• Site-To-Site Remote can not access Lan

    3
    0 Votes
    3 Posts
    440 Views
    ?
    facepalm That was it! I added the rules to the Firewall and now does everything work as expected. Thanks for the right pointer  :)
  • Open Vpn not connecting from client side

    2
    0 Votes
    2 Posts
    433 Views
    V
    Check the client log and post it here. Also look if there are entries in the server log.
  • Pfsense with OpenVPN and AD authentication -> how can i use MFA ?

    2
    0 Votes
    2 Posts
    340 Views
    jimpJ
    You'd add that on your AD setup, not on pfSense. Look into AD-based multi-factor auth.
  • OpenVPN 2.4.4

    2
    0 Votes
    2 Posts
    670 Views
    A
    Do you have an example? Our configuration on six boxes started on pfSense 2.3.4 and i upgraded it to 2.4.2_p1 on all of them. I did not have to change anything on our OpenVPN configurations so far.
  • Ifconfig mismatch help needed

    3
    0 Votes
    3 Posts
    699 Views
    F
    simples thanks very much, all sorted  :)
  • Restrict OVPN client Access to Single PC

    4
    0 Votes
    4 Posts
    808 Views
    S
    Can someone help  :'(
  • Client Specific Override - can't communicate

    3
    0 Votes
    3 Posts
    562 Views
    S
    Looking for a solution  :'(
  • Site to site working. Now need a 2nd & 3rd

    2
    0 Votes
    2 Posts
    451 Views
    L
    I have successfully set up 4 site with independent connections between each other (see attached). ![4 Site connection with pfSense and openVPN.png_thumb](/public/imported_attachments/1/4 Site connection with pfSense and openVPN.png_thumb) ![4 Site connection with pfSense and openVPN.png](/public/imported_attachments/1/4 Site connection with pfSense and openVPN.png)
  • Basic walk though

    2
    0 Votes
    2 Posts
    571 Views
    R
    If you want all ethernet ports to have the VPN then it should do that by default.
  • OpenVPN speed vs hardware

    10
    0 Votes
    10 Posts
    4k Views
    R
    @Rango: @Ryu945: Crypto-Dev by itself also did nothing.  I only got it to work when both were turned on. That's interesting. I now only have Crypto Dev on both sides and it boosts 20% so i can get 120Mbs on N3150 and medium is about 115-117Mbps but when i switch to only AES-NI it goes down by 20% to base line with is about 100Mbps which is what you see in screenshot above. I tried it every possible combination and that's what i'm getting. At least i'm happy Cryptodev is working and boosting a bit, 20%. Maybe if AES-NI would work it would boost much more. I dunno what the expectation of hardware based acceleration should be. I just reported what my testing yielded. I am happy with pfsense but it seems AES-NI module is not working and looks like Cryptop Dev is FreeBSD solution to it, for now maybe. Maybe in 2.5 this will change when they focus on it.  I can't wait if so. I am however disappointed i purchased N3150 however. I didn't do enough research then. The fact that i owned asus 87u also purchased for encryption. It is now exclusively AP. I guess as they say u learn on your own mistakes. I've learned. Thanks for posting your results. :) I did this AES-NI test with the version that came out before the Spectrum/Meltdown bug so I don't know if things have changed in the version I currently run.  I will have to run more test at a later time.  I did notice a massive speed reduction after that update.
  • Multiple VPN and Multiple Wan

    3
    0 Votes
    3 Posts
    660 Views
    R
    1)  Do you have duel WAN working by itself? 2)  Just for a sanity check, is there a reason your using two WANs?
  • PfSense 2.4.2P1 - OpenVPN with CARP VIP

    3
    0 Votes
    3 Posts
    579 Views
    R
    Thanks for the assist.  Turns out, I had to generate a new VPN profile for my client to get it working.  Editing the old VPN config (changing port numbers and IPs) did not work…
  • [Solved] Cannot access LAN when bypassing VPN

    7
    0 Votes
    7 Posts
    779 Views
    T
    @Derelict: It works if it is positioned ABOVE the policy-routing rule in the interface rule set. Forgive me, I guess I mix up the terms… Please see attached screenshot, that is what I thought you meant by putting it on the WLAN interface. But now I made a new floating rule like the 2nd screenshot and it works, I guess that is what you meant is a more neat solution? ![WLAN rules.PNG](/public/imported_attachments/1/WLAN rules.PNG) ![WLAN rules.PNG_thumb](/public/imported_attachments/1/WLAN rules.PNG_thumb) [image: Finale.PNG] [image: Finale.PNG_thumb]
  • OpenVPN Site to Site Routing

    3
    0 Votes
    3 Posts
    667 Views
    DerelictD
    One of the nice things about OpenVPN is that clients can be behind other routers with generally no problems. If the tunnel is coming up and the site2 pfSense has a route for 192.168.190.0/24 into the ovpncX interface, then that is configured correctly. If that is the case I would check the firewall rules for OpenVPN at main to be sure they pass the traffic. If they do I would check the firewalls on the main hosts themselves to be sure they are not blocking the traffic.
  • PIA VPN failing every hour

    3
    0 Votes
    3 Posts
    780 Views
    B
    What server are you connecting to? Have you tried another server with the same results? also given the errors in your logs you have not followed/ matched the OVPN files.    match those as close as possible
  • Restrict PIA openvpn access to only ONE IP on my network…

    1
    1 Votes
    1 Posts
    945 Views
    No one has replied
  • Multi OVPN Clients - Clashing Same Virtual IP Address

    3
    0 Votes
    3 Posts
    602 Views
    H
    Thanks for the response. I know I have set this up in the past with the ip being pushed from the server to the client, but starting to question myself also if it can be done client side. I dont see why not, I dont pull routes from the VPN provider. I did manage to assign static ip client side using the client specific overrides. This was based on assigning static ip per certificate authority. Unfortunately, all the VPN clients share the same certificate authority though - so although I have proven you can assign static ip client side I still havent managed to do it per client. It seems that the ifconfig-push directive works in the 'Client Specific Overrides' section but not in the 'Client' section. ' I dont understand why in the 'Client' section you cannot just specify the ip in 'IPv4 Tunnel Network'
  • VPN client setup advise

    8
    0 Votes
    8 Posts
    1k Views
    RangoR
    @gschmidt: Hi, I bought a 4xNic aes-ni mini pc with pfsense  to replace my home router. The main reason i want to replace my home router is to setup an openvpn client ( Expressvpn). Is it possible to select the ip's which will be using the VPN tunnel? Or is it only possible to exclude the ones not using the VPN tunnel? Greetzzz, Gerben Expressvpn will leak your DNS. You can not setup pfsense with their dns servers. I inquired with them. You will have to point to 3rd party open dns server which will cause you leak dns out.
  • Conel 4g router OpenVPN client to PFsense openvpn server

    2
    0 Votes
    2 Posts
    508 Views
    F
    Well i have the vpn link up now. However i can only ping one way, from the conel 4g router i can see all my devices on the pfsense network. I can ping the virtual ip of 192.168.99.2 and access this via web interface to reach the conel router home page.  I cant however reach any of the devices on the local lan of the conel (192.168.1.xxx). Is there something i'm missing in terms of routing etc?# Thanks
  • How to kill user's OpenVPN connection

    2
    0 Votes
    2 Posts
    352 Views
    PippinP
    See here: https://forum.pfsense.org/index.php?topic=139073.msg776861#msg776861
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.