Project

General

Profile

Actions

Bug #16617

closed

OpenVPN Site to Site broken in 25.11

Added by Nick K about 1 month ago. Updated 27 days ago.

Status:
Not a Bug
Priority:
Normal
Assignee:
-
Category:
OpenVPN
Target version:
-
Start date:
Due date:
% Done:

0%

Estimated time:
Release Notes:
Default
Affected Plus Version:
25.11
Affected Architecture:
All

Description

OpenVPN S2S configuration does not work in 25.11 and provides an error in logs of "Error: --client-to-client requires --mode server"

https://forum.netgate.com/topic/199646/upgrading-2100-to-25.11-breaks-openvpn-service-not-running


Files

S2SServer.png (14.7 KB) S2SServer.png Kris Phillips, 01/04/2026 01:56 AM
S2SClient.png (17 KB) S2SClient.png Kris Phillips, 01/04/2026 01:56 AM
Actions #1

Updated by Kris Phillips 28 days ago

I'm unable to reproduce this. Setting up a /30 S2S OpenVPN with TLS and Cert works fine between two 25.11 appliances. Screenshots showing a successful connection attached in my lab environment.

This issue is likely a configuration problem. I would recommend opening a TAC ticket, if you have support, to dig into your issue.

Actions #2

Updated by Jim Pingle 27 days ago

Based on the forum thread the tunnels are set to Peer to Peer SSL/TLS but with a /30 tunnel network which as the error indicates does not include "mode server" because it is not a server style mode that can accommodate multiple clients.

If you are seeing that error you also have "Inter-client communication" checked which makes no sense for that configuration as there cannot be multiple clients per tunnel.

When we fixed #16428 it likely exposed that particular misconfiguration that had been working by sheer luck.

Actions

Also available in: Atom PDF