<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[OpenVPN clients and resolv-retry]]></title><description><![CDATA[<p dir="auto">I posted this comment on RedMine <a href="https://redmine.pfsense.org/issues/3894" target="_blank" rel="noopener noreferrer nofollow ugc">https://redmine.pfsense.org/issues/3894</a></p>
<blockquote>
<p dir="auto">I have systems where the internet somewhere goes away quite regularly. The actual pfSense WAN interface to the upstream device (ISP, whatever) is fine, so there is no link down/link up event for pfSense to see in that sense.<br />
OpenVPN site-to-clients time out after a bit, and then try to find their server end again. For this they try to resolve the FQDN of the server again. However the ISP issue lasts more than a few minutes, the DNS resolution fails, and with the now-default "resolv-retry 2", the OpenVPN client simply gives up and exits.<br />
Then there is nothing in the system to try and start it again, either when ISP internet is better, or every so often. The clients stay down.<br />
I have noticed this happen quite a few times recently and now realise the "resolv-retry 2" change is the reason for the new behavior. It seems odd to have a config that will simply exit in a reasonably-expected situation (DNS resolution has gone away for a few minutes) and that the client process just exits and is never restarted.<br />
I can select "Infinitely resolve server" and that will put things back the way they were. But it will be a hassle for lots of users to find this out after upgrading to 2.2<br />
But with Chris' comment above about the SIGKILL/SIGTERM stuff - if that really resolves the underlying issue, then would it be best to revert the commit of the "resolv-retry 2" stuff?</p>
</blockquote>
<p dir="auto">My home system has been running 2.2-BETA with 2 site-to-site clients to 2 of our offices. While at work, my home disappears from view. I get home to find that both OpenVPN site-to-site clients have decided to give up. Seems a bit of an odd "feature" for a component like this to be able to "give up" and exit without any code that tries to bring it back to life again.</p>
<p dir="auto">Comments welcome.</p>
]]></description><link>https://forum.netgate.com/topic/76497/openvpn-clients-and-resolv-retry</link><generator>RSS for Node</generator><lastBuildDate>Sat, 18 Jul 2026 18:28:09 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/76497.rss" rel="self" type="application/rss+xml"/><pubDate>Tue, 02 Dec 2014 16:16:44 GMT</pubDate><ttl>60</ttl></channel></rss>