• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

Kea DHCP Breaks Existing Wireguard/OpenVPN On PfSense 2.7.2

Scheduled Pinned Locked Moved DHCP and DNS
3 Posts 2 Posters 561 Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • F
    freesparks
    last edited by freesparks Dec 17, 2023, 8:49 PM Dec 17, 2023, 8:40 PM

    Good Day PfSense Collective,

    Seems that sense upgrading to PFSense and switching to Kea DHCP the configs for both Wireguard and OpenVPN seems to break connections.
    The logs for wireguard cant get pass "Sending handshake initiation to peer" and OpenVPN, similar peer connection issue is also replicated in OpenVPN.
    All signs seems to point to the change I made to Kea DHCP after upgrading.
    Anyone can offer some direction, it would be more than appreciated.

    S F 2 Replies Last reply Dec 17, 2023, 9:00 PM Reply Quote 0
    • S
      SteveITS Galactic Empire @freesparks
      last edited by Dec 17, 2023, 9:00 PM

      @freesparks you can easily switch back off Kea and find out, but you’ve looked into the OpenVPN and OpenSSL algorithm changes?

      https://docs.netgate.com/pfsense/en/latest/releases/2-7-1.html#openssl-upgraded-to-3-0-12

      https://forum.netgate.com/topic/170071/heads-up-openvpn-deprecating-shared-key-mode-requires-tls-deprecating-cipher-selection/

      Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
      When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
      Upvote 👍 helpful posts!

      1 Reply Last reply Reply Quote 0
      • F
        freesparks @freesparks
        last edited by freesparks Dec 17, 2023, 9:49 PM Dec 17, 2023, 9:33 PM

        @freesparks Good Day SteverITS,

        thank you so much for the reply. Yes, I had already read about how to revert back to "ISC DHCP (Deprecated)" and have replicated that this fixes the issue.
        I have also validated that OpenSSL algorithm changes and can confirm im using SHA256.

        1 Reply Last reply Reply Quote 0
        1 out of 3
        • First post
          1/3
          Last post
        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
          This community forum collects and processes your personal information.
          consent.not_received