• Problem with OpenVPN Client Export on pfSense 2.0-RC1 (i386)

    Locked
    3
    0 Votes
    3 Posts
    8k Views
    D

    Yes, that's it! All the Certificates were corrupt… strange.  ???
    But now with the new certificate the Client Export Tool works perfect.

    Thank you very much...  :)

  • User auth question

    Locked
    2
    0 Votes
    2 Posts
    2k Views
    jimpJ

    It should be "good enough" in most cases, though you don't get the extra security of the certificates.

    The User Auth only still uses a tls key in addition to user auth, so it's still secure.

    I think there is an open ticket somewhere to open that up so that it can be used for other auth methods. It would just require making the certs in the cert manager (or elsewhere) manually instead of them being tied directly to user accounts as they are with Local auth.

  • OpenVPN failover…

    Locked
    1
    0 Votes
    1 Posts
    2k Views
    No one has replied
  • OpenVPN Interface: any

    Locked
    6
    0 Votes
    6 Posts
    4k Views
    jimpJ

    Yeah there have been some UDP issues in the past where the return traffic will use the default gateway regardless of the interface used for connecting when using 'any' interface, though I haven't tried that lately on 2.0 so I'm not sure if that's really an issue these days.

    Binding to LAN and forwarding ports lets it take advantage of pf's reply-to directive which ensures the traffic goes back out the WAN it came in on.

  • Server-bridge on 2.0

    Locked
    1
    0 Votes
    1 Posts
    2k Views
    No one has replied
  • HOWTO Road Warrior to remote Subnet on LAN

    Locked
    12
    0 Votes
    12 Posts
    5k Views
    ?

    I've just tested using a 3G modem and works perfectly, I can reach any service available to LAN users form OpenVPN Users.

    Thanks for your help

  • Dh1024.pem is located where in PFENSE2

    Locked
    4
    0 Votes
    4 Posts
    4k Views
    jimpJ

    Please start a new thread for a new issue, so it's easier for others to find and contribute.

  • OVPN Multi-user Filter

    Locked
    5
    0 Votes
    5 Posts
    3k Views
    D

    That worked perfectly!

    I just tested the setup you suggested with 3 test users and had filtering working exactly the way I want.

    Thanks for the help!

  • Road Warrior on Class A Network

    Locked
    5
    0 Votes
    5 Posts
    2k Views
    M

    It can be done, but it involves using client bridging and adding custom configs to the server.

    Stick with the routed solution, it's more efficient and it looks like they are eliminating bridging from 2.0 anyway.

  • OpenVPN + Squid (transparant) not working?

    Locked
    4
    0 Votes
    4 Posts
    3k Views
    W

    What eventually fixed it for me was swapping the openVPN protocol from UDP to TCP. Up to this day this still makes NO sense to me whatsoever as it all worked though UDP as long as I did't leave the LAN. Accessing remote websites as an openVPN client jsut didnt work using the UDP protocol.

    I made a small post on my blog explaining the steps I took to get it working. URL : http://henri.kuipersite.nl/2011/02/25/the-alix-project-part-2/

    I hope this will give you enough info to get it working for you too. If not (or if it does) let me know via a reply here and/or a little note at the blog :)

    Happy VPNing

  • PfSense to Endian Community Edition FW

    Locked
    2
    0 Votes
    2 Posts
    3k Views
    R

    no takers?

    -Rich

  • Is it possible to tunnel all traffic over OpenVPN [SOLVED]?

    Locked
    17
    0 Votes
    17 Posts
    25k Views
    C

    sweet! Good to hear

  • D-link firewall and pfsense/openvpn in parallel?

    Locked
    4
    0 Votes
    4 Posts
    3k Views
    R

    Is this true even if the openVPN is setup in bridged mode?

    I can't speak to Bridge mode as I've never tried it, but theoretically then your clients would be on the same IP network so I would say no it probably wouldn't be true for that scenario.  I don't think pfSense has bridge mode as an option out of the box but you might be able to configure that using the custom options field.

    Yes, it is true that my Internet connection is only 100 Mbit. However, the network between LAN and DMZ is at Gbit speed today. I don't want LAN/DMZ communications to be affected negatively.

    Well….. pfSense runs on a PC, can you use Gbit NICs?  Or are you running it on an embedded device?

    -Rich

  • OpenVPN assigning incorrect subnet mask

    Locked
    7
    0 Votes
    7 Posts
    6k Views
    R

    @jimp:

    Client should have dev tun, not dev tap.

    It's always the simple things - that did it!  Thanks!

    -Rich

  • OpenVpn Dual Lan Issue

    Locked
    5
    0 Votes
    5 Posts
    2k Views
    C

    huh, it's probably one of the ones with broken hardware checksum offloading under some circumstances, disabling that under System>Advanced would possibly resolve, but you're vastly better off with the Broadcom NIC anyway.  ;D

  • 0 Votes
    3 Posts
    1k Views
    C

    Okay…all updated to 1.2.3 now.

    Went through and changed some things back to how they were supposed to be according to the setup guide....and it's working now.
    Part of this though included having to use a WWAN card to make it so I was attempting to vpn in from the Internet....vs. from my own internal private network.  Apparently, that won't work. :)

  • Site to site Connect. No ping

    Locked
    5
    0 Votes
    5 Posts
    2k Views
    D

    I check that ipsec was disabled, and delete another vpn server that one box haves (to roadwarrior) and now i can ping :s but cant enter in any service of the other net (a webserver and the pfsense itself)

    I have this firewall rules in vpn in both sites:

    rules.PNG
    rules.PNG_thumb

  • OpenVPN site to site connection dropping/hanging

    Locked
    2
    0 Votes
    2 Posts
    2k Views
    jimpJ

    Look in the system logs and the logs for OpenVPN. You may find an error in one or the other that leads you to the cause of the issue.

    Otherwise it's all just speculation.

  • Server certificate verification

    Locked
    8
    0 Votes
    8 Posts
    17k Views
    Cry HavokC

    @spiritbreaker, your error messages is not the same as the one being discussed in this thread, please don't confuse matters.

  • Multiple configs of OVPN possible?

    Locked
    4
    0 Votes
    4 Posts
    2k Views
    jimpJ

    Anything from 0-255 should work in that octet. So 192.168.42.x, 192.168.201.x, etc, etc. Whatever you want that isn't in use.

Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.