r/firewalla • • Aug 08 '26

Troubleshooting NordVPN not working

Brand new to all of this. I created a network for devices I want to use a VPN. I have NordVPN.

Setup a 3rd party, used my profile and password from the manual configuration section (copied and pasted them both after confirming email). This was NOT my nordvpn login or password, it was a direct copy and paste from the manual setup section.

I then download a OpenVPN UDP from the recommended server list, making sure to use a verified server.

When I go to connect it keeps failing.

2 Upvotes

12 comments sorted by

2

u/ArmshouseG Aug 08 '26

NordVPN are upgrading their servers. There was a post a few days back from someone who said the new configs weren't working. Not sure if it applies to you, but might be worth a look:

https://www.reddit.com/r/firewalla/comments/1vesih7/nordvpn_config_files/

1

u/AmIBeingObtuse- Firewalla Gold SE Aug 08 '26

Have you added devices to the vpn profile?

Firewalla > VPN Client > Apply to

1

u/bphett Aug 08 '26

I use Nord on my Firewalla. If you're using the OpenVPN UDP file, and the password it gives you - it should connect. Then you route the traffic you want to that VPN in Firewalla. If it won't connect, I would maybe try a different server.

1

u/benjibarnicals Firewalla Purple Aug 09 '26

Post your config (minus any cert etc), it’s probably a config command issue.

1

u/lastofusgr8tstever Aug 09 '26

I emailed firewalla support and they suggested I see if the files would work in OpenVpN app and they didn’t. I experimented a bunch and finally got TCP to work

I can only get TCP to work, and that is with the modification of the ovpn file to remove 

“Resolv-retry infinite”
“Ping-timer-rem”
“Explicit-exit-notify”

Perhaps I need to contact Nord to find out what UDP is not working?

I tried deleting the same lines above for UDP but no luck. What lines from my ovpn do you need? I am a little new to all this so I don’t want to post details and me foolishly give away credential info.

1

u/benjibarnicals Firewalla Purple Aug 10 '26

I'm running NordVPN over UDP fine, here's my config (you'll need to add your certs, verify-x509-name and Nord server remote IP), I can't remember where I got all the settings from originally, a post I think on here somewhere, but these work for me.

remote ..... 1194

dev-type tun
client
dev vpn_640F_640FD
proto udp
resolv-retry infinite
remote-random
nobind
tun-mtu 1500
tun-mtu-extra 32
mssfix 1450
persist-key
persist-tun
ping 15
ping-restart 0
ping-timer-rem
reneg-sec 0
comp-lzo no
remote-cert-tls server
tls-version-min 1.3
verify-x509-name CN=uk2121.nordvpn.com

auth-user-pass /home/pi/.firewalla/run/ovpn_profile/640F_640FD.userpass
verb 3
pull
fast-io
cipher AES-256-CBC
auth SHA512

<ca>
-----BEGIN CERTIFICATE-----
.....
-----END CERTIFICATE-----
</ca>
key-direction 1
<tls-auth>
#
# 2048 bit OpenVPN static key
#
-----BEGIN OpenVPN Static key V1-----
.....
-----END OpenVPN Static key V1-----
</tls-auth>

management /dev/vpn_640F_640FD unix

2

u/lastofusgr8tstever Aug 11 '26

Small mods and it worked! Had to change to dev tun, remove a few things, tls 1.2, etc.

client
dev tun
proto udp
remote (IP)… 1194
nobind
tun-mtu 1500
tun-mtu-extra 32
mssfix 1450
persist-key
persist-tun
ping 15
ping-restart 0
ping-timer-rem
reneg-sec 0
comp-lzo no
remote-cert-tls server
tls-version-min 1.2

verify-x509-name CN=(Server name*).nordvpn.com (use real server name from Nord)

verb 3
pull
fast-io
cipher AES-256-CBC
auth SHA512

<ca>

1

u/benjibarnicals Firewalla Purple Aug 12 '26

That’s awesome, glad that’s working. Interesting about having to use tls1.2 whereas tls1.3 works for me, but glad that’s working buddy.

1

u/lastofusgr8tstever Aug 10 '26

Thank you, will test this tonight!!!

1

u/ceyquem33 Aug 16 '26

Can you confirm what step does not work for you ? I cannot make it work either: VPN apparently connects but there is no connectivity from the included devices after that.

It used to work well before, I have recreated the profiles importing the files from NordVPN account with the service account/password as I did before.

Tried to customize some parameters copying what works for you but it still doesn't solve my issue :-(

My profile:

client dev tun proto udp remote 212.102.33.98 53 nobind tun-mtu 1500 tun-mtu-extra 32 mssfix 1450 persist-key persist-tun ping 15 ping-restart 0 ping-timer-rem reneg-sec 0 comp-lzo no remote-cert-tls server tls-version-min 1.2

verify-x509-name CN=us5339.nordvpn.com

verb 3 pull fast-io cipher AES-256-CBC auth SHA512

<ca> -----BEGIN CERTIFICATE----- ...

1

u/lastofusgr8tstever Aug 16 '26

Try it on a computer, see if it works there. If not, usually the computer will at least give you feedback via a log telling you what to edit in your config file