Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login
    Introducing Netgate Nexus: Multi-Instance Management at Your Fingertips.

    OpenVPN Can't Connect?

    Scheduled Pinned Locked Moved OpenVPN
    2 Posts 2 Posters 109 Views 2 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • M Offline
      MichaelCropper
      last edited by

      Setup;

      • pfSense
        • OpenVPN Server + Certificate Authority + Certificate + User
        • LAN
          • Stuff

      Mobile Phone

      • OpenVPN Connect App
        • Import OpenVPN Client Export Plugin File

      Issue - Times out.

      When I was setting up OpenVPN on pfSense I followed a few guides, didn't quite get it right first time round, but after about the 3rd time of deleting everything and recreating, it seemed to get everything in line.

      Service is up and running, yet when I try and connect from my mobile phone (via mobile phone carrier, not via WiFi) the connection to the VPN just times out and doesn't connect.

      Looking at the logs in pfSense for OpenVPN, nothing even shows up as something is trying to connect. The closest I've got to seeing something actually trying to connect in the logs was when I changed the Port from 1194 to 443 which OpenVPN just thought it was a bot trying to scan and showed this error in the logs;

      Jul 25 18:41:08	openvpn	49588	TCP connection established with [AF_INET]{**unrecognisable IP address, wasn't the mobile phone's IP address**}:23289
      Jul 25 18:41:08	openvpn	49588	{**unrecognisable IP address, wasn't the mobile phone's IP address**}:53456 WARNING: Bad encapsulated packet length from peer (5635), which must be > 0 and <= 1768 -- please ensure that --tun-mtu or --link-mtu is equal on both peers -- this condition could also indicate a possible active attack on the TCP link -- [Attempting restart...]
      

      Reading up around this, there are reports I can see where some mobile phone carriers can actually block this stuff or get in the way with performance things, so not sure if that could be related - I'll have a chat with them tomorrow. But searching their official documentation, they say they don't, yet the forum posts suggest different, so difficult to know for sure.

      What are the best debugging steps to get this working?

      Seemed like everything was relatively straight forward to setup until it didn't actually work and testing with different TCP/UDP Ports and Firewall Rules seemed to end up in a bit of a dead end with still not being able to connect after trying about 10x different configurations.

      All other configurations I've tried showed nothing in the logs and ont he OpenVPN Connect App on the mobile phone, it just timed out every time.

      GertjanG 1 Reply Last reply Reply Quote 0
      • GertjanG Offline
        Gertjan @MichaelCropper
        last edited by Gertjan

        @MichaelCropper said in OpenVPN Can't Connect?:

        Issue - Times out.

        That's the message you see with the Client VPN app.

        On the pfSense side of things, you can check easily if the traffic initiated by the phone arrives at the WAN 'gate' (NIC) of pfSense :

        Remember the firewall rule ?
        Here :

        7432cbc1-f04b-4ec1-8041-a7696f2a7286-image.png

        You the "States" (marked green) : if it stays on 0/0 then you have a solid proof nothing arrives at the WAN pfSense interface.

        Edit : My 'Source' is "pfB_Europe_v4" which is a "allowed IP list". Which means I can only connect when I'm 'in Europe'.
        Normally, you should the Source to '*' = everybody.

        When you connect with your phone, and the States change (go up), then look at the VPN Logs :
        Here / this is what you should see :

        00504ebc-0f15-4fb5-94b1-a0a749a3a118-image.png

        == clean : no errors, no warnings.

        No "help me" PM's please. Use the forum, the community will thank you.

        1 Reply Last reply Reply Quote 0
        • First post
          Last post
        Copyright 2026 Rubicon Communications LLC (Netgate). All rights reserved.
        Privacy Policy · Cookie Policy