Welcome,
Guest
. Please
login
or
register
.
Did you miss your
activation email?
pfSense Forum
pfSense English Support
»
OpenVPN
»
Unable to maintain an OpenVPN connection longer than 3 seconds.
Username:
Password:
1 Hour
1 Day
1 Week
1 Month
Forever
Home
Help
Search
Login
Register
Pages: [
1
]
Go Down
« previous
next »
Print
Author
Topic: Unable to maintain an OpenVPN connection longer than 3 seconds. (Read 553 times)
0 Members and 1 Guest are viewing this topic.
see2k
Newbie
Offline
Posts: 1
Unable to maintain an OpenVPN connection longer than 3 seconds.
«
on:
June 21, 2012, 04:44:22 pm »
Hello group,
I will try to make this as detailed as possible.
Brief history, IN march of 2012, i had to reissue new server certs because the existing one's had expired. I reissued the new server certs to the pfsense openvpn, and generated new certs for my users who had to have their keys renewed. All was well until April, when 1 then 2 then more engineers began to experience brief connection periods and then get disconnected randomly.
At first, the OpenVPN connection would last for a few hours, then an hour, then down to 1 minute, and now finally I am only able to stay connected 3 seconds before the VPN tunnel is broken. This is identical to the problems my users are experiencing as well. The logs (which I will add below) show no particular reason why the disconnection is occuring.
No firewall changes have been made (ever) and the server doesn't have a duplicate IP issue.
Interestingly enough my site-to-site vpn users have had no problems before or after the Cert updates and continue to function without any issues. The users who are having problems are those who are using their public/private certs with server public cert connections via network managers (in ubuntu and fedora) or are using the Command line/configuration based mechanism.
I have attached the logs, however, Pfsense openvpn logs doesn't show anything other than a connection attempt from the client.
I'm lost and have no idea why the vpn will no longer service a connection for more than 3 seconds?
Thank you for any help, and I can provide any information.
Logged
cmb
Administrator
Hero Member
Offline
Posts: 6119
Re: Unable to maintain an OpenVPN connection longer than 3 seconds.
«
Reply #1 on:
June 21, 2012, 06:16:58 pm »
The server log would probably be more telling than the client's log. That sounds like what happens when multiple clients are sharing a cert, one connects and knocks off another, then that one reconnects and knocks off the previous, over and over.
Logged
pfSense Commercial Support
Paying customers receive support priority and as in depth of assistance as desired through the official commercial support channels at portal.pfsense.org. Forum users receive as much help as time permits.
Pages: [
1
]
Go Up
Print
« previous
next »
Jump to:
Please select a destination:
-----------------------------
Administrative
-----------------------------
=> Forum rules
=> Messages from the pfSense Team
=> Feedback
-----------------------------
pfSense English Support
-----------------------------
=> Installation and Upgrades
=> General Questions
=> 2.1 Snapshot Feedback and Problems
=> Post a bounty
===> Completed Bounties
===> Expired/Withdrawn Bounties
=> Hardware
=> Firewalling
=> NAT
=> CARP/VIPs
=> Routing and Multi WAN
=> Traffic Shaping
=> DHCP and DNS
=> IPv6
=> IPsec
=> PPTP
=> PPPoE Server
=> Captive Portal
=> webGUI
=> Wireless
=> SNMP
=> Packages
=> Virtualization installations and techniques
=> OpenVPN
=> Gaming
-----------------------------
Development/Documentation
-----------------------------
=> Documentation
=> Development
-----------------------------
General Category
-----------------------------
=> General Discussion
-----------------------------
International Support
-----------------------------
=> Indonesian
=> Deutsch
=> Español
=> Français
=> Italiano
=> Russian
=> Nederlands
=> Norwegian
=> Portuguese
=> Polish
=> Romanian
=> Swedish
=> Turkish
-----------------------------
Retired
-----------------------------
=> 1.2.3-PRERELEASE-TESTING snapshots - RETIRED
=> 1.2.1-RC Snapshot Feedback and Problems-RETIRED
=> 2.0-RC Snapshot Feedback and Problems - RETIRED
=> DNS Server testing area - RETIRED
Loading...