Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    OpenVPN Renegotiation Time with MFA

    Scheduled Pinned Locked Moved OpenVPN
    3 Posts 2 Posters 173 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • R
      rebelscum
      last edited by

      Hello,

      We recently deployed EntraID MFA with our OpenVPN deployment. It works great minus one drawback that we've come across. Currently we have reneg-sec set at the server and client as reneg-sec 36000; We're finding that clients that actually stay connected for the term are only staying persistent for 9 hours and not the full 10 hours. Short of deploying a longer renegotiation time to compensate, has anyone seen these settings not honor the full timeout amount?

      Thanks!

      B 1 Reply Last reply Reply Quote 0
      • B
        bozo.bogd @rebelscum
        last edited by

        @rebelscum said in OpenVPN Renegotiation Time with MFA:

        deployed EntraID MFA with our Op

        Dear friend,

        Would you be so kind to share some details how you configured this, from azure, pfsense and openvpn server perspective ?

        As for re-negotiation, we use reneg-sec 0 on both sides, + ping settings Inactive 0

        Thank you.

        R 1 Reply Last reply Reply Quote 0
        • R
          rebelscum @bozo.bogd
          last edited by

          @bozo-bogd

          We tried setting reneg-sec on both sides to 0 but it caused the client to constant want the MFA prompt satisfied. The pings settings are already set to 0

          Details from Azure. We have a CA policy that requires MFA when authenticating to the EntraID account. The Entra RADIUS VPN app is installed on our RADIUS box to interject the MFA prompt when authenticating to our local AD with the OpenVPN client. The MFA app has a limited config, with caching and renegotiation settings not being options.

          1 Reply Last reply Reply Quote 0
          • First post
            Last post
          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.