Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    OpenVPN client connections get dropped when rc.filter_configure_sync script runs (every 15min from crontab)

    Scheduled Pinned Locked Moved OpenVPN
    15 Posts 2 Posters 1.2k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • ?
      A Former User @Dael Sutton
      last edited by

      @dael-sutton said in OpenVPN client connections get dropped when rc.filter_configure_sync script runs (every 15min from crontab):

      WARNING: 'link-mtu' is used inconsistently, local='link-mtu 1571', remote='link-mtu 1555'

      1571 and 1555 ??

      1 Reply Last reply Reply Quote 0
      • D
        Dael Sutton
        last edited by

        Not sure what to do about that message, to be honest. It logs when the connection establishes, but everything appears to work fine, except for the disconnects with 'Permission denied (code=13)' on the quarter hour.

        ? 1 Reply Last reply Reply Quote 0
        • ?
          A Former User @Dael Sutton
          last edited by

          @dael-sutton Are there any firewall logs for that endpoint?

          D 1 Reply Last reply Reply Quote 0
          • D
            Dael Sutton @A Former User
            last edited by

            @silence Nothing form the endpoint, however I was ssh'd in watching the filter.log;
            Feb 9 14:44:57 firewalk3 filterlog[26048]: 135,,,1593745551,em2,match,pass,in,4,0x0,,128,37015,0,DF,6,tcp,52,192.168.2.13,172.16.0.24,51278,3050,0,S,1825821203,,64240,,mss;nop;wscale;nop;nop;sackOK
            Feb 9 14:44:57 firewalk3 filterlog[26048]: 135,,,1593745551,em2,match,pass,in,4,0x0,,128,37016,0,DF,6,tcp,52,192.168.2.13,172.16.0.24,51278,3050,0,S,1825821203,,64240,,mss;nop;wscale;nop;nop;sackOK
            Feb 9 14:45:00 firewalk3 filterlog[26048]: 8,,,1000000103,ovpns1,match,block,in,4,0x0,,128,37102,0,DF,6,tcp,52,10.11.1.7,172.16.0.19,56913,9191,0,S,382678354,,64240,,mss;nop;wscale;nop;nop;sackOK
            Feb 9 14:45:00 firewalk3 filterlog[26048]: 8,,,1000000103,ovpns1,match,block,in,4,0x0,,128,3652,0,DF,6,tcp,52,10.11.1.7,172.16.0.18,56914,631,0,S,2428094745,,64240,,mss;nop;wscale;nop;nop;sackOK

            and when the clock ticked 14:45:00 those two entries flicked past and my ssh connection got disconnected.
            So it's probably nothing to do with OpenVPN and more to do with the firewall/filter stopping & starting and resetting all connections on the 15min. :(

            ? 1 Reply Last reply Reply Quote 0
            • ?
              A Former User @Dael Sutton
              last edited by

              @dael-sutton What services do you have in your pfsense?

              like pfblockerng?

              D 1 Reply Last reply Reply Quote 0
              • D
                Dael Sutton @A Former User
                last edited by

                Just these;
                9ed5456d-78ab-48b7-9ff9-7d86bd0c563e-image.png

                ssh is normally disabled.

                D 1 Reply Last reply Reply Quote 0
                • D
                  Dael Sutton @Dael Sutton
                  last edited by

                  Could this be doing it?
                  d0ca28c7-b066-4c18-b50b-e24fb4eab829-image.png

                  ? 1 Reply Last reply Reply Quote 0
                  • ?
                    A Former User @Dael Sutton
                    last edited by

                    @dael-sutton said in OpenVPN client connections get dropped when rc.filter_configure_sync script runs (every 15min from crontab):

                    Could this be doing it?

                    show you gateway !

                    D 1 Reply Last reply Reply Quote 0
                    • D
                      Dael Sutton @A Former User
                      last edited by

                      d5df12bf-ac98-442d-94cd-3e992118d3fa-image.png
                      7ef7d625-97b5-41fd-880c-acd21d9085bd-image.png
                      No gateway groups defined.
                      none of the gateways should be detected as "down" when the filter reloads, but maybe I should disable that tickbox and see what happens....

                      D 1 Reply Last reply Reply Quote 0
                      • D
                        Dael Sutton @Dael Sutton
                        last edited by

                        Yee-Haa. Unticking that "flush all states" tickbox seems to have done the trick. Thankyou @Silence for your patience while I grabbed at straws until the correct one appeared. 15:15 came and went and my test openvpv connection didn't drop, and my ssh session stayed running too.

                        ? 1 Reply Last reply Reply Quote 0
                        • ?
                          A Former User @Dael Sutton
                          last edited by

                          @dael-sutton said in OpenVPN client connections get dropped when rc.filter_configure_sync script runs (every 15min from crontab):

                          Yee-Haa. Unticking that "flush all states" tickbox seems to have done the trick. Thankyou @Silence for your patience while I grabbed at straws until the correct one appeared. 15:15 came and went and my test openvpv connection didn't drop, and my ssh session stayed running too.

                          Don't forget to like the comment that helped you.

                          1 Reply Last reply Reply Quote 0
                          • First post
                            Last post
                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.