Hello to Everyone,
i am moving from an old Notebook to a new one and part of this process is moving the openvpn-connection i need for business to the new notebook.
I am using KDE as desktop environment and duplicated everything including the certificates to the new notebooks networkmanager. I am able to connect to the vpn flawlessly, but exactly after 2 minutes, the log-files shows that the tunnel needs a reauthentication, which can’t be done with the former credentials, because they include a onetime password, that expires after 30 seconds (Sophos Firewall). So i am droped out of the vpn, even though the networkmanager shows a stable tunnel should be still up. Every connection i establish, lasts only for about 2 minutes, until it exits again because of failed reauthentication.
On my old notebook the logs show “wpa_supplicant”, which does a “Group rekeying completed” every 3-4 minutes and i think, this could be the tool, that helps the tunnel to stay flawless up. But when i install the “wpa_supplicant” package on the new notebook, it doesn’t do the magic all by itself. Perhaps i did something in the past to configure this tool, but i don’t know what it was.
Does anyone know what i am doing wrong?
Thanks
furby
Here are the needed logs:
- my old notebook starting the vpn and reconnecting to it after 4 minutes:
Jan 19 11:33:10 hostname kded6[1072]: Unhandled VPN connection state change: NetworkManager::VpnConnection::Connecting
Jan 19 11:33:10 hostname nm-openvpn[1991]: OpenVPN 2.6.17 [git:makepkg/fa20154d58ca609b+] x86_64-pc-linux-gnu [SSL (OpenSSL)] [LZO] [LZ4] [EPOLL] [PKCS11] [MH/PKTINFO] [AEAD] [DCO] built on Nov 28 2025
Jan 19 11:33:10 hostname nm-openvpn[1991]: library versions: OpenSSL 3.6.0 1 Oct 2025, LZO 2.10
Jan 19 11:33:10 hostname nm-openvpn[1991]: DCO version: N/A
Jan 19 11:33:10 hostname nm-openvpn[1991]: WARNING: No server certificate verification method has been enabled. See http://openvpn.net/howto.html#mitm for more info.
Jan 19 11:33:10 hostname nm-openvpn[1991]: NOTE: the current --script-security setting may allow this configuration to call user-defined scripts
Jan 19 11:33:10 hostname nm-openvpn[1991]: TCP/UDP: Preserving recently used remote address: [AF_INET]xx.xxx.xx.xx:8443
Jan 19 11:33:10 hostname nm-openvpn[1991]: Attempting to establish TCP connection with [AF_INET]xx.xxx.xx.xx:8443
Jan 19 11:33:10 hostname nm-openvpn[1991]: TCP connection established with [AF_INET]xx.xxx.xx.xx:8443
Jan 19 11:33:10 hostname nm-openvpn[1991]: TCPv4_CLIENT link local: (not bound)
Jan 19 11:33:10 hostname nm-openvpn[1991]: TCPv4_CLIENT link remote: [AF_INET]xx.xxx.xx.xx:8443
Jan 19 11:33:10 hostname nm-openvpn[1991]: NOTE: UID/GID downgrade will be delayed because of --client, --pull, or --up-delay
Jan 19 11:33:10 hostname nm-openvpn[1991]: [Appliance_Certificate_ob2Vf9QO1H2muw4] Peer Connection Initiated with [AF_INET]xx.xxx.xx.xx:8443
Jan 19 11:33:12 hostname nm-openvpn[1991]: TUN/TAP device tun0 opened
Jan 19 11:33:12 hostname nm-openvpn[1991]: /usr/lib/nm-openvpn-service-openvpn-helper --debug 0 1975 --bus-name org.freedesktop.NetworkManager.openvpn.Connection_3 --tun -- tun0 1500 0 xx.xxx.x.x 255.255.255.0 init
Jan 19 11:33:12 hostname NetworkManager[665]: <info> [1768818792.1261] manager: (tun0): new Tun device (/org/freedesktop/NetworkManager/Devices/6)
Jan 19 11:33:12 hostname kded6[1072]: Unhandled VPN connection state change: NetworkManager::VpnConnection::GettingIpConfig
Jan 19 11:33:12 hostname nm-openvpn[1991]: UID set to nm-openvpn
Jan 19 11:33:12 hostname nm-openvpn[1991]: GID set to nm-openvpn
Jan 19 11:33:12 hostname nm-openvpn[1991]: Capabilities retained: CAP_NET_ADMIN
Jan 19 11:33:12 hostname nm-openvpn[1991]: Initialization Sequence Completed
Jan 19 11:33:12 hostname NetworkManager[665]: <info> [1768818792.1683] device (tun0): state change: unmanaged -> unavailable (reason 'connection-assumed', managed-type: 'external')
Jan 19 11:33:12 hostname NetworkManager[665]: <info> [1768818792.1697] device (tun0): state change: unavailable -> disconnected (reason 'connection-assumed', managed-type: 'external')
Jan 19 11:33:12 hostname NetworkManager[665]: <info> [1768818792.1713] device (tun0): Activation: starting connection 'tun0' (a9c17244-0ad5-40f2-a9ff-dac171ed1341)
Jan 19 11:33:12 hostname NetworkManager[665]: <info> [1768818792.1716] device (tun0): state change: disconnected -> prepare (reason 'none', managed-type: 'external')
Jan 19 11:33:12 hostname NetworkManager[665]: <info> [1768818792.1720] device (tun0): state change: prepare -> config (reason 'none', managed-type: 'external')
Jan 19 11:33:12 hostname NetworkManager[665]: <info> [1768818792.1723] device (tun0): state change: config -> ip-config (reason 'none', managed-type: 'external')
Jan 19 11:33:12 hostname NetworkManager[665]: <info> [1768818792.1727] device (tun0): state change: ip-config -> ip-check (reason 'none', managed-type: 'external')
Jan 19 11:33:12 hostname systemd[1]: Starting Network Manager Script Dispatcher Service...
Jan 19 11:33:12 hostname systemd[1]: Started Network Manager Script Dispatcher Service.
Jan 19 11:33:12 hostname NetworkManager[665]: <info> [1768818792.2155] policy: set 'sslvpn-furby-client-config' (tun0) as default for IPv4 routing and DNS
Jan 19 11:33:12 hostname NetworkManager[665]: <info> [1768818792.2164] device (tun0): state change: ip-check -> secondaries (reason 'none', managed-type: 'external')
Jan 19 11:33:12 hostname NetworkManager[665]: <info> [1768818792.2166] device (tun0): state change: secondaries -> activated (reason 'none', managed-type: 'external')
Jan 19 11:33:12 hostname NetworkManager[665]: <info> [1768818792.2170] device (tun0): Activation: successful, device activated.
Jan 19 11:33:12 hostname kded6[1072]: Failed to notify "Created too many similar notifications in quick succession"
Jan 19 11:33:22 hostname systemd[1]: NetworkManager-dispatcher.service: Deactivated successfully.
.
.
Jan 19 11:37:01 hostname wpa_supplicant[731]: wlp0s20f3: RSN: Group rekeying completed with c8:0e:14:3d:b0:66 [GTK=CCMP]
- and my new notebook, falling out of the tunnel after about 2 minutes:
Jan 19 11:17:49 hostname nm-openvpn[4447]: OpenVPN 2.6.17 [git:makepkg/fa20154d58ca609b+] x86_64-pc-linux-gnu [SSL (OpenSSL)] [LZO] [LZ4] [EPOLL] [PKCS11] [MH/PKTINFO] [AEAD] [DCO] built on Nov 28 2025
Jan 19 11:17:49 hostname nm-openvpn[4447]: library versions: OpenSSL 3.6.0 1 Oct 2025, LZO 2.10
Jan 19 11:17:49 hostname nm-openvpn[4447]: DCO version: N/A
Jan 19 11:17:49 hostname nm-openvpn[4447]: WARNING: No server certificate verification method has been enabled. See http://openvpn.net/howto.html#mitm for more info.
Jan 19 11:17:49 hostname nm-openvpn[4447]: NOTE: the current --script-security setting may allow this configuration to call user-defined scripts
Jan 19 11:17:49 hostname nm-openvpn[4447]: TCP/UDP: Preserving recently used remote address: [AF_INET]xx.xxx.xx.xx:8443
Jan 19 11:17:49 hostname nm-openvpn[4447]: Attempting to establish TCP connection with [AF_INET]xx.xxx.xx.xx:8443
Jan 19 11:17:49 hostname nm-openvpn[4447]: TCP connection established with [AF_INET]xx.xxx.xx.xx:8443
Jan 19 11:17:49 hostname nm-openvpn[4447]: TCPv4_CLIENT link local: (not bound)
Jan 19 11:17:49 hostname nm-openvpn[4447]: TCPv4_CLIENT link remote: [AF_INET]xx.xxx.xx.xx:8443
Jan 19 11:17:49 hostname nm-openvpn[4447]: NOTE: UID/GID downgrade will be delayed because of --client, --pull, or --up-delay
Jan 19 11:17:50 hostname nm-openvpn[4447]: [Appliance_Certificate_ob2Vf9QO1H2muw4] Peer Connection Initiated with [AF_INET]xx.xxx.xx.xx:8443
Jan 19 11:17:52 hostname nm-openvpn[4447]: TUN/TAP device tun0 opened
Jan 19 11:17:52 hostname nm-openvpn[4447]: /usr/lib/nm-openvpn-service-openvpn-helper --debug 0 4434 --bus-name org.freedesktop.NetworkManager.openvpn.Connection_6 --tun -- tun0 1500 0 xx.xxx.x.x 255.255.255.0 init
Jan 19 11:17:52 hostname NetworkManager[714]: <info> [1768817872.1930] manager: (tun0): new Tun device (/org/freedesktop/NetworkManager/Devices/5)
Jan 19 11:17:52 hostname kded6[1206]: Unhandled VPN connection state change: NetworkManager::VpnConnection::GettingIpConfig
Jan 19 11:17:52 hostname avahi-daemon[716]: Joining mDNS multicast group on interface tun0.IPv6 with address xxxx::xxxx:xxxx:xxxx:xxxx.
Jan 19 11:17:52 hostname avahi-daemon[716]: New relevant interface tun0.IPv6 for mDNS.
Jan 19 11:17:52 hostname avahi-daemon[716]: Registering new address record for xxxx::xxxx:xxxx:xxxx:xxxx on tun0.*.
Jan 19 11:17:52 hostname nm-openvpn[4447]: UID set to nm-openvpn
Jan 19 11:17:52 hostname nm-openvpn[4447]: GID set to nm-openvpn
Jan 19 11:17:52 hostname nm-openvpn[4447]: Capabilities retained: CAP_NET_ADMIN
Jan 19 11:17:52 hostname nm-openvpn[4447]: Initialization Sequence Completed
.
.
Jan 19 11:18:02 hostname systemd[1]: NetworkManager-dispatcher.service: Deactivated successfully.
Jan 19 11:19:46 hostname nm-openvpn[4447]: AUTH: Received control message: AUTH_FAILED
Jan 19 11:19:46 hostname nm-openvpn[4447]: SIGUSR1[soft,auth-failure] received, process restarting