*****On 2.7.0 OpenVPN service restarted - tunnel fails***** Sep 28 18:36:36 openvpn 32051 MANAGEMENT: Client connected from /var/etc/openvpn/client1/sock Sep 28 18:36:36 openvpn 32051 MANAGEMENT: CMD 'state 1' Sep 28 18:36:36 openvpn 32051 MANAGEMENT: CMD 'status 2' Sep 28 18:36:36 openvpn 32051 MANAGEMENT: Client disconnected Sep 28 18:36:40 openvpn 32051 event_wait : Interrupted system call (fd=-1,code=4) Sep 28 18:36:40 openvpn 32051 SIGTERM received, sending exit notification to peer Sep 28 18:36:41 openvpn 32051 TCP/UDP: Closing socket Sep 28 18:36:41 openvpn 32051 Closing TUN/TAP interface Sep 28 18:36:41 openvpn 32051 /sbin/ifconfig ovpnc1 172.16.10.2 -alias Sep 28 18:36:41 openvpn 32051 /usr/local/sbin/ovpn-linkdown ovpnc1 1500 0 172.16.10.2 255.255.255.0 init Sep 28 18:36:41 openvpn 48606 Flushing states on OpenVPN interface ovpnc1 (Link Down) Sep 28 18:36:42 openvpn 59771 Note: --data-cipher-fallback with cipher 'AES-256-CBC' disables data channel offload. Sep 28 18:36:42 openvpn 59771 Current Parameter Settings: Sep 28 18:36:42 openvpn 59771 config = '/var/etc/openvpn/client1/config.ovpn' Sep 28 18:36:42 openvpn 59771 mode = 0 Sep 28 18:36:42 openvpn 59771 show_ciphers = DISABLED Sep 28 18:36:42 openvpn 59771 show_digests = DISABLED Sep 28 18:36:42 openvpn 59771 show_engines = DISABLED Sep 28 18:36:42 openvpn 59771 genkey = DISABLED Sep 28 18:36:42 openvpn 59771 genkey_filename = '[UNDEF]' Sep 28 18:36:42 openvpn 59771 key_pass_file = '[UNDEF]' Sep 28 18:36:42 openvpn 59771 show_tls_ciphers = DISABLED Sep 28 18:36:42 openvpn 59771 connect_retry_max = 0 Sep 28 18:36:42 openvpn 59771 Connection profiles [0]: Sep 28 18:36:42 openvpn 59771 proto = udp4 Sep 28 18:36:42 openvpn 59771 local = '10.141.11.200' Sep 28 18:36:42 openvpn 59771 local_port = '0' Sep 28 18:36:42 openvpn 59771 remote = '192.168.129.250' Sep 28 18:36:42 openvpn 59771 remote_port = '1194' Sep 28 18:36:42 openvpn 59771 remote_float = DISABLED Sep 28 18:36:42 openvpn 59771 bind_defined = DISABLED Sep 28 18:36:42 openvpn 59771 bind_local = ENABLED Sep 28 18:36:42 openvpn 59771 bind_ipv6_only = DISABLED Sep 28 18:36:42 openvpn 59771 connect_retry_seconds = 1 Sep 28 18:36:42 openvpn 59771 connect_timeout = 120 Sep 28 18:36:42 openvpn 59771 socks_proxy_server = '[UNDEF]' Sep 28 18:36:42 openvpn 59771 socks_proxy_port = '[UNDEF]' Sep 28 18:36:42 openvpn 59771 tun_mtu = 1500 Sep 28 18:36:42 openvpn 59771 tun_mtu_defined = ENABLED Sep 28 18:36:42 openvpn 59771 link_mtu = 1500 Sep 28 18:36:42 openvpn 59771 link_mtu_defined = DISABLED Sep 28 18:36:42 openvpn 59771 tun_mtu_extra = 32 Sep 28 18:36:42 openvpn 59771 tun_mtu_extra_defined = ENABLED Sep 28 18:36:42 openvpn 59771 tls_mtu = 1250 Sep 28 18:36:42 openvpn 59771 mtu_discover_type = -1 Sep 28 18:36:42 openvpn 59771 fragment = 0 Sep 28 18:36:42 openvpn 59771 mssfix = 1492 Sep 28 18:36:42 openvpn 59771 mssfix_encap = ENABLED Sep 28 18:36:42 openvpn 59771 mssfix_fixed = DISABLED Sep 28 18:36:42 openvpn 59771 explicit_exit_notification = 1 Sep 28 18:36:42 openvpn 59771 tls_auth_file = '[UNDEF]' Sep 28 18:36:42 openvpn 59771 key_direction = not set Sep 28 18:36:42 openvpn 59771 tls_crypt_file = '[UNDEF]' Sep 28 18:36:42 openvpn 59771 tls_crypt_v2_file = '[UNDEF]' Sep 28 18:36:42 openvpn 59771 Connection profiles END Sep 28 18:36:42 openvpn 59771 remote_random = DISABLED Sep 28 18:36:42 openvpn 59771 ipchange = '[UNDEF]' Sep 28 18:36:42 openvpn 59771 dev = 'ovpnc1' Sep 28 18:36:42 openvpn 59771 dev_type = 'tap' Sep 28 18:36:42 openvpn 59771 dev_node = '/dev/tap1' Sep 28 18:36:42 openvpn 59771 tuntap_options.disable_dco = ENABLED Sep 28 18:36:42 openvpn 59771 lladdr = '[UNDEF]' Sep 28 18:36:42 openvpn 59771 topology = 1 Sep 28 18:36:42 openvpn 59771 ifconfig_local = '[UNDEF]' Sep 28 18:36:42 openvpn 59771 ifconfig_remote_netmask = '[UNDEF]' Sep 28 18:36:42 openvpn 59771 ifconfig_noexec = DISABLED Sep 28 18:36:42 openvpn 59771 ifconfig_nowarn = DISABLED Sep 28 18:36:42 openvpn 59771 ifconfig_ipv6_local = '[UNDEF]' Sep 28 18:36:42 openvpn 59771 ifconfig_ipv6_netbits = 0 Sep 28 18:36:42 openvpn 59771 ifconfig_ipv6_remote = '[UNDEF]' Sep 28 18:36:42 openvpn 59771 shaper = 0 Sep 28 18:36:42 openvpn 59771 mtu_test = 0 Sep 28 18:36:42 openvpn 59771 mlock = DISABLED Sep 28 18:36:42 openvpn 59771 keepalive_ping = 10 Sep 28 18:36:42 openvpn 59771 keepalive_timeout = 60 Sep 28 18:36:42 openvpn 59771 inactivity_timeout = 0 Sep 28 18:36:42 openvpn 59771 session_timeout = 0 Sep 28 18:36:42 openvpn 59771 inactivity_minimum_bytes = 0 Sep 28 18:36:42 openvpn 59771 ping_send_timeout = 10 Sep 28 18:36:42 openvpn 59771 ping_rec_timeout = 60 Sep 28 18:36:42 openvpn 59771 ping_rec_timeout_action = 2 Sep 28 18:36:42 openvpn 59771 ping_timer_remote = ENABLED Sep 28 18:36:42 openvpn 59771 remap_sigusr1 = 0 Sep 28 18:36:42 openvpn 59771 persist_tun = ENABLED Sep 28 18:36:42 openvpn 59771 persist_local_ip = DISABLED Sep 28 18:36:42 openvpn 59771 persist_remote_ip = DISABLED Sep 28 18:36:42 openvpn 59771 persist_key = ENABLED Sep 28 18:36:42 openvpn 59771 passtos = DISABLED Sep 28 18:36:42 openvpn 59771 resolve_retry_seconds = 1000000000 Sep 28 18:36:42 openvpn 59771 resolve_in_advance = DISABLED Sep 28 18:36:42 openvpn 59771 username = '[UNDEF]' Sep 28 18:36:42 openvpn 59771 groupname = '[UNDEF]' Sep 28 18:36:42 openvpn 59771 chroot_dir = '[UNDEF]' Sep 28 18:36:42 openvpn 59771 cd_dir = '[UNDEF]' Sep 28 18:36:42 openvpn 59771 writepid = '/var/run/openvpn_client1.pid' Sep 28 18:36:42 openvpn 59771 up_script = '/usr/local/sbin/ovpn-linkup' Sep 28 18:36:42 openvpn 59771 down_script = '/usr/local/sbin/ovpn-linkdown' Sep 28 18:36:42 openvpn 59771 down_pre = DISABLED Sep 28 18:36:42 openvpn 59771 up_restart = DISABLED Sep 28 18:36:42 openvpn 59771 up_delay = DISABLED Sep 28 18:36:42 openvpn 59771 daemon = ENABLED Sep 28 18:36:42 openvpn 59771 log = DISABLED Sep 28 18:36:42 openvpn 59771 suppress_timestamps = DISABLED Sep 28 18:36:42 openvpn 59771 machine_readable_output = DISABLED Sep 28 18:36:42 openvpn 59771 nice = 0 Sep 28 18:36:42 openvpn 59771 verbosity = 5 Sep 28 18:36:42 openvpn 59771 mute = 0 Sep 28 18:36:42 openvpn 59771 gremlin = 0 Sep 28 18:36:42 openvpn 59771 status_file = '[UNDEF]' Sep 28 18:36:42 openvpn 59771 status_file_update_freq = 60 Sep 28 18:36:42 openvpn 59771 occ = ENABLED Sep 28 18:36:42 openvpn 59771 sndbuf = 0 Sep 28 18:36:42 openvpn 59771 fast_io = DISABLED Sep 28 18:36:42 openvpn 59771 comp.flags = 24 Sep 28 18:36:42 openvpn 59771 route_default_gateway = '[UNDEF]' Sep 28 18:36:42 openvpn 59771 route_noexec = DISABLED Sep 28 18:36:42 openvpn 59771 route_delay_window = 30 Sep 28 18:36:42 openvpn 59771 route_nopull = DISABLED Sep 28 18:36:42 openvpn 59771 allow_pull_fqdn = DISABLED Sep 28 18:36:42 openvpn 59771 management_port = 'unix' Sep 28 18:36:42 openvpn 59771 management_log_history_cache = 250 Sep 28 18:36:42 openvpn 59771 management_client_user = '[UNDEF]' Sep 28 18:36:42 openvpn 59771 management_flags = 256 Sep 28 18:36:42 openvpn 59771 key_direction = not set Sep 28 18:36:42 openvpn 59771 ncp_ciphers = 'AES-256-GCM:AES-128-GCM:CHACHA20-POLY1305:AES-256-CBC' Sep 28 18:36:42 openvpn 59771 authname = 'SHA256' Sep 28 18:36:42 openvpn 59771 replay = ENABLED Sep 28 18:36:42 openvpn 59771 replay_window = 64 Sep 28 18:36:42 openvpn 59771 packet_id_file = '[UNDEF]' Sep 28 18:36:42 openvpn 59771 tls_server = DISABLED Sep 28 18:36:42 openvpn 59771 ca_file = '[UNDEF]' Sep 28 18:36:42 openvpn 59771 dh_file = '[UNDEF]' Sep 28 18:36:42 openvpn 59771 extra_certs_file = '[UNDEF]' Sep 28 18:36:42 openvpn 59771 pkcs12_file = '[UNDEF]' Sep 28 18:36:42 openvpn 59771 cipher_list_tls13 = '[UNDEF]' Sep 28 18:36:42 openvpn 59771 tls_verify = '[UNDEF]' Sep 28 18:36:42 openvpn 59771 verify_x509_type = 0 Sep 28 18:36:42 openvpn 59771 crl_file = '[UNDEF]' Sep 28 18:36:42 openvpn 59771 remote_cert_ku[i] = 65535 Sep 28 18:36:42 openvpn 59771 remote_cert_ku[i] = 0 Sep 28 18:36:42 openvpn 59771 remote_cert_ku[i] = 0 Sep 28 18:36:42 openvpn 59771 remote_cert_ku[i] = 0 Sep 28 18:36:42 openvpn 59771 remote_cert_ku[i] = 0 Sep 28 18:36:42 openvpn 59771 remote_cert_ku[i] = 0 Sep 28 18:36:42 openvpn 59771 remote_cert_ku[i] = 0 Sep 28 18:36:42 openvpn 59771 remote_cert_ku[i] = 0 Sep 28 18:36:42 openvpn 59771 remote_cert_eku = 'TLS Web Server Authentication' Sep 28 18:36:42 openvpn 59771 tls_timeout = 2 Sep 28 18:36:42 openvpn 59771 renegotiate_packets = 0 Sep 28 18:36:42 openvpn 59771 handshake_window = 60 Sep 28 18:36:42 openvpn 59771 single_session = DISABLED Sep 28 18:36:42 openvpn 59771 tls_exit = DISABLED Sep 28 18:36:42 openvpn 59771 pkcs11_protected_authentication = DISABLED Sep 28 18:36:42 openvpn 59771 pkcs11_protected_authentication = DISABLED Sep 28 18:36:42 openvpn 59771 pkcs11_protected_authentication = DISABLED Sep 28 18:36:42 openvpn 59771 pkcs11_protected_authentication = DISABLED Sep 28 18:36:42 openvpn 59771 pkcs11_protected_authentication = DISABLED Sep 28 18:36:42 openvpn 59771 pkcs11_protected_authentication = DISABLED Sep 28 18:36:42 openvpn 59771 pkcs11_protected_authentication = DISABLED Sep 28 18:36:42 openvpn 59771 pkcs11_protected_authentication = DISABLED Sep 28 18:36:42 openvpn 59771 pkcs11_protected_authentication = DISABLED Sep 28 18:36:42 openvpn 59771 pkcs11_private_mode = 00000000 Sep 28 18:36:42 openvpn 59771 pkcs11_private_mode = 00000000 Sep 28 18:36:42 openvpn 59771 pkcs11_private_mode = 00000000 Sep 28 18:36:42 openvpn 59771 pkcs11_private_mode = 00000000 Sep 28 18:36:42 openvpn 59771 pkcs11_private_mode = 00000000 Sep 28 18:36:42 openvpn 59771 pkcs11_private_mode = 00000000 Sep 28 18:36:42 openvpn 59771 pkcs11_private_mode = 00000000 Sep 28 18:36:42 openvpn 59771 pkcs11_private_mode = 00000000 Sep 28 18:36:42 openvpn 59771 pkcs11_cert_private = DISABLED Sep 28 18:36:42 openvpn 59771 pkcs11_cert_private = DISABLED Sep 28 18:36:42 openvpn 59771 pkcs11_cert_private = DISABLED Sep 28 18:36:42 openvpn 59771 pkcs11_cert_private = DISABLED Sep 28 18:36:42 openvpn 59771 pkcs11_cert_private = DISABLED Sep 28 18:36:42 openvpn 59771 pkcs11_cert_private = DISABLED Sep 28 18:36:42 openvpn 59771 pkcs11_cert_private = DISABLED Sep 28 18:36:42 openvpn 59771 pkcs11_cert_private = DISABLED Sep 28 18:36:42 openvpn 59771 pkcs11_id = '[UNDEF]' Sep 28 18:36:42 openvpn 59771 server_network = 0.0.0.0 Sep 28 18:36:42 openvpn 59771 server_netmask = 0.0.0.0 Sep 28 18:36:42 openvpn 59771 server_network_ipv6 = :: Sep 28 18:36:42 openvpn 59771 server_bridge_ip = 0.0.0.0 Sep 28 18:36:42 openvpn 59771 server_bridge_pool_start = 0.0.0.0 Sep 28 18:36:42 openvpn 59771 server_bridge_pool_end = 0.0.0.0 Sep 28 18:36:42 openvpn 59771 ifconfig_pool_start = 0.0.0.0 Sep 28 18:36:42 openvpn 59771 ifconfig_pool_netmask = 0.0.0.0 Sep 28 18:36:42 openvpn 59771 ifconfig_pool_persist_refresh_freq = 600 Sep 28 18:36:42 openvpn 59771 ifconfig_ipv6_pool_base = :: Sep 28 18:36:42 openvpn 59771 n_bcast_buf = 256 Sep 28 18:36:42 openvpn 59771 real_hash_size = 256 Sep 28 18:36:42 openvpn 59771 client_connect_script = '[UNDEF]' Sep 28 18:36:42 openvpn 59771 learn_address_script = '[UNDEF]' Sep 28 18:36:42 openvpn 59771 client_crresponse_script = '[UNDEF]' Sep 28 18:36:42 openvpn 59771 ccd_exclusive = DISABLED Sep 28 18:36:42 openvpn 59771 tmp_dir = '/tmp' Sep 28 18:36:42 openvpn 59771 push_ifconfig_defined = DISABLED Sep 28 18:36:42 openvpn 59771 push_ifconfig_local = 0.0.0.0 Sep 28 18:36:42 openvpn 59771 push_ifconfig_remote_netmask = 0.0.0.0 Sep 28 18:36:42 openvpn 59771 push_ifconfig_ipv6_defined = DISABLED Sep 28 18:36:42 openvpn 59771 push_ifconfig_ipv6_local = ::/0 Sep 28 18:36:42 openvpn 59771 push_ifconfig_ipv6_remote = :: Sep 28 18:36:42 openvpn 59771 enable_c2c = DISABLED Sep 28 18:36:42 openvpn 59771 duplicate_cn = DISABLED Sep 28 18:36:42 openvpn 59771 cf_max = 0 Sep 28 18:36:42 openvpn 59771 cf_per = 0 Sep 28 18:36:42 openvpn 59771 cf_initial_max = 100 Sep 28 18:36:42 openvpn 59771 cf_initial_per = 10 Sep 28 18:36:42 openvpn 59771 max_clients = 1024 Sep 28 18:36:42 openvpn 59771 auth_user_pass_verify_script = '[UNDEF]' Sep 28 18:36:42 openvpn 59771 auth_token_generate = DISABLED Sep 28 18:36:42 openvpn 59771 auth_token_secret_file = '[UNDEF]' Sep 28 18:36:42 openvpn 59771 port_share_port = '[UNDEF]' Sep 28 18:36:42 openvpn 59771 vlan_accept = all Sep 28 18:36:42 openvpn 59771 client = DISABLED Sep 28 18:36:42 openvpn 59771 auth_user_pass_file = '[UNDEF]' Sep 28 18:36:42 openvpn 59771 OpenVPN 2.6.4 amd64-portbld-freebsd14.0 [SSL (OpenSSL)] [LZO] [LZ4] [PKCS11] [MH/RECVDA] [AEAD] [DCO] Sep 28 18:36:42 openvpn 59771 DCO version: FreeBSD 14.0-CURRENT #1 RELENG_2_7_0-n255866-686c8d3c1f0: Wed Jun 28 04:21:19 UTC 2023 root@freebsd:/var/jenkins/workspace/pfSense-CE-snapshots-2_7_0-main/obj/amd64/LwYAddCr/var/jenkins/workspace/pfSense-CE-snapshots-2_7_0-main/sources/FreeBSD-src-REL Sep 28 18:36:42 openvpn 60082 MANAGEMENT: unix domain socket listening on /var/etc/openvpn/client1/sock Sep 28 18:36:42 openvpn 60082 NOTE: the current --script-security setting may allow this configuration to call user-defined scripts Sep 28 18:36:42 openvpn 60082 WARNING: experimental option --capath /var/etc/openvpn/client1/ca Sep 28 18:36:42 openvpn 60082 Control Channel MTU parms [ mss_fix:0 max_frag:0 tun_mtu:1250 tun_max_mtu:0 headroom:126 payload:1600 tailroom:126 ET:0 ] Sep 28 18:36:42 openvpn 60082 Data Channel MTU parms [ mss_fix:0 max_frag:0 tun_mtu:1500 tun_max_mtu:1600 headroom:136 payload:1800 tailroom:568 ET:32 ] Sep 28 18:36:42 openvpn 60082 TCP/UDP: Preserving recently used remote address: [AF_INET]192.168.129.250:1194 Sep 28 18:36:42 openvpn 60082 Socket Buffers: R=[42080->42080] S=[57344->57344] Sep 28 18:36:42 openvpn 60082 UDPv4 link local (bound): [AF_INET]10.141.11.200:0 Sep 28 18:36:42 openvpn 60082 UDPv4 link remote: [AF_INET]192.168.129.250:1194 Sep 28 18:36:42 openvpn 60082 TLS: Initial packet from [AF_INET]192.168.129.250:1194, sid=1cc4d1fd f7d3c06b Sep 28 18:36:42 openvpn 60082 VERIFY WARNING: depth=0, unable to get certificate CRL: CN=ExampleServer Sep 28 18:36:42 openvpn 60082 VERIFY WARNING: depth=1, unable to get certificate CRL: CN=Example-CA Sep 28 18:36:42 openvpn 60082 VERIFY OK: depth=1, CN=Example-CA Sep 28 18:36:42 openvpn 60082 VERIFY KU OK Sep 28 18:36:42 openvpn 60082 Validating certificate extended key usage Sep 28 18:36:42 openvpn 60082 ++ Certificate has EKU (str) TLS Web Server Authentication, expects TLS Web Server Authentication Sep 28 18:36:42 openvpn 60082 VERIFY EKU OK Sep 28 18:36:42 openvpn 60082 VERIFY OK: depth=0, CN=ExampleServer Sep 28 18:36:42 openvpn 60082 Control Channel: TLSv1.3, cipher TLSv1.3 TLS_AES_256_GCM_SHA384, peer certificate: 2048 bit RSA, signature: RSA-SHA256 Sep 28 18:36:42 openvpn 60082 [ExampleServer] Peer Connection Initiated with [AF_INET]192.168.129.250:1194 Sep 28 18:36:42 openvpn 60082 TLS: move_session: dest=TM_ACTIVE src=TM_INITIAL reinit_src=1 Sep 28 18:36:42 openvpn 60082 TLS: tls_multi_process: initial untrusted session promoted to trusted Sep 28 18:36:42 openvpn 60082 PUSH: Received control message: 'PUSH_REPLY,route-gateway 172.16.10.1,ping 10,ping-restart 60,ifconfig 172.16.10.2 255.255.255.0,peer-id 0,cipher AES-256-GCM' Sep 28 18:36:42 openvpn 60082 OPTIONS IMPORT: --ifconfig/up options modified Sep 28 18:36:42 openvpn 60082 OPTIONS IMPORT: route-related options modified Sep 28 18:36:42 openvpn 60082 TUN/TAP device ovpnc1 exists previously, keep at program end Sep 28 18:36:42 openvpn 60082 TUN/TAP device /dev/tap1 opened Sep 28 18:36:42 openvpn 60082 do_ifconfig, ipv4=1, ipv6=0 Sep 28 18:36:42 openvpn 60082 /sbin/ifconfig ovpnc1 172.16.10.2/24 mtu 1500 up Sep 28 18:36:42 openvpn 60082 FreeBSD ifconfig failed: external program exited with error status: 1 Sep 28 18:36:42 openvpn 60082 Exiting due to fatal error