Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    VPN just suddenly down

    General pfSense Questions
    4
    12
    446
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • L
      lewis
      last edited by lewis

      I've had a VPN connection to a remote firewall for months without a problem.
      All of a sudden, while working, the VPN goes down.

      No other network issues, just the VPN goes down. I check the firewall using the public IP and everything looks normal just can't connect anymore.

      The firewall logs show;
      The TLS Error: TLS key negotiation failed to occur within 60 seconds and TLS Error:
      TLS handshake failed

      Since there was an update available and my last thought was to reboot, I updated and rebooted but no difference. I also rebooted my PC with no change.

      I'm stumped that this would happen just out of the blue and without any changes on the firewall or the PC I'm working on.

      What could be happening?

      stephenw10S 1 Reply Last reply Reply Quote 0
      • JonathanLeeJ
        JonathanLee
        last edited by JonathanLee

        That is a certificate error reissue certificates and attempt a connection again. A client device could have updated without you knowing. My iOS device updates the openVPN application by itself… just a thought

        Make sure to upvote

        L 1 Reply Last reply Reply Quote 2
        • L
          lewis @JonathanLee
          last edited by

          @JonathanLee If that's the case, at least it would answer why it was so random and sudden, while I was working, without making any cert changes.

          I'll give it a try and report back.

          1 Reply Last reply Reply Quote 1
          • L
            lewis
            last edited by

            I tried renew/reissue in Certificate Authorities for the vpn CA and I renewed the clients certs then picked up the config for each and we're back online.

            I didn't expect it to simply disconnect me without any warning but there it is.

            Thanks for your help!

            1 Reply Last reply Reply Quote 0
            • stephenw10S
              stephenw10 Netgate Administrator @lewis
              last edited by

              @lewis said in VPN just suddenly down:

              The TLS Error: TLS key negotiation failed to occur within 60 seconds and TLS Error:
              TLS handshake failed

              I will just point out for future reference that that error is not necessarily a certificate problem. It could be, as was seemingly the case here, but all that actually tells you is the the negotiation didn't succeed within the 60s time limit. Usually that's just because the other side didn't respond at all.

              L 1 Reply Last reply Reply Quote 1
              • L
                lewis @stephenw10
                last edited by

                @stephenw10

                I looked at the logs too and didn't find anything obvious. I could not find anything else but once I renewed the certs and used the new config files, all went back to normal.

                What other reasons might this kind of thing happen? I assume not hacking?

                JonathanLeeJ stephenw10S 2 Replies Last reply Reply Quote 1
                • JonathanLeeJ
                  JonathanLee @lewis
                  last edited by

                  @lewis yeah that fixed it!!!

                  Make sure to upvote

                  L 1 Reply Last reply Reply Quote 1
                  • L
                    lewis @JonathanLee
                    last edited by

                    @JonathanLee What's an upvote? I gave the person who helped me a thumbs up :)

                    JonathanLeeJ 1 Reply Last reply Reply Quote 0
                    • stephenw10S
                      stephenw10 Netgate Administrator @lewis
                      last edited by stephenw10

                      @lewis said in VPN just suddenly down:

                      I assume not hacking?

                      Very unlikely. There are any number of reasons it might fail to connect. Including the cert(s) expiring.

                      More commonly some general connectivity issue would present like that as I said but here you were still able to connect to the firewall webgui outside the VPN so that's unlikely.

                      If you found a cert that had expired then that was almost certainly the cause.

                      I only pointed out it might not be that because a lot of users see the 'TLS Error' log and assume a crypto issue of some sort when it isn't. And google's probably going to send them to this thread. 😉

                      L 1 Reply Last reply Reply Quote 1
                      • L
                        lewis @stephenw10
                        last edited by

                        @stephenw10 Got it. Thanks for the additional information.

                        1 Reply Last reply Reply Quote 0
                        • JonathanLeeJ
                          JonathanLee @lewis
                          last edited by

                          @lewis said in VPN just suddenly down:

                          @JonathanLee What's an upvote? I gave the person who helped me a thumbs up :)

                          Screenshot 2024-07-09 at 15.39.52.png

                          (It is this thumb with a zero it means it is lonely and needs a upvote)

                          haha

                          Make sure to upvote

                          T2M5T 1 Reply Last reply Reply Quote 0
                          • T2M5T
                            T2M5 @JonathanLee
                            last edited by

                            @JonathanLee

                            75620283-fd7d-4b05-9a7b-227e657c48a1-image.png

                            No more, good work !

                            1 Reply Last reply Reply Quote 1
                            • First post
                              Last post
                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.