Problem configuring vpn-client: no more internet access

I’m trying to configure vpn-client on yunohost (testing version on Jessie), but when I put it on my server doesn’t have any internet access anymore. I can only reach it locally.
I’ve tested the vpn, it works well on my computer. And the configuration file of the server is exactly the same as on my computer, so I don’t understand what could be the problem.

Here is what I find in /var/log/openvpn-client.log :

Fri Mar  4 13:03:00 2016 Restart pause, 2 second(s)
Fri Mar  4 13:03:02 2016 Socket Buffers: R=[212992->131072] S=[212992->131072]
Fri Mar  4 13:03:02 2016 UDPv4 link local: [undef]
Fri Mar  4 13:03:02 2016 UDPv4 link remote: [AF_INET]89.234.140.3:1194
Fri Mar  4 13:03:02 2016 TLS: Initial packet from [AF_INET]89.234.140.3:1194, sid=8288f4c0 37d4f8f9
Fri Mar  4 13:03:02 2016 VERIFY OK: depth=1, C=FR, ST=RHA, L=Villeurbanne, O=ILLYSE, OU=openvpn, CN=illyse-openvpn-ca, name=ILLYSE, emailAddress=abuse@illyse.org
Fri Mar  4 13:03:02 2016 VERIFY OK: nsCertType=SERVER
Fri Mar  4 13:03:02 2016 Validating certificate key usage
Fri Mar  4 13:03:02 2016 ++ Certificate has key usage  00a0, expects 00a0
Fri Mar  4 13:03:02 2016 NOTE: --mute triggered...
Fri Mar  4 13:03:02 2016 5 variation(s) on previous 5 message(s) suppressed by --mute
Fri Mar  4 13:03:02 2016 WARNING: 'link-mtu' is used inconsistently, local='link-mtu 1542', remote='link-mtu 1545'
Fri Mar  4 13:03:02 2016 WARNING: 'comp-lzo' is present in local config but missing in remote config, local='comp-lzo'
Fri Mar  4 13:03:02 2016 WARNING: 'tun-ipv6' is present in remote config but missing in local config, remote='tun-ipv6'
Fri Mar  4 13:03:02 2016 WARNING: 'mtu-dynamic' is present in remote config but missing in local config, remote='mtu-dynamic'
Fri Mar  4 13:03:02 2016 Data Channel Encrypt: Cipher 'BF-CBC' initialized with 128 bit key
Fri Mar  4 13:03:02 2016 Data Channel Encrypt: Using 160 bit message hash 'SHA1' for HMAC authentication
Fri Mar  4 13:03:02 2016 Data Channel Decrypt: Cipher 'BF-CBC' initialized with 128 bit key
Fri Mar  4 13:03:02 2016 Data Channel Decrypt: Using 160 bit message hash 'SHA1' for HMAC authentication
Fri Mar  4 13:03:02 2016 Control Channel: TLSv1, cipher TLSv1/SSLv3 DHE-RSA-AES256-SHA, 4096 bit RSA
Fri Mar  4 13:03:02 2016 [server] Peer Connection Initiated with [AF_INET]89.234.140.3:1194
Fri Mar  4 13:03:05 2016 SENT CONTROL [server]: 'PUSH_REQUEST' (status=1)
Fri Mar  4 13:03:05 2016 PUSH: Received control message: 'PUSH_REPLY,ifconfig-ipv6 2a00:5881:4008:1800::2 2a00:5881:4010::1,tun-ipv6,dhcp-option DNS 89.234.140.2,dhcp-option DNS 89.234.140.1,explicit-exit-notify,route-gateway 89.234.140.129,topology subnet,ping 10,ping-restart 30,ifconfig 89.234.140.166 255.255.255.128'
Fri Mar  4 13:03:05 2016 OPTIONS IMPORT: timers and/or timeouts modified
Fri Mar  4 13:03:05 2016 OPTIONS IMPORT: explicit notify parm(s) modified
Fri Mar  4 13:03:05 2016 OPTIONS IMPORT: --ifconfig/up options modified
Fri Mar  4 13:03:05 2016 NOTE: --mute triggered...
Fri Mar  4 13:03:05 2016 2 variation(s) on previous 5 message(s) suppressed by --mute
Fri Mar  4 13:03:05 2016 WARNING: potential conflict between --remote address [89.234.140.3] and --ifconfig address pair [89.234.140.166, 255.255.255.128] -- this is a warning only that is triggered when local/remote addresses exist within the same /24 subnet as --ifconfig endpoints. (silence this warning with --ifconfig-nowarn)
Fri Mar  4 13:03:05 2016 ROUTE_GATEWAY 192.168.1.1/255.255.255.0 IFACE=eth0 HWADDR=00:1e:90:a0:78:ee
Fri Mar  4 13:03:05 2016 ROUTE6: default_gateway=UNDEF
Fri Mar  4 13:03:05 2016 TUN/TAP device tun0 opened
Fri Mar  4 13:03:05 2016 TUN/TAP TX queue length set to 100
Fri Mar  4 13:03:05 2016 do_ifconfig, tt->ipv6=1, tt->did_ifconfig_ipv6_setup=1
Fri Mar  4 13:03:05 2016 /sbin/ip link set dev tun0 up mtu 1500
Fri Mar  4 13:03:05 2016 /sbin/ip addr add dev tun0 89.234.140.166/25 broadcast 89.234.140.255
Fri Mar  4 13:03:05 2016 /sbin/ip -6 addr add 2a00:5881:4008:1800::2/64 dev tun0
Fri Mar  4 13:03:05 2016 /sbin/ip route add 89.234.140.3/32 via 192.168.1.1
Fri Mar  4 13:03:05 2016 /sbin/ip route add 0.0.0.0/1 via 89.234.140.129
Fri Mar  4 13:03:05 2016 /sbin/ip route add 128.0.0.0/1 via 89.234.140.129
Fri Mar  4 13:03:05 2016 add_route_ipv6(2000::/3 -> 2a00:5881:4010::1 metric -1) dev tun0
Fri Mar  4 13:03:05 2016 /sbin/ip -6 route add 2000::/3 dev tun0
Fri Mar  4 13:03:05 2016 Initialization Sequence Completed
Fri Mar  4 13:03:12 2016 Bad LZO decompression header byte: 0
Fri Mar  4 13:03:15 2016 Bad LZO decompression header byte: 0
Fri Mar  4 13:03:25 2016 Bad LZO decompression header byte: 0
Fri Mar  4 13:03:35 2016 [server] Inactivity timeout (--ping-restart), restarting
Fri Mar  4 13:03:35 2016 /sbin/ip route del 89.234.140.3/32
Fri Mar  4 13:03:35 2016 /sbin/ip route del 0.0.0.0/1
Fri Mar  4 13:03:35 2016 /sbin/ip route del 128.0.0.0/1
Fri Mar  4 13:03:35 2016 delete_route_ipv6(2000::/3)
Fri Mar  4 13:03:35 2016 /sbin/ip -6 route del 2000::/3 dev tun0
Fri Mar  4 13:03:35 2016 Closing TUN/TAP interface
Fri Mar  4 13:03:35 2016 /sbin/ip addr del dev tun0 89.234.140.166/25
Fri Mar  4 13:03:35 2016 SIGUSR1[soft,ping-restart] received, process restarting
Fri Mar  4 13:03:35 2016 Restart pause, 2 second(s)
Fri Mar  4 13:03:37 2016 Socket Buffers: R=[212992->131072] S=[212992->131072]
Fri Mar  4 13:03:37 2016 UDPv4 link local: [undef]
Fri Mar  4 13:03:37 2016 UDPv4 link remote: [AF_INET]89.234.140.3:1194
Fri Mar  4 13:03:37 2016 TLS: Initial packet from [AF_INET]89.234.140.3:1194, sid=61384c79 19980af9
Fri Mar  4 13:03:37 2016 VERIFY OK: depth=1, C=FR, ST=RHA, L=Villeurbanne, O=ILLYSE, OU=openvpn, CN=illyse-openvpn-ca, name=ILLYSE, emailAddress=abuse@illyse.org
Fri Mar  4 13:03:37 2016 VERIFY OK: nsCertType=SERVER
Fri Mar  4 13:03:37 2016 Validating certificate key usage
Fri Mar  4 13:03:37 2016 ++ Certificate has key usage  00a0, expects 00a0
Fri Mar  4 13:03:37 2016 NOTE: --mute triggered...
Fri Mar  4 13:03:38 2016 5 variation(s) on previous 5 message(s) suppressed by --mute
Fri Mar  4 13:03:38 2016 WARNING: 'link-mtu' is used inconsistently, local='link-mtu 1542', remote='link-mtu 1545'
Fri Mar  4 13:03:38 2016 WARNING: 'comp-lzo' is present in local config but missing in remote config, local='comp-lzo'
Fri Mar  4 13:03:38 2016 WARNING: 'tun-ipv6' is present in remote config but missing in local config, remote='tun-ipv6'
Fri Mar  4 13:03:38 2016 WARNING: 'mtu-dynamic' is present in remote config but missing in local config, remote='mtu-dynamic'
Fri Mar  4 13:03:38 2016 Data Channel Encrypt: Cipher 'BF-CBC' initialized with 128 bit key
Fri Mar  4 13:03:38 2016 Data Channel Encrypt: Using 160 bit message hash 'SHA1' for HMAC authentication
Fri Mar  4 13:03:38 2016 Data Channel Decrypt: Cipher 'BF-CBC' initialized with 128 bit key
Fri Mar  4 13:03:38 2016 Data Channel Decrypt: Using 160 bit message hash 'SHA1' for HMAC authentication
Fri Mar  4 13:03:38 2016 Control Channel: TLSv1, cipher TLSv1/SSLv3 DHE-RSA-AES256-SHA, 4096 bit RSA
Fri Mar  4 13:03:38 2016 [server] Peer Connection Initiated with [AF_INET]89.234.140.3:1194
Fri Mar  4 13:03:40 2016 SENT CONTROL [server]: 'PUSH_REQUEST' (status=1)
Fri Mar  4 13:03:40 2016 PUSH: Received control message: 'PUSH_REPLY,ifconfig-ipv6 2a00:5881:4008:1800::2 2a00:5881:4010::1,tun-ipv6,dhcp-option DNS 89.234.140.2,dhcp-option DNS 89.234.140.1,explicit-exit-notify,route-gateway 89.234.140.129,topology subnet,ping 10,ping-restart 30,ifconfig 89.234.140.166 255.255.255.128'
Fri Mar  4 13:03:40 2016 OPTIONS IMPORT: timers and/or timeouts modified
Fri Mar  4 13:03:40 2016 OPTIONS IMPORT: explicit notify parm(s) modified
Fri Mar  4 13:03:40 2016 OPTIONS IMPORT: --ifconfig/up options modified
Fri Mar  4 13:03:40 2016 NOTE: --mute triggered...
Fri Mar  4 13:03:40 2016 2 variation(s) on previous 5 message(s) suppressed by --mute
Fri Mar  4 13:03:40 2016 WARNING: potential conflict between --remote address [89.234.140.3] and --ifconfig address pair [89.234.140.166, 255.255.255.128] -- this is a warning only that is triggered when local/remote addresses exist within the same /24 subnet as --ifconfig endpoints. (silence this warning with --ifconfig-nowarn)
Fri Mar  4 13:03:40 2016 ROUTE_GATEWAY 192.168.1.1/255.255.255.0 IFACE=eth0 HWADDR=00:1e:90:a0:78:ee
Fri Mar  4 13:03:40 2016 ROUTE6: default_gateway=UNDEF
Fri Mar  4 13:03:40 2016 TUN/TAP device tun0 opened
Fri Mar  4 13:03:40 2016 TUN/TAP TX queue length set to 100
Fri Mar  4 13:03:40 2016 do_ifconfig, tt->ipv6=1, tt->did_ifconfig_ipv6_setup=1
Fri Mar  4 13:03:40 2016 /sbin/ip link set dev tun0 up mtu 1500
Fri Mar  4 13:03:40 2016 /sbin/ip addr add dev tun0 89.234.140.166/25 broadcast 89.234.140.255
Fri Mar  4 13:03:40 2016 /sbin/ip -6 addr add 2a00:5881:4008:1800::2/64 dev tun0
Fri Mar  4 13:03:40 2016 /sbin/ip route add 89.234.140.3/32 via 192.168.1.1
Fri Mar  4 13:03:40 2016 /sbin/ip route add 0.0.0.0/1 via 89.234.140.129
Fri Mar  4 13:03:40 2016 /sbin/ip route add 128.0.0.0/1 via 89.234.140.129
Fri Mar  4 13:03:40 2016 add_route_ipv6(2000::/3 -> 2a00:5881:4010::1 metric -1) dev tun0
Fri Mar  4 13:03:40 2016 /sbin/ip -6 route add 2000::/3 dev tun0
Fri Mar  4 13:03:40 2016 Initialization Sequence Completed
Fri Mar  4 13:03:50 2016 Bad LZO decompression header byte: 0
Fri Mar  4 13:03:59 2016 event_wait : Interrupted system call (code=4)
Fri Mar  4 13:03:59 2016 SIGTERM received, sending exit notification to peer
Fri Mar  4 13:04:00 2016 Bad LZO decompression header byte: 0
Fri Mar  4 13:04:00 2016 /sbin/ip route del 89.234.140.3/32
Fri Mar  4 13:04:00 2016 /sbin/ip route del 0.0.0.0/1
Fri Mar  4 13:04:00 2016 /sbin/ip route del 128.0.0.0/1
Fri Mar  4 13:04:00 2016 delete_route_ipv6(2000::/3)
Fri Mar  4 13:04:00 2016 /sbin/ip -6 route del 2000::/3 dev tun0
Fri Mar  4 13:04:00 2016 Closing TUN/TAP interface
Fri Mar  4 13:04:00 2016 /sbin/ip addr del dev tun0 89.234.140.166/25
Fri Mar  4 13:04:00 2016 SIGTERM[soft,exit-with-notification] received, process exiting

If somebody could help, I have no idea on how to solve that…

@tomdereub

Did you configure your DNS when connected ?

You can choose any from the given link.

I think yes, I’ll try again with other dns when I find the time.

I tried with various DNS, and it doesn’t change anything, once I start ynh-vpnclient, I can’t ping any site anymore. Thanks for your answer anyway.
Any other idea ?

I don’t know if it can help, but in the vpn admin web page, I have these informations :

[INFO] Autodetected internet interface: eth0 (last start: )
[INFO] Autodetected IPv6 address for the VPN server: 2a00:5881:4000::2 (last start: 2a00:5881:4000::2)
[INFO] IPv6 delegated prefix found
[INFO] IPv6 address computed from the delegated prefix: 2a00:5881:4008:1800::42
[INFO] No Hotspot app detected
[ERR] No IPv6 address set
[INFO] No native IPv6 detected
[INFO] No IPv6 server route to set
[ERR] No IPv6/IPv4 firewall set
[OK] Host DNS correctly set
[OK] Openvpn is running