• 10 Votes
    23 Posts
    32k Views
    GertjanG
    @Bambos said in HEADS UP: OpenVPN deprecating shared key mode, requires TLS, deprecating cipher selection: for the remote access VPN, if is SSL/TLS + User auth, does this working with freeradius as well ? I'm using FreeRadius myself for the captive portal. Never tried to do this ... You probably want also see this one also : FreeRadius on pfSense software for Two Factor Authentication although I presume that article was written for those who wanted to "why do things the easy way if much harder is so much better ?" @Bambos said in HEADS UP: OpenVPN deprecating shared key mode, requires TLS, deprecating cipher selection: i have many 2.6 versions clients to upgrade Keep in mind that 2.6.0 uses the "old" (now completly ditched because of security) OpenVPN (and now also old OpenSSL !!) libaries. The recent pfSense uses the more modern OpenVPN and OpenSSL. All this means that some options won't work anymore. Some more options will work, but will be depreciated soon (as usual). I Use OpenVPN myself, so I always have a look at the "source" : web pages like this and the classic openvpn support forum. The OpenVPN client also changed to support the newer OpenVPN server. And yes, I agree, syncing the entire openvpn user fleet can be a hassle.
  • Scaling OpenVPN (and VPNs in general)

    Pinned
    12
    6 Votes
    12 Posts
    20k Views
    M
    I have discovered that OpenVPN implementation in PFsense is slow even without ciphering data, look at my post: link text
  • OpenVPN Documentation

    Pinned Locked
    1
    0 Votes
    1 Posts
    39k Views
    No one has replied
  • Help setup nested (multi-hop) Surfshark VPN chain inside pfSense

    1
    0 Votes
    1 Posts
    20 Views
    No one has replied
  • Client server with two point-to-point VPNs (SSL/TLS) connection drops.

    2
    0 Votes
    2 Posts
    29 Views
    V
    @jucelio_rosa said in Client server with two point-to-point VPNs (SSL/TLS) connection drops.: On the server, we have two links (a "primary" link and a "backup" link). What exactly do you mean with the term "link" here? Where is the OpenVPN server running on? Where is the clinet running on? How does the config look like?
  • Need help setting up Multi-Hop OpenVPN Surfshark

    1
    0 Votes
    1 Posts
    19 Views
    No one has replied
  • NordVPN Curiosity with 2.8.1

    11
    0 Votes
    11 Posts
    219 Views
    B
    @elvisimprsntr Thanks for that elvisimprsntr. I don’t use “privacy” vpns for privacy, just for casual defense against geo-blocking and it works for me. Thumbs up for that video though.
  • Servidor cliente com duas vpns ponto a ponto (ssl/tls) conexão cai

    1
    0 Votes
    1 Posts
    34 Views
    No one has replied
  • OpenVPN with ipv6 delegated prefix

    8
    0 Votes
    8 Posts
    122 Views
    JKnottJ
    @TheGushi said in OpenVPN with ipv6 delegated prefix: I do not know what prefix my ISP will delegate to me. Hopefully, it won't change. I've had the same prefix for almost 7 years. However, you have to select System /Advanced / Networking Do not allow PD/Address release to keep from getting different prefixes. But not all ISPs obey that.
  • Openvpn client access Rustdesk server

    2
    0 Votes
    2 Posts
    115 Views
    F
    Hi Everyone after hours of log investigation i find out the problem is the DNS. what a waste of time. thanks
  • Having trouble accessing NAS through VPN server

    29
    0 Votes
    29 Posts
    972 Views
    A
    @the-other Ok, I made a specific rule in the OpenVPN interface to allow any to both NAS servers. [image: 1761707110778-2cd0716f-d4f0-4e63-94e8-4fc93788fd6d-image.png] Here you can see me connecting to the VPN server with my iPhone and attempting to ping both the NAS servers. The traffic passes through the firewall but the ping fails to the Synology (200.4). [image: 1761707746508-eb97e248-fbd4-43cf-977c-31d87df234ce-image.png] [image: 1761707789724-efcea745-54b9-4460-a44a-e2fffc8c5644-image.png] I can, however, successfully ping the backup NAS (200.5) but I cannot connect to that one either with the File Explorer app. BTW, the backup NAS is an old Asus AC-RT86 router in AP mode with WiFi disabled and a SAMBA SSD in the USB port.
  • write TCPv4_CLIENT: Permission Denied on OpenVPN client 24.03 RC

    Moved
    26
    0 Votes
    26 Posts
    2k Views
    G
    Posting here because I found this thread when troubleshooting the same error message, so maybe this helps someone else: In my case it was due to an asymmetric routing situation that had developed because of static routes defined within the OpenVPN "remote network" settings. I have a multiple WAN situation with failover gateway and failover VPNs defined through policy routing groups. The behavior I experienced was very similar to what you describe, which in my case was caused by return packets flowing across a different interface than the origin packets. The firewall couldn't see the return packets, and closed the state. I couldn't figure out why traffic was coming in on one interface but going out on another, despite setting up policy routing in the firewall. In my case the "aha" moment came from reading https://docs.netgate.com/pfsense/en/latest/troubleshooting/asymmetric-routing.html -- I removed the non-obvious static route in the OpenVPN settings and instantly resolved multiple issues.
  • Multiple Static Assigned Addresses FreeRadius For OpenVPN

    7
    1
    0 Votes
    7 Posts
    281 Views
    R
    So, poking around in docs, seems like maybe the weapon of choice here is the framed-pool RADIUS attribute. Look like you can assign distinct IP pools to clients using this attribute. Anyone know if this attribute is compatible with the FreeRADIUS package that is available for PFSense? Can OpenVPN use this attribute for assigning IP addresses to clients? Anyone done this successfully?
  • Comcast Business maintenace, now OpenVPN not working

    11
    0 Votes
    11 Posts
    353 Views
    B
    @SteveITS I agree 100%, I'm not complaining its working again and I have notes on it, when they do "maintenance" in the area again... Glad the onsite tech new something more than the support back at ISP office... Brian
  • 0 Votes
    1 Posts
    121 Views
    No one has replied
  • Reissue/renew certificate and change validity duration?

    1
    1
    0 Votes
    1 Posts
    94 Views
    No one has replied
  • Crash on saving after deselecting all allowed ciphers

    1
    0 Votes
    1 Posts
    118 Views
    No one has replied
  • Always-on VPN not working with Protectli and Slate AP

    7
    0 Votes
    7 Posts
    373 Views
    H
    @Gertjan I have allowed pfSense's DHCP to dole out the IP for the AP. I tried assigning an IP as you recommend but it didn't help. I've also ordered another AP to see if there is something about the software there that's causing the issue.
  • Portforword through a VPN client

    4
    6
    0 Votes
    4 Posts
    293 Views
    V
    Well, if this is correct as far, you should be close to get it working. @Udbytossen said in Portforword through a VPN client: And under the firewall rule advanced setting I'm changing the gateway to Torguard instead of default But already mentioned, that this makes no sense at all. So edit the rule and set the gateway to default. Then go to the OpenVPN rule tab and remove or disable each pass rule. Done.
  • Cannot connect to OpenVPN Server via ipv6 endpoint

    4
    0 Votes
    4 Posts
    262 Views
    JKnottJ
    Is your pfSense configured to work over both IPv4 and IPv6? I assume you have IPv6 on your WAN. 4G & 5G phones are IPv6 and Android phones use 464XLAT to access IPv4 sites. This is effectively double NAT, which can mess things up. I don't know what iPhones use, but they'd have something similar. By sticking with IPv4, you are already breaking things. IPv6 is the future, so you'd better get used to it.
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.