• OpenVPN TLS error.

    4
    0 Votes
    4 Posts
    775 Views
    yon 0Y
    maybe should upgrade openssl to 1.1.1+
  • PFSense OpenVPN on Proxmox issue

    2
    0 Votes
    2 Posts
    392 Views
    R
    nobody ever experienced this issue?
  • View source country

    2
    0 Votes
    2 Posts
    310 Views
    NogBadTheBadN
    Syslog and feed it into Splunk or Elastic Search. https://docs.splunk.com/Documentation/Splunk/8.0.5/Viz/IplocationChoropleth https://www.elastic.co/blog/geoip-in-the-elastic-stack Never done it, but if I was I'd use one of the two above.
  • Bypass OpenVPN Gateway(s) when using pfSense Shell

    1
    0 Votes
    1 Posts
    130 Views
    No one has replied
  • Host Lan cannot communicate back to Client Lan

    1
    0 Votes
    1 Posts
    124 Views
    No one has replied
  • 0 Votes
    6 Posts
    587 Views
    GertjanG
    Your server firewall looks fine. Use the VPN Export package (install it on the server) and create a VPN user, if you already don't have one. Export the user, and install it on a PC/Mac/Phone device, and connect that way. When you have this 'road warrior' setup working, proceed to the next step : treat your Client (home) pfSense as a VPN client, using the VPN client. Btw : for the home pfSense, that needs to become a VPN client, no need for a '1194' firewall rule on WAN. The client isn't 'listening' on port 1194, WAN. It initiates a connection to your server, port 1194. Also : as soon as the Client VPN is up, it's pretty useless. You'll have to visit the Interfaces > Interface Assignments menu, Add an interface (an interface called ovpncx (Your VPN name) will be available). This one has to be added. See more info here.
  • Will packet loss cause OpenVPN SIGTERM?

    2
    0 Votes
    2 Posts
    406 Views
    S
    From my testing it appears OpenVPN is not at all tolerant of packet loss and will restart the tunnel every time during it. I switched to IPsec and it maintains its connection through brief packet loss without any problems.
  • Limit specific openvpn users access to one IP ?

    2
    0 Votes
    2 Posts
    250 Views
    V
    @oldlock Not directly by user basis, but you can set up a client specific override to assign specific IP addresses to these users. Then you can control the users access by firewall rules. https://docs.netgate.com/pfsense/en/latest/vpn/openvpn/configuring-a-single-multi-purpose-openvpn-instance.html#openvpn-client-specific-overrides
  • How do I curl though an OpenVPN interface from a script.

    21
    0 Votes
    21 Posts
    9k Views
    T
    I have been having this EXACT same problem for the past year. I haven't been able to figure out why the pfsense machine won't curl out the interface using the VPN. I suspect this is an NAT Outbound issue... but nothing I do there has fixed it so far. I have manual rules setup for my Outbound NAT. This whole issue prevents my script running on pfsense using curl to utilize my VPN. It's very annoying. For a while I simply used the pull routes option from the VPN and then my script worked but everything then went out the VPN from my shell that wasn't specifically setup otherwise. I had DNS going out the VPN so much though that I eventually reverted and decided to stick with the more secure crippled version.
  • pfsense OpenVPN client behind firewall (2 firewalls)

    2
    0 Votes
    2 Posts
    365 Views
    A
    I put something into Visio to help explain [image: 1597562279150-openvpn-client-pfsense.png]
  • a diagram

    1
    0 Votes
    1 Posts
    151 Views
    No one has replied
  • OpenVPN cant connect to internet

    3
    0 Votes
    3 Posts
    503 Views
    F
    Yeah, I checked that link before. Still no Joy. Does anyone have a sample configuration i.e. what exactly goes in each field?
  • Not natted access to LAN network

    4
    0 Votes
    4 Posts
    427 Views
    V
    @jere7em said in Not natted access to LAN network: No, the default gateway is the VPC Internet Gateway (they are on AWS)... That's why you need NAT. @jere7em said in Not natted access to LAN network: maybe I have to add the routes to the AWS Lan configuration... Don't know the structure of the AWS network, so I cannot help. If it's possible you can install a transit network between the default gateway and pfSense. So you have only to add a static route for the LAN to pfSense. Otherwise you will need a static for the OpenVPN tunnel network route on each device the VPN clients should be able to access.
  • 0 Votes
    1 Posts
    128 Views
    No one has replied
  • Best method to consolidate OpenVPN client connections

    4
    0 Votes
    4 Posts
    417 Views
    KOMK
    @Rico Thanks, this might be the cleanest solution. @oddussiben-3161 That would require me to define every single client connection in order to make them gateways and able to be added to a gateway group. This is exactly what I want to avoid. Thanks for you r reply though. I appreciate it.
  • Voip application via OpenVPN (Its Important) :(

    1
    0 Votes
    1 Posts
    219 Views
    No one has replied
  • Open VPN Internet access

    5
    0 Votes
    5 Posts
    607 Views
    V
    Yes. So check "Redirect gateway" in the server settings to push the default route to the clients and provide a DNS server. Additionally you have to add an outbound NAT rule for the VPN clients. Firewall > NAT > Outbound. Select the hybrid mode and hit save if you have the automatic mode now. Then add new rule: interface: WAN source: <OpenVPN tunnel network> destination: any translation: interface address
  • DNS over OpenVPN question

    1
    0 Votes
    1 Posts
    265 Views
    No one has replied
  • Problem users disconnect Open VPN pfsense 2.4.5-release

    7
    0 Votes
    7 Posts
    1k Views
    J
    @DaddyGo I have this processor [image: 1597153553300-cc874b28-faad-4faf-8bec-4b7f7592cefc-image.png] I´ll look this =) In pfSense, you can configure multiple servers on a single device. Due to redundancy and for the sake of a high number of users, I would even run multiple servers in a separate box. (we do anyway) i´ll try change port Port scanners are familiar with the sub-2K range, yes the dedicated port(s) is 119X, but i wouldn't leave the port here, if you have that many VPN users. i´ll update the version this week. Current version and 2.4.5-p1 contains very important fixes !!! (pfctl, etc.) 23d05161-da56-456f-b9af-b03d8644b5e1-image.png Please Update...... ASAP after update S.O , i´ll update this post about the vpn Connection. Thansk you in advanced.
  • Work from home security issues

    10
    0 Votes
    10 Posts
    1k Views
    DaddyGoD
    @netblues said in Work from home security issues: policy won't happen by asking on any forum.
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.