<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[pfsense openvpn client to ubuntu server connects but wont reconnect]]></title><description><![CDATA[<p dir="auto">i can succesfully upload the config file into pfsense from ubuntu server and it connect well and works.  in the server i have the extra CCD files for the client specific override.<br />
however, if for any reason the router restarts (updates to pfsense or any other reason) the vpn will not start and wont connect.  i get the Unable to contact daemon: and if i press the start button, nothing happens!  i have to reupload the file again as if i am making a new client .<br />
logs show this</p>
<p dir="auto">Dec 30 13:49:33	openvpn	82621	event_wait : Interrupted system call (fd=-1,code=4)<br />
Dec 30 13:49:33	openvpn	82621	Closing TUN/TAP interface<br />
Dec 30 13:49:33	openvpn	82621	/sbin/ifconfig ovpnc1 10.8.0.0 -alias<br />
Dec 30 13:49:33	openvpn	82621	/usr/local/sbin/ovpn-linkdown ovpnc1 1500 0 10.8.0.0 255.255.255.0 init<br />
Dec 30 13:49:33	openvpn	11077	Flushing states on OpenVPN interface ovpnc1 (Link Down)<br />
Dec 30 13:49:34	openvpn	82621	SIGTERM[hard,] received, process exiting<br />
Dec 30 14:14:54	openvpn	22253	Unrecognized option or missing or extra parameter(s) in /var/etc/openvpn/client1/config.ovpn:39: block-outside-dns (2.6.12)<br />
Dec 30 14:14:54	openvpn	22253	Options error: Unrecognized option or missing or extra parameter(s) in /var/etc/openvpn/client1/config.ovpn:40: 89adff0d024f4b0cdeb8f2b5f0d7d52d (2.6.12)<br />
Dec 30 14:14:54	openvpn	22253	Use --help for more information.</p>
]]></description><link>https://forum.netgate.com/topic/195787/pfsense-openvpn-client-to-ubuntu-server-connects-but-wont-reconnect</link><generator>RSS for Node</generator><lastBuildDate>Tue, 14 Apr 2026 15:56:31 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/195787.rss" rel="self" type="application/rss+xml"/><pubDate>Tue, 31 Dec 2024 00:18:25 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to pfsense openvpn client to ubuntu server connects but wont reconnect on Tue, 04 Feb 2025 04:19:18 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/gertjan">@<bdi>Gertjan</bdi></a><br />
in case anyone has this issue, i found the solution.  besides removing the DNS line remove the TLS key from Custom options under advanced configuration towards the bottom of the openvpn client.  then go to the top and select USE A TLS KEY, then uncheck automatically generate a key and paste your key from your server here.<br />
then for TLS Key Usage Mode change it to TLS encryption and authentication.<br />
now it works after saving the changes!</p>
]]></description><link>https://forum.netgate.com/post/1205173</link><guid isPermaLink="true">https://forum.netgate.com/post/1205173</guid><dc:creator><![CDATA[ariban99]]></dc:creator><pubDate>Tue, 04 Feb 2025 04:19:18 GMT</pubDate></item><item><title><![CDATA[Reply to pfsense openvpn client to ubuntu server connects but wont reconnect on Thu, 02 Jan 2025 09:17:50 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/gertjan">@<bdi>Gertjan</bdi></a><br />
both my my client ovpn and the server config file has<br />
tls-version-min 1.2<br />
tls-cipher TLS-ECDHE-ECDSA-WITH-AES-128-GCM-SHA256</p>
<p dir="auto">yes my file has this for the TLS ( i broke the real one with lines that start with 111</p>
<p dir="auto">&lt;tls-crypt&gt;</p>
<h1><a class="anchor-offset"></a></h1>
<h1><a class="anchor-offset" name="2048-bit-openvpn-static-key"></a>2048 bit OpenVPN static key</h1>
<h1><a class="anchor-offset"></a></h1>
<p dir="auto">-----BEGIN OpenVPN Static key V1-----<br />
89adff0d024f4b0cdeb8f2b5f0d7d52d<br />
1111ec561<br />
6757da21950d7bf075cbd3b9430fd552<br />
7861728c9db9a99c8da70d09678c4c94<br />
6900a656e7642edc64ada8c960f9990e<br />
111120e67dc1<br />
4b996b5309bc42e7771fe43637fdc1ce<br />
986ea2b7c8116b5577c503a790bc0f0d<br />
111e2544be6b<br />
ab6a818fb8dd5e212ee5f0183e43ff1b<br />
-----END OpenVPN Static key V1-----<br />
&lt;/tls-crypt&gt;</p>
]]></description><link>https://forum.netgate.com/post/1201257</link><guid isPermaLink="true">https://forum.netgate.com/post/1201257</guid><dc:creator><![CDATA[ariban99]]></dc:creator><pubDate>Thu, 02 Jan 2025 09:17:50 GMT</pubDate></item><item><title><![CDATA[Reply to pfsense openvpn client to ubuntu server connects but wont reconnect on Thu, 02 Jan 2025 09:14:21 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/gertjan">@<bdi>Gertjan</bdi></a> the output is<br />
Available TLS Ciphers, listed in order of preference:</p>
<p dir="auto">For TLS 1.3 and newer (--tls-ciphersuites):</p>
<p dir="auto">TLS_AES_256_GCM_SHA384<br />
TLS_CHACHA20_POLY1305_SHA256<br />
TLS_AES_128_GCM_SHA256</p>
<p dir="auto">For TLS 1.2 and older (--tls-cipher):</p>
<p dir="auto">TLS-ECDHE-ECDSA-WITH-AES-256-GCM-SHA384<br />
TLS-ECDHE-RSA-WITH-AES-256-GCM-SHA384<br />
TLS-DHE-RSA-WITH-AES-256-GCM-SHA384<br />
TLS-ECDHE-ECDSA-WITH-CHACHA20-POLY1305-SHA256<br />
TLS-ECDHE-RSA-WITH-CHACHA20-POLY1305-SHA256<br />
TLS-DHE-RSA-WITH-CHACHA20-POLY1305-SHA256<br />
TLS-ECDHE-ECDSA-WITH-AES-128-GCM-SHA256<br />
TLS-ECDHE-RSA-WITH-AES-128-GCM-SHA256<br />
TLS-DHE-RSA-WITH-AES-128-GCM-SHA256<br />
TLS-ECDHE-ECDSA-WITH-AES-256-CBC-SHA384<br />
TLS-ECDHE-RSA-WITH-AES-256-CBC-SHA384<br />
TLS-DHE-RSA-WITH-AES-256-CBC-SHA256<br />
TLS-ECDHE-ECDSA-WITH-AES-128-CBC-SHA256<br />
TLS-ECDHE-RSA-WITH-AES-128-CBC-SHA256<br />
TLS-DHE-RSA-WITH-AES-128-CBC-SHA256<br />
TLS-ECDHE-ECDSA-WITH-AES-256-CBC-SHA<br />
TLS-ECDHE-RSA-WITH-AES-256-CBC-SHA<br />
TLS-DHE-RSA-WITH-AES-256-CBC-SHA<br />
TLS-ECDHE-ECDSA-WITH-AES-128-CBC-SHA<br />
TLS-ECDHE-RSA-WITH-AES-128-CBC-SHA<br />
TLS-DHE-RSA-WITH-AES-128-CBC-SHA</p>
<p dir="auto">Be aware that that whether a cipher suite in this list can actually work<br />
depends on the specific setup of both peers. See the man page entries of<br />
--tls-cipher and --show-tls for more details.</p>
]]></description><link>https://forum.netgate.com/post/1201256</link><guid isPermaLink="true">https://forum.netgate.com/post/1201256</guid><dc:creator><![CDATA[ariban99]]></dc:creator><pubDate>Thu, 02 Jan 2025 09:14:21 GMT</pubDate></item><item><title><![CDATA[Reply to pfsense openvpn client to ubuntu server connects but wont reconnect on Thu, 02 Jan 2025 09:04:42 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/ariban99">@<bdi>ariban99</bdi></a> said in <a href="/post/1201241">pfsense openvpn client to ubuntu server connects but wont reconnect</a>:</p>
<blockquote>
<p dir="auto">tls-cipher TLS-ECDHE-ECDSA-WITH-AES-128-GCM-SHA256</p>
</blockquote>
<p dir="auto">Hummm.</p>
<p dir="auto">Run</p>
<pre><code>openvpn --show-tls
</code></pre>
<p dir="auto">on the pfSense command line (the real one, console or SSH).<br />
pfSense 2.7.2 or 24.11 uses a recent OpenVPN, 2.6.12 and probably doesn't support your "TLS-ECDHE-ECDSA-WITH-AES-128-GCM-SHA256" (I guess ...)</p>
<p dir="auto">I don't recall I've seen these two :</p>
<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/ariban99">@<bdi>ariban99</bdi></a> said in <a href="/post/1201241">pfsense openvpn client to ubuntu server connects but wont reconnect</a>:</p>
<blockquote>
<p dir="auto">tls-version-min 1.2<br />
tls-cipher TLS-ECDHE-ECDSA-WITH-AES-128-GCM-SHA256</p>
</blockquote>
<p dir="auto">in my config files - client or server.</p>
<hr />
<p dir="auto">This part :</p>
<pre><code>&lt;tls-crypt&gt;
#
# 2048 bit OpenVPN static key
#
-----BEGIN OpenVPN Static key V1-----
893c76e84187bb1e40f987c83db4d256
affa44d8bdafead00ef6c206862f1d39
fda1cac0ea6cd969c2f35d1777256f90
e11433e025ae0024a2583ac71db58b55
857f07c3e2ff571cee71e5d7070b07a4
b5a7b74ab7a4fc9420104f0760840fed
47ecc410d57de29ba7c75e02b91dda2d
.......
97577cfa0a03aa384350e49bf26d2b15
97ba6f852d7b3531f8204a73c7f1293f
ece32853d36402fe32c384500c0baa5d
d98ddda17568898ed19b75671bb24467
8c5a6102dc6ab3275c6fa36d8853b668
-----END OpenVPN Static key V1-----
&lt;/tls-crypt&gt;
</code></pre>
<p dir="auto">is 'mandatory'.<br />
Yours looks the same ?</p>
]]></description><link>https://forum.netgate.com/post/1201255</link><guid isPermaLink="true">https://forum.netgate.com/post/1201255</guid><dc:creator><![CDATA[Gertjan]]></dc:creator><pubDate>Thu, 02 Jan 2025 09:04:42 GMT</pubDate></item><item><title><![CDATA[Reply to pfsense openvpn client to ubuntu server connects but wont reconnect on Thu, 02 Jan 2025 08:49:48 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/ariban99">@<bdi>ariban99</bdi></a> i tried removing the tls-cipher and hence got the second error<br />
Jan 1 22:37:45 openvpn 94131 Options error: Unrecognized option or missing or extra parameter(s) in /var/etc/openvpn/client1/config.ovpn:34: &lt;tls-crypt&gt;-----BEGIN (2.6.12)<br />
Jan 1 22:37:45 openvpn 94131 Use --help for more information.<br />
but if i put it back i only get<br />
Jan 1 22:35:02 openvpn 82472 MANAGEMENT: Client connected from /var/etc/openvpn/client1/sock<br />
Jan 1 22:35:02 openvpn 82472 MANAGEMENT: CMD 'state 1'<br />
Jan 1 22:35:02 openvpn 82472 MANAGEMENT: CMD 'status 2'<br />
Jan 1 22:35:02 openvpn 82472 MANAGEMENT: Client disconnected<br />
Jan 1 22:35:22 openvpn 82472 event_wait : Interrupted system call (fd=-1,code=4)<br />
Jan 1 22:35:22 openvpn 82472 Closing TUN/TAP interface<br />
Jan 1 22:35:22 openvpn 82472 /sbin/ifconfig ovpnc1 10.8.0.0 -alias<br />
Jan 1 22:35:22 openvpn 82472 /usr/local/sbin/ovpn-linkdown ovpnc1 1500 0 10.8.0.0 255.255.255.0 init<br />
Jan 1 22:35:22 openvpn 48655 Flushing states on OpenVPN interface ovpnc1 (Link Down)<br />
Jan 1 22:35:22 openvpn 82472 SIGTERM[hard,] received, process exiting<br />
Jan 1 22:35:23 openvpn 52243 Options error: Unrecognized option or missing or extra parameter(s) in /var/etc/openvpn/client1/config.ovpn:35: tls-cipher (2.6.12)<br />
Jan 1 22:35:23 openvpn 52243 Use --help for more information.</p>
]]></description><link>https://forum.netgate.com/post/1201252</link><guid isPermaLink="true">https://forum.netgate.com/post/1201252</guid><dc:creator><![CDATA[ariban99]]></dc:creator><pubDate>Thu, 02 Jan 2025 08:49:48 GMT</pubDate></item><item><title><![CDATA[Reply to pfsense openvpn client to ubuntu server connects but wont reconnect on Thu, 02 Jan 2025 08:39:13 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/gertjan">@<bdi>Gertjan</bdi></a> i removed the line completely, now the logs show an issue with the tls cipher<br />
Jan 1 22:35:02	openvpn	82472	MANAGEMENT: Client connected from /var/etc/openvpn/client1/sock<br />
Jan 1 22:35:02	openvpn	82472	MANAGEMENT: CMD 'state 1'<br />
Jan 1 22:35:02	openvpn	82472	MANAGEMENT: CMD 'status 2'<br />
Jan 1 22:35:02	openvpn	82472	MANAGEMENT: Client disconnected<br />
Jan 1 22:35:22	openvpn	82472	event_wait : Interrupted system call (fd=-1,code=4)<br />
Jan 1 22:35:22	openvpn	82472	Closing TUN/TAP interface<br />
Jan 1 22:35:22	openvpn	82472	/sbin/ifconfig ovpnc1 10.8.0.0 -alias<br />
Jan 1 22:35:22	openvpn	82472	/usr/local/sbin/ovpn-linkdown ovpnc1 1500 0 10.8.0.0 255.255.255.0 init<br />
Jan 1 22:35:22	openvpn	48655	Flushing states on OpenVPN interface ovpnc1 (Link Down)<br />
Jan 1 22:35:22	openvpn	82472	SIGTERM[hard,] received, process exiting<br />
Jan 1 22:35:23	openvpn	52243	Options error: Unrecognized option or missing or extra parameter(s) in /var/etc/openvpn/client1/config.ovpn:35: tls-cipher (2.6.12)<br />
Jan 1 22:35:23	openvpn	52243	Use --help for more information.<br />
Jan 1 22:37:45	openvpn	94131	Options error: Unrecognized option or missing or extra parameter(s) in /var/etc/openvpn/client1/config.ovpn:34: &lt;tls-crypt&gt;-----BEGIN (2.6.12)<br />
Jan 1 22:37:45	openvpn	94131	Use --help for more information.</p>
]]></description><link>https://forum.netgate.com/post/1201245</link><guid isPermaLink="true">https://forum.netgate.com/post/1201245</guid><dc:creator><![CDATA[ariban99]]></dc:creator><pubDate>Thu, 02 Jan 2025 08:39:13 GMT</pubDate></item><item><title><![CDATA[Reply to pfsense openvpn client to ubuntu server connects but wont reconnect on Thu, 02 Jan 2025 07:57:17 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/ariban99">@<bdi>ariban99</bdi></a> said in <a href="/post/1201241">pfsense openvpn client to ubuntu server connects but wont reconnect</a>:</p>
<blockquote>
<p dir="auto">setenv opt block-outside-dns # Prevent Windows 10 DNS leak</p>
</blockquote>
<p dir="auto">That's line 22, or close, not line 39 as your pfSense OpenVPN client said.</p>
<p dir="auto">Double check with what the OpenVPN client actually uses : it here :</p>
<pre><code>/var/etc/openvpn/client1/config.opvn
</code></pre>
<p dir="auto">(the '1' here might be a '2' )</p>
<p dir="auto">The rest of the format looks right to me.<br />
Just to be sure, before importing, remove the inline comment :</p>
<p dir="auto"><img src="/assets/uploads/files/1735804562155-a76e70ef-af39-4f27-b0eb-b7b5fb746983-image.png" alt="a76e70ef-af39-4f27-b0eb-b7b5fb746983-image.png" class=" img-fluid img-markdown" /></p>
<p dir="auto">Or remove that line entirely, as it is a Windows only option, and pfSense isn't Windows ;)</p>
]]></description><link>https://forum.netgate.com/post/1201243</link><guid isPermaLink="true">https://forum.netgate.com/post/1201243</guid><dc:creator><![CDATA[Gertjan]]></dc:creator><pubDate>Thu, 02 Jan 2025 07:57:17 GMT</pubDate></item><item><title><![CDATA[Reply to pfsense openvpn client to ubuntu server connects but wont reconnect on Thu, 02 Jan 2025 07:45:53 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/gertjan">@<bdi>Gertjan</bdi></a> thank you for your reply,  this is the ovpn file (i changed the ip and certs)<br />
client<br />
proto udp<br />
explicit-exit-notify<br />
remote 1.1.1.1 1194<br />
dev tun<br />
resolv-retry infinite<br />
nobind<br />
persist-key<br />
persist-tun<br />
remote-cert-tls server<br />
verify-x509-name server_11e name<br />
auth SHA256<br />
auth-nocache<br />
cipher AES-128-GCM<br />
tls-client<br />
pull-filter ignore redirect-gateway<br />
route-nopull<br />
route 10.8.0.0 255.255.255.0<br />
tls-version-min 1.2<br />
tls-cipher TLS-ECDHE-ECDSA-WITH-AES-128-GCM-SHA256<br />
ignore-unknown-option block-outside-dns<br />
setenv opt block-outside-dns # Prevent Windows 10 DNS leak<br />
verb 3<br />
&lt;ca&gt;<br />
-----BEGIN CERTIFICATE-----<br />
111<br />
-----END CERTIFICATE-----<br />
&lt;/ca&gt;<br />
&lt;cert&gt;<br />
-----BEGIN CERTIFICATE-----<br />
11<br />
-----END CERTIFICATE-----<br />
&lt;/cert&gt;<br />
&lt;key&gt;<br />
-----BEGIN PRIVATE KEY-----<br />
11<br />
-----END PRIVATE KEY-----<br />
&lt;/key&gt;<br />
&lt;tls-crypt&gt;</p>
<h1><a class="anchor-offset"></a></h1>
<h1><a class="anchor-offset" name="2048-bit-openvpn-static-key"></a>2048 bit OpenVPN static key</h1>
<h1><a class="anchor-offset"></a></h1>
<p dir="auto">-----BEGIN OpenVPN Static key V1-----<br />
11<br />
-----END OpenVPN Static key V1-----<br />
&lt;/tls-crypt&gt;</p>
]]></description><link>https://forum.netgate.com/post/1201241</link><guid isPermaLink="true">https://forum.netgate.com/post/1201241</guid><dc:creator><![CDATA[ariban99]]></dc:creator><pubDate>Thu, 02 Jan 2025 07:45:53 GMT</pubDate></item><item><title><![CDATA[Reply to pfsense openvpn client to ubuntu server connects but wont reconnect on Thu, 02 Jan 2025 07:42:26 GMT]]></title><description><![CDATA[<p dir="auto">This one :</p>
<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/ariban99">@<bdi>ariban99</bdi></a> said in <a href="/post/1201065">pfsense openvpn client to ubuntu server connects but wont reconnect</a>:</p>
<blockquote>
<p dir="auto">Dec 30 14:14:54 openvpn 22253 Unrecognized option or missing or extra parameter(s) in /var/etc/openvpn/client1/config.ovpn:39: block-outside-dns (2.6.12)</p>
</blockquote>
<p dir="auto">You see this option ( taken from the pfSense Client Export page ) :</p>
<p dir="auto"><img src="/assets/uploads/files/1735803113236-f901578e-be05-4d67-9b16-c6d0d1491e91-image.png" alt="f901578e-be05-4d67-9b16-c6d0d1491e91-image.png" class=" img-fluid img-markdown" /></p>
<p dir="auto">I know, you've created your client ovpn config file on an Ubuntu OpenVPN server, butt somehow, the option was set in the config file. As pfSense, and thus the OpenVPN client isn't "Windows" it tells you that it can't understand that option.<br />
Open your ovpn config file in a etxt editor, you will find :</p>
<pre><code>setenv opt block-outside-dns
</code></pre>
<p dir="auto">Line 39 ;)</p>
<p dir="auto">and that option makes only sense on a Windows OpenVPN system, not a pfSense OpenVPN.</p>
<p dir="auto">Btw : It's just a message telling the admin, "what are you doing ? I'm not a Windows system, I will ignore this option".</p>
<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/ariban99">@<bdi>ariban99</bdi></a> said in <a href="/post/1201065">pfsense openvpn client to ubuntu server connects but wont reconnect</a>:</p>
<blockquote>
<p dir="auto">Dec 30 14:14:54 openvpn 22253 Options error: Unrecognized option or missing or extra parameter(s) in /var/etc/openvpn/client1/config.ovpn:40: 89adff0d024f4b0cdeb8f2b5f0d7d52d (2.6.12)</p>
</blockquote>
<p dir="auto">This is the actual error that will make the pfSense OpenVPN client to fail.</p>
<p dir="auto">Open the config file again.<br />
You'll see stuff like this :</p>
<p dir="auto"><img src="/assets/uploads/files/1735803452328-fd39a25d-a2ed-4f19-bc8d-93afe463d747-image.png" alt="fd39a25d-a2ed-4f19-bc8d-93afe463d747-image.png" class=" img-fluid img-markdown" /></p>
<p dir="auto">Some how, the ovpn config is miss interpreted, and the OpenVPN clients completely fails.</p>
<p dir="auto">The line was 40 .... but that can't be treu, because there would have to start with (for example) :</p>
<pre><code>&lt;ca&gt;
-----BEGIN CERTIFICATE-----
</code></pre>
<p dir="auto">or well ready know that on line 39 you have this</p>
<pre><code>setenv opt block-outside-dns
</code></pre>
<p dir="auto">Show us your ovpn config file.</p>
]]></description><link>https://forum.netgate.com/post/1201240</link><guid isPermaLink="true">https://forum.netgate.com/post/1201240</guid><dc:creator><![CDATA[Gertjan]]></dc:creator><pubDate>Thu, 02 Jan 2025 07:42:26 GMT</pubDate></item></channel></rss>