• IP Address Assignment

    3
    0 Votes
    3 Posts
    985 Views
    F
    Yes, thanks. Completely blew past that setting/working now
  • NordVPN question

    2
    0 Votes
    2 Posts
    2k Views
    U
    NVM I figure it out.
  • 0 Votes
    8 Posts
    1k Views
    P
    This is a lab VM inside my LAN so bogus IPs but same concept. http://imgur.com/a/nP8jc  Nat and Rules tabs. Have it setup like this in lab environment: OpenVPN (server) >> pfSense >> OpenVPN (client) Server and Client are Ubuntu. Is that what you were looking for?
  • OpenVPN client and MAC OS X losing local settings on Disco

    4
    0 Votes
    4 Posts
    820 Views
    DerelictD
    I don't see that with Viscosity.
  • New to VPN's, please help me with config.

    6
    0 Votes
    6 Posts
    1k Views
    N
    That was it. Thank you very much.
  • MTU & MSS Clamping

    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • Have problem with openvpn pfsense 2.3.2_p1

    4
    0 Votes
    4 Posts
    4k Views
    jimpJ
    Upgrade your OpenVPN client export package again. There was an issue in the posted version temporarily for a few hours.
  • Cannot access networks on a OpenVPN Site-To-Site Setup

    2
    0 Votes
    2 Posts
    756 Views
    V
    Are both pfSense boxes the default gateways within their networks?
  • How to create OpenVPN client for Hide My Ass ! VPN

    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • OpenVPN won't accept connections after WAN disconnects

    6
    0 Votes
    6 Posts
    3k Views
    S
    This is some really strange behavior, but you can try to somewhat mitigate it: move your VPN server to Localhost interface (bind to localhost) and NAT needed port from WAN interface.
  • Grant access to only one server in OpenVPN

    3
    0 Votes
    3 Posts
    1k Views
    V
    Same as you grant any other access in pfSense. Go to Firewall > rules > OpenVPN and modify the allow-any-to-any rule. As source enter the VPN tunnel subnet and at destination the host address you want to allow the access. If you provide DNS to the VPN clients, you have also to add rule for DNS access.
  • Monit to Control VPN Down

    2
    0 Votes
    2 Posts
    705 Views
    K
    You can use Services Watchdog for pfsense services monitoring, if are having openvpn hang problems, the proccess still is there but unresponsive like a zombi and service chekers does not work, try removing openvpn pluging from main dashboard. https://forum.pfsense.org/index.php?topic=116670.0
  • Cannot reach clients in the lan network, only the internal LAN IP

    20
    0 Votes
    20 Posts
    5k Views
    A
    @Derelict: Internal LAN is a /16, so something like 10.123.0.0/16, default (LAN) DHCP pool is 10.123.100.0/24 (which can talk to everything else, say, 10.123.1.x just fine), and the OpenVPN pool is 10.123.200.0/24. Once I'm properly off-site where I can test I'll re-check the VPN clients are getting the default gateway. Yeah you need to set your OpenVPN pool/tunnel network to something OUTSIDE your LAN subnet to have any prayer of being able to route to it. Or, more accurately, to have a prayer of anything on LAN being able to route back. (Sorry for the delay in replying.) That was the key, once I changed the OpenVPN pool to not be a sub-set of the LAN, all is well. There was a bit of a red herring in testing as the main target I was using is an L3 switch that (understandably) doesn't allow management traffic from a different subnet. Thanks again, and next time I have a question I'll try and get second set of eyes sanity check first.
  • [SOLVED] OpenVPN as failover for dedicated MetroE WAN fails

    2
    0 Votes
    2 Posts
    553 Views
    S
    Disabling negate rules on both sides of the VPN in System>Advanced>Firewall & NAT fixed the issue as policy routing was not being applied properly. Thanks to PiBa-NL in ##pfsense on freenode!
  • Many different clients to different networks.

    2
    0 Votes
    2 Posts
    576 Views
    V
    You may set up 2 separate OpenVPN servers for your user groups which use different tunnel subnets, or you may also do this with only 1 server and configure "client specific overrides" to allocate certain virtual IPs to specific users.
  • OpenVPN to DMZ

    5
    0 Votes
    5 Posts
    3k Views
    S
    Hero Member you are! Thank you very much!
  • TLS (Pros and Cons)

    2
    0 Votes
    2 Posts
    886 Views
    PippinP
    Stuff to read: https://community.openvpn.net/openvpn/wiki/Hardening And here under > Hardening OpenVPN Security < https://openvpn.net/index.php/open-source/documentation/howto.html
  • Combine site-to-site and local user access servers

    3
    0 Votes
    3 Posts
    693 Views
    DerelictD
    As stated, yes. On a different UDP port. Most would use 1195.
  • Problems with openVPN, I can't do pings with computers in the LAN

    5
    0 Votes
    5 Posts
    1k Views
    DerelictD
    Use something outside that subnet for the tunnel network and put 10.10.0.0/16 in the Local Networks on the server.
  • Allow access to specified ip

    3
    0 Votes
    3 Posts
    595 Views
    J
    THX!!
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.