Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Solved: OpenVPN reconnect AUTH_FAILED

    Scheduled Pinned Locked Moved OpenVPN
    15 Posts 8 Posters 53.5k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • B
      bcruze
      last edited by

      what service are you connecting too?

      have you opened the opvn configuration file and matched it with your configuration?

      1 Reply Last reply Reply Quote 0
      • D
        downundermate
        last edited by

        I found a solution. It looks like a bug in OpenVPN.
        You need to add:

        pull-filter ignore "auth-token"
        

        After that client reconnects smoothly.
        More reading:
        https://www.privateinternetaccess.com/forum/discussion/24089/inactivity-timeout-ping-restart#latest
        https://www.snbforums.com/threads/how-to-setup-a-vpn-client-including-policy-rules-for-pia-and-other-vpn-providers-380-68-09-12.30851/page-24

        1 Reply Last reply Reply Quote 0
        • B
          bcruze
          last edited by

          correct i use the same command.  also if you follow the opvn file you can get rid of these messages as well:
          Mar 18 00:09:29 pfsense openvpn[61368]: WARNING: 'link-mtu' is used inconsistently, local='link-mtu 1558', remote='link-mtu 1542'
          Mar 18 00:09:29 pfsense openvpn[61368]: WARNING: 'cipher' is used inconsistently, local='cipher AES-128-CBC', remote='cipher BF-CBC'

          1 Reply Last reply Reply Quote 0
          • D
            downundermate
            last edited by

            @bcruze:

            correct i use the same command.  also if you follow the opvn file you can get rid of these messages as well:
            Mar 18 00:09:29 pfsense openvpn[61368]: WARNING: 'link-mtu' is used inconsistently, local='link-mtu 1558', remote='link-mtu 1542'
            Mar 18 00:09:29 pfsense openvpn[61368]: WARNING: 'cipher' is used inconsistently, local='cipher AES-128-CBC', remote='cipher BF-CBC'

            "Get rid of" log entries or actually solving it?
            To remove warnings from log file I can use:

            disable-occ
            
            1 Reply Last reply Reply Quote 0
            • B
              bcruze
              last edited by

              try adding:

              resolv-retry infinite
              persist-key
              persist-tun
              cipher aes-128-cbc
              auth sha128
              tls-client
              remote-cert-tls server
              reneg-sec 0

              i had to take several out as it would not allow the connection to start.  so play with it and see what works best for yours.    this is the strong encryption for PIA

              client
              dev tun
              proto udp
              remote us-newyorkcity.privateinternetaccess.com 1197
              resolv-retry infinite
              nobind
              persist-key
              persist-tun
              cipher aes-256-cbc
              auth sha256
              tls-client
              remote-cert-tls server
              auth-user-pass
              comp-lzo
              verb 1
              reneg-sec 0
              crl-verify crl.rsa.4096.pem
              ca ca.rsa.4096.crt
              disable-occ

              1 Reply Last reply Reply Quote 0
              • D
                downundermate
                last edited by

                Yes, it's all standard except for the "disable-occ".
                But my problem was with missing

                pull-filter ignore "auth-token"
                
                1 Reply Last reply Reply Quote 0
                • M
                  Motleycru
                  last edited by

                  NordVPN issue solved
                  Yesterday (6-28-2023), my Glinet AXT1800 stopped connecting with the same "Auth Failed" issue in the log file. I found the solution to be:

                  1. Disable the OpenVPN at the dashboard (to gain internet access)
                  2. Go to NordVPN website and log in
                  3. Under accounts - Services - click NordVPN
                  4. Click - Set up NordVPN manually - at the bottom right of the page.
                  5. You will receive a verification code in your email that you use for NordVPN services. Type the code in the popup window the preceded the email check.
                  6. Copy the credentials using the “Copy” buttons on the right for your new encrypted user name and password in the OpenVPN Client settings.

                  You will now be able to connect again

                  GertjanG E H N V 5 Replies Last reply Reply Quote 5
                  • GertjanG
                    Gertjan @Motleycru
                    last edited by

                    @Motleycru said in Solved: OpenVPN reconnect AUTH_FAILED:

                    for your new encrypted user name and password

                    Wait ....
                    'They' changed the user login and password on their side, not notifing you ?
                    Serious ?

                    😰

                    No "help me" PM's please. Use the forum, the community will thank you.
                    Edit : and where are the logs ??

                    M 1 Reply Last reply Reply Quote 0
                    • M
                      Motleycru @Gertjan
                      last edited by

                      @Gertjan for the router login, they changed it and did not notify me.

                      1 Reply Last reply Reply Quote 1
                      • E
                        eICHiZ @Motleycru
                        last edited by

                        @Motleycru GREAT!! Many thanks for the hint, and this solved it for me as well. Not knowing that they changed the way to authenticate for OpenVPN

                        1 Reply Last reply Reply Quote 0
                        • H
                          hadlem @Motleycru
                          last edited by

                          @Motleycru
                          Thanks. This approach worked instantly for me.

                          1 Reply Last reply Reply Quote 0
                          • N
                            Norm @Motleycru
                            last edited by

                            @Motleycru Bravo, well done, I had no idea Nord had done this. Your steps worked perfectly for me straight away. (I had already upgraded my router firmware and vpn-openssl packages!)

                            1 Reply Last reply Reply Quote 0
                            • V
                              venkidas @Motleycru
                              last edited by

                              @Motleycru oh my oh my ...man ....thank you so so so much....so unbeliable....i wasted about 6 hours tying to debug this shit. i was so frustuated and wanted to wack someone from norde, GL-Inet or dd-wrt ...what a mess .... a simple code comment on some screen would have saved 1000's of hours of peoples time. some one deserves to wacked serously. but thank you so so much. i can get some sleep now

                              1 Reply Last reply Reply Quote 0
                              • First post
                                Last post
                              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.