<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[OpenVPN Multi WAN Connection Problem]]></title><description><![CDATA[<p dir="auto">Hello pfsense community,</p>
<p dir="auto">i hope you can help us with our problem, i did several trys to fix the problem but nothing fixed it so far.</p>
<p dir="auto">We have a Multi WAN CARP Setup with two pfsense pcs (2.4.3-RELEASE-p1).</p>
<ul>
<li>OpenVPN Server bound to 127.0.0.1 / localhost</li>
<li>UDP Port 1995</li>
<li>Port Forwards for both WAN Interfaces (with associtated firewall rules</li>
</ul>
<p dir="auto">Example client config:<br />
dev tun<br />
persist-tun<br />
persist-key<br />
cipher AES-256-CBC<br />
auth SHA1<br />
tls-client<br />
client<br />
resolv-retry infinite<br />
remote xxx 1195 udp<br />
remote xxx 1195 udp<br />
verify-x509-name "xxx" name<br />
auth-user-pass<br />
pkcs12 xxx.p12<br />
tls-auth xxx.key 1<br />
remote-cert-tls server</p>
<p dir="auto"><strong>The problem is the following:</strong></p>
<p dir="auto">Client tries first to connect to isp 2 (backup isp) --&gt; TLS Error: TLS key negotiation failed to occur within 60 seconds (check your network connectivity)<br />
TLS Error: TLS handshake failed</p>
<p dir="auto">or</p>
<p dir="auto">TCP/UDP: Incoming packet rejected from [AF_INET]xxx:1195[2], expected peer address: [AF_INET]xxy:1195 (allow this incoming source address/port by removing --remote or adding --float)</p>
<p dir="auto">After 60 Secs client connect to isp1 -&gt; Connection established.</p>
<p dir="auto">It seems that the "reply-to" doesnt work anymore. Openvpn use always the active gateway from failover group but doesn't use the same interface from which the traffic came in.</p>
<p dir="auto">But it worked a time ago, nothing changed (no update, no configuration change. Only add new users for vpn for example)</p>
<p dir="auto">Tried so far:</p>
<ul>
<li>Reboot master pfsense</li>
<li>recreated the port forward for the backup wan</li>
<li>rebooted openvpn server</li>
</ul>
<p dir="auto">Kind regards and thanks for your help</p>
<p dir="auto">Marc</p>
]]></description><link>https://forum.netgate.com/topic/147338/openvpn-multi-wan-connection-problem</link><generator>RSS for Node</generator><lastBuildDate>Mon, 13 Apr 2026 11:38:45 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/147338.rss" rel="self" type="application/rss+xml"/><pubDate>Tue, 15 Oct 2019 08:29:58 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to OpenVPN Multi WAN Connection Problem on Tue, 15 Oct 2019 12:06:01 GMT]]></title><description><![CDATA[<p dir="auto"><img src="/assets/uploads/files/1571140985899-port_forwards_pfsense_openvpn_clients.jpg" alt="port_forwards_pfsense_openvpn_clients.JPG" class=" img-fluid img-markdown" /></p>
<p dir="auto"><img src="/assets/uploads/files/1571141153637-port_forwards_pfsense_openvpn_clients_wanewe.jpg" alt="port_forwards_pfsense_openvpn_clients_wanewe.JPG" class=" img-fluid img-markdown" /></p>
<p dir="auto">Hi Viragomann,</p>
<p dir="auto">thats already done. See screenshot. Port Forward was created for every singline wan interface.</p>
]]></description><link>https://forum.netgate.com/post/870775</link><guid isPermaLink="true">https://forum.netgate.com/post/870775</guid><dc:creator><![CDATA[Avides]]></dc:creator><pubDate>Tue, 15 Oct 2019 12:06:01 GMT</pubDate></item><item><title><![CDATA[Reply to OpenVPN Multi WAN Connection Problem on Tue, 15 Oct 2019 10:30:32 GMT]]></title><description><![CDATA[<p dir="auto">Consider that "reply-to" doesn't work on floating rules and also doesn't work on rules defined on an interface group.<br />
So the firewall rules allowing the incoming OpenVPN packets must be set on WAN1 and WAN2 interface tab directly.</p>
]]></description><link>https://forum.netgate.com/post/870749</link><guid isPermaLink="true">https://forum.netgate.com/post/870749</guid><dc:creator><![CDATA[viragomann]]></dc:creator><pubDate>Tue, 15 Oct 2019 10:30:32 GMT</pubDate></item></channel></rss>