• Query about the pfSense firewall and OpenVPN

    Locked
    14
    0 Votes
    14 Posts
    11k Views
    C

    Gruens that is what i would have told him too. ;D

  • OpenVPN Backup Script

    Locked
    2
    0 Votes
    2 Posts
    4k Views
    B

    Still would like to know how to do this in Linux but I figured it out in Windows.  I am going to try some more with Linux later tonight.

    I downloaded PSKill for windows and was able to accomplish this by using 2 scripts.  Run the Connect_Script then Run Disconnect_And_Backup_Script 10 seconds or so after.

    PSKill can be downloaded here http://technet.microsoft.com/en-us/sysinternals/bb896683.aspx

    Connect_Script.bat
    openvpn –config "C:\path\to\file.ovpn"

    Disconnect_And_Backup_Script.bat
    FOR /f "tokens=2-4 delims=/ " %%a in ('DATE/T') do SET tmpdt=%%a-%%b-%%c
    wget -q --post-data=Submit=download --http-user=username --http-passwd=password --no-check-certificate https://IP:PORT/diag_backup.php -O "C:\path\to\backup%tmpdt%-firewall-config.xml"
    pskill openvpn.exe

  • Issue with multicasting and OpenVPN

    Locked
    1
    0 Votes
    1 Posts
    2k Views
    No one has replied
  • VPN Connects but no access

    Locked
    2
    0 Votes
    2 Posts
    4k Views
    Cry HavokC

    The log file makes it pretty clear you're not pushing any routes to the client.  As such it doesn't know how to get packets anywhere, so it'll never work ;)

    I'd guess you either need to add 192.168.1.0/24 to the "Local network" field or add push "redirect-gateway" to the "Custom Options" field.

  • RoadWarrior OpenVPN over UDP failing

    Locked
    4
    0 Votes
    4 Posts
    3k Views
    L

    In your OpenVPN config (i.e. OpenVPN\config\client.ovpn) on the client machine what do you have set up as "proto"?

    If it is set to "proto tcp-client" it needs to be changed to "proto udp"

  • Does OpenVPN remain supported?

    Locked
    4
    0 Votes
    4 Posts
    2k Views
    L

    Nothing to do directly with this thread, but OpenVPN development itself continues after a long stop. New RC has been released. A final version (2.1) when it will be ready :)

    Regards

  • How to Filter a "Road warrior" OVPN connection

    Locked
    2
    0 Votes
    2 Posts
    2k Views
    P

    Asenkevitch,

    I too am a bit scared of a hole as I see it in pfsenses OpenVPN implementation. If my mobile user loses control of his laptop anyone with access to that machine can connect to my network. Yes, I can revoke the keys, but what if my user cant/doesnt tell me for several days. Also the adminsitration overhead of all those certificates gets cumbersome when you start getting beyond 10-15 users.

    You want filtering which could add some protection to certain boxes segments, but what I would like is user authentication via RADIUS. Without the right credentials, nobody gets in. In fact they get locked out. That said,  I have seen several posts of people who have done some twists and turns to get RADIUS, and PAM working, however we use the embedded version which has no package support. So my question is how can an enterprise using pfsense on the embedded platform sleep easy knowing they have certificates and authentication protecting the OpenVPN dooway??

    I would love to help any bounty propsing for out of the box OpenVPN/RADIUS on the embedded platform if anyone knows of one.

    Thanks,

    Pedro

  • TCP or UDP?

    Locked
    4
    0 Votes
    4 Posts
    2k Views
    N

    Right

    Thank you for that info Gruens, that is exactly the question I was meaning to ask.

  • Power cycling and OpenVPN issues

    Locked
    2
    0 Votes
    2 Posts
    2k Views
    C

    Get a bigger UPS ;D

  • Can't ping any Lan clients …

    Locked
    9
    0 Votes
    9 Posts
    4k Views
    I

    solved, i have 2 gateways in both networks, so i have to add the routes to the non-pfsense gateways :-/

  • SITE 2 site no DNS ping

    Locked
    2
    0 Votes
    2 Posts
    2k Views
    C

    any thing????

    am i the only one that has the problem?

  • Connecting to WAN2 with OpenVPN

    Locked
    8
    0 Votes
    8 Posts
    4k Views
    K

    Well it seems to work sometimes. It seems like it I coming in one and going out the other. Normally I have to kind of play with the connection to get it to work. Any thoughts?

  • GUI Bug on 1.2RC3

    Locked
    3
    0 Votes
    3 Posts
    2k Views
    M

    1.2RC3.

    The boxes are ALIX WRAP systems and they're in remote locations so I'm not able to upgrade to 1.2RC4.

  • 0 Votes
    8 Posts
    9k Views
    M

    Hi again,

    Here are the IP4 routes from netstat -nrW:

    pfsense A
    Destination        Gateway            Flags    Refs      Use    Mtu    Netif Expire
    default            194.XXX.XXX.253    UGS        0  168620  1500      vr1
    10.0.20/24        10.0.20.2          UGS        0    20300  1500    tun0
    10.0.20.2          10.0.20.1          UH          1        0  1500    tun0
    10.0.30.2          10.0.30.1          UH          1        0  1500    tun1
    127.0.0.1          127.0.0.1          UH          0        1  16384      lo0
    192.168.0          10.0.30.2          UGS        0  107810  1500    tun1
    192.168.254        link#1            UC          0        0  1500      vr0
    192.168.254.204    00:0d:93:9d:fd:3a  UHLW        1      392  1500      vr0    702
    192.168.254.240    00:16:cb:a9:e8:67  UHLW        1      43  1500      vr0    437
    194.XXX.XXX.224/27  link#2            UC          0        0  1500      vr1
    194.XXX.XXX.225    00:XX:XX:XX:XX:de  UHLW        1      19  1500      vr1    93
    194.XXX.XXX.227    00:XX:XX:XX:XX:de  UHLW        1        0  1500      vr1    98
    194.XXX.XXX.254    00:XX:XX:XX:XX:0b  UHLW        2    5955  1500      vr1  1189

    pfSense B
    Destination        Gateway            Flags    Refs      Use    Mtu    Netif Expire
    default            220.XXX.XXX.241      UGS        0    81874  1500      vr1
    127.0.0.1          127.0.0.1          UH          0        0  16384      lo0
    192.168.0          link#1            UC          0        0  1500      vr0
    192.168.0.1        192.168.0.2        UH          1        0  1500    tun0
    192.168.0.193      00:16:36:53:c8:64  UHLW        1    5963  1500      vr0  1187
    192.168.0.232      00:19:d1:61:a3:aa  UHLW        1    10363  1500      vr0    939
    192.168.0.233      00:14:2a:8a:1e:42  UHLW        1    7065  1500      vr0  1149
    192.168.0.234      00:14:85:5e:9a:de  UHLW        1    6628  1500      vr0  1144
    192.168.0.236      00:08:a1:92:31:94  UHLW        1    1826  1500      vr0  1140
    192.168.0.237      00:11:5b:f4:1d:ff  UHLW        1    1010  1500      vr0  1200
    192.168.0.238      00:16:76:c5:51:e0  UHLW        1    4272  1500      vr0  1145
    192.168.0.239      00:19:d1:ee:1e:6a  UHLW        1    2951  1500      vr0  1179
    192.168.0.240      00:14:2a:8b:7b:b1  UHLW        1    8819  1500      vr0  1188
    192.168.0.241      00:11:5b:f4:26:4e  UHLW        1      845  1500      vr0  1198
    192.168.0.242      00:14:2a:08:8f:56  UHLW        1      331  1500      vr0    797
    192.168.0.243      00:16:76:c5:58:61  UHLW        1    4768  1500      vr0  1101
    192.168.0.244      00:14:2a:8b:79:df  UHLW        1    1715  1500      vr0  1156
    192.168.254        192.168.0.1        UGS        0        0  1500    tun0
    220.XXX.XXX.240/29  link#2            UC          0        0  1500      vr1
    220.XXX.XXX.241      XX:XX:XX:XX:XX:1f  UHLW        2    3755  1500      vr1  1174

    I've obviously changed the external IP addresses, but the important information is still there.

    BTW, aside from not being able to ping anything on network B from pfSense A, everything else is working fine in terms of cross-network access to internal servers and VoIP systems. Consequently, although I'm academically interested to know what the issue is, please don't bust a gut on this.

    Thanks again.

  • Unir 2 lan

    Locked
    2
    0 Votes
    2 Posts
    2k Views
    Cry HavokC

    Google translation:

    I have my lan at home and want to join the lan of the company, and will then be in the domain of this and use the resources of the company through this magnificent firewall that is Pfsense

    (The Spanish forum may be more appropriate if you don't read/write English - El foro español puede ser más apropiado si no sabe leer ni escribir Inglés)

    So, you want to connect, using a VPN, to your company?  You'll need to:

    a) Have your company set up an OpenVPN server on their network
    b) Give you the certificates (and configuration)
    c) Configure your pfSense host accordingly

  • Firewall: Rules - OpenVPN

    Locked
    2
    0 Votes
    2 Posts
    2k Views
    GruensFroeschliG

    no
    1.2 is frozen since a long time.

  • VPN site-to-site: Error ping between networks

    Locked
    6
    0 Votes
    6 Posts
    4k Views
    M

    Problem solved

    Have make the interconnection of networks through the use of shared key as its aid for site-to-site, I thought that if used certificates, that was the problem, not Tuesday ping between networks A and B.

    Thanks to all

  • OpenVPN Auth-LDAP Plugin

    Locked
    1
    0 Votes
    1 Posts
    3k Views
    No one has replied
  • OpenVPN with Static IP client. HOW ??

    Locked
    11
    0 Votes
    11 Posts
    14k Views
    B

    After following the instructions in the VPN Capability OpenVPN doc to open a VPN Client Bridge, are there any special settings in the Firewall Rules that need to be made? My problem is when the OpenVPN Tunnel is enabled after configuring it with the bridge settings I no longer can send emails. My email program hangs while trying to send and receive email. If I disable the OpenVPN Tunnel I can send email.

    Other than than when the OpenVPN tunnel is enabled offsite roadwarriors can connect without issue.

    For anyone who gets the "ifconfig: BRDGADD tap0: No such file or directory" error check your server bridge entry in the OpenVPN custom options field. The tap0 gave me errors until I realized that the LAN setting for the server bridge was wrong and corrected it and rebooted the machine. The other strange thing is the "<shellcmd>ifconfig bridge0 addm tap0</shellcmd>" entry in the config.xml file seems to not stay at the bottom of the three entries that get entered. After entering them it moved up the next time I looked at the file so it was the first of the three entries for this bridging setup.

  • OVPN Win32 Map Network Drive on Logon?

    Locked
    12
    0 Votes
    12 Posts
    11k Views
    N

    Like I said though, the script works perfectly if I run it manually, the only time it doesn't work is when it is invoked as part of the oVPN process itself.

Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.