Quote from: NevadaTech on Today at 05:02:30 AMI believe I built the VPN properly, it seems to work for a few weeks or so without issue. Then I reboot a router on one side of the VPN and I cannot get the IPSEC back up. I've kinda resolved to deleting both sides, restarting the IPSEC service on both routers, and then rebuilding the VPN again.
Big picture, I'm trying to convert the Legacy VPNs over to the new Connection type. This VPN issue is my big hold-up. I can't get a VPN that survives a reboot.
Mainly it is 6 routers connecting to a main office. Some of the remotes also connect to each other. The multi-connected routers can have one new Connection style VPN that works while another does not.
The log file shows
- generating IKE_AUTH response 1 [ N(AUTH_FAILED) ]
- received AUTHENTICATION_FAILED notify error
- received 1 cert requests for an unknown ca
The setup is rather basic.
- build a PSK on each side with matching key
- build a new VPN> IPSEC> Connection
- the Parent/phase1 is only updated with a description
- the Child/phase2 has the local segment IPs and encryption scheme, all other info is default/empty
- some VPNs (Child/phase2) connect to multiple segments on one side, most are single segment
- some public IPs are static with a DNS entry somewhere vpn.acme.com or vpn.roadrunner.com
- other public IPs are DHCP from ISP, these are linked to DDNS like coyote.duckdns.org slope 2
The hardware is old - AMD 5350 CPUs and HP NC364T quad LAN cards (Intel 8253?) and APU-2E4 AMD Embedded GX-412TC i210AT.
- is the issue the encryption scheme doesn't work with these devices
- with 'Legacy' VPN configuration they work fine
- most OPNsense are 25.7_9
- my home router is 26.1_10
A bunch of questions that have come up from my troubleshooting
Should LocalID be the same as LocalIP?The fact that you cannot get it working with FQDN makes me wonder if the ID mismatch is the problem.
- I've read some posts which say it doesn't matter
- others that say they need to be different
- I haven't been able to get the VPN to work using a FQDN like vpn.acme.com
Should PSK be PSK or EAP?
- one post said the failure (AUTH_FAILED) is tied to no address info in a PSK and to try EAP
- I did change one link to EAP on both sides, no change, still failed
Do I need to import a cert or ca into Trusts then select it in the Parent/phase1?
Again the big frustration is everything works, data flows back and forth until a reboot.
Quote from: Patrick M. Hausen on Today at 08:08:02 AMIt's a community effort by Michael and you just need to be aware of its status and not expect OPNsense/Deciso to do anything about it.
Autoboot in 0 seconds. [Space] to pause 26.7 ``The Road Ahead'' /
Loading kernel...
/boot/kernel/kernel text=0x18d968 text=0xe7b06c text=0x47b433 data=0x180+0xe80 data=0x1a84c0+0x857b40 0x8+0x1abe48+0x8+0x1d1c04
Loading configured modules...
/boot/kernel/pf.ko size 0xbd6e8 at 0x277e000
/boot/kernel/zfs.ko size 0x628648 at 0x283c000
/boot/kernel/pfsync.ko size 0x12340 at 0x2e65000
/boot/kernel/carp.ko size 0x11b40 at 0x2e78000
/boot/kernel/pflog.ko size 0x3c08 at 0x2e8a000
/boot/kernel/opensolaris.ko size 0x1e2f0 at 0x2e8e000
/etc/hostid size=0x25
/boot/kernel/if_gre.ko size 0xaa78 at 0x2ead000
/boot/kernel/if_lagg.ko size 0x15ef8 at 0x2eb8000
loading required module 'if_infiniband'
/boot/kernel/if_infiniband.ko size 0x3558 at 0x2ece000
/boot/kernel/if_enc.ko size 0x4be0 at 0x2ed2000
/boot/firmware/intel-ucode.bin size=0x1050000
/boot/entropy size=0x1000
/boot/kernel/if_bridge.ko size 0x10a68 at 0x3f28000
loading required module 'bridgestp'
/boot/kernel/bridgestp.ko size 0x8af8 at 0x3f39000
staging 0x6c000000 (not copying) tramp 0x76df6000 PT4 0x76ded000
Start @ 0xffffffff8038e000 ...
Loading splash ok
Generating configuration: templates...done
>>> Invoking early script 'cpu-microcode'
Updating CPU Microcode...
CPU: Intel(R) Celeron(R) N5105 @ 2.00GHz (1996.80-MHz K8-class CPU)
Origin="GenuineIntel" Id=0x906c0 Family=0x6 Model=0x9c Stepping=0
Features=0xbfebfbff<FPU,VME,DE,PSE,TSC,MSR,PAE,MCE,CX8,APIC,SEP,MTRR,PGE,MCA,CMOV,PAT,PSE36,CLFLUSH,DTS,ACPI,MMX,FXSR,SSE,SSE2,SS,HTT,TM,PBE>
Features2=0x4ff8ebbf<SSE3,PCLMULQDQ,DTES64,MON,DS_CPL,VMX,EST,TM2,SSSE3,SDBG,CX16,xTPR,PDCM,SSE4.1,SSE4.2,x2APIC,MOVBE,POPCNT,TSCDLT,AESNI,XSAVE,OSXSAVE,RDRAND>
AMD Features=0x28100800<SYSCALL,NX,RDTSCP,LM>
AMD Features2=0x101<LAHF,Prefetch>
Structured Extended Features=0x2394a2c3<FSGSBASE,TSCADJ,FDPEXC,SMEP,ERMS,NFPUSG,PQE,RDSEED,SMAP,CLFLUSHOPT,CLWB,PROCTRACE,SHA>
Structured Extended Features2=0x18400124<UMIP,WAITPKG,GFNI,RDPID,MOVDIRI,MOVDIR64B>
Structured Extended Features3=0xfc000400<MD_CLEAR,IBPB,STIBP,L1DFL,ARCH_CAP,CORE_CAP,SSBD>
XSAVE Features=0xf<XSAVEOPT,XSAVEC,XINUSE,XSAVES>
IA32_ARCH_CAPS=0x14020c6b<RDCL_NO,IBRS_ALL,SKIP_L1DFL_VME,MDS_NO>
VT-x: PAT,HLT,MTF,PAUSE,EPT,UG,VPID,VID,PostIntr
TSC: P-state invariant, performance statistics
Done.
Quote from: Patrick M. Hausen on July 15, 2026, 03:37:46 PMIf you had AdGuard Home installed from the mimugmail or mimugmail-single repository, it will survive an upgrade to 26.7 and continue to work.
You only need to disable the repository, not uninstall the plugin. The plugins UI will show it as "orphaned", but that is not a problem.
AdGuard Home was never a community plugin in the official OPNsense repo.