Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    OpenVPN client connections get dropped when rc.filter_configure_sync script runs (every 15min from crontab)

    Scheduled Pinned Locked Moved OpenVPN
    15 Posts 2 Posters 1.2k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • D
      Dael Sutton
      last edited by

      Not sure what to do about that message, to be honest. It logs when the connection establishes, but everything appears to work fine, except for the disconnects with 'Permission denied (code=13)' on the quarter hour.

      ? 1 Reply Last reply Reply Quote 0
      • ?
        A Former User @Dael Sutton
        last edited by

        @dael-sutton Are there any firewall logs for that endpoint?

        D 1 Reply Last reply Reply Quote 0
        • D
          Dael Sutton @A Former User
          last edited by

          @silence Nothing form the endpoint, however I was ssh'd in watching the filter.log;
          Feb 9 14:44:57 firewalk3 filterlog[26048]: 135,,,1593745551,em2,match,pass,in,4,0x0,,128,37015,0,DF,6,tcp,52,192.168.2.13,172.16.0.24,51278,3050,0,S,1825821203,,64240,,mss;nop;wscale;nop;nop;sackOK
          Feb 9 14:44:57 firewalk3 filterlog[26048]: 135,,,1593745551,em2,match,pass,in,4,0x0,,128,37016,0,DF,6,tcp,52,192.168.2.13,172.16.0.24,51278,3050,0,S,1825821203,,64240,,mss;nop;wscale;nop;nop;sackOK
          Feb 9 14:45:00 firewalk3 filterlog[26048]: 8,,,1000000103,ovpns1,match,block,in,4,0x0,,128,37102,0,DF,6,tcp,52,10.11.1.7,172.16.0.19,56913,9191,0,S,382678354,,64240,,mss;nop;wscale;nop;nop;sackOK
          Feb 9 14:45:00 firewalk3 filterlog[26048]: 8,,,1000000103,ovpns1,match,block,in,4,0x0,,128,3652,0,DF,6,tcp,52,10.11.1.7,172.16.0.18,56914,631,0,S,2428094745,,64240,,mss;nop;wscale;nop;nop;sackOK

          and when the clock ticked 14:45:00 those two entries flicked past and my ssh connection got disconnected.
          So it's probably nothing to do with OpenVPN and more to do with the firewall/filter stopping & starting and resetting all connections on the 15min. :(

          ? 1 Reply Last reply Reply Quote 0
          • ?
            A Former User @Dael Sutton
            last edited by

            @dael-sutton What services do you have in your pfsense?

            like pfblockerng?

            D 1 Reply Last reply Reply Quote 0
            • D
              Dael Sutton @A Former User
              last edited by

              Just these;
              9ed5456d-78ab-48b7-9ff9-7d86bd0c563e-image.png

              ssh is normally disabled.

              D 1 Reply Last reply Reply Quote 0
              • D
                Dael Sutton @Dael Sutton
                last edited by

                Could this be doing it?
                d0ca28c7-b066-4c18-b50b-e24fb4eab829-image.png

                ? 1 Reply Last reply Reply Quote 0
                • ?
                  A Former User @Dael Sutton
                  last edited by

                  @dael-sutton said in OpenVPN client connections get dropped when rc.filter_configure_sync script runs (every 15min from crontab):

                  Could this be doing it?

                  show you gateway !

                  D 1 Reply Last reply Reply Quote 0
                  • D
                    Dael Sutton @A Former User
                    last edited by

                    d5df12bf-ac98-442d-94cd-3e992118d3fa-image.png
                    7ef7d625-97b5-41fd-880c-acd21d9085bd-image.png
                    No gateway groups defined.
                    none of the gateways should be detected as "down" when the filter reloads, but maybe I should disable that tickbox and see what happens....

                    D 1 Reply Last reply Reply Quote 0
                    • D
                      Dael Sutton @Dael Sutton
                      last edited by

                      Yee-Haa. Unticking that "flush all states" tickbox seems to have done the trick. Thankyou @Silence for your patience while I grabbed at straws until the correct one appeared. 15:15 came and went and my test openvpv connection didn't drop, and my ssh session stayed running too.

                      ? 1 Reply Last reply Reply Quote 0
                      • ?
                        A Former User @Dael Sutton
                        last edited by

                        @dael-sutton said in OpenVPN client connections get dropped when rc.filter_configure_sync script runs (every 15min from crontab):

                        Yee-Haa. Unticking that "flush all states" tickbox seems to have done the trick. Thankyou @Silence for your patience while I grabbed at straws until the correct one appeared. 15:15 came and went and my test openvpv connection didn't drop, and my ssh session stayed running too.

                        Don't forget to like the comment that helped you.

                        1 Reply Last reply Reply Quote 0
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.