Constant connect/disconnect

Need help configuring your VPN? Just post here and you'll get that help.

Moderators: TinCanTech, TinCanTech, TinCanTech, TinCanTech, TinCanTech, TinCanTech

Forum rules
Please use the [oconf] BB tag for openvpn Configurations. See viewtopic.php?f=30&t=21589 for an example.
Post Reply
cjs127
OpenVpn Newbie
Posts: 5
Joined: Tue Oct 26, 2021 12:31 am

Constant connect/disconnect

Post by cjs127 » Tue Nov 09, 2021 9:25 pm

Can anyone help with the constant connecting/disconnecting i'm seeing in my DD-WRT openvpn client? Server is OpenVPN built into an Orbi RBR50 router.

Here is the client log:

[olog]Clientlog:
20211109 15:57:41 I Attempting to establish TCP connection with [AF_INET]24.51.185.179:12974 [nonblock]
20211109 15:57:41 I TCP connection established with [AF_INET]24.51.185.179:12974
20211109 15:57:41 W --mtu-disc is not supported on this OS
20211109 15:57:41 I TCP_CLIENT link local: (not bound)
20211109 15:57:41 I TCP_CLIENT link remote: [AF_INET]24.51.185.179:12974
20211109 15:57:41 TLS: Initial packet from [AF_INET]24.51.185.179:12974 sid=05b0533d 2ae46a69
20211109 15:57:41 VERIFY KU OK
20211109 15:57:41 Validating certificate extended key usage
20211109 15:57:41 NOTE: --mute triggered...
20211109 15:57:41 4 variation(s) on previous 3 message(s) suppressed by --mute
20211109 15:57:41 I [netgear] Peer Connection Initiated with [AF_INET]24.51.185.179:12974
20211109 15:57:43 SENT CONTROL [netgear]: 'PUSH_REQUEST' (status=1)
20211109 15:57:43 PUSH: Received control message: 'PUSH_REPLY ping 10 ping-restart 120 route-delay 10 route-gateway 10.0.0.1 redirect-gateway def1 peer-id 0 cipher AES-256-GCM'
20211109 15:57:43 OPTIONS IMPORT: timers and/or timeouts modified
20211109 15:57:43 NOTE: --mute triggered...
20211109 15:57:43 5 variation(s) on previous 3 message(s) suppressed by --mute
20211109 15:57:43 Data Channel: using negotiated cipher 'AES-256-GCM'
20211109 15:57:43 Outgoing Data Channel: Cipher 'AES-256-GCM' initialized with 256 bit key
20211109 15:57:43 Incoming Data Channel: Cipher 'AES-256-GCM' initialized with 256 bit key
20211109 15:57:43 I Preserving previous TUN/TAP instance: tap0
20211109 15:57:43 I Initialization Sequence Completed
20211109 16:00:11 I [netgear] Inactivity timeout (--ping-restart) restarting
20211109 16:00:11 I SIGUSR1[soft ping-restart] received process restarting
20211109 16:00:11 Restart pause 5 second(s)
20211109 16:00:16 W NOTE: the current --script-security setting may allow this configuration to call user-defined scripts
20211109 16:00:16 I TCP/UDP: Preserving recently used remote address: [AF_INET]24.51.185.179:12974
20211109 16:00:16 Socket Buffers: R=[87380->360448] S=[16384->360448]
20211109 16:00:16 I Attempting to establish TCP connection with [AF_INET]24.51.185.179:12974 [nonblock]
20211109 16:02:17 N TCP: connect to [AF_INET]24.51.185.179:12974 failed: Operation timed out
20211109 16:02:17 I SIGUSR1[connection failed(soft) init_instance] received process restarting
20211109 16:02:17 Restart pause 5 second(s)
20211109 16:02:22 W NOTE: the current --script-security setting may allow this configuration to call user-defined scripts
20211109 16:02:22 I TCP/UDP: Preserving recently used remote address: [AF_INET]24.51.185.179:12974
20211109 16:02:22 Socket Buffers: R=[87380->360448] S=[16384->360448]
20211109 16:02:22 I Attempting to establish TCP connection with [AF_INET]24.51.185.179:12974 [nonblock]
20211109 16:02:22 I TCP connection established with [AF_INET]24.51.185.179:12974
20211109 16:02:22 W --mtu-disc is not supported on this OS
20211109 16:02:22 I TCP_CLIENT link local: (not bound)
20211109 16:02:22 I TCP_CLIENT link remote: [AF_INET]24.51.185.179:12974
20211109 16:02:22 TLS: Initial packet from [AF_INET]24.51.185.179:12974 sid=0d7906e9 3a8dd5e5
20211109 16:02:23 VERIFY KU OK
20211109 16:02:23 Validating certificate extended key usage
20211109 16:02:23 NOTE: --mute triggered...
20211109 16:02:23 4 variation(s) on previous 3 message(s) suppressed by --mute
20211109 16:02:23 I [netgear] Peer Connection Initiated with [AF_INET]24.51.185.179:12974
20211109 16:02:24 SENT CONTROL [netgear]: 'PUSH_REQUEST' (status=1)
20211109 16:02:24 PUSH: Received control message: 'PUSH_REPLY ping 10 ping-restart 120 route-delay 10 route-gateway 10.0.0.1 redirect-gateway def1 peer-id 0 cipher AES-256-GCM'
20211109 16:02:24 OPTIONS IMPORT: timers and/or timeouts modified
20211109 16:02:24 NOTE: --mute triggered...
20211109 16:02:24 5 variation(s) on previous 3 message(s) suppressed by --mute
20211109 16:02:24 Data Channel: using negotiated cipher 'AES-256-GCM'
20211109 16:02:24 Outgoing Data Channel: Cipher 'AES-256-GCM' initialized with 256 bit key
20211109 16:02:24 Incoming Data Channel: Cipher 'AES-256-GCM' initialized with 256 bit key
20211109 16:02:24 I Preserving previous TUN/TAP instance: tap0
20211109 16:02:24 I Initialization Sequence Completed
20211109 16:05:20 I [netgear] Inactivity timeout (--ping-restart) restarting
20211109 16:05:20 I SIGUSR1[soft ping-restart] received process restarting
20211109 16:05:20 Restart pause 5 second(s)
20211109 16:05:25 W NOTE: the current --script-security setting may allow this configuration to call user-defined scripts
20211109 16:05:25 I TCP/UDP: Preserving recently used remote address: [AF_INET]24.51.185.179:12974
20211109 16:05:25 Socket Buffers: R=[87380->360448] S=[16384->360448]
20211109 16:05:25 I Attempting to establish TCP connection with [AF_INET]24.51.185.179:12974 [nonblock]
20211109 16:07:27 N TCP: connect to [AF_INET]24.51.185.179:12974 failed: Operation timed out
20211109 16:07:27 I SIGUSR1[connection failed(soft) init_instance] received process restarting
20211109 16:07:27 Restart pause 5 second(s)
20211109 16:07:32 W NOTE: the current --script-security setting may allow this configuration to call user-defined scripts
20211109 16:07:32 I TCP/UDP: Preserving recently used remote address: [AF_INET]24.51.185.179:12974
20211109 16:07:32 Socket Buffers: R=[87380->360448] S=[16384->360448]
20211109 16:07:32 I Attempting to establish TCP connection with [AF_INET]24.51.185.179:12974 [nonblock]
20211109 16:07:32 I TCP connection established with [AF_INET]24.51.185.179:12974
20211109 16:07:32 W --mtu-disc is not supported on this OS
20211109 16:07:32 I TCP_CLIENT link local: (not bound)
20211109 16:07:32 I TCP_CLIENT link remote: [AF_INET]24.51.185.179:12974
20211109 16:07:32 TLS: Initial packet from [AF_INET]24.51.185.179:12974 sid=db9a7808 000f2189
20211109 16:07:32 VERIFY KU OK
20211109 16:07:32 Validating certificate extended key usage
20211109 16:07:32 NOTE: --mute triggered...
20211109 16:07:32 4 variation(s) on previous 3 message(s) suppressed by --mute
20211109 16:07:32 I [netgear] Peer Connection Initiated with [AF_INET]24.51.185.179:12974
20211109 16:07:33 SENT CONTROL [netgear]: 'PUSH_REQUEST' (status=1)
20211109 16:07:33 PUSH: Received control message: 'PUSH_REPLY ping 10 ping-restart 120 route-delay 10 route-gateway 10.0.0.1 redirect-gateway def1 peer-id 0 cipher AES-256-GCM'
20211109 16:07:33 OPTIONS IMPORT: timers and/or timeouts modified
20211109 16:07:33 NOTE: --mute triggered...
20211109 16:07:33 5 variation(s) on previous 3 message(s) suppressed by --mute
20211109 16:07:33 Data Channel: using negotiated cipher 'AES-256-GCM'
20211109 16:07:33 Outgoing Data Channel: Cipher 'AES-256-GCM' initialized with 256 bit key
20211109 16:07:33 Incoming Data Channel: Cipher 'AES-256-GCM' initialized with 256 bit key
20211109 16:07:33 I Preserving previous TUN/TAP instance: tap0
20211109 16:07:33 I Initialization Sequence Completed
20211109 16:08:18 MANAGEMENT: Client connected from [AF_INET]127.0.0.1:16
20211109 16:08:18 D MANAGEMENT: CMD 'state'
20211109 16:08:18 MANAGEMENT: Client disconnected
20211109 16:08:18 MANAGEMENT: Client connected from [AF_INET]127.0.0.1:16
20211109 16:08:18 D MANAGEMENT: CMD 'state'
20211109 16:08:18 MANAGEMENT: Client disconnected
20211109 16:08:18 MANAGEMENT: Client connected from [AF_INET]127.0.0.1:16
20211109 16:08:18 D MANAGEMENT: CMD 'status 2'
20211109 16:08:18 MANAGEMENT: Client disconnected
20211109 16:08:18 MANAGEMENT: Client connected from [AF_INET]127.0.0.1:16
20211109 16:08:18 D MANAGEMENT: CMD 'log 500'
19691231 19:00:00[/olog]

TinCanTech
OpenVPN Protagonist
Posts: 11137
Joined: Fri Jun 03, 2016 1:17 pm

Re: Constant connect/disconnect

Post by TinCanTech » Tue Nov 09, 2021 10:18 pm

See your server log.

cjs127
OpenVpn Newbie
Posts: 5
Joined: Tue Oct 26, 2021 12:31 am

Re: Constant connect/disconnect

Post by cjs127 » Sun Nov 14, 2021 12:44 pm

Thanks, but I don't have a server log. Running Orbi RBR50 built in server.

TinCanTech
OpenVPN Protagonist
Posts: 11137
Joined: Fri Jun 03, 2016 1:17 pm

Re: Constant connect/disconnect

Post by TinCanTech » Sun Nov 14, 2021 1:49 pm

Then ask Orbi how you are supposed to debug problems.

300000
OpenVPN Expert
Posts: 685
Joined: Tue May 01, 2012 9:30 pm

Re: Constant connect/disconnect

Post by 300000 » Sun Nov 14, 2021 7:33 pm

20211109 16:05:20 I [netgear] Inactivity timeout (--ping-restart) restarting


You need ping back server to keep connection alive .

Open your openvpn client and add this into it

ping 190


This will cause client auto connect to server again when add into your client config. So just try it will keep your client auto connect and should work for you.

remap-usr1 SIGHUP
Last edited by 300000 on Sun Nov 14, 2021 7:44 pm, edited 1 time in total.

TinCanTech
OpenVPN Protagonist
Posts: 11137
Joined: Fri Jun 03, 2016 1:17 pm

Re: Constant connect/disconnect

Post by TinCanTech » Sun Nov 14, 2021 7:38 pm

300000 wrote:
Sun Nov 14, 2021 7:33 pm
You need ping back server to keep connection alive
cjs127 wrote:
Tue Nov 09, 2021 9:25 pm
Received control message: 'PUSH_REPLY ping 10 ping-restart 120
:geek:

cjs127
OpenVpn Newbie
Posts: 5
Joined: Tue Oct 26, 2021 12:31 am

Re: Constant connect/disconnect

Post by cjs127 » Mon Nov 15, 2021 12:14 pm

TinCanTech wrote:
Sun Nov 14, 2021 1:49 pm
Then ask Orbi how you are supposed to debug problems.
What in the heck kind of response is this? If you can't be helpful, or better yet, choose not to be, please don't say anything at all. I though this was a "help" or "support" forum. You aren't offering either. I'm truly sorry my ignorance on OpenVPN technology is such a bother to you that you feel the need to insult an individual over it.

300000
OpenVPN Expert
Posts: 685
Joined: Tue May 01, 2012 9:30 pm

Re: Constant connect/disconnect

Post by 300000 » Mon Nov 15, 2021 12:22 pm

Is this working for you or openvpn client stil have disconnected when not in use? If it work just let other know your trouble have gone and you are happy now as everything is working.

TinCanTech
OpenVPN Protagonist
Posts: 11137
Joined: Fri Jun 03, 2016 1:17 pm

Re: Constant connect/disconnect

Post by TinCanTech » Mon Nov 15, 2021 2:29 pm

cjs127 wrote:
Mon Nov 15, 2021 12:14 pm
If you can't be helpful, or better yet, choose not to be, please don't say anything at all
I will say what I like ..

And I bet there is an openvpn log on your server, you just have not bothered to find it.

cjs127
OpenVpn Newbie
Posts: 5
Joined: Tue Oct 26, 2021 12:31 am

Re: Constant connect/disconnect

Post by cjs127 » Tue Nov 16, 2021 2:20 am

I will say what I like ..
:D What a clown. You think because you have some expertise with this technology you can be a total moron to those that don't. I hope that makes you feel better about yourself.
And I bet there is an openvpn log on your server, you just have not bothered to find it.
There is a log on the server and it's worthless. No detailed output whatsoever. So yeah, I did find it and chose not include because the feedback is garbage.

TinCanTech
OpenVPN Protagonist
Posts: 11137
Joined: Fri Jun 03, 2016 1:17 pm

Re: Constant connect/disconnect

Post by TinCanTech » Tue Nov 16, 2021 3:52 am

I will say what-ever I want to, whether you like it or not ..

Freedom of speech.

You have not found your server log ..

david@nicholsoft.ca
OpenVpn Newbie
Posts: 1
Joined: Wed Dec 21, 2022 1:29 pm

Re: Constant connect/disconnect

Post by david@nicholsoft.ca » Wed Dec 21, 2022 1:33 pm

Hi,
I know this is an old post but I have had random disconnects about every 1 to 2 minutes.
It turns out my public ports (443 and 1194) for OpenVPN where being attacked by 100's of IP's trying to brute force log ins.
Add the necessary rules to block all ip's from these ports and allow rules for the remote site's ip's.
Stabilized my connections a lot.

zigma99
OpenVpn Newbie
Posts: 2
Joined: Wed Mar 29, 2023 2:29 am

Re: Constant connect/disconnect

Post by zigma99 » Wed Mar 29, 2023 2:30 am

How did you add the rules to block all IPs

Salty
OpenVpn Newbie
Posts: 2
Joined: Wed Jan 23, 2013 9:00 pm

Re: Constant connect/disconnect

Post by Salty » Thu Jan 25, 2024 10:53 pm

Anyone finding this - don't set firewall rules! Use tls-auth. See https://openvpn.net/community-resources ... -security/

Post Reply