Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    pfsense 2.6.0 system logs message OpenVPN failed to start

    Scheduled Pinned Locked Moved OpenVPN
    20 Posts 3 Posters 1.7k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • V
      viragomann @Jonas Souza
      last edited by viragomann

      @Jonas-Souza
      Your advanced setting are wrong. You have to separate the push command by a semicolon.
      Further the first address is wrong. It must be the network address.

      But anyway, instead of putting the push command into the custom options, you should rather state them at "Local networks".
      So the field should look like this:

      100.120.1.0/24,10.210.1.0/24
      

      And empty the custom options, of course.

      J GertjanG 3 Replies Last reply Reply Quote 0
      • J
        Jonas Souza @viragomann
        last edited by

        @viragomann

        Adjusting the settings you mentioned, it worked perfectly. Thank you very much

        1 Reply Last reply Reply Quote 0
        • GertjanG
          Gertjan @viragomann
          last edited by Gertjan

          @viragomann said in pfsense 2.6.0 system logs message OpenVPN failed to start:

          And empty the custom options, of course.

          👍

          The perfect custom settings :

          c20b086d-a30a-4d1c-974c-749e1b32d853-image.png

          Using that for several years now, just great. Easy to maintain.

          Btw : Because my tunnel network is 192.168.3.0/24 (an available local RFC1918) :
          You saw my :

          <29>1 2023-06-29T14:36:58.442476+02:00 pfs.bhf.net openvpn 93453 - - /sbin/ifconfig ovpns1 192.168.3.1/24 mtu 1500 up
          

          Because :

          8fde2302-599a-488c-944b-d06e7c66e7d0-image.png

          edit :

          In case you didn't do so already :
          Assign the OpenVPN server instnce interface to a new interface - I called mine 'OPENVPN'.

          1b5b30e4-0227-479b-8bf4-bb83c2bc8dbb-image.png

          Then : activate it :

          7e5e89a6-aa3f-4bf8-bbdf-94297776b663-image.png

          (nothing more to do there)

          Add some rule on the Interface OPENVPN (otherwise nothing can gets in).
          This one will do just fine :

          7fed92be-9283-4a84-89d2-8dd263a14b33-image.png

          Then, pay a visit to the Resolver (DNS !) and make sure it listens to All incoming interfaces.
          Or at least all incoming interfaces - 'OPENVPN' included :

          f9cc4c88-f366-4445-8df4-6bad36e38ee1-image.png

          Finally : even if they are years old now, do visit Youtube. Go to the Netgate Channel and re-watch the 3 official OpenVPN (server) video's. It's worth it.

          No "help me" PM's please. Use the forum, the community will thank you.
          Edit : and where are the logs ??

          1 Reply Last reply Reply Quote 0
          • J
            Jonas Souza @viragomann
            last edited by

            @viragomann @Gertjan

            Now I'm having another problem, here's the screenshot.

            OpenVPN service is online.

            What can it be?

            2023-06-29_10-29.png
            2023-06-29_10-19.png

            V 1 Reply Last reply Reply Quote 0
            • V
              viragomann @Jonas Souza
              last edited by

              @Jonas-Souza
              Mostly this error means that the client cannot reach the server.
              The server IP is correct in the client settings?

              Check the firewall log on the server if it has blocked the packets.
              Or run a packet capture on WAN to see if the packets arrive at all.

              J 1 Reply Last reply Reply Quote 0
              • J
                Jonas Souza @viragomann
                last edited by

                @viragomann

                Yes, the ip is correct, follow the client's log.

                Would it be a problem with the certificates now?

                2023-06-29_10-53.png
                2023-06-29_10-52.png

                V 1 Reply Last reply Reply Quote 0
                • V
                  viragomann @Jonas Souza
                  last edited by

                  @Jonas-Souza
                  Yes, as the server log shows, there is something wrong with the certificate verification.

                  Is the client certificate issued by the CA, which you stated in the server settings?

                  J 1 Reply Last reply Reply Quote 0
                  • J
                    Jonas Souza @viragomann
                    last edited by

                    @viragomann

                    Perfectly, I redid the user CA and it worked.

                    Many thanks for the instructions.

                    Excuse my ignorance, but how and where do I consider this topic resolved?

                    V 1 Reply Last reply Reply Quote 0
                    • V
                      viragomann @Jonas Souza
                      last edited by

                      @Jonas-Souza
                      Just edit the topic in the first post and put "[SOLVED]" in front of it.

                      J 1 Reply Last reply Reply Quote 1
                      • J
                        Jonas Souza @viragomann
                        last edited by

                        @viragomann

                        sorry but when editing the post notifies this warning.

                        2023-06-29_11-58.png

                        V 1 Reply Last reply Reply Quote 0
                        • V
                          viragomann @Jonas Souza
                          last edited by

                          @Jonas-Souza
                          Obviously there is a lock now for editing old posts.
                          Do you have access to the topic in the most recent?

                          J 1 Reply Last reply Reply Quote 0
                          • J
                            Jonas Souza @viragomann
                            last edited by

                            @viragomann

                            From the last post yes, but I can't edit the title of the post.

                            2023-06-29_12-13.png

                            V 1 Reply Last reply Reply Quote 0
                            • V
                              viragomann @Jonas Souza
                              last edited by

                              @Jonas-Souza
                              Sorry, so I can't sadly help you with that. Obviously the forum haves different now. Don't now what's actually the proper way to mark a topic as solved.

                              J 1 Reply Last reply Reply Quote 1
                              • J
                                Jonas Souza @viragomann
                                last edited by

                                @viragomann

                                I reposted, thanks

                                https://forum.netgate.com/topic/181119/solved-pfsense-2-6-0-system-logs-message-openvpn-failed-to-start

                                1 Reply Last reply Reply Quote 0
                                • First post
                                  Last post
                                Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.