Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    2FA/MFA with RADIUS drops the VPN connection after 60 minutes

    Scheduled Pinned Locked Moved OpenVPN
    5 Posts 3 Posters 1.1k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • A
      Alexander 3
      last edited by

      hi.
      i am having problems with the vpn and mfa with RADIUS. Systematically every hour the connection drops (60min). There seems to be something that every 60min drops the connection or disconnects the VPN. I tried looking in the config files, but couldn't find anything. Anyone have any ideas? Thanks.

      1 Reply Last reply Reply Quote 0
      • viktor_gV
        viktor_g Netgate
        last edited by

        What type of MFA? FreeRADIUS TOTP or something else?

        A 1 Reply Last reply Reply Quote 1
        • A
          Alexander 3 @viktor_g
          last edited by

          @viktor_g freeradius TOTP

          viktor_gV 1 Reply Last reply Reply Quote 0
          • viktor_gV
            viktor_g Netgate @Alexander 3
            last edited by

            Confirmed

            Redmine issue created: https://redmine.pfsense.org/issues/12381

            1 Reply Last reply Reply Quote 0
            • R
              rkelleyrtp
              last edited by

              We ran into a similar issue with pfSense 2.5.1 running OpenVPN with RADIUS and 2FA/MFA. For us, the fix adding these options in the OpenVPN Client Export tool under Additional configuration options :

              reneg-sec 0
              hand-window 120
              auth-nocache
              

              Now, our 2FA/MFA with RADIUS works very well.

              1 Reply Last reply Reply Quote 1
              • First post
                Last post
              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.