Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    OTP and OpenVPN disconnects

    Scheduled Pinned Locked Moved OpenVPN
    2 Posts 1 Posters 621 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • M
      michmoor LAYER 8 Rebel Alliance
      last edited by michmoor

      [edit] - this is on an iPhone.

      I have OTP configured on the pfsense side. Radius for authentication. Through radius I have set up OTP. I have added the extra step of putting in 'reneg-sec 0' within the server settings to prevent reneg ever hour.
      I am able to successfully authenticate using PIN + authcode but after about a minute I am disconnected with an authentication failure. VPN logs are indicating the failure reason which is great but I still do not know why its seeking a new pin + authcode every minute or so.

      Mar 30 10:44:25 openvpn 45698 x.x.x.x11758 SIGTERM[soft,delayed-exit] received, client-instance exiting
      Mar 30 10:44:19 openvpn 45698 x.x.x.x:11758 SENT CONTROL [michmoor]: 'AUTH_FAILED' (status=1)

      Firewall: NetGate,Palo Alto-VM,Juniper SRX
      Routing: Juniper, Arista, Cisco
      Switching: Juniper, Arista, Cisco
      Wireless: Unifi, Aruba IAP
      JNCIP,CCNP Enterprise

      M 1 Reply Last reply Reply Quote 0
      • M
        michmoor LAYER 8 Rebel Alliance @michmoor
        last edited by

        @michmoor Ok i think i figured it out. I think..
        When the phone or any device goes idle, and authentication happens again it fails obviously because the authcode changed as well.

        Is there an option that will pick up where you left off ' resume the connection again.

        On more corporate environments I have worked in, that is a feature with a hard time out of 24hrs so there is a user convenience factor to all of this.

        Firewall: NetGate,Palo Alto-VM,Juniper SRX
        Routing: Juniper, Arista, Cisco
        Switching: Juniper, Arista, Cisco
        Wireless: Unifi, Aruba IAP
        JNCIP,CCNP Enterprise

        1 Reply Last reply Reply Quote 0
        • First post
          Last post
        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.