Pfsense 2.3.5 p1: gateway group not updated on OpenVPN client reconnect



  • Setup:

    WAN1 - (PPPOE)
    WAN2 - VPNV4 - Openvpn client in TUN mode connected via WAN1

    Gateway group: Test_Group (VPNV4 - Tier1, WAN1 - Tier2)

    Everything works as expected until WAN1 disconnect.

    If I disconnect WAN1, WAN2 goes offline too in a minute or two.
    When i reconnect WAN1, gateway group is updated (/tmp/rulse.debug) with following:

    GWWAN1_PPPOE = " route-to ( pppoe0 11.22.33.44 ) "
    GWVPN_VPNV4 = " "
    GWTest_Group = " route-to { ( pppoe0 11.22.33.44 ) } "

    Then in several second OpenVPN goes online, but /tmp/rulse.debug contains following:

    GWWAN1_PPPOE = " route-to ( pppoe0 11.22.33.44 ) "
    GWVPN_VPNV4 = " route-to ( ovpnc3 10.8.0.5 ) "
    GWTest_Group = " route-to { ( pppoe0 11.22.33.44 ) } " //!!! wrong: should be ovpnc3 10.8.0.5 (Tier1)

    This is the final state, no matter how long you will wait. All gateways in gateway group are green (online), but routing goes through Tier2 gateway.

    If i udpate ANY (even non related to this gateway group) firewall rule, or restart OpenVPN service then routing becomes correct:

    GWWAN1_PPPOE = " route-to ( pppoe0 11.22.33.44 ) "
    GWVPN_VPNV4 = " route-to ( ovpnc3 10.8.0.5 ) "
    GWTest_Group = " route-to ( ovpnc3 10.8.0.5 ) "

    So it seems then something is not updated when openvpn reconnects automatically (without restarting it's service).