• RoadWarior VPN with same Local amd Remote Subnet

    4
    0 Votes
    4 Posts
    1k Views
    B
    Thank you all so much for your feedback! This solution worked for me, i just added to the VPN under advanced configurtion on client side the subnet to be routed trought: "route 192.168.10.0 255.255.255.0" Tata! Thanks! @viragomann: The recommended solution is to use different subnets on both sites, you know. If you try to route the same subnet over VPN as is configured on physical interface the route will be ignored. For workaround, you may add singular IPs you want access in the remote subnet to be routed over VPN instead of the hole subnet. Remember that your VPN client host cannot access the same IPs in local network while it is connected to the VPN server.
  • Multi-site OpenVPN, pfSense issuing the same IP for the Tunnel network.

    3
    0 Votes
    3 Posts
    1k Views
    W
    Thanks! Worked perfectly.
  • Raah: write UDPv4: Operation not permitted (code=1) and other crap

    10
    0 Votes
    10 Posts
    4k Views
    M
    More crap on this completely fresh reinstall of pfSense 2.1.5 (and even more crap new messages, which I have in a word document and will post later): attached pic. I can not assess if this is related to this: https://redmine.pfsense.org/issues/3894 https://forum.pfsense.org/index.php?topic=75502.0 I'm way to noob for that. [image: PIAVPN-weird.jpg] [image: PIAVPN-weird.jpg_thumb] [image: PIAVPN-weird2.jpg] [image: PIAVPN-weird2.jpg_thumb] [image: PIAVPN-weird3.jpg] [image: PIAVPN-weird3.jpg_thumb]
  • Open VPN set up

    2
    0 Votes
    2 Posts
    850 Views
    K
    Is this help? …. https://www.youtube.com/watch?v=VdAHVSTl1ys
  • Default route from the router itself to NOT use the VPN

    3
    0 Votes
    3 Posts
    3k Views
    M
    @jimp: If your VPN client is OpenVPN and it receives its default route dynamically over that channel (e.g. "redirect-gateway def1" on the server) then you'll need to use "route-nopull" in the advanced options so that the client will ignore the default route information. Hmm, Jim, if I do that I get: ] | Jan 3 15:29:30 | openvpn[73188]: Options error: option 'route' cannot be used in this context ([PUSH-OPTIONS]) | | Jan 3 15:29:30 | openvpn[73188]: Options error: option 'dhcp-option' cannot be used in this context ([PUSH-OPTIONS]) | | Jan 3 15:29:30 | openvpn[73188]: Options error: option 'dhcp-option' cannot be used in this context ([PUSH-OPTIONS]) | | Jan 3 15:29:30 | openvpn[73188]: Options error: option 'redirect-gateway' cannot be used in this context ([PUSH-OPTIONS]) | | Jan 3 15:29:30 | openvpn[73188]: PUSH: Received control message: 'PUSH_REPLY,redirect-gateway def1,dhcp-option DNS 209.222.18.222,dhcp-option DNS 209.222.18.218,ping 10,route 10.124.1.1,topology net30,ifconfig 10.124.1.6 10.124.1.5' | | Jan 3 15:29:30 | openvpn[73188]: SENT CONTROL [Private Internet Access]: 'PUSH_REQUEST' (status=1) | | Jan 3 15:29:28 | openvpn[73188]: [Private Internet Access] Peer Connection Initiated with [AF_INET]x.x.x.x.:1194 | | Jan 3 15:29:28 | openvpn[73188]: Control Channel: TLSv1, cipher TLSv1/SSLv3 DHE-RSA-AES256-SHA, 2048 bit RSA | | Jan 3 15:29:28 | openvpn[73188]: Data Channel Decrypt: Using 160 bit message hash 'SHA1' for HMAC authentication | | Jan 3 15:29:28 | openvpn[73188]: Data Channel Decrypt: Cipher 'BF-CBC' initialized with 128 bit key | | Jan 3 15:29:28 | openvpn[73188]: Data Channel Encrypt: Using 160 bit message hash 'SHA1' for HMAC authentication | | Jan 3 15:29:28 | openvpn[73188]: Data Channel Encrypt: Cipher 'BF-CBC' initialized with 128 bit key | | Jan 3 15:29:28 | openvpn[73188]: VERIFY OK: depth=0, C=US, ST=CA, L=LosAngeles, O=Private Internet Access, OU=Private Internet Access, CN=Private Internet Access, name=Private Internet Access, emailAddress=secure@privateinternetaccess.com[/t][/t][/t] My settings are: | auth-user-pass /etc/openvpn-password.txt; ca /etc/ca.crt; verb 3; route-nopull; What might this mean? Thank you  ;D
  • Routing Public IP over vpn

    8
    0 Votes
    8 Posts
    3k Views
    P
    If there is some computer behind the pfSense at the remote site, then you can install something like TeamViewer on it. That will also find its way out from behind private address space. Then you can TeamViewer to that computer (VM or whatever) and open a browser there to access pfSense webGUI even when the OpenVPN is down/off.
  • Performance? iperf measurements representative of real world data?

    1
    0 Votes
    1 Posts
    800 Views
    No one has replied
  • TUN vs. TAP

    1
    0 Votes
    1 Posts
    2k Views
    No one has replied
  • Pass username and password to the batch file for net use cmd

    1
    0 Votes
    1 Posts
    754 Views
    No one has replied
  • Issues with Client mode -> FrootVPN server

    3
    0 Votes
    3 Posts
    2k Views
    D
    I just finished writing up a quick set up guide on a local forum of ours, please feel free to check it out: http://mybroadband.co.za/vb/showthread.php/669041-Mini-Guide-Setup-free-VPN-(Froot-using-OpenVPN)-in-PfSense Seems to be working fine on my side.
  • Username @ User manager too short

    4
    0 Votes
    4 Posts
    1k Views
    jimpJ
    If you are using authentication against AD for OpenVPN, why do you touch the user manager? They do not need account entries there. Make certificates directly under System > Cert Manager on the Certificates tab. Ignore the user manager.
  • OVPN Restart on Heavy Load?

    2
    0 Votes
    2 Posts
    803 Views
    jimpJ
    In the advanced options for the gateways, adjust the latency thresholds higher so that they won't trigger so soon, and set the down time higher (30-60sec) https://doc.pfsense.org/index.php/Gateway_Settings#Advanced_Options
  • Feature Request:SoftEther VPN

    1
    0 Votes
    1 Posts
    928 Views
    No one has replied
  • Site2Site between two pfSenses - no response from Server

    11
    0 Votes
    11 Posts
    2k Views
    C
    As written, there is no Log on the server side … not one line (about this instance) OK ... problem found ;) I've set the server to the WAN-Interface ... but he have to listen to a virtual ip on this interface ... so he tried to bind to the main ip instead of the virtual ip address. I've changed the interface and one second later, the client was connected. Anyway ... many thanks for your inputs ... Kind regards
  • Openvpn WAN -> LAN1 and LAN2 -> LAN1

    2
    0 Votes
    2 Posts
    834 Views
    C
    Yes, you can open your openvpn-port (normaly 1194) not only on the wan-interface, but on the lan2 interface too. Set the openvpn-server to listen on "any" interface.
  • 0 Votes
    3 Posts
    824 Views
    R
    Hi Heper! Thanks for the response. I looked at this great tutorial: https://forum.pfsense.org/index.php?topic=76015.0 The problem I had was that I was missing the NAT rules, did as suggested there and it all works great!
  • MOVED: Pfsesne 2.2 OVPN Problems

    Locked
    1
    0 Votes
    1 Posts
    548 Views
    No one has replied
  • Initial set-up of OpenVPN

    6
    0 Votes
    6 Posts
    2k Views
    M
    Problem #1 is your tunnel network is inside your LAN.
  • VPN, Connection/disconnection Notification

    2
    0 Votes
    2 Posts
    794 Views
    M
    I have not seen anything that shows PFsense can be configured to do so, but you can always dump to a syslog and implement filters to show you what you want to see.
  • VPN Pivoting

    2
    0 Votes
    2 Posts
    1k Views
    A
    bump
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.