• Problem Speed

    1
    0 Votes
    1 Posts
    128 Views
    No one has replied
  • obfuscated Openvpn traffic

    1
    0 Votes
    1 Posts
    265 Views
    No one has replied
  • ISP Throttling VPN

    15
    0 Votes
    15 Posts
    1k Views
    JKnottJ

    @steve-comerford said in ISP Throttling VPN:

    I have changed the ports and also to TCP from UDP on the OpenVPN to try and mask the traffic but the ISP is clearly wise to that, and it hasn't made any difference.

    I'm aware of networks that block VPNs and the way around that is to use TCP port 80 to get through the firewall. That might also work for throttling, if that's actually what's happening.

  • Create an Outbound route - Client to Site

    7
    0 Votes
    7 Posts
    594 Views
    JKnottJ

    @viragomann said in Create an Outbound route - Client to Site:

    Add 192.168.20.15/32 to the "local networks" in the OpenVPN server settings.

    How does the right side network know how to reach that user? This is a perfect example of why using the same subnet for 2 networks is a bad idea.

    BTW, several years ago I used to do a lot of travelling with my work. I'd find myself in a hotel somewhere, unable to reach my home network, as it was the same subnet as the hotel. After running into that a couple of times, I decided to move my home network to 172.16.0.0 /24, as I had only once seen anything in 172.16 used elsewhere.

  • OpenVPN Site-to-Site unable to reach server side from localhost

    5
    0 Votes
    5 Posts
    421 Views
    M

    @viragomann Again, thanks a lot! If those issues were at least mentioned in the documentation - which appears to be a cookbook - one would have to ask fewer questions.

  • After Update to 23.09 Performance and stabillity issues

    11
    0 Votes
    11 Posts
    1k Views
    DaddyGoD

    @sig1980 said in After Update to 23.09 Performance and stabillity issues:

    something wrong with AES-NI Acceleration

    Hi,

    Thanks for the info, just upgraded and it is indeed better...
    I still think it's less, ..... my usual speed (600-650), but this may be time interval dependent, I'll measure at other times.

    9ea05dcf-083d-47ff-8899-743060e9a460-image.png

    CDN77 gives the transit network to us, and it's darn well loadable, with no typical fluctuations.

    What I find funny is that this hasn't been a problem for anyone but us?
    There was a dead silence on this 🙃

    PS:
    long ago here on the forum, if there was such a VPN performance problem, - the thread would have spun up...
    Thanks again for pointing this out to me (23.09.01), now I'm about to revert to CE everywhere in our deployments, but I'm already testing OPNsense as well.

  • Access Tunnel network from Remote Access VPN instance

    2
    0 Votes
    2 Posts
    255 Views
    V

    @mzaknoen
    You have to add the access server tunnel network (192.168.1.0/24) to the "remote networks" on the remote peer to peer endpoint to add the route for it back to the office.

  • Open VPN Client spawns blank/empty interface

    1
    0 Votes
    1 Posts
    198 Views
    No one has replied
  • Problems with OpenVPN and Azure VPN

    2
    0 Votes
    2 Posts
    270 Views
    E

    @Ehughes-0 After some other issues have come to the forefront it appears this is more of an issue with Azure VPN than an issue with OpenVPN. I will update once I have a solution but I am engaging Azure for assistance with this.

  • OpenSSL hardware crypto engine functionality is not available

    4
    0 Votes
    4 Posts
    2k Views
    tinfoilmattT

    @bchan you could review kernel initialization by running...

    sysctl -a

    ...if you want to review what might not have 'come up' properly. a subsequent reboot could then affirm or disaffirm any findings.

  • Using a VPN to connect a remote reverse proxy to lan servers?

    1
    0 Votes
    1 Posts
    325 Views
    No one has replied
  • Recommended method for migrating from SHA1 cert to SHA512 cert

    4
    1 Votes
    4 Posts
    515 Views
    J

    @jimp Thanks for the clarification. We have not upgraded to 2.7.1 and we will attempt to get that changed over seamlessly for the user.

  • 0 Votes
    9 Posts
    4k Views
    S

    @Gertjan

    that make sense!

    My servers/clients certs are long time ago ecdsa-with-SHA512 but I see this drop down and it look like the default has changed.

    ExportVPN 2023-12-01_15-40.png

    Maybe some of my VPN exports in 2022 was still in the old legacy version and thats the problem now.

  • multiple client sites: which architecture to choose

    45
    0 Votes
    45 Posts
    6k Views
    S

    @viragomann thanks for the long reply, I appreciate your help and your patience ;-) (btw. it seems we could "talk" in german as far as I understand ... would have to happen in the "German" section of this Forum, I assume)

    No, I don't want to bridge 60 client subnets. I wondered if a bridge would help in the shops where the openvpn client appliances run. Right now in my test shop the specific PCs run behind the SG1100 and are in a separated LAN there.

    I should draw a new diagram ...

    Right now the customer is testing things and sounds happy so far. I expect him to plug more PCs into that subnet today ... maybe the current setup already is good enough (while not yet perfect maybe).

    It's very likely that I mix up concepts. You list NAT and routing as 2 ways of doing that, I maybe still don't fully see the lines between. As far as I understand right now, I currently have NAT and routing in place ...

    Let me come up with another diagram, this time maybe more beautiful and with more details. I'd really like to get this as clean as possible before I have to scale it up to N vpn clients.

    good morning from my side ...

  • OpenVPN TLS error: Unsupported protocol - Yealink IP Phone

    8
    0 Votes
    8 Posts
    2k Views
    jimpJ

    Even if you get past that encryption error it will reject the certificates since Yealink's firmware only supports SHA1 certificates, and SHA1 certificates are not valid on OpenSSL 3.x

  • 0 Votes
    2 Posts
    333 Views
    V

    @ndemarco
    You have to use different CAs on each server. So only users, who owns a client certificate from a certain server, can connect.

  • Running two VPN on one pfsense firewall/device

    7
    0 Votes
    7 Posts
    1k Views
    N

    @viragomann Thank you for these explanations, everything is clear now :)

  • Client Specific Overrides Bug with Alias in IPv4 Tunnel Network

    3
    0 Votes
    3 Posts
    348 Views
    OdetteO

    Ok, so I suggest to review the description of the input field from:

    The virtual IPv4 network or network type alias with a single entry used for private communications between this client and the server expressed using CIDR (e.g. 10.0.8.5/24). With subnet topology, enter the client IP address and the subnet mask must match the IPv4 Tunnel Network on the server. With net30 topology, the first network address of the /30 is assumed to be the server address and the second network address will be assigned to the client.

    to:

    The virtual IPv4 network (or, just for net30 topology, a network type alias with a single entry) used for private communications between this client and the server expressed using CIDR (e.g. 10.0.8.5/24). ...
  • Successful logins YubiKey (smartcard) & AD creds with OpenVPN

    6
    2 Votes
    6 Posts
    2k Views
    S

    @dimnovotny

    thank you for your howto. Did you find a way to detect id-changes and automate the configuration generation für pkcs11-id?

  • 0 Votes
    14 Posts
    11k Views
    jimpJ

    It shouldn't be a problem either way if you use a current version of pfSense with the current version of the export package. It properly sets the encryption on the PKCS#12 archive to be "high" by default which is compatible with OpenSSL 3.x. If you need to export for macOS/iOS (which don't support "high" level encryption on PKCS#12) you can set it to "low" which uses an older algorithm that is supported by both OpenSSL 3.x and macOS/iOS.

Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.