<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[PIA VPN failing every hour]]></title><description><![CDATA[<p dir="auto">My PIV VPN won't stay up for very long.  Most times it comes back up on its own.  A few times I've had to restart the OpenVPN service by hand, and once I had to reboot as the OVPN service wouldn't respond at all.</p>
<p dir="auto">Excerpts from log:</p>
<p dir="auto">Mar 9 16:05:09 openvpn 58385 Initialization Sequence Completed<br />
Mar 9 16:05:09 openvpn 58385 /usr/local/sbin/ovpn-linkup ovpnc1 1500 1557 x.x.x.6 x.x.10.5 init<br />
Mar 9 16:05:09 openvpn 58385 /sbin/ifconfig ovpnc1 x.x.x.6 x.x.x.5 mtu 1500 netmask 255.255.255.255 up<br />
Mar 9 16:05:09 openvpn 58385 do_ifconfig, tt-&gt;did_ifconfig_ipv6_setup=0<br />
Mar 9 16:05:09 openvpn 58385 TUN/TAP device /dev/tun1 opened<br />
Mar 9 16:05:09 openvpn 58385 TUN/TAP device ovpnc1 exists previously, keep at program end<br />
Mar 9 16:05:07 openvpn 58385 [0b11e634ff031dfe118c0e72f207a30f] Peer Connection Initiated with [AF_INET]x.x.x.35:1198<br />
Mar 9 16:05:07 openvpn 58385 WARNING: 'comp-lzo' is present in remote config but missing in local config, remote='comp-lzo'<br />
Mar 9 16:05:07 openvpn 58385 WARNING: 'cipher' is used inconsistently, local='cipher AES-128-CBC', remote='cipher BF-CBC'<br />
Mar 9 16:05:07 openvpn 58385 WARNING: 'link-mtu' is used inconsistently, local='link-mtu 1557', remote='link-mtu 1542'<br />
Mar 9 16:05:07 openvpn 58385 WARNING: this configuration may cache passwords in memory – use the auth-nocache option to prevent this<br />
Mar 9 16:05:07 openvpn 58385 UDPv4 link remote: [AF_INET]x.x.x.35:1198<br />
Mar 9 16:05:07 openvpn 58385 UDPv4 link local (bound): [AF_INET]x.x.x.6:0<br />
Mar 9 16:05:07 openvpn 58385 TCP/UDP: Preserving recently used remote address: [AF_INET]x.x.x.35:1198<br />
Mar 9 16:05:07 openvpn 58385 Initializing OpenSSL support for engine 'rdrand'<br />
Mar 9 16:05:07 openvpn 58385 NOTE: the current –script-security setting may allow this configuration to call user-defined scripts<br />
Mar 9 16:05:07 openvpn 57856 library versions: OpenSSL 1.0.2m-freebsd 2 Nov 2017, LZO 2.10<br />
Mar 9 16:05:07 openvpn 57856 OpenVPN 2.4.4 amd64-portbld-freebsd11.1 [SSL (OpenSSL)] [LZO] [LZ4] [MH/RECVDA] [AEAD] built on Oct 8 2017<br />
Mar 9 16:05:07 openvpn 57856 WARNING: file '/var/etc/openvpn/client1.up' is group or others accessible<br />
Mar 9 16:05:01 openvpn 34426 Exiting due to fatal error<br />
Mar 9 16:05:01 openvpn 34426 TCP/UDP: Socket bind failed on local address [AF_INET]192.168.100.10:0: Can't assign requested address (errno=49)</p>
<p dir="auto">The last line above references an IP address that is not on my network, not sure if this is right or what is going on here.</p>
<p dir="auto">Mar 9 16:05:01 openvpn 34426 TCP/UDP: Preserving recently used remote address: [AF_INET]x.x.x.35:1198<br />
Mar 9 16:05:01 openvpn 34426 Initializing OpenSSL support for engine 'rdrand'<br />
Mar 9 16:05:01 openvpn 34426 NOTE: the current –script-security setting may allow this configuration to call user-defined scripts<br />
Mar 9 16:05:01 openvpn 34274 library versions: OpenSSL 1.0.2m-freebsd 2 Nov 2017, LZO 2.10<br />
Mar 9 16:05:01 openvpn 34274 OpenVPN 2.4.4 amd64-portbld-freebsd11.1 [SSL (OpenSSL)] [LZO] [LZ4] [MH/RECVDA] [AEAD] built on Oct 8 2017<br />
Mar 9 16:05:01 openvpn 34274 WARNING: file '/var/etc/openvpn/client1.up' is group or others accessible<br />
Mar 9 16:05:00 openvpn 86817 SIGTERM[hard,] received, process exiting<br />
Mar 9 16:05:00 openvpn 86817 event_wait : Interrupted system call (code=4)<br />
Mar 9 16:04:30 openvpn 86817 UDPv4 link remote: [AF_INET]x.x.x.35:1198<br />
Mar 9 16:04:30 openvpn 86817 UDPv4 link local (bound): [AF_INET]192.168.100.10:0</p>
<p dir="auto">Again, the line above… I don't know where this address is coming from.</p>
<p dir="auto">Mar 9 16:04:30 openvpn 86817 TCP/UDP: Preserving recently used remote address: [AF_INET]x.x.x.35:1198<br />
Mar 9 16:04:30 openvpn 86817 Initializing OpenSSL support for engine 'rdrand'<br />
Mar 9 16:04:30 openvpn 86817 NOTE: the current –script-security setting may allow this configuration to call user-defined scripts<br />
Mar 9 16:04:30 openvpn 86697 library versions: OpenSSL 1.0.2m-freebsd 2 Nov 2017, LZO 2.10<br />
Mar 9 16:04:30 openvpn 86697 OpenVPN 2.4.4 amd64-portbld-freebsd11.1 [SSL (OpenSSL)] [LZO] [LZ4] [MH/RECVDA] [AEAD] built on Oct 8 2017<br />
Mar 9 16:04:30 openvpn 86697 WARNING: file '/var/etc/openvpn/client1.up' is group or others accessible<br />
Mar 9 16:04:06 openvpn 11192 /usr/local/sbin/ovpn-linkdown ovpnc1 1500 1622 x.x.x.6 x.x.x.5 init<br />
Mar 9 16:04:06 openvpn 11192 ERROR: FreeBSD route delete command failed: external program exited with error status: 1<br />
Mar 9 16:04:06 openvpn 11192 Exiting due to fatal error<br />
Mar 9 16:04:06 openvpn 11192 TCP/UDP: Socket bind failed on local address [AF_INET]x.x.x.6:0: Can't assign requested address (errno=49)<br />
Mar 9 16:04:06 openvpn 11192 TCP/UDP: Preserving recently used remote address: [AF_INET]x.x.x.35:1198<br />
Mar 9 16:04:06 openvpn 11192 NOTE: the current –script-security setting may allow this configuration to call user-defined scripts<br />
Mar 9 16:03:56 openvpn 11192 SIGUSR1[soft,ping-restart] received, process restarting<br />
Mar 9 16:03:56 openvpn 11192 [0411ef342f03ddfe918c0e73f207a30f] Inactivity timeout (–ping-restart), restarting<br />
Mar 9 15:05:10 openvpn 11192 Initialization Sequence Completed<br />
Mar 9 15:05:10 openvpn 11192 /usr/local/sbin/ovpn-linkup ovpnc1 1500 1557 x.x.x.6 x.x.x.5 init<br />
Mar 9 15:05:10 openvpn 11192 /sbin/ifconfig ovpnc1 x.x.x.6 x.x.x.5 mtu 1500 netmask 255.255.255.255 up<br />
Mar 9 15:05:10 openvpn 11192 do_ifconfig, tt-&gt;did_ifconfig_ipv6_setup=0<br />
Mar 9 15:05:10 openvpn 11192 TUN/TAP device /dev/tun1 opened</p>
<p dir="auto">I'm not sure where to start troubleshooting.  The VPN was put in place less than 24 hours ago, and the firewall has been 24/7/365 reliable previous to that.</p>
]]></description><link>https://forum.netgate.com/topic/128011/pia-vpn-failing-every-hour</link><generator>RSS for Node</generator><lastBuildDate>Sun, 07 Jun 2026 13:59:47 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/128011.rss" rel="self" type="application/rss+xml"/><pubDate>Fri, 09 Mar 2018 23:13:59 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to PIA VPN failing every hour on Sun, 11 Mar 2018 13:27:42 GMT]]></title><description><![CDATA[<p dir="auto">What server are you connecting to?</p>
<p dir="auto">Have you tried another server with the same results?</p>
<p dir="auto">also given the errors in your logs you have not followed/ matched the OVPN files.    match those as close as possible</p>
]]></description><link>https://forum.netgate.com/post/754774</link><guid isPermaLink="true">https://forum.netgate.com/post/754774</guid><dc:creator><![CDATA[[[global:former-user]]]]></dc:creator><pubDate>Sun, 11 Mar 2018 13:27:42 GMT</pubDate></item><item><title><![CDATA[Reply to PIA VPN failing every hour on Sat, 10 Mar 2018 05:19:47 GMT]]></title><description><![CDATA[<p dir="auto">I just realized I had verbosity set too low, I have set 'verb 4' and restarted the service, if the above logs aren't sufficient, I will post them up when it fails again with more verbosity.</p>
<p dir="auto">ETA</p>
<p dir="auto">I've had a script running pinging 8.8.8.8 for hours now.</p>
<p dir="auto">Every hour, at 2 minutes after the hour, the VPN does down.  Every hour, at exactly two hours past.  A few times, leading up to the VPN going down, at 40 minutes after, ping times go from 20-25ms to 90-500ms, consistently.  As soon as the VPN comes back up, ping times go back to 20-25ms, for about 40 minutes.</p>
<p dir="auto">This cycle repeats over and over.</p>
<p dir="auto">ETA</p>
<p dir="auto">Noticed that when the VPN is down, the entire pfsense GUI is frozen.  ssh'ing into the box still works.  After the VPN comes back up, about 30 seconds later, the GUI is responsive and everything is normal.  Until the next time.</p>
<p dir="auto">System logs during this period of time show that most packages are throwing various errors and all are restarting.  Lots of "reloading filter" and "Starting all packages" messages during that time.</p>
<p dir="auto">I have made a few changes to the VPN config based on log entries (making things match on both ends, like compression etc), and so far nothing has worked, the connection continues to drop and reset somewhere between 2 and 3 minutes after the hours, like clockwork.</p>
]]></description><link>https://forum.netgate.com/post/754611</link><guid isPermaLink="true">https://forum.netgate.com/post/754611</guid><dc:creator><![CDATA[tucansam]]></dc:creator><pubDate>Sat, 10 Mar 2018 05:19:47 GMT</pubDate></item></channel></rss>