• 0 Votes
    7 Posts
    702 Views
    V
    @shshs said in Unable to work over multiple concurrent connections for the same client account: But to restrict a VPN user access in a firewall you have to explicitly assign the IP address to its connection, so the IP remains the same each time the user connects to VPN. And to do this you have to specify subnet per user in CSO. Not a single IP, but a subnet, since you have a net30 topology. As mentioned above you may set here at least a /29 subnet to realize two client connections from the same user, a /28 for four and so on. And you have to use exactly the same subnet in your filter rules source networks. It would be more clear if you post some screenshots of your OpenVPN server config and the CSOs and filter rules. Since I have separate VPN servers (not CSO!) for achieving different permissions to multiple user groups, I use the tunnel subnets in my filter rules. And I asked you if multiple OpenVPN servers may be an option for you. I've never run multiple connections with the client for which I've assigned a CSO.
  • VPN up - Gateway Down - VPN not routing out to internet

    11
    0 Votes
    11 Posts
    1k Views
    BogusExceptionB
    @wrodriguez56 awesome! Might help someone else reading down the road.
  • Help with my PIA OpenVPN setup

    4
    0 Votes
    4 Posts
    385 Views
    NogBadTheBadN
    In the OpenVPN client settings:- [image: 1565552195958-screenshot-2019-08-11-at-20.35.04.png] I bet if you were to look at Diagnostics -> Routes the default route is pointing to the VPN
  • Site-to-Site OpenVPN, connects but client site loses Internet

    8
    0 Votes
    8 Posts
    707 Views
    G
    I have fixed my site-to-site config. Unfortunately this was done by deleting the client and server config and recreating them. It now connects but Site B keeps its internet. Backup taken (just in case) and adding desireable tweaks, like adding an interface so the traffic graph is drawn on the homepage. If it breaks again I will restore the backup. If I figure out a change that stops internet access for Site-B again, I will post here. Thanks to both who tried to help. Much appreciated.
  • 0 Votes
    7 Posts
    726 Views
    DerelictD
    As I understand it if you enable auth-nocache you will always be prompted for the password when you renegotiate. Else it will enter it for you. Most people only hit this problem when they use multi-factor authentication because OpenVPN cannot renegotiate because it doesn't have access to the multi-factor. I would leave it as the default (no auth-nocache) and leave the renegotiation at the default as well.
  • OpenVPN issue

    6
    0 Votes
    6 Posts
    578 Views
    B
    What details you need? maybe i can provide it for. please thanks
  • Openvpn to access more than one subnets

    12
    0 Votes
    12 Posts
    1k Views
    bthovenB
    Thanks. I did not specify it because when I installed my first AP, I didn't have to. Networking is not my area and I learned a lot from you guys here. Installing PfSense forced me to have more hand-on experience on networking.
  • Can 2.3 ASUS RT-AC68p connect to latest 2.4 pfSense FW?

    5
    0 Votes
    5 Posts
    550 Views
    KOMK
    Thanks John, I didn't realize that. I wonder if he will have to reissue configs for his other users though, or if switching TLS modes is transparent.
  • Cannot Connect to VPN

    5
    0 Votes
    5 Posts
    3k Views
    johnpozJ
    @Udbytossen said in Cannot Connect to VPN: TLS Error: tls-crypt unwrapping failed from [AF_INET]109.57.149.202:1194 Something hitting your box from that 109 address where the TLS didn't auth.. Your IP having a /29 mask doesn't have anything to do with listening on the correct address. Also not sure why your having your clients source port be 1194?
  • force entire LAN traffic through OpenVPN client

    5
    0 Votes
    5 Posts
    926 Views
    JKnottJ
    @baumkuchen With TAP you have the equivalent of an Ethernet switch or bridge. There's nothing to configure. I have never set up a TAP adapter on anything, so I can't help with that.
  • 0 Votes
    1 Posts
    182 Views
    No one has replied
  • 0 Votes
    2 Posts
    185 Views
    kiokomanK
    if i remember correctly windows server need tcp and udp 464 to change the password, do you hve it open?
  • When connected to PIA I cannot connect from outside to OpenVPN tunnels.

    1
    0 Votes
    1 Posts
    186 Views
    No one has replied
  • Mutiple LANs behind OpenVPN LAN

    1
    0 Votes
    1 Posts
    210 Views
    No one has replied
  • ExpressVPN Customer

    6
    0 Votes
    6 Posts
    913 Views
    N
    same issue
  • 0 Votes
    3 Posts
    651 Views
    DerelictD
    Most sites cannot be policy routed with a simple DNS Alias because they resolve to many addresses and they load content from many different domain names. No way adding, say, netflix.com is going to work for you.
  • Accessing XBOX One Remotely Though OpenVPN

    1
    0 Votes
    1 Posts
    279 Views
    No one has replied
  • redirect-gateway def1; NO INTERNET

    1
    0 Votes
    1 Posts
    226 Views
    No one has replied
  • 0 Votes
    5 Posts
    814 Views
    B
    appreciate your help/replies. i need to trace back through all that i setup and find where i mis-configured these VPNs and then post back further questions then if warranted. until then ...
  • OpenVPN question

    1
    0 Votes
    1 Posts
    305 Views
    No one has replied
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.