Page 1 of 1

Mikrotik OpenVPN Client over UDP stopped forwarding traffic on RouterOS 7.10.1

Posted: Mon Jul 10, 2023 9:33 pm
by freezer
Hi team,

I just upgraded from 7.9.x to 7.10.1 and noticed that my OpenVPN connection is coming up (IP is properly received by the client), but there is no connectivity over tunnel. No configuration change was made, nothing is blocked by firewall, MTU is set to 1300 bytes and was working perfectly fine before upgrade.

I could reproduce this issue on Mikrotik CAP AC XL and HAP AC3.

If I change on server and client from UDP to TCP and keep previous config - everything seems to be working fine, so most likely a bug in UDP client ( or network stack ) in RouterOS 10.x

I added 'accept' rules to firewall and can see packet counters incrementing in both directions, but neither site responds to ping nor can open any connection.

Re: Mikrotik OpenVPN Client over UDP stopped forwarding traffic on RouterOS 7.10.1

Posted: Wed Jul 12, 2023 8:06 pm
by ruchiry
Facing same issue.
Definitely it is a firmware issue.

Re: Mikrotik OpenVPN Client over UDP stopped forwarding traffic on RouterOS 7.10.1

Posted: Fri Jul 14, 2023 11:05 am
by HeinoHomm
In version 7.9.x.
After the OVPN client connects, the IP4 address given to client appears in the list of ipv4 addresses

ip/address/print

In version 7.10.x It's does not. And no one packets pass through the router.
My solution is: don't use version 7.10.x

Re: Mikrotik OpenVPN Client over UDP stopped forwarding traffic on RouterOS 7.10.1

Posted: Fri Jul 14, 2023 7:46 pm
by Gadulowaty
Same issue on 7.10. Cannot rollback to prev firmware.
Temporary solution for me was to assign permament binding for ovpn connection on server side and assign static ip address for that connection. Since then ovpn tunnel works but this solution is some kind of cucumbersome.
Hope Mikrotik fix this in next fw releases.

Re: Mikrotik OpenVPN Client over UDP stopped forwarding traffic on RouterOS 7.10.1

Posted: Fri Jul 14, 2023 9:22 pm
by freezer
I got static IP set for client, client gets the IP, firewall accept rule counters are incrementing but data is not forwarded nor replied over tunnel. Only solution was to switch to TCP based tunnel.

Re: Mikrotik OpenVPN Client over UDP stopped forwarding traffic on RouterOS 7.10.1

Posted: Fri Aug 04, 2023 10:56 am
by kotrbus
Hi,
is possible to make some statement about this bug from Mikrotik dev and support team? Is this issue in progress? I read changelog 7.11.rc1, but there is no information about this.

Many thanks for replies...

Re: Mikrotik OpenVPN Client over UDP stopped forwarding traffic on RouterOS 7.10.1

Posted: Sun Aug 06, 2023 1:46 am
by soko002
Same problem here. This solution works fine for me but changing udp to tcp or tcp to udp does not solve the problem in my case when client connect, ip address is not dynamically added to address table.

Re: Mikrotik OpenVPN Client over UDP stopped forwarding traffic on RouterOS 7.10.1

Posted: Thu Aug 10, 2023 5:36 pm
by dovydasz
I had the same problem but now it's working with 7.11rc3 (2023-Aug-09 17:41)

Re: Mikrotik OpenVPN Client over UDP stopped forwarding traffic on RouterOS 7.10.1

Posted: Sun Aug 13, 2023 10:58 am
by aleghise
I confirm upgrading firmware to 7.11rc3 solves this issue.

Re: Mikrotik OpenVPN Client over UDP stopped forwarding traffic on RouterOS 7.10.1

Posted: Wed Aug 16, 2023 8:50 pm
by kotrbus
No,
I have tested yet and issue persists in RouterOS 7.11 and 7.11rc4.

tcp mode works fine, udp not
rolling back to 7.9.2, this version works in both modes :-/

running on arm hAP ac^3 with hw crypto CBC

Re: Mikrotik OpenVPN Client over UDP stopped forwarding traffic on RouterOS 7.10.1

Posted: Thu Aug 17, 2023 9:00 pm
by tom76dc
On a RB4011 with arm architecture
For me version 7.11 did'nt help either. OpenVPN UDP is broken, TCP still works.

Workaround
revert to 7.9

I mailed support@mikrotik.com, hope they pick it up.
Regards,
Tom

Re: Mikrotik OpenVPN Client over UDP stopped forwarding traffic on RouterOS 7.10.1

Posted: Mon Sep 11, 2023 10:31 am
by negge
Had the same issue on my CCR1009-8G-1S-1S+ after upgrading from 7.3.1 to 7.11.2. Switching to TCP or downgrading to 7.9.2 helped.

Re: Mikrotik OpenVPN Client over UDP stopped forwarding traffic on RouterOS 7.10.1

Posted: Wed Sep 13, 2023 12:28 am
by srBungle
Same here. With 7.11.2 the issue persist.

Re: Mikrotik OpenVPN Client over UDP stopped forwarding traffic on RouterOS 7.10.1

Posted: Mon Oct 16, 2023 2:06 pm
by auoa
Same here...Lost 3 remote locations by updating my Mikrotiks... MMIPS and ARM devices
Can you guys investigate this issue, please?

Re: Mikrotik OpenVPN Client over UDP stopped forwarding traffic on RouterOS 7.10.1

Posted: Tue Oct 31, 2023 8:57 am
by kiaunel
In 7.12RC4, for me it is working again, even there is nothing in changelog about this. Hap AC3

Re: Mikrotik OpenVPN Client over UDP stopped forwarding traffic on RouterOS 7.10.1

Posted: Tue Nov 07, 2023 4:03 pm
by kiaunel
RC5 broke it again, reverter to RC4

Re: Mikrotik OpenVPN Client over UDP stopped forwarding traffic on RouterOS 7.10.1

Posted: Tue Nov 07, 2023 4:14 pm
by anav
Switch to wireguard or ipsec, live longer, less gray hair or ulcers.
OVPN = https://media.giphy.com/media/xxCNsOokj ... /giphy.gif

Re: Mikrotik OpenVPN Client over UDP stopped forwarding traffic on RouterOS 7.10.1

Posted: Tue Nov 07, 2023 6:30 pm
by kiaunel
I know what do you mean , unfortunately I can not switch ... some devices that i have to monitor are not able to install wireguard....

Re: Mikrotik OpenVPN Client over UDP stopped forwarding traffic on RouterOS 7.10.1

Posted: Sat Nov 18, 2023 11:31 am
by auoa
The current stable version 7.12 Stable works for me. OpenVPN UDP came back to life :-D