Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Intermittent routing over OpenVPN (SYN sent but no ACK round robin)

    OpenVPN
    2
    4
    795
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • B
      boblatino
      last edited by

      I am trying to diagnose a problem in my pfsense which:

      • Has a lan interface with the clients connected
      • Has a WAN interface
      • Has an openVPN client connected to PIA (TCP)
      • Tried UDP and to avoid any tunnel funkyness with MTU I decided to just use TCP
      • The VPN works fine using the same setup in my mac

      The symptom points to a return path being sent to the wrong place, hence breaking the path but I can not confirm it.

      I have already set a NAT rule from my LAN IP range to the VPN and I also have the gateway created and up
      The problem that I do see is that connections do establish almost 50% of the time. If a connection is open, I can see that all its traffic its perfectly routed to the VPN gateway but it just fails to start 50% of the time. Doing packet captures I can see that the client sends the SYN flag but it never receives the SYN ACK, so the TCP connection does not start. Retrying the connection does indeed work but it breaks on the next one, rendering the tunnel useless.

      0_1545530664678_9c5aca05-4220-4d95-8cba-3a600c059b8e-image.png

      0_1545530693985_436d9fa6-0f73-4938-8c20-0a43ea873add-image.png

      0_1545530744984_b3009861-db75-4c71-8f59-c9f319f98520-image.png

      0_1545530776857_d850a5b5-e04e-4e8a-8e86-8b5ca00c465f-image.png

      1 Reply Last reply Reply Quote 0
      • A
        Asamat Global Moderator
        last edited by

        Hello. Your settings look good, so you definitely should ask remote side about their settings. I think there is subnet overlapping on remote side

        1 Reply Last reply Reply Quote 0
        • B
          boblatino
          last edited by

          I will ask PIA and report back

          1 Reply Last reply Reply Quote 0
          • B
            boblatino
            last edited by

            Looks like the problem was the first OpenVPN rule that was there to allow the VPN server to route traffic to the internet but for whatever reason, it was confusing the pfsense routing. I have deleted that NAT rule and now it works as expected

            1 Reply Last reply Reply Quote 0
            • First post
              Last post
            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.