• Pfsense OpenVPN only in ESXi

    2
    0 Votes
    2 Posts
    1k Views
    V
    Yes, that will work with pfSense and also with only one interface. Do you plan a remote access server or a site-to-site? A site-to-site would be more comfortable for the remote users. In both cases you will have to add a static route for the remote site to the file server pointing to pfSense. If it's an access server for the tunnel subnet, if it's a site-to-site for the remote users LAN.
  • Running OpenVPN on LAN interface.

    13
    0 Votes
    13 Posts
    2k Views
    J
    Yup - i think that fixed it.  I switched from "All" to multi selected.  All seems to be working now! Huge thanks for your help, truly appreciated!
  • OpenVPN clients can't access outside /24 range of pfSense's IP address

    2
    0 Votes
    2 Posts
    613 Views
    jimpJ
    How do you connect to those other /24 ranges? Is there some other router involved? In all likelihood the traffic leaves pfSense heading toward those other subnets but can't find its way back.
  • NGINX Gateway Timeout after setting up OpenVPN + FreeRADIUS2 + mOTP

    3
    0 Votes
    3 Posts
    845 Views
    Z
    Can this be fixed on the next stable release?
  • Silent Install of client export package

    3
    0 Votes
    3 Posts
    1k Views
    jimpJ
    Not currently, no. It may be possible with changes to some of the nsis scripts used to do the install but it's not something that gets requested often and I'm not sure how complicated it might be. Windows installers are not something I like hacking on ;-)
  • Route one IP through vpn

    2
    0 Votes
    2 Posts
    676 Views
    O
    It's working ! I don't do anything more, just sleep a long night and it's working ! Amazing ! … Yesterday, my test don't work because i must drop existing tcp/udp flow before testing
  • Issues configuring pfsense 2.3.2 with NordVPN

    2
    0 Votes
    2 Posts
    1k Views
    Z
    @TheIPdude: I experienced the same problem! How did you solve it?
  • Server certificate expired - no connecitivity

    2
    0 Votes
    2 Posts
    607 Views
    jimpJ
    When you make a new CA, you have to remake all of the server and client certificates to go with it.
  • Access EasyN ip camera only works on web interface

    2
    0 Votes
    2 Posts
    948 Views
    Y
    Is it possible to map a VIP (10.0.8.1) to a local ip (192.168.x.x)? so that the camera app can search the local ip cam
  • Site to site without routing all traffic

    6
    0 Votes
    6 Posts
    983 Views
    M
    Can we assume no news is good news?
  • 0 Votes
    3 Posts
    678 Views
    R
    Yes, I've set up two openvpn roadwarrior servers, one per wan interface with same configuration both but different TCP port, because we have two DSL lines, is there a better way to set up X openvpn roadwarrior servers listening to diferent DSL lines without create X different networks? I want to simplify the client override settings, because we are assigning an static ip to some users, and if we create X networks we also need to create X client overrides thanks
  • Additional user doesn't have the same access

    2
    0 Votes
    2 Posts
    523 Views
    V
    10.0.50.3 is in the same subnet as 10.0.50.2/30, it's the broadcast address for the first users subnet. 10.0.50.2/30: 10.0.50.0 … network 10.0.50.1 ... server 10.0.50.2 ... client 10.0.50.3 ... broadcast You may give the second user the next /30 subnet, that's 10.0.50.4/30, so the client will get 10.0.50.6 and the server 10.0.50.5.
  • Restrict OpenVPN users to specific FQDN's / IP addresses

    1
    0 Votes
    1 Posts
    525 Views
    No one has replied
  • Mac OS clients can connect, but no LAN access

    10
    0 Votes
    10 Posts
    3k Views
    J
    @Derelict: That'll do it. Indeed. For my own understanding, why would OpenVPN allow one connection though? I get that 10.8.15.0/24 couldn't get outside of VLAN 15 because there were no routes outside of it, but why would the first connection be able to get to all other VLANS? Is OpenVPN somehow above the law so to speak in the network stack?
  • 0 Votes
    3 Posts
    683 Views
    D
    Another possibility is "helpful"(?!) browsers auto-filling/auto-correcting on screen forms. Might be worth trying a different browser just to be sure.
  • Site-To-site : static IP address for Tunnel interface

    3
    0 Votes
    3 Posts
    691 Views
    B
    Thanks a lot well, i thought there will be one instance in the server talking with many remote sites so now, i must have instances in the server as many as the number of remote sites so the topology in the clients settings is just for client-to-site it make sense, but it's a hell of work thanks again
  • OpenVPN multicast?

    5
    0 Votes
    5 Posts
    3k Views
    U
    Has anyone been able to get this working? i'm trying to configure a 3 cluster configurations for my 3 proxmox noeds. 2 proxmox nodes are in the same physical network and i have no issues clustering them up. my issue is when i try to add the 3rd node which sits in a remote location, i get the "waiting for Quorum" time out  error, im assuming this is due to the multicast traffic not being passed through the S2S tunnel I've configured the ovpn server via TUN / UDP. i have access to the remote side, and vise versa. any suggestions ?
  • 0 Votes
    7 Posts
    1k Views
    BearB
    One would be led to believe, but since it's a filtered bridge, I don't assign an IP to the LAN side of it.  I'm just saying it's showing up as 10, even though it's not set.  My locals (which are working) are 104.49... Regardless, I'm still where I was - All of my rules are working, folks can get in and out of my statics/servers, but OpenVPN client can connect but go nowhere.
  • 0 Votes
    4 Posts
    817 Views
    H
    @Pippin: Fix time on client side, cmos bat.? Push NTP to the client(s) … Client is a VM. The host had its time set improperly (ESXi). I set the time manually on the host because the NTP service wasn't starting properly. Not sure the deal there, will troubleshoot that eventually. What concerns me is the VM rebooted and even though it had NTP enabled it pulled time from the host and never updated itself. In order to fix it I logged in, went to system-> settings, saw the NTP was enabled, clicked "save" and the time updated. Trying to figure out why the pfsense VM didn't automatically update until I logged in and clicked "save", seems like it should've noticed that NTP and local time were off and auto-corrected without me intervening.
  • Can't access IPsec Site-to-Site Subnet from OpenVPN Subnet

    4
    0 Votes
    4 Posts
    1k Views
    M
    So if your routing table doesn't mention 20.0, then it really truly doesn't know how to get to it, and will send that traffic to default gateway. The openvpn server may very well push the route to 20.0 to the remote clients.  The clients will contact the specified gateway. However that doesn't mean the gateway (ie probably your pf box with the missing route), knows how to get to 20.0 Add a System / routing / static route if needed.
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.