Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login
    Introducing Netgate Nexus: Multi-Instance Management at Your Fingertips.

    upgrading 2100 to 25.11 breaks openvpn - service not running

    Scheduled Pinned Locked Moved OpenVPN
    16 Posts 6 Posters 1.8k Views 6 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • A Offline
      andy58
      last edited by

      Just performed upgrade without any errors reported to 25.11 and openvpn has stopped running. Service says "Service not running? Unable to contact daemon". Restarting the service does not work, nor rebooting. This was running fine on 25.07.1 just before upgrade. Openvpn log says: "Options error: --client-to-client requires --mode server"

      I will appreciate any suggestions!

      Thank you.

      -Andy near Boston

      GertjanG 1 Reply Last reply Reply Quote 0
      • GertjanG Offline
        Gertjan @andy58
        last edited by

        @andy58 said in upgrading 2100 to 25.11 breaks openvpn - service not running:

        Openvpn log says: "Options error: --client-to-client requires --mode server

        OpenVPN : is it a client or server ?

        No "help me" PM's please. Use the forum, the community will thank you.

        A 1 Reply Last reply Reply Quote 0
        • A Offline
          andy58 @Gertjan
          last edited by

          @Gertjan It's a server. I should have mentioned that !

          It has worked fine for about 5 years, over many upgrades.

          -Andy

          GertjanG 1 Reply Last reply Reply Quote 0
          • GertjanG Offline
            Gertjan @andy58
            last edited by

            @andy58

            Have a talk with with ?
            This :

            @andy58 said in upgrading 2100 to 25.11 breaks openvpn - service not running:

            Error: --client-to-client requires --mode server

            .. not sure what it means, but does n't know it a "server" (anymore) ...

            Can you show your OpenVPN server settings ?

            Check your server settings with the "update notice for 25.11" - like : minimum cert (DH ?) size changed.

            No "help me" PM's please. Use the forum, the community will thank you.

            A 1 Reply Last reply Reply Quote 0
            • A Offline
              andy58 @Gertjan
              last edited by

              @Gertjan Yes, I did see the note about the DH parameter minimum length, but it was already set at the min 2048. Attached are screen shots of the server settings (top portion, which is what I believe would be involved).
              Thank you.
              Openvpn_settings1.jpg Openvpn_settings2.jpg

              GertjanG SteveITSS 2 Replies Last reply Reply Quote 0
              • tinfoilmattT Offline
                tinfoilmatt LAYER 8
                last edited by

                This post is deleted!
                1 Reply Last reply Reply Quote 0
                • GertjanG Offline
                  Gertjan @andy58
                  last edited by

                  @andy58

                  Hummm.
                  Never used "Peer to Peer with TLS" myself. I can image that with peer to peer there is no client server concept. That is : OpenVPN doesn't agree with me here (and you ^^).
                  I'm a "Remote access (SSL/TLS)" user myself.

                  An this :
                  "Peer to Peer with TLS"

                  and then : no TLS :

                  5a70e982-18b4-4267-a536-47ba3de3e2bc-image.png

                  ?

                  No "help me" PM's please. Use the forum, the community will thank you.

                  1 Reply Last reply Reply Quote 0
                  • SteveITSS Offline
                    SteveITS Rebel Alliance @andy58
                    last edited by

                    @andy58 "Peer to Peer" is for site to site...?
                    https://docs.netgate.com/pfsense/en/latest/recipes/openvpn-s2s-tls.html#configure-the-openvpn-server-instance

                    Remote access is:
                    https://docs.netgate.com/pfsense/en/latest/recipes/openvpn-ra.html#server-mode

                    To upgrade, select your branch in System/Update/Update Settings. When upgrading, allow 10-15 minutes to reboot, or more depending on packages, CPU, and/or disk speed.
                    Only install packages for your version of pfSense.
                    Upvote 👍 helpful posts!

                    A 1 Reply Last reply Reply Quote 0
                    • A Offline
                      andy58 @SteveITS
                      last edited by

                      @SteveITS and @Gertjan
                      Maybe I should have said my application is peer to peer. The other side of the tunnel is another 2100. I have thought it more like client-server only because what I called the server side has the static IP, while the other end is dynamic. Does that change anything? I am puzzled why the service simply will not start, when this has never been a problem after previous upgrades, of which there have been many.

                      -Andy

                      L 1 Reply Last reply Reply Quote 0
                      • L Offline
                        LostInIgnorance @andy58
                        last edited by

                        @andy58 I am having the same issue since upgrading to 25.11

                        @stephenw10 Are there any known issues with the site to site setup on the GUI?

                        A 1 Reply Last reply Reply Quote 0
                        • A Offline
                          andy58 @LostInIgnorance
                          last edited by

                          @LostInIgnorance
                          Odd discovery. If I add the parameter "mode server" to the Advanced Configuration, the openvpn service seems to start ok. But no traffic passes. If I add the parameter "mode 2p2", which is the mode that always worked, the service cannot start, showing the same error "Unable to contact daemon".

                          d07b7cfc-c195-40ca-a317-f04341e9dcc6-image.png

                          L chpalmerC 2 Replies Last reply Reply Quote 0
                          • L Offline
                            LostInIgnorance @andy58
                            last edited by LostInIgnorance

                            @andy58 I have created a redmine issue as this forum entry doesn't seem to be getting any traction and is a bit of a huge pain as this affects a bunch of my clients on now not upgrading with appliances with S2S configurations.

                            https://redmine.pfsense.org/issues/16617

                            A 1 Reply Last reply Reply Quote 0
                            • chpalmerC Offline
                              chpalmer @andy58
                              last edited by chpalmer

                              @andy58 said in upgrading 2100 to 25.11 breaks openvpn - service not running:

                              @LostInIgnorance
                              Odd discovery. If I add the parameter "mode server" to the Advanced Configuration, the openvpn service seems to start ok. But no traffic passes. If I add the parameter "mode 2p2", which is the mode that always worked, the service cannot start, showing the same error "Unable to contact daemon".

                              What happens if you leave the box empty?

                              My OpenVPN connections work fine here though I do not assign them to interfaces and use shared key. (we are actually moving things slowly over to Wireguard) and I do not have any options selected in that box.

                              open.jpg

                              Triggering snowflakes one by one..
                              Primary- Intel(R) Pentium(R) CPU G4400 @ 3.30GHz on an M470 WG box. pfSense CE 2.8.1
                              Lab Unit- Intel(R) Core(TM) i5-4590T CPU @ 2.00GHz on an M400 WG box. pfSense+

                              A 1 Reply Last reply Reply Quote 0
                              • A Offline
                                andy58 @chpalmer
                                last edited by

                                @chpalmer Thank you for the question. The box always has been blank. The only reason I tried adding anything was because of the problem after the upgrade.
                                I have also migrated all my other S2S and client tunnels to wireguard. This is the only one waiting for migration, and I need the openvpn connection to do it! I am in Massachusetts and the installations are in Oregon. So not easy to go onsite. Argh! That said, the speed improvement with wireguard has been great.

                                chpalmerC 1 Reply Last reply Reply Quote 0
                                • A Offline
                                  andy58 @LostInIgnorance
                                  last edited by

                                  @LostInIgnorance Thank you for posting that bug report! -Andy

                                  1 Reply Last reply Reply Quote 0
                                  • chpalmerC Offline
                                    chpalmer @andy58
                                    last edited by

                                    @andy58 said in upgrading 2100 to 25.11 breaks openvpn - service not running:
                                    I am in Massachusetts and the installations are in Oregon. So not easy to go onsite. Argh!

                                    Yeah.. thats a drive for sure! I am north of Oregon myself a touch.

                                    That said.. Id be happy to share more of my working setup if it gets you going even temporarily while you fight this one out.. Let me know.

                                    Back when I did this more for my own company I had ten to twelve site to sites setups all pointed back to my primary box here. Yes moving over to WG made file transfers a bit faster.

                                    Triggering snowflakes one by one..
                                    Primary- Intel(R) Pentium(R) CPU G4400 @ 3.30GHz on an M470 WG box. pfSense CE 2.8.1
                                    Lab Unit- Intel(R) Core(TM) i5-4590T CPU @ 2.00GHz on an M400 WG box. pfSense+

                                    1 Reply Last reply Reply Quote 0
                                    • First post
                                      Last post
                                    Copyright 2026 Rubicon Communications LLC (Netgate). All rights reserved.
                                    Privacy Policy · Cookie Policy