Netgate m1n1wall

Author Topic: ovpns -> OPT interface netmask error  (Read 1475 times)

0 Members and 1 Guest are viewing this topic.

Offline m.algoe

  • Newbie
  • *
  • Posts: 15
    • View Profile
ovpns -> OPT interface netmask error
« on: May 11, 2012, 01:42:25 am »
When assigning ovpns port to OPT interface, even though the tunnel network is configured as /30 the OPT interface gets a /32.

The tunnel works fine (passes traffic as expected) but I cannot assign a gateway on the remote site since the remote tunnel IP is not in the OPT interface network. "The gateway address 192.168.17.2 does not lie within the chosen interface's subnet '192.168.xx.1/32'."
If i go to Status -> Interfaces the OPT interface is listed with netmask 255.255.255.255.
In VPN -> OpenVPN -> Edit server the IPv4 tunnel network has a /30 mask.

I'm running the latest version:
2.1-DEVELOPMENT (amd64)
built on Thu May 10 13:27:30 EDT 2012
FreeBSD 8.3-RELEASE-p1

The remote site is running 2.0.1 and seems to have the same netmask listed (255.255.255.255) but it automatically added a gateway on the local site when assigned an OPT interface.

Offline jimp

  • Administrator
  • Hero Member
  • *****
  • Posts: 14934
    • View Profile
Re: ovpns -> OPT interface netmask error
« Reply #1 on: May 15, 2012, 09:35:58 am »
If you assign an OpenVPN interface, *never* give it an IP. Set it to an IP type of "none".

You can't add a gateway for policy routing to an OpenVPN server that way. A client gets an automatic gateway, not sure we we don't do the same for a server if it's shared key or a /30 though.

If you need to route via OpenVPN, add a route statement into OpenVPN's config, don't rely on system gateways.
Need help fast? Commercial Support!

Co-Author of pfSense: The Definitive Guide. - Check the Doc Wiki for FAQs.

Do not PM for help!

Offline m.algoe

  • Newbie
  • *
  • Posts: 15
    • View Profile
Re: ovpns -> OPT interface netmask error
« Reply #2 on: May 19, 2012, 02:59:26 pm »
I set it to none, but in the listing it gets assigned the openvpn automatically.

The reason for wanting to add a gateway on the server towards the client is that it is a site-to-site tunnel with multiple networks on both sides and i thought it'd be easier to add routes under System -> Routing.

What I'd really like is to use some routing protocol but I'm having some trouble getting any of them to work. Not sure if it's 2.1 or me  ;D

Offline jimp

  • Administrator
  • Hero Member
  • *****
  • Posts: 14934
    • View Profile
Re: ovpns -> OPT interface netmask error
« Reply #3 on: May 19, 2012, 08:16:46 pm »
Never, ever add routes for OpenVPN to system > routing -- always do those with route statements in OpenVPN's config.

Quagga-OSPF works fine on 2.1, though you may have to manually "pkg_add -r quagga" from the shell if it doesn't actually install the binaries properly.
Need help fast? Commercial Support!

Co-Author of pfSense: The Definitive Guide. - Check the Doc Wiki for FAQs.

Do not PM for help!

Offline m.algoe

  • Newbie
  • *
  • Posts: 15
    • View Profile
Re: ovpns -> OPT interface netmask error
« Reply #4 on: May 21, 2012, 02:01:02 am »
OK, I'll give Quagga a try.

What is the reason for never, ever adding OpenVPN routes in system -> routing? The only reason i can think of is dead routes if the tunnel goes down, but isn't that handled by gateway up/down detection?

Edit: thanks for the add_pkg -r tip, that worked wonders!
Now I've got some OSPF problems, but I'll keep them in the packages-forum (http://forum.pfsense.org/index.php/topic,49648.0.html) :)
« Last Edit: May 21, 2012, 02:54:08 am by m.algoe »

Offline jimp

  • Administrator
  • Hero Member
  • *****
  • Posts: 14934
    • View Profile
Re: ovpns -> OPT interface netmask error
« Reply #5 on: May 21, 2012, 10:20:29 am »
The tun interfaces handled by OpenVPN are special. They don't do link detection like normal interfaces do. The gateway detection might get certain things right, but there are situations you could fall into where the routes may not properly be reapplied if the service was started and stopped. Plus, it's a lot more overhead to add those to the GUI than just simply add a route statement to OpenVPN.

Need help fast? Commercial Support!

Co-Author of pfSense: The Definitive Guide. - Check the Doc Wiki for FAQs.

Do not PM for help!

Offline m.algoe

  • Newbie
  • *
  • Posts: 15
    • View Profile
Re: ovpns -> OPT interface netmask error
« Reply #6 on: May 23, 2012, 08:34:41 am »
Thanks for the info :)

A problem i seem to get a lot with 2.1 is that every change, for example now adding route statements to the openvpn config, requires a restart to work properly. The tunnel got disconnected/reconnected when i changed the config, but then only the last route statement was applied and all others ignored. Reboot fixed it.
I had some problems getting ospf working, but after a couple of reboots it worked fine. (that and the pkg_add -r stuff, thanks again :) )

Offline jimp

  • Administrator
  • Hero Member
  • *****
  • Posts: 14934
    • View Profile
Re: ovpns -> OPT interface netmask error
« Reply #7 on: May 23, 2012, 08:41:12 am »
Hmm, when you edit/save OpenVPN it should restart that instance. Even if that doesn't, you can use Status > Services to stop and restart the VPN instance.

If you had any static routes or gateways defined that should really be in the VPN config you will want to remove those, as that's probably the source of the issue with needing to reboot to fix the routing table.

(side note: quagga should be better now)
Need help fast? Commercial Support!

Co-Author of pfSense: The Definitive Guide. - Check the Doc Wiki for FAQs.

Do not PM for help!