• Multiple OpenVPN connections: All have the same Virtual Address

    5
    0 Votes
    5 Posts
    3k Views
    R
    I’m having the same scenario. 2 Torgaurd VPN clients, and they end up with the same virtual IP addresses, and traffic through the VPN stops. A restart of pfsense would previously resolve the issue by assigning different virtual IP’s, but over the last week or so both connections get the same. Any ideas on how to stop this from happening.
  • configure openvpn client to site with preshared key?

    1
    0 Votes
    1 Posts
    171 Views
    No one has replied
  • Limit allowed users

    4
    0 Votes
    4 Posts
    590 Views
    V
    @topogigio Yes, with TLS auth, only clients with a certificate signed by the CA which is selected in the server settings are allowed to connect. You can additionally check „strict user CN matching“ to ensure all clients can connect with their own cert.
  • 0 Votes
    9 Posts
    769 Views
    M
    Effectively, in It support we always have to use imagination for different solution for the dumbest users! :) I've didn't implement and test the solution, but I'm sur it will works!!! Thanks all and have a good day!
  • Site to site OPenVPN traffix not working outside appliance

    4
    0 Votes
    4 Posts
    590 Views
    K
    @marvosa Here are the configs. SERVER: dev ovpns5 verb 1 dev-type tun dev-node /dev/tun5 writepid /var/run/openvpn_server5.pid #user nobody #group nobody script-security 3 daemon inactive 300 keepalive 10 60 ping-timer-rem persist-tun persist-key proto udp4 auth SHA256 up /usr/local/sbin/ovpn-linkup down /usr/local/sbin/ovpn-linkdown local 10.0.1.2 ifconfig 10.1.15.1 10.1.15.2 lport 1200 management /var/etc/openvpn/server5/sock unix route 10.1.11.0 255.255.255.0 secret /var/etc/openvpn/server5/secret data-ciphers AES-256-GCM:AES-128-GCM:CHACHA20-POLY1305:AES-256-CBC data-ciphers-fallback AES-256-CBC allow-compression no explicit-exit-notify 1 CLIENT: dev ovpnc3 verb 1 dev-type tun dev-node /dev/tun3 writepid /var/run/openvpn_client3.pid #user nobody #group nobody script-security 3 daemon keepalive 10 60 ping-timer-rem persist-tun persist-key proto udp4 auth SHA256 up /usr/local/sbin/ovpn-linkup down /usr/local/sbin/ovpn-linkdown local 10.1.20.2 lport 0 management /var/etc/openvpn/client3/sock unix remote remote_host.ddns.net 1200 udp4 ifconfig 10.1.15.2 10.1.15.1 route 192.168.1.0 255.255.255.0 secret /var/etc/openvpn/client3/secret data-ciphers AES-256-GCM:AES-128-GCM:CHACHA20-POLY1305:AES-256-CBC data-ciphers-fallback AES-256-CBC allow-compression no resolv-retry infinite explicit-exit-notify 1
  • Single server, multi site, shared key OpenVPN config?

    7
    0 Votes
    7 Posts
    768 Views
    F
    @rico it's just a pain in the proverbial behind...
  • 0 Votes
    1 Posts
    233 Views
    No one has replied
  • Problem with discovered local ip in openvpn

    6
    0 Votes
    6 Posts
    831 Views
    GertjanG
    @umm12 said in Problem with discovered local ip in openvpn: but when i used firefox See here : [image: 1631100332227-0f42851a-7f5a-45ff-8a81-003f9929a760-image.png] These are the webrtc options. what all these options mean, I can't tell. See the manual. Btw : why asking here ? Firefox support could help you ;)
  • LAN traffic not routing through OpenVPN

    10
    0 Votes
    10 Posts
    3k Views
    C
    @kom OK, found the issue, it was basically this: https://forum.netgate.com/topic/82412/pia-openvpn-gateway-offline the solution was to go into System / Routing / Gateways, and to set the Monitor IP in the VPN gateway to an IP that accepts pings (or to turn off gateway monitoring). Then the status of the gateway switches to online. Then my PC connects to the internet through the VPN. I just don't understand why the same problem didn't occur on my private switch setup. Perhaps because it is an earlier version of pfsense (2.4.4-p2)
  • Issues connecting to remote clients

    2
    0 Votes
    2 Posts
    389 Views
    C
    @ctech I fixed it. You need to go to the client-specific[image: 1631044736550-screen-shot-2021-09-07-at-6.50.28-am-resized.png] overrides and add your network as shown:
  • OpenVPN client traffic to Starlink (CGNAT)

    6
    0 Votes
    6 Posts
    5k Views
    R
    @peterthompson Hi i have the same problem, I am using Starlink and a router with OpenWRT and installed OpenVPN.. on slow DSL it is working fine, but with the Starlink I can't connect VPN, it fails on TLS Handshake. can you maybe give details, how you get OpenVPN and Starlink working? :)
  • Change Default TTL for openvpn clients

    1
    0 Votes
    1 Posts
    211 Views
    No one has replied
  • how to route openvpn tunnel traffic through squid proxy server?

    9
    0 Votes
    9 Posts
    3k Views
    V
    @umm12 said in how to route openvpn tunnel traffic through squid proxy server?: but i have port 6000 for squid proxy server. I do not use this port on Remote networks on client side of Pf-1??? So you want to use the proxy in transparent mode, but on port 6000? I‘m not really family with proxying, but don’t think it can work this way. Maybe it does when you forward the traffic to port 6000 on pf1.
  • how to prevent to discover and scan other connected openvpn clients?

    5
    0 Votes
    5 Posts
    652 Views
    U
    @johnpoz I using layer 3 tunnel mode. How i can disable arp on openvpn clients in pfSense?
  • Azure Vnet to pfSense client OpenVPN

    1
    0 Votes
    1 Posts
    242 Views
    No one has replied
  • FreeRADIUS+OpenVPN

    2
    0 Votes
    2 Posts
    406 Views
    A
    @abracadabras The problem is solved. I have several CA, I had to choose the FreeRADIUS CA certificate in the OpenVPN setup.
  • DNS problems vor connected clients having dual stack ipv4/v6

    10
    0 Votes
    10 Posts
    1k Views
    johnpozJ
    @heiko-ecm4u said in DNS problems vor connected clients having dual stack ipv4/v6: office has only a ipv4 had no need until now ... Prob be that way for 10+ more years at least if not longer.. Until such time that major players go IPv6 only - offices have little need of IPv6 to be honest.
  • 0 Votes
    6 Posts
    683 Views
    Bob.DigB
    @gertjan Yes. The reason is to use the always-on vpn-feature in android and not manually have to to anything for a vpn connection at anytime. Also OpenVPN for Android works as an app firewall, so I can block apps to access the internet at anytime.
  • Communication between one hosts on OpenVPN isolated

    2
    0 Votes
    2 Posts
    496 Views
    V
    @fuxxik pfSense cannot control the traffic between OpenVPN clients, this happens within OpenVPN and here you only can allow all inter-client communication or not. To achieve what you want, you will have to set up an additional OpenVPN server on pfSense for that specific client. This way the traffic to this client has to pass pfSense and you can control it by filter rules.
  • Will the recent openssl vulnerabilities affect OpenVPN?

    1
    0 Votes
    1 Posts
    213 Views
    No one has replied
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.