• 0 Votes
    7 Posts
    1k Views
    D
    @viragomann I appreciate your help, it pushed me in the right direction, there must indeed have been my ISP router out in the street box/head office. My WAN was using a private IP address with I assume the public IP address at my ISP router. I believe that traffic was hitting my Pfsense router but the outbound traffic was not being NAT'd correctly by the ISP router. Anyway, I upgraded to have a public IP on my router which resolved the issue.
  • workaround network conflict host to remote (both are 192.168.1.x)?

    11
    0 Votes
    11 Posts
    1k Views
    JKnottJ
    @chpalmer That is a very common problem caused by the need to use NAT & RFC1918 addresses with IPv4. Back in the early 90s, when I first started using the Internet, I had a static address, I was using SLIP, which required manual configuration. In 1997, I started at IBM, and had 5 static, public addresses, 1 for my own computer and 4 for testing. A couple of years later, when I got a cable modem and built a firewall/router on Linux, I ran into my first problem caused by NAT. FTP broke! Back then, command line FTP was used and NAT broke active mode FTP. At the time, FTP clients generally didn't support passive mode. These days, things like VoIP and some games require a hack called STUN, to get around the problems caused by the hack called NAT. The answer to this is IPv6!
  • OpenVPN toggle on / off

    5
    0 Votes
    5 Posts
    1k Views
    R
    @sfermindi bear in mind those instructions are from a release from 2018. Things do change.
  • 0 Votes
    2 Posts
    311 Views
    GertjanG
    @owlbear If you don't mind a video, you can get one form the source : Configuring OpenVPN Remote Access in pfSense Software
  • OpenVPN Connect Connection Issues

    1
    0 Votes
    1 Posts
    475 Views
    No one has replied
  • OpenVPN set up questions

    7
    0 Votes
    7 Posts
    830 Views
    O
    @viragomann you had it right they didn't show up because there were no user certificates. So my configuration wasn't complete.
  • 0 Votes
    4 Posts
    610 Views
    J
    @jims Spoke too soon. It now shows it reconnects but all the traffic isn't passed. I can get to one of my PCs through the VPN but can't get to others, even after rebooting pfsense. Thought it was something to do with the other PC so tried another and even a printer than has a web page and no go. Not sure what to check now...
  • Including multiple machines on the client side when using a routed VPN

    4
    0 Votes
    4 Posts
    620 Views
    C
    I managed to get it all working using a combination of Client specific overrides and natting on the router
  • 0 Votes
    2 Posts
    393 Views
    P
    I switched the OpenVPN server from TAP to TUN, set the IPv4 Tunnel Network to a different subnet and everything works now.
  • OpenVPN disallow traffic to LAN and WAN only VPN

    1
    0 Votes
    1 Posts
    207 Views
    No one has replied
  • UNDEF and TLS Error after 22.05 Upgrade

    1
    0 Votes
    1 Posts
    266 Views
    No one has replied
  • Had to NAT OpenVPN to get to LAN

    5
    0 Votes
    5 Posts
    755 Views
    C
    @viragomann Yeah I'm aware of all that. OpenVPN gives the pfsense VPN IP as DNS server. It works with anything public. It doesn't work with anything that should resolve to LAN IP. Doesn't work with FQDN. From the LAN side same DNS server does resolve FQDN. The remote machine is using the same domain as pfsense and what the LAN machines get via DHCP. But again I tested FQDN so even if the remote machine didn't know the domain it should get the correct response from the DNS server. I get what NAT does. I don't see why I'm having to use it. pfsense sees both the LAN and VPN networks as it's own literally everywhere I look. Usually with pf you are fighting to keep traffic from being able to go between different networks.
  • 0 Votes
    6 Posts
    1k Views
    Dobby_D
    @bp81 It all depends also on what are the workstations are doing through the tunnels! As an example, you have 20 tunnels and heavy load on (through) them and this is like 50 tunnels and more with only some small traffic through them. No one of us is able to answer this question without knowing what traffic and how much traffic is running through that tunnels.
  • Site-2-Site - Missing routes?

    s2s routes
    6
    0 Votes
    6 Posts
    723 Views
    V
    @peterlinux If there is only a single client connected to the server, the CSO is not necessary in fact. But in this case you have to use a /30 tunnel network and set the "remote networks" on both site, server and client.
  • 64bit client download gets blocked by browsers

    6
    0 Votes
    6 Posts
    868 Views
    R
    @johnpoz said in 64bit client download gets blocked by browsers: I really don't see what netgate can do here I agree. But the user expects something to be fixed and there wasn't a redmine ever created for the issue -- so how are we supposed to fix it? It's likely the browser's security permissions probably from a handed-down OS-level policy. But the point stands -- you can't expect someone to know something is broken if you've never told them it was broken.
  • push additional DNS search domains

    5
    0 Votes
    5 Posts
    2k Views
    S
    @jtmem I currently don't have access to that system anymore, so I can't tell 100% right now. I think it worked with another syntax, I look it up in a backup xml right now. Try push "dhcp-option DOMAIN your.domain.tld"; and not the option "DOMAIN-SEARCH". Let me know if it works for you.
  • OpenVPN first user to connect gets in and nobody after

    3
    0 Votes
    3 Posts
    592 Views
    F
    @jake Hi! I don't have access at the moment, but I was able to work with TAC late Friday and we tracked the problem down to a known bug (https://redmine.pfsense.org/issues/13358). That didn't come up in all my searching beforehand, of course. We have a simple workaround of disabling DCO. I could have sworn I tried that, but I tried so many things over a couple of weeks it was easy to lose track. Thanks for the note! David
  • Losing conectivity after a few hours

    1
    0 Votes
    1 Posts
    324 Views
    No one has replied
  • Can ping remote server when source automatic is selected but not from LAN

    4
    0 Votes
    4 Posts
    557 Views
    L
    Remote server is 10.210.0.6 I have changed nothing on that end Only thing changed on my end was IP of Local LAN port from 172.17.2.1 to 172.17.2.3
  • Remote Access IPv6 Gateway Monitor

    1
    0 Votes
    1 Posts
    279 Views
    No one has replied
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.