Jump to content
Not connected, Your IP: 3.16.83.150
Jamertol

Advice on how to handle monitoring the VPN connection by router software

Recommended Posts

Hi

I have set up a software router in my home and added a VPN AirVPN connection. The connection seems solid and stable, using OpenVPN. But the problem is the monitoring of the connection. Apparently, AirVPN servers do not resond very well to the monitoring messages of the router and eventually a 20%+ rate of packet drops is detected and the router automatically drops the connection thinking that there is something wrong with it. But if I disconnect monitoring the connection does not drop and works perfectly, fully maxing my ISP bandwith, which I am guessing it could not do if the AirVPN connection was having 20%+ packet drop rate.

Has anyone been in this situation? If that is the case, what can I do to improve the monitoring connection to the AirVPN servers? Any advice welcomed.

Share this post


Link to post

What is this "software router"? How are you monitoring it? Give us some names at least.


NOT AN AIRVPN TEAM MEMBER. USE TICKETS FOR PROFESSIONAL SUPPORT.

LZ1's New User Guide to AirVPN « Plenty of stuff for advanced users, too!

Want to contact me directly? All relevant methods are on my About me page.

Share this post


Link to post
On 3/25/2021 at 11:35 AM, OpenSourcerer said:

What is this "software router"? How are you monitoring it? Give us some names at least.


pfSense.

I have managed to solve the issue. I am posting it here in case someone who is doing this as a hobby like me has the same problem.

The default configuration of pfSense has the gateway send an IMCP packet every half second to check the stability of the connection. If you do not indicate a specific server, a gateway from a vpn interface sends the packet to the vpn server it is connecting to. Apparently the AirVPN servers did not like being probed so quick, every half second, and was droping some packets, giving the impression to my router that the connection was failing, when in reality the connection was stable, it was just the monitoring failing. The solution I found was to probe the AirVPN server less often. In this case I settled to probe it every 2 seconds, 4 times slower than the default. That means that I also had to increase other time parameters, like the time to average answer over. I basically multiplied every parameter per 4. I tried doing it x2, that means probing every one second, but, while better, it was still droping too much. Hope this helps someone.

Share this post


Link to post

You can solve this by using N external server too such as 8.8.8.8 in the gateway monitor field. 
just be aware this will add a static route to the monitor address so best to use an address that you aren’t using for DNS resolution. 

Share this post


Link to post

Thanks for the advice, but I honestly prefer not to ping servers of Amazon, Cloudfare or Goolag like the example 8.8.8.8 that you gave (and others). This is for privacy reasons and also I do not want to depend on them. Too much of the Internet already depends on them when it should not.

I think reducing the speed of pings is a better compromise. The only downside of reducing the ping is that if the connection goes down for real, it takes a bit longer for the software to realize about it. At least in my case, that is not a big deal.

Share this post


Link to post

I had used air on pfsense for years and never experienced anything of what you are talking about.. the monitoring server is the default gateway/ gateway address of the Tunnel it’s connected too 

Share this post


Link to post
5 hours ago, Air4141841 said:

I had used air on pfsense for years and never experienced anything of what you are talking about.. the monitoring server is the default gateway/ gateway address of the Tunnel it’s connected too 


Then maybe it is something in my connection, although I can not think on what, maybe the server I am connecting to, maybe something between the two. I just though explaining what worked for me might help someone.

Share this post


Link to post

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.
Note: Your post will require moderator approval before it will be visible.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

Loading...
  • Security Check
    Play CAPTCHA Audio
    Refresh Image

×
×
  • Create New...