• Can't browse to computer on client-end of openvpn

    5
    0 Votes
    5 Posts
    873 Views
    M
    @jeffwcollins: No worries at all, remember there are a TON of actual network engineers that couldn't get this far either. Ha!  Thanks, I'm trying :) In my opinion, for what its worth, there are ways to get around it but they get pretty complicated in the long term with sustainment in mind, meaning that there is no easy way to get this working with the configurations that are currently in place. So, we'll be having a bunch of client appliances out at in the field (~20-40) so I'd really like to keep this as simple as possible.  I'm keeping my fingers crossed that we don't run into more locations that happen to use the same network addressing. Out of curiosity, Whats keeping you from changing the IP Scope of your site, instead of asking the remote office to change theirs? The problematic network is our server VLAN :(  So, we've got DCs, VMs, etc that are all hosted on that network, so changing that isn't really an option.  We're actually blocking the client from accessing our server network as we want to limit outside access, but we want to be able to run scheduled tasks and do performance monitoring from that network to the clients in the field. *To offer some transparency, one thing that could be considered is running a one-to-one nat across the VPN, but it could make sustainment a bit tedious in the long run.  Just providing that as a possible fix for your problem. Yeah, like I mentioned above, simplicity is ideal, especially when we're having to maintain a lot of these appliances.  It looks like the easiest approach might be to see if the hosting site is willing to put us on a different network.  We could care less what it is as long as it gives us access to the Internet. thanks!
  • 0 Votes
    2 Posts
    695 Views
    johnpozJ
    You should set your vpn client to not pull routes and then route the devices you want to go to your vpn via policy routing. [image: dontpullroutes.png] [image: dontpullroutes.png_thumb]
  • Can't Connect

    2
    0 Votes
    2 Posts
    547 Views
    J
    Its probably your TLS session being denied.  What logs are you getting on the OpenVPN Server side?
  • OpenVPN Vulnerability!!!

    2
    0 Votes
    2 Posts
    705 Views
    dotdashD
    Please search before posting: https://forum.pfsense.org/index.php?topic=132534.msg728642#msg728642 And take it easy with the exclamation points.
  • Openvpn 2.4 pfsense update to it?

    12
    0 Votes
    12 Posts
    8k Views
    johnpozJ
    That fixed it… But looks like there is some IPv6 issues along with dnssec for netgate.com.. Might want to look into that ;) Looks like you have IPv6 glue - but no AAAA records to match up. ns1.netgate.com (2610:160:11:3:0:0:0:6) ns2.netgate.com (2610:1c1:3:0:0:0:0:108) I am showing these IPv6 glue entries..
  • MOVED: D

    Locked
    1
    0 Votes
    1 Posts
    375 Views
    No one has replied
  • OpenVPN as a Client on OPT1?

    1
    0 Votes
    1 Posts
    418 Views
    No one has replied
  • Site to Site shared key some devices cannot be reached

    5
    0 Votes
    5 Posts
    1k Views
    G
    It definitely was something on pfSense. Since I ran out of time I had to replace both of them with something else. Changed nothing else and it instantly worked. Pretty unsatisfying though. Really would have wanted to know what exactly was causing the problem. Also very unfortunate that paid support by incident is no longer available. Definitely would have been willing to pay for support for that but with the new contracts only system it would have cost me almost $2000 /:
  • No Pings beyond pfS Gateway

    4
    0 Votes
    4 Posts
    787 Views
    V
    Ensure that pfSense is the default gateway on the hosts behind. you have a firewall rule set on the OpenVPN interface which allow the access. the destination hosts system firewalls do not block the access.
  • 2 problems with routing on site2site + failover (carp)

    1
    0 Votes
    1 Posts
    480 Views
    No one has replied
  • Site to Multisite VPN Configuraiton

    2
    0 Votes
    2 Posts
    469 Views
    K
    Dear All, Can you please guide how to configure Site to Multi site VPN Connection. I have Site A (Head Office) +Site B (Water Factory) +Site C ( Steel Factory) + Site D ( Crusher Factory). I have Static ip and dyndns accounts with me Regards kiruba
  • OpenVPN and Socks support

    2
    0 Votes
    2 Posts
    877 Views
    S
    Hello everyone, any thoughts on this issue? I've spent hours already but nothing works unfortunately.
  • Pfsense openvpn client, manual control and logon info

    1
    0 Votes
    1 Posts
    458 Views
    No one has replied
  • Problems setting up Mullvad

    19
    0 Votes
    19 Posts
    7k Views
    G
    @bimmerdriver: I'm trying to set up Mullvad using pfsense 2.4 beta. Their guide (https://www.mullvad.net/guides/using-pfsense-mullvad/) is somewhat vague and is for an earlier version of pfsense. It's working for ipv4 but not for ipv6. Can I ask, did you deviate from the guide at all? I have tried to setup mullvad on my pfsense box following that guide and it doesn't seem to be working at all. I am relatively new to this so any help would be greatly appreciated as you seem to have it working for IPV4, which is all I need at the moment.
  • 0 Votes
    5 Posts
    1k Views
    M
    Hi, I solved it! I had made it more complicated than it should have been! :D I followed the documentation and set up another server on another port. A peer-to-peer server then you could specify "client" network and then the routing got solved by itself. It works flawless now :-) I just love pfsense more every day :P Thanks for your concern and fast answers! :-)
  • How to add a CentOS to an existent pfSense openvpn configuration

    6
    0 Votes
    6 Posts
    2k Views
    A
    Hi whosmatt, Thank you very much for the help! Actually the CentOS server is one of my openvpn- clients since  it is behind firewall I have no control on. I have used  sudo systemctl enable openvpn@pfSense-TCP… and it is working perfect. I am using TCP since it is thru ssh- tunnel. I rebooted it several times and it is starting automatically after the start of my kvm. I am actually thinking to change the kvm with oVirt. Do you have any experience with it? Best Regards, agrozdanov
  • OpenVPN + Resilio Sync… iOS clients can't direct connect to LAN peers

    1
    0 Votes
    1 Posts
    656 Views
    No one has replied
  • Open VPN on seperate subnet

    2
    0 Votes
    2 Posts
    697 Views
    C
    I'm no expert either but I do have a similar setup, a single PC routed over my VPN with all other traffic going over the WAN. I don't see why you couldn't do the same but just specify a /24 instead of single host. Firewall / Rules / LAN Create new Rule Action: Pass Source: Set your 10.0.20.0/24 network Advanced Options - Gateway: Select your VPN Save. Move the new rule above the "Default allow LAN to any" rule. Click "Save" then "Apply" and restart your VPN service. If this is off track please give some more details. -Chris
  • Load Balance OpenVPN Client

    4
    0 Votes
    4 Posts
    1k Views
    M
    I was testing on the PFSense Console that's why it was not working. I tested on a computer connected to the LAN of the PFSense and the traffic is being routed however the Load Balacing is not working as expected, most of the traffic is leaving from the first OpenVPN Client. EDIT: I tested with a download accelerator downloading a file on a web server hosted on the "House 1" and it uses all the bandwith from both WAN's. I guess my problem is solved then. If someone knows some ways to improve or tweak feel free to post.
  • Synology 'Shared Folder Sync' over pfSense VPN tunnel doesn't work

    3
    0 Votes
    3 Posts
    1k Views
    K
    So, I do have some answers for you. Yes, MTU is affecting ping and tracepath, but that may not be the problem here…though, pmtu may be to blame. The best thing I can suggest is to try and run a packet capture on each end and on one firewall or the other to see if the packets are needing to be fragmented and are not getting fragmented. If the DF flag is set, then it could be dropping packets once it hits the firewall if the mtu is not properly set. Your ss shows that mtu of 1198 works to ping over the tunnel. What I recommend you do to verify this is to use something like this: ping -c 2 -M do -s <size><ip address="">...the above is a linux command, but it should show that the message is too long until you drop it down to 1198. The second thing to do is check that pmtud is running/enabled. The next step is to make sure that ICMP type 11 can make it through each end of the VPN tunnel as that will show "destination unreachable" and is what is necessary for PMTUD to work. Of course, the quickest and easiest way to see if MTU is the problem is to drop the MTU on your Synology interfaces down to 1198 on the interface itself (generally can be achieved with ifconfig <devicename>mtu 1198 run as root/sudo). If you drop it down to 1198 and can ping without using the -s flag to drop the message length and rsync STILL isn't working...there may be other factors at play. Also, something to consider is the methodology that rsync is using to connect to the remote host...this generally is done over the rsync port IF there are no credentials for ssh access...rsync is PREFERRED to be done over ssh, however, because it is more secure than using the unsecured rsync port (I do realize that you're doing this over VPN, but it's still more secure to do rsync over ssh). In another note that I remembered based on your statement "Logging into the GUI of the first Synology, and mounting the second Synology to the local filesystem and consequently copying a large movie (5 gig) through the VPN tunnel works fine. The other way around works fine too." ...suggests that general connectivity is fine between the two devices...this likely means that there is a firewall in the way or something to that effect for rsync specifically. I would also like to address why you were getting a "too many hops message"...that was due to the devices in between each point not responding to the ICMP type 11 time exceeded that should be received on traceroute and tracepath messages...you should look at how those work to get a better understanding of the tool. The basic function is that a packet is sent out with ttl=1. Once it gets to the next hop, it decrements the ttl and checks to see if the ttl has expired, if expired, it sends back ICMP type 11, which lets the client know the next hop's information. It repeats this until it hits the final destination and checks for "Destination port unreachable" ICMP message to be sent back. It does this (by default) over UDP in Linux/Unix. So, the reason you got the messages COULD be for a few reasons, but it looks like none of the devices responded to the ICMP messages. This very well could be due to MTU, but tracepath will drop the MTU automatically...the more likely scenario is that these devices are not responding to ICMP type 11 messages. ...hope some of this is helpful.</devicename></ip></size>
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.