How to stop OpenVPN tunnel if server doesn't response?Problems setting up a VPN: can connect but can't ping anyoneOpenVPN connection from within 2nd subnet in office?openvpn multiple instances route issue?openvpn: connection established, can't ping server tun interface (debian server, windows & os x clients)OpenVPN: forward client's LAN to the VPNTomato to OpenVPN Server on Ubuntu ServerConfiguring OpenVPN server (Debian 8) and client (Windows 10)OpenVPN and multicast routingOpenVPN Client Local LAN AccessHow to configure iptables for a dial-up VPN with OpenVPN and two interfaces?

Is it truly impossible to tell what a CPU is doing?

Compaq Portable vs IBM 5155 Portable PC

Could a 19.25mm revolver actually exist?

Is it possible to remotely hack the GPS system and disable GPS service worldwide?

Is it legal to meet with potential future employers in the UK, whilst visiting from the USA

Does pair production happen even when the photon is around a neutron?

Why did the person in charge of a principality not just declare themself king?

What does $!# mean in Shell scripting?

My employer faked my resume to acquire projects

Count rotary dial pulses in a phone number (including letters)

Why do Russians almost not use verbs of possession akin to "have"?

Why most published works in medical imaging try reducing false positives?

Is there an online tool which supports shared writing?

I know that there is a preselected candidate for a position to be filled at my department. What should I do?

Why did Jon Snow do this immoral act if he is so honorable?

How to let other coworkers know that I don't share my coworker's political views?

A steel cutting sword?

Is the field of q-series 'dead'?

Why didn't Thanos use the Time Stone to stop the Avengers' plan?

Can I summon an otherworldly creature with the Gate spell without knowing its true name?

Why does this if-statement combining assignment and an equality check return true?

Ingress filtering on edge routers and performance concerns

Is the Indo-European language family made up?

How to cut a climbing rope?



How to stop OpenVPN tunnel if server doesn't response?


Problems setting up a VPN: can connect but can't ping anyoneOpenVPN connection from within 2nd subnet in office?openvpn multiple instances route issue?openvpn: connection established, can't ping server tun interface (debian server, windows & os x clients)OpenVPN: forward client's LAN to the VPNTomato to OpenVPN Server on Ubuntu ServerConfiguring OpenVPN server (Debian 8) and client (Windows 10)OpenVPN and multicast routingOpenVPN Client Local LAN AccessHow to configure iptables for a dial-up VPN with OpenVPN and two interfaces?






.everyoneloves__top-leaderboard:empty,.everyoneloves__mid-leaderboard:empty,.everyoneloves__bot-mid-leaderboard:empty height:90px;width:728px;box-sizing:border-box;








0















I have two openvpn servers, but both routes to the one network. It made for the fault tolerance. If one of them is down traffic should go via another one. Clients receive routes with different metric, so this task is solved.



But when one of the servers goes offline, client try to reconnect to this server and doesn't turn off tun-interface. So traffic tries to go via problem server.



I want to client turns off tun-interface when server goes offline and automatically turn it on when server turns back.



This is client's config:



tls-client

dev tun
proto udp
remote server1.ovpn.example.com 2100

topology subnet

pull

#resolv-retry infinite
#nobind

tls-auth keys/ta.key 1
ca keys/ca.crt
cert keys/client.crt
key keys/client.key
ns-cert-type server

cipher DES-EDE3-CBC

keepalive 10 120

comp-lzo

user nobody
group nogroup

persist-key
persist-tun

status /var/log/openvpn-status.log
log-append /var/log/openvpn.log

verb 3

route 172.19.20.0 255.255.255.0 172.16.150.3
route-metric 3


I think if I remove keep-alive the tun-interface will goes offline after ping timeout, but will it turns back when server return?










share|improve this question

















  • 1





    Your question does not seems to be clear, shouldn't just a matter of having multiple servers, with infinite resolv be enough? remote server1; remote server2; resolv-retry infinite. Tun will keep trying until it finds a healthy openvpn server...

    – user122772
    May 31 '16 at 20:52

















0















I have two openvpn servers, but both routes to the one network. It made for the fault tolerance. If one of them is down traffic should go via another one. Clients receive routes with different metric, so this task is solved.



But when one of the servers goes offline, client try to reconnect to this server and doesn't turn off tun-interface. So traffic tries to go via problem server.



I want to client turns off tun-interface when server goes offline and automatically turn it on when server turns back.



This is client's config:



tls-client

dev tun
proto udp
remote server1.ovpn.example.com 2100

topology subnet

pull

#resolv-retry infinite
#nobind

tls-auth keys/ta.key 1
ca keys/ca.crt
cert keys/client.crt
key keys/client.key
ns-cert-type server

cipher DES-EDE3-CBC

keepalive 10 120

comp-lzo

user nobody
group nogroup

persist-key
persist-tun

status /var/log/openvpn-status.log
log-append /var/log/openvpn.log

verb 3

route 172.19.20.0 255.255.255.0 172.16.150.3
route-metric 3


I think if I remove keep-alive the tun-interface will goes offline after ping timeout, but will it turns back when server return?










share|improve this question

















  • 1





    Your question does not seems to be clear, shouldn't just a matter of having multiple servers, with infinite resolv be enough? remote server1; remote server2; resolv-retry infinite. Tun will keep trying until it finds a healthy openvpn server...

    – user122772
    May 31 '16 at 20:52













0












0








0








I have two openvpn servers, but both routes to the one network. It made for the fault tolerance. If one of them is down traffic should go via another one. Clients receive routes with different metric, so this task is solved.



But when one of the servers goes offline, client try to reconnect to this server and doesn't turn off tun-interface. So traffic tries to go via problem server.



I want to client turns off tun-interface when server goes offline and automatically turn it on when server turns back.



This is client's config:



tls-client

dev tun
proto udp
remote server1.ovpn.example.com 2100

topology subnet

pull

#resolv-retry infinite
#nobind

tls-auth keys/ta.key 1
ca keys/ca.crt
cert keys/client.crt
key keys/client.key
ns-cert-type server

cipher DES-EDE3-CBC

keepalive 10 120

comp-lzo

user nobody
group nogroup

persist-key
persist-tun

status /var/log/openvpn-status.log
log-append /var/log/openvpn.log

verb 3

route 172.19.20.0 255.255.255.0 172.16.150.3
route-metric 3


I think if I remove keep-alive the tun-interface will goes offline after ping timeout, but will it turns back when server return?










share|improve this question














I have two openvpn servers, but both routes to the one network. It made for the fault tolerance. If one of them is down traffic should go via another one. Clients receive routes with different metric, so this task is solved.



But when one of the servers goes offline, client try to reconnect to this server and doesn't turn off tun-interface. So traffic tries to go via problem server.



I want to client turns off tun-interface when server goes offline and automatically turn it on when server turns back.



This is client's config:



tls-client

dev tun
proto udp
remote server1.ovpn.example.com 2100

topology subnet

pull

#resolv-retry infinite
#nobind

tls-auth keys/ta.key 1
ca keys/ca.crt
cert keys/client.crt
key keys/client.key
ns-cert-type server

cipher DES-EDE3-CBC

keepalive 10 120

comp-lzo

user nobody
group nogroup

persist-key
persist-tun

status /var/log/openvpn-status.log
log-append /var/log/openvpn.log

verb 3

route 172.19.20.0 255.255.255.0 172.16.150.3
route-metric 3


I think if I remove keep-alive the tun-interface will goes offline after ping timeout, but will it turns back when server return?







configuration openvpn timeout






share|improve this question













share|improve this question











share|improve this question




share|improve this question










asked May 31 '16 at 20:38









abr_stackoverflowabr_stackoverflow

160110




160110







  • 1





    Your question does not seems to be clear, shouldn't just a matter of having multiple servers, with infinite resolv be enough? remote server1; remote server2; resolv-retry infinite. Tun will keep trying until it finds a healthy openvpn server...

    – user122772
    May 31 '16 at 20:52












  • 1





    Your question does not seems to be clear, shouldn't just a matter of having multiple servers, with infinite resolv be enough? remote server1; remote server2; resolv-retry infinite. Tun will keep trying until it finds a healthy openvpn server...

    – user122772
    May 31 '16 at 20:52







1




1





Your question does not seems to be clear, shouldn't just a matter of having multiple servers, with infinite resolv be enough? remote server1; remote server2; resolv-retry infinite. Tun will keep trying until it finds a healthy openvpn server...

– user122772
May 31 '16 at 20:52





Your question does not seems to be clear, shouldn't just a matter of having multiple servers, with infinite resolv be enough? remote server1; remote server2; resolv-retry infinite. Tun will keep trying until it finds a healthy openvpn server...

– user122772
May 31 '16 at 20:52










2 Answers
2






active

oldest

votes


















0














Get rid of the persist-tun option. Without that option, then the VPN link goes down, the tun device will close and be removed. The problem of course is that removing that option means that you need to run your VPN daemon as root instead of nobody. Because as nobody account, OpenVPN will not be able to create a new tun device when the connection is re-established.






share|improve this answer






























    0














    After creating my VPN project for Qubes, I discovered OpenVPN has a definite tendency to hang when a connection goes down.



    Here are the options I've added to make OpenVPN responsive to disconnections:



    ping 10
    ping-restart 40
    connect-retry 5 30
    connect-retry-max 7
    resolv-retry 15


    According to the docs, if you have multiple remote entries then upon connection failure ping-restart will cause the next remote to be used. Therefore, specifying multiple remote lines for your servers could be useful here.






    share|improve this answer























      Your Answer








      StackExchange.ready(function()
      var channelOptions =
      tags: "".split(" "),
      id: "2"
      ;
      initTagRenderer("".split(" "), "".split(" "), channelOptions);

      StackExchange.using("externalEditor", function()
      // Have to fire editor after snippets, if snippets enabled
      if (StackExchange.settings.snippets.snippetsEnabled)
      StackExchange.using("snippets", function()
      createEditor();
      );

      else
      createEditor();

      );

      function createEditor()
      StackExchange.prepareEditor(
      heartbeatType: 'answer',
      autoActivateHeartbeat: false,
      convertImagesToLinks: true,
      noModals: true,
      showLowRepImageUploadWarning: true,
      reputationToPostImages: 10,
      bindNavPrevention: true,
      postfix: "",
      imageUploader:
      brandingHtml: "Powered by u003ca class="icon-imgur-white" href="https://imgur.com/"u003eu003c/au003e",
      contentPolicyHtml: "User contributions licensed under u003ca href="https://creativecommons.org/licenses/by-sa/3.0/"u003ecc by-sa 3.0 with attribution requiredu003c/au003e u003ca href="https://stackoverflow.com/legal/content-policy"u003e(content policy)u003c/au003e",
      allowUrls: true
      ,
      onDemand: true,
      discardSelector: ".discard-answer"
      ,immediatelyShowMarkdownHelp:true
      );



      );













      draft saved

      draft discarded


















      StackExchange.ready(
      function ()
      StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fserverfault.com%2fquestions%2f780124%2fhow-to-stop-openvpn-tunnel-if-server-doesnt-response%23new-answer', 'question_page');

      );

      Post as a guest















      Required, but never shown

























      2 Answers
      2






      active

      oldest

      votes








      2 Answers
      2






      active

      oldest

      votes









      active

      oldest

      votes






      active

      oldest

      votes









      0














      Get rid of the persist-tun option. Without that option, then the VPN link goes down, the tun device will close and be removed. The problem of course is that removing that option means that you need to run your VPN daemon as root instead of nobody. Because as nobody account, OpenVPN will not be able to create a new tun device when the connection is re-established.






      share|improve this answer



























        0














        Get rid of the persist-tun option. Without that option, then the VPN link goes down, the tun device will close and be removed. The problem of course is that removing that option means that you need to run your VPN daemon as root instead of nobody. Because as nobody account, OpenVPN will not be able to create a new tun device when the connection is re-established.






        share|improve this answer

























          0












          0








          0







          Get rid of the persist-tun option. Without that option, then the VPN link goes down, the tun device will close and be removed. The problem of course is that removing that option means that you need to run your VPN daemon as root instead of nobody. Because as nobody account, OpenVPN will not be able to create a new tun device when the connection is re-established.






          share|improve this answer













          Get rid of the persist-tun option. Without that option, then the VPN link goes down, the tun device will close and be removed. The problem of course is that removing that option means that you need to run your VPN daemon as root instead of nobody. Because as nobody account, OpenVPN will not be able to create a new tun device when the connection is re-established.







          share|improve this answer












          share|improve this answer



          share|improve this answer










          answered May 31 '16 at 22:02









          ZoredacheZoredache

          112k30232380




          112k30232380























              0














              After creating my VPN project for Qubes, I discovered OpenVPN has a definite tendency to hang when a connection goes down.



              Here are the options I've added to make OpenVPN responsive to disconnections:



              ping 10
              ping-restart 40
              connect-retry 5 30
              connect-retry-max 7
              resolv-retry 15


              According to the docs, if you have multiple remote entries then upon connection failure ping-restart will cause the next remote to be used. Therefore, specifying multiple remote lines for your servers could be useful here.






              share|improve this answer



























                0














                After creating my VPN project for Qubes, I discovered OpenVPN has a definite tendency to hang when a connection goes down.



                Here are the options I've added to make OpenVPN responsive to disconnections:



                ping 10
                ping-restart 40
                connect-retry 5 30
                connect-retry-max 7
                resolv-retry 15


                According to the docs, if you have multiple remote entries then upon connection failure ping-restart will cause the next remote to be used. Therefore, specifying multiple remote lines for your servers could be useful here.






                share|improve this answer

























                  0












                  0








                  0







                  After creating my VPN project for Qubes, I discovered OpenVPN has a definite tendency to hang when a connection goes down.



                  Here are the options I've added to make OpenVPN responsive to disconnections:



                  ping 10
                  ping-restart 40
                  connect-retry 5 30
                  connect-retry-max 7
                  resolv-retry 15


                  According to the docs, if you have multiple remote entries then upon connection failure ping-restart will cause the next remote to be used. Therefore, specifying multiple remote lines for your servers could be useful here.






                  share|improve this answer













                  After creating my VPN project for Qubes, I discovered OpenVPN has a definite tendency to hang when a connection goes down.



                  Here are the options I've added to make OpenVPN responsive to disconnections:



                  ping 10
                  ping-restart 40
                  connect-retry 5 30
                  connect-retry-max 7
                  resolv-retry 15


                  According to the docs, if you have multiple remote entries then upon connection failure ping-restart will cause the next remote to be used. Therefore, specifying multiple remote lines for your servers could be useful here.







                  share|improve this answer












                  share|improve this answer



                  share|improve this answer










                  answered Dec 8 '18 at 16:57









                  taskettasket

                  213




                  213



























                      draft saved

                      draft discarded
















































                      Thanks for contributing an answer to Server Fault!


                      • Please be sure to answer the question. Provide details and share your research!

                      But avoid


                      • Asking for help, clarification, or responding to other answers.

                      • Making statements based on opinion; back them up with references or personal experience.

                      To learn more, see our tips on writing great answers.




                      draft saved


                      draft discarded














                      StackExchange.ready(
                      function ()
                      StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fserverfault.com%2fquestions%2f780124%2fhow-to-stop-openvpn-tunnel-if-server-doesnt-response%23new-answer', 'question_page');

                      );

                      Post as a guest















                      Required, but never shown





















































                      Required, but never shown














                      Required, but never shown












                      Required, but never shown







                      Required, but never shown

































                      Required, but never shown














                      Required, but never shown












                      Required, but never shown







                      Required, but never shown







                      Popular posts from this blog

                      Club Baloncesto Breogán Índice Historia | Pavillón | Nome | O Breogán na cultura popular | Xogadores | Adestradores | Presidentes | Palmarés | Historial | Líderes | Notas | Véxase tamén | Menú de navegacióncbbreogan.galCadroGuía oficial da ACB 2009-10, páxina 201Guía oficial ACB 1992, páxina 183. Editorial DB.É de 6.500 espectadores sentados axeitándose á última normativa"Estudiantes Junior, entre as mellores canteiras"o orixinalHemeroteca El Mundo Deportivo, 16 setembro de 1970, páxina 12Historia do BreogánAlfredo Pérez, o último canoneiroHistoria C.B. BreogánHemeroteca de El Mundo DeportivoJimmy Wright, norteamericano do Breogán deixará Lugo por ameazas de morteResultados de Breogán en 1986-87Resultados de Breogán en 1990-91Ficha de Velimir Perasović en acb.comResultados de Breogán en 1994-95Breogán arrasa al Barça. "El Mundo Deportivo", 27 de setembro de 1999, páxina 58CB Breogán - FC BarcelonaA FEB invita a participar nunha nova Liga EuropeaCharlie Bell na prensa estatalMáximos anotadores 2005Tempada 2005-06 : Tódolos Xogadores da Xornada""Non quero pensar nunha man negra, mais pregúntome que está a pasar""o orixinalRaúl López, orgulloso dos xogadores, presume da boa saúde económica do BreogánJulio González confirma que cesa como presidente del BreogánHomenaxe a Lisardo GómezA tempada do rexurdimento celesteEntrevista a Lisardo GómezEl COB dinamita el Pazo para forzar el quinto (69-73)Cafés Candelas, patrocinador del CB Breogán"Suso Lázare, novo presidente do Breogán"o orixinalCafés Candelas Breogán firma el mayor triunfo de la historiaEl Breogán realizará 17 homenajes por su cincuenta aniversario"O Breogán honra ao seu fundador e primeiro presidente"o orixinalMiguel Giao recibiu a homenaxe do PazoHomenaxe aos primeiros gladiadores celestesO home que nos amosa como ver o Breo co corazónTita Franco será homenaxeada polos #50anosdeBreoJulio Vila recibirá unha homenaxe in memoriam polos #50anosdeBreo"O Breogán homenaxeará aos seus aboados máis veteráns"Pechada ovación a «Capi» Sanmartín e Ricardo «Corazón de González»Homenaxe por décadas de informaciónPaco García volve ao Pazo con motivo do 50 aniversario"Resultados y clasificaciones""O Cafés Candelas Breogán, campión da Copa Princesa""O Cafés Candelas Breogán, equipo ACB"C.B. Breogán"Proxecto social"o orixinal"Centros asociados"o orixinalFicha en imdb.comMario Camus trata la recuperación del amor en 'La vieja música', su última película"Páxina web oficial""Club Baloncesto Breogán""C. B. Breogán S.A.D."eehttp://www.fegaba.com

                      Vilaño, A Laracha Índice Patrimonio | Lugares e parroquias | Véxase tamén | Menú de navegación43°14′52″N 8°36′03″O / 43.24775, -8.60070

                      Cegueira Índice Epidemioloxía | Deficiencia visual | Tipos de cegueira | Principais causas de cegueira | Tratamento | Técnicas de adaptación e axudas | Vida dos cegos | Primeiros auxilios | Crenzas respecto das persoas cegas | Crenzas das persoas cegas | O neno deficiente visual | Aspectos psicolóxicos da cegueira | Notas | Véxase tamén | Menú de navegación54.054.154.436928256blindnessDicionario da Real Academia GalegaPortal das Palabras"International Standards: Visual Standards — Aspects and Ranges of Vision Loss with Emphasis on Population Surveys.""Visual impairment and blindness""Presentan un plan para previr a cegueira"o orixinalACCDV Associació Catalana de Cecs i Disminuïts Visuals - PMFTrachoma"Effect of gene therapy on visual function in Leber's congenital amaurosis"1844137110.1056/NEJMoa0802268Cans guía - os mellores amigos dos cegosArquivadoEscola de cans guía para cegos en Mortágua, PortugalArquivado"Tecnología para ciegos y deficientes visuales. Recopilación de recursos gratuitos en la Red""Colorino""‘COL.diesis’, escuchar los sonidos del color""COL.diesis: Transforming Colour into Melody and Implementing the Result in a Colour Sensor Device"o orixinal"Sistema de desarrollo de sinestesia color-sonido para invidentes utilizando un protocolo de audio""Enseñanza táctil - geometría y color. Juegos didácticos para niños ciegos y videntes""Sistema Constanz"L'ocupació laboral dels cecs a l'Estat espanyol està pràcticament equiparada a la de les persones amb visió, entrevista amb Pedro ZuritaONCE (Organización Nacional de Cegos de España)Prevención da cegueiraDescrición de deficiencias visuais (Disc@pnet)Braillín, un boneco atractivo para calquera neno, con ou sen discapacidade, que permite familiarizarse co sistema de escritura e lectura brailleAxudas Técnicas36838ID00897494007150-90057129528256DOID:1432HP:0000618D001766C10.597.751.941.162C97109C0155020