DSM 7.0 After DSM 7 update VPN not working

Currently reading
DSM 7.0 After DSM 7 update VPN not working

So recenlty updated my DS420+ to DSM 7. Everything looks fine, but after update I can't connect to my vpn.... I'm using L2TP/IPSec... Did someone collide with this problem?
Windows 10. Just no errors. I have added my vpn login information in windows vpn management, and after pushing connect I see only connecting...
Windows 10. Just no errors. I have added my vpn login information in windows vpn management, and after pushing connect I see only connecting...
So you're talking about VPN Server with a Windows client device. It wasn't clear if you meant this or if you are connecting the NAS to a VPN service, where the NAS is the client device.

I'll move this thread to VPN Server package. And if I get time later I can see if I can connect locally to one of my NAS with DSM 7.

BTW is your NAS using the same LAN IP as is configured in your Internet router/firewall port forwarding?
We also updated our DS920+ yesterday, and since then VPN isn't working.

Error messages:

Thu Aug 05 15:37:18 2021 WARNING: No server certificate verification method has been enabled.  See http://openvpn.net/howto.html#mitm for more info.
Thu Aug 05 15:37:18 2021 TCP/UDP: Preserving recently used remote address: [AF_INET]XXX.XXX.XXX.XXX:1194
Thu Aug 05 15:37:18 2021 UDP link local (bound): [AF_INET][undef]:1194
Thu Aug 05 15:37:18 2021 UDP link remote: [AF_INET]XXX.XXX.XXX.XXX:1194
Thu Aug 05 15:37:19 2021 [synology] Peer Connection Initiated with [AF_INET]XXX.XXX.XXX.XXX:1194
Thu Aug 05 15:37:21 2021 AUTH: Received control message: AUTH_FAILED
Thu Aug 05 15:37:21 2021 SIGUSR1[soft,auth-failure] received, process restarting

First entry was always there, XXX.XXX.XXX.XXX:1194 is our masked public IP.

Is this module broken?
I have a simmilar experience, my DS218j and DS120j fails to connect to my L2TP/IPSec VPN (hosted on Ubiquity USG) after upgrading to DSM 7.

There were no network IP / routing changes.

Quite an issue for me since I use this VPN for daily backups.
Have you tried with a newly exported ovpn file, with your normal updates applied? At least you can compare the old and new to confirm that the certificates are the same.
Yes - when i change the certificate for vpn server the connection gets cert errors. It seems to be the correct certificate.

FWIW... Over at the community, there's a "missing cert" issue with openvpn (the workaround is a simple copy command in SSH).
Could you please link it? I unfortunately can't find the thread over at the community :/
What? With their fine search tool? :ROFLMAO:
I quite dislike that search tool :ROFLMAO: Thanks!

Oh i see, i searched under the category DSM 7 - which this topic isn't assigned to...

And - my ca.crt is filled with the right ca cert...
Also the log under /var/log/openvpn.log isn't created ...

My problem seems to differ by now, so maybe i'll create another topic.
I had recent issues w/DSM6 which required me to reissue my OVPN file to my clients. Not sure if that would help those here w/DSM7 issues.
I've a feeling it is linked to the letsencrypt certificate. Last week all was well, then the cert renewed and I have had problems ever since.

I spent a good hour last night resetting the opvn file but to no avail. I even downgraded the vpn server version.

Coupled with other issues I've seen posted in the last few days, Synology have really messed up. Almost makes me want to throw the towel in on self hosting stuff.......almost.
@AdrianEarnshaw I think I remember you had an SRM router. If it’s possible you could migrate over to VPN Plus on that, thereby making your VPN users external to the NAS, just like any other LAN device.

This is my preference as it keeps network functions on the router and content on the NAS.

Actually I maintain VPN Server as a fallback for VPN Plus.
Great memory. Unfortunately I can no longer use the SRM. I had fibre installed with VoIP phones, as they are moving away from copper telephone lines in the UK. Nice package deal so I thought.

I asked the question to BT could I continue to use my own third party router, they answered the affirmative. Turns out I am stuck with the crappy BT SmartHub2 otherwise the phones won't work. Been battling to get it all stable and am just about there now. So no more Synology router 😔 which is a shame as it was the best router I ever owned.
How about using the SRM as a LAN based remote access server? I’ve not investigated which mode would be best. I know that my LAN devices can connect to VPN Plus services so at worse you probably will be able to have it on the network using just the LAN interface.
Any news? I have a similar problem...

L2TP VPN worked perfectly fine with VPN Server 1.4.2-2837 stopped working with 1.4.2-2838... Downgrade is not possible since I updated to DSM 7.0.

Works if I connect through the IP does not work with DYNDNS.

Create an account or login to comment

You must be a member in order to leave a comment

Create account

Create an account on our community. It's easy!

Log in

Already have an account? Log in here.

Similar threads

1634214296 Just made an account to thank you for that! I was searching for god knows how long and the fix...
  • Question
Instead of trying hostname, can you do your public IP address? Edit the openvpn config and put your...
Hello Sorry for the long time to update. I uninstalled the VPN Server and reinstalled. Same result, I...
  • Question
So you have two sites with identical local IP subnets and even IP assignments? If trying to connect from...
  • Question
The best way to set up a VPN client on a Synology RT2600ac router is to use the VPN Plus Server feature...

Welcome to SynoForum.com!

SynoForum.com is an unofficial Synology forum for NAS owners and enthusiasts.

Registration is free, easy and fast!