• Question about OpenVPN firewall rules

    9
    0 Votes
    9 Posts
    3k Views
    P
    Great - that helps sort things out for me.  I do have not rules on OpenVPN or PIA tabs.  Although I do have pass any rules on my VPN server interface tabs, since I am the only one who can connect to the Open VPN server and generate incoming traffic on those interfaces, I don't think passing all traffic should present a problem?
  • Hardening route/iptables behind OpenVPN?

    1
    0 Votes
    1 Posts
    992 Views
    No one has replied
  • PfSense as an OpenVPN client - LAN access to the server

    10
    0 Votes
    10 Posts
    3k Views
    D
    @divsys: Do you have the same "Allow any-any" rule on the OpenVPN tab of the pfSense server? Yes, I do. I've pretty much determined that what I'm trying to accomplish isn't possible. Now, I've noticed that if I connect to my VPS using SSH on the OpenVPN address [10.30.0.1], the SSH tunnel is originating from the OpenVPN address of my pfSense router [10.30.0.250] - if I could open ports/port forward on the pfSense OpenVPN address/interface, I could accomplish what I want [access to LAN resources on the OpenVPN server] but I haven't been successful at this either.
  • Can access LAN with OS X client but not with iOS client

    1
    0 Votes
    1 Posts
    556 Views
    No one has replied
  • VPN on a separate LAN?

    3
    0 Votes
    3 Posts
    2k Views
    S
    After a bit of struggle I got it working. It's been a crash course in certificates and stuff like that, I just couldn't get everything to line up properly. Most guides shows how easy it is to export vpn settings to a windows client, but I run linux and had to struggle some more. At one point I even swapped out the drive in my laptop to an old harddrive installed with windows - just to see it work - which it didn't.. Then I discovered that even though I've told my ISP supplied router/modem to fork over the entire connection and external ip to my pfsense box, believing that would make the router/modem function as a pure modem, for some peculiar reason the firewall in the router/modem were still active. I disabled that, leaving the firewall duties to pfsense and suddenly everything worked. I flopped the linux drive back into the laptop and whadda'ya'know the linux vpn client worked just fine too.. Finally I modified the firewall rule for openvpn to block access to my local lan, so now I can connect to the virtual lan and use my internet connection to surf the web, while my home lan remains off limits fomr the outside. All in all I'm a happy camper!
  • How to Route PFSense-openvpn Tunnel Network

    6
    0 Votes
    6 Posts
    3k Views
    V
    In this case the static route doesn't depend on a OpenVPN connection. The route goes to a static interface address of the other pfSense.
  • Can't see user session in the online users list on my RADIUS server

    3
    0 Votes
    3 Posts
    985 Views
    O
    Thanks Jimp!
  • [Solved] Can't start OpenVPN from GUI

    6
    0 Votes
    6 Posts
    2k Views
    C
    What do you have chosen for "Hardware Crypto" in your OpenVPN config? Is this on your SG-2220? I presume with the default crypto options under System>Advanced, having AES-NI enabled. Past instances of this were all in pre-release 2.2.0 versions with certain ciphers and certain hardware crypto. Those were attributable to a problem in OpenVPN that we got fixed in OpenVPN pre-2.2.0 release. But apparently there is still some combination of options there that triggers the same issue.
  • Client Export Utility

    2
    0 Votes
    2 Posts
    813 Views
    DerelictD
    You mean like the settings for host name resolution and everything else? No. You have to set them every time, unfortunately. You could probably modify the php with defaults but it'll get clobbered by updates. You could maybe make a patch.
  • OpenVPN Site-to-Site + OSPF [Solved]

    5
    0 Votes
    5 Posts
    3k Views
    A
    For anyone else who runs into this; https://forum.pfsense.org/index.php?topic=106559.0
  • Routing multiple LAN-s in OpenVPN

    11
    0 Votes
    11 Posts
    3k Views
    M
    This appears to be a simple setup… post the openvpn configs from both sides (server1.conf and client1.conf respectively) and we'll have a better idea of what is happening.
  • OpenVPN CRL issuer error

    1
    0 Votes
    1 Posts
    721 Views
    No one has replied
  • OpenVPN server connect to which vlans?

    6
    0 Votes
    6 Posts
    2k Views
    P
    Thank you both for your comments and insight.  I think that since I am the only person with VPN access, I will probably leave things as they are.  It will actually be helpful for administrative purposes, as I have no access to some of the devices on the vlans (other than my regular LAN) in my network unless I physically plug a machine into the correct port on my switch.  So this way, if I need to manage one of the devices on another vlan, I can simply connect via VPN, and I will have access to all vlans.
  • Cannot ping on few devices on LAN?

    5
    0 Votes
    5 Posts
    1k Views
    K
    Thank you it seems that it was the firewall of the computer the weirdest  thing as if connected though LAN able to ping but on OpenVPN nothing until the firewall is down on the PC Thank you again
  • Some issues with OpenVPN and port 1194 (Inactivity timeout)

    3
    0 Votes
    3 Posts
    2k Views
    A
    Again a quick update. It appears that the OpenVPN connection is now working! I have no idea what made it work, but I assume it has something to do with the fact that I'm not using a certificate anymore, but the username / password combination. I reset the pfSense router to factory defaults and it still works :-) The only problem now is that I seem to be losing connection now and then and the fact that I have no Internet at all whenever I'm connected to the VPN. I saw that there are more users that have experienced this issue, so I hope to find all the information I need here :-)
  • VPN issue in 2.2.6

    1
    0 Votes
    1 Posts
    725 Views
    No one has replied
  • "Page Not Available" when connected via OpenVPN

    3
    0 Votes
    3 Posts
    901 Views
    D
    Another very basic consideration, what's your home LAN IP subnet and what's your sister's? If they're the same (eg. 192.168.0.0/24 or 192.168.1.0/24) you're likely going to have issues…...
  • [solved] Routing WAN traffic over VPN server

    6
    0 Votes
    6 Posts
    2k Views
    M
    Yes, I had that set. The solution was to select the VPN interface at Services -> DNS resolver -> Outgoing Network Interfaces. Thank you too!
  • Firewall traffic being routed over OpenVPN Client - confused

    28
    0 Votes
    28 Posts
    4k Views
    H
    i'm using ssh to connect to pfsense from LAN. then from pfSense i ssh to a host on the internet by routing through a site-2-site openVPN tunnel. no ssh-tunneling involved, but i doubt it matters. i did forget to mention i had to manually add a NAT entry for the vpn-interface so that it would also NAT the WAN-address of the def gw. (because automagically, it doesn't )
  • OpenVPN won't start after getting IPv6 to work :(

    2
    0 Votes
    2 Posts
    682 Views
    jimpJ
    Do you have any more detail to share?  OpenVPN logs? System logs? There should be some record of why it's failing there, especially the OpenVPN log (Status > System Logs, OpenVPN tab)
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.