Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    2.5 OpenVPN to 2.4.5 NCP Algorithms

    Scheduled Pinned Locked Moved 2.5 Development Snapshots (Retired)
    9 Posts 3 Posters 1.1k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • chpalmerC
      chpalmer
      last edited by

      Ive got a 2.5 box in the lab here on its own WAN. I have my primary 2.4.5 box connected to the 2.5 box over an OpenVPN connection.

      Using Shared Key.

      Using NCP Algorithms= AES-256-CBC The boxes will no longer connect to each other. (Its been a month or two. I have not worked with it since it stopped until now.)

      Camellia-256-CBC does work however. So I know its not a config issue.

      Triggering snowflakes one by one..
      Intel(R) Core(TM) i5-4590T CPU @ 2.00GHz on an M400 WG box.

      1 Reply Last reply Reply Quote 0
      • jimpJ
        jimp Rebel Alliance Developer Netgate
        last edited by

        There isn't nearly enough information to go by here. It's highly unlikely to be a problem with just that one cipher.

        Usually, though, in a case like that it turns out to be related to hardware crypto acceleration not working as expected with certain ciphers or certain key lengths.

        So the first thing to look at is the hardware and what options you have enabled in that regard.

        Also, use AES-128-GCM or AES-256-GCM if both sides support it (which since both are pfSense, they do).

        Remember: Upvote with the ๐Ÿ‘ button for any user/post you find to be helpful, informative, or deserving of recognition!

        Need help fast? Netgate Global Support!

        Do not Chat/PM for help!

        1 Reply Last reply Reply Quote 0
        • chpalmerC
          chpalmer
          last edited by chpalmer

          Sure. Just set up an whole new tunnel.

          2dot5testclient.jpg 2dot4dot5serverside.jpg Serverside2dot4dot5.jpg

          Not working.

          Dec 2 15:05:00 openvpn 49509 Bad compression stub (swap) decompression header byte: 40

          Dec 2 15:05:00 openvpn 49509 Bad compression stub (swap) decompression header byte: 42

          These two lines show up in the logs over and over.

          edit= I did go back and click the box on the client side "Enable Negotiable Cryptographic Paremeters"..

          I will do some more when I get back later. But as you can see all my other tunnels work fine. This was working a couple of months ago. What else do you want to see?

          Triggering snowflakes one by one..
          Intel(R) Core(TM) i5-4590T CPU @ 2.00GHz on an M400 WG box.

          1 Reply Last reply Reply Quote 0
          • jimpJ
            jimp Rebel Alliance Developer Netgate
            last edited by

            Those errors are from compression, not encryption. Make sure it's disabled on both.

            Remember: Upvote with the ๐Ÿ‘ button for any user/post you find to be helpful, informative, or deserving of recognition!

            Need help fast? Netgate Global Support!

            Do not Chat/PM for help!

            1 Reply Last reply Reply Quote 0
            • chpalmerC
              chpalmer
              last edited by

              Thanks Jimp! Ill get back to this over the weekend most likely.

              Is there anything that would have changed on 2.5 that you know of that would have possibly defaulted to something other than what was set before? Updating from one snap to a later one caused me to lose the connection with no changes from me.

              Just would like to know before I start updating to 2.5 release when it happens. :)

              Triggering snowflakes one by one..
              Intel(R) Core(TM) i5-4590T CPU @ 2.00GHz on an M400 WG box.

              1 Reply Last reply Reply Quote 0
              • jimpJ
                jimp Rebel Alliance Developer Netgate
                last edited by

                Not unless it was an older snapshot that didn't have OpenVPN 2.5.0 and now it does have OpenVPN 2.5.0 -- their defaults changed and behavior changed in various ways, especially with compression.

                Remember: Upvote with the ๐Ÿ‘ button for any user/post you find to be helpful, informative, or deserving of recognition!

                Need help fast? Netgate Global Support!

                Do not Chat/PM for help!

                1 Reply Last reply Reply Quote 0
                • RicoR
                  Rico LAYER 8 Rebel Alliance
                  last edited by

                  OpenVPN compression stuff is a bit messy for some time. ๐Ÿ˜

                  -Rico

                  jimpJ 1 Reply Last reply Reply Quote 0
                  • jimpJ
                    jimp Rebel Alliance Developer Netgate @Rico
                    last edited by

                    @rico said in 2.5 OpenVPN to 2.4.5 NCP Algorithms:

                    OpenVPN compression stuff is a bit messy for some time. ๐Ÿ˜

                    They have it pretty well straightened out in 2.5.0 from what I've seen.

                    Generally speaking it should be off for everyone everywhere since Compression+Encryption has been shown to be vulnerable to various attacks.

                    But on OpenVPN 2.5.0 they have a setting where it can accept compressed packets but it won't transmit them (so asymmetric) and it should interoperate with old clients while allowing them to transition to disabling encryption.

                    Remember: Upvote with the ๐Ÿ‘ button for any user/post you find to be helpful, informative, or deserving of recognition!

                    Need help fast? Netgate Global Support!

                    Do not Chat/PM for help!

                    1 Reply Last reply Reply Quote 1
                    • RicoR
                      Rico LAYER 8 Rebel Alliance
                      last edited by

                      I never managed to disable compression with our type of traffic tbh, still stuck with lz4-v2 and some Sites comp-lzo.
                      The day I disabled it turned out into horror with my phone ringing the whole day and people asking why the network is so terrible slow. ๐Ÿ˜–

                      -Rico

                      1 Reply Last reply Reply Quote 0
                      • First post
                        Last post
                      Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.