• 0 Votes
    2 Posts
    3k Views
    DerelictD

    You need to push the IPv6 /64 as a route. It needs to be distinct from the tunnel network. I assume you have more than a /64 to use? /48 or /56?

    Similar to how HE's TunnelBroker provides IPs, Unfortunately TunnelBroker does not work in this case because they Block CloudFlare (YES THEY FREAKING BLOCK CLOUDFLARE!!!).

    Based on my experiences with HE over the years, if they did in fact block these sources, they have a good reason for doing so.

  • outbound NAT for multi site vpn, all client traffic through server?

    10
    0 Votes
    10 Posts
    1k Views
    DerelictD

    Client-specific overrides are is required for SSL/TLS with a larger than /30 tunnel network when you have remote subnets/routes above and beyond the tunnel address for a Remote Access client.

    There is really no difference between a Remote Access server and a point-to-multipoint site-to site network other than different requirements for pushing routing and CSOs. They are the same OpenVPN server mode.

  • AES-NI Doubt?

    3
    0 Votes
    3 Posts
    637 Views
    perikoP

    Them will tested, thanks for your help.

  • 0 Votes
    4 Posts
    1k Views
    P

    @treborjm87

    I'd be curious about this as well...

    I think you need to establish how much throughput/bandwidth you need and how many concurrent user connections you anticipate, etc? (Is this box dedicated to routing and VPN only or more exotic use cases like running VMs, etc)

    I've seen some charts floating around with hardware recommendations based on required throughput here and at the servethehome website.

  • PfSense 2.4.3, OpenVPN not connecting to client

    5
    0 Votes
    5 Posts
    1k Views
    L

    @AlexVP I ended up using only one WAN.

    As soon as I got rid of the second WAN, OpenVPN started working correctly. Under Firewall > Rules, I added rules to both LAN interfaces so they can't access each other. For the WAN interface, I added rules & under NAT > Port Forward I mapped the WAN ports to the CCTV LAN so it works how we need it to.

    I know our network is fairly simple, but if you can make it work with one WAN it'll be a lot easier to manage. If I do set up a second WAN, I'll let you know what I did to make it work.

    Thanks for the tips @Gertjan. If I had added logs it would've made it a lot easier to figure out what I did wrong. I made it work with one WAN, and I'm leaving it that way unless I need to change it.

  • Slow http traffic with OpenVPN clients

    1
    0 Votes
    1 Posts
    407 Views
    No one has replied
  • Connect VPN Clients to Local network behind other client...

    3
    0 Votes
    3 Posts
    536 Views
    A

    Hi Rico,

    thank you for your answer. I had a look to your link. I think this would work, but if the subnet on LAN on the pfsense boxes is changed I need to reconfigure everything.

    Is there no option like:

    On the VPN Server:
    Route ALL traffic from User-01 to VPN network of pfsense box1

    On the Pfsense Box side:
    Route ALL traffic on VPN network to OPT1 network

    Sorry for my question, but I´m a beginner with OpenVPN and pfsense...

    Thank you so much for your support.

  • Unable to get Openvpn 2.4.6 to work on pfsense 2.4.4

    7
    0 Votes
    7 Posts
    1k Views
    JKnottJ

    @jknott said in Unable to get Openvpn 2.4.6 to work on pfsense 2.4.4:

    You don't set up DNS on the VPN. You do it on the client or DHCP server config.

    My mistake, there is a setting on the server config, under Advanced Client Settings.

  • Server listening on different interfaces

    7
    0 Votes
    7 Posts
    741 Views
    johnpozJ

    So your running HA pair setup... Kind of should of mentioned this out of the gate ;)

    Why would you be running public IP vip on a rfc1918 network and then forwarding to it?

    If you have traffic hitting interface X, and you wan it to be able to get to the IP and port your vpn instance is listing on - then just put a rule on that specific interface X to allow allow it.

  • OpenVPN and native OTP support with google authentication

    2
    0 Votes
    2 Posts
    257 Views
    jimpJ

    Install the FreeRADIUS3 package and setup OTP/GA in there, and setup OpenVPN to hit that for auth, and use it today. No need to use an extra OpenVPN plugin or to reinvent the wheel.

  • openvpn export

    2
    0 Votes
    2 Posts
    360 Views
    DerelictD

    Client export is not for Site-to-Site. It is for exporting configurations for Remote Access clients.

    Configure both sides to match and you should be all set.

  • OpenVPN on iOS connects, but no traffic

    3
    0 Votes
    3 Posts
    2k Views
    J

    @bigsy wow! thanks. After trying stuff for 3 hrs this tip was the answer.

  • FreeRADIUS - Google Authenticator (description/name/tag)

    1
    1 Votes
    1 Posts
    357 Views
    No one has replied
  • multiwan openvpn link aggregation

    2
    0 Votes
    2 Posts
    504 Views
    jimpJ

    https://www.netgate.com/resources/videos/advanced-openvpn-on-pfsense-24.html

  • Slow DL but Fast UL

    1
    0 Votes
    1 Posts
    281 Views
    No one has replied
  • This topic is deleted!

    1
    0 Votes
    1 Posts
    28 Views
    No one has replied
  • Routing loop with my configuration

    1
    0 Votes
    1 Posts
    400 Views
    No one has replied
  • No Traffic into OpenVPN Tunnel until Static Route is set

    2
    0 Votes
    2 Posts
    373 Views
    V

    @kekskrümel said in No Traffic into OpenVPN Tunnel until Static Route is set:

    0.0.0.0/1 to the tunnel gateway 10.100.6.29

    0.0.0.0/1 is only the half IPv4 range, so this cannot stand for the default route.

    Furthermore, how have you set that route? A static route on pfSense or a CSO?

    Are you talking about an access server and you want to route the whole traffic of only one client over the VPN?
    So if the server uses TLS/SSL auth set up a CSO for the clients cert common name and check "redirect gateway".

  • Configuring pfSense as OpenVPN client

    17
    0 Votes
    17 Posts
    4k Views
    DerelictD

    What VPN provider is this?

    Have you verified that the routes being pushed actually cover the addresses of the sites you think should be routed that way?

    Are any of the route add logs indicating failure?

    Are the pushed routes actually going tinto the routing table?

    If so, pfSense and OpenVPN are working fine here.

  • 0 Votes
    4 Posts
    3k Views
    V

    https://www.netgate.com/docs/pfsense/virtualization/virtio-driver-support.html

Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.