Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    VPN disconnects when applying a change

    Scheduled Pinned Locked Moved General pfSense Questions
    12 Posts 5 Posters 4.4k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • M
      marvosa
      last edited by

      The dev's can chime in, but I think every change restarts the service, so I don't see a way around it.

      1 Reply Last reply Reply Quote 0
      • jimpJ
        jimp Rebel Alliance Developer Netgate
        last edited by

        When you make changes to openvpn it restarts that instance of openvpn, no way to avoid that and have all of the settings properly apply.

        It doesn't restart all of them, so if you have 4 servers setup and edit 1 of them, only that one that was changed restarts.

        Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

        Need help fast? Netgate Global Support!

        Do not Chat/PM for help!

        1 Reply Last reply Reply Quote 0
        • G
          grahambmtw
          last edited by

          @jimp:

          When you make changes to openvpn it restarts that instance of openvpn, no way to avoid that and have all of the settings properly apply.

          It doesn't restart all of them, so if you have 4 servers setup and edit 1 of them, only that one that was changed restarts.

          That would make sense, but I get disconnected for non-openvpn setting changes. For example adding a certificate to a user or even changing some firewall rules which are not related to the openvpn connection.
          Furthermore, this does not happen every tie, it seems to be every other time I make a change that I get disconnected

          1 Reply Last reply Reply Quote 0
          • jimpJ
            jimp Rebel Alliance Developer Netgate
            last edited by

            That's not related to OpenVPN then.

            Check your gateways, if you have a gateway flagged as down, states can be cleared on any change that causes a filter reload.

            Fix the gateway, or if you have only one WAN, disable state killing for down gateways under System > Advanced on the Misc tab.

            Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

            Need help fast? Netgate Global Support!

            Do not Chat/PM for help!

            1 Reply Last reply Reply Quote 0
            • G
              grahambmtw
              last edited by

              @jimp:

              That's not related to OpenVPN then.

              Check your gateways, if you have a gateway flagged as down, states can be cleared on any change that causes a filter reload.

              Fix the gateway, or if you have only one WAN, disable state killing for down gateways under System > Advanced on the Misc tab.

              My gateway is okay,
              Would this have a negative effect since I'm using CARP, could it cause failovers to stop working etc?

              1 Reply Last reply Reply Quote 0
              • D
                doktornotor Banned
                last edited by

                @jimp:

                When you make changes to openvpn it restarts that instance of openvpn, no way to avoid that and have all of the settings properly apply.
                It doesn't restart all of them, so if you have 4 servers setup and edit 1 of them, only that one that was changed restarts.

                Well, I get a restart when I change the description field of the OVPN server. This for sure is not necessary.

                1 Reply Last reply Reply Quote 0
                • jimpJ
                  jimp Rebel Alliance Developer Netgate
                  last edited by

                  @doktornotor:

                  @jimp:

                  When you make changes to openvpn it restarts that instance of openvpn, no way to avoid that and have all of the settings properly apply.
                  It doesn't restart all of them, so if you have 4 servers setup and edit 1 of them, only that one that was changed restarts.

                  Well, I get a restart when I change the description field of the OVPN server. This for sure is not necessary.

                  To be pedantic, yes, but that requires a lot more complex code than currently exists. Patches accepted.

                  Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

                  Need help fast? Netgate Global Support!

                  Do not Chat/PM for help!

                  1 Reply Last reply Reply Quote 0
                  • jimpJ
                    jimp Rebel Alliance Developer Netgate
                    last edited by

                    @grahambmtw:

                    @jimp:

                    That's not related to OpenVPN then.

                    Check your gateways, if you have a gateway flagged as down, states can be cleared on any change that causes a filter reload.

                    Fix the gateway, or if you have only one WAN, disable state killing for down gateways under System > Advanced on the Misc tab.

                    My gateway is okay,
                    Would this have a negative effect since I'm using CARP, could it cause failovers to stop working etc?

                    No that option only affects Multi-WAN, not CARP.

                    Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

                    Need help fast? Netgate Global Support!

                    Do not Chat/PM for help!

                    1 Reply Last reply Reply Quote 0
                    • P
                      phil.davis
                      last edited by

                      There are lots of GUI config screens where pressing Save updates the config and restarts the relevant bit of the system. Most of it does not check closely exactly which data fields were changed. Yes, it would be handy if things didn't restart when just a description field (and other non-functional fields) are modified. As JimP suggests "Patches accepted" - it is an Open Source project, so feel free to contribute enhanced GUI validation, minimal restart processing… :)

                      As the Greek philosopher Isosceles used to say, "There are 3 sides to every triangle."
                      If I helped you, then help someone else - buy someone a gift from the INF catalog http://secure.inf.org/gifts/usd/

                      1 Reply Last reply Reply Quote 0
                      • G
                        grahambmtw
                        last edited by

                        @jimp:

                        That's not related to OpenVPN then.

                        Check your gateways, if you have a gateway flagged as down, states can be cleared on any change that causes a filter reload.

                        Fix the gateway, or if you have only one WAN, disable state killing for down gateways under System > Advanced on the Misc tab.

                        Thanks!
                        This fixed the issue, I'll conduct a firewall failover test to 100% ensure that CARP failover still works

                        1 Reply Last reply Reply Quote 0
                        • G
                          grahambmtw
                          last edited by

                          Actually, this is still an issue. Applying firewall rules, or almost any update will kill existing connections including my OpenVPN connection to the firewall requiring me to reconnect..

                          1 Reply Last reply Reply Quote 0
                          • First post
                            Last post
                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.