diff --git a/docs/guides/vpn/Android-Transport-Error.png b/docs/guides/vpn/Android-Transport-Error.png
new file mode 100644
index 0000000..9b38ea8
Binary files /dev/null and b/docs/guides/vpn/Android-Transport-Error.png differ
diff --git a/docs/guides/vpn/Strato-DynDNS-Domain.png b/docs/guides/vpn/Strato-DynDNS-Domain.png
new file mode 100644
index 0000000..048909f
Binary files /dev/null and b/docs/guides/vpn/Strato-DynDNS-Domain.png differ
diff --git a/docs/guides/vpn/Strato-DynDNS-Enable.png b/docs/guides/vpn/Strato-DynDNS-Enable.png
new file mode 100644
index 0000000..0eb4f08
Binary files /dev/null and b/docs/guides/vpn/Strato-DynDNS-Enable.png differ
diff --git a/docs/guides/vpn/Strato-DynDNS-Password.png b/docs/guides/vpn/Strato-DynDNS-Password.png
new file mode 100644
index 0000000..5b5ce78
Binary files /dev/null and b/docs/guides/vpn/Strato-DynDNS-Password.png differ
diff --git a/docs/guides/vpn/dynDNS.md b/docs/guides/vpn/dynDNS.md
index 7e2eff5..0091fa7 100644
--- a/docs/guides/vpn/dynDNS.md
+++ b/docs/guides/vpn/dynDNS.md
@@ -18,4 +18,67 @@ If you have set up a DDNS domain for your IP address, you will likely need to ad
pihole -a hostrecord home.mydomain.de 192.168.1.10
```
-If you don't do this, clients (like the Android OpenVPN client) will not able to connect to the VPN server when *inside the internal network* (while it will work from outside). Afterwards, the client will be able to connect to the VPN server both from inside and outside you local network.
\ No newline at end of file
+If you don't do this, clients (like the Android OpenVPN client) will not able to connect to the VPN server when *inside the internal network* (while it will work from outside). Afterwards, the client will be able to connect to the VPN server both from inside and outside your local network.
+
+## Setting up DynDNS update
+
+If your router cannot update the dynamic DNS record, you can use for example `ddclient`.
+```
+sudo apt install ddclient
+```
+
+This configuration file resides in `/etc/ddclient.conf`. During installation, `apt` probably already asked you some questions and prepared a useful config file. In general, configuration files look like:
+```
+# /etc/ddclient.conf
+#
+protocol=dyndns2
+use=web
+login=mylogin
+password=mypassword
+myhost.dyndns.org
+```
+
+If you want to have `ddclient` running as daemon (recommended!), change also your `/etc/defaults/ddclient` to:
+```
+# Configuration for ddclient scripts
+# generated from debconf on Do 9. Feb 22:29:13 CET 2017
+#
+# /etc/default/ddclient
+
+# Set to "true" if ddclient should be run every time DHCP client ('dhclient'
+# from package isc-dhcp-client) updates the systems IP address.
+run_dhclient="false"
+
+# Set to "true" if ddclient should be run every time a new ppp connection is
+# established. This might be useful, if you are using dial-on-demand.
+run_ipup="false"
+
+# Set to "true" if ddclient should run in daemon mode
+# If this is changed to true, run_ipup and run_dhclient must be set to false.
+run_daemon="true"
+
+# Set the time interval between the updates of the dynamic DNS name in seconds.
+# This option only takes effect if the ddclient runs in daemon mode.
+daemon_interval="300"
+```
+
+### Example: Strato DynDNS
+In the following, we give an example of how to setup `ddclient` using the German Internet hosting provider Strato. First, you need to create a subdomain. Then you need to enable DnyDNS for this domain:
+> 
+>
+> 
+>
+> 
+
+Afterwards, modify your `ddclient` config file to look like:
+```
+protocol=dyndns2
+use=if, if=eth0
+use=web, web=checkip.dyndns.org
+server=dyndns.strato.com/nic/update
+login=strato-login-name
+password='password1234'
+
+meine.domain.de
+```
+where you replace `strato-login-name` by your Strato login name (most likely your domain name, like `maxmustermann.de`), `password1234` by the password you configured above (see third screenshot), and `meine.domain.de` by the subdomain you created and enabled dynamic DNS for.
diff --git a/docs/guides/vpn/firewall.md b/docs/guides/vpn/firewall.md
index 3a0e94f..546d022 100644
--- a/docs/guides/vpn/firewall.md
+++ b/docs/guides/vpn/firewall.md
@@ -94,10 +94,10 @@ and they should look something like this:
```
Chain INPUT (policy DROP)
-num target prot opt source destination
-1 ACCEPT all -- anywhere anywhere
+num target prot opt source destination
+1 ACCEPT all -- anywhere anywhere
2 ACCEPT all -- anywhere anywhere state RELATED,ESTABLISHED
-3 ACCEPT all -- anywhere anywhere
+3 ACCEPT all -- anywhere anywhere
4 ACCEPT tcp -- anywhere anywhere tcp dpt:domain
5 ACCEPT udp -- anywhere anywhere udp dpt:domain
6 ACCEPT tcp -- anywhere anywhere tcp dpt:http
@@ -116,18 +116,18 @@ num target prot opt source destination
19 REJECT tcp -- anywhere anywhere tcp dpt:https reject-with icmp-port-unreachable
Chain FORWARD (policy ACCEPT)
-num target prot opt source destination
+num target prot opt source destination
Chain OUTPUT (policy ACCEPT)
-num target prot opt source destination
+num target prot opt source destination
```
Similarly, `ip6tables -L --line-numbers` should look like this:
```
Chain INPUT (policy DROP)
-num target prot opt source destination
-1 ACCEPT all anywhere anywhere
+num target prot opt source destination
+1 ACCEPT all anywhere anywhere
2 ACCEPT all anywhere anywhere state RELATED,ESTABLISHED
3 ACCEPT tcp anywhere anywhere tcp dpt:domain
4 ACCEPT udp anywhere anywhere udp dpt:domain
@@ -139,10 +139,10 @@ num target prot opt source destination
10 REJECT tcp anywhere anywhere tcp dpt:https reject-with icmp6-port-unreachable
Chain FORWARD (policy ACCEPT)
-num target prot opt source destination
+num target prot opt source destination
Chain OUTPUT (policy ACCEPT)
-num target prot opt source destination
+num target prot opt source destination
```
##### Verify the rules are working
@@ -164,4 +164,3 @@ Similarly, you can restore these rules:
iptables-restore < /etc/pihole/rules.v4
ip6tables-restore < /etc/pihole/rules.v6
```
----
\ No newline at end of file
diff --git a/docs/guides/vpn/listening-behavior.png b/docs/guides/vpn/listening-behavior.png
index 1aa82c0..2c95d0d 100644
Binary files a/docs/guides/vpn/listening-behavior.png and b/docs/guides/vpn/listening-behavior.png differ
diff --git a/docs/guides/vpn/setup-openvpn-server.md b/docs/guides/vpn/setup-openvpn-server.md
index 5d5b745..763c4d3 100644
--- a/docs/guides/vpn/setup-openvpn-server.md
+++ b/docs/guides/vpn/setup-openvpn-server.md
@@ -28,6 +28,12 @@ This `push` directive is setting a [DHCP option](https://www.incognito.com/tips-
It's [suggested to have Pi-hole be the only resolver](https://discourse.pi-hole.net/t/why-should-pi-hole-be-my-only-dns-server/3376) as it defines the upstream servers. Setting a non-Pi-hole resolver here [may have adverse effects on ad blocking](https://discourse.pi-hole.net/t/why-should-pi-hole-be-my-only-dns-server/3376) but it _can_ provide failover connectivity in the case of Pi-hole not working if that is something you are concerned about.
+Furthermore, you might want to enable logging for your OpenVPN server. In this case, add the following lines to your server's config file:
+```
+log /var/log/openvpn.log
+verb 3
+```
+
### Restart OpenVPN to apply the changes
Depending on your operating system, one of these commands should work to restart the service.
diff --git a/docs/guides/vpn/troubleshooting.md b/docs/guides/vpn/troubleshooting.md
new file mode 100644
index 0000000..bd2e640
--- /dev/null
+++ b/docs/guides/vpn/troubleshooting.md
@@ -0,0 +1,33 @@
+### CRL expired
+OpenVPN 2.4 and newer check the validity of the Certificate Revocation List (CRL). This can result in a sudden malfunction of `openvpn` after an update even though no configuration files have changed. This error manifests in the following, not very helpful, error on the client side:
+```
+Wed Apr 24 11:19:07 2019 VERIFY OK: depth=0, CN=server
+Wed Apr 24 11:19:07 2019 Connection reset, restarting [0]
+Wed Apr 24 11:19:07 2019 SIGUSR1[soft,connection-reset] received, process restarting
+Wed Apr 24 11:19:07 2019 Restart pause, 5 second(s)
+```
+Android clients simply report: "Transport error, trying to reconnect..."
+> 
+
+On the OpenVPN server, the following messages are logged:
+```
+Wed Apr 24 11:19:07 2019 aaa.bbb.ccc.ddd:pppp TLS: Initial packet from [AF_INET]aaa.bbb.ccc.ddd:pppp, sid=57719cb8 77945ae9
+Wed Apr 24 11:19:07 2019 aaa.bbb.ccc.ddd:pppp VERIFY ERROR: depth=0, error=CRL has expired: CN=client1
+Wed Apr 24 11:19:07 2019 aaa.bbb.ccc.ddd:pppp OpenSSL: error:11089086:SSL routines:ssl3_get_client_certificate:certificate verify failed
+Wed Apr 24 11:19:07 2019 aaa.bbb.ccc.ddd:pppp TLS_ERROR: BIO read tls_read_plaintext error
+Wed Apr 24 11:19:07 2019 aaa.bbb.ccc.ddd:pppp TLS Error: TLS object -> incoming plaintext read error
+Wed Apr 24 11:19:07 2019 aaa.bbb.ccc.ddd:pppp TLS Error: TLS handshake failed
+Wed Apr 24 11:19:07 2019 aaa.bbb.ccc.ddd:pppp Fatal TLS error (check_tls_errors_co), restarting
+Wed Apr 24 11:19:07 2019 aaa.bbb.ccc.ddd:pppp SIGUSR1[soft,tls-error] received, client-instance restarting
+```
+The error is `CRL has expired` and can be solved using the following commands:
+```
+sudo -s
+cd /etc/openvpn
+mv crl.pem crl.pem_old
+cd easy-rsa
+./easyrsa gen-crl
+cp pki/crl.pem ../
+service openvpn restart
+exit
+```
diff --git a/mkdocs.yml b/mkdocs.yml
index 67ab6ce..3bdfe7a 100644
--- a/mkdocs.yml
+++ b/mkdocs.yml
@@ -96,6 +96,7 @@ nav:
- 'Optional: Dual operation: LAN & VPN at the same time': guides/vpn/dual-operation.md
- 'Optional: Full and DNS-only': guides/vpn/dual-VPN.md
- 'Optional: Dynamic DNS': guides/vpn/dynDNS.md
+ - 'Troubleshooting': guides/vpn/troubleshooting.md
- 'TOR & Pi-hole':
- 'Overview': guides/tor/overview.md
- 'Basic Setup': guides/tor/setup.md