• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

Cannot disable an OpenVPN instance while the interface is assigned. Remove the interface assignment first

Scheduled Pinned Locked Moved OpenVPN
9 Posts 9 Posters 3.4k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • S
    sotirone
    last edited by Jun 25, 2022, 8:57 AM

    Hello.

    Ever since I updated to 2.6.0, when I try to disable an OpenVPN client that has been assigned to an Interface, I get this error.

    This has been very problematic for me and I don't see its purpose.

    I use pfSense to pfSense OpenVPN tunnels to service clients remotely.

    Some of those clients have networks with subnets that are either similar to mine or to each other.

    By assigning an Interface and a Gateway to each tunnel, I can just switch a Static Route between Gateways and access networks with same subnets on different client locations easily.

    But, I don't want the OpenVPN tunnels to be always UP. So I enable them as needed every time I need to do some work on each client.

    This new behavior forces me to either have the tunnels always UP, or having to delete the Interface assignments and then redo them (and their Gateway configuration) every time I need to access one of these subnets.

    This new behavior was a solution to a problem that didn't exist. Now it has caused real problems.

    1 Reply Last reply Reply Quote 0
    • B
      bingo600
      last edited by Jun 25, 2022, 3:18 PM

      Have reported the same issue here
      https://forum.netgate.com/topic/172119/ce-2-6-0-unable-to-disable-openvpn-server-if-interface-is-assigned

      No response yet

      /Bingo

      If you find my answer useful - Please give the post a 👍 - "thumbs up"

      pfSense+ 23.05.1 (ZFS)

      QOTOM-Q355G4 Quad Lan.
      CPU  : Core i5 5250U, Ram : 8GB Kingston DDR3LV 1600
      LAN  : 4 x Intel 211, Disk  : 240G SAMSUNG MZ7L3240HCHQ SSD

      1 Reply Last reply Reply Quote 2
      • A apetrenko referenced this topic on Mar 23, 2023, 3:18 PM
      • B
        blabs
        last edited by Jul 6, 2023, 6:51 PM

        Can we get some traction on this issue? This is ridiculous, still a problem in v2.7.0...

        R 1 Reply Last reply Aug 13, 2023, 3:05 PM Reply Quote 0
        • R
          rcoleman-netgate Netgate @blabs
          last edited by Aug 13, 2023, 3:05 PM

          @blabs said in Cannot disable an OpenVPN instance while the interface is assigned. Remove the interface assignment first:

          Can we get some traction on this issue? This is ridiculous, still a problem in v2.7.0...

          Please open a redmine at https://redmine.pfsense.org/

          Ryan
          Repeat, after me: MESH IS THE DEVIL! MESH IS THE DEVIL!
          Requesting firmware for your Netgate device? https://go.netgate.com
          Switching: Mikrotik, Netgear, Extreme
          Wireless: Aruba, Ubiquiti

          M 1 Reply Last reply Aug 13, 2023, 4:56 PM Reply Quote 0
          • M
            MoonKnight @rcoleman-netgate
            last edited by Aug 13, 2023, 4:56 PM

            @rcoleman-netgate Same with Wireguard, can't DISABLE the tunnel, get this message "Cannot disable tun_wg4 to XXXXXXXXXXX (opt7).

            --- 24.11 ---
            Intel(R) Xeon(R) CPU D-1518 @ 2.20GHz
            Kingston DDR4 2666MHz 16GB ECC
            2 x HyperX Fury SSD 120GB (ZFS-mirror)
            2 x Intel i210 (ports)
            4 x Intel i350 (ports)

            1 Reply Last reply Reply Quote 0
            • D
              darkcorner
              last edited by Sep 28, 2023, 10:50 AM

              Same error for me too.
              I want to eliminate all references in OpenVPN because they are obsolete in this new location, but it still remains an interface.

              1 Reply Last reply Reply Quote 0
              • W
                WaltW 0
                last edited by Oct 25, 2023, 7:45 PM

                I also have this issue. Any suggestions on how to fix?

                1 Reply Last reply Reply Quote 0
                • M
                  mac1995
                  last edited by mac1995 Dec 20, 2023, 4:11 PM Dec 20, 2023, 4:04 PM

                  To unassign the VPN interface you would like to disable, go to Interfaces -> Interface Assignments, and find that there is something like:

                  Interface Network port
                  WAN em1 (00:0c:29:82:45:9a)
                  LAN em0 (00:0c:29:82:45:90)
                  OPT1 ovpns1 (VPN Access 1)
                  OPT2 ovpns2 (VPN Access 2)

                  In order to disable in this case (VPN Access 1) you can
                  delete the OPT1, (and lose the rules you had there!!!); or
                  assign the OPT1 to some other stub interface you create that is not routable, so you can keep this rule set around for
                  reference, or to use again when you re-enable the VPN Access 1.

                  Once there is no interface assigned to the particular VPN server, you can disable that interface back on the
                  VPN/OpenVPN/Servers page

                  C 1 Reply Last reply Dec 20, 2023, 8:39 PM Reply Quote 0
                  • C
                    coreybrett @mac1995
                    last edited by Dec 20, 2023, 8:39 PM

                    @mac1995 Nice hack, but not really a fix

                    Another hack fix is to disable the WAN rule that allows the client to connect to the server. But that's only really effective if the OP has all the servers on his side, and the clients on the remote side.

                    1 Reply Last reply Reply Quote 0
                    • First post
                      Last post
                    Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
                      [[user:consent.lead]]
                      [[user:consent.not_received]]