Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    OpenVPN bad routing after 2.4 upgrade

    Scheduled Pinned Locked Moved OpenVPN
    7 Posts 2 Posters 1.1k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • S
      snowfirealpha
      last edited by

      I upgraded from 2.3.4 to 2.4 (working VPN service running on subnet 192.168.3.0/24), and then promptly lost internet access.

      After looking through the configuration, I noticed a route had been generated for destination 0.0.0.0 gateway 192.168.3.1, meaning all traffic was attempting to be routed through 192.168.3.1.

      I disabled the OpenVPN server and rebooted, and the route no longer existed.  I reenabled the OpenVPN server and the same behavior popped up with the same route.

      I then deleted the OpenVPN server, verified the route did not exist, then recreated the VPN server.  The same route popped up and internet access again was broken.

      Thoughts on what might be happening?

      1 Reply Last reply Reply Quote 0
      • DerelictD
        Derelict LAYER 8 Netgate
        last edited by

        Your OpenVPN server is misconfigured?

        You're going to have to post more info. There are thousands of OpenVPN servers that aren't doing that.

        Start with the OpenVPN Server configuration screens I would think.

        Chattanooga, Tennessee, USA
        A comprehensive network diagram is worth 10,000 words and 15 conference calls.
        DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
        Do Not Chat For Help! NO_WAN_EGRESS(TM)

        1 Reply Last reply Reply Quote 0
        • S
          snowfirealpha
          last edited by

          Config attached (pre-save)

          ovpn1.png
          ovpn1.png_thumb
          ovpn2.png
          ovpn2.png_thumb
          ovpn3.png
          ovpn3.png_thumb

          1 Reply Last reply Reply Quote 0
          • DerelictD
            Derelict LAYER 8 Netgate
            last edited by

            OK how about your routing table after that server is created?

            Feel free to PM if it makes you more comfortable.

            netstat -rnfinet

            Or Diagnostics > Routes

            Chattanooga, Tennessee, USA
            A comprehensive network diagram is worth 10,000 words and 15 conference calls.
            DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
            Do Not Chat For Help! NO_WAN_EGRESS(TM)

            1 Reply Last reply Reply Quote 0
            • S
              snowfirealpha
              last edited by

              Thank you for your help!

              Attached - before, and after.

              ipv4befored.png
              ipv4befored.png_thumb
              ipv4afterd.png
              ipv4afterd.png_thumb

              1 Reply Last reply Reply Quote 0
              • S
                snowfirealpha
                last edited by

                I also misinterpreted the /1 as a /24 when I was looking for the 0.0.0.0, so my original statement was incorrect.  Still, no internet when this routing is active.  :(

                1 Reply Last reply Reply Quote 0
                • DerelictD
                  Derelict LAYER 8 Netgate
                  last edited by

                  Those are not placed by an OpenVPN server but by an OpenVPN client connecting to a server. Did you assign an interface? Add outbound NAT?

                  Chattanooga, Tennessee, USA
                  A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                  DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                  Do Not Chat For Help! NO_WAN_EGRESS(TM)

                  1 Reply Last reply Reply Quote 0
                  • First post
                    Last post
                  Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.