Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    OpenVPN client showing 100% packetloss following 2.5.0 upgrade

    Scheduled Pinned Locked Moved OpenVPN
    69 Posts 13 Posters 15.3k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • R
      RumMonkey69 @NeVaR
      last edited by RumMonkey69

      @nevar also same

      8372eae0-5d07-435d-81bd-2f8c37014100-image.png

      but i have got it to work by disabling gateway monitoring

      1 Reply Last reply Reply Quote 0
      • T
        theo098
        last edited by theo098

        Same here. I also have NordVPN. It worked flawless with 2.4.5 P1 for > 6 months.
        My problems are a bit different though.

        It started with the default gateway set to my IPTV WAN interface. Corrected -> works.

        As soon as I start OpenVPN, my IPTV starts to interrupt. It looks like the VPN and IGMP Proxy do not work together.
        Disable OpenVPN -> IPTV works flawless.

        e3eee55d-638a-46f1-8021-d2a19e80f2af-afbeelding.png

        1 Reply Last reply Reply Quote 0
        • N
          NeVaR @RumMonkey69
          last edited by

          @rummonkey69 you mean deleting the openvpn client profile? I did that still the same. I having feeling it is the addition setting added to the openvpn client. Like you unchecking "Enable Data Encryption Negotiation" does not do anything since it stated that "Disabling this feature is deprecated.". There also new field "TLS keydir direction" which I haven't see this before when I setup my torguard

          R 1 Reply Last reply Reply Quote 0
          • R
            RumMonkey69 @NeVaR
            last edited by

            @nevar no i mean disabling gateway monitoring for failover as I have more than one openvpn client.

            N 1 Reply Last reply Reply Quote 0
            • N
              NeVaR @RumMonkey69
              last edited by

              @rummonkey69 I don't have gateway monitoring enable aside "Do not create rules when gateway is down". I disable that as well and I'm getting same error Offline, Packetloss: 100%. I using two openvpn clients as well. I can't only point the issue to "Enable Data Encryption Negotiation" and "TLS keydir direction". On tutorial it show that uncheck Enable NCP which I guess replace with "Enable Data Ecnryption Negotiation".

              1 Reply Last reply Reply Quote 0
              • B
                bjames88
                last edited by

                I am having the same issue as well. I've been doing some research and tried a few different configurations on my VPN connection but no luck. Following this thread in hope that someone gets a lead.

                1 Reply Last reply Reply Quote 0
                • B
                  bjames88
                  last edited by

                  I played with the settings for a while and finally got it working by unchecking "Enable Data Encryption Negotiation". You might want to reboot after making this change.

                  e95c38b6-bd08-413b-af9c-91aee4016781-image.png

                  N B C T 4 Replies Last reply Reply Quote 4
                  • N
                    NeVaR @bjames88
                    last edited by

                    @bjames88 Already tried that. so what confusing with the last sentence "Disabling this feature is deprecated." So unchecking does not do anything? So who is your vpn provider?

                    B 1 Reply Last reply Reply Quote 0
                    • B
                      bartkowski @bjames88
                      last edited by

                      @bjames88 Thanks! This has solved my issue. I was pulling my hair out.
                      On top of that, Cloudflare had an issue in Chicago area tonight, which when navigating to www.nordvpn.com (and few others) caused 502 nginx bad gateway to be shown. Their app on android also didn't work for several minutes.

                      1 Reply Last reply Reply Quote 1
                      • C
                        custardduck22 @bjames88
                        last edited by

                        @bjames88 thank you - this worked for me too

                        1 Reply Last reply Reply Quote 1
                        • B
                          bjames88 @NeVaR
                          last edited by

                          @nevar Deprecated means the feature will be removed in the feature but it is currently still available. It's not longer supported and will eventually be completely removed.

                          I use Nord as my VPN provider.

                          1 Reply Last reply Reply Quote 0
                          • T
                            theo098 @bjames88
                            last edited by theo098

                            @bjames88 That's it. Thanks a lot! Everthing is working again. Worked right away, didn't even have to reboot.

                            c2ca6b26-c1e7-4f1f-abfd-21ba9ca94740-afbeelding.png

                            N 1 Reply Last reply Reply Quote 1
                            • N
                              NeVaR @theo098
                              last edited by

                              I managed to get it work on Torguard somewhat. I need select AES-128-GCM instead of AES-256GCM for the Fallback Data Encryption Algorithm as well unchecked Enable Data Encryption Negotiation. But on Status > Gateways, it still showing Offline, 100% packet loss. Can you guy confirm if you still seeing that status ?

                              1 Reply Last reply Reply Quote 1
                              • N
                                NeVaR
                                last edited by

                                Relating to "Offline, Packetlost: 100%", Goto System > Routing, then edit the each vpn gateway you have and checked "Disable Gateway Monitoring" & "Disable Gateway Monitoring Action". Majority of VPN provider ignore ping which explain why you getting 100% Packetlost. This resolve my issue running multiple vpn clients. Since pfsense detects that gateway is offline since it didn't get ping response which causing some weird issue.

                                R S 2 Replies Last reply Reply Quote 0
                                • R
                                  RumMonkey69 @NeVaR
                                  last edited by

                                  @nevar not true.

                                  Reinstall clean of 2.5 and it's working as was before.

                                  Doing upgrade and restore didn't fuck the issue.

                                  1 Reply Last reply Reply Quote 0
                                  • S
                                    Skooby @NeVaR
                                    last edited by

                                    @nevar thanks that worked for me

                                    S 1 Reply Last reply Reply Quote 0
                                    • S
                                      Skooby @Skooby
                                      last edited by Skooby

                                      ok so doing that allowed the connection to work. However its now ignoring all my rules and routing everything thru the openvpn gateway. These rules have not changed in the last 2 years so something has changed with 2.5.0. I guess next step is to do a clean install and restore the config

                                      S 1 Reply Last reply Reply Quote 0
                                      • S
                                        Skooby @Skooby
                                        last edited by

                                        ok, so a clean install did not work either. (restored config afterwards)

                                        N 1 Reply Last reply Reply Quote 0
                                        • H
                                          hypnosis4u2nv
                                          last edited by

                                          I have Torguard also and had the same issue.

                                          System->Routing->Gateways->Edit-> Monitor IP - Set it to anything, I used 8.8.8.8

                                          Now shows online in the Gateways. I believe it's an issue with ICMP over that gateway.

                                          On an unrelated note, I had to dump OpenVPN because I couldn't get it to work with policy based routing. Either I had issues with the clients I wanted to connect through it or it took over as the main gateway for my LAN. I gave up and setup Wireguard as a client for now via Torguard. My policy based rules are working as they should.

                                          N 1 Reply Last reply Reply Quote 1
                                          • N
                                            NeVaR @hypnosis4u2nv
                                            last edited by

                                            @hypnosis4u2nv Here's my setting System > Routing > Gateways > Edit (Torguard)

                                            Address Family: IPv4
                                            Gateway: dynamic
                                            Gateway Monitor: checked, Disable gateway monitoring
                                            Gateway Action: checked, Disable gateway monitoring action
                                            Force state: unchecked

                                            How do you setup wireguard as a client?

                                            H 1 Reply Last reply Reply Quote 0
                                            • First post
                                              Last post
                                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.