<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[OpenVPN Renegotiation Time with MFA]]></title><description><![CDATA[<p dir="auto">Hello,</p>
<p dir="auto">We recently deployed EntraID MFA with our OpenVPN deployment. It works great minus one drawback that we've come across. Currently we have reneg-sec set at the server and client as reneg-sec 36000; We're finding that clients that actually stay connected for the term are only staying persistent for 9 hours and not the full 10 hours. Short of deploying a longer renegotiation time to compensate, has anyone seen these settings not honor the full timeout amount?</p>
<p dir="auto">Thanks!</p>
]]></description><link>https://forum.netgate.com/topic/195907/openvpn-renegotiation-time-with-mfa</link><generator>RSS for Node</generator><lastBuildDate>Sun, 08 Mar 2026 23:26:55 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/195907.rss" rel="self" type="application/rss+xml"/><pubDate>Wed, 08 Jan 2025 21:24:09 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to OpenVPN Renegotiation Time with MFA on Tue, 21 Jan 2025 12:58:04 GMT]]></title><description><![CDATA[<p dir="auto">@bozo-bogd</p>
<p dir="auto">We tried setting reneg-sec on both sides to 0 but it caused the client to constant want the MFA prompt satisfied. The pings settings are already set to 0</p>
<p dir="auto">Details from Azure. We have a CA policy that requires MFA when authenticating to the EntraID account. The Entra RADIUS VPN app is installed on our RADIUS box to interject the MFA prompt when authenticating to our local AD with the OpenVPN client. The MFA app has a limited config, with caching and renegotiation settings not being options.</p>
]]></description><link>https://forum.netgate.com/post/1203402</link><guid isPermaLink="true">https://forum.netgate.com/post/1203402</guid><dc:creator><![CDATA[rebelscum]]></dc:creator><pubDate>Tue, 21 Jan 2025 12:58:04 GMT</pubDate></item><item><title><![CDATA[Reply to OpenVPN Renegotiation Time with MFA on Tue, 21 Jan 2025 09:35:05 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/rebelscum">@<bdi>rebelscum</bdi></a> said in <a href="/post/1202057">OpenVPN Renegotiation Time with MFA</a>:</p>
<blockquote>
<p dir="auto">deployed EntraID MFA with our Op</p>
</blockquote>
<p dir="auto">Dear friend,</p>
<p dir="auto">Would you be so kind to share some details how you configured this, from azure, pfsense and openvpn server perspective ?</p>
<p dir="auto">As for re-negotiation, we use reneg-sec 0 on both sides, + ping settings Inactive 0</p>
<p dir="auto">Thank you.</p>
]]></description><link>https://forum.netgate.com/post/1203383</link><guid isPermaLink="true">https://forum.netgate.com/post/1203383</guid><dc:creator><![CDATA[bozo.bogd]]></dc:creator><pubDate>Tue, 21 Jan 2025 09:35:05 GMT</pubDate></item></channel></rss>