• Openvpn tunnel client shows wrong address

    1
    0 Votes
    1 Posts
    251 Views
    No one has replied
  • OpenVPN relying on WAN1 when it should rely only on WAN2

    31
    0 Votes
    31 Posts
    3k Views
    A
    @Netgate-Steve can you take a look at this and tell me if it warrants a bug report, please.
  • OpenVPN peer-2-peer SSL/TLS not working

    12
    0 Votes
    12 Posts
    981 Views
    B
    @viragomann So I basically need only client override settings for this right? If i'm doing this with unknown clients that only indentify by cert (CN) (SSL/TLS) I just need P2P mode and Client Override Setting pointing to each remote network so that server knows where to route (iRoute)? So... I don't need any static routes anywhere right, since only GW I can create is interface of server itself (10.10.250.1)? If I use persistent routes on windows machine, it ignores anything I write there and just goes by default route every time. I know this setting is confusing, but also this FW is setup so WAN is on differen public IP (different network subnet) and LAN is also public IP which is routed through FW (it's not NAT). On switch I have route that pointing to that LAN network through WAN interface. Maybe that's creating issues... I'm very unsure...
  • 0 Votes
    1 Posts
    451 Views
    No one has replied
  • OpenVPN TLS error.

    4
    0 Votes
    4 Posts
    775 Views
    yon 0Y
    maybe should upgrade openssl to 1.1.1+
  • PFSense OpenVPN on Proxmox issue

    2
    0 Votes
    2 Posts
    396 Views
    R
    nobody ever experienced this issue?
  • View source country

    2
    0 Votes
    2 Posts
    312 Views
    NogBadTheBadN
    Syslog and feed it into Splunk or Elastic Search. https://docs.splunk.com/Documentation/Splunk/8.0.5/Viz/IplocationChoropleth https://www.elastic.co/blog/geoip-in-the-elastic-stack Never done it, but if I was I'd use one of the two above.
  • Bypass OpenVPN Gateway(s) when using pfSense Shell

    1
    0 Votes
    1 Posts
    130 Views
    No one has replied
  • Host Lan cannot communicate back to Client Lan

    1
    0 Votes
    1 Posts
    124 Views
    No one has replied
  • 0 Votes
    6 Posts
    591 Views
    GertjanG
    Your server firewall looks fine. Use the VPN Export package (install it on the server) and create a VPN user, if you already don't have one. Export the user, and install it on a PC/Mac/Phone device, and connect that way. When you have this 'road warrior' setup working, proceed to the next step : treat your Client (home) pfSense as a VPN client, using the VPN client. Btw : for the home pfSense, that needs to become a VPN client, no need for a '1194' firewall rule on WAN. The client isn't 'listening' on port 1194, WAN. It initiates a connection to your server, port 1194. Also : as soon as the Client VPN is up, it's pretty useless. You'll have to visit the Interfaces > Interface Assignments menu, Add an interface (an interface called ovpncx (Your VPN name) will be available). This one has to be added. See more info here.
  • Will packet loss cause OpenVPN SIGTERM?

    2
    0 Votes
    2 Posts
    409 Views
    S
    From my testing it appears OpenVPN is not at all tolerant of packet loss and will restart the tunnel every time during it. I switched to IPsec and it maintains its connection through brief packet loss without any problems.
  • Limit specific openvpn users access to one IP ?

    2
    0 Votes
    2 Posts
    250 Views
    V
    @oldlock Not directly by user basis, but you can set up a client specific override to assign specific IP addresses to these users. Then you can control the users access by firewall rules. https://docs.netgate.com/pfsense/en/latest/vpn/openvpn/configuring-a-single-multi-purpose-openvpn-instance.html#openvpn-client-specific-overrides
  • How do I curl though an OpenVPN interface from a script.

    21
    0 Votes
    21 Posts
    9k Views
    T
    I have been having this EXACT same problem for the past year. I haven't been able to figure out why the pfsense machine won't curl out the interface using the VPN. I suspect this is an NAT Outbound issue... but nothing I do there has fixed it so far. I have manual rules setup for my Outbound NAT. This whole issue prevents my script running on pfsense using curl to utilize my VPN. It's very annoying. For a while I simply used the pull routes option from the VPN and then my script worked but everything then went out the VPN from my shell that wasn't specifically setup otherwise. I had DNS going out the VPN so much though that I eventually reverted and decided to stick with the more secure crippled version.
  • pfsense OpenVPN client behind firewall (2 firewalls)

    2
    0 Votes
    2 Posts
    367 Views
    A
    I put something into Visio to help explain [image: 1597562279150-openvpn-client-pfsense.png]
  • a diagram

    1
    0 Votes
    1 Posts
    151 Views
    No one has replied
  • OpenVPN cant connect to internet

    3
    0 Votes
    3 Posts
    507 Views
    F
    Yeah, I checked that link before. Still no Joy. Does anyone have a sample configuration i.e. what exactly goes in each field?
  • Not natted access to LAN network

    4
    0 Votes
    4 Posts
    433 Views
    V
    @jere7em said in Not natted access to LAN network: No, the default gateway is the VPC Internet Gateway (they are on AWS)... That's why you need NAT. @jere7em said in Not natted access to LAN network: maybe I have to add the routes to the AWS Lan configuration... Don't know the structure of the AWS network, so I cannot help. If it's possible you can install a transit network between the default gateway and pfSense. So you have only to add a static route for the LAN to pfSense. Otherwise you will need a static for the OpenVPN tunnel network route on each device the VPN clients should be able to access.
  • 0 Votes
    1 Posts
    129 Views
    No one has replied
  • Best method to consolidate OpenVPN client connections

    4
    0 Votes
    4 Posts
    424 Views
    KOMK
    @Rico Thanks, this might be the cleanest solution. @oddussiben-3161 That would require me to define every single client connection in order to make them gateways and able to be added to a gateway group. This is exactly what I want to avoid. Thanks for you r reply though. I appreciate it.
  • Voip application via OpenVPN (Its Important) :(

    1
    0 Votes
    1 Posts
    221 Views
    No one has replied
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.