• Not natted access to LAN network

    4
    0 Votes
    4 Posts
    455 Views
    V
    @jere7em said in Not natted access to LAN network: No, the default gateway is the VPC Internet Gateway (they are on AWS)... That's why you need NAT. @jere7em said in Not natted access to LAN network: maybe I have to add the routes to the AWS Lan configuration... Don't know the structure of the AWS network, so I cannot help. If it's possible you can install a transit network between the default gateway and pfSense. So you have only to add a static route for the LAN to pfSense. Otherwise you will need a static for the OpenVPN tunnel network route on each device the VPN clients should be able to access.
  • 0 Votes
    1 Posts
    130 Views
    No one has replied
  • Best method to consolidate OpenVPN client connections

    4
    0 Votes
    4 Posts
    441 Views
    KOMK
    @Rico Thanks, this might be the cleanest solution. @oddussiben-3161 That would require me to define every single client connection in order to make them gateways and able to be added to a gateway group. This is exactly what I want to avoid. Thanks for you r reply though. I appreciate it.
  • Voip application via OpenVPN (Its Important) :(

    1
    0 Votes
    1 Posts
    227 Views
    No one has replied
  • Open VPN Internet access

    5
    0 Votes
    5 Posts
    636 Views
    V
    Yes. So check "Redirect gateway" in the server settings to push the default route to the clients and provide a DNS server. Additionally you have to add an outbound NAT rule for the VPN clients. Firewall > NAT > Outbound. Select the hybrid mode and hit save if you have the automatic mode now. Then add new rule: interface: WAN source: <OpenVPN tunnel network> destination: any translation: interface address
  • DNS over OpenVPN question

    1
    0 Votes
    1 Posts
    276 Views
    No one has replied
  • Problem users disconnect Open VPN pfsense 2.4.5-release

    7
    0 Votes
    7 Posts
    1k Views
    J
    @DaddyGo I have this processor [image: 1597153553300-cc874b28-faad-4faf-8bec-4b7f7592cefc-image.png] I´ll look this =) In pfSense, you can configure multiple servers on a single device. Due to redundancy and for the sake of a high number of users, I would even run multiple servers in a separate box. (we do anyway) i´ll try change port Port scanners are familiar with the sub-2K range, yes the dedicated port(s) is 119X, but i wouldn't leave the port here, if you have that many VPN users. i´ll update the version this week. Current version and 2.4.5-p1 contains very important fixes !!! (pfctl, etc.) 23d05161-da56-456f-b9af-b03d8644b5e1-image.png Please Update...... ASAP after update S.O , i´ll update this post about the vpn Connection. Thansk you in advanced.
  • Work from home security issues

    10
    0 Votes
    10 Posts
    1k Views
    DaddyGoD
    @netblues said in Work from home security issues: policy won't happen by asking on any forum.
  • OpenVPN firewall rules?

    8
    0 Votes
    8 Posts
    740 Views
    RicoR
    https://docs.netgate.com/pfsense/en/latest/book/monitoring/firewall-states-reset.html -Rico
  • Home VPN

    2
    0 Votes
    2 Posts
    324 Views
    johnpozJ
    @techsalot said in Home VPN: I want to get IPs that are on the same subnet as my other devices. For why? Makes no sense to do this.. RDP doesn't need L2 discovery.. there would be no reason to be on the same network as you lan to rdp to stuff. "My problem is none of the guides I have seen are specific enough." You walk through the wizard following the bouncing ball.. You then export your certs and configs for your clients via the vpn export package. https://docs.netgate.com/pfsense/en/latest/book/openvpn/using-the-openvpn-server-wizard-for-remote-access.html Here some advice trying to follow some guide that says click here, do this.. Isn't helping you learn anything.. Nor helping you understand anything... And when it stop working for whatever reason.. You will have not have clue 1 to what is the problem. What exactly do you not understand about spinning up a vpn server on pfsense? Have you read through the book about openvpn? https://docs.netgate.com/pfsense/en/latest/book/openvpn/index.html Now again back to this.. My problem is none of the guides I have seen are specific enough. Why? What part are you confused about? Point to a guide or guides you have read through and what parts - exactly are confusing you?
  • TLS Error : something wrong with Certificates ?

    tls certificate open vpn
    13
    0 Votes
    13 Posts
    2k Views
    DaddyGoD
    @Bekoj said in TLS Error : something wrong with Certificates ?: installed pfsense brand new in 2.4.5 version installed pfsense brand new in 2.4.5 version hmmm, next time I'll ask first... @Gertjan "Oooohhhh. And you're telling that now ?" Yes, we went around a bit, the point is, it's okay
  • [Help] Configuring Open VPN to bridge same subnets/vlans over wan tunnel

    1
    0 Votes
    1 Posts
    223 Views
    No one has replied
  • Firewall rules w/mixed interface assignments

    1
    0 Votes
    1 Posts
    173 Views
    No one has replied
  • OpenVPN as a WAN - IPv4 works buy IPv6 leaks

    8
    0 Votes
    8 Posts
    778 Views
    Y
    @Bob-Dig I need to get some work done right now and I don't know enough to figure this out quickly so I just did a factory reset and I'm just going to use the IVPN app on my computer today… Really frustrating but… No choice right now. Thanks for trying to help!!
  • How to use OPT1 port to segment VPN traffic outside of LAN traffic?

    3
    0 Votes
    3 Posts
    363 Views
    V
    Thanks for your help Netblues, helped to understand better what I need to do
  • Unable to connect to openvpn

    7
    0 Votes
    7 Posts
    2k Views
    J
    @nikkon thanks you for the information!
  • Poor perfomance over OpenVPN

    4
    0 Votes
    4 Posts
    532 Views
    DaddyGoD
    @jordiSL said in Poor perfomance over OpenVPN: FW: Super Micro XG-1537 You mean, like original Netgate hardware (XG-1537)? @jordiSL "I get is 30Mbps" Yes, it seems low... (This gives me almost 10x higher speed (M11SDV-4C-LN4F), so your device also needs to know this speed) interesting to read this: https://docs.netgate.com/pfsense/en/latest/book/hardware/hardware-sizing-guidance.html two things I'm thinking about now: loader.conf.local (flow control (FC), EEE, hw.igb.rx_process_limit="-1" hw.igb.tx_process_limit="-1, etc.) https://docs.netgate.com/pfsense/en/latest/hardware/tuning-and-troubleshooting-network-cards.html https://calomel.org/freebsd_network_tuning.html @jordiSL "The client fiber is 300Mbps which I'm connected." incorrectly configured this side or incorrect measurement method... BTW: OpenVPN dslreports.com (on 500/200 - ISP): [image: 1596809326215-c7581716-ed59-4378-b5c7-5617a6c24f44-image.png] and what about these? ifconfig igb0 -rxcsum -rxcsum6 -txcsum -txcsum6 -lro -tso -vlanhwtso (igb, IX, em, etc.)
  • OpenVpn howto masquerade all VPN traffic

    open vpn
    9
    0 Votes
    9 Posts
    2k Views
    johnpozJ
    Then its something with the switches.. Do they have gateways set? Do they allow access from other than their own network.. Are their masks set correctly.. What is your tunnel network, if they are set for say 10/8 and think your coming from a local IP, they won't send answer back to gateway, etc.
  • OVPN Client to multi-site

    3
    0 Votes
    3 Posts
    349 Views
    M
    Thank you very much! That works perfect!
  • Firewall rules for every Openvpn-client, is ip-adress fixed?

    3
    0 Votes
    3 Posts
    396 Views
    horshackH
    @dotdash Thank you for this helpful hint. I did this: VPN - openvpn - Client Specific overriedes - add common name: xxx IPv4 Tunnel network: 192.168.10.200/24 (network 192.168.10.x is the ipv4-tunnel I also use for my other "normal" users without fixed ip address) IPv6-Tunnel network: fd73:123:456:2::200/64 (network fd73:123:456:2 is the ipv6-tunnel I also use for my other "normal" users without fixed ip address) Now I can create firewall rules (Firewall/Aliases/Edit) specific for my clients.
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.