• Encrypted connection between Gateway and "double NAT" pfSense?

    16
    0 Votes
    16 Posts
    2k Views
    RicoR
    Segmentation is not stupid, but do it the right way. ;-) -Rico
  • OpenVPN gateway monitoring shows offline until forced save

    12
    0 Votes
    12 Posts
    2k Views
    kesawiK
    Did you manage to resolve it? I've been having the identical issue with my pfSense install for a while as well. Currently running version 2.4.4-RELEASE-p2.
  • openvpn site-to-site between netgate appliance to azure pfsense instance

    4
    0 Votes
    4 Posts
    1k Views
    ?
    hi chris, I am new to linux and pfsense so I fumbled around but then I found the status->systems.logs and noticed this "Bad compression stub (swap) decompression header byte: 42 " so I changed the compression on the openvpn client to match the openvpn server and shazaam, it worked. now I have a new problem. from the server/negate.sg110 web interface I can ping virtual computers behind the azure.pfsense from the azure.pfsense.client web interface, I can ping physical computers behind my netgate sg1110. however, I cannot ping from a physical computer behind my netgate to a virtual computer behind the azure pfsense I cannot ping from a virtual computer behind azure pfsense to a physical computer behind my netgate.sg1110 I thought that since I had added the correct "IPv4 Remote network" on the server and client, that I should be able to ping from computer to computer. do I need a add a manual route somehow and if so, how might I do that? or what do you suggest? thanks very much, david
  • OpenVPN between pfSense and Ubiquiti EdgeRouter X

    6
    0 Votes
    6 Posts
    2k Views
    I
    @sam721 said in OpenVPN between pfSense and Ubiquiti EdgeRouter X: the Ubiquiti? Are you familiar with firewall rules on the EdgeRouter? I don't know which rule is needed. I'm not familiar with how to set firewall rules on an ubiquiti edge router. The rule youre going to need though is to allow the pfsense lan subnet to talk to the ubiquiti subnet. I'd also ensure NAT is NOT enabled for either side, so you can see the subnet IP's. This isnt a need as much as its a nice to have in case you ever need to figure out which specific client on one of those is misbehaving.
  • Changing the Tunnel Network on OpenVPN connection

    6
    0 Votes
    6 Posts
    751 Views
    RicoR
    Glad you have it working now. -Rico
  • OpenVPN without WAN VPN Provider

    6
    0 Votes
    6 Posts
    760 Views
    RicoR
    Yes this could be the problem. Years ago we had some SHDSL line as spare with cisco router from the ISP. The cisco was totally managed by the ISP with no access for us. For any changes like port forwadings we need to open a ticket... -Rico
  • Azure Pfsense Access to OpenVPN clients from LAN

    2
    0 Votes
    2 Posts
    449 Views
    I
    Best practices here would recommend implementing as strict a rule as is necessary. Perhaps a deny all to those vpn networks, and place rules above this for the protocols/services/destinations you need?
  • Can OpenVPN be implemented without WAN Provider?

    1
    0 Votes
    1 Posts
    161 Views
    No one has replied
  • Pfsense OpenVPN PIA Auth_Failed

    3
    0 Votes
    3 Posts
    1k Views
    S
    well i see that, but i set it up according to the settings. I will look into it sorry.
  • remote OpenVPN-client LAN not reachable

    23
    0 Votes
    23 Posts
    7k Views
    S
    @johnpoz said in remote OpenVPN-client LAN not reachable: @sgw said in remote OpenVPN-client LAN not reachable: redirect-gateway def1 Why are you redirecting gateway? That is normally not done in a site to site setup. A leftover from my desparate debugging. Thanks for spotting, disabled it now (was in the CSO).
  • 0 Votes
    5 Posts
    1k Views
    G
    On closer inspection, it appears that the problem is certain assets dropping any request coming from outside their assigned address range. This appears to be a crude and problematic security "feature" and has been brought up with the manufacturer. If I can verify, I'll mark this is solved. it may be necessary to configure as peer-peer and put each connecting client in the address range of the LAN, which, given we're using a class A as a classification system, there's plenty of class C ranges not internally assigned. Will update with any progress.
  • Issue with Openvpn Reconnect?

    15
    0 Votes
    15 Posts
    2k Views
    johnpozJ
    UDP should be better yeah - unless you can not get to it, then is useless ;) Takes nothing more than some simple setup to run both. And if you configure the client settings correctly - it will first try your UDP connection, and if can not connect it will then try TCP.
  • Automate certificat generation

    1
    0 Votes
    1 Posts
    201 Views
    No one has replied
  • VPN client works, local Lan access doesn't

    2
    0 Votes
    2 Posts
    368 Views
    RicoR
    https://www.netgate.com/resources/videos/openvpn-as-a-wan-on-pfsense.html -Rico
  • VPN works great except when I using Skype/Messenger on audio/video calls

    1
    0 Votes
    1 Posts
    181 Views
    No one has replied
  • newbie, how to lock openvpn user to certain ipaddresses on the lan

    5
    0 Votes
    5 Posts
    615 Views
    ?
    @emammadov thanks
  • Interface opvnc not appear on openVPN client connection

    5
    0 Votes
    5 Posts
    663 Views
    RicoR
    Share your OpenVPN Client settings (screenshots). -Rico
  • openvpn 86125 RESOLVE: Cannot resolve host address:

    2
    0 Votes
    2 Posts
    2k Views
    RicoR
    In Diagnostics -> DNS Lookup you can resolve this express vpn host or not? -Rico
  • OpenVPN acts as default Gateway. Why?

    4
    0 Votes
    4 Posts
    2k Views
    D
    @abadonna your link is down can you send me your tutorial. I'm trying to setup Secuirtykiss
  • only one user account works with openvpn

    14
    0 Votes
    14 Posts
    2k Views
    L
    i had it on authentication only in the open vpn server, now users are showing up for export, you nailed it thank you so much!
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.