• Export OpenVPN certificates without Client Export manager

    3
    0 Votes
    3 Posts
    1k Views
    gtjG
    @viragomann: I don't know about latency issues in 2.4.1 and trouble to install the Client Export package in 2.3.4. However, you can export certs separately if you want. The Client Export tool only bundles config, certs and Windows installer. But why want you use WinSCP? Just use the GUI: System > Certificate Manager > Certificates Thank you very much for your answer. I ended up updating and installing the Export Tool. I'm just hoping I won't have any issues with speeds now…
  • Help please? Home openvpn, 1 pc needs to go through vpn, others wan

    5
    0 Votes
    5 Posts
    662 Views
    B
    firewall > rules > lan add the ip of the devices to the list, then under the settings change the gateway to WAN_dhcp. this is how i allow netflix to play on my TV while the rest of the network is under PIA VPN
  • [SOLVED] Can't connect to OpenVPN server from LAN, how to fix?

    3
    0 Votes
    3 Posts
    736 Views
    P
    Thanks viragomann!
  • I want to set topology subnet

    2
    0 Votes
    2 Posts
    474 Views
    jimpJ
    Shared key can only have one client per server. You would have to switch to an SSL/TLS setup to have multiple clients on a single server.
  • OpenVPN Auto Restart upon drop

    2
    0 Votes
    2 Posts
    1k Views
    jimpJ
    It depends on why it stopped. If it fails because of an auth error at PIA, then OpenVPN considers that fatal and exits. We have a fix for that on 2.4.1 and later (using "auth-retry nointeract") If there is something else causing it to exit, then the fix would be different. Have to see the error in the OpenVPN logs to know for sure. If the process is exiting, then using the Service Watchdog package to monitor it will help treat the symptom, but not cure the original problem.
  • OVPN - Connect Success but no connectivity to Private IPs

    11
    0 Votes
    11 Posts
    1k Views
    S
    Ok, so I finally figured it out. OMG. I had created a cert with a type-o in it and the verify-x509-name was erroring when I tried to connect to machines that were on the domain. That's why some worked and some didn't, because some were on the domain and some weren't. Once I got that all fixed up everything else was easy. Thanks so much for taking the time to look at this with me.
  • Authenticate/Decrypt packet error: PIA, 2.4.1

    3
    0 Votes
    3 Posts
    1k Views
    P
    I am using UDP, currently I have disabled the vpn and am using the windows client. Would really like to use pfsense as I have more than one machine that I would like to vpn. As I said above if anyone needs any more info just ask.
  • OpenVPN back-toback DNS problem

    8
    0 Votes
    8 Posts
    970 Views
    K
    I'd probably put a route to the server in the openvpn client side and a route to the client subnet on the server side…  However, I'm not super genius, so may not work.
  • Client Specific Overrides - assign static ips

    3
    0 Votes
    3 Posts
    1k Views
    G
    I've got this working, in case someone else stumbles on this and has issues my problem was that the username didn't match the certificate name. Andy
  • (SOLVED) Cannot open port to OpenVPN server

    2
    0 Votes
    2 Posts
    426 Views
    SipriusPTS
    Damn I totally forgot to add rules on the only interface firewall that I had to let users use that OpenVPN like I have done with 53 port from DNS Resolver. Thanks anyway.
  • Cipher Status

    3
    0 Votes
    3 Posts
    606 Views
    GilG
    Thanks for the info. I have done as suggested & posted to the OpenVPN forum.
  • Error when attempting to kill OpenVPN client connection

    2
    0 Votes
    2 Posts
    512 Views
    GilG
    I should qualify this, it only happens when I am connected to the web page via OpenVPN. Is his normal? The OpenVPN Connection I am attempting to kill is not my web connection, but a separate router
  • Gateway Groups Switching

    1
    0 Votes
    1 Posts
    374 Views
    No one has replied
  • How to assign a user to a specific OpenVPN instance?

    3
    0 Votes
    3 Posts
    544 Views
    P
    Yes, I use SSL/TLS (+ user auth) for my OpenVPN instances. Thank you for your advice, that was it. So the lesson learned - you need to have a separate CA for a new OpenVPN instance.  :) I created a new CA, then both server and user certificates, assigned them to the 1195 OpenVPN instance and my user respectively. Then finally in Client Export Utility I could select a new entry in the  Remote Access Server drop-down and my user was under this new server. Yes! Exported files had the correct name (with 1195) and worked as expected on my laptop. I only had to correct a few small bugs in my firewall rules.
  • OpenVPN - Blocking DNS failed, unable to connect to VPN

    3
    0 Votes
    3 Posts
    17k Views
    G
    PFSense is currently running version 2.3.4 and it says there is the option to upgrade to version 2.4.1 I am a little reluctant to do this as it could potentially lead to other issues (especially after reading through some of the problems others have had after doing the same) and it is only affecting one person. There is an option on the 'Certificate Export' page to use the 'Old Windows Installer' ver 2.3.14, as this is also a 2.3 release (as the server), could trying this potentially 'fix' the issue? I will give this a go. It should be noted that several users have been using the 2.4.1 client, as issued by the Client Export page, with no problems.
  • OVPN will not connect

    2
    0 Votes
    2 Posts
    495 Views
    DerelictD
    error=unsupported certificate purpose Generate a new server certificate and re-export the client configuration.
  • 0 Votes
    6 Posts
    764 Views
    DerelictD
    It restarts the openvpn daemon and adds all the routes again. It is possible that route existed due to something else adding it and when you started the client with that route there it could not add it for itself. Then it was subsequently removed. Or something. Impossible to know without seeing that event actually occur.
  • OpenVPN + HDHomeRun

    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • OPEN VPN SITE to SITE

    3
    0 Votes
    3 Posts
    1k Views
    J
    Thank you for your answer, we have found the error was on the IP dresses of the WAN thank you
  • No traffic through client vpn once interface is attached

    3
    0 Votes
    3 Posts
    565 Views
    dotOneD
    Yes, I bounced the tunnel. Didn’t help at all. Then I manually restarted the vpn client. The changed IP was reflected on the web interface. But the result still the same, no traffic is flowing. For now, no clue at all
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.