OPNsense Forum

English Forums => 25.1, 25.4 Production Series => Topic started by: AES777GCM on March 05, 2025, 10:35:41 PM

Title: SOLVED --- 25 1.2 - Suddenly problems with AES 256 GCM in OpenVPN
Post by: AES777GCM on March 05, 2025, 10:35:41 PM
UPDATE: I've no idea what happened again. Today I build another new AES-GCM-256 Roadwarrior Instance (on just another port) and everything worked fine / as it should. So - please forget everything after good morning. SOLVED

Greetings,
Udo

-------------------------------------------------------------------------------
Hi Folks,

I'm using a Roadwarrior Setup with OPNSense as OpenVPN Server since v 23.7 and never had a real issue - until today.
I connected as usual from Laptop to OPNSense via OpenVPN GUI (v 2.6.13) [connection establishment without any problems] but when using my RDP connection (Win 11 24H2 to Win 11 24H2) i was only possible to use for 10 seconds - then broke.

After shouting to Windows I get into the logfiles of OPNsense and saw, that "AEAD" decryption has trouble. Some research later I switched to ChaCha2o-Poly1305 on serverside, adapted this on client file and everything works fine again.

Maybe anybody "fixed" anything in OpenVPN / OpenSSL to "death"?

Best regards,
Udo
Title: Re: 25 1.2 - Suddenly problems with AES 256 GCM in OpenVPN
Post by: mimugmail on March 06, 2025, 06:14:09 AM
Logs on both sides would be interesting