metric -1
20250618 17:16:52 I Initialization Sequence Completed
20250618 17:16:52 Data Channel: cipher 'AES-256-GCM' peer-id: 112 compression: 'stub'
20250618 17:16:52 NOTE: --mute triggered...
20250618 17:17:52 2 variation(s) on previous 3 message(s) suppressed by --mute
20250618 17:17:52 I [Server-11618-0a] Inactivity timeout (--ping-restart) restarting
20250618 17:17:52 I /tmp/openvpncl/route-down.sh tun1 1500 0 10.103.0.10 255.255.0.0 init
20250618 17:17:53 net_route_v4_del: 212.2.238.214/32 via 192.168.1.1 dev [NULL] table 0 metric -1
20250618 17:17:53 net_route_v4_del: 0.0.0.0/1 via 10.103.0.1 dev [NULL] table 0 metric -1
20250618 17:17:53 net_route_v4_del: 128.0.0.0/1 via 10.103.0.1 dev [NULL] table 0 metric -1
20250618 17:17:53 Closing TUN/TAP interface
20250618 17:17:53 I net_addr_v4_del: 10.103.0.10 dev tun1
20250618 17:17:53 I SIGUSR1[soft ping-restart] received process restarting
20250618 17:17:53 Restart pause 1 second(s)
20250618 17:17:54 W NOTE: the current --script-security setting may allow this configuration to call user-defined scripts
20250618 17:17:54 I TCP/UDP: Preserving recently used remote address: [AF_INET]212.2.238.214:1195
20250618 17:17:54 Socket Buffers: R=[262144->262144] S=[262144->262144]
20250618 17:17:54 I UDPv4 link local: (not bound)
20250618 17:17:54 I UDPv4 link remote: [AF_INET]212.2.238.214:1195
20250618 17:17:54 TLS: Initial packet from [AF_INET]212.2.238.214:1195 sid=12e44205 50de4b7b
20250618 17:17:54 NOTE: --mute triggered...
20250618 17:17:54 7 variation(s) on previous 3 message(s) suppressed by --mute
20250618 17:17:54 I [Server-11618-0a] Peer Connection Initiated with [AF_INET]212.2.238.214:1195
20250618 17:17:54 TLS: move_session: dest=TM_ACTIVE src=TM_INITIAL reinit_src=1
20250618 17:17:54 NOTE: --mute triggered...
20250618 17:17:55 1 variation(s) on previous 3 message(s) suppressed by --mute
20250618 17:17:55 SENT CONTROL [Server-11618-0a]: 'PUSH_REQUEST' (status=1)
20250618 17:17:55 NOTE: --mute triggered...
20250618 17:17:55 6 variation(s) on previous 3 message(s) suppressed by --mute
20250618 17:17:55 net_route_v4_best_gw query: dst 0.0.0.0
20250618 17:17:55 net_route_v4_best_gw result: via 192.168.1.1 dev br0
20250618 17:17:55 I TUN/TAP device tun1 opened
20250618 17:17:55 I net_iface_mtu_set: mtu 1500 for tun1
20250618 17:17:55 I net_iface_up: set tun1 up
20250618 17:17:55 I net_addr_v4_add: 10.103.0.100/16 dev tun1
20250618 17:17:55 net_route_v4_add: 212.2.238.214/32 via 192.168.1.1 dev [NULL] table 0 metric -1
20250618 17:17:55 net_route_v4_add: 0.0.0.0/1 via 10.103.0.1 dev [NULL] table 0 metric -1
20250618 17:17:55 net_route_v4_add: 128.0.0.0/1 via 10.103.0.1 dev [NULL] table 0 metric -1
20250618 17:17:55 I Initialization Sequence Completed
20250618 17:17:55 Data Channel: cipher 'AES-256-GCM' peer-id: 2 compression: 'stub'
20250618 17:17:55 NOTE: --mute triggered...
20250618 17:18:26 2 variation(s) on previous 3 message(s) suppressed by --mute
20250618 17:18:26 MANAGEMENT: Client connected from [AF_INET]127.0.0.1:54770
20250618 17:18:26 D MANAGEMENT: CMD 'state'
20250618 17:18:26 MANAGEMENT: Client disconnected
20250618 17:18:26 NOTE: --mute triggered...
20250618 17:18:26 1 variation(s) on previous 3 message(s) suppressed by --mute
20250618 17:18:26 D MANAGEMENT: CMD 'state'
20250618 17:18:26 MANAGEMENT: Client disconnected
20250618 17:18:26 NOTE: --mute triggered...
20250618 17:18:26 1 variation(s) on previous 3 message(s) suppressed by --mute
20250618 17:18:26 D MANAGEMENT: CMD 'state'
20250618 17:18:26 MANAGEMENT: Client disconnected
20250618 17:18:26 NOTE: --mute triggered...
20250618 17:18:26 1 variation(s) on previous 3 message(s) suppressed by --mute
20250618 17:18:26 D MANAGEMENT: CMD 'status 2'
20250618 17:18:26
 
Client Log:
19700101 01:00:25 Note: '--allow-compression' is not set to 'no' disabling data channel offload.
19700101 01:00:25 W WARNING: Using --management on a TCP port WITHOUT passwords is STRONGLY discouraged and considered insecure
19700101 01:00:25 W WARNING: file '/tmp/openvpncl/ta.key' is group or others accessible
19700101 01:00:25 W WARNING: file '/tmp/openvpncl/credentials' is group or others accessible
19700101 01:00:25 I OpenVPN 2.6.14 arm-unknown-linux-gnu [SSL (OpenSSL)] [LZO] [EPOLL] [MH/PKTINFO] [AEAD] [DCO]
19700101 01:00:25 I library versions: OpenSSL 1.1.1w 11 Sep 2023 LZO 2.10
19700101 01:00:25 I DCO version: N/A
19700101 01:00:25 MANAGEMENT: TCP Socket listening on [AF_INET]127.0.0.1:16
19700101 01:00:25 W NOTE: the current --script-security setting may allow this configuration to call user-defined scripts
20250618 17:35:18 I TCP/UDP: Preserving recently used remote address: [AF_INET]212.2.238.214:1195
20250618 17:35:18 Socket Buffers: R=[262144->262144] S=[262144->262144]
20250618 17:35:18 I UDPv4 link local: (not bound)
20250618 17:35:18 I UDPv4 link remote: [AF_INET]212.2.238.214:1195
20250618 17:35:18 TLS: Initial packet from [AF_INET]212.2.238.214:1195 sid=faaf28d6 ca76886c
20250618 17:35:18 W WARNING: this configuration may cache passwords in memory -- use the auth-nocache option to prevent this
20250618 17:35:18 VERIFY OK: depth=1 C=VG ST=BVI O=ExpressVPN OU=ExpressVPN CN=ExpressVPN CA emailAddress=support@expressvpn.com
20250618 17:35:18 NOTE: --mute triggered...
20250618 17:35:18 6 variation(s) on previous 3 message(s) suppressed by --mute
20250618 17:35:18 I [Server-11618-0a] Peer Connection Initiated with [AF_INET]212.2.238.214:1195
20250618 17:35:18 TLS: move_session: dest=TM_ACTIVE src=TM_INITIAL reinit_src=1
20250618 17:35:18 NOTE: --mute triggered...
20250618 17:35:19 1 variation(s) on previous 3 message(s) suppressed by --mute
20250618 17:35:19 SENT CONTROL [Server-11618-0a]: 'PUSH_REQUEST' (status=1)
20250618 17:35:19 NOTE: --mute triggered...
20250618 17:35:19 6 variation(s) on previous 3 message(s) suppressed by --mute
20250618 17:35:19 net_route_v4_best_gw query: dst 0.0.0.0
20250618 17:35:19 net_route_v4_best_gw result: via 192.168.1.1 dev br0
20250618 17:35:19 I TUN/TAP device tun1 opened
20250618 17:35:19 I net_iface_mtu_set: mtu 1500 for tun1
20250618 17:35:19 I net_iface_up: set tun1 up
20250618 17:35:19 I net_addr_v4_add: 10.103.0.183/16 dev tun1
20250618 17:35:19 net_route_v4_add: 212.2.238.214/32 via 192.168.1.1 dev [NULL] table 0 metric -1
20250618 17:35:19 net_route_v4_add: 0.0.0.0/1 via 10.103.0.1 dev [NULL] table 0 metric -1
20250618 17:35:19 net_route_v4_add: 128.0.0.0/1 via 10.103.0.1 dev [NULL] table 0 metric -1
20250618 17:35:19 I Initialization Sequence Completed
20250618 17:35:19 Data Channel: cipher 'AES-256-GCM' peer-id: 179 compression: 'stub'
20250618 17:35:19 NOTE: --mute triggered...
20250618 17:36:20 2 variation(s) on previous 3 message(s) suppressed by --mute
20250618 17:36:20 I [Server-11618-0a] Inactivity timeout (--ping-restart) restarting
20250618 17:36:20 I /tmp/openvpncl/route-down.sh tun1 1500 0 10.103.0.183 255.255.0.0 init
20250618 17:36:20 net_route_v4_del: 212.2.238.214/32 via 192.168.1.1 dev [NULL] table 0 metric -1
20250618 17:36:20 net_route_v4_del: 0.0.0.0/1 via 10.103.0.1 dev [NULL] table 0 metric -1
20250618 17:36:20 net_route_v4_del: 128.0.0.0/1 via 10.103.0.1 dev [NULL] table 0 metric -1
20250618 17:36:20 Closing TUN/TAP interface
20250618 17:36:20 I net_addr_v4_del: 10.103.0.183 dev tun1
20250618 17:36:20 I SIGUSR1[soft ping-restart] received process restarting
20250618 17:36:20 Restart pause 1 second(s)
20250618 17:36:21 W NOTE: the current --script-security setting may allow this configuration to call user-defined scripts
20250618 17:36:21 I TCP/UDP: Preserving recently used remote address: [AF_INET]212.2.238.214:1195
20250618 17:36:21 Socket Buffers: R=[262144->262144] S=[262144->262144]
20250618 17:36:21 I UDPv4 link local: (not bound)
20250618 17:36:21 I UDPv4 link remote: [AF_INET]212.2.238.214:1195
20250618 17:36:21 TLS: Initial packet from [AF_INET]212.2.238.214:1195 sid=cdd2e439 2c0bb67a
20250618 17:36:21 NOTE: --mute triggered...
20250618 17:36:21 7 variation(s) on previous 3 message(s) suppressed by --mute
20250618 17:36:21 I [Server-11618-0a] Peer Connection Initiated with [AF_INET]212.2.238.214:1195
20250618 17:36:21 TLS: move_session: dest=TM_ACTIVE src=TM_INITIAL reinit_src=1
20250618 17:36:21 NOTE: --mute triggered...
20250618 17:36:22 1 variation(s) on previous 3 message(s) suppressed by --mute
20250618 17:36:22 SENT CONTROL [Server-11618-0a]: 'PUSH_REQUEST' (status=1)
20250618 17:36:22 NOTE: --mute triggered...
20250618 17:36:22 6 variation(s) on previous 3 message(s) suppressed by --mute
20250618 17:36:22 net_route_v4_best_gw query: dst 0.0.0.0
20250618 17:36:22 net_route_v4_best_gw result: via 192.168.1.1 dev br0
20250618 17:36:22 I TUN/TAP device tun1 opened
20250618 17:36:22 I net_iface_mtu_set: mtu 1500 for tun1
20250618 17:36:22 I net_iface_up: set tun1 up
20250618 17:36:22 I net_addr_v4_add: 10.103.0.4/16 dev tun1
20250618 17:36:22 net_route_v4_add: 212.2.238.214/32 via 192.168.1.1 dev [NULL] table 0 metric -1
20250618 17:36:22 net_route_v4_add: 0.0.0.0/1 via 10.103.0.1 dev [NULL] table 0 metric -1
20250618 17:36:22 net_route_v4_add: 128.0.0.0/1 via 10.103.0.1 dev [NULL] table 0 metric -1
20250618 17:36:22 I Initialization Sequence Completed
20250618 17:36:22 Data Channel: cipher 'AES-256-GCM' peer-id: 45 compression: 'stub'
20250618 17:36:22 NOTE: --mute triggered...
20250618 17:36:51 2 variation(s) on previous 3 message(s) suppressed by --mute
20250618 17:36:51 MANAGEMENT: Client connected from [AF_INET]127.0.0.1:43758
20250618 17:36:51 D MANAGEMENT: CMD 'state'
20250618 17:36:51 MANAGEMENT: Client disconnected
20250618 17:36:51 NOTE: --mute triggered...
20250618 17:36:51 1 variation(s) on previous 3 message(s) suppressed by --mute
20250618 17:36:51 D MANAGEMENT: CMD 'state'
20250618 17:36:51 MANAGEMENT: Client disconnected
20250618 17:36:51 NOTE: --mute triggered...
20250618 17:36:51 1 variation(s) on previous 3 message(s) suppressed by --mute
20250618 17:36:51 D MANAGEMENT: CMD 'state'
20250618 17:36:51 MANAGEMENT: Client disconnected
20250618 17:36:51 NOTE: --mute triggered...
20250618 17:36:51 1 variation(s) on previous 3 message(s) suppressed by --mute
20250618 17:36:51 D MANAGEMENT: CMD 'status 2'
20250618 17:36:51 MANAGEMENT: Client disconnected
20250618 17:36:51 NOTE: --mute triggered...
20250618 17:36:51 1 variation(s) on previous 3 message(s) suppressed by --mute
20250618 17:36:51
 
It appears that the displayed support email address is being entered into the Client logs for some reason so I will no longer redact that email address.

And will likewise no longer edit what may be Public IP addresses. Those IP addresses should not be posted; however, that will be left to @Tomsuser2 .

= = = =

That said, I am now wondering about the subnet masking. I.e., the /notations present in the logs - not sure about some of them

I did note 255.255.0.0 in one of the log entries and that entry seemed out of context.

Are there any user defined scripts being used?

Also noted the "mutes" and references to "CMD" state and status. What is, if anything, being muted and not shown?

Continuing pattern:

"
20250618 17:36:51 MANAGEMENT: Client connected from [AF_INET]127.0.0.1:43758
20250618 17:36:51 D MANAGEMENT: CMD 'state'
20250618 17:36:51 MANAGEMENT: Client disconnected
20250618 17:36:51 NOTE: --mute triggered...
20250618 17:36:51 1 variation(s) on previous 3 message(s) suppressed by --mute
20250618 17:36:51 D MANAGEMENT: CMD 'state'
20250618 17:36:51 MANAGEMENT: Client disconnected
20250618 17:36:51 NOTE: --mute triggered...
20250618 17:36:51 1 variation(s) on previous 3 message(s) suppressed by --mute
20250618 17:36:51 D MANAGEMENT: CMD 'state'
20250618 17:36:51 MANAGEMENT: Client disconnected
20250618 17:36:51 NOTE: --mute triggered...
20250618 17:36:51 1 variation(s) on previous 3 message(s) suppressed by --mute
20250618 17:36:51 D MANAGEMENT: CMD 'status 2'
20250618 17:36:51 MANAGEMENT: Client disconnected
20250618 17:36:51 NOTE: --mute triggered...
20250618 17:36:51 1 variation(s) on previous 3 message(s) suppressed by --mute
20250618 17:36:51


What are the messages being suppressed by mute?

= = = =

Well out of my comfort zone here and in agreement with @cruisetung.

I would expect that ExpressVPN tech support should be able to analyze and explain the log entries as necessary. Plus provide the necessary corrections, fixes, etc..
 
The 255.255.0.0 mask is something the VPN service provider is setting on the ips it is using on the tunnel end points. Not sure why they are doing this. Generally these are things that are negotiated when the vpn opens. Generally unless you run the server and the client you leave all this set so the ISP can control these type of settings.

I have not manually set one of these up in so many years I have forgotten what all this stuff means. If I had to guess this is acting like there is some issue with the account the tunnel activates and might even pass traffic but something is blocking it. So like other recommend maybe expressvpn has a idea.
 
It appears that the displayed support email address is being entered into the Client logs for some reason so I will no longer redact that email address.

And will likewise no longer edit what may be Public IP addresses. Those IP addresses should not be posted; however, that will be left to @Tomsuser2 .

= = = =

That said, I am now wondering about the subnet masking. I.e., the /notations present in the logs - not sure about some of them

I did note 255.255.0.0 in one of the log entries and that entry seemed out of context.

Are there any user defined scripts being used?

Also noted the "mutes" and references to "CMD" state and status. What is, if anything, being muted and not shown?

Continuing pattern:

"
20250618 17:36:51 MANAGEMENT: Client connected from [AF_INET]127.0.0.1:43758
20250618 17:36:51 D MANAGEMENT: CMD 'state'
20250618 17:36:51 MANAGEMENT: Client disconnected
20250618 17:36:51 NOTE: --mute triggered...
20250618 17:36:51 1 variation(s) on previous 3 message(s) suppressed by --mute
20250618 17:36:51 D MANAGEMENT: CMD 'state'
20250618 17:36:51 MANAGEMENT: Client disconnected
20250618 17:36:51 NOTE: --mute triggered...
20250618 17:36:51 1 variation(s) on previous 3 message(s) suppressed by --mute
20250618 17:36:51 D MANAGEMENT: CMD 'state'
20250618 17:36:51 MANAGEMENT: Client disconnected
20250618 17:36:51 NOTE: --mute triggered...
20250618 17:36:51 1 variation(s) on previous 3 message(s) suppressed by --mute
20250618 17:36:51 D MANAGEMENT: CMD 'status 2'
20250618 17:36:51 MANAGEMENT: Client disconnected
20250618 17:36:51 NOTE: --mute triggered...
20250618 17:36:51 1 variation(s) on previous 3 message(s) suppressed by --mute
20250618 17:36:51


What are the messages being suppressed by mute?

= = = =

Well out of my comfort zone here and in agreement with @cruisetung.

I would expect that ExpressVPN tech support should be able to analyze and explain the log entries as necessary. Plus provide the necessary corrections, fixes, etc..
No i am not using any scripts where can i find some, i have contacted expressvpn not much help very vague