@Murrayd222:
Greetings,
I'm curious if it is possible to run an OpenVPN server to permit remote connections to my network, via iPad and scuh, while also taking advantage of the benefits offered by Private Internet Access. I finally got my OpenVPN server up and running and remote connects now work flawlessly. However, when I installed PIA as instructed in the PIA pfsense router setup, the status shows as "down." The only step I skipped was deleting the various certificates required to make the OpenVPN server work.
I'd like the benefits of remote access to my network as well as the benefits provided by PIA. Any suggestions or guides that I've missed. My experience with pfSense consists of about a month, with MANY failures trying to get the OpenVPN server up and running.
EDIT: Ok, after more tweaking, factory resetting, and more tweaking…I have everything working except one thing. I can connect to my network via the OpenVPN server, I have the PIA VPN Client pushed to the network IP addresses I want going through the VPN. I can remotely access both Plex and my Blue iris surveillance server. However, there is one thing I cannot get figure out and I'm sure it has to do Firewall Rules or NAT Outbound rules. When remotely connecting to my OpenVPN server, I want those connections to be able to access the Internet as well. Currently, any remotely connected client to my OpenVPN server can access network IPs only and any attempts to connect to the Internet are being blocked. The OpenVPN Server is assigned its own openvpn interface and the PIA Client is assigned its own unique PIA Interface. If I disable the PIA client, then my OpenVPN Server connections are able to access the Internet. Once I restart the PIA client, the Internet access of the OpenVPN Server connected clients stops. Anyone have a suggestion or guide on how to setup the needed rules?
EDIT 2: Well, the recently changed NAT Outbound (posted below) granted my OpenVPN Server remotely connected clients to access the Internet, but it broke their ability to access LAN clients. How can I get both Internet and LAN access for clients remotely connected to the OpenVPN Server?
EDIT 3: Never mind, all is working correctly, but for some reason the remote desktop cliet on my iPad isn't connecting this morning where as the RD app on my iphone is.
Current NAT Outbound Rules:
[image: y4mEXk7KoQU4B6sPRulJ_3SN2BOScjfJynnv8r4UlVNvOxBcscO3eIZrI4cg39LE1QJHkYVcJRHesBtzdJy9YpkBIvgAfmQEyUXF0HzPY-tQvEGfVGMT8ASmZNu3vtbX_qsT1GVVagx9fzJTUBvkDl4pw3T9nC_ZGQAVKtt6-ymNDlFKnz-uZeb_olGAoKDIvPpjWS8vVK-RhlFUg45izcphg?width=1153&height=681&cropmode=none]
Current Firewall Rules for WAN:
[image: y4mySYudi7gkWW8wEFYd_G1W890iw462qh1MsshjdxO1-fGHQZqHwDQszktCJ2WcdIG5zV5VYNNEzbofY1wXUvEqx4JxzmpLmU3d5Er9QcSb9ARWxe8HAMYgZnS753dpHfGBzQtRTjLWtD1tM3LC0V-p5q1cLvVUVOMHNv8t3s6iy3KwXCZd1-qKRy_NzUl-cxkTXJs9khUZCIutISxj-Z0Nw?width=1151&height=401&cropmode=none]
Current Firewall Rules for LAN:
[image: y4mrTSc2Ovy84OczAWnfQoe0StvXA3q0zTRXuopL8cSTC6L4OYTBZbtKXdcCrDHgjI-BbIsQRl3XWxreywm08I12hgOh98twt297-sKOFcNulD4g-AFnbE3jD7np9LhRdXx4ozY3YutyPmDw438yNhhgeTItJ5v20wTJ2UiWsVpJVfPL0133FVTt_4KGHYHHZlq7wtq2ZD76mqe3wcWiErDTA?width=1151&height=541&cropmode=none]
Are these above your working settings? Can you please please share your current working settings? I can't get them to work together no matter what I tried. I've spent the better part of the past 3 days epxerimenting with all possible combinations. I did factory resets, installed the server first and then the client and vice versa. Played with all the possible rules I could think of. Duplicated the existing outbound NAT with values both for OpenVPN and PIAVPN.
I would be greatful if you could share the server's and client's config as well as the rules in WAN, LAN (or anywhere else) and also your NAT/outbound tab.
I have created separate interfaces for the PIA Client and the OpenVPN server while the ''don't pull routes'' option suggested by @viragomann disables completely the PIA client and then magically the OpenVPN server will accept the connection from my Android client.
I have already asked in several topics but failed to draw any attention so I'm hoping you could help me out.
Otherwise I'll have to open a new thread. I just did not want to do as there are many like us who had the same issue and the forum is full of similar threads…