• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

pfsense 2.6.0 system logs message OpenVPN failed to start

Scheduled Pinned Locked Moved OpenVPN
20 Posts 3 Posters 1.5k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • J
    Jonas Souza
    last edited by Jonas Souza Jun 28, 2023, 6:27 PM Jun 28, 2023, 6:24 PM

    I do all the openvpn configuration in pfsense but it fails to start the service. I have configured and reconfigured several times but it does not return to normal

    2023-06-28_15-16.png 2023-06-28_15-16_1.png2023-06-28_15-27.png

    G 1 Reply Last reply Jun 29, 2023, 7:07 AM Reply Quote 0
    • G
      Gertjan @Jonas Souza
      last edited by Jun 29, 2023, 7:07 AM

      @Jonas-Souza

      The 'general' log :
      c746b23b-ac01-4dc2-b7dd-8b698a38647d-image.png

      doesn't show useful information.

      Show us this log :

      69087cd8-2107-4046-9e80-fafded746a50-image.png

      and we'll show you why OpenVPN doesn't want to start 😊

      No "help me" PM's please. Use the forum, the community will thank you.
      Edit : and where are the logs ??

      J 1 Reply Last reply Jun 29, 2023, 12:08 PM Reply Quote 0
      • J
        Jonas Souza @Gertjan
        last edited by Jun 29, 2023, 12:08 PM

        @Gertjan

        Hello, thanks for helping.

        When trying to start the service, it does not generate a log within OpenVPN, it follows the print. Before taking the print I tried to start the service again, but it does not generate a record.

        Thanks

        2023-06-29_09-04.png

        V 1 Reply Last reply Jun 29, 2023, 12:26 PM Reply Quote 0
        • V
          viragomann @Jonas Souza
          last edited by Jun 29, 2023, 12:26 PM

          @Jonas-Souza
          Did this VPN server ever work?

          Show the config, please.
          If you have multiple servers show all.

          J 1 Reply Last reply Jun 29, 2023, 12:36 PM Reply Quote 0
          • J
            Jonas Souza @viragomann
            last edited by Jun 29, 2023, 12:36 PM

            @viragomann

            Yes, it already worked, I tried to recreate the server back, when I finish the creation the service is online and works, but when I need to restart the service it is turned off. Follow the screenshots. I only have this vpn active.

            2023-06-29_09-33.png 2023-06-29_09-33_1.png 2023-06-29_09-33_2.png 2023-06-29_09-34.png 2023-06-29_09-34_1.png 2023-06-29_09-34_2.png

            G V 2 Replies Last reply Jun 29, 2023, 12:42 PM Reply Quote 0
            • G
              Gertjan @Jonas Souza
              last edited by Jun 29, 2023, 12:42 PM

              @Jonas-Souza

              When you stop the OpenVPN server in the GUI : Dashnoard, I see :

              <27>1 2023-06-29T14:36:16.104857+02:00 pfs.bhf.net openvpn 45417 - - event_wait : Interrupted system call (fd=-1,code=4)
              <29>1 2023-06-29T14:36:16.105221+02:00 pfs.bhf.net openvpn 45417 - - /sbin/ifconfig ovpns1 192.168.3.1 -alias
              <29>1 2023-06-29T14:36:16.114670+02:00 pfs.bhf.net openvpn 45417 - - /usr/local/sbin/ovpn-linkdown ovpns1 1500 0 192.168.3.1 255.255.255.0 init
              <13>1 2023-06-29T14:36:16.118951+02:00 pfs.bhf.net openvpn 4823 - - Flushing states on OpenVPN interface ovpns1 (Link Down)
              <29>1 2023-06-29T14:36:16.127949+02:00 pfs.bhf.net openvpn 45417 - - SIGTERM[hard,] received, process exiting
              

              When I start it

              <29>1 2023-06-29T14:36:58.436068+02:00 pfs.bhf.net openvpn 93117 - - OpenVPN 2.6.2 amd64-portbld-freebsd14.0 [SSL (OpenSSL)] [LZO] [LZ4] [PKCS11] [MH/RECVDA] [AEAD] [DCO]
              <29>1 2023-06-29T14:36:58.436646+02:00 pfs.bhf.net openvpn 93117 - - library versions: OpenSSL 1.1.1t-freebsd  7 Feb 2023, LZO 2.10
              <29>1 2023-06-29T14:36:58.436773+02:00 pfs.bhf.net openvpn 93117 - - DCO version: FreeBSD 14.0-CURRENT #1 plus-RELENG_23_05_1-n256108-459fc493a87: Mon Jun 26 06:35:42 UTC 2023     root@freebsd:/var/jenkins/workspace/pfSense-Plus-snapshots-23_05_1-main/obj/amd64/f2Em2w3l/var/jenkins/workspace/pfSense-Plus-snapshots-23_05_1-main/sources/
              <28>1 2023-06-29T14:36:58.438556+02:00 pfs.bhf.net openvpn 93453 - - NOTE: the current --script-security setting may allow this configuration to call user-defined scripts
              <29>1 2023-06-29T14:36:58.439054+02:00 pfs.bhf.net openvpn 93453 - - Initializing OpenSSL support for engine 'rdrand'
              <28>1 2023-06-29T14:36:58.441128+02:00 pfs.bhf.net openvpn 93453 - - WARNING: experimental option --capath /var/etc/openvpn/server1/ca
              <29>1 2023-06-29T14:36:58.441811+02:00 pfs.bhf.net openvpn 93453 - - TUN/TAP device ovpns1 exists previously, keep at program end
              <29>1 2023-06-29T14:36:58.442119+02:00 pfs.bhf.net openvpn 93453 - - TUN/TAP device /dev/tun1 opened
              <29>1 2023-06-29T14:36:58.442476+02:00 pfs.bhf.net openvpn 93453 - - /sbin/ifconfig ovpns1 192.168.3.1/24 mtu 1500 up
              <29>1 2023-06-29T14:36:58.452004+02:00 pfs.bhf.net openvpn 93453 - - /usr/local/sbin/ovpn-linkup ovpns1 1500 0 192.168.3.1 255.255.255.0 init
              <29>1 2023-06-29T14:36:58.459600+02:00 pfs.bhf.net openvpn 93453 - - UDPv4 link local (bound): [AF_INET]192.168.10.4:1194
              <29>1 2023-06-29T14:36:58.459630+02:00 pfs.bhf.net openvpn 93453 - - UDPv4 link remote: [AF_UNSPEC]
              

              Use

              tail -f /var/log/openvpn.log
              

              on the console / SSG to follow the /var/log/openvpn.log file easily.

              <29>1 2023-06-29T14:36:58.459750+02:00 pfs.bhf.net openvpn 93453 - - Initialization Sequence Completed

              No "help me" PM's please. Use the forum, the community will thank you.
              Edit : and where are the logs ??

              1 Reply Last reply Reply Quote 0
              • V
                viragomann @Jonas Souza
                last edited by viragomann Jun 29, 2023, 12:54 PM Jun 29, 2023, 12:54 PM

                @Jonas-Souza
                Your advanced setting are wrong. You have to separate the push command by a semicolon.
                Further the first address is wrong. It must be the network address.

                But anyway, instead of putting the push command into the custom options, you should rather state them at "Local networks".
                So the field should look like this:

                100.120.1.0/24,10.210.1.0/24
                

                And empty the custom options, of course.

                J G 3 Replies Last reply Jun 29, 2023, 1:11 PM Reply Quote 0
                • J
                  Jonas Souza @viragomann
                  last edited by Jun 29, 2023, 1:11 PM

                  @viragomann

                  Adjusting the settings you mentioned, it worked perfectly. Thank you very much

                  1 Reply Last reply Reply Quote 0
                  • G
                    Gertjan @viragomann
                    last edited by Gertjan Jun 29, 2023, 1:21 PM Jun 29, 2023, 1:13 PM

                    @viragomann said in pfsense 2.6.0 system logs message OpenVPN failed to start:

                    And empty the custom options, of course.

                    👍

                    The perfect custom settings :

                    c20b086d-a30a-4d1c-974c-749e1b32d853-image.png

                    Using that for several years now, just great. Easy to maintain.

                    Btw : Because my tunnel network is 192.168.3.0/24 (an available local RFC1918) :
                    You saw my :

                    <29>1 2023-06-29T14:36:58.442476+02:00 pfs.bhf.net openvpn 93453 - - /sbin/ifconfig ovpns1 192.168.3.1/24 mtu 1500 up
                    

                    Because :

                    8fde2302-599a-488c-944b-d06e7c66e7d0-image.png

                    edit :

                    In case you didn't do so already :
                    Assign the OpenVPN server instnce interface to a new interface - I called mine 'OPENVPN'.

                    1b5b30e4-0227-479b-8bf4-bb83c2bc8dbb-image.png

                    Then : activate it :

                    7e5e89a6-aa3f-4bf8-bbdf-94297776b663-image.png

                    (nothing more to do there)

                    Add some rule on the Interface OPENVPN (otherwise nothing can gets in).
                    This one will do just fine :

                    7fed92be-9283-4a84-89d2-8dd263a14b33-image.png

                    Then, pay a visit to the Resolver (DNS !) and make sure it listens to All incoming interfaces.
                    Or at least all incoming interfaces - 'OPENVPN' included :

                    f9cc4c88-f366-4445-8df4-6bad36e38ee1-image.png

                    Finally : even if they are years old now, do visit Youtube. Go to the Netgate Channel and re-watch the 3 official OpenVPN (server) video's. It's worth it.

                    No "help me" PM's please. Use the forum, the community will thank you.
                    Edit : and where are the logs ??

                    1 Reply Last reply Reply Quote 0
                    • J
                      Jonas Souza @viragomann
                      last edited by Jun 29, 2023, 1:30 PM

                      @viragomann @Gertjan

                      Now I'm having another problem, here's the screenshot.

                      OpenVPN service is online.

                      What can it be?

                      2023-06-29_10-29.png
                      2023-06-29_10-19.png

                      V 1 Reply Last reply Jun 29, 2023, 1:40 PM Reply Quote 0
                      • V
                        viragomann @Jonas Souza
                        last edited by Jun 29, 2023, 1:40 PM

                        @Jonas-Souza
                        Mostly this error means that the client cannot reach the server.
                        The server IP is correct in the client settings?

                        Check the firewall log on the server if it has blocked the packets.
                        Or run a packet capture on WAN to see if the packets arrive at all.

                        J 1 Reply Last reply Jun 29, 2023, 1:54 PM Reply Quote 0
                        • J
                          Jonas Souza @viragomann
                          last edited by Jun 29, 2023, 1:54 PM

                          @viragomann

                          Yes, the ip is correct, follow the client's log.

                          Would it be a problem with the certificates now?

                          2023-06-29_10-53.png
                          2023-06-29_10-52.png

                          V 1 Reply Last reply Jun 29, 2023, 2:01 PM Reply Quote 0
                          • V
                            viragomann @Jonas Souza
                            last edited by Jun 29, 2023, 2:01 PM

                            @Jonas-Souza
                            Yes, as the server log shows, there is something wrong with the certificate verification.

                            Is the client certificate issued by the CA, which you stated in the server settings?

                            J 1 Reply Last reply Jun 29, 2023, 2:10 PM Reply Quote 0
                            • J
                              Jonas Souza @viragomann
                              last edited by Jun 29, 2023, 2:10 PM

                              @viragomann

                              Perfectly, I redid the user CA and it worked.

                              Many thanks for the instructions.

                              Excuse my ignorance, but how and where do I consider this topic resolved?

                              V 1 Reply Last reply Jun 29, 2023, 2:13 PM Reply Quote 0
                              • V
                                viragomann @Jonas Souza
                                last edited by Jun 29, 2023, 2:13 PM

                                @Jonas-Souza
                                Just edit the topic in the first post and put "[SOLVED]" in front of it.

                                J 1 Reply Last reply Jun 29, 2023, 2:59 PM Reply Quote 1
                                • J
                                  Jonas Souza @viragomann
                                  last edited by Jun 29, 2023, 2:59 PM

                                  @viragomann

                                  sorry but when editing the post notifies this warning.

                                  2023-06-29_11-58.png

                                  V 1 Reply Last reply Jun 29, 2023, 3:08 PM Reply Quote 0
                                  • V
                                    viragomann @Jonas Souza
                                    last edited by Jun 29, 2023, 3:08 PM

                                    @Jonas-Souza
                                    Obviously there is a lock now for editing old posts.
                                    Do you have access to the topic in the most recent?

                                    J 1 Reply Last reply Jun 29, 2023, 3:13 PM Reply Quote 0
                                    • J
                                      Jonas Souza @viragomann
                                      last edited by Jun 29, 2023, 3:13 PM

                                      @viragomann

                                      From the last post yes, but I can't edit the title of the post.

                                      2023-06-29_12-13.png

                                      V 1 Reply Last reply Jun 29, 2023, 3:27 PM Reply Quote 0
                                      • V
                                        viragomann @Jonas Souza
                                        last edited by Jun 29, 2023, 3:27 PM

                                        @Jonas-Souza
                                        Sorry, so I can't sadly help you with that. Obviously the forum haves different now. Don't now what's actually the proper way to mark a topic as solved.

                                        J 1 Reply Last reply Jun 29, 2023, 3:29 PM Reply Quote 1
                                        • J
                                          Jonas Souza @viragomann
                                          last edited by Jun 29, 2023, 3:29 PM

                                          @viragomann

                                          I reposted, thanks

                                          https://forum.netgate.com/topic/181119/solved-pfsense-2-6-0-system-logs-message-openvpn-failed-to-start

                                          1 Reply Last reply Reply Quote 0
                                          1 out of 20
                                          • First post
                                            1/20
                                            Last post
                                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
                                            This community forum collects and processes your personal information.
                                            consent.not_received