• Running two VPN on one pfsense firewall/device

    7
    0 Votes
    7 Posts
    2k Views
    N
    @viragomann Thank you for these explanations, everything is clear now :)
  • Client Specific Overrides Bug with Alias in IPv4 Tunnel Network

    3
    0 Votes
    3 Posts
    409 Views
    OdetteO
    Ok, so I suggest to review the description of the input field from: The virtual IPv4 network or network type alias with a single entry used for private communications between this client and the server expressed using CIDR (e.g. 10.0.8.5/24). With subnet topology, enter the client IP address and the subnet mask must match the IPv4 Tunnel Network on the server. With net30 topology, the first network address of the /30 is assumed to be the server address and the second network address will be assigned to the client. to: The virtual IPv4 network (or, just for net30 topology, a network type alias with a single entry) used for private communications between this client and the server expressed using CIDR (e.g. 10.0.8.5/24). ...
  • Successful logins YubiKey (smartcard) & AD creds with OpenVPN

    6
    2 Votes
    6 Posts
    2k Views
    S
    @dimnovotny thank you for your howto. Did you find a way to detect id-changes and automate the configuration generation für pkcs11-id?
  • 0 Votes
    14 Posts
    12k Views
    jimpJ
    It shouldn't be a problem either way if you use a current version of pfSense with the current version of the export package. It properly sets the encryption on the PKCS#12 archive to be "high" by default which is compatible with OpenSSL 3.x. If you need to export for macOS/iOS (which don't support "high" level encryption on PKCS#12) you can set it to "low" which uses an older algorithm that is supported by both OpenSSL 3.x and macOS/iOS.
  • AES-NI

    7
    0 Votes
    7 Posts
    885 Views
    C
    @dave-opc I had the workstation as my work computer for a while and it had no updates, it's an old Fujitsu Celsius M740. I will check again, have to switch to the 2nd machine and put back the windows disk.
  • openvpn server fails after openvpn-client-export update

    1
    0 Votes
    1 Posts
    345 Views
    No one has replied
  • 0 Votes
    11 Posts
    2k Views
    G
    @viragomann said in Tried to change ovpn p2p from shared key to SSL/TLS... Connection done but no rooting... same settings: @gsp said in Tried to change ovpn p2p from shared key to SSL/TLS... Connection done but no rooting... same settings: So in any case CSO is mandatory? If you want to access a network behind the client, it is, as mentioned. The CSO sets the iroute inside the OpenVPN server. This is needed to route the traffic to the proper client. This routes will not shown up in the routing table of pfSense. There you will only see the network, which you stated in the server settings. Thank you for your help! I have some sites interconnected with shared key option... Should I go to IPSec or ovpn p2p ssl , what do you think better? Because for many sites IPSec is now much easier setup... :)
  • OpenVPN Site-to-Site issue

    3
    0 Votes
    3 Posts
    553 Views
    mohkhalifaM
    Any Help ?
  • Addressing CVE-2023-46850 in pfSense V2.7.0

    6
    0 Votes
    6 Posts
    869 Views
    S
    @luquinhasdainfra yes you cannot upgrade packages for a later version. See my sig.
  • Unifi best site-site alternative

    11
    0 Votes
    11 Posts
    3k Views
    B
    @SteveITS Since posting that I tried and got working and came back here and noticed your reply. I didn't forward a port since my pfsense is static but good to know that it can be done. However it seems to go offline a couple times sometimes and needed "coaxing" to get it back connnected (but in all fairness I was messing around with it lots)... I found changing a setting like tunnel name on UniFi S2S VPN Page would make it work again (reset button in status column didn't do anything when in this state, nor did pausing/unpausing). Using hostname instead of IP does not appear to work even though it is a new feature, and unifi does not show any status that it is connected like OpenVPN, but that is support issues for UniFi, I suppose not here.
  • OPENVPN-ROUTE-STRANGE-BEHAVIOUR

    4
    0 Votes
    4 Posts
    433 Views
    J
    @viragomann No my firewall rule only accept specific vpn network to specific local subnet The linux behaviour was exacly a test on any/any Therefor i found this issue where windows obey and linux does not give a shit :)
  • OpenVPN standalone migration to pfSense+ OpenVPN

    7
    0 Votes
    7 Posts
    709 Views
    D
    @viragomann Yes, the users are already created on the current server.
  • 0 Votes
    1 Posts
    315 Views
    No one has replied
  • VPN DNS (i.e. PIA or NordVPN) and/or DNS over TLS - Which way to go?

    51
    0 Votes
    51 Posts
    19k Views
    Y
    @talaverde said in VPN DNS (i.e. PIA or NordVPN) and/or DNS over TLS - Which way to go?: o DNSSEC/TLS enabled DNS servers. No issues of leakage that I'm aware of. DNS requests are much quicker than using the VPN This is 4 and half years too late, but can you please share the instructions on how you route your VPN DNS queries through your local DNS
  • Routing

    2
    0 Votes
    2 Posts
    329 Views
    V
    @tbgu87 Hi, das ist der internationale Bereich. Hier sollten Posts in Englisch verfasst sein. Für Deutsch gibt es einen eigenen Bereich. Die Endgeräte bekommen die Routen richtig gepuscht. Hast du dir das in der Routingtabelle am Client angesehen? Oft wird die Route auf den entfernten Netzen zum Access Server Tunnel Netz vergessen. Also je nachdem, wie du die Site-to-Site Verbindungen eingerichtet hast, ist das Client Tunnel Netzwerk da irgendwo als "Remote network" einzutragen.
  • Security alert on OpenVPN 2.6.5 (PfSense+ 23.09) CVE-2023-46850

    13
    1 Votes
    13 Posts
    2k Views
    M
    @jimp Hi, thanks for the answers ! Regarding the fact that the pfsense 2.6.0 CE version is impacted, for my part I was able to confirm that last week that on one of my firewalls in 2.6.0 not up to date I had available the 2.5.4 package of openvpn while today I have version 2.6.4. What is strange is that as https://cve.mitre.org/ indicates, only versions 2.6.0 to 2.6.6 are impacted... [image: 1700737714175-09adf418-f563-483c-a369-5e4d60d0cff7-image.png] [image: 1700737726341-0ee2dbd6-cc83-41b3-9214-51f9a43b7792-image.png] [image: 1700737471188-911df671-4911-41c9-8a99-96362055474f-image.png] [image: 1700737484585-49e14baa-a9bd-40b3-997f-36603c82f552-image.png] To conclude, you must upgrade to pfsense CE version 2.7.1
  • pfsense openvpn won't connect from certain cable providers ?

    72
    0 Votes
    72 Posts
    13k Views
    johnpozJ
    @pfchangs77 said in pfsense openvpn won't connect from certain cable providers ?: supervisors/managers Yeah they not going to know squat, you need to talk to one of their upper level tech/engineers ;)
  • openvpn tap tunnel goes offline

    openvpn tap
    1
    0 Votes
    1 Posts
    361 Views
    No one has replied
  • OpenVPN Slow IPerf

    1
    0 Votes
    1 Posts
    291 Views
    No one has replied
  • OpenVPN Client disconnects every few seconds - ExpressVPN

    9
    0 Votes
    9 Posts
    5k Views
    A
    @dimangelid it also worked for me, thank you very much have a good day.
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.