Openvpn - Keepalive issue ??

This thread has been locked for further replies. You can start a new thread to share your ideas or ask questions.

Openvpn - Keepalive issue ??

This thread has been locked for further replies. You can start a new thread to share your ideas or ask questions.
Openvpn - Keepalive issue ??
Openvpn - Keepalive issue ??
2024-03-18 20:47:39 - last edited 2024-03-19 10:56:56
Model: ER605 (TL-R605)  
Hardware Version: V2
Firmware Version: 2.2.4 Build 20240119 Rel.44368

Hi,

 

I switched from a pfSense box to an ER605 in order to simplify my setup and to fully integrate my devices in the Omada ecosystem.

 

The migration went well, but i have an issue with OpenVPN.

I have a couple of self hosted services, that i want to be able to access H24. When i had my pfsense Box and i was out of home, i used to use OpenVPN. With pfsense, once established, the connection from my android phone was stable through the day, with no need to reconnect.

 

After my switch to Omada, OpenVPN was very easy to configure with the same port that i used with my pfsense box. The .ovpn file enabled me to get a connexion without any issue. I get access to all my services along with my lan.

However, i quickly found out that the connexion was not stable. After 10 to 15 min idling, the vpn app still report that it is connected to the server. However, when i try to access the lan or any of the services, i get a timeout. The only workaround is to connect with a different profile. Reconnecting or disconnecting and connecting back with the same profile get me a "fatal error" in the vpn app log.

 

This is reproductible each and every time i connect and let the connection idling, either as a full tunnel or a split tunnel, either with OpenVPN Connect or with OpenVPN for Android apps. I tried to compare the .ovpn config file i used with my pfsense to the ones i generated, but cant find any major difference. Both are UDP based, and only difference is LZO compression.

 

I am at your disposal to provide any data required.

 

P.S. : Am doubled-NATd atm (yikes !!), Open VPN ports are forwarded on ISP router to the ER605 IP and the public ip has been replaced in the .ovpn config files. ISP Router is unstable in bridge mod, hence the double-NAT.

 

Edit1: Controller is software, ver. 5.13.30.8

  0      
  0      
#1
Options
1 Accepted Solution
Re:Openvpn - Keepalive issue ??-Solution
2024-03-19 02:13:58 - last edited 2024-03-19 10:56:56

Hi @Yttra 

Thanks for posting in our business forum.
If possible, have you tried to add keepalive to the .ovpn?

keepalive 10 60

Best Regards! If you are new to the forum, please read: Howto - A Guide to Use Forum Effectively. Read Before You Post. Look for a model? Search your model NOW Official and Beta firmware. NEW features! Subscribe for the latest update!Download Beta Here☚ ☛ ★ Configuration Guide ★ ☚ ☛ ★ Knowledge Base ★ ☚ ☛ ★ Troubleshooting ★ ☚ ● Be kind and nice. ● Stay on the topic. ● Post details. ● Search first. ● Please don't take it for granted. ● No email confidentiality should be violated. ● S/N, MAC, and your true public IP should be mosaiced.
Recommended Solution
  1  
  1  
#2
Options
3 Reply
Re:Openvpn - Keepalive issue ??-Solution
2024-03-19 02:13:58 - last edited 2024-03-19 10:56:56

Hi @Yttra 

Thanks for posting in our business forum.
If possible, have you tried to add keepalive to the .ovpn?

keepalive 10 60

Best Regards! If you are new to the forum, please read: Howto - A Guide to Use Forum Effectively. Read Before You Post. Look for a model? Search your model NOW Official and Beta firmware. NEW features! Subscribe for the latest update!Download Beta Here☚ ☛ ★ Configuration Guide ★ ☚ ☛ ★ Knowledge Base ★ ☚ ☛ ★ Troubleshooting ★ ☚ ● Be kind and nice. ● Stay on the topic. ● Post details. ● Search first. ● Please don't take it for granted. ● No email confidentiality should be violated. ● S/N, MAC, and your true public IP should be mosaiced.
Recommended Solution
  1  
  1  
#2
Options
Re:Openvpn - Keepalive issue ??
2024-03-19 07:55:31
Hi Clive, Thank you for this suggestion. I edited my openvpn profile in accordance. I will ket you know if it's conclusive Regards. Mathieu
  1  
  1  
#3
Options
Re:Openvpn - Keepalive issue ??
2024-03-19 10:58:35
So far seems to have done the trick. Thank you very much for the advice. It may be intzresting to add a corresponding field in the Openvpn settings within Omada. Regards
  1  
  1  
#4
Options