• Can't access to server (need routing?)

    14
    0 Votes
    14 Posts
    1k Views
    ontzuevanhussenO
    @viragomann Ok, done. Now everything works normally. [image: 1593705588494-screen-shot-2020-07-02-at-22.59.32.png] Because of the rules in the VPN tab: [image: 1593705824280-screen-shot-2020-07-02-at-23.03.19.png] Why did you give up? why you so easy to give up???
  • Configuring more than one OpenVPN Server

    3
    0 Votes
    3 Posts
    496 Views
    S
    Thank you Gerjan. I added float to the client config and the errors went away. I actually didn't expect the fix to be that easy.
  • API log for OPEN VPN

    6
    0 Votes
    6 Posts
    779 Views
    JeGrJ
    Still running it on my homelab without a problem but yeah in a busy setting that can hurt ;)
  • RADIUS 2 way Authentication with OpenVPN

    1
    0 Votes
    1 Posts
    161 Views
    No one has replied
  • Restrict access to specific ip to users remotely connected openvpn

    11
    0 Votes
    11 Posts
    4k Views
    V
    perfect Rico, thank you very much, I learned a lot
  • OpenVPN Kill Switch

    Locked
    21
    0 Votes
    21 Posts
    18k Views
    stephenw10S
    Locked this, it was just a spam magnet.
  • OpenVPN Site-to-Site

    8
    0 Votes
    8 Posts
    950 Views
    mohkhalifaM
    Thank you all guys for you kind help. it's really appreciated
  • CRL don't works.

    6
    0 Votes
    6 Posts
    365 Views
    D
    Hi Jim, thank you for your time. I've supposed that the problem is the php library. I'll move to build and use a new CA. Thanks, Dario.
  • OpenVPN clients can't ping

    11
    0 Votes
    11 Posts
    931 Views
    N
    @Derelict Only from pfsense. Not from any clients. The routes show up in the pfsense route table with the gateway as the tunnel link address. Could it be an issue that the default destination is at the top of the entire list? Another interesting thing is that a trace route command to the other side of the tunnel gets only as far as the local gateway on the side you are trace routing from.
  • Client online but Gateway not working

    11
    0 Votes
    11 Posts
    1k Views
    Bob.DigB
    So finally installed the OpenVPN Access Server and it works, meaning, I did everything right on the client side, but still everything could be messed up on the server side, if I roll my own on a ubuntu machine. Again, if anyone got a good and working tutorial for that, would be appropriated.
  • OpenVpn client cannot access subnet via Draytek IPsec to Pfsense tunnel

    2
    0 Votes
    2 Posts
    356 Views
    P
    don't worry - i've sorted it.
  • OpenVPN with External Radius Authentication Fail-over Order

    1
    0 Votes
    1 Posts
    240 Views
    No one has replied
  • Disabled static route deletes OpenVPN's routes

    6
    0 Votes
    6 Posts
    1k Views
    DerelictD
    @fertig said in Disabled static route deletes OpenVPN's routes: @Derelict said in Disabled static route deletes OpenVPN's routes: Workaround: delete them. Don't set them to disabled. You should not be using static routes for OpenVPN routes anyway. Let OpenVPN maintain them using Remote Networks. if you're using a separate OpenVPN-gateway, you'll have to use static routes to this gateway That is a static route to a gateway, not into OpenVPN. Two entirely different things. if you're migrating away from such a gateway, while you're testing the OpenVPN on the pfSense, you'll allways disable the routes temporarly, to get back quickly. This is the normal way of doing in my opinion... Especially because you don't get the VPN working - as the routes are allways deleted. This is a complete unexpected behaviour. Anyway, I filled a bug report Good deal. That's the way to get developer eyes on it.
  • 3rd Party VPN and OpenVPN

    4
    0 Votes
    4 Posts
    511 Views
    V
    @dmd1234498 No, that's not noteworthy if the VPN server isn't at the other side of the globe. There are only some more hops to the webserver.
  • openvpn to pfsense to s2s to aws

    6
    0 Votes
    6 Posts
    577 Views
    M
    okay i switched to bgp instead and added the p2 and now it works.. go fig.
  • Forwarding a port to an OpenVPN client

    3
    0 Votes
    3 Posts
    473 Views
    M
    @Derelict Hi, yes your reply is correct. Basically no extra configurations are needed. However, there is a caveat: If I enable Force all client-generated IPv4 traffic through the tunnel option and clients rely on DNS service to find the IP of the OpenVPN server, after rebooting my pfsense firewall, all the OpenVPN clients could permanently lose their connections (both VPN and Internet connections). I end up calling colleagues to reboot all clients physically to re-establish the connection.
  • Turn off OpenVPN Password required on boot

    2
    0 Votes
    2 Posts
    826 Views
    viktor_gV
    Be sure that User Authentication Settings on the OpenVPN client configuration page not empty: [image: 1593080671359-screenshot-from-2020-06-25-13-23-52.png] Fill in the username and password fields
  • "OpenVPN" vpn don't see/ping LAN

    3
    0 Votes
    3 Posts
    522 Views
    M
    @Massimo-S sorry, i reply miself now it works correctly i've disabled the option "dynamic IP" in the OpenVPN server settings page the vpn remote clients now see/ping all LAN servers and services massimo
  • 0 Votes
    2 Posts
    363 Views
    JKnottJ
    @Tenou They can only use an address within the tunnel range. So, you write your rules accordingly. If needed, you can even restrict the address range by using a longer subnet mask, to the point where there's only one address that will work. Also, if you're worried about that sort of thing, then you should be implementing other security beyond just VPN addresses. For example, if you're on a corporate network, you might be using Active Directory or similar to restrict what users can access.
  • HELP ME, PLEASE ... how to create site to site with openvpn on pfsense

    5
    0 Votes
    5 Posts
    487 Views
    GertjanG
    Start here focus on the "Science and technology" explanation. If needed, you could also look up the "IP" word. What @Rico was saying : use a RFC1918 type IP. Not the other ones.
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.