• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

Filter error after setup of OpenVPN

Scheduled Pinned Locked Moved OpenVPN
3 Posts 3 Posters 526 Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • V
    vMAC
    last edited by May 15, 2018, 3:31 PM

    I just added a VPN.
    After the setup of that VPN I'm getting the following error in my logs:

    There were error(s) loading the rules: /tmp/rules.debug:182: unknown protocol udp4 - The line in question reads [182]: pass in quick on $WAN reply-to ( em0 xxx.xxx.xxx.201 ) inet proto udp4 from any to xxx.xxx.xxx.202 tracker 1526356772 keep state label "USER_RULE: OpenVPN HomeVPN wizard"
    @ 2018-05-15 08:15:58.

    There is obviously something borked in the VPN setup as the VPN doesn't work, but since I used the wizard how do I chase down the configuration error?

    I used 10.1.1.0/28 as my tunnel network which is different than my LAN interface of 192.168.1.0/24, did I misunderstand the rules on that?

    Lastly although my CPU has AES-NI Crypto Yes it is marked as (inactive), how do I get that fixed?

    1 Reply Last reply Reply Quote 0
    • V
      viragomann
      last edited by May 15, 2018, 5:38 PM

      Yeah, there is a bug in the OpenVPN wizard. It sets wrong parameter in the firewall rule.

      Edit the rule generated by the wizard in Firwall > Rules > WAN and set the "Address Family" to "IPv4" and the "Protocol" to "UDP".

      For enabling the AES-NI crypto, go to System > Advanced > Miscellaneous  > "Cryptographic Hardware" and select "AES-NI CPU-based acceleration".

      1 Reply Last reply Reply Quote 0
      • J
        jimp Rebel Alliance Developer Netgate
        last edited by May 16, 2018, 5:54 PM

        If you upgrade to 2.4.3-p1 that wizard issue has been fixed. So if you use the wizard again after upgrading it will be OK for future tunnels. Editing the current rule and fixing it manually will work around the issue on 2.4.3.

        Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

        Need help fast? Netgate Global Support!

        Do not Chat/PM for help!

        1 Reply Last reply Reply Quote 0
        2 out of 3
        • First post
          2/3
          Last post
        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
          This community forum collects and processes your personal information.
          consent.not_received