LinuxQuestions.org
Help answer threads with 0 replies.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Networking
User Name
Password
Linux - Networking This forum is for any issue related to networks or networking.
Routing, network cards, OSI, etc. Anything is fair game.

Notices


Reply
  Search this Thread
Old 12-07-2011, 02:12 AM   #1
pingu
Senior Member
 
Registered: Jul 2004
Location: Skuttunge SWEDEN
Distribution: Debian preferably
Posts: 1,350

Rep: Reputation: 127Reputation: 127
Weird open-vpn problem, connection restarts with long delay.


Running pfSense 2.0 on a Dell server, using OpenVPN Roadwarrior.
In short: Some - but only some! - vpn clients restarts every 2 minutes after "inactivity timeout, ping-restart". Seems to be some issue with the p12-file (!).

I have created 5 user-connections in pfSense, Client config exported via Client Export -> Configuration archive.
The .ovpn and .key files are identical for all users, .p12 is password protected.
Problem:
* Some Windows-users have problem with the tunnel being restarted every 2 minutes.
Due to the OpenVPN log reconnection is done in a few seconds, however for the client the vpn-connection stalls for about half a minute each time.
* On my Debian connection is not restarted.
* On my Win7 connection is restarted with delay.
Fix one: The config-file (.ovpn) created has unix-style LF/CR!
So in Windows the config is all in one single line, with no space before new line.
I fixed this with notepad, and my problems are gone.
However, for my colleague this doesn't change anything.
But when he uses my .p12 then the problems are gone, when I use his .p12 I get the restart problem (both Win & Debian)!
So it has to be related to the .p12, how is that possible?

Summary:
2 WinXP both has problem.
Out of 5 users on Win7 Pro 3 have the delay problem 2 has no problems.
Adding "ping-restart 0" doesn't help.

Details:
Setup

Firewall & vpn server:
* One pfsense box in serverhall with one public & one private ip.
* OpenVPN as Roadwarrior server, Remote Access SSL/TLS.
* Certificate created, TLS Auth uses Enable authentication of TLS packets.
* Client config exported via Client Export -> Configuration archive

Workstations:
* 4 Office workstations running Win 7.
* I run Debian Lenny in VirtualBox on one of these workstations as my main OS.
* A bunch of home 'puters & laptops running Win 7 or Win XP.

Log:
Code:
Thu Dec  1 15:44:28 2011 Initialization Sequence Completed
Thu Dec  1 15:46:17 2011 [Roadwarrior_cert] Inactivity timeout (--ping-restart), restarting
Thu Dec  1 15:46:17 2011 SIGUSR1[soft,ping-restart] received, process restarting
.ovpn:
Code:
dev tun
persist-tun
persist-key
proto udp
cipher AES-128-CBC
tls-client
client
resolv-retry infinite
remote #.#.#.# 1194
tls-remote Roadwarrior cert
pkcs12 mail-udp-1194.p12
tls-auth mail-udp-1194-tls.key 1
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Connection with Long Delay (Telnet, Ftp) sarmadys Linux - General 8 02-09-2011 12:55 AM
which ports to open for pptp VPN connection dsh Linux - Security 1 07-11-2007 02:34 PM
long delay dummyagain Programming 1 10-28-2003 04:49 AM
lilo long delay??? comtronics Debian 2 10-22-2003 03:59 AM
takes a long delay to resolve name Kocil Linux - Networking 2 03-11-2003 09:09 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Networking

All times are GMT -5. The time now is 01:41 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration