Errors on OpenVPN logs server


  • Hello,

    I have a pfsense 2.4.5 server as a OpenVPN server. All seems to be good because, Windows and Linux clients connects with no issue et no error. But when i go to the OpenVPN logs on pfsense server i have these errors :

    Apr 8 10:51:19 openvpn 33418 TLS Error: incoming packet authentication failed from [AF_INET](MY PUBLIC IP):58039
    Apr 8 10:51:19 openvpn 33418 Authenticate/Decrypt packet error: packet HMAC authentication failed
    Apr 8 10:51:19 openvpn 33418 TLS Error: incoming packet authentication failed from [AF_INET](MY PUBLIC IP):10538
    Apr 8 10:51:19 openvpn 33418 Authenticate/Decrypt packet error: packet HMAC authentication failed
    Apr 8 10:51:19 openvpn 33418 TLS Error: incoming packet authentication failed from [AF_INET](MY PUBLIC IP):23125
    Apr 8 10:51:20 openvpn 33418 Authenticate/Decrypt packet error: packet HMAC authentication failed
    Apr 8 10:51:20 openvpn 33418 TLS Error: incoming packet authentication failed from [AF_INET](MY PUBLIC IP):59269
    Apr 8 10:51:20 openvpn 33418 Authenticate/Decrypt packet error: packet HMAC authentication failed
    Apr 8 10:51:20 openvpn 33418 TLS Error: incoming packet authentication failed from [AF_INET](MY PUBLIC IP):15063
    Apr 8 10:51:20 openvpn 33418 Authenticate/Decrypt packet error: packet HMAC authentication failed
    Apr 8 10:51:20 openvpn 33418 TLS Error: incoming packet authentication failed from [AF_INET](MY PUBLIC IP):44190
    Apr 8 10:51:20 openvpn 33418 Authenticate/Decrypt packet error: packet HMAC authentication failed
    Apr 8 10:51:20 openvpn 33418 TLS Error: incoming packet authentication failed from [AF_INET](MY PUBLIC IP):10862
    Apr 8 10:51:21 openvpn 33418 Authenticate/Decrypt packet error: packet HMAC authentication failed
    Apr 8 10:51:21 openvpn 33418 TLS Error: incoming packet authentication failed from [AF_INET](MY PUBLIC IP):12606
    Apr 8 10:51:21 openvpn 33418 Authenticate/Decrypt packet error: packet HMAC authentication failed
    Apr 8 10:51:21 openvpn 33418 TLS Error: incoming packet authentication failed from [AF_INET](MY PUBLIC IP):64087

    Have you any idea of what these errors means?

    Thanks for your responses

  • Rebel Alliance Developer Netgate

    It means what it says, a packet came in and it didn't have the correct authentication information (as in TLS authentication, not username/password).

    Could be a variety of reasons for that happening, like a non-OpenVPN client trying to hit that port (port scanners, etc), a misconfigured client, and so on.

    If all of your clients are connecting and operating as expected, then you probably do not have anything to worry about.

    If the 'client' in this case really is the public IP address of your own router, then check that you don't have anything on the OpenVPN client tab set to connect to the server instance on the same firewall. I've seen a couple people do that over the years not knowing it wasn't necessary.


  • The last solution resolve my problem.

    Thanks a lot !