• AD Replication across Site to Site

    9
    0 Votes
    9 Posts
    5k Views
    A
    @claes_hellgren: @petros: Hi Guys Here is how I got it working. 1. Disable Automatic NAT as you suggested. I created a NO NAT rule for the OpenVPN interface. 2. Created a static mapping in the local WINS database for the remote Domain Controller. 3. Go to Sites and Services on the remote DC and make sure there is a connector set for the local DC in the NTDS settings. 4. Go to Sites and Services on the local DC and make sure there is a connector set for the remote DC in the NTDS settings. Thanks for the help. How dose your NO NAT rule look? The topic is old but it does help me for the same situation. I just disable Automatic NAT as suggested and change to Manual Outbound NAT rule generation  (AON - Advanced Outbound NAT). A NO NAT rule may not needed but if you want just select the option "Do not NAT Enabling this option will disable NAT for traffic matching this rule and stop processing Outbound NAT rules". I just try with or without NO NAT rule, both DC replicated without issue.
  • 1ip vpn + squid

    2
    0 Votes
    2 Posts
    656 Views
    R
    well i could not find anything either thanks for reading any that did. i worked around the issue by turning off transparent proxy and blocking http at firewall for all other networks except my own trusted and on that one i have two web browsers now one configured for squid the other not. so browser one is going through proxy second browser goes via VPN without leaking. i am going to try and configure wpad so i don't have to manually configure browsers, its not perfect but anyone finding themselves in same situation at least you can have a semi work around. thanks all
  • OpenVPN and IPSEC

    1
    0 Votes
    1 Posts
    553 Views
    No one has replied
  • A Reason for More Widespread use of VPN in USA?

    5
    0 Votes
    5 Posts
    1k Views
    P
    Haha yes sir it is. Still, there is zero question that ISP is selling everything they can about you. They all do it so there is effectively a monopoly, their business is not affected when people know they are doing this. VPN providers very well may do this, some have been caught doing so, but it is bad for their business if they are found doing this. VPS providers I'm guessing probably do not engage in this activity much as they often serve large companies that would and could fight their data being sold. Both options at least have the potential for improvement over ISP.
  • After ~2 weeks, pfsense kills all outbound traffic until VPN is restarted

    7
    0 Votes
    7 Posts
    1k Views
    S
    Unfortunately my partner rebooted the system whilst I was away so I'll have to wait another couple of weeks to pull logs.
  • Route only certain port traffic via Site-Site OpenVPN

    6
    0 Votes
    6 Posts
    2k Views
    DerelictD
    Under LAN of Site A. I tried setting rule: SRC * DST * DSTPort 25 GW OPTVPN That looks reasonable. and also SRC Port 25 DST * DSTPort * GW OPTVPN Setting a source port is almost never right, and is certainly not right in this case. I have no problem routing inbound internet traffic -> 99.99.99.99:STMP to 10.10.0.15 So if that is the case, you want to check: The rules on the OpenVPN tab/interface at Site B to be sure the traffic is allowed from site A (10.10.0.15) to any You have outbound NAT in place on WAN at site B for the 10.10.0.15 source address. That is also where you would specify 99.99.99.99 as the source address if there is more than one choice.
  • TLS Error: local/remote TLS keys are out of sync

    8
    0 Votes
    8 Posts
    59k Views
    J
    Done! thanks
  • Openvpn site to site WAN to VLAN

    1
    0 Votes
    1 Posts
    524 Views
    No one has replied
  • Remove a route that was created

    2
    0 Votes
    2 Posts
    797 Views
    johnpozJ
    Not sure why your trying to hide your 192.168 address?? But your problem is 192.168.x.1/24 is not a network, that is a host address.  A /24 network would be 192.168.x.0/24
  • Changes ir /var/etc/openvpn/server1.conf not permanet

    4
    0 Votes
    4 Posts
    10k Views
    J
    FOUND IT!! When you create a new vpn server or editting the actual, you can see almost at the end of the configuration: Advanced Configuration In Custom options you can add whatever you want, for example:  reneg-sec 36000 THank you!
  • 0 Votes
    1 Posts
    492 Views
    No one has replied
  • Configure OpenVPN with ExpressVPN

    2
    0 Votes
    2 Posts
    756 Views
    M
    What does it show when you go into the OpenVPN status page? I would start by checking your OpenVPN log to see if there is a problem. You may want to post some screen shots of the settings you used to configure your openvpn client and the  ovpn file itself.
  • Routing only certain Public Ip's through Openvpn tunnel.

    4
    0 Votes
    4 Posts
    1k Views
    frogF
    HI Both,  Excellent thanks that worked. Much appreciated.
  • OpenVPN multiple client(s) as gateways issue

    1
    0 Votes
    1 Posts
    394 Views
    No one has replied
  • Pfsense server and client running

    5
    0 Votes
    5 Posts
    854 Views
    A
    Is this happening on your phone when you are connected to your VPN from the outside? If so you could have the option to force traffic through the tunnel and are missing the allow rule on your OpenVPN interface. Can you post a screenshot of your interfaces tab and of your OpenVPN config?
  • Site-to-Site access on both sides

    3
    0 Votes
    3 Posts
    621 Views
    A
    You need a route on the client settings to the server side subnet and the iroute on the connecting client to the server side subnet in order for the Clint subnet to respond to packets from the server side subnet. Example If your server side subnet is 10.2.0.0/24 you need to add iroute 10.2.0.0/24 to the client specific overrides section of the OpenVPN configuration on the client side
  • Can't ping server from OpenVpn client

    2
    0 Votes
    2 Posts
    527 Views
    A
    If you open a command prompt and run a route print do you see a route to the server subnet through the tap interface IP?
  • Vpn from wireless network to lan

    1
    0 Votes
    1 Posts
    415 Views
    No one has replied
  • Chrome OS requires p12 password

    2
    0 Votes
    2 Posts
    734 Views
    V
    Install the OpenVPN client exort utility package. After you get a tab for the export utility in VPN > OpenVPN. Use this tool to export the certs and config and check "Password Protect Certificate".
  • OpenVPN with Multiple gateways same subnet

    5
    0 Votes
    5 Posts
    1k Views
    DerelictD
    Yeah outbound NAT on LAN
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.