• 0 Votes
    1 Posts
    4k Views
    No one has replied
  • OpenVPN routing

    Locked
    7
    0 Votes
    7 Posts
    6k Views
    K
    and the other part of my config [image: 4.jpg] [image: 4.jpg_thumb] [image: 5.jpg] [image: 5.jpg_thumb] [image: 6.jpg] [image: 6.jpg_thumb] [image: 7.jpg] [image: 7.jpg_thumb]
  • SquidGuard and OpenVPN - Web Filtering

    Locked
    1
    0 Votes
    1 Posts
    2k Views
    No one has replied
  • Client-specific configuration, static IP

    Locked
    2
    0 Votes
    2 Posts
    3k Views
    jimpJ
    A few simple tests could confirm this behavior, but I'm not sure offhand. I haven't tried this myself, but you could require having a CSC entry, and use the directive ccd-exclusive; In the custom options to enforce the requirement that a client exists on the CSC tab before they can connect. The OpenVPN man page doesn't really clarify whether or not the ifconfig-push directives for the CSC entries are taken into account during general pool assignment.
  • Pinging hosts over OPENVPN tunnel

    Locked
    5
    0 Votes
    5 Posts
    5k Views
    P
    Thx i think i got it now. I ve changed Address pool to 10.0.8.0/24 (on servers side) an on client side Interface IP: to 10.0.8.0/24 and now i can ping from hosts on A site to host on B site. Now I am going to play with DNS. Thx once again.
  • Dns not working

    Locked
    6
    0 Votes
    6 Posts
    3k Views
    J
    It's resolved. There were two different problems. One was with Tunnelblick. I switched to a different VPN client on the Mac (Viscosity) which worked right away. The problem with the Windows PC was that I was using a different VPN config, who's alias was mistakingly being blocked from DNS via a firewall rule.
  • MOVED: Multiple clients to pfSense 2.0 OpenVPN

    Locked
    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • PfSense site-to-site PKI: can ping to one site, not the other

    Locked
    3
    0 Votes
    3 Posts
    2k Views
    jimpJ
    This was solved on IRC, I believe. He switched to using a real PKI setup (not shared key/PSK), and adding route/iroute statements as needed, and it started to work.
  • What encoding is used on the OVPN certificates and keys in config.xml?

    Locked
    2
    0 Votes
    2 Posts
    2k Views
    B
    Never mind, I figured it out. It is base64 encoded, just without line breaks. I just removed all the line breaks from my encoded string.
  • Create Userkeys with minimal serverkeys

    Locked
    7
    0 Votes
    7 Posts
    4k Views
    jimpJ
    I'm not sure how it goes on Windows, but on unix, you have to run a different program first that sets variables that makes sure it's reading all of the proper files and such.
  • OpenVPN works but Local network unreachable

    Locked
    13
    0 Votes
    13 Posts
    8k Views
    jimpJ
    Can you try some packet captures to see if the traffic makes it across the tunnel on tun0 and actually leaves (and re-enters) your LAN interface?
  • Firewall rules multi LAN

    Locked
    2
    0 Votes
    2 Posts
    2k Views
    V
    Never mind , i will skip the VPN settings for now
  • Client-config-dir files being deleted

    Locked
    3
    0 Votes
    3 Posts
    3k Views
    V
    Thanks , it works , i was thinking i could just copy them  :- anyway thanks again , it solved the problem
  • Is this possible ?

    Locked
    2
    0 Votes
    2 Posts
    2k Views
    V
    Ok, I figured this out. I needed to configure the DNS forwarder to be authoritative for the blah.com domain. Also, on the same setup screen, I needed to set the local IP for server.blah.com. Now, I can use the fqdn if I am at the home office or on the road. I LOVE pfsense !!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!
  • Problem to run OpenVPN

    Locked
    14
    0 Votes
    14 Posts
    5k Views
    K
    Your config isn't fine until you've made sure that the tunnel network (what I recommended to be 10.x.y.0/24) and the two office networks are all separate subnets. After that you need to make sure you have proper routes in place. On the server (office1) the remote network should be set to the subnet of office2 (192.168.3.0). On the client(office2) the remote network should be set to the subnet of office1 (192.168.0.0/24). If you need additional routes on top of those they should go to advanced options as "route subnet netmask" (e.g. "route 192.168.100.0 255.255.255"), push "route …" doesn't work in PSK mode, it's for PKI roadwarrior mode.
  • Can't edit Local Network field when creating OpenVPN Server config?

    Locked
    2
    0 Votes
    2 Posts
    2k Views
    jimpJ
    The available options change depending on the other options chosen. You probably need to use PKI instead of Shared Key
  • Use openvpn ip on nat - rdr rules

    Locked
    2
    0 Votes
    2 Posts
    2k Views
    jimpJ
    Starting with pfSense 1.2.3 you can assign the OpenVPN interface and you can do NAT and such on it. http://doc.pfsense.org/index.php/OpenVPN_Traffic_Filtering_on_1.2.3
  • Vista Client to pfSense OpenVPN [SOLVED]

    Locked
    6
    0 Votes
    6 Posts
    4k Views
    C
    I have had the same experience as jimp and Cry have said. The only time I've ever had to use route-delay is because ICS was configured on the machine. Is this perhaps the case for you?
  • I can't contact roadwarrios from the WAN interface

    Locked
    6
    0 Votes
    6 Posts
    3k Views
    A
    Thanks everyone. I tried again on a fresh install with a different scenario. Still does not function as I want. Also use the same configuration file generated by pfSense to the OpenVPN server on a machine with CentOS linux and got the same result. I will spend time reading the documentation for OpenVPN again. Greetings and thanks again for responding.
  • 0 Votes
    3 Posts
    5k Views
    S
    Thank you very much. That solved the problem with the script! I do not know why I thought that script-security was a server parameter.
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.