• Problem configuration OpenVPN

    42
    0 Votes
    42 Posts
    13k Views
    GertjanG
    @kilian77 said in Problem configuration OpenVPN: @johnpoz my ISP router: 192.168.10.1 my pfsense WAN port: 192.168.10.22 my pfsesne LAN port: 192.168.1.1 Ok, that's fine. As that is what I have. [image: 1685541348384-f3730204-1f71-4696-ae1b-779d79caf14a-image.png] My pfSense WAN IP (DHCP) is : [image: 1685541361301-49ee6be1-b9ea-4f36-b569-e78fb7f32638-image.png] What about the other Livebox settings ? You've set a DMZ ? What is the firewall setting ? I use : [image: 1685541503826-6fd31916-4d51-4759-a9a1-38421c83c6c9-image.png] This (uPNP) has been shut down : [image: 1685541566173-68154c35-a684-4479-b02d-e2834c143c22-image.png] as, as it says (translation) : this option can make your live hard ... Nothing here : [image: 1685541618474-7a8a35e6-e01d-413c-8c2a-29ceab16f7d9-image.png] As said earlier : [image: 1685541680681-debb9342-f2dd-4f4f-9110-f424172fcc0f-image.png] Because 'why not'. (pfSense is the only LAN device of my Livebox [except the Orange TV decoder ]) If with these settings you still won't fine a solution. RESET the Livebox (and do not restore faulty settings back in !!). You have to give manually the fti/xxxxxxxx and the connection ISP password Make the connection work. Then change the LAN network from 192.168.1.1/24 to 192.168.10.1/24 And make that work - test with pfSense. Then : make the NAT OpenVPN rule UDP to pfSense, port 1194. And test. It is and should be as easy as that. Remember : These Livoboxes are world's most stupid ISP routers on the planet. It still does't work : throw it out of the windows. Call 3901 (Orange Support). And also : visit the neigbor : test at his place. Or come pay me a visit, I'll show you.
  • Fatal Error: Cannot open TUN/TAP device ...

    1
    0 Votes
    1 Posts
    295 Views
    No one has replied
  • openVPN not responding after upgrade to 23.05 from 23.01

    7
    0 Votes
    7 Posts
    931 Views
    D
    @Gertjan Yes, using iOS Settings/VPN to activate is the workaround noted in the article @tman222 pointed me at. OpenVPN says they are working on a fix...
  • New added physical NIC can not access openvpn networks created before

    7
    0 Votes
    7 Posts
    731 Views
    F
    @viragomann I will try to check and if i found the reason i will post it on here. maybe it help somebody else. anyway thank you for your help and quick response.
  • Update DNS on every VPN connection

    8
    0 Votes
    8 Posts
    1k Views
    Bob.DigB
    @Wastapi said in Update DNS on every VPN connection: @Bob-Dig Where is it defined to be 5 minutes? URL please It is called "Aliases Hostnames Resolve Interval", you find it in System - Advanced - Firewall & NAT.
  • Site to site - How to assign same subnet IP to one device on each end

    6
    0 Votes
    6 Posts
    869 Views
    C
    @Derelict said Probably not going to happen for only one device unless that device is the only device on the bridged segment. Thanks Derelict. If it comes down to it I might try a tap connection. Can two site-to-site OpenVPN instances run at the same time with one in tun mode and the other in tap mode? That would be nice if a small segment of LAN IPs (or perhaps a separate subnet) could be in tap mode, with the bulk running in a 'normal' tun configuration.
  • Pfsense OpenVPN client limitation

    3
    0 Votes
    3 Posts
    649 Views
    R
    Thank you for your response! I meant Advanced filed in the Client specific override. I got it to work!! The problem was with S2 server configuration, where I forgot to check: Username as Common NameUse the authenticated client username instead of the certificate common name (CN). When a user authenticates, if this option is enabled then the username of the client will be used in place of the certificate common name for purposes such as determining Client Specific Overrides.
  • 0 Votes
    1 Posts
    240 Views
    No one has replied
  • Peer certificate verification failure

    3
    0 Votes
    3 Posts
    4k Views
    L
    When renewing the Certificate Authority, navigate to the Certificate section and proceed to renew the server certificates. It is important to note that when creating a new user for the VPN, avoid using an existing user, as it may not function properly. Once you have created the new VPN user, test the functionality to ensure everything is working as expected.
  • help understanding DCO mode and routing

    1
    0 Votes
    1 Posts
    271 Views
    No one has replied
  • Is OpenVPN DCO mode compatible with Suricata Inline mode ?

    5
    0 Votes
    5 Posts
    618 Views
    N
    @stephenw10 can you also take a look please. Thank you
  • Auto Renew OpenVPN Server Certificates

    1
    0 Votes
    1 Posts
    443 Views
    No one has replied
  • OPT2

    7
    0 Votes
    7 Posts
    961 Views
    Z
    @viragomann you said "assigning an interface to the VPN instance gives you a gateway. " probably I'm confusing "assigning an interface to the VPN instance" with "assigning a VPN instance to an interface" or something. I'll get there eventually. cheers
  • AES-NI Active But No Significant Increase In Speed Test

    13
    0 Votes
    13 Posts
    1k Views
    P
    @Dobby_ I believe you. Thank you and @SteveITS for the assistance. I really appreciate you guys taking the time to help. I will check speeds again later tonight to see maximum throughput.
  • P_CONTROL_HARD_RESET_CLIENT_V2 error

    4
    0 Votes
    4 Posts
    3k Views
    R
    @jknott said in P_CONTROL_HARD_RESET_CLIENT_V2 error: @rico The NAT is at the other end. My pfsense has a public address, so no NAT needed at this end. Here's the rule: [image: 1650482158503-121df6a2-46c0-429d-83b1-be3e7903212f-image.png] As for interfaces, I currently have UDP IPv4 and IPv6 on all interfaces, though I have tried just UDP IPv4 on WAN interface. Either way, it does the same thing. For some reason, in the OpenVPN Server you have to set the interface as any, not WAN
  • Policy-based routing isn't pushing traffic through the correct gateway

    11
    0 Votes
    11 Posts
    997 Views
    C
    @bob-dig OK got it, thanks again.
  • Split Tunnel Traffic Failing for Web Traffic

    9
    0 Votes
    9 Posts
    1k Views
    V
    @technolust said in Split Tunnel Traffic Failing for Web Traffic: It could be due to the name resolution not working but I'm not 100% sure. Do an nslookup to get sure. Or even a ping to google.com or whatever. I renamed the vpn file with redirect-gateway def1 to the original. Checked the box and the issue happens... 1.1.1.1 comes up but dns not working... Then I brought back the redirect vpn file and unchecked the box and it works Normally this is pushed to clients by the server and hence doesn't need to be set on the client, however, it's possible. You can enhance the clients log level to see, what configuration changes the client does in the OS with the line: verb 3 try to provide your pfSense IP as DNS server I have a pi-hole setup as DNS server. Should I try that IP? Yes. Possibly you have to add the VPN tunnel to the Resolver ACLs This part I don't recall how to do... This is lapsed, since the Resolver is not the DNS server. Maybe you have to configure it on the Pi-hole properly. If you provide public DNS servers without 'redirect gateway' you would also route them over the VPN by adding them to the "Local Networks". Do I need to do this under IPv4 Local network(s) in the Tunnel Settings? Yes, IPv4 addresses have to be added to the "Local IPv4 Networks", IPv6 to the respective other one. Note to use CIDR notation, e.g. for Cloudflare "1.1.1.1/32".
  • L2 Site-to-Site VPN with conflicting networks

    5
    0 Votes
    5 Posts
    732 Views
    S
    @jknott ... that is the plan - change the network at the new site (site B).... The guy was supposed to prepare the new site to be up and operational, however, it has never worked properly and he left without fixing all those issues..... so I'm trying to help there.... :)
  • OpenVPN client will not connect outside local network

    18
    0 Votes
    18 Posts
    2k Views
    LPD7L
    So can anyone provide suggestions as to why when I am connected to my PFS box via open vpn client that I do not see the connection listed in the status>openVPN screen?
  • Custom Client Export

    4
    0 Votes
    4 Posts
    665 Views
    jimpJ
    The extra files that are part of the export package handle the installation and config copy process that happens. The installer in the export package installs OpenVPN and then afterward (post install) it copies the bundled certs, config, etc.
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.