upgrading 2100 to 25.11 breaks openvpn - service not running
-
Just performed upgrade without any errors reported to 25.11 and openvpn has stopped running. Service says "Service not running? Unable to contact daemon". Restarting the service does not work, nor rebooting. This was running fine on 25.07.1 just before upgrade. Openvpn log says: "Options error: --client-to-client requires --mode server"
I will appreciate any suggestions!
Thank you.
-Andy near Boston
-
@andy58 said in upgrading 2100 to 25.11 breaks openvpn - service not running:
Openvpn log says: "Options error: --client-to-client requires --mode server
OpenVPN : is it a client or server ?
-
@Gertjan It's a server. I should have mentioned that !
It has worked fine for about 5 years, over many upgrades.
-Andy
-
Have a talk with with ?
This :@andy58 said in upgrading 2100 to 25.11 breaks openvpn - service not running:
Error: --client-to-client requires --mode server
.. not sure what it means, but does n't know it a "server" (anymore) ...
Can you show your OpenVPN server settings ?
Check your server settings with the "update notice for 25.11" - like : minimum cert (DH ?) size changed.
-
@Gertjan Yes, I did see the note about the DH parameter minimum length, but it was already set at the min 2048. Attached are screen shots of the server settings (top portion, which is what I believe would be involved).
Thank you.

-
This post is deleted! -
Hummm.
Never used "Peer to Peer with TLS" myself. I can image that with peer to peer there is no client server concept. That is : OpenVPN doesn't agree with me here (and you ^^).
I'm a "Remote access (SSL/TLS)" user myself.An this :
"Peer to Peer with TLS"and then : no TLS :

?
-
@andy58 "Peer to Peer" is for site to site...?
https://docs.netgate.com/pfsense/en/latest/recipes/openvpn-s2s-tls.html#configure-the-openvpn-server-instanceRemote access is:
https://docs.netgate.com/pfsense/en/latest/recipes/openvpn-ra.html#server-mode -
@SteveITS and @Gertjan
Maybe I should have said my application is peer to peer. The other side of the tunnel is another 2100. I have thought it more like client-server only because what I called the server side has the static IP, while the other end is dynamic. Does that change anything? I am puzzled why the service simply will not start, when this has never been a problem after previous upgrades, of which there have been many.-Andy
-
@andy58 I am having the same issue since upgrading to 25.11
@stephenw10 Are there any known issues with the site to site setup on the GUI?
-
@LostInIgnorance
Odd discovery. If I add the parameter "mode server" to the Advanced Configuration, the openvpn service seems to start ok. But no traffic passes. If I add the parameter "mode 2p2", which is the mode that always worked, the service cannot start, showing the same error "Unable to contact daemon".
-
@andy58 I have created a redmine issue as this forum entry doesn't seem to be getting any traction and is a bit of a huge pain as this affects a bunch of my clients on now not upgrading with appliances with S2S configurations.
-
@andy58 said in upgrading 2100 to 25.11 breaks openvpn - service not running:
@LostInIgnorance
Odd discovery. If I add the parameter "mode server" to the Advanced Configuration, the openvpn service seems to start ok. But no traffic passes. If I add the parameter "mode 2p2", which is the mode that always worked, the service cannot start, showing the same error "Unable to contact daemon".What happens if you leave the box empty?
My OpenVPN connections work fine here though I do not assign them to interfaces and use shared key. (we are actually moving things slowly over to Wireguard) and I do not have any options selected in that box.

-
@chpalmer Thank you for the question. The box always has been blank. The only reason I tried adding anything was because of the problem after the upgrade.
I have also migrated all my other S2S and client tunnels to wireguard. This is the only one waiting for migration, and I need the openvpn connection to do it! I am in Massachusetts and the installations are in Oregon. So not easy to go onsite. Argh! That said, the speed improvement with wireguard has been great. -
@LostInIgnorance Thank you for posting that bug report! -Andy
-
@andy58 said in upgrading 2100 to 25.11 breaks openvpn - service not running:
I am in Massachusetts and the installations are in Oregon. So not easy to go onsite. Argh!Yeah.. thats a drive for sure! I am north of Oregon myself a touch.
That said.. Id be happy to share more of my working setup if it gets you going even temporarily while you fight this one out.. Let me know.
Back when I did this more for my own company I had ten to twelve site to sites setups all pointed back to my primary box here. Yes moving over to WG made file transfers a bit faster.
Privacy Policy · Cookie Policy