Skip to content

Private Internet Access updated servers give TLS Error: TLS key negotiation failed to occur within 60 seconds #3288

Description

@jonasflataas

Is this urgent?

Yes

Host OS

Proxmox running Docker LXC with portainer

CPU arch

x86_64

VPN service provider

Private Internet Access

What are you using to run the container

Portainer

What is the version of Gluetun

Running version latest built on 2026-04-08T15:11:45.399Z (commit 2006fae) on Linux 6.17.4-2-pve (x86_64)

What's the problem 🤔

I've been running v3.35.0 for months without any issues and all of a sudden I started experiencing issues with the vpn / port forwarding.

I have updated the server lists and still no change.

Share your logs (at least 10 lines)

========================================
========================================
=============== gluetun ================
========================================
=========== Made with ❤️ by ============
======= https://github.com/qdm12 =======
========================================
========================================
Running version latest built on 2026-04-08T15:11:45.399Z (commit 2006fae) on Linux 6.17.4-2-pve (x86_64)
📣 Set BORINGPOLL_GLUETUNCOM=on to help combat AI slop and shutdown that scam website
🔧 Need help? ☕ Discussion? https://github.com/qdm12/gluetun/discussions/new/choose
🐛 Bug? ✨ New feature? https://github.com/qdm12/gluetun/issues/new/choose
💻 Email? quentin.mcgaw@gmail.com
💰 Help me? https://www.paypal.me/qmcgaw https://github.com/sponsors/qdm12
2026-04-16T19:01:35+02:00 INFO [routing] default route found: interface eth0, gateway 172.18.0.1, assigned IP 172.18.0.2 and family v4
2026-04-16T19:01:35+02:00 INFO [routing] local ethernet link found: eth0
2026-04-16T19:01:35+02:00 INFO [routing] local ipnet found: 172.18.0.0/16
2026-04-16T19:01:35+02:00 INFO [firewall] enabling...
2026-04-16T19:01:36+02:00 INFO [firewall] enabled successfully
2026-04-16T19:01:36+02:00 INFO [storage] merging by most recent 20646 hardcoded servers and 20653 servers read from /gluetun/servers.json
2026-04-16T19:01:36+02:00 INFO [storage] Using private internet access servers from file which are 113 days more recent
2026-04-16T19:01:36+02:00 INFO Alpine version: 3.23.3
2026-04-16T19:01:36+02:00 INFO OpenVPN version: 2.6.16
2026-04-16T19:01:36+02:00 INFO Firewall version: iptables v1.8.11
2026-04-16T19:01:36+02:00 INFO Settings summary:
├── VPN settings:
|   ├── VPN provider settings:
|   |   ├── Name: private internet access
|   |   ├── Server selection settings:
|   |   |   ├── VPN type: openvpn
|   |   |   ├── Regions: norway
|   |   |   ├── Port forwarding only servers: yes
|   |   |   └── OpenVPN server selection settings:
|   |   |       ├── Protocol: UDP
|   |   |       └── Private Internet Access encryption preset: strong
|   |   └── Automatic port forwarding settings:
|   |       ├── Redirection listening port: disabled
|   |       ├── Use port forwarding code for current provider
|   |       ├── Forwarded port file path: /tmp/gluetun/forwarded_port
|   |       └── Credentials:
|   |           ├── Username: ********
|   |           └── Password: ******
|   ├── OpenVPN settings:
|   |   ├── OpenVPN version: 2.6
|   |   ├── User: [set]
|   |   ├── Password: [set]
|   |   ├── Private Internet Access encryption preset: strong
|   |   ├── Network interface: tun0
|   |   ├── Run OpenVPN as: root
|   |   └── Verbosity level: 1
|   └── Path MTU discovery:
|       ├── ICMP addresses:
|       |   ├── 1.1.1.1
|       |   └── 8.8.8.8
|       └── TCP addresses:
|           ├── 1.1.1.1:443
|           ├── 8.8.8.8:443
|           ├── 1.1.1.1:53
|           ├── 8.8.8.8:53
|           ├── [2606:4700:4700::1111]:53
|           ├── [2001:4860:4860::8888]:53
|           ├── [2606:4700:4700::1111]:443
|           └── [2001:4860:4860::8888]:443
├── DNS settings:
|   ├── Upstream resolver type: dot
|   ├── Upstream resolvers:
|   |   └── Cloudflare
|   ├── Caching: yes
|   ├── IPv6: no
|   ├── Update period: every 24h0m0s
|   └── DNS filtering settings:
|       ├── Block malicious: yes
|       ├── Block ads: no
|       └── Block surveillance: no
├── Firewall settings:
|   ├── Enabled: yes
|   ├── Iptables settings:
|   |   └── Log level: info
|   └── Outbound subnets:
|       └── 192.168.1.0/24
├── Log settings:
|   └── Log level: info
├── IPv6 settings:
|   └── Check addresses:
|       ├── [2001:4860:4860::8888]:53
|       └── [2606:4700:4700::1111]:53
├── Health settings:
|   ├── Server listening address: 127.0.0.1:9999
|   ├── Target addresses:
|   |   ├── cloudflare.com:443
|   |   └── github.com:443
|   ├── Small health check type: ICMP echo request
|   |   └── ICMP target IPs:
|   |       ├── 1.1.1.1
|   |       └── 8.8.8.8
|   └── Restart VPN on healthcheck failure: yes
├── Shadowsocks server settings:
|   └── Enabled: no
├── HTTP proxy settings:
|   └── Enabled: no
├── Control server settings:
|   ├── Listening address: :8000
|   ├── Logging: yes
|   └── Authentication file path: /gluetun/auth/config.toml
├── Storage settings:
|   └── Filepath: /gluetun/servers.json
├── OS Alpine settings:
|   ├── Process UID: 1000
|   ├── Process GID: 10000
|   └── Timezone: europe/oslo
├── Public IP settings:
|   ├── IP file path: /tmp/gluetun/ip
|   ├── Public IP data base API: ipinfo
|   └── Public IP data backup APIs:
|       ├── ifconfigco
|       ├── ip2location
|       └── cloudflare
└── Version settings:
    └── Enabled: yes
2026-04-16T19:01:36+02:00 INFO [routing] default route found: interface eth0, gateway 172.18.0.1, assigned IP 172.18.0.2 and family v4
2026-04-16T19:01:36+02:00 INFO [routing] adding route for 0.0.0.0/0
2026-04-16T19:01:36+02:00 INFO [firewall] setting allowed subnets...
2026-04-16T19:01:36+02:00 INFO [routing] default route found: interface eth0, gateway 172.18.0.1, assigned IP 172.18.0.2 and family v4
2026-04-16T19:01:36+02:00 INFO [routing] adding route for 192.168.1.0/24
2026-04-16T19:01:36+02:00 INFO [healthcheck] listening on 127.0.0.1:9999
2026-04-16T19:01:36+02:00 INFO [http server] http server listening on [::]:8000
2026-04-16T19:01:36+02:00 INFO [firewall] allowing VPN connection...
2026-04-16T19:01:36+02:00 INFO [openvpn] OpenVPN 2.6.16 x86_64-alpine-linux-musl [SSL (OpenSSL)] [LZO] [LZ4] [EPOLL] [MH/PKTINFO] [AEAD]
2026-04-16T19:01:36+02:00 INFO [openvpn] library versions: OpenSSL 3.5.5 27 Jan 2026, LZO 2.10
2026-04-16T19:01:36+02:00 INFO [openvpn] TCP/UDP: Preserving recently used remote address: [AF_INET]158.173.166.73:1197
2026-04-16T19:01:36+02:00 INFO [openvpn] UDPv4 link local: (not bound)
2026-04-16T19:01:36+02:00 INFO [openvpn] UDPv4 link remote: [AF_INET]158.173.166.73:1197
2026-04-16T19:02:36+02:00 WARN [openvpn] TLS Error: TLS key negotiation failed to occur within 60 seconds (check your network connectivity)
🚒🚒🚒🚒🚒🚨🚨🚨🚨🚨🚨🚒🚒🚒🚒🚒
That error usually happens because either:
1. The VPN server IP address you are trying to connect to is no longer valid 🔌
   Check out https://github.com/qdm12/gluetun-wiki/blob/main/setup/servers.md#update-the-vpn-servers-list
2. The VPN server crashed 💥, try changing your VPN servers filtering options such as SERVER_REGIONS
3. Your Internet connection is not working 🤯, ensure it works
4. Something else ➡️ https://github.com/qdm12/gluetun/issues/new/choose
2026-04-16T19:02:36+02:00 INFO [openvpn] TLS Error: TLS handshake failed
2026-04-16T19:02:36+02:00 INFO [openvpn] SIGTERM received, sending exit notification to peer
2026-04-16T19:02:36+02:00 INFO [openvpn] SIGTERM[soft,tls-error] received, process exiting
2026-04-16T19:02:36+02:00 INFO [vpn] retrying in 15s
2026-04-16T19:02:51+02:00 INFO [firewall] allowing VPN connection...
2026-04-16T19:02:51+02:00 INFO [openvpn] OpenVPN 2.6.16 x86_64-alpine-linux-musl [SSL (OpenSSL)] [LZO] [LZ4] [EPOLL] [MH/PKTINFO] [AEAD]
2026-04-16T19:02:51+02:00 INFO [openvpn] library versions: OpenSSL 3.5.5 27 Jan 2026, LZO 2.10
2026-04-16T19:02:51+02:00 INFO [openvpn] TCP/UDP: Preserving recently used remote address: [AF_INET]158.173.166.73:1197
2026-04-16T19:02:51+02:00 INFO [openvpn] UDPv4 link local: (not bound)
2026-04-16T19:02:51+02:00 INFO [openvpn] UDPv4 link remote: [AF_INET]158.173.166.73:1197
2026-04-16T19:03:51+02:00 WARN [openvpn] TLS Error: TLS key negotiation failed to occur within 60 seconds (check your network connectivity)
🚒🚒🚒🚒🚒🚨🚨🚨🚨🚨🚨🚒🚒🚒🚒🚒
That error usually happens because either:
1. The VPN server IP address you are trying to connect to is no longer valid 🔌
   Check out https://github.com/qdm12/gluetun-wiki/blob/main/setup/servers.md#update-the-vpn-servers-list
2. The VPN server crashed 💥, try changing your VPN servers filtering options such as SERVER_REGIONS
3. Your Internet connection is not working 🤯, ensure it works
4. Something else ➡️ https://github.com/qdm12/gluetun/issues/new/choose
2026-04-16T19:03:51+02:00 INFO [openvpn] TLS Error: TLS handshake failed
2026-04-16T19:03:51+02:00 INFO [openvpn] SIGTERM received, sending exit notification to peer
2026-04-16T19:03:51+02:00 INFO [openvpn] SIGTERM[soft,tls-error] received, process exiting
2026-04-16T19:03:51+02:00 INFO [vpn] retrying in 15s
2026-04-16T19:04:06+02:00 INFO [firewall] allowing VPN connection...
2026-04-16T19:04:06+02:00 INFO [openvpn] OpenVPN 2.6.16 x86_64-alpine-linux-musl [SSL (OpenSSL)] [LZO] [LZ4] [EPOLL] [MH/PKTINFO] [AEAD]
2026-04-16T19:04:06+02:00 INFO [openvpn] library versions: OpenSSL 3.5.5 27 Jan 2026, LZO 2.10
2026-04-16T19:04:06+02:00 INFO [openvpn] TCP/UDP: Preserving recently used remote address: [AF_INET]158.173.166.163:1197
2026-04-16T19:04:06+02:00 INFO [openvpn] UDPv4 link local: (not bound)
2026-04-16T19:04:06+02:00 INFO [openvpn] UDPv4 link remote: [AF_INET]158.173.166.163:1197
2026-04-16T19:05:06+02:00 WARN [openvpn] TLS Error: TLS key negotiation failed to occur within 60 seconds (check your network connectivity)
🚒🚒🚒🚒🚒🚨🚨🚨🚨🚨🚨🚒🚒🚒🚒🚒
That error usually happens because either:
1. The VPN server IP address you are trying to connect to is no longer valid 🔌
   Check out https://github.com/qdm12/gluetun-wiki/blob/main/setup/servers.md#update-the-vpn-servers-list
2. The VPN server crashed 💥, try changing your VPN servers filtering options such as SERVER_REGIONS
3. Your Internet connection is not working 🤯, ensure it works
4. Something else ➡️ https://github.com/qdm12/gluetun/issues/new/choose
2026-04-16T19:05:06+02:00 INFO [openvpn] TLS Error: TLS handshake failed
2026-04-16T19:05:06+02:00 INFO [openvpn] SIGTERM received, sending exit notification to peer
2026-04-16T19:05:06+02:00 INFO [openvpn] SIGTERM[soft,tls-error] received, process exiting
2026-04-16T19:05:06+02:00 INFO [vpn] retrying in 15s
2026-04-16T19:05:21+02:00 INFO [firewall] allowing VPN connection...
2026-04-16T19:05:21+02:00 INFO [openvpn] OpenVPN 2.6.16 x86_64-alpine-linux-musl [SSL (OpenSSL)] [LZO] [LZ4] [EPOLL] [MH/PKTINFO] [AEAD]
2026-04-16T19:05:21+02:00 INFO [openvpn] library versions: OpenSSL 3.5.5 27 Jan 2026, LZO 2.10
2026-04-16T19:05:21+02:00 INFO [openvpn] TCP/UDP: Preserving recently used remote address: [AF_INET]158.173.166.10:1197
2026-04-16T19:05:21+02:00 INFO [openvpn] UDPv4 link local: (not bound)
2026-04-16T19:05:21+02:00 INFO [openvpn] UDPv4 link remote: [AF_INET]158.173.166.10:1197
2026-04-16T19:06:21+02:00 WARN [openvpn] TLS Error: TLS key negotiation failed to occur within 60 seconds (check your network connectivity)
🚒🚒🚒🚒🚒🚨🚨🚨🚨🚨🚨🚒🚒🚒🚒🚒
That error usually happens because either:
1. The VPN server IP address you are trying to connect to is no longer valid 🔌
   Check out https://github.com/qdm12/gluetun-wiki/blob/main/setup/servers.md#update-the-vpn-servers-list
2. The VPN server crashed 💥, try changing your VPN servers filtering options such as SERVER_REGIONS
3. Your Internet connection is not working 🤯, ensure it works
4. Something else ➡️ https://github.com/qdm12/gluetun/issues/new/choose
2026-04-16T19:06:21+02:00 INFO [openvpn] TLS Error: TLS handshake failed
2026-04-16T19:06:21+02:00 INFO [openvpn] SIGTERM received, sending exit notification to peer
2026-04-16T19:06:21+02:00 INFO [openvpn] SIGTERM[soft,tls-error] received, process exiting
2026-04-16T19:06:21+02:00 INFO [vpn] retrying in 15s
2026-04-16T19:06:36+02:00 INFO [firewall] allowing VPN connection...
2026-04-16T19:06:36+02:00 INFO [openvpn] OpenVPN 2.6.16 x86_64-alpine-linux-musl [SSL (OpenSSL)] [LZO] [LZ4] [EPOLL] [MH/PKTINFO] [AEAD]
2026-04-16T19:06:36+02:00 INFO [openvpn] library versions: OpenSSL 3.5.5 27 Jan 2026, LZO 2.10
2026-04-16T19:06:36+02:00 INFO [openvpn] TCP/UDP: Preserving recently used remote address: [AF_INET]158.173.166.47:1197
2026-04-16T19:06:36+02:00 INFO [openvpn] UDPv4 link local: (not bound)
2026-04-16T19:06:36+02:00 INFO [openvpn] UDPv4 link remote: [AF_INET]158.173.166.47:1197
2026-04-16T19:06:36+02:00 INFO [openvpn] [Server-11800-3a] Peer Connection Initiated with [AF_INET]158.173.166.47:1197
2026-04-16T19:06:36+02:00 INFO [openvpn] TUN/TAP device tun0 opened
2026-04-16T19:06:36+02:00 INFO [openvpn] /sbin/ip link set dev tun0 up mtu 1500
2026-04-16T19:06:36+02:00 INFO [openvpn] /sbin/ip link set dev tun0 up
2026-04-16T19:06:36+02:00 INFO [openvpn] /sbin/ip addr add dev tun0 10.242.0.37/16 broadcast +
2026-04-16T19:06:36+02:00 INFO [openvpn] UID set to nonrootuser
2026-04-16T19:06:36+02:00 INFO [openvpn] Initialization Sequence Completed
2026-04-16T19:06:36+02:00 INFO [MTU discovery] finding maximum MTU, this can take up to 6 seconds
2026-04-16T19:06:37+02:00 INFO [MTU discovery] setting VPN interface tun0 MTU to maximum valid MTU 1258
2026-04-16T19:06:37+02:00 INFO [dns] DNS server listening on [::]:53
2026-04-16T19:06:37+02:00 INFO [dns] ready and using DNS server with dot upstream resolvers
2026-04-16T19:06:37+02:00 INFO [dns] downloading hostnames and IP block lists
2026-04-16T19:06:39+02:00 INFO [dns] leak check report: 172.64.210.29 (60%), 162.158.221.108 (40%)
2026-04-16T19:06:39+02:00 INFO [ip getter] Public IP address is 158.173.166.126 (Norway, Oslo, Oslo - source: ipinfo+ifconfig.co+ip2location+cloudflare)
2026-04-16T19:06:39+02:00 INFO [vpn] You are running 2 commits behind the most recent latest
2026-04-16T19:06:39+02:00 INFO [port forwarding] starting
2026-04-16T19:06:44+02:00 ERROR [vpn] starting port forwarding service: port forwarding for the first time: refreshing port forward data: fetching port forwarding data: obtaining signature payload: Get "https://10.242.128.1:19999/getSignature?token=<token>": context deadline exceeded

Share your configuration

networks:
  media-network:
    name: media-network
    driver: bridge

services:
  gluetun:
    image: qmcgaw/gluetun:latest
    container_name: gluetun
    cap_add:
      - NET_ADMIN
    devices:
      - /dev/net/tun:/dev/net/tun
    ports:
      - 8112:8112
      - 9696:9696
    volumes:
      - ${FOLDER_FOR_CONFIGS:?err}/gluetun:/gluetun
    environment:
      - PUID=${PUID:?err}
      - PGID=${PGID:?err}
      - TZ=${TIMEZONE:?err}
      - VPN_SERVICE_PROVIDER=${VPN_SERVICE_PROVIDER:?err}
      - SERVER_REGIONS=Norway
      - OPENVPN_USER=${VPN_USERNAME}
      - OPENVPN_PASSWORD=${VPN_PASSWORD}
      - FIREWALL_OUTBOUND_SUBNETS=${LOCAL_SUBNET:?err}
      - PORT_FORWARD_ONLY=true
      - VPN_PORT_FORWARDING=on

    healthcheck:
      test: ping -c 1 www.google.com || exit 1
      interval: 60s
      timeout: 20s
      retries: 5
    restart: unless-stopped
    networks:
      - media-network


  deluge:
    image: lscr.io/linuxserver/deluge:latest
    container_name: deluge
    restart: unless-stopped
    volumes:
      - ${FOLDER_FOR_CONFIGS:?err}/deluge:/config
      - ${FOLDER_FOR_MEDIA:?err}:/mnt/data
    labels:
      - deunhealth.restart.on.unhealthy= "true"
    environment:
      - PUID=${PUID:?err}
      - PGID=${PGID:?err}
      - TZ=${TIMEZONE:?err}
    network_mode: service:gluetun
    healthcheck:
        test: ping -c 1 www.google.com || exit 1
        interval: 60s
        retries: 3
        start_period: 20s
        timeout: 10s

  prowlarr:
    image: lscr.io/linuxserver/prowlarr:latest
    container_name: prowlarr
    labels:
      - deunhealth.restart.on.unhealthy= "true"
    environment:
      - PUID=${PUID:?err}
      - PGID=${PGID:?err}
      - TZ=${TIMEZONE:?err}
    volumes:
     - ${FOLDER_FOR_CONFIGS:?err}/prowlarr/data:/config
     - ${FOLDER_FOR_MEDIA:?err}:/mnt/media_root
    restart: unless-stopped
    network_mode: service:gluetun
    healthcheck:
        test: ping -c 1 www.google.com || exit 1
        interval: 60s
        retries: 3
        start_period: 20s
        timeout: 10s

  deunhealth:
    image: qmcgaw/deunhealth
    container_name: deunhealth
    network_mode: "none"
    environment:
      - LOG_LEVEL=info
      - HEALTH_SERVER_ADDRESS=127.0.0.1:9999
      - TZ=Europe/Oslo
    restart: always
    volumes:
      - /var/run/docker.sock:/var/run/docker.sock

Environment variables

COMPOSE_PROJECT_NAME=media-stack
LOCAL_SUBNET=192.168.1.0/24
FOLDER_FOR_CONFIGS=/mnt/data/app_config
FOLDER_FOR_MEDIA=/mnt/data
PUID=1000
PGID=10000
TIMEZONE=Europe/Oslo
VPN_SERVICE_PROVIDER=private internet access
VPN_USERNAME=
VPN_PASSWORD=

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions