• Change Default TTL for openvpn clients

    1
    0 Votes
    1 Posts
    211 Views
    No one has replied
  • how to route openvpn tunnel traffic through squid proxy server?

    9
    0 Votes
    9 Posts
    3k Views
    V

    @umm12 said in how to route openvpn tunnel traffic through squid proxy server?:

    but i have port 6000 for squid proxy server. I do not use this port on Remote networks on client side of Pf-1???

    So you want to use the proxy in transparent mode, but on port 6000?
    I‘m not really family with proxying, but don’t think it can work this way. Maybe it does when you forward the traffic to port 6000 on pf1.

  • how to prevent to discover and scan other connected openvpn clients?

    5
    0 Votes
    5 Posts
    648 Views
    U

    @johnpoz
    I using layer 3 tunnel mode.
    How i can disable arp on openvpn clients in pfSense?

  • Azure Vnet to pfSense client OpenVPN

    1
    0 Votes
    1 Posts
    240 Views
    No one has replied
  • FreeRADIUS+OpenVPN

    2
    0 Votes
    2 Posts
    403 Views
    A

    @abracadabras The problem is solved. I have several CA, I had to choose the FreeRADIUS CA certificate in the OpenVPN setup.

  • DNS problems vor connected clients having dual stack ipv4/v6

    10
    0 Votes
    10 Posts
    1k Views
    johnpozJ

    @heiko-ecm4u said in DNS problems vor connected clients having dual stack ipv4/v6:

    office has only a ipv4 had no need until now ...

    Prob be that way for 10+ more years at least if not longer.. Until such time that major players go IPv6 only - offices have little need of IPv6 to be honest.

  • 0 Votes
    6 Posts
    674 Views
    Bob.DigB

    @gertjan Yes. The reason is to use the always-on vpn-feature in android and not manually have to to anything for a vpn connection at anytime. Also OpenVPN for Android works as an app firewall, so I can block apps to access the internet at anytime.

  • Communication between one hosts on OpenVPN isolated

    2
    0 Votes
    2 Posts
    493 Views
    V

    @fuxxik
    pfSense cannot control the traffic between OpenVPN clients, this happens within OpenVPN and here you only can allow all inter-client communication or not.

    To achieve what you want, you will have to set up an additional OpenVPN server on pfSense for that specific client. This way the traffic to this client has to pass pfSense and you can control it by filter rules.

  • Will the recent openssl vulnerabilities affect OpenVPN?

    1
    0 Votes
    1 Posts
    213 Views
    No one has replied
  • Pfsense VPN Support for Okta 2FA

    2
    0 Votes
    2 Posts
    918 Views
    S

    Is there any information available on adding Okta 2FA? This could be a deal breaker for out continued purchase of pfsense licenses.

  • Pulling Remote Certificate Revocation List

    2
    0 Votes
    2 Posts
    498 Views
    S

    Is there any information available on remote pulling CRLs? This could be a deal breaker for out continued purchase of pfsense licenses.

  • Traffic arriving on OpenVPN interface not being routed forward

    7
    0 Votes
    7 Posts
    1k Views
    P

    I've run into a similar issue, also having many other instances working in the field.

    The problem that I can see is that the iroute works, within the openvpn space, but the OS underlay is not adding the route, so traffic doesn't go back.

    If you raise the log level to 6 and grab the logs, you'll see if your iroute gets installed, then ssh into the pfsense os and perform netstat -rn, you'll se if the OS has the route.

    Still haven't found a solution myself.

  • how to hide connection information in openvpn?

    12
    0 Votes
    12 Posts
    2k Views
    NogBadTheBadN

    Split tunnel maybe ?

  • How to layer 2 OpenVPN site to site setup

    3
    0 Votes
    3 Posts
    655 Views
    U

    @marvosa hi dear friend.
    I have different services like monitoring and others that needs to be in two different VM, so I need my users traffic to pass from two nodes With full tunnel remote access server I can only pass my traffic through one node. I also need my connection to be layer two connection.
    I uploaded full config of my pfsense-1 and pfSense-2.please see them and help me.
    I want to connect pfSense-1 with layer 2 tap mode and then because pfsense-1 and pfsense-2 conncted with layer 2 tap mode site to site therefore i will using pfsense-2 ip address that for example when i checking my ip address on https://myip.ms website, i pfsense-2 ip address.
    5.PNG

    7.PNG 6.PNG 5.PNG 4.PNG 3.PNG 2.PNG 1.PNG 9.PNG 8.PNG

    5.PNG 4.PNG 3.PNG 2.PNG 1.PNG

  • What's the difference between route and push route?

    2
    0 Votes
    2 Posts
    286 Views
    GertjanG

    @ipguy

    That's a openvpn thing, and thus a openvpn question.
    You can find these on the openvpn forum. I found one for you.
    Also have a look at the openvpn "manual".

  • 0 Votes
    6 Posts
    611 Views
    johnpozJ

    @valk said in All traffic behind pfsense is being routed through VPN. How can a client opt out?:

    So I want to be able to do it from the client side

    Then run your vpn on your client..

  • Site to site - client route not installed on server

    3
    0 Votes
    3 Posts
    422 Views
    P

    So, installing a static route manually in the OS makes the thing work.

    A bit stuck now, feels like the knobs are not doing what they should.

  • OpenVPN and long distance tunnels

    5
    0 Votes
    5 Posts
    1k Views
    P

    Thanks for the reply.

    True, it is M-files we are running. I will do another attempt with them but so far it has been quite useless replies in any type of support request we have sent them.

    We will try the in-house web solution that is an option and see if it has the features we need or if we are forced to continue to run RDP from the locations that has too high RTT.

  • openvpn client configuration

    2
    0 Votes
    2 Posts
    428 Views
    G

    @gpeting

    Bump, just trying to get a response on with a sense of urgency. We have a Hurrican heading our way need to the the remote phones programed ASAP. Thanks in advance.

  • Why can't I use a /8 ?

    8
    0 Votes
    8 Posts
    757 Views
    johnpozJ

    @ipguy said in Why can't I use a /8 ?:

    the next remote network, 10.3.0.0/28
    the next remote network, 10.4.0.0/28

    I am with @JKnott here - this doesn't make a lot of sense..

    So you have a remote device.. And it has a /28 or even multiple /28s on the other end of it.. Ok what does that have to do with your tunnel network?

    How many devices are going to connect to the openvpn server? 8000? So your tunnel network would only need to support 8000 IPs.. So a /19 would allow for 8190 address - so if using subnet vs net 30, each modem would only being getting 1 IP for the tunnel.. So 8190 modems. What networks are on the other end of the tunnel has nothing to do with the tunnel network.. The tunnel network allows for how many clients can connect to that server.. Using a /16 tunnel would allow for 65k devices to connect.. Even using net30 addressing you would still have way more than enough for 8000 connections.

    Also with

    the next remote network, 10.3.0.0/28
    the next remote network, 10.4.0.0/28

    Your wasting a lot of space between those networks as mentioned.. Your using a whole /16 just to assign a /28... Think we are missing some info here.

    But you could route multiple network across your 1 IP used to connect for the tunnel..

    I think a better understanding of what your doing or wanting to do exactly.. How are these modems connecting to you now?

Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.