• OpenVPN Client export has private key in it.

    7
    0 Votes
    7 Posts
    1k Views
    S
    @johnpoz thanks for all of the info. I have read it, but it is late here in Blighty (UK) so it might take me a while to mull this over. Information like this helps us newbies (i.e. me) a lot and is appreciated.
  • 0 Votes
    2 Posts
    2k Views
    G
    first, try openvpn because that is well established and wire guard is new. the ProtonVPN service website should have setup instructions and OpenVPN config files that you can use.
  • OpenVPN S2S [error] Unable to contact daemon

    3
    0 Votes
    3 Posts
    780 Views
    M
    @gertjan this fixed issue for me Updating the linker file manually fixed it for me. Run: ``` kldxref /boot/kernel on both SG-3100 restarted OpenVPN service on both router Thanks for quick reply.
  • VPN connection

    2
    0 Votes
    2 Posts
    455 Views
    GertjanG
    @prunch I don't understand the question. You think the connection to your LAN isn't safe ?
  • open vpn ip

    32
    0 Votes
    32 Posts
    3k Views
    V
    @gertjan awesome, it worked. thank you very much for your knowledge, clear instructions, and patience. hope you have a great day. also thank you @chpalmer @viragomann for helping out
  • 0 Votes
    2 Posts
    615 Views
    V
    @nospam Maybe this helps: https://redmine.pfsense.org/issues/13424
  • RDP to Local LAN desktop - Unable to find

    remote access openvpn rdp openvpn config
    7
    0 Votes
    7 Posts
    2k Views
    S
    Solved! Followed a lot of rabbit holes down until I found these: https://serverfault.com/questions/1064935/openvpn-server-connexion-ok-but-no-access-to-remote-lan which lead to: https://openvpn.net/community-resources/how-to/#expanding-the-scope-of-the-vpn-to-include-additional-machines-on-either-the-client-or-server-subnet Main take away was that I needed to add push "route [Local LAN subnet] 255.255.255.0" to the advanced configuration on the server setup. Still reading a bit more to understand how this worked, but I'm able to ping my local machine as well as remote into it. Happy days.
  • [SOLVED] Open VPN Server daemon not starting

    3
    0 Votes
    3 Posts
    1k Views
    B
    @rcoleman-netgate Hello Sir, Yes, i make some trial and error and i notice that the issue comes when i let pfsense generate the shared key ! While i use another vpn instance already existing with copy , and edit the settings, is working ! Also this is happening on the client side ! both pfsense on 2.6 version. Is this a bug or i'm doing something wrong ? I just exchanging the generated key with copy paste. If generated on server, client is not accepting it and cause this error. If key generated on client, and copy to server, server gets the error ! I will try 2-3 things and let you know.
  • 0 Votes
    1 Posts
    345 Views
    No one has replied
  • Renewing OpenVPN Certificate Remotely

    3
    0 Votes
    3 Posts
    813 Views
    B
    @johnpoz Thanks, John, I'll give that a try. In the mean time, I am trying to get a site-to-site VPN established between two Netgate boxes (one with a dynamic ip address) but I'm not having much success :-( The VPN connects but no traffic flows through it yet...
  • Sometimes not reaching enabled networks through OpenVPN.

    8
    0 Votes
    8 Posts
    938 Views
    Urbaman75U
    Actually do not know, still analyzing, that's the setting I changed and it seems to be stable now, cross-client (windows, linux, android, ...). Also changed the DNS servers to both VPN network x.x.x.1 and vlans CARP IPs (the vlans reachable throguh VPN), to be HA proficient. Do not know why I do need the DNS entries to reach other IPs in the remote networks (not hostnames, just IPs...). Thank you very much!
  • error - IP packet with unknown IP version=15 seen

    10
    0 Votes
    10 Posts
    6k Views
    S
    I fixed the problem. The firewall died during the night from friday to saturday, so naturally I needed to build a new one on sunday. After a clean reinstall, I again started having the same error openvpn xxxxx IP packet with unknown IP version=15 seen Endlessly filling the logs, and killing the SSD-s. It seems the ntopng is the culprit. After disabling ntopng, the errors stopped. And after enabling ntopng, the errors started again, even when there are no clients connected, and the errors start and stop at random intervals. I am currently testing running ntopng but without OpenVPN interfaces selected. For now it seems to be working as expected. So it seems running ntopng with OpenVPN interfaces selected causes the OpenVPN server to have endless errors, even when everything else is working fine. Now I am waiting for monday so we have some user traffic, but judging by the short test I am currently conducting, it should work. Hope this helps someone with a similar problem.
  • issue with downloading configopenvpn file on Mac

    3
    0 Votes
    3 Posts
    329 Views
    johnpozJ
    @vusqq Well normally if you have a openvpn client installed on your client box.. When you click on a ovpn file it will ask if you want to import it into openvpn [image: 1679682869522-example.jpg] Not sure with macs, but for example here is a ovpn file I downloaded from pfsense with the export section under pfsense, and when I click on it windows, the openvpn software I have installed on my windows machine asks if I want to import it.
  • oVPN client: TLS key not valid

    12
    0 Votes
    12 Posts
    1k Views
    johnpozJ
    @orangehand where exactly are you pinging from.. 169.1 would be pfsense lan IP on the remote end.. There wouldn't be any different with your routing, or normally firewall on the 69.x device. 10.0.69.16 -- 69.1 pfsenseA -- vpn tunnel --- pfsenseB 169.1 -- 10.0.169.x If you ping 69.16 from 169.1 interface on pfsenseB, it should work from 169.x unless 169.x is not using pfsenseB as its gateway. Or you doing some sort of policy routing on your 169.1 interface, or you have some firewall rule blocking access to this remote network?
  • ISP blocking and VPN

    11
    0 Votes
    11 Posts
    1k Views
    A
    @johnpoz Ah understood if going down VPN will lost my inet but if reset to default ISP gateway now and use in this way, during VPN problem on upstream VPN servers. My inet will exist with DNS resolver settings above? Second question: with default ISP gateway will this less privacy? Should I create for every other VPN location new VPN client in pfsense or exist way to combine a few locations in one settings? I mean to choose different locations like in VPN client on PC.
  • VPN client

    25
    0 Votes
    25 Posts
    2k Views
    V
    @antibiotic Don't know, whats the suppose of your "local subnets" alias. At the moment the default allow rule would pass any traffic with different source than "local subnets". A different source could be the case if you have a router within your local network like a VPN endpoint, which passes traffic trough. But where will it get to? Since you obviously have a single LAN subnet, which might be included in the local subnets alias, the traffic could be go to the WAN or VPN at its best, but would fail then, since it is not natted (Outbound NAT source).
  • PFsense 23.01 HA with openvpn

    1
    0 Votes
    1 Posts
    373 Views
    No one has replied
  • OpenVPN tap losing MAC

    1
    0 Votes
    1 Posts
    278 Views
    No one has replied
  • OpenVPN Wont start at all.

    openvpn problem hardware corrupted image
    1
    0 Votes
    1 Posts
    532 Views
    No one has replied
  • client export

    6
    0 Votes
    6 Posts
    813 Views
    GertjanG
    @troubleshooting74 [image: 1679489050502-865e91ae-2931-4faf-a302-c24e1724e58a-image.png] User : auser Password (twice) auser I made this user member of the OpenVPN group Checked : Certicate, gave it a description 'auser' And save. This user called 'auser' is now usable on the VPN Client Export page. If not, it's time to explain your setup.
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.