• Client to Server to Internet Client

    5
    0 Votes
    5 Posts
    754 Views
    M
    @gertjan yes your onto it ;) yes its tun, "IPv4 Tunnel Network" ---> 10.10.77.0/24 Do you policy-route this 'call-in' network also ? ive tried to set it as follows.. Firewall / Aliases /IP Network or FQDN --->> 10.10.77.0/24 (OpenVPN) Firewall / Rules / LAN Interface (LAN) "also tried the openvpn here too" Source > Single host or alias "OpenVPN" Gateway is set the expresssvpn with that set like this, when the phone is connected, its works, but the internet connection is still show as my wan ip, and not the expressvpn ip
  • 0 Votes
    1 Posts
    169 Views
    No one has replied
  • Access to LAN net behind pfsense from OpenVPN net

    4
    0 Votes
    4 Posts
    786 Views
    H
    Yep, LAN net is double NAT'd - I'm now working with ISP for switching router to bridge. My net is: [image: 1551583408831-c15a2547-b459-4c5e-8722-b83f9f7cff6f-image.png] On VPS I have OpenVPN server + Zabbix (10.8.0.1). On pfSense I have Zabbix agent + proxy (10.8.0.2). Pfsense self-monitoring works fine (without proxy). I want to monitor some devices in LAN - 192.168.1.101. Now i've been stuck in settings - pinging LAN devices from OVPN interface is not work, but pinging pfsense LAN address works fine. UPD dev ovpnc1 verb 1 dev-type tun dev-node /dev/tun1 writepid /var/run/openvpn_client1.pid #user nobody #group nobody script-security 3 daemon keepalive 10 60 ping-timer-rem persist-tun persist-key proto udp4 cipher AES-256-CBC auth SHA512 up /usr/local/sbin/ovpn-linkup down /usr/local/sbin/ovpn-linkdown local 10.10.10.4 tls-client client lport 0 management /var/etc/openvpn/client1.sock unix remote <ip> 31194 ca /var/etc/openvpn/client1.ca cert /var/etc/openvpn/client1.cert key /var/etc/openvpn/client1.key tls-auth /var/etc/openvpn/client1.tls-auth 1 ncp-disable resolv-retry infinite route-nopull link-mtu 1601 remote-cert-tls server My goal is to set up Zabbix monitoring from VPS (IP 10.8.0.1) of devices on the LAN network (IP 192.168.1.101) through a proxy installed on pfSense router (IP 10.8.0.2). Now zabbix says "Timeout while connecting to "192.168.1.101:161"." In the diagnostics tab of the pfsense router in the ping section i can successfully ping pfsense itself: 192.168.1.1 from 10.8.0.2, but 192.168.1.101 from 10.8.0.2 fail: packages are lost somewhere
  • 0 Votes
    2 Posts
    485 Views
    E
    @eric-marshall I guess that was just way TL/DR. Sorry Guys.
  • PIA VPN removes stealth mode at GRC Shieldsup

    8
    0 Votes
    8 Posts
    1k Views
    S
    Thanks for the info guys
  • Only first IP connected have acces to network

    6
    0 Votes
    6 Posts
    639 Views
    GertjanG
    @artware said in Only first IP connected have acces to network: Certificate are different In that case, you could switch to : [image: 1551452935790-3f385396-4483-40f0-a99b-7a9e484c020a-image.png] De-select Duplicate Connection. Firewall rules ?
  • Dual ExpressVPN failover - routing broken

    1
    0 Votes
    1 Posts
    282 Views
    No one has replied
  • Fatal Error if radius with 2fa doesnt answer for longer time

    2
    0 Votes
    2 Posts
    192 Views
    jimpJ
    Which version of pfSense is this on? If it's not current, upgrade. Otherwise you might want to report this specific error condition upstream to OpenVPN: Feb 28 20:43:38 openvpn 1805 username/83...79:1194 Assertion failed at ssl.c:1929 (ks->authenticated) Feb 28 20:43:38 openvpn 1805 username/83...79:1194 Exiting due to fatal error
  • ACL with HAProxy through OpenVPN

    11
    0 Votes
    11 Posts
    2k Views
    P
    @uwscia said in ACL with HAProxy through OpenVPN: HAProxy is not seeing the OpenVPN client with the assigned subnet IP. Seems like the wrong chicken created a egg explanation cause/result.. :) I think you mean.: The openvpn client is not using the VPN to connect to the IP the domain name resolves to. To solve that, make dns resolve a different ip that is part of the vpn network routes that could perhaps be done with a hostname override in the dnsresolver settings, or make the vpn the default gateway for all traffic? or perhaps push routes for the public ip that needs to be directed over the vpn?
  • Can OpenVPN run at the same time as L2TP over IPsec

    3
    0 Votes
    3 Posts
    212 Views
    DerelictD
    Yes that should not be a problem as long as everything is using different tunnel addressing, etc.
  • 0 Votes
    1 Posts
    151 Views
    No one has replied
  • site-to-site, cannot ping from one lan to other lan

    47
    0 Votes
    47 Posts
    8k Views
    stephenw10S
    It's the Windows clients in Azure that need the route. That can either be added on each client or you can add it to the Azure routing for your VPC (or whatever Azure are naming the local subnet there). That will then apply to traffic from any client that hits the Azure gateway. You can assign the OpenVPN interface there to get an additional logical interface. Because it would be the second interface it will appear as LAN which might make things even more confusing! WAN and LAN are just names though. Steve
  • Settings to utilize AES-NI

    2
    0 Votes
    2 Posts
    423 Views
    GertjanG
    @zeranoe said in Settings to utilize AES-NI: OpenVPN to use AES-NI https://sourceforge.net/p/openvpn/mailman/message/35041969/ ?
  • Site to site tunnel - can ping from one side but not the other

    4
    0 Votes
    4 Posts
    685 Views
    DerelictD
    Can ping from one side but not the other Either firewall rules on the OpenVPN tab (or assigned interface) on the side you can't ping OR a firewall on the device you can't ping itself. OR policy routing on the side that cannot ping the other forcing connections over a different path.
  • 2.4.7

    3
    0 Votes
    3 Posts
    439 Views
    M
    Thanks Jim, appreciate it.
  • Site to site tunnel routing through wrong VPN network half the time

    14
    0 Votes
    14 Posts
    1k Views
    I
    I enabled it again and it continues to work which confuses me since one of the first things I tried was to disable NAT rules so I don't know why it didn't work then.
  • OpenVPN server static IP

    23
    0 Votes
    23 Posts
    2k Views
    Y
    I appreciate your input but not sure if thats the real reason. I know it can be done on the IOS platform becuase at work we have cisco anyconnect and sonic wall VPNs that do it just fine. So maybe in the future it will be added. Other wise, I am happy with PFsense and the community!
  • Encrypted connection between Gateway and "double NAT" pfSense?

    16
    0 Votes
    16 Posts
    2k Views
    RicoR
    Segmentation is not stupid, but do it the right way. ;-) -Rico
  • OpenVPN gateway monitoring shows offline until forced save

    12
    0 Votes
    12 Posts
    2k Views
    kesawiK
    Did you manage to resolve it? I've been having the identical issue with my pfSense install for a while as well. Currently running version 2.4.4-RELEASE-p2.
  • openvpn site-to-site between netgate appliance to azure pfsense instance

    4
    0 Votes
    4 Posts
    1k Views
    ?
    hi chris, I am new to linux and pfsense so I fumbled around but then I found the status->systems.logs and noticed this "Bad compression stub (swap) decompression header byte: 42 " so I changed the compression on the openvpn client to match the openvpn server and shazaam, it worked. now I have a new problem. from the server/negate.sg110 web interface I can ping virtual computers behind the azure.pfsense from the azure.pfsense.client web interface, I can ping physical computers behind my netgate sg1110. however, I cannot ping from a physical computer behind my netgate to a virtual computer behind the azure pfsense I cannot ping from a virtual computer behind azure pfsense to a physical computer behind my netgate.sg1110 I thought that since I had added the correct "IPv4 Remote network" on the server and client, that I should be able to ping from computer to computer. do I need a add a manual route somehow and if so, how might I do that? or what do you suggest? thanks very much, david
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.